Nessus Report

Report generated by Tenable Nessus™

Server 1

Sat, 10 Jan 2026 05:42:13 India Standard Time

TABLE OF CONTENTS
Vulnerabilities by HostExpand All | Collapse All
172.17.100.31
2
16
12
1
1778
Critical
High
Medium
Low
Info
Scan Information
Start time: Sat Jan 10 02:05:16 2026
End time: Sat Jan 10 04:18:37 2026
Host Information
Netbios Name: TECHE_LIVE_DB
IP: 172.17.100.31
MAC Address: D4:F5:EF:60:4D:20 D4:F5:EF:60:4D:23
OS: Microsoft Windows Server 2019 Datacenter Build 17763
Vulnerabilities

249130 - KB5063877: Windows 10 version 1809 / Windows Server 2019 Security Update (August 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5063877. It is, therefore, affected by multiple vulnerabilities

- Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
(CVE-2025-53766)

- Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. (CVE-2025-49751)

- Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. (CVE-2025-49743)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5063877
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.017
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/08/12, Modified: 2025/10/29
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5063877

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.7009
Should be : 10.0.17763.7671
270378 - KB5066586: Windows 10 version 1809 / Windows Server 2019 Security Update (October 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5066586. It is, therefore, affected by multiple vulnerabilities

- tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka Predictor heap-buffer-overflow. (CVE-2016-9535)

- In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image. (CVE-2025-47827)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5066586
Risk Factor
High
CVSS v3.0 Base Score
9.9 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
9.2
EPSS Score
0.0824
CVSS v2.0 Base Score
7.5 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
6.2 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2016-9535
CVE CVE-2025-24052
CVE CVE-2025-24990
CVE CVE-2025-25004
CVE CVE-2025-47827
CVE CVE-2025-48813
CVE CVE-2025-49708
CVE CVE-2025-50152
CVE CVE-2025-50175
CVE CVE-2025-53150
CVE CVE-2025-53768
CVE CVE-2025-54957
CVE CVE-2025-55325
CVE CVE-2025-55326
CVE CVE-2025-55328
CVE CVE-2025-55332
CVE CVE-2025-55333
CVE CVE-2025-55335
CVE CVE-2025-55336
CVE CVE-2025-55338
CVE CVE-2025-55678
CVE CVE-2025-55679
CVE CVE-2025-55680
CVE CVE-2025-55681
CVE CVE-2025-55683
CVE CVE-2025-55687
CVE CVE-2025-55692
CVE CVE-2025-55695
CVE CVE-2025-55696
CVE CVE-2025-55699
CVE CVE-2025-55700
CVE CVE-2025-55701
CVE CVE-2025-58714
CVE CVE-2025-58715
CVE CVE-2025-58716
CVE CVE-2025-58717
CVE CVE-2025-58718
CVE CVE-2025-58719
CVE CVE-2025-58720
CVE CVE-2025-58722
CVE CVE-2025-58725
CVE CVE-2025-58726
CVE CVE-2025-58728
CVE CVE-2025-58729
CVE CVE-2025-58730
CVE CVE-2025-58732
CVE CVE-2025-58733
CVE CVE-2025-58734
CVE CVE-2025-58735
CVE CVE-2025-58736
CVE CVE-2025-58737
CVE CVE-2025-58738
CVE CVE-2025-58739
CVE CVE-2025-59184
CVE CVE-2025-59185
CVE CVE-2025-59186
CVE CVE-2025-59187
CVE CVE-2025-59188
CVE CVE-2025-59190
CVE CVE-2025-59191
CVE CVE-2025-59192
CVE CVE-2025-59193
CVE CVE-2025-59195
CVE CVE-2025-59196
CVE CVE-2025-59197
CVE CVE-2025-59198
CVE CVE-2025-59199
CVE CVE-2025-59200
CVE CVE-2025-59201
CVE CVE-2025-59202
CVE CVE-2025-59203
CVE CVE-2025-59204
CVE CVE-2025-59205
CVE CVE-2025-59207
CVE CVE-2025-59208
CVE CVE-2025-59209
CVE CVE-2025-59211
CVE CVE-2025-59214
CVE CVE-2025-59230
CVE CVE-2025-59242
CVE CVE-2025-59244
CVE CVE-2025-59253
CVE CVE-2025-59254
CVE CVE-2025-59255
CVE CVE-2025-59258
CVE CVE-2025-59259
CVE CVE-2025-59260
CVE CVE-2025-59275
CVE CVE-2025-59277
CVE CVE-2025-59278
CVE CVE-2025-59280
CVE CVE-2025-59282
CVE CVE-2025-59294
CVE CVE-2025-59295
MSKB 5066586
XREF MSFT:MS25-5066586
XREF CISA-KNOWN-EXPLOITED:2025/11/04
XREF IAVA:2025-A-0775-S
XREF IAVA:2025-A-0776-S
Plugin Information
Published: 2025/10/14, Modified: 2025/11/18
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5066586

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.7009
Should be : 10.0.17763.7919
242639 - 7-Zip < 25.00
-
Synopsis
The remote host is missing a security update.
Description
The version of 7-Zip installed on the remote host is prior to 25.00. It is, therefore, affected by multiple vulnerabilities:

- 7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. Interaction with this product is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the handling of symbolic links in ZIP files. Crafted data in a ZIP file can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of a service account. (CVE-2025-11001, CVE-2025-11002)

- An error in Z-zip's RAR5 handler's error correction for corrupted items can lead to a buffer overflow, resulting in memory corruption and denial of service.
(CVE-2025-53816)

- A Null pointer dereference in 7-Zip's implementation of the Compound handler can lead to denial of service at specific values. (CVE-2025-53817)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to 7-Zip version 25.00 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.0 (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
9.2
EPSS Score
0.0031
CVSS v2.0 Base Score
6.2 (CVSS2#AV:L/AC:H/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-11001
CVE CVE-2025-11002
CVE CVE-2025-53816
CVE CVE-2025-53817
XREF IAVA:2025-A-0540-S
Plugin Information
Published: 2025/07/23, Modified: 2025/11/20
Plugin Output

tcp/445/cifs


Path : C:\Program Files\7-Zip
Installed version : 24.9.0.0
Fixed version : 25.00
234046 - KB5055519: Windows 10 version 1809 / Windows Server 2019 Security Update (April 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5055519. It is, therefore, affected by multiple vulnerabilities

- Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network. (CVE-2025-26687)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-27481)
- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges. (CVE-2025-27740)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5055519
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.2827
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-21174
CVE CVE-2025-21191
CVE CVE-2025-21197
CVE CVE-2025-21203
CVE CVE-2025-21204
CVE CVE-2025-21205
CVE CVE-2025-21221
CVE CVE-2025-21222
CVE CVE-2025-24058
CVE CVE-2025-24060
CVE CVE-2025-24073
CVE CVE-2025-24074
CVE CVE-2025-26635
CVE CVE-2025-26637
CVE CVE-2025-26640
CVE CVE-2025-26641
CVE CVE-2025-26644
CVE CVE-2025-26647
CVE CVE-2025-26648
CVE CVE-2025-26652
CVE CVE-2025-26663
CVE CVE-2025-26664
CVE CVE-2025-26665
CVE CVE-2025-26666
CVE CVE-2025-26667
CVE CVE-2025-26668
CVE CVE-2025-26669
CVE CVE-2025-26670
CVE CVE-2025-26671
CVE CVE-2025-26672
CVE CVE-2025-26673
CVE CVE-2025-26674
CVE CVE-2025-26676
CVE CVE-2025-26678
CVE CVE-2025-26679
CVE CVE-2025-26680
CVE CVE-2025-26686
CVE CVE-2025-26687
CVE CVE-2025-26688
CVE CVE-2025-27467
CVE CVE-2025-27469
CVE CVE-2025-27470
CVE CVE-2025-27471
CVE CVE-2025-27473
CVE CVE-2025-27474
CVE CVE-2025-27476
CVE CVE-2025-27477
CVE CVE-2025-27478
CVE CVE-2025-27479
CVE CVE-2025-27480
CVE CVE-2025-27481
CVE CVE-2025-27482
CVE CVE-2025-27483
CVE CVE-2025-27484
CVE CVE-2025-27485
CVE CVE-2025-27486
CVE CVE-2025-27487
CVE CVE-2025-27491
CVE CVE-2025-27727
CVE CVE-2025-27730
CVE CVE-2025-27731
CVE CVE-2025-27732
CVE CVE-2025-27733
CVE CVE-2025-27735
CVE CVE-2025-27736
CVE CVE-2025-27737
CVE CVE-2025-27738
CVE CVE-2025-27739
CVE CVE-2025-27740
CVE CVE-2025-27741
CVE CVE-2025-27742
CVE CVE-2025-29809
CVE CVE-2025-29810
CVE CVE-2025-29824
MSKB 5055519
XREF CISA-KNOWN-EXPLOITED:2025/04/29
XREF MSFT:MS25-5055519
XREF IAVA:2025-A-0256-S
XREF IAVA:2025-A-0255-S
XREF CWE:20
XREF CWE:59
XREF CWE:121
XREF CWE:122
XREF CWE:125
XREF CWE:126
XREF CWE:200
XREF CWE:284
XREF CWE:345
XREF CWE:367
XREF CWE:400
XREF CWE:410
XREF CWE:415
XREF CWE:416
XREF CWE:591
XREF CWE:667
XREF CWE:693
XREF CWE:787
XREF CWE:822
XREF CWE:908
XREF CWE:922
XREF CWE:1039
XREF CWE:1390
Plugin Information
Published: 2025/04/08, Modified: 2025/09/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5055519

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.7009
Should be : 10.0.17763.7131
235845 - KB5058392: Windows 10 version 1809 / Windows Server 2019 Security Update (May 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5058392. It is, therefore, affected by multiple vulnerabilities

- Heap-based buffer overflow in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. (CVE-2025-29967)

- Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. (CVE-2025-29830, CVE-2025-29958, CVE-2025-29959)

- Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. (CVE-2025-29832, CVE-2025-29835, CVE-2025-29836, CVE-2025-29960, CVE-2025-29961)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5058392
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
8.1
EPSS Score
0.2127
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/05/13, Modified: 2025/10/29
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5058392

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.7009
Should be : 10.0.17763.7309
238080 - KB5060531: Windows 10 version 1809 / Windows Server 2019 Security Update (June 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5060531. It is, therefore, affected by multiple vulnerabilities

- Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. (CVE-2025-33066)

- Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.
(CVE-2025-33073)

- Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
(CVE-2025-32712)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5060531
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.7
EPSS Score
0.5119
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-3052
CVE CVE-2025-24065
CVE CVE-2025-24068
CVE CVE-2025-24069
CVE CVE-2025-32712
CVE CVE-2025-32713
CVE CVE-2025-32714
CVE CVE-2025-32715
CVE CVE-2025-32716
CVE CVE-2025-32718
CVE CVE-2025-32719
CVE CVE-2025-32720
CVE CVE-2025-32721
CVE CVE-2025-32722
CVE CVE-2025-32724
CVE CVE-2025-32725
CVE CVE-2025-33050
CVE CVE-2025-33052
CVE CVE-2025-33053
CVE CVE-2025-33055
CVE CVE-2025-33056
CVE CVE-2025-33057
CVE CVE-2025-33058
CVE CVE-2025-33059
CVE CVE-2025-33060
CVE CVE-2025-33061
CVE CVE-2025-33062
CVE CVE-2025-33063
CVE CVE-2025-33064
CVE CVE-2025-33065
CVE CVE-2025-33066
CVE CVE-2025-33067
CVE CVE-2025-33068
CVE CVE-2025-33070
CVE CVE-2025-33071
CVE CVE-2025-33073
CVE CVE-2025-33075
CVE CVE-2025-47160
MSKB 5060531
XREF MSFT:MS25-5060531
XREF IAVA:2025-A-0428-S
XREF IAVA:2025-A-0417-S
XREF CISA-KNOWN-EXPLOITED:2025/11/10
XREF CISA-KNOWN-EXPLOITED:2025/07/01
XREF CWE:59
XREF CWE:73
XREF CWE:122
XREF CWE:125
XREF CWE:126
XREF CWE:190
XREF CWE:269
XREF CWE:284
XREF CWE:400
XREF CWE:416
XREF CWE:476
XREF CWE:693
XREF CWE:908
Exploitable With
Core Impact (true) Metasploit (true)
Plugin Information
Published: 2025/06/10, Modified: 2025/10/21
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5060531

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.7009
Should be : 10.0.17763.7434
241548 - KB5062557: Windows 10 version 1809 / Windows Server 2019 Security Update (July 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5062557. It is, therefore, affected by multiple vulnerabilities

- Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally.
(CVE-2025-49659)

- Improper link resolution before file access ('link following') in Windows Update Service allows an authorized attacker to elevate privileges locally. (CVE-2025-48799)

- Improper link resolution before file access ('link following') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally. (CVE-2025-48820)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5062557
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.1
EPSS Score
0.0055
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-36350
CVE CVE-2025-36357
CVE CVE-2025-47159
CVE CVE-2025-47971
CVE CVE-2025-47972
CVE CVE-2025-47973
CVE CVE-2025-47975
CVE CVE-2025-47976
CVE CVE-2025-47980
CVE CVE-2025-47981
CVE CVE-2025-47982
CVE CVE-2025-47984
CVE CVE-2025-47985
CVE CVE-2025-47986
CVE CVE-2025-47987
CVE CVE-2025-47991
CVE CVE-2025-47996
CVE CVE-2025-47998
CVE CVE-2025-47999
CVE CVE-2025-48000
CVE CVE-2025-48001
CVE CVE-2025-48003
CVE CVE-2025-48799
CVE CVE-2025-48800
CVE CVE-2025-48803
CVE CVE-2025-48804
CVE CVE-2025-48805
CVE CVE-2025-48806
CVE CVE-2025-48808
CVE CVE-2025-48811
CVE CVE-2025-48814
CVE CVE-2025-48815
CVE CVE-2025-48816
CVE CVE-2025-48817
CVE CVE-2025-48818
CVE CVE-2025-48819
CVE CVE-2025-48820
CVE CVE-2025-48821
CVE CVE-2025-48822
CVE CVE-2025-48823
CVE CVE-2025-48824
CVE CVE-2025-49657
CVE CVE-2025-49658
CVE CVE-2025-49659
CVE CVE-2025-49660
CVE CVE-2025-49661
CVE CVE-2025-49663
CVE CVE-2025-49664
CVE CVE-2025-49665
CVE CVE-2025-49666
CVE CVE-2025-49667
CVE CVE-2025-49668
CVE CVE-2025-49669
CVE CVE-2025-49670
CVE CVE-2025-49671
CVE CVE-2025-49672
CVE CVE-2025-49673
CVE CVE-2025-49674
CVE CVE-2025-49675
CVE CVE-2025-49676
CVE CVE-2025-49678
CVE CVE-2025-49679
CVE CVE-2025-49680
CVE CVE-2025-49681
CVE CVE-2025-49683
CVE CVE-2025-49684
CVE CVE-2025-49685
CVE CVE-2025-49686
CVE CVE-2025-49687
CVE CVE-2025-49688
CVE CVE-2025-49689
CVE CVE-2025-49690
CVE CVE-2025-49691
CVE CVE-2025-49716
CVE CVE-2025-49721
CVE CVE-2025-49722
CVE CVE-2025-49723
CVE CVE-2025-49724
CVE CVE-2025-49725
CVE CVE-2025-49726
CVE CVE-2025-49727
CVE CVE-2025-49729
CVE CVE-2025-49730
CVE CVE-2025-49732
CVE CVE-2025-49733
CVE CVE-2025-49740
CVE CVE-2025-49742
CVE CVE-2025-49744
CVE CVE-2025-49753
CVE CVE-2025-49760
CVE CVE-2025-55230
CVE CVE-2025-55231
MSKB 5062557
XREF MSFT:MS25-5062557
XREF IAVA:2025-A-0507-S
XREF IAVA:2025-A-0506-S
XREF IAVA:2025-A-0631-S
XREF CWE:20
XREF CWE:23
XREF CWE:59
XREF CWE:73
XREF CWE:122
XREF CWE:125
XREF CWE:126
XREF CWE:190
XREF CWE:191
XREF CWE:197
XREF CWE:200
XREF CWE:284
XREF CWE:306
XREF CWE:326
XREF CWE:349
XREF CWE:353
XREF CWE:362
XREF CWE:367
XREF CWE:400
XREF CWE:415
XREF CWE:416
XREF CWE:476
XREF CWE:591
XREF CWE:693
XREF CWE:787
XREF CWE:820
XREF CWE:822
XREF CWE:843
XREF CWE:862
Plugin Information
Published: 2025/07/08, Modified: 2025/10/29
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5062557

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.7009
Should be : 10.0.17763.7558
261799 - KB5065428: Windows 10 version 1809 / Windows Server 2019 Security Update (September 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5065428. It is, therefore, affected by multiple vulnerabilities

- SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vulnerabilities could perform relay attacks and make the users subject to elevation of privilege attacks. The SMB Server already supports mechanisms for hardening against relay attacks: SMB Server signing SMB Server Extended Protection for Authentication (EPA) Microsoft is releasing this CVE to provide customers with audit capabilities to help them to assess their environment and to identify any potential device or software incompatibility issues before deploying SMB Server hardening measures that protect against relay attacks. If you have not already enabled SMB Server hardening measures, we advise customers to take the following actions to be protected from these relay attacks:
Assess your environment by utilizing the audit capabilities that we are exposing in the September 2025 security updates. See Support for Audit Events to deploy SMB Server HardeningSMB Server Signing & SMB Server EPA. Adopt appropriate SMB Server hardening measures. (CVE-2025-55234)

- Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally. (CVE-2025-49734)

- Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. (CVE-2025-53796, CVE-2025-53797, CVE-2025-53798, CVE-2025-53806)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5065428
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.1
EPSS Score
0.0073
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/09/09, Modified: 2025/10/29
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5065428

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.7009
Should be : 10.0.17763.7786
274782 - KB5068791: Windows 10 version 1809 / Windows Server 2019 Security Update (November 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5068791. It is, therefore, affected by multiple vulnerabilities

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-60724, CVE-2025-60714, CVE-2025-60715, CVE-2025-62452)

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information.
(CVE-2025-59509, CVE-2025-59513, CVE-2025-60706, CVE-2025-62208, CVE-2025-62209)

- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges.
(CVE-2025-59505, CVE-2025-59506, CVE-2025-59507, CVE-2025-59508, CVE-2025-59511, CVE-2025-59512, CVE-2025-59514, CVE-2025-59515, CVE-2025-60703, CVE-2025-60704, CVE-2025-60705, CVE-2025-60707, CVE-2025-60709, CVE-2025-60713, CVE-2025-60716, CVE-2025-60717, CVE-2025-60719, CVE-2025-60720, CVE-2025-62213, CVE-2025-62215, CVE-2025-62217)


Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5068791
Risk Factor
Critical
CVSS v3.0 Base Score
7.0 (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.0009
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/11/11, Modified: 2025/11/14
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5068791

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.7009
Should be : 10.0.17763.8024
277987 - KB5071544: Windows 10 version 1809 / Windows Server 2019 Security Update (December 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5071544. It is, therefore, affected by multiple vulnerabilities

- Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. (CVE-2025-62549)

- Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. (CVE-2025-62457)

- Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. (CVE-2025-62458)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5071544
Risk Factor
Critical
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
8.1
EPSS Score
0.0821
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/12/09, Modified: 2025/12/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5071544

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.17763.7009
Should be : 10.0.17763.8146
40435 - MS09-035: Vulnerabilities in Visual Studio Active Template Library Could Allow Remote Code Execution (969706)
-
Synopsis
Arbitrary code can be executed on the remote host through Microsoft Active Template Library.
Description
The remote Windows host contains a version of the Microsoft Active Template Library (ATL), included as part of Visual Studio or Visual C++, that is affected by multiple vulnerabilities :

- On systems with components and controls installed that were built using Visual Studio ATL, an issue in the ATL headers could allow an attacker to force VariantClear to be called on a VARIANT that has not been correctly initialized and, by supplying a corrupt stream, to execute arbitrary code. (CVE-2009-0901)

- On systems with components and controls installed that were built using Visual Studio ATL, unsafe usage of OleLoadFromStream could allow instantiation of arbitrary objects that can bypass related security policy, such as kill bits within Internet Explorer.
(CVE-2009-2493)

- On systems with components and controls installed that were built using Visual Studio ATL, an issue in the ATL headers could allow a string to be read without a terminating NULL character, which could lead to disclosure of information in memory. (CVE-2009-2495)
See Also
Solution
Microsoft has released a set of patches for Visual Studio .NET 2003, Visual Studio 2005 and 2008, as well as Visual C++ 2005 and 2008.
Risk Factor
High
VPR Score
5.9
EPSS Score
0.6425
CVSS v2.0 Base Score
7.6 (CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
BID 35828
BID 35830
BID 35832
CVE CVE-2009-0901
CVE CVE-2009-2493
CVE CVE-2009-2495
MSKB 973544
MSKB 973551
MSKB 973552
MSKB 973675
XREF MSFT:MS09-035
XREF IAVB:2009-B-0033-S
XREF CERT:456745
XREF CWE:94
XREF CWE:200
XREF CWE:264
Plugin Information
Published: 2009/07/30, Modified: 2020/08/05
Plugin Output

tcp/445/cifs



The following Visual C++ Redistributable Package has not
been patched :

Product : Visual C++ 2005 SP1 Redistributable Package
File : atl80.dll
Installed version : 8.0.50727.762
Fixed version : 8.0.50727.4053
63155 - Microsoft Windows Unquoted Service Path Enumeration
-
Synopsis
The remote Windows host has at least one service installed that uses an unquoted service path.
Description
The remote Windows host has at least one service installed that uses an unquoted service path, which contains at least one whitespace. A local attacker can gain elevated privileges by inserting an executable file in the path of the affected service.

Note that this is a generic test that will flag any application affected by the described vulnerability.
See Also
Solution
Ensure that any services that contain a space in the path enclose the path in quotes.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0078
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.4 (CVSS2#E:POC/RL:OF/RC:C)
References
BID 58591
BID 58617
BID 65873
BID 68520
CVE CVE-2013-1609
CVE CVE-2014-0759
CVE CVE-2014-5455
XREF ICSA:14-058-01
XREF EDB-ID:34037
Exploitable With
Metasploit (true)
Plugin Information
Published: 2012/12/05, Modified: 2025/05/29
Plugin Output

tcp/445/cifs


Nessus found the following service with an untrusted path :
vmrcs : C:\Program Files (x86)\vmrx\vmrc.exe
240630 - Notepad++ < 8.8.2 Privilege Escalation (CVE-2025-49144)
-
Synopsis
A text editor on the remote Windows host is affected by privilege escalation.
Description
The version of Notepad++ installed on the remote host is prior to 8.8.2. It is, therefore, affected by a privilege escalation vulnerability:

- Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.8.1 installer that allows unprivileged users to gain SYSTEM-level privileges through insecure executable search paths. An attacker could use social engineering or clickjacking to trick users into downloading both the legitimate installer and a malicious executable to the same directory (typically Downloads folder - which is known as Vulnerable directory). Upon running the installer, the attack executes automatically with SYSTEM privileges. This issue has been fixed and will be released in version 8.8.2.
(CVE-2025-49144) Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Notepad++ 8.8.2 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.3 (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
VPR Score
8.4
EPSS Score
0.0001
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-49144
XREF IAVA:2025-A-0452
Plugin Information
Published: 2025/06/26, Modified: 2025/11/10
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Notepad++
Installed version : 8.7.7.0
Fixed version : 8.8.2
242073 - RARLAB WinRAR < 7.12 Beta 1 Directory Traversal Remote Code Execution (CVE-2025-6218)
-
Synopsis
The remote Windows host has an application installed which is affected by a directory traversal remote code execution vulnerability.
Description
The remote host is running RARLAB WinRAR, an archive manager for Windows, whose reported version is prior to 7.12 Beta 1. It is, therefore, affected by a vulnerability:

- RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of file paths within archive files. A crafted file path can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27198. (CVE-2025-6218)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to RARLAB WinRAR version 7.12 Beta 1 or later.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
9.4
EPSS Score
0.0029
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.0 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2025-6218
XREF IAVA:2025-A-0227
XREF ZDI:ZDI-25-409
XREF CISA-KNOWN-EXPLOITED:2025/12/30
Plugin Information
Published: 2025/07/14, Modified: 2025/12/09
Plugin Output

tcp/445/cifs


Path : C:\Program Files\WinRAR\WinRAR.exe
Installed version : 7.1.0.0
Fixed version : 7.12 Beta 1
248462 - RARLAB WinRAR < 7.13 Directory Traversal (CVE-2025-8088)
-
Synopsis
The remote Windows host has an application installed which is affected by a directory traversal vulnerability.
Description
The remote host is running RARLAB WinRAR, an archive manager for Windows, whose reported version is prior to 7.13. It is, therefore, affected by a vulnerability:

- A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET. (CVE-2025-8088)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to RARLAB WinRAR version 7.13 or later.
Risk Factor
Critical
CVSS v4.0 Base Score
8.4 (CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
9.5
EPSS Score
0.0562
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2025-8088
XREF CISA-KNOWN-EXPLOITED:2025/09/02
XREF IAVA:2025-A-0608
Plugin Information
Published: 2025/08/11, Modified: 2025/08/21
Plugin Output

tcp/445/cifs


Path : C:\Program Files\WinRAR\WinRAR.exe
Installed version : 7.1.0.0
Fixed version : 7.13

42873 - SSL Medium Strength Cipher Suites Supported (SWEET32)
-
Synopsis
The remote service supports the use of medium strength SSL ciphers.
Description
The remote host supports the use of SSL ciphers that offer medium strength encryption. Nessus regards medium strength as any encryption that uses key lengths at least 64 bits and less than 112 bits, or else that uses the 3DES encryption suite.

Note that it is considerably easier to circumvent medium strength encryption if the attacker is on the same physical network.
See Also
Solution
Reconfigure the affected application if possible to avoid use of medium strength ciphers.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
VPR Score
6.1
EPSS Score
0.4002
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
References
Plugin Information
Published: 2009/11/23, Modified: 2025/02/12
Plugin Output

tcp/3389/msrdp


Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

214274 - Security Updates for Microsoft .NET Framework (January 2025)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is missing a security update.
Description
The Microsoft .NET Framework installation on the remote host is missing a security update. It is, therefore, affected by multiple denial of service vulnerabilities, as follows:

- A remote code execution vulnerability. An attacker can exploit this issue to cause the affected component to execute unauthorized code. (CVE-2025-21176)

Note that Nessus has relied upon on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0035
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-21176
MSKB 5049614
MSKB 5049618
MSKB 5049620
MSKB 5049622
MSKB 5049624
MSKB 5049993
MSKB 5050013
MSKB 5050180
MSKB 5050181
MSKB 5050182
MSKB 5050183
MSKB 5050184
MSKB 5050185
MSKB 5050186
MSKB 5050187
MSKB 5050188
MSKB 5050416
XREF MSFT:MS25-5049614
XREF MSFT:MS25-5049618
XREF MSFT:MS25-5049620
XREF MSFT:MS25-5049622
XREF MSFT:MS25-5049624
XREF MSFT:MS25-5049993
XREF MSFT:MS25-5050013
XREF MSFT:MS25-5050180
XREF MSFT:MS25-5050181
XREF MSFT:MS25-5050182
XREF MSFT:MS25-5050183
XREF MSFT:MS25-5050184
XREF MSFT:MS25-5050185
XREF MSFT:MS25-5050186
XREF MSFT:MS25-5050187
XREF MSFT:MS25-5050188
XREF MSFT:MS25-5050416
XREF IAVA:2025-A-0028-S
XREF CWE:126
Plugin Information
Published: 2025/01/16, Modified: 2025/04/09
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.7.2
The remote host is missing one of the following rollup KBs :

Cumulative
- 5049608

C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorlib.dll has not been patched.
Remote version : 4.7.4121.0
Should be : 4.7.4126.0

166555 - WinVerifyTrust Signature Validation CVE-2013-3900 Mitigation (EnableCertPaddingCheck)
-
Synopsis
The remote Windows host is potentially missing a mitigation for a remote code execution vulnerability.
Description
The remote system may be in a vulnerable state to CVE-2013-3900 due to a missing or misconfigured registry keys:
- HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck
- HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck An unauthenticated, remote attacker could exploit this, by sending specially crafted requests, to execute arbitrary code on an affected host.
See Also
Solution
Add and enable registry value EnableCertPaddingCheck:
- HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck

Additionally, on 64 Bit OS systems, Add and enable registry value EnableCertPaddingCheck:

- HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.0
EPSS Score
0.7941
CVSS v2.0 Base Score
7.6 (CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.6 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2013-3900
XREF CISA-KNOWN-EXPLOITED:2022/07/10
XREF IAVA:2013-A-0227
Plugin Information
Published: 2022/10/26, Modified: 2025/12/17
Plugin Output

tcp/445/cifs



Nessus detected the following potentially insecure registry key configuration:
- Software\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck is not present in the registry.
- Software\Wow6432Node\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck is not present in the registry.

11213 - HTTP TRACE / TRACK Methods Allowed
-
Synopsis
Debugging functions are enabled on the remote web server.
Description
The remote web server supports the TRACE and/or TRACK methods. TRACE and TRACK are HTTP methods that are used to debug web server connections.
See Also
Solution
Disable these HTTP methods. Refer to the plugin output for more information.
Risk Factor
Medium
CVSS v3.0 Base Score
5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
CVSS v3.0 Temporal Score
4.6 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.0
EPSS Score
0.6899
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
3.7 (CVSS2#E:U/RL:OF/RC:C)
References
BID 9506
BID 9561
BID 11604
BID 33374
BID 37995
CVE CVE-2003-1567
CVE CVE-2004-2320
CVE CVE-2010-0386
XREF CERT:288308
XREF CERT:867593
XREF CWE:16
XREF CWE:200
Plugin Information
Published: 2003/01/23, Modified: 2024/04/09
Plugin Output

tcp/8686/www


Nessus sent the following TRACE request : \n\n------------------------------ snip ------------------------------\nTRACE /Nessus965011984.html HTTP/1.1
Connection: Close
Host: TechE_Live_DB
Pragma: no-cache
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */*
Accept-Language: en
Accept-Charset: iso-8859-1,*,utf-8

------------------------------ snip ------------------------------\n\nand received the following response from the remote server :\n\n------------------------------ snip ------------------------------\nHTTP/1.1 200 OK
Connection: keep-alive
Content-Type: message/http
Content-Length: 312
Date: Fri, 09 Jan 2026 20:43:11 GMT

TRACE /Nessus965011984.html HTTP/1.1
Accept-Charset: iso-8859-1,*,utf-8
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */*
Connection: Keep-Alive
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)
Host: TechE_Live_DB
Accept-Language: en
Pragma: no-cache
------------------------------ snip ------------------------------\n
11714 - Nonexistent Page (404) Physical Path Disclosure
-
Synopsis
The remote web server is affected by an information disclosure vulnerability.
Description
The remote web server reveals the physical path of the webroot when a nonexistent page is requested.

While printing errors to the output is useful for debugging applications, this feature should be disabled on production servers.
See Also
Solution
Upgrade the web server to the latest version. Alternatively, reconfigure the web server to disable debug reporting.
Risk Factor
Medium
VPR Score
3.5
EPSS Score
0.0821
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
3.9 (CVSS2#E:POC/RL:OF/RC:C)
References
BID 3341
BID 4035
BID 4261
BID 5054
BID 8075
CVE CVE-2001-1372
CVE CVE-2002-0266
CVE CVE-2002-2008
CVE CVE-2003-0456
XREF CERT:278971
XREF EDB-ID:21276
XREF CWE:200
Plugin Information
Published: 2003/06/11, Modified: 2025/09/29
Plugin Output

tcp/8686/www


URL : http://172.17.100.31:8686/niet1352789660.cfm
Path disclosed : D:\Techexcel_DP\root\
Response snippet :
------------------------------ snip ------------------------------
<tr>

<td class="label">Message</td>

<td>Page /niet1352789660.cfm [D:\Techexcel_DP\root\niet1352789660.cfm] not found</td>

</tr>




------------------------------ snip ------------------------------

51192 - SSL Certificate Cannot Be Trusted
-
Synopsis
The SSL certificate for this service cannot be trusted.
Description
The server's X.509 certificate cannot be trusted. This situation can occur in three different ways, in which the chain of trust can be broken, as stated below :

- First, the top of the certificate chain sent by the server might not be descended from a known public certificate authority. This can occur either when the top of the chain is an unrecognized, self-signed certificate, or when intermediate certificates are missing that would connect the top of the certificate chain to a known public certificate authority.

- Second, the certificate chain may contain a certificate that is not valid at the time of the scan. This can occur either when the scan occurs before one of the certificate's 'notBefore' dates, or after one of the certificate's 'notAfter' dates.

- Third, the certificate chain may contain a signature that either didn't match the certificate's information or could not be verified. Bad signatures can be fixed by getting the certificate with the bad signature to be re-signed by its issuer. Signatures that could not be verified are the result of the certificate's issuer using a signing algorithm that Nessus either does not support or does not recognize.

If the remote host is a public host in production, any break in the chain makes it more difficult for users to verify the authenticity and identity of the web server. This could make it easier to carry out man-in-the-middle attacks against the remote host.
See Also
Solution
Purchase or generate a proper SSL certificate for this service.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
CVSS v2.0 Base Score
6.4 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N)
Plugin Information
Published: 2010/12/15, Modified: 2025/06/16
Plugin Output

tcp/3389/msrdp


The following certificate was at the top of the certificate
chain sent by the remote host, but it is signed by an unknown
certificate authority :

|-Subject : CN=TechE_Live_DB
|-Issuer : CN=TechE_Live_DB

51192 - SSL Certificate Cannot Be Trusted
-
Synopsis
The SSL certificate for this service cannot be trusted.
Description
The server's X.509 certificate cannot be trusted. This situation can occur in three different ways, in which the chain of trust can be broken, as stated below :

- First, the top of the certificate chain sent by the server might not be descended from a known public certificate authority. This can occur either when the top of the chain is an unrecognized, self-signed certificate, or when intermediate certificates are missing that would connect the top of the certificate chain to a known public certificate authority.

- Second, the certificate chain may contain a certificate that is not valid at the time of the scan. This can occur either when the scan occurs before one of the certificate's 'notBefore' dates, or after one of the certificate's 'notAfter' dates.

- Third, the certificate chain may contain a signature that either didn't match the certificate's information or could not be verified. Bad signatures can be fixed by getting the certificate with the bad signature to be re-signed by its issuer. Signatures that could not be verified are the result of the certificate's issuer using a signing algorithm that Nessus either does not support or does not recognize.

If the remote host is a public host in production, any break in the chain makes it more difficult for users to verify the authenticity and identity of the web server. This could make it easier to carry out man-in-the-middle attacks against the remote host.
See Also
Solution
Purchase or generate a proper SSL certificate for this service.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
CVSS v2.0 Base Score
6.4 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N)
Plugin Information
Published: 2010/12/15, Modified: 2025/06/16
Plugin Output

tcp/6443/www


The following certificate was at the top of the certificate
chain sent by the remote host, but it is signed by an unknown
certificate authority :

|-Subject : CN=TechE_Live_DB
|-Issuer : CN=TechE_Live_DB

57582 - SSL Self-Signed Certificate
-
Synopsis
The SSL certificate chain for this service ends in an unrecognized self-signed certificate.
Description
The X.509 certificate chain for this service is not signed by a recognized certificate authority. If the remote host is a public host in production, this nullifies the use of SSL as anyone could establish a man-in-the-middle attack against the remote host.

Note that this plugin does not check for certificate chains that end in a certificate that is not self-signed, but is signed by an unrecognized certificate authority.
Solution
Purchase or generate a proper SSL certificate for this service.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
CVSS v2.0 Base Score
6.4 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N)
Plugin Information
Published: 2012/01/17, Modified: 2022/06/14
Plugin Output

tcp/3389/msrdp


The following certificate was found at the top of the certificate
chain sent by the remote host, but is self-signed and was not
found in the list of known certificate authorities :

|-Subject : CN=TechE_Live_DB

57582 - SSL Self-Signed Certificate
-
Synopsis
The SSL certificate chain for this service ends in an unrecognized self-signed certificate.
Description
The X.509 certificate chain for this service is not signed by a recognized certificate authority. If the remote host is a public host in production, this nullifies the use of SSL as anyone could establish a man-in-the-middle attack against the remote host.

Note that this plugin does not check for certificate chains that end in a certificate that is not self-signed, but is signed by an unrecognized certificate authority.
Solution
Purchase or generate a proper SSL certificate for this service.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
CVSS v2.0 Base Score
6.4 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N)
Plugin Information
Published: 2012/01/17, Modified: 2022/06/14
Plugin Output

tcp/6443/www


The following certificate was found at the top of the certificate
chain sent by the remote host, but is self-signed and was not
found in the list of known certificate authorities :

|-Subject : CN=TechE_Live_DB

104743 - TLS Version 1.0 Protocol Detection
-
Synopsis
The remote service encrypts traffic using an older version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.0. TLS 1.0 has a number of cryptographic design flaws. Modern implementations of TLS 1.0 mitigate these problems, but newer versions of TLS like 1.2 and 1.3 are designed against these flaws and should be used whenever possible.

As of March 31, 2020, Endpoints that aren’t enabled for TLS 1.2 and higher will no longer function properly with major web browsers and major vendors.

PCI DSS v3.2 requires that TLS 1.0 be disabled entirely by June 30, 2018, except for POS POI terminals (and the SSL/TLS termination points to which they connect) that can be verified as not being susceptible to any known exploits.
See Also
Solution
Enable support for TLS 1.2 and 1.3, and disable support for TLS 1.0.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N)
CVSS v2.0 Base Score
6.1 (CVSS2#AV:N/AC:H/Au:N/C:C/I:P/A:N)
References
XREF CWE:327
Plugin Information
Published: 2017/11/22, Modified: 2023/04/19
Plugin Output

tcp/3389/msrdp

TLSv1 is enabled and the server supports at least one cipher.
157288 - TLS Version 1.1 Deprecated Protocol
-
Synopsis
The remote service encrypts traffic using an older version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.1. TLS 1.1 lacks support for current and recommended cipher suites. Ciphers that support encryption before MAC computation, and authenticated encryption modes such as GCM cannot be used with TLS 1.1

As of March 31, 2020, Endpoints that are not enabled for TLS 1.2 and higher will no longer function properly with major web browsers and major vendors.
See Also
Solution
Enable support for TLS 1.2 and/or 1.3, and disable support for TLS 1.1.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N)
CVSS v2.0 Base Score
6.1 (CVSS2#AV:N/AC:H/Au:N/C:C/I:P/A:N)
References
XREF CWE:327
Plugin Information
Published: 2022/04/04, Modified: 2024/05/14
Plugin Output

tcp/3389/msrdp

TLSv1.1 is enabled and the server supports at least one cipher.

234002 - WinRAR < 7.11 Mark of the Web Bypass (CVE-2025-31334)
-
Synopsis
The remote Windows host has an application installed which is affected by a mark of the web bypass vulnerability.
Description
The remote host is running WinRAR, an archive manager for Windows, whose reported version is prior to 7.11. It is, therefore, affected by a vulnerability:

- Issue that bypasses the 'Mark of the Web' security warning function for files when opening a symbolic link that points to an executable file exists in WinRAR versions prior to 7.11. If a symbolic link specially crafted by an attacker is opened on the affected product, arbitrary code may be executed. (CVE-2025-31334)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to WinRAR version 7.11 or later.
Risk Factor
High
CVSS v3.0 Base Score
6.8 (CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0007
CVSS v2.0 Base Score
8.5 (CVSS2#AV:N/AC:M/Au:S/C:C/I:C/A:C)
STIG Severity
II
References
CVE CVE-2025-31334
XREF IAVA:2025-A-0227
Plugin Information
Published: 2025/04/08, Modified: 2025/04/11
Plugin Output

tcp/445/cifs


Path : C:\Program Files\WinRAR\WinRAR.exe
Installed version : 7.1.0.0
Fixed version : 7.11
132101 - Windows Speculative Execution Configuration Check
-
Synopsis
The remote host has not properly mitigated a series of speculative execution vulnerabilities.
Description
The remote host has not properly mitigated a series of known speculative execution vulnerabilities. It, therefore, may be affected by :
- Branch Target Injection (BTI) (CVE-2017-5715)
- Bounds Check Bypass (BCB) (CVE-2017-5753)
- Rogue Data Cache Load (RDCL) (CVE-2017-5754)
- Rogue System Register Read (RSRE) (CVE-2018-3640)
- Speculative Store Bypass (SSB) (CVE-2018-3639)
- L1 Terminal Fault (L1TF) (CVE-2018-3615, CVE-2018-3620, CVE-2018-3646)
- Microarchitectural Data Sampling Uncacheable Memory (MDSUM) (CVE-2019-11091)
- Microarchitectural Store Buffer Data Sampling (MSBDS) (CVE-2018-12126)
- Microarchitectural Load Port Data Sampling (MLPDS) (CVE-2018-12127)
- Microarchitectural Fill Buffer Data Sampling (MFBDS) (CVE-2018-12130)
- TSX Asynchronous Abort (TAA) (CVE-2019-11135)
- Intel Branch History Injection (BHI) (CVE-2022-0001)
See Also
Solution
Apply vendor recommended settings.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
6.2 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
7.9
EPSS Score
0.9433
CVSS v2.0 Base Score
5.4 (CVSS2#AV:L/AC:M/Au:N/C:C/I:P/A:N)
CVSS v2.0 Temporal Score
4.7 (CVSS2#E:H/RL:OF/RC:C)
References
BID 102371
BID 102378
BID 104232
BID 105080
BID 108330
CVE CVE-2017-5715
CVE CVE-2017-5753
CVE CVE-2017-5754
CVE CVE-2018-3615
CVE CVE-2018-3620
CVE CVE-2018-3639
CVE CVE-2018-3646
CVE CVE-2018-12126
CVE CVE-2018-12127
CVE CVE-2018-12130
CVE CVE-2019-11135
CVE CVE-2022-0001
XREF CEA-ID:CEA-2019-0547
XREF CEA-ID:CEA-2019-0324
Exploitable With
CANVAS (true)
Plugin Information
Published: 2019/12/18, Modified: 2025/08/27
Plugin Output

tcp/445/cifs

Current Settings:
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverrideMask: Not Set
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverride: Not Set

-----------------------------------

Recommended Settings 1:
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverrideMask: 0x00000003 (3)
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverride: 0x00000048 (72)
CVEs Covered:
CVE-2017-5715, CVE-2017-5753, CVE-2017-5754, CVE-2018-3615, CVE-2018-3620,
CVE-2018-3639, CVE-2018-3646, CVE-2018-11091, CVE-2018-12126, CVE-2018-12127,
CVE-2018-12130, CVE-2019-11135
Note: Hyper-Threading enabled.

-----------------------------------

Recommended Settings 2:
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverrideMask: 0x00000003 (3)
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverride: 0x00002048 (8264)
CVEs Covered:
CVE-2017-5715, CVE-2017-5753, CVE-2017-5754, CVE-2018-3615, CVE-2018-3620,
CVE-2018-3639, CVE-2018-3646, CVE-2018-11091, CVE-2018-12126, CVE-2018-12127,
CVE-2018-12130, CVE-2019-11135
Note: Hyper-Threading disabled.

-----------------------------------

Recommended Settings 3:
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverrideMask: 0x00000003 (3)
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverride: 0x00802048 (8396872)
CVEs Covered:
CVE-2017-5715, CVE-2017-5753, CVE-2017-5754, CVE-2018-3615, CVE-2018-3620,
CVE-2018-3639, CVE-2018-3646, CVE-2018-11091, CVE-2018-12126, CVE-2018-12127,
CVE-2018-12130, CVE-2019-11135, CVE-2022-0001
Note: Hyper-Threading disabled.

-----------------------------------

Recommended Settings 4:
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverrideMask: 0x00000003 (3)
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverride: 0x00800048 (8388680)
CVEs Covered:
CVE-2017-5715, CVE-2017-5753, CVE-2017-5754, CVE-2018-3615, CVE-2018-3620,
CVE-2018-3639, CVE-2018-3646, CVE-2018-11091, CVE-2018-12126, CVE-2018-12127,
CVE-2018-12130, CVE-2019-11135, CVE-2022-0001
Note: Hyper-Threading enabled.

121479 - web.config File Information Disclosure
-
Synopsis
The remote web server hosts an application that is affected by an information disclosure vulnerability.
Description
An information disclosure vulnerability exists in the remote web server due to the disclosure of the web.config file. An unauthenticated, remote attacker can exploit this, via a simple GET request, to disclose potentially sensitive configuration information.
Solution
Ensure proper restrictions are in place, or remove the web.config file if the file is not required.
Risk Factor
Medium
CVSS v3.0 Base Score
5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
Plugin Information
Published: 2019/01/30, Modified: 2020/04/27
Plugin Output

tcp/80/www


Nessus was able to exploit the issue using the following request :

GET /web.config HTTP/1.1
Host: 172.17.100.31
Accept-Charset: iso-8859-1,utf-8;q=0.9,*;q=0.1
Accept-Language: en
Connection: Keep-Alive
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)
Pragma: no-cache
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */*




This produced the following truncated output (limited to 5 lines) :
------------------------------ snip ------------------------------
<?xml version="1.0" encoding="UTF-8"?>
<configuration>
<system.webServer>
<httpProtocol>
<customHeaders>
[...]

------------------------------ snip ------------------------------

121479 - web.config File Information Disclosure
-
Synopsis
The remote web server hosts an application that is affected by an information disclosure vulnerability.
Description
An information disclosure vulnerability exists in the remote web server due to the disclosure of the web.config file. An unauthenticated, remote attacker can exploit this, via a simple GET request, to disclose potentially sensitive configuration information.
Solution
Ensure proper restrictions are in place, or remove the web.config file if the file is not required.
Risk Factor
Medium
CVSS v3.0 Base Score
5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
Plugin Information
Published: 2019/01/30, Modified: 2020/04/27
Plugin Output

tcp/81/www


Nessus was able to exploit the issue using the following request :

GET /web.config HTTP/1.1
Host: 172.17.100.31:81
Accept-Charset: iso-8859-1,utf-8;q=0.9,*;q=0.1
Accept-Language: en
Connection: Keep-Alive
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)
Pragma: no-cache
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */*




This produced the following truncated output (limited to 5 lines) :
------------------------------ snip ------------------------------
<?xml version="1.0" encoding="UTF-8"?>
<configuration>
<system.webServer>
<httpProtocol>
<customHeaders>
[...]

------------------------------ snip ------------------------------

249179 - 7-Zip < 25.01
-
Synopsis
The remote host is missing a security update.
Description
The version of 7-Zip installed on the remote host is prior to 25.01. It is, therefore, affected by a security bypass vulnerability. The code for handling symbolic links has been changed to provide greater security when extracting files from archives. Command line switch -snld20 can be used to bypass default security checks when creating symbolic links.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to 7-Zip version 25.01 or later.
Risk Factor
Low
CVSS v3.0 Base Score
3.6 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N)
VPR Score
3.2
EPSS Score
0.0001
CVSS v2.0 Base Score
2.1 (CVSS2#AV:L/AC:L/Au:N/C:N/I:P/A:N)
STIG Severity
I
References
CVE CVE-2025-55188
XREF IAVA:2025-A-0572
Plugin Information
Published: 2025/08/13, Modified: 2025/08/15
Plugin Output

tcp/445/cifs


Path : C:\Program Files\7-Zip
Installed version : 24.9.0.0
Fixed version : 25.01
91231 - 7-Zip Installed
-
Synopsis
A compression utility is installed on the remote Windows host.
Description
7-Zip, a compressed archive manager, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0734
Plugin Information
Published: 2016/05/19, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Path : C:\Program Files\7-Zip
Version : 24.9.0.0

92413 - 7-Zip Recent Files
-
Synopsis
Nessus was able to enumerate recently accessed 7-Zip compressed files on the remote host.
Description
Nessus was able to query 7-Zip settings on the remote Windows host to find recently accessed compressed files.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

techexcel
- F:\BACKUP\FOCAPS.ZIP\ FOCAPS\
- F:\BACKUP\FOCAPS.ZIP\
46180 - Additional DNS Hostnames
-
Synopsis
Nessus has detected potential virtual hosts.
Description
Hostnames different from the current hostname have been collected by miscellaneous plugins. Nessus has generated a list of hostnames that point to the remote host. Note that these are only the alternate hostnames for vhosts discovered on a web server.

Different web servers may be hosted on name-based virtual hosts.
See Also
Solution
If you want to test them, re-scan using the special vhost syntax, such as :

www.example.com[192.0.32.10]
Risk Factor
None
Plugin Information
Published: 2010/04/29, Modified: 2022/08/15
Plugin Output

tcp/0

The following hostnames point to the remote host :
- teche_live_db

48204 - Apache HTTP Server Version
-
Synopsis
It is possible to obtain the version number of the remote Apache HTTP server.
Description
The remote host is running the Apache HTTP Server, an open source web server. It was possible to read the version number from the banner.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0030
XREF IAVT:0001-T-0530
Plugin Information
Published: 2010/07/30, Modified: 2023/08/17
Plugin Output

tcp/6443/www


URL : https://172.17.100.31:6443/
Version : unknown
Source : Server: Apache
backported : 0

130590 - Apache Tomcat Installed (Windows)
-
Synopsis
Apache Tomcat is installed on the remote Windows host.
Description
Apache Tomcat, a web server, was found on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0535
Plugin Information
Published: 2019/11/06, Modified: 2025/12/18
Plugin Output

tcp/0


Nessus detected 6 installs of Apache Tomcat:

Path : D:\Techexcel\LoadBalancing\Lucee14\tomcat\bin\Tomcat9.exe
Version : unknown
Product : Apache Tomcat

Path : D:\Techexcel\LoadBalancing\Lucee12\tomcat\bin\Tomcat9.exe
Version : unknown
Product : Apache Tomcat

Path : D:\Techexcel\LoadBalancing\Lucee11\tomcat\bin\Tomcat9.exe
Version : unknown
Product : Apache Tomcat

Path : D:\Techexcel\lucee02\tomcat\bin\Tomcat9.exe
Version : unknown
Product : Apache Tomcat

Path : D:\Techexcel\LoadBalancing\Lucee13\tomcat\bin\Tomcat9.exe
Version : unknown
Product : Apache Tomcat

Path : D:\Techexcel\lucee\tomcat\bin\Tomcat9.exe
Version : unknown
Product : Apache Tomcat
92415 - Application Compatibility Cache
-
Synopsis
Nessus was able to gather application compatibility settings on the remote host.
Description
Nessus was able to generate a report on the application compatibility cache on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

Application compatibility cache report attached.
34097 - BIOS Info (SMB)
-
Synopsis
BIOS info could be read.
Description
It is possible to get information about the BIOS via the host's SMB interface.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/08, Modified: 2024/06/11
Plugin Output

tcp/0


Version : U32
Release date : 20230720000000.000000+000
Secure boot : disabled
34096 - BIOS Info (WMI)
-
Synopsis
The BIOS info could be read.
Description
It is possible to get information about the BIOS via the host's WMI interface.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/05, Modified: 2025/12/15
Plugin Output

tcp/0


Vendor : HPE
Version : U32
Release date : 20230720000000.000000+000
UUID : 35333250-3937-4E43-5831-343830373730
Secure boot : disabled
92416 - BagMRU Folder History
-
Synopsis
Nessus was able to enumerate folders that were opened in Windows Explorer.
Description
Nessus was able to enumerate folders that were opened in Windows Explorer. Microsoft Windows maintains folder settings using a registry key known as shellbags or BagMRU. The generated folder list report contains folders local to the system, folders from past mounted network drives, and folders from mounted devices.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

BagMRU report attached.

96533 - Chrome Browser Extension Enumeration
-
Synopsis
One or more Chrome browser extensions are installed on the remote host.
Description
Nessus was able to enumerate Chrome browser extensions installed on the remote host.
See Also
Solution
Make sure that the use and configuration of these extensions comply with your organization's acceptable use and security policies.
Risk Factor
None
References
XREF IAVT:0001-T-0511
Plugin Information
Published: 2017/01/16, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


User : Administrator
|- Browser : Chrome
|- Add-on information :

Name : Google Docs Offline
Description : Edit, create, and view your documents, spreadsheets, and presentations — all without internet access.
Version : 1.93.1
Update Date : Jul. 1, 2025 at 10:19:57 GMT
Path : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.93.1_0

Name : Chrome Web Store Payments
Description : Chrome Web Store Payments
Version : 1.0.0.6
Update Date : Jul. 1, 2025 at 10:19:53 GMT
Path : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0

User : LKPAdmin
|- Browser : Chrome
|- Add-on information :

Name : Google Docs Offline
Description : Edit, create, and view your documents, spreadsheets, and presentations — all without internet access.
Version : 1.80.1
Update Date : Aug. 27, 2024 at 03:02:14 GMT
Path : C:\Users\LKPAdmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.80.1_0

Name : Chrome Web Store Payments
Description : Chrome Web Store Payments
Version : 1.0.0.6
Update Date : Aug. 27, 2024 at 03:02:14 GMT
Path : C:\Users\LKPAdmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0

User : techapp
|- Browser : Chrome
|- Add-on information :

Name : Google Docs Offline
Description : Edit, create, and view your documents, spreadsheets, and presentations — all without internet access.
Version : 1.73.0
Update Date : Jan. 30, 2024 at 05:20:01 GMT
Path : C:\Users\techapp\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.73.0_0

Name : Chrome Web Store Payments
Description : Chrome Web Store Payments
Version : 1.0.0.6
Update Date : Jan. 30, 2024 at 05:20:01 GMT
Path : C:\Users\techapp\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0

User : techexcel
|- Browser : Chrome
|- Add-on information :

Name : Google Docs Offline
Description : Edit, create, and view your documents, spreadsheets, and presentations — all without internet access.
Version : 1.99.1
Update Date : Jan. 9, 2026 at 05:15:00 GMT
Path : C:\Users\techexcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.99.1_0

Name : IE Tab
Description : Display web pages using IE within Chrome. Use Java, Silverlight, ActiveX, Sharepoint, and more.
Version : 18.12.12.1
Update Date : Jan. 9, 2026 at 05:15:00 GMT
Path : C:\Users\techexcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\hehijbfgiekmjfkfjpbkbammjbdenadd\18.12.12.1_0

Name : Chrome Web Store Payments
Description : Chrome Web Store Payments
Version : 1.0.0.6
Update Date : Jan. 9, 2026 at 05:15:00 GMT
Path : C:\Users\techexcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0

User : uatlkp
|- Browser : Chrome
|- Add-on information :

Name : Google Docs Offline
Description : Edit, create, and view your documents, spreadsheets, and presentations — all without internet access.
Version : 1.75.4
Update Date : Apr. 11, 2024 at 05:40:25 GMT
Path : C:\Users\uatlkp\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.75.4_0

Name : Chrome Web Store Payments
Description : Chrome Web Store Payments
Version : 1.0.0.6
Update Date : Apr. 11, 2024 at 05:40:25 GMT
Path : C:\Users\uatlkp\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0

45590 - Common Platform Enumeration (CPE)
-
Synopsis
It was possible to enumerate CPE names that matched on the remote system.
Description
By using information obtained from a Nessus scan, this plugin reports CPE (Common Platform Enumeration) matches for various hardware and software products found on a host.

Note that if an official CPE is not available for the product, this plugin computes the best possible CPE based on the information available from the scan.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/04/21, Modified: 2025/09/29
Plugin Output

tcp/0


The remote operating system matched the following CPE :

cpe:/o:microsoft:windows_server_2019:10.0.17763.7009:-:~~datacenter~~x64~ -> Microsoft Windows Server 2019

Following application CPE's matched on the remote system :

cpe:/a:7-zip:7-zip:24.9.0.0 -> 7-Zip -
cpe:/a:apache:http_server -> Apache Software Foundation Apache HTTP Server
cpe:/a:apache:tomcat -> Apache Software Foundation Tomcat
cpe:/a:git_for_windows_project:git_for_windows:2.47.1.0.2 -> Git for Windows Project Git for Windows
cpe:/a:google:chrome:143.0.7499.171 -> Google Chrome
cpe:/a:haxx:curl:8.9.1.0 -> Haxx Curl
cpe:/a:jquery:jquery -> jQuery
cpe:/a:microsoft:.net_framework:2.0.50727 -> Microsoft .NET Framework
cpe:/a:microsoft:.net_framework:3.0 -> Microsoft .NET Framework
cpe:/a:microsoft:.net_framework:3.0.6920.9063 -> Microsoft .NET Framework
cpe:/a:microsoft:.net_framework:3.5 -> Microsoft .NET Framework
cpe:/a:microsoft:.net_framework:4.7.2 -> Microsoft .NET Framework
cpe:/a:microsoft:.net_framework:4.7.4115.0 -> Microsoft .NET Framework
cpe:/a:microsoft:edge:143.0.3650.96 -> Microsoft Edge
cpe:/a:microsoft:ie:11.1790.17763.0 -> Microsoft Internet Explorer
cpe:/a:microsoft:internet_explorer:11.0.17763.7009 -> Microsoft Internet Explorer
cpe:/a:microsoft:internet_information_services:10.0.17763.5830 -> Microsoft Internet Information Server (IIS) -
cpe:/a:microsoft:remote_desktop_connection:10.0.17763.5830 -> Microsoft Remote Desktop Connection
cpe:/a:microsoft:sql_server_management_studio:2019.150.18390.0 -> Microsoft SQL Server Management Studio
cpe:/a:microsoft:visual_studio_code:1.106.3 -> Microsoft Visual Studio Code
cpe:/a:microsoft:visual_studio_tools_for_applications:15.0.27520
cpe:/a:nginx:nginx -> Nginx
cpe:/a:notepad-plus-plus:notepad%2b%2b:8.7.7.0 -> notepad-plus-plus Notepad++
cpe:/a:postman:postman:11.77.0 -> Postman
cpe:/a:rarlab:winrar:7.1.0.0 -> RARLAB WinRAR
cpe:/a:smartbedded:meteobridge_firmware
x-cpe:/a:hpe:smart_storage_administrator:3.40.3.0
x-cpe:/a:microsoft:azure_data_studio:1.51.1.0
x-cpe:/a:microsoft:odbc_driver_for_sql_server:17.10.6.1
x-cpe:/a:microsoft:ole_db_driver_for_sql_server:18.7.4.0
x-cpe:/a:microsoft:visual_studio_code:0.0.3
x-cpe:/a:microsoft:visual_studio_code:0.1.6
x-cpe:/a:microsoft:visual_studio_code:0.1.9
x-cpe:/a:microsoft:visual_studio_code:0.5.15
x-cpe:/a:microsoft:visual_studio_code:0.5.4
x-cpe:/a:microsoft:visual_studio_code:1.1.1
x-cpe:/a:microsoft:visual_studio_code:1.1.2
x-cpe:/a:microsoft:visual_studio_code:1.10.0
x-cpe:/a:microsoft:visual_studio_code:1.12.0
x-cpe:/a:microsoft:visual_studio_code:1.3.0
x-cpe:/a:microsoft:visual_studio_code:12.15.0
x-cpe:/a:microsoft:visual_studio_code:2.17.0
x-cpe:/a:microsoft:visual_studio_code:2025.10.2
x-cpe:/a:microsoft:visual_studio_code:2025.14.1
x-cpe:/a:microsoft:visual_studio_code:2025.16.0
x-cpe:/a:microsoft:visual_studio_code:2025.18.0
x-cpe:/a:microsoft:visual_studio_code:2025.7.0
x-cpe:/a:microsoft:visual_studio_code:2025.8.0
x-cpe:/a:microsoft:visual_studio_code:2025.8.3
x-cpe:/a:microsoft:visual_studio_code:2025.9.1
x-cpe:/a:microsoft:visual_studio_code:3.0.2
x-cpe:/a:microsoft:visual_studio_code:5.27.0
x-cpe:/a:microsoft:visual_studio_code:5.29.0
24270 - Computer Manufacturer Information (WMI)
-
Synopsis
It is possible to obtain the name of the remote computer manufacturer.
Description
By making certain WMI queries, it is possible to obtain the model of the remote computer as well as the name of its manufacturer and its serial number.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/02/02, Modified: 2025/12/15
Plugin Output

tcp/0


Computer Manufacturer : HPE
Computer Model : ProLiant DL360 Gen10
Computer SerialNumber : CNX1480770
Computer Type : Rack Mount Chassis

Computer Physical CPU's : 2
Computer Logical CPU's : 32
CPU0
Architecture : x64
Physical Cores: 8
Logical Cores : 16
CPU1
Architecture : x64
Physical Cores: 8
Logical Cores : 16

Computer Memory : 196264 MB

Form Factor: DIMM
Type : Unknown
Capacity : 65536 MB

Form Factor: DIMM
Type : Unknown
Capacity : 65536 MB

Form Factor: DIMM
Type : Unknown
Capacity : 65536 MB
171860 - Curl Installed (Windows)
-
Synopsis
Curl is installed on the remote Windows host.
Description
Curl, a command line tool for transferring data with URLs, was detected on the remote Windows host.

Please note, if the installation is located in either the Windows\System32 or Windows\SysWOW64 directory, it will be considered as managed by the OS. In this case, paranoid scanning is require to trigger downstream vulnerabilty checks. Paranoid scanning has no affect on this plugin itself.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/02/23, Modified: 2025/12/15
Plugin Output

tcp/0


Nessus detected 2 installs of Curl:

Path : c:\windows\system32\curl.exe
Version : 8.9.1.0
Managed by OS : True

Path : c:\windows\syswow64\curl.exe
Version : 8.9.1.0
Managed by OS : True

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/135/epmap


The following DCERPC services are available locally :

Object UUID : 765294ba-60bc-48b8-92e9-89fd77769d91
UUID : d95afe70-a6d5-4259-822e-2c84da1ddb0d, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WindowsShutdown

Object UUID : 765294ba-60bc-48b8-92e9-89fd77769d91
UUID : d95afe70-a6d5-4259-822e-2c84da1ddb0d, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WMsgKRpc01B6150

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000000
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WindowsShutdown

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000000
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WMsgKRpc01B6150

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : dabrpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : csebpub

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-844ae2b190293b6cfd

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a111f1c5-5923-47c0-9a68-d0bafb577901, version 1.0
Description : Unknown RPC service
Annotation : NetSetup API
Type : Local RPC service
Named pipe : LRPC-9c6e490f43796b6344

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3473dd4d-2e88-4006-9cba-22570909dd10, version 5.0
Description : Unknown RPC service
Annotation : WinHttp Auto-Proxy Service
Type : Local RPC service
Named pipe : LRPC-fb7714017354ca86e9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3473dd4d-2e88-4006-9cba-22570909dd10, version 5.0
Description : Unknown RPC service
Annotation : WinHttp Auto-Proxy Service
Type : Local RPC service
Named pipe : 36add040-08ea-4446-8da4-99397c46dcae

Object UUID : 3bdb59a0-d736-4d44-9074-c1ee00000005
UUID : f3f09ffd-fbcf-4291-944d-70ad6e0e73bb, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-739697fe49ffb08d52

Object UUID : 3bdb59a0-d736-4d44-9074-c1ee00000002
UUID : f3f09ffd-fbcf-4291-944d-70ad6e0e73bb, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b4d089b436d5536edf

Object UUID : 3bdb59a0-d736-4d44-9074-c1ee00000007
UUID : f3f09ffd-fbcf-4291-944d-70ad6e0e73bb, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-16f790b6a04c7a5626

Object UUID : 3bdb59a0-d736-4d44-9074-c1ee00000006
UUID : f3f09ffd-fbcf-4291-944d-70ad6e0e73bb, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-1cfa210dd042b4effa

Object UUID : 00000007-0000-0000-0000-000000000000
UUID : 8ec21e98-b5ce-4916-a3d6-449fa428a007, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEAEC17323422A8D7CD79EC71476DF

Object UUID : 00000007-0000-0000-0000-000000000000
UUID : 8ec21e98-b5ce-4916-a3d6-449fa428a007, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-ed636a84234772c24a

Object UUID : 00000007-0000-0000-0000-000000000000
UUID : 0fc77b1a-95d8-4a2e-a0c0-cff54237462b, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEAEC17323422A8D7CD79EC71476DF

Object UUID : 00000007-0000-0000-0000-000000000000
UUID : 0fc77b1a-95d8-4a2e-a0c0-cff54237462b, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-ed636a84234772c24a

Object UUID : 00000007-0000-0000-0000-000000000000
UUID : b1ef227e-dfa5-421e-82bb-67a6a129c496, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEAEC17323422A8D7CD79EC71476DF

Object UUID : 00000007-0000-0000-0000-000000000000
UUID : b1ef227e-dfa5-421e-82bb-67a6a129c496, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-ed636a84234772c24a

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000007
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WMsgKRpc05977AE2B7

Object UUID : 52ef130c-08fd-4388-86b3-6edf00000007
UUID : 12e65dd8-887f-41ef-91bf-8d816c42c2e7, version 1.0
Description : Unknown RPC service
Annotation : Secure Desktop LRPC interface
Type : Local RPC service
Named pipe : WMsgKRpc05977AE2B7

Object UUID : 8c7daf44-b6dc-11d1-9a4c-0020af6e7c57
UUID : 8c7daf44-b6dc-11d1-9a4c-0020af6e7c57, version 1.0
Description : Application Management service
Windows process : svchost.exe
Annotation : Group Policy RPC Interface
Type : Local RPC service
Named pipe : LRPC-bdc8e525eb34615b24

Object UUID : 00000006-0000-0000-0000-000000000000
UUID : 8ec21e98-b5ce-4916-a3d6-449fa428a007, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE2AAC48079FE04A10F4951ED56F73

Object UUID : 00000006-0000-0000-0000-000000000000
UUID : 8ec21e98-b5ce-4916-a3d6-449fa428a007, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-eaa06be4e467a897f1

Object UUID : 00000006-0000-0000-0000-000000000000
UUID : 0fc77b1a-95d8-4a2e-a0c0-cff54237462b, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE2AAC48079FE04A10F4951ED56F73

Object UUID : 00000006-0000-0000-0000-000000000000
UUID : 0fc77b1a-95d8-4a2e-a0c0-cff54237462b, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-eaa06be4e467a897f1

Object UUID : 00000006-0000-0000-0000-000000000000
UUID : b1ef227e-dfa5-421e-82bb-67a6a129c496, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE2AAC48079FE04A10F4951ED56F73

Object UUID : 00000006-0000-0000-0000-000000000000
UUID : b1ef227e-dfa5-421e-82bb-67a6a129c496, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-eaa06be4e467a897f1

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000006
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WMsgKRpc023B67D276

Object UUID : 52ef130c-08fd-4388-86b3-6edf00000006
UUID : 12e65dd8-887f-41ef-91bf-8d816c42c2e7, version 1.0
Description : Unknown RPC service
Annotation : Secure Desktop LRPC interface
Type : Local RPC service
Named pipe : WMsgKRpc023B67D276

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : bf4dc912-e52f-4904-8ebe-9317c1bdd497, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEE5E12AD7DA45C74F6A8553580D34

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : bf4dc912-e52f-4904-8ebe-9317c1bdd497, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-324945e3908c7cc8b4

Object UUID : 00000005-0000-0000-0000-000000000000
UUID : 8ec21e98-b5ce-4916-a3d6-449fa428a007, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE95DA20A283C5CFBC7764A7E09F7E

Object UUID : 00000005-0000-0000-0000-000000000000
UUID : 8ec21e98-b5ce-4916-a3d6-449fa428a007, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c8dfcd8e7b8fb51962

Object UUID : 00000005-0000-0000-0000-000000000000
UUID : 0fc77b1a-95d8-4a2e-a0c0-cff54237462b, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE95DA20A283C5CFBC7764A7E09F7E

Object UUID : 00000005-0000-0000-0000-000000000000
UUID : 0fc77b1a-95d8-4a2e-a0c0-cff54237462b, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c8dfcd8e7b8fb51962

Object UUID : 00000005-0000-0000-0000-000000000000
UUID : b1ef227e-dfa5-421e-82bb-67a6a129c496, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE95DA20A283C5CFBC7764A7E09F7E

Object UUID : 00000005-0000-0000-0000-000000000000
UUID : b1ef227e-dfa5-421e-82bb-67a6a129c496, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c8dfcd8e7b8fb51962

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000005
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WMsgKRpc0D26C9855

Object UUID : 52ef130c-08fd-4388-86b3-6edf00000005
UUID : 12e65dd8-887f-41ef-91bf-8d816c42c2e7, version 1.0
Description : Unknown RPC service
Annotation : Secure Desktop LRPC interface
Type : Local RPC service
Named pipe : WMsgKRpc0D26C9855

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9435cc56-1d9c-4924-ac7d-b60a2c3520e1, version 1.0
Description : Unknown RPC service
Annotation : SPPSVC Default RPC Interface
Type : Local RPC service
Named pipe : SPPCTransportEndpoint-00001

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0497b57d-2e66-424f-a0c6-157cd5d41700, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-a84e79c980a862f161

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 201ef99a-7fa0-444c-9399-19ba84f12a1a, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-a84e79c980a862f161

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5f54ce7d-5b79-4175-8584-cb65313a0e98, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-a84e79c980a862f161

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fd7a0523-dc70-43dd-9b2e-9c5ed48225b1, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-a84e79c980a862f161

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 58e604e8-9adb-4d2e-a464-3b0683fb1480, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-a84e79c980a862f161

Object UUID : 00000003-0000-0000-0000-000000000000
UUID : 8ec21e98-b5ce-4916-a3d6-449fa428a007, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE185742C5473B5A2A5BE77981FAD5

Object UUID : 00000003-0000-0000-0000-000000000000
UUID : 8ec21e98-b5ce-4916-a3d6-449fa428a007, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-50e7ce358785054382

Object UUID : 00000003-0000-0000-0000-000000000000
UUID : 0fc77b1a-95d8-4a2e-a0c0-cff54237462b, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE185742C5473B5A2A5BE77981FAD5

Object UUID : 00000003-0000-0000-0000-000000000000
UUID : 0fc77b1a-95d8-4a2e-a0c0-cff54237462b, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-50e7ce358785054382

Object UUID : 00000003-0000-0000-0000-000000000000
UUID : b1ef227e-dfa5-421e-82bb-67a6a129c496, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE185742C5473B5A2A5BE77981FAD5

Object UUID : 00000003-0000-0000-0000-000000000000
UUID : b1ef227e-dfa5-421e-82bb-67a6a129c496, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-50e7ce358785054382

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000003
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WMsgKRpc0695A9673

Object UUID : 52ef130c-08fd-4388-86b3-6edf00000003
UUID : 12e65dd8-887f-41ef-91bf-8d816c42c2e7, version 1.0
Description : Unknown RPC service
Annotation : Secure Desktop LRPC interface
Type : Local RPC service
Named pipe : WMsgKRpc0695A9673

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a4b8d482-80ce-40d6-934d-b22a01a44fe7, version 1.0
Description : Unknown RPC service
Annotation : LicenseManager
Type : Local RPC service
Named pipe : LicenseServiceEndpoint

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : be7f785e-0e3a-4ab7-91de-7e46e443be29, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-61537fe756bde09b27

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 54b4c689-969a-476f-8dc2-990885e9f562, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-61537fe756bde09b27

Object UUID : d12a9603-5747-4bb2-abda-aaac5ffeb2be
UUID : 906b0ce0-c70b-1067-b317-00dd010662da, version 1.0
Description : Distributed Transaction Coordinator
Windows process : msdtc.exe
Type : Local RPC service
Named pipe : LRPC-caaca28228f0f44f16

Object UUID : e5740d68-39e8-4d6a-b1ba-f1eb435256af
UUID : 906b0ce0-c70b-1067-b317-00dd010662da, version 1.0
Description : Distributed Transaction Coordinator
Windows process : msdtc.exe
Type : Local RPC service
Named pipe : LRPC-caaca28228f0f44f16

Object UUID : f7839220-e3f2-4e4c-9a29-e32a39d5c085
UUID : 906b0ce0-c70b-1067-b317-00dd010662da, version 1.0
Description : Distributed Transaction Coordinator
Windows process : msdtc.exe
Type : Local RPC service
Named pipe : LRPC-caaca28228f0f44f16

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0767a036-0d22-48aa-ba69-b619480f38cb, version 1.0
Description : Unknown RPC service
Annotation : PcaSvc
Type : Local RPC service
Named pipe : LRPC-4d1192bd63fb42ee89

Object UUID : 00000002-0000-0000-0000-000000000000
UUID : 8ec21e98-b5ce-4916-a3d6-449fa428a007, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE2AC088F0278D9B40B32332F3D878

Object UUID : 00000002-0000-0000-0000-000000000000
UUID : 8ec21e98-b5ce-4916-a3d6-449fa428a007, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-02ac2bebe61f24eaaa

Object UUID : 00000002-0000-0000-0000-000000000000
UUID : 0fc77b1a-95d8-4a2e-a0c0-cff54237462b, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE2AC088F0278D9B40B32332F3D878

Object UUID : 00000002-0000-0000-0000-000000000000
UUID : 0fc77b1a-95d8-4a2e-a0c0-cff54237462b, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-02ac2bebe61f24eaaa

Object UUID : 00000002-0000-0000-0000-000000000000
UUID : b1ef227e-dfa5-421e-82bb-67a6a129c496, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE2AC088F0278D9B40B32332F3D878

Object UUID : 00000002-0000-0000-0000-000000000000
UUID : b1ef227e-dfa5-421e-82bb-67a6a129c496, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-02ac2bebe61f24eaaa

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000002
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WMsgKRpc01601312

Object UUID : 52ef130c-08fd-4388-86b3-6edf00000002
UUID : 12e65dd8-887f-41ef-91bf-8d816c42c2e7, version 1.0
Description : Unknown RPC service
Annotation : Secure Desktop LRPC interface
Type : Local RPC service
Named pipe : WMsgKRpc01601312

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4c9dbf19-d39e-4bb9-90ee-8f7179b20283, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-cb1eecbed4d455e847

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fd8be72b-a9cd-4b2c-a9ca-4ded242fbe4d, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-cb1eecbed4d455e847

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 95095ec8-32ea-4eb0-a3e2-041f97b36168, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-cb1eecbed4d455e847

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e38f5360-8572-473e-b696-1b46873beeab, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-cb1eecbed4d455e847

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : d22895ef-aff4-42c5-a5b2-b14466d34ab4, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-cb1eecbed4d455e847

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 98cd761e-e77d-41c8-a3c0-0fb756d90ec2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-cb1eecbed4d455e847

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 650a7e26-eab8-5533-ce43-9c1dfce11511, version 1.0
Description : Unknown RPC service
Annotation : Vpn APIs
Type : Local RPC service
Named pipe : RasmanLrpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 650a7e26-eab8-5533-ce43-9c1dfce11511, version 1.0
Description : Unknown RPC service
Annotation : Vpn APIs
Type : Local RPC service
Named pipe : VpnikeRpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 650a7e26-eab8-5533-ce43-9c1dfce11511, version 1.0
Description : Unknown RPC service
Annotation : Vpn APIs
Type : Local RPC service
Named pipe : LRPC-5daefa336530e460c5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 98716d03-89ac-44c7-bb8c-285824e51c4a, version 1.0
Description : Unknown RPC service
Annotation : XactSrv service
Type : Local RPC service
Named pipe : LRPC-4c5a9aa6acc89b47a0

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1a0d010f-1c33-432c-b0f5-8cf4e8053099, version 1.0
Description : Unknown RPC service
Annotation : IdSegSrv service
Type : Local RPC service
Named pipe : LRPC-4c5a9aa6acc89b47a0

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a398e520-d59a-4bdd-aa7a-3c1e0303a511, version 1.0
Description : Unknown RPC service
Annotation : IKE/Authip API
Type : Local RPC service
Named pipe : LRPC-a5eb52e9e9e913324b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 552d076a-cb29-4e44-8b6a-d15e59e2c0af, version 1.0
Description : Unknown RPC service
Annotation : IP Transition Configuration endpoint
Type : Local RPC service
Named pipe : LRPC-20eef0bed93a25d664

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Local RPC service
Named pipe : LRPC-20eef0bed93a25d664

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Local RPC service
Named pipe : TeredoDiagnostics

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Local RPC service
Named pipe : TeredoControl

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Local RPC service
Named pipe : LRPC-20eef0bed93a25d664

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Local RPC service
Named pipe : TeredoDiagnostics

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Local RPC service
Named pipe : TeredoControl

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Local RPC service
Named pipe : LRPC-20eef0bed93a25d664

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Local RPC service
Named pipe : TeredoDiagnostics

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Local RPC service
Named pipe : TeredoControl

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b58aa02e-2884-4e97-8176-4ee06d794184, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-d105baed4b08ec200d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : audit

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : securityevent

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : LSARPC_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : lsacap

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : LSA_IDPEXT_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : LSA_EAS_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : lsapolicylookup

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : lsasspirpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : protected_storage

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : SidKey Local End Point

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : samss lpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : audit

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : securityevent

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSARPC_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsacap

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSA_IDPEXT_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSA_EAS_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsapolicylookup

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsasspirpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : protected_storage

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : SidKey Local End Point

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : samss lpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : audit

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : securityevent

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSARPC_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsacap

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSA_IDPEXT_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSA_EAS_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsapolicylookup

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsasspirpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : protected_storage

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : SidKey Local End Point

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : samss lpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : audit

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : securityevent

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : LSARPC_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : lsacap

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : LSA_IDPEXT_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : LSA_EAS_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : lsapolicylookup

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : lsasspirpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : protected_storage

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : SidKey Local End Point

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : samss lpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : dd490425-5325-4565-b774-7e27d6c09c24, version 1.0
Description : Unknown RPC service
Annotation : Base Firewall Engine API
Type : Local RPC service
Named pipe : LRPC-1a08215e6a4a589d32

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7f9d11bf-7fb9-436b-a812-b2d50c5d4c03, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-1a08215e6a4a589d32

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7f9d11bf-7fb9-436b-a812-b2d50c5d4c03, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-451f0254ac6da8a0f6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f47433c3-3e9d-4157-aad4-83aa1f5c2d4c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-1a08215e6a4a589d32

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f47433c3-3e9d-4157-aad4-83aa1f5c2d4c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-451f0254ac6da8a0f6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f47433c3-3e9d-4157-aad4-83aa1f5c2d4c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-40818ddf9c3467a49f

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2fb92682-6599-42dc-ae13-bd2ca89bd11c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-1a08215e6a4a589d32

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2fb92682-6599-42dc-ae13-bd2ca89bd11c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-451f0254ac6da8a0f6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2fb92682-6599-42dc-ae13-bd2ca89bd11c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-40818ddf9c3467a49f

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2fb92682-6599-42dc-ae13-bd2ca89bd11c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-5fb866e9c886fe56db

Object UUID : 73736573-6f69-656e-6e76-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : LRPC-3de36ef4f72e7a22b7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3de36ef4f72e7a22b7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : SessEnvPrivateRpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b18fbab6-56f8-4702-84e0-41053293a869, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : OLE56B9489910EC34C9389E5B4DE287

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b18fbab6-56f8-4702-84e0-41053293a869, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : LRPC-f240eb3c33a89e622d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3c7f20-1c8d-4654-a1b3-51563b298bda, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : OLE56B9489910EC34C9389E5B4DE287

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3c7f20-1c8d-4654-a1b3-51563b298bda, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : LRPC-f240eb3c33a89e622d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : abfb6ca3-0c5e-4734-9285-0aee72fe8d1c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLED2F956DB25242C324AF481DA74C0

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : abfb6ca3-0c5e-4734-9285-0aee72fe8d1c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-a7068d7af629852db3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b37f900a-eae4-4304-a2ab-12bb668c0188, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLED2F956DB25242C324AF481DA74C0

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b37f900a-eae4-4304-a2ab-12bb668c0188, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-a7068d7af629852db3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e7f76134-9ef5-4949-a2d6-3368cc0988f3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLED2F956DB25242C324AF481DA74C0

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e7f76134-9ef5-4949-a2d6-3368cc0988f3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-a7068d7af629852db3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7aeb6705-3ae6-471a-882d-f39c109edc12, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLED2F956DB25242C324AF481DA74C0

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7aeb6705-3ae6-471a-882d-f39c109edc12, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-a7068d7af629852db3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f44e62af-dab1-44c2-8013-049a9de417d6, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLED2F956DB25242C324AF481DA74C0

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f44e62af-dab1-44c2-8013-049a9de417d6, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-a7068d7af629852db3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c2d1b5dd-fa81-4460-9dd6-e7658b85454b, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLED2F956DB25242C324AF481DA74C0

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c2d1b5dd-fa81-4460-9dd6-e7658b85454b, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-a7068d7af629852db3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f2c9b409-c1c9-4100-8639-d8ab1486694a, version 1.0
Description : Unknown RPC service
Annotation : Witness Client Upcall Server
Type : Local RPC service
Named pipe : LRPC-075d261dae42726174

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : eb081a0d-10ee-478a-a1dd-50995283e7a8, version 3.0
Description : Unknown RPC service
Annotation : Witness Client Test Interface
Type : Local RPC service
Named pipe : LRPC-075d261dae42726174

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7f1343fe-50a9-4927-a778-0c5859517bac, version 1.0
Description : Unknown RPC service
Annotation : DfsDs service
Type : Local RPC service
Named pipe : LRPC-075d261dae42726174

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 30b044a5-a225-43f0-b3a4-e060df91f9c1, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-9f1014d3b26e85e75a

Object UUID : 736e6573-0000-0000-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : senssvc

Object UUID : 736e6573-0000-0000-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : LRPC-8cf1d93092a761f7cc

Object UUID : 666f7270-6c69-7365-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0a74ef1c-41a4-4e06-83ae-dc74fb1cdd53, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : LRPC-47a25e3e60b3beef06

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1ff70682-0a51-30e8-076d-740be8cee98b, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : LRPC-47a25e3e60b3beef06

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 378e52b0-c0a9-11cf-822d-00aa0051e40f, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : LRPC-47a25e3e60b3beef06

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 33d84484-3626-47ee-8c6f-e7e98b113be1, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-47a25e3e60b3beef06

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 33d84484-3626-47ee-8c6f-e7e98b113be1, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 33d84484-3626-47ee-8c6f-e7e98b113be1, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-f3c1bc7e2174eb902d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-47a25e3e60b3beef06

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-f3c1bc7e2174eb902d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-47a25e3e60b3beef06

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-f3c1bc7e2174eb902d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : df4df73a-c52d-4e3a-8003-8437fdf8302a, version 0.0
Description : Unknown RPC service
Annotation : WM_WindowManagerRPC\Server
Type : Local RPC service
Named pipe : LRPC-fb447058daab9be663

Object UUID : 6c637067-6569-746e-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : LRPC-45877ad81b2d086d85

Object UUID : 24d1f7c7-76af-4f28-9ccd-7f6cb6468601
UUID : 2eb08e3e-639f-4fba-97b1-14f878961076, version 1.0
Description : Unknown RPC service
Annotation : Group Policy RPC Interface
Type : Local RPC service
Named pipe : LRPC-355c691fe4c5c586ca

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6, version 1.0
Description : Unknown RPC service
Annotation : DHCPv6 Client LRPC Endpoint
Type : Local RPC service
Named pipe : dhcpcsvc6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5, version 1.0
Description : DHCP Client Service
Windows process : svchost.exe
Annotation : DHCP Client LRPC Endpoint
Type : Local RPC service
Named pipe : dhcpcsvc6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5, version 1.0
Description : DHCP Client Service
Windows process : svchost.exe
Annotation : DHCP Client LRPC Endpoint
Type : Local RPC service
Named pipe : dhcpcsvc

Object UUID : 3bdb59a0-d736-4d44-9074-c1ee00000001
UUID : f3f09ffd-fbcf-4291-944d-70ad6e0e73bb, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-8ce1afc99e91a8886d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7ea70bcf-48af-4f6a-8968-6a440754d5fa, version 1.0
Description : Unknown RPC service
Annotation : NSI server endpoint
Type : Local RPC service
Named pipe : LRPC-1d48efc5d3164d2408

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f6beaff7-1e19-4fbb-9f8f-b89e2018337c, version 1.0
Description : Unknown RPC service
Annotation : Event log TCPIP
Type : Local RPC service
Named pipe : eventlog

Object UUID : fdd099c6-df06-4904-83b4-a87a27903c70
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-47f41b416c1151ffb8

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5222821f-d5e2-4885-84f1-5f6185a0ec41, version 1.0
Description : Unknown RPC service
Annotation : Network Connection Broker server endpoint for NCB Reset module
Type : Local RPC service
Named pipe : LRPC-47f41b416c1151ffb8

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5222821f-d5e2-4885-84f1-5f6185a0ec41, version 1.0
Description : Unknown RPC service
Annotation : Network Connection Broker server endpoint for NCB Reset module
Type : Local RPC service
Named pipe : LRPC-afc2d520126a6e5151

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 880fd55e-43b9-11e0-b1a8-cf4edfd72085, version 1.0
Description : Unknown RPC service
Annotation : KAPI Service endpoint
Type : Local RPC service
Named pipe : LRPC-47f41b416c1151ffb8

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 880fd55e-43b9-11e0-b1a8-cf4edfd72085, version 1.0
Description : Unknown RPC service
Annotation : KAPI Service endpoint
Type : Local RPC service
Named pipe : LRPC-afc2d520126a6e5151

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 880fd55e-43b9-11e0-b1a8-cf4edfd72085, version 1.0
Description : Unknown RPC service
Annotation : KAPI Service endpoint
Type : Local RPC service
Named pipe : OLECA207F36AE99DE39AB49B657AA39

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 880fd55e-43b9-11e0-b1a8-cf4edfd72085, version 1.0
Description : Unknown RPC service
Annotation : KAPI Service endpoint
Type : Local RPC service
Named pipe : LRPC-226c1c608b1d6760d5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e40f7b57-7a25-4cd3-a135-7f7d3df9d16b, version 1.0
Description : Unknown RPC service
Annotation : Network Connection Broker server endpoint
Type : Local RPC service
Named pipe : LRPC-47f41b416c1151ffb8

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e40f7b57-7a25-4cd3-a135-7f7d3df9d16b, version 1.0
Description : Unknown RPC service
Annotation : Network Connection Broker server endpoint
Type : Local RPC service
Named pipe : LRPC-afc2d520126a6e5151

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e40f7b57-7a25-4cd3-a135-7f7d3df9d16b, version 1.0
Description : Unknown RPC service
Annotation : Network Connection Broker server endpoint
Type : Local RPC service
Named pipe : OLECA207F36AE99DE39AB49B657AA39

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e40f7b57-7a25-4cd3-a135-7f7d3df9d16b, version 1.0
Description : Unknown RPC service
Annotation : Network Connection Broker server endpoint
Type : Local RPC service
Named pipe : LRPC-226c1c608b1d6760d5

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000001
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WMsgKRpc01B9501

Object UUID : b5ccd5ef-4238-440b-bba0-999f828f1cfe
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-47bf732bacdaa3fe0b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a500d4c6-0dd1-4543-bc0c-d5f93486eaf8, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-47bf732bacdaa3fe0b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a500d4c6-0dd1-4543-bc0c-d5f93486eaf8, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-d2a9b41f0042c1bf01

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 30adc50c-5cbc-46ce-9a0e-91914789e23c, version 1.0
Description : Unknown RPC service
Annotation : NRP server endpoint
Type : Local RPC service
Named pipe : LRPC-e560c4f7ea304c92d4

Object UUID : 6d726574-7273-0076-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : LRPC-e7d46b53e98411c41b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4bec6bb8-b5c2-4b6f-b2c1-5da5cf92d0d9, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 085b0334-e454-4d91-9b8c-4134f9e793f3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8782d3b9-ebbd-4644-a3d8-e8725381919b, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3b338d89-6cfa-44b8-847e-531531bc9992, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : bdaa0970-413b-4a3e-9e5d-f6dc9d7e0760, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5824833b-3c1a-4ad2-bdfd-c31d19e23ed2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0361ae94-0316-4c6c-8ad8-c594375800e2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2d98a740-581d-41b9-aa0d-a88b9d5ce938, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2d98a740-581d-41b9-aa0d-a88b9d5ce938, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2d98a740-581d-41b9-aa0d-a88b9d5ce938, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-83d138263b700e40d2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8bfc3be1-6def-4e2d-af74-7c47cd0ade4a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8bfc3be1-6def-4e2d-af74-7c47cd0ade4a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8bfc3be1-6def-4e2d-af74-7c47cd0ade4a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-83d138263b700e40d2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1b37ca91-76b1-4f5e-a3c7-2abfc61f2bb0, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1b37ca91-76b1-4f5e-a3c7-2abfc61f2bb0, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1b37ca91-76b1-4f5e-a3c7-2abfc61f2bb0, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-83d138263b700e40d2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c605f9fb-f0a3-4e2a-a073-73560f8d9e3e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c605f9fb-f0a3-4e2a-a073-73560f8d9e3e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c605f9fb-f0a3-4e2a-a073-73560f8d9e3e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-83d138263b700e40d2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3e2735-cea0-4ecc-a9e2-41a2d81aed4e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3e2735-cea0-4ecc-a9e2-41a2d81aed4e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3e2735-cea0-4ecc-a9e2-41a2d81aed4e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-83d138263b700e40d2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2513bcbe-6cd4-4348-855e-7efb3c336dd3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2513bcbe-6cd4-4348-855e-7efb3c336dd3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2513bcbe-6cd4-4348-855e-7efb3c336dd3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-83d138263b700e40d2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2513bcbe-6cd4-4348-855e-7efb3c336dd3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLED0BB86FC6C7269063AA315247CDB

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2513bcbe-6cd4-4348-855e-7efb3c336dd3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b86ca2ddf501760a2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 20c40295-8dba-48e6-aebf-3e78ef3bb144, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 20c40295-8dba-48e6-aebf-3e78ef3bb144, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 20c40295-8dba-48e6-aebf-3e78ef3bb144, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-83d138263b700e40d2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 20c40295-8dba-48e6-aebf-3e78ef3bb144, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLED0BB86FC6C7269063AA315247CDB

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 20c40295-8dba-48e6-aebf-3e78ef3bb144, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b86ca2ddf501760a2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b8cadbaf-e84b-46b9-84f2-6f71c03f9e55, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b8cadbaf-e84b-46b9-84f2-6f71c03f9e55, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b8cadbaf-e84b-46b9-84f2-6f71c03f9e55, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-83d138263b700e40d2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b8cadbaf-e84b-46b9-84f2-6f71c03f9e55, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLED0BB86FC6C7269063AA315247CDB

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b8cadbaf-e84b-46b9-84f2-6f71c03f9e55, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b86ca2ddf501760a2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-83d138263b700e40d2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLED0BB86FC6C7269063AA315247CDB

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b86ca2ddf501760a2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-83d138263b700e40d2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLED0BB86FC6C7269063AA315247CDB

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b86ca2ddf501760a2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c1f1ad45113c086ab3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-83d138263b700e40d2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLED0BB86FC6C7269063AA315247CDB

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b86ca2ddf501760a2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c1f1ad45113c086ab3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-83d138263b700e40d2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLED0BB86FC6C7269063AA315247CDB

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b86ca2ddf501760a2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c1f1ad45113c086ab3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2c7fd9ce-e706-4b40-b412-953107ef9bb0, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c521facf-09a9-42c5-b155-72388595cbf0, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1832bcf6-cab8-41d4-85d2-c9410764f75a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4dace966-a243-4450-ae3f-9b7bcb5315b8, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 178d84be-9291-4994-82c6-3f909aca5a03, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e53d94ca-7464-4839-b044-09a2fb8b3ae5, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fae436b0-b864-4a87-9eda-298547cd82f2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 082a3471-31b6-422a-b931-a54401960c62, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 6982a06e-5fe2-46b1-b39c-a2c545bfa069, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0ff1f646-13bb-400a-ab50-9a78f2b7a85a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4ed8abcc-f1e2-438b-981f-bb0e8abc010c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 95406f0b-b239-4318-91bb-cea3a46ff0dc, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d47017b-b33b-46ad-9e18-fe96456c5078, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : dd59071b-3215-4c59-8481-972edadc0f6a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 7cd4a68a-505e-456b-b11e-ca76a5dd491c
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 7cd4a68a-505e-456b-b11e-ca76a5dd491c
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 7cd4a68a-505e-456b-b11e-ca76a5dd491c
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-83d138263b700e40d2

Object UUID : 7cd4a68a-505e-456b-b11e-ca76a5dd491c
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLED0BB86FC6C7269063AA315247CDB

Object UUID : 7cd4a68a-505e-456b-b11e-ca76a5dd491c
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b86ca2ddf501760a2

Object UUID : 7cd4a68a-505e-456b-b11e-ca76a5dd491c
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c1f1ad45113c086ab3

Object UUID : 7cd4a68a-505e-456b-b11e-ca76a5dd491c
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-1c365b4ce5d214370f

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-83d138263b700e40d2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLED0BB86FC6C7269063AA315247CDB

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b86ca2ddf501760a2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c1f1ad45113c086ab3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-1c365b4ce5d214370f

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b416dec214270c1dbb

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-83d138263b700e40d2

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLED0BB86FC6C7269063AA315247CDB

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b86ca2ddf501760a2

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c1f1ad45113c086ab3

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-1c365b4ce5d214370f

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b416dec214270c1dbb

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-83d138263b700e40d2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLED0BB86FC6C7269063AA315247CDB

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b86ca2ddf501760a2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c1f1ad45113c086ab3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-1c365b4ce5d214370f

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b416dec214270c1dbb

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-844ae2b190293b6cfd

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-83d138263b700e40d2

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLED0BB86FC6C7269063AA315247CDB

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b86ca2ddf501760a2

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c1f1ad45113c086ab3

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-1c365b4ce5d214370f

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b416dec214270c1dbb

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-844ae2b190293b6cfd

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : csebpub

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-83d138263b700e40d2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLED0BB86FC6C7269063AA315247CDB

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6b86ca2ddf501760a2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c1f1ad45113c086ab3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-1c365b4ce5d214370f

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b416dec214270c1dbb

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/445/cifs


The following DCERPC services are available remotely :

Object UUID : 765294ba-60bc-48b8-92e9-89fd77769d91
UUID : d95afe70-a6d5-4259-822e-2c84da1ddb0d, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\InitShutdown
Netbios name : \\TECHE_LIVE_DB

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000000
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\InitShutdown
Netbios name : \\TECHE_LIVE_DB

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 650a7e26-eab8-5533-ce43-9c1dfce11511, version 1.0
Description : Unknown RPC service
Annotation : Vpn APIs
Type : Remote RPC service
Named pipe : \PIPE\ROUTER
Netbios name : \\TECHE_LIVE_DB

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Remote RPC service
Named pipe : \pipe\lsass
Netbios name : \\TECHE_LIVE_DB

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Remote RPC service
Named pipe : \pipe\lsass
Netbios name : \\TECHE_LIVE_DB

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Remote RPC service
Named pipe : \pipe\lsass
Netbios name : \\TECHE_LIVE_DB

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Remote RPC service
Named pipe : \pipe\lsass
Netbios name : \\TECHE_LIVE_DB

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\SessEnvPublicRpc
Netbios name : \\TECHE_LIVE_DB

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7f1343fe-50a9-4927-a778-0c5859517bac, version 1.0
Description : Unknown RPC service
Annotation : DfsDs service
Type : Remote RPC service
Named pipe : \PIPE\wkssvc
Netbios name : \\TECHE_LIVE_DB

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1ff70682-0a51-30e8-076d-740be8cee98b, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\TECHE_LIVE_DB

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 378e52b0-c0a9-11cf-822d-00aa0051e40f, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\TECHE_LIVE_DB

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 33d84484-3626-47ee-8c6f-e7e98b113be1, version 2.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\TECHE_LIVE_DB

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\TECHE_LIVE_DB

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\TECHE_LIVE_DB

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f6beaff7-1e19-4fbb-9f8f-b89e2018337c, version 1.0
Description : Unknown RPC service
Annotation : Event log TCPIP
Type : Remote RPC service
Named pipe : \pipe\eventlog
Netbios name : \\TECHE_LIVE_DB

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49664/dce-rpc


The following DCERPC services are available on TCP port 49664 :

Object UUID : 765294ba-60bc-48b8-92e9-89fd77769d91
UUID : d95afe70-a6d5-4259-822e-2c84da1ddb0d, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49664
IP : 172.17.100.31

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49665/dce-rpc


The following DCERPC services are available on TCP port 49665 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f6beaff7-1e19-4fbb-9f8f-b89e2018337c, version 1.0
Description : Unknown RPC service
Annotation : Event log TCPIP
Type : Remote RPC service
TCP Port : 49665
IP : 172.17.100.31

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49666/dce-rpc


The following DCERPC services are available on TCP port 49666 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.31

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.31

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49667/dce-rpc


The following DCERPC services are available on TCP port 49667 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49667
IP : 172.17.100.31

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49842/dce-rpc


The following DCERPC services are available on TCP port 49842 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Remote RPC service
TCP Port : 49842
IP : 172.17.100.31

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49931/dce-rpc


The following DCERPC services are available on TCP port 49931 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 367abb81-9844-35f1-ad32-98f038001003, version 2.0
Description : Service Control Manager
Windows process : svchost.exe
Type : Remote RPC service
TCP Port : 49931
IP : 172.17.100.31

84239 - Debugging Log Report
-
Synopsis
This plugin gathers the logs written by other plugins and reports them.
Description
Logs generated by other plugins are reported by this plugin. Plugin debugging must be enabled in the policy in order for this plugin to run.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2015/06/17, Modified: 2025/07/14
Plugin Output

tcp/0

Plugin debug log(s) have been attached.
55472 - Device Hostname
-
Synopsis
It was possible to determine the remote system hostname.
Description
This plugin reports a device's hostname collected via SSH or WMI.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/06/30, Modified: 2025/12/15
Plugin Output

tcp/0


Hostname : TECHE_LIVE_DB
TECHE_LIVE_DB (WMI)
54615 - Device Type
-
Synopsis
It is possible to guess the remote device type.
Description
Based on the remote operating system, it is possible to determine what the remote system type is (eg: a printer, router, general-purpose computer, etc).
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/05/23, Modified: 2025/03/12
Plugin Output

tcp/0

Remote device type : general-purpose
Confidence level : 100

19689 - Embedded Web Server Detection
-
Synopsis
The remote web server is embedded.
Description
The remote web server cannot host user-supplied CGIs. CGI scanning will be disabled on this server.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2005/09/14, Modified: 2025/09/29
Plugin Output

tcp/5800/www

71246 - Enumerate Local Group Memberships
-
Synopsis
Nessus was able to connect to a host via SMB to retrieve a list of local Groups and their Members.
Description
Nessus was able to connect to a host via SMB to retrieve a list of local Groups and their Members.

