Nessus Report

Report generated by Tenable Nessus™

Server 5

Sat, 24 Jan 2026 13:07:11 India Standard Time

TABLE OF CONTENTS
Vulnerabilities by HostExpand All | Collapse All
172.17.100.140
14
251
47
3
1417
Critical
High
Medium
Low
Info
Scan Information
Start time: Sat Jan 24 12:16:17 2026
End time: Sat Jan 24 13:02:35 2026
Host Information
Netbios Name: LKP_SIP_APPSRV-
IP: 172.17.100.140
MAC Address: 00:50:56:88:13:C1 00:50:56:88:84:22
OS: Microsoft Windows Server 2019 Datacenter Build 17763
Vulnerabilities

172178 - ASP.NET Core SEoL
-
Synopsis
An unsupported version of ASP.NET Core is installed on the remote host.
Description
According to its version, the ASP.NET Core installed on the remote host is no longer maintained by its vendor or provider.

Lack of support implies that no new security patches for the product will be released by the vendor. As a result, it may contain security vulnerabilities.
See Also
Solution
Upgrade to a version of ASP.NET Core that is currently supported.
Risk Factor
Critical
CVSS v3.0 Base Score
10.0 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
Plugin Information
Published: 2023/03/07, Modified: 2023/03/07
Plugin Output

tcp/0


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.AspNetCore.App\5.0.17
Installed version : 5.0.17
Security End of Life : May 9, 2022
Time since Security End of Life (Est.) : >= 3 years

tcp/0


Path : C:\Program Files\dotnet\shared\Microsoft.AspNetCore.App\5.0.17
Installed version : 5.0.17
Security End of Life : May 9, 2022
Time since Security End of Life (Est.) : >= 3 years

249130 - KB5063877: Windows 10 version 1809 / Windows Server 2019 Security Update (August 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5063877. It is, therefore, affected by multiple vulnerabilities

- Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
(CVE-2025-53766)

- Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. (CVE-2025-49751)

- Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. (CVE-2025-49743)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5063877
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.017
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/08/12, Modified: 2025/10/29
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5063877

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.6893
Should be : 10.0.17763.7671
270378 - KB5066586: Windows 10 version 1809 / Windows Server 2019 Security Update (October 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5066586. It is, therefore, affected by multiple vulnerabilities

- tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka Predictor heap-buffer-overflow. (CVE-2016-9535)

- In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image. (CVE-2025-47827)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5066586
Risk Factor
High
CVSS v3.0 Base Score
9.9 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
9.2
EPSS Score
0.0824
CVSS v2.0 Base Score
7.5 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
6.2 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2016-9535
CVE CVE-2025-24052
CVE CVE-2025-24990
CVE CVE-2025-25004
CVE CVE-2025-47827
CVE CVE-2025-48813
CVE CVE-2025-49708
CVE CVE-2025-50152
CVE CVE-2025-50175
CVE CVE-2025-53150
CVE CVE-2025-53768
CVE CVE-2025-54957
CVE CVE-2025-55325
CVE CVE-2025-55326
CVE CVE-2025-55328
CVE CVE-2025-55332
CVE CVE-2025-55333
CVE CVE-2025-55335
CVE CVE-2025-55336
CVE CVE-2025-55338
CVE CVE-2025-55678
CVE CVE-2025-55679
CVE CVE-2025-55680
CVE CVE-2025-55681
CVE CVE-2025-55683
CVE CVE-2025-55687
CVE CVE-2025-55692
CVE CVE-2025-55695
CVE CVE-2025-55696
CVE CVE-2025-55699
CVE CVE-2025-55700
CVE CVE-2025-55701
CVE CVE-2025-58714
CVE CVE-2025-58715
CVE CVE-2025-58716
CVE CVE-2025-58717
CVE CVE-2025-58718
CVE CVE-2025-58719
CVE CVE-2025-58720
CVE CVE-2025-58722
CVE CVE-2025-58725
CVE CVE-2025-58726
CVE CVE-2025-58728
CVE CVE-2025-58729
CVE CVE-2025-58730
CVE CVE-2025-58732
CVE CVE-2025-58733
CVE CVE-2025-58734
CVE CVE-2025-58735
CVE CVE-2025-58736
CVE CVE-2025-58737
CVE CVE-2025-58738
CVE CVE-2025-58739
CVE CVE-2025-59184
CVE CVE-2025-59185
CVE CVE-2025-59186
CVE CVE-2025-59187
CVE CVE-2025-59188
CVE CVE-2025-59190
CVE CVE-2025-59191
CVE CVE-2025-59192
CVE CVE-2025-59193
CVE CVE-2025-59195
CVE CVE-2025-59196
CVE CVE-2025-59197
CVE CVE-2025-59198
CVE CVE-2025-59199
CVE CVE-2025-59200
CVE CVE-2025-59201
CVE CVE-2025-59202
CVE CVE-2025-59203
CVE CVE-2025-59204
CVE CVE-2025-59205
CVE CVE-2025-59207
CVE CVE-2025-59208
CVE CVE-2025-59209
CVE CVE-2025-59211
CVE CVE-2025-59214
CVE CVE-2025-59230
CVE CVE-2025-59242
CVE CVE-2025-59244
CVE CVE-2025-59253
CVE CVE-2025-59254
CVE CVE-2025-59255
CVE CVE-2025-59258
CVE CVE-2025-59259
CVE CVE-2025-59260
CVE CVE-2025-59275
CVE CVE-2025-59277
CVE CVE-2025-59278
CVE CVE-2025-59280
CVE CVE-2025-59282
CVE CVE-2025-59294
CVE CVE-2025-59295
MSKB 5066586
XREF MSFT:MS25-5066586
XREF CISA-KNOWN-EXPLOITED:2025/11/04
XREF IAVA:2025-A-0775-S
XREF IAVA:2025-A-0776-S
Plugin Information
Published: 2025/10/14, Modified: 2025/11/18
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5066586

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.6893
Should be : 10.0.17763.7919
95811 - MS16-148: Security Update for Microsoft Office (3204068)
-
Synopsis
An application installed on the remote host is affected by multiple vulnerabilities.
Description
The Microsoft Office application or Microsoft Office Services and Web Apps installed on the remote Windows host is missing a security update. It is, therefore, affected by multiple vulnerabilities :

- An arbitrary command execution vulnerability exists in Microsoft Office due to improper validation of user-supplied input. An unauthenticated, remote attacker can exploit this by convincing a user to open a specially crafted Office file, resulting in a bypass of security restrictions and the execution of arbitrary commands. (CVE-2016-7262)

- Multiple remote code execution vulnerabilities exist in Microsoft Office software due to a failure to properly handle objects in memory. An unauthenticated, remote attacker can exploit these vulnerabilities by convincing a user to open a specially crafted Office file, resulting in the execution of arbitrary code in the context of the current user. (CVE-2016-7263, CVE-2016-7277, CVE-2016-7289, CVE-2016-7298)

- Multiple information disclosure vulnerabilities exist in Microsoft Office software due to an out-of-bounds memory read error. An unauthenticated, remote attacker can exploit these vulnerabilities by convincing a user to open a specially crafted Office file, resulting in the disclosure of memory contents. (CVE-2016-7264, CVE-2016-7265, CVE-2016-7268, CVE-2016-7276, CVE-2016-7290, CVE-2016-7291)

- An arbitrary command execution vulnerability exists in Microsoft Office due to improper validation of registry settings when running embedded content. An unauthenticated, remote attacker can exploit this by convincing a user to open a specially crafted document file multiple times, resulting in a bypass of security restrictions and the execution of arbitrary commands.
(CVE-2016-7266)

- A security bypass vulnerability exists in Microsoft Office due to improper parsing of file formats. An unauthenticated, remote attacker can exploit this by convincing a user to open a specially crafted Office file, resulting in a bypass security restrictions.
(CVE-2016-7267)

- An elevation of privilege vulnerability exists in Microsoft Office due to improper validation before loading libraries. A local attacker can exploit this, via a specially crafted application, to gain elevated privileges. (CVE-2016-7275)
See Also
Solution
Microsoft has released a set of patches for Microsoft Office 2007, 2010, 2013, 2013 RT, and 2016; Microsoft Excel 2007, 2010, 2013, 2013 RT, and 2016; Microsoft Word 2007, 2010; Microsoft Publisher 2010 Office Compatibility Pack; Excel Viewer; Word Viewer; Microsoft SharePoint Server 2007 and 2010; and Office Web Apps 2010.
Risk Factor
High
CVSS v3.0 Base Score
9.6 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.2 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.8
EPSS Score
0.8709
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
BID 94662
BID 94664
BID 94665
BID 94668
BID 94670
BID 94671
BID 94672
BID 94715
BID 94718
BID 94720
BID 94721
BID 94769
CVE CVE-2016-7262
CVE CVE-2016-7263
CVE CVE-2016-7264
CVE CVE-2016-7265
CVE CVE-2016-7266
CVE CVE-2016-7267
CVE CVE-2016-7268
CVE CVE-2016-7275
CVE CVE-2016-7276
CVE CVE-2016-7277
CVE CVE-2016-7289
CVE CVE-2016-7290
CVE CVE-2016-7291
CVE CVE-2016-7298
MSKB 3128020
MSKB 2883033
MSKB 3127986
MSKB 3127968
MSKB 3128029
MSKB 3127892
MSKB 3128037
MSKB 3128019
MSKB 3128025
MSKB 3128022
MSKB 3128024
MSKB 3128023
MSKB 3128016
MSKB 3128008
MSKB 3128026
MSKB 3118380
MSKB 3128032
MSKB 2889841
MSKB 3128034
MSKB 3114395
MSKB 3128035
MSKB 3128044
MSKB 3128043
MSKB 3127995
XREF MSFT:MS16-148
XREF IAVA:2016-A-0345-S
XREF CISA-KNOWN-EXPLOITED:2022/03/24
Plugin Information
Published: 2016/12/14, Modified: 2023/04/25
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4471.1000

172179 - Microsoft .NET Core SEoL
-
Synopsis
An unsupported version of Microsoft .NET Core is installed on the remote host.
Description
According to its version, the Microsoft .NET Core installed on the remote host is no longer maintained by its vendor or provider.

Lack of support implies that no new security patches for the product will be released by the vendor. As a result, it may contain security vulnerabilities.
See Also
Solution
Upgrade to a version of Microsoft .NET Core that is currently supported.
Risk Factor
Critical
CVSS v3.0 Base Score
10.0 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
Plugin Information
Published: 2023/03/07, Modified: 2023/03/07
Plugin Output

tcp/0


Path : C:\Program Files\dotnet\shared\Microsoft.NetCore.App\5.0.17\
Installed version : 5.0.17.31213
Security End of Life : May 9, 2022
Time since Security End of Life (Est.) : >= 3 years

270707 - Microsoft ASP.NET Core Security Feature Bypass (October 2025)
-
Synopsis
The remote Windows host is affected by a security feature bypass vulnerability.
Description
The version of ASP.NET Core installed on the remote Windows host is 8.0.x prior to 8.0.21, 9.0.x prior to 9.0.10, or 10.0.0-rc.1.25451.107. It is, therefore, affected by a security feature bypass vulnerability.
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core to version 8.0.21, 9.0.10, 10.0.0-rc.2.25502.107 or later.
Risk Factor
High
CVSS v3.0 Base Score
9.9 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L)
VPR Score
10.0
EPSS Score
0.0004
CVSS v2.0 Base Score
8.7 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:P)
STIG Severity
I
References
CVE CVE-2025-55315
XREF IAVA:2025-A-0753
Plugin Information
Published: 2025/10/17, Modified: 2025/10/17
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.AspNetCore.App\8.0.8
Installed version : 8.0.8
Fixed version : 8.0.21

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.AspNetCore.App\8.0.8
Installed version : 8.0.8
Fixed version : 8.0.21
136511 - Security Updates for Microsoft Excel Products (May 2020)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update.
It is, therefore, affected by the following vulnerability :

- A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-0901)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4484365
-KB4484384
-KB4484338

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.4586
CVSS v2.0 Base Score
7.5 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.5 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2020-0901
MSKB 4484365
MSKB 4484384
MSKB 4484338
XREF MSFT:MS20-4484365
XREF MSFT:MS20-4484384
XREF MSFT:MS20-4484338
XREF IAVA:2020-A-0199-S
Plugin Information
Published: 2020/05/12, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5005.1000

Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4993.1001
126583 - Security Updates for Microsoft Office Products (July 2019)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. They are, therefore, affected by multiple vulnerabilities:

- An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. (CVE-2019-1084)

- A spoofing vulnerability exists when Microsoft Office Javascript does not check the validity of the web page making a request to Office documents. An attacker who successfully exploited this vulnerability could read or write information in Office documents. (CVE-2019-1109)

- A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Exploitation of the vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Excel. In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and convincing the user to open the file. In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) containing a specially crafted file designed to exploit the vulnerability. An attacker would have no way to force users to visit the website. Instead, an attacker would have to convince users to click a link, typically by way of an enticement in an email or instant message, and then convince them to open the specially crafted file.(CVE-2019-1111)

- An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory.
An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data.
To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it.
An attacker must know the memory address location where the object was created. (CVE-2019-1112) The update addresses the vulnerability by changing the way certain Excel functions handle objects in memory.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4462224
-KB4464558
-KB4464543
-KB4018375
-KB4475514
-KB4464534
-KB4461539

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
9.1 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
CVSS v3.0 Temporal Score
7.9 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.2706
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
BID 108415
BID 108965
BID 108974
BID 108975
CVE CVE-2019-1084
CVE CVE-2019-1109
CVE CVE-2019-1111
CVE CVE-2019-1112
MSKB 4462224
MSKB 4464558
MSKB 4464543
MSKB 4018375
MSKB 4475514
MSKB 4464534
MSKB 4461539
XREF MSFT:MS19-4462224
XREF MSFT:MS19-4464558
XREF MSFT:MS19-4464543
XREF MSFT:MS19-4018375
XREF MSFT:MS19-4475514
XREF MSFT:MS19-4464534
XREF MSFT:MS19-4461539
Plugin Information
Published: 2019/07/09, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4464534
- C:\Program Files\Microsoft Office\Office16\osf.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4873.1000

Product : Microsoft Office 2016
KB : 4475514
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso99lwin32client.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4873.1000

Product : Microsoft Office 2016
KB : 4461539
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4873.1000
130913 - Security Updates for Microsoft Office Products (November 2019)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities :

- An information disclosure vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system.
(CVE-2019-1402)

- A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2019-1448)

- A security feature bypass vulnerability exists in the way that Office Click-to-Run (C2R) components handle a specially crafted file, which could lead to a standard user, any AppContainer sandbox, and Office LPAC Protected View to escalate privileges to SYSTEM.
(CVE-2019-1449)

- An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the users computer or data. (CVE-2019-1446)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4484152
-KB4484160
-KB4484148
-KB4484127
-KB4484113
-KB4484119

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.3802
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2019-1402
CVE CVE-2019-1446
CVE CVE-2019-1448
CVE CVE-2019-1449
MSKB 4484152
MSKB 4484160
MSKB 4484148
MSKB 4484127
MSKB 4484113
MSKB 4484119
XREF MSFT:MS19-4484152
XREF MSFT:MS19-4484160
XREF MSFT:MS19-4484148
XREF MSFT:MS19-4484127
XREF MSFT:MS19-4484113
XREF MSFT:MS19-4484119
Plugin Information
Published: 2019/11/12, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4484148
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4927.1000

Product : Microsoft Office 2016
KB : 4484113
- C:\Program Files\Common Files\Microsoft Shared\Office16\acecore.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4927.1000
171449 - Security Updates for Microsoft Word Products (February 2023)
-
Synopsis
The Microsoft Word Products are missing a security update.
Description
The Microsoft Word Products are missing a security update. It is, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002316
-KB5002323

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.6
EPSS Score
0.9115
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-21716
MSKB 5002316
MSKB 5002323
XREF MSFT:MS23-5002316
XREF MSFT:MS23-5002323
XREF IAVA:2023-A-0085-S
Plugin Information
Published: 2023/02/14, Modified: 2023/05/11
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5383.1000
178162 - Security Updates for Microsoft Word Products (July 2023)
-
Synopsis
The Microsoft Word Products are missing a security update.
Description
The Microsoft Word Products are missing a security update. It is, therefore, affected by a security feature bypass vulnerability. An attacker can exploit this and bypass the security feature and perform unauthorized actions compromising the integrity of the system/application.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002406
-KB5002411
Risk Factor
Critical
CVSS v3.0 Base Score
9.6 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.3 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.1
EPSS Score
0.0105
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-33150
MSKB 5002411
MSKB 5002406
XREF MSFT:MS23-5002411
XREF MSFT:MS23-5002406
XREF IAVA:2023-A-0348-S
Plugin Information
Published: 2023/07/11, Modified: 2023/08/11
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5404.1000
172527 - Security Updates for Outlook (March 2023)
-
Synopsis
The Microsoft Outlook application installed on the remote host is missing a security update.
Description
The Microsoft Outlook application installed on the remote host is missing a security update. It is, therefore, affected by an elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002265
-KB5002254

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.8
EPSS Score
0.9364
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-23397
MSKB 5002265
MSKB 5002254
XREF MSFT:MS23-5002265
XREF MSFT:MS23-5002254
XREF CISA-KNOWN-EXPLOITED:2023/04/04
XREF IAVA:2023-A-0140-S
Plugin Information
Published: 2023/03/14, Modified: 2023/06/16
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5387.1000
65057 - Insecure Windows Service Permissions
-
Synopsis
At least one improperly configured Windows service may have a privilege escalation vulnerability.
Description
At least one Windows service executable with insecure permissions was detected on the remote host. Services configured to use an executable with weak permissions are vulnerable to privilege escalation attacks.
An unprivileged user could modify or overwrite the executable with arbitrary code, which would be executed the next time the service is started. Depending on the user that the service runs as, this could result in privilege escalation.

This plugin checks if any of the following groups have permissions to modify executable files that are started by Windows services :

- Everyone
- Users
- Domain Users
- Authenticated Users
See Also
Solution
Ensure that the Everyone, Users, Domain Users and Authenticated Users groups do not have permissions to modify or write service executables. Additionally, ensure these groups do not have Full Control permission to any directories that contain service executables.
Risk Factor
High
CVSS v3.0 Base Score
8.4 (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
Plugin Information
Published: 2013/03/06, Modified: 2025/03/14
Plugin Output

tcp/445/cifs


Path : d:\nexsus\nexsus_patch\nexcommserver\nexsus.commserver.exe
Used by services : Nexsus Communication Server
File write allowed for groups : Users (S-1-5-32-545)
Full control of directory allowed for groups : Users (S-1-5-32-545)

Path : d:\nexsus\nexsus_patch\nexsus.maxdial.emailservice\nexsusemailservice.exe
Used by services : NexsusEmailService
File write allowed for groups : Users (S-1-5-32-545)
Full control of directory allowed for groups : Users (S-1-5-32-545)

Path : d:\nexsus\nexsus_patch\nexsus.maxdial.voicelogservice_web_lkp\nexsus.callbalancel.voicelogservice.exe
Used by services : CallBalanceClopsVoiceLogService_LKP
File write allowed for groups : Users (S-1-5-32-545)
Full control of directory allowed for groups : Users (S-1-5-32-545)

Path : d:\nexsus\nexsus_services\nexsus.maxdial.userstatusvalidator_web\nexsus.maxdial.userstatusvalidator.exe
Used by services : Nexsus.UserStatusValidatorWeb
File write allowed for groups : Users (S-1-5-32-545)
Full control of directory allowed for groups : Users (S-1-5-32-545)

Bad Shares :
232617 - KB5053596: Windows 10 version 1809 / Windows Server 2019 Security Update (March 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5053596. It is, therefore, affected by multiple vulnerabilities

- Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network. (CVE-2025-26645)

- Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. (CVE-2025-24035, CVE-2025-24045)

- ** UNSUPPORTED WHEN ASSIGNED ** A privilege escalation vulnerability in CxUIUSvc64.exe and CxUIUSvc32.exe of Synaptics audio drivers allows a local authorized attacker to load a DLL in a privileged process. Out of an abundance of caution, this CVE ID is being assigned to better serve our customers and ensure all who are still running this product understand that the product is End-of-Life and should be removed. For more information on this, refer to the CVE Record's reference information. (CVE-2024-9157)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5053596
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
9.5
EPSS Score
0.5654
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-9157
CVE CVE-2025-21180
CVE CVE-2025-21247
CVE CVE-2025-24035
CVE CVE-2025-24044
CVE CVE-2025-24045
CVE CVE-2025-24046
CVE CVE-2025-24048
CVE CVE-2025-24050
CVE CVE-2025-24051
CVE CVE-2025-24054
CVE CVE-2025-24055
CVE CVE-2025-24056
CVE CVE-2025-24059
CVE CVE-2025-24061
CVE CVE-2025-24064
CVE CVE-2025-24066
CVE CVE-2025-24067
CVE CVE-2025-24071
CVE CVE-2025-24072
CVE CVE-2025-24984
CVE CVE-2025-24985
CVE CVE-2025-24987
CVE CVE-2025-24988
CVE CVE-2025-24991
CVE CVE-2025-24992
CVE CVE-2025-24993
CVE CVE-2025-24995
CVE CVE-2025-24996
CVE CVE-2025-25008
CVE CVE-2025-26633
CVE CVE-2025-26645
MSKB 5053596
XREF MSFT:MS25-5053596
XREF IAVA:2025-A-0181-S
XREF IAVA:2025-A-0182-S
XREF CISA-KNOWN-EXPLOITED:2025/05/08
XREF CISA-KNOWN-EXPLOITED:2025/04/01
XREF CWE:23
XREF CWE:41
XREF CWE:59
XREF CWE:73
XREF CWE:122
XREF CWE:125
XREF CWE:126
XREF CWE:190
XREF CWE:200
XREF CWE:284
XREF CWE:416
XREF CWE:532
XREF CWE:591
XREF CWE:681
XREF CWE:693
XREF CWE:707
Plugin Information
Published: 2025/03/11, Modified: 2025/09/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5053596

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.6893
Should be : 10.0.17763.7009
234046 - KB5055519: Windows 10 version 1809 / Windows Server 2019 Security Update (April 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5055519. It is, therefore, affected by multiple vulnerabilities

- Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network. (CVE-2025-26687)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-27481)
- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges. (CVE-2025-27740)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5055519
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.2827
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-21174
CVE CVE-2025-21191
CVE CVE-2025-21197
CVE CVE-2025-21203
CVE CVE-2025-21204
CVE CVE-2025-21205
CVE CVE-2025-21221
CVE CVE-2025-21222
CVE CVE-2025-24058
CVE CVE-2025-24060
CVE CVE-2025-24073
CVE CVE-2025-24074
CVE CVE-2025-26635
CVE CVE-2025-26637
CVE CVE-2025-26640
CVE CVE-2025-26641
CVE CVE-2025-26644
CVE CVE-2025-26647
CVE CVE-2025-26648
CVE CVE-2025-26652
CVE CVE-2025-26663
CVE CVE-2025-26664
CVE CVE-2025-26665
CVE CVE-2025-26666
CVE CVE-2025-26667
CVE CVE-2025-26668
CVE CVE-2025-26669
CVE CVE-2025-26670
CVE CVE-2025-26671
CVE CVE-2025-26672
CVE CVE-2025-26673
CVE CVE-2025-26674
CVE CVE-2025-26676
CVE CVE-2025-26678
CVE CVE-2025-26679
CVE CVE-2025-26680
CVE CVE-2025-26686
CVE CVE-2025-26687
CVE CVE-2025-26688
CVE CVE-2025-27467
CVE CVE-2025-27469
CVE CVE-2025-27470
CVE CVE-2025-27471
CVE CVE-2025-27473
CVE CVE-2025-27474
CVE CVE-2025-27476
CVE CVE-2025-27477
CVE CVE-2025-27478
CVE CVE-2025-27479
CVE CVE-2025-27480
CVE CVE-2025-27481
CVE CVE-2025-27482
CVE CVE-2025-27483
CVE CVE-2025-27484
CVE CVE-2025-27485
CVE CVE-2025-27486
CVE CVE-2025-27487
CVE CVE-2025-27491
CVE CVE-2025-27727
CVE CVE-2025-27730
CVE CVE-2025-27731
CVE CVE-2025-27732
CVE CVE-2025-27733
CVE CVE-2025-27735
CVE CVE-2025-27736
CVE CVE-2025-27737
CVE CVE-2025-27738
CVE CVE-2025-27739
CVE CVE-2025-27740
CVE CVE-2025-27741
CVE CVE-2025-27742
CVE CVE-2025-29809
CVE CVE-2025-29810
CVE CVE-2025-29824
MSKB 5055519
XREF CISA-KNOWN-EXPLOITED:2025/04/29
XREF MSFT:MS25-5055519
XREF IAVA:2025-A-0256-S
XREF IAVA:2025-A-0255-S
XREF CWE:20
XREF CWE:59
XREF CWE:121
XREF CWE:122
XREF CWE:125
XREF CWE:126
XREF CWE:200
XREF CWE:284
XREF CWE:345
XREF CWE:367
XREF CWE:400
XREF CWE:410
XREF CWE:415
XREF CWE:416
XREF CWE:591
XREF CWE:667
XREF CWE:693
XREF CWE:787
XREF CWE:822
XREF CWE:908
XREF CWE:922
XREF CWE:1039
XREF CWE:1390
Plugin Information
Published: 2025/04/08, Modified: 2025/09/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5055519

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.6893
Should be : 10.0.17763.7131
235845 - KB5058392: Windows 10 version 1809 / Windows Server 2019 Security Update (May 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5058392. It is, therefore, affected by multiple vulnerabilities

- Heap-based buffer overflow in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. (CVE-2025-29967)

- Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. (CVE-2025-29830, CVE-2025-29958, CVE-2025-29959)

- Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. (CVE-2025-29832, CVE-2025-29835, CVE-2025-29836, CVE-2025-29960, CVE-2025-29961)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5058392
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
8.1
EPSS Score
0.2127
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/05/13, Modified: 2025/10/29
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5058392

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.6893
Should be : 10.0.17763.7309
238080 - KB5060531: Windows 10 version 1809 / Windows Server 2019 Security Update (June 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5060531. It is, therefore, affected by multiple vulnerabilities

- Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. (CVE-2025-33066)

- Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.
(CVE-2025-33073)

- Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
(CVE-2025-32712)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5060531
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.7
EPSS Score
0.5119
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-3052
CVE CVE-2025-24065
CVE CVE-2025-24068
CVE CVE-2025-24069
CVE CVE-2025-32712
CVE CVE-2025-32713
CVE CVE-2025-32714
CVE CVE-2025-32715
CVE CVE-2025-32716
CVE CVE-2025-32718
CVE CVE-2025-32719
CVE CVE-2025-32720
CVE CVE-2025-32721
CVE CVE-2025-32722
CVE CVE-2025-32724
CVE CVE-2025-32725
CVE CVE-2025-33050
CVE CVE-2025-33052
CVE CVE-2025-33053
CVE CVE-2025-33055
CVE CVE-2025-33056
CVE CVE-2025-33057
CVE CVE-2025-33058
CVE CVE-2025-33059
CVE CVE-2025-33060
CVE CVE-2025-33061
CVE CVE-2025-33062
CVE CVE-2025-33063
CVE CVE-2025-33064
CVE CVE-2025-33065
CVE CVE-2025-33066
CVE CVE-2025-33067
CVE CVE-2025-33068
CVE CVE-2025-33070
CVE CVE-2025-33071
CVE CVE-2025-33073
CVE CVE-2025-33075
CVE CVE-2025-47160
MSKB 5060531
XREF MSFT:MS25-5060531
XREF IAVA:2025-A-0428-S
XREF IAVA:2025-A-0417-S
XREF CISA-KNOWN-EXPLOITED:2025/11/10
XREF CISA-KNOWN-EXPLOITED:2025/07/01
XREF CWE:59
XREF CWE:73
XREF CWE:122
XREF CWE:125
XREF CWE:126
XREF CWE:190
XREF CWE:269
XREF CWE:284
XREF CWE:400
XREF CWE:416
XREF CWE:476
XREF CWE:693
XREF CWE:908
Exploitable With
Core Impact (true) Metasploit (true)
Plugin Information
Published: 2025/06/10, Modified: 2025/10/21
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5060531

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.6893
Should be : 10.0.17763.7434
241548 - KB5062557: Windows 10 version 1809 / Windows Server 2019 Security Update (July 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5062557. It is, therefore, affected by multiple vulnerabilities

- Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally.
(CVE-2025-49659)

- Improper link resolution before file access ('link following') in Windows Update Service allows an authorized attacker to elevate privileges locally. (CVE-2025-48799)

- Improper link resolution before file access ('link following') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally. (CVE-2025-48820)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5062557
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.1
EPSS Score
0.0055
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-36350
CVE CVE-2025-36357
CVE CVE-2025-47159
CVE CVE-2025-47971
CVE CVE-2025-47972
CVE CVE-2025-47973
CVE CVE-2025-47975
CVE CVE-2025-47976
CVE CVE-2025-47980
CVE CVE-2025-47981
CVE CVE-2025-47982
CVE CVE-2025-47984
CVE CVE-2025-47985
CVE CVE-2025-47986
CVE CVE-2025-47987
CVE CVE-2025-47991
CVE CVE-2025-47996
CVE CVE-2025-47998
CVE CVE-2025-47999
CVE CVE-2025-48000
CVE CVE-2025-48001
CVE CVE-2025-48003
CVE CVE-2025-48799
CVE CVE-2025-48800
CVE CVE-2025-48803
CVE CVE-2025-48804
CVE CVE-2025-48805
CVE CVE-2025-48806
CVE CVE-2025-48808
CVE CVE-2025-48811
CVE CVE-2025-48814
CVE CVE-2025-48815
CVE CVE-2025-48816
CVE CVE-2025-48817
CVE CVE-2025-48818
CVE CVE-2025-48819
CVE CVE-2025-48820
CVE CVE-2025-48821
CVE CVE-2025-48822
CVE CVE-2025-48823
CVE CVE-2025-48824
CVE CVE-2025-49657
CVE CVE-2025-49658
CVE CVE-2025-49659
CVE CVE-2025-49660
CVE CVE-2025-49661
CVE CVE-2025-49663
CVE CVE-2025-49664
CVE CVE-2025-49665
CVE CVE-2025-49666
CVE CVE-2025-49667
CVE CVE-2025-49668
CVE CVE-2025-49669
CVE CVE-2025-49670
CVE CVE-2025-49671
CVE CVE-2025-49672
CVE CVE-2025-49673
CVE CVE-2025-49674
CVE CVE-2025-49675
CVE CVE-2025-49676
CVE CVE-2025-49678
CVE CVE-2025-49679
CVE CVE-2025-49680
CVE CVE-2025-49681
CVE CVE-2025-49683
CVE CVE-2025-49684
CVE CVE-2025-49685
CVE CVE-2025-49686
CVE CVE-2025-49687
CVE CVE-2025-49688
CVE CVE-2025-49689
CVE CVE-2025-49690
CVE CVE-2025-49691
CVE CVE-2025-49716
CVE CVE-2025-49721
CVE CVE-2025-49722
CVE CVE-2025-49723
CVE CVE-2025-49724
CVE CVE-2025-49725
CVE CVE-2025-49726
CVE CVE-2025-49727
CVE CVE-2025-49729
CVE CVE-2025-49730
CVE CVE-2025-49732
CVE CVE-2025-49733
CVE CVE-2025-49740
CVE CVE-2025-49742
CVE CVE-2025-49744
CVE CVE-2025-49753
CVE CVE-2025-49760
CVE CVE-2025-55230
CVE CVE-2025-55231
MSKB 5062557
XREF MSFT:MS25-5062557
XREF IAVA:2025-A-0507-S
XREF IAVA:2025-A-0506-S
XREF IAVA:2025-A-0631-S
XREF CWE:20
XREF CWE:23
XREF CWE:59
XREF CWE:73
XREF CWE:122
XREF CWE:125
XREF CWE:126
XREF CWE:190
XREF CWE:191
XREF CWE:197
XREF CWE:200
XREF CWE:284
XREF CWE:306
XREF CWE:326
XREF CWE:349
XREF CWE:353
XREF CWE:362
XREF CWE:367
XREF CWE:400
XREF CWE:415
XREF CWE:416
XREF CWE:476
XREF CWE:591
XREF CWE:693
XREF CWE:787
XREF CWE:820
XREF CWE:822
XREF CWE:843
XREF CWE:862
Plugin Information
Published: 2025/07/08, Modified: 2025/10/29
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5062557

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.6893
Should be : 10.0.17763.7558
261799 - KB5065428: Windows 10 version 1809 / Windows Server 2019 Security Update (September 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5065428. It is, therefore, affected by multiple vulnerabilities

- SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vulnerabilities could perform relay attacks and make the users subject to elevation of privilege attacks. The SMB Server already supports mechanisms for hardening against relay attacks: SMB Server signing SMB Server Extended Protection for Authentication (EPA) Microsoft is releasing this CVE to provide customers with audit capabilities to help them to assess their environment and to identify any potential device or software incompatibility issues before deploying SMB Server hardening measures that protect against relay attacks. If you have not already enabled SMB Server hardening measures, we advise customers to take the following actions to be protected from these relay attacks:
Assess your environment by utilizing the audit capabilities that we are exposing in the September 2025 security updates. See Support for Audit Events to deploy SMB Server HardeningSMB Server Signing & SMB Server EPA. Adopt appropriate SMB Server hardening measures. (CVE-2025-55234)

- Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally. (CVE-2025-49734)

- Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. (CVE-2025-53796, CVE-2025-53797, CVE-2025-53798, CVE-2025-53806)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5065428
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.1
EPSS Score
0.0073
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/09/09, Modified: 2025/10/29
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5065428

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.6893
Should be : 10.0.17763.7786
274782 - KB5068791: Windows 10 version 1809 / Windows Server 2019 Security Update (November 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5068791. It is, therefore, affected by multiple vulnerabilities

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-60724, CVE-2025-60714, CVE-2025-60715, CVE-2025-62452)

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information.
(CVE-2025-59509, CVE-2025-59513, CVE-2025-60706, CVE-2025-62208, CVE-2025-62209)

- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges.
(CVE-2025-59505, CVE-2025-59506, CVE-2025-59507, CVE-2025-59508, CVE-2025-59511, CVE-2025-59512, CVE-2025-59514, CVE-2025-59515, CVE-2025-60703, CVE-2025-60704, CVE-2025-60705, CVE-2025-60707, CVE-2025-60709, CVE-2025-60713, CVE-2025-60716, CVE-2025-60717, CVE-2025-60719, CVE-2025-60720, CVE-2025-62213, CVE-2025-62215, CVE-2025-62217)


Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5068791
Risk Factor
Critical
CVSS v3.0 Base Score
7.0 (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.0009
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/11/11, Modified: 2025/11/14
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5068791

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.6893
Should be : 10.0.17763.8024
277987 - KB5071544: Windows 10 version 1809 / Windows Server 2019 Security Update (December 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5071544. It is, therefore, affected by multiple vulnerabilities

- Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. (CVE-2025-62549)

- Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. (CVE-2025-62457)

- Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. (CVE-2025-62458)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5071544
Risk Factor
Critical
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
8.1
EPSS Score
0.0821
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/12/09, Modified: 2025/12/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5071544

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.6893
Should be : 10.0.17763.8146
63420 - MS13-002: Vulnerabilities in Microsoft XML Core Services Could Allow Remote Code Execution (2756145)
-
Synopsis
Arbitrary code can be executed on the remote host through Microsoft XML Core Services.
Description
The version of Microsoft XML Core Services installed on the remote Windows host is affected by multiple code execution vulnerabilities when visiting a specially crafted web page using Internet Explorer.
See Also
Solution
Microsoft has released a set of patches for Windows XP, 2003, Vista, 2008, 7, and 2008 R2, 8, 2012, Office 2003, 2007, Word Viewer, Office Compatibility Pack, Expression Web Service, Expression Web 2, SharePoint Server 2007 and Groove Server 2007.
Risk Factor
High
VPR Score
6.7
EPSS Score
0.6508
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
BID 57116
BID 57122
CVE CVE-2013-0006
CVE CVE-2013-0007
MSKB 2687497
MSKB 2687499
MSKB 2757638
MSKB 2758694
MSKB 2758696
MSKB 2760574
XREF MSFT:MS13-002
XREF IAVA:2013-A-0004
Plugin Information
Published: 2013/01/09, Modified: 2018/11/15
Plugin Output

tcp/445/cifs



- C:\Program Files (x86)\Common Files\Microsoft Shared\Office11\Msxml5.dll has not been patched.
Remote version : 5.20.1072.0
Should be : 5.20.1099.0
85350 - MS15-081: Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (3080790)
-
Synopsis
The remote Windows host is affected by multiple remote code execution vulnerabilities.
Description
The remote Windows host has a version of Microsoft Office, Word, Word Viewer, Excel, PowerPoint, Visio, SharePoint Server, Microsoft Office Compatibility Pack, Microsoft Word Web Apps, or Microsoft Office Web Apps installed that is affected by multiple remote code execution vulnerabilities :

- Multiple remote code execution vulnerabilities exist due to improper handling of objects in memory. A remote attacker can exploit these vulnerabilities by convincing a user to open a specially crafted Office file, resulting in the execution of arbitrary code in the context of the current user. (CVE-2015-1642, CVE-2015-2467, CVE-2015-2468, CVE-2015-2469, CVE-2015-2477)

- An information disclosure vulnerability exists when files at a medium integrity level become accessible to Internet Explorer running in Enhanced Protection Mode (EPM). An attacker can exploit this vulnerability by leveraging another vulnerability to execute code in IE with EPM, and then executing Excel, Notepad, PowerPoint, Visio, or Word using an unsafe command line parameter.
(CVE-2015-2423)

- A remote code execution vulnerability exists due a failure to properly validate templates. A remote attacker can exploit this vulnerability by convincing a user to open a specially crafted template file, resulting in the execution of arbitrary code in the context of the current user. (CVE-2015-2466)

- A remote code execution vulnerability exists when Office decreases an integer value beyond its intended minimum value. A remote attacker can exploit this vulnerability by convincing a user to open a specially crafted Office file, resulting in the execution of arbitrary code in the context of the current user. (CVE-2015-2470)
See Also
Solution
Microsoft has released a set of patches for Office 2007, 2010, 2013, 2013 RT, 2016, SharePoint Server 2010, SharePoint Server 2013, Microsoft Office Compatibility Pack, Microsoft Word Web Apps 2010, and Microsoft Office Web Apps 2013.
Risk Factor
High
VPR Score
8.9
EPSS Score
0.7288
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
BID 76200
BID 76202
BID 76204
BID 76206
BID 76212
BID 76214
BID 76217
BID 76219
CVE CVE-2015-1642
CVE CVE-2015-2423
CVE CVE-2015-2466
CVE CVE-2015-2467
CVE CVE-2015-2468
CVE CVE-2015-2469
CVE CVE-2015-2470
CVE CVE-2015-2477
MSKB 2553313
MSKB 2596650
MSKB 2598244
MSKB 2687409
MSKB 2837610
MSKB 2920691
MSKB 2920708
MSKB 2965280
MSKB 2965310
MSKB 2986254
MSKB 3039734
MSKB 3039798
MSKB 3054816
MSKB 3054858
MSKB 3054876
MSKB 3054888
MSKB 3054929
MSKB 3054960
MSKB 3054974
MSKB 3054991
MSKB 3054992
MSKB 3055003
MSKB 3055029
MSKB 3055030
MSKB 3055033
MSKB 3055037
MSKB 3055039
MSKB 3055044
MSKB 3055051
MSKB 3055052
MSKB 3055053
MSKB 3055054
MSKB 3085538
XREF MSFT:MS15-081
XREF IAVA:2015-A-0194-S
XREF CISA-KNOWN-EXPLOITED:2022/03/24
Plugin Information
Published: 2015/08/12, Modified: 2023/02/16
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4288.1000
85879 - MS15-099: Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (3089664)
-
Synopsis
The remote Windows host is affected by multiple remote code execution vulnerabilities.
Description
The remote Windows host has a version of Microsoft Office, Excel, Excel Viewer, SharePoint Server, Microsoft Office Compatibility Pack, Microsoft Office Web Apps, and/or Microsoft SharePoint Foundation installed that is affected by one or more of the following vulnerabilities :

- Multiple remote code execution vulnerabilities exist due to improper handling of objects in memory. A remote attacker can exploit these vulnerabilities by convincing a user to open a specially crafted file in Microsoft Office, resulting in execution of arbitrary code in the context of the current user. (CVE-2015-2520, CVE-2015-2521, CVE-2015-2523)

- A cross-site scripting vulnerability exists in SharePoint due to improper sanitization of user-supplied web requests. A remote attacker can exploit this vulnerability, via a specially crafted web request, to execute arbitrary script code in the context of the current user. (CVE-2015-2522)

- A remote code execution vulnerability exists in Microsoft Office due to improper handling of malformed graphics images. A remote attacker can exploit this vulnerability by convincing a user to open a file or visit a website containing a specially crafted EPS image binary, resulting in execution of arbitrary code in the context of the current user. (CVE-2015-2545)
See Also
Solution
Microsoft has released a set of patches for Office 2007, 2010, 2013, 2013 RT, 2016, SharePoint Server 2013, Microsoft Office Compatibility Pack, and Microsoft Office Web Apps 2013.
Risk Factor
High
VPR Score
9.6
EPSS Score
0.9345
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
BID 76561
BID 76562
BID 76564
BID 76588
BID 76667
CVE CVE-2015-2520
CVE CVE-2015-2521
CVE CVE-2015-2522
CVE CVE-2015-2523
CVE CVE-2015-2545
MSKB 3054813
MSKB 3054932
MSKB 3054965
MSKB 3054987
MSKB 3085635
MSKB 3054993
MSKB 3054995
MSKB 3085483
MSKB 3085487
MSKB 3085501
MSKB 3085502
MSKB 3085526
MSKB 3085543
MSKB 2920693
XREF MSFT:MS15-099
XREF IAVA:2015-A-0214
XREF EDB-ID:38214
XREF EDB-ID:38215
XREF EDB-ID:38216
XREF CISA-KNOWN-EXPLOITED:2022/03/24
Exploitable With
Core Impact (true)
Plugin Information
Published: 2015/09/09, Modified: 2022/03/08
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 3085635
- C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\epsimp32.flt has not been patched.
Remote version : 2012.1600.4266.1001
Should be : 2012.1600.4300.1002

Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4288.1000
86374 - MS15-110: Security Updates for Microsoft Office to Address Remote Code Execution (3089440)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host has a version of Microsoft Office, Excel, Excel Viewer, SharePoint Server, Microsoft Office Compatibility Pack, or Microsoft Office Web Apps installed that is affected by multiple vulnerabilities :

- Multiple remote code execution vulnerabilities exist due to improper handling of objects in memory. A remote attacker can exploit these vulnerabilities by convincing a user to open a specially crafted file, resulting in execution of arbitrary code in the context of the current user. (CVE-2015-2555, CVE-2015-2557, CVE-2015-2558)

- An information disclosure vulnerability exists in the SharePoint InfoPath Forms Services due to improper parsing of document type definitions (DTD) in XML files.
A remote attacker can exploit this, via a crafted XML file, to browse the contents of arbitrary files on a SharePoint server. (CVE-2015-2556)

- A cross-site scripting vulnerability exists in Office Web Apps Server due to improper sanitization of crafted requests before returning it to the user. A remote attacker can exploit this to run arbitrary script code in the user's browser session. (CVE-2015-6037)

- A security feature bypass vulnerability exists in SharePoint due to improper enforcement of permission levels for applications or users. This allows Office Marketplace to inject JavaScript code that will persist in a SharePoint page. A remote attacker can exploit this to conduct a cross-site scripting attack, resulting in execution of arbitrary code in the user's browser session. (CVE-2015-6039)
See Also
Solution
Microsoft has released a set of patches for Office 2007, 2010, 2013, 2013 RT, 2016; SharePoint Server 2007, 2010, 2013; Microsoft Office Compatibility Pack SP3; Microsoft Excel Viewer; and Microsoft Office Web Apps 2010, 2013.
Risk Factor
High
VPR Score
6.7
EPSS Score
0.4303
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
BID 76988
BID 76996
BID 76997
BID 77003
BID 77009
BID 77011
CVE CVE-2015-2555
CVE CVE-2015-2556
CVE CVE-2015-2557
CVE CVE-2015-2558
CVE CVE-2015-6037
CVE CVE-2015-6039
MSKB 2553405
MSKB 2596670
MSKB 2920693
MSKB 3054994
MSKB 3085514
MSKB 3085520
MSKB 3085542
MSKB 3085567
MSKB 3085568
MSKB 3085571
MSKB 3085582
MSKB 3085583
MSKB 3085595
MSKB 3085596
MSKB 3085609
MSKB 3085615
MSKB 3085618
MSKB 3085619
XREF MSFT:MS15-110
Plugin Information
Published: 2015/10/13, Modified: 2018/07/30
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4288.1000
86823 - MS15-116: Security Update for Microsoft Office to Address Remote Code Execution (3104540)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host has a version of Microsoft Office, Access, Excel, InfoPath, OneNote, PowerPoint, Project, Publisher, Visio, Word, Excel Viewer, Word Viewer, SharePoint Server, Office Compatibility Pack, Office Web Apps, Skype for Business, or Lync installed that is affected by multiple vulnerabilities :

- Multiple remote code execution vulnerabilities exist due to improper handling of objects in memory. A remote attacker can exploit these vulnerabilities by convincing a user to open a specially crafted Office file, resulting in execution of arbitrary code in the context of the current user. (CVE-2015-6038, CVE-2015-6091, CVE-2015-6092, CVE-2015-6093, CVE-2015-6094)

- An elevation of privilege vulnerability exists when an attacker instantiates an affected Office application via a COM control. An attacker who successfully exploits this vulnerability can gain elevated privileges and break out of the Internet Explorer sandbox.
(CVE-2015-2503)
See Also
Solution
Microsoft has released a set of patches for Office 2007, 2010, 2013, 2013 RT, 2016; SharePoint Server 2007, 2010, 2013; Office Compatibility Pack, Excel Viewer, Word Viewer, Office Web Apps 2010 and 2013, and Lync 2013 and 2016.
Risk Factor
High
VPR Score
8.9
EPSS Score
0.4348
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
BID 77485
BID 77489
BID 77490
BID 77491
BID 77492
BID 77493
CVE CVE-2015-2503
CVE CVE-2015-6038
CVE CVE-2015-6091
CVE CVE-2015-6092
CVE CVE-2015-6093
CVE CVE-2015-6094
MSKB 2596614
MSKB 2596770
MSKB 2687406
MSKB 2817478
MSKB 2878230
MSKB 2880506
MSKB 2889915
MSKB 2899473
MSKB 2899516
MSKB 2910978
MSKB 2920680
MSKB 2920698
MSKB 2920726
MSKB 2965313
MSKB 3054793
MSKB 3054978
MSKB 3085477
MSKB 3085511
MSKB 3085548
MSKB 3085551
MSKB 3085552
MSKB 3085561
MSKB 3085584
MSKB 3085594
MSKB 3085614
MSKB 3085634
MSKB 3101359
MSKB 3101360
MSKB 3101364
MSKB 3101365
MSKB 3101367
MSKB 3101370
MSKB 3101371
MSKB 3101496
MSKB 3101499
MSKB 3101506
MSKB 3101507
MSKB 3101509
MSKB 3101510
MSKB 3101512
MSKB 3101513
MSKB 3101514
MSKB 3101521
MSKB 3101525
MSKB 3101526
MSKB 3101529
MSKB 3101533
MSKB 3101543
MSKB 3101544
MSKB 3101553
MSKB 3101554
MSKB 3101555
MSKB 3101558
MSKB 3101559
MSKB 3101560
MSKB 3101564
XREF MSFT:MS15-116
XREF IAVA:2015-A-0272-S
Plugin Information
Published: 2015/11/10, Modified: 2023/02/17
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4300.1001

Product : OneNote 2016
- C:\Program Files\Microsoft Office\Office16\OneNote.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4300.1001

Product : PowerPoint 2016
- C:\Program Files\Microsoft Office\Office16\ppcore.dll has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4300.1001

Product : Publisher 2016
- C:\Program Files\Microsoft Office\Office16\Mspub.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4300.1000

Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4300.1001
87260 - MS15-131: Security Update for Microsoft Office to Address Remote Code Execution (3116111)
-
Synopsis
The remote Windows host is affected by multiple remote code execution vulnerabilities.
Description
The remote Windows host has a version of Microsoft Office, Word, Word Viewer, Excel, Excel Viewer, or Microsoft Office Compatibility Pack installed that is affected by multiple remote code execution vulnerabilities :

- Multiple memory corruption issues exist due to improper handling of objects in memory. A remote attacker can exploit these issues by convincing a user to open a specially crafted file in an affected version of Office, resulting in the execution of arbitrary code in the context of the current user. (CVE-2015-6040, CVE-2015-6118, CVE-2015-6122, CVE-2015-6124, CVE-2015-6177)

- A remote code execution vulnerability exists due to improper parsing of email messages. A remote attacker can exploit this vulnerability by convincing a user to open or preview a specially crafted email message, resulting in the execution of arbitrary code in the context of the current user. (CVE-2015-6172)
See Also
Solution
Microsoft has released a set of patches for Office 2007, 2010, 2013, 2013 RT, 2016, Word, Word Viewer, Excel, Excel Viewer, and Microsoft Office Compatibility Pack.
Risk Factor
High
VPR Score
8.9
EPSS Score
0.3755
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
BID 78543
BID 78546
BID 78547
BID 78548
BID 78549
BID 78550
CVE CVE-2015-6040
CVE CVE-2015-6118
CVE CVE-2015-6122
CVE CVE-2015-6124
CVE CVE-2015-6172
CVE CVE-2015-6177
MSKB 3085528
MSKB 3085549
MSKB 3101532
MSKB 3114342
MSKB 3114382
MSKB 3114403
MSKB 3114415
MSKB 3114422
MSKB 3114425
MSKB 3114431
MSKB 3114433
MSKB 3114457
MSKB 3114458
MSKB 3114479
XREF MSFT:MS15-131
XREF IAVA:2015-A-0300-S
Plugin Information
Published: 2015/12/08, Modified: 2023/02/17
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4312.1001
87882 - MS16-004: Security Update for Microsoft Office to Address Remote Code Execution (3124585)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host has a version of Microsoft Office, Word, Word Viewer, Excel, Excel Viewer, PowerPoint, Visio, SharePoint, Visual Basic, or Microsoft Office Compatibility Pack installed that is affected by multiple vulnerabilities :

- Multiple cross-site scripting vulnerabilities exist in Microsoft SharePoint due to improper enforcement of Access Control Policy (ACP) configuration settings. A remote attacker can exploit these vulnerabilities, via a specially crafted request, to execute arbitrary script code in a user's browser session. (CVE-2015-6117, CVE-2016-0011)

- Multiple remote code execution vulnerabilities exist in Microsoft Office due to improper handling of objects in memory. An attacker can exploit these vulnerabilities by convincing a user to open a specially crafted file in Microsoft Office, resulting in execution of arbitrary code in the context of the current user. (CVE-2016-0010, CVE-2016-0035)

- An information disclosure vulnerability exists in Microsoft Office due to a failure to use the Address Space Layout Randomization (ASLR) security feature. An attacker can exploit this to predict memory offsets of specific instructions in a call stack. (CVE-2016-0012)
See Also
Solution
Microsoft has released a set of patches for Office 2007, 2010, 2013, 2013 RT, 2016, Word, Word Viewer, Excel, Excel Viewer, PowerPoint, Visio, SharePoint Server 2013, SharePoint Foundation 2013, Microsoft Office Compatibility Pack, and Visual Basic 6.0 Runtime.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.5962
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
BID 80028
BID 80029
BID 80030
BID 80031
BID 80032
CVE CVE-2015-6117
CVE CVE-2016-0010
CVE CVE-2016-0011
CVE CVE-2016-0012
CVE CVE-2016-0035
MSKB 2881067
MSKB 3114541
MSKB 3114540
MSKB 3114429
MSKB 3114421
MSKB 3114549
MSKB 2881029
MSKB 3114553
MSKB 3114554
MSKB 3114564
MSKB 3114396
MSKB 3114402
MSKB 3114557
MSKB 3039794
MSKB 3114486
MSKB 3114504
MSKB 3114482
MSKB 3114489
MSKB 3114494
MSKB 2920727
MSKB 3114527
MSKB 3114520
MSKB 3114518
MSKB 3114511
MSKB 3114526
MSKB 3114546
MSKB 3114547
MSKB 3114569
MSKB 3114503
MSKB 3096896
XREF MSFT:MS16-004
XREF IAVA:2016-A-0011-S
Plugin Information
Published: 2016/01/12, Modified: 2023/02/17
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4324.1001

Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4324.1000
88647 - MS16-015: Security Update for Microsoft Office to Address Remote Code Execution (3134226)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host has a version of Microsoft Office, Word, Word Viewer, Excel, Excel Viewer, SharePoint, Microsoft Office Compatibility Pack, or Office Web Apps installed that is affected by multiple vulnerabilities :

- Multiple remote code execution vulnerabilities exist due to improper handling of objects in memory. A remote attacker can exploit these vulnerabilities by convincing a user to open a specially crafted file in Microsoft Office, resulting in the execution of arbitrary code in the context of the current user. (CVE-2016-0022, CVE-2016-0052, CVE-2016-0053, CVE-2016-0054, CVE-2016-0055, CVE-2015-0056)

- A cross-site scripting vulnerability exists in SharePoint due to improper sanitization of specially crafted web requests. An authenticated, remote attacker can exploit this, via a specially crafted web request, to execute arbitrary script code in a user's browser session. (CVE-2016-0039)
See Also
Solution
Microsoft has released a set of patches for Office 2007, 2010, 2013, 2013 RT, and 2016; Word, Word Viewer, Excel, Excel Viewer; SharePoint Server 2007, 2010, and 2013; SharePoint Foundation 2013, Microsoft Office Compatibility Pack, and Office Web Apps.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.9
EPSS Score
0.3152
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
BID 82508
BID 82512
BID 82652
BID 82654
BID 82657
BID 82660
BID 82787
CVE CVE-2016-0022
CVE CVE-2016-0039
CVE CVE-2016-0052
CVE CVE-2016-0053
CVE CVE-2016-0054
CVE CVE-2016-0055
CVE CVE-2016-0056
MSKB 3039768
MSKB 3114335
MSKB 3114338
MSKB 3114401
MSKB 3114407
MSKB 3114432
MSKB 3114481
MSKB 3114548
MSKB 3114698
MSKB 3114702
MSKB 3114724
MSKB 3114733
MSKB 3114734
MSKB 3114741
MSKB 3114742
MSKB 3114745
MSKB 3114747
MSKB 3114748
MSKB 3114752
MSKB 3114755
MSKB 3104759
MSKB 3114773
XREF MSFT:MS16-015
XREF IAVA:2016-A-0043-S
Plugin Information
Published: 2016/02/09, Modified: 2023/02/17
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4339.1000

Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4339.1000
89752 - MS16-029: Security Update for Microsoft Office to Address Remote Code Execution (3141806)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host has a version of Microsoft Office, Office Compatibility Pack, Office Web Apps, Microsoft SharePoint, Microsoft Word, or Word Viewer installed that is affected by multiple vulnerabilities :

- Multiple remote code execution vulnerabilities exist in Microsoft Office software due to improper handling of objects in memory. An attacker can exploit these, by convincing a user to open a specially crafted file, to execute arbitrary code in the context of the current user. (CVE-2016-0021, CVE-2016-0134)

- A security feature bypass vulnerability exists in Microsoft Office software due to an improperly signed binary file. An attacker with write access to the target host can exploit this, by overwriting the file with a malicious binary with a similar configuration, to execute arbitrary code. (CVE-2016-0057).
See Also
Solution
Microsoft has released a set of patches for Office 2007, 2010, 2013, 2013 RT, and 2016; Microsoft InfoPath 2007, 2010 and 2013; Microsoft Word 2007, 2010, 2013, 2013 RT, and 2016; Word Viewer; SharePoint Server 2010 and 2013; Microsoft Office Compatibility Pack; and Office Web Apps 2010 and 2013.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.4
EPSS Score
0.4852
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
BID 84024
BID 84026
BID 84030
CVE CVE-2016-0021
CVE CVE-2016-0057
CVE CVE-2016-0134
MSKB 2956063
MSKB 2956110
MSKB 3039746
MSKB 3114414
MSKB 3114426
MSKB 3114690
MSKB 3114812
MSKB 3114814
MSKB 3114821
MSKB 3114824
MSKB 3114833
MSKB 3114855
MSKB 3114866
MSKB 3114873
MSKB 3114878
MSKB 3114880
MSKB 3114900
MSKB 3114901
XREF MSFT:MS16-029
XREF IAVA:2016-A-0063-S
Plugin Information
Published: 2016/03/08, Modified: 2023/02/17
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4351.1001
90436 - MS16-042: Security Update for Microsoft Office (3148775)
-
Synopsis
An application installed on the remote Windows host is affected by multiple remote code execution vulnerabilities.
Description
The version of Microsoft Office installed on the remote Windows host is affected by multiple remote code execution vulnerabilities due to improper handling of objects in memory. A remote attacker can exploit these issues by convincing a user to open a specially crafted file in Microsoft Office, resulting in the execution of arbitrary code in the context of the current user.
See Also
Solution
Microsoft has released a set of patches for Microsoft Office 2010;
Microsoft Word 2007, 2010, 2013, and 2013 RT; Microsoft Excel 2007, 2010, 2013, 2013 RT, and 2016; Word Viewer; Excel Viewer; SharePoint Server 2007, 2010, and 2013; Microsoft Office Compatibility Pack; and Office Web Apps 2010 and 2013.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.9
EPSS Score
0.4064
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
BID 85897
BID 85901
BID 85923
BID 85934
CVE CVE-2016-0122
CVE CVE-2016-0127
CVE CVE-2016-0136
CVE CVE-2016-0139
MSKB 3114871
MSKB 3114888
MSKB 3114892
MSKB 3114895
MSKB 3114897
MSKB 3114898
MSKB 3114927
MSKB 3114934
MSKB 3114937
MSKB 3114947
MSKB 3114964
MSKB 3114982
MSKB 3114983
MSKB 3114987
MSKB 3114988
MSKB 3114990
MSKB 3114993
MSKB 3114994
XREF MSFT:MS16-042
XREF IAVA:2016-A-0090-S
Plugin Information
Published: 2016/04/12, Modified: 2023/02/17
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4366.1000
91004 - MS16-054: Security Update for Microsoft Office (3155544)
-
Synopsis
An application installed on the remote Windows host is affected by multiple remote code execution vulnerabilities.
Description
The version of Microsoft Office installed on the remote Windows host is affected by multiple vulnerabilities :

- Multiple remote code execution vulnerabilities exist due to improper handling of objects in memory. An unauthenticated, remote attacker can exploit these vulnerabilities by convincing a user to visit a specially crafted website or open a specially crafted file, resulting in the execution of arbitrary code in the context of the current user. (CVE-2016-0126, CVE-2016-0140, CVE-2016-0198)

- A remote code execution vulnerability exists in the Windows Font library due to improper handling of embedded fonts. An unauthenticated, remote attacker can exploit this by convincing a user to visit a specially crafted website or open a specially crafted file, resulting in the execution arbitrary code in the context of the current user. (CVE-2016-0183)
See Also
Solution
Microsoft has released a set of patches for Microsoft Office 2007, 2010, 2013, 2013 RT, and 2016; Microsoft Word 2007, 2010, 2013, 2013 RT, and 2016; Word Viewer; Microsoft Office Compatibility Pack;
Office Web Apps 2010; and Microsoft SharePoint Server 2010.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.9
EPSS Score
0.4037
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
BID 89938
BID 89953
BID 89962
CVE CVE-2016-0126
CVE CVE-2016-0140
CVE CVE-2016-0183
CVE CVE-2016-0198
MSKB 2984938
MSKB 2984943
MSKB 3115115
MSKB 3115116
MSKB 3115121
MSKB 3054984
MSKB 3101520
MSKB 3115123
MSKB 3115016
MSKB 3115025
MSKB 3115103
MSKB 3115094
MSKB 3115132
MSKB 3115117
MSKB 3115124
XREF MSFT:MS16-054
XREF IAVA:2016-A-0124-S
Plugin Information
Published: 2016/05/10, Modified: 2023/02/17
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4378.1001
91611 - MS16-070: Security Update for Microsoft Office (3163610)
-
Synopsis
An application installed on the remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing a security update. It is, therefore, affected by multiple vulnerabilities in Microsoft Office :

- Multiple remote code execution vulnerabilities exist due to improper handling of objects in memory. An unauthenticated, remote attacker can exploit these by convincing a user to open a specially crafted file or visit a website that hosts such a file, resulting in the execution of arbitrary code in the context of the user.
(CVE-2016-0025, CVE-2016-3233)

- A flaw exists due to improper disclosure of memory contents. An unauthenticated, remote attacker can exploit this by convincing a user to open a specially crafted file, resulting in the disclosure of potentially sensitive information. (CVE-2016-3234)

- A flaw exists due to improper validation of input before loading OLE library files. A local attacker can exploit this, via a specially crafted application, to execute arbitrary code. (CVE-2016-3235)
See Also
Solution
Microsoft has released a set of patches for Microsoft Office 2007, 2010, 2013, 2013 RT, and 2016; Microsoft Word 2007, 2010, 2013, 2013 RT, and 2016; Microsoft Excel 2007 and 2010; Microsoft Visio 2007, 2010, 2013, and 2016; Visio Viewer 2007 and 2010; Word Viewer;
Microsoft Office Compatibility Pack; Office Web Apps 2010 and 2013;
Microsoft SharePoint Server 2010 and 2013; and Office Online Server.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.9
EPSS Score
0.8116
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
BID 91089
BID 91091
BID 91095
BID 91096
CVE CVE-2016-0025
CVE CVE-2016-3233
CVE CVE-2016-3234
CVE CVE-2016-3235
MSKB 2596915
MSKB 2999465
MSKB 3114740
MSKB 3114872
MSKB 3115014
MSKB 3115020
MSKB 3115041
MSKB 3115107
MSKB 3115111
MSKB 3115130
MSKB 3115134
MSKB 3115144
MSKB 3115170
MSKB 3115173
MSKB 3115182
MSKB 3115187
MSKB 3115194
MSKB 3115195
MSKB 3115196
MSKB 3115198
MSKB 3115243
MSKB 3115244
XREF MSFT:MS16-070
XREF IAVA:2016-A-0148-S
XREF CISA-KNOWN-EXPLOITED:2022/05/03
Exploitable With
Metasploit (true)
Plugin Information
Published: 2016/06/15, Modified: 2023/04/25
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4393.1000
92019 - MS16-088: Security Update for Microsoft Office (3170008)
-
Synopsis
An application installed on the remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing a security update. It is, therefore, affected by multiple vulnerabilities :

- Multiple remote code execution vulnerabilities exist in Microsoft Office software due to improper handling of objects in memory. A remote attacker can exploit these vulnerabilities by convincing a user to open a specially crafted Office file, resulting in the execution of arbitrary code in the context of the current user.
(CVE-2016-3278, CVE-2016-3280, CVE-2016-3281, CVE-2016-3282, CVE-2016-3283, CVE-2016-3284)

- A remote code execution vulnerability exists in Microsoft Office software due to improper handling of XLA files. A remote attacker can exploit this vulnerability by convincing a user to open a specially crafted XLA file in Office, resulting in the execution of arbitrary code in the context of the current user.
(CVE-2016-3279)
See Also
Solution
Microsoft has released a set of patches for Microsoft Office 2007, 2010, 2013, 2013 RT, and 2016; Microsoft Word 2007, 2010, 2013, 2013 RT, and 2016; Microsoft Excel 2007, 2010, 2013, 2013 RT, and 2016;
Microsoft Outlook 2010, 2013, 2013 RT, and 2016; Microsoft PowerPoint 2010, 2013, and 2013 RT; Excel Viewer; Word Viewer; Microsoft Office Compatibility Pack; Office Web Apps 2010 and 2013; Microsoft SharePoint Server 2010, 2013 and 2016; Microsoft SharePoint Foundation 2010 and 2013; and Office Online Server.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.5459
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
BID 91574
BID 91582
BID 91587
BID 91588
BID 91589
BID 91592
CVE CVE-2016-3278
CVE CVE-2016-3279
CVE CVE-2016-3280
CVE CVE-2016-3281
CVE CVE-2016-3282
CVE CVE-2016-3283
CVE CVE-2016-3284
MSKB 3114890
MSKB 3115114
MSKB 3115118
MSKB 3115246
MSKB 3115254
MSKB 3115259
MSKB 3115262
MSKB 3115272
MSKB 3115279
MSKB 3115285
MSKB 3115289
MSKB 3115292
MSKB 3115294
MSKB 3115299
MSKB 3115301
MSKB 3115306
MSKB 3115308
MSKB 3115309
MSKB 3115311
MSKB 3115312
MSKB 3115315
MSKB 3115317
MSKB 3115318
MSKB 3115322
MSKB 3115386
MSKB 3115393
MSKB 3115395
XREF MSFT:MS16-088
XREF IAVA:2016-A-0176-S
Plugin Information
Published: 2016/07/12, Modified: 2023/02/17
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4405.1000

Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4405.1000

Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4405.1000
92839 - MS16-099: Security Update for Microsoft Office (3177451)
-
Synopsis
An application installed on the remote Windows host is affected by multiple vulnerabilities.
Description
The Microsoft Office application installed on the remote Windows host is missing a security update. It is, therefore, affected by multiple vulnerabilities :

- Multiple memory corruption issues exist in Microsoft Office software due to improper handling of objects in memory. An unauthenticated, remote attacker can exploit these issues, by convincing a user to open a specially crafted file, to execute arbitrary code in the context of the current user. (CVE-2016-3313, CVE-2016-3316, CVE-2016-3317, CVE-2016-3318)

- An information disclosure vulnerability exists in Microsoft OneNote due to an unspecified flaw. An unauthenticated, remote attacker can exploit this, by convincing a user to open a specially crafted OneNote file, to disclose sensitive memory contents.
(CVE-2016-3315)
See Also
Solution
Microsoft has released a set of patches for Microsoft Office 2007, 2010, 2013, 2013 RT, and 2016; Microsoft Word 2007, 2010, 2013, 2013 RT, and 2016; Microsoft OneNote 2007, 2010, 2013, 2013 RT, and 2016;
Microsoft Outlook 2007, 2010, 2013, and 2016; and Word Viewer.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.9
EPSS Score
0.5027
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
BID 92289
BID 92294
BID 92300
BID 92303
BID 92308
CVE CVE-2016-3313
CVE CVE-2016-3315
CVE CVE-2016-3316
CVE CVE-2016-3317
CVE CVE-2016-3318
MSKB 3114340
MSKB 3114400
MSKB 3114442
MSKB 3114456
MSKB 3114869
MSKB 3114885
MSKB 3114893
MSKB 3114981
MSKB 3115256
MSKB 3115415
MSKB 3115419
MSKB 3115427
MSKB 3115439
MSKB 3115440
MSKB 3115449
MSKB 3115452
MSKB 3115465
MSKB 3115468
MSKB 3115471
MSKB 3115474
MSKB 3115479
MSKB 3115480
XREF MSFT:MS16-099
XREF IAVA:2016-A-0203-S
Plugin Information
Published: 2016/08/10, Modified: 2023/02/17
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 3115415
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4417.1000

Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4417.1000

Product : OneNote 2016
- C:\Program Files\Microsoft Office\Office16\OneNote.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4405.1000

Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4417.1000
93481 - MS16-107: Security Update for Microsoft Office (3185852)
-
Synopsis
An application installed on the remote host is affected by multiple vulnerabilities.
Description
The Microsoft Office application installed on the remote Windows host is missing a security update. It is, therefore, affected by multiple vulnerabilities :

- An information disclosure vulnerability exists in the the Click-to-Run (C2R) components due to improper handling of objects in memory. An authenticated, remote attacker can exploit this, via a specially crafted application, to obtain sensitive information and thereby bypass the Address Space Layout Randomization (ASLR) security feature. (CVE-2016-0137)

- An information disclosure vulnerability exists due to Visual Basic macros improperly exporting a user's private key from the certificate store while saving a document.
An unauthenticated, remote attacker can exploit this, by convincing a user to provide the saved document, to gain access to the user's private key. (CVE-2016-0141)

- Multiple remote code execution vulnerabilities exist in Microsoft Office software due to improper handling of objects in memory. A remote attacker can exploit these, by convincing a user to open a specially crafted Office file, to execute arbitrary code in the context of the current user. (CVE-2016-3357, CVE-2016-3358, CVE-2016-3359, CVE-2016-3360, CVE-2016-3361, CVE-2016-3362, CVE-2016-3363, CVE-2016-3364, CVE-2016-3365, CVE-2016-3381)

- A spoofing vulnerability exists in Microsoft Outlook due to a failure to conform to RFC2046 and properly identify the end of a MIME attachment. An unauthenticated, remote attacker can exploit this, by convincing a user to open a specially crafted email attachment, to cause antivirus or antispam security features to fail. (CVE-2016-3366)
See Also
Solution
Microsoft has released a set of patches for Microsoft Office 2007, 2010, 2013, 2013 RT, and 2016; Microsoft Excel 2007, 2010, 2013, 2013 RT, and 2016; Microsoft PowerPoint 2007, 2010, 2013, and 2013 RT;
Microsoft Outlook 2007, 2010, 2013, 2013 RT, and 2016; Microsoft Visio 2016; Office Compatibility Pack; Excel Viewer; PowerPoint Viewer; Word Viewer; Microsoft SharePoint Server 2007, 2010, and 2013; Office Web Apps 2010 and 2013; and Office Online Server.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.3241
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.3 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
II
References
BID 92785
BID 92786
BID 92791
BID 92795
BID 92796
BID 92798
BID 92799
BID 92801
BID 92803
BID 92804
BID 92805
BID 92831
BID 92903
CVE CVE-2016-0137
CVE CVE-2016-0141
CVE CVE-2016-3357
CVE CVE-2016-3358
CVE CVE-2016-3359
CVE CVE-2016-3360
CVE CVE-2016-3361
CVE CVE-2016-3362
CVE CVE-2016-3363
CVE CVE-2016-3364
CVE CVE-2016-3365
CVE CVE-2016-3366
CVE CVE-2016-3381
MSKB 2553432
MSKB 2597974
MSKB 3054862
MSKB 3054969
MSKB 3114744
MSKB 3115112
MSKB 3115119
MSKB 3115169
MSKB 3115443
MSKB 3115459
MSKB 3115462
MSKB 3115463
MSKB 3115466
MSKB 3115467
MSKB 3115472
MSKB 3115487
MSKB 3118268
MSKB 3118270
MSKB 3118280
MSKB 3118284
MSKB 3118290
MSKB 3118292
MSKB 3118293
MSKB 3118297
MSKB 3118299
MSKB 3118300
MSKB 3118303
MSKB 3118309
MSKB 3118313
MSKB 3118316
XREF MSFT:MS16-107
XREF IAVA:2016-A-0243-S
Plugin Information
Published: 2016/09/14, Modified: 2023/02/17
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 3118292
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4432.1000

Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4432.1003

Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4432.1001
94016 - MS16-121: Security Update for Microsoft Office (3194063)
-
Synopsis
An application installed on the remote host is affected by a remote code execution vulnerability.
Description
The Microsoft Office application installed on the remote Windows host is missing a security update. It is, therefore, affected by a remote code execution vulnerability due to improper handling of RTF files. An unauthenticated, remote attacker can exploit this by convincing a user to open a specially crafted Office file, resulting in the execution of arbitrary code in the context of the current user.
See Also
Solution
Microsoft has released a set of patches for Microsoft Office 2007, 2010, 2013, 2013 RT, and 2016; Microsoft Word 2007, 2010, 2013, 2013 RT, and 2016; Microsoft Office Compatibility Pack; Microsoft Word Viewer; Microsoft SharePoint Server 2010 and 2013; Microsoft Office Web Apps 2010 and 2013; and Office Online Server.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.9
EPSS Score
0.712
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
BID 93372
CVE CVE-2016-7193
MSKB 3118307
MSKB 3118308
MSKB 3118311
MSKB 3118312
MSKB 3118331
MSKB 3118345
MSKB 3118352
MSKB 3118360
MSKB 3118377
MSKB 3118384
MSKB 3127897
MSKB 3127898
MSKB 3193438
MSKB 3193442
XREF MSFT:MS16-121
XREF IAVA:2016-A-0280-S
XREF CISA-KNOWN-EXPLOITED:2022/03/24
Plugin Information
Published: 2016/10/12, Modified: 2023/02/17
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4444.1003
94634 - MS16-133: Security Update for Microsoft Office (3199168)
-
Synopsis
An application installed on the remote host is affected by multiple vulnerabilities.
Description
The Microsoft Office application installed on the remote Windows host is missing a security update. It is, therefore, affected by multiple vulnerabilities :

- Multiple remote code execution vulnerabilities exist due to improper handling of objects in memory. An unauthenticated, remote attacker can exploit these by convincing a user to visit a specially crafted website or open a specially crafted Office file, resulting in the execution of arbitrary code in the context of the current user. (CVE-2016-7213, CVE-2016-7228, CVE-2016-7229, CVE-2016-7230, CVE-2016-7231, CVE-2016-7232, CVE-2016-7234, CVE-2016-7235, CVE-2016-7236, CVE-2016-7245)

- An information disclosure vulnerability exists due to an out-of-bounds read error caused by an uninitialized variable. An unauthenticated, remote attacker can exploit this by convincing a user to open a specially crafted Office file, resulting in the disclosure of memory contents. (CVE-2016-7233)

- A denial of service vulnerability exists due to improper handling of objects in memory. An unauthenticated, remote attacker can exploit this by convincing a user to open a specially crafted file, resulting in a crash of the application. (CVE-2016-7244)
See Also
Solution
Microsoft has released a set of patches for Microsoft Office 2007, 2010, 2013, 2013 RT, and 2016; Microsoft Excel 2007, 2010, 2013, 2013 RT, and 2016; Microsoft PowerPoint 2010; Microsoft Word 2007, 2010, 2013, and 2013 RT; Office Compatibility Pack; Excel Viewer;
PowerPoint Viewer; Word Viewer; Microsoft SharePoint Server 2010 and 2013; and Office Web Apps 2010 and 2013
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.7
EPSS Score
0.4835
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
BID 93993
BID 93994
BID 93995
BID 93996
BID 94005
BID 94006
BID 94020
BID 94022
BID 94025
BID 94026
BID 94029
BID 94031
CVE CVE-2016-7213
CVE CVE-2016-7228
CVE CVE-2016-7229
CVE CVE-2016-7230
CVE CVE-2016-7231
CVE CVE-2016-7232
CVE CVE-2016-7233
CVE CVE-2016-7234
CVE CVE-2016-7235
CVE CVE-2016-7236
CVE CVE-2016-7244
CVE CVE-2016-7245
MSKB 2986253
MSKB 3115120
MSKB 3115135
MSKB 3115153
MSKB 3118378
MSKB 3118381
MSKB 3118382
MSKB 3118390
MSKB 3118395
MSKB 3118396
MSKB 3127889
MSKB 3127893
MSKB 3127904
MSKB 3127921
MSKB 3127927
MSKB 3127929
MSKB 3127932
MSKB 3127948
MSKB 3127949
MSKB 3127950
MSKB 3127951
MSKB 3127953
MSKB 3127954
MSKB 3127962
XREF MSFT:MS16-133
XREF IAVA:2016-A-0319-S
Plugin Information
Published: 2016/11/08, Modified: 2023/02/17
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4456.1003
96391 - MS17-002: Security Update for Microsoft Office (3214291)
-
Synopsis
An application installed on the remote host is affected by a remote code execution vulnerability.
Description
The version of Microsoft Word or Microsoft SharePoint Server installed on the remote Windows host is missing a security update. It is, therefore, affected by a memory corruption issue due to improper handling of objects in memory. An unauthenticated, remote attacker can exploit this, by convincing a user to visit a specially crafted website or open a specially crafted Office file, to execute arbitrary code in the context of the current user.
See Also
Solution
Microsoft has released a set of patches for Microsoft Word 2016 and SharePoint Server 2016
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.3361
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2017-0003
MSKB 3128057
MSKB 3141486
XREF MSFT:MS17-002
XREF IAVA:2017-A-0009-S
Plugin Information
Published: 2017/01/10, Modified: 2023/02/17
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4483.1000
97740 - MS17-014: Security Update for Microsoft Office (4013241)
-
Synopsis
An application installed on the remote host is affected by multiple vulnerabilities.
Description
The Microsoft Office application, Office Web Apps, or SharePoint Server installed on the remote Windows host is missing a security update. It is, therefore, affected by multiple vulnerabilities :

- Multiple remote code execution vulnerabilities exist in Microsoft Office software due to improper handling of objects in memory. An unauthenticated, remote attacker can exploit these, by convincing a user to open a specially crafted document file, to execute arbitrary code in the context of the current user. (CVE-2017-0006, CVE-2017-0019, CVE-2017-0020, CVE-2017-0030, CVE-2017-0031, CVE-2017-0052, CVE-2017-0053)

- An information disclosure vulnerability exists in Microsoft Office due to improper disclosure of memory contents. An unauthenticated, remote attacker can exploit this to disclose sensitive system memory information by convincing a user to open a specially crafted document file. (CVE-2017-0027)

- A denial of service vulnerability exists in Microsoft Office that allows an unauthenticated, remote attacker to cause Office to stop responding by convincing a user to open a specially crafted document file.
(CVE-2017-0029)

- An out-of-bounds read error exists in Microsoft Office due to an uninitialized variable. A local attacker can exploit this to disclose memory contents by opening a specially crafted document file. (CVE-2017-0105)

- A cross-site scripting (XSS) vulnerability exists in Microsoft SharePoint Server due to improper validation of input before returning it to users. An authenticated, remote attacker can exploit this, via a specially crafted request, to execute arbitrary script code in a user's browser session. (CVE-2017-0107)
See Also
Solution
Microsoft has released a set of patches for Microsoft Office 2007, 2010, 2013, and 2016; Microsoft Excel 2007, 2010, 2013, and 2016;
Microsoft Word 2007, 2010, 2013, and 2016; Microsoft Office Compatibility Pack; Microsoft Excel Viewer; Microsoft Word Viewer;
Microsoft SharePoint Server 2007, 2010, and 2013; Microsoft SharePoint Foundation 2013; and Microsoft Office Web Apps Server 2010 and 2013.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.4318
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
BID 96042
BID 96043
BID 96045
BID 96050
BID 96051
BID 96052
BID 96740
BID 96741
BID 96745
BID 96746
BID 96748
BID 96752
CVE CVE-2017-0006
CVE CVE-2017-0019
CVE CVE-2017-0020
CVE CVE-2017-0027
CVE CVE-2017-0029
CVE CVE-2017-0030
CVE CVE-2017-0031
CVE CVE-2017-0052
CVE CVE-2017-0053
CVE CVE-2017-0105
CVE CVE-2017-0107
MSKB 3172431
MSKB 3172457
MSKB 3172464
MSKB 3172540
MSKB 3172542
MSKB 3178673
MSKB 3178674
MSKB 3178676
MSKB 3178677
MSKB 3178678
MSKB 3178680
MSKB 3178682
MSKB 3178683
MSKB 3178684
MSKB 3178685
MSKB 3178686
MSKB 3178687
MSKB 3178689
MSKB 3178690
MSKB 3178694
XREF MSFT:MS17-014
XREF IAVA:2017-A-0060-S
Plugin Information
Published: 2017/03/15, Modified: 2023/02/17
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4510.1000

Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4510.1000

42873 - SSL Medium Strength Cipher Suites Supported (SWEET32)
-
Synopsis
The remote service supports the use of medium strength SSL ciphers.
Description
The remote host supports the use of SSL ciphers that offer medium strength encryption. Nessus regards medium strength as any encryption that uses key lengths at least 64 bits and less than 112 bits, or else that uses the 3DES encryption suite.

Note that it is considerably easier to circumvent medium strength encryption if the attacker is on the same physical network.
See Also
Solution
Reconfigure the affected application if possible to avoid use of medium strength ciphers.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
VPR Score
6.1
EPSS Score
0.4002
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
References
Plugin Information
Published: 2009/11/23, Modified: 2025/02/12
Plugin Output

tcp/3389/msrdp


Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

137264 - Security Feature Bypass Vulnerability for Microsoft Excel Products (June 2020)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products is missing a security update, and Therefore is affected by a security feature bypass vulnerability. An attacker who exploited this vulnerability could cause a system to load remote images which could disclose the IP address of the targeted system to the attacker.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4484415
-KB4484410
-KB4484403

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.2062
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2020-1225
CVE CVE-2020-1226
MSKB 4484415
MSKB 4484410
MSKB 4484403
XREF MSFT:MS20-4484415
XREF MSFT:MS20-4484410
XREF MSFT:MS20-4484403
XREF IAVA:2020-A-0249-S
Plugin Information
Published: 2020/06/09, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5017.1000
232847 - Security Update for Microsoft .NET 8 Core (January 2025)
-
Synopsis
The remote Windows host is affected by a .NET Core vulnerability
Description
The version of Microsoft .NET 8 Core installed on the remote host is prior to 8.0.12. It is, therefore, affected by multiple vulnerabilities as referenced in the vendor advisory.

- .NET and Visual Studio Remote Code Execution Vulnerability (CVE-2025-21172)

- .NET Elevation of Privilege Vulnerability (CVE-2025-21173)

- .NET and Visual Studio Remote Code Execution Vulnerability (CVE-2025-21176)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core, remove vulnerable packages and refer to vendor advisory.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0035
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
References
Plugin Information
Published: 2025/03/19, Modified: 2025/03/19
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NETCore.App\8.0.8\
Installed version : 8.0.8
Fixed version : 8.0.12

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.8\
Installed version : 8.0.8
Fixed version : 8.0.12
234051 - Security Update for Microsoft .NET Core (April 2025)
-
Synopsis
The remote Windows host is affected by a .NET Core vulnerability
Description
The version of tested product installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the vendor advisory.

- Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. (CVE-2025-26682)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core, remove vulnerable packages and refer to vendor advisory.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.3085
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)
CVSS v2.0 Temporal Score
5.8 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-26682
XREF IAVA:2025-A-0238-S
Plugin Information
Published: 2025/04/08, Modified: 2025/05/16
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NETCore.App\8.0.8\
Installed version : 8.0.8
Fixed version : 8.0.15

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.8\
Installed version : 8.0.8
Fixed version : 8.0.15
238082 - Security Update for Microsoft .NET Core (June 2025)
-
Synopsis
The remote Windows host is affected by a .NET Core vulnerability
Description
The version of tested product installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the vendor advisory.

- .NET and Visual Studio Remote Code Execution Vulnerability (CVE-2025-30399)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core, remove vulnerable packages and refer to vendor advisory.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.0006
CVSS v2.0 Base Score
7.6 (CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-30399
XREF IAVA:2025-A-0410-S
Plugin Information
Published: 2025/06/10, Modified: 2025/10/29
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NETCore.App\8.0.8\
Installed version : 8.0.8
Fixed version : 8.0.17

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.8\
Installed version : 8.0.8
Fixed version : 8.0.17
232619 - Security Update for Microsoft .NET Core (March 2025)
-
Synopsis
The remote Windows host is affected by a .NET Core vulnerability
Description
The version of Microsoft .NET Core installed on the remote host is 8.0.x < 8.0.14 or 9.0.x < 9.0.3.
It is, therefore, affected by a vulnerability as referenced in the vendor advisory.

- Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network. (CVE-2025-24070)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core, remove vulnerable packages and refer to vendor advisory.
Risk Factor
Medium
CVSS v3.0 Base Score
7.0 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H)
CVSS v3.0 Temporal Score
6.1 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.5
EPSS Score
0.0015
CVSS v2.0 Base Score
6.6 (CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:C)
CVSS v2.0 Temporal Score
4.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-24070
XREF IAVA:2025-A-0175-S
Plugin Information
Published: 2025/03/11, Modified: 2025/04/10
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NETCore.App\8.0.8\
Installed version : 8.0.8
Fixed version : 8.0.14

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.8\
Installed version : 8.0.8
Fixed version : 8.0.14
235852 - Security Update for Microsoft .NET Core (May 2025)
-
Synopsis
The remote Windows host is affected by a .NET Core vulnerability
Description
The version of tested product installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the vendor advisory.

- External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network. (CVE-2025-26646)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core, remove vulnerable packages and refer to vendor advisory.
Risk Factor
High
CVSS v3.0 Base Score
8.0 (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0004
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.7 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-26646
XREF IAVA:2025-A-0330-S
Plugin Information
Published: 2025/05/13, Modified: 2025/06/12
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NETCore.App\8.0.8\
Installed version : 8.0.8
Fixed version : 8.0.16

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.8\
Installed version : 8.0.8
Fixed version : 8.0.16
208286 - Security Update for Microsoft .NET Core (October 2024)
-
Synopsis
The remote Windows host is affected by a .NET Core vulnerability
Description
The version of tested product installed on the remote host is prior to tested version. It is, therefore, affected by multiple vulnerabilities as referenced in the vendor advisory.

- .NET and Visual Studio Remote Code Execution Vulnerability (CVE-2024-38229)

- .NET and Visual Studio Denial of Service Vulnerability (CVE-2024-43483,CVE-2024-43484,CVE-2024-43485)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core, remove vulnerable packages and refer to vendor advisory.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0338
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)
CVSS v2.0 Temporal Score
5.8 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-38229
CVE CVE-2024-43483
CVE CVE-2024-43484
CVE CVE-2024-43485
XREF IAVA:2024-A-0625-S
XREF IAVA:2024-A-0632-S
Plugin Information
Published: 2024/10/08, Modified: 2025/05/07
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NETCore.App\8.0.8\
Installed version : 8.0.8
Fixed version : 8.0.10

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.8\
Installed version : 8.0.8
Fixed version : 8.0.10
103138 - Security Update for Microsoft Office Excel Products (September 2017)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the same permissions as the current user. Exploitation of this vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Office software. In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and convincing the user to open the file. In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) that contains a specially crafted file that is designed to exploit the vulnerability. However, an attacker would have no way to force the user to visit the website. Instead, an attacker would have to convince the user to click a link, typically by way of an enticement in an email or Instant Messenger message, and then convince the user to open the specially crafted file. The security update addresses the vulnerability by correcting how Microsoft Office handles files in memory.
(CVE-2017-8631, CVE-2017-8632)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4011108
-KB4011050
-KB4011061
-KB4011062
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.2642
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
BID 100734
BID 100751
CVE CVE-2017-8631
CVE CVE-2017-8632
MSKB 4011108
MSKB 4011062
MSKB 4011061
XREF MSFT:MS17-4011050
XREF MSFT:MS17-4011108
XREF MSFT:MS17-4011062
XREF MSFT:MS17-4011061
XREF IAVA:2017-A-0274
Plugin Information
Published: 2017/09/12, Modified: 2019/11/12
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4588.1000
99314 - Security Update for Microsoft Office Products (April 2017) (Petya)
-
Synopsis
An application installed on the remote Windows host is affected by multiple vulnerabilities.
Description
The Microsoft Office application, Office Web Apps, or SharePoint Server installed on the remote Windows host is missing a security update. It is, therefore, affected by multiple vulnerabilities :

- An arbitrary code execution vulnerability exists in Microsoft Outlook due to improper parsing of email messages. An unauthenticated, remote attacker can exploit this, via a specially crafted email message, to execute arbitrary code. (CVE-2017-0106)

- An information disclosure vulnerability exists in Microsoft Office due to improper handling of objects in memory. An unauthenticated, remote attacker can exploit this, by convincing a user to open a specially crafted Excel file, to disclose the contents of memory.
(CVE-2017-0194)

- A cross-site scripting (XSS) vulnerability exists in Office Web Apps Server due to improper validation of input before returning it to users. An authenticated, remote attacker can exploit this, via a specially crafted request, to execute arbitrary script code in a user's browser session. (CVE-2017-0195)

- An arbitrary code execution vulnerability exists in Microsoft Office due to improper validation of input before loading dynamic link library (DLL) files. An unauthenticated, remote attacker can exploit this, by convincing a user to open a specially crafted Office document, to execute arbitrary code. (CVE-2017-0197)

- An arbitrary code execution vulnerability exists in Microsoft Office and Windows WordPad due to improper validation of user-supplied input. An unauthenticated, remote attacker can exploit this, by convincing a user to open a specially crafted file, to execute arbitrary code. Note that this vulnerability is being utilized to spread the Petya ransomware. (CVE-2017-0199)

- A security feature bypass vulnerability exists in Microsoft Office due to improper parsing of file formats. An unauthenticated, remote attacker can exploit this, by convincing a user into opening a specially crafted file, to bypass security features.
(CVE-2017-0204)

- A spoofing vulnerability in Microsoft Outlook due to improper validation of input passed via HTML tags. An unauthenticated, remote attacker can exploit this, by sending an email with specific HTML tags, to display a malicious authentication prompt and gain access to a user's authentication information or login credentials.
(CVE-2017-0207)
See Also
Solution
Microsoft has released a set of patches for Microsoft Office 2007, 2010, 2013, and 2016; Microsoft Excel 2007 and 2010; Microsoft OneNote 2007 and 2010; Microsoft Outlook 2007, 2010, 2013, and 2016; Microsoft Office Compatibility Pack; Excel Services on Microsoft SharePoint Server 2010 and 2013; Microsoft Excel Web App 2010; Microsoft Office Web Apps Server 2010 and 2013; and Office Online Server.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.8
EPSS Score
0.9437
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
BID 95961
BID 97411
BID 97413
BID 97417
BID 97436
BID 97458
BID 97463
BID 97498
CVE CVE-2017-0106
CVE CVE-2017-0194
CVE CVE-2017-0195
CVE CVE-2017-0197
CVE CVE-2017-0199
CVE CVE-2017-0204
CVE CVE-2017-0207
MSKB 2589382
MSKB 3101522
MSKB 3118388
MSKB 3127890
MSKB 3127895
MSKB 3141529
MSKB 3141538
MSKB 3172519
MSKB 3178664
MSKB 3178702
MSKB 3178703
MSKB 3178710
MSKB 3178724
MSKB 3178725
MSKB 3191827
MSKB 3191829
MSKB 3191830
MSKB 3191840
MSKB 3191845
MSKB 3191847
XREF CERT:921560
XREF EDB-ID:41894
XREF EDB-ID:41934
XREF MSFT:MS17-2589382
XREF MSFT:MS17-3101522
XREF MSFT:MS17-3118388
XREF MSFT:MS17-3127890
XREF MSFT:MS17-3127895
XREF MSFT:MS17-3141529
XREF MSFT:MS17-3141538
XREF MSFT:MS17-3172519
XREF MSFT:MS17-3178664
XREF MSFT:MS17-3178702
XREF MSFT:MS17-3178703
XREF MSFT:MS17-3178710
XREF MSFT:MS17-3178724
XREF MSFT:MS17-3178725
XREF MSFT:MS17-3191827
XREF MSFT:MS17-3191829
XREF MSFT:MS17-3191830
XREF MSFT:MS17-3191840
XREF MSFT:MS17-3191845
XREF MSFT:MS17-3191847
XREF IAVA:2017-A-0101-S
XREF IAVA:2017-A-0104-S
XREF CISA-KNOWN-EXPLOITED:2022/05/03
Exploitable With
Core Impact (true) Metasploit (true)
Plugin Information
Published: 2017/04/12, Modified: 2023/06/16
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 3178702
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4522.1002

Product : Microsoft Office 2016
KB : 3178703
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso30win32client.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4522.1000

Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4522.1001
101371 - Security Update for Microsoft Office Products (July 2017)
-
Synopsis
An application installed on the remote Windows host is affected by multiple remote code execution vulnerabilities.
Description
The Microsoft Office application, Microsoft Office Compatibility Pack, or Microsoft Excel Viewer installed on the remote Windows host is missing a security update. It is, therefore, affected by multiple remote code execution vulnerabilities due to improper handling of objects in memory. An unauthenticated, remote attacker can exploit these vulnerabilities, by convincing a user to open a specially crafted document or to visit a specially crafted website, to execute arbitrary code in the context of the current user.

Note that KB2880514 for Office 2007 and KB3203468 for Office 2010 SP2 are only applicable to Office installations with the Galician language pack installed.
See Also
Solution
Microsoft has released a set of patches for Microsoft Office 2007, 2010, 2013, and 2016; Microsoft Excel 2007, 2010, 2013, and 2016;
Microsoft Excel Viewer 2007; and Microsoft Office Compatibility Pack.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.8
EPSS Score
0.9425
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
BID 99441
BID 99442
BID 99445
BID 99446
CVE CVE-2017-0243
CVE CVE-2017-8501
CVE CVE-2017-8502
CVE CVE-2017-8570
MSKB 2880514
MSKB 3191833
MSKB 3191894
MSKB 3191897
MSKB 3191907
MSKB 3203468
MSKB 3203477
MSKB 3213537
MSKB 3213545
MSKB 3213555
MSKB 3213624
MSKB 3213640
XREF MSFT:MS17-2880514
XREF MSFT:MS17-3191833
XREF MSFT:MS17-3191894
XREF MSFT:MS17-3191897
XREF MSFT:MS17-3191907
XREF MSFT:MS17-3203468
XREF MSFT:MS17-3203477
XREF MSFT:MS17-3213537
XREF MSFT:MS17-3213545
XREF MSFT:MS17-3213555
XREF MSFT:MS17-3213624
XREF MSFT:MS17-3213640
XREF CISA-KNOWN-EXPLOITED:2022/08/25
Exploitable With
CANVAS (true)
Plugin Information
Published: 2017/07/11, Modified: 2022/02/28
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 3213545
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso30win32client.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4561.1002

Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4561.1000
100782 - Security Update for Microsoft Office Products (June 2017)
-
Synopsis
An application installed on the remote Windows host is affected by multiple vulnerabilities.
Description
The Microsoft Office application installed on the remote Windows host is missing a security update. It is, therefore, affected by multiple vulnerabilities :

- Multiple remote code execution vulnerabilities exist in Microsoft Office due to improper validation of input before loading dynamic link library (DLL) files. An unauthenticated, remote attacker can exploit these, by convincing a user to open a specially crafted Office document, to execute arbitrary code in the context of the current user. (CVE-2017-0260. CVE-2017-8506)

- Multiple information disclosure vulnerabilities exist in Windows Uniscribe due to improper handling of objects in memory. An unauthenticated, remote attacker can exploit these, by convincing a user to visit a specially crafted website or to open a specially crafted document file, to disclose the contents of memory. (CVE-2017-0282, CVE-2017-0284, CVE-2017-0285, CVE-2017-8534)

- Multiple remote code execution vulnerabilities exist in Windows Uniscribe due to improper handling of objects in memory. An unauthenticated, remote attacker can exploit these, by convincing a user to visit a specially crafted website or open a specially crafted document, to execute arbitrary code in the context of the current user.
(CVE-2017-0283, CVE-2017-8528)

- Multiple information disclosure vulnerabilities exist in the Windows GDI component due to improper handling of objects in memory. An unauthenticated, remote attacker can exploit these, by convincing a user to visit a specially crafted website or to open a specially crafted document file, to disclose the contents of memory.
(CVE-2017-0286, CVE-2017-0287, CVE-2017-0288, CVE-2017-0289, CVE-2017-8531, CVE-2017-8532, CVE-2017-8533)

- A remote code execution vulnerability exists in Microsoft Windows due to improper parsing of PDF files.
An unauthenticated, remote attacker can exploit this, by convincing a user to open a specially crafted PDF file, to execute arbitrary code in the context of the current user. (CVE-2017-0292)

- A remote code execution vulnerability exists in Microsoft Outlook due to improper parsing of email messages. An unauthenticated, remote attacker can exploit this, by convincing a user to open a specially crafted email message, to execute arbitrary code in the context of the current user. (CVE-2017-8507)

- A security bypass vulnerability exists in Microsoft Outlook due to improper parsing of file formats. An unauthenticated, remote attacker can exploit this, by convincing a user to open a specially crafted Office document, to bypass security feature protections.
(CVE-2017-8508)

- Multiple remote code execution vulnerabilities exist in Microsoft Office due to improper handling of objects in memory. An unauthenticated, remote attacker can exploit these, by convincing a user to open a specially crafted Office document, to execute arbitrary code in the context of the current user. (CVE-2017-8509, CVE-2017-8510, CVE-2017-8511, CVE-2017-8512, CVE-2017-8550)

- A remote code execution vulnerability exists in Microsoft PowerPoint due to improper handling of objects in memory. An unauthenticated, remote attacker can exploit this, by convincing a user to open a specially crafted file, to execute arbitrary code in the context of the current user. (CVE-2017-8513)

- A remote code execution vulnerability exists in the Windows font library due to improper handling of embedded fonts. An unauthenticated, remote attacker can exploit this, by convincing a user to visit a specially crafted website or open a specially crafted Microsoft document, to execute arbitrary code in the context of the current user. (CVE-2017-8527)
See Also
Solution
Microsoft has released a set of patches for Microsoft Office 2007, 2010, 2013, and 2016; Microsoft OneNote 2010; Microsoft Outlook 2007, 2010, and 2016; Microsoft PowerPoint 2007; Microsoft Word 2007, 2010, 2013, and 2016; Microsoft Word Viewer; and Microsoft Office Compatibility Pack.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.9
EPSS Score
0.5511
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
BID 98810
BID 98811
BID 98812
BID 98813
BID 98815
BID 98816
BID 98819
BID 98820
BID 98821
BID 98822
BID 98827
BID 98828
BID 98830
BID 98836
BID 98885
BID 98891
BID 98914
BID 98916
BID 98918
BID 98920
BID 98922
BID 98923
BID 98929
BID 98933
BID 98949
CVE CVE-2017-0260
CVE CVE-2017-0282
CVE CVE-2017-0283
CVE CVE-2017-0284
CVE CVE-2017-0285
CVE CVE-2017-0286
CVE CVE-2017-0287
CVE CVE-2017-0288
CVE CVE-2017-0289
CVE CVE-2017-0292
CVE CVE-2017-8506
CVE CVE-2017-8507
CVE CVE-2017-8508
CVE CVE-2017-8509
CVE CVE-2017-8510
CVE CVE-2017-8511
CVE CVE-2017-8512
CVE CVE-2017-8513
CVE CVE-2017-8527
CVE CVE-2017-8528
CVE CVE-2017-8531
CVE CVE-2017-8532
CVE CVE-2017-8533
CVE CVE-2017-8534
CVE CVE-2017-8550
MSKB 3118304
MSKB 3118389
MSKB 3127888
MSKB 3162051
MSKB 3178667
MSKB 3191828
MSKB 3191837
MSKB 3191844
MSKB 3191848
MSKB 3191882
MSKB 3191898
MSKB 3191908
MSKB 3191932
MSKB 3191938
MSKB 3191943
MSKB 3191944
MSKB 3191945
MSKB 3203383
MSKB 3203386
MSKB 3203392
MSKB 3203393
MSKB 3203427
MSKB 3203436
MSKB 3203438
MSKB 3203441
MSKB 3203460
MSKB 3203461
MSKB 3203463
MSKB 3203464
MSKB 3203467
MSKB 3203484
XREF MSFT:MS17-3118304
XREF MSFT:MS17-3118389
XREF MSFT:MS17-3127888
XREF MSFT:MS17-3162051
XREF MSFT:MS17-3178667
XREF MSFT:MS17-3191828
XREF MSFT:MS17-3191837
XREF MSFT:MS17-3191844
XREF MSFT:MS17-3191848
XREF MSFT:MS17-3191882
XREF MSFT:MS17-3191898
XREF MSFT:MS17-3191908
XREF MSFT:MS17-3191932
XREF MSFT:MS17-3191938
XREF MSFT:MS17-3191943
XREF MSFT:MS17-3191944
XREF MSFT:MS17-3191945
XREF MSFT:MS17-3203383
XREF MSFT:MS17-3203386
XREF MSFT:MS17-3203392
XREF MSFT:MS17-3203393
XREF MSFT:MS17-3203427
XREF MSFT:MS17-3203436
XREF MSFT:MS17-3203438
XREF MSFT:MS17-3203441
XREF MSFT:MS17-3203460
XREF MSFT:MS17-3203461
XREF MSFT:MS17-3203463
XREF MSFT:MS17-3203464
XREF MSFT:MS17-3203467
XREF MSFT:MS17-3203484
XREF IAVA:2017-A-0179-S
Plugin Information
Published: 2017/06/14, Modified: 2025/12/16
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 3191944
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4549.1001

Product : Microsoft Office 2016
KB : 3178667
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso20win32client.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4549.1000

Product : Microsoft Office 2016
KB : 3191882
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso30win32client.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4549.1000

Product : Microsoft Office 2016
KB : 3203383
- C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\epsimp32.flt has not been patched.
Remote version : 2012.1600.4266.1001
Should be : 2012.1600.4540.1000

Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4549.1000

Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4549.1002
100103 - Security Update for Microsoft Office Products (May 2017)
-
Synopsis
An application installed on the remote Windows host is affected by multiple vulnerabilities.
Description
The Microsoft Office application, Office Web Apps, or SharePoint Server installed on the remote Windows host is missing a security update. It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists in Microsoft Office software due to improper handling of objects in memory. An unauthenticated, remote attacker can exploit this, by convincing a user to open a specially crafted Office document, to execute arbitrary code in the context of the current user. (CVE-2017-0254)

- A cross-site scripting (XSS) vulnerability exists in Microsoft SharePoint Server due improper validation of user-supplied input in web requests. An unauthenticated, remote attacker can exploit this, via a specially crafted request, to execute arbitrary script code in a user's browser session. (CVE-2017-0255)

- A remote code execution vulnerability exists in Microsoft Office due to improper handling of malformed graphics images. An unauthenticated, remote attacker can exploit this, by convincing a user to open a specially crafted EPS file, to execute arbitrary code in the context of the current user. (CVE-2017-0261)

- A remote code execution vulnerability exists in Microsoft Office when handling malformed graphics images. An unauthenticated, remote attacker can exploit this, by convincing a user to open a specially crafted EPS file or visit a specially crafted website, to execute arbitrary code. (CVE-2017-0262)

- A remote code execution vulnerability exists in Microsoft Office due to improper handling of objects in memory. An unauthenticated, remote attacker can exploit this, by convincing a user to open a specially crafted file, to execute arbitrary code in the context of the current user. (CVE-2017-0281)
See Also
Solution
Microsoft has released a set of patches for Microsoft Office 2007, 2010, 2013, and 2016; Microsoft Word 2007, 2010, 2013, and 2016; Skype for Business 2016; Microsoft Word Viewer; Microsoft Office Compatibility Pack; SharePoint Server 2010; SharePoint Enterprise Server 2013 and 2016; SharePoint Foundation 2013; Word Automation Services on Microsoft SharePoint Server 2010 and 2013; Microsoft Office Project Server 2013; Microsoft Office Web Apps Server 2010 and 2013; and Office Online Server.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.9
EPSS Score
0.9225
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
BID 98101
BID 98104
BID 98107
BID 98279
BID 98297
CVE CVE-2017-0254
CVE CVE-2017-0255
CVE CVE-2017-0261
CVE CVE-2017-0262
CVE CVE-2017-0281
MSKB 2596904
MSKB 3114375
MSKB 3118310
MSKB 3162040
MSKB 3162054
MSKB 3162069
MSKB 3172458
MSKB 3172475
MSKB 3172482
MSKB 3172532
MSKB 3172536
MSKB 3178633
MSKB 3178638
MSKB 3178729
MSKB 3191835
MSKB 3191836
MSKB 3191839
MSKB 3191841
MSKB 3191843
MSKB 3191858
MSKB 3191863
MSKB 3191865
MSKB 3191880
MSKB 3191881
MSKB 3191885
MSKB 3191886
MSKB 3191887
MSKB 3191888
MSKB 3191890
MSKB 3191895
MSKB 3191899
MSKB 3191904
MSKB 3191909
MSKB 3191913
MSKB 3191914
MSKB 3191915
XREF MSFT:MS17-2596904
XREF MSFT:MS17-3114375
XREF MSFT:MS17-3118310
XREF MSFT:MS17-3162040
XREF MSFT:MS17-3162054
XREF MSFT:MS17-3162069
XREF MSFT:MS17-3172458
XREF MSFT:MS17-3172475
XREF MSFT:MS17-3172482
XREF MSFT:MS17-3172532
XREF MSFT:MS17-3172536
XREF MSFT:MS17-3178633
XREF MSFT:MS17-3178638
XREF MSFT:MS17-3178729
XREF MSFT:MS17-3191835
XREF MSFT:MS17-3191836
XREF MSFT:MS17-3191839
XREF MSFT:MS17-3191841
XREF MSFT:MS17-3191843
XREF MSFT:MS17-3191858
XREF MSFT:MS17-3191863
XREF MSFT:MS17-3191865
XREF MSFT:MS17-3191880
XREF MSFT:MS17-3191881
XREF MSFT:MS17-3191885
XREF MSFT:MS17-3191886
XREF MSFT:MS17-3191887
XREF MSFT:MS17-3191888
XREF MSFT:MS17-3191890
XREF MSFT:MS17-3191895
XREF MSFT:MS17-3191899
XREF MSFT:MS17-3191904
XREF MSFT:MS17-3191909
XREF MSFT:MS17-3191913
XREF MSFT:MS17-3191914
XREF MSFT:MS17-3191915
XREF IAVA:2017-A-0143-S
XREF CISA-KNOWN-EXPLOITED:2022/08/10
XREF CISA-KNOWN-EXPLOITED:2022/03/24
Exploitable With
Core Impact (true)
Plugin Information
Published: 2017/05/10, Modified: 2023/02/17
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 3191881
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4534.1000

Product : Microsoft Office 2016
KB : 3191863
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso99lres.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4519.1000

Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4534.1000
108969 - Security Updates for Microsoft Excel Products (April 2018)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-0920, CVE-2018-1011, CVE-2018-1027, CVE-2018-1029)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4018353
-KB4018350
-KB4018337
-KB4018362
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.9
EPSS Score
0.3741
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
CVE CVE-2018-0920
CVE CVE-2018-1011
CVE CVE-2018-1027
CVE CVE-2018-1029
MSKB 4018353
MSKB 4018350
MSKB 4018337
MSKB 4018362
XREF MSFT:MS18-4018353
XREF MSFT:MS18-4018350
XREF MSFT:MS18-4018337
XREF MSFT:MS18-4018362
Plugin Information
Published: 2018/04/10, Modified: 2024/11/11
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4678.1000
123949 - Security Updates for Microsoft Excel Products (April 2019)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update.
It is, therefore, affected by the following vulnerability :

- A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2019-0828)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4462230
-KB4462209
-KB4462236

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.2548
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2019-0828
MSKB 4462230
MSKB 4462209
MSKB 4462236
XREF MSFT:MS19-4462230
XREF MSFT:MS19-4462209
XREF MSFT:MS19-4462236
Plugin Information
Published: 2019/04/09, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4834.1000
135474 - Security Updates for Microsoft Excel Products (April 2020)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries. An attacker could then install programs;
view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. (CVE-2020-0760)

- A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-0906)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4484283
-KB4484273
-KB4484285

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.3457
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2020-0760
CVE CVE-2020-0906
CVE CVE-2020-0979
MSKB 4484283
MSKB 4484273
MSKB 4484285
XREF MSFT:MS20-4484283
XREF MSFT:MS20-4484273
XREF MSFT:MS20-4484285
XREF IAVA:2020-A-0144-S
Plugin Information
Published: 2020/04/14, Modified: 2024/03/19
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4993.1001
148470 - Security Updates for Microsoft Excel Products (April 2021)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing security updates. It is, therefore, affected by multiple vulnerabilities :

- Microsoft Office Remote Code Execution Vulnerability (CVE-2021-28449)

- Microsoft Excel Remote Code Execution Vulnerability (CVE-2021-28451, CVE-2021-28454, CVE-2021-28456) Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB3017810
-KB4504721
-KB4504735 For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.0347
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-28449
CVE CVE-2021-28451
CVE CVE-2021-28454
CVE CVE-2021-28456
MSKB 3017810
MSKB 4504721
MSKB 4504735
XREF MSFT:MS21-3017810
XREF MSFT:MS21-4504721
XREF MSFT:MS21-4504735
XREF IAVA:2021-A-0170-S
Plugin Information
Published: 2021/04/13, Modified: 2024/01/04
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5149.1000
159673 - Security Updates for Microsoft Excel Products (April 2022)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update.
It is, therefore, affected by the following vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2022-24473, CVE-2022-26901)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002175
-KB5002177

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.0054
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-24473
CVE CVE-2022-26901
MSKB 5002175
MSKB 5002177
XREF MSFT:MS22-5002175
XREF MSFT:MS22-5002177
XREF IAVA:2022-A-0140-S
Plugin Information
Published: 2022/04/12, Modified: 2023/11/02
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5305.1000
234032 - Security Updates for Microsoft Excel Products (April 2025)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. They are, therefore, affected by multiple remote code execution vulnerabilities. An attacker can exploit these to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002704 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.001
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-26642
CVE CVE-2025-27750
CVE CVE-2025-27751
MSKB 5002704
XREF MSFT:MS25-5002704
XREF IAVA:2025-A-0245-S
XREF CWE:125
XREF CWE:190
XREF CWE:416
Plugin Information
Published: 2025/04/08, Modified: 2025/09/17
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5495.1000
111694 - Security Updates for Microsoft Excel Products (August 2018)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities :

- An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the users computer or data. (CVE-2018-8382)

- A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-8375, CVE-2018-8379)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4032223
-KB4032229
-KB4032241
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.346
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2018-8375
CVE CVE-2018-8379
CVE CVE-2018-8382
MSKB 4032223
MSKB 4032229
MSKB 4032241
XREF MSFT:MS18-4032223
XREF MSFT:MS18-4032229
XREF MSFT:MS18-4032241
Plugin Information
Published: 2018/08/14, Modified: 2024/08/21
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4732.1000
139497 - Security Updates for Microsoft Excel Products (August 2020)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities :

- An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the users computer or data. (CVE-2020-1497)

- A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-1494, CVE-2020-1495, CVE-2020-1496, CVE-2020-1498, CVE-2020-1504)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4484465
-KB4484449
-KB4484461

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.1579
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-1494
CVE CVE-2020-1495
CVE CVE-2020-1496
CVE CVE-2020-1497
CVE CVE-2020-1498
CVE CVE-2020-1504
MSKB 4484465
MSKB 4484449
MSKB 4484461
XREF MSFT:MS20-4484465
XREF MSFT:MS20-4484449
XREF MSFT:MS20-4484461
XREF IAVA:2020-A-0365-S
XREF CEA-ID:CEA-2020-0101
Plugin Information
Published: 2020/08/11, Modified: 2024/12/02
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5044.1000
163949 - Security Updates for Microsoft Excel Products (August 2022)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. It is, therefore, affected by the following vulnerability:

- A security feature bypass vulnerability exists. An attacker can exploit this and bypass the security feature and perform unauthorized actions compromising the integrity of the system/application.
(CVE-2022-33631)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002242
-KB5002232

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
7.3 (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.4 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0057
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-33631
MSKB 5002242
MSKB 5002232
XREF MSFT:MS22-5002242
XREF MSFT:MS22-5002232
XREF IAVA:2022-A-0316-S
XREF IAVA:2022-A-0317-S
Plugin Information
Published: 2022/08/09, Modified: 2022/12/07
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5356.1000
179490 - Security Updates for Microsoft Excel Products (August 2023)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update.
It is, therefore, affected by the following vulnerability:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2023-36896)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002451
-KB5002463

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.0374
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-36896
MSKB 5002451
MSKB 5002463
XREF MSFT:MS23-5002451
XREF MSFT:MS23-5002463
XREF IAVA:2023-A-0405-S
XREF IAVA:2023-A-0419-S
Plugin Information
Published: 2023/08/08, Modified: 2023/09/18
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5408.1001
249128 - Security Updates for Microsoft Excel Products (August 2025)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. They are, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-53735, CVE-2025-53737, CVE-2025-53739, CVE-2025-53741)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002758 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0011
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-53735
CVE CVE-2025-53737
CVE CVE-2025-53739
CVE CVE-2025-53741
MSKB 5002758
XREF MSFT:MS25-5002758
XREF IAVA:2025-A-0594-S
XREF CWE:122
XREF CWE:416
XREF CWE:787
XREF CWE:843
Plugin Information
Published: 2025/08/12, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5513.1000
119592 - Security Updates for Microsoft Excel Products (December 2018)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities :

- An information disclosure vulnerability exists when Microsoft Excel software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory. An attacker who successfully exploited the vulnerability could view out of bound memory. Exploitation of the vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Excel software. The security update addresses the vulnerability by properly initializing the affected variable. (CVE-2018-8627)

- A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-8597, CVE-2018-8636)

- An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the users computer or data. (CVE-2018-8598)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4461577
-KB4461559
-KB4461542
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.3134
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2018-8597
CVE CVE-2018-8598
CVE CVE-2018-8627
CVE CVE-2018-8636
MSKB 4461577
MSKB 4461559
MSKB 4461542
XREF MSFT:MS18-4461577
XREF MSFT:MS18-4461559
XREF MSFT:MS18-4461542
Plugin Information
Published: 2018/12/11, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4783.1000
143564 - Security Updates for Microsoft Excel Products (December 2020)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2020-17123, CVE-2020-17125, CVE-2020-17127, CVE-2020-17128, CVE-2020-17129)

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2020-17126)

- A security feature bypass vulnerability exists. An attacker can exploit this and bypass the security feature and perform unauthorized actions compromising the integrity of the system/application.
(CVE-2020-17130)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4493148
-KB4486754
-KB4493139

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0398
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-17123
CVE CVE-2020-17125
CVE CVE-2020-17126
CVE CVE-2020-17127
CVE CVE-2020-17128
CVE CVE-2020-17129
CVE CVE-2020-17130
MSKB 4493148
MSKB 4493139
MSKB 4486754
XREF MSFT:MS20-4493148
XREF MSFT:MS20-4493139
XREF MSFT:MS20-4486754
XREF IAVA:2020-A-0556-S
XREF IAVA:2021-A-0017-S
XREF CEA-ID:CEA-2020-0138
Plugin Information
Published: 2020/12/08, Modified: 2024/02/06
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5095.1000
156074 - Security Updates for Microsoft Excel Products (December 2021)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update.
It is, therefore, affected by the following vulnerability:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2021-43256)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002098
-KB5002105

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0062
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-43256
MSKB 5002098
MSKB 5002105
XREF MSFT:MS21-5002098
XREF MSFT:MS21-5002105
XREF IAVA:2021-A-0578-S
Plugin Information
Published: 2021/12/14, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5254.1000
212238 - Security Updates for Microsoft Excel Products (December 2024)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. It is, therefore, affected by the following vulnerability:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2024-49069)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002660 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0013
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-49069
MSKB 5002660
XREF MSFT:MS24-5002660
XREF IAVA:2024-A-0806-S
Plugin Information
Published: 2024/12/10, Modified: 2025/01/17
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5478.1002
277999 - Security Updates for Microsoft Excel Products (December 2025)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. They are, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-62553, CVE-2025-62564, CVE-2025-62563, CVE-2025-62556, CVE-2025-62561, CVE-2025-62560)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002820 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0008
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-62553
CVE CVE-2025-62556
CVE CVE-2025-62560
CVE CVE-2025-62561
CVE CVE-2025-62563
CVE CVE-2025-62564
MSKB 5002820
XREF MSFT:MS25-5002820
XREF IAVA:2025-A-0912
Plugin Information
Published: 2025/12/09, Modified: 2025/12/12
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5530.1000
133616 - Security Updates for Microsoft Excel Products (February 2020)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing a security update. It is, therefore, affected by the following vulnerability :

- A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
See Also
Solution
Microsoft has released the following security updates to address this issue:
- KB4484256
- KB4484265
- KB4484267

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.3291
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2020-0759
MSKB 4484256
MSKB 4484265
MSKB 4484267
XREF MSFT:MS20-4484256
XREF MSFT:MS20-4484265
XREF MSFT:MS20-4484267
Plugin Information
Published: 2020/02/11, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4966.1000
146336 - Security Updates for Microsoft Excel Products (February 2021)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2021-24067, CVE-2021-24068, CVE-2021-24069, CVE-2021-24070)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4493222
-KB4493211
-KB4493196

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0148
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-24067
CVE CVE-2021-24068
CVE CVE-2021-24069
CVE CVE-2021-24070
MSKB 4493222
MSKB 4493211
MSKB 4493196
XREF MSFT:MS21-4493222
XREF MSFT:MS21-4493211
XREF MSFT:MS21-4493196
XREF IAVA:2021-A-0067-S
Plugin Information
Published: 2021/02/09, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5122.1000
190488 - Security Updates for Microsoft Excel Products (February 2024)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. They are, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002536 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.0176
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-20673
MSKB 5002536
XREF MSFT:MS24-5002536
XREF IAVA:2024-A-0095-S
XREF IAVA:2024-A-0094-S
Plugin Information
Published: 2024/02/13, Modified: 2024/09/13
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5435.1000
216133 - Security Updates for Microsoft Excel Products (February 2025)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. It is, therefore, affected by multiple remote code execution vulnerabilities. An attacker can exploit these to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002687 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0009
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-21381
CVE CVE-2025-21386
CVE CVE-2025-21387
CVE CVE-2025-21390
CVE CVE-2025-21394
MSKB 5002687
XREF MSFT:MS25-5002687
XREF IAVA:2025-A-0105
XREF IAVA:2025-A-0104-S
XREF CWE:122
XREF CWE:416
XREF CWE:822
Plugin Information
Published: 2025/02/11, Modified: 2025/09/17
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5487.1000
105694 - Security Updates for Microsoft Excel Products (January 2018)
-
Synopsis
The Microsoft Excel Products are affected by a remote code execution vulnerability.
Description
The Microsoft Excel Products are missing a security update.
It is, therefore, affected by the following vulnerability :

- A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-0796)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4011602
-KB4011627
-KB4011639
-KB4011660
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.364
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
BID 102372
CVE CVE-2018-0796
MSKB 4011602
MSKB 4011627
MSKB 4011639
MSKB 4011660
XREF MSFT:MS17-4011602
XREF MSFT:MS17-4011627
XREF MSFT:MS17-4011639
XREF MSFT:MS17-4011660
XREF IAVA:2018-A-0009-S
Plugin Information
Published: 2018/01/09, Modified: 2025/11/10
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4639.1000
132867 - Security Updates for Microsoft Excel Products (January 2020)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-0650, CVE-2020-0651)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4484234
-KB4484217
-KB4484243 For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.3365
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2020-0650
CVE CVE-2020-0651
MSKB 4484234
MSKB 4484217
MSKB 4484243
XREF MSFT:MS20-4484234
XREF MSFT:MS20-4484217
XREF MSFT:MS20-4484243
Plugin Information
Published: 2020/01/14, Modified: 2024/04/01
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4954.1000
144879 - Security Updates for Microsoft Excel Products (January 2021)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2021-1713, CVE-2021-1714)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4493186
-KB4493165
-KB4493176

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0158
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-1713
CVE CVE-2021-1714
MSKB 4493186
MSKB 4493165
MSKB 4493176
XREF MSFT:MS21-4493186
XREF MSFT:MS21-4493165
XREF MSFT:MS21-4493176
XREF IAVA:2021-A-0016-S
XREF CEA-ID:CEA-2021-0001
Plugin Information
Published: 2021/01/12, Modified: 2022/12/07
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5110.1000
156628 - Security Updates for Microsoft Excel Products (January 2022)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. It is, therefore, affected by the following vulnerabilities:

- Two remote code execution vulnerabilities. An attacker can exploit these to bypass authentication and execute unauthorized arbitrary commands. (CVE-2022-21840, CVE-2022-21841)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002128
-KB5002114

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0776
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-21840
CVE CVE-2022-21841
MSKB 5002128
MSKB 5002114
XREF MSFT:MS22-5002128
XREF MSFT:MS22-5002114
XREF IAVA:2022-A-0008-S
Plugin Information
Published: 2022/01/11, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5266.1000
214133 - Security Updates for Microsoft Excel Products (January 2025)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. It is, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002673 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
8.4 (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.3 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0032
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-21362
MSKB 5002673
XREF MSFT:MS25-5002673
XREF IAVA:2025-A-0032-S
XREF CWE:416
Plugin Information
Published: 2025/01/14, Modified: 2025/09/17
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5483.1000
126580 - Security Updates for Microsoft Excel Products (July 2019)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing security updates. They are, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. (CVE-2019-1110, CVE-2019-1111)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4464565
-KB4464572
-KB4475513 For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.2706
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
BID 108967
BID 108974
CVE CVE-2019-1110
CVE CVE-2019-1111
MSKB 4464565
MSKB 4464572
MSKB 4475513
XREF MSFT:MS19-4464565
XREF MSFT:MS19-4464572
XREF MSFT:MS19-4475513
Plugin Information
Published: 2019/07/09, Modified: 2024/05/10
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4873.1000
151609 - Security Updates for Microsoft Excel Products (July 2021)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing security updates. It is, therefore, affected by multiple remote code execution vulnerabilities. An attacker can exploit these to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5001993
-KB5001977

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.1219
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-34501
CVE CVE-2021-34518
MSKB 5001993
MSKB 5001977
XREF MSFT:MS21-5001993
XREF MSFT:MS21-5001977
XREF IAVA:2021-A-0314-S
Plugin Information
Published: 2021/07/13, Modified: 2023/12/29
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5188.1000
241564 - Security Updates for Microsoft Excel Products (July 2025)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. They are, therefore, affected by multiple vulnerabilities:

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2025-48812)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-49697, CVE-2025-49711)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002749 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
8.4 (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0006
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-48812
CVE CVE-2025-49697
CVE CVE-2025-49711
MSKB 5002749
XREF MSFT:MS25-5002749
XREF IAVA:2025-A-0487-S
XREF CWE:122
XREF CWE:125
XREF CWE:416
Plugin Information
Published: 2025/07/08, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5508.1001
150371 - Security Updates for Microsoft Excel Products (June 2021)
-
Synopsis
The Microsoft Excel Products are affected by a remote code execution vulnerability.
Description
The Microsoft Excel Products are missing security updates. It is, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5001947
-KB5001963 For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.0713
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-31939
MSKB 5001963
MSKB 5001947
XREF MSFT:MS21-5001963
XREF MSFT:MS21-5001947
XREF IAVA:2021-A-0272-S
Plugin Information
Published: 2021/06/08, Modified: 2023/12/27
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5173.1000
162204 - Security Updates for Microsoft Excel Products (June 2022)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing a security update. It is, therefore, affected by the following vulnerability:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2022-30173) Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002220
-KB5002208
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0085
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-30173
MSKB 5002208
MSKB 5002220
XREF MSFT:MS22-5002208
XREF MSFT:MS22-5002220
XREF IAVA:2022-A-0238-S
Plugin Information
Published: 2022/06/14, Modified: 2023/10/20
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5332.1000
177248 - Security Updates for Microsoft Excel Products (June 2023)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing security updates. They are, therefore, affected by multiple remote code execution vulnerabilities. An attacker can exploit these to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002405
-KB5002414
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.3896
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-32029
CVE CVE-2023-33133
CVE CVE-2023-33137
MSKB 5002405
MSKB 5002414
XREF MSFT:MS23-5002405
XREF MSFT:MS23-5002414
XREF IAVA:2023-A-0292-S
Plugin Information
Published: 2023/06/13, Modified: 2023/07/13
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5400.1000
238089 - Security Updates for Microsoft Excel Products (June 2025)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. They are, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002735 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0006
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-47165
MSKB 5002735
XREF MSFT:MS25-5002735
XREF IAVA:2025-A-0413-S
XREF CWE:416
Plugin Information
Published: 2025/06/10, Modified: 2025/09/17
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5504.1000
147225 - Security Updates for Microsoft Excel Products (March 2021)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2021-27053, CVE-2021-27054, CVE-2021-27057)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4504707
-KB4493239
-KB4493233

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.0487
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-27053
CVE CVE-2021-27054
CVE CVE-2021-27057
MSKB 4504707
MSKB 4493239
MSKB 4493233
XREF MSFT:MS21-4504707
XREF MSFT:MS21-4493239
XREF MSFT:MS21-4493233
XREF IAVA:2021-A-0135-S
Plugin Information
Published: 2021/03/09, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5134.1000
172522 - Security Updates for Microsoft Excel Products (March 2023)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing security updates. They are, therefore, affected by multiple vulnerabilities:

- A session spoofing vulnerability exists. An attacker can exploit this to perform actions with the privileges of another user. (CVE-2023-23398)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2023-23399)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002348
-KB5002351

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.02
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-23398
CVE CVE-2023-23399
MSKB 5002348
MSKB 5002351
XREF MSFT:MS23-5002348
XREF MSFT:MS23-5002351
XREF IAVA:2023-A-0136-S
Plugin Information
Published: 2023/03/14, Modified: 2023/05/11
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5387.1000
232614 - Security Updates for Microsoft Excel Products (March 2025)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. They are, therefore, affected by multiple remote code execution vulnerabilities. An attacker can exploit these to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002696 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
5.9
EPSS Score
0.0008
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-24075
CVE CVE-2025-24081
CVE CVE-2025-24082
MSKB 5002696
XREF MSFT:MS25-5002696
XREF IAVA:2025-A-0171-S
XREF IAVA:2025-A-0174-S
XREF IAVA:2025-A-0177-S
XREF CWE:121
XREF CWE:416
Plugin Information
Published: 2025/03/11, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5491.1000
109612 - Security Updates for Microsoft Excel Products (May 2018)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities :
- A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-8147, CVE-2018-8148, CVE-2018-8162)
- An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. (CVE-2018-8163)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4022146
-KB4018399
-KB4018382
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.9
EPSS Score
0.3391
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2018-8147
CVE CVE-2018-8148
CVE CVE-2018-8162
CVE CVE-2018-8163
MSKB 4022146
MSKB 4018399
MSKB 4018382
XREF MSFT:MS18-4022146
XREF MSFT:MS18-4018399
XREF MSFT:MS18-4018382
XREF IAVA:2018-A-0151-S
Plugin Information
Published: 2018/05/08, Modified: 2024/10/11
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4690.1000
149397 - Security Updates for Microsoft Excel Products (May 2021)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2021-31175, CVE-2021-31177, CVE-2021-31179)

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2021-31174, CVE-2021-31178)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5001918
-KB5001936

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.2555
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-31174
CVE CVE-2021-31175
CVE CVE-2021-31177
CVE CVE-2021-31178
CVE CVE-2021-31179
MSKB 5001918
MSKB 5001936
XREF MSFT:MS21-5001918
XREF IAVA:2021-A-0228-S
XREF MSFT:MS21-5001936
Plugin Information
Published: 2021/05/11, Modified: 2024/01/02
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5161.1000
160940 - Security Updates for Microsoft Excel Products (May 2022)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. It is, therefore, affected by the following vulnerability:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2022-29110)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002196
-KB5002204

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0094
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.7 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-29110
MSKB 5002196
MSKB 5002204
XREF MSFT:MS22-5002196
XREF MSFT:MS22-5002204
XREF IAVA:2022-A-0193-S
Plugin Information
Published: 2022/05/10, Modified: 2023/10/27
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5317.1000
175337 - Security Updates for Microsoft Excel Products (May 2023)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. They are, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002384
-KB5002386
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.0374
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-24953
MSKB 5002384
MSKB 5002386
XREF MSFT:MS23-5002384
XREF MSFT:MS23-5002386
XREF IAVA:2023-A-0245-S
Plugin Information
Published: 2023/05/09, Modified: 2023/06/16
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5395.1000
197013 - Security Updates for Microsoft Excel Products (May 2024)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. They are, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002587 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0101
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-30042
MSKB 5002587
XREF MSFT:MS24-5002587
XREF IAVA:2024-A-0283-S
Plugin Information
Published: 2024/05/14, Modified: 2024/09/13
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5448.1000
235850 - Security Updates for Microsoft Excel Products (May 2025)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. They are, therefore, affected by multiple remote code execution vulnerabilities. An attacker can exploit these to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002717 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0012
CVSS v2.0 Base Score
6.6 (CVSS2#AV:L/AC:M/Au:S/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-29977
CVE CVE-2025-29979
CVE CVE-2025-30375
CVE CVE-2025-30376
CVE CVE-2025-30379
CVE CVE-2025-30381
CVE CVE-2025-30383
MSKB 5002717
XREF MSFT:MS25-5002717
XREF IAVA:2025-A-0332-S
XREF CWE:122
XREF CWE:125
XREF CWE:416
XREF CWE:763
XREF CWE:787
XREF CWE:822
XREF CWE:843
Plugin Information
Published: 2025/05/13, Modified: 2025/09/17
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5500.1000
104556 - Security Updates for Microsoft Excel Products (November 2017)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2017-11878)

- A security feature bypass vulnerability exists in Microsoft Office software by not enforcing macro settings on an Excel document. The security feature bypass by itself does not allow arbitrary code execution. To successfully exploit the vulnerability, an attacker would have to embed a control in an Excel worksheet that specifies a macro should be run.
(CVE-2017-11877)

- A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Exploitation of the vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Office. In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and convincing the user to open the file. In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) containing a specially crafted file designed to exploit the vulnerability. An attacker would have no way to force users to visit the website. Instead, an attacker would have to convince users to click a link, typically by way of an enticement in an email or instant message, and then convince them to open the specially crafted file. (CVE-2017-11884)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4011197
-KB4011220
-KB4011233
-KB4011199
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.5562
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
BID 100734
BID 100751
BID 101766
CVE CVE-2017-11877
CVE CVE-2017-11878
CVE CVE-2017-11884
MSKB 4011197
MSKB 4011220
MSKB 4011233
MSKB 4011199
XREF MSFT:MS17-4011197
XREF MSFT:MS17-4011220
XREF MSFT:MS17-4011233
XREF MSFT:MS17-4011199
XREF IAVA:2017-A-0337-S
Plugin Information
Published: 2017/11/14, Modified: 2021/06/03
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4615.1000
118921 - Security Updates for Microsoft Excel Products (November 2018)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-8574, CVE-2018-8577)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4461503
-KB4461530
-KB4461488
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.2281
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
BID 105833
BID 105834
CVE CVE-2018-8574
CVE CVE-2018-8577
MSKB 4461503
MSKB 4461530
MSKB 4461488
XREF MSFT:MS18-4461503
XREF MSFT:MS18-4461530
XREF MSFT:MS18-4461488
Plugin Information
Published: 2018/11/13, Modified: 2024/07/22
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4771.1000
130911 - Security Updates for Microsoft Excel Products (November 2019)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2019-1448)

- An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the users computer or data. (CVE-2019-1446)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4484164
-KB4484158
-KB4484144 For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.3802
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2019-1446
CVE CVE-2019-1448
MSKB 4484164
MSKB 4484158
MSKB 4484144
XREF MSFT:MS19-4484164
XREF MSFT:MS19-4484158
XREF MSFT:MS19-4484144
Plugin Information
Published: 2019/11/12, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4927.1000
142685 - Security Updates for Microsoft Excel Products (November 2020)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Excel installation on the remote host is missing a security update. It is, therefore, affected by an unspecified remote code execution vulnerability. An attacker can exploit this vulnerability by tricking a user into opening a specially crafted Office file.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4486718
-KB4486743
-KB4486734

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.046
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2020-17064
CVE CVE-2020-17065
CVE CVE-2020-17066
CVE CVE-2020-17067
MSKB 4486718
MSKB 4486743
MSKB 4486734
XREF MSFT:MS20-4486718
XREF MSFT:MS20-4486743
XREF MSFT:MS20-4486734
XREF CEA-ID:CEA-2020-0135
Plugin Information
Published: 2020/11/10, Modified: 2024/02/09
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5083.1000
154982 - Security Updates for Microsoft Excel Products (November 2021)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities:

- A security feature bypass vulnerability exists. An attacker can exploit this and bypass the security feature and perform unauthorized actions compromising the integrity of the system/application.
(CVE-2021-42292)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2021-40442)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002056
-KB5002072
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.2
EPSS Score
0.1301
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.9 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-40442
CVE CVE-2021-42292
MSKB 5002056
MSKB 5002072
XREF MSFT:MS21-5002056
XREF MSFT:MS21-5002072
XREF CISA-KNOWN-EXPLOITED:2021/12/01
XREF IAVA:2021-A-0541-S
Plugin Information
Published: 2021/11/09, Modified: 2024/04/01
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5239.1001
167108 - Security Updates for Microsoft Excel Products (November 2022)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing security updates. It is, therefore, affected by multiple vulnerabilities:

- A security feature bypass vulnerability exists. An attacker can exploit this and bypass the security feature and perform unauthorized actions compromising the integrity of the system/application.
(CVE-2022-41104)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2022-41063, CVE-2022-41106)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002253
-KB5002275

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0362
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-41063
CVE CVE-2022-41104
CVE CVE-2022-41106
MSKB 5002275
MSKB 5002253
XREF MSFT:MS22-5002275
XREF MSFT:MS22-5002253
XREF IAVA:2022-A-0476-S
Plugin Information
Published: 2022/11/08, Modified: 2023/10/05
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5369.1000
185586 - Security Updates for Microsoft Excel Products (November 2023)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing security updates. It is, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2023-36041)

- A security feature bypass vulnerability exists. An attacker can exploit this and bypass the security feature and perform unauthorized actions compromising the integrity of the system/application.
(CVE-2023-36037)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002518 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0337
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-36037
CVE CVE-2023-36041
MSKB 5002518
XREF MSFT:MS23-5002518
XREF IAVA:2023-A-0620-S
Plugin Information
Published: 2023/11/14, Modified: 2024/02/16
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5422.1000
210854 - Security Updates for Microsoft Excel Products (November 2024)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. They are, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2024-49026, CVE-2024-49027, CVE-2024-49028, CVE-2024-49029, CVE-2024-49030)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002653 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0049
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-49026
CVE CVE-2024-49027
CVE CVE-2024-49028
CVE CVE-2024-49029
CVE CVE-2024-49030
MSKB 5002653
XREF MSFT:MS24-5002653
XREF IAVA:2024-A-0733-S
Plugin Information
Published: 2024/11/12, Modified: 2024/12/13
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5474.1000
274788 - Security Updates for Microsoft Excel Products (Novermber 2025)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. They are, therefore, affected by multiple vulnerabilities:

- Microsoft Excel allows an unauthorized attacker to disclose information locally.
(CVE-2025-59240, CVE-2025-62200, CVE-2025-62201, CVE-2025-62202, CVE-2025-62203, CVE-2025-60726)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-62199, CVE-2025-60727)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002811 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0006
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-59240
CVE CVE-2025-62200
CVE CVE-2025-62201
CVE CVE-2025-62202
CVE CVE-2025-62203
CVE CVE-2025-60726
CVE CVE-2025-60727
MSKB 5002811
XREF MSFT:MS25-5002811
XREF IAVA:2025-A-0845
XREF CWE:125
XREF CWE:416
XREF CWE:843
Plugin Information
Published: 2025/11/11, Modified: 2025/11/14
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5526.1002
118007 - Security Updates for Microsoft Excel Products (October 2018)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update.
It is, therefore, affected by the following vulnerability :

- A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in Protected View. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-8502)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4461466
-KB4461460
-KB4461448
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.2612
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2018-8502
MSKB 4461466
MSKB 4461460
MSKB 4461448
XREF MSFT:MS18-4461466
XREF MSFT:MS18-4461460
XREF MSFT:MS18-4461448
Plugin Information
Published: 2018/10/09, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4756.1000
129727 - Security Updates for Microsoft Excel Products (October 2019)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2019-1327, CVE-2019-1331)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4484123
-KB4484130
-KB4484112 For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.3831
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2019-1327
CVE CVE-2019-1331
MSKB 4484123
MSKB 4484130
MSKB 4484112
XREF MSFT:MS19-4484123
XREF MSFT:MS19-4484130
XREF MSFT:MS19-4484112
Plugin Information
Published: 2019/10/08, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4912.1000
141417 - Security Updates for Microsoft Excel Products (October 2020)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-16929, CVE-2020-16931, CVE-2020-16932)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4486695
-KB4486678
-KB4486707

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0652
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-16929
CVE CVE-2020-16931
CVE CVE-2020-16932
MSKB 4486695
MSKB 4486678
MSKB 4486707
XREF MSFT:MS20-4486695
XREF MSFT:MS20-4486678
XREF MSFT:MS20-4486707
XREF IAVA:2020-A-0462-S
XREF CEA-ID:CEA-2020-0126
Plugin Information
Published: 2020/10/13, Modified: 2022/12/05
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5071.1000
154027 - Security Updates for Microsoft Excel Products (October 2021)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2021-40474, CVE-2021-40485)

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2021-40472)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002030
-KB5002043

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0301
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-40471
CVE CVE-2021-40472
CVE CVE-2021-40473
CVE CVE-2021-40474
CVE CVE-2021-40479
CVE CVE-2021-40485
MSKB 5002030
MSKB 5002043
XREF MSFT:MS21-5002030
XREF MSFT:MS21-5002043
XREF IAVA:2021-A-0468-S
XREF IAVA:2021-A-0465-S
Plugin Information
Published: 2021/10/12, Modified: 2023/11/28
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5227.1000
208288 - Security Updates for Microsoft Excel Products (October 2024)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. They are, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002643 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.1222
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-43504
MSKB 5002643
XREF MSFT:MS24-5002643
XREF IAVA:2024-A-0633-S
Plugin Information
Published: 2024/10/08, Modified: 2024/11/15
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5469.1000
270389 - Security Updates for Microsoft Excel Products (October 2025)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. They are, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-59223, CVE-2025-59224, CVE-2025-59225, CVE-2025-59231, CVE-2025-59233)

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2025-59232, CVE-2025-59235)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002794 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0011
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-59223
CVE CVE-2025-59224
CVE CVE-2025-59225
CVE CVE-2025-59231
CVE CVE-2025-59232
CVE CVE-2025-59233
CVE CVE-2025-59235
MSKB 5002794
XREF MSFT:MS25-5002794
XREF IAVA:2025-A-0756-S
XREF CWE:125
XREF CWE:416
XREF CWE:843
Plugin Information
Published: 2025/10/14, Modified: 2025/11/18
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5522.1000
128645 - Security Updates for Microsoft Excel Products (September 2019)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2019-1297)

- An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the users computer or data. (CVE-2019-1263)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4475566
-KB4475574
-KB4475579 For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.3084
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.7 (CVSS2#E:F/RL:OF/RC:C)
References
CVE CVE-2019-1263
CVE CVE-2019-1297
MSKB 4475566
MSKB 4475574
MSKB 4475579
XREF MSFT:MS19-4475566
XREF MSFT:MS19-4475574
XREF MSFT:MS19-4475579
XREF CISA-KNOWN-EXPLOITED:2022/03/17
Plugin Information
Published: 2019/09/10, Modified: 2023/04/25
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4900.1000
140426 - Security Updates for Microsoft Excel Products (September 2020)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities :

- An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the users computer or data. (CVE-2020-1224)

- A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-1332, CVE-2020-1335, CVE-2020-1594)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4484507
-KB4484526
-KB4486665

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.2188
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-1224
CVE CVE-2020-1332
CVE CVE-2020-1335
CVE CVE-2020-1594
MSKB 4484507
MSKB 4484526
MSKB 4486665
XREF MSFT:MS20-4484507
XREF MSFT:MS20-4484526
XREF MSFT:MS20-4486665
XREF IAVA:2020-A-0405-S
XREF CEA-ID:CEA-2020-0118
Plugin Information
Published: 2020/09/08, Modified: 2024/11/29
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5056.1000
153380 - Security Updates for Microsoft Excel Products (September 2021)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2021-38655, CVE-2021-38660)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002003
-KB5002014

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0563
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-38655
CVE CVE-2021-38660
MSKB 5002003
MSKB 5002014
XREF MSFT:MS21-5002003
XREF MSFT:MS21-5002014
XREF IAVA:2021-A-0425-S
Plugin Information
Published: 2021/09/14, Modified: 2023/11/30
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5215.1000
206903 - Security Updates for Microsoft Excel Products (September 2024)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. It is, therefore, affected by the following vulnerability:

- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges.
(CVE-2024-43465)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002605 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0036
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-43465
MSKB 5002605
XREF MSFT:MS24-5002605
XREF IAVA:2024-A-0564-S
XREF IAVA:2024-A-0562-S
Plugin Information
Published: 2024/09/10, Modified: 2024/10/11
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5465.1000
261813 - Security Updates for Microsoft Excel Products (September 2025)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. They are, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-54896, CVE-2025-54898, CVE-2025-54899, CVE-2025-54900, CVE-2025-54902, CVE-2025-54903, CVE-2025-54904)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002782 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0006
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-54896
CVE CVE-2025-54898
CVE CVE-2025-54899
CVE CVE-2025-54900
CVE CVE-2025-54902
CVE CVE-2025-54903
CVE CVE-2025-54904
MSKB 5002782
XREF MSFT:MS25-5002782
XREF IAVA:2025-A-0664-S
XREF CWE:122
XREF CWE:125
XREF CWE:416
XREF CWE:590
Plugin Information
Published: 2025/09/09, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5517.1000
108972 - Security Updates for Microsoft Office Products (April 2018)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities :

- An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the users computer or data. (CVE-2018-1007)

- An information disclosure vulnerability exists when Office renders Rich Text Format (RTF) email messages containing OLE objects when a message is opened or previewed. This vulnerability could potentially result in the disclosure of sensitive information to a malicious site. (CVE-2018-0950)

- A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-1026, CVE-2018-1030)

- A remote code execution vulnerability exists when the Office graphics component improperly handles specially crafted embedded fonts. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-1028)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4018357
-KB4011628
-KB4018330
-KB4018319
-KB4018288
-KB4018328
-KB4018311
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.4743
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2018-0950
CVE CVE-2018-1007
CVE CVE-2018-1026
CVE CVE-2018-1028
CVE CVE-2018-1030
MSKB 4018357
MSKB 4011628
MSKB 4018330
MSKB 4018319
MSKB 4018288
MSKB 4018328
MSKB 4018311
XREF MSFT:MS18-4018357
XREF MSFT:MS18-4011628
XREF MSFT:MS18-4018330
XREF MSFT:MS18-4018319
XREF MSFT:MS18-4018288
XREF MSFT:MS18-4018328
XREF MSFT:MS18-4018311
Plugin Information
Published: 2018/04/10, Modified: 2024/11/11
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4018328
- C:\Program Files\Common Files\Microsoft Shared\OFFICE16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4678.1000
123952 - Security Updates for Microsoft Office Products (April 2019)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists when Microsoft Office fails to properly handle certain files.
(CVE-2019-0801)

- A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. (CVE-2019-0822)

- A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Microsoft Office Access Connectivity Engine handles objects in memory.
(CVE-2019-0823, CVE-2019-0824, CVE-2019-0825, CVE-2019-0826, CVE-2019-0827)

- A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2019-0828)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4462223
-KB4464504
-KB4462204
-KB4464520
-KB4462213
-KB4462242

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.2823
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2019-0801
CVE CVE-2019-0822
CVE CVE-2019-0823
CVE CVE-2019-0824
CVE CVE-2019-0825
CVE CVE-2019-0826
CVE CVE-2019-0827
CVE CVE-2019-0828
MSKB 4462223
MSKB 4464504
MSKB 4462204
MSKB 4464520
MSKB 4462213
MSKB 4462242
XREF MSFT:MS19-4462223
XREF MSFT:MS19-4464504
XREF MSFT:MS19-4462204
XREF MSFT:MS19-4464520
XREF MSFT:MS19-4462213
XREF MSFT:MS19-4462242
Plugin Information
Published: 2019/04/09, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4462213
- C:\Program Files\Common Files\Microsoft Shared\Office16\acecore.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4831.1000

Product : Microsoft Office 2016
KB : 4462242
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4834.1000
135476 - Security Updates for Microsoft Office Products (April 2020)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries. An attacker could then install programs;
view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. (CVE-2020-0760)

- A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the same permissions as the current user. (CVE-2020-0980)

- A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-0991)

- A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Microsoft Office Access Connectivity Engine handles objects in memory.
(CVE-2020-0961)

- A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-0906, CVE-2020-0979)
See Also
Solution
Microsoft has released security updates for Microsoft Office Products.

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.4016
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2020-0760
CVE CVE-2020-0906
CVE CVE-2020-0961
CVE CVE-2020-0979
CVE CVE-2020-0980
CVE CVE-2020-0991
MSKB 3128012
MSKB 3203462
MSKB 4011104
MSKB 4484117
MSKB 4484126
MSKB 4484214
MSKB 4484229
MSKB 4484238
MSKB 4484258
MSKB 4484260
MSKB 4484266
MSKB 4484287
MSKB 4484294
XREF MSFT:MS20-3128012
XREF MSFT:MS20-3203462
XREF MSFT:MS20-4011104
XREF MSFT:MS20-4484117
XREF MSFT:MS20-4484126
XREF MSFT:MS20-4484214
XREF MSFT:MS20-4484229
XREF MSFT:MS20-4484238
XREF MSFT:MS20-4484258
XREF MSFT:MS20-4484260
XREF MSFT:MS20-4484266
XREF MSFT:MS20-4484287
XREF MSFT:MS20-4484294
XREF IAVA:2020-A-0142-S
Plugin Information
Published: 2020/04/14, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 3128012
- C:\Program Files\Common Files\Microsoft Shared\VBA\VBA7.1\vbe7.dll has not been patched.
Remote version : 7.1.10.48
Should be : 7.1.10.96

Product : Microsoft Office 2016
KB : 4484214
- C:\Program Files\Common Files\Microsoft Shared\OFFICE16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4993.1002

Product : Microsoft Office 2016
KB : 4484287
- C:\Program Files\Common Files\Microsoft Shared\OFFICE16\acecore.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4993.1000

Product : Microsoft Office 2016
KB : 4484258
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4993.1000
148474 - Security Updates for Microsoft Office Products (April 2021)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft office Product is missing security updates. It is, therefore, affected by multiple vulnerabilities:

- Microsoft Office Remote Code Execution Vulnerability (CVE-2021-28449)

- Microsoft Word Remote Code Execution Vulnerability (CVE-2021-28453)

- Microsoft Excel Remote Code Execution Vulnerability (CVE-2021-28454)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB2553491
-KB2589361
-KB3178639
-KB3178643
-KB4504738
-KB4504722
-KB4504726
-KB4504724
-KB4504739
-KB4504727
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.0274
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-28449
CVE CVE-2021-28453
CVE CVE-2021-28454
MSKB 2553491
MSKB 2589361
MSKB 3178639
MSKB 3178643
MSKB 4493215
MSKB 4504738
MSKB 4504722
MSKB 4504726
MSKB 4504724
MSKB 4504739
MSKB 4504727
XREF MSFT:MS21-2553491
XREF MSFT:MS21-2589361
XREF MSFT:MS21-3178639
XREF MSFT:MS21-3178643
XREF MSFT:MS21-4493215
XREF MSFT:MS21-4504738
XREF MSFT:MS21-4504722
XREF MSFT:MS21-4504726
XREF MSFT:MS21-4504724
XREF MSFT:MS21-4504739
XREF MSFT:MS21-4504727
XREF IAVA:2021-A-0174-S
Plugin Information
Published: 2021/04/13, Modified: 2024/01/04
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4504722
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5149.1000

Product : Microsoft Office 2016
KB : 4504724
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5149.1000
159683 - Security Updates for Microsoft Office Products (April 2022)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates.
It is, therefore, affected by the following vulnerability:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2022-24473, CVE-2022-26901)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002143
-KB5002148

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.0054
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-24473
CVE CVE-2022-26901
MSKB 5002143
MSKB 5002148
XREF MSFT:MS22-5002143
XREF MSFT:MS22-5002148
XREF IAVA:2022-A-0144-S
Plugin Information
Published: 2022/04/12, Modified: 2023/11/02
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002143
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5305.1000
234041 - Security Updates for Microsoft Office Products (April 2025)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. They are, therefore, affected by multiple vulnerabilities:

- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges.
(CVE-2025-29792)

- A security feature bypass vulnerability exists. An attacker can exploit this and bypass the security feature and perform unauthorized actions compromising the integrity of the system/application.
(CVE-2025-29816)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-26642, CVE-2025-27745, CVE-2025-27746, CVE-2025-27748, CVE-2025-27749, CVE-2025-27752, CVE-2025-29791)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following updates to address these issues:
- KB4484432
- KB5002573
- KB5002588
- KB5002700
- KB5002703
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0015
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-26642
CVE CVE-2025-27745
CVE CVE-2025-27746
CVE CVE-2025-27748
CVE CVE-2025-27749
CVE CVE-2025-27752
CVE CVE-2025-29791
CVE CVE-2025-29792
CVE CVE-2025-29816
MSKB 4484432
MSKB 5002573
MSKB 5002588
MSKB 5002700
MSKB 5002703
XREF MSFT:MS25-4484432
XREF MSFT:MS25-5002573
XREF MSFT:MS25-5002588
XREF MSFT:MS25-5002700
XREF MSFT:MS25-5002703
XREF IAVA:2025-A-0245-S
XREF IAVA:2025-A-0246-S
XREF IAVA:2025-A-0244-S
XREF CWE:122
XREF CWE:125
XREF CWE:190
XREF CWE:349
XREF CWE:416
XREF CWE:843
Plugin Information
Published: 2025/04/08, Modified: 2025/09/17
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002588
- C:\Program Files\Common Files\Microsoft Shared\Office16\aceexcl.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5404.1000

Product : Microsoft Office 2016
KB : 4484432
- C:\Program Files\Microsoft Office\Office16\chart.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5495.1000

Product : Microsoft Office 2016
KB : 5002703
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5495.1000

Product : Microsoft Office 2016
KB : 5002700
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5495.1002

Product : Microsoft Office 2016
KB : 5002573
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso30win32client.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5495.1002
127853 - Security Updates for Microsoft Office Products (August 2019)
-
Synopsis
A Microsoft Office product is affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the same permissions as the current user. (CVE-2019-1200)

- A remote code execution vulnerability exists in Microsoft Outlook when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2019-1199)

- An elevation of privilege vulnerability exists when Microsoft Outlook initiates processing of incoming messages without sufficient validation of the formatting of the messages. An attacker who successfully exploited the vulnerability could attempt to force Outlook to load a local or remote message store (over SMB).
(CVE-2019-1204)

- A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the same permissions as the current user. (CVE-2019-1201, CVE-2019-1205)

- A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Windows Jet Database Engine handles objects in memory. (CVE-2019-1155)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4475531
-KB4475538
-KB4475506
-KB4464599 For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.1249
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2019-1155
CVE CVE-2019-1199
CVE CVE-2019-1200
CVE CVE-2019-1201
CVE CVE-2019-1204
CVE CVE-2019-1205
MSKB 4475531
MSKB 4475538
MSKB 4475506
MSKB 4464599
XREF MSFT:MS19-4475531
XREF MSFT:MS19-4475538
XREF MSFT:MS19-4475506
XREF MSFT:MS19-4464599
Plugin Information
Published: 2019/08/13, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4475538
- C:\Program Files\Common Files\Microsoft Shared\Office16\aceexcl.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4888.1000
139499 - Security Updates for Microsoft Office Products (August 2020)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-1494, CVE-2020-1495, CVE-2020-1496)

- An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the users computer or data. (CVE-2020-1497)

- An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the users computer or data. (CVE-2020-1503, CVE-2020-1583)

- A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-1563)

- An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) components handle objects in memory. An attacker who successfully exploited the vulnerability could elevate privileges. The attacker would need to already have the ability to execute code on the system.
(CVE-2020-1581)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4484346
-KB4484354
-KB4484359
-KB4484375
-KB4484379
-KB4484431
-KB4484492 For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.2252
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-1494
CVE CVE-2020-1495
CVE CVE-2020-1496
CVE CVE-2020-1497
CVE CVE-2020-1503
CVE CVE-2020-1563
CVE CVE-2020-1581
CVE CVE-2020-1583
MSKB 4484346
MSKB 4484354
MSKB 4484359
MSKB 4484375
MSKB 4484379
MSKB 4484431
MSKB 4484492
XREF MSFT:MS20-4484346
XREF MSFT:MS20-4484354
XREF MSFT:MS20-4484359
XREF MSFT:MS20-4484375
XREF MSFT:MS20-4484379
XREF MSFT:MS20-4484431
XREF MSFT:MS20-4484492
XREF IAVA:2020-A-0359-S
XREF IAVA:2020-A-0365-S
XREF IAVA:2020-A-0369-S
XREF CEA-ID:CEA-2020-0101
Plugin Information
Published: 2020/08/11, Modified: 2024/12/02
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4484346
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5044.1000

Product : Microsoft Office 2016
KB : 4484431
- C:\Program Files\Common Files\Microsoft Shared\OFFICE16\aceexcl.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5044.1000
163950 - Security Updates for Microsoft Office Products (August 2022)
-
Synopsis
The Microsoft Office Products are affected by a remote code execution vulnerability.
Description
The Microsoft Office Products are missing security updates. It is, therefore, affected by the following vulnerability:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2022-34717)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4462148
-KB4462142

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0256
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-34717
MSKB 4462148
MSKB 4462142
XREF MSFT:MS22-4462148
XREF MSFT:MS22-4462142
XREF IAVA:2022-A-0316-S
Plugin Information
Published: 2022/08/09, Modified: 2022/12/07
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4462148
- C:\Program Files\Microsoft Office\Office16\msohev.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5356.1000
249124 - Security Updates for Microsoft Office Products (August 2025)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. They are, therefore, affected by multiple vulnerabilities.

- A Remote Code Execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-53731, CVE-2025-53740)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following updates to address these issues:
- KB5002756
Risk Factor
High
CVSS v3.0 Base Score
8.4 (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0005
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-53731
CVE CVE-2025-53740
MSKB 5002756
XREF MSFT:MS25-5002756
XREF IAVA:2025-A-0596
XREF CWE:416
Plugin Information
Published: 2025/08/12, Modified: 2025/09/17
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002756
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5513.1000
131937 - Security Updates for Microsoft Office Products (December 2019)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities :

- An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the users computer or data. (CVE-2019-1464)

- A denial of service vulnerability exists in Microsoft Word software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could cause a remote denial of service against a system. Exploitation of the vulnerability requires that a specially crafted document be sent to a vulnerable user. The security update addresses the vulnerability by correcting how Microsoft Word handles objects in memory. (CVE-2019-1461)

- An information disclosure vulnerability exists in Microsoft Access software when the software fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system.
(CVE-2019-1400, CVE-2019-1463)

- A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2019-1462)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4484182
-KB4484180
-KB4484186
-KB4484193
-KB4484192
-KB4475598
-KB4484184

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.2131
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2019-1400
CVE CVE-2019-1461
CVE CVE-2019-1462
CVE CVE-2019-1463
CVE CVE-2019-1464
MSKB 4484182
MSKB 4484180
MSKB 4484186
MSKB 4484193
MSKB 4484192
MSKB 4475598
MSKB 4484184
XREF MSFT:MS19-4484182
XREF MSFT:MS19-4484180
XREF MSFT:MS19-4484186
XREF MSFT:MS19-4484193
XREF MSFT:MS19-4484192
XREF MSFT:MS19-4475598
XREF MSFT:MS19-4484184
Plugin Information
Published: 2019/12/10, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4484180
- C:\Program Files\Common Files\Microsoft Shared\Office16\acecore.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4939.1000

Product : Microsoft Office 2016
KB : 4484182
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4939.1000
143555 - Security Updates for Microsoft Office Products (December 2020)
-
Synopsis
The Microsoft Office Products are affected by multiple remote code execution vulnerabilities.
Description
The Microsoft Office Products are missing security updates. It is, therefore, affected by multiple remote code execution vulnerabilities. An attacker can exploit these to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address these issues:
-KB4486698
-KB4493140
-KB4486757

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.041
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-17122
CVE CVE-2020-17128
MSKB 4486698
MSKB 4493140
MSKB 4486757
XREF MSFT:MS20-4486698
XREF MSFT:MS20-4493140
XREF MSFT:MS20-4486757
XREF IAVA:2020-A-0557-S
XREF IAVA:2021-A-0017-S
XREF CEA-ID:CEA-2020-0138
Plugin Information
Published: 2020/12/08, Modified: 2025/08/29
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4486757
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5095.1000
156062 - Security Updates for Microsoft Office Products (December 2021)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. It is, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2021-43256, CVE-2021-43875)

- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges.
(CVE-2021-42293)

- A session spoofing vulnerability exists. An attacker can exploit this to perform actions with the privileges of another user. (CVE-2021-43255)

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2021-42295)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4504710
-KB4504745
-KB4486726
-KB5002033
-KB5002099
-KB5002104
-KB5002101

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.018
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-42293
CVE CVE-2021-42295
CVE CVE-2021-43255
CVE CVE-2021-43256
CVE CVE-2021-43875
MSKB 4486726
MSKB 4504710
MSKB 4504745
MSKB 5002033
MSKB 5002099
MSKB 5002101
MSKB 5002104
XREF MSFT:MS21-4504710
XREF MSFT:MS21-4504745
XREF MSFT:MS21-4486726
XREF MSFT:MS21-5002033
XREF MSFT:MS21-5002099
XREF MSFT:MS21-5002101
XREF MSFT:MS21-5002104
XREF IAVA:2021-A-0584-S
Plugin Information
Published: 2021/12/14, Modified: 2023/03/16
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4504710
- C:\Program Files\Common Files\Microsoft Shared\VBA\VBA7.1\vbe7.dll has not been patched.
Remote version : 7.1.10.48
Should be : 7.1.11.16

Product : Microsoft Office 2016
KB : 5002033
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5254.1001

Product : Microsoft Office 2016
KB : 4504745
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso20win32client.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5254.1001

Product : Microsoft Office 2016
KB : 5002099
- C:\Program Files\Common Files\Microsoft Shared\Office16\acecore.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5251.1000
212230 - Security Updates for Microsoft Office Products (December 2024)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. They are, therefore, affected by multiple vulnerabilities:

- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges.
(CVE-2024-43600, CVE-2024-49059)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2024-49065)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following updates to address these issues:
- KB4475587
- KB5002661
Risk Factor
Medium
CVSS v3.0 Base Score
7.0 (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.1 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0024
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-43600
CVE CVE-2024-49059
CVE CVE-2024-49065
MSKB 4475587
MSKB 5002661
XREF MSFT:MS24-4475587
XREF MSFT:MS24-5002661
XREF IAVA:2024-A-0807-S
Plugin Information
Published: 2024/12/10, Modified: 2025/01/17
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4475587
- C:\Program Files\Common Files\Microsoft Shared\Office16\olicenseheartbeat.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5478.1000

Product : Microsoft Office 2016
KB : 5002661
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5478.1000
277985 - Security Updates for Microsoft Office Products (December 2025)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. They are, therefore, affected by multiple vulnerabilities.

- A Remote Code Execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-62552, CVE-2025-62557, CVE-2025-62554, CVE-2025-62553, CVE-2025-62561, CVE-2025-62563)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following updates to address these issues:
- KB5002812
- KB5002818
- KB5002819
Risk Factor
High
CVSS v3.0 Base Score
8.4 (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
VPR Score
7.4
EPSS Score
0.0015
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-62552
CVE CVE-2025-62553
CVE CVE-2025-62554
CVE CVE-2025-62557
CVE CVE-2025-62561
CVE CVE-2025-62563
MSKB 5002812
MSKB 5002818
MSKB 5002819
MSKB 5002818
XREF MSFT:MS25-5002812
XREF MSFT:MS25-5002818
XREF MSFT:MS25-5002819
XREF IAVA:2025-A-0914
Plugin Information
Published: 2025/12/09, Modified: 2025/12/12
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002819
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5530.1001

Product : Microsoft Office 2016
KB : 5002818
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5530.1000

Product : Microsoft Office 2016
KB : 5002812
- C:\Program Files\Common Files\Microsoft Shared\Office16\acecore.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5530.1000
106805 - Security Updates for Microsoft Office Products (February 2018)
-
Synopsis
The Microsoft Office Products are missing a security update.
Description
The Microsoft Office Products are missing security updates.
It is, therefore, affected by the following vulnerabilities :

- A remote code execution vulnerability exists in Microsoft Office software when the Office software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-0851)

- An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory. An attacker who successfully exploited the vulnerability could view out of bound memory. Exploitation of the vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Office software. The security update addresses the vulnerability by properly initializing the affected variable. (CVE-2018-0853)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4011715
-KB4011707
-KB3114874
-KB4011690
-KB3172459
-KB4011686
-KB4011143
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.3054
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2018-0851
CVE CVE-2018-0853
MSKB 4011715
MSKB 4011707
MSKB 3114874
MSKB 4011690
MSKB 3172459
MSKB 4011686
MSKB 4011143
XREF MSFT:MS18-4011715
XREF MSFT:MS18-4011707
XREF MSFT:MS18-3114874
XREF MSFT:MS18-4011690
XREF MSFT:MS18-3172459
XREF MSFT:MS18-4011686
XREF MSFT:MS18-4011143
XREF IAVA:2018-A-0051-S
Plugin Information
Published: 2018/02/13, Modified: 2020/12/11
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4011686
- C:\Program Files\Common Files\Microsoft Shared\OFFICE16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4654.1000

Product : Microsoft Office 2016
KB : 4011143
- C:\Program Files\Common Files\Microsoft Shared\OFFICE16\acecore.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4654.1000
122132 - Security Updates for Microsoft Office Products (February 2019)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. They are, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. (CVE-2019-0538, CVE-2019-0582)

- A security feature bypass vulnerability exists when Microsoft Office does not validate URLs. An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials. An attacker who successfully exploited this vulnerability could perform a phishing attack. (CVE-2019-0540)

- An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user's computer or data. To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker must know the memory address location where the object was created.
(CVE-2019-0669)

- A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. (CVE-2019-0671, CVE-2019-0672, CVE-2019-0673, CVE-2019-0674, CVE-2019-0675)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4018294
-KB4018300
-KB4018313
-KB4462138
-KB4462146
-KB4462174
-KB4462177

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.3544
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
BID 106419
BID 106433
CVE CVE-2019-0538
CVE CVE-2019-0540
CVE CVE-2019-0582
CVE CVE-2019-0669
CVE CVE-2019-0671
CVE CVE-2019-0672
CVE CVE-2019-0673
CVE CVE-2019-0674
CVE CVE-2019-0675
MSKB 4018294
MSKB 4018300
MSKB 4018313
MSKB 4462138
MSKB 4462146
MSKB 4462174
MSKB 4462177
XREF MSFT:MS19-4018294
XREF MSFT:MS19-4018300
XREF MSFT:MS19-4018313
XREF MSFT:MS19-4462138
XREF MSFT:MS19-4462146
XREF MSFT:MS19-4462174
XREF MSFT:MS19-4462177
Plugin Information
Published: 2019/02/12, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4018294
- C:\Program Files\Common Files\Microsoft Shared\Office16\acecore.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4810.1000

Product : Microsoft Office 2016
KB : 4462146
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4810.1000
157433 - Security Updates for Microsoft Office Products (February 2022)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. It is, therefore, affected by multiple vulnerabilities:

- Two remote code execution vulnerabilities. An attacker can exploit these to bypass authentication and execute unauthorized arbitrary commands. (CVE-2022-22003, CVE-2022-22004)

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2022-23252)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB3118335
-KB3172514
-KB5002140
-KB5002146

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.0168
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-21988
CVE CVE-2022-22003
CVE CVE-2022-22004
CVE CVE-2022-23252
MSKB 3118335
MSKB 3172514
MSKB 5002140
MSKB 5002146
XREF MSFT:MS22-3118335
XREF MSFT:MS22-3172514
XREF MSFT:MS22-5002140
XREF MSFT:MS22-5002146
XREF IAVA:2022-A-0066-S
Plugin Information
Published: 2022/02/08, Modified: 2023/11/13
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002140
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5278.1000

Product : Microsoft Office 2016
KB : 3118335
- C:\Program Files\Microsoft Office\Office16\gkexcel.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5278.1000
190483 - Security Updates for Microsoft Office Products (February 2024)
-
Synopsis
The Microsoft Office Products are affected by multiple remote code execution vulnerabilities.
Description
The Microsoft Office Products are missing security updates. They are, therefore, affected by multiple remote code execution vulnerabilities. An attacker can exploit these to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002467
-KB5002469
-KB5002519
-KB5002522
-KB5002537
Risk Factor
Critical
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.2
EPSS Score
0.9338
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-20673
CVE CVE-2024-21413
MSKB 5002467
MSKB 5002469
MSKB 5002519
MSKB 5002522
MSKB 5002537
XREF MSFT:MS24-5002467
XREF MSFT:MS24-5002469
XREF MSFT:MS24-5002519
XREF MSFT:MS24-5002522
XREF MSFT:MS24-5002537
XREF IAVA:2024-A-0096-S
XREF IAVA:2024-A-0095-S
XREF IAVA:2024-A-0099-S
XREF IAVA:2024-A-0100-S
XREF IAVA:2024-A-0101-S
XREF IAVA:2024-A-0094-S
XREF IAVA:2024-A-0097-S
XREF CISA-KNOWN-EXPLOITED:2025/02/27
Exploitable With
Core Impact (true)
Plugin Information
Published: 2024/02/13, Modified: 2025/05/30
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002537
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5435.1001

Product : Microsoft Office 2016
KB : 5002467
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso20win32client.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5431.1000

Product : Microsoft Office 2016
KB : 5002522
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso30win32client.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5435.1001

Product : Microsoft Office 2016
KB : 5002469
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso40uiwin32client.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5435.1000

Product : Microsoft Office 2016
KB : 5002519
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso99lwin32client.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5431.1000
216125 - Security Updates for Microsoft Office Products (February 2025)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. It is, therefore, affected by multiple vulnerabilities:

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2025-21383)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-21387, CVE-2025-21390, CVE-2025-21392)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following updates to address these issues:
- KB5002179
- KB5002684
- KB5002686
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0009
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-21383
CVE CVE-2025-21387
CVE CVE-2025-21390
CVE CVE-2025-21392
MSKB 5002179
MSKB 5002684
MSKB 5002686
XREF MSFT:MS25-5002179
XREF MSFT:MS25-5002684
XREF MSFT:MS25-5002686
XREF IAVA:2025-A-0105
XREF IAVA:2025-A-0104-S
XREF CWE:122
XREF CWE:125
XREF CWE:416
Plugin Information
Published: 2025/02/11, Modified: 2025/09/17
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002684
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5487.1000

Product : Microsoft Office 2016
KB : 5002179
- C:\Program Files\Microsoft Office\Office16\gkexcel.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5487.1000

Product : Microsoft Office 2016
KB : 5002686
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5487.1000
105728 - Security Updates for Microsoft Office Products (January 2018)
-
Synopsis
The Microsoft Office Products are missing a security update.
Description
The Microsoft Office Products are missing security updates.
It is, therefore, affected by the following vulnerabilities :

- A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-0794, CVE-2018-0795)

- An Office RTF remote code execution vulnerability exists in Microsoft Office software when the Office software fails to properly handle RTF files. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-0797)

- A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-0798, CVE-2018-0801, CVE-2018-0802, CVE-2018-0804, CVE-2018-0805, CVE-2018-0806, CVE-2018-0807, CVE-2018-0812)

- A remote code execution vulnerability exists in the way that Microsoft Outlook parses specially crafted email messages. An attacker who successfully exploited the vulnerability could take control of an affected system.
An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Exploitation of this vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Outlook. (CVE-2018-0793)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4011201
-KB4011574
-KB4011580
-KB4011610
-KB4011611
-KB4011622
-KB4011632
-KB4011636
-KB4011656
-KB4011658
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.8
EPSS Score
0.9407
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
BID 102347
BID 102348
BID 102356
BID 102370
BID 102373
BID 102375
BID 102406
BID 102457
BID 102459
BID 102460
BID 102461
BID 102463
CVE CVE-2018-0793
CVE CVE-2018-0794
CVE CVE-2018-0795
CVE CVE-2018-0797
CVE CVE-2018-0798
CVE CVE-2018-0801
CVE CVE-2018-0802
CVE CVE-2018-0804
CVE CVE-2018-0805
CVE CVE-2018-0806
CVE CVE-2018-0807
CVE CVE-2018-0812
CVE CVE-2018-0845
CVE CVE-2018-0848
CVE CVE-2018-0849
CVE CVE-2018-0862
MSKB 4011201
MSKB 4011574
MSKB 4011580
MSKB 4011610
MSKB 4011611
MSKB 4011622
MSKB 4011632
MSKB 4011636
MSKB 4011656
MSKB 4011658
XREF MSFT:MS17-4011201
XREF MSFT:MS17-4011574
XREF MSFT:MS17-4011580
XREF MSFT:MS17-4011610
XREF MSFT:MS17-4011611
XREF MSFT:MS17-4011622
XREF MSFT:MS17-4011632
XREF MSFT:MS17-4011636
XREF MSFT:MS17-4011656
XREF MSFT:MS17-4011658
XREF IAVA:2018-A-0009-S
XREF CISA-KNOWN-EXPLOITED:2022/05/03
Exploitable With
Core Impact (true)
Plugin Information
Published: 2018/01/10, Modified: 2023/04/25
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4011632
- C:\Program Files\Common Files\Microsoft Shared\OFFICE16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4639.1000

Product : Microsoft Office 2016
KB : 4011622
- C:\Program Files\Common Files\Microsoft Shared\OFFICE16\mso99lres.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4519.1000

Product : Microsoft Office 2016
KB : 4011574
- C:\Program Files\Common Files\Microsoft Shared\EQUATION\eqnedt32.exe has not been patched.
Remote version : 2000.11.9.0
Should be : 2018.0.0.0
121024 - Security Updates for Microsoft Office Products (January 2019)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input. An attacker could execute arbitrary code in the context of the current user. (CVE-2019-0541)

- An information disclosure vulnerability exists when Microsoft Outlook improperly handles certain types of messages. An attacker who successfully exploited this vulnerability could gather information about the victim.
An attacker could exploit this vulnerability by sending a specially crafted email to the victim. The update addresses the vulnerability by correcting the way Microsoft Outlook handles these types of messages.
(CVE-2019-0559)

- An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the users computer or data. (CVE-2019-0560)

- An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the users computer or data. (CVE-2019-0560)

- A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the same permissions as the current user. (CVE-2019-0585)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB2553332
-KB3172522
-KB4022162
-KB4461535
-KB4461537
-KB4461614
-KB4461617

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.2
EPSS Score
0.8094
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
CVE CVE-2019-0541
CVE CVE-2019-0559
CVE CVE-2019-0560
CVE CVE-2019-0561
CVE CVE-2019-0585
MSKB 2553332
MSKB 3172522
MSKB 4022162
MSKB 4461535
MSKB 4461537
MSKB 4461614
MSKB 4461617
XREF MSFT:MS19-2553332
XREF MSFT:MS19-3172522
XREF MSFT:MS19-4022162
XREF MSFT:MS19-4461535
XREF MSFT:MS19-4461537
XREF MSFT:MS19-4461614
XREF MSFT:MS19-4461617
XREF CISA-KNOWN-EXPLOITED:2022/05/03
Plugin Information
Published: 2019/01/08, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4022162
- C:\Program Files\Microsoft Office\Office16\msohev.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4795.1000

Product : Microsoft Office 2016
KB : 4461535
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4795.1000
132869 - Security Updates for Microsoft Office Products (January 2020)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing a security update. It is, therefore, affected by the following vulnerability:

- A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4484221
-KB4484227
-KB4484236 For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.1667
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2020-0652
MSKB 4484221
MSKB 4484227
MSKB 4484236
XREF MSFT:MS20-4484221
XREF MSFT:MS20-4484227
XREF MSFT:MS20-4484236
XREF IAVA:2020-A-0029-S
Plugin Information
Published: 2020/01/14, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4484221
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4954.1000
144885 - Security Updates for Microsoft Office Products (January 2021)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft office Product is missing security updates. It is, therefore, affected by multiple vulnerabilities:

- Microsoft Office Remote Code Execution Vulnerability (CVE-2021-1711)

- Microsoft Excel Remote Code Execution Vulnerability (CVE-2021-1714)

- Microsoft Word Remote Code Execution Vulnerability (CVE-2021-1715, CVE-2021-1716)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4486759
-KB4493168
-KB4493181
-KB4486755
-KB4486762
-KB4493142
-KB4493143

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0222
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-1711
CVE CVE-2021-1714
CVE CVE-2021-1715
CVE CVE-2021-1716
MSKB 4493168
MSKB 4486759
MSKB 4493181
MSKB 4486755
MSKB 4486762
MSKB 4493143
MSKB 4493142
XREF MSFT:MS21-4493168
XREF MSFT:MS21-4486759
XREF MSFT:MS21-4493181
XREF MSFT:MS21-4486755
XREF MSFT:MS21-4486762
XREF MSFT:MS21-4493143
XREF MSFT:MS21-4493142
XREF IAVA:2021-A-0016-S
XREF IAVA:2021-A-0017-S
XREF IAVA:2021-A-0024-S
XREF CEA-ID:CEA-2021-0001
Plugin Information
Published: 2021/01/12, Modified: 2022/12/07
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4493168
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5110.1000

Product : Microsoft Office 2016
KB : 4486755
- C:\Program Files\Common Files\Microsoft Shared\Office16\acecore.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5110.1000
156630 - Security Updates for Microsoft Office Products (January 2022)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2022-21840, CVE-2022-21841)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4462205
-KB5002052
-KB5002060
-KB5002064
-KB5002115
-KB5002116
-KB5002119
-KB5002124

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0776
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-21840
CVE CVE-2022-21841
MSKB 4462205
MSKB 5002052
MSKB 5002060
MSKB 5002064
MSKB 5002115
MSKB 5002116
MSKB 5002119
MSKB 5002124
XREF MSFT:MS22-4462205
XREF MSFT:MS22-5002052
XREF MSFT:MS22-5002060
XREF MSFT:MS22-5002064
XREF MSFT:MS22-5002115
XREF MSFT:MS22-5002116
XREF MSFT:MS22-5002119
XREF MSFT:MS22-5002124
XREF IAVA:2022-A-0018-S
Plugin Information
Published: 2022/01/11, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002116
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5266.1000

Product : Microsoft Office 2016
KB : 5002060
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5266.1000

Product : Microsoft Office 2016
KB : 5002052
- C:\Program Files\Microsoft Office\Office16\stslist.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5266.1000

Product : Microsoft Office 2016
KB : 5002115
- C:\Program Files\Common Files\Microsoft Shared\Office16\acecore.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5266.1001
214128 - Security Updates for Microsoft Office Products (January 2025)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. It is, therefore, affected by a security feature bypass vulnerability. An attacker can exploit this and bypass the security feature and perform unauthorized actions compromising the integrity and availability of the system/application.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following updates to address these issues:
- KB5002595
- KB5002675
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.003
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-21346
MSKB 5002595
MSKB 5002675
XREF MSFT:MS25-5002595
XREF MSFT:MS25-5002675
XREF IAVA:2025-A-0030
XREF CWE:693
Plugin Information
Published: 2025/01/14, Modified: 2025/09/17
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002595
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5483.1000

Product : Microsoft Office 2016
KB : 5002675
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5483.1000
151595 - Security Updates for Microsoft Office Products (July 2021)
-
Synopsis
The Microsoft Office Products are affected by a security feature bypass vulnerability.
Description
The Microsoft Office Products are missing security updates. It is, therefore, affected by a security feature bypass vulnerability. An attacker can exploit this and bypass the security feature and perform unauthorized actions compromising the confidentiality and integrity of the system/application.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5001979
-KB5001983

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
8.2 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N)
CVSS v3.0 Temporal Score
7.6 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.0067
CVSS v2.0 Base Score
5.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:N)
CVSS v2.0 Temporal Score
4.8 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-34469
MSKB 5001979
MSKB 5001983
XREF MSFT:MS21-5001979
XREF MSFT:MS21-5001983
XREF IAVA:2021-A-0316-S
Plugin Information
Published: 2021/07/13, Modified: 2023/12/29
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5001979
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5188.1000
178169 - Security Updates for Microsoft Office Products (July 2023)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. It is, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2023-33149, CVE-2023-33152, CVE-2023-33153)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4464506
-KB4475581
-KB4493154
-KB5001952
-KB5002058
-KB5002069
-KB5002400
-KB5002419
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
8.4
EPSS Score
0.0374
CVSS v2.0 Base Score
7.6 (CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2023-33149
CVE CVE-2023-33152
CVE CVE-2023-33153
MSKB 4464506
MSKB 4475581
MSKB 4493154
MSKB 5001952
MSKB 5002058
MSKB 5002069
MSKB 5002400
MSKB 5002419
XREF MSFT:MS23-4464506
XREF MSFT:MS23-4475581
XREF MSFT:MS23-4493154
XREF MSFT:MS23-5001952
XREF MSFT:MS23-5002058
XREF MSFT:MS23-5002069
XREF MSFT:MS23-5002400
XREF MSFT:MS23-5002419
XREF IAVA:2023-A-0349-S
Plugin Information
Published: 2023/07/11, Modified: 2023/08/11
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002419
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5404.1000

Product : Microsoft Office 2016
KB : 4493154
- C:\Program Files\Microsoft Office\Office16\oart.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5404.1000

Product : Microsoft Office 2016
KB : 4475581
- C:\Program Files\Microsoft Office\Office16\ADDINS\umoutlookaddin.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5404.1000
202025 - Security Updates for Microsoft Office Products (July 2024)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2024-38021)

- A session spoofing vulnerability exists. An attacker can exploit this to perform actions with the privileges of another user. (CVE-2024-38020)
See Also
Solution
Microsoft has released KB5002620 to address this issue.
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.9
EPSS Score
0.1956
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-38020
CVE CVE-2024-38021
MSKB 5002620
XREF MSFT:MS24-5002620
XREF IAVA:2024-A-0403-S
XREF IAVA:2024-A-0402-S
Plugin Information
Published: 2024/07/09, Modified: 2025/08/22
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002620
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5456.1000
241553 - Security Updates for Microsoft Office Products (July 2025)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. They are, therefore, affected by multiple vulnerabilities.

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2025-48812)

- A Remote Code Execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-49695, CVE-2025-49696, CVE-2025-49697, CVE-2025-49698, CVE-2025-49699, CVE-2025-49700, CVE-2025-49702)

- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges.
(CVE-2025-47994)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following updates to address these issues:
- KB4464583
- KB5001941
- KB5002655
- KB5002734
- KB5002742
Risk Factor
High
CVSS v3.0 Base Score
8.4 (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
VPR Score
7.3
EPSS Score
0.0015
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-47994
CVE CVE-2025-48812
CVE CVE-2025-49695
CVE CVE-2025-49696
CVE CVE-2025-49697
CVE CVE-2025-49698
CVE CVE-2025-49699
CVE CVE-2025-49700
CVE CVE-2025-49702
MSKB 4464583
MSKB 5001941
MSKB 5002655
MSKB 5002734
MSKB 5002742
XREF MSFT:MS25-4464583
XREF MSFT:MS25-5001941
XREF MSFT:MS25-5002655
XREF MSFT:MS25-5002733
XREF MSFT:MS25-5002734
XREF MSFT:MS25-5002742
XREF IAVA:2025-A-0488-S
XREF CWE:122
XREF CWE:125
XREF CWE:416
XREF CWE:502
XREF CWE:843
Plugin Information
Published: 2025/07/08, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4464583
- C:\Program Files\Microsoft Office\Office16\css7data0009.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5508.1000

Product : Microsoft Office 2016
KB : 5002655
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso99lwin32client.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5508.1000

Product : Microsoft Office 2016
KB : 5002734
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5508.1001

Product : Microsoft Office 2016
KB : 5002742
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5508.1001
110495 - Security Updates for Microsoft Office Products (June 2018)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities :

- An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the users computer or data. (CVE-2018-8246)

- A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-8248)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4022182
-KB3115197
-KB3115248
-KB4022177
-KB4018387
-KB4022199
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.5207
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2018-8246
CVE CVE-2018-8248
MSKB 4022182
MSKB 3115197
MSKB 3115248
MSKB 4022177
MSKB 4018387
MSKB 4022199
XREF MSFT:MS18-4022182
XREF MSFT:MS18-3115197
XREF MSFT:MS18-3115248
XREF MSFT:MS18-4022177
XREF MSFT:MS18-4018387
XREF MSFT:MS18-4022199
Plugin Information
Published: 2018/06/12, Modified: 2019/11/04
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4022177
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4705.1000
150356 - Security Updates for Microsoft Office Products (June 2021)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. It is, therefore, affected by multiple vulnerabilities :

- Microsoft Excel remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2021-31939)

- Microsoft Office Graphics remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2021-31940, CVE-2021-31941) Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5001950
-KB5001951
-KB5001953
-KB5001955 For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0713
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-31939
CVE CVE-2021-31940
CVE CVE-2021-31941
CVE CVE-2021-31949
MSKB 5001950
MSKB 5001955
MSKB 5001951
MSKB 5001953
XREF MSFT:MS21-5001950
XREF MSFT:MS21-5001955
XREF MSFT:MS21-5001951
XREF MSFT:MS21-5001953
XREF IAVA:2021-A-0275-S
Plugin Information
Published: 2021/06/08, Modified: 2024/11/28
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5001950
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5173.1000

Product : Microsoft Office 2016
KB : 5001951
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5173.1000
200348 - Security Updates for Microsoft Office Products (June 2024)
-
Synopsis
The Microsoft Office Products are affected by multiple remote code execution vulnerabilities.
Description
The Microsoft Office Products are missing security updates. They are, therefore, affected by multiple remote code execution vulnerabilities. An attacker can exploit these to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002575
-KB5002591
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0384
CVSS v2.0 Base Score
7.6 (CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.0 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-30101
CVE CVE-2024-30104
MSKB 5002575
MSKB 5002591
XREF MSFT:MS24-5002575
XREF MSFT:MS24-5002591
XREF IAVA:2024-A-0341-S
Plugin Information
Published: 2024/06/11, Modified: 2024/09/13
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002591
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5452.1000

Product : Microsoft Office 2016
KB : 5002575
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso20win32client.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5452.1000
238088 - Security Updates for Microsoft Office Products (June 2025)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. They are, therefore, affected by multiple remote code execution vulnerabilities. An attacker can exploit these to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following updates to address these issues:
- KB5002616
- KB5002730
Risk Factor
High
CVSS v3.0 Base Score
8.4 (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0016
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-47162
CVE CVE-2025-47164
CVE CVE-2025-47167
CVE CVE-2025-47173
CVE CVE-2025-47953
MSKB 5002616
MSKB 5002730
XREF MSFT:MS25-5002616
XREF MSFT:MS25-5002730
XREF IAVA:2025-A-0416-S
XREF CWE:122
XREF CWE:416
XREF CWE:641
XREF CWE:843
Plugin Information
Published: 2025/06/10, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002616
- C:\Program Files\Microsoft Office\Office16\oart.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5504.1000

Product : Microsoft Office 2016
KB : 5002730
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5504.1002
172537 - Security Updates for Microsoft Office Products (March 2023)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. They are, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002197
-KB5002198

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.02
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-23399
MSKB 5002197
MSKB 5002198
XREF MSFT:MS23-5002197
XREF MSFT:MS23-5002198
XREF IAVA:2023-A-0137-S
Plugin Information
Published: 2023/03/14, Modified: 2023/06/16
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002197
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5387.1000
232699 - Security Updates for Microsoft Office Products (March 2025)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. They are, therefore, affected by multiple remote code execution vulnerabilities. An attacker can exploit these to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following updates to address these issues:
- KB5002693
- KB5002694
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0008
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-24057
CVE CVE-2025-24080
CVE CVE-2025-24083
MSKB 5002693
MSKB 5002694
XREF MSFT:MS25-5002693
XREF MSFT:MS25-5002694
XREF IAVA:2025-A-0176-S
XREF CWE:122
XREF CWE:416
XREF CWE:822
Plugin Information
Published: 2025/03/13, Modified: 2025/09/17
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002693
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5491.1001

Product : Microsoft Office 2016
KB : 5002694
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5491.1000
109614 - Security Updates for Microsoft Office Products (May 2018)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-8147, CVE-2018-8148)

- An information disclosure vulnerability exists in Outlook when a message is opened. This vulnerability could potentially result in the disclosure of sensitive information to a malicious site. (CVE-2018-8160)

- A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-8157, CVE-2018-8158, CVE-2018-8161)

- A remote code execution vulnerability exists in Microsoft InfoPath when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2018-8173)

- A security feature bypass vulnerability exists when the Microsoft Outlook attachment block filter does not properly handle attachments. An attacker who successfully exploited the vulnerability could execute arbitrary commands. The security feature bypass by itself does not allow arbitrary code execution. (CVE-2018-8150)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4022137
-KB2899590
-KB3172436
-KB4022139
-KB3162075
-KB4018327
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.9
EPSS Score
0.3391
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2018-8147
CVE CVE-2018-8148
CVE CVE-2018-8150
CVE CVE-2018-8157
CVE CVE-2018-8158
CVE CVE-2018-8160
CVE CVE-2018-8161
CVE CVE-2018-8173
MSKB 4022137
MSKB 2899590
MSKB 3172436
MSKB 4022139
MSKB 3162075
MSKB 4018327
XREF MSFT:MS18-4022137
XREF MSFT:MS18-2899590
XREF MSFT:MS18-3172436
XREF MSFT:MS18-4022139
XREF MSFT:MS18-3162075
XREF MSFT:MS18-4018327
XREF IAVA:2018-A-0151-S
Plugin Information
Published: 2018/05/08, Modified: 2024/10/11
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4018327
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4690.1000
125071 - Security Updates for Microsoft Office Products (May 2019)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. It is, therefore, affected by multiple remote code execution vulnerabilities due to the way Microsoft Office Access Connectivity Engine improperly handles objects in memory. An attacker who successfully exploited these vulnerabilities could execute arbitrary code on a victim system. An attacker could exploit these vulnerabilities by enticing a victim to open a specially crafted file. The update addresses the vulnerabilities by correcting the way the Microsoft Office Access Connectivity Engine handles objects in memory.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4464567
-KB4464551
-KB4464561

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.2976
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2019-0945
CVE CVE-2019-0946
CVE CVE-2019-0947
MSKB 4464567
MSKB 4464551
MSKB 4464561
XREF MSFT:MS19-4464567
XREF MSFT:MS19-4464551
XREF MSFT:MS19-4464561
XREF CEA-ID:CEA-2019-0326
Plugin Information
Published: 2019/05/14, Modified: 2022/12/05
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4464551
- C:\Program Files\Common Files\Microsoft Shared\Office16\aceexcl.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4849.1000
149401 - Security Updates for Microsoft Office Products (May 2021)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. It is, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2021-28455, CVE-2021-31175, CVE-2021-31176, CVE-2021-31177, CVE-2021-31179, CVE-2021-31180)

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2021-31174, CVE-2021-31178)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address these issues:
-KB4464542
-KB4493206
-KB4493197
-KB5001920
-KB5001923
-KB5001925
-KB5001927 For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.2555
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-28455
CVE CVE-2021-31174
CVE CVE-2021-31175
CVE CVE-2021-31176
CVE CVE-2021-31178
CVE CVE-2021-31179
CVE CVE-2021-31180
MSKB 4464542
MSKB 4493197
MSKB 4493206
MSKB 5001920
MSKB 5001923
MSKB 5001925
MSKB 5001927
XREF MSFT:MS21-4464542
XREF MSFT:MS21-4493206
XREF MSFT:MS21-4493197
XREF MSFT:MS21-5001920
XREF MSFT:MS21-5001923
XREF MSFT:MS21-5001925
XREF MSFT:MS21-5001927
XREF IAVA:2021-A-0225-S
Plugin Information
Published: 2021/05/11, Modified: 2024/01/02
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5001923
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5161.1000

Product : Microsoft Office 2016
KB : 5001920
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5161.1002

Product : Microsoft Office 2016
KB : 4493197
- C:\Program Files\Common Files\Microsoft Shared\Office16\acecore.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5161.1001
235849 - Security Updates for Microsoft Office Products (May 2025)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. It is, therefore, affected by multiple remote code execution vulnerabilities. An attacker can exploit these to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following updates to address these issues:
- KB5002695
- KB5002711
- KB5002716
Risk Factor
High
CVSS v3.0 Base Score
8.4 (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0006
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-30377
CVE CVE-2025-30379
CVE CVE-2025-30386
CVE CVE-2025-32704
MSKB 5002695
MSKB 5002711
MSKB 5002716
XREF MSFT:MS25-5002695
XREF MSFT:MS25-5002711
XREF MSFT:MS25-5002716
XREF IAVA:2025-A-0337-S
XREF CWE:125
XREF CWE:126
XREF CWE:416
XREF CWE:763
Plugin Information
Published: 2025/05/13, Modified: 2025/09/17
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002716
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5500.1000

Product : Microsoft Office 2016
KB : 5002695
- C:\Program Files\Microsoft Office\Office16\gkexcel.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5500.1001

Product : Microsoft Office 2016
KB : 5002711
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5500.1002
104557 - Security Updates for Microsoft Office Products (November 2017)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities :

- Microsoft has released an update for Microsoft Office that provides enhanced security as a defense-in-depth measure.

- A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. (CVE-2017-11854)

- A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. (CVE-2017-11882)
See Also
Solution
Microsoft has released security updates for Microsoft Office Products.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.8
EPSS Score
0.9438
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
BID 101746
BID 101757
CVE CVE-2017-11854
CVE CVE-2017-11882
MSKB 3162047
MSKB 4011268
MSKB 4011604
MSKB 4011262
MSKB 4011618
XREF MSFT:MS17-3162047
XREF MSFT:MS17-4011268
XREF MSFT:MS17-4011604
XREF MSFT:MS17-4011262
XREF MSFT:MS17-4011618
XREF IAVA:2017-A-0337-S
XREF CISA-KNOWN-EXPLOITED:2022/05/03
Exploitable With
Core Impact (true) Metasploit (true)
Plugin Information
Published: 2017/11/14, Modified: 2023/04/25
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4011262
- C:\Program Files\Common Files\Microsoft Shared\Equation\eqnedt32.exe has not been patched.
Remote version : 2000.11.9.0
Should be : 2017.8.14.0
118923 - Security Updates for Microsoft Office Products (November 2018)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the same permissions as the current user. (CVE-2018-8539)

- A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the same permissions as the current user. (CVE-2018-8573)

- A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. (CVE-2018-8577)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB3114565
-KB4022232
-KB4022237
-KB4032218
-KB4461524
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.1857
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
BID 105834
BID 105835
BID 105836
CVE CVE-2018-8539
CVE CVE-2018-8573
CVE CVE-2018-8577
MSKB 3114565
MSKB 4022232
MSKB 4022237
MSKB 4032218
MSKB 4461524
XREF MSFT:MS18-3114565
XREF MSFT:MS18-4022232
XREF MSFT:MS18-4022237
XREF MSFT:MS18-4032218
XREF MSFT:MS18-4461524
Plugin Information
Published: 2018/11/13, Modified: 2024/07/22
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4022232
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4771.1000
142689 - Security Updates for Microsoft Office Products (November 2020)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft office Product is missing security updates.

- Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability (CVE-2020-17062)

- Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2020-17019, CVE-2020-17065, CVE-2020-17066. (CVE-2020-17064)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4484534
-KB4484520
-KB4486722
-KB4486737
-KB4484455
-KB4486738
-KB4484508
-KB4486725

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.046
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-17062
CVE CVE-2020-17064
MSKB 4484534
MSKB 4484520
MSKB 4486722
MSKB 4486737
MSKB 4484455
MSKB 4486738
MSKB 4484508
MSKB 4486725
XREF MSFT:MS20-4484534
XREF MSFT:MS20-4484520
XREF MSFT:MS20-4486722
XREF MSFT:MS20-4486737
XREF MSFT:MS20-4484455
XREF MSFT:MS20-4486738
XREF MSFT:MS20-4484508
XREF MSFT:MS20-4486725
XREF IAVA:2020-A-0516-S
XREF CEA-ID:CEA-2020-0135
Plugin Information
Published: 2020/11/10, Modified: 2024/02/09
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4486722
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5083.1000

Product : Microsoft Office 2016
KB : 4484508
- C:\Program Files\Common Files\Microsoft Shared\Office16\acecore.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5083.1000
155000 - Security Updates for Microsoft Office Products (November 2021)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. It is, therefore, affected by multiple vulnerabilities:

- A security feature bypass vulnerability exists. An attacker can exploit this and bypass the security feature and perform unauthorized actions compromising the integrity of the system/application.
(CVE-2021-42292)

- Two remote code execution vulnerabilities. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2021-40442, CVE-2021-41368)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4486670
-KB5002032
-KB5002038
-KB5002035
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.2
EPSS Score
0.1301
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.9 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-40442
CVE CVE-2021-41368
CVE CVE-2021-42292
MSKB 5002038
MSKB 4486670
MSKB 5002035
MSKB 5002032
XREF CISA-KNOWN-EXPLOITED:2021/12/01
XREF MSFT:MS21-5002038
XREF MSFT:MS21-4486670
XREF MSFT:MS21-5002035
XREF MSFT:MS21-5002032
XREF IAVA:2021-A-0546-S
Plugin Information
Published: 2021/11/09, Modified: 2024/04/01
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4886670
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso99lwin32client.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5239.1001

Product : Microsoft Office 2016
KB : 5002032
- C:\Program Files\Common Files\Microsoft Shared\Office16\acecore.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5239.1000
210859 - Security Updates for Microsoft Office Products (November 2024)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. They are, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2024-49031, CVE-2024-49032)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002642 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0036
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-49031
CVE CVE-2024-49032
MSKB 5002642
XREF MSFT:MS24-5002642
XREF IAVA:2024-A-0728-S
Plugin Information
Published: 2024/11/12, Modified: 2024/12/13
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002642
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5474.1000
274786 - Security Updates for Microsoft Office Products (November 2025)
-
Synopsis
The Microsoft Office Products are affected by Remote Code Execution Vulnerability.
Description
The Microsoft Office Products are missing security updates. They are, therefore, affected by multiple vulnerabilities:

- Microsoft Excel allows an unauthorized attacker to disclose information locally.
(CVE-2025-62202, CVE-2025-60726)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-62199, CVE-2025-60727)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following updates to address these issues:
- KB5002809
Risk Factor
High
CVSS v3.0 Base Score
8.4 (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0006
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-62199
CVE CVE-2025-62202
CVE CVE-2025-60726
CVE CVE-2025-60727
MSKB 5002809
MSKB 5002810
XREF MSFT:MS25-5002809
XREF MSFT:MS25-5002810
XREF IAVA:2025-A-0846
XREF CWE:416
Plugin Information
Published: 2025/11/11, Modified: 2025/11/14
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002809
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5526.1000

Product : Microsoft Office 2016
KB : 5002810
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5526.1000
103784 - Security Updates for Microsoft Office Products (October 2017)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities :

- Microsoft has released an update for Microsoft Office that provides enhanced security as a defense-in-depth measure.

- A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the same permissions as the current user. (CVE-2017-11825)

- A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. (CVE-2017-11826)
See Also
Solution
Microsoft has released security updates for Microsoft Office Products.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.4
EPSS Score
0.9034
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
BID 101124
BID 101219
CVE CVE-2017-11825
CVE CVE-2017-11826
MSKB 3172524
MSKB 3172531
MSKB 4011185
MSKB 2920723
MSKB 2553338
MSKB 2837599
MSKB 4011222
MSKB 3213648
MSKB 4011232
MSKB 3213630
MSKB 3213627
XREF MSFT:MS17-3172524
XREF MSFT:MS17-3172531
XREF MSFT:MS17-4011185
XREF MSFT:MS17-2920723
XREF MSFT:MS17-2553338
XREF MSFT:MS17-2837599
XREF MSFT:MS17-4011222
XREF MSFT:MS17-3213648
XREF MSFT:MS17-4011232
XREF MSFT:MS17-32136304
XREF MSFT:MS17-3213627
XREF IAVA:2017-A-0291-S
XREF CISA-KNOWN-EXPLOITED:2022/03/24
Exploitable With
Core Impact (true)
Plugin Information
Published: 2017/10/11, Modified: 2023/02/17
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4011185
- C:\Program Files\Common Files\Microsoft Shared\Source Engine\ose.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4600.1000

Product : Microsoft Office 2016
KB : 2920723
- C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Office Setup Controller\osetup.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4600.1000

Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4600.1002
118010 - Security Updates for Microsoft Office Products (October 2018)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists in Microsoft Word software when the software fails to properly handle objects in Protected View. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-8504)

- A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in Protected View. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-8501)

- A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in Protected View. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-8502)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4461445
-KB4461437
-KB4092437
-KB4092483
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.2612
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2018-8501
CVE CVE-2018-8502
CVE CVE-2018-8504
MSKB 4461445
MSKB 4461437
MSKB 4092437
MSKB 4092483
XREF MSFT:MS18-4461445
XREF MSFT:MS18-4461437
XREF MSFT:MS18-4092437
XREF MSFT:MS18-4092483
Plugin Information
Published: 2018/10/09, Modified: 2024/07/31
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4461437
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4756.1000
141418 - Security Updates for Microsoft Office Products (October 2020)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-16929, CVE-2020-16930)

- A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-16954)

- A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.(CVE-2020-16957)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4484417
-KB4484435
-KB4486682
-KB4486688
-KB4486700

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0652
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-16929
CVE CVE-2020-16930
CVE CVE-2020-16954
CVE CVE-2020-16957
MSKB 4484417
MSKB 4484435
MSKB 4486682
MSKB 4486688
MSKB 4486700
XREF MSFT:MS20-4484417
XREF MSFT:MS20-4484435
XREF MSFT:MS20-4486682
XREF MSFT:MS20-4486688
XREF MSFT:MS20-4486700
XREF IAVA:2020-A-0454-S
XREF IAVA:2020-A-0462-S
XREF CEA-ID:CEA-2020-0126
Plugin Information
Published: 2020/10/13, Modified: 2022/12/05
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4484417
- C:\Program Files\Common Files\Microsoft Shared\VBA\VBA7.1\vbe7.dll has not been patched.
Remote version : 7.1.10.48
Should be : 7.1.11.0

Product : Microsoft Office 2016
KB : 4486682
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5071.1000
154038 - Security Updates for Microsoft Office Products (October 2021)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities :

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2021-40454, CVE-2021-40472)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2021-40471, CVE-2021-40473, CVE-2021-40474, CVE-2021-40479, CVE-2021-40480, CVE-2021-40481, CVE-2021-40485, CVE-2021-40486)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4018332
-KB5001982
-KB5001985
-KB4461476

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.0301
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-40454
CVE CVE-2021-40471
CVE CVE-2021-40472
CVE CVE-2021-40473
CVE CVE-2021-40479
MSKB 4018332
MSKB 4461476
MSKB 5001982
MSKB 5001985
XREF MSFT:MS21-4018332
XREF MSFT:MS21-4461476
XREF MSFT:MS21-5001982
XREF MSFT:MS21-5001985
XREF IAVA:2021-A-0472-S
XREF IAVA:2021-A-0475-S
XREF IAVA:2021-A-0473-S
XREF IAVA:2021-A-0468-S
XREF IAVA:2021-A-0465-S
Plugin Information
Published: 2021/10/12, Modified: 2023/11/28
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5001982
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5227.1000

Product : Microsoft Office 2016
KB : 4461476
- C:\Program Files\Common Files\Microsoft Shared\Office16\riched20.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5227.1000
166037 - Security Updates for Microsoft Office Products (October 2022)
-
Synopsis
The Microsoft Office Products are affected by a remote code execution vulnerability.
Description
The Microsoft Office Products are missing security updates. It is, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002026
-KB5002279
-KB5002288

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.03
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.0 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-38048
MSKB 5002026
MSKB 5002279
MSKB 5002288
XREF MSFT:MS22-5002026
XREF MSFT:MS22-5002279
XREF MSFT:MS22-5002288
XREF IAVA:2022-A-0412-S
Plugin Information
Published: 2022/10/11, Modified: 2023/10/09
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002288
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5365.1000

Product : Microsoft Office 2016
KB : 5002026
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso40uiwin32client.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5365.1000
270387 - Security Updates for Microsoft Office Products (October 2025)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. They are, therefore, affected by multiple vulnerabilities.

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-59226, CVE-2025-59227, CVE-2025-59234)

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2025-59232, CVE-2025-59235)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following updates to address these issues:
- KB5002341
- KB5002719
- KB5002757
- KB5002792
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0006
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-59226
CVE CVE-2025-59227
CVE CVE-2025-59232
CVE CVE-2025-59234
CVE CVE-2025-59235
MSKB 5002341
MSKB 5002719
MSKB 5002757
MSKB 5002792
XREF MSFT:MS25-5002341
XREF MSFT:MS25-5002719
XREF MSFT:MS25-5002757
XREF MSFT:MS25-5002792
XREF IAVA:2025-A-0759-S
XREF CWE:125
XREF CWE:416
Plugin Information
Published: 2025/10/14, Modified: 2025/11/18
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002341
- C:\Program Files\Microsoft Office\Office16\stslist.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5522.1000

Product : Microsoft Office 2016
KB : 5002719
- C:\Program Files\Common Files\Microsoft Shared\Office16\acees.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5522.1000

Product : Microsoft Office 2016
KB : 5002757
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5522.1000

Product : Microsoft Office 2016
KB : 5002792
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5522.1000
103133 - Security Updates for Microsoft Office Products (September 2017)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the same permissions as the current user. Exploitation of this vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Office software. In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and convincing the user to open the file. In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) that contains a specially crafted file that is designed to exploit the vulnerability. However, an attacker would have no way to force the user to visit the website. Instead, an attacker would have to convince the user to click a link, typically by way of an enticement in an email or Instant Messenger message, and then convince the user to open the specially crafted file. The security update addresses the vulnerability by correcting how Microsoft Office handles files in memory.
(CVE-2017-8630, CVE-2017-8744)

- A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. There are multiple ways an attacker could exploit this vulnerability. In a web- based attack scenario, an attacker could host a specially crafted website that is designed to exploit this vulnerability and then convince a user to view the website. An attacker would have no way to force users to view the attacker-controlled content. Instead, an attacker would have to convince users to take action, typically by getting them to click a link in an email message or in an Instant Messenger message that takes users to the attacker's website, or by opening an attachment sent through email. In a file sharing attack scenario, an attacker could provide a specially crafted document file that is designed to exploit this vulnerability, and then convince a user to open the document file. The security update addresses the vulnerabilities by correcting how the Windows font library handles embedded fonts. (CVE-2017-8682)

- An information disclosure vulnerability exists when Windows Uniscribe improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document or by convincing a user to visit an untrusted webpage.
The update addresses the vulnerability by correcting how Windows Uniscribe handles objects in memory.
(CVE-2017-8695)

- A remote code execution vulnerability exists due to the way Windows Uniscribe handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. There are multiple ways an attacker could exploit this vulnerability: In a web-based attack scenario, an attacker could host a specially crafted website designed to exploit this vulnerability and then convince a user to view the website. An attacker would have no way to force users to view the attacker-controlled content.
Instead, an attacker would have to convince users to take action, typically by getting them to click a link in an email or instant message that takes users to the attacker's website, or by opening an attachment sent through email. In a file-sharing attack scenario, an attacker could provide a specially crafted document file designed to exploit this vulnerability and then convince a user to open the document file.The security update addresses the vulnerability by correcting how Windows Uniscribe handles objects in memory. (CVE-2017-8696)

- A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Exploitation of the vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Office software. In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and convincing the user to open the file. In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) that contains a specially crafted file designed to exploit the vulnerability. An attacker would have no way to force users to visit the website.
Instead, an attacker would have to convince users to click a link, typically by way of an enticement in an email or instant message, and then convince them to open the specially crafted file. Note that the Preview Pane is not an attack vector for this vulnerability. The security update addresses the vulnerability by correcting how Office handles objects in memory.
(CVE-2017-8742)

- An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system. By itself, the information disclosure does not allow arbitrary code execution; however, it could allow arbitrary code to be run if the attacker uses it in combination with another vulnerability. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. Note that where the severity is indicated as Critical in the Affected Products table, the Preview Pane is an attack vector for this vulnerability. The security update addresses the vulnerability by correcting how GDI handles memory addresses. (CVE-2017-8676)
See Also
Solution
Microsoft has released security updates for Microsoft Office Products.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.9
EPSS Score
0.6601
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
BID 100732
BID 100741
BID 100748
BID 100755
BID 100772
BID 100773
BID 100780
CVE CVE-2017-8630
CVE CVE-2017-8676
CVE CVE-2017-8682
CVE CVE-2017-8695
CVE CVE-2017-8696
CVE CVE-2017-8742
CVE CVE-2017-8744
MSKB 4011055
MSKB 3213649
MSKB 4011038
MSKB 3213626
MSKB 3213646
MSKB 3213641
MSKB 3213642
MSKB 3213564
MSKB 3203474
MSKB 3213638
MSKB 4011103
MSKB 4011126
MSKB 4011063
MSKB 4011062
MSKB 3213551
MSKB 3213631
XREF MSFT:MS17-4011055
XREF MSFT:MS17-3213649
XREF MSFT:MS17-4011038
XREF MSFT:MS17-3213626
XREF MSFT:MS17-3213646
XREF MSFT:MS17-3213641
XREF MSFT:MS17-3213642
XREF MSFT:MS17-3213564
XREF MSFT:MS17-3203474
XREF MSFT:MS17-3213638
XREF MSFT:MS17-4011103
XREF MSFT:MS17-4011126
XREF MSFT:MS17-4011063
XREF MSFT:MS17-4011062
XREF MSFT:MS17-3213551
XREF MSFT:MS17-3213631
XREF IAVA:2017-A-0274
Plugin Information
Published: 2017/09/12, Modified: 2025/11/21
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4011038
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso99lwin32client.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4588.1000

Product : Microsoft Office 2016
KB : 4011126
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso30win32client.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4588.1002

Product : Microsoft Office 2016
KB : 3213551
- C:\Program Files\Common Files\Microsoft Shared\TextConv\wpft632.cnv has not been patched.
Remote version : 2012.1600.4266.1001
Should be : 2012.1600.4588.1000
128648 - Security Updates for Microsoft Office Products (September 2019)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Windows Jet Database Engine handles objects in memory. (CVE-2019-1246)

- A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2019-1297)

- An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the users computer or data. (CVE-2019-1263)

- A security feature bypass vulnerability exists when Microsoft Office improperly handles input. An attacker who successfully exploited the vulnerability could execute arbitrary commands. In a file-sharing attack scenario, an attacker could provide a specially crafted document file designed to exploit the vulnerability, and then convince a user to open the document file and interact with the document by clicking a specific cell.
The update addresses the vulnerability by correcting how Microsoft Office handles input. (CVE-2019-1264)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4464566
-KB4475607
-KB4475599
-KB4475611
-KB4475583
-KB4475591 For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.3546
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.7 (CVSS2#E:F/RL:OF/RC:C)
References
CVE CVE-2019-1246
CVE CVE-2019-1263
CVE CVE-2019-1264
CVE CVE-2019-1297
MSKB 4464566
MSKB 4475607
MSKB 4475599
MSKB 4475611
MSKB 4475583
MSKB 4475591
XREF MSFT:MS19-4464566
XREF MSFT:MS19-4475607
XREF MSFT:MS19-4475599
XREF MSFT:MS19-4475611
XREF MSFT:MS19-4475583
XREF MSFT:MS19-4475591
XREF CISA-KNOWN-EXPLOITED:2022/03/17
Plugin Information
Published: 2019/09/10, Modified: 2023/04/25
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4475591
- C:\Program Files\Common Files\Microsoft Shared\Office16\acecore.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4900.1000

Product : Microsoft Office 2016
KB : 4475583
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4900.1000
140430 - Security Updates for Microsoft Office Products (September 2020)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. It is, therefore, affected by multiple vulnerabilities :

- An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the users computer or data. (CVE-2020-1224)

- A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-1193, CVE-2020-1332, CVE-2020-1335, CVE-2020-1594)

- A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the same permissions as the current user. (CVE-2020-1218, CVE-2020-1338)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4484513
-KB4484533
-KB4484532
-KB4484517
-KB4484530
-KB4484469
-KB4484466

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.2188
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-1193
CVE CVE-2020-1218
CVE CVE-2020-1224
CVE CVE-2020-1332
CVE CVE-2020-1335
CVE CVE-2020-1338
CVE CVE-2020-1594
MSKB 4484513
MSKB 4484533
MSKB 4484532
MSKB 4484517
MSKB 4484530
MSKB 4484469
MSKB 4484466
XREF MSFT:MS20-4484513
XREF MSFT:MS20-4484533
XREF MSFT:MS20-4484532
XREF MSFT:MS20-4484517
XREF MSFT:MS20-4484530
XREF MSFT:MS20-4484469
XREF MSFT:MS20-4484466
XREF IAVA:2020-A-0406-S
XREF CEA-ID:CEA-2020-0118
Plugin Information
Published: 2020/09/08, Modified: 2024/11/29
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4484513
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5056.1000

Product : Microsoft Office 2016
KB : 4484466
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5056.1000
153387 - Security Updates for Microsoft Office Products (September 2021)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. It is, therefore, affected by multiple vulnerabilities:

- A session spoofing vulnerability exists. An attacker can exploit this to perform actions with the privileges of another user. (CVE-2021-38650)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2021-38646, CVE-2021-38655, CVE-2021-38658, CVE-2021-38659, CVE-2021-38660)

- An information disclosure vulnerability in the graphics component. An attacker can exploit this to disclose sensitive information. (CVE-2021-38657)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4484103
-KB4484108
-KB5001958
-KB5001997
-KB5002005
-KB5002007

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.3625
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-38646
CVE CVE-2021-38650
CVE CVE-2021-38655
CVE CVE-2021-38657
CVE CVE-2021-38658
CVE CVE-2021-38659
CVE CVE-2021-38660
MSKB 4484103
MSKB 4484108
MSKB 5001958
MSKB 5001997
MSKB 5002005
MSKB 5002007
XREF MSFT:MS21-4484103
XREF MSFT:MS21-4484108
XREF MSFT:MS21-5001958
XREF MSFT:MS21-5001997
XREF MSFT:MS21-5002005
XREF MSFT:MS21-5002007
XREF IAVA:2021-A-0428-S
XREF IAVA:2021-A-0425-S
XREF CISA-KNOWN-EXPLOITED:2022/04/18
Plugin Information
Published: 2021/09/14, Modified: 2023/04/25
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5001997
- C:\Program Files\Common Files\Microsoft Shared\Office16\acecore.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5164.1000

Product : Microsoft Office 2016
KB : 5002005
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5215.1000

Product : Microsoft Office 2016
KB : 4484103
- C:\Program Files\Microsoft Office\Office16\osfproxy.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5215.1000
164993 - Security Updates for Microsoft Office Products (September 2022)
-
Synopsis
The Microsoft Office Products are affected by a remote code execution vulnerability.
Description
The Microsoft Office Products are missing security updates. They are, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002178
-KB5002166

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0065
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.0 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-37962
MSKB 5002178
MSKB 5002166
XREF MSFT:MS22-5002178
XREF MSFT:MS22-5002166
XREF IAVA:2022-A-0372-S
Plugin Information
Published: 2022/09/13, Modified: 2023/10/12
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002178
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5361.1000
261796 - Security Updates for Microsoft Office Products (September 2025)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. They are, therefore, affected by multiple vulnerabilities.

- A Remote Code Execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-54906, CVE-2025-54910)

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2025-54901)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following updates to address these issues:
- KB5002576
- KB5002762
- KB5002766
- KB5002781
Risk Factor
High
CVSS v3.0 Base Score
8.4 (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0006
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-54901
CVE CVE-2025-54906
CVE CVE-2025-54910
MSKB 5002576
MSKB 5002762
MSKB 5002766
MSKB 5002781
XREF MSFT:MS25-5002576
XREF MSFT:MS25-5002762
XREF MSFT:MS25-5002766
XREF MSFT:MS25-5002781
XREF IAVA:2025-A-0666-S
XREF CWE:122
XREF CWE:126
XREF CWE:416
Plugin Information
Published: 2025/09/09, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002576
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso40uiwin32client.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5517.1000

Product : Microsoft Office 2016
KB : 5002762
- C:\Program Files\Microsoft Office\Office16\gkexcel.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5517.1000

Product : Microsoft Office 2016
KB : 5002766
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso99lwin32client.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5513.1000

Product : Microsoft Office 2016
KB : 5002781
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5517.1000
234035 - Security Updates for Microsoft OneNote Products (April 2025)
-
Synopsis
The Microsoft OneNote Products are missing a security update.
Description
The Microsoft OneNote Products are missing a security update. They are, therefore, affected by a security feature bypass vulnerability. An attacker can exploit this and bypass the security feature and perform unauthorized actions compromising the integrity of the system/application.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002622 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0008
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-29822
MSKB 5002622
XREF MSFT:MS25-5002622
XREF IAVA:2025-A-0240
XREF CWE:184
Plugin Information
Published: 2025/04/08, Modified: 2025/09/17
Plugin Output

tcp/445/cifs



Product : OneNote 2016
- C:\Program Files\Microsoft Office\Office16\OneNote.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5472.1000
135479 - Security Updates for Microsoft PowerPoint Products (April 2020)
-
Synopsis
The Microsoft PowerPoint Products are missing a security update.
Description
The Microsoft PowerPoint Products are missing a security update. It is, therefore, affected by the following vulnerability :

- A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries. An attacker could then install programs;
view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. (CVE-2020-0760)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4484235
-KB4484246
-KB4484226

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.3457
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2020-0760
MSKB 4484235
MSKB 4484246
MSKB 4484226
XREF MSFT:MS20-4484235
XREF MSFT:MS20-4484246
XREF MSFT:MS20-4484226
XREF IAVA:2020-A-0141-S
Plugin Information
Published: 2020/04/14, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : PowerPoint 2016
- C:\Program Files\Microsoft Office\Office16\ppcore.dll has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4993.1001
205595 - Security Updates for Microsoft PowerPoint Products (August 2024)
-
Synopsis
The Microsoft PowerPoint Products are missing a security update.
Description
The Microsoft PowerPoint Products are missing a security update. It is, therefore, affected by the following vulnerability:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2024-38171)
See Also
Solution
Microsoft has released KB5002586 to address this issue.

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0047
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-38171
MSKB 5002586
XREF MSFT:MS24-5002586
XREF IAVA:2024-A-0494-S
Plugin Information
Published: 2024/08/15, Modified: 2025/06/13
Plugin Output

tcp/445/cifs



Product : PowerPoint 2016
- C:\Program Files\Microsoft Office\Office16\ppcore.dll has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5461.1000
249134 - Security Updates for Microsoft PowerPoint Products (August 2025)
-
Synopsis
The Microsoft PowerPoint Products are missing a security update.
Description
The Microsoft PowerPoint Products are missing a security update. They are, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002765 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
5.9
EPSS Score
0.0006
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-53761
MSKB 5002765
XREF MSFT:MS25-5002765
XREF IAVA:2025-A-0597-S
XREF CWE:416
Plugin Information
Published: 2025/08/12, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



Product : PowerPoint 2016
- C:\Program Files\Microsoft Office\Office16\ppcore.dll has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5513.1000
119599 - Security Updates for Microsoft PowerPoint Products (December 2018)
-
Synopsis
The Microsoft PowerPoint Products are missing a security update.
Description
The Microsoft PowerPoint Products are missing a security update. It is, therefore, affected by the following vulnerability :

- A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-8628)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4461532
-KB4461481
-KB4461521
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.3453
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2018-8628
MSKB 4461532
MSKB 4461481
MSKB 4461521
XREF MSFT:MS18-4461532
XREF MSFT:MS18-4461481
XREF MSFT:MS18-4461521
Plugin Information
Published: 2018/12/11, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : PowerPoint 2016
- C:\Program Files\Microsoft Office\Office16\ppcore.dll has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4783.1000
131938 - Security Updates for Microsoft PowerPoint Products (December 2019)
-
Synopsis
The Microsoft PowerPoint Products are missing a security update.
Description
The Microsoft PowerPoint Products are missing a security update. It is, therefore, affected by the following vulnerability :

- A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2019-1462)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4461590
-KB4461613
-KB4484166 For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.2131
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2019-1462
MSKB 4461590
MSKB 4461613
MSKB 4484166
XREF MSFT:MS19-4461590
XREF MSFT:MS19-4461613
XREF MSFT:MS19-4484166
Plugin Information
Published: 2019/12/10, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : PowerPoint 2016
- C:\Program Files\Microsoft Office\Office16\ppcore.dll has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4936.1000
143567 - Security Updates for Microsoft PowerPoint Products (December 2020)
-
Synopsis
The Microsoft PowerPoint Products are missing a security update.
Description
The Microsoft PowerPoint Products are missing a security update. It is, therefore, affected by the following vulnerability:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2020-17124)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4484393
-KB4484372
-KB4484468

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0255
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-17124
MSKB 4484372
MSKB 4484468
MSKB 4484393
XREF MSFT:MS20-4484372
XREF MSFT:MS19-4484468
XREF MSFT:MS19-4484393
XREF IAVA:2020-A-0559-S
XREF IAVA:2021-A-0017-S
Plugin Information
Published: 2020/12/08, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : PowerPoint 2016
- C:\Program Files\Microsoft Office\Office16\ppcore.dll has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5095.1000
190470 - Security Updates for Microsoft PowerPoint Products (February 2024)
-
Synopsis
The Microsoft PowerPoint Products are missing a security update.
Description
The Microsoft PowerPoint Products are missing a security update. They are, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002495 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.0176
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-20673
MSKB 5002495
XREF MSFT:MS24-5002495
XREF IAVA:2024-A-0099-S
XREF IAVA:2024-A-0094-S
Plugin Information
Published: 2024/02/13, Modified: 2024/09/13
Plugin Output

tcp/445/cifs



Product : PowerPoint 2016
- C:\Program Files\Microsoft Office\Office16\ppcore.dll has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5435.1000
241542 - Security Updates for Microsoft PowerPoint Products (July 2025)
-
Synopsis
The Microsoft PowerPoint Products are missing a security update.
Description
The Microsoft PowerPoint Products are missing a security update. They are, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002746 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
5.9
EPSS Score
0.0006
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-49705
MSKB 5002746
XREF MSFT:MS25-5002746
XREF IAVA:2025-A-0490-S
XREF CWE:122
Plugin Information
Published: 2025/07/08, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



Product : PowerPoint 2016
- C:\Program Files\Microsoft Office\Office16\ppcore.dll has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5508.1000
238086 - Security Updates for Microsoft PowerPoint Products (June 2025)
-
Synopsis
The Microsoft PowerPoint Products are missing a security update.
Description
The Microsoft PowerPoint Products are missing a security update. They are, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002689 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0006
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-47175
MSKB 5002689
XREF MSFT:MS25-5002689
XREF IAVA:2025-A-0418-S
XREF CWE:416
Plugin Information
Published: 2025/06/10, Modified: 2025/09/17
Plugin Output

tcp/445/cifs



Product : PowerPoint 2016
- C:\Program Files\Microsoft Office\Office16\ppcore.dll has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5504.1000
147216 - Security Updates for Microsoft PowerPoint Products (March 2021)
-
Synopsis
The Microsoft PowerPoint Products are missing a security update.
Description
The Microsoft PowerPoint Products are missing a security update. It is, therefore, affected by the following vulnerability:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2021-27056)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4493227
-KB4504702
-KB4493224
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.1123
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2021-27056
MSKB 4493227
MSKB 4504702
MSKB 4493224
XREF MSFT:MS21-4493227
XREF MSFT:MS21-4504702
XREF MSFT:MS21-4493224
XREF IAVA:2021-A-0128-S
Plugin Information
Published: 2021/03/09, Modified: 2023/08/11
Plugin Output

tcp/445/cifs



Product : PowerPoint 2016
- C:\Program Files\Microsoft Office\Office16\ppcore.dll has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5131.1000
118015 - Security Updates for Microsoft PowerPoint Products (October 2018)
-
Synopsis
The Microsoft PowerPoint Products are missing a security update.
Description
The Microsoft PowerPoint Products are missing a security update. It is, therefore, affected by the following vulnerability :

- A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in Protected View. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-8501)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4092453
-KB4092482
-KB4461434
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.2056
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2018-8501
MSKB 4092453
MSKB 4092482
MSKB 4461434
XREF MSFT:MS18-4092453
XREF MSFT:MS18-4092482
XREF MSFT:MS18-4461434
Plugin Information
Published: 2018/10/09, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : PowerPoint 2016
- C:\Program Files\Microsoft Office\Office16\ppcore.dll has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4756.1000
270692 - Security Updates for Microsoft PowerPoint Products (October 2025)
-
Synopsis
The Microsoft PowerPoint Products are missing a security update.
Description
The Microsoft PowerPoint Products are missing a security update. They are, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002790 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
5.9
EPSS Score
0.0006
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-59238
MSKB 5002790
XREF MSFT:MS25-5002790
XREF IAVA:2025-A-0758
XREF CWE:416
Plugin Information
Published: 2025/10/17, Modified: 2025/10/17
Plugin Output

tcp/445/cifs



Product : PowerPoint 2016
- C:\Program Files\Microsoft Office\Office16\ppcore.dll has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5522.1000
261805 - Security Updates for Microsoft PowerPoint Products (September 2025)
-
Synopsis
The Microsoft PowerPoint Products are missing a security update.
Description
The Microsoft PowerPoint Products are missing a security update. They are, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002779 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
5.9
EPSS Score
0.0006
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-54908
MSKB 5002779
XREF MSFT:MS25-5002779
XREF IAVA:2025-A-0667-S
XREF CWE:416
Plugin Information
Published: 2025/09/09, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



Product : PowerPoint 2016
- C:\Program Files\Microsoft Office\Office16\ppcore.dll has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5517.1000
103136 - Security Updates for Microsoft Powerpoint Products (September 2017)
-
Synopsis
The Microsoft Powerpoint Products are affected by multiple vulnerabilities.
Description
The Microsoft Powerpoint Products are missing security updates. It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Exploitation of the vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Office software. In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and convincing the user to open the file. In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) that contains a specially crafted file designed to exploit the vulnerability. An attacker would have no way to force users to visit the website.
Instead, an attacker would have to convince users to click a link, typically by way of an enticement in an email or instant message, and then convince them to open the specially crafted file. Note that the Preview Pane is not an attack vector for this vulnerability. The security update addresses the vulnerability by correcting how Office handles objects in memory.
(CVE-2017-8742, CVE-2017-8743)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4011041
-KB3128027
-KB4011069
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.3652
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
BID 100741
BID 100746
CVE CVE-2017-8742
CVE CVE-2017-8743
MSKB 4011041
MSKB 3128027
MSKB 4011069
XREF MSFT:MS17-3213642
XREF MSFT:MS17-4011041
XREF MSFT:MS17-3128027
XREF MSFT:MS17-4011069
XREF IAVA:2017-A-0274
Plugin Information
Published: 2017/09/12, Modified: 2019/11/12
Plugin Output

tcp/445/cifs



Product : PowerPoint 2016
- C:\Program Files\Microsoft Office\Office16\ppcore.dll has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4588.1000
135462 - Security Updates for Microsoft Publisher Products (April 2020)
-
Synopsis
The Microsoft Publisher Products are missing a security update.
Description
The Microsoft Publisher Products are missing a security update. It is, therefore, affected by the following vulnerability :

- A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries. An attacker could then install programs;
view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. (CVE-2020-0760)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB3162033
-KB4011097
-KB4032216
Risk Factor
Medium
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.3457
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-0760
MSKB 3162033
MSKB 4011097
MSKB 4032216
XREF MSFT:MS20-3162033
XREF MSFT:MS20-4011097
XREF MSFT:MS20-4032216
XREF IAVA:2020-A-0173-S
Plugin Information
Published: 2020/04/14, Modified: 2022/05/17
Plugin Output

tcp/445/cifs



Product : Publisher 2016
- C:\Program Files\Microsoft Office\Office16\Mspub.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4993.1001
174114 - Security Updates for Microsoft Publisher Products (April 2023)
-
Synopsis
The Microsoft Publisher Products are missing a security update.
Description
The Microsoft Publisher Products are missing a security update. It is, therefore, affected by multiple remote code execution vulnerabilities. An attacker can exploit these to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002213
-KB5002221
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.0235
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-28287
CVE CVE-2023-28295
MSKB 5002213
MSKB 5002221
XREF MSFT:MS23-5002213
XREF MSFT:MS23-5002221
XREF IAVA:2023-A-0193-S
Plugin Information
Published: 2023/04/11, Modified: 2024/02/16
Plugin Output

tcp/445/cifs



Product : Publisher 2016
- C:\Program Files\Microsoft Office\Office16\Mspub.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5391.1000
190480 - Security Updates for Microsoft Publisher Products (February 2024)
-
Synopsis
The Microsoft Publisher Products are missing a security update.
Description
The Microsoft Publisher Products are missing a security update. They are, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002492 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.0176
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-20673
MSKB 5002492
XREF MSFT:MS24-5002492
XREF IAVA:2024-A-0101-S
XREF IAVA:2024-A-0094-S
Plugin Information
Published: 2024/02/13, Modified: 2024/09/13
Plugin Output

tcp/445/cifs



Product : Publisher 2016
- C:\Program Files\Microsoft Office\Office16\Mspub.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5435.1000
206892 - Security Updates for Microsoft Publisher Products (September 2024)
-
Synopsis
The Microsoft Publisher Products are missing a security update.
Description
The Microsoft Publisher Products are missing a security update. It is, therefore, affected by the following vulnerability:

- A security feature bypass vulnerability exists. An attacker can exploit this and bypass the security feature and perform unauthorized actions compromising the integrity of the system/application.
(CVE-2024-38226)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002566 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.3 (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0124
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-38226
MSKB 5002566
XREF MSFT:MS24-5002566
XREF CISA-KNOWN-EXPLOITED:2024/10/01
XREF IAVA:2024-A-0563
Plugin Information
Published: 2024/09/10, Modified: 2024/09/13
Plugin Output

tcp/445/cifs



Product : Publisher 2016
- C:\Program Files\Microsoft Office\Office16\Mspub.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5460.1000
135482 - Security Updates for Microsoft Word Products (April 2020)
-
Synopsis
The Microsoft Word Products are affected by multiple vulnerabilities.
Description
The Microsoft Word Products are missing security updates. It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries. An attacker could then install programs;
view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. (CVE-2020-0760)

- A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the same permissions as the current user. (CVE-2020-0980)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4484300
-KB4484319
-KB4484295

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.4016
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2020-0760
CVE CVE-2020-0980
MSKB 4484300
MSKB 4484319
MSKB 4484295
XREF MSFT:MS20-4484300
XREF MSFT:MS20-4484319
XREF MSFT:MS20-4484295
XREF IAVA:2020-A-0149-S
Plugin Information
Published: 2020/04/14, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4993.1001
148478 - Security Updates for Microsoft Word Products (April 2021)
-
Synopsis
The Microsoft Word Products are affected by a remote code execution vulnerability.
Description
The Microsoft Word Products are missing security updates. It is, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4493208
-KB4493218
-KB4493198 For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.0208
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-28453
MSKB 4493208
MSKB 4493218
MSKB 4493198
XREF MSFT:MS21-4493208
XREF MSFT:MS21-4493218
XREF MSFT:MS21-4493198
XREF IAVA:2021-A-0177-S
Plugin Information
Published: 2021/04/13, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5149.1000
234045 - Security Updates for Microsoft Word Products (April 2025)
-
Synopsis
The Microsoft Word Products are affected by multiple vulnerabilities.
Description
The Microsoft Word Products are missing security updates. They are, therefore, affected by multiple vulnerabilities:

- A security feature bypass vulnerability exists. An attacker can exploit this and bypass the security feature and perform unauthorized actions compromising the integrity of the system/application.
(CVE-2025-29816)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-27747, CVE-2025-29820)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002702 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0008
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-27747
CVE CVE-2025-29816
CVE CVE-2025-29820
MSKB 5002702
XREF MSFT:MS25-5002702
XREF IAVA:2025-A-0244-S
XREF CWE:349
XREF CWE:416
XREF CWE:822
Plugin Information
Published: 2025/04/08, Modified: 2025/09/17
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5495.1002
127856 - Security Updates for Microsoft Word Products (August 2019)
-
Synopsis
A Microsoft Word product is affected by multiple vulnerabilities.
Description
A Microsoft Word product is missing security updates. It is, therefore, affected by the following vulnerability :

- A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the same permissions as the current user. (CVE-2019-1201)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4475533
-KB4475547
-KB4475540
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.1029
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2019-1201
MSKB 4475533
MSKB 4475547
MSKB 4475540
XREF MSFT:MS19-4475533
XREF MSFT:MS19-4475547
XREF MSFT:MS19-4475540
Plugin Information
Published: 2019/08/13, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4888.1000
179672 - Security Updates for Microsoft Word Products (August 2023)
-
Synopsis
The Microsoft Word Products are missing a security update.
Description
The Microsoft Word Products are missing a security update. It is, therefore, affected by a vulnerability and missing a defense-in-depth security update.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002445
-KB5002464

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.0235
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-36895
MSKB 5002445
MSKB 5002464
XREF MSFT:MS23-5002445
XREF MSFT:MS23-5002464
XREF IAVA:2023-A-0419-S
Plugin Information
Published: 2023/08/10, Modified: 2023/09/18
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5408.1001
249121 - Security Updates for Microsoft Word Products (August 2025)
-
Synopsis
The Microsoft Word Products are affected by a multiple vulnerabilities.
Description
The Microsoft Word Products are missing a security update. They are, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-53733, CVE-2025-53738)

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2025-53736)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002763 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
8.4 (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0011
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-53733
CVE CVE-2025-53736
CVE CVE-2025-53738
MSKB 5002763
XREF MSFT:MS25-5002763
XREF IAVA:2025-A-0606-S
XREF CWE:126
XREF CWE:416
XREF CWE:681
Plugin Information
Published: 2025/08/12, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5513.1000
105192 - Security Updates for Microsoft Word Products (December 2017)
-
Synopsis
The Microsoft Word Products are affected by multiple vulnerabilities.
Description
The Microsoft Word Products are missing security updates. Microsoft has released an update for Microsoft Office that provides enhanced security as a defense-in-depth measure. The update disables the Dynamic Update Exchange protocol (DDE) in all supported editions of Microsoft Word. More information can be found in Microsoft Security Advisory 4053440.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4011590
-KB4011608
-KB4011614
-KB4011575
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
II
References
MSKB 4011590
MSKB 4011608
MSKB 4011614
MSKB 4011575
XREF MSFT:MS17-4011590
XREF MSFT:MS17-4011608
XREF MSFT:MS17-4011614
XREF MSFT:MS17-4011575
XREF IAVA:2017-A-0363-S
Plugin Information
Published: 2017/12/12, Modified: 2023/02/20
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4627.1000
277989 - Security Updates for Microsoft Word Products (December 2025)
-
Synopsis
The Microsoft Word Products are affected by multiple vulnerabilities.
Description
The Microsoft Word Products are missing a security update. They are, therefore, affected by multiple remote code execution vulnerabilities. An attacker can exploit these to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002806 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
7.4
EPSS Score
0.0008
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-62555
CVE CVE-2025-62558
CVE CVE-2025-62559
CVE CVE-2025-62562
MSKB 5002806
XREF MSFT:MS25-5002806
XREF IAVA:2025-A-0918
Plugin Information
Published: 2025/12/09, Modified: 2025/12/12
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5530.1000
190485 - Security Updates for Microsoft Word Products (February 2024)
-
Synopsis
The Microsoft Word Products are affected by multiple vulnerabilities.
Description
The Microsoft Word Products are missing security updates. They are, therefore, affected by multiple remote code execution vulnerabilities. An attacker can exploit these to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002542 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.0176
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-20673
CVE CVE-2024-21379
MSKB 5002542
XREF MSFT:MS24-5002542
XREF IAVA:2024-A-0094-S
XREF IAVA:2024-A-0097-S
Plugin Information
Published: 2024/02/13, Modified: 2024/11/15
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5435.1000
105700 - Security Updates for Microsoft Word Products (January 2018)
-
Synopsis
The Microsoft Word Products are affected by multiple vulnerabilities.
Description
The Microsoft Words Products are missing security updates. It is therefore affected by multiple issues involving handling of Office and RTF (Rich Text Format) files. If successfully exploited, an attacker could execute code in the context of the current user.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4011657
-KB4011659
-KB4011651
-KB4011643
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.8
EPSS Score
0.9406
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
BID 102370
BID 102373
BID 102375
BID 102381
BID 102406
CVE CVE-2018-0792
CVE CVE-2018-0793
CVE CVE-2018-0794
CVE CVE-2018-0797
CVE CVE-2018-0798
CVE CVE-2018-0845
CVE CVE-2018-0848
CVE CVE-2018-0849
CVE CVE-2018-0862
MSKB 4011657
MSKB 4011643
MSKB 4011659
MSKB 4011651
XREF MSFT:MS18-4011657
XREF MSFT:MS18-4011643
XREF MSFT:MS18-4011659
XREF MSFT:MS18-4011651
XREF IAVA:2018-A-0009-S
XREF CISA-KNOWN-EXPLOITED:2022/05/03
Plugin Information
Published: 2018/01/09, Modified: 2023/04/25
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4639.1000
121028 - Security Updates for Microsoft Word Products (January 2019)
-
Synopsis
The Microsoft Word Products are affected by multiple vulnerabilities.
Description
The Microsoft Word Products are missing security updates. It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the same permissions as the current user. (CVE-2019-0585)

- An information disclosure vulnerability exists when Microsoft Word macro buttons are used improperly. An attacker who successfully exploited this vulnerability could read arbitrary files from a targeted system.
(CVE-2019-0561)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4461543
-KB4461594
-KB4461625

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.2816
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2019-0561
CVE CVE-2019-0585
MSKB 4461543
MSKB 4461594
MSKB 4461625
XREF MSFT:MS19-4461543
XREF MSFT:MS19-4461594
XREF MSFT:MS19-4461625
Plugin Information
Published: 2019/01/08, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4795.1001
144875 - Security Updates for Microsoft Word Products (January 2021)
-
Synopsis
The Microsoft Word Products are affected by multiple vulnerabilities.
Description
The Microsoft Word Products are missing security updates. It is, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2021-1715, CVE-2021-1716)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4486764
-KB4493156
-KB4493145

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0215
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-1715
CVE CVE-2021-1716
MSKB 4486764
MSKB 4493156
MSKB 4493145
XREF MSFT:MS21-4486764
XREF MSFT:MS21-4493156
XREF MSFT:MS21-4493145
XREF IAVA:2021-A-0024-S
XREF CEA-ID:CEA-2021-0001
Plugin Information
Published: 2021/01/12, Modified: 2022/12/07
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5110.1000
156631 - Security Updates for Microsoft Word Products (January 2022)
-
Synopsis
The Microsoft Word Products are missing a security update.
Description
The Microsoft Word Products are missing a security update.
It is, therefore, affected by the following vulnerability:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2022-21842)
See Also
Solution
Microsoft has released KB5002057 to address this issue.

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.021
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-21842
MSKB 5002057
XREF MSFT:MS22-5002057
XREF IAVA:2022-A-0019-S
Plugin Information
Published: 2022/01/11, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5266.1000
110994 - Security Updates for Microsoft Word Products (July 2018)
-
Synopsis
The Microsoft Word Products are missing a security update.
Description
The Microsoft Word Products are missing a security update.
It is, therefore, affected by the following vulnerability :

- A tampering vulnerability exists when Microsoft Outlook does not properly handle specific attachment types when rendering HTML emails. An attacker could exploit the vulnerability by sending a specially crafted email and attachment to a victim, or by hosting a malicious .eml file on a web server. The attacker who successfully exploited the vulnerability could then embed untrusted TrueType fonts in the body of an email. This behavior could be combined with other exploits to further compromise a user's system. The security update addresses the vulnerability by correcting how Microsoft Outlook handles attachments. (CVE-2018-8310)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4022218
-KB4022224
-KB4022202
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.0551
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N)
CVSS v2.0 Temporal Score
3.7 (CVSS2#E:U/RL:OF/RC:C)
References
BID 104615
CVE CVE-2018-8310
MSKB 4022218
MSKB 4022224
MSKB 4022202
XREF MSFT:MS18-4022218
XREF MSFT:MS18-4022224
XREF MSFT:MS18-4022202
Plugin Information
Published: 2018/07/10, Modified: 2019/11/04
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4717.1000
138474 - Security Updates for Microsoft Word Products (July 2020)
-
Synopsis
The Microsoft Word Products are affected by multiple vulnerabilities.
Description
The Microsoft Word Products are missing security updates. It is, therefore, affected by multiple vulnerabilities :

- An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the users computer or data. (CVE-2020-1445)

- A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the same permissions as the current user. (CVE-2020-1446, CVE-2020-1447, CVE-2020-1448)

- An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory. An attacker who successfully exploited the vulnerability could view out of bound memory. Exploitation of the vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Office software. The security update addresses the vulnerability by properly initializing the affected variable. (CVE-2020-1342)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4484458
-KB4484446
-KB4484438

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.4595
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2020-1342
CVE CVE-2020-1445
CVE CVE-2020-1446
CVE CVE-2020-1447
CVE CVE-2020-1448
MSKB 4484458
MSKB 4484446
MSKB 4484438
XREF MSFT:MS20-4484458
XREF MSFT:MS20-4484446
XREF MSFT:MS20-4484438
XREF IAVA:2020-A-0312-S
Plugin Information
Published: 2020/07/14, Modified: 2024/03/01
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5032.1000
151590 - Security Updates for Microsoft Word Products (July 2021)
-
Synopsis
The Microsoft Word Products are affected by a remote code execution vulnerability.
Description
The Microsoft Word Products are missing security updates. They are, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5001949 to address this issue.

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0102
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-34452
MSKB 5001949
XREF MSFT:MS21-5001949
XREF IAVA:2021-A-0320-S
Plugin Information
Published: 2021/07/13, Modified: 2023/12/08
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5188.1000
241561 - Security Updates for Microsoft Word Products (July 2025)
-
Synopsis
The Microsoft Word Products are affected by a remote code execution vulnerability.
Description
The Microsoft Word Products are missing security updates. They are, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002745 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0006
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-49703
MSKB 5002745
XREF MSFT:MS25-5002745
XREF IAVA:2025-A-0495-S
XREF CWE:416
Plugin Information
Published: 2025/07/08, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5508.1000
125832 - Security Updates for Microsoft Word Products (June 2019)
-
Synopsis
The Microsoft Word Products are missing a security update.
Description
The Microsoft Word Products are missing a security update.
It is, therefore, affected by the following vulnerability :

- A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the same permissions as the current user. (CVE-2019-1034)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4461619
-KB4464590
-KB4464596
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.126
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2019-1034
MSKB 4461619
MSKB 4464590
MSKB 4464596
XREF MSFT:MS19-4461619
XREF MSFT:MS19-4464590
XREF MSFT:MS19-4464596
XREF CEA-ID:CEA-2019-0430
Plugin Information
Published: 2019/06/11, Modified: 2022/12/05
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4861.1000
238093 - Security Updates for Microsoft Word Products (June 2025)
-
Synopsis
The Microsoft Word Products are affected by multiple vulnerabilities.
Description
The Microsoft Word Products are missing security updates. They are, therefore, affected by multiple remote code execution vulnerabilities. An attacker can exploit these to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002710 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
5.9
EPSS Score
0.0006
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-47168
CVE CVE-2025-47169
MSKB 5002710
XREF MSFT:MS25-5002710
XREF IAVA:2025-A-0412-S
XREF CWE:122
XREF CWE:416
Plugin Information
Published: 2025/06/10, Modified: 2025/09/17
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5504.1000
108301 - Security Updates for Microsoft Word Products (March 2018)
-
Synopsis
The Microsoft Word Products are affected by multiple vulnerabilities.
Description
The Microsoft Word Products are missing security updates. It is, therefore, affected by multiple vulnerabilities :

- An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory. An attacker who successfully exploited the vulnerability could view out of bound memory. Exploitation of the vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Office software. The security update addresses the vulnerability by properly initializing the affected variable. (CVE-2018-0919)

- A remote code execution vulnerability exists in Microsoft Office software when the Office software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-0922)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4011721
-KB4011674
-KB4011730
-KB4011695
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.3251
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
BID 103311
BID 103314
CVE CVE-2018-0919
CVE CVE-2018-0922
MSKB 4011721
MSKB 4011674
MSKB 4011730
MSKB 4011695
XREF MSFT:MS18-4011721
XREF MSFT:MS18-4011674
XREF MSFT:MS18-4011730
XREF MSFT:MS18-4011695
XREF IAVA:2018-A-0077-S
Plugin Information
Published: 2018/03/13, Modified: 2020/12/11
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4666.1000
134382 - Security Updates for Microsoft Word Products (March 2020)
-
Synopsis
The Microsoft Word Products are affected by a Remote Code Execution Vulnerability. (CVE-2020-0850, CVE-2020-0892)
Description
The Microsoft Word Products are missing security updates.
It is, therefore, affected by affected by the following vulnerability:

- A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the same permissions as the current user.

To exploit the vulnerability, a user must open a specially crafted file with an affected version of Microsoft Word software. In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and convincing the user to open the file. In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) that contains a specially crafted file that is designed to exploit the vulnerability. However, an attacker would have no way to force the user to visit the website. Instead, an attacker would have to convince the user to click a link, typically by way of an enticement in an email or Instant Messenger message, and then convince the user to open the specially crafted file. (CVE-2020-0850, CVE-2020-0892)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4484268
-KB4484240
-KB4484231

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open Word and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.4016
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2020-0850
CVE CVE-2020-0892
MSKB 4484268
MSKB 4484240
MSKB 4484231
XREF MSFT:MS20-4484268
XREF MSFT:MS20-4484240
XREF MSFT:MS20-4484231
Plugin Information
Published: 2020/03/10, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4978.1000
232610 - Security Updates for Microsoft Word Products (March 2025)
-
Synopsis
The Microsoft Word Products are affected by a security feature bypass vulnerability.
Description
The Microsoft Word Products are missing security updates. They are, therefore, affected by multiple remote code execution vulnerabilities. An attacker can exploit these to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002662 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0008
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-24078
CVE CVE-2025-24079
MSKB 5002662
XREF MSFT:MS25-5002662
XREF IAVA:2025-A-0171-S
XREF IAVA:2025-A-0177-S
XREF IAVA:2025-A-0174-S
XREF CWE:416
Plugin Information
Published: 2025/03/11, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5491.1000
109617 - Security Updates for Microsoft Word Products (May 2018)
-
Synopsis
The Microsoft Word Products are missing a security update.
Description
The Microsoft Word Products are missing a security update.
It is, therefore, affected by the following vulnerability :

- A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-8161)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4018396
-KB4018383
-KB4022141
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.3244
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2018-8161
MSKB 4018396
MSKB 4018383
MSKB 4022141
XREF MSFT:MS18-4018396
XREF MSFT:MS18-4018383
XREF MSFT:MS18-4022141
XREF IAVA:2018-A-0151-S
Plugin Information
Published: 2018/05/08, Modified: 2020/12/11
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4690.1000
125072 - Security Updates for Microsoft Word Products (May 2019)
-
Synopsis
The Microsoft Word Products are missing a security update.
Description
The Microsoft Word Products are missing a security update. It is, therefore, affected by a remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the same permissions as the current user.
See Also
Solution
Microsoft has released KB4464536 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.2564
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2019-0953
MSKB 4464536
XREF MSFT:MS19-4464536
XREF CEA-ID:CEA-2019-0326
Plugin Information
Published: 2019/05/14, Modified: 2022/12/05
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4849.1000
149399 - Security Updates for Microsoft Word Products (May 2021)
-
Synopsis
The Microsoft Word Products are missing a security update.
Description
The Microsoft Word Products are missing a security update.
It is, therefore, affected by the following vulnerability:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2021-31180)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5001919
-KB5001931

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.0347
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-31180
MSKB 5001919
MSKB 5001931
XREF MSFT:MS21-5001919
XREF IAVA:2021-A-0226-S
XREF MSFT:MS21-5001931
Plugin Information
Published: 2021/05/11, Modified: 2024/01/02
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5161.1000
175346 - Security Updates for Microsoft Word Products (May 2023)
-
Synopsis
The Microsoft Word Products are missing a security update.
Description
The Microsoft Word Products are missing a security update. They are, therefore, affected by a security feature bypass vulnerability. An attacker can exploit this and bypass the security feature and perform unauthorized actions compromising the integrity of the system/application.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002365
-KB5002369
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.015
CVSS v2.0 Base Score
7.6 (CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-29335
MSKB 5002369
MSKB 5002365
XREF MSFT:MS23-5002369
XREF MSFT:MS23-5002365
XREF IAVA:2023-A-0246-S
Plugin Information
Published: 2023/05/09, Modified: 2023/07/13
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5395.1000
104562 - Security Updates for Microsoft Word Products (November 2017)
-
Synopsis
The Microsoft Word Products are missing a security update.
Description
The Microsoft Office Products are missing a security update.
It is, therefore, affected by the following vulnerability :

- A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2017-11854)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4011250
-KB4011242
-KB4011270
-KB4011266
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.1871
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
BID 101746
CVE CVE-2017-11854
MSKB 4011250
MSKB 4011242
MSKB 4011270
MSKB 4011266
XREF MSFT:MS17-4011250
XREF MSFT:MS17-4011242
XREF MSFT:MS17-4011270
XREF MSFT:MS17-4011266
XREF IAVA:2017-A-0337-S
Plugin Information
Published: 2017/11/14, Modified: 2021/06/03
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4615.1000
118930 - Security Updates for Microsoft Word Products (November 2018)
-
Synopsis
The Microsoft Word Products are missing a security update.
Description
The Microsoft Word Products are missing a security update.
It is, therefore, affected by the following vulnerability :

- A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the same permissions as the current user. (CVE-2018-8573)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4461526
-KB4461504
-KB4461485
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.1857
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
BID 105836
CVE CVE-2018-8573
MSKB 4461526
MSKB 4461504
MSKB 4461485
XREF MSFT:MS18-4461526
XREF MSFT:MS18-4461504
XREF MSFT:MS18-4461485
Plugin Information
Published: 2018/11/13, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4771.1000
210862 - Security Updates for Microsoft Word Products (November 2024)
-
Synopsis
The Microsoft Word Products are affected by a security feature bypass vulnerability.
Description
The Microsoft Word Products are missing security updates. They are, therefore, affected by a security feature bypass vulnerability.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002619 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0538
CVSS v2.0 Base Score
7.6 (CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-49033
MSKB 5002619
XREF MSFT:MS24-5002619
XREF IAVA:2024-A-0735-S
Plugin Information
Published: 2024/11/12, Modified: 2024/12/12
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5474.1000
118016 - Security Updates for Microsoft Word Products (October 2018)
-
Synopsis
The Microsoft Word Products are missing a security update.
Description
The Microsoft Word Products are missing a security update.
It is, therefore, affected by the following vulnerability :

- A remote code execution vulnerability exists in Microsoft Word software when the software fails to properly handle objects in Protected View. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-8504)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4092439
-KB4461457
-KB4461449
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.1681
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2018-8504
MSKB 4092439
MSKB 4461457
MSKB 4461449
XREF MSFT:MS18-4092439
XREF MSFT:MS18-4461457
XREF MSFT:MS18-4461449
Plugin Information
Published: 2018/10/09, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4756.1000
141415 - Security Updates for Microsoft Word Products (October 2020)
-
Synopsis
The Microsoft Word Products are missing a security update.
Description
The Microsoft Word Products are missing a security update.
It is, therefore, affected by the following vulnerability :

- A security feature bypass vulnerability exists in Microsoft Word software when it fails to properly handle .LNK files. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the same permissions as the current user. (CVE-2020-16933)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4486703
-KB4486692
-KB4486701
-KB4486679

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0157
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2020-16933
MSKB 4486703
MSKB 4486692
MSKB 4486679
XREF MSFT:MS20-4486703
XREF MSFT:MS20-4486692
XREF MSFT:MS20-4486679
XREF CEA-ID:CEA-2020-0126
Plugin Information
Published: 2020/10/13, Modified: 2024/11/29
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5071.1000
154031 - Security Updates for Microsoft Word Products (October 2021)
-
Synopsis
The Microsoft Word Products are missing a security update.
Description
The Microsoft Word Products are missing a security update.
It is, therefore, affected by the following vulnerability :

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2021-40486)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5001960
-KB5002004

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.0158
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-40486
MSKB 5001960
MSKB 5002004
XREF MSFT:MS21-5001960
XREF MSFT:MS21-5002004
XREF IAVA:2021-A-0473-S
Plugin Information
Published: 2021/10/12, Modified: 2023/11/28
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5227.1000
270364 - Security Updates for Microsoft Word Products (October 2025)
-
Synopsis
The Microsoft Word Products are affected by multiple vulnerabilities.
Description
The Microsoft Word Products are missing a security update. They are, therefore, affected by multiple remote code execution vulnerabilities. An attacker can exploit these to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002789 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0006
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-59221
CVE CVE-2025-59222
MSKB 5002789
XREF MSFT:MS25-5002789
XREF IAVA:2025-A-0762
XREF CWE:416
Plugin Information
Published: 2025/10/14, Modified: 2025/10/17
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5522.1000
117426 - Security Updates for Microsoft Word Products (September 2018)
-
Synopsis
The Microsoft Word Products are missing a security update.
Description
The Microsoft Word Products are missing a security update.
It is, therefore, affected by the following vulnerability :

- A remote code execution vulnerability exists in Microsoft Word if a user opens a specially crafted PDF file. An attacker who successfully exploited the vulnerability could cause arbitrary code to execute in the context of the current user. (CVE-2018-8430)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4032246
-KB4092447
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.1642
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
BID 105212
CVE CVE-2018-8430
MSKB 4032246
MSKB 4092447
XREF MSFT:MS18-4032246
XREF MSFT:MS18-4092447
Plugin Information
Published: 2018/09/11, Modified: 2019/11/01
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4744.1000
140433 - Security Updates for Microsoft Word Products (September 2020)
-
Synopsis
The Microsoft Word Products are missing a security update.
Description
The Microsoft Word Products are missing a security update.
It is, therefore, affected by the following vulnerability :

- A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the same permissions as the current user. (CVE-2020-1218)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4484510
-KB4484522
-KB4486660

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.024
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-1218
MSKB 4484510
MSKB 4484522
MSKB 4486660
XREF MSFT:MS20-4484510
XREF MSFT:MS20-4484522
XREF MSFT:MS20-4486660
XREF IAVA:2020-A-0404-S
XREF CEA-ID:CEA-2020-0118
Plugin Information
Published: 2020/09/08, Modified: 2024/11/29
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5056.1000
181292 - Security Updates for Microsoft Word Products (September 2023)
-
Synopsis
The Microsoft Word Products are affected by multiple vulnerabilities.
Description
The Microsoft Word Products are missing security updates. It is, therefore, affected by multiple vulnerabilities:

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2023-36761)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2023-36762)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002483
-KB5002497
Risk Factor
High
CVSS v3.0 Base Score
7.3 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
8.0
EPSS Score
0.0733
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N)
CVSS v2.0 Temporal Score
6.4 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-36761
CVE CVE-2023-36762
MSKB 5002483
MSKB 5002497
XREF MSFT:MS23-5002483
XREF MSFT:MS23-5002497
XREF CISA-KNOWN-EXPLOITED:2023/10/03
XREF IAVA:2023-A-0481-S
Plugin Information
Published: 2023/09/12, Modified: 2024/06/24
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5413.1000
261814 - Security Updates for Microsoft Word Products (September 2025)
-
Synopsis
The Microsoft Word Products are affected by a multiple vulnerabilities.
Description
The Microsoft Word Products are missing a security update. They are, therefore, affected by an information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002780 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.1 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H)
VPR Score
5.2
EPSS Score
0.0005
CVSS v2.0 Base Score
6.3 (CVSS2#AV:L/AC:M/Au:N/C:C/I:N/A:C)
STIG Severity
I
References
CVE CVE-2025-54905
MSKB 5002780
XREF MSFT:MS25-5002780
XREF IAVA:2025-A-0672-S
XREF CWE:822
Plugin Information
Published: 2025/09/09, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5517.1000
135478 - Security Updates for Outlook (April 2020)
-
Synopsis
The Microsoft Outlook application installed on the remote host is missing a security update.
Description
The Microsoft Outlook application installed on the remote host is missing a security update. It is, therefore, affected by the following vulnerability :

- A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries. An attacker could then install programs;
view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. (CVE-2020-0760)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4484281
-KB4484274
-KB4484284

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.3457
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2020-0760
MSKB 4484281
MSKB 4484274
MSKB 4484284
XREF MSFT:MS20-4484281
XREF MSFT:MS20-4484274
XREF MSFT:MS20-4484284
XREF IAVA:2020-A-0152-S
Plugin Information
Published: 2020/04/14, Modified: 2020/07/17
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4993.1001
148464 - Security Updates for Outlook (April 2021)
-
Synopsis
The Microsoft Outlook application installed on the remote host is affected by a memory corruption vulnerability.
Description
The Microsoft Outlook application installed on the remote host is missing security updates. It is, therefore, affected by a memory corruption vulnerability.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4504712
-KB4504733
-KB4493185

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.0073
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2021-28452
MSKB 4504712
MSKB 4504733
MSKB 4493185
XREF MSFT:MS21-4504712
XREF MSFT:MS21-4504733
XREF MSFT:MS21-4493185
XREF IAVA:2021-A-0175-S
Plugin Information
Published: 2021/04/13, Modified: 2024/11/29
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5149.1000
127854 - Security Updates for Outlook (August 2019)
-
Synopsis
The Microsoft Outlook application installed on the remote host is affected by multiple vulnerabilities.
Description
The Microsoft Outlook application installed on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the same permissions as the current user. (CVE-2019-1200)

- An elevation of privilege vulnerability exists when Microsoft Outlook initiates processing of incoming messages without sufficient validation of the formatting of the messages. An attacker who successfully exploited the vulnerability could attempt to force Outlook to load a local or remote message store (over SMB).
(CVE-2019-1204)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4475553
-KB4475573
-KB4475563
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.1249
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2019-1200
CVE CVE-2019-1204
MSKB 4475553
MSKB 4475573
MSKB 4475563
XREF MSFT:MS19-4475553
XREF MSFT:MS19-4475573
XREF MSFT:MS19-4475563
Plugin Information
Published: 2019/08/13, Modified: 2020/02/14
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4888.1000
163944 - Security Updates for Outlook (August 2022)
-
Synopsis
The Microsoft Outlook application installed on the remote host is missing a security update.
Description
The Microsoft Outlook application installed on the remote host is missing a security update. It is, therefore, affected by the following vulnerability:

- A denial of service (DoS) vulnerability. An attacker can exploit this issue to cause the affected component to deny system or application services. (CVE-2022-35742) Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5001990
-KB5002051

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.0582
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)
CVSS v2.0 Temporal Score
5.8 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-35742
MSKB 5001990
MSKB 5002051
XREF MSFT:MS22-5001990
XREF MSFT:MS22-5002051
XREF IAVA:2022-A-0316-S
XREF IAVA:2022-A-0325-S
Plugin Information
Published: 2022/08/09, Modified: 2023/03/21
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5257.1000
119598 - Security Updates for Outlook (December 2018)
-
Synopsis
The Microsoft Outlook application installed on the remote host is missing a security update.
Description
The Microsoft Outlook application installed on the remote host is missing a security update. It is, therefore, affected by the following vulnerability :

- A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the same permissions as the current user. (CVE-2018-8587)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4461576
-KB4461556
-KB4461544
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.4676
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2018-8587
MSKB 4461576
MSKB 4461556
MSKB 4461544
XREF MSFT:MS18-4461576
XREF MSFT:MS18-4461556
XREF MSFT:MS18-4461544
Plugin Information
Published: 2018/12/11, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4783.1000
143563 - Security Updates for Outlook (December 2020)
-
Synopsis
The Microsoft Outlook application installed on the remote host is missing a security update.
Description
The Microsoft Outlook application installed on the remote host is missing a security update. It is, therefore, affected by the following vulnerability:

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2020-17119)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4486732
-KB4486742
-KB4486748

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0507
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
3.7 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-17119
MSKB 4486742
MSKB 4486732
MSKB 4486748
XREF MSFT:MS20-4486742
XREF MSFT:MS20-4486732
XREF MSFT:MS20-4486748
XREF IAVA:2020-A-0558-S
XREF IAVA:2021-A-0017-S
Plugin Information
Published: 2020/12/08, Modified: 2025/08/29
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5095.1000
106807 - Security Updates for Outlook (February 2018)
-
Synopsis
The Microsoft Outlook application installed on the remote host is affected by multiple vulnerabilities.
Description
The Microsoft Outlook application installed on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities :

- An elevation of privilege vulnerability exists when Microsoft Outlook initiates processing of incoming messages without sufficient validation of the formatting of the messages. An attacker who successfully exploited the vulnerability could attempt to force Outlook to load a local or remote message store (over SMB).
(CVE-2018-0850)

- A remote code execution vulnerability exists in Microsoft Outlook when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2018-0852)
See Also
Solution
Microsoft has released the following security updates to address this issue:
- KB4011682
- KB4011697
- KB4011711
- KB4011200
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.3054
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
BID 102866
BID 102871
CVE CVE-2018-0850
CVE CVE-2018-0852
MSKB 4011682
MSKB 4011697
MSKB 4011711
MSKB 4011200
XREF MSFT:MS18-4011682
XREF MSFT:MS18-4011697
XREF MSFT:MS18-4011711
XREF MSFT:MS18-4011200
XREF IAVA:2018-A-0051-S
Plugin Information
Published: 2018/02/13, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4654.1000
190489 - Security Updates for Outlook (February 2024)
-
Synopsis
The Microsoft Outlook application installed on the remote host is missing a security update.
Description
The Microsoft Outlook application installed on the remote host is missing a security update. It is, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002543 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.9 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.1555
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.0 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-21378
MSKB 5002543
XREF MSFT:MS24-5002543
XREF IAVA:2024-A-0096-S
XREF IAVA:2024-A-0094-S
Plugin Information
Published: 2024/02/13, Modified: 2024/09/13
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5430.1000
105699 - Security Updates for Outlook (January 2018)
-
Synopsis
The version of Outlook installed on the remote host is affected by a remote code execution vulnerability.
Description
The version of Microsoft Outlook installed on the remote host is missing a security update. It is, therefore, affected by a remote code execution vulnerability in the way that Microsoft Outlook parses specially crafted email messages. An attacker who successfully exploited the vulnerability could take control of an affected system, then install programs; view, change, or delete data; or create new accounts with full user rights.
See Also
Solution
Microsoft has released a set of patches for Outlook 2007, 2010, 2013, and 2016.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.3557
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
BID 102383
CVE CVE-2018-0791
MSKB 4011213
MSKB 4011273
MSKB 4011637
MSKB 4011626
XREF MSFT:MS18-4011213
XREF MSFT:MS18-4011273
XREF MSFT:MS18-4011637
XREF MSFT:MS18-4011626
XREF IAVA:2018-A-0009-S
Plugin Information
Published: 2018/01/09, Modified: 2021/06/03
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4639.1000
102035 - Security Updates for Outlook (July 2017)
-
Synopsis
An application installed on the remote Windows host is affected by multiple vulnerabilities.
Description
The Microsoft Office or Outlook application installed on the remote Windows host is missing a security update. It is, therefore, affected by multiple vulnerabilities :

- A security feature bypass vulnerability exists in Microsoft Office due to improper handling of user-supplied input. An unauthenticated, remote attacker can exploit this, by convincing a user to open and interact with a specially crafted document file, to bypass security measures and execute arbitrary commands.
(CVE-2017-8571)

- An information disclosure vulnerability exists in Microsoft Office due to improper handling of objects in memory. An unauthenticated, remote attacker can exploit this, by convincing a user to open a specially crafted document file, to disclose the contents of memory.
(CVE-2017-8572)

- A remote code execution vulnerability exists in Microsoft Outlook due to improper parsing of email messages. An unauthenticated, remote attacker can exploit this, with a specially crafted email message with a malicious attachment, to execute arbitrary code in the context of the current user. (CVE-2017-8663)
See Also
Solution
Microsoft has released a set of patches for Outlook 2007, 2010, 2013, and 2016.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.1432
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
BID 99452
BID 99453
BID 100004
CVE CVE-2017-8571
CVE CVE-2017-8572
CVE CVE-2017-8663
MSKB 2956078
MSKB 3213643
MSKB 4011052
MSKB 4011078
XREF MSFT:MS17-2956078
XREF MSFT:MS17-3213643
XREF MSFT:MS17-4011052
XREF MSFT:MS17-4011078
Plugin Information
Published: 2017/07/28, Modified: 2019/11/12
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4573.1001
138470 - Security Updates for Outlook (July 2020)
-
Synopsis
The Microsoft Outlook application installed on the remote host is missing a security update.
Description
The Microsoft Outlook application installed on the remote host is missing a security update. It is, therefore, affected by the following vulnerability :

- A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the same permissions as the current user. (CVE-2020-1349)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4484382
-KB4484363
-KB4484433

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.2597
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2020-1349
MSKB 4484382
MSKB 4484363
MSKB 4484433
XREF MSFT:MS20-4484382
XREF MSFT:MS20-4484363
XREF MSFT:MS20-4484433
XREF IAVA:2020-A-0308-S
Plugin Information
Published: 2020/07/14, Modified: 2020/08/14
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5017.1000
178165 - Security Updates for Outlook (July 2023)
-
Synopsis
The Microsoft Outlook application installed on the remote host is affected by multiple vulnerabilities.
Description
The Microsoft Outlook application installed on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities:

- A session spoofing vulnerability exists. An attacker can exploit this to perform actions with the privileges of another user. (CVE-2023-33151)

- A security feature bypass vulnerability exists. An attacker can exploit this and bypass the security feature and perform unauthorized actions compromising the integrity of the system/application.
(CVE-2023-35311)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002427
-KB5002432
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.028
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N)
CVSS v2.0 Temporal Score
6.4 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-33151
CVE CVE-2023-35311
MSKB 5002427
MSKB 5002432
XREF MSFT:MS23-5002427
XREF MSFT:MS23-5002432
XREF CISA-KNOWN-EXPLOITED:2023/08/01
XREF IAVA:2023-A-0344-S
Plugin Information
Published: 2023/07/11, Modified: 2025/10/30
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5404.1000
241560 - Security Updates for Outlook (July 2025)
-
Synopsis
The Microsoft Outlook application installed on the remote host is missing a security update.
Description
The Microsoft Outlook application installed on the remote host is missing a security update. It is, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002747 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.0 (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0006
CVSS v2.0 Base Score
6.2 (CVSS2#AV:L/AC:H/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-49699
MSKB 5002747
XREF MSFT:MS25-5002747
XREF IAVA:2025-A-0489
XREF CWE:416
Plugin Information
Published: 2025/07/08, Modified: 2025/09/17
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5507.1000
150351 - Security Updates for Outlook (June 2021)
-
Synopsis
The Microsoft Outlook application installed on the remote host is affected by a remote code execution vulnerability.
Description
The Microsoft Outlook application installed on the remote host is missing security updates. It is, therefore, affected by a remote code execution vulnerability. An authenticated, remote attacker can exploit this to execute arbitrary code on an affected system.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5001934
-KB5001942 For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0082
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2021-31949
MSKB 5001942
MSKB 5001934
XREF MSFT:MS21-5001942
XREF MSFT:MS21-5001934
XREF IAVA:2021-A-0276-S
Plugin Information
Published: 2021/06/08, Modified: 2024/11/28
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5173.1000
177245 - Security Updates for Outlook (June 2023)
-
Synopsis
The Microsoft Outlook application installed on the remote host is missing a security update.
Description
The Microsoft Outlook application installed on the remote host is missing a security update. It is, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002382
-KB5002387
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.9 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.1054
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.8 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-33131
MSKB 5002382
MSKB 5002387
XREF MSFT:MS23-5002382
XREF MSFT:MS23-5002387
XREF IAVA:2023-A-0296-S
Plugin Information
Published: 2023/06/13, Modified: 2023/07/13
Plugin Output

tcp/445/cifs



Product : Microsoft Outlook 2016
KB : 5002387
- c:\program files\microsoft office\office16\outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5395.1000
200350 - Security Updates for Outlook (June 2024)
-
Synopsis
The Microsoft Outlook application installed on the remote host is missing a security update.
Description
The Microsoft Outlook application installed on the remote host is missing a security update. It is, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002600 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.1596
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.7 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-30103
MSKB 5002600
XREF MSFT:MS24-5002600
XREF IAVA:2024-A-0340-S
Plugin Information
Published: 2024/06/11, Modified: 2024/07/12
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5450.1000
118928 - Security Updates for Outlook (November 2018)
-
Synopsis
The Microsoft Outlook application installed on the remote host is affected by multiple vulnerabilities.
Description
The Microsoft Outlook application installed on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists in the way that Microsoft Outlook parses specially modified rule export files. An attacker who successfully exploited this vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-8582)

- A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the same permissions as the current user. (CVE-2018-8522, CVE-2018-8524, CVE-2018-8576)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4461486
-KB4461529
-KB4461506
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.2039
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
BID 105820
BID 105822
BID 105823
BID 105825
BID 105826
BID 105828
CVE CVE-2018-8522
CVE CVE-2018-8524
CVE CVE-2018-8558
CVE CVE-2018-8576
CVE CVE-2018-8579
CVE CVE-2018-8582
MSKB 4461486
MSKB 4461529
MSKB 4461506
XREF MSFT:MS18-4461486
XREF MSFT:MS18-4461529
XREF MSFT:MS18-4461506
Plugin Information
Published: 2018/11/13, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4771.1000
103752 - Security Updates for Outlook (October 2017)
-
Synopsis
The version of Outlook installed on the remote host is affected by multiple vulnerabilities.
Description
The version of Microsoft Outlook installed on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities :

- An information disclosure vulnerability exists when Microsoft Outlook fails to establish a secure connection. An attacker who exploited the vulnerability could use it to obtain the email content of a user. The security update addresses the vulnerability by preventing Outlook from disclosing user email content.
(CVE-2017-11776)

- A security feature bypass vulnerability exists when Microsoft Office improperly handles objects in memory.
An attacker who successfully exploited the vulnerability could execute arbitrary commands. In a file-sharing attack scenario, an attacker could provide a specially crafted document file designed to exploit the vulnerability, and then convince users to open the document file and interact with the document. The security update addresses the vulnerability by correcting how Microsoft Office handles objects in memory. (CVE-2017-11774)
See Also
Solution
Microsoft has released a set of patches for Outlook 2010, 2013, and 2016.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.9
EPSS Score
0.8285
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.9 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
BID 101098
BID 101106
CVE CVE-2017-11774
CVE CVE-2017-11776
MSKB 4011178
MSKB 4011196
XREF MSFT:MS17-4011162
XREF MSFT:MS17-4011178
XREF MSFT:MS17-4011196
XREF IAVA:2017-A-0291-S
XREF CISA-KNOWN-EXPLOITED:2022/05/03
Plugin Information
Published: 2017/10/10, Modified: 2023/02/17
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4600.1000
118014 - Security Updates for Outlook (October 2018)
-
Synopsis
The Microsoft Outlook application installed on the remote host is affected by multiple vulnerabilities.
Description
The Microsoft Outlook application installed on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities including a remote code execution vulnerability requiring user interaction. See Microsoft Security Advisory ADV180026 for more information.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4092477
-KB4461440
-KB4227170
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
References
MSKB 4092477
MSKB 4461440
MSKB 4227170
XREF MSFT:MS18-4092477
XREF MSFT:MS18-4461440
XREF MSFT:MS18-4227170
Plugin Information
Published: 2018/10/09, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4756.1001
141428 - Security Updates for Outlook (October 2020)
-
Synopsis
The Microsoft Outlook application installed on the remote host is affected by multiple vulnerabilities.
Description
The Microsoft Outlook application installed on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists in Microsoft Outlook software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the System user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-16947)

- A denial of service vulnerability exists in Microsoft Outlook software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could cause a remote denial of service against a system. Exploitation of the vulnerability requires that a specially crafted email be sent to a vulnerable Outlook server. The security update addresses the vulnerability by correcting how Microsoft Outlook handles objects in memory. (CVE-2020-16949)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4484524
-KB4486663
-KB4486671

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.9
EPSS Score
0.4558
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-16947
CVE CVE-2020-16949
MSKB 4484524
MSKB 4486663
MSKB 4486671
XREF MSFT:MS20-4484524
XREF MSFT:MS20-4486663
XREF MSFT:MS20-4486671
XREF IAVA:2020-A-0455-S
XREF CEA-ID:CEA-2020-0126
Plugin Information
Published: 2020/10/13, Modified: 2024/11/29
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5071.1000
103456 - Security Updates for Outlook (September 2017)
-
Synopsis
The version of Outlook installed on the remote host is affected by multiple vulnerabilities.
Description
The version of Microsoft Outlook installed on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists in the way that Microsoft Outlook parses specially crafted email messages. An attacker who successfully exploited the vulnerability could take control of an affected system to then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2017-0106)

- A security feature bypass vulnerability exists in Microsoft Office software when it improperly handles the parsing of file formats. To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted file. (CVE-2017-0204)

- A remote code execution vulnerability exists when Microsoft Office improperly validates input before loading dynamic link library (DLL) files. An attacker who successfully exploited this vulnerability could take control of an affected system to then install programs;
view, change, or delete data; or create new accounts with full user rights. (CVE-2017-8506)

- A remote code execution vulnerability exists in the way that Microsoft Outlook parses specially crafted email messages. An attacker who successfully exploited this vulnerability could take control of an affected system.
(CVE-2017-8507)

- A security feature bypass vulnerability exists in Microsoft Office software when it improperly handles the parsing of file formats. (CVE-2017-8508)

- A security feature bypass vulnerability exists when Microsoft Office Outlook improperly handles input.
An attacker who successfully exploited the vulnerability could execute arbitrary commands. (CVE-2017-8571)

- An information disclosure vulnerability exists when Microsoft Outlook fails to properly validate authentication requests. (CVE-2017-8572)

- A remote code execution vulnerability exists in the way that Microsoft Outlook parses specially crafted email messages. An attacker who successfully exploited the vulnerability could take control of an affected system.
(CVE-2017-8663)
See Also
Solution
Microsoft has released a set of patches for Outlook 2007, 2010, 2013, and 2016.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.3391
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
BID 97413
BID 97458
BID 98811
BID 98827
BID 98828
BID 99452
BID 99453
BID 100004
CVE CVE-2017-0106
CVE CVE-2017-0204
CVE CVE-2017-8506
CVE CVE-2017-8507
CVE CVE-2017-8508
CVE CVE-2017-8571
CVE CVE-2017-8572
CVE CVE-2017-8663
MSKB 4011089
MSKB 4011110
MSKB 4011091
MSKB 4011090
XREF MSFT:MS17-4011089
XREF MSFT:MS17-4011110
XREF MSFT:MS17-4011091
XREF MSFT:MS17-4011090
Plugin Information
Published: 2017/09/25, Modified: 2019/11/12
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4588.1000
181301 - Security Updates for Outlook (September 2023)
-
Synopsis
The Microsoft Outlook application installed on the remote host is missing a security update.
Description
The Microsoft Outlook application installed on the remote host is missing a security update. It is, therefore, affected by an information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002499 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.0352
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N)
CVSS v2.0 Temporal Score
5.8 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-36763
MSKB 5002499
XREF MSFT:MS23-5002499
XREF IAVA:2023-A-0480-S
Plugin Information
Published: 2023/09/12, Modified: 2024/02/16
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5413.1000
233416 - VMware Tools 11.x / 12.x < 12.5.1 Authentication Bypass (VMSA-2025-0005)
-
Synopsis
The virtualization tool suite is installed on the remote Windows host is affected by an authentication bypass vulnerability.
Description
The version of VMware Tools installed on the remote Windows host is 11.x or 12.x prior to 12.5.1. It is, therefore, affected by an authentication bypass vulnerability:

- VMware Tools for Windows contains an authentication bypass vulnerability due to improper access control. A malicious actor with non-administrative privileges on a guest VM may gain ability to perform certain high privilege operations within that VM. (CVE-2025-22230)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to VMware Tools version 12.5.1 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0003
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-22230
XREF VMSA:2025-0005
XREF IAVA:2025-A-0199-S
Plugin Information
Published: 2025/03/27, Modified: 2025/05/16
Plugin Output

tcp/445/cifs


Path : C:\Program Files\VMware\VMware Tools\
Installed version : 12.4.0.48309
Fixed version : 12.5.1
266420 - VMware Tools 11.x < 12.5.4 / 13.x < 13.0.5 Multiple Vulnerabilities (VMSA-2025-0015)
-
Synopsis
The virtualization tool suite installed on the remote host is affected by multiple vulnerabilities.
Description
The version of VMware Tools installed on the remote host is 11.x or 12.x prior to 12.5.4, or 13.x prior to 13.0.5.
It is, therefore, affected by multiple vulnerabilities as disclosed in the VMSA-2025-0015 advisory:

- VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM. (CVE-2025-41244)

- VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls. A malicious actor with non-administrative privileges on a guest VM, who is already authenticated through vCenter or ESX may exploit this issue to access other guest VMs. Successful exploitation requires knowledge of credentials of the targeted VMs and vCenter or ESX. (CVE-2025-41246)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to VMware Tools version 12.5.4, 13.0.5 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
9.2
EPSS Score
0.0002
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-41244
CVE CVE-2025-41246
XREF VMSA:2025-0015
XREF IAVA:2025-A-0712
XREF CISA-KNOWN-EXPLOITED:2025/11/20
Plugin Information
Published: 2025/10/02, Modified: 2025/10/30
Plugin Output

tcp/445/cifs


Path : C:\Program Files\VMware\VMware Tools\
Installed version : 12.4.0.48309
Fixed version : 12.5.4
CVE(s) : CVE-2025-41244 CVE-2025-41246
166555 - WinVerifyTrust Signature Validation CVE-2013-3900 Mitigation (EnableCertPaddingCheck)
-
Synopsis
The remote Windows host is potentially missing a mitigation for a remote code execution vulnerability.
Description
The remote system may be in a vulnerable state to CVE-2013-3900 due to a missing or misconfigured registry keys:
- HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck
- HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck An unauthenticated, remote attacker could exploit this, by sending specially crafted requests, to execute arbitrary code on an affected host.
See Also
Solution
Add and enable registry value EnableCertPaddingCheck:
- HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck

Additionally, on 64 Bit OS systems, Add and enable registry value EnableCertPaddingCheck:

- HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.0
EPSS Score
0.7941
CVSS v2.0 Base Score
7.6 (CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.6 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2013-3900
XREF CISA-KNOWN-EXPLOITED:2022/07/10
XREF IAVA:2013-A-0227
Plugin Information
Published: 2022/10/26, Modified: 2025/12/17
Plugin Output

tcp/445/cifs



Nessus detected the following potentially insecure registry key configuration:
- Software\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck is not present in the registry.
- Software\Wow6432Node\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck is not present in the registry.
216494 - Wireshark 4.2.x < 4.2.11 / 4.4.x < 4.4.4 DoS Vulnerability
-
Synopsis
An application installed on the remote Windows host is affected by a vulnerability.
Description
The version of Wireshark installed on the remote Windows host is prior to 4.2.11 or 4.4.4.
It is, therefore, affected by a vulnerability as referenced in the wireshark-4.2.11 advisory.

- The Bundle Protocol and CBOR dissectors could crash. Fixed in master: 83c73a83ad Fixed in release-4.4:
73d7d46bcc Fixed in release-4.2: 2e5e8c1d9a Discovered by OSS-Fuzz. We are unaware of any exploits for this issue. It may be possible to make Wireshark crash consume excessive CPU resources by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
(CVE-2025-1492)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Wireshark version 4.2.11, 4.4.4 or later.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.0002
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)
CVSS v2.0 Temporal Score
5.8 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-1492
XREF IAVB:2025-B-0029-S
Plugin Information
Published: 2025/02/19, Modified: 2025/06/05
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Wireshark
Installed version : 4.4.2
Fixed version : 4.4.4
237766 - Wireshark 4.2.x < 4.2.12 / 4.4.x < 4.4.7 DoS
-
Synopsis
An application installed on the remote Windows host is affected by a denial of service vulnerability.
Description
The version of Wireshark installed on the remote Windows host is 4.2.x prior to 4.2.12 or 4.4.x prior to 4.4.7. It is, therefore, affected by a denial of service vulnerability as referenced in the wnpa-sec-2025-02 advisory.

- Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows denial of service via packet injection or crafted capture file (CVE-2025-5601)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Wireshark version 4.2.12, 4.4.7 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0001
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVSS v2.0 Temporal Score
3.7 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-5601
XREF IAVB:2025-B-0086
Plugin Information
Published: 2025/06/04, Modified: 2025/06/25
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Wireshark
Installed version : 4.4.2
Fixed version : 4.4.7
271971 - Wireshark 4.4.x < 4.4.9 Multiple Vulnerabilities
-
Synopsis
An application installed on the remote Windows host is affected by multiple vulnerabilities.
Description
The version of Wireshark installed on the remote Windows host is prior to 4.4.9. It is, therefore, affected by multiple vulnerabilities as referenced in the wireshark-4.4.9 advisory.

- SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service (CVE-2025-9817)

- Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows denial of service via packet injection or crafted capture file (CVE-2025-5601)

- Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0 to 4.2.10 allows denial of service via packet injection or crafted capture file (CVE-2025-1492)

- FiveCo RAP dissector infinite loop in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file (CVE-2024-11595)

- ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file (CVE-2024-11596)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Wireshark version 4.4.9 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.7 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0014
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVSS v2.0 Temporal Score
3.9 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-9780
CVE CVE-2024-9781
CVE CVE-2024-11595
CVE CVE-2024-11596
CVE CVE-2025-1492
CVE CVE-2025-5601
CVE CVE-2025-9817
XREF IAVB:2024-B-0153-S
XREF IAVB:2024-B-0185-S
XREF IAVB:2025-B-0029-S
XREF IAVB:2025-B-0086-S
XREF IAVB:2025-B-0148-S
Plugin Information
Published: 2025/10/29, Modified: 2025/10/29
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Wireshark
Installed version : 4.4.2
Fixed version : 4.4.9

136929 - JQuery 1.2 < 3.5.0 Multiple XSS
-
Synopsis
The remote web server is affected by multiple cross site scripting vulnerability.
Description
According to the self-reported version in the script, the version of JQuery hosted on the remote web server is greater than or equal to 1.2 and prior to 3.5.0. It is, therefore, affected by multiple cross site scripting vulnerabilities.

Note, the vulnerabilities referenced in this plugin have no security impact on PAN-OS, and/or the scenarios required for successful exploitation do not exist on devices running a PAN-OS release.
See Also
Solution
Upgrade to JQuery version 3.5.0 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
6.1 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
CVSS v3.0 Temporal Score
5.7 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
5.7
EPSS Score
0.323
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)
CVSS v2.0 Temporal Score
3.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2020-11022
CVE CVE-2020-11023
XREF IAVB:2020-B-0030
XREF CEA-ID:CEA-2021-0004
XREF CEA-ID:CEA-2021-0025
XREF CISA-KNOWN-EXPLOITED:2025/02/13
Plugin Information
Published: 2020/05/28, Modified: 2025/01/24
Plugin Output

tcp/8001/www


URL : http://172.17.100.140:8001/Scripts/jquery-1.4.4.min.js
Installed version : 1.4.4
Fixed version : 3.5.0

tcp/8001/www


URL : http://172.17.100.140:8001/Scripts_SSO/jquery-3.3.1.js
Installed version : 3.3.1
Fixed version : 3.5.0

57608 - SMB Signing not required
-
Synopsis
Signing is not required on the remote SMB server.
Description
Signing is not required on the remote SMB server. An unauthenticated, remote attacker can exploit this to conduct man-in-the-middle attacks against the SMB server.
See Also
Solution
Enforce message signing in the host's configuration. On Windows, this is found in the policy setting 'Microsoft network server: Digitally sign communications (always)'. On Samba, the setting is called 'server signing'. See the 'see also' links for further details.
Risk Factor
Medium
CVSS v3.0 Base Score
5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
CVSS v3.0 Temporal Score
4.6 (CVSS:3.0/E:U/RL:O/RC:C)
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N)
CVSS v2.0 Temporal Score
3.7 (CVSS2#E:U/RL:OF/RC:C)
Plugin Information
Published: 2012/01/19, Modified: 2022/10/05
Plugin Output

tcp/445/cifs

51192 - SSL Certificate Cannot Be Trusted
-
Synopsis
The SSL certificate for this service cannot be trusted.
Description
The server's X.509 certificate cannot be trusted. This situation can occur in three different ways, in which the chain of trust can be broken, as stated below :

- First, the top of the certificate chain sent by the server might not be descended from a known public certificate authority. This can occur either when the top of the chain is an unrecognized, self-signed certificate, or when intermediate certificates are missing that would connect the top of the certificate chain to a known public certificate authority.

- Second, the certificate chain may contain a certificate that is not valid at the time of the scan. This can occur either when the scan occurs before one of the certificate's 'notBefore' dates, or after one of the certificate's 'notAfter' dates.

- Third, the certificate chain may contain a signature that either didn't match the certificate's information or could not be verified. Bad signatures can be fixed by getting the certificate with the bad signature to be re-signed by its issuer. Signatures that could not be verified are the result of the certificate's issuer using a signing algorithm that Nessus either does not support or does not recognize.

If the remote host is a public host in production, any break in the chain makes it more difficult for users to verify the authenticity and identity of the web server. This could make it easier to carry out man-in-the-middle attacks against the remote host.
See Also
Solution
Purchase or generate a proper SSL certificate for this service.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
CVSS v2.0 Base Score
6.4 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N)
Plugin Information
Published: 2010/12/15, Modified: 2025/06/16
Plugin Output

tcp/3389/msrdp


The following certificate was at the top of the certificate
chain sent by the remote host, but it is signed by an unknown
certificate authority :

|-Subject : CN=LKP_SIP_AppSrv-140
|-Issuer : CN=LKP_SIP_AppSrv-140
57582 - SSL Self-Signed Certificate
-
Synopsis
The SSL certificate chain for this service ends in an unrecognized self-signed certificate.
Description
The X.509 certificate chain for this service is not signed by a recognized certificate authority. If the remote host is a public host in production, this nullifies the use of SSL as anyone could establish a man-in-the-middle attack against the remote host.

Note that this plugin does not check for certificate chains that end in a certificate that is not self-signed, but is signed by an unrecognized certificate authority.
Solution
Purchase or generate a proper SSL certificate for this service.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
CVSS v2.0 Base Score
6.4 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N)
Plugin Information
Published: 2012/01/17, Modified: 2022/06/14
Plugin Output

tcp/3389/msrdp


The following certificate was found at the top of the certificate
chain sent by the remote host, but is self-signed and was not
found in the list of known certificate authorities :

|-Subject : CN=LKP_SIP_AppSrv-140

137272 - Security Feature Bypass Vulnerability for Word (June 2020)
-
Synopsis
The Microsoft Word Products are affected by security feature bypass vulnerability.
Description
The Microsoft Word Products is missing a security update, and Therefore is affected by a security feature bypass vulnerability. An attacker who exploited this vulnerability could cause a system to load remote images which could disclose the IP address of the targeted system to the attacker.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4484380
-KB4484396
-KB4484361

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
4.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N)
CVSS v3.0 Temporal Score
3.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
2.2
EPSS Score
0.0905
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
3.2 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2020-1229
MSKB 4484380
MSKB 4484396
MSKB 4484361
XREF MSFT:MS20-4484380
XREF MSFT:MS20-4484396
XREF MSFT:MS20-4484361
XREF IAVA:2020-A-0255-S
Plugin Information
Published: 2020/06/09, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5017.1000
270711 - Security Update for Microsoft .NET Core (October 2025)
-
Synopsis
The remote Windows host is affected by a .NET Core vulnerability
Description
The version of tested product installed on the remote host is prior to tested version. It is, therefore, affected by information disclosure vulnerability as referenced in the vendor advisory.

- Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network. (CVE-2025-55248)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Update .NET Core, remove vulnerable packages and refer to vendor advisory.
Risk Factor
Medium
CVSS v3.0 Base Score
4.8 (CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N)
VPR Score
3.6
EPSS Score
0.0003
CVSS v2.0 Base Score
4.9 (CVSS2#AV:N/AC:H/Au:S/C:C/I:N/A:N)
STIG Severity
I
References
CVE CVE-2025-55248
XREF IAVA:2025-A-0752
Plugin Information
Published: 2025/10/17, Modified: 2025/11/12
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NETCore.App\8.0.8\
Installed version : 8.0.8
Fixed version : 8.0.21

tcp/445/cifs


Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.8\
Installed version : 8.0.8
Fixed version : 8.0.21
131935 - Security Updates for Microsoft Excel Products (December 2019)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update.
It is, therefore, affected by the following vulnerability :

- An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the users computer or data. (CVE-2019-1464)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4484196
-KB4484190
-KB4484179 For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
5.5 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
4.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.1177
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
3.2 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2019-1464
MSKB 4484196
MSKB 4484190
MSKB 4484179
XREF MSFT:MS19-4484196
XREF MSFT:MS19-4484190
XREF MSFT:MS19-4484179
Plugin Information
Published: 2019/12/10, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4939.1000
122128 - Security Updates for Microsoft Excel Products (February 2019)
-
Synopsis
The Microsoft Excel Products are affected by multiple vulnerabilities.
Description
The Microsoft Excel Products are missing security updates. They are, therefore, affected by multiple vulnerabilities :

- An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user's computer or data. To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker must know the memory address location where the object was created.
(CVE-2019-0669)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4462186
-KB4461597
-KB4462115

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
5.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.1624
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
3.2 (CVSS2#E:U/RL:OF/RC:C)
References
BID 106897
CVE CVE-2019-0669
MSKB 4462186
MSKB 4461597
MSKB 4462115
XREF MSFT:MS19-4462186
XREF MSFT:MS19-4461597
XREF MSFT:MS19-4462115
Plugin Information
Published: 2019/02/12, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4810.1000
157441 - Security Updates for Microsoft Excel Products (February 2022)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. It is, therefore, affected by the following vulnerability:

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2022-22716)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002137
-KB5002156

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
5.5 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
4.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.013
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
3.2 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-22716
MSKB 5002137
MSKB 5002156
XREF MSFT:MS22-5002137
XREF MSFT:MS22-5002156
XREF IAVA:2022-A-0080-S
Plugin Information
Published: 2022/02/08, Modified: 2024/11/27
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5278.1000
178171 - Security Updates for Microsoft Excel Products (July 2023)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. It is, therefore, affected by an information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002434
-KB5002426
Risk Factor
Medium
CVSS v3.0 Base Score
5.5 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
4.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.0423
CVSS v2.0 Base Score
4.9 (CVSS2#AV:L/AC:L/Au:N/C:C/I:N/A:N)
CVSS v2.0 Temporal Score
3.6 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-33162
MSKB 5002434
MSKB 5002426
XREF MSFT:MS23-5002434
XREF MSFT:MS23-5002426
XREF IAVA:2023-A-0341-S
Plugin Information
Published: 2023/07/11, Modified: 2023/08/11
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5404.1000
110492 - Security Updates for Microsoft Excel Products (June 2018)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update.
It is, therefore, affected by the following vulnerability :

- An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the users computer or data. (CVE-2018-8246)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4022191
-KB4022209
-KB4022174
Risk Factor
Medium
CVSS v3.0 Base Score
5.5 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
4.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.1826
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
3.2 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2018-8246
MSKB 4022191
MSKB 4022209
MSKB 4022174
XREF MSFT:MS18-4022191
XREF MSFT:MS18-4022209
XREF MSFT:MS18-4022174
Plugin Information
Published: 2018/06/12, Modified: 2019/11/04
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4705.1000
117421 - Security Updates for Microsoft Excel Products (September 2018)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update.
It is, therefore, affected by the following vulnerability :

- An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could access information previously deleted from the active worksheet. (CVE-2018-8429)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4092460
-KB4227175
-KB4092479
Risk Factor
Medium
CVSS v3.0 Base Score
5.5 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
4.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.2296
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
3.2 (CVSS2#E:U/RL:OF/RC:C)
References
BID 105219
CVE CVE-2018-8429
MSKB 4092460
MSKB 4227175
MSKB 4092479
XREF MSFT:MS18-4092460
XREF MSFT:MS18-4227175
XREF MSFT:MS18-4092479
Plugin Information
Published: 2018/09/11, Modified: 2019/11/01
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4744.1000
181304 - Security Updates for Microsoft Excel Products (September 2023)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. It is, therefore, affected by an information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002488
-KB5002496
Risk Factor
Medium
CVSS v3.0 Base Score
5.5 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
4.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.0162
CVSS v2.0 Base Score
4.9 (CVSS2#AV:L/AC:L/Au:N/C:C/I:N/A:N)
CVSS v2.0 Temporal Score
3.6 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-36766
MSKB 5002488
MSKB 5002496
XREF MSFT:MS23-5002488
XREF MSFT:MS23-5002496
XREF IAVA:2023-A-0478-S
Plugin Information
Published: 2023/09/12, Modified: 2023/11/16
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5413.1000
111696 - Security Updates for Microsoft Office Products (August 2018)
-
Synopsis
The Microsoft Office Products are missing a security update.
Description
The Microsoft Office Products are missing a security update.
It is, therefore, affected by the following vulnerability :

- An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory. An attacker who successfully exploited the vulnerability could view out of bound memory. Exploitation of the vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Office software. The security update addresses the vulnerability by properly initializing the affected variable. (CVE-2018-8378)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4022198
-KB3213636
-KB4032239
-KB4032233
Risk Factor
Medium
CVSS v3.0 Base Score
5.5 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
4.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.2694
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
3.2 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2018-8378
MSKB 4022198
MSKB 3213636
MSKB 4032239
MSKB 4032233
XREF MSFT:MS18-4022198
XREF MSFT:MS18-3213636
XREF MSFT:MS18-4032239
XREF MSFT:MS18-4032233
Plugin Information
Published: 2018/08/14, Modified: 2019/11/04
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4032233
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.4732.1000
205462 - Security Updates for Microsoft Office Products (August 2024)
-
Synopsis
The Microsoft Office Products are affected by a spoofing vulnerability.
Description
The Microsoft Office Products are missing security updates. They are, therefore, affected by a spoofing vulnerability.
An attacker can exploit this to gain access to sensitive data via a third party interaction.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002570
-KB5002625
Risk Factor
High
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
6.0 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
5.1
EPSS Score
0.5358
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N)
CVSS v2.0 Temporal Score
6.4 (CVSS2#E:F/RL:OF/RC:C)
References
CVE CVE-2024-38200
MSKB 5002570
MSKB 5002625
XREF MSFT:MS24-5002570
XREF MSFT:MS24-5002625
Exploitable With
Core Impact (true)
Plugin Information
Published: 2024/08/13, Modified: 2025/10/06
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002625
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5461.1001

Product : Microsoft Office 2016
KB : 5002570
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso99lwin32client.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5460.1000
163044 - Security Updates for Microsoft Office Products (July 2022)
-
Synopsis
The Microsoft Office Products are missing a security update.
Description
The Microsoft Office Products are missing a security update. It is, therefore, affected by the following vulnerability:

- A security feature bypass vulnerability exists. An attacker can exploit this and bypass the security feature and perform unauthorized actions compromising the integrity of the system/application.
(CVE-2022-33632)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002112
-KB5002121

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
4.7 (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N)
CVSS v3.0 Temporal Score
4.4 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
5.1
EPSS Score
0.0009
CVSS v2.0 Base Score
4.6 (CVSS2#AV:N/AC:H/Au:S/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
3.8 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-33632
MSKB 5002112
MSKB 5002121
XREF MSFT:MS22-5002112
XREF MSFT:MS22-5002121
XREF IAVA:2022-A-0270-S
XREF CEA-ID:CEA-2022-0026
Plugin Information
Published: 2022/07/12, Modified: 2023/10/18
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2013 SP1
KB : 5002121
- C:\Program Files\Common Files\Microsoft Shared\VBA\VBA7.1\vbe7.dll has not been patched.
Remote version : 7.1.10.48
Should be : 7.1.11.23

Product : Microsoft Office 2016
KB : 5002112
- C:\Program Files\Common Files\Microsoft Shared\VBA\VBA7.1\vbe7.dll has not been patched.
Remote version : 7.1.10.48
Should be : 7.1.11.23
137267 - Security Updates for Microsoft Office Products (June 2020)
-
Synopsis
The Microsoft Office Products are missing a security update.
Description
The Microsoft Office Products are missing a security update.
It is, therefore, affected by the following vulnerability :

- A security feature bypass vulnerability exists in Microsoft Outlook when Office fails to enforce security settings configured on a system. An attacker who successfully exploited this vulnerability could cause a system to load remote images. These images could disclose the IP address of the targeted system to the attacker. Exploitation of the vulnerability requires that a user open a specially crafted image with an affected version of Microsoft Office software.
(CVE-2020-1229)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4484342
-KB4484351
-KB4484373
-KB4484378
Risk Factor
Medium
CVSS v3.0 Base Score
4.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N)
CVSS v3.0 Temporal Score
3.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
2.2
EPSS Score
0.0905
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
3.2 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2020-1229
MSKB 4484342
MSKB 4484351
MSKB 4484373
MSKB 4484378
XREF MSFT:MS20-4484342
XREF MSFT:MS20-4484351
XREF MSFT:MS20-4484373
XREF MSFT:MS20-4484378
XREF IAVA:2020-A-0255-S
Plugin Information
Published: 2020/06/09, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4484342
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5017.1000
147218 - Security Updates for Microsoft Office Products (March 2021)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates.
They are affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2021-24108, CVE-2021-27054, CVE-2021-27057, CVE-2021-27059)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4493228
-KB4493203
-KB4504703
-KB4493225
-KB4493200
-KB4493214
Risk Factor
High
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.0 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0487
CVSS v2.0 Base Score
8.5 (CVSS2#AV:N/AC:M/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.0 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-24108
CVE CVE-2021-27054
CVE CVE-2021-27057
CVE CVE-2021-27059
MSKB 4493228
MSKB 4493203
MSKB 4504703
MSKB 4493225
MSKB 4493200
MSKB 4493214
XREF MSFT:MS21-4493228
XREF MSFT:MS21-4493203
XREF MSFT:MS21-4504703
XREF MSFT:MS21-4493225
XREF MSFT:MS21-4493200
XREF MSFT:MS21-4493214
XREF IAVA:2021-A-0132-S
XREF CISA-KNOWN-EXPLOITED:2021/11/17
Plugin Information
Published: 2021/03/09, Modified: 2025/10/31
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4493200
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5134.1000

Product : Microsoft Office 2016
KB : 4493225
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5134.1000
185584 - Security Updates for Microsoft Office Products (November 2023)
-
Synopsis
The Microsoft Office Products are affected by a security feature bypass vulnerability.
Description
The Microsoft Office Products are missing security updates. It is, therefore, affected by a security feature bypass vulnerability. An attacker can exploit this and bypass the security feature and perform unauthorized actions compromising the integrity of the system/application.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002521 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
CVSS v3.0 Temporal Score
5.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.1
EPSS Score
0.0079
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N)
CVSS v2.0 Temporal Score
5.8 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-36413
MSKB 5002521
XREF MSFT:MS23-5002521
XREF IAVA:2023-A-0623-S
Plugin Information
Published: 2023/11/14, Modified: 2023/12/15
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002521
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5422.1000
208290 - Security Updates for Microsoft Office Products (October 2024)
-
Synopsis
The Microsoft Office Products are affected by a spoofing vulnerability.
Description
The Microsoft Office Products are missing security updates. They are, therefore, affected by a spoofing vulnerability.
An attacker can exploit this to gain access to sensitive data via a third party interaction.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002635 the to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
CVSS v3.0 Temporal Score
5.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.1
EPSS Score
0.0717
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N)
CVSS v2.0 Temporal Score
5.8 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-43609
MSKB 5002635
XREF MSFT:MS24-5002635
XREF IAVA:2024-A-0627-S
Plugin Information
Published: 2024/10/08, Modified: 2024/11/15
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002635
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso99lwin32client.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5463.1000
181295 - Security Updates for Microsoft Office Products (September 2023)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. It is, therefore, affected by multiple vulnerabilities:

- A security feature bypass vulnerability exists. An attacker can exploit this and bypass the security feature and perform unauthorized actions compromising the integrity of the system/application.
(CVE-2023-36767)

- A session spoofing vulnerability exists. An attacker can exploit this to perform actions with the privileges of another user. (CVE-2023-41764)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002100
-KB5002457
-KB5002477
-KB5002498
Risk Factor
Medium
CVSS v3.0 Base Score
5.5 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
CVSS v3.0 Temporal Score
4.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.1
EPSS Score
0.0174
CVSS v2.0 Base Score
4.9 (CVSS2#AV:L/AC:L/Au:N/C:N/I:C/A:N)
CVSS v2.0 Temporal Score
3.6 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-36767
CVE CVE-2023-41764
MSKB 5002100
MSKB 5002457
MSKB 5002477
MSKB 5002498
XREF MSFT:MS23-5002100
XREF MSFT:MS23-5002457
XREF MSFT:MS23-5002477
XREF MSFT:MS23-5002498
XREF IAVA:2023-A-0474-S
Plugin Information
Published: 2023/09/12, Modified: 2023/10/13
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002100
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso99lwin32client.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5413.1000

Product : Microsoft Office 2016
KB : 5002498
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso30win32client.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5413.1000

Product : Microsoft Office 2016
KB : 5002457
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5413.1000
160939 - Security Updates for Microsoft Publisher Products (May 2022)
-
Synopsis
The Microsoft Publisher Products are missing a security update.
Description
The Microsoft Publisher Products are missing a security update. It is, therefore, affected by the following vulnerability:

- A security feature bypass vulnerability exists. An attacker can exploit this and bypass the security feature and perform unauthorized actions compromising the integrity of the system/application.
(CVE-2022-29107)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4484347
-KB4493152
Risk Factor
Medium
CVSS v3.0 Base Score
5.5 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
5.1 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.006
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
3.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-29107
MSKB 4484347
MSKB 4493152
XREF MSFT:MS22-4484347
XREF MSFT:MS22-4493152
XREF IAVA:2022-A-0197-S
Plugin Information
Published: 2022/05/10, Modified: 2023/10/27
Plugin Output

tcp/445/cifs



Product : Publisher 2016
- C:\Program Files\Microsoft Office\Office16\Mspub.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5317.1000
108976 - Security Updates for Microsoft Word Products (April 2018)
-
Synopsis
The Microsoft Word Products are affected by an information disclosure vulnerability.
Description
The Microsoft Word Products are missing security updates. It is, therefore, affected by an information disclosure vulnerability when Office renders Rich Text Format (RTF) email messages containing OLE objects when a message is opened or previewed. This vulnerability could potentially result in the disclosure of sensitive information to a malicious site.

The security update addresses the vulnerability by correcting how Office processes OLE objects.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4018339
-KB4018355
-KB4018347
-KB4018359
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
5.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.1072
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
3.2 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2018-0950
MSKB 4018339
MSKB 4018355
MSKB 4018347
MSKB 4018359
XREF MSFT:MS18-4018339
XREF MSFT:MS18-4018355
XREF MSFT:MS18-4018347
XREF MSFT:MS18-4018359
Plugin Information
Published: 2018/04/10, Modified: 2019/11/08
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4666.1000
139507 - Security Updates for Microsoft Word Products (August 2020)
-
Synopsis
The Microsoft Word Products are affected by multiple vulnerabilities.
Description
The Microsoft Word Products are missing security updates. It is, therefore, affected by multiple vulnerabilities :

- An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. (CVE-2020-1502)

- An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the users computer or data. (CVE-2020-1503, CVE-2020-1583)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4484494
-KB4484484
-KB4484474

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
5.5 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
4.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.2252
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
3.2 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-1502
CVE CVE-2020-1503
CVE CVE-2020-1583
MSKB 4484494
MSKB 4484484
MSKB 4484474
XREF MSFT:MS20-4484494
XREF MSFT:MS20-4484484
XREF MSFT:MS20-4484474
XREF IAVA:2020-A-0359-S
XREF CEA-ID:CEA-2020-0101
Plugin Information
Published: 2020/08/11, Modified: 2024/12/02
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5044.1000
131940 - Security Updates for Microsoft Word Products (December 2019)
-
Synopsis
The Microsoft Word Products are missing a security update.
Description
The Microsoft Word Products are missing a security update.
It is, therefore, affected by the following vulnerability :

- A denial of service vulnerability exists in Microsoft Word software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could cause a remote denial of service against a system. Exploitation of the vulnerability requires that a specially crafted document be sent to a vulnerable user. The security update addresses the vulnerability by correcting how Microsoft Word handles objects in memory. (CVE-2019-1461)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4475601
-KB4484094
-KB4484169 For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
5.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.1505
CVSS v2.0 Base Score
7.1 (CVSS2#AV:N/AC:M/Au:N/C:N/I:N/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2019-1461
MSKB 4475601
MSKB 4484094
MSKB 4484169
XREF MSFT:MS19-4475601
XREF MSFT:MS19-4484094
XREF MSFT:MS19-4484169
Plugin Information
Published: 2019/12/10, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4939.1000
186780 - Security Updates for Microsoft Word Products (December 2023)
-
Synopsis
The Microsoft Word Products are affected by an information disclosure vulnerability.
Description
The Microsoft Word Products are missing security updates. It is, therefore, affected by an information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002520 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
5.5 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
4.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.0071
CVSS v2.0 Base Score
4.9 (CVSS2#AV:L/AC:L/Au:N/C:C/I:N/A:N)
CVSS v2.0 Temporal Score
3.6 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-36009
MSKB 5002520
XREF MSFT:MS23-5002520
XREF IAVA:2023-A-0686-S
Plugin Information
Published: 2023/12/12, Modified: 2024/01/12
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5426.1000
158705 - Security Updates for Microsoft Word Products (March 2022)
-
Synopsis
The Microsoft Word Products are missing a security update.
Description
The Microsoft Word Products are missing a security update.
It is, therefore, affected by the following vulnerability:

- A Microsoft Office Word Tampering Vulnerability. (CVE-2022-24511)
See Also
Solution
Microsoft has released KB5002068 and 5002139 to address this issue.