Note: Unable to query local Domain Controllers during Agent scans.
Rendering Group data obtained by plugin 171956.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/12/06, Modified: 2025/12/15
Plugin Output

tcp/0

Group Name : Access Control Assistance Operators
Host Name : TECHE_LIVE_DB
Group SID : S-1-5-32-579
Members :

Group Name : Administrators
Host Name : TECHE_LIVE_DB
Group SID : S-1-5-32-544
Members :
Name : Production
Domain : TECHE_LIVE_DB
Class : Win32_UserAccount
SID : S-1-5-21-1185746460-1788592564-4118236249-500
Name : LKPAdmin
Domain : TECHE_LIVE_DB
Class : Win32_UserAccount
SID : S-1-5-21-1185746460-1788592564-4118236249-1000
Name : techexcel
Domain : TECHE_LIVE_DB
Class : Win32_UserAccount
SID : S-1-5-21-1185746460-1788592564-4118236249-1001
Name : Techrobot
Domain : TECHE_LIVE_DB
Class : Win32_UserAccount
SID : S-1-5-21-1185746460-1788592564-4118236249-1005
Name : Backoffice
Domain : TECHE_LIVE_DB
Class : Win32_UserAccount
SID : S-1-5-21-1185746460-1788592564-4118236249-1006
Name : uatlkp
Domain : TECHE_LIVE_DB
Class : Win32_UserAccount
SID : S-1-5-21-1185746460-1788592564-4118236249-1010
Name : tidua
Domain : TECHE_LIVE_DB
Class : Win32_UserAccount
SID : S-1-5-21-1185746460-1788592564-4118236249-1012

Group Name : Backup Operators
Host Name : TECHE_LIVE_DB
Group SID : S-1-5-32-551
Members :

Group Name : Certificate Service DCOM Access
Host Name : TECHE_LIVE_DB
Group SID : S-1-5-32-574
Members :

Group Name : Cryptographic Operators
Host Name : TECHE_LIVE_DB
Group SID : S-1-5-32-569
Members :

Group Name : Device Owners
Host Name : TECHE_LIVE_DB
Group SID : S-1-5-32-583
Members :

Group Name : Distributed COM Users
Host Name : TECHE_LIVE_DB
Group SID : S-1-5-32-562
Members :

Group Name : Event Log Readers
Host Name : TECHE_LIVE_DB
Group SID : S-1-5-32-573
Members :

Group Name : Guests
Host Name : TECHE_LIVE_DB
Group SID : S-1-5-32-546
Members :
Name : Guest
Domain : TECHE_LIVE_DB
Class : Win32_UserAccount
SID : S-1-5-21-1185746460-1788592564-4118236249-501

Group Name : Hyper-V Administrators
Host Name : TECHE_LIVE_DB
Group SID : S-1-5-32-578
Members :

Group Name : IIS_IUSRS
Host Name : TECHE_LIVE_DB
Group SID : S-1-5-32-568
Members :

Group Name : Network Configuration Operators
Host Name : TECHE_LIVE_DB
Group SID : S-1-5-32-556
Members :

Group Name : Performance Log Users
Host Name : TECHE_LIVE_DB
Group SID : S-1-5-32-559
Members :

Group Name : Performance Monitor Users
Host Name : TECHE_LIVE_DB
Group SID : S-1-5-32-558
Members :
Name : MSSQLSERVER
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :
Name : SQLSERVERAGENT
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :

Group Name : Power Users
Host Name : TECHE_LIVE_DB
Group SID : S-1-5-32-547
Members :
Name : LKPAdmin
Domain : TECHE_LIVE_DB
Class : Win32_UserAccount
SID : S-1-5-21-1185746460-1788592564-4118236249-1000
Name : Backoffice
Domain : TECHE_LIVE_DB
Class : Win32_UserAccount
SID : S-1-5-21-1185746460-1788592564-4118236249-1006

Group Name : Print Operators
Host Name : TECHE_LIVE_DB
Group SID : S-1-5-32-550
Members :

Group Name : RDS Endpoint Servers
Host Name : TECHE_LIVE_DB
Group SID : S-1-5-32-576
Members :

Group Name : RDS Management Servers
Host Name : TECHE_LIVE_DB
Group SID : S-1-5-32-577
Members :

Group Name : RDS Remote Access Servers
Host Name : TECHE_LIVE_DB
Group SID : S-1-5-32-575
Members :

Group Name : Remote Desktop Users
Host Name : TECHE_LIVE_DB
Group SID : S-1-5-32-555
Members :
Name : techapp
Domain : TECHE_LIVE_DB
Class : Win32_UserAccount
SID : S-1-5-21-1185746460-1788592564-4118236249-1002
Name : Backoffice
Domain : TECHE_LIVE_DB
Class : Win32_UserAccount
SID : S-1-5-21-1185746460-1788592564-4118236249-1006

Group Name : Remote Management Users
Host Name : TECHE_LIVE_DB
Group SID : S-1-5-32-580
Members :

Group Name : Replicator
Host Name : TECHE_LIVE_DB
Group SID : S-1-5-32-552
Members :

Group Name : Storage Replica Administrators
Host Name : TECHE_LIVE_DB
Group SID : S-1-5-32-582
Members :

Group Name : System Managed Accounts Group
Host Name : TECHE_LIVE_DB
Group SID : S-1-5-32-581
Members :
Name : DefaultAccount
Domain : TECHE_LIVE_DB
Class : Win32_UserAccount
SID : S-1-5-21-1185746460-1788592564-4118236249-503

Group Name : Users
Host Name : TECHE_LIVE_DB
Group SID : S-1-5-32-545
Members :
Name : INTERACTIVE
Domain : TECHE_LIVE_DB
Class : Win32_SystemAccount
SID : S-1-5-4
Name : Authenticated Users
Domain : TECHE_LIVE_DB
Class : Win32_SystemAccount
SID : S-1-5-11
Name : LKPAdmin
Domain : TECHE_LIVE_DB
Class : Win32_UserAccount
SID : S-1-5-21-1185746460-1788592564-4118236249-1000
Name : techexcel
Domain : TECHE_LIVE_DB
Class : Win32_UserAccount
SID : S-1-5-21-1185746460-1788592564-4118236249-1001
Name : techapp
Domain : TECHE_LIVE_DB
Class : Win32_UserAccount
SID : S-1-5-21-1185746460-1788592564-4118236249-1002
Name : Techrobot
Domain : TECHE_LIVE_DB
Class : Win32_UserAccount
SID : S-1-5-21-1185746460-1788592564-4118236249-1005
Name : uatlkp
Domain : TECHE_LIVE_DB
Class : Win32_UserAccount
SID : S-1-5-21-1185746460-1788592564-4118236249-1010
Name : tidua
Domain : TECHE_LIVE_DB
Class : Win32_UserAccount
SID : S-1-5-21-1185746460-1788592564-4118236249-1012

Group Name : Cyber Operators
Host Name : TECHE_LIVE_DB
Group SID : S-1-5-21-1185746460-1788592564-4118236249-1013
Members :

Group Name : SQLRUserGroup
Host Name : TECHE_LIVE_DB
Group SID : S-1-5-21-1185746460-1788592564-4118236249-1004
Members :
Name : MSSQLLaunchpad
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :

Group Name : SQLServer2005SQLBrowserUser$TECHE_LIVE_DB
Host Name : TECHE_LIVE_DB
Group SID : S-1-5-21-1185746460-1788592564-4118236249-1003
Members :
Name : SQLBrowser
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :

Group Name : VisualSVN Replication Partners
Host Name : TECHE_LIVE_DB
Group SID : S-1-5-21-1185746460-1788592564-4118236249-1016
Members :

Group Name : VisualSVN Repository Supervisors
Host Name : TECHE_LIVE_DB
Group SID : S-1-5-21-1185746460-1788592564-4118236249-1015
Members :

Group Name : VisualSVN Server Admins
Host Name : TECHE_LIVE_DB
Group SID : S-1-5-21-1185746460-1788592564-4118236249-1014
Members :
72684 - Enumerate Users via WMI
-
Synopsis
Nessus was able to connect to a host via SMB to retrieve a list of users using WMI.
Description
Nessus was able to connect to a host via SMB to retrieve a list of users using WMI. Only identities that the authenticated SMB user has permissions to view will be retrieved by this plugin.

Note: Unable to query local Domain Controllers during Agent scans.
Rendering User data obtained by plugin 171956.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2014/02/25, Modified: 2025/12/15
Plugin Output

tcp/0


Name : Backoffice
SID : S-1-5-21-1185746460-1788592564-4118236249-1006
Disabled : False
Lockout : False
Change password : False
Source : Local

Name : DefaultAccount
SID : S-1-5-21-1185746460-1788592564-4118236249-503
Disabled : True
Lockout : False
Change password : True
Source : Local

Name : Guest
SID : S-1-5-21-1185746460-1788592564-4118236249-501
Disabled : True
Lockout : False
Change password : False
Source : Local

Name : LKPAdmin
SID : S-1-5-21-1185746460-1788592564-4118236249-1000
Disabled : False
Lockout : False
Change password : True
Source : Local

Name : Production
SID : S-1-5-21-1185746460-1788592564-4118236249-500
Disabled : False
Lockout : False
Change password : True
Source : Local

Name : techapp
SID : S-1-5-21-1185746460-1788592564-4118236249-1002
Disabled : False
Lockout : False
Change password : False
Source : Local

Name : techexcel
SID : S-1-5-21-1185746460-1788592564-4118236249-1001
Disabled : False
Lockout : False
Change password : False
Source : Local

Name : Techrobot
SID : S-1-5-21-1185746460-1788592564-4118236249-1005
Disabled : False
Lockout : False
Change password : False
Source : Local

Name : tidua
SID : S-1-5-21-1185746460-1788592564-4118236249-1012
Disabled : False
Lockout : False
Change password : True
Source : Local

Name : uatlkp
SID : S-1-5-21-1185746460-1788592564-4118236249-1010
Disabled : False
Lockout : False
Change password : True
Source : Local

Name : WDAGUtilityAccount
SID : S-1-5-21-1185746460-1788592564-4118236249-504
Disabled : True
Lockout : False
Change password : True
Source : Local

No. Of Users : 11
35716 - Ethernet Card Manufacturer Detection
-
Synopsis
The manufacturer can be identified from the Ethernet OUI.
Description
Each ethernet MAC address starts with a 24-bit Organizationally Unique Identifier (OUI). These OUIs are registered by IEEE.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/02/19, Modified: 2020/05/13
Plugin Output

tcp/0


The following card manufacturers were identified :

D4:F5:EF:60:4D:20 : Hewlett Packard Enterprise
D4:F5:EF:60:4D:23 : Hewlett Packard Enterprise
86420 - Ethernet MAC Addresses
-
Synopsis
This plugin gathers MAC addresses from various sources and consolidates them into a list.
Description
This plugin gathers MAC addresses discovered from both remote probing of the host (e.g. SNMP and Netbios) and from running local checks (e.g. ifconfig). It then consolidates the MAC addresses into a single, unique, and uniform list.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2015/10/16, Modified: 2025/06/10
Plugin Output

tcp/0

The following is a consolidated list of detected MAC addresses:
- D4:F5:EF:60:4D:20
- D4:F5:EF:60:4D:23
92439 - Explorer Search History
-
Synopsis
Nessus was able to gather a list of items searched for in the Windows UI.
Description
Nessus was able to gather evidence of cached search results from Windows Explorer searches.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0


Explorer search history report attached.

80305 - Git for Windows Detection
-
Synopsis
A version control client is installed on the remote Windows host.
Description
Git for Windows (also known as msysGit), a version control client, is installed on the remote Windows host.

Note: If multiple installs exist on the host for different user accounts, the user must be logged in prior to enumerating the Windows registry. Otherwise, the software installation may not appear in the report.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2014/12/30, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Git
Version : 2.47.1
34196 - Google Chrome Detection (Windows)
-
Synopsis
The remote Windows host contains a web browser.
Description
Google Chrome, a web browser from Google, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0511
Plugin Information
Published: 2008/09/12, Modified: 2025/07/10
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Google\Chrome\Application
Version : 143.0.7499.171

Note that Nessus only looked in the registry for evidence of Google
Chrome. If there are multiple users on this host, you may wish to
enable the 'Perform thorough tests' setting and re-scan. This will
cause Nessus to scan each local user's directory for installs.
97860 - HPE Smart Storage Administrator Installed
-
Synopsis
An enterprise storage controller management application is installed on the remote Windows host.
Description
HPE Smart Storage Administrator, an enterprise storage controller management application, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0623
Plugin Information
Published: 2017/03/21, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Smart Storage Administrator\ssa\
Version : 3.40.3.0

84502 - HSTS Missing From HTTPS Server
-
Synopsis
The remote web server is not enforcing HSTS.
Description
The remote HTTPS server is not enforcing HTTP Strict Transport Security (HSTS). HSTS is an optional response header that can be configured on the server to instruct the browser to only communicate via HTTPS. The lack of HSTS allows downgrade attacks, SSL-stripping man-in-the-middle attacks, and weakens cookie-hijacking protections.
See Also
Solution
Configure the remote web server to use HSTS.
Risk Factor
None
Plugin Information
Published: 2015/07/02, Modified: 2024/08/09
Plugin Output

tcp/6443/www


HTTP/1.1 401 Unauthorized

Date: Fri, 09 Jan 2026 20:42:59 GMT
Server: Apache
X-Frame-Options: SAMEORIGIN
Referrer-Policy: no-referrer
WWW-Authenticate: Basic realm="VisualSVN Server"
Content-Length: 381
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html; charset=iso-8859-1


The remote HTTPS server does not send the HTTP
"Strict-Transport-Security" header.

10107 - HTTP Server Type and Version
-
Synopsis
A web server is running on the remote host.
Description
This plugin attempts to determine the type and the version of the remote web server.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0931
Plugin Information
Published: 2000/01/04, Modified: 2020/10/30
Plugin Output

tcp/80/www

The remote web server type is :

nginx

10107 - HTTP Server Type and Version
-
Synopsis
A web server is running on the remote host.
Description
This plugin attempts to determine the type and the version of the remote web server.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0931
Plugin Information
Published: 2000/01/04, Modified: 2020/10/30
Plugin Output

tcp/81/www

The remote web server type is :

nginx

10107 - HTTP Server Type and Version
-
Synopsis
A web server is running on the remote host.
Description
This plugin attempts to determine the type and the version of the remote web server.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0931
Plugin Information
Published: 2000/01/04, Modified: 2020/10/30
Plugin Output

tcp/5800/www

The remote web server type is :

RealVNC/E4

10107 - HTTP Server Type and Version
-
Synopsis
A web server is running on the remote host.
Description
This plugin attempts to determine the type and the version of the remote web server.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0931
Plugin Information
Published: 2000/01/04, Modified: 2020/10/30
Plugin Output

tcp/6443/www

The remote web server type is :

Apache

10107 - HTTP Server Type and Version
-
Synopsis
A web server is running on the remote host.
Description
This plugin attempts to determine the type and the version of the remote web server.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0931
Plugin Information
Published: 2000/01/04, Modified: 2020/10/30
Plugin Output

tcp/8888/www

The remote web server type is :

""

12053 - Host Fully Qualified Domain Name (FQDN) Resolution
-
Synopsis
It was possible to resolve the name of the remote host.
Description
Nessus was able to resolve the fully qualified domain name (FQDN) of the remote host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2004/02/11, Modified: 2025/03/13
Plugin Output

tcp/0


172.17.100.31 resolves as TechE_Live_DB.

24260 - HyperText Transfer Protocol (HTTP) Information
-
Synopsis
Some information about the remote HTTP configuration can be extracted.
Description
This test gives some information about the remote HTTP protocol - the version used, whether HTTP Keep-Alive is enabled, etc...

This test is informational only and does not denote any security problem.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/01/30, Modified: 2024/02/26
Plugin Output

tcp/80/www


Response Code : HTTP/1.1 200

Protocol version : HTTP/1.1
HTTP/2 TLS Support: No
HTTP/2 Cleartext Support: No
SSL : no
Keep-Alive : no
Options allowed : (Not implemented)
Headers :

Date: Fri, 09 Jan 2026 20:45:16 GMT
Content-Type: text/html;charset=UTF-8
Content-Length: 2961
Connection: keep-alive
Set-Cookie: cftoken=0;Path=/;Domain=172.17.100.31;Secure;HttpOnly;SameSite=Strict
Set-Cookie: cfid=718d6a1c-87d8-4029-9cab-954cce8c5355;Path=/;Domain=172.17.100.31;Secure;HttpOnly;SameSite=Strict
X-Frame-Options: SAMEORIGIN
Strict-Transport-Security: max-age=31536000
X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff

Response Body :

<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1">
<meta name="description" content="">
<meta name="author" content="">
<title>TechExcel Software</title>
<link href="/WebClient/bootstrap-master/docs/dist/css/bootstrap.min.css" rel="stylesheet">
<link href="/WebClient/css/signin.css" rel="stylesheet">
<link href="/WebClient/css/Client/bootstrap.css" rel="stylesheet">
<script src="/WebClient/bootstrap-master/docs/assets/js/ie-emulation-modes-warning.js"></script>
</head>
<body>
<FORM>
<center><IMG SRC="/StaticData/Images/LOGO.JPG"
BORDER="0"
alt="Images/LOGO.JPG No File Found"></center>
<div class="container" >
<div class="col-sm-4">
<div class="panel panel-primary">
<div class="panel-heading">
<h3 class="panel-title" align="center">Head office Login</h3>
</div>
<div class="panel-body">
<a class="Link" href="/Focaps/Sessions/Login.cfm" >Backoffice - NSE/BSE/MCX-SX/MCX/NCDEX/NBFC</a>
<div class="clearfix">&nbsp;</div>
<a class="Link" href="/Depository/" >Depository(CDSL/NSDL)</a>
<div class="clearfix">&nbsp;</div>
<a class="Link" href="http://www.techexcel.in/corporate-actions/" >TechExcel Corporate Action Doc</a>
<div class="clearfix">&nbsp;</div>
</div>
</div>
</div>
<div class="col-sm-4">
<div class="panel panel-primary">
<div class="panel-heading">
<h3 class="panel-title" align="center">Middle office Login</h3>
</div>
<div class="panel-body">
<a class="Link" href="/LiveRisk/" >Live RMS</a>
<div class="clearfix">&nbsp;</div>
</div>
</div>
</div>
<!-- /.col-sm-4 -->
<div class="col-sm-4">
<div class="panel panel-primary">
<div class="panel-heading">
<h3 class="panel-title" align="center">Web Access Points</h3>
</div>
<div class="panel-body">
<a class="Link" href="/WebClient/" >Client Login(Mobile/Web)</a>
<div class="clearfix">&nbsp;</div>
<a class="Link" href="/WebLogin/index.cfm?Logintype=Branch" >Area/Region/Master/Main/Subs(9 Layers) Branch</a>
<div class="clearfix">&nbsp;</div>
<a class="Link" href="/WebLogin/index.cfm?Logintype=Group" >Family</a>
<div class="clearfix">&nbsp;</div>
<a class="Link" href="/WebLogin/index.cfm?Logintype=RO" >Relationship Officer</a>
<div class="clearfix">&nbsp;</div>
<a class="Link" href="/WebLogin/index.cfm?Logintype=RM" >Relationship Manager</a>
<div class="clearfix">&nbsp;</div>
<a class="Link" href="/WebLogin/index.cfm?Logintype=D" >Dealer</a>
<div class="clearfix">&nbsp;</div>
<a class="Link" href="/WebLogin/index.cfm?Logintype=I" >Introducer</a>
<div class="clearfix">&nbsp;</div>
<a class="Link" href="/WebLogin/index.cfm?Logintype=SUBBRANCH" >Remisier</a>
<div class="clearfix">&nbsp;</div>
</div>
</div>
</div>
<!-- /.col-sm-4 -->
</div>
<div class="page-header text-right">
<p><h6><a href="http://www.techexcel.in">Develop By Techexcel Software Solution Pvt. Ltd.&nbsp;&nbsp;&nbsp;</a></h6></p>
</div>
</FORM>
</body>
</html>

24260 - HyperText Transfer Protocol (HTTP) Information
-
Synopsis
Some information about the remote HTTP configuration can be extracted.
Description
This test gives some information about the remote HTTP protocol - the version used, whether HTTP Keep-Alive is enabled, etc...

This test is informational only and does not denote any security problem.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/01/30, Modified: 2024/02/26
Plugin Output

tcp/81/www


Response Code : HTTP/1.1 200

Protocol version : HTTP/1.1
HTTP/2 TLS Support: No
HTTP/2 Cleartext Support: No
SSL : no
Keep-Alive : no
Options allowed : (Not implemented)
Headers :

Date: Fri, 09 Jan 2026 20:45:16 GMT
Content-Type: text/html;charset=UTF-8
Content-Length: 2961
Connection: keep-alive
Set-Cookie: cftoken=0;Path=/;Domain=172.17.100.31;Secure;HttpOnly;SameSite=Strict
Set-Cookie: cfid=35e7eab1-da3b-4aec-a1ab-c255c724f958;Path=/;Domain=172.17.100.31;Secure;HttpOnly;SameSite=Strict
X-Frame-Options: SAMEORIGIN
Strict-Transport-Security: max-age=31536000
X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff

Response Body :

<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1">
<meta name="description" content="">
<meta name="author" content="">
<title>TechExcel Software</title>
<link href="/WebClient/bootstrap-master/docs/dist/css/bootstrap.min.css" rel="stylesheet">
<link href="/WebClient/css/signin.css" rel="stylesheet">
<link href="/WebClient/css/Client/bootstrap.css" rel="stylesheet">
<script src="/WebClient/bootstrap-master/docs/assets/js/ie-emulation-modes-warning.js"></script>
</head>
<body>
<FORM>
<center><IMG SRC="/StaticData/Images/LOGO.JPG"
BORDER="0"
alt="Images/LOGO.JPG No File Found"></center>
<div class="container" >
<div class="col-sm-4">
<div class="panel panel-primary">
<div class="panel-heading">
<h3 class="panel-title" align="center">Head office Login</h3>
</div>
<div class="panel-body">
<a class="Link" href="/Focaps/Sessions/Login.cfm" >Backoffice - NSE/BSE/MCX-SX/MCX/NCDEX/NBFC</a>
<div class="clearfix">&nbsp;</div>
<a class="Link" href="/Depository/" >Depository(CDSL/NSDL)</a>
<div class="clearfix">&nbsp;</div>
<a class="Link" href="http://www.techexcel.in/corporate-actions/" >TechExcel Corporate Action Doc</a>
<div class="clearfix">&nbsp;</div>
</div>
</div>
</div>
<div class="col-sm-4">
<div class="panel panel-primary">
<div class="panel-heading">
<h3 class="panel-title" align="center">Middle office Login</h3>
</div>
<div class="panel-body">
<a class="Link" href="/LiveRisk/" >Live RMS</a>
<div class="clearfix">&nbsp;</div>
</div>
</div>
</div>
<!-- /.col-sm-4 -->
<div class="col-sm-4">
<div class="panel panel-primary">
<div class="panel-heading">
<h3 class="panel-title" align="center">Web Access Points</h3>
</div>
<div class="panel-body">
<a class="Link" href="/WebClient/" >Client Login(Mobile/Web)</a>
<div class="clearfix">&nbsp;</div>
<a class="Link" href="/WebLogin/index.cfm?Logintype=Branch" >Area/Region/Master/Main/Subs(9 Layers) Branch</a>
<div class="clearfix">&nbsp;</div>
<a class="Link" href="/WebLogin/index.cfm?Logintype=Group" >Family</a>
<div class="clearfix">&nbsp;</div>
<a class="Link" href="/WebLogin/index.cfm?Logintype=RO" >Relationship Officer</a>
<div class="clearfix">&nbsp;</div>
<a class="Link" href="/WebLogin/index.cfm?Logintype=RM" >Relationship Manager</a>
<div class="clearfix">&nbsp;</div>
<a class="Link" href="/WebLogin/index.cfm?Logintype=D" >Dealer</a>
<div class="clearfix">&nbsp;</div>
<a class="Link" href="/WebLogin/index.cfm?Logintype=I" >Introducer</a>
<div class="clearfix">&nbsp;</div>
<a class="Link" href="/WebLogin/index.cfm?Logintype=SUBBRANCH" >Remisier</a>
<div class="clearfix">&nbsp;</div>
</div>
</div>
</div>
<!-- /.col-sm-4 -->
</div>
<div class="page-header text-right">
<p><h6><a href="http://www.techexcel.in">Develop By Techexcel Software Solution Pvt. Ltd.&nbsp;&nbsp;&nbsp;</a></h6></p>
</div>
</FORM>
</body>
</html>

24260 - HyperText Transfer Protocol (HTTP) Information
-
Synopsis
Some information about the remote HTTP configuration can be extracted.
Description
This test gives some information about the remote HTTP protocol - the version used, whether HTTP Keep-Alive is enabled, etc...

This test is informational only and does not denote any security problem.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/01/30, Modified: 2024/02/26
Plugin Output

tcp/5985/www


Response Code : HTTP/1.1 404 Not Found

Protocol version : HTTP/1.1
HTTP/2 TLS Support: No
HTTP/2 Cleartext Support: No
SSL : no
Keep-Alive : no
Options allowed : (Not implemented)
Headers :

Content-Type: text/html; charset=us-ascii
Date: Fri, 09 Jan 2026 20:45:15 GMT
Connection: close
Content-Length: 315

Response Body :

24260 - HyperText Transfer Protocol (HTTP) Information
-
Synopsis
Some information about the remote HTTP configuration can be extracted.
Description
This test gives some information about the remote HTTP protocol - the version used, whether HTTP Keep-Alive is enabled, etc...

This test is informational only and does not denote any security problem.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/01/30, Modified: 2024/02/26
Plugin Output

tcp/6443/www


Response Code : HTTP/1.1 401 Unauthorized

Protocol version : HTTP/1.1
HTTP/2 TLS Support: No
HTTP/2 Cleartext Support: No
SSL : yes
Keep-Alive : yes
Options allowed : (Not implemented)
Headers :

Date: Fri, 09 Jan 2026 20:45:16 GMT
Server: Apache
X-Frame-Options: SAMEORIGIN
Referrer-Policy: no-referrer
WWW-Authenticate: Basic realm="VisualSVN Server"
Content-Length: 381
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html; charset=iso-8859-1

Response Body :

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>401 Unauthorized</title>
</head><body>
<h1>Unauthorized</h1>
<p>This server could not verify that you
are authorized to access the document
requested. Either you supplied the wrong
credentials (e.g., bad password), or your
browser doesn't understand how to supply
the credentials required.</p>
</body></html>

24260 - HyperText Transfer Protocol (HTTP) Information
-
Synopsis
Some information about the remote HTTP configuration can be extracted.
Description
This test gives some information about the remote HTTP protocol - the version used, whether HTTP Keep-Alive is enabled, etc...

This test is informational only and does not denote any security problem.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/01/30, Modified: 2024/02/26
Plugin Output

tcp/8686/www


Response Code : HTTP/1.1 200 OK

Protocol version : HTTP/1.1
HTTP/2 TLS Support: No
HTTP/2 Cleartext Support: No
SSL : no
Keep-Alive : no
Options allowed : (Not implemented)
Headers :

Connection: keep-alive
Content-Type: text/html;charset=UTF-8
Content-Length: 2426
Date: Fri, 09 Jan 2026 20:45:16 GMT

Response Body :


<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1">
<meta name="description" content="">
<meta name="author" content="">
<title>TechExcel Software</title>



<link href="includes/css/bootstrap.min.css" rel="stylesheet">

<script src="includes/js/jquery.js"></script>
<script src="includes/js/bootstrap.min.js"></script>
<style>
/* Utility */
.centered { text-align: center !important; }
.inline{ display: inline !important; }
.margin10{ margin: 10px; }
.padding10{ padding: 10px; }
.margin0{ margin: 0px; }
.padding0{ padding: 0px; }
.footer {
margin-top: 45px;
padding: 35px 35px;
border-top: 1px solid #e5e5e5;
}
.footer p {
margin-bottom: 0;
color: #555;
}
body{ padding-top: 50px; }
</style>
</head>
<body data-spy="scroll">

<nav class="navbar navbar-inverse navbar-fixed-top" role="navigation">
<div class="container-fluid">

<div class="navbar-header">

<button type="button" class="navbar-toggle" data-toggle="collapse" data-target="#navbar-collapse">
<span class="sr-only">Toggle navigation</span>
<span class="icon-bar"></span>
<span class="icon-bar"></span>
<span class="icon-bar"></span>
</button>


</div>
</div>
</nav>


<div class="container">
<FORM NAME="Welcome">
<center><IMG SRC="/StaticData/Images/LOGO.JPG"
BORDER="0"
alt="Images/LOGO.JPG No File Found"></center>
<div class="container" >
<div class="col-sm-4">
<div class="panel panel-primary">
<div class="panel-heading">
<h3 class="panel-title" align="center">Logins</h3>
</div>
<div class="panel-body">


<a class="Link" href="/techRPA/?fwreinit=1" >techRPA</a>
<div class="clearfix">&nbsp;</div>


</div>
</div>
</div>


</div>

<div class="page-header text-right">
<p><h6><a href="http://www.techexcel.in">Developed By Techexcel Software Solution Pvt. Ltd.&nbsp;&nbsp;&nbsp;</a></h6></p>
</div>
</FORM>

</div>



<script>
$(function() {
// activate all drop downs
$('.dropdown-toggle').dropdown();
// Tooltips
$("[rel=tooltip]").tooltip();
})
</script>
</body>
</html>

24260 - HyperText Transfer Protocol (HTTP) Information
-
Synopsis
Some information about the remote HTTP configuration can be extracted.
Description
This test gives some information about the remote HTTP protocol - the version used, whether HTTP Keep-Alive is enabled, etc...

This test is informational only and does not denote any security problem.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/01/30, Modified: 2024/02/26
Plugin Output

tcp/8888/www


Response Code : HTTP/1.1 200 OK

Protocol version : HTTP/1.1
HTTP/2 TLS Support: No
HTTP/2 Cleartext Support: No
SSL : no
Keep-Alive : no
Options allowed : (Not implemented)
Headers :

Cache-Control: private
Content-Type: text/html;charset=UTF-8
Server: ""
Set-Cookie: cftoken=0;Path=/;Domain=172.17.100.31%3A8888;Secure;HttpOnly;SameSite=Strict
Set-Cookie: cfid=fd86d542-4d1d-41ae-8fa0-a6938e0ab25e;Path=/;Domain=172.17.100.31%3A8888;Secure;HttpOnly;SameSite=Strict
X-FRAME-OPTIONS: SAMEORIGIN
X-Xss-Protection: 1; mode=block
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000
Date: Fri, 09 Jan 2026 20:45:16 GMT
Content-Length: 2961

Response Body :

<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1">
<meta name="description" content="">
<meta name="author" content="">
<title>TechExcel Software</title>
<link href="/WebClient/bootstrap-master/docs/dist/css/bootstrap.min.css" rel="stylesheet">
<link href="/WebClient/css/signin.css" rel="stylesheet">
<link href="/WebClient/css/Client/bootstrap.css" rel="stylesheet">
<script src="/WebClient/bootstrap-master/docs/assets/js/ie-emulation-modes-warning.js"></script>
</head>
<body>
<FORM>
<center><IMG SRC="/StaticData/Images/LOGO.JPG"
BORDER="0"
alt="Images/LOGO.JPG No File Found"></center>
<div class="container" >
<div class="col-sm-4">
<div class="panel panel-primary">
<div class="panel-heading">
<h3 class="panel-title" align="center">Head office Login</h3>
</div>
<div class="panel-body">
<a class="Link" href="/Focaps/Sessions/Login.cfm" >Backoffice - NSE/BSE/MCX-SX/MCX/NCDEX/NBFC</a>
<div class="clearfix">&nbsp;</div>
<a class="Link" href="/Depository/" >Depository(CDSL/NSDL)</a>
<div class="clearfix">&nbsp;</div>
<a class="Link" href="http://www.techexcel.in/corporate-actions/" >TechExcel Corporate Action Doc</a>
<div class="clearfix">&nbsp;</div>
</div>
</div>
</div>
<div class="col-sm-4">
<div class="panel panel-primary">
<div class="panel-heading">
<h3 class="panel-title" align="center">Middle office Login</h3>
</div>
<div class="panel-body">
<a class="Link" href="/LiveRisk/" >Live RMS</a>
<div class="clearfix">&nbsp;</div>
</div>
</div>
</div>
<!-- /.col-sm-4 -->
<div class="col-sm-4">
<div class="panel panel-primary">
<div class="panel-heading">
<h3 class="panel-title" align="center">Web Access Points</h3>
</div>
<div class="panel-body">
<a class="Link" href="/WebClient/" >Client Login(Mobile/Web)</a>
<div class="clearfix">&nbsp;</div>
<a class="Link" href="/WebLogin/index.cfm?Logintype=Branch" >Area/Region/Master/Main/Subs(9 Layers) Branch</a>
<div class="clearfix">&nbsp;</div>
<a class="Link" href="/WebLogin/index.cfm?Logintype=Group" >Family</a>
<div class="clearfix">&nbsp;</div>
<a class="Link" href="/WebLogin/index.cfm?Logintype=RO" >Relationship Officer</a>
<div class="clearfix">&nbsp;</div>
<a class="Link" href="/WebLogin/index.cfm?Logintype=RM" >Relationship Manager</a>
<div class="clearfix">&nbsp;</div>
<a class="Link" href="/WebLogin/index.cfm?Logintype=D" >Dealer</a>
<div class="clearfix">&nbsp;</div>
<a class="Link" href="/WebLogin/index.cfm?Logintype=I" >Introducer</a>
<div class="clearfix">&nbsp;</div>
<a class="Link" href="/WebLogin/index.cfm?Logintype=SUBBRANCH" >Remisier</a>
<div class="clearfix">&nbsp;</div>
</div>
</div>
</div>
<!-- /.col-sm-4 -->
</div>
<div class="page-header text-right">
<p><h6><a href="http://www.techexcel.in">Develop By Techexcel Software Solution Pvt. Ltd.&nbsp;&nbsp;&nbsp;</a></h6></p>
</div>
</FORM>
</body>
</html>

171410 - IP Assignment Method Detection
-
Synopsis
Enumerates the IP address assignment method(static/dynamic).
Description
Enumerates the IP address assignment method(static/dynamic).
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/02/14, Modified: 2025/12/15
Plugin Output

tcp/0

+ LAN_31
+ IPv4
- Address : 172.17.100.31
Assign Method : static
+ Loopback Pseudo-Interface 1
+ IPv4
- Address : 127.0.0.1
Assign Method : static
+ IPv6
- Address : ::1
Assign Method : static
+ CrossConnect
+ IPv4
- Address : 20.20.20.31
Assign Method : static

179947 - Intel CPUID detection
-
Synopsis
The processor CPUID was detected on the remote host.
Description
The CPUID of the Intel processor was detected on the remote host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/08/18, Modified: 2025/12/15
Plugin Output

tcp/135/epmap

Nessus was able to extract the following cpuid: 50654

92421 - Internet Explorer Typed URLs
-
Synopsis
Nessus was able to enumerate URLs that were manually typed into the Internet Explorer address bar.
Description
Nessus was able to generate a list URLs that were manually typed into the Internet Explorer address bar.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2024/05/08
Plugin Output

tcp/0

http://go.microsoft.com/fwlink/p/?LinkId=255141
http://172.17.100.31:8505/techstaff/index.cfm
http://172.17.100.31:8505/techstaff
http://172.17.100.33:8505/FOCAPS/Common/Admin_Frame.cfm
http://172.17.100.33:8505/
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://127.0.0.1:8080/
http://127.0.0.1:8505/ProcessView.cfm?Pass
http://172.17.100.31:8505/Focaps/Sessions/Login.cfm
http://127.0.0.1:8505/techstaff
http://127.0.0.1:8555/
http://172.17.100.31/
http://172.17.100.31/staticdata/wsdl/samplekyc.cfm
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://172.17.100.31:8505/KRA/home.cfm
http://127.0.0.1:8505/Focaps/Sessions/Login.cfm
https://172.17.100.131/
http://172.17.100.33:8505/
http://www.google.com/
http://172.17.100.33:8505/Replication/
http://127.0.0.1:8686/
http://127.0.0.1:8989/
http://172.17.100.33:8505/replication/index1.cfm
http://172.17.100.31:8505/
http://127.0.0.1:8505/
http://127.0.0.1:8555/TechBoRest/api/documentation
https://backoffice.lkp.net.in:8080/techexcelapi/index.cfm

Internet Explorer typed URL report attached.

106658 - JQuery Detection
-
Synopsis
The web server on the remote host uses JQuery.
Description
Nessus was able to detect JQuery on the remote host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2018/02/07, Modified: 2024/02/08
Plugin Output

tcp/8686/www


URL : http://172.17.100.31:8686/includes/js/jquery.js
Version : unknown

53513 - Link-Local Multicast Name Resolution (LLMNR) Detection
-
Synopsis
The remote device supports LLMNR.
Description
The remote device answered to a Link-local Multicast Name Resolution (LLMNR) request. This protocol provides a name lookup service similar to NetBIOS or DNS. It is enabled by default on modern Windows versions.
See Also
Solution
Make sure that use of this software conforms to your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2011/04/21, Modified: 2023/10/17
Plugin Output

udp/5355/llmnr


According to LLMNR, the name of the remote host is 'TechE_Live_DB'.

160301 - Link-Local Multicast Name Resolution (LLMNR) Service Detection
-
Synopsis
Verify status of the LLMNR service on the remote host.
Description
The Link-Local Multicast Name Resolution (LLMNR) service allows both IPv4 and IPv6 hosts to perform name resolution for hosts on the same local link
See Also
Solution
Make sure that use of this software conforms to your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2022/04/28, Modified: 2022/12/29
Plugin Output

tcp/445/cifs


LLMNR Key SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast not found.

24871 - Logical Drive Insecure Filesystem Enumeration (WMI)
-
Synopsis
The remote host is using an insecure filesystem.
Description
By making certain WMI queries, it is possible to extract the list of logical drives of the remote host that do not use NTFS.
Solution
Migrate any reported filesystems to NTFS.
Risk Factor
None
Plugin Information
Published: 2007/03/20, Modified: 2025/12/15
Plugin Output

tcp/0


The following drives are not formatted with NTFS :

Caption : E:
Description : Removable Disk
92424 - MUICache Program Execution History
-
Synopsis
Nessus was able to enumerate recently executed programs on the remote host.
Description
Nessus was able to query the MUIcache registry key to find evidence of program execution.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/16
Plugin Output

tcp/0

report output too big - ending list here

51351 - Microsoft .NET Framework Detection
-
Synopsis
A software framework is installed on the remote host.
Description
Microsoft .NET Framework, a software framework for Microsoft Windows operating systems, is installed on the remote host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0655
Plugin Information
Published: 2010/12/20, Modified: 2025/10/15
Plugin Output

tcp/445/cifs


Nessus detected 5 installs of Microsoft .NET Framework:

Path : C:\Windows\Microsoft.NET\Framework64\v2.0.50727
Version : 2.0.50727
Full Version : 2.0.50727.4927
SP : 2

Path : C:\Windows\Microsoft.NET\Framework64\v3.0
Version : 3.0
Full Version : 3.0.30729.4926
SP : 2

Path : C:\Windows\Microsoft.NET\Framework64\v3.5\
Version : 3.5
Full Version : 3.5.30729.4926
SP : 1

Path : C:\Windows\Microsoft.NET\Framework64\v4.0.30319\
Version : 4.7.2
Full Version : 4.7.03190
Install Type : Full
Release : 461814

Path : C:\Windows\Microsoft.NET\Framework64\v4.0.30319\
Version : 4.7.2
Full Version : 4.7.03190
Install Type : Client
Release : 461814

24242 - Microsoft .NET Handlers Enumeration
-
Synopsis
It is possible to enumerate the remote .NET handlers used by the remote web server.
Description
It is possible to obtain the list of handlers the remote ASP.NET web server supports.
See Also
Solution
None
Risk Factor
None
Plugin Information
Published: 2007/01/26, Modified: 2018/11/15
Plugin Output

tcp/8888/www


The remote extensions are handled by the remote ASP.NET server :

- .ashx
- .aspx
- .asmx

99364 - Microsoft .NET Security Rollup Enumeration
-
Synopsis
This plugin enumerates installed Microsoft .NET security rollups.
Description
Nessus was able to enumerate the Microsoft .NET security rollups installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2017/04/14, Modified: 2025/10/23
Plugin Output

tcp/445/cifs


Nessus detected 2 installs of Microsoft .NET Framework:

Path : C:\Windows\Microsoft.NET\Framework\v4.0.30319\system.core.dll
Version : 4.7.4115.0
.NET Version : 4.7.2
Associated KB : 5044016
Latest effective update level : 10_2024

Path : C:\Windows\winsxs\*system.printing_31bf3856ad364e35*
Version : 3.0.6920.9063
.NET Version : 3.5
Associated KB : 5044022
Latest effective update level : 10_2024

192148 - Microsoft Azure Data Studio Installed (Windows)
-
Synopsis
Microsoft Azure Data Studio is installed on the remote Windows host.
Description
Microsoft Azure Data Studio is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2024/03/15, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\Program Files\Azure Data Studio\
Version : 1.51.1.0

176212 - Microsoft Edge Add-on Enumeration (Windows)
-
Synopsis
One or more Microsoft Egde browser extensions are installed on the remote host.
Description
Nessus was able to enumerate Microsoft Edge browser extensions installed on the remote host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/05/22, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


User : Administrator
|- Browser : Microsoft Edge
|- Add-on information :

Name : unknown
Version : 1.94.1
Path : C:\Users\Administrator\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.94.1_0

Name : Edge relevant text changes
Description : Edge relevant text changes on select websites to improve user experience and precisely surfaces the action they want to take.
Version : 1.2.1
Path : C:\Users\Administrator\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha\1.2.1_0

User : techexcel
|- Browser : Microsoft Edge
|- Add-on information :

Name : Microsoft Edge Unminification Extension
Description : Provides Named Function Ranges from typescript's compiler to augment sourcemap scopes information
Version : 135.0.3176.0
Path : C:\Users\techexcel\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\cgjgjfacjflmgphhhepmbhhbgjieaecn\135.0.3176.0_0

Name : unknown
Version : 1.99.1
Path : C:\Users\techexcel\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.99.1_0

Name : Edge relevant text changes
Description : Edge relevant text changes on select websites to improve user experience and precisely surfaces the action they want to take.
Version : 1.2.1
Path : C:\Users\techexcel\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha\1.2.1_0

Name : Microsoft Edge DevTools Enhancements
Description : Microsoft Edge DevTools Enhancements
Version : 113.0.1765.0
Path : C:\Users\techexcel\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\kfbdpdaobnofkbopebjglnaadopfikhh\113.0.1765.0_0
136969 - Microsoft Edge Chromium Installed
-
Synopsis
Microsoft Edge (Chromium-based) is installed on the remote host.
Description
Microsoft Edge (Chromium-based), a Chromium-based web browser, is installed on the remote host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2020/05/29, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft\Edge\Application
Version : 143.0.3650.96
Channel : stable
72879 - Microsoft Internet Explorer Enhanced Security Configuration Detection
-
Synopsis
The remote host supports IE Enhanced Security Configuration.
Description
Nessus detects if the remote Windows host supports IE Enhanced Security Configuration (ESC) and if IE ESC features are enabled or disabled.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2014/03/07, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Type : Admin Groups
Is Enabled : True

Type : User Groups
Is Enabled : True

162560 - Microsoft Internet Explorer Installed
-
Synopsis
A web browser is installed on the remote Windows host.
Description
Microsoft Internet Explorer, a web browser bundled with Microsoft Windows, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2022/06/28, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\Windows\system32\mshtml.dll
Version : 11.0.17763.7009

72367 - Microsoft Internet Explorer Version Detection
-
Synopsis
Internet Explorer is installed on the remote host.
Description
The remote Windows host contains Internet Explorer, a web browser created by Microsoft.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0509
Plugin Information
Published: 2014/02/06, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Version : 11.1790.17763.0

139615 - Microsoft Internet Information Services (IIS) Installed
-
Synopsis
Checks Windows registry keys and executables for a Microsoft Internet Information Services (IIS) installation.
Description
Microsoft Internet Information Services installation (IIS) has been detected on the remote Windows host.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0030
XREF IAVT:0001-T-0944
Plugin Information
Published: 2020/08/17, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\Windows\system32\inetsrv
Version : 10.0.17763.5830

140655 - Microsoft Internet Information Services (IIS) Sites Enumeration
-
Synopsis
Checks IIS configuration file for configured sites and their bound addresses.
Description
Microsoft Internet Information Services configuration file has been parsed to extract information about the existing sites, their protocols, domains and IP addresses.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2020/09/18, Modified: 2025/12/15
Plugin Output

tcp/445/cifs

Nessus found the following sites configured on the remote host:
+ site name: BackOffice
+ binding 0
- IP address : *
- port : 8888
- domain :
- protocol : http
66424 - Microsoft Malicious Software Removal Tool Installed
-
Synopsis
An antimalware application is installed on the remote Windows host.
Description
The Microsoft Malicious Software Removal Tool is installed on the remote host. This tool is an application that attempts to detect and remove known malware from Windows systems.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/05/15, Modified: 2023/01/10
Plugin Output

tcp/445/cifs


File : C:\Windows\system32\MRT.exe
Version : 5.130.24110.1001
Release at last run : unknown
Report infection information to Microsoft : Yes
174413 - Microsoft ODBC Driver for SQL Server Installed (Windows)
-
Synopsis
Microsoft ODBC Driver for SQL Server is installed on the remote Windows host.
Description
Microsoft ODBC Driver for SQL Server is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/04/17, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Path : C:\Windows\System32\msodbcsql17.dll
Version : 17.10.6.1
174405 - Microsoft OLE DB Driver for SQL Server Installed (Windows)
-
Synopsis
Microsoft OLE DB Driver for SQL Server is installed on the remote Windows host.
Description
Microsoft OLE DB Driver for SQL Server is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/04/17, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Path : C:\Windows\System32\msoledbsql.dll
Version : 18.7.4.0

92427 - Microsoft Paint Recent File History
-
Synopsis
Nessus was able to enumerate files opened in Microsoft Paint on the remote host.
Description
Nessus was able to generate a list of files opened using the Microsoft Paint program.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

Production
- D:\Techexcel Setup\Raid conf1.jpg
- D:\Techexcel Setup\Raid conf2.jpg
- C:\Users\Administrator\Documents\Before.png
- D:\Techexcel Setup\Raid conf3.jpg
- C:\Users\Administrator\Documents\te error.png
techexcel
- D:\Techexcel Setup\SQLPatch_Prerequisite\DB_Logins_08052024.png
- D:\Techexcel\Lucee\tomcat\webapps\ROOT\depository\ireport\Logo.JPG
- D:\Techexcel\Lucee\tomcat\webapps\ROOT\depository\ireport\logo_Comm.jpg
- D:\Techexcel Setup\Patch_prerequisites\All_services.png
- D:\Techexcel\Lucee\tomcat\webapps\ROOT\depository\ireport\R2logo.jpg
- D:\Techexcel\Lucee\tomcat\webapps\ROOT\depository\ireport\CDSL_LOGO.JPG
- D:\Techexcel Setup\SQLPatch_Prerequisite\SQL_Version_SName.png
- D:\Techexcel\Lucee\tomcat\webapps\ROOT\depository\ireport\NSDL_LOGO.JPG
- \\172.17.100.33\techexcel$\Lucee\tomcat\webapps\ROOT\WEB-INF\lucee\classes\LOGO.JPG

57033 - Microsoft Patch Bulletin Feasibility Check
-
Synopsis
Nessus is able to check for Microsoft patch bulletins.
Description
Using credentials supplied in the scan policy, Nessus is able to collect information about the software and patches installed on the remote Windows host and will use that information to check for missing Microsoft security updates.

Note that this plugin is purely informational.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/06, Modified: 2021/07/12
Plugin Output

tcp/445/cifs



Nessus is able to test for missing patches using :
Nessus

125835 - Microsoft Remote Desktop Connection Installed
-
Synopsis
A graphical interface connection utility is installed on the remote Windows host
Description
Microsoft Remote Desktop Connection (also known as Remote Desktop Protocol or Terminal Services Client) is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2019/06/12, Modified: 2022/10/10
Plugin Output

tcp/0


Path : C:\Windows\\System32\\mstsc.exe
Version : 10.0.17763.5830
118095 - Microsoft SQL Server Management Studio (SSMS) Installed
-
Synopsis
A SQL Server Management solution is installed on the remote Windows host.
Description
Microsoft SQL Server Management Studio (SSMS) is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0805
Plugin Information
Published: 2018/10/12, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\Program Files (x86)\Microsoft SQL Server Management Studio 18\Common7\IDE\
Version : 2019.150.18390.0

93962 - Microsoft Security Rollup Enumeration
-
Synopsis
This plugin enumerates installed Microsoft security rollups.
Description
Nessus was able to enumerate the Microsoft security rollups installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/10/11, Modified: 2025/11/18
Plugin Output

tcp/445/cifs


Cumulative Rollup : 03_2025 [KB5053596]
Cumulative Rollup : 02_2025
Cumulative Rollup : 01_2025
Cumulative Rollup : 12_2024
Cumulative Rollup : 11_2024
Cumulative Rollup : 10_2024
Cumulative Rollup : 09_2024
Cumulative Rollup : 08_2024
Cumulative Rollup : 07_2024
Cumulative Rollup : 06_2024
Cumulative Rollup : 05_2024
Cumulative Rollup : 04_2024
Cumulative Rollup : 03_2024
Cumulative Rollup : 02_2024
Cumulative Rollup : 01_2024
Cumulative Rollup : 12_2023
Cumulative Rollup : 11_2023
Cumulative Rollup : 10_2023
Cumulative Rollup : 09_2023
Cumulative Rollup : 08_2023
Cumulative Rollup : 07_2023
Cumulative Rollup : 06_2023
Cumulative Rollup : 05_2023
Cumulative Rollup : 04_2023
Cumulative Rollup : 03_2023
Cumulative Rollup : 02_2023
Cumulative Rollup : 01_2023
Cumulative Rollup : 12_2022
Cumulative Rollup : 11_2022
Cumulative Rollup : 10_2022
Cumulative Rollup : 09_2022
Cumulative Rollup : 08_2022
Cumulative Rollup : 07_2022
Cumulative Rollup : 06_2022
Cumulative Rollup : 05_2022
Cumulative Rollup : 04_2022
Cumulative Rollup : 03_2022
Cumulative Rollup : 02_2022
Cumulative Rollup : 01_2022
Cumulative Rollup : 12_2021
Cumulative Rollup : 11_2021
Cumulative Rollup : 10_2021
Cumulative Rollup : 09_2021
Cumulative Rollup : 08_2021 [KB5005030]
Cumulative Rollup : 07_2021
Cumulative Rollup : 06_2021_07_01
Cumulative Rollup : 06_2021
Cumulative Rollup : 05_2021
Cumulative Rollup : 04_2021
Cumulative Rollup : 03_2021
Cumulative Rollup : 02_2021
Cumulative Rollup : 01_2021
Cumulative Rollup : 12_2020
Cumulative Rollup : 11_2020
Cumulative Rollup : 10_2020
Cumulative Rollup : 09_2020
Cumulative Rollup : 08_2020
Cumulative Rollup : 07_2020
Cumulative Rollup : 06_2020
Cumulative Rollup : 05_2020
Cumulative Rollup : 04_2020
Cumulative Rollup : 03_2020
Cumulative Rollup : 02_2020
Cumulative Rollup : 01_2020
Cumulative Rollup : 12_2019
Cumulative Rollup : 11_2019
Cumulative Rollup : 10_2019
Cumulative Rollup : 09_2019
Cumulative Rollup : 08_2019
Cumulative Rollup : 07_2019
Cumulative Rollup : 06_2019
Cumulative Rollup : 05_2019
Cumulative Rollup : 04_2019
Cumulative Rollup : 03_2019
Cumulative Rollup : 02_2019
Cumulative Rollup : 01_2019
Cumulative Rollup : 12_2018
Cumulative Rollup : 11_2018
Cumulative Rollup : 10_2018

Latest effective update level : 03_2025
File checked : C:\Windows\system32\ntoskrnl.exe
File version : 10.0.17763.7009
Associated KB : 5053596
136618 - Microsoft Visual Studio Code Extensions Installed
-
Synopsis
One or more extensions for an integrated development environment software application are installed on the remote Windows host.
Description
One or more extensions for Microsoft Visual Studio Code, an integrated development environment software application, are installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2020/05/15, Modified: 2025/12/15
Plugin Output

tcp/445/cifs

The following extensions of Visual Studio code were found:


Extension : vs-code::better-comments
Path : C:\Users\techexcel\.vscode\extensions\aaron-bond.better-comments-3.0.2\
Version : 3.0.2

Extension : vs-code::coldfusionsymbols
Path : C:\Users\techexcel\.vscode\extensions\dalucema.coldfusionsymbols-0.0.3\
Version : 0.0.3

Extension : vs-code::auto-close-tag
Path : C:\Users\techexcel\.vscode\extensions\formulahendry.auto-close-tag-0.5.15\
Version : 0.5.15

Extension : vs-code::svn-scm
Path : C:\Users\techexcel\.vscode\extensions\johnstoncode.svn-scm-2.17.0\
Version : 2.17.0

Extension : vs-code::vscode-cfml
Path : C:\Users\techexcel\.vscode\extensions\kamasamak.vscode-cfml-0.5.4\
Version : 0.5.4

Extension : vs-code::debugpy
Path : C:\Users\techexcel\.vscode\extensions\ms-python.debugpy-2025.14.1-win32-x64\
Version : 2025.14.1

Extension : vs-code::debugpy
Path : C:\Users\techexcel\.vscode\extensions\ms-python.debugpy-2025.16.0-win32-x64\
Version : 2025.16.0

Extension : vs-code::python
Path : C:\Users\techexcel\.vscode\extensions\ms-python.python-2025.16.0-win32-x64\
Version : 2025.16.0

Extension : vs-code::python
Path : C:\Users\techexcel\.vscode\extensions\ms-python.python-2025.18.0-win32-x64\
Version : 2025.18.0

Extension : vs-code::vscode-pylance
Path : C:\Users\techexcel\.vscode\extensions\ms-python.vscode-pylance-2025.10.2\
Version : 2025.10.2

Extension : vs-code::vscode-pylance
Path : C:\Users\techexcel\.vscode\extensions\ms-python.vscode-pylance-2025.8.3\
Version : 2025.8.3

Extension : vs-code::vscode-python-envs
Path : C:\Users\techexcel\.vscode\extensions\ms-python.vscode-python-envs-1.10.0-win32-x64\
Version : 1.10.0

Extension : vs-code::vscode-python-envs
Path : C:\Users\techexcel\.vscode\extensions\ms-python.vscode-python-envs-1.12.0-win32-x64\
Version : 1.12.0

Extension : vs-code::jupyter
Path : C:\Users\techexcel\.vscode\extensions\ms-toolsai.jupyter-2025.7.0-win32-x64\
Version : 2025.7.0

Extension : vs-code::jupyter
Path : C:\Users\techexcel\.vscode\extensions\ms-toolsai.jupyter-2025.8.0-win32-x64\
Version : 2025.8.0

Extension : vs-code::jupyter
Path : C:\Users\techexcel\.vscode\extensions\ms-toolsai.jupyter-2025.9.1-win32-x64\
Version : 2025.9.1

Extension : vs-code::jupyter-keymap
Path : C:\Users\techexcel\.vscode\extensions\ms-toolsai.jupyter-keymap-1.1.2\
Version : 1.1.2

Extension : vs-code::jupyter-renderers
Path : C:\Users\techexcel\.vscode\extensions\ms-toolsai.jupyter-renderers-1.3.0\
Version : 1.3.0

Extension : vs-code::vscode-jupyter-cell-tags
Path : C:\Users\techexcel\.vscode\extensions\ms-toolsai.vscode-jupyter-cell-tags-0.1.9\
Version : 0.1.9

Extension : vs-code::vscode-jupyter-slideshow
Path : C:\Users\techexcel\.vscode\extensions\ms-toolsai.vscode-jupyter-slideshow-0.1.6\
Version : 0.1.6

Extension : vs-code::vscode-coldbox
Path : C:\Users\techexcel\.vscode\extensions\ortus-solutions.vscode-coldbox-1.1.1\
Version : 1.1.1

Extension : vs-code::material-icon-theme
Path : C:\Users\techexcel\.vscode\extensions\pkief.material-icon-theme-5.27.0\
Version : 5.27.0

Extension : vs-code::material-icon-theme
Path : C:\Users\techexcel\.vscode\extensions\pkief.material-icon-theme-5.29.0\
Version : 5.29.0

Extension : vs-code::cfgoto
Path : C:\Users\techexcel\.vscode\extensions\rohithkrajan.cfgoto-0.0.3\
Version : 0.0.3

Extension : vs-code::vscode-icons
Path : C:\Users\techexcel\.vscode\extensions\vscode-icons-team.vscode-icons-12.15.0\
Version : 12.15.0

122256 - Microsoft Visual Studio Code Installed
-
Synopsis
An integrated development environment software application is installed on the remote Windows host.
Description
Microsoft Visual Studio Code, an integrated development environment software application, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2019/02/15, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\
Version : 1.106.3
File Version : 1.105.0.0
265694 - Microsoft Visual Studio Tools for Applications Installed (Windows)
-
Synopsis
The remote Windows host has an integrated development environment installed.
Description
Microsoft Visual Studio Tools for Applications (VSTA) is a set of tools that independent software vendors (ISVs) can use to build customization abilities into their applications for both automation and extensibility, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/09/22, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\Program Files\Common Files\Microsoft Shared\VSTA\15.0\Bin\VstaCore.dll
Version : 15.0.27520
product_version : 2017

10902 - Microsoft Windows 'Administrators' Group User List
-
Synopsis
There is at least one user in the 'Administrators' group.
Description
Using the supplied credentials, it is possible to extract the member list of the 'Administrators' group. Members of this group have complete access to the remote system.
Solution
Verify that each member of the group should have this type of access.
Risk Factor
None
Plugin Information
Published: 2002/03/15, Modified: 2018/05/16
Plugin Output

tcp/445/cifs


The following users are members of the 'Administrators' group :

- TECHE_LIVE_DB\Production (User)
- TECHE_LIVE_DB\LKPAdmin (User)
- TECHE_LIVE_DB\techexcel (User)
- TECHE_LIVE_DB\Techrobot (User)
- TECHE_LIVE_DB\Backoffice (User)
- TECHE_LIVE_DB\uatlkp (User)
- TECHE_LIVE_DB\tidua (User)
48763 - Microsoft Windows 'CWDIllegalInDllSearch' Registry Setting
-
Synopsis
CWDIllegalInDllSearch Settings: Improper settings could allow code execution attacks.
Description
Windows Hosts can be hardened against DLL hijacking attacks by setting the The 'CWDIllegalInDllSearch' registry entry in to one of the following settings:

- 0xFFFFFFFF (Removes the current working directory from the default DLL search order)

- 1 (Blocks a DLL Load from the current working directory if the current working directory is set to a WebDAV folder)

- 2 (Blocks a DLL Load from the current working directory if the current working directory is set to a remote folder)
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/08/26, Modified: 2019/12/20
Plugin Output

tcp/445/cifs


Name : SYSTEM\CurrentControlSet\Control\Session Manager\CWDIllegalInDllSearch
Value : Registry Key Empty or Missing

70615 - Microsoft Windows AutoRuns Boot Execute
-
Synopsis
Report programs that startup associates with session manager subsystem.
Description
Report registry startup locations associated with the session manager subsystem during boot time.

These registry keys start-up with the smss.exe service during boot time and perform system tasks that cannot be performed while Windows is running.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0

+ HKLM\System\CurrentControlSet\Control\Session Manager\bootexecute
- autocheck autochk /q /v *

70616 - Microsoft Windows AutoRuns Codecs
-
Synopsis
Report programs set to normally start with multimedia.
Description
Codecs are encoders and decoders for digital data streams commonly associated with video and audio playback.

The following keys are codecs that are set to start automatically to control different types of digital media encoding and decoding.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
- vidc.yvu9 : tsbyuv.dll
- vidc.mrle : msrle32.dll
- vidc.iyuv : iyuv_32.dll
- wavemapper : msacm32.drv
- msacm.msadpcm : msadp32.acm
- vidc.yuy2 : msyuv.dll
- vidc.uyvy : msyuv.dll
- vidc.msvc : msvidc32.dll
- msacm.imaadpcm : imaadp32.acm
- msacm.msg711 : msg711.acm
- msacm.msgsm610 : msgsm32.acm
- msacm.l3acm : C:\Windows\System32\l3codeca.acm
- vidc.yvyu : msyuv.dll
- midimapper : midimap.dll
- vidc.i420 : iyuv_32.dll


+ HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32
- vidc.yvu9 : tsbyuv.dll
- vidc.mrle : msrle32.dll
- vidc.iyuv : iyuv_32.dll
- wavemapper : msacm32.drv
- msacm.msadpcm : msadp32.acm
- vidc.yuy2 : msyuv.dll
- vidc.uyvy : msyuv.dll
- vidc.msvc : msvidc32.dll
- msacm.imaadpcm : imaadp32.acm
- msacm.msg711 : msg711.acm
- msacm.msgsm610 : msgsm32.acm
- msacm.l3acm : C:\Windows\SysWOW64\l3codeca.acm
- vidc.cvid : iccvid.dll
- vidc.yvyu : msyuv.dll
- midimapper : midimap.dll
- vidc.i420 : iyuv_32.dll


+ HKLM\Software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance
+ CLSID : {129D7E40-C10D-11D0-AFB9-00AA00B67A42}
- Name : DV Muxer
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {1643E180-90F5-11CE-97D5-00AA0055595A}
- Name : Color Space Converter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {187463A0-5BB7-11D3-ACBE-0080C75E246E}
- Name : WM ASF Reader
- Value : C:\Windows\System32\qasf.dll

+ CLSID : {1B544C20-FD0B-11CE-8C63-00AA0044B51E}
- Name : AVI Splitter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {1DA08500-9EDC-11CF-BC10-00AA00AC74F6}
- Name : VGA 16 Color Ditherer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {1f26a602-2b5c-4b63-b8e8-9ea5c1a7dc2e}
- Name : SBE2MediaTypeProfile
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {212690FB-83E5-4526-8FD7-74478B7939CD}
- Name : Microsoft DTV-DVD Video Decoder
- Value : C:\Windows\System32\msmpeg2vdec.dll

+ CLSID : {280A3020-86CF-11D1-ABE6-00A0C905F375}
- Name : AC3 Parser Filter
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {2DB47AE5-CF39-43C2-B4D6-0CD8D90946F4}
- Name : StreamBufferSink
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {301056D0-6DFF-11D2-9EEB-006008039E37}
- Name : MJPEG Decompressor
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {336475D0-942A-11CE-A870-00AA002FEAB5}
- Name : MPEG-I Stream Splitter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {33FACFE0-A9BE-11D0-A520-00A0D10129C0}
- Name : SAMI (CC) Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {370A1D5D-DDEB-418C-81CD-189E0D4FA443}
- Name : VBI Codec
- Value : C:\Windows\System32\VBICodec.ax

+ CLSID : {3AE86B20-7BE8-11D1-ABE6-00A0C905F375}
- Name : MPEG-2 Splitter
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {3D07A539-35CA-447C-9B05-8D85CE924F9E}
- Name : Closed Captions Analysis Filter
- Value : C:\Windows\System32\cca.dll

+ CLSID : {3E458037-0CA6-41aa-A594-2AA6C02D709B}
- Name : SBE2FileScan
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {42150CD9-CA9A-4EA5-9939-30EE037F6E74}
- Name : Microsoft MPEG-2 Video Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {48025243-2D39-11CE-875D-00608CB78066}
- Name : Internal Script Command Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {4A2286E0-7BEF-11CE-9BD9-0000E202599C}
- Name : MPEG Audio Decoder
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {4EB31670-9FC6-11CF-AF6E-00AA00B67A42}
- Name : DV Splitter
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {51B4ABF3-748F-4E3B-A276-C828330E926A}
- Name : Video Mixing Renderer 9
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {5F5AFF4A-2F7F-4279-88C2-CD88EB39D144}
- Name : Microsoft MPEG-2 Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {6A08CF80-0E18-11CF-A24D-0020AFD79767}
- Name : ACM Wrapper
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {6BC1CFFA-8FC1-4261-AC22-CFB4CC38DB50}
- Name : Video Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {6CFAD761-735D-4AA5-8AFC-AF91A7D61EBA}
- Name : MPEG-2 Video Stream Analyzer
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {6E8D4A20-310C-11D0-B79A-00AA003767A7}
- Name : Line 21 Decoder
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {6F26A6CD-967B-47FD-874A-7AED2C9D25A2}
- Name : Video Port Manager
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {70E102B0-5556-11CE-97C0-00AA0055595A}
- Name : Video Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {7B3BC2A0-AA50-4ae7-BD44-B03649EC87C2}
- Name : VPS Decoder
- Value : C:\Windows\System32\WSTPager.ax

+ CLSID : {7C23220E-55BB-11D3-8B16-00C04FB6BD3D}
- Name : WM ASF Writer
- Value : C:\Windows\System32\qasf.dll

+ CLSID : {814B9800-1C88-11D1-BAD9-00609744111A}
- Name : VBI Surface Allocator
- Value : %SystemRoot%\System32\vbisurf.ax

+ CLSID : {8596E5F0-0DA5-11D0-BD21-00A0C911CE86}
- Name : File writer
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {9B8C4620-2C1A-11D0-8493-00A02438AD48}
- Name : DVD Navigator
- Value : C:\Windows\System32\qdvd.dll

+ CLSID : {A0025E90-E45B-11D1-ABE9-00A0C905F375}
- Name : Overlay Mixer2
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {A888DF60-1E90-11CF-AC98-00AA004C0FA9}
- Name : AVI Draw
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {ACD453BC-C58A-44D1-BBF5-BFB325BE2D78}
- Name : Microsoft MPEG-2 Audio Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {AD6C8934-F31B-4F43-B5E4-0541C1452F6F}
- Name : WST Pager
- Value : C:\Windows\System32\WSTPager.ax

+ CLSID : {AFB6C280-2C41-11D3-8A60-0000F81E0E4A}
- Name : MPEG-2 Demultiplexer
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {B1B77C00-C3E4-11CF-AF79-00AA00B67A42}
- Name : DV Video Decoder
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {C1F400A0-3F08-11D3-9F0B-006008039E37}
- Name : SampleGrabber
- Value : C:\Windows\System32\qedit.dll

+ CLSID : {C1F400A4-3F08-11D3-9F0B-006008039E37}
- Name : Null Renderer
- Value : C:\Windows\System32\qedit.dll

+ CLSID : {C666E115-BB62-4027-A113-82D643FE2D99}
- Name : MPEG-2 Sections and Tables
- Value : C:\Windows\System32\Mpeg2Data.ax

+ CLSID : {C9F5FE02-F851-4EB5-99EE-AD602AF1E619}
- Name : StreamBufferSource
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {CC58E280-8AA1-11D1-B3F1-00AA003761C5}
- Name : Smart Tee
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {CD8743A1-3736-11D0-9E69-00C04FD7C15B}
- Name : Overlay Mixer
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {CF49D4E0-1115-11CE-B03A-0020AF0BA770}
- Name : AVI Decompressor
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D3588AB0-0781-11CE-B03A-0020AF0BA770}
- Name : AVI/WAV File Source
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A1-7548-11CF-A520-0080C77EF58A}
- Name : Wave Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A2-7548-11CF-A520-0080C77EF58A}
- Name : MIDI Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A3-7548-11CF-A520-0080C77EF58A}
- Name : Multi-file Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A5-7548-11CF-A520-0080C77EF58A}
- Name : File stream renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E2448508-95DA-4205-9A27-7EC81E723B1A}
- Name : StreamBufferSink2
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {E2510970-F137-11CE-8B67-00AA00A3F1A6}
- Name : AVI Mux
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {E4206432-01A1-4BEE-B3E1-3702C8EDC574}
- Name : Line 21 Decoder 2
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E436EBB5-524F-11CE-9F53-0020AF0BA770}
- Name : File Source (Async.)
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E436EBB6-524F-11CE-9F53-0020AF0BA770}
- Name : File Source (URL)
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {F8388A40-D5BB-11D0-BE5A-0080C706568E}
- Name : Infinite Pin Tee Filter
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {FA10746C-9B63-4B6C-BC49-FC300EA5F256}
- Name : Enhanced Video Renderer
- Value : C:\Windows\System32\evr.dll

+ CLSID : {FC772AB0-0C7F-11D3-8FF2-00A0C9224CF4}
- Name : BDA MPEG2 Transport Information Filter
- Value : C:\Windows\System32\psisrndr.ax

+ CLSID : {FEB50740-7BEF-11CE-9BD9-0000E202599C}
- Name : MPEG Video Decoder
- Value : C:\Windows\System32\quartz.dll


+ HKLM\Software\Wow6432Node\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance
+ CLSID : {129D7E40-C10D-11D0-AFB9-00AA00B67A42}
- Name : DV Muxer
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {1643E180-90F5-11CE-97D5-00AA0055595A}
- Name : Color Space Converter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {187463A0-5BB7-11D3-ACBE-0080C75E246E}
- Name : WM ASF Reader
- Value : C:\Windows\System32\qasf.dll

+ CLSID : {1B544C20-FD0B-11CE-8C63-00AA0044B51E}
- Name : AVI Splitter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {1DA08500-9EDC-11CF-BC10-00AA00AC74F6}
- Name : VGA 16 Color Ditherer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {1f26a602-2b5c-4b63-b8e8-9ea5c1a7dc2e}
- Name : SBE2MediaTypeProfile
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {212690FB-83E5-4526-8FD7-74478B7939CD}
- Name : Microsoft DTV-DVD Video Decoder
- Value : C:\Windows\System32\msmpeg2vdec.dll

+ CLSID : {280A3020-86CF-11D1-ABE6-00A0C905F375}
- Name : AC3 Parser Filter
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {2DB47AE5-CF39-43C2-B4D6-0CD8D90946F4}
- Name : StreamBufferSink
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {301056D0-6DFF-11D2-9EEB-006008039E37}
- Name : MJPEG Decompressor
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {336475D0-942A-11CE-A870-00AA002FEAB5}
- Name : MPEG-I Stream Splitter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {33FACFE0-A9BE-11D0-A520-00A0D10129C0}
- Name : SAMI (CC) Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {370A1D5D-DDEB-418C-81CD-189E0D4FA443}
- Name : VBI Codec
- Value : C:\Windows\System32\VBICodec.ax

+ CLSID : {3AE86B20-7BE8-11D1-ABE6-00A0C905F375}
- Name : MPEG-2 Splitter
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {3D07A539-35CA-447C-9B05-8D85CE924F9E}
- Name : Closed Captions Analysis Filter
- Value : C:\Windows\System32\cca.dll

+ CLSID : {3E458037-0CA6-41aa-A594-2AA6C02D709B}
- Name : SBE2FileScan
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {42150CD9-CA9A-4EA5-9939-30EE037F6E74}
- Name : Microsoft MPEG-2 Video Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {48025243-2D39-11CE-875D-00608CB78066}
- Name : Internal Script Command Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {4A2286E0-7BEF-11CE-9BD9-0000E202599C}
- Name : MPEG Audio Decoder
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {4EB31670-9FC6-11CF-AF6E-00AA00B67A42}
- Name : DV Splitter
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {51B4ABF3-748F-4E3B-A276-C828330E926A}
- Name : Video Mixing Renderer 9
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {5F5AFF4A-2F7F-4279-88C2-CD88EB39D144}
- Name : Microsoft MPEG-2 Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {6A08CF80-0E18-11CF-A24D-0020AFD79767}
- Name : ACM Wrapper
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {6BC1CFFA-8FC1-4261-AC22-CFB4CC38DB50}
- Name : Video Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {6CFAD761-735D-4AA5-8AFC-AF91A7D61EBA}
- Name : MPEG-2 Video Stream Analyzer
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {6E8D4A20-310C-11D0-B79A-00AA003767A7}
- Name : Line 21 Decoder
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {6F26A6CD-967B-47FD-874A-7AED2C9D25A2}
- Name : Video Port Manager
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {70E102B0-5556-11CE-97C0-00AA0055595A}
- Name : Video Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {7B3BC2A0-AA50-4ae7-BD44-B03649EC87C2}
- Name : VPS Decoder
- Value : C:\Windows\System32\WSTPager.ax

+ CLSID : {7C23220E-55BB-11D3-8B16-00C04FB6BD3D}
- Name : WM ASF Writer
- Value : C:\Windows\System32\qasf.dll

+ CLSID : {814B9800-1C88-11D1-BAD9-00609744111A}
- Name : VBI Surface Allocator
- Value : %SystemRoot%\System32\vbisurf.ax

+ CLSID : {8596E5F0-0DA5-11D0-BD21-00A0C911CE86}
- Name : File writer
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {9B8C4620-2C1A-11D0-8493-00A02438AD48}
- Name : DVD Navigator
- Value : C:\Windows\System32\qdvd.dll

+ CLSID : {A0025E90-E45B-11D1-ABE9-00A0C905F375}
- Name : Overlay Mixer2
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {A888DF60-1E90-11CF-AC98-00AA004C0FA9}
- Name : AVI Draw
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {ACD453BC-C58A-44D1-BBF5-BFB325BE2D78}
- Name : Microsoft MPEG-2 Audio Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {AD6C8934-F31B-4F43-B5E4-0541C1452F6F}
- Name : WST Pager
- Value : C:\Windows\System32\WSTPager.ax

+ CLSID : {AFB6C280-2C41-11D3-8A60-0000F81E0E4A}
- Name : MPEG-2 Demultiplexer
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {B1B77C00-C3E4-11CF-AF79-00AA00B67A42}
- Name : DV Video Decoder
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {C1F400A0-3F08-11D3-9F0B-006008039E37}
- Name : SampleGrabber
- Value : C:\Windows\System32\qedit.dll

+ CLSID : {C1F400A4-3F08-11D3-9F0B-006008039E37}
- Name : Null Renderer
- Value : C:\Windows\System32\qedit.dll

+ CLSID : {C666E115-BB62-4027-A113-82D643FE2D99}
- Name : MPEG-2 Sections and Tables
- Value : C:\Windows\System32\Mpeg2Data.ax

+ CLSID : {C9F5FE02-F851-4EB5-99EE-AD602AF1E619}
- Name : StreamBufferSource
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {CC58E280-8AA1-11D1-B3F1-00AA003761C5}
- Name : Smart Tee
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {CD8743A1-3736-11D0-9E69-00C04FD7C15B}
- Name : Overlay Mixer
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {CF49D4E0-1115-11CE-B03A-0020AF0BA770}
- Name : AVI Decompressor
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D3588AB0-0781-11CE-B03A-0020AF0BA770}
- Name : AVI/WAV File Source
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A1-7548-11CF-A520-0080C77EF58A}
- Name : Wave Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A2-7548-11CF-A520-0080C77EF58A}
- Name : MIDI Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A3-7548-11CF-A520-0080C77EF58A}
- Name : Multi-file Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A5-7548-11CF-A520-0080C77EF58A}
- Name : File stream renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E2448508-95DA-4205-9A27-7EC81E723B1A}
- Name : StreamBufferSink2
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {E2510970-F137-11CE-8B67-00AA00A3F1A6}
- Name : AVI Mux
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {E4206432-01A1-4BEE-B3E1-3702C8EDC574}
- Name : Line 21 Decoder 2
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E436EBB5-524F-11CE-9F53-0020AF0BA770}
- Name : File Source (Async.)
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E436EBB6-524F-11CE-9F53-0020AF0BA770}
- Name : File Source (URL)
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {F8388A40-D5BB-11D0-BE5A-0080C706568E}
- Name : Infinite Pin Tee Filter
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {FA10746C-9B63-4B6C-BC49-FC300EA5F256}
- Name : Enhanced Video Renderer
- Value : C:\Windows\System32\evr.dll

+ CLSID : {FC772AB0-0C7F-11D3-8FF2-00A0C9224CF4}
- Name : BDA MPEG2 Transport Information Filter
- Value : C:\Windows\System32\psisrndr.ax

+ CLSID : {FEB50740-7BEF-11CE-9BD9-0000E202599C}
- Name : MPEG Video Decoder
- Value : C:\Windows\System32\quartz.dll


+ HKLM\Software\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance
+ CLSID : {5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}
- Name : Microsoft Camera Raw Decoder
- Value : C:\Windows\System32\WindowsCodecsRaw.dll


+ HKLM\Software\Wow6432Node\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance
+ CLSID : {5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}
- Name : Microsoft Camera Raw Decoder
- Value : C:\Windows\System32\WindowsCodecsRaw.dll


70617 - Microsoft Windows AutoRuns Explorer
-
Synopsis
Reports programs that startup associates with the explorer process.
Description
Report the startup locations associated with the explorer.exe process.

These items could add controls to menus, add extensions for common protocols such as HTTP or FTP, or set control user activity with the desktop and control panels.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\SOFTWARE\Classes\Protocols\Filter
+ CLSID : {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
- Name : application/octet-stream
- Value : C:\Windows\System32\mscoree.dll

+ CLSID : {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
- Name : application/x-complus
- Value : C:\Windows\System32\mscoree.dll

+ CLSID : {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
- Name : application/x-msdownload
- Value : C:\Windows\System32\mscoree.dll


+ HKLM\SOFTWARE\Classes\Protocols\Handler
+ CLSID : {3050F406-98B5-11CF-BB82-00AA00BDCE0B}
- Name : about
- Value : C:\Windows\System32\mshtml.dll

+ CLSID : {3dd53d40-7b8b-11D0-b013-00aa0059ce02}
- Name : cdl
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {12D51199-0DB5-46FE-A120-47A3D7D937CC}
- Name : dvd
- Value : C:\Windows\System32\msvidctl.dll

+ CLSID : {79eac9e7-baf9-11ce-8c82-00aa004ba90b}
- Name : file
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {79eac9e3-baf9-11ce-8c82-00aa004ba90b}
- Name : ftp
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {79eac9e2-baf9-11ce-8c82-00aa004ba90b}
- Name : http
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {79eac9e5-baf9-11ce-8c82-00aa004ba90b}
- Name : https
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {9D148291-B9C8-11D0-A4CC-0000F80149F6}
- Name : its
- Value : C:\Windows\System32\itss.dll

+ CLSID : {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B}
- Name : javascript
- Value : C:\Windows\System32\mshtml.dll

+ CLSID : {79eac9e7-baf9-11ce-8c82-00aa004ba90b}
- Name : local
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B}
- Name : mailto
- Value : C:\Windows\System32\mshtml.dll

+ CLSID : {05300401-BCBC-11d0-85E3-00C04FD85AB4}
- Name : mhtml
- Value : C:\Windows\System32\inetcomm.dll

+ CLSID : {79eac9e6-baf9-11ce-8c82-00aa004ba90b}
- Name : mk
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {9D148291-B9C8-11D0-A4CC-0000F80149F6}
- Name : ms-its
- Value : C:\Windows\System32\itss.dll

+ CLSID : {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B}
- Name : res
- Value : C:\Windows\System32\mshtml.dll

+ CLSID : {14654CA6-5711-491D-B89A-58E571679951}
- Name : tbauth
- Value : C:\Windows\System32\tbauth.dll

+ CLSID : {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E}
- Name : tv
- Value : C:\Windows\System32\msvidctl.dll

+ CLSID : {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B}
- Name : vbscript
- Value : C:\Windows\System32\mshtml.dll

+ CLSID : {14654CA6-5711-491D-B89A-58E571679951}
- Name : windows.tbauth
- Value : C:\Windows\System32\tbauth.dll


+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
+ CLSID : {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
- Name : webcheck
- Value :


+ HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
+ CLSID : {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
- Name : webcheck
- Value :


+ HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers
+ CLSID : {23170F69-40C1-278A-1000-000100020000}
- Name : 7-Zip
- Value : C:\Program Files\7-Zip\7-zip.dll

+ CLSID : {e2bf9676-5f8f-435c-97eb-11607a5bedf7}
- Name : ModernSharing
- Value : %SystemRoot%\system32\ntshrui.dll

+ CLSID : {09799AFB-AD67-11d1-ABCD-00C04FC30936}
- Name : Open With
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {A470F8CF-A1E8-4f65-8335-227475AA5C46}
- Name : Open With EncryptionMenu
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}
- Name : Sharing
- Value : %SystemRoot%\system32\ntshrui.dll

+ CLSID : {244bcb42-d214-46b8-aa32-e3cc2e6662ee}
- Name : SimpleShlExt
- Value : C:\Program Files\BackupClient\ShellExtensions\ATPShellExt.dll

+ CLSID : {30351349-7B7D-4FCC-81B4-1E394CA267EB}
- Name : TortoiseSVN
- Value : D:\Techexcel\Program Files\TortoiseSVN\bin\TortoiseStub.dll

+ CLSID : {4E716236-AA30-4C65-B225-D68BBA81E9C2}
- Name : WinMerge
- Value : C:\Program Files\WinMerge\ShellExtensionX64.dll

+ CLSID : {B41DB860-64E4-11D2-9906-E49FADC173CA}
- Name : WinRAR
- Value : C:\Program Files\WinRAR\rarext.dll

+ CLSID : {B41DB860-8EE4-11D2-9906-E49FADC173CA}
- Name : WinRAR32
- Value :

+ CLSID : {90AA3A4E-1CBA-4233-B8BB-535773D48449}
- Name : Taskband Pin
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
- Name : Start Menu Pin
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {C539A15A-3AF9-4c92-B771-50CB78F5C751}
- Name :
- Value : C:\Program Files\BackupClient\ShellExtensions\tishell64.dll


+ HKLM\Software\Classes\*\ShellEx\PropertySheetHandlers
+ CLSID : {7444C719-39BF-11D1-8CD9-00C04FC29D45}
- Name : CryptoSignMenu
- Value : %SystemRoot%\system32\cryptext.dll

+ CLSID : {748F920F-FB24-4D09-B360-BAF6F199AD6D}
- Name : FCI Properties
- Value : C:\Windows\System32\srmshell.dll

+ CLSID : {30351349-7B7D-4FCC-81B4-1E394CA267EB}
- Name : TortoiseSVN
- Value : D:\Techexcel\Program Files\TortoiseSVN\bin\TortoiseStub.dll

+ CLSID : {1f2e5c40-9550-11ce-99d2-00aa006e086c}
- Name :
- Value : %SystemRoot%\system32\rshx32.dll

+ CLSID : {3EA48300-8CF6-101B-84FB-666CCB9BCD32}
- Name : OLE DocFile Property Page
- Value : %SystemRoot%\system32\docprop.dll

+ CLSID : {883373C3-BF89-11D1-BE35-080036B11A03}
- Name : Summary Properties Page
- Value : %SystemRoot%\system32\shell32.dll


+ HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers
+ CLSID : {f3d06e7c-1e45-4a26-847e-f9fcdee59be0}
- Name : CopyAsPathMenu
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {7BA4C740-9E81-11CF-99D3-00AA004AE837}
- Name : SendTo
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {474C98EE-CF3D-41f5-80E3-4AAB0AB04301}
- Name :
- Value : %SystemRoot%\System32\cscui.dll

+ CLSID : {596AB062-B4D2-4215-9F74-E9109B0A8153}
- Name :
- Value : %SystemRoot%\system32\twext.dll

+ CLSID : {a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
- Name : Start Menu Pin
- Value : %SystemRoot%\system32\shell32.dll


+ HKLM\Software\Classes\AllFileSystemObjects\ShellEx\PropertySheetHandlers
+ CLSID : {596AB062-B4D2-4215-9F74-E9109B0A8153}
- Name :
- Value : %SystemRoot%\system32\twext.dll

+ CLSID : {7EFA68C6-086B-43e1-A2D2-55A113531240}
- Name :
- Value : %SystemRoot%\System32\cscui.dll


+ HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers
+ CLSID : {23170F69-40C1-278A-1000-000100020000}
- Name : 7-Zip
- Value : C:\Program Files\7-Zip\7-zip.dll

+ CLSID : {A470F8CF-A1E8-4f65-8335-227475AA5C46}
- Name : EncryptionMenu
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {474C98EE-CF3D-41f5-80E3-4AAB0AB04301}
- Name : Offline Files
- Value : %SystemRoot%\System32\cscui.dll

+ CLSID : {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}
- Name : Sharing
- Value : %SystemRoot%\system32\ntshrui.dll

+ CLSID : {30351349-7B7D-4FCC-81B4-1E394CA267EB}
- Name : TortoiseSVN
- Value : D:\Techexcel\Program Files\TortoiseSVN\bin\TortoiseStub.dll

+ CLSID : {4E716236-AA30-4C65-B225-D68BBA81E9C2}
- Name : WinMerge
- Value : C:\Program Files\WinMerge\ShellExtensionX64.dll

+ CLSID : {596AB062-B4D2-4215-9F74-E9109B0A8153}
- Name :
- Value : %SystemRoot%\system32\twext.dll


+ HKLM\Software\Classes\Directory\Shellex\DragDropHandlers
+ CLSID : {23170F69-40C1-278A-1000-000100020000}
- Name : 7-Zip
- Value : C:\Program Files\7-Zip\7-zip.dll

+ CLSID : {3035134A-7B7D-4FCC-81B4-1E394CA267EB}
- Name : TortoiseSVN
- Value : D:\Techexcel\Program Files\TortoiseSVN\bin\TortoiseStub.dll

+ CLSID : {4E716236-AA30-4C65-B225-D68BBA81E9C2}
- Name : WinMerge
- Value : C:\Program Files\WinMerge\ShellExtensionX64.dll


+ HKLM\Software\Classes\Directory\Shellex\PropertySheetHandlers
+ CLSID : {7EFA68C6-086B-43e1-A2D2-55A113531240}
- Name : Offline Files
- Value : %SystemRoot%\System32\cscui.dll

+ CLSID : {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}
- Name : Sharing
- Value : %SystemRoot%\system32\ntshrui.dll

+ CLSID : {30351349-7B7D-4FCC-81B4-1E394CA267EB}
- Name : TortoiseSVN
- Value : D:\Techexcel\Program Files\TortoiseSVN\bin\TortoiseStub.dll

+ CLSID : {1f2e5c40-9550-11ce-99d2-00aa006e086c}
- Name :
- Value : %SystemRoot%\system32\rshx32.dll

+ CLSID : {4a7ded0a-ad25-11d0-98a8-0800361b1103}
- Name :
- Value : %SystemRoot%\system32\mydocs.dll

+ CLSID : {596AB062-B4D2-4215-9F74-E9109B0A8153}
- Name :
- Value : %SystemRoot%\system32\twext.dll

+ CLSID : {ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}
- Name :
- Value : C:\Windows\System32\DfsShlEx.dll

+ CLSID : {ef43ecfe-2ab9-4632-bf21-58909dd177f0}
- Name :
- Value : %SystemRoot%\system32\shell32.dll


+ HKLM\Software\Classes\Directory\Shellex\CopyHookHandlers
+ CLSID : {217FC9C0-3AEA-1069-A2DB-08002B30309D}
- Name : FileSystem
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {40dd6e20-7c17-11ce-a804-00aa003ca9f6}
- Name : Sharing
- Value : %SystemRoot%\system32\ntshrui.dll

+ CLSID : {30351349-7B7D-4FCC-81B4-1E394CA267EB}
- Name : TortoiseSVN
- Value : D:\Techexcel\Program Files\TortoiseSVN\bin\TortoiseStub.dll


+ HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers
+ CLSID : {D969A300-E7FF-11d0-A93B-00A0C90F2719}
- Name : New
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}
- Name : Sharing
- Value : %SystemRoot%\system32\ntshrui.dll

+ CLSID : {30351349-7B7D-4FCC-81B4-1E394CA267EB}
- Name : TortoiseSVN
- Value : D:\Techexcel\Program Files\TortoiseSVN\bin\TortoiseStub.dll

+ CLSID : {4E716236-AA30-4C65-B225-D68BBA81E9C2}
- Name : WinMerge
- Value : C:\Program Files\WinMerge\ShellExtensionX64.dll


+ HKLM\Software\Classes\Folder\Shellex\ColumnHandlers
+ CLSID : {30351349-7B7D-4FCC-81B4-1E394CA267EB}
- Name :
- Value : D:\Techexcel\Program Files\TortoiseSVN\bin\TortoiseStub.dll


+ HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers
+ CLSID : {23170F69-40C1-278A-1000-000100020000}
- Name : 7-Zip
- Value : C:\Program Files\7-Zip\7-zip.dll

+ CLSID : {3dad6c5d-2167-4cae-9914-f99e41c12cfa}
- Name : Library Location
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {474C98EE-CF3D-41f5-80E3-4AAB0AB04301}
- Name : Offline Files
- Value : %SystemRoot%\System32\cscui.dll

+ CLSID : {470C0EBD-5D73-4d58-9CED-E91E22E23282}
- Name : PintoStartScreen
- Value : C:\Windows\System32\appresolver.dll

+ CLSID : {244bcb42-d214-46b8-aa32-e3cc2e6662ee}
- Name : SimpleShlExt
- Value : C:\Program Files\BackupClient\ShellExtensions\ATPShellExt.dll

+ CLSID : {30351349-7B7D-4FCC-81B4-1E394CA267EB}
- Name : TortoiseSVN
- Value : D:\Techexcel\Program Files\TortoiseSVN\bin\TortoiseStub.dll

+ CLSID : {B41DB860-64E4-11D2-9906-E49FADC173CA}
- Name : WinRAR
- Value : C:\Program Files\WinRAR\rarext.dll

+ CLSID : {B41DB860-8EE4-11D2-9906-E49FADC173CA}
- Name : WinRAR32
- Value :

+ CLSID : {a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
- Name : Start Menu Pin
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {C539A15A-3AF9-4c92-B771-50CB78F5C751}
- Name :
- Value : C:\Program Files\BackupClient\ShellExtensions\tishell64.dll


+ HKLM\Software\Classes\Folder\ShellEx\DragDropHandlers
+ CLSID : {3035134A-7B7D-4FCC-81B4-1E394CA267EB}
- Name : TortoiseSVN
- Value : D:\Techexcel\Program Files\TortoiseSVN\bin\TortoiseStub.dll

+ CLSID : {B41DB860-64E4-11D2-9906-E49FADC173CA}
- Name : WinRAR
- Value : C:\Program Files\WinRAR\rarext.dll

+ CLSID : {B41DB860-8EE4-11D2-9906-E49FADC173CA}
- Name : WinRAR32
- Value :

+ CLSID : {BD472F60-27FA-11cf-B8B4-444553540000}
- Name :
- Value : %SystemRoot%\system32\zipfldr.dll


+ HKLM\Software\Classes\Folder\ShellEx\PropertySheetHandlers
+ CLSID : {748F920F-FB24-4D09-B360-BAF6F199AD6D}
- Name : FCI Properties
- Value : C:\Windows\System32\srmshell.dll

+ CLSID : {7EFA68C6-086B-43e1-A2D2-55A113531240}
- Name : Offline Files
- Value : %SystemRoot%\System32\cscui.dll


+ HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers
+ CLSID : {C5994560-53D9-4125-87C9-F193FC689CB2}
- Name : Tortoise1Normal
- Value : C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

+ CLSID : {C5994561-53D9-4125-87C9-F193FC689CB2}
- Name : Tortoise2Modified
- Value : C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

+ CLSID : {C5994562-53D9-4125-87C9-F193FC689CB2}
- Name : Tortoise3Conflict
- Value : C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

+ CLSID : {C5994563-53D9-4125-87C9-F193FC689CB2}
- Name : Tortoise4Locked
- Value : C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

+ CLSID : {C5994564-53D9-4125-87C9-F193FC689CB2}
- Name : Tortoise5ReadOnly
- Value : C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

+ CLSID : {C5994565-53D9-4125-87C9-F193FC689CB2}
- Name : Tortoise6Deleted
- Value : C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

+ CLSID : {C5994566-53D9-4125-87C9-F193FC689CB2}
- Name : Tortoise7Added
- Value : C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

+ CLSID : {C5994567-53D9-4125-87C9-F193FC689CB2}
- Name : Tortoise8Ignored
- Value : C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

+ CLSID : {C5994568-53D9-4125-87C9-F193FC689CB2}
- Name : Tortoise9Unversioned
- Value : C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

+ CLSID : {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}
- Name : EnhancedStorageShell
- Value : C:\Windows\System32\EhStorShell.dll

+ CLSID : {4E77131D-3629-431c-9818-C5679DC83E81}
- Name : Offline Files
- Value : %SystemRoot%\System32\cscui.dll


+ HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers
+ CLSID : {C5994560-53D9-4125-87C9-F193FC689CB2}
- Name : Tortoise1Normal
- Value : C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

+ CLSID : {C5994561-53D9-4125-87C9-F193FC689CB2}
- Name : Tortoise2Modified
- Value : C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

+ CLSID : {C5994562-53D9-4125-87C9-F193FC689CB2}
- Name : Tortoise3Conflict
- Value : C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

+ CLSID : {C5994563-53D9-4125-87C9-F193FC689CB2}
- Name : Tortoise4Locked
- Value : C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

+ CLSID : {C5994564-53D9-4125-87C9-F193FC689CB2}
- Name : Tortoise5ReadOnly
- Value : C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

+ CLSID : {C5994565-53D9-4125-87C9-F193FC689CB2}
- Name : Tortoise6Deleted
- Value : C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

+ CLSID : {C5994566-53D9-4125-87C9-F193FC689CB2}
- Name : Tortoise7Added
- Value : C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

+ CLSID : {C5994567-53D9-4125-87C9-F193FC689CB2}
- Name : Tortoise8Ignored
- Value : C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

+ CLSID : {C5994568-53D9-4125-87C9-F193FC689CB2}
- Name : Tortoise9Unversioned
- Value : C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll


70619 - Microsoft Windows AutoRuns Internet Explorer
-
Synopsis
Report programs that startup associates with Internet Explorer.
Description
Report registry startup locations associated with the Internet Explorer (IE) application.

The startup values include Internet Explorer plugins to extend the functionality of IE, browser toolbars, hooks into browser controls, and settings.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
+ CLSID : {1FD49718-1D00-4B19-AF5F-070AF6D5D54C}
- Name : IEToEdge BHO
- Value : C:\Program Files (x86)\Microsoft\Edge\Application\143.0.3650.96\BHO\ie_to_edge_bho_64.dll

+ CLSID : {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
- Value : C:\Program Files\Java\jre1.8.0_161\bin\ssv.dll

+ CLSID : {DBC80044-A445-435b-BC74-9C25C1C588A9}
- Value : C:\Program Files\Java\jre1.8.0_161\bin\jp2ssv.dll


HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
+ CLSID : {1FD49718-1D00-4B19-AF5F-070AF6D5D54C}
- Name : IEToEdge BHO
- Value : C:\Program Files (x86)\Microsoft\Edge\Application\143.0.3650.96\BHO\ie_to_edge_bho_64.dll


70620 - Microsoft Windows AutoRuns Known DLLs
-
Synopsis
DLLs listed to be shared by processes.
Description
The known DLLs registry setting is used to define DLLs that are shared between processes without a process having to search for the DLL location.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0

+ HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs
- imagehlp : IMAGEHLP.dll
- shcore : SHCORE.dll
- oleaut32 : OLEAUT32.dll
- normaliz : NORMALIZ.dll
- msvcrt : MSVCRT.dll
- shell32 : SHELL32.dll
- msctf : MSCTF.dll
- gdi32 : gdi32.dll
- nsi : NSI.dll
- advapi32 : advapi32.dll
- coml2 : coml2.dll
- _wowarmhw : wowarmhw.dll
- clbcatq : clbcatq.dll
- wow64win : wow64win.dll
- shlwapi : SHLWAPI.dll
- psapi : PSAPI.DLL
- imm32 : IMM32.dll
- combase : combase.dll
- user32 : user32.dll
- sechost : sechost.dll
- _xtajit : xtajit.dll
- _wow64cpu : wow64cpu.dll
- wow64 : wow64.dll
- rpcrt4 : rpcrt4.dll
- kernel32 : kernel32.dll
- ws2_32 : WS2_32.dll
- wldap32 : WLDAP32.dll
- ole32 : ole32.dll
- difxapi : difxapi.dll
- setupapi : Setupapi.dll
- comdlg32 : COMDLG32.dll
- gdiplus : gdiplus.dll
70613 - Microsoft Windows AutoRuns LSA Providers
-
Synopsis
Programs set to start as Local Security Authority.
Description
An LSA (Local Security Authority) is an application that can be used to authorize users to their systems. The reported autoruns are available to provide this service or features to this service.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0



+ HKLM\SYSTEM\CurrentControlSet\Control\Lsa\authentication packages
- msv1_0


+ HKLM\SYSTEM\CurrentControlSet\Control\Lsa\notification packages
- rassfm
- scecli


+ HKLM\SYSTEM\CurrentControlSet\Control\Lsa\security packages
- ""
70621 - Microsoft Windows AutoRuns Logon
-
Synopsis
Report programs that start-up from the most common registry locations.
Description
Report the most common startup locations used by programs. These are commonly associated with programs that start automatically when the computer is turned on, users log in, users log off, or remote sessions are started.

Such keys can be set from a program install, GPO, or through a malicious process to maintain persistence.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd
- rdpclip


+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\userinit
- C:\Windows\system32\userinit.exe


+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\vmapplet
- SystemPropertiesPerformance.exe /pagefile


+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\shell
- explorer.exe


+ HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot
- AlternateShell : cmd.exe


+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Name : securityhealth
- Value : %windir%\system32\SecurityHealthSystray.exe

- Name : mmsmonitor.exe
- Value : C:\Program Files\BackupClient\TrayMonitor\MmsMonitor.exe

- Name : acronis scheduler2 service
- Value : "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe"


+ HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
- Name : acronistibmountermonitor
- Value : C:\Program Files (x86)\Common Files\Acronis\TibMounter\tib_mounter_monitor.exe

- Name : sunjavaupdatesched
- Value : "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"


+ HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components
+ CLSID : >{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
- Name : Microsoft Windows Media Player
- Value : %SystemRoot%\system32\unregmp2.exe /ShowWMP

+ CLSID : {2C7339CF-2B09-4501-B3F3-F3508C9228ED}
- Name : Themes Setup
- Value : /UserInstall

+ CLSID : {49210152-871f-4ffa-961d-a172abcbc09d}
- Name : Google Platform Experience Helper
- Value : "C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe" --first-run

+ CLSID : {6BF52A52-394A-11d3-B153-00C04F79FAA6}
- Name : Microsoft Windows Media Player
- Value : %SystemRoot%\system32\unregmp2.exe /FirstLogon

+ CLSID : {89820200-ECBD-11cf-8B85-00AA005B4340}
- Name : Windows Desktop Update
- Value : U

+ CLSID : {89820200-ECBD-11cf-8B85-00AA005B4383}
- Name : Web Platform Customizations
- Value : C:\Windows\System32\ie4uinit.exe -UserConfig

+ CLSID : {89B4C1CD-B018-4511-B0A1-5476DBF70820}
- Name :
- Value : C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install

+ CLSID : {8A69D345-D564-463c-AFF1-A69D9E530F96}
- Name : Google Chrome
- Value : "C:\Program Files\Google\Chrome\Application\143.0.7499.171\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --channel=stable

+ CLSID : {9459C573-B17A-45AE-9F64-1857B5D58CEE}
- Name : Microsoft Edge
- Value : "C:\Program Files (x86)\Microsoft\Edge\Application\143.0.3650.96\Installer\setup.exe" --configure-user-settings --verbose-logging --system-level --msedge --channel=stable

+ CLSID : {A509B1A7-37EF-4b3f-8CFC-4F3A74704073}
- Name : Applying Enhanced Security Configuration
- Value : "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iesetup.dll",IEHardenAdmin

+ CLSID : {A509B1A8-37EF-4b3f-8CFC-4F3A74704073}
- Name : Applying Enhanced Security Configuration
- Value : "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iesetup.dll",IEHardenUser


+ HKLM\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components
+ CLSID : >{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
- Name : Microsoft Windows Media Player
- Value : %SystemRoot%\system32\unregmp2.exe /ShowWMP

+ CLSID : {6BF52A52-394A-11d3-B153-00C04F79FAA6}
- Name : Microsoft Windows Media Player
- Value : %SystemRoot%\system32\unregmp2.exe /FirstLogon

+ CLSID : {89B4C1CD-B018-4511-B0A1-5476DBF70820}
- Name :
- Value : C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install


+ HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows
- iconservicelib : IconCodecService.dll
- Load :



HKU : \Users\techexcel : S-1-5-21-1185746460-1788592564-4118236249-1001

+ HKU\S-1-5-21-1185746460-1788592564-4118236249-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce
- Name : application restart #3
- Value : C:\Program Files (x86)\Microsoft SQL Server Management Studio 18\Common7\IDE\Ssms.exe /restartManager /recoveryFile "C:\Users\techexcel\AppData\Roaming\Microsoft\SQL Server Management Studio\18.0_IsoShell\AutoRecoverDat\256.dat;C:\Users\techexcel\AppData\Roaming\Microsoft\SQL Server Management Studio\18.0_IsoShell\AutoRecoverDat\256.suodat"

70622 - Microsoft Windows AutoRuns Network Providers
-
Synopsis
Report programs set to automatically start-up as a Network Provider.
Description
The DLLs listed under the registry key are used to provide network services for new protocols.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order\ProviderOrder
- RDPNP : %SystemRoot%\System32\drprov.dll
- LanmanWorkstation : %SystemRoot%\System32\ntlanman.dll

+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\HwOrder\ProviderOrder
- RDPNP : %SystemRoot%\System32\drprov.dll
- LanmanWorkstation : %SystemRoot%\System32\ntlanman.dll
70623 - Microsoft Windows AutoRuns Print Monitor
-
Synopsis
Report programs set to start automatically as a print monitor.
Description
Report the DLLs that control print monitor functions for multiple programs and systems.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0

+ HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
- Local Port : localspl.dll
- MONVNC : VNCpm.dll
- Standard TCP/IP Port : tcpmon.dll
- USB Monitor : usbmon.dll
- WSD Port : APMon.dll
70618 - Microsoft Windows AutoRuns Registry Hijack Possible Locations
-
Synopsis
Report common registry keys used to hijack execution.
Description
Report common registry keys that can be used to hijack system process execution.