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
5.5 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
4.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.0018
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)
CVSS v2.0 Temporal Score
3.2 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-24462
CVE CVE-2022-24511
MSKB 5002068
MSKB 5002139
XREF MSFT:MS22-5002068
XREF MSFT:MS22-5002139
XREF IAVA:2022-A-0107-S
Plugin Information
Published: 2022/03/08, Modified: 2024/11/27
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5290.1000
160935 - Security Updates for Microsoft Word Products (May 2022)
-
Synopsis
The Microsoft Word Products are missing a security update.
Description
The Microsoft Word Products are missing a security update. It is, therefore, affected by the following vulnerability:

- A security feature bypass vulnerability exists. An attacker can exploit this and bypass the security feature and perform unauthorized actions compromising the integrity of the system/application.
(CVE-2022-29107)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002184
-KB5002187

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
5.5 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
5.1 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.006
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
3.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-29107
MSKB 5002184
MSKB 5002187
XREF MSFT:MS22-5002184
XREF MSFT:MS22-5002187
XREF IAVA:2022-A-0199-S
Plugin Information
Published: 2022/05/10, Modified: 2023/10/27
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5317.1000
167110 - Security Updates for Microsoft Word Products (November 2022)
-
Synopsis
The Microsoft Word Products are affected by multiple vulnerabilities.
Description
The Microsoft Word Products are missing security updates. It is, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2022-41061)

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2022-41060, CVE-2022-41103)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002217
-KB5002223

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
5.5 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
5.1 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0029
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.0 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-41060
CVE CVE-2022-41061
CVE CVE-2022-41103
MSKB 5002217
MSKB 5002223
XREF MSFT:MS22-5002217
XREF MSFT:MS22-5002223
XREF IAVA:2022-A-0478-S
Plugin Information
Published: 2022/11/08, Modified: 2025/03/04
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5369.1000
139505 - Security Updates for Outlook (August 2020)
-
Synopsis
The Microsoft Outlook application installed on the remote host is affected by multiple vulnerabilities.
Description
The Microsoft Outlook application installed on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists in Microsoft Outlook when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2020-1483)

- An information disclosure vulnerability exists when attaching files to Outlook messages. This vulnerability could potentially allow users to share attached files such that they are accessible by anonymous users where they should be restricted to specific users.
(CVE-2020-1493)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4484486
-KB4484497
-KB4484475

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
5.5 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
5.0 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.3
EPSS Score
0.3033
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.3 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-1483
CVE CVE-2020-1493
MSKB 4484486
MSKB 4484497
MSKB 4484475
XREF MSFT:MS20-4484486
XREF MSFT:MS20-4484497
XREF MSFT:MS20-4484475
XREF IAVA:2020-A-0360-S
XREF CEA-ID:CEA-2020-0101
Plugin Information
Published: 2020/08/11, Modified: 2024/02/26
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5044.1000
179496 - Security Updates for Outlook (August 2023)
-
Synopsis
The Microsoft Outlook application installed on the remote host is affected by multiple vulnerabilities.
Description
The Microsoft Outlook application installed on the remote host is missing a security update. It is, therefore, affected by the following vulnerability:

- A session spoofing vulnerability exists. An attacker can exploit this to perform actions with the privileges of another user. (CVE-2023-36893)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002459
-KB5002449 For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
High
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
5.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.0415
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N)
CVSS v2.0 Temporal Score
5.8 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-36893
MSKB 5002449
MSKB 5002459
XREF MSFT:MS23-5002449
XREF MSFT:MS23-5002459
XREF IAVA:2023-A-0408-S
XREF IAVA:2023-A-0419-S
Plugin Information
Published: 2023/08/08, Modified: 2023/09/18
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5408.1000
205596 - Security Updates for Outlook (August 2024)
-
Synopsis
The Microsoft Outlook application installed on the remote host is missing a security update.
Description
The Microsoft Outlook application installed on the remote host is missing a security update. It is, therefore, affected by the following vulnerability:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2024-38173)
See Also
Solution
Microsoft has released KB5002626 to address this issue.

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
6.7 (CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
5.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.0023
CVSS v2.0 Base Score
6.0 (CVSS2#AV:L/AC:H/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
4.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-38173
MSKB 5002626
XREF MSFT:MS24-5002626
XREF IAVA:2024-A-0493-S
Plugin Information
Published: 2024/08/15, Modified: 2025/01/17
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5461.1001
186783 - Security Updates for Outlook (December 2023)
-
Synopsis
The Microsoft Outlook application installed on the remote host is missing a security update.
Description
The Microsoft Outlook application installed on the remote host is missing a security update. It is, therefore, affected by an information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002520 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
5.9 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.1188
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N)
CVSS v2.0 Temporal Score
6.1 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-35636
MSKB 5002529
XREF MSFT:MS23-5002529
XREF IAVA:2023-A-0686-S
Plugin Information
Published: 2023/12/12, Modified: 2024/01/23
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5426.1000
133622 - Security Updates for Outlook (February 2020)
-
Synopsis
The Microsoft Outlook application installed on the remote host is affected by a Security Feature Bypass Vulnerability (CVE-2020-0696).
Description
An security feature bypass exists in Outlook due to improper the parsing of URI formats. An unauthenticated, remote attacker can exploit this via a specially crafted URI. This can provide opportunities for additional exploits.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4484250
-KB4484163
-KB4484156
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
CVSS v3.0 Temporal Score
5.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0497
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)
CVSS v2.0 Temporal Score
3.2 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2020-0696
MSKB 4484250
MSKB 4484163
MSKB 4484156
XREF MSFT:MS20-4484250
XREF MSFT:MS20-4484163
XREF MSFT:MS20-4484156
Plugin Information
Published: 2020/02/11, Modified: 2020/04/17
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4966.1000
121027 - Security Updates for Outlook (January 2019)
-
Synopsis
The Microsoft Outlook application installed on the remote host is missing a security update.
Description
The Microsoft Outlook application installed on the remote host is missing a security update. It is, therefore, affected by the following vulnerability :

- An information disclosure vulnerability exists when Microsoft Outlook improperly handles certain types of messages. An attacker who successfully exploited this vulnerability could gather information about the victim.
An attacker could exploit this vulnerability by sending a specially crafted email to the victim. The update addresses the vulnerability by correcting the way Microsoft Outlook handles these types of messages.
(CVE-2019-0559)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4461595
-KB4461601
-KB4461623

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
5.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.2237
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
3.2 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2019-0559
MSKB 4461595
MSKB 4461601
MSKB 4461623
XREF MSFT:MS19-4461595
XREF MSFT:MS19-4461601
XREF MSFT:MS19-4461623
Plugin Information
Published: 2019/01/08, Modified: 2019/10/31
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4795.1000
214117 - Security Updates for Outlook (January 2025)
-
Synopsis
The Microsoft Outlook application installed on the remote host is missing a security update.
Description
The Microsoft Outlook application installed on the remote host is missing a security update. It is, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002656 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
6.7 (CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
5.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0006
CVSS v2.0 Base Score
6.0 (CVSS2#AV:L/AC:H/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
4.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-21357
MSKB 5002656
XREF MSFT:MS25-5002656
XREF IAVA:2025-A-0036-S
XREF CWE:908
Plugin Information
Published: 2025/01/14, Modified: 2025/09/17
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5483.1000
126585 - Security Updates for Outlook (July 2019)
-
Synopsis
The Microsoft Outlook application installed on the remote host is affected by a vulnerability.
Description
The Microsoft Outlook application installed on the remote host is missing security updates. It is, therefore, affected by a vulnerability:

- An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. (CVE-2019-1084)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4464592
-KB4475517
-KB4475509

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
5.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.0796
CVSS v2.0 Base Score
4.0 (CVSS2#AV:N/AC:L/Au:S/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
3.0 (CVSS2#E:U/RL:OF/RC:C)
References
BID 108929
CVE CVE-2019-1084
MSKB 4464592
MSKB 4475509
MSKB 4475517
XREF MSFT:MS19-4464592
XREF MSFT:MS19-4475509
XREF MSFT:MS19-4475517
Plugin Information
Published: 2019/07/09, Modified: 2019/10/18
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4873.1000
202023 - Security Updates for Outlook (July 2024)
-
Synopsis
The Microsoft Outlook application installed on the remote host is missing a security update.
Description
The Microsoft Outlook application installed on the remote host is missing a security update. It is, therefore, affected by the following vulnerability:

- A session spoofing vulnerability exists. An attacker can exploit this to perform actions with the privileges of another user. (CVE-2024-38020)
See Also
Solution
Microsoft has released KB5002621 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
5.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.0046
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N)
CVSS v2.0 Temporal Score
5.8 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-38020
MSKB 5002621
XREF MSFT:MS24-5002621
XREF IAVA:2024-A-0403-S
XREF IAVA:2024-A-0402-S
Plugin Information
Published: 2024/07/09, Modified: 2024/09/13
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5456.1000
110499 - Security Updates for Outlook (June 2018)
-
Synopsis
The Microsoft Outlook application installed on the remote host is missing a security update.
Description
The Microsoft Outlook application installed on the remote host is missing a security update. It is, therefore, affected by the following vulnerability :

- An elevation of privilege vulnerability exists when Microsoft Outlook does not validate attachment headers properly. An attacker who successfully exploited the vulnerability could send an email with hidden attachments that would be opened or executed once a victim clicks a link within the email. Note that this does not bypass attachment filters, so blocked attachments will still be excluded. (CVE-2018-8244)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4022205
-KB4022169
-KB4022160
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
CVSS v3.0 Temporal Score
5.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.104
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)
CVSS v2.0 Temporal Score
3.2 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2018-8244
MSKB 4022205
MSKB 4022169
MSKB 4022160
XREF MSFT:MS18-4022205
XREF MSFT:MS18-4022169
XREF MSFT:MS18-4022160
Plugin Information
Published: 2018/06/12, Modified: 2019/11/04
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4705.1000
238078 - Security Updates for Outlook (June 2025)
-
Synopsis
The Microsoft Outlook application installed on the remote host is missing a security update.
Description
The Microsoft Outlook application installed on the remote host is missing a security update. It is, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002683 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
6.7 (CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0007
CVSS v2.0 Base Score
6.0 (CVSS2#AV:L/AC:H/Au:S/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-47171
MSKB 5002683
XREF MSFT:MS25-5002683
XREF IAVA:2025-A-0415-S
XREF CWE:20
Plugin Information
Published: 2025/06/10, Modified: 2025/09/17
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5504.1000

104743 - TLS Version 1.0 Protocol Detection
-
Synopsis
The remote service encrypts traffic using an older version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.0. TLS 1.0 has a number of cryptographic design flaws. Modern implementations of TLS 1.0 mitigate these problems, but newer versions of TLS like 1.2 and 1.3 are designed against these flaws and should be used whenever possible.

As of March 31, 2020, Endpoints that aren’t enabled for TLS 1.2 and higher will no longer function properly with major web browsers and major vendors.

PCI DSS v3.2 requires that TLS 1.0 be disabled entirely by June 30, 2018, except for POS POI terminals (and the SSL/TLS termination points to which they connect) that can be verified as not being susceptible to any known exploits.
See Also
Solution
Enable support for TLS 1.2 and 1.3, and disable support for TLS 1.0.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N)
CVSS v2.0 Base Score
6.1 (CVSS2#AV:N/AC:H/Au:N/C:C/I:P/A:N)
References
XREF CWE:327
Plugin Information
Published: 2017/11/22, Modified: 2023/04/19
Plugin Output

tcp/3389/msrdp

TLSv1 is enabled and the server supports at least one cipher.
157288 - TLS Version 1.1 Deprecated Protocol
-
Synopsis
The remote service encrypts traffic using an older version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.1. TLS 1.1 lacks support for current and recommended cipher suites. Ciphers that support encryption before MAC computation, and authenticated encryption modes such as GCM cannot be used with TLS 1.1

As of March 31, 2020, Endpoints that are not enabled for TLS 1.2 and higher will no longer function properly with major web browsers and major vendors.
See Also
Solution
Enable support for TLS 1.2 and/or 1.3, and disable support for TLS 1.1.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N)
CVSS v2.0 Base Score
6.1 (CVSS2#AV:N/AC:H/Au:N/C:C/I:P/A:N)
References
XREF CWE:327
Plugin Information
Published: 2022/04/04, Modified: 2024/05/14
Plugin Output

tcp/3389/msrdp

TLSv1.1 is enabled and the server supports at least one cipher.

236832 - VMware Tools 11.x / 12.x < 12.5.2 Insecure File Handling (VMSA-2025-0007)
-
Synopsis
The virtualization tool suite is installed on the remote host is affected by an insecure file handling vulnerability.
Description
The version of VMware Tools installed on the remote host is 11.x or 12.x prior to 12.5.2. It is, therefore, affected by an insecure file handling vulnerability:

- VMware Tools contains an insecure file handling vulnerability. A malicious actor with non-administrative privileges on a guest VM may tamper the local files to trigger insecure file operations within that VM. (CVE-2025-22247)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to VMware Tools version 12.5.2 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
6.1 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N)
VPR Score
5.0
EPSS Score
0.0001
CVSS v2.0 Base Score
5.2 (CVSS2#AV:L/AC:L/Au:S/C:P/I:C/A:N)
STIG Severity
I
References
CVE CVE-2025-22247
XREF VMSA:2025-0007
XREF IAVA:2025-A-0324-S
Plugin Information
Published: 2025/05/16, Modified: 2025/10/02
Plugin Output

tcp/445/cifs


Path : C:\Program Files\VMware\VMware Tools\
Installed version : 12.4.0.48309
Fixed version : 12.5.2
247827 - VMware Tools 11.x / 12.x < 12.5.3 / 13.x < 13.0.1.0 vSockets Information Disclosure (VMSA-2025-0013)
-
Synopsis
The virtualization tool suite is installed on the remote Windows host is affected by an information disclosure vulnerability.
Description
The version of VMware Tools installed on the remote Windows host is 11.x, 12.x prior to 12.5.3, or 13.x prior to 13.0.1.0. It is, therefore, affected by an information disclosure vulnerbility:

- VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of an uninitialised memory in vSockets. A malicious actor with local administrative privileges on a virtual machine may be able to exploit this issue to leak memory from processes communicating with vSockets. (CVE-2025-41239)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to VMware Tools version 12.5.3 or 13.0.1.0 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
6.2 (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
VPR Score
4.4
EPSS Score
0.0001
CVSS v2.0 Base Score
4.9 (CVSS2#AV:L/AC:L/Au:N/C:C/I:N/A:N)
References
CVE CVE-2025-41239
XREF VMSA:2025-0013
Plugin Information
Published: 2025/08/11, Modified: 2025/08/11
Plugin Output

tcp/445/cifs


Path : C:\Program Files\VMware\VMware Tools\
Installed version : 12.4.0.48309
Fixed version : 12.5.3
132101 - Windows Speculative Execution Configuration Check
-
Synopsis
The remote host has not properly mitigated a series of speculative execution vulnerabilities.
Description
The remote host has not properly mitigated a series of known speculative execution vulnerabilities. It, therefore, may be affected by :
- Branch Target Injection (BTI) (CVE-2017-5715)
- Bounds Check Bypass (BCB) (CVE-2017-5753)
- Rogue Data Cache Load (RDCL) (CVE-2017-5754)
- Rogue System Register Read (RSRE) (CVE-2018-3640)
- Speculative Store Bypass (SSB) (CVE-2018-3639)
- L1 Terminal Fault (L1TF) (CVE-2018-3615, CVE-2018-3620, CVE-2018-3646)
- Microarchitectural Data Sampling Uncacheable Memory (MDSUM) (CVE-2019-11091)
- Microarchitectural Store Buffer Data Sampling (MSBDS) (CVE-2018-12126)
- Microarchitectural Load Port Data Sampling (MLPDS) (CVE-2018-12127)
- Microarchitectural Fill Buffer Data Sampling (MFBDS) (CVE-2018-12130)
- TSX Asynchronous Abort (TAA) (CVE-2019-11135)
- Intel Branch History Injection (BHI) (CVE-2022-0001)
See Also
Solution
Apply vendor recommended settings.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
6.2 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
7.9
EPSS Score
0.9433
CVSS v2.0 Base Score
5.4 (CVSS2#AV:L/AC:M/Au:N/C:C/I:P/A:N)
CVSS v2.0 Temporal Score
4.7 (CVSS2#E:H/RL:OF/RC:C)
References
BID 102371
BID 102378
BID 104232
BID 105080
BID 108330
CVE CVE-2017-5715
CVE CVE-2017-5753
CVE CVE-2017-5754
CVE CVE-2018-3615
CVE CVE-2018-3620
CVE CVE-2018-3639
CVE CVE-2018-3646
CVE CVE-2018-12126
CVE CVE-2018-12127
CVE CVE-2018-12130
CVE CVE-2019-11135
CVE CVE-2022-0001
XREF CEA-ID:CEA-2019-0547
XREF CEA-ID:CEA-2019-0324
Exploitable With
CANVAS (true)
Plugin Information
Published: 2019/12/18, Modified: 2025/08/27
Plugin Output

tcp/445/cifs

Current Settings:
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverrideMask: Not Set
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverride: Not Set

-----------------------------------

Recommended Settings 1:
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverrideMask: 0x00000003 (3)
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverride: 0x00000048 (72)
CVEs Covered:
CVE-2017-5715, CVE-2017-5753, CVE-2017-5754, CVE-2018-3615, CVE-2018-3620,
CVE-2018-3639, CVE-2018-3646, CVE-2018-11091, CVE-2018-12126, CVE-2018-12127,
CVE-2018-12130, CVE-2019-11135
Note: Hyper-Threading enabled.

-----------------------------------

Recommended Settings 2:
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverrideMask: 0x00000003 (3)
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverride: 0x00002048 (8264)
CVEs Covered:
CVE-2017-5715, CVE-2017-5753, CVE-2017-5754, CVE-2018-3615, CVE-2018-3620,
CVE-2018-3639, CVE-2018-3646, CVE-2018-11091, CVE-2018-12126, CVE-2018-12127,
CVE-2018-12130, CVE-2019-11135
Note: Hyper-Threading disabled.

-----------------------------------

Recommended Settings 3:
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverrideMask: 0x00000003 (3)
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverride: 0x00802048 (8396872)
CVEs Covered:
CVE-2017-5715, CVE-2017-5753, CVE-2017-5754, CVE-2018-3615, CVE-2018-3620,
CVE-2018-3639, CVE-2018-3646, CVE-2018-11091, CVE-2018-12126, CVE-2018-12127,
CVE-2018-12130, CVE-2019-11135, CVE-2022-0001
Note: Hyper-Threading disabled.

-----------------------------------

Recommended Settings 4:
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverrideMask: 0x00000003 (3)
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverride: 0x00800048 (8388680)
CVEs Covered:
CVE-2017-5715, CVE-2017-5753, CVE-2017-5754, CVE-2018-3615, CVE-2018-3620,
CVE-2018-3639, CVE-2018-3646, CVE-2018-11091, CVE-2018-12126, CVE-2018-12127,
CVE-2018-12130, CVE-2019-11135, CVE-2022-0001
Note: Hyper-Threading enabled.

10114 - ICMP Timestamp Request Remote Date Disclosure
-
Synopsis
It is possible to determine the exact time set on the remote host.
Description
The remote host answers to an ICMP timestamp request. This allows an attacker to know the date that is set on the targeted machine, which may assist an unauthenticated, remote attacker in defeating time-based authentication protocols.

Timestamps returned from machines running Windows Vista / 7 / 2008 / 2008 R2 are deliberately incorrect, but usually within 1000 seconds of the actual system time.
Solution
Filter out the ICMP timestamp requests (13), and the outgoing ICMP timestamp replies (14).
Risk Factor
Low
VPR Score
2.2
EPSS Score
0.0037
CVSS v2.0 Base Score
2.1 (CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:N)
References
Plugin Information
Published: 1999/08/01, Modified: 2024/10/07
Plugin Output

icmp/0

This host returns non-standard timestamps (high bit is set)
The ICMP timestamps might be in little endian format (not in network format)
The remote clock is synchronized with the local clock.

142688 - Security Updates for Microsoft Word Products (November 2020)
-
Synopsis
The Microsoft Word Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Word installation on the remote host is missing a security update. It is, therefore, affected by an unspecified remote code execution vulnerability. An attacker can exploit this vulnerability by tricking a user into opening a specially crafted Office file.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4486730
-KB4486719
-KB4486740

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Low
CVSS v3.0 Base Score
3.3 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N)
CVSS v3.0 Temporal Score
2.9 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
1.4
EPSS Score
0.0101
CVSS v2.0 Base Score
2.1 (CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
1.6 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-17020
MSKB 4486730
MSKB 4486719
MSKB 4486740
XREF MSFT:MS20-4486730
XREF MSFT:MS20-4486719
XREF MSFT:MS20-4486740
XREF IAVA:2020-A-0563-S
Plugin Information
Published: 2020/11/10, Modified: 2024/02/09
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5083.1000
111756 - Security Updates for Outlook (August 2018)
-
Synopsis
The Microsoft Outlook application installed on the remote host is affected by multiple vulnerabilities.
Description
The Microsoft Outlook application installed on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4032222
-KB4032235
-KB4032240
Risk Factor
Low
References
MSKB 4032222
MSKB 4032235
MSKB 4032240
XREF MSFT:MS18-4032222
XREF MSFT:MS18-4032235
XREF MSFT:MS18-4032240
Plugin Information
Published: 2018/08/15, Modified: 2018/08/15
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.4732.1000

46180 - Additional DNS Hostnames
-
Synopsis
Nessus has detected potential virtual hosts.
Description
Hostnames different from the current hostname have been collected by miscellaneous plugins. Nessus has generated a list of hostnames that point to the remote host. Note that these are only the alternate hostnames for vhosts discovered on a web server.

Different web servers may be hosted on name-based virtual hosts.
See Also
Solution
If you want to test them, re-scan using the special vhost syntax, such as :

www.example.com[192.0.32.10]
Risk Factor
None
Plugin Information
Published: 2010/04/29, Modified: 2022/08/15
Plugin Output

tcp/0

The following hostnames point to the remote host :
- lkp_sip_appsrv-140

16193 - Antivirus Software Check
-
Synopsis
An antivirus application is installed on the remote host.
Description
An antivirus application is installed on the remote host, and its engine and virus definitions are up to date.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2005/01/18, Modified: 2025/05/27
Plugin Output

tcp/445/cifs


Kaspersky :
Kaspersky Anti-Virus is installed on the remote host :

Product name : Kaspersky Endpoint Security for Windows
Version : 21.15.8.493
Installation path : C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0
Virus signatures : 01/24/2026

92415 - Application Compatibility Cache
-
Synopsis
Nessus was able to gather application compatibility settings on the remote host.
Description
Nessus was able to generate a report on the application compatibility cache on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

Application compatibility cache report attached.
34097 - BIOS Info (SMB)
-
Synopsis
BIOS info could be read.
Description
It is possible to get information about the BIOS via the host's SMB interface.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/08, Modified: 2024/06/11
Plugin Output

tcp/0


Version : VMW71.00V.21805430.B64.2305221826
Release date : 20230522000000.000000+000
Secure boot : enabled
34096 - BIOS Info (WMI)
-
Synopsis
The BIOS info could be read.
Description
It is possible to get information about the BIOS via the host's WMI interface.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/05, Modified: 2025/12/15
Plugin Output

tcp/0


Vendor : VMware, Inc.
Version : VMW71.00V.21805430.B64.2305221826
Release date : 20230522000000.000000+000
UUID : E51C0842-C856-965F-5992-BF08B74D116E
Secure boot : enabled
92416 - BagMRU Folder History
-
Synopsis
Nessus was able to enumerate folders that were opened in Windows Explorer.
Description
Nessus was able to enumerate folders that were opened in Windows Explorer. Microsoft Windows maintains folder settings using a registry key known as shellbags or BagMRU. The generated folder list report contains folders local to the system, folders from past mounted network drives, and folders from mounted devices.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

BagMRU report attached.

42799 - Broken Web Servers
-
Synopsis
Tests on this web server have been disabled.
Description
The remote web server seems password protected or misconfigured. Further tests on it were disabled so that the whole scan is not slowed down.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/11/13, Modified: 2011/08/17
Plugin Output

tcp/5357/www


This web server was declared broken by :
httpver.nasl
for the following reason :
The web server returns 503 when / is requested.

42799 - Broken Web Servers
-
Synopsis
Tests on this web server have been disabled.
Description
The remote web server seems password protected or misconfigured. Further tests on it were disabled so that the whole scan is not slowed down.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/11/13, Modified: 2011/08/17
Plugin Output

tcp/8002/www


This web server was declared broken by :
apache_log4j_jdni_ldap_generic_http_headers.nbin
for the following reason :
The web server failed to respond at least 244 times for 430 s.

45590 - Common Platform Enumeration (CPE)
-
Synopsis
It was possible to enumerate CPE names that matched on the remote system.
Description
By using information obtained from a Nessus scan, this plugin reports CPE (Common Platform Enumeration) matches for various hardware and software products found on a host.

Note that if an official CPE is not available for the product, this plugin computes the best possible CPE based on the information available from the scan.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/04/21, Modified: 2025/09/29
Plugin Output

tcp/0


The remote operating system matched the following CPE :

cpe:/o:microsoft:windows_server_2019:10.0.17763.6893:-:~~datacenter~~x64~ -> Microsoft Windows Server 2019

Following application CPE's matched on the remote system :

cpe:/a:haxx:curl:8.9.1.0 -> Haxx Curl
cpe:/a:jquery:jquery:1.4.4 -> jQuery
cpe:/a:jquery:jquery:3.3.1 -> jQuery
cpe:/a:kaspersky:kaspersky_anti-virus:21.15.8.493 -> Kaspersky Anti-virus
cpe:/a:microsoft:.net_core:5.0.17.31213 -> Microsoft .NET Core
cpe:/a:microsoft:.net_core:8.0.8 -> Microsoft .NET Core
cpe:/a:microsoft:.net_framework:2.0.50727 -> Microsoft .NET Framework
cpe:/a:microsoft:.net_framework:3.0 -> Microsoft .NET Framework
cpe:/a:microsoft:.net_framework:3.0.6920.9063 -> Microsoft .NET Framework
cpe:/a:microsoft:.net_framework:3.5 -> Microsoft .NET Framework
cpe:/a:microsoft:.net_framework:4.7.2 -> Microsoft .NET Framework
cpe:/a:microsoft:.net_framework:4.7.4126.0 -> Microsoft .NET Framework
cpe:/a:microsoft:asp.net_core:5.0.17 -> Microsoft ASP.NET Core
cpe:/a:microsoft:asp.net_core:8.0.8 -> Microsoft ASP.NET Core
cpe:/a:microsoft:edge:144.0.3719.82 -> Microsoft Edge
cpe:/a:microsoft:excel:16.0.4266.1001:0 -> Microsoft Excel
cpe:/a:microsoft:excelcnv:16.0.4266.1001:0
cpe:/a:microsoft:groove:16.0.4266.1001:0 -> Microsoft Groove
cpe:/a:microsoft:ie:11.1790.17763.0 -> Microsoft Internet Explorer
cpe:/a:microsoft:iis:10.0 -> Microsoft IIS
cpe:/a:microsoft:internet_explorer:11.0.17763.6766 -> Microsoft Internet Explorer
cpe:/a:microsoft:internet_information_services:10.0.17763.5830 -> Microsoft Internet Information Server (IIS) -
cpe:/a:microsoft:office:2016:0 -> Microsoft Office
cpe:/a:microsoft:office_compatibility_pack -> Microsoft Office Compatibility Pack Service Pack 2
cpe:/a:microsoft:office_compatibility_pack:16.0.4266.1001 -> Microsoft Office Compatibility Pack Service Pack 2
cpe:/a:microsoft:onenote:16.0.4266.1001 -> Microsoft OneNote
cpe:/a:microsoft:onenote:16.0.4266.1001:0 -> Microsoft OneNote
cpe:/a:microsoft:outlook:16.0.4266.1001:0 -> Microsoft Outlook
cpe:/a:microsoft:powerpoint:16.0.4266.1001:0 -> Microsoft PowerPoint
cpe:/a:microsoft:publisher:16.0.4266.1001:0 -> Microsoft Publisher
cpe:/a:microsoft:remote_desktop_connection:10.0.17763.5830 -> Microsoft Remote Desktop Connection
cpe:/a:microsoft:sql_server_reporting_services:15.0.9098.6826 -> Microsoft SQL Server Reporting Services
cpe:/a:microsoft:windows_defender:4.18.24050.7 -> Microsoft Windows Defender
cpe:/a:microsoft:word:16.0.4266.1001:0 -> Microsoft Word
cpe:/a:microsoft:wordcnv:16.0.4266.1001:0
cpe:/a:postman:postman:11.65.4 -> Postman
cpe:/a:smartbedded:meteobridge_firmware
cpe:/a:vmware:tools:12.4.0.48309 -> VMWare Tools
cpe:/a:wireshark:wireshark:4.4.2 -> Wireshark
24270 - Computer Manufacturer Information (WMI)
-
Synopsis
It is possible to obtain the name of the remote computer manufacturer.
Description
By making certain WMI queries, it is possible to obtain the model of the remote computer as well as the name of its manufacturer and its serial number.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/02/02, Modified: 2025/12/15
Plugin Output

tcp/0


Computer Manufacturer : VMware, Inc.
Computer Model : VMware7,1
Computer SerialNumber : VMware-42 08 1c e5 56 c8 5f 96-59 92 bf 08 b7 4d 11 6e
Computer Type : Other

Computer Physical CPU's : 1
Computer Logical CPU's : 4
CPU0
Architecture : x64
Physical Cores: 4
Logical Cores : 4

Computer Memory : 65535 MB
RAM slot #0
Form Factor: DIMM
Type : DRAM
Capacity : 16384 MB
RAM slot #1
Form Factor: DIMM
Type : DRAM
Capacity : 16384 MB
RAM slot #2
Form Factor: DIMM
Type : DRAM
Capacity : 16384 MB
RAM slot #3
Form Factor: DIMM
Type : DRAM
Capacity : 16384 MB
171860 - Curl Installed (Windows)
-
Synopsis
Curl is installed on the remote Windows host.
Description
Curl, a command line tool for transferring data with URLs, was detected on the remote Windows host.

Please note, if the installation is located in either the Windows\System32 or Windows\SysWOW64 directory, it will be considered as managed by the OS. In this case, paranoid scanning is require to trigger downstream vulnerabilty checks. Paranoid scanning has no affect on this plugin itself.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/02/23, Modified: 2025/12/15
Plugin Output

tcp/0


Nessus detected 2 installs of Curl:

Path : c:\windows\system32\curl.exe
Version : 8.9.1.0
Managed by OS : True

Path : c:\windows\syswow64\curl.exe
Version : 8.9.1.0
Managed by OS : True

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/135/epmap


The following DCERPC services are available locally :

Object UUID : 765294ba-60bc-48b8-92e9-89fd77769d91
UUID : d95afe70-a6d5-4259-822e-2c84da1ddb0d, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WindowsShutdown

Object UUID : 765294ba-60bc-48b8-92e9-89fd77769d91
UUID : d95afe70-a6d5-4259-822e-2c84da1ddb0d, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WMsgKRpc0B5260

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000000
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WindowsShutdown

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000000
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WMsgKRpc0B5260

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : dabrpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : csebpub

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-54d6d0b8c429d52871

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3473dd4d-2e88-4006-9cba-22570909dd10, version 5.0
Description : Unknown RPC service
Annotation : WinHttp Auto-Proxy Service
Type : Local RPC service
Named pipe : LRPC-b51ca64dd3903e13ed

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3473dd4d-2e88-4006-9cba-22570909dd10, version 5.0
Description : Unknown RPC service
Annotation : WinHttp Auto-Proxy Service
Type : Local RPC service
Named pipe : 9c0ffb89-5f17-47f0-b798-ac853fe2cb0a

Object UUID : 5252504b-4950-534e-0c48-64e1581f0000
UUID : 9b3e3722-421e-3b60-4b50-525250494453, version 160.163
Description : Unknown RPC service
Annotation : PRRUniversal#0D40C441E9825F29:8024
Type : Local RPC service
Named pipe : PRRUniversal#0D40C441E9825F29:8024

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : be7f785e-0e3a-4ab7-91de-7e46e443be29, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-df98f5a3afd9561d83

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 54b4c689-969a-476f-8dc2-990885e9f562, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-df98f5a3afd9561d83

Object UUID : 5252504b-4950-534e-ad9e-000f98130000
UUID : 9b3e3722-aa00-2e06-4b50-525250494453, version 184.111
Description : Unknown RPC service
Annotation : PRRUniversal#3ADCFBC81573673E:5016
Type : Local RPC service
Named pipe : PRRUniversal#3ADCFBC81573673E:5016

Object UUID : 9b3e3722-fb3c-0007-4b50-525250524944
UUID : 9b3e3722-d801-7233-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : PR_REMOTE_MANAGER_PROP
Type : Local RPC service
Named pipe : PRRNameService:5016

Object UUID : 9b3e3722-fb3c-0007-4b50-525250524944
UUID : 9b3e3722-d801-7233-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : PR_REMOTE_MANAGER_PROP
Type : Local RPC service
Named pipe : PRRUniversal#3ADCFBC81573673E:5016

Object UUID : 9b3e3722-e72a-000f-4b50-525250524944
UUID : 9b3e3722-e474-f035-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : cpnPRAGUE_REMOTE_API
Type : Local RPC service
Named pipe : PRRNameService:5016

Object UUID : 9b3e3722-e72a-000f-4b50-525250524944
UUID : 9b3e3722-e474-f035-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : cpnPRAGUE_REMOTE_API
Type : Local RPC service
Named pipe : PRRUniversal#3ADCFBC81573673E:5016

Object UUID : 07363b1c-0000-0000-ad9e-000f98130000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 184.111
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:5016

Object UUID : 07363b1c-0000-0000-ad9e-000f98130000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 184.111
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#3ADCFBC81573673E:5016

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e8748f69-a2a4-40df-9366-62dbeb696e26, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-25c73d74ba129540e9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c8ba73d2-3d55-429c-8e9a-c44f006f69fc, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-25c73d74ba129540e9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 43890c94-bfd7-4655-ad6a-b4a68397cdcb, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-25c73d74ba129540e9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0497b57d-2e66-424f-a0c6-157cd5d41700, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-686fa0975faf157880

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 201ef99a-7fa0-444c-9399-19ba84f12a1a, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-686fa0975faf157880

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5f54ce7d-5b79-4175-8584-cb65313a0e98, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-686fa0975faf157880

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fd7a0523-dc70-43dd-9b2e-9c5ed48225b1, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-686fa0975faf157880

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 58e604e8-9adb-4d2e-a464-3b0683fb1480, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-686fa0975faf157880

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0767a036-0d22-48aa-ba69-b619480f38cb, version 1.0
Description : Unknown RPC service
Annotation : PcaSvc
Type : Local RPC service
Named pipe : LRPC-96e0f9397b03afe25b

Object UUID : 00000002-0000-0000-0000-000000000000
UUID : 8ec21e98-b5ce-4916-a3d6-449fa428a007, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE3C6AAE7B8BC99C5DF29B78E1E5A9

Object UUID : 00000002-0000-0000-0000-000000000000
UUID : 8ec21e98-b5ce-4916-a3d6-449fa428a007, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-0aaa7e7e39fb985d81

Object UUID : 00000002-0000-0000-0000-000000000000
UUID : 0fc77b1a-95d8-4a2e-a0c0-cff54237462b, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE3C6AAE7B8BC99C5DF29B78E1E5A9

Object UUID : 00000002-0000-0000-0000-000000000000
UUID : 0fc77b1a-95d8-4a2e-a0c0-cff54237462b, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-0aaa7e7e39fb985d81

Object UUID : 00000002-0000-0000-0000-000000000000
UUID : b1ef227e-dfa5-421e-82bb-67a6a129c496, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE3C6AAE7B8BC99C5DF29B78E1E5A9

Object UUID : 00000002-0000-0000-0000-000000000000
UUID : b1ef227e-dfa5-421e-82bb-67a6a129c496, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-0aaa7e7e39fb985d81

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : audit

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : securityevent

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : LSARPC_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : lsacap

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : LSA_IDPEXT_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : LSA_EAS_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : lsapolicylookup

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : lsasspirpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : protected_storage

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : SidKey Local End Point

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : samss lpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : audit

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : securityevent

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSARPC_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsacap

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSA_IDPEXT_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSA_EAS_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsapolicylookup

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsasspirpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : protected_storage

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : SidKey Local End Point

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : samss lpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : audit

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : securityevent

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSARPC_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsacap

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSA_IDPEXT_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSA_EAS_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsapolicylookup

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsasspirpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : protected_storage

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : SidKey Local End Point

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : samss lpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : audit

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : securityevent

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : LSARPC_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : lsacap

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : LSA_IDPEXT_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : LSA_EAS_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : lsapolicylookup

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : lsasspirpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : protected_storage

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : SidKey Local End Point

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : samss lpc

Object UUID : 5252504b-4950-534e-621d-1494b8180000
UUID : 9b3e3722-090e-c861-4b50-525250494453, version 184.111
Description : Unknown RPC service
Annotation : PRRUniversal#BFF07A7C237A6219:6328
Type : Local RPC service
Named pipe : PRRUniversal#BFF07A7C237A6219:6328

Object UUID : 9b3e3722-fb3c-0007-4b50-525250524944
UUID : 9b3e3722-d801-7233-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : PR_REMOTE_MANAGER_PROP
Type : Local RPC service
Named pipe : PRRNameService:6328

Object UUID : 9b3e3722-fb3c-0007-4b50-525250524944
UUID : 9b3e3722-d801-7233-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : PR_REMOTE_MANAGER_PROP
Type : Local RPC service
Named pipe : PRRUniversal#BFF07A7C237A6219:6328

Object UUID : 9b3e3722-e72a-000f-4b50-525250524944
UUID : 9b3e3722-e474-f035-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : cpnPRAGUE_REMOTE_API
Type : Local RPC service
Named pipe : PRRNameService:6328

Object UUID : 9b3e3722-e72a-000f-4b50-525250524944
UUID : 9b3e3722-e474-f035-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : cpnPRAGUE_REMOTE_API
Type : Local RPC service
Named pipe : PRRUniversal#BFF07A7C237A6219:6328

Object UUID : 02afbeac-0000-0000-621d-1494b8180000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 184.111
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:6328

Object UUID : 02afbeac-0000-0000-621d-1494b8180000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 184.111
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#BFF07A7C237A6219:6328

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000002
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WMsgKRpc070A452

Object UUID : 52ef130c-08fd-4388-86b3-6edf00000002
UUID : 12e65dd8-887f-41ef-91bf-8d816c42c2e7, version 1.0
Description : Unknown RPC service
Annotation : Secure Desktop LRPC interface
Type : Local RPC service
Named pipe : WMsgKRpc070A452

Object UUID : eb65660c-720c-40d1-8e02-4fd5be5a07cd
UUID : 906b0ce0-c70b-1067-b317-00dd010662da, version 1.0
Description : Distributed Transaction Coordinator
Windows process : msdtc.exe
Type : Local RPC service
Named pipe : LRPC-a800dc50fadb19218f

Object UUID : b5d43bd7-33c5-43e1-b160-33aec6f11f04
UUID : 906b0ce0-c70b-1067-b317-00dd010662da, version 1.0
Description : Distributed Transaction Coordinator
Windows process : msdtc.exe
Type : Local RPC service
Named pipe : LRPC-a800dc50fadb19218f

Object UUID : 12801db7-37fb-4ee8-b0e3-74c581fb42f1
UUID : 906b0ce0-c70b-1067-b317-00dd010662da, version 1.0
Description : Distributed Transaction Coordinator
Windows process : msdtc.exe
Type : Local RPC service
Named pipe : LRPC-a800dc50fadb19218f

Object UUID : 19bb6f6f-55ca-4e67-bf6a-f607fb49b169
UUID : 906b0ce0-c70b-1067-b317-00dd010662da, version 1.0
Description : Distributed Transaction Coordinator
Windows process : msdtc.exe
Type : Local RPC service
Named pipe : OLE5DA67ACC3250393D5BE4351DE8EA

Object UUID : 19bb6f6f-55ca-4e67-bf6a-f607fb49b169
UUID : 906b0ce0-c70b-1067-b317-00dd010662da, version 1.0
Description : Distributed Transaction Coordinator
Windows process : msdtc.exe
Type : Local RPC service
Named pipe : LRPC-edb986215848804d5e

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 650a7e26-eab8-5533-ce43-9c1dfce11511, version 1.0
Description : Unknown RPC service
Annotation : Vpn APIs
Type : Local RPC service
Named pipe : RasmanLrpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 650a7e26-eab8-5533-ce43-9c1dfce11511, version 1.0
Description : Unknown RPC service
Annotation : Vpn APIs
Type : Local RPC service
Named pipe : VpnikeRpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 650a7e26-eab8-5533-ce43-9c1dfce11511, version 1.0
Description : Unknown RPC service
Annotation : Vpn APIs
Type : Local RPC service
Named pipe : LRPC-300790435e351208d7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4c9dbf19-d39e-4bb9-90ee-8f7179b20283, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-df3ec30bc35cd5bd16

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fd8be72b-a9cd-4b2c-a9ca-4ded242fbe4d, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-df3ec30bc35cd5bd16

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 95095ec8-32ea-4eb0-a3e2-041f97b36168, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-df3ec30bc35cd5bd16

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e38f5360-8572-473e-b696-1b46873beeab, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-df3ec30bc35cd5bd16

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : d22895ef-aff4-42c5-a5b2-b14466d34ab4, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-df3ec30bc35cd5bd16

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 98cd761e-e77d-41c8-a3c0-0fb756d90ec2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-df3ec30bc35cd5bd16

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 6b5bdd1e-528c-422c-af8c-a4079be4fe48, version 1.0
Description : Unknown RPC service
Annotation : Remote Fw APIs
Type : Local RPC service
Named pipe : ipsec

Object UUID : 5252504b-4950-534e-68f4-b782900b0000
UUID : 9b3e3722-1a39-0d7c-4b50-525250494453, version 184.111
Description : Unknown RPC service
Annotation : PRRUniversal#AE9451822210B4B5:2960
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 9b3e3722-fb3c-0007-4b50-525250524944
UUID : 9b3e3722-d801-7233-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : PR_REMOTE_MANAGER_PROP
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 9b3e3722-fb3c-0007-4b50-525250524944
UUID : 9b3e3722-d801-7233-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : PR_REMOTE_MANAGER_PROP
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 9b3e3722-e72a-000f-4b50-525250524944
UUID : 9b3e3722-e474-f035-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : cpnPRAGUE_REMOTE_API
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 9b3e3722-e72a-000f-4b50-525250524944
UUID : 9b3e3722-e474-f035-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : cpnPRAGUE_REMOTE_API
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 06a20fa0-0000-0000-68f4-b782900b0000
UUID : 9b3e3722-bab3-e001-4b50-52524f424a53, version 184.111
Description : Unknown RPC service
Annotation : ai_loader_remote_object
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 06a20fa0-0000-0000-68f4-b782900b0000
UUID : 9b3e3722-bab3-e001-4b50-52524f424a53, version 184.111
Description : Unknown RPC service
Annotation : ai_loader_remote_object
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 9b3e3722-abb6-0007-4b50-525250524944
UUID : 9b3e3722-7551-7dee-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : cpTEMPFILE_MEMMANAGER
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 9b3e3722-abb6-0007-4b50-525250524944
UUID : 9b3e3722-7551-7dee-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : cpTEMPFILE_MEMMANAGER
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 00000000-0000-0000-68f4-b782900b0000
UUID : 9b3e3722-bab3-e001-4b50-52524f424a53, version 184.111
Description : Unknown RPC service
Annotation : ai_loader_remote_object
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 00000000-0000-0000-68f4-b782900b0000
UUID : 9b3e3722-bab3-e001-4b50-52524f424a53, version 184.111
Description : Unknown RPC service
Annotation : ai_loader_remote_object
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 0575eb2c-0000-0000-68f4-b782900b0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 184.111
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 0575eb2c-0000-0000-68f4-b782900b0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 184.111
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 9b3e3722-8790-000c-4b50-525250524944
UUID : 9b3e3722-1441-c93d-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : cpTASK_MANAGER_TASK_TYPE_NAME
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 9b3e3722-8790-000c-4b50-525250524944
UUID : 9b3e3722-1441-c93d-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : cpTASK_MANAGER_TASK_TYPE_NAME
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 9b3e3722-a517-000d-4b50-525250524944
UUID : 9b3e3722-f9a8-d5cb-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : cpTASK_MANAGER_PROFILE_NAME
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 9b3e3722-a517-000d-4b50-525250524944
UUID : 9b3e3722-f9a8-d5cb-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : cpTASK_MANAGER_PROFILE_NAME
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 9b3e3722-b19c-0002-4b50-525250524944
UUID : 9b3e3722-050c-2b49-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : cpTASK_MANAGER_TASK_ID
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 9b3e3722-b19c-0002-4b50-525250524944
UUID : 9b3e3722-050c-2b49-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : cpTASK_MANAGER_TASK_ID
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 9b3e3722-1931-0005-4b50-525250524944
UUID : 9b3e3722-a39b-5baa-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : npAVS_HTTP_REQ
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 9b3e3722-1931-0005-4b50-525250524944
UUID : 9b3e3722-a39b-5baa-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : npAVS_HTTP_REQ
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 9b3e3722-4d95-0005-4b50-525250524944
UUID : 9b3e3722-f7aa-5ba3-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : npAVS_HTTP_RSP
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 9b3e3722-4d95-0005-4b50-525250524944
UUID : 9b3e3722-f7aa-5ba3-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : npAVS_HTTP_RSP
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 9b3e3722-b87a-0007-4b50-525250524944
UUID : 9b3e3722-86c2-73eb-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : MESSAGE_IS_INCOMING
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 9b3e3722-b87a-0007-4b50-525250524944
UUID : 9b3e3722-86c2-73eb-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : MESSAGE_IS_INCOMING
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 9b3e3722-5916-0003-4b50-525250524944
UUID : 9b3e3722-0276-35b6-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : MESSAGE_CHECK_ONLY
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 9b3e3722-5916-0003-4b50-525250524944
UUID : 9b3e3722-0276-35b6-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : MESSAGE_CHECK_ONLY
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 9b3e3722-20c7-000f-4b50-525250524944
UUID : 9b3e3722-c49b-fe45-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : PROTOCOL_TYPE
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 9b3e3722-20c7-000f-4b50-525250524944
UUID : 9b3e3722-c49b-fe45-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : PROTOCOL_TYPE
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 9b3e3722-c384-0000-4b50-525250524944
UUID : 9b3e3722-6122-0a2a-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : npENGINE_VIRTUAL_OBJECT_NAME
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 9b3e3722-c384-0000-4b50-525250524944
UUID : 9b3e3722-6122-0a2a-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : npENGINE_VIRTUAL_OBJECT_NAME
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 9b3e3722-7401-0008-4b50-525250524944
UUID : 9b3e3722-62c7-816c-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : npUserContext
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 9b3e3722-7401-0008-4b50-525250524944
UUID : 9b3e3722-62c7-816c-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : npUserContext
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 9b3e3722-0568-0001-4b50-525250524944
UUID : 9b3e3722-1d09-1186-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : npAVS_SCAN_AREA_ID
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 9b3e3722-0568-0001-4b50-525250524944
UUID : 9b3e3722-1d09-1186-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : npAVS_SCAN_AREA_ID
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 9b3e3722-618e-000d-4b50-525250524944
UUID : 9b3e3722-7819-d199-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : antimalware.am_core_dll.registered
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 9b3e3722-618e-000d-4b50-525250524944
UUID : 9b3e3722-7819-d199-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : antimalware.am_core_dll.registered
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 9b3e3722-4dfb-000b-4b50-525250524944
UUID : 9b3e3722-56be-b1b4-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : npSCAN_OBJECT_CONTEXT
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 9b3e3722-4dfb-000b-4b50-525250524944
UUID : 9b3e3722-56be-b1b4-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : npSCAN_OBJECT_CONTEXT
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 9b3e3722-5c94-000c-4b50-525250524944
UUID : 9b3e3722-7dc3-c215-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : npENGINE_OBJECT_READONLY_tERROR
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 9b3e3722-5c94-000c-4b50-525250524944
UUID : 9b3e3722-7dc3-c215-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : npENGINE_OBJECT_READONLY_tERROR
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 9b3e3722-66bb-0002-4b50-525250524944
UUID : 9b3e3722-b130-2d78-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : npENGINE_OBJECT_EXECUTABLE_PARENT_IO_hOBJECT
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 9b3e3722-66bb-0002-4b50-525250524944
UUID : 9b3e3722-b130-2d78-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : npENGINE_OBJECT_EXECUTABLE_PARENT_IO_hOBJECT
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 9b3e3722-0726-0007-4b50-525250524944
UUID : 9b3e3722-dfbb-7d89-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : npENGINE_OBJECT_SET_WRITE_ACCESS_tERROR
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 9b3e3722-0726-0007-4b50-525250524944
UUID : 9b3e3722-dfbb-7d89-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : npENGINE_OBJECT_SET_WRITE_ACCESS_tERROR
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 9b3e3722-21ab-0008-4b50-525250524944
UUID : 9b3e3722-da96-8fb3-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : npENGINE_INTEGRAL_PARENT_IO
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 9b3e3722-21ab-0008-4b50-525250524944
UUID : 9b3e3722-da96-8fb3-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : npENGINE_INTEGRAL_PARENT_IO
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 9b3e3722-554f-0006-4b50-525250524944
UUID : 9b3e3722-3fdc-66a9-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : npOBJECT_STARTUP
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 9b3e3722-554f-0006-4b50-525250524944
UUID : 9b3e3722-3fdc-66a9-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : npOBJECT_STARTUP
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 9b3e3722-ae59-0004-4b50-525250524944
UUID : 9b3e3722-49dd-4e78-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : antimalware.oas.PenderPtr
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 9b3e3722-ae59-0004-4b50-525250524944
UUID : 9b3e3722-49dd-4e78-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : antimalware.oas.PenderPtr
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 9b3e3722-e77b-0006-4b50-525250524944
UUID : 9b3e3722-d7d6-630a-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : native file io object is a stream really
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 9b3e3722-e77b-0006-4b50-525250524944
UUID : 9b3e3722-d7d6-630a-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : native file io object is a stream really
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 9b3e3722-54e6-0005-4b50-525250524944
UUID : 9b3e3722-97cf-5c32-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : native file io object streams
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 9b3e3722-54e6-0005-4b50-525250524944
UUID : 9b3e3722-97cf-5c32-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : native file io object streams
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 9b3e3722-c572-000b-4b50-525250524944
UUID : 9b3e3722-7d85-bb8f-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : npTM_PROFILE
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 9b3e3722-c572-000b-4b50-525250524944
UUID : 9b3e3722-7d85-bb8f-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : npTM_PROFILE
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 9b3e3722-2be7-0004-4b50-525250524944
UUID : 9b3e3722-2175-40a9-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : cpTEMPFILE_SYSCACHED
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 9b3e3722-2be7-0004-4b50-525250524944
UUID : 9b3e3722-2175-40a9-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : cpTEMPFILE_SYSCACHED
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 0752e978-0000-0000-68f4-b782900b0000
UUID : 9b3e3722-b8eb-3e0b-4b50-52524f424a53, version 184.111
Description : Unknown RPC service
Annotation : TaskManager
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 0752e978-0000-0000-68f4-b782900b0000
UUID : 9b3e3722-b8eb-3e0b-4b50-52524f424a53, version 184.111
Description : Unknown RPC service
Annotation : TaskManager
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 9b3e3722-aa75-0009-4b50-525250524944
UUID : 9b3e3722-b9de-913a-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : DEFER_THREAD_INIT
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 9b3e3722-aa75-0009-4b50-525250524944
UUID : 9b3e3722-b9de-913a-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : DEFER_THREAD_INIT
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 9b3e3722-1e7b-0004-4b50-525250524944
UUID : 9b3e3722-6afd-4748-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : MAILER_PID
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 9b3e3722-1e7b-0004-4b50-525250524944
UUID : 9b3e3722-6afd-4748-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : MAILER_PID
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 9b3e3722-487b-0006-4b50-525250524944
UUID : 9b3e3722-2a49-6623-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : npMESSAGE_IS_COMPLETE
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 9b3e3722-487b-0006-4b50-525250524944
UUID : 9b3e3722-2a49-6623-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : npMESSAGE_IS_COMPLETE
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 9b3e3722-cf60-000f-4b50-525250524944
UUID : 9b3e3722-93c9-f5ca-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : NO_NEED_TREATMENT
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 9b3e3722-cf60-000f-4b50-525250524944
UUID : 9b3e3722-93c9-f5ca-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : NO_NEED_TREATMENT
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 9b3e3722-7820-0006-4b50-525250524944
UUID : 9b3e3722-9839-6e01-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : MAILER_TID
Type : Local RPC service
Named pipe : PRRNameService:2960

Object UUID : 9b3e3722-7820-0006-4b50-525250524944
UUID : 9b3e3722-9839-6e01-4b50-525250524f50, version 184.111
Description : Unknown RPC service
Annotation : MAILER_TID
Type : Local RPC service
Named pipe : PRRUniversal#AE9451822210B4B5:2960

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 30adc50c-5cbc-46ce-9a0e-91914789e23c, version 1.0
Description : Unknown RPC service
Annotation : NRP server endpoint
Type : Local RPC service
Named pipe : LRPC-1f59ffa8141f6e9fe6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fdb3a030-065f-11d1-bb9b-00a024ea5525, version 1.0
Description : Message Queuing Service
Windows process : mqsvc.exe
Annotation : Message Queuing - QMRT V1
Type : Local RPC service
Named pipe : QMsvc$lkp_sip_appsrv-

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fdb3a030-065f-11d1-bb9b-00a024ea5525, version 1.0
Description : Message Queuing Service
Windows process : mqsvc.exe
Annotation : Message Queuing - QMRT V1
Type : Local RPC service
Named pipe : QMMgmtFacility$lkp_sip_appsrv-

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76d12b80-3467-11d3-91ff-0090272f9ea3, version 1.0
Description : Message Queuing Service
Windows process : mqsvc.exe
Annotation : Message Queuing - QMRT V2
Type : Local RPC service
Named pipe : QMsvc$lkp_sip_appsrv-

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76d12b80-3467-11d3-91ff-0090272f9ea3, version 1.0
Description : Message Queuing Service
Windows process : mqsvc.exe
Annotation : Message Queuing - QMRT V2
Type : Local RPC service
Named pipe : QMMgmtFacility$lkp_sip_appsrv-

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1088a980-eae5-11d0-8d9b-00a02453c337, version 1.0
Description : Message Queuing Service
Windows process : mqsvc.exe
Annotation : Message Queuing - QM2QM V1
Type : Local RPC service
Named pipe : QMsvc$lkp_sip_appsrv-

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1088a980-eae5-11d0-8d9b-00a02453c337, version 1.0
Description : Message Queuing Service
Windows process : mqsvc.exe
Annotation : Message Queuing - QM2QM V1
Type : Local RPC service
Named pipe : QMMgmtFacility$lkp_sip_appsrv-

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1a9134dd-7b39-45ba-ad88-44d01ca47f28, version 1.0
Description : Unknown RPC service
Annotation : Message Queuing - RemoteRead V1
Type : Local RPC service
Named pipe : QMsvc$lkp_sip_appsrv-

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1a9134dd-7b39-45ba-ad88-44d01ca47f28, version 1.0
Description : Unknown RPC service
Annotation : Message Queuing - RemoteRead V1
Type : Local RPC service
Named pipe : QMMgmtFacility$lkp_sip_appsrv-

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 98716d03-89ac-44c7-bb8c-285824e51c4a, version 1.0
Description : Unknown RPC service
Annotation : XactSrv service
Type : Local RPC service
Named pipe : LRPC-c1b5bbb81fc902a780

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1a0d010f-1c33-432c-b0f5-8cf4e8053099, version 1.0
Description : Unknown RPC service
Annotation : IdSegSrv service
Type : Local RPC service
Named pipe : LRPC-c1b5bbb81fc902a780

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 552d076a-cb29-4e44-8b6a-d15e59e2c0af, version 1.0
Description : Unknown RPC service
Annotation : IP Transition Configuration endpoint
Type : Local RPC service
Named pipe : LRPC-947bf73aef7367b041

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Local RPC service
Named pipe : LRPC-947bf73aef7367b041

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Local RPC service
Named pipe : TeredoDiagnostics

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Local RPC service
Named pipe : TeredoControl

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Local RPC service
Named pipe : LRPC-947bf73aef7367b041

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Local RPC service
Named pipe : TeredoDiagnostics

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Local RPC service
Named pipe : TeredoControl

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Local RPC service
Named pipe : OLE6B08AE1A3BA2D90FE44661F334F6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Local RPC service
Named pipe : LRPC-947bf73aef7367b041

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Local RPC service
Named pipe : TeredoDiagnostics

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Local RPC service
Named pipe : TeredoControl

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Local RPC service
Named pipe : OLE6B08AE1A3BA2D90FE44661F334F6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b58aa02e-2884-4e97-8176-4ee06d794184, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c89ae4108ebac1b352

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345678-1234-abcd-ef00-0123456789ab, version 1.0
Description : IPsec Services (Windows XP & 2003)
Windows process : lsass.exe
Type : Local RPC service
Named pipe : LRPC-ddb77e259710fc80d5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0b6edbfa-4a24-4fc6-8a23-942b1eca65d1, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-ddb77e259710fc80d5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : ae33069b-a2a8-46ee-a235-ddfd339be281, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-ddb77e259710fc80d5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4a452661-8290-4b36-8fbe-7f4093a94978, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-ddb77e259710fc80d5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76f03f96-cdfd-44fc-a22c-64950a001209, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-ddb77e259710fc80d5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a398e520-d59a-4bdd-aa7a-3c1e0303a511, version 1.0
Description : Unknown RPC service
Annotation : IKE/Authip API
Type : Local RPC service
Named pipe : LRPC-41d1561c96d703dd90

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b18fbab6-56f8-4702-84e0-41053293a869, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : OLE04BA96432F82DB4A3E4258753A7E

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b18fbab6-56f8-4702-84e0-41053293a869, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : LRPC-a20c7cabcc683d3a45

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3c7f20-1c8d-4654-a1b3-51563b298bda, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : OLE04BA96432F82DB4A3E4258753A7E

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3c7f20-1c8d-4654-a1b3-51563b298bda, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : LRPC-a20c7cabcc683d3a45

Object UUID : 73736573-6f69-656e-6e76-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : LRPC-b15b763448a275017a

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b15b763448a275017a

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : SessEnvPrivateRpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : dd490425-5325-4565-b774-7e27d6c09c24, version 1.0
Description : Unknown RPC service
Annotation : Base Firewall Engine API
Type : Local RPC service
Named pipe : LRPC-2e30a0be17e92cbec5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7f9d11bf-7fb9-436b-a812-b2d50c5d4c03, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-2e30a0be17e92cbec5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7f9d11bf-7fb9-436b-a812-b2d50c5d4c03, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-c6419f0981158ce08d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f47433c3-3e9d-4157-aad4-83aa1f5c2d4c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-2e30a0be17e92cbec5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f47433c3-3e9d-4157-aad4-83aa1f5c2d4c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-c6419f0981158ce08d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f47433c3-3e9d-4157-aad4-83aa1f5c2d4c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-5cd100fd36863a48c0

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2fb92682-6599-42dc-ae13-bd2ca89bd11c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-2e30a0be17e92cbec5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2fb92682-6599-42dc-ae13-bd2ca89bd11c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-c6419f0981158ce08d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2fb92682-6599-42dc-ae13-bd2ca89bd11c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-5cd100fd36863a48c0

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2fb92682-6599-42dc-ae13-bd2ca89bd11c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-b15d104210b0c059f2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : abfb6ca3-0c5e-4734-9285-0aee72fe8d1c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE45B905D494A1564E95842A3FED53

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : abfb6ca3-0c5e-4734-9285-0aee72fe8d1c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-d699fe441ffd8ea3b1

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b37f900a-eae4-4304-a2ab-12bb668c0188, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE45B905D494A1564E95842A3FED53

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b37f900a-eae4-4304-a2ab-12bb668c0188, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-d699fe441ffd8ea3b1

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e7f76134-9ef5-4949-a2d6-3368cc0988f3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE45B905D494A1564E95842A3FED53

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e7f76134-9ef5-4949-a2d6-3368cc0988f3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-d699fe441ffd8ea3b1

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7aeb6705-3ae6-471a-882d-f39c109edc12, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE45B905D494A1564E95842A3FED53

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7aeb6705-3ae6-471a-882d-f39c109edc12, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-d699fe441ffd8ea3b1

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f44e62af-dab1-44c2-8013-049a9de417d6, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE45B905D494A1564E95842A3FED53

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f44e62af-dab1-44c2-8013-049a9de417d6, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-d699fe441ffd8ea3b1

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c2d1b5dd-fa81-4460-9dd6-e7658b85454b, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE45B905D494A1564E95842A3FED53

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c2d1b5dd-fa81-4460-9dd6-e7658b85454b, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-d699fe441ffd8ea3b1

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f2c9b409-c1c9-4100-8639-d8ab1486694a, version 1.0
Description : Unknown RPC service
Annotation : Witness Client Upcall Server
Type : Local RPC service
Named pipe : LRPC-af7e2a373aa63ee0d2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : eb081a0d-10ee-478a-a1dd-50995283e7a8, version 3.0
Description : Unknown RPC service
Annotation : Witness Client Test Interface
Type : Local RPC service
Named pipe : LRPC-af7e2a373aa63ee0d2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7f1343fe-50a9-4927-a778-0c5859517bac, version 1.0
Description : Unknown RPC service
Annotation : DfsDs service
Type : Local RPC service
Named pipe : LRPC-af7e2a373aa63ee0d2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 30b044a5-a225-43f0-b3a4-e060df91f9c1, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-96b3c5d950e33bfefd

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0a74ef1c-41a4-4e06-83ae-dc74fb1cdd53, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : LRPC-9a02c2eb86e1601536

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1ff70682-0a51-30e8-076d-740be8cee98b, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : LRPC-9a02c2eb86e1601536

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 378e52b0-c0a9-11cf-822d-00aa0051e40f, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : LRPC-9a02c2eb86e1601536

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 33d84484-3626-47ee-8c6f-e7e98b113be1, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-9a02c2eb86e1601536

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 33d84484-3626-47ee-8c6f-e7e98b113be1, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 33d84484-3626-47ee-8c6f-e7e98b113be1, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b8981f877826dbd728

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-9a02c2eb86e1601536

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b8981f877826dbd728

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-9a02c2eb86e1601536

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b8981f877826dbd728

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : df4df73a-c52d-4e3a-8003-8437fdf8302a, version 0.0
Description : Unknown RPC service
Annotation : WM_WindowManagerRPC\Server
Type : Local RPC service
Named pipe : LRPC-3f2a6af9f80479a799

Object UUID : 736e6573-0000-0000-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : senssvc

Object UUID : 736e6573-0000-0000-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : LRPC-6c61226d3f82f872ef

Object UUID : 6c637067-6569-746e-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : LRPC-debd747b2e210a9146

Object UUID : 24d1f7c7-76af-4f28-9ccd-7f6cb6468601
UUID : 2eb08e3e-639f-4fba-97b1-14f878961076, version 1.0
Description : Unknown RPC service
Annotation : Group Policy RPC Interface
Type : Local RPC service
Named pipe : LRPC-3a4dabee7baa0e7464

Object UUID : 666f7270-6c69-7365-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5, version 1.0
Description : DHCP Client Service
Windows process : svchost.exe
Annotation : DHCP Client LRPC Endpoint
Type : Local RPC service
Named pipe : dhcpcsvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6, version 1.0
Description : Unknown RPC service
Annotation : DHCPv6 Client LRPC Endpoint
Type : Local RPC service
Named pipe : dhcpcsvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6, version 1.0
Description : Unknown RPC service
Annotation : DHCPv6 Client LRPC Endpoint
Type : Local RPC service
Named pipe : dhcpcsvc6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7ea70bcf-48af-4f6a-8968-6a440754d5fa, version 1.0
Description : Unknown RPC service
Annotation : NSI server endpoint
Type : Local RPC service
Named pipe : LRPC-7ad029e8043a9d5b69

Object UUID : 3bdb59a0-d736-4d44-9074-c1ee00000001
UUID : f3f09ffd-fbcf-4291-944d-70ad6e0e73bb, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-999c296bb30abc3201

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f6beaff7-1e19-4fbb-9f8f-b89e2018337c, version 1.0
Description : Unknown RPC service
Annotation : Event log TCPIP
Type : Local RPC service
Named pipe : eventlog

Object UUID : fdd099c6-df06-4904-83b4-a87a27903c70
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-7d228954a2753d120e

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5222821f-d5e2-4885-84f1-5f6185a0ec41, version 1.0
Description : Unknown RPC service
Annotation : Network Connection Broker server endpoint for NCB Reset module
Type : Local RPC service
Named pipe : LRPC-7d228954a2753d120e

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5222821f-d5e2-4885-84f1-5f6185a0ec41, version 1.0
Description : Unknown RPC service
Annotation : Network Connection Broker server endpoint for NCB Reset module
Type : Local RPC service
Named pipe : LRPC-2454aaa601053c404d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 880fd55e-43b9-11e0-b1a8-cf4edfd72085, version 1.0
Description : Unknown RPC service
Annotation : KAPI Service endpoint
Type : Local RPC service
Named pipe : LRPC-7d228954a2753d120e

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 880fd55e-43b9-11e0-b1a8-cf4edfd72085, version 1.0
Description : Unknown RPC service
Annotation : KAPI Service endpoint
Type : Local RPC service
Named pipe : LRPC-2454aaa601053c404d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 880fd55e-43b9-11e0-b1a8-cf4edfd72085, version 1.0
Description : Unknown RPC service
Annotation : KAPI Service endpoint
Type : Local RPC service
Named pipe : OLE21217C9A642724B6D3737C14FB6C

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 880fd55e-43b9-11e0-b1a8-cf4edfd72085, version 1.0
Description : Unknown RPC service
Annotation : KAPI Service endpoint
Type : Local RPC service
Named pipe : LRPC-2d35244246fa7eb0b7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e40f7b57-7a25-4cd3-a135-7f7d3df9d16b, version 1.0
Description : Unknown RPC service
Annotation : Network Connection Broker server endpoint
Type : Local RPC service
Named pipe : LRPC-7d228954a2753d120e

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e40f7b57-7a25-4cd3-a135-7f7d3df9d16b, version 1.0
Description : Unknown RPC service
Annotation : Network Connection Broker server endpoint
Type : Local RPC service
Named pipe : LRPC-2454aaa601053c404d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e40f7b57-7a25-4cd3-a135-7f7d3df9d16b, version 1.0
Description : Unknown RPC service
Annotation : Network Connection Broker server endpoint
Type : Local RPC service
Named pipe : OLE21217C9A642724B6D3737C14FB6C

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e40f7b57-7a25-4cd3-a135-7f7d3df9d16b, version 1.0
Description : Unknown RPC service
Annotation : Network Connection Broker server endpoint
Type : Local RPC service
Named pipe : LRPC-2d35244246fa7eb0b7

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000001
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WMsgKRpc0B6E81

Object UUID : b5ccd5ef-4238-440b-bba0-999f828f1cfe
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-340d97a094fa9879f9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a500d4c6-0dd1-4543-bc0c-d5f93486eaf8, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-340d97a094fa9879f9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a500d4c6-0dd1-4543-bc0c-d5f93486eaf8, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-29097c0a9e6c43609d

Object UUID : 6d726574-7273-0076-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : LRPC-cd84d6581178a0c006

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4bec6bb8-b5c2-4b6f-b2c1-5da5cf92d0d9, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 085b0334-e454-4d91-9b8c-4134f9e793f3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8782d3b9-ebbd-4644-a3d8-e8725381919b, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3b338d89-6cfa-44b8-847e-531531bc9992, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : bdaa0970-413b-4a3e-9e5d-f6dc9d7e0760, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5824833b-3c1a-4ad2-bdfd-c31d19e23ed2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0361ae94-0316-4c6c-8ad8-c594375800e2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2d98a740-581d-41b9-aa0d-a88b9d5ce938, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2d98a740-581d-41b9-aa0d-a88b9d5ce938, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2d98a740-581d-41b9-aa0d-a88b9d5ce938, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-84ea1b9aa8e1c8851d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8bfc3be1-6def-4e2d-af74-7c47cd0ade4a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8bfc3be1-6def-4e2d-af74-7c47cd0ade4a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8bfc3be1-6def-4e2d-af74-7c47cd0ade4a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-84ea1b9aa8e1c8851d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1b37ca91-76b1-4f5e-a3c7-2abfc61f2bb0, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1b37ca91-76b1-4f5e-a3c7-2abfc61f2bb0, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1b37ca91-76b1-4f5e-a3c7-2abfc61f2bb0, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-84ea1b9aa8e1c8851d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c605f9fb-f0a3-4e2a-a073-73560f8d9e3e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c605f9fb-f0a3-4e2a-a073-73560f8d9e3e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c605f9fb-f0a3-4e2a-a073-73560f8d9e3e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-84ea1b9aa8e1c8851d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3e2735-cea0-4ecc-a9e2-41a2d81aed4e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3e2735-cea0-4ecc-a9e2-41a2d81aed4e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3e2735-cea0-4ecc-a9e2-41a2d81aed4e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-84ea1b9aa8e1c8851d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2513bcbe-6cd4-4348-855e-7efb3c336dd3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2513bcbe-6cd4-4348-855e-7efb3c336dd3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2513bcbe-6cd4-4348-855e-7efb3c336dd3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-84ea1b9aa8e1c8851d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2513bcbe-6cd4-4348-855e-7efb3c336dd3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEE416DA4A6DE4281DF8996AD5C81E

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2513bcbe-6cd4-4348-855e-7efb3c336dd3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-148d321806da75d81b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 20c40295-8dba-48e6-aebf-3e78ef3bb144, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 20c40295-8dba-48e6-aebf-3e78ef3bb144, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 20c40295-8dba-48e6-aebf-3e78ef3bb144, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-84ea1b9aa8e1c8851d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 20c40295-8dba-48e6-aebf-3e78ef3bb144, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEE416DA4A6DE4281DF8996AD5C81E

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 20c40295-8dba-48e6-aebf-3e78ef3bb144, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-148d321806da75d81b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b8cadbaf-e84b-46b9-84f2-6f71c03f9e55, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b8cadbaf-e84b-46b9-84f2-6f71c03f9e55, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b8cadbaf-e84b-46b9-84f2-6f71c03f9e55, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-84ea1b9aa8e1c8851d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b8cadbaf-e84b-46b9-84f2-6f71c03f9e55, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEE416DA4A6DE4281DF8996AD5C81E

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b8cadbaf-e84b-46b9-84f2-6f71c03f9e55, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-148d321806da75d81b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-84ea1b9aa8e1c8851d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEE416DA4A6DE4281DF8996AD5C81E

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-148d321806da75d81b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-84ea1b9aa8e1c8851d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEE416DA4A6DE4281DF8996AD5C81E

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-148d321806da75d81b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-ee24b2bac611f4c992

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-84ea1b9aa8e1c8851d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEE416DA4A6DE4281DF8996AD5C81E

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-148d321806da75d81b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-ee24b2bac611f4c992

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-84ea1b9aa8e1c8851d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEE416DA4A6DE4281DF8996AD5C81E

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-148d321806da75d81b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-ee24b2bac611f4c992

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2c7fd9ce-e706-4b40-b412-953107ef9bb0, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c521facf-09a9-42c5-b155-72388595cbf0, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1832bcf6-cab8-41d4-85d2-c9410764f75a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4dace966-a243-4450-ae3f-9b7bcb5315b8, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 178d84be-9291-4994-82c6-3f909aca5a03, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e53d94ca-7464-4839-b044-09a2fb8b3ae5, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fae436b0-b864-4a87-9eda-298547cd82f2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 082a3471-31b6-422a-b931-a54401960c62, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 6982a06e-5fe2-46b1-b39c-a2c545bfa069, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0ff1f646-13bb-400a-ab50-9a78f2b7a85a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4ed8abcc-f1e2-438b-981f-bb0e8abc010c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 95406f0b-b239-4318-91bb-cea3a46ff0dc, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d47017b-b33b-46ad-9e18-fe96456c5078, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : dd59071b-3215-4c59-8481-972edadc0f6a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 7cd4a68a-505e-456b-b11e-ca76a5dd491c
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 7cd4a68a-505e-456b-b11e-ca76a5dd491c
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 7cd4a68a-505e-456b-b11e-ca76a5dd491c
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-84ea1b9aa8e1c8851d

Object UUID : 7cd4a68a-505e-456b-b11e-ca76a5dd491c
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEE416DA4A6DE4281DF8996AD5C81E

Object UUID : 7cd4a68a-505e-456b-b11e-ca76a5dd491c
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-148d321806da75d81b

Object UUID : 7cd4a68a-505e-456b-b11e-ca76a5dd491c
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-ee24b2bac611f4c992

Object UUID : 7cd4a68a-505e-456b-b11e-ca76a5dd491c
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-2af183f4e6c68b6623

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-84ea1b9aa8e1c8851d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEE416DA4A6DE4281DF8996AD5C81E

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-148d321806da75d81b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-ee24b2bac611f4c992

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-2af183f4e6c68b6623

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c8266cef03c52397cd

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-84ea1b9aa8e1c8851d

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEE416DA4A6DE4281DF8996AD5C81E

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-148d321806da75d81b

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-ee24b2bac611f4c992

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-2af183f4e6c68b6623

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c8266cef03c52397cd

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-84ea1b9aa8e1c8851d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEE416DA4A6DE4281DF8996AD5C81E

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-148d321806da75d81b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-ee24b2bac611f4c992

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-2af183f4e6c68b6623

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c8266cef03c52397cd

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-54d6d0b8c429d52871

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-84ea1b9aa8e1c8851d

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEE416DA4A6DE4281DF8996AD5C81E

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-148d321806da75d81b

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-ee24b2bac611f4c992

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-2af183f4e6c68b6623

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c8266cef03c52397cd

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-54d6d0b8c429d52871

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : csebpub

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-84ea1b9aa8e1c8851d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEE416DA4A6DE4281DF8996AD5C81E

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-148d321806da75d81b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-ee24b2bac611f4c992

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-2af183f4e6c68b6623

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c8266cef03c52397cd

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/445/cifs


The following DCERPC services are available remotely :

Object UUID : 765294ba-60bc-48b8-92e9-89fd77769d91
UUID : d95afe70-a6d5-4259-822e-2c84da1ddb0d, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\InitShutdown
Netbios name : \\LKP_SIP_APPSRV-

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000000
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\InitShutdown
Netbios name : \\LKP_SIP_APPSRV-

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 338cd001-2244-31f1-aaaa-900038001003, version 1.0
Description : Remote Registry
Windows process : svchost.exe
Annotation : RemoteRegistry Interface
Type : Remote RPC service
Named pipe : \PIPE\winreg
Netbios name : \\LKP_SIP_APPSRV-

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : da5a86c5-12c2-4943-ab30-7f74a813d853, version 1.0
Description : Unknown RPC service
Annotation : RemoteRegistry Perflib Interface
Type : Remote RPC service
Named pipe : \PIPE\winreg
Netbios name : \\LKP_SIP_APPSRV-

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Remote RPC service
Named pipe : \pipe\lsass
Netbios name : \\LKP_SIP_APPSRV-

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Remote RPC service
Named pipe : \pipe\lsass
Netbios name : \\LKP_SIP_APPSRV-

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Remote RPC service
Named pipe : \pipe\lsass
Netbios name : \\LKP_SIP_APPSRV-

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Remote RPC service
Named pipe : \pipe\lsass
Netbios name : \\LKP_SIP_APPSRV-

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 650a7e26-eab8-5533-ce43-9c1dfce11511, version 1.0
Description : Unknown RPC service
Annotation : Vpn APIs
Type : Remote RPC service
Named pipe : \PIPE\ROUTER
Netbios name : \\LKP_SIP_APPSRV-

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\SessEnvPublicRpc
Netbios name : \\LKP_SIP_APPSRV-

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7f1343fe-50a9-4927-a778-0c5859517bac, version 1.0
Description : Unknown RPC service
Annotation : DfsDs service
Type : Remote RPC service
Named pipe : \PIPE\wkssvc
Netbios name : \\LKP_SIP_APPSRV-

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1ff70682-0a51-30e8-076d-740be8cee98b, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\LKP_SIP_APPSRV-

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 378e52b0-c0a9-11cf-822d-00aa0051e40f, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\LKP_SIP_APPSRV-

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 33d84484-3626-47ee-8c6f-e7e98b113be1, version 2.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\LKP_SIP_APPSRV-

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\LKP_SIP_APPSRV-

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\LKP_SIP_APPSRV-

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f6beaff7-1e19-4fbb-9f8f-b89e2018337c, version 1.0
Description : Unknown RPC service
Annotation : Event log TCPIP
Type : Remote RPC service
Named pipe : \pipe\eventlog
Netbios name : \\LKP_SIP_APPSRV-

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/2103/dce-rpc


The following DCERPC services are available on TCP port 2103 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fdb3a030-065f-11d1-bb9b-00a024ea5525, version 1.0
Description : Message Queuing Service
Windows process : mqsvc.exe
Annotation : Message Queuing - QMRT V1
Type : Remote RPC service
TCP Port : 2103
IP : 172.17.100.140

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76d12b80-3467-11d3-91ff-0090272f9ea3, version 1.0
Description : Message Queuing Service
Windows process : mqsvc.exe
Annotation : Message Queuing - QMRT V2
Type : Remote RPC service
TCP Port : 2103
IP : 172.17.100.140

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1088a980-eae5-11d0-8d9b-00a02453c337, version 1.0
Description : Message Queuing Service
Windows process : mqsvc.exe
Annotation : Message Queuing - QM2QM V1
Type : Remote RPC service
TCP Port : 2103
IP : 172.17.100.140

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1a9134dd-7b39-45ba-ad88-44d01ca47f28, version 1.0
Description : Unknown RPC service
Annotation : Message Queuing - RemoteRead V1
Type : Remote RPC service
TCP Port : 2103
IP : 172.17.100.140

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/2105/dce-rpc


The following DCERPC services are available on TCP port 2105 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fdb3a030-065f-11d1-bb9b-00a024ea5525, version 1.0
Description : Message Queuing Service
Windows process : mqsvc.exe
Annotation : Message Queuing - QMRT V1
Type : Remote RPC service
TCP Port : 2105
IP : 172.17.100.140

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76d12b80-3467-11d3-91ff-0090272f9ea3, version 1.0
Description : Message Queuing Service
Windows process : mqsvc.exe
Annotation : Message Queuing - QMRT V2
Type : Remote RPC service
TCP Port : 2105
IP : 172.17.100.140

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1088a980-eae5-11d0-8d9b-00a02453c337, version 1.0
Description : Message Queuing Service
Windows process : mqsvc.exe
Annotation : Message Queuing - QM2QM V1
Type : Remote RPC service
TCP Port : 2105
IP : 172.17.100.140

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1a9134dd-7b39-45ba-ad88-44d01ca47f28, version 1.0
Description : Unknown RPC service
Annotation : Message Queuing - RemoteRead V1
Type : Remote RPC service
TCP Port : 2105
IP : 172.17.100.140

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/2107/dce-rpc


The following DCERPC services are available on TCP port 2107 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fdb3a030-065f-11d1-bb9b-00a024ea5525, version 1.0
Description : Message Queuing Service
Windows process : mqsvc.exe
Annotation : Message Queuing - QMRT V1
Type : Remote RPC service
TCP Port : 2107
IP : 172.17.100.140

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76d12b80-3467-11d3-91ff-0090272f9ea3, version 1.0
Description : Message Queuing Service
Windows process : mqsvc.exe
Annotation : Message Queuing - QMRT V2
Type : Remote RPC service
TCP Port : 2107
IP : 172.17.100.140

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1088a980-eae5-11d0-8d9b-00a02453c337, version 1.0
Description : Message Queuing Service
Windows process : mqsvc.exe
Annotation : Message Queuing - QM2QM V1
Type : Remote RPC service
TCP Port : 2107
IP : 172.17.100.140

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1a9134dd-7b39-45ba-ad88-44d01ca47f28, version 1.0
Description : Unknown RPC service
Annotation : Message Queuing - RemoteRead V1
Type : Remote RPC service
TCP Port : 2107
IP : 172.17.100.140

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49664/dce-rpc


The following DCERPC services are available on TCP port 49664 :

Object UUID : 765294ba-60bc-48b8-92e9-89fd77769d91
UUID : d95afe70-a6d5-4259-822e-2c84da1ddb0d, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49664
IP : 172.17.100.140

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49665/dce-rpc


The following DCERPC services are available on TCP port 49665 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f6beaff7-1e19-4fbb-9f8f-b89e2018337c, version 1.0
Description : Unknown RPC service
Annotation : Event log TCPIP
Type : Remote RPC service
TCP Port : 49665
IP : 172.17.100.140

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49666/dce-rpc


The following DCERPC services are available on TCP port 49666 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.140

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.140

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49667/dce-rpc


The following DCERPC services are available on TCP port 49667 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49667
IP : 172.17.100.140

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49668/dce-rpc


The following DCERPC services are available on TCP port 49668 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345678-1234-abcd-ef00-0123456789ab, version 1.0
Description : IPsec Services (Windows XP & 2003)
Windows process : lsass.exe
Type : Remote RPC service
TCP Port : 49668
IP : 172.17.100.140

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0b6edbfa-4a24-4fc6-8a23-942b1eca65d1, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49668
IP : 172.17.100.140

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : ae33069b-a2a8-46ee-a235-ddfd339be281, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49668
IP : 172.17.100.140

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4a452661-8290-4b36-8fbe-7f4093a94978, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49668
IP : 172.17.100.140

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76f03f96-cdfd-44fc-a22c-64950a001209, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49668
IP : 172.17.100.140

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49669/dce-rpc


The following DCERPC services are available on TCP port 49669 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fdb3a030-065f-11d1-bb9b-00a024ea5525, version 1.0
Description : Message Queuing Service
Windows process : mqsvc.exe
Annotation : Message Queuing - QMRT V1
Type : Remote RPC service
TCP Port : 49669
IP : 172.17.100.140

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76d12b80-3467-11d3-91ff-0090272f9ea3, version 1.0
Description : Message Queuing Service
Windows process : mqsvc.exe
Annotation : Message Queuing - QMRT V2
Type : Remote RPC service
TCP Port : 49669
IP : 172.17.100.140

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1088a980-eae5-11d0-8d9b-00a02453c337, version 1.0
Description : Message Queuing Service
Windows process : mqsvc.exe
Annotation : Message Queuing - QM2QM V1
Type : Remote RPC service
TCP Port : 49669
IP : 172.17.100.140

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1a9134dd-7b39-45ba-ad88-44d01ca47f28, version 1.0
Description : Unknown RPC service
Annotation : Message Queuing - RemoteRead V1
Type : Remote RPC service
TCP Port : 49669
IP : 172.17.100.140

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49670/dce-rpc


The following DCERPC services are available on TCP port 49670 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 6b5bdd1e-528c-422c-af8c-a4079be4fe48, version 1.0
Description : Unknown RPC service
Annotation : Remote Fw APIs
Type : Remote RPC service
TCP Port : 49670
IP : 172.17.100.140

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49678/dce-rpc


The following DCERPC services are available on TCP port 49678 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 367abb81-9844-35f1-ad32-98f038001003, version 2.0
Description : Service Control Manager
Windows process : svchost.exe
Type : Remote RPC service
TCP Port : 49678
IP : 172.17.100.140

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49744/dce-rpc


The following DCERPC services are available on TCP port 49744 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Remote RPC service
TCP Port : 49744
IP : 172.17.100.140

139785 - DISM Package List (Windows)
-
Synopsis
Use DISM to extract package info from the host.
Description
Using the Deployment Image Servicing Management tool, this plugin enumerates installed packages.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2020/08/25, Modified: 2025/12/15
Plugin Output

tcp/445/cifs

The following packages were enumerated using the Deployment Image Servicing and Management Tool:

Package : Microsoft-Windows-FodMetadata-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : Feature Pack
Install Time : 15-09-2018 09:08

Package : Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : Foundation
Install Time : 15-09-2018 07:21

Package : Microsoft-Windows-InternetExplorer-Optional-Package~31bf3856ad364e35~amd64~~11.0.17763.1
State : Installed
Release Type : OnDemand Pack
Install Time : 15-09-2018 09:07

Package : Microsoft-Windows-LanguageFeatures-Basic-en-gb-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : OnDemand Pack
Install Time : 26-06-2024 11:53

Package : Microsoft-Windows-LanguageFeatures-Basic-en-us-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : OnDemand Pack
Install Time : 15-09-2018 09:08

Package : Microsoft-Windows-LanguageFeatures-Handwriting-en-us-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : OnDemand Pack
Install Time : 15-09-2018 09:08

Package : Microsoft-Windows-LanguageFeatures-OCR-en-gb-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : OnDemand Pack
Install Time : 26-06-2024 11:53

Package : Microsoft-Windows-LanguageFeatures-OCR-en-us-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : OnDemand Pack
Install Time : 15-09-2018 09:08

Package : Microsoft-Windows-LanguageFeatures-Speech-en-in-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : OnDemand Pack
Install Time : 26-06-2024 11:53

Package : Microsoft-Windows-LanguageFeatures-Speech-en-us-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : OnDemand Pack
Install Time : 15-09-2018 09:08

Package : Microsoft-Windows-LanguageFeatures-TextToSpeech-en-in-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : OnDemand Pack
Install Time : 26-06-2024 11:53

Package : Microsoft-Windows-LanguageFeatures-TextToSpeech-en-us-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : OnDemand Pack
Install Time : 15-09-2018 09:08

Package : Microsoft-Windows-MediaPlayer-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : OnDemand Pack
Install Time : 15-09-2018 09:08

Package : Microsoft-Windows-NetFx3-OnDemand-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : OnDemand Pack
Install Time : 12-12-2024 12:46

Package : Microsoft-Windows-Security-SPP-Component-SKU-ServerDatacenter-GVLK-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : Feature Pack
Install Time : 15-09-2018 09:11

Package : Microsoft-Windows-Server-LanguagePack-Package~31bf3856ad364e35~amd64~en-US~10.0.17763.1
State : Installed
Release Type : Language Pack
Install Time : 15-09-2018 09:07

Package : Microsoft-Windows-ServerCore-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : Feature Pack
Install Time : 15-09-2018 07:21

Package : Microsoft-Windows-ServerCore-SKU-Foundation-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : Feature Pack
Install Time : 15-09-2018 07:21

Package : Microsoft-Windows-TabletPCMath-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : OnDemand Pack
Install Time : 15-09-2018 09:09

Package : Microsoft-Windows-Xps-Xps-Viewer-Opt-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : OnDemand Pack
Install Time : 15-09-2018 09:08

Package : Msix-PackagingTool-Driver-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : OnDemand Pack
Install Time : 30-12-2025 03:37

Package : OpenSSH-Client-Package~31bf3856ad364e35~amd64~~10.0.17763.1
State : Installed
Release Type : OnDemand Pack
Install Time : 15-09-2018 09:08

Package : Package_for_DotNetRollup~31bf3856ad364e35~amd64~~10.0.3840.1
State : Superseded
Release Type : Update
Install Time : 05-08-2021 19:24

Package : Package_for_DotNetRollup~31bf3856ad364e35~amd64~~10.0.4126.1
State : Installed
Release Type : Update
Install Time : 02-04-2025 12:15

Package : Package_for_KB4589208~31bf3856ad364e35~amd64~~10.0.2.4
State : Installed
Release Type : Update
Install Time : 26-06-2024 12:04

Package : Package_for_KB5005112~31bf3856ad364e35~amd64~~17763.2111.1.0
State : Installed
Release Type : Security Update
Install Time : 05-08-2021 19:24

Package : Package_for_RollupFix~31bf3856ad364e35~amd64~~17763.2114.1.3
State : Superseded
Release Type : Security Update
Install Time : 05-08-2021 19:36

Package : Package_for_RollupFix~31bf3856ad364e35~amd64~~17763.6893.1.6
State : Installed
Release Type : Security Update
Install Time : 02-04-2025 12:15

Package : Package_for_ServicingStack_5920~31bf3856ad364e35~amd64~~17763.5920.1.1
State : Installed
Release Type : Security Update
Install Time : 26-06-2024 11:54

Package : Package_for_ServicingStack_6763~31bf3856ad364e35~amd64~~17763.6763.1.1
State : Installed
Release Type : Security Update
Install Time : 02-04-2025 06:22

84239 - Debugging Log Report
-
Synopsis
This plugin gathers the logs written by other plugins and reports them.
Description
Logs generated by other plugins are reported by this plugin. Plugin debugging must be enabled in the policy in order for this plugin to run.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2015/06/17, Modified: 2025/07/14
Plugin Output

tcp/0

Plugin debug log(s) have been attached.

179500 - Defense-in-Depth Security Updates for Microsoft Office Products (August 2023)
-
Synopsis
The Microsoft Office Products are missing defense-in-depth security updates.
Description
The Microsoft Office Products are missing defense-in-depth security updates to help improve security-related features.
See Also
Solution
Microsoft has released the following defense-in-depth security updates to address this issue:
-KB5002439
-KB5002465
Risk Factor
None
References
MSKB 5002439
MSKB 5002465
XREF MSFT:MS23-5002439
XREF MSFT:MS23-5002465
Plugin Information
Published: 2023/08/08, Modified: 2023/08/08
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002465
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso30win32client.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5408.1001
179668 - Defense-in-Depth Security Updates for Microsoft PowerPoint Products (August 2023)
-
Synopsis
The Microsoft PowerPoint Products are missing defense-in-depth security update.
Description
The Microsoft PowerPoint Products are missing missing defense-in-depth security updates to help improve security-related features.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5002399
-KB4504720
Risk Factor
None
References
MSKB 5002399
MSKB 4504720
XREF MSFT:MS23-5002399
XREF MSFT:MS23-4504720
Plugin Information
Published: 2023/08/10, Modified: 2023/08/10
Plugin Output

tcp/445/cifs



Product : PowerPoint 2016
- C:\Program Files\Microsoft Office\Office16\ppcore.dll has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5408.1001
179671 - Defense-in-Depth Security Updates for Microsoft Publisher Products (August 2023)
-
Synopsis
The Microsoft Publisher Products are missing defense-in-depth security updates.
Description
The Microsoft Publisher Products are missing defense-in-depth security updates to help improve security-related features.
See Also
Solution
Microsoft has released the following defense-in-depth security updates to address this issue:
-KB5002391
-KB5002462
Risk Factor
None
References
MSKB 5002391
MSKB 5002462
XREF MSFT:MS23-5002391
XREF MSFT:MS23-5002462
Plugin Information
Published: 2023/08/10, Modified: 2023/08/10
Plugin Output

tcp/445/cifs



Product : Publisher 2016
- C:\Program Files\Microsoft Office\Office16\Mspub.exe has not been patched.
Remote version : 16.0.4266.1001
Fixed version : 16.0.5408.1001

55472 - Device Hostname
-
Synopsis
It was possible to determine the remote system hostname.
Description
This plugin reports a device's hostname collected via SSH or WMI.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/06/30, Modified: 2025/12/15
Plugin Output

tcp/0


Hostname :
LKP_SIP_APPSRV- (WMI)
54615 - Device Type
-
Synopsis
It is possible to guess the remote device type.
Description
Based on the remote operating system, it is possible to determine what the remote system type is (eg: a printer, router, general-purpose computer, etc).
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/05/23, Modified: 2025/03/12
Plugin Output

tcp/0

Remote device type : general-purpose
Confidence level : 100

19689 - Embedded Web Server Detection
-
Synopsis
The remote web server is embedded.
Description
The remote web server cannot host user-supplied CGIs. CGI scanning will be disabled on this server.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2005/09/14, Modified: 2025/09/29
Plugin Output

tcp/1947/www

71246 - Enumerate Local Group Memberships
-
Synopsis
Nessus was able to connect to a host via SMB to retrieve a list of local Groups and their Members.
Description
Nessus was able to connect to a host via SMB to retrieve a list of local Groups and their Members.

Note: Unable to query local Domain Controllers during Agent scans.
Rendering Group data obtained by plugin 171956.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/12/06, Modified: 2025/12/15
Plugin Output

tcp/0

Group Name : Access Control Assistance Operators
Host Name : LKP_SIP_APPSRV-
Group SID : S-1-5-32-579
Members :

Group Name : Administrators
Host Name : LKP_SIP_APPSRV-
Group SID : S-1-5-32-544
Members :
Name : Production
Domain : LKP_SIP_APPSRV-
Class : Win32_UserAccount
SID : S-1-5-21-3194671253-1068146636-4210433707-500
Name : LKPAdmin
Domain : LKP_SIP_APPSRV-
Class : Win32_UserAccount
SID : S-1-5-21-3194671253-1068146636-4210433707-1000
Name : tidua
Domain : LKP_SIP_APPSRV-
Class : Win32_UserAccount
SID : S-1-5-21-3194671253-1068146636-4210433707-1003

Group Name : Backup Operators
Host Name : LKP_SIP_APPSRV-
Group SID : S-1-5-32-551
Members :

Group Name : Certificate Service DCOM Access
Host Name : LKP_SIP_APPSRV-
Group SID : S-1-5-32-574
Members :

Group Name : Cryptographic Operators
Host Name : LKP_SIP_APPSRV-
Group SID : S-1-5-32-569
Members :

Group Name : Device Owners
Host Name : LKP_SIP_APPSRV-
Group SID : S-1-5-32-583
Members :

Group Name : Distributed COM Users
Host Name : LKP_SIP_APPSRV-
Group SID : S-1-5-32-562
Members :

Group Name : Event Log Readers
Host Name : LKP_SIP_APPSRV-
Group SID : S-1-5-32-573
Members :

Group Name : Guests
Host Name : LKP_SIP_APPSRV-
Group SID : S-1-5-32-546
Members :
Name : Guest
Domain : LKP_SIP_APPSRV-
Class : Win32_UserAccount
SID : S-1-5-21-3194671253-1068146636-4210433707-501

Group Name : Hyper-V Administrators
Host Name : LKP_SIP_APPSRV-
Group SID : S-1-5-32-578
Members :

Group Name : IIS_IUSRS
Host Name : LKP_SIP_APPSRV-
Group SID : S-1-5-32-568
Members :

Group Name : Network Configuration Operators
Host Name : LKP_SIP_APPSRV-
Group SID : S-1-5-32-556
Members :

Group Name : Performance Log Users
Host Name : LKP_SIP_APPSRV-
Group SID : S-1-5-32-559
Members :

Group Name : Performance Monitor Users
Host Name : LKP_SIP_APPSRV-
Group SID : S-1-5-32-558
Members :
Name : SQLServerReportingServices
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :

Group Name : Power Users
Host Name : LKP_SIP_APPSRV-
Group SID : S-1-5-32-547
Members :
Name : LKPAdmin
Domain : LKP_SIP_APPSRV-
Class : Win32_UserAccount
SID : S-1-5-21-3194671253-1068146636-4210433707-1000

Group Name : Print Operators
Host Name : LKP_SIP_APPSRV-
Group SID : S-1-5-32-550
Members :

Group Name : RDS Endpoint Servers
Host Name : LKP_SIP_APPSRV-
Group SID : S-1-5-32-576
Members :

Group Name : RDS Management Servers
Host Name : LKP_SIP_APPSRV-
Group SID : S-1-5-32-577
Members :

Group Name : RDS Remote Access Servers
Host Name : LKP_SIP_APPSRV-
Group SID : S-1-5-32-575
Members :

Group Name : Remote Desktop Users
Host Name : LKP_SIP_APPSRV-
Group SID : S-1-5-32-555
Members :

Group Name : Remote Management Users
Host Name : LKP_SIP_APPSRV-
Group SID : S-1-5-32-580
Members :

Group Name : Replicator
Host Name : LKP_SIP_APPSRV-
Group SID : S-1-5-32-552
Members :

Group Name : Storage Replica Administrators
Host Name : LKP_SIP_APPSRV-
Group SID : S-1-5-32-582
Members :

Group Name : System Managed Accounts Group
Host Name : LKP_SIP_APPSRV-
Group SID : S-1-5-32-581
Members :
Name : DefaultAccount
Domain : LKP_SIP_APPSRV-
Class : Win32_UserAccount
SID : S-1-5-21-3194671253-1068146636-4210433707-503

Group Name : Users
Host Name : LKP_SIP_APPSRV-
Group SID : S-1-5-32-545
Members :
Name : INTERACTIVE
Domain : LKP_SIP_APPSRV-
Class : Win32_SystemAccount
SID : S-1-5-4
Name : Authenticated Users
Domain : LKP_SIP_APPSRV-
Class : Win32_SystemAccount
SID : S-1-5-11
Name : LKPAdmin
Domain : LKP_SIP_APPSRV-
Class : Win32_UserAccount
SID : S-1-5-21-3194671253-1068146636-4210433707-1000
Name : tidua
Domain : LKP_SIP_APPSRV-
Class : Win32_UserAccount
SID : S-1-5-21-3194671253-1068146636-4210433707-1003

Group Name : KLAdmins
Host Name : LKP_SIP_APPSRV-
Group SID : S-1-5-21-3194671253-1068146636-4210433707-1001
Members :
Name : ksnproxy
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :

Group Name : KLOperators
Host Name : LKP_SIP_APPSRV-
Group SID : S-1-5-21-3194671253-1068146636-4210433707-1002
Members :
72684 - Enumerate Users via WMI
-
Synopsis
Nessus was able to connect to a host via SMB to retrieve a list of users using WMI.
Description
Nessus was able to connect to a host via SMB to retrieve a list of users using WMI. Only identities that the authenticated SMB user has permissions to view will be retrieved by this plugin.

Note: Unable to query local Domain Controllers during Agent scans.
Rendering User data obtained by plugin 171956.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2014/02/25, Modified: 2025/12/15
Plugin Output

tcp/0


Name : DefaultAccount
SID : S-1-5-21-3194671253-1068146636-4210433707-503
Disabled : True
Lockout : False
Change password : True
Source : Local

Name : Guest
SID : S-1-5-21-3194671253-1068146636-4210433707-501
Disabled : True
Lockout : False
Change password : False
Source : Local

Name : LKPAdmin
SID : S-1-5-21-3194671253-1068146636-4210433707-1000
Disabled : False
Lockout : False
Change password : True
Source : Local

Name : Production
SID : S-1-5-21-3194671253-1068146636-4210433707-500
Disabled : False
Lockout : False
Change password : True
Source : Local

Name : tidua
SID : S-1-5-21-3194671253-1068146636-4210433707-1003
Disabled : False
Lockout : False
Change password : False
Source : Local

Name : WDAGUtilityAccount
SID : S-1-5-21-3194671253-1068146636-4210433707-504
Disabled : True
Lockout : False
Change password : True
Source : Local

No. Of Users : 6
168980 - Enumerate the PATH Variables
-
Synopsis
Enumerates the PATH variable of the current scan user.
Description
Enumerates the PATH variables of the current scan user.
Solution
Ensure that directories listed here are in line with corporate policy.
Risk Factor
None
Plugin Information
Published: 2022/12/21, Modified: 2025/12/18
Plugin Output

tcp/0

Nessus has enumerated the path of the current scan user :

C:\Windows\system32
C:\Windows
C:\Windows\System32\Wbem
C:\Windows\System32\WindowsPowerShell\v1.0\
C:\Windows\System32\OpenSSH\
C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\
C:\Program Files\OpenSSL-Win64
C:\Program Files\dotnet\
C:\Program Files (x86)\dotnet\
117530 - Errors in nessusd.dump
-
Synopsis
This plugin parses information from the nessusd.dump log file and reports on errors.
Description
This plugin parses information from the nessusd.dump log file and reports on errors.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2018/09/17, Modified: 2024/11/04
Plugin Output

tcp/0

The nessusd.dump log file contained errors from the following plugins:

- smb_enum_software_versions.nasl reported 1 error
- wmi_enum_start_menu_software_versions.nbin reported 1 error
- react_CVE-2025-55182.nbin reported 4 errors
- log4j_log4shell_www.nbin reported 1 error
- quic_detect.nasl reported 1 error
- wmi_start_server_svc.nbin reported 4 errors
35716 - Ethernet Card Manufacturer Detection
-
Synopsis
The manufacturer can be identified from the Ethernet OUI.
Description
Each ethernet MAC address starts with a 24-bit Organizationally Unique Identifier (OUI). These OUIs are registered by IEEE.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/02/19, Modified: 2020/05/13
Plugin Output

tcp/0


The following card manufacturers were identified :

00:50:56:88:13:C1 : VMware, Inc.
00:50:56:88:84:22 : VMware, Inc.
86420 - Ethernet MAC Addresses
-
Synopsis
This plugin gathers MAC addresses from various sources and consolidates them into a list.
Description
This plugin gathers MAC addresses discovered from both remote probing of the host (e.g. SNMP and Netbios) and from running local checks (e.g. ifconfig). It then consolidates the MAC addresses into a single, unique, and uniform list.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2015/10/16, Modified: 2025/06/10
Plugin Output

tcp/0

The following is a consolidated list of detected MAC addresses:
- 00:50:56:88:13:C1
- 00:50:56:88:84:22
92439 - Explorer Search History
-
Synopsis
Nessus was able to gather a list of items searched for in the Windows UI.
Description
Nessus was able to gather evidence of cached search results from Windows Explorer searches.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0


Explorer search history report attached.
56310 - Firewall Rule Enumeration
-
Synopsis
A firewall is configured on the remote host.
Description
Using the supplied credentials, Nessus was able to get a list of firewall rules from the remote host.

Note: The output for this plugin can be very long, and is not shown by default. To display it, enable verbose reporting in scan settings.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/09/28, Modified: 2020/09/11
Plugin Output

tcp/0

report output too big - ending list here

43111 - HTTP Methods Allowed (per directory)
-
Synopsis
This plugin determines which HTTP methods are allowed on various CGI directories.
Description
By calling the OPTIONS method, it is possible to determine which HTTP methods are allowed on each directory.

The following HTTP methods are considered insecure:
PUT, DELETE, CONNECT, TRACE, HEAD

Many frameworks and languages treat 'HEAD' as a 'GET' request, albeit one without any body in the response. If a security constraint was set on 'GET' requests such that only 'authenticatedUsers' could access GET requests for a particular servlet or resource, it would be bypassed for the 'HEAD' version. This allowed unauthorized blind submission of any privileged GET request.

As this list may be incomplete, the plugin also tests - if 'Thorough tests' are enabled or 'Enable web applications tests' is set to 'yes'
in the scan policy - various known HTTP methods on each directory and considers them as unsupported if it receives a response code of 400, 403, 405, or 501.

Note that the plugin output is only informational and does not necessarily indicate the presence of any security vulnerabilities.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/12/10, Modified: 2022/04/11
Plugin Output

tcp/80/www

Based on the response to an OPTIONS request :

- HTTP methods GET HEAD POST TRACE OPTIONS are allowed on :

/

43111 - HTTP Methods Allowed (per directory)
-
Synopsis
This plugin determines which HTTP methods are allowed on various CGI directories.
Description
By calling the OPTIONS method, it is possible to determine which HTTP methods are allowed on each directory.

The following HTTP methods are considered insecure:
PUT, DELETE, CONNECT, TRACE, HEAD

Many frameworks and languages treat 'HEAD' as a 'GET' request, albeit one without any body in the response. If a security constraint was set on 'GET' requests such that only 'authenticatedUsers' could access GET requests for a particular servlet or resource, it would be bypassed for the 'HEAD' version. This allowed unauthorized blind submission of any privileged GET request.

As this list may be incomplete, the plugin also tests - if 'Thorough tests' are enabled or 'Enable web applications tests' is set to 'yes'
in the scan policy - various known HTTP methods on each directory and considers them as unsupported if it receives a response code of 400, 403, 405, or 501.

Note that the plugin output is only informational and does not necessarily indicate the presence of any security vulnerabilities.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/12/10, Modified: 2022/04/11
Plugin Output

tcp/8001/www

Based on the response to an OPTIONS request :

- HTTP methods GET HEAD POST TRACE OPTIONS are allowed on :

/

43111 - HTTP Methods Allowed (per directory)
-
Synopsis
This plugin determines which HTTP methods are allowed on various CGI directories.
Description
By calling the OPTIONS method, it is possible to determine which HTTP methods are allowed on each directory.

The following HTTP methods are considered insecure:
PUT, DELETE, CONNECT, TRACE, HEAD

Many frameworks and languages treat 'HEAD' as a 'GET' request, albeit one without any body in the response. If a security constraint was set on 'GET' requests such that only 'authenticatedUsers' could access GET requests for a particular servlet or resource, it would be bypassed for the 'HEAD' version. This allowed unauthorized blind submission of any privileged GET request.

As this list may be incomplete, the plugin also tests - if 'Thorough tests' are enabled or 'Enable web applications tests' is set to 'yes'
in the scan policy - various known HTTP methods on each directory and considers them as unsupported if it receives a response code of 400, 403, 405, or 501.

Note that the plugin output is only informational and does not necessarily indicate the presence of any security vulnerabilities.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/12/10, Modified: 2022/04/11
Plugin Output

tcp/8002/www

Based on the response to an OPTIONS request :

- HTTP methods GET HEAD POST TRACE OPTIONS are allowed on :

/

10107 - HTTP Server Type and Version
-
Synopsis
A web server is running on the remote host.
Description
This plugin attempts to determine the type and the version of the remote web server.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0931
Plugin Information
Published: 2000/01/04, Modified: 2020/10/30
Plugin Output

tcp/80/www

The remote web server type is :

Microsoft-IIS/10.0

10107 - HTTP Server Type and Version
-
Synopsis
A web server is running on the remote host.
Description
This plugin attempts to determine the type and the version of the remote web server.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0931
Plugin Information
Published: 2000/01/04, Modified: 2020/10/30
Plugin Output

tcp/1947/www

The remote web server type is :

HASP LM/22.01

10107 - HTTP Server Type and Version
-
Synopsis
A web server is running on the remote host.
Description
This plugin attempts to determine the type and the version of the remote web server.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0931
Plugin Information
Published: 2000/01/04, Modified: 2020/10/30
Plugin Output

tcp/5985/www

The remote web server type is :

Microsoft-HTTPAPI/2.0

10107 - HTTP Server Type and Version
-
Synopsis
A web server is running on the remote host.
Description
This plugin attempts to determine the type and the version of the remote web server.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0931
Plugin Information
Published: 2000/01/04, Modified: 2020/10/30
Plugin Output

tcp/7001/www

The remote web server type is :

Microsoft-IIS/10.0

10107 - HTTP Server Type and Version
-
Synopsis
A web server is running on the remote host.
Description
This plugin attempts to determine the type and the version of the remote web server.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0931
Plugin Information
Published: 2000/01/04, Modified: 2020/10/30
Plugin Output

tcp/8001/www

The remote web server type is :

Microsoft-IIS/10.0

10107 - HTTP Server Type and Version
-
Synopsis
A web server is running on the remote host.
Description
This plugin attempts to determine the type and the version of the remote web server.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0931
Plugin Information
Published: 2000/01/04, Modified: 2020/10/30
Plugin Output

tcp/8002/www

The remote web server type is :

Microsoft-IIS/10.0

10107 - HTTP Server Type and Version
-
Synopsis
A web server is running on the remote host.
Description
This plugin attempts to determine the type and the version of the remote web server.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0931
Plugin Information
Published: 2000/01/04, Modified: 2020/10/30
Plugin Output

tcp/9505/www

The remote web server type is :

Microsoft-HTTPAPI/2.0

10107 - HTTP Server Type and Version
-
Synopsis
A web server is running on the remote host.
Description
This plugin attempts to determine the type and the version of the remote web server.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0931
Plugin Information
Published: 2000/01/04, Modified: 2020/10/30
Plugin Output

tcp/47001/www

The remote web server type is :

Microsoft-HTTPAPI/2.0

12053 - Host Fully Qualified Domain Name (FQDN) Resolution
-
Synopsis
It was possible to resolve the name of the remote host.
Description
Nessus was able to resolve the fully qualified domain name (FQDN) of the remote host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2004/02/11, Modified: 2025/03/13
Plugin Output

tcp/0


172.17.100.140 resolves as LKP_SIP_AppSrv-140.

24260 - HyperText Transfer Protocol (HTTP) Information
-
Synopsis
Some information about the remote HTTP configuration can be extracted.
Description
This test gives some information about the remote HTTP protocol - the version used, whether HTTP Keep-Alive is enabled, etc...

This test is informational only and does not denote any security problem.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/01/30, Modified: 2024/02/26
Plugin Output

tcp/80/www


Response Code : HTTP/1.1 200 OK

Protocol version : HTTP/1.1
HTTP/2 TLS Support: No
HTTP/2 Cleartext Support: No
SSL : no
Keep-Alive : no
Options allowed : OPTIONS, TRACE, GET, HEAD, POST
Headers :

Content-Type: text/html
Last-Modified: Fri, 06 Dec 2024 11:34:34 GMT
Accept-Ranges: bytes
ETag: "863a32d3d247db1:0"
Server: Microsoft-IIS/10.0
X-Powered-By: ASP.NET
Date: Sat, 24 Jan 2026 06:56:07 GMT
Content-Length: 703

Response Body :

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" />
<title>IIS Windows Server</title>
<style type="text/css">
<!--
body {
color:#000000;
background-color:#0072C6;
margin:0;
}

#container {
margin-left:auto;
margin-right:auto;
text-align:center;
}

a img {
border:none;
}

-->
</style>
</head>
<body>
<div id="container">
<a href="http://go.microsoft.com/fwlink/?linkid=66138&amp;clcid=0x409"><img src="iisstart.png" alt="IIS" width="960" height="600" /></a>
</div>
</body>
</html>

24260 - HyperText Transfer Protocol (HTTP) Information
-
Synopsis
Some information about the remote HTTP configuration can be extracted.
Description
This test gives some information about the remote HTTP protocol - the version used, whether HTTP Keep-Alive is enabled, etc...

This test is informational only and does not denote any security problem.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/01/30, Modified: 2024/02/26
Plugin Output

tcp/5985/www


Response Code : HTTP/1.1 404 Not Found

Protocol version : HTTP/1.1
HTTP/2 TLS Support: No
HTTP/2 Cleartext Support: No
SSL : no
Keep-Alive : no
Options allowed : (Not implemented)
Headers :

Content-Type: text/html; charset=us-ascii
Server: Microsoft-HTTPAPI/2.0
Date: Sat, 24 Jan 2026 06:56:07 GMT
Connection: close
Content-Length: 315

Response Body :

24260 - HyperText Transfer Protocol (HTTP) Information
-
Synopsis
Some information about the remote HTTP configuration can be extracted.
Description
This test gives some information about the remote HTTP protocol - the version used, whether HTTP Keep-Alive is enabled, etc...

This test is informational only and does not denote any security problem.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/01/30, Modified: 2024/02/26
Plugin Output

tcp/7001/www


Response Code : HTTP/1.1 404 Not Found

Protocol version : HTTP/1.1
HTTP/2 TLS Support: No
HTTP/2 Cleartext Support: No
SSL : no
Keep-Alive : no
Options allowed : (Not implemented)
Headers :

Transfer-Encoding: chunked
Server: Microsoft-IIS/10.0
X-Rate-Limit-Limit: 1m
X-Rate-Limit-Remaining: 88
X-Rate-Limit-Reset: 2026-01-24T06:56:36.7936729Z
X-Powered-By: ASP.NET
Date: Sat, 24 Jan 2026 06:56:07 GMT

Response Body :

24260 - HyperText Transfer Protocol (HTTP) Information
-
Synopsis
Some information about the remote HTTP configuration can be extracted.
Description
This test gives some information about the remote HTTP protocol - the version used, whether HTTP Keep-Alive is enabled, etc...

This test is informational only and does not denote any security problem.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/01/30, Modified: 2024/02/26
Plugin Output

tcp/8001/www


Response Code : HTTP/1.1 200 OK

Protocol version : HTTP/1.1
HTTP/2 TLS Support: No
HTTP/2 Cleartext Support: No
SSL : no
Keep-Alive : no
Options allowed : OPTIONS, TRACE, GET, HEAD, POST
Headers :

Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/10.0
X-AspNetMvc-Version: 4.0
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
Access-Control-Allow-Origin: *
Access-Control-Allow-Headers: Content-Type
Date: Sat, 24 Jan 2026 06:56:07 GMT
Content-Length: 24795

Response Body :






<!DOCTYPE html>
<head>




<link href="/Content/CSS/SC_Login.css" rel="stylesheet" />
<link href="/Content/CSS/CallBalanceMaster.css" rel="stylesheet" />
<link href="/Content/CSS/jquery-ui.css" rel="stylesheet" />



<script src="/Scripts_SSO/jquery-3.3.1.js"></script>
<script src="/Scripts/jquery.validate.min.js"></script>
<script src="/Scripts/jquery.validate.unobtrusive.min.js"></script>

<style>
.popupcss {
display: block;
z-index: 1004;
outline: 0px;
position: absolute;
height: auto;
width: 481px;
top: 90px !important;
left: 464px;
}

.csspopupClass {
position: absolute;
height: 323px;
width: 479px;
top: 16%;
left: 30%;
display: block;
z-index: 10002;
}

.callDest {
width: 279px;
height: 33px;
}



</style>


<title>Login</title>

<link href="/Content/css/Standard_Chartered.css" rel="stylesheet" type="text/css" />
<link href="/Content/css/callbalance_logincss.css?v1.0" rel="stylesheet" type="text/css" />
<link href="/Content/common.css?v1.0" rel="stylesheet" type="text/css" />
<script src="/Scripts_SSO/jquery-3.3.1.js"></script>
<script type="text/javascript">

//var UserAlreadyLoggedIn= null;

$(document).ready(function () {
//debugger;
//if(UserAlreadyLoggedIn==true)
//{
// ShowPopupUserKillSession();
//}

if(null == true)
{
ShowPopupUserKillSession();
}


if((null) == null&&(null)==null){
// ShowWarningPopupLoginPage();
}

if(userName!=null)
{
$("#UserId").val(userName);
$("#Password").val(password);
$("#RememberMe").attr('checked', true);
}

$("#btnForgotpassword").click(function () {
debugger;
ShowPopUp();


$("#txtUserId").change(function () {
var urlUserId = '/User/UserIdExsist';
var UserId = $("#txtUserId").val();
// alert(UserId);
if (UserId != null)
$.getJSON(urlUserId, { UserId: UserId }, function (data) {
if (data == true) {
$("#txtUserEmail").removeAttr("disabled", "disabled");
$(".lblErrorForgetPassword").css("display", "none");
}
else {
$(".lblErrorForgetPassword").css("display", "block").html('UserCode does not exist.');
$("#txtUserEmail").prop('disabled', true);
}
});

else if ($("#txtUserId").val() == "") {
// $("#lblUseridError").show();
$(".lblErrorForgetPassword").css("display", "block").html('please Enter Your UserCode');
$("#txtUserEmail").prop('disabled', true);
}

});


});

$("#UserId").keydown(function(){
$("#loginpageerror").hide();
});


$("#Password").keypress(function(){
$("#loginpageerror").hide();
});


function ShowPopUp() {

debugger;
$("#frgPass").fadeIn("slow");
$("#frgPass").addClass("csspopupClass");

$(".LightBoxContent").css("min-height", "auto");

$(".LightBoxContent").css("height", "160px");
$("#popupshadow").fadeIn("slow");

}


$(".login_Button_Btn").click(function(){
$("#loginpageerror").text("");
});

//Don't allow Copy paste cut
$('#Password').bind("cut copy paste",function(e) {
e.preventDefault();
});

});

</script>
</head>

<body style="margin-top:50px; background-color:#ededed; background-image:url(../../Images/bodeybg1.jpg); background-repeat:no-repeat; height:100%; width:100% !important;">
<div class="CS_logoBandBG"><img src="/Images/LKP_Band.jpeg" width="100%" height="67" alt="" /></div>

<div class="main">
<div class="loginBox">
<form action="/" method="post"><input name="__RequestVerificationToken" type="hidden" value="u12fovkXKx4vP7I6WaLoHrMAb_QfISAyVaGypm8w4YYskpieQpIt1nCtjxIdtKzjDAaTDH0klM2JSgasPW2vFyaFlb9vFst1vMgbD-QO3qE1" /> <div class="loginContent">
<div class="boxheadTopImg"><img src="/Images/box-header_sc1.jpg" width="100%" height="08" alt="" /></div>
<div class="nlite_logo">
<ul>
</ul>
<li><img src="/Images/CallBalance_logo.png" width="160" height="50" alt="" /></li>
</div>
<div class="logo_line">
&nbsp;
</div>

<div class="content_log">
<div>
<ul>
<li><label class="label_Txt">User Name :</label></li>
<li>
<input class="login_textbox" data-val="true" data-val-required="User Name is required." id="UserId" name="UserId" required="required" type="text" value="" />
</li>
<li>
&nbsp; <span class="field-validation-valid lblError" data-valmsg-for="UserId" data-valmsg-replace="true"></span>
</li>
<li><label class="label_Txt">Password :</label></li>
<li>
<input class="login_textbox" data-val="true" data-val-required="Password is required." id="Password" name="Password" required="required" type="password" />
</li>
<li style="width:300px">
&nbsp;
<span class="field-validation-valid lblError" data-valmsg-for="Password" data-valmsg-replace="true"></span>
</li>

</ul>
</div>
<div class="Remember">
<ul style="width: 100%; padding: 0px; margin-left: 160px;">


<li class="ForgotPassword">
<a id="btnForgotpassword" href="#btnForgotpassword" class=" frgpwd">Forgot Password?</a>
</li>


<li class="clear"></li>
</ul>
</div>

</div>

<div class="clear"></div>



<div class=""><input type="submit" style="color:white" value="Submit" class="login_Button_Btn" /></div>

</div>
</form> <script src="/Scripts/jquery-1.4.4.min.js"></script>
<script src="/Scripts/jquery-ui-1.8.24.js"></script>
<script src="/Scripts/gips.js" type="text/javascript"></script>

<style>
.csspopupClass {
position: absolute;
height: 250px;
width: 479px;
top: 30%;
left: 31%;
display: block;
z-index: 10002;
}

.labelCss {
padding-right: 50px;
font-size: 11px;
font-size: 12px;
color: #084d7d;
text-align: right;
font-weight: 500;
}

</style>


<script type="text/javascript">

function ShowPopUp()
{
$("#frgPass").fadeIn("slow");
$("#frgPass").addClass("csspopupClass");
$("#popupshadow").fadeIn("slow");
}


function ShowPopUpPassword()
{
$("#setNewPass").fadeIn("slow");
$("#setNewPass").addClass("csspopupClass");
$("#popupshadow").fadeIn("slow");
}


function CloseDialog()
{
$(".lblErrorForgetPassword").css("display", "none");
$("#txtUserId").val("");
$("#txtUserEmail").val("");
$("#txtSecurityAnswer").val("");
$("#txtNewPassword").val("");
$("#txtConfirmPassword").val("");
$("#frgPass").fadeOut();
$("#setNewPass").fadeOut();
$("#popupshadow").fadeOut();
}


$(document).ready(function () {

$("#lblUserIdError").hide();

if ('' == '0')
$('input#Password').gips({ 'theme': 'red', placement: 'right', text: 'Your account has been locked out because you have exceeded the maximum number of login attempts. You will NOT be able to login until you contact a site administrator and have your account unlocked.', autohide: false });
else
if ('' != '')
$('input#Password').gips({ 'theme': 'red', placement: 'right', text: 'You have only attempts left. After 3 failed login attempts, your account will be locked.', autohide: false });




$("#btnSendOtp").click(function () {
debugger;
var UserCode = $("#txtUserCode").val();
var UserPhone = $("#txtUserPhone").val();

if (UserCode != null && UserCode.trim() !== "" && UserPhone != null && UserPhone.trim() !== "")
{
$.ajax({
type: 'GET',
url: '/User/CheckUserExists',
data: { UserCode: UserCode, UserPhone: UserPhone },
success: function (data) {
debugger;
if (data == true) {

$.ajax({
type: 'GET',
url: '/User/GenerateOTPForPasswordReset',
data: { UserCode: UserCode, UserPhone: UserPhone },
success: function (otpResult) {
debugger;
if (otpResult === "1")
{
alert("OTP sent to the registered phone number.");
$("#txtValidateOTP").attr("disabled", false);
}
else if (otpResult === "2")
{
alert("An unused OTP is still valid. Please use that.");
$("#txtValidateOTP").attr("disabled", false);
}
else
{
alert("Failed to send OTP. Please try again.");
}
},
error: function (xhr, status, error) {
console.log("Error sending OTP:", error);
}
});
}
else {
alert("No records found with given credentials.");
return false;
}
},
error: function (xhr, status, error) {
console.log("Error verifying user:", error);
}

});
}
});



$("#btnValidateOtp").click(function () {
debugger;

var OTP = $("#txtValidateOTP").val();

$.ajax({
type: 'GET',
url: '/User/ValidateOTPForPasswordReset',
data: { OTP: OTP },
success: function (result) {
debugger;
if (result === "1") {
$("#frgPass").fadeOut();
$("#popupshadow").fadeOut();
ShowPopUpPassword();
}
else {
alert("Invalid OTP. Please enter the correct OTP sent to the registered Phone No.")
}
},
error: function (xhr, status, error) {
console.log("Error while Validating OTP:", error);
}
});
});



$("#btnSavePassword").click(function () {
debugger;

var Password = $("#txtNewPassword").val();
var ConfirmPassword = $("#txtConfirmPassword").val();
var UserCode = $("#txtUserCode").val();

if(Password == ConfirmPassword)
{
$.ajax({
type: 'POST',
url: '/User/UpdatePassword',
data: { Password: Password, UserCode: UserCode },
success: function (data) {
debugger;
if(data === 1)
{
alert("Your new password has been updated successfully.");
CloseDialog();
}
else {
alert("An error was faced while saving your password. Please try again.");
}
},
error: function(xhr, status, error)
{
console.log("Error while saving password: ", error);
}
});
}
else {
alert("Please ensure that both the passwords are same.")
return false;
}
});



$("#btnForgotpassword").click(function () {

ShowPopUp();
});


});

</script>



<div class="lightBoxContainer" id="frgPass" style="display:none">

<div class="lightBoxHeader">
Reset Password

<div class="lightboxclose1"><img src="/Areas/Aiveares/Content/images/closeIcon.png" onclick="CloseDialog()" alt="" /></div>
</div>

<div class="LightBoxContent" style="height:170px !important; min-height:170px !important;">
<table>
<tr>
<td>
<span class="labelCss">UserCode : </span>
</td>
<td><input id="txtUserCode" class="textboxStyle" type="text" onpaste="return false;" /></td>
<td><span id="lblUserCodeError" style="display:none; color:red"></span></td>
</tr>

<tr>
<td>
<span class="labelCss">Registered Phone No. : </span>
</td>
<td><input id="txtUserPhone" class="textboxStyle" type="text" onpaste="return false;" /></td>
<td><span id="lblUserPhoneError" style="display:none; color:red"></span></td>
</tr>
</table>

<div class="bodyContentBoxFooter" style="background-image: none;">
<table border="0" cellpadding="0" cellspacing="5">
<tr>
<td>
<input type="button" id="btnSendOtp" style="float:right; margin-right:230%; min-width:150% !important" value="Send OTP" class="blueButtonStyle">
</td>
</tr>
</table>
</div>

<table>
<tr>
<td><input id="txtValidateOTP" class="textboxStyle" style="margin-right:120px; margin-top:20px;" type="text" placeholder="Enter OTP" onpaste="return false;" disabled="disabled" /></td>

<td>
<input type="button" id="btnValidateOtp" value="Validate OTP" class="blueButtonStyle" style="margin-top: 20px; float:right; margin-right:23%; min-width:123% !important" />
</td>
</tr>
</table>

</div>

</div>


<div class="lightBoxContainer" id="setNewPass" style="display:none; height:210px !important">

<div class="lightBoxHeader">
Set New Password
<div class="lightboxclose1"><img src="/Areas/Aiveares/Content/images/closeIcon.png" onclick="CloseDialog()" alt="" /></div>
</div>

<div class="LightBoxContent" style="height:130px !important; min-height:130px !important;">
<table>
<tr>
<td><span class="labelCss">Enter Password :</span></td>
<td><input id="txtNewPassword" class="textboxStyle" type="password" /></td>
<td><span id="lblNewPasswordError" style="display:none; color:red;"></span></td>
</tr>
<tr>
<td><span class="labelCss">Confirm Password :</span></td>
<td><input id="txtConfirmPassword" class="textboxStyle" type="password" /></td>
<td><span id="lblConfirmPasswordError" style="display:none; color:red;"></span></td>
</tr>
</table>

<div class="bodyContentBoxFooter" style="background-image: none; margin-top: 15px;">
<table border="0" cellpadding="0" cellspacing="5">
<tr>
<td>
<input type="button" id="btnSavePassword" value="Save Password" class="blueButtonStyle" style="float:right; margin-right:145%; min-width:125% !important" />
</td>
</tr>
</table>
</div>
</div>

</div>


<style>
.cssChppopupClass {
position: absolute;
height: auto;
width: 479px;
top: 16%;
left: 31%;
display: block;
z-index: 10002;
}

.LabelChpCss {
font-size: 12px;
color: #084d7d;
/* text-align: right; */
font-weight: 500;
font-family: Verdana, Geneva, sans-serif;
}
</style>

<div class="lightBoxContainer" id="UserKillSessionPopup" style="display:none;">
<div class="lightBoxHeader">
Kill session
</div>
<div class="LightBoxContent">
<div id="pop_securityquestion">
<table style="width:386px;max-height:120px">
<tr>
<td>
<span class="" style="color: Red"></span>
</td>
</tr>
<tr>
<td>
<span class="LabelCss">Do you want kill this session?</span>
</td>
</tr>
</table>
<div class="bodyContentBoxFooter" style=" background-image: none; margin-top: 25px;">
<table width="20%" border="0" cellpadding="0" cellspacing="5">
<tr>
<td>
<input type="button" class="blueButtonStyle" id="btn_killSession" value="Kill Session" style="float:right" />
</td>
<td>
<input type="button" class="blueButtonStyle" id="btn_SessionCancel" value="Cancel" style="float:right" />
</td>
</tr>
</table>
</div>
</div>
</div>
</div>



<div class="lightBoxContainer" id="FirstTimeShowWarningPopup" style="display:none;">
<div class="lightBoxHeader">
Access Warning !
</div>

<div class="LightBoxContent">
<div id="pop_securityquestion">

<table style="width: 450px; max-height: 120px; font-size:11px;">
<tr>
<td>
<p>
This site, its network and data contained therein is the property of the Call Balance Ltd.
Access to this site and network is restricted to Persons and Programs authorized by the Group only.
Access by others is prohibited and unauthorized, and is wrongful under the law.
Do not proceed if you are not authorized. Any unauthorized access will be prosecuted to the fullest extent of the law.
</p>
</td>
</tr>
</table>



<div class="bodyContentBoxFooter" style=" background-image: none; margin-top: 1px;">
<table width="20%" border="0" cellpadding="0" cellspacing="5">
<tr>
<td>
<input type="button" class="blueButtonStyle" id="btn_WarningPopupCancel" value="OK" style="float:right" />
</td>
</tr>
</table>
</div>
</div>
</div>
</div>


<div class="ui-widget-overlay" id="popupChpshadow" style="width: 100%; display:none; background: #000; height: 100%; z-index: 10001 !important;"></div>

<script type="text/javascript">

function ShowPopupUserKillSession() {
$("#UserKillSessionPopup").css("background-color", "#000");
$("#UserKillSessionPopup").fadeIn("slow");

$("#UserKillSessionPopup").addClass("cssChppopupClass");

$(".LightBoxContent").css("min-height", "50%");

$("#popupChpshadow").fadeIn("slow");
}

$("#btn_killSession").click(function () {
$("#UserKillSessionPopup").fadeOut();
$("#popupshadow").fadeOut();
$("#logoutForm").submit();
})

$("#btn_SessionCancel").click(function () {
$("#UserKillSessionPopup").fadeOut();
$("#popupChpshadow").fadeOut();

// $("#logoutForm").submit();
});
// Warning Popup

function ShowWarningPopupLoginPage() {
$("#FirstTimeShowWarningPopup").css("background-color", "#000");
$("#FirstTimeShowWarningPopup").fadeIn("slow");

$("#FirstTimeShowWarningPopup").addClass("cssChppopupClass");

$(".LightBoxContent").css("min-height", "50%");

$("#popupChpshadow").fadeIn("slow");
}
$("#btn_WarningPopupCancel").click(function () {
$("#FirstTimeShowWarningPopup").fadeOut();
$("#popupChpshadow").fadeOut();
});
</script>


</div>
<div>&nbsp;</div>
</div>



<div class="login_footer">
<img src="/Images/footerbg1.png" width="100%" height="44" alt="" />
<div class="copy_right_Txt" style="margin:0px;position: absolute;display: inline-block;top: -32px;left: 61px;">© 2017. All Rights Reserved. Developed by Nexsus Techo Solutions Pvt. Ltd.</div>
</div>
<div class="lightBoxContainer" id="ChangePassword" style="display:none">


<div class="lightBoxHeader">
Change Password
<!--<span class="lightboxclose"><a href="#"><img src="images/cross-button.png" alt=""></a></span>-->
<!--for Square Close Button-->
<!--for Circle Close Button-->
</div>
<div class="ui-widget-overlay" id="popupshadow" style="width: 100%; display:none; background: #000; z-index: 10000;"></div>
</div>

<div>
<form action="/User/LogOff" id="logoutForm" method="post"><input name="__RequestVerificationToken" type="hidden" value="7bqXmUBfCVbw17nXugzffCtTbl1xGLcaMWbGD78m6NhP2sWbKuGe0_elztWE_2OCnQmc5nDrFev2Q2k9CEV_rj1esUTTK6Gk_m1VgaIutJA1" /></form> </div>

</body>
</html>



















<!--LoginBoxBottom Div-->
<!--LoginBox Div-->







<!--MainCintainer Div-->

<!--<span class="lightboxclose"><a href="#"><img src="images/cross-button.png" alt=""></a></span>-->
<!--for Square Close Button-->
<!--for Circle Close Button-->























24260 - HyperText Transfer Protocol (HTTP) Information
-
Synopsis
Some information about the remote HTTP configuration can be extracted.
Description
This test gives some information about the remote HTTP protocol - the version used, whether HTTP Keep-Alive is enabled, etc...

This test is informational only and does not denote any security problem.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/01/30, Modified: 2024/02/26
Plugin Output

tcp/9505/www


Response Code : HTTP/1.1 404 Not Found

Protocol version : HTTP/1.1
HTTP/2 TLS Support: No
HTTP/2 Cleartext Support: No
SSL : no
Keep-Alive : no
Options allowed : (Not implemented)
Headers :

Content-Length: 0
Server: Microsoft-HTTPAPI/2.0
Date: Sat, 24 Jan 2026 06:56:07 GMT

Response Body :

24260 - HyperText Transfer Protocol (HTTP) Information
-
Synopsis
Some information about the remote HTTP configuration can be extracted.
Description
This test gives some information about the remote HTTP protocol - the version used, whether HTTP Keep-Alive is enabled, etc...

This test is informational only and does not denote any security problem.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/01/30, Modified: 2024/02/26
Plugin Output

tcp/47001/www


Response Code : HTTP/1.1 404 Not Found

Protocol version : HTTP/1.1
HTTP/2 TLS Support: No
HTTP/2 Cleartext Support: No
SSL : no
Keep-Alive : no
Options allowed : (Not implemented)
Headers :

Content-Type: text/html; charset=us-ascii
Server: Microsoft-HTTPAPI/2.0
Date: Sat, 24 Jan 2026 06:56:07 GMT
Connection: close
Content-Length: 315

Response Body :

171410 - IP Assignment Method Detection
-
Synopsis
Enumerates the IP address assignment method(static/dynamic).
Description
Enumerates the IP address assignment method(static/dynamic).
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/02/14, Modified: 2025/12/15
Plugin Output

tcp/0

+ Loopback Pseudo-Interface 1
+ IPv4
- Address : 127.0.0.1
Assign Method : static
+ IPv6
- Address : ::1
Assign Method : static
+ LAN
+ IPv4
- Address : 172.17.100.140
Assign Method : static
+ SIP
+ IPv4
- Address : 10.54.158.102
Assign Method : static

179947 - Intel CPUID detection
-
Synopsis
The processor CPUID was detected on the remote host.
Description
The CPUID of the Intel processor was detected on the remote host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/08/18, Modified: 2025/12/15
Plugin Output

tcp/135/epmap

Nessus was able to extract the following cpuid: C06F2

92421 - Internet Explorer Typed URLs
-
Synopsis
Nessus was able to enumerate URLs that were manually typed into the Internet Explorer address bar.
Description
Nessus was able to generate a list URLs that were manually typed into the Internet Explorer address bar.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2024/05/08
Plugin Output

tcp/0

http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://172.17.100.140:8001/User/Login
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://172.17.100.140:8086/sso
http://172.17.100.140:8086/
http://172.17.100.140:8001/

Internet Explorer typed URL report attached.

106658 - JQuery Detection
-
Synopsis
The web server on the remote host uses JQuery.
Description
Nessus was able to detect JQuery on the remote host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2018/02/07, Modified: 2024/02/08
Plugin Output

tcp/8001/www


Nessus detected 2 installs of jquery:

URL : http://172.17.100.140:8001/Scripts/jquery-1.4.4.min.js
Version : 1.4.4

URL : http://172.17.100.140:8001/Scripts_SSO/jquery-3.3.1.js
Version : 3.3.1

106658 - JQuery Detection
-
Synopsis
The web server on the remote host uses JQuery.
Description
Nessus was able to detect JQuery on the remote host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2018/02/07, Modified: 2024/02/08
Plugin Output

tcp/8002/www


Nessus detected 2 installs of jquery:

URL : https://172.17.100.140:8002/Scripts/jquery-1.4.4.min.js
Version : 1.4.4

URL : https://172.17.100.140:8002/Scripts_SSO/jquery-3.3.1.js
Version : 3.3.1

53513 - Link-Local Multicast Name Resolution (LLMNR) Detection
-
Synopsis
The remote device supports LLMNR.
Description
The remote device answered to a Link-local Multicast Name Resolution (LLMNR) request. This protocol provides a name lookup service similar to NetBIOS or DNS. It is enabled by default on modern Windows versions.
See Also
Solution
Make sure that use of this software conforms to your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2011/04/21, Modified: 2023/10/17
Plugin Output

udp/5355/llmnr


According to LLMNR, the name of the remote host is 'LKP_SIP_AppSrv-140'.

160301 - Link-Local Multicast Name Resolution (LLMNR) Service Detection
-
Synopsis
Verify status of the LLMNR service on the remote host.
Description
The Link-Local Multicast Name Resolution (LLMNR) service allows both IPv4 and IPv6 hosts to perform name resolution for hosts on the same local link
See Also
Solution
Make sure that use of this software conforms to your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2022/04/28, Modified: 2022/12/29
Plugin Output

tcp/445/cifs


LLMNR Key SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast not found.

92424 - MUICache Program Execution History
-
Synopsis
Nessus was able to enumerate recently executed programs on the remote host.
Description
Nessus was able to query the MUIcache registry key to find evidence of program execution.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/16
Plugin Output

tcp/0

@%systemroot%\system32\ngcrecovery.dll,-100 : Windows Hello Recovery Key Encryption
@%systemroot%\system32\windowspowershell\v1.0\powershell.exe,-124 : Document Encryption
@%systemroot%\system32\wuaueng.dll,-400 : Windows Update
@%systemroot%\system32\dnsapi.dll,-103 : Domain Name System (DNS) Server Trust
@%systemroot%\system32\ci.dll,-100 : Isolated User Mode (IUM)
@%systemroot%\system32\ci.dll,-101 : Enclave
@%systemroot%\system32\firewallapi.dll,-38527 : Web Management Service (HTTP)
@%systemroot%\system32\winhttp.dll,-100 : WinHTTP Web Proxy Auto-Discovery Service
@%systemroot%\system32\themeservice.dll,-8192 : Themes
@%systemroot%\system32\firewallapi.dll,-3400 : COM+ Network Access
@%windir%\system32\inetsrv\iisres.dll,-20001 : Web Management Service
@%systemroot%\system32\mprmsg.dll,-32011 : Remote Access IP ARP Driver
@%systemroot%\system32\tabsvc.dll,-100 : Touch Keyboard and Handwriting Panel Service
@%systemroot%\system32\windows.devices.picker.dll,-1006 : DevicePicker
@%systemroot%\system32\bfe.dll,-1002 : The Base Filtering Engine (BFE) is a service that manages firewall and Internet Protocol security (IPsec) policies and implements user mode filtering. Stopping or disabling the BFE service will significantly reduce the security of the system. It will also result in unpredictable behavior in IPsec management and firewall applications.
@%systemroot%\system32\icsvc.dll,-201 : Hyper-V Data Exchange Service
c:\windows\system32,@elscore.dll,-8 : Microsoft Malayalam to Latin Transliteration
@%systemroot%\system32\devicesflowbroker.dll,-103 : DevicesFlow
@c:\windows\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8198 : Receives activation requests over the net.tcp protocol and passes them to the Windows Process Activation Service.
@%systemroot%\system32\msimsg.dll,-27 : Windows Installer
@%systemroot%\system32\rmapi.dll,-1001 : Radio Management Service
@%systemroot%\system32\drivers\winnat.sys,-10001 : Windows NAT Driver
@%systemroot%\system32\drivers\afd.sys,-1000 : Ancillary Function Driver for Winsock
@%windir%\system32\inetsrv\iisres.dll,-20002 : The Web Management Service enables remote and delegated management capabilities for administrators to manage for the Web server, sites and applications present on this machine.
@%systemroot%\system32\userdataaccessres.dll,-14000 : Provides apps access to structured user data, including contact info, calendars, messages, and other content. If you stop or disable this service, apps that use this data might not work correctly.
@regsvc.dll,-1 : Remote Registry
@%systemroot%\system32\das.dll,-100 : Device Association Service
@%systemroot%\system32\tieringengineservice.exe,-701 : Optimizes the placement of data in storage tiers on all tiered storage spaces in the system.
@%systemroot%\system32\drivers\tunnel.sys,-500 : Microsoft Tunnel Miniport Adapter Driver
@%systemroot%\system32\vssvc.exe,-102 : Volume Shadow Copy
@%systemroot%\system32\wephostsvc.dll,-100 : Windows Encryption Provider Host Service
@%systemroot%\system32\devquerybroker.dll,-100 : DevQuery Background Discovery Broker
@%systemroot%\system32\drivers\ehstorclass.sys,-100 : Enhanced Storage Filter Driver
@%systemroot%\system32\cscsvc.dll,-201 : The Offline Files service performs maintenance activities on the Offline Files cache, responds to user logon and logoff events, implements the internals of the public API, and dispatches interesting events to those interested in Offline Files activities and changes in cache state.
@%systemroot%\system32\appinfo.dll,-100 : Application Information
@%systemroot%\system32\drivers\tsusbflt.sys,-1000 : Remote Desktop USB Hub Class Filter Driver
@%systemroot%\system32\wevtsvc.dll,-201 : This service manages events and event logs. It supports logging events, querying events, subscribing to events, archiving event logs, and managing event metadata. It can display events in both XML and plain text format. Stopping this service may compromise security and reliability of the system.
@%systemroot%\system32\sysmain.dll,-1001 : Maintains and improves system performance over time.
@%systemroot%\system32\locator.exe,-2 : Remote Procedure Call (RPC) Locator
@%systemroot%\system32\wecsvc.dll,-201 : This service manages persistent subscriptions to events from remote sources that support WS-Management protocol. This includes Windows Vista event logs, hardware and IPMI-enabled event sources. The service stores forwarded events in a local Event Log. If this service is stopped or disabled event subscriptions cannot be created and forwarded events cannot be accepted.
@%systemroot%\system32\srvsvc.dll,-101 : Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\dnsapi.dll,-101 : DNS Client
@%systemroot%\system32\frameserver.dll,-100 : Windows Camera Frame Server
@%systemroot%\system32\wcmsvc.dll,-4098 : Makes automatic connect/disconnect decisions based on the network connectivity options currently available to the PC and enables management of network connectivity based on Group Policy settings.
@%systemroot%\system32\btagservice.dll,-102 : Service supporting the audio gateway role of the Bluetooth Handsfree Profile.
@%systemroot%\system32\phoneserviceres.dll,-10000 : Phone Service
@%systemroot%\system32\wkssvc.dll,-2001 : Browser
@comres.dll,-2947 : Coordinates transactions between the Distributed Transaction Coordinator (MSDTC) and the Kernel Transaction Manager (KTM). If it is not needed, it is recommended that this service remain stopped. If it is needed, both MSDTC and KTM will start this service automatically. If this service is disabled, any MSDTC transaction interacting with a Kernel Resource Manager will fail and any services that explicitly depend on it will fail to start.
@%windir%\system32\rpcepmap.dll,-1002 : Resolves RPC interfaces identifiers to transport endpoints. If this service is stopped or disabled, programs using Remote Procedure Call (RPC) services will not function properly.
@%systemroot%\system32\firewallapi.dll,-3405 : COM+ Remote Administration
@%systemroot%\system32\locator.exe,-3 : In Windows 2003 and earlier versions of Windows, the Remote Procedure Call (RPC) Locator service manages the RPC name service database. In Windows Vista and later versions of Windows, this service does not provide any functionality and is present for application compatibility.
@%systemroot%\system32\fdrespub.dll,-101 : Publishes this computer and resources attached to this computer so they can be discovered over the network. If this service is stopped, network resources will no longer be published and they will not be discovered by other computers on the network.
@%systemroot%\system32\drivers\appvvfs.sys,-101 : AppvVfs
@%windir%\system32\systemeventsbrokerserver.dll,-1001 : System Events Broker
@combase.dll,-5010 : Remote Procedure Call (RPC)
@%systemroot%\system32\wbiosrvc.dll,-101 : The Windows biometric service gives client applications the ability to capture, compare, manipulate, and store biometric data without gaining direct access to any biometric hardware or samples. The service is hosted in a privileged SVCHOST process.
@%systemroot%\system32\qwave.dll,-2 : Quality Windows Audio Video Experience (qWave) is a networking platform for Audio Video (AV) streaming applications on IP home networks. qWave enhances AV streaming performance and reliability by ensuring network quality-of-service (QoS) for AV applications. It provides mechanisms for admission control, run time monitoring and enforcement, application feedback, and traffic prioritization.
@%systemroot%\system32\drivers\ndisimplatform.sys,-501 : Microsoft Network Adapter Multiplexor Protocol
@%systemroot%\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8196 : Receives activation requests over the net.pipe protocol and passes them to the Windows Process Activation Service.
@%systemroot%\system32\drivers\mpsdrv.sys,-23092 : Windows Defender Firewall Authorization Driver
@%systemroot%\system32\printworkflowservice.dll,-100 : PrintWorkflow
@%windir%\system32\inetsrv\iisres.dll,-30015 : Provides W3C logging for Internet Information Services (IIS). If this service is stopped, W3C logging configured by IIS will not work.
@%systemroot%\system32\appvclient.exe,-102 : Microsoft App-V Client
@%systemroot%\system32\drivers\mslbfoprovider.sys,-501 : Microsoft Load Balancing/Failover Provider
@%systemroot%\system32\hnetcfgclient.dll,-201 : HNetCfg Client
@%systemroot%\system32\umpo.dll,-101 : Manages power policy and power policy notification delivery.
@%programfiles%\windows defender\mpasdesc.dll,-330 : Windows Defender Antivirus Mini-Filter Driver
@fssmres.dll,-100 : File Server Remote Management
@%systemroot%\system32\sensorservice.dll,-1000 : Sensor Service
@combase.dll,-5011 : The RPCSS service is the Service Control Manager for COM and DCOM servers. It performs object activations requests, object exporter resolutions and distributed garbage collection for COM and DCOM servers. If this service is stopped or disabled, programs using COM or DCOM will not function properly. It is strongly recommended that you have the RPCSS service running.
@%systemroot%\syswow64\perfhost.exe,-2 : Performance Counter DLL Host
@%systemroot%\system32\upnphost.dll,-214 : Allows UPnP devices to be hosted on this computer. If this service is stopped, any hosted UPnP devices will stop functioning and no additional hosted devices can be added. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\lfsvc.dll,-2 : This service monitors the current location of the system and manages geofences (a geographical location with associated events). If you turn off this service, applications will be unable to use or receive notifications for geolocation or geofences.
@%systemroot%\system32\storsvc.dll,-100 : Storage Service
@%systemroot%\system32\drivers\mslldp.sys,-211 : Microsoft LLDP Protocol Driver
@%systemroot%\system32\dssvc.dll,-10003 : Data Sharing Service
@%systemroot%\system32\svsvc.dll,-102 : Verifies potential file system corruptions.
@%systemroot%\system32\sgrmbroker.exe,-101 : Monitors and attests to the integrity of the Windows platform.
@%systemroot%\system32\polstore.dll,-5010 : IPsec Policy Agent
@%systemroot%\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8201 : Net.Tcp Port Sharing Service
@%windir%\system32\inetsrv\iisres.dll,-30011 : Application Host Helper Service
@%systemroot%\system32\printworkflowservice.dll,-101 : Print Workflow
@peerdistsh.dll,-9002 : BranchCache - Hosted Cache Server (Uses HTTPS)
@%systemroot%\system32\lmhsvc.dll,-101 : TCP/IP NetBIOS Helper
@%systemroot%\system32\mprmsg.dll,-32012 : Remote Access IPv6 ARP Driver
@%systemroot%\system32\cdpsvc.dll,-100 : Connected Devices Platform Service
@%systemroot%\system32\defragsvc.dll,-102 : Helps the computer run more efficiently by optimizing files on storage drives.
@%systemroot%\system32\sppsvc.exe,-100 : Enables the download, installation and enforcement of digital licenses for Windows and Windows applications. If the service is disabled, the operating system and licensed applications may run in a notification mode. It is strongly recommended that you not disable the Software Protection service.
@gpapi.dll,-113 : The service is responsible for applying settings configured by administrators for the computer and users through the Group Policy component. If the service is disabled, the settings will not be applied and applications and components will not be manageable through Group Policy. Any components or applications that depend on the Group Policy component might not be functional if the service is disabled.
@%windir%\system32\bisrv.dll,-101 : Windows infrastructure service that controls which background tasks can run on the system.
@%systemroot%\system32\polstore.dll,-5011 : Internet Protocol security (IPsec) supports network-level peer authentication, data origin authentication, data integrity, data confidentiality (encryption), and replay protection. This service enforces IPsec policies created through the IP Security Policies snap-in or the command-line tool ""netsh ipsec"". If you stop this service, you may experience network connectivity issues if your policy requires that connections use IPsec. Also,remote management of Windows Defender Firewall is not available when this service is stopped.
@%programfiles%\windows media player\wmpnetwk.exe,-101 : Windows Media Player Network Sharing Service
@%systemroot%\system32\tapisrv.dll,-10100 : Telephony
@%systemroot%\system32\wephostsvc.dll,-101 : Windows Encryption Provider Host Service brokers encryption related functionalities from 3rd Party Encryption Providers to processes that need to evaluate and apply EAS policies. Stopping this will compromise EAS compliancy checks that have been established by the connected Mail Accounts
@%systemroot%\system32\themeservice.dll,-8193 : Provides user experience theme management.
@%systemroot%\system32\firewallapi.dll,-38521 : World Wide Web Services (HTTP)
@%systemroot%\system32\dosvc.dll,-100 : Delivery Optimization
@%systemroot%\system32\wkssvc.dll,-1000 : Redirected Buffering Sub System
@%systemroot%\system32\ngcsvc.dll,-101 : Provides process isolation for cryptographic keys used to authenticate to a user’s associated identity providers. If this service is disabled, all uses and management of these keys will not be available, which includes machine logon and single-sign on for apps and websites. This service starts and stops automatically. It is recommended that you do not reconfigure this service.
@%systemroot%\system32\eapsvc.dll,-1 : Extensible Authentication Protocol
@%systemroot%\system32\cdpusersvc.dll,-100 : Connected Devices Platform User Service
@gpapi.dll,-115 : Provides a network service that processes requests to simulate application of Group Policy settings for a target user or computer in various situations and computes the Resultant Set of Policy settings.
@%systemroot%\system32\sensordataservice.exe,-102 : Delivers data from a variety of sensors
@peerdistsh.dll,-9001 : BranchCache - Peer Discovery (Uses WSD)
@%systemroot%\system32\bridgeres.dll,-1 : Microsoft MAC Bridge
@%windir%\system32\drivers\pacer.sys,-100 : Quality of Service Packet Scheduler. This component provides network traffic control, including rate-of-flow and prioritization services.
@%systemroot%\system32\hvhostsvc.dll,-101 : Provides an interface for the Hyper-V hypervisor to provide per-partition performance counters to the host operating system.
@%systemroot%\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8195 : Net.Msmq Listener Adapter
@%systemroot%\microsoft.net\framework64\v4.0.30319\aspnet_rc.dll,-1 : ASP.NET State Service
@%systemroot%\system32\tapisrv.dll,-10101 : Provides Telephony API (TAPI) support for programs that control telephony devices on the local computer and, through the LAN, on servers that are also running the service.
@%systemroot%\system32\ngcctnrsvc.dll,-2 : Manages local user identity keys used to authenticate user to identity providers as well as TPM virtual smart cards. If this service is disabled, local user identity keys and TPM virtual smart cards will not be accessible. It is recommended that you do not reconfigure this service.
@%windir%\system32\lsm.dll,-1002 : Core Windows Service that manages local user sessions. Stopping or disabling this service will result in system instability.
@%windir%\system32\inetsrv\iisres.dll,-30012 : Provides administrative services for IIS, for example configuration history and Application Pool account mapping. If this service is stopped, configuration history and locking down files or directories with Application Pool specific Access Control Entries will not work.
@peerdistsh.dll,-9000 : BranchCache - Content Retrieval (Uses HTTP)
@c:\windows\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8199 : Net.Tcp Listener Adapter
@%systemroot%\system32\smphost.dll,-102 : Microsoft Storage Spaces SMP
@%systemroot%\system32\appreadiness.dll,-1001 : Gets apps ready for use the first time a user signs in to this PC and when adding new apps.
@netlogon.dll,-1010 : Netlogon Service
@%systemroot%\system32\lltdres.dll,-1 : Link-Layer Topology Discovery Mapper
@%systemroot%\system32\drivers\fileinfo.sys,-100 : File Information FS MiniFilter
@%systemroot%\system32\schedsvc.dll,-100 : Task Scheduler
@gpapi.dll,-114 : Resultant Set of Policy Provider
@%systemroot%\system32\diagsvcs\diagnosticshub.standardcollector.serviceres.dll,-1000 : Microsoft (R) Diagnostics Hub Standard Collector Service
@%systemroot%\system32\drivers\clfs.sys,-100 : Common Log (CLFS)
@%systemroot%\system32\sppsvc.exe,-101 : Software Protection
@%systemroot%\system32\drivers\wfplwfs.sys,-6000 : Microsoft Windows Filtering Platform
@%systemroot%\system32\fdphost.dll,-101 : The FDPHOST service hosts the Function Discovery (FD) network discovery providers. These FD providers supply network discovery services for the Simple Services Discovery Protocol (SSDP) and Web Services – Discovery (WS-D) protocol. Stopping or disabling the FDPHOST service will disable network discovery for these protocols when using FD. When this service is unavailable, network services using FD and relying on these discovery protocols will be unable to find network devices or resources.
@%systemroot%\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8194 : Receives activation requests over the net.msmq and msmq.formatname protocols and passes them to the Windows Process Activation Service.
@keyiso.dll,-101 : The CNG key isolation service is hosted in the LSA process. The service provides key process isolation to private keys and associated cryptographic operations as required by the Common Criteria. The service stores and uses long-lived keys in a secure process complying with Common Criteria requirements.
@%windir%\system32\timebrokerserver.dll,-1001 : Time Broker
@%systemroot%\system32\nsisvc.dll,-200 : Network Store Interface Service
@%systemroot%\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8197 : Net.Pipe Listener Adapter
@appmgmts.dll,-3251 : Processes installation, removal, and enumeration requests for software deployed through Group Policy. If the service is disabled, users will be unable to install, remove, or enumerate software deployed through Group Policy. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\pushtoinstall.dll,-200 : Windows PushToInstall Service
@%systemroot%\system32\drivers\cnghwassist.sys,-100 : CNG Hardware Assist algorithm provider
@%systemroot%\system32\tokenbroker.dll,-100 : Web Account Manager
@%systemroot%\system32\spoolsv.exe,-2 : This service spools print jobs and handles interaction with the printer. If you turn off this service, you won’t be able to print or see your printers.
@%systemroot%\system32\icsvc.dll,-301 : Hyper-V Guest Shutdown Service
@%systemroot%\system32\defragsvc.dll,-101 : Optimize drives
@%systemroot%\system32\axinstsv.dll,-103 : ActiveX Installer (AxInstSV)
@%systemroot%\system32\drivers\indirectkmd.sys,-100 : Indirect Displays Kernel-Mode Driver
@%systemroot%\system32\windowspowershell\v1.0\powershell.exe,-124 : Document Encryption
@%systemroot%\system32\hvhostsvc.dll,-100 : HV Host Service
@%systemroot%\system32\capabilityaccessmanager.dll,-2 : Provides facilities for managing UWP apps access to app capabilities as well as checking an app's access to specific app capabilities
@%systemroot%\system32\sgrmbroker.exe,-100 : System Guard Runtime Monitor Broker
@%systemroot%\system32\windows.internal.management.dll,-100 : Device Management Enrollment Service
@%systemroot%\system32\icsvc.dll,-902 : Provides a mechanism to manage virtual machine with PowerShell via VM session without a virtual network.
@%systemroot%\system32\srpapi.dll,-102 : Smartlocker Filter Driver
@%systemroot%\system32\ncasvc.dll,-3008 : Provides DirectAccess status notification for UI components
@%systemroot%\system32\pcasvc.dll,-1 : Program Compatibility Assistant Service
@%systemroot%\system32\wiaservc.dll,-9 : Windows Image Acquisition (WIA)
@%systemroot%\system32\drivers\appvvemgr.sys,-101 : AppvVemgr
@%systemroot%\system32\icsvc.dll,-801 : Hyper-V Guest Service Interface
@%systemroot%\system32\netman.dll,-109 : Network Connections
@mqutil.dll,-6104 : Provides a messaging infrastructure and development tool for creating distributed messaging applications for Windows-based networks and programs. If this service is stopped, distributed messages will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\scdeviceenum.dll,-100 : Smart Card Device Enumeration Service
c:\windows\system32,@elscore.dll,-7 : Microsoft Devanagari to Latin Transliteration
@%systemroot%\system32\drivers\volmgrx.sys,-100 : Dynamic Volume Manager
@%systemroot%\system32\fdrespub.dll,-100 : Function Discovery Resource Publication
@comres.dll,-2451 : Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\nlasvc.dll,-2 : Collects and stores configuration information for the network and notifies programs when this information is modified. If this service is stopped, configuration information might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\ncasvc.dll,-3009 : Network Connectivity Assistant
@%systemroot%\system32\mprmsg.dll,-32002 : Remote Access NDIS WAN Driver
@%systemroot%\system32\rmapi.dll,-1002 : Radio Management and Airplane Mode Service
c:\windows\system32,@elscore.dll,-3 : Microsoft Traditional Chinese to Simplified Chinese Transliteration
@%systemroot%\system32\alg.exe,-113 : Provides support for 3rd party protocol plug-ins for Internet Connection Sharing
@%systemroot%\system32\das.dll,-101 : Enables pairing between the system and wired or wireless devices.
@%systemroot%\system32\samsrv.dll,-2 : The startup of this service signals other services that the Security Accounts Manager (SAM) is ready to accept requests. Disabling this service will prevent other services in the system from being notified when the SAM is ready, which may in turn cause those services to fail to start correctly. This service should not be disabled.
@%systemroot%\system32\audiosrv.dll,-200 : Windows Audio
@keyiso.dll,-100 : CNG Key Isolation
@%systemroot%\system32\umrdp.dll,-1000 : Remote Desktop Services UserMode Port Redirector
@%systemroot%\system32\powrprof.dll,-15 : Balanced
@%systemroot%\system32\wpdbusenum.dll,-101 : Enforces group policy for removable mass-storage devices. Enables applications such as Windows Media Player and Image Import Wizard to transfer and synchronize content using removable mass-storage devices.
@%systemroot%\system32\termsrv.dll,-268 : Remote Desktop Services
@%systemroot%\system32\samsrv.dll,-1 : Security Accounts Manager
@%systemroot%\system32\ipnathlp.dll,-106 : Internet Connection Sharing (ICS)
@%systemroot%\system32\semgrsvc.dll,-1001 : Payments and NFC/SE Manager
@%systemroot%\system32\srvsvc.dll,-110 : Allows other computers to access resources on your computer using a Microsoft network.
@%systemroot%\system32\ci.dll,-101 : Enclave
@%systemroot%\system32\powrprof.dll,-13 : High performance
@%systemroot%\system32\usermgr.dll,-101 : User Manager provides the runtime components required for multi-user interaction. If this service is stopped, some applications may not operate correctly.
@%systemroot%\microsoft.net\framework64\v4.0.30319\servicemodelevents.dll,-2002 : Windows Communication Foundation
@%systemroot%\system32\drivers\hvservice.sys,-16 : Hypervisor/Virtual Machine Support Driver
@%systemroot%\system32\cscsvc.dll,-200 : Offline Files
@%systemroot%\system32\firewallapi.dll,-37302 : mDNS
@%systemroot%\system32\fntcache.dll,-100 : Windows Font Cache Service
@%systemroot%\system32\audioendpointbuilder.dll,-204 : Windows Audio Endpoint Builder
@%programfiles%\windows defender\mpasdesc.dll,-370 : Windows Defender Antivirus Network Inspection System Driver
@%systemroot%\system32\windows.staterepository.dll,-1 : State Repository Service
@%systemroot%\system32\mprdim.dll,-200 : Routing and Remote Access
@%systemroot%\system32\userdataaccessres.dll,-10003 : User Data Storage
@%systemroot%\system32\tokenbroker.dll,-101 : This service is used by Web Account Manager to provide single-sign-on to apps and services.
@%windir%\system32\inetsrv\iisres.dll,-30001 : Windows Process Activation Service
@%systemroot%\system32\cryptsvc.dll,-1002 : Provides three management services: Catalog Database Service, which confirms the signatures of Windows files and allows new programs to be installed; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Automatic Root Certificate Update Service, which retrieves root certificates from Windows Update and enable scenarios such as SSL. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\netlogon.dll,-102 : Netlogon
@%systemroot%\system32\drivers\msseccore.sys,-1001 : Microsoft Security Core Boot Driver
@%windir%\system32\drivers\pacer.sys,-101 : QoS Packet Scheduler
@%systemroot%\system32\semgrsvc.dll,-1002 : Manages payments and Near Field Communication (NFC) based secure elements.
@%systemroot%\system32\drivers\pdc.sys,-100 : PDC
@winlangdb.dll,-1114 : English (India)
@%systemroot%\system32\firewallapi.dll,-23090 : Windows Defender Firewall
@firewallapi.dll,-50323 : SNMP Trap
@%systemroot%\system32\mprmsg.dll,-32014 : Remote Access LEGACY NDIS WAN Driver
@%systemroot%\system32\mprmsg.dll,-32013 : IP Traffic Filter Driver
@%systemroot%\system32\drivers\fltmgr.sys,-10001 : FltMgr
@%systemroot%\system32\moshost.dll,-101 : Windows service for application access to downloaded maps. This service is started on-demand by application accessing downloaded maps. Disabling this service will prevent apps from accessing maps.
@%systemroot%\system32\drivers\wcnfs.sys,-100 : Windows Container Name Virtualization
@%systemroot%\system32\devicesflowbroker.dll,-104 : Allows ConnectUX and PC Settings to Connect and Pair with WiFi displays and Bluetooth devices.
@%systemroot%\system32\wdi.dll,-502 : Diagnostic Service Host
@%systemroot%\system32\drivers\mssecflt.sys,-1001 : Microsoft Security Events Component Minifilter
@%systemroot%\system32\presentationhost.exe,-3310 : Optimizes performance of Windows Presentation Foundation (WPF) applications by caching commonly used font data. WPF applications will start this service if it is not already running. It can be disabled, though doing so will degrade the performance of WPF applications.
@%systemroot%\system32\wuaueng.dll,-400 : Windows Update
@%systemroot%\system32\drivers\verifierext.sys,-1000 : Driver Verifier Extension
@%systemroot%\system32\tzautoupdate.dll,-200 : Auto Time Zone Updater
@%systemroot%\system32\wpnuserservice.dll,-1 : Windows Push Notifications User Service
@%systemroot%\system32\cdpsvc.dll,-101 : This service is used for Connected Devices Platform scenarios
@%systemroot%\system32\userdataaccessres.dll,-15001 : Contact Data
@%systemroot%\system32\securityhealthagent.dll,-1001 : Windows Security Service handles unified device protection and health information
@%windir%\system32\rpcepmap.dll,-1001 : RPC Endpoint Mapper
@%systemroot%\system32\drivers\mshidkmdf.sys,-100 : Pass-through HID to KMDF Filter Driver
@%systemroot%\system32\powrprof.dll,-12 : Favors performance, but may use more energy.
@%systemroot%\system32\sessenv.dll,-1027 : Remote Desktop Configuration service (RDCS) is responsible for all Remote Desktop Services and Remote Desktop related configuration and session maintenance activities that require SYSTEM context. These include per-session temporary folders, RD themes, and RD certificates.
@%systemroot%\system32\w32time.dll,-200 : Windows Time
@%systemroot%\system32\kpssvc.dll,-100 : KDC Proxy Server service (KPS)
@%systemroot%\system32\tetheringservice.dll,-4097 : Windows Mobile Hotspot Service
@%systemroot%\system32\windows.staterepository.dll,-2 : Provides required infrastructure support for the application model.
@%systemroot%\system32\rasauto.dll,-201 : Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address.
@%systemroot%\system32\flightsettings.dll,-103 : Windows Insider Service
@%systemroot%\system32\drivers\http.sys,-1 : HTTP Service
@%systemroot%\system32\walletservice.dll,-1000 : WalletService
@%windir%\system32\inetsrv\iisres.dll,-30008 : Enables this server to administer the IIS metabase. The IIS metabase stores configuration for the SMTP and FTP services. If this service is stopped, the server will be unable to configure SMTP or FTP. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\umpnpmgr.dll,-101 : Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability.
@%systemroot%\system32\drivers\netbt.sys,-2 : NETBT
@%systemroot%\system32\drivers\ipsecgw.sys,-10001 : Windows IPsec Gateway Driver
@%systemroot%\servicing\trustedinstaller.exe,-101 : Enables installation, modification, and removal of Windows updates and optional components. If this service is disabled, install or uninstall of Windows updates might fail for this computer.
@%systemroot%\system32\icsvc.dll,-202 : Provides a mechanism to exchange data between the virtual machine and the operating system running on the physical computer.
@%systemroot%\system32\umpnpmgr.dll,-200 : Plug and Play
@%systemroot%\system32\certprop.dll,-13 : Smart Card Removal Policy
@comres.dll,-2946 : KtmRm for Distributed Transaction Coordinator
@%systemroot%\system32\nlasvc.dll,-1 : Network Location Awareness
@icsvc.dll,-700 : Virtual Machine Monitoring
c:\windows\system32,@elscore.dll,-4 : Microsoft Simplified Chinese to Traditional Chinese Transliteration
@%systemroot%\system32\iscsidsc.dll,-5000 : Microsoft iSCSI Initiator Service
@%systemroot%\system32\srvsvc.dll,-109 : File and Printer Sharing for Microsoft Networks
@%systemroot%\system32\coremessaging.dll,-1 : CoreMessaging
@%systemroot%\system32\drivers\wdf01000.sys,-1000 : Kernel Mode Driver Frameworks service
@%systemroot%\system32\audioendpointbuilder.dll,-205 : Manages audio devices for the Windows Audio service. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start
@%systemroot%\system32\scdeviceenum.dll,-101 : Creates software device nodes for all smart card readers accessible to a given session. If this service is disabled, WinRT APIs will not be able to enumerate smart card readers.
@%systemroot%\system32\msimsg.dll,-32 : Adds, modifies, and removes applications provided as a Windows Installer (*.msi, *.msp) package. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\ajrouter.dll,-1 : Routes AllJoyn messages for the local AllJoyn clients. If this service is stopped the AllJoyn clients that do not have their own bundled routers will be unable to run.
@%systemroot%\system32\ngcctnrsvc.dll,-1 : Microsoft Passport Container
@%systemroot%\system32\drivers\tcpip.sys,-10101 : Transmission Control Protocol/Internet Protocol. The default wide area network protocol that provides communication across diverse interconnected networks.
@%systemroot%\system32\vds.exe,-112 : Provides management services for disks, volumes, file systems, and storage arrays.
@%systemroot%\system32\powrprof.dll,-10 : Saves energy by reducing your computer’s performance where possible.
@%systemroot%\system32\ssdpsrv.dll,-100 : SSDP Discovery
@%systemroot%\system32\sstpsvc.dll,-202 : WAN Miniport (SSTP)
@%systemroot%\system32\embeddedmodesvc.dll,-202 : The Embedded Mode service enables scenarios related to Background Applications. Disabling this service will prevent Background Applications from being activated.
@%programfiles%\windows defender advanced threat protection\mssense.exe,-1002 : Windows Defender Advanced Threat Protection service helps protect against advanced threats by monitoring and reporting security events that happen on the computer.
@%systemroot%\system32\windows.warp.jitservice.dll,-101 : Provides a JIT out of process service for WARP when running with ACG enabled.
@%systemroot%\system32\drivers\sgrmagent.sys,-1001 : System Guard Runtime Monitor Agent
@%systemroot%\system32\profsvc.dll,-301 : This service is responsible for loading and unloading user profiles. If this service is stopped or disabled, users will no longer be able to successfully sign in or sign out, apps might have problems getting to users' data, and components registered to receive profile event notifications won't receive them.
@%systemroot%\system32\seclogon.dll,-7001 : Secondary Logon
@appmgmts.dll,-3250 : Application Management
@%systemroot%\system32\iscsidsc.dll,-5001 : Manages Internet SCSI (iSCSI) sessions from this computer to remote iSCSI target devices. If this service is stopped, this computer will not be able to login or access iSCSI targets. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\umrdp.dll,-1001 : Allows the redirection of Printers/Drives/Ports for RDP connections
@%systemroot%\system32\wkssvc.dll,-1008 : DFS Namespace Client Driver
@%systemroot%\system32\lmhsvc.dll,-102 : Provides support for the NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution for clients on the network, therefore enabling users to share files, print, and log on to the network. If this service is stopped, these functions might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\lltdres.dll,-6 : Link-Layer Topology Discovery Mapper I/O Driver
@%systemroot%\system32\pla.dll,-501 : Performance Logs and Alerts Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\drivers\hwpolicy.sys,-101 : Hardware Policy Driver
@%systemroot%\system32\wcmsvc.dll,-4097 : Windows Connection Manager
@%systemroot%\system32\wsmsvc.dll,-102 : Windows Remote Management (WinRM) service implements the WS-Management protocol for remote management. WS-Management is a standard web services protocol used for remote software and hardware management. The WinRM service listens on the network for WS-Management requests and processes them. The WinRM Service needs to be configured with a listener using winrm.cmd command line tool or through Group Policy in order for it to listen over the network. The WinRM service provides access to WMI data and enables event collection. Event collection and subscription to events require that the service is running. WinRM messages use HTTP and HTTPS as transports. The WinRM service does not depend on IIS but is preconfigured to share a port with IIS on the same machine. The WinRM service reserves the /wsman URL prefix. To prevent conflicts with IIS, administrators should ensure that any websites hosted on IIS do not use the /wsman URL prefix.
@%systemroot%\system32\tieringengineservice.exe,-702 : Storage Tiers Management
@%systemroot%\system32\dps.dll,-500 : Diagnostic Policy Service
@%systemroot%\system32\sensrsvc.dll,-1001 : Monitors various sensors in order to expose data and adapt to system and user state. If this service is stopped or disabled, the display brightness will not adapt to lighting conditions. Stopping this service may affect other system functionality and features as well.
@%systemroot%\system32\dnsapi.dll,-103 : Domain Name System (DNS) Server Trust
c:\windows\system32,@elscore.dll,-1 : Microsoft Language Detection
@%systemroot%\system32\axinstsv.dll,-104 : Provides User Account Control validation for the installation of ActiveX controls from the Internet and enables management of ActiveX control installation based on Group Policy settings. This service is started on demand and if disabled the installation of ActiveX controls will behave according to default browser settings.
@%systemroot%\system32\mprmsg.dll,-32001 : Remote Access NDIS TAPI Driver
@%systemroot%\system32\drivers\mup.sys,-101 : MUP
@%systemroot%\system32\storsvc.dll,-101 : Provides enabling services for storage settings and external storage expansion
@enterpriseappmgmtsvc.dll,-2 : Enables enterprise application management.
@%systemroot%\system32\windows.sharedpc.accountmanager.dll,-100 : Shared PC Account Manager
@%systemroot%\system32\netsetupsvc.dll,-3 : Network Setup Service
@%systemroot%\system32\netlogon.dll,-103 : Maintains a secure channel between this computer and the domain controller for authenticating users and services. If this service is stopped, the computer may not authenticate users and services and the domain controller cannot register DNS records. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\scardsvr.dll,-1 : Smart Card
@%systemroot%\system32\clipsvc.dll,-104 : Provides infrastructure support for the Microsoft Store. This service is started on demand and if disabled applications bought using Windows Store will not behave correctly.
@%systemroot%\servicing\trustedinstaller.exe,-100 : Windows Modules Installer
@%systemroot%\system32\pushtoinstall.dll,-201 : Provides infrastructure support for the Microsoft Store. This service is started automatically and if disabled then remote installations will not function properly.
@%systemroot%\system32\icsvcext.dll,-601 : Hyper-V Remote Desktop Virtualization Service
@%systemroot%\system32\drivers\mslldp.sys,-210 : IEEE 802.1AB Link-Layer Discovery Protocol (LLDP). Supports Microsoft Data Center Networking (DCN).
@%systemroot%\system32\phoneserviceres.dll,-10001 : Manages the telephony state on the device
@%systemroot%\system32\dot3svc.dll,-1103 : The Wired AutoConfig (DOT3SVC) service is responsible for performing IEEE 802.1X authentication on Ethernet interfaces. If your current wired network deployment enforces 802.1X authentication, the DOT3SVC service should be configured to run for establishing Layer 2 connectivity and/or providing access to network resources. Wired networks that do not enforce 802.1X authentication are unaffected by the DOT3SVC service.
@comres.dll,-948 : Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\dmwappushsvc.dll,-201 : Routes Wireless Application Protocol (WAP) Push messages received by the device and synchronizes Device Management sessions
@%systemroot%\system32\wkssvc.dll,-100 : Workstation
@%systemroot%\system32\netprofmsvc.dll,-202 : Network List Service
@waasmedicsvc.dll,-100 : Windows Update Medic Service
@%systemroot%\system32\efssvc.dll,-100 : Encrypting File System (EFS)
@%systemroot%\system32\wkssvc.dll,-1002 : SMB MiniRedirector Wrapper and Engine
@%systemroot%\system32\drivers\filecrypt.sys,-100 : FileCrypt
@%systemroot%\system32\captureservice.dll,-100 : CaptureService
@%windir%\system32\systemeventsbrokerserver.dll,-1002 : Coordinates execution of background work for WinRT application. If this service is stopped or disabled, then background work might not be triggered.
@%systemroot%\system32\shsvcs.dll,-12289 : Provides notifications for AutoPlay hardware events.
@%systemroot%\system32\icsvcext.dll,-602 : Provides a platform for communication between the virtual machine and the operating system running on the physical computer.
@%systemroot%\system32\dhcpcore.dll,-101 : Registers and updates IP addresses and DNS records for this computer. If this service is stopped, this computer will not receive dynamic IP addresses and DNS updates. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\powrprof.dll,-14 : Automatically balances performance with energy consumption on capable hardware.
@%systemroot%\system32\wercplsupport.dll,-101 : Problem Reports and Solutions Control Panel Support
@%windir%\system32\inetsrv\iisres.dll,-30004 : Provides Web connectivity and administration through the Internet Information Services Manager
@%windir%\system32\inetsrv\iisres.dll,-30007 : IIS Admin Service
@%systemroot%\system32\dmwappushsvc.dll,-200 : Device Management Wireless Application Protocol (WAP) Push message Routing Service
@%systemroot%\system32\devicesetupmanager.dll,-1000 : Device Setup Manager
@%systemroot%\system32\rasmans.dll,-200 : Remote Access Connection Manager
@%systemroot%\system32\drivers\tcpip.sys,-10100 : Internet Protocol Version 4 (TCP/IPv4)
@%systemroot%\system32\swprv.dll,-103 : Microsoft Software Shadow Copy Provider
@%systemroot%\system32\drivers\tcpip.sys,-10102 : Internet Protocol Version 6 (TCP/IPv6)
c:\windows\system32,@elscore.dll,-9 : Microsoft Bengali to Latin Transliteration
@%systemroot%\system32\icsvc.dll,-402 : Synchronizes the system time of this virtual machine with the system time of the physical computer.
@%systemroot%\system32\firewallapi.dll,-23091 : Windows Defender Firewall helps protect your computer by preventing unauthorized users from gaining access to your computer through the Internet or a network.
@%systemroot%\system32\wkssvc.dll,-1010 : Client for Microsoft Networks
@%systemroot%\system32\tzautoupdate.dll,-201 : Automatically sets the system time zone.
@%systemroot%\system32\usocore.dll,-102 : Manages Windows Updates. If stopped, your devices will not be able download and install latest udpates.
@%systemroot%\system32\cbdhsvc.dll,-100 : Clipboard User Service
@%systemroot%\system32\iphlpsvc.dll,-501 : Provides tunnel connectivity using IPv6 transition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS. If this service is stopped, the computer will not have the enhanced connectivity benefits that these technologies offer.
@%systemroot%\system32\seclogon.dll,-7000 : Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\drivers\ahcache.sys,-102 : Application Compatibility Cache
@%systemroot%\system32\ncbservice.dll,-500 : Network Connection Broker
@%systemroot%\system32\iphlpsvc.dll,-500 : IP Helper
@%systemroot%\system32\diagsvcs\diagnosticshub.standardcollector.serviceres.dll,-1001 : Diagnostics Hub Standard Collector Service. When running, this service collects real time ETW events and processes them.
@%systemroot%\system32\icsvc.dll,-901 : Hyper-V PowerShell Direct Service
@c:\windows\system32\spool\drivers\x64\3\printconfig.dll,-1 : Printer Extensions and Notifications
@%systemroot%\system32\installservice.dll,-200 : Microsoft Store Install Service
@%systemroot%\system32\searchindexer.exe,-104 : Provides content indexing, property caching, and search results for files, e-mail, and other content.
@%systemroot%\system32\windows.warp.jitservice.dll,-100 : WarpJITSvc
@%systemroot%\system32\icsvcext.dll,-502 : Coordinates the communications that are required to use Volume Shadow Copy Service to back up applications and data on this virtual machine from the operating system on the physical computer.
@%systemroot%\system32\lfsvc.dll,-1 : Geolocation Service
@%systemroot%\system32\wbem\wmiapsrv.exe,-111 : Provides performance library information from Windows Management Instrumentation (WMI) providers to clients on the network. This service only runs when Performance Data Helper is activated.
@%systemroot%\system32\licensemanagersvc.dll,-200 : Windows License Manager Service
@%systemroot%\system32\drivers\mshidumdf.sys,-100 : Pass-through HID to UMDF Driver
@%systemroot%\system32\appvclient.exe,-101 : Manages App-V users and virtual applications
@%systemroot%\system32\lltdres.dll,-2 : Creates a Network Map, consisting of PC and device topology (connectivity) information, and metadata describing each PC and device. If this service is disabled, the Network Map will not function properly.
@%systemroot%\system32\vaultsvc.dll,-1003 : Credential Manager
@%systemroot%\system32\drivers\storqosflt.sys,-101 : Storage QoS Filter Driver
@%systemroot%\system32\wpnuserservice.dll,-2 : This service hosts Windows notification platform which provides support for local and push notifications. Supported notifications are tile, toast and raw.
@%windir%\system32\inetsrv\iisres.dll,-30003 : World Wide Web Publishing Service
@%systemroot%\system32\wersvc.dll,-100 : Windows Error Reporting Service
@%systemroot%\system32\clipsvc.dll,-103 : Client License Service (ClipSVC)
@%systemroot%\system32\ualsvc.dll,-102 : User Access Logging Service
@combase.dll,-5012 : DCOM Server Process Launcher
@%systemroot%\system32\scardsvr.dll,-5 : Manages access to smart cards read by this computer. If this service is stopped, this computer will be unable to read smart cards. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\firewallapi.dll,-38523 : Secure World Wide Web Services (HTTPS)
@%systemroot%\system32\mprmsg.dll,-32007 : Remote Access PPPOE Driver
@%systemroot%\system32\shsvcs.dll,-12288 : Shell Hardware Detection
@%systemroot%\system32\drivers\ndisimplatform.sys,-500 : Provides a platform for network adapter load balancing and fail-over.
@%systemroot%\system32\wlidsvc.dll,-101 : Enables user sign-in through Microsoft account identity services. If this service is stopped, users will not be able to logon to the computer with their Microsoft account.
@%systemroot%\system32\dosvc.dll,-101 : Performs content delivery optimization tasks
@%systemroot%\system32\lltdres.dll,-4 : Used to discover and locate other PCs, devices, and network infrastructure components on the network. Also used to determine network bandwidth.
@%programfiles%\windows defender\mpasdesc.dll,-240 : Helps protect users from malware and other potentially unwanted software
@%systemroot%\system32\wkssvc.dll,-101 : Creates and maintains client network connections to remote servers using the SMB protocol. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\cbdhsvc.dll,-101 : This user service is used for Clipboard scenarios
@%systemroot%\system32\trkwks.dll,-1 : Distributed Link Tracking Client
@%systemroot%\system32\sensrsvc.dll,-1000 : Sensor Monitoring Service
@%windir%\system32\lsm.dll,-1001 : Local Session Manager
@%systemroot%\system32\dps.dll,-501 : The Diagnostic Policy Service enables problem detection, troubleshooting and resolution for Windows components. If this service is stopped, diagnostics will no longer function.
@%systemroot%\system32\drivers\luafv.sys,-100 : UAC File Virtualization
@%systemroot%\system32\userdataaccessres.dll,-15000 : Indexes contact data for fast contact searching. If you stop or disable this service, contacts might be missing from your search results.
@%systemroot%\system32\windows.devices.picker.dll,-1007 : This user service is used for managing the Miracast, DLNA, and DIAL UI
@%systemroot%\system32\icsvc.dll,-802 : Provides an interface for the Hyper-V host to interact with specific services running inside the virtual machine.
@%systemroot%\system32\sessenv.dll,-1026 : Remote Desktop Configuration
@%systemroot%\system32\nsisvc.dll,-201 : This service delivers network notifications (e.g. interface addition/deleting etc) to user mode clients. Stopping this service will cause loss of network connectivity. If this service is disabled, any other services that explicitly depend on this service will fail to start.
@%systemroot%\system32\btagservice.dll,-101 : Bluetooth Audio Gateway Service
@%systemroot%\system32\userdataaccessres.dll,-10002 : Handles storage of structured user data, including contact info, calendars, messages, and other content. If you stop or disable this service, apps that use this data might not work correctly.
c:\windows\system32,@elscore.dll,-10 : Microsoft Hangul Decomposition Transliteration
@%systemroot%\system32\windows.sharedpc.accountmanager.dll,-101 : Manages profiles and accounts on a SharedPC configured device
@%systemroot%\system32\ngcrecovery.dll,-100 : Windows Hello Recovery Key Encryption
@%systemroot%\system32\usocore.dll,-101 : Update Orchestrator Service
@%systemroot%\system32\bthserv.dll,-101 : Bluetooth Support Service
@%systemroot%\system32\mprmsg.dll,-32005 : WAN Miniport (L2TP)
@%systemroot%\system32\spoolsv.exe,-1 : Print Spooler
@%systemroot%\system32\tetheringservice.dll,-4098 : Provides the ability to share a cellular data connection with another device.
@%systemroot%\system32\smphost.dll,-101 : Host service for the Microsoft Storage Spaces management provider. If this service is stopped or disabled, Storage Spaces cannot be managed.
@comres.dll,-947 : COM+ System Application
@%systemroot%\system32\drivers\wimmount.sys,-101 : WIMMount
@%systemroot%\system32\ssdpsrv.dll,-101 : Discovers networked devices and services that use the SSDP discovery protocol, such as UPnP devices. Also announces SSDP devices and services running on the local computer. If this service is stopped, SSDP-based devices will not be discovered. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\devicesetupmanager.dll,-1001 : Enables the detection, download and installation of device-related software. If this service is disabled, devices may be configured with outdated software, and may not work correctly.
@%systemroot%\system32\firewallapi.dll,-11199 : Message Queuing
@%systemroot%\system32\swprv.dll,-102 : Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\qmgr.dll,-1001 : Transfers files in the background using idle network bandwidth. If the service is disabled, then any applications that depend on BITS, such as Windows Update or MSN Explorer, will be unable to automatically download programs and other information.
@%systemroot%\system32\certprop.dll,-11 : Certificate Propagation
@comres.dll,-2798 : Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will fail. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\dssvc.dll,-10002 : Provides data brokering between applications.
@%systemroot%\system32\umpo.dll,-100 : Power
@%windir%\system32\inetsrv\iisres.dll,-30014 : W3C Logging Service
@comres.dll,-2797 : Distributed Transaction Coordinator
@%systemroot%\system32\cdpusersvc.dll,-101 : This user service is used for Connected Devices Platform scenarios
@%systemroot%\system32\wercplsupport.dll,-100 : This service provides support for viewing, sending and deletion of system-level problem reports for the Problem Reports and Solutions control panel.
@%systemroot%\system32\qwave.dll,-1 : Quality Windows Audio Video Experience
@%systemroot%\system32\drivers\tcpip.sys,-10001 : TCP/IP Protocol Driver
@firewallapi.dll,-50324 : Receives trap messages generated by local or remote Simple Network Management Protocol (SNMP) agents and forwards the messages to SNMP management programs running on this computer. If this service is stopped, SNMP-based programs on this computer will not receive SNMP trap messages. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\certprop.dll,-14 : Allows the system to be configured to lock the user desktop upon smart card removal.
@%systemroot%\system32\firewallapi.dll,-36902 : Software Load Balancer
@%systemroot%\system32\wuaueng.dll,-106 : Enables the detection, download, and installation of updates for Windows and other programs. If this service is disabled, users of this computer will not be able to use Windows Update or its automatic updating feature, and programs will not be able to use the Windows Update Agent (WUA) API.
@%systemroot%\system32\ikeext.dll,-502 : The IKEEXT service hosts the Internet Key Exchange (IKE) and Authenticated Internet Protocol (AuthIP) keying modules. These keying modules are used for authentication and key exchange in Internet Protocol security (IPsec). Stopping or disabling the IKEEXT service will disable IKE and AuthIP key exchange with peer computers. IPsec is typically configured to use IKE or AuthIP; therefore, stopping or disabling the IKEEXT service might result in an IPsec failure and might compromise the security of the system. It is strongly recommended that you have the IKEEXT service running.
@%systemroot%\system32\sensorservice.dll,-1001 : A service for sensors that manages different sensors' functionality. Manages Simple Device Orientation (SDO) and History for sensors. Loads the SDO sensor that reports device orientation changes. If this service is stopped or disabled, the SDO sensor will not be loaded and so auto-rotation will not occur. History collection from Sensors will also be stopped.
@%systemroot%\system32\capabilityaccessmanager.dll,-1 : Capability Access Manager Service
@%systemroot%\system32\drivers\dam.sys,-100 : Desktop Activity Moderator Driver
@%systemroot%\system32\agentservice.exe,-102 : User Experience Virtualization Service
@%systemroot%\system32\drivers\mountmgr.sys,-100 : Mount Point Manager
@%systemroot%\system32\wiaservc.dll,-10 : Provides image acquisition services for scanners and cameras
@%systemroot%\syswow64\perfhost.exe,-1 : Enables remote users and 64-bit processes to query performance counters provided by 32-bit DLLs. If this service is stopped, only local users and 32-bit processes will be able to query performance counters provided by 32-bit DLLs.
@%systemroot%\system32\bthserv.dll,-102 : The Bluetooth service supports discovery and association of remote Bluetooth devices. Stopping or disabling this service may cause already installed Bluetooth devices to fail to operate properly and prevent new devices from being discovered or associated.
@%systemroot%\system32\lltdres.dll,-3 : Allows this PC to be discovered and located on the network.
@%systemroot%\system32\wpnservice.dll,-2 : This service runs in session 0 and hosts the notification platform and connection provider which handles the connection between the device and WNS server.
@%windir%\system32\timebrokerserver.dll,-1002 : Coordinates execution of background work for WinRT application. If this service is stopped or disabled, then background work might not be triggered.
@%systemroot%\system32\cscsvc.dll,-202 : Offline Files Driver
@%systemroot%\system32\wkssvc.dll,-1006 : SMB 2.0 MiniRedirector
@%systemroot%\system32\alg.exe,-112 : Application Layer Gateway Service
@%systemroot%\system32\usermgr.dll,-100 : User Manager
@%systemroot%\system32\drivers\ndproxy.sys,-6000 : NDIS Proxy Driver
@mqutil.dll,-6102 : Message Queuing
@%programfiles%\windows defender advanced threat protection\mssense.exe,-1001 : Windows Defender Advanced Threat Protection Service
@%systemroot%\system32\frameserver.dll,-101 : Enables multiple clients to access video frames from camera devices.
@c:\windows\system32\firewallcontrolpanel.dll,-12122 : Windows Defender Firewall
@%systemroot%\system32\icsvcext.dll,-501 : Hyper-V Volume Shadow Copy Requestor
@%systemroot%\system32\sacsvr.dll,-500 : Special Administration Console Helper
@%systemroot%\system32\wbem\wmisvc.dll,-204 : Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\schedsvc.dll,-101 : Enables a user to configure and schedule automated tasks on this computer. The service also hosts multiple Windows system-critical tasks. If this service is stopped or disabled, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start.
@%windir%\system32\bisrv.dll,-100 : Background Tasks Infrastructure Service
@%systemroot%\system32\wersvc.dll,-101 : Allows errors to be reported when programs stop working or responding and allows existing solutions to be delivered. Also allows logs to be generated for diagnostic and repair services. If this service is stopped, error reporting might not work correctly and results of diagnostic services and repairs might not be displayed.
@%systemroot%\system32\termsrv.dll,-267 : Allows users to connect interactively to a remote computer. Remote Desktop and Remote Desktop Session Host Server depend on this service. To prevent remote use of this computer, clear the checkboxes on the Remote tab of the System properties control panel item.
@%systemroot%\system32\sens.dll,-201 : Monitors system events and notifies subscribers to COM+ Event System of these events.
@%systemroot%\system32\drivers\mssecwfp.sys,-1001 : Microsoft Security WFP Callout Driver
@%systemroot%\system32\devquerybroker.dll,-101 : Enables apps to discover devices with a backgroud task
@%systemroot%\system32\tabsvc.dll,-101 : Enables Touch Keyboard and Handwriting Panel pen and ink functionality
@%systemroot%\system32\drivers\scfilter.sys,-11 : Smart card PnP Class Filter Driver
@%systemroot%\system32\wsmsvc.dll,-101 : Windows Remote Management (WS-Management)
@%systemroot%\system32\userdataaccessres.dll,-14001 : User Data Access
@%systemroot%\system32\ncbservice.dll,-501 : Brokers connections that allow Windows Store Apps to receive notifications from the internet.
@%systemroot%\system32\wpnservice.dll,-1 : Windows Push Notifications System Service
@%systemroot%\system32\drivers\volsnap.sys,-100 : Volume Shadow Copy driver
@%systemroot%\system32\hidserv.dll,-102 : Activates and maintains the use of hot buttons on keyboards, remote controls, and other multimedia devices. It is recommended that you keep this service running.
@%systemroot%\system32\efssvc.dll,-101 : Provides the core file encryption technology used to store encrypted files on NTFS file system volumes. If this service is stopped or disabled, applications will be unable to access encrypted files.
@%systemroot%\system32\vds.exe,-100 : Virtual Disk
@%systemroot%\system32\drivers\rdpdr.sys,-100 : Remote Desktop Device Redirector Driver
@%systemroot%\system32\wdi.dll,-500 : Diagnostic System Host
@%systemroot%\system32\drivers\appvstrm.sys,-101 : AppvStrm
@%systemroot%\system32\lltdres.dll,-5 : Link-Layer Topology Discovery Responder
@%programfiles%\windows defender\mpasdesc.dll,-320 : Windows Defender Antivirus Network Inspection Service
@%systemroot%\system32\wbiosrvc.dll,-100 : Windows Biometric Service
@%systemroot%\system32\umpnpmgr.dll,-100 : Device Install Service
@%systemroot%\system32\wkssvc.dll,-1011 : Allows your computer to access resources on a Microsoft network.
@%systemroot%\system32\consentuxclient.dll,-101 : Allows ConnectUX and PC Settings to Connect and Pair with WiFi displays and Bluetooth devices.
@%systemroot%\system32\captureservice.dll,-101 : OneCore Capture Service
@%systemroot%\system32\sstpsvc.dll,-201 : Provides support for the Secure Socket Tunneling Protocol (SSTP) to connect to remote computers using VPN. If this service is disabled, users will not be able to use SSTP to access remote servers.
@%systemroot%\system32\wevtsvc.dll,-200 : Windows Event Log
@%systemroot%\system32\upnphost.dll,-213 : UPnP Device Host
@%systemroot%\system32\windows.internal.management.dll,-101 : Performs Device Enrollment Activities for Device Management
@%systemroot%\system32\diagtrack.dll,-3002 : The Connected User Experiences and Telemetry service enables features that support in-application and connected user experiences. Additionally, this service manages the event driven collection and transmission of diagnostic and usage information (used to improve the experience and quality of the Windows Platform) when the diagnostics and usage privacy option settings are enabled under Feedback and Diagnostics.
@%systemroot%\system32\svsvc.dll,-101 : Spot Verifier
@%systemroot%\system32\trkwks.dll,-2 : Maintains links between NTFS files within a computer or across computers in a network.
@%systemroot%\system32\drivers\wpdupfltr.sys,-100 : WPD Upper Class Filter Driver
@%systemroot%\system32\drivers\partmgr.sys,-100 : Partition driver
@%systemroot%\system32\ci.dll,-100 : Isolated User Mode (IUM)
@%systemroot%\system32\drivers\filetrace.sys,-10001 : FileTrace
@%systemroot%\system32\urlmon.dll,-4200 : Open File - Security Warning
@%systemroot%\system32\wecsvc.dll,-200 : Windows Event Collector
@%systemroot%\system32\drivers\wudfpf.sys,-1000 : User Mode Driver Frameworks Platform Driver
@%systemroot%\system32\icsvc.dll,-302 : Provides a mechanism to shut down the operating system of this virtual machine from the management interfaces on the physical computer.
@%systemroot%\system32\drivers\bam.sys,-100 : Background Activity Moderator Driver
@%systemroot%\system32\wpdbusenum.dll,-100 : Portable Device Enumerator Service
@%systemroot%\system32\pla.dll,-500 : Performance Logs & Alerts
@%systemroot%\system32\sstpsvc.dll,-200 : Secure Socket Tunneling Protocol Service
@comres.dll,-2450 : COM+ Event System
@%systemroot%\system32\vaultsvc.dll,-1004 : Provides secure storage and retrieval of credentials to users, applications and security service packages.
@%systemroot%\system32\installservice.dll,-201 : Provides infrastructure support for the Microsoft Store. This service is started on demand and if disabled then installations will not function properly.
@%systemroot%\system32\mprmsg.dll,-32006 : WAN Miniport (PPTP)
@%systemroot%\system32\appxdeploymentserver.dll,-1 : AppX Deployment Service (AppXSVC)
@gpapi.dll,-112 : Group Policy Client
@%systemroot%\system32\vssvc.exe,-101 : Manages and implements Volume Shadow Copies used for backup and other purposes. If this service is stopped, shadow copies will be unavailable for backup and the backup may fail. If this service is disabled, any services that explicitly depend on it will fail to start.
@mqutil.dll,-6101 : Message Queuing Access Control
@%systemroot%\system32\appreadiness.dll,-1000 : App Readiness
@%windir%\system32\drivers\netbios.sys,-503 : NetBIOS Interface
@%systemroot%\system32\drivers\qwavedrv.sys,-1 : QWAVE driver
@%systemroot%\system32\certprop.dll,-12 : Copies user certificates and root certificates from smart cards into the current user's certificate store, detects when a smart card is inserted into a smart card reader, and, if needed, installs the smart card Plug and Play minidriver.
c:\windows\system32,@elscore.dll,-5 : Microsoft Transliteration Engine
@%systemroot%\system32\drivers\bindflt.sys,-100 : Windows Bind Filter Driver
@%systemroot%\system32\sensordataservice.exe,-101 : Sensor Data Service
@c:\windows\syswow64\firewallcontrolpanel.dll,-12122 : Windows Defender Firewall
@%systemroot%\system32\flightsettings.dll,-104 : Provides infrastructure support for the Windows Insider Program. This service must remain enabled for the Windows Insider Program to work.
@%systemroot%\microsoft.net\framework64\v4.0.30319\aspnet_rc.dll,-2 : Provides support for out-of-process session states for ASP.NET. If this service is stopped, out-of-process requests will not be processed. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\moshost.dll,-100 : Downloaded Maps Manager
@%systemroot%\system32\hidserv.dll,-101 : Human Interface Device Service
@%systemroot%\system32\sacsvr.dll,-501 : Allows administrators to remotely access a command prompt using Emergency Management Services.
@%systemroot%\system32\powrprof.dll,-11 : Power saver
@%systemroot%\system32\graphicsperfsvc.dll,-101 : Graphics performance monitor service
@%systemroot%\system32\graphicsperfsvc.dll,-100 : GraphicsPerfSvc
@%systemroot%\system32\qmgr.dll,-1000 : Background Intelligent Transfer Service
@c:\windows\system32\spool\drivers\x64\3\printconfig.dll,-2 : This service opens custom printer dialog boxes and handles notifications from a remote print server or a printer. If you turn off this service, you won’t be able to see printer extensions or notifications.
@%systemroot%\system32\dnsapi.dll,-102 : The DNS Client service (dnscache) caches Domain Name System (DNS) names and registers the full computer name for this computer. If the service is stopped, DNS names will continue to be resolved. However, the results of DNS name queries will not be cached and the computer's name will not be registered. If the service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\ualsvc.dll,-101 : This service logs unique client access requests, in the form of IP addresses and user names, of installed products and roles on the local server. This information can be queried, via Powershell, by administrators needing to quantify client demand of server software for offline Client Access License (CAL) management. If the service is disabled, client requests will not be logged and will not be retrievable via Powershell queries. Stopping the service will not affect query of historical data (see supporting documentation for steps to delete historical data). The local system administrator must consult his, or her, Windows Server license terms to determine the number of CALs that are required for the server software to be appropriately licensed; use of the UAL service and data does not alter this obligation.
@%systemroot%\system32\ikeext.dll,-501 : IKE and AuthIP IPsec Keying Modules
@%systemroot%\system32\appidsvc.dll,-100 : Application Identity
@%systemroot%\system32\cryptsvc.dll,-1001 : Cryptographic Services
@%systemroot%\system32\embeddedmodesvc.dll,-201 : Embedded Mode
@%systemroot%\system32\ajrouter.dll,-2 : AllJoyn Router Service
@%systemroot%\system32\srpapi.dll,-100 : AppID Driver
@%systemroot%\system32\licensemanagersvc.dll,-201 : Provides infrastructure support for the Microsoft Store. This service is started on demand and if disabled then content acquired through the Microsoft Store will not function properly.
@%systemroot%\system32\rasauto.dll,-200 : Remote Access Auto Connection Manager
@%systemroot%\system32\ngcsvc.dll,-100 : Microsoft Passport
@%systemroot%\system32\w32time.dll,-201 : Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\presentationhost.exe,-3309 : Windows Presentation Foundation Font Cache 3.0.0.0
@%systemroot%\system32\drivers\ndiscap.sys,-5000 : Microsoft NDIS Capture
@%systemroot%\system32\drivers\ndis.sys,-200 : NDIS System Driver
@%systemroot%\system32\srvsvc.dll,-100 : Server
@%systemroot%\system32\winhttp.dll,-101 : WinHTTP implements the client HTTP stack and provides developers with a Win32 API and COM Automation component for sending HTTP requests and receiving responses. In addition, WinHTTP provides support for auto-discovering a proxy configuration via its implementation of the Web Proxy Auto-Discovery (WPAD) protocol.
@%systemroot%\system32\diagtrack.dll,-3001 : Connected User Experiences and Telemetry
@%systemroot%\system32\kpssvc.dll,-101 : KDC Proxy Server service runs on edge servers to proxy Kerberos protocol messages to domain controllers on the corporate network.
@%systemroot%\system32\appxdeploymentserver.dll,-2 : Provides infrastructure support for deploying Store applications. This service is started on demand and if disabled Store applications will not be deployed to the system, and may not function properly.
c:\windows\system32,@elscore.dll,-6 : Microsoft Cyrillic to Latin Transliteration
@%systemroot%\system32\mprdim.dll,-201 : Offers routing services to businesses in local area and wide area network environments.
@%systemroot%\system32\bthavctpsvc.dll,-101 : AVCTP service
@%systemroot%\system32\drivers\wudfrd.sys,-1000 : Windows Driver Foundation - User-mode Driver Framework Reflector
@%systemroot%\system32\sysmain.dll,-1000 : SysMain
@%systemroot%\system32\bthavctpsvc.dll,-102 : This is Audio Video Control Transport Protocol service
c:\windows\system32,@elscore.dll,-2 : Microsoft Script Detection
@%systemroot%\system32\wlidsvc.dll,-100 : Microsoft Account Sign-in Assistant
@%systemroot%\system32\wiarpc.dll,-1 : Launches applications associated with still image acquisition events.
@sstpsvc.dll,-35001 : Secure Socket Tunneling Protocol
@%systemroot%\system32\drivers\mslldp.sys,-200 : Microsoft Link-Layer Discovery Protocol
@%programfiles%\windows defender\mpasdesc.dll,-310 : Windows Defender Antivirus Service
@%systemroot%\system32\wbem\wmisvc.dll,-205 : Windows Management Instrumentation
@%systemroot%\system32\consentuxclient.dll,-100 : ConsentUX
@%systemroot%\system32\appidsvc.dll,-101 : Determines and verifies the identity of an application. Disabling this service will prevent AppLocker from being enforced.
@%systemroot%\system32\rasmans.dll,-201 : Manages dial-up and virtual private network (VPN) connections from this computer to the Internet or other remote networks. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\profsvc.dll,-300 : User Profile Service
@%windir%\system32\inetsrv\iisres.dll,-30002 : The Windows Process Activation Service (WAS) provides process activation, resource management and health management services for message-activated applications.
@%systemroot%\system32\icsvc.dll,-102 : Monitors the state of this virtual machine by reporting a heartbeat at regular intervals. This service helps you identify running virtual machines that have stopped responding.
@%systemroot%\system32\netsetupsvc.dll,-4 : The Network Setup Service manages the installation of network drivers and permits the configuration of low-level network settings. If this service is stopped, any driver installations that are in-progress may be cancelled.
@%systemroot%\system32\drivers\wcifs.sys,-100 : Windows Container Isolation
@%systemroot%\system32\fdphost.dll,-100 : Function Discovery Provider Host
@%systemroot%\system32\ipnathlp.dll,-107 : Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network.
@%systemroot%\system32\agentservice.exe,-101 : Provides support for application and OS settings roaming
@%systemroot%\system32\wbem\wmiapsrv.exe,-110 : WMI Performance Adapter
@waasmedicsvc.dll,-101 : Enables remediation and protection of Windows Update components.
@%programfiles%\windows defender\mpasdesc.dll,-242 : Helps guard against intrusion attempts targeting known and newly discovered vulnerabilities in network protocols
@%systemroot%\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8200 : Provides ability to share TCP ports over the net.tcp protocol.
@combase.dll,-5013 : The DCOMLAUNCH service launches COM and DCOM servers in response to object activation requests. If this service is stopped or disabled, programs using COM or DCOM will not function properly. It is strongly recommended that you have the DCOMLAUNCH service running.
@%systemroot%\system32\drivers\mmcss.sys,-100 : Multimedia Class Scheduler
@%systemroot%\system32\walletservice.dll,-1001 : Hosts objects used by clients of the wallet
@%systemroot%\system32\icsvc.dll,-401 : Hyper-V Time Synchronization Service
@%systemroot%\system32\drivers\ndisvirtualbus.sys,-200 : Microsoft Virtual Network Adapter Enumerator
@%systemroot%\system32\audiosrv.dll,-201 : Manages audio for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start
@%systemroot%\system32\pcasvc.dll,-2 : This service provides support for the Program Compatibility Assistant (PCA). PCA monitors programs installed and run by the user and detects known compatibility problems. If this service is stopped, PCA will not function properly.
@%systemroot%\system32\bfe.dll,-1001 : Base Filtering Engine
@%systemroot%\system32\sens.dll,-200 : System Event Notification Service
@%systemroot%\system32\mprmsg.dll,-32000 : RAS Asynchronous Media Driver
@%systemroot%\system32\wdi.dll,-503 : The Diagnostic Service Host is used by the Diagnostic Policy Service to host diagnostics that need to run in a Local Service context. If this service is stopped, any diagnostics that depend on it will no longer function.
@%systemroot%\system32\netman.dll,-110 : Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections.
@regsvc.dll,-2 : Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\icsvc.dll,-101 : Hyper-V Heartbeat Service
@%systemroot%\system32\srvsvc.dll,-104 : Server SMB 2.xxx Driver
@%systemroot%\system32\netprofmsvc.dll,-203 : Identifies the networks to which the computer has connected, collects and stores properties for these networks, and notifies applications when these properties change.
@%systemroot%\system32\dot3svc.dll,-1102 : Wired AutoConfig
@%systemroot%\system32\drivers\tcpip.sys,-10103 : TCP/IP version 6. The latest version of the internet protocol that provides communication across diverse interconnected networks.
@peerdistsh.dll,-9003 : BranchCache - Hosted Cache Client (Uses HTTPS)
@%systemroot%\system32\dhcpcore.dll,-100 : DHCP Client
@%systemroot%\system32\drivers\uevagentdriver.sys,-101 : UevAgentDriver
@%systemroot%\system32\tcpipcfg.dll,-50004 : NetIO Legacy TDI Support Driver
@%systemroot%\system32\appinfo.dll,-101 : Facilitates the running of interactive applications with additional administrative privileges. If this service is stopped, users will be unable to launch applications with the additional administrative privileges they may require to perform desired user tasks.
@%systemroot%\system32\wiarpc.dll,-2 : Still Image Acquisition Events
@%systemroot%\system32\eapsvc.dll,-2 : The Extensible Authentication Protocol (EAP) service provides network authentication in such scenarios as 802.1x wired and wireless, VPN, and Network Access Protection (NAP). EAP also provides application programming interfaces (APIs) that are used by network access clients, including wireless and VPN clients, during the authentication process. If you disable this service, this computer is prevented from accessing networks that require EAP authentication.
@%systemroot%\system32\securityhealthagent.dll,-1002 : Windows Security Service
@%systemroot%\system32\wdi.dll,-501 : The Diagnostic System Host is used by the Diagnostic Policy Service to host diagnostics that need to run in a Local System context. If this service is stopped, any diagnostics that depend on it will no longer function.
@enterpriseappmgmtsvc.dll,-1 : Enterprise App Management Service
@%systemroot%\system32\coremessaging.dll,-2 : Manages communication between system components.
@%programfiles%\windows defender\mpasdesc.dll,-390 : Windows Defender Antivirus Boot Driver
@%systemroot%\system32\drivers\nsiproxy.sys,-2 : NSI Proxy Service Driver
@%systemroot%\system32\drivers\fsdepends.sys,-10001 : File System Dependency Minifilter
@%programfiles%\windows media player\wmpnetwk.exe,-102 : Shares Windows Media Player libraries to other networked players and media devices using Universal Plug and Play
@%systemroot%\system32\fntcache.dll,-101 : Optimizes performance of applications by caching commonly used font data. Applications will start this service if it is not already running. It can be disabled, though doing so will degrade application performance.
@%systemroot%\system32\searchindexer.exe,-103 : Windows Search
@%systemroot%\system32\firewallapi.dll,-38527 : Web Management Service (HTTP)
@%systemroot%\system32\winhttp.dll,-100 : WinHTTP Web Proxy Auto-Discovery Service
@%systemroot%\system32\themeservice.dll,-8192 : Themes
@%systemroot%\system32\firewallapi.dll,-3400 : COM+ Network Access
@%windir%\system32\inetsrv\iisres.dll,-20001 : Web Management Service
@%systemroot%\system32\mprmsg.dll,-32011 : Remote Access IP ARP Driver
@%systemroot%\system32\tabsvc.dll,-100 : Touch Keyboard and Handwriting Panel Service
@%systemroot%\system32\windows.devices.picker.dll,-1006 : DevicePicker
@%systemroot%\system32\bfe.dll,-1002 : The Base Filtering Engine (BFE) is a service that manages firewall and Internet Protocol security (IPsec) policies and implements user mode filtering. Stopping or disabling the BFE service will significantly reduce the security of the system. It will also result in unpredictable behavior in IPsec management and firewall applications.
@%systemroot%\system32\icsvc.dll,-201 : Hyper-V Data Exchange Service
c:\windows\system32,@elscore.dll,-8 : Microsoft Malayalam to Latin Transliteration
@%systemroot%\system32\devicesflowbroker.dll,-103 : DevicesFlow
@c:\windows\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8198 : Receives activation requests over the net.tcp protocol and passes them to the Windows Process Activation Service.
@%systemroot%\system32\msimsg.dll,-27 : Windows Installer
@%systemroot%\system32\rmapi.dll,-1001 : Radio Management Service
@%systemroot%\system32\drivers\winnat.sys,-10001 : Windows NAT Driver
@%systemroot%\system32\drivers\afd.sys,-1000 : Ancillary Function Driver for Winsock
@%windir%\system32\inetsrv\iisres.dll,-20002 : The Web Management Service enables remote and delegated management capabilities for administrators to manage for the Web server, sites and applications present on this machine.
@%systemroot%\system32\userdataaccessres.dll,-14000 : Provides apps access to structured user data, including contact info, calendars, messages, and other content. If you stop or disable this service, apps that use this data might not work correctly.
@regsvc.dll,-1 : Remote Registry
@%systemroot%\system32\das.dll,-100 : Device Association Service
@%systemroot%\system32\tieringengineservice.exe,-701 : Optimizes the placement of data in storage tiers on all tiered storage spaces in the system.
@%systemroot%\system32\drivers\tunnel.sys,-500 : Microsoft Tunnel Miniport Adapter Driver
@%systemroot%\system32\vssvc.exe,-102 : Volume Shadow Copy
@%systemroot%\system32\wephostsvc.dll,-100 : Windows Encryption Provider Host Service
@%systemroot%\system32\devquerybroker.dll,-100 : DevQuery Background Discovery Broker
@%systemroot%\system32\drivers\ehstorclass.sys,-100 : Enhanced Storage Filter Driver
@%systemroot%\system32\cscsvc.dll,-201 : The Offline Files service performs maintenance activities on the Offline Files cache, responds to user logon and logoff events, implements the internals of the public API, and dispatches interesting events to those interested in Offline Files activities and changes in cache state.
@%systemroot%\system32\appinfo.dll,-100 : Application Information
@%systemroot%\system32\drivers\tsusbflt.sys,-1000 : Remote Desktop USB Hub Class Filter Driver
@%systemroot%\system32\wevtsvc.dll,-201 : This service manages events and event logs. It supports logging events, querying events, subscribing to events, archiving event logs, and managing event metadata. It can display events in both XML and plain text format. Stopping this service may compromise security and reliability of the system.
@%systemroot%\system32\sysmain.dll,-1001 : Maintains and improves system performance over time.
@%systemroot%\system32\locator.exe,-2 : Remote Procedure Call (RPC) Locator
@%systemroot%\system32\wecsvc.dll,-201 : This service manages persistent subscriptions to events from remote sources that support WS-Management protocol. This includes Windows Vista event logs, hardware and IPMI-enabled event sources. The service stores forwarded events in a local Event Log. If this service is stopped or disabled event subscriptions cannot be created and forwarded events cannot be accepted.
@%systemroot%\system32\srvsvc.dll,-101 : Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\dnsapi.dll,-101 : DNS Client
@%systemroot%\system32\frameserver.dll,-100 : Windows Camera Frame Server
@%systemroot%\system32\wcmsvc.dll,-4098 : Makes automatic connect/disconnect decisions based on the network connectivity options currently available to the PC and enables management of network connectivity based on Group Policy settings.
@%systemroot%\system32\btagservice.dll,-102 : Service supporting the audio gateway role of the Bluetooth Handsfree Profile.
@%systemroot%\system32\phoneserviceres.dll,-10000 : Phone Service
@%systemroot%\system32\wkssvc.dll,-2001 : Browser
@comres.dll,-2947 : Coordinates transactions between the Distributed Transaction Coordinator (MSDTC) and the Kernel Transaction Manager (KTM). If it is not needed, it is recommended that this service remain stopped. If it is needed, both MSDTC and KTM will start this service automatically. If this service is disabled, any MSDTC transaction interacting with a Kernel Resource Manager will fail and any services that explicitly depend on it will fail to start.
@%windir%\system32\rpcepmap.dll,-1002 : Resolves RPC interfaces identifiers to transport endpoints. If this service is stopped or disabled, programs using Remote Procedure Call (RPC) services will not function properly.
@%systemroot%\system32\firewallapi.dll,-3405 : COM+ Remote Administration
@%systemroot%\system32\locator.exe,-3 : In Windows 2003 and earlier versions of Windows, the Remote Procedure Call (RPC) Locator service manages the RPC name service database. In Windows Vista and later versions of Windows, this service does not provide any functionality and is present for application compatibility.
@%systemroot%\system32\fdrespub.dll,-101 : Publishes this computer and resources attached to this computer so they can be discovered over the network. If this service is stopped, network resources will no longer be published and they will not be discovered by other computers on the network.
@%systemroot%\system32\drivers\appvvfs.sys,-101 : AppvVfs
@%windir%\system32\systemeventsbrokerserver.dll,-1001 : System Events Broker
@combase.dll,-5010 : Remote Procedure Call (RPC)
@%systemroot%\system32\wbiosrvc.dll,-101 : The Windows biometric service gives client applications the ability to capture, compare, manipulate, and store biometric data without gaining direct access to any biometric hardware or samples. The service is hosted in a privileged SVCHOST process.
@%systemroot%\system32\qwave.dll,-2 : Quality Windows Audio Video Experience (qWave) is a networking platform for Audio Video (AV) streaming applications on IP home networks. qWave enhances AV streaming performance and reliability by ensuring network quality-of-service (QoS) for AV applications. It provides mechanisms for admission control, run time monitoring and enforcement, application feedback, and traffic prioritization.
@%systemroot%\system32\drivers\ndisimplatform.sys,-501 : Microsoft Network Adapter Multiplexor Protocol
@%systemroot%\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8196 : Receives activation requests over the net.pipe protocol and passes them to the Windows Process Activation Service.
@%systemroot%\system32\drivers\mpsdrv.sys,-23092 : Windows Defender Firewall Authorization Driver
@%systemroot%\system32\printworkflowservice.dll,-100 : PrintWorkflow
@%windir%\system32\inetsrv\iisres.dll,-30015 : Provides W3C logging for Internet Information Services (IIS). If this service is stopped, W3C logging configured by IIS will not work.
@%systemroot%\system32\appvclient.exe,-102 : Microsoft App-V Client
@%systemroot%\system32\drivers\mslbfoprovider.sys,-501 : Microsoft Load Balancing/Failover Provider
@%systemroot%\system32\hnetcfgclient.dll,-201 : HNetCfg Client
@%systemroot%\system32\umpo.dll,-101 : Manages power policy and power policy notification delivery.
@%programfiles%\windows defender\mpasdesc.dll,-330 : Windows Defender Antivirus Mini-Filter Driver
@fssmres.dll,-100 : File Server Remote Management
@%systemroot%\system32\sensorservice.dll,-1000 : Sensor Service
@combase.dll,-5011 : The RPCSS service is the Service Control Manager for COM and DCOM servers. It performs object activations requests, object exporter resolutions and distributed garbage collection for COM and DCOM servers. If this service is stopped or disabled, programs using COM or DCOM will not function properly. It is strongly recommended that you have the RPCSS service running.
@%systemroot%\syswow64\perfhost.exe,-2 : Performance Counter DLL Host
@%systemroot%\system32\upnphost.dll,-214 : Allows UPnP devices to be hosted on this computer. If this service is stopped, any hosted UPnP devices will stop functioning and no additional hosted devices can be added. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\lfsvc.dll,-2 : This service monitors the current location of the system and manages geofences (a geographical location with associated events). If you turn off this service, applications will be unable to use or receive notifications for geolocation or geofences.
@%systemroot%\system32\storsvc.dll,-100 : Storage Service
@%systemroot%\system32\drivers\mslldp.sys,-211 : Microsoft LLDP Protocol Driver
@%systemroot%\system32\dssvc.dll,-10003 : Data Sharing Service
@%systemroot%\system32\svsvc.dll,-102 : Verifies potential file system corruptions.
@%systemroot%\system32\sgrmbroker.exe,-101 : Monitors and attests to the integrity of the Windows platform.
@%systemroot%\system32\polstore.dll,-5010 : IPsec Policy Agent
@%systemroot%\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8201 : Net.Tcp Port Sharing Service
@%windir%\system32\inetsrv\iisres.dll,-30011 : Application Host Helper Service
@%systemroot%\system32\printworkflowservice.dll,-101 : Print Workflow
@peerdistsh.dll,-9002 : BranchCache - Hosted Cache Server (Uses HTTPS)
@%systemroot%\system32\lmhsvc.dll,-101 : TCP/IP NetBIOS Helper
@%systemroot%\system32\mprmsg.dll,-32012 : Remote Access IPv6 ARP Driver
@%systemroot%\system32\cdpsvc.dll,-100 : Connected Devices Platform Service
@%systemroot%\system32\defragsvc.dll,-102 : Helps the computer run more efficiently by optimizing files on storage drives.
@%systemroot%\system32\sppsvc.exe,-100 : Enables the download, installation and enforcement of digital licenses for Windows and Windows applications. If the service is disabled, the operating system and licensed applications may run in a notification mode. It is strongly recommended that you not disable the Software Protection service.
@gpapi.dll,-113 : The service is responsible for applying settings configured by administrators for the computer and users through the Group Policy component. If the service is disabled, the settings will not be applied and applications and components will not be manageable through Group Policy. Any components or applications that depend on the Group Policy component might not be functional if the service is disabled.
@%windir%\system32\bisrv.dll,-101 : Windows infrastructure service that controls which background tasks can run on the system.
@%systemroot%\system32\polstore.dll,-5011 : Internet Protocol security (IPsec) supports network-level peer authentication, data origin authentication, data integrity, data confidentiality (encryption), and replay protection. This service enforces IPsec policies created through the IP Security Policies snap-in or the command-line tool ""netsh ipsec"". If you stop this service, you may experience network connectivity issues if your policy requires that connections use IPsec. Also,remote management of Windows Defender Firewall is not available when this service is stopped.
@%programfiles%\windows media player\wmpnetwk.exe,-101 : Windows Media Player Network Sharing Service
@%systemroot%\system32\tapisrv.dll,-10100 : Telephony
@%systemroot%\system32\wephostsvc.dll,-101 : Windows Encryption Provider Host Service brokers encryption related functionalities from 3rd Party Encryption Providers to processes that need to evaluate and apply EAS policies. Stopping this will compromise EAS compliancy checks that have been established by the connected Mail Accounts
@%systemroot%\system32\themeservice.dll,-8193 : Provides user experience theme management.
@%systemroot%\system32\firewallapi.dll,-38521 : World Wide Web Services (HTTP)
@%systemroot%\system32\dosvc.dll,-100 : Delivery Optimization
@%systemroot%\system32\wkssvc.dll,-1000 : Redirected Buffering Sub System
@%systemroot%\system32\ngcsvc.dll,-101 : Provides process isolation for cryptographic keys used to authenticate to a user’s associated identity providers. If this service is disabled, all uses and management of these keys will not be available, which includes machine logon and single-sign on for apps and websites. This service starts and stops automatically. It is recommended that you do not reconfigure this service.
@%systemroot%\system32\eapsvc.dll,-1 : Extensible Authentication Protocol
@%systemroot%\system32\cdpusersvc.dll,-100 : Connected Devices Platform User Service
@gpapi.dll,-115 : Provides a network service that processes requests to simulate application of Group Policy settings for a target user or computer in various situations and computes the Resultant Set of Policy settings.
@%systemroot%\system32\sensordataservice.exe,-102 : Delivers data from a variety of sensors
@peerdistsh.dll,-9001 : BranchCache - Peer Discovery (Uses WSD)
@%systemroot%\system32\bridgeres.dll,-1 : Microsoft MAC Bridge
@%windir%\system32\drivers\pacer.sys,-100 : Quality of Service Packet Scheduler. This component provides network traffic control, including rate-of-flow and prioritization services.
@%systemroot%\system32\hvhostsvc.dll,-101 : Provides an interface for the Hyper-V hypervisor to provide per-partition performance counters to the host operating system.
@%systemroot%\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8195 : Net.Msmq Listener Adapter
@%systemroot%\microsoft.net\framework64\v4.0.30319\aspnet_rc.dll,-1 : ASP.NET State Service
@%systemroot%\system32\tapisrv.dll,-10101 : Provides Telephony API (TAPI) support for programs that control telephony devices on the local computer and, through the LAN, on servers that are also running the service.
@%systemroot%\system32\ngcctnrsvc.dll,-2 : Manages local user identity keys used to authenticate user to identity providers as well as TPM virtual smart cards. If this service is disabled, local user identity keys and TPM virtual smart cards will not be accessible. It is recommended that you do not reconfigure this service.
@%windir%\system32\lsm.dll,-1002 : Core Windows Service that manages local user sessions. Stopping or disabling this service will result in system instability.
@%windir%\system32\inetsrv\iisres.dll,-30012 : Provides administrative services for IIS, for example configuration history and Application Pool account mapping. If this service is stopped, configuration history and locking down files or directories with Application Pool specific Access Control Entries will not work.
@peerdistsh.dll,-9000 : BranchCache - Content Retrieval (Uses HTTP)
@c:\windows\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8199 : Net.Tcp Listener Adapter
@%systemroot%\system32\smphost.dll,-102 : Microsoft Storage Spaces SMP
@%systemroot%\system32\appreadiness.dll,-1001 : Gets apps ready for use the first time a user signs in to this PC and when adding new apps.
@netlogon.dll,-1010 : Netlogon Service
@%systemroot%\system32\lltdres.dll,-1 : Link-Layer Topology Discovery Mapper
@%systemroot%\system32\drivers\fileinfo.sys,-100 : File Information FS MiniFilter
@%systemroot%\system32\schedsvc.dll,-100 : Task Scheduler
@gpapi.dll,-114 : Resultant Set of Policy Provider
@%systemroot%\system32\diagsvcs\diagnosticshub.standardcollector.serviceres.dll,-1000 : Microsoft (R) Diagnostics Hub Standard Collector Service
@%systemroot%\system32\drivers\clfs.sys,-100 : Common Log (CLFS)
@%systemroot%\system32\sppsvc.exe,-101 : Software Protection
@%systemroot%\system32\drivers\wfplwfs.sys,-6000 : Microsoft Windows Filtering Platform
@%systemroot%\system32\fdphost.dll,-101 : The FDPHOST service hosts the Function Discovery (FD) network discovery providers. These FD providers supply network discovery services for the Simple Services Discovery Protocol (SSDP) and Web Services – Discovery (WS-D) protocol. Stopping or disabling the FDPHOST service will disable network discovery for these protocols when using FD. When this service is unavailable, network services using FD and relying on these discovery protocols will be unable to find network devices or resources.
@%systemroot%\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8194 : Receives activation requests over the net.msmq and msmq.formatname protocols and passes them to the Windows Process Activation Service.
@keyiso.dll,-101 : The CNG key isolation service is hosted in the LSA process. The service provides key process isolation to private keys and associated cryptographic operations as required by the Common Criteria. The service stores and uses long-lived keys in a secure process complying with Common Criteria requirements.
@%windir%\system32\timebrokerserver.dll,-1001 : Time Broker
@%systemroot%\system32\nsisvc.dll,-200 : Network Store Interface Service
@%systemroot%\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8197 : Net.Pipe Listener Adapter
@appmgmts.dll,-3251 : Processes installation, removal, and enumeration requests for software deployed through Group Policy. If the service is disabled, users will be unable to install, remove, or enumerate software deployed through Group Policy. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\pushtoinstall.dll,-200 : Windows PushToInstall Service
@%systemroot%\system32\drivers\cnghwassist.sys,-100 : CNG Hardware Assist algorithm provider
@%systemroot%\system32\tokenbroker.dll,-100 : Web Account Manager
@%systemroot%\system32\spoolsv.exe,-2 : This service spools print jobs and handles interaction with the printer. If you turn off this service, you won’t be able to print or see your printers.
@%systemroot%\system32\icsvc.dll,-301 : Hyper-V Guest Shutdown Service
@%systemroot%\system32\defragsvc.dll,-101 : Optimize drives
@%systemroot%\system32\axinstsv.dll,-103 : ActiveX Installer (AxInstSV)
@%systemroot%\system32\drivers\indirectkmd.sys,-100 : Indirect Displays Kernel-Mode Driver
@%systemroot%\system32\windowspowershell\v1.0\powershell.exe,-124 : Document Encryption
@%systemroot%\system32\hvhostsvc.dll,-100 : HV Host Service
@%systemroot%\system32\capabilityaccessmanager.dll,-2 : Provides facilities for managing UWP apps access to app capabilities as well as checking an app's access to specific app capabilities
@%systemroot%\system32\sgrmbroker.exe,-100 : System Guard Runtime Monitor Broker
@%systemroot%\system32\windows.internal.management.dll,-100 : Device Management Enrollment Service
@%systemroot%\system32\icsvc.dll,-902 : Provides a mechanism to manage virtual machine with PowerShell via VM session without a virtual network.
@%systemroot%\system32\srpapi.dll,-102 : Smartlocker Filter Driver
@%systemroot%\system32\ncasvc.dll,-3008 : Provides DirectAccess status notification for UI components
@%systemroot%\system32\pcasvc.dll,-1 : Program Compatibility Assistant Service
@%systemroot%\system32\wiaservc.dll,-9 : Windows Image Acquisition (WIA)
@%systemroot%\system32\drivers\appvvemgr.sys,-101 : AppvVemgr
@%systemroot%\system32\icsvc.dll,-801 : Hyper-V Guest Service Interface
@%systemroot%\system32\netman.dll,-109 : Network Connections
@mqutil.dll,-6104 : Provides a messaging infrastructure and development tool for creating distributed messaging applications for Windows-based networks and programs. If this service is stopped, distributed messages will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\scdeviceenum.dll,-100 : Smart Card Device Enumeration Service
c:\windows\system32,@elscore.dll,-7 : Microsoft Devanagari to Latin Transliteration
@%systemroot%\system32\drivers\volmgrx.sys,-100 : Dynamic Volume Manager
@%systemroot%\system32\fdrespub.dll,-100 : Function Discovery Resource Publication
@comres.dll,-2451 : Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\nlasvc.dll,-2 : Collects and stores configuration information for the network and notifies programs when this information is modified. If this service is stopped, configuration information might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\ncasvc.dll,-3009 : Network Connectivity Assistant
@%systemroot%\system32\mprmsg.dll,-32002 : Remote Access NDIS WAN Driver
@%systemroot%\system32\rmapi.dll,-1002 : Radio Management and Airplane Mode Service
c:\windows\system32,@elscore.dll,-3 : Microsoft Traditional Chinese to Simplified Chinese Transliteration
@%systemroot%\system32\alg.exe,-113 : Provides support for 3rd party protocol plug-ins for Internet Connection Sharing
@%systemroot%\system32\das.dll,-101 : Enables pairing between the system and wired or wireless devices.
@%systemroot%\system32\samsrv.dll,-2 : The startup of this service signals other services that the Security Accounts Manager (SAM) is ready to accept requests. Disabling this service will prevent other services in the system from being notified when the SAM is ready, which may in turn cause those services to fail to start correctly. This service should not be disabled.
@%systemroot%\system32\audiosrv.dll,-200 : Windows Audio
@keyiso.dll,-100 : CNG Key Isolation
@%systemroot%\system32\umrdp.dll,-1000 : Remote Desktop Services UserMode Port Redirector
@%systemroot%\system32\powrprof.dll,-15 : Balanced
@%systemroot%\system32\wpdbusenum.dll,-101 : Enforces group policy for removable mass-storage devices. Enables applications such as Windows Media Player and Image Import Wizard to transfer and synchronize content using removable mass-storage devices.
@%systemroot%\system32\termsrv.dll,-268 : Remote Desktop Services
@%systemroot%\system32\samsrv.dll,-1 : Security Accounts Manager
@%systemroot%\system32\ipnathlp.dll,-106 : Internet Connection Sharing (ICS)
@%systemroot%\system32\semgrsvc.dll,-1001 : Payments and NFC/SE Manager
@%systemroot%\system32\srvsvc.dll,-110 : Allows other computers to access resources on your computer using a Microsoft network.
@%systemroot%\system32\ci.dll,-101 : Enclave
@%systemroot%\system32\powrprof.dll,-13 : High performance
@%systemroot%\system32\usermgr.dll,-101 : User Manager provides the runtime components required for multi-user interaction. If this service is stopped, some applications may not operate correctly.
@%systemroot%\microsoft.net\framework64\v4.0.30319\servicemodelevents.dll,-2002 : Windows Communication Foundation
@%systemroot%\system32\drivers\hvservice.sys,-16 : Hypervisor/Virtual Machine Support Driver
@%systemroot%\system32\cscsvc.dll,-200 : Offline Files
@%systemroot%\system32\firewallapi.dll,-37302 : mDNS
@%systemroot%\system32\fntcache.dll,-100 : Windows Font Cache Service
@%systemroot%\system32\audioendpointbuilder.dll,-204 : Windows Audio Endpoint Builder
@%programfiles%\windows defender\mpasdesc.dll,-370 : Windows Defender Antivirus Network Inspection System Driver
@%systemroot%\system32\windows.staterepository.dll,-1 : State Repository Service
@%systemroot%\system32\mprdim.dll,-200 : Routing and Remote Access
@%systemroot%\system32\userdataaccessres.dll,-10003 : User Data Storage
@%systemroot%\system32\tokenbroker.dll,-101 : This service is used by Web Account Manager to provide single-sign-on to apps and services.
@%windir%\system32\inetsrv\iisres.dll,-30001 : Windows Process Activation Service
@%systemroot%\system32\cryptsvc.dll,-1002 : Provides three management services: Catalog Database Service, which confirms the signatures of Windows files and allows new programs to be installed; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Automatic Root Certificate Update Service, which retrieves root certificates from Windows Update and enable scenarios such as SSL. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\netlogon.dll,-102 : Netlogon
@%systemroot%\system32\drivers\msseccore.sys,-1001 : Microsoft Security Core Boot Driver
@%windir%\system32\drivers\pacer.sys,-101 : QoS Packet Scheduler
@%systemroot%\system32\semgrsvc.dll,-1002 : Manages payments and Near Field Communication (NFC) based secure elements.
@%systemroot%\system32\drivers\pdc.sys,-100 : PDC
@winlangdb.dll,-1114 : English (India)
@%systemroot%\system32\firewallapi.dll,-23090 : Windows Defender Firewall
@firewallapi.dll,-50323 : SNMP Trap
@%systemroot%\system32\mprmsg.dll,-32014 : Remote Access LEGACY NDIS WAN Driver
@%systemroot%\system32\mprmsg.dll,-32013 : IP Traffic Filter Driver
@%systemroot%\system32\drivers\fltmgr.sys,-10001 : FltMgr
@%systemroot%\system32\moshost.dll,-101 : Windows service for application access to downloaded maps. This service is started on-demand by application accessing downloaded maps. Disabling this service will prevent apps from accessing maps.
@%systemroot%\system32\drivers\wcnfs.sys,-100 : Windows Container Name Virtualization
@%systemroot%\system32\devicesflowbroker.dll,-104 : Allows ConnectUX and PC Settings to Connect and Pair with WiFi displays and Bluetooth devices.
@%systemroot%\system32\wdi.dll,-502 : Diagnostic Service Host
@%systemroot%\system32\drivers\mssecflt.sys,-1001 : Microsoft Security Events Component Minifilter
@%systemroot%\system32\presentationhost.exe,-3310 : Optimizes performance of Windows Presentation Foundation (WPF) applications by caching commonly used font data. WPF applications will start this service if it is not already running. It can be disabled, though doing so will degrade the performance of WPF applications.
@%systemroot%\system32\wuaueng.dll,-400 : Windows Update
@%systemroot%\system32\drivers\verifierext.sys,-1000 : Driver Verifier Extension
@%systemroot%\system32\tzautoupdate.dll,-200 : Auto Time Zone Updater
@%systemroot%\system32\wpnuserservice.dll,-1 : Windows Push Notifications User Service
@%systemroot%\system32\cdpsvc.dll,-101 : This service is used for Connected Devices Platform scenarios
@%systemroot%\system32\userdataaccessres.dll,-15001 : Contact Data
@%systemroot%\system32\securityhealthagent.dll,-1001 : Windows Security Service handles unified device protection and health information
@%windir%\system32\rpcepmap.dll,-1001 : RPC Endpoint Mapper
@%systemroot%\system32\drivers\mshidkmdf.sys,-100 : Pass-through HID to KMDF Filter Driver
@%systemroot%\system32\powrprof.dll,-12 : Favors performance, but may use more energy.
@%systemroot%\system32\sessenv.dll,-1027 : Remote Desktop Configuration service (RDCS) is responsible for all Remote Desktop Services and Remote Desktop related configuration and session maintenance activities that require SYSTEM context. These include per-session temporary folders, RD themes, and RD certificates.
@%systemroot%\system32\w32time.dll,-200 : Windows Time
@%systemroot%\system32\kpssvc.dll,-100 : KDC Proxy Server service (KPS)
@%systemroot%\system32\tetheringservice.dll,-4097 : Windows Mobile Hotspot Service
@%systemroot%\system32\windows.staterepository.dll,-2 : Provides required infrastructure support for the application model.
@%systemroot%\system32\rasauto.dll,-201 : Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address.
@%systemroot%\system32\flightsettings.dll,-103 : Windows Insider Service
@%systemroot%\system32\drivers\http.sys,-1 : HTTP Service
@%systemroot%\system32\walletservice.dll,-1000 : WalletService
@%windir%\system32\inetsrv\iisres.dll,-30008 : Enables this server to administer the IIS metabase. The IIS metabase stores configuration for the SMTP and FTP services. If this service is stopped, the server will be unable to configure SMTP or FTP. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\umpnpmgr.dll,-101 : Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability.
@%systemroot%\system32\drivers\netbt.sys,-2 : NETBT
@%systemroot%\system32\drivers\ipsecgw.sys,-10001 : Windows IPsec Gateway Driver
@%systemroot%\servicing\trustedinstaller.exe,-101 : Enables installation, modification, and removal of Windows updates and optional components. If this service is disabled, install or uninstall of Windows updates might fail for this computer.
@%systemroot%\system32\icsvc.dll,-202 : Provides a mechanism to exchange data between the virtual machine and the operating system running on the physical computer.
@%systemroot%\system32\umpnpmgr.dll,-200 : Plug and Play
@%systemroot%\system32\certprop.dll,-13 : Smart Card Removal Policy
@comres.dll,-2946 : KtmRm for Distributed Transaction Coordinator
@%systemroot%\system32\nlasvc.dll,-1 : Network Location Awareness
@icsvc.dll,-700 : Virtual Machine Monitoring
c:\windows\system32,@elscore.dll,-4 : Microsoft Simplified Chinese to Traditional Chinese Transliteration
@%systemroot%\system32\iscsidsc.dll,-5000 : Microsoft iSCSI Initiator Service
@%systemroot%\system32\srvsvc.dll,-109 : File and Printer Sharing for Microsoft Networks
@%systemroot%\system32\coremessaging.dll,-1 : CoreMessaging
@%systemroot%\system32\drivers\wdf01000.sys,-1000 : Kernel Mode Driver Frameworks service
@%systemroot%\system32\audioendpointbuilder.dll,-205 : Manages audio devices for the Windows Audio service. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start
@%systemroot%\system32\scdeviceenum.dll,-101 : Creates software device nodes for all smart card readers accessible to a given session. If this service is disabled, WinRT APIs will not be able to enumerate smart card readers.
@%systemroot%\system32\msimsg.dll,-32 : Adds, modifies, and removes applications provided as a Windows Installer (*.msi, *.msp) package. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\ajrouter.dll,-1 : Routes AllJoyn messages for the local AllJoyn clients. If this service is stopped the AllJoyn clients that do not have their own bundled routers will be unable to run.
@%systemroot%\system32\ngcctnrsvc.dll,-1 : Microsoft Passport Container
@%systemroot%\system32\drivers\tcpip.sys,-10101 : Transmission Control Protocol/Internet Protocol. The default wide area network protocol that provides communication across diverse interconnected networks.
@%systemroot%\system32\vds.exe,-112 : Provides management services for disks, volumes, file systems, and storage arrays.
@%systemroot%\system32\powrprof.dll,-10 : Saves energy by reducing your computer’s performance where possible.
@%systemroot%\system32\ssdpsrv.dll,-100 : SSDP Discovery
@%systemroot%\system32\sstpsvc.dll,-202 : WAN Miniport (SSTP)
@%systemroot%\system32\embeddedmodesvc.dll,-202 : The Embedded Mode service enables scenarios related to Background Applications. Disabling this service will prevent Background Applications from being activated.
@%programfiles%\windows defender advanced threat protection\mssense.exe,-1002 : Windows Defender Advanced Threat Protection service helps protect against advanced threats by monitoring and reporting security events that happen on the computer.
@%systemroot%\system32\windows.warp.jitservice.dll,-101 : Provides a JIT out of process service for WARP when running with ACG enabled.
@%systemroot%\system32\drivers\sgrmagent.sys,-1001 : System Guard Runtime Monitor Agent
@%systemroot%\system32\profsvc.dll,-301 : This service is responsible for loading and unloading user profiles. If this service is stopped or disabled, users will no longer be able to successfully sign in or sign out, apps might have problems getting to users' data, and components registered to receive profile event notifications won't receive them.
@%systemroot%\system32\seclogon.dll,-7001 : Secondary Logon
@appmgmts.dll,-3250 : Application Management
@%systemroot%\system32\iscsidsc.dll,-5001 : Manages Internet SCSI (iSCSI) sessions from this computer to remote iSCSI target devices. If this service is stopped, this computer will not be able to login or access iSCSI targets. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\umrdp.dll,-1001 : Allows the redirection of Printers/Drives/Ports for RDP connections
@%systemroot%\system32\wkssvc.dll,-1008 : DFS Namespace Client Driver
@%systemroot%\system32\lmhsvc.dll,-102 : Provides support for the NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution for clients on the network, therefore enabling users to share files, print, and log on to the network. If this service is stopped, these functions might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\lltdres.dll,-6 : Link-Layer Topology Discovery Mapper I/O Driver
@%systemroot%\system32\pla.dll,-501 : Performance Logs and Alerts Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\drivers\hwpolicy.sys,-101 : Hardware Policy Driver
@%systemroot%\system32\wcmsvc.dll,-4097 : Windows Connection Manager
@%systemroot%\system32\wsmsvc.dll,-102 : Windows Remote Management (WinRM) service implements the WS-Management protocol for remote management. WS-Management is a standard web services protocol used for remote software and hardware management. The WinRM service listens on the network for WS-Management requests and processes them. The WinRM Service needs to be configured with a listener using winrm.cmd command line tool or through Group Policy in order for it to listen over the network. The WinRM service provides access to WMI data and enables event collection. Event collection and subscription to events require that the service is running. WinRM messages use HTTP and HTTPS as transports. The WinRM service does not depend on IIS but is preconfigured to share a port with IIS on the same machine. The WinRM service reserves the /wsman URL prefix. To prevent conflicts with IIS, administrators should ensure that any websites hosted on IIS do not use the /wsman URL prefix.
@%systemroot%\system32\tieringengineservice.exe,-702 : Storage Tiers Management
@%systemroot%\system32\dps.dll,-500 : Diagnostic Policy Service
@%systemroot%\system32\sensrsvc.dll,-1001 : Monitors various sensors in order to expose data and adapt to system and user state. If this service is stopped or disabled, the display brightness will not adapt to lighting conditions. Stopping this service may affect other system functionality and features as well.
@%systemroot%\system32\dnsapi.dll,-103 : Domain Name System (DNS) Server Trust
c:\windows\system32,@elscore.dll,-1 : Microsoft Language Detection
@%systemroot%\system32\axinstsv.dll,-104 : Provides User Account Control validation for the installation of ActiveX controls from the Internet and enables management of ActiveX control installation based on Group Policy settings. This service is started on demand and if disabled the installation of ActiveX controls will behave according to default browser settings.
@%systemroot%\system32\mprmsg.dll,-32001 : Remote Access NDIS TAPI Driver
@%systemroot%\system32\drivers\mup.sys,-101 : MUP
@%systemroot%\system32\storsvc.dll,-101 : Provides enabling services for storage settings and external storage expansion
@enterpriseappmgmtsvc.dll,-2 : Enables enterprise application management.
@%systemroot%\system32\windows.sharedpc.accountmanager.dll,-100 : Shared PC Account Manager
@%systemroot%\system32\netsetupsvc.dll,-3 : Network Setup Service
@%systemroot%\system32\netlogon.dll,-103 : Maintains a secure channel between this computer and the domain controller for authenticating users and services. If this service is stopped, the computer may not authenticate users and services and the domain controller cannot register DNS records. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\scardsvr.dll,-1 : Smart Card
@%systemroot%\system32\clipsvc.dll,-104 : Provides infrastructure support for the Microsoft Store. This service is started on demand and if disabled applications bought using Windows Store will not behave correctly.
@%systemroot%\servicing\trustedinstaller.exe,-100 : Windows Modules Installer
@%systemroot%\system32\pushtoinstall.dll,-201 : Provides infrastructure support for the Microsoft Store. This service is started automatically and if disabled then remote installations will not function properly.
@%systemroot%\system32\icsvcext.dll,-601 : Hyper-V Remote Desktop Virtualization Service
@%systemroot%\system32\drivers\mslldp.sys,-210 : IEEE 802.1AB Link-Layer Discovery Protocol (LLDP). Supports Microsoft Data Center Networking (DCN).
@%systemroot%\system32\phoneserviceres.dll,-10001 : Manages the telephony state on the device
@%systemroot%\system32\dot3svc.dll,-1103 : The Wired AutoConfig (DOT3SVC) service is responsible for performing IEEE 802.1X authentication on Ethernet interfaces. If your current wired network deployment enforces 802.1X authentication, the DOT3SVC service should be configured to run for establishing Layer 2 connectivity and/or providing access to network resources. Wired networks that do not enforce 802.1X authentication are unaffected by the DOT3SVC service.
@comres.dll,-948 : Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\dmwappushsvc.dll,-201 : Routes Wireless Application Protocol (WAP) Push messages received by the device and synchronizes Device Management sessions
@%systemroot%\system32\wkssvc.dll,-100 : Workstation
@%systemroot%\system32\netprofmsvc.dll,-202 : Network List Service
@waasmedicsvc.dll,-100 : Windows Update Medic Service
@%systemroot%\system32\efssvc.dll,-100 : Encrypting File System (EFS)
@%systemroot%\system32\wkssvc.dll,-1002 : SMB MiniRedirector Wrapper and Engine
@%systemroot%\system32\drivers\filecrypt.sys,-100 : FileCrypt
@%systemroot%\system32\captureservice.dll,-100 : CaptureService
@%windir%\system32\systemeventsbrokerserver.dll,-1002 : Coordinates execution of background work for WinRT application. If this service is stopped or disabled, then background work might not be triggered.
@%systemroot%\system32\shsvcs.dll,-12289 : Provides notifications for AutoPlay hardware events.
@%systemroot%\system32\icsvcext.dll,-602 : Provides a platform for communication between the virtual machine and the operating system running on the physical computer.
@%systemroot%\system32\dhcpcore.dll,-101 : Registers and updates IP addresses and DNS records for this computer. If this service is stopped, this computer will not receive dynamic IP addresses and DNS updates. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\powrprof.dll,-14 : Automatically balances performance with energy consumption on capable hardware.
@%systemroot%\system32\wercplsupport.dll,-101 : Problem Reports and Solutions Control Panel Support
@%windir%\system32\inetsrv\iisres.dll,-30004 : Provides Web connectivity and administration through the Internet Information Services Manager
@%windir%\system32\inetsrv\iisres.dll,-30007 : IIS Admin Service
@%systemroot%\system32\dmwappushsvc.dll,-200 : Device Management Wireless Application Protocol (WAP) Push message Routing Service
@%systemroot%\system32\devicesetupmanager.dll,-1000 : Device Setup Manager
@%systemroot%\system32\rasmans.dll,-200 : Remote Access Connection Manager
@%systemroot%\system32\drivers\tcpip.sys,-10100 : Internet Protocol Version 4 (TCP/IPv4)
@%systemroot%\system32\swprv.dll,-103 : Microsoft Software Shadow Copy Provider
@%systemroot%\system32\drivers\tcpip.sys,-10102 : Internet Protocol Version 6 (TCP/IPv6)
c:\windows\system32,@elscore.dll,-9 : Microsoft Bengali to Latin Transliteration
@%systemroot%\system32\icsvc.dll,-402 : Synchronizes the system time of this virtual machine with the system time of the physical computer.
@%systemroot%\system32\firewallapi.dll,-23091 : Windows Defender Firewall helps protect your computer by preventing unauthorized users from gaining access to your computer through the Internet or a network.
@%systemroot%\system32\wkssvc.dll,-1010 : Client for Microsoft Networks
@%systemroot%\system32\tzautoupdate.dll,-201 : Automatically sets the system time zone.
@%systemroot%\system32\usocore.dll,-102 : Manages Windows Updates. If stopped, your devices will not be able download and install latest udpates.
@%systemroot%\system32\cbdhsvc.dll,-100 : Clipboard User Service
@%systemroot%\system32\iphlpsvc.dll,-501 : Provides tunnel connectivity using IPv6 transition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS. If this service is stopped, the computer will not have the enhanced connectivity benefits that these technologies offer.
@%systemroot%\system32\seclogon.dll,-7000 : Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\drivers\ahcache.sys,-102 : Application Compatibility Cache
@%systemroot%\system32\ncbservice.dll,-500 : Network Connection Broker
@%systemroot%\system32\iphlpsvc.dll,-500 : IP Helper
@%systemroot%\system32\diagsvcs\diagnosticshub.standardcollector.serviceres.dll,-1001 : Diagnostics Hub Standard Collector Service. When running, this service collects real time ETW events and processes them.
@%systemroot%\system32\icsvc.dll,-901 : Hyper-V PowerShell Direct Service
@c:\windows\system32\spool\drivers\x64\3\printconfig.dll,-1 : Printer Extensions and Notifications
@%systemroot%\system32\installservice.dll,-200 : Microsoft Store Install Service
@%systemroot%\system32\searchindexer.exe,-104 : Provides content indexing, property caching, and search results for files, e-mail, and other content.
@%systemroot%\system32\windows.warp.jitservice.dll,-100 : WarpJITSvc
@%systemroot%\system32\icsvcext.dll,-502 : Coordinates the communications that are required to use Volume Shadow Copy Service to back up applications and data on this virtual machine from the operating system on the physical computer.
@%systemroot%\system32\lfsvc.dll,-1 : Geolocation Service
@%systemroot%\system32\wbem\wmiapsrv.exe,-111 : Provides performance library information from Windows Management Instrumentation (WMI) providers to clients on the network. This service only runs when Performance Data Helper is activated.
@%systemroot%\system32\licensemanagersvc.dll,-200 : Windows License Manager Service
@%systemroot%\system32\drivers\mshidumdf.sys,-100 : Pass-through HID to UMDF Driver
@%systemroot%\system32\appvclient.exe,-101 : Manages App-V users and virtual applications
@%systemroot%\system32\lltdres.dll,-2 : Creates a Network Map, consisting of PC and device topology (connectivity) information, and metadata describing each PC and device. If this service is disabled, the Network Map will not function properly.
@%systemroot%\system32\vaultsvc.dll,-1003 : Credential Manager
@%systemroot%\system32\drivers\storqosflt.sys,-101 : Storage QoS Filter Driver
@%systemroot%\system32\wpnuserservice.dll,-2 : This service hosts Windows notification platform which provides support for local and push notifications. Supported notifications are tile, toast and raw.
@%windir%\system32\inetsrv\iisres.dll,-30003 : World Wide Web Publishing Service
@%systemroot%\system32\wersvc.dll,-100 : Windows Error Reporting Service
@%systemroot%\system32\clipsvc.dll,-103 : Client License Service (ClipSVC)
@%systemroot%\system32\ualsvc.dll,-102 : User Access Logging Service
@combase.dll,-5012 : DCOM Server Process Launcher
@%systemroot%\system32\scardsvr.dll,-5 : Manages access to smart cards read by this computer. If this service is stopped, this computer will be unable to read smart cards. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\firewallapi.dll,-38523 : Secure World Wide Web Services (HTTPS)
@%systemroot%\system32\mprmsg.dll,-32007 : Remote Access PPPOE Driver
@%systemroot%\system32\shsvcs.dll,-12288 : Shell Hardware Detection
@%systemroot%\system32\drivers\ndisimplatform.sys,-500 : Provides a platform for network adapter load balancing and fail-over.
@%systemroot%\system32\wlidsvc.dll,-101 : Enables user sign-in through Microsoft account identity services. If this service is stopped, users will not be able to logon to the computer with their Microsoft account.
@%systemroot%\system32\dosvc.dll,-101 : Performs content delivery optimization tasks
@%systemroot%\system32\lltdres.dll,-4 : Used to discover and locate other PCs, devices, and network infrastructure components on the network. Also used to determine network bandwidth.
@%programfiles%\windows defender\mpasdesc.dll,-240 : Helps protect users from malware and other potentially unwanted software
@%systemroot%\system32\wkssvc.dll,-101 : Creates and maintains client network connections to remote servers using the SMB protocol. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\cbdhsvc.dll,-101 : This user service is used for Clipboard scenarios
@%systemroot%\system32\trkwks.dll,-1 : Distributed Link Tracking Client
@%systemroot%\system32\sensrsvc.dll,-1000 : Sensor Monitoring Service
@%windir%\system32\lsm.dll,-1001 : Local Session Manager
@%systemroot%\system32\dps.dll,-501 : The Diagnostic Policy Service enables problem detection, troubleshooting and resolution for Windows components. If this service is stopped, diagnostics will no longer function.
@%systemroot%\system32\drivers\luafv.sys,-100 : UAC File Virtualization
@%systemroot%\system32\userdataaccessres.dll,-15000 : Indexes contact data for fast contact searching. If you stop or disable this service, contacts might be missing from your search results.
@%systemroot%\system32\windows.devices.picker.dll,-1007 : This user service is used for managing the Miracast, DLNA, and DIAL UI
@%systemroot%\system32\icsvc.dll,-802 : Provides an interface for the Hyper-V host to interact with specific services running inside the virtual machine.
@%systemroot%\system32\sessenv.dll,-1026 : Remote Desktop Configuration
@%systemroot%\system32\nsisvc.dll,-201 : This service delivers network notifications (e.g. interface addition/deleting etc) to user mode clients. Stopping this service will cause loss of network connectivity. If this service is disabled, any other services that explicitly depend on this service will fail to start.
@%systemroot%\system32\btagservice.dll,-101 : Bluetooth Audio Gateway Service
@%systemroot%\system32\userdataaccessres.dll,-10002 : Handles storage of structured user data, including contact info, calendars, messages, and other content. If you stop or disable this service, apps that use this data might not work correctly.
c:\windows\system32,@elscore.dll,-10 : Microsoft Hangul Decomposition Transliteration
@%systemroot%\system32\windows.sharedpc.accountmanager.dll,-101 : Manages profiles and accounts on a SharedPC configured device
@%systemroot%\system32\ngcrecovery.dll,-100 : Windows Hello Recovery Key Encryption
@%systemroot%\system32\usocore.dll,-101 : Update Orchestrator Service
@%systemroot%\system32\bthserv.dll,-101 : Bluetooth Support Service
@%systemroot%\system32\mprmsg.dll,-32005 : WAN Miniport (L2TP)
@%systemroot%\system32\spoolsv.exe,-1 : Print Spooler
@%systemroot%\system32\tetheringservice.dll,-4098 : Provides the ability to share a cellular data connection with another device.
@%systemroot%\system32\smphost.dll,-101 : Host service for the Microsoft Storage Spaces management provider. If this service is stopped or disabled, Storage Spaces cannot be managed.
@comres.dll,-947 : COM+ System Application
@%systemroot%\system32\drivers\wimmount.sys,-101 : WIMMount
@%systemroot%\system32\ssdpsrv.dll,-101 : Discovers networked devices and services that use the SSDP discovery protocol, such as UPnP devices. Also announces SSDP devices and services running on the local computer. If this service is stopped, SSDP-based devices will not be discovered. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\devicesetupmanager.dll,-1001 : Enables the detection, download and installation of device-related software. If this service is disabled, devices may be configured with outdated software, and may not work correctly.
@%systemroot%\system32\firewallapi.dll,-11199 : Message Queuing
@%systemroot%\system32\swprv.dll,-102 : Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\qmgr.dll,-1001 : Transfers files in the background using idle network bandwidth. If the service is disabled, then any applications that depend on BITS, such as Windows Update or MSN Explorer, will be unable to automatically download programs and other information.
@%systemroot%\system32\certprop.dll,-11 : Certificate Propagation
@comres.dll,-2798 : Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will fail. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\dssvc.dll,-10002 : Provides data brokering between applications.
@%systemroot%\system32\umpo.dll,-100 : Power
@%windir%\system32\inetsrv\iisres.dll,-30014 : W3C Logging Service
@comres.dll,-2797 : Distributed Transaction Coordinator
@%systemroot%\system32\cdpusersvc.dll,-101 : This user service is used for Connected Devices Platform scenarios
@%systemroot%\system32\wercplsupport.dll,-100 : This service provides support for viewing, sending and deletion of system-level problem reports for the Problem Reports and Solutions control panel.
@%systemroot%\system32\qwave.dll,-1 : Quality Windows Audio Video Experience
@%systemroot%\system32\drivers\tcpip.sys,-10001 : TCP/IP Protocol Driver
@firewallapi.dll,-50324 : Receives trap messages generated by local or remote Simple Network Management Protocol (SNMP) agents and forwards the messages to SNMP management programs running on this computer. If this service is stopped, SNMP-based programs on this computer will not receive SNMP trap messages. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\certprop.dll,-14 : Allows the system to be configured to lock the user desktop upon smart card removal.
@%systemroot%\system32\firewallapi.dll,-36902 : Software Load Balancer
@%systemroot%\system32\wuaueng.dll,-106 : Enables the detection, download, and installation of updates for Windows and other programs. If this service is disabled, users of this computer will not be able to use Windows Update or its automatic updating feature, and programs will not be able to use the Windows Update Agent (WUA) API.
@%systemroot%\system32\ikeext.dll,-502 : The IKEEXT service hosts the Internet Key Exchange (IKE) and Authenticated Internet Protocol (AuthIP) keying modules. These keying modules are used for authentication and key exchange in Internet Protocol security (IPsec). Stopping or disabling the IKEEXT service will disable IKE and AuthIP key exchange with peer computers. IPsec is typically configured to use IKE or AuthIP; therefore, stopping or disabling the IKEEXT service might result in an IPsec failure and might compromise the security of the system. It is strongly recommended that you have the IKEEXT service running.
@%systemroot%\system32\sensorservice.dll,-1001 : A service for sensors that manages different sensors' functionality. Manages Simple Device Orientation (SDO) and History for sensors. Loads the SDO sensor that reports device orientation changes. If this service is stopped or disabled, the SDO sensor will not be loaded and so auto-rotation will not occur. History collection from Sensors will also be stopped.
@%systemroot%\system32\capabilityaccessmanager.dll,-1 : Capability Access Manager Service
@%systemroot%\system32\drivers\dam.sys,-100 : Desktop Activity Moderator Driver
@%systemroot%\system32\agentservice.exe,-102 : User Experience Virtualization Service
@%systemroot%\system32\drivers\mountmgr.sys,-100 : Mount Point Manager
@%systemroot%\system32\wiaservc.dll,-10 : Provides image acquisition services for scanners and cameras
@%systemroot%\syswow64\perfhost.exe,-1 : Enables remote users and 64-bit processes to query performance counters provided by 32-bit DLLs. If this service is stopped, only local users and 32-bit processes will be able to query performance counters provided by 32-bit DLLs.
@%systemroot%\system32\bthserv.dll,-102 : The Bluetooth service supports discovery and association of remote Bluetooth devices. Stopping or disabling this service may cause already installed Bluetooth devices to fail to operate properly and prevent new devices from being discovered or associated.
@%systemroot%\system32\lltdres.dll,-3 : Allows this PC to be discovered and located on the network.
@%systemroot%\system32\wpnservice.dll,-2 : This service runs in session 0 and hosts the notification platform and connection provider which handles the connection between the device and WNS server.
@%windir%\system32\timebrokerserver.dll,-1002 : Coordinates execution of background work for WinRT application. If this service is stopped or disabled, then background work might not be triggered.
@%systemroot%\system32\cscsvc.dll,-202 : Offline Files Driver
@%systemroot%\system32\wkssvc.dll,-1006 : SMB 2.0 MiniRedirector
@%systemroot%\system32\alg.exe,-112 : Application Layer Gateway Service
@%systemroot%\system32\usermgr.dll,-100 : User Manager
@%systemroot%\system32\drivers\ndproxy.sys,-6000 : NDIS Proxy Driver
@mqutil.dll,-6102 : Message Queuing
@%programfiles%\windows defender advanced threat protection\mssense.exe,-1001 : Windows Defender Advanced Threat Protection Service
@%systemroot%\system32\frameserver.dll,-101 : Enables multiple clients to access video frames from camera devices.
@c:\windows\system32\firewallcontrolpanel.dll,-12122 : Windows Defender Firewall
@%systemroot%\system32\icsvcext.dll,-501 : Hyper-V Volume Shadow Copy Requestor
@%systemroot%\system32\sacsvr.dll,-500 : Special Administration Console Helper
@%systemroot%\system32\wbem\wmisvc.dll,-204 : Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\schedsvc.dll,-101 : Enables a user to configure and schedule automated tasks on this computer. The service also hosts multiple Windows system-critical tasks. If this service is stopped or disabled, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start.
@%windir%\system32\bisrv.dll,-100 : Background Tasks Infrastructure Service
@%systemroot%\system32\wersvc.dll,-101 : Allows errors to be reported when programs stop working or responding and allows existing solutions to be delivered. Also allows logs to be generated for diagnostic and repair services. If this service is stopped, error reporting might not work correctly and results of diagnostic services and repairs might not be displayed.
@%systemroot%\system32\termsrv.dll,-267 : Allows users to connect interactively to a remote computer. Remote Desktop and Remote Desktop Session Host Server depend on this service. To prevent remote use of this computer, clear the checkboxes on the Remote tab of the System properties control panel item.
@%systemroot%\system32\sens.dll,-201 : Monitors system events and notifies subscribers to COM+ Event System of these events.
@%systemroot%\system32\drivers\mssecwfp.sys,-1001 : Microsoft Security WFP Callout Driver
@%systemroot%\system32\devquerybroker.dll,-101 : Enables apps to discover devices with a backgroud task
@%systemroot%\system32\tabsvc.dll,-101 : Enables Touch Keyboard and Handwriting Panel pen and ink functionality
@%systemroot%\system32\drivers\scfilter.sys,-11 : Smart card PnP Class Filter Driver
@%systemroot%\system32\wsmsvc.dll,-101 : Windows Remote Management (WS-Management)
@%systemroot%\system32\userdataaccessres.dll,-14001 : User Data Access
@%systemroot%\system32\ncbservice.dll,-501 : Brokers connections that allow Windows Store Apps to receive notifications from the internet.
@%systemroot%\system32\wpnservice.dll,-1 : Windows Push Notifications System Service
@%systemroot%\system32\drivers\volsnap.sys,-100 : Volume Shadow Copy driver
@%systemroot%\system32\hidserv.dll,-102 : Activates and maintains the use of hot buttons on keyboards, remote controls, and other multimedia devices. It is recommended that you keep this service running.
@%systemroot%\system32\efssvc.dll,-101 : Provides the core file encryption technology used to store encrypted files on NTFS file system volumes. If this service is stopped or disabled, applications will be unable to access encrypted files.
@%systemroot%\system32\vds.exe,-100 : Virtual Disk
@%systemroot%\system32\drivers\rdpdr.sys,-100 : Remote Desktop Device Redirector Driver
@%systemroot%\system32\wdi.dll,-500 : Diagnostic System Host
@%systemroot%\system32\drivers\appvstrm.sys,-101 : AppvStrm
@%systemroot%\system32\lltdres.dll,-5 : Link-Layer Topology Discovery Responder
@%programfiles%\windows defender\mpasdesc.dll,-320 : Windows Defender Antivirus Network Inspection Service
@%systemroot%\system32\wbiosrvc.dll,-100 : Windows Biometric Service
@%systemroot%\system32\umpnpmgr.dll,-100 : Device Install Service
@%systemroot%\system32\wkssvc.dll,-1011 : Allows your computer to access resources on a Microsoft network.
@%systemroot%\system32\consentuxclient.dll,-101 : Allows ConnectUX and PC Settings to Connect and Pair with WiFi displays and Bluetooth devices.
@%systemroot%\system32\captureservice.dll,-101 : OneCore Capture Service
@%systemroot%\system32\sstpsvc.dll,-201 : Provides support for the Secure Socket Tunneling Protocol (SSTP) to connect to remote computers using VPN. If this service is disabled, users will not be able to use SSTP to access remote servers.
@%systemroot%\system32\wevtsvc.dll,-200 : Windows Event Log
@%systemroot%\system32\upnphost.dll,-213 : UPnP Device Host
@%systemroot%\system32\windows.internal.management.dll,-101 : Performs Device Enrollment Activities for Device Management
@%systemroot%\system32\diagtrack.dll,-3002 : The Connected User Experiences and Telemetry service enables features that support in-application and connected user experiences. Additionally, this service manages the event driven collection and transmission of diagnostic and usage information (used to improve the experience and quality of the Windows Platform) when the diagnostics and usage privacy option settings are enabled under Feedback and Diagnostics.
@%systemroot%\system32\svsvc.dll,-101 : Spot Verifier
@%systemroot%\system32\trkwks.dll,-2 : Maintains links between NTFS files within a computer or across computers in a network.
@%systemroot%\system32\drivers\wpdupfltr.sys,-100 : WPD Upper Class Filter Driver
@%systemroot%\system32\drivers\partmgr.sys,-100 : Partition driver
@%systemroot%\system32\ci.dll,-100 : Isolated User Mode (IUM)
@%systemroot%\system32\drivers\filetrace.sys,-10001 : FileTrace
@%systemroot%\system32\urlmon.dll,-4200 : Open File - Security Warning
@%systemroot%\system32\wecsvc.dll,-200 : Windows Event Collector
@%systemroot%\system32\drivers\wudfpf.sys,-1000 : User Mode Driver Frameworks Platform Driver
@%systemroot%\system32\icsvc.dll,-302 : Provides a mechanism to shut down the operating system of this virtual machine from the management interfaces on the physical computer.
@%systemroot%\system32\drivers\bam.sys,-100 : Background Activity Moderator Driver
@%systemroot%\system32\wpdbusenum.dll,-100 : Portable Device Enumerator Service
@%systemroot%\system32\pla.dll,-500 : Performance Logs & Alerts
@%systemroot%\system32\sstpsvc.dll,-200 : Secure Socket Tunneling Protocol Service
@comres.dll,-2450 : COM+ Event System
@%systemroot%\system32\vaultsvc.dll,-1004 : Provides secure storage and retrieval of credentials to users, applications and security service packages.
@%systemroot%\system32\installservice.dll,-201 : Provides infrastructure support for the Microsoft Store. This service is started on demand and if disabled then installations will not function properly.
@%systemroot%\system32\mprmsg.dll,-32006 : WAN Miniport (PPTP)
@%systemroot%\system32\appxdeploymentserver.dll,-1 : AppX Deployment Service (AppXSVC)
@gpapi.dll,-112 : Group Policy Client
@%systemroot%\system32\vssvc.exe,-101 : Manages and implements Volume Shadow Copies used for backup and other purposes. If this service is stopped, shadow copies will be unavailable for backup and the backup may fail. If this service is disabled, any services that explicitly depend on it will fail to start.
@mqutil.dll,-6101 : Message Queuing Access Control
@%systemroot%\system32\appreadiness.dll,-1000 : App Readiness
@%windir%\system32\drivers\netbios.sys,-503 : NetBIOS Interface
@%systemroot%\system32\drivers\qwavedrv.sys,-1 : QWAVE driver
@%systemroot%\system32\certprop.dll,-12 : Copies user certificates and root certificates from smart cards into the current user's certificate store, detects when a smart card is inserted into a smart card reader, and, if needed, installs the smart card Plug and Play minidriver.
c:\windows\system32,@elscore.dll,-5 : Microsoft Transliteration Engine
@%systemroot%\system32\drivers\bindflt.sys,-100 : Windows Bind Filter Driver
@%systemroot%\system32\sensordataservice.exe,-101 : Sensor Data Service
@c:\windows\syswow64\firewallcontrolpanel.dll,-12122 : Windows Defender Firewall
@%systemroot%\system32\flightsettings.dll,-104 : Provides infrastructure support for the Windows Insider Program. This service must remain enabled for the Windows Insider Program to work.
@%systemroot%\microsoft.net\framework64\v4.0.30319\aspnet_rc.dll,-2 : Provides support for out-of-process session states for ASP.NET. If this service is stopped, out-of-process requests will not be processed. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\moshost.dll,-100 : Downloaded Maps Manager
@%systemroot%\system32\hidserv.dll,-101 : Human Interface Device Service
@%systemroot%\system32\sacsvr.dll,-501 : Allows administrators to remotely access a command prompt using Emergency Management Services.
@%systemroot%\system32\powrprof.dll,-11 : Power saver
@%systemroot%\system32\graphicsperfsvc.dll,-101 : Graphics performance monitor service
@%systemroot%\system32\graphicsperfsvc.dll,-100 : GraphicsPerfSvc
@%systemroot%\system32\qmgr.dll,-1000 : Background Intelligent Transfer Service
@c:\windows\system32\spool\drivers\x64\3\printconfig.dll,-2 : This service opens custom printer dialog boxes and handles notifications from a remote print server or a printer. If you turn off this service, you won’t be able to see printer extensions or notifications.
@%systemroot%\system32\dnsapi.dll,-102 : The DNS Client service (dnscache) caches Domain Name System (DNS) names and registers the full computer name for this computer. If the service is stopped, DNS names will continue to be resolved. However, the results of DNS name queries will not be cached and the computer's name will not be registered. If the service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\ualsvc.dll,-101 : This service logs unique client access requests, in the form of IP addresses and user names, of installed products and roles on the local server. This information can be queried, via Powershell, by administrators needing to quantify client demand of server software for offline Client Access License (CAL) management. If the service is disabled, client requests will not be logged and will not be retrievable via Powershell queries. Stopping the service will not affect query of historical data (see supporting documentation for steps to delete historical data). The local system administrator must consult his, or her, Windows Server license terms to determine the number of CALs that are required for the server software to be appropriately licensed; use of the UAL service and data does not alter this obligation.
@%systemroot%\system32\ikeext.dll,-501 : IKE and AuthIP IPsec Keying Modules
@%systemroot%\system32\appidsvc.dll,-100 : Application Identity
@%systemroot%\system32\cryptsvc.dll,-1001 : Cryptographic Services
@%systemroot%\system32\embeddedmodesvc.dll,-201 : Embedded Mode
@%systemroot%\system32\ajrouter.dll,-2 : AllJoyn Router Service
@%systemroot%\system32\srpapi.dll,-100 : AppID Driver
@%systemroot%\system32\licensemanagersvc.dll,-201 : Provides infrastructure support for the Microsoft Store. This service is started on demand and if disabled then content acquired through the Microsoft Store will not function properly.
@%systemroot%\system32\rasauto.dll,-200 : Remote Access Auto Connection Manager
@%systemroot%\system32\ngcsvc.dll,-100 : Microsoft Passport
@%systemroot%\system32\w32time.dll,-201 : Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\presentationhost.exe,-3309 : Windows Presentation Foundation Font Cache 3.0.0.0
@%systemroot%\system32\drivers\ndiscap.sys,-5000 : Microsoft NDIS Capture
@%systemroot%\system32\drivers\ndis.sys,-200 : NDIS System Driver
@%systemroot%\system32\srvsvc.dll,-100 : Server
@%systemroot%\system32\winhttp.dll,-101 : WinHTTP implements the client HTTP stack and provides developers with a Win32 API and COM Automation component for sending HTTP requests and receiving responses. In addition, WinHTTP provides support for auto-discovering a proxy configuration via its implementation of the Web Proxy Auto-Discovery (WPAD) protocol.
@%systemroot%\system32\diagtrack.dll,-3001 : Connected User Experiences and Telemetry
@%systemroot%\system32\kpssvc.dll,-101 : KDC Proxy Server service runs on edge servers to proxy Kerberos protocol messages to domain controllers on the corporate network.
@%systemroot%\system32\appxdeploymentserver.dll,-2 : Provides infrastructure support for deploying Store applications. This service is started on demand and if disabled Store applications will not be deployed to the system, and may not function properly.
c:\windows\system32,@elscore.dll,-6 : Microsoft Cyrillic to Latin Transliteration
@%systemroot%\system32\mprdim.dll,-201 : Offers routing services to businesses in local area and wide area network environments.
@%systemroot%\system32\bthavctpsvc.dll,-101 : AVCTP service
@%systemroot%\system32\drivers\wudfrd.sys,-1000 : Windows Driver Foundation - User-mode Driver Framework Reflector
@%systemroot%\system32\sysmain.dll,-1000 : SysMain
@%systemroot%\system32\bthavctpsvc.dll,-102 : This is Audio Video Control Transport Protocol service
c:\windows\system32,@elscore.dll,-2 : Microsoft Script Detection
@%systemroot%\system32\wlidsvc.dll,-100 : Microsoft Account Sign-in Assistant
@%systemroot%\system32\wiarpc.dll,-1 : Launches applications associated with still image acquisition events.
@sstpsvc.dll,-35001 : Secure Socket Tunneling Protocol
@%systemroot%\system32\drivers\mslldp.sys,-200 : Microsoft Link-Layer Discovery Protocol
@%programfiles%\windows defender\mpasdesc.dll,-310 : Windows Defender Antivirus Service
@%systemroot%\system32\wbem\wmisvc.dll,-205 : Windows Management Instrumentation
@%systemroot%\system32\consentuxclient.dll,-100 : ConsentUX
@%systemroot%\system32\appidsvc.dll,-101 : Determines and verifies the identity of an application. Disabling this service will prevent AppLocker from being enforced.
@%systemroot%\system32\rasmans.dll,-201 : Manages dial-up and virtual private network (VPN) connections from this computer to the Internet or other remote networks. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\profsvc.dll,-300 : User Profile Service
@%windir%\system32\inetsrv\iisres.dll,-30002 : The Windows Process Activation Service (WAS) provides process activation, resource management and health management services for message-activated applications.
@%systemroot%\system32\icsvc.dll,-102 : Monitors the state of this virtual machine by reporting a heartbeat at regular intervals. This service helps you identify running virtual machines that have stopped responding.
@%systemroot%\system32\netsetupsvc.dll,-4 : The Network Setup Service manages the installation of network drivers and permits the configuration of low-level network settings. If this service is stopped, any driver installations that are in-progress may be cancelled.
@%systemroot%\system32\drivers\wcifs.sys,-100 : Windows Container Isolation
@%systemroot%\system32\fdphost.dll,-100 : Function Discovery Provider Host
@%systemroot%\system32\ipnathlp.dll,-107 : Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network.
@%systemroot%\system32\agentservice.exe,-101 : Provides support for application and OS settings roaming
@%systemroot%\system32\wbem\wmiapsrv.exe,-110 : WMI Performance Adapter
@waasmedicsvc.dll,-101 : Enables remediation and protection of Windows Update components.
@%programfiles%\windows defender\mpasdesc.dll,-242 : Helps guard against intrusion attempts targeting known and newly discovered vulnerabilities in network protocols
@%systemroot%\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8200 : Provides ability to share TCP ports over the net.tcp protocol.
@combase.dll,-5013 : The DCOMLAUNCH service launches COM and DCOM servers in response to object activation requests. If this service is stopped or disabled, programs using COM or DCOM will not function properly. It is strongly recommended that you have the DCOMLAUNCH service running.
@%systemroot%\system32\drivers\mmcss.sys,-100 : Multimedia Class Scheduler
@%systemroot%\system32\walletservice.dll,-1001 : Hosts objects used by clients of the wallet
@%systemroot%\system32\icsvc.dll,-401 : Hyper-V Time Synchronization Service
@%systemroot%\system32\drivers\ndisvirtualbus.sys,-200 : Microsoft Virtual Network Adapter Enumerator
@%systemroot%\system32\audiosrv.dll,-201 : Manages audio for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start
@%systemroot%\system32\pcasvc.dll,-2 : This service provides support for the Program Compatibility Assistant (PCA). PCA monitors programs installed and run by the user and detects known compatibility problems. If this service is stopped, PCA will not function properly.
@%systemroot%\system32\bfe.dll,-1001 : Base Filtering Engine
@%systemroot%\system32\sens.dll,-200 : System Event Notification Service
@%systemroot%\system32\mprmsg.dll,-32000 : RAS Asynchronous Media Driver
@%systemroot%\system32\wdi.dll,-503 : The Diagnostic Service Host is used by the Diagnostic Policy Service to host diagnostics that need to run in a Local Service context. If this service is stopped, any diagnostics that depend on it will no longer function.
@%systemroot%\system32\netman.dll,-110 : Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections.
@regsvc.dll,-2 : Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\icsvc.dll,-101 : Hyper-V Heartbeat Service
@%systemroot%\system32\srvsvc.dll,-104 : Server SMB 2.xxx Driver
@%systemroot%\system32\netprofmsvc.dll,-203 : Identifies the networks to which the computer has connected, collects and stores properties for these networks, and notifies applications when these properties change.
@%systemroot%\system32\dot3svc.dll,-1102 : Wired AutoConfig
@%systemroot%\system32\drivers\tcpip.sys,-10103 : TCP/IP version 6. The latest version of the internet protocol that provides communication across diverse interconnected networks.
@peerdistsh.dll,-9003 : BranchCache - Hosted Cache Client (Uses HTTPS)
@%systemroot%\system32\dhcpcore.dll,-100 : DHCP Client
@%systemroot%\system32\drivers\uevagentdriver.sys,-101 : UevAgentDriver
@%systemroot%\system32\tcpipcfg.dll,-50004 : NetIO Legacy TDI Support Driver
@%systemroot%\system32\appinfo.dll,-101 : Facilitates the running of interactive applications with additional administrative privileges. If this service is stopped, users will be unable to launch applications with the additional administrative privileges they may require to perform desired user tasks.
@%systemroot%\system32\wiarpc.dll,-2 : Still Image Acquisition Events
@%systemroot%\system32\eapsvc.dll,-2 : The Extensible Authentication Protocol (EAP) service provides network authentication in such scenarios as 802.1x wired and wireless, VPN, and Network Access Protection (NAP). EAP also provides application programming interfaces (APIs) that are used by network access clients, including wireless and VPN clients, during the authentication process. If you disable this service, this computer is prevented from accessing networks that require EAP authentication.
@%systemroot%\system32\securityhealthagent.dll,-1002 : Windows Security Service
@%systemroot%\system32\wdi.dll,-501 : The Diagnostic System Host is used by the Diagnostic Policy Service to host diagnostics that need to run in a Local System context. If this service is stopped, any diagnostics that depend on it will no longer function.
@enterpriseappmgmtsvc.dll,-1 : Enterprise App Management Service
@%systemroot%\system32\coremessaging.dll,-2 : Manages communication between system components.
@%programfiles%\windows defender\mpasdesc.dll,-390 : Windows Defender Antivirus Boot Driver
@%systemroot%\system32\drivers\nsiproxy.sys,-2 : NSI Proxy Service Driver
@%systemroot%\system32\drivers\fsdepends.sys,-10001 : File System Dependency Minifilter
@%programfiles%\windows media player\wmpnetwk.exe,-102 : Shares Windows Media Player libraries to other networked players and media devices using Universal Plug and Play
@%systemroot%\system32\fntcache.dll,-101 : Optimizes performance of applications by caching commonly used font data. Applications will start this service if it is not already running. It can be disabled, though doing so will degrade application performance.
@%systemroot%\system32\searchindexer.exe,-103 : Windows Search
d:\nexsus\lkp engine_ver2.7\nexsus.maxdial.engine.exe.friendlyappname : CallBalance Engine
d:\lkpsoft\date_minute_second_logger.bat.friendlyappname : date_minute_second_logger.bat
c:\windows\system32\cryptext.dll.applicationcompany : Microsoft Corporation
d:\nexsus\lkp_engine_ver2.3\nexsus.maxdial.engine.exe.applicationcompany : Nexsus Techno Solutions Pvt. Ltd.
c:\users\administrator\desktop\vls patch_24102025\vls patch_24102025\nexsus.callbalancel.voicelogservice.exe.applicationcompany : Nexsus Techno Solutions Pvt. Ltd.
c:\users\administrator\desktop\engine_ver2.7.7.0\engine_ver2.7.7.0\nexsus.maxdial.engine.exe.applicationcompany : Nexsus Techno Solutions Pvt. Ltd.
d:\nexsus\lkp_engine_ver2.3\nexsus.maxdial.engine.exe.friendlyappname : CallBalance Engine
c:\windows\system32\compmgmtlauncher.exe.applicationcompany : Microsoft Corporation
d:\nexsus\lkp_engine_ver2.7.5\nexsus.maxdial.engine.exe.friendlyappname : CallBalance Engine
c:\program files\internet explorer\iexplore.exe.applicationcompany : Microsoft Corporation
c:\shcti\test.exe.friendlyappname : CTI driver: SSM layer
c:\users\administrator\desktop\engine_ver2.7.6.0\nexsus.maxdial.engine.exe.friendlyappname : CallBalance Engine
c:\windows\system32\explorerframe.dll.friendlyappname : ExplorerFrame
d:\nexsus\lkp_engine_ver2.7.7.0\nexsus.maxdial.engine.exe.applicationcompany : Nexsus Techno Solutions Pvt. Ltd.
c:\windows\system32\mmc.exe.friendlyappname : Microsoft Management Console
c:\users\administrator\desktop\engine_2.7.3\engine_2.7.3\nexsus.maxdial.engine.exe.friendlyappname : CallBalance Engine
c:\windows\system32\shell32.dll.applicationcompany : Microsoft Corporation
c:\windows\system32\inetsrv\inetmgr.exe.friendlyappname : IIS Manager
c:\windows\system32\control.exe.applicationcompany : Microsoft Corporation
c:\windows\system32\windowspowershell\v1.0\powershell_ise.exe.friendlyappname : Windows PowerShell ISE
d:\nexsus\nexsus_patch\lkp_engine_ver1.1\nexsus.maxdial.engine.exe.friendlyappname : CallBalance Engine
c:\program files\windows nt\accessories\wordpad.exe.friendlyappname : WordPad
c:\windows\system32\mspaint.exe.friendlyappname : Paint
c:\program files (x86)\windows media player\wmplayer.exe.friendlyappname : Windows Media Player
c:\users\administrator\desktop\vls patch_24102025\vls patch_24102025\nexsus.callbalancel.voicelogservice.exe.friendlyappname : Nexsus.MaxDial.VoiceLogService
c:\windows\system32\win32calc.exe.friendlyappname : Windows Calculator
d:\nexsus\nexsus_patch\nexsus.maxdial.engine\nexsus.maxdial.engine.exe.applicationcompany : Nexsus Techno Solutions Pvt. Ltd.
d:\nexsus\lkp_engine_ver2.6\nexsus.maxdial.engine.exe.applicationcompany : Nexsus Techno Solutions Pvt. Ltd.
c:\windows\system32\windowspowershell\v1.0\powershell.exe.applicationcompany : Microsoft Corporation
d:\nexsus\lkp_engine_ver2.7.6.0\nexsus.maxdial.engine.exe.applicationcompany : Nexsus Techno Solutions Pvt. Ltd.
c:\users\administrator\desktop\vls1\nexsus.callbalancel.voicelogservice.exe.applicationcompany : Nexsus Techno Solutions Pvt. Ltd.
c:\windows\system32\compmgmtlauncher.exe.friendlyappname : Computer Management Snapin Launcher
c:\windows\system32\appresolver.dll.friendlyappname : App Resolver
c:\users\administrator\desktop\engine_2.7.3\engine_2.7.3\nexsus.maxdial.engine.exe.applicationcompany : Nexsus Techno Solutions Pvt. Ltd.
c:\windows\system32\notepad.exe.friendlyappname : Notepad
c:\users\administrator\desktop\lkp engine_ver2.6 updated\nexsus.maxdial.engine.exe.friendlyappname : CallBalance Engine
c:\program files (x86)\zoiper\zoiper.exe.applicationcompany : Securax Ltd
d:\nexsus\lkp_engine_ver2.7.5\nexsus.maxdial.engine.exe.applicationcompany : Nexsus Techno Solutions Pvt. Ltd.
d:\nexsus\nexsus_patch\lkp_engine_ver1.1\nexsus.maxdial.engine.exe.applicationcompany : Nexsus Techno Solutions Pvt. Ltd.
c:\program files\internet explorer\iexplore.exe.friendlyappname : Internet Explorer
d:\nexsus\lkp_engine_ver2.6 - rnd\nexsus.maxdial.engine.exe.applicationcompany : Nexsus Techno Solutions Pvt. Ltd.
d:\nexsus\lkp_engine_ver2.7\nexsus.maxdial.engine.exe.friendlyappname : CallBalance Engine
d:\nexsus\lkp_engine_ver2.7.5\nexsus.maxdial.engine1.exe.friendlyappname : CallBalance Engine
c:\windows\system32\mmc.exe.applicationcompany : Microsoft Corporation
d:\nexsus\lkp_engine_ver2.7.8.0\nexsus.maxdial.engine.exe.friendlyappname : CallBalance Engine
d:\nexsus\backup\18dec2025\lkp_engine_ver2.3\nexsus.maxdial.engine.exe.friendlyappname : CallBalance Engine
d:\nexsus\lkp_engine_ver2.7\nexsus.maxdial.engine.exe.applicationcompany : Nexsus Techno Solutions Pvt. Ltd.
c:\windows\explorer.exe.applicationcompany : Microsoft Corporation
d:\nexsus\lkp_engine_ver2.7.5\nexsus.maxdial.engine1.exe.applicationcompany : Nexsus Techno Solutions Pvt. Ltd.
c:\windows\system32\fsquirt.exe.friendlyappname : fsquirt.exe
c:\users\administrator\desktop\engine_ver2.7.7.0\engine_ver2.7.7.0\nexsus.maxdial.engine.exe.friendlyappname : CallBalance Engine
d:\nexsus\nexsus_patch\nexsus.maxdial.engine\nexsus.maxdial.engine.exe.friendlyappname : CallBalance Engine
c:\windows\system32\win32calc.exe.applicationcompany : Microsoft Corporation
d:\nexsus\lkp_engine_ver2.7.9.0\nexsus.maxdial.engine.exe.applicationcompany : Nexsus Techno Solutions Pvt. Ltd.
c:\program files (x86)\zoiper\zoiper.exe.friendlyappname : Zoiper 3.9 for Windows 32bit
c:\program files\common files\microsoft shared\office16\msoxmled.exe.applicationcompany : Microsoft Corporation
c:\windows\system32\windowspowershell\v1.0\powershell_ise.exe.applicationcompany : Microsoft Corporation
c:\program files (x86)\windows media player\wmplayer.exe.applicationcompany : Microsoft Corporation
c:\program files\microsoft office\office16\excel.exe.applicationcompany : Microsoft Corporation
c:\windows\system32\openwith.exe.applicationcompany : Microsoft Corporation
c:\program files\windows nt\accessories\wordpad.exe.applicationcompany : Microsoft Corporation
c:\program files\microsoft office\office16\winword.exe.applicationcompany : Microsoft Corporation
d:\nexsus\lkp_engine_ver2.7.9.1\nexsus.maxdial.engine.exe.friendlyappname : CallBalance Engine
c:\users\administrator\desktop\2.6 working\nexsus.maxdial.engine.exe.friendlyappname : CallBalance Engine
c:\program files\common files\system\ole db\oledb32.dll.friendlyappname : OLE DB Core Services
d:\nexsus\lkp_engine_ver2.7.7.0\nexsus.maxdial.engine.exe.friendlyappname : CallBalance Engine
c:\windows\system32\notepad.exe.applicationcompany : Microsoft Corporation
c:\program files\microsoft office\office16\excel.exe.friendlyappname : Excel 2016
c:\windows\system32\mspaint.exe.applicationcompany : Microsoft Corporation
c:\users\administrator\desktop\lkp engine_ver2.6 updated\nexsus.maxdial.engine.exe.applicationcompany : Nexsus Techno Solutions Pvt. Ltd.
d:\nexsus\lkp_engine_ver2.5\nexsus.maxdial.engine.exe.applicationcompany : Nexsus Techno Solutions Pvt. Ltd.
c:\windows\system32\fsquirt.exe.applicationcompany : Microsoft Corporation
c:\program files\microsoft office\office16\winword.exe.friendlyappname : Word 2016
c:\windows\system32\mstsc.exe.applicationcompany : Microsoft Corporation
c:\windows\system32\cryptext.dll.friendlyappname : Crypto Shell Extensions
d:\nexsus\lkp_engine_ver2.7.6.1\nexsus.maxdial.engine.exe.applicationcompany : Nexsus Techno Solutions Pvt. Ltd.
c:\windows\system32\shell32.dll.friendlyappname : Windows Shell Common Dll
c:\windows\system32\inetsrv\inetmgr.exe.applicationcompany : Microsoft Corporation
c:\windows\system32\mstsc.exe.friendlyappname : Remote Desktop Connection
c:\windows\system32\appresolver.dll.applicationcompany : Microsoft Corporation
d:\nexsus\lkp_engine_ver2.7.8.0\nexsus.maxdial.engine.exe.applicationcompany : Nexsus Techno Solutions Pvt. Ltd.
c:\windows\system32\openwith.exe.friendlyappname : Pick an app
d:\nexsus\lkp_engine_ver2.5\nexsus.maxdial.engine.exe.friendlyappname : CallBalance Engine
d:\nexsus\backup\18dec2025\lkp_engine_ver2.3\nexsus.maxdial.engine.exe.applicationcompany : Nexsus Techno Solutions Pvt. Ltd.
c:\users\administrator\desktop\2.6 working\nexsus.maxdial.engine.exe.applicationcompany : Nexsus Techno Solutions Pvt. Ltd.
c:\windows\system32\windowspowershell\v1.0\powershell.exe.friendlyappname : Windows PowerShell
c:\program files\common files\system\ole db\oledb32.dll.applicationcompany : Microsoft Corporation
langid : .
d:\nexsus\lkp_engine_ver2.7.9.1\nexsus.maxdial.engine.exe.applicationcompany : Nexsus Techno Solutions Pvt. Ltd.
c:\windows\system32\msiexec.exe.friendlyappname : Windows® installer
c:\windows\system32\control.exe.friendlyappname : Windows Control Panel
c:\windows\system32\msiexec.exe.applicationcompany : Microsoft Corporation
d:\nexsus\lkp_engine_ver2.8.0.0\nexsus.maxdial.engine.exe.applicationcompany : Nexsus Techno Solutions Pvt. Ltd.
c:\program files (x86)\microsoft\edge\application\msedge.exe.applicationcompany : Microsoft Corporation
c:\windows\explorer.exe.friendlyappname : Windows Explorer
d:\nexsus\backup\timestamping.exe.friendlyappname : TimeStamping
c:\program files\common files\microsoft shared\office16\msoxmled.exe.friendlyappname : Office XML Handler
c:\users\administrator\desktop\vls1\nexsus.callbalancel.voicelogservice.exe.friendlyappname : Nexsus.MaxDial.VoiceLogService
d:\nexsus\lkp_engine_ver2.6 - rnd\nexsus.maxdial.engine.exe.friendlyappname : CallBalance Engine
c:\users\administrator\desktop\engine_ver2.7.6.0\nexsus.maxdial.engine.exe.applicationcompany : Nexsus Techno Solutions Pvt. Ltd.
d:\nexsus\lkp_engine_ver2.8.0.0\nexsus.maxdial.engine.exe.friendlyappname : CallBalance Engine
d:\nexsus\lkp engine_ver2.7\nexsus.maxdial.engine.exe.applicationcompany : Nexsus Techno Solutions Pvt. Ltd.
c:\program files (x86)\microsoft\edge\application\msedge.exe.friendlyappname : Microsoft Edge
d:\nexsus\lkp_engine_ver2.7.6.1\nexsus.maxdial.engine.exe.friendlyappname : CallBalance Engine
d:\nexsus\lkp_engine_ver2.6\nexsus.maxdial.engine.exe.friendlyappname : CallBalance Engine
d:\nexsus\lkp_engine_ver2.7.6.0\nexsus.maxdial.engine.exe.friendlyappname : CallBalance Engine
d:\nexsus\lkp_engine_ver2.7.9.0\nexsus.maxdial.engine.exe.friendlyappname : CallBalance Engine
d:\nexsus\nexsus_patch\nexsus.maxdial.emailservice\nexsusemailservice.exe.friendlyappname : ReadExcel
c:\program files\wireshark\wireshark.exe.friendlyappname : Wireshark
c:\program files\wireshark\wireshark.exe.applicationcompany : The Wireshark developer community, https://www.wireshark.org/
c:\windows\system32\explorerframe.dll.applicationcompany : Microsoft Corporation

MUICache report attached.

104668 - Microsoft .NET Core for Windows
-
Synopsis
.NET Core runtime is installed on the remote Windows host.
Description
.NET Core, a managed software framework, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0653
Plugin Information
Published: 2017/11/17, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Nessus detected 3 installs of .NET Core Windows:

Path : C:\Program Files\dotnet\shared\Microsoft.NetCore.App\5.0.17\
Version : 5.0.17.31213

Path : C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.8\
Version : 8.0.8

Path : C:\Program Files (x86)\dotnet\shared\Microsoft.NETCore.App\8.0.8\
Version : 8.0.8
51351 - Microsoft .NET Framework Detection
-
Synopsis
A software framework is installed on the remote host.
Description
Microsoft .NET Framework, a software framework for Microsoft Windows operating systems, is installed on the remote host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0655
Plugin Information
Published: 2010/12/20, Modified: 2025/10/15
Plugin Output

tcp/445/cifs


Nessus detected 5 installs of Microsoft .NET Framework:

Path : C:\Windows\Microsoft.NET\Framework64\v2.0.50727
Version : 2.0.50727
Full Version : 2.0.50727.4927
SP : 2

Path : C:\Windows\Microsoft.NET\Framework64\v3.0
Version : 3.0
Full Version : 3.0.30729.4926
SP : 2

Path : C:\Windows\Microsoft.NET\Framework64\v3.5\
Version : 3.5
Full Version : 3.5.30729.4926
SP : 1

Path : C:\Windows\Microsoft.NET\Framework64\v4.0.30319\
Version : 4.7.2
Full Version : 4.7.03190
Install Type : Full
Release : 461814

Path : C:\Windows\Microsoft.NET\Framework64\v4.0.30319\
Version : 4.7.2
Full Version : 4.7.03190
Install Type : Client
Release : 461814
99364 - Microsoft .NET Security Rollup Enumeration
-
Synopsis
This plugin enumerates installed Microsoft .NET security rollups.
Description
Nessus was able to enumerate the Microsoft .NET security rollups installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2017/04/14, Modified: 2025/10/23
Plugin Output

tcp/445/cifs


Nessus detected 2 installs of Microsoft .NET Framework:

Path : C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorlib.dll
Version : 4.7.4126.0
.NET Version : 4.7.2
Associated KB : 5049608
Latest effective update level : 01_2025

Path : C:\Windows\winsxs\*system.printing_31bf3856ad364e35*
Version : 3.0.6920.9063
.NET Version : 3.5
Associated KB : 5044022
Latest effective update level : 10_2024
104667 - Microsoft ASP .NET Core for Windows
-
Synopsis
ASP .NET Core runtime packages are installed on the remote Windows host.
Description
ASP .NET Core runtime, web application server side components, are installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0657
Plugin Information
Published: 2017/11/17, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Nessus detected 4 installs of ASP .NET Core Windows:

Path : C:\Program Files\dotnet\shared\Microsoft.AspNetCore.App\5.0.17
Version : 5.0.17

Path : C:\Program Files\dotnet\shared\Microsoft.AspNetCore.App\8.0.8
Version : 8.0.8

Path : C:\Program Files (x86)\dotnet\shared\Microsoft.AspNetCore.App\8.0.8
Version : 8.0.8

Path : C:\Program Files (x86)\dotnet\shared\Microsoft.AspNetCore.App\5.0.17
Version : 5.0.17
176212 - Microsoft Edge Add-on Enumeration (Windows)
-
Synopsis
One or more Microsoft Egde browser extensions are installed on the remote host.
Description
Nessus was able to enumerate Microsoft Edge browser extensions installed on the remote host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/05/22, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


User : Administrator
|- Browser : Microsoft Edge
|- Add-on information :

Name : unknown
Version : 1.99.1
Path : C:\Users\Administrator\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.99.1_0

Name : Edge relevant text changes
Description : Edge relevant text changes on select websites to improve user experience and precisely surfaces the action they want to take.
Version : 1.2.1
Path : C:\Users\Administrator\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha\1.2.1_0
136969 - Microsoft Edge Chromium Installed
-
Synopsis
Microsoft Edge (Chromium-based) is installed on the remote host.
Description
Microsoft Edge (Chromium-based), a Chromium-based web browser, is installed on the remote host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2020/05/29, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft\Edge\Application
Version : 144.0.3719.82
Channel : stable
72879 - Microsoft Internet Explorer Enhanced Security Configuration Detection
-
Synopsis
The remote host supports IE Enhanced Security Configuration.
Description
Nessus detects if the remote Windows host supports IE Enhanced Security Configuration (ESC) and if IE ESC features are enabled or disabled.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2014/03/07, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Type : Admin Groups
Is Enabled : True

Type : User Groups
Is Enabled : True

162560 - Microsoft Internet Explorer Installed
-
Synopsis
A web browser is installed on the remote Windows host.
Description
Microsoft Internet Explorer, a web browser bundled with Microsoft Windows, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2022/06/28, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\Windows\system32\mshtml.dll
Version : 11.0.17763.6766

72367 - Microsoft Internet Explorer Version Detection
-
Synopsis
Internet Explorer is installed on the remote host.
Description
The remote Windows host contains Internet Explorer, a web browser created by Microsoft.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0509
Plugin Information
Published: 2014/02/06, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Version : 11.1790.17763.0

139615 - Microsoft Internet Information Services (IIS) Installed
-
Synopsis
Checks Windows registry keys and executables for a Microsoft Internet Information Services (IIS) installation.
Description
Microsoft Internet Information Services installation (IIS) has been detected on the remote Windows host.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0030
XREF IAVT:0001-T-0944
Plugin Information
Published: 2020/08/17, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\Windows\system32\inetsrv
Version : 10.0.17763.5830

140655 - Microsoft Internet Information Services (IIS) Sites Enumeration
-
Synopsis
Checks IIS configuration file for configured sites and their bound addresses.
Description
Microsoft Internet Information Services configuration file has been parsed to extract information about the existing sites, their protocols, domains and IP addresses.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2020/09/18, Modified: 2025/12/15
Plugin Output

tcp/445/cifs

Nessus found the following sites configured on the remote host:
+ site name: ivr.lkpsec.in
+ binding 0
- IP address : *
- port : 443
- domain : ivr.lkpsec.in
- protocol : https
+ site name: LKPCustomer-Onboard
+ binding 0
- IP address : 172.17.100.140
- port : 7001
- domain :
- protocol : http
+ site name: Default Web Site
+ binding 0
- IP address : *
- port : 80
- domain :
- protocol : http
+ binding 1
- IP address : 808
- port : *
- domain :
- protocol : net.tcp
+ binding 2
- IP address : localhost
- port :
- domain :
- protocol : net.msmq
+ binding 3
- IP address : localhost
- port :
- domain :
- protocol : msmq.formatname
+ binding 4
- IP address : *
- port :
- domain :
- protocol : net.pipe
+ site name: CallBalanceWeb
+ binding 0
- IP address : 172.17.100.140
- port : 8002
- domain :
- protocol : https
+ binding 1
- IP address : 172.17.100.140
- port : 8001
- domain :
- protocol : http
+ site name: commserverivr.lkpsec.in
+ binding 0
- IP address : *
- port : 443
- domain : commserverivr.lkpsec.in
- protocol : https
66424 - Microsoft Malicious Software Removal Tool Installed
-
Synopsis
An antimalware application is installed on the remote Windows host.
Description
The Microsoft Malicious Software Removal Tool is installed on the remote host. This tool is an application that attempts to detect and remove known malware from Windows systems.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/05/15, Modified: 2023/01/10
Plugin Output

tcp/445/cifs


File : C:\Windows\system32\MRT.exe
Version : 5.132.25020.1001
Release at last run : unknown
Report infection information to Microsoft : Yes

174933 - Microsoft Message Queuing Detection
-
Synopsis
Microsoft Message Queuing is running on the remote host.
Description
Microsoft Message Queuing is running on the remote host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/04/28, Modified: 2025/09/29
Plugin Output

tcp/1801/msmq

MSMQ response:

0x00: 10 00 1B 00 4C 49 4F 52 24 00 00 00 FF FF FF FF ....LIOR$.......
0x10: 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x20: 40 00 00 00 @...

93232 - Microsoft Office Compatibility Pack Installed (credentialed check)
-
Synopsis
A compatibility application is installed on the remote host.
Description
Microsoft Office Compatibility Pack, used to enable older versions of Microsoft Office applications to view and edit files created with newer versions of Microsoft Office applications, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0663
Plugin Information
Published: 2016/08/30, Modified: 2025/09/29
Plugin Output

tcp/445/cifs


Office Compatibility Pack is installed with the following components:

Component : Excel Converter
Version : 16.0.4266.1001
Path : C:\Program Files\Microsoft Office\Office16\Excelcnv.exe

Component : Word Converter
Version : 16.0.4266.1001
Path : C:\Program Files\Microsoft Office\Office16\Wordconv.exe
27524 - Microsoft Office Detection
-
Synopsis
The remote Windows host contains an office suite.
Description
Microsoft Office is installed on the remote host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0505
Plugin Information
Published: 2007/10/23, Modified: 2025/10/14
Plugin Output

tcp/445/cifs


The remote host has the following Microsoft Office 2016 Service Pack 0 components installed :

- WordCnv : 16.0.4266.1001
- Word : 16.0.4266.1001
- ExcelCnv : 16.0.4266.1001
- Excel : 16.0.4266.1001
- Publisher : 16.0.4266.1001
- Outlook : 16.0.4266.1001
- Groove : 16.0.4266.1001
- PowerPoint : 16.0.4266.1001
- OneNote : 16.0.4266.1001

92425 - Microsoft Office File History
-
Synopsis
Nessus was able to enumerate files opened in Microsoft Office on the remote host.
Description
Nessus was able to gather evidence of files that were opened using any Microsoft Office application. The report was extracted from Office MRU (Most Recently Used) registry keys.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

item 3
item 2
item 1
item 3
item 2
item 1
item 3
item 2
item 1
item 3
item 2
item 1
item 3
item 2
item 1
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\index.dat
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\LKP Summary.xlsx.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\LKP_ClientDetails_new.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\Odin Client Data.xlsx.LNK

User AppData recent used file report attached
Office MRU registry report attached.
92361 - Microsoft Office Macros Configuration
-
Synopsis
Nessus was able to collect and report Office macro configuration data for active accounts on the remote host.
Description
Nessus was able to collect Office macro configuration information for active accounts on the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/16
Plugin Output

tcp/0

Office macros information attached.
77605 - Microsoft OneNote Detection
-
Synopsis
The remote Windows host contains Microsoft OneNote.
Description
Microsoft OneNote is installed on the remote host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0664
Plugin Information
Published: 2014/09/10, Modified: 2025/09/29
Plugin Output

tcp/0


Path : C:\Program Files\Microsoft Office\Office16\OneNote.exe
Version : 16.0.4266.1001
124120 - Microsoft Outlook Attachment Previewing Enabled
-
Synopsis
Microsoft Outlook application that is installed on the remote host has attachment previewing enabled.
Description
Microsoft Outlook application that is installed on the remote host has attachment previewing enabled.
Solution
Disable attachment previewing settings.
Risk Factor
None
Plugin Information
Published: 2019/04/17, Modified: 2019/04/17
Plugin Output

tcp/0

Outlook application in Microsoft Office 2016 has attachment previewing enabled.
92427 - Microsoft Paint Recent File History
-
Synopsis
Nessus was able to enumerate files opened in Microsoft Paint on the remote host.
Description
Nessus was able to generate a list of files opened using the Microsoft Paint program.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

Production
- D:\Nexsus\CallBalance\Images\agentFooterMenuBG.jpg
- D:\Nexsus\CallBalance\Images\agentFooterMenuBG50.jpg
- D:\Nexsus\CallBalance\Images\agent.png
- D:\Nexsus\CallBalance\Images\CallBalance_logo.png
- D:\Nexsus\CallBalance\Images\Nexsus_logo_band1.jpg
- D:\Nexsus\CallBalance\Images\Nexsus_logo_band1_LKP.jpg
- D:\Nexsus\CallBalance\TPINGeneration.png

57033 - Microsoft Patch Bulletin Feasibility Check
-
Synopsis
Nessus is able to check for Microsoft patch bulletins.
Description
Using credentials supplied in the scan policy, Nessus is able to collect information about the software and patches installed on the remote Windows host and will use that information to check for missing Microsoft security updates.