These registry keys can be used to either replace execution or shim a process in the middle of execution to hijack control. Confirm that everything listed here is set to the appropriate settings and that it doesn't look like another process is taking control of the process's execution.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\SOFTWARE\Classes\Exefile\Shell\Open\Command
- Command : "%1" %*


+ HKLM\Software\Classes\.exe : exefile
- open : "%1" %*
- runas : "%1" %*
- runasuser :


+ HKLM\Software\Classes\.cmd : cmdfile
- edit : %SystemRoot%\System32\NOTEPAD.EXE %1
- open : "%1" %*
- print : %SystemRoot%\System32\NOTEPAD.EXE /p %1
- runas : %SystemRoot%\System32\cmd.exe /C "%1" %*
- runasuser :


+ HKLM\Software\Classes\.htm : htmlfile
- open : "C:\Program Files\Internet Explorer\iexplore.exe" %1
- print : "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
- printto : "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" "%2" "%3" "%4"


+ HKLM\Software\Classes\.html : htmlfile
- open : "C:\Program Files\Internet Explorer\iexplore.exe" %1
- print : "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
- printto : "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" "%2" "%3" "%4"


+ HKLM\Software\Classes\.docx : docxfile
- open : "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1"
- print : "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" /p "%1"
- printto : "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" /pt "%1" "%2" "%3" "%4"


+ HKLM\Software\Classes\.vbs : VBSFile
- Edit : "%SystemRoot%\System32\Notepad.exe" %1
- Open : "%SystemRoot%\System32\WScript.exe" "%1" %*
- Open2 : "%SystemRoot%\System32\CScript.exe" "%1" %*
- Print : "%SystemRoot%\System32\Notepad.exe" /p %1


+ HKLM\Software\Classes\.txt : txtfile
- open : %SystemRoot%\system32\NOTEPAD.EXE %1
- print : %SystemRoot%\system32\NOTEPAD.EXE /p %1
- printto : %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4"


+ HKLM\Software\Classes\.xml : xmlfile
- Open : "C:\Program Files\Internet Explorer\iexplore.exe" %1


+ HKLM\Software\Classes\.pif : piffile
- open : "%1" %*


+ HKLM\Software\Classes\.txt : txtfile
- open : %SystemRoot%\system32\NOTEPAD.EXE %1
- print : %SystemRoot%\system32\NOTEPAD.EXE /p %1
- printto : %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4"




HKU : \Users\techexcel : S-1-5-21-1185746460-1788592564-4118236249-1001

+ HKU\Software\Classes\.xls : xls_auto_file
- open : "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1"

70624 - Microsoft Windows AutoRuns Report
-
Synopsis
Generate a CSV report of all autoruns.
Description
Collect all autoruns listed in the Windows autoruns plugins and report the primary content in a CSV report.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+Enabled Autoruns Detection Types
- LSA Provider
- Boot Execute
- WinLogon
- Known DLLs
- Winsock Provider
- Service
- Explorer
- Logon
- Codecs
- Driver
- Image Hijack
- Network Provider
- Print Monitor
- Internet Explorer


The attached CSV contains information about Windows autoruns.
70626 - Microsoft Windows AutoRuns Services and Drivers
-
Synopsis
Report programs that are set to start automatically on boot as a service or driver.
Description
Report the registry keys that track programs that are set to start on boot as a service.

These programs can start as a system wide service or be loaded as a driver.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\System\CurrentControlSet\Services
Drivers :
+ Acronis Agent Core Service
- "C:\Program Files\Common Files\Acronis\Agent\aakore.exe" run
- Auto Load
- Enables Acronis Agent Core Service.

+ Acronis Active Protection Service
- "C:\Program Files\Common Files\Acronis\ActiveProtection\active_protection_service.exe"
- Auto Load
- Acronis Active Protection Service

+ Acronis Cyber Protection Service
- "C:\Program Files\BackupClient\CyberProtect\cyber-protect-service.exe"
- Auto Load
- Acronis Cyber Protection Service

+ Acronis Scheduler2 Service
- "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe"
- Auto Load
- Provides scheduling for tasks of Acronis components.

+ AdoeCheck
- "C:\Program Files\Git\AdobeCheck.exe"
- Auto Load
- AdoeCheck

+ @%SystemRoot%\system32\AJRouter.dll,-2
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\AJRouter.dll,-1

+ @%SystemRoot%\system32\Alg.exe,-112
- %SystemRoot%\System32\alg.exe
- Load on Demand
- @%SystemRoot%\system32\Alg.exe,-113

+ Agentless Management Service
- "C:\Program Files\OEM\AMS\service\ams.exe"
- Auto Load
- Provides out of band management system with OS-level Agentless Management information and Active Health System events.

+ @%windir%\system32\inetsrv\iisres.dll,-30011
- %windir%\system32\svchost.exe -k apphost
- Auto Load
- @%windir%\system32\inetsrv\iisres.dll,-30012

+ @%systemroot%\system32\appidsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\appidsvc.dll,-101

+ @%systemroot%\system32\appinfo.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\appinfo.dll,-101

+ @appmgmts.dll,-3250
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @appmgmts.dll,-3251

+ @%SystemRoot%\System32\AppReadiness.dll,-1000
- %SystemRoot%\System32\svchost.exe -k AppReadiness -p
- Load on Demand
- @%SystemRoot%\System32\AppReadiness.dll,-1001

+ @%systemroot%\system32\AppVClient.exe,-102
- %systemroot%\system32\AppVClient.exe
- disabled
- @%systemroot%\system32\AppVClient.exe,-101

+ @%SystemRoot%\system32\appxdeploymentserver.dll,-1
- %systemroot%\system32\svchost.exe -k wsappx -p
- Load on Demand
- @%SystemRoot%\system32\appxdeploymentserver.dll,-2

+ @%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1
- %systemroot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
- Load on Demand
- @%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-2

+ @%SystemRoot%\system32\AudioEndpointBuilder.dll,-204
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\AudioEndpointBuilder.dll,-205

+ @%SystemRoot%\system32\audiosrv.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\audiosrv.dll,-201

+ @%SystemRoot%\system32\AxInstSV.dll,-103
- %SystemRoot%\system32\svchost.exe -k AxInstSVGroup
- disabled
- @%SystemRoot%\system32\AxInstSV.dll,-104

+ AzureAttestService
- C:\Windows\system32\svchost.exe -k AzureAttestService
- Auto Load
-

+ @%SystemRoot%\system32\bfe.dll,-1001
- %systemroot%\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p
- Auto Load
- @%SystemRoot%\system32\bfe.dll,-1002

+ Background Intelligent Transfer Service
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\qmgr.dll,-1001

+ @%windir%\system32\bisrv.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @%windir%\system32\bisrv.dll,-101

+ @%SystemRoot%\system32\BTAGService.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\BTAGService.dll,-102

+ @%SystemRoot%\system32\BthAvctpSvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\BthAvctpSvc.dll,-102

+ @%SystemRoot%\System32\bthserv.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\System32\bthserv.dll,-102

+ @%SystemRoot%\system32\CapabilityAccessManager.dll,-1
- %SystemRoot%\system32\svchost.exe -k appmodel -p
- Load on Demand
- @%SystemRoot%\system32\CapabilityAccessManager.dll,-2

+ @%SystemRoot%\system32\cdpsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @%SystemRoot%\system32\cdpsvc.dll,-101

+ @%SystemRoot%\System32\certprop.dll,-11
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\certprop.dll,-12

+ @%SystemRoot%\system32\ClipSVC.dll,-103
- %SystemRoot%\System32\svchost.exe -k wsappx -p
- Load on Demand
- @%SystemRoot%\system32\ClipSVC.dll,-104

+ @comres.dll,-947
- %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
- Load on Demand
- @comres.dll,-948

+ @%SystemRoot%\system32\coremessaging.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork -p
- Auto Load
- @%SystemRoot%\system32\coremessaging.dll,-2

+ @%SystemRoot%\system32\cryptsvc.dll,-1001
- %SystemRoot%\system32\svchost.exe -k NetworkService -p
- Auto Load
- @%SystemRoot%\system32\cryptsvc.dll,-1002

+ @%systemroot%\system32\cscsvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- disabled
- @%systemroot%\system32\cscsvc.dll,-201

+ @combase.dll,-5012
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @combase.dll,-5013

+ @%SystemRoot%\system32\defragsvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k defragsvc
- Load on Demand
- @%SystemRoot%\system32\defragsvc.dll,-102

+ @%SystemRoot%\system32\das.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\das.dll,-101

+ @%SystemRoot%\system32\umpnpmgr.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Load on Demand
- @%SystemRoot%\system32\umpnpmgr.dll,-101

+ @%SystemRoot%\system32\DevQueryBroker.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\DevQueryBroker.dll,-101

+ @%SystemRoot%\system32\dhcpcore.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\dhcpcore.dll,-101

+ @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000
- %SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe
- Load on Demand
- @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1001

+ @%SystemRoot%\system32\diagtrack.dll,-3001
- %SystemRoot%\System32\svchost.exe -k utcsvc -p
- Auto Load
- @%SystemRoot%\system32\diagtrack.dll,-3002

+ @%systemroot%\system32\Windows.Internal.Management.dll,-100
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\Windows.Internal.Management.dll,-101

+ @%SystemRoot%\system32\dmwappushsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\system32\dmwappushsvc.dll,-201

+ @%SystemRoot%\System32\dnsapi.dll,-101
- %SystemRoot%\system32\svchost.exe -k NetworkService -p
- Auto Load
- @%SystemRoot%\System32\dnsapi.dll,-102

+ @%systemroot%\system32\dosvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Load on Demand
- @%systemroot%\system32\dosvc.dll,-101

+ @%systemroot%\system32\dot3svc.dll,-1102
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\dot3svc.dll,-1103

+ @%systemroot%\system32\dps.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork -p
- Auto Load
- @%systemroot%\system32\dps.dll,-501

+ @%SystemRoot%\system32\DeviceSetupManager.dll,-1000
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\DeviceSetupManager.dll,-1001

+ @%SystemRoot%\system32\dssvc.dll,-10003
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\dssvc.dll,-10002

+ @%systemroot%\system32\eapsvc.dll,-1
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\eapsvc.dll,-2

+ Microsoft Edge Update Service (edgeupdate)
- "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svc
- Auto Load
- Keeps your Microsoft software up to date. If this service is disabled or stopped, your Microsoft software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Microsoft software using it.

+ Microsoft Edge Update Service (edgeupdatem)
- "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /medsvc
- Load on Demand
- Keeps your Microsoft software up to date. If this service is disabled or stopped, your Microsoft software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Microsoft software using it.

+ @%SystemRoot%\system32\efssvc.dll,-100
- %SystemRoot%\System32\lsass.exe
- Load on Demand
- @%SystemRoot%\system32\efssvc.dll,-101

+ @%SystemRoot%\system32\embeddedmodesvc.dll,-201
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\embeddedmodesvc.dll,-202

+ Acronis Emergency Updater 0.0.1.2826
- "C:\Program Files (x86)\Common Files\Acronis\EmergencyUpdater\0.0.1.2826\emergency-updater.exe" --emergency-updater
- Auto Load
- Enables Acronis Emergency Updater.

+ @EnterpriseAppMgmtSvc.dll,-1
- %systemroot%\system32\svchost.exe -k appmodel -p
- Load on Demand
- @EnterpriseAppMgmtSvc.dll,-2

+ @%SystemRoot%\system32\wevtsvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\wevtsvc.dll,-201

+ @comres.dll,-2450
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @comres.dll,-2451

+ @%systemroot%\system32\fdPHost.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%systemroot%\system32\fdPHost.dll,-101

+ @%systemroot%\system32\fdrespub.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- Load on Demand
- @%systemroot%\system32\fdrespub.dll,-101

+ @%systemroot%\system32\FntCache.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @%systemroot%\system32\FntCache.dll,-101

+ @%SystemRoot%\system32\PresentationHost.exe,-3309
- %systemroot%\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
- Load on Demand
- @%SystemRoot%\system32\PresentationHost.exe,-3310

+ @%systemroot%\system32\FrameServer.dll,-100
- %SystemRoot%\System32\svchost.exe -k Camera
- Load on Demand
- @%systemroot%\system32\FrameServer.dll,-101

+ Google Chrome Elevation Service (GoogleChromeElevationService)
- "C:\Program Files\Google\Chrome\Application\143.0.7499.171\elevation_service.exe"
- Load on Demand
- Provides encryption services and a secure way for recovering Google Chrome if it gets out of date. If this service is disabled, Google Chrome may lose access to encrypted data, and Google Chrome may not be able recover itself.

+ Google Updater Internal Service (GoogleUpdaterInternalService145.0.7569.0)
- "C:\Program Files (x86)\Google\GoogleUpdater\145.0.7569.0\updater.exe" --system --windows-service --service=update-internal
- Auto Load
- Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it.

+ Google Updater Service (GoogleUpdaterService145.0.7569.0)
- "C:\Program Files (x86)\Google\GoogleUpdater\145.0.7569.0\updater.exe" --system --windows-service --service=update
- Auto Load
- Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it.

+ @gpapi.dll,-112
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @gpapi.dll,-113

+ @%SystemRoot%\system32\GraphicsPerfSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k GraphicsPerfSvcGroup
- disabled
- @%SystemRoot%\system32\GraphicsPerfSvc.dll,-101

+ @%SystemRoot%\System32\hidserv.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\hidserv.dll,-102

+ HPE Smart Array SR Event Notification Service
- "C:\Program Files\HPE\HpePqiESrv\hpepqiesrv.exe"
- Auto Load
- The HPE Smart Array SR Notification Service provides event notification to the Windows system event log, HPE ProLiant Integrated Management Log and HPE Integrity System Event Log for systems using the HPE Smart Array controller driver.

+ @%SystemRoot%\system32\hvhostsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\hvhostsvc.dll,-101

+ @%SystemRoot%\System32\tetheringservice.dll,-4097
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- disabled
- @%SystemRoot%\System32\tetheringservice.dll,-4098

+ @%windir%\system32\inetsrv\iisres.dll,-30007
- %windir%\system32\inetsrv\inetinfo.exe
- Auto Load
- @%windir%\system32\inetsrv\iisres.dll,-30008

+ @%SystemRoot%\system32\ikeext.dll,-501
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\system32\ikeext.dll,-502

+ @%SystemRoot%\system32\InstallService.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\InstallService.dll,-201

+ @%SystemRoot%\system32\iphlpsvc.dll,-500
- %SystemRoot%\System32\svchost.exe -k NetSvcs -p
- Auto Load
- @%SystemRoot%\system32\iphlpsvc.dll,-501

+ @keyiso.dll,-100
- %SystemRoot%\system32\lsass.exe
- Load on Demand
- @keyiso.dll,-101

+ @%systemroot%\system32\kpssvc.dll,-100
- %systemroot%\system32\svchost.exe -k KpsSvcGroup
- Load on Demand
- @%systemroot%\system32\kpssvc.dll,-101

+ @comres.dll,-2946
- %SystemRoot%\System32\svchost.exe -k NetworkServiceAndNoImpersonation -p
- Load on Demand
- @comres.dll,-2947

+ @%systemroot%\system32\srvsvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k smbsvcs
- Auto Load
- @%systemroot%\system32\srvsvc.dll,-101

+ @%systemroot%\system32\wkssvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Auto Load
- @%systemroot%\system32\wkssvc.dll,-101

+ @%SystemRoot%\System32\lfsvc.dll,-1
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\System32\lfsvc.dll,-2

+ @%SystemRoot%\system32\licensemanagersvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\licensemanagersvc.dll,-201

+ @%SystemRoot%\system32\lltdres.dll,-1
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- disabled
- @%SystemRoot%\system32\lltdres.dll,-2

+ @%SystemRoot%\system32\lmhsvc.dll,-101
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\lmhsvc.dll,-102

+ @%windir%\system32\lsm.dll,-1001
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @%windir%\system32\lsm.dll,-1002

+ Techexcel_Lucee
- D:\Techexcel\lucee\tomcat\bin\Tomcat9.exe //RS//Lucee
- Auto Load
- Apache Tomcat 9.0.45 Server - https://tomcat.apache.org/

+ Techexcel_Lucee02
- D:\Techexcel\lucee02\tomcat\bin\Tomcat9.exe //RS//Lucee02
- Auto Load
- Apache Tomcat 9.0.45 Server - https://tomcat.apache.org/

+ Techexcel_Lucee11
- D:\Techexcel\LoadBalancing\Lucee11\tomcat\bin\Tomcat9.exe //RS//Lucee11
- Auto Load
- Apache Tomcat 9.0.62 Server - https://tomcat.apache.org/

+ Techexcel_Lucee12
- D:\Techexcel\LoadBalancing\Lucee12\tomcat\bin\Tomcat9.exe //RS//Lucee12
- Auto Load
- Apache Tomcat 9.0.62 Server - https://tomcat.apache.org/

+ Techexcel_Lucee13
- D:\Techexcel\LoadBalancing\Lucee13\tomcat\bin\Tomcat9.exe //RS//Lucee13
- Auto Load
- Apache Tomcat 9.0.62 Server - https://tomcat.apache.org/

+ Techexcel_Lucee14
- D:\Techexcel\LoadBalancing\Lucee14\tomcat\bin\Tomcat9.exe //RS//Lucee14
- Auto Load
- Apache Tomcat 9.0.62 Server - https://tomcat.apache.org/

+ @%SystemRoot%\System32\moshost.dll,-100
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- disabled
- @%SystemRoot%\System32\moshost.dll,-101

+ Microsoft Edge Elevation Service (MicrosoftEdgeElevationService)
- "C:\Program Files (x86)\Microsoft\Edge\Application\143.0.3650.96\elevation_service.exe"
- Load on Demand
- Provides elevated privileges for Microsoft Edge.

+ Acronis Managed Machine Service
- "C:\Program Files\BackupClient\BackupAndRecovery\mms.exe"
- Auto Load
- Enables data backup and recovery on the machine.

+ @%SystemRoot%\system32\FirewallAPI.dll,-23090
- %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p
- Auto Load
- @%SystemRoot%\system32\FirewallAPI.dll,-23091

+ @comres.dll,-2797
- %SystemRoot%\System32\msdtc.exe
- Auto Load
- @comres.dll,-2798

+ @%SystemRoot%\system32\iscsidsc.dll,-5000
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\iscsidsc.dll,-5001

+ @%SystemRoot%\system32\msimsg.dll,-27
- %systemroot%\system32\msiexec.exe /V
- Load on Demand
- @%SystemRoot%\system32\msimsg.dll,-32

+ MS-MPI Launch Service
- "C:\Program Files\Microsoft MPI\Bin\msmpilaunchsvc.exe"
- Load on Demand
- Service for launching MS-MPI applications

+ SQL Full-text Filter Daemon Launcher (MSSQLSERVER)
- "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL15.MSSQLSERVER
- Load on Demand
- Service to launch full-text filter daemon process which will perform document filtering and word breaking for SQL Server full-text search. Disabling this service will make full-text search features of SQL Server unavailable.

+ SQL Server Launchpad (MSSQLSERVER)
- "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\launchpad.exe" -launcher RLauncher.dll -launcher Pythonlauncher.dll -launcher commonlauncher.dll -pipename sqlsatellitelaunch -timeout 600000 -logPath "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\LOG\ExtensibilityLog" -workingDir "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExtensibilityData" -externalLanguagesTempDir "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLanguagesTemp" -externalLanguagesDir "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLanguages" -externalLibrariesTempDir "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLibrariesTemp" -externalLibrariesDir "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLibraries" -satelliteDllPath "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlsatellite.dll"
- Auto Load
- Service to launch Advanced Analytics Extensions Launchpad process that enables integration with Microsoft R Open using standard T-SQL statements. Disabling this service will make Advanced Analytics features of SQL Server unavailable.

+ SQL Server (MSSQLSERVER)
- "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER
- Auto Load
- Provides storage, processing and controlled access of data, and rapid transaction processing.

+ @%SystemRoot%\system32\ncasvc.dll,-3009
- %SystemRoot%\System32\svchost.exe -k NetSvcs -p
- Load on Demand
- @%SystemRoot%\system32\ncasvc.dll,-3008

+ @%SystemRoot%\system32\ncbservice.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\ncbservice.dll,-501

+ @%SystemRoot%\System32\netlogon.dll,-102
- %systemroot%\system32\lsass.exe
- Load on Demand
- @%SystemRoot%\System32\netlogon.dll,-103

+ @%SystemRoot%\system32\netman.dll,-109
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\netman.dll,-110

+ @%SystemRoot%\system32\netprofmsvc.dll,-202
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\netprofmsvc.dll,-203

+ @%SystemRoot%\system32\NetSetupSvc.dll,-3
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\NetSetupSvc.dll,-4

+ @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8201
- %systemroot%\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
- disabled
- @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8200

+ @%SystemRoot%\System32\NgcCtnrSvc.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\NgcCtnrSvc.dll,-2

+ @%SystemRoot%\System32\ngcsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\ngcsvc.dll,-101

+ @%SystemRoot%\System32\nlasvc.dll,-1
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Auto Load
- @%SystemRoot%\System32\nlasvc.dll,-2

+ @%SystemRoot%\system32\nsisvc.dll,-200
- %systemroot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @%SystemRoot%\system32\nsisvc.dll,-201

+ NXLog
- "C:\Program Files\nxlog\nxlog.exe" -c "C:\Program Files\nxlog\conf\nxlog.conf"
- Auto Load
- This service is responsible for running the NXLog agent. See www.nxlog.co.

+ Office 64 Source Engine
- "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
- Load on Demand
- Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports.

+ @%SystemRoot%\system32\pcasvc.dll,-1
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\pcasvc.dll,-2

+ @%systemroot%\sysWow64\perfhost.exe,-2
- %SystemRoot%\SysWow64\perfhost.exe
- Load on Demand
- @%systemroot%\SysWow64\perfhost.exe,-1

+ @%SystemRoot%\system32\PhoneserviceRes.dll,-10000
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- disabled
- @%SystemRoot%\system32\PhoneserviceRes.dll,-10001

+ @%systemroot%\system32\pla.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork -p
- Load on Demand
- @%systemroot%\system32\pla.dll,-501

+ @%SystemRoot%\system32\umpnpmgr.dll,-200
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Load on Demand
- @%SystemRoot%\system32\umpnpmgr.dll,-101

+ @%SystemRoot%\System32\polstore.dll,-5010
- %SystemRoot%\system32\svchost.exe -k NetworkServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\polstore.dll,-5011

+ @%SystemRoot%\system32\umpo.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @%SystemRoot%\system32\umpo.dll,-101

+ @%systemroot%\system32\profsvc.dll,-300
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%systemroot%\system32\profsvc.dll,-301

+ @%SystemRoot%\system32\pushtoinstall.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\system32\pushtoinstall.dll,-201

+ @%SystemRoot%\system32\qwave.dll,-1
- %windir%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- Load on Demand
- @%SystemRoot%\system32\qwave.dll,-2

+ @%Systemroot%\system32\rasauto.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%Systemroot%\system32\rasauto.dll,-201

+ @%Systemroot%\system32\rasmans.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Auto Load
- @%Systemroot%\system32\rasmans.dll,-201

+ Redis
- "D:\Techexcel\Program Files\Redis\redis-server.exe" --service-run "D:\Techexcel\Program Files\Redis\redis.windows-service.conf"
- Auto Load
- This service runs the Redis server

+ @%Systemroot%\system32\mprdim.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs
- disabled
- @%Systemroot%\system32\mprdim.dll,-201

+ Remote Registry
- %SystemRoot%\system32\svchost.exe -k localService -p
- Load on Demand
- @regsvc.dll,-2

+ @%SystemRoot%\system32\RMapi.dll,-1001
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
- disabled
- @%SystemRoot%\system32\RMapi.dll,-1002

+ @%windir%\system32\RpcEpMap.dll,-1001
- %SystemRoot%\system32\svchost.exe -k RPCSS -p
- Auto Load
- @%windir%\system32\RpcEpMap.dll,-1002

+ @%systemroot%\system32\Locator.exe,-2
- %SystemRoot%\system32\locator.exe
- Load on Demand
- @%systemroot%\system32\Locator.exe,-3

+ @combase.dll,-5010
- %SystemRoot%\system32\svchost.exe -k rpcss -p
- Auto Load
- @combase.dll,-5011

+ @gpapi.dll,-114
- %SystemRoot%\system32\RSoPProv.exe
- Load on Demand
- @gpapi.dll,-115

+ @%systemroot%\system32\sacsvr.dll,-500
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\sacsvr.dll,-501

+ @%SystemRoot%\system32\samsrv.dll,-1
- %SystemRoot%\system32\lsass.exe
- Auto Load
- @%SystemRoot%\system32\samsrv.dll,-2

+ @%SystemRoot%\System32\SCardSvr.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
- Load on Demand
- @%SystemRoot%\System32\SCardSvr.dll,-5

+ @%SystemRoot%\System32\ScDeviceEnum.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- disabled
- @%SystemRoot%\System32\ScDeviceEnum.dll,-101

+ @%SystemRoot%\system32\schedsvc.dll,-100
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\system32\schedsvc.dll,-101

+ @%SystemRoot%\System32\certprop.dll,-13
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\certprop.dll,-14

+ @%SystemRoot%\system32\seclogon.dll,-7001
- %windir%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\seclogon.dll,-7000

+ @%systemroot%\system32\SecurityHealthAgent.dll,-1002
- %SystemRoot%\system32\SecurityHealthService.exe
- Load on Demand
- @%systemroot%\system32\SecurityHealthAgent.dll,-1001

+ @%SystemRoot%\System32\SEMgrSvc.dll,-1001
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- disabled
- @%SystemRoot%\System32\SEMgrSvc.dll,-1002

+ @%SystemRoot%\system32\Sens.dll,-200
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\system32\Sens.dll,-201

+ @%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1001
- "%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe"
- Load on Demand
- @%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1002

+ @%SystemRoot%\system32\SensorDataService.exe,-101
- %SystemRoot%\System32\SensorDataService.exe
- disabled
- @%SystemRoot%\system32\SensorDataService.exe,-102

+ @%SystemRoot%\System32\sensorservice.dll,-1000
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\sensorservice.dll,-1001

+ @%SystemRoot%\System32\sensrsvc.dll,-1000
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- Load on Demand
- @%SystemRoot%\System32\sensrsvc.dll,-1001

+ @%SystemRoot%\System32\SessEnv.dll,-1026
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\System32\SessEnv.dll,-1027

+ @%SystemRoot%\System32\SgrmBroker.exe,-100
- %SystemRoot%\system32\SgrmBroker.exe
- Load on Demand
- @%SystemRoot%\System32\SgrmBroker.exe,-101

+ @%SystemRoot%\system32\ipnathlp.dll,-106
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\system32\ipnathlp.dll,-107

+ @%SystemRoot%\System32\shsvcs.dll,-12288
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\System32\shsvcs.dll,-12289

+ @%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-101

+ System Management Assistant Service
- "C:\Program Files\OEM\AMS\service\sma.exe"
- disabled
- Provides OS-level inband and out of band Agentless Management information and Active Health System events.

+ @%SystemRoot%\System32\smphost.dll,-102
- %SystemRoot%\System32\svchost.exe -k smphost
- Load on Demand
- @%SystemRoot%\System32\smphost.dll,-101

+ @firewallapi.dll,-50323
- %SystemRoot%\System32\snmptrap.exe
- Load on Demand
- @firewallapi.dll,-50324

+ @%SystemRoot%\system32\sppsvc.exe,-101
- %SystemRoot%\system32\sppsvc.exe
- Auto Load
- @%SystemRoot%\system32\sppsvc.exe,-100

+ SQL Server Browser
- "C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe"
- disabled
- Provides SQL Server connection information to client computers.

+ SQL Server Agent (MSSQLSERVER)
- "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER
- Auto Load
- Executes jobs, monitors SQL Server, fires alerts, and allows automation of some administrative tasks.

+ SQL Server CEIP service (MSSQLSERVER)
- "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlceip.exe" -Service
- Load on Demand
- CEIP service for Sql server

+ SQL Server VSS Writer
- "C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
- Auto Load
- Provides the interface to backup/restore Microsoft SQL server through the Windows VSS infrastructure.

+ @%systemroot%\system32\ssdpsrv.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- disabled
- @%systemroot%\system32\ssdpsrv.dll,-101

+ OpenSSH Authentication Agent
- %SystemRoot%\System32\OpenSSH\ssh-agent.exe
- disabled
- Agent to hold private keys used for public key authentication.

+ @%SystemRoot%\system32\sstpsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\sstpsvc.dll,-201

+ @%SystemRoot%\system32\windows.staterepository.dll,-1
- %SystemRoot%\system32\svchost.exe -k appmodel -p
- Load on Demand
- @%SystemRoot%\system32\windows.staterepository.dll,-2

+ @%SystemRoot%\system32\wiaservc.dll,-9
- %SystemRoot%\system32\svchost.exe -k imgsvc
- Load on Demand
- @%SystemRoot%\system32\wiaservc.dll,-10

+ @%SystemRoot%\System32\StorSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\StorSvc.dll,-101

+ @%SystemRoot%\system32\svsvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\svsvc.dll,-102

+ @%SystemRoot%\System32\swprv.dll,-103
- %SystemRoot%\System32\svchost.exe -k swprv
- Load on Demand
- @%SystemRoot%\System32\swprv.dll,-102

+ @%SystemRoot%\system32\sysmain.dll,-1000
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\sysmain.dll,-1001

+ @%windir%\system32\SystemEventsBrokerServer.dll,-1001
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @%windir%\system32\SystemEventsBrokerServer.dll,-1002

+ @%SystemRoot%\system32\TabSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\TabSvc.dll,-101

+ @%SystemRoot%\system32\tapisrv.dll,-10100
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Load on Demand
- @%SystemRoot%\system32\tapisrv.dll,-10101

+ Techexcel_API
- D:\Techexcel_DP\Install\nssm.exe
- Auto Load
-

+ Techexcel_API_2
- D:\Techexcel_DP\Install_2\nssm.exe
- Auto Load
-

+ Techexcel_Jenkins_Slave
- D:\Techexcel\Jenkins\nssm.exe
- Auto Load
-

+ Techexcel_Nginx_Server
- D:\Techexcel\LoadBalancing\Install\nssm.exe
- Auto Load
-

+ Techexcel_PHP_ApacheServer
- "D:\Techexcel\PHPApp\Apache24\bin\httpd.exe" -k runservice
- Auto Load
- Apache/2.4.59 (Win64) OpenSSL/1.1.1q

+ @%SystemRoot%\System32\termsrv.dll,-268
- %SystemRoot%\System32\svchost.exe -k termsvcs
- Load on Demand
- @%SystemRoot%\System32\termsrv.dll,-267

+ @%SystemRoot%\System32\themeservice.dll,-8192
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\System32\themeservice.dll,-8193

+ Tib Mounter Service
- "C:\Program Files (x86)\Common Files\Acronis\TibMounter64\tib_mounter_service.exe"
- Load on Demand
-

+ @%SystemRoot%\system32\TieringEngineService.exe,-702
- %SystemRoot%\system32\TieringEngineService.exe
- Load on Demand
- @%SystemRoot%\system32\TieringEngineService.exe,-701

+ @%windir%\system32\TimeBrokerServer.dll,-1001
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%windir%\system32\TimeBrokerServer.dll,-1002

+ @%systemroot%\system32\tokenbroker.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\tokenbroker.dll,-101

+ @%SystemRoot%\system32\trkwks.dll,-1
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\trkwks.dll,-2

+ @%SystemRoot%\servicing\TrustedInstaller.exe,-100
- %SystemRoot%\servicing\TrustedInstaller.exe
- Load on Demand
- @%SystemRoot%\servicing\TrustedInstaller.exe,-101

+ @%SystemRoot%\system32\tzautoupdate.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- disabled
- @%SystemRoot%\system32\tzautoupdate.dll,-201

+ @%systemroot%\system32\ualsvc.dll,-102
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Auto Load
- @%systemroot%\system32\ualsvc.dll,-101

+ @%systemroot%\system32\AgentService.exe,-102
- %systemroot%\system32\AgentService.exe
- disabled
- @%systemroot%\system32\AgentService.exe,-101

+ @%SystemRoot%\system32\umrdp.dll,-1000
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\umrdp.dll,-1001

+
- cmd /c start C:\Windows\PLA\spawner.exe
- Auto Load
-

+ @%systemroot%\system32\upnphost.dll,-213
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- disabled
- @%systemroot%\system32\upnphost.dll,-214

+ @%systemroot%\system32\usermgr.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%systemroot%\system32\usermgr.dll,-101

+ @%systemroot%\system32\usocore.dll,-101
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%systemroot%\system32\usocore.dll,-102

+ @%SystemRoot%\system32\vaultsvc.dll,-1003
- %SystemRoot%\system32\lsass.exe
- Load on Demand
- @%SystemRoot%\system32\vaultsvc.dll,-1004

+ VisualSVN Distributed File System Service
- "D:\Techexcel\Program Files\VisualSVN Server\bin\vdfssvc.exe" runservice
- disabled
- Allows to create, manage and automatically synchronize distributed Subversion repositories.

+ @%SystemRoot%\system32\vds.exe,-100
- %SystemRoot%\System32\vds.exe
- Load on Demand
- @%SystemRoot%\system32\vds.exe,-112

+ VisualSVN HTTP Service
- "D:\Techexcel\Program Files\VisualSVN Server\bin\vsvnhttpsvc.exe" -k runservice -C "LoadModule log_visualsvn_module bin/mod_log_visualsvn.so" -E nul
- Auto Load
- Makes the VisualSVN Server accessible by end users through the HTTP(S) protocol.

+ @%systemroot%\system32\icsvc.dll,-801
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-802

+ @%systemroot%\system32\icsvc.dll,-101
- %systemroot%\system32\svchost.exe -k ICService -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-102

+ @%systemroot%\system32\icsvc.dll,-201
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-202

+ @%systemroot%\system32\icsvcext.dll,-601
- %systemroot%\system32\svchost.exe -k ICService -p
- Load on Demand
- @%systemroot%\system32\icsvcext.dll,-602

+ @%systemroot%\system32\icsvc.dll,-301
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-302

+ @%systemroot%\system32\icsvc.dll,-401
- %systemroot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-402

+ @%systemroot%\system32\icsvc.dll,-901
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-902

+ @%systemroot%\system32\icsvcext.dll,-501
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvcext.dll,-502

+ VMware Remote Console Emulator
- C:\Program Files (x86)\vmrx\vmrc.exe
- Auto Load
- Provides support for remote console for ESXI connections.

+ VisualSVN Repository Configurator Service
- "D:\Techexcel\Program Files\VisualSVN Server\bin\vrepocfgsvc.exe"
- Load on Demand
- Provides server-side support for VisualSVN Repository Configurator.

+ @%systemroot%\system32\vssvc.exe,-102
- %systemroot%\system32\vssvc.exe
- Load on Demand
- @%systemroot%\system32\vssvc.exe,-101

+ VisualSVN Background Job Service
- "D:\Techexcel\Program Files\VisualSVN Server\bin\vsvnjobsvc.exe"
- Auto Load
- Schedules and executes background jobs for VisualSVN Server.

+ VisualSVN Search Index Service
- "D:\Techexcel\Program Files\VisualSVN Server\bin\vsvnsearchsvc.exe" runservice
- disabled
- Provides content indexing and search capabilities for VisualSVN Server.

+ @%SystemRoot%\system32\w32time.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\w32time.dll,-201

+ @%windir%\system32\inetsrv\iisres.dll,-30014
- %windir%\system32\svchost.exe -k apphost
- Load on Demand
- @%windir%\system32\inetsrv\iisres.dll,-30015

+ @%windir%\system32\inetsrv\iisres.dll,-30003
- %windir%\system32\svchost.exe -k iissvcs
- Auto Load
- @%windir%\system32\inetsrv\iisres.dll,-30004

+ @WaaSMedicSvc.dll,-100
- %systemroot%\system32\svchost.exe -k wusvcs -p
- Load on Demand
- @WaaSMedicSvc.dll,-101

+ @%SystemRoot%\System32\WalletService.dll,-1000
- %SystemRoot%\System32\svchost.exe -k appmodel -p
- disabled
- @%SystemRoot%\System32\WalletService.dll,-1001

+ @%SystemRoot%\System32\Windows.WARP.JITService.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\Windows.WARP.JITService.dll,-101

+ @%windir%\system32\inetsrv\iisres.dll,-30001
- %windir%\system32\svchost.exe -k iissvcs
- Load on Demand
- @%windir%\system32\inetsrv\iisres.dll,-30002

+ Wazuh
- "C:\Program Files (x86)\ossec-agent\wazuh-agent.exe"
- Auto Load
- Wazuh Windows Agent

+ @%systemroot%\system32\wbiosrvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k WbioSvcGroup
- Load on Demand
- @%systemroot%\system32\wbiosrvc.dll,-101

+ @%SystemRoot%\System32\wcmsvc.dll,-4097
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Auto Load
- @%SystemRoot%\System32\wcmsvc.dll,-4098

+ @%systemroot%\system32\wdi.dll,-502
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- Load on Demand
- @%systemroot%\system32\wdi.dll,-503

+ @%systemroot%\system32\wdi.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\wdi.dll,-501

+ @%SystemRoot%\system32\wecsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k NetworkService -p
- Load on Demand
- @%SystemRoot%\system32\wecsvc.dll,-201

+ @%systemroot%\system32\wephostsvc.dll,-100
- %systemroot%\system32\svchost.exe -k WepHostSvcGroup
- Load on Demand
- @%systemroot%\system32\wephostsvc.dll,-101

+ @%SystemRoot%\System32\wercplsupport.dll,-101
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\System32\wercplsupport.dll,-100

+ @%SystemRoot%\System32\wersvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k WerSvcGroup
- Load on Demand
- @%SystemRoot%\System32\wersvc.dll,-101

+ @%SystemRoot%\system32\wiarpc.dll,-2
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\wiarpc.dll,-1

+ @%SystemRoot%\system32\winhttp.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\winhttp.dll,-101

+ @%Systemroot%\system32\wbem\wmisvc.dll,-205
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%Systemroot%\system32\wbem\wmisvc.dll,-204

+ @%Systemroot%\system32\wsmsvc.dll,-101
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Auto Load
- @%Systemroot%\system32\wsmsvc.dll,-102

+ VNC Server Version 4
- "C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service
- Auto Load
-

+ @%SystemRoot%\system32\flightsettings.dll,-103
- %systemroot%\system32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\system32\flightsettings.dll,-104

+ @%SystemRoot%\system32\wlidsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\wlidsvc.dll,-101

+ @%Systemroot%\system32\wbem\wmiapsrv.exe,-110
- %systemroot%\system32\wbem\WmiApSrv.exe
- Load on Demand
- @%Systemroot%\system32\wbem\wmiapsrv.exe,-111

+ @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101
- "%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe"
- Load on Demand
- @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-102

+ @%windir%\system32\inetsrv\iisres.dll,-20001
- %windir%\system32\inetsrv\wmsvc.exe
- Load on Demand
- @%windir%\system32\inetsrv\iisres.dll,-20002

+ @%SystemRoot%\system32\wpdbusenum.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\wpdbusenum.dll,-101

+ @%SystemRoot%\system32\wpnservice.dll,-1
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\system32\wpnservice.dll,-2

+ @%systemroot%\system32\SearchIndexer.exe,-103
- %systemroot%\system32\SearchIndexer.exe /Embedding
- Auto Load
- @%systemroot%\system32\SearchIndexer.exe,-104

+ Windows Update
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%systemroot%\system32\wuaueng.dll,-106

+ @wpdfs.inf,%WPDFS_SvcName%;WPD File System driver
- \SystemRoot\system32\DRIVERS\WUDFRd.sys
- Load on Demand
- @wpdfs.inf,%WPDFS_SvcDesc%;User mode driver that enables communication with removable storage devices via the WPD interface


Services :
+ Acronis Agent Core Service
- "C:\Program Files\Common Files\Acronis\Agent\aakore.exe" run
- Auto Load
- Enables Acronis Agent Core Service.

+ Acronis Active Protection Service
- "C:\Program Files\Common Files\Acronis\ActiveProtection\active_protection_service.exe"
- Auto Load
- Acronis Active Protection Service

+ Acronis Cyber Protection Service
- "C:\Program Files\BackupClient\CyberProtect\cyber-protect-service.exe"
- Auto Load
- Acronis Cyber Protection Service

+ Acronis Scheduler2 Service
- "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe"
- Auto Load
- Provides scheduling for tasks of Acronis components.

+ AdoeCheck
- "C:\Program Files\Git\AdobeCheck.exe"
- Auto Load
- AdoeCheck

+ @%SystemRoot%\system32\AJRouter.dll,-2
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\AJRouter.dll,-1

+ @%SystemRoot%\system32\Alg.exe,-112
- %SystemRoot%\System32\alg.exe
- Load on Demand
- @%SystemRoot%\system32\Alg.exe,-113

+ Agentless Management Service
- "C:\Program Files\OEM\AMS\service\ams.exe"
- Auto Load
- Provides out of band management system with OS-level Agentless Management information and Active Health System events.

+ @%windir%\system32\inetsrv\iisres.dll,-30011
- %windir%\system32\svchost.exe -k apphost
- Auto Load
- @%windir%\system32\inetsrv\iisres.dll,-30012

+ @%systemroot%\system32\appidsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\appidsvc.dll,-101

+ @%systemroot%\system32\appinfo.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\appinfo.dll,-101

+ @appmgmts.dll,-3250
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @appmgmts.dll,-3251

+ @%SystemRoot%\System32\AppReadiness.dll,-1000
- %SystemRoot%\System32\svchost.exe -k AppReadiness -p
- Load on Demand
- @%SystemRoot%\System32\AppReadiness.dll,-1001

+ @%systemroot%\system32\AppVClient.exe,-102
- %systemroot%\system32\AppVClient.exe
- disabled
- @%systemroot%\system32\AppVClient.exe,-101

+ @%SystemRoot%\system32\appxdeploymentserver.dll,-1
- %systemroot%\system32\svchost.exe -k wsappx -p
- Load on Demand
- @%SystemRoot%\system32\appxdeploymentserver.dll,-2

+ @%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1
- %systemroot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
- Load on Demand
- @%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-2

+ @%SystemRoot%\system32\AudioEndpointBuilder.dll,-204
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\AudioEndpointBuilder.dll,-205

+ @%SystemRoot%\system32\audiosrv.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\audiosrv.dll,-201

+ @%SystemRoot%\system32\AxInstSV.dll,-103
- %SystemRoot%\system32\svchost.exe -k AxInstSVGroup
- disabled
- @%SystemRoot%\system32\AxInstSV.dll,-104

+ AzureAttestService
- C:\Windows\system32\svchost.exe -k AzureAttestService
- Auto Load
-

+ @%SystemRoot%\system32\bfe.dll,-1001
- %systemroot%\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p
- Auto Load
- @%SystemRoot%\system32\bfe.dll,-1002

+ Background Intelligent Transfer Service
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\qmgr.dll,-1001

+ @%windir%\system32\bisrv.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @%windir%\system32\bisrv.dll,-101

+ @%SystemRoot%\system32\BTAGService.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\BTAGService.dll,-102

+ @%SystemRoot%\system32\BthAvctpSvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\BthAvctpSvc.dll,-102

+ @%SystemRoot%\System32\bthserv.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\System32\bthserv.dll,-102

+ @%SystemRoot%\system32\CapabilityAccessManager.dll,-1
- %SystemRoot%\system32\svchost.exe -k appmodel -p
- Load on Demand
- @%SystemRoot%\system32\CapabilityAccessManager.dll,-2

+ @%SystemRoot%\system32\cdpsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @%SystemRoot%\system32\cdpsvc.dll,-101

+ @%SystemRoot%\System32\certprop.dll,-11
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\certprop.dll,-12

+ @%SystemRoot%\system32\ClipSVC.dll,-103
- %SystemRoot%\System32\svchost.exe -k wsappx -p
- Load on Demand
- @%SystemRoot%\system32\ClipSVC.dll,-104

+ @comres.dll,-947
- %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
- Load on Demand
- @comres.dll,-948

+ @%SystemRoot%\system32\coremessaging.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork -p
- Auto Load
- @%SystemRoot%\system32\coremessaging.dll,-2

+ @%SystemRoot%\system32\cryptsvc.dll,-1001
- %SystemRoot%\system32\svchost.exe -k NetworkService -p
- Auto Load
- @%SystemRoot%\system32\cryptsvc.dll,-1002

+ @%systemroot%\system32\cscsvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- disabled
- @%systemroot%\system32\cscsvc.dll,-201

+ @combase.dll,-5012
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @combase.dll,-5013

+ @%SystemRoot%\system32\defragsvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k defragsvc
- Load on Demand
- @%SystemRoot%\system32\defragsvc.dll,-102

+ @%SystemRoot%\system32\das.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\das.dll,-101

+ @%SystemRoot%\system32\umpnpmgr.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Load on Demand
- @%SystemRoot%\system32\umpnpmgr.dll,-101

+ @%SystemRoot%\system32\DevQueryBroker.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\DevQueryBroker.dll,-101

+ @%SystemRoot%\system32\dhcpcore.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\dhcpcore.dll,-101

+ @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000
- %SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe
- Load on Demand
- @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1001

+ @%SystemRoot%\system32\diagtrack.dll,-3001
- %SystemRoot%\System32\svchost.exe -k utcsvc -p
- Auto Load
- @%SystemRoot%\system32\diagtrack.dll,-3002

+ @%systemroot%\system32\Windows.Internal.Management.dll,-100
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\Windows.Internal.Management.dll,-101

+ @%SystemRoot%\system32\dmwappushsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\system32\dmwappushsvc.dll,-201

+ @%SystemRoot%\System32\dnsapi.dll,-101
- %SystemRoot%\system32\svchost.exe -k NetworkService -p
- Auto Load
- @%SystemRoot%\System32\dnsapi.dll,-102

+ @%systemroot%\system32\dosvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Load on Demand
- @%systemroot%\system32\dosvc.dll,-101

+ @%systemroot%\system32\dot3svc.dll,-1102
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\dot3svc.dll,-1103

+ @%systemroot%\system32\dps.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork -p
- Auto Load
- @%systemroot%\system32\dps.dll,-501

+ @%SystemRoot%\system32\DeviceSetupManager.dll,-1000
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\DeviceSetupManager.dll,-1001

+ @%SystemRoot%\system32\dssvc.dll,-10003
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\dssvc.dll,-10002

+ @%systemroot%\system32\eapsvc.dll,-1
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\eapsvc.dll,-2

+ Microsoft Edge Update Service (edgeupdate)
- "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svc
- Auto Load
- Keeps your Microsoft software up to date. If this service is disabled or stopped, your Microsoft software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Microsoft software using it.

+ Microsoft Edge Update Service (edgeupdatem)
- "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /medsvc
- Load on Demand
- Keeps your Microsoft software up to date. If this service is disabled or stopped, your Microsoft software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Microsoft software using it.

+ @%SystemRoot%\system32\efssvc.dll,-100
- %SystemRoot%\System32\lsass.exe
- Load on Demand
- @%SystemRoot%\system32\efssvc.dll,-101

+ @%SystemRoot%\system32\embeddedmodesvc.dll,-201
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\embeddedmodesvc.dll,-202

+ Acronis Emergency Updater 0.0.1.2826
- "C:\Program Files (x86)\Common Files\Acronis\EmergencyUpdater\0.0.1.2826\emergency-updater.exe" --emergency-updater
- Auto Load
- Enables Acronis Emergency Updater.

+ @EnterpriseAppMgmtSvc.dll,-1
- %systemroot%\system32\svchost.exe -k appmodel -p
- Load on Demand
- @EnterpriseAppMgmtSvc.dll,-2

+ @%SystemRoot%\system32\wevtsvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\wevtsvc.dll,-201

+ @comres.dll,-2450
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @comres.dll,-2451

+ @%systemroot%\system32\fdPHost.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%systemroot%\system32\fdPHost.dll,-101

+ @%systemroot%\system32\fdrespub.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- Load on Demand
- @%systemroot%\system32\fdrespub.dll,-101

+ @%systemroot%\system32\FntCache.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @%systemroot%\system32\FntCache.dll,-101

+ @%SystemRoot%\system32\PresentationHost.exe,-3309
- %systemroot%\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
- Load on Demand
- @%SystemRoot%\system32\PresentationHost.exe,-3310

+ @%systemroot%\system32\FrameServer.dll,-100
- %SystemRoot%\System32\svchost.exe -k Camera
- Load on Demand
- @%systemroot%\system32\FrameServer.dll,-101

+ Google Chrome Elevation Service (GoogleChromeElevationService)
- "C:\Program Files\Google\Chrome\Application\143.0.7499.171\elevation_service.exe"
- Load on Demand
- Provides encryption services and a secure way for recovering Google Chrome if it gets out of date. If this service is disabled, Google Chrome may lose access to encrypted data, and Google Chrome may not be able recover itself.

+ Google Updater Internal Service (GoogleUpdaterInternalService145.0.7569.0)
- "C:\Program Files (x86)\Google\GoogleUpdater\145.0.7569.0\updater.exe" --system --windows-service --service=update-internal
- Auto Load
- Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it.

+ Google Updater Service (GoogleUpdaterService145.0.7569.0)
- "C:\Program Files (x86)\Google\GoogleUpdater\145.0.7569.0\updater.exe" --system --windows-service --service=update
- Auto Load
- Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it.

+ @gpapi.dll,-112
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @gpapi.dll,-113

+ @%SystemRoot%\system32\GraphicsPerfSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k GraphicsPerfSvcGroup
- disabled
- @%SystemRoot%\system32\GraphicsPerfSvc.dll,-101

+ @%SystemRoot%\System32\hidserv.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\hidserv.dll,-102

+ HPE Smart Array SR Event Notification Service
- "C:\Program Files\HPE\HpePqiESrv\hpepqiesrv.exe"
- Auto Load
- The HPE Smart Array SR Notification Service provides event notification to the Windows system event log, HPE ProLiant Integrated Management Log and HPE Integrity System Event Log for systems using the HPE Smart Array controller driver.

+ @%SystemRoot%\system32\hvhostsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\hvhostsvc.dll,-101

+ @%SystemRoot%\System32\tetheringservice.dll,-4097
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- disabled
- @%SystemRoot%\System32\tetheringservice.dll,-4098

+ @%windir%\system32\inetsrv\iisres.dll,-30007
- %windir%\system32\inetsrv\inetinfo.exe
- Auto Load
- @%windir%\system32\inetsrv\iisres.dll,-30008

+ @%SystemRoot%\system32\ikeext.dll,-501
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\system32\ikeext.dll,-502

+ @%SystemRoot%\system32\InstallService.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\InstallService.dll,-201

+ @%SystemRoot%\system32\iphlpsvc.dll,-500
- %SystemRoot%\System32\svchost.exe -k NetSvcs -p
- Auto Load
- @%SystemRoot%\system32\iphlpsvc.dll,-501

+ @keyiso.dll,-100
- %SystemRoot%\system32\lsass.exe
- Load on Demand
- @keyiso.dll,-101

+ @%systemroot%\system32\kpssvc.dll,-100
- %systemroot%\system32\svchost.exe -k KpsSvcGroup
- Load on Demand
- @%systemroot%\system32\kpssvc.dll,-101

+ @comres.dll,-2946
- %SystemRoot%\System32\svchost.exe -k NetworkServiceAndNoImpersonation -p
- Load on Demand
- @comres.dll,-2947

+ @%systemroot%\system32\srvsvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k smbsvcs
- Auto Load
- @%systemroot%\system32\srvsvc.dll,-101

+ @%systemroot%\system32\wkssvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Auto Load
- @%systemroot%\system32\wkssvc.dll,-101

+ @%SystemRoot%\System32\lfsvc.dll,-1
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\System32\lfsvc.dll,-2

+ @%SystemRoot%\system32\licensemanagersvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\licensemanagersvc.dll,-201

+ @%SystemRoot%\system32\lltdres.dll,-1
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- disabled
- @%SystemRoot%\system32\lltdres.dll,-2

+ @%SystemRoot%\system32\lmhsvc.dll,-101
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\lmhsvc.dll,-102

+ @%windir%\system32\lsm.dll,-1001
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @%windir%\system32\lsm.dll,-1002

+ Techexcel_Lucee
- D:\Techexcel\lucee\tomcat\bin\Tomcat9.exe //RS//Lucee
- Auto Load
- Apache Tomcat 9.0.45 Server - https://tomcat.apache.org/

+ Techexcel_Lucee02
- D:\Techexcel\lucee02\tomcat\bin\Tomcat9.exe //RS//Lucee02
- Auto Load
- Apache Tomcat 9.0.45 Server - https://tomcat.apache.org/

+ Techexcel_Lucee11
- D:\Techexcel\LoadBalancing\Lucee11\tomcat\bin\Tomcat9.exe //RS//Lucee11
- Auto Load
- Apache Tomcat 9.0.62 Server - https://tomcat.apache.org/

+ Techexcel_Lucee12
- D:\Techexcel\LoadBalancing\Lucee12\tomcat\bin\Tomcat9.exe //RS//Lucee12
- Auto Load
- Apache Tomcat 9.0.62 Server - https://tomcat.apache.org/

+ Techexcel_Lucee13
- D:\Techexcel\LoadBalancing\Lucee13\tomcat\bin\Tomcat9.exe //RS//Lucee13
- Auto Load
- Apache Tomcat 9.0.62 Server - https://tomcat.apache.org/

+ Techexcel_Lucee14
- D:\Techexcel\LoadBalancing\Lucee14\tomcat\bin\Tomcat9.exe //RS//Lucee14
- Auto Load
- Apache Tomcat 9.0.62 Server - https://tomcat.apache.org/

+ @%SystemRoot%\System32\moshost.dll,-100
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- disabled
- @%SystemRoot%\System32\moshost.dll,-101

+ Microsoft Edge Elevation Service (MicrosoftEdgeElevationService)
- "C:\Program Files (x86)\Microsoft\Edge\Application\143.0.3650.96\elevation_service.exe"
- Load on Demand
- Provides elevated privileges for Microsoft Edge.

+ Acronis Managed Machine Service
- "C:\Program Files\BackupClient\BackupAndRecovery\mms.exe"
- Auto Load
- Enables data backup and recovery on the machine.

+ @%SystemRoot%\system32\FirewallAPI.dll,-23090
- %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p
- Auto Load
- @%SystemRoot%\system32\FirewallAPI.dll,-23091

+ @comres.dll,-2797
- %SystemRoot%\System32\msdtc.exe
- Auto Load
- @comres.dll,-2798

+ @%SystemRoot%\system32\iscsidsc.dll,-5000
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\iscsidsc.dll,-5001

+ @%SystemRoot%\system32\msimsg.dll,-27
- %systemroot%\system32\msiexec.exe /V
- Load on Demand
- @%SystemRoot%\system32\msimsg.dll,-32

+ MS-MPI Launch Service
- "C:\Program Files\Microsoft MPI\Bin\msmpilaunchsvc.exe"
- Load on Demand
- Service for launching MS-MPI applications

+ SQL Full-text Filter Daemon Launcher (MSSQLSERVER)
- "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL15.MSSQLSERVER
- Load on Demand
- Service to launch full-text filter daemon process which will perform document filtering and word breaking for SQL Server full-text search. Disabling this service will make full-text search features of SQL Server unavailable.

+ SQL Server Launchpad (MSSQLSERVER)
- "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\launchpad.exe" -launcher RLauncher.dll -launcher Pythonlauncher.dll -launcher commonlauncher.dll -pipename sqlsatellitelaunch -timeout 600000 -logPath "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\LOG\ExtensibilityLog" -workingDir "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExtensibilityData" -externalLanguagesTempDir "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLanguagesTemp" -externalLanguagesDir "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLanguages" -externalLibrariesTempDir "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLibrariesTemp" -externalLibrariesDir "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLibraries" -satelliteDllPath "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlsatellite.dll"
- Auto Load
- Service to launch Advanced Analytics Extensions Launchpad process that enables integration with Microsoft R Open using standard T-SQL statements. Disabling this service will make Advanced Analytics features of SQL Server unavailable.

+ SQL Server (MSSQLSERVER)
- "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER
- Auto Load
- Provides storage, processing and controlled access of data, and rapid transaction processing.

+ @%SystemRoot%\system32\ncasvc.dll,-3009
- %SystemRoot%\System32\svchost.exe -k NetSvcs -p
- Load on Demand
- @%SystemRoot%\system32\ncasvc.dll,-3008

+ @%SystemRoot%\system32\ncbservice.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\ncbservice.dll,-501

+ @%SystemRoot%\System32\netlogon.dll,-102
- %systemroot%\system32\lsass.exe
- Load on Demand
- @%SystemRoot%\System32\netlogon.dll,-103

+ @%SystemRoot%\system32\netman.dll,-109
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\netman.dll,-110

+ @%SystemRoot%\system32\netprofmsvc.dll,-202
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\netprofmsvc.dll,-203

+ @%SystemRoot%\system32\NetSetupSvc.dll,-3
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\NetSetupSvc.dll,-4

+ @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8201
- %systemroot%\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
- disabled
- @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8200

+ @%SystemRoot%\System32\NgcCtnrSvc.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\NgcCtnrSvc.dll,-2

+ @%SystemRoot%\System32\ngcsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\ngcsvc.dll,-101

+ @%SystemRoot%\System32\nlasvc.dll,-1
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Auto Load
- @%SystemRoot%\System32\nlasvc.dll,-2

+ @%SystemRoot%\system32\nsisvc.dll,-200
- %systemroot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @%SystemRoot%\system32\nsisvc.dll,-201

+ NXLog
- "C:\Program Files\nxlog\nxlog.exe" -c "C:\Program Files\nxlog\conf\nxlog.conf"
- Auto Load
- This service is responsible for running the NXLog agent. See www.nxlog.co.

+ Office 64 Source Engine
- "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
- Load on Demand
- Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports.

+ @%SystemRoot%\system32\pcasvc.dll,-1
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\pcasvc.dll,-2

+ @%systemroot%\sysWow64\perfhost.exe,-2
- %SystemRoot%\SysWow64\perfhost.exe
- Load on Demand
- @%systemroot%\SysWow64\perfhost.exe,-1

+ @%SystemRoot%\system32\PhoneserviceRes.dll,-10000
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- disabled
- @%SystemRoot%\system32\PhoneserviceRes.dll,-10001

+ @%systemroot%\system32\pla.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork -p
- Load on Demand
- @%systemroot%\system32\pla.dll,-501

+ @%SystemRoot%\system32\umpnpmgr.dll,-200
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Load on Demand
- @%SystemRoot%\system32\umpnpmgr.dll,-101

+ @%SystemRoot%\System32\polstore.dll,-5010
- %SystemRoot%\system32\svchost.exe -k NetworkServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\polstore.dll,-5011

+ @%SystemRoot%\system32\umpo.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @%SystemRoot%\system32\umpo.dll,-101

+ @%systemroot%\system32\profsvc.dll,-300
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%systemroot%\system32\profsvc.dll,-301

+ @%SystemRoot%\system32\pushtoinstall.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\system32\pushtoinstall.dll,-201

+ @%SystemRoot%\system32\qwave.dll,-1
- %windir%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- Load on Demand
- @%SystemRoot%\system32\qwave.dll,-2

+ @%Systemroot%\system32\rasauto.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%Systemroot%\system32\rasauto.dll,-201

+ @%Systemroot%\system32\rasmans.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Auto Load
- @%Systemroot%\system32\rasmans.dll,-201

+ Redis
- "D:\Techexcel\Program Files\Redis\redis-server.exe" --service-run "D:\Techexcel\Program Files\Redis\redis.windows-service.conf"
- Auto Load
- This service runs the Redis server

+ @%Systemroot%\system32\mprdim.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs
- disabled
- @%Systemroot%\system32\mprdim.dll,-201

+ Remote Registry
- %SystemRoot%\system32\svchost.exe -k localService -p
- Load on Demand
- @regsvc.dll,-2

+ @%SystemRoot%\system32\RMapi.dll,-1001
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
- disabled
- @%SystemRoot%\system32\RMapi.dll,-1002

+ @%windir%\system32\RpcEpMap.dll,-1001
- %SystemRoot%\system32\svchost.exe -k RPCSS -p
- Auto Load
- @%windir%\system32\RpcEpMap.dll,-1002

+ @%systemroot%\system32\Locator.exe,-2
- %SystemRoot%\system32\locator.exe
- Load on Demand
- @%systemroot%\system32\Locator.exe,-3

+ @combase.dll,-5010
- %SystemRoot%\system32\svchost.exe -k rpcss -p
- Auto Load
- @combase.dll,-5011

+ @gpapi.dll,-114
- %SystemRoot%\system32\RSoPProv.exe
- Load on Demand
- @gpapi.dll,-115

+ @%systemroot%\system32\sacsvr.dll,-500
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\sacsvr.dll,-501

+ @%SystemRoot%\system32\samsrv.dll,-1
- %SystemRoot%\system32\lsass.exe
- Auto Load
- @%SystemRoot%\system32\samsrv.dll,-2

+ @%SystemRoot%\System32\SCardSvr.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
- Load on Demand
- @%SystemRoot%\System32\SCardSvr.dll,-5

+ @%SystemRoot%\System32\ScDeviceEnum.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- disabled
- @%SystemRoot%\System32\ScDeviceEnum.dll,-101

+ @%SystemRoot%\system32\schedsvc.dll,-100
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\system32\schedsvc.dll,-101

+ @%SystemRoot%\System32\certprop.dll,-13
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\certprop.dll,-14

+ @%SystemRoot%\system32\seclogon.dll,-7001
- %windir%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\seclogon.dll,-7000

+ @%systemroot%\system32\SecurityHealthAgent.dll,-1002
- %SystemRoot%\system32\SecurityHealthService.exe
- Load on Demand
- @%systemroot%\system32\SecurityHealthAgent.dll,-1001

+ @%SystemRoot%\System32\SEMgrSvc.dll,-1001
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- disabled
- @%SystemRoot%\System32\SEMgrSvc.dll,-1002

+ @%SystemRoot%\system32\Sens.dll,-200
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\system32\Sens.dll,-201

+ @%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1001
- "%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe"
- Load on Demand
- @%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1002

+ @%SystemRoot%\system32\SensorDataService.exe,-101
- %SystemRoot%\System32\SensorDataService.exe
- disabled
- @%SystemRoot%\system32\SensorDataService.exe,-102

+ @%SystemRoot%\System32\sensorservice.dll,-1000
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\sensorservice.dll,-1001

+ @%SystemRoot%\System32\sensrsvc.dll,-1000
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- Load on Demand
- @%SystemRoot%\System32\sensrsvc.dll,-1001

+ @%SystemRoot%\System32\SessEnv.dll,-1026
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\System32\SessEnv.dll,-1027

+ @%SystemRoot%\System32\SgrmBroker.exe,-100
- %SystemRoot%\system32\SgrmBroker.exe
- Load on Demand
- @%SystemRoot%\System32\SgrmBroker.exe,-101

+ @%SystemRoot%\system32\ipnathlp.dll,-106
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\system32\ipnathlp.dll,-107

+ @%SystemRoot%\System32\shsvcs.dll,-12288
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\System32\shsvcs.dll,-12289

+ @%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-101

+ System Management Assistant Service
- "C:\Program Files\OEM\AMS\service\sma.exe"
- disabled
- Provides OS-level inband and out of band Agentless Management information and Active Health System events.

+ @%SystemRoot%\System32\smphost.dll,-102
- %SystemRoot%\System32\svchost.exe -k smphost
- Load on Demand
- @%SystemRoot%\System32\smphost.dll,-101

+ @firewallapi.dll,-50323
- %SystemRoot%\System32\snmptrap.exe
- Load on Demand
- @firewallapi.dll,-50324

+ @%SystemRoot%\system32\sppsvc.exe,-101
- %SystemRoot%\system32\sppsvc.exe
- Auto Load
- @%SystemRoot%\system32\sppsvc.exe,-100

+ SQL Server Browser
- "C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe"
- disabled
- Provides SQL Server connection information to client computers.

+ SQL Server Agent (MSSQLSERVER)
- "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER
- Auto Load
- Executes jobs, monitors SQL Server, fires alerts, and allows automation of some administrative tasks.

+ SQL Server CEIP service (MSSQLSERVER)
- "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlceip.exe" -Service
- Load on Demand
- CEIP service for Sql server

+ SQL Server VSS Writer
- "C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
- Auto Load
- Provides the interface to backup/restore Microsoft SQL server through the Windows VSS infrastructure.

+ @%systemroot%\system32\ssdpsrv.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- disabled
- @%systemroot%\system32\ssdpsrv.dll,-101

+ OpenSSH Authentication Agent
- %SystemRoot%\System32\OpenSSH\ssh-agent.exe
- disabled
- Agent to hold private keys used for public key authentication.

+ @%SystemRoot%\system32\sstpsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\sstpsvc.dll,-201

+ @%SystemRoot%\system32\windows.staterepository.dll,-1
- %SystemRoot%\system32\svchost.exe -k appmodel -p
- Load on Demand
- @%SystemRoot%\system32\windows.staterepository.dll,-2

+ @%SystemRoot%\system32\wiaservc.dll,-9
- %SystemRoot%\system32\svchost.exe -k imgsvc
- Load on Demand
- @%SystemRoot%\system32\wiaservc.dll,-10

+ @%SystemRoot%\System32\StorSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\StorSvc.dll,-101

+ @%SystemRoot%\system32\svsvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\svsvc.dll,-102

+ @%SystemRoot%\System32\swprv.dll,-103
- %SystemRoot%\System32\svchost.exe -k swprv
- Load on Demand
- @%SystemRoot%\System32\swprv.dll,-102

+ @%SystemRoot%\system32\sysmain.dll,-1000
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\sysmain.dll,-1001

+ @%windir%\system32\SystemEventsBrokerServer.dll,-1001
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @%windir%\system32\SystemEventsBrokerServer.dll,-1002

+ @%SystemRoot%\system32\TabSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\TabSvc.dll,-101

+ @%SystemRoot%\system32\tapisrv.dll,-10100
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Load on Demand
- @%SystemRoot%\system32\tapisrv.dll,-10101

+ Techexcel_API
- D:\Techexcel_DP\Install\nssm.exe
- Auto Load
-

+ Techexcel_API_2
- D:\Techexcel_DP\Install_2\nssm.exe
- Auto Load
-

+ Techexcel_Jenkins_Slave
- D:\Techexcel\Jenkins\nssm.exe
- Auto Load
-

+ Techexcel_Nginx_Server
- D:\Techexcel\LoadBalancing\Install\nssm.exe
- Auto Load
-

+ Techexcel_PHP_ApacheServer
- "D:\Techexcel\PHPApp\Apache24\bin\httpd.exe" -k runservice
- Auto Load
- Apache/2.4.59 (Win64) OpenSSL/1.1.1q

+ @%SystemRoot%\System32\termsrv.dll,-268
- %SystemRoot%\System32\svchost.exe -k termsvcs
- Load on Demand
- @%SystemRoot%\System32\termsrv.dll,-267

+ @%SystemRoot%\System32\themeservice.dll,-8192
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\System32\themeservice.dll,-8193

+ Tib Mounter Service
- "C:\Program Files (x86)\Common Files\Acronis\TibMounter64\tib_mounter_service.exe"
- Load on Demand
-

+ @%SystemRoot%\system32\TieringEngineService.exe,-702
- %SystemRoot%\system32\TieringEngineService.exe
- Load on Demand
- @%SystemRoot%\system32\TieringEngineService.exe,-701

+ @%windir%\system32\TimeBrokerServer.dll,-1001
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%windir%\system32\TimeBrokerServer.dll,-1002

+ @%systemroot%\system32\tokenbroker.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\tokenbroker.dll,-101

+ @%SystemRoot%\system32\trkwks.dll,-1
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\trkwks.dll,-2

+ @%SystemRoot%\servicing\TrustedInstaller.exe,-100
- %SystemRoot%\servicing\TrustedInstaller.exe
- Load on Demand
- @%SystemRoot%\servicing\TrustedInstaller.exe,-101

+ @%SystemRoot%\system32\tzautoupdate.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- disabled
- @%SystemRoot%\system32\tzautoupdate.dll,-201

+ @%systemroot%\system32\ualsvc.dll,-102
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Auto Load
- @%systemroot%\system32\ualsvc.dll,-101

+ @%systemroot%\system32\AgentService.exe,-102
- %systemroot%\system32\AgentService.exe
- disabled
- @%systemroot%\system32\AgentService.exe,-101

+ @%SystemRoot%\system32\umrdp.dll,-1000
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\umrdp.dll,-1001

+
- cmd /c start C:\Windows\PLA\spawner.exe
- Auto Load
-

+ @%systemroot%\system32\upnphost.dll,-213
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- disabled
- @%systemroot%\system32\upnphost.dll,-214

+ @%systemroot%\system32\usermgr.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%systemroot%\system32\usermgr.dll,-101

+ @%systemroot%\system32\usocore.dll,-101
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%systemroot%\system32\usocore.dll,-102

+ @%SystemRoot%\system32\vaultsvc.dll,-1003
- %SystemRoot%\system32\lsass.exe
- Load on Demand
- @%SystemRoot%\system32\vaultsvc.dll,-1004

+ VisualSVN Distributed File System Service
- "D:\Techexcel\Program Files\VisualSVN Server\bin\vdfssvc.exe" runservice
- disabled
- Allows to create, manage and automatically synchronize distributed Subversion repositories.

+ @%SystemRoot%\system32\vds.exe,-100
- %SystemRoot%\System32\vds.exe
- Load on Demand
- @%SystemRoot%\system32\vds.exe,-112

+ VisualSVN HTTP Service
- "D:\Techexcel\Program Files\VisualSVN Server\bin\vsvnhttpsvc.exe" -k runservice -C "LoadModule log_visualsvn_module bin/mod_log_visualsvn.so" -E nul
- Auto Load
- Makes the VisualSVN Server accessible by end users through the HTTP(S) protocol.

+ @%systemroot%\system32\icsvc.dll,-801
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-802

+ @%systemroot%\system32\icsvc.dll,-101
- %systemroot%\system32\svchost.exe -k ICService -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-102

+ @%systemroot%\system32\icsvc.dll,-201
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-202

+ @%systemroot%\system32\icsvcext.dll,-601
- %systemroot%\system32\svchost.exe -k ICService -p
- Load on Demand
- @%systemroot%\system32\icsvcext.dll,-602

+ @%systemroot%\system32\icsvc.dll,-301
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-302

+ @%systemroot%\system32\icsvc.dll,-401
- %systemroot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-402

+ @%systemroot%\system32\icsvc.dll,-901
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-902

+ @%systemroot%\system32\icsvcext.dll,-501
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvcext.dll,-502

+ VMware Remote Console Emulator
- C:\Program Files (x86)\vmrx\vmrc.exe
- Auto Load
- Provides support for remote console for ESXI connections.

+ VisualSVN Repository Configurator Service
- "D:\Techexcel\Program Files\VisualSVN Server\bin\vrepocfgsvc.exe"
- Load on Demand
- Provides server-side support for VisualSVN Repository Configurator.

+ @%systemroot%\system32\vssvc.exe,-102
- %systemroot%\system32\vssvc.exe
- Load on Demand
- @%systemroot%\system32\vssvc.exe,-101

+ VisualSVN Background Job Service
- "D:\Techexcel\Program Files\VisualSVN Server\bin\vsvnjobsvc.exe"
- Auto Load
- Schedules and executes background jobs for VisualSVN Server.

+ VisualSVN Search Index Service
- "D:\Techexcel\Program Files\VisualSVN Server\bin\vsvnsearchsvc.exe" runservice
- disabled
- Provides content indexing and search capabilities for VisualSVN Server.

+ @%SystemRoot%\system32\w32time.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\w32time.dll,-201

+ @%windir%\system32\inetsrv\iisres.dll,-30014
- %windir%\system32\svchost.exe -k apphost
- Load on Demand
- @%windir%\system32\inetsrv\iisres.dll,-30015

+ @%windir%\system32\inetsrv\iisres.dll,-30003
- %windir%\system32\svchost.exe -k iissvcs
- Auto Load
- @%windir%\system32\inetsrv\iisres.dll,-30004

+ @WaaSMedicSvc.dll,-100
- %systemroot%\system32\svchost.exe -k wusvcs -p
- Load on Demand
- @WaaSMedicSvc.dll,-101

+ @%SystemRoot%\System32\WalletService.dll,-1000
- %SystemRoot%\System32\svchost.exe -k appmodel -p
- disabled
- @%SystemRoot%\System32\WalletService.dll,-1001

+ @%SystemRoot%\System32\Windows.WARP.JITService.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\Windows.WARP.JITService.dll,-101

+ @%windir%\system32\inetsrv\iisres.dll,-30001
- %windir%\system32\svchost.exe -k iissvcs
- Load on Demand
- @%windir%\system32\inetsrv\iisres.dll,-30002

+ Wazuh
- "C:\Program Files (x86)\ossec-agent\wazuh-agent.exe"
- Auto Load
- Wazuh Windows Agent

+ @%systemroot%\system32\wbiosrvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k WbioSvcGroup
- Load on Demand
- @%systemroot%\system32\wbiosrvc.dll,-101

+ @%SystemRoot%\System32\wcmsvc.dll,-4097
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Auto Load
- @%SystemRoot%\System32\wcmsvc.dll,-4098

+ @%systemroot%\system32\wdi.dll,-502
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- Load on Demand
- @%systemroot%\system32\wdi.dll,-503

+ @%systemroot%\system32\wdi.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\wdi.dll,-501

+ @%SystemRoot%\system32\wecsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k NetworkService -p
- Load on Demand
- @%SystemRoot%\system32\wecsvc.dll,-201

+ @%systemroot%\system32\wephostsvc.dll,-100
- %systemroot%\system32\svchost.exe -k WepHostSvcGroup
- Load on Demand
- @%systemroot%\system32\wephostsvc.dll,-101

+ @%SystemRoot%\System32\wercplsupport.dll,-101
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\System32\wercplsupport.dll,-100

+ @%SystemRoot%\System32\wersvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k WerSvcGroup
- Load on Demand
- @%SystemRoot%\System32\wersvc.dll,-101

+ @%SystemRoot%\system32\wiarpc.dll,-2
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\wiarpc.dll,-1

+ @%SystemRoot%\system32\winhttp.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\winhttp.dll,-101

+ @%Systemroot%\system32\wbem\wmisvc.dll,-205
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%Systemroot%\system32\wbem\wmisvc.dll,-204

+ @%Systemroot%\system32\wsmsvc.dll,-101
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Auto Load
- @%Systemroot%\system32\wsmsvc.dll,-102

+ VNC Server Version 4
- "C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service
- Auto Load
-

+ @%SystemRoot%\system32\flightsettings.dll,-103
- %systemroot%\system32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\system32\flightsettings.dll,-104

+ @%SystemRoot%\system32\wlidsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\wlidsvc.dll,-101

+ @%Systemroot%\system32\wbem\wmiapsrv.exe,-110
- %systemroot%\system32\wbem\WmiApSrv.exe
- Load on Demand
- @%Systemroot%\system32\wbem\wmiapsrv.exe,-111

+ @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101
- "%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe"
- Load on Demand
- @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-102

+ @%windir%\system32\inetsrv\iisres.dll,-20001
- %windir%\system32\inetsrv\wmsvc.exe
- Load on Demand
- @%windir%\system32\inetsrv\iisres.dll,-20002

+ @%SystemRoot%\system32\wpdbusenum.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\wpdbusenum.dll,-101

+ @%SystemRoot%\system32\wpnservice.dll,-1
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\system32\wpnservice.dll,-2

+ @%systemroot%\system32\SearchIndexer.exe,-103
- %systemroot%\system32\SearchIndexer.exe /Embedding
- Auto Load
- @%systemroot%\system32\SearchIndexer.exe,-104

+ Windows Update
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%systemroot%\system32\wuaueng.dll,-106
70629 - Microsoft Windows AutoRuns Winlogon
-
Synopsis
Report programs that startup associates with the winlogon process.
Description
Report the startup locations associated with the winlogon process.

These values could add features to the logon process, assist in authentication, or set screen savers.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers
+ CLSID : {1b283861-754f-4022-ad47-a5eaaa618894}
- Name : Smartcard Reader Selection Provider
- Value : %SystemRoot%\system32\SmartcardCredentialProvider.dll

+ CLSID : {1ee7337f-85ac-45e2-a23c-37c753209769}
- Name : Smartcard WinRT Provider
- Value : %SystemRoot%\system32\SmartcardCredentialProvider.dll

+ CLSID : {2135f72a-90b5-4ed3-a7f1-8bb705ac276a}
- Name : PicturePasswordLogonProvider
- Value : %SystemRoot%\system32\credprovslegacy.dll

+ CLSID : {25CBB996-92ED-457e-B28C-4774084BD562}
- Name : GenericProvider
- Value : %SystemRoot%\system32\credprovs.dll

+ CLSID : {27FBDB57-B613-4AF2-9D7E-4FA7A66C21AD}
- Name : TrustedSignal Credential Provider
- Value : %systemroot%\system32\TrustedSignalCredProv.dll

+ CLSID : {3dd6bec0-8193-4ffe-ae25-e08e39ea4063}
- Name : NPProvider
- Value : %SystemRoot%\system32\credprovs.dll

+ CLSID : {48B4E58D-2791-456C-9091-D524C6C706F2}
- Name : Secondary Authentication Factor Credential Provider
- Value : C:\Windows\System32\devicengccredprov.dll

+ CLSID : {600e7adb-da3e-41a4-9225-3c0399e88c0c}
- Name : CngCredUICredentialProvider
- Value : %systemroot%\system32\cngcredui.dll

+ CLSID : {60b78e88-ead8-445c-9cfd-0b87f74ea6cd}
- Name : PasswordProvider
- Value : %SystemRoot%\system32\credprovs.dll

+ CLSID : {8FD7E19C-3BF7-489B-A72C-846AB3678C96}
- Name : Smartcard Credential Provider
- Value : %SystemRoot%\system32\SmartcardCredentialProvider.dll

+ CLSID : {94596c7e-3744-41ce-893e-bbf09122f76a}
- Name : Smartcard Pin Provider
- Value : %SystemRoot%\system32\SmartcardCredentialProvider.dll

+ CLSID : {BEC09223-B018-416D-A0AC-523971B639F5}
- Name : WinBio Credential Provider
- Value : %SystemRoot%\System32\BioCredProv.dll

+ CLSID : {C5D7540A-CD51-453B-B22B-05305BA03F07}
- Name : Cloud Experience Credential Provider
- Value : C:\Windows\System32\cxcredprov.dll

+ CLSID : {cb82ea12-9f71-446d-89e1-8d0924e1256e}
- Name : PINLogonProvider
- Value : %SystemRoot%\system32\credprovslegacy.dll

+ CLSID : {D6886603-9D2F-4EB2-B667-1971041FA96B}
- Name : NGC Credential Provider
- Value : C:\Windows\System32\ngccredprov.dll

+ CLSID : {e74e57b0-6c6d-44d5-9cda-fb2df5ed7435}
- Name : CertCredProvider
- Value : %systemroot%\system32\certCredProvider.dll

+ CLSID : {F8A0B131-5F68-486c-8040-7E8FC3C85BB6}
- Name : WLIDCredentialProvider
- Value : %SystemRoot%\system32\wlidcredprov.dll

+ CLSID : {F8A1793B-7873-4046-B2A7-1F318747F427}
- Name : FIDO Credential Provider
- Value : %systemroot%\system32\fidocredprov.dll


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Provider Filters
+ CLSID : {DDC0EED2-ADBE-40b6-A217-EDE16A79A0DE}
- Name : GenericFilter
- Value : %SystemRoot%\system32\credprovs.dll


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\PLAP Providers
+ CLSID : {5537E283-B1E7-4EF8-9C6E-7AB0AFE5056D}
- Name : RasProvider
- Value : %SystemRoot%\system32\rasplap.dll




70630 - Microsoft Windows AutoRuns Winsock Provider
-
Synopsis
Report Winsock providers extensions.
Description
A Winsock provider is a type of Layered Service Provider (LSP) that can be used to control protocols by inserting itself into the TCP/IP stack. This can commonly be used to help filter web traffic, enable QoS type services, or anything to hook network traffic controls.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries
- Name : AF_UNIX
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60100
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60101
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60102
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60200
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60201
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60202
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-100
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-101
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-102
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-103
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : MSAFD L2CAP [Bluetooth]
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : MSAFD RfComm [Bluetooth]
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : Hyper-V RAW
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll


+ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries
- LibararyPath : %SystemRoot%\system32\napinsp.dll
- LibararyPath : %SystemRoot%\System32\mswsock.dll
- LibararyPath : %SystemRoot%\System32\winrnr.dll
- LibararyPath : %SystemRoot%\system32\NLAapi.dll
- LibararyPath : %SystemRoot%\system32\wshbth.dll


+ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64
- Name : AF_UNIX
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60100
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60101
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60102
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60200
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60201
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60202
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-100
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-101
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-102
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-103
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : MSAFD L2CAP [Bluetooth]
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : MSAFD RfComm [Bluetooth]
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : Hyper-V RAW
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll


+ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64
- LibararyPath : %SystemRoot%\system32\napinsp.dll
- LibararyPath : %SystemRoot%\System32\mswsock.dll
- LibararyPath : %SystemRoot%\System32\winrnr.dll
- LibararyPath : %SystemRoot%\system32\NLAapi.dll
- LibararyPath : %SystemRoot%\system32\wshbth.dll

92363 - Microsoft Windows Device Logs
-
Synopsis
Nessus was able to collect available device logs from the remote host.
Description
Nessus was able to collect available device logs from the remote Windows host and add them as attachments.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

Device logs attached.
92364 - Microsoft Windows Environment Variables
-
Synopsis
Nessus was able to collect and report environment variables from the remote host.
Description
Nessus was able to collect system and active account environment variables on the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0757
Plugin Information
Published: 2016/07/19, Modified: 2022/06/24
Plugin Output

tcp/0

Global Environment Variables :
processor_level : 6
comspec : %SystemRoot%\system32\cmd.exe
msmpi_benchmarks : C:\Program Files\Microsoft MPI\Benchmarks\
username : SYSTEM
os : Windows_NT
number_of_processors : 32
server_ip : 172.17.100.31
temp : %SystemRoot%\TEMP
processor_revision : 5504
path : D:\app\techexcel\product\11.2.0\client_1\bin;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Microsoft MPI\Bin\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;D:\Program Files\Microsoft SQL Server\Client SDK\ODBC\170\Tools\Binn\;D:\Program Files (x86)\Microsoft SQL Server\150\Tools\Binn\;D:\Program Files\Microsoft SQL Server\150\Tools\Binn\;D:\Program Files\Microsoft SQL Server\150\DTS\Binn\;D:\Program Files (x86)\Microsoft SQL Server\150\DTS\Binn\;C:\Program Files\Azure Data Studio\bin;C:\Program Files\Java\jdk1.8.0_161\bin;C:\Program Files\\SUT\bin;D:\Techexcel\PHPApp\php;C:\ProgramData\ComposerSetup\bin;C:\Program Files\BackupClient\CommandLineTool\;C:\Program Files (x86)\Common Files\Acronis\FileProtector\;C:\Program Files (x86)\Common Files\Acronis\FileProtector64\;C:\Program Files\BackupClient\PyShell\bin\;C:\Program Files (x86)\Common Files\Acronis\SnapAPI\;C:\Program Files\Git\cmd;D:\Techexcel\Program Files\VisualSVN Server\bin;D:\Techexcel\Program Files\TortoiseSVN\bin;D:\Techexcel\Program Files\Redis\
tmp : %SystemRoot%\TEMP
processor_identifier : Intel64 Family 6 Model 85 Stepping 4, GenuineIntel
driverdata : C:\Windows\System32\Drivers\DriverData
msmpi_bin : C:\Program Files\Microsoft MPI\Bin\
pathext : .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
processor_architecture : AMD64
visualsvn_server : D:\Techexcel\Program Files\VisualSVN Server\
psmodulepath : %ProgramFiles%\WindowsPowerShell\Modules;%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules;D:\Program Files (x86)\Microsoft SQL Server\150\Tools\PowerShell\Modules\;D:\Techexcel\Program Files\VisualSVN Server\PowerShellModules
windir : %SystemRoot%

Active User Environment Variables
- S-1-5-21-1185746460-1788592564-4118236249-500
temp : %USERPROFILE%\AppData\Local\Temp
path : %USERPROFILE%\AppData\Local\Microsoft\WindowsApps;
tmp : %USERPROFILE%\AppData\Local\Temp
- S-1-5-21-1185746460-1788592564-4118236249-1002
temp : %USERPROFILE%\AppData\Local\Temp
path : %USERPROFILE%\AppData\Local\Microsoft\WindowsApps;
tmp : %USERPROFILE%\AppData\Local\Temp
- S-1-5-21-1185746460-1788592564-4118236249-1001
temp : %USERPROFILE%\AppData\Local\Temp
path : %USERPROFILE%\AppData\Local\Microsoft\WindowsApps;;C:\Program Files\Azure Data Studio\bin;C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\bin;C:\Users\techexcel\AppData\Roaming\Composer\vendor\bin
tmp : %USERPROFILE%\AppData\Local\Temp
- S-1-5-21-1185746460-1788592564-4118236249-1012
temp : %USERPROFILE%\AppData\Local\Temp
path : %USERPROFILE%\AppData\Local\Microsoft\WindowsApps;
tmp : %USERPROFILE%\AppData\Local\Temp
92365 - Microsoft Windows Hosts File
-
Synopsis
Nessus was able to collect the hosts file from the remote host.
Description
Nessus was able to collect the hosts file from the remote Windows host and report it as attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2020/01/27
Plugin Output

tcp/0

Windows hosts file attached.

MD5: bd0f42040d65ea2ca37da4997231d392
SHA-1: 4c7569089c42150212842eab822fc69a07f8b1a4
SHA-256: 1245f47b2928e0593c30ac0c2cfe04b80fc2df99c7e2864f85f4b2f08eca5f1c
187318 - Microsoft Windows Installed
-
Synopsis
The remote host is running Microsoft Windows.
Description
The remote host is running Microsoft Windows.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/12/27, Modified: 2025/12/10
Plugin Output

tcp/0


OS Name : Microsoft Windows Server 2019 1809
Vendor : Microsoft
Product : Windows Server
Release : 2019 1809
Edition : Datacenter
Version : 10.0.17763.7009
Role : server
Kernel : Windows NT 10.0
Architecture : x64
CPE v2.2 : cpe:/o:microsoft:windows_server_2019:10.0.17763.7009:-:~~datacenter~~x64~
CPE v2.3 : cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.7009:-:*:*:datacenter:*:x64:*
Type : local
Method : SMB
Confidence : 100

20811 - Microsoft Windows Installed Software Enumeration (credentialed check)
-
Synopsis
It is possible to enumerate installed software.
Description
This plugin lists software potentially installed on the remote host by crawling the registry entries in :

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall HKLM\SOFTWARE\Microsoft\Updates

Note that these entries do not necessarily mean the applications are actually installed on the remote host - they may have been left behind by uninstallers, or the associated files may have been manually removed.
Solution
Remove any applications that are not compliant with your organization's acceptable use and security policies.
Risk Factor
None
References
XREF IAVT:0001-T-0501
Plugin Information
Published: 2006/01/26, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


The following software are installed on the remote host :

7-Zip 24.09 (x64) [version 24.09]
Acronis Cyber Protect [version 24.11.39130]
FreeFileSync [version 12.1] [installed on 2023/03/24]
Git [version 2.47.1.2] [installed on 2025/02/06]
Google Chrome [version 143.0.7499.171] [installed on 2026/01/09]
Agentless Management Service [version 2.51.4.1]
Hotfix 4188 for SQL Server 2019 (KB5007182) (64-bit) [version 15.0.4188.2] [installed on 2022/01/14]
Hotfix 4355 for SQL Server 2019 (KB5033688) (64-bit) [version 15.0.4355.3] [installed on 2024/04/06]
Hotfix 4365 for SQL Server 2019 (KB5035123) (64-bit) [version 15.0.4365.2] [installed on 2024/05/08]
Hotfix 4420 for SQL Server 2019 (KB5049296) (64-bit) [version 15.0.4420.2] [installed on 2025/02/15]
Lucee [version 5.3.8.201] [installed on 2022/01/14]
Matrox Graphics Software (remove only) [version 4.5.0.5]
Microsoft Edge [version 143.0.3650.96] [installed on 2025/12/20]
Microsoft Edge Update [version 1.3.215.9]
Microsoft Help Viewer 2.3 [version 2.3.28107]
Microsoft SQL Server 2019 (64-bit)
Notepad++ (64-bit x64) [version 8.7.7]
VNC Enterprise Edition E4.6.1 [version E4.6.1] [installed on 2022/01/08]
TreeSize Free V4.4.2 [version 4.4.2] [installed on 2022/04/20]
WinMerge 2.16.28.0 x64 [version 2.16.28.0] [installed on 2025/01/27]
WinRAR 7.01 (64-bit) [version 7.01.0]
iReport 5.5.0 [version 5.5.0]
wkhtmltopdf
SQL Server Management Studio for Reporting Services [version 15.0.18390.0] [installed on 2022/01/13]
Redis on Windows [version 5.0.14.1] [installed on 2025/12/16]
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 [version 12.0.30501.0]
Microsoft Visual C++ 2005 Redistributable (x64) [version 8.0.56336] [installed on 2022/01/17]
Microsoft ODBC Driver 17 for SQL Server [version 17.10.6.1] [installed on 2024/05/08]
SQL Server 2019 Common Files [version 15.0.2000.5] [installed on 2025/02/15]
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 [version 12.0.21005] [installed on 2022/01/13]
Microsoft SQL Server 2019 RsFx Driver [version 15.0.4420.2] [installed on 2025/02/15]
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.38.33135 [version 14.38.33135] [installed on 2024/05/09]
Microsoft Visual C++ 2017 Redistributable (x86) - 14.14.26429 [version 14.14.26429.4]
SQL Server 2019 XEvent [version 15.0.2000.5] [installed on 2025/02/15]
TortoiseSVN 1.14.9.29743 (64 bit) [version 1.14.29743] [installed on 2025/04/14]
Integrated Smart Update Tools for Windows [version 4.5.0.0] [installed on 2024/06/08]
Smart Storage Administrator [version 3.40.3.0] [installed on 2024/06/18]
Java 8 Update 161 (64-bit) [version 8.0.1610.12] [installed on 2022/01/14]
SQL Server 2019 sql_inst_java [version 15.0.2000.5] [installed on 2022/01/13]
SQL Server 2019 SQL Diagnostics [version 15.0.2000.5] [installed on 2022/01/13]
Microsoft VSS Writer for SQL Server 2019 [version 15.0.2000.5] [installed on 2025/02/15]
Microsoft SQL Server 2019 T-SQL Language Service [version 15.0.2000.5] [installed on 2022/01/13]
NVMe Drive Eject NMI Fix [version 1.1.0.0] [installed on 2022/01/08]
MergeModule2012 [version 1.0.0] [installed on 2022/01/07]
SQL Server Management Studio [version 15.0.18390.0] [installed on 2022/01/13]
HPE Lights-Out Online Configuration Utility [version 6.0.0.0] [installed on 2024/06/08]
Integration Services [version 15.0.2000.168] [installed on 2022/01/13]
Java Auto Updater [version 2.8.161.12] [installed on 2022/01/14]
Microsoft SQL Server 2019 Setup (English) [version 15.0.4420.2] [installed on 2025/02/15]
SSMS Post Install Tasks [version 15.0.18390.0] [installed on 2022/01/13]
Microsoft Analysis Services OLE DB Provider [version 15.0.2000.568] [installed on 2022/01/13]
BonCode AJP 1.3 Connector [version 1.0] [installed on 2022/01/14]
Browser for SQL Server 2019 [version 15.0.2000.5] [installed on 2025/02/15]
SQL Server 2019 Database Engine Shared [version 15.0.2000.5] [installed on 2022/01/13]
SQL Server 2019 Shared Management Objects [version 15.0.2000.5] [installed on 2025/02/15]
Java SE Development Kit 8 Update 161 (64-bit) [version 8.0.1610.12] [installed on 2022/01/14]
Azure Data Studio [version 1.51.1] [installed on 2025/03/26]
Microsoft Visual C++ 2017 x86 Additional Runtime - 14.14.26429 [version 14.14.26429] [installed on 2022/01/13]
Composer - PHP Dependency Manager [installed on 2024/10/17]
Microsoft OLE DB Driver for SQL Server [version 18.7.4.0] [installed on 2025/02/15]
Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.14.26429 [version 14.14.26429] [installed on 2022/01/13]
SQL Server 2019 DMF [version 15.0.2000.5] [installed on 2025/02/15]
Microsoft MPI (10.1.12498.17) [version 10.1.12498.17] [installed on 2022/01/14]
HPE Smart Array SR Event Notification Service [version 1.2.1.67] [installed on 2024/06/08]
SQL Server 2019 Shared Management Objects Extensions [version 15.0.2000.5] [installed on 2025/02/15]
Microsoft Access database engine 2016 (English) [version 16.0.4519.1000] [installed on 2023/01/05]
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 [version 12.0.21005] [installed on 2022/01/14]
Microsoft Visual Studio Tools for Applications 2017 x86 Hosting Support [version 15.0.27520] [installed on 2022/01/13]
Cyber Protect [version 24.11.39130] [installed on 2024/12/19]
SQL Server 2019 Connection Info [version 15.0.2000.5] [installed on 2022/01/13]
SQL Server Management Studio for Analysis Services [version 15.0.18390.0] [installed on 2022/01/13]
SQL Server 2019 Database Engine Services [version 15.0.2000.5] [installed on 2025/02/15]
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 [version 12.0.21005] [installed on 2022/01/14]
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.38.33135 [version 14.38.33135] [installed on 2024/05/09]
Visual Studio 2017 Isolated Shell for SSMS [version 15.0.28307.421] [installed on 2022/01/13]
Wazuh Agent [version 4.11.2] [installed on 2025/04/16]
Microsoft SQL Server 2012 Native Client [version 11.4.7515.2] [installed on 2025/02/15]
Microsoft Visual Studio Tools for Applications 2017 x64 Hosting Support [version 15.0.27520] [installed on 2022/01/13]
SQL Server 2019 sql_inst_mr [version 15.0.2000.5] [installed on 2025/02/15]
SQL Server 2019 Advanced Analytics [version 15.0.2000.5] [installed on 2025/02/15]
NXLog-CE [version 3.2.2329] [installed on 2023/10/11]
SQL Server 2019 Full text search [version 15.0.2000.5] [installed on 2025/02/15]
SQL Server 2019 Batch Parser [version 15.0.2000.5] [installed on 2025/02/15]
VisualSVN Server 5.4.3 [version 5.4.3.0] [installed on 2025/04/14]
DataForLiveRisk [version 1.0.0] [installed on 2025/07/04]
IIS URL Rewrite Module 2 [version 7.2.2] [installed on 2022/01/14]
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 [version 12.0.21005] [installed on 2022/01/13]
SQL Server 2019 sql_azul_java [version 15.0.2000.5] [installed on 2025/02/15]
Microsoft SQL Server Management Studio - 18.10 [version 15.0.18390.0]
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.38.33135 [version 14.38.33135.0]
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 [version 12.0.30501.0]
Microsoft Visual Studio Tools for Applications 2017 [version 15.0.27520]
178102 - Microsoft Windows Installed Software Version Enumeration
-
Synopsis
Enumerates installed software versions.
Description
This plugin enumerates the installed software version by interrogating information obtained from various registry entries and files on disk. This plugin provides a best guess at the software version and a confidence level for that version.

Note that the versions detected here do not necessarily indicate the actual installed version nor do they necessarily mean that the application is actually installed on the remote host. In some cases there may be artifacts left behind by uninstallers on the system.
Solution
Remove any applications that are not compliant with your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2023/07/10, Modified: 2024/07/15
Plugin Output

tcp/445/cifs


The following software information is available on the remote host :

- Microsoft MPI (10.1.12498.17)
Best Confidence Version : 10.1.12498.17
Version Confidence Level : 2
All Possible Versions : 10.1.12498.17
Other Version Data
[InstallDate] :
Raw Value : 2022/01/14
[InstallLocation] :
Raw Value : C:\Program Files\Microsoft MPI\
[UninstallString] :
Raw Value : MsiExec.exe /X{8499ACD3-C1E3-45AB-BF96-DA491727EBE1}
[VersionMinor] :
Raw Value : 1
[Version] :
Raw Value : 167850194
[VersionMajor] :
Raw Value : 10
[Publisher] :
Raw Value : Microsoft Corporation
[DisplayVersion] :
Raw Value : 10.1.12498.17
[DisplayName] :
Raw Value : Microsoft MPI (10.1.12498.17)

- WinRAR 7.01 (64-bit)
Best Confidence Version : 7.1.0.0
Version Confidence Level : 3
All Possible Versions : 7.1.0.0, 7.01.0
Other Version Data
[VersionMajor] :
Raw Value : 7
[InstallLocation] :
Raw Value : C:\Program Files\WinRAR
[DisplayName] :
Raw Value : WinRAR 7.01 (64-bit)
[UninstallString] :
Raw Value : C:\Program Files\WinRAR\uninstall.exe
Parsed File Path : C:\Program Files\WinRAR\uninstall.exe
Parsed File Version : 7.1.0.0
[DisplayVersion] :
Raw Value : 7.01.0
[Publisher] :
Raw Value : win.rar GmbH
[VersionMinor] :
Raw Value : 1
[DisplayIcon] :
Raw Value : C:\Program Files\WinRAR\WinRAR.exe
Parsed File Path : C:\Program Files\WinRAR\WinRAR.exe
Parsed File Version : 7.1.0.0

- Matrox Graphics Software (remove only)
Best Confidence Version : 4.5.0.5
Version Confidence Level : 2
All Possible Versions : 4.5.0.5
Other Version Data
[DisplayName] :
Raw Value : Matrox Graphics Software (remove only)
[UninstallString] :
Raw Value : %SystemRoot%\SysWOW64\Matrox\Matrox.WddmUninstaller.exe
[DisplayVersion] :
Raw Value : 4.5.0.5

- Hotfix 4420 for SQL Server 2019 (KB5049296) (64-bit)
Best Confidence Version : 2019.150.4420.2
Version Confidence Level : 3
All Possible Versions : 2019.150.4420.2, 15.0.4420.2
Other Version Data
[DisplayName] :
Raw Value : Hotfix 4420 for SQL Server 2019 (KB5049296) (64-bit)
[UninstallString] :
Raw Value : "C:\Program Files\Microsoft SQL Server\150\Setup Bootstrap\Update Cache\KB5049296\QFE\setup.exe" /Action=RemovePatch /AllInstances
Parsed File Path : C:\Program Files\Microsoft SQL Server\150\Setup Bootstrap\Update Cache\KB5049296\QFE\setup.exe
Parsed File Version : 2019.150.4420.2
[InstallDate] :
Raw Value : 2025/02/15
[DisplayVersion] :
Raw Value : 15.0.4420.2
[Publisher] :
Raw Value : Microsoft Corporation

- Hotfix 4365 for SQL Server 2019 (KB5035123) (64-bit)
Best Confidence Version : 2019.150.4365.2
Version Confidence Level : 3
All Possible Versions : 2019.150.4365.2, 15.0.4365.2
Other Version Data
[DisplayName] :
Raw Value : Hotfix 4365 for SQL Server 2019 (KB5035123) (64-bit)
[UninstallString] :
Raw Value : "C:\Program Files\Microsoft SQL Server\150\Setup Bootstrap\Update Cache\KB5035123\QFE\setup.exe" /Action=RemovePatch /AllInstances
Parsed File Path : C:\Program Files\Microsoft SQL Server\150\Setup Bootstrap\Update Cache\KB5035123\QFE\setup.exe
Parsed File Version : 2019.150.4365.2
[InstallDate] :
Raw Value : 2024/05/08
[DisplayVersion] :
Raw Value : 15.0.4365.2
[Publisher] :
Raw Value : Microsoft Corporation

- TortoiseSVN 1.14.9.29743 (64 bit)
Best Confidence Version : 1.14.29743
Version Confidence Level : 2
All Possible Versions : 23.114.17507, 1.14.29743
Other Version Data
[VersionMajor] :
Raw Value : 1
[Version] :
Raw Value : 17724463
Parsed Version : 23.114.17507
[DisplayName] :
Raw Value : TortoiseSVN 1.14.9.29743 (64 bit)
[UninstallString] :
Raw Value : MsiExec.exe /I{23095FB3-EE67-4F2C-9827-7BE50F389442}
[InstallDate] :
Raw Value : 2025/04/14
[DisplayVersion] :
Raw Value : 1.14.29743
[Publisher] :
Raw Value : TortoiseSVN
[VersionMinor] :
Raw Value : 14

- SQL Server 2019 Database Engine Shared
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Database Engine Shared
[UninstallString] :
Raw Value : MsiExec.exe /I{DE5B7937-D5B5-4157-BC30-BB87F021CFF0}
[InstallDate] :
Raw Value : 2025/02/15
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft Help Viewer 2.3
Best Confidence Version : 2.3.28107
Version Confidence Level : 2
All Possible Versions : 51.119.37191, 2.3.28107
Other Version Data
[InstallDate] :
Raw Value : 2022/01/13
[DisplayIcon] :
Raw Value : msiexec.exe
[InstallLocation] :
Raw Value : C:\Program Files (x86)\Microsoft Help Viewer\v2.3\
[UninstallString] :
Raw Value : msiexec.exe /X{BEFC10C1-7032-3C8E-80BC-621A77BFEABD}
[VersionMinor] :
Raw Value : 0
[Version] :
Raw Value : 33779147
Parsed Version : 51.119.37191
[VersionMajor] :
Raw Value : 2
[DisplayVersion] :
Raw Value : 2.3.28107
[DisplayName] :
Raw Value : Microsoft Help Viewer 2.3

- Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.38.33135
Best Confidence Version : 14.38.33135.0
Version Confidence Level : 3
All Possible Versions : 14.38.33135.0
Other Version Data
[DisplayName] :
Raw Value : Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.38.33135
[UninstallString] :
Raw Value : "C:\ProgramData\Package Cache\{c649ede4-f16a-4486-a117-dcc2f2a35165}\VC_redist.x64.exe" /uninstall
Parsed File Path : C:\ProgramData\Package Cache\{c649ede4-f16a-4486-a117-dcc2f2a35165}\VC_redist.x64.exe
Parsed File Version : 14.38.33135.0
[DisplayVersion] :
Raw Value : 14.38.33135.0
[DisplayIcon] :
Raw Value : C:\ProgramData\Package Cache\{c649ede4-f16a-4486-a117-dcc2f2a35165}\VC_redist.x64.exe,0
Parsed File Path : C:\ProgramData\Package Cache\{c649ede4-f16a-4486-a117-dcc2f2a35165}\VC_redist.x64.exe
Parsed File Version : 14.38.33135.0

- Browser for SQL Server 2019
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : Browser for SQL Server 2019
[UninstallString] :
Raw Value : MsiExec.exe /X{5E366957-8D78-4BB5-A790-96F97A9766BD}
[InstallDate] :
Raw Value : 2025/02/15
[DisplayVersion] :
Raw Value : 15.0.2000.5
[VersionMinor] :
Raw Value : 0

- SQL Server 2019 XEvent
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 XEvent
[UninstallString] :
Raw Value : MsiExec.exe /I{2129312E-5204-4F3A-9039-B6D34DBB00FB}
[InstallDate] :
Raw Value : 2025/02/15
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005
Best Confidence Version : 12.0.21005
Version Confidence Level : 2
All Possible Versions : 12.0.21005
Other Version Data
[VersionMajor] :
Raw Value : 12
[Version] :
Raw Value : 201347597
[DisplayName] :
Raw Value : Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005
[UninstallString] :
Raw Value : MsiExec.exe /X{929FBD26-9020-399B-9A7A-751D61F0B942}
[InstallDate] :
Raw Value : 2022/01/14
[DisplayVersion] :
Raw Value : 12.0.21005
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- SQL Server 2019 Full text search
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Full text search
[UninstallString] :
Raw Value : MsiExec.exe /I{BFF9440C-BC5B-4326-A861-916CC3788A4A}
[InstallDate] :
Raw Value : 2025/02/15
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- wkhtmltox 0.12.2.1
Best Confidence Version :
Version Confidence Level :
All Possible Versions :
Other Version Data
[DisplayName] :
Raw Value : wkhtmltox 0.12.2.1
[UninstallString] :
Raw Value : "D:\Techexcel\Lucee\tomcat\webapps\ROOT\wkhtmltopdf\uninstall.exe"
Parsed File Path : D:\Techexcel\Lucee\tomcat\webapps\ROOT\wkhtmltopdf\uninstall.exe

- SQL Server 2019 Shared Management Objects Extensions
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Shared Management Objects Extensions
[UninstallString] :
Raw Value : MsiExec.exe /I{C7E6D4B7-CB10-4239-BA04-D9339B39D0BD}
[InstallDate] :
Raw Value : 2022/01/13
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- SQL Server 2019 sql_azul_java
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 sql_azul_java
[UninstallString] :
Raw Value : MsiExec.exe /I{FF7B55CB-CDC3-4084-B27A-6C3B65800DD4}
[InstallDate] :
Raw Value : 2025/02/15
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft ODBC Driver 17 for SQL Server
Best Confidence Version : 17.10.6.1
Version Confidence Level : 2
All Possible Versions : 17.10.6.1
Other Version Data
[VersionMajor] :
Raw Value : 17
[Version] :
Raw Value : 285868038
[DisplayName] :
Raw Value : Microsoft ODBC Driver 17 for SQL Server
[UninstallString] :
Raw Value : MsiExec.exe /I{0E0F96AC-80DE-4400-A40C-429D63293651}
[InstallDate] :
Raw Value : 2024/05/08
[DisplayVersion] :
Raw Value : 17.10.6.1
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 10

- SQL Server Management Studio
Best Confidence Version : 15.0.18390.0
Version Confidence Level : 2
All Possible Versions : 15.0.18390.0
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251676630
[DisplayName] :
Raw Value : SQL Server Management Studio
[UninstallString] :
Raw Value : MsiExec.exe /I{3F338A1B-1DCF-458F-8189-416B09B7D077}
[InstallDate] :
Raw Value : 2022/01/13
[DisplayVersion] :
Raw Value : 15.0.18390.0
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Agentless Management Service
Best Confidence Version : 2.51.4.1
Version Confidence Level : 2
All Possible Versions : 54.137.26482, 2.51.4.1
Other Version Data
[InstallDate] :
Raw Value : 2024/06/08
[InstallLocation] :
Raw Value : %ProgramFiles%\OEM\AMS\Service
[UninstallString] :
Raw Value : MsiExec.exe /X{51E9FF2E-A4C2-4ADC-A3BE-651CE43A9F00}
[VersionMinor] :
Raw Value : 51
[Version] :
Raw Value : 36896772
Parsed Version : 54.137.26482
[VersionMajor] :
Raw Value : 2
[Publisher] :
Raw Value : Hewlett Packard Enterprise Development LP
[DisplayVersion] :
Raw Value : 2.51.4.1
[DisplayName] :
Raw Value : Agentless Management Service

- NXLog-CE
Best Confidence Version : 3.2.2329
Version Confidence Level : 2
All Possible Versions : 80.70.20553, 3.2.2329
Other Version Data
[InstallDate] :
Raw Value : 2023/10/11
[InstallLocation] :
Raw Value : C:\Program Files\nxlog\
[UninstallString] :
Raw Value : MsiExec.exe /X{BE5E656D-853E-4570-AE57-A45967208689}
[VersionMinor] :
Raw Value : 2
[Version] :
Raw Value : 50465049
Parsed Version : 80.70.20553
[VersionMajor] :
Raw Value : 3
[Publisher] :
Raw Value : NXLog Ltd
[DisplayVersion] :
Raw Value : 3.2.2329
[DisplayName] :
Raw Value : NXLog-CE

- Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501
Best Confidence Version : 12.0.30501.0
Version Confidence Level : 3
All Possible Versions : 12.0.30501.0
Other Version Data
[DisplayName] :
Raw Value : Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501
[UninstallString] :
Raw Value : "C:\ProgramData\Package Cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe" /uninstall
Parsed File Path : C:\ProgramData\Package Cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe
Parsed File Version : 12.0.30501.0
[DisplayVersion] :
Raw Value : 12.0.30501.0
[DisplayIcon] :
Raw Value : C:\ProgramData\Package Cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe,0
Parsed File Path : C:\ProgramData\Package Cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe
Parsed File Version : 12.0.30501.0

- Microsoft Analysis Services OLE DB Provider
Best Confidence Version : 15.0.2000.568
Version Confidence Level : 2
All Possible Versions : 15.0.2000.568
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : Microsoft Analysis Services OLE DB Provider
[UninstallString] :
Raw Value : MsiExec.exe /I{4F1405AB-36A8-4383-9C1A-AE00491C255F}
[InstallDate] :
Raw Value : 2022/01/13
[DisplayVersion] :
Raw Value : 15.0.2000.568
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- IIS URL Rewrite Module 2
Best Confidence Version : 7.2.2
Version Confidence Level : 2
All Possible Versions : 7.2.2
Other Version Data
[VersionMajor] :
Raw Value : 7
[Version] :
Raw Value : 117571586
[DisplayName] :
Raw Value : IIS URL Rewrite Module 2
[UninstallString] :
Raw Value : MsiExec.exe /X{EB675D0A-2C95-405B-BEE8-B42A65D23E11}
[InstallDate] :
Raw Value : 2022/01/14
[DisplayVersion] :
Raw Value : 7.2.2
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 2

- WinMerge 2.16.28.0 x64
Best Confidence Version : 51.1052.0.0
Version Confidence Level : 3
All Possible Versions : 51.1052.0.0, 2.16.28.0
Other Version Data
[VersionMajor] :
Raw Value : 2
[InstallLocation] :
Raw Value : C:\Program Files\WinMerge\
[DisplayName] :
Raw Value : WinMerge 2.16.28.0 x64
[UninstallString] :
Raw Value : "C:\Program Files\WinMerge\unins000.exe"
Parsed File Path : C:\Program Files\WinMerge\unins000.exe
Parsed File Version : 51.1052.0.0
[InstallDate] :
Raw Value : 2025/01/27
[DisplayVersion] :
Raw Value : 2.16.28.0
[Publisher] :
Raw Value : Thingamahoochie Software
[VersionMinor] :
Raw Value : 16
[DisplayIcon] :
Raw Value : C:\Program Files\WinMerge\WinMergeU.exe
Parsed File Path : C:\Program Files\WinMerge\WinMergeU.exe
Parsed File Version : 2.16.28.0

- SQL Server Management Studio for Reporting Services
Best Confidence Version : 15.0.18390.0
Version Confidence Level : 2
All Possible Versions : 15.0.18390.0
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251676630
[DisplayName] :
Raw Value : SQL Server Management Studio for Reporting Services
[UninstallString] :
Raw Value : MsiExec.exe /I{0278A8F5-4DDC-40FF-95CC-1D4725CA074B}
[InstallDate] :
Raw Value : 2022/01/13
[DisplayVersion] :
Raw Value : 15.0.18390.0
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Notepad++ (64-bit x64)
Best Confidence Version : 8.7.7.0
Version Confidence Level : 3
All Possible Versions : 8.7.7.0, 8.7.7
Other Version Data
[VersionMajor] :
Raw Value : 8
[DisplayName] :
Raw Value : Notepad++ (64-bit x64)
[UninstallString] :
Raw Value : "C:\Program Files\Notepad++\uninstall.exe"
Parsed File Path : C:\Program Files\Notepad++\uninstall.exe
Parsed File Version : 8.7.7.0
[DisplayVersion] :
Raw Value : 8.7.7
[Publisher] :
Raw Value : Notepad++ Team
[VersionMinor] :
Raw Value : 77
[DisplayIcon] :
Raw Value : C:\Program Files\Notepad++\notepad++.exe
Parsed File Path : C:\Program Files\Notepad++\notepad++.exe
Parsed File Version : 8.7.7.0

- Integration Services
Best Confidence Version : 15.0.2000.168
Version Confidence Level : 2
All Possible Versions : 15.0.2000.168
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : Integration Services
[UninstallString] :
Raw Value : MsiExec.exe /I{4938A647-7EA4-4496-A843-5E338B91C07E}
[InstallDate] :
Raw Value : 2022/01/13
[DisplayVersion] :
Raw Value : 15.0.2000.168
[VersionMinor] :
Raw Value : 0

- Composer - PHP Dependency Manager
Best Confidence Version : 51.1052.0.0
Version Confidence Level : 3
All Possible Versions : 51.1052.0.0
Other Version Data
[InstallLocation] :
Raw Value : C:\Program Files (x86)\ComposerSetup\
[DisplayName] :
Raw Value : Composer - PHP Dependency Manager
[UninstallString] :
Raw Value : "C:\Program Files (x86)\ComposerSetup\unins000.exe"
Parsed File Path : C:\Program Files (x86)\ComposerSetup\unins000.exe
Parsed File Version : 51.1052.0.0
[InstallDate] :
Raw Value : 2024/10/17
[DisplayIcon] :
Raw Value : C:\Program Files (x86)\ComposerSetup\unins000.exe
Parsed File Path : C:\Program Files (x86)\ComposerSetup\unins000.exe
Parsed File Version : 51.1052.0.0

- HPE Smart Array SR Event Notification Service
Best Confidence Version : 1.2.1.67
Version Confidence Level : 2
All Possible Versions : 22.144.33417, 1.2.1.67
Other Version Data
[VersionMajor] :
Raw Value : 1
[Version] :
Raw Value : 16908289
Parsed Version : 22.144.33417
[DisplayName] :
Raw Value : HPE Smart Array SR Event Notification Service
[UninstallString] :
Raw Value : MsiExec.exe /X{8719FECF-5DF9-4C94-B288-AF9A1B5067F0}
[InstallDate] :
Raw Value : 2024/06/08
[DisplayVersion] :
Raw Value : 1.2.1.67
[Publisher] :
Raw Value : Hewlett Packard Enterprise Development LP
[VersionMinor] :
Raw Value : 2

- Microsoft Edge
Best Confidence Version : 143.0.3650.96
Version Confidence Level : 3
All Possible Versions : 143.0.3650.96
Other Version Data
[InstallDate] :
Raw Value : 2025/12/20
[DisplayIcon] :
Raw Value : C:\Program Files (x86)\Microsoft\Edge\Application\143.0.3650.96\msedge.exe,0
Parsed File Path : C:\Program Files (x86)\Microsoft\Edge\Application\143.0.3650.96\msedge.exe
Parsed File Version : 143.0.3650.96
[InstallLocation] :
Raw Value : C:\Program Files (x86)\Microsoft\Edge\Application
[UninstallString] :
Raw Value : "C:\Program Files (x86)\Microsoft\Edge\Application\143.0.3650.96\Installer\setup.exe" --uninstall --msedge --channel=stable --system-level --verbose-logging
Parsed File Path : C:\Program Files (x86)\Microsoft\Edge\Application\143.0.3650.96\Installer\setup.exe
Parsed File Version : 143.0.3650.96
[VersionMinor] :
Raw Value : 96
[Version] :
Raw Value : 143.0.3650.96
[VersionMajor] :
Raw Value : 3650
[DisplayVersion] :
Raw Value : 143.0.3650.96
[DisplayName] :
Raw Value : Microsoft Edge

- SQL Server 2019 DMF
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 DMF
[UninstallString] :
Raw Value : MsiExec.exe /I{FC8DC283-4A85-467F-8D0E-2FE4606DCCA1}
[InstallDate] :
Raw Value : 2022/01/13
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Java 8 Update 161 (64-bit)
Best Confidence Version : 8.0.1610.12
Version Confidence Level : 2
All Possible Versions : 8.0.1610.12
Other Version Data
[InstallDate] :
Raw Value : 2022/01/14
[InstallLocation] :
Raw Value : C:\Program Files\Java\jre1.8.0_161\
[UninstallString] :
Raw Value : MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F64180161F0}
[VersionMinor] :
Raw Value : 0
[Version] :
Raw Value : 134219338
[VersionMajor] :
Raw Value : 8
[Publisher] :
Raw Value : Oracle Corporation
[DisplayVersion] :
Raw Value : 8.0.1610.12
[DisplayName] :
Raw Value : Java 8 Update 161 (64-bit)

- Microsoft Visual C++ 2017 Redistributable (x86) - 14.14.26429
Best Confidence Version : 14.14.26429.4
Version Confidence Level : 3
All Possible Versions : 14.14.26429.4
Other Version Data
[DisplayName] :
Raw Value : Microsoft Visual C++ 2017 Redistributable (x86) - 14.14.26429
[UninstallString] :
Raw Value : "C:\ProgramData\Package Cache\{2019b6a0-8533-4a04-ac0e-b2c10bdb9841}\VC_redist.x86.exe" /uninstall
Parsed File Path : C:\ProgramData\Package Cache\{2019b6a0-8533-4a04-ac0e-b2c10bdb9841}\VC_redist.x86.exe
Parsed File Version : 14.14.26429.4
[DisplayVersion] :
Raw Value : 14.14.26429.4
[DisplayIcon] :
Raw Value : C:\ProgramData\Package Cache\{2019b6a0-8533-4a04-ac0e-b2c10bdb9841}\VC_redist.x86.exe,0
Parsed File Path : C:\ProgramData\Package Cache\{2019b6a0-8533-4a04-ac0e-b2c10bdb9841}\VC_redist.x86.exe
Parsed File Version : 14.14.26429.4

- FreeFileSync
Best Confidence Version : 12.1
Version Confidence Level : 2
All Possible Versions : 12.1
Other Version Data
[VersionMajor] :
Raw Value : 12
[InstallLocation] :
Raw Value : D:\techexcel\Jenkins\FreeFileSync\
[DisplayName] :
Raw Value : FreeFileSync
[UninstallString] :
Raw Value : "D:\techexcel\Jenkins\FreeFileSync\Uninstall\unins000.exe"
Parsed File Path : D:\techexcel\Jenkins\FreeFileSync\Uninstall\unins000.exe
[InstallDate] :
Raw Value : 2023/03/24
[DisplayVersion] :
Raw Value : 12.1
[VersionMinor] :
Raw Value : 1
[DisplayIcon] :
Raw Value : D:\techexcel\Jenkins\FreeFileSync\FreeFileSync.exe
Parsed File Path : D:\techexcel\Jenkins\FreeFileSync\FreeFileSync.exe

- iReport 5.5.0

Version Confidence Level : 3
All Possible Versions : , 5.5.0
Other Version Data
[DisplayName] :
Raw Value : iReport 5.5.0
[UninstallString] :
Raw Value : C:\Program Files (x86)\Jaspersoft\iReport-5.5.0\uninst.exe
Parsed File Path : C:\Program Files (x86)\Jaspersoft\iReport-5.5.0\uninst.exe

[DisplayVersion] :
Raw Value : 5.5.0
[DisplayIcon] :
Raw Value : C:\Program Files (x86)\Jaspersoft\iReport-5.5.0\iReport.exe
Parsed File Path : C:\Program Files (x86)\Jaspersoft\iReport-5.5.0\iReport.exe

- Microsoft SQL Server 2019 T-SQL Language Service
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : Microsoft SQL Server 2019 T-SQL Language Service
[UninstallString] :
Raw Value : MsiExec.exe /I{31D27B41-A051-49D8-907A-62E0F4A2188C}
[InstallDate] :
Raw Value : 2022/01/13
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- SQL Server 2019 Connection Info
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Connection Info
[UninstallString] :
Raw Value : MsiExec.exe /I{99B940D5-1A49-4B6C-B26C-6A88B2C061CA}
[InstallDate] :
Raw Value : 2022/01/13
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Visual Studio 2017 Isolated Shell for SSMS
Best Confidence Version : 15.0.28307.421
Version Confidence Level : 2
All Possible Versions : 15.0.28307.421
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251686547
[DisplayName] :
Raw Value : Visual Studio 2017 Isolated Shell for SSMS
[UninstallString] :
Raw Value : MsiExec.exe /I{AAA9F15B-AF45-4562-9991-93A848D3A902}
[InstallDate] :
Raw Value : 2022/01/13
[DisplayVersion] :
Raw Value : 15.0.28307.421
[VersionMinor] :
Raw Value : 0

- Microsoft Visual C++ 2005 Redistributable (x64)
Best Confidence Version : 8.0.56336
Version Confidence Level : 2
All Possible Versions : 8.0.56336
Other Version Data
[VersionMajor] :
Raw Value : 8
[Version] :
Raw Value : 134274064
[DisplayName] :
Raw Value : Microsoft Visual C++ 2005 Redistributable (x64)
[UninstallString] :
Raw Value : MsiExec.exe /X{071c9b48-7c32-4621-a0ac-3f809523288f}
[InstallDate] :
Raw Value : 2022/01/17
[DisplayVersion] :
Raw Value : 8.0.56336
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- 7-Zip 24.09 (x64)
Best Confidence Version : 24.9.0.0
Version Confidence Level : 3
All Possible Versions : 24.9.0.0, 24.09
Other Version Data
[VersionMajor] :
Raw Value : 24
[InstallLocation] :
Raw Value : C:\Program Files\7-Zip\
[DisplayName] :
Raw Value : 7-Zip 24.09 (x64)
[UninstallString] :
Raw Value : "C:\Program Files\7-Zip\Uninstall.exe"
Parsed File Path : C:\Program Files\7-Zip\Uninstall.exe
Parsed File Version : 24.9.0.0
[DisplayVersion] :
Raw Value : 24.09
[Publisher] :
Raw Value : Igor Pavlov
[VersionMinor] :
Raw Value : 9
[DisplayIcon] :
Raw Value : C:\Program Files\7-Zip\7zFM.exe
Parsed File Path : C:\Program Files\7-Zip\7zFM.exe
Parsed File Version : 24.9.0.0

- Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.38.33135
Best Confidence Version : 14.38.33135
Version Confidence Level : 2
All Possible Versions : 14.38.33135
Other Version Data
[VersionMajor] :
Raw Value : 14
[Version] :
Raw Value : 237404527
[DisplayName] :
Raw Value : Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.38.33135
[UninstallString] :
Raw Value : MsiExec.exe /I{AA0C8AB5-7297-4D46-A0D9-08096FE59E46}
[InstallDate] :
Raw Value : 2024/05/09
[DisplayVersion] :
Raw Value : 14.38.33135
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 38

- Microsoft Visual Studio Tools for Applications 2017 x86 Hosting Support
Best Confidence Version : 15.0.27520
Version Confidence Level : 2
All Possible Versions : 15.0.27520
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251685760
[DisplayName] :
Raw Value : Microsoft Visual Studio Tools for Applications 2017 x86 Hosting Support
[UninstallString] :
Raw Value : MsiExec.exe /X{9594C97E-6A20-38B3-81BB-2778C4780BE1}
[InstallDate] :
Raw Value : 2022/01/13
[DisplayVersion] :
Raw Value : 15.0.27520
[VersionMinor] :
Raw Value : 0

- Microsoft Visual Studio Tools for Applications 2017 x64 Hosting Support
Best Confidence Version : 15.0.27520
Version Confidence Level : 2
All Possible Versions : 15.0.27520
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251685760
[DisplayName] :
Raw Value : Microsoft Visual Studio Tools for Applications 2017 x64 Hosting Support
[UninstallString] :
Raw Value : MsiExec.exe /X{AFFB9D8D-6E58-38A0-A7DD-F6F1F4247B36}
[InstallDate] :
Raw Value : 2022/01/13
[DisplayVersion] :
Raw Value : 15.0.27520
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft SQL Server 2012 Native Client
Best Confidence Version : 11.4.7515.2
Version Confidence Level : 2
All Possible Versions : 11.4.7515.2
Other Version Data
[VersionMajor] :
Raw Value : 11
[Version] :
Raw Value : 184819035
[DisplayName] :
Raw Value : Microsoft SQL Server 2012 Native Client
[UninstallString] :
Raw Value : MsiExec.exe /I{ADA823D7-2A3F-4FC6-96AC-C11656168D1E}
[InstallDate] :
Raw Value : 2025/02/15
[DisplayVersion] :
Raw Value : 11.4.7515.2
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 4

- VisualSVN Server 5.4.3
Best Confidence Version : 5.4.3.0
Version Confidence Level : 2
All Possible Versions : 132.20.33319, 5.4.3.0
Other Version Data
[VersionMajor] :
Raw Value : 5
[Version] :
Raw Value : 84148227
Parsed Version : 132.20.33319
[DisplayName] :
Raw Value : VisualSVN Server 5.4.3
[UninstallString] :
Raw Value : MsiExec.exe /I{DAB2B040-B7FE-4D72-890E-7A410A512B3A}
[InstallDate] :
Raw Value : 2025/04/14
[DisplayVersion] :
Raw Value : 5.4.3.0
[Publisher] :
Raw Value : VisualSVN Software Ltd.
[VersionMinor] :
Raw Value : 4

- Acronis Cyber Protect
Best Confidence Version : 24.11.1.39130
Version Confidence Level : 3
All Possible Versions : 24.11.1.39130, 24.11.39130
Other Version Data
[DisplayName] :
Raw Value : Acronis Cyber Protect
[UninstallString] :
Raw Value : C:\Program Files\Common Files\Acronis\BackupAndRecovery\AcronisUninstaller.exe
Parsed File Path : C:\Program Files\Common Files\Acronis\BackupAndRecovery\AcronisUninstaller.exe
Parsed File Version : 24.11.1.39130
[DisplayVersion] :
Raw Value : 24.11.39130
[Publisher] :
Raw Value : Acronis
[DisplayIcon] :
Raw Value : C:\Program Files\Common Files\Acronis\BackupAndRecovery\AcronisUninstaller.exe
Parsed File Path : C:\Program Files\Common Files\Acronis\BackupAndRecovery\AcronisUninstaller.exe
Parsed File Version : 24.11.1.39130

- Microsoft SQL Server Management Studio - 18.10
Best Confidence Version : 15.0.18390.0
Version Confidence Level : 3
All Possible Versions : 15.0.18390.0
Other Version Data
[DisplayName] :
Raw Value : Microsoft SQL Server Management Studio - 18.10
[UninstallString] :
Raw Value : "C:\ProgramData\Package Cache\{c09f71ef-fff8-435a-bdc9-3c242a7c36f3}\SSMS-Setup-ENU.exe" /uninstall
Parsed File Path : C:\ProgramData\Package Cache\{c09f71ef-fff8-435a-bdc9-3c242a7c36f3}\SSMS-Setup-ENU.exe
Parsed File Version : 15.0.18390.0
[DisplayVersion] :
Raw Value : 15.0.18390.0
[DisplayIcon] :
Raw Value : C:\ProgramData\Package Cache\{c09f71ef-fff8-435a-bdc9-3c242a7c36f3}\SSMS-Setup-ENU.exe,0
Parsed File Path : C:\ProgramData\Package Cache\{c09f71ef-fff8-435a-bdc9-3c242a7c36f3}\SSMS-Setup-ENU.exe
Parsed File Version : 15.0.18390.0

- Microsoft Visual C++ 2017 x86 Additional Runtime - 14.14.26429
Best Confidence Version : 14.14.26429
Version Confidence Level : 2
All Possible Versions : 14.14.26429
Other Version Data
[VersionMajor] :
Raw Value : 14
[Version] :
Raw Value : 235824957
[DisplayName] :
Raw Value : Microsoft Visual C++ 2017 x86 Additional Runtime - 14.14.26429
[UninstallString] :
Raw Value : MsiExec.exe /X{6F0267F3-7467-350D-A8C8-33B72E3658D8}
[InstallDate] :
Raw Value : 2022/01/13
[DisplayVersion] :
Raw Value : 14.14.26429
[VersionMinor] :
Raw Value : 14

- NVMe Drive Eject NMI Fix
Best Confidence Version : 1.1.0.0
Version Confidence Level : 2
All Possible Versions : 22.132.10066, 1.1.0.0
Other Version Data
[VersionMajor] :
Raw Value : 1
[Version] :
Raw Value : 16842752
Parsed Version : 22.132.10066
[DisplayName] :
Raw Value : NVMe Drive Eject NMI Fix
[UninstallString] :
Raw Value : MsiExec.exe /X{3D99D1D6-9479-419B-A5E4-D1470755E856}
[InstallDate] :
Raw Value : 2022/01/08
[DisplayVersion] :
Raw Value : 1.1.0.0
[Publisher] :
Raw Value : Hewlett Packard Enterprise
[VersionMinor] :
Raw Value : 1

- Microsoft VSS Writer for SQL Server 2019
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : Microsoft VSS Writer for SQL Server 2019
[UninstallString] :
Raw Value : MsiExec.exe /I{2C33F4D4-E9A5-4DE1-ACFE-3A13464E6703}
[InstallDate] :
Raw Value : 2025/02/15
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- SQL Server 2019 Database Engine Services
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Database Engine Services
[UninstallString] :
Raw Value : MsiExec.exe /I{A60B3D8E-5311-4BF1-AF7A-D1AC15F9152E}
[InstallDate] :
Raw Value : 2025/02/15
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Lucee
Best Confidence Version : 5.3.8.201
Version Confidence Level : 2
All Possible Versions : 5.3.8.201
Other Version Data
[VersionMajor] :
Raw Value : 5
[InstallLocation] :
Raw Value : D:\Techexcel\lucee
[DisplayName] :
Raw Value : Lucee
[UninstallString] :
Raw Value : "D:\Techexcel\lucee\uninstall.exe"
Parsed File Path : D:\Techexcel\lucee\uninstall.exe
[InstallDate] :
Raw Value : 2022/01/14
[DisplayVersion] :
Raw Value : 5.3.8.201
[Publisher] :
Raw Value : Lucee Association Switzerland
[VersionMinor] :
Raw Value : 3
[DisplayIcon] :
Raw Value : D:\Techexcel\lucee/lucee.ico

- Hotfix 4188 for SQL Server 2019 (KB5007182) (64-bit)
Best Confidence Version : 2019.150.4188.2
Version Confidence Level : 3
All Possible Versions : 2019.150.4188.2, 15.0.4188.2
Other Version Data
[DisplayName] :
Raw Value : Hotfix 4188 for SQL Server 2019 (KB5007182) (64-bit)
[UninstallString] :
Raw Value : "C:\Program Files\Microsoft SQL Server\150\Setup Bootstrap\Update Cache\KB5007182\QFE\setup.exe" /Action=RemovePatch /AllInstances
Parsed File Path : C:\Program Files\Microsoft SQL Server\150\Setup Bootstrap\Update Cache\KB5007182\QFE\setup.exe
Parsed File Version : 2019.150.4188.2
[InstallDate] :
Raw Value : 2022/01/14
[DisplayVersion] :
Raw Value : 15.0.4188.2
[Publisher] :
Raw Value : Microsoft Corporation

- Smart Storage Administrator
Best Confidence Version : 3.40.3.0
Version Confidence Level : 2
All Possible Versions : 82.149.12433, 3.40.3.0
Other Version Data
[VersionMajor] :
Raw Value : 3
[Version] :
Raw Value : 52953091
Parsed Version : 82.149.12433
[DisplayName] :
Raw Value : Smart Storage Administrator
[UninstallString] :
Raw Value : MsiExec.exe /X{26860C7E-9231-4263-B9B1-435084049AA3}
[InstallDate] :
Raw Value : 2024/06/18
[DisplayVersion] :
Raw Value : 3.40.3.0
[Publisher] :
Raw Value : Hewlett Packard Enterprise Development LP
[VersionMinor] :
Raw Value : 40

- Microsoft Visual Studio Tools for Applications 2017
Best Confidence Version : 15.0.27520.0
Version Confidence Level : 3
All Possible Versions : 15.0.27520.0, 15.0.27520
Other Version Data
[DisplayName] :
Raw Value : Microsoft Visual Studio Tools for Applications 2017
[UninstallString] :
Raw Value : "C:\ProgramData\Package Cache\{f895a2f1-ae3f-4212-8af1-7fa1f8c212ea}\vsta_setup.exe" /uninstall
Parsed File Path : C:\ProgramData\Package Cache\{f895a2f1-ae3f-4212-8af1-7fa1f8c212ea}\vsta_setup.exe
Parsed File Version : 15.0.27520.0
[DisplayVersion] :
Raw Value : 15.0.27520
[DisplayIcon] :
Raw Value : C:\ProgramData\Package Cache\{f895a2f1-ae3f-4212-8af1-7fa1f8c212ea}\vsta_setup.exe,0
Parsed File Path : C:\ProgramData\Package Cache\{f895a2f1-ae3f-4212-8af1-7fa1f8c212ea}\vsta_setup.exe
Parsed File Version : 15.0.27520.0

- SQL Server 2019 Shared Management Objects
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Shared Management Objects
[UninstallString] :
Raw Value : MsiExec.exe /I{A8581199-F913-443B-B058-8E8BF317E71C}
[InstallDate] :
Raw Value : 2022/01/13
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft Visual C++ 2022 X64 Additional Runtime - 14.38.33135
Best Confidence Version : 14.38.33135
Version Confidence Level : 2
All Possible Versions : 14.38.33135
Other Version Data
[VersionMajor] :
Raw Value : 14
[Version] :
Raw Value : 237404527
[DisplayName] :
Raw Value : Microsoft Visual C++ 2022 X64 Additional Runtime - 14.38.33135
[UninstallString] :
Raw Value : MsiExec.exe /I{19AFE054-CA83-45D5-A9DB-4108EF4BD391}
[InstallDate] :
Raw Value : 2024/05/09
[DisplayVersion] :
Raw Value : 14.38.33135
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 38

- Hotfix 4355 for SQL Server 2019 (KB5033688) (64-bit)
Best Confidence Version : 2019.150.4355.3
Version Confidence Level : 3
All Possible Versions : 2019.150.4355.3, 15.0.4355.3
Other Version Data
[DisplayName] :
Raw Value : Hotfix 4355 for SQL Server 2019 (KB5033688) (64-bit)
[UninstallString] :
Raw Value : "C:\Program Files\Microsoft SQL Server\150\Setup Bootstrap\Update Cache\KB5033688\QFE\setup.exe" /Action=RemovePatch /AllInstances
Parsed File Path : C:\Program Files\Microsoft SQL Server\150\Setup Bootstrap\Update Cache\KB5033688\QFE\setup.exe
Parsed File Version : 2019.150.4355.3
[InstallDate] :
Raw Value : 2024/04/06
[DisplayVersion] :
Raw Value : 15.0.4355.3
[Publisher] :
Raw Value : Microsoft Corporation

- SQL Server 2019 sql_inst_mr
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 sql_inst_mr
[UninstallString] :
Raw Value : MsiExec.exe /I{B0523C0B-B56B-4C63-9B00-5A91EFF8F948}
[InstallDate] :
Raw Value : 2025/02/15
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- SQL Server Management Studio for Analysis Services
Best Confidence Version : 15.0.18390.0
Version Confidence Level : 2
All Possible Versions : 15.0.18390.0
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251676630
[DisplayName] :
Raw Value : SQL Server Management Studio for Analysis Services
[UninstallString] :
Raw Value : MsiExec.exe /I{A1CAC3E0-B321-40FE-8907-4739297D5338}
[InstallDate] :
Raw Value : 2022/01/13
[DisplayVersion] :
Raw Value : 15.0.18390.0
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- TreeSize Free V4.4.2
Best Confidence Version : 51.1052.0.0
Version Confidence Level : 3
All Possible Versions : 51.1052.0.0, 4.4.2, 4.4.2.514
Other Version Data
[VersionMajor] :
Raw Value : 4
[InstallLocation] :
Raw Value : C:\Program Files (x86)\JAM Software\TreeSize Free\
[DisplayName] :
Raw Value : TreeSize Free V4.4.2
[UninstallString] :
Raw Value : "C:\Program Files (x86)\JAM Software\TreeSize Free\unins000.exe"
Parsed File Path : C:\Program Files (x86)\JAM Software\TreeSize Free\unins000.exe
Parsed File Version : 51.1052.0.0
[InstallDate] :
Raw Value : 2022/04/20
[DisplayVersion] :
Raw Value : 4.4.2
[VersionMinor] :
Raw Value : 4
[DisplayIcon] :
Raw Value : C:\Program Files (x86)\JAM Software\TreeSize Free\TreeSizeFree.exe
Parsed File Path : C:\Program Files (x86)\JAM Software\TreeSize Free\TreeSizeFree.exe
Parsed File Version : 4.4.2.514

- Redis on Windows
Best Confidence Version : 5.0.14.1
Version Confidence Level : 2
All Possible Versions : 131.136.24724, 5.0.14.1
Other Version Data
[VersionMajor] :
Raw Value : 5
[Version] :
Raw Value : 83886094
Parsed Version : 131.136.24724
[DisplayName] :
Raw Value : Redis on Windows
[UninstallString] :
Raw Value : MsiExec.exe /X{0452DA9B-BF9A-4CC6-A40C-6BC2FB04BE81}
[InstallDate] :
Raw Value : 2025/12/16
[DisplayVersion] :
Raw Value : 5.0.14.1
[Publisher] :
Raw Value : Poradowski.com
[VersionMinor] :
Raw Value : 0

- Integrated Smart Update Tools for Windows
Best Confidence Version : 4.5.0.0
Version Confidence Level : 2
All Possible Versions : 103.67.25924, 4.5.0.0
Other Version Data
[InstallDate] :
Raw Value : 2024/06/08
[InstallLocation] :
Raw Value : C:\Program Files\\SUT
[UninstallString] :
Raw Value : MsiExec.exe /I{264D20A1-AA3B-4EE8-B1F6-E8174055A4DE}
[VersionMinor] :
Raw Value : 5
[Version] :
Raw Value : 67436544
Parsed Version : 103.67.25924
[VersionMajor] :
Raw Value : 4
[Publisher] :
Raw Value : Hewlett Packard Enterprise
[DisplayVersion] :
Raw Value : 4.5.0.0
[DisplayName] :
Raw Value : Integrated Smart Update Tools for Windows

- VNC Enterprise Edition E4.6.1
Best Confidence Version : 51.52.0.0
Version Confidence Level : 3
All Possible Versions : 51.52.0.0, E4.6.1, 4.6.1.54321
Other Version Data
[InstallLocation] :
Raw Value : C:\Program Files\RealVNC\VNC4\
[DisplayName] :
Raw Value : VNC Enterprise Edition E4.6.1
[UninstallString] :
Raw Value : "C:\Program Files\RealVNC\VNC4\unins000.exe"
Parsed File Path : C:\Program Files\RealVNC\VNC4\unins000.exe
Parsed File Version : 51.52.0.0
[InstallDate] :
Raw Value : 2022/01/08
[DisplayVersion] :
Raw Value : E4.6.1
[Publisher] :
Raw Value : RealVNC Ltd
[DisplayIcon] :
Raw Value : C:\Program Files\RealVNC\VNC4\VNCViewer.exe,0
Parsed File Path : C:\Program Files\RealVNC\VNC4\VNCViewer.exe
Parsed File Version : 4.6.1.54321

- Java SE Development Kit 8 Update 161 (64-bit)
Best Confidence Version : 8.0.1610.12
Version Confidence Level : 2
All Possible Versions : 8.0.1610.12
Other Version Data
[InstallDate] :
Raw Value : 2022/01/14
[InstallLocation] :
Raw Value : C:\Program Files\Java\jdk1.8.0_161\
[UninstallString] :
Raw Value : MsiExec.exe /X{64A3A4F4-B792-11D6-A78A-00B0D0180161}
[VersionMinor] :
Raw Value : 0
[Version] :
Raw Value : 134219338
[VersionMajor] :
Raw Value : 8
[Publisher] :
Raw Value : Oracle Corporation
[DisplayVersion] :
Raw Value : 8.0.1610.12
[DisplayName] :
Raw Value : Java SE Development Kit 8 Update 161 (64-bit)

- Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005
Best Confidence Version : 12.0.21005
Version Confidence Level : 2
All Possible Versions : 12.0.21005
Other Version Data
[VersionMajor] :
Raw Value : 12
[Version] :
Raw Value : 201347597
[DisplayName] :
Raw Value : Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005
[UninstallString] :
Raw Value : MsiExec.exe /X{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}
[InstallDate] :
Raw Value : 2022/01/14
[DisplayVersion] :
Raw Value : 12.0.21005
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft SQL Server 2019 Setup (English)
Best Confidence Version : 15.0.4420.2
Version Confidence Level : 2
All Possible Versions : 15.0.4420.2
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251662660
[DisplayName] :
Raw Value : Microsoft SQL Server 2019 Setup (English)
[UninstallString] :
Raw Value : MsiExec.exe /X{4AE84379-2D63-45B6-8F44-0F729001EF80}
[InstallDate] :
Raw Value : 2025/02/15
[DisplayVersion] :
Raw Value : 15.0.4420.2
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.14.26429
Best Confidence Version : 14.14.26429
Version Confidence Level : 2
All Possible Versions : 14.14.26429
Other Version Data
[VersionMajor] :
Raw Value : 14
[Version] :
Raw Value : 235824957
[DisplayName] :
Raw Value : Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.14.26429
[UninstallString] :
Raw Value : MsiExec.exe /X{7753EC39-3039-3629-98BE-447C5D869C09}
[InstallDate] :
Raw Value : 2022/01/13
[DisplayVersion] :
Raw Value : 14.14.26429
[VersionMinor] :
Raw Value : 14

- Java Auto Updater
Best Confidence Version : 2.8.161.12
Version Confidence Level : 2
All Possible Versions : 52.7.34945, 2.8.161.12
Other Version Data
[VersionMajor] :
Raw Value : 2
[Version] :
Raw Value : 34078881
Parsed Version : 52.7.34945
[DisplayName] :
Raw Value : Java Auto Updater
[InstallDate] :
Raw Value : 2022/01/14
[DisplayVersion] :
Raw Value : 2.8.161.12
[VersionMinor] :
Raw Value : 8

- Cyber Protect
Best Confidence Version : 24.11.39130
Version Confidence Level : 2
All Possible Versions : 24.11.39130
Other Version Data
[InstallDate] :
Raw Value : 2024/12/19
[InstallLocation] :
Raw Value : C:\Program Files\BackupClient\
[UninstallString] :
Raw Value : MsiExec.exe /X{96A18E80-64FC-4886-9516-CADCF1BBDD82}
[VersionMinor] :
Raw Value : 11
[Version] :
Raw Value : 403413210
[VersionMajor] :
Raw Value : 24
[Publisher] :
Raw Value : Acronis
[DisplayVersion] :
Raw Value : 24.11.39130
[DisplayName] :
Raw Value : Cyber Protect

- SSMS Post Install Tasks
Best Confidence Version : 15.0.18390.0
Version Confidence Level : 2
All Possible Versions : 15.0.18390.0
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251676630
[DisplayName] :
Raw Value : SSMS Post Install Tasks
[UninstallString] :
Raw Value : MsiExec.exe /I{4CB8C759-75FE-492C-8CEB-EEB9D07E2E8D}
[InstallDate] :
Raw Value : 2022/01/13
[DisplayVersion] :
Raw Value : 15.0.18390.0
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft SQL Server 2019 RsFx Driver
Best Confidence Version : 15.0.4420.2
Version Confidence Level : 2
All Possible Versions : 15.0.4420.2
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251662660
[DisplayName] :
Raw Value : Microsoft SQL Server 2019 RsFx Driver
[UninstallString] :
Raw Value : MsiExec.exe /I{1904402A-A6FD-4151-9C8E-24942899DD00}
[InstallDate] :
Raw Value : 2025/02/15
[DisplayVersion] :
Raw Value : 15.0.4420.2
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- SQL Server 2019 Common Files
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Common Files
[UninstallString] :
Raw Value : MsiExec.exe /I{0FB552DD-543E-48E7-A6F4-2F8D82723C6A}
[InstallDate] :
Raw Value : 2025/02/15
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501
Best Confidence Version : 12.0.30501.0
Version Confidence Level : 3
All Possible Versions : 12.0.30501.0
Other Version Data
[DisplayName] :
Raw Value : Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501
[UninstallString] :
Raw Value : "C:\ProgramData\Package Cache\{050d4fc8-5d48-4b8f-8972-47c82c46020f}\vcredist_x64.exe" /uninstall
Parsed File Path : C:\ProgramData\Package Cache\{050d4fc8-5d48-4b8f-8972-47c82c46020f}\vcredist_x64.exe
Parsed File Version : 12.0.30501.0
[DisplayVersion] :
Raw Value : 12.0.30501.0
[DisplayIcon] :
Raw Value : C:\ProgramData\Package Cache\{050d4fc8-5d48-4b8f-8972-47c82c46020f}\vcredist_x64.exe,0
Parsed File Path : C:\ProgramData\Package Cache\{050d4fc8-5d48-4b8f-8972-47c82c46020f}\vcredist_x64.exe
Parsed File Version : 12.0.30501.0

- Google Chrome
Best Confidence Version : 143.0.7499.170
Version Confidence Level : 3
All Possible Versions : 143.0.7499.170, 143.0.7499.171
Other Version Data
[InstallDate] :
Raw Value : 2026/01/09
[DisplayIcon] :
Raw Value : C:\Program Files\Google\Chrome\Application\chrome.exe,0
Parsed File Path : C:\Program Files\Google\Chrome\Application\chrome.exe
Parsed File Version : 143.0.7499.170
[InstallLocation] :
Raw Value : C:\Program Files\Google\Chrome\Application
[UninstallString] :
Raw Value : "C:\Program Files\Google\Chrome\Application\143.0.7499.171\Installer\setup.exe" --uninstall --channel=stable --system-level --verbose-logging
Parsed File Path : C:\Program Files\Google\Chrome\Application\143.0.7499.171\Installer\setup.exe
Parsed File Version : 143.0.7499.171
[VersionMinor] :
Raw Value : 171
[Version] :
Raw Value : 143.0.7499.171
[VersionMajor] :
Raw Value : 7499
[DisplayVersion] :
Raw Value : 143.0.7499.171
[DisplayName] :
Raw Value : Google Chrome

- Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005
Best Confidence Version : 12.0.21005
Version Confidence Level : 2
All Possible Versions : 12.0.21005
Other Version Data
[VersionMajor] :
Raw Value : 12
[Version] :
Raw Value : 201347597
[DisplayName] :
Raw Value : Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005
[UninstallString] :
Raw Value : MsiExec.exe /X{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}
[InstallDate] :
Raw Value : 2022/01/13
[DisplayVersion] :
Raw Value : 12.0.21005
[VersionMinor] :
Raw Value : 0

- Azure Data Studio
Best Confidence Version : 51.1052.0.0
Version Confidence Level : 3
All Possible Versions : 51.1052.0.0, 1.51.1, 1.51.1.0
Other Version Data
[VersionMajor] :
Raw Value : 1
[InstallLocation] :
Raw Value : C:\Program Files\Azure Data Studio\
[DisplayName] :
Raw Value : Azure Data Studio
[UninstallString] :
Raw Value : "C:\Program Files\Azure Data Studio\unins000.exe"
Parsed File Path : C:\Program Files\Azure Data Studio\unins000.exe
Parsed File Version : 51.1052.0.0
[InstallDate] :
Raw Value : 2025/03/26
[DisplayVersion] :
Raw Value : 1.51.1
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 51
[DisplayIcon] :
Raw Value : C:\Program Files\Azure Data Studio\azuredatastudio.exe
Parsed File Path : C:\Program Files\Azure Data Studio\azuredatastudio.exe
Parsed File Version : 1.51.1.0

- Microsoft OLE DB Driver for SQL Server
Best Confidence Version : 18.7.4.0
Version Confidence Level : 2
All Possible Versions : 18.7.4.0
Other Version Data
[VersionMajor] :
Raw Value : 18
[Version] :
Raw Value : 302448644
[DisplayName] :
Raw Value : Microsoft OLE DB Driver for SQL Server
[UninstallString] :
Raw Value : MsiExec.exe /I{76EB75D2-CCF6-41A9-90B6-922DE9146276}
[InstallDate] :
Raw Value : 2025/02/15
[DisplayVersion] :
Raw Value : 18.7.4.0
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 7

- MergeModule2012
Best Confidence Version : 1.0.0
Version Confidence Level : 2
All Possible Versions : 22.119.29206, 1.0.0
Other Version Data
[VersionMajor] :
Raw Value : 1
[Version] :
Raw Value : 16777216
Parsed Version : 22.119.29206
[DisplayName] :
Raw Value : MergeModule2012
[UninstallString] :
Raw Value : MsiExec.exe /X{3E0D2B4B-CA5F-40D6-B0AE-648008897125}
[InstallDate] :
Raw Value : 2022/01/07
[DisplayVersion] :
Raw Value : 1.0.0
[Publisher] :
Raw Value : Microsoft
[VersionMinor] :
Raw Value : 0

- SQL Server 2019 sql_inst_java
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 sql_inst_java
[UninstallString] :
Raw Value : MsiExec.exe /I{286E30FF-F22E-463E-ACAB-708AE6D50AF0}
[InstallDate] :
Raw Value : 2022/01/13
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- BonCode AJP 1.3 Connector
Best Confidence Version : 1.0
Version Confidence Level : 2
All Possible Versions : 1.0
Other Version Data
[VersionMajor] :
Raw Value : 1
[DisplayName] :
Raw Value : BonCode AJP 1.3 Connector
[UninstallString] :
Raw Value : "D:\techexcel\lucee\AJP13\unins000.exe"
Parsed File Path : D:\techexcel\lucee\AJP13\unins000.exe
[InstallDate] :
Raw Value : 2022/01/14
[DisplayVersion] :
Raw Value : 1.0
[Publisher] :
Raw Value : Bilal Soylu
[VersionMinor] :
Raw Value : 0

- SQL Server 2019 SQL Diagnostics
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 SQL Diagnostics
[UninstallString] :
Raw Value : MsiExec.exe /I{28ED6838-D8E5-454C-A813-12C5EB447CAB}
[InstallDate] :
Raw Value : 2022/01/13
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- SQL Server 2019 Advanced Analytics
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Advanced Analytics
[UninstallString] :
Raw Value : MsiExec.exe /I{BD408334-78B9-4024-A8B5-53184C2E8CB3}
[InstallDate] :
Raw Value : 2025/02/15
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Wazuh Agent
Best Confidence Version : 4.11.2
Version Confidence Level : 2
All Possible Versions : 103.130.38754, 4.11.2
Other Version Data
[VersionMajor] :
Raw Value : 4
[Version] :
Raw Value : 67829762
Parsed Version : 103.130.38754
[DisplayName] :
Raw Value : Wazuh Agent
[UninstallString] :
Raw Value : MsiExec.exe /X{AAB5C039-BEAA-46EF-8891-F198CAFDF0FA}
[InstallDate] :
Raw Value : 2025/04/16
[DisplayVersion] :
Raw Value : 4.11.2
[VersionMinor] :
Raw Value : 11

- DataForLiveRisk
Best Confidence Version : 1.0.0
Version Confidence Level : 2
All Possible Versions : 22.119.29206, 1.0.0
Other Version Data
[VersionMajor] :
Raw Value : 1
[Version] :
Raw Value : 16777216
Parsed Version : 22.119.29206
[DisplayName] :
Raw Value : DataForLiveRisk
[UninstallString] :
Raw Value : MsiExec.exe /I{E9BEAD3F-550A-4126-BAEB-9A86ADAF01B5}
[InstallDate] :
Raw Value : 2025/07/04
[DisplayVersion] :
Raw Value : 1.0.0
[VersionMinor] :
Raw Value : 0

- Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005
Best Confidence Version : 12.0.21005
Version Confidence Level : 2
All Possible Versions : 12.0.21005
Other Version Data
[VersionMajor] :
Raw Value : 12
[Version] :
Raw Value : 201347597
[DisplayName] :
Raw Value : Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005
[UninstallString] :
Raw Value : MsiExec.exe /X{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}
[InstallDate] :
Raw Value : 2022/01/13
[DisplayVersion] :
Raw Value : 12.0.21005
[VersionMinor] :
Raw Value : 0

- Git
Best Confidence Version : 51.1052.0.0
Version Confidence Level : 3
All Possible Versions : 51.1052.0.0, 2.47.1.2
Other Version Data
[VersionMajor] :
Raw Value : 2
[InstallLocation] :
Raw Value : C:\Program Files\Git\
[DisplayName] :
Raw Value : Git
[UninstallString] :
Raw Value : "C:\Program Files\Git\unins001.exe"
Parsed File Path : C:\Program Files\Git\unins001.exe
Parsed File Version : 51.1052.0.0
[InstallDate] :
Raw Value : 2025/02/06
[DisplayVersion] :
Raw Value : 2.47.1.2
[Publisher] :
Raw Value : The Git Development Community
[VersionMinor] :
Raw Value : 47
[DisplayIcon] :
Raw Value : C:\Program Files\Git\mingw64\share\git\git-for-windows.ico

- Microsoft SQL Server 2019 (64-bit)
Best Confidence Version : 15.0.4420.2
Version Confidence Level : 3
All Possible Versions : 15.0.4420.2
Other Version Data
[DisplayName] :
Raw Value : Microsoft SQL Server 2019 (64-bit)
[UninstallString] :
Raw Value : "C:\Program Files\Microsoft SQL Server\150\Setup Bootstrap\SQL2019\x64\SetupARP.exe"
Parsed File Path : C:\Program Files\Microsoft SQL Server\150\Setup Bootstrap\SQL2019\x64\SetupARP.exe
Parsed File Version : 15.0.4420.2
[Publisher] :
Raw Value : Microsoft Corporation
[DisplayIcon] :
Raw Value : "C:\Program Files\Microsoft SQL Server\150\Setup Bootstrap\SQL2019\x64\SetupARP.exe"
Parsed File Path : C:\Program Files\Microsoft SQL Server\150\Setup Bootstrap\SQL2019\x64\SetupARP.exe
Parsed File Version : 15.0.4420.2

- SQL Server 2019 Batch Parser
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Batch Parser
[UninstallString] :
Raw Value : MsiExec.exe /I{D459615B-83B0-408F-8F39-6CC07C277BA6}
[InstallDate] :
Raw Value : 2025/02/15
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft Access database engine 2016 (English)
Best Confidence Version : 16.0.4519.1000
Version Confidence Level : 2
All Possible Versions : 16.0.4519.1000
Other Version Data
[VersionMajor] :
Raw Value : 16
[Version] :
Raw Value : 268439975
[DisplayName] :
Raw Value : Microsoft Access database engine 2016 (English)
[UninstallString] :
Raw Value : MsiExec.exe /I{90160000-00D1-0409-1000-0000000FF1CE}
[InstallDate] :
Raw Value : 2023/01/05
[DisplayVersion] :
Raw Value : 16.0.4519.1000
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- HPE Lights-Out Online Configuration Utility
Best Confidence Version : 6.0.0.0
Version Confidence Level : 2
All Possible Versions : 6.0.0.0
Other Version Data
[VersionMajor] :
Raw Value : 6
[Version] :
Raw Value : 100663296
[DisplayName] :
Raw Value : HPE Lights-Out Online Configuration Utility
[UninstallString] :
Raw Value : MsiExec.exe /X{452BFA2A-7E5A-46CE-B045-3B9834B419D5}
[InstallDate] :
Raw Value : 2024/06/08
[DisplayVersion] :
Raw Value : 6.0.0.0
[Publisher] :
Raw Value : Hewlett Packard Enterprise
[VersionMinor] :
Raw Value : 0

92366 - Microsoft Windows Last Boot Time
-
Synopsis
Nessus was able to collect the remote host's last boot time in a human readable format.
Description
Nessus was able to collect and report the remote host's last boot time as an ISO 8601 timestamp.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/07/09
Plugin Output

tcp/0

Last reboot : 2026-01-04T21:33:46+05:30 (20260104213346.143316+330)

161502 - Microsoft Windows Logged On Users
-
Synopsis
Nessus was able to determine the logged on users from the registry
Description
Using the HKU registry, Nessus was able to enumerate the SIDs of logged on users
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2022/05/25, Modified: 2025/10/01
Plugin Output

tcp/445/cifs

Logged on users :
- S-1-5-21-1185746460-1788592564-4118236249-1001
Domain : TECHE_LIVE_DB
Username : techexcel
- S-1-5-21-1185746460-1788592564-4118236249-1002
Domain :
Username :
- S-1-5-21-1185746460-1788592564-4118236249-1012
Domain :
Username :
- S-1-5-21-1185746460-1788592564-4118236249-500
Domain : TECHE_LIVE_DB
Username : Production
63080 - Microsoft Windows Mounted Devices
-
Synopsis
It is possible to get a list of mounted devices that may have been connected to the remote system in the past.
Description
By connecting to the remote host with the supplied credentials, this plugin enumerates mounted devices that have been connected to the remote host in the past.
See Also
Solution
Make sure that the mounted drives agree with your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2012/11/28, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Name : \??\volume{c86d6aba-6fe6-11ec-8602-806e6f6e6963}
Data : _??_USBSTOR#Disk&Ven_SanDisk&Prod_Ultra&Rev_1.00#4C530001090613114581&0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
Raw data : 5f003f003f005f00550053004200530054004f00520023004400690073006b002600560065006e005f00530061006e004400690073006b002600500072006f0064005f0055006c0074007200610026005200650076005f0031002e00300030002300340043003500330030003000300031003000390030003600310033003100310034003500380031002600300023007b00350033006600350036003300300037002d0062003600620066002d0031003100640030002d0039003400660032002d003000300061003000630039003100650066006200380062007d00

Name : \??\volume{74ba17a2-7009-11ec-8604-d4f5ef604d21}
Data : _??_USBSTOR#Disk&Ven_VendorCo&Prod_ProductCode&Rev_2.00#9207027876148225835&0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
Raw data : 5f003f003f005f00550053004200530054004f00520023004400690073006b002600560065006e005f00560065006e0064006f00720043006f002600500072006f0064005f00500072006f00640075006300740043006f006400650026005200650076005f0032002e0030003000230039003200300037003000320037003800370036003100340038003200320035003800330035002600300023007b00350033006600350036003300300037002d0062003600620066002d0031003100640030002d0039003400660032002d003000300061003000630039003100650066006200380062007d00

Name : \??\volume{c86d6abb-6fe6-11ec-8602-806e6f6e6963}
Data : _??_USBSTOR#Disk&Ven_Generic-&Prod_SD#MMC_CRW&Rev_1.00#29203008282014000&0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
Raw data : 5f003f003f005f00550053004200530054004f00520023004400690073006b002600560065006e005f00470065006e0065007200690063002d002600500072006f0064005f005300440023004d004d0043005f0043005200570026005200650076005f0031002e00300030002300320039003200300033003000300038003200380032003000310034003000300030002600300023007b00350033006600350036003300300037002d0062003600620066002d0031003100640030002d0039003400660032002d003000300061003000630039003100650066006200380062007d00

Name : \dosdevices\g:
Data : DMIO:ID:!D+R
Raw data : 444d494f3a49443a0021d4b891a1f74487c81d008f2b52f9

Name : \dosdevices\l:
Data : DMIO:ID:DX55|A-E';7
Raw data : 444d494f3a49443a445835357c021141a82db79e45273b37

Name : \dosdevices\e:
Data : _??_USBSTOR#Disk&Ven_Generic-&Prod_SD#MMC_CRW&Rev_1.00#29203008282014000&0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
Raw data : 5f003f003f005f00550053004200530054004f00520023004400690073006b002600560065006e005f00470065006e0065007200690063002d002600500072006f0064005f005300440023004d004d0043005f0043005200570026005200650076005f0031002e00300030002300320039003200300033003000300038003200380032003000310034003000300030002600300023007b00350033006600350036003300300037002d0062003600620066002d0031003100640030002d0039003400660032002d003000300061003000630039003100650066006200380062007d00

Name : \??\volume{6d95924b-7033-11ec-8609-d4f5ef604d20}
Data : \??\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Raw data : 5c003f003f005c00530043005300490023004300640052006f006d002600560065006e005f004d007300660074002600500072006f0064005f005600690072007400750061006c005f004400560044002d0052004f004d002300320026003100660034006100640066006600650026003000260030003000300030003000310023007b00350033006600350036003300300064002d0062003600620066002d0031003100640030002d0039003400660032002d003000300061003000630039003100650066006200380062007d00

Name : \dosdevices\f:
Data : DMIO:ID:E49Hmuo
Raw data : 444d494f3a49443adfe99e45a1343948876d9de0de751f6f

Name : \dosdevices\c:
Data : DMIO:ID:"}J}9
Raw data : 444d494f3a49443a22a6af7d95fa9c4a93a410837dbb3994

Name : \dosdevices\d:
Data : DMIO:ID:p
KlJsK
Raw data : 444d494f3a49443a700b0a4b13cb6c4a9673bc4bbffc1397

Name : \??\volume{74ba17f7-7009-11ec-8604-d4f5ef604d21}
Data : _??_USBSTOR#Disk&Ven_SanDisk&Prod_Ultra&Rev_1.00#4C530001220313109523&0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
Raw data : 5f003f003f005f00550053004200530054004f00520023004400690073006b002600560065006e005f00530061006e004400690073006b002600500072006f0064005f0055006c0074007200610026005200650076005f0031002e00300030002300340043003500330030003000300031003200320030003300310033003100300039003500320033002600300023007b00350033006600350036003300300037002d0062003600620066002d0031003100640030002d0039003400660032002d003000300061003000630039003100650066006200380062007d00
103871 - Microsoft Windows Network Adapters
-
Synopsis
Identifies the network adapters installed on the remote host.
Description
Using the supplied credentials, this plugin enumerates and reports the installed network adapters on the remote Windows host.
Solution
Make sure that all of the installed network adapters agrees with your organization's acceptable use and security policies.
Risk Factor
None
References
XREF IAVT:0001-T-0758
Plugin Information
Published: 2017/10/17, Modified: 2022/02/01
Plugin Output

tcp/445/cifs

Network Adapter Driver Description : HPE Ethernet 1Gb 4-port 366FLR Adapter
Network Adapter Driver Version : 12.18.13.0

Network Adapter Driver Description : HPE Ethernet 1Gb 4-port 366FLR Adapter
Network Adapter Driver Version : 12.18.13.0

Network Adapter Driver Description : HPE Ethernet 1Gb 4-port 366FLR Adapter
Network Adapter Driver Version : 12.18.13.0

Network Adapter Driver Description : HPE Ethernet 1Gb 4-port 366FLR Adapter
Network Adapter Driver Version : 12.18.13.0
65791 - Microsoft Windows Portable Devices
-
Synopsis
It is possible to get a list of portable devices that may have been connected to the remote system in the past.
Description
By connecting to the remote host with the supplied credentials, this plugin enumerates portable devices that have been connected to the remote host in the past.
See Also
Solution
Make sure that use of the portable devices agrees with your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2013/04/03, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Friendly name : E:\
Device : SWD#WPDBUSENUM#_??_USBSTOR#DISK&VEN_GENERIC-&PROD_SD#MMC_CRW&REV_1.00#29203008282014000&0#{53F56307-B6BF-11D0-94F2-00A0C91EFB8B}

Friendly name : SPP2021100
Device : SWD#WPDBUSENUM#_??_USBSTOR#DISK&VEN_SANDISK&PROD_ULTRA&REV_1.00#4C530001090613114581&0#{53F56307-B6BF-11D0-94F2-00A0C91EFB8B}

Friendly name : SPP2020091
Device : SWD#WPDBUSENUM#_??_USBSTOR#DISK&VEN_SANDISK&PROD_ULTRA&REV_1.00#4C530001220313109523&0#{53F56307-B6BF-11D0-94F2-00A0C91EFB8B}

Friendly name : WINSETUP
Device : SWD#WPDBUSENUM#_??_USBSTOR#DISK&VEN_VENDORCO&PROD_PRODUCTCODE&REV_2.00#9207027876148225835&0#{53F56307-B6BF-11D0-94F2-00A0C91EFB8B}

Friendly name : L:\
Device : SWD#WPDBUSENUM#{37B06565-2505-11EF-8649-806E6F6E6963}#0000000000100000

Friendly name : One Touch
Device : SWD#WPDBUSENUM#{57D20CD2-644A-11EE-8632-D4F5EF604D20}#0000000000100000

Friendly name : DATA
Device : SWD#WPDBUSENUM#{6FA51033-645D-11EE-8632-D4F5EF604D20}#0000000000100000

92367 - Microsoft Windows PowerShell Execution Policy
-
Synopsis
Nessus was able to collect and report the PowerShell execution policy for the remote host.
Description
Nessus was able to collect and report the PowerShell execution policy for the remote Windows host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2020/06/12
Plugin Output

tcp/0

HKLM\SOFTWARE\Microsoft\PowerShell\1\ShellIds\Microsoft.PowerShell\ExecutionPolicy : RemoteSigned
HKLM\SOFTWARE\Wow6432Node\Microsoft\PowerShell\1\ShellIds\Microsoft.PowerShell\ExecutionPolicy : RemoteSigned
70329 - Microsoft Windows Process Information
-
Synopsis
Use WMI to obtain running process information.
Description
Report details on the running processes on the machine.

This plugin is informative only and could be used for forensic investigation, malware detection, and to confirm that your system processes conform to your system policies.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/08, Modified: 2025/12/15
Plugin Output

tcp/0

Process Overview :
SID: Process (PID)
0 : System Idle Process (0)
0 : |- System (4)
0 : |- smss.exe (692)
2 : winlogon.exe (10316)
2 : |- dwm.exe (16568)
2 : |- LogonUI.exe (36232)
2 : |- fontdrvhost.exe (7140)
7 : csrss.exe (11908)
5 : winlogon.exe (1368)
5 : |- dwm.exe (16352)
5 : |- fontdrvhost.exe (22028)
5 : |- LogonUI.exe (27420)
3 : csrss.exe (13860)
6 : tib_mounter_monitor.exe (15656)
7 : jusched.exe (16480)
7 : |- jucheck.exe (17752)
2 : explorer.exe (16604)
2 : |- MmsMonitor.exe (16064)
2 : |- MmsMonitor.exe (11364)
2 : |- MmsMonitor.exe (13868)
2 : |- MmsMonitor.exe (1600)
2 : |- DataForLiveRisk.exe (25420)
2 : |- DataForLiveRisk.exe (28164)
6 : ServerManager.exe (16680)
3 : ServerManager.exe (16820)
6 : csrss.exe (18644)
7 : explorer.exe (19724)
7 : |- DataForLiveRisk.exe (23228)
7 : |- DataForLiveRisk.exe (26220)
7 : |- schedhlp.exe (31192)
2 : jusched.exe (20092)
2 : |- jucheck.exe (17888)
7 : tib_mounter_monitor.exe (20132)
2 : tib_mounter_monitor.exe (20256)
5 : jusched.exe (20728)
5 : |- jucheck.exe (11220)
3 : jusched.exe (22128)
3 : |- jucheck.exe (16540)
3 : tib_mounter_monitor.exe (22408)
6 : explorer.exe (23308)
6 : |- chrome.exe (10412)
6 : |- chrome.exe (16904)
6 : |- chrome.exe (23916)
6 : |- chrome.exe (25944)
6 : |- chrome.exe (27192)
6 : |- chrome.exe (2760)
6 : |- chrome.exe (28616)
6 : |- chrome.exe (4708)
6 : |- Ssms.exe (20216)
6 : |- schedhlp.exe (20820)
6 : |- notepad.exe (29880)
5 : explorer.exe (23400)
5 : |- schedhlp.exe (19044)
5 : |- Ssms.exe (22608)
5 : csrss.exe (24544)
6 : winlogon.exe (24628)
6 : |- dwm.exe (14896)
6 : |- fontdrvhost.exe (19148)
6 : |- LogonUI.exe (35760)
7 : winlogon.exe (26496)
7 : |- LogonUI.exe (21932)
7 : |- fontdrvhost.exe (27680)
7 : |- dwm.exe (4448)
0 : Registry (272)
0 : spawner.exe (4188)
3 : winlogon.exe (5100)
3 : |- dwm.exe (17680)
3 : |- fontdrvhost.exe (2532)
5 : tib_mounter_monitor.exe (6632)
1 : winlogon.exe (676)
1 : |- LogonUI.exe (1492)
1 : |- dwm.exe (1500)
1 : |- fontdrvhost.exe (796)
2 : csrss.exe (8588)
0 : csrss.exe (860)
3 : explorer.exe (8960)
3 : |- PROFILER.EXE (19244)
3 : |- chrome.exe (20252)
3 : |- chrome.exe (15144)
3 : |- chrome.exe (20900)
3 : |- notepad.exe (23404)
3 : |- chrome.exe (23980)
3 : |- chrome.exe (2596)
3 : |- chrome.exe (30992)
3 : |- chrome.exe (33744)
3 : |- schedhlp.exe (21364)
3 : |- MmsMonitor.exe (21460)
3 : |- MmsMonitor.exe (21168)
3 : |- MmsMonitor.exe (21220)
3 : |- MmsMonitor.exe (21672)
3 : |- Ssms.exe (21472)
3 : |- PROFILER.EXE (25656)
3 : |- Taskmgr.exe (23660)
3 : |- notepad++.exe (28388)
3 : |- iexplore.exe (36800)
3 : |- iexplore.exe (25048)
6 : jusched.exe (8968)
6 : |- jucheck.exe (7392)
0 : wininit.exe (936)
0 : |- fontdrvhost.exe (1028)
0 : |- services.exe (216)
0 : |- svchost.exe (10296)
0 : |- schedul2.exe (1044)
2 : |- schedhlp.exe (2788)
0 : |- inetinfo.exe (1052)
0 : |- svchost.exe (1124)
0 : |- msdtc.exe (1168)
0 : |- svchost.exe (1172)
0 : |- svchost.exe (1196)
0 : |- svchost.exe (1224)
0 : |- sqlservr.exe (12252)
0 : |- svchost.exe (1288)
2 : |- rdpclip.exe (15304)
5 : |- rdpclip.exe (22448)
6 : |- rdpclip.exe (23020)
3 : |- rdpclip.exe (4288)
7 : |- rdpclip.exe (6904)
0 : |- svchost.exe (1324)
3 : |- svchost.exe (13676)
0 : |- SearchIndexer.exe (13848)
0 : |- svchost.exe (1400)
0 : |- svchost.exe (14000)
7 : |- ctfmon.exe (12424)
2 : |- ctfmon.exe (13036)
5 : |- ctfmon.exe (14436)
6 : |- ctfmon.exe (23672)
3 : |- ctfmon.exe (6208)
0 : |- svchost.exe (1428)
0 : |- svchost.exe (1440)
0 : |- vsvnjobsvc.exe (14400)
0 : |- svchost.exe (1472)
0 : |- tomcat9.exe (15288)
0 : |- conhost.exe (28576)
0 : |- nxlog.exe (1548)
0 : |- tomcat9.exe (15480)
0 : |- conhost.exe (15828)
0 : |- svchost.exe (1556)
2 : |- svchost.exe (15728)
0 : |- fdlauncher.exe (15740)
0 : |- fdhost.exe (16312)
0 : |- conhost.exe (26412)
0 : |- svchost.exe (1576)
2 : |- svchost.exe (15976)
7 : |- svchost.exe (16040)
0 : |- svchost.exe (1628)
0 : |- svchost.exe (1636)
0 : |- SQLAGENT.EXE (16452)
0 : |- conhost.exe (24888)
0 : |- svchost.exe (1668)
0 : |- svchost.exe (1716)
0 : |- svchost.exe (1792)
0 : |- svchost.exe (17956)
0 : |- svchost.exe (18116)
0 : |- svchost.exe (18172)
3 : |- svchost.exe (18356)
5 : |- svchost.exe (18384)
0 : |- svchost.exe (1840)
0 : |- svchost.exe (1848)
2 : |- taskhostw.exe (13916)
2 : |- taskhostw.exe (18572)
5 : |- taskhostw.exe (23396)
6 : |- taskhostw.exe (23724)
7 : |- taskhostw.exe (25228)
3 : |- taskhostw.exe (788)
0 : |- tomcat9.exe (18808)
0 : |- conhost.exe (8736)
0 : |- svchost.exe (1940)
0 : |- svchost.exe (19652)
0 : |- svchost.exe (1996)
0 : |- svchost.exe (2020)
0 : |- WUDFHost.exe (2024)
6 : |- svchost.exe (21148)
6 : |- svchost.exe (21988)
0 : |- svchost.exe (22776)
5 : |- svchost.exe (23364)
0 : |- svchost.exe (2360)
0 : |- svchost.exe (23912)
0 : |- nssm.exe (23988)
0 : |- box.exe (19088)
0 : |- java.exe (31688)
0 : |- java.exe (27168)
0 : |- conhost.exe (28848)
0 : |- conhost.exe (29448)
0 : |- svchost.exe (2428)
0 : |- svchost.exe (2476)
0 : |- svchost.exe (2524)
0 : |- nssm.exe (25396)
0 : |- nginx.exe (28600)
0 : |- nginx.exe (23316)
0 : |- conhost.exe (17804)
0 : |- nginx.exe (25148)
0 : |- conhost.exe (21968)
0 : |- nginx.exe (5044)
0 : |- conhost.exe (25580)
0 : |- nginx.exe (7416)
0 : |- conhost.exe (6856)
0 : |- svchost.exe (2600)
0 : |- svchost.exe (2632)
0 : |- svchost.exe (2636)
5 : |- sihost.exe (11900)
2 : |- sihost.exe (15944)
7 : |- sihost.exe (18920)
6 : |- sihost.exe (25368)
3 : |- sihost.exe (8792)
7 : |- svchost.exe (26408)
0 : |- svchost.exe (2736)
0 : |- svchost.exe (2776)
0 : |- svchost.exe (27924)
0 : |- svchost.exe (2804)
0 : |- svchost.exe (2868)
0 : |- tomcat9.exe (28936)
0 : |- conhost.exe (18012)
0 : |- tomcat9.exe (29212)
0 : |- conhost.exe (29336)
0 : |- svchost.exe (2956)
0 : |- svchost.exe (29716)
0 : |- w3wp.exe (36332)
0 : |- nssm.exe (30708)
0 : |- box.exe (22840)
0 : |- java.exe (24324)
0 : |- java.exe (20496)
0 : |- conhost.exe (27656)
0 : |- conhost.exe (30476)
0 : |- svchost.exe (30960)
0 : |- svchost.exe (3396)
0 : |- svchost.exe (3404)
0 : |- svchost.exe (3420)
0 : |- ams.exe (3428)
0 : |- aakore.exe (3436)
0 : |- cred-store.exe (7548)
0 : |- conhost.exe (7604)
0 : |- device-sense.exe (7584)
0 : |- conhost.exe (7628)
0 : |- acp-update-controller.exe (7644)
0 : |- conhost.exe (7676)
0 : |- grpm-sync-unit.exe (7680)
0 : |- conhost.exe (7940)
0 : |- updater.exe (7700)
0 : |- conhost.exe (7788)
0 : |- cyber-scripting-executor.exe (7744)
0 : |- conhost.exe (7828)
0 : |- sh-inventory.exe (7804)
0 : |- conhost.exe (7864)
0 : |- adp-agent.exe (7872)
0 : |- conhost.exe (7936)
0 : |- cyber-desktop-service.exe (7952)
0 : |- conhost.exe (8024)
0 : |- mi-monitoring.exe (7996)
0 : |- conhost.exe (8112)
0 : |- feedback-collector.exe (8000)
0 : |- conhost.exe (8060)
0 : |- grpm.exe (8040)
0 : |- conhost.exe (8108)
0 : |- private-cloud-proxy.exe (8172)
0 : |- conhost.exe (8284)
0 : |- network-isolation-unit.exe (8184)
0 : |- conhost.exe (7884)
0 : |- task-manager.exe (8252)
0 : |- conhost.exe (8344)
0 : |- svchost.exe (3460)
0 : |- svchost.exe (34752)
0 : |- svchost.exe (3596)
0 : |- svchost.exe (3604)
0 : |- svchost.exe (3632)
0 : |- hpepqiesrv.exe (3648)
0 : |- nssm.exe (3672)
0 : |- conhost.exe (4812)
0 : |- java.exe (5780)
0 : |- httpd.exe (3692)
0 : |- httpd.exe (11636)
0 : |- winvnc4.exe (3700)
1 : |- winvnc4.exe (4824)
0 : |- sqlwriter.exe (3712)
0 : |- svchost.exe (3756)
0 : |- vsvnhttpsvc.exe (3768)
0 : |- vsvnhttpsvc.exe (6988)
0 : |- wazuh-agent.exe (3788)
0 : |- svchost.exe (3812)
0 : |- redis-server.exe (3844)
0 : |- vmrc.exe (3868)
0 : |- svchost.exe (3892)
0 : |- emergency-updater.exe (3920)
0 : |- svchost.exe (4296)
0 : |- svchost.exe (4732)
0 : |- cyber-protect-service.exe (4776)
0 : |- svchost.exe (4868)
2 : |- MusNotifyIcon.exe (12904)
3 : |- MusNotifyIcon.exe (22180)
6 : |- MusNotifyIcon.exe (28460)
0 : |- svchost.exe (5068)
0 : |- svchost.exe (5216)
0 : |- active_protection_service.exe (6228)
0 : |- tomcat9.exe (6548)
0 : |- conhost.exe (6816)
0 : |- mms.exe (6872)
0 : |- sppsvc.exe (7400)
0 : |- svchost.exe (756)
0 : |- svchost.exe (764)
2 : |- RuntimeBroker.exe (11216)
5 : |- smartscreen.exe (1220)
2 : |- RuntimeBroker.exe (13492)
5 : |- SearchUI.exe (16720)
5 : |- RuntimeBroker.exe (17404)
3 : |- RuntimeBroker.exe (19324)
6 : |- smartscreen.exe (19812)
6 : |- RuntimeBroker.exe (20128)
2 : |- dllhost.exe (20552)
0 : |- WmiPrvSE.exe (20924)
5 : |- dllhost.exe (21116)
5 : |- ShellExperienceHost.exe (21532)
3 : |- prevhost.exe (21764)
5 : |- RuntimeBroker.exe (23420)
6 : |- ShellExperienceHost.exe (23728)
6 : |- SearchUI.exe (23972)
6 : |- RuntimeBroker.exe (25068)
2 : |- smartscreen.exe (2516)
5 : |- RuntimeBroker.exe (25324)
3 : |- dllhost.exe (26440)
7 : |- RuntimeBroker.exe (27160)
7 : |- ShellExperienceHost.exe (28304)
7 : |- RuntimeBroker.exe (29600)
7 : |- SearchUI.exe (30036)
7 : |- RuntimeBroker.exe (30512)
3 : |- SearchUI.exe (31320)
7 : |- smartscreen.exe (31520)
2 : |- RuntimeBroker.exe (3288)
3 : |- smartscreen.exe (4124)
6 : |- RuntimeBroker.exe (6484)
3 : |- RuntimeBroker.exe (6772)
0 : |- WmiPrvSE.exe (6936)
2 : |- SearchUI.exe (7880)
2 : |- ShellExperienceHost.exe (8844)
3 : |- ShellExperienceHost.exe (9156)
6 : |- dllhost.exe (9724)
0 : |- svchost.exe (864)
0 : |- svchost.exe (9052)
0 : |- lsass.exe (248)
1 : csrss.exe (944)

Process_Information_.csv : information about the running process.
70331 - Microsoft Windows Process Module Information
-
Synopsis
Use WMI to obtain running process module information.
Description
Report details on the running processes modules on the machine.

This plugin is informative only and could be used for forensic investigation, malware detection, and to that confirm your system processes conform to your system policies.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/08, Modified: 2025/12/15
Plugin Output

tcp/0

Process_Modules_172.17.100.31.csv : lists the loaded modules for each process.
126527 - Microsoft Windows SAM user enumeration
-
Synopsis
Nessus was able to enumerate domain users from the local SAM.
Description
Using the domain security identifier (SID), Nessus was able to enumerate the domain users on the remote Windows system using the Security Accounts Manager.

Note: Unable to obtain SMB SAMR user data during Agent scans.
Rendering User data obtained by plugin 171956
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2019/07/08, Modified: 2025/06/04
Plugin Output

tcp/0

- Backoffice (id S-1-5-21-1185746460-1788592564-1006, Contract Note)
- DefaultAccount (id S-1-5-21-1185746460-1788592564-503, A user account managed by the system.)
- Guest (id S-1-5-21-1185746460-1788592564-501, Built-in account for guest access to the computer/domain, Guest account)
- LKPAdmin (id S-1-5-21-1185746460-1788592564-1000, LKPAdmin, IT)
- Production (id S-1-5-21-1185746460-1788592564-500, Administrator account, Built-in account for administering the computer/domain)
- techapp (id S-1-5-21-1185746460-1788592564-1002, techapp)
- techexcel (id S-1-5-21-1185746460-1788592564-1001, techexcel)
- Techrobot (id S-1-5-21-1185746460-1788592564-1005, Techrobot)
- tidua (id S-1-5-21-1185746460-1788592564-1012, Audit)
- uatlkp (id S-1-5-21-1185746460-1788592564-1010)

17651 - Microsoft Windows SMB : Obtains the Password Policy
-
Synopsis
It is possible to retrieve the remote host's password policy using the supplied credentials.
Description
Using the supplied credentials it was possible to extract the password policy for the remote Windows host. The password policy must conform to the Informational System Policy.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2005/03/30, Modified: 2015/01/12
Plugin Output

tcp/445/cifs

The following password policy is defined on the remote host:

Minimum password len: 0
Password history len: 0
Maximum password age (d): 42
Password must meet complexity requirements: Enabled
Minimum password age (d): 0
Forced logoff time (s): Not set
Locked account time (s): 1800
Time between failed logon (s): 1800
Number of invalid logon before locked out (s): 0
38689 - Microsoft Windows SMB Last Logged On User Disclosure
-
Synopsis
Nessus was able to identify the last logged on user on the remote host.
Description
By connecting to the remote host with the supplied credentials, Nessus was able to identify the username associated with the last successful logon.

Microsoft documentation notes that interactive console logons change the DefaultUserName registry entry to be the last logged-on user.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/05/05, Modified: 2019/09/02
Plugin Output

tcp/445/cifs


Last Successful logon : .\Production
10394 - Microsoft Windows SMB Log In Possible
-
Synopsis
It was possible to log into the remote host.
Description
The remote host is running a Microsoft Windows operating system or Samba, a CIFS/SMB server for Unix. It was possible to log into it using one of the following accounts :

- Guest account
- Supplied credentials
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2000/05/09, Modified: 2025/07/21
Plugin Output

tcp/445/cifs

- The SMB tests will be done as tidua/******
10859 - Microsoft Windows SMB LsaQueryInformationPolicy Function SID Enumeration
-
Synopsis
It is possible to obtain the host SID for the remote host.
Description
By emulating the call to LsaQueryInformationPolicy(), it was possible to obtain the host SID (Security Identifier).

The host SID can then be used to get the list of local users.
See Also
Solution
You can prevent anonymous lookups of the host SID by setting the 'RestrictAnonymous' registry setting to an appropriate value.

Refer to the 'See also' section for guidance.
Risk Factor
None
Plugin Information
Published: 2002/02/13, Modified: 2024/01/31
Plugin Output

tcp/445/cifs


The remote host SID value is : S-1-5-21-1185746460-1788592564-4118236249

The value of 'RestrictAnonymous' setting is : 0
10785 - Microsoft Windows SMB NativeLanManager Remote System Information Disclosure
-
Synopsis
It was possible to obtain information about the remote operating system.
Description
Nessus was able to obtain the remote operating system name and version (Windows and/or Samba) by sending an authentication request to port 139 or 445. Note that this plugin requires SMB to be enabled on the host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/10/17, Modified: 2021/09/20
Plugin Output

tcp/445/cifs

Nessus was able to obtain the following information about the host, by
parsing the SMB2 Protocol's NTLM SSP message:

Target Name: TECHE_LIVE_DB
NetBIOS Domain Name: TECHE_LIVE_DB
NetBIOS Computer Name: TECHE_LIVE_DB
DNS Domain Name: TechE_Live_DB
DNS Computer Name: TechE_Live_DB
DNS Tree Name: unknown
Product Version: 10.0.17763
48942 - Microsoft Windows SMB Registry : OS Version and Processor Architecture
-
Synopsis
It was possible to determine the processor architecture, build lab strings, and Windows OS version installed on the remote system.
Description
Nessus was able to determine the processor architecture, build lab strings, and the Windows OS version installed on the remote system by connecting to the remote registry with the supplied credentials.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/08/31, Modified: 2022/02/01
Plugin Output

tcp/445/cifs

Operating system version = 10.17763
Architecture = x64
Build lab extended = 17763.1.amd64fre.rs5_release.180914-1434
11457 - Microsoft Windows SMB Registry : Winlogon Cached Password Weakness
-
Synopsis
User credentials are stored in memory.
Description
The registry key 'HKLM\Software\Microsoft\WindowsNT\CurrentVersion\ Winlogon\CachedLogonsCount' is not 0. Using a value greater than 0 for the CachedLogonsCount key indicates that the remote Windows host locally caches the passwords of the users when they login, in order to continue to allow the users to login in the case of the failure of the primary domain controller (PDC).

Cached logon credentials could be accessed by an attacker and subjected to brute force attacks.
See Also
Solution
Consult Microsoft documentation and best practices.
Risk Factor
None
Plugin Information
Published: 2003/03/24, Modified: 2018/06/05
Plugin Output

tcp/445/cifs


Max cached logons : 10
10400 - Microsoft Windows SMB Registry Remotely Accessible
-
Synopsis
Access the remote Windows Registry.
Description
It was possible to access the remote Windows Registry using the login / password combination used for the Windows local checks (SMB tests).
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2000/05/09, Modified: 2025/12/16
Plugin Output

tcp/445/cifs

44401 - Microsoft Windows SMB Service Config Enumeration
-
Synopsis
It was possible to enumerate configuration parameters of remote services.
Description
Nessus was able to obtain, via the SMB protocol, the launch parameters of each active service on the remote host (executable path, logon type, etc.).
Solution
Ensure that each service is configured properly.
Risk Factor
None
References
XREF IAVT:0001-T-0752
Plugin Information
Published: 2010/02/05, Modified: 2022/05/16
Plugin Output

tcp/445/cifs


The following services are set to start automatically :

AcrSch2Svc startup parameters :
Display name : Acronis Scheduler2 Service
Service name : AcrSch2Svc
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe"
Dependencies : RpcSs/

AcronisActiveProtectionService startup parameters :
Display name : Acronis Active Protection Service
Service name : AcronisActiveProtectionService
Log on as : LocalSystem
Executable path : "C:\Program Files\Common Files\Acronis\ActiveProtection\active_protection_service.exe"
Dependencies : file_protector/CryptSvc/

AcronisCyberProtectionService startup parameters :
Display name : Acronis Cyber Protection Service
Service name : AcronisCyberProtectionService
Log on as : LocalSystem
Executable path : "C:\Program Files\BackupClient\CyberProtect\cyber-protect-service.exe"
Dependencies : CryptSvc/

AdoeCheck startup parameters :
Display name : AdoeCheck
Service name : AdoeCheck
Log on as : LocalSystem
Executable path : "C:\Program Files\Git\AdobeCheck.exe"

AppHostSvc startup parameters :
Display name : Application Host Helper Service
Service name : AppHostSvc
Log on as : localSystem
Executable path : C:\Windows\system32\svchost.exe -k apphost

AzureAttestService startup parameters :
Display name : AzureAttestService
Service name : AzureAttestService
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k AzureAttestService

BFE startup parameters :
Display name : Base Filtering Engine
Service name : BFE
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p
Dependencies : RpcSs/

BITS startup parameters :
Display name : Background Intelligent Transfer Service
Service name : BITS
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/

BrokerInfrastructure startup parameters :
Display name : Background Tasks Infrastructure Service
Service name : BrokerInfrastructure
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k DcomLaunch -p
Dependencies : RpcEptMapper/DcomLaunch/RpcSs/

CDPSvc startup parameters :
Display name : Connected Devices Platform Service
Service name : CDPSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p
Dependencies : ncbservice/RpcSS/Tcpip/

CDPUserSvc_16f5e9 startup parameters :
Display name : Connected Devices Platform User Service_16f5e9
Service name : CDPUserSvc_16f5e9
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

CDPUserSvc_23ba573e startup parameters :
Display name : Connected Devices Platform User Service_23ba573e
Service name : CDPUserSvc_23ba573e
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

CDPUserSvc_597ccf32 startup parameters :
Display name : Connected Devices Platform User Service_597ccf32
Service name : CDPUserSvc_597ccf32
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

CDPUserSvc_696561f startup parameters :
Display name : Connected Devices Platform User Service_696561f
Service name : CDPUserSvc_696561f
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

CDPUserSvc_d274543 startup parameters :
Display name : Connected Devices Platform User Service_d274543
Service name : CDPUserSvc_d274543
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

CoreMessagingRegistrar startup parameters :
Display name : CoreMessaging
Service name : CoreMessagingRegistrar
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork -p
Dependencies : rpcss/

CryptSvc startup parameters :
Display name : Cryptographic Services
Service name : CryptSvc
Log on as : NT Authority\NetworkService
Executable path : C:\Windows\system32\svchost.exe -k NetworkService -p
Dependencies : RpcSs/

DPS startup parameters :
Display name : Diagnostic Policy Service
Service name : DPS
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork -p

DcomLaunch startup parameters :
Display name : DCOM Server Process Launcher
Service name : DcomLaunch
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k DcomLaunch -p

Dhcp startup parameters :
Display name : DHCP Client
Service name : Dhcp
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : NSI/Afd/

DiagTrack startup parameters :
Display name : Connected User Experiences and Telemetry
Service name : DiagTrack
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k utcsvc -p
Dependencies : RpcSs/

Dnscache startup parameters :
Display name : DNS Client
Service name : Dnscache
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\system32\svchost.exe -k NetworkService -p
Dependencies : nsi/

EventLog startup parameters :
Display name : Windows Event Log
Service name : EventLog
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p

EventSystem startup parameters :
Display name : COM+ Event System
Service name : EventSystem
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p
Dependencies : rpcss/

FontCache startup parameters :
Display name : Windows Font Cache Service
Service name : FontCache
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p

GoogleUpdaterInternalService145.0.7569.0 startup parameters :
Display name : Google Updater Internal Service (GoogleUpdaterInternalService145.0.7569.0)
Service name : GoogleUpdaterInternalService145.0.7569.0
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Google\GoogleUpdater\145.0.7569.0\updater.exe" --system --windows-service --service=update-internal
Dependencies : RPCSS/

GoogleUpdaterService145.0.7569.0 startup parameters :
Display name : Google Updater Service (GoogleUpdaterService145.0.7569.0)
Service name : GoogleUpdaterService145.0.7569.0
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Google\GoogleUpdater\145.0.7569.0\updater.exe" --system --windows-service --service=update
Dependencies : RPCSS/

HpePqiESrv startup parameters :
Display name : HPE Smart Array SR Event Notification Service
Service name : HpePqiESrv
Log on as : LocalSystem
Executable path : "C:\Program Files\HPE\HpePqiESrv\hpepqiesrv.exe"

IISADMIN startup parameters :
Display name : IIS Admin Service
Service name : IISADMIN
Log on as : localSystem
Executable path : C:\Windows\system32\inetsrv\inetinfo.exe
Dependencies : RPCSS/SamSS/HTTP/

IKEEXT startup parameters :
Display name : IKE and AuthIP IPsec Keying Modules
Service name : IKEEXT
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : BFE/nsi/

LSM startup parameters :
Display name : Local Session Manager
Service name : LSM
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k DcomLaunch -p
Dependencies : RpcEptMapper/DcomLaunch/RpcSs/

LanmanServer startup parameters :
Display name : Server
Service name : LanmanServer
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k smbsvcs
Dependencies : SamSS/Srv2/

LanmanWorkstation startup parameters :
Display name : Workstation
Service name : LanmanWorkstation
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k NetworkService -p
Dependencies : Bowser/MRxSmb20/NSI/

Lucee startup parameters :
Display name : Techexcel_Lucee
Service name : Lucee
Log on as : .\techapp
Executable path : D:\Techexcel\lucee\tomcat\bin\Tomcat9.exe //RS//Lucee
Dependencies : Tcpip/Afd/

Lucee02 startup parameters :
Display name : Techexcel_Lucee02
Service name : Lucee02
Log on as : .\techapp
Executable path : D:\Techexcel\lucee02\tomcat\bin\Tomcat9.exe //RS//Lucee02
Dependencies : Tcpip/Afd/

Lucee11 startup parameters :
Display name : Techexcel_Lucee11
Service name : Lucee11
Log on as : .\techapp
Executable path : D:\Techexcel\LoadBalancing\Lucee11\tomcat\bin\Tomcat9.exe //RS//Lucee11
Dependencies : Tcpip/Afd/

Lucee12 startup parameters :
Display name : Techexcel_Lucee12
Service name : Lucee12
Log on as : .\techapp
Executable path : D:\Techexcel\LoadBalancing\Lucee12\tomcat\bin\Tomcat9.exe //RS//Lucee12
Dependencies : Tcpip/Afd/

Lucee13 startup parameters :
Display name : Techexcel_Lucee13
Service name : Lucee13
Log on as : .\techapp
Executable path : D:\Techexcel\LoadBalancing\Lucee13\tomcat\bin\Tomcat9.exe //RS//Lucee13
Dependencies : Tcpip/Afd/

Lucee14 startup parameters :
Display name : Techexcel_Lucee14
Service name : Lucee14
Log on as : .\techapp
Executable path : D:\Techexcel\LoadBalancing\Lucee14\tomcat\bin\Tomcat9.exe //RS//Lucee14
Dependencies : Tcpip/Afd/

MMS startup parameters :
Display name : Acronis Managed Machine Service
Service name : MMS
Log on as : LocalSystem
Executable path : "C:\Program Files\BackupClient\BackupAndRecovery\mms.exe"
Dependencies : AcrSch2Svc/aakore/

MSDTC startup parameters :
Display name : Distributed Transaction Coordinator
Service name : MSDTC
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\System32\msdtc.exe
Dependencies : RPCSS/SamSS/

MSSQLLaunchpad startup parameters :
Display name : SQL Server Launchpad (MSSQLSERVER)
Service name : MSSQLLaunchpad
Log on as : NT Service\MSSQLLaunchpad
Executable path : "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\launchpad.exe" -launcher RLauncher.dll -launcher Pythonlauncher.dll -launcher commonlauncher.dll -pipename sqlsatellitelaunch -timeout 600000 -logPath "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\LOG\ExtensibilityLog" -workingDir "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExtensibilityData" -externalLanguagesTempDir "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLanguagesTemp" -externalLanguagesDir "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLanguages" -externalLibrariesTempDir "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLibrariesTemp" -externalLibrariesDir "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLibraries" -satelliteDllPath "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlsatellite.dll"
Dependencies : MSSQLServer/

MSSQLSERVER startup parameters :
Display name : SQL Server (MSSQLSERVER)
Service name : MSSQLSERVER
Log on as : .\techexcel
Executable path : "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER
Dependencies : KEYISO/

NlaSvc startup parameters :
Display name : Network Location Awareness
Service name : NlaSvc
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k NetworkService -p
Dependencies : NSI/RpcSs/TcpIp/Dhcp/Eventlog/

Power startup parameters :
Display name : Power
Service name : Power
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k DcomLaunch -p

ProfSvc startup parameters :
Display name : User Profile Service
Service name : ProfSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/

RasMan startup parameters :
Display name : Remote Access Connection Manager
Service name : RasMan
Log on as : localSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs
Dependencies : SstpSvc/DnsCache/

Redis startup parameters :
Display name : Redis
Service name : Redis
Log on as : NT AUTHORITY\NETWORKSERVICE
Executable path : "D:\Techexcel\Program Files\Redis\redis-server.exe" --service-run "D:\Techexcel\Program Files\Redis\redis.windows-service.conf"

RpcEptMapper startup parameters :
Display name : RPC Endpoint Mapper
Service name : RpcEptMapper
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\system32\svchost.exe -k RPCSS -p

RpcSs startup parameters :
Display name : Remote Procedure Call (RPC)
Service name : RpcSs
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\system32\svchost.exe -k rpcss -p
Dependencies : RpcEptMapper/DcomLaunch/

SENS startup parameters :
Display name : System Event Notification Service
Service name : SENS
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : EventSystem/

SQLSERVERAGENT startup parameters :
Display name : SQL Server Agent (MSSQLSERVER)
Service name : SQLSERVERAGENT
Log on as : .\techexcel
Executable path : "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER
Dependencies : MSSQLSERVER/

SQLWriter startup parameters :
Display name : SQL Server VSS Writer
Service name : SQLWriter
Log on as : LocalSystem
Executable path : "C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"

SamSs startup parameters :
Display name : Security Accounts Manager
Service name : SamSs
Log on as : LocalSystem
Executable path : C:\Windows\system32\lsass.exe
Dependencies : RPCSS/

Schedule startup parameters :
Display name : Task Scheduler
Service name : Schedule
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : RPCSS/SystemEventsBroker/

ShellHWDetection startup parameters :
Display name : Shell Hardware Detection
Service name : ShellHWDetection
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/

SysMain startup parameters :
Display name : SysMain
Service name : SysMain
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : rpcss/

SystemEventsBroker startup parameters :
Display name : System Events Broker
Service name : SystemEventsBroker
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k DcomLaunch -p
Dependencies : RpcEptMapper/RpcSs/

Techexcel_API startup parameters :
Display name : Techexcel_API
Service name : Techexcel_API
Log on as : .\techapp
Executable path : D:\Techexcel_DP\Install\nssm.exe

Techexcel_API_2 startup parameters :
Display name : Techexcel_API_2
Service name : Techexcel_API_2
Log on as : .\techapp
Executable path : D:\Techexcel_DP\Install_2\nssm.exe

Techexcel_Jenkins_Slave startup parameters :
Display name : Techexcel_Jenkins_Slave
Service name : Techexcel_Jenkins_Slave
Log on as : LocalSystem
Executable path : D:\Techexcel\Jenkins\nssm.exe

Techexcel_Nginx_Server startup parameters :
Display name : Techexcel_Nginx_Server
Service name : Techexcel_Nginx_Server
Log on as : .\techapp
Executable path : D:\Techexcel\LoadBalancing\Install\nssm.exe

Techexcel_PHP_ApacheServer startup parameters :
Display name : Techexcel_PHP_ApacheServer
Service name : Techexcel_PHP_ApacheServer
Log on as : LocalSystem
Executable path : "D:\Techexcel\PHPApp\Apache24\bin\httpd.exe" -k runservice
Dependencies : Tcpip/Afd/

Themes startup parameters :
Display name : Themes
Service name : Themes
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p

TrkWks startup parameters :
Display name : Distributed Link Tracking Client
Service name : TrkWks
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/

UALSVC startup parameters :
Display name : User Access Logging Service
Service name : UALSVC
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : WinMgmt/

UserManager startup parameters :
Display name : User Manager
Service name : UserManager
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/ProfSvc/

UsoSvc startup parameters :
Display name : Update Orchestrator Service
Service name : UsoSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

VisualSVNServer startup parameters :
Display name : VisualSVN HTTP Service
Service name : VisualSVNServer
Log on as : LocalSystem
Executable path : "D:\Techexcel\Program Files\VisualSVN Server\bin\vsvnhttpsvc.exe" -k runservice -C "LoadModule log_visualsvn_module bin/mod_log_visualsvn.so" -E nul
Dependencies : Afd/Tcpip/

W3SVC startup parameters :
Display name : World Wide Web Publishing Service
Service name : W3SVC
Log on as : localSystem
Executable path : C:\Windows\system32\svchost.exe -k iissvcs
Dependencies : WAS/HTTP/

WSearch startup parameters :
Display name : Windows Search
Service name : WSearch
Log on as : LocalSystem
Executable path : C:\Windows\system32\SearchIndexer.exe /Embedding
Dependencies : RPCSS/BrokerInfrastructure/

WazuhSvc startup parameters :
Display name : Wazuh
Service name : WazuhSvc
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\ossec-agent\wazuh-agent.exe"

Wcmsvc startup parameters :
Display name : Windows Connection Manager
Service name : Wcmsvc
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : RpcSs/NSI/

WinRM startup parameters :
Display name : Windows Remote Management (WS-Management)
Service name : WinRM
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k NetworkService -p
Dependencies : RPCSS/HTTP/

WinVNC4 startup parameters :
Display name : VNC Server Version 4
Service name : WinVNC4
Log on as : LocalSystem
Executable path : "C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service

Winmgmt startup parameters :
Display name : Windows Management Instrumentation
Service name : Winmgmt
Log on as : localSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : RPCSS/

WpnService startup parameters :
Display name : Windows Push Notifications System Service
Service name : WpnService
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

WpnUserService_16f5e9 startup parameters :
Display name : Windows Push Notifications User Service_16f5e9
Service name : WpnUserService_16f5e9
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

WpnUserService_23ba573e startup parameters :
Display name : Windows Push Notifications User Service_23ba573e
Service name : WpnUserService_23ba573e
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

WpnUserService_597ccf32 startup parameters :
Display name : Windows Push Notifications User Service_597ccf32
Service name : WpnUserService_597ccf32
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

WpnUserService_696561f startup parameters :
Display name : Windows Push Notifications User Service_696561f
Service name : WpnUserService_696561f
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

WpnUserService_d274543 startup parameters :
Display name : Windows Push Notifications User Service_d274543
Service name : WpnUserService_d274543
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

aakore startup parameters :
Display name : Acronis Agent Core Service
Service name : aakore
Log on as : LocalSystem
Executable path : "C:\Program Files\Common Files\Acronis\Agent\aakore.exe" run

ams startup parameters :
Display name : Agentless Management Service
Service name : ams
Log on as : LocalSystem
Executable path : "C:\Program Files\OEM\AMS\service\ams.exe"

edgeupdate startup parameters :
Display name : Microsoft Edge Update Service (edgeupdate)
Service name : edgeupdate
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svc
Dependencies : RPCSS/

emergency-updater-0.0.1.2826 startup parameters :
Display name : Acronis Emergency Updater 0.0.1.2826
Service name : emergency-updater-0.0.1.2826
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Common Files\Acronis\EmergencyUpdater\0.0.1.2826\emergency-updater.exe" --emergency-updater

gpsvc startup parameters :
Display name : Group Policy Client
Service name : gpsvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : RPCSS/Mup/

iphlpsvc startup parameters :
Display name : IP Helper
Service name : iphlpsvc
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k NetSvcs -p
Dependencies : RpcSS/winmgmt/tcpip/nsi/WinHttpAutoProxySvc/

mpssvc startup parameters :
Display name : Windows Defender Firewall
Service name : mpssvc
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p
Dependencies : mpsdrv/bfe/

nsi startup parameters :
Display name : Network Store Interface Service
Service name : nsi
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p
Dependencies : rpcss/nsiproxy/

nxlog startup parameters :
Display name : nxlog
Service name : nxlog
Log on as : LocalSystem
Executable path : "C:\Program Files\nxlog\nxlog.exe" -c "C:\Program Files\nxlog\conf\nxlog.conf"
Dependencies : eventlog/

sppsvc startup parameters :
Display name : Software Protection
Service name : sppsvc
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\system32\sppsvc.exe
Dependencies : RpcSs/

updatesd startup parameters :
Display name : updatesd
Service name : updatesd
Log on as : LocalSystem
Executable path : cmd /c start C:\Windows\PLA\spawner.exe

vmrcs startup parameters :
Display name : VMware Remote Console Emulator
Service name : vmrcs
Log on as : LocalSystem
Executable path : C:\Program Files (x86)\vmrx\vmrc.exe

vsvnjobsvc startup parameters :
Display name : VisualSVN Background Job Service
Service name : vsvnjobsvc
Log on as : LocalSystem
Executable path : "D:\Techexcel\Program Files\VisualSVN Server\bin\vsvnjobsvc.exe"
Dependencies : RpcSs/

wuauserv startup parameters :
Display name : Windows Update
Service name : wuauserv
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

The following services must be started manually :

AJRouter startup parameters :
Display name : AllJoyn Router Service
Service name : AJRouter
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p

ALG startup parameters :
Display name : Application Layer Gateway Service
Service name : ALG
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\alg.exe

AppIDSvc startup parameters :
Display name : Application Identity
Service name : AppIDSvc
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : RpcSs/AppID/CryptSvc/

AppMgmt startup parameters :
Display name : Application Management
Service name : AppMgmt
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p