Note that this plugin is purely informational.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/06, Modified: 2021/07/12
Plugin Output

tcp/445/cifs



Nessus is able to test for missing patches using :
Nessus

125835 - Microsoft Remote Desktop Connection Installed
-
Synopsis
A graphical interface connection utility is installed on the remote Windows host
Description
Microsoft Remote Desktop Connection (also known as Remote Desktop Protocol or Terminal Services Client) is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2019/06/12, Modified: 2022/10/10
Plugin Output

tcp/0


Path : C:\Windows\\System32\\mstsc.exe
Version : 10.0.17763.5830

93962 - Microsoft Security Rollup Enumeration
-
Synopsis
This plugin enumerates installed Microsoft security rollups.
Description
Nessus was able to enumerate the Microsoft security rollups installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/10/11, Modified: 2025/11/18
Plugin Output

tcp/445/cifs


Cumulative Rollup : 02_2025 [KB5052000]
Cumulative Rollup : 01_2025
Cumulative Rollup : 12_2024
Cumulative Rollup : 11_2024
Cumulative Rollup : 10_2024
Cumulative Rollup : 09_2024
Cumulative Rollup : 08_2024
Cumulative Rollup : 07_2024
Cumulative Rollup : 06_2024
Cumulative Rollup : 05_2024
Cumulative Rollup : 04_2024
Cumulative Rollup : 03_2024
Cumulative Rollup : 02_2024
Cumulative Rollup : 01_2024
Cumulative Rollup : 12_2023
Cumulative Rollup : 11_2023
Cumulative Rollup : 10_2023
Cumulative Rollup : 09_2023
Cumulative Rollup : 08_2023
Cumulative Rollup : 07_2023
Cumulative Rollup : 06_2023
Cumulative Rollup : 05_2023
Cumulative Rollup : 04_2023
Cumulative Rollup : 03_2023
Cumulative Rollup : 02_2023
Cumulative Rollup : 01_2023
Cumulative Rollup : 12_2022
Cumulative Rollup : 11_2022
Cumulative Rollup : 10_2022
Cumulative Rollup : 09_2022
Cumulative Rollup : 08_2022
Cumulative Rollup : 07_2022
Cumulative Rollup : 06_2022
Cumulative Rollup : 05_2022
Cumulative Rollup : 04_2022
Cumulative Rollup : 03_2022
Cumulative Rollup : 02_2022
Cumulative Rollup : 01_2022
Cumulative Rollup : 12_2021
Cumulative Rollup : 11_2021
Cumulative Rollup : 10_2021
Cumulative Rollup : 09_2021
Cumulative Rollup : 08_2021 [KB5005030]
Cumulative Rollup : 07_2021
Cumulative Rollup : 06_2021_07_01
Cumulative Rollup : 06_2021
Cumulative Rollup : 05_2021
Cumulative Rollup : 04_2021
Cumulative Rollup : 03_2021
Cumulative Rollup : 02_2021
Cumulative Rollup : 01_2021
Cumulative Rollup : 12_2020
Cumulative Rollup : 11_2020
Cumulative Rollup : 10_2020
Cumulative Rollup : 09_2020
Cumulative Rollup : 08_2020
Cumulative Rollup : 07_2020
Cumulative Rollup : 06_2020
Cumulative Rollup : 05_2020
Cumulative Rollup : 04_2020
Cumulative Rollup : 03_2020
Cumulative Rollup : 02_2020
Cumulative Rollup : 01_2020
Cumulative Rollup : 12_2019
Cumulative Rollup : 11_2019
Cumulative Rollup : 10_2019
Cumulative Rollup : 09_2019
Cumulative Rollup : 08_2019
Cumulative Rollup : 07_2019
Cumulative Rollup : 06_2019
Cumulative Rollup : 05_2019
Cumulative Rollup : 04_2019
Cumulative Rollup : 03_2019
Cumulative Rollup : 02_2019
Cumulative Rollup : 01_2019
Cumulative Rollup : 12_2018
Cumulative Rollup : 11_2018
Cumulative Rollup : 10_2018

Latest effective update level : 02_2025
File checked : C:\Windows\system32\ntoskrnl.exe
File version : 10.0.17763.6893
Associated KB : 5052000
10902 - Microsoft Windows 'Administrators' Group User List
-
Synopsis
There is at least one user in the 'Administrators' group.
Description
Using the supplied credentials, it is possible to extract the member list of the 'Administrators' group. Members of this group have complete access to the remote system.
Solution
Verify that each member of the group should have this type of access.
Risk Factor
None
Plugin Information
Published: 2002/03/15, Modified: 2018/05/16
Plugin Output

tcp/445/cifs


The following users are members of the 'Administrators' group :

- LKP_SIP_APPSRV-\Production (User)
- LKP_SIP_APPSRV-\LKPAdmin (User)
- LKP_SIP_APPSRV-\tidua (User)
48763 - Microsoft Windows 'CWDIllegalInDllSearch' Registry Setting
-
Synopsis
CWDIllegalInDllSearch Settings: Improper settings could allow code execution attacks.
Description
Windows Hosts can be hardened against DLL hijacking attacks by setting the The 'CWDIllegalInDllSearch' registry entry in to one of the following settings:

- 0xFFFFFFFF (Removes the current working directory from the default DLL search order)

- 1 (Blocks a DLL Load from the current working directory if the current working directory is set to a WebDAV folder)

- 2 (Blocks a DLL Load from the current working directory if the current working directory is set to a remote folder)
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/08/26, Modified: 2019/12/20
Plugin Output

tcp/445/cifs


Name : SYSTEM\CurrentControlSet\Control\Session Manager\CWDIllegalInDllSearch
Value : Registry Key Empty or Missing

92370 - Microsoft Windows ARP Table
-
Synopsis
Nessus was able to collect and report ARP table information from the remote host.
Description
Nessus was able to collect ARP table information from the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2025/12/15
Plugin Output

tcp/0

172.17.100.10 : 78-64-a0-ba-d1-47
172.17.100.35 : 00-50-56-bc-fc-73
172.17.100.38 : 00-50-56-88-a7-ac
172.17.100.39 : 00-50-56-bc-4f-46
172.17.100.53 : 00-50-56-88-ef-ed
172.17.100.56 : 00-50-56-88-08-9c
172.17.100.59 : 00-50-56-88-e7-eb
172.17.100.68 : 00-50-56-93-38-d4
172.17.100.69 : 00-50-56-93-20-59
172.17.100.78 : 00-50-56-bc-8d-b9
172.17.100.81 : 00-50-56-93-1e-75
172.17.100.91 : 00-50-56-88-23-83
172.17.100.112 : 00-50-56-bc-7d-2b
172.17.100.117 : 00-50-56-bc-4d-ab
172.17.100.141 : 00-50-56-88-57-a4
172.17.100.146 : 00-50-56-93-e4-72
172.17.100.149 : 00-50-56-93-04-7f
172.17.100.154 : 00-50-56-bc-f3-c3
172.17.100.160 : 00-50-56-88-49-b4
172.17.100.167 : 00-50-56-bc-74-6f
172.17.100.183 : 00-50-56-bc-ed-d0
172.17.100.186 : 00-50-56-bc-ad-94
172.17.100.189 : 00-50-56-bc-6b-55
172.17.100.190 : 00-50-56-88-d4-3e
172.17.100.254 : 1a-c2-41-87-f6-3d
172.17.100.255 : ff-ff-ff-ff-ff-ff
224.0.0.22 : 01-00-5e-00-00-16
224.0.0.251 : 01-00-5e-00-00-fb
224.0.0.252 : 01-00-5e-00-00-fc
239.255.255.250 : 01-00-5e-7f-ff-fa
255.255.255.255 : ff-ff-ff-ff-ff-ff
10.54.158.101 : 9c-a3-89-37-ea-68
10.54.158.103 : ff-ff-ff-ff-ff-ff
224.0.0.22 : 01-00-5e-00-00-16
224.0.0.251 : 01-00-5e-00-00-fb
224.0.0.252 : 01-00-5e-00-00-fc
239.255.255.250 : 01-00-5e-7f-ff-fa

Extended ARP table information attached.
70615 - Microsoft Windows AutoRuns Boot Execute
-
Synopsis
Report programs that startup associates with session manager subsystem.
Description
Report registry startup locations associated with the session manager subsystem during boot time.

These registry keys start-up with the smss.exe service during boot time and perform system tasks that cannot be performed while Windows is running.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0

+ HKLM\System\CurrentControlSet\Control\Session Manager\bootexecute
- autocheck autochk /q /v *

70616 - Microsoft Windows AutoRuns Codecs
-
Synopsis
Report programs set to normally start with multimedia.
Description
Codecs are encoders and decoders for digital data streams commonly associated with video and audio playback.

The following keys are codecs that are set to start automatically to control different types of digital media encoding and decoding.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
- vidc.yvu9 : tsbyuv.dll
- vidc.mrle : msrle32.dll
- vidc.iyuv : iyuv_32.dll
- wavemapper : msacm32.drv
- msacm.msadpcm : msadp32.acm
- vidc.yuy2 : msyuv.dll
- vidc.uyvy : msyuv.dll
- vidc.msvc : msvidc32.dll
- msacm.imaadpcm : imaadp32.acm
- msacm.msg711 : msg711.acm
- msacm.msgsm610 : msgsm32.acm
- msacm.l3acm : C:\Windows\System32\l3codeca.acm
- vidc.yvyu : msyuv.dll
- midimapper : midimap.dll
- vidc.i420 : iyuv_32.dll


+ HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32
- vidc.yvu9 : tsbyuv.dll
- vidc.mrle : msrle32.dll
- vidc.iyuv : iyuv_32.dll
- wavemapper : msacm32.drv
- msacm.msadpcm : msadp32.acm
- vidc.yuy2 : msyuv.dll
- vidc.uyvy : msyuv.dll
- vidc.msvc : msvidc32.dll
- msacm.imaadpcm : imaadp32.acm
- msacm.msg711 : msg711.acm
- msacm.msgsm610 : msgsm32.acm
- msacm.l3acm : C:\Windows\SysWOW64\l3codeca.acm
- vidc.cvid : iccvid.dll
- vidc.yvyu : msyuv.dll
- midimapper : midimap.dll
- vidc.i420 : iyuv_32.dll


+ HKLM\Software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance
+ CLSID : {129D7E40-C10D-11D0-AFB9-00AA00B67A42}
- Name : DV Muxer
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {1643E180-90F5-11CE-97D5-00AA0055595A}
- Name : Color Space Converter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {187463A0-5BB7-11D3-ACBE-0080C75E246E}
- Name : WM ASF Reader
- Value : C:\Windows\System32\qasf.dll

+ CLSID : {1B544C20-FD0B-11CE-8C63-00AA0044B51E}
- Name : AVI Splitter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {1DA08500-9EDC-11CF-BC10-00AA00AC74F6}
- Name : VGA 16 Color Ditherer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {1f26a602-2b5c-4b63-b8e8-9ea5c1a7dc2e}
- Name : SBE2MediaTypeProfile
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {212690FB-83E5-4526-8FD7-74478B7939CD}
- Name : Microsoft DTV-DVD Video Decoder
- Value : C:\Windows\System32\msmpeg2vdec.dll

+ CLSID : {280A3020-86CF-11D1-ABE6-00A0C905F375}
- Name : AC3 Parser Filter
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {2DB47AE5-CF39-43C2-B4D6-0CD8D90946F4}
- Name : StreamBufferSink
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {301056D0-6DFF-11D2-9EEB-006008039E37}
- Name : MJPEG Decompressor
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {336475D0-942A-11CE-A870-00AA002FEAB5}
- Name : MPEG-I Stream Splitter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {33FACFE0-A9BE-11D0-A520-00A0D10129C0}
- Name : SAMI (CC) Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {370A1D5D-DDEB-418C-81CD-189E0D4FA443}
- Name : VBI Codec
- Value : C:\Windows\System32\VBICodec.ax

+ CLSID : {3AE86B20-7BE8-11D1-ABE6-00A0C905F375}
- Name : MPEG-2 Splitter
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {3D07A539-35CA-447C-9B05-8D85CE924F9E}
- Name : Closed Captions Analysis Filter
- Value : C:\Windows\System32\cca.dll

+ CLSID : {3E458037-0CA6-41aa-A594-2AA6C02D709B}
- Name : SBE2FileScan
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {42150CD9-CA9A-4EA5-9939-30EE037F6E74}
- Name : Microsoft MPEG-2 Video Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {48025243-2D39-11CE-875D-00608CB78066}
- Name : Internal Script Command Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {4A2286E0-7BEF-11CE-9BD9-0000E202599C}
- Name : MPEG Audio Decoder
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {4EB31670-9FC6-11CF-AF6E-00AA00B67A42}
- Name : DV Splitter
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {51B4ABF3-748F-4E3B-A276-C828330E926A}
- Name : Video Mixing Renderer 9
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {5F5AFF4A-2F7F-4279-88C2-CD88EB39D144}
- Name : Microsoft MPEG-2 Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {6A08CF80-0E18-11CF-A24D-0020AFD79767}
- Name : ACM Wrapper
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {6BC1CFFA-8FC1-4261-AC22-CFB4CC38DB50}
- Name : Video Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {6CFAD761-735D-4AA5-8AFC-AF91A7D61EBA}
- Name : MPEG-2 Video Stream Analyzer
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {6E8D4A20-310C-11D0-B79A-00AA003767A7}
- Name : Line 21 Decoder
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {6F26A6CD-967B-47FD-874A-7AED2C9D25A2}
- Name : Video Port Manager
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {70E102B0-5556-11CE-97C0-00AA0055595A}
- Name : Video Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {7B3BC2A0-AA50-4ae7-BD44-B03649EC87C2}
- Name : VPS Decoder
- Value : C:\Windows\System32\WSTPager.ax

+ CLSID : {7C23220E-55BB-11D3-8B16-00C04FB6BD3D}
- Name : WM ASF Writer
- Value : C:\Windows\System32\qasf.dll

+ CLSID : {814B9800-1C88-11D1-BAD9-00609744111A}
- Name : VBI Surface Allocator
- Value : %SystemRoot%\System32\vbisurf.ax

+ CLSID : {8596E5F0-0DA5-11D0-BD21-00A0C911CE86}
- Name : File writer
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {9B8C4620-2C1A-11D0-8493-00A02438AD48}
- Name : DVD Navigator
- Value : C:\Windows\System32\qdvd.dll

+ CLSID : {A0025E90-E45B-11D1-ABE9-00A0C905F375}
- Name : Overlay Mixer2
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {A888DF60-1E90-11CF-AC98-00AA004C0FA9}
- Name : AVI Draw
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {ACD453BC-C58A-44D1-BBF5-BFB325BE2D78}
- Name : Microsoft MPEG-2 Audio Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {AD6C8934-F31B-4F43-B5E4-0541C1452F6F}
- Name : WST Pager
- Value : C:\Windows\System32\WSTPager.ax

+ CLSID : {AFB6C280-2C41-11D3-8A60-0000F81E0E4A}
- Name : MPEG-2 Demultiplexer
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {B1B77C00-C3E4-11CF-AF79-00AA00B67A42}
- Name : DV Video Decoder
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {C1F400A0-3F08-11D3-9F0B-006008039E37}
- Name : SampleGrabber
- Value : C:\Windows\System32\qedit.dll

+ CLSID : {C1F400A4-3F08-11D3-9F0B-006008039E37}
- Name : Null Renderer
- Value : C:\Windows\System32\qedit.dll

+ CLSID : {C666E115-BB62-4027-A113-82D643FE2D99}
- Name : MPEG-2 Sections and Tables
- Value : C:\Windows\System32\Mpeg2Data.ax

+ CLSID : {C9F5FE02-F851-4EB5-99EE-AD602AF1E619}
- Name : StreamBufferSource
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {CC58E280-8AA1-11D1-B3F1-00AA003761C5}
- Name : Smart Tee
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {CD8743A1-3736-11D0-9E69-00C04FD7C15B}
- Name : Overlay Mixer
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {CF49D4E0-1115-11CE-B03A-0020AF0BA770}
- Name : AVI Decompressor
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D3588AB0-0781-11CE-B03A-0020AF0BA770}
- Name : AVI/WAV File Source
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A1-7548-11CF-A520-0080C77EF58A}
- Name : Wave Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A2-7548-11CF-A520-0080C77EF58A}
- Name : MIDI Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A3-7548-11CF-A520-0080C77EF58A}
- Name : Multi-file Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A5-7548-11CF-A520-0080C77EF58A}
- Name : File stream renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E2448508-95DA-4205-9A27-7EC81E723B1A}
- Name : StreamBufferSink2
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {E2510970-F137-11CE-8B67-00AA00A3F1A6}
- Name : AVI Mux
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {E4206432-01A1-4BEE-B3E1-3702C8EDC574}
- Name : Line 21 Decoder 2
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E436EBB5-524F-11CE-9F53-0020AF0BA770}
- Name : File Source (Async.)
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E436EBB6-524F-11CE-9F53-0020AF0BA770}
- Name : File Source (URL)
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {F8388A40-D5BB-11D0-BE5A-0080C706568E}
- Name : Infinite Pin Tee Filter
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {FA10746C-9B63-4B6C-BC49-FC300EA5F256}
- Name : Enhanced Video Renderer
- Value : C:\Windows\System32\evr.dll

+ CLSID : {FC772AB0-0C7F-11D3-8FF2-00A0C9224CF4}
- Name : BDA MPEG2 Transport Information Filter
- Value : C:\Windows\System32\psisrndr.ax

+ CLSID : {FEB50740-7BEF-11CE-9BD9-0000E202599C}
- Name : MPEG Video Decoder
- Value : C:\Windows\System32\quartz.dll


+ HKLM\Software\Wow6432Node\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance
+ CLSID : {129D7E40-C10D-11D0-AFB9-00AA00B67A42}
- Name : DV Muxer
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {1643E180-90F5-11CE-97D5-00AA0055595A}
- Name : Color Space Converter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {187463A0-5BB7-11D3-ACBE-0080C75E246E}
- Name : WM ASF Reader
- Value : C:\Windows\System32\qasf.dll

+ CLSID : {1B544C20-FD0B-11CE-8C63-00AA0044B51E}
- Name : AVI Splitter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {1DA08500-9EDC-11CF-BC10-00AA00AC74F6}
- Name : VGA 16 Color Ditherer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {1f26a602-2b5c-4b63-b8e8-9ea5c1a7dc2e}
- Name : SBE2MediaTypeProfile
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {212690FB-83E5-4526-8FD7-74478B7939CD}
- Name : Microsoft DTV-DVD Video Decoder
- Value : C:\Windows\System32\msmpeg2vdec.dll

+ CLSID : {280A3020-86CF-11D1-ABE6-00A0C905F375}
- Name : AC3 Parser Filter
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {2DB47AE5-CF39-43C2-B4D6-0CD8D90946F4}
- Name : StreamBufferSink
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {301056D0-6DFF-11D2-9EEB-006008039E37}
- Name : MJPEG Decompressor
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {336475D0-942A-11CE-A870-00AA002FEAB5}
- Name : MPEG-I Stream Splitter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {33FACFE0-A9BE-11D0-A520-00A0D10129C0}
- Name : SAMI (CC) Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {370A1D5D-DDEB-418C-81CD-189E0D4FA443}
- Name : VBI Codec
- Value : C:\Windows\System32\VBICodec.ax

+ CLSID : {3AE86B20-7BE8-11D1-ABE6-00A0C905F375}
- Name : MPEG-2 Splitter
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {3D07A539-35CA-447C-9B05-8D85CE924F9E}
- Name : Closed Captions Analysis Filter
- Value : C:\Windows\System32\cca.dll

+ CLSID : {3E458037-0CA6-41aa-A594-2AA6C02D709B}
- Name : SBE2FileScan
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {42150CD9-CA9A-4EA5-9939-30EE037F6E74}
- Name : Microsoft MPEG-2 Video Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {48025243-2D39-11CE-875D-00608CB78066}
- Name : Internal Script Command Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {4A2286E0-7BEF-11CE-9BD9-0000E202599C}
- Name : MPEG Audio Decoder
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {4EB31670-9FC6-11CF-AF6E-00AA00B67A42}
- Name : DV Splitter
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {51B4ABF3-748F-4E3B-A276-C828330E926A}
- Name : Video Mixing Renderer 9
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {5F5AFF4A-2F7F-4279-88C2-CD88EB39D144}
- Name : Microsoft MPEG-2 Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {6A08CF80-0E18-11CF-A24D-0020AFD79767}
- Name : ACM Wrapper
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {6BC1CFFA-8FC1-4261-AC22-CFB4CC38DB50}
- Name : Video Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {6CFAD761-735D-4AA5-8AFC-AF91A7D61EBA}
- Name : MPEG-2 Video Stream Analyzer
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {6E8D4A20-310C-11D0-B79A-00AA003767A7}
- Name : Line 21 Decoder
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {6F26A6CD-967B-47FD-874A-7AED2C9D25A2}
- Name : Video Port Manager
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {70E102B0-5556-11CE-97C0-00AA0055595A}
- Name : Video Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {7B3BC2A0-AA50-4ae7-BD44-B03649EC87C2}
- Name : VPS Decoder
- Value : C:\Windows\System32\WSTPager.ax

+ CLSID : {7C23220E-55BB-11D3-8B16-00C04FB6BD3D}
- Name : WM ASF Writer
- Value : C:\Windows\System32\qasf.dll

+ CLSID : {814B9800-1C88-11D1-BAD9-00609744111A}
- Name : VBI Surface Allocator
- Value : %SystemRoot%\System32\vbisurf.ax

+ CLSID : {8596E5F0-0DA5-11D0-BD21-00A0C911CE86}
- Name : File writer
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {9B8C4620-2C1A-11D0-8493-00A02438AD48}
- Name : DVD Navigator
- Value : C:\Windows\System32\qdvd.dll

+ CLSID : {A0025E90-E45B-11D1-ABE9-00A0C905F375}
- Name : Overlay Mixer2
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {A888DF60-1E90-11CF-AC98-00AA004C0FA9}
- Name : AVI Draw
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {ACD453BC-C58A-44D1-BBF5-BFB325BE2D78}
- Name : Microsoft MPEG-2 Audio Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {AD6C8934-F31B-4F43-B5E4-0541C1452F6F}
- Name : WST Pager
- Value : C:\Windows\System32\WSTPager.ax

+ CLSID : {AFB6C280-2C41-11D3-8A60-0000F81E0E4A}
- Name : MPEG-2 Demultiplexer
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {B1B77C00-C3E4-11CF-AF79-00AA00B67A42}
- Name : DV Video Decoder
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {C1F400A0-3F08-11D3-9F0B-006008039E37}
- Name : SampleGrabber
- Value : C:\Windows\System32\qedit.dll

+ CLSID : {C1F400A4-3F08-11D3-9F0B-006008039E37}
- Name : Null Renderer
- Value : C:\Windows\System32\qedit.dll

+ CLSID : {C666E115-BB62-4027-A113-82D643FE2D99}
- Name : MPEG-2 Sections and Tables
- Value : C:\Windows\System32\Mpeg2Data.ax

+ CLSID : {C9F5FE02-F851-4EB5-99EE-AD602AF1E619}
- Name : StreamBufferSource
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {CC58E280-8AA1-11D1-B3F1-00AA003761C5}
- Name : Smart Tee
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {CD8743A1-3736-11D0-9E69-00C04FD7C15B}
- Name : Overlay Mixer
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {CF49D4E0-1115-11CE-B03A-0020AF0BA770}
- Name : AVI Decompressor
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D3588AB0-0781-11CE-B03A-0020AF0BA770}
- Name : AVI/WAV File Source
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A1-7548-11CF-A520-0080C77EF58A}
- Name : Wave Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A2-7548-11CF-A520-0080C77EF58A}
- Name : MIDI Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A3-7548-11CF-A520-0080C77EF58A}
- Name : Multi-file Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A5-7548-11CF-A520-0080C77EF58A}
- Name : File stream renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E2448508-95DA-4205-9A27-7EC81E723B1A}
- Name : StreamBufferSink2
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {E2510970-F137-11CE-8B67-00AA00A3F1A6}
- Name : AVI Mux
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {E4206432-01A1-4BEE-B3E1-3702C8EDC574}
- Name : Line 21 Decoder 2
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E436EBB5-524F-11CE-9F53-0020AF0BA770}
- Name : File Source (Async.)
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E436EBB6-524F-11CE-9F53-0020AF0BA770}
- Name : File Source (URL)
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {F8388A40-D5BB-11D0-BE5A-0080C706568E}
- Name : Infinite Pin Tee Filter
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {FA10746C-9B63-4B6C-BC49-FC300EA5F256}
- Name : Enhanced Video Renderer
- Value : C:\Windows\System32\evr.dll

+ CLSID : {FC772AB0-0C7F-11D3-8FF2-00A0C9224CF4}
- Name : BDA MPEG2 Transport Information Filter
- Value : C:\Windows\System32\psisrndr.ax

+ CLSID : {FEB50740-7BEF-11CE-9BD9-0000E202599C}
- Name : MPEG Video Decoder
- Value : C:\Windows\System32\quartz.dll


+ HKLM\Software\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance
+ CLSID : {5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}
- Name : Microsoft Camera Raw Decoder
- Value : C:\Windows\System32\WindowsCodecsRaw.dll


+ HKLM\Software\Wow6432Node\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance
+ CLSID : {5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}
- Name : Microsoft Camera Raw Decoder
- Value : C:\Windows\System32\WindowsCodecsRaw.dll


70617 - Microsoft Windows AutoRuns Explorer
-
Synopsis
Reports programs that startup associates with the explorer process.
Description
Report the startup locations associated with the explorer.exe process.

These items could add controls to menus, add extensions for common protocols such as HTTP or FTP, or set control user activity with the desktop and control panels.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\SOFTWARE\Classes\Protocols\Filter
+ CLSID : {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
- Name : application/octet-stream
- Value : C:\Windows\System32\mscoree.dll

+ CLSID : {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
- Name : application/x-complus
- Value : C:\Windows\System32\mscoree.dll

+ CLSID : {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
- Name : application/x-msdownload
- Value : C:\Windows\System32\mscoree.dll

+ CLSID : {807583E5-5146-11D5-A672-00B0D022E945}
- Name : text/xml
- Value : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\MSOXMLMF.DLL


+ HKLM\SOFTWARE\Classes\Protocols\Handler
+ CLSID : {3050F406-98B5-11CF-BB82-00AA00BDCE0B}
- Name : about
- Value : C:\Windows\System32\mshtml.dll

+ CLSID : {3dd53d40-7b8b-11D0-b013-00aa0059ce02}
- Name : cdl
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {12D51199-0DB5-46FE-A120-47A3D7D937CC}
- Name : dvd
- Value : C:\Windows\System32\msvidctl.dll

+ CLSID : {79eac9e7-baf9-11ce-8c82-00aa004ba90b}
- Name : file
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {79eac9e3-baf9-11ce-8c82-00aa004ba90b}
- Name : ftp
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {79eac9e2-baf9-11ce-8c82-00aa004ba90b}
- Name : http
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {79eac9e5-baf9-11ce-8c82-00aa004ba90b}
- Name : https
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {9D148291-B9C8-11D0-A4CC-0000F80149F6}
- Name : its
- Value : C:\Windows\System32\itss.dll

+ CLSID : {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B}
- Name : javascript
- Value : C:\Windows\System32\mshtml.dll

+ CLSID : {79eac9e7-baf9-11ce-8c82-00aa004ba90b}
- Name : local
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B}
- Name : mailto
- Value : C:\Windows\System32\mshtml.dll

+ CLSID : {05300401-BCBC-11d0-85E3-00C04FD85AB4}
- Name : mhtml
- Value : C:\Windows\System32\inetcomm.dll

+ CLSID : {79eac9e6-baf9-11ce-8c82-00aa004ba90b}
- Name : mk
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {314111c7-a502-11d2-bbca-00c04f8ec294}
- Name : ms-help
- Value : C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll

+ CLSID : {9D148291-B9C8-11D0-A4CC-0000F80149F6}
- Name : ms-its
- Value : C:\Windows\System32\itss.dll

+ CLSID : {3459B272-CC19-4448-86C9-DDC3B4B2FAD3}
- Name : mso-minsb.16
- Value : C:\Program Files\Microsoft Office\Office16\MSOSB.DLL

+ CLSID : {5504BE45-A83B-4808-900A-3A5C36E7F77A}
- Name : osf.16
- Value : C:\Program Files\Microsoft Office\Office16\MSOSB.DLL

+ CLSID : {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B}
- Name : res
- Value : C:\Windows\System32\mshtml.dll

+ CLSID : {14654CA6-5711-491D-B89A-58E571679951}
- Name : tbauth
- Value : C:\Windows\System32\tbauth.dll

+ CLSID : {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E}
- Name : tv
- Value : C:\Windows\System32\msvidctl.dll

+ CLSID : {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B}
- Name : vbscript
- Value : C:\Windows\System32\mshtml.dll

+ CLSID : {14654CA6-5711-491D-B89A-58E571679951}
- Name : windows.tbauth
- Value : C:\Windows\System32\tbauth.dll


+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
+ CLSID : {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
- Name : webcheck
- Value :


+ HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
+ CLSID : {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
- Name : webcheck
- Value :


+ HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers
+ CLSID : {AE81D5A2-A34B-4D93-8DF8-540DBCE48043}
- Name : Kaspersky Anti-Virus 21.15
- Value : C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\x64\shellex.dll

+ CLSID : {e2bf9676-5f8f-435c-97eb-11607a5bedf7}
- Name : ModernSharing
- Value : %SystemRoot%\system32\ntshrui.dll

+ CLSID : {09799AFB-AD67-11d1-ABCD-00C04FC30936}
- Name : Open With
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {A470F8CF-A1E8-4f65-8335-227475AA5C46}
- Name : Open With EncryptionMenu
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}
- Name : Sharing
- Value : %SystemRoot%\system32\ntshrui.dll

+ CLSID : {90AA3A4E-1CBA-4233-B8BB-535773D48449}
- Name : Taskband Pin
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
- Name : Start Menu Pin
- Value : %SystemRoot%\system32\shell32.dll


+ HKLM\Software\Classes\*\ShellEx\PropertySheetHandlers
+ CLSID : {7444C719-39BF-11D1-8CD9-00C04FC29D45}
- Name : CryptoSignMenu
- Value : %SystemRoot%\system32\cryptext.dll

+ CLSID : {748F920F-FB24-4D09-B360-BAF6F199AD6D}
- Name : FCI Properties
- Value : C:\Windows\System32\srmshell.dll

+ CLSID : {1f2e5c40-9550-11ce-99d2-00aa006e086c}
- Name :
- Value : %SystemRoot%\system32\rshx32.dll

+ CLSID : {3EA48300-8CF6-101B-84FB-666CCB9BCD32}
- Name : OLE DocFile Property Page
- Value : %SystemRoot%\system32\docprop.dll

+ CLSID : {883373C3-BF89-11D1-BE35-080036B11A03}
- Name : Summary Properties Page
- Value : %SystemRoot%\system32\shell32.dll


+ HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers
+ CLSID : {f3d06e7c-1e45-4a26-847e-f9fcdee59be0}
- Name : CopyAsPathMenu
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {7BA4C740-9E81-11CF-99D3-00AA004AE837}
- Name : SendTo
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {474C98EE-CF3D-41f5-80E3-4AAB0AB04301}
- Name :
- Value : %SystemRoot%\System32\cscui.dll

+ CLSID : {596AB062-B4D2-4215-9F74-E9109B0A8153}
- Name :
- Value : %SystemRoot%\system32\twext.dll

+ CLSID : {a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
- Name : Start Menu Pin
- Value : %SystemRoot%\system32\shell32.dll


+ HKLM\Software\Classes\AllFileSystemObjects\ShellEx\PropertySheetHandlers
+ CLSID : {596AB062-B4D2-4215-9F74-E9109B0A8153}
- Name :
- Value : %SystemRoot%\system32\twext.dll

+ CLSID : {7EFA68C6-086B-43e1-A2D2-55A113531240}
- Name :
- Value : %SystemRoot%\System32\cscui.dll


+ HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers
+ CLSID : {A470F8CF-A1E8-4f65-8335-227475AA5C46}
- Name : EncryptionMenu
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {AE81D5A2-A34B-4D93-8DF8-540DBCE48043}
- Name : Kaspersky Anti-Virus 21.15
- Value : C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\x64\shellex.dll

+ CLSID : {474C98EE-CF3D-41f5-80E3-4AAB0AB04301}
- Name : Offline Files
- Value : %SystemRoot%\System32\cscui.dll

+ CLSID : {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}
- Name : Sharing
- Value : %SystemRoot%\system32\ntshrui.dll

+ CLSID : {596AB062-B4D2-4215-9F74-E9109B0A8153}
- Name :
- Value : %SystemRoot%\system32\twext.dll


+ HKLM\Software\Classes\Directory\Shellex\PropertySheetHandlers
+ CLSID : {7EFA68C6-086B-43e1-A2D2-55A113531240}
- Name : Offline Files
- Value : %SystemRoot%\System32\cscui.dll

+ CLSID : {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}
- Name : Sharing
- Value : %SystemRoot%\system32\ntshrui.dll

+ CLSID : {1f2e5c40-9550-11ce-99d2-00aa006e086c}
- Name :
- Value : %SystemRoot%\system32\rshx32.dll

+ CLSID : {4a7ded0a-ad25-11d0-98a8-0800361b1103}
- Name :
- Value : %SystemRoot%\system32\mydocs.dll

+ CLSID : {596AB062-B4D2-4215-9F74-E9109B0A8153}
- Name :
- Value : %SystemRoot%\system32\twext.dll

+ CLSID : {ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}
- Name :
- Value : C:\Windows\System32\DfsShlEx.dll

+ CLSID : {ef43ecfe-2ab9-4632-bf21-58909dd177f0}
- Name :
- Value : %SystemRoot%\system32\shell32.dll


+ HKLM\Software\Classes\Directory\Shellex\CopyHookHandlers
+ CLSID : {217FC9C0-3AEA-1069-A2DB-08002B30309D}
- Name : FileSystem
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {40dd6e20-7c17-11ce-a804-00aa003ca9f6}
- Name : Sharing
- Value : %SystemRoot%\system32\ntshrui.dll


+ HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers
+ CLSID : {D969A300-E7FF-11d0-A93B-00A0C90F2719}
- Name : New
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}
- Name : Sharing
- Value : %SystemRoot%\system32\ntshrui.dll


+ HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers
+ CLSID : {AE81D5A2-A34B-4D93-8DF8-540DBCE48043}
- Name : Kaspersky Anti-Virus 21.15
- Value : C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\x64\shellex.dll

+ CLSID : {3dad6c5d-2167-4cae-9914-f99e41c12cfa}
- Name : Library Location
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {474C98EE-CF3D-41f5-80E3-4AAB0AB04301}
- Name : Offline Files
- Value : %SystemRoot%\System32\cscui.dll

+ CLSID : {470C0EBD-5D73-4d58-9CED-E91E22E23282}
- Name : PintoStartScreen
- Value : C:\Windows\System32\appresolver.dll

+ CLSID : {a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
- Name : Start Menu Pin
- Value : %SystemRoot%\system32\shell32.dll


+ HKLM\Software\Classes\Folder\ShellEx\DragDropHandlers
+ CLSID : {BD472F60-27FA-11cf-B8B4-444553540000}
- Name :
- Value : %SystemRoot%\system32\zipfldr.dll


+ HKLM\Software\Classes\Folder\ShellEx\PropertySheetHandlers
+ CLSID : {748F920F-FB24-4D09-B360-BAF6F199AD6D}
- Name : FCI Properties
- Value : C:\Windows\System32\srmshell.dll

+ CLSID : {7EFA68C6-086B-43e1-A2D2-55A113531240}
- Name : Offline Files
- Value : %SystemRoot%\System32\cscui.dll


+ HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers
+ CLSID : {8BA85C75-763B-4103-94EB-9470F12FE0F7}
- Name : SkyDrivePro1 (ErrorConflict)
- Value : C:\PROGRA~1\MICROS~1\Office16\GROOVEEX.DLL

+ CLSID : {CD55129A-B1A1-438E-A425-CEBC7DC684EE}
- Name : SkyDrivePro2 (SyncInProgress)
- Value : C:\PROGRA~1\MICROS~1\Office16\GROOVEEX.DLL

+ CLSID : {E768CD3B-BDDC-436D-9C13-E1B39CA257B1}
- Name : SkyDrivePro3 (InSync)
- Value : C:\PROGRA~1\MICROS~1\Office16\GROOVEEX.DLL

+ CLSID : {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}
- Name : EnhancedStorageShell
- Value : C:\Windows\System32\EhStorShell.dll

+ CLSID : {4E77131D-3629-431c-9818-C5679DC83E81}
- Name : Offline Files
- Value : %SystemRoot%\System32\cscui.dll


+ HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers
+ CLSID : {8BA85C75-763B-4103-94EB-9470F12FE0F7}
- Name : SkyDrivePro1 (ErrorConflict)
- Value : C:\PROGRA~1\MICROS~1\Office16\GROOVEEX.DLL

+ CLSID : {CD55129A-B1A1-438E-A425-CEBC7DC684EE}
- Name : SkyDrivePro2 (SyncInProgress)
- Value : C:\PROGRA~1\MICROS~1\Office16\GROOVEEX.DLL

+ CLSID : {E768CD3B-BDDC-436D-9C13-E1B39CA257B1}
- Name : SkyDrivePro3 (InSync)
- Value : C:\PROGRA~1\MICROS~1\Office16\GROOVEEX.DLL


70619 - Microsoft Windows AutoRuns Internet Explorer
-
Synopsis
Report programs that startup associates with Internet Explorer.
Description
Report registry startup locations associated with the Internet Explorer (IE) application.

The startup values include Internet Explorer plugins to extend the functionality of IE, browser toolbars, hooks into browser controls, and settings.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
+ CLSID : {1FD49718-1D00-4B19-AF5F-070AF6D5D54C}
- Name : IEToEdge BHO
- Value : C:\Program Files (x86)\Microsoft\Edge\Application\144.0.3719.82\BHO\ie_to_edge_bho_64.dll

+ CLSID : {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}
- Value : C:\PROGRA~1\MICROS~1\Office16\GROOVEEX.DLL


HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
+ CLSID : {1FD49718-1D00-4B19-AF5F-070AF6D5D54C}
- Name : IEToEdge BHO
- Value : C:\Program Files (x86)\Microsoft\Edge\Application\144.0.3719.82\BHO\ie_to_edge_bho_64.dll

+ CLSID : {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}
- Value : C:\PROGRA~1\MICROS~1\Office16\GROOVEEX.DLL


HKLM\Software\Microsoft\Internet Explorer\Extensions
+ CLSID : {2670000A-7350-4f3c-8081-5663EE0C6C49}
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}
- Value : CLSID is not set in HKCR\CLSID\


HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Extensions
+ CLSID : {2670000A-7350-4f3c-8081-5663EE0C6C49}
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}
- Value : CLSID is not set in HKCR\CLSID\


70620 - Microsoft Windows AutoRuns Known DLLs
-
Synopsis
DLLs listed to be shared by processes.
Description
The known DLLs registry setting is used to define DLLs that are shared between processes without a process having to search for the DLL location.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0

+ HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs
- imagehlp : IMAGEHLP.dll
- shcore : SHCORE.dll
- oleaut32 : OLEAUT32.dll
- normaliz : NORMALIZ.dll
- msvcrt : MSVCRT.dll
- shell32 : SHELL32.dll
- msctf : MSCTF.dll
- gdi32 : gdi32.dll
- nsi : NSI.dll
- advapi32 : advapi32.dll
- coml2 : coml2.dll
- _wowarmhw : wowarmhw.dll
- clbcatq : clbcatq.dll
- wow64win : wow64win.dll
- shlwapi : SHLWAPI.dll
- psapi : PSAPI.DLL
- imm32 : IMM32.dll
- combase : combase.dll
- user32 : user32.dll
- sechost : sechost.dll
- _xtajit : xtajit.dll
- _wow64cpu : wow64cpu.dll
- wow64 : wow64.dll
- rpcrt4 : rpcrt4.dll
- kernel32 : kernel32.dll
- ws2_32 : WS2_32.dll
- wldap32 : WLDAP32.dll
- ole32 : ole32.dll
- difxapi : difxapi.dll
- setupapi : Setupapi.dll
- comdlg32 : COMDLG32.dll
- gdiplus : gdiplus.dll
70613 - Microsoft Windows AutoRuns LSA Providers
-
Synopsis
Programs set to start as Local Security Authority.
Description
An LSA (Local Security Authority) is an application that can be used to authorize users to their systems. The reported autoruns are available to provide this service or features to this service.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0



+ HKLM\SYSTEM\CurrentControlSet\Control\Lsa\authentication packages
- msv1_0


+ HKLM\SYSTEM\CurrentControlSet\Control\Lsa\notification packages
- rassfm
- scecli


+ HKLM\SYSTEM\CurrentControlSet\Control\Lsa\security packages
- ""
70621 - Microsoft Windows AutoRuns Logon
-
Synopsis
Report programs that start-up from the most common registry locations.
Description
Report the most common startup locations used by programs. These are commonly associated with programs that start automatically when the computer is turned on, users log in, users log off, or remote sessions are started.

Such keys can be set from a program install, GPO, or through a malicious process to maintain persistence.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd
- rdpclip


+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\userinit
- C:\Windows\system32\userinit.exe


+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\vmapplet
- SystemPropertiesPerformance.exe /pagefile


+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\shell
- explorer.exe


+ HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot
- AlternateShell : cmd.exe


+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Name : vmware user process
- Value : "C:\Program Files\VMware\VMware Tools\vmtoolsd.exe" -n vmusr

- Name : securityhealth
- Value : %windir%\system32\SecurityHealthSystray.exe


+ HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components
+ CLSID : >{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
- Name : Microsoft Windows Media Player
- Value : %SystemRoot%\system32\unregmp2.exe /ShowWMP

+ CLSID : {2C7339CF-2B09-4501-B3F3-F3508C9228ED}
- Name : Themes Setup
- Value : /UserInstall

+ CLSID : {6BF52A52-394A-11d3-B153-00C04F79FAA6}
- Name : Microsoft Windows Media Player
- Value : %SystemRoot%\system32\unregmp2.exe /FirstLogon

+ CLSID : {89820200-ECBD-11cf-8B85-00AA005B4340}
- Name : Windows Desktop Update
- Value : U

+ CLSID : {89820200-ECBD-11cf-8B85-00AA005B4383}
- Name : Web Platform Customizations
- Value : C:\Windows\System32\ie4uinit.exe -UserConfig

+ CLSID : {89B4C1CD-B018-4511-B0A1-5476DBF70820}
- Name :
- Value : C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install

+ CLSID : {9459C573-B17A-45AE-9F64-1857B5D58CEE}
- Name : Microsoft Edge
- Value : "C:\Program Files (x86)\Microsoft\Edge\Application\144.0.3719.82\Installer\setup.exe" --configure-user-settings --verbose-logging --system-level --msedge --channel=stable

+ CLSID : {A509B1A7-37EF-4b3f-8CFC-4F3A74704073}
- Name : Applying Enhanced Security Configuration
- Value : "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iesetup.dll",IEHardenAdmin

+ CLSID : {A509B1A8-37EF-4b3f-8CFC-4F3A74704073}
- Name : Applying Enhanced Security Configuration
- Value : "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iesetup.dll",IEHardenUser


+ HKLM\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components
+ CLSID : >{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
- Name : Microsoft Windows Media Player
- Value : %SystemRoot%\system32\unregmp2.exe /ShowWMP

+ CLSID : {6BF52A52-394A-11d3-B153-00C04F79FAA6}
- Name : Microsoft Windows Media Player
- Value : %SystemRoot%\system32\unregmp2.exe /FirstLogon

+ CLSID : {89B4C1CD-B018-4511-B0A1-5476DBF70820}
- Name :
- Value : C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install


+ HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows
- iconservicelib : IconCodecService.dll
- Load :


70622 - Microsoft Windows AutoRuns Network Providers
-
Synopsis
Report programs set to automatically start-up as a Network Provider.
Description
The DLLs listed under the registry key are used to provide network services for new protocols.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order\ProviderOrder
- vmhgfs : %SystemRoot%\System32\vmhgfs.dll
- RDPNP : %SystemRoot%\System32\drprov.dll
- LanmanWorkstation : %SystemRoot%\System32\ntlanman.dll

+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\HwOrder\ProviderOrder
- vmhgfs : %SystemRoot%\System32\vmhgfs.dll
- RDPNP : %SystemRoot%\System32\drprov.dll
- LanmanWorkstation : %SystemRoot%\System32\ntlanman.dll
70623 - Microsoft Windows AutoRuns Print Monitor
-
Synopsis
Report programs set to start automatically as a print monitor.
Description
Report the DLLs that control print monitor functions for multiple programs and systems.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0

+ HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
- Local Port : localspl.dll
- Standard TCP/IP Port : tcpmon.dll
- USB Monitor : usbmon.dll
- WSD Port : APMon.dll
70618 - Microsoft Windows AutoRuns Registry Hijack Possible Locations
-
Synopsis
Report common registry keys used to hijack execution.
Description
Report common registry keys that can be used to hijack system process execution.

These registry keys can be used to either replace execution or shim a process in the middle of execution to hijack control. Confirm that everything listed here is set to the appropriate settings and that it doesn't look like another process is taking control of the process's execution.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\SOFTWARE\Classes\Exefile\Shell\Open\Command
- Command : "%1" %*


+ HKLM\Software\Classes\.exe : exefile
- open : "%1" %*
- runas : "%1" %*
- runasuser :


+ HKLM\Software\Classes\.cmd : cmdfile
- edit : %SystemRoot%\System32\NOTEPAD.EXE %1
- open : "%1" %*
- print : %SystemRoot%\System32\NOTEPAD.EXE /p %1
- runas : %SystemRoot%\System32\cmd.exe /C "%1" %*
- runasuser :


+ HKLM\Software\Classes\.htm : htmlfile
- Edit : "C:\Program Files\Microsoft Office\Office16\msohtmed.exe" %1
- open : "C:\Program Files\Internet Explorer\iexplore.exe" %1
- Print : "C:\Program Files\Microsoft Office\Office16\msohtmed.exe" /p %1
- printto : "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" "%2" "%3" "%4"


+ HKLM\Software\Classes\.html : htmlfile
- Edit : "C:\Program Files\Microsoft Office\Office16\msohtmed.exe" %1
- open : "C:\Program Files\Internet Explorer\iexplore.exe" %1
- Print : "C:\Program Files\Microsoft Office\Office16\msohtmed.exe" /p %1
- printto : "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" "%2" "%3" "%4"


+ HKLM\Software\Classes\.doc : Word.Document.8
- Edit : "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" /vu "%1"
- New : "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" /n /f "%1"
- OnenotePrintto : "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" /j "%1" "%2"
- Open : "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" /n "%1" /o "%u"
- OpenAsReadOnly : "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" /h /n "%1"
- Print : "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" /i "%1"
- Printto : "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" /j "%1" "%2"
- ViewProtected : "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" /vp "%1"


+ HKLM\Software\Classes\.docx : Word.Document.12
- Edit : "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" /vu "%1"
- New : "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" /n /f "%1"
- OnenotePrintto : "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" /j "%1" "%2"
- Open : "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" /n "%1" /o "%u"
- OpenAsReadOnly : "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" /h /n "%1"
- Print : "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" /i "%1"
- Printto : "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" /j "%1" "%2"
- ViewProtected : "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" /vp "%1"


+ HKLM\Software\Classes\.vbs : VBSFile
- Edit : "%SystemRoot%\System32\Notepad.exe" %1
- Open : "%SystemRoot%\System32\WScript.exe" "%1" %*
- Open2 : "%SystemRoot%\System32\CScript.exe" "%1" %*
- Print : "%SystemRoot%\System32\Notepad.exe" /p %1


+ HKLM\Software\Classes\.txt : txtfile
- open : %SystemRoot%\system32\NOTEPAD.EXE %1
- print : %SystemRoot%\system32\NOTEPAD.EXE /p %1
- printto : %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4"


+ HKLM\Software\Classes\.xls : Excel.Sheet.8
- Edit : "C:\Program Files\Microsoft Office\Office16\EXCEL.EXE" /dde
- New : "C:\Program Files\Microsoft Office\Office16\EXCEL.EXE" /dde /n
- Open : "C:\Program Files\Microsoft Office\Office16\EXCEL.EXE" /dde
- OpenAsReadOnly : "C:\Program Files\Microsoft Office\Office16\EXCEL.EXE" /h /dde
- Print : "C:\Program Files\Microsoft Office\Office16\EXCEL.EXE" /dde
- Printto : "C:\Program Files\Microsoft Office\Office16\EXCEL.EXE" /dde
- ViewProtected : "C:\Program Files\Microsoft Office\Office16\EXCEL.EXE" /dde


+ HKLM\Software\Classes\.xml : xmlfile
- edit : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\MSOXMLED.EXE" /verb edit "%1"
- open : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\MSOXMLED.EXE" /verb open "%1"


+ HKLM\Software\Classes\.pif : piffile
- open : "%1" %*


+ HKLM\Software\Classes\.txt : txtfile
- open : %SystemRoot%\system32\NOTEPAD.EXE %1
- print : %SystemRoot%\system32\NOTEPAD.EXE /p %1
- printto : %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4"



70624 - Microsoft Windows AutoRuns Report
-
Synopsis
Generate a CSV report of all autoruns.
Description
Collect all autoruns listed in the Windows autoruns plugins and report the primary content in a CSV report.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+Enabled Autoruns Detection Types
- LSA Provider
- Boot Execute
- WinLogon
- Known DLLs
- Winsock Provider
- Service
- Explorer
- Logon
- Codecs
- Driver
- Image Hijack
- Network Provider
- Scheduled Tasks
- Print Monitor
- Internet Explorer


The attached CSV contains information about Windows autoruns.
70625 - Microsoft Windows AutoRuns Scheduled Tasks
-
Synopsis
Report processes that start-up via the scheduled task manager.
Description
This plugin lists the scheduled tasks for the system. The scheduled tasks are often used to update software, for systems administrators to run processes, and can be used by malware to spread on systems.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ Task
+ RegistrationInfo
- Version : 1.3.215.9
- Description : Keeps your Microsoft software up to date. If this task is disabled or stopped, your Microsoft software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This task uninstalls itself when there is no Microsoft software using it.
- URI : \MicrosoftEdgeUpdateTaskMachineCore{416F8AF3-3A26-4052-96FE-D3C5484CAE9F}
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : Parallel
- Priority : 4
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ LogonTrigger
+ CalendarTrigger
- StartBoundary : 2025-12-22T11:12:13
+ ScheduleByDay
- DaysInterval : 1
+ Actions
+ Exec
- Command : C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
- Arguments : /c

+ Task
+ RegistrationInfo
- Version : 1.3.215.9
- Description : Keeps your Microsoft software up to date. If this task is disabled or stopped, your Microsoft software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This task uninstalls itself when there is no Microsoft software using it.
- URI : \MicrosoftEdgeUpdateTaskMachineUA{98905A8C-9E8B-46E6-A7AA-8E57D8D4FEBE}
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
- Priority : 4
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ CalendarTrigger
- StartBoundary : 2025-12-22T10:42:13
+ Repetition
- Interval : PT1H
- Duration : P1D
+ ScheduleByDay
- DaysInterval : 1
+ Actions
+ Exec
- Command : C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
- Arguments : /ua /installsource scheduler

+ Task
+ RegistrationInfo
- Description : Ensure Npcap service is configured to start at boot
- URI : \npcapwatchdog
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
+ Actions
+ Exec
- Command : C:\Program Files\Npcap\CheckStatus.bat

+ Task
+ RegistrationInfo
- Author : LKP_SIP_APPSRV-\Production
- Description : Updates out-of-date system feeds.
- URI : \User_Feed_Synchronization-{D3E03E00-A856-48AF-8634-8010F28507B0}
+ Principals
+ Principal
- UserId : S-1-5-21-3194671253-1068146636-4210433707-500
- LogonType : InteractiveToken
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ CalendarTrigger
- StartBoundary : 2026-01-24T16:43:36+05:30
- EndBoundary : 2036-01-24T16:43:36+05:30
+ ScheduleByDay
- DaysInterval : 1
+ Actions
+ Exec
- Command : C:\Windows\system32\msfeedssync.exe
- Arguments : sync

+ Task
+ RegistrationInfo
- Version : 15.0.0
- Date : 2012-01-01T00:00:00
- Author : Microsoft Office
- Description : Task used to ensure that the Microsoft Office Subscription licensing is current.
- URI : \Microsoft\Office\Office 15 Subscription Heartbeat
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT4H
- MultipleInstancesPolicy : IgnoreNew
+ RestartOnFailure
- Count : 3
- Interval : PT1M
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ CalendarTrigger
- StartBoundary : 2010-01-01T00:00:00
- ExecutionTimeLimit : PT4H
- RandomDelay : PT8H
+ ScheduleByDay
- DaysInterval : 1
+ Actions
+ Exec
- Command : %ProgramFiles%\Common Files\Microsoft Shared\Office16\OLicenseHeartbeat.exe

+ Task
+ RegistrationInfo
- Description : This task initiates the background task for Office Telemetry Agent, which scans and uploads usage and error information for Office solutions.
- URI : \Microsoft\Office\OfficeTelemetryAgentFallBack2016
+ Principals
+ Principal
- GroupId : S-1-5-32-545
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ LogonTrigger
- Delay : PT30M
+ Repetition
- Interval : PT12H
+ Actions
+ Exec
- Command : "C:\Program Files\Microsoft Office\Office16\msoia.exe"
- Arguments : scan upload mininterval:2880

+ Task
+ RegistrationInfo
- Description : This task initiates Office Telemetry Agent, which scans and uploads usage and error information for Office solutions when a user logs on to the computer.
- URI : \Microsoft\Office\OfficeTelemetryAgentLogOn2016
+ Principals
+ Principal
- GroupId : S-1-5-32-545
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ LogonTrigger
+ Repetition
- Interval : PT8H
+ Actions
+ Exec
- Command : "C:\Program Files\Microsoft Office\Office16\msoia.exe"
- Arguments : scan upload

+ Task
+ RegistrationInfo
- Author : $(@%systemroot%\system32\SrvInitConfig.exe,-100)
- Description : $(@%systemroot%\system32\SrvInitConfig.exe,-101)
- URI : \Microsoft\Windows\Server Initial Configuration Task
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
+ Actions
+ Exec
- Command : %windir%\system32\srvinitconfig.exe
- Arguments : /disableconfigtask

+ Task
+ RegistrationInfo
- Date : 2010-09-30T14:53:37.9516706
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICI;GR;;;AU)(A;;FRFX;;;LS)
- URI : \Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT2H
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P2D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {84F0FAE1-C27B-4F6F-807B-28CF6F96287D}
- Data : /RuntimeWide

+ Task
+ RegistrationInfo
- Date : 2010-09-30T14:53:37.9516706
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICI;GR;;;AU)(A;;FRFX;;;LS)
- URI : \Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT2H
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P2D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {429BC048-379E-45E0-80E4-EB1977941B5C}
- Data : /RuntimeWide

+ Task
+ RegistrationInfo
- Date : 2010-09-30T14:53:37.9516706
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICI;GR;;;AU)(A;;FRFX;;;LS)
- URI : \Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Critical
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT2H
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- WakeToRun : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P2D
+ Triggers
+ IdleTrigger
+ Actions
+ ComHandler
- ClassId : {613FBA38-A3DF-4AB8-9674-5604984A299A}
- Data : /RuntimeWide

+ Task
+ RegistrationInfo
- Date : 2010-09-30T14:53:37.9516706
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICI;GR;;;AU)(A;;FRFX;;;LS)
- URI : \Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Critical
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT2H
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- WakeToRun : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P2D
+ Triggers
+ IdleTrigger
+ Actions
+ ComHandler
- ClassId : {DE434264-8FE9-4C0B-A83B-89EBEEBFF78E}
- Data : /RuntimeWide

+ Task
+ RegistrationInfo
- Date : 2006-11-10T14:29:55.5851926
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;WD)
- Author : $(@%systemRoot%\System32\msdrm.dll,-6001)
- Description : $(@%systemRoot%\System32\msdrm.dll,-6002)
- URI : \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)
+ Principals
+ Principal
- GroupId : S-1-1-0
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : Parallel
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ CalendarTrigger
- StartBoundary : 2006-11-09T03:00:00
- RandomDelay : PT1H
+ ScheduleByDay
- DaysInterval : 1
+ LogonTrigger
- Delay : PT1H
+ Actions
+ ComHandler
- ClassId : {CF2CF428-325B-48D3-8CA8-7633E36E5A32}

+ Task
+ RegistrationInfo
- Date : 2006-11-10T14:29:55.5851926
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;WD)
- Author : $(@%systemRoot%\System32\msdrm.dll,-6001)
- Description : $(@%systemRoot%\System32\msdrm.dll,-6003)
- URI : \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)
+ Principals
+ Principal
- GroupId : S-1-1-0
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : Parallel
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
- Enabled : false
- Delay : PT1H
+ Actions
+ ComHandler
- ClassId : {BF5CB148-7C77-4D8A-A53E-D81C70CF743C}

+ Task
+ RegistrationInfo
- Date : 2015-02-09T10:54:13.9629482
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FA;;;S-1-5-87-2978287140-3787137133-1749738600-1988163579-2060695581)
- Source : $(@%SystemRoot%\system32\ApplockerCsp.dll,-101)
- Author : $(@%SystemRoot%\system32\ApplockerCsp.dll,-100)
- Description : $(@%SystemRoot%\system32\ApplockerCsp.dll,-102)
- URI : \Microsoft\Windows\AppID\EDP Policy Manager
+ Principals
+ Principal
- UserId : S-1-5-19
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7588BCA328009213
+ WnfStateChangeTrigger
- StateName : 75E0BCA328009213
+ Actions
+ ComHandler
- ClassId : {DECA92E0-AF85-439E-9204-86679978DA08}
- Data : EdpPolicyManager

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;CI;FA;;;LS)(A;CI;FA;;;S-1-5-80-2078495744-2416903469-4072184685-3943858305-976987417)
- Source : $(@%systemroot%\system32\appidsvc.dll,-300)
- Author : $(@%systemroot%\system32\appidsvc.dll,-301)
- Description : $(@%systemroot%\system32\appidsvc.dll,-302)
- URI : \Microsoft\Windows\AppID\PolicyConverter
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- MultipleInstancesPolicy : Queue
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\appidpolicyconverter.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;CI;FA;;;LS)(A;CI;FA;;;S-1-5-80-2078495744-2416903469-4072184685-3943858305-976987417)
- Source : $(@%systemroot%\system32\appidsvc.dll,-200)
- Author : $(@%systemroot%\system32\appidsvc.dll,-201)
- Description : $(@%systemroot%\system32\appidsvc.dll,-202)
- URI : \Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck
+ Principals
+ Principal
- UserId : S-1-5-19
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- MultipleInstancesPolicy : Queue
- Priority : 10
- StartWhenAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- Duration : PT3M
- WaitTimeout : PT23H
- StopOnIdleEnd : true
- RestartOnIdle : true
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
- Delay : PT30M
+ Repetition
- Interval : P1D
+ Actions
+ Exec
- Command : %windir%\system32\appidcertstorecheck.exe

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;GA;;;BA)(A;;GA;;;SY)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\system32\appraiser.dll,-500)
- Author : $(@%SystemRoot%\system32\appraiser.dll,-501)
- Description : $(@%SystemRoot%\system32\appraiser.dll,-502)
- URI : \Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : P4D
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2008-09-01T03:00:00
+ Repetition
- Interval : P1D
- RandomDelay : PT2H
+ WnfStateChangeTrigger
- Enabled : false
- StateName : 750CBCA3290B9641
- Data : 01
+ WnfStateChangeTrigger
- Enabled : false
- StateName : 7510BCA323028B41
- Data : 01
+ Actions
+ Exec
- Command : %windir%\system32\compattelrunner.exe

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;GA;;;BA)(A;;GA;;;SY)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\system32\invagent.dll,-701)
- Author : $(@%SystemRoot%\system32\invagent.dll,-701)
- Description : $(@%SystemRoot%\system32\invagent.dll,-702)
- URI : \Microsoft\Windows\Application Experience\ProgramDataUpdater
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
- Priority : 4
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P1DT12H
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\compattelrunner.exe
- Arguments : -maintenance

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;LA)(A;OICI;FA;;;SY)(A;OICI;FRFX;;;AU)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\system32\Startupscan.dll,-701)
- Author : $(@%SystemRoot%\system32\Startupscan.dll,-701)
- Description : $(@%SystemRoot%\system32\Startupscan.dll,-702)
- URI : \Microsoft\Windows\Application Experience\StartupAppTask
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : Parallel
- Priority : 4
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P2D
- Deadline : P3D
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\rundll32.exe
- Arguments : Startupscan.dll,SusRunTask

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FRFX;;;BA)(A;;FRFX;;;AU)(A;;FRFX;;;IU)
- Source : $(@%systemroot%\system32\AppHostRegistrationVerifier.exe,-10005)
- Author : $(@%systemroot%\system32\AppHostRegistrationVerifier.exe,-10004)
- Description : $(@%systemroot%\system32\AppHostRegistrationVerifier.exe,-10002)
- URI : \Microsoft\Windows\ApplicationData\appuriverifierdaily
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT15M
- MultipleInstancesPolicy : Queue
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P7D
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\AppHostRegistrationVerifier.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FRFX;;;BA)(A;;FRFX;;;AU)(A;;FRFX;;;IU)
- Source : $(@%systemroot%\system32\AppHostRegistrationVerifier.exe,-10005)
- Author : $(@%systemroot%\system32\AppHostRegistrationVerifier.exe,-10004)
- Description : $(@%systemroot%\system32\AppHostRegistrationVerifier.exe,-10002)
- URI : \Microsoft\Windows\ApplicationData\appuriverifierinstall
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT15M
- MultipleInstancesPolicy : Queue
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- Delay : PT1M
- StateName : 7508BCA32C7C8741
+ Actions
+ Exec
- Command : %windir%\system32\AppHostRegistrationVerifier.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FRFX;;;BA)(A;;FA;;;SY)
- Source : $(@%systemroot%\system32\Windows.Storage.ApplicationData.dll,-5001)
- Author : $(@%systemroot%\system32\Windows.Storage.ApplicationData.dll,-5002)
- Description : $(@%systemroot%\system32\Windows.Storage.ApplicationData.dll,-5003)
- URI : \Microsoft\Windows\ApplicationData\CleanupTemporaryState
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P1M
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\rundll32.exe
- Arguments : Windows.Storage.ApplicationData.dll,CleanupTemporaryState

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FRFX;;;BA)(A;;FA;;;SY)
- Source : $(@%systemroot%\system32\dssvc.dll,-10005)
- Author : $(@%systemroot%\system32\dssvc.dll,-10004)
- Description : $(@%systemroot%\system32\dssvc.dll,-10006)
- URI : \Microsoft\Windows\ApplicationData\DsSvcCleanup
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P1M
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\dstokenclean.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;GA;;;SY)(A;;FRFX;;;LS)(A;;FA;;;BA)
- URI : \Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfIdle : true
+ IdleSettings
- Duration : PT15M
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P7D
+ Triggers
+ LogonTrigger
- Delay : PT1H
+ Actions
+ Exec
- Command : %windir%\system32\rundll32.exe
- Arguments : %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask

+ Task
+ RegistrationInfo
- Source : $(@%systemroot%\system32\acproxy.dll,-100)
- Author : $(@%systemroot%\system32\acproxy.dll,-101)
- Description : $(@%systemroot%\system32\acproxy.dll,-102)
- URI : \Microsoft\Windows\Autochk\Proxy
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : P365D
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
- Delay : PT30M
+ Actions
+ Exec
- Command : %windir%\system32\rundll32.exe
- Arguments : /d acproxy.dll,PerformAutochkOperations

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FRFX;;;AU)(A;;FA;;;SY)
- URI : \Microsoft\Windows\BitLocker\BitLocker Encrypt All Drives
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7568BCA32B188341
+ Actions
+ ComHandler
- ClassId : {61BCD1B9-340C-40EC-9D41-D7F1C0632F05}
- Data : BitLockerEncryptAllDrives

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FRFX;;;AU)(A;;FA;;;SY)
- URI : \Microsoft\Windows\BitLocker\BitLocker MDM policy Refresh
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7540BCA32B188341
+ Actions
+ ComHandler
- ClassId : {61BCD1B9-340C-40EC-9D41-D7F1C0632F05}
- Data : BitLockerPolicy

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)
- Author : $(@%SystemRoot%\system32\BthUdTask.exe,-1002)
- Description : $(@%SystemRoot%\system32\BthUdTask.exe,-1001)
- URI : \Microsoft\Windows\Bluetooth\UninstallDeviceTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- MultipleInstancesPolicy : Parallel
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ Exec
- Command : BthUdTask.exe
- Arguments : $(Arg0)

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)
- Author : $(@%systemRoot%\System32\bisrv.dll,-102)
- Description : $(@%systemRoot%\System32\bisrv.dll,-103)
- URI : \Microsoft\Windows\BrokerInfrastructure\BgTaskRegistrationMaintenanceTask
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT6M
- MultipleInstancesPolicy : IgnoreNew
- Priority : 6
- RunOnlyIfIdle : true
+ IdleSettings
- Duration : PT1S
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P14D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {E984D939-0E00-4DD9-AC3A-7ACA04745521}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FRFX;;;NS)
- Source : $(@%SystemRoot%\system32\ngctasks.dll,-101)
- Author : $(@%SystemRoot%\system32\ngctasks.dll,-100)
- Description : $(@%SystemRoot%\system32\ngctasks.dll,-103)
- URI : \Microsoft\Windows\CertificateServicesClient\AikCertEnrollTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : Queue
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7510BCA323098541
+ Actions
+ ComHandler
- ClassId : {47E30D54-DAC1-473A-AFF7-2355BF78881F}
- Data : AIKCertEnroll

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FRFX;;;NS)
- Source : $(@%SystemRoot%\system32\ngctasks.dll,-101)
- Author : $(@%SystemRoot%\system32\ngctasks.dll,-100)
- Description : $(@%SystemRoot%\system32\ngctasks.dll,-104)
- URI : \Microsoft\Windows\CertificateServicesClient\CryptoPolicyTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : Queue
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7530BCA323098541
+ Actions
+ ComHandler
- ClassId : {47E30D54-DAC1-473A-AFF7-2355BF78881F}
- Data : CryptoPolicy

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FRFX;;;NS)
- Source : $(@%SystemRoot%\system32\ngctasks.dll,-101)
- Author : $(@%SystemRoot%\system32\ngctasks.dll,-100)
- Description : $(@%SystemRoot%\system32\ngctasks.dll,-102)
- URI : \Microsoft\Windows\CertificateServicesClient\KeyPreGenTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : Queue
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA323098541
+ WnfStateChangeTrigger
- Delay : PT10M
- StateName : 7520BCA323098541
+ WnfStateChangeTrigger
- Delay : PT10M
- StateName : 75C0BCA33E06830D
+ LogonTrigger
- Enabled : false
- Delay : PT10M
+ SessionStateChangeTrigger
- Enabled : false
- Delay : PT10M
- StateChange : ConsoleConnect
+ Actions
+ ComHandler
- ClassId : {47E30D54-DAC1-473A-AFF7-2355BF78881F}
- Data : NGCKeyPregen

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)
- Source : $(@%SystemRoot%\system32\dimsjob.dll,-100)
- Author : $(@%SystemRoot%\system32\dimsjob.dll,-101)
- Description : $(@%SystemRoot%\system32\dimsjob.dll,-102)
- URI : \Microsoft\Windows\CertificateServicesClient\SystemTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : Parallel
+ RestartOnFailure
- Count : 5
- Interval : PT1M
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA32A1E890D
+ RegistrationTrigger
+ BootTrigger
- Delay : PT10S
+ Repetition
- Interval : PT8H
+ Actions
+ ComHandler
- ClassId : {58FB76B9-AC85-4E55-AC04-427593B1D060}
- Data : SYSTEM

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;IU)
- Source : $(@%SystemRoot%\system32\dimsjob.dll,-100)
- Author : $(@%SystemRoot%\system32\dimsjob.dll,-101)
- Description : $(@%SystemRoot%\system32\dimsjob.dll,-102)
- URI : \Microsoft\Windows\CertificateServicesClient\UserTask
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : Parallel
+ RestartOnFailure
- Count : 5
- Interval : PT1M
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : F510BCA32A1E890D
+ RegistrationTrigger
+ LogonTrigger
+ Repetition
- Interval : PT8H
+ EventTrigger
- ExecutionTimeLimit : PT30M
- Delay : PT25M
+ Repetition
- Interval : PT1H
- Duration : PT4H
- Subscription : <QueryList><Query Id="0" Path="Microsoft-Windows-User Device Registration/Admin"><Select Path="Microsoft-Windows-User Device Registration/Admin">*[System[Provider[@Name='Microsoft-Windows-User Device Registration'] and EventID=300]]</Select></Query></QueryList>
+ Actions
+ ComHandler
- ClassId : {58FB76B9-AC85-4E55-AC04-427593B1D060}
- Data : USER

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFW;;;IU)
- Source : $(@%SystemRoot%\system32\dimsjob.dll,-100)
- Author : $(@%SystemRoot%\system32\dimsjob.dll,-101)
- Description : $(@%SystemRoot%\system32\dimsjob.dll,-102)
- URI : \Microsoft\Windows\CertificateServicesClient\UserTask-Roam
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : Parallel
+ RestartOnFailure
- Count : 5
- Interval : PT1M
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ SessionStateChangeTrigger
- StateChange : SessionLock
+ SessionStateChangeTrigger
- StateChange : SessionUnlock
+ Actions
+ ComHandler
- ClassId : {58FB76B9-AC85-4E55-AC04-427593B1D060}
- Data : KEYROAMING

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FR;;;AU)
- Source : $(@%systemroot%\system32\pstask.dll,-100)
- Author : $(@%systemroot%\system32\pstask.dll,-101)
- Description : $(@%systemroot%\system32\pstask.dll,-102)
- URI : \Microsoft\Windows\Chkdsk\ProactiveScan
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P7D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {CF4270F5-2E43-4468-83B3-A8C45BB33EA1}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FR;;;AU)(A;;FA;;;SY)
- URI : \Microsoft\Windows\Chkdsk\SyspartRepair
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA32C0D8E0A
+ Actions
+ Exec
- Command : %windir%\system32\bcdboot.exe
- Arguments : %windir% /sysrepair

+ Task
+ RegistrationInfo
- Date : 2014-01-01T00:00:00
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;GRGX;;;SU)(A;;FA;;;S-1-5-80-65843127-2189646064-2697706863-2125155322-3141006483)(A;;FR;;;S-1-5-87-1452649159-2109950929-2856838567-3638795029-1283063528)
- Source : $(@%SystemRoot%\system32\ClipUp.exe,-102)
- Author : $(@%SystemRoot%\system32\ClipUp.exe,-100)
- Description : $(@%SystemRoot%\system32\ClipUp.exe,-101)
- URI : \Microsoft\Windows\Clip\License Validation
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
- Enabled : false
+ Actions
+ Exec
- Command : %SystemRoot%\system32\ClipUp.exe
- Arguments : -p -s -o

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FRFX;;;IU)
- URI : \Microsoft\Windows\CloudExperienceHost\CreateObjectTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT1H
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ ComHandler
- ClassId : {E4544ABA-62BF-4C54-AAB2-EC246342626C}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICI;GRGX;;;AU)
- Source : $(@%systemRoot%\system32\wsqmcons.exe,-106)
- Author : $(@%systemRoot%\system32\wsqmcons.exe,-108)
- Description : $(@%systemRoot%\system32\wsqmcons.exe,-107)
- URI : \Microsoft\Windows\Customer Experience Improvement Program\Consolidator
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2004-01-02T00:00:00
+ Repetition
- Interval : PT6H
+ Actions
+ Exec
- Command : %SystemRoot%\System32\wsqmcons.exe

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICI;GRGX;;;AU)(A;OICI;SD;;;S-1-5-87-1060603329-121822201-3452730971-4292368946-61207722)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\system32\usbceip.dll,-601)
- Author : $(@%SystemRoot%\system32\usbceip.dll,-600)
- Description : $(@%SystemRoot%\system32\usbceip.dll,-602)
- URI : \Microsoft\Windows\Customer Experience Improvement Program\UsbCeip
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {C27F6B1D-FE0B-45E4-9257-38799FA69BC8}
- Data : SYSTEM

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FR;;;AU)
- Source : $(@%systemroot%\system32\discan.dll,-601)
- Author : $(@%systemroot%\system32\discan.dll,-600)
- Description : $(@%systemroot%\system32\discan.dll,-602)
- URI : \Microsoft\Windows\Data Integrity Scan\Data Integrity Scan
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ CalendarTrigger
- StartBoundary : 2011-01-01T23:00:00
- RandomDelay : P7D
+ ScheduleByWeek
- WeeksInterval : 4
+ DaysOfWeek
+ Saturday
+ BootTrigger
- Enabled : false
- Delay : PT1H
+ Actions
+ ComHandler
- ClassId : {DCFD3EA8-D960-4719-8206-490AE315F94F}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FR;;;AU)
- Source : $(@%systemroot%\system32\discan.dll,-601)
- Author : $(@%systemroot%\system32\discan.dll,-600)
- Description : $(@%systemroot%\system32\discan.dll,-603)
- URI : \Microsoft\Windows\Data Integrity Scan\Data Integrity Scan for Crash Recovery
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- Priority : 5
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- Delay : PT5M
- StateName : 7508BCA32907950A
+ Actions
+ ComHandler
- ClassId : {DCFD3EA8-D960-4719-8206-490AE315F94F}
- Data : -CrashRecovery

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FR;;;AU)
- Source : $(@%systemroot%\system32\defragsvc.dll,-800)
- Author : $(@%systemroot%\system32\defragsvc.dll,-801)
- Description : $(@%systemroot%\system32\defragsvc.dll,-802)
- URI : \Microsoft\Windows\Defrag\ScheduledDefrag
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P1M
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\defrag.exe
- Arguments : -c -h -k -g -$

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;GA;;;BA)(A;;GA;;;SY)(A;;FRFX;;;LS)
- URI : \Microsoft\Windows\Device Information\Device
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : P4D
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2008-09-01T03:00:00
+ Repetition
- Interval : P1D
- RandomDelay : PT2H
+ WnfStateChangeTrigger
- Enabled : false
- StateName : 750CBCA3290B9641
- Data : 01
+ Actions
+ Exec
- Command : %windir%\system32\devicecensus.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FRFX;;;BA)(A;;FA;;;SY)
- Source : $(@%SystemRoot%\System32\DeviceSetupManager.dll,-601)
- Author : $(@%SystemRoot%\System32\DeviceSetupManager.dll,-600)
- Description : $(@%SystemRoot%\System32\DeviceSetupManager.dll,-602)
- URI : \Microsoft\Windows\Device Setup\Metadata Refresh
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Hidden : true
- MultipleInstancesPolicy : Parallel
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P10D
- Deadline : P14D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {23C1F3CF-C110-4512-ACA9-7B6174ECE888}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : O:BAG:BAD:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;BU)(A;;FRFX;;;LS)
- Source : $(@%systemroot%\system32\sdiagschd.dll,-102)
- Author : $(@%systemroot%\system32\sdiagschd.dll,-101)
- Description : $(@%systemroot%\system32\sdiagschd.dll,-103)
- URI : \Microsoft\Windows\Diagnosis\Scheduled
+ Principals
+ Principal
- GroupId : S-1-5-4
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P1M
+ Triggers
+ Actions
+ ComHandler
- ClassId : {C1F85EF8-BCC2-4606-BB39-70C523715EB3}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)
- URI : \Microsoft\Windows\DirectX\DXGIAdapterCache
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- AllowStartOnDemand : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Hidden : true
- MultipleInstancesPolicy : StopExisting
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7580BCA32916C641
+ WnfStateChangeTrigger
- StateName : 7588BCA32916C641
+ Actions
+ Exec
- Command : %windir%\system32\dxgiadaptercache.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;AU)
- Source : $(@%systemroot%\system32\cleanmgr.exe,-1300)
- Author : $(@%systemroot%\system32\cleanmgr.exe,-1300)
- Description : $(@%systemroot%\system32\cleanmgr.exe,-1301)
- URI : \Microsoft\Windows\DiskCleanup\SilentCleanup
+ Principals
+ Principal
- GroupId : S-1-5-32-545
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT15M
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : true
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P1M
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\cleanmgr.exe
- Arguments : /autoclean /d %systemdrive%

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;GA;;;BA)(A;;GA;;;SY)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\System32\DFDTS.dll,-100)
- Author : $(@%SystemRoot%\System32\DFDTS.dll,-101)
- Description : $(@%SystemRoot%\System32\DFDTS.dll,-119)
- URI : \Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- Enabled : false
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P14D
- Deadline : P1M
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\rundll32.exe
- Arguments : dfdts.dll,DfdGetDefaultPolicyAndSMART

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;GA;;;BA)(A;;GA;;;SY)(A;;FR;;;BU)
- Source : $(@%SystemRoot%\System32\DFDTS.dll,-100)
- Author : $(@%SystemRoot%\System32\DFDTS.dll,-101)
- Description : $(@%SystemRoot%\System32\DFDTS.dll,-118)
- URI : \Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver
+ Principals
+ Principal
- GroupId : S-1-5-32-545
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- Hidden : true
- MultipleInstancesPolicy : Parallel
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ Actions
+ Exec
- Command : %windir%\system32\DFDWiz.exe

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\DiskFootprint\Diagnostics
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P7D
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\disksnapshot.exe
- Arguments : -z

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\DiskFootprint\StorageSense
+ Principals
+ Principal
- GroupId : S-1-5-32-545
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P7D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {AB2A519B-03B0-43CE-940A-A73DF850B49A}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FRFX;;;AU)(A;;FA;;;SY)
- URI : \Microsoft\Windows\EDP\EDP App Launch Task
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 3508BCA3280A9641
+ Actions
+ ComHandler
- ClassId : {61BCD1B9-340C-40EC-9D41-D7F1C0632F05}
- Data : AppLaunch

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FRFX;;;AU)(A;;FA;;;SY)
- URI : \Microsoft\Windows\EDP\EDP Auth Task
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7538BCA3280A9641
+ Actions
+ ComHandler
- ClassId : {61BCD1B9-340C-40EC-9D41-D7F1C0632F05}
- Data : ReAuth

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FRFX;;;AU)(A;;FA;;;SY)
- URI : \Microsoft\Windows\EDP\EDP Inaccessible Credentials Task
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7560BCA3280A9641
+ Actions
+ ComHandler
- ClassId : {61BCD1B9-340C-40EC-9D41-D7F1C0632F05}
- Data : MissingCredentials

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FRFX;;;AU)(A;;FA;;;SY)
- URI : \Microsoft\Windows\EDP\StorageCardEncryption Task
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7548BCA32B188341
+ Actions
+ ComHandler
- ClassId : {61BCD1B9-340C-40EC-9D41-D7F1C0632F05}
- Data : SDCardEncryptionPolicy

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;FRFX;;;AU)
- Source : $(@%systemroot%\system32\mitigationconfiguration.dll,-601)
- Author : $(@%systemroot%\system32\mitigationconfiguration.dll,-600)
- Description : $(@%systemroot%\system32\mitigationconfiguration.dll,-602)
- URI : \Microsoft\Windows\ExploitGuard\ExploitGuard MDM policy Refresh
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BEA328009213
+ WnfStateChangeTrigger
- StateName : 7508BCA32A1E890D
+ BootTrigger
+ Actions
+ ComHandler
- ClassId : {711001CD-CC1D-4470-9B7E-1EF73849C79E}
- Data : ExploitGuardPolicy

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(D;;SD;;;AU)(A;;FRFWFX;;;AU)
- Source : $(@%systemroot%\system32\srm.dll,-18000)
- Author : $(@%systemroot%\system32\srm.dll,-18001)
- Description : $(@%systemroot%\system32\srm.dll,-18002)
- URI : \Microsoft\Windows\File Classification Infrastructure\Property Definition Sync
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT5M
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- Duration : PT1M
- WaitTimeout : PT1M
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ CalendarTrigger
- StartBoundary : 2006-11-09T03:00:00
- RandomDelay : PT4H
+ ScheduleByDay
- DaysInterval : 1
+ Actions
+ ComHandler
- ClassId : {2AE64751-B728-4D6B-97A0-B2DA2E7D2A3B}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;FRFX;;;AU)
- Source : $(@%systemroot%\system32\fcon.dll,-602)
- Author : $(@%systemroot%\system32\fcon.dll,-601)
- Description : $(@%systemroot%\system32\fcon.dll,-603)
- URI : \Microsoft\Windows\Flighting\FeatureConfig\ReconcileFeatures
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT5M
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA32A1E890D
+ Actions
+ ComHandler
- ClassId : {59EECBFE-C2F5-4419-9B99-13FE05FF2675}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;FRFX;;;AU)
- Source : $(@%systemroot%\system32\wosc.dll,-602)
- Author : $(@%systemroot%\system32\wosc.dll,-601)
- Description : $(@%systemroot%\system32\wosc.dll,-603)
- URI : \Microsoft\Windows\Flighting\OneSettings\RefreshCache
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT5M
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2026-01-25T04:22:44+05:30
+ Repetition
- Interval : PT23H
- RandomDelay : PT1H
+ Actions
+ ComHandler
- ClassId : {E07647F7-AED2-48D9-9720-939BC24A8A3C}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FRFX;;;BA)
- URI : \Microsoft\Windows\InstallService\ScanForUpdates
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT4H
- MultipleInstancesPolicy : Queue
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2014-01-01T05:30:00+05:30
+ Repetition
- Interval : P1D
- RandomDelay : P1D
+ WnfStateChangeTrigger
- Delay : PT15M
- StateName : 7524BCA33E06830D
+ TimeTrigger
- StartBoundary : 2014-01-01T05:30:00+05:30
- Enabled : false
+ Actions
+ ComHandler
- ClassId : {A558C6A5-B42B-4C98-B610-BF9559143139}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FA;;;BA)(A;;FRFX;;;IU)
- URI : \Microsoft\Windows\InstallService\ScanForUpdatesAsUser
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT4H
- MultipleInstancesPolicy : Queue
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P3D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {DDAFAEA2-8842-4E96-BADE-D44A8D676FDB}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;GRGX;;;SU)
- URI : \Microsoft\Windows\InstallService\SmartRetry
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : Queue
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- DisallowStartOnRemoteAppSession : true
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
- Enabled : false
- Delay : PT6M
+ TimeTrigger
- StartBoundary : 2014-01-01T05:30:00+05:30
- Enabled : false
+ WnfStateChangeTrigger
- Enabled : false
- StateName : 7538BDA33E06830D
+ WnfStateChangeTrigger
- Enabled : false
- StateName : 7518BCA33E06830D
+ WnfStateChangeTrigger
- Enabled : false
- StateName : 7510BCA33E0B8441
- Data : 03
+ TimeTrigger
- StartBoundary : 2014-01-01T05:30:00+05:30
- Enabled : false
+ Actions
+ ComHandler
- ClassId : {F3A219C3-2698-4CBF-9C07-037EDB8E72E6}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FRFX;;;BA)
- URI : \Microsoft\Windows\InstallService\WakeUpAndContinueUpdates
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT4H
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- WakeToRun : true
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ ComHandler
- ClassId : {0DC331EE-8438-49D5-A721-E10B937CE459}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FRFX;;;BA)
- URI : \Microsoft\Windows\InstallService\WakeUpAndScanForUpdates
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT4H
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- WakeToRun : true
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2014-01-01T05:30:00+05:30
+ Repetition
- Interval : P1D
- RandomDelay : P1D
+ Actions
+ ComHandler
- ClassId : {D5A04D91-6FE6-4FE4-A98A-FEB4500C5AF7}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;IU)
- Source : $(@%systemRoot%\System32\LanguageComponentsInstaller.Dll,-601)
- Author : $(@%systemRoot%\System32\LanguageComponentsInstaller.Dll,-600)
- Description : $(@%systemRoot%\System32\LanguageComponentsInstaller.Dll,-602)
- URI : \Microsoft\Windows\LanguageComponentsInstaller\Installation
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
- Delay : PT15M
+ Repetition
- Interval : P1D
+ IdleTrigger
+ Repetition
- Interval : P1D
+ Actions
+ ComHandler
- ClassId : {6F58F65F-EC0E-4ACA-99FE-FC5A1A25E4BE}
- Data : Install $(Arg0)

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)
- Source : $(@%systemRoot%\System32\LanguageComponentsInstaller.Dll,-601)
- Author : $(@%systemRoot%\System32\LanguageComponentsInstaller.Dll,-600)
- Description : $(@%systemRoot%\System32\LanguageComponentsInstaller.Dll,-603)
- URI : \Microsoft\Windows\LanguageComponentsInstaller\Uninstallation
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : Queue
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P14D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {6F58F65F-EC0E-4ACA-99FE-FC5A1A25E4BE}
- Data : Uninstall

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;GRGX;;;SU)
- Source : $(@%SystemRoot%\system32\TempSignedLicenseExchangeTask.dll,-601)
- Author : $(@%SystemRoot%\system32\TempSignedLicenseExchangeTask.dll,-600)
- Description : $(@%SystemRoot%\system32\TempSignedLicenseExchangeTask.dll,-602)
- URI : \Microsoft\Windows\License Manager\TempSignedLicenseExchange
+ Principals
+ Principal
- GroupId : S-1-5-4
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P7D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {77646A68-AD14-4D53-897D-7BE4DDE5F929}

+ Task
+ RegistrationInfo
- Version : 1.3
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;AU)
- Description : $(@%systemRoot%\system32\LocationNotificationWindows.exe,-102)
- URI : \Microsoft\Windows\Location\Notifications
+ Principals
+ Principal
- GroupId : S-1-5-11
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : Parallel
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA321089541
- Data : 01
+ Actions
+ Exec
- Command : %windir%\System32\LocationNotificationWindows.exe

+ Task
+ RegistrationInfo
- Version : 1.3
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;AU)
- Description : $(@%systemRoot%\System32\WindowsActionDialog.exe,-102)
- URI : \Microsoft\Windows\Location\WindowsActionDialog
+ Principals
+ Principal
- GroupId : S-1-5-11
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : Parallel
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7548BCA321089541
+ Actions
+ Exec
- Command : %windir%\System32\WindowsActionDialog.exe

+ Task
+ RegistrationInfo
- Date : 2008-02-25T19:15:00
- SecurityDescriptor : D:(A;;GA;;;BA)(A;;GA;;;SY)(A;;FRFX;;;LS)
- Source : $(@%systemroot%\system32\winsatapi.dll,-113)
- Author : $(@%systemroot%\system32\winsatapi.dll,-112)
- Description : $(@%systemroot%\system32\winsatapi.dll,-114)
- URI : \Microsoft\Windows\Maintenance\WinSAT
+ Principals
+ Principal
- GroupId : S-1-5-32-544
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT30M
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P1M
- Exclusive : true
+ Triggers
+ Actions
+ ComHandler
- ClassId : {A9A33436-678B-4C9C-A211-7CC38785E79D}

+ Task
+ RegistrationInfo
- Date : 2014-11-05T00:00:00
- SecurityDescriptor : D:(A;;0x111FFFFF;;;SY)(A;;0x111FFFFF;;;BA)(A;;0x111FFFFF;;;S-1-5-80-3028837079-3186095147-955107200-3701964851-1150726376)(A;;FRFX;;;AU)
- Author : $(@%SystemRoot%\system32\mapstoasttask.dll,-600)
- Description : $(@%SystemRoot%\system32\mapstoasttask.dll,-602)
- URI : \Microsoft\Windows\Maps\MapsToastTask
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT5S
- Hidden : true
- MultipleInstancesPolicy : Queue
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ ComHandler
- ClassId : {9885AEF2-BD9F-41E0-B15E-B3141395E803}
- Data : $(Arg0);$(Arg1);$(Arg2);$(Arg3);$(Arg4);$(Arg5);$(Arg6);$(Arg7)

+ Task
+ RegistrationInfo
- Date : 2014-11-05T00:00:00
- SecurityDescriptor : D:(A;;0x111FFFFF;;;SY)(A;;0x111FFFFF;;;BA)(A;;0x111FFFFF;;;S-1-5-80-3028837079-3186095147-955107200-3701964851-1150726376)(A;;FRFX;;;NS)(A;;FRFX;;;AU)
- Author : $(@%SystemRoot%\system32\mapsupdatetask.dll,-600)
- Description : $(@%SystemRoot%\system32\mapsupdatetask.dll,-602)
- URI : \Microsoft\Windows\Maps\MapsUpdateTask
+ Principals
+ Principal
- UserId : S-1-5-20
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT40S
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2014-10-21T00:00:00
+ Repetition
- Interval : P1D
- RandomDelay : PT2H
+ Actions
+ ComHandler
- ClassId : {B9033E87-33CF-4D77-BC9B-895AFBBA72E4}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;AU)
- Source : $(@%SystemRoot%\system32\MemoryDiagnostic.dll,-601)
- Author : $(@%SystemRoot%\system32\MemoryDiagnostic.dll,-600)
- Description : $(@%SystemRoot%\system32\MemoryDiagnostic.dll,-603)
- URI : \Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents
+ Principals
+ Principal
- GroupId : S-1-5-32-544
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT2H
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : true
- UseUnifiedSchedulingEngine : true
+ Triggers
+ EventTrigger
- Subscription : <QueryList><Query Id="0" Path="System"><Select Path="System">*[System[Provider[@Name='Microsoft-Windows-WER-SystemErrorReporting'] and (EventID=1000 or EventID=1001 or EventID=1006)]]</Select></Query></QueryList>
+ EventTrigger
- Subscription : <QueryList><Query Id="0" Path="Application"><Select Path="Application">*[System[Provider[@Name='Application Error'] and EventID=1000]]</Select></Query></QueryList>
+ EventTrigger
- Subscription : <QueryList><Query Id="0" Path="System"><Select Path="System">*[System[Provider[@Name='Application Popup'] and EventID=1801]]</Select></Query></QueryList>
+ EventTrigger
- Subscription : <QueryList><Query Id="0" Path="Microsoft-Windows-Kernel-StoreMgr/Operational"><Select Path="Microsoft-Windows-Kernel-StoreMgr/Operational">*[System[Provider[@Name='Microsoft-Windows-Kernel-StoreMgr'] and EventID=6]]</Select></Query></QueryList>
+ Actions
+ ComHandler
- ClassId : {8168E74A-B39F-46D8-ADCD-7BED477B80A3}
- Data : Event

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;AU)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\system32\MemoryDiagnostic.dll,-601)
- Author : $(@%SystemRoot%\system32\MemoryDiagnostic.dll,-600)
- Description : $(@%SystemRoot%\system32\MemoryDiagnostic.dll,-602)
- URI : \Microsoft\Windows\MemoryDiagnostic\RunFullMemoryDiagnostic
+ Principals
+ Principal
- GroupId : S-1-5-32-544
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT2H
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : true
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P2M
+ Triggers
+ Actions
+ ComHandler
- ClassId : {8168E74A-B39F-46D8-ADCD-7BED477B80A3}
- Data : Time

+ Task
+ RegistrationInfo
- Version : 1.3
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;AU)
- Source : $(@%SystemRoot%\system32\MbaeParserTask.exe,-1901)
- Author : $(@%SystemRoot%\system32\MbaeParserTask.exe,-1902)
- Description : $(@%SystemRoot%\system32\MbaeParserTask.exe,-1903)
- URI : \Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT3M
- MultipleInstancesPolicy : Queue
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ EventTrigger
- Subscription : <QueryList>
<Query Id='1'>
<Select Path='Microsoft-Windows-DeviceSetupManager/Operational'>*[System/EventID=302] and *[EventData/Data[@Name='Prop_ServiceInfoNamespace']='http://schemas.microsoft.com/windows/2010/12/DeviceMetadata/MobileBroadBandInfo']</Select>
</Query>
</QueryList>
+ Actions
+ Exec
- Command : %SystemRoot%\System32\MbaeParserTask.exe

+ Task
+ RegistrationInfo
- Source : $(@%systemRoot%\System32\lpremove.exe,-100)
- Author : $(@%systemRoot%\System32\lpremove.exe,-100)
- Description : $(@%systemRoot%\System32\lpremove.exe,-101)
- URI : \Microsoft\Windows\MUI\LPRemove
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT9H
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P3D
- Deadline : P4D
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\lpremove.exe

+ Task
+ RegistrationInfo
- Date : 2005-06-23T13:48:00-08:00
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;AU)
- Source : $(@%systemRoot%\System32\PlaySndSrv.Dll,-106)
- Description : $(@%systemRoot%\System32\PlaySndSrv.Dll,-105)
- URI : \Microsoft\Windows\Multimedia\SystemSoundsService
+ Principals
+ Principal
- GroupId : S-1-5-32-545
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : Parallel
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ Actions
+ ComHandler
- ClassId : {2DEA658F-54C1-4227-AF9B-260AB5FC3543}

+ Task
+ RegistrationInfo
- Source : $(@%SystemRoot%\system32\nettrace.dll,-6910)
- Author : $(@%SystemRoot%\system32\nettrace.dll,-6911)
- Description : $(@%SystemRoot%\system32\nettrace.dll,-6912)
- URI : \Microsoft\Windows\NetTrace\GatherNetworkInfo
+ Principals
+ Principal
- GroupId : S-1-5-32-545
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : Parallel
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\gatherNetworkInfo.vbs
- WorkingDirectory : $(Arg1)

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)
- Source : $(@%SystemRoot%\system32\wbem\SDNDiagnosticsProvider.dll,-500)
- Author : $(@%SystemRoot%\system32\wbem\SDNDiagnosticsProvider.dll,-500)
- Description : $(@%SystemRoot%\system32\wbem\SDNDiagnosticsProvider.dll,-501)
- URI : \Microsoft\Windows\Network Controller\SDN Diagnostics Task
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2015-08-21T00:00:00
+ Repetition
- Interval : PT30M
+ BootTrigger
+ Actions
+ Exec
- Command : %windir%\System32\SDNDiagnosticsTask.exe

+ Task
+ RegistrationInfo
- Version : 1.0
- Source : $(@%systemroot%\system32\cscui.dll,-5000)
- Author : $(@%systemroot%\system32\cscui.dll,-5001)
- Description : $(@%systemroot%\system32\cscui.dll,-5003)
- URI : \Microsoft\Windows\Offline Files\Background Synchronization
+ Principals
+ Principal
- GroupId : S-1-5-11
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : P1D
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2008-01-01T00:00:00
+ Repetition
- Interval : PT2H
- RandomDelay : PT20M
+ Actions
+ ComHandler
- ClassId : {FA3F3DD9-4C1A-456B-A8FA-C76EF3ED83B8}

+ Task
+ RegistrationInfo
- Version : 1.0
- Source : $(@%systemroot%\system32\cscui.dll,-5000)
- Author : $(@%systemroot%\system32\cscui.dll,-5001)
- Description : $(@%systemroot%\system32\cscui.dll,-5002)
- URI : \Microsoft\Windows\Offline Files\Logon Synchronization
+ Principals
+ Principal
- GroupId : S-1-5-11
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : P1D
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
- Delay : PT4M
+ Actions
+ ComHandler
- ClassId : {FA3F3DD9-4C1A-456B-A8FA-C76EF3ED83B8}
- Data : Logon

+ Task
+ RegistrationInfo
- Date : 2012-02-07T16:39:20
- SecurityDescriptor : O:BAG:BAD:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\system32\TpmTasks.dll,-601)
- Author : $(@%SystemRoot%\system32\TpmTasks.dll,-600)
- Description : $(@%SystemRoot%\system32\TpmTasks.dll,-604)
- URI : \Microsoft\Windows\PI\Secure-Boot-Update
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- Delay : PT2M
- StateName : 7508BCA33E0C9541
+ Actions
+ ComHandler
- ClassId : {5014B7C8-934E-4262-9816-887FA745A6C4}
- Data : SBServicing

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;AU)(A;;FRFX;;;LS)
- URI : \Microsoft\Windows\PI\SecureBootEncodeUEFI
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT10S
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ RegistrationTrigger
+ BootTrigger
- EndBoundary : 2025-12-31T12:00:00
- Delay : PT5M
+ CalendarTrigger
- StartBoundary : 2025-12-31T12:00:00
+ ScheduleByMonth
+ Months
+ January
+ February
+ March
+ April
+ May
+ June
+ July
+ August
+ September
+ October
+ November
+ December
- DaysOfMonth
- Day : 1 : 15
+ Actions
+ Exec
- Command : %WINDIR%\system32\SecureBootEncodeUEFI.exe

+ Task
+ RegistrationInfo
- Date : 2011-07-22T00:00:00.8844064
- SecurityDescriptor : O:BAG:BAD:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\system32\TpmTasks.dll,-601)
- Author : $(@%SystemRoot%\system32\TpmTasks.dll,-600)
- Description : $(@%SystemRoot%\system32\TpmTasks.dll,-603)
- URI : \Microsoft\Windows\PI\Sqm-Tasks
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1M
+ Triggers
+ Actions
+ ComHandler
- ClassId : {5014B7C8-934E-4262-9816-887FA745A6C4}
- Data : PiSqmTasks

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FA;;;BA)(A;;0x1301ff;;;S-1-5-80-2661322625-712705077-2999183737-3043590567-590698655)(A;;FRFX;;;LU)
- Source : $(@%systemroot%\system32\wbem\mgmtprovider.dll,-101)
- Author : $(@%systemroot%\system32\wbem\mgmtprovider.dll,-8197)
- URI : \Microsoft\Windows\PLA\Server Manager Performance Monitor
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- Priority : 2
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Data
+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)
- Author : $(@%SystemRoot%\system32\pnppolicy.dll,-600)
- Description : $(@%SystemRoot%\system32\pnppolicy.dll,-602)
- URI : \Microsoft\Windows\Plug and Play\Device Install Group Policy
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : P1D
- Hidden : true
- MultipleInstancesPolicy : Queue
- Priority : 6
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA32A1E890D
+ Actions
+ ComHandler
- ClassId : {60400283-B242-4FA8-8C25-CAF695B88209}

+ Task
+ RegistrationInfo
- SecurityDescriptor : O:BAG:BAD:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;;FR;;;IU)
- Author : $(@%SystemRoot%\system32\pnpui.dll,-600)
- Description : $(@%SystemRoot%\system32\pnpui.dll,-602)
- URI : \Microsoft\Windows\Plug and Play\Device Install Reboot Required
+ Principals
+ Principal
- GroupId : S-1-5-4
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- AllowStartOnDemand : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Hidden : true
- MultipleInstancesPolicy : Queue
- Priority : 6
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA33D009602
+ LogonTrigger
+ Actions
+ ComHandler
- ClassId : {48794782-6A1F-47B9-BD52-1D5F95D49C1B}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)
- Author : $(@%SystemRoot%\System32\sppnp.dll,-2000)
- Description : $(@%SystemRoot%\System32\sppnp.dll,-2001)
- URI : \Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ Exec
- Command : %SystemRoot%\System32\drvinst.exe
- Arguments : 6

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICI;GR;;;AU)(A;;FRFX;;;LS)
- Source : $(@%systemRoot%\system32\energytask.dll,-601)
- Author : $(@%systemRoot%\system32\energytask.dll,-600)
- Description : $(@%systemRoot%\system32\energytask.dll,-602)
- URI : \Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT5M
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P2D
- Exclusive : true
+ Triggers
+ Actions
+ ComHandler
- ClassId : {927EA2AF-1C54-43D5-825E-0074CE028EEE}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;GRGX;;;SU)
- URI : \Microsoft\Windows\PushToInstall\LoginCheck
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : Parallel
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- DisallowStartOnRemoteAppSession : true
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
- StartBoundary : 2017-01-01T05:30:00+05:30
- EndBoundary : 2017-01-01T05:30:00+05:30
- Delay : PT5M
+ Actions
+ Exec
- Command : %windir%\system32\sc.exe
- Arguments : start pushtoinstall login

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;GRGX;;;SU)
- URI : \Microsoft\Windows\PushToInstall\Registration
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- DisallowStartOnRemoteAppSession : true
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2017-01-01T05:30:00+05:30
+ Repetition
- Interval : P20D
+ WnfStateChangeTrigger
- Delay : PT15M
- StateName : 750CBCA3290B9641
- Data : 01
+ Actions
+ Exec
- Command : %windir%\system32\sc.exe
- Arguments : start pushtoinstall registration

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;LS)
- Author : $(@%SystemRoot%\system32\rasmbmgr.dll,-201)
- Description : $(@%SystemRoot%\system32\rasmbmgr.dll,-202)
- URI : \Microsoft\Windows\Ras\MobilityManager
+ Principals
+ Principal
- UserId : S-1-5-19
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : Parallel
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ EventTrigger
- Subscription : <QueryList>







<Query







Id="0"







Path="Application"







>







<Select Path="Application">*[System[Provider[@Name='RasClient'] and (Level=4 or Level=0) and (EventID=20281)]]</Select>







</Query>







</QueryList>
+ Actions
+ ComHandler
- ClassId : {C463A0FC-794F-4FDF-9201-01938CEACAFA}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;AU)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\system32\ReAgentTask.dll,-602)
- Author : $(@%SystemRoot%\system32\ReAgentTask.dll,-601)
- Description : $(@%SystemRoot%\system32\ReAgentTask.dll,-603)
- URI : \Microsoft\Windows\RecoveryEnvironment\VerifyWinRE
+ Principals
+ Principal
- GroupId : S-1-5-32-544
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT1H
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P14D
- Deadline : P1M
+ Triggers
+ Actions
+ ComHandler
- ClassId : {89D1D0C2-A3CF-490C-ABE3-B86CDE34B047}
- Data : VerifyWinRE

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : O:BAG:BAD:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;IU)(A;;FRFX;;;S-1-5-80-2970612574-78537857-698502321-558674196-1451644582)(A;;FRFX;;;LS)
- Source : $(@%systemroot%\system32\regidle.dll,-601)
- Author : $(@%systemroot%\system32\regidle.dll,-600)
- Description : $(@%systemroot%\system32\regidle.dll,-602)
- URI : \Microsoft\Windows\Registry\RegIdleBackup
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- Priority : 5
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P10D
- Deadline : P14D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {CA767AA8-9157-4604-B64B-40747123D5F2}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : O:SYD:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;AU)(A;;FRFX;;;LU)
- Source : $(@%systemroot%\system32\wbem\mgmtprovider.dll,-101)
- Author : $(@%systemroot%\system32\wbem\mgmtprovider.dll,-8197)
- URI : \Microsoft\Windows\Server Manager\CleanupOldPerfLogs
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT2M
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ Exec
- Command : %systemroot%\system32\cscript.exe
- Arguments : /B /nologo %systemroot%\system32\calluxxprovider.vbs $(Arg0) $(Arg1) $(Arg2)

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;BU)
- Source : $(@%SystemRoot%\system32\svrmgrnc.dll,-101)
- Author : $(@%SystemRoot%\system32\svrmgrnc.dll,-103)
- Description : $(@%SystemRoot%\system32\svrmgrnc.dll,-104)
- URI : \Microsoft\Windows\Server Manager\ServerManager
+ Principals
+ Principal
- GroupId : S-1-5-32-544
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : IgnoreNew
- Priority : 4
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ Actions
+ Exec
- Command : %windir%\system32\ServerManagerLauncher.exe

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\Servicing\StartComponentCleanup
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P14D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {752073A1-23F2-4396-85F0-8FDB879ED0ED}

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\SharedPC\Account Cleanup
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT30M
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- WakeToRun : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
+ Triggers
+ Actions
+ Exec
- Command : %windir%\System32\rundll32.exe
- Arguments : %windir%\System32\Windows.SharedPC.AccountManager.dll,StartMaintenance

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FRFX;;;IU)
- Source : $(@%SystemRoot%\system32\shell32.dll,-14349)
- Author : $(@%SystemRoot%\system32\shell32.dll,-14349)
- Description : $(@%SystemRoot%\system32\shell32.dll,-14350)
- URI : \Microsoft\Windows\Shell\CreateObjectTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT30S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ ComHandler
- ClassId : {990A9F8F-301F-45F7-8D0E-68C5952DBA43}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FA;;;LS)(A;;FR;;;BA)
- Source : $(@%systemroot%\system32\srchadmin.dll,-1901)
- Author : $(@%systemroot%\system32\srchadmin.dll,-1901)
- Description : $(@%systemroot%\system32\srchadmin.dll,-1902)
- URI : \Microsoft\Windows\Shell\IndexerAutomaticMaintenance
+ Principals
+ Principal
- UserId : S-1-5-19
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P2D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {3FBA60A6-7BF5-4868-A2CA-6623B3DFFEA6}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;BU)
- URI : \Microsoft\Windows\Software Inventory Logging\Collection
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowStartOnDemand : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT10M
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2000-01-01T03:00:00
+ Repetition
- Interval : PT1H
- RandomDelay : PT30M
+ Actions
+ Exec
- Command : %systemroot%\system32\cmd.exe
- Arguments : /d /c %systemroot%\system32\silcollector.cmd publish

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;BU)
- URI : \Microsoft\Windows\Software Inventory Logging\Configuration
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- AllowStartOnDemand : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT2M
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
- Delay : PT1M
+ Actions
+ Exec
- Command : %systemroot%\system32\cmd.exe
- Arguments : /d /c %systemroot%\system32\silcollector.cmd configure

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;FA;;;S-1-5-80-123231216-2592883651-3715271367-3753151631-4175906628)(A;;FR;;;S-1-5-87-2912274048-3994893941-1669128114-1310430903-1263774323)
- Source : $(@%systemroot%\system32\sppc.dll,-200)
- Author : $(@%systemroot%\system32\sppc.dll,-200)
- Description : $(@%systemroot%\system32\sppc.dll,-201)
- URI : \Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask
+ Principals
+ Principal
- UserId : S-1-5-20
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ RestartOnFailure
- Count : 3
- Interval : PT1M
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ CalendarTrigger
- StartBoundary : 2026-01-24T13:22:57+05:30
+ ScheduleByDay
- DaysInterval : 1
+ Actions
+ ComHandler
- ClassId : {B1AEBB5D-EAD9-4476-B375-9C3ED9F32AFC}
- Data : timer

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;FRFW;;;S-1-5-80-123231216-2592883651-3715271367-3753151631-4175906628)(A;;FR;;;S-1-5-4)
- Source : $(@%systemroot%\system32\sppc.dll,-200)
- Author : $(@%systemroot%\system32\sppc.dll,-200)
- Description : $(@%systemroot%\system32\sppc.dll,-202)
- URI : \Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskLogon
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ RestartOnFailure
- Count : 3
- Interval : PT1M
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ Actions
+ ComHandler
- ClassId : {B1AEBB5D-EAD9-4476-B375-9C3ED9F32AFC}
- Data : logon

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;FRFW;;;S-1-5-80-123231216-2592883651-3715271367-3753151631-4175906628)(A;;FR;;;S-1-5-87-431836887-2321537645-4075769387-3393595759-2187231311)
- Source : $(@%systemroot%\system32\sppc.dll,-200)
- Author : $(@%systemroot%\system32\sppc.dll,-200)
- Description : $(@%systemroot%\system32\sppc.dll,-203)
- URI : \Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskNetwork
+ Principals
+ Principal
- UserId : S-1-5-20
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ RestartOnFailure
- Count : 3
- Interval : PT1M
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ EventTrigger
- Subscription : <QueryList><Query Id="0" Path="Microsoft-Windows-NetworkProfile/Operational"><Select Path="Microsoft-Windows-NetworkProfile/Operational">*[System[EventID=10000]]</Select></Query></QueryList>
+ Actions
+ ComHandler
- ClassId : {B1AEBB5D-EAD9-4476-B375-9C3ED9F32AFC}
- Data : network

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)
- Source : $(@%SystemRoot%\system32\SpaceAgent.exe,-1)
- Author : $(@%SystemRoot%\system32\SpaceAgent.exe,-2)
- Description : $(@%SystemRoot%\system32\SpaceAgent.exe,-3)
- URI : \Microsoft\Windows\SpacePort\SpaceAgentTask
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT6H
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
- Enabled : false
- Delay : PT2M
+ WnfStateChangeTrigger
- StateName : 7508BCA33E1E8702
+ Actions
+ Exec
- Command : %windir%\system32\SpaceAgent.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)
- Source : $(@%SystemRoot%\system32\spaceman.exe,-1)
- Author : $(@%SystemRoot%\system32\spaceman.exe,-2)
- Description : $(@%SystemRoot%\system32\spaceman.exe,-3)
- URI : \Microsoft\Windows\SpacePort\SpaceManagerTask
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
- Enabled : false
- Delay : PT2M
+ WnfStateChangeTrigger
- StateName : 7510BCA33E1E8702
+ Actions
+ Exec
- Command : %windir%\system32\spaceman.exe
- Arguments : /Work

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:AI(A;;FA;;;BA)(A;;FA;;;SY)(A;;FA;;;AU)
- URI : \Microsoft\Windows\Speech\HeadsetButtonPress
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7510BCA33E1E8509
+ Actions
+ Exec
- Command : %windir%\system32\speech_onecore\common\SpeechRuntime.exe
- Arguments : StartedFromTask

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;GA;;;NU)
- URI : \Microsoft\Windows\Speech\SpeechModelDownloadTask
+ Principals
+ Principal
- UserId : S-1-5-20
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT10M
- MultipleInstancesPolicy : IgnoreNew
+ RestartOnFailure
- Count : 3
- Interval : PT1M
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- Duration : PT10M
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2004-01-01T00:00:00
+ Repetition
- Interval : P1D
- RandomDelay : PT4H
+ Actions
+ Exec
- Command : %windir%\system32\speech_onecore\common\SpeechModelDownload.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FR;;;AU)
- Source : $(@%systemroot%\system32\TieringEngineService.exe,-601)
- Author : $(@%systemroot%\system32\TieringEngineService.exe,-600)
- Description : $(@%systemroot%\system32\TieringEngineService.exe,-602)
- URI : \Microsoft\Windows\Storage Tiers Management\Storage Tiers Management Initialization
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA32B1D940D
+ Actions
+ ComHandler
- ClassId : {5C9AB547-345D-4175-9AF6-65133463A100}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FR;;;AU)
- Source : $(@%systemroot%\system32\TieringEngineService.exe,-601)
- Author : $(@%systemroot%\system32\TieringEngineService.exe,-600)
- Description : $(@%systemroot%\system32\TieringEngineService.exe,-603)
- URI : \Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2013-01-01T01:00:00
+ Repetition
- Interval : PT4H
+ Actions
+ Exec
- Command : %windir%\system32\defrag.exe
- Arguments : -c -h -g -# -m 8 -i 13500

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : O:BAG:BAD:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;IU)
- Source : $(@%systemroot%\system32\wdc.dll,-10042)
- Author : $(@%systemroot%\system32\wdc.dll,-10041)
- Description : $(@%systemroot%\system32\wdc.dll,-10043)
- URI : \Microsoft\Windows\Task Manager\Interactive
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : Parallel
- Priority : 5
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ ComHandler
- ClassId : {855FEC53-D2E4-4999-9E87-3414E9CF0FF4}
- Data : $(Arg0)

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;BU)
- Source : $(@%systemRoot%\system32\MsCtfMonitor.dll,-1000)
- Description : $(@%systemRoot%\system32\MsCtfMonitor.dll,-1001)
- URI : \Microsoft\Windows\TextServicesFramework\MsCtfMonitor
+ Principals
+ Principal
- GroupId : S-1-5-32-545
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : Parallel
- Priority : 5
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ Actions
+ ComHandler
- ClassId : {01575CFE-9A55-4003-A5E1-F38D1EBDCBE1}

+ Task
+ RegistrationInfo
- Source : $(@%SystemRoot%\system32\TimeSyncTask.dll,-601)
- Author : $(@%SystemRoot%\system32\TimeSyncTask.dll,-600)
- Description : $(@%SystemRoot%\system32\TimeSyncTask.dll,-602)
- URI : \Microsoft\Windows\Time Synchronization\ForceSynchronizeTime
+ Principals
+ Principal
- UserId : S-1-5-19
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- Delay : PT1M
- StateName : 7510BCA32F018915
+ Actions
+ ComHandler
- ClassId : {A31AD6C2-FF4C-43D4-8E90-7101023096F9}
- Data : TimeSyncTask

+ Task
+ RegistrationInfo
- Source : $(@%systemroot%\system32\w32time.dll,-200)
- Author : $(@%systemroot%\system32\w32time.dll,-202)
- Description : $(@%systemroot%\system32\w32time.dll,-201)
- URI : \Microsoft\Windows\Time Synchronization\SynchronizeTime
+ Principals
+ Principal
- UserId : S-1-5-19
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P2D
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\sc.exe
- Arguments : start w32time task_started

+ Task
+ RegistrationInfo
- Date : 2013-01-10T16:32:04.2837388
- Author : $(@%SystemRoot%\system32\tzsyncres.dll,-101)
- Description : $(@%SystemRoot%\system32\tzsyncres.dll,-102)
- URI : \Microsoft\Windows\Time Zone\SynchronizeTimeZone
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P14D
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\tzsync.exe

+ Task
+ RegistrationInfo
- Date : 2015-02-16T17:49:20.8844064
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)
- Source : $(@%SystemRoot%\system32\TpmTasks.dll,-601)
- Author : $(@%SystemRoot%\system32\TpmTasks.dll,-600)
- Description : $(@%SystemRoot%\system32\TpmTasks.dll,-605)
- URI : \Microsoft\Windows\TPM\Tpm-HASCertRetr
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : Queue
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA3250F9541
+ Actions
+ ComHandler
- ClassId : {5014B7C8-934E-4262-9816-887FA745A6C4}
- Data : HASCertRetr

+ Task
+ RegistrationInfo
- Date : 2010-06-10T17:49:20.8844064
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FA;;;S-1-5-87-1469317444-2401623638-2778953283-1691679301-3481717153)
- Source : $(@%SystemRoot%\system32\TpmTasks.dll,-601)
- Author : $(@%SystemRoot%\system32\TpmTasks.dll,-600)
- Description : $(@%SystemRoot%\system32\TpmTasks.dll,-602)
- URI : \Microsoft\Windows\TPM\Tpm-Maintenance
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : Queue
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7518BCA3391E8B41
+ WnfStateChangeTrigger
- StateName : 7560BCA322028F02
+ WnfStateChangeTrigger
- StateName : 7510BCA3391E8B41
+ WnfStateChangeTrigger
- StateName : 3528BCA32E1D8E0D
+ Actions
+ ComHandler
- ClassId : {5014B7C8-934E-4262-9816-887FA745A6C4}
- Data : TpmTasks

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\UpdateOrchestrator\AC Power Download
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- WakeToRun : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA3380C960C
- Data : 01000000
+ Actions
+ Exec
- Command : %systemroot%\system32\usoclient.exe
- Arguments : StartDownload

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\UpdateOrchestrator\Backup Scan
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- WakeToRun : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ TimeTrigger
- StartBoundary : 2026-02-07T11:38:30+05:30
+ Actions
+ Exec
- Command : %systemroot%\system32\usoclient.exe
- Arguments : StartScan

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\UpdateOrchestrator\Maintenance Install
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P2D
+ Triggers
+ Actions
+ Exec
- Command : %systemroot%\system32\usoclient.exe
- Arguments : StartInstall

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ TimeTrigger
- StartBoundary : 2026-01-25T07:40:14+05:30
+ Actions
+ Exec
- Command : %systemroot%\system32\MusNotification.exe
- Arguments : Display

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\UpdateOrchestrator\Reboot
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- Enabled : false
- MultipleInstancesPolicy : IgnoreNew
+ RestartOnFailure
- Count : 3
- Interval : PT10M
- StartWhenAvailable : true
- WakeToRun : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ TimeTrigger
- StartBoundary : 2025-04-02T17:43:00+05:30
+ Actions
+ Exec
- Command : %systemroot%\system32\MusNotification.exe
- Arguments : Reboot

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\UpdateOrchestrator\Schedule Scan
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2024-06-27T11:03:43+05:30
+ Repetition
- Interval : PT22H
- RandomDelay : PT4H
+ Actions
+ Exec
- Command : %systemroot%\system32\usoclient.exe
- Arguments : StartScan

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FRFX;;;BA)
- Source : $(@%systemRoot%\system32\usocore.dll,-104)
- Author : $(@%systemRoot%\system32\usocore.dll,-103)
- Description : $(@%systemRoot%\system32\usocore.dll,-105)
- URI : \Microsoft\Windows\UpdateOrchestrator\Schedule Scan Static Task
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- Delay : PT2H5M
- StateName : 7524BCA33E06830D
- Data : 01
+ WnfStateChangeTrigger
- Delay : PT2H5M
- StateName : 750CBCA3290B9641
- Data : 01
+ WnfStateChangeTrigger
- StateName : 7550BCA322028F02
+ WnfStateChangeTrigger
- StateName : 7508BCA32E07C641
+ EventTrigger
- Subscription : <QueryList><Query Id="0" Path="System"><Select Path="System">*[System[EventID=8202]]</Select></Query></QueryList>
+ Actions
+ Exec
- Command : %systemroot%\system32\usoclient.exe
- Arguments : StartScan

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FRFX;;;BA)
- Source : $(@%systemRoot%\system32\usocore.dll,-104)
- Author : $(@%systemRoot%\system32\usocore.dll,-103)
- Description : $(@%systemRoot%\system32\usocore.dll,-106)
- URI : \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowStartOnDemand : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : Queue
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7510BCA3381D8941
+ CalendarTrigger
- StartBoundary : 2000-01-01T03:00:00
- RandomDelay : P1D
+ ScheduleByDay
- DaysInterval : 1
+ Actions
+ Exec
- Command : %systemroot%\system32\MusNotification.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)
- Author : $(@%systemroot%\system32\upnphost.dll,-215)
- Description : $(@%systemroot%\system32\upnphost.dll,-216)
- URI : \Microsoft\Windows\UPnP\UPnPHostConfig
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ Exec
- Command : sc.exe
- Arguments : config upnphost start= auto

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)
- Source : $(@%SystemRoot%\system32\profsvc,-500)
- Author : $(@%SystemRoot%\system32\profsvc,-500)
- Description : $(@%SystemRoot%\system32\profsvc,-501)
- URI : \Microsoft\Windows\User Profile Service\HiveUploadTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- Enabled : false
- MultipleInstancesPolicy : IgnoreNew
+ RestartOnFailure
- Count : 3
- Interval : PT2M
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT2H
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2007-08-28T00:00:00
+ Repetition
- Interval : PT12H
- RandomDelay : PT1H
+ Actions
+ ComHandler
- ClassId : {BA677074-762C-444B-94C8-8C83F93F6605}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FRFX;;;BA)
- Source : $(@%systemroot%\system32\WaasMedicSvc.dll,-103)
- Author : $(@%systemroot%\system32\WaasMedicSvc.dll,-102)
- Description : $(@%systemroot%\system32\WaasMedicSvc.dll,-104)
- URI : \Microsoft\Windows\WaaSMedic\PerformRemediation
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2000-10-15T03:00:00
+ Repetition
- Interval : P7D
- RandomDelay : PT4H
+ Actions
+ ComHandler
- ClassId : {72566E27-1ABB-4EB3-B4F0-EB431CB1CB32}
- Data : None

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : O:BAG:BAD:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;IU)(A;;FRFX;;;S-1-5-80-2970612574-78537857-698502321-558674196-1451644582)
- Source : $(@%systemroot%\system32\dps.dll,-601)
- Author : $(@%systemroot%\system32\dps.dll,-600)
- Description : $(@%systemroot%\system32\dps.dll,-602)
- URI : \Microsoft\Windows\WDI\ResolutionHost
+ Principals
+ Principal
- GroupId : S-1-5-4
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : Parallel
- Priority : 10
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ ComHandler
- ClassId : {900BE39D-6BE8-461A-BC4D-B0FA71F5ECB1}

+ Task
+ RegistrationInfo
- Version : 1.5
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;WD)
- Source : $(@%SystemRoot%\system32\wer.dll,-292)
- Author : $(@%SystemRoot%\system32\wer.dll,-293)
- Description : $(@%SystemRoot%\system32\wer.dll,-294)
- URI : \Microsoft\Windows\Windows Error Reporting\QueueReporting
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT4H
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
- Delay : PT3M
+ WnfStateChangeTrigger
- StateName : 7510BCA33A0B9441
- Data : 01
+ WnfStateChangeTrigger
- StateName : 7510BCA33E0B8441
- Data : 03
+ TimeTrigger
- StartBoundary : 2025-09-15T17:18:31+05:30
- Enabled : false
+ Repetition
- Interval : PT30M
- RandomDelay : PT30M
+ Actions
+ Exec
- Command : %windir%\system32\wermgr.exe
- Arguments : -upload

+ Task
+ RegistrationInfo
- Author : $(@%SystemRoot%\system32\bfe.dll,-2001)
- Description : $(@%SystemRoot%\system32\bfe.dll,-2002)
- URI : \Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowHardTerminate : false
- AllowStartOnDemand : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Hidden : true
- MultipleInstancesPolicy : Queue
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ EventTrigger
- Subscription : <QueryList><Query Id="0" Path="System"><Select Path="System">*/System/Provider[@Name='Service Control Manager'] and */System/EventID='7040' and */EventData/Data[@Name='param4']='BFE'</Select></Query></QueryList>
+ Actions
+ Exec
- Command : %windir%\system32\rundll32.exe
- Arguments : bfe.dll,BfeOnServiceStartTypeChange

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;AU)
- Author : $(@%ProgramFiles%\Windows Media Player\wmpnscfg.exe,-1001)
- Description : $(@%ProgramFiles%\Windows Media Player\wmpnscfg.exe,-1002)
- URI : \Microsoft\Windows\Windows Media Sharing\UpdateLibrary
+ Principals
+ Principal
- GroupId : S-1-5-11
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : Parallel
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ EventTrigger
- Subscription : <QueryList>
<Query
Id="0"
Path="System"
>
<Select Path="System">*[System[Provider[@Name='Microsoft-Windows-WMPNSS-Service'] and (EventID=14210)]]</Select>
</Query>
</QueryList>
+ Actions
+ Exec
- Command : "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FWFR;;;BU)
- Source : $(@%SystemRoot%\system32\mscms.dll,-200)
- Author : $(@%SystemRoot%\system32\mscms.dll,-201)
- Description : $(@%SystemRoot%\system32\mscms.dll,-202)
- URI : \Microsoft\Windows\WindowsColorSystem\Calibration Loader
+ Principals
+ Principal
- GroupId : S-1-5-32-545
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : Queue
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ SessionStateChangeTrigger
- StateChange : ConsoleConnect
+ Actions
+ ComHandler
- ClassId : {B210D694-C8DF-490D-9576-9E20CDBC20BD}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FA;;;BA)
- Source : Microsoft Corporation.
- Author : Microsoft Corporation.
- Description : This task is used to start the Windows Update service when needed to perform scheduled operations such as scans.
- URI : \Microsoft\Windows\WindowsUpdate\Scheduled Start
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowStartOnDemand : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2026-01-25T12:22:48+05:30
- RandomDelay : PT1M
+ SessionStateChangeTrigger
- Enabled : false
- StateChange : ConsoleDisconnect
+ SessionStateChangeTrigger
- Enabled : false
- StateChange : RemoteDisconnect
+ WnfStateChangeTrigger
- Enabled : false
- StateName : 7508BCA3380C960C
- Data : 01
+ Actions
+ Exec
- Command : C:\Windows\system32\sc.exe
- Arguments : start wuauserv

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;0x001200a9;;;BU)(A;;0x001200a9;;;WD)(A;;0x001200a9;;;LW)
- Author : $(@%systemroot%\system32\wininet.dll,-16000)
- Description : $(@%systemroot%\system32\wininet.dll,-16001)
- URI : \Microsoft\Windows\Wininet\CacheTask
+ Principals
+ Principal
- GroupId : S-1-5-32-545
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : Parallel
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ Actions
+ ComHandler
- ClassId : {0358B920-0AC7-461F-98F4-58E32CD89148}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;NS)(A;;GA;;;SY)(A;ID;FA;;;BA)(A;ID;GRGX;;;AU)
- Description : $(@%SystemRoot%\system32\dsregcmd.exe,-101)
- URI : \Microsoft\Windows\Workplace Join\Automatic-Device-Join
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT5M
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
- Delay : PT1M
+ EventTrigger
+ Repetition
- Interval : PT1H
- Duration : P1D
- Subscription : <QueryList><Query Id="0" Path="Microsoft-Windows-User Device Registration/Admin"><Select Path="Microsoft-Windows-User Device Registration/Admin">*[System[Provider[@Name='Microsoft-Windows-User Device Registration'] and EventID=4096]]</Select></Query></QueryList>
+ Actions
+ Exec
- Command : %SystemRoot%\System32\dsregcmd.exe
- Arguments : $(Arg0) $(Arg1) $(Arg2)

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;NS)(A;;GA;;;SY)(A;ID;FA;;;BA)(A;ID;GRGX;;;AU)
- Description : $(@%SystemRoot%\system32\dsregcmd.exe,-102)
- URI : \Microsoft\Windows\Workplace Join\Recovery-Check
+ Principals
+ Principal
- GroupId : S-1-5-4
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT2H
- MultipleInstancesPolicy : Queue
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ Actions
+ Exec
- Command : %SystemRoot%\System32\dsregcmd.exe
- Arguments : /checkrecovery
70626 - Microsoft Windows AutoRuns Services and Drivers
-
Synopsis
Report programs that are set to start automatically on boot as a service or driver.
Description
Report the registry keys that track programs that are set to start on boot as a service.

These programs can start as a system wide service or be loaded as a driver.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\System\CurrentControlSet\Services
Drivers :
+ @%SystemRoot%\system32\AJRouter.dll,-2
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\AJRouter.dll,-1

+ @%SystemRoot%\system32\Alg.exe,-112
- %SystemRoot%\System32\alg.exe
- Load on Demand
- @%SystemRoot%\system32\Alg.exe,-113

+ @%windir%\system32\inetsrv\iisres.dll,-30011
- %windir%\system32\svchost.exe -k apphost
- Auto Load
- @%windir%\system32\inetsrv\iisres.dll,-30012

+ @%systemroot%\system32\appidsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\appidsvc.dll,-101

+ @%systemroot%\system32\appinfo.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\appinfo.dll,-101

+ @appmgmts.dll,-3250
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @appmgmts.dll,-3251

+ @%SystemRoot%\System32\AppReadiness.dll,-1000
- %SystemRoot%\System32\svchost.exe -k AppReadiness -p
- Load on Demand
- @%SystemRoot%\System32\AppReadiness.dll,-1001

+ @%systemroot%\system32\AppVClient.exe,-102
- %systemroot%\system32\AppVClient.exe
- disabled
- @%systemroot%\system32\AppVClient.exe,-101

+ @%SystemRoot%\system32\appxdeploymentserver.dll,-1
- %systemroot%\system32\svchost.exe -k wsappx -p
- Load on Demand
- @%SystemRoot%\system32\appxdeploymentserver.dll,-2

+ @%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1
- %systemroot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
- Load on Demand
- @%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-2

+ @%SystemRoot%\system32\AudioEndpointBuilder.dll,-204
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\AudioEndpointBuilder.dll,-205

+ @%SystemRoot%\system32\audiosrv.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\audiosrv.dll,-201

+ Kaspersky Endpoint Security Service (KES.21.15)
- "C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avp.exe" -r
- Auto Load
- Provides computer protection against viruses, other malicious applications, and network attacks.

+ Kaspersky Seamless Update Service (KES.21.15)
- "C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avpsus.exe"
- Auto Load
- Lets you install and roll back critical and approved updates of application modules.

+ @%SystemRoot%\system32\AxInstSV.dll,-103
- %SystemRoot%\system32\svchost.exe -k AxInstSVGroup
- disabled
- @%SystemRoot%\system32\AxInstSV.dll,-104

+ @%SystemRoot%\system32\bfe.dll,-1001
- %systemroot%\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p
- Auto Load
- @%SystemRoot%\system32\bfe.dll,-1002

+ @%SystemRoot%\system32\qmgr.dll,-1000
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\qmgr.dll,-1001

+ @%windir%\system32\bisrv.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @%windir%\system32\bisrv.dll,-101

+ @%SystemRoot%\system32\BTAGService.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\BTAGService.dll,-102

+ @%SystemRoot%\system32\BthAvctpSvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\BthAvctpSvc.dll,-102

+ @%SystemRoot%\System32\bthserv.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\System32\bthserv.dll,-102

+ CallBalanceClopsVoiceLogService_LKP
- "D:\Nexsus\Nexsus_Patch\Nexsus.MaxDial.VoiceLogService_Web_LKP\Nexsus.CallBalancel.VoiceLogService.exe"
- Auto Load
- MaxDialLogService punch data into database.

+ @%SystemRoot%\system32\CapabilityAccessManager.dll,-1
- %SystemRoot%\system32\svchost.exe -k appmodel -p
- Load on Demand
- @%SystemRoot%\system32\CapabilityAccessManager.dll,-2

+ @%SystemRoot%\system32\cdpsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @%SystemRoot%\system32\cdpsvc.dll,-101

+ @%SystemRoot%\System32\certprop.dll,-11
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\certprop.dll,-12

+ @%SystemRoot%\system32\ClipSVC.dll,-103
- %SystemRoot%\System32\svchost.exe -k wsappx -p
- Load on Demand
- @%SystemRoot%\system32\ClipSVC.dll,-104

+ @comres.dll,-947
- %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
- Load on Demand
- @comres.dll,-948

+ @%SystemRoot%\system32\coremessaging.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork -p
- Auto Load
- @%SystemRoot%\system32\coremessaging.dll,-2

+ @%SystemRoot%\system32\cryptsvc.dll,-1001
- %SystemRoot%\system32\svchost.exe -k NetworkService -p
- Auto Load
- @%SystemRoot%\system32\cryptsvc.dll,-1002

+ @%systemroot%\system32\cscsvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- disabled
- @%systemroot%\system32\cscsvc.dll,-201

+ @combase.dll,-5012
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @combase.dll,-5013

+ @%SystemRoot%\system32\defragsvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k defragsvc
- Load on Demand
- @%SystemRoot%\system32\defragsvc.dll,-102

+ @%SystemRoot%\system32\das.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\das.dll,-101

+ @%SystemRoot%\system32\umpnpmgr.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Load on Demand
- @%SystemRoot%\system32\umpnpmgr.dll,-101

+ @%SystemRoot%\system32\DevQueryBroker.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\DevQueryBroker.dll,-101

+ @%SystemRoot%\system32\dhcpcore.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\dhcpcore.dll,-101

+ @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000
- %SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe
- Load on Demand
- @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1001

+ @%SystemRoot%\system32\diagtrack.dll,-3001
- %SystemRoot%\System32\svchost.exe -k utcsvc -p
- Auto Load
- @%SystemRoot%\system32\diagtrack.dll,-3002

+ @%systemroot%\system32\Windows.Internal.Management.dll,-100
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\Windows.Internal.Management.dll,-101

+ @%SystemRoot%\system32\dmwappushsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\system32\dmwappushsvc.dll,-201

+ @%SystemRoot%\System32\dnsapi.dll,-101
- %SystemRoot%\system32\svchost.exe -k NetworkService -p
- Auto Load
- @%SystemRoot%\System32\dnsapi.dll,-102

+ @%systemroot%\system32\dosvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Load on Demand
- @%systemroot%\system32\dosvc.dll,-101

+ @%systemroot%\system32\dot3svc.dll,-1102
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\dot3svc.dll,-1103

+ @%systemroot%\system32\dps.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork -p
- Auto Load
- @%systemroot%\system32\dps.dll,-501

+ @%SystemRoot%\system32\DeviceSetupManager.dll,-1000
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\DeviceSetupManager.dll,-1001

+ @%SystemRoot%\system32\dssvc.dll,-10003
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\dssvc.dll,-10002

+ @%systemroot%\system32\eapsvc.dll,-1
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\eapsvc.dll,-2

+ Microsoft Edge Update Service (edgeupdate)
- "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svc
- Auto Load
- Keeps your Microsoft software up to date. If this service is disabled or stopped, your Microsoft software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Microsoft software using it.

+ Microsoft Edge Update Service (edgeupdatem)
- "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /medsvc
- Load on Demand
- Keeps your Microsoft software up to date. If this service is disabled or stopped, your Microsoft software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Microsoft software using it.

+ @%SystemRoot%\system32\efssvc.dll,-100
- %SystemRoot%\System32\lsass.exe
- Load on Demand
- @%SystemRoot%\system32\efssvc.dll,-101

+ @%SystemRoot%\system32\embeddedmodesvc.dll,-201
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\embeddedmodesvc.dll,-202

+ @EnterpriseAppMgmtSvc.dll,-1
- %systemroot%\system32\svchost.exe -k appmodel -p
- Load on Demand
- @EnterpriseAppMgmtSvc.dll,-2

+ @%SystemRoot%\system32\wevtsvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\wevtsvc.dll,-201

+ @comres.dll,-2450
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @comres.dll,-2451

+ @%systemroot%\system32\fdPHost.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%systemroot%\system32\fdPHost.dll,-101

+ @%systemroot%\system32\fdrespub.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- Load on Demand
- @%systemroot%\system32\fdrespub.dll,-101

+ @%systemroot%\system32\FntCache.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @%systemroot%\system32\FntCache.dll,-101

+ @%SystemRoot%\system32\PresentationHost.exe,-3309
- %systemroot%\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
- Load on Demand
- @%SystemRoot%\system32\PresentationHost.exe,-3310

+ @%systemroot%\system32\FrameServer.dll,-100
- %SystemRoot%\System32\svchost.exe -k Camera
- Load on Demand
- @%systemroot%\system32\FrameServer.dll,-101

+ @gpapi.dll,-112
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @gpapi.dll,-113

+ @%SystemRoot%\system32\GraphicsPerfSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k GraphicsPerfSvcGroup
- disabled
- @%SystemRoot%\system32\GraphicsPerfSvc.dll,-101

+ Sentinel LDK License Manager
- C:\Windows\system32\hasplms.exe -run
- Auto Load
- Manages licenses secured by Sentinel LDK.

+ @%SystemRoot%\System32\hidserv.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\hidserv.dll,-102

+ @%SystemRoot%\system32\hvhostsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\hvhostsvc.dll,-101

+ @%SystemRoot%\System32\tetheringservice.dll,-4097
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- disabled
- @%SystemRoot%\System32\tetheringservice.dll,-4098

+ @%windir%\system32\inetsrv\iisres.dll,-30007
- %windir%\system32\inetsrv\inetinfo.exe
- Auto Load
- @%windir%\system32\inetsrv\iisres.dll,-30008

+ @%SystemRoot%\system32\ikeext.dll,-501
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\system32\ikeext.dll,-502

+ @%SystemRoot%\system32\InstallService.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\InstallService.dll,-201

+ @%SystemRoot%\system32\iphlpsvc.dll,-500
- %SystemRoot%\System32\svchost.exe -k NetSvcs -p
- Auto Load
- @%SystemRoot%\system32\iphlpsvc.dll,-501

+ @keyiso.dll,-100
- %SystemRoot%\system32\lsass.exe
- Load on Demand
- @keyiso.dll,-101

+ Kaspersky Security Center Network Agent
- "C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\klnagent.exe"
- Auto Load
- Network Agent coordinates interaction between the Administration Server and Kaspersky applications installed on devices.

+ @%systemroot%\system32\kpssvc.dll,-100
- %systemroot%\system32\svchost.exe -k KpsSvcGroup
- Load on Demand
- @%systemroot%\system32\kpssvc.dll,-101

+ Kaspersky Security Network proxy server
- "C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\ksnproxy.exe"
- Load on Demand
- The KSN proxy service retranslates requests to Kaspersky Security Network and caches the responses.

+ @comres.dll,-2946
- %SystemRoot%\System32\svchost.exe -k NetworkServiceAndNoImpersonation -p
- Load on Demand
- @comres.dll,-2947

+ @%systemroot%\system32\srvsvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k smbsvcs
- Auto Load
- @%systemroot%\system32\srvsvc.dll,-101

+ @%systemroot%\system32\wkssvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Auto Load
- @%systemroot%\system32\wkssvc.dll,-101

+ @%SystemRoot%\System32\lfsvc.dll,-1
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\System32\lfsvc.dll,-2

+ @%SystemRoot%\system32\licensemanagersvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\licensemanagersvc.dll,-201

+ @%SystemRoot%\system32\lltdres.dll,-1
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- disabled
- @%SystemRoot%\system32\lltdres.dll,-2

+ @%SystemRoot%\system32\lmhsvc.dll,-101
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\lmhsvc.dll,-102

+ @%windir%\system32\lsm.dll,-1001
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @%windir%\system32\lsm.dll,-1002

+ @%SystemRoot%\System32\moshost.dll,-100
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- disabled
- @%SystemRoot%\System32\moshost.dll,-101

+ Microsoft Edge Elevation Service (MicrosoftEdgeElevationService)
- "C:\Program Files (x86)\Microsoft\Edge\Application\144.0.3719.82\elevation_service.exe"
- Load on Demand
- Provides elevated privileges for Microsoft Edge.

+ @%SystemRoot%\system32\FirewallAPI.dll,-23090
- %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p
- Auto Load
- @%SystemRoot%\system32\FirewallAPI.dll,-23091

+ @comres.dll,-2797
- %SystemRoot%\System32\msdtc.exe
- Auto Load
- @comres.dll,-2798

+ @%SystemRoot%\system32\iscsidsc.dll,-5000
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\iscsidsc.dll,-5001

+ @%SystemRoot%\system32\msimsg.dll,-27
- %systemroot%\system32\msiexec.exe /V
- Load on Demand
- @%SystemRoot%\system32\msimsg.dll,-32

+ @mqutil.dll,-6102
- %systemroot%\system32\mqsvc.exe
- Auto Load
- @mqutil.dll,-6104

+ @%SystemRoot%\system32\ncasvc.dll,-3009
- %SystemRoot%\System32\svchost.exe -k NetSvcs -p
- Load on Demand
- @%SystemRoot%\system32\ncasvc.dll,-3008

+ @%SystemRoot%\system32\ncbservice.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\ncbservice.dll,-501

+ @%SystemRoot%\System32\netlogon.dll,-102
- %systemroot%\system32\lsass.exe
- Load on Demand
- @%SystemRoot%\System32\netlogon.dll,-103

+ @%SystemRoot%\system32\netman.dll,-109
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\netman.dll,-110

+ @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8195
- "%systemroot%\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe" -NetMsmqActivator
- Auto Load
- @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8194

+ @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8197
- %systemroot%\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
- Auto Load
- @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8196

+ @%SystemRoot%\system32\netprofmsvc.dll,-202
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\netprofmsvc.dll,-203

+ @%SystemRoot%\system32\NetSetupSvc.dll,-3
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\NetSetupSvc.dll,-4

+ @C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8199
- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
- Auto Load
- @C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8198

+ @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8201
- %systemroot%\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
- Load on Demand
- @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8200

+ Nexsus Communication Server
- "D:\Nexsus\Nexsus_Patch\NexCommServer\Nexsus.CommServer.exe"
- Load on Demand
- Establish multi party bi-directional real time communication

+ Nexsus.UserStatusValidatorWeb
- "D:\Nexsus\Nexsus_Services\Nexsus.MaxDial.UserStatusValidator_Web\Nexsus.MaxDial.UserStatusValidator.exe"
- Auto Load
-

+
- "D:\Nexsus\Nexsus_Patch\Nexsus.MaxDial.EmailService\NexsusEmailService.exe"
- Auto Load
-

+ @%SystemRoot%\System32\NgcCtnrSvc.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\NgcCtnrSvc.dll,-2

+ @%SystemRoot%\System32\ngcsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\ngcsvc.dll,-101

+ @%SystemRoot%\System32\nlasvc.dll,-1
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Auto Load
- @%SystemRoot%\System32\nlasvc.dll,-2

+ @%SystemRoot%\system32\nsisvc.dll,-200
- %systemroot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @%SystemRoot%\system32\nsisvc.dll,-201

+ Office Source Engine
- "C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
- Load on Demand
- Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports.

+ Office 64 Source Engine
- "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
- Load on Demand
- Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports.

+ @%SystemRoot%\system32\pcasvc.dll,-1
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\pcasvc.dll,-2

+ @%systemroot%\sysWow64\perfhost.exe,-2
- %SystemRoot%\SysWow64\perfhost.exe
- Load on Demand
- @%systemroot%\SysWow64\perfhost.exe,-1

+ @%SystemRoot%\system32\PhoneserviceRes.dll,-10000
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- disabled
- @%SystemRoot%\system32\PhoneserviceRes.dll,-10001

+ @%systemroot%\system32\pla.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork -p
- Load on Demand
- @%systemroot%\system32\pla.dll,-501

+ @%SystemRoot%\system32\umpnpmgr.dll,-200
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Load on Demand
- @%SystemRoot%\system32\umpnpmgr.dll,-101

+ @%SystemRoot%\System32\polstore.dll,-5010
- %SystemRoot%\system32\svchost.exe -k NetworkServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\polstore.dll,-5011

+ @%SystemRoot%\system32\umpo.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @%SystemRoot%\system32\umpo.dll,-101

+ @%systemroot%\system32\profsvc.dll,-300
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%systemroot%\system32\profsvc.dll,-301

+ @%SystemRoot%\system32\pushtoinstall.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\system32\pushtoinstall.dll,-201

+ @%SystemRoot%\system32\qwave.dll,-1
- %windir%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- Load on Demand
- @%SystemRoot%\system32\qwave.dll,-2

+ @%Systemroot%\system32\rasauto.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%Systemroot%\system32\rasauto.dll,-201

+ @%Systemroot%\system32\rasmans.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Auto Load
- @%Systemroot%\system32\rasmans.dll,-201

+ @%Systemroot%\system32\mprdim.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs
- disabled
- @%Systemroot%\system32\mprdim.dll,-201

+ Remote Registry
- %SystemRoot%\system32\svchost.exe -k localService -p
- Load on Demand
- @regsvc.dll,-2

+ @%SystemRoot%\system32\RMapi.dll,-1001
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
- disabled
- @%SystemRoot%\system32\RMapi.dll,-1002

+ Remote Packet Capture Protocol v.0 (experimental)
- "%ProgramFiles(x86)%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles(x86)%\WinPcap\rpcapd.ini"
- Load on Demand
- Allows to capture traffic on this machine from a remote machine.

+ @%windir%\system32\RpcEpMap.dll,-1001
- %SystemRoot%\system32\svchost.exe -k RPCSS -p
- Auto Load
- @%windir%\system32\RpcEpMap.dll,-1002

+ @%systemroot%\system32\Locator.exe,-2
- %SystemRoot%\system32\locator.exe
- Load on Demand
- @%systemroot%\system32\Locator.exe,-3

+ @combase.dll,-5010
- %SystemRoot%\system32\svchost.exe -k rpcss -p
- Auto Load
- @combase.dll,-5011

+ @gpapi.dll,-114
- %SystemRoot%\system32\RSoPProv.exe
- Load on Demand
- @gpapi.dll,-115

+ @%systemroot%\system32\sacsvr.dll,-500
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\sacsvr.dll,-501

+ @%SystemRoot%\system32\samsrv.dll,-1
- %SystemRoot%\system32\lsass.exe
- Auto Load
- @%SystemRoot%\system32\samsrv.dll,-2

+ @%SystemRoot%\System32\SCardSvr.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
- Load on Demand
- @%SystemRoot%\System32\SCardSvr.dll,-5

+ @%SystemRoot%\System32\ScDeviceEnum.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- disabled
- @%SystemRoot%\System32\ScDeviceEnum.dll,-101

+ @%SystemRoot%\system32\schedsvc.dll,-100
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\system32\schedsvc.dll,-101

+ @%SystemRoot%\System32\certprop.dll,-13
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\certprop.dll,-14

+ @%SystemRoot%\system32\seclogon.dll,-7001
- %windir%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\seclogon.dll,-7000

+ @%systemroot%\system32\SecurityHealthAgent.dll,-1002
- %SystemRoot%\system32\SecurityHealthService.exe
- Load on Demand
- @%systemroot%\system32\SecurityHealthAgent.dll,-1001

+ @%SystemRoot%\System32\SEMgrSvc.dll,-1001
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- disabled
- @%SystemRoot%\System32\SEMgrSvc.dll,-1002

+ @%SystemRoot%\system32\Sens.dll,-200
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\system32\Sens.dll,-201

+ @%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1001
- "%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe"
- Load on Demand
- @%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1002

+ @%SystemRoot%\system32\SensorDataService.exe,-101
- %SystemRoot%\System32\SensorDataService.exe
- disabled
- @%SystemRoot%\system32\SensorDataService.exe,-102

+ @%SystemRoot%\System32\sensorservice.dll,-1000
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\sensorservice.dll,-1001

+ @%SystemRoot%\System32\sensrsvc.dll,-1000
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- Load on Demand
- @%SystemRoot%\System32\sensrsvc.dll,-1001

+ @%SystemRoot%\System32\SessEnv.dll,-1026
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\System32\SessEnv.dll,-1027

+ @%SystemRoot%\System32\SgrmBroker.exe,-100
- %SystemRoot%\system32\SgrmBroker.exe
- Load on Demand
- @%SystemRoot%\System32\SgrmBroker.exe,-101

+ @%SystemRoot%\system32\ipnathlp.dll,-106
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\system32\ipnathlp.dll,-107

+ @%SystemRoot%\System32\shsvcs.dll,-12288
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\System32\shsvcs.dll,-12289

+ @%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-101

+ @%SystemRoot%\System32\smphost.dll,-102
- %SystemRoot%\System32\svchost.exe -k smphost
- Load on Demand
- @%SystemRoot%\System32\smphost.dll,-101

+ @firewallapi.dll,-50323
- %SystemRoot%\System32\snmptrap.exe
- Load on Demand
- @firewallapi.dll,-50324

+ @%SystemRoot%\system32\sppsvc.exe,-101
- %SystemRoot%\system32\sppsvc.exe
- Auto Load
- @%SystemRoot%\system32\sppsvc.exe,-100

+ SQL Server Reporting Services
- "C:\Program Files\Microsoft SQL Server Reporting Services\SSRS\RSHostingService\RSHostingService.exe"
- Auto Load
- Manages, executes, renders, schedules, and delivers reports.

+ @%systemroot%\system32\ssdpsrv.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- disabled
- @%systemroot%\system32\ssdpsrv.dll,-101

+ OpenSSH Authentication Agent
- %SystemRoot%\System32\OpenSSH\ssh-agent.exe
- disabled
- Agent to hold private keys used for public key authentication.

+ @%SystemRoot%\system32\sstpsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\sstpsvc.dll,-201

+ @%SystemRoot%\system32\windows.staterepository.dll,-1
- %SystemRoot%\system32\svchost.exe -k appmodel -p
- Load on Demand
- @%SystemRoot%\system32\windows.staterepository.dll,-2

+ @%SystemRoot%\system32\wiaservc.dll,-9
- %SystemRoot%\system32\svchost.exe -k imgsvc
- Load on Demand
- @%SystemRoot%\system32\wiaservc.dll,-10

+ @%SystemRoot%\System32\StorSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\StorSvc.dll,-101

+ @%SystemRoot%\system32\svsvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\svsvc.dll,-102

+ @%SystemRoot%\System32\swprv.dll,-103
- %SystemRoot%\System32\svchost.exe -k swprv
- Load on Demand
- @%SystemRoot%\System32\swprv.dll,-102

+ SynHMPCodec
- C:\ShCti\HMPCodec.exe
- Auto Load
-

+ SynIPR Record Slaver
- C:\ShCti\record_slaver.exe
- Auto Load
-

+ @%SystemRoot%\system32\sysmain.dll,-1000
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\sysmain.dll,-1001

+ @%windir%\system32\SystemEventsBrokerServer.dll,-1001
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @%windir%\system32\SystemEventsBrokerServer.dll,-1002

+ @%SystemRoot%\system32\TabSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\TabSvc.dll,-101

+ @%SystemRoot%\system32\tapisrv.dll,-10100
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Load on Demand
- @%SystemRoot%\system32\tapisrv.dll,-10101

+ @%SystemRoot%\System32\termsrv.dll,-268
- %SystemRoot%\System32\svchost.exe -k termsvcs
- Load on Demand
- @%SystemRoot%\System32\termsrv.dll,-267

+ @%SystemRoot%\System32\themeservice.dll,-8192
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\System32\themeservice.dll,-8193

+ @%SystemRoot%\system32\TieringEngineService.exe,-702
- %SystemRoot%\system32\TieringEngineService.exe
- Load on Demand
- @%SystemRoot%\system32\TieringEngineService.exe,-701

+ @%windir%\system32\TimeBrokerServer.dll,-1001
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%windir%\system32\TimeBrokerServer.dll,-1002

+ @%systemroot%\system32\tokenbroker.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\tokenbroker.dll,-101

+ @%SystemRoot%\system32\trkwks.dll,-1
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\trkwks.dll,-2

+ @%SystemRoot%\servicing\TrustedInstaller.exe,-100
- %SystemRoot%\servicing\TrustedInstaller.exe
- Load on Demand
- @%SystemRoot%\servicing\TrustedInstaller.exe,-101

+ @%SystemRoot%\system32\tzautoupdate.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- disabled
- @%SystemRoot%\system32\tzautoupdate.dll,-201

+ @%systemroot%\system32\ualsvc.dll,-102
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Auto Load
- @%systemroot%\system32\ualsvc.dll,-101

+ @%systemroot%\system32\AgentService.exe,-102
- %systemroot%\system32\AgentService.exe
- disabled
- @%systemroot%\system32\AgentService.exe,-101

+ @%SystemRoot%\system32\umrdp.dll,-1000
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\umrdp.dll,-1001

+ @%systemroot%\system32\upnphost.dll,-213
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- disabled
- @%systemroot%\system32\upnphost.dll,-214

+ @%systemroot%\system32\usermgr.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%systemroot%\system32\usermgr.dll,-101

+ @%systemroot%\system32\usocore.dll,-101
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%systemroot%\system32\usocore.dll,-102

+ @%SystemRoot%\system32\vaultsvc.dll,-1003
- %SystemRoot%\system32\lsass.exe
- Load on Demand
- @%SystemRoot%\system32\vaultsvc.dll,-1004

+ @%SystemRoot%\system32\vds.exe,-100
- %SystemRoot%\System32\vds.exe
- Load on Demand
- @%SystemRoot%\system32\vds.exe,-112

+ VMware Alias Manager and Ticket Service
- "C:\Program Files\VMware\VMware Tools\VMware VGAuth\VGAuthService.exe"
- Auto Load
- Alias Manager and Ticket Service

+ @oem8.inf,%VM3DSERVICE_DISPLAYNAME%;VMware SVGA Helper Service
- %SystemRoot%\system32\vm3dservice.exe
- Auto Load
- @oem8.inf,%VM3DSERVICE_DESCRIPTION%;Helps VMware SVGA driver by collecting and conveying user mode information

+ @%systemroot%\system32\icsvc.dll,-801
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-802

+ @%systemroot%\system32\icsvc.dll,-101
- %systemroot%\system32\svchost.exe -k ICService -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-102

+ @%systemroot%\system32\icsvc.dll,-201
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-202

+ @%systemroot%\system32\icsvcext.dll,-601
- %systemroot%\system32\svchost.exe -k ICService -p
- Load on Demand
- @%systemroot%\system32\icsvcext.dll,-602

+ @%systemroot%\system32\icsvc.dll,-301
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-302

+ @%systemroot%\system32\icsvc.dll,-401
- %systemroot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-402

+ @%systemroot%\system32\icsvc.dll,-901
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-902

+ @%systemroot%\system32\icsvcext.dll,-501
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvcext.dll,-502

+ VMware Tools
- "C:\Program Files\VMware\VMware Tools\vmtoolsd.exe"
- Auto Load
- Provides support for synchronizing objects between the host and guest operating systems.