AppReadiness startup parameters :
Display name : App Readiness
Service name : AppReadiness
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k AppReadiness -p

AppXSvc startup parameters :
Display name : AppX Deployment Service (AppXSVC)
Service name : AppXSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k wsappx -p
Dependencies : rpcss/staterepository/

Appinfo startup parameters :
Display name : Application Information
Service name : Appinfo
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/ProfSvc/

AudioEndpointBuilder startup parameters :
Display name : Windows Audio Endpoint Builder
Service name : AudioEndpointBuilder
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p

Audiosrv startup parameters :
Display name : Windows Audio
Service name : Audiosrv
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : AudioEndpointBuilder/RpcSs/

BTAGService startup parameters :
Display name : Bluetooth Audio Gateway Service
Service name : BTAGService
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted
Dependencies : bthserv/rpcss/

BthAvctpSvc startup parameters :
Display name : AVCTP service
Service name : BthAvctpSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p
Dependencies : rpcss/

COMSysApp startup parameters :
Display name : COM+ System Application
Service name : COMSysApp
Log on as : LocalSystem
Executable path : C:\Windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
Dependencies : RpcSs/EventSystem/SENS/

CaptureService_16f5e9 startup parameters :
Display name : CaptureService_16f5e9
Service name : CaptureService_16f5e9
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p

CaptureService_23ba573e startup parameters :
Display name : CaptureService_23ba573e
Service name : CaptureService_23ba573e
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p

CaptureService_597ccf32 startup parameters :
Display name : CaptureService_597ccf32
Service name : CaptureService_597ccf32
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p

CaptureService_696561f startup parameters :
Display name : CaptureService_696561f
Service name : CaptureService_696561f
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p

CaptureService_d274543 startup parameters :
Display name : CaptureService_d274543
Service name : CaptureService_d274543
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p

CertPropSvc startup parameters :
Display name : Certificate Propagation
Service name : CertPropSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs
Dependencies : RpcSs/

ClipSVC startup parameters :
Display name : Client License Service (ClipSVC)
Service name : ClipSVC
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k wsappx -p
Dependencies : rpcss/

ConsentUxUserSvc_16f5e9 startup parameters :
Display name : ConsentUX_16f5e9
Service name : ConsentUxUserSvc_16f5e9
Executable path : C:\Windows\system32\svchost.exe -k DevicesFlow

ConsentUxUserSvc_23ba573e startup parameters :
Display name : ConsentUX_23ba573e
Service name : ConsentUxUserSvc_23ba573e
Executable path : C:\Windows\system32\svchost.exe -k DevicesFlow

ConsentUxUserSvc_597ccf32 startup parameters :
Display name : ConsentUX_597ccf32
Service name : ConsentUxUserSvc_597ccf32
Executable path : C:\Windows\system32\svchost.exe -k DevicesFlow

ConsentUxUserSvc_696561f startup parameters :
Display name : ConsentUX_696561f
Service name : ConsentUxUserSvc_696561f
Executable path : C:\Windows\system32\svchost.exe -k DevicesFlow

ConsentUxUserSvc_d274543 startup parameters :
Display name : ConsentUX_d274543
Service name : ConsentUxUserSvc_d274543
Executable path : C:\Windows\system32\svchost.exe -k DevicesFlow

DevQueryBroker startup parameters :
Display name : DevQuery Background Discovery Broker
Service name : DevQueryBroker
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p

DeviceAssociationService startup parameters :
Display name : Device Association Service
Service name : DeviceAssociationService
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p

DeviceInstall startup parameters :
Display name : Device Install Service
Service name : DeviceInstall
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k DcomLaunch -p

DevicesFlowUserSvc_16f5e9 startup parameters :
Display name : DevicesFlow_16f5e9
Service name : DevicesFlowUserSvc_16f5e9
Executable path : C:\Windows\system32\svchost.exe -k DevicesFlow

DevicesFlowUserSvc_23ba573e startup parameters :
Display name : DevicesFlow_23ba573e
Service name : DevicesFlowUserSvc_23ba573e
Executable path : C:\Windows\system32\svchost.exe -k DevicesFlow

DevicesFlowUserSvc_597ccf32 startup parameters :
Display name : DevicesFlow_597ccf32
Service name : DevicesFlowUserSvc_597ccf32
Executable path : C:\Windows\system32\svchost.exe -k DevicesFlow

DevicesFlowUserSvc_696561f startup parameters :
Display name : DevicesFlow_696561f
Service name : DevicesFlowUserSvc_696561f
Executable path : C:\Windows\system32\svchost.exe -k DevicesFlow

DevicesFlowUserSvc_d274543 startup parameters :
Display name : DevicesFlow_d274543
Service name : DevicesFlowUserSvc_d274543
Executable path : C:\Windows\system32\svchost.exe -k DevicesFlow

DmEnrollmentSvc startup parameters :
Display name : Device Management Enrollment Service
Service name : DmEnrollmentSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

DoSvc startup parameters :
Display name : Delivery Optimization
Service name : DoSvc
Log on as : NT Authority\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k NetworkService -p
Dependencies : rpcss/

DsSvc startup parameters :
Display name : Data Sharing Service
Service name : DsSvc
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p

DsmSvc startup parameters :
Display name : Device Setup Manager
Service name : DsmSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/

EFS startup parameters :
Display name : Encrypting File System (EFS)
Service name : EFS
Log on as : LocalSystem
Executable path : C:\Windows\System32\lsass.exe
Dependencies : RPCSS/

Eaphost startup parameters :
Display name : Extensible Authentication Protocol
Service name : Eaphost
Log on as : localSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p
Dependencies : RPCSS/KeyIso/

EntAppSvc startup parameters :
Display name : Enterprise App Management Service
Service name : EntAppSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k appmodel -p
Dependencies : rpcss/

FDResPub startup parameters :
Display name : Function Discovery Resource Publication
Service name : FDResPub
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
Dependencies : RpcSs/http/fdphost/

FontCache3.0.0.0 startup parameters :
Display name : Windows Presentation Foundation Font Cache 3.0.0.0
Service name : FontCache3.0.0.0
Log on as : NT Authority\LocalService
Executable path : C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe

FrameServer startup parameters :
Display name : Windows Camera Frame Server
Service name : FrameServer
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k Camera
Dependencies : rpcss/

GoogleChromeElevationService startup parameters :
Display name : Google Chrome Elevation Service (GoogleChromeElevationService)
Service name : GoogleChromeElevationService
Log on as : LocalSystem
Executable path : "C:\Program Files\Google\Chrome\Application\143.0.7499.171\elevation_service.exe"
Dependencies : RPCSS/

HvHost startup parameters :
Display name : HV Host Service
Service name : HvHost
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : hvservice/

InstallService startup parameters :
Display name : Microsoft Store Install Service
Service name : InstallService
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

KPSSVC startup parameters :
Display name : KDC Proxy Server service (KPS)
Service name : KPSSVC
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\system32\svchost.exe -k KpsSvcGroup
Dependencies : rpcss/http/

KeyIso startup parameters :
Display name : CNG Key Isolation
Service name : KeyIso
Log on as : LocalSystem
Executable path : C:\Windows\system32\lsass.exe
Dependencies : RpcSs/

KtmRm startup parameters :
Display name : KtmRm for Distributed Transaction Coordinator
Service name : KtmRm
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k NetworkServiceAndNoImpersonation -p
Dependencies : RPCSS/SamSS/

LicenseManager startup parameters :
Display name : Windows License Manager Service
Service name : LicenseManager
Log on as : NT Authority\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalService -p
Dependencies : rpcss/

MSSQLFDLauncher startup parameters :
Display name : SQL Full-text Filter Daemon Launcher (MSSQLSERVER)
Service name : MSSQLFDLauncher
Log on as : NT Service\MSSQLFDLauncher
Executable path : "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL15.MSSQLSERVER

MSiSCSI startup parameters :
Display name : Microsoft iSCSI Initiator Service
Service name : MSiSCSI
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p

MicrosoftEdgeElevationService startup parameters :
Display name : Microsoft Edge Elevation Service (MicrosoftEdgeElevationService)
Service name : MicrosoftEdgeElevationService
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Microsoft\Edge\Application\143.0.3650.96\elevation_service.exe"
Dependencies : RPCSS/

MsMpiLaunchSvc startup parameters :
Display name : MS-MPI Launch Service
Service name : MsMpiLaunchSvc
Log on as : LocalSystem
Executable path : "C:\Program Files\Microsoft MPI\Bin\msmpilaunchsvc.exe"

NcaSvc startup parameters :
Display name : Network Connectivity Assistant
Service name : NcaSvc
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k NetSvcs -p
Dependencies : BFE/dnscache/NSI/iphlpsvc/

NcbService startup parameters :
Display name : Network Connection Broker
Service name : NcbService
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSS/tcpip/

NetSetupSvc startup parameters :
Display name : Network Setup Service
Service name : NetSetupSvc
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/

Netlogon startup parameters :
Display name : Netlogon
Service name : Netlogon
Log on as : LocalSystem
Executable path : C:\Windows\system32\lsass.exe
Dependencies : LanmanWorkstation/

Netman startup parameters :
Display name : Network Connections
Service name : Netman
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/nsi/

NgcCtnrSvc startup parameters :
Display name : Microsoft Passport Container
Service name : NgcCtnrSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : RpcSs/

NgcSvc startup parameters :
Display name : Microsoft Passport
Service name : NgcSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/

PcaSvc startup parameters :
Display name : Program Compatibility Assistant Service
Service name : PcaSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/

PerfHost startup parameters :
Display name : Performance Counter DLL Host
Service name : PerfHost
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\SysWow64\perfhost.exe
Dependencies : RPCSS/

PimIndexMaintenanceSvc_16f5e9 startup parameters :
Display name : Contact Data_16f5e9
Service name : PimIndexMaintenanceSvc_16f5e9
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

PimIndexMaintenanceSvc_23ba573e startup parameters :
Display name : Contact Data_23ba573e
Service name : PimIndexMaintenanceSvc_23ba573e
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

PimIndexMaintenanceSvc_597ccf32 startup parameters :
Display name : Contact Data_597ccf32
Service name : PimIndexMaintenanceSvc_597ccf32
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

PimIndexMaintenanceSvc_696561f startup parameters :
Display name : Contact Data_696561f
Service name : PimIndexMaintenanceSvc_696561f
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

PimIndexMaintenanceSvc_d274543 startup parameters :
Display name : Contact Data_d274543
Service name : PimIndexMaintenanceSvc_d274543
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

PlugPlay startup parameters :
Display name : Plug and Play
Service name : PlugPlay
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k DcomLaunch -p

PolicyAgent startup parameters :
Display name : IPsec Policy Agent
Service name : PolicyAgent
Log on as : NT Authority\NetworkService
Executable path : C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted -p
Dependencies : Tcpip/bfe/

PrintNotify startup parameters :
Display name : Printer Extensions and Notifications
Service name : PrintNotify
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k print
Dependencies : RpcSs/

PrintWorkflowUserSvc_16f5e9 startup parameters :
Display name : PrintWorkflow_16f5e9
Service name : PrintWorkflowUserSvc_16f5e9
Executable path : C:\Windows\system32\svchost.exe -k PrintWorkflow

PrintWorkflowUserSvc_23ba573e startup parameters :
Display name : PrintWorkflow_23ba573e
Service name : PrintWorkflowUserSvc_23ba573e
Executable path : C:\Windows\system32\svchost.exe -k PrintWorkflow

PrintWorkflowUserSvc_597ccf32 startup parameters :
Display name : PrintWorkflow_597ccf32
Service name : PrintWorkflowUserSvc_597ccf32
Executable path : C:\Windows\system32\svchost.exe -k PrintWorkflow

PrintWorkflowUserSvc_696561f startup parameters :
Display name : PrintWorkflow_696561f
Service name : PrintWorkflowUserSvc_696561f
Executable path : C:\Windows\system32\svchost.exe -k PrintWorkflow

PrintWorkflowUserSvc_d274543 startup parameters :
Display name : PrintWorkflow_d274543
Service name : PrintWorkflowUserSvc_d274543
Executable path : C:\Windows\system32\svchost.exe -k PrintWorkflow

QWAVE startup parameters :
Display name : Quality Windows Audio Video Experience
Service name : QWAVE
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
Dependencies : rpcss/psched/QWAVEdrv/LLTDIO/

RSoPProv startup parameters :
Display name : Resultant Set of Policy Provider
Service name : RSoPProv
Log on as : LocalSystem
Executable path : C:\Windows\system32\RSoPProv.exe
Dependencies : RPCSS/

RasAuto startup parameters :
Display name : Remote Access Auto Connection Manager
Service name : RasAuto
Log on as : localSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p
Dependencies : RasAcd/

RemoteRegistry startup parameters :
Display name : Remote Registry
Service name : RemoteRegistry
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k localService -p
Dependencies : RPCSS/

RpcLocator startup parameters :
Display name : Remote Procedure Call (RPC) Locator
Service name : RpcLocator
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\system32\locator.exe

SCPolicySvc startup parameters :
Display name : Smart Card Removal Policy
Service name : SCPolicySvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs
Dependencies : RpcSs/

SCardSvr startup parameters :
Display name : Smart Card
Service name : SCardSvr
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

SNMPTRAP startup parameters :
Display name : SNMP Trap
Service name : SNMPTRAP
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\snmptrap.exe

SQLTELEMETRY startup parameters :
Display name : SQL Server CEIP service (MSSQLSERVER)
Service name : SQLTELEMETRY
Log on as : NT Service\SQLTELEMETRY
Executable path : "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlceip.exe" -Service

SecurityHealthService startup parameters :
Display name : Windows Security Service
Service name : SecurityHealthService
Log on as : LocalSystem
Executable path : C:\Windows\system32\SecurityHealthService.exe
Dependencies : RpcSs/

Sense startup parameters :
Display name : Windows Defender Advanced Threat Protection Service
Service name : Sense
Log on as : LocalSystem
Executable path : "C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe"

SensorService startup parameters :
Display name : Sensor Service
Service name : SensorService
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p

SensrSvc startup parameters :
Display name : Sensor Monitoring Service
Service name : SensrSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p

SessionEnv startup parameters :
Display name : Remote Desktop Configuration
Service name : SessionEnv
Log on as : localSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p
Dependencies : RPCSS/LanmanWorkstation/

SgrmBroker startup parameters :
Display name : System Guard Runtime Monitor Broker
Service name : SgrmBroker
Log on as : LocalSystem
Executable path : C:\Windows\system32\SgrmBroker.exe
Dependencies : RpcSs/

SstpSvc startup parameters :
Display name : Secure Socket Tunneling Protocol Service
Service name : SstpSvc
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p

StateRepository startup parameters :
Display name : State Repository Service
Service name : StateRepository
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k appmodel -p
Dependencies : rpcss/

StorSvc startup parameters :
Display name : Storage Service
Service name : StorSvc
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p

TabletInputService startup parameters :
Display name : Touch Keyboard and Handwriting Panel Service
Service name : TabletInputService
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/

TermService startup parameters :
Display name : Remote Desktop Services
Service name : TermService
Log on as : NT Authority\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k termsvcs
Dependencies : RPCSS/

Tib Mounter Service startup parameters :
Display name : Tib Mounter Service
Service name : Tib Mounter Service
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Common Files\Acronis\TibMounter64\tib_mounter_service.exe"
Dependencies : RPCSS/

TieringEngineService startup parameters :
Display name : Storage Tiers Management
Service name : TieringEngineService
Log on as : localSystem
Executable path : C:\Windows\system32\TieringEngineService.exe

TimeBrokerSvc startup parameters :
Display name : Time Broker
Service name : TimeBrokerSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p

TokenBroker startup parameters :
Display name : Web Account Manager
Service name : TokenBroker
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : UserManager/

TrustedInstaller startup parameters :
Display name : Windows Modules Installer
Service name : TrustedInstaller
Log on as : localSystem
Executable path : C:\Windows\servicing\TrustedInstaller.exe

UmRdpService startup parameters :
Display name : Remote Desktop Services UserMode Port Redirector
Service name : UmRdpService
Log on as : localSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : TermService/RDPDR/

UnistoreSvc_16f5e9 startup parameters :
Display name : User Data Storage_16f5e9
Service name : UnistoreSvc_16f5e9
Executable path : C:\Windows\System32\svchost.exe -k UnistackSvcGroup

UnistoreSvc_23ba573e startup parameters :
Display name : User Data Storage_23ba573e
Service name : UnistoreSvc_23ba573e
Executable path : C:\Windows\System32\svchost.exe -k UnistackSvcGroup

UnistoreSvc_597ccf32 startup parameters :
Display name : User Data Storage_597ccf32
Service name : UnistoreSvc_597ccf32
Executable path : C:\Windows\System32\svchost.exe -k UnistackSvcGroup

UnistoreSvc_696561f startup parameters :
Display name : User Data Storage_696561f
Service name : UnistoreSvc_696561f
Executable path : C:\Windows\System32\svchost.exe -k UnistackSvcGroup

UnistoreSvc_d274543 startup parameters :
Display name : User Data Storage_d274543
Service name : UnistoreSvc_d274543
Executable path : C:\Windows\System32\svchost.exe -k UnistackSvcGroup

UserDataSvc_16f5e9 startup parameters :
Display name : User Data Access_16f5e9
Service name : UserDataSvc_16f5e9
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

UserDataSvc_23ba573e startup parameters :
Display name : User Data Access_23ba573e
Service name : UserDataSvc_23ba573e
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

UserDataSvc_597ccf32 startup parameters :
Display name : User Data Access_597ccf32
Service name : UserDataSvc_597ccf32
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

UserDataSvc_696561f startup parameters :
Display name : User Data Access_696561f
Service name : UserDataSvc_696561f
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

UserDataSvc_d274543 startup parameters :
Display name : User Data Access_d274543
Service name : UserDataSvc_d274543
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

VSS startup parameters :
Display name : Volume Shadow Copy
Service name : VSS
Log on as : LocalSystem
Executable path : C:\Windows\system32\vssvc.exe
Dependencies : RPCSS/

VaultSvc startup parameters :
Display name : Credential Manager
Service name : VaultSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\lsass.exe
Dependencies : rpcss/

W32Time startup parameters :
Display name : Windows Time
Service name : W32Time
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService

WAS startup parameters :
Display name : Windows Process Activation Service
Service name : WAS
Log on as : localSystem
Executable path : C:\Windows\system32\svchost.exe -k iissvcs
Dependencies : RPCSS/

WEPHOSTSVC startup parameters :
Display name : Windows Encryption Provider Host Service
Service name : WEPHOSTSVC
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k WepHostSvcGroup
Dependencies : rpcss/

WMPNetworkSvc startup parameters :
Display name : Windows Media Player Network Sharing Service
Service name : WMPNetworkSvc
Log on as : NT AUTHORITY\NetworkService
Executable path : "C:\Program Files\Windows Media Player\wmpnetwk.exe"
Dependencies : http/WSearch/

WMSVC startup parameters :
Display name : Web Management Service
Service name : WMSVC
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\inetsrv\wmsvc.exe
Dependencies : HTTP/

WPDBusEnum startup parameters :
Display name : Portable Device Enumerator Service
Service name : WPDBusEnum
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : RpcSs/

WaaSMedicSvc startup parameters :
Display name : Windows Update Medic Service
Service name : WaaSMedicSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k wusvcs -p
Dependencies : rpcss/

WarpJITSvc startup parameters :
Display name : WarpJITSvc
Service name : WarpJITSvc
Log on as : NT Authority\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

WbioSrvc startup parameters :
Display name : Windows Biometric Service
Service name : WbioSrvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k WbioSvcGroup
Dependencies : RpcSs/

WdiServiceHost startup parameters :
Display name : Diagnostic Service Host
Service name : WdiServiceHost
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalService -p

WdiSystemHost startup parameters :
Display name : Diagnostic System Host
Service name : WdiSystemHost
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p

Wecsvc startup parameters :
Display name : Windows Event Collector
Service name : Wecsvc
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\system32\svchost.exe -k NetworkService -p
Dependencies : HTTP/Eventlog/

WerSvc startup parameters :
Display name : Windows Error Reporting Service
Service name : WerSvc
Log on as : localSystem
Executable path : C:\Windows\System32\svchost.exe -k WerSvcGroup

WiaRpc startup parameters :
Display name : Still Image Acquisition Events
Service name : WiaRpc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/

WinHttpAutoProxySvc startup parameters :
Display name : WinHTTP Web Proxy Auto-Discovery Service
Service name : WinHttpAutoProxySvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : Dhcp/

aspnet_state startup parameters :
Display name : ASP.NET State Service
Service name : aspnet_state
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe

bthserv startup parameters :
Display name : Bluetooth Support Service
Service name : bthserv
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p

camsvc startup parameters :
Display name : Capability Access Manager Service
Service name : camsvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k appmodel -p

cbdhsvc_16f5e9 startup parameters :
Display name : Clipboard User Service_16f5e9
Service name : cbdhsvc_16f5e9
Executable path : C:\Windows\system32\svchost.exe -k ClipboardSvcGroup -p

cbdhsvc_23ba573e startup parameters :
Display name : Clipboard User Service_23ba573e
Service name : cbdhsvc_23ba573e
Executable path : C:\Windows\system32\svchost.exe -k ClipboardSvcGroup -p

cbdhsvc_597ccf32 startup parameters :
Display name : Clipboard User Service_597ccf32
Service name : cbdhsvc_597ccf32
Executable path : C:\Windows\system32\svchost.exe -k ClipboardSvcGroup -p

cbdhsvc_696561f startup parameters :
Display name : Clipboard User Service_696561f
Service name : cbdhsvc_696561f
Executable path : C:\Windows\system32\svchost.exe -k ClipboardSvcGroup -p

cbdhsvc_d274543 startup parameters :
Display name : Clipboard User Service_d274543
Service name : cbdhsvc_d274543
Executable path : C:\Windows\system32\svchost.exe -k ClipboardSvcGroup -p

defragsvc startup parameters :
Display name : Optimize drives
Service name : defragsvc
Log on as : localSystem
Executable path : C:\Windows\system32\svchost.exe -k defragsvc
Dependencies : RPCSS/

diagnosticshub.standardcollector.service startup parameters :
Display name : Microsoft (R) Diagnostics Hub Standard Collector Service
Service name : diagnosticshub.standardcollector.service
Log on as : LocalSystem
Executable path : C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe

dot3svc startup parameters :
Display name : Wired AutoConfig
Service name : dot3svc
Log on as : localSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/Ndisuio/Eaphost/

edgeupdatem startup parameters :
Display name : Microsoft Edge Update Service (edgeupdatem)
Service name : edgeupdatem
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /medsvc
Dependencies : RPCSS/

embeddedmode startup parameters :
Display name : Embedded Mode
Service name : embeddedmode
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : BrokerInfrastructure/

fdPHost startup parameters :
Display name : Function Discovery Provider Host
Service name : fdPHost
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p
Dependencies : RpcSs/http/

hidserv startup parameters :
Display name : Human Interface Device Service
Service name : hidserv
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p

lmhosts startup parameters :
Display name : TCP/IP NetBIOS Helper
Service name : lmhosts
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : Afd/

msiserver startup parameters :
Display name : Windows Installer
Service name : msiserver
Log on as : LocalSystem
Executable path : C:\Windows\system32\msiexec.exe /V
Dependencies : rpcss/

netprofm startup parameters :
Display name : Network List Service
Service name : netprofm
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalService -p
Dependencies : RpcSs/nlasvc/

ose64 startup parameters :
Display name : Office 64 Source Engine
Service name : ose64
Log on as : LocalSystem
Executable path : "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"

pla startup parameters :
Display name : Performance Logs & Alerts
Service name : pla
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork -p
Dependencies : RPCSS/

sacsvr startup parameters :
Display name : Special Administration Console Helper
Service name : sacsvr
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p

seclogon startup parameters :
Display name : Secondary Logon
Service name : seclogon
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p

smphost startup parameters :
Display name : Microsoft Storage Spaces SMP
Service name : smphost
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k smphost
Dependencies : RPCSS/

stisvc startup parameters :
Display name : Windows Image Acquisition (WIA)
Service name : stisvc
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k imgsvc
Dependencies : RpcSs/

svsvc startup parameters :
Display name : Spot Verifier
Service name : svsvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p

swprv startup parameters :
Display name : Microsoft Software Shadow Copy Provider
Service name : swprv
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k swprv
Dependencies : RPCSS/

tapisrv startup parameters :
Display name : Telephony
Service name : tapisrv
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k NetworkService -p
Dependencies : RpcSs/

vds startup parameters :
Display name : Virtual Disk
Service name : vds
Log on as : LocalSystem
Executable path : C:\Windows\System32\vds.exe
Dependencies : RpcSs/

vmicguestinterface startup parameters :
Display name : Hyper-V Guest Service Interface
Service name : vmicguestinterface
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p

vmicheartbeat startup parameters :
Display name : Hyper-V Heartbeat Service
Service name : vmicheartbeat
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k ICService -p

vmickvpexchange startup parameters :
Display name : Hyper-V Data Exchange Service
Service name : vmickvpexchange
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p

vmicrdv startup parameters :
Display name : Hyper-V Remote Desktop Virtualization Service
Service name : vmicrdv
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k ICService -p

vmicshutdown startup parameters :
Display name : Hyper-V Guest Shutdown Service
Service name : vmicshutdown
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p

vmictimesync startup parameters :
Display name : Hyper-V Time Synchronization Service
Service name : vmictimesync
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : VmGid/

vmicvmsession startup parameters :
Display name : Hyper-V PowerShell Direct Service
Service name : vmicvmsession
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p

vmicvss startup parameters :
Display name : Hyper-V Volume Shadow Copy Requestor
Service name : vmicvss
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p

vrepocfgsvc startup parameters :
Display name : VisualSVN Repository Configurator Service
Service name : vrepocfgsvc
Log on as : NT AUTHORITY\Networkservice
Executable path : "D:\Techexcel\Program Files\VisualSVN Server\bin\vrepocfgsvc.exe"
Dependencies : RpcSS/

w3logsvc startup parameters :
Display name : W3C Logging Service
Service name : w3logsvc
Log on as : localSystem
Executable path : C:\Windows\system32\svchost.exe -k apphost
Dependencies : HTTP/

wercplsupport startup parameters :
Display name : Problem Reports and Solutions Control Panel Support
Service name : wercplsupport
Log on as : localSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p

wlidsvc startup parameters :
Display name : Microsoft Account Sign-in Assistant
Service name : wlidsvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/

wmiApSrv startup parameters :
Display name : WMI Performance Adapter
Service name : wmiApSrv
Log on as : localSystem
Executable path : C:\Windows\system32\wbem\WmiApSrv.exe

The following services are disabled :

AppVClient startup parameters :
Display name : Microsoft App-V Client
Service name : AppVClient
Log on as : LocalSystem
Executable path : C:\Windows\system32\AppVClient.exe
Dependencies : RpcSS/netprofm/AppvVfs/AppVStrm/

AxInstSV startup parameters :
Display name : ActiveX Installer (AxInstSV)
Service name : AxInstSV
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k AxInstSVGroup
Dependencies : rpcss/

CscService startup parameters :
Display name : Offline Files
Service name : CscService
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/

DevicePickerUserSvc_16f5e9 startup parameters :
Display name : DevicePicker_16f5e9
Service name : DevicePickerUserSvc_16f5e9
Executable path : C:\Windows\system32\svchost.exe -k DevicesFlow

DevicePickerUserSvc_23ba573e startup parameters :
Display name : DevicePicker_23ba573e
Service name : DevicePickerUserSvc_23ba573e
Executable path : C:\Windows\system32\svchost.exe -k DevicesFlow

DevicePickerUserSvc_597ccf32 startup parameters :
Display name : DevicePicker_597ccf32
Service name : DevicePickerUserSvc_597ccf32
Executable path : C:\Windows\system32\svchost.exe -k DevicesFlow

DevicePickerUserSvc_696561f startup parameters :
Display name : DevicePicker_696561f
Service name : DevicePickerUserSvc_696561f
Executable path : C:\Windows\system32\svchost.exe -k DevicesFlow

DevicePickerUserSvc_d274543 startup parameters :
Display name : DevicePicker_d274543
Service name : DevicePickerUserSvc_d274543
Executable path : C:\Windows\system32\svchost.exe -k DevicesFlow

GraphicsPerfSvc startup parameters :
Display name : GraphicsPerfSvc
Service name : GraphicsPerfSvc
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k GraphicsPerfSvcGroup

MapsBroker startup parameters :
Display name : Downloaded Maps Manager
Service name : MapsBroker
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k NetworkService -p
Dependencies : rpcss/

NetTcpPortSharing startup parameters :
Display name : Net.Tcp Port Sharing Service
Service name : NetTcpPortSharing
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe

PhoneSvc startup parameters :
Display name : Phone Service
Service name : PhoneSvc
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p
Dependencies : RpcSs/

PushToInstall startup parameters :
Display name : Windows PushToInstall Service
Service name : PushToInstall
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

RemoteAccess startup parameters :
Display name : Routing and Remote Access
Service name : RemoteAccess
Log on as : localSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs
Dependencies : RpcSS/Bfe/RasMan/Http/+NetBIOSGroup/

RmSvc startup parameters :
Display name : Radio Management Service
Service name : RmSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
Dependencies : RpcSs/

SEMgrSvc startup parameters :
Display name : Payments and NFC/SE Manager
Service name : SEMgrSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p
Dependencies : RpcSs/

SQLBrowser startup parameters :
Display name : SQL Server Browser
Service name : SQLBrowser
Log on as : NT AUTHORITY\LOCALSERVICE
Executable path : "C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe"

SSDPSRV startup parameters :
Display name : SSDP Discovery
Service name : SSDPSRV
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
Dependencies : HTTP/NSI/

ScDeviceEnum startup parameters :
Display name : Smart Card Device Enumeration Service
Service name : ScDeviceEnum
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted

SensorDataService startup parameters :
Display name : Sensor Data Service
Service name : SensorDataService
Log on as : LocalSystem
Executable path : C:\Windows\System32\SensorDataService.exe

SharedAccess startup parameters :
Display name : Internet Connection Sharing (ICS)
Service name : SharedAccess
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p
Dependencies : BFE/

Spooler startup parameters :
Display name : Print Spooler
Service name : Spooler
Log on as : LocalSystem
Executable path : C:\Windows\System32\spoolsv.exe
Dependencies : RPCSS/http/

UevAgentService startup parameters :
Display name : User Experience Virtualization Service
Service name : UevAgentService
Log on as : LocalSystem
Executable path : C:\Windows\system32\AgentService.exe

WalletService startup parameters :
Display name : WalletService
Service name : WalletService
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k appmodel -p

dmwappushservice startup parameters :
Display name : Device Management Wireless Application Protocol (WAP) Push message Routing Service
Service name : dmwappushservice
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

icssvc startup parameters :
Display name : Windows Mobile Hotspot Service
Service name : icssvc
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : RpcSs/wcmsvc/

lfsvc startup parameters :
Display name : Geolocation Service
Service name : lfsvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/

lltdsvc startup parameters :
Display name : Link-Layer Topology Discovery Mapper
Service name : lltdsvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalService -p
Dependencies : rpcss/lltdio/

shpamsvc startup parameters :
Display name : Shared PC Account Manager
Service name : shpamsvc
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/ProfSvc/

sma startup parameters :
Display name : System Management Assistant Service
Service name : sma
Log on as : LocalSystem
Executable path : "C:\Program Files\OEM\AMS\service\sma.exe"

ssh-agent startup parameters :
Display name : OpenSSH Authentication Agent
Service name : ssh-agent
Log on as : LocalSystem
Executable path : C:\Windows\System32\OpenSSH\ssh-agent.exe

tzautoupdate startup parameters :
Display name : Auto Time Zone Updater
Service name : tzautoupdate
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService -p

upnphost startup parameters :
Display name : UPnP Device Host
Service name : upnphost
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
Dependencies : SSDPSRV/HTTP/

vdfssvc startup parameters :
Display name : VisualSVN Distributed File System Service
Service name : vdfssvc
Log on as : NT AUTHORITY\Networkservice
Executable path : "D:\Techexcel\Program Files\VisualSVN Server\bin\vdfssvc.exe" runservice
Dependencies : RpcSs/Tcpip/

vsvnsearchsvc startup parameters :
Display name : VisualSVN Search Index Service
Service name : vsvnsearchsvc
Log on as : NT AUTHORITY\Networkservice
Executable path : "D:\Techexcel\Program Files\VisualSVN Server\bin\vsvnsearchsvc.exe" runservice
Dependencies : RpcSs/

wisvc startup parameters :
Display name : Windows Insider Service
Service name : wisvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

11011 - Microsoft Windows SMB Service Detection
-
Synopsis
A file / print sharing service is listening on the remote host.
Description
The remote service understands the CIFS (Common Internet File System) or Server Message Block (SMB) protocol, used to provide shared access to files, printers, etc between nodes on a network.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2002/06/05, Modified: 2021/02/11
Plugin Output

tcp/139/smb


An SMB server is running on this port.

11011 - Microsoft Windows SMB Service Detection
-
Synopsis
A file / print sharing service is listening on the remote host.
Description
The remote service understands the CIFS (Common Internet File System) or Server Message Block (SMB) protocol, used to provide shared access to files, printers, etc between nodes on a network.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2002/06/05, Modified: 2021/02/11
Plugin Output

tcp/445/cifs


A CIFS server is running on this port.
10456 - Microsoft Windows SMB Service Enumeration
-
Synopsis
It is possible to enumerate remote services.
Description
This plugin implements the SvcOpenSCManager() and SvcEnumServices() calls to obtain, using the SMB protocol, the list of active and inactive services of the remote host.

An attacker may use this feature to gain better knowledge of the remote host.
Solution
To prevent the listing of the services from being obtained, you should either have tight login restrictions, so that only trusted users can access your host, and/or you should filter incoming traffic to this port.
Risk Factor
None
References
XREF IAVT:0001-T-0751
Plugin Information
Published: 2000/07/03, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Active Services :

Acronis Agent Core Service [ aakore ]
Acronis Active Protection Service [ AcronisActiveProtectionService ]
Acronis Cyber Protection Service [ AcronisCyberProtectionService ]
Acronis Scheduler2 Service [ AcrSch2Svc ]
Agentless Management Service [ ams ]
Application Host Helper Service [ AppHostSvc ]
Application Information [ Appinfo ]
Application Management [ AppMgmt ]
AzureAttestService [ AzureAttestService ]
Base Filtering Engine [ BFE ]
Background Tasks Infrastructure Service [ BrokerInfrastructure ]
Connected Devices Platform Service [ CDPSvc ]
Certificate Propagation [ CertPropSvc ]
CoreMessaging [ CoreMessagingRegistrar ]
Cryptographic Services [ CryptSvc ]
DCOM Server Process Launcher [ DcomLaunch ]
DHCP Client [ Dhcp ]
Connected User Experiences and Telemetry [ DiagTrack ]
DNS Client [ Dnscache ]
Diagnostic Policy Service [ DPS ]
Data Sharing Service [ DsSvc ]
Acronis Emergency Updater 0.0.1.2826 [ emergency-updater-0.0.1.2826 ]
Windows Event Log [ EventLog ]
COM+ Event System [ EventSystem ]
Function Discovery Provider Host [ fdPHost ]
Windows Font Cache Service [ FontCache ]
Group Policy Client [ gpsvc ]
HPE Smart Array SR Event Notification Service [ HpePqiESrv ]
IIS Admin Service [ IISADMIN ]
IKE and AuthIP IPsec Keying Modules [ IKEEXT ]
IP Helper [ iphlpsvc ]
CNG Key Isolation [ KeyIso ]
Server [ LanmanServer ]
Workstation [ LanmanWorkstation ]
Windows License Manager Service [ LicenseManager ]
TCP/IP NetBIOS Helper [ lmhosts ]
Local Session Manager [ LSM ]
Techexcel_Lucee [ Lucee ]
Techexcel_Lucee02 [ Lucee02 ]
Techexcel_Lucee11 [ Lucee11 ]
Techexcel_Lucee12 [ Lucee12 ]
Techexcel_Lucee13 [ Lucee13 ]
Techexcel_Lucee14 [ Lucee14 ]
Acronis Managed Machine Service [ MMS ]
Windows Defender Firewall [ mpssvc ]
Distributed Transaction Coordinator [ MSDTC ]
SQL Full-text Filter Daemon Launcher (MSSQLSERVER) [ MSSQLFDLauncher ]
SQL Server (MSSQLSERVER) [ MSSQLSERVER ]
Network Connection Broker [ NcbService ]
Network Connections [ Netman ]
Network List Service [ netprofm ]
Network Setup Service [ NetSetupSvc ]
Network Location Awareness [ NlaSvc ]
Network Store Interface Service [ nsi ]
nxlog [ nxlog ]
Program Compatibility Assistant Service [ PcaSvc ]
Plug and Play [ PlugPlay ]
IPsec Policy Agent [ PolicyAgent ]
Power [ Power ]
User Profile Service [ ProfSvc ]
Remote Access Connection Manager [ RasMan ]
Redis [ Redis ]
Remote Registry [ RemoteRegistry ]
RPC Endpoint Mapper [ RpcEptMapper ]
Remote Procedure Call (RPC) [ RpcSs ]
Security Accounts Manager [ SamSs ]
Task Scheduler [ Schedule ]
System Event Notification Service [ SENS ]
Remote Desktop Configuration [ SessionEnv ]
Shell Hardware Detection [ ShellHWDetection ]
Software Protection [ sppsvc ]
SQL Server Agent (MSSQLSERVER) [ SQLSERVERAGENT ]
SQL Server VSS Writer [ SQLWriter ]
Secure Socket Tunneling Protocol Service [ SstpSvc ]
State Repository Service [ StateRepository ]
Storage Service [ StorSvc ]
SysMain [ SysMain ]
System Events Broker [ SystemEventsBroker ]
Touch Keyboard and Handwriting Panel Service [ TabletInputService ]
Techexcel_API [ Techexcel_API ]
Techexcel_API_2 [ Techexcel_API_2 ]
Techexcel_Jenkins_Slave [ Techexcel_Jenkins_Slave ]
Techexcel_Nginx_Server [ Techexcel_Nginx_Server ]
Techexcel_PHP_ApacheServer [ Techexcel_PHP_ApacheServer ]
Remote Desktop Services [ TermService ]
Themes [ Themes ]
Time Broker [ TimeBrokerSvc ]
Web Account Manager [ TokenBroker ]
Distributed Link Tracking Client [ TrkWks ]
Windows Modules Installer [ TrustedInstaller ]
User Access Logging Service [ UALSVC ]
Remote Desktop Services UserMode Port Redirector [ UmRdpService ]
User Manager [ UserManager ]
Update Orchestrator Service [ UsoSvc ]
Credential Manager [ VaultSvc ]
VisualSVN HTTP Service [ VisualSVNServer ]
VMware Remote Console Emulator [ vmrcs ]
VisualSVN Background Job Service [ vsvnjobsvc ]
World Wide Web Publishing Service [ W3SVC ]
Windows Process Activation Service [ WAS ]
Wazuh [ WazuhSvc ]
Windows Connection Manager [ Wcmsvc ]
Diagnostic Service Host [ WdiServiceHost ]
WinHTTP Web Proxy Auto-Discovery Service [ WinHttpAutoProxySvc ]
Windows Management Instrumentation [ Winmgmt ]
Windows Remote Management (WS-Management) [ WinRM ]
VNC Server Version 4 [ WinVNC4 ]
Windows Push Notifications System Service [ WpnService ]
Windows Search [ WSearch ]
Connected Devices Platform User Service_16f5e9 [ CDPUserSvc_16f5e9 ]
Windows Push Notifications User Service_16f5e9 [ WpnUserService_16f5e9 ]
Connected Devices Platform User Service_696561f [ CDPUserSvc_696561f ]
Windows Push Notifications User Service_696561f [ WpnUserService_696561f ]
Connected Devices Platform User Service_d274543 [ CDPUserSvc_d274543 ]
Windows Push Notifications User Service_d274543 [ WpnUserService_d274543 ]
Connected Devices Platform User Service_23ba573e [ CDPUserSvc_23ba573e ]
Windows Push Notifications User Service_23ba573e [ WpnUserService_23ba573e ]
Connected Devices Platform User Service_597ccf32 [ CDPUserSvc_597ccf32 ]
Windows Push Notifications User Service_597ccf32 [ WpnUserService_597ccf32 ]

Inactive Services :

AdoeCheck [ AdoeCheck ]
AllJoyn Router Service [ AJRouter ]
Application Layer Gateway Service [ ALG ]
Application Identity [ AppIDSvc ]
App Readiness [ AppReadiness ]
Microsoft App-V Client [ AppVClient ]
AppX Deployment Service (AppXSVC) [ AppXSvc ]
ASP.NET State Service [ aspnet_state ]
Windows Audio Endpoint Builder [ AudioEndpointBuilder ]
Windows Audio [ Audiosrv ]
ActiveX Installer (AxInstSV) [ AxInstSV ]
Background Intelligent Transfer Service [ BITS ]
Bluetooth Audio Gateway Service [ BTAGService ]
AVCTP service [ BthAvctpSvc ]
Bluetooth Support Service [ bthserv ]
Capability Access Manager Service [ camsvc ]
Client License Service (ClipSVC) [ ClipSVC ]
COM+ System Application [ COMSysApp ]
Offline Files [ CscService ]
Optimize drives [ defragsvc ]
Device Association Service [ DeviceAssociationService ]
Device Install Service [ DeviceInstall ]
DevQuery Background Discovery Broker [ DevQueryBroker ]
Microsoft (R) Diagnostics Hub Standard Collector Service [ diagnosticshub.standardcollector.service ]
Device Management Enrollment Service [ DmEnrollmentSvc ]
Device Management Wireless Application Protocol (WAP) Push message Routing Service [ dmwappushservice ]
Delivery Optimization [ DoSvc ]
Wired AutoConfig [ dot3svc ]
Device Setup Manager [ DsmSvc ]
Extensible Authentication Protocol [ Eaphost ]
Microsoft Edge Update Service (edgeupdate) [ edgeupdate ]
Microsoft Edge Update Service (edgeupdatem) [ edgeupdatem ]
Encrypting File System (EFS) [ EFS ]
Embedded Mode [ embeddedmode ]
Enterprise App Management Service [ EntAppSvc ]
Function Discovery Resource Publication [ FDResPub ]
Windows Presentation Foundation Font Cache 3.0.0.0 [ FontCache3.0.0.0 ]
Windows Camera Frame Server [ FrameServer ]
Google Chrome Elevation Service (GoogleChromeElevationService) [ GoogleChromeElevationService ]
Google Updater Internal Service (GoogleUpdaterInternalService145.0.7569.0) [ GoogleUpdaterInternalService145.0.7569.0 ]
Google Updater Service (GoogleUpdaterService145.0.7569.0) [ GoogleUpdaterService145.0.7569.0 ]
GraphicsPerfSvc [ GraphicsPerfSvc ]
Human Interface Device Service [ hidserv ]
HV Host Service [ HvHost ]
Windows Mobile Hotspot Service [ icssvc ]
Microsoft Store Install Service [ InstallService ]
KDC Proxy Server service (KPS) [ KPSSVC ]
KtmRm for Distributed Transaction Coordinator [ KtmRm ]
Geolocation Service [ lfsvc ]
Link-Layer Topology Discovery Mapper [ lltdsvc ]
Downloaded Maps Manager [ MapsBroker ]
Microsoft Edge Elevation Service (MicrosoftEdgeElevationService) [ MicrosoftEdgeElevationService ]
Microsoft iSCSI Initiator Service [ MSiSCSI ]
Windows Installer [ msiserver ]
MS-MPI Launch Service [ MsMpiLaunchSvc ]
SQL Server Launchpad (MSSQLSERVER) [ MSSQLLaunchpad ]
Network Connectivity Assistant [ NcaSvc ]
Netlogon [ Netlogon ]
Net.Tcp Port Sharing Service [ NetTcpPortSharing ]
Microsoft Passport Container [ NgcCtnrSvc ]
Microsoft Passport [ NgcSvc ]
Office 64 Source Engine [ ose64 ]
Performance Counter DLL Host [ PerfHost ]
Phone Service [ PhoneSvc ]
Performance Logs & Alerts [ pla ]
Printer Extensions and Notifications [ PrintNotify ]
Windows PushToInstall Service [ PushToInstall ]
Quality Windows Audio Video Experience [ QWAVE ]
Remote Access Auto Connection Manager [ RasAuto ]
Routing and Remote Access [ RemoteAccess ]
Radio Management Service [ RmSvc ]
Remote Procedure Call (RPC) Locator [ RpcLocator ]
Resultant Set of Policy Provider [ RSoPProv ]
Special Administration Console Helper [ sacsvr ]
Smart Card [ SCardSvr ]
Smart Card Device Enumeration Service [ ScDeviceEnum ]
Smart Card Removal Policy [ SCPolicySvc ]
Secondary Logon [ seclogon ]
Windows Security Service [ SecurityHealthService ]
Payments and NFC/SE Manager [ SEMgrSvc ]
Windows Defender Advanced Threat Protection Service [ Sense ]
Sensor Data Service [ SensorDataService ]
Sensor Service [ SensorService ]
Sensor Monitoring Service [ SensrSvc ]
System Guard Runtime Monitor Broker [ SgrmBroker ]
Internet Connection Sharing (ICS) [ SharedAccess ]
Shared PC Account Manager [ shpamsvc ]
System Management Assistant Service [ sma ]
Microsoft Storage Spaces SMP [ smphost ]
SNMP Trap [ SNMPTRAP ]
Print Spooler [ Spooler ]
SQL Server Browser [ SQLBrowser ]
SQL Server CEIP service (MSSQLSERVER) [ SQLTELEMETRY ]
SSDP Discovery [ SSDPSRV ]
OpenSSH Authentication Agent [ ssh-agent ]
Windows Image Acquisition (WIA) [ stisvc ]
Spot Verifier [ svsvc ]
Microsoft Software Shadow Copy Provider [ swprv ]
Telephony [ tapisrv ]
Tib Mounter Service [ Tib Mounter Service ]
Storage Tiers Management [ TieringEngineService ]
Auto Time Zone Updater [ tzautoupdate ]
User Experience Virtualization Service [ UevAgentService ]
updatesd [ updatesd ]
UPnP Device Host [ upnphost ]
VisualSVN Distributed File System Service [ vdfssvc ]
Virtual Disk [ vds ]
Hyper-V Guest Service Interface [ vmicguestinterface ]
Hyper-V Heartbeat Service [ vmicheartbeat ]
Hyper-V Data Exchange Service [ vmickvpexchange ]
Hyper-V Remote Desktop Virtualization Service [ vmicrdv ]
Hyper-V Guest Shutdown Service [ vmicshutdown ]
Hyper-V Time Synchronization Service [ vmictimesync ]
Hyper-V PowerShell Direct Service [ vmicvmsession ]
Hyper-V Volume Shadow Copy Requestor [ vmicvss ]
VisualSVN Repository Configurator Service [ vrepocfgsvc ]
Volume Shadow Copy [ VSS ]
VisualSVN Search Index Service [ vsvnsearchsvc ]
Windows Time [ W32Time ]
W3C Logging Service [ w3logsvc ]
Windows Update Medic Service [ WaaSMedicSvc ]
WalletService [ WalletService ]
WarpJITSvc [ WarpJITSvc ]
Windows Biometric Service [ WbioSrvc ]
Diagnostic System Host [ WdiSystemHost ]
Windows Event Collector [ Wecsvc ]
Windows Encryption Provider Host Service [ WEPHOSTSVC ]
Problem Reports and Solutions Control Panel Support [ wercplsupport ]
Windows Error Reporting Service [ WerSvc ]
Still Image Acquisition Events [ WiaRpc ]
Windows Insider Service [ wisvc ]
Microsoft Account Sign-in Assistant [ wlidsvc ]
WMI Performance Adapter [ wmiApSrv ]
Windows Media Player Network Sharing Service [ WMPNetworkSvc ]
Web Management Service [ WMSVC ]
Portable Device Enumerator Service [ WPDBusEnum ]
Windows Update [ wuauserv ]
CaptureService_16f5e9 [ CaptureService_16f5e9 ]
Clipboard User Service_16f5e9 [ cbdhsvc_16f5e9 ]
ConsentUX_16f5e9 [ ConsentUxUserSvc_16f5e9 ]
DevicePicker_16f5e9 [ DevicePickerUserSvc_16f5e9 ]
DevicesFlow_16f5e9 [ DevicesFlowUserSvc_16f5e9 ]
Contact Data_16f5e9 [ PimIndexMaintenanceSvc_16f5e9 ]
PrintWorkflow_16f5e9 [ PrintWorkflowUserSvc_16f5e9 ]
User Data Storage_16f5e9 [ UnistoreSvc_16f5e9 ]
User Data Access_16f5e9 [ UserDataSvc_16f5e9 ]
CaptureService_696561f [ CaptureService_696561f ]
Clipboard User Service_696561f [ cbdhsvc_696561f ]
ConsentUX_696561f [ ConsentUxUserSvc_696561f ]
DevicePicker_696561f [ DevicePickerUserSvc_696561f ]
DevicesFlow_696561f [ DevicesFlowUserSvc_696561f ]
Contact Data_696561f [ PimIndexMaintenanceSvc_696561f ]
PrintWorkflow_696561f [ PrintWorkflowUserSvc_696561f ]
User Data Storage_696561f [ UnistoreSvc_696561f ]
User Data Access_696561f [ UserDataSvc_696561f ]
CaptureService_d274543 [ CaptureService_d274543 ]
Clipboard User Service_d274543 [ cbdhsvc_d274543 ]
ConsentUX_d274543 [ ConsentUxUserSvc_d274543 ]
DevicePicker_d274543 [ DevicePickerUserSvc_d274543 ]
DevicesFlow_d274543 [ DevicesFlowUserSvc_d274543 ]
Contact Data_d274543 [ PimIndexMaintenanceSvc_d274543 ]
PrintWorkflow_d274543 [ PrintWorkflowUserSvc_d274543 ]
User Data Storage_d274543 [ UnistoreSvc_d274543 ]
User Data Access_d274543 [ UserDataSvc_d274543 ]
CaptureService_23ba573e [ CaptureService_23ba573e ]
Clipboard User Service_23ba573e [ cbdhsvc_23ba573e ]
ConsentUX_23ba573e [ ConsentUxUserSvc_23ba573e ]
DevicePicker_23ba573e [ DevicePickerUserSvc_23ba573e ]
DevicesFlow_23ba573e [ DevicesFlowUserSvc_23ba573e ]
Contact Data_23ba573e [ PimIndexMaintenanceSvc_23ba573e ]
PrintWorkflow_23ba573e [ PrintWorkflowUserSvc_23ba573e ]
User Data Storage_23ba573e [ UnistoreSvc_23ba573e ]
User Data Access_23ba573e [ UserDataSvc_23ba573e ]
CaptureService_597ccf32 [ CaptureService_597ccf32 ]
Clipboard User Service_597ccf32 [ cbdhsvc_597ccf32 ]
ConsentUX_597ccf32 [ ConsentUxUserSvc_597ccf32 ]
DevicePicker_597ccf32 [ DevicePickerUserSvc_597ccf32 ]
DevicesFlow_597ccf32 [ DevicesFlowUserSvc_597ccf32 ]
Contact Data_597ccf32 [ PimIndexMaintenanceSvc_597ccf32 ]
PrintWorkflow_597ccf32 [ PrintWorkflowUserSvc_597ccf32 ]
User Data Storage_597ccf32 [ UnistoreSvc_597ccf32 ]
User Data Access_597ccf32 [ UserDataSvc_597ccf32 ]
23974 - Microsoft Windows SMB Share Hosting Office Files
-
Synopsis
The remote share contains Office-related files.
Description
This plugin connects to the remotely accessible SMB shares and attempts to find office related files (such as .doc, .ppt, .xls, .pdf etc).
Solution
Make sure that the files containing confidential information have proper access controls set on them.
Risk Factor
None
Plugin Information
Published: 2007/01/04, Modified: 2011/03/21
Plugin Output

tcp/445/cifs


Here is a list of office files which have been found on the remote SMB
shares :

+ C$ :

- C:\Windows\System32\MSDRM\MsoIrmProtector.doc
- C:\Windows\WinSxS\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.5830_none_6579d6f2fbd323de\MsoIrmProtector.doc
- C:\Windows\WinSxS\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.1697_none_6594d176fbbe42d1\MsoIrmProtector.doc
- C:\Windows\WinSxS\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.5830_none_5b252ca0c77261e3\MsoIrmProtector.doc
- C:\Windows\WinSxS\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.1697_none_5b402724c75d80d6\MsoIrmProtector.doc
- C:\Windows\SysWOW64\MSDRM\MsoIrmProtector.doc
- C:\Windows\System32\MSDRM\MsoIrmProtector.ppt
- C:\Windows\WinSxS\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.5830_none_6579d6f2fbd323de\MsoIrmProtector.ppt
- C:\Windows\WinSxS\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.1697_none_6594d176fbbe42d1\MsoIrmProtector.ppt
- C:\Windows\WinSxS\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.5830_none_5b252ca0c77261e3\MsoIrmProtector.ppt
- C:\Windows\WinSxS\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.1697_none_5b402724c75d80d6\MsoIrmProtector.ppt
- C:\Windows\SysWOW64\MSDRM\MsoIrmProtector.ppt
- C:\Users\techexcel\Desktop\Desktop Data\ADITYABILA MF_BULK_13.08.2025.xls
- C:\Users\techexcel\Desktop\Desktop Data\Client_Master190957.xls
- C:\Users\techexcel\Desktop\Desktop Data\Client_Master191306.xls
- C:\Users\techexcel\Desktop\Desktop Data\Demat Holding_11112022_030816.xls
- C:\Users\techexcel\Desktop\Desktop Data\INSTBULKCLIMPORT (3).xls
- C:\Users\techexcel\Desktop\Desktop Data\Off Market Transfer_11112022_040920.xls
- C:\Users\techexcel\Desktop\Desktop Data\Share Transactions_11112022_030929.xls
- C:\Users\techexcel\Documents\459_20052025185939.xls
- C:\Users\techexcel\Downloads\101101113205_29052025113209.xls
- C:\Users\techexcel\Downloads\101121134059_02012026134059.xls
- C:\Users\techexcel\Downloads\1222180359_05012026180400.xls
- C:\Users\techexcel\Downloads\2002_03112025162641.xls
- C:\Users\techexcel\Downloads\2188_20012024_12022372904830_TECHEXCEL.xls
- C:\Users\techexcel\Downloads\519_1400_06092024154112.xls
- C:\Users\techexcel\Downloads\519_1400_06092024155147.xls
- C:\Users\techexcel\Downloads\519_30082024104247.xls
- C:\Users\techexcel\Downloads\519_30082024104433.xls
- C:\Users\techexcel\Downloads\666130328_15042025130328.xls
- C:\Users\techexcel\Downloads\666193915_11062024193915.xls
- C:\Users\techexcel\Downloads\704_13032025160829.xls
- C:\Users\techexcel\Downloads\79_17092025_0956437483837725379_TECHEXCEL.xls
- C:\Users\techexcel\Downloads\960_08042025_04571965767822771431_TECHEXCEL.xls
- C:\Users\techexcel\Downloads\960_08042025_05050694716057804514_TECHEXCEL.xls
- C:\Users\techexcel\Downloads\D__Techexcel___ExportData.xls
- C:\Users\techexcel\Downloads\Holding_23072025.xls
- C:\Users\techexcel\Downloads\NinstDashboard03032025054240.xls
- C:\Users\techexcel\Downloads\NinstDashboard03032025062248.xls
- C:\Users\techexcel\Downloads\NinstDashboard03032025062329.xls
- C:\Users\techexcel\Downloads\NinstDashboard05032025112511.xls
- C:\Users\techexcel\Downloads\NinstDashboard05032025112642.xls
- C:\Users\techexcel\Downloads\NinstDashboard05032025112758.xls
- C:\Users\techexcel\Downloads\NinstDashboard05032025113614.xls
- C:\Users\techexcel\Downloads\NinstDashboard05032025113958.xls
- C:\Users\techexcel\Downloads\NinstDashboard06032025040545.xls
- C:\Users\techexcel\Downloads\NinstDashboard06032025040919.xls
- C:\Users\techexcel\Downloads\NinstDashboard06032025041154.xls
- C:\Users\techexcel\Downloads\NinstDashboard06032025045822.xls
- C:\Users\techexcel\Downloads\NinstDashboard27022025071846.xls
- C:\Users\techexcel\Downloads\PennyDrop_113224.xls
- C:\Users\techexcel\Downloads\PennyDrop_123419.xls
- C:\Users\techexcel\Downloads\PennyDrop_123548.xls
- C:\Users\techexcel\Downloads\Trade Summary with Exp_05122023_024111.xls
- C:\Users\techexcel\Downloads\Trade Summary with Exp_05122023_024437.xls
- C:\Windows\System32\MSDRM\MsoIrmProtector.xls
- C:\Windows\WinSxS\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.5830_none_6579d6f2fbd323de\MsoIrmProtector.xls
- C:\Windows\WinSxS\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.1697_none_6594d176fbbe42d1\MsoIrmProtector.xls
- C:\Windows\WinSxS\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.5830_none_5b252ca0c77261e3\MsoIrmProtector.xls
- C:\Windows\WinSxS\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.17763.1697_none_5b402724c75d80d6\MsoIrmProtector.xls
- C:\Windows\SysWOW64\MSDRM\MsoIrmProtector.xls
- C:\Users\techexcel\Downloads\PennyDrop_112516.xls
- C:\Users\techexcel\Downloads\PennyDrop_042102.xls
- C:\Users\techexcel\Downloads\NinstDashboard28022025124546.xls
- C:\Users\techexcel\Downloads\NinstDashboard28022025042115.xls
- C:\Users\techexcel\Downloads\NinstDashboard27082024120528.xls
- C:\Users\techexcel\Downloads\NinstDashboard27022025073114.xls
- C:\Users\techexcel\Downloads\NinstDashboard05032025120103.xls
- C:\Users\techexcel\Downloads\NinstDashboard05032025115621.xls
- C:\Users\techexcel\Downloads\NinstDashboard05032025115337.xls
- C:\Users\techexcel\Downloads\NinstDashboard05032025114332.xls
- C:\Users\techexcel\Downloads\NinstDashboard05032025114243.xls
- C:\Users\techexcel\Downloads\NinstDashboard05032025112114.xls
- C:\Users\techexcel\Downloads\NinstDashboard05032025110939.xls
- C:\Users\techexcel\Downloads\NinstDashboard04032025065040.xls
- C:\Users\techexcel\Downloads\NinstDashboard04032025063256.xls
- C:\Users\techexcel\Downloads\NinstDashboard04032025061324.xls
- C:\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit.xlsx.xls
- C:\Users\techexcel\Downloads\CLIENTMASTEREXPORT_21112025185238.xls
- C:\Users\techexcel\Downloads\CLIENTMASTEREXPORT_16042025115932.xls
- C:\Users\techexcel\Downloads\auditlog_09042025143956.xls
- C:\Users\techexcel\Downloads\auditlog_09042025143929.xls
- C:\Users\techexcel\Downloads\666192826_11062024192826.xls
- C:\Users\techexcel\Downloads\666153435_16042025153503.xls
- C:\Users\techexcel\Downloads\666131614_15042025131615.xls
- C:\Users\techexcel\Downloads\666131426_15042025131426.xls
- C:\Users\techexcel\Downloads\666130643_15042025130644.xls
- C:\Users\techexcel\Downloads\31072023052606\BSE_20230731.xls
- C:\Users\techexcel\Downloads\29072023052629\BSE_20230728.xls
- C:\Users\techexcel\Downloads\287_16122024_07331423372054843612_TECHEXCEL.xls
- C:\Users\techexcel\Downloads\25062025125017.xls
- C:\Users\techexcel\Downloads\25062025124839.xls
- C:\Users\techexcel\Downloads\101101112441_29052025112446.xls
- C:\Users\techexcel\Downloads\101101110228_29052025110240.xls
- C:\Users\techexcel\Downloads\10000010_01022024135653.xls
- C:\Users\techexcel\Downloads\10000010_01022024132846.xls
- C:\Users\techexcel\Downloads\09092025192316.xls
- C:\Users\techexcel\Desktop\Desktop Data\DEBARRED ENTRY LIST.xls
- C:\Users\techexcel\Desktop\Desktop Data\CrtsSCRIPSUPLOAD.xls
- C:\Users\techexcel\Desktop\Desktop Data\CRTSScripfile1.xls
- C:\Users\techexcel\Desktop\Desktop Data\CRTSScripfile.xls
- C:\Users\techexcel\Desktop\Desktop Data\Client_Master195538.xls
- C:\Users\techexcel\Desktop\Desktop Data\BRACNH_STATUS (1).xlsx
- C:\Users\techexcel\Desktop\Desktop Data\CRTS code (1).xlsx
- C:\Users\techexcel\Desktop\Desktop Data\Test.xlsx
- C:\Users\techexcel\Desktop\Desktop Data\Web Alloc0635.xlsx
- C:\Users\techexcel\Documents\Direct_to_party.xlsx
- C:\Users\techexcel\Documents\Party_to_direct.xlsx
- C:\Users\techexcel\Documents\Web Alloc0635.xlsx
- C:\Users\techexcel\Downloads\getxl (1).xlsx
- C:\Users\techexcel\Downloads\getxl (2).xlsx
- C:\Users\techexcel\Downloads\getxl (3).xlsx
- C:\Users\techexcel\Downloads\getxl (4).xlsx
- C:\Users\techexcel\Downloads\getxl (5).xlsx
- C:\Users\techexcel\Downloads\Sms_Template (1).xlsx
- C:\Users\techexcel\Downloads\Sms_Template.xlsx
- C:\Users\techexcel\Downloads\Web Alloc0635.xlsx
- C:\Users\techexcel\Downloads\xlsx_10000010_techexcel_01022024_01275593108538802003.xlsx
- C:\Users\techexcel\Downloads\xlsx_10000010_techexcel_01022024_0156124643102910740.xlsx
- C:\Users\techexcel\Downloads\xlsx_101121172254_techexcel_09012026_05225458828719577002.xlsx
- C:\Users\techexcel\Downloads\xlsx_666151055_techexcel_22042025_03105721362753370308.xlsx
- C:\Users\techexcel\Downloads\xlsx_666131256_techexcel_15042025_01125719661865389989.xlsx
- C:\Users\techexcel\Downloads\xlsx_666130843_techexcel_15042025_01084343282893953413.xlsx
- C:\Users\techexcel\Downloads\xlsx_666130722_techexcel_15042025_01072391994683639289.xlsx
- C:\Users\techexcel\Downloads\xlsx_666130255_techexcel_15042025_01025559577721308998.xlsx
- C:\Users\techexcel\Downloads\SearchResults (86).xlsx
- C:\Users\techexcel\Downloads\SearchResults (77).xlsx
- C:\Users\techexcel\Downloads\SearchResults (67).xlsx
- C:\Users\techexcel\Downloads\hdfcDP.xlsx
- C:\Users\techexcel\Downloads\hdfcDP (1).xlsx
- C:\Users\techexcel\Downloads\getxl.xlsx
- C:\Users\techexcel\Downloads\CRTS.xlsx
- C:\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\~$CC_Limit.xlsx
- C:\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit.xlsx
- C:\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\Help.xlsx
- C:\Users\techexcel\Downloads\BRACNH_STATUS (1).xlsx
- C:\Users\techexcel\Desktop\Desktop Data\TEST LKP.xlsx
- C:\Users\techexcel\Desktop\Desktop Data\Sms_Template.xlsx
- C:\Users\techexcel\Desktop\Desktop Data\hdfcDP.xlsx
- C:\Users\techexcel\Desktop\Desktop Data\dp_debit.xlsx
- C:\Users\techexcel\Desktop\Desktop Data\CRTS.xlsx
- C:\Program Files (x86)\Microsoft SQL Server Management Studio 18\Licenses\1033\SSMS License Terms.docx
- C:\Users\techexcel\Downloads\client_limit\patch update.docx
- C:\Users\techexcel\Desktop\Desktop Data\Email Template for Margin Statement.docx
- C:\Users\techexcel\Desktop\Desktop Data\Email Template for Contract Note.docx
- C:\Users\techexcel\Desktop\Desktop Data\brs_123 (1).docx
- C:\Program Files (x86)\Microsoft SQL Server Management Studio 18\Licenses\Third Party Notices SQL Server.docx
11777 - Microsoft Windows SMB Share Hosting Possibly Copyrighted Material
-
Synopsis
The remote host may contain material (movies/audio) infringing copyright.
Description
This plugin displays a list of media files (such as .mp3, .ogg, .mpg, .avi) which have been found on the remote SMB shares.

Some of these files may contain copyrighted materials, such as commercial movies or music files, that are being shared without the owner's permission.

If any of these files actually contain copyrighted material, and if they are freely swapped around, your organization might be held liable for copyright infringement by associations such as the RIAA or the MPAA.
Solution
Delete the files infringing copyright.
Risk Factor
None
Plugin Information
Published: 2003/06/26, Modified: 2012/11/29
Plugin Output

tcp/445/cifs


Here is a list of files which have been found on the remote SMB shares.
Some of these files may contain copyrighted materials, such as commercial
movies or music files.

+ C$ :

C:\P64606_001_gen10spp-2023.09.00.00-SPP2023090000.2023_0902.19\packages\assets\media\notify.mp3
C:\Program Files\Azure Data Studio\resources\app\out\vs\platform\audioCues\browser\media\break.mp3
C:\Program Files\Azure Data Studio\resources\app\out\vs\platform\audioCues\browser\media\chatRequestSent.mp3
C:\Program Files\Azure Data Studio\resources\app\out\vs\platform\audioCues\browser\media\diffLineDeleted.mp3
C:\Program Files\Azure Data Studio\resources\app\out\vs\platform\audioCues\browser\media\diffLineInserted.mp3
C:\Program Files\Azure Data Studio\resources\app\out\vs\platform\audioCues\browser\media\diffLineModified.mp3
C:\Program Files\Azure Data Studio\resources\app\out\vs\platform\audioCues\browser\media\error.mp3
C:\Program Files\Azure Data Studio\resources\app\out\vs\platform\audioCues\browser\media\foldedAreas.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\accessibilitySignal\browser\media\break.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\accessibilitySignal\browser\media\chatEditModifiedFile.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\accessibilitySignal\browser\media\chatUserActionRequired.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\accessibilitySignal\browser\media\clear.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\accessibilitySignal\browser\media\codeActionApplied.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\accessibilitySignal\browser\media\editsUndone.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\accessibilitySignal\browser\media\error.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\accessibilitySignal\browser\media\foldedAreas.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\accessibilitySignal\browser\media\format.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\accessibilitySignal\browser\media\nextEditSuggestion.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\accessibilitySignal\browser\media\responseReceived3.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\accessibilitySignal\browser\media\responseReceived4.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\accessibilitySignal\browser\media\save.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\accessibilitySignal\browser\media\success.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\accessibilitySignal\browser\media\taskCompleted.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\accessibilitySignal\browser\media\warning.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\_\resources\app\out\vs\platform\accessibilitySignal\browser\media\break.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\_\resources\app\out\vs\platform\accessibilitySignal\browser\media\chatEditModifiedFile.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\_\resources\app\out\vs\platform\accessibilitySignal\browser\media\chatUserActionRequired.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\_\resources\app\out\vs\platform\accessibilitySignal\browser\media\clear.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\_\resources\app\out\vs\platform\accessibilitySignal\browser\media\editsKept.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\_\resources\app\out\vs\platform\accessibilitySignal\browser\media\editsUndone.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\_\resources\app\out\vs\platform\accessibilitySignal\browser\media\error.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\_\resources\app\out\vs\platform\accessibilitySignal\browser\media\foldedAreas.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\_\resources\app\out\vs\platform\accessibilitySignal\browser\media\format.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\_\resources\app\out\vs\platform\accessibilitySignal\browser\media\responseReceived3.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\_\resources\app\out\vs\platform\accessibilitySignal\browser\media\responseReceived4.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\_\resources\app\out\vs\platform\accessibilitySignal\browser\media\save.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\_\resources\app\out\vs\platform\accessibilitySignal\browser\media\success.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\_\resources\app\out\vs\platform\accessibilitySignal\browser\media\taskCompleted.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\_\resources\app\out\vs\platform\accessibilitySignal\browser\media\taskFailed.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\_\resources\app\out\vs\platform\accessibilitySignal\browser\media\warning.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\_\resources\app\out\vs\platform\accessibilitySignal\browser\media\voiceRecordingStopped.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\_\resources\app\out\vs\platform\accessibilitySignal\browser\media\voiceRecordingStarted.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\_\resources\app\out\vs\platform\accessibilitySignal\browser\media\terminalCommandSucceeded.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\_\resources\app\out\vs\platform\accessibilitySignal\browser\media\terminalBell.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\_\resources\app\out\vs\platform\accessibilitySignal\browser\media\responseReceived2.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\_\resources\app\out\vs\platform\accessibilitySignal\browser\media\responseReceived1.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\_\resources\app\out\vs\platform\accessibilitySignal\browser\media\requestSent.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\_\resources\app\out\vs\platform\accessibilitySignal\browser\media\quickFixes.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\_\resources\app\out\vs\platform\accessibilitySignal\browser\media\progress.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\_\resources\app\out\vs\platform\accessibilitySignal\browser\media\nextEditSuggestion.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\_\resources\app\out\vs\platform\accessibilitySignal\browser\media\diffLineModified.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\_\resources\app\out\vs\platform\accessibilitySignal\browser\media\diffLineInserted.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\_\resources\app\out\vs\platform\accessibilitySignal\browser\media\diffLineDeleted.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\_\resources\app\out\vs\platform\accessibilitySignal\browser\media\codeActionTriggered.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\_\resources\app\out\vs\platform\accessibilitySignal\browser\media\codeActionApplied.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\accessibilitySignal\browser\media\voiceRecordingStopped.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\accessibilitySignal\browser\media\voiceRecordingStarted.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\accessibilitySignal\browser\media\terminalCommandSucceeded.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\accessibilitySignal\browser\media\terminalBell.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\accessibilitySignal\browser\media\taskFailed.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\accessibilitySignal\browser\media\responseReceived2.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\accessibilitySignal\browser\media\responseReceived1.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\accessibilitySignal\browser\media\requestSent.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\accessibilitySignal\browser\media\quickFixes.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\accessibilitySignal\browser\media\progress.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\accessibilitySignal\browser\media\editsKept.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\accessibilitySignal\browser\media\diffLineModified.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\accessibilitySignal\browser\media\diffLineInserted.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\accessibilitySignal\browser\media\diffLineDeleted.mp3
C:\Users\techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\accessibilitySignal\browser\media\codeActionTriggered.mp3
C:\Program Files\Azure Data Studio\resources\app\out\vs\platform\audioCues\browser\media\warning.mp3
C:\Program Files\Azure Data Studio\resources\app\out\vs\platform\audioCues\browser\media\terminalBell.mp3
C:\Program Files\Azure Data Studio\resources\app\out\vs\platform\audioCues\browser\media\taskFailed.mp3
C:\Program Files\Azure Data Studio\resources\app\out\vs\platform\audioCues\browser\media\taskCompleted.mp3
C:\Program Files\Azure Data Studio\resources\app\out\vs\platform\audioCues\browser\media\quickFixes.mp3
C:\Program Files\Azure Data Studio\resources\app\out\vs\platform\audioCues\browser\media\chatResponseReceived4.mp3
C:\Program Files\Azure Data Studio\resources\app\out\vs\platform\audioCues\browser\media\chatResponseReceived3.mp3
C:\Program Files\Azure Data Studio\resources\app\out\vs\platform\audioCues\browser\media\chatResponseReceived2.mp3
C:\Program Files\Azure Data Studio\resources\app\out\vs\platform\audioCues\browser\media\chatResponseReceived1.mp3
C:\Program Files\Azure Data Studio\resources\app\out\vs\platform\audioCues\browser\media\chatResponsePending.mp3

60119 - Microsoft Windows SMB Share Permissions Enumeration
-
Synopsis
It was possible to enumerate the permissions of remote network shares.
Description
By using the supplied credentials, Nessus was able to enumerate the permissions of network shares. User permissions are enumerated for each network share that has a list of access control entries (ACEs).
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2012/07/25, Modified: 2022/08/11
Plugin Output

tcp/445/cifs


Share path : \\TECHE_LIVE_DB\ADMIN$
Local path : C:\Windows
Comment : Remote Admin
[*] Allow ACE for TECHE_LIVE_DB\tidua (S-1-5-21-1185746460-1788592564-4118236249-1012): 0x001200a9
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: NO
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: NO
FILE_ADD_FILE: NO
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: NO
DELETE: NO
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: NO
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: NO
FILE_CREATE_PIPE_INSTANCE: NO
FILE_WRITE_ATTRIBUTES: NO

Share path : \\TECHE_LIVE_DB\C$
Local path : C:\
Comment : Default share
[*] Allow ACE for TECHE_LIVE_DB\tidua (S-1-5-21-1185746460-1788592564-4118236249-1012): 0x001200a9
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: NO
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: NO
FILE_ADD_FILE: NO
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: NO
DELETE: NO
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: NO
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: NO
FILE_CREATE_PIPE_INSTANCE: NO
FILE_WRITE_ATTRIBUTES: NO

Share path : \\TECHE_LIVE_DB\FBACKUP$
Local path : F:\BACKUP
[*] Allow ACE for BUILTIN\Administrators (S-1-5-32-544): 0x001f01ff
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: YES
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: YES
FILE_ADD_FILE: YES
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: YES
DELETE: YES
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: YES
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: YES
FILE_CREATE_PIPE_INSTANCE: YES
FILE_WRITE_ATTRIBUTES: YES
[*] Allow ACE for Everyone (S-1-1-0): 0x001f01ff
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: YES
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: YES
FILE_ADD_FILE: YES
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: YES
DELETE: YES
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: YES
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: YES
FILE_CREATE_PIPE_INSTANCE: YES
FILE_WRITE_ATTRIBUTES: YES

Share path : \\TECHE_LIVE_DB\NewBackup
Local path : F:\NewBackup
[*] Allow ACE for BUILTIN\Administrators (S-1-5-32-544): 0x001f01ff
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: YES
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: YES
FILE_ADD_FILE: YES
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: YES
DELETE: YES
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: YES
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: YES
FILE_CREATE_PIPE_INSTANCE: YES
FILE_WRITE_ATTRIBUTES: YES
[*] Allow ACE for Everyone (S-1-1-0): 0x001f01ff
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: YES
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: YES
FILE_ADD_FILE: YES
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: YES
DELETE: YES
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: YES
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: YES
FILE_CREATE_PIPE_INSTANCE: YES
FILE_WRITE_ATTRIBUTES: YES

Share path : \\TECHE_LIVE_DB\Reports
Local path : D:\Techexcel\Lucee\tomcat\webapps\ROOT\Reports
[*] Allow ACE for TECHE_LIVE_DB\Techrobot (S-1-5-21-1185746460-1788592564-4118236249-1005): 0x001200a9
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: NO
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: NO
FILE_ADD_FILE: NO
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: NO
DELETE: NO
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: NO
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: NO
FILE_CREATE_PIPE_INSTANCE: NO
FILE_WRITE_ATTRIBUTES: NO

Share path : \\TECHE_LIVE_DB\TEBACKUP
Local path : F:\BACKUP
Comment : TEBACKUP
[*] Allow ACE for Everyone (S-1-1-0): 0x001200a9
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: NO
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: NO
FILE_ADD_FILE: NO
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: NO
DELETE: NO
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: NO
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: NO
FILE_CREATE_PIPE_INSTANCE: NO
FILE_WRITE_ATTRIBUTES: NO

Share path : \\TECHE_LIVE_DB\TechESignDoc
Local path : D:\Techexcel\TechESignDoc
[*] Allow ACE for Everyone (S-1-1-0): 0x001f01ff
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: YES
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: YES
FILE_ADD_FILE: YES
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: YES
DELETE: YES
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: YES
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: YES
FILE_CREATE_PIPE_INSTANCE: YES
FILE_WRITE_ATTRIBUTES: YES

Share path : \\TECHE_LIVE_DB\Techexcel$
Local path : D:\Techexcel
[*] Allow ACE for BUILTIN\Administrators (S-1-5-32-544): 0x001f01ff
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: YES
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: YES
FILE_ADD_FILE: YES
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: YES
DELETE: YES
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: YES
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: YES
FILE_CREATE_PIPE_INSTANCE: YES
FILE_WRITE_ATTRIBUTES: YES
[*] Allow ACE for Everyone (S-1-1-0): 0x001f01ff
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: YES
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: YES
FILE_ADD_FILE: YES
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: YES
DELETE: YES
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: YES
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: YES
FILE_CREATE_PIPE_INSTANCE: YES
FILE_WRITE_ATTRIBUTES: YES

Share path : \\TECHE_LIVE_DB\Techexcel_DP
Local path : D:\Techexcel_DP
[*] Allow ACE for TECHE_LIVE_DB\techexcel (S-1-5-21-1185746460-1788592564-4118236249-1001): 0x001f01ff
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: YES
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: YES
FILE_ADD_FILE: YES
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: YES
DELETE: YES
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: YES
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: YES
FILE_CREATE_PIPE_INSTANCE: YES
FILE_WRITE_ATTRIBUTES: YES
[*] Allow ACE for TECHE_LIVE_DB\techapp (S-1-5-21-1185746460-1788592564-4118236249-1002): 0x001f01ff
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: YES
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: YES
FILE_ADD_FILE: YES
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: YES
DELETE: YES
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: YES
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: YES
FILE_CREATE_PIPE_INSTANCE: YES
FILE_WRITE_ATTRIBUTES: YES
[*] Allow ACE for TECHE_LIVE_DB\Techrobot (S-1-5-21-1185746460-1788592564-4118236249-1005): 0x001f01ff
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: YES
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: YES
FILE_ADD_FILE: YES
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: YES
DELETE: YES
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: YES
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: YES
FILE_CREATE_PIPE_INSTANCE: YES
FILE_WRITE_ATTRIBUTES: YES

Share path : \\TECHE_LIVE_DB\UAT Backup$
Local path : G:\UAT Backup
[*] Allow ACE for TECHE_LIVE_DB\Production (S-1-5-21-1185746460-1788592564-4118236249-500): 0x001f01ff
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: YES
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: YES
FILE_ADD_FILE: YES
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: YES
DELETE: YES
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: YES
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: YES
FILE_CREATE_PIPE_INSTANCE: YES
FILE_WRITE_ATTRIBUTES: YES
[*] Allow ACE for TECHE_LIVE_DB\techexcel (S-1-5-21-1185746460-1788592564-4118236249-1001): 0x001f01ff
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: YES
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: YES
FILE_ADD_FILE: YES
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: YES
DELETE: YES
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: YES
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: YES
FILE_CREATE_PIPE_INSTANCE: YES
FILE_WRITE_ATTRIBUTES: YES
[*] Allow ACE for TECHE_LIVE_DB\techapp (S-1-5-21-1185746460-1788592564-4118236249-1002): 0x001f01ff
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: YES
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: YES
FILE_ADD_FILE: YES
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: YES
DELETE: YES
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: YES
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: YES
FILE_CREATE_PIPE_INSTANCE: YES
FILE_WRITE_ATTRIBUTES: YES

Share path : \\TECHE_LIVE_DB\Upload$
Local path : D:\Techexcel\Upload
[*] Allow ACE for TECHE_LIVE_DB\techapp (S-1-5-21-1185746460-1788592564-4118236249-1002): 0x001f01ff
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: YES
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: YES
FILE_ADD_FILE: YES
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: YES
DELETE: YES
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: YES
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: YES
FILE_CREATE_PIPE_INSTANCE: YES
FILE_WRITE_ATTRIBUTES: YES
[*] Allow ACE for TECHE_LIVE_DB\techexcel (S-1-5-21-1185746460-1788592564-4118236249-1001): 0x001f01ff
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: YES
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: YES
FILE_ADD_FILE: YES
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: YES
DELETE: YES
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: YES
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: YES
FILE_CREATE_PIPE_INSTANCE: YES
FILE_WRITE_ATTRIBUTES: YES
[*] Allow ACE for TECHE_LIVE_DB\Techrobot (S-1-5-21-1185746460-1788592564-4118236249-1005): 0x001f01ff
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: YES
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: YES
FILE_ADD_FILE: YES
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: YES
DELETE: YES
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: YES
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: YES
FILE_CREATE_PIPE_INSTANCE: YES
FILE_WRITE_ATTRIBUTES: YES
10396 - Microsoft Windows SMB Shares Access
-
Synopsis
It is possible to access a network share.
Description
The remote has one or more Windows shares that can be accessed through the network with the given credentials.

Depending on the share rights, it may allow an attacker to read / write confidential data.
Solution
To restrict access under Windows, open Explorer, do a right click on each share, go to the 'sharing' tab, and click on 'permissions'.
Risk Factor
None
Plugin Information
Published: 2000/05/09, Modified: 2021/10/04
Plugin Output

tcp/445/cifs


The following shares can be accessed as tidua :

- ADMIN$ - (readable)
+ Content of this share :
..
ADFS
appcompat
apppatch
AppReadiness
assembly
bcastdvr
bfsvc.exe
BonCode
BonCodeAJP13.settings
Boot
bootstat.dat
Branding
CbsTemp
Containers
CSC
Cursors
debug
DfsrAdmin.exe
DfsrAdmin.exe.config
diagnostics
DigitalLocker
Downloaded Program Files
drivers
DtcInstall.log
ELAMBKUP
en-US
explorer.exe
Fonts
Globalization
Help
HelpPane.exe
hh.exe
IdentityCRL
iis.log
IME
ImmersiveControlPanel
INF
InputMethod
Installer
L2Schemas
LiveKernelReports
Logs
lsasetup.log
media
mib.bin
Microsoft.NET
Migration
ModemLogs
notepad.exe
OCR
Offline Web Pages
Panther
Performance
PFRO.log
PLA
PolicyDefinitions
Prefetch
PrintDialog
Provisioning
regedit.exe
Registration
RemotePackages
rescache
Resources
SchCache
schemas
security
ServerDataCenter.xml
ServiceProfiles
ServiceState
servicing
Setup
setuperr.log
ShellComponents
ShellExperiences
SKB
SoftwareDistribution
Speech
Speech_OneCore
splwow64.exe
storelibdebug.txt
System
system.ini
System32
SystemApps
SystemResources
SystemTemp
SysWOW64
TAPI
Tasks
TechexcelNewAppBackup

- TechESignDoc - (readable,writable)
+ Content of this share :
..
40DP37U.361785
a
Deleted
Fail
Images
Log
Outbox
Outbox_PDF
POP.txt
Sentitems
Signature
ZipDocument

- Techexcel$ - (readable,writable)
+ Content of this share :
..
11Capture.JPG
Account ledgers.xlsx
ACTIVE_AP_LIST_WITH_MOBILE__EMAIL___ADDRESS (1).xlsx
all exchange active ap data with address_tech excel.xlsx
AP LIST WITH ZONE CODE_17082023.xlsx
AP TERMINATION lIST.xlsx
ap3595.xlsx
AP4952---1.csv
AP49521.csv
AP4991.csv
AP4995.csv
Authorised Person List _Tech Excel Closure (1).xlsx
Auto Delv_old
AutoDelivery.log
AutoImport
AutoPayinBatch
Auto_Delivery
Backoffice_TechexcelAPI_Application_Restart.bat
Backup
Backup_VAPT
Backup_Web.txtx
BadVariable.txt
BANK_clientlist.txt
Batch
BESTDATA
BoltPlusData
BRACNH_STATUS.xlsx
BranchFTP
BRANCHLIMIT
BRANCH_CODE_update.csv
BSE AP file (3).xlsx
BSE_CASHBillParams.txt
BSE_Terminal
BSE_UCC
Capture.JPG
ChequeImages
ChromeProfiles
CKYC
ClientMasterApi
ClientMasterImages
ClientMasterImages_Mod
ClientReport
Clone_DB
COMMUCC
Contract
conversion
Copy of Book3 (2).xlsx
Copy of SLBM_AP ACTIVATION lIST as per tech excel.xlsx
CopyAppToC.bat
cr
ctcl.TXT
CU1admin.00048
CU1admin.00050
CU1admin.00051
CU1admin.00053
CU1admin.00054

- TEBACKUP - (readable)
+ Content of this share :
..
Arbitrage.ZIP
Backup_Local_Log.txt
CAPSFO.BAK
classes.ZIP
Depository.BAK
DEPOSITORY.ZIP
FOCAPS.ZIP
FTPDOWNLOAD.ZIP
KRA.ZIP
KYC.ZIP
LiveRisk.ZIP
Lucee_logs.ZIP
master_01.03.2025.bak
NBFC.ZIP
ODBC.ZIP
SIGNATUREFILES.ZIP
StaticData.ZIP
TechArb.ZIP
TechESign.ZIP
TechESignDoc_Signature.ZIP
techexcelapi.ZIP
techinx.ZIP
TechMsg.ZIP
TechMsg_New.ZIP
techRPA.ZIP
TechRPA_DB.BAK
webclient.ZIP
weblogin.ZIP

- NewBackup - (readable,writable)
+ Content of this share :
..
API-PATH 08032025

- FBACKUP$ - (readable,writable)
+ Content of this share :
..
Arbitrage.ZIP
Backup_Local_Log.txt
CAPSFO.BAK
classes.ZIP
Depository.BAK
DEPOSITORY.ZIP
FOCAPS.ZIP
FTPDOWNLOAD.ZIP
KRA.ZIP
KYC.ZIP
LiveRisk.ZIP
Lucee_logs.ZIP
master_01.03.2025.bak
NBFC.ZIP
ODBC.ZIP
SIGNATUREFILES.ZIP
StaticData.ZIP
TechArb.ZIP
TechESign.ZIP
TechESignDoc_Signature.ZIP
techexcelapi.ZIP
techinx.ZIP
TechMsg.ZIP
TechMsg_New.ZIP
techRPA.ZIP
TechRPA_DB.BAK
webclient.ZIP
weblogin.ZIP

- C$ - (readable)
+ Content of this share :
Backup
CDSL_PhysicalShare
cpqsystem
Documents and Settings
ExportFiles
iMPORTTRADEFILES
inetpub
lucee
P64606_001_gen10spp-2023.09.00.00-SPP2023090000.2023_0902.19
pagefile.sys
PerfLogs
Program Files
Program Files (x86)
ProgramData
Railo
Recovery
Reports
SW_DVD9_Win_Server_STD_CORE_2019_1809.18_64Bit_English_DC_STD_MLF_X22-74330.ISO
System Volume Information
temp
Users
Windows
10395 - Microsoft Windows SMB Shares Enumeration
-
Synopsis
It is possible to enumerate remote network shares.
Description
By connecting to the remote host, Nessus was able to enumerate the network share names.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2000/05/09, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Here are the SMB shares available on the remote host when logged in as tidua:

- ADMIN$
- C$
- FBACKUP$
- IPC$
- NewBackup
- Reports
- TEBACKUP
- TechESignDoc
- Techexcel$
- Techexcel_DP
- UAT Backup$
- Upload$
100871 - Microsoft Windows SMB Versions Supported (remote check)
-
Synopsis
It was possible to obtain information about the version of SMB running on the remote host.
Description
Nessus was able to obtain the version of SMB running on the remote host by sending an authentication request to port 139 or 445.

Note that this plugin is a remote check and does not work on agents.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2017/06/19, Modified: 2019/11/22
Plugin Output

tcp/445/cifs


The remote host supports the following versions of SMB :
SMBv2
106716 - Microsoft Windows SMB2 and SMB3 Dialects Supported (remote check)
-
Synopsis
It was possible to obtain information about the dialects of SMB2 and SMB3 available on the remote host.
Description
Nessus was able to obtain the set of SMB2 and SMB3 dialects running on the remote host by sending an authentication request to port 139 or 445.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2018/02/09, Modified: 2020/03/11
Plugin Output

tcp/445/cifs


The remote host supports the following SMB dialects :
_version_ _introduced in windows version_
2.0.2 Windows 2008
2.1 Windows 7
3.0 Windows 8
3.0.2 Windows 8.1
3.1.1 Windows 10

The remote host does NOT support the following SMB dialects :
_version_ _introduced in windows version_
2.2.2 Windows 8 Beta
2.2.4 Windows 8 Beta
3.1 Windows 10

92368 - Microsoft Windows Scripting Host Settings
-
Synopsis
Nessus was able to collect and report the Windows scripting host settings from the remote host.
Description
Nessus was able to collect system and user level Windows scripting host settings from the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings\displaylogo : 1
HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings\usewinsafer : 1
HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings\silentterminate : 0
HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings\activedebugging : 1
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\displaylogo : 1
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\usewinsafer : 1
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\silentterminate : 0
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\activedebugging : 1

Windows scripting host configuration attached.

200493 - Microsoft Windows Start Menu Software Version Enumeration
-
Synopsis
Enumerates Start Menu software versions.
Description
This plugin enumerates the installed software version by interrogating information obtained from various registry entries and files on disk. This plugin provides a best guess at the software version and a confidence level for that version.

Note that the versions detected here do not necessarily indicate the actual installed version nor do they necessarily mean that the application is actually installed on the remote host. In some cases there may be artifacts left behind by uninstallers on the system.
Solution
Remove any applications that are not compliant with your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2024/06/13, Modified: 2025/12/15
Plugin Output

tcp/445/cifs

The following software information is available on the remote host :

- Google Chrome.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Google Chrome.lnk
Target : C:\Program Files\Google\Chrome\Application\chrome.exe
Version : 143.0.7499.170

- Immersive Control Panel.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Immersive Control Panel.lnk
Target : C:\Windows\System32\Control.exe
Version : 10.0.17763.2300

- Microsoft Edge.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Edge.lnk
Target : C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
Version : 143.0.3650.96

- Notepad++.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Notepad++.lnk
Target : C:\Program Files\Notepad++\notepad++.exe
Version : 8.7.7.0

- Server Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Server Manager.lnk
Target : C:\Windows\system32\ServerManager.exe
Version : 10.0.17763.168

- 7-Zip File Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\7-Zip\7-Zip File Manager.lnk
Target : C:\Program Files\7-Zip\7zFM.exe
Version : 24.9.0.0

- 7-Zip Help.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\7-Zip\7-Zip Help.lnk
Target : C:\Program Files\7-Zip\7-zip.chm
Version : unknown

- Speech Recognition.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessibility\Speech Recognition.lnk
Target : C:\Windows\Speech\Common\sapisvr.exe
Version : 5.3.22514.0

- Calculator.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Calculator.lnk
Target : C:\Windows\system32\win32calc.exe
Version : 10.0.17763.4377

- Math Input Panel.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Math Input Panel.lnk
Target : C:\Program Files\Common Files\Microsoft Shared\Ink\mip.exe
Version : 10.0.17763.1697

- Paint.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Paint.lnk
Target : C:\Windows\system32\mspaint.exe
Version : 10.0.17763.1697

- Remote Desktop Connection.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Remote Desktop Connection.lnk
Target : C:\Windows\system32\mstsc.exe
Version : 10.0.17763.5830

- Snipping Tool.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Snipping Tool.lnk
Target : C:\Windows\system32\SnippingTool.exe
Version : 10.0.17763.1697

- Steps Recorder.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Steps Recorder.lnk
Target : C:\Windows\system32\psr.exe
Version : 10.0.17763.1697

- Windows Media Player.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Windows Media Player.lnk
Target : C:\Program Files (x86)\Windows Media Player\wmplayer.exe
Version : 12.0.17763.5830

- Wordpad.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Wordpad.lnk
Target : C:\Program Files\Windows NT\Accessories\wordpad.exe
Version : 10.0.17763.5328

- XPS Viewer.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\XPS Viewer.lnk
Target : C:\Windows\system32\xpsrchvw.exe
Version : 10.0.17763.5830

- Character Map.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\System Tools\Character Map.lnk
Target : C:\Windows\system32\charmap.exe
Version : 5.2.3668.0

- Windows Server Backup.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\System Tools\Windows Server Backup.lnk
Target : C:\Windows\system32\wbadmin.msc
Version : unknown

- Acronis Cyber Protect Monitor.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Acronis\Acronis Cyber Protect Monitor.lnk
Target : C:\Program Files\BackupClient\TrayMonitor\MmsMonitor.exe
Version : 24.11.1008.0

- Acronis System Report.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Acronis\Acronis System Report.lnk
Target : C:\Program Files\Common Files\Acronis\AdvReport\systeminfo.exe
Version : 24.11.1.39130

- Component Services.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Component Services.lnk
Target : C:\Windows\system32\comexp.msc
Version : unknown

- Computer Management.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Computer Management.lnk
Target : C:\Windows\system32\compmgmt.msc
Version : unknown

- dfrgui.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\dfrgui.lnk
Target : C:\Windows\system32\dfrgui.exe
Version : 10.0.17763.1697

- Disk Cleanup.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Disk Cleanup.lnk
Target : C:\Windows\system32\cleanmgr.exe
Version : 10.0.17763.6893

- Event Viewer.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Event Viewer.lnk
Target : C:\Windows\system32\eventvwr.msc
Version : unknown

- IIS Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\IIS Manager.lnk
Target : C:\Windows\system32\inetsrv\InetMgr.exe
Version : 10.0.17763.5830

- iSCSI Initiator.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\iSCSI Initiator.lnk
Target : C:\Windows\system32\iscsicpl.exe
Version : 10.0.17763.1

- Memory Diagnostics Tool.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Memory Diagnostics Tool.lnk
Target : C:\Windows\system32\MdSched.exe
Version : 10.0.17763.1

- Microsoft Azure services.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Microsoft Azure services.lnk
Target : C:\Windows\explorer.exe
Version : 10.0.17763.6530

- ODBC Data Sources (32-bit).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\ODBC Data Sources (32-bit).lnk
Target : C:\Windows\syswow64\odbcad32.exe
Version : 10.0.17763.1

- ODBC Data Sources (64-bit).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\ODBC Data Sources (64-bit).lnk
Target : C:\Windows\system32\odbcad32.exe
Version : 10.0.17763.1

- Performance Monitor.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Performance Monitor.lnk
Target : C:\Windows\system32\perfmon.msc
Version : unknown

- Print Management.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Print Management.lnk
Target : C:\Windows\system32\printmanagement.msc
Version : unknown

- RecoveryDrive.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\RecoveryDrive.lnk
Target : C:\Windows\system32\RecoveryDrive.exe
Version : 10.0.17763.7009

- Registry Editor.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Registry Editor.lnk
Target : C:\Windows\regedit.exe
Version : 10.0.17763.1697

- Resource Monitor.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Resource Monitor.lnk
Target : C:\Windows\system32\perfmon.exe
Version : 10.0.17763.5830

- Security Configuration Management.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Security Configuration Management.lnk
Target : C:\Windows\system32\secpol.msc
Version : unknown

- Server Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Server Manager.lnk
Target : C:\Windows\system32\ServerManager.exe
Version : 10.0.17763.168

- services.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\services.lnk
Target : C:\Windows\system32\services.msc
Version : unknown

- System Configuration.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\System Configuration.lnk
Target : C:\Windows\system32\msconfig.exe
Version : 10.0.17763.2061

- System Information.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\System Information.lnk
Target : C:\Windows\system32\msinfo32.exe
Version : 10.0.17763.5830

- Task Scheduler.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Task Scheduler.lnk
Target : C:\Windows\system32\taskschd.msc
Version : unknown

- Windows Defender Firewall with Advanced Security.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Windows Defender Firewall with Advanced Security.lnk
Target : C:\Windows\system32\WF.msc
Version : unknown

- Windows Server Backup.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Windows Server Backup.lnk
Target : C:\Windows\system32\wbadmin.msc
Version : unknown

- Azure Data Studio.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Azure Data Studio\Azure Data Studio.lnk
Target : C:\Program Files\Azure Data Studio\azuredatastudio.exe
Version : 1.51.1.0

- Git Bash.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Git\Git Bash.lnk
Target : C:\Program Files\Git\git-bash.exe
Version : 2.47.1.2

- Git CMD.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Git\Git CMD.lnk
Target : C:\Program Files\Git\git-cmd.exe
Version : 2.47.1.2

- Git GUI.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Git\Git GUI.lnk
Target : C:\Program Files\Git\cmd\git-gui.exe
Version : 2.47.1.2

- Git Release Notes.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Git\Git Release Notes.lnk
Target : C:\Program Files\Git\ReleaseNotes.html
Version : unknown

- HPE Lights-Out Online Configuration Utility.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\HPE System Tools\HPE Lights-Out Online Configuration Utility\HPE Lights-Out Online Configuration Utility.lnk
Target : C:\Windows\Installer\{452BFA2A-7E5A-46CE-B045-3B9834B419D5}\icon.ico
Version : unknown

- README.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\HPE System Tools\HPE Lights-Out Online Configuration Utility\README.lnk
Target :
Version : unknown

- iReport-5.5.0.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Jaspersoft\iReport-5.5.0\iReport-5.5.0.lnk
Target : C:\Program Files (x86)\Jaspersoft\iReport-5.5.0\bin\ireport.exe
Version : unknown

- Uninstall.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Jaspersoft\iReport-5.5.0\Uninstall.lnk
Target : C:\Program Files (x86)\Jaspersoft\iReport-5.5.0\uninst.exe
Version : unknown

- About Java.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Java\About Java.lnk
Target : C:\Program Files\Java\jre1.8.0_161\bin\javacpl.exe
Version : 11.161.2.12

- Check For Updates.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Java\Check For Updates.lnk
Target : C:\Program Files\Java\jre1.8.0_161\bin\javacpl.exe
Version : 11.161.2.12

- Configure Java.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Java\Configure Java.lnk
Target : C:\Program Files\Java\jre1.8.0_161\bin\javacpl.exe
Version : 11.161.2.12

- Java Mission Control.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Java Development Kit\Java Mission Control.lnk
Target : C:\Program Files\Java\jdk1.8.0_161\bin\jmc.exe
Version : unknown

- Lucee-Tomcat Service Control.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Lucee\Lucee-Tomcat Service Control.lnk
Target : D:\Techexcel\lucee\tomcat\bin\Luceew.exe
Version : unknown

- Lucee-Tomcat Service Monitor.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Lucee\Lucee-Tomcat Service Monitor.lnk
Target : D:\Techexcel\lucee\tomcat\bin\Luceew.exe
Version : unknown

- Tomcat Host Config.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Lucee\Tomcat Host Config.lnk
Target : C:\Windows\system32\notepad.exe
Version : 10.0.17763.5328

- Uninstall Lucee.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Lucee\Uninstall Lucee.lnk
Target : D:\Techexcel\lucee\uninstall.exe
Version : unknown

- SQL Server 2019 Import and Export Data (64-bit).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2019\SQL Server 2019 Import and Export Data (64-bit).lnk
Target : D:\Program Files\Microsoft SQL Server\150\DTS\Binn\DTSWizard.exe
Version : unknown

- SQL Server 2019 Configuration Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2019\Configuration Tools\SQL Server 2019 Configuration Manager.lnk
Target : C:\Windows\SysWOW64\mmc.exe
Version : 10.0.17763.7009

- SQL Server 2019 Error and Usage Reporting.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2019\Configuration Tools\SQL Server 2019 Error and Usage Reporting.lnk
Target : C:\Program Files\Microsoft SQL Server\150\Shared\SqlWtsn.exe
Version : 15.0.2000.5

- SQL Server 2019 Installation Center (64-bit).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2019\Configuration Tools\SQL Server 2019 Installation Center (64-bit).lnk
Target : C:\Program Files\Microsoft SQL Server\150\Setup Bootstrap\SQL2019\x64\LandingPage.exe
Version : 15.0.4420.2

- Analysis Services Deployment Wizard 18.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server Tools 18\Analysis Services Deployment Wizard 18.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server Management Studio 18\Common7\IDE\Microsoft.AnalysisServices.Deployment.exe
Version : 15.0.19714.0

- Microsoft SQL Server Management Studio 18.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server Tools 18\Microsoft SQL Server Management Studio 18.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server Management Studio 18\Common7\IDE\Ssms.exe
Version : 2019.150.18390.0

- Database Engine Tuning Advisor 18.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server Tools 18\Performance Tools\Database Engine Tuning Advisor 18.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server Management Studio 18\Common7\DTASHELL.EXE
Version : 15.0.18390.0

- SQL Server Profiler 18.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server Tools 18\Performance Tools\SQL Server Profiler 18.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server Management Studio 18\Common7\PROFILER.EXE
Version : 2019.150.18390.0

- Oracle ODBC Help.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Oracle - OraClient11g_home1\Application Development\Oracle ODBC Help.lnk
Target : C:\Windows\hh.exe
Version : 10.0.17763.1

- Oracle Provider for OLE DB Readme.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Oracle - OraClient11g_home1\Application Development\Oracle Provider for OLE DB Readme.lnk
Target : C:\Windows\system32\notepad.exe
Version : 10.0.17763.5328

- SQL Developer.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Oracle - OraClient11g_home1\Application Development\SQL Developer.lnk
Target : D:\app\techexcel\product\11.2.0\client_1\SQLDEVELOPER\SQLDEVELOPER\BIN\SQLDEVELOPER.BAT
Version : unknown

- SQL Plus.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Oracle - OraClient11g_home1\Application Development\SQL Plus.lnk
Target : D:\app\techexcel\product\11.2.0\client_1\BIN\sqlplus.exe
Version : unknown

- Administration Assistant for Windows.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Oracle - OraClient11g_home1\Configuration and Migration Tools\Administration Assistant for Windows.lnk
Target : D:\app\techexcel\product\11.2.0\client_1\MMC Snap-Ins\ORAMMC11.exe
Version : unknown

- Microsoft ODBC Administrator.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Oracle - OraClient11g_home1\Configuration and Migration Tools\Microsoft ODBC Administrator.lnk
Target : C:\Windows\System32\odbcad32.exe
Version : 10.0.17763.1

- Net Configuration Assistant.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Oracle - OraClient11g_home1\Configuration and Migration Tools\Net Configuration Assistant.lnk
Target : D:\app\techexcel\product\11.2.0\client_1\BIN\launch.exe
Version : unknown

- Net Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Oracle - OraClient11g_home1\Configuration and Migration Tools\Net Manager.lnk
Target : D:\app\techexcel\product\11.2.0\client_1\BIN\launch.exe
Version : unknown

- OLAP Analytic Workspace Manager and Worksheet.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Oracle - OraClient11g_home1\Integrated Management Tools\OLAP Analytic Workspace Manager and Worksheet.lnk
Target : D:\app\techexcel\product\11.2.0\client_1\BIN\awm.bat
Version : unknown

- Wallet Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Oracle - OraClient11g_home1\Integrated Management Tools\Wallet Manager.lnk
Target : D:\app\techexcel\product\11.2.0\client_1\BIN\launch.exe
Version : unknown

- Universal Installer.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Oracle - OraClient11g_home1\Oracle Installation Products\Universal Installer.lnk
Target : D:\app\techexcel\product\11.2.0\client_1\oui\bin\setup.exe
Version : unknown

- Documentation.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\OSSEC\Documentation.lnk
Target :
Version : unknown

- Edit conf.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\OSSEC\Edit conf.lnk
Target : C:\Program Files (x86)\ossec-agent\ossec.conf
Version : unknown

- Manage Agent.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\OSSEC\Manage Agent.lnk
Target : C:\Program Files (x86)\ossec-agent\win32ui.exe
Version : 4.11.2.0

- Uninstall.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\OSSEC\Uninstall.lnk
Target : C:\Windows\System32\msiexec.exe
Version : 5.0.17763.4644

- VNC Address Book.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\RealVNC\VNC Address Book.lnk
Target : C:\Program Files\RealVNC\VNC4\vncaddrbook.exe
Version : 4.6.1.54321

- VNC Server.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\RealVNC\VNC Server.lnk
Target : C:\Program Files\RealVNC\VNC4\winvnc4.exe
Version : 4.6.1.54321

- VNC Viewer.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\RealVNC\VNC Viewer.lnk
Target : C:\Program Files\RealVNC\VNC4\vncviewer.exe
Version : 4.6.1.54321

- Enter VNC Server License Key.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\RealVNC\Advanced\Enter VNC Server License Key.lnk
Target : C:\Program Files\RealVNC\VNC4\vncconfig.exe
Version : 4.6.1.54321

- Start Listening VNC Viewer.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\RealVNC\Advanced\Start Listening VNC Viewer.lnk
Target : C:\Program Files\RealVNC\VNC4\vncviewer.exe
Version : 4.6.1.54321

- VNC Server (User Mode).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\RealVNC\Advanced\VNC Server (User Mode).lnk
Target : C:\Program Files\RealVNC\VNC4\winvnc4.exe
Version : 4.6.1.54321

- Task Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\System Tools\Task Manager.lnk
Target : C:\Windows\system32\taskmgr.exe
Version : 10.0.17763.2989

- README.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\System Tools\Smart Storage Administrator\README.lnk
Target : C:\Program Files\Smart Storage Administrator\ssa\README.TXT
Version : unknown

- Smart Storage Administrator Preferences.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\System Tools\Smart Storage Administrator\Smart Storage Administrator Preferences.lnk
Target : C:\Program Files\Smart Storage Administrator\ssa\bin\ssaprefs.exe
Version : 2.80.0.0

- Smart Storage Administrator.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\System Tools\Smart Storage Administrator\Smart Storage Administrator.lnk
Target : C:\Program Files\Smart Storage Administrator\ssa\bin\ssaclient.exe
Version : 3.40.3.0

- Help.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\TortoiseSVN\Help.lnk
Target : D:\Techexcel\Program Files\TortoiseSVN\bin\TortoiseProc.exe
Version : unknown

- Settings.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\TortoiseSVN\Settings.lnk
Target : D:\Techexcel\Program Files\TortoiseSVN\bin\TortoiseProc.exe
Version : unknown

- TortoiseIDiff.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\TortoiseSVN\TortoiseIDiff.lnk
Target : D:\Techexcel\Program Files\TortoiseSVN\bin\TortoiseIDiff.exe
Version : unknown

- TortoiseMerge.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\TortoiseSVN\TortoiseMerge.lnk
Target : D:\Techexcel\Program Files\TortoiseSVN\bin\TortoiseMerge.exe
Version : unknown

- TortoiseSVN Project Monitor.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\TortoiseSVN\TortoiseSVN Project Monitor.lnk
Target : D:\Techexcel\Program Files\TortoiseSVN\bin\TortoiseProc.exe
Version : unknown

- TortoiseSVN Repository Browser.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\TortoiseSVN\TortoiseSVN Repository Browser.lnk
Target : D:\Techexcel\Program Files\TortoiseSVN\bin\TortoiseProc.exe
Version : unknown

- TortoiseSVN.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\TortoiseSVN\TortoiseSVN.lnk
Target : D:\Techexcel\Program Files\TortoiseSVN\bin\TortoiseProc.exe
Version : unknown

- Website.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\TortoiseSVN\Website.lnk
Target : D:\Techexcel\Program Files\TortoiseSVN\bin\Website.url
Version : unknown

- TreeSize Free (Administrator).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\TreeSize Free\TreeSize Free (Administrator).lnk
Target : C:\Program Files (x86)\JAM Software\TreeSize Free\TreeSizeFree.exe
Version : 4.4.2.514

- TreeSize Free Help.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\TreeSize Free\TreeSize Free Help.lnk
Target : C:\Program Files (x86)\JAM Software\TreeSize Free\TreeSizeFree.chm
Version : unknown

- TreeSize Free.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\TreeSize Free\TreeSize Free.lnk
Target : C:\Program Files (x86)\JAM Software\TreeSize Free\TreeSizeFree.exe
Version : 4.4.2.514

- VisualSVN Repository Configurator.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\VisualSVN\VisualSVN Repository Configurator.lnk
Target : D:\Techexcel\Program Files\VisualSVN Server\bin\VisualSVNRepoCfg.exe
Version : unknown

- VisualSVN Server Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\VisualSVN\VisualSVN Server Manager.lnk
Target : D:\Techexcel\Program Files\VisualSVN Server\bin\VisualSVN Server.msc
Version : unknown

- VisualSVN Server PowerShell.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\VisualSVN\VisualSVN Server PowerShell.lnk
Target : D:\Techexcel\Program Files\VisualSVN Server\bin\VisualSVNServerShell.exe
Version : unknown

- User's Guide.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\WinMerge\User's Guide.lnk
Target : C:\Program Files\WinMerge\Docs\WinMerge.chm
Version : unknown

- WinMerge.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\WinMerge\WinMerge.lnk
Target : C:\Program Files\WinMerge\WinMergeU.exe
Version : 2.16.28.0

- Console RAR manual.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\WinRAR\Console RAR manual.lnk
Target : C:\Program Files\WinRAR\Rar.txt
Version : unknown

- What is new in the latest version.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\WinRAR\What is new in the latest version.lnk
Target : C:\Program Files\WinRAR\WhatsNew.txt
Version : unknown

- WinRAR help.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\WinRAR\WinRAR help.lnk
Target : C:\Program Files\WinRAR\WinRAR.chm
Version : unknown

- WinRAR.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\WinRAR\WinRAR.lnk
Target : C:\Program Files\WinRAR\WinRAR.exe
Version : 7.1.0.0
58452 - Microsoft Windows Startup Software Enumeration
-
Synopsis
It is possible to enumerate startup software.
Description
This plugin lists software that is configured to run on system startup by crawling the registry entries in :

- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersi on\Run
Solution
Review the list of applications and remove any that are not compliant with your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2012/03/23, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


The following startup item was found :

Acronis Scheduler2 Service - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
AcronisTibMounterMonitor - C:\Program Files (x86)\Common Files\Acronis\TibMounter\tib_mounter_monitor.exe
MmsMonitor.exe - C:\Program Files\BackupClient\TrayMonitor\MmsMonitor.exe
SecurityHealth - %windir%\system32\SecurityHealthSystray.exe
SunJavaUpdateSched - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
38153 - Microsoft Windows Summary of Missing Patches
-
Synopsis
The remote host is missing several Microsoft security patches.
Description
This plugin summarizes updates for Microsoft Security Bulletins or Knowledge Base (KB) security updates that have not been installed on the remote Windows host based on the results of either a credentialed check using the supplied credentials or a check done using a supported third-party patch management tool.