+ VMware Snapshot Provider
- C:\Windows\system32\dllhost.exe /Processid:{EF7DED12-05C5-4EFB-8CB5-70F3C252BB5F}
- Load on Demand
- VMware Snapshot Provider

+ @%systemroot%\system32\vssvc.exe,-102
- %systemroot%\system32\vssvc.exe
- Load on Demand
- @%systemroot%\system32\vssvc.exe,-101

+ @%SystemRoot%\system32\w32time.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService
- Auto Load
- @%SystemRoot%\system32\w32time.dll,-201

+ @%windir%\system32\inetsrv\iisres.dll,-30014
- %windir%\system32\svchost.exe -k apphost
- Load on Demand
- @%windir%\system32\inetsrv\iisres.dll,-30015

+ @%windir%\system32\inetsrv\iisres.dll,-30003
- %windir%\system32\svchost.exe -k iissvcs
- Auto Load
- @%windir%\system32\inetsrv\iisres.dll,-30004

+ @WaaSMedicSvc.dll,-100
- %systemroot%\system32\svchost.exe -k wusvcs -p
- Load on Demand
- @WaaSMedicSvc.dll,-101

+ @%SystemRoot%\System32\WalletService.dll,-1000
- %SystemRoot%\System32\svchost.exe -k appmodel -p
- disabled
- @%SystemRoot%\System32\WalletService.dll,-1001

+ @%SystemRoot%\System32\Windows.WARP.JITService.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\Windows.WARP.JITService.dll,-101

+ @%windir%\system32\inetsrv\iisres.dll,-30001
- %windir%\system32\svchost.exe -k iissvcs
- Load on Demand
- @%windir%\system32\inetsrv\iisres.dll,-30002

+ @%systemroot%\system32\wbiosrvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k WbioSvcGroup
- Load on Demand
- @%systemroot%\system32\wbiosrvc.dll,-101

+ @%SystemRoot%\System32\wcmsvc.dll,-4097
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Auto Load
- @%SystemRoot%\System32\wcmsvc.dll,-4098

+ @%systemroot%\system32\wdi.dll,-502
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- Load on Demand
- @%systemroot%\system32\wdi.dll,-503

+ @%systemroot%\system32\wdi.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\wdi.dll,-501

+ @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320
- "%ProgramData%\Microsoft\Windows Defender\platform\4.18.24050.7-0\NisSrv.exe"
- Load on Demand
- @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-242

+ @%SystemRoot%\system32\wecsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k NetworkService -p
- Load on Demand
- @%SystemRoot%\system32\wecsvc.dll,-201

+ @%systemroot%\system32\wephostsvc.dll,-100
- %systemroot%\system32\svchost.exe -k WepHostSvcGroup
- Load on Demand
- @%systemroot%\system32\wephostsvc.dll,-101

+ @%SystemRoot%\System32\wercplsupport.dll,-101
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\System32\wercplsupport.dll,-100

+ @%SystemRoot%\System32\wersvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k WerSvcGroup
- Load on Demand
- @%SystemRoot%\System32\wersvc.dll,-101

+ @%SystemRoot%\system32\wiarpc.dll,-2
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\wiarpc.dll,-1

+ @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310
- "C:\ProgramData\Microsoft\Windows Defender\platform\4.18.24050.7-0\MsMpEng.exe"
- Load on Demand
- @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-240

+ @%SystemRoot%\system32\winhttp.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\winhttp.dll,-101

+ @%Systemroot%\system32\wbem\wmisvc.dll,-205
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%Systemroot%\system32\wbem\wmisvc.dll,-204

+ @%Systemroot%\system32\wsmsvc.dll,-101
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Auto Load
- @%Systemroot%\system32\wsmsvc.dll,-102

+ @%SystemRoot%\system32\flightsettings.dll,-103
- %systemroot%\system32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\system32\flightsettings.dll,-104

+ @%SystemRoot%\system32\wlidsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\wlidsvc.dll,-101

+ @%Systemroot%\system32\wbem\wmiapsrv.exe,-110
- %systemroot%\system32\wbem\WmiApSrv.exe
- Load on Demand
- @%Systemroot%\system32\wbem\wmiapsrv.exe,-111

+ @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101
- "%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe"
- Load on Demand
- @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-102

+ @%windir%\system32\inetsrv\iisres.dll,-20001
- %windir%\system32\inetsrv\wmsvc.exe
- Load on Demand
- @%windir%\system32\inetsrv\iisres.dll,-20002

+ @%SystemRoot%\system32\wpdbusenum.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\wpdbusenum.dll,-101

+ @%SystemRoot%\system32\wpnservice.dll,-1
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\system32\wpnservice.dll,-2

+ @%systemroot%\system32\SearchIndexer.exe,-103
- %systemroot%\system32\SearchIndexer.exe /Embedding
- disabled
- @%systemroot%\system32\SearchIndexer.exe,-104

+ Windows Update
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%systemroot%\system32\wuaueng.dll,-106

+ @wpdfs.inf,%WPDFS_SvcName%;WPD File System driver
- \SystemRoot\system32\DRIVERS\WUDFRd.sys
- Load on Demand
- @wpdfs.inf,%WPDFS_SvcDesc%;User mode driver that enables communication with removable storage devices via the WPD interface


Services :
+ @%SystemRoot%\system32\AJRouter.dll,-2
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\AJRouter.dll,-1

+ @%SystemRoot%\system32\Alg.exe,-112
- %SystemRoot%\System32\alg.exe
- Load on Demand
- @%SystemRoot%\system32\Alg.exe,-113

+ @%windir%\system32\inetsrv\iisres.dll,-30011
- %windir%\system32\svchost.exe -k apphost
- Auto Load
- @%windir%\system32\inetsrv\iisres.dll,-30012

+ @%systemroot%\system32\appidsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\appidsvc.dll,-101

+ @%systemroot%\system32\appinfo.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\appinfo.dll,-101

+ @appmgmts.dll,-3250
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @appmgmts.dll,-3251

+ @%SystemRoot%\System32\AppReadiness.dll,-1000
- %SystemRoot%\System32\svchost.exe -k AppReadiness -p
- Load on Demand
- @%SystemRoot%\System32\AppReadiness.dll,-1001

+ @%systemroot%\system32\AppVClient.exe,-102
- %systemroot%\system32\AppVClient.exe
- disabled
- @%systemroot%\system32\AppVClient.exe,-101

+ @%SystemRoot%\system32\appxdeploymentserver.dll,-1
- %systemroot%\system32\svchost.exe -k wsappx -p
- Load on Demand
- @%SystemRoot%\system32\appxdeploymentserver.dll,-2

+ @%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1
- %systemroot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
- Load on Demand
- @%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-2

+ @%SystemRoot%\system32\AudioEndpointBuilder.dll,-204
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\AudioEndpointBuilder.dll,-205

+ @%SystemRoot%\system32\audiosrv.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\audiosrv.dll,-201

+ Kaspersky Endpoint Security Service (KES.21.15)
- "C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avp.exe" -r
- Auto Load
- Provides computer protection against viruses, other malicious applications, and network attacks.

+ Kaspersky Seamless Update Service (KES.21.15)
- "C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avpsus.exe"
- Auto Load
- Lets you install and roll back critical and approved updates of application modules.

+ @%SystemRoot%\system32\AxInstSV.dll,-103
- %SystemRoot%\system32\svchost.exe -k AxInstSVGroup
- disabled
- @%SystemRoot%\system32\AxInstSV.dll,-104

+ @%SystemRoot%\system32\bfe.dll,-1001
- %systemroot%\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p
- Auto Load
- @%SystemRoot%\system32\bfe.dll,-1002

+ @%SystemRoot%\system32\qmgr.dll,-1000
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\qmgr.dll,-1001

+ @%windir%\system32\bisrv.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @%windir%\system32\bisrv.dll,-101

+ @%SystemRoot%\system32\BTAGService.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\BTAGService.dll,-102

+ @%SystemRoot%\system32\BthAvctpSvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\BthAvctpSvc.dll,-102

+ @%SystemRoot%\System32\bthserv.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\System32\bthserv.dll,-102

+ CallBalanceClopsVoiceLogService_LKP
- "D:\Nexsus\Nexsus_Patch\Nexsus.MaxDial.VoiceLogService_Web_LKP\Nexsus.CallBalancel.VoiceLogService.exe"
- Auto Load
- MaxDialLogService punch data into database.

+ @%SystemRoot%\system32\CapabilityAccessManager.dll,-1
- %SystemRoot%\system32\svchost.exe -k appmodel -p
- Load on Demand
- @%SystemRoot%\system32\CapabilityAccessManager.dll,-2

+ @%SystemRoot%\system32\cdpsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @%SystemRoot%\system32\cdpsvc.dll,-101

+ @%SystemRoot%\System32\certprop.dll,-11
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\certprop.dll,-12

+ @%SystemRoot%\system32\ClipSVC.dll,-103
- %SystemRoot%\System32\svchost.exe -k wsappx -p
- Load on Demand
- @%SystemRoot%\system32\ClipSVC.dll,-104

+ @comres.dll,-947
- %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
- Load on Demand
- @comres.dll,-948

+ @%SystemRoot%\system32\coremessaging.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork -p
- Auto Load
- @%SystemRoot%\system32\coremessaging.dll,-2

+ @%SystemRoot%\system32\cryptsvc.dll,-1001
- %SystemRoot%\system32\svchost.exe -k NetworkService -p
- Auto Load
- @%SystemRoot%\system32\cryptsvc.dll,-1002

+ @%systemroot%\system32\cscsvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- disabled
- @%systemroot%\system32\cscsvc.dll,-201

+ @combase.dll,-5012
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @combase.dll,-5013

+ @%SystemRoot%\system32\defragsvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k defragsvc
- Load on Demand
- @%SystemRoot%\system32\defragsvc.dll,-102

+ @%SystemRoot%\system32\das.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\das.dll,-101

+ @%SystemRoot%\system32\umpnpmgr.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Load on Demand
- @%SystemRoot%\system32\umpnpmgr.dll,-101

+ @%SystemRoot%\system32\DevQueryBroker.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\DevQueryBroker.dll,-101

+ @%SystemRoot%\system32\dhcpcore.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\dhcpcore.dll,-101

+ @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000
- %SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe
- Load on Demand
- @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1001

+ @%SystemRoot%\system32\diagtrack.dll,-3001
- %SystemRoot%\System32\svchost.exe -k utcsvc -p
- Auto Load
- @%SystemRoot%\system32\diagtrack.dll,-3002

+ @%systemroot%\system32\Windows.Internal.Management.dll,-100
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\Windows.Internal.Management.dll,-101

+ @%SystemRoot%\system32\dmwappushsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\system32\dmwappushsvc.dll,-201

+ @%SystemRoot%\System32\dnsapi.dll,-101
- %SystemRoot%\system32\svchost.exe -k NetworkService -p
- Auto Load
- @%SystemRoot%\System32\dnsapi.dll,-102

+ @%systemroot%\system32\dosvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Load on Demand
- @%systemroot%\system32\dosvc.dll,-101

+ @%systemroot%\system32\dot3svc.dll,-1102
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\dot3svc.dll,-1103

+ @%systemroot%\system32\dps.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork -p
- Auto Load
- @%systemroot%\system32\dps.dll,-501

+ @%SystemRoot%\system32\DeviceSetupManager.dll,-1000
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\DeviceSetupManager.dll,-1001

+ @%SystemRoot%\system32\dssvc.dll,-10003
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\dssvc.dll,-10002

+ @%systemroot%\system32\eapsvc.dll,-1
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\eapsvc.dll,-2

+ Microsoft Edge Update Service (edgeupdate)
- "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svc
- Auto Load
- Keeps your Microsoft software up to date. If this service is disabled or stopped, your Microsoft software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Microsoft software using it.

+ Microsoft Edge Update Service (edgeupdatem)
- "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /medsvc
- Load on Demand
- Keeps your Microsoft software up to date. If this service is disabled or stopped, your Microsoft software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Microsoft software using it.

+ @%SystemRoot%\system32\efssvc.dll,-100
- %SystemRoot%\System32\lsass.exe
- Load on Demand
- @%SystemRoot%\system32\efssvc.dll,-101

+ @%SystemRoot%\system32\embeddedmodesvc.dll,-201
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\embeddedmodesvc.dll,-202

+ @EnterpriseAppMgmtSvc.dll,-1
- %systemroot%\system32\svchost.exe -k appmodel -p
- Load on Demand
- @EnterpriseAppMgmtSvc.dll,-2

+ @%SystemRoot%\system32\wevtsvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\wevtsvc.dll,-201

+ @comres.dll,-2450
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @comres.dll,-2451

+ @%systemroot%\system32\fdPHost.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%systemroot%\system32\fdPHost.dll,-101

+ @%systemroot%\system32\fdrespub.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- Load on Demand
- @%systemroot%\system32\fdrespub.dll,-101

+ @%systemroot%\system32\FntCache.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @%systemroot%\system32\FntCache.dll,-101

+ @%SystemRoot%\system32\PresentationHost.exe,-3309
- %systemroot%\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
- Load on Demand
- @%SystemRoot%\system32\PresentationHost.exe,-3310

+ @%systemroot%\system32\FrameServer.dll,-100
- %SystemRoot%\System32\svchost.exe -k Camera
- Load on Demand
- @%systemroot%\system32\FrameServer.dll,-101

+ @gpapi.dll,-112
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @gpapi.dll,-113

+ @%SystemRoot%\system32\GraphicsPerfSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k GraphicsPerfSvcGroup
- disabled
- @%SystemRoot%\system32\GraphicsPerfSvc.dll,-101

+ Sentinel LDK License Manager
- C:\Windows\system32\hasplms.exe -run
- Auto Load
- Manages licenses secured by Sentinel LDK.

+ @%SystemRoot%\System32\hidserv.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\hidserv.dll,-102

+ @%SystemRoot%\system32\hvhostsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\hvhostsvc.dll,-101

+ @%SystemRoot%\System32\tetheringservice.dll,-4097
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- disabled
- @%SystemRoot%\System32\tetheringservice.dll,-4098

+ @%windir%\system32\inetsrv\iisres.dll,-30007
- %windir%\system32\inetsrv\inetinfo.exe
- Auto Load
- @%windir%\system32\inetsrv\iisres.dll,-30008

+ @%SystemRoot%\system32\ikeext.dll,-501
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\system32\ikeext.dll,-502

+ @%SystemRoot%\system32\InstallService.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\InstallService.dll,-201

+ @%SystemRoot%\system32\iphlpsvc.dll,-500
- %SystemRoot%\System32\svchost.exe -k NetSvcs -p
- Auto Load
- @%SystemRoot%\system32\iphlpsvc.dll,-501

+ @keyiso.dll,-100
- %SystemRoot%\system32\lsass.exe
- Load on Demand
- @keyiso.dll,-101

+ Kaspersky Security Center Network Agent
- "C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\klnagent.exe"
- Auto Load
- Network Agent coordinates interaction between the Administration Server and Kaspersky applications installed on devices.

+ @%systemroot%\system32\kpssvc.dll,-100
- %systemroot%\system32\svchost.exe -k KpsSvcGroup
- Load on Demand
- @%systemroot%\system32\kpssvc.dll,-101

+ Kaspersky Security Network proxy server
- "C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\ksnproxy.exe"
- Load on Demand
- The KSN proxy service retranslates requests to Kaspersky Security Network and caches the responses.

+ @comres.dll,-2946
- %SystemRoot%\System32\svchost.exe -k NetworkServiceAndNoImpersonation -p
- Load on Demand
- @comres.dll,-2947

+ @%systemroot%\system32\srvsvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k smbsvcs
- Auto Load
- @%systemroot%\system32\srvsvc.dll,-101

+ @%systemroot%\system32\wkssvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Auto Load
- @%systemroot%\system32\wkssvc.dll,-101

+ @%SystemRoot%\System32\lfsvc.dll,-1
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\System32\lfsvc.dll,-2

+ @%SystemRoot%\system32\licensemanagersvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\licensemanagersvc.dll,-201

+ @%SystemRoot%\system32\lltdres.dll,-1
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- disabled
- @%SystemRoot%\system32\lltdres.dll,-2

+ @%SystemRoot%\system32\lmhsvc.dll,-101
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\lmhsvc.dll,-102

+ @%windir%\system32\lsm.dll,-1001
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @%windir%\system32\lsm.dll,-1002

+ @%SystemRoot%\System32\moshost.dll,-100
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- disabled
- @%SystemRoot%\System32\moshost.dll,-101

+ Microsoft Edge Elevation Service (MicrosoftEdgeElevationService)
- "C:\Program Files (x86)\Microsoft\Edge\Application\144.0.3719.82\elevation_service.exe"
- Load on Demand
- Provides elevated privileges for Microsoft Edge.

+ @%SystemRoot%\system32\FirewallAPI.dll,-23090
- %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p
- Auto Load
- @%SystemRoot%\system32\FirewallAPI.dll,-23091

+ @comres.dll,-2797
- %SystemRoot%\System32\msdtc.exe
- Auto Load
- @comres.dll,-2798

+ @%SystemRoot%\system32\iscsidsc.dll,-5000
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\iscsidsc.dll,-5001

+ @%SystemRoot%\system32\msimsg.dll,-27
- %systemroot%\system32\msiexec.exe /V
- Load on Demand
- @%SystemRoot%\system32\msimsg.dll,-32

+ @mqutil.dll,-6102
- %systemroot%\system32\mqsvc.exe
- Auto Load
- @mqutil.dll,-6104

+ @%SystemRoot%\system32\ncasvc.dll,-3009
- %SystemRoot%\System32\svchost.exe -k NetSvcs -p
- Load on Demand
- @%SystemRoot%\system32\ncasvc.dll,-3008

+ @%SystemRoot%\system32\ncbservice.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\ncbservice.dll,-501

+ @%SystemRoot%\System32\netlogon.dll,-102
- %systemroot%\system32\lsass.exe
- Load on Demand
- @%SystemRoot%\System32\netlogon.dll,-103

+ @%SystemRoot%\system32\netman.dll,-109
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\netman.dll,-110

+ @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8195
- "%systemroot%\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe" -NetMsmqActivator
- Auto Load
- @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8194

+ @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8197
- %systemroot%\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
- Auto Load
- @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8196

+ @%SystemRoot%\system32\netprofmsvc.dll,-202
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\netprofmsvc.dll,-203

+ @%SystemRoot%\system32\NetSetupSvc.dll,-3
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\NetSetupSvc.dll,-4

+ @C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8199
- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
- Auto Load
- @C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8198

+ @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8201
- %systemroot%\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
- Load on Demand
- @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8200

+ Nexsus Communication Server
- "D:\Nexsus\Nexsus_Patch\NexCommServer\Nexsus.CommServer.exe"
- Load on Demand
- Establish multi party bi-directional real time communication

+ Nexsus.UserStatusValidatorWeb
- "D:\Nexsus\Nexsus_Services\Nexsus.MaxDial.UserStatusValidator_Web\Nexsus.MaxDial.UserStatusValidator.exe"
- Auto Load
-

+
- "D:\Nexsus\Nexsus_Patch\Nexsus.MaxDial.EmailService\NexsusEmailService.exe"
- Auto Load
-

+ @%SystemRoot%\System32\NgcCtnrSvc.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\NgcCtnrSvc.dll,-2

+ @%SystemRoot%\System32\ngcsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\ngcsvc.dll,-101

+ @%SystemRoot%\System32\nlasvc.dll,-1
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Auto Load
- @%SystemRoot%\System32\nlasvc.dll,-2

+ @%SystemRoot%\system32\nsisvc.dll,-200
- %systemroot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @%SystemRoot%\system32\nsisvc.dll,-201

+ Office Source Engine
- "C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
- Load on Demand
- Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports.

+ Office 64 Source Engine
- "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
- Load on Demand
- Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports.

+ @%SystemRoot%\system32\pcasvc.dll,-1
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\pcasvc.dll,-2

+ @%systemroot%\sysWow64\perfhost.exe,-2
- %SystemRoot%\SysWow64\perfhost.exe
- Load on Demand
- @%systemroot%\SysWow64\perfhost.exe,-1

+ @%SystemRoot%\system32\PhoneserviceRes.dll,-10000
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- disabled
- @%SystemRoot%\system32\PhoneserviceRes.dll,-10001

+ @%systemroot%\system32\pla.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork -p
- Load on Demand
- @%systemroot%\system32\pla.dll,-501

+ @%SystemRoot%\system32\umpnpmgr.dll,-200
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Load on Demand
- @%SystemRoot%\system32\umpnpmgr.dll,-101

+ @%SystemRoot%\System32\polstore.dll,-5010
- %SystemRoot%\system32\svchost.exe -k NetworkServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\polstore.dll,-5011

+ @%SystemRoot%\system32\umpo.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @%SystemRoot%\system32\umpo.dll,-101

+ @%systemroot%\system32\profsvc.dll,-300
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%systemroot%\system32\profsvc.dll,-301

+ @%SystemRoot%\system32\pushtoinstall.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\system32\pushtoinstall.dll,-201

+ @%SystemRoot%\system32\qwave.dll,-1
- %windir%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- Load on Demand
- @%SystemRoot%\system32\qwave.dll,-2

+ @%Systemroot%\system32\rasauto.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%Systemroot%\system32\rasauto.dll,-201

+ @%Systemroot%\system32\rasmans.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Auto Load
- @%Systemroot%\system32\rasmans.dll,-201

+ @%Systemroot%\system32\mprdim.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs
- disabled
- @%Systemroot%\system32\mprdim.dll,-201

+ Remote Registry
- %SystemRoot%\system32\svchost.exe -k localService -p
- Load on Demand
- @regsvc.dll,-2

+ @%SystemRoot%\system32\RMapi.dll,-1001
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
- disabled
- @%SystemRoot%\system32\RMapi.dll,-1002

+ Remote Packet Capture Protocol v.0 (experimental)
- "%ProgramFiles(x86)%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles(x86)%\WinPcap\rpcapd.ini"
- Load on Demand
- Allows to capture traffic on this machine from a remote machine.

+ @%windir%\system32\RpcEpMap.dll,-1001
- %SystemRoot%\system32\svchost.exe -k RPCSS -p
- Auto Load
- @%windir%\system32\RpcEpMap.dll,-1002

+ @%systemroot%\system32\Locator.exe,-2
- %SystemRoot%\system32\locator.exe
- Load on Demand
- @%systemroot%\system32\Locator.exe,-3

+ @combase.dll,-5010
- %SystemRoot%\system32\svchost.exe -k rpcss -p
- Auto Load
- @combase.dll,-5011

+ @gpapi.dll,-114
- %SystemRoot%\system32\RSoPProv.exe
- Load on Demand
- @gpapi.dll,-115

+ @%systemroot%\system32\sacsvr.dll,-500
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\sacsvr.dll,-501

+ @%SystemRoot%\system32\samsrv.dll,-1
- %SystemRoot%\system32\lsass.exe
- Auto Load
- @%SystemRoot%\system32\samsrv.dll,-2

+ @%SystemRoot%\System32\SCardSvr.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
- Load on Demand
- @%SystemRoot%\System32\SCardSvr.dll,-5

+ @%SystemRoot%\System32\ScDeviceEnum.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- disabled
- @%SystemRoot%\System32\ScDeviceEnum.dll,-101

+ @%SystemRoot%\system32\schedsvc.dll,-100
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\system32\schedsvc.dll,-101

+ @%SystemRoot%\System32\certprop.dll,-13
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\certprop.dll,-14

+ @%SystemRoot%\system32\seclogon.dll,-7001
- %windir%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\seclogon.dll,-7000

+ @%systemroot%\system32\SecurityHealthAgent.dll,-1002
- %SystemRoot%\system32\SecurityHealthService.exe
- Load on Demand
- @%systemroot%\system32\SecurityHealthAgent.dll,-1001

+ @%SystemRoot%\System32\SEMgrSvc.dll,-1001
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- disabled
- @%SystemRoot%\System32\SEMgrSvc.dll,-1002

+ @%SystemRoot%\system32\Sens.dll,-200
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\system32\Sens.dll,-201

+ @%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1001
- "%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe"
- Load on Demand
- @%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1002

+ @%SystemRoot%\system32\SensorDataService.exe,-101
- %SystemRoot%\System32\SensorDataService.exe
- disabled
- @%SystemRoot%\system32\SensorDataService.exe,-102

+ @%SystemRoot%\System32\sensorservice.dll,-1000
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\sensorservice.dll,-1001

+ @%SystemRoot%\System32\sensrsvc.dll,-1000
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- Load on Demand
- @%SystemRoot%\System32\sensrsvc.dll,-1001

+ @%SystemRoot%\System32\SessEnv.dll,-1026
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\System32\SessEnv.dll,-1027

+ @%SystemRoot%\System32\SgrmBroker.exe,-100
- %SystemRoot%\system32\SgrmBroker.exe
- Load on Demand
- @%SystemRoot%\System32\SgrmBroker.exe,-101

+ @%SystemRoot%\system32\ipnathlp.dll,-106
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\system32\ipnathlp.dll,-107

+ @%SystemRoot%\System32\shsvcs.dll,-12288
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\System32\shsvcs.dll,-12289

+ @%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-101

+ @%SystemRoot%\System32\smphost.dll,-102
- %SystemRoot%\System32\svchost.exe -k smphost
- Load on Demand
- @%SystemRoot%\System32\smphost.dll,-101

+ @firewallapi.dll,-50323
- %SystemRoot%\System32\snmptrap.exe
- Load on Demand
- @firewallapi.dll,-50324

+ @%SystemRoot%\system32\sppsvc.exe,-101
- %SystemRoot%\system32\sppsvc.exe
- Auto Load
- @%SystemRoot%\system32\sppsvc.exe,-100

+ SQL Server Reporting Services
- "C:\Program Files\Microsoft SQL Server Reporting Services\SSRS\RSHostingService\RSHostingService.exe"
- Auto Load
- Manages, executes, renders, schedules, and delivers reports.

+ @%systemroot%\system32\ssdpsrv.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- disabled
- @%systemroot%\system32\ssdpsrv.dll,-101

+ OpenSSH Authentication Agent
- %SystemRoot%\System32\OpenSSH\ssh-agent.exe
- disabled
- Agent to hold private keys used for public key authentication.

+ @%SystemRoot%\system32\sstpsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\sstpsvc.dll,-201

+ @%SystemRoot%\system32\windows.staterepository.dll,-1
- %SystemRoot%\system32\svchost.exe -k appmodel -p
- Load on Demand
- @%SystemRoot%\system32\windows.staterepository.dll,-2

+ @%SystemRoot%\system32\wiaservc.dll,-9
- %SystemRoot%\system32\svchost.exe -k imgsvc
- Load on Demand
- @%SystemRoot%\system32\wiaservc.dll,-10

+ @%SystemRoot%\System32\StorSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\StorSvc.dll,-101

+ @%SystemRoot%\system32\svsvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\svsvc.dll,-102

+ @%SystemRoot%\System32\swprv.dll,-103
- %SystemRoot%\System32\svchost.exe -k swprv
- Load on Demand
- @%SystemRoot%\System32\swprv.dll,-102

+ SynHMPCodec
- C:\ShCti\HMPCodec.exe
- Auto Load
-

+ SynIPR Record Slaver
- C:\ShCti\record_slaver.exe
- Auto Load
-

+ @%SystemRoot%\system32\sysmain.dll,-1000
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\sysmain.dll,-1001

+ @%windir%\system32\SystemEventsBrokerServer.dll,-1001
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @%windir%\system32\SystemEventsBrokerServer.dll,-1002

+ @%SystemRoot%\system32\TabSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\TabSvc.dll,-101

+ @%SystemRoot%\system32\tapisrv.dll,-10100
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Load on Demand
- @%SystemRoot%\system32\tapisrv.dll,-10101

+ @%SystemRoot%\System32\termsrv.dll,-268
- %SystemRoot%\System32\svchost.exe -k termsvcs
- Load on Demand
- @%SystemRoot%\System32\termsrv.dll,-267

+ @%SystemRoot%\System32\themeservice.dll,-8192
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\System32\themeservice.dll,-8193

+ @%SystemRoot%\system32\TieringEngineService.exe,-702
- %SystemRoot%\system32\TieringEngineService.exe
- Load on Demand
- @%SystemRoot%\system32\TieringEngineService.exe,-701

+ @%windir%\system32\TimeBrokerServer.dll,-1001
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%windir%\system32\TimeBrokerServer.dll,-1002

+ @%systemroot%\system32\tokenbroker.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\tokenbroker.dll,-101

+ @%SystemRoot%\system32\trkwks.dll,-1
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\trkwks.dll,-2

+ @%SystemRoot%\servicing\TrustedInstaller.exe,-100
- %SystemRoot%\servicing\TrustedInstaller.exe
- Load on Demand
- @%SystemRoot%\servicing\TrustedInstaller.exe,-101

+ @%SystemRoot%\system32\tzautoupdate.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- disabled
- @%SystemRoot%\system32\tzautoupdate.dll,-201

+ @%systemroot%\system32\ualsvc.dll,-102
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Auto Load
- @%systemroot%\system32\ualsvc.dll,-101

+ @%systemroot%\system32\AgentService.exe,-102
- %systemroot%\system32\AgentService.exe
- disabled
- @%systemroot%\system32\AgentService.exe,-101

+ @%SystemRoot%\system32\umrdp.dll,-1000
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\umrdp.dll,-1001

+ @%systemroot%\system32\upnphost.dll,-213
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- disabled
- @%systemroot%\system32\upnphost.dll,-214

+ @%systemroot%\system32\usermgr.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%systemroot%\system32\usermgr.dll,-101

+ @%systemroot%\system32\usocore.dll,-101
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%systemroot%\system32\usocore.dll,-102

+ @%SystemRoot%\system32\vaultsvc.dll,-1003
- %SystemRoot%\system32\lsass.exe
- Load on Demand
- @%SystemRoot%\system32\vaultsvc.dll,-1004

+ @%SystemRoot%\system32\vds.exe,-100
- %SystemRoot%\System32\vds.exe
- Load on Demand
- @%SystemRoot%\system32\vds.exe,-112

+ VMware Alias Manager and Ticket Service
- "C:\Program Files\VMware\VMware Tools\VMware VGAuth\VGAuthService.exe"
- Auto Load
- Alias Manager and Ticket Service

+ @oem8.inf,%VM3DSERVICE_DISPLAYNAME%;VMware SVGA Helper Service
- %SystemRoot%\system32\vm3dservice.exe
- Auto Load
- @oem8.inf,%VM3DSERVICE_DESCRIPTION%;Helps VMware SVGA driver by collecting and conveying user mode information

+ @%systemroot%\system32\icsvc.dll,-801
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-802

+ @%systemroot%\system32\icsvc.dll,-101
- %systemroot%\system32\svchost.exe -k ICService -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-102

+ @%systemroot%\system32\icsvc.dll,-201
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-202

+ @%systemroot%\system32\icsvcext.dll,-601
- %systemroot%\system32\svchost.exe -k ICService -p
- Load on Demand
- @%systemroot%\system32\icsvcext.dll,-602

+ @%systemroot%\system32\icsvc.dll,-301
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-302

+ @%systemroot%\system32\icsvc.dll,-401
- %systemroot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-402

+ @%systemroot%\system32\icsvc.dll,-901
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-902

+ @%systemroot%\system32\icsvcext.dll,-501
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvcext.dll,-502

+ VMware Tools
- "C:\Program Files\VMware\VMware Tools\vmtoolsd.exe"
- Auto Load
- Provides support for synchronizing objects between the host and guest operating systems.

+ VMware Snapshot Provider
- C:\Windows\system32\dllhost.exe /Processid:{EF7DED12-05C5-4EFB-8CB5-70F3C252BB5F}
- Load on Demand
- VMware Snapshot Provider

+ @%systemroot%\system32\vssvc.exe,-102
- %systemroot%\system32\vssvc.exe
- Load on Demand
- @%systemroot%\system32\vssvc.exe,-101

+ @%SystemRoot%\system32\w32time.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService
- Auto Load
- @%SystemRoot%\system32\w32time.dll,-201

+ @%windir%\system32\inetsrv\iisres.dll,-30014
- %windir%\system32\svchost.exe -k apphost
- Load on Demand
- @%windir%\system32\inetsrv\iisres.dll,-30015

+ @%windir%\system32\inetsrv\iisres.dll,-30003
- %windir%\system32\svchost.exe -k iissvcs
- Auto Load
- @%windir%\system32\inetsrv\iisres.dll,-30004

+ @WaaSMedicSvc.dll,-100
- %systemroot%\system32\svchost.exe -k wusvcs -p
- Load on Demand
- @WaaSMedicSvc.dll,-101

+ @%SystemRoot%\System32\WalletService.dll,-1000
- %SystemRoot%\System32\svchost.exe -k appmodel -p
- disabled
- @%SystemRoot%\System32\WalletService.dll,-1001

+ @%SystemRoot%\System32\Windows.WARP.JITService.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\Windows.WARP.JITService.dll,-101

+ @%windir%\system32\inetsrv\iisres.dll,-30001
- %windir%\system32\svchost.exe -k iissvcs
- Load on Demand
- @%windir%\system32\inetsrv\iisres.dll,-30002

+ @%systemroot%\system32\wbiosrvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k WbioSvcGroup
- Load on Demand
- @%systemroot%\system32\wbiosrvc.dll,-101

+ @%SystemRoot%\System32\wcmsvc.dll,-4097
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Auto Load
- @%SystemRoot%\System32\wcmsvc.dll,-4098

+ @%systemroot%\system32\wdi.dll,-502
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- Load on Demand
- @%systemroot%\system32\wdi.dll,-503

+ @%systemroot%\system32\wdi.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\wdi.dll,-501

+ @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320
- "%ProgramData%\Microsoft\Windows Defender\platform\4.18.24050.7-0\NisSrv.exe"
- Load on Demand
- @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-242

+ @%SystemRoot%\system32\wecsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k NetworkService -p
- Load on Demand
- @%SystemRoot%\system32\wecsvc.dll,-201

+ @%systemroot%\system32\wephostsvc.dll,-100
- %systemroot%\system32\svchost.exe -k WepHostSvcGroup
- Load on Demand
- @%systemroot%\system32\wephostsvc.dll,-101

+ @%SystemRoot%\System32\wercplsupport.dll,-101
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\System32\wercplsupport.dll,-100

+ @%SystemRoot%\System32\wersvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k WerSvcGroup
- Load on Demand
- @%SystemRoot%\System32\wersvc.dll,-101

+ @%SystemRoot%\system32\wiarpc.dll,-2
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\wiarpc.dll,-1

+ @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310
- "C:\ProgramData\Microsoft\Windows Defender\platform\4.18.24050.7-0\MsMpEng.exe"
- Load on Demand
- @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-240

+ @%SystemRoot%\system32\winhttp.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\winhttp.dll,-101

+ @%Systemroot%\system32\wbem\wmisvc.dll,-205
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%Systemroot%\system32\wbem\wmisvc.dll,-204

+ @%Systemroot%\system32\wsmsvc.dll,-101
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Auto Load
- @%Systemroot%\system32\wsmsvc.dll,-102

+ @%SystemRoot%\system32\flightsettings.dll,-103
- %systemroot%\system32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\system32\flightsettings.dll,-104

+ @%SystemRoot%\system32\wlidsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\wlidsvc.dll,-101

+ @%Systemroot%\system32\wbem\wmiapsrv.exe,-110
- %systemroot%\system32\wbem\WmiApSrv.exe
- Load on Demand
- @%Systemroot%\system32\wbem\wmiapsrv.exe,-111

+ @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101
- "%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe"
- Load on Demand
- @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-102

+ @%windir%\system32\inetsrv\iisres.dll,-20001
- %windir%\system32\inetsrv\wmsvc.exe
- Load on Demand
- @%windir%\system32\inetsrv\iisres.dll,-20002

+ @%SystemRoot%\system32\wpdbusenum.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\wpdbusenum.dll,-101

+ @%SystemRoot%\system32\wpnservice.dll,-1
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\system32\wpnservice.dll,-2

+ @%systemroot%\system32\SearchIndexer.exe,-103
- %systemroot%\system32\SearchIndexer.exe /Embedding
- disabled
- @%systemroot%\system32\SearchIndexer.exe,-104

+ Windows Update
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%systemroot%\system32\wuaueng.dll,-106
70629 - Microsoft Windows AutoRuns Winlogon
-
Synopsis
Report programs that startup associates with the winlogon process.
Description
Report the startup locations associated with the winlogon process.

These values could add features to the logon process, assist in authentication, or set screen savers.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers
+ CLSID : {1b283861-754f-4022-ad47-a5eaaa618894}
- Name : Smartcard Reader Selection Provider
- Value : %SystemRoot%\system32\SmartcardCredentialProvider.dll

+ CLSID : {1ee7337f-85ac-45e2-a23c-37c753209769}
- Name : Smartcard WinRT Provider
- Value : %SystemRoot%\system32\SmartcardCredentialProvider.dll

+ CLSID : {2135f72a-90b5-4ed3-a7f1-8bb705ac276a}
- Name : PicturePasswordLogonProvider
- Value : %SystemRoot%\system32\credprovslegacy.dll

+ CLSID : {25CBB996-92ED-457e-B28C-4774084BD562}
- Name : GenericProvider
- Value : %SystemRoot%\system32\credprovs.dll

+ CLSID : {27FBDB57-B613-4AF2-9D7E-4FA7A66C21AD}
- Name : TrustedSignal Credential Provider
- Value : %systemroot%\system32\TrustedSignalCredProv.dll

+ CLSID : {3dd6bec0-8193-4ffe-ae25-e08e39ea4063}
- Name : NPProvider
- Value : %SystemRoot%\system32\credprovs.dll

+ CLSID : {48B4E58D-2791-456C-9091-D524C6C706F2}
- Name : Secondary Authentication Factor Credential Provider
- Value : C:\Windows\System32\devicengccredprov.dll

+ CLSID : {600e7adb-da3e-41a4-9225-3c0399e88c0c}
- Name : CngCredUICredentialProvider
- Value : %systemroot%\system32\cngcredui.dll

+ CLSID : {60b78e88-ead8-445c-9cfd-0b87f74ea6cd}
- Name : PasswordProvider
- Value : %SystemRoot%\system32\credprovs.dll

+ CLSID : {8FD7E19C-3BF7-489B-A72C-846AB3678C96}
- Name : Smartcard Credential Provider
- Value : %SystemRoot%\system32\SmartcardCredentialProvider.dll

+ CLSID : {94596c7e-3744-41ce-893e-bbf09122f76a}
- Name : Smartcard Pin Provider
- Value : %SystemRoot%\system32\SmartcardCredentialProvider.dll

+ CLSID : {BEC09223-B018-416D-A0AC-523971B639F5}
- Name : WinBio Credential Provider
- Value : %SystemRoot%\System32\BioCredProv.dll

+ CLSID : {C5D7540A-CD51-453B-B22B-05305BA03F07}
- Name : Cloud Experience Credential Provider
- Value : C:\Windows\System32\cxcredprov.dll

+ CLSID : {cb82ea12-9f71-446d-89e1-8d0924e1256e}
- Name : PINLogonProvider
- Value : %SystemRoot%\system32\credprovslegacy.dll

+ CLSID : {D6886603-9D2F-4EB2-B667-1971041FA96B}
- Name : NGC Credential Provider
- Value : C:\Windows\System32\ngccredprov.dll

+ CLSID : {e74e57b0-6c6d-44d5-9cda-fb2df5ed7435}
- Name : CertCredProvider
- Value : %systemroot%\system32\certCredProvider.dll

+ CLSID : {F8A0B131-5F68-486c-8040-7E8FC3C85BB6}
- Name : WLIDCredentialProvider
- Value : %SystemRoot%\system32\wlidcredprov.dll

+ CLSID : {F8A1793B-7873-4046-B2A7-1F318747F427}
- Name : FIDO Credential Provider
- Value : %systemroot%\system32\fidocredprov.dll


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Provider Filters
+ CLSID : {DDC0EED2-ADBE-40b6-A217-EDE16A79A0DE}
- Name : GenericFilter
- Value : %SystemRoot%\system32\credprovs.dll


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\PLAP Providers
+ CLSID : {5537E283-B1E7-4EF8-9C6E-7AB0AFE5056D}
- Name : RasProvider
- Value : %SystemRoot%\system32\rasplap.dll




70630 - Microsoft Windows AutoRuns Winsock Provider
-
Synopsis
Report Winsock providers extensions.
Description
A Winsock provider is a type of Layered Service Provider (LSP) that can be used to control protocols by inserting itself into the TCP/IP stack. This can commonly be used to help filter web traffic, enable QoS type services, or anything to hook network traffic controls.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries
- Name : AF_UNIX
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60100
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60101
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60102
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60200
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60201
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60202
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-100
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-101
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-102
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-103
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : MSAFD L2CAP [Bluetooth]
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : MSAFD RfComm [Bluetooth]
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : Hyper-V RAW
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : vSockets DGRAM
- PackedCatalogItem : %windir%\system32\vsocklib.dll

- Name : vSockets STREAM
- PackedCatalogItem : %windir%\system32\vsocklib.dll


+ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries
- LibararyPath : %SystemRoot%\system32\napinsp.dll
- LibararyPath : %SystemRoot%\System32\mswsock.dll
- LibararyPath : %SystemRoot%\System32\winrnr.dll
- LibararyPath : %SystemRoot%\system32\NLAapi.dll
- LibararyPath : %SystemRoot%\system32\wshbth.dll


+ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64
- Name : AF_UNIX
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60100
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60101
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60102
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60200
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60201
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60202
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-100
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-101
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-102
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-103
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : MSAFD L2CAP [Bluetooth]
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : MSAFD RfComm [Bluetooth]
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : Hyper-V RAW
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : vSockets DGRAM
- PackedCatalogItem : %windir%\system32\vsocklib.dll

- Name : vSockets STREAM
- PackedCatalogItem : %windir%\system32\vsocklib.dll


+ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64
- LibararyPath : %SystemRoot%\system32\napinsp.dll
- LibararyPath : %SystemRoot%\System32\mswsock.dll
- LibararyPath : %SystemRoot%\System32\winrnr.dll
- LibararyPath : %SystemRoot%\system32\NLAapi.dll
- LibararyPath : %SystemRoot%\system32\wshbth.dll

92371 - Microsoft Windows DNS Cache
-
Synopsis
Nessus was able to collect and report DNS cache information from the remote host.
Description
Nessus was able to collect details of the DNS cache from the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2025/12/15
Plugin Output

tcp/0

102.129.143.114.in-addr.arpa
141.100.17.172.in-addr.arpa
231.100.17.172.in-addr.arpa
ckm.synway.net
lkp_sip_dbsrv-1
lkp_sip_dbsrv-1
nexsus-dv72
nexsus-dv72
vcsa.lkpvm.com
vcsa.lkpvm.com

DNS cache information attached.
92363 - Microsoft Windows Device Logs
-
Synopsis
Nessus was able to collect available device logs from the remote host.
Description
Nessus was able to collect available device logs from the remote Windows host and add them as attachments.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

Device logs attached.
92364 - Microsoft Windows Environment Variables
-
Synopsis
Nessus was able to collect and report environment variables from the remote host.
Description
Nessus was able to collect system and active account environment variables on the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0757
Plugin Information
Published: 2016/07/19, Modified: 2022/06/24
Plugin Output

tcp/0

Global Environment Variables :
comspec : %SystemRoot%\system32\cmd.exe
processor_level : 6
username : SYSTEM
os : Windows_NT
number_of_processors : 4
temp : %SystemRoot%\TEMP
path : %SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\;C:\Program Files\OpenSSL-Win64;C:\Program Files\dotnet\;C:\Program Files (x86)\dotnet\
processor_revision : cf02
tmp : %SystemRoot%\TEMP
driverdata : C:\Windows\System32\Drivers\DriverData
pathext : .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
processor_architecture : AMD64
processor_identifier : Intel64 Family 6 Model 207 Stepping 2, GenuineIntel
psmodulepath : %ProgramFiles%\WindowsPowerShell\Modules;%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules
windir : %SystemRoot%

Active User Environment Variables
- S-1-5-21-3194671253-1068146636-4210433707-500
temp : %USERPROFILE%\AppData\Local\Temp
path : %USERPROFILE%\AppData\Local\Microsoft\WindowsApps;
tmp : %USERPROFILE%\AppData\Local\Temp
92365 - Microsoft Windows Hosts File
-
Synopsis
Nessus was able to collect the hosts file from the remote host.
Description
Nessus was able to collect the hosts file from the remote Windows host and report it as attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2020/01/27
Plugin Output

tcp/0

Windows hosts file attached.

MD5: 92d8666b38534da0e38a1c2c9e5942bb
SHA-1: a8c50ffc0d9a68e15575225a4403ac5cdddafda0
SHA-256: 37443577961cd37fe2374f5c083c0e7269015bda5a47952899f1d389e4b5de05
187318 - Microsoft Windows Installed
-
Synopsis
The remote host is running Microsoft Windows.
Description
The remote host is running Microsoft Windows.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/12/27, Modified: 2025/12/10
Plugin Output

tcp/0


OS Name : Microsoft Windows Server 2019 1809
Vendor : Microsoft
Product : Windows Server
Release : 2019 1809
Edition : Datacenter
Version : 10.0.17763.6893
Role : server
Kernel : Windows NT 10.0
Architecture : x64
CPE v2.2 : cpe:/o:microsoft:windows_server_2019:10.0.17763.6893:-:~~datacenter~~x64~
CPE v2.3 : cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.6893:-:*:*:datacenter:*:x64:*
Type : local
Method : SMB
Confidence : 100

20811 - Microsoft Windows Installed Software Enumeration (credentialed check)
-
Synopsis
It is possible to enumerate installed software.
Description
This plugin lists software potentially installed on the remote host by crawling the registry entries in :

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall HKLM\SOFTWARE\Microsoft\Updates

Note that these entries do not necessarily mean the applications are actually installed on the remote host - they may have been left behind by uninstallers, or the associated files may have been manually removed.
Solution
Remove any applications that are not compliant with your organization's acceptable use and security policies.
Risk Factor
None
References
XREF IAVT:0001-T-0501
Plugin Information
Published: 2006/01/26, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


The following software are installed on the remote host :

Windows Driver Package - Intel Net (06/19/2013 12.7.27.0) [version 06/19/2013 12.7.27.0]
Kaspersky Security Center Network Agent [version 14.2.0.26967]
Microsoft Edge [version 144.0.3719.82] [installed on 2026/01/18]
Microsoft Edge Update [version 1.3.215.9]
Npcap [version 1.79]
Microsoft Office Standard 2016 [version 16.0.4266.1001]
OpenSSL 3.4.0 (64-bit) [version 3.4.0] [installed on 2025/01/03]
WinPcap 4.1.3 [version 4.1.0.2980]
Wireshark 4.4.2 x64 [version 4.4.2]
Zoiper [version 3.9]
Kaspersky Endpoint Security for Windows [version 11.15.8.493]
Microsoft ASP.NET Core 8.0.8 Shared Framework (x64) [version 8.0.8.24369] [installed on 2025/03/25]
Microsoft ASP.NET Core Module V2 [version 18.0.24201.0] [installed on 2025/03/25]
Microsoft .NET Runtime - 5.0.17 (x86) [version 5.0.17.31213]
Microsoft .NET Host - 8.0.8 (x86) [version 64.32.18380] [installed on 2025/03/25]
Microsoft .NET Host - 8.0.8 (x64) [version 64.32.18380] [installed on 2025/03/25]
Microsoft Application Request Routing 3.0 [version 3.0.05311] [installed on 2025/07/24]
Microsoft SQL Server Reporting Services [version 15.0.9098.6826] [installed on 2025/01/23]
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.36.32532 [version 14.36.32532.0]
Microsoft .NET Host - 5.0.17 (x86) [version 40.68.31213] [installed on 2025/03/25]
VMware Tools [version 12.4.0.23259341] [installed on 2025/02/22]
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.40.33816 [version 14.40.33816] [installed on 2025/01/03]
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.40.33816 [version 14.40.33816] [installed on 2025/01/03]
Microsoft .NET Runtime - 5.0.17 (x86) [version 40.68.31213] [installed on 2025/03/25]
Microsoft .NET Runtime - 5.0.17 (x64) [version 40.68.31213] [installed on 2025/03/25]
Microsoft .NET Runtime - 8.0.8 (x86) [version 64.32.18380] [installed on 2025/03/25]
Microsoft .NET Host FX Resolver - 8.0.8 (x86) [version 64.32.18380] [installed on 2025/03/25]
Microsoft ASP.NET Core 5.0.17 Shared Framework (x86) [version 5.0.17.22215] [installed on 2025/03/25]
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.36.32532 [version 14.36.32532] [installed on 2024/06/26]
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.40.33816 [version 14.40.33816.0]
Microsoft ASP.NET Core 8.0.8 Shared Framework (x86) [version 8.0.8.24369] [installed on 2025/03/25]
Microsoft .NET Host FX Resolver - 8.0.8 (x64) [version 64.32.18380] [installed on 2025/03/25]
Microsoft ASP.NET Core 8.0.8 Hosting Bundle Options [version 8.0.8.24369] [installed on 2025/03/25]
Kaspersky Endpoint Security for Windows [version 12.3.0.493] [installed on 2024/06/27]
Microsoft .NET Host FX Resolver - 5.0.17 (x64) [version 40.68.31213] [installed on 2025/03/25]
Microsoft Office Access database engine 2007 (English) [version 12.0.4518.1031] [installed on 2024/12/21]
Microsoft Access database engine 2010 (English) [version 14.0.7015.1000] [installed on 2024/12/24]
Microsoft Excel MUI (English) 2016 [version 16.0.4266.1001] [installed on 2024/12/21]
Microsoft PowerPoint MUI (English) 2016 [version 16.0.4266.1001] [installed on 2024/12/21]
Microsoft Publisher MUI (English) 2016 [version 16.0.4266.1001] [installed on 2024/12/21]
Microsoft Outlook MUI (English) 2016 [version 16.0.4266.1001] [installed on 2024/12/21]
Microsoft Word MUI (English) 2016 [version 16.0.4266.1001] [installed on 2024/12/21]
Microsoft Office Proofing Tools 2016 - English [version 16.0.4266.1001] [installed on 2024/12/21]
Outils de vérification linguistique 2016 de Microsoft Office - Français [version 16.0.4266.1001] [installed on 2024/12/21]
Herramientas de corrección de Microsoft Office 2016: español [version 16.0.4266.1001] [installed on 2024/12/21]
Microsoft Office Proofing (English) 2016 [version 16.0.4266.1001] [installed on 2024/12/21]
Microsoft Office Shared MUI (English) 2016 [version 16.0.4266.1001] [installed on 2024/12/21]
Microsoft OneNote MUI (English) 2016 [version 16.0.4266.1001] [installed on 2024/12/21]
Microsoft Groove MUI (English) 2016 [version 16.0.4266.1001] [installed on 2024/12/21]
Microsoft Office 32-bit Components 2016 [version 16.0.4266.1001] [installed on 2024/12/21]
Microsoft Office Shared 32-bit MUI (English) 2016 [version 16.0.4266.1001] [installed on 2024/12/21]
Microsoft Office OSM MUI (English) 2016 [version 16.0.4266.1001] [installed on 2024/12/21]
Microsoft Office OSM UX MUI (English) 2016 [version 16.0.4266.1001] [installed on 2024/12/21]
Microsoft Office Shared Setup Metadata MUI (English) 2016 [version 16.0.4266.1001] [installed on 2024/12/21]
Microsoft .NET 8.0.8 - Windows Server Hosting [version 8.0.8.24369]
Microsoft System CLR Types for SQL Server 2019 CTP3.0 [version 15.0.1600.8] [installed on 2025/01/23]
Microsoft .NET Runtime - 8.0.8 (x64) [version 64.32.18380] [installed on 2025/03/25]
IIS URL Rewrite Module 2 [version 7.2.1993] [installed on 2025/07/24]
Active Directory Authentication Library for SQL Server [version 14.0.3015.40] [installed on 2025/01/23]
Microsoft ASP.NET Core 5.0.17 Hosting Bundle Options [version 5.0.17.22215] [installed on 2025/03/25]
Microsoft .NET Host FX Resolver - 5.0.17 (x86) [version 40.68.31213] [installed on 2025/03/25]
Microsoft ASP.NET Core 5.0.17 Shared Framework (x64) [version 5.0.17.22215] [installed on 2025/03/25]
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.36.32532 [version 14.36.32532] [installed on 2024/06/26]
Sentinel Runtime [version 7.91.26692.60000] [installed on 2024/12/06]
Microsoft .NET Host - 5.0.17 (x64) [version 40.68.31213] [installed on 2025/03/25]
Microsoft .NET Runtime - 5.0.17 (x64) [version 5.0.17.31213]
Microsoft .NET 5.0.17 - Windows Server Hosting [version 5.0.17.22215]
Microsoft ASP.NET Core 5.0.17 - Shared Framework (x86) [version 5.0.17.22215]
Microsoft ASP.NET Core 5.0.17 - Shared Framework (x64) [version 5.0.17.22215]

The following updates are installed :

.NET :
Microsoft .NET 5.0.17 - Windows Server Hosting (x86) [version 5.0.17.22215] [installed on 03-25-2025]
Microsoft .NET 8.0.8 - Windows Server Hosting (x86) [version 8.0.8.24369] [installed on 03-25-2025]
Microsoft ASP.NET Core 5.0.17 - Shared Framework (x64) [version 5.0.17.22215] [installed on 03-25-2025]
Microsoft ASP.NET Core 5.0.17 - Shared Framework (x86) [version 5.0.17.22215] [installed on 03-25-2025]

92366 - Microsoft Windows Last Boot Time
-
Synopsis
Nessus was able to collect the remote host's last boot time in a human readable format.
Description
Nessus was able to collect and report the remote host's last boot time as an ISO 8601 timestamp.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/07/09
Plugin Output

tcp/0

Last reboot : 2026-01-21T09:23:00+05:30 (20260121092300.500000+330)

161502 - Microsoft Windows Logged On Users
-
Synopsis
Nessus was able to determine the logged on users from the registry
Description
Using the HKU registry, Nessus was able to enumerate the SIDs of logged on users
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2022/05/25, Modified: 2025/10/01
Plugin Output

tcp/445/cifs

Logged on users :
- S-1-5-21-3194671253-1068146636-4210433707-500
Domain : LKP_SIP_APPSRV-
Username : Production
63080 - Microsoft Windows Mounted Devices
-
Synopsis
It is possible to get a list of mounted devices that may have been connected to the remote system in the past.
Description
By connecting to the remote host with the supplied credentials, this plugin enumerates mounted devices that have been connected to the remote host in the past.
See Also
Solution
Make sure that the mounted drives agree with your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2012/11/28, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Name : \dosdevices\e:
Data : \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&11bd2db8&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Raw data : 5c003f003f005c00530043005300490023004300640052006f006d002600560065006e005f004e004500430056004d005700610072002600500072006f0064005f0056004d0077006100720065005f0053004100540041005f0043004400300030002300350026003100310062006400320064006200380026003000260030003000300030003000300023007b00350033006600350036003300300064002d0062003600620066002d0031003100640030002d0039003400660032002d003000300061003000630039003100650066006200380062007d00

Name : \dosdevices\f:
Data : \??\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Raw data : 5c003f003f005c00530043005300490023004300640052006f006d002600560065006e005f004d007300660074002600500072006f0064005f005600690072007400750061006c005f004400560044002d0052004f004d002300320026003100660034006100640066006600650026003000260030003000300030003000310023007b00350033006600350036003300300064002d0062003600620066002d0031003100640030002d0039003400660032002d003000300061003000630039003100650066006200380062007d00

Name : \??\volume{446d365c-b882-11ef-9738-005056a9a212}
Data : \??\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Raw data : 5c003f003f005c00530043005300490023004300640052006f006d002600560065006e005f004d007300660074002600500072006f0064005f005600690072007400750061006c005f004400560044002d0052004f004d002300320026003100660034006100640066006600650026003000260030003000300030003000310023007b00350033006600350036003300300064002d0062003600620066002d0031003100640030002d0039003400660032002d003000300061003000630039003100650066006200380062007d00

Name : \dosdevices\d:
Data : DMIO:ID:cGAW~N
Raw data : 444d494f3a49443a86a584a26347904190b1f2a7577e4eee

Name : \dosdevices\c:
Data : DMIO:ID:pp>fWC
Raw data : 444d494f3a49443a70fe703e02665743be8de7c4e011d5ed

Name : \??\volume{45b2c0d9-337d-11ef-972b-806e6f6e6963}
Data : \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&11bd2db8&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Raw data : 5c003f003f005c00530043005300490023004300640052006f006d002600560065006e005f004e004500430056004d005700610072002600500072006f0064005f0056004d0077006100720065005f0053004100540041005f0043004400300030002300350026003100310062006400320064006200380026003000260030003000300030003000300023007b00350033006600350036003300300064002d0062003600620066002d0031003100640030002d0039003400660032002d003000300061003000630039003100650066006200380062007d00
42410 - Microsoft Windows NTLMSSP Authentication Request Remote Network Name Disclosure
-
Synopsis
It is possible to obtain the network name of the remote host.
Description
The remote host listens on tcp port 445 and replies to SMB requests.

By sending an NTLMSSP authentication request it is possible to obtain the name of the remote system and the name of its domain.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/11/06, Modified: 2019/11/22
Plugin Output

tcp/445/cifs

The following 2 NetBIOS names have been gathered :

LKP_SIP_APPSRV- = Computer name
LKP_SIP_APPSRV- = Workgroup / Domain name

92372 - Microsoft Windows NetBIOS over TCP/IP Info
-
Synopsis
Nessus was able to collect and report NBT information from the remote host.
Description
Nessus was able to collect details for NetBIOS over TCP/IP from the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2025/12/15
Plugin Output

tcp/0

NBT information attached.
First 10 lines of all CSVs:
nbtstat_local.csv:
Interface,Name,Suffix,Type,Status,MAC
10.54.158.102,LKP_SIP_APPSRV-,<20>,UNIQUE,Registered,00:50:56:88:84:22
10.54.158.102,LKP_SIP_APPSRV-,<00>,UNIQUE,Registered,00:50:56:88:84:22
10.54.158.102,WORKGROUP,<00>,GROUP,Registered,00:50:56:88:84:22

103871 - Microsoft Windows Network Adapters
-
Synopsis
Identifies the network adapters installed on the remote host.
Description
Using the supplied credentials, this plugin enumerates and reports the installed network adapters on the remote Windows host.
Solution
Make sure that all of the installed network adapters agrees with your organization's acceptable use and security policies.
Risk Factor
None
References
XREF IAVT:0001-T-0758
Plugin Information
Published: 2017/10/17, Modified: 2022/02/01
Plugin Output

tcp/445/cifs

Network Adapter Driver Description : vmxnet3 Ethernet Adapter
Network Adapter Driver Version : 1.9.14.0

Network Adapter Driver Description : vmxnet3 Ethernet Adapter
Network Adapter Driver Version : 1.9.14.0

Network Adapter Driver Description : vmxnet3 Ethernet Adapter
Network Adapter Driver Version : 1.9.20.0

Network Adapter Driver Description : vmxnet3 Ethernet Adapter
Network Adapter Driver Version : 1.9.20.0
65791 - Microsoft Windows Portable Devices
-
Synopsis
It is possible to get a list of portable devices that may have been connected to the remote system in the past.
Description
By connecting to the remote host with the supplied credentials, this plugin enumerates portable devices that have been connected to the remote host in the past.
See Also
Solution
Make sure that use of the portable devices agrees with your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2013/04/03, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Friendly name : New Volume
Device : SWD#WPDBUSENUM#{45B2C0C7-337D-11EF-972B-806E6F6E6963}#0000000001000000

92367 - Microsoft Windows PowerShell Execution Policy
-
Synopsis
Nessus was able to collect and report the PowerShell execution policy for the remote host.
Description
Nessus was able to collect and report the PowerShell execution policy for the remote Windows host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2020/06/12
Plugin Output

tcp/0

HKLM\SOFTWARE\Microsoft\PowerShell\1\ShellIds\Microsoft.PowerShell\ExecutionPolicy : RemoteSigned
HKLM\SOFTWARE\Wow6432Node\Microsoft\PowerShell\1\ShellIds\Microsoft.PowerShell\ExecutionPolicy : RemoteSigned

151440 - Microsoft Windows Print Spooler Service Enabled
-
Synopsis
The Microsoft Windows Print Spooler service on the remote host is enabled.
Description
The Microsoft Windows Print Spooler service (spoolsv.exe) on the remote host is enabled.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2021/07/07, Modified: 2021/07/07
Plugin Output

tcp/445/cifs

The Microsoft Windows Print Spooler service on the remote host is enabled.

70329 - Microsoft Windows Process Information
-
Synopsis
Use WMI to obtain running process information.
Description
Report details on the running processes on the machine.

This plugin is informative only and could be used for forensic investigation, malware detection, and to confirm that your system processes conform to your system policies.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/08, Modified: 2025/12/15
Plugin Output

tcp/0

Process Overview :
SID: Process (PID)
0 : System Idle Process (0)
0 : |- System (4)
0 : |- smss.exe (436)
0 : Registry (104)
0 : csrss.exe (540)
2 : winlogon.exe (5888)
2 : |- fontdrvhost.exe (6332)
2 : |- dwm.exe (7324)
2 : csrss.exe (5996)
0 : wininit.exe (644)
0 : |- services.exe (788)
0 : |- svchost.exe (1064)
0 : |- svchost.exe (1068)
2 : |- rdpclip.exe (7292)
0 : |- svchost.exe (1100)
0 : |- svchost.exe (11036)
0 : |- svchost.exe (1144)
0 : |- svchost.exe (1160)
0 : |- svchost.exe (1168)
0 : |- svchost.exe (1176)
0 : |- svchost.exe (1356)
0 : |- svchost.exe (1436)
0 : |- svchost.exe (1468)
0 : |- svchost.exe (1532)
0 : |- svchost.exe (1556)
0 : |- svchost.exe (1564)
0 : |- svchost.exe (1572)
0 : |- svchost.exe (1580)
0 : |- WUDFHost.exe (1616)
0 : |- svchost.exe (1724)
0 : |- svchost.exe (1788)
0 : |- svchost.exe (1804)
2 : |- taskhostw.exe (7440)
0 : |- svchost.exe (1820)
0 : |- svchost.exe (1832)
0 : |- svchost.exe (1928)
0 : |- svchost.exe (1936)
0 : |- svchost.exe (2132)
0 : |- svchost.exe (2232)
0 : |- svchost.exe (2244)
0 : |- svchost.exe (2328)
0 : |- SMSvcHost.exe (2400)
0 : |- svchost.exe (2504)
0 : |- svchost.exe (2536)
2 : |- sihost.exe (7332)
0 : |- svchost.exe (2652)
0 : |- svchost.exe (2660)
0 : |- Nexsus.MaxDial.UserStatusValidator.exe (2672)
0 : |- spoolsv.exe (2808)
0 : |- svchost.exe (2888)
0 : |- svchost.exe (2896)
0 : |- svchost.exe (2908)
0 : |- Nexsus.CallBalancel.VoiceLogService.exe (2920)
0 : |- hasplms.exe (2932)
0 : |- hasplmv.exe (4812)
0 : |- inetinfo.exe (2944)
0 : |- svchost.exe (2952)
0 : |- avp.exe (2960)
2 : |- avpui.exe (6328)
0 : |- svchost.exe (3028)
0 : |- w3wp.exe (11300)
0 : |- w3wp.exe (8912)
0 : |- w3wp.exe (9364)
0 : |- conhost.exe (5684)
0 : |- NexsusEmailService.exe (3076)
0 : |- svchost.exe (3084)
0 : |- HMPCodec.exe (3108)
0 : |- record_slaver.exe (3120)
0 : |- svchost.exe (3140)
0 : |- vmtoolsd.exe (3168)
0 : |- svchost.exe (3180)
0 : |- mqsvc.exe (3188)
0 : |- VGAuthService.exe (3196)
0 : |- vm3dservice.exe (3204)
1 : |- vm3dservice.exe (3624)
0 : |- svchost.exe (3232)
0 : |- svchost.exe (3240)
0 : |- svchost.exe (3260)
0 : |- svchost.exe (3292)
0 : |- svchost.exe (3312)
0 : |- avpsus.exe (3488)
0 : |- svchost.exe (3504)
0 : |- svchost.exe (3676)
0 : |- svchost.exe (4380)
0 : |- RSHostingService.exe (4420)
0 : |- svchost.exe (4508)
0 : |- SMSvcHost.exe (4904)
0 : |- dllhost.exe (4928)
0 : |- klnagent.exe (5016)
0 : |- vapm.exe (8884)
0 : |- svchost.exe (508)
0 : |- svchost.exe (5788)
0 : |- svchost.exe (5848)
0 : |- svchost.exe (636)
0 : |- msdtc.exe (6700)
0 : |- svchost.exe (7092)
2 : |- svchost.exe (7340)
2 : |- svchost.exe (7368)
0 : |- svchost.exe (7436)
0 : |- svchost.exe (7552)
0 : |- svchost.exe (7800)
2 : |- ctfmon.exe (7856)
0 : |- svchost.exe (7908)
0 : |- svchost.exe (8232)
0 : |- svchost.exe (8464)
2 : |- MusNotifyIcon.exe (2984)
0 : |- svchost.exe (8720)
0 : |- svchost.exe (932)
0 : |- svchost.exe (952)
0 : |- WmiPrvSE.exe (11780)
2 : |- dllhost.exe (1216)
0 : |- unsecapp.exe (1736)
0 : |- WmiPrvSE.exe (1964)
0 : |- WmiPrvSE.exe (5152)
0 : |- WmiPrvSE.exe (5952)
2 : |- ApplicationFrameHost.exe (6872)
2 : |- ShellExperienceHost.exe (7524)
2 : |- smartscreen.exe (8188)
2 : |- SearchUI.exe (8272)
2 : |- RuntimeBroker.exe (8348)
2 : |- RuntimeBroker.exe (8436)
2 : |- RuntimeBroker.exe (9192)
2 : |- svchost.exe (9800)
0 : |- lsass.exe (796)
0 : |- fontdrvhost.exe (976)
1 : csrss.exe (652)
1 : winlogon.exe (716)
1 : |- LogonUI.exe (1256)
1 : |- dwm.exe (1264)
1 : |- fontdrvhost.exe (984)
2 : explorer.exe (8024)
2 : |- TimeStamping.exe (10976)
2 : |- notepad.exe (11256)
2 : |- notepad.exe (11832)
2 : |- msinfo32.exe (3800)
2 : |- Nexsus.MaxDial.Engine.exe (4752)
2 : |- watchdogsyn.exe (5540)
2 : |- InetMgr.exe (4940)
2 : |- Taskmgr.exe (5248)
2 : |- mmc.exe (6608)
2 : |- mstsc.exe (676)
2 : |- cmd.exe (8656)
2 : |- conhost.exe (8828)
2 : |- regedit.exe (9088)

Process_Information_.csv : information about the running process.
70331 - Microsoft Windows Process Module Information
-
Synopsis
Use WMI to obtain running process module information.
Description
Report details on the running processes modules on the machine.

This plugin is informative only and could be used for forensic investigation, malware detection, and to that confirm your system processes conform to your system policies.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/08, Modified: 2025/12/15
Plugin Output

tcp/0

Process_Modules_.csv : lists the loaded modules for each process.

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/80/www


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/123


The Win32 process 'svchost.exe' is listening on this port (pid 3232).

This process 'svchost.exe' (pid 3232) is hosting the following Windows services :
W32Time (@%SystemRoot%\system32\w32time.dll,-200)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/135/epmap


The Win32 process 'svchost.exe' is listening on this port (pid 508).

This process 'svchost.exe' (pid 508) is hosting the following Windows services :
RpcEptMapper (@%windir%\system32\RpcEpMap.dll,-1001)
RpcSs (@combase.dll,-5010)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/443


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/500


The Win32 process 'svchost.exe' is listening on this port (pid 2660).

This process 'svchost.exe' (pid 2660) is hosting the following Windows services :
IKEEXT (@%SystemRoot%\system32\ikeext.dll,-501)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/1801/msmq


The Win32 process 'mqsvc.exe' is listening on this port (pid 3188).

This process 'mqsvc.exe' (pid 3188) is hosting the following Windows services :
MSMQ (@mqutil.dll,-6102)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/1947/www


The Win32 process 'hasplms.exe' is listening on this port (pid 2932).

This process 'hasplms.exe' (pid 2932) is hosting the following Windows services :
hasplms (Sentinel LDK License Manager)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/1947


The Win32 process 'hasplms.exe' is listening on this port (pid 2932).

This process 'hasplms.exe' (pid 2932) is hosting the following Windows services :
hasplms (Sentinel LDK License Manager)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/2103/dce-rpc


The Win32 process 'mqsvc.exe' is listening on this port (pid 3188).

This process 'mqsvc.exe' (pid 3188) is hosting the following Windows services :
MSMQ (@mqutil.dll,-6102)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/2105/dce-rpc


The Win32 process 'mqsvc.exe' is listening on this port (pid 3188).

This process 'mqsvc.exe' (pid 3188) is hosting the following Windows services :
MSMQ (@mqutil.dll,-6102)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/2107/dce-rpc


The Win32 process 'mqsvc.exe' is listening on this port (pid 3188).

This process 'mqsvc.exe' (pid 3188) is hosting the following Windows services :
MSMQ (@mqutil.dll,-6102)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/3389/msrdp


The Win32 process 'svchost.exe' is listening on this port (pid 1068).

This process 'svchost.exe' (pid 1068) is hosting the following Windows services :
TermService (@%SystemRoot%\System32\termsrv.dll,-268)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/3389


The Win32 process 'svchost.exe' is listening on this port (pid 1068).

This process 'svchost.exe' (pid 1068) is hosting the following Windows services :
TermService (@%SystemRoot%\System32\termsrv.dll,-268)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/3702


The Win32 process 'svchost.exe' is listening on this port (pid 5848).

This process 'svchost.exe' (pid 5848) is hosting the following Windows services :
FDResPub (@%systemroot%\system32\fdrespub.dll,-100)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/4500


The Win32 process 'svchost.exe' is listening on this port (pid 2660).

This process 'svchost.exe' (pid 2660) is hosting the following Windows services :
IKEEXT (@%SystemRoot%\system32\ikeext.dll,-501)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/5061


The Win32 process 'Nexsus.MaxDial.Engine.exe' is listening on this port (pid 4752).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/5353


The Win32 process 'svchost.exe' is listening on this port (pid 1936).

This process 'svchost.exe' (pid 1936) is hosting the following Windows services :
Dnscache (@%SystemRoot%\System32\dnsapi.dll,-101)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/5355/llmnr


The Win32 process 'svchost.exe' is listening on this port (pid 1936).

This process 'svchost.exe' (pid 1936) is hosting the following Windows services :
Dnscache (@%SystemRoot%\System32\dnsapi.dll,-101)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/5357/www


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/5985/www


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/7001/www


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/8001/www


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/8002/www


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/9505/www


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/15000


The Win32 process 'klnagent.exe' is listening on this port (pid 5016).

This process 'klnagent.exe' (pid 5016) is hosting the following Windows services :
klnagent (Kaspersky Security Center Network Agent)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/47001/www


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49664/dce-rpc


The Win32 process 'wininit.exe' is listening on this port (pid 644).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49665/dce-rpc


The Win32 process 'svchost.exe' is listening on this port (pid 1176).

This process 'svchost.exe' (pid 1176) is hosting the following Windows services :
EventLog (@%SystemRoot%\system32\wevtsvc.dll,-200)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49666/dce-rpc


The Win32 process 'svchost.exe' is listening on this port (pid 1804).

This process 'svchost.exe' (pid 1804) is hosting the following Windows services :
Schedule (@%SystemRoot%\system32\schedsvc.dll,-100)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49667/dce-rpc


The Win32 process 'svchost.exe' is listening on this port (pid 2504).

This process 'svchost.exe' (pid 2504) is hosting the following Windows services :
SessionEnv (@%SystemRoot%\System32\SessEnv.dll,-1026)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49668/dce-rpc


The Win32 process 'spoolsv.exe' is listening on this port (pid 2808).

This process 'spoolsv.exe' (pid 2808) is hosting the following Windows services :
Spooler (@%systemroot%\system32\spoolsv.exe,-1)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49669/dce-rpc


The Win32 process 'mqsvc.exe' is listening on this port (pid 3188).

This process 'mqsvc.exe' (pid 3188) is hosting the following Windows services :
MSMQ (@mqutil.dll,-6102)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49670/dce-rpc


The Win32 process 'svchost.exe' is listening on this port (pid 2652).

This process 'svchost.exe' (pid 2652) is hosting the following Windows services :
PolicyAgent (@%SystemRoot%\System32\polstore.dll,-5010)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49678/dce-rpc


The Win32 process 'services.exe' is listening on this port (pid 788).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49744/dce-rpc


The Win32 process 'lsass.exe' is listening on this port (pid 796).

This process 'lsass.exe' (pid 796) is hosting the following Windows services :
KeyIso (@keyiso.dll,-100)
SamSs (@%SystemRoot%\system32\samsrv.dll,-1)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/51068


The Win32 process 'svchost.exe' is listening on this port (pid 2952).

This process 'svchost.exe' (pid 2952) is hosting the following Windows services :
Winmgmt (@%Systemroot%\system32\wbem\wmisvc.dll,-205)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/52697


The Win32 process 'svchost.exe' is listening on this port (pid 5848).

This process 'svchost.exe' (pid 5848) is hosting the following Windows services :
FDResPub (@%systemroot%\system32\fdrespub.dll,-100)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/53616


The Win32 process 'mstsc.exe' is listening on this port (pid 676).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/59535


The Win32 process 'hasplms.exe' is listening on this port (pid 2932).

This process 'hasplms.exe' (pid 2932) is hosting the following Windows services :
hasplms (Sentinel LDK License Manager)

126527 - Microsoft Windows SAM user enumeration
-
Synopsis
Nessus was able to enumerate domain users from the local SAM.
Description
Using the domain security identifier (SID), Nessus was able to enumerate the domain users on the remote Windows system using the Security Accounts Manager.

Note: Unable to obtain SMB SAMR user data during Agent scans.
Rendering User data obtained by plugin 171956
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2019/07/08, Modified: 2025/06/04
Plugin Output

tcp/0

- DefaultAccount (id S-1-5-21-3194671253-1068146636-503, A user account managed by the system.)
- Guest (id S-1-5-21-3194671253-1068146636-501, Built-in account for guest access to the computer/domain, Guest account)
- LKPAdmin (id S-1-5-21-3194671253-1068146636-1000, LKPAdmin, LKP-IT)
- Production (id S-1-5-21-3194671253-1068146636-500, Administrator account, Built-in account for administering the computer/domain)
- tidua (id S-1-5-21-3194671253-1068146636-1003, tidua)
- WDAGUtilityAccount (id S-1-5-21-3194671253-1068146636-504, A user account managed and used by the system for Windows Defender Application Guard scenarios.)

17651 - Microsoft Windows SMB : Obtains the Password Policy
-
Synopsis
It is possible to retrieve the remote host's password policy using the supplied credentials.
Description
Using the supplied credentials it was possible to extract the password policy for the remote Windows host. The password policy must conform to the Informational System Policy.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2005/03/30, Modified: 2015/01/12
Plugin Output

tcp/445/cifs

The following password policy is defined on the remote host:

Minimum password len: 0
Password history len: 0
Maximum password age (d): 42
Password must meet complexity requirements: Enabled
Minimum password age (d): 0
Forced logoff time (s): Not set
Locked account time (s): 1800
Time between failed logon (s): 1800
Number of invalid logon before locked out (s): 0
38689 - Microsoft Windows SMB Last Logged On User Disclosure
-
Synopsis
Nessus was able to identify the last logged on user on the remote host.
Description
By connecting to the remote host with the supplied credentials, Nessus was able to identify the username associated with the last successful logon.

Microsoft documentation notes that interactive console logons change the DefaultUserName registry entry to be the last logged-on user.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/05/05, Modified: 2019/09/02
Plugin Output

tcp/445/cifs


Last Successful logon : .\Production
10394 - Microsoft Windows SMB Log In Possible
-
Synopsis
It was possible to log into the remote host.
Description
The remote host is running a Microsoft Windows operating system or Samba, a CIFS/SMB server for Unix. It was possible to log into it using one of the following accounts :

- Guest account
- Supplied credentials
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2000/05/09, Modified: 2025/07/21
Plugin Output

tcp/445/cifs

- The SMB tests will be done as tidua/******
10859 - Microsoft Windows SMB LsaQueryInformationPolicy Function SID Enumeration
-
Synopsis
It is possible to obtain the host SID for the remote host.
Description
By emulating the call to LsaQueryInformationPolicy(), it was possible to obtain the host SID (Security Identifier).

The host SID can then be used to get the list of local users.
See Also
Solution
You can prevent anonymous lookups of the host SID by setting the 'RestrictAnonymous' registry setting to an appropriate value.

Refer to the 'See also' section for guidance.
Risk Factor
None
Plugin Information
Published: 2002/02/13, Modified: 2024/01/31
Plugin Output

tcp/445/cifs


The remote host SID value is : S-1-5-21-3194671253-1068146636-4210433707

The value of 'RestrictAnonymous' setting is : 0
10785 - Microsoft Windows SMB NativeLanManager Remote System Information Disclosure
-
Synopsis
It was possible to obtain information about the remote operating system.
Description
Nessus was able to obtain the remote operating system name and version (Windows and/or Samba) by sending an authentication request to port 139 or 445. Note that this plugin requires SMB to be enabled on the host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/10/17, Modified: 2021/09/20
Plugin Output

tcp/445/cifs

Nessus was able to obtain the following information about the host, by
parsing the SMB2 Protocol's NTLM SSP message:

Target Name: LKP_SIP_APPSRV-
NetBIOS Domain Name: LKP_SIP_APPSRV-
NetBIOS Computer Name: LKP_SIP_APPSRV-
DNS Domain Name: LKP_SIP_AppSrv-140
DNS Computer Name: LKP_SIP_AppSrv-140
DNS Tree Name: unknown
Product Version: 10.0.17763
48942 - Microsoft Windows SMB Registry : OS Version and Processor Architecture
-
Synopsis
It was possible to determine the processor architecture, build lab strings, and Windows OS version installed on the remote system.
Description
Nessus was able to determine the processor architecture, build lab strings, and the Windows OS version installed on the remote system by connecting to the remote registry with the supplied credentials.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/08/31, Modified: 2022/02/01
Plugin Output

tcp/445/cifs

Operating system version = 10.17763
Architecture = x64
Build lab extended = 17763.1.amd64fre.rs5_release.180914-1434
11457 - Microsoft Windows SMB Registry : Winlogon Cached Password Weakness
-
Synopsis
User credentials are stored in memory.
Description
The registry key 'HKLM\Software\Microsoft\WindowsNT\CurrentVersion\ Winlogon\CachedLogonsCount' is not 0. Using a value greater than 0 for the CachedLogonsCount key indicates that the remote Windows host locally caches the passwords of the users when they login, in order to continue to allow the users to login in the case of the failure of the primary domain controller (PDC).

Cached logon credentials could be accessed by an attacker and subjected to brute force attacks.
See Also
Solution
Consult Microsoft documentation and best practices.
Risk Factor
None
Plugin Information
Published: 2003/03/24, Modified: 2018/06/05
Plugin Output

tcp/445/cifs


Max cached logons : 10
10400 - Microsoft Windows SMB Registry Remotely Accessible
-
Synopsis
Access the remote Windows Registry.
Description
It was possible to access the remote Windows Registry using the login / password combination used for the Windows local checks (SMB tests).
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2000/05/09, Modified: 2025/12/16
Plugin Output

tcp/445/cifs

44401 - Microsoft Windows SMB Service Config Enumeration
-
Synopsis
It was possible to enumerate configuration parameters of remote services.
Description
Nessus was able to obtain, via the SMB protocol, the launch parameters of each active service on the remote host (executable path, logon type, etc.).
Solution
Ensure that each service is configured properly.
Risk Factor
None
References
XREF IAVT:0001-T-0752
Plugin Information
Published: 2010/02/05, Modified: 2022/05/16
Plugin Output

tcp/445/cifs


The following services are set to start automatically :

AVP.KES.21.15 startup parameters :
Display name : Kaspersky Endpoint Security Service (KES.21.15)
Service name : AVP.KES.21.15
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avp.exe" -r

AppHostSvc startup parameters :
Display name : Application Host Helper Service
Service name : AppHostSvc
Log on as : localSystem
Executable path : C:\Windows\system32\svchost.exe -k apphost

BFE startup parameters :
Display name : Base Filtering Engine
Service name : BFE
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p
Dependencies : RpcSs/

BITS startup parameters :
Display name : Background Intelligent Transfer Service
Service name : BITS
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/

BrokerInfrastructure startup parameters :
Display name : Background Tasks Infrastructure Service
Service name : BrokerInfrastructure
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k DcomLaunch -p
Dependencies : RpcEptMapper/DcomLaunch/RpcSs/

CDPSvc startup parameters :
Display name : Connected Devices Platform Service
Service name : CDPSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p
Dependencies : ncbservice/RpcSS/Tcpip/

CDPUserSvc_7fbee startup parameters :
Display name : Connected Devices Platform User Service_7fbee
Service name : CDPUserSvc_7fbee
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

CallBalanceClopsVoiceLogService_LKP startup parameters :
Display name : CallBalanceClopsVoiceLogService_LKP
Service name : CallBalanceClopsVoiceLogService_LKP
Log on as : LocalSystem
Executable path : "D:\Nexsus\Nexsus_Patch\Nexsus.MaxDial.VoiceLogService_Web_LKP\Nexsus.CallBalancel.VoiceLogService.exe"

CoreMessagingRegistrar startup parameters :
Display name : CoreMessaging
Service name : CoreMessagingRegistrar
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork -p
Dependencies : rpcss/

CryptSvc startup parameters :
Display name : Cryptographic Services
Service name : CryptSvc
Log on as : NT Authority\NetworkService
Executable path : C:\Windows\system32\svchost.exe -k NetworkService -p
Dependencies : RpcSs/

DPS startup parameters :
Display name : Diagnostic Policy Service
Service name : DPS
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork -p

DcomLaunch startup parameters :
Display name : DCOM Server Process Launcher
Service name : DcomLaunch
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k DcomLaunch -p

Dhcp startup parameters :
Display name : DHCP Client
Service name : Dhcp
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : NSI/Afd/

DiagTrack startup parameters :
Display name : Connected User Experiences and Telemetry
Service name : DiagTrack
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k utcsvc -p
Dependencies : RpcSs/

Dnscache startup parameters :
Display name : DNS Client
Service name : Dnscache
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\system32\svchost.exe -k NetworkService -p
Dependencies : nsi/

EventLog startup parameters :
Display name : Windows Event Log
Service name : EventLog
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p

EventSystem startup parameters :
Display name : COM+ Event System
Service name : EventSystem
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p
Dependencies : rpcss/

FontCache startup parameters :
Display name : Windows Font Cache Service
Service name : FontCache
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p

IISADMIN startup parameters :
Display name : IIS Admin Service
Service name : IISADMIN
Log on as : localSystem
Executable path : C:\Windows\system32\inetsrv\inetinfo.exe
Dependencies : RPCSS/SamSS/HTTP/

IKEEXT startup parameters :
Display name : IKE and AuthIP IPsec Keying Modules
Service name : IKEEXT
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : BFE/nsi/

LSM startup parameters :
Display name : Local Session Manager
Service name : LSM
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k DcomLaunch -p
Dependencies : RpcEptMapper/DcomLaunch/RpcSs/

LanmanServer startup parameters :
Display name : Server
Service name : LanmanServer
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k smbsvcs
Dependencies : SamSS/Srv2/

LanmanWorkstation startup parameters :
Display name : Workstation
Service name : LanmanWorkstation
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k NetworkService -p
Dependencies : Bowser/MRxSmb20/NSI/

MSDTC startup parameters :
Display name : Distributed Transaction Coordinator
Service name : MSDTC
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\System32\msdtc.exe
Dependencies : RPCSS/SamSS/

MSMQ startup parameters :
Display name : Message Queuing
Service name : MSMQ
Log on as : NT Authority\NetworkService
Executable path : C:\Windows\system32\mqsvc.exe
Dependencies : mqac/rpcss/eventlog/

NetMsmqActivator startup parameters :
Display name : Net.Msmq Listener Adapter
Service name : NetMsmqActivator
Log on as : NT AUTHORITY\NetworkService
Executable path : "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe" -NetMsmqActivator
Dependencies : was/msmq/

NetPipeActivator startup parameters :
Display name : Net.Pipe Listener Adapter
Service name : NetPipeActivator
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
Dependencies : was/

NetTcpActivator startup parameters :
Display name : Net.Tcp Listener Adapter
Service name : NetTcpActivator
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
Dependencies : was/NetTcpPortSharing/

Nexsus.UserStatusValidatorWeb startup parameters :
Display name : Nexsus.UserStatusValidatorWeb
Service name : Nexsus.UserStatusValidatorWeb
Log on as : NT AUTHORITY\LocalService
Executable path : "D:\Nexsus\Nexsus_Services\Nexsus.MaxDial.UserStatusValidator_Web\Nexsus.MaxDial.UserStatusValidator.exe"

NexsusEmailService startup parameters :
Display name : NexsusEmailService
Service name : NexsusEmailService
Log on as : LocalSystem
Executable path : "D:\Nexsus\Nexsus_Patch\Nexsus.MaxDial.EmailService\NexsusEmailService.exe"

NlaSvc startup parameters :
Display name : Network Location Awareness
Service name : NlaSvc
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k NetworkService -p
Dependencies : NSI/RpcSs/TcpIp/Dhcp/Eventlog/

Power startup parameters :
Display name : Power
Service name : Power
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k DcomLaunch -p

ProfSvc startup parameters :
Display name : User Profile Service
Service name : ProfSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/

RasMan startup parameters :
Display name : Remote Access Connection Manager
Service name : RasMan
Log on as : localSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs
Dependencies : SstpSvc/DnsCache/

RpcEptMapper startup parameters :
Display name : RPC Endpoint Mapper
Service name : RpcEptMapper
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\system32\svchost.exe -k RPCSS -p

RpcSs startup parameters :
Display name : Remote Procedure Call (RPC)
Service name : RpcSs
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\system32\svchost.exe -k rpcss -p
Dependencies : RpcEptMapper/DcomLaunch/

SENS startup parameters :
Display name : System Event Notification Service
Service name : SENS
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : EventSystem/

SQLServerReportingServices startup parameters :
Display name : SQL Server Reporting Services
Service name : SQLServerReportingServices
Log on as : NT SERVICE\SQLServerReportingServices
Executable path : "C:\Program Files\Microsoft SQL Server Reporting Services\SSRS\RSHostingService\RSHostingService.exe"

SamSs startup parameters :
Display name : Security Accounts Manager
Service name : SamSs
Log on as : LocalSystem
Executable path : C:\Windows\system32\lsass.exe
Dependencies : RPCSS/

Schedule startup parameters :
Display name : Task Scheduler
Service name : Schedule
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : RPCSS/SystemEventsBroker/

ShellHWDetection startup parameters :
Display name : Shell Hardware Detection
Service name : ShellHWDetection
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/

Spooler startup parameters :
Display name : Print Spooler
Service name : Spooler
Log on as : LocalSystem
Executable path : C:\Windows\System32\spoolsv.exe
Dependencies : RPCSS/http/

SynHMPCodec startup parameters :
Display name : SynHMPCodec
Service name : SynHMPCodec
Log on as : LocalSystem
Executable path : C:\ShCti\HMPCodec.exe
Dependencies : Tcpip/

SynIPR Record Slaver startup parameters :
Display name : SynIPR Record Slaver
Service name : SynIPR Record Slaver
Log on as : LocalSystem
Executable path : C:\ShCti\record_slaver.exe
Dependencies : Tcpip/

SysMain startup parameters :
Display name : SysMain
Service name : SysMain
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : rpcss/

SystemEventsBroker startup parameters :
Display name : System Events Broker
Service name : SystemEventsBroker
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k DcomLaunch -p
Dependencies : RpcEptMapper/RpcSs/

Themes startup parameters :
Display name : Themes
Service name : Themes
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p

TrkWks startup parameters :
Display name : Distributed Link Tracking Client
Service name : TrkWks
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/

UALSVC startup parameters :
Display name : User Access Logging Service
Service name : UALSVC
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : WinMgmt/

UserManager startup parameters :
Display name : User Manager
Service name : UserManager
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/ProfSvc/

UsoSvc startup parameters :
Display name : Update Orchestrator Service
Service name : UsoSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

VGAuthService startup parameters :
Display name : VMware Alias Manager and Ticket Service
Service name : VGAuthService
Log on as : LocalSystem
Executable path : "C:\Program Files\VMware\VMware Tools\VMware VGAuth\VGAuthService.exe"

VMTools startup parameters :
Display name : VMware Tools
Service name : VMTools
Log on as : LocalSystem
Executable path : "C:\Program Files\VMware\VMware Tools\vmtoolsd.exe"

W32Time startup parameters :
Display name : Windows Time
Service name : W32Time
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService

W3SVC startup parameters :
Display name : World Wide Web Publishing Service
Service name : W3SVC
Log on as : localSystem
Executable path : C:\Windows\system32\svchost.exe -k iissvcs
Dependencies : WAS/HTTP/

Wcmsvc startup parameters :
Display name : Windows Connection Manager
Service name : Wcmsvc
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : RpcSs/NSI/

WinRM startup parameters :
Display name : Windows Remote Management (WS-Management)
Service name : WinRM
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k NetworkService -p
Dependencies : RPCSS/HTTP/

Winmgmt startup parameters :
Display name : Windows Management Instrumentation
Service name : Winmgmt
Log on as : localSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : RPCSS/

WpnService startup parameters :
Display name : Windows Push Notifications System Service
Service name : WpnService
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

WpnUserService_7fbee startup parameters :
Display name : Windows Push Notifications User Service_7fbee
Service name : WpnUserService_7fbee
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

avpsus.KES.21.15 startup parameters :
Display name : Kaspersky Seamless Update Service (KES.21.15)
Service name : avpsus.KES.21.15
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avpsus.exe"

edgeupdate startup parameters :
Display name : Microsoft Edge Update Service (edgeupdate)
Service name : edgeupdate
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svc
Dependencies : RPCSS/

gpsvc startup parameters :
Display name : Group Policy Client
Service name : gpsvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : RPCSS/Mup/

hasplms startup parameters :
Display name : Sentinel LDK License Manager
Service name : hasplms
Log on as : LocalSystem
Executable path : C:\Windows\system32\hasplms.exe -run
Dependencies : Tcpip/

iphlpsvc startup parameters :
Display name : IP Helper
Service name : iphlpsvc
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k NetSvcs -p
Dependencies : RpcSS/winmgmt/tcpip/nsi/WinHttpAutoProxySvc/

klnagent startup parameters :
Display name : Kaspersky Security Center Network Agent
Service name : klnagent
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\klnagent.exe"

mpssvc startup parameters :
Display name : Windows Defender Firewall
Service name : mpssvc
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p
Dependencies : mpsdrv/bfe/

nsi startup parameters :
Display name : Network Store Interface Service
Service name : nsi
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p
Dependencies : rpcss/nsiproxy/

sppsvc startup parameters :
Display name : Software Protection
Service name : sppsvc
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\system32\sppsvc.exe
Dependencies : RpcSs/

vm3dservice startup parameters :
Display name : VMware SVGA Helper Service
Service name : vm3dservice
Log on as : LocalSystem
Executable path : C:\Windows\system32\vm3dservice.exe

wuauserv startup parameters :
Display name : Windows Update
Service name : wuauserv
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

The following services must be started manually :

AJRouter startup parameters :
Display name : AllJoyn Router Service
Service name : AJRouter
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p

ALG startup parameters :
Display name : Application Layer Gateway Service
Service name : ALG
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\alg.exe

AppIDSvc startup parameters :
Display name : Application Identity
Service name : AppIDSvc
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : RpcSs/AppID/CryptSvc/

AppMgmt startup parameters :
Display name : Application Management
Service name : AppMgmt
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p

AppReadiness startup parameters :
Display name : App Readiness
Service name : AppReadiness
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k AppReadiness -p

AppXSvc startup parameters :
Display name : AppX Deployment Service (AppXSVC)
Service name : AppXSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k wsappx -p
Dependencies : rpcss/staterepository/

Appinfo startup parameters :
Display name : Application Information
Service name : Appinfo
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/ProfSvc/

AudioEndpointBuilder startup parameters :
Display name : Windows Audio Endpoint Builder
Service name : AudioEndpointBuilder
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p

Audiosrv startup parameters :
Display name : Windows Audio
Service name : Audiosrv
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : AudioEndpointBuilder/RpcSs/

BTAGService startup parameters :
Display name : Bluetooth Audio Gateway Service
Service name : BTAGService
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted
Dependencies : bthserv/rpcss/

BthAvctpSvc startup parameters :
Display name : AVCTP service
Service name : BthAvctpSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p
Dependencies : rpcss/

COMSysApp startup parameters :
Display name : COM+ System Application
Service name : COMSysApp
Log on as : LocalSystem
Executable path : C:\Windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
Dependencies : RpcSs/EventSystem/SENS/

CaptureService_7fbee startup parameters :
Display name : CaptureService_7fbee
Service name : CaptureService_7fbee
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p

CertPropSvc startup parameters :
Display name : Certificate Propagation
Service name : CertPropSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs
Dependencies : RpcSs/

ClipSVC startup parameters :
Display name : Client License Service (ClipSVC)
Service name : ClipSVC
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k wsappx -p
Dependencies : rpcss/

ConsentUxUserSvc_7fbee startup parameters :
Display name : ConsentUX_7fbee
Service name : ConsentUxUserSvc_7fbee
Executable path : C:\Windows\system32\svchost.exe -k DevicesFlow

DevQueryBroker startup parameters :
Display name : DevQuery Background Discovery Broker
Service name : DevQueryBroker
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p

DeviceAssociationService startup parameters :
Display name : Device Association Service
Service name : DeviceAssociationService
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p

DeviceInstall startup parameters :
Display name : Device Install Service
Service name : DeviceInstall
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k DcomLaunch -p

DevicesFlowUserSvc_7fbee startup parameters :
Display name : DevicesFlow_7fbee
Service name : DevicesFlowUserSvc_7fbee
Executable path : C:\Windows\system32\svchost.exe -k DevicesFlow

DmEnrollmentSvc startup parameters :
Display name : Device Management Enrollment Service
Service name : DmEnrollmentSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

DoSvc startup parameters :
Display name : Delivery Optimization
Service name : DoSvc
Log on as : NT Authority\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k NetworkService -p
Dependencies : rpcss/

DsSvc startup parameters :
Display name : Data Sharing Service
Service name : DsSvc
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p

DsmSvc startup parameters :
Display name : Device Setup Manager
Service name : DsmSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/

EFS startup parameters :
Display name : Encrypting File System (EFS)
Service name : EFS
Log on as : LocalSystem
Executable path : C:\Windows\System32\lsass.exe
Dependencies : RPCSS/

Eaphost startup parameters :
Display name : Extensible Authentication Protocol
Service name : Eaphost
Log on as : localSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p
Dependencies : RPCSS/KeyIso/

EntAppSvc startup parameters :
Display name : Enterprise App Management Service
Service name : EntAppSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k appmodel -p
Dependencies : rpcss/

FDResPub startup parameters :
Display name : Function Discovery Resource Publication
Service name : FDResPub
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
Dependencies : RpcSs/http/fdphost/

FontCache3.0.0.0 startup parameters :
Display name : Windows Presentation Foundation Font Cache 3.0.0.0
Service name : FontCache3.0.0.0
Log on as : NT Authority\LocalService
Executable path : C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe

FrameServer startup parameters :
Display name : Windows Camera Frame Server
Service name : FrameServer
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k Camera
Dependencies : rpcss/

HvHost startup parameters :
Display name : HV Host Service
Service name : HvHost
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : hvservice/

InstallService startup parameters :
Display name : Microsoft Store Install Service
Service name : InstallService
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

KPSSVC startup parameters :
Display name : KDC Proxy Server service (KPS)
Service name : KPSSVC
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\system32\svchost.exe -k KpsSvcGroup
Dependencies : rpcss/http/

KeyIso startup parameters :
Display name : CNG Key Isolation
Service name : KeyIso
Log on as : LocalSystem
Executable path : C:\Windows\system32\lsass.exe
Dependencies : RpcSs/

KtmRm startup parameters :
Display name : KtmRm for Distributed Transaction Coordinator
Service name : KtmRm
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k NetworkServiceAndNoImpersonation -p
Dependencies : RPCSS/SamSS/

LicenseManager startup parameters :
Display name : Windows License Manager Service
Service name : LicenseManager
Log on as : NT Authority\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalService -p
Dependencies : rpcss/

MSiSCSI startup parameters :
Display name : Microsoft iSCSI Initiator Service
Service name : MSiSCSI
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p

MicrosoftEdgeElevationService startup parameters :
Display name : Microsoft Edge Elevation Service (MicrosoftEdgeElevationService)
Service name : MicrosoftEdgeElevationService
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Microsoft\Edge\Application\144.0.3719.82\elevation_service.exe"
Dependencies : RPCSS/

NcaSvc startup parameters :
Display name : Network Connectivity Assistant
Service name : NcaSvc
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k NetSvcs -p
Dependencies : BFE/dnscache/NSI/iphlpsvc/

NcbService startup parameters :
Display name : Network Connection Broker
Service name : NcbService
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSS/tcpip/

NetSetupSvc startup parameters :
Display name : Network Setup Service
Service name : NetSetupSvc
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/

NetTcpPortSharing startup parameters :
Display name : Net.Tcp Port Sharing Service
Service name : NetTcpPortSharing
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe

Netlogon startup parameters :
Display name : Netlogon
Service name : Netlogon
Log on as : LocalSystem
Executable path : C:\Windows\system32\lsass.exe
Dependencies : LanmanWorkstation/

Netman startup parameters :
Display name : Network Connections
Service name : Netman
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/nsi/

Nexsus Communication Server startup parameters :
Display name : Nexsus Communication Server
Service name : Nexsus Communication Server
Log on as : LocalSystem
Executable path : "D:\Nexsus\Nexsus_Patch\NexCommServer\Nexsus.CommServer.exe"

NgcCtnrSvc startup parameters :
Display name : Microsoft Passport Container
Service name : NgcCtnrSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : RpcSs/

NgcSvc startup parameters :
Display name : Microsoft Passport
Service name : NgcSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/

PcaSvc startup parameters :
Display name : Program Compatibility Assistant Service
Service name : PcaSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/

PerfHost startup parameters :
Display name : Performance Counter DLL Host
Service name : PerfHost
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\SysWow64\perfhost.exe
Dependencies : RPCSS/

PimIndexMaintenanceSvc_7fbee startup parameters :
Display name : Contact Data_7fbee
Service name : PimIndexMaintenanceSvc_7fbee
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

PlugPlay startup parameters :
Display name : Plug and Play
Service name : PlugPlay
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k DcomLaunch -p

PolicyAgent startup parameters :
Display name : IPsec Policy Agent
Service name : PolicyAgent
Log on as : NT Authority\NetworkService
Executable path : C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted -p
Dependencies : Tcpip/bfe/

PrintNotify startup parameters :
Display name : Printer Extensions and Notifications
Service name : PrintNotify
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k print
Dependencies : RpcSs/

PrintWorkflowUserSvc_7fbee startup parameters :
Display name : PrintWorkflow_7fbee
Service name : PrintWorkflowUserSvc_7fbee
Executable path : C:\Windows\system32\svchost.exe -k PrintWorkflow

QWAVE startup parameters :
Display name : Quality Windows Audio Video Experience
Service name : QWAVE
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
Dependencies : rpcss/psched/QWAVEdrv/LLTDIO/

RSoPProv startup parameters :
Display name : Resultant Set of Policy Provider
Service name : RSoPProv
Log on as : LocalSystem
Executable path : C:\Windows\system32\RSoPProv.exe
Dependencies : RPCSS/

RasAuto startup parameters :
Display name : Remote Access Auto Connection Manager
Service name : RasAuto
Log on as : localSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p
Dependencies : RasAcd/

RemoteRegistry startup parameters :
Display name : Remote Registry
Service name : RemoteRegistry
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k localService -p
Dependencies : RPCSS/

RpcLocator startup parameters :
Display name : Remote Procedure Call (RPC) Locator
Service name : RpcLocator
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\system32\locator.exe

SCPolicySvc startup parameters :
Display name : Smart Card Removal Policy
Service name : SCPolicySvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs
Dependencies : RpcSs/

SCardSvr startup parameters :
Display name : Smart Card
Service name : SCardSvr
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

SNMPTRAP startup parameters :
Display name : SNMP Trap
Service name : SNMPTRAP
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\snmptrap.exe

SecurityHealthService startup parameters :
Display name : Windows Security Service
Service name : SecurityHealthService
Log on as : LocalSystem
Executable path : C:\Windows\system32\SecurityHealthService.exe
Dependencies : RpcSs/

Sense startup parameters :
Display name : Windows Defender Advanced Threat Protection Service
Service name : Sense
Log on as : LocalSystem
Executable path : "C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe"

SensorService startup parameters :
Display name : Sensor Service
Service name : SensorService
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p

SensrSvc startup parameters :
Display name : Sensor Monitoring Service
Service name : SensrSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p

SessionEnv startup parameters :
Display name : Remote Desktop Configuration
Service name : SessionEnv
Log on as : localSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p
Dependencies : RPCSS/LanmanWorkstation/

SgrmBroker startup parameters :
Display name : System Guard Runtime Monitor Broker
Service name : SgrmBroker
Log on as : LocalSystem
Executable path : C:\Windows\system32\SgrmBroker.exe
Dependencies : RpcSs/

SstpSvc startup parameters :
Display name : Secure Socket Tunneling Protocol Service
Service name : SstpSvc
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p

StateRepository startup parameters :
Display name : State Repository Service
Service name : StateRepository
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k appmodel -p
Dependencies : rpcss/

StorSvc startup parameters :
Display name : Storage Service
Service name : StorSvc
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p

TabletInputService startup parameters :
Display name : Touch Keyboard and Handwriting Panel Service
Service name : TabletInputService
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/

TermService startup parameters :
Display name : Remote Desktop Services
Service name : TermService
Log on as : NT Authority\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k termsvcs
Dependencies : RPCSS/

TieringEngineService startup parameters :
Display name : Storage Tiers Management
Service name : TieringEngineService
Log on as : localSystem
Executable path : C:\Windows\system32\TieringEngineService.exe

TimeBrokerSvc startup parameters :
Display name : Time Broker
Service name : TimeBrokerSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p

TokenBroker startup parameters :
Display name : Web Account Manager
Service name : TokenBroker
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : UserManager/

TrustedInstaller startup parameters :
Display name : Windows Modules Installer
Service name : TrustedInstaller
Log on as : localSystem
Executable path : C:\Windows\servicing\TrustedInstaller.exe

UmRdpService startup parameters :
Display name : Remote Desktop Services UserMode Port Redirector
Service name : UmRdpService
Log on as : localSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : TermService/RDPDR/

UnistoreSvc_7fbee startup parameters :
Display name : User Data Storage_7fbee
Service name : UnistoreSvc_7fbee
Executable path : C:\Windows\System32\svchost.exe -k UnistackSvcGroup

UserDataSvc_7fbee startup parameters :
Display name : User Data Access_7fbee
Service name : UserDataSvc_7fbee
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

VSS startup parameters :
Display name : Volume Shadow Copy
Service name : VSS
Log on as : LocalSystem
Executable path : C:\Windows\system32\vssvc.exe
Dependencies : RPCSS/

VaultSvc startup parameters :
Display name : Credential Manager
Service name : VaultSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\lsass.exe
Dependencies : rpcss/

WAS startup parameters :
Display name : Windows Process Activation Service
Service name : WAS
Log on as : localSystem
Executable path : C:\Windows\system32\svchost.exe -k iissvcs
Dependencies : RPCSS/

WEPHOSTSVC startup parameters :
Display name : Windows Encryption Provider Host Service
Service name : WEPHOSTSVC
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k WepHostSvcGroup
Dependencies : rpcss/

WMPNetworkSvc startup parameters :
Display name : Windows Media Player Network Sharing Service
Service name : WMPNetworkSvc
Log on as : NT AUTHORITY\NetworkService
Executable path : "C:\Program Files\Windows Media Player\wmpnetwk.exe"
Dependencies : http/WSearch/

WMSVC startup parameters :
Display name : Web Management Service
Service name : WMSVC
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\inetsrv\wmsvc.exe
Dependencies : HTTP/

WPDBusEnum startup parameters :
Display name : Portable Device Enumerator Service
Service name : WPDBusEnum
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : RpcSs/

WaaSMedicSvc startup parameters :
Display name : Windows Update Medic Service
Service name : WaaSMedicSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k wusvcs -p
Dependencies : rpcss/

WarpJITSvc startup parameters :
Display name : WarpJITSvc
Service name : WarpJITSvc
Log on as : NT Authority\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

WbioSrvc startup parameters :
Display name : Windows Biometric Service
Service name : WbioSrvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k WbioSvcGroup
Dependencies : RpcSs/

WdNisSvc startup parameters :
Display name : Windows Defender Antivirus Network Inspection Service
Service name : WdNisSvc
Log on as : NT AUTHORITY\LocalService
Executable path : "C:\ProgramData\Microsoft\Windows Defender\platform\4.18.24050.7-0\NisSrv.exe"
Dependencies : WdNisDrv/

WdiServiceHost startup parameters :
Display name : Diagnostic Service Host
Service name : WdiServiceHost
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalService -p

WdiSystemHost startup parameters :
Display name : Diagnostic System Host
Service name : WdiSystemHost
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p

Wecsvc startup parameters :
Display name : Windows Event Collector
Service name : Wecsvc
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\system32\svchost.exe -k NetworkService -p
Dependencies : HTTP/Eventlog/

WerSvc startup parameters :
Display name : Windows Error Reporting Service
Service name : WerSvc
Log on as : localSystem
Executable path : C:\Windows\System32\svchost.exe -k WerSvcGroup

WiaRpc startup parameters :
Display name : Still Image Acquisition Events
Service name : WiaRpc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/

WinDefend startup parameters :
Display name : Windows Defender Antivirus Service
Service name : WinDefend
Log on as : LocalSystem
Executable path : "C:\ProgramData\Microsoft\Windows Defender\platform\4.18.24050.7-0\MsMpEng.exe"
Dependencies : RpcSs/

WinHttpAutoProxySvc startup parameters :
Display name : WinHTTP Web Proxy Auto-Discovery Service
Service name : WinHttpAutoProxySvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : Dhcp/

aspnet_state startup parameters :
Display name : ASP.NET State Service
Service name : aspnet_state
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe

bthserv startup parameters :
Display name : Bluetooth Support Service
Service name : bthserv
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p

camsvc startup parameters :
Display name : Capability Access Manager Service
Service name : camsvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k appmodel -p

cbdhsvc_7fbee startup parameters :
Display name : Clipboard User Service_7fbee
Service name : cbdhsvc_7fbee
Executable path : C:\Windows\system32\svchost.exe -k ClipboardSvcGroup -p

defragsvc startup parameters :
Display name : Optimize drives
Service name : defragsvc
Log on as : localSystem
Executable path : C:\Windows\system32\svchost.exe -k defragsvc
Dependencies : RPCSS/

diagnosticshub.standardcollector.service startup parameters :
Display name : Microsoft (R) Diagnostics Hub Standard Collector Service
Service name : diagnosticshub.standardcollector.service
Log on as : LocalSystem
Executable path : C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe

dot3svc startup parameters :
Display name : Wired AutoConfig
Service name : dot3svc
Log on as : localSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/Ndisuio/Eaphost/

edgeupdatem startup parameters :
Display name : Microsoft Edge Update Service (edgeupdatem)
Service name : edgeupdatem
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /medsvc
Dependencies : RPCSS/

embeddedmode startup parameters :
Display name : Embedded Mode
Service name : embeddedmode
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : BrokerInfrastructure/

fdPHost startup parameters :
Display name : Function Discovery Provider Host
Service name : fdPHost
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p
Dependencies : RpcSs/http/

hidserv startup parameters :
Display name : Human Interface Device Service
Service name : hidserv
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p

ksnproxy startup parameters :
Display name : Kaspersky Security Network proxy server
Service name : ksnproxy
Log on as : NT SERVICE\ksnproxy
Executable path : "C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\ksnproxy.exe"

lmhosts startup parameters :
Display name : TCP/IP NetBIOS Helper
Service name : lmhosts
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : Afd/

msiserver startup parameters :
Display name : Windows Installer
Service name : msiserver
Log on as : LocalSystem
Executable path : C:\Windows\system32\msiexec.exe /V
Dependencies : rpcss/

netprofm startup parameters :
Display name : Network List Service
Service name : netprofm
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalService -p
Dependencies : RpcSs/nlasvc/

ose startup parameters :
Display name : Office Source Engine
Service name : ose
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE"

ose64 startup parameters :
Display name : Office 64 Source Engine
Service name : ose64
Log on as : LocalSystem
Executable path : "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"

pla startup parameters :
Display name : Performance Logs & Alerts
Service name : pla
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork -p
Dependencies : RPCSS/

rpcapd startup parameters :
Display name : Remote Packet Capture Protocol v.0 (experimental)
Service name : rpcapd
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\WinPcap\rpcapd.exe" -d -f "C:\Program Files (x86)\WinPcap\rpcapd.ini"

sacsvr startup parameters :
Display name : Special Administration Console Helper
Service name : sacsvr
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p

seclogon startup parameters :
Display name : Secondary Logon
Service name : seclogon
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p

smphost startup parameters :
Display name : Microsoft Storage Spaces SMP
Service name : smphost
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k smphost
Dependencies : RPCSS/

stisvc startup parameters :
Display name : Windows Image Acquisition (WIA)
Service name : stisvc
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k imgsvc
Dependencies : RpcSs/

svsvc startup parameters :
Display name : Spot Verifier
Service name : svsvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p

swprv startup parameters :
Display name : Microsoft Software Shadow Copy Provider
Service name : swprv
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k swprv
Dependencies : RPCSS/

tapisrv startup parameters :
Display name : Telephony
Service name : tapisrv
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k NetworkService -p
Dependencies : RpcSs/

vds startup parameters :
Display name : Virtual Disk
Service name : vds
Log on as : LocalSystem
Executable path : C:\Windows\System32\vds.exe
Dependencies : RpcSs/

vmicguestinterface startup parameters :
Display name : Hyper-V Guest Service Interface
Service name : vmicguestinterface
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p

vmicheartbeat startup parameters :
Display name : Hyper-V Heartbeat Service
Service name : vmicheartbeat
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k ICService -p

vmickvpexchange startup parameters :
Display name : Hyper-V Data Exchange Service
Service name : vmickvpexchange
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p

vmicrdv startup parameters :
Display name : Hyper-V Remote Desktop Virtualization Service
Service name : vmicrdv
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k ICService -p

vmicshutdown startup parameters :
Display name : Hyper-V Guest Shutdown Service
Service name : vmicshutdown
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p

vmictimesync startup parameters :
Display name : Hyper-V Time Synchronization Service
Service name : vmictimesync
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : VmGid/

vmicvmsession startup parameters :
Display name : Hyper-V PowerShell Direct Service
Service name : vmicvmsession
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p

vmicvss startup parameters :
Display name : Hyper-V Volume Shadow Copy Requestor
Service name : vmicvss
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p

vmvss startup parameters :
Display name : VMware Snapshot Provider
Service name : vmvss
Log on as : LocalSystem
Executable path : C:\Windows\system32\dllhost.exe /Processid:{EF7DED12-05C5-4EFB-8CB5-70F3C252BB5F}
Dependencies : rpcss/

w3logsvc startup parameters :
Display name : W3C Logging Service
Service name : w3logsvc
Log on as : localSystem
Executable path : C:\Windows\system32\svchost.exe -k apphost
Dependencies : HTTP/

wercplsupport startup parameters :
Display name : Problem Reports and Solutions Control Panel Support
Service name : wercplsupport
Log on as : localSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p

wlidsvc startup parameters :
Display name : Microsoft Account Sign-in Assistant
Service name : wlidsvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/

wmiApSrv startup parameters :
Display name : WMI Performance Adapter
Service name : wmiApSrv
Log on as : localSystem
Executable path : C:\Windows\system32\wbem\WmiApSrv.exe

The following services are disabled :

AppVClient startup parameters :
Display name : Microsoft App-V Client
Service name : AppVClient
Log on as : LocalSystem
Executable path : C:\Windows\system32\AppVClient.exe
Dependencies : RpcSS/netprofm/AppvVfs/AppVStrm/

AxInstSV startup parameters :
Display name : ActiveX Installer (AxInstSV)
Service name : AxInstSV
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k AxInstSVGroup
Dependencies : rpcss/

CscService startup parameters :
Display name : Offline Files
Service name : CscService
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/

DevicePickerUserSvc_7fbee startup parameters :
Display name : DevicePicker_7fbee
Service name : DevicePickerUserSvc_7fbee
Executable path : C:\Windows\system32\svchost.exe -k DevicesFlow

GraphicsPerfSvc startup parameters :
Display name : GraphicsPerfSvc
Service name : GraphicsPerfSvc
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k GraphicsPerfSvcGroup

MapsBroker startup parameters :
Display name : Downloaded Maps Manager
Service name : MapsBroker
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k NetworkService -p
Dependencies : rpcss/

PhoneSvc startup parameters :
Display name : Phone Service
Service name : PhoneSvc
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p
Dependencies : RpcSs/

PushToInstall startup parameters :
Display name : Windows PushToInstall Service
Service name : PushToInstall
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

RemoteAccess startup parameters :
Display name : Routing and Remote Access
Service name : RemoteAccess
Log on as : localSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs
Dependencies : RpcSS/Bfe/RasMan/Http/+NetBIOSGroup/

RmSvc startup parameters :
Display name : Radio Management Service
Service name : RmSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
Dependencies : RpcSs/

SEMgrSvc startup parameters :
Display name : Payments and NFC/SE Manager
Service name : SEMgrSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p
Dependencies : RpcSs/

SSDPSRV startup parameters :
Display name : SSDP Discovery
Service name : SSDPSRV
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
Dependencies : HTTP/NSI/

ScDeviceEnum startup parameters :
Display name : Smart Card Device Enumeration Service
Service name : ScDeviceEnum
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted

SensorDataService startup parameters :
Display name : Sensor Data Service
Service name : SensorDataService
Log on as : LocalSystem
Executable path : C:\Windows\System32\SensorDataService.exe

SharedAccess startup parameters :
Display name : Internet Connection Sharing (ICS)
Service name : SharedAccess
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p
Dependencies : BFE/

UevAgentService startup parameters :
Display name : User Experience Virtualization Service
Service name : UevAgentService
Log on as : LocalSystem
Executable path : C:\Windows\system32\AgentService.exe

WSearch startup parameters :
Display name : Windows Search
Service name : WSearch
Log on as : LocalSystem
Executable path : C:\Windows\system32\SearchIndexer.exe /Embedding
Dependencies : RPCSS/BrokerInfrastructure/

WalletService startup parameters :
Display name : WalletService
Service name : WalletService
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k appmodel -p

dmwappushservice startup parameters :
Display name : Device Management Wireless Application Protocol (WAP) Push message Routing Service
Service name : dmwappushservice
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

icssvc startup parameters :
Display name : Windows Mobile Hotspot Service
Service name : icssvc
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : RpcSs/wcmsvc/

lfsvc startup parameters :
Display name : Geolocation Service
Service name : lfsvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/

lltdsvc startup parameters :
Display name : Link-Layer Topology Discovery Mapper
Service name : lltdsvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalService -p
Dependencies : rpcss/lltdio/

shpamsvc startup parameters :
Display name : Shared PC Account Manager
Service name : shpamsvc
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/ProfSvc/

ssh-agent startup parameters :
Display name : OpenSSH Authentication Agent
Service name : ssh-agent
Log on as : LocalSystem
Executable path : C:\Windows\System32\OpenSSH\ssh-agent.exe

tzautoupdate startup parameters :
Display name : Auto Time Zone Updater
Service name : tzautoupdate
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p

upnphost startup parameters :
Display name : UPnP Device Host
Service name : upnphost
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
Dependencies : SSDPSRV/HTTP/

wisvc startup parameters :
Display name : Windows Insider Service
Service name : wisvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : rpcss/
11011 - Microsoft Windows SMB Service Detection
-
Synopsis
A file / print sharing service is listening on the remote host.
Description
The remote service understands the CIFS (Common Internet File System) or Server Message Block (SMB) protocol, used to provide shared access to files, printers, etc between nodes on a network.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2002/06/05, Modified: 2021/02/11
Plugin Output

tcp/445/cifs


A CIFS server is running on this port.
10456 - Microsoft Windows SMB Service Enumeration
-
Synopsis
It is possible to enumerate remote services.
Description
This plugin implements the SvcOpenSCManager() and SvcEnumServices() calls to obtain, using the SMB protocol, the list of active and inactive services of the remote host.

An attacker may use this feature to gain better knowledge of the remote host.
Solution
To prevent the listing of the services from being obtained, you should either have tight login restrictions, so that only trusted users can access your host, and/or you should filter incoming traffic to this port.
Risk Factor
None
References
XREF IAVT:0001-T-0751
Plugin Information
Published: 2000/07/03, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Active Services :

Application Host Helper Service [ AppHostSvc ]
Application Information [ Appinfo ]
Kaspersky Endpoint Security Service (KES.21.15) [ AVP.KES.21.15 ]
Kaspersky Seamless Update Service (KES.21.15) [ avpsus.KES.21.15 ]
Base Filtering Engine [ BFE ]
Background Tasks Infrastructure Service [ BrokerInfrastructure ]
AVCTP service [ BthAvctpSvc ]
CallBalanceClopsVoiceLogService_LKP [ CallBalanceClopsVoiceLogService_LKP ]
Connected Devices Platform Service [ CDPSvc ]
Certificate Propagation [ CertPropSvc ]
COM+ System Application [ COMSysApp ]
CoreMessaging [ CoreMessagingRegistrar ]
Cryptographic Services [ CryptSvc ]
DCOM Server Process Launcher [ DcomLaunch ]
DHCP Client [ Dhcp ]
Connected User Experiences and Telemetry [ DiagTrack ]
DNS Client [ Dnscache ]
Diagnostic Policy Service [ DPS ]
Windows Event Log [ EventLog ]
COM+ Event System [ EventSystem ]
Function Discovery Provider Host [ fdPHost ]
Function Discovery Resource Publication [ FDResPub ]
Windows Font Cache Service [ FontCache ]
Group Policy Client [ gpsvc ]
Sentinel LDK License Manager [ hasplms ]
IIS Admin Service [ IISADMIN ]
IKE and AuthIP IPsec Keying Modules [ IKEEXT ]
IP Helper [ iphlpsvc ]
CNG Key Isolation [ KeyIso ]
Kaspersky Security Center Network Agent [ klnagent ]
Server [ LanmanServer ]
Workstation [ LanmanWorkstation ]
TCP/IP NetBIOS Helper [ lmhosts ]
Local Session Manager [ LSM ]
Windows Defender Firewall [ mpssvc ]
Distributed Transaction Coordinator [ MSDTC ]
Message Queuing [ MSMQ ]
Network Connection Broker [ NcbService ]
Net.Msmq Listener Adapter [ NetMsmqActivator ]
Net.Pipe Listener Adapter [ NetPipeActivator ]
Network List Service [ netprofm ]
Net.Tcp Listener Adapter [ NetTcpActivator ]
Net.Tcp Port Sharing Service [ NetTcpPortSharing ]
Nexsus.UserStatusValidatorWeb [ Nexsus.UserStatusValidatorWeb ]
NexsusEmailService [ NexsusEmailService ]
Network Location Awareness [ NlaSvc ]
Network Store Interface Service [ nsi ]
Program Compatibility Assistant Service [ PcaSvc ]
Plug and Play [ PlugPlay ]
IPsec Policy Agent [ PolicyAgent ]
Power [ Power ]
User Profile Service [ ProfSvc ]
Remote Access Connection Manager [ RasMan ]
Remote Registry [ RemoteRegistry ]
RPC Endpoint Mapper [ RpcEptMapper ]
Remote Procedure Call (RPC) [ RpcSs ]
Security Accounts Manager [ SamSs ]
Task Scheduler [ Schedule ]
System Event Notification Service [ SENS ]
Remote Desktop Configuration [ SessionEnv ]
Shell Hardware Detection [ ShellHWDetection ]
Print Spooler [ Spooler ]
SQL Server Reporting Services [ SQLServerReportingServices ]
Secure Socket Tunneling Protocol Service [ SstpSvc ]
State Repository Service [ StateRepository ]
Storage Service [ StorSvc ]
SynHMPCodec [ SynHMPCodec ]
SynIPR Record Slaver [ SynIPR Record Slaver ]
SysMain [ SysMain ]
System Events Broker [ SystemEventsBroker ]
Touch Keyboard and Handwriting Panel Service [ TabletInputService ]
Remote Desktop Services [ TermService ]
Themes [ Themes ]
Time Broker [ TimeBrokerSvc ]
Web Account Manager [ TokenBroker ]
Distributed Link Tracking Client [ TrkWks ]
Windows Modules Installer [ TrustedInstaller ]
User Access Logging Service [ UALSVC ]
Remote Desktop Services UserMode Port Redirector [ UmRdpService ]
User Manager [ UserManager ]
Update Orchestrator Service [ UsoSvc ]
VMware Alias Manager and Ticket Service [ VGAuthService ]
VMware SVGA Helper Service [ vm3dservice ]
VMware Tools [ VMTools ]
Windows Time [ W32Time ]
World Wide Web Publishing Service [ W3SVC ]
Windows Process Activation Service [ WAS ]
Windows Connection Manager [ Wcmsvc ]
WinHTTP Web Proxy Auto-Discovery Service [ WinHttpAutoProxySvc ]
Windows Management Instrumentation [ Winmgmt ]
Windows Remote Management (WS-Management) [ WinRM ]
Windows Push Notifications System Service [ WpnService ]
Connected Devices Platform User Service_7fbee [ CDPUserSvc_7fbee ]
Contact Data_7fbee [ PimIndexMaintenanceSvc_7fbee ]
User Data Storage_7fbee [ UnistoreSvc_7fbee ]
User Data Access_7fbee [ UserDataSvc_7fbee ]
Windows Push Notifications User Service_7fbee [ WpnUserService_7fbee ]

Inactive Services :

AllJoyn Router Service [ AJRouter ]
Application Layer Gateway Service [ ALG ]
Application Identity [ AppIDSvc ]
Application Management [ AppMgmt ]
App Readiness [ AppReadiness ]
Microsoft App-V Client [ AppVClient ]
AppX Deployment Service (AppXSVC) [ AppXSvc ]
ASP.NET State Service [ aspnet_state ]
Windows Audio Endpoint Builder [ AudioEndpointBuilder ]
Windows Audio [ Audiosrv ]
ActiveX Installer (AxInstSV) [ AxInstSV ]
Background Intelligent Transfer Service [ BITS ]
Bluetooth Audio Gateway Service [ BTAGService ]
Bluetooth Support Service [ bthserv ]
Capability Access Manager Service [ camsvc ]
Client License Service (ClipSVC) [ ClipSVC ]
Offline Files [ CscService ]
Optimize drives [ defragsvc ]
Device Association Service [ DeviceAssociationService ]
Device Install Service [ DeviceInstall ]
DevQuery Background Discovery Broker [ DevQueryBroker ]
Microsoft (R) Diagnostics Hub Standard Collector Service [ diagnosticshub.standardcollector.service ]
Device Management Enrollment Service [ DmEnrollmentSvc ]
Device Management Wireless Application Protocol (WAP) Push message Routing Service [ dmwappushservice ]
Delivery Optimization [ DoSvc ]
Wired AutoConfig [ dot3svc ]
Device Setup Manager [ DsmSvc ]
Data Sharing Service [ DsSvc ]
Extensible Authentication Protocol [ Eaphost ]
Microsoft Edge Update Service (edgeupdate) [ edgeupdate ]
Microsoft Edge Update Service (edgeupdatem) [ edgeupdatem ]
Encrypting File System (EFS) [ EFS ]
Embedded Mode [ embeddedmode ]
Enterprise App Management Service [ EntAppSvc ]
Windows Presentation Foundation Font Cache 3.0.0.0 [ FontCache3.0.0.0 ]
Windows Camera Frame Server [ FrameServer ]
GraphicsPerfSvc [ GraphicsPerfSvc ]
Human Interface Device Service [ hidserv ]
HV Host Service [ HvHost ]
Windows Mobile Hotspot Service [ icssvc ]
Microsoft Store Install Service [ InstallService ]
KDC Proxy Server service (KPS) [ KPSSVC ]
Kaspersky Security Network proxy server [ ksnproxy ]
KtmRm for Distributed Transaction Coordinator [ KtmRm ]
Geolocation Service [ lfsvc ]
Windows License Manager Service [ LicenseManager ]
Link-Layer Topology Discovery Mapper [ lltdsvc ]
Downloaded Maps Manager [ MapsBroker ]
Microsoft Edge Elevation Service (MicrosoftEdgeElevationService) [ MicrosoftEdgeElevationService ]
Microsoft iSCSI Initiator Service [ MSiSCSI ]
Windows Installer [ msiserver ]
Network Connectivity Assistant [ NcaSvc ]
Netlogon [ Netlogon ]
Network Connections [ Netman ]
Network Setup Service [ NetSetupSvc ]
Nexsus Communication Server [ Nexsus Communication Server ]
Microsoft Passport Container [ NgcCtnrSvc ]
Microsoft Passport [ NgcSvc ]
Office Source Engine [ ose ]
Office 64 Source Engine [ ose64 ]
Performance Counter DLL Host [ PerfHost ]
Phone Service [ PhoneSvc ]
Performance Logs & Alerts [ pla ]
Printer Extensions and Notifications [ PrintNotify ]
Windows PushToInstall Service [ PushToInstall ]
Quality Windows Audio Video Experience [ QWAVE ]
Remote Access Auto Connection Manager [ RasAuto ]
Routing and Remote Access [ RemoteAccess ]
Radio Management Service [ RmSvc ]
Remote Packet Capture Protocol v.0 (experimental) [ rpcapd ]
Remote Procedure Call (RPC) Locator [ RpcLocator ]
Resultant Set of Policy Provider [ RSoPProv ]
Special Administration Console Helper [ sacsvr ]
Smart Card [ SCardSvr ]
Smart Card Device Enumeration Service [ ScDeviceEnum ]
Smart Card Removal Policy [ SCPolicySvc ]
Secondary Logon [ seclogon ]
Windows Security Service [ SecurityHealthService ]
Payments and NFC/SE Manager [ SEMgrSvc ]
Windows Defender Advanced Threat Protection Service [ Sense ]
Sensor Data Service [ SensorDataService ]
Sensor Service [ SensorService ]
Sensor Monitoring Service [ SensrSvc ]
System Guard Runtime Monitor Broker [ SgrmBroker ]
Internet Connection Sharing (ICS) [ SharedAccess ]
Shared PC Account Manager [ shpamsvc ]
Microsoft Storage Spaces SMP [ smphost ]
SNMP Trap [ SNMPTRAP ]
Software Protection [ sppsvc ]
SSDP Discovery [ SSDPSRV ]
OpenSSH Authentication Agent [ ssh-agent ]
Windows Image Acquisition (WIA) [ stisvc ]
Spot Verifier [ svsvc ]
Microsoft Software Shadow Copy Provider [ swprv ]
Telephony [ tapisrv ]
Storage Tiers Management [ TieringEngineService ]
Auto Time Zone Updater [ tzautoupdate ]
User Experience Virtualization Service [ UevAgentService ]
UPnP Device Host [ upnphost ]
Credential Manager [ VaultSvc ]
Virtual Disk [ vds ]
Hyper-V Guest Service Interface [ vmicguestinterface ]
Hyper-V Heartbeat Service [ vmicheartbeat ]
Hyper-V Data Exchange Service [ vmickvpexchange ]
Hyper-V Remote Desktop Virtualization Service [ vmicrdv ]
Hyper-V Guest Shutdown Service [ vmicshutdown ]
Hyper-V Time Synchronization Service [ vmictimesync ]
Hyper-V PowerShell Direct Service [ vmicvmsession ]
Hyper-V Volume Shadow Copy Requestor [ vmicvss ]
VMware Snapshot Provider [ vmvss ]
Volume Shadow Copy [ VSS ]
W3C Logging Service [ w3logsvc ]
Windows Update Medic Service [ WaaSMedicSvc ]
WalletService [ WalletService ]
WarpJITSvc [ WarpJITSvc ]
Windows Biometric Service [ WbioSrvc ]
Diagnostic Service Host [ WdiServiceHost ]
Diagnostic System Host [ WdiSystemHost ]
Windows Defender Antivirus Network Inspection Service [ WdNisSvc ]
Windows Event Collector [ Wecsvc ]
Windows Encryption Provider Host Service [ WEPHOSTSVC ]
Problem Reports and Solutions Control Panel Support [ wercplsupport ]
Windows Error Reporting Service [ WerSvc ]
Still Image Acquisition Events [ WiaRpc ]
Windows Defender Antivirus Service [ WinDefend ]
Windows Insider Service [ wisvc ]
Microsoft Account Sign-in Assistant [ wlidsvc ]
WMI Performance Adapter [ wmiApSrv ]
Windows Media Player Network Sharing Service [ WMPNetworkSvc ]
Web Management Service [ WMSVC ]
Portable Device Enumerator Service [ WPDBusEnum ]
Windows Search [ WSearch ]
Windows Update [ wuauserv ]
CaptureService_7fbee [ CaptureService_7fbee ]
Clipboard User Service_7fbee [ cbdhsvc_7fbee ]
ConsentUX_7fbee [ ConsentUxUserSvc_7fbee ]
DevicePicker_7fbee [ DevicePickerUserSvc_7fbee ]
DevicesFlow_7fbee [ DevicesFlowUserSvc_7fbee ]
PrintWorkflow_7fbee [ PrintWorkflowUserSvc_7fbee ]

92373 - Microsoft Windows SMB Sessions
-
Synopsis
Nessus was able to collect and report SMB session information from the remote host.
Description
Nessus was able to collect details of SMB sessions from the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2025/12/15
Plugin Output

tcp/0

tidua

Extended SMB session information attached.

23974 - Microsoft Windows SMB Share Hosting Office Files
-
Synopsis
The remote share contains Office-related files.
Description
This plugin connects to the remotely accessible SMB shares and attempts to find office related files (such as .doc, .ppt, .xls, .pdf etc).
Solution
Make sure that the files containing confidential information have proper access controls set on them.
Risk Factor
None
Plugin Information
Published: 2007/01/04, Modified: 2011/03/21
Plugin Output

tcp/445/cifs


Here is a list of office files which have been found on the remote SMB
shares :

+ D$ :

- D:\CallbalanceVoiceLogs\LKP Summary.xlsx
- D:\Nexsus\Backup\0306_Engine\CallBalance\Uploads\Book1.xlsx
- D:\Nexsus\Backup\0306_Engine\CallBalance\Uploads\LKP_ClientDetails_new.xlsx
- D:\Nexsus\Backup\0306_Engine\CallBalance\Uploads\LKP_Data.xlsx
- D:\Nexsus\Backup\0306_Engine\CallBalance\Uploads\New.xlsx
- D:\Nexsus\Backup\0409_2025\CallBalance\Uploads\Odin Client Data.xlsx
- D:\Nexsus\Backup\06082025\CallBalance\Uploads\Book1.xlsx
- D:\Nexsus\Backup\06082025\CallBalance\Uploads\LKP_ClientDetails_new.xlsx
- D:\Nexsus\Backup\06082025\CallBalance\Uploads\LKP_Data.xlsx
- D:\Nexsus\Backup\06082025\CallBalance\Uploads\New.xlsx
- D:\Nexsus\Backup\10092025\CallBalance\Uploads\Odin Client Data.xlsx
- D:\Nexsus\Backup\18092025\CallBalance\Uploads\Book1.xlsx
- D:\Nexsus\Backup\18092025\CallBalance\Uploads\LKP_ClientDetails_new.xlsx
- D:\Nexsus\Backup\18092025\CallBalance\Uploads\LKP_Data.xlsx
- D:\Nexsus\Backup\18092025\CallBalance\Uploads\New.xlsx
- D:\Nexsus\Backup\2005\CallBalance\Uploads\Odin Client Data.xlsx
- D:\Nexsus\Backup\2205\CallBalance\Uploads\Book1.xlsx
- D:\Nexsus\Backup\2205\CallBalance\Uploads\LKP_ClientDetails_new.xlsx
- D:\Nexsus\Backup\2205\CallBalance\Uploads\LKP_Data.xlsx
- D:\Nexsus\Backup\2205\CallBalance\Uploads\New.xlsx
- D:\Nexsus\Backup\Backup2908\CallBalance\Uploads\Odin Client Data.xlsx
- D:\Nexsus\Backup\MainBackup\CallBalance\Uploads\Book1.xlsx
- D:\Nexsus\Backup\MainBackup\CallBalance\Uploads\LKP_ClientDetails_new.xlsx
- D:\Nexsus\Backup\MainBackup\CallBalance\Uploads\LKP_Data.xlsx
- D:\Nexsus\Backup\MainBackup\CallBalance\Uploads\New.xlsx
- D:\Nexsus\CallBalance\Uploads\Odin Client Data.xlsx
- D:\Nexsus\CallBalance_HTTPS\Uploads\Book1.xlsx
- D:\Nexsus\CallBalance_HTTPS\Uploads\LKP_ClientDetails_new.xlsx
- D:\Nexsus\CallBalance_HTTPS\Uploads\LKP_Data.xlsx
- D:\Nexsus\CallBalance_HTTPS\Uploads\New.xlsx
- D:\Nexsus\CallBalance_HTTPS\Uploads\Odin Client Data.xlsx
- D:\Nexsus\Nexsus_Patch\Patch\CallBalance - Copy\Uploads\LKP_Data.xlsx
- D:\Nexsus\Nexsus_Patch\Patch\CallBalance_LKP_16122024\CallBalance_LKP\Uploads\Book1.xlsx
- D:\Nexsus\Nexsus_Patch\Patch\CallBalance_LKP_20122024\CallBalance_LKP\Uploads\Book1.xlsx
- D:\Nexsus\Nexsus_Patch\Patch\LKP21122024\LKP21122024\LKP_ClientDetails_new.xlsx
- D:\Nexsus\Nexsus_Patch\Patch\LKP_ClientMaster_20122024\LKP_ClientMaster_20122024\ClientMasterLKP_Client.xlsx
- D:\Nexsus\Nexsus_Patch\Patch\CallBalance - Copy\Uploads\LKP_ClientDetails_new.xlsx
- D:\Nexsus\CallBalance_HTTPS - Copy\Uploads\Odin Client Data.xlsx
- D:\Nexsus\CallBalance_HTTPS - Copy\Uploads\New.xlsx
- D:\Nexsus\CallBalance_HTTPS - Copy\Uploads\LKP_Data.xlsx
- D:\Nexsus\CallBalance_HTTPS - Copy\Uploads\LKP_ClientDetails_new.xlsx
- D:\Nexsus\CallBalance_HTTPS - Copy\Uploads\Book1.xlsx
- D:\Nexsus\CallBalance\Uploads\New.xlsx
- D:\Nexsus\CallBalance\Uploads\LKP_Data.xlsx
- D:\Nexsus\CallBalance\Uploads\LKP_ClientDetails_new.xlsx
- D:\Nexsus\CallBalance\Uploads\Book1.xlsx
- D:\Nexsus\Backup\MainBackup\CallBalance\Uploads\Odin Client Data.xlsx
- D:\Nexsus\Backup\Backup2908\CallBalance\Uploads\New.xlsx
- D:\Nexsus\Backup\Backup2908\CallBalance\Uploads\LKP_Data.xlsx
- D:\Nexsus\Backup\Backup2908\CallBalance\Uploads\LKP_ClientDetails_new.xlsx
- D:\Nexsus\Backup\Backup2908\CallBalance\Uploads\Book1.xlsx
- D:\Nexsus\Backup\2205\CallBalance\Uploads\Odin Client Data.xlsx
- D:\Nexsus\Backup\2005\CallBalance\Uploads\New.xlsx
- D:\Nexsus\Backup\2005\CallBalance\Uploads\LKP_Data.xlsx
- D:\Nexsus\Backup\2005\CallBalance\Uploads\LKP_ClientDetails_new.xlsx
- D:\Nexsus\Backup\2005\CallBalance\Uploads\Book1.xlsx
- D:\Nexsus\Backup\18092025\CallBalance\Uploads\Odin Client Data.xlsx
- D:\Nexsus\Backup\10092025\CallBalance\Uploads\New.xlsx
- D:\Nexsus\Backup\10092025\CallBalance\Uploads\LKP_Data.xlsx
- D:\Nexsus\Backup\10092025\CallBalance\Uploads\LKP_ClientDetails_new.xlsx
- D:\Nexsus\Backup\10092025\CallBalance\Uploads\Book1.xlsx
- D:\Nexsus\Backup\06082025\CallBalance\Uploads\Odin Client Data.xlsx
- D:\Nexsus\Backup\0409_2025\CallBalance\Uploads\New.xlsx
- D:\Nexsus\Backup\0409_2025\CallBalance\Uploads\LKP_Data.xlsx
- D:\Nexsus\Backup\0409_2025\CallBalance\Uploads\LKP_ClientDetails_new.xlsx
- D:\Nexsus\Backup\0409_2025\CallBalance\Uploads\Book1.xlsx
- D:\Nexsus\Backup\0306_Engine\CallBalance\Uploads\Odin Client Data.xlsx
- D:\$RECYCLE.BIN\S-1-5-21-3194671253-1068146636-4210433707-500\$IN8792V.xlsx
- D:\$RECYCLE.BIN\S-1-5-21-3194671253-1068146636-4210433707-500\$IHAVO7K.xlsx
- D:\$RECYCLE.BIN\S-1-5-21-3194671253-1068146636-4210433707-500\$IDUNYM8.xlsx
- D:\$RECYCLE.BIN\S-1-5-21-3194671253-1068146636-4210433707-500\$IDEY16E.xlsx
- D:\$RECYCLE.BIN\S-1-5-21-3194671253-1068146636-4210433707-500\$ICSIBJD.xlsx

+ C$ :

- C:\Program Files\Microsoft Office\Office16\1033\PROTTPLN.DOC
- C:\Windows\SysWOW64\MSDRM\MsoIrmProtector.doc
- C:\Windows\WinSxS\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.1697_none_5b402724c75d80d6\MsoIrmProtector.doc
- C:\Windows\WinSxS\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.5830_none_5b252ca0c77261e3\MsoIrmProtector.doc
- C:\Windows\WinSxS\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.1697_none_6594d176fbbe42d1\MsoIrmProtector.doc
- C:\Windows\WinSxS\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.5830_none_6579d6f2fbd323de\MsoIrmProtector.doc
- C:\Windows\System32\MSDRM\MsoIrmProtector.doc
- C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~17763.6893.1.6\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.5830_none_6579d6f2fbd323de\r\msoirmprotector.doc
- C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~17763.6893.1.6\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.5830_none_6579d6f2fbd323de\f\msoirmprotector.doc
- C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~17763.6893.1.6\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.5830_none_5b252ca0c77261e3\r\msoirmprotector.doc
- C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~17763.6893.1.6\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.5830_none_5b252ca0c77261e3\f\msoirmprotector.doc
- C:\Program Files\Microsoft Office\Office16\1033\PROTTPLV.DOC
- C:\Program Files\Microsoft Office\Office16\1033\PROTTPLN.PPT
- C:\Windows\SysWOW64\MSDRM\MsoIrmProtector.ppt
- C:\Windows\WinSxS\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.1697_none_5b402724c75d80d6\MsoIrmProtector.ppt
- C:\Windows\WinSxS\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.5830_none_5b252ca0c77261e3\MsoIrmProtector.ppt
- C:\Windows\WinSxS\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.1697_none_6594d176fbbe42d1\MsoIrmProtector.ppt
- C:\Windows\WinSxS\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.5830_none_6579d6f2fbd323de\MsoIrmProtector.ppt
- C:\Windows\System32\MSDRM\MsoIrmProtector.ppt
- C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~17763.6893.1.6\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.5830_none_6579d6f2fbd323de\r\msoirmprotector.ppt
- C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~17763.6893.1.6\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.5830_none_6579d6f2fbd323de\f\msoirmprotector.ppt
- C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~17763.6893.1.6\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.5830_none_5b252ca0c77261e3\r\msoirmprotector.ppt
- C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~17763.6893.1.6\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.5830_none_5b252ca0c77261e3\f\msoirmprotector.ppt
- C:\Program Files\Microsoft Office\Office16\1033\PROTTPLV.PPT
- C:\Program Files (x86)\ShCtiSetup\Tools\HelpFile\DST_PBX_Support.xls
- C:\Program Files\Microsoft Office\Office16\1033\PROTTPLN.XLS
- C:\Program Files\Microsoft Office\Office16\1033\PROTTPLV.XLS
- C:\Program Files\Microsoft Office\Office16\SAMPLES\SOLVSAMP.XLS
- C:\Windows\SysWOW64\MSDRM\MsoIrmProtector.xls
- C:\Windows\WinSxS\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.1697_none_5b402724c75d80d6\MsoIrmProtector.xls
- C:\Windows\WinSxS\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.5830_none_5b252ca0c77261e3\MsoIrmProtector.xls
- C:\Windows\WinSxS\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.1697_none_6594d176fbbe42d1\MsoIrmProtector.xls
- C:\Windows\WinSxS\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.5830_none_6579d6f2fbd323de\MsoIrmProtector.xls
- C:\Windows\System32\MSDRM\MsoIrmProtector.xls
- C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~17763.6893.1.6\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.5830_none_6579d6f2fbd323de\r\msoirmprotector.xls
- C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~17763.6893.1.6\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.5830_none_6579d6f2fbd323de\f\msoirmprotector.xls
- C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~17763.6893.1.6\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.5830_none_5b252ca0c77261e3\r\msoirmprotector.xls
- C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~17763.6893.1.6\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.5830_none_5b252ca0c77261e3\f\msoirmprotector.xls
- C:\ShCti\DST_PBX_Support.xls
- C:\Users\Administrator\Documents\LKP_ClientDetails_new.xlsx
- C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~17763.6893.1.6\amd64_microsoft-windows-hvsi-office_31bf3856ad364e35_10.0.17763.2989_none_b92210e4eb27bace\f\wdagplaceholder.xlsx
- C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~17763.6893.1.6\amd64_microsoft-windows-hvsi-office_31bf3856ad364e35_10.0.17763.2989_none_b92210e4eb27bace\r\wdagplaceholder.xlsx
- C:\Windows\SHELLNEW\EXCEL12.XLSX
- C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~17763.6893.1.6\amd64_microsoft-windows-hvsi-office_31bf3856ad364e35_10.0.17763.2989_none_b92210e4eb27bace\f\wdagplaceholder.docx
- C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~17763.6893.1.6\amd64_microsoft-windows-hvsi-office_31bf3856ad364e35_10.0.17763.2989_none_b92210e4eb27bace\r\wdagplaceholder.docx
- C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~17763.6893.1.6\amd64_microsoft-windows-hvsi-office_31bf3856ad364e35_10.0.17763.2989_none_b92210e4eb27bace\f\wdagplaceholder.pptx
- C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~17763.6893.1.6\amd64_microsoft-windows-hvsi-office_31bf3856ad364e35_10.0.17763.2989_none_b92210e4eb27bace\r\wdagplaceholder.pptx
11777 - Microsoft Windows SMB Share Hosting Possibly Copyrighted Material
-
Synopsis
The remote host may contain material (movies/audio) infringing copyright.
Description
This plugin displays a list of media files (such as .mp3, .ogg, .mpg, .avi) which have been found on the remote SMB shares.

Some of these files may contain copyrighted materials, such as commercial movies or music files, that are being shared without the owner's permission.

If any of these files actually contain copyrighted material, and if they are freely swapped around, your organization might be held liable for copyright infringement by associations such as the RIAA or the MPAA.
Solution
Delete the files infringing copyright.
Risk Factor
None
Plugin Information
Published: 2003/06/26, Modified: 2012/11/29
Plugin Output

tcp/445/cifs


Here is a list of files which have been found on the remote SMB shares.
Some of these files may contain copyrighted materials, such as commercial
movies or music files.

+ D$ :

D:\Nexsus\Backup\0306_Engine\CallBalance\callalert.mp3
D:\Nexsus\Backup\0306_Engine\CallBalance\Recordings\E23 M1001 05-29-25 09=53=13 IN 917738258525 UID10215 C6390 1000001441 D41.mp3
D:\Nexsus\Backup\0409_2025\CallBalance\callalert.mp3
D:\Nexsus\Backup\18092025\CallBalance\callalert.mp3
D:\Nexsus\Backup\18092025\CallBalance\Recordings\E23 M1001 08-07-25 23=27=03 OUT 09820135360 C6390 U10261 1000002195 SD.mp3
D:\Nexsus\Backup\2005\CallBalance\callalert.mp3
D:\Nexsus\Backup\2005\CallBalance\Recordings\E23 M1001 04-25-25 12=08=51 IN 918657335158 UID10219 C6390 1000001073 D50.mp3
D:\Nexsus\Backup\2205\CallBalance\callalert.mp3
D:\Nexsus\CallBalance\Recordings\E202 M1001 12-01-25 09=21=14 IN 9920014394 UID10343 C6390 1000041374 D214.mp3
D:\Nexsus\CallBalance_HTTPS - Copy\callalert.mp3
D:\Nexsus\CallBalance_HTTPS - Copy\Recordings\E101 M1001 10-14-25 08=44=14 IN 919820343476 UID10343 C6390 1000011634 D16.mp3
D:\Nexsus\CallBalance_HTTPS - Copy\Recordings\E25 M1001 09-01-25 09=22=33 OUT 09820040619 C6390 U10216 1000003118 SD.mp3
D:\Nexsus\CallBalance_HTTPS\callalert.mp3
D:\Nexsus\CallBalance_HTTPS\Recordings\E101 M1001 10-14-25 08=44=14 IN 919820343476 UID10343 C6390 1000011634 D16.mp3
D:\Nexsus\Nexsus_Patch\Patch\CallBalance_LKP_20122024\CallBalance_LKP\callalert.mp3
D:\Nexsus\Nexsus_Patch\Patch\CallBalance_LKP_16122024\CallBalance_LKP\callalert.mp3
D:\Nexsus\Nexsus_Patch\Patch\CallBalance - Copy\callalert.mp3
D:\Nexsus\CallBalance_HTTPS\Recordings\E25 M1001 09-01-25 09=22=33 OUT 09820040619 C6390 U10216 1000003118 SD.mp3
D:\Nexsus\CallBalance_HTTPS\Recordings\E181 M1001 11-13-25 10=55=28 OUT 09840159665 C6390 U10393 1000031778 SD.mp3
D:\Nexsus\CallBalance\callalert.mp3
D:\Nexsus\Backup\MainBackup\CallBalance\Recordings\E23 M1001 08-07-25 23=27=03 OUT 09820135360 C6390 U10261 1000002195 SD.mp3
D:\Nexsus\Backup\MainBackup\CallBalance\callalert.mp3
D:\Nexsus\Backup\Backup2908\CallBalance\Recordings\E23 M1001 08-07-25 23=27=03 OUT 09820135360 C6390 U10261 1000002195 SD.mp3
D:\Nexsus\Backup\Backup2908\CallBalance\callalert.mp3
D:\Nexsus\Backup\2205\CallBalance\Recordings\E23 M1001 04-25-25 12=08=51 IN 918657335158 UID10219 C6390 1000001073 D50.mp3
D:\Nexsus\Backup\10092025\CallBalance\Recordings\E23 M1001 08-07-25 23=27=03 OUT 09820135360 C6390 U10261 1000002195 SD.mp3
D:\Nexsus\Backup\10092025\CallBalance\callalert.mp3
D:\Nexsus\Backup\06082025\CallBalance\Recordings\E24 M1001 06-12-25 10=42=09 OUT 09561444365 C6390 U10258 1000001567 SD.mp3
D:\Nexsus\Backup\06082025\CallBalance\callalert.mp3
D:\Nexsus\Backup\0409_2025\CallBalance\Recordings\E23 M1001 08-07-25 23=27=03 OUT 09820135360 C6390 U10261 1000002195 SD.mp3

60119 - Microsoft Windows SMB Share Permissions Enumeration
-
Synopsis
It was possible to enumerate the permissions of remote network shares.
Description
By using the supplied credentials, Nessus was able to enumerate the permissions of network shares. User permissions are enumerated for each network share that has a list of access control entries (ACEs).
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2012/07/25, Modified: 2022/08/11
Plugin Output

tcp/445/cifs


Share path : \\LKP_SIP_APPSRV-\CallbalanceVoiceLogs
Local path : D:\CallbalanceVoiceLogs
[*] Allow ACE for BUILTIN\Administrators (S-1-5-32-544): 0x001f01ff
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: YES
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: YES
FILE_ADD_FILE: YES
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: YES
DELETE: YES
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: YES
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: YES
FILE_CREATE_PIPE_INSTANCE: YES
FILE_WRITE_ATTRIBUTES: YES
[*] Allow ACE for Everyone (S-1-1-0): 0x001f01ff
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: YES
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: YES
FILE_ADD_FILE: YES
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: YES
DELETE: YES
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: YES
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: YES
FILE_CREATE_PIPE_INSTANCE: YES
FILE_WRITE_ATTRIBUTES: YES
10396 - Microsoft Windows SMB Shares Access
-
Synopsis
It is possible to access a network share.
Description
The remote has one or more Windows shares that can be accessed through the network with the given credentials.

Depending on the share rights, it may allow an attacker to read / write confidential data.
Solution
To restrict access under Windows, open Explorer, do a right click on each share, go to the 'sharing' tab, and click on 'permissions'.
Risk Factor
None
Plugin Information
Published: 2000/05/09, Modified: 2021/10/04
Plugin Output

tcp/445/cifs


The following shares can be accessed as tidua :

- D$ - (readable,writable)
+ Content of this share :
CallbalanceVoiceLogs
LKPSOFT
Nexsus
SECURITY LOGS 14012026.csv
SETUP LOGS 14012026.csv
SYSTEM EVT14012026.csv
SYSTEM LOGS 14012026.csv
System Volume Information
TIME LOGS 14012026.csv
Wiresharl Logs

- CallbalanceVoiceLogs - (readable,writable)
+ Content of this share :
..
Diskless
Diskless - Copy
Diskless - Copy1
Hidden
LKP Summary.xlsx
Processed
UnRecorded
Voice
Voice.zip

- C$ - (readable,writable)
+ Content of this share :
CallbalanceEngineLog
CallbalanceWeb
Documents and Settings
EmailServiceLog
inetpub
LKP
MaxDialEngineLog
MSOCache
pagefile.sys
PerfLogs
Program Files
Program Files (x86)
ProgramData
Recovery
Reliance
ServiceLog
ShCti
System Volume Information
Users
UserStatusValidationService
UserValidatotStatus
Windows

- ADMIN$ - (readable,writable)
+ Content of this share :
..
000030FE_00000001.dll
4713_16DPC+stp-mtp3.dll
ADFS
aksdrvsetup.log
appcompat
apppatch
AppReadiness
assembly
bcastdvr
bfsvc.exe
bmputil.dll
Boot
bootstat.dat
Branding
CbsTemp
CKM.dll
Containers
CSC
Cursors
debug
DfsrAdmin.exe
DfsrAdmin.exe.config
diagnostics
DigitalLocker
Downloaded Program Files
DPINST.LOG
drivers
DSTDecode.dll
DtcInstall.log
ELAMBKUP
en-US
explorer.exe
Fonts
g729a.dll
Globalization
h323dll.dll
hasp_windows.dll
hasp_windows64.dll
Help
HelpPane.exe
hh.exe
HMPLink.dll
HMPRouter.dll
HMPRTPC.dll
HMPVirtualDevice.dll
IdentityCRL
iis.log
IME
ImmersiveControlPanel
INF
InputMethod
Installer
IPAnalyzer.dll
IPV6.dll
IsdnUser.dll
L2Schemas
libcurl.dll
libeay32.dll
LiveKernelReports
Logs
lsasetup.log
M537.dll
macmcvt.dll
media
MGCPDecode.dll
mib.bin
Microsoft.NET
Migration
MMFClnt.dll
MmfServer.dll
ModemLogs
msvcr120.dll
mtp3.dll
notepad.exe
OCR
Oct.dll
oct2200.img
Offline Web Pages
OpenDHCPServer.exe
OpenTFTPServerMT.exe
Panther
PCHEALTH
Performance
PFRO.log
PLA
PolicyDefinitions
10395 - Microsoft Windows SMB Shares Enumeration
-
Synopsis
It is possible to enumerate remote network shares.
Description
By connecting to the remote host, Nessus was able to enumerate the network share names.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2000/05/09, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Here are the SMB shares available on the remote host when logged in as tidua:

- ADMIN$
- C$
- CallbalanceVoiceLogs
- D$
- IPC$
100871 - Microsoft Windows SMB Versions Supported (remote check)
-
Synopsis
It was possible to obtain information about the version of SMB running on the remote host.
Description
Nessus was able to obtain the version of SMB running on the remote host by sending an authentication request to port 139 or 445.