Note the results of missing patches also include superseded patches.

Review the summary and apply any missing updates in order to be up to date.
Solution
Run Windows Update on the remote host or use a patch management solution.
Risk Factor
None
Plugin Information
Published: 2009/04/24, Modified: 2019/06/13
Plugin Output

tcp/445/cifs

The patches for the following bulletins or KBs are missing on the remote host :

- MS09-035 ( http://technet.microsoft.com/en-us/security/bulletin/ms09-035 )
- KB5049608 ( https://support.microsoft.com/en-us/help/5049608 )
- KB5055519 ( https://support.microsoft.com/en-us/help/5055519 )
- KB5058392 ( https://support.microsoft.com/en-us/help/5058392 )
- KB5060531 ( https://support.microsoft.com/en-us/help/5060531 )
- KB5062557 ( https://support.microsoft.com/en-us/help/5062557 )
- KB5063877 ( https://support.microsoft.com/en-us/help/5063877 )
- KB5065428 ( https://support.microsoft.com/en-us/help/5065428 )
- KB5066586 ( https://support.microsoft.com/en-us/help/5066586 )
- KB5068791 ( https://support.microsoft.com/en-us/help/5068791 )
- KB5071544 ( https://support.microsoft.com/en-us/help/5071544 )

92369 - Microsoft Windows Time Zone Information
-
Synopsis
Nessus was able to collect and report time zone information from the remote host.
Description
Nessus was able to collect time zone information from the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2023/06/06
Plugin Output

tcp/0

HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\TimeZoneKeyName : India Standard Time
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\StandardName : @tzres.dll,-492
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\DaylightName : @tzres.dll,-491
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\DynamicDaylightTimeDisabled : 0x00000000
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\StandardBias : 0x00000000
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\DaylightBias : 0xFFFFFFC4
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\Bias : 0xFFFFFEB6
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\ActiveTimeBias : 0xFFFFFEB6
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\DaylightStart : 00000000000000000000000000000000
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\StandardStart : 00000000000000000000000000000000

35730 - Microsoft Windows USB Device Usage Report
-
Synopsis
It was possible to get a list of USB devices that may have been connected to the remote system in the past.
Description
Using the supplied credentials, this plugin enumerates USB devices that have been connected to the remote Windows host in the past.
See Also
Solution
Make sure that the use of USB drives is in accordance with your organization's security policy.
Risk Factor
None
Plugin Information
Published: 2009/02/24, Modified: 2022/06/01
Plugin Output

tcp/445/cifs


The following is a list of USB devices that have been connected
to remote system at least once in the past :


Device Name : Generic- SD/MMC CRW USB Device
Last Inserted Time : Jan. 4, 2026 at 16:03:49 GMT

First used : unknown

Device Name : hp x740w USB Device
Last Inserted Time : Jun. 7, 2024 at 20:30:27 GMT

First used : unknown

Device Name : SanDisk Ultra USB Device
Last Inserted Time : Jan. 7, 2022 at 18:24:26 GMT

First used : unknown

Device Name : SanDisk Ultra USB Device
Last Inserted Time : Jan. 8, 2022 at 01:03:55 GMT

First used : unknown

Device Name : Seagate Expansion USB Device
Last Inserted Time : Oct. 6, 2023 at 16:06:55 GMT

First used : unknown

Device Name : VendorCo ProductCode USB Device
Last Inserted Time : Jan. 7, 2022 at 23:01:52 GMT

First used : unknown

(Note that for a complete listing of 'First used' times you should
run this test with the option 'thorough_tests' enabled.)

11219 - Nessus SYN scanner
-
Synopsis
It is possible to determine which TCP ports are open.
Description
This plugin is a SYN 'half-open' port scanner. It shall be reasonably quick even against a firewalled target.

Note that SYN scans are less intrusive than TCP (full connect) scans against broken services, but they might cause problems for less robust firewalls and also leave unclosed connections on the remote target, if the network is loaded.
Solution
Protect your target with an IP filter.
Risk Factor
None
Plugin Information
Published: 2009/02/04, Modified: 2025/07/14
Plugin Output

tcp/80/www

Port 80/tcp was found to be open

11219 - Nessus SYN scanner
-
Synopsis
It is possible to determine which TCP ports are open.
Description
This plugin is a SYN 'half-open' port scanner. It shall be reasonably quick even against a firewalled target.

Note that SYN scans are less intrusive than TCP (full connect) scans against broken services, but they might cause problems for less robust firewalls and also leave unclosed connections on the remote target, if the network is loaded.
Solution
Protect your target with an IP filter.
Risk Factor
None
Plugin Information
Published: 2009/02/04, Modified: 2025/07/14
Plugin Output

tcp/81/www

Port 81/tcp was found to be open

11219 - Nessus SYN scanner
-
Synopsis
It is possible to determine which TCP ports are open.
Description
This plugin is a SYN 'half-open' port scanner. It shall be reasonably quick even against a firewalled target.

Note that SYN scans are less intrusive than TCP (full connect) scans against broken services, but they might cause problems for less robust firewalls and also leave unclosed connections on the remote target, if the network is loaded.
Solution
Protect your target with an IP filter.
Risk Factor
None
Plugin Information
Published: 2009/02/04, Modified: 2025/07/14
Plugin Output

tcp/135/epmap

Port 135/tcp was found to be open

11219 - Nessus SYN scanner
-
Synopsis
It is possible to determine which TCP ports are open.
Description
This plugin is a SYN 'half-open' port scanner. It shall be reasonably quick even against a firewalled target.

Note that SYN scans are less intrusive than TCP (full connect) scans against broken services, but they might cause problems for less robust firewalls and also leave unclosed connections on the remote target, if the network is loaded.
Solution
Protect your target with an IP filter.
Risk Factor
None
Plugin Information
Published: 2009/02/04, Modified: 2025/07/14
Plugin Output

tcp/139/smb

Port 139/tcp was found to be open

11219 - Nessus SYN scanner
-
Synopsis
It is possible to determine which TCP ports are open.
Description
This plugin is a SYN 'half-open' port scanner. It shall be reasonably quick even against a firewalled target.

Note that SYN scans are less intrusive than TCP (full connect) scans against broken services, but they might cause problems for less robust firewalls and also leave unclosed connections on the remote target, if the network is loaded.
Solution
Protect your target with an IP filter.
Risk Factor
None
Plugin Information
Published: 2009/02/04, Modified: 2025/07/14
Plugin Output

tcp/445/cifs

Port 445/tcp was found to be open

11219 - Nessus SYN scanner
-
Synopsis
It is possible to determine which TCP ports are open.
Description
This plugin is a SYN 'half-open' port scanner. It shall be reasonably quick even against a firewalled target.

Note that SYN scans are less intrusive than TCP (full connect) scans against broken services, but they might cause problems for less robust firewalls and also leave unclosed connections on the remote target, if the network is loaded.
Solution
Protect your target with an IP filter.
Risk Factor
None
Plugin Information
Published: 2009/02/04, Modified: 2025/07/14
Plugin Output

tcp/3389/msrdp

Port 3389/tcp was found to be open

11219 - Nessus SYN scanner
-
Synopsis
It is possible to determine which TCP ports are open.
Description
This plugin is a SYN 'half-open' port scanner. It shall be reasonably quick even against a firewalled target.

Note that SYN scans are less intrusive than TCP (full connect) scans against broken services, but they might cause problems for less robust firewalls and also leave unclosed connections on the remote target, if the network is loaded.
Solution
Protect your target with an IP filter.
Risk Factor
None
Plugin Information
Published: 2009/02/04, Modified: 2025/07/14
Plugin Output

tcp/5800/www

Port 5800/tcp was found to be open

11219 - Nessus SYN scanner
-
Synopsis
It is possible to determine which TCP ports are open.
Description
This plugin is a SYN 'half-open' port scanner. It shall be reasonably quick even against a firewalled target.

Note that SYN scans are less intrusive than TCP (full connect) scans against broken services, but they might cause problems for less robust firewalls and also leave unclosed connections on the remote target, if the network is loaded.
Solution
Protect your target with an IP filter.
Risk Factor
None
Plugin Information
Published: 2009/02/04, Modified: 2025/07/14
Plugin Output

tcp/5900/vnc

Port 5900/tcp was found to be open

11219 - Nessus SYN scanner
-
Synopsis
It is possible to determine which TCP ports are open.
Description
This plugin is a SYN 'half-open' port scanner. It shall be reasonably quick even against a firewalled target.

Note that SYN scans are less intrusive than TCP (full connect) scans against broken services, but they might cause problems for less robust firewalls and also leave unclosed connections on the remote target, if the network is loaded.
Solution
Protect your target with an IP filter.
Risk Factor
None
Plugin Information
Published: 2009/02/04, Modified: 2025/07/14
Plugin Output

tcp/5985/www

Port 5985/tcp was found to be open

11219 - Nessus SYN scanner
-
Synopsis
It is possible to determine which TCP ports are open.
Description
This plugin is a SYN 'half-open' port scanner. It shall be reasonably quick even against a firewalled target.

Note that SYN scans are less intrusive than TCP (full connect) scans against broken services, but they might cause problems for less robust firewalls and also leave unclosed connections on the remote target, if the network is loaded.
Solution
Protect your target with an IP filter.
Risk Factor
None
Plugin Information
Published: 2009/02/04, Modified: 2025/07/14
Plugin Output

tcp/6443/www

Port 6443/tcp was found to be open

11219 - Nessus SYN scanner
-
Synopsis
It is possible to determine which TCP ports are open.
Description
This plugin is a SYN 'half-open' port scanner. It shall be reasonably quick even against a firewalled target.

Note that SYN scans are less intrusive than TCP (full connect) scans against broken services, but they might cause problems for less robust firewalls and also leave unclosed connections on the remote target, if the network is loaded.
Solution
Protect your target with an IP filter.
Risk Factor
None
Plugin Information
Published: 2009/02/04, Modified: 2025/07/14
Plugin Output

tcp/8686/www

Port 8686/tcp was found to be open

11219 - Nessus SYN scanner
-
Synopsis
It is possible to determine which TCP ports are open.
Description
This plugin is a SYN 'half-open' port scanner. It shall be reasonably quick even against a firewalled target.

Note that SYN scans are less intrusive than TCP (full connect) scans against broken services, but they might cause problems for less robust firewalls and also leave unclosed connections on the remote target, if the network is loaded.
Solution
Protect your target with an IP filter.
Risk Factor
None
Plugin Information
Published: 2009/02/04, Modified: 2025/07/14
Plugin Output

tcp/8888/www

Port 8888/tcp was found to be open

11219 - Nessus SYN scanner
-
Synopsis
It is possible to determine which TCP ports are open.
Description
This plugin is a SYN 'half-open' port scanner. It shall be reasonably quick even against a firewalled target.

Note that SYN scans are less intrusive than TCP (full connect) scans against broken services, but they might cause problems for less robust firewalls and also leave unclosed connections on the remote target, if the network is loaded.
Solution
Protect your target with an IP filter.
Risk Factor
None
Plugin Information
Published: 2009/02/04, Modified: 2025/07/14
Plugin Output

tcp/54341

Port 54341/tcp was found to be open

19506 - Nessus Scan Information
-
Synopsis
This plugin displays information about the Nessus scan.
Description
This plugin displays, for each tested host, information about the scan itself :

- The version of the plugin set.
- The type of scanner (Nessus or Nessus Home).
- The version of the Nessus Engine.
- The port scanner(s) used.
- The port range scanned.
- The ping round trip time
- Whether credentialed or third-party patch management checks are possible.
- Whether the display of superseded patches is enabled
- The date of the scan.
- The duration of the scan.
- The number of hosts scanned in parallel.
- The number of checks done in parallel.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2005/08/26, Modified: 2025/10/29
Plugin Output

tcp/0

Information about this scan :

Nessus version : 10.11.1
Nessus build : 20021
Plugin feed version : 202601041845
Scanner edition used : Nessus
Scanner OS : WINDOWS
Scanner distribution : win-x86-64
Scan type : Normal
Scan name : Server 1
Scan policy used : Server
Scanner IP : 172.17.100.38
Port scanner(s) : nessus_syn_scanner
Port range : 1-65535
Ping RTT : Unavailable
Thorough tests : no
Experimental tests : no
Scan for Unpatched Vulnerabilities : yes
Plugin debugging enabled : yes (at debugging level 4)
Paranoia level : 0
Report verbosity : 2
Safe checks : yes
Optimize the test : yes
Credentialed checks : yes, as '172.17.100.31\tidua' via SMB
Patch management checks : None
Display superseded patches : yes (supersedence plugin did not launch)
CGI scanning : disabled
Web application tests : disabled
Max hosts : 2
Max checks : 2
Recv timeout : 5
Backports : None
Allow post-scan editing : Yes
Nessus Plugin Signature Checking : Enabled
Audit File Signature Checking : Disabled
Scan Start Date : 2026/1/10 2:05 India Standard Time (UTC +05:30)
Scan duration : 7976 sec
Scan for malware : no

43815 - NetBIOS Multiple IP Address Enumeration
-
Synopsis
The remote host is configured with multiple IP addresses.
Description
By sending a special NetBIOS query, Nessus was able to detect the use of multiple IP addresses on the remote host. This indicates the host may be running virtualization software, a VPN client, or has multiple network interfaces.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/01/06, Modified: 2011/09/02
Plugin Output

udp/137/netbios-ns


The remote host appears to be using the following IP addresses :

- 172.17.100.31
- 20.20.20.31

24272 - Network Interfaces Enumeration (WMI)
-
Synopsis
Nessus was able to obtain the list of network interfaces on the remote host.
Description
Nessus was able, via WMI queries, to extract a list of network interfaces on the remote host and the IP addresses attached to them.
Note that this plugin only enumerates IPv6 addresses for systems running Windows Vista or later.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/02/03, Modified: 2025/12/15
Plugin Output

tcp/0

+ Network Interface Information :

- Network Interface = [00000001] HPE Ethernet 1Gb 4-port 366FLR Adapter
- MAC Address = D4:F5:EF:60:4D:23
- IPAddress/IPSubnet = 20.20.20.31/255.255.255.0

+ Network Interface Information :

- Network Interface = [00000004] HPE Ethernet 1Gb 4-port 366FLR Adapter
- MAC Address = D4:F5:EF:60:4D:20
- IPAddress/IPSubnet = 172.17.100.31/255.255.255.0


+ Routing Information :

Destination Netmask Gateway
----------- ------- -------
0.0.0.0 0.0.0.0 172.17.100.10
20.20.20.0 255.255.255.0 0.0.0.0
20.20.20.31 255.255.255.255 0.0.0.0
20.20.20.255 255.255.255.255 0.0.0.0
127.0.0.0 255.0.0.0 0.0.0.0
127.0.0.1 255.255.255.255 0.0.0.0
127.255.255.255 255.255.255.255 0.0.0.0
172.17.100.0 255.255.255.0 0.0.0.0
172.17.100.31 255.255.255.255 0.0.0.0
172.17.100.255 255.255.255.255 0.0.0.0
224.0.0.0 240.0.0.0 0.0.0.0
224.0.0.0 240.0.0.0 0.0.0.0
224.0.0.0 240.0.0.0 0.0.0.0
255.255.255.255 255.255.255.255 0.0.0.0
255.255.255.255 255.255.255.255 0.0.0.0
255.255.255.255 255.255.255.255 0.0.0.0

42823 - Non-compliant Strict Transport Security (STS)
-
Synopsis
The remote web server implements Strict Transport Security incorrectly.
Description
The remote web server implements Strict Transport Security. However, it does not respect all the requirements of the STS draft standard.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/11/16, Modified: 2014/09/19
Plugin Output

tcp/80/www


The Strict-Transport-Security header must not be sent over an
unencrypted channel.

42823 - Non-compliant Strict Transport Security (STS)
-
Synopsis
The remote web server implements Strict Transport Security incorrectly.
Description
The remote web server implements Strict Transport Security. However, it does not respect all the requirements of the STS draft standard.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/11/16, Modified: 2014/09/19
Plugin Output

tcp/81/www


The Strict-Transport-Security header must not be sent over an
unencrypted channel.

42823 - Non-compliant Strict Transport Security (STS)
-
Synopsis
The remote web server implements Strict Transport Security incorrectly.
Description
The remote web server implements Strict Transport Security. However, it does not respect all the requirements of the STS draft standard.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/11/16, Modified: 2014/09/19
Plugin Output

tcp/8888/www


The Strict-Transport-Security header must not be sent over an
unencrypted channel.

181646 - Notepad++ Installed (Windows)
-
Synopsis
Notepad++ is installed on the remote Windows host.
Description
Notepad++ is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/09/20, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\Program Files\Notepad++
Version : 8.7.7.0
209654 - OS Fingerprints Detected
-
Synopsis
Multiple OS fingerprints were detected.
Description
Using a combination of remote probes (TCP/IP, SMB, HTTP, NTP, SNMP, etc), it was possible to gather one or more fingerprints from the remote system. While the highest-confidence result was reported in plugin 11936, “OS Identification”, the complete set of fingerprints detected are reported here.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/02/26, Modified: 2025/03/03
Plugin Output

tcp/0


Following OS Fingerprints were found

Remote operating system : Mitel SIP Device
Confidence level : 56
Method : MLSinFP
Type : unknown
Fingerprint : unknown

Remote operating system : Windows
Confidence level : 50
Method : Misc
Type : general-purpose
Fingerprint : unknown

Remote operating system : Microsoft Windows Server 2019 Datacenter Build 17763
Confidence level : 100
Method : SMB_OS
Type : general-purpose
Fingerprint : unknown

Remote operating system : Microsoft Windows Server 2019 Datacenter Build 17763
Confidence level : 59
Method : SinFP
Type : general-purpose
Fingerprint : SinFP:
P1:B11113:F0x12:W65392:O0204ffff:M1460:
P2:B11113:F0x12:W65535:O0204ffff0103030801010402:M1460:
P3:B00000:F0x00:W0:O0:M0
P4:191601_7_p=6443

Following fingerprints could not be used to determine OS :
HTTP:!:Server: nginx

SSLcert:!:i/CN:TechE_Live_DBs/CN:TechE_Live_DB
a905cd9c602e84db4207cd3294051d222314ad89
i/CN:TechE_Live_DBs/CN:TechE_Live_DB
02f2f1945ec1a0083a3ba20564aeebafba07e305
11936 - OS Identification
-
Synopsis
It is possible to guess the remote operating system.
Description
Using a combination of remote probes (e.g., TCP/IP, SMB, HTTP, NTP, SNMP, etc.), it is possible to guess the name of the remote operating system in use. It is also possible sometimes to guess the version of the operating system.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2003/12/09, Modified: 2025/06/03
Plugin Output

tcp/0


Remote operating system : Microsoft Windows Server 2019 Datacenter Build 17763
Confidence level : 100
Method : SMB_OS


The remote host is running Microsoft Windows Server 2019 Datacenter Build 17763

117887 - OS Security Patch Assessment Available
-
Synopsis
Nessus was able to log in to the remote host using the provided credentials and enumerate OS security patch levels.
Description
Nessus was able to determine OS security patch levels by logging into the remote host and running commands to determine the version of the operating system and its components. The remote host was identified as an operating system or device that Nessus supports for patch and update assessment. The necessary information was obtained to perform these checks.
Solution
n/a
Risk Factor
None
References
XREF IAVB:0001-B-0516
Plugin Information
Published: 2018/10/02, Modified: 2021/07/12
Plugin Output

tcp/445/cifs

OS Security Patch Assessment is available.

Account : 172.17.100.31\tidua
Protocol : SMB

92426 - OpenSaveMRU History
-
Synopsis
Nessus was able to enumerate opened and saved files on the remote host.
Description
Nessus was able to generate a report on files that were opened using the shell dialog box or saved using the shell dialog box. This is the box that appears when you attempt to save a document or open a document in Windows Explorer.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

Open / Save report attached.
66334 - Patch Report
-
Synopsis
The remote host is missing several patches.
Description
The remote host is missing one or more security patches. This plugin lists the newest version of each patch to install to make sure the remote host is up-to-date.

Note: Because the 'Show missing patches that have been superseded' setting in your scan policy depends on this plugin, it will always run and cannot be disabled.
Solution
Install the patches listed below.
Risk Factor
None
Plugin Information
Published: 2013/07/08, Modified: 2025/12/15
Plugin Output

tcp/0



. You need to take the following 7 actions :

+ Install the following Microsoft patches :
- KB5071544 (9 vulnerabilities)The following KBs would be covered:
KB5063877, KB5065428, KB5066586, KB5055519, KB5058392,
KB5060531, KB5068791, KB5062557, KB5053596
- KB5049608

[ 7-Zip < 25.01 (249179) ]

+ Action to take : Upgrade to 7-Zip version 25.01 or later.

+ Impact : Taking this action will resolve the following 5 different vulnerabilities :
CVE-2025-55188, CVE-2025-53817, CVE-2025-53816, CVE-2025-11002, CVE-2025-11001



[ MS09-035: Vulnerabilities in Visual Studio Active Template Library Could Allow Remote Code Execution (969706) (40435) ]

+ Action to take : Microsoft has released a set of patches for Visual Studio .NET 2003, Visual Studio 2005 and 2008, as well as Visual C++ 2005 and 2008.

+ Impact : Taking this action will resolve the following 3 different vulnerabilities :
CVE-2009-2495, CVE-2009-2493, CVE-2009-0901


[ Notepad++ < 8.8.2 Privilege Escalation (CVE-2025-49144) (240630) ]

+ Action to take : Upgrade to Notepad++ 8.8.2 or later.


[ RARLAB WinRAR < 7.13 Directory Traversal (CVE-2025-8088) (248462) ]

+ Action to take : Upgrade to RARLAB WinRAR version 7.13 or later.

+ Impact : Taking this action will resolve the following 2 different vulnerabilities :
CVE-2025-6218, CVE-2025-31334


[ Security Updates for Microsoft .NET Framework (January 2025) (214274) ]

+ Action to take : Microsoft has released security updates for Microsoft .NET Framework.

206777 - Postman Installed (Windows)
-
Synopsis
Postman is installed on the remote Windows host.
Description
Postman is installed on the remote Windows host.

Note. To detect the software, customers need to use an account that is used to install the software, or one that has the administrative privileges on the target.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2024/09/09, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\Users\techexcel\AppData\Local\Postman
Version : 11.77.0

122422 - RARLAB WinRAR Installed (Windows)
-
Synopsis
An archive manager is installed on the remote Windows host.
Description
RARLAB WinRaR, an archive manager, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0706
Plugin Information
Published: 2019/02/26, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Path : C:\Program Files\WinRAR\WinRAR.exe
Version : 7.1.0.0

92428 - Recent File History
-
Synopsis
Nessus was able to enumerate recently opened files on the remote host.
Description
Nessus was able to gather evidence of files opened by file type from the remote host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

C:\\Users\uatlkp\AppData\Roaming\Microsoft\Windows\Recent\testenc.lnk

Recent files found in registry and appdata attached.
92429 - Recycle Bin Files
-
Synopsis
Nessus was able to enumerate files in the recycle bin on the remote host.
Description
Nessus was able to generate a list of all files found in $Recycle.Bin subdirectories.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

C:\\$Recycle.Bin\\.
C:\\$Recycle.Bin\\..
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1000
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1001
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1002
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1006
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1010
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-500
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1000\.
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1000\..
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1000\$I0PAZW5.exe
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1000\$IDEWRZM.exe
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1000\$IMSZNZW.ini
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1000\$IWN3NHQ.exe
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1000\$R0PAZW5.exe
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1000\$RDEWRZM.exe
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1000\$RMSZNZW.ini
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1000\$RWN3NHQ.exe
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1000\desktop.ini
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1001\.
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1001\..
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1001\$I1YFW1O.xsp
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1001\$I2LSAVY.TMP
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1001\$I5WFSTY.hxa
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1001\$IAIV6DC.aco
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1001\$IKRQF5S.2sw
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1001\$IQQNGAL.TMP
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1001\desktop.ini
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1002\.
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1002\..
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1002\desktop.ini
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1006\.
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1006\..
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1006\desktop.ini
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1010\.
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1010\..
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-1010\desktop.ini
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-500\.
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-500\..
C:\\$Recycle.Bin\\S-1-5-21-1185746460-1788592564-4118236249-500\desktop.ini
92430 - Registry Editor Last Accessed
-
Synopsis
Nessus was able to find the last key accessed by the Registry Editor when it was closed on the remote host.
Description
Nessus was able to find evidence of the last key that was opened when the Registry Editor was closed for each user.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

Production
- Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VisualStudio\14.0\VC

techexcel
- Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\MSSQL15.MSSQLSERVER\Setup

10940 - Remote Desktop Protocol Service Detection
-
Synopsis
The remote host has an remote desktop protocol service enabled.
Description
The Remote Desktop Protocol allows a user to remotely obtain a graphical login (and therefore act as a local user on the remote host).

If an attacker gains a valid login and password, this service could be used to gain further access on the remote host. An attacker may also use this service to mount a dictionary attack against the remote host to try to log in remotely.

Note that RDP (the Remote Desktop Protocol) is vulnerable to Man-in-the-middle attacks, making it easy for attackers to steal the credentials of legitimate users by impersonating the Windows server.
Solution
Disable the service if you do not use it, and do not allow this service to run across the Internet.
Risk Factor
None
Plugin Information
Published: 2002/04/20, Modified: 2023/08/21
Plugin Output

tcp/3389/msrdp

277650 - Remote Services Not Using Post-Quantum Ciphers
-
Synopsis
Reports remote services that do not offer post-quantum ciphers.
Description
This plugin reports network services that do not offer post-quantum ciphers. Tenable makes no attempt to determine whether the remote service would be vulnerable to a post-quantum attack.

However, cryptography that depends on the classic difficulty of solving the discrete logarithm problem or on the classic difficulty of large prime factorization is broken by Shor's algorithm. Examples of this are RSA asymmetric encryption and Diffie-Hellman key exchange.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/08, Modified: 2025/12/08
Plugin Output

tcp/3389/msrdp

The target TLS server offers no post-quantum ciphers.

277650 - Remote Services Not Using Post-Quantum Ciphers
-
Synopsis
Reports remote services that do not offer post-quantum ciphers.
Description
This plugin reports network services that do not offer post-quantum ciphers. Tenable makes no attempt to determine whether the remote service would be vulnerable to a post-quantum attack.

However, cryptography that depends on the classic difficulty of solving the discrete logarithm problem or on the classic difficulty of large prime factorization is broken by Shor's algorithm. Examples of this are RSA asymmetric encryption and Diffie-Hellman key exchange.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/08, Modified: 2025/12/08
Plugin Output

tcp/6443/www

The target TLS server offers no post-quantum ciphers.

62042 - SMB QuickFixEngineering (QFE) Enumeration
-
Synopsis
The remote host has quick-fix engineering updates installed.
Description
By connecting to the host with the supplied credentials, this plugin enumerates quick-fix engineering updates installed on the remote host via the registry.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2012/09/11, Modified: 2022/02/01
Plugin Output

tcp/0


Here is a list of quick-fix engineering updates installed on the
remote system :

KB4502496, Installed on: 2022/01/08
KB4535680, Installed on: 2022/01/08
KB4535684, Installed on: 2022/01/08
KB4535685, Installed on: 2022/01/08
KB4589208, Installed on: 2022/01/08
KB5004335
KB5005030, Installed on: 2021/08/06
KB5005112, Installed on: 2021/08/06
KB5008287, Installed on: 2022/01/08
KB5011574, Installed on: 2022/05/04
KB5014031, Installed on: 2022/07/22
KB5014797, Installed on: 2022/07/22
KB5020374, Installed on: 2023/01/05
KB5046268, Installed on: 2024/12/21
42897 - SMB Registry : Start the Registry Service during the scan (WMI)
-
Synopsis
The registry service was enabled for the duration of the scan.
Description
To perform a full credentialed scan, Nessus needs the ability to connect to the remote registry service (RemoteRegistry). If the service is down, this plugin will attempt to start for the duration of the scan.

For this plugin to work, you need to select the option 'Start the Remote Registry service during the scan' on the credentials page when you add your Windows credentials.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/11/25, Modified: 2025/12/15
Plugin Output

tcp/0


The registry service was successfully started for the duration of the scan.
42898 - SMB Registry : Stop the Registry Service after the scan (WMI)
-
Synopsis
The registry service was stopped after the scan.
Description
To perform a full credentialed scan, Nessus needs the ability to connect to the remote registry service (RemoteRegistry). If the service is down and if Nessus automatically enabled the registry for the duration of the scan, this plugins will stop it afterwards.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/11/25, Modified: 2025/12/15
Plugin Output

tcp/0


The registry service was successfully stopped after the scan.

56984 - SSL / TLS Versions Supported
-
Synopsis
The remote service encrypts communications.
Description
This plugin detects which SSL and TLS versions are supported by the remote service for encrypting communications.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/01, Modified: 2025/06/16
Plugin Output

tcp/3389/msrdp


This port supports TLSv1.0/TLSv1.1/TLSv1.2.

56984 - SSL / TLS Versions Supported
-
Synopsis
The remote service encrypts communications.
Description
This plugin detects which SSL and TLS versions are supported by the remote service for encrypting communications.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/01, Modified: 2025/06/16
Plugin Output

tcp/6443/www


This port supports TLSv1.3/TLSv1.2.

10863 - SSL Certificate Information
-
Synopsis
This plugin displays the SSL certificate.
Description
This plugin connects to every SSL-related port and attempts to extract and dump the X.509 certificate.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/05/19, Modified: 2021/02/03
Plugin Output

tcp/3389/msrdp

Subject Name:

Common Name: TechE_Live_DB

Issuer Name:

Common Name: TechE_Live_DB

Serial Number: 50 3E 19 66 E4 20 6E A7 40 03 F7 7A 56 B3 54 56

Version: 3

Signature Algorithm: SHA-256 With RSA Encryption

Not Valid Before: Sep 29 08:51:23 2025 GMT
Not Valid After: Mar 31 08:51:23 2026 GMT

Public Key Info:

Algorithm: RSA Encryption
Key Length: 2048 bits
Public Key: 00 D3 BF 31 4A 85 B6 3D 9D D1 19 7A 83 40 52 AD E2 0D 39 7F
6E CB 2A 30 57 00 43 93 03 7E F2 B9 18 58 2C C4 BE BF CC E6
48 9B A8 72 C1 E8 7F 54 69 BE 6D 04 2B F0 DE A3 E4 D4 0C 1F
09 35 59 60 08 F3 67 71 3C 19 68 54 9A 10 2F 2F C8 AE F9 C0
2C C9 B2 56 CA A7 9E 43 0B 9D 7B 90 A5 A4 D6 C9 42 6E 18 33
C8 AF 74 1F 7E 9A 81 46 7E 88 90 38 6E 1F B3 62 01 D9 42 4E
A5 A4 6D F4 49 90 18 34 12 F5 8A 36 AD 65 0B 0A 8C F9 D7 5E
C8 89 A1 A7 70 D3 AC 52 8D 97 F1 F1 FC FA 53 5F 42 66 4C 1C
EA B5 4B 6C 79 9C BF C3 9B D6 47 6E 2A A9 9C D6 39 8B 48 E3
DA EA F5 0D 49 A5 20 0A 78 4D 83 E3 53 86 97 DA 89 9C 21 A9
A9 66 8E 22 4C F8 8A 2C 6C AC 1D 7D B7 C1 8B 82 34 54 65 D7
C3 63 7B F3 1D 84 FD 2D 42 00 B3 72 90 CF 33 CB 5E 42 A3 4F
7A E9 AF 68 EC D0 6B E8 F4 9E 6D 86 AA 53 6C 04 99
Exponent: 01 00 01

Signature Length: 256 bytes / 2048 bits
Signature: 00 02 6C A8 C3 36 58 C8 83 C4 F5 E5 D8 12 A5 85 4E 85 7E FA
CD 2F FE 4A 8D D7 70 8A 1D ED 60 86 4A 5E 61 7B 63 F2 99 53
B3 88 4C 9F 51 99 B4 42 D9 53 C4 4C DA D4 A5 D9 36 6A 25 62
11 08 DF 63 96 EF EC 19 A7 CE 5A 39 20 5B 0C C4 65 D2 A7 6C
C7 56 31 9B DD 71 BA 3C C3 D0 BE E8 2A F2 A3 D8 6B E6 8B F7
FF 78 60 0E 10 7B 5D 38 5D 7D 91 E6 25 F8 8F 0C A0 35 13 2E
6F 0D 7B B8 76 59 DE B6 C8 2F 30 54 1B 09 57 D4 20 0E A9 95
F7 99 68 94 0A 02 60 88 55 BF 1E 45 3C 85 47 D1 47 21 9B 0C
6E 82 08 97 87 3F 8C 47 95 94 82 AC DD F9 87 37 52 5F 1C D8
45 DB 4A F1 E2 8C E0 40 37 49 C1 EA 3E 46 EB C1 59 C8 EE 29
AB 1A 63 BC 8A 58 72 4E 73 B6 75 C2 89 AA CC 40 B6 19 18 84
D5 61 C0 5A 77 54 AD 7C 57 42 5F A7 59 6B 60 FB B1 42 6B C6
73 DB 3A BE DC DA DD 38 A5 0B CA C4 4E 07 2D CF 6B

Extension: Extended Key Usage(2.5.29.37)
Critical: 0
Purpose#1: Web Server Authentication (1.3.6.1.5.5.7.3.1)


Extension: Key Usage(2.5.29.15)
Critical: 0
Key Usage: Key Encipherment, Data Encipherment


Fingerprints :

SHA-256 Fingerprint: EC FD C7 41 B5 D5 DC 7C 80 8D 33 2C B8 91 80 8D 72 8B 95 7B
3B 3B 5E 41 DC 24 A4 A0 57 34 46 12
SHA-1 Fingerprint: 02 F2 F1 94 5E C1 A0 08 3A 3B A2 05 64 AE EB AF BA 07 E3 05
MD5 Fingerprint: 98 31 55 60 D1 6D 95 E3 44 D0 94 3F FD F6 C4 41


PEM certificate :

-----BEGIN CERTIFICATE-----
MIIC+DCCAeCgAwIBAgIQUD4ZZuQgbqdAA/d6VrNUVjANBgkqhkiG9w0BAQsFADAlMSMwIQYDVQQDHhoAVABlAGMAaABFAF8ATABpAHYAZQBfAEQAQjAeFw0yNTA5MjkwODUxMjNaFw0yNjAzMzEwODUxMjNaMCUxIzAhBgNVBAMeGgBUAGUAYwBoAEUAXwBMAGkAdgBlAF8ARABCMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA078xSoW2PZ3RGXqDQFKt4g05f27LKjBXAEOTA37yuRhYLMS+v8zmSJuocsHof1Rpvm0EK/Deo+TUDB8JNVlgCPNncTwZaFSaEC8vyK75wCzJslbKp55DC517kKWk1slCbhgzyK90H36agUZ+iJA4bh+zYgHZQk6lpG30SZAYNBL1ijatZQsKjPnXXsiJoadw06xSjZfx8fz6U19CZkwc6rVLbHmcv8Ob1kduKqmc1jmLSOPa6vUNSaUgCnhNg+NThpfaiZwhqalmjiJM+IosbKwdfbfBi4I0VGXXw2N78x2E/S1CALNykM8zy15Co0966a9o7NBr6PSebYaqU2wEmQIDAQABoyQwIjATBgNVHSUEDDAKBggrBgEFBQcDATALBgNVHQ8EBAMCBDAwDQYJKoZIhvcNAQELBQADggEBAAJsqMM2WMiDxPXl2BKlhU6FfvrNL/5Kjddwih3tYIZKXmF7Y/KZU7OITJ9RmbRC2VPETNrUpdk2aiViEQjfY5bv7Bmnzlo5IFsMxGXSp2zHVjGb3XG6PMPQvugq8qPYa+aL9/94YA4Qe104XX2R5iX4jwygNRMubw17uHZZ3rbILzBUGwlX1CAOqZX3mWiUCgJgiFW/HkU8hUfRRyGbDG6CCJeHP4xHlZSCrN35hzdSXxzYRdtK8eKM4EA3ScHqPkbrwVnI7imrGmO8ilhyTnO2dcKJqsxAthkYhNVhwFp3VK18V0Jfp1lrYPuxQmvGc9s6vtza3TilC8rETgctz2s=
-----END CERTIFICATE-----

10863 - SSL Certificate Information
-
Synopsis
This plugin displays the SSL certificate.
Description
This plugin connects to every SSL-related port and attempts to extract and dump the X.509 certificate.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/05/19, Modified: 2021/02/03
Plugin Output

tcp/6443/www

Subject Name:

Common Name: TechE_Live_DB

Issuer Name:

Common Name: TechE_Live_DB

Serial Number: 77 64 A8 E8 91 AB BE 86 4B 63 40 33 11 6A 62 88

Version: 3

Signature Algorithm: SHA-256 With RSA Encryption

Not Valid Before: Apr 14 08:31:38 2025 GMT
Not Valid After: Apr 12 08:31:38 2035 GMT

Public Key Info:

Algorithm: RSA Encryption
Key Length: 2048 bits
Public Key: 00 B9 F9 86 E4 66 6C 25 83 55 C4 E9 6E 5E 86 9C AD 81 3A 87
33 39 01 37 49 E5 78 91 AD F6 BD 6B A7 80 FB C1 B8 1A EC E1
DC 0D 32 A7 33 A0 3C 29 FD 10 47 9A BF 09 41 B1 85 F1 26 0C
DF F2 6F 31 45 58 31 49 B9 D5 B8 52 E7 7A 39 EB 63 8A 0C 09
05 44 C4 1B 78 D0 14 40 79 64 5F F9 3A C7 BC A0 4D 0C C8 C9
38 DA 37 D4 4B 19 3E 64 69 3E 29 44 31 8B CC B7 8E C4 FA C2
C5 32 D6 5F 13 B2 78 A7 74 16 3D 8D FB 77 D2 08 45 25 57 CD
56 5A 1F E5 B1 99 64 17 5B 8A DF B6 36 E0 BB DB 83 BE 11 B3
50 65 B2 5B 01 5F 76 32 C7 EB 5E 94 DE 07 0F 7F 9F 12 62 77
F0 1A D2 24 C0 06 CE CE 43 A6 0A 20 B1 3A 02 18 79 7C D3 78
6E 40 2B E1 23 F8 3F D4 A4 CE 3C DA 5E 4D 58 0D 32 05 F7 5B
4A 5B 40 F5 D5 63 9A F8 30 9F 42 9E 93 E3 03 0D E3 89 98 76
72 BD FA F3 9F 59 10 A1 D8 8C 8D E5 F4 CE A3 FC F9
Exponent: 01 00 01

Signature Length: 256 bytes / 2048 bits
Signature: 00 4A AE 0A DA 38 D4 88 03 48 A7 C5 F0 31 68 C9 54 C8 6F 11
36 FC B9 DD A2 46 F6 2F 26 E2 D2 FB FB ED B0 F7 48 14 B8 54
2C 3F 35 D0 81 89 7A A5 34 40 1D 40 B9 68 A6 8E 98 EB C4 6E
7E EC 26 42 C0 14 BE 58 3E 28 3A E3 D7 9D E2 5E 77 16 48 F6
CE 4C 74 F0 6E 7A 26 35 D0 2F 70 6D C9 D9 80 E6 CA 3A CC 29
60 7D 33 4A 3A B6 11 C9 62 7D 64 C2 A6 89 42 FF 96 98 17 5A
C9 69 41 B1 F6 A9 6D 34 45 4D 94 C7 1C 4E 2C AE 1F 5D FC AC
A1 32 DE 1A A7 6E E5 09 AA 3D A5 46 52 1D 02 D9 4F C6 9E AF
7A E4 A0 F0 3A 5F DC 25 C3 9D C4 91 BA C3 5D 0C B3 3F C6 7C
05 B5 CA B9 FB FE AB 59 1D 05 C8 BB 31 D7 4E 7E 6E 66 36 96
6A 8B 73 1F D8 3C 37 DC E8 8A EC 6E C7 BF C9 1A 5F AE EC 71
FF 4E 45 F3 BE 0C 25 4E 6F 24 AD FA 18 98 ED 43 B5 D3 F3 F2
A8 BC 39 65 32 59 7B AC B4 DE 35 4C 41 97 5A C9 AD

Extension: Key Usage(2.5.29.15)
Critical: 0
Key Usage: Digital Signature, Key Encipherment, Data Encipherment


Extension: Extended Key Usage(2.5.29.37)
Critical: 0
Purpose#1: Web Server Authentication (1.3.6.1.5.5.7.3.1)


Extension: Subject Alternative Name(2.5.29.17)
Critical: 0
DNS: TechE_Live_DB


Fingerprints :

SHA-256 Fingerprint: 36 7B 13 8D 18 23 41 18 D1 FB D5 27 EB 0C 17 BD 26 E0 1A A7
B6 C9 81 35 8E 76 84 8C C8 CF 59 8A
SHA-1 Fingerprint: A9 05 CD 9C 60 2E 84 DB 42 07 CD 32 94 05 1D 22 23 14 AD 89
MD5 Fingerprint: AA 03 DE F0 86 5A C7 40 29 E8 C6 DA 60 C5 5A FA


PEM certificate :

-----BEGIN CERTIFICATE-----
MIIC+DCCAeCgAwIBAgIQd2So6JGrvoZLY0AzEWpiiDANBgkqhkiG9w0BAQsFADAYMRYwFAYDVQQDDA1UZWNoRV9MaXZlX0RCMB4XDTI1MDQxNDA4MzEzOFoXDTM1MDQxMjA4MzEzOFowGDEWMBQGA1UEAwwNVGVjaEVfTGl2ZV9EQjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALn5huRmbCWDVcTpbl6GnK2BOoczOQE3SeV4ka32vWungPvBuBrs4dwNMqczoDwp/RBHmr8JQbGF8SYM3/JvMUVYMUm51bhS53o562OKDAkFRMQbeNAUQHlkX/k6x7ygTQzIyTjaN9RLGT5kaT4pRDGLzLeOxPrCxTLWXxOyeKd0Fj2N+3fSCEUlV81WWh/lsZlkF1uK37Y24Lvbg74Rs1BlslsBX3Yyx+telN4HD3+fEmJ38BrSJMAGzs5DpgogsToCGHl803huQCvhI/g/1KTOPNpeTVgNMgX3W0pbQPXVY5r4MJ9CnpPjAw3jiZh2cr36859ZEKHYjI3l9M6j/PkCAwEAAaM+MDwwCwYDVR0PBAQDAgSwMBMGA1UdJQQMMAoGCCsGAQUFBwMBMBgGA1UdEQQRMA+CDVRlY2hFX0xpdmVfREIwDQYJKoZIhvcNAQELBQADggEBAEquCto41IgDSKfF8DFoyVTIbxE2/Lndokb2Lybi0vv77bD3SBS4VCw/NdCBiXqlNEAdQLlopo6Y68RufuwmQsAUvlg+KDrj153iXncWSPbOTHTwbnomNdAvcG3J2YDmyjrMKWB9M0o6thHJYn1kwqaJQv+WmBdayWlBsfapbTRFTZTHHE4srh9d/KyhMt4ap27lCao9pUZSHQLZT8aer3rkoPA6X9wlw53EkbrDXQyzP8Z8BbXKufv+q1kdBci7MddOfm5mNpZqi3Mf2Dw33OiK7G7Hv8kaX67scf9ORfO+DCVObySt+hiY7UO10/PyqLw5ZTJZe6y03jVMQZdaya0=
-----END CERTIFICATE-----

70544 - SSL Cipher Block Chaining Cipher Suites Supported
-
Synopsis
The remote service supports the use of SSL Cipher Block Chaining ciphers, which combine previous blocks with subsequent ones.
Description
The remote host supports the use of SSL ciphers that operate in Cipher Block Chaining (CBC) mode. These cipher suites offer additional security over Electronic Codebook (ECB) mode, but have the potential to leak information if used improperly.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/22, Modified: 2021/02/03
Plugin Output

tcp/3389/msrdp


Here is the list of SSL CBC ciphers supported by the remote server :

Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

70544 - SSL Cipher Block Chaining Cipher Suites Supported
-
Synopsis
The remote service supports the use of SSL Cipher Block Chaining ciphers, which combine previous blocks with subsequent ones.
Description
The remote host supports the use of SSL ciphers that operate in Cipher Block Chaining (CBC) mode. These cipher suites offer additional security over Electronic Codebook (ECB) mode, but have the potential to leak information if used improperly.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/22, Modified: 2021/02/03
Plugin Output

tcp/6443/www


Here is the list of SSL CBC ciphers supported by the remote server :

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

21643 - SSL Cipher Suites Supported
-
Synopsis
The remote service encrypts communications using SSL.
Description
This plugin detects which SSL ciphers are supported by the remote service for encrypting communications.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2006/06/05, Modified: 2024/09/11
Plugin Output

tcp/3389/msrdp


Here is the list of SSL ciphers supported by the remote server :
Each group is reported per SSL Version.

SSL Version : TLSv12
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA256 0x00, 0x9E DHE RSA AES-GCM(128) SHA256
DHE-RSA-AES256-SHA384 0x00, 0x9F DHE RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA256 0xC0, 0x2F ECDHE RSA AES-GCM(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x30 ECDHE RSA AES-GCM(256) SHA384
RSA-AES128-SHA256 0x00, 0x9C RSA RSA AES-GCM(128) SHA256
RSA-AES256-SHA384 0x00, 0x9D RSA RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256


SSL Version : TLSv11
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1


SSL Version : TLSv1
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

Note that this service does not encrypt traffic by default but does
support upgrading to an encrypted connection using STARTTLS.

21643 - SSL Cipher Suites Supported
-
Synopsis
The remote service encrypts communications using SSL.
Description
This plugin detects which SSL ciphers are supported by the remote service for encrypting communications.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2006/06/05, Modified: 2024/09/11
Plugin Output

tcp/6443/www


Here is the list of SSL ciphers supported by the remote server :
Each group is reported per SSL Version.

SSL Version : TLSv13
High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
TLS_AES_256_GCM_SHA384 0x13, 0x02 - - AES-GCM(256) SHA384


SSL Version : TLSv12
High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
ECDHE-RSA-AES128-SHA256 0xC0, 0x2F ECDHE RSA AES-GCM(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x30 ECDHE RSA AES-GCM(256) SHA384
RSA-AES128-SHA256 0x00, 0x9C RSA RSA AES-GCM(128) SHA256
RSA-AES256-SHA384 0x00, 0x9D RSA RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

57041 - SSL Perfect Forward Secrecy Cipher Suites Supported
-
Synopsis
The remote service supports the use of SSL Perfect Forward Secrecy ciphers, which maintain confidentiality even if the key is stolen.
Description
The remote host supports the use of SSL ciphers that offer Perfect Forward Secrecy (PFS) encryption. These cipher suites ensure that recorded SSL traffic cannot be broken at a future date if the server's private key is compromised.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/07, Modified: 2021/03/09
Plugin Output

tcp/3389/msrdp


Here is the list of SSL PFS ciphers supported by the remote server :

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA256 0x00, 0x9E DHE RSA AES-GCM(128) SHA256
DHE-RSA-AES256-SHA384 0x00, 0x9F DHE RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA256 0xC0, 0x2F ECDHE RSA AES-GCM(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x30 ECDHE RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

57041 - SSL Perfect Forward Secrecy Cipher Suites Supported
-
Synopsis
The remote service supports the use of SSL Perfect Forward Secrecy ciphers, which maintain confidentiality even if the key is stolen.
Description
The remote host supports the use of SSL ciphers that offer Perfect Forward Secrecy (PFS) encryption. These cipher suites ensure that recorded SSL traffic cannot be broken at a future date if the server's private key is compromised.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/07, Modified: 2021/03/09
Plugin Output

tcp/6443/www


Here is the list of SSL PFS ciphers supported by the remote server :

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
ECDHE-RSA-AES128-SHA256 0xC0, 0x2F ECDHE RSA AES-GCM(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x30 ECDHE RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

156899 - SSL/TLS Recommended Cipher Suites
-
Synopsis
The remote host advertises discouraged SSL/TLS ciphers.
Description
The remote host has open SSL/TLS ports which advertise discouraged cipher suites. It is recommended to only enable support for the following cipher suites:

TLSv1.3:
- 0x13,0x01 TLS13_AES_128_GCM_SHA256
- 0x13,0x02 TLS13_AES_256_GCM_SHA384
- 0x13,0x03 TLS13_CHACHA20_POLY1305_SHA256

TLSv1.2:
- 0xC0,0x2B ECDHE-ECDSA-AES128-GCM-SHA256
- 0xC0,0x2F ECDHE-RSA-AES128-GCM-SHA256
- 0xC0,0x2C ECDHE-ECDSA-AES256-GCM-SHA384
- 0xC0,0x30 ECDHE-RSA-AES256-GCM-SHA384
- 0xCC,0xA9 ECDHE-ECDSA-CHACHA20-POLY1305
- 0xCC,0xA8 ECDHE-RSA-CHACHA20-POLY1305

This is the recommended configuration for the vast majority of services, as it is highly secure and compatible with nearly every client released in the last five (or more) years.
See Also
Solution
Only enable support for recommened cipher suites.
Risk Factor
None
Plugin Information
Published: 2022/01/20, Modified: 2024/02/12
Plugin Output

tcp/3389/msrdp

The remote host has listening SSL/TLS ports which advertise the discouraged cipher suites outlined below:


Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA256 0x00, 0x9E DHE RSA AES-GCM(128) SHA256
DHE-RSA-AES256-SHA384 0x00, 0x9F DHE RSA AES-GCM(256) SHA384
RSA-AES128-SHA256 0x00, 0x9C RSA RSA AES-GCM(128) SHA256
RSA-AES256-SHA384 0x00, 0x9D RSA RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

156899 - SSL/TLS Recommended Cipher Suites
-
Synopsis
The remote host advertises discouraged SSL/TLS ciphers.
Description
The remote host has open SSL/TLS ports which advertise discouraged cipher suites. It is recommended to only enable support for the following cipher suites:

TLSv1.3:
- 0x13,0x01 TLS13_AES_128_GCM_SHA256
- 0x13,0x02 TLS13_AES_256_GCM_SHA384
- 0x13,0x03 TLS13_CHACHA20_POLY1305_SHA256

TLSv1.2:
- 0xC0,0x2B ECDHE-ECDSA-AES128-GCM-SHA256
- 0xC0,0x2F ECDHE-RSA-AES128-GCM-SHA256
- 0xC0,0x2C ECDHE-ECDSA-AES256-GCM-SHA384
- 0xC0,0x30 ECDHE-RSA-AES256-GCM-SHA384
- 0xCC,0xA9 ECDHE-ECDSA-CHACHA20-POLY1305
- 0xCC,0xA8 ECDHE-RSA-CHACHA20-POLY1305

This is the recommended configuration for the vast majority of services, as it is highly secure and compatible with nearly every client released in the last five (or more) years.
See Also
Solution
Only enable support for recommened cipher suites.
Risk Factor
None
Plugin Information
Published: 2022/01/20, Modified: 2024/02/12
Plugin Output

tcp/6443/www

The remote host has listening SSL/TLS ports which advertise the discouraged cipher suites outlined below:


High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
RSA-AES128-SHA256 0x00, 0x9C RSA RSA AES-GCM(128) SHA256
RSA-AES256-SHA384 0x00, 0x9D RSA RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

160486 - Server Message Block (SMB) Protocol Version Detection
-
Synopsis
Verify the version of SMB on the remote host.
Description
The Server Message Block (SMB) Protocol provides shared access to files and printers across nodes on a network.
See Also
Solution
Disable SMB version 1 and block all versions of SMB at the network boundary by blocking TCP port 445 with related protocols on UDP ports 137-138 and TCP port 139, for all boundary devices.
Risk Factor
None
Plugin Information
Published: 2022/05/04, Modified: 2022/05/04
Plugin Output

tcp/445/cifs

- SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\SMB2 : Key not found.
- SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\SMB3 : Key not found.
- SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\SMB1 : Key not found.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/80/www

A web server is running on this port.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/81/www

A web server is running on this port.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/5800/www

A web server is running on this port.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/5900/vnc

A vnc server is running on this port.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/5985/www

A web server is running on this port.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/6443/www

A TLSv1.3 server answered on this port.

tcp/6443/www

A web server is running on this port through TLSv1.3.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/8686/www

A web server is running on this port.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/8888/www

A web server is running on this port.

278501 - Smartbedded Meteobridge Web Detection
-
Synopsis
The web UI for Smartbedded Meteobridge was detected on the remote host.
Description
Smartbedded Meteobridge, a dedicated weather monitoring application, is running on the remote host.

Note: Basic HTTP Authentication credentials are required to obtain the version.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/12, Modified: 2025/12/15
Plugin Output

tcp/80/www


URL : http://172.17.100.31/cgi-bin/meteobridge
Version : unknown
Authenticated : False

278501 - Smartbedded Meteobridge Web Detection
-
Synopsis
The web UI for Smartbedded Meteobridge was detected on the remote host.
Description
Smartbedded Meteobridge, a dedicated weather monitoring application, is running on the remote host.

Note: Basic HTTP Authentication credentials are required to obtain the version.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/12, Modified: 2025/12/15
Plugin Output

tcp/81/www


URL : http://172.17.100.31:81/cgi-bin/meteobridge
Version : unknown
Authenticated : False

278501 - Smartbedded Meteobridge Web Detection
-
Synopsis
The web UI for Smartbedded Meteobridge was detected on the remote host.
Description
Smartbedded Meteobridge, a dedicated weather monitoring application, is running on the remote host.

Note: Basic HTTP Authentication credentials are required to obtain the version.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/12, Modified: 2025/12/15
Plugin Output

tcp/5985/www


URL : http://172.17.100.31:5985/cgi-bin/meteobridge
Version : unknown
Authenticated : False

278501 - Smartbedded Meteobridge Web Detection
-
Synopsis
The web UI for Smartbedded Meteobridge was detected on the remote host.
Description
Smartbedded Meteobridge, a dedicated weather monitoring application, is running on the remote host.

Note: Basic HTTP Authentication credentials are required to obtain the version.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/12, Modified: 2025/12/15
Plugin Output

tcp/6443/www


URL : https://172.17.100.31:6443/cgi-bin/meteobridge
Version : unknown
Authenticated : False

278501 - Smartbedded Meteobridge Web Detection
-
Synopsis
The web UI for Smartbedded Meteobridge was detected on the remote host.
Description
Smartbedded Meteobridge, a dedicated weather monitoring application, is running on the remote host.

Note: Basic HTTP Authentication credentials are required to obtain the version.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/12, Modified: 2025/12/15
Plugin Output

tcp/8686/www


URL : http://172.17.100.31:8686/cgi-bin/meteobridge
Version : unknown
Authenticated : False

278501 - Smartbedded Meteobridge Web Detection
-
Synopsis
The web UI for Smartbedded Meteobridge was detected on the remote host.
Description
Smartbedded Meteobridge, a dedicated weather monitoring application, is running on the remote host.

Note: Basic HTTP Authentication credentials are required to obtain the version.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/12, Modified: 2025/12/15
Plugin Output

tcp/8888/www


URL : http://172.17.100.31:8888/cgi-bin/meteobridge
Version : unknown
Authenticated : False

42822 - Strict Transport Security (STS) Detection
-
Synopsis
The remote web server implements Strict Transport Security.
Description
The remote web server implements Strict Transport Security (STS).
The goal of STS is to make sure that a user does not accidentally downgrade the security of his or her browser.

All unencrypted HTTP connections are redirected to HTTPS. The browser is expected to treat all cookies as 'secure' and to close the connection in the event of potentially insecure situations.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/11/16, Modified: 2019/11/22
Plugin Output

tcp/80/www


The STS header line is :

Strict-Transport-Security: max-age=31536000

42822 - Strict Transport Security (STS) Detection
-
Synopsis
The remote web server implements Strict Transport Security.
Description
The remote web server implements Strict Transport Security (STS).
The goal of STS is to make sure that a user does not accidentally downgrade the security of his or her browser.

All unencrypted HTTP connections are redirected to HTTPS. The browser is expected to treat all cookies as 'secure' and to close the connection in the event of potentially insecure situations.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/11/16, Modified: 2019/11/22
Plugin Output

tcp/81/www


The STS header line is :

Strict-Transport-Security: max-age=31536000

42822 - Strict Transport Security (STS) Detection
-
Synopsis
The remote web server implements Strict Transport Security.
Description
The remote web server implements Strict Transport Security (STS).
The goal of STS is to make sure that a user does not accidentally downgrade the security of his or her browser.

All unencrypted HTTP connections are redirected to HTTPS. The browser is expected to treat all cookies as 'secure' and to close the connection in the event of potentially insecure situations.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/11/16, Modified: 2019/11/22
Plugin Output

tcp/8888/www


The STS header line is :

Strict-Transport-Security: max-age=31536000

161455 - Supersedence Data Builder
-
Synopsis
Supersedence data.
Description
Collects and stores supersedence patch data for various patch types.
Solution
N/A
Risk Factor
None
Plugin Information
Published: 2022/05/24, Modified: 2025/07/14
Plugin Output

tcp/0

Supersedence patch data summary :
- MSKB : 11


Plugin debug log has been attached.

84821 - TLS ALPN Supported Protocol Enumeration
-
Synopsis
The remote host supports the TLS ALPN extension.
Description
The remote host supports the TLS ALPN extension. This plugin enumerates the protocols the extension supports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2015/07/17, Modified: 2024/09/11
Plugin Output

tcp/6443/www


http/1.1
277654 - TLS Supported Groups
-
Synopsis
The remote service negotiates TLS supported curve groups.
Description
This plugin detects which TLS supported groups entries are supported by the remote service.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/08, Modified: 2025/12/10
Plugin Output

tcp/6443/www


These are the TLS supported groups offered by the remote server :


TLS supported groups :

Name Code
--------------------------
x25519 0x001d
secp256r1 0x0017
x448 0x001e
secp521r1 0x0019
secp384r1 0x0018
ffdhe2048 0x0100
ffdhe3072 0x0101
ffdhe4096 0x0102
ffdhe6144 0x0103
ffdhe8192 0x0104

121010 - TLS Version 1.1 Protocol Detection
-
Synopsis
The remote service encrypts traffic using an older version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.1.
TLS 1.1 lacks support for current and recommended cipher suites.
Ciphers that support encryption before MAC computation, and authenticated encryption modes such as GCM cannot be used with TLS 1.1

As of March 31, 2020, Endpoints that are not enabled for TLS 1.2 and higher will no longer function properly with major web browsers and major vendors.
See Also
Solution
Enable support for TLS 1.2 and/or 1.3, and disable support for TLS 1.1.
Risk Factor
None
References
XREF CWE:327
Plugin Information
Published: 2019/01/08, Modified: 2023/04/19
Plugin Output

tcp/3389/msrdp

TLSv1.1 is enabled and the server supports at least one cipher.
136318 - TLS Version 1.2 Protocol Detection
-
Synopsis
The remote service encrypts traffic using a version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.2.
See Also
Solution
N/A
Risk Factor
None
Plugin Information
Published: 2020/05/04, Modified: 2020/05/04
Plugin Output

tcp/3389/msrdp

TLSv1.2 is enabled and the server supports at least one cipher.

136318 - TLS Version 1.2 Protocol Detection
-
Synopsis
The remote service encrypts traffic using a version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.2.
See Also
Solution
N/A
Risk Factor
None
Plugin Information
Published: 2020/05/04, Modified: 2020/05/04
Plugin Output

tcp/6443/www

TLSv1.2 is enabled and the server supports at least one cipher.
138330 - TLS Version 1.3 Protocol Detection
-
Synopsis
The remote service encrypts traffic using a version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.3.
See Also
Solution
N/A
Risk Factor
None
Plugin Information
Published: 2020/07/09, Modified: 2023/12/13
Plugin Output

tcp/6443/www

TLSv1.3 is enabled and the server supports at least one cipher.

150799 - Target Access Problems by Authentication Protocol - Maximum Privilege Account Used in Scan
-
Synopsis
Nessus scanned the target host with the highest available privilege level. Yet Nessus encountered permissions issues while accessing one or more items during the scan.
Description
Nessus was able to log in to the remote host using the provided credentials. The provided credentials have the highest privilege possible on the remote host. Yet Nessus encountered permissions issues while accessing items during the scan.

It is likely that this condition is caused by one or more of the following:

1) A plugin tried to access a resource that requires a special privilege level such as NT_AUTHORITY on Windows. The resource may have had its permissions altered since the plugin was written.
2) Environmental issues may have caused an intermittent failure in authentication that caused Nessus to stop attempting privilege escalation.
3) A resource on the host that Nessus attempts to access multiple times may be configured with access limits. Related lockouts may look like permissions failures.
4) Nessus may have tried to access a resource that does not exist on a target that fails to properly report permissions issues.
For instance, on some legacy unix systems such as AIX or HP-UX there is no way to distinguish a missing resource from a permissions error.

If you believe that the plugin indicated attempted to access the wrong resource or a resource that has recently received special OS protection, please contact Tenable Support.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2021/07/06, Modified: 2021/07/06
Plugin Output

tcp/445/cifs


Nessus was able to log in to the remote host via the following
protocol as tidua. During the scan Nessus encountered
the following permissions issues while performing the planned checks:

Protocol : SMB
Port : 445

Problems:
Plugin 134050: Permission was denied while opening 'TEMP\nessus_IJ293PDA.TXT'.
Plugin 139785: Permission was denied while opening 'TEMP\nessus_LY5E3E4W.TXT'.
Plugin 140578: Permission was denied while opening 'TEMP\nessus_0P6Z4HJY.TXT'.
Plugin 148499: Permission was denied while opening 'TEMP\nessus_VOPHLWZS.TXT'.
Plugin 152100: Permission was denied while opening 'TEMP\nessus_Q1P2MV4M.TXT'.
Plugin 155470: Permission was denied while opening 'TEMP\nessus_enumerate_oci_winVJKB5NSL.TXT'.
Plugin 156001: Permission was denied while opening 'TEMP\nessus_E1CR8O4O.TXT'.
Plugin 171956: Permission was denied while opening 'TEMP\nessus_FA8D43NU.TXT'.
Plugin 177646: Permission was denied while opening 'TEMP\nessus_azure_ad_join_XY5LU18A.txt'.
Plugin 25197: Permission was denied while opening 'TEMP\nessus_993P47ZK.TXT'.
Plugin 34220: Permission was denied while opening 'TEMP\nessus_9HA8IF46.TXT'.
Plugin 61797: Permission was denied while opening 'TEMP\nessus_D44OMEAL.TXT'.
Plugin 70625: Permission was denied while opening 'TEMP\nessus_VKJ6BVJ7.TXT'.
Plugin 85736: Permission was denied while opening 'TEMP\nessus_02UQFQ3G.TXT'.
Plugin 92370: Permission was denied while opening 'temp\nessus_YR5BVKAD.txt'.
Plugin 92371: Permission was denied while opening 'temp\nessus_VLTNXXK3.txt'.
Plugin 92372: Permission was denied while opening 'temp\nessus_Q7KQXTHI.txt'.
Plugin 92373: Permission was denied while opening 'temp\nessus_EJVEFLAN.txt'.



Note: Nessus was unable to determine the privilege of
the logged in user and therefore is reporting permissions
problems here. Please check to see whether privilege escalation
failed or whether the scan can be configured to supply more access.
141118 - Target Credential Status by Authentication Protocol - Valid Credentials Provided
-
Synopsis
Valid credentials were provided for an available authentication protocol.
Description
Nessus was able to determine that valid credentials were provided for an authentication protocol available on the remote target because it was able to successfully authenticate directly to the remote target using that authentication protocol at least once. Authentication was successful because the authentication protocol service was available remotely, the service was able to be identified, the authentication protocol was able to be negotiated successfully, and a set of credentials provided in the scan policy for that authentication protocol was accepted by the remote service. See plugin output for details, including protocol, port, and account.

Please note the following :

- This plugin reports per protocol, so it is possible for valid credentials to be provided for one protocol and not another. For example, authentication may succeed via SSH but fail via SMB, while no credentials were provided for an available SNMP service.

- Providing valid credentials for all available authentication protocols may improve scan coverage, but the value of successful authentication for a given protocol may vary from target to target depending upon what data (if any) is gathered from the target via that protocol. For example, successful authentication via SSH is more valuable for Linux targets than for Windows targets, and likewise successful authentication via SMB is more valuable for Windows targets than for Linux targets.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2020/10/15, Modified: 2024/03/25
Plugin Output

tcp/445/cifs


Nessus was able to log in to the remote host via the following :

User: '172.17.100.31\tidua'
Port: 445
Proto: SMB
Method: password

92433 - Terminal Services History
-
Synopsis
Nessus was able to gather terminal service connection information.
Description
Nessus was able to generate a report on terminal service connections on the target system.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

Terminal Services Client
- Production
- Production
- Production
- Production
- Production
- Production
- Production
- techexcel
- techexcel
- techexcel
- techexcel
- techexcel


Terminal Services Server
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582_Classes
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582_Classes
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582_Classes
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582_Classes
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582_Classes
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582_Classes
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582_Classes
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582_Classes
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582_Classes
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582_Classes
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582_Classes
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582_Classes
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582_Classes
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582_Classes
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582_Classes
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582_Classes
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582_Classes
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582_Classes
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582_Classes
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582_Classes
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582_Classes
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582_Classes
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582_Classes
- Production
- Production
- Production
- Production
- Production
- Production
- Production
- Production
- Production
- Production
- Production
- Production
- Production
- Production
- Production
- Production
- Production
- Production
- Production
- Production
- Production
- Production
- Production
- techexcel
- techexcel
- techexcel
- techexcel
- techexcel
- techexcel
- techexcel
- techexcel
- techexcel
- techexcel
- S-1-5-21-1185746460-1788592564-4118236249-1002
- S-1-5-21-1185746460-1788592564-4118236249-1002
- S-1-5-21-1185746460-1788592564-4118236249-1002
- S-1-5-21-1185746460-1788592564-4118236249-1002
- S-1-5-21-1185746460-1788592564-4118236249-1002
- S-1-5-21-1185746460-1788592564-4118236249-1002
- S-1-5-21-1185746460-1788592564-4118236249-1002
- S-1-5-21-1185746460-1788592564-4118236249-1002
- S-1-5-21-1185746460-1788592564-4118236249-1002
- S-1-5-21-1185746460-1788592564-4118236249-1002
- S-1-5-21-1185746460-1788592564-4118236249-500_Classes
- S-1-5-21-1185746460-1788592564-4118236249-500_Classes
- S-1-5-21-1185746460-1788592564-4118236249-500_Classes
- S-1-5-21-1185746460-1788592564-4118236249-500_Classes
- S-1-5-21-1185746460-1788592564-4118236249-500_Classes
- S-1-5-21-1185746460-1788592564-4118236249-500_Classes
- S-1-5-21-1185746460-1788592564-4118236249-500_Classes
- S-1-5-21-1185746460-1788592564-4118236249-500_Classes
- S-1-5-21-1185746460-1788592564-4118236249-500_Classes
- S-1-5-21-1185746460-1788592564-4118236249-500_Classes
- S-1-5-21-1185746460-1788592564-4118236249-500_Classes
- S-1-5-21-1185746460-1788592564-4118236249-500_Classes
- S-1-5-21-1185746460-1788592564-4118236249-500_Classes
- S-1-5-21-1185746460-1788592564-4118236249-500_Classes
- S-1-5-21-1185746460-1788592564-4118236249-500_Classes
- S-1-5-21-1185746460-1788592564-4118236249-500_Classes
- S-1-5-21-1185746460-1788592564-4118236249-500_Classes
- S-1-5-21-1185746460-1788592564-4118236249-500_Classes
- S-1-5-21-1185746460-1788592564-4118236249-500_Classes
- S-1-5-21-1185746460-1788592564-4118236249-500_Classes
- S-1-5-21-1185746460-1788592564-4118236249-500_Classes
- S-1-5-21-1185746460-1788592564-4118236249-500_Classes
- S-1-5-21-1185746460-1788592564-4118236249-500_Classes
- S-1-5-18
- S-1-5-18
- S-1-5-18
- S-1-5-18
- S-1-5-18
- S-1-5-18
- S-1-5-18
- S-1-5-18
- S-1-5-18
- S-1-5-18
- S-1-5-18
- S-1-5-18
- S-1-5-18
- S-1-5-18
- S-1-5-18
- S-1-5-18
- S-1-5-18
- S-1-5-18
- S-1-5-18
- S-1-5-18
- S-1-5-18
- S-1-5-18
- S-1-5-18
- S-1-5-21-1185746460-1788592564-4118236249-1012
- S-1-5-21-1185746460-1788592564-4118236249-1012
- S-1-5-21-1185746460-1788592564-4118236249-1012
- S-1-5-21-1185746460-1788592564-4118236249-1012
- S-1-5-21-1185746460-1788592564-4118236249-1012
- S-1-5-21-1185746460-1788592564-4118236249-1012
- S-1-5-21-1185746460-1788592564-4118236249-1012
- S-1-5-21-1185746460-1788592564-4118236249-1012
- S-1-5-21-1185746460-1788592564-4118236249-1012
- S-1-5-21-1185746460-1788592564-4118236249-1012
- S-1-5-21-1185746460-1788592564-4118236249-1002_Classes
- S-1-5-21-1185746460-1788592564-4118236249-1002_Classes
- S-1-5-21-1185746460-1788592564-4118236249-1002_Classes
- S-1-5-21-1185746460-1788592564-4118236249-1002_Classes
- S-1-5-21-1185746460-1788592564-4118236249-1002_Classes
- S-1-5-21-1185746460-1788592564-4118236249-1002_Classes
- S-1-5-21-1185746460-1788592564-4118236249-1002_Classes
- S-1-5-21-1185746460-1788592564-4118236249-1002_Classes
- S-1-5-21-1185746460-1788592564-4118236249-1002_Classes
- S-1-5-21-1185746460-1788592564-4118236249-1002_Classes
- S-1-5-21-1185746460-1788592564-4118236249-1001_Classes
- S-1-5-21-1185746460-1788592564-4118236249-1001_Classes
- S-1-5-21-1185746460-1788592564-4118236249-1001_Classes
- S-1-5-21-1185746460-1788592564-4118236249-1001_Classes
- S-1-5-21-1185746460-1788592564-4118236249-1001_Classes
- S-1-5-21-1185746460-1788592564-4118236249-1001_Classes
- S-1-5-21-1185746460-1788592564-4118236249-1001_Classes
- S-1-5-21-1185746460-1788592564-4118236249-1001_Classes
- S-1-5-21-1185746460-1788592564-4118236249-1001_Classes
- S-1-5-21-1185746460-1788592564-4118236249-1001_Classes


Extended Terminal Services report attached.

64814 - Terminal Services Use SSL/TLS
-
Synopsis
The remote Terminal Services use SSL/TLS.
Description
The remote Terminal Services is configured to use SSL/TLS.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/02/22, Modified: 2023/07/10
Plugin Output

tcp/3389/msrdp

Subject Name:

Common Name: TechE_Live_DB

Issuer Name:

Common Name: TechE_Live_DB

Serial Number: 50 3E 19 66 E4 20 6E A7 40 03 F7 7A 56 B3 54 56

Version: 3

Signature Algorithm: SHA-256 With RSA Encryption

Not Valid Before: Sep 29 08:51:23 2025 GMT
Not Valid After: Mar 31 08:51:23 2026 GMT

Public Key Info:

Algorithm: RSA Encryption
Key Length: 2048 bits
Public Key: 00 D3 BF 31 4A 85 B6 3D 9D D1 19 7A 83 40 52 AD E2 0D 39 7F
6E CB 2A 30 57 00 43 93 03 7E F2 B9 18 58 2C C4 BE BF CC E6
48 9B A8 72 C1 E8 7F 54 69 BE 6D 04 2B F0 DE A3 E4 D4 0C 1F
09 35 59 60 08 F3 67 71 3C 19 68 54 9A 10 2F 2F C8 AE F9 C0
2C C9 B2 56 CA A7 9E 43 0B 9D 7B 90 A5 A4 D6 C9 42 6E 18 33
C8 AF 74 1F 7E 9A 81 46 7E 88 90 38 6E 1F B3 62 01 D9 42 4E
A5 A4 6D F4 49 90 18 34 12 F5 8A 36 AD 65 0B 0A 8C F9 D7 5E
C8 89 A1 A7 70 D3 AC 52 8D 97 F1 F1 FC FA 53 5F 42 66 4C 1C
EA B5 4B 6C 79 9C BF C3 9B D6 47 6E 2A A9 9C D6 39 8B 48 E3
DA EA F5 0D 49 A5 20 0A 78 4D 83 E3 53 86 97 DA 89 9C 21 A9
A9 66 8E 22 4C F8 8A 2C 6C AC 1D 7D B7 C1 8B 82 34 54 65 D7
C3 63 7B F3 1D 84 FD 2D 42 00 B3 72 90 CF 33 CB 5E 42 A3 4F
7A E9 AF 68 EC D0 6B E8 F4 9E 6D 86 AA 53 6C 04 99
Exponent: 01 00 01

Signature Length: 256 bytes / 2048 bits
Signature: 00 02 6C A8 C3 36 58 C8 83 C4 F5 E5 D8 12 A5 85 4E 85 7E FA
CD 2F FE 4A 8D D7 70 8A 1D ED 60 86 4A 5E 61 7B 63 F2 99 53
B3 88 4C 9F 51 99 B4 42 D9 53 C4 4C DA D4 A5 D9 36 6A 25 62
11 08 DF 63 96 EF EC 19 A7 CE 5A 39 20 5B 0C C4 65 D2 A7 6C
C7 56 31 9B DD 71 BA 3C C3 D0 BE E8 2A F2 A3 D8 6B E6 8B F7
FF 78 60 0E 10 7B 5D 38 5D 7D 91 E6 25 F8 8F 0C A0 35 13 2E
6F 0D 7B B8 76 59 DE B6 C8 2F 30 54 1B 09 57 D4 20 0E A9 95
F7 99 68 94 0A 02 60 88 55 BF 1E 45 3C 85 47 D1 47 21 9B 0C
6E 82 08 97 87 3F 8C 47 95 94 82 AC DD F9 87 37 52 5F 1C D8
45 DB 4A F1 E2 8C E0 40 37 49 C1 EA 3E 46 EB C1 59 C8 EE 29
AB 1A 63 BC 8A 58 72 4E 73 B6 75 C2 89 AA CC 40 B6 19 18 84
D5 61 C0 5A 77 54 AD 7C 57 42 5F A7 59 6B 60 FB B1 42 6B C6
73 DB 3A BE DC DA DD 38 A5 0B CA C4 4E 07 2D CF 6B

Extension: Extended Key Usage(2.5.29.37)
Critical: 0
Purpose#1: Web Server Authentication (1.3.6.1.5.5.7.3.1)


Extension: Key Usage(2.5.29.15)
Critical: 0
Key Usage: Key Encipherment, Data Encipherment

161691 - The Microsoft Windows Support Diagnostic Tool (MSDT) RCE Workaround Detection (CVE-2022-30190)
-
Synopsis
Checks for the HKEY_CLASSES_ROOT\ms-msdt registry key.
Description
The remote host has the HKEY_CLASSES_ROOT\ms-msdt registry key. This is a known exposure for CVE-2022-30190.

Note that Nessus has not tested for CVE-2022-30190. It is only checking if the registry key exists. The recommendation is to apply the latest patch.
See Also
Solution
Apply the latest Cumulative Update.
Risk Factor
None
Plugin Information
Published: 2022/05/31, Modified: 2022/07/28
Plugin Output

tcp/445/cifs

The HKEY_CLASSES_ROOT\ms-msdt registry key exists on the target. This may indicate that the target is vulnerable to CVE-2022-30190, if the vendor patch is not applied.

56468 - Time of Last System Startup
-
Synopsis
The system has been started.
Description
Using the supplied credentials, Nessus was able to determine when the host was last started.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/10/12, Modified: 2018/06/19
Plugin Output

tcp/0


20260104213346.143316+330

10287 - Traceroute Information
-
Synopsis
It was possible to obtain traceroute information.
Description
Makes a traceroute to the remote host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 1999/11/27, Modified: 2023/12/04
Plugin Output

udp/0

For your information, here is the traceroute from 172.17.100.38 to 172.17.100.31 :
172.17.100.38
172.17.100.31

Hop Count: 1

24274 - USB Drives Enumeration (WMI)
-
Synopsis
It is possible to obtain the list of USB drives on the remote host.
Description
By connecting to the remote host with the supplied credentials, it is possible to extract the list of USB drives of the remote host and the drive name attached to each.
Solution
Make sure that use of external USB drives matches your organization's security policy.
Risk Factor
None
Plugin Information
Published: 2007/02/05, Modified: 2025/12/15
Plugin Output

tcp/0

+ Generic- SD/MMC CRW USB Device
92434 - User Download Folder Files
-
Synopsis
Nessus was able to enumerate downloaded files on the remote host.
Description
Nessus was able to generate a report of all files listed in the default user download folder.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/16
Plugin Output

tcp/0

C:\\Users\Administrator\Downloads\12062025053622.zip
C:\\Users\Administrator\Downloads\19062025054655.zip
C:\\Users\Administrator\Downloads\19062025054952.pdf
C:\\Users\Administrator\Downloads\19062025062617.pdf
C:\\Users\Administrator\Downloads\22042025063720.pdf
C:\\Users\Administrator\Downloads\22042025064228.pdf
C:\\Users\Administrator\Downloads\24042025055522.zip
C:\\Users\Administrator\Downloads\24042025055724.zip
C:\\Users\Administrator\Downloads\desktop.ini
C:\\Users\Administrator\Downloads\jointholder_bo.htm
C:\\Users\Backoffice\Downloads\desktop.ini
C:\\Users\LKPAdmin\Downloads\desktop.ini
C:\\Users\Public\Downloads\desktop.ini
C:\\Users\techapp\Downloads\desktop.ini
C:\\Users\techexcel\Downloads\0\AAACL0963A_11092023_01.zip
C:\\Users\techexcel\Downloads\02082024061111.zip
C:\\Users\techexcel\Downloads\02082024061507.zip
C:\\Users\techexcel\Downloads\02082024072044.zip
C:\\Users\techexcel\Downloads\02092025034538techexcel.zip
C:\\Users\techexcel\Downloads\02092025045824techexcel\mirae_02092025.pdf
C:\\Users\techexcel\Downloads\02092025045824techexcel.zip
C:\\Users\techexcel\Downloads\02092025052913techexcel.zip
C:\\Users\techexcel\Downloads\02092025054108techexcel.zip
C:\\Users\techexcel\Downloads\02092025115735.pdf
C:\\Users\techexcel\Downloads\0310202511585503-10-2025115904.pdf
C:\\Users\techexcel\Downloads\03112023_07200.txt.gz
C:\\Users\techexcel\Downloads\05092025125134.zip
C:\\Users\techexcel\Downloads\05122025053039.pdf
C:\\Users\techexcel\Downloads\05122025053712.pdf
C:\\Users\techexcel\Downloads\06-Jun-2025_144919.zip
C:\\Users\techexcel\Downloads\06-Jun-2025_145012.zip
C:\\Users\techexcel\Downloads\06012025064018.zip
C:\\Users\techexcel\Downloads\06052025061935.zip
C:\\Users\techexcel\Downloads\06052025070727.zip
C:\\Users\techexcel\Downloads\06052025_1059.pdf
C:\\Users\techexcel\Downloads\06052025_1102.pdf
C:\\Users\techexcel\Downloads\06082025055507techexcel.zip
C:\\Users\techexcel\Downloads\06082025055742techexcel.zip
C:\\Users\techexcel\Downloads\06082025063600techexcel.zip
C:\\Users\techexcel\Downloads\06082025063617techexcel.zip
C:\\Users\techexcel\Downloads\06082025063914techexcel.zip
C:\\Users\techexcel\Downloads\07042025_1717.pdf
C:\\Users\techexcel\Downloads\07062025063754techexcel.zip
C:\\Users\techexcel\Downloads\07102025184808_kra.zip
C:\\Users\techexcel\Downloads\08030000.01012
C:\\Users\techexcel\Downloads\08030000.01012.enc.21.zip
C:\\Users\techexcel\Downloads\0810202501053308-10-2025130540.pdf
C:\\Users\techexcel\Downloads\09-Jun-2025_130930.zip
C:\\Users\techexcel\Downloads\09012026054810.pdf
C:\\Users\techexcel\Downloads\09042025_1900.pdf
C:\\Users\techexcel\Downloads\09092025192316.xls
C:\\Users\techexcel\Downloads\10000010_01022024132846.xls
C:\\Users\techexcel\Downloads\10000010_01022024135653.xls
C:\\Users\techexcel\Downloads\10012025114854techexcel.zip
C:\\Users\techexcel\Downloads\10012025115711techexcel.zip
C:\\Users\techexcel\Downloads\10012025115730techexcel.zip
C:\\Users\techexcel\Downloads\10012025115747techexcel.zip
C:\\Users\techexcel\Downloads\10012025115824techexcel.zip
C:\\Users\techexcel\Downloads\10012025120513.pdf
C:\\Users\techexcel\Downloads\10012025124800techexcel.zip
C:\\Users\techexcel\Downloads\10062025055743.pdf
C:\\Users\techexcel\Downloads\101101110228_29052025110240.xls
C:\\Users\techexcel\Downloads\101101112441_29052025112446.xls
C:\\Users\techexcel\Downloads\101101113205_29052025113209.xls
C:\\Users\techexcel\Downloads\101121134059_02012026134059.xls
C:\\Users\techexcel\Downloads\10122025125917.zip
C:\\Users\techexcel\Downloads\11030000.04284.enc.13.zip
C:\\Users\techexcel\Downloads\11030000.04285.enc.21.zip
C:\\Users\techexcel\Downloads\111.txt
C:\\Users\techexcel\Downloads\11112025014036techexcel.zip
C:\\Users\techexcel\Downloads\11112025014810techexcel.zip
C:\\Users\techexcel\Downloads\11112025023640techexcel.zip
C:\\Users\techexcel\Downloads\12062025031901.zip
C:\\Users\techexcel\Downloads\12062025043735.zip
C:\\Users\techexcel\Downloads\12062025044936.zip
C:\\Users\techexcel\Downloads\12092023041014.zip
C:\\Users\techexcel\Downloads\12092023041811\0\AAACL0963A_11092023_01.zip
C:\\Users\techexcel\Downloads\12092023041811\ICCL\AAACL0963A_11092023_01.csv
C:\\Users\techexcel\Downloads\12092023041811\ICCL\AAACL0963A_11092023_01.zip
C:\\Users\techexcel\Downloads\12092023041811\MCX\AAACL0963A_11092023_01.zip
C:\\Users\techexcel\Downloads\12092023041811.zip
C:\\Users\techexcel\Downloads\1222180359_05012026180400.xls
C:\\Users\techexcel\Downloads\13022025020834.zip
C:\\Users\techexcel\Downloads\13022025042245.zip
C:\\Users\techexcel\Downloads\13030000.01240.enc.34.zip
C:\\Users\techexcel\Downloads\13030000.01241.enc.42.zip
C:\\Users\techexcel\Downloads\13030000.01244.enc.21.zip
C:\\Users\techexcel\Downloads\13030000.01245.enc.34.zip
C:\\Users\techexcel\Downloads\13030000.01246.enc.42.zip
C:\\Users\techexcel\Downloads\13032025022936.zip
C:\\Users\techexcel\Downloads\13032025023047.zip
C:\\Users\techexcel\Downloads\13032025_162158.zip
C:\\Users\techexcel\Downloads\13082025043107techexcel.zip
C:\\Users\techexcel\Downloads\13102025071324.zip
C:\\Users\techexcel\Downloads\13102025071646.zip
C:\\Users\techexcel\Downloads\14012025_122430.zip
C:\\Users\techexcel\Downloads\14022024_0.zip
C:\\Users\techexcel\Downloads\14022025105904.pdf
C:\\Users\techexcel\Downloads\14082024052616.zip
C:\\Users\techexcel\Downloads\14082024102839.zip
C:\\Users\techexcel\Downloads\14102025072547.zip
C:\\Users\techexcel\Downloads\14148632821.tcl
C:\\Users\techexcel\Downloads\15052025_1349.pdf
C:\\Users\techexcel\Downloads\15092025012507.zip
C:\\Users\techexcel\Downloads\15092025013320.zip
C:\\Users\techexcel\Downloads\15092025013729.zip
C:\\Users\techexcel\Downloads\15092025034250techexcel.zip
C:\\Users\techexcel\Downloads\15092025041531techexcel.zip
C:\\Users\techexcel\Downloads\15092025041640techexcel.zip
C:\\Users\techexcel\Downloads\15092025041705techexcel.zip
C:\\Users\techexcel\Downloads\15092025051740techexcel.zip
C:\\Users\techexcel\Downloads\15092025051832techexcel.zip
C:\\Users\techexcel\Downloads\15092025121958.zip
C:\\Users\techexcel\Downloads\15092025122950.zip
C:\\Users\techexcel\Downloads\15092025123546.zip
C:\\Users\techexcel\Downloads\15770340001410_1690873412746.txt\15770340001410_1690873412746.txt
C:\\Users\techexcel\Downloads\15770340001410_1718171711094.txt.gz
C:\\Users\techexcel\Downloads\15770340001410_1718172335844.txt.gz
C:\\Users\techexcel\Downloads\15770340001410_1718185345852.txt.gz
C:\\Users\techexcel\Downloads\15770340001410_20240130_1706605438544
C:\\Users\techexcel\Downloads\15770340001410_20240130_1706605438544.gz
C:\\Users\techexcel\Downloads\16072025054123.zip
C:\\Users\techexcel\Downloads\16102025100158.zip
C:\\Users\techexcel\Downloads\17102024013244\MTFCollatralScripDetails_17102024013244.csv
C:\\Users\techexcel\Downloads\17102024013244\MTFFundingScripDetails_17102024013244.csv
C:\\Users\techexcel\Downloads\17102024013244\MTFTradedFundedScripDetails_17102024013244.csv
C:\\Users\techexcel\Downloads\17102024013244\MTF_17102024013244.csv
C:\\Users\techexcel\Downloads\17102024013244.zip
C:\\Users\techexcel\Downloads\17102025103214.zip
C:\\Users\techexcel\Downloads\17102025104049.zip
C:\\Users\techexcel\Downloads\17102025_1434.pdf
C:\\Users\techexcel\Downloads\17102025_1706.pdf
C:\\Users\techexcel\Downloads\17102025_1711.pdf
C:\\Users\techexcel\Downloads\18030000.03012024.01240.enc.00.zip
C:\\Users\techexcel\Downloads\18030000.03012024.01241.enc.00.zip
C:\\Users\techexcel\Downloads\18030000.03012024.01244.enc.00.zip
C:\\Users\techexcel\Downloads\18030000.03012024.01245.enc.00.zip
C:\\Users\techexcel\Downloads\18030000.03012024.01246.enc.00.zip
C:\\Users\techexcel\Downloads\18030000.04032025.94892.enc.33.zip
C:\\Users\techexcel\Downloads\18030000.17112023.91511.enc.33.zip
C:\\Users\techexcel\Downloads\18030000.17112023.91511.zip
C:\\Users\techexcel\Downloads\18030000.21072023.90316.enc.11.zip
C:\\Users\techexcel\Downloads\18062025043605.zip
C:\\Users\techexcel\Downloads\18062025055521.zip
C:\\Users\techexcel\Downloads\18062025062733.zip
C:\\Users\techexcel\Downloads\18062025063052.zip
C:\\Users\techexcel\Downloads\18062025063643.zip
C:\\Users\techexcel\Downloads\18062025114756.pdf
C:\\Users\techexcel\Downloads\18112025065552.pdf
C:\\Users\techexcel\Downloads\1812030000.24022025.02337.enc.00.zip
C:\\Users\techexcel\Downloads\1812030000.24022025.02337.zip
C:\\Users\techexcel\Downloads\19052025035331techexcel.zip
C:\\Users\techexcel\Downloads\19052025040745techexcel.zip
C:\\Users\techexcel\Downloads\19052025040814techexcel.zip
C:\\Users\techexcel\Downloads\19062025012647.zip
C:\\Users\techexcel\Downloads\19062025060451.zip
C:\\Users\techexcel\Downloads\19092024_0.zip
C:\\Users\techexcel\Downloads\19092024_02.zip
C:\\Users\techexcel\Downloads\19092025_16112378948_0_0288722538614.pdf
C:\\Users\techexcel\Downloads\19092025_18096192059_0_0291487134875.pdf
C:\\Users\techexcel\Downloads\19112024_1611.pdf
C:\\Users\techexcel\Downloads\19112024_1622.pdf
C:\\Users\techexcel\Downloads\2002_03112025162641.xls
C:\\Users\techexcel\Downloads\2002_techexcel_03112025_04263536929710_042725.pdf
C:\\Users\techexcel\Downloads\20052025052749techexcel.zip
C:\\Users\techexcel\Downloads\20052025052815techexcel.zip
C:\\Users\techexcel\Downloads\20052025052836techexcel.zip
C:\\Users\techexcel\Downloads\20102025_1240.pdf
C:\\Users\techexcel\Downloads\2024-09-26=- 123030
C:\\Users\techexcel\Downloads\2024-09-26=- 123307
C:\\Users\techexcel\Downloads\20240729_040602_624963.zip
C:\\Users\techexcel\Downloads\20240729_043014_9825573 (1).zip
C:\\Users\techexcel\Downloads\20240729_043014_9825573.zip
C:\\Users\techexcel\Downloads\20240729_045510_2130526.zip
C:\\Users\techexcel\Downloads\20240729_045607_2135288.zip
C:\\Users\techexcel\Downloads\21012025083629.pdf
C:\\Users\techexcel\Downloads\21032025070747techexcel.zip
C:\\Users\techexcel\Downloads\2180_18022025_035935350700_TECHEXCEL.csv
C:\\Users\techexcel\Downloads\2188_20012024_12022372904830_TECHEXCEL.xls
C:\\Users\techexcel\Downloads\22092023122043.zip
C:\\Users\techexcel\Downloads\22092025010640.zip
C:\\Users\techexcel\Downloads\22092025013553.zip
C:\\Users\techexcel\Downloads\22092025014018.zip
C:\\Users\techexcel\Downloads\22092025033336.zip
C:\\Users\techexcel\Downloads\22092025041247.zip
C:\\Users\techexcel\Downloads\22092025045005.zip
C:\\Users\techexcel\Downloads\23012025014231techexcel.zip
C:\\Users\techexcel\Downloads\23012025014309techexcel.zip
C:\\Users\techexcel\Downloads\23012025014652techexcel.zip
C:\\Users\techexcel\Downloads\23012025080034.pdf
C:\\Users\techexcel\Downloads\23012025081351.pdf
C:\\Users\techexcel\Downloads\23092025_1619.pdf
C:\\Users\techexcel\Downloads\23092025_1815.pdf
C:\\Users\techexcel\Downloads\23092025_1903.pdf
C:\\Users\techexcel\Downloads\23092025_1905.pdf
C:\\Users\techexcel\Downloads\23102024044136.zip
C:\\Users\techexcel\Downloads\23102024045338.zip
C:\\Users\techexcel\Downloads\24012025015720.pdf
C:\\Users\techexcel\Downloads\24012025042556.pdf
C:\\Users\techexcel\Downloads\24012025060240.pdf
C:\\Users\techexcel\Downloads\24012025063307.pdf
C:\\Users\techexcel\Downloads\24012025064943.pdf
C:\\Users\techexcel\Downloads\24012025065154.pdf
C:\\Users\techexcel\Downloads\24012025123707.pdf
C:\\Users\techexcel\Downloads\24042025010346techexcel.zip
C:\\Users\techexcel\Downloads\24042025015049techexcel.zip
C:\\Users\techexcel\Downloads\24042025061213.zip
C:\\Users\techexcel\Downloads\24042025122904techexcel.zip
C:\\Users\techexcel\Downloads\24042025125930techexcel.zip
C:\\Users\techexcel\Downloads\24092025020827.zip
C:\\Users\techexcel\Downloads\2409202502143624-09-2025141442.pdf
C:\\Users\techexcel\Downloads\24092025022928.zip
C:\\Users\techexcel\Downloads\24092025023022.zip
C:\\Users\techexcel\Downloads\24092025023233.zip
C:\\Users\techexcel\Downloads\25062025124839.xls
C:\\Users\techexcel\Downloads\25062025125017.xls
C:\\Users\techexcel\Downloads\25072025_1345.pdf
C:\\Users\techexcel\Downloads\25082025022835MCX.pdf
C:\\Users\techexcel\Downloads\25102023\BFX_MGTM0408.M02
C:\\Users\techexcel\Downloads\25102023\EQ_MRTM_0408.M02
C:\\Users\techexcel\Downloads\25102023\F_MRG_TM_23102023_02.csv
C:\\Users\techexcel\Downloads\25102023\Margin_25102023_061449.zip
C:\\Users\techexcel\Downloads\25102023\MCX_MARGIN_20231023_.M02
C:\\Users\techexcel\Downloads\25102023\MG408.M02
C:\\Users\techexcel\Downloads\25102023\X_MRG_TM_23102023_02.csv
C:\\Users\techexcel\Downloads\25112024_150525.zip
C:\\Users\techexcel\Downloads\25112025084529.zip
C:\\Users\techexcel\Downloads\26052025040513techexcel.zip
C:\\Users\techexcel\Downloads\26052025040552techexcel.zip
C:\\Users\techexcel\Downloads\26052025040611techexcel.zip
C:\\Users\techexcel\Downloads\26052025045623techexcel.zip
C:\\Users\techexcel\Downloads\26052025124042techexcel.zip
C:\\Users\techexcel\Downloads\26112025040512.zip
C:\\Users\techexcel\Downloads\27062025060013techexcel.zip
C:\\Users\techexcel\Downloads\27062025060038techexcel.zip
C:\\Users\techexcel\Downloads\27062025060111techexcel.zip
C:\\Users\techexcel\Downloads\27062025121045techexcel.zip
C:\\Users\techexcel\Downloads\27092024115427techexcel.zip
C:\\Users\techexcel\Downloads\28022025115408.pdf
C:\\Users\techexcel\Downloads\28022025115605.pdf
C:\\Users\techexcel\Downloads\28022025115832.pdf
C:\\Users\techexcel\Downloads\28022025121915.pdf
C:\\Users\techexcel\Downloads\28072025054125.zip
C:\\Users\techexcel\Downloads\287_16122024_07331423372054843612_TECHEXCEL.xls
C:\\Users\techexcel\Downloads\29042025031721techexcel.zip
C:\\Users\techexcel\Downloads\29042025031742techexcel.zip
C:\\Users\techexcel\Downloads\29042025032028techexcel.zip
C:\\Users\techexcel\Downloads\29072023052629\BSE_20230728.csv
C:\\Users\techexcel\Downloads\29072023052629\BSE_20230728.xls
C:\\Users\techexcel\Downloads\29072024043541.zip
C:\\Users\techexcel\Downloads\29102025_1221.pdf
C:\\Users\techexcel\Downloads\29122025095012.pdf
C:\\Users\techexcel\Downloads\29122025095635.zip
C:\\Users\techexcel\Downloads\29122025101341.zip
C:\\Users\techexcel\Downloads\29122025103856.zip
C:\\Users\techexcel\Downloads\30012025111821\boltPlusStk1_29012025_01_DDPBowl.csv
C:\\Users\techexcel\Downloads\30012025111821\boltPlusStk2_29012025_01_DT1Bowl.csv
C:\\Users\techexcel\Downloads\30012025111821\boltPlusSurveillance_29012025_01_DDepbow.csv
C:\\Users\techexcel\Downloads\30012025111821\ODINStk1_29012025_01_DCUS.txt
C:\\Users\techexcel\Downloads\30012025111821\ODINStk2_29012025_01_DPOAP.txt
C:\\Users\techexcel\Downloads\30012025111821\ODINStk3_29012025_01_DSAR.txt
C:\\Users\techexcel\Downloads\30012025111821\ODINStk4_29012025_01_DMTF.txt
C:\\Users\techexcel\Downloads\30012025111821\ODINSurveillance_29012025_01depo.txt
C:\\Users\techexcel\Downloads\30012025111821\RestrictedScripList.csv
C:\\Users\techexcel\Downloads\30012025111821\SYMPHONYDeposit_29012025_01_Dcmrgn.csv
C:\\Users\techexcel\Downloads\30012025111821\SYMPHONYStk1_29012025_01_Disin.csv
C:\\Users\techexcel\Downloads\30012025111821\SYMPHONYStk2_29012025_01_Dbtst.csv
C:\\Users\techexcel\Downloads\30012025111821\SYMPHONYStk3_29012025_01_DPLEDGE.CSV
C:\\Users\techexcel\Downloads\30012025111821\SYMPHONYStk4_29012025_01_Dmtf.csv
C:\\Users\techexcel\Downloads\30012025111821\SYMPHONYStk5_29012025_01_Dtest.csv
C:\\Users\techexcel\Downloads\30012025111821\SYMPHONYStk6_29012025_01.CSV
C:\\Users\techexcel\Downloads\30012025111821\SYMPHONYStk6_29012025_01_Dlimit.csv
C:\\Users\techexcel\Downloads\30092024074400.zip
C:\\Users\techexcel\Downloads\3009202512203230-09-2025122041.pdf
C:\\Users\techexcel\Downloads\30102025_1131.pdf
C:\\Users\techexcel\Downloads\30122025111432.pdf
C:\\Users\techexcel\Downloads\30122025111757.pdf
C:\\Users\techexcel\Downloads\30122025112225.pdf
C:\\Users\techexcel\Downloads\31052025122834techexcel.zip
C:\\Users\techexcel\Downloads\31052025122959techexcel.zip
C:\\Users\techexcel\Downloads\31072023052606\BSE_20230731.csv
C:\\Users\techexcel\Downloads\31072023052606\BSE_20230731.xls
C:\\Users\techexcel\Downloads\3368160_5151438_084510.pdf.pdf
C:\\Users\techexcel\Downloads\360O\lkp.txt
C:\\Users\techexcel\Downloads\360O.zip
C:\\Users\techexcel\Downloads\40DP37U.285351
C:\\Users\techexcel\Downloads\414863820.txt
C:\\Users\techexcel\Downloads\50014022_06012025044533_68313171264032.csv
C:\\Users\techexcel\Downloads\519_1400_06092024154112.xls
C:\\Users\techexcel\Downloads\519_1400_06092024155147.xls
C:\\Users\techexcel\Downloads\519_30082024104247.xls
C:\\Users\techexcel\Downloads\519_30082024104433.xls
C:\\Users\techexcel\Downloads\64740081_Other4.pdf
C:\\Users\techexcel\Downloads\666130328_15042025130328.xls
C:\\Users\techexcel\Downloads\666130643_15042025130644.xls
C:\\Users\techexcel\Downloads\666131426_15042025131426.xls
C:\\Users\techexcel\Downloads\666131614_15042025131615.xls
C:\\Users\techexcel\Downloads\666153435_16042025153503.xls
C:\\Users\techexcel\Downloads\666192826_11062024192826.xls
C:\\Users\techexcel\Downloads\666193915_11062024193915.xls
C:\\Users\techexcel\Downloads\6A7A_2025-04-21_172025.B67
C:\\Users\techexcel\Downloads\704_13032025160829.xls
C:\\Users\techexcel\Downloads\79_17092025_0956437483837725379_TECHEXCEL.xls
C:\\Users\techexcel\Downloads\7z2409-x64.exe
C:\\Users\techexcel\Downloads\94259.zip
C:\\Users\techexcel\Downloads\94907.zip
C:\\Users\techexcel\Downloads\94914.zip
C:\\Users\techexcel\Downloads\94924.zip
C:\\Users\techexcel\Downloads\95247.zip
C:\\Users\techexcel\Downloads\95248.zip
C:\\Users\techexcel\Downloads\95249.zip
C:\\Users\techexcel\Downloads\95257.zip
C:\\Users\techexcel\Downloads\95259.zip
C:\\Users\techexcel\Downloads\95506.zip
C:\\Users\techexcel\Downloads\95594.zip
C:\\Users\techexcel\Downloads\95596.zip
C:\\Users\techexcel\Downloads\95807.zip
C:\\Users\techexcel\Downloads\960_08042025_04571965767822771431_TECHEXCEL.xls
C:\\Users\techexcel\Downloads\960_08042025_05050694716057804514_TECHEXCEL.xls
C:\\Users\techexcel\Downloads\AgeingReport__67e3e7624a863.zip
C:\\Users\techexcel\Downloads\AgeingReport__6819b42491fb6.zip
C:\\Users\techexcel\Downloads\AgeingReport__6819b81114335.zip
C:\\Users\techexcel\Downloads\AllSegment_2504202505252486659843543575.CSV
C:\\Users\techexcel\Downloads\AnnualPL_16352499_2023.pdf
C:\\Users\techexcel\Downloads\auditlog_09042025143929.xls
C:\\Users\techexcel\Downloads\auditlog_09042025143956.xls
C:\\Users\techexcel\Downloads\B0184C1E-B880-48BB-8457BC10A8580A3F.zip.zip
C:\\Users\techexcel\Downloads\BESTClient_Registration_01012000_08072024_0708202403503775071118898397.zip
C:\\Users\techexcel\Downloads\Blocklimit_0910202508500123493774411699.csv
C:\\Users\techexcel\Downloads\Blocklimit_1408202411572469002348604901.csv
C:\\Users\techexcel\Downloads\Blocklimit_1604202503483161162238428103.csv
C:\\Users\techexcel\Downloads\Blocklimit_1712202410215038726457126345.csv
C:\\Users\techexcel\Downloads\BOClosure_Latter_ACCOUNTCODE_05082024.pdf
C:\\Users\techexcel\Downloads\BOClosure_Latter_ACCOUNTCODE_17102025 (1).pdf
C:\\Users\techexcel\Downloads\BOClosure_Latter_ACCOUNTCODE_17102025.pdf
C:\\Users\techexcel\Downloads\BOClosure_Latter_ACCOUNTCODE_23092025 (1).pdf
C:\\Users\techexcel\Downloads\BOClosure_Latter_ACCOUNTCODE_23092025 (2).pdf
C:\\Users\techexcel\Downloads\BOClosure_Latter_ACCOUNTCODE_23092025 (3).pdf
C:\\Users\techexcel\Downloads\BOClosure_Latter_ACCOUNTCODE_23092025.pdf
C:\\Users\techexcel\Downloads\BOClosure_Latter_ACCOUNTCODE_24062025.pdf
C:\\Users\techexcel\Downloads\BOClosure_Latter_ACCOUNTCODE_24092025.pdf
C:\\Users\techexcel\Downloads\BOClosure_Latter_ACCOUNTCODE_25092025.pdf
C:\\Users\techexcel\Downloads\BOClosure_Latter_ACCOUNTCODE_26092025 (1).pdf
C:\\Users\techexcel\Downloads\BOClosure_Latter_ACCOUNTCODE_26092025 (2).pdf
C:\\Users\techexcel\Downloads\BOClosure_Latter_ACCOUNTCODE_26092025 (3).pdf
C:\\Users\techexcel\Downloads\BOClosure_Latter_ACCOUNTCODE_26092025 (4).pdf
C:\\Users\techexcel\Downloads\BOClosure_Latter_ACCOUNTCODE_26092025 (5).pdf
C:\\Users\techexcel\Downloads\BOClosure_Latter_ACCOUNTCODE_26092025 (6).pdf
C:\\Users\techexcel\Downloads\BOClosure_Latter_ACCOUNTCODE_26092025 (7).pdf
C:\\Users\techexcel\Downloads\BOClosure_Latter_ACCOUNTCODE_26092025 (8).pdf
C:\\Users\techexcel\Downloads\BOClosure_Latter_ACCOUNTCODE_26092025.pdf
C:\\Users\techexcel\Downloads\BOClosure_Latter_ACCOUNTCODE_30092025 (1).pdf
C:\\Users\techexcel\Downloads\BOClosure_Latter_ACCOUNTCODE_30092025 (2).pdf
C:\\Users\techexcel\Downloads\BOClosure_Latter_ACCOUNTCODE_30092025 (3).pdf
C:\\Users\techexcel\Downloads\BOClosure_Latter_ACCOUNTCODE_30092025 (4).pdf
C:\\Users\techexcel\Downloads\BOClosure_Latter_ACCOUNTCODE_30092025.pdf
C:\\Users\techexcel\Downloads\bofreeze_1812030000.24022025.02337
C:\\Users\techexcel\Downloads\BoFreeze_Letter_ACCOUNTCODE_01092023.pdf
C:\\Users\techexcel\Downloads\BoFreeze_Letter_ACCOUNTCODE_05052025.pdf
C:\\Users\techexcel\Downloads\BoFreeze_Letter_ACCOUNTCODE_05082024.pdf
C:\\Users\techexcel\Downloads\BoFreeze_Letter_ACCOUNTCODE_07062025.pdf
C:\\Users\techexcel\Downloads\BoFreeze_Letter_ACCOUNTCODE_08052025.pdf
C:\\Users\techexcel\Downloads\BoFreeze_Letter_ACCOUNTCODE_08082024 (1).pdf
C:\\Users\techexcel\Downloads\BoFreeze_Letter_ACCOUNTCODE_08082024.pdf
C:\\Users\techexcel\Downloads\BoFreeze_Letter_ACCOUNTCODE_10062025 (1).pdf
C:\\Users\techexcel\Downloads\BoFreeze_Letter_ACCOUNTCODE_10062025 (2).pdf
C:\\Users\techexcel\Downloads\BoFreeze_Letter_ACCOUNTCODE_10062025.pdf
C:\\Users\techexcel\Downloads\BoFreeze_Letter_ACCOUNTCODE_10072025 (1).pdf
C:\\Users\techexcel\Downloads\BoFreeze_Letter_ACCOUNTCODE_10072025 (2).pdf
C:\\Users\techexcel\Downloads\BoFreeze_Letter_ACCOUNTCODE_10072025 (3).pdf
C:\\Users\techexcel\Downloads\BoFreeze_Letter_ACCOUNTCODE_10072025 (4).pdf
C:\\Users\techexcel\Downloads\BoFreeze_Letter_ACCOUNTCODE_10072025 (5).pdf
C:\\Users\techexcel\Downloads\BoFreeze_Letter_ACCOUNTCODE_10072025 (6).pdf
C:\\Users\techexcel\Downloads\BoFreeze_Letter_ACCOUNTCODE_10072025.pdf
C:\\Users\techexcel\Downloads\BoFreeze_Letter_ACCOUNTCODE_12062025 (1).pdf
C:\\Users\techexcel\Downloads\BoFreeze_Letter_ACCOUNTCODE_12062025.pdf
C:\\Users\techexcel\Downloads\BoFreeze_Letter_ACCOUNTCODE_17062025 (1).pdf
C:\\Users\techexcel\Downloads\BoFreeze_Letter_ACCOUNTCODE_17062025 (2).pdf
C:\\Users\techexcel\Downloads\BoFreeze_Letter_ACCOUNTCODE_17062025.pdf
C:\\Users\techexcel\Downloads\BoFreeze_Letter_ACCOUNTCODE_19062025.pdf
C:\\Users\techexcel\Downloads\BoFreeze_Letter_ACCOUNTCODE_25062025 (1).pdf
C:\\Users\techexcel\Downloads\BoFreeze_Letter_ACCOUNTCODE_25062025 (2).pdf
C:\\Users\techexcel\Downloads\BoFreeze_Letter_ACCOUNTCODE_25062025 (3).pdf
C:\\Users\techexcel\Downloads\BoFreeze_Letter_ACCOUNTCODE_25062025 (4).pdf
C:\\Users\techexcel\Downloads\BoFreeze_Letter_ACCOUNTCODE_25062025.pdf
C:\\Users\techexcel\Downloads\BoFreeze_Letter_ACCOUNTCODE_25082023.pdf
C:\\Users\techexcel\Downloads\BoFreeze_Letter_ACCOUNTCODE_30052025.pdf
C:\\Users\techexcel\Downloads\BoFreeze_Letter_ACCOUNTCODE_31052025.pdf
C:\\Users\techexcel\Downloads\BOUNfreeze_Letter_ACCOUNTCODE_10072025 (1).pdf
C:\\Users\techexcel\Downloads\BOUNfreeze_Letter_ACCOUNTCODE_10072025 (2).pdf
C:\\Users\techexcel\Downloads\BOUNfreeze_Letter_ACCOUNTCODE_10072025 (3).pdf
C:\\Users\techexcel\Downloads\BOUNfreeze_Letter_ACCOUNTCODE_10072025.pdf
C:\\Users\techexcel\Downloads\BOUNfreeze_Letter_ACCOUNTCODE_23062025 (1).pdf
C:\\Users\techexcel\Downloads\BOUNfreeze_Letter_ACCOUNTCODE_23062025.pdf
C:\\Users\techexcel\Downloads\BOUNfreeze_Letter_ACCOUNTCODE_28072025.pdf
C:\\Users\techexcel\Downloads\BOUNfreeze_Letter_ACCOUNTCODE_31052025.pdf
C:\\Users\techexcel\Downloads\BO_UPLD_030000_202409261230_4284.csv.enc.32.zip
C:\\Users\techexcel\Downloads\BO_UPLD_030000_202409261233_4285.csv.enc.41.zip
C:\\Users\techexcel\Downloads\BO_UPLD_030000_202502110629_4624.csv.enc.41.zip
C:\\Users\techexcel\Downloads\BO_UPLD_030000_202502110646_4625.csv.enc.00.zip
C:\\Users\techexcel\Downloads\BO_UPLD_030000_202510100633_5160.csv.enc.32.zip
C:\\Users\techexcel\Downloads\BRACNH_STATUS (1).xlsx
C:\\Users\techexcel\Downloads\BSE_CASHDealerWisePOSITION_18062025.CSV
C:\\Users\techexcel\Downloads\BSE_CASHDealerWisePOSITION_19062025 (1).CSV
C:\\Users\techexcel\Downloads\BSE_CASHDealerWisePOSITION_19062025 (2).CSV
C:\\Users\techexcel\Downloads\BSE_CASHDealerWisePOSITION_19062025.CSV
C:\\Users\techexcel\Downloads\BSE_CASHPOSITION_01072025.txt
C:\\Users\techexcel\Downloads\BSE_CASHPOSITION_17062025.txt
C:\\Users\techexcel\Downloads\BulkAgeingReport_69392ab6b6a24.zip
C:\\Users\techexcel\Downloads\BulkAgeingReport_69392d51de6d0.zip
C:\\Users\techexcel\Downloads\BulkAgeingReport_69392dd7d7278.zip
C:\\Users\techexcel\Downloads\BulkAgeingReport_69392ec7680b2.zip
C:\\Users\techexcel\Downloads\Capture.JPG1.JPG
C:\\Users\techexcel\Downloads\CDSLModificationReport.pdf
C:\\Users\techexcel\Downloads\CLIENTBENMAPPING_08092025 (1).txt
C:\\Users\techexcel\Downloads\CLIENTBENMAPPING_08092025.txt
C:\\Users\techexcel\Downloads\CLIENTBENMAPPING_10072025.txt
C:\\Users\techexcel\Downloads\CLIENTBENMAPPING_18092025 (1).txt
C:\\Users\techexcel\Downloads\CLIENTBENMAPPING_18092025 (2).txt
C:\\Users\techexcel\Downloads\CLIENTBENMAPPING_18092025 (3).txt
C:\\Users\techexcel\Downloads\CLIENTBENMAPPING_18092025 (4).txt
C:\\Users\techexcel\Downloads\CLIENTBENMAPPING_18092025 (5).txt
C:\\Users\techexcel\Downloads\CLIENTBENMAPPING_18092025 (6).txt
C:\\Users\techexcel\Downloads\CLIENTBENMAPPING_18092025 (7).txt
C:\\Users\techexcel\Downloads\CLIENTBENMAPPING_18092025 (8).txt
C:\\Users\techexcel\Downloads\CLIENTBENMAPPING_18092025.txt
C:\\Users\techexcel\Downloads\CLIENTBENMAPPING_30072025.txt
C:\\Users\techexcel\Downloads\ClientHolding_09092025_162351.csv
C:\\Users\techexcel\Downloads\CLIENTMASTEREXPORT_16042025115932.xls
C:\\Users\techexcel\Downloads\CLIENTMASTEREXPORT_21112025185238.xls
C:\\Users\techexcel\Downloads\client_limit\1.schemas.sql
C:\\Users\techexcel\Downloads\client_limit\12.menu.sql
C:\\Users\techexcel\Downloads\client_limit\2.enableservices.sql
C:\\Users\techexcel\Downloads\client_limit\3.columns.sql
C:\\Users\techexcel\Downloads\client_limit\4.createservicebrokerquery.sql
C:\\Users\techexcel\Downloads\client_limit\5.createtable.sql
C:\\Users\techexcel\Downloads\client_limit\6.createview.sql
C:\\Users\techexcel\Downloads\client_limit\7.createproc.sql
C:\\Users\techexcel\Downloads\client_limit\8.createtrigger.sql
C:\\Users\techexcel\Downloads\client_limit\9.fa_accountsubtytrigger.sql
C:\\Users\techexcel\Downloads\client_limit\99.LastSql.sql
C:\\Users\techexcel\Downloads\client_limit\991.CC_Collatral_Process.sql
C:\\Users\techexcel\Downloads\client_limit\992.runproc.sql
C:\\Users\techexcel\Downloads\client_limit\999.createjob.sql
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\1_runrpt.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\2_runrpt.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\3_runrpt.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\4_runrpt.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\5_runrpt.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\6_runrpt.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\7_runrpt.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\9_runrpt.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\cocd.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\commonparam.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\company_Settings_Master.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\dynamiccss.css
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\ExchangeCol.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\filedownloadZip.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\firstindex.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\firstindex1.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\gried.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\head.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\head1.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\Help.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\Help.xlsx
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\HTML\Common.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\HTML\Common.htm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\Import.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\input.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\KYC_Allocation.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\process.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\QuertToTab.cfc
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\Query.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\report_help.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\RMS_Settings.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\Rpt.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\runrpt.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\settings.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\settings_master.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\Status.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\texthtml.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\textquery.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\Version.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\viewreport.cfm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\CC_Limit\xmlconvert.cfc
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit.htm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit.xlsx
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit.xlsx.xls
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit_files\filelist.xml
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit_files\image001.png
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit_files\image002.png
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit_files\image003.png
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit_files\image004.png
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit_files\image005.png
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit_files\image006.png
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit_files\image007.png
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit_files\image008.png
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit_files\image009.png
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit_files\image010.png
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit_files\image011.png
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit_files\image012.png
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit_files\image013.png
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit_files\image014.png
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit_files\image015.png
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit_files\image016.png
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit_files\image017.png
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit_files\image019.png
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit_files\sheet001.htm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit_files\sheet002.htm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit_files\sheet003.htm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit_files\sheet004.htm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit_files\sheet005.htm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit_files\sheet006.htm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit_files\sheet007.htm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit_files\sheet008.htm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit_files\stylesheet.css
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\CC_Limit_files\tabstrip.htm
C:\\Users\techexcel\Downloads\client_limit\FOCAPS\Help_HTML\~$CC_Limit.xlsx
C:\\Users\techexcel\Downloads\client_limit\patch update.docx
C:\\Users\techexcel\Downloads\CNSI_S2008_GRP1_74836 (1).PDF
C:\\Users\techexcel\Downloads\CNSI_S2008_GRP1_74836.PDF
C:\\Users\techexcel\Downloads\cn_OWN_25072025_grp1.pdf
C:\\Users\techexcel\Downloads\COD_EXP_30000_434993_F_202504071914_022_P0.csv
C:\\Users\techexcel\Downloads\ComplianceExport_TBParty_17092025_173410.csv
C:\\Users\techexcel\Downloads\ComplianceExport_TBParty_17092025_192911.csv
C:\\Users\techexcel\Downloads\ContractRegister_02092025_115742.csv
C:\\Users\techexcel\Downloads\ContractRegister_09012026_174814.csv
C:\\Users\techexcel\Downloads\ContractRegister_10012025_120526.csv
C:\\Users\techexcel\Downloads\ContractRegister_10062025_180559.csv
C:\\Users\techexcel\Downloads\ContractRegister_18062025_114802.csv
C:\\Users\techexcel\Downloads\ContractRegister_18112025_185555.csv
C:\\Users\techexcel\Downloads\ContractRegister_24012025_135727.csv
C:\\Users\techexcel\Downloads\ContractRegister_24012025_183318.csv
C:\\Users\techexcel\Downloads\ContractRegister_24012025_184959.csv
C:\\Users\techexcel\Downloads\ContractRegister_25082025_142849.csv
C:\\Users\techexcel\Downloads\ContractRegister_28022025_115423.csv
C:\\Users\techexcel\Downloads\ContractRegister_28022025_115624.csv
C:\\Users\techexcel\Downloads\ContractRegister_28022025_115845.csv
C:\\Users\techexcel\Downloads\ContractRegister_28022025_122604.csv
C:\\Users\techexcel\Downloads\ContractRegister_29122025_215031.csv
C:\\Users\techexcel\Downloads\ContractRegister_30122025_111439.csv
C:\\Users\techexcel\Downloads\ContractRegister_30122025_111802.csv
C:\\Users\techexcel\Downloads\ContractRegister_30122025_112230.csv
C:\\Users\techexcel\Downloads\Corporateaction_transaction_view (1).csv
C:\\Users\techexcel\Downloads\Corporateaction_transaction_view.csv
C:\\Users\techexcel\Downloads\CRTS.xlsx
C:\\Users\techexcel\Downloads\Csv_101101153903_13032025153909.csv
C:\\Users\techexcel\Downloads\Csv_101101154900_13032025154907.csv
C:\\Users\techexcel\Downloads\Csv_101101155227_13032025155253.csv
C:\\Users\techexcel\Downloads\Csv_101101160541_13032025160542.csv
C:\\Users\techexcel\Downloads\Csv_101121165210_09012026165211.csv
C:\\Users\techexcel\Downloads\Csv_101121165621_09012026165622.csv
C:\\Users\techexcel\Downloads\Csv_101121174320_05012026174320.csv
C:\\Users\techexcel\Downloads\Csv_666135318_06112025135318.csv
C:\\Users\techexcel\Downloads\Csv_666135510_06112025135547.csv
C:\\Users\techexcel\Downloads\Csv_666140208_06112025140208.csv
C:\\Users\techexcel\Downloads\Data_.csv
C:\\Users\techexcel\Downloads\DeliveryDpo_ICCL_CM_EquityT1_CM_408_20250404_F_0000 (1).CSV
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_01072025 (1).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_01072025 (2).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_01072025 (3).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_01072025 (4).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_01072025 (5).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_01072025 (6).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_01072025 (7).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_01072025 (8).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_01072025.pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_05072025 (1).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_05072025 (10).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_05072025 (11).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_05072025 (12).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_05072025 (13).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_05072025 (14).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_05072025 (15).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_05072025 (2).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_05072025 (3).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_05072025 (4).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_05072025 (5).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_05072025 (6).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_05072025 (7).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_05072025 (8).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_05072025 (9).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_05072025.pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_05082025 (1).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_05082025 (2).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_05082025 (3).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_05082025 (4).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_05082025 (5).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_05082025 (6).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_05082025 (7).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_05082025 (8).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_05082025.pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_07072025 (1).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_07072025.pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_18082025 (1).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_18082025 (2).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_18082025 (3).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_18082025 (4) (1).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_18082025 (4).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_18082025 (5).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_18082025 (6).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_18082025 (7) (1).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_18082025 (7).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_18082025 (8).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_18082025.pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_20082025 (1).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_20082025 (2).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_20082025.pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_21082025 (1).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_21082025 (2).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_21082025.pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_27052025 (1).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_27052025.pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_27062025 (1).pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_27062025.pdf
C:\\Users\techexcel\Downloads\DematAknowledgementLetter_ACCOUNTCODE_28052025.pdf
C:\\Users\techexcel\Downloads\desktop.ini
C:\\Users\techexcel\Downloads\Dhan.zip
C:\\Users\techexcel\Downloads\DPH_1203000001112625_CDSL_30122024 (1).PDF
C:\\Users\techexcel\Downloads\DPH_1203000001112625_CDSL_30122024.PDF
C:\\Users\techexcel\Downloads\DP_1203000001386945_01122025_03122025.pdf
C:\\Users\techexcel\Downloads\DP_1203000001386945_01122025_05122025 (1).pdf
C:\\Users\techexcel\Downloads\DP_1203000001386945_01122025_05122025.pdf
C:\\Users\techexcel\Downloads\DP_1203000001506182_01082024_31082024.pdf
C:\\Users\techexcel\Downloads\DP_1203000001506182_01102024_23102024.pdf
C:\\Users\techexcel\Downloads\DP_1203000001562011_01072025_19092025.pdf
C:\\Users\techexcel\Downloads\DP_1203000001562011_01092025_23092025 (1).pdf
C:\\Users\techexcel\Downloads\DP_1203000001562011_01092025_23092025.pdf
C:\\Users\techexcel\Downloads\DP_1203000001562011_21-06-2025_19092025.pdf
C:\\Users\techexcel\Downloads\DP_1203000001562011_21062025_19092025 (1).pdf
C:\\Users\techexcel\Downloads\DP_1203000001562011_21062025_19092025 (2).pdf
C:\\Users\techexcel\Downloads\DP_1203000001562011_21062025_19092025 (3).pdf
C:\\Users\techexcel\Downloads\DP_1203000001562011_21062025_19092025 (4).pdf
C:\\Users\techexcel\Downloads\DP_1203000001562011_21062025_19092025.pdf
C:\\Users\techexcel\Downloads\DVP_07200_CM_01092025 (1).csv
C:\\Users\techexcel\Downloads\DVP_07200_CM_01092025 (2).csv
C:\\Users\techexcel\Downloads\DVP_07200_CM_01092025 (3).csv
C:\\Users\techexcel\Downloads\DVP_07200_CM_01092025.csv
C:\\Users\techexcel\Downloads\DVP_408_CM_12092025 (1).csv
C:\\Users\techexcel\Downloads\DVP_408_CM_12092025 (2).csv
C:\\Users\techexcel\Downloads\DVP_408_CM_12092025.csv
C:\\Users\techexcel\Downloads\D__Techexcel__lucee_tomcat_webapps_ROOT_REPORTS__Remeshire_30042025155840.Txt
C:\\Users\techexcel\Downloads\D__Techexcel___ExportData.xls
C:\\Users\techexcel\Downloads\D__Techexcel___Reports__KRA__20250221_34776_KRA.xml
C:\\Users\techexcel\Downloads\EDIS_Report_06Jun2025_100621.csv
C:\\Users\techexcel\Downloads\getxl (1).cfm
C:\\Users\techexcel\Downloads\getxl (1).xlsx
C:\\Users\techexcel\Downloads\getxl (2).cfm
C:\\Users\techexcel\Downloads\getxl (2).xlsx
C:\\Users\techexcel\Downloads\getxl (3).xlsx
C:\\Users\techexcel\Downloads\getxl (4).xlsx
C:\\Users\techexcel\Downloads\getxl (5).xlsx
C:\\Users\techexcel\Downloads\getxl.cfm
C:\\Users\techexcel\Downloads\getxl.xlsx
C:\\Users\techexcel\Downloads\hdfcDP (1).xlsx
C:\\Users\techexcel\Downloads\hdfcDP.xlsx
C:\\Users\techexcel\Downloads\Holding_23072025.xls
C:\\Users\techexcel\Downloads\ICCL\AAACL0963A_11092023_01.zip
C:\\Users\techexcel\Downloads\ietabhelper.exe
C:\\Users\techexcel\Downloads\IN1102_0001_06102025_V1.3_techexcel_U44391.zip
C:\\Users\techexcel\Downloads\KYC.pdf
C:\\Users\techexcel\Downloads\LDWK_66020252_GRP1_22072024 (1).PDF
C:\\Users\techexcel\Downloads\LDWK_66020252_GRP1_22072024.PDF
C:\\Users\techexcel\Downloads\LKPSFTP_16062025_005.txt
C:\\Users\techexcel\Downloads\LoadBalancing-Main V2.zip
C:\\Users\techexcel\Downloads\LOGO.jpg
C:\\Users\techexcel\Downloads\MarginRegister_08102025_120113.csv
C:\\Users\techexcel\Downloads\MarginRegister_08102025_130540.csv
C:\\Users\techexcel\Downloads\MarginRegister_24092025_141442.csv
C:\\Users\techexcel\Downloads\Margin_06012026_044728.zip
C:\\Users\techexcel\Downloads\Margin_21072025_055548.zip
C:\\Users\techexcel\Downloads\Margin_22072025_113635.zip
C:\\Users\techexcel\Downloads\Margin_25102023_061449.zip
C:\\Users\techexcel\Downloads\MCX\AAACL0963A_11092023_01.zip
C:\\Users\techexcel\Downloads\MCXDealerWisePOSITION_16062025.CSV
C:\\Users\techexcel\Downloads\MCXDealerWisePOSITION_18062025 (1).CSV
C:\\Users\techexcel\Downloads\MCXDealerWisePOSITION_18062025.CSV
C:\\Users\techexcel\Downloads\MCXDealerWisePOSITION_19062025.CSV
C:\\Users\techexcel\Downloads\MCXPOSITION_01072025.txt
C:\\Users\techexcel\Downloads\MCXPOSITION_16062025.txt
C:\\Users\techexcel\Downloads\MCXPOSITION_17062025 (1).txt
C:\\Users\techexcel\Downloads\MCXPOSITION_17062025 (2).txt
C:\\Users\techexcel\Downloads\MCXPOSITION_17062025 (3).txt
C:\\Users\techexcel\Downloads\MCXPOSITION_17062025 (4).txt
C:\\Users\techexcel\Downloads\MCXPOSITION_17062025 (5).txt
C:\\Users\techexcel\Downloads\MCXPOSITION_17062025.txt
C:\\Users\techexcel\Downloads\MCXPOSITION_23062025 (1).txt
C:\\Users\techexcel\Downloads\MCXPOSITION_23062025 (2).txt
C:\\Users\techexcel\Downloads\MCXPOSITION_23062025.txt
C:\\Users\techexcel\Downloads\MicrosoftEdgeSetup.exe
C:\\Users\techexcel\Downloads\mirae_02092025.pdf
C:\\Users\techexcel\Downloads\ML_ACCOUNTCODE_05032025.pdf
C:\\Users\techexcel\Downloads\ML_ACCOUNTCODE_07012025.pdf
C:\\Users\techexcel\Downloads\ML_ACCOUNTCODE_18022025.pdf
C:\\Users\techexcel\Downloads\ModificationLetter_ACCOUNTCODE_19052025 (1).pdf
C:\\Users\techexcel\Downloads\ModificationLetter_ACCOUNTCODE_19052025.pdf
C:\\Users\techexcel\Downloads\ModificationLetter_ACCOUNTCODE_21012025 (1).pdf
C:\\Users\techexcel\Downloads\ModificationLetter_ACCOUNTCODE_21012025 (2).pdf
C:\\Users\techexcel\Downloads\ModificationLetter_ACCOUNTCODE_21012025.pdf
C:\\Users\techexcel\Downloads\MTF_01082024_05082024_144559689.csv
C:\\Users\techexcel\Downloads\MTF_07012026_07012026_190811501.csv
C:\\Users\techexcel\Downloads\MTF_07012026_07012026_191115911.csv
C:\\Users\techexcel\Downloads\MTF_07012026_07012026_192714635.csv
C:\\Users\techexcel\Downloads\MTF_07012026_07012026_195542297.csv
C:\\Users\techexcel\Downloads\MTF_22082024_28082024_114543514.csv
C:\\Users\techexcel\Downloads\MTF_SaleProcess_unPledge_05012026_06012026_170407965.csv
C:\\Users\techexcel\Downloads\mt_12005294_10012025_grp1.pdf
C:\\Users\techexcel\Downloads\new 21.txt
C:\\Users\techexcel\Downloads\New_Boclosure_02057 (1).zip
C:\\Users\techexcel\Downloads\New_Boclosure_02057 (2).zip
C:\\Users\techexcel\Downloads\New_Boclosure_02057.zip
C:\\Users\techexcel\Downloads\New_BoFreeze_02337 (1).zip
C:\\Users\techexcel\Downloads\New_BoFreeze_02337.zip
C:\\Users\techexcel\Downloads\NinstDashboard03032025054240.xls
C:\\Users\techexcel\Downloads\NinstDashboard03032025062248.xls
C:\\Users\techexcel\Downloads\NinstDashboard03032025062329.xls
C:\\Users\techexcel\Downloads\NinstDashboard04032025061324.xls
C:\\Users\techexcel\Downloads\NinstDashboard04032025063256.xls
C:\\Users\techexcel\Downloads\NinstDashboard04032025065040.xls
C:\\Users\techexcel\Downloads\NinstDashboard05032025110939.xls
C:\\Users\techexcel\Downloads\NinstDashboard05032025112114.xls
C:\\Users\techexcel\Downloads\NinstDashboard05032025112511.xls
C:\\Users\techexcel\Downloads\NinstDashboard05032025112642.xls
C:\\Users\techexcel\Downloads\NinstDashboard05032025112758.xls
C:\\Users\techexcel\Downloads\NinstDashboard05032025113614.xls
C:\\Users\techexcel\Downloads\NinstDashboard05032025113958.xls
C:\\Users\techexcel\Downloads\NinstDashboard05032025114243.xls
C:\\Users\techexcel\Downloads\NinstDashboard05032025114332.xls
C:\\Users\techexcel\Downloads\NinstDashboard05032025115337.xls
C:\\Users\techexcel\Downloads\NinstDashboard05032025115621.xls
C:\\Users\techexcel\Downloads\NinstDashboard05032025120103.xls
C:\\Users\techexcel\Downloads\NinstDashboard06032025040545.xls
C:\\Users\techexcel\Downloads\NinstDashboard06032025040919.xls
C:\\Users\techexcel\Downloads\NinstDashboard06032025041154.xls
C:\\Users\techexcel\Downloads\NinstDashboard06032025045822.xls
C:\\Users\techexcel\Downloads\NinstDashboard27022025071846.xls
C:\\Users\techexcel\Downloads\NinstDashboard27022025073114.xls
C:\\Users\techexcel\Downloads\NinstDashboard27082024120528.xls
C:\\Users\techexcel\Downloads\NinstDashboard28022025022726.csv
C:\\Users\techexcel\Downloads\NinstDashboard28022025023917.csv
C:\\Users\techexcel\Downloads\NinstDashboard28022025024057.csv
C:\\Users\techexcel\Downloads\NinstDashboard28022025035526.csv
C:\\Users\techexcel\Downloads\NinstDashboard28022025042115.xls
C:\\Users\techexcel\Downloads\NinstDashboard28022025124546.xls
C:\\Users\techexcel\Downloads\npp.8.7.7.Installer.x64 (1).exe
C:\\Users\techexcel\Downloads\npp.8.7.7.Installer.x64.exe
C:\\Users\techexcel\Downloads\nsdl-ss-user-setup-3.0.0.exe
C:\\Users\techexcel\Downloads\nsdl-ss-user-setup-3.0.0.zip
C:\\Users\techexcel\Downloads\NSE_COMDealerWisePOSITION_26122024.CSV
C:\\Users\techexcel\Downloads\NSE_FNODealerWisePOSITION_13022025.CSV
C:\\Users\techexcel\Downloads\NSE_FNODealerWisePOSITION_31012025.CSV
C:\\Users\techexcel\Downloads\NSE_FNOPOSITION_04112025.txt
C:\\Users\techexcel\Downloads\Obligation_ICCL_CM_EquityT1_TM_0408_20240805_F_0000.CSV
C:\\Users\techexcel\Downloads\ODINClient_Registration_01011900 (1).zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_01011900 (2).zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_01011900 (3).zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_01011900 (4).zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_01011900.zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_01012000 (1).zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_01012000 (2).zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_01012000.zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_01012020 (1).zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_01012020.zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_01012024.zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_01012025.zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_04012000 (1).zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_04012000.zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_04012020 (1).zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_04012020 (10).zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_04012020 (2).zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_04012020 (3).zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_04012020 (4).zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_04012020 (5).zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_04012020 (6).zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_04012020 (7).zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_04012020 (8).zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_04012020 (9).zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_04012020.zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_04012022 (1).zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_04012022 (2).zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_04012022.zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_04012025.zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_04042025.zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_07042025.zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_10041900.zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_10062020.zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_12102025 (1).zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_12102025.zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_12112022.zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_24112025 (1).zip
C:\\Users\techexcel\Downloads\ODINClient_Registration_24112025.zip
C:\\Users\techexcel\Downloads\OutPut.txt
C:\\Users\techexcel\Downloads\PayinShort_AllRePledge_09092025_103929517.csv
C:\\Users\techexcel\Downloads\payoutdata_1706202512204539096588090855.csv
C:\\Users\techexcel\Downloads\payoutdata_221220250617377454995535687.csv
C:\\Users\techexcel\Downloads\payoutdata_250420250612008180989891118.csv
C:\\Users\techexcel\Downloads\payoutdata_2912202511330625828983901430.csv
C:\\Users\techexcel\Downloads\payoutdata_2912202511353445454367562631.csv
C:\\Users\techexcel\Downloads\PDF_10000010_techexcel_01022024_0123507849767928374.PDF
C:\\Users\techexcel\Downloads\PDF_101121142228_techexcel_09012026_02222873764779219783.PDF
C:\\Users\techexcel\Downloads\PDF_666130317_techexcel_16122025_01032468034341963684.PDF
C:\\Users\techexcel\Downloads\PennyDrop_042102.xls
C:\\Users\techexcel\Downloads\PennyDrop_112516.xls
C:\\Users\techexcel\Downloads\PennyDrop_113224.xls
C:\\Users\techexcel\Downloads\PennyDrop_123419.xls
C:\\Users\techexcel\Downloads\PennyDrop_123548.xls
C:\\Users\techexcel\Downloads\PledgerLatter_ACCOUNTCODE_05062025.pdf
C:\\Users\techexcel\Downloads\PledgerLatter_ACCOUNTCODE_06062025.pdf
C:\\Users\techexcel\Downloads\PledgerLatter_ACCOUNTCODE_07072025.pdf
C:\\Users\techexcel\Downloads\PledgerLatter_ACCOUNTCODE_28052025.pdf
C:\\Users\techexcel\Downloads\Pledge_P_BSE_26122024_84_15217.zip
C:\\Users\techexcel\Downloads\Postman-win64-Setup.exe
C:\\Users\techexcel\Downloads\POTM_408_20240614-01.CSV
C:\\Users\techexcel\Downloads\PTA_reporting_21042025_408.csv
C:\\Users\techexcel\Downloads\Readable-BO_UPLD_030000_202409261230_4284.csv
C:\\Users\techexcel\Downloads\Readable-BO_UPLD_030000_202409261233_4285.csv
C:\\Users\techexcel\Downloads\Readable-BO_UPLD_030000_202502110629_4624.csv
C:\\Users\techexcel\Downloads\Readable-BO_UPLD_030000_202502110646_4625.csv
C:\\Users\techexcel\Downloads\Readable-BO_UPLD_030000_202510100633_5160.csv
C:\\Users\techexcel\Downloads\Readable_18030000_17112023_161526
C:\\Users\techexcel\Downloads\Readable_18_03012024_190151
C:\\Users\techexcel\Downloads\Readable_18_03012024_190627
C:\\Users\techexcel\Downloads\Readable_18_03012024_190942
C:\\Users\techexcel\Downloads\Readable_18_03012024_191048
C:\\Users\techexcel\Downloads\Readable_18_03012024_191712
C:\\Users\techexcel\Downloads\ReadReadable-TXN_UPLD_030000_202506060131_44509.csv
C:\\Users\techexcel\Downloads\ReadReadable-TXN_UPLD_030000_202506060249_44518.csv
C:\\Users\techexcel\Downloads\ReadReadable-TXN_UPLD_030000_202506060250_44519.csv
C:\\Users\techexcel\Downloads\ReadReadable-TXN_UPLD_030000_202506090109_44588.csv
C:\\Users\techexcel\Downloads\Read_18030000.04032025.94892
C:\\Users\techexcel\Downloads\Read_18030000.21072023.90316
C:\\Users\techexcel\Downloads\Read_18030000.21072023.90320
C:\\Users\techexcel\Downloads\RetentionStatement.json
C:\\Users\techexcel\Downloads\RL_23071380_GRP1_03012025 (2).PDF
C:\\Users\techexcel\Downloads\RL_23071380_GRP1_03012025 (7).PDF
C:\\Users\techexcel\Downloads\RL_COB30_GRP1_07022025 (1).PDF
C:\\Users\techexcel\Downloads\RL_COB30_GRP1_07022025.PDF
C:\\Users\techexcel\Downloads\RosStatement_6711ffcef3e70.zip
C:\\Users\techexcel\Downloads\SAS1115_Other3.pdf
C:\\Users\techexcel\Downloads\SAS1115_Other4.pdf
C:\\Users\techexcel\Downloads\ScripList (1).csv
C:\\Users\techexcel\Downloads\ScripList.csv
C:\\Users\techexcel\Downloads\script.sql
C:\\Users\techexcel\Downloads\SCRIP_091225.TXT
C:\\Users\techexcel\Downloads\SearchResults (67).xlsx
C:\\Users\techexcel\Downloads\SearchResults (77).xlsx
C:\\Users\techexcel\Downloads\SearchResults (86).xlsx
C:\\Users\techexcel\Downloads\SellBeneficiaryReport__67dcfd3311018.zip
C:\\Users\techexcel\Downloads\SellBeneficiaryReport__67ecc81c43e52.zip
C:\\Users\techexcel\Downloads\SellBeneficiaryReport__67ecce27cf091.zip
C:\\Users\techexcel\Downloads\Sms_Template (1).xlsx
C:\\Users\techexcel\Downloads\Sms_Template.xlsx
C:\\Users\techexcel\Downloads\SQLServer2019-KB5007182-x64.exe
C:\\Users\techexcel\Downloads\StampDuty_ICCL_FO_FOPHY_TM_408_20250529_F_0000.CSV
C:\\Users\techexcel\Downloads\STT_ICCL_FO_FOPHY_TM_408_20250529_F_0000.CSV
C:\\Users\techexcel\Downloads\SYMPHONYClient_Registration_09012025_09092025_0909202505452898204352731171.zip
C:\\Users\techexcel\Downloads\SYMPHONYClient_Registration_09032025_09032025_090920250547308645143528178.zip
C:\\Users\techexcel\Downloads\SYMPHONYClient_Registration_09032025_09032025_0909202507410698936913191447.zip
C:\\Users\techexcel\Downloads\S_STC_JAN2024_27122023.csv
C:\\Users\techexcel\Downloads\Trade Summary with Exp_05122023_024111.xls
C:\\Users\techexcel\Downloads\Trade Summary with Exp_05122023_024437.xls
C:\\Users\techexcel\Downloads\Trade_NSE_CO_0_TM_11297_20241217_F_0000.csv
C:\\Users\techexcel\Downloads\TXN_UPLD_030000_202506060249_44518.csv.enc.12
C:\\Users\techexcel\Downloads\TXN_UPLD_030000_202506060249_44518.csv.enc.12.zip
C:\\Users\techexcel\Downloads\TXN_UPLD_030000_202506060250_44519.csv.enc.00
C:\\Users\techexcel\Downloads\TXN_UPLD_030000_202506060250_44519.csv.enc.00.zip
C:\\Users\techexcel\Downloads\TXN_UPLD_030000_202506090109_44588.csv.enc.12
C:\\Users\techexcel\Downloads\UnBlocklimit_0910202508500123493774411699.csv
C:\\Users\techexcel\Downloads\UnBlocklimit_1408202411572469002348604901.csv
C:\\Users\techexcel\Downloads\UnBlocklimit_1604202503483161162238428103.csv
C:\\Users\techexcel\Downloads\UnBlocklimit_1712202410215038726457126345.csv
C:\\Users\techexcel\Downloads\VC_redist.x64.exe
C:\\Users\techexcel\Downloads\VN240425.TXT
C:\\Users\techexcel\Downloads\VN250425.TXT
C:\\Users\techexcel\Downloads\Web Alloc0635.xlsx
C:\\Users\techexcel\Downloads\WelComeLatters (1).pdf
C:\\Users\techexcel\Downloads\WelComeLatters (2).pdf
C:\\Users\techexcel\Downloads\WelComeLatters (3).pdf
C:\\Users\techexcel\Downloads\WelComeLatters (4).pdf
C:\\Users\techexcel\Downloads\WelComeLatters (5).pdf
C:\\Users\techexcel\Downloads\WelComeLatters (6).pdf
C:\\Users\techexcel\Downloads\WelComeLatters (7).pdf
C:\\Users\techexcel\Downloads\WelComeLatters.pdf
C:\\Users\techexcel\Downloads\WelcomeLetter_2025-03-10_052158_1707208.zip
C:\\Users\techexcel\Downloads\WelcomeLetter_2025-04-05_013318_1682161.zip
C:\\Users\techexcel\Downloads\WelcomeLetter_2025-04-11_050527_7398391.zip
C:\\Users\techexcel\Downloads\WelcomeLetter_2025-04-11_051819_948136 (1).zip
C:\\Users\techexcel\Downloads\WelcomeLetter_2025-04-11_051819_948136 (2).zip
C:\\Users\techexcel\Downloads\WelcomeLetter_2025-04-11_051819_948136.zip
C:\\Users\techexcel\Downloads\WelcomeLetter_2025-04-11_053759_9670449.zip
C:\\Users\techexcel\Downloads\WinMerge-2.16.28-x64-Setup\WinMerge-2.16.28-x64-Setup.exe
C:\\Users\techexcel\Downloads\WinMerge-2.16.28-x64-Setup.exe
C:\\Users\techexcel\Downloads\WinMerge-2.16.28-x64-Setup.zip
C:\\Users\techexcel\Downloads\WL_ACCOUNTCODE_14062024.pdf
C:\\Users\techexcel\Downloads\WL_ACCOUNTCODE_18062024 (1).pdf
C:\\Users\techexcel\Downloads\WL_ACCOUNTCODE_18062024 (2).pdf
C:\\Users\techexcel\Downloads\WL_ACCOUNTCODE_18062024 (3).pdf
C:\\Users\techexcel\Downloads\WL_ACCOUNTCODE_18062024.pdf
C:\\Users\techexcel\Downloads\WL_ACCOUNTCODE_19012024.pdf
C:\\Users\techexcel\Downloads\WL_ACCOUNTCODE_25072025 (1).pdf
C:\\Users\techexcel\Downloads\WL_ACCOUNTCODE_25072025 (2).pdf
C:\\Users\techexcel\Downloads\WL_ACCOUNTCODE_25072025.pdf
C:\\Users\techexcel\Downloads\xlsx_10000010_techexcel_01022024_01275593108538802003.xlsx
C:\\Users\techexcel\Downloads\xlsx_10000010_techexcel_01022024_0156124643102910740.xlsx
C:\\Users\techexcel\Downloads\xlsx_1000012_techexcel_12062024_05504169890387012031.csv
C:\\Users\techexcel\Downloads\xlsx_1000012_techexcel_12062024_06044067343398617519.csv
C:\\Users\techexcel\Downloads\xlsx_1000112_techexcel_20112025_07363991378313350024.csv
C:\\Users\techexcel\Downloads\xlsx_101121172254_techexcel_09012026_05225458828719577002.xlsx
C:\\Users\techexcel\Downloads\xlsx_5000022_techexcel_06122025_04354461476086295732.csv
C:\\Users\techexcel\Downloads\xlsx_5014129_techexcel_30042025_12544648389933068861.csv
C:\\Users\techexcel\Downloads\xlsx_666130255_techexcel_15042025_01025559577721308998.xlsx
C:\\Users\techexcel\Downloads\xlsx_666130722_techexcel_15042025_01072391994683639289.xlsx
C:\\Users\techexcel\Downloads\xlsx_666130843_techexcel_15042025_01084343282893953413.xlsx
C:\\Users\techexcel\Downloads\xlsx_666131256_techexcel_15042025_01125719661865389989.xlsx
C:\\Users\techexcel\Downloads\xlsx_666151055_techexcel_22042025_03105721362753370308.xlsx
C:\\Users\uatlkp\Downloads\desktop.ini

Download folder content report attached.
92431 - User Shell Folders Settings
-
Synopsis
Nessus was able to find the folder paths for user folders on the remote host.
Description
Nessus was able to gather a list of settings from the target system that store common user folder locations. A few of the more common locations are listed below :

- Administrative Tools
- AppData
- Cache
- CD Burning
- Cookies
- Desktop
- Favorites
- Fonts
- History
- Local AppData
- My Music
- My Pictures
- My Video
- NetHood
- Personal
- PrintHood
- Programs
- Recent
- SendTo
- Start Menu
- Startup
- Templates
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/16
Plugin Output

tcp/0

S-1-5-21-1185746460-1788592564-4118236249-1002
- {7d1d3a04-debb-4115-95cf-2f29da2920da} : C:\Users\techapp\Searches
- {1b3ea5dc-b587-4786-b4ef-bd1dc332aeae} : C:\Users\techapp\AppData\Roaming\Microsoft\Windows\Libraries
- {374de290-123f-4565-9164-39c4925e467b} : C:\Users\techapp\Downloads
- recent : C:\Users\techapp\AppData\Roaming\Microsoft\Windows\Recent
- my video : C:\Users\techapp\Videos
- my music : C:\Users\techapp\Music
- {56784854-c6cb-462b-8169-88e350acb882} : C:\Users\techapp\Contacts
- {bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968} : C:\Users\techapp\Links
- {a520a1a4-1780-4ff6-bd18-167343c5af16} : C:\Users\techapp\AppData\LocalLow
- sendto : C:\Users\techapp\AppData\Roaming\Microsoft\Windows\SendTo
- start menu : C:\Users\techapp\AppData\Roaming\Microsoft\Windows\Start Menu
- cookies : C:\Users\techapp\AppData\Local\Microsoft\Windows\INetCookies
- personal : C:\Users\techapp\Documents
- administrative tools : C:\Users\techapp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
- startup : C:\Users\techapp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
- nethood : C:\Users\techapp\AppData\Roaming\Microsoft\Windows\Network Shortcuts
- history : C:\Users\techapp\AppData\Local\Microsoft\Windows\History
- {4c5c32ff-bb9d-43b0-b5b4-2d72e54eaaa4} : C:\Users\techapp\Saved Games
- {00bcfc5a-ed94-4e48-96a1-3f6217f21990} : C:\Users\techapp\AppData\Local\Microsoft\Windows\RoamingTiles
- !do not use this registry key : Use the SHGetFolderPath or SHGetKnownFolderPath function instead
- local appdata : C:\Users\techapp\AppData\Local
- my pictures : C:\Users\techapp\Pictures
- templates : C:\Users\techapp\AppData\Roaming\Microsoft\Windows\Templates
- printhood : C:\Users\techapp\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
- cache : C:\Users\techapp\AppData\Local\Microsoft\Windows\INetCache
- desktop : C:\Users\techapp\Desktop
- programs : C:\Users\techapp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
- fonts : C:\Windows\Fonts
- cd burning : C:\Users\techapp\AppData\Local\Microsoft\Windows\Burn\Burn
- favorites : C:\Users\techapp\Favorites
- appdata : C:\Users\techapp\AppData\Roaming

Production
- {7d1d3a04-debb-4115-95cf-2f29da2920da} : C:\Users\Administrator\Searches
- {1b3ea5dc-b587-4786-b4ef-bd1dc332aeae} : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Libraries
- {374de290-123f-4565-9164-39c4925e467b} : C:\Users\Administrator\Downloads
- recent : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Recent
- my video : C:\Users\Administrator\Videos
- my music : C:\Users\Administrator\Music
- {56784854-c6cb-462b-8169-88e350acb882} : C:\Users\Administrator\Contacts
- {bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968} : C:\Users\Administrator\Links
- {a520a1a4-1780-4ff6-bd18-167343c5af16} : C:\Users\Administrator\AppData\LocalLow
- sendto : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\SendTo
- start menu : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu
- cookies : C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCookies
- personal : C:\Users\Administrator\Documents
- administrative tools : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
- startup : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
- nethood : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Network Shortcuts
- history : C:\Users\Administrator\AppData\Local\Microsoft\Windows\History
- {4c5c32ff-bb9d-43b0-b5b4-2d72e54eaaa4} : C:\Users\Administrator\Saved Games
- {00bcfc5a-ed94-4e48-96a1-3f6217f21990} : C:\Users\Administrator\AppData\Local\Microsoft\Windows\RoamingTiles
- !do not use this registry key : Use the SHGetFolderPath or SHGetKnownFolderPath function instead
- local appdata : C:\Users\Administrator\AppData\Local
- my pictures : C:\Users\Administrator\Pictures
- templates : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates
- printhood : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
- cache : C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache
- desktop : C:\Users\Administrator\Desktop
- programs : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
- fonts : C:\Windows\Fonts
- cd burning : C:\Users\Administrator\AppData\Local\Microsoft\Windows\Burn\Burn
- favorites : C:\Users\Administrator\Favorites
- appdata : C:\Users\Administrator\AppData\Roaming

techexcel
- {7d1d3a04-debb-4115-95cf-2f29da2920da} : C:\Users\techexcel\Searches
- {1b3ea5dc-b587-4786-b4ef-bd1dc332aeae} : C:\Users\techexcel\AppData\Roaming\Microsoft\Windows\Libraries
- {374de290-123f-4565-9164-39c4925e467b} : C:\Users\techexcel\Downloads
- recent : C:\Users\techexcel\AppData\Roaming\Microsoft\Windows\Recent
- my video : C:\Users\techexcel\Videos
- my music : C:\Users\techexcel\Music
- {56784854-c6cb-462b-8169-88e350acb882} : C:\Users\techexcel\Contacts
- {bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968} : C:\Users\techexcel\Links
- {a520a1a4-1780-4ff6-bd18-167343c5af16} : C:\Users\techexcel\AppData\LocalLow
- sendto : C:\Users\techexcel\AppData\Roaming\Microsoft\Windows\SendTo
- start menu : C:\Users\techexcel\AppData\Roaming\Microsoft\Windows\Start Menu
- cookies : C:\Users\techexcel\AppData\Local\Microsoft\Windows\INetCookies
- personal : C:\Users\techexcel\Documents
- administrative tools : C:\Users\techexcel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
- startup : C:\Users\techexcel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
- nethood : C:\Users\techexcel\AppData\Roaming\Microsoft\Windows\Network Shortcuts
- history : C:\Users\techexcel\AppData\Local\Microsoft\Windows\History
- {4c5c32ff-bb9d-43b0-b5b4-2d72e54eaaa4} : C:\Users\techexcel\Saved Games
- {00bcfc5a-ed94-4e48-96a1-3f6217f21990} : C:\Users\techexcel\AppData\Local\Microsoft\Windows\RoamingTiles
- !do not use this registry key : Use the SHGetFolderPath or SHGetKnownFolderPath function instead
- local appdata : C:\Users\techexcel\AppData\Local
- my pictures : C:\Users\techexcel\Pictures
- templates : C:\Users\techexcel\AppData\Roaming\Microsoft\Windows\Templates
- printhood : C:\Users\techexcel\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
- cache : C:\Users\techexcel\AppData\Local\Microsoft\Windows\INetCache
- desktop : C:\Users\techexcel\Desktop
- programs : C:\Users\techexcel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
- fonts : C:\Windows\Fonts
- cd burning : C:\Users\techexcel\AppData\Local\Microsoft\Windows\Burn\Burn
- favorites : C:\Users\techexcel\Favorites
- appdata : C:\Users\techexcel\AppData\Roaming
92435 - UserAssist Execution History
-
Synopsis
Nessus was able to enumerate program execution history on the remote host.
Description
Nessus was able to gather evidence from the UserAssist registry key that has a list of programs that have been executed.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2019/11/12
Plugin Output

tcp/0

microsoft.autogenerated.{c804bba7-fa5f-cbf7-8b55-2096e5f972cb}
tsvn.tsvn.1.tortoiseproc2d313792337dc0ce988407e3198d0899
d:\techexcel\lucee\tomcat\webapps\root\panv4\pan_verification_v4_custom\p2j.bat
microsoft.autogenerated.{1bacf67e-7d6f-7cde-188d-98418bad9c2a}
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\windowspowershell\v1.0\powershell.exe
f:\techexcel setup\raid card\hp raid cp031007.exe
d:\techexcel\installer\dataforliverisk-nse\dataforliverisk.exe
d:\techexcel\chromeprofiles\google chrome 1.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\visualsvn\visualsvn server manager.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\system tools\task manager.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\microsoft edge.lnk
c:\users\techexcel\desktop\google chrome.lnk
c:\users\techexcel\downloads\npp.8.7.7.installer.x64.exe
microsoft.internetexplorer.default
c:\users\public\desktop\ireport-5.5.0.lnk
c:\users\techexcel\desktop\mimikatz.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\services.lnk
c:\users\techexcel\downloads\winmerge-2.16.28-x64-setup.exe
f:\techexcel setup\raid card\cp057857.exe
d:\techexcel\lucee\tomcat\webapps\root\depository\7za.exe
microsoft.windows.mediaplayer32
msedge
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft\edgeupdate\1.3.197.27\microsoftedgeupdate.exe
{6d809377-6af0-444b-8957-a3773f02200e}\notepad++\updater\gup.exe
f:\techexcel setup\raid card\cp036448.exe
d:\techexcel\lucee\tomcat\webapps\root\focaps\masters\newkyc\pan_verification_v4_custom\pkcs7gen_latest.bat
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\postman\postman.lnk
d:\techexcel\lucee\tomcat\bin\luceew.exe
c:\users\techexcel\desktop\postman.lnk
com.squirrel.postman.postman
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\notepad++.lnk
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\accessories\notepad.lnk
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft\edgeupdate\microsoftedgeupdate.exe
d:\techexcel\chromeprofiles\google chrome 2.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\paint.lnk
microsoft.autogenerated.{a16c4efe-38da-ef82-3713-fad638cfb297}
d:\techexcel\jenkins\install\freefilesync_12.1_windows_setup.exe
cyber protect monitor
c:\users\techexcel\documents\chromeprofiles\google chrome 1.lnk
ueme_ctlsession
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\system tools\command prompt.lnk
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\windows powershell\windows powershell ise.lnk
d:\techexcel\postman\postman-win64-8.11.1-setup.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\wscript.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\cmd.exe
thingamahoochie.winmerge
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\calc.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\notepad.exe
c:\users\techexcel\downloads\nsdl-ss-user-setup-3.0.0.exe
c:\users\techexcel\appdata\local\temp\{9f8293c4-0307-40a8-beaa-6afbd312ba85}\cpqsetup.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\windows powershell\windows powershell.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\servermanager.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\system tools\administrative tools.lnk
embarcadero.desktoptoasts.5513caf9
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\conhost.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\microsoft sql server management studio 18.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\msconfig.exe
d:\techexcel\installer\dataforliverisk\dataforliverisk.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\microsoft sql server tools 18\performance tools\sql server profiler 18.lnk
d:\techexcel setup\treesizefreesetup.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\dxdiag.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\notepad.lnk
f:\techexcel setup\iiscryptowithtls1.3.exe
d:\techexcel\lucee\tomcat\bin\tomcat9w.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\snipping tool.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\services.exe
c:\users\techexcel\desktop\google chrome 2.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\snippingtool.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\google chrome.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\sessionmsg.exe
d:\techexcel\lucee\tomcat\webapps\root\focaps\ireport\pan_verification\1.bat
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\eventvwr.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\msiexec.exe
c:\users\techexcel\desktop\test\closevscode.bat
d:\techexcel\lucee02\tomcat\bin\luceew02.exe
c:\users\techexcel\appdata\local\temp\~nsu1.tmp\un.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\jam software\treesize free\treesizefree.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\task scheduler.lnk
d:\techexcel\lucee\tomcat\webapps\root\cdsl_acc_opening\cdsl_bosetup_java\cdsl_authtoken.bat
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\notepad++\updater\gup.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\systempropertiesremote.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\common files\java\java update\jucheck.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\iis manager.lnk
chrome.session1.default
d:\techexcel setup\wkhtmltox-0.11.0_rc1-installer.exe
c:\users\techexcel\downloads\ietabhelper.exe
{6d809377-6af0-444b-8957-a3773f02200e}\microsoft\azureattestservice\azureattestserviceinstaller.exe
d:\techexcel setup\wkhtmltox-0.12.2.1_msvc2013-win64.exe
c:\users\techexcel\desktop\test\closepostman.bat
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\rundll32.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\registry editor.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\winrar\winrar.lnk
{6d809377-6af0-444b-8957-a3773f02200e}\notepad++\notepad++.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\microsoft sql server tools 18\microsoft sql server management studio 18.lnk
microsoft.windows.remotedesktop
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft sql server management studio 18\common7\ide\ssms.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\acronis\acronis cyber protect monitor.lnk
d:\techexcel setup\sqlpatch_prerequisite\sql_patch_cu26\sqlserver2019-kb5035123-x64.exe
microsoft.windows.computer
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\easeofaccessdialog.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\computer management.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\odbcad32.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\mspaint.exe
d:\as-ssd-benchmark2.0.7316\as ssd benchmark.exe
d:\techexcel setup\done\client\setup.exe
microsoft.windows.cortana_cw5n1h2txyewy!cortanaui
d:\techexcel\lucee02\tomcat\bin\luceew.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\oracle - oraclient11g_home1\configuration and migration tools\net manager.lnk
d:\techexcel setup\sqlserver2019-kb5033688-x64_a781728ac862e8cd97c508314f3ea4886b70bd84.exe
{d65231b0-b2f1-4857-a4ce-a8e7c6ea7d27}\encrypt.exe
{6d809377-6af0-444b-8957-a3773f02200e}\7-zip\7zg.exe
{6d809377-6af0-444b-8957-a3773f02200e}\git\adobecheck.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\windows nt\accessories\wordpad.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\system tools\control panel.lnk
d:\techexcel\loadbalancing\lucee11\tomcat\bin\lucee11w.exe
d:\5420b421b7822689c103563a58\x64\scenarioengine.exe
{6d809377-6af0-444b-8957-a3773f02200e}\realvnc\vnc4\vncaddrbook.exe
microsoft.autogenerated.{8abd94fb-e7d6-84a6-a997-c918edde0ae5}
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\msinfo32.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\openwith.exe
d:\techexcel\lucee\tomcat\webapps\root\copyimage.bat
c:\users\techexcel\downloads\7z2409-x64.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\telnet.exe
{d65231b0-b2f1-4857-a4ce-a8e7c6ea7d27}\notepad.exe
c:\users\techexcel\appdata\local\temp\{7f66dbc0-52a1-47b1-bc2e-7d2754682d70}\cpqsetup.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\event viewer.lnk
{f38bf404-1d43-42f2-9305-67de0b28fc23}\regedit.exe
d:\techexcel\chromeprofiles\google chrome 3.lnk
f:\techexcel setup\dataforliverisksetup\dataforliverisk\dataforliverisk.exe
d:\techexcelappbackup\winscp\winscp\winscp.exe
d:\techexcel\lucee\ajp13\connector_setup.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\server manager.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\hpe system tools\hpe lights-out online configuration utility\hpe lights-out online configuration utility.lnk
d:\techexcel\lucee02\tomcat\bin\tomcat9.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\internet explorer.lnk
microsoft.windows.apprep.chxapp_cw5n1h2txyewy!app
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\notepad++\notepad++.lnk
c:\users\techexcel\appdata\local\temp\4\npp.8.7.5.installer.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\accessories\internet explorer.lnk
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\file explorer.lnk
g:\as-ssd-benchmark2.0.7316\as ssd benchmark.exe
f:\lkpsoft\sqlserver2019-kb5049296-x64.exe
f:\techexcel setup\smsniff-x64\smsniff.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\jaspersoft\ireport-5.5.0\bin\ireport.exe
f:\00aa8595c4843e9b99\x64\scenarioengine.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\visual studio code\visual studio code.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\systempropertiescomputername.exe
{6d809377-6af0-444b-8957-a3773f02200e}\winrar\winrar.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\system tools\file explorer.lnk
c:\users\public\desktop\microsoft edge.lnk
{6d809377-6af0-444b-8957-a3773f02200e}\windows nt\accessories\wordpad.exe
microsoft.autogenerated.{bd3f924e-55fb-a1ba-9de6-b50f9f2460ac}
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\services.msc
microsoft.windows.administrativetools
microsoft.autogenerated.{bb044bfd-25b7-2faa-22a8-6371a93e0456}
microsoft.windows.explorer
microsoft.autogenerated.{923dd477-5846-686b-a659-0fccd73851a8}
c:\users\techexcel\desktop\google chrome 3.lnk
microsoft.windows.windowsinstaller
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\win32calc.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\google chrome.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\calculator.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\systempropertiesadvanced.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft sql server management studio 18\common7\profiler.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\remote desktop connection.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\inetsrv\inetmgr.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\windowspowershell\v1.0\powershell_ise.exe
microsoft.windows.shell.rundialog
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\microsoft sql server 2019\configuration tools\sql server 2019 configuration manager.lnk
c:\users\techexcel\desktop\google chrome 1.lnk
d:\techexcel\program files\visualsvn server\bin\visualsvn server.msc
c:\users\public\desktop\notepad++.lnk
{6d809377-6af0-444b-8957-a3773f02200e}\7-zip\7zfm.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\mmc.exe
chrome.session3.default
d:\techexcel\phpapp\install\composer-setup.exe
microsoft.windows.controlpanel
{d65231b0-b2f1-4857-a4ce-a8e7c6ea7d27}\odbcad32.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\realvnc\vnc viewer.lnk
c:\users\techexcel\appdata\local\temp\{840fce47-7ab1-4354-8268-eb8834d1ee71}\cpqsetup.exe
c:\users\techexcel\desktop\visual studio code.lnk
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft sql server management studio 18\common7\ide\controlservice.exe
microsoft.autogenerated.{c1c6f8ac-40a3-0f5c-146f-65a9dc70bbb4}
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft sql server management studio 18\common7\dtashell.exe
d:\techexcel_dp\install_2\nssm.exe
d:\techexcel\installer\dataforliverisk-cdbse\dataforliverisk.exe
c:\users\public\desktop\google chrome.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\system tools\smart storage administrator\smart storage administrator.lnk
c:\users\techexcel\appdata\local\temp\2\{690c3478-9a0a-4899-a15e-dd3b4683531d}\.cr\vc_redist.x64.exe
chrome.devtoolsapp
microsoft.windows.shellexperiencehost_cw5n1h2txyewy!app
chrome
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\winver.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\notepad++\notepad++.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\lucee\lucee-tomcat service control.lnk
c:\users\techexcel\downloads\vc_redist.x64.exe
ueme_ctlcuacount:ctor
c:\users\techexcel\downloads\microsoftedgesetup.exe
microsoft.visualstudiocode
d:\techexcel\lucee02\tomcat\bin\lucee02w.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\msdt.exe
c:\users\techexcel\desktop\test\startchrome.bat
c:\users\techexcel\appdata\local\squirreltemp\update.exe
{6d809377-6af0-444b-8957-a3773f02200e}\realvnc\vnc4\vncviewer.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\realvnc\vnc address book.lnk
c:\users\techexcel\appdata\local\temp\{5a557cf3-0dce-442f-9823-7dab0cced0d0}\cpqsetup.exe
d:\techexcel\lucee02\tomcat\bin\lucee02.exe
d:\techexcelappbackup\runbatchnew.bat
d:\techexcel\lucee\tomcat\bin\tomcat9.exe
{6d809377-6af0-444b-8957-a3773f02200e}\hewlett packard enterprise\hponcfg\hponcfg_gui.exe
{6d809377-6af0-444b-8957-a3773f02200e}\smart storage administrator\ssa\bin\ssaclient.exe
windows.immersivecontrolpanel_cw5n1h2txyewy!microsoft.windows.immersivecontrolpanel
c:\users\techexcel\desktop\test\openvscode.bat
g:\65033f54b826dc45350132769966\x64\scenarioengine.exe
c:\users\techexcel\desktop\test\closechrome.bat
microsoft.autogenerated.{2c18cdd1-cf26-19b4-988a-862fc5db076a}
d:\techexcel\jenkins\install\git-2.39.0.2-64-bit.exe
d:\techexcel\jenkins\git-2.47.1.2-64-bit.exe
chrome.session2.default
microsoft.autogenerated.{c804bba7-fa5f-cbf7-8b55-2096e5f972cb}
microsoft.autogenerated.{4f89591c-2dec-4562-d5af-e921c65273b4}
tsvn.tsvn.1.tortoiseproc2d313792337dc0ce988407e3198d0899
d:\techexcel\lucee\tomcat\webapps\root\panv4\pan_verification_v4_custom\p2j.bat
microsoft.autogenerated.{1bacf67e-7d6f-7cde-188d-98418bad9c2a}
microsoft.autogenerated.{21a0406e-7390-4dba-8e06-a6804c6dd1c9}
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\windowspowershell\v1.0\powershell.exe
f:\techexcel setup\raid card\hp raid cp031007.exe
c:\users\administrator\desktop\liverisk exe\dataforliverisk.exe - bse_cd_fno.lnk
d:\techexcel\installer\dataforliverisk-nse\dataforliverisk.exe
d:\techexcel\chromeprofiles\google chrome 1.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\visualsvn\visualsvn server manager.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\system tools\task manager.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\microsoft edge.lnk
c:\users\techexcel\desktop\google chrome.lnk
c:\users\techexcel\downloads\npp.8.7.7.installer.x64.exe
microsoft.internetexplorer.default
c:\users\public\desktop\ireport-5.5.0.lnk
c:\users\techexcel\desktop\mimikatz.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\services.lnk
c:\users\techexcel\downloads\winmerge-2.16.28-x64-setup.exe
f:\techexcel setup\raid card\cp057857.exe
d:\techexcel\lucee\tomcat\webapps\root\depository\7za.exe
microsoft.windows.mediaplayer32
msedge
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft\edgeupdate\1.3.197.27\microsoftedgeupdate.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\credwiz.exe
{6d809377-6af0-444b-8957-a3773f02200e}\notepad++\updater\gup.exe
f:\techexcel setup\raid card\cp036448.exe
d:\techexcel\lucee\tomcat\webapps\root\focaps\masters\newkyc\pan_verification_v4_custom\pkcs7gen_latest.bat
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\postman\postman.lnk
d:\techexcel\lucee\tomcat\bin\luceew.exe
c:\users\techexcel\desktop\postman.lnk
com.squirrel.postman.postman
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\notepad++.lnk
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\accessories\notepad.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\treesize free\treesize free.lnk
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft\edgeupdate\microsoftedgeupdate.exe
d:\techexcel\chromeprofiles\google chrome 2.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\system tools\smart storage administrator\smart storage administrator preferences.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\paint.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\shutdown.exe
c:\users\administrator\appdata\local\temp\4\jds179862218.tmp\jre-8u401-windows-au.exe
microsoft.autogenerated.{a16c4efe-38da-ef82-3713-fad638cfb297}
d:\techexcel\jenkins\install\freefilesync_12.1_windows_setup.exe
cyber protect monitor
c:\users\techexcel\documents\chromeprofiles\google chrome 1.lnk
ueme_ctlsession
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\system tools\command prompt.lnk
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\google\update\googleupdate.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\windows powershell\windows powershell ise.lnk
d:\techexcel\postman\postman-win64-8.11.1-setup.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\wscript.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\cmd.exe
thingamahoochie.winmerge
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\wuauclt.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\calc.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\notepad.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\ping.exe
c:\users\techexcel\downloads\nsdl-ss-user-setup-3.0.0.exe
c:\users\techexcel\appdata\local\temp\{9f8293c4-0307-40a8-beaa-6afbd312ba85}\cpqsetup.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\windows powershell\windows powershell.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\servermanager.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\system tools\administrative tools.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\azure data studio\azure data studio.lnk
embarcadero.desktoptoasts.5513caf9
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\conhost.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\microsoft sql server management studio 18.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\msconfig.exe
d:\techexcel\installer\dataforliverisk\dataforliverisk.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\microsoft sql server tools 18\performance tools\sql server profiler 18.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\security configuration management.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\pnputil.exe
d:\techexcel setup\treesizefreesetup.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\dxdiag.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\notepad.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\system tools\smart storage administrator cli\smart storage administrator cli.lnk
c:\users\administrator\appdata\local\temp\4\jds136978156.tmp\jre-8u471-windows-au.exe
f:\techexcel setup\iiscryptowithtls1.3.exe
d:\techexcel\lucee\tomcat\bin\tomcat9w.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\snipping tool.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\services.exe
microsoft.autogenerated.{18c6f720-abae-a6ef-86ec-0e72549f6916}
c:\users\administrator\desktop\kes agent mover.bat
c:\users\administrator\appdata\local\temp\3\jds192075609.tmp\jre-8u431-windows-au.exe
c:\users\techexcel\desktop\google chrome 2.lnk
f:\lkpsoft\acroniscyberprotect_agentforwindows_web.exe
microsoft.windows.sechealthui_cw5n1h2txyewy!sechealthui
d:\lkpsoft\acroniscyberprotect_agentforwindows_web.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\snippingtool.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\google chrome.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\sessionmsg.exe
c:\users\administrator\desktop\liverisk exe\dataforliverisk.exe - shortcut (2).lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\hpe system tools\hp lights-out online configuration utility\hp lights-out online configuration utility.lnk
d:\techexcel\lucee\tomcat\webapps\root\focaps\ireport\pan_verification\1.bat
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\eventvwr.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\msiexec.exe
d:\chromesetup (1).exe
c:\users\techexcel\desktop\test\closevscode.bat
\\192.168.10.234\soft\real vnc 4.6.1 enterprise edition\vnc-e4_6_1-x86_x64_win32.exe
d:\techexcel\lucee02\tomcat\bin\luceew02.exe
c:\users\techexcel\appdata\local\temp\~nsu1.tmp\un.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\jam software\treesize free\treesizefree.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\task scheduler.lnk
d:\techexcel\lucee\tomcat\webapps\root\cdsl_acc_opening\cdsl_bosetup_java\cdsl_authtoken.bat
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\notepad++\updater\gup.exe
c:\users\administrator\downloads\cp049491.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\systempropertiesremote.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\common files\java\java update\jucheck.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\cleanmgr.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\iis manager.lnk
chrome.session1.default
d:\techexcel setup\wkhtmltox-0.11.0_rc1-installer.exe
c:\users\techexcel\downloads\ietabhelper.exe
{6d809377-6af0-444b-8957-a3773f02200e}\realvnc\vnc4\vncconfig.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\google\temp\guma8b8.tmp\googleupdate.exe
{6d809377-6af0-444b-8957-a3773f02200e}\microsoft\azureattestservice\azureattestserviceinstaller.exe
d:\techexcel setup\wkhtmltox-0.12.2.1_msvc2013-win64.exe
{6d809377-6af0-444b-8957-a3773f02200e}\smart storage administrator\ssa\bin\ssaprefs.exe
c:\users\techexcel\desktop\test\closepostman.bat
\\192.168.10.135\lkpsoft\software\winrar-x64-590.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\rundll32.exe
d:\launch_sum.bat
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\registry editor.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\winrar\winrar.lnk
d:\lkpsoft\kesav+netagent_13.2.0.1511_11.11.0.452\installer.exe
{6d809377-6af0-444b-8957-a3773f02200e}\notepad++\notepad++.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\microsoft sql server tools 18\microsoft sql server management studio 18.lnk
microsoft.windows.remotedesktop
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft sql server management studio 18\common7\ide\ssms.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\acronis\acronis cyber protect monitor.lnk
d:\techexcel setup\sqlpatch_prerequisite\sql_patch_cu26\sqlserver2019-kb5035123-x64.exe
microsoft.windows.computer
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\easeofaccessdialog.exe
c:\users\administrator\appdata\local\temp\7e84303f-3461-46b8-a4fa-aff6dffc07e2\cyber_cloud_uninstaller_enterprise.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\computer management.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\odbcad32.exe
kasperskylab.kis.ui.toasts
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\mspaint.exe
d:\as-ssd-benchmark2.0.7316\as ssd benchmark.exe
d:\techexcel setup\done\client\setup.exe
microsoft.windows.cortana_cw5n1h2txyewy!cortanaui
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\wusa.exe
d:\techexcel\lucee02\tomcat\bin\luceew.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\oracle - oraclient11g_home1\configuration and migration tools\net manager.lnk
d:\techexcel setup\sqlserver2019-kb5033688-x64_a781728ac862e8cd97c508314f3ea4886b70bd84.exe
{d65231b0-b2f1-4857-a4ce-a8e7c6ea7d27}\encrypt.exe
{6d809377-6af0-444b-8957-a3773f02200e}\7-zip\7zg.exe
{6d809377-6af0-444b-8957-a3773f02200e}\git\adobecheck.exe
microsoft.autogenerated.{40815e86-5702-c2c8-a620-1ed06b4da7ee}
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\windows nt\accessories\wordpad.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\system tools\control panel.lnk
{6d809377-6af0-444b-8957-a3773f02200e}\microsoft sql server\150\setup bootstrap\sql2019\x64\landingpage.exe
d:\techexcel\loadbalancing\lucee11\tomcat\bin\lucee11w.exe
d:\5420b421b7822689c103563a58\x64\scenarioengine.exe
{6d809377-6af0-444b-8957-a3773f02200e}\realvnc\vnc4\vncaddrbook.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\microsoft sql server 2019\configuration tools\sql server 2019 installation center (64-bit).lnk
microsoft.autogenerated.{8abd94fb-e7d6-84a6-a997-c918edde0ae5}
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\msinfo32.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\openwith.exe
microsoft.autogenerated.{5b29b9ae-8060-1960-9833-2f50c0175c01}
d:\techexcel\lucee\tomcat\webapps\root\copyimage.bat
c:\users\techexcel\downloads\7z2409-x64.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\telnet.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\iisreset.exe
{d65231b0-b2f1-4857-a4ce-a8e7c6ea7d27}\notepad.exe
c:\users\techexcel\appdata\local\temp\{7f66dbc0-52a1-47b1-bc2e-7d2754682d70}\cpqsetup.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\event viewer.lnk
{f38bf404-1d43-42f2-9305-67de0b28fc23}\regedit.exe
d:\techexcel\chromeprofiles\google chrome 3.lnk
f:\techexcel setup\dataforliverisksetup\dataforliverisk\dataforliverisk.exe
d:\techexcelappbackup\winscp\winscp\winscp.exe
d:\techexcel\lucee\ajp13\connector_setup.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\compmgmt.msc
c:\users\administrator\desktop\liverisk exe\dataforliverisk.exe - shortcut.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\server manager.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\hpe system tools\hpe lights-out online configuration utility\hpe lights-out online configuration utility.lnk
d:\techexcel\lucee02\tomcat\bin\tomcat9.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\internet explorer.lnk
microsoft.windows.apprep.chxapp_cw5n1h2txyewy!app
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\notepad++\notepad++.lnk
c:\users\techexcel\appdata\local\temp\4\npp.8.7.5.installer.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\accessories\internet explorer.lnk
c:\users\administrator\desktop\liverisk exe\dataforliverisk.exe - nse.lnk
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\file explorer.lnk
g:\as-ssd-benchmark2.0.7316\as ssd benchmark.exe
f:\lkpsoft\sqlserver2019-kb5049296-x64.exe
{6d809377-6af0-444b-8957-a3773f02200e}\realvnc\vnc4\printer driver\printerinst.exe
f:\techexcel setup\smsniff-x64\smsniff.exe
c:\users\administrator\appdata\local\temp\3\jds169221031.tmp\jre-8u381-windows-au.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\jaspersoft\ireport-5.5.0\bin\ireport.exe
microsoft.azuredatastudio
f:\00aa8595c4843e9b99\x64\scenarioengine.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\visual studio code\visual studio code.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\systempropertiescomputername.exe
{6d809377-6af0-444b-8957-a3773f02200e}\winrar\winrar.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\system tools\file explorer.lnk
c:\users\public\desktop\microsoft edge.lnk
{6d809377-6af0-444b-8957-a3773f02200e}\windows nt\accessories\wordpad.exe
microsoft.autogenerated.{bd3f924e-55fb-a1ba-9de6-b50f9f2460ac}
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\services.msc
\\192.168.10.234\soft\winrar-x64-590.exe
microsoft.windows.administrativetools
microsoft.autogenerated.{bb044bfd-25b7-2faa-22a8-6371a93e0456}
microsoft.windows.explorer
microsoft.autogenerated.{923dd477-5846-686b-a659-0fccd73851a8}
c:\users\techexcel\desktop\google chrome 3.lnk
microsoft.windows.windowsinstaller
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\win32calc.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\google chrome.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\calculator.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\systempropertiesadvanced.exe
c:\users\administrator\appdata\local\temp\1\{6ea8a649-68ab-4d3b-95f4-5e6224faccbd}\cpqsetup.exe
{6d809377-6af0-444b-8957-a3773f02200e}\smart storage administrator\ssacli\bin\ssacli.exe
{6d809377-6af0-444b-8957-a3773f02200e}\sut\bin\sut.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft sql server management studio 18\common7\profiler.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\remote desktop connection.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\inetsrv\inetmgr.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\windowspowershell\v1.0\powershell_ise.exe
c:\users\administrator\downloads\cp048819.exe
c:\users\administrator\appdata\local\temp\1\{0df3a5c5-3053-49c1-9108-b76a74230bee}\cpqsetup.exe
microsoft.windows.shell.rundialog
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\microsoft sql server 2019\configuration tools\sql server 2019 configuration manager.lnk
c:\users\techexcel\desktop\google chrome 1.lnk
d:\techexcel\program files\visualsvn server\bin\visualsvn server.msc
c:\users\public\desktop\notepad++.lnk
{6d809377-6af0-444b-8957-a3773f02200e}\7-zip\7zfm.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\mmc.exe
chrome.session3.default
f:\lkpsoft\winrar-x64-701.exe
d:\techexcel\phpapp\install\composer-setup.exe
d:\lkpsoft\ppinventory\ppinfo.exe
microsoft.windows.controlpanel
c:\users\administrator\desktop\microsoft sql server management studio 18.lnk
c:\users\administrator\appdata\local\temp\~nsu1.tmp\un.exe
{d65231b0-b2f1-4857-a4ce-a8e7c6ea7d27}\odbcad32.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\realvnc\vnc viewer.lnk
c:\users\techexcel\appdata\local\temp\{840fce47-7ab1-4354-8268-eb8834d1ee71}\cpqsetup.exe
c:\users\techexcel\desktop\visual studio code.lnk
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft sql server management studio 18\common7\ide\controlservice.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\shrpubw.exe
microsoft.autogenerated.{c1c6f8ac-40a3-0f5c-146f-65a9dc70bbb4}
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft sql server management studio 18\common7\dtashell.exe
d:\techexcel_dp\install_2\nssm.exe
d:\techexcel\installer\dataforliverisk-cdbse\dataforliverisk.exe
c:\users\public\desktop\google chrome.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\system tools\smart storage administrator\smart storage administrator.lnk
c:\users\techexcel\appdata\local\temp\2\{690c3478-9a0a-4899-a15e-dd3b4683531d}\.cr\vc_redist.x64.exe
chrome.devtoolsapp
d:\lkpsoft\sanernow_lkp_window_cm_windows_x86_6.3\sanernow_windows_x86_6.3.exe
microsoft.windows.shellexperiencehost_cw5n1h2txyewy!app
chrome
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\lucee\tomcat host config.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\winver.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\credentialuibroker.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\notepad++\notepad++.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\lucee\lucee-tomcat service control.lnk
c:\users\techexcel\downloads\vc_redist.x64.exe
c:\users\administrator\appdata\local\temp\1\{7113d22b-0cbe-4c70-8cc8-d38983628e2f}\cpqsetup.exe
ueme_ctlcuacount:ctor
c:\users\techexcel\downloads\microsoftedgesetup.exe
microsoft.visualstudiocode
d:\techexcel\lucee02\tomcat\bin\lucee02w.exe
microsoft.autogenerated.{42b20eb6-a399-75e3-7fe2-4122e5903011}
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\msdt.exe
c:\users\techexcel\desktop\test\startchrome.bat
c:\users\techexcel\appdata\local\squirreltemp\update.exe
{6d809377-6af0-444b-8957-a3773f02200e}\realvnc\vnc4\vncviewer.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\realvnc\vnc address book.lnk
c:\users\techexcel\appdata\local\temp\{5a557cf3-0dce-442f-9823-7dab0cced0d0}\cpqsetup.exe
d:\techexcel\lucee02\tomcat\bin\lucee02.exe
d:\techexcelappbackup\runbatchnew.bat
d:\techexcel\lucee\tomcat\bin\tomcat9.exe
{6d809377-6af0-444b-8957-a3773f02200e}\hewlett packard enterprise\hponcfg\hponcfg_gui.exe
{6d809377-6af0-444b-8957-a3773f02200e}\smart storage administrator\ssa\bin\ssaclient.exe
windows.immersivecontrolpanel_cw5n1h2txyewy!microsoft.windows.immersivecontrolpanel
c:\users\techexcel\desktop\test\openvscode.bat
c:\users\administrator\appdata\local\temp\9306655c-3ca2-4d1f-aa78-1bc467139e05\cyber_cloud_uninstaller_enterprise.exe
g:\65033f54b826dc45350132769966\x64\scenarioengine.exe
c:\users\administrator\downloads\cp049025.exe
c:\users\techexcel\desktop\test\closechrome.bat
microsoft.autogenerated.{2c18cdd1-cf26-19b4-988a-862fc5db076a}
d:\techexcel\jenkins\install\git-2.39.0.2-64-bit.exe
microsoft.autogenerated.{b7bd0f5b-ac0a-e9db-c4b4-db291315165c}
d:\techexcel\jenkins\git-2.47.1.2-64-bit.exe
chrome.session2.default
microsoft.autogenerated.{c804bba7-fa5f-cbf7-8b55-2096e5f972cb}
tsvn.tsvn.1.tortoiseproc2d313792337dc0ce988407e3198d0899
d:\techexcel\lucee\tomcat\webapps\root\panv4\pan_verification_v4_custom\p2j.bat
microsoft.autogenerated.{1bacf67e-7d6f-7cde-188d-98418bad9c2a}
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\windowspowershell\v1.0\powershell.exe
f:\techexcel setup\raid card\hp raid cp031007.exe
d:\techexcel\installer\dataforliverisk-nse\dataforliverisk.exe
d:\techexcel\chromeprofiles\google chrome 1.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\visualsvn\visualsvn server manager.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\system tools\task manager.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\microsoft edge.lnk
c:\users\techexcel\desktop\google chrome.lnk
c:\users\techexcel\downloads\npp.8.7.7.installer.x64.exe
microsoft.internetexplorer.default
c:\users\public\desktop\ireport-5.5.0.lnk
c:\users\techexcel\desktop\mimikatz.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\services.lnk
c:\users\techexcel\downloads\winmerge-2.16.28-x64-setup.exe
f:\techexcel setup\raid card\cp057857.exe
d:\techexcel\lucee\tomcat\webapps\root\depository\7za.exe
microsoft.windows.mediaplayer32
msedge
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft\edgeupdate\1.3.197.27\microsoftedgeupdate.exe
{6d809377-6af0-444b-8957-a3773f02200e}\notepad++\updater\gup.exe
f:\techexcel setup\raid card\cp036448.exe
d:\techexcel\lucee\tomcat\webapps\root\focaps\masters\newkyc\pan_verification_v4_custom\pkcs7gen_latest.bat
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\postman\postman.lnk
d:\techexcel\lucee\tomcat\bin\luceew.exe
c:\users\techexcel\desktop\postman.lnk
com.squirrel.postman.postman
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\notepad++.lnk
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\accessories\notepad.lnk
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft\edgeupdate\microsoftedgeupdate.exe
d:\techexcel\chromeprofiles\google chrome 2.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\paint.lnk
microsoft.autogenerated.{a16c4efe-38da-ef82-3713-fad638cfb297}
d:\techexcel\jenkins\install\freefilesync_12.1_windows_setup.exe
cyber protect monitor
c:\users\techexcel\documents\chromeprofiles\google chrome 1.lnk
ueme_ctlsession
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\system tools\command prompt.lnk
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\windows powershell\windows powershell ise.lnk
d:\techexcel\postman\postman-win64-8.11.1-setup.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\wscript.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\cmd.exe
thingamahoochie.winmerge
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\calc.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\notepad.exe
c:\users\techexcel\downloads\nsdl-ss-user-setup-3.0.0.exe
c:\users\techexcel\appdata\local\temp\{9f8293c4-0307-40a8-beaa-6afbd312ba85}\cpqsetup.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\windows powershell\windows powershell.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\servermanager.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\system tools\administrative tools.lnk
embarcadero.desktoptoasts.5513caf9
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\conhost.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\microsoft sql server management studio 18.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\msconfig.exe
d:\techexcel\installer\dataforliverisk\dataforliverisk.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\microsoft sql server tools 18\performance tools\sql server profiler 18.lnk
d:\techexcel setup\treesizefreesetup.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\dxdiag.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\notepad.lnk
f:\techexcel setup\iiscryptowithtls1.3.exe
d:\techexcel\lucee\tomcat\bin\tomcat9w.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\snipping tool.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\services.exe
c:\users\techexcel\desktop\google chrome 2.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\snippingtool.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\google chrome.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\sessionmsg.exe
d:\techexcel\lucee\tomcat\webapps\root\focaps\ireport\pan_verification\1.bat
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\eventvwr.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\msiexec.exe
c:\users\techexcel\desktop\test\closevscode.bat
d:\techexcel\lucee02\tomcat\bin\luceew02.exe
c:\users\techexcel\appdata\local\temp\~nsu1.tmp\un.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\jam software\treesize free\treesizefree.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\task scheduler.lnk
d:\techexcel\lucee\tomcat\webapps\root\cdsl_acc_opening\cdsl_bosetup_java\cdsl_authtoken.bat
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\notepad++\updater\gup.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\systempropertiesremote.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\common files\java\java update\jucheck.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\iis manager.lnk
chrome.session1.default
d:\techexcel setup\wkhtmltox-0.11.0_rc1-installer.exe
c:\users\techexcel\downloads\ietabhelper.exe
{6d809377-6af0-444b-8957-a3773f02200e}\microsoft\azureattestservice\azureattestserviceinstaller.exe
d:\techexcel setup\wkhtmltox-0.12.2.1_msvc2013-win64.exe
c:\users\techexcel\desktop\test\closepostman.bat
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\rundll32.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\registry editor.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\winrar\winrar.lnk
{6d809377-6af0-444b-8957-a3773f02200e}\notepad++\notepad++.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\microsoft sql server tools 18\microsoft sql server management studio 18.lnk
microsoft.windows.remotedesktop
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft sql server management studio 18\common7\ide\ssms.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\acronis\acronis cyber protect monitor.lnk
d:\techexcel setup\sqlpatch_prerequisite\sql_patch_cu26\sqlserver2019-kb5035123-x64.exe
microsoft.windows.computer
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\easeofaccessdialog.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\computer management.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\odbcad32.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\mspaint.exe
d:\as-ssd-benchmark2.0.7316\as ssd benchmark.exe
d:\techexcel setup\done\client\setup.exe
microsoft.windows.cortana_cw5n1h2txyewy!cortanaui
d:\techexcel\lucee02\tomcat\bin\luceew.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\oracle - oraclient11g_home1\configuration and migration tools\net manager.lnk
d:\techexcel setup\sqlserver2019-kb5033688-x64_a781728ac862e8cd97c508314f3ea4886b70bd84.exe
{d65231b0-b2f1-4857-a4ce-a8e7c6ea7d27}\encrypt.exe
{6d809377-6af0-444b-8957-a3773f02200e}\7-zip\7zg.exe
{6d809377-6af0-444b-8957-a3773f02200e}\git\adobecheck.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\windows nt\accessories\wordpad.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\system tools\control panel.lnk
d:\techexcel\loadbalancing\lucee11\tomcat\bin\lucee11w.exe
d:\5420b421b7822689c103563a58\x64\scenarioengine.exe
{6d809377-6af0-444b-8957-a3773f02200e}\realvnc\vnc4\vncaddrbook.exe
microsoft.autogenerated.{8abd94fb-e7d6-84a6-a997-c918edde0ae5}
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\msinfo32.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\openwith.exe
d:\techexcel\lucee\tomcat\webapps\root\copyimage.bat
c:\users\techexcel\downloads\7z2409-x64.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\telnet.exe
{d65231b0-b2f1-4857-a4ce-a8e7c6ea7d27}\notepad.exe
c:\users\techexcel\appdata\local\temp\{7f66dbc0-52a1-47b1-bc2e-7d2754682d70}\cpqsetup.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\event viewer.lnk
{f38bf404-1d43-42f2-9305-67de0b28fc23}\regedit.exe
d:\techexcel\chromeprofiles\google chrome 3.lnk
f:\techexcel setup\dataforliverisksetup\dataforliverisk\dataforliverisk.exe
d:\techexcelappbackup\winscp\winscp\winscp.exe
d:\techexcel\lucee\ajp13\connector_setup.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\server manager.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\hpe system tools\hpe lights-out online configuration utility\hpe lights-out online configuration utility.lnk
d:\techexcel\lucee02\tomcat\bin\tomcat9.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\internet explorer.lnk
microsoft.windows.apprep.chxapp_cw5n1h2txyewy!app
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\notepad++\notepad++.lnk
c:\users\techexcel\appdata\local\temp\4\npp.8.7.5.installer.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\accessories\internet explorer.lnk
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\file explorer.lnk
g:\as-ssd-benchmark2.0.7316\as ssd benchmark.exe
f:\lkpsoft\sqlserver2019-kb5049296-x64.exe
f:\techexcel setup\smsniff-x64\smsniff.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\jaspersoft\ireport-5.5.0\bin\ireport.exe
f:\00aa8595c4843e9b99\x64\scenarioengine.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\visual studio code\visual studio code.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\systempropertiescomputername.exe
{6d809377-6af0-444b-8957-a3773f02200e}\winrar\winrar.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\system tools\file explorer.lnk
c:\users\public\desktop\microsoft edge.lnk
{6d809377-6af0-444b-8957-a3773f02200e}\windows nt\accessories\wordpad.exe
microsoft.autogenerated.{bd3f924e-55fb-a1ba-9de6-b50f9f2460ac}
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\services.msc
microsoft.windows.administrativetools
microsoft.autogenerated.{bb044bfd-25b7-2faa-22a8-6371a93e0456}
microsoft.windows.explorer
microsoft.autogenerated.{923dd477-5846-686b-a659-0fccd73851a8}
c:\users\techexcel\desktop\google chrome 3.lnk
microsoft.windows.windowsinstaller
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\win32calc.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\google chrome.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\calculator.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\systempropertiesadvanced.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft sql server management studio 18\common7\profiler.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\remote desktop connection.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\inetsrv\inetmgr.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\windowspowershell\v1.0\powershell_ise.exe
microsoft.windows.shell.rundialog
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\microsoft sql server 2019\configuration tools\sql server 2019 configuration manager.lnk
c:\users\techexcel\desktop\google chrome 1.lnk
d:\techexcel\program files\visualsvn server\bin\visualsvn server.msc
c:\users\public\desktop\notepad++.lnk
{6d809377-6af0-444b-8957-a3773f02200e}\7-zip\7zfm.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\mmc.exe
chrome.session3.default
d:\techexcel\phpapp\install\composer-setup.exe
microsoft.windows.controlpanel
{d65231b0-b2f1-4857-a4ce-a8e7c6ea7d27}\odbcad32.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\realvnc\vnc viewer.lnk
c:\users\techexcel\appdata\local\temp\{840fce47-7ab1-4354-8268-eb8834d1ee71}\cpqsetup.exe
c:\users\techexcel\desktop\visual studio code.lnk
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft sql server management studio 18\common7\ide\controlservice.exe
microsoft.autogenerated.{c1c6f8ac-40a3-0f5c-146f-65a9dc70bbb4}
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft sql server management studio 18\common7\dtashell.exe
d:\techexcel_dp\install_2\nssm.exe
d:\techexcel\installer\dataforliverisk-cdbse\dataforliverisk.exe
c:\users\public\desktop\google chrome.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\system tools\smart storage administrator\smart storage administrator.lnk
c:\users\techexcel\appdata\local\temp\2\{690c3478-9a0a-4899-a15e-dd3b4683531d}\.cr\vc_redist.x64.exe
chrome.devtoolsapp
microsoft.windows.shellexperiencehost_cw5n1h2txyewy!app
chrome
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\winver.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\notepad++\notepad++.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\lucee\lucee-tomcat service control.lnk
c:\users\techexcel\downloads\vc_redist.x64.exe
ueme_ctlcuacount:ctor
c:\users\techexcel\downloads\microsoftedgesetup.exe
microsoft.visualstudiocode
d:\techexcel\lucee02\tomcat\bin\lucee02w.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\msdt.exe
c:\users\techexcel\desktop\test\startchrome.bat
c:\users\techexcel\appdata\local\squirreltemp\update.exe
{6d809377-6af0-444b-8957-a3773f02200e}\realvnc\vnc4\vncviewer.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\realvnc\vnc address book.lnk
c:\users\techexcel\appdata\local\temp\{5a557cf3-0dce-442f-9823-7dab0cced0d0}\cpqsetup.exe
d:\techexcel\lucee02\tomcat\bin\lucee02.exe
d:\techexcelappbackup\runbatchnew.bat
d:\techexcel\lucee\tomcat\bin\tomcat9.exe
{6d809377-6af0-444b-8957-a3773f02200e}\hewlett packard enterprise\hponcfg\hponcfg_gui.exe
{6d809377-6af0-444b-8957-a3773f02200e}\smart storage administrator\ssa\bin\ssaclient.exe
windows.immersivecontrolpanel_cw5n1h2txyewy!microsoft.windows.immersivecontrolpanel
c:\users\techexcel\desktop\test\openvscode.bat
g:\65033f54b826dc45350132769966\x64\scenarioengine.exe
c:\users\techexcel\desktop\test\closechrome.bat
microsoft.autogenerated.{2c18cdd1-cf26-19b4-988a-862fc5db076a}
d:\techexcel\jenkins\install\git-2.39.0.2-64-bit.exe
d:\techexcel\jenkins\git-2.47.1.2-64-bit.exe
chrome.session2.default

Extended userassist report attached.