Note that this plugin is a remote check and does not work on agents.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2017/06/19, Modified: 2019/11/22
Plugin Output

tcp/445/cifs


The remote host supports the following versions of SMB :
SMBv2
106716 - Microsoft Windows SMB2 and SMB3 Dialects Supported (remote check)
-
Synopsis
It was possible to obtain information about the dialects of SMB2 and SMB3 available on the remote host.
Description
Nessus was able to obtain the set of SMB2 and SMB3 dialects running on the remote host by sending an authentication request to port 139 or 445.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2018/02/09, Modified: 2020/03/11
Plugin Output

tcp/445/cifs


The remote host supports the following SMB dialects :
_version_ _introduced in windows version_
2.0.2 Windows 2008
2.1 Windows 7
3.0 Windows 8
3.0.2 Windows 8.1
3.1.1 Windows 10

The remote host does NOT support the following SMB dialects :
_version_ _introduced in windows version_
2.2.2 Windows 8 Beta
2.2.4 Windows 8 Beta
3.1 Windows 10

92368 - Microsoft Windows Scripting Host Settings
-
Synopsis
Nessus was able to collect and report the Windows scripting host settings from the remote host.
Description
Nessus was able to collect system and user level Windows scripting host settings from the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings\displaylogo : 1
HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings\usewinsafer : 1
HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings\silentterminate : 0
HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings\activedebugging : 1
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\displaylogo : 1
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\usewinsafer : 1
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\silentterminate : 0
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\activedebugging : 1

Windows scripting host configuration attached.

58452 - Microsoft Windows Startup Software Enumeration
-
Synopsis
It is possible to enumerate startup software.
Description
This plugin lists software that is configured to run on system startup by crawling the registry entries in :

- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersi on\Run
Solution
Review the list of applications and remove any that are not compliant with your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2012/03/23, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


The following startup item was found :

SecurityHealth - %windir%\system32\SecurityHealthSystray.exe
VMware User Process - C:\Program Files\VMware\VMware Tools\vmtoolsd.exe
38153 - Microsoft Windows Summary of Missing Patches
-
Synopsis
The remote host is missing several Microsoft security patches.
Description
This plugin summarizes updates for Microsoft Security Bulletins or Knowledge Base (KB) security updates that have not been installed on the remote Windows host based on the results of either a credentialed check using the supplied credentials or a check done using a supported third-party patch management tool.

Note the results of missing patches also include superseded patches.

Review the summary and apply any missing updates in order to be up to date.
Solution
Run Windows Update on the remote host or use a patch management solution.
Risk Factor
None
Plugin Information
Published: 2009/04/24, Modified: 2019/06/13
Plugin Output

tcp/445/cifs

The patches for the following bulletins or KBs are missing on the remote host :

- MS13-002 ( http://technet.microsoft.com/en-us/security/bulletin/ms13-002 )
- MS15-081 ( http://technet.microsoft.com/en-us/security/bulletin/ms15-081 )
- MS15-099 ( http://technet.microsoft.com/en-us/security/bulletin/ms15-099 )
- MS15-110 ( http://technet.microsoft.com/en-us/security/bulletin/ms15-110 )
- MS15-116 ( http://technet.microsoft.com/en-us/security/bulletin/ms15-116 )
- MS15-131 ( http://technet.microsoft.com/en-us/security/bulletin/ms15-131 )
- MS16-004 ( http://technet.microsoft.com/en-us/security/bulletin/ms16-004 )
- MS16-015 ( http://technet.microsoft.com/en-us/security/bulletin/ms16-015 )
- MS16-029 ( http://technet.microsoft.com/en-us/security/bulletin/ms16-029 )
- MS16-042 ( http://technet.microsoft.com/en-us/security/bulletin/ms16-042 )
- MS16-054 ( http://technet.microsoft.com/en-us/security/bulletin/ms16-054 )
- MS16-070 ( http://technet.microsoft.com/en-us/security/bulletin/ms16-070 )
- MS16-088 ( http://technet.microsoft.com/en-us/security/bulletin/ms16-088 )
- MS16-099 ( http://technet.microsoft.com/en-us/security/bulletin/ms16-099 )
- MS16-107 ( http://technet.microsoft.com/en-us/security/bulletin/ms16-107 )
- MS16-121 ( http://technet.microsoft.com/en-us/security/bulletin/ms16-121 )
- MS16-133 ( http://technet.microsoft.com/en-us/security/bulletin/ms16-133 )
- MS16-148 ( http://technet.microsoft.com/en-us/security/bulletin/ms16-148 )
- MS17-002 ( http://technet.microsoft.com/en-us/security/bulletin/ms17-002 )
- MS17-014 ( http://technet.microsoft.com/en-us/security/bulletin/ms17-014 )
- KB3178664 ( https://support.microsoft.com/en-us/help/3178664 )
- KB3178702 ( https://support.microsoft.com/en-us/help/3178702 )
- KB3178703 ( https://support.microsoft.com/en-us/help/3178703 )
- KB3191863 ( https://support.microsoft.com/en-us/help/3191863 )
- KB3191865 ( https://support.microsoft.com/en-us/help/3191865 )
- KB3191881 ( https://support.microsoft.com/en-us/help/3191881 )
- KB3178667 ( https://support.microsoft.com/en-us/help/3178667 )
- KB3191882 ( https://support.microsoft.com/en-us/help/3191882 )
- KB3191932 ( https://support.microsoft.com/en-us/help/3191932 )
- KB3191944 ( https://support.microsoft.com/en-us/help/3191944 )
- KB3191945 ( https://support.microsoft.com/en-us/help/3191945 )
- KB3203383 ( https://support.microsoft.com/en-us/help/3203383 )
- KB3203477 ( https://support.microsoft.com/en-us/help/3203477 )
- KB3213545 ( https://support.microsoft.com/en-us/help/3213545 )
- KB4011052 ( https://support.microsoft.com/en-us/help/4011052 )
- KB3213551 ( https://support.microsoft.com/en-us/help/3213551 )
- KB4011038 ( https://support.microsoft.com/en-us/help/4011038 )
- KB4011041 ( https://support.microsoft.com/en-us/help/4011041 )
- KB4011050 ( https://support.microsoft.com/en-us/help/4011050 )
- KB4011091 ( https://support.microsoft.com/en-us/help/4011091 )
- KB4011126 ( https://support.microsoft.com/en-us/help/4011126 )
- KB2920723 ( https://support.microsoft.com/en-us/help/2920723 )
- KB4011162 ( https://support.microsoft.com/en-us/help/4011162 )
- KB4011185 ( https://support.microsoft.com/en-us/help/4011185 )
- KB4011222 ( https://support.microsoft.com/en-us/help/4011222 )
- KB4011220 ( https://support.microsoft.com/en-us/help/4011220 )
- KB4011242 ( https://support.microsoft.com/en-us/help/4011242 )
- KB4011262 ( https://support.microsoft.com/en-us/help/4011262 )
- KB4011575 ( https://support.microsoft.com/en-us/help/4011575 )
- KB4011574 ( https://support.microsoft.com/en-us/help/4011574 )
- KB4011622 ( https://support.microsoft.com/en-us/help/4011622 )
- KB4011626 ( https://support.microsoft.com/en-us/help/4011626 )
- KB4011627 ( https://support.microsoft.com/en-us/help/4011627 )
- KB4011632 ( https://support.microsoft.com/en-us/help/4011632 )
- KB4011643 ( https://support.microsoft.com/en-us/help/4011643 )
- KB4011143 ( https://support.microsoft.com/en-us/help/4011143 )
- KB4011682 ( https://support.microsoft.com/en-us/help/4011682 )
- KB4011686 ( https://support.microsoft.com/en-us/help/4011686 )
- KB4011730 ( https://support.microsoft.com/en-us/help/4011730 )
- KB4018328 ( https://support.microsoft.com/en-us/help/4018328 )
- KB4018337 ( https://support.microsoft.com/en-us/help/4018337 )
- KB4018339 ( https://support.microsoft.com/en-us/help/4018339 )
- KB4018327 ( https://support.microsoft.com/en-us/help/4018327 )
- KB4018382 ( https://support.microsoft.com/en-us/help/4018382 )
- KB4018383 ( https://support.microsoft.com/en-us/help/4018383 )
- KB4022160 ( https://support.microsoft.com/en-us/help/4022160 )
- KB4022174 ( https://support.microsoft.com/en-us/help/4022174 )
- KB4022177 ( https://support.microsoft.com/en-us/help/4022177 )
- KB4022218 ( https://support.microsoft.com/en-us/help/4022218 )
- KB4032229 ( https://support.microsoft.com/en-us/help/4032229 )
- KB4032233 ( https://support.microsoft.com/en-us/help/4032233 )
- KB4032235 ( https://support.microsoft.com/en-us/help/4032235 )
- KB4092447 ( https://support.microsoft.com/en-us/help/4092447 )
- KB4092460 ( https://support.microsoft.com/en-us/help/4092460 )
- KB4461434 ( https://support.microsoft.com/en-us/help/4461434 )
- KB4461437 ( https://support.microsoft.com/en-us/help/4461437 )
- KB4461440 ( https://support.microsoft.com/en-us/help/4461440 )
- KB4461448 ( https://support.microsoft.com/en-us/help/4461448 )
- KB4461449 ( https://support.microsoft.com/en-us/help/4461449 )
- KB4022232 ( https://support.microsoft.com/en-us/help/4022232 )
- KB4461503 ( https://support.microsoft.com/en-us/help/4461503 )
- KB4461504 ( https://support.microsoft.com/en-us/help/4461504 )
- KB4461506 ( https://support.microsoft.com/en-us/help/4461506 )
- KB4461532 ( https://support.microsoft.com/en-us/help/4461532 )
- KB4461542 ( https://support.microsoft.com/en-us/help/4461542 )
- KB4461544 ( https://support.microsoft.com/en-us/help/4461544 )
- KB4022162 ( https://support.microsoft.com/en-us/help/4022162 )
- KB4461535 ( https://support.microsoft.com/en-us/help/4461535 )
- KB4461543 ( https://support.microsoft.com/en-us/help/4461543 )
- KB4461601 ( https://support.microsoft.com/en-us/help/4461601 )
- KB4018294 ( https://support.microsoft.com/en-us/help/4018294 )
- KB4462115 ( https://support.microsoft.com/en-us/help/4462115 )
- KB4462146 ( https://support.microsoft.com/en-us/help/4462146 )
- KB4462213 ( https://support.microsoft.com/en-us/help/4462213 )
- KB4462236 ( https://support.microsoft.com/en-us/help/4462236 )
- KB4462242 ( https://support.microsoft.com/en-us/help/4462242 )
- KB4464536 ( https://support.microsoft.com/en-us/help/4464536 )
- KB4464551 ( https://support.microsoft.com/en-us/help/4464551 )
- KB4464596 ( https://support.microsoft.com/en-us/help/4464596 )
- KB4461539 ( https://support.microsoft.com/en-us/help/4461539 )
- KB4464534 ( https://support.microsoft.com/en-us/help/4464534 )
- KB4475513 ( https://support.microsoft.com/en-us/help/4475513 )
- KB4475514 ( https://support.microsoft.com/en-us/help/4475514 )
- KB4475517 ( https://support.microsoft.com/en-us/help/4475517 )
- KB4475538 ( https://support.microsoft.com/en-us/help/4475538 )
- KB4475540 ( https://support.microsoft.com/en-us/help/4475540 )
- KB4475553 ( https://support.microsoft.com/en-us/help/4475553 )
- KB4475579 ( https://support.microsoft.com/en-us/help/4475579 )
- KB4475583 ( https://support.microsoft.com/en-us/help/4475583 )
- KB4475591 ( https://support.microsoft.com/en-us/help/4475591 )
- KB4484112 ( https://support.microsoft.com/en-us/help/4484112 )
- KB4484113 ( https://support.microsoft.com/en-us/help/4484113 )
- KB4484144 ( https://support.microsoft.com/en-us/help/4484144 )
- KB4484148 ( https://support.microsoft.com/en-us/help/4484148 )
- KB4484166 ( https://support.microsoft.com/en-us/help/4484166 )
- KB4484169 ( https://support.microsoft.com/en-us/help/4484169 )
- KB4484179 ( https://support.microsoft.com/en-us/help/4484179 )
- KB4484180 ( https://support.microsoft.com/en-us/help/4484180 )
- KB4484182 ( https://support.microsoft.com/en-us/help/4484182 )
- KB4484217 ( https://support.microsoft.com/en-us/help/4484217 )
- KB4484221 ( https://support.microsoft.com/en-us/help/4484221 )
- KB4484250 ( https://support.microsoft.com/en-us/help/4484250 )
- KB4484256 ( https://support.microsoft.com/en-us/help/4484256 )
- KB4484268 ( https://support.microsoft.com/en-us/help/4484268 )
- KB3128012 ( https://support.microsoft.com/en-us/help/3128012 )
- KB4011097 ( https://support.microsoft.com/en-us/help/4011097 )
- KB4484214 ( https://support.microsoft.com/en-us/help/4484214 )
- KB4484246 ( https://support.microsoft.com/en-us/help/4484246 )
- KB4484258 ( https://support.microsoft.com/en-us/help/4484258 )
- KB4484273 ( https://support.microsoft.com/en-us/help/4484273 )
- KB4484274 ( https://support.microsoft.com/en-us/help/4484274 )
- KB4484287 ( https://support.microsoft.com/en-us/help/4484287 )
- KB4484300 ( https://support.microsoft.com/en-us/help/4484300 )
- KB4484338 ( https://support.microsoft.com/en-us/help/4484338 )
- KB4484342 ( https://support.microsoft.com/en-us/help/4484342 )
- KB4484396 ( https://support.microsoft.com/en-us/help/4484396 )
- KB4484403 ( https://support.microsoft.com/en-us/help/4484403 )
- KB4484433 ( https://support.microsoft.com/en-us/help/4484433 )
- KB4484438 ( https://support.microsoft.com/en-us/help/4484438 )
- KB4484346 ( https://support.microsoft.com/en-us/help/4484346 )
- KB4484431 ( https://support.microsoft.com/en-us/help/4484431 )
- KB4484465 ( https://support.microsoft.com/en-us/help/4484465 )
- KB4484475 ( https://support.microsoft.com/en-us/help/4484475 )
- KB4484466 ( https://support.microsoft.com/en-us/help/4484466 )
- KB4484507 ( https://support.microsoft.com/en-us/help/4484507 )
- KB4484510 ( https://support.microsoft.com/en-us/help/4484510 )
- KB4484513 ( https://support.microsoft.com/en-us/help/4484513 )
- KB4484417 ( https://support.microsoft.com/en-us/help/4484417 )
- KB4486671 ( https://support.microsoft.com/en-us/help/4486671 )
- KB4486678 ( https://support.microsoft.com/en-us/help/4486678 )
- KB4486679 ( https://support.microsoft.com/en-us/help/4486679 )
- KB4486682 ( https://support.microsoft.com/en-us/help/4486682 )
- KB4484508 ( https://support.microsoft.com/en-us/help/4484508 )
- KB4486718 ( https://support.microsoft.com/en-us/help/4486718 )
- KB4486719 ( https://support.microsoft.com/en-us/help/4486719 )
- KB4486722 ( https://support.microsoft.com/en-us/help/4486722 )
- KB4486748 ( https://support.microsoft.com/en-us/help/4486748 )
- KB4486754 ( https://support.microsoft.com/en-us/help/4486754 )
- KB4486757 ( https://support.microsoft.com/en-us/help/4486757 )
- KB4486755 ( https://support.microsoft.com/en-us/help/4486755 )
- KB4493156 ( https://support.microsoft.com/en-us/help/4493156 )
- KB4493165 ( https://support.microsoft.com/en-us/help/4493165 )
- KB4493168 ( https://support.microsoft.com/en-us/help/4493168 )
- KB4493196 ( https://support.microsoft.com/en-us/help/4493196 )
- KB4493224 ( https://support.microsoft.com/en-us/help/4493224 )
- KB4493233 ( https://support.microsoft.com/en-us/help/4493233 )
- KB4493198 ( https://support.microsoft.com/en-us/help/4493198 )
- KB4504712 ( https://support.microsoft.com/en-us/help/4504712 )
- KB4504721 ( https://support.microsoft.com/en-us/help/4504721 )
- KB4504722 ( https://support.microsoft.com/en-us/help/4504722 )
- KB4504724 ( https://support.microsoft.com/en-us/help/4504724 )
- KB4493197 ( https://support.microsoft.com/en-us/help/4493197 )
- KB5001918 ( https://support.microsoft.com/en-us/help/5001918 )
- KB5001919 ( https://support.microsoft.com/en-us/help/5001919 )
- KB5001920 ( https://support.microsoft.com/en-us/help/5001920 )
- KB5001923 ( https://support.microsoft.com/en-us/help/5001923 )
- KB5001947 ( https://support.microsoft.com/en-us/help/5001947 )
- KB5001950 ( https://support.microsoft.com/en-us/help/5001950 )
- KB5001951 ( https://support.microsoft.com/en-us/help/5001951 )
- KB5001949 ( https://support.microsoft.com/en-us/help/5001949 )
- KB5001977 ( https://support.microsoft.com/en-us/help/5001977 )
- KB5001979 ( https://support.microsoft.com/en-us/help/5001979 )
- KB4484103 ( https://support.microsoft.com/en-us/help/4484103 )
- KB5001997 ( https://support.microsoft.com/en-us/help/5001997 )
- KB5002003 ( https://support.microsoft.com/en-us/help/5002003 )
- KB5002005 ( https://support.microsoft.com/en-us/help/5002005 )
- KB4461476 ( https://support.microsoft.com/en-us/help/4461476 )
- KB5001982 ( https://support.microsoft.com/en-us/help/5001982 )
- KB5002004 ( https://support.microsoft.com/en-us/help/5002004 )
- KB5002030 ( https://support.microsoft.com/en-us/help/5002030 )
- KB5002056 ( https://support.microsoft.com/en-us/help/5002056 )
- KB4504710 ( https://support.microsoft.com/en-us/help/4504710 )
- KB4504745 ( https://support.microsoft.com/en-us/help/4504745 )
- KB5002033 ( https://support.microsoft.com/en-us/help/5002033 )
- KB5002098 ( https://support.microsoft.com/en-us/help/5002098 )
- KB5002099 ( https://support.microsoft.com/en-us/help/5002099 )
- KB5002052 ( https://support.microsoft.com/en-us/help/5002052 )
- KB5002057 ( https://support.microsoft.com/en-us/help/5002057 )
- KB5002060 ( https://support.microsoft.com/en-us/help/5002060 )
- KB5002114 ( https://support.microsoft.com/en-us/help/5002114 )
- KB5002115 ( https://support.microsoft.com/en-us/help/5002115 )
- KB5002116 ( https://support.microsoft.com/en-us/help/5002116 )
- KB3118335 ( https://support.microsoft.com/en-us/help/3118335 )
- KB5002137 ( https://support.microsoft.com/en-us/help/5002137 )
- KB5002140 ( https://support.microsoft.com/en-us/help/5002140 )
- KB5002139 ( https://support.microsoft.com/en-us/help/5002139 )
- KB5002143 ( https://support.microsoft.com/en-us/help/5002143 )
- KB5002177 ( https://support.microsoft.com/en-us/help/5002177 )
- KB4493152 ( https://support.microsoft.com/en-us/help/4493152 )
- KB5002184 ( https://support.microsoft.com/en-us/help/5002184 )
- KB5002196 ( https://support.microsoft.com/en-us/help/5002196 )
- KB5002208 ( https://support.microsoft.com/en-us/help/5002208 )
- KB5002051 ( https://support.microsoft.com/en-us/help/5002051 )
- KB5002208 ( https://support.microsoft.com/en-us/help/5002208 )
- KB5002223 ( https://support.microsoft.com/en-us/help/5002223 )
- KB5002253 ( https://support.microsoft.com/en-us/help/5002253 )
- KB5002323 ( https://support.microsoft.com/en-us/help/5002323 )
- KB5002254 ( https://support.microsoft.com/en-us/help/5002254 )
- KB5002351 ( https://support.microsoft.com/en-us/help/5002351 )
- KB5002221 ( https://support.microsoft.com/en-us/help/5002221 )
- KB5002369 ( https://support.microsoft.com/en-us/help/5002369 )
- KB5002386 ( https://support.microsoft.com/en-us/help/5002386 )
- KB5002387 ( https://support.microsoft.com/en-us/help/5002387 )
- KB5002405 ( https://support.microsoft.com/en-us/help/5002405 )
- KB5002406 ( https://support.microsoft.com/en-us/help/5002406 )
- KB5002426 ( https://support.microsoft.com/en-us/help/5002426 )
- KB5002427 ( https://support.microsoft.com/en-us/help/5002427 )
- KB4504720 ( https://support.microsoft.com/en-us/help/4504720 )
- KB5002459 ( https://support.microsoft.com/en-us/help/5002459 )
- KB5002462 ( https://support.microsoft.com/en-us/help/5002462 )
- KB5002463 ( https://support.microsoft.com/en-us/help/5002463 )
- KB5002464 ( https://support.microsoft.com/en-us/help/5002464 )
- KB5002496 ( https://support.microsoft.com/en-us/help/5002496 )
- KB5002497 ( https://support.microsoft.com/en-us/help/5002497 )
- KB5002499 ( https://support.microsoft.com/en-us/help/5002499 )
- KB5002518 ( https://support.microsoft.com/en-us/help/5002518 )
- KB5002520 ( https://support.microsoft.com/en-us/help/5002520 )
- KB5002529 ( https://support.microsoft.com/en-us/help/5002529 )
- KB5002492 ( https://support.microsoft.com/en-us/help/5002492 )
- KB5002495 ( https://support.microsoft.com/en-us/help/5002495 )
- KB5002536 ( https://support.microsoft.com/en-us/help/5002536 )
- KB5002542 ( https://support.microsoft.com/en-us/help/5002542 )
- KB5002543 ( https://support.microsoft.com/en-us/help/5002543 )
- KB5002587 ( https://support.microsoft.com/en-us/help/5002587 )
- KB5002600 ( https://support.microsoft.com/en-us/help/5002600 )
- KB5002621 ( https://support.microsoft.com/en-us/help/5002621 )
- KB5002586 ( https://support.microsoft.com/en-us/help/5002586 )
- KB5002626 ( https://support.microsoft.com/en-us/help/5002626 )
- KB5002566 ( https://support.microsoft.com/en-us/help/5002566 )
- KB5002605 ( https://support.microsoft.com/en-us/help/5002605 )
- KB5002643 ( https://support.microsoft.com/en-us/help/5002643 )
- KB5002619 ( https://support.microsoft.com/en-us/help/5002619 )
- KB5002653 ( https://support.microsoft.com/en-us/help/5002653 )
- KB5002660 ( https://support.microsoft.com/en-us/help/5002660 )
- KB5002656 ( https://support.microsoft.com/en-us/help/5002656 )
- KB5002673 ( https://support.microsoft.com/en-us/help/5002673 )
- KB5002687 ( https://support.microsoft.com/en-us/help/5002687 )
- KB5002662 ( https://support.microsoft.com/en-us/help/5002662 )
- KB5002696 ( https://support.microsoft.com/en-us/help/5002696 )
- KB5053596 ( https://support.microsoft.com/en-us/help/5053596 )
- KB5002622 ( https://support.microsoft.com/en-us/help/5002622 )
- KB5002702 ( https://support.microsoft.com/en-us/help/5002702 )
- KB5002704 ( https://support.microsoft.com/en-us/help/5002704 )
- KB5055519 ( https://support.microsoft.com/en-us/help/5055519 )
- KB5002717 ( https://support.microsoft.com/en-us/help/5002717 )
- KB5058392 ( https://support.microsoft.com/en-us/help/5058392 )
- KB5002683 ( https://support.microsoft.com/en-us/help/5002683 )
- KB5002689 ( https://support.microsoft.com/en-us/help/5002689 )
- KB5002710 ( https://support.microsoft.com/en-us/help/5002710 )
- KB5002735 ( https://support.microsoft.com/en-us/help/5002735 )
- KB5060531 ( https://support.microsoft.com/en-us/help/5060531 )
- KB5002745 ( https://support.microsoft.com/en-us/help/5002745 )
- KB5002746 ( https://support.microsoft.com/en-us/help/5002746 )
- KB5002747 ( https://support.microsoft.com/en-us/help/5002747 )
- KB5002749 ( https://support.microsoft.com/en-us/help/5002749 )
- KB5062557 ( https://support.microsoft.com/en-us/help/5062557 )
- KB5002758 ( https://support.microsoft.com/en-us/help/5002758 )
- KB5002763 ( https://support.microsoft.com/en-us/help/5002763 )
- KB5002765 ( https://support.microsoft.com/en-us/help/5002765 )
- KB5063877 ( https://support.microsoft.com/en-us/help/5063877 )
- KB5002779 ( https://support.microsoft.com/en-us/help/5002779 )
- KB5002780 ( https://support.microsoft.com/en-us/help/5002780 )
- KB5002782 ( https://support.microsoft.com/en-us/help/5002782 )
- KB5065428 ( https://support.microsoft.com/en-us/help/5065428 )
- KB5002789 ( https://support.microsoft.com/en-us/help/5002789 )
- KB5002790 ( https://support.microsoft.com/en-us/help/5002790 )
- KB5002794 ( https://support.microsoft.com/en-us/help/5002794 )
- KB5066586 ( https://support.microsoft.com/en-us/help/5066586 )
- KB5002811 ( https://support.microsoft.com/en-us/help/5002811 )
- KB5068791 ( https://support.microsoft.com/en-us/help/5068791 )
- KB5002806 ( https://support.microsoft.com/en-us/help/5002806 )
- KB5002820 ( https://support.microsoft.com/en-us/help/5002820 )
- KB5071544 ( https://support.microsoft.com/en-us/help/5071544 )

92369 - Microsoft Windows Time Zone Information
-
Synopsis
Nessus was able to collect and report time zone information from the remote host.
Description
Nessus was able to collect time zone information from the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2023/06/06
Plugin Output

tcp/0

HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\TimeZoneKeyName : India Standard Time
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\StandardName : @tzres.dll,-492
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\DaylightName : @tzres.dll,-491
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\DynamicDaylightTimeDisabled : 0x00000000
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\StandardBias : 0x00000000
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\DaylightBias : 0x00000000
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\Bias : 0xFFFFFEB6
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\ActiveTimeBias : 0xFFFFFEB6
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\DaylightStart : 00000000000000000000000000000000
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\StandardStart : 00000000000000000000000000000000
19506 - Nessus Scan Information
-
Synopsis
This plugin displays information about the Nessus scan.
Description
This plugin displays, for each tested host, information about the scan itself :

- The version of the plugin set.
- The type of scanner (Nessus or Nessus Home).
- The version of the Nessus Engine.
- The port scanner(s) used.
- The port range scanned.
- The ping round trip time
- Whether credentialed or third-party patch management checks are possible.
- Whether the display of superseded patches is enabled
- The date of the scan.
- The duration of the scan.
- The number of hosts scanned in parallel.
- The number of checks done in parallel.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2005/08/26, Modified: 2025/10/29
Plugin Output

tcp/0

Information about this scan :

Nessus version : 10.11.1
Nessus build : 20021
Plugin feed version : 202601041845
Scanner edition used : Nessus
Scanner OS : WINDOWS
Scanner distribution : win-x86-64
Scan type : Normal
Scan name : Server 5
Scan policy used : Server
Scanner IP : 172.17.100.38
Port scanner(s) : wmi_netstat
Port range : 1-65535
Ping RTT : Unavailable
Thorough tests : no
Experimental tests : no
Scan for Unpatched Vulnerabilities : yes
Plugin debugging enabled : yes (at debugging level 4)
Paranoia level : 0
Report verbosity : 2
Safe checks : yes
Optimize the test : yes
Credentialed checks : yes, as '172.17.100.140\tidua' via SMB
Patch management checks : None
Display superseded patches : yes (supersedence plugin did not launch)
CGI scanning : disabled
Web application tests : disabled
Max hosts : 2
Max checks : 2
Recv timeout : 5
Backports : None
Allow post-scan editing : Yes
Nessus Plugin Signature Checking : Enabled
Audit File Signature Checking : Disabled
Scan Start Date : 2026/1/24 12:16 India Standard Time (UTC +05:30)
Scan duration : 2743 sec
Scan for malware : no
58651 - Netstat Active Connections
-
Synopsis
Active connections are enumerated via the 'netstat' command.
Description
This plugin runs 'netstat' on the remote machine to enumerate all active 'ESTABLISHED' or 'LISTENING' tcp/udp connections.

Note: The output for this plugin can be very long, and is not shown by default. To display it, enable verbose reporting in scan settings.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2012/04/10, Modified: 2021/06/29
Plugin Output

tcp/0


Netstat output :

Active Connections

Proto Local Address Foreign Address State PID
TCP 0.0.0.0:80 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING 508
TCP 0.0.0.0:443 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:445 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:1801 0.0.0.0:0 LISTENING 3188
TCP 0.0.0.0:1947 0.0.0.0:0 LISTENING 2932
TCP 0.0.0.0:2103 0.0.0.0:0 LISTENING 3188
TCP 0.0.0.0:2105 0.0.0.0:0 LISTENING 3188
TCP 0.0.0.0:2107 0.0.0.0:0 LISTENING 3188
TCP 0.0.0.0:3389 0.0.0.0:0 LISTENING 1068
TCP 0.0.0.0:5061 0.0.0.0:0 LISTENING 4752
TCP 0.0.0.0:5357 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:5985 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:7001 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:8001 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:8002 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:47001 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:49664 0.0.0.0:0 LISTENING 644
TCP 0.0.0.0:49665 0.0.0.0:0 LISTENING 1176
TCP 0.0.0.0:49666 0.0.0.0:0 LISTENING 1804
TCP 0.0.0.0:49667 0.0.0.0:0 LISTENING 2504
TCP 0.0.0.0:49668 0.0.0.0:0 LISTENING 2808
TCP 0.0.0.0:49669 0.0.0.0:0 LISTENING 3188
TCP 0.0.0.0:49670 0.0.0.0:0 LISTENING 2652
TCP 0.0.0.0:49678 0.0.0.0:0 LISTENING 788
TCP 0.0.0.0:49744 0.0.0.0:0 LISTENING 796
TCP 0.0.0.0:51068 0.0.0.0:0 LISTENING 2952
TCP 10.54.158.102:139 0.0.0.0:0 LISTENING 4
TCP 10.54.158.102:5060 0.0.0.0:0 LISTENING 4752
TCP 127.0.0.1:5050 0.0.0.0:0 LISTENING 3108
TCP 127.0.0.1:12001 127.0.0.1:58811 ESTABLISHED 4752
TCP 127.0.0.1:12002 127.0.0.1:58812 ESTABLISHED 4752
TCP 127.0.0.1:30523 0.0.0.0:0 LISTENING 5016
TCP 127.0.0.1:49708 0.0.0.0:0 LISTENING 2960
TCP 127.0.0.1:49956 0.0.0.0:0 LISTENING 5016
TCP 127.0.0.1:51112 127.0.0.1:8082 SYN_SENT 4420
TCP 127.0.0.1:58811 127.0.0.1:12001 ESTABLISHED 4752
TCP 127.0.0.1:58812 127.0.0.1:12002 ESTABLISHED 4752
TCP 172.17.100.140:80 172.17.100.38:48554 ESTABLISHED 4
TCP 172.17.100.140:135 172.17.100.38:48866 ESTABLISHED 508
TCP 172.17.100.140:443 172.17.100.38:48556 ESTABLISHED 4
TCP 172.17.100.140:445 172.17.100.38:48865 ESTABLISHED 4
TCP 172.17.100.140:3389 192.168.10.254:48614 ESTABLISHED 1068
TCP 172.17.100.140:9505 0.0.0.0:0 LISTENING 4
TCP 172.17.100.140:9505 172.17.100.140:58770 ESTABLISHED 4
TCP 172.17.100.140:49517 172.17.100.141:1433 ESTABLISHED 2672
TCP 172.17.100.140:49672 172.17.100.141:1433 ESTABLISHED 3076
TCP 172.17.100.140:50609 172.17.100.141:1433 ESTABLISHED 4752
TCP 172.17.100.140:51045 192.168.10.20:13000 TIME_WAIT 0
TCP 172.17.100.140:51068 172.17.100.38:48867 ESTABLISHED 2952
TCP 172.17.100.140:53675 172.17.100.141:1433 ESTABLISHED 2672
TCP 172.17.100.140:55966 172.17.100.141:3389 ESTABLISHED 676
TCP 172.17.100.140:57404 172.17.100.141:1433 ESTABLISHED 4752
TCP 172.17.100.140:57946 172.17.100.141:1433 ESTABLISHED 4752
TCP 172.17.100.140:58770 172.17.100.140:9505 ESTABLISHED 4752
TCP 172.17.100.140:58829 172.17.100.141:1433 ESTABLISHED 4752
TCP 172.17.100.140:61960 172.17.100.141:1433 TIME_WAIT 0
TCP 172.17.100.140:62455 172.17.100.141:1433 ESTABLISHED 2672
TCP [::]:80 [::]:0 LISTENING 4
TCP [::]:135 [::]:0 LISTENING 508
TCP [::]:443 [::]:0 LISTENING 4
TCP [::]:445 [::]:0 LISTENING 4
TCP [::]:1801 [::]:0 LISTENING 3188
TCP [::]:1947 [::]:0 LISTENING 2932
TCP [::]:2103 [::]:0 LISTENING 3188
TCP [::]:2105 [::]:0 LISTENING 3188
TCP [::]:2107 [::]:0 LISTENING 3188
TCP [::]:3389 [::]:0 LISTENING 1068
TCP [::]:5357 [::]:0 LISTENING 4
TCP [::]:5985 [::]:0 LISTENING 4
TCP [::]:7001 [::]:0 LISTENING 4
TCP [::]:8001 [::]:0 LISTENING 4
TCP [::]:8002 [::]:0 LISTENING 4
TCP [::]:47001 [::]:0 LISTENING 4
TCP [::]:49664 [::]:0 LISTENING 644
TCP [::]:49665 [::]:0 LISTENING 1176
TCP [::]:49666 [::]:0 LISTENING 1804
TCP [::]:49667 [::]:0 LISTENING 2504
TCP [::]:49668 [::]:0 LISTENING 2808
TCP [::]:49669 [::]:0 LISTENING 3188
TCP [::]:49670 [::]:0 LISTENING 2652
TCP [::]:49678 [::]:0 LISTENING 788
TCP [::]:49744 [::]:0 LISTENING 796
TCP [::]:51068 [::]:0 LISTENING 2952
TCP [::1]:30523 [::]:0 LISTENING 5016
TCP [::1]:49956 [::]:0 LISTENING 5016
UDP 0.0.0.0:123 *:* 3232
UDP 0.0.0.0:500 *:* 2660
UDP 0.0.0.0:1947 *:* 2932
UDP 0.0.0.0:3389 *:* 1068
UDP 0.0.0.0:3702 *:* 5848
UDP 0.0.0.0:3702 *:* 5848
UDP 0.0.0.0:4500 *:* 2660
UDP 0.0.0.0:5353 *:* 1936
UDP 0.0.0.0:5355 *:* 1936
UDP 0.0.0.0:15000 *:* 5016
UDP 0.0.0.0:52697 *:* 5848
UDP 0.0.0.0:53616 *:* 676
UDP 0.0.0.0:59535 *:* 2932
UDP 10.54.158.102:137 *:* 4
UDP 10.54.158.102:138 *:* 4
UDP 10.54.158.102:5060 *:* 4752
UDP 10.54.158.102:6000 *:* 4752
UDP 10.54.158.102:6001 *:* 4752
UDP 10.54.158.102:6002 *:* 4752
UDP 10.54.158.102:6003 *:* 4752
UDP 10.54.158.102:6004 *:* 4752
UDP 10.54.158.102:6005 *:* 4752
UDP 10.54.158.102:6006 *:* 4752
UDP 10.54.158.102:6007 *:* 4752
UDP 10.54.158.102:6008 *:* 4752
UDP 10.54.158.102:6009 *:* 4752
UDP 10.54.158.102:6010 *:* 4752
UDP 10.54.158.102:6011 *:* 4752
UDP 10.54.158.102:6012 *:* 4752
UDP 10.54.158.102:6013 *:* 4752
UDP 10.54.158.102:6014 *:* 4752
UDP 10.54.158.102:6015 *:* 4752
UDP 10.54.158.102:6016 *:* 4752
UDP 10.54.158.102:6017 *:* 4752
UDP 10.54.158.102:6018 *:* 4752
UDP 10.54.158.102:6019 *:* 4752
UDP 10.54.158.102:6020 *:* 4752
UDP 10.54.158.102:6021 *:* 4752
UDP 10.54.158.102:6022 *:* 4752
UDP 10.54.158.102:6023 *:* 4752
UDP 10.54.158.102:6024 *:* 4752
UDP 10.54.158.102:6025 *:* 4752
UDP 10.54.158.102:6026 *:* 4752
UDP 10.54.158.102:6027 *:* 4752
UDP 10.54.158.102:6028 *:* 4752
UDP 10.54.158.102:6029 *:* 4752
UDP 10.54.158.102:6030 *:* 4752
UDP 10.54.158.102:6031 *:* 4752
UDP 10.54.158.102:6032 *:* 4752
UDP 10.54.158.102:6033 *:* 4752
UDP 10.54.158.102:6034 *:* 4752
UDP 10.54.158.102:6035 *:* 4752
UDP 10.54.158.102:6036 *:* 4752
UDP 10.54.158.102:6037 *:* 4752
UDP 10.54.158.102:6038 *:* 4752
UDP 10.54.158.102:6039 *:* 4752
UDP 10.54.158.102:6040 *:* 4752
UDP 10.54.158.102:6041 *:* 4752
UDP 10.54.158.102:6042 *:* 4752
UDP 10.54.158.102:6043 *:* 4752
UDP 10.54.158.102:6044 *:* 4752
UDP 10.54.158.102:6045 *:* 4752
UDP 10.54.158.102:6046 *:* 4752
UDP 10.54.158.102:6047 *:* 4752
UDP 10.54.158.102:6048 *:* 4752
UDP 10.54.158.102:6049 *:* 4752
UDP 10.54.158.102:6050 *:* 4752
UDP 10.54.158.102:6051 *:* 4752
UDP 10.54.158.102:6052 *:* 4752
UDP 10.54.158.102:6053 *:* 4752
UDP 10.54.158.102:6054 *:* 4752
UDP 10.54.158.102:6055 *:* 4752
UDP 10.54.158.102:6056 *:* 4752
UDP 10.54.158.102:6057 *:* 4752
UDP 10.54.158.102:6058 *:* 4752
UDP 10.54.158.102:6059 *:* 4752
UDP 10.54.158.102:6060 *:* 4752
UDP 10.54.158.102:6061 *:* 4752
UDP 10.54.158.102:6062 *:* 4752
UDP 10.54.158.102:6063 *:* 4752
UDP 10.54.158.102:6064 *:* 4752
UDP 10.54.158.102:6065 *:* 4752
UDP 10.54.158.102:6066 *:* 4752
UDP 10.54.158.102:6067 *:* 4752
UDP 10.54.158.102:6068 *:* 4752
UDP 10.54.158.102:6069 *:* 4752
UDP 10.54.158.102:6070 *:* 4752
UDP 10.54.158.102:6071 *:* 4752
UDP 10.54.158.102:6072 *:* 4752
UDP 10.54.158.102:6073 *:* 4752
UDP 10.54.158.102:6074 *:* 4752
UDP 10.54.158.102:6075 *:* 4752
UDP 10.54.158.102:6076 *:* 4752
UDP 10.54.158.102:6077 *:* 4752
UDP 10.54.158.102:6078 *:* 4752
UDP 10.54.158.102:6079 *:* 4752
UDP 10.54.158.102:6080 *:* 4752
UDP 10.54.158.102:6081 *:* 4752
UDP 10.54.158.102:6082 *:* 4752
UDP 10.54.158.102:6083 *:* 4752
UDP 10.54.158.102:6084 *:* 4752
UDP 10.54.158.102:6085 *:* 4752
UDP 10.54.158.102:6086 *:* 4752
UDP 10.54.158.102:6087 *:* 4752
UDP 10.54.158.102:6088 *:* 4752
UDP 10.54.158.102:6089 *:* 4752
UDP 10.54.158.102:6090 *:* 4752
UDP 10.54.158.102:6091 *:* 4752
UDP 10.54.158.102:6092 *:* 4752
UDP 10.54.158.102:6093 *:* 4752
UDP 10.54.158.102:6094 *:* 4752
UDP 10.54.158.102:6095 *:* 4752
UDP 10.54.158.102:6096 *:* 4752
UDP 10.54.158.102:6097 *:* 4752
UDP 10.54.158.102:6098 *:* 4752
UDP 10.54.158.102:6099 *:* 4752
UDP 10.54.158.102:6100 *:* 4752
UDP 10.54.158.102:6101 *:* 4752
UDP 10.54.158.102:6102 *:* 4752
UDP 10.54.158.102:6103 *:* 4752
UDP 10.54.158.102:6104 *:* 4752
UDP 10.54.158.102:6105 *:* 4752
UDP 10.54.158.102:6106 *:* 4752
UDP 10.54.158.102:6107 *:* 4752
UDP 10.54.158.102:6108 *:* 4752
UDP 10.54.158.102:6109 *:* 4752
UDP 10.54.158.102:6110 *:* 4752
UDP 10.54.158.102:6111 *:* 4752
UDP 10.54.158.102:6112 *:* 4752
UDP 10.54.158.102:6113 *:* 4752
UDP 10.54.158.102:6114 *:* 4752
UDP 10.54.158.102:6115 *:* 4752
UDP 10.54.158.102:6116 *:* 4752
UDP 10.54.158.102:6117 *:* 4752
UDP 10.54.158.102:6118 *:* 4752
UDP 10.54.158.102:6119 *:* 4752
UDP 10.54.158.102:6120 *:* 4752
UDP 10.54.158.102:6121 *:* 4752
UDP 10.54.158.102:6122 *:* 4752
UDP 10.54.158.102:6123 *:* 4752
UDP 10.54.158.102:6124 *:* 4752
UDP 10.54.158.102:6125 *:* 4752
UDP 10.54.158.102:6126 *:* 4752
UDP 10.54.158.102:6127 *:* 4752
UDP 10.54.158.102:6128 *:* 4752
UDP 10.54.158.102:6129 *:* 4752
UDP 10.54.158.102:6130 *:* 4752
UDP 10.54.158.102:6131 *:* 4752
UDP 10.54.158.102:6132 *:* 4752
UDP 10.54.158.102:6133 *:* 4752
UDP 10.54.158.102:6134 *:* 4752
UDP 10.54.158.102:6135 *:* 4752
UDP 10.54.158.102:6136 *:* 4752
UDP 10.54.158.102:6137 *:* 4752
UDP 10.54.158.102:6138 *:* 4752
UDP 10.54.158.102:6139 *:* 4752
UDP 10.54.158.102:6140 *:* 4752
UDP 10.54.158.102:6141 *:* 4752
UDP 10.54.158.102:6142 *:* 4752
UDP 10.54.158.102:6143 *:* 4752
UDP 10.54.158.102:6144 *:* 4752
UDP 10.54.158.102:6145 *:* 4752
UDP 10.54.158.102:6146 *:* 4752
UDP 10.54.158.102:6147 *:* 4752
UDP 10.54.158.102:6148 *:* 4752
UDP 10.54.158.102:6149 *:* 4752
UDP 10.54.158.102:6150 *:* 4752
UDP 10.54.158.102:6151 *:* 4752
UDP 10.54.158.102:6152 *:* 4752
UDP 10.54.158.102:6153 *:* 4752
UDP 10.54.158.102:6154 *:* 4752
UDP 10.54.158.102:6155 *:* 4752
UDP 10.54.158.102:6156 *:* 4752
UDP 10.54.158.102:6157 *:* 4752
UDP 10.54.158.102:6158 *:* 4752
UDP 10.54.158.102:6159 *:* 4752
UDP 10.54.158.102:6160 *:* 4752
UDP 10.54.158.102:6161 *:* 4752
UDP 10.54.158.102:6162 *:* 4752
UDP 10.54.158.102:6163 *:* 4752
UDP 10.54.158.102:6164 *:* 4752
UDP 10.54.158.102:6165 *:* 4752
UDP 10.54.158.102:6166 *:* 4752
UDP 10.54.158.102:6167 *:* 4752
UDP 10.54.158.102:6168 *:* 4752
UDP 10.54.158.102:6169 *:* 4752
UDP 10.54.158.102:6170 *:* 4752
UDP 10.54.158.102:6171 *:* 4752
UDP 10.54.158.102:6172 *:* 4752
UDP 10.54.158.102:6173 *:* 4752
UDP 10.54.158.102:6174 *:* 4752
UDP 10.54.158.102:6175 *:* 4752
UDP 10.54.158.102:6176 *:* 4752
UDP 10.54.158.102:6177 *:* 4752
UDP 10.54.158.102:6178 *:* 4752
UDP 10.54.158.102:6179 *:* 4752
UDP 10.54.158.102:6180 *:* 4752
UDP 10.54.158.102:6181 *:* 4752
UDP 10.54.158.102:6182 *:* 4752
UDP 10.54.158.102:6183 *:* 4752
UDP 10.54.158.102:6184 *:* 4752
UDP 10.54.158.102:6185 *:* 4752
UDP 10.54.158.102:6186 *:* 4752
UDP 10.54.158.102:6187 *:* 4752
UDP 10.54.158.102:6188 *:* 4752
UDP 10.54.158.102:6189 *:* 4752
UDP 10.54.158.102:6190 *:* 4752
UDP 10.54.158.102:6191 *:* 4752
UDP 10.54.158.102:6192 *:* 4752
UDP 10.54.158.102:6193 *:* 4752
UDP 10.54.158.102:6194 *:* 4752
UDP 10.54.158.102:6195 *:* 4752
UDP 10.54.158.102:6196 *:* 4752
UDP 10.54.158.102:6197 *:* 4752
UDP 10.54.158.102:6198 *:* 4752
UDP 10.54.158.102:6199 *:* 4752
UDP 10.54.158.102:6200 *:* 4752
UDP 10.54.158.102:6201 *:* 4752
UDP 10.54.158.102:6202 *:* 4752
UDP 10.54.158.102:6203 *:* 4752
UDP 10.54.158.102:6204 *:* 4752
UDP 10.54.158.102:6205 *:* 4752
UDP 10.54.158.102:6206 *:* 4752
UDP 10.54.158.102:6207 *:* 4752
UDP 10.54.158.102:6208 *:* 4752
UDP 10.54.158.102:6209 *:* 4752
UDP 10.54.158.102:6210 *:* 4752
UDP 10.54.158.102:6211 *:* 4752
UDP 10.54.158.102:6212 *:* 4752
UDP 10.54.158.102:6213 *:* 4752
UDP 10.54.158.102:6214 *:* 4752
UDP 10.54.158.102:6215 *:* 4752
UDP 10.54.158.102:6216 *:* 4752
UDP 10.54.158.102:6217 *:* 4752
UDP 10.54.158.102:6218 *:* 4752
UDP 10.54.158.102:6219 *:* 4752
UDP 10.54.158.102:6220 *:* 4752
UDP 10.54.158.102:6221 *:* 4752
UDP 10.54.158.102:6222 *:* 4752
UDP 10.54.158.102:6223 *:* 4752
UDP 10.54.158.102:6224 *:* 4752
UDP 10.54.158.102:6225 *:* 4752
UDP 10.54.158.102:6226 *:* 4752
UDP 10.54.158.102:6227 *:* 4752
UDP 10.54.158.102:6228 *:* 4752
UDP 10.54.158.102:6229 *:* 4752
UDP 10.54.158.102:6230 *:* 4752
UDP 10.54.158.102:6231 *:* 4752
UDP 10.54.158.102:6232 *:* 4752
UDP 10.54.158.102:6233 *:* 4752
UDP 10.54.158.102:6234 *:* 4752
UDP 10.54.158.102:6235 *:* 4752
UDP 10.54.158.102:6236 *:* 4752
UDP 10.54.158.102:6237 *:* 4752
UDP 10.54.158.102:6238 *:* 4752
UDP 10.54.158.102:6239 *:* 4752
UDP 10.54.158.102:6240 *:* 4752
UDP 10.54.158.102:6241 *:* 4752
UDP 10.54.158.102:6242 *:* 4752
UDP 10.54.158.102:6243 *:* 4752
UDP 10.54.158.102:6244 *:* 4752
UDP 10.54.158.102:6245 *:* 4752
UDP 10.54.158.102:6246 *:* 4752
UDP 10.54.158.102:6247 *:* 4752
UDP 10.54.158.102:6248 *:* 4752
UDP 10.54.158.102:6249 *:* 4752
UDP 10.54.158.102:6250 *:* 4752
UDP 10.54.158.102:6251 *:* 4752
UDP 10.54.158.102:6252 *:* 4752
UDP 10.54.158.102:6253 *:* 4752
UDP 10.54.158.102:6254 *:* 4752
UDP 10.54.158.102:6255 *:* 4752
UDP 10.54.158.102:6256 *:* 4752
UDP 10.54.158.102:6257 *:* 4752
UDP 10.54.158.102:6258 *:* 4752
UDP 10.54.158.102:6259 *:* 4752
UDP 10.54.158.102:6260 *:* 4752
UDP 10.54.158.102:6261 *:* 4752
UDP 10.54.158.102:6262 *:* 4752
UDP 10.54.158.102:6263 *:* 4752
UDP 10.54.158.102:6264 *:* 4752
UDP 10.54.158.102:6265 *:* 4752
UDP 10.54.158.102:6266 *:* 4752
UDP 10.54.158.102:6267 *:* 4752
UDP 10.54.158.102:6268 *:* 4752
UDP 10.54.158.102:6269 *:* 4752
UDP 10.54.158.102:6270 *:* 4752
UDP 10.54.158.102:6271 *:* 4752
UDP 10.54.158.102:6272 *:* 4752
UDP 10.54.158.102:6273 *:* 4752
UDP 10.54.158.102:6274 *:* 4752
UDP 10.54.158.102:6275 *:* 4752
UDP 10.54.158.102:6276 *:* 4752
UDP 10.54.158.102:6277 *:* 4752
UDP 10.54.158.102:6278 *:* 4752
UDP 10.54.158.102:6279 *:* 4752
UDP 10.54.158.102:6280 *:* 4752
UDP 10.54.158.102:6281 *:* 4752
UDP 10.54.158.102:6282 *:* 4752
UDP 10.54.158.102:6283 *:* 4752
UDP 10.54.158.102:6284 *:* 4752
UDP 10.54.158.102:6285 *:* 4752
UDP 10.54.158.102:6286 *:* 4752
UDP 10.54.158.102:6287 *:* 4752
UDP 10.54.158.102:6288 *:* 4752
UDP 10.54.158.102:6289 *:* 4752
UDP 10.54.158.102:6290 *:* 4752
UDP 10.54.158.102:6291 *:* 4752
UDP 10.54.158.102:6292 *:* 4752
UDP 10.54.158.102:6293 *:* 4752
UDP 10.54.158.102:6294 *:* 4752
UDP 10.54.158.102:6295 *:* 4752
UDP 10.54.158.102:6296 *:* 4752
UDP 10.54.158.102:6297 *:* 4752
UDP 10.54.158.102:6298 *:* 4752
UDP 10.54.158.102:6299 *:* 4752
UDP 10.54.158.102:6300 *:* 4752
UDP 10.54.158.102:6301 *:* 4752
UDP 10.54.158.102:6302 *:* 4752
UDP 10.54.158.102:6303 *:* 4752
UDP 10.54.158.102:6304 *:* 4752
UDP 10.54.158.102:6305 *:* 4752
UDP 10.54.158.102:6306 *:* 4752
UDP 10.54.158.102:6307 *:* 4752
UDP 10.54.158.102:6308 *:* 4752
UDP 10.54.158.102:6309 *:* 4752
UDP 10.54.158.102:6310 *:* 4752
UDP 10.54.158.102:6311 *:* 4752
UDP 10.54.158.102:6312 *:* 4752
UDP 10.54.158.102:6313 *:* 4752
UDP 10.54.158.102:6314 *:* 4752
UDP 10.54.158.102:6315 *:* 4752
UDP 10.54.158.102:6316 *:* 4752
UDP 10.54.158.102:6317 *:* 4752
UDP 10.54.158.102:6318 *:* 4752
UDP 10.54.158.102:6319 *:* 4752
UDP 10.54.158.102:6320 *:* 4752
UDP 10.54.158.102:6321 *:* 4752
UDP 10.54.158.102:6322 *:* 4752
UDP 10.54.158.102:6323 *:* 4752
UDP 10.54.158.102:6324 *:* 4752
UDP 10.54.158.102:6325 *:* 4752
UDP 10.54.158.102:6326 *:* 4752
UDP 10.54.158.102:6327 *:* 4752
UDP 10.54.158.102:6328 *:* 4752
UDP 10.54.158.102:6329 *:* 4752
UDP 10.54.158.102:6330 *:* 4752
UDP 10.54.158.102:6331 *:* 4752
UDP 10.54.158.102:6332 *:* 4752
UDP 10.54.158.102:6333 *:* 4752
UDP 10.54.158.102:6334 *:* 4752
UDP 10.54.158.102:6335 *:* 4752
UDP 10.54.158.102:6336 *:* 4752
UDP 10.54.158.102:6337 *:* 4752
UDP 10.54.158.102:6338 *:* 4752
UDP 10.54.158.102:6339 *:* 4752
UDP 10.54.158.102:6340 *:* 4752
UDP 10.54.158.102:6341 *:* 4752
UDP 10.54.158.102:6342 *:* 4752
UDP 10.54.158.102:6343 *:* 4752
UDP 10.54.158.102:6344 *:* 4752
UDP 10.54.158.102:6345 *:* 4752
UDP 10.54.158.102:6346 *:* 4752
UDP 10.54.158.102:6347 *:* 4752
UDP 10.54.158.102:6348 *:* 4752
UDP 10.54.158.102:6349 *:* 4752
UDP 10.54.158.102:6350 *:* 4752
UDP 10.54.158.102:6351 *:* 4752
UDP 10.54.158.102:6352 *:* 4752
UDP 10.54.158.102:6353 *:* 4752
UDP 10.54.158.102:6354 *:* 4752
UDP 10.54.158.102:6355 *:* 4752
UDP 10.54.158.102:6356 *:* 4752
UDP 10.54.158.102:6357 *:* 4752
UDP 10.54.158.102:6358 *:* 4752
UDP 10.54.158.102:6359 *:* 4752
UDP 10.54.158.102:6360 *:* 4752
UDP 10.54.158.102:6361 *:* 4752
UDP 10.54.158.102:6362 *:* 4752
UDP 10.54.158.102:6363 *:* 4752
UDP 10.54.158.102:6364 *:* 4752
UDP 10.54.158.102:6365 *:* 4752
UDP 10.54.158.102:6366 *:* 4752
UDP 10.54.158.102:6367 *:* 4752
UDP 10.54.158.102:6368 *:* 4752
UDP 10.54.158.102:6369 *:* 4752
UDP 10.54.158.102:6370 *:* 4752
UDP 10.54.158.102:6371 *:* 4752
UDP 10.54.158.102:6372 *:* 4752
UDP 10.54.158.102:6373 *:* 4752
UDP 10.54.158.102:6374 *:* 4752
UDP 10.54.158.102:6375 *:* 4752
UDP 10.54.158.102:6376 *:* 4752
UDP 10.54.158.102:6377 *:* 4752
UDP 10.54.158.102:6378 *:* 4752
UDP 10.54.158.102:6379 *:* 4752
UDP 10.54.158.102:6380 *:* 4752
UDP 10.54.158.102:6381 *:* 4752
UDP 10.54.158.102:6382 *:* 4752
UDP 10.54.158.102:6383 *:* 4752
UDP 10.54.158.102:6384 *:* 4752
UDP 10.54.158.102:6385 *:* 4752
UDP 10.54.158.102:6386 *:* 4752
UDP 10.54.158.102:6387 *:* 4752
UDP 10.54.158.102:6388 *:* 4752
UDP 10.54.158.102:6389 *:* 4752
UDP 10.54.158.102:6390 *:* 4752
UDP 10.54.158.102:6391 *:* 4752
UDP 10.54.158.102:6392 *:* 4752
UDP 10.54.158.102:6393 *:* 4752
UDP 10.54.158.102:6394 *:* 4752
UDP 10.54.158.102:6395 *:* 4752
UDP 10.54.158.102:6396 *:* 4752
UDP 10.54.158.102:6397 *:* 4752
UDP 10.54.158.102:6398 *:* 4752
UDP 10.54.158.102:6399 *:* 4752
UDP 10.54.158.102:6400 *:* 4752
UDP 10.54.158.102:6401 *:* 4752
UDP 10.54.158.102:6402 *:* 4752
UDP 10.54.158.102:6403 *:* 4752
UDP 10.54.158.102:6404 *:* 4752
UDP 10.54.158.102:6405 *:* 4752
UDP 10.54.158.102:6406 *:* 4752
UDP 10.54.158.102:6407 *:* 4752
UDP 10.54.158.102:6408 *:* 4752
UDP 10.54.158.102:6409 *:* 4752
UDP 10.54.158.102:6410 *:* 4752
UDP 10.54.158.102:6411 *:* 4752
UDP 10.54.158.102:6412 *:* 4752
UDP 10.54.158.102:6413 *:* 4752
UDP 10.54.158.102:6414 *:* 4752
UDP 10.54.158.102:6415 *:* 4752
UDP 10.54.158.102:6416 *:* 4752
UDP 10.54.158.102:6417 *:* 4752
UDP 10.54.158.102:6418 *:* 4752
UDP 10.54.158.102:6419 *:* 4752
UDP 10.54.158.102:6420 *:* 4752
UDP 10.54.158.102:6421 *:* 4752
UDP 10.54.158.102:6422 *:* 4752
UDP 10.54.158.102:6423 *:* 4752
UDP 10.54.158.102:6424 *:* 4752
UDP 10.54.158.102:6425 *:* 4752
UDP 10.54.158.102:6426 *:* 4752
UDP 10.54.158.102:6427 *:* 4752
UDP 10.54.158.102:6428 *:* 4752
UDP 10.54.158.102:6429 *:* 4752
UDP 10.54.158.102:6430 *:* 4752
UDP 10.54.158.102:6431 *:* 4752
UDP 10.54.158.102:6432 *:* 4752
UDP 10.54.158.102:6433 *:* 4752
UDP 10.54.158.102:6434 *:* 4752
UDP 10.54.158.102:6435 *:* 4752
UDP 10.54.158.102:6436 *:* 4752
UDP 10.54.158.102:6437 *:* 4752
UDP 10.54.158.102:6438 *:* 4752
UDP 10.54.158.102:6439 *:* 4752
UDP 10.54.158.102:6440 *:* 4752
UDP 10.54.158.102:6441 *:* 4752
UDP 10.54.158.102:6442 *:* 4752
UDP 10.54.158.102:6443 *:* 4752
UDP 10.54.158.102:6444 *:* 4752
UDP 10.54.158.102:6445 *:* 4752
UDP 10.54.158.102:6446 *:* 4752
UDP 10.54.158.102:6447 *:* 4752
UDP 10.54.158.102:6448 *:* 4752
UDP 10.54.158.102:6449 *:* 4752
UDP 10.54.158.102:6450 *:* 4752
UDP 10.54.158.102:6451 *:* 4752
UDP 10.54.158.102:6452 *:* 4752
UDP 10.54.158.102:6453 *:* 4752
UDP 10.54.158.102:6454 *:* 4752
UDP 10.54.158.102:6455 *:* 4752
UDP 10.54.158.102:6456 *:* 4752
UDP 10.54.158.102:6457 *:* 4752
UDP 10.54.158.102:6458 *:* 4752
UDP 10.54.158.102:6459 *:* 4752
UDP 10.54.158.102:6460 *:* 4752
UDP 10.54.158.102:6461 *:* 4752
UDP 10.54.158.102:6462 *:* 4752
UDP 10.54.158.102:6463 *:* 4752
UDP 10.54.158.102:6464 *:* 4752
UDP 10.54.158.102:6465 *:* 4752
UDP 10.54.158.102:6466 *:* 4752
UDP 10.54.158.102:6467 *:* 4752
UDP 10.54.158.102:6468 *:* 4752
UDP 10.54.158.102:6469 *:* 4752
UDP 10.54.158.102:6470 *:* 4752
UDP 10.54.158.102:6471 *:* 4752
UDP 10.54.158.102:6472 *:* 4752
UDP 10.54.158.102:6473 *:* 4752
UDP 10.54.158.102:6474 *:* 4752
UDP 10.54.158.102:6475 *:* 4752
UDP 10.54.158.102:6476 *:* 4752
UDP 10.54.158.102:6477 *:* 4752
UDP 10.54.158.102:6478 *:* 4752
UDP 10.54.158.102:6479 *:* 4752
UDP 10.54.158.102:6480 *:* 4752
UDP 10.54.158.102:6481 *:* 4752
UDP 10.54.158.102:6482 *:* 4752
UDP 10.54.158.102:6483 *:* 4752
UDP 10.54.158.102:6484 *:* 4752
UDP 10.54.158.102:6485 *:* 4752
UDP 10.54.158.102:6486 *:* 4752
UDP 10.54.158.102:6487 *:* 4752
UDP 10.54.158.102:6488 *:* 4752
UDP 10.54.158.102:6489 *:* 4752
UDP 10.54.158.102:6490 *:* 4752
UDP 10.54.158.102:6491 *:* 4752
UDP 10.54.158.102:6492 *:* 4752
UDP 10.54.158.102:6493 *:* 4752
UDP 10.54.158.102:6494 *:* 4752
UDP 10.54.158.102:6495 *:* 4752
UDP 10.54.158.102:6496 *:* 4752
UDP 10.54.158.102:6497 *:* 4752
UDP 10.54.158.102:6498 *:* 4752
UDP 10.54.158.102:6499 *:* 4752
UDP 10.54.158.102:6500 *:* 4752
UDP 10.54.158.102:6501 *:* 4752
UDP 10.54.158.102:6502 *:* 4752
UDP 10.54.158.102:6503 *:* 4752
UDP 10.54.158.102:6504 *:* 4752
UDP 10.54.158.102:6505 *:* 4752
UDP 10.54.158.102:6506 *:* 4752
UDP 10.54.158.102:6507 *:* 4752
UDP 10.54.158.102:6508 *:* 4752
UDP 10.54.158.102:6509 *:* 4752
UDP 10.54.158.102:6510 *:* 4752
UDP 10.54.158.102:6511 *:* 4752
UDP 10.54.158.102:6512 *:* 4752
UDP 10.54.158.102:6513 *:* 4752
UDP 10.54.158.102:6514 *:* 4752
UDP 10.54.158.102:6515 *:* 4752
UDP 10.54.158.102:6516 *:* 4752
UDP 10.54.158.102:6517 *:* 4752
UDP 10.54.158.102:6518 *:* 4752
UDP 10.54.158.102:6519 *:* 4752
UDP 10.54.158.102:6520 *:* 4752
UDP 10.54.158.102:6521 *:* 4752
UDP 10.54.158.102:6522 *:* 4752
UDP 10.54.158.102:6523 *:* 4752
UDP 10.54.158.102:6524 *:* 4752
UDP 10.54.158.102:6525 *:* 4752
UDP 10.54.158.102:6526 *:* 4752
UDP 10.54.158.102:6527 *:* 4752
UDP 10.54.158.102:6528 *:* 4752
UDP 10.54.158.102:6529 *:* 4752
UDP 10.54.158.102:6530 *:* 4752
UDP 10.54.158.102:6531 *:* 4752
UDP 10.54.158.102:6532 *:* 4752
UDP 10.54.158.102:6533 *:* 4752
UDP 10.54.158.102:6534 *:* 4752
UDP 10.54.158.102:6535 *:* 4752
UDP 10.54.158.102:6536 *:* 4752
UDP 10.54.158.102:6537 *:* 4752
UDP 10.54.158.102:6538 *:* 4752
UDP 10.54.158.102:6539 *:* 4752
UDP 10.54.158.102:6540 *:* 4752
UDP 10.54.158.102:6541 *:* 4752
UDP 10.54.158.102:6542 *:* 4752
UDP 10.54.158.102:6543 *:* 4752
UDP 10.54.158.102:6544 *:* 4752
UDP 10.54.158.102:6545 *:* 4752
UDP 10.54.158.102:6546 *:* 4752
UDP 10.54.158.102:6547 *:* 4752
UDP 10.54.158.102:6548 *:* 4752
UDP 10.54.158.102:6549 *:* 4752
UDP 10.54.158.102:6550 *:* 4752
UDP 10.54.158.102:6551 *:* 4752
UDP 10.54.158.102:6552 *:* 4752
UDP 10.54.158.102:6553 *:* 4752
UDP 10.54.158.102:6554 *:* 4752
UDP 10.54.158.102:6555 *:* 4752
UDP 10.54.158.102:6556 *:* 4752
UDP 10.54.158.102:6557 *:* 4752
UDP 10.54.158.102:6558 *:* 4752
UDP 10.54.158.102:6559 *:* 4752
UDP 10.54.158.102:6560 *:* 4752
UDP 10.54.158.102:6561 *:* 4752
UDP 10.54.158.102:6562 *:* 4752
UDP 10.54.158.102:6563 *:* 4752
UDP 10.54.158.102:6564 *:* 4752
UDP 10.54.158.102:6565 *:* 4752
UDP 10.54.158.102:6566 *:* 4752
UDP 10.54.158.102:6567 *:* 4752
UDP 10.54.158.102:6568 *:* 4752
UDP 10.54.158.102:6569 *:* 4752
UDP 10.54.158.102:6570 *:* 4752
UDP 10.54.158.102:6571 *:* 4752
UDP 10.54.158.102:6572 *:* 4752
UDP 10.54.158.102:6573 *:* 4752
UDP 10.54.158.102:6574 *:* 4752
UDP 10.54.158.102:6575 *:* 4752
UDP 10.54.158.102:6576 *:* 4752
UDP 10.54.158.102:6577 *:* 4752
UDP 10.54.158.102:6578 *:* 4752
UDP 10.54.158.102:6579 *:* 4752
UDP 10.54.158.102:6580 *:* 4752
UDP 10.54.158.102:6581 *:* 4752
UDP 10.54.158.102:6582 *:* 4752
UDP 10.54.158.102:6583 *:* 4752
UDP 10.54.158.102:6584 *:* 4752
UDP 10.54.158.102:6585 *:* 4752
UDP 10.54.158.102:6586 *:* 4752
UDP 10.54.158.102:6587 *:* 4752
UDP 10.54.158.102:6588 *:* 4752
UDP 10.54.158.102:6589 *:* 4752
UDP 10.54.158.102:6590 *:* 4752
UDP 10.54.158.102:6591 *:* 4752
UDP 10.54.158.102:6592 *:* 4752
UDP 10.54.158.102:6593 *:* 4752
UDP 10.54.158.102:6594 *:* 4752
UDP 10.54.158.102:6595 *:* 4752
UDP 10.54.158.102:6596 *:* 4752
UDP 10.54.158.102:6597 *:* 4752
UDP 10.54.158.102:6598 *:* 4752
UDP 10.54.158.102:6599 *:* 4752
UDP 10.54.158.102:6600 *:* 4752
UDP 10.54.158.102:6601 *:* 4752
UDP 10.54.158.102:6602 *:* 4752
UDP 10.54.158.102:6603 *:* 4752
UDP 10.54.158.102:6604 *:* 4752
UDP 10.54.158.102:6605 *:* 4752
UDP 10.54.158.102:6606 *:* 4752
UDP 10.54.158.102:6607 *:* 4752
UDP 10.54.158.102:6608 *:* 4752
UDP 10.54.158.102:6609 *:* 4752
UDP 10.54.158.102:6610 *:* 4752
UDP 10.54.158.102:6611 *:* 4752
UDP 10.54.158.102:6612 *:* 4752
UDP 10.54.158.102:6613 *:* 4752
UDP 10.54.158.102:6614 *:* 4752
UDP 10.54.158.102:6615 *:* 4752
UDP 10.54.158.102:6616 *:* 4752
UDP 10.54.158.102:6617 *:* 4752
UDP 10.54.158.102:6618 *:* 4752
UDP 10.54.158.102:6619 *:* 4752
UDP 10.54.158.102:6620 *:* 4752
UDP 10.54.158.102:6621 *:* 4752
UDP 10.54.158.102:6622 *:* 4752
UDP 10.54.158.102:6623 *:* 4752
UDP 10.54.158.102:6624 *:* 4752
UDP 10.54.158.102:6625 *:* 4752
UDP 10.54.158.102:6626 *:* 4752
UDP 10.54.158.102:6627 *:* 4752
UDP 10.54.158.102:6628 *:* 4752
UDP 10.54.158.102:6629 *:* 4752
UDP 10.54.158.102:6630 *:* 4752
UDP 10.54.158.102:6631 *:* 4752
UDP 10.54.158.102:6632 *:* 4752
UDP 10.54.158.102:6633 *:* 4752
UDP 10.54.158.102:6634 *:* 4752
UDP 10.54.158.102:6635 *:* 4752
UDP 10.54.158.102:6636 *:* 4752
UDP 10.54.158.102:6637 *:* 4752
UDP 10.54.158.102:6638 *:* 4752
UDP 10.54.158.102:6639 *:* 4752
UDP 10.54.158.102:6640 *:* 4752
UDP 10.54.158.102:6641 *:* 4752
UDP 10.54.158.102:6642 *:* 4752
UDP 10.54.158.102:6643 *:* 4752
UDP 10.54.158.102:6644 *:* 4752
UDP 10.54.158.102:6645 *:* 4752
UDP 10.54.158.102:6646 *:* 4752
UDP 10.54.158.102:6647 *:* 4752
UDP 10.54.158.102:6648 *:* 4752
UDP 10.54.158.102:6649 *:* 4752
UDP 10.54.158.102:6650 *:* 4752
UDP 10.54.158.102:6651 *:* 4752
UDP 10.54.158.102:6652 *:* 4752
UDP 10.54.158.102:6653 *:* 4752
UDP 10.54.158.102:6654 *:* 4752
UDP 10.54.158.102:6655 *:* 4752
UDP 10.54.158.102:6656 *:* 4752
UDP 10.54.158.102:6657 *:* 4752
UDP 10.54.158.102:6658 *:* 4752
UDP 10.54.158.102:6659 *:* 4752
UDP 10.54.158.102:6660 *:* 4752
UDP 10.54.158.102:6661 *:* 4752
UDP 10.54.158.102:6662 *:* 4752
UDP 10.54.158.102:6663 *:* 4752
UDP 10.54.158.102:6664 *:* 4752
UDP 10.54.158.102:6665 *:* 4752
UDP 10.54.158.102:6666 *:* 4752
UDP 10.54.158.102:6667 *:* 4752
UDP 10.54.158.102:6668 *:* 4752
UDP 10.54.158.102:6669 *:* 4752
UDP 10.54.158.102:6670 *:* 4752
UDP 10.54.158.102:6671 *:* 4752
UDP 10.54.158.102:6672 *:* 4752
UDP 10.54.158.102:6673 *:* 4752
UDP 10.54.158.102:6674 *:* 4752
UDP 10.54.158.102:6675 *:* 4752
UDP 10.54.158.102:6676 *:* 4752
UDP 10.54.158.102:6677 *:* 4752
UDP 10.54.158.102:6678 *:* 4752
UDP 10.54.158.102:6679 *:* 4752
UDP 10.54.158.102:6680 *:* 4752
UDP 10.54.158.102:6681 *:* 4752
UDP 10.54.158.102:6682 *:* 4752
UDP 10.54.158.102:6683 *:* 4752
UDP 10.54.158.102:6684 *:* 4752
UDP 10.54.158.102:6685 *:* 4752
UDP 10.54.158.102:6686 *:* 4752
UDP 10.54.158.102:6687 *:* 4752
UDP 10.54.158.102:6688 *:* 4752
UDP 10.54.158.102:6689 *:* 4752
UDP 10.54.158.102:6690 *:* 4752
UDP 10.54.158.102:6691 *:* 4752
UDP 10.54.158.102:6692 *:* 4752
UDP 10.54.158.102:6693 *:* 4752
UDP 10.54.158.102:6694 *:* 4752
UDP 10.54.158.102:6695 *:* 4752
UDP 10.54.158.102:6696 *:* 4752
UDP 10.54.158.102:6697 *:* 4752
UDP 10.54.158.102:6698 *:* 4752
UDP 10.54.158.102:6699 *:* 4752
UDP 10.54.158.102:6700 *:* 4752
UDP 10.54.158.102:6701 *:* 4752
UDP 10.54.158.102:6702 *:* 4752
UDP 10.54.158.102:6703 *:* 4752
UDP 10.54.158.102:6704 *:* 4752
UDP 10.54.158.102:6705 *:* 4752
UDP 10.54.158.102:6706 *:* 4752
UDP 10.54.158.102:6707 *:* 4752
UDP 10.54.158.102:6708 *:* 4752
UDP 10.54.158.102:6709 *:* 4752
UDP 10.54.158.102:6710 *:* 4752
UDP 10.54.158.102:6711 *:* 4752
UDP 10.54.158.102:6712 *:* 4752
UDP 10.54.158.102:6713 *:* 4752
UDP 10.54.158.102:6714 *:* 4752
UDP 10.54.158.102:6715 *:* 4752
UDP 10.54.158.102:6716 *:* 4752
UDP 10.54.158.102:6717 *:* 4752
UDP 10.54.158.102:6718 *:* 4752
UDP 10.54.158.102:6719 *:* 4752
UDP 10.54.158.102:6720 *:* 4752
UDP 10.54.158.102:6721 *:* 4752
UDP 10.54.158.102:6722 *:* 4752
UDP 10.54.158.102:6723 *:* 4752
UDP 10.54.158.102:6724 *:* 4752
UDP 10.54.158.102:6725 *:* 4752
UDP 10.54.158.102:6726 *:* 4752
UDP 10.54.158.102:6727 *:* 4752
UDP 10.54.158.102:6728 *:* 4752
UDP 10.54.158.102:6729 *:* 4752
UDP 10.54.158.102:6730 *:* 4752
UDP 10.54.158.102:6731 *:* 4752
UDP 10.54.158.102:6732 *:* 4752
UDP 10.54.158.102:6733 *:* 4752
UDP 10.54.158.102:6734 *:* 4752
UDP 10.54.158.102:6735 *:* 4752
UDP 10.54.158.102:6736 *:* 4752
UDP 10.54.158.102:6737 *:* 4752
UDP 10.54.158.102:6738 *:* 4752
UDP 10.54.158.102:6739 *:* 4752
UDP 10.54.158.102:6740 *:* 4752
UDP 10.54.158.102:6741 *:* 4752
UDP 10.54.158.102:6742 *:* 4752
UDP 10.54.158.102:6743 *:* 4752
UDP 10.54.158.102:6744 *:* 4752
UDP 10.54.158.102:6745 *:* 4752
UDP 10.54.158.102:6746 *:* 4752
UDP 10.54.158.102:6747 *:* 4752
UDP 10.54.158.102:6748 *:* 4752
UDP 10.54.158.102:6749 *:* 4752
UDP 10.54.158.102:6750 *:* 4752
UDP 10.54.158.102:6751 *:* 4752
UDP 10.54.158.102:6752 *:* 4752
UDP 10.54.158.102:6753 *:* 4752
UDP 10.54.158.102:6754 *:* 4752
UDP 10.54.158.102:6755 *:* 4752
UDP 10.54.158.102:6756 *:* 4752
UDP 10.54.158.102:6757 *:* 4752
UDP 10.54.158.102:6758 *:* 4752
UDP 10.54.158.102:6759 *:* 4752
UDP 10.54.158.102:6760 *:* 4752
UDP 10.54.158.102:6761 *:* 4752
UDP 10.54.158.102:6762 *:* 4752
UDP 10.54.158.102:6763 *:* 4752
UDP 10.54.158.102:6764 *:* 4752
UDP 10.54.158.102:6765 *:* 4752
UDP 10.54.158.102:6766 *:* 4752
UDP 10.54.158.102:6767 *:* 4752
UDP 10.54.158.102:6768 *:* 4752
UDP 10.54.158.102:6769 *:* 4752
UDP 10.54.158.102:6770 *:* 4752
UDP 10.54.158.102:6771 *:* 4752
UDP 10.54.158.102:6772 *:* 4752
UDP 10.54.158.102:6773 *:* 4752
UDP 10.54.158.102:6774 *:* 4752
UDP 10.54.158.102:6775 *:* 4752
UDP 10.54.158.102:6776 *:* 4752
UDP 10.54.158.102:6777 *:* 4752
UDP 10.54.158.102:6778 *:* 4752
UDP 10.54.158.102:6779 *:* 4752
UDP 10.54.158.102:6780 *:* 4752
UDP 10.54.158.102:6781 *:* 4752
UDP 10.54.158.102:6782 *:* 4752
UDP 10.54.158.102:6783 *:* 4752
UDP 10.54.158.102:6784 *:* 4752
UDP 10.54.158.102:6785 *:* 4752
UDP 10.54.158.102:6786 *:* 4752
UDP 10.54.158.102:6787 *:* 4752
UDP 10.54.158.102:6788 *:* 4752
UDP 10.54.158.102:6789 *:* 4752
UDP 10.54.158.102:6790 *:* 4752
UDP 10.54.158.102:6791 *:* 4752
UDP 10.54.158.102:6792 *:* 4752
UDP 10.54.158.102:6793 *:* 4752
UDP 10.54.158.102:6794 *:* 4752
UDP 10.54.158.102:6795 *:* 4752
UDP 10.54.158.102:6796 *:* 4752
UDP 10.54.158.102:6797 *:* 4752
UDP 10.54.158.102:6798 *:* 4752
UDP 10.54.158.102:6799 *:* 4752
UDP 127.0.0.1:59534 *:* 3312
UDP [::]:123 *:* 3232
UDP [::]:500 *:* 2660
UDP [::]:1947 *:* 2932
UDP [::]:3389 *:* 1068
UDP [::]:3702 *:* 5848
UDP [::]:3702 *:* 5848
UDP [::]:4500 *:* 2660
UDP [::]:15000 *:* 5016
UDP [::]:52698 *:* 5848
64582 - Netstat Connection Information
-
Synopsis
Nessus was able to parse the results of the 'netstat' command on the remote host.
Description
The remote host has listening ports or established connections that Nessus was able to extract from the results of the 'netstat' command.

Note: The output for this plugin can be very long, and is not shown by default. To display it, enable verbose reporting in scan settings.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/02/13, Modified: 2023/05/23
Plugin Output

tcp/0

tcp4 (listen)
src: [host=0.0.0.0, port=80]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=135]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=443]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=445]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=1801]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=1947]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=2103]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=2105]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=2107]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=3389]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=5061]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=5357]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=5985]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=7001]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=8001]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=8002]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=47001]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49664]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49665]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49666]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49667]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49668]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49669]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49670]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49678]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49744]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=51068]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=10.54.158.102, port=139]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=10.54.158.102, port=5060]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=127.0.0.1, port=5050]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=12001]
dst: [host=127.0.0.1, port=58811]

tcp4 (established)
src: [host=127.0.0.1, port=12002]
dst: [host=127.0.0.1, port=58812]

tcp4 (listen)
src: [host=127.0.0.1, port=30523]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=127.0.0.1, port=49708]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=127.0.0.1, port=49956]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=51112]
dst: [host=127.0.0.1, port=8082]

tcp4 (established)
src: [host=127.0.0.1, port=58811]
dst: [host=127.0.0.1, port=12001]

tcp4 (established)
src: [host=127.0.0.1, port=58812]
dst: [host=127.0.0.1, port=12002]

tcp4 (established)
src: [host=172.17.100.140, port=80]
dst: [host=172.17.100.38, port=48554]

tcp4 (established)
src: [host=172.17.100.140, port=135]
dst: [host=172.17.100.38, port=48866]

tcp4 (established)
src: [host=172.17.100.140, port=443]
dst: [host=172.17.100.38, port=48556]

tcp4 (established)
src: [host=172.17.100.140, port=445]
dst: [host=172.17.100.38, port=48865]

tcp4 (established)
src: [host=172.17.100.140, port=3389]
dst: [host=192.168.10.254, port=48614]

tcp4 (listen)
src: [host=172.17.100.140, port=9505]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=172.17.100.140, port=9505]
dst: [host=172.17.100.140, port=58770]

tcp4 (established)
src: [host=172.17.100.140, port=49517]
dst: [host=172.17.100.141, port=1433]

tcp4 (established)
src: [host=172.17.100.140, port=49672]
dst: [host=172.17.100.141, port=1433]

tcp4 (established)
src: [host=172.17.100.140, port=50609]
dst: [host=172.17.100.141, port=1433]

tcp4 (established)
src: [host=172.17.100.140, port=51045]
dst: [host=192.168.10.20, port=13000]

tcp4 (established)
src: [host=172.17.100.140, port=51068]
dst: [host=172.17.100.38, port=48867]

tcp4 (established)
src: [host=172.17.100.140, port=53675]
dst: [host=172.17.100.141, port=1433]

tcp4 (established)
src: [host=172.17.100.140, port=55966]
dst: [host=172.17.100.141, port=3389]

tcp4 (established)
src: [host=172.17.100.140, port=57404]
dst: [host=172.17.100.141, port=1433]

tcp4 (established)
src: [host=172.17.100.140, port=57946]
dst: [host=172.17.100.141, port=1433]

tcp4 (established)
src: [host=172.17.100.140, port=58770]
dst: [host=172.17.100.140, port=9505]

tcp4 (established)
src: [host=172.17.100.140, port=58829]
dst: [host=172.17.100.141, port=1433]

tcp4 (established)
src: [host=172.17.100.140, port=61960]
dst: [host=172.17.100.141, port=1433]

tcp4 (established)
src: [host=172.17.100.140, port=62455]
dst: [host=172.17.100.141, port=1433]

tcp6 (listen)
src: [host=[::], port=80]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=135]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=443]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=445]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=1801]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=1947]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=2103]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=2105]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=2107]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=3389]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=5357]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=5985]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=7001]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=8001]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=8002]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=47001]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49664]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49665]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49666]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49667]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49668]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49669]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49670]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49678]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49744]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=51068]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::1], port=30523]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::1], port=49956]
dst: [host=[::], port=0]

udp4 (listen)
src: [host=0.0.0.0, port=123]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=500]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=1947]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=3389]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=3702]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=3702]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=4500]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=5353]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=5355]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=15000]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=52697]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=53616]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=59535]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=137]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=138]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=5060]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6000]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6001]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6002]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6003]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6004]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6005]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6006]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6007]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6008]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6009]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6010]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6011]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6012]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6013]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6014]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6015]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6016]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6017]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6018]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6019]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6020]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6021]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6022]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6023]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6024]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6025]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6026]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6027]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6028]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6029]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6030]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6031]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6032]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6033]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6034]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6035]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6036]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6037]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6038]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6039]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6040]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6041]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6042]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6043]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6044]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6045]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6046]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6047]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6048]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6049]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6050]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6051]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6052]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6053]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6054]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6055]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6056]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6057]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6058]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6059]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6060]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6061]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6062]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6063]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6064]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6065]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6066]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6067]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6068]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6069]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6070]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6071]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6072]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6073]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6074]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6075]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6076]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6077]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6078]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6079]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6080]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6081]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6082]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6083]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6084]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6085]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6086]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6087]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6088]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6089]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6090]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6091]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6092]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6093]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6094]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6095]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6096]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6097]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6098]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6099]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6100]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6101]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6102]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6103]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6104]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6105]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6106]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6107]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6108]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6109]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6110]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6111]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6112]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6113]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6114]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6115]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6116]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6117]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6118]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6119]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6120]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6121]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6122]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6123]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6124]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6125]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6126]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6127]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6128]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6129]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6130]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6131]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6132]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6133]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6134]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6135]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6136]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6137]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6138]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6139]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6140]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6141]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6142]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6143]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6144]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6145]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6146]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6147]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6148]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6149]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6150]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6151]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6152]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6153]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6154]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6155]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6156]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6157]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6158]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6159]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6160]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6161]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6162]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6163]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6164]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6165]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6166]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6167]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6168]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6169]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6170]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6171]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6172]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6173]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6174]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6175]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6176]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6177]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6178]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6179]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6180]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6181]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6182]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6183]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6184]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6185]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6186]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6187]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6188]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6189]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6190]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6191]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6192]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6193]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6194]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6195]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6196]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6197]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6198]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6199]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6200]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6201]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6202]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6203]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6204]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6205]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6206]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6207]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6208]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6209]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6210]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6211]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6212]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6213]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6214]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6215]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6216]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6217]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6218]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6219]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6220]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6221]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6222]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6223]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6224]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6225]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6226]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6227]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6228]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6229]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6230]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6231]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6232]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6233]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6234]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6235]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6236]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6237]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6238]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6239]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6240]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6241]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6242]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6243]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6244]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6245]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6246]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6247]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6248]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6249]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6250]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6251]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6252]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6253]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6254]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6255]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6256]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6257]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6258]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6259]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6260]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6261]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6262]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6263]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6264]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6265]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6266]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6267]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6268]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6269]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6270]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6271]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6272]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6273]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6274]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6275]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6276]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6277]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6278]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6279]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6280]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6281]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6282]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6283]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6284]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6285]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6286]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6287]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6288]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6289]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6290]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6291]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6292]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6293]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6294]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6295]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6296]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6297]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6298]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6299]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6300]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6301]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6302]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6303]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6304]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6305]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6306]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6307]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6308]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6309]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6310]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6311]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6312]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6313]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6314]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6315]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6316]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6317]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6318]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6319]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6320]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6321]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6322]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6323]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6324]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6325]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6326]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6327]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6328]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6329]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6330]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6331]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6332]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6333]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6334]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6335]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6336]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6337]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6338]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6339]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6340]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6341]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6342]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6343]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6344]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6345]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6346]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6347]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6348]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6349]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6350]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6351]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6352]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6353]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6354]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6355]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6356]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6357]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6358]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6359]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6360]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6361]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6362]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6363]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6364]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6365]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6366]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6367]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6368]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6369]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6370]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6371]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6372]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6373]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6374]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6375]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6376]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6377]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6378]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6379]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6380]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6381]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6382]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6383]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6384]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6385]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6386]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6387]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6388]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6389]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6390]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6391]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6392]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6393]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6394]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6395]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6396]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6397]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6398]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6399]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6400]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6401]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6402]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6403]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6404]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6405]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6406]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6407]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6408]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6409]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6410]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6411]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6412]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6413]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6414]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6415]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6416]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6417]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6418]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6419]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6420]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6421]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6422]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6423]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6424]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6425]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6426]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6427]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6428]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6429]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6430]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6431]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6432]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6433]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6434]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6435]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6436]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6437]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6438]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6439]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6440]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6441]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6442]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6443]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6444]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6445]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6446]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6447]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6448]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6449]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6450]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6451]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6452]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6453]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6454]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6455]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6456]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6457]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6458]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6459]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6460]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6461]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6462]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6463]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6464]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6465]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6466]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6467]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6468]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6469]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6470]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6471]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6472]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6473]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6474]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6475]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6476]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6477]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6478]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6479]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6480]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6481]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6482]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6483]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6484]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6485]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6486]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6487]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6488]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6489]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6490]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6491]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6492]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6493]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6494]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6495]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6496]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6497]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6498]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6499]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6500]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6501]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6502]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6503]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6504]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6505]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6506]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6507]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6508]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6509]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6510]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6511]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6512]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6513]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6514]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6515]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6516]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6517]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6518]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6519]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6520]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6521]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6522]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6523]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6524]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6525]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6526]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6527]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6528]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6529]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6530]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6531]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6532]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6533]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6534]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6535]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6536]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6537]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6538]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6539]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6540]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6541]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6542]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6543]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6544]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6545]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6546]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6547]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6548]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6549]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6550]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6551]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6552]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6553]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6554]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6555]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6556]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6557]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6558]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6559]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6560]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6561]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6562]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6563]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6564]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6565]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6566]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6567]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6568]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6569]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6570]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6571]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6572]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6573]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6574]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6575]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6576]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6577]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6578]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6579]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6580]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6581]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6582]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6583]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6584]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6585]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6586]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6587]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6588]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6589]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6590]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6591]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6592]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6593]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6594]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6595]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6596]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6597]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6598]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6599]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6600]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6601]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6602]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6603]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6604]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6605]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6606]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6607]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6608]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6609]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6610]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6611]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6612]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6613]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6614]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6615]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6616]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6617]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6618]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6619]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6620]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6621]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6622]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6623]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6624]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6625]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6626]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6627]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6628]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6629]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6630]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6631]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6632]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6633]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6634]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6635]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6636]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6637]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6638]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6639]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6640]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6641]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6642]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6643]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6644]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6645]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6646]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6647]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6648]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6649]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6650]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6651]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6652]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6653]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6654]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6655]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6656]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6657]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6658]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6659]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6660]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6661]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6662]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6663]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6664]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6665]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6666]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6667]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6668]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6669]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6670]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6671]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6672]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6673]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6674]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6675]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6676]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6677]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6678]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6679]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6680]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6681]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6682]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6683]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6684]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6685]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6686]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6687]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6688]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6689]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6690]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6691]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6692]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6693]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6694]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6695]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6696]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6697]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6698]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6699]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6700]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6701]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6702]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6703]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6704]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6705]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6706]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6707]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6708]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6709]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6710]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6711]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6712]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6713]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6714]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6715]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6716]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6717]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6718]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6719]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6720]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6721]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6722]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6723]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6724]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6725]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6726]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6727]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6728]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6729]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6730]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6731]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6732]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6733]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6734]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6735]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6736]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6737]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6738]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6739]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6740]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6741]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6742]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6743]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6744]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6745]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6746]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6747]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6748]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6749]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6750]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6751]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6752]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6753]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6754]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6755]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6756]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6757]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6758]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6759]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6760]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6761]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6762]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6763]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6764]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6765]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6766]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6767]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6768]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6769]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6770]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6771]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6772]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6773]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6774]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6775]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6776]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6777]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6778]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6779]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6780]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6781]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6782]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6783]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6784]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6785]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6786]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6787]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6788]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6789]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6790]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6791]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6792]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6793]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6794]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6795]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6796]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6797]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6798]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.54.158.102, port=6799]
dst: [host=*, port=*]

udp4 (listen)
src: [host=127.0.0.1, port=59534]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=123]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=500]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=1947]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=3389]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=3702]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=3702]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=4500]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=15000]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=52698]
dst: [host=*, port=*]
34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/0


Nessus was able to find 41 open ports.

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/80/www

Port 80/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/123

Port 123/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/135/epmap

Port 135/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/443

Port 443/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/445/cifs

Port 445/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/500

Port 500/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/1801/msmq

Port 1801/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/1947/www

Port 1947/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/1947

Port 1947/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/2103/dce-rpc

Port 2103/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/2105/dce-rpc

Port 2105/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/2107/dce-rpc

Port 2107/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/3389/msrdp

Port 3389/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/3389

Port 3389/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/3702

Port 3702/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/4500

Port 4500/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/5061

Port 5061/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/5353

Port 5353/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/5355/llmnr

Port 5355/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/5357/www

Port 5357/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/5985/www

Port 5985/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/7001/www

Port 7001/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/8001/www

Port 8001/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/8002/www

Port 8002/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/9505/www

Port 9505/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/15000

Port 15000/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/47001/www

Port 47001/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49664/dce-rpc

Port 49664/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49665/dce-rpc

Port 49665/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49666/dce-rpc

Port 49666/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49667/dce-rpc

Port 49667/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49668/dce-rpc

Port 49668/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49669/dce-rpc

Port 49669/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49670/dce-rpc

Port 49670/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49678/dce-rpc

Port 49678/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49744/dce-rpc

Port 49744/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/51068

Port 51068/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/52697

Port 52697/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/53616

Port 53616/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/59535

Port 59535/udp was found to be open

24272 - Network Interfaces Enumeration (WMI)
-
Synopsis
Nessus was able to obtain the list of network interfaces on the remote host.
Description
Nessus was able, via WMI queries, to extract a list of network interfaces on the remote host and the IP addresses attached to them.
Note that this plugin only enumerates IPv6 addresses for systems running Windows Vista or later.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/02/03, Modified: 2025/12/15
Plugin Output

tcp/0

+ Network Interface Information :

- Network Interface = [00000003] vmxnet3 Ethernet Adapter
- MAC Address = 00:50:56:88:13:C1
- IPAddress/IPSubnet = 172.17.100.140/255.255.255.0

+ Network Interface Information :

- Network Interface = [00000004] vmxnet3 Ethernet Adapter
- MAC Address = 00:50:56:88:84:22
- IPAddress/IPSubnet = 10.54.158.102/255.255.255.252


+ Routing Information :

Destination Netmask Gateway
----------- ------- -------
0.0.0.0 0.0.0.0 172.17.100.10
10.54.158.0 255.255.255.0 10.54.158.101
10.54.158.100 255.255.255.252 0.0.0.0
10.54.158.102 255.255.255.255 0.0.0.0
10.54.158.103 255.255.255.255 0.0.0.0
10.79.162.0 255.255.255.0 10.54.158.101
10.79.210.0 255.255.255.0 10.54.158.101
127.0.0.0 255.0.0.0 0.0.0.0
127.0.0.1 255.255.255.255 0.0.0.0
127.255.255.255 255.255.255.255 0.0.0.0
172.17.100.0 255.255.255.0 0.0.0.0
172.17.100.140 255.255.255.255 0.0.0.0
172.17.100.255 255.255.255.255 0.0.0.0
224.0.0.0 240.0.0.0 0.0.0.0
224.0.0.0 240.0.0.0 0.0.0.0
224.0.0.0 240.0.0.0 0.0.0.0
255.255.255.255 255.255.255.255 0.0.0.0
255.255.255.255 255.255.255.255 0.0.0.0
255.255.255.255 255.255.255.255 0.0.0.0
209654 - OS Fingerprints Detected
-
Synopsis
Multiple OS fingerprints were detected.
Description
Using a combination of remote probes (TCP/IP, SMB, HTTP, NTP, SNMP, etc), it was possible to gather one or more fingerprints from the remote system. While the highest-confidence result was reported in plugin 11936, “OS Identification”, the complete set of fingerprints detected are reported here.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/02/26, Modified: 2025/03/03
Plugin Output

tcp/0


Following OS Fingerprints were found

Remote operating system : Microsoft Windows Server 2019
Confidence level : 56
Method : MLSinFP
Type : unknown
Fingerprint : unknown

Remote operating system : Windows
Confidence level : 50
Method : Misc
Type : general-purpose
Fingerprint : unknown

Remote operating system : Microsoft Windows Server 2019 Datacenter Build 17763
Confidence level : 100
Method : SMB_OS
Type : general-purpose
Fingerprint : unknown

Remote operating system : Microsoft Windows Server 2019 Datacenter Build 17763
Confidence level : 70
Method : HTTP
Type : general-purpose
Fingerprint : HTTP:Server: Microsoft-HTTPAPI/2.0


Remote operating system : Microsoft Windows Server 2019 Datacenter Build 17763
Confidence level : 70
Method : SinFP
Type : general-purpose
Fingerprint : SinFP:
P1:B11113:F0x12:W65392:O0204ffff:M1460:
P2:B11113:F0x12:W65535:O0204ffff0103030801010402:M1460:
P3:B00000:F0x00:W0:O0:M0
P4:191601_7_p=49667

Following fingerprints could not be used to determine OS :
SSLcert:!:i/CN:LKP_SIP_AppSrv-140s/CN:LKP_SIP_AppSrv-140
3328cc346be861f87bb9ad91f2cec3ab489a8fc1
11936 - OS Identification
-
Synopsis
It is possible to guess the remote operating system.
Description
Using a combination of remote probes (e.g., TCP/IP, SMB, HTTP, NTP, SNMP, etc.), it is possible to guess the name of the remote operating system in use. It is also possible sometimes to guess the version of the operating system.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2003/12/09, Modified: 2025/06/03
Plugin Output

tcp/0


Remote operating system : Microsoft Windows Server 2019 Datacenter Build 17763
Confidence level : 100
Method : SMB_OS


The remote host is running Microsoft Windows Server 2019 Datacenter Build 17763

117887 - OS Security Patch Assessment Available
-
Synopsis
Nessus was able to log in to the remote host using the provided credentials and enumerate OS security patch levels.
Description
Nessus was able to determine OS security patch levels by logging into the remote host and running commands to determine the version of the operating system and its components. The remote host was identified as an operating system or device that Nessus supports for patch and update assessment. The necessary information was obtained to perform these checks.
Solution
n/a
Risk Factor
None
References
XREF IAVB:0001-B-0516
Plugin Information
Published: 2018/10/02, Modified: 2021/07/12
Plugin Output

tcp/445/cifs

OS Security Patch Assessment is available.

Account : 172.17.100.140\tidua
Protocol : SMB

92426 - OpenSaveMRU History
-
Synopsis
Nessus was able to enumerate opened and saved files on the remote host.
Description
Nessus was able to generate a report on files that were opened using the shell dialog box or saved using the shell dialog box. This is the box that appears when you attempt to save a document or open a document in Windows Explorer.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

Open / Save report attached.
66334 - Patch Report
-
Synopsis
The remote host is missing several patches.
Description
The remote host is missing one or more security patches. This plugin lists the newest version of each patch to install to make sure the remote host is up-to-date.

Note: Because the 'Show missing patches that have been superseded' setting in your scan policy depends on this plugin, it will always run and cannot be disabled.
Solution
Install the patches listed below.
Risk Factor
None
Plugin Information
Published: 2013/07/08, Modified: 2025/12/15
Plugin Output

tcp/0



. You need to take the following 40 actions :

+ Install the following Microsoft patches :
- KB4011574 (MS18-01) (3 vulnerabilities)The following KBs would be covered:
[4041083; 4049016], [4049016, 4041083]
- KB5071544 (10 vulnerabilities)The following KBs would be covered:
KB5063877, KB5065428, KB5066586, KB5055519, KB5052000,
KB5058392, KB5060531, KB5068791, KB5062557, KB5053596
- KB5002820 (20 vulnerabilities)The following KBs would be covered:
KB5002758, KB5002782, KB5002794, KB5002704, KB5002687,
KB5002735, KB5002717, KB5002660, KB5002673, KB5002811,
KB5002749, KB5002696, KB5002587, KB5002605, KB5002643,
KB5002536, KB5002518, KB5002653, KB5002463, KB5002496
- KB5002806 (12 vulnerabilities)The following KBs would be covered:
KB5002763, KB5002780, KB5002619, KB5002702, KB5002710,
KB5002789, KB5002745, KB5002662, KB5002542, KB5002520,
KB5002464, KB5002497
- KB5002790 (14 vulnerabilities)The following KBs would be covered:
KB5002765, KB5002779, KB5002586, KB5002689, KB5002746,
KB4504720, KB5002495, KB4493224, KB4484393, KB4484166,
KB4461532, KB4011041, KB4461434, KB3114518
- KB5002747
- KB5002683 (8 vulnerabilities)The following KBs would be covered:
KB5002656, KB5002626, KB5002543, KB5002600, KB5002529,
KB5002621, KB5002459, KB5002499
- KB5002622 (1 vulnerabilities)The following KBs would be covered:
KB4484434
- KB5002566 (2 vulnerabilities)The following KBs would be covered:
KB5002492, KB5002462
- KB5002427 (23 vulnerabilities)The following KBs would be covered:
KB5002051, KB5002254, KB5002387, KB5001942, KB4486748,
KB4484475, KB4484274, KB4475553, KB4486671, KB4484433,
KB4484250, KB4461601, KB4461544, KB4475517, KB4032235,
KB4461440, KB4011682, KB4011162, KB4011626, KB4461506,
KB4022160, KB4011052, KB4011091
- KB5002426 (4 vulnerabilities)The following KBs would be covered:
KB5002351, KB5002322, KB5002386, KB5002405
- KB5002406 (45 vulnerabilities)The following KBs would be covered:
KB3128057, KB3178674, KB3191865, KB5002323, KB5002369,
KB5002223, KB5002184, KB5002139, KB5002057, KB5002004,
KB5001949, KB4493198, KB5001919, KB4486719, KB4493156,
KB4484474, KB4484510, KB4486679, KB4484169, KB4484300,
KB4484396, KB4484268, KB4461543, KB4464536, KB4461504,
KB4475540, KB4464596, KB4022218, KB4092447, KB4461449,
KB4018339, KB4011643, KB4018383, KB4011575, KB4011730,
KB3191945, KB4011222, KB4011242, KB3118331, KB3115439,
KB3115301, KB3115182, KB3115094, KB3142577, KB3154208
- KB5002253 (25 vulnerabilities)The following KBs would be covered:
KB5002232, KB5002177, KB5002196, KB5002098, KB5002114,
KB5002137, KB5001977, KB5002003, KB5002030, KB4504721,
KB4493196, KB5002056, KB5001918, KB5001947, KB4486754,
KB4493165, KB4493233, KB4484465, KB4484507, KB4484273,
KB4484338, KB4486718, KB4484403, KB4484256, KB4486678
- KB5002221 (3 vulnerabilities)The following KBs would be covered:
KB4011097, KB2920680, KB4493152
- KB4484217 (29 vulnerabilities)The following KBs would be covered:
KB3128016, KB4484179, KB4475513, KB4475579, KB4484112,
KB4462236, KB4461542, KB4484144, KB4462115, KB4092460,
KB4461448, KB4018337, KB4011220, KB4461503, KB4011727,
KB4011050, KB3178673, KB4032229, KB4018382, KB4022174,
KB3203477, KB3127904, KB3118290, KB3115272, KB3114964,
KB3114698, KB3114520, KB3101510, KB2920693
- KB4484103
- KB4464534
- KB4011185
- KB3213551 (2 vulnerabilities)The following KBs would be covered:
KB3203383, KB3114375
- KB3191932 (2 vulnerabilities)The following KBs would be covered:
KB3178664, KB3118293
- KB3178702 (8 vulnerabilities)The following KBs would be covered:
KB3127986, KB3115415, KB3115144, KB3114702, KB3114526,
KB3114382, KB3101513, KB2920691
- KB3115440
- KB3115419 (1 vulnerabilities)The following KBs would be covered:
KB3114862
- KB3115279 (1 vulnerabilities)The following KBs would be covered:
KB3114861
- KB3085635
- KB2920726
- KB2920723

[ JQuery 1.2 < 3.5.0 Multiple XSS (136929) ]

+ Action to take : Upgrade to JQuery version 3.5.0 or later.

+ Impact : Taking this action will resolve the following 2 different vulnerabilities :
CVE-2020-11023, CVE-2020-11022


[ MS13-002: Vulnerabilities in Microsoft XML Core Services Could Allow Remote Code Execution (2756145) (63420) ]

+ Action to take : Microsoft has released a set of patches for Windows XP, 2003, Vista, 2008, 7, and 2008 R2, 8, 2012, Office 2003, 2007, Word Viewer, Office Compatibility Pack, Expression Web Service, Expression Web 2, SharePoint Server 2007 and Groove Server 2007.

+ Impact : Taking this action will resolve the following 2 different vulnerabilities :
CVE-2013-0007, CVE-2013-0006


[ Microsoft ASP.NET Core Security Feature Bypass (October 2025) (270707) ]

+ Action to take : Update .NET Core to version 8.0.21, 9.0.10, 10.0.0-rc.2.25502.107 or later.


[ Security Update for Microsoft .NET Core (October 2025) (270711) ]

+ Action to take : Update .NET Core, remove vulnerable packages and refer to vendor advisory.

+ Impact : Taking this action will resolve the following 12 different vulnerabilities :
CVE-2025-55248, CVE-2025-30399, CVE-2025-26682, CVE-2025-26646, CVE-2025-24070
CVE-2025-21176, CVE-2025-21173, CVE-2025-21172, CVE-2024-43485, CVE-2024-43484
CVE-2024-43483, CVE-2024-38229


[ Security Updates for Microsoft Excel Products (December 2025) (277999) ]

+ Action to take : Microsoft has released KB5002820 to address this issue.

+ Impact : Taking this action will resolve the following 6 different vulnerabilities :
CVE-2025-62564, CVE-2025-62563, CVE-2025-62561, CVE-2025-62560, CVE-2025-62556
CVE-2025-62553


[ Security Updates for Microsoft Office Products (December 2025) (277985) ]

+ Action to take : Microsoft has released the following updates to address these issues:
- KB5002812
- KB5002818
- KB5002819

+ Impact : Taking this action will resolve the following 545 different vulnerabilities :
CVE-2025-62563, CVE-2025-62561, CVE-2025-62557, CVE-2025-62554, CVE-2025-62553
CVE-2025-62552, CVE-2025-62203, CVE-2025-62202, CVE-2025-62201, CVE-2025-62200
CVE-2025-62199, CVE-2025-60727, CVE-2025-60726, CVE-2025-59240, CVE-2025-59235
CVE-2025-59234, CVE-2025-59233, CVE-2025-59232, CVE-2025-59231, CVE-2025-59227
CVE-2025-59226, CVE-2025-59225, CVE-2025-59224, CVE-2025-59223, CVE-2025-54910
CVE-2025-54906, CVE-2025-54904, CVE-2025-54903, CVE-2025-54902, CVE-2025-54901
CVE-2025-54900, CVE-2025-54899, CVE-2025-54898, CVE-2025-54896, CVE-2025-53741
CVE-2025-53740, CVE-2025-53739, CVE-2025-53737, CVE-2025-53735, CVE-2025-53731
CVE-2025-49711, CVE-2025-49702, CVE-2025-49700, CVE-2025-49699, CVE-2025-49698
CVE-2025-49697, CVE-2025-49696, CVE-2025-49695, CVE-2025-48812, CVE-2025-47994
CVE-2025-47953, CVE-2025-47173, CVE-2025-47167, CVE-2025-47165, CVE-2025-47164
CVE-2025-47162, CVE-2025-32704, CVE-2025-30386, CVE-2025-30383, CVE-2025-30381
CVE-2025-30379, CVE-2025-30377, CVE-2025-30376, CVE-2025-30375, CVE-2025-29979
CVE-2025-29977, CVE-2025-29816, CVE-2025-29792, CVE-2025-29791, CVE-2025-27752
CVE-2025-27751, CVE-2025-27750, CVE-2025-27749, CVE-2025-27748, CVE-2025-27746
CVE-2025-27745, CVE-2025-26642, CVE-2025-24083, CVE-2025-24082, CVE-2025-24081
CVE-2025-24080, CVE-2025-24075, CVE-2025-24057, CVE-2025-21394, CVE-2025-21392
CVE-2025-21390, CVE-2025-21387, CVE-2025-21386, CVE-2025-21383, CVE-2025-21381
CVE-2025-21362, CVE-2025-21346, CVE-2024-49069, CVE-2024-49065, CVE-2024-49059
CVE-2024-49032, CVE-2024-49031, CVE-2024-49030, CVE-2024-49029, CVE-2024-49028
CVE-2024-49027, CVE-2024-49026, CVE-2024-43609, CVE-2024-43600, CVE-2024-43504
CVE-2024-43465, CVE-2024-38200, CVE-2024-38021, CVE-2024-38020, CVE-2024-30104
CVE-2024-30101, CVE-2024-30042, CVE-2024-21413, CVE-2024-20673, CVE-2023-41764
CVE-2023-36896, CVE-2023-36767, CVE-2023-36766, CVE-2023-36413, CVE-2023-36041
CVE-2023-36037, CVE-2023-33162, CVE-2023-33153, CVE-2023-33152, CVE-2023-33149
CVE-2023-33137, CVE-2023-33133, CVE-2023-32029, CVE-2023-24953, CVE-2023-23399
CVE-2023-23398, CVE-2022-41106, CVE-2022-41104, CVE-2022-41063, CVE-2022-38048
CVE-2022-37962, CVE-2022-34717, CVE-2022-33632, CVE-2022-33631, CVE-2022-30173
CVE-2022-29110, CVE-2022-26901, CVE-2022-24473, CVE-2022-23252, CVE-2022-22716
CVE-2022-22004, CVE-2022-22003, CVE-2022-21988, CVE-2022-21841, CVE-2022-21840
CVE-2021-43875, CVE-2021-43256, CVE-2021-43255, CVE-2021-42295, CVE-2021-42293
CVE-2021-42292, CVE-2021-41368, CVE-2021-40485, CVE-2021-40479, CVE-2021-40474
CVE-2021-40473, CVE-2021-40472, CVE-2021-40471, CVE-2021-40454, CVE-2021-40442
CVE-2021-38660, CVE-2021-38659, CVE-2021-38658, CVE-2021-38657, CVE-2021-38655
CVE-2021-38650, CVE-2021-38646, CVE-2021-34518, CVE-2021-34501, CVE-2021-34469
CVE-2021-31949, CVE-2021-31941, CVE-2021-31940, CVE-2021-31939, CVE-2021-31180
CVE-2021-31179, CVE-2021-31178, CVE-2021-31177, CVE-2021-31176, CVE-2021-31175
CVE-2021-31174, CVE-2021-28456, CVE-2021-28455, CVE-2021-28454, CVE-2021-28453
CVE-2021-28451, CVE-2021-28449, CVE-2021-27059, CVE-2021-27057, CVE-2021-27054
CVE-2021-27053, CVE-2021-24108, CVE-2021-24070, CVE-2021-24069, CVE-2021-24068
CVE-2021-24067, CVE-2021-1716, CVE-2021-1715, CVE-2021-1714, CVE-2021-1713
CVE-2021-1711, CVE-2020-17130, CVE-2020-17129, CVE-2020-17128, CVE-2020-17127
CVE-2020-17126, CVE-2020-17125, CVE-2020-17123, CVE-2020-17122, CVE-2020-17067
CVE-2020-17066, CVE-2020-17065, CVE-2020-17064, CVE-2020-17062, CVE-2020-16957
CVE-2020-16954, CVE-2020-16932, CVE-2020-16931, CVE-2020-16930, CVE-2020-16929
CVE-2020-1594, CVE-2020-1583, CVE-2020-1581, CVE-2020-1563, CVE-2020-1504
CVE-2020-1503, CVE-2020-1498, CVE-2020-1497, CVE-2020-1496, CVE-2020-1495
CVE-2020-1494, CVE-2020-1338, CVE-2020-1335, CVE-2020-1332, CVE-2020-1229
CVE-2020-1226, CVE-2020-1225, CVE-2020-1224, CVE-2020-1218, CVE-2020-1193
CVE-2020-0991, CVE-2020-0980, CVE-2020-0979, CVE-2020-0961, CVE-2020-0906
CVE-2020-0901, CVE-2020-0760, CVE-2020-0759, CVE-2020-0652, CVE-2020-0651
CVE-2020-0650, CVE-2019-1464, CVE-2019-1463, CVE-2019-1462, CVE-2019-1461
CVE-2019-1449, CVE-2019-1448, CVE-2019-1446, CVE-2019-1402, CVE-2019-1400
CVE-2019-1331, CVE-2019-1327, CVE-2019-1297, CVE-2019-1264, CVE-2019-1263
CVE-2019-1246, CVE-2019-1205, CVE-2019-1204, CVE-2019-1201, CVE-2019-1200
CVE-2019-1199, CVE-2019-1155, CVE-2019-1112, CVE-2019-1111, CVE-2019-1110
CVE-2019-1109, CVE-2019-1084, CVE-2019-0947, CVE-2019-0946, CVE-2019-0945
CVE-2019-0828, CVE-2019-0827, CVE-2019-0826, CVE-2019-0825, CVE-2019-0824
CVE-2019-0823, CVE-2019-0822, CVE-2019-0801, CVE-2019-0675, CVE-2019-0674
CVE-2019-0673, CVE-2019-0672, CVE-2019-0671, CVE-2019-0669, CVE-2019-0585
CVE-2019-0582, CVE-2019-0561, CVE-2019-0560, CVE-2019-0559, CVE-2019-0541
CVE-2019-0540, CVE-2019-0538, CVE-2018-8636, CVE-2018-8627, CVE-2018-8598
CVE-2018-8597, CVE-2018-8577, CVE-2018-8574, CVE-2018-8573, CVE-2018-8539
CVE-2018-8504, CVE-2018-8502, CVE-2018-8501, CVE-2018-8429, CVE-2018-8382
CVE-2018-8379, CVE-2018-8378, CVE-2018-8375, CVE-2018-8248, CVE-2018-8246
CVE-2018-8173, CVE-2018-8163, CVE-2018-8162, CVE-2018-8161, CVE-2018-8160
CVE-2018-8158, CVE-2018-8157, CVE-2018-8150, CVE-2018-8148, CVE-2018-8147
CVE-2018-1030, CVE-2018-1029, CVE-2018-1028, CVE-2018-1027, CVE-2018-1026
CVE-2018-1011, CVE-2018-1007, CVE-2018-0950, CVE-2018-0920, CVE-2018-0862
CVE-2018-0853, CVE-2018-0851, CVE-2018-0849, CVE-2018-0848, CVE-2018-0845
CVE-2018-0812, CVE-2018-0807, CVE-2018-0806, CVE-2018-0805, CVE-2018-0804
CVE-2018-0802, CVE-2018-0801, CVE-2018-0798, CVE-2018-0797, CVE-2018-0796
CVE-2018-0795, CVE-2018-0794, CVE-2018-0793, CVE-2017-8744, CVE-2017-8742
CVE-2017-8696, CVE-2017-8695, CVE-2017-8682, CVE-2017-8676, CVE-2017-8663
CVE-2017-8632, CVE-2017-8631, CVE-2017-8630, CVE-2017-8572, CVE-2017-8571
CVE-2017-8570, CVE-2017-8550, CVE-2017-8534, CVE-2017-8533, CVE-2017-8532
CVE-2017-8531, CVE-2017-8528, CVE-2017-8527, CVE-2017-8513, CVE-2017-8512
CVE-2017-8511, CVE-2017-8510, CVE-2017-8509, CVE-2017-8508, CVE-2017-8507
CVE-2017-8506, CVE-2017-8502, CVE-2017-8501, CVE-2017-11884, CVE-2017-11882
CVE-2017-11878, CVE-2017-11877, CVE-2017-11854, CVE-2017-11826, CVE-2017-11825
CVE-2017-0292, CVE-2017-0289, CVE-2017-0288, CVE-2017-0287, CVE-2017-0286
CVE-2017-0285, CVE-2017-0284, CVE-2017-0283, CVE-2017-0282, CVE-2017-0281
CVE-2017-0262, CVE-2017-0261, CVE-2017-0260, CVE-2017-0255, CVE-2017-0254
CVE-2017-0243, CVE-2017-0207, CVE-2017-0204, CVE-2017-0199, CVE-2017-0197
CVE-2017-0195, CVE-2017-0194, CVE-2017-0107, CVE-2017-0106, CVE-2017-0105
CVE-2017-0053, CVE-2017-0052, CVE-2017-0031, CVE-2017-0030, CVE-2017-0029
CVE-2017-0027, CVE-2017-0020, CVE-2017-0019, CVE-2017-0006, CVE-2017-0003
CVE-2016-7298, CVE-2016-7291, CVE-2016-7290, CVE-2016-7289, CVE-2016-7277
CVE-2016-7276, CVE-2016-7275, CVE-2016-7268, CVE-2016-7267, CVE-2016-7266
CVE-2016-7265, CVE-2016-7264, CVE-2016-7263, CVE-2016-7262, CVE-2016-7245
CVE-2016-7244, CVE-2016-7236, CVE-2016-7235, CVE-2016-7234, CVE-2016-7233
CVE-2016-7232, CVE-2016-7231, CVE-2016-7230, CVE-2016-7229, CVE-2016-7228
CVE-2016-7213, CVE-2016-7193, CVE-2016-3381, CVE-2016-3366, CVE-2016-3365
CVE-2016-3364, CVE-2016-3363, CVE-2016-3362, CVE-2016-3361, CVE-2016-3360
CVE-2016-3359, CVE-2016-3358, CVE-2016-3357, CVE-2016-3318, CVE-2016-3317
CVE-2016-3316, CVE-2016-3315, CVE-2016-3313, CVE-2016-3284, CVE-2016-3283
CVE-2016-3282, CVE-2016-3281, CVE-2016-3280, CVE-2016-3279, CVE-2016-3278
CVE-2016-3235, CVE-2016-3234, CVE-2016-3233, CVE-2016-0198, CVE-2016-0183
CVE-2016-0141, CVE-2016-0140, CVE-2016-0139, CVE-2016-0137, CVE-2016-0136
CVE-2016-0134, CVE-2016-0127, CVE-2016-0126, CVE-2016-0122, CVE-2016-0057
CVE-2016-0056, CVE-2016-0055, CVE-2016-0054, CVE-2016-0053, CVE-2016-0052
CVE-2016-0039, CVE-2016-0035, CVE-2016-0025, CVE-2016-0022, CVE-2016-0021
CVE-2016-0012, CVE-2016-0011, CVE-2016-0010, CVE-2015-6177, CVE-2015-6172
CVE-2015-6124, CVE-2015-6122, CVE-2015-6118, CVE-2015-6117, CVE-2015-6094
CVE-2015-6093, CVE-2015-6092, CVE-2015-6091, CVE-2015-6040, CVE-2015-6039
CVE-2015-6038, CVE-2015-6037, CVE-2015-2558, CVE-2015-2557, CVE-2015-2556
CVE-2015-2555, CVE-2015-2545, CVE-2015-2523, CVE-2015-2522, CVE-2015-2521
CVE-2015-2520, CVE-2015-2503, CVE-2015-2477, CVE-2015-2470, CVE-2015-2469
CVE-2015-2468, CVE-2015-2467, CVE-2015-2466, CVE-2015-2423, CVE-2015-1642



[ Security Updates for Microsoft OneNote Products (April 2025) (234035) ]

+ Action to take : Microsoft has released KB5002622 to address this issue.


[ Security Updates for Microsoft PowerPoint Products (October 2025) (270692) ]

+ Action to take : Microsoft has released KB5002790 to address this issue.

+ Impact : Taking this action will resolve the following 15 different vulnerabilities :
CVE-2025-59238, CVE-2025-54908, CVE-2025-53761, CVE-2025-49705, CVE-2025-47175
CVE-2024-38171, CVE-2024-20673, CVE-2021-27056, CVE-2020-17124, CVE-2020-0760
CVE-2019-1462, CVE-2018-8628, CVE-2018-8501, CVE-2017-8743, CVE-2017-8742



[ Security Updates for Microsoft Publisher Products (September 2024) (206892) ]

+ Action to take : Microsoft has released KB5002566 to address this issue.

+ Impact : Taking this action will resolve the following 6 different vulnerabilities :
CVE-2024-38226, CVE-2024-20673, CVE-2023-28295, CVE-2023-28287, CVE-2022-29107
CVE-2020-0760


[ Security Updates for Microsoft Word Products (December 2025) (277989) ]

+ Action to take : Microsoft has released KB5002806 to address this issue.

+ Impact : Taking this action will resolve the following 81 different vulnerabilities :
CVE-2025-62562, CVE-2025-62559, CVE-2025-62558, CVE-2025-62555, CVE-2025-59222
CVE-2025-59221, CVE-2025-54905, CVE-2025-53738, CVE-2025-53736, CVE-2025-53733
CVE-2025-49703, CVE-2025-47169, CVE-2025-47168, CVE-2025-29820, CVE-2025-29816
CVE-2025-27747, CVE-2025-24079, CVE-2025-24078, CVE-2024-49033, CVE-2024-21379
CVE-2024-20673, CVE-2023-36895, CVE-2023-36762, CVE-2023-36761, CVE-2023-36009
CVE-2023-33150, CVE-2023-29335, CVE-2023-21716, CVE-2022-41103, CVE-2022-41061
CVE-2022-41060, CVE-2022-29107, CVE-2022-24511, CVE-2022-24462, CVE-2022-21842
CVE-2021-40486, CVE-2021-34452, CVE-2021-31180, CVE-2021-28453, CVE-2021-1716
CVE-2021-1715, CVE-2020-17020, CVE-2020-16933, CVE-2020-1583, CVE-2020-1503
CVE-2020-1502, CVE-2020-1448, CVE-2020-1447, CVE-2020-1446, CVE-2020-1445
CVE-2020-1342, CVE-2020-1229, CVE-2020-1218, CVE-2020-0980, CVE-2020-0892
CVE-2020-0850, CVE-2020-0760, CVE-2019-1461, CVE-2019-1201, CVE-2019-1034
CVE-2019-0953, CVE-2019-0585, CVE-2019-0561, CVE-2018-8573, CVE-2018-8504
CVE-2018-8430, CVE-2018-8310, CVE-2018-8161, CVE-2018-0950, CVE-2018-0922
CVE-2018-0919, CVE-2018-0862, CVE-2018-0849, CVE-2018-0848, CVE-2018-0845
CVE-2018-0798, CVE-2018-0797, CVE-2018-0794, CVE-2018-0793, CVE-2018-0792
CVE-2017-11854


[ Security Updates for Outlook (July 2025) (241560) ]

+ Action to take : Microsoft has released KB5002747 to address this issue.

+ Impact : Taking this action will resolve the following 48 different vulnerabilities :
CVE-2025-62564, CVE-2025-62563, CVE-2025-62561, CVE-2025-62560, CVE-2025-62556
CVE-2025-62553, CVE-2025-49699, CVE-2025-47171, CVE-2025-21357, CVE-2024-38173
CVE-2024-38020, CVE-2024-30103, CVE-2024-21378, CVE-2023-36893, CVE-2023-36763
CVE-2023-35636, CVE-2023-35311, CVE-2023-33151, CVE-2023-33131, CVE-2023-23397
CVE-2022-35742, CVE-2021-31949, CVE-2021-28452, CVE-2020-17119, CVE-2020-16949
CVE-2020-16947, CVE-2020-1493, CVE-2020-1483, CVE-2020-1349, CVE-2020-0760
CVE-2020-0696, CVE-2019-1204, CVE-2019-1200, CVE-2019-1084, CVE-2019-0559
CVE-2018-8587, CVE-2018-8582, CVE-2018-8579, CVE-2018-8576, CVE-2018-8558
CVE-2018-8524, CVE-2018-8522, CVE-2018-8244, CVE-2018-0852, CVE-2018-0850
CVE-2018-0791, CVE-2017-11776, CVE-2017-11774


[ VMware Tools 11.x < 12.5.4 / 13.x < 13.0.5 Multiple Vulnerabilities (VMSA-2025-0015) (266420) ]

+ Action to take : Upgrade to VMware Tools version 12.5.4, 13.0.5 or later.

+ Impact : Taking this action will resolve the following 5 different vulnerabilities :
CVE-2025-41246, CVE-2025-41244, CVE-2025-41239, CVE-2025-22247, CVE-2025-22230



[ Wireshark 4.2.x < 4.2.12 / 4.4.x < 4.4.7 DoS (237766) ]

+ Action to take : Upgrade to Wireshark version 4.2.12, 4.4.7 or later.

+ Impact : Taking this action will resolve the following 7 different vulnerabilities :
CVE-2025-9817, CVE-2025-5601, CVE-2025-1492, CVE-2024-9781, CVE-2024-9780
CVE-2024-11596, CVE-2024-11595

206777 - Postman Installed (Windows)
-
Synopsis
Postman is installed on the remote Windows host.
Description
Postman is installed on the remote Windows host.

Note. To detect the software, customers need to use an account that is used to install the software, or one that has the administrative privileges on the target.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2024/09/09, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\Users\Administrator\AppData\Local\Postman
Version : 11.65.4
92428 - Recent File History
-
Synopsis
Nessus was able to enumerate recently opened files on the remote host.
Description
Nessus was able to gather evidence of files opened by file type from the remote host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

C:\\Users\Administrator\AppData\Roaming\Microsoft\Windows\Recent\XML.lnk

Recent files found in registry and appdata attached.
92429 - Recycle Bin Files
-
Synopsis
Nessus was able to enumerate files in the recycle bin on the remote host.
Description
Nessus was able to generate a list of all files found in $Recycle.Bin subdirectories.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

C:\\$Recycle.Bin\\.
C:\\$Recycle.Bin\\..
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\.
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\..
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I01HPBJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I033WUS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I04AT4N.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I04I6RK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I04ZLSC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I05M1QG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I05R8Y8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I06HC81.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I079J9V.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I07KHWJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I09AUJQ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0ALQNZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0B4FBH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0BHB25.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0BHOGA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0BX4V2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0D2DMK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0DD0VW.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0ELFY9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0EWD2E.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0F35XG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0FH4FH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0G84U4
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0GA43I.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0H8V8M.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0HGM4Z.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0HSP69.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0HZP9I.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0IJJZ8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0IL7W0
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0IQGN8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0JBP2B
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0JPXUN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0JZHNI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0K0RPV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0K4G28.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0K8T6C.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0L780J.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0M2FSI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0MOTC8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0MW3DU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0N0ZRW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0OMS3Y.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0RPEZU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0RQECC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0RQYVJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0SKYL9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0SU0WM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0THLHI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0U2DT9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0URTTI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0VKAMK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0VPOXV.18380
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0VQA3E.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0WESEF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0WRHP8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0X312R.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0X505W.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0X7742.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0YT13H.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0YWNYW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0ZJQMB.6826
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I0ZZL5C.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I10B29L.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I10DA1W.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I10QW3I.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I115XKW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I117R5B.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I11CQY1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I11EE4V.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I12QE9A.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I12U9T9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I136P8Q.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I13V8JN.xml
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I13Z2MC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I14T4QN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I15VSAX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I165EL8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I168XKQ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I16D61Z.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I16E02B.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I16LLIC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I16O961.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I16Q975.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I177F9L.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I17B91L.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I17KHFP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I17KRIW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I17MQY2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1A0FLM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1A512F.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1AIJ04.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1BIQNX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1D99LE.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1DOU5O.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1DPGGS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1DPHGJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1DYU8X.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1ENDNW.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1FNCUJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1FQ480.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1GLJD7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1GM1S1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1GOTGO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1GY5DA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1GYIPT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1ILOU1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1JJ9FZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1JKHAT.18380
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1JNEL1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1JT1B5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1JXDKV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1K0PKW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1K5P8V.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1KPL8M.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1KV15G.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1L3M1Q.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1LI6L9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1LVBVL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1M6HKD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1M79DC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1MAW53.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1MUGGR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1NSQNC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1ODHJF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1P4SWQ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1QL43S.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1R0J5D.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1R58ZU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1RBTKK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1RE70W.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1RQ37W.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1RWLRL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1SNCIM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1STGEN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1SX6HZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1T31M9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1T93LO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1TD3YE.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1TGW5L.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1TKN2P.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1UASUA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1UOG3Y.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1V845A.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1VJSYV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1VK1WF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1W2VN1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1W7MEW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1W9L8T.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1WB7B2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1WBKRV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1XW4FB.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1YNIAD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1YSNFM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I1YW30J.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I20F0U3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I211Y00.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I21GVN1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I21T1XO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I22NMZ1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I239COW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I23LCKU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I24M5RY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I25DNED.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I25UM2R.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I26OL0C.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I284QQV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I292V8I.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I29D0T3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I29SS3J.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I29ZXNN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2A1FGD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2A47ZW
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2BJAAD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2BXNT6.zip
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2C215R.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2C4EMP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2CN7JT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2D2OXF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2D7Q5B.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2DBVP0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2DGNYQ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2FG9LS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2FMQNP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2FVQ1R.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2GKYWD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2HID12.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2HSW4L.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2HZ4ZZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2IJJUO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2J22YO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2K94SV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2KCNVL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2KF3RF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2KFNNJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2L09YU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2L2YTP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2L73Y2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2M1F38.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2M3DOW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2MB0AN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2MDU75.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2MIART.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2MK2U5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2MSXAP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2N8KVM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2OD0Z0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2OEV65.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2OQ7Q9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2ORJ2E.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2Q6QTW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2R8QB9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2RINCN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2TGIHA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2TSNY5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2U1NA9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2UN1ST.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2UVZSZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2VEF55.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2VFKIN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2VOF7K.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2WV21C.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2YB595.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2YHKBJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2YLCQ3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2Z9WGQ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I2ZP9BO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I30BVLE.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I30Z9EF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I32TR9O.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I330Z6N.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I33AVBW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I33YA7K.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I35AZ70.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I35ELLY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I35MS06.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I35TT3L.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I365N3Q.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I368L3U.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I38ET28.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I38NZQD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I39N6H3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3BID5P
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3BK1MT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3BVYDH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3BWWO4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3CEE59.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3D2671.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3F6L0Y.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3FA0JZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3FBQZX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3FDRWM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3FIQKS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3G8AJY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3H850B.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3IGIZ2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3J7C8Q.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3JSZAE.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3JTWZH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3KQK8T.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3L2B7I.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3L46AU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3L6HXI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3LCJPN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3LEJYK
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3MJH8V.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3MWP19.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3N9SUX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3NSVBR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3QDRDU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3QG87S.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3QI7BR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3QJPGJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3R35FK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3RYFK1.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3SM9FH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3UOS8Q.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3V8YMW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3VC7JI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3VSMCR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3VSWL5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3VW9PV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3W1R5Z.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3WDUPQ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3WLFE0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3WO67O.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3WWXFP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3Y5T63.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3YU4KA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I3YY21E.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I402054.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I40TJ95.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I41WHK1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I429CNC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I42I7YX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I42KSZI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I42ZNLH.22215
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I43O7G1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I43U0KM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I445JCR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I45LV8F.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I45TCZF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I46ONHO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4811Q2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I48JTLF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I48N5BK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4AOIJ9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4BC9YH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4BGLGH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4C40Y6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4CYQ3X.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4D6SB9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4DBV8C.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4EIT8L.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4ER2K3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4ETIEB.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4F7HTZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4FAQH1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4GGWQP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4H3AS5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4H3S17.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4H9BGS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4HS80I.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4HU8CG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4HUHSW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4ILAO2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4J5II7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4J83IF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4JK8FV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4JM509.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4KQP60.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4KT3M1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4M7IAQ.31213
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4MOGXH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4MRMUD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4O110W.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4O63PN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4OGAX1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4PODR9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4PWHP9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4Q8ATV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4QJU1H.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4QO7C1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4SCH2F.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4THI9O.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4U099D.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4U9QYL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4UFEKF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4UU4RU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4WKIZX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4WOLYW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4WUGSY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4X5PRU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4XDHOO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4XH9VG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4XW8VA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4Y3ZB6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4Z061P.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I4ZGJ4Y.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I50DS2H.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I50M0TK.24369
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I50NYD8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I50ZI35.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I514Q1O
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I51512Y.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I51L9DJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I51TWDU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I520EC9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I56W7H0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I56Y8YY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I58NDRT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I592795.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I594VK4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5AAX20.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5BEEDK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5BPU76.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5CSZQT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5CXM9V.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5DGV3O.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5FCSFN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5GPQ1G.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5HGTAO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5HNRBE.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5HY436.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5I85CX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5IEFU8
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5JX8BJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5K9BNN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5KFUV4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5LDJFW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5LL5MM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5MCY2G.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5MJYQT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5MXAHF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5QEH0S
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5QEUZ2.xml
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5QMO33.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5RCBJP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5RD0BA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5RHWTN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5S8F6B.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5SL54U.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5SOGVM
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5SZJUD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5T9MIR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5TFFFT.xml
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5TJNH7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5TNFDD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5UHHD0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5V9IAX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5VNQTF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5VQ9OR.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5VQZ60.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5W2LRG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5WYSX2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5X0EDS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5Z2M6J.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5Z6FUS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5ZSS43.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I5ZURY2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6087I5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I60DLPY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I62BCI8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I63F5I5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I63H9G0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I63QJJI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I63XOYI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I64UL6E.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I65F7TW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I67QSIT
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I687YU9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I68ETWI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I68FUUQ
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I691WUY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I699V47.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I69WWSB.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I69ZH6E.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I69ZOM3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6AIDKZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6AOH0S.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6AVILY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6BDIMG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6C3NMO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6C88XR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6CMB38.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6E0U4E
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6ETN88.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6F28OA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6FHWEM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6GUJ7W.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6IDF50.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6IG21P.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6IZLNF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6J8K9N.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6JBL53.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6JJQOW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6JKG57.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6JUCIV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6JYPDN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6JZFKW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6K7EB2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6LJBFJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6LXTKN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6LY1IN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6O2Z4E.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6O4NAD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6ONGBY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6PW3VY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6Q2COG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6QDY4R.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6QX6Q0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6QZUP6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6R41NY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6REG8R.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6ROS68.zip
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6SB8B2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6SOGK8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6TRLIA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6TVMIN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6VQD1J.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6XQ0I7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6XUF75.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6Y4YEC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6YRFTW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I6YYXGT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I70DL5G.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I714RQP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I71E0EC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I71M5TL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I71NG1I.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I72GBAS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I730WSZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I73RNL4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7523JL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I75CVUL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I75DONP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I76BEWS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I77H3MR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I78N35Z.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I792KIV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I79VL99.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7ABC4P.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7B71SC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7BJ7DQ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7C3WOU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7CVTL6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7D05SN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7DNFLI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7FAEZR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7FGCKK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7FQNZ6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7GGVM6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7GZCHF.zip
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7I8A8A
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7JBNFE.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7KU2C5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7M6T17.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7NC4LN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7OMQ1L.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7P5XGR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7PHWNR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7PQE52.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7QDXQT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7QINPP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7QM449.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7R6K7M.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7RKP9A.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7RKYHH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7S5YFG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7S6D25.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7S871X.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7T91C2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7TPJ9V.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7UM0CC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7VBODU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7VN622.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7VW5HM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7WALAY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7WKF1M.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7Y0QXY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7YE3XN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7YWG45.xml
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7YZTTK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7Z8VRL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I7ZQX2K.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I80BVVZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I80QQEQ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I81E7VP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I81GGIU.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I81I8TC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I81QYSM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I822VZE.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I826P2N.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I82QKHQ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I82TFGP.zip
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I838FOS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I83BLJ1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I83J6CA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I84VEBN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I850N0H
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I854NVP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I85FH09.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I85HZLS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I86I0X9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I871BZ2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I87AWAO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I88BURD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I88ETE2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I88J0YJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I88WRMU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I89BNL6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I89BTU5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I89FH5Z.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8A3OJZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8C9M1B.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8DLUSE.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8E0OEG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8ESU6X.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8FV2IR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8IRO6U.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8J2QDJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8J38IK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8JAJ36.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8LVCCO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8M84GK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8O5707.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8OK1J6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8OM3D8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8OMAEU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8OPQAT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8OZHIZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8P8ZA7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8PCLUV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8QYKKG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8RP25R.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8RVP9N.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8S4T1O.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8UAWVE.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8V1CBP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8V4Q1B.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8V75RI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8W2FIZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8W6VST.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8WTE52.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8WVN1S.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8YEKAR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I8Z2OD8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I91MSFK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9230DV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I92GBXV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I92YWEQ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I940F6S.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I942CF4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I956BLO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I95AOZ9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I95US5O.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I96JLEJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I98APER.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I98UEX3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I99AZ6D.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9AGMIC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9BU81U.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9BV3JG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9C3FDY.31213
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9F7P5Y.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9FCAYQ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9FH2AI.31213
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9FSJON.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9FWNHF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9GAZWP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9GEC8B.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9GTQG9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9H9ASQ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9HGZCZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9IQFEL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9IUZIN.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9JKFBC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9K4C1X.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9KRG32.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9L2IZH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9M2F4P.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9M73VG.xml
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9NFDI3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9NJKWN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9O9ZNZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9OH3TX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9PVX48.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9Q7R4S.31213
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9QXI27.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9S0HJF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9TLZYC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9TQO4D.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9TWB1T.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9V01IX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9VENRO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9VKY1Q.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9WCNT8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9WMU0B.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9WQWUG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9X13D1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9X4U21.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$I9Z87U0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IA0A9H5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IA16RU4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IA1CITP.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IA1RUHK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IA1SMG4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IA23LJ9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IA2HTQ8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IA2LNAN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IA2XUFW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IA3G8ST.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IA3HS9H.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IA3WW4O.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IA49SJG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IA4A4FT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IA4LO6L.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IA4N0GI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IA4QX9L.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IA4S7PX.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IA62BHR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IA6EZPI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IA77QSU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IA7IOCY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IA7T1JU.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IA8ZKI7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IA9A38G.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IA9IQC4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAA5YIK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAAM79H.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAAW3SL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IABZQIQ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IACOJNX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IADCO6P.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAESOPL.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAEU3J2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAF84ND
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAFM28D.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAG08HJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAH16T1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAIHNIO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAIMMEA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAJ4ZT9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAJKUGR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAL44MD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IALNXYJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAN4L0L.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAPB4CG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAPIMIX
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAPY17M.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAQ12F2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAQHUO2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAQKET5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IARDVI5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IARPI98.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IASE9KJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAU821U.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAUARF0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAVG1VZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAWY9V4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAX0NBI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAXCXOJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAXEQPK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAY218I.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAY80E8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAY9NKR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAZGD9A.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAZNH7H.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IAZUKUX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IB3YVOX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IB4BKVS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IB4I7EZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IB4QR04.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IB4ZL4K.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IB54S3T.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IB5EVEL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IB6BFEY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IB74P2A.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IB77CV7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IB8028N.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IB8668B.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBACYEP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBAGIR4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBB9O71.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBBXZY8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBC3KQW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBCL55T.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBD3WQQ.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBDCBB1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBE15X0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBEHRWN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBEN9TH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBFN6I1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBGG91U.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBGXLBY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBHL9YV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBHQFGT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBI7NJ8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBKZ2HS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBL5BPJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBLGRIW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBLIDYI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBLLV35.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBN4I4Q.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBN77KU
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBN7ZEO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBODZ9O.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBP6T0O.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBPIMCA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBPTY7G.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBQE0HA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBQHSEV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBQQFOE.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBUEVJQ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBUFALZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBUSV9I.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBUUI20.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBVIGI0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBWMK36.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBWMS9K.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBXAVQP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBYNCIG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBZ5PTG.xml
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBZTMSC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IBZV1Q0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IC0JJHE.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IC0TH23.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IC1M9LR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IC2CLL6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IC2INPC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IC2Y6A7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IC3ZUB6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IC40Q6I.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IC4F15D.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IC4VRNL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IC578OC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IC5IUHA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IC726XO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IC7C80E
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IC7J48V.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IC7YDA3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IC8LSYC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IC9VSX5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICAQK94.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICBU92H
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICDECQU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICDIKAY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICEBJB4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICEUAXT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICF0W1D.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICFC13E.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICG3ONE.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICH1GAL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICHO619.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICHTM82.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICIVMZS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICKUO80.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICM9OCW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICMN8AN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICMZ1ER.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICN60C8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICNQW2J.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICO5MG7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICO81T7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICO8ZHE.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICO987B.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICOJJUZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICOK6UV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICOLCIM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICOTID1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICOWWGP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICPGKA2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICPOXLU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICRATE3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICRCE4D.18380
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICRMLHD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICS5FX1
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICSJPLB.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICSQOF6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICT7FN4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICTN98T.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICU31G0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICU5A8L.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICUIS4D.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICV4T7F.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICWUNJ7
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICWWGF0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICY0JDC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICY1M2P.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICY7Y4Y.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICYE6PF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICZB5AB.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICZHLHY.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICZLARC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ICZLJPO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ID0TSD0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ID0YLIS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ID18ER5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ID27HA6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ID27OO7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ID29CUH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ID2FV7I.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ID2HPHF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ID31D0Y.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ID39FH9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ID3FIC9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ID3GQ3F.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ID4WKWG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ID5EG4A.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ID5U1XZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ID60EFF
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ID6HMG1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ID7DI7B.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ID897DZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ID9H4RW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ID9HFZR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ID9O5Z8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ID9O7JS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDAGUXO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDAJT46.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDAK4IL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDANPSG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDARW32.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDB49O6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDC068R.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDC1J4A.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDCD8MY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDCUT5A.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDD8P2T.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDDY1N5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDEYF9I.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDF1M05.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDFBBNL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDFBI3E.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDG249H.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDG4WNN.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDHR0QM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDIFU9W.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDIKCT5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDK29MI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDK3Q0V.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDKGZU4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDKMSLD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDKTIY0.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDKTVVH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDM48I5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDOKZC1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDOQMGI
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDP0SE5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDSI6SX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDV89QC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDVG8DO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDVIMYR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDVX9LF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDW4CEN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDW7YUY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDWPPGM.lnk
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDWQ83W.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDWQJEP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDXZD12.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDYWRNE.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IDYWVZY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IE0P1V8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IE21XL5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IE2Z07L.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IE36247.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IE3SXAX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IE5883Z.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IE6LDLD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IE6TZT7
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IE7B0RB.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IE7FP2K.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IE8DR9M.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IE9FYVO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IE9USS0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IE9WVHC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEACWEF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEBFSY9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEBO0AI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEBXEJU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IECHS2U.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IECJGCP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEDS93Y.18380
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEDTUQK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEDZRVQ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEE0ISA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEEDG4Y.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEEIW5T.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEGWQER.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEIFBLG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEIKVCO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEIVSWA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEJ1IBU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEJBBDY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEJJKYM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEKSD3I.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IELHXKG.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IELJNJX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IELKQJU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEOEKM7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEONX4X.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEPQAFC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEQ0OSF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEQEWN2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IER5FDF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IERAZKZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IERXS2F.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IET799E.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IETSSUE.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEVIKQ6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEVPU6D.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEVV6EB.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEW4SYB.8
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEWW3GW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEXWMZH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEYLG4N.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEYO9K3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEYXFIC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IEZ4JGG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IF0DRMN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IF0YYNA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IF2EZOR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IF2S6IG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IF34QU0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IF3X63U.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IF4X148.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IF57ZRP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IF60LBI
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IF6AMA7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IF6PPR7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IF77A73.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IF77KCK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IF78H63.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IF7PNQO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IF8531Q.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IF9IBAT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFAGTR0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFB6ZWF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFCFF8V.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFD467G.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFFIEAR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFFU1P9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFGH1XV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFGZOW9
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFH37VY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFH493J.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFH9XMK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFHWJK0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFIHF6U.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFIQ32F.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFIUELN.22215
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFJ8UUY.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFJADLV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFJBKF6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFJVJSN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFJZ0PH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFK41PM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFMEDKX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFMNM3N.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFNRXAO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFO5M96.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFOFJO3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFORYCD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFPBLIW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFPBN2R.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFPFUX4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFQMM01.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFRDK2E.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFRFT2E.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFRH1SV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFSVFH4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFSVJMA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFT9O84.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFTXCEH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFUQ3YJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFVATYO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFVYB62.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFVZ8F4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFW8ZW9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFXYUGE.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFYA5MF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFZE0HQ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IFZJXDJ.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IG0VE0X.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IG1BSC2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IG1KQIV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IG1RHZM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IG2N960.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IG2T162.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IG436KO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IG56223.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IG5O6N3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IG5VH1O.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IG5W644.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IG6ZSOB
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IG70VQ2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IG71B1E.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IG72SRG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IG8ST4Z.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IG96KV7
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGA47R7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGALAIG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGALFPY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGB1TIR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGCFBTS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGCOLO3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGCZ5FE.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGDGMWT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGE6W26.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGEHMH3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGEYBOK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGFB7E0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGFEGNE.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGGTJPK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGH6R4A
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGHTYAX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGI73GU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGJ7WT8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGJ90TC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGJW57C
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGKDEO3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGKJ7A8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGL4B75.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGLZN1T.zip
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGM5M8O.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGOZ8C6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGP1PYI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGPJGY6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGQV0RI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGRGJHR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGRS28L.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGSS6C2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGTCRCO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGTJNKW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGUZ3YW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGWA0J2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGWSY9G.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGX4UCF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGY212P.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGY6V6A.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGZC76W.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IGZDBLK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IH1UU89.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IH26S9Q.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IH2M4Z9.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IH2NC7V.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IH3L4TH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IH46E21.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IH46S9Z.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IH478MJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IH4PUP3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IH5E944.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IH67VUN.24369
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IH6IOOP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IH6WO6Z.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IH79NYE.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IH7SAVQ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IH81HGH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IH8FS14.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IH8MTVX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IH8SLVN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IH9AMZU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHBV62Q.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHCA81H.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHCU34D.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHFZXI0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHGIQKO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHH0EPT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHHBDQA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHHEHW6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHHJDIW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHHMQSZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHHNWPL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHHTOVK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHIA1GB.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHJUM0F.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHJXX0E.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHK1RAY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHKA96F.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHLP5X5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHME2Z8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHMFTY0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHMPB69.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHMPHN9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHNRCY3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHNUILG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHOOEE7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHOPWXG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHP64JA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHPE44H.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHPHRCN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHQT3QC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHRHH8J.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHRS28R.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHSMAAR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHT22QR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHU3Z6H.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHUH0XO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHUS6IG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHUT4FN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHUTFG9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHUUAEK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHVGQZI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHVTJI2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHWB6MH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHWKUX6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHWT7AZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHX6CK9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHXC4O3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHXYXLO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHY3A95.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHYXIHJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IHZCDQ5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$II12G5L.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$II1GQUX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$II1XCSD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$II2E13E.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$II2O9YN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$II2ZQGV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$II3OL5Z.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$II3P7BX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$II4W3O1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$II574LF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$II5OXVL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$II6NUFG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$II7IPQV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIABH4X.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIAFQ8B.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIBKSSR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IICN702.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IICV6T6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIDBK8I.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIGDA96.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIGQ4C9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIGTHV8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIHLPI3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIHWJ8N.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$III02FP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIIC6QN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIIKDY1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIJ8BRV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIJBVE7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIJYWD5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIKXPYY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IILGK7H.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIMV7IL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIN0UUJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IINEKMM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IINFTCW.xml
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IINVTT2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IINZ8J5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIOCOIJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIPTW7F.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIQ0ATM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIQETGI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIQWVI2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIR4N8B.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIRBDR9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IISL5N3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIT4DNL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIT961T.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IITW2LC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIUDJY2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIUS4DQ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIUV87I.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIV03DT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIV4PY3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIVWP32.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIVY583.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIWEAKZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIXU62N.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIY3QM1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIY6VJL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IIYQ8L7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJ0MG0Z.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJ0ZOV0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJ16HDC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJ1GPAV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJ1KL4O.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJ1UMC0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJ30WAQ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJ3KQL7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJ41K7B.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJ4VTFQ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJ4YIA5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJ55UZ4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJ5J8GJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJ5WAGI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJ67DRZ.xml
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJ69YT5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJ6H623.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJ6Q24R.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJ7FBO3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJ88BOA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJA7WWN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJANTIP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJBA8TR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJCQDES.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJE9619.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJFK558.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJFLZ35.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJFWZO3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJFZ48S.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJGOTJK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJIRRIH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJK8I8F.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJMT1TC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJN1JTD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJNOFGJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJO4QHB.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJOGS0T.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJOW9YT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJPA8LM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJQ4JS7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJR7YGV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJRGBOU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJRSZS1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJRVOH9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJS5D3M.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJT6JNY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJUMKJX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJUYKJQ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJV3OUR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJV60NS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJV7RCE.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJWFESG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJX1SD3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJXA5EN
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJY255S.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJZH22Y.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJZOCCA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IJZQIJK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IK0RSDL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IK2IJVX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IK2SZTB.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IK2VX4E.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IK2X5H3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IK36SGZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IK3F1HW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IK3RE62.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IK4RCI9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IK5M5N9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IK5NQE5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IK7094D.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IK70CSG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IK70UNZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IK7XREM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IK8GTAG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IK8HU9W.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKADLQE.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKALWIP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKAXA1V.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKB6YGM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKBADBF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKBKVKH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKDJNOY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKDS2LS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKENOXB.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKFZOPL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKGLDB7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKHFCFT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKHL19P.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKHQU5S.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKI0ZRH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKIKULM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKIUXM0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKJ7QXJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKJ932C.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKJEZL0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKJYR3S.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKKUJ2D.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKL8KQV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKLJUIJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKLK464.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKLM3UM.18380
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKLME4J.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKLZWXK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKOG13J.32532
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKQEHUS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKR730Y.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKS4M1I.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKSL400.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKSLTH7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKSQT0Y.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKT3DMX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKUL14G.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKUPAF5
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKV09K6
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKWBAMR.ses
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKXI1IH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IKXVM39.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IL18MKJ.40
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IL1JD5R.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IL3I0CB.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IL3JUEO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IL3MQ0Z.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IL3ZWLH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IL4NFPU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IL52N9O.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IL5UAX1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IL5XF80.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IL65K6K.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IL6HUS8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IL6L769.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IL71RQV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IL8B2PF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IL9OVG0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IL9XTW6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILAYWQC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILB3P23.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILBDSYU
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILBWZAF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILCU5DG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILD8CDN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILDB7RT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILEJYWE.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILF9B06.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILFUY8M.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILHLJS7.xml
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILIDR4G.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILIXH6Z.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILJ56ZA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILJNE9W
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILJQ3ZK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILJV2HQ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILJXF6Y.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILK4FRS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILKGWWA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILKJZPD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILKSC9U.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILLQMFU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILLRLDD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILMNCN9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILN1IRB.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILNFTFA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILNJDW8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILOC9AX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILP4JW8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILP4TYY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILPDP5R.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILPNYDR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILQ7YBB.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILRSMH3.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILRYKNY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILS7GDN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILSBH8X.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILSC5RV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILTZHKX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILU3GRG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILV87AA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILW52OD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILWIYX8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILWO4DM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILY44TH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILY678U.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ILZBVOD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IM0B654.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IM104Z9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IM14OTE.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IM19GUI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IM1QWPV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IM210BI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IM5DX1Z.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IM5FCR8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IM5UTLE.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IM8EK7Z.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IM9LH9A.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMA53QG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMBD5OJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMBOT0P.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMC2SGO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMCZNN2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMD14VN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMEA0TI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMFGCRO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMHBRAR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMHE2Z5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMHKR9P.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMIJX3T.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMJR2XD
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMKFU9L.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMKK6YR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMKM7E8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMKRLDK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IML9YMV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMM2OFG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMN4O58.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMNO64V.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMOK9BI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMOTJSW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMP1QX1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMPA7ZZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMQ0Z5U.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMQD9AD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMQMGLK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMRFP63.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMS56EI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMSHX8A
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMTL43G.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMU8GUU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMUT46C.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMUTEFZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMVMCWJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMWHNCF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMX3XR4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMXLGPT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMXO349.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMXXXMI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IMYJH8D.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IN01P4K.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IN0M6GF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IN182JJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IN2JU2Z.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IN3AYQA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IN4Q9YZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IN5ED1D.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IN5NNQ7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IN69FM2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IN6L01R.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IN6M772.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IN7EJGE.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IN8T4P1.31213
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INA05I6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INA9MGC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INAHSI7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INANDYA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INAQMDV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INBOM69.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INCSQQ5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INCYWUA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INDDBVG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INDUUZ0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INESNF0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INFJ2LL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INFTUSV.22215
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INHVTVG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INIHH4O.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INIKWBQ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INIQXF8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INL9VST.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INL9W67.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INLQKID.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INMW441.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INMYL0U.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INND655.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INO7CQ1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INP92PB.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INPEILI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INPO7EW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INPXCV7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INQBNQ4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INQZ1AQ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INSAAYI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INSE36E.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INT1V26.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INT8R3F.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INTE0OV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INTJI1Z.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INUGBDW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INUYK8D.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INW3226.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INWQJZY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INXR6ER.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INYIUYZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INYUJGF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INZ7JJ6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$INZVDQ7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IO0A1F5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IO0PUKK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IO0VL19.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IO15AL9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IO1Y2AT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IO2835K.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IO30C1I.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IO47Y6P.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IO4EDMA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IO52SZ2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IO5FF8D.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IO5NN0F.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IO5WG59.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IO6F5SS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IO6TWVS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IO7GQD0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IO8B9Q4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IO8SQ65.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IO9BY0T.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IO9G34A.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IOCEZWB.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IOCTQNK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IOEW1N5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IOEYN8P.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IOF6SUN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IOH2M7L.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IOHSDG2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IOIOU0U.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IOJ8BDP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IOJ91AE.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IOKDAD9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IOKI5RV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IOLAI9R.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IOO7W90.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IOP14CF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IOPUPY6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IOR3KHY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IOSUOUH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IOU4GVB.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IOUVWDB.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IOV3YLF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IOW0R8C.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IOWQJ7Q.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IOZ8DZT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IP0W6SF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IP1A7VI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IP1VFBX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IP263O1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IP2EI89.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IP2RD2H.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IP2WG2G.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IP3M1BO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IP46JR6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IP4DWU1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IP4M1N8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IP4XUF9
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IP57R56.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IP5MXJD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IP5XQ1Q.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IP61THN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IP6E9RS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IP7BJGN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IP7BKWW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IP7HNP5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IP7PIST.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IP83LVS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IP9GPYP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPAEJDI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPAPM1M.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPB5XBL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPBIMDD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPFF6K0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPFJNL8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPFMPKY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPFOVMD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPFOYSU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPH0IP8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPH8L93.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPHMC18.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPHPI86.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPHYNBD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPI06NA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPIKQJU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPIPKWK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPJ0UUS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPJ2X8C.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPJGN5K.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPKDD18.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPKRX03.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPLEO2D.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPN6V0Q.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPOKCC5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPOWMBD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPPEUBI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPPZGCE.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPQNAGP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPRJ6FP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPSNA4W.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPSYCJ6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPTA52S.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPVL29C.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPWPV4R.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPX0RB6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPXOUVI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPXP69R.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPY7H59.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPYMFGC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPZ641F.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPZ6P3O.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPZ96SK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPZADI0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPZJJP1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IPZLQM9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQ09CRS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQ284NR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQ2RRPK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQ33DF3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQ4UM7G.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQ5SSXS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQ61GON.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQ69JCE.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQ6TLLA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQ6VLTR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQ7DL79.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQ7X35R.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQ8RMBH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQ96X13.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQ9DZ93.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQC5RGB.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQCJ6QQ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQCQ332.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQD1L5F.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQE4MU2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQEIWVE.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQELYJX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQENX7B.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQFI00M.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQGG4PZ
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQGJF7X.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQGKLT5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQHPTIK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQHWNUW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQJ3KDI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQJ5GH7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQJF5FP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQKMQ6C.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQL5RZA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQL7OB9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQNCSOJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQNP1OU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQONM1M.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQOXCPW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQP8TOH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQPJI1I.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQRI4D5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQRYQKV.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQS8GL1.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQT4819.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQTA2CV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQU02VR
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQU60KP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQUW0AP
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQVKV95.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQVRXYQ.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQW0WWT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQWYO82.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQX7I8V.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQYAXI3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQYEGY6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQYXI1D.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQYZ28Y.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IQZB0JB.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IR08BUH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IR0HPLR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IR1HYAR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IR2VAMO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IR30Q4N.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IR3NO15
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IR46MP0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IR4G24F.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IR4NR7M.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IR4TX4T.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IR4V5QG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IR60NED.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IR6HGG3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IR6VR47.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IR74S5Q.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IR81F6V.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IR8DKZA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IR96VOB.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRAN65U.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRAVL7F.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRC9TTN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRCL8E1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRCLOYN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRCX3UC.32532
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRD9IL5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRDEUAN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRDIWVD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRDQ8T0.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRDQNM5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRDVN08.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IREEV7Z.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IREUR94.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRFEWOC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRGEUM0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRH02Y1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRHS794.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRHXNRG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRIJ3QD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRJAP1F.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRKF4ZS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRKJ9Z8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRKOV48.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRKSCM3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRL1JKY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRN4MBL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRN9CP2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRO0MIS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IROKMYS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRPYLT1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRR8JWZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRRVSX6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRT6A11.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRT9100.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRU6FG6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRUCWJM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRVYY4K.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRW82CE.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRW91GJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRWFMFW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRWHH0Q.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRWQW31.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRXJTOJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRXXVFQ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRYRXFA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRYY1T7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRZ6RTA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRZBM2H.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRZRITC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IRZY352.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IS02HSF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IS09SIS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IS0FKMJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IS1GVHZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IS2N5K9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IS2XJ64.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IS3OEVA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IS49H1G.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IS5UKNC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IS67JY9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IS72IH3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IS73015.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IS84BVK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IS8E9ZS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IS8NVGT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IS911MK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IS9GDHA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IS9HRI7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISA4YK2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISA58MB.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISAF07Y.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISAN4WA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISAPUTB.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISBJ9HV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISEKHLS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISHL12A.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISIZ919.24369
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISJPFJ4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISJVV0E.mof
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISJWWBW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISKQSB3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISLF4V9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISLKPYW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISM9IA1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISMZBBB.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISN0IL6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISN0T2J.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISNOHQP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISNXOVX
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISOK1HG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISP7228.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISPS7WB.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISPXE0X.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISQBFTX
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISQI7JM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISQNHVS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISR65Y6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISRN3RT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISRZYSZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISSPCSP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IST7M9T.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISTKX80.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISTMDWG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISUGFQO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISUJRMJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISUQVXG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISV3DXR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISV6CXS.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISVNZ8E.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISVRRY5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISWTKWC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISXCROT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISXTLUA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISY6TI2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISY9ZL7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISYB66E.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISZ29JU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ISZ57X9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IT0W05O.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IT28DH5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IT2IOC8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IT2LYN7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IT4578K.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IT5X1ZR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IT60U1B.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IT96TGH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITASMNC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITAX980.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITAYMFF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITB4IIB.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITBBYD6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITEBPO2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITEFINI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITFDZQR.18380
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITFMAS9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITGGDQ2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITH1WR4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITH6WBQ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITIWWA0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITJJEHA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITKDEC9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITL39NS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITLDQ9T.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITLRHF5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITLU1EN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITM4JW4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITN1W84.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITN9QZ1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITNZBBK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITODJIH
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITPEV4J.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITQ3RN0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITQHZB4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITRYTGM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITT6HE2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITTPXL7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITUQAN6
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITV1EFB.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITV8XZP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITVZA1J.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITW6HTA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITWL6BG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITWM2LL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITX1K68.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITY654M.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITYL4IW.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITYUBFY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITZ4A6K.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$ITZ94CH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IU05OWX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IU0V6MR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IU13JH3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IU19F34.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IU1VJ27.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IU1Y3EZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IU2RS9J.31213
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IU3PZRV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IU5J3GZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IU5KMDH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IU7LZT9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IU8IZCO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IU8ZP6Y.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IU904UH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IU92NRZ.xml
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IU9DN8S.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUC27PS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUDE2GW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUEBBMY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUEVJIJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUH0GKP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUH3U83.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUI9UBW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUJHNBH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUJTKRD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUJWHD1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUK5HNJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUK7S2D.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUL420G.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUMMB04.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUOEF00.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUOI9C0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUOSFHP.0
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUPQ5FG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUQAW6P.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUQBAHH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUR1373.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUSBEYP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUSDI8E.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUSK0SZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUTNNWN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUTZYOG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUU4HZ0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUW4GIP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUWP5HM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUWXP7Q.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUX6Z7E.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUXGO8K.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUXNBBT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUY9OC7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUZ8A9V.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IUZPVV5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IV00QFV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IV1YOFH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IV2J0YI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IV3FIJ6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IV3IWPF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IV3LPQV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IV3NTP1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IV41P2F.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IV554O8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IV5FD3V.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IV5NHRV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IV5YAY8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IV7DNNU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IV8AHUK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IV8ONZS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IV8RZHS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IV9HULR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IV9KRSW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IV9W3DS.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVB8TJN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVBQOYH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVBSZ43.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVC8R9T.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVCA6O4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVCHAGS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVCWXFO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVDUHXS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVDYFHC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVECYMS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVF4201.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVFIW4A.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVH1DOK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVJM4LY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVK26B5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVKYCAE.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVMX3OT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVNBU88.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVNC7UL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVNEU3X.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVNNEJ0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVNT5EB.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVO598G.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVO5V3U.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVP0H1H.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVPD3T2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVPQWI1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVPR00V.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVQMBB4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVR8O2A.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVSXQIY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVT09SK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVT1AXL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVTYH1M.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVUKJA0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVURXN1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVUTOC4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVUX9BJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVVXU2O.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVWRQ2A.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVXQB2S.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVXUDOM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVYU4L8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVZ1HF1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVZ7QC9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IVZE7LX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IW1DRUA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IW1LU1Q.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IW2ZO1X.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IW38LGV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IW3B9LA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IW3QGLS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IW3UC18.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IW56ZRQ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IW5L7XK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IW5YO4B.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IW66ERO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IW70ACA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IW7CURM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IW7L0ZP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IW8AK88.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IW8CMM5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IW9ACPS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IW9LCWE.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWA49FL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWA7654.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWAAQQ1
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWAJOSW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWBNB6K.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWBT7UU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWCTEB1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWGSJIC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWHAA7H.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWHH320.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWHHRVD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWHPXVS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWI3QAF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWICQ63.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWJK7KS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWL3XE5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWL56IR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWMIYS4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWMXH4R.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWNT01V.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWO5V1W.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWP4RV0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWQ3U3V.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWQC88T.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWQPMP1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWS965D.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWSESJP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWSHEIW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWSKSN0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWSOKRT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWTVBII.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWU4GQ3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWU7NQP.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWUL5AP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWUS27S.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWUWUJ1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWV0OU5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWVBEMK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWVN9GI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWVS5G3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWWQSJF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IWZ4Q0Q
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IX1ENSC.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IX1IWOX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IX39OJP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IX55I8B.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IX61EAO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IX63JJW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IX6EZW4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IX71TJT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IX7JNB7
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IX806IE.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IX8H6U1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IX8TLZH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IX92J9D.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IX9Q3N9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXA4V6V.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXBKWVU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXC2JU6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXCIXSK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXEREKX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXFFCT0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXFKGUF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXFLVT0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXFML72.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXH00M6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXHHVHH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXIMSX6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXKA2N2.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXKUCYV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXLKQ6I.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXMB0HL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXMVJFT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXOB9NO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXOJ02U.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXORZYJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXQI66O.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXQXRYM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXR4LVA.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXRSMH5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXSEJT0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXSFPGA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXTAA3Y.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXTEVP6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXTW8XX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXUK1Q4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXVJPXV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXWXIK1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXWZJV5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXX95FT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXXX96Y.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXYKCDM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXZVTTQ.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IXZZVXP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IY0BJ6F.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IY2BW4X.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IY2CWZZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IY2P3DB
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IY2Y31N.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IY46MQA.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IY48L70.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IY4OER8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IY5321C.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IY60JXK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IY64H6H.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IY6E6BF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IY6E97V.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IY6LBMH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IY8HBFV.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IY8L4GT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IY93PUC.xml
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IY9PB9T.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IY9WYF4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYAUURH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYBS0Q7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYCQPS3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYCSDTG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYCYB0E.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYD112F.33816
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYD7L6O.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYE7LG8.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYEAYOZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYEGDXB.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYF18NJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYF1FCJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYFWE6N.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYG6FVN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYGAIW9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYGMEKJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYGOMB7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYI8M5G.33816
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYJSL8A.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYJT5NM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYKEYHQ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYKI7Z1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYKMWXM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYMRI2D.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYNQP6V.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYO0WPZ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYOCMLE.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYOE4IS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYOH3P9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYOKZIT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYOTVBU.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYOZI0G
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYPN7RQ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYQ176Q.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYQ3W54.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYQRZ2K.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYQT55L.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYQYP6L.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYR1MSX.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYRODRN.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYS5BZ5.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYT3F6K.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYTBP4C.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYTHIQW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYTRVVJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYUY0GD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYVVYY4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYW3XTI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYWJLRD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYWNROS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYXTE1Z.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IYZFACO.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZ0DB47.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZ13XPM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZ1GLNL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZ1HTNY.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZ2U53I.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZ3HR8W.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZ50Q08
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZ5B7YQ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZ5U8PQ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZ6FFJH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZ6Z1B4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZ7XJBL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZ85KHK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZ87W3I.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZ8EUHR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZ8FOCL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZ8G157.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZ93J2U.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZ9K1F3.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZA5BXK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZBJJXS.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZBN41L.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZDXZP9.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZEG698.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZF8TBW.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZFQ72K.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZGD560.zip
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZGWP7Z.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZGYRSH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZH6WAA
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZHNUFK.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZIJC9R.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZJ9PY1.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZJK093
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZJK0ET.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZKVLYT.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZLH5PI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZLNRO0.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZLTKNJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZMCSAD.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZMRFDM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZOHA4Q
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZOSF9H.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZPDOD6.lnk
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZQAX7W.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZQMCBJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZR56W6.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZS6TIF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZT39P7.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZU8A2Q.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZUERFI.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZUGUXR.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZVKJ5T.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZVTEBF.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZW1ODJ.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZWYZYL.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZXEE64.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZXHPG4.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZXHPPP.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZXINPG.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZXLYUM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZZ54IH.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZZOAFM.txt
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$IZZP1KJ.log
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$R2BXNT6.zip
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$R6ROS68.zip
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$R7GZCHF.zip
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$RGLZN1T.zip
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$RMH5LFC
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$RZGD560.zip
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$RZPDOD6.lnk
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\desktop.ini
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$RMH5LFC\.
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$RMH5LFC\..
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$RMH5LFC\29
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$RMH5LFC\30
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$RMH5LFC\30_v1
C:\\$Recycle.Bin\\S-1-5-21-3194671253-1068146636-4210433707-500\$RMH5LFC\April
92430 - Registry Editor Last Accessed
-
Synopsis
Nessus was able to find the last key accessed by the Registry Editor when it was closed on the remote host.
Description
Nessus was able to find evidence of the last key that was opened when the Registry Editor was closed for each user.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

Production
- Computer\HKEY_CURRENT_USER\Control Panel\International

10940 - Remote Desktop Protocol Service Detection
-
Synopsis
The remote host has an remote desktop protocol service enabled.
Description
The Remote Desktop Protocol allows a user to remotely obtain a graphical login (and therefore act as a local user on the remote host).

If an attacker gains a valid login and password, this service could be used to gain further access on the remote host. An attacker may also use this service to mount a dictionary attack against the remote host to try to log in remotely.

Note that RDP (the Remote Desktop Protocol) is vulnerable to Man-in-the-middle attacks, making it easy for attackers to steal the credentials of legitimate users by impersonating the Windows server.
Solution
Disable the service if you do not use it, and do not allow this service to run across the Internet.
Risk Factor
None
Plugin Information
Published: 2002/04/20, Modified: 2023/08/21
Plugin Output

tcp/3389/msrdp

277650 - Remote Services Not Using Post-Quantum Ciphers
-
Synopsis
Reports remote services that do not offer post-quantum ciphers.
Description
This plugin reports network services that do not offer post-quantum ciphers. Tenable makes no attempt to determine whether the remote service would be vulnerable to a post-quantum attack.

However, cryptography that depends on the classic difficulty of solving the discrete logarithm problem or on the classic difficulty of large prime factorization is broken by Shor's algorithm. Examples of this are RSA asymmetric encryption and Diffie-Hellman key exchange.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/08, Modified: 2025/12/08
Plugin Output

tcp/3389/msrdp

The target TLS server offers no post-quantum ciphers.

62042 - SMB QuickFixEngineering (QFE) Enumeration
-
Synopsis
The remote host has quick-fix engineering updates installed.
Description
By connecting to the host with the supplied credentials, this plugin enumerates quick-fix engineering updates installed on the remote host via the registry.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2012/09/11, Modified: 2022/02/01
Plugin Output

tcp/0


Here is a list of quick-fix engineering updates installed on the
remote system :

KB4589208, Installed on: 2024/06/26
KB5004335
KB5005030, Installed on: 2021/08/06
KB5005112, Installed on: 2021/08/06
KB5049608, Installed on: 2025/04/02
140535 - SQL Server Reporting Services Installed
-
Synopsis
A server-based report generating software system is installed on the remote host.
Description
SQL Server Reporting Services, a server-based report generating software system is installed on the remote host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2020/09/11, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\Program Files\Microsoft SQL Server Reporting Services
Version : 15.0.9098.6826

56984 - SSL / TLS Versions Supported
-
Synopsis
The remote service encrypts communications.
Description
This plugin detects which SSL and TLS versions are supported by the remote service for encrypting communications.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/01, Modified: 2025/06/16
Plugin Output

tcp/3389/msrdp


This port supports TLSv1.0/TLSv1.1/TLSv1.2.
83298 - SSL Certificate Chain Contains Certificates Expiring Soon
-
Synopsis
The remote host has an SSL certificate chain with one or more certificates that are going to expire soon.
Description
The remote host has an SSL certificate chain with one or more SSL certificates that are going to expire soon. Failure to renew these certificates before the expiration date may result in denial of service for users.
Solution
Renew any soon to expire SSL certificates.
Risk Factor
None
Plugin Information
Published: 2015/05/08, Modified: 2015/05/08
Plugin Output

tcp/3389/msrdp


The following soon to expire certificate was part of the certificate
chain sent by the remote host :

|-Subject : CN=LKP_SIP_AppSrv-140
|-Not After : Mar 23 22:44:55 2026 GMT
42981 - SSL Certificate Expiry - Future Expiry
-
Synopsis
The SSL certificate associated with the remote service will expire soon.
Description
The SSL certificate associated with the remote service will expire soon.
Solution
Purchase or generate a new SSL certificate in the near future to replace the existing one.
Risk Factor
None
Plugin Information
Published: 2009/12/02, Modified: 2020/09/04
Plugin Output

tcp/3389/msrdp


The SSL certificate will expire within 60 days, at
Mar 23 22:44:55 2026 GMT :

Subject : CN=LKP_SIP_AppSrv-140
Issuer : CN=LKP_SIP_AppSrv-140
Not valid before : Sep 21 22:44:55 2025 GMT
Not valid after : Mar 23 22:44:55 2026 GMT
10863 - SSL Certificate Information
-
Synopsis
This plugin displays the SSL certificate.
Description
This plugin connects to every SSL-related port and attempts to extract and dump the X.509 certificate.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/05/19, Modified: 2021/02/03
Plugin Output

tcp/3389/msrdp

Subject Name:

Common Name: LKP_SIP_AppSrv-140

Issuer Name:

Common Name: LKP_SIP_AppSrv-140

Serial Number: 38 BA 2A CB 4F B4 42 AD 48 1F B2 70 46 62 9B C7

Version: 3

Signature Algorithm: SHA-256 With RSA Encryption

Not Valid Before: Sep 21 22:44:55 2025 GMT
Not Valid After: Mar 23 22:44:55 2026 GMT

Public Key Info:

Algorithm: RSA Encryption
Key Length: 2048 bits
Public Key: 00 F1 63 B5 F6 BC 6C BB C9 CF 6E 7C E6 78 F0 2B 39 28 24 9C
16 01 53 7B 73 5B C2 11 D8 B5 6B DF 86 CF 06 D5 97 C4 BC 33
C7 F8 10 EE 5A 30 58 88 8F 4A 05 09 B3 90 46 92 42 3F E5 75
70 11 88 B0 99 55 A5 BC 89 FF CE E7 81 8D B4 9A B1 52 F1 82
4D E8 18 B8 0C DC EF 18 A9 86 D3 27 BC DA 52 F3 09 C3 8F D0
93 F6 B8 B6 BC 5D 3F 3F B0 8F C2 39 19 BC 6B 23 2A 39 A9 7B
89 C1 28 40 77 22 5A BD 88 34 02 B8 59 03 77 6B FB 58 A0 FD
40 69 DC 00 14 89 5E 64 AD D8 8F 3B 07 16 94 C2 78 97 18 93
14 1E B9 51 59 0F 70 FF EF 10 75 9A CF 8E 02 D6 A6 44 21 94
14 73 C6 A5 43 A7 1F 41 67 BA 24 31 AA 62 BD 15 D9 39 93 4C
16 71 F5 EB 0B D2 88 2D 48 C6 00 B8 5B A3 28 F9 09 FF 39 20
F5 25 E4 09 8A 16 CD 28 C1 8E C3 A4 3E 0C 14 05 C0 37 FB 32
02 89 E3 41 BE 6A 27 A4 D2 F4 D1 46 48 20 AD 8A 09
Exponent: 01 00 01

Signature Length: 256 bytes / 2048 bits
Signature: 00 06 82 9C CC AF 02 1E 73 1C 84 CD C1 53 3D 25 87 08 D4 16
E0 7E 75 F4 96 0C 1C C9 AC D8 BB 7C 58 B8 CB 85 FD F4 1D A9
37 02 48 3E F1 B9 CB C9 E1 C5 24 78 91 7F 17 5C D6 BA 90 94
9E 7E A5 1D D2 C7 D0 4C E5 24 7A 36 BF 45 B0 25 49 EF CE D1
24 19 E9 F0 E1 DA E8 09 7D 5C 84 6E 79 B7 7B EF 5C B6 65 33
86 CE 13 C4 15 21 28 10 47 6B 30 DD 4F C6 BD 0B C6 7D FA 60
BF 7F DB 4C DD D5 17 9A DD FB DD 66 55 35 BF FC A2 F9 7C 9C
1B B5 E5 EB 48 47 AA B1 89 30 38 9A 79 0E DC CA 65 FA B5 0B
91 87 44 45 0A 7F 4B E9 AA 90 9D 1F 5C 07 2A 77 47 92 07 72
D9 AD E9 21 0A 00 20 B1 05 D6 AF 2B 31 50 78 31 48 54 36 C8
56 1D F6 B9 CC 12 F7 6E EE AF 39 E8 4B D3 4B 5E D3 89 F6 D1
C0 9D 95 38 50 A5 77 36 51 BB E3 C2 AC EA EF 3D C2 F7 D0 C2
A5 DA 44 49 43 29 D1 6C 1A 36 12 02 9B 57 21 68 7D

Extension: Extended Key Usage(2.5.29.37)
Critical: 0
Purpose#1: Web Server Authentication (1.3.6.1.5.5.7.3.1)


Extension: Key Usage(2.5.29.15)
Critical: 0
Key Usage: Key Encipherment, Data Encipherment


Fingerprints :

SHA-256 Fingerprint: 8B 4B 4D C5 17 A3 70 25 17 B8 C4 80 F3 B8 4C 30 57 5B 8C 7E
85 6E 98 D3 F4 6C D8 6A A6 4C BC F1
SHA-1 Fingerprint: 33 28 CC 34 6B E8 61 F8 7B B9 AD 91 F2 CE C3 AB 48 9A 8F C1
MD5 Fingerprint: 6A 11 22 5B 95 CC A2 29 AC F4 00 C2 39 F1 08 6C


PEM certificate :

-----BEGIN CERTIFICATE-----
MIIDDDCCAfSgAwIBAgIQOLoqy0+0Qq1IH7JwRmKbxzANBgkqhkiG9w0BAQsFADAvMS0wKwYDVQQDHiQATABLAFAAXwBTAEkAUABfAEEAcABwAFMAcgB2AC0AMQA0ADAwHhcNMjUwOTIxMjI0NDU1WhcNMjYwMzIzMjI0NDU1WjAvMS0wKwYDVQQDHiQATABLAFAAXwBTAEkAUABfAEEAcABwAFMAcgB2AC0AMQA0ADAwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDxY7X2vGy7yc9ufOZ48Cs5KCScFgFTe3NbwhHYtWvfhs8G1ZfEvDPH+BDuWjBYiI9KBQmzkEaSQj/ldXARiLCZVaW8if/O54GNtJqxUvGCTegYuAzc7xiphtMnvNpS8wnDj9CT9ri2vF0/P7CPwjkZvGsjKjmpe4nBKEB3Ilq9iDQCuFkDd2v7WKD9QGncABSJXmSt2I87BxaUwniXGJMUHrlRWQ9w/+8QdZrPjgLWpkQhlBRzxqVDpx9BZ7okMapivRXZOZNMFnH16wvSiC1IxgC4W6Mo+Qn/OSD1JeQJihbNKMGOw6Q+DBQFwDf7MgKJ40G+aiek0vTRRkggrYoJAgMBAAGjJDAiMBMGA1UdJQQMMAoGCCsGAQUFBwMBMAsGA1UdDwQEAwIEMDANBgkqhkiG9w0BAQsFAAOCAQEABoKczK8CHnMchM3BUz0lhwjUFuB+dfSWDBzJrNi7fFi4y4X99B2pNwJIPvG5y8nhxSR4kX8XXNa6kJSefqUd0sfQTOUkeja/RbAlSe/O0SQZ6fDh2ugJfVyEbnm3e+9ctmUzhs4TxBUhKBBHazDdT8a9C8Z9+mC/f9tM3dUXmt373WZVNb/8ovl8nBu15etIR6qxiTA4mnkO3Mpl+rULkYdERQp/S+mqkJ0fXAcqd0eSB3LZrekhCgAgsQXWrysxUHgxSFQ2yFYd9rnMEvdu7q856EvTS17TifbRwJ2VOFCldzZRu+PCrOrvPcL30MKl2kRJQynRbBo2EgKbVyFofQ==
-----END CERTIFICATE-----
70544 - SSL Cipher Block Chaining Cipher Suites Supported
-
Synopsis
The remote service supports the use of SSL Cipher Block Chaining ciphers, which combine previous blocks with subsequent ones.
Description
The remote host supports the use of SSL ciphers that operate in Cipher Block Chaining (CBC) mode. These cipher suites offer additional security over Electronic Codebook (ECB) mode, but have the potential to leak information if used improperly.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/22, Modified: 2021/02/03
Plugin Output

tcp/3389/msrdp


Here is the list of SSL CBC ciphers supported by the remote server :

Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}
21643 - SSL Cipher Suites Supported
-
Synopsis
The remote service encrypts communications using SSL.
Description
This plugin detects which SSL ciphers are supported by the remote service for encrypting communications.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2006/06/05, Modified: 2024/09/11
Plugin Output

tcp/3389/msrdp


Here is the list of SSL ciphers supported by the remote server :
Each group is reported per SSL Version.

SSL Version : TLSv12
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA256 0x00, 0x9E DHE RSA AES-GCM(128) SHA256
DHE-RSA-AES256-SHA384 0x00, 0x9F DHE RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA256 0xC0, 0x2F ECDHE RSA AES-GCM(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x30 ECDHE RSA AES-GCM(256) SHA384
RSA-AES128-SHA256 0x00, 0x9C RSA RSA AES-GCM(128) SHA256
RSA-AES256-SHA384 0x00, 0x9D RSA RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256


SSL Version : TLSv11
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1


SSL Version : TLSv1
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

Note that this service does not encrypt traffic by default but does
support upgrading to an encrypted connection using STARTTLS.
57041 - SSL Perfect Forward Secrecy Cipher Suites Supported
-
Synopsis
The remote service supports the use of SSL Perfect Forward Secrecy ciphers, which maintain confidentiality even if the key is stolen.
Description
The remote host supports the use of SSL ciphers that offer Perfect Forward Secrecy (PFS) encryption. These cipher suites ensure that recorded SSL traffic cannot be broken at a future date if the server's private key is compromised.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/07, Modified: 2021/03/09
Plugin Output

tcp/3389/msrdp


Here is the list of SSL PFS ciphers supported by the remote server :

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA256 0x00, 0x9E DHE RSA AES-GCM(128) SHA256
DHE-RSA-AES256-SHA384 0x00, 0x9F DHE RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA256 0xC0, 0x2F ECDHE RSA AES-GCM(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x30 ECDHE RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}
156899 - SSL/TLS Recommended Cipher Suites
-
Synopsis
The remote host advertises discouraged SSL/TLS ciphers.
Description
The remote host has open SSL/TLS ports which advertise discouraged cipher suites. It is recommended to only enable support for the following cipher suites:

TLSv1.3:
- 0x13,0x01 TLS13_AES_128_GCM_SHA256
- 0x13,0x02 TLS13_AES_256_GCM_SHA384
- 0x13,0x03 TLS13_CHACHA20_POLY1305_SHA256

TLSv1.2:
- 0xC0,0x2B ECDHE-ECDSA-AES128-GCM-SHA256
- 0xC0,0x2F ECDHE-RSA-AES128-GCM-SHA256
- 0xC0,0x2C ECDHE-ECDSA-AES256-GCM-SHA384
- 0xC0,0x30 ECDHE-RSA-AES256-GCM-SHA384
- 0xCC,0xA9 ECDHE-ECDSA-CHACHA20-POLY1305
- 0xCC,0xA8 ECDHE-RSA-CHACHA20-POLY1305

This is the recommended configuration for the vast majority of services, as it is highly secure and compatible with nearly every client released in the last five (or more) years.
See Also
Solution
Only enable support for recommened cipher suites.
Risk Factor
None
Plugin Information
Published: 2022/01/20, Modified: 2024/02/12
Plugin Output

tcp/3389/msrdp

The remote host has listening SSL/TLS ports which advertise the discouraged cipher suites outlined below:


Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA256 0x00, 0x9E DHE RSA AES-GCM(128) SHA256
DHE-RSA-AES256-SHA384 0x00, 0x9F DHE RSA AES-GCM(256) SHA384
RSA-AES128-SHA256 0x00, 0x9C RSA RSA AES-GCM(128) SHA256
RSA-AES256-SHA384 0x00, 0x9D RSA RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

167117 - Security Updates for Microsoft Office Products (November 2022)
-
Synopsis
The Microsoft Office Products are missing a security update.
Description
The Microsoft Office Products are missing a security update that provides enhanced security as a defense-in-depth measure. This update provides hardening around IRM-protected documents to ensure the trust-of-certificate chain.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB3191875
-KB3191869

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
None
STIG Severity
I
References
MSKB 3191875
MSKB 3191869
XREF MSFT:MS22-3191875
XREF MSFT:MS22-3191869
XREF IAVA:2022-A-0479-S
Plugin Information
Published: 2022/11/08, Modified: 2022/12/29
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 3191869
- C:\Program Files\Microsoft Office\Office16\MSIPC\msipc.dll has not been patched.
Remote version : 1.0.623.47
Should be : 1.0.5017.0
160486 - Server Message Block (SMB) Protocol Version Detection
-
Synopsis
Verify the version of SMB on the remote host.
Description
The Server Message Block (SMB) Protocol provides shared access to files and printers across nodes on a network.
See Also
Solution
Disable SMB version 1 and block all versions of SMB at the network boundary by blocking TCP port 445 with related protocols on UDP ports 137-138 and TCP port 139, for all boundary devices.
Risk Factor
None
Plugin Information
Published: 2022/05/04, Modified: 2022/05/04
Plugin Output

tcp/445/cifs

- SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\SMB2 : Key not found.
- SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\SMB3 : Key not found.
- SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\SMB1 : Key not found.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/80/www

A web server is running on this port.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/1947/www

A web server is running on this port.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/5061

The service closed the connection without sending any data.
It might be protected by some sort of TCP wrapper.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/5357/www

A web server is running on this port.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/5985/www

A web server is running on this port.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/7001/www

A web server is running on this port.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/8001/www

A web server is running on this port.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/8002/www

A TLSv1.2 server answered on this port.

tcp/8002/www

A web server is running on this port through TLSv1.2.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/9505/www

A web server is running on this port.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/47001/www

A web server is running on this port.

278501 - Smartbedded Meteobridge Web Detection
-
Synopsis
The web UI for Smartbedded Meteobridge was detected on the remote host.
Description
Smartbedded Meteobridge, a dedicated weather monitoring application, is running on the remote host.

Note: Basic HTTP Authentication credentials are required to obtain the version.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/12, Modified: 2025/12/15
Plugin Output

tcp/80/www


URL : http://172.17.100.140/cgi-bin/meteobridge
Version : unknown
Authenticated : False

278501 - Smartbedded Meteobridge Web Detection
-
Synopsis
The web UI for Smartbedded Meteobridge was detected on the remote host.
Description
Smartbedded Meteobridge, a dedicated weather monitoring application, is running on the remote host.

Note: Basic HTTP Authentication credentials are required to obtain the version.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/12, Modified: 2025/12/15
Plugin Output

tcp/5985/www


URL : http://172.17.100.140:5985/cgi-bin/meteobridge
Version : unknown
Authenticated : False

278501 - Smartbedded Meteobridge Web Detection
-
Synopsis
The web UI for Smartbedded Meteobridge was detected on the remote host.
Description
Smartbedded Meteobridge, a dedicated weather monitoring application, is running on the remote host.

Note: Basic HTTP Authentication credentials are required to obtain the version.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/12, Modified: 2025/12/15
Plugin Output

tcp/7001/www


URL : http://172.17.100.140:7001/cgi-bin/meteobridge
Version : unknown
Authenticated : False

278501 - Smartbedded Meteobridge Web Detection
-
Synopsis
The web UI for Smartbedded Meteobridge was detected on the remote host.
Description
Smartbedded Meteobridge, a dedicated weather monitoring application, is running on the remote host.

Note: Basic HTTP Authentication credentials are required to obtain the version.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/12, Modified: 2025/12/15
Plugin Output

tcp/8001/www


URL : http://172.17.100.140:8001/cgi-bin/meteobridge
Version : unknown
Authenticated : False

278501 - Smartbedded Meteobridge Web Detection
-
Synopsis
The web UI for Smartbedded Meteobridge was detected on the remote host.
Description
Smartbedded Meteobridge, a dedicated weather monitoring application, is running on the remote host.

Note: Basic HTTP Authentication credentials are required to obtain the version.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/12, Modified: 2025/12/15
Plugin Output

tcp/8002/www


URL : https://172.17.100.140:8002/cgi-bin/meteobridge
Version : unknown
Authenticated : False

278501 - Smartbedded Meteobridge Web Detection
-
Synopsis
The web UI for Smartbedded Meteobridge was detected on the remote host.
Description
Smartbedded Meteobridge, a dedicated weather monitoring application, is running on the remote host.

Note: Basic HTTP Authentication credentials are required to obtain the version.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/12, Modified: 2025/12/15
Plugin Output

tcp/9505/www


URL : http://172.17.100.140:9505/cgi-bin/meteobridge
Version : unknown
Authenticated : False

278501 - Smartbedded Meteobridge Web Detection
-
Synopsis
The web UI for Smartbedded Meteobridge was detected on the remote host.
Description
Smartbedded Meteobridge, a dedicated weather monitoring application, is running on the remote host.

Note: Basic HTTP Authentication credentials are required to obtain the version.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/12, Modified: 2025/12/15
Plugin Output

tcp/47001/www


URL : http://172.17.100.140:47001/cgi-bin/meteobridge
Version : unknown
Authenticated : False

161455 - Supersedence Data Builder
-
Synopsis
Supersedence data.
Description
Collects and stores supersedence patch data for various patch types.
Solution
N/A
Risk Factor
None
Plugin Information
Published: 2022/05/24, Modified: 2025/07/14
Plugin Output

tcp/0

Supersedence patch data summary :
- MSKB : 310


Plugin debug log has been attached.

121010 - TLS Version 1.1 Protocol Detection
-
Synopsis
The remote service encrypts traffic using an older version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.1.
TLS 1.1 lacks support for current and recommended cipher suites.
Ciphers that support encryption before MAC computation, and authenticated encryption modes such as GCM cannot be used with TLS 1.1

As of March 31, 2020, Endpoints that are not enabled for TLS 1.2 and higher will no longer function properly with major web browsers and major vendors.
See Also
Solution
Enable support for TLS 1.2 and/or 1.3, and disable support for TLS 1.1.
Risk Factor
None
References
XREF CWE:327
Plugin Information
Published: 2019/01/08, Modified: 2023/04/19
Plugin Output

tcp/3389/msrdp

TLSv1.1 is enabled and the server supports at least one cipher.
136318 - TLS Version 1.2 Protocol Detection
-
Synopsis
The remote service encrypts traffic using a version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.2.
See Also
Solution
N/A
Risk Factor
None
Plugin Information
Published: 2020/05/04, Modified: 2020/05/04
Plugin Output

tcp/3389/msrdp

TLSv1.2 is enabled and the server supports at least one cipher.

110095 - Target Credential Issues by Authentication Protocol - No Issues Found
-
Synopsis
Nessus was able to log in to the remote host using the provided credentials. No issues were reported with access, privilege, or intermittent failure.
Description
Valid credentials were provided for an authentication protocol on the remote target and Nessus did not log any subsequent errors or failures for the authentication protocol.

When possible, Nessus tracks errors or failures related to otherwise valid credentials in order to highlight issues that may result in incomplete scan results or limited scan coverage. The types of issues that are tracked include errors that indicate that the account used for scanning did not have sufficient permissions for a particular check, intermittent protocol failures which are unexpected after the protocol has been negotiated successfully earlier in the scan, and intermittent authentication failures which are unexpected after a credential set has been accepted as valid earlier in the scan. This plugin reports when none of the above issues have been logged during the course of the scan for at least one authenticated protocol. See plugin output for details, including protocol, port, and account.

Please note the following :

- This plugin reports per protocol, so it is possible for issues to be encountered for one protocol and not another.
For example, authentication to the SSH service on the remote target may have consistently succeeded with no privilege errors encountered, while connections to the SMB service on the remote target may have failed intermittently.

- Resolving logged issues for all available authentication protocols may improve scan coverage, but the value of resolving each issue for a particular protocol may vary from target to target depending upon what data (if any) is gathered from the target via that protocol and what particular check failed. For example, consistently successful checks via SSH are more critical for Linux targets than for Windows targets, and likewise consistently successful checks via SMB are more critical for Windows targets than for Linux targets.
Solution
n/a
Risk Factor
None
References
XREF IAVB:0001-B-0520
Plugin Information
Published: 2018/05/24, Modified: 2025/08/28
Plugin Output

tcp/445/cifs


Nessus was able to log into the remote host with no privilege or access
problems via the following :

User: '172.17.100.140\tidua'
Port: 445
Proto: SMB
Method: password
141118 - Target Credential Status by Authentication Protocol - Valid Credentials Provided
-
Synopsis
Valid credentials were provided for an available authentication protocol.
Description
Nessus was able to determine that valid credentials were provided for an authentication protocol available on the remote target because it was able to successfully authenticate directly to the remote target using that authentication protocol at least once. Authentication was successful because the authentication protocol service was available remotely, the service was able to be identified, the authentication protocol was able to be negotiated successfully, and a set of credentials provided in the scan policy for that authentication protocol was accepted by the remote service. See plugin output for details, including protocol, port, and account.

Please note the following :

- This plugin reports per protocol, so it is possible for valid credentials to be provided for one protocol and not another. For example, authentication may succeed via SSH but fail via SMB, while no credentials were provided for an available SNMP service.

- Providing valid credentials for all available authentication protocols may improve scan coverage, but the value of successful authentication for a given protocol may vary from target to target depending upon what data (if any) is gathered from the target via that protocol. For example, successful authentication via SSH is more valuable for Linux targets than for Windows targets, and likewise successful authentication via SMB is more valuable for Windows targets than for Linux targets.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2020/10/15, Modified: 2024/03/25
Plugin Output

tcp/445/cifs


Nessus was able to log in to the remote host via the following :

User: '172.17.100.140\tidua'
Port: 445
Proto: SMB
Method: password

92433 - Terminal Services History
-
Synopsis
Nessus was able to gather terminal service connection information.
Description
Nessus was able to generate a report on terminal service connections on the target system.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

Terminal Services Client
- Production


Terminal Services Server
- S-1-5-21-3194671253-1068146636-4210433707-500_Classes
- S-1-5-21-3194671253-1068146636-4210433707-500_Classes
- Production
- Production
- S-1-5-18
- S-1-5-18
- S-1-5-80-4050220999-2730734961-1537482082-519850261-379003301
- S-1-5-80-4050220999-2730734961-1537482082-519850261-379003301
- S-1-5-80-4050220999-2730734961-1537482082-519850261-379003301_Classes
- S-1-5-80-4050220999-2730734961-1537482082-519850261-379003301_Classes


Extended Terminal Services report attached.

64814 - Terminal Services Use SSL/TLS
-
Synopsis
The remote Terminal Services use SSL/TLS.
Description
The remote Terminal Services is configured to use SSL/TLS.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/02/22, Modified: 2023/07/10
Plugin Output

tcp/3389/msrdp

Subject Name:

Common Name: LKP_SIP_AppSrv-140

Issuer Name:

Common Name: LKP_SIP_AppSrv-140

Serial Number: 38 BA 2A CB 4F B4 42 AD 48 1F B2 70 46 62 9B C7

Version: 3

Signature Algorithm: SHA-256 With RSA Encryption

Not Valid Before: Sep 21 22:44:55 2025 GMT
Not Valid After: Mar 23 22:44:55 2026 GMT

Public Key Info:

Algorithm: RSA Encryption
Key Length: 2048 bits
Public Key: 00 F1 63 B5 F6 BC 6C BB C9 CF 6E 7C E6 78 F0 2B 39 28 24 9C
16 01 53 7B 73 5B C2 11 D8 B5 6B DF 86 CF 06 D5 97 C4 BC 33
C7 F8 10 EE 5A 30 58 88 8F 4A 05 09 B3 90 46 92 42 3F E5 75
70 11 88 B0 99 55 A5 BC 89 FF CE E7 81 8D B4 9A B1 52 F1 82
4D E8 18 B8 0C DC EF 18 A9 86 D3 27 BC DA 52 F3 09 C3 8F D0
93 F6 B8 B6 BC 5D 3F 3F B0 8F C2 39 19 BC 6B 23 2A 39 A9 7B
89 C1 28 40 77 22 5A BD 88 34 02 B8 59 03 77 6B FB 58 A0 FD
40 69 DC 00 14 89 5E 64 AD D8 8F 3B 07 16 94 C2 78 97 18 93
14 1E B9 51 59 0F 70 FF EF 10 75 9A CF 8E 02 D6 A6 44 21 94
14 73 C6 A5 43 A7 1F 41 67 BA 24 31 AA 62 BD 15 D9 39 93 4C
16 71 F5 EB 0B D2 88 2D 48 C6 00 B8 5B A3 28 F9 09 FF 39 20
F5 25 E4 09 8A 16 CD 28 C1 8E C3 A4 3E 0C 14 05 C0 37 FB 32
02 89 E3 41 BE 6A 27 A4 D2 F4 D1 46 48 20 AD 8A 09
Exponent: 01 00 01

Signature Length: 256 bytes / 2048 bits
Signature: 00 06 82 9C CC AF 02 1E 73 1C 84 CD C1 53 3D 25 87 08 D4 16
E0 7E 75 F4 96 0C 1C C9 AC D8 BB 7C 58 B8 CB 85 FD F4 1D A9
37 02 48 3E F1 B9 CB C9 E1 C5 24 78 91 7F 17 5C D6 BA 90 94
9E 7E A5 1D D2 C7 D0 4C E5 24 7A 36 BF 45 B0 25 49 EF CE D1
24 19 E9 F0 E1 DA E8 09 7D 5C 84 6E 79 B7 7B EF 5C B6 65 33
86 CE 13 C4 15 21 28 10 47 6B 30 DD 4F C6 BD 0B C6 7D FA 60
BF 7F DB 4C DD D5 17 9A DD FB DD 66 55 35 BF FC A2 F9 7C 9C
1B B5 E5 EB 48 47 AA B1 89 30 38 9A 79 0E DC CA 65 FA B5 0B
91 87 44 45 0A 7F 4B E9 AA 90 9D 1F 5C 07 2A 77 47 92 07 72
D9 AD E9 21 0A 00 20 B1 05 D6 AF 2B 31 50 78 31 48 54 36 C8
56 1D F6 B9 CC 12 F7 6E EE AF 39 E8 4B D3 4B 5E D3 89 F6 D1
C0 9D 95 38 50 A5 77 36 51 BB E3 C2 AC EA EF 3D C2 F7 D0 C2
A5 DA 44 49 43 29 D1 6C 1A 36 12 02 9B 57 21 68 7D

Extension: Extended Key Usage(2.5.29.37)
Critical: 0
Purpose#1: Web Server Authentication (1.3.6.1.5.5.7.3.1)


Extension: Key Usage(2.5.29.15)
Critical: 0
Key Usage: Key Encipherment, Data Encipherment

161691 - The Microsoft Windows Support Diagnostic Tool (MSDT) RCE Workaround Detection (CVE-2022-30190)
-
Synopsis
Checks for the HKEY_CLASSES_ROOT\ms-msdt registry key.
Description
The remote host has the HKEY_CLASSES_ROOT\ms-msdt registry key. This is a known exposure for CVE-2022-30190.

Note that Nessus has not tested for CVE-2022-30190. It is only checking if the registry key exists. The recommendation is to apply the latest patch.
See Also
Solution
Apply the latest Cumulative Update.
Risk Factor
None
Plugin Information
Published: 2022/05/31, Modified: 2022/07/28
Plugin Output

tcp/445/cifs

The HKEY_CLASSES_ROOT\ms-msdt registry key exists on the target. This may indicate that the target is vulnerable to CVE-2022-30190, if the vendor patch is not applied.

56468 - Time of Last System Startup
-
Synopsis
The system has been started.
Description
Using the supplied credentials, Nessus was able to determine when the host was last started.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/10/12, Modified: 2018/06/19
Plugin Output

tcp/0


20260121092300.500000+330

10287 - Traceroute Information
-
Synopsis
It was possible to obtain traceroute information.
Description
Makes a traceroute to the remote host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 1999/11/27, Modified: 2023/12/04
Plugin Output

udp/0

For your information, here is the traceroute from 172.17.100.38 to 172.17.100.140 :
172.17.100.38
172.17.100.140

Hop Count: 1

92434 - User Download Folder Files
-
Synopsis
Nessus was able to enumerate downloaded files on the remote host.
Description
Nessus was able to generate a report of all files listed in the default user download folder.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/16
Plugin Output

tcp/0

C:\\Users\Administrator\Downloads\accessdatabaseengine_X64.exe
C:\\Users\Administrator\Downloads\desktop.ini
C:\\Users\Administrator\Downloads\MicrosoftEdgeSetup.exe
C:\\Users\Administrator\Downloads\NDP452-KB2901907-x86-x64-AllOS-ENU.exe
C:\\Users\Administrator\Downloads\Postman-win64-Setup.exe
C:\\Users\Administrator\Downloads\requestRouter_amd64.msi
C:\\Users\Administrator\Downloads\rewrite_amd64_en-US.msi
C:\\Users\Administrator\Downloads\SQLServerReportingServices.exe
C:\\Users\Public\Downloads\desktop.ini

Download folder content report attached.
92431 - User Shell Folders Settings
-
Synopsis
Nessus was able to find the folder paths for user folders on the remote host.
Description
Nessus was able to gather a list of settings from the target system that store common user folder locations. A few of the more common locations are listed below :

- Administrative Tools
- AppData
- Cache
- CD Burning
- Cookies
- Desktop
- Favorites
- Fonts
- History
- Local AppData
- My Music
- My Pictures
- My Video
- NetHood
- Personal
- PrintHood
- Programs
- Recent
- SendTo
- Start Menu
- Startup
- Templates
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/16
Plugin Output

tcp/0

Production
- {7d1d3a04-debb-4115-95cf-2f29da2920da} : C:\Users\Administrator\Searches
- {1b3ea5dc-b587-4786-b4ef-bd1dc332aeae} : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Libraries
- {374de290-123f-4565-9164-39c4925e467b} : C:\Users\Administrator\Downloads
- recent : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Recent
- my video : C:\Users\Administrator\Videos
- my music : C:\Users\Administrator\Music
- {56784854-c6cb-462b-8169-88e350acb882} : C:\Users\Administrator\Contacts
- {bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968} : C:\Users\Administrator\Links
- {a520a1a4-1780-4ff6-bd18-167343c5af16} : C:\Users\Administrator\AppData\LocalLow
- sendto : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\SendTo
- start menu : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu
- cookies : C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCookies
- personal : C:\Users\Administrator\Documents
- administrative tools : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
- startup : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
- nethood : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Network Shortcuts
- history : C:\Users\Administrator\AppData\Local\Microsoft\Windows\History
- {4c5c32ff-bb9d-43b0-b5b4-2d72e54eaaa4} : C:\Users\Administrator\Saved Games
- {00bcfc5a-ed94-4e48-96a1-3f6217f21990} : C:\Users\Administrator\AppData\Local\Microsoft\Windows\RoamingTiles
- !do not use this registry key : Use the SHGetFolderPath or SHGetKnownFolderPath function instead
- local appdata : C:\Users\Administrator\AppData\Local
- my pictures : C:\Users\Administrator\Pictures
- templates : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates
- printhood : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
- cache : C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache
- desktop : C:\Users\Administrator\Desktop
- programs : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
- fonts : C:\Windows\Fonts
- cd burning : C:\Users\Administrator\AppData\Local\Microsoft\Windows\Burn\Burn
- favorites : C:\Users\Administrator\Favorites
- appdata : C:\Users\Administrator\AppData\Roaming
92435 - UserAssist Execution History
-
Synopsis
Nessus was able to enumerate program execution history on the remote host.
Description
Nessus was able to gather evidence from the UserAssist registry key that has a list of programs that have been executed.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2019/11/12
Plugin Output

tcp/0

c:\users\administrator\desktop\engine_ver2.7.7.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\cleanmgr.exe
{6d809377-6af0-444b-8957-a3773f02200e}\wireshark\npcap-1.79.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\system information.lnk
{f38bf404-1d43-42f2-9305-67de0b28fc23}\temp\{d962a358-2197-46f7-b587-f23bb438c149}\.cr\dotnet-hosting-8.0.8-win.exe
d:\nexsus\lkp_engine_ver2.7.7.0\nexsus.maxdial.engine.exe
ueme_ctlsession
c:\users\administrator\downloads\accessdatabaseengine_x64.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\snippingtool.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\windowspowershell\v1.0\powershell_ise.exe
c:\users\administrator\downloads\sqlserverreportingservices.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\rundll32.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\remote desktop connection.lnk
c:\users\public\desktop\microsoft edge.lnk
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft\edgeupdate\microsoftedgeupdate.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\msdt.exe
kasperskylab.kis.ui.toasts
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\shctisetup\_selfinstall\winpcap_4_1_2.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\services.lnk
c:\users\administrator\desktop\engine_ver2.8.0.0..lnk
microsoft.internetexplorer.default
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\microsoft sql server reporting services\report server configuration manager.lnk
{6d809377-6af0-444b-8957-a3773f02200e}\microsoft office\office16\excel.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\zoiper\zoiper.exe
d:\nexsus\nexsus_software\zoiper_3.9_setup.exe
{f38bf404-1d43-42f2-9305-67de0b28fc23}\temp\{8d760a06-1ddd-4688-8dc6-6bd76d53b85b}\.cr\dotnet-hosting-5.0.17-win.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\mmc.exe
d:\nexsus\backup\timestamping.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\remote desktop connection.lnk
c:\users\administrator\desktop\engine_ver2.7.5.lnk
d:\setup64.exe
d:\nexsus\accessdatabaseengine.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\microsoft edge.lnk
{f38bf404-1d43-42f2-9305-67de0b28fc23}\hh.exe
d:\nexsus\lkp_engine_ver2.3\nexsus.maxdial.engine.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\logmein rescue applet\lmir0a39b001.tmp\lmi_rescue.exe
d:\nexsus\backup\18dec2025\lkp_engine_ver2.3\nexsus.maxdial.engine.exe
c:\users\administrator\desktop\engine_ver2.7.lnk
d:\nexsus\lkp_engine_ver2.8.0.0\nexsus.maxdial.engine.exe
c:\users\administrator\desktop\encryptdecrypt\encryptdecryptcallbalance - shortcut.lnk
d:\nexsus\x-lite_win32_4.5.5._71236.exe
{d65231b0-b2f1-4857-a4ce-a8e7c6ea7d27}\cmd.exe
d:\nexsus\nexsus_software\timestamping.exe
c:\users\administrator\desktop\engine_ver2.7.5.0.lnk
microsoft.autogenerated.{923dd477-5846-686b-a659-0fccd73851a8}
{6d809377-6af0-444b-8957-a3773f02200e}\vmware\vmware tools\vmtoolsd.exe
d:\nexsus\accessdatabaseengine (2).exe
c:\users\administrator\desktop\engine_ver2.7.6.1.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\paint.lnk
c:\users\administrator\desktop\engine_ver2.7.6.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\shutdown.exe
c:\shcti\getinfotool.exe
c:\users\administrator\desktop\edtool - shortcut.lnk
c:\users\administrator\desktop\test - shortcut.lnk
com.squirrel.postman.postman
e:\setup64.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\notepad.exe
{6d809377-6af0-444b-8957-a3773f02200e}\wireshark\wireshark.exe
c:\users\administrator\appdata\local\logmein rescue applet\lmir0a399001.tmp\lmi_rescue.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\internet explorer.lnk
d:\lkpsoft\date_minute_second_logger.bat
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\systempropertiescomputername.exe
d:\nexsus\lkp_engine_ver2.7.9.1\nexsus.maxdial.engine.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\dfrgui.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\ultraviewer\ultraviewer_desktop.exe
c:\users\administrator\desktop\engine_ver2.7.8.0.lnk
microsoft.windows.explorer
ueme_ctlcuacount:ctor
c:\users\administrator\desktop\sip link check.bat
c:\users\administrator\documents\accessdatabaseengine.exe
d:\nexsus\nexsus.maxdial.engine\nexsus.maxdial.engine.exe
d:\nexsus\nexsus_software\ed tool\edtool.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\file explorer.lnk
d:\nexsus\nexsus_patch\nexsus.maxdial.emailservice\nexsusemailservice.exe.config - shortcut.lnk
d:\nexsus\lkp_engine_ver2.7.5\nexsus.maxdial.engine.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\systempropertiesadvanced.exe
c:\users\administrator\desktop\engine_ver2.5.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\iis manager.lnk
{6d809377-6af0-444b-8957-a3773f02200e}\microsoft sql server reporting services\shared tools\rsconfigtool.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\dcomcnfg.exe
c:\users\administrator\desktop\dotnet-hosting-5.0.17-win.exe
{f38bf404-1d43-42f2-9305-67de0b28fc23}\regedit.exe
d:\nexsus\lkp_engine_ver2.6\nexsus.maxdial.engine.exe
d:\nexsus\mailalert\mailalert\_internal\mailalert.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft\edgeupdate\1.3.195.39\microsoftedgeupdate.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\zoiper\zoiper.lnk
d:\nexsus\nexsus_patch\nexsus.maxdial.engine\nexsus.maxdial.engine.exe
microsoft.windows.controlpanel
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\credentialuibroker.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\system tools\control panel.lnk
c:\users\administrator\desktop\engine_ver2.7.9.0.lnk
d:\nexsus\lkp_engine_ver2.7.8.0\nexsus.maxdial.engine.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\winver.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\wscript.exe
c:\users\administrator\desktop\engine_ver2.3.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\win32calc.exe
d:\nexsus\lkp_engine_ver2.5\nexsus.maxdial.engine.exe
c:\users\administrator\recent\timestamp_log.txt.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\windowspowershell\v1.0\powershell.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\shctisetup\_selfinstall\dpinst_x64.exe
c:\users\administrator\desktop\encryptdecryptcallbalance - shortcut.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\registry editor.lnk
c:\users\administrator\desktop\engine_ver2.6.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\computer management.lnk
microsoft.windows.apprep.chxapp_cw5n1h2txyewy!app
microsoft.windows.windowsinstaller
d:\nexsus\nexsus_software\timer\timer.bat
microsoft.autogenerated.{bb044bfd-25b7-2faa-22a8-6371a93e0456}
d:\nexsus\lkp_engine_ver2.7.6.0\nexsus.maxdial.engine.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\systempropertiesremote.exe
d:\nexsus\lkp_engine_ver2.7.9.0\nexsus.maxdial.engine.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\dxdiag.exe
d:\nexsus\nexsus_patch\lkp_engine_ver1.1\nexsus.maxdial.engine.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\msinfo32.exe
c:\users\administrator\desktop\edtool - tpin.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\shcti\test.lnk
c:\shcti\test.exe
c:\users\administrator\recent\connection.lnk
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\system tools\command prompt.lnk
c:\users\administrator\downloads\postman-win64-setup.exe
d:\nexsus\nexsus_patch\21backup\nexsus.maxdial.engine.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\mspaint.exe
microsoft.autogenerated.{c804bba7-fa5f-cbf7-8b55-2096e5f972cb}
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\event viewer.lnk
microsoft.windows.computer
d:\nexsus\nexsus_software\debug\api_data_insert.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\calc.exe
microsoft.windows.remotedesktop
c:\users\administrator\appdata\local\squirreltemp\update.exe
c:\users\administrator\desktop\win64openssl-3_4_0.exe
d:\nexsus\lkp_engine_ver2.6 - rnd\nexsus.maxdial.engine.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\iisreset.exe
microsoft.windows.cortana_cw5n1h2txyewy!cortanaui
d:\nexsus\lkp_engine_ver2.7\nexsus.maxdial.engine.exe
c:\users\administrator\desktop\iis manager.lnk
microsoft.windows.mediaplayer32
d:\nexsus\synway_pci(usb)_5442_en.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\wireshark.lnk
d:\nexsus\mailalert\mailalert\mailalert.exe
\\192.168.10.235\lkpsoft\microsoft\office\sw_dvd5_office_2016_64bit_english_mlf_x20-42479\setup.exe
d:\nexsus\nexsus_software\encryptdecryptcallbalance.exe
c:\shcti\shcticonfig.exe
c:\users\administrator\desktop\nexsus.maxdial.engine - shortcut.lnk
d:\lkpsoft\live netagent_14.2.0.26967_kes 12.3.0.493 aes256\installer.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\server manager.lnk
c:\users\administrator\desktop\rnd.lnk
microsoft.autogenerated.{8abd94fb-e7d6-84a6-a997-c918edde0ae5}
d:\nexsus\accessdatabaseengine (1).exe
microsoft.windows.shell.rundialog
c:\users\administrator\desktop\engine_ver2.7.9.1.lnk
c:\users\administrator\downloads\microsoftedgesetup.exe
d:\nexsus\ed tool\edtool.exe
microsoft.windows.shellexperiencehost_cw5n1h2txyewy!app
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\snipping tool.lnk
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\microsoft edge.lnk
windows.immersivecontrolpanel_cw5n1h2txyewy!microsoft.windows.immersivecontrolpanel
msedge
d:\nexsus\wireshark-4.4.2-x64.exe
d:\nexsus\encryptdecryptcallbalance.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\servermanager.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\cmd.exe
d:\nexsus\lkp_engine_ver2.7.6.1\nexsus.maxdial.engine.exe
c:\users\administrator\desktop\dotnet-hosting-8.0.8-win.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\inetsrv\inetmgr.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\ping.exe
c:\users\administrator\desktop\postman.lnk
c:\users\administrator\downloads\ndp452-kb2901907-x86-x64-allos-enu.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\openwith.exe
d:\nexsus\nexsus_patch\nexsus.maxdial.engine - copy\nexsus.maxdial.engine.exe
c:\users\administrator\desktop\engine_2.7.lnk
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\postman\postman.lnk
c:\shcti\castool.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\services.msc
c:\users\administrator\recent\machine.lnk
c:\users\administrator\recent\16-04-2025.txt.lnk
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\accessories\notepad.lnk
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\windows powershell\windows powershell.lnk
c:\users\administrator\desktop\nexsus.maxdial.engine.exe - shortcut.lnk
c:\users\administrator\recent\16-apr-2025.txt.lnk
{6d809377-6af0-444b-8957-a3773f02200e}\npcap\npfinstall.exe

Extended userassist report attached.

105793 - VMware Tools Detection
-
Synopsis
A virtual machine management application is installed on the remote host.
Description
VMware Tools, a suite of utilities that enhances the performance of the virtual machines guest operating system is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0738
Plugin Information
Published: 2018/01/13, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Path : C:\Program Files\VMware\VMware Tools\
Version : 12.4.0.48309

20094 - VMware Virtual Machine Detection
-
Synopsis
The remote host is a VMware virtual machine.
Description
According to the MAC address of its network adapter, the remote host is a VMware virtual machine.
Solution
Since it is physically accessible through the network, ensure that its configuration matches your organization's security policy.
Risk Factor
None
Plugin Information
Published: 2005/10/27, Modified: 2019/12/11
Plugin Output

tcp/0


The remote host is a VMware virtual machine.

24269 - WMI Available
-
Synopsis
WMI queries can be made against the remote host.
Description
The supplied credentials can be used to make WMI (Windows Management Instrumentation) requests against the remote host over DCOM.

These requests can be used to gather information about the remote host, such as its current state, network interface configuration, etc.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/02/03, Modified: 2025/12/15
Plugin Output

tcp/445/cifs

The remote host returned the following caption from Win32_OperatingSystem:

Microsoft Windows Server 2019 Datacenter

71637 - WMI IIS ISAPI Extension Enumeration
-
Synopsis
The remote host has ISAPI extensions set up with IIS.
Description
The remote host is running one or more ISAPI IIS extensions such as ASP.NET installed. This plugin enumerates these extensions by examining the ISAPI filters and displays information on whether the extension is enabled or disabled.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/12/20, Modified: 2025/12/15
Plugin Output

tcp/0


IIS component : Active Server Pages
Component path : %windir%\system32\inetsrv\asp.dll
Enabled ? : Yes

IIS component : WebDAV
Component path : %windir%\system32\inetsrv\webdav.dll
Enabled ? : Yes

IIS component : ASP.NET v2.0.50727
Component path : %windir%\Microsoft.NET\Framework64\v2.0.50727\aspnet_isapi.dll
Enabled ? : Yes

IIS component : ASP.NET v2.0.50727
Component path : %windir%\Microsoft.NET\Framework\v2.0.50727\aspnet_isapi.dll
Enabled ? : Yes

IIS component : ASP.NET v4.0.30319
Component path : %windir%\Microsoft.NET\Framework\v4.0.30319\aspnet_isapi.dll
Enabled ? : Yes

IIS component : ASP.NET v4.0.30319
Component path : %windir%\Microsoft.NET\Framework64\v4.0.30319\aspnet_isapi.dll
Enabled ? : Yes
52001 - WMI QuickFixEngineering (QFE) Enumeration
-
Synopsis
The remote Windows host has quick-fix engineering updates installed.
Description
By connecting to the remote host with the supplied credentials, this plugin enumerates quick-fix engineering updates installed on the remote host via WMI.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/02/16, Modified: 2025/12/15
Plugin Output

tcp/0


Here is a list of quick-fix engineering updates installed on the
remote system :

+ KB5049608
- Description : Update
- InstalledOn : 4/2/2025
- SystemName : LKP_SIP_APPSRV-
- InstalledBy : LKP_SIP_APPSRV-\Production
- Caption : http://support.microsoft.com/?kbid=5049608

+ KB4589208
- Description : Update
- InstalledOn : 6/26/2024
- SystemName : LKP_SIP_APPSRV-
- InstalledBy : NT AUTHORITY\SYSTEM
- Caption : https://support.microsoft.com/help/4589208

+ KB5005112
- Description : Security Update
- InstalledOn : 8/5/2021
- SystemName : LKP_SIP_APPSRV-
- Caption : https://support.microsoft.com/help/5005112

+ KB5052000
- Description : Security Update
- InstalledOn : 4/2/2025
- SystemName : LKP_SIP_APPSRV-
- InstalledBy : NT AUTHORITY\SYSTEM
- Caption : https://support.microsoft.com/help/5052000

+ KB5039335
- Description : Security Update
- InstalledOn : 6/26/2024
- SystemName : LKP_SIP_APPSRV-
- InstalledBy : NT AUTHORITY\SYSTEM

+ KB5050110
- Description : Security Update
- InstalledOn : 4/2/2025
- SystemName : LKP_SIP_APPSRV-
- InstalledBy : NT AUTHORITY\SYSTEM
44871 - WMI Windows Feature Enumeration
-
Synopsis
It is possible to enumerate Windows features using WMI.
Description
Nessus was able to enumerate the server features of the remote host by querying the 'Win32_ServerFeature' class of the '\Root\cimv2' WMI namespace for Windows Server versions or the 'Win32_OptionalFeature' class of the '\Root\cimv2' WMI namespace for Windows Desktop versions.

Note that Features can only be enumerated for Windows 7 and later for desktop versions.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0754
Plugin Information
Published: 2010/02/24, Modified: 2025/12/15
Plugin Output

tcp/0


Nessus enumerated the following Windows features :

- .NET Environment 3.5
- .NET Extensibility 3.5
- .NET Extensibility 4.7
- .NET Framework 3.5 (includes .NET 2.0 and 3.0)
- .NET Framework 3.5 Features
- .NET Framework 4.7
- .NET Framework 4.7 Features
- ASP
- ASP.NET 3.5
- ASP.NET 4.7
- ASP.NET 4.7
- Application Development
- Application Initialization
- Basic Authentication
- CGI
- Centralized SSL Certificate Support
- Client Certificate Mapping Authentication
- Common HTTP Features
- Configuration APIs
- Custom Logging
- Default Document
- Digest Authentication
- Directory Browsing
- Dynamic Content Compression
- File Server
- File and Storage Services
- File and iSCSI Services
- HTTP Activation
- HTTP Activation
- HTTP Errors
- HTTP Logging
- HTTP Redirection
- Health and Diagnostics
- IIS 6 Management Compatibility
- IIS 6 Management Console
- IIS 6 Metabase Compatibility
- IIS 6 Scripting Tools
- IIS 6 WMI Compatibility
- IIS Client Certificate Mapping Authentication
- IIS Hostable Web Core
- IIS Management Console
- IIS Management Scripts and Tools
- IP and Domain Restrictions
- ISAPI Extensions
- ISAPI Filters
- Logging Tools
- Management Service
- Management Tools
- Message Queuing
- Message Queuing (MSMQ) Activation
- Message Queuing Server
- Message Queuing Services
- Named Pipe Activation
- Non-HTTP Activation
- ODBC Logging
- Performance
- Process Model
- Request Filtering
- Request Monitor
- Security
- Server Side Includes
- Static Content
- Static Content Compression
- Storage Services
- System Data Archiver
- TCP Activation
- TCP Port Sharing
- Telnet Client
- Tracing
- URL Authorization
- WCF Services
- Web Server
- Web Server (IIS)
- WebDAV Publishing
- WebSocket Protocol
- Windows Authentication
- Windows Defender Antivirus
- Windows PowerShell
- Windows PowerShell 2.0 Engine
- Windows PowerShell 5.1
- Windows PowerShell ISE
- Windows Process Activation Service
- WoW64 Support
- XPS Viewer

33139 - WS-Management Server Detection
-
Synopsis
The remote web server is used for remote management.
Description
The remote web server supports the Web Services for Management (WS-Management) specification, a general web services protocol based on SOAP for managing systems, applications, and other such entities.
See Also
Solution
Limit incoming traffic to this port if desired.
Risk Factor
None
Plugin Information
Published: 2008/06/11, Modified: 2021/05/19
Plugin Output

tcp/5985/www


Here is some information about the WS-Management Server :

Product Vendor : Microsoft Corporation
Product Version : OS: 0.0.0 SP: 0.0 Stack: 3.0

11422 - Web Server Unconfigured - Default Install Page Present
-
Synopsis
The remote web server is not configured or is improperly configured.
Description
The remote web server uses its default welcome page. Therefore, it's probable that this server is not used at all or is serving content that is meant to be hidden.
Solution
Disable this service if you do not use it.
Risk Factor
None
Plugin Information
Published: 2003/03/20, Modified: 2018/08/15
Plugin Output

tcp/80/www


The default welcome page is from IIS.

162174 - Windows Always Installed Elevated Status
-
Synopsis
Windows AlwaysInstallElevated policy status was found on the remote Windows host
Description
Windows AlwaysInstallElevated policy status was found on the remote Windows host.
You can use the AlwaysInstallElevated policy to install a Windows Installer package with elevated (system) privileges This option is equivalent to granting full administrative rights, which can pose a massive security risk. Microsoft strongly discourages the use of this setting.
Solution
If enabled, disable AlwaysInstallElevated policy per your corporate security guidelines.
Risk Factor
None
Plugin Information
Published: 2022/06/14, Modified: 2022/06/14
Plugin Output

tcp/445/cifs

AlwaysInstallElevated policy is not enabled under HKEY_LOCAL_MACHINE.
AlwaysInstallElevated policy is not enabled under HKEY_USERS user:S-1-5-21-3194671253-1068146636-4210433707-500

48337 - Windows ComputerSystemProduct Enumeration (WMI)
-
Synopsis
It is possible to obtain product information from the remote host using WMI.
Description
By querying the WMI class 'Win32_ComputerSystemProduct', it is possible to extract product information about the computer system such as UUID, IdentifyingNumber, vendor, etc.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/08/16, Modified: 2025/12/15
Plugin Output

tcp/0


+ Computer System Product
- IdentifyingNumber : VMware-42 08 1c e5 56 c8 5f 96-59 92 bf 08 b7 4d 11 6e
- Description : Computer System Product
- Vendor : VMware, Inc.
- Name : VMware7,1
- UUID : E51C0842-C856-965F-5992-BF08B74D116E
- Version : None

159817 - Windows Credential Guard Status
-
Synopsis
Retrieves the status of Windows Credential Guard.
Description
Retrieves the status of Windows Credential Guard.
Credential Guard prevents attacks such as such as Pass-the-Hash or Pass-The-Ticket by protecting NTLM password hashes, Kerberos Ticket Granting Tickets, and credentials stored by applications as domain credentials.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2022/04/18, Modified: 2023/08/25
Plugin Output

tcp/445/cifs


Windows Credential Guard is not fully enabled.
The following registry keys have not been set :
- System\CurrentControlSet\Control\DeviceGuard\RequirePlatformSecurityFeatures : Key not found.
- System\CurrentControlSet\Control\LSA\LsaCfgFlags : Key not found.
- System\CurrentControlSet\Control\DeviceGuard\EnableVirtualizationBasedSecurity : Key not found.
58181 - Windows DNS Server Enumeration
-
Synopsis
Nessus enumerated the DNS servers being used by the remote Windows host.
Description
Nessus was able to enumerate the DNS servers configured on the remote Windows host by looking in the registry.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2012/03/01, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Nessus enumerated DNS servers for the following interfaces :

Interface: {934160fb-8b50-4cc7-8f5c-35e39899f321}
Network Connection : LAN
NameServer: 8.8.8.8

131023 - Windows Defender Installed
-
Synopsis
Windows Defender is installed on the remote Windows host.
Description
Windows Defender, an antivirus component of Microsoft Windows is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2019/11/15, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\ProgramData\Microsoft\Windows Defender\platform\4.18.24050.7-0\
Version : 4.18.24050.7
Disabled : 1
Engine Version : 1.1.24050.5
Malware Signature Timestamp : Jun. 26, 2024 at 04:38:35 GMT
Malware Signature Version : 1.413.529.0
Signatures Last Updated : Jun. 26, 2024 at 11:52:21 GMT

164690 - Windows Disabled Command Prompt Enumeration
-
Synopsis
This plugin determines if the DisableCMD policy is enabled or disabled on the remote host for each local user.
Description
The remote host may employ the DisableCMD policy on a per user basis. Enumerated local users may have the following registry key:
'HKLM\Software\Policies\Microsoft\Windows\System\DisableCMD'

- Unset or 0: The command prompt is enabled normally.
- 1: The command promt is disabled.
- 2: The command prompt is disabled however windows batch processing is allowed.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2022/09/06, Modified: 2022/10/05
Plugin Output

tcp/445/cifs


Username: tidua
SID: S-1-5-21-3194671253-1068146636-4210433707-1003
DisableCMD: Unset

Username: LKPAdmin
SID: S-1-5-21-3194671253-1068146636-4210433707-1000
DisableCMD: Unset

Username: DefaultAccount
SID: S-1-5-21-3194671253-1068146636-4210433707-503
DisableCMD: Unset

Username: WDAGUtilityAccount
SID: S-1-5-21-3194671253-1068146636-4210433707-504
DisableCMD: Unset

Username: Production
SID: S-1-5-21-3194671253-1068146636-4210433707-500
DisableCMD: Unset

Username: Guest
SID: S-1-5-21-3194671253-1068146636-4210433707-501
DisableCMD: Unset

72482 - Windows Display Driver Enumeration
-
Synopsis
Nessus was able to enumerate one or more of the display drivers on the remote host.
Description
Nessus was able to enumerate one or more of the display drivers on the remote host via WMI.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0756
Plugin Information
Published: 2014/02/06, Modified: 2025/12/15
Plugin Output

tcp/0


Device Name : VMware SVGA 3D
Driver File Version : 9.17.7.2
Driver Date : 08/28/2023
Video Processor : VMware Virtual SVGA 3D Graphics Adapter
171956 - Windows Enumerate Accounts
-
Synopsis
Enumerate Windows accounts.
Description
Enumerate Windows accounts.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/02/28, Modified: 2025/12/15
Plugin Output

tcp/0

Windows accounts enumerated. Results output to DB.
User data gathered in scan starting at : 2026/1/24 12:16 India Standard Time
92423 - Windows Explorer Recently Executed Programs
-
Synopsis
Nessus was able to enumerate recently executed programs on the remote host.
Description
Nessus was able to find evidence of program execution using Windows Explorer registry logs and settings.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2019/08/15
Plugin Output

tcp/0

notepad.exePO :i+00:.:,LB)A&&-:\nk\nk
InetMgr.exePO :i+00/D:\V1g[CLKPSOFT@X@g[C.*2lLKPSOFT
msedge.exePO :i+00/D:\T1YINexsus>YxXYI./6Nexsusb1YoFLKP21122024HYoFYoF.%IRLKP21122024b1YFLKP21122024HYoFYF.:LKP21122024
mmc.exePO :i+00/D:\
msinfo32.exePO :i+00.+ezFkp:
IEXPLORE.EXEPO :i+00.+ezFkp:
winver\1
mstsc\1
calc\1
perfmon\1
drivers\1
cmd\1
iisreset\1
recent\1
dxdiag\1
services.msc\1
wmimgmt.msc\1
gpedit.msc\1
\\192.168.10.234\1
ping 172.31.100.49\1
regedit\1
inetmgr\1
notepad\1
D:\Nexsus\Nexsus_Patch\Nexsus.MaxDial.VoiceLogService_Web_LKP\1
mspaint\1
firewall.cpl\1
kjpnzeohmlgicbdaqsywxtvurf
appwiz.cpl\1
certlm.msc\1
dcomcnfg\1
compmgmt.msc\1
%temp%\1
ncpa.cpl\1
GetInfoTool.exe4B
NOTEPAD.EXE.6
API_Data_Insert.exeJ7
msedge.exe
IEXPLORE.EXE
mmc.exec\n
InetMgr.exed{\r
msinfo32.exe22N:e
X\r,!PCsg<
x@_dP/N

MRU programs details in attached report.
92418 - Windows Explorer Typed Paths
-
Synopsis
Nessus was able to enumerate the directory paths that users visited by typing the full directory path into Windows Explorer.
Description
Nessus was able to enumerate the directory paths that users visited by manually typing the full directory path into Windows Explorer. The generated folder list report contains folders local to the system, folders from past mounted network drives, and folders from mounted devices.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

\\192.168.10.234\bod
C:\
C:\Program Files (x86)
D:\CallbalanceVoiceLogs
D:\
D:\Nexsus\Nexsus_Service_updated\Nexsus.MaxDial.UserStatusValidator_Web
ftp://114.143.214.98/
F:\
C:\CallbalanceEngineLog\2025\January\07
C:\CallbalanceEngineLog\2025\April\16
C:\ShCti\ShCtiLog
C:\Windows\Microsoft.NET\Framework64\v4.0.30319
D:\Nexsus\Nexsus_Patch\Nexsus.MaxDial.VoiceLogService_Web_LKP
cmd
C:\Users\Administrator\Desktop\Config
D:\Nexsus\CallBalance\Log\App Log
D:\Nexsus
D:\CallbalanceVoiceLogs\Processed\LKP\West\Maharashtra\Mumbai\2025
D:\Nexsus\Nexsus_Services\Nexsus.MaxDial.UserStatusValidator_Web_Backup
D:\Nexsus\Nexsus_Patch\Nexsus.MaxDial.UserStatusValidator_Web
D:\Nexsus\Nexsus_Patch
D:\Nexsus\Nexsus_Services\Nexsus.MaxDial.UserStatusValidator_Web

Extended explorer typed paths report attached.

159929 - Windows LSA Protection Status
-
Synopsis
Windows LSA Protection is disabled on the remote Windows host.
Description
The LSA Protection validates users for local and remote sign-ins and enforces local security policies to prevent reading memory and code injection by non-protected processes. This provides added security for the credentials that the LSA stores and manages. This protects against Pass-the-Hash or Mimikatz-style attacks.
Solution
Enable LSA Protection per your corporate security guidelines.
Risk Factor
None
Plugin Information
Published: 2022/04/20, Modified: 2025/06/16
Plugin Output

tcp/445/cifs


LSA Protection Key \SYSTEM\CurrentControlSet\Control\Lsa\RunAsPPL not found.

148541 - Windows Language Settings Detection
-
Synopsis
This plugin enumerates language files on a windows host.
Description
By connecting to the remote host with the supplied credentials, this plugin enumerates language IDs listed on the host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2021/04/14, Modified: 2022/02/01
Plugin Output

tcp/0

Default Install Language Code: 1033

Default Active Language Code: 16393

Other common microsoft Language packs may be scanned as well.

10150 - Windows NetBIOS / SMB Remote Host Information Disclosure
-
Synopsis
It was possible to obtain the network name of the remote host.
Description
The remote host is listening on UDP port 137 or TCP port 445, and replies to NetBIOS nbtscan or SMB requests.

Note that this plugin gathers information to be used in other plugins, but does not itself generate a report.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 1999/10/12, Modified: 2021/02/10
Plugin Output

tcp/445/cifs

The following 2 NetBIOS names have been gathered :

LKP_SIP_APPSRV- = Computer name
LKP_SIP_APPSRV- = Workgroup / Domain name
155963 - Windows Printer Driver Enumeration
-
Synopsis
Nessus was able to enumerate one or more of the printer drivers on the remote host.
Description
Nessus was able to enumerate one or more of the printer drivers on the remote host via WMI.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2021/12/09, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


--- Microsoft XPS Document Writer v4 ---

Path : C:\Windows\System32\DriverStore\FileRepository\ntprint.inf_amd64_dc0a6d45c3f7a557\Amd64\mxdwdrv.dll
Version : 10.0.17763.1
Supported Platform : Windows x64

--- Microsoft Software Printer Driver ---

Path : C:\Windows\System32\DriverStore\FileRepository\ntprint.inf_amd64_dc0a6d45c3f7a557\Amd64\mxdwdrv.dll
Version : 10.0.17763.5830
Supported Platform : Windows x64

--- Microsoft enhanced Point and Print compatibility driver ---

Nessus detected 2 installs of Microsoft enhanced Point and Print compatibility driver:

Path : C:\Windows\system32\spool\DRIVERS\x64\3\mxdwdrv.dll
Version : 10.0.17763.5933
Supported Platform : Windows x64

Path : C:\Windows\system32\spool\DRIVERS\W32X86\3\mxdwdrv.dll
Version : 10.0.17763.5933
Supported Platform : Windows NT x86

--- Send to Microsoft OneNote 16 Driver ---

Path : C:\Windows\System32\DriverStore\FileRepository\ntprint.inf_amd64_dc0a6d45c3f7a557\Amd64\mxdwdrv.dll
Version : 16.0.1626.4000
Supported Platform : Windows x64

--- Microsoft Print To PDF ---

Path : C:\Windows\System32\DriverStore\FileRepository\ntprint.inf_amd64_dc0a6d45c3f7a557\Amd64\mxdwdrv.dll
Version : 10.0.17763.1
Supported Platform : Windows x64

--- Microsoft Shared Fax Driver ---

Path : C:\Windows\system32\spool\DRIVERS\x64\3\FXSDRV.DLL
Version : 10.0.17763.6414
Supported Platform : Windows x64

--- Remote Desktop Easy Print ---

Path : C:\Windows\system32\spool\DRIVERS\x64\3\mxdwdrv.dll
Version : 10.0.17763.973
Supported Platform : Windows x64
63620 - Windows Product Key Retrieval
-
Synopsis
This plugin retrieves the Windows Product key of the remote Windows host.
Description
Using the supplied credentials, Nessus was able to obtain the retrieve the Windows host's partial product key'.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/01/18, Modified: 2013/01/18
Plugin Output

tcp/445/cifs


Product key : XXXXX-XXXXX-XXXXX-XXXXX-BWT4H

Note that all but the final portion of the key has been obfuscated.
160576 - Windows Services Registry ACL
-
Synopsis
Checks Windows Registry for Service ACLs
Description
Checks Windows Registry for Service ACLs.
Solution
N/A
Risk Factor
None
Plugin Information
Published: 2022/05/05, Modified: 2024/01/15
Plugin Output

tcp/445/cifs

report output too big - ending list here

204960 - Windows System Driver Enumeration (Windows)
-
Synopsis
One or more kernel or file system drivers were enumerated on the remote Windows host.
Description
One or more kernel or file system drivers were enumerated on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2024/08/01, Modified: 2025/12/15
Plugin Output

tcp/0


Total : 373

Name : 1394ohci
Path : C:\Windows\system32\drivers\1394ohci.sys
Service Type : Kernel Driver
Description : 1394 OHCI Compliant Host Controller
State : Stopped

Name : 3ware
Path : C:\Windows\system32\drivers\3ware.sys
Service Type : Kernel Driver
Description : 3ware
State : Stopped

Name : ACPI
Path : C:\Windows\system32\drivers\ACPI.sys
Service Type : Kernel Driver
Description : Microsoft ACPI Driver
State : Running

Name : AcpiDev
Path : C:\Windows\system32\drivers\AcpiDev.sys
Service Type : Kernel Driver
Description : ACPI Devices driver
State : Stopped

Name : acpiex
Path : C:\Windows\system32\Drivers\acpiex.sys
Service Type : Kernel Driver
Description : Microsoft ACPIEx Driver
State : Running

Name : acpipagr
Path : C:\Windows\system32\drivers\acpipagr.sys
Service Type : Kernel Driver
Description : ACPI Processor Aggregator Driver
State : Stopped

Name : AcpiPmi
Path : C:\Windows\system32\drivers\acpipmi.sys
Service Type : Kernel Driver
Description : ACPI Power Meter Driver
State : Stopped

Name : acpitime
Path : C:\Windows\system32\drivers\acpitime.sys
Service Type : Kernel Driver
Description : ACPI Wake Alarm Driver
State : Stopped

Name : ADP80XX
Path : C:\Windows\system32\drivers\ADP80XX.SYS
Service Type : Kernel Driver
Description : ADP80XX
State : Stopped

Name : AFD
Path : C:\Windows\system32\drivers\afd.sys
Service Type : Kernel Driver
Description : Ancillary Function Driver for Winsock
State : Running

Name : afunix
Path : C:\Windows\system32\drivers\afunix.sys
Service Type : Kernel Driver
Description : afunix
State : Running

Name : ahcache
Path : C:\Windows\system32\DRIVERS\ahcache.sys
Service Type : Kernel Driver
Description : Application Compatibility Cache
State : Running

Name : aksdf
Path : \??\C:\Windows\system32\drivers\aksdf.sys
Service Type : Kernel Driver
Description : aksdf
State : Running

Name : aksfridge
Path : \??\C:\Windows\system32\drivers\aksfridge.sys
Service Type : Kernel Driver
Description : aksfridge
State : Running

Name : AmdK8
Path : C:\Windows\system32\drivers\amdk8.sys
Service Type : Kernel Driver
Description : AMD K8 Processor Driver
State : Stopped

Name : AmdPPM
Path : C:\Windows\system32\drivers\amdppm.sys
Service Type : Kernel Driver
Description : AMD Processor Driver
State : Stopped

Name : amdsata
Path : C:\Windows\system32\drivers\amdsata.sys
Service Type : Kernel Driver
Description : amdsata
State : Stopped

Name : amdsbs
Path : C:\Windows\system32\drivers\amdsbs.sys
Service Type : Kernel Driver
Description : amdsbs
State : Stopped

Name : amdxata
Path : C:\Windows\system32\drivers\amdxata.sys
Service Type : Kernel Driver
Description : amdxata
State : Stopped

Name : AppID
Path : C:\Windows\system32\drivers\appid.sys
Service Type : Kernel Driver
Description : AppID Driver
State : Stopped

Name : applockerfltr
Path : C:\Windows\system32\drivers\applockerfltr.sys
Service Type : Kernel Driver
Description : Smartlocker Filter Driver
State : Stopped

Name : AppvStrm
Path : C:\Windows\system32\drivers\AppvStrm.sys
Service Type : File System Driver
Description : AppvStrm
State : Stopped

Name : AppvVemgr
Path : C:\Windows\system32\drivers\AppvVemgr.sys
Service Type : File System Driver
Description : AppvVemgr
State : Stopped

Name : AppvVfs
Path : C:\Windows\system32\drivers\AppvVfs.sys
Service Type : File System Driver
Description : AppvVfs
State : Stopped

Name : arcsas
Path : C:\Windows\system32\drivers\arcsas.sys
Service Type : Kernel Driver
Description : Adaptec SAS/SATA-II RAID Storport's Miniport Driver
State : Stopped

Name : AsyncMac
Path : C:\Windows\system32\drivers\asyncmac.sys
Service Type : Kernel Driver
Description : RAS Asynchronous Media Driver
State : Stopped

Name : atapi
Path : C:\Windows\system32\drivers\atapi.sys
Service Type : Kernel Driver
Description : IDE Channel
State : Running

Name : b06bdrv
Path : C:\Windows\system32\drivers\bxvbda.sys
Service Type : Kernel Driver
Description : QLogic Network Adapter VBD
State : Stopped

Name : bam
Path : C:\Windows\system32\drivers\bam.sys
Service Type : Kernel Driver
Description : Background Activity Moderator Driver
State : Running

Name : BasicDisplay
Path : C:\Windows\system32\DriverStore\FileRepository\basicdisplay.inf_amd64_5103ac179273be89\BasicDisplay.sys
Service Type : Kernel Driver
Description : BasicDisplay
State : Running

Name : BasicRender
Path : C:\Windows\system32\DriverStore\FileRepository\basicrender.inf_amd64_efdc64af60c69a6d\BasicRender.sys
Service Type : Kernel Driver
Description : BasicRender
State : Running

Name : bcmfn2
Path : C:\Windows\system32\drivers\bcmfn2.sys
Service Type : Kernel Driver
Description : bcmfn2 Service
State : Stopped

Name : Beep
Path : C:\Windows\system32\drivers\Beep.sys
Service Type : Kernel Driver
Description : Beep
State : Stopped

Name : bfadfcoei
Path : C:\Windows\system32\drivers\bfadfcoei.sys
Service Type : Kernel Driver
Description : bfadfcoei
State : Stopped

Name : bfadi
Path : C:\Windows\system32\drivers\bfadi.sys
Service Type : Kernel Driver
Description : bfadi
State : Stopped

Name : bindflt
Path : C:\Windows\system32\drivers\bindflt.sys
Service Type : File System Driver
Description : Windows Bind Filter Driver
State : Stopped

Name : bowser
Path : C:\Windows\system32\DRIVERS\bowser.sys
Service Type : File System Driver
Description : Browser
State : Running

Name : BthEnum
Path : C:\Windows\system32\drivers\BthEnum.sys
Service Type : Kernel Driver
Description : Bluetooth Enumerator Service
State : Stopped

Name : BthLEEnum
Path : C:\Windows\system32\drivers\Microsoft.Bluetooth.Legacy.LEEnumerator.sys
Service Type : Kernel Driver
Description : Bluetooth Low Energy Driver
State : Stopped

Name : BthMini
Path : C:\Windows\system32\drivers\BTHMINI.sys
Service Type : Kernel Driver
Description : Bluetooth Radio Driver
State : Stopped

Name : BTHPORT
Path : C:\Windows\system32\drivers\BTHport.sys
Service Type : Kernel Driver
Description : Bluetooth Port Driver
State : Stopped

Name : BTHUSB
Path : C:\Windows\system32\drivers\BTHUSB.sys
Service Type : Kernel Driver
Description : Bluetooth Radio USB Driver
State : Stopped

Name : bttflt
Path : C:\Windows\system32\drivers\bttflt.sys
Service Type : Kernel Driver
Description : Microsoft Hyper-V VHDPMEM BTT Filter
State : Stopped

Name : buttonconverter
Path : C:\Windows\system32\drivers\buttonconverter.sys
Service Type : Kernel Driver
Description : Service for Portable Device Control devices
State : Stopped

Name : bxfcoe
Path : C:\Windows\system32\drivers\bxfcoe.sys
Service Type : Kernel Driver
Description : QLogic FCoE Offload driver
State : Stopped

Name : bxois
Path : C:\Windows\system32\drivers\bxois.sys
Service Type : Kernel Driver
Description : QLogic Offload iSCSI Driver
State : Stopped

Name : CapImg
Path : C:\Windows\system32\drivers\capimg.sys
Service Type : Kernel Driver
Description : HID driver for CapImg touch screen
State : Stopped

Name : cdfs
Path : C:\Windows\system32\DRIVERS\cdfs.sys
Service Type : File System Driver
Description : CD/DVD File System Reader
State : Stopped

Name : cdrom
Path : C:\Windows\system32\drivers\cdrom.sys
Service Type : Kernel Driver
Description : CD-ROM Driver
State : Running

Name : cht4iscsi
Path : C:\Windows\system32\drivers\cht4sx64.sys
Service Type : Kernel Driver
Description : cht4iscsi
State : Stopped

Name : cht4vbd
Path : C:\Windows\system32\drivers\cht4vx64.sys
Service Type : Kernel Driver
Description : Chelsio Virtual Bus Driver
State : Stopped

Name : CldFlt
Path : C:\Windows\system32\drivers\cldflt.sys
Service Type : File System Driver
Description : Windows Cloud Files Filter Driver
State : Running

Name : CLFS
Path : C:\Windows\system32\drivers\CLFS.sys
Service Type : Kernel Driver
Description : Common Log (CLFS)
State : Running

Name : CmBatt
Path : C:\Windows\system32\drivers\CmBatt.sys
Service Type : Kernel Driver
Description : Microsoft ACPI Control Method Battery Driver
State : Running

Name : CNG
Path : C:\Windows\system32\Drivers\cng.sys
Service Type : Kernel Driver
Description : CNG
State : Running

Name : cnghwassist
Path : C:\Windows\system32\DRIVERS\cnghwassist.sys
Service Type : Kernel Driver
Description : CNG Hardware Assist algorithm provider
State : Stopped

Name : CompositeBus
Path : C:\Windows\system32\DriverStore\FileRepository\compositebus.inf_amd64_e4d35af746093dc3\CompositeBus.sys
Service Type : Kernel Driver
Description : Composite Bus Enumerator Driver
State : Running

Name : condrv
Path : C:\Windows\system32\drivers\condrv.sys
Service Type : Kernel Driver
Description : Console Driver
State : Running

Name : CSC
Path : C:\Windows\system32\drivers\csc.sys
Service Type : Kernel Driver
Description : Offline Files Driver
State : Stopped

Name : dam
Path : C:\Windows\system32\drivers\dam.sys
Service Type : Kernel Driver
Description : Desktop Activity Moderator Driver
State : Stopped

Name : Dfsc
Path : C:\Windows\system32\Drivers\dfsc.sys
Service Type : File System Driver
Description : DFS Namespace Client Driver
State : Running

Name : Disk
Path : C:\Windows\system32\drivers\disk.sys
Service Type : Kernel Driver
Description : Disk Driver
State : Running

Name : dmvsc
Path : C:\Windows\system32\drivers\dmvsc.sys
Service Type : Kernel Driver
Description : dmvsc
State : Stopped

Name : drmkaud
Path : C:\Windows\system32\drivers\drmkaud.sys
Service Type : Kernel Driver
Description : Microsoft Trusted Audio Drivers
State : Stopped

Name : DXGKrnl
Path : C:\Windows\system32\drivers\dxgkrnl.sys
Service Type : Kernel Driver
Description : LDDM Graphics Subsystem
State : Running

Name : ebdrv
Path : C:\Windows\system32\drivers\evbda.sys
Service Type : Kernel Driver
Description : QLogic 10 Gigabit Ethernet Adapter VBD
State : Stopped

Name : EhStorClass
Path : C:\Windows\system32\drivers\EhStorClass.sys
Service Type : Kernel Driver
Description : Enhanced Storage Filter Driver
State : Running

Name : EhStorTcgDrv
Path : C:\Windows\system32\drivers\EhStorTcgDrv.sys
Service Type : Kernel Driver
Description : Microsoft driver for storage devices supporting IEEE 1667 and TCG protocols
State : Stopped

Name : elxfcoe
Path : C:\Windows\system32\drivers\elxfcoe.sys
Service Type : Kernel Driver
Description : elxfcoe
State : Stopped

Name : elxstor
Path : C:\Windows\system32\drivers\elxstor.sys
Service Type : Kernel Driver
Description : elxstor
State : Stopped

Name : ErrDev
Path : C:\Windows\system32\drivers\errdev.sys
Service Type : Kernel Driver
Description : Microsoft Hardware Error Device Driver
State : Stopped

Name : exfat
Path : C:\Windows\system32\drivers\exfat.sys
Service Type : File System Driver
Description : exFAT File System Driver
State : Stopped

Name : fastfat
Path : C:\Windows\system32\drivers\fastfat.sys
Service Type : File System Driver
Description : FAT12/16/32 File System Driver
State : Running

Name : fcvsc
Path : C:\Windows\system32\drivers\fcvsc.sys
Service Type : Kernel Driver
Description : fcvsc
State : Stopped

Name : fdc
Path : C:\Windows\system32\drivers\fdc.sys
Service Type : Kernel Driver
Description : Floppy Disk Controller Driver
State : Stopped

Name : FileCrypt
Path : C:\Windows\system32\drivers\filecrypt.sys
Service Type : File System Driver
Description : FileCrypt
State : Running

Name : FileInfo
Path : C:\Windows\system32\drivers\fileinfo.sys
Service Type : File System Driver
Description : File Information FS MiniFilter
State : Stopped

Name : Filetrace
Path : C:\Windows\system32\drivers\filetrace.sys
Service Type : File System Driver
Description : Filetrace
State : Stopped

Name : flpydisk
Path : C:\Windows\system32\drivers\flpydisk.sys
Service Type : Kernel Driver
Description : Floppy Disk Driver
State : Stopped

Name : FltMgr
Path : C:\Windows\system32\drivers\fltmgr.sys
Service Type : File System Driver
Description : FltMgr
State : Running

Name : FsDepends
Path : C:\Windows\system32\drivers\FsDepends.sys
Service Type : File System Driver
Description : File System Dependency Minifilter
State : Stopped

Name : gencounter
Path : C:\Windows\system32\drivers\vmgencounter.sys
Service Type : Kernel Driver
Description : Microsoft Hyper-V Generation Counter
State : Running

Name : genericusbfn
Path : C:\Windows\system32\drivers\genericusbfn.sys
Service Type : Kernel Driver
Description : Generic USB Function Class
State : Stopped

Name : GPIOClx0101
Path : C:\Windows\system32\Drivers\msgpioclx.sys
Service Type : Kernel Driver
Description : Microsoft GPIO Class Extension Driver
State : Stopped

Name : hardlock
Path : \??\C:\Windows\system32\drivers\hardlock.sys
Service Type : Kernel Driver
Description : hardlock
State : Running

Name : HDAudBus
Path : C:\Windows\system32\drivers\HDAudBus.sys
Service Type : Kernel Driver
Description : Microsoft UAA Bus Driver for High Definition Audio
State : Stopped

Name : HidBatt
Path : C:\Windows\system32\drivers\HidBatt.sys
Service Type : Kernel Driver
Description : HID UPS Battery Driver
State : Stopped

Name : hidinterrupt
Path : C:\Windows\system32\drivers\hidinterrupt.sys
Service Type : Kernel Driver
Description : Common Driver for HID Buttons implemented with interrupts
State : Stopped

Name : HidUsb
Path : C:\Windows\system32\drivers\hidusb.sys
Service Type : Kernel Driver
Description : Microsoft HID Class Driver
State : Running

Name : HpSAMD
Path : C:\Windows\system32\drivers\HpSAMD.sys
Service Type : Kernel Driver
Description : HpSAMD
State : Stopped

Name : HTTP
Path : C:\Windows\system32\drivers\HTTP.sys
Service Type : Kernel Driver
Description : HTTP Service
State : Running

Name : hvcrash
Path : C:\Windows\system32\drivers\hvcrash.sys
Service Type : Kernel Driver
Description : hvcrash
State : Stopped

Name : hvservice
Path : C:\Windows\system32\drivers\hvservice.sys
Service Type : Kernel Driver
Description : Hypervisor/Virtual Machine Support Driver
State : Stopped

Name : HwNClx0101
Path : C:\Windows\system32\Drivers\mshwnclx.sys
Service Type : Kernel Driver
Description : Microsoft Hardware Notifications Class Extension Driver
State : Stopped

Name : hwpolicy
Path : C:\Windows\system32\drivers\hwpolicy.sys
Service Type : Kernel Driver
Description : Hardware Policy Driver
State : Stopped

Name : hyperkbd
Path : C:\Windows\system32\drivers\hyperkbd.sys
Service Type : Kernel Driver
Description : hyperkbd
State : Stopped

Name : HyperVideo
Path : C:\Windows\system32\drivers\HyperVideo.sys
Service Type : Kernel Driver
Description : HyperVideo
State : Stopped

Name : i8042prt
Path : C:\Windows\system32\drivers\i8042prt.sys
Service Type : Kernel Driver
Description : PS/2 Keyboard and Mouse Port Driver
State : Running

Name : iaLPSSi_GPIO
Path : C:\Windows\system32\drivers\iaLPSSi_GPIO.sys
Service Type : Kernel Driver
Description : Intel(R) Serial IO GPIO Controller Driver
State : Stopped

Name : iaLPSSi_I2C
Path : C:\Windows\system32\drivers\iaLPSSi_I2C.sys
Service Type : Kernel Driver
Description : Intel(R) Serial IO I2C Controller Driver
State : Stopped

Name : iaStorAVC
Path : C:\Windows\system32\drivers\iaStorAVC.sys
Service Type : Kernel Driver
Description : Intel Chipset SATA RAID Controller
State : Stopped

Name : iaStorV
Path : C:\Windows\system32\drivers\iaStorV.sys
Service Type : Kernel Driver
Description : Intel RAID Controller Windows 7
State : Stopped

Name : ibbus
Path : C:\Windows\system32\drivers\ibbus.sys
Service Type : Kernel Driver
Description : Mellanox InfiniBand Bus/AL (Filter Driver)
State : Stopped

Name : IndirectKmd
Path : C:\Windows\system32\drivers\IndirectKmd.sys
Service Type : Kernel Driver
Description : Indirect Displays Kernel-Mode Driver
State : Stopped

Name : intelide
Path : C:\Windows\system32\drivers\intelide.sys
Service Type : Kernel Driver
Description : intelide
State : Running

Name : intelpep
Path : C:\Windows\system32\drivers\intelpep.sys
Service Type : Kernel Driver
Description : Intel(R) Power Engine Plug-in Driver
State : Running

Name : intelppm
Path : C:\Windows\system32\drivers\intelppm.sys
Service Type : Kernel Driver
Description : Intel Processor Driver
State : Running

Name : IpFilterDriver
Path : C:\Windows\system32\DRIVERS\ipfltdrv.sys
Service Type : Kernel Driver
Description : IP Traffic Filter Driver
State : Stopped

Name : IPMIDRV
Path : C:\Windows\system32\drivers\IPMIDrv.sys
Service Type : Kernel Driver
Description : IPMIDRV
State : Stopped

Name : IPNAT
Path : C:\Windows\system32\drivers\ipnat.sys
Service Type : Kernel Driver
Description : IP Network Address Translator
State : Stopped

Name : IPsecGW
Path : C:\Windows\system32\drivers\ipsecgw.sys
Service Type : Kernel Driver
Description : Windows IPsec Gateway Driver
State : Stopped

Name : IPT
Path : C:\Windows\system32\drivers\ipt.sys
Service Type : Kernel Driver
Description : IPT
State : Stopped

Name : isapnp
Path : C:\Windows\system32\drivers\isapnp.sys
Service Type : Kernel Driver
Description : isapnp
State : Stopped

Name : iScsiPrt
Path : C:\Windows\system32\drivers\msiscsi.sys
Service Type : Kernel Driver
Description : iScsiPort Driver
State : Stopped

Name : ItSas35i
Path : C:\Windows\system32\drivers\ItSas35i.sys
Service Type : Kernel Driver
Description : ItSas35i
State : Stopped

Name : kbdclass
Path : C:\Windows\system32\drivers\kbdclass.sys
Service Type : Kernel Driver
Description : Keyboard Class Driver
State : Running

Name : kbdhid
Path : C:\Windows\system32\drivers\kbdhid.sys
Service Type : Kernel Driver
Description : Keyboard HID Driver
State : Stopped

Name : kdnic
Path : C:\Windows\system32\drivers\kdnic.sys
Service Type : Kernel Driver
Description : Microsoft Kernel Debug Network Miniport (NDIS 6.20)
State : Running

Name : klbackupdisk.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\klbackupdisk.sys
Service Type : Kernel Driver
Description : Kaspersky Lab klbackupdisk.KES-21-15
State : Running

Name : klbackupflt.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\klbackupflt.sys
Service Type : File System Driver
Description : Kaspersky Lab klbackupflt.KES-21-15
State : Running

Name : klelam
Path : C:\Windows\system32\DRIVERS\klelam.sys
Service Type : Kernel Driver
Description : klelam
State : Stopped

Name : klflt.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\klflt.sys
Service Type : Kernel Driver
Description : Kaspersky Lab Kernel DLL.KES-21-15
State : Running

Name : klfltdev.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\klfltdev.sys
Service Type : Kernel Driver
Description : Kaspersky Lab KLFltDev.KES-21-15
State : Running

Name : klgse.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\klgse.sys
Service Type : File System Driver
Description : Kaspersky Lab Security Extender Driver.KES-21-15
State : Running

Name : klhk.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\klhk.sys
Service Type : Kernel Driver
Description : Kaspersky Lab service driver.KES-21-15
State : Running

Name : klids.KES-21-15
Path : \??\C:\ProgramData\Kaspersky Lab\KES.21.15\Bases\klids.sys
Service Type : Kernel Driver
Description : klids.KES-21-15
State : Running

Name : KLIF.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\klif.sys
Service Type : File System Driver
Description : Kaspersky Lab Driver.KES-21-15
State : Running

Name : klim6
Path : C:\Windows\system32\DRIVERS\klim6.sys
Service Type : Kernel Driver
Description : Kaspersky Anti-Virus NDIS 6 Filter
State : Running

Name : klpd.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\klpd.sys
Service Type : File System Driver
Description : Kaspersky Lab format recognizer driver.KES-21-15
State : Running

Name : klpnpflt.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\klpnpflt.sys
Service Type : Kernel Driver
Description : Kaspersky Lab klpnpflt.KES-21-15
State : Running

Name : klupd_KES-21-15_arkmon
Path : C:\Windows\system32\Drivers\klupd_KES-21-15_arkmon.sys
Service Type : Kernel Driver
Description : klupd_KES-21-15_arkmon
State : Running

Name : klupd_KES-21-15_klark
Path : C:\Windows\system32\Drivers\klupd_KES-21-15_klark.sys
Service Type : Kernel Driver
Description : klupd_KES-21-15_klark
State : Running

Name : klupd_KES-21-15_klbg
Path : C:\Windows\system32\Drivers\klupd_KES-21-15_klbg.sys
Service Type : Kernel Driver
Description : klupd_KES-21-15_klbg
State : Running

Name : klupd_KES-21-15_mark
Path : C:\Windows\system32\Drivers\klupd_KES-21-15_mark.sys
Service Type : Kernel Driver
Description : klupd_KES-21-15_mark
State : Running

Name : klwfp
Path : C:\Windows\system32\DRIVERS\klwfp.sys
Service Type : Kernel Driver
Description : klwfp
State : Running

Name : klwtp.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\klwtp.sys
Service Type : Kernel Driver
Description : klwtp.KES-21-15
State : Running

Name : kneps.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\kneps.sys
Service Type : Kernel Driver
Description : kneps.KES-21-15
State : Running

Name : KSecDD
Path : C:\Windows\system32\Drivers\ksecdd.sys
Service Type : Kernel Driver
Description : KSecDD
State : Running

Name : KSecPkg
Path : C:\Windows\system32\Drivers\ksecpkg.sys
Service Type : Kernel Driver
Description : KSecPkg
State : Running

Name : ksthunk
Path : C:\Windows\system32\drivers\ksthunk.sys
Service Type : Kernel Driver
Description : Kernel Streaming Thunks
State : Stopped

Name : lltdio
Path : C:\Windows\system32\drivers\lltdio.sys
Service Type : Kernel Driver
Description : Link-Layer Topology Discovery Mapper I/O Driver
State : Running

Name : LSI_SAS
Path : C:\Windows\system32\drivers\lsi_sas.sys
Service Type : Kernel Driver
Description : LSI_SAS
State : Running

Name : LSI_SAS2i
Path : C:\Windows\system32\drivers\lsi_sas2i.sys
Service Type : Kernel Driver
Description : LSI_SAS2i
State : Stopped

Name : LSI_SAS3i
Path : C:\Windows\system32\drivers\lsi_sas3i.sys
Service Type : Kernel Driver
Description : LSI_SAS3i
State : Stopped

Name : LSI_SSS
Path : C:\Windows\system32\drivers\lsi_sss.sys
Service Type : Kernel Driver
Description : LSI_SSS
State : Stopped

Name : luafv
Path : C:\Windows\system32\drivers\luafv.sys
Service Type : File System Driver
Description : UAC File Virtualization
State : Running

Name : mausbhost
Path : C:\Windows\system32\drivers\mausbhost.sys
Service Type : Kernel Driver
Description : MA-USB Host Controller Driver
State : Stopped

Name : mausbip
Path : C:\Windows\system32\drivers\mausbip.sys
Service Type : Kernel Driver
Description : MA-USB IP Filter Driver
State : Stopped

Name : megasas
Path : C:\Windows\system32\drivers\megasas.sys
Service Type : Kernel Driver
Description : megasas
State : Stopped

Name : megasas2i
Path : C:\Windows\system32\drivers\MegaSas2i.sys
Service Type : Kernel Driver
Description : megasas2i
State : Stopped

Name : megasas35i
Path : C:\Windows\system32\drivers\megasas35i.sys
Service Type : Kernel Driver
Description : megasas35i
State : Stopped

Name : megasr
Path : C:\Windows\system32\drivers\megasr.sys
Service Type : Kernel Driver
Description : megasr
State : Stopped

Name : Microsoft_Bluetooth_AvrcpTransport
Path : C:\Windows\system32\drivers\Microsoft.Bluetooth.AvrcpTransport.sys
Service Type : Kernel Driver
Description : Microsoft Bluetooth Avrcp Transport Driver
State : Stopped

Name : mlx4_bus
Path : C:\Windows\system32\drivers\mlx4_bus.sys
Service Type : Kernel Driver
Description : Mellanox ConnectX Bus Enumerator
State : Stopped

Name : MMCSS
Path : C:\Windows\system32\drivers\mmcss.sys
Service Type : Kernel Driver
Description : Multimedia Class Scheduler
State : Stopped

Name : Modem
Path : C:\Windows\system32\drivers\modem.sys
Service Type : Kernel Driver
Description : Modem
State : Stopped

Name : monitor
Path : C:\Windows\system32\drivers\monitor.sys
Service Type : Kernel Driver
Description : Microsoft Monitor Class Function Driver Service
State : Running

Name : mouclass
Path : C:\Windows\system32\drivers\mouclass.sys
Service Type : Kernel Driver
Description : Mouse Class Driver
State : Running

Name : mouhid
Path : C:\Windows\system32\drivers\mouhid.sys
Service Type : Kernel Driver
Description : Mouse HID Driver
State : Running

Name : mountmgr
Path : C:\Windows\system32\drivers\mountmgr.sys
Service Type : Kernel Driver
Description : Mount Point Manager
State : Running

Name : mpsdrv
Path : C:\Windows\system32\drivers\mpsdrv.sys
Service Type : Kernel Driver
Description : Windows Defender Firewall Authorization Driver
State : Running

Name : MQAC
Path : C:\Windows\system32\drivers\mqac.sys
Service Type : Kernel Driver
Description : Message Queuing Access Control
State : Running

Name : mrxsmb
Path : C:\Windows\system32\DRIVERS\mrxsmb.sys
Service Type : File System Driver
Description : SMB MiniRedirector Wrapper and Engine
State : Running

Name : mrxsmb20
Path : C:\Windows\system32\DRIVERS\mrxsmb20.sys
Service Type : File System Driver
Description : SMB 2.0 MiniRedirector
State : Running

Name : MsBridge
Path : C:\Windows\system32\drivers\bridge.sys
Service Type : Kernel Driver
Description : Microsoft MAC Bridge
State : Stopped

Name : Msfs
Path : C:\Windows\system32\drivers\Msfs.sys
Service Type : File System Driver
Description : Msfs
State : Running

Name : msgpiowin32
Path : C:\Windows\system32\drivers\msgpiowin32.sys
Service Type : Kernel Driver
Description : Common Driver for Buttons, DockMode and Laptop/Slate Indicator
State : Stopped

Name : mshidkmdf
Path : C:\Windows\system32\drivers\mshidkmdf.sys
Service Type : Kernel Driver
Description : Pass-through HID to KMDF Filter Driver
State : Stopped

Name : mshidumdf
Path : C:\Windows\system32\drivers\mshidumdf.sys
Service Type : Kernel Driver
Description : Pass-through HID to UMDF Driver
State : Stopped

Name : msisadrv
Path : C:\Windows\system32\drivers\msisadrv.sys
Service Type : Kernel Driver
Description : msisadrv
State : Running

Name : MsixPackagingToolMonitor
Path : C:\Windows\system32\drivers\MsixPackagingToolMonitor.sys
Service Type : File System Driver
Description : MSIX Packaging Tool monitor mini-filter driver
State : Stopped

Name : MSKSSRV
Path : C:\Windows\system32\drivers\MSKSSRV.sys
Service Type : Kernel Driver
Description : Microsoft Streaming Service Proxy
State : Stopped

Name : MsLbfoProvider
Path : C:\Windows\system32\drivers\MsLbfoProvider.sys
Service Type : Kernel Driver
Description : Microsoft Load Balancing/Failover Provider
State : Stopped

Name : MsLldp
Path : C:\Windows\system32\drivers\mslldp.sys
Service Type : Kernel Driver
Description : Microsoft Link-Layer Discovery Protocol
State : Running

Name : MSPCLOCK
Path : C:\Windows\system32\drivers\MSPCLOCK.sys
Service Type : Kernel Driver
Description : Microsoft Streaming Clock Proxy
State : Stopped

Name : MSPQM
Path : C:\Windows\system32\drivers\MSPQM.sys
Service Type : Kernel Driver
Description : Microsoft Streaming Quality Manager Proxy
State : Stopped

Name : MsRPC
Path : C:\Windows\system32\drivers\MsRPC.sys
Service Type : Kernel Driver
Description : MsRPC
State : Stopped

Name : MsSecCore
Path : C:\Windows\system32\drivers\msseccore.sys
Service Type : Kernel Driver
Description : Microsoft Security Core Boot Driver
State : Running

Name : MsSecFlt
Path : C:\Windows\system32\drivers\mssecflt.sys
Service Type : Kernel Driver
Description : Microsoft Security Events Component Minifilter
State : Stopped

Name : MsSecWfp
Path : C:\Windows\system32\drivers\mssecwfp.sys
Service Type : Kernel Driver
Description : Microsoft Security WFP Callout Driver
State : Stopped

Name : mssmbios
Path : C:\Windows\system32\drivers\mssmbios.sys
Service Type : Kernel Driver
Description : Microsoft System Management BIOS Driver
State : Running

Name : MSTEE
Path : C:\Windows\system32\drivers\MSTEE.sys
Service Type : Kernel Driver
Description : Microsoft Streaming Tee/Sink-to-Sink Converter
State : Stopped

Name : MTConfig
Path : C:\Windows\system32\drivers\MTConfig.sys
Service Type : Kernel Driver
Description : Microsoft Input Configuration Driver
State : Stopped

Name : Mup
Path : C:\Windows\system32\Drivers\mup.sys
Service Type : File System Driver
Description : Mup
State : Running

Name : mvumis
Path : C:\Windows\system32\drivers\mvumis.sys
Service Type : Kernel Driver
Description : mvumis
State : Stopped

Name : ndfltr
Path : C:\Windows\system32\drivers\ndfltr.sys
Service Type : Kernel Driver
Description : NetworkDirect Service
State : Stopped

Name : NDIS
Path : C:\Windows\system32\drivers\ndis.sys
Service Type : Kernel Driver
Description : NDIS System Driver
State : Running

Name : NdisCap
Path : C:\Windows\system32\drivers\ndiscap.sys
Service Type : Kernel Driver
Description : Microsoft NDIS Capture
State : Stopped

Name : NdisImPlatform
Path : C:\Windows\system32\drivers\NdisImPlatform.sys
Service Type : Kernel Driver
Description : Microsoft Network Adapter Multiplexor Protocol
State : Stopped

Name : NdisTapi
Path : C:\Windows\system32\DRIVERS\ndistapi.sys
Service Type : Kernel Driver
Description : Remote Access NDIS TAPI Driver
State : Running

Name : Ndisuio
Path : C:\Windows\system32\drivers\ndisuio.sys
Service Type : Kernel Driver
Description : NDIS Usermode I/O Protocol
State : Stopped

Name : NdisVirtualBus
Path : C:\Windows\system32\drivers\NdisVirtualBus.sys
Service Type : Kernel Driver
Description : Microsoft Virtual Network Adapter Enumerator
State : Running

Name : NdisWan
Path : C:\Windows\system32\drivers\ndiswan.sys
Service Type : Kernel Driver
Description : Remote Access NDIS WAN Driver
State : Running

Name : ndiswanlegacy
Path : C:\Windows\system32\DRIVERS\ndiswan.sys
Service Type : Kernel Driver
Description : Remote Access LEGACY NDIS WAN Driver
State : Stopped

Name : ndproxy
Path : C:\Windows\system32\DRIVERS\NDProxy.sys
Service Type : Kernel Driver
Description : NDIS Proxy Driver
State : Running

Name : NetAdapterCx
Path : C:\Windows\system32\drivers\NetAdapterCx.sys
Service Type : Kernel Driver
Description : Network Adapter Wdf Class Extension Library
State : Stopped

Name : NetBIOS
Path : C:\Windows\system32\drivers\netbios.sys
Service Type : File System Driver
Description : NetBIOS Interface
State : Running

Name : NetBT
Path : C:\Windows\system32\DRIVERS\netbt.sys
Service Type : Kernel Driver
Description : NetBT
State : Running

Name : netvsc
Path : C:\Windows\system32\drivers\netvsc.sys
Service Type : Kernel Driver
Description : netvsc
State : Stopped

Name : npcap
Path : C:\Windows\system32\DRIVERS\npcap.sys
Service Type : Kernel Driver
Description : Npcap Packet Driver (NPCAP)
State : Running

Name : NPF
Path : C:\Windows\system32\drivers\npf.sys
Service Type : Kernel Driver
Description : NetGroup Packet Filter Driver
State : Running

Name : Npfs
Path : C:\Windows\system32\drivers\Npfs.sys
Service Type : File System Driver
Description : Npfs
State : Running

Name : npsvctrig
Path : C:\Windows\system32\drivers\npsvctrig.sys
Service Type : Kernel Driver
Description : Named pipe service trigger provider
State : Running

Name : nsiproxy
Path : C:\Windows\system32\drivers\nsiproxy.sys
Service Type : Kernel Driver
Description : NSI Proxy Service Driver
State : Running

Name : Ntfs
Path : C:\Windows\system32\drivers\Ntfs.sys
Service Type : File System Driver
Description : Ntfs
State : Running

Name : Null
Path : C:\Windows\system32\drivers\Null.sys
Service Type : Kernel Driver
Description : Null
State : Running

Name : nvdimm
Path : C:\Windows\system32\drivers\nvdimm.sys
Service Type : Kernel Driver
Description : Microsoft NVDIMM device driver
State : Stopped

Name : nvraid
Path : C:\Windows\system32\drivers\nvraid.sys
Service Type : Kernel Driver
Description : nvraid
State : Stopped

Name : nvstor
Path : C:\Windows\system32\drivers\nvstor.sys
Service Type : Kernel Driver
Description : nvstor
State : Stopped

Name : Parport
Path : C:\Windows\system32\drivers\parport.sys
Service Type : Kernel Driver
Description : Parallel port driver
State : Stopped

Name : partmgr
Path : C:\Windows\system32\drivers\partmgr.sys
Service Type : Kernel Driver
Description : Partition driver
State : Running

Name : pci
Path : C:\Windows\system32\drivers\pci.sys
Service Type : Kernel Driver
Description : PCI Bus Driver
State : Running

Name : pciide
Path : C:\Windows\system32\drivers\pciide.sys
Service Type : Kernel Driver
Description : pciide
State : Stopped

Name : pcmcia
Path : C:\Windows\system32\drivers\pcmcia.sys
Service Type : Kernel Driver
Description : pcmcia
State : Stopped

Name : pcw
Path : C:\Windows\system32\drivers\pcw.sys
Service Type : Kernel Driver
Description : Performance Counters for Windows Driver
State : Running

Name : pdc
Path : C:\Windows\system32\drivers\pdc.sys
Service Type : Kernel Driver
Description : pdc
State : Running

Name : PEAUTH
Path : C:\Windows\system32\drivers\peauth.sys
Service Type : Kernel Driver
Description : PEAUTH
State : Running

Name : percsas2i
Path : C:\Windows\system32\drivers\percsas2i.sys
Service Type : Kernel Driver
Description : percsas2i
State : Stopped

Name : percsas3i
Path : C:\Windows\system32\drivers\percsas3i.sys
Service Type : Kernel Driver
Description : percsas3i
State : Stopped

Name : PktMon
Path : C:\Windows\system32\drivers\PktMon.sys
Service Type : Kernel Driver
Description : Packet Monitor Driver
State : Stopped

Name : pmem
Path : C:\Windows\system32\drivers\pmem.sys
Service Type : Kernel Driver
Description : Microsoft persistent memory disk driver
State : Stopped

Name : PNPMEM
Path : C:\Windows\system32\drivers\pnpmem.sys
Service Type : Kernel Driver
Description : Microsoft Memory Module Driver
State : Stopped

Name : PptpMiniport
Path : C:\Windows\system32\drivers\raspptp.sys
Service Type : Kernel Driver
Description : WAN Miniport (PPTP)
State : Running

Name : Processor
Path : C:\Windows\system32\drivers\processr.sys
Service Type : Kernel Driver
Description : Processor Driver
State : Stopped

Name : Psched
Path : C:\Windows\system32\drivers\pacer.sys
Service Type : Kernel Driver
Description : QoS Packet Scheduler
State : Running

Name : qebdrv
Path : C:\Windows\system32\drivers\qevbda.sys
Service Type : Kernel Driver
Description : QLogic FastLinQ Ethernet VBD
State : Stopped

Name : qefcoe
Path : C:\Windows\system32\drivers\qefcoe.sys
Service Type : Kernel Driver
Description : QLogic FCoE driver
State : Stopped

Name : qeois
Path : C:\Windows\system32\drivers\qeois.sys
Service Type : Kernel Driver
Description : QLogic 40G iSCSI Driver
State : Stopped

Name : ql2300i
Path : C:\Windows\system32\drivers\ql2300i.sys
Service Type : Kernel Driver
Description : QLogic Fibre Channel STOR Miniport Inbox Driver (wx64)
State : Stopped

Name : ql40xx2i
Path : C:\Windows\system32\drivers\ql40xx2i.sys
Service Type : Kernel Driver
Description : QLogic iSCSI Miniport Inbox Driver
State : Stopped

Name : qlfcoei
Path : C:\Windows\system32\drivers\qlfcoei.sys
Service Type : Kernel Driver
Description : QLogic [FCoE] STOR Miniport Inbox Driver (wx64)
State : Stopped

Name : QWAVEdrv
Path : C:\Windows\system32\drivers\qwavedrv.sys
Service Type : Kernel Driver
Description : QWAVE driver
State : Stopped

Name : Ramdisk
Path : C:\Windows\system32\DRIVERS\ramdisk.sys
Service Type : Kernel Driver
Description : Windows RAM Disk Driver
State : Stopped

Name : RasAcd
Path : C:\Windows\system32\DRIVERS\rasacd.sys
Service Type : Kernel Driver
Description : Remote Access Auto Connection Driver
State : Stopped

Name : RasAgileVpn
Path : C:\Windows\system32\drivers\AgileVpn.sys
Service Type : Kernel Driver
Description : WAN Miniport (IKEv2)
State : Running

Name : RasGre
Path : C:\Windows\system32\drivers\rasgre.sys
Service Type : Kernel Driver
Description : WAN Miniport (GRE)
State : Running

Name : Rasl2tp
Path : C:\Windows\system32\drivers\rasl2tp.sys
Service Type : Kernel Driver
Description : WAN Miniport (L2TP)
State : Running

Name : RasPppoe
Path : C:\Windows\system32\DRIVERS\raspppoe.sys
Service Type : Kernel Driver
Description : Remote Access PPPOE Driver
State : Running

Name : RasSstp
Path : C:\Windows\system32\drivers\rassstp.sys
Service Type : Kernel Driver
Description : WAN Miniport (SSTP)
State : Running

Name : rdbss
Path : C:\Windows\system32\DRIVERS\rdbss.sys
Service Type : File System Driver
Description : Redirected Buffering Sub System
State : Running

Name : rdpbus
Path : C:\Windows\system32\drivers\rdpbus.sys
Service Type : Kernel Driver
Description : Remote Desktop Device Redirector Bus Driver
State : Running

Name : RDPDR
Path : C:\Windows\system32\drivers\rdpdr.sys
Service Type : Kernel Driver
Description : Remote Desktop Device Redirector Driver
State : Running

Name : RdpVideoMiniport
Path : C:\Windows\system32\drivers\rdpvideominiport.sys
Service Type : Kernel Driver
Description : Remote Desktop Video Miniport Driver
State : Running

Name : ReFS
Path : C:\Windows\system32\drivers\ReFS.sys
Service Type : File System Driver
Description : ReFS
State : Stopped

Name : ReFSv1
Path : C:\Windows\system32\drivers\ReFSv1.sys
Service Type : File System Driver
Description : ReFSv1
State : Stopped

Name : RFCOMM
Path : C:\Windows\system32\drivers\rfcomm.sys
Service Type : Kernel Driver
Description : Bluetooth Device (RFCOMM Protocol TDI)
State : Stopped

Name : rhproxy
Path : C:\Windows\system32\drivers\rhproxy.sys
Service Type : Kernel Driver
Description : Resource Hub proxy driver
State : Stopped

Name : rspndr
Path : C:\Windows\system32\drivers\rspndr.sys
Service Type : Kernel Driver
Description : Link-Layer Topology Discovery Responder
State : Running

Name : s3cap
Path : C:\Windows\system32\drivers\vms3cap.sys
Service Type : Kernel Driver
Description : s3cap
State : Stopped

Name : sacdrv
Path : C:\Windows\system32\DRIVERS\sacdrv.sys
Service Type : Kernel Driver
Description : sacdrv
State : Stopped

Name : sbp2port
Path : C:\Windows\system32\drivers\sbp2port.sys
Service Type : Kernel Driver
Description : SBP-2 Transport/Protocol Bus Driver
State : Stopped

Name : scfilter
Path : C:\Windows\system32\DRIVERS\scfilter.sys
Service Type : Kernel Driver
Description : Smart card PnP Class Filter Driver
State : Stopped

Name : scmbus
Path : C:\Windows\system32\drivers\scmbus.sys
Service Type : Kernel Driver
Description : Microsoft Storage Class Memory Bus Driver
State : Stopped

Name : sdbus
Path : C:\Windows\system32\drivers\sdbus.sys
Service Type : Kernel Driver
Description : sdbus
State : Stopped

Name : SDFRd
Path : C:\Windows\system32\drivers\SDFRd.sys
Service Type : Kernel Driver
Description : SDF Reflector
State : Stopped

Name : sdstor
Path : C:\Windows\system32\drivers\sdstor.sys
Service Type : Kernel Driver
Description : SD Storage Port Driver
State : Stopped

Name : SerCx
Path : C:\Windows\system32\drivers\SerCx.sys
Service Type : Kernel Driver
Description : Serial UART Support Library
State : Stopped

Name : SerCx2
Path : C:\Windows\system32\drivers\SerCx2.sys
Service Type : Kernel Driver
Description : Serial UART Support Library
State : Stopped

Name : Serenum
Path : C:\Windows\system32\drivers\serenum.sys
Service Type : Kernel Driver
Description : Serenum Filter Driver
State : Stopped

Name : Serial
Path : C:\Windows\system32\drivers\serial.sys
Service Type : Kernel Driver
Description : Serial port driver
State : Stopped

Name : sermouse
Path : C:\Windows\system32\drivers\sermouse.sys
Service Type : Kernel Driver
Description : Serial Mouse Driver
State : Stopped

Name : sfloppy
Path : C:\Windows\system32\drivers\sfloppy.sys
Service Type : Kernel Driver
Description : High-Capacity Floppy Disk Drive
State : Stopped

Name : SgrmAgent
Path : C:\Windows\system32\drivers\SgrmAgent.sys
Service Type : Kernel Driver
Description : System Guard Runtime Monitor Agent
State : Running

Name : SiSRaid2
Path : C:\Windows\system32\drivers\SiSRaid2.sys
Service Type : Kernel Driver
Description : SiSRaid2
State : Stopped

Name : SiSRaid4
Path : C:\Windows\system32\drivers\sisraid4.sys
Service Type : Kernel Driver
Description : SiSRaid4
State : Stopped

Name : SmartSAMD
Path : C:\Windows\system32\drivers\SmartSAMD.sys
Service Type : Kernel Driver
Description : SmartSAMD
State : Stopped

Name : smbdirect
Path : C:\Windows\system32\DRIVERS\smbdirect.sys
Service Type : File System Driver
Description : smbdirect
State : Stopped

Name : spaceport
Path : C:\Windows\system32\drivers\spaceport.sys
Service Type : Kernel Driver
Description : Storage Spaces Driver
State : Running

Name : SpbCx
Path : C:\Windows\system32\drivers\SpbCx.sys
Service Type : Kernel Driver
Description : Simple Peripheral Bus Support Library
State : Stopped

Name : srv2
Path : C:\Windows\system32\DRIVERS\srv2.sys
Service Type : File System Driver
Description : Server SMB 2.xxx Driver
State : Running

Name : srvnet
Path : C:\Windows\system32\DRIVERS\srvnet.sys
Service Type : File System Driver
Description : srvnet
State : Running

Name : stexstor
Path : C:\Windows\system32\drivers\stexstor.sys
Service Type : Kernel Driver
Description : stexstor
State : Stopped

Name : storahci
Path : C:\Windows\system32\drivers\storahci.sys
Service Type : Kernel Driver
Description : Microsoft Standard SATA AHCI Driver
State : Running

Name : storflt
Path : C:\Windows\system32\drivers\vmstorfl.sys
Service Type : Kernel Driver
Description : Microsoft Hyper-V Storage Accelerator
State : Stopped

Name : stornvme
Path : C:\Windows\system32\drivers\stornvme.sys
Service Type : Kernel Driver
Description : Microsoft Standard NVM Express Driver
State : Stopped

Name : storqosflt
Path : C:\Windows\system32\drivers\storqosflt.sys
Service Type : File System Driver
Description : Storage QoS Filter Driver
State : Running

Name : storufs
Path : C:\Windows\system32\drivers\storufs.sys
Service Type : Kernel Driver
Description : Microsoft Universal Flash Storage (UFS) Driver
State : Stopped

Name : storvsc
Path : C:\Windows\system32\drivers\storvsc.sys
Service Type : Kernel Driver
Description : storvsc
State : Stopped

Name : swenum
Path : C:\Windows\system32\DriverStore\FileRepository\swenum.inf_amd64_31f554b660026323\swenum.sys
Service Type : Kernel Driver
Description : Software Bus Driver
State : Running

Name : Synth3dVsc
Path : C:\Windows\system32\drivers\Synth3dVsc.sys
Service Type : Kernel Driver
Description : Synth3dVsc
State : Stopped

Name : Tcpip
Path : C:\Windows\system32\drivers\tcpip.sys
Service Type : Kernel Driver
Description : TCP/IP Protocol Driver
State : Running

Name : Tcpip6
Path : C:\Windows\system32\drivers\tcpip.sys
Service Type : Kernel Driver
Description : @todo.dll,-100;Microsoft IPv6 Protocol Driver
State : Stopped

Name : tcpipreg
Path : C:\Windows\system32\drivers\tcpipreg.sys
Service Type : Kernel Driver
Description : TCP/IP Registry Compatibility
State : Running

Name : tdx
Path : C:\Windows\system32\DRIVERS\tdx.sys
Service Type : Kernel Driver
Description : NetIO Legacy TDI Support Driver
State : Running

Name : terminpt
Path : C:\Windows\system32\drivers\terminpt.sys
Service Type : Kernel Driver
Description : Microsoft Remote Desktop Input Driver
State : Running

Name : TPM
Path : C:\Windows\system32\drivers\tpm.sys
Service Type : Kernel Driver
Description : TPM
State : Stopped

Name : TsUsbFlt
Path : C:\Windows\system32\drivers\tsusbflt.sys
Service Type : Kernel Driver
Description : Remote Desktop USB Hub Class Filter Driver
State : Stopped

Name : TsUsbGD
Path : C:\Windows\system32\drivers\TsUsbGD.sys
Service Type : Kernel Driver
Description : Remote Desktop Generic USB Device
State : Stopped

Name : tsusbhub
Path : C:\Windows\system32\drivers\tsusbhub.sys
Service Type : Kernel Driver
Description : Remote Desktop USB Hub
State : Stopped

Name : tunnel
Path : C:\Windows\system32\drivers\tunnel.sys
Service Type : Kernel Driver
Description : Microsoft Tunnel Miniport Adapter Driver
State : Stopped

Name : UASPStor
Path : C:\Windows\system32\drivers\uaspstor.sys
Service Type : Kernel Driver
Description : USB Attached SCSI (UAS) Driver
State : Stopped

Name : UcmCx0101
Path : C:\Windows\system32\Drivers\UcmCx.sys
Service Type : Kernel Driver
Description : USB Connector Manager KMDF Class Extension
State : Stopped

Name : UcmTcpciCx0101
Path : C:\Windows\system32\Drivers\UcmTcpciCx.sys
Service Type : Kernel Driver
Description : UCM-TCPCI KMDF Class Extension
State : Stopped

Name : UcmUcsi
Path : C:\Windows\system32\drivers\UcmUcsi.sys
Service Type : Kernel Driver
Description : USB Connector Manager UCSI Client
State : Stopped

Name : UcmUcsiAcpiClient
Path : C:\Windows\system32\drivers\UcmUcsiAcpiClient.sys
Service Type : Kernel Driver
Description : UCM-UCSI ACPI Client
State : Stopped

Name : UcmUcsiCx0101
Path : C:\Windows\system32\Drivers\UcmUcsiCx.sys
Service Type : Kernel Driver
Description : UCM-UCSI KMDF Class Extension
State : Stopped

Name : Ucx01000
Path : C:\Windows\system32\drivers\ucx01000.sys
Service Type : Kernel Driver
Description : USB Host Support Library
State : Running

Name : UdeCx
Path : C:\Windows\system32\drivers\udecx.sys
Service Type : Kernel Driver
Description : USB Device Emulation Support Library
State : Stopped

Name : udfs
Path : C:\Windows\system32\DRIVERS\udfs.sys
Service Type : File System Driver
Description : udfs
State : Stopped

Name : UEFI
Path : C:\Windows\system32\drivers\UEFI.sys
Service Type : Kernel Driver
Description : Microsoft UEFI Driver
State : Stopped

Name : UevAgentDriver
Path : C:\Windows\system32\drivers\UevAgentDriver.sys
Service Type : File System Driver
Description : UevAgentDriver
State : Stopped

Name : Ufx01000
Path : C:\Windows\system32\drivers\ufx01000.sys
Service Type : Kernel Driver
Description : USB Function Class Extension
State : Stopped

Name : UfxChipidea
Path : C:\Windows\system32\drivers\UfxChipidea.sys
Service Type : Kernel Driver
Description : USB Chipidea Controller
State : Stopped

Name : ufxsynopsys
Path : C:\Windows\system32\drivers\ufxsynopsys.sys
Service Type : Kernel Driver
Description : USB Synopsys Controller
State : Stopped

Name : umbus
Path : C:\Windows\system32\drivers\umbus.sys
Service Type : Kernel Driver
Description : UMBus Enumerator Driver
State : Running

Name : UmPass
Path : C:\Windows\system32\drivers\umpass.sys
Service Type : Kernel Driver
Description : Microsoft UMPass Driver
State : Stopped

Name : UrsChipidea
Path : C:\Windows\system32\drivers\urschipidea.sys
Service Type : Kernel Driver
Description : Chipidea USB Role-Switch Driver
State : Stopped

Name : UrsCx01000
Path : C:\Windows\system32\drivers\urscx01000.sys
Service Type : Kernel Driver
Description : USB Role-Switch Support Library
State : Stopped

Name : UrsSynopsys
Path : C:\Windows\system32\drivers\urssynopsys.sys
Service Type : Kernel Driver
Description : Synopsys USB Role-Switch Driver
State : Stopped

Name : usbccgp
Path : C:\Windows\system32\drivers\usbccgp.sys
Service Type : Kernel Driver
Description : Microsoft USB Generic Parent Driver
State : Running

Name : usbehci
Path : C:\Windows\system32\drivers\usbehci.sys
Service Type : Kernel Driver
Description : Microsoft USB 2.0 Enhanced Host Controller Miniport Driver
State : Stopped

Name : usbhub
Path : C:\Windows\system32\drivers\usbhub.sys
Service Type : Kernel Driver
Description : Microsoft USB Standard Hub Driver
State : Stopped

Name : USBHUB3
Path : C:\Windows\system32\drivers\UsbHub3.sys
Service Type : Kernel Driver
Description : SuperSpeed Hub
State : Running

Name : usbohci
Path : C:\Windows\system32\drivers\usbohci.sys
Service Type : Kernel Driver
Description : Microsoft USB Open Host Controller Miniport Driver
State : Stopped

Name : usbprint
Path : C:\Windows\system32\drivers\usbprint.sys
Service Type : Kernel Driver
Description : Microsoft USB PRINTER Class
State : Stopped

Name : usbser
Path : C:\Windows\system32\drivers\usbser.sys
Service Type : Kernel Driver
Description : Microsoft USB Serial Driver
State : Stopped

Name : USBSTOR
Path : C:\Windows\system32\drivers\USBSTOR.SYS
Service Type : Kernel Driver
Description : USB Mass Storage Driver
State : Stopped

Name : usbuhci
Path : C:\Windows\system32\drivers\usbuhci.sys
Service Type : Kernel Driver
Description : Microsoft USB Universal Host Controller Miniport Driver
State : Stopped

Name : USBXHCI
Path : C:\Windows\system32\drivers\USBXHCI.SYS
Service Type : Kernel Driver
Description : USB xHCI Compliant Host Controller
State : Running

Name : vdrvroot
Path : C:\Windows\system32\drivers\vdrvroot.sys
Service Type : Kernel Driver
Description : Microsoft Virtual Drive Enumerator
State : Running

Name : VerifierExt
Path : C:\Windows\system32\drivers\VerifierExt.sys
Service Type : Kernel Driver
Description : Driver Verifier Extension
State : Stopped

Name : vhdmp
Path : C:\Windows\system32\drivers\vhdmp.sys
Service Type : Kernel Driver
Description : vhdmp
State : Stopped

Name : vhf
Path : C:\Windows\system32\drivers\vhf.sys
Service Type : Kernel Driver
Description : Virtual HID Framework (VHF) Driver
State : Stopped

Name : vm3dmp
Path : C:\Windows\system32\DRIVERS\vm3dmp.sys
Service Type : Kernel Driver
Description : vm3dmp
State : Running

Name : vm3dmp-debug
Path : C:\Windows\system32\DRIVERS\vm3dmp-debug.sys
Service Type : Kernel Driver
Description : vm3dmp-debug
State : Stopped

Name : vm3dmp-stats
Path : C:\Windows\system32\DRIVERS\vm3dmp-stats.sys
Service Type : Kernel Driver
Description : vm3dmp-stats
State : Stopped

Name : vm3dmp_loader
Path : C:\Windows\system32\DRIVERS\vm3dmp_loader.sys
Service Type : Kernel Driver
Description : vm3dmp_loader
State : Running

Name : vmbus
Path : C:\Windows\system32\drivers\vmbus.sys
Service Type : Kernel Driver
Description : Virtual Machine Bus
State : Stopped

Name : VMBusHID
Path : C:\Windows\system32\drivers\VMBusHID.sys
Service Type : Kernel Driver
Description : VMBusHID
State : Stopped

Name : vmci
Path : C:\Windows\system32\drivers\vmci.sys
Service Type : Kernel Driver
Description : VMware VMCI Bus Driver
State : Running

Name : vmgid
Path : C:\Windows\system32\drivers\vmgid.sys
Service Type : Kernel Driver
Description : Microsoft Hyper-V Guest Infrastructure Driver
State : Stopped

Name : vmhgfs
Path : C:\Windows\system32\DRIVERS\vmhgfs.sys
Service Type : File System Driver
Description : VMware Host Guest Client Redirector
State : Stopped

Name : VMMemCtl
Path : C:\Windows\system32\DRIVERS\vmmemctl.sys
Service Type : Kernel Driver
Description : Memory Control Driver
State : Running

Name : vmmouse
Path : C:\Windows\system32\drivers\vmmouse.sys
Service Type : Kernel Driver
Description : VMware Pointing Device
State : Running

Name : vmrawdsk
Path : C:\Windows\system32\DRIVERS\vmrawdsk.sys
Service Type : Kernel Driver
Description : VMware Physical Disk Helper
State : Running

Name : vmusbmouse
Path : C:\Windows\system32\drivers\vmusbmouse.sys
Service Type : Kernel Driver
Description : VMware USB Pointing Device
State : Running

Name : vmxnet3ndis6
Path : C:\Windows\system32\drivers\vmxnet3.sys
Service Type : Kernel Driver
Description : vmxnet3 NDIS 6 Ethernet Adapter Driver
State : Running

Name : vnetWFP
Path : C:\Windows\system32\DRIVERS\vnetWFP.sys
Service Type : Kernel Driver
Description : vnetWFP
State : Running

Name : volmgr
Path : C:\Windows\system32\drivers\volmgr.sys
Service Type : Kernel Driver
Description : Volume Manager Driver
State : Running

Name : volmgrx
Path : C:\Windows\system32\drivers\volmgrx.sys
Service Type : Kernel Driver
Description : Dynamic Volume Manager
State : Running

Name : volsnap
Path : C:\Windows\system32\drivers\volsnap.sys
Service Type : Kernel Driver
Description : Volume Shadow Copy driver
State : Running

Name : volume
Path : C:\Windows\system32\drivers\volume.sys
Service Type : Kernel Driver
Description : Volume driver
State : Running

Name : vpci
Path : C:\Windows\system32\drivers\vpci.sys
Service Type : Kernel Driver
Description : Microsoft Hyper-V Virtual PCI Bus
State : Stopped

Name : vsepflt
Path : C:\Windows\system32\DRIVERS\vsepflt.sys
Service Type : File System Driver
Description : vsepflt
State : Running

Name : vsmraid
Path : C:\Windows\system32\drivers\vsmraid.sys
Service Type : Kernel Driver
Description : vsmraid
State : Stopped

Name : vsock
Path : C:\Windows\system32\DRIVERS\vsock.sys
Service Type : Kernel Driver
Description : vSockets Virtual Machine Communication Interface Sockets driver
State : Running

Name : VSTXRAID
Path : C:\Windows\system32\drivers\vstxraid.sys
Service Type : Kernel Driver
Description : VIA StorX Storage RAID Controller Windows Driver
State : Stopped

Name : WacomPen
Path : C:\Windows\system32\drivers\wacompen.sys
Service Type : Kernel Driver
Description : Wacom Serial Pen HID Driver
State : Stopped

Name : wanarp
Path : C:\Windows\system32\DRIVERS\wanarp.sys
Service Type : Kernel Driver
Description : Remote Access IP ARP Driver
State : Running

Name : wanarpv6
Path : C:\Windows\system32\DRIVERS\wanarp.sys
Service Type : Kernel Driver
Description : Remote Access IPv6 ARP Driver
State : Stopped

Name : wcifs
Path : C:\Windows\system32\drivers\wcifs.sys
Service Type : File System Driver
Description : Windows Container Isolation
State : Running

Name : wcnfs
Path : C:\Windows\system32\drivers\wcnfs.sys
Service Type : File System Driver
Description : Windows Container Name Virtualization
State : Stopped

Name : WdBoot
Path : C:\Windows\system32\drivers\wd\WdBoot.sys
Service Type : Kernel Driver
Description : Windows Defender Antivirus Boot Driver
State : Stopped

Name : Wdf01000
Path : C:\Windows\system32\drivers\Wdf01000.sys
Service Type : Kernel Driver
Description : Kernel Mode Driver Frameworks service
State : Running

Name : WdFilter
Path : C:\Windows\system32\drivers\wd\WdFilter.sys
Service Type : File System Driver
Description : Windows Defender Antivirus Mini-Filter Driver
State : Stopped

Name : WdmCompanionFilter
Path : C:\Windows\system32\drivers\WdmCompanionFilter.sys
Service Type : Kernel Driver
Description : WdmCompanionFilter
State : Stopped

Name : WdNisDrv
Path : C:\Windows\system32\drivers\wd\WdNisDrv.sys
Service Type : Kernel Driver
Description : Windows Defender Antivirus Network Inspection System Driver
State : Stopped

Name : WFPLWFS
Path : C:\Windows\system32\drivers\wfplwfs.sys
Service Type : Kernel Driver
Description : Microsoft Windows Filtering Platform
State : Running

Name : WIMMount
Path : C:\Windows\system32\drivers\wimmount.sys
Service Type : File System Driver
Description : WIMMount
State : Stopped

Name : WindowsTrustedRT
Path : C:\Windows\system32\drivers\WindowsTrustedRT.sys
Service Type : Kernel Driver
Description : Windows Trusted Execution Environment Class Extension
State : Running

Name : WindowsTrustedRTProxy
Path : C:\Windows\system32\drivers\WindowsTrustedRTProxy.sys
Service Type : Kernel Driver
Description : Microsoft Windows Trusted Runtime Secure Service
State : Running

Name : WinMad
Path : C:\Windows\system32\drivers\winmad.sys
Service Type : Kernel Driver
Description : WinMad Service
State : Stopped

Name : WinNat
Path : C:\Windows\system32\drivers\winnat.sys
Service Type : Kernel Driver
Description : Windows NAT Driver
State : Stopped

Name : WinQuic
Path : C:\Windows\system32\drivers\winquic.sys
Service Type : Kernel Driver
Description : WinQuic
State : Running

Name : WINUSB
Path : C:\Windows\system32\drivers\WinUSB.SYS
Service Type : Kernel Driver
Description : WinUsb Driver
State : Stopped

Name : WinVerbs
Path : C:\Windows\system32\drivers\winverbs.sys
Service Type : Kernel Driver
Description : WinVerbs Service
State : Stopped

Name : WmiAcpi
Path : C:\Windows\system32\drivers\wmiacpi.sys
Service Type : Kernel Driver
Description : Microsoft Windows Management Interface for ACPI
State : Stopped

Name : Wof
Path : C:\Windows\system32\drivers\Wof.sys
Service Type : File System Driver
Description : Windows Overlay File System Filter Driver
State : Running

Name : WpdUpFltr
Path : C:\Windows\system32\drivers\WpdUpFltr.sys
Service Type : Kernel Driver
Description : WPD Upper Class Filter Driver
State : Running

Name : ws2ifsl
Path : C:\Windows\system32\drivers\ws2ifsl.sys
Service Type : Kernel Driver
Description : Windows Socket 2.0 Non-IFS Service Provider Support Environment
State : Running

Name : WudfPf
Path : C:\Windows\system32\drivers\WudfPf.sys
Service Type : Kernel Driver
Description : User Mode Driver Frameworks Platform Driver
State : Stopped

Name : WUDFRd
Path : C:\Windows\system32\drivers\WUDFRd.sys
Service Type : Kernel Driver
Description : Windows Driver Foundation - User-mode Driver Framework Reflector
State : Running

Name : WUDFWpdFs
Path : C:\Windows\system32\DRIVERS\WUDFRd.sys
Service Type : Kernel Driver
Description : WPD File System driver
State : Running

34112 - Wireshark / Ethereal Detection (Windows)
-
Synopsis
A network protocol analyzer is installed on the remote host.
Description
Wireshark (formerly known as Ethereal) is installed on the remote Windows host.

Wireshark is a popular open source network protocol analyzer (sniffer) typically used for network troubleshooting and protocol analysis.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0746
Plugin Information
Published: 2008/09/09, Modified: 2023/02/06
Plugin Output

tcp/445/cifs


Application : Wireshark
Path : C:\Program Files\Wireshark
Version : 4.4.2
Compliance 'FAILED'
Compliance 'SKIPPED'
Compliance 'PASSED'
Compliance 'INFO', 'WARNING', 'ERROR'
Remediations
Suggested Remediations
Taking the following actions across 2 hosts would resolve 25% of the vulnerabilities on the network.
Action to take Vulns Hosts
Security Updates for Microsoft Office Products (December 2025): Microsoft has released the following updates to address these issues: - KB5002812 - KB5002818 - KB5002819 545 1
Security Updates for Microsoft Word Products (December 2025): Microsoft has released KB5002806 to address this issue. 81 1
Security Updates for Outlook (July 2025): Microsoft has released KB5002747 to address this issue. 48 1
Install KB5002406 45 1
Security Updates for Microsoft .NET Framework (January 2025): Microsoft has released security updates for Microsoft .NET Framework. 38 1
Install KB4484217 29 1
Install KB5002253 25 1
Security Update for Microsoft .NET Core (October 2025): Update .NET Core, remove vulnerable packages and refer to vendor advisory. 24 2
Install KB5002427 23 1
Install KB5002820 20 1
Install KB5071544 20 2
Security Updates for Microsoft PowerPoint Products (October 2025): Microsoft has released KB5002790 to address this issue. 15 1
Install KB5002790 14 1
Install KB5002806 12 1
VMware Tools 11.x < 12.5.4 / 13.x < 13.0.5 Multiple Vulnerabilities (VMSA-2025-0015): Upgrade to VMware Tools version 12.5.4, 13.0.5 or later. 10 2
Install KB5002683 8 1
Install KB3178702 8 1
Wireshark 4.2.x < 4.2.12 / 4.4.x < 4.4.7 DoS: Upgrade to Wireshark version 4.2.12, 4.4.7 or later. 7 1
Security Updates for Microsoft Excel Products (December 2025): Microsoft has released KB5002820 to address this issue. 6 1
Security Updates for Microsoft Publisher Products (September 2024): Microsoft has released KB5002566 to address this issue. 6 1
Install KB5002426 4 1
Install MS18-01 3 1
Install KB5002221 3 1
RARLAB WinRAR < 7.13 Directory Traversal (CVE-2025-8088): Upgrade to RARLAB WinRAR version 7.13 or later. 3 1
Install KB5002566 2 1
Install KB3213551 2 1
Install KB3191932 2 1
JQuery 1.2 < 3.5.0 Multiple XSS: Upgrade to JQuery version 3.5.0 or later. 2 1
MS13-002: Vulnerabilities in Microsoft XML Core Services Could Allow Remote Code Execution (2756145): Microsoft has released a set of patches for Windows XP, 2003, Vista, 2008, 7, and 2008 R2, 8, 2012, Office 2003, 2007, Word Viewer, Office Compatibility Pack, Expression Web Service, Expression Web 2, SharePoint Server 2007 and Groove Server 2007. 2 1
Microsoft ASP.NET Core Security Feature Bypass (October 2025): Update .NET Core to version 8.0.21, 9.0.10, 10.0.0-rc.2.25502.107 or later. 2 2
Install KB5002622 1 1
Install KB3115419 1 1
Install KB3115279 1 1
Security Updates for Microsoft OneNote Products (April 2025): Microsoft has released KB5002622 to address this issue. 1 1
Curl Use-After-Free < 7.87 (CVE-2022-43552): Upgrade Curl to version 7.87.0 or later 1 1
Notepad++ < 8.8.2 Privilege Escalation (CVE-2025-49144): Upgrade to Notepad++ 8.8.2 or later. 1 1
© 2026 Tenable™, Inc. All rights reserved.