10758 - VNC HTTP Server Detection
-
Synopsis
The remote host is running a remote display software (VNC).
Description
The remote host is running VNC (Virtual Network Computing), which uses the RFB (Remote Framebuffer) protocol to provide remote access to graphical user interfaces and thus permits a console on the remote host to be displayed on another.
See Also
Solution
Make sure use of this software is done in accordance with your organization's security policy and filter incoming traffic to this port.
Risk Factor
None
Plugin Information
Published: 2001/09/14, Modified: 2020/06/12
Plugin Output

tcp/5800/www

19288 - VNC Server Security Type Detection
-
Synopsis
A VNC server is running on the remote host.
Description
This script checks the remote VNC server protocol version and the available 'security types'.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2005/07/22, Modified: 2021/07/13
Plugin Output

tcp/5900/vnc


The remote VNC server supports the following security types :\n\n 5 (RA2)
129
10342 - VNC Software Detection
-
Synopsis
The remote host is running a remote display software (VNC).
Description
The remote host is running VNC (Virtual Network Computing), which uses the RFB (Remote Framebuffer) protocol to provide remote access to graphical user interfaces and thus permits a console on the remote host to be displayed on another.
See Also
Solution
Make sure use of this software is done in accordance with your organization's security policy and filter incoming traffic to this port.
Risk Factor
None
Plugin Information
Published: 2000/03/07, Modified: 2017/06/12
Plugin Output

tcp/5900/vnc


The highest RFB protocol version supported by the server is :

4.1

24269 - WMI Available
-
Synopsis
WMI queries can be made against the remote host.
Description
The supplied credentials can be used to make WMI (Windows Management Instrumentation) requests against the remote host over DCOM.

These requests can be used to gather information about the remote host, such as its current state, network interface configuration, etc.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/02/03, Modified: 2025/12/15
Plugin Output

tcp/445/cifs

The remote host returned the following caption from Win32_OperatingSystem:

Microsoft Windows Server 2019 Datacenter

71637 - WMI IIS ISAPI Extension Enumeration
-
Synopsis
The remote host has ISAPI extensions set up with IIS.
Description
The remote host is running one or more ISAPI IIS extensions such as ASP.NET installed. This plugin enumerates these extensions by examining the ISAPI filters and displays information on whether the extension is enabled or disabled.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/12/20, Modified: 2025/12/15
Plugin Output

tcp/0


IIS component : WebDAV
Component path : %windir%\system32\inetsrv\webdav.dll
Enabled ? : Yes

IIS component : ASP.NET v4.0.30319
Component path : %windir%\Microsoft.NET\Framework\v4.0.30319\aspnet_isapi.dll
Enabled ? : Yes

IIS component : ASP.NET v4.0.30319
Component path : %windir%\Microsoft.NET\Framework64\v4.0.30319\aspnet_isapi.dll
Enabled ? : Yes
52001 - WMI QuickFixEngineering (QFE) Enumeration
-
Synopsis
The remote Windows host has quick-fix engineering updates installed.
Description
By connecting to the remote host with the supplied credentials, this plugin enumerates quick-fix engineering updates installed on the remote host via WMI.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/02/16, Modified: 2025/12/15
Plugin Output

tcp/0


Here is a list of quick-fix engineering updates installed on the
remote system :

+ KB5046268
- Description : Update
- InstalledOn : 12/21/2024
- SystemName : TECHE_LIVE_DB
- InstalledBy : NT AUTHORITY\SYSTEM
- Caption : http://support.microsoft.com/?kbid=5046268

+ KB4535680
- Description : Security Update
- InstalledOn : 1/8/2022
- SystemName : TECHE_LIVE_DB
- InstalledBy : NT AUTHORITY\SYSTEM
- Caption : http://support.microsoft.com/?kbid=4535680

+ KB4589208
- Description : Update
- InstalledOn : 1/8/2022
- SystemName : TECHE_LIVE_DB
- InstalledBy : TECHE_LIVE_DB\Production
- Caption : https://support.microsoft.com/help/4589208

+ KB5005112
- Description : Security Update
- InstalledOn : 8/5/2021
- SystemName : TECHE_LIVE_DB
- Caption : https://support.microsoft.com/help/5005112

+ KB5053596
- Description : Security Update
- InstalledOn : 3/24/2025
- SystemName : TECHE_LIVE_DB
- InstalledBy : NT AUTHORITY\SYSTEM
- Caption : https://support.microsoft.com/help/5053596

+ KB5008287
- Description : Security Update
- InstalledOn : 1/7/2022
- SystemName : TECHE_LIVE_DB
- InstalledBy : NT AUTHORITY\SYSTEM

+ KB5011574
- Description : Update
- InstalledOn : 5/4/2022
- SystemName : TECHE_LIVE_DB
- InstalledBy : NT AUTHORITY\SYSTEM

+ KB5014031
- Description : Update
- InstalledOn : 7/22/2022
- SystemName : TECHE_LIVE_DB
- InstalledBy : NT AUTHORITY\SYSTEM

+ KB5014797
- Description : Update
- InstalledOn : 7/22/2022
- SystemName : TECHE_LIVE_DB
- InstalledBy : NT AUTHORITY\SYSTEM

+ KB5020374
- Description : Security Update
- InstalledOn : 1/5/2023
- SystemName : TECHE_LIVE_DB
- InstalledBy : NT AUTHORITY\SYSTEM

+ KB5043126
- Description : Security Update
- InstalledOn : 12/21/2024
- SystemName : TECHE_LIVE_DB
- InstalledBy : NT AUTHORITY\SYSTEM

+ KB5050110
- Description : Security Update
- InstalledOn : 3/22/2025
- SystemName : TECHE_LIVE_DB
- InstalledBy : TECHE_LIVE_DB\Production

+ KB5054007
- Description : Security Update
- InstalledOn : 3/24/2025
- SystemName : TECHE_LIVE_DB
- InstalledBy : TECHE_LIVE_DB\Production
44871 - WMI Windows Feature Enumeration
-
Synopsis
It is possible to enumerate Windows features using WMI.
Description
Nessus was able to enumerate the server features of the remote host by querying the 'Win32_ServerFeature' class of the '\Root\cimv2' WMI namespace for Windows Server versions or the 'Win32_OptionalFeature' class of the '\Root\cimv2' WMI namespace for Windows Desktop versions.

Note that Features can only be enumerated for Windows 7 and later for desktop versions.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0754
Plugin Information
Published: 2010/02/24, Modified: 2025/12/15
Plugin Output

tcp/0


Nessus enumerated the following Windows features :

- .NET Environment 3.5
- .NET Extensibility 4.7
- .NET Framework 3.5 (includes .NET 2.0 and 3.0)
- .NET Framework 3.5 Features
- .NET Framework 4.7
- .NET Framework 4.7 Features
- ASP.NET 4.7
- ASP.NET 4.7
- Application Development
- Basic Authentication
- Centralized SSL Certificate Support
- Client Certificate Mapping Authentication
- Common HTTP Features
- Custom Logging
- Default Document
- Digest Authentication
- Directory Browsing
- Dynamic Content Compression
- File Server
- File and Storage Services
- File and iSCSI Services
- HTTP Errors
- HTTP Logging
- HTTP Redirection
- Health and Diagnostics
- IIS 6 Management Compatibility
- IIS 6 Metabase Compatibility
- IIS Client Certificate Mapping Authentication
- IIS Hostable Web Core
- IIS Management Console
- IIS Management Scripts and Tools
- IP and Domain Restrictions
- ISAPI Extensions
- ISAPI Filters
- Logging Tools
- Management Service
- Management Tools
- ODBC Logging
- Performance
- Process Model
- Request Filtering
- Request Monitor
- Security
- Static Content
- Static Content Compression
- Storage Services
- System Data Archiver
- TCP Port Sharing
- Telnet Client
- Tracing
- URL Authorization
- WCF Services
- Web Server
- Web Server (IIS)
- WebDAV Publishing
- Windows Authentication
- Windows PowerShell
- Windows PowerShell 2.0 Engine
- Windows PowerShell 5.1
- Windows PowerShell ISE
- Windows Process Activation Service
- WoW64 Support
- XPS Viewer

33139 - WS-Management Server Detection
-
Synopsis
The remote web server is used for remote management.
Description
The remote web server supports the Web Services for Management (WS-Management) specification, a general web services protocol based on SOAP for managing systems, applications, and other such entities.
See Also
Solution
Limit incoming traffic to this port if desired.
Risk Factor
None
Plugin Information
Published: 2008/06/11, Modified: 2021/05/19
Plugin Output

tcp/5985/www


Here is some information about the WS-Management Server :

Product Vendor : Microsoft Corporation
Product Version : OS: 0.0.0 SP: 0.0 Stack: 3.0

11239 - Web Server Crafted Request Vendor/Version Information Disclosure
-
Synopsis
The remote host is running a web server that may be leaking information.
Description
The web server running on the remote host appears to be hiding its version or name, which is a good thing. However, using a specially crafted request, Nessus was able to discover the information.
Solution
No generic solution is known. Contact your vendor for a fix or a workaround.
Risk Factor
None
Plugin Information
Published: 2003/02/19, Modified: 2018/08/15
Plugin Output

tcp/80/www


After sending this request :
HELP


Nessus was able to gather the following information from the web server :
nginx

11239 - Web Server Crafted Request Vendor/Version Information Disclosure
-
Synopsis
The remote host is running a web server that may be leaking information.
Description
The web server running on the remote host appears to be hiding its version or name, which is a good thing. However, using a specially crafted request, Nessus was able to discover the information.
Solution
No generic solution is known. Contact your vendor for a fix or a workaround.
Risk Factor
None
Plugin Information
Published: 2003/02/19, Modified: 2018/08/15
Plugin Output

tcp/81/www


After sending this request :
HELP


Nessus was able to gather the following information from the web server :
nginx

10302 - Web Server robots.txt Information Disclosure
-
Synopsis
The remote web server contains a 'robots.txt' file.
Description
The remote host contains a file named 'robots.txt' that is intended to prevent web 'robots' from visiting certain directories in a website for maintenance or indexing purposes. A malicious user may also be able to use the contents of this file to learn of sensitive documents or directories on the affected site and either retrieve them directly or target them for other attacks.
See Also
Solution
Review the contents of the site's robots.txt file, use Robots META tags instead of entries in the robots.txt file, and/or adjust the web server's access controls to limit access to sensitive material.
Risk Factor
None
Plugin Information
Published: 1999/10/12, Modified: 2018/11/15
Plugin Output

tcp/80/www

Contents of robots.txt :

User-agent: *
Disallow: /

10302 - Web Server robots.txt Information Disclosure
-
Synopsis
The remote web server contains a 'robots.txt' file.
Description
The remote host contains a file named 'robots.txt' that is intended to prevent web 'robots' from visiting certain directories in a website for maintenance or indexing purposes. A malicious user may also be able to use the contents of this file to learn of sensitive documents or directories on the affected site and either retrieve them directly or target them for other attacks.
See Also
Solution
Review the contents of the site's robots.txt file, use Robots META tags instead of entries in the robots.txt file, and/or adjust the web server's access controls to limit access to sensitive material.
Risk Factor
None
Plugin Information
Published: 1999/10/12, Modified: 2018/11/15
Plugin Output

tcp/81/www

Contents of robots.txt :

User-agent: *
Disallow: /

10302 - Web Server robots.txt Information Disclosure
-
Synopsis
The remote web server contains a 'robots.txt' file.
Description
The remote host contains a file named 'robots.txt' that is intended to prevent web 'robots' from visiting certain directories in a website for maintenance or indexing purposes. A malicious user may also be able to use the contents of this file to learn of sensitive documents or directories on the affected site and either retrieve them directly or target them for other attacks.
See Also
Solution
Review the contents of the site's robots.txt file, use Robots META tags instead of entries in the robots.txt file, and/or adjust the web server's access controls to limit access to sensitive material.
Risk Factor
None
Plugin Information
Published: 1999/10/12, Modified: 2018/11/15
Plugin Output

tcp/8686/www

Contents of robots.txt :


User-agent: Slurp
Crawl-delay: 100
Disallow:

User-agent: gsa-crawler-www
Crawl-delay: 100

User-agent: Googlebot
Crawl-delay: 100

User-agent: Mediapartners-Google
Disallow:

User-agent: Yahoo-NewsCrawler
Disallow:

User-Agent: msnbot
Crawl-delay: 100
Disallow:

User-Agent: *
Disallow: /config/
Disallow: /handlers/
Disallow: /includes/
Disallow: /interceptors/
Disallow: /layouts/
Disallow: /logs/
Disallow: /models/
Disallow: /modules/
Disallow: /modules_app/
Disallow: /views/
Allow: /

10302 - Web Server robots.txt Information Disclosure
-
Synopsis
The remote web server contains a 'robots.txt' file.
Description
The remote host contains a file named 'robots.txt' that is intended to prevent web 'robots' from visiting certain directories in a website for maintenance or indexing purposes. A malicious user may also be able to use the contents of this file to learn of sensitive documents or directories on the affected site and either retrieve them directly or target them for other attacks.
See Also
Solution
Review the contents of the site's robots.txt file, use Robots META tags instead of entries in the robots.txt file, and/or adjust the web server's access controls to limit access to sensitive material.
Risk Factor
None
Plugin Information
Published: 1999/10/12, Modified: 2018/11/15
Plugin Output

tcp/8888/www

Contents of robots.txt :

User-agent: *
Disallow: /

92436 - WinRAR History
-
Synopsis
Nessus was able to enumerate files opened with WinRAR on the remote host.
Description
Nessus was able to gather evidence of compressed files that were opened by WinRAR. Note that only compressed files that were opened and not extracted through the explorer shortcut or command line interface were reported.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

C:\Users\Administrator\Downloads\19062025054655.zip
C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache\IE\2RKHRD8U\23062025070129.zip
C:\Users\Administrator\Desktop\26062025061348.zip
C:\Users\techexcel\Downloads\29122025101341.zip
C:\Users\techexcel\Downloads\Margin_06012026_044728.zip
D:\Techexcel\Lucee\tomcat\webapps\ROOT\Reports\MTFStatement\28112024061639.zip
C:\Users\techexcel\Downloads\29122025095635.zip

WinRAR report attached.

162174 - Windows Always Installed Elevated Status
-
Synopsis
Windows AlwaysInstallElevated policy status was found on the remote Windows host
Description
Windows AlwaysInstallElevated policy status was found on the remote Windows host.
You can use the AlwaysInstallElevated policy to install a Windows Installer package with elevated (system) privileges This option is equivalent to granting full administrative rights, which can pose a massive security risk. Microsoft strongly discourages the use of this setting.
Solution
If enabled, disable AlwaysInstallElevated policy per your corporate security guidelines.
Risk Factor
None
Plugin Information
Published: 2022/06/14, Modified: 2022/06/14
Plugin Output

tcp/445/cifs

AlwaysInstallElevated policy is not enabled under HKEY_LOCAL_MACHINE.
AlwaysInstallElevated policy is not enabled under HKEY_USERS user:S-1-5-21-1185746460-1788592564-4118236249-1001
AlwaysInstallElevated policy is not enabled under HKEY_USERS user:S-1-5-21-1185746460-1788592564-4118236249-1002
AlwaysInstallElevated policy is not enabled under HKEY_USERS user:S-1-5-21-1185746460-1788592564-4118236249-1012
AlwaysInstallElevated policy is not enabled under HKEY_USERS user:S-1-5-21-1185746460-1788592564-4118236249-500

48337 - Windows ComputerSystemProduct Enumeration (WMI)
-
Synopsis
It is possible to obtain product information from the remote host using WMI.
Description
By querying the WMI class 'Win32_ComputerSystemProduct', it is possible to extract product information about the computer system such as UUID, IdentifyingNumber, vendor, etc.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/08/16, Modified: 2025/12/15
Plugin Output

tcp/0


+ Computer System Product
- IdentifyingNumber : CNX1480770
- Description : Computer System Product
- Vendor : HPE
- Name : ProLiant DL360 Gen10
- UUID : 35333250-3937-4E43-5831-343830373730

159817 - Windows Credential Guard Status
-
Synopsis
Retrieves the status of Windows Credential Guard.
Description
Retrieves the status of Windows Credential Guard.
Credential Guard prevents attacks such as such as Pass-the-Hash or Pass-The-Ticket by protecting NTLM password hashes, Kerberos Ticket Granting Tickets, and credentials stored by applications as domain credentials.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2022/04/18, Modified: 2023/08/25
Plugin Output

tcp/445/cifs


Windows Credential Guard is not fully enabled.
The following registry keys have not been set :
- System\CurrentControlSet\Control\DeviceGuard\RequirePlatformSecurityFeatures : Key not found.
- System\CurrentControlSet\Control\LSA\LsaCfgFlags : Key not found.
- System\CurrentControlSet\Control\DeviceGuard\EnableVirtualizationBasedSecurity : Key not found.
58181 - Windows DNS Server Enumeration
-
Synopsis
Nessus enumerated the DNS servers being used by the remote Windows host.
Description
Nessus was able to enumerate the DNS servers configured on the remote Windows host by looking in the registry.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2012/03/01, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Nessus enumerated DNS servers for the following interfaces :

Interface: {039dc6e3-6971-4a25-8c26-0a7568b26022}
Network Connection : LAN_31
NameServer: 8.8.8.8,4.2.2.2
164690 - Windows Disabled Command Prompt Enumeration
-
Synopsis
This plugin determines if the DisableCMD policy is enabled or disabled on the remote host for each local user.
Description
The remote host may employ the DisableCMD policy on a per user basis. Enumerated local users may have the following registry key:
'HKLM\Software\Policies\Microsoft\Windows\System\DisableCMD'

- Unset or 0: The command prompt is enabled normally.
- 1: The command promt is disabled.
- 2: The command prompt is disabled however windows batch processing is allowed.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2022/09/06, Modified: 2022/10/05
Plugin Output

tcp/445/cifs


Username: uatlkp
SID: S-1-5-21-1185746460-1788592564-4118236249-1010
DisableCMD: Unset

Username: Production
SID: S-1-5-21-1185746460-1788592564-4118236249-500
DisableCMD: Unset

Username: WDAGUtilityAccount
SID: S-1-5-21-1185746460-1788592564-4118236249-504
DisableCMD: Unset

Username: techexcel
SID: S-1-5-21-1185746460-1788592564-4118236249-1001
DisableCMD: Unset

Username: tidua
SID: S-1-5-21-1185746460-1788592564-4118236249-1012
DisableCMD: Unset

Username: Guest
SID: S-1-5-21-1185746460-1788592564-4118236249-501
DisableCMD: Unset

Username: DefaultAccount
SID: S-1-5-21-1185746460-1788592564-4118236249-503
DisableCMD: Unset

Username: Backoffice
SID: S-1-5-21-1185746460-1788592564-4118236249-1006
DisableCMD: Unset

Username: Techrobot
SID: S-1-5-21-1185746460-1788592564-4118236249-1005
DisableCMD: Unset

Username: techapp
SID: S-1-5-21-1185746460-1788592564-4118236249-1002
DisableCMD: Unset

Username: LKPAdmin
SID: S-1-5-21-1185746460-1788592564-4118236249-1000
DisableCMD: Unset

72482 - Windows Display Driver Enumeration
-
Synopsis
Nessus was able to enumerate one or more of the display drivers on the remote host.
Description
Nessus was able to enumerate one or more of the display drivers on the remote host via WMI.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0756
Plugin Information
Published: 2014/02/06, Modified: 2025/12/15
Plugin Output

tcp/0


Device Name : Matrox G200eh3 (HPE) WDDM 2.0
Driver File Version : 4.5.0.5
Driver Date : 05/26/2021
Video Processor : Matrox G200eH
92423 - Windows Explorer Recently Executed Programs
-
Synopsis
Nessus was able to enumerate recently executed programs on the remote host.
Description
Nessus was able to find evidence of program execution using Windows Explorer registry logs and settings.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2019/08/15
Plugin Output

tcp/0

IEXPLORE.EXEPO :i+00.9#K&]B_
mspaint.exePO :i+00:.+ezFkp:&&XRuiJQ>d
msedge.exePO :i+00/D:\
InetMgr.exePO :i+00/D:\V1U7ELKPSOFT@'T"U7E.&\rLKPSOFTJ1U7ESSL8U6EU7E.(kSSL
notepad.exePO :i+00:.:,LB)A&&XRu]j
SanerNow_Windows_x86_6.3.exePO :i+00/D:\V1Ylkpsoft@YY.* \rlkpsoft1YSanerNow_LKP_Window_CM_Windows_x86_6.3~YY.< %/-SanerNow_LKP_Window_CM_Windows_x86_6.36
Explorer.EXEPO :i+00/C:\1XIpPROGRA~1t/Ma:XIp.ZJKOmProgram Files@shell32.dll,-21781b1YBBACKUP~1J>WDYB.usa)BackupClient`1Y|TRAYMO~1HY|Y|."%3YTrayMonitor
SnippingTool.exePO :i+00/D:\n1-TOhTechexcel SetupP-TOh-TOh.ClTechexcel Setup
iexplore.exePO :i+00:.:,LB)A&& +Ne@k_w_
Postman.exePO :i+00:.:,LB)A&& +N.]mam
OpenWith.exe9#1SPS.+,AutoListBprop4294967295N8N{x PO :i+00/C:\1xVWCPROGRA~1t/Ma:xV\C.ZJProgram Files@shell32.dll,-21781itemB6@=aw@Search Results in Program Files9$AutolistCacheTimewGtw"AutolistCacheKey!Search Results in Program Files0tY^Hg3(gs3\nEJ.* m 1SPS@>+lG7*"Bprop4294967295mie1SPS.+,!Key:PIDmConditionBprop4294967295#\RZHF|{TEPB\rfK=VLN]IN9r\RZHF|{TEPB\rfK=VLN]IN9r\RZHF|{TEPB\rfK=VLN]chromeen-USN9rchromeen-USchromeD@>+lG7*"\rchromeen-USchrome@>+lG7*"\rchromeen-USchromeuKey:FMTIDN{1E3EE840-BC2B-476C-8237-2ACD1A839B22}+\nNamechrome\nType!chromeJ1SPSjc(=OStack0=1SPS0%G`!\nchrome*B6@=aw@LB{zOH
notepad++.exePO :i+00/D:\\1[jTechexcelD-Tgq!\=.TechexcelP1[Ai0Lucee<.Tm>!\@.,`LuceeT1[Ai0tomcat>.Tm>!\@.`/tomcatV1%[Qi0webapps@.Tm>!\:>.e\?webappsN1[2'0ROOT:.Tm>!\@.e*)ROOTJ1F[C0kra8.Tm>!\A.0pPkra`1M[:0exportdataF.Tm>!\A.7pjRexportdata
Composer-Setup.tmpPO :i+00/D:\\1QYK=TechexcelD-TgqQYK=.}:TechexcelT1QYR=PHPApp>QYK=QYR=.V8PHPAppJ1V php8QYR=QYS=.$php
\n\r
chrome.exePO :i+00:.:,LB)A&& +N.]mam
mmc.exePO :i+00/D:\\1ZCTechexcelD-TgqZzH.eTechexceln1ZCLatestDbChangesP.Tp>Z8D.LatestDbChanges
WinSCP.exePO :i+00/F:\n1ZjTechexcel SetupP-TOhZj.O[Techexcel Setup
Code.exePO :i+00/D:\\1ZwTechexcelD-TgqZM.{TechexcelP1OZ40Lucee<.Tm>ZK.,`CvLuceeT1OZ40tomcat>.Tm>ZK.`ktomcatV1OZ20webapps@.Tm>ZI.ewebappsN1Z%0ROOT:.Tm>ZP.ezvROOT`1Z./0depositoryF.Tm>ZL.eqdepository\11Y{?0io_focapsD.Tm>ZN.fio_focapsV1Wp5scripts@.Tm>ZP.f,scripts
notepad.exePO :i+00:.:,LB)A&& +N0K22A4
DTAShell.exePO :i+00:.:,LB)A&& +Ng\r^g\r^
SnippingTool.exePO :i+00.9#K&]B_
Ssms.exePO :i+00/D:\\1[cTechexcelD-Tgq[c.diTechexcel`1:[q3conversionFKUu>[].*H=conversion
Profiler.exePO :i+00.+ezFkp:
mspaint.exePO :i+00/D:\n1XTTechexcel SetupP-TOhXT.C5Techexcel Setup1XTSQLPatch_Prerequisite\XRXT.\r:SQLPatch_Prerequisite$
services.msc\1
dcba
\\20.20.20.32\1
CALC\1
\\172.17.100.33\inbox$\1
cmd\1
d:\1
D:\Techexcel\Lucee\tomcat\webapps\ROOT\1
\\172.17.100.31\1
D:\Techexcel\\lucee\tomcat\webapps\ROOT\Reports\1\04022025015152\1
\\172.17.100.32\Techexcel\\1
dxdiag\1
notepad\1
mstsc\1
services.msc\1
\\172.17.100.32\Techexcel\Lucee\tomcat\webapps\ROOT\WEB-INF\lucee\1
control\1
\\172.17.100.32\Techexcel\Lucee\tomcat\webapps\1
D:\Techexcel\Lucee\tomcat\webapps\ROOT\Reports\CommonContract\1
D:\Techexcel\\lucee\tomcat\webapps\ROOT\Reports\Retantion\08052025033752\1
D:\Techexcel\\lucee\tomcat\webapps\ROOT\Reports\1
winver\1
ncpa.cpl\1
D:\Techexcel\\lucee\tomcat\webapps\ROOT\Reports\1\\1
D:\Techexcel\\lucee\tomcat\webapps\ROOT\Reports\\1
idjwlpysztkmcofhenuxarqvbg
regedit\1
\\172.17.100.224\1
\\172.17.100.32\Techexcel\Lucee\tomcat\webapps\\1
D:\Techexcel\\lucee\tomcat\webapps\ROOT\1
\\192.168.10.234\1
appwiz.cpl\1
calc\1
D:\Techexcel\Lucee\tomcat\webapps\ROOT\focaps\Std_Import\\1
D://Techexcel////lucee//tomcat//webapps//ROOT\1
cmd\1
services.msc\1
D:\Techexcel\\lucee\tomcat\webapps\ROOT\Reports\MarginProcess\08102025120106\1
D:\Techexcel\Lucee\tomcat\webapps\ROOT\focaps\misreports_ii\1
D:\Techexcel\\lucee\tomcat\webapps\ROOT\Reports\CommonContract\29122025095012\1
notepad\1
D://Techexcel////\1
D://Techexcel//lucee//tomcat//webapps//ROOT//WEB-INF//lucee//classes/\1
\\172.17.100.31\techexcel$\1
D:\Techexcel\Lucee\tomcat\webapps\ROOT\techesign\FileView.cfm\1
\\172.17.100.35\1
D:\Techexcel\IMPORTTRADEFILES\1
D:\Techexcel\Lucee\tomcat\webapps\ROOT\techesign\1
mstsc\1
D:\Techexcel\\lucee\tomcat\webapps\ROOT\Reports\Latters\BoClosure\17102025_1622\\1
D:\Techexcel\\lucee\tomcat\webapps\ROOT\Reports\Latters\BoClosure\30092025_2027\\1
\\172.17.100.33\techexcel$\Lucee\tomcat\webapps\ROOT\staticData\wsdl\1
nduktprqhlgjwmizvcfbysoaex
D:\Techexcel\\ImportTradeFiles\NSDLSOH.txt\1
D://Techexcel////lucee//tomcat//webapps//ROOT//WEB-INF//lucee//classes\1
D:\Techexcel\\lucee\tomcat\webapps\ROOT\\1
D:\Techexcel\\1
D:\Techexcel\Lucee\tomcat\webapps\ROOT\1
\\172.17.100.33\inbox$\1
msedge.exe^
mspaint.exe_mM
regedit.exe445A<gwp
InetMgr.exee
iexplore.exe^
notepad.exe@[ThH
SanerNow_Windows_x86_6.3.exeE_{
Explorer.EXElX@\
SnippingTool.exe3
IEXPLORE.EXE?:
WinRAR.exe+~.
OpenWith.execk+,
Profiler.exe^+
notepad++.exe+G
\r\n
chrome.exeHdS
mmc.exeniV
Composer-Setup.tmpd{]lz
WinSCP.exeR=
notepad.exe
Code.exe^
DTAShell.exeNNVmm
SnippingTool.exe3
Ssms.exe^
Postman.exe
mspaint.exe^_mM
x@_dP/N
X\r,!PCsg<
x@_dP/N
X\r,!PCsg<

MRU programs details in attached report.
92418 - Windows Explorer Typed Paths
-
Synopsis
Nessus was able to enumerate the directory paths that users visited by typing the full directory path into Windows Explorer.
Description
Nessus was able to enumerate the directory paths that users visited by manually typing the full directory path into Windows Explorer. The generated folder list report contains folders local to the system, folders from past mounted network drives, and folders from mounted devices.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

\\20.20.20.32\backup$
\\172.17.100.75\d$
\\172.17.100.32\Techexcel\Lucee\tomcat\webapps\ROOT\WEB-INF
\\172.17.100.224
D:\backup
D:\Techexcel\Lucee\tomcat\webapps\ROOT\Reports\PDFContract
\\192.168.10.234\d$
\\172.17.100.224\d$
C:\ProgramData\Microsoft\Windows
D:\Techexcel\TechESignDoc\Sentitems
ftp://103.181.209.252/
cmd
D:\
Control Panel\All Control Panel Items\Programs and Features
D:\Techexcel
D:\Techexcel\Lucee\tomcat
F:\WeeklyStatement
F:\backup
This PC
D:\lucee\tomcat\webapps\ROOT
D:\Techexcel\Lucee\tomcat\webapps\ROOT\techesign
F:\
\\172.17.100.224\e$
D:\Techexcel\Lucee\tomcat\webapps\ROOT
\\172.17.100.224\E$
D:\Techexcel\Lucee\tomcat\webapps\ROOT\Reports
D:\Techexcel\Lucee\tomcat\webapps\ROOT\Latters
D:\Techexcel\Lucee\tomcat\webapps\ROOT\focaps\commoncontract
D:\Techexcel\Lucee\tomcat\webapps\ROOT\depository\text_reports
D:\Techexcel\Lucee\tomcat\webapps\ROOT\depository\cdsl\masters
D:\Techexcel\Lucee\tomcat\webapps\ROOT\depository\text_reports\dpinkjet
D:\Techexcel\Lucee\tomcat\webapps\ROOT
D:\Techexcel\Lucee\tomcat\webapps\ROOT\WEB-INF\lucee\classes
D:\Techexcel
D:\Techexcel\Installer
\\172.17.100.31\techexcel$\
\\172.17.100.31\techexcel$\Lucee\tomcat\webapps\ROOT\focaps\inst
\\172.17.100.33\techexcel$
D:\Techexcel\Lucee\tomcat\webapps\ROOT\focaps
G:\
D:\Techexcel\Lucee\tomcat\webapps\ROOT\ftpdownload
cmd
D:\Techexcel\Lucee\tomcat\webapps\ROOT\depository\fileexports
D:\Techexcel\Lucee\tomcat\webapps\ROOT\weblogin\reports\smartreport\detail_New
D:\Techexcel\Lucee\tomcat\webapps\ROOT\Reports
D:\Techexcel\TechESignDoc
D:\Techexcel\Lucee\tomcat\webapps\ROOT\Report\TransDetail
D:\Techexcel\Lucee\tomcat\webapps\ROOT\depository\io_focaps\reports
D:\Techexcel\Lucee\tomcat\webapps\ROOT\Report
D:\Techexcel\Lucee\tomcat\webapps\ROOT\depository
D:\Techexcel\Lucee\tomcat\webapps\ROOT\focaps\PatchUpdate

Extended explorer typed paths report attached.

159929 - Windows LSA Protection Status
-
Synopsis
Windows LSA Protection is disabled on the remote Windows host.
Description
The LSA Protection validates users for local and remote sign-ins and enforces local security policies to prevent reading memory and code injection by non-protected processes. This provides added security for the credentials that the LSA stores and manages. This protects against Pass-the-Hash or Mimikatz-style attacks.
Solution
Enable LSA Protection per your corporate security guidelines.
Risk Factor
None
Plugin Information
Published: 2022/04/20, Modified: 2025/06/16
Plugin Output

tcp/445/cifs


LSA Protection Key \SYSTEM\CurrentControlSet\Control\Lsa\RunAsPPL not found.

148541 - Windows Language Settings Detection
-
Synopsis
This plugin enumerates language files on a windows host.
Description
By connecting to the remote host with the supplied credentials, this plugin enumerates language IDs listed on the host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2021/04/14, Modified: 2022/02/01
Plugin Output

tcp/0

Default Install Language Code: 1033

Default Active Language Code: 1033

Other common microsoft Language packs may be scanned as well.
92422 - Windows Mapped Network Drives
-
Synopsis
Nessus was able to enumerate mapped network drives on the remote host.
Description
Nessus was able to generate a report of mapped network drives on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

mrulist : a
a : \\172.17.100.224\e$
mrulist : a
a : \\172.17.100.51\otd


Extended mapped network drive report attached.

10150 - Windows NetBIOS / SMB Remote Host Information Disclosure
-
Synopsis
It was possible to obtain the network name of the remote host.
Description
The remote host is listening on UDP port 137 or TCP port 445, and replies to NetBIOS nbtscan or SMB requests.

Note that this plugin gathers information to be used in other plugins, but does not itself generate a report.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 1999/10/12, Modified: 2021/02/10
Plugin Output

udp/137/netbios-ns

The following 3 NetBIOS names have been gathered :

TECHE_LIVE_DB = Computer name
WORKGROUP = Workgroup / Domain name
TECHE_LIVE_DB = File Server Service

The remote host has the following MAC address on its adapter :

d4:f5:ef:60:4d:20

63620 - Windows Product Key Retrieval
-
Synopsis
This plugin retrieves the Windows Product key of the remote Windows host.
Description
Using the supplied credentials, Nessus was able to obtain the retrieve the Windows host's partial product key'.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/01/18, Modified: 2013/01/18
Plugin Output

tcp/445/cifs


Product key : XXXXX-XXXXX-XXXXX-XXXXX-BWT4H

Note that all but the final portion of the key has been obfuscated.
160576 - Windows Services Registry ACL
-
Synopsis
Checks Windows Registry for Service ACLs
Description
Checks Windows Registry for Service ACLs.
Solution
N/A
Risk Factor
None
Plugin Information
Published: 2022/05/05, Modified: 2024/01/15
Plugin Output

tcp/445/cifs

report output too big - ending list here

204960 - Windows System Driver Enumeration (Windows)
-
Synopsis
One or more kernel or file system drivers were enumerated on the remote Windows host.
Description
One or more kernel or file system drivers were enumerated on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2024/08/01, Modified: 2025/12/15
Plugin Output

tcp/0


Total : 350

Name : 1394ohci
Path : C:\Windows\system32\drivers\1394ohci.sys
Service Type : Kernel Driver
Description : 1394 OHCI Compliant Host Controller
State : Stopped

Name : 3ware
Path : C:\Windows\system32\drivers\3ware.sys
Service Type : Kernel Driver
Description : 3ware
State : Stopped

Name : ACPI
Path : C:\Windows\system32\drivers\ACPI.sys
Service Type : Kernel Driver
Description : Microsoft ACPI Driver
State : Running

Name : AcpiDev
Path : C:\Windows\system32\drivers\AcpiDev.sys
Service Type : Kernel Driver
Description : ACPI Devices driver
State : Stopped

Name : acpiex
Path : C:\Windows\system32\Drivers\acpiex.sys
Service Type : Kernel Driver
Description : Microsoft ACPIEx Driver
State : Running

Name : acpipagr
Path : C:\Windows\system32\drivers\acpipagr.sys
Service Type : Kernel Driver
Description : ACPI Processor Aggregator Driver
State : Stopped

Name : AcpiPmi
Path : C:\Windows\system32\drivers\acpipmi.sys
Service Type : Kernel Driver
Description : ACPI Power Meter Driver
State : Running

Name : acpitime
Path : C:\Windows\system32\drivers\acpitime.sys
Service Type : Kernel Driver
Description : ACPI Wake Alarm Driver
State : Running

Name : ADP80XX
Path : C:\Windows\system32\drivers\ADP80XX.SYS
Service Type : Kernel Driver
Description : ADP80XX
State : Stopped

Name : AFD
Path : C:\Windows\system32\drivers\afd.sys
Service Type : Kernel Driver
Description : Ancillary Function Driver for Winsock
State : Running

Name : afunix
Path : C:\Windows\system32\drivers\afunix.sys
Service Type : Kernel Driver
Description : afunix
State : Running

Name : ahcache
Path : C:\Windows\system32\DRIVERS\ahcache.sys
Service Type : Kernel Driver
Description : Application Compatibility Cache
State : Running

Name : AmdK8
Path : C:\Windows\system32\drivers\amdk8.sys
Service Type : Kernel Driver
Description : AMD K8 Processor Driver
State : Stopped

Name : AmdPPM
Path : C:\Windows\system32\drivers\amdppm.sys
Service Type : Kernel Driver
Description : AMD Processor Driver
State : Stopped

Name : amdsata
Path : C:\Windows\system32\drivers\amdsata.sys
Service Type : Kernel Driver
Description : amdsata
State : Stopped

Name : amdsbs
Path : C:\Windows\system32\drivers\amdsbs.sys
Service Type : Kernel Driver
Description : amdsbs
State : Stopped

Name : amdxata
Path : C:\Windows\system32\drivers\amdxata.sys
Service Type : Kernel Driver
Description : amdxata
State : Stopped

Name : AppID
Path : C:\Windows\system32\drivers\appid.sys
Service Type : Kernel Driver
Description : AppID Driver
State : Stopped

Name : applockerfltr
Path : C:\Windows\system32\drivers\applockerfltr.sys
Service Type : Kernel Driver
Description : Smartlocker Filter Driver
State : Stopped

Name : AppvStrm
Path : C:\Windows\system32\drivers\AppvStrm.sys
Service Type : File System Driver
Description : AppvStrm
State : Stopped

Name : AppvVemgr
Path : C:\Windows\system32\drivers\AppvVemgr.sys
Service Type : File System Driver
Description : AppvVemgr
State : Stopped

Name : AppvVfs
Path : C:\Windows\system32\drivers\AppvVfs.sys
Service Type : File System Driver
Description : AppvVfs
State : Stopped

Name : arcsas
Path : C:\Windows\system32\drivers\arcsas.sys
Service Type : Kernel Driver
Description : Adaptec SAS/SATA-II RAID Storport's Miniport Driver
State : Stopped

Name : AsyncMac
Path : C:\Windows\system32\drivers\asyncmac.sys
Service Type : Kernel Driver
Description : RAS Asynchronous Media Driver
State : Stopped

Name : atapi
Path : C:\Windows\system32\drivers\atapi.sys
Service Type : Kernel Driver
Description : IDE Channel
State : Stopped

Name : b06bdrv
Path : C:\Windows\system32\drivers\bxvbda.sys
Service Type : Kernel Driver
Description : QLogic Network Adapter VBD
State : Stopped

Name : bam
Path : C:\Windows\system32\drivers\bam.sys
Service Type : Kernel Driver
Description : Background Activity Moderator Driver
State : Running

Name : BasicDisplay
Path : C:\Windows\system32\DriverStore\FileRepository\basicdisplay.inf_amd64_5103ac179273be89\BasicDisplay.sys
Service Type : Kernel Driver
Description : BasicDisplay
State : Running

Name : BasicRender
Path : C:\Windows\system32\DriverStore\FileRepository\basicrender.inf_amd64_efdc64af60c69a6d\BasicRender.sys
Service Type : Kernel Driver
Description : BasicRender
State : Running

Name : bcmfn2
Path : C:\Windows\system32\drivers\bcmfn2.sys
Service Type : Kernel Driver
Description : bcmfn2 Service
State : Stopped

Name : BdDci
Path : C:\Windows\system32\DRIVERS\bddci.sys
Service Type : Kernel Driver
Description : BdDci Service
State : Running

Name : Beep
Path : C:\Windows\system32\drivers\Beep.sys
Service Type : Kernel Driver
Description : Beep
State : Stopped

Name : bfadfcoei
Path : C:\Windows\system32\drivers\bfadfcoei.sys
Service Type : Kernel Driver
Description : bfadfcoei
State : Stopped

Name : bfadi
Path : C:\Windows\system32\drivers\bfadi.sys
Service Type : Kernel Driver
Description : bfadi
State : Stopped

Name : bindflt
Path : C:\Windows\system32\drivers\bindflt.sys
Service Type : File System Driver
Description : Windows Bind Filter Driver
State : Stopped

Name : bowser
Path : C:\Windows\system32\DRIVERS\bowser.sys
Service Type : File System Driver
Description : Browser
State : Running

Name : BthEnum
Path : C:\Windows\system32\drivers\BthEnum.sys
Service Type : Kernel Driver
Description : Bluetooth Enumerator Service
State : Stopped

Name : BthLEEnum
Path : C:\Windows\system32\drivers\Microsoft.Bluetooth.Legacy.LEEnumerator.sys
Service Type : Kernel Driver
Description : Bluetooth Low Energy Driver
State : Stopped

Name : BthMini
Path : C:\Windows\system32\drivers\BTHMINI.sys
Service Type : Kernel Driver
Description : Bluetooth Radio Driver
State : Stopped

Name : BTHPORT
Path : C:\Windows\system32\drivers\BTHport.sys
Service Type : Kernel Driver
Description : Bluetooth Port Driver
State : Stopped

Name : BTHUSB
Path : C:\Windows\system32\drivers\BTHUSB.sys
Service Type : Kernel Driver
Description : Bluetooth Radio USB Driver
State : Stopped

Name : bttflt
Path : C:\Windows\system32\drivers\bttflt.sys
Service Type : Kernel Driver
Description : Microsoft Hyper-V VHDPMEM BTT Filter
State : Stopped

Name : buttonconverter
Path : C:\Windows\system32\drivers\buttonconverter.sys
Service Type : Kernel Driver
Description : Service for Portable Device Control devices
State : Stopped

Name : bxfcoe
Path : C:\Windows\system32\drivers\bxfcoe.sys
Service Type : Kernel Driver
Description : QLogic FCoE Offload driver
State : Stopped

Name : bxois
Path : C:\Windows\system32\drivers\bxois.sys
Service Type : Kernel Driver
Description : QLogic Offload iSCSI Driver
State : Stopped

Name : CapImg
Path : C:\Windows\system32\drivers\capimg.sys
Service Type : Kernel Driver
Description : HID driver for CapImg touch screen
State : Stopped

Name : cdfs
Path : C:\Windows\system32\DRIVERS\cdfs.sys
Service Type : File System Driver
Description : CD/DVD File System Reader
State : Stopped

Name : cdrom
Path : C:\Windows\system32\drivers\cdrom.sys
Service Type : Kernel Driver
Description : CD-ROM Driver
State : Running

Name : cht4iscsi
Path : C:\Windows\system32\drivers\cht4sx64.sys
Service Type : Kernel Driver
Description : cht4iscsi
State : Stopped

Name : cht4vbd
Path : C:\Windows\system32\drivers\cht4vx64.sys
Service Type : Kernel Driver
Description : Chelsio Virtual Bus Driver
State : Stopped

Name : CldFlt
Path : C:\Windows\system32\drivers\cldflt.sys
Service Type : File System Driver
Description : Windows Cloud Files Filter Driver
State : Running

Name : CLFS
Path : C:\Windows\system32\drivers\CLFS.sys
Service Type : Kernel Driver
Description : Common Log (CLFS)
State : Running

Name : CmBatt
Path : C:\Windows\system32\drivers\CmBatt.sys
Service Type : Kernel Driver
Description : Microsoft ACPI Control Method Battery Driver
State : Stopped

Name : CNG
Path : C:\Windows\system32\Drivers\cng.sys
Service Type : Kernel Driver
Description : CNG
State : Running

Name : cnghwassist
Path : C:\Windows\system32\DRIVERS\cnghwassist.sys
Service Type : Kernel Driver
Description : CNG Hardware Assist algorithm provider
State : Stopped

Name : CompositeBus
Path : C:\Windows\system32\DriverStore\FileRepository\compositebus.inf_amd64_e4d35af746093dc3\CompositeBus.sys
Service Type : Kernel Driver
Description : Composite Bus Enumerator Driver
State : Running

Name : condrv
Path : C:\Windows\system32\drivers\condrv.sys
Service Type : Kernel Driver
Description : Console Driver
State : Running

Name : CSC
Path : C:\Windows\system32\drivers\csc.sys
Service Type : Kernel Driver
Description : Offline Files Driver
State : Stopped

Name : dam
Path : C:\Windows\system32\drivers\dam.sys
Service Type : Kernel Driver
Description : Desktop Activity Moderator Driver
State : Stopped

Name : Dfsc
Path : C:\Windows\system32\Drivers\dfsc.sys
Service Type : File System Driver
Description : DFS Namespace Client Driver
State : Running

Name : Disk
Path : C:\Windows\system32\drivers\disk.sys
Service Type : Kernel Driver
Description : Disk Driver
State : Running

Name : dmvsc
Path : C:\Windows\system32\drivers\dmvsc.sys
Service Type : Kernel Driver
Description : dmvsc
State : Stopped

Name : drmkaud
Path : C:\Windows\system32\drivers\drmkaud.sys
Service Type : Kernel Driver
Description : Microsoft Trusted Audio Drivers
State : Stopped

Name : DXGKrnl
Path : C:\Windows\system32\drivers\dxgkrnl.sys
Service Type : Kernel Driver
Description : LDDM Graphics Subsystem
State : Running

Name : e1iexpress
Path : C:\Windows\system32\drivers\e1i63x64.sys
Service Type : Kernel Driver
Description : Intel(R) PRO/1000 PCI Express Network Connection Driver I
State : Stopped

Name : e1rexpress
Path : C:\Windows\system32\drivers\e1r68x64.sys
Service Type : Kernel Driver
Description : Intel(R) PCI Express Network Connection Driver R
State : Running

Name : ebdrv
Path : C:\Windows\system32\drivers\evbda.sys
Service Type : Kernel Driver
Description : QLogic 10 Gigabit Ethernet Adapter VBD
State : Stopped

Name : EhStorClass
Path : C:\Windows\system32\drivers\EhStorClass.sys
Service Type : Kernel Driver
Description : Enhanced Storage Filter Driver
State : Stopped

Name : EhStorTcgDrv
Path : C:\Windows\system32\drivers\EhStorTcgDrv.sys
Service Type : Kernel Driver
Description : Microsoft driver for storage devices supporting IEEE 1667 and TCG protocols
State : Stopped

Name : elxfcoe
Path : C:\Windows\system32\drivers\elxfcoe.sys
Service Type : Kernel Driver
Description : elxfcoe
State : Stopped

Name : elxstor
Path : C:\Windows\system32\drivers\elxstor.sys
Service Type : Kernel Driver
Description : elxstor
State : Stopped

Name : ErrDev
Path : C:\Windows\system32\drivers\errdev.sys
Service Type : Kernel Driver
Description : Microsoft Hardware Error Device Driver
State : Running

Name : exfat
Path : C:\Windows\system32\drivers\exfat.sys
Service Type : File System Driver
Description : exFAT File System Driver
State : Stopped

Name : fastfat
Path : C:\Windows\system32\drivers\fastfat.sys
Service Type : File System Driver
Description : FAT12/16/32 File System Driver
State : Running

Name : fcvsc
Path : C:\Windows\system32\drivers\fcvsc.sys
Service Type : Kernel Driver
Description : fcvsc
State : Stopped

Name : fdc
Path : C:\Windows\system32\drivers\fdc.sys
Service Type : Kernel Driver
Description : Floppy Disk Controller Driver
State : Stopped

Name : FileCrypt
Path : C:\Windows\system32\drivers\filecrypt.sys
Service Type : File System Driver
Description : FileCrypt
State : Running

Name : FileInfo
Path : C:\Windows\system32\drivers\fileinfo.sys
Service Type : File System Driver
Description : File Information FS MiniFilter
State : Stopped

Name : Filetrace
Path : C:\Windows\system32\drivers\filetrace.sys
Service Type : File System Driver
Description : Filetrace
State : Stopped

Name : file_monitor
Path : C:\Windows\system32\DRIVERS\file_monitor.sys
Service Type : File System Driver
Description : file_monitor
State : Running

Name : file_protector
Path : C:\Windows\system32\DRIVERS\file_protector.sys
Service Type : File System Driver
Description : Acronis File Protector Driver
State : Running

Name : flpydisk
Path : C:\Windows\system32\drivers\flpydisk.sys
Service Type : Kernel Driver
Description : Floppy Disk Driver
State : Stopped

Name : FltMgr
Path : C:\Windows\system32\drivers\fltmgr.sys
Service Type : File System Driver
Description : FltMgr
State : Running

Name : fltsrv
Path : C:\Windows\system32\DRIVERS\fltsrv.sys
Service Type : Kernel Driver
Description : Acronis Storage Filter Management
State : Running

Name : FsDepends
Path : C:\Windows\system32\drivers\FsDepends.sys
Service Type : File System Driver
Description : File System Dependency Minifilter
State : Stopped

Name : gencounter
Path : C:\Windows\system32\drivers\vmgencounter.sys
Service Type : Kernel Driver
Description : Microsoft Hyper-V Generation Counter
State : Stopped

Name : genericusbfn
Path : C:\Windows\system32\drivers\genericusbfn.sys
Service Type : Kernel Driver
Description : Generic USB Function Class
State : Stopped

Name : GPIOClx0101
Path : C:\Windows\system32\Drivers\msgpioclx.sys
Service Type : Kernel Driver
Description : Microsoft GPIO Class Extension Driver
State : Stopped

Name : HDAudBus
Path : C:\Windows\system32\drivers\HDAudBus.sys
Service Type : Kernel Driver
Description : Microsoft UAA Bus Driver for High Definition Audio
State : Stopped

Name : HidBatt
Path : C:\Windows\system32\drivers\HidBatt.sys
Service Type : Kernel Driver
Description : HID UPS Battery Driver
State : Stopped

Name : hidinterrupt
Path : C:\Windows\system32\drivers\hidinterrupt.sys
Service Type : Kernel Driver
Description : Common Driver for HID Buttons implemented with interrupts
State : Stopped

Name : HidUsb
Path : C:\Windows\system32\drivers\hidusb.sys
Service Type : Kernel Driver
Description : Microsoft HID Class Driver
State : Stopped

Name : HpSAMD
Path : C:\Windows\system32\drivers\HpSAMD.sys
Service Type : Kernel Driver
Description : HpSAMD
State : Stopped

Name : HTTP
Path : C:\Windows\system32\drivers\HTTP.sys
Service Type : Kernel Driver
Description : HTTP Service
State : Running

Name : hvcrash
Path : C:\Windows\system32\drivers\hvcrash.sys
Service Type : Kernel Driver
Description : hvcrash
State : Stopped

Name : hvservice
Path : C:\Windows\system32\drivers\hvservice.sys
Service Type : Kernel Driver
Description : Hypervisor/Virtual Machine Support Driver
State : Stopped

Name : HwNClx0101
Path : C:\Windows\system32\Drivers\mshwnclx.sys
Service Type : Kernel Driver
Description : Microsoft Hardware Notifications Class Extension Driver
State : Stopped

Name : hwpolicy
Path : C:\Windows\system32\drivers\hwpolicy.sys
Service Type : Kernel Driver
Description : Hardware Policy Driver
State : Stopped

Name : hyperkbd
Path : C:\Windows\system32\drivers\hyperkbd.sys
Service Type : Kernel Driver
Description : hyperkbd
State : Stopped

Name : HyperVideo
Path : C:\Windows\system32\drivers\HyperVideo.sys
Service Type : Kernel Driver
Description : HyperVideo
State : Stopped

Name : i8042prt
Path : C:\Windows\system32\drivers\i8042prt.sys
Service Type : Kernel Driver
Description : i8042 Keyboard and PS/2 Mouse Port Driver
State : Stopped

Name : iaLPSSi_GPIO
Path : C:\Windows\system32\drivers\iaLPSSi_GPIO.sys
Service Type : Kernel Driver
Description : Intel(R) Serial IO GPIO Controller Driver
State : Stopped

Name : iaLPSSi_I2C
Path : C:\Windows\system32\drivers\iaLPSSi_I2C.sys
Service Type : Kernel Driver
Description : Intel(R) Serial IO I2C Controller Driver
State : Stopped

Name : iaStorAVC
Path : C:\Windows\system32\drivers\iaStorAVC.sys
Service Type : Kernel Driver
Description : Intel Chipset SATA RAID Controller
State : Stopped

Name : iaStorV
Path : C:\Windows\system32\drivers\iaStorV.sys
Service Type : Kernel Driver
Description : Intel RAID Controller Windows 7
State : Stopped

Name : ibbus
Path : C:\Windows\system32\drivers\ibbus.sys
Service Type : Kernel Driver
Description : Mellanox InfiniBand Bus/AL (Filter Driver)
State : Stopped

Name : IndirectKmd
Path : C:\Windows\system32\drivers\IndirectKmd.sys
Service Type : Kernel Driver
Description : Indirect Displays Kernel-Mode Driver
State : Stopped

Name : intelide
Path : C:\Windows\system32\drivers\intelide.sys
Service Type : Kernel Driver
Description : intelide
State : Stopped

Name : intelpep
Path : C:\Windows\system32\drivers\intelpep.sys
Service Type : Kernel Driver
Description : Intel(R) Power Engine Plug-in Driver
State : Running

Name : intelppm
Path : C:\Windows\system32\drivers\intelppm.sys
Service Type : Kernel Driver
Description : Intel Processor Driver
State : Running

Name : IpFilterDriver
Path : C:\Windows\system32\DRIVERS\ipfltdrv.sys
Service Type : Kernel Driver
Description : IP Traffic Filter Driver
State : Stopped

Name : IPMIDRV
Path : C:\Windows\system32\drivers\IPMIDrv.sys
Service Type : Kernel Driver
Description : IPMIDRV
State : Running

Name : IPNAT
Path : C:\Windows\system32\drivers\ipnat.sys
Service Type : Kernel Driver
Description : IP Network Address Translator
State : Stopped

Name : IPsecGW
Path : C:\Windows\system32\drivers\ipsecgw.sys
Service Type : Kernel Driver
Description : Windows IPsec Gateway Driver
State : Stopped

Name : IPT
Path : C:\Windows\system32\drivers\ipt.sys
Service Type : Kernel Driver
Description : IPT
State : Stopped

Name : isapnp
Path : C:\Windows\system32\drivers\isapnp.sys
Service Type : Kernel Driver
Description : isapnp
State : Stopped

Name : iScsiPrt
Path : C:\Windows\system32\drivers\msiscsi.sys
Service Type : Kernel Driver
Description : iScsiPort Driver
State : Stopped

Name : ItSas35i
Path : C:\Windows\system32\drivers\ItSas35i.sys
Service Type : Kernel Driver
Description : ItSas35i
State : Stopped

Name : kbdclass
Path : C:\Windows\system32\drivers\kbdclass.sys
Service Type : Kernel Driver
Description : Keyboard Class Driver
State : Running

Name : kbdhid
Path : C:\Windows\system32\drivers\kbdhid.sys
Service Type : Kernel Driver
Description : Keyboard HID Driver
State : Stopped

Name : kdnic
Path : C:\Windows\system32\drivers\kdnic.sys
Service Type : Kernel Driver
Description : Microsoft Kernel Debug Network Miniport (NDIS 6.20)
State : Running

Name : KSecDD
Path : C:\Windows\system32\Drivers\ksecdd.sys
Service Type : Kernel Driver
Description : KSecDD
State : Running

Name : KSecPkg
Path : C:\Windows\system32\Drivers\ksecpkg.sys
Service Type : Kernel Driver
Description : KSecPkg
State : Running

Name : ksthunk
Path : C:\Windows\system32\drivers\ksthunk.sys
Service Type : Kernel Driver
Description : Kernel Streaming Thunks
State : Stopped

Name : lltdio
Path : C:\Windows\system32\drivers\lltdio.sys
Service Type : Kernel Driver
Description : Link-Layer Topology Discovery Mapper I/O Driver
State : Running

Name : LSI_SAS
Path : C:\Windows\system32\drivers\lsi_sas.sys
Service Type : Kernel Driver
Description : LSI_SAS
State : Stopped

Name : LSI_SAS2i
Path : C:\Windows\system32\drivers\lsi_sas2i.sys
Service Type : Kernel Driver
Description : LSI_SAS2i
State : Stopped

Name : LSI_SAS3i
Path : C:\Windows\system32\drivers\lsi_sas3i.sys
Service Type : Kernel Driver
Description : LSI_SAS3i
State : Stopped

Name : LSI_SSS
Path : C:\Windows\system32\drivers\lsi_sss.sys
Service Type : Kernel Driver
Description : LSI_SSS
State : Stopped

Name : luafv
Path : C:\Windows\system32\drivers\luafv.sys
Service Type : File System Driver
Description : UAC File Virtualization
State : Running

Name : mausbhost
Path : C:\Windows\system32\drivers\mausbhost.sys
Service Type : Kernel Driver
Description : MA-USB Host Controller Driver
State : Stopped

Name : mausbip
Path : C:\Windows\system32\drivers\mausbip.sys
Service Type : Kernel Driver
Description : MA-USB IP Filter Driver
State : Stopped

Name : megasas
Path : C:\Windows\system32\drivers\megasas.sys
Service Type : Kernel Driver
Description : megasas
State : Stopped

Name : megasas2i
Path : C:\Windows\system32\drivers\MegaSas2i.sys
Service Type : Kernel Driver
Description : megasas2i
State : Stopped

Name : megasas35i
Path : C:\Windows\system32\drivers\megasas35i.sys
Service Type : Kernel Driver
Description : megasas35i
State : Stopped

Name : megasr
Path : C:\Windows\system32\drivers\megasr.sys
Service Type : Kernel Driver
Description : megasr
State : Stopped

Name : Microsoft_Bluetooth_AvrcpTransport
Path : C:\Windows\system32\drivers\Microsoft.Bluetooth.AvrcpTransport.sys
Service Type : Kernel Driver
Description : Microsoft Bluetooth Avrcp Transport Driver
State : Stopped

Name : mlx4_bus
Path : C:\Windows\system32\drivers\mlx4_bus.sys
Service Type : Kernel Driver
Description : Mellanox ConnectX Bus Enumerator
State : Stopped

Name : MMCSS
Path : C:\Windows\system32\drivers\mmcss.sys
Service Type : Kernel Driver
Description : Multimedia Class Scheduler
State : Stopped

Name : Modem
Path : C:\Windows\system32\drivers\modem.sys
Service Type : Kernel Driver
Description : Modem
State : Stopped

Name : monitor
Path : C:\Windows\system32\drivers\monitor.sys
Service Type : Kernel Driver
Description : Microsoft Monitor Class Function Driver Service
State : Stopped

Name : mouclass
Path : C:\Windows\system32\drivers\mouclass.sys
Service Type : Kernel Driver
Description : Mouse Class Driver
State : Running

Name : mouhid
Path : C:\Windows\system32\drivers\mouhid.sys
Service Type : Kernel Driver
Description : Mouse HID Driver
State : Stopped

Name : mountmgr
Path : C:\Windows\system32\drivers\mountmgr.sys
Service Type : Kernel Driver
Description : Mount Point Manager
State : Running

Name : mpsdrv
Path : C:\Windows\system32\drivers\mpsdrv.sys
Service Type : Kernel Driver
Description : Windows Defender Firewall Authorization Driver
State : Running

Name : mrxsmb
Path : C:\Windows\system32\DRIVERS\mrxsmb.sys
Service Type : File System Driver
Description : SMB MiniRedirector Wrapper and Engine
State : Running

Name : mrxsmb20
Path : C:\Windows\system32\DRIVERS\mrxsmb20.sys
Service Type : File System Driver
Description : SMB 2.0 MiniRedirector
State : Running

Name : MsBridge
Path : C:\Windows\system32\drivers\bridge.sys
Service Type : Kernel Driver
Description : Microsoft MAC Bridge
State : Stopped

Name : Msfs
Path : C:\Windows\system32\drivers\Msfs.sys
Service Type : File System Driver
Description : Msfs
State : Running

Name : msgpiowin32
Path : C:\Windows\system32\drivers\msgpiowin32.sys
Service Type : Kernel Driver
Description : Common Driver for Buttons, DockMode and Laptop/Slate Indicator
State : Stopped

Name : mshidkmdf
Path : C:\Windows\system32\drivers\mshidkmdf.sys
Service Type : Kernel Driver
Description : Pass-through HID to KMDF Filter Driver
State : Stopped

Name : mshidumdf
Path : C:\Windows\system32\drivers\mshidumdf.sys
Service Type : Kernel Driver
Description : Pass-through HID to UMDF Driver
State : Stopped

Name : msisadrv
Path : C:\Windows\system32\drivers\msisadrv.sys
Service Type : Kernel Driver
Description : msisadrv
State : Running

Name : MSKSSRV
Path : C:\Windows\system32\drivers\MSKSSRV.sys
Service Type : Kernel Driver
Description : Microsoft Streaming Service Proxy
State : Stopped

Name : MsLbfoProvider
Path : C:\Windows\system32\drivers\MsLbfoProvider.sys
Service Type : Kernel Driver
Description : Microsoft Load Balancing/Failover Provider
State : Stopped

Name : MsLldp
Path : C:\Windows\system32\drivers\mslldp.sys
Service Type : Kernel Driver
Description : Microsoft Link-Layer Discovery Protocol
State : Running

Name : MSPCLOCK
Path : C:\Windows\system32\drivers\MSPCLOCK.sys
Service Type : Kernel Driver
Description : Microsoft Streaming Clock Proxy
State : Stopped

Name : MSPQM
Path : C:\Windows\system32\drivers\MSPQM.sys
Service Type : Kernel Driver
Description : Microsoft Streaming Quality Manager Proxy
State : Stopped

Name : MsRPC
Path : C:\Windows\system32\drivers\MsRPC.sys
Service Type : Kernel Driver
Description : MsRPC
State : Stopped

Name : MsSecCore
Path : C:\Windows\system32\drivers\msseccore.sys
Service Type : Kernel Driver
Description : Microsoft Security Core Boot Driver
State : Running

Name : MsSecFlt
Path : C:\Windows\system32\drivers\mssecflt.sys
Service Type : Kernel Driver
Description : Microsoft Security Events Component Minifilter
State : Stopped

Name : MsSecWfp
Path : C:\Windows\system32\drivers\mssecwfp.sys
Service Type : Kernel Driver
Description : Microsoft Security WFP Callout Driver
State : Stopped

Name : mssmbios
Path : C:\Windows\system32\drivers\mssmbios.sys
Service Type : Kernel Driver
Description : Microsoft System Management BIOS Driver
State : Running

Name : MSTEE
Path : C:\Windows\system32\drivers\MSTEE.sys
Service Type : Kernel Driver
Description : Microsoft Streaming Tee/Sink-to-Sink Converter
State : Stopped

Name : MTConfig
Path : C:\Windows\system32\drivers\MTConfig.sys
Service Type : Kernel Driver
Description : Microsoft Input Configuration Driver
State : Stopped

Name : Mup
Path : C:\Windows\system32\Drivers\mup.sys
Service Type : File System Driver
Description : Mup
State : Running

Name : mvumis
Path : C:\Windows\system32\drivers\mvumis.sys
Service Type : Kernel Driver
Description : mvumis
State : Stopped

Name : MxG2hDO64
Path : C:\Windows\system32\DRIVERS\MxG2hDO64.sys
Service Type : Kernel Driver
Description : MxG2hDO64
State : Running

Name : ndfltr
Path : C:\Windows\system32\drivers\ndfltr.sys
Service Type : Kernel Driver
Description : NetworkDirect Service
State : Stopped

Name : NDIS
Path : C:\Windows\system32\drivers\ndis.sys
Service Type : Kernel Driver
Description : NDIS System Driver
State : Running

Name : NdisCap
Path : C:\Windows\system32\drivers\ndiscap.sys
Service Type : Kernel Driver
Description : Microsoft NDIS Capture
State : Stopped

Name : NdisImPlatform
Path : C:\Windows\system32\drivers\NdisImPlatform.sys
Service Type : Kernel Driver
Description : Microsoft Network Adapter Multiplexor Protocol
State : Stopped

Name : NdisTapi
Path : C:\Windows\system32\DRIVERS\ndistapi.sys
Service Type : Kernel Driver
Description : Remote Access NDIS TAPI Driver
State : Running

Name : Ndisuio
Path : C:\Windows\system32\drivers\ndisuio.sys
Service Type : Kernel Driver
Description : NDIS Usermode I/O Protocol
State : Stopped

Name : NdisVirtualBus
Path : C:\Windows\system32\drivers\NdisVirtualBus.sys
Service Type : Kernel Driver
Description : Microsoft Virtual Network Adapter Enumerator
State : Running

Name : NdisWan
Path : C:\Windows\system32\drivers\ndiswan.sys
Service Type : Kernel Driver
Description : Remote Access NDIS WAN Driver
State : Running

Name : ndiswanlegacy
Path : C:\Windows\system32\DRIVERS\ndiswan.sys
Service Type : Kernel Driver
Description : Remote Access LEGACY NDIS WAN Driver
State : Stopped

Name : ndproxy
Path : C:\Windows\system32\DRIVERS\NDProxy.sys
Service Type : Kernel Driver
Description : NDIS Proxy Driver
State : Running

Name : nechesasr
Path : C:\Windows\system32\drivers\nechesasr.sys
Service Type : Kernel Driver
Description : iLO 5 ASR Driver
State : Running

Name : necheschif
Path : C:\Windows\system32\drivers\necheschif.sys
Service Type : Kernel Driver
Description : iLO 5 CHIF Driver
State : Running

Name : NetAdapterCx
Path : C:\Windows\system32\drivers\NetAdapterCx.sys
Service Type : Kernel Driver
Description : Network Adapter Wdf Class Extension Library
State : Stopped

Name : NetBIOS
Path : C:\Windows\system32\drivers\netbios.sys
Service Type : File System Driver
Description : NetBIOS Interface
State : Running

Name : NetBT
Path : C:\Windows\system32\DRIVERS\netbt.sys
Service Type : Kernel Driver
Description : NetBT
State : Running

Name : netvsc
Path : C:\Windows\system32\drivers\netvsc.sys
Service Type : Kernel Driver
Description : netvsc
State : Stopped

Name : ng-netfilter
Path : C:\Windows\system32\DRIVERS\ng-netfilter.sys
Service Type : Kernel Driver
Description : ng-netfilter
State : Stopped

Name : ngelam
Path : C:\Windows\system32\drivers\ngelam.sys
Service Type : Kernel Driver
Description : ngelam
State : Stopped

Name : NgScan
Path : C:\Windows\system32\DRIVERS\ngscan.sys
Service Type : File System Driver
Description : NgScan
State : Running

Name : Npfs
Path : C:\Windows\system32\drivers\Npfs.sys
Service Type : File System Driver
Description : Npfs
State : Running

Name : npsvctrig
Path : C:\Windows\system32\drivers\npsvctrig.sys
Service Type : Kernel Driver
Description : Named pipe service trigger provider
State : Running

Name : nsiproxy
Path : C:\Windows\system32\drivers\nsiproxy.sys
Service Type : Kernel Driver
Description : NSI Proxy Service Driver
State : Running

Name : Ntfs
Path : C:\Windows\system32\drivers\Ntfs.sys
Service Type : File System Driver
Description : Ntfs
State : Running

Name : Null
Path : C:\Windows\system32\drivers\Null.sys
Service Type : Kernel Driver
Description : Null
State : Running

Name : nvdimm
Path : C:\Windows\system32\drivers\nvdimm.sys
Service Type : Kernel Driver
Description : Microsoft NVDIMM device driver
State : Stopped

Name : nvraid
Path : C:\Windows\system32\drivers\nvraid.sys
Service Type : Kernel Driver
Description : nvraid
State : Stopped

Name : nvstor
Path : C:\Windows\system32\drivers\nvstor.sys
Service Type : Kernel Driver
Description : nvstor
State : Stopped

Name : Parport
Path : C:\Windows\system32\drivers\parport.sys
Service Type : Kernel Driver
Description : Parallel port driver
State : Stopped

Name : partmgr
Path : C:\Windows\system32\drivers\partmgr.sys
Service Type : Kernel Driver
Description : Partition driver
State : Running

Name : pci
Path : C:\Windows\system32\drivers\pci.sys
Service Type : Kernel Driver
Description : PCI Bus Driver
State : Running

Name : pciide
Path : C:\Windows\system32\drivers\pciide.sys
Service Type : Kernel Driver
Description : pciide
State : Stopped

Name : pcmcia
Path : C:\Windows\system32\drivers\pcmcia.sys
Service Type : Kernel Driver
Description : pcmcia
State : Stopped

Name : pcw
Path : C:\Windows\system32\drivers\pcw.sys
Service Type : Kernel Driver
Description : Performance Counters for Windows Driver
State : Running

Name : pdc
Path : C:\Windows\system32\drivers\pdc.sys
Service Type : Kernel Driver
Description : pdc
State : Running

Name : PEAUTH
Path : C:\Windows\system32\drivers\peauth.sys
Service Type : Kernel Driver
Description : PEAUTH
State : Running

Name : percsas2i
Path : C:\Windows\system32\drivers\percsas2i.sys
Service Type : Kernel Driver
Description : percsas2i
State : Stopped

Name : percsas3i
Path : C:\Windows\system32\drivers\percsas3i.sys
Service Type : Kernel Driver
Description : percsas3i
State : Stopped

Name : PktMon
Path : C:\Windows\system32\drivers\PktMon.sys
Service Type : Kernel Driver
Description : Packet Monitor Driver
State : Stopped

Name : pmem
Path : C:\Windows\system32\drivers\pmem.sys
Service Type : Kernel Driver
Description : Microsoft persistent memory disk driver
State : Stopped

Name : PNPMEM
Path : C:\Windows\system32\drivers\pnpmem.sys
Service Type : Kernel Driver
Description : Microsoft Memory Module Driver
State : Stopped

Name : PptpMiniport
Path : C:\Windows\system32\drivers\raspptp.sys
Service Type : Kernel Driver
Description : WAN Miniport (PPTP)
State : Running

Name : Processor
Path : C:\Windows\system32\drivers\processr.sys
Service Type : Kernel Driver
Description : Processor Driver
State : Stopped

Name : Psched
Path : C:\Windows\system32\drivers\pacer.sys
Service Type : Kernel Driver
Description : QoS Packet Scheduler
State : Running

Name : qebdrv
Path : C:\Windows\system32\drivers\qevbda.sys
Service Type : Kernel Driver
Description : QLogic FastLinQ Ethernet VBD
State : Stopped

Name : qefcoe
Path : C:\Windows\system32\drivers\qefcoe.sys
Service Type : Kernel Driver
Description : QLogic FCoE driver
State : Stopped

Name : qeois
Path : C:\Windows\system32\drivers\qeois.sys
Service Type : Kernel Driver
Description : QLogic 40G iSCSI Driver
State : Stopped

Name : ql2300i
Path : C:\Windows\system32\drivers\ql2300i.sys
Service Type : Kernel Driver
Description : QLogic Fibre Channel STOR Miniport Inbox Driver (wx64)
State : Stopped

Name : ql40xx2i
Path : C:\Windows\system32\drivers\ql40xx2i.sys
Service Type : Kernel Driver
Description : QLogic iSCSI Miniport Inbox Driver
State : Stopped

Name : qlfcoei
Path : C:\Windows\system32\drivers\qlfcoei.sys
Service Type : Kernel Driver
Description : QLogic [FCoE] STOR Miniport Inbox Driver (wx64)
State : Stopped

Name : QWAVEdrv
Path : C:\Windows\system32\drivers\qwavedrv.sys
Service Type : Kernel Driver
Description : QWAVE driver
State : Stopped

Name : Ramdisk
Path : C:\Windows\system32\DRIVERS\ramdisk.sys
Service Type : Kernel Driver
Description : Windows RAM Disk Driver
State : Stopped

Name : RasAcd
Path : C:\Windows\system32\DRIVERS\rasacd.sys
Service Type : Kernel Driver
Description : Remote Access Auto Connection Driver
State : Stopped

Name : RasAgileVpn
Path : C:\Windows\system32\drivers\AgileVpn.sys
Service Type : Kernel Driver
Description : WAN Miniport (IKEv2)
State : Running

Name : RasGre
Path : C:\Windows\system32\drivers\rasgre.sys
Service Type : Kernel Driver
Description : WAN Miniport (GRE)
State : Running

Name : Rasl2tp
Path : C:\Windows\system32\drivers\rasl2tp.sys
Service Type : Kernel Driver
Description : WAN Miniport (L2TP)
State : Running

Name : RasPppoe
Path : C:\Windows\system32\DRIVERS\raspppoe.sys
Service Type : Kernel Driver
Description : Remote Access PPPOE Driver
State : Running

Name : RasSstp
Path : C:\Windows\system32\drivers\rassstp.sys
Service Type : Kernel Driver
Description : WAN Miniport (SSTP)
State : Running

Name : rdbss
Path : C:\Windows\system32\DRIVERS\rdbss.sys
Service Type : File System Driver
Description : Redirected Buffering Sub System
State : Running

Name : rdpbus
Path : C:\Windows\system32\drivers\rdpbus.sys
Service Type : Kernel Driver
Description : Remote Desktop Device Redirector Bus Driver
State : Running

Name : RDPDR
Path : C:\Windows\system32\drivers\rdpdr.sys
Service Type : Kernel Driver
Description : Remote Desktop Device Redirector Driver
State : Running

Name : RdpVideoMiniport
Path : C:\Windows\system32\drivers\rdpvideominiport.sys
Service Type : Kernel Driver
Description : Remote Desktop Video Miniport Driver
State : Running

Name : ReFS
Path : C:\Windows\system32\drivers\ReFS.sys
Service Type : File System Driver
Description : ReFS
State : Stopped

Name : ReFSv1
Path : C:\Windows\system32\drivers\ReFSv1.sys
Service Type : File System Driver
Description : ReFSv1
State : Stopped

Name : RegCacheFilter
Path : C:\Windows\system32\DRIVERS\RegCacheFilter.sys
Service Type : File System Driver
Description : RegCacheFilter
State : Running

Name : RFCOMM
Path : C:\Windows\system32\drivers\rfcomm.sys
Service Type : Kernel Driver
Description : Bluetooth Device (RFCOMM Protocol TDI)
State : Stopped

Name : rhproxy
Path : C:\Windows\system32\drivers\rhproxy.sys
Service Type : Kernel Driver
Description : Resource Hub proxy driver
State : Stopped

Name : RsFx0603
Path : C:\Windows\system32\DRIVERS\RsFx0603.sys
Service Type : File System Driver
Description : RsFx0603 Driver
State : Stopped

Name : rspndr
Path : C:\Windows\system32\drivers\rspndr.sys
Service Type : Kernel Driver
Description : Link-Layer Topology Discovery Responder
State : Running

Name : s3cap
Path : C:\Windows\system32\drivers\vms3cap.sys
Service Type : Kernel Driver
Description : s3cap
State : Stopped

Name : sacdrv
Path : C:\Windows\system32\DRIVERS\sacdrv.sys
Service Type : Kernel Driver
Description : sacdrv
State : Stopped

Name : sbp2port
Path : C:\Windows\system32\drivers\sbp2port.sys
Service Type : Kernel Driver
Description : SBP-2 Transport/Protocol Bus Driver
State : Stopped

Name : scfilter
Path : C:\Windows\system32\DRIVERS\scfilter.sys
Service Type : Kernel Driver
Description : Smart card PnP Class Filter Driver
State : Stopped

Name : scmbus
Path : C:\Windows\system32\drivers\scmbus.sys
Service Type : Kernel Driver
Description : Microsoft Storage Class Memory Bus Driver
State : Stopped

Name : sdbus
Path : C:\Windows\system32\drivers\sdbus.sys
Service Type : Kernel Driver
Description : sdbus
State : Stopped

Name : SDFRd
Path : C:\Windows\system32\drivers\SDFRd.sys
Service Type : Kernel Driver
Description : SDF Reflector
State : Stopped

Name : sdstor
Path : C:\Windows\system32\drivers\sdstor.sys
Service Type : Kernel Driver
Description : SD Storage Port Driver
State : Stopped

Name : SerCx
Path : C:\Windows\system32\drivers\SerCx.sys
Service Type : Kernel Driver
Description : Serial UART Support Library
State : Stopped

Name : SerCx2
Path : C:\Windows\system32\drivers\SerCx2.sys
Service Type : Kernel Driver
Description : Serial UART Support Library
State : Stopped

Name : Serenum
Path : C:\Windows\system32\drivers\serenum.sys
Service Type : Kernel Driver
Description : Serenum Filter Driver
State : Running

Name : Serial
Path : C:\Windows\system32\drivers\serial.sys
Service Type : Kernel Driver
Description : Serial port driver
State : Running

Name : sermouse
Path : C:\Windows\system32\drivers\sermouse.sys
Service Type : Kernel Driver
Description : Serial Mouse Driver
State : Stopped

Name : sfloppy
Path : C:\Windows\system32\drivers\sfloppy.sys
Service Type : Kernel Driver
Description : High-Capacity Floppy Disk Drive
State : Stopped

Name : SgrmAgent
Path : C:\Windows\system32\drivers\SgrmAgent.sys
Service Type : Kernel Driver
Description : System Guard Runtime Monitor Agent
State : Running

Name : SiSRaid2
Path : C:\Windows\system32\drivers\SiSRaid2.sys
Service Type : Kernel Driver
Description : SiSRaid2
State : Stopped

Name : SiSRaid4
Path : C:\Windows\system32\drivers\sisraid4.sys
Service Type : Kernel Driver
Description : SiSRaid4
State : Stopped

Name : SmartPqi
Path : C:\Windows\system32\drivers\SmartPqi.sys
Service Type : Kernel Driver
Description : SmartPqi
State : Running

Name : SmartSAMD
Path : C:\Windows\system32\drivers\SmartSAMD.sys
Service Type : Kernel Driver
Description : SmartSAMD
State : Stopped

Name : smbdirect
Path : C:\Windows\system32\DRIVERS\smbdirect.sys
Service Type : File System Driver
Description : smbdirect
State : Stopped

Name : snapman
Path : C:\Windows\system32\DRIVERS\snapman.sys
Service Type : Kernel Driver
Description : Acronis Snapshots Manager
State : Running

Name : spaceport
Path : C:\Windows\system32\drivers\spaceport.sys
Service Type : Kernel Driver
Description : Storage Spaces Driver
State : Running

Name : SpbCx
Path : C:\Windows\system32\drivers\SpbCx.sys
Service Type : Kernel Driver
Description : Simple Peripheral Bus Support Library
State : Stopped

Name : srv2
Path : C:\Windows\system32\DRIVERS\srv2.sys
Service Type : File System Driver
Description : Server SMB 2.xxx Driver
State : Running

Name : srvnet
Path : C:\Windows\system32\DRIVERS\srvnet.sys
Service Type : File System Driver
Description : srvnet
State : Running

Name : stexstor
Path : C:\Windows\system32\drivers\stexstor.sys
Service Type : Kernel Driver
Description : stexstor
State : Stopped

Name : storahci
Path : C:\Windows\system32\drivers\storahci.sys
Service Type : Kernel Driver
Description : Microsoft Standard SATA AHCI Driver
State : Stopped

Name : storflt
Path : C:\Windows\system32\drivers\vmstorfl.sys
Service Type : Kernel Driver
Description : Microsoft Hyper-V Storage Accelerator
State : Stopped

Name : stornvme
Path : C:\Windows\system32\drivers\stornvme.sys
Service Type : Kernel Driver
Description : Microsoft Standard NVM Express Driver
State : Stopped

Name : storqosflt
Path : C:\Windows\system32\drivers\storqosflt.sys
Service Type : File System Driver
Description : Storage QoS Filter Driver
State : Running

Name : storufs
Path : C:\Windows\system32\drivers\storufs.sys
Service Type : Kernel Driver
Description : Microsoft Universal Flash Storage (UFS) Driver
State : Stopped

Name : storvsc
Path : C:\Windows\system32\drivers\storvsc.sys
Service Type : Kernel Driver
Description : storvsc
State : Stopped

Name : swenum
Path : C:\Windows\system32\DriverStore\FileRepository\swenum.inf_amd64_31f554b660026323\swenum.sys
Service Type : Kernel Driver
Description : Software Bus Driver
State : Running

Name : Synth3dVsc
Path : C:\Windows\system32\drivers\Synth3dVsc.sys
Service Type : Kernel Driver
Description : Synth3dVsc
State : Stopped

Name : system_monitor
Path : C:\Windows\system32\DRIVERS\system_monitor.sys
Service Type : Kernel Driver
Description : system_monitor
State : Running

Name : Tcpip
Path : C:\Windows\system32\drivers\tcpip.sys
Service Type : Kernel Driver
Description : TCP/IP Protocol Driver
State : Running

Name : Tcpip6
Path : C:\Windows\system32\drivers\tcpip.sys
Service Type : Kernel Driver
Description : @todo.dll,-100;Microsoft IPv6 Protocol Driver
State : Stopped

Name : tcpipreg
Path : C:\Windows\system32\drivers\tcpipreg.sys
Service Type : Kernel Driver
Description : TCP/IP Registry Compatibility
State : Running

Name : tdx
Path : C:\Windows\system32\DRIVERS\tdx.sys
Service Type : Kernel Driver
Description : NetIO Legacy TDI Support Driver
State : Running

Name : terminpt
Path : C:\Windows\system32\drivers\terminpt.sys
Service Type : Kernel Driver
Description : Microsoft Remote Desktop Input Driver
State : Running

Name : tib_mounter
Path : C:\Windows\system32\DRIVERS\tib_mounter.sys
Service Type : Kernel Driver
Description : Acronis TIB Mounter
State : Running

Name : TPM
Path : C:\Windows\system32\drivers\tpm.sys
Service Type : Kernel Driver
Description : TPM
State : Stopped

Name : TsUsbFlt
Path : C:\Windows\system32\drivers\tsusbflt.sys
Service Type : Kernel Driver
Description : Remote Desktop USB Hub Class Filter Driver
State : Stopped

Name : TsUsbGD
Path : C:\Windows\system32\drivers\TsUsbGD.sys
Service Type : Kernel Driver
Description : Remote Desktop Generic USB Device
State : Stopped

Name : tsusbhub
Path : C:\Windows\system32\drivers\tsusbhub.sys
Service Type : Kernel Driver
Description : Remote Desktop USB Hub
State : Stopped

Name : tunnel
Path : C:\Windows\system32\drivers\tunnel.sys
Service Type : Kernel Driver
Description : Microsoft Tunnel Miniport Adapter Driver
State : Stopped

Name : UASPStor
Path : C:\Windows\system32\drivers\uaspstor.sys
Service Type : Kernel Driver
Description : USB Attached SCSI (UAS) Driver
State : Stopped

Name : UcmCx0101
Path : C:\Windows\system32\Drivers\UcmCx.sys
Service Type : Kernel Driver
Description : USB Connector Manager KMDF Class Extension
State : Stopped

Name : UcmTcpciCx0101
Path : C:\Windows\system32\Drivers\UcmTcpciCx.sys
Service Type : Kernel Driver
Description : UCM-TCPCI KMDF Class Extension
State : Stopped

Name : UcmUcsi
Path : C:\Windows\system32\drivers\UcmUcsi.sys
Service Type : Kernel Driver
Description : USB Connector Manager UCSI Client
State : Stopped

Name : UcmUcsiAcpiClient
Path : C:\Windows\system32\drivers\UcmUcsiAcpiClient.sys
Service Type : Kernel Driver
Description : UCM-UCSI ACPI Client
State : Stopped

Name : UcmUcsiCx0101
Path : C:\Windows\system32\Drivers\UcmUcsiCx.sys
Service Type : Kernel Driver
Description : UCM-UCSI KMDF Class Extension
State : Stopped

Name : Ucx01000
Path : C:\Windows\system32\drivers\ucx01000.sys
Service Type : Kernel Driver
Description : USB Host Support Library
State : Running

Name : UdeCx
Path : C:\Windows\system32\drivers\udecx.sys
Service Type : Kernel Driver
Description : USB Device Emulation Support Library
State : Stopped

Name : udfs
Path : C:\Windows\system32\DRIVERS\udfs.sys
Service Type : File System Driver
Description : udfs
State : Stopped

Name : UEFI
Path : C:\Windows\system32\drivers\UEFI.sys
Service Type : Kernel Driver
Description : Microsoft UEFI Driver
State : Stopped

Name : UevAgentDriver
Path : C:\Windows\system32\drivers\UevAgentDriver.sys
Service Type : File System Driver
Description : UevAgentDriver
State : Stopped

Name : Ufx01000
Path : C:\Windows\system32\drivers\ufx01000.sys
Service Type : Kernel Driver
Description : USB Function Class Extension
State : Stopped

Name : UfxChipidea
Path : C:\Windows\system32\drivers\UfxChipidea.sys
Service Type : Kernel Driver
Description : USB Chipidea Controller
State : Stopped

Name : ufxsynopsys
Path : C:\Windows\system32\drivers\ufxsynopsys.sys
Service Type : Kernel Driver
Description : USB Synopsys Controller
State : Stopped

Name : umbus
Path : C:\Windows\system32\drivers\umbus.sys
Service Type : Kernel Driver
Description : UMBus Enumerator Driver
State : Running

Name : UmPass
Path : C:\Windows\system32\drivers\umpass.sys
Service Type : Kernel Driver
Description : Microsoft UMPass Driver
State : Stopped

Name : UrsChipidea
Path : C:\Windows\system32\drivers\urschipidea.sys
Service Type : Kernel Driver
Description : Chipidea USB Role-Switch Driver
State : Stopped

Name : UrsCx01000
Path : C:\Windows\system32\drivers\urscx01000.sys
Service Type : Kernel Driver
Description : USB Role-Switch Support Library
State : Stopped

Name : UrsSynopsys
Path : C:\Windows\system32\drivers\urssynopsys.sys
Service Type : Kernel Driver
Description : Synopsys USB Role-Switch Driver
State : Stopped

Name : usbccgp
Path : C:\Windows\system32\drivers\usbccgp.sys
Service Type : Kernel Driver
Description : Microsoft USB Generic Parent Driver
State : Stopped

Name : usbehci
Path : C:\Windows\system32\drivers\usbehci.sys
Service Type : Kernel Driver
Description : Microsoft USB 2.0 Enhanced Host Controller Miniport Driver
State : Running

Name : usbhub
Path : C:\Windows\system32\drivers\usbhub.sys
Service Type : Kernel Driver
Description : Microsoft USB Standard Hub Driver
State : Running

Name : USBHUB3
Path : C:\Windows\system32\drivers\UsbHub3.sys
Service Type : Kernel Driver
Description : SuperSpeed Hub
State : Running

Name : usbohci
Path : C:\Windows\system32\drivers\usbohci.sys
Service Type : Kernel Driver
Description : Microsoft USB Open Host Controller Miniport Driver
State : Stopped

Name : usbprint
Path : C:\Windows\system32\drivers\usbprint.sys
Service Type : Kernel Driver
Description : Microsoft USB PRINTER Class
State : Stopped

Name : usbser
Path : C:\Windows\system32\drivers\usbser.sys
Service Type : Kernel Driver
Description : Microsoft USB Serial Driver
State : Stopped

Name : USBSTOR
Path : C:\Windows\system32\drivers\USBSTOR.SYS
Service Type : Kernel Driver
Description : USB Mass Storage Driver
State : Running

Name : usbuhci
Path : C:\Windows\system32\drivers\usbuhci.sys
Service Type : Kernel Driver
Description : Microsoft USB Universal Host Controller Miniport Driver
State : Stopped

Name : USBXHCI
Path : C:\Windows\system32\drivers\USBXHCI.SYS
Service Type : Kernel Driver
Description : USB xHCI Compliant Host Controller
State : Running

Name : vdrvroot
Path : C:\Windows\system32\drivers\vdrvroot.sys
Service Type : Kernel Driver
Description : Microsoft Virtual Drive Enumerator
State : Running

Name : VerifierExt
Path : C:\Windows\system32\drivers\VerifierExt.sys
Service Type : Kernel Driver
Description : Driver Verifier Extension
State : Stopped

Name : vhdmp
Path : C:\Windows\system32\drivers\vhdmp.sys
Service Type : Kernel Driver
Description : vhdmp
State : Stopped

Name : vhf
Path : C:\Windows\system32\drivers\vhf.sys
Service Type : Kernel Driver
Description : Virtual HID Framework (VHF) Driver
State : Stopped

Name : vmbus
Path : C:\Windows\system32\drivers\vmbus.sys
Service Type : Kernel Driver
Description : Virtual Machine Bus
State : Stopped

Name : VMBusHID
Path : C:\Windows\system32\drivers\VMBusHID.sys
Service Type : Kernel Driver
Description : VMBusHID
State : Stopped

Name : vmgid
Path : C:\Windows\system32\drivers\vmgid.sys
Service Type : Kernel Driver
Description : Microsoft Hyper-V Guest Infrastructure Driver
State : Stopped

Name : vncmirror
Path : C:\Windows\system32\drivers\vncmirror.sys
Service Type : Kernel Driver
Description : vncmirror
State : Running

Name : volmgr
Path : C:\Windows\system32\drivers\volmgr.sys
Service Type : Kernel Driver
Description : Volume Manager Driver
State : Running

Name : volmgrx
Path : C:\Windows\system32\drivers\volmgrx.sys
Service Type : Kernel Driver
Description : Dynamic Volume Manager
State : Running

Name : volsnap
Path : C:\Windows\system32\drivers\volsnap.sys
Service Type : Kernel Driver
Description : Volume Shadow Copy driver
State : Running

Name : volume
Path : C:\Windows\system32\drivers\volume.sys
Service Type : Kernel Driver
Description : Volume driver
State : Running

Name : volume_tracker
Path : C:\Windows\system32\DRIVERS\volume_tracker.sys
Service Type : Kernel Driver
Description : Acronis Volume Tracker
State : Running

Name : vpci
Path : C:\Windows\system32\drivers\vpci.sys
Service Type : Kernel Driver
Description : Microsoft Hyper-V Virtual PCI Bus
State : Stopped

Name : vsmraid
Path : C:\Windows\system32\drivers\vsmraid.sys
Service Type : Kernel Driver
Description : vsmraid
State : Stopped

Name : VSTXRAID
Path : C:\Windows\system32\drivers\vstxraid.sys
Service Type : Kernel Driver
Description : VIA StorX Storage RAID Controller Windows Driver
State : Stopped

Name : WacomPen
Path : C:\Windows\system32\drivers\wacompen.sys
Service Type : Kernel Driver
Description : Wacom Serial Pen HID Driver
State : Stopped

Name : wanarp
Path : C:\Windows\system32\DRIVERS\wanarp.sys
Service Type : Kernel Driver
Description : Remote Access IP ARP Driver
State : Running

Name : wanarpv6
Path : C:\Windows\system32\DRIVERS\wanarp.sys
Service Type : Kernel Driver
Description : Remote Access IPv6 ARP Driver
State : Stopped

Name : wcifs
Path : C:\Windows\system32\drivers\wcifs.sys
Service Type : File System Driver
Description : Windows Container Isolation
State : Running

Name : wcnfs
Path : C:\Windows\system32\drivers\wcnfs.sys
Service Type : File System Driver
Description : Windows Container Name Virtualization
State : Stopped

Name : Wdf01000
Path : C:\Windows\system32\drivers\Wdf01000.sys
Service Type : Kernel Driver
Description : Kernel Mode Driver Frameworks service
State : Running

Name : WdmCompanionFilter
Path : C:\Windows\system32\drivers\WdmCompanionFilter.sys
Service Type : Kernel Driver
Description : WdmCompanionFilter
State : Stopped

Name : WFPLWFS
Path : C:\Windows\system32\drivers\wfplwfs.sys
Service Type : Kernel Driver
Description : Microsoft Windows Filtering Platform
State : Running

Name : WIMMount
Path : C:\Windows\system32\drivers\wimmount.sys
Service Type : File System Driver
Description : WIMMount
State : Stopped

Name : WindowsTrustedRT
Path : C:\Windows\system32\drivers\WindowsTrustedRT.sys
Service Type : Kernel Driver
Description : Windows Trusted Execution Environment Class Extension
State : Running

Name : WindowsTrustedRTProxy
Path : C:\Windows\system32\drivers\WindowsTrustedRTProxy.sys
Service Type : Kernel Driver
Description : Microsoft Windows Trusted Runtime Secure Service
State : Running

Name : WinMad
Path : C:\Windows\system32\drivers\winmad.sys
Service Type : Kernel Driver
Description : WinMad Service
State : Stopped

Name : WinNat
Path : C:\Windows\system32\drivers\winnat.sys
Service Type : Kernel Driver
Description : Windows NAT Driver
State : Stopped

Name : WinQuic
Path : C:\Windows\system32\drivers\winquic.sys
Service Type : Kernel Driver
Description : WinQuic
State : Running

Name : WINUSB
Path : C:\Windows\system32\drivers\WinUSB.SYS
Service Type : Kernel Driver
Description : WinUsb Driver
State : Stopped

Name : WinVerbs
Path : C:\Windows\system32\drivers\winverbs.sys
Service Type : Kernel Driver
Description : WinVerbs Service
State : Stopped

Name : WmiAcpi
Path : C:\Windows\system32\drivers\wmiacpi.sys
Service Type : Kernel Driver
Description : Microsoft Windows Management Interface for ACPI
State : Running

Name : Wof
Path : C:\Windows\system32\drivers\Wof.sys
Service Type : File System Driver
Description : Windows Overlay File System Filter Driver
State : Running

Name : WpdUpFltr
Path : C:\Windows\system32\drivers\WpdUpFltr.sys
Service Type : Kernel Driver
Description : WPD Upper Class Filter Driver
State : Running

Name : ws2ifsl
Path : C:\Windows\system32\drivers\ws2ifsl.sys
Service Type : Kernel Driver
Description : Winsock IFS Driver
State : Stopped

Name : WudfPf
Path : C:\Windows\system32\drivers\WudfPf.sys
Service Type : Kernel Driver
Description : User Mode Driver Frameworks Platform Driver
State : Stopped

Name : WUDFRd
Path : C:\Windows\system32\drivers\WUDFRd.sys
Service Type : Kernel Driver
Description : Windows Driver Foundation - User-mode Driver Framework Reflector
State : Running

Name : WUDFWpdFs
Path : C:\Windows\system32\DRIVERS\WUDFRd.sys
Service Type : Kernel Driver
Description : WPD File System driver
State : Running
92438 - WordPad History
-
Synopsis
Nessus was able to gather WordPad opened file history on the remote host.
Description
Nessus was able to generate a report of files opened in WordPad on the remote host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

C:\Users\techexcel\Downloads\PennyDrop_123419.xls
C:\Users\techexcel\Downloads\Trade Summary with Exp_05122023_024111.xls
C:\Users\techexcel\AppData\Local\Microsoft\Windows\INetCache\IE\UX0G12JL\instdata24042024184928.xls
D:\Techexcel\IMPORTTRADEFILES\INSTBULKCLIMPORT.xls
C:\Users\techexcel\Desktop\Sms_Template.xlsx
C:\Users\techexcel\AppData\Local\Temp\3\Rar$DIa18200.37890\IO DP MASTER.xls
C:\Users\techexcel\Desktop\INSTBULKCLIMPORT (3).xls
C:\Users\techexcel\AppData\Local\Microsoft\Windows\INetCache\IE\05Z8F701\666120615_1600_06072024120617.xls
C:\Users\techexcel\Downloads\NinstDashboard28022025022726.csv

WordPad report attached.

106375 - nginx HTTP Server Detection
-
Synopsis
The nginx HTTP server was detected on the remote host.
Description
Nessus was able to detect the nginx HTTP server by looking at the HTTP banner on the remote host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0677
Plugin Information
Published: 2018/01/26, Modified: 2023/05/24
Plugin Output

tcp/80/www


URL : http://172.17.100.31/
Version : unknown
source : Server: nginx

106375 - nginx HTTP Server Detection
-
Synopsis
The nginx HTTP server was detected on the remote host.
Description
Nessus was able to detect the nginx HTTP server by looking at the HTTP banner on the remote host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0677
Plugin Information
Published: 2018/01/26, Modified: 2023/05/24
Plugin Output

tcp/81/www


URL : http://172.17.100.31:81/
Version : unknown
source : Server: nginx
Compliance 'FAILED'
Compliance 'SKIPPED'
Compliance 'PASSED'
Compliance 'INFO', 'WARNING', 'ERROR'
Remediations
Suggested Remediations
Taking the following actions across 10 hosts would resolve 28% of the vulnerabilities on the network.
Action to take Vulns Hosts
KB4577015: Windows 10 Version 1607 and Windows Server 2016 September 2020 Security Update: Apply Cumulative Update KB4577015. 1130 1
Security Updates for Microsoft SQL Server (November 2025): Microsoft has released security updates for Microsoft SQL Server. 714 7
Security Updates for Microsoft Office Products (December 2025): Microsoft has released the following updates to address these issues: - KB5002812 - KB5002818 - KB5002819 545 1
Security Updates for Microsoft Office Products (April 2021): Microsoft has released the following security updates to address this issue: -KB2553491 -KB2589361 -KB3178639 -KB3178643 -KB4504738 -KB4504722 -KB4504726 -KB4504724 -KB4504739 -KB4504727 322 1
Install KB5071544 259 7
Oracle Database Multiple Vulnerabilities (April 2012 CPU): Apply the appropriate patch according to the April 2012 Oracle Critical Patch Update advisory. 174 1
Security Updates for Microsoft .NET Framework (January 2025): Microsoft has released security updates for Microsoft .NET Framework. 168 6
Security Updates for Microsoft SQL Server OLE DB Driver (July 2024): Microsoft has released security updates for the Microsoft SQL OLE DB Driver. 168 6
Oracle Java SE Multiple Vulnerabilities (October 2025 CPU): Apply the appropriate patch according to the October 2025 Oracle Critical Patch Update advisory. 148 2
Mozilla Firefox < 146.0.1: Upgrade to Mozilla Firefox version 146.0.1 or later. 126 1
Install KB5071543 118 2
Security Update for Microsoft .NET Core (October 2025): Update .NET Core, remove vulnerable packages and refer to vendor advisory. 102 2
Security Updates for Microsoft Excel Products (April 2021): Microsoft has released the following security updates to address this issue: -KB3017810 -KB4504721 -KB4504735 For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update. 96 1
Security Updates for Microsoft Word Products (December 2025): Microsoft has released KB5002806 to address this issue. 81 1
RARLAB WinRAR < 7.13 Directory Traversal (CVE-2025-8088): Upgrade to RARLAB WinRAR version 7.13 or later. 63 9
Security Updates for Microsoft Office Products (March 2021): Microsoft has released the following security updates to address this issue: -KB4493228 -KB4493203 -KB4504703 -KB4493225 -KB4493200 -KB4493214 59 1
Security Updates for Outlook (July 2025): Microsoft has released KB5002747 to address this issue. 48 1
Install KB5002406 45 1
Install KB4484243 43 1
Security Updates for Microsoft Word Products (April 2021): Microsoft has released the following security updates to address this issue: -KB4493208 -KB4493218 -KB4493198 For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update. 41 1
7-Zip < 25.01: Upgrade to 7-Zip version 25.01 or later. 33 3
Security Updates for Microsoft .NET Framework (October 2020): Microsoft has released security updates for Microsoft .NET Framework. 30 1
Microsoft ASP.NET Core Security Feature Bypass (October 2025): Update .NET Core to version 8.0.21, 9.0.10, 10.0.0-rc.2.25502.107 or later. 30 2
Install KB4484217 29 1
Security Updates for Outlook (April 2021): Microsoft has released the following security updates to address this issue: -KB4504712 -KB4504733 -KB4493185 For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update. 26 1
Install KB5002253 25 1
Install KB5002427 23 1
Node.js Multiple Vulnerabilities (November 2018 Security Releases): Upgrade Node.js to 6.15 / 8.14.0 / 10.14.0 / 11.3.0 or later. 20 1
Install KB5002820 20 1
Apache Tomcat 9.0.0.M1 < 9.0.110: Upgrade to Apache Tomcat version 9.0.110 or later. 20 1
Install KB4493185 19 1
Install KB4504739 18 1
MS13-085: Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2885080): Microsoft has released a set of patches for Excel 2007, Excel 2010, Excel 2013, Office 2007, Office 2010, Office 2013, Excel Viewer, and Office Compatibility Pack. 18 1
Notepad++ < 8.8.2 Privilege Escalation (CVE-2025-49144): Upgrade to Notepad++ 8.8.2 or later. 18 3
Security Updates for Microsoft PowerPoint Products (October 2025): Microsoft has released KB5002790 to address this issue. 15 1
VMware Tools 11.x < 12.5.4 / 13.x < 13.0.5 Multiple Vulnerabilities (VMSA-2025-0015): Upgrade to VMware Tools version 12.5.4, 13.0.5 or later. 15 5
Install KB5002790 14 1
Security Updates for Outlook (January 2019): Microsoft has released the following security updates to address this issue: -KB4461595 -KB4461601 -KB4461623 For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update. 14 1
Install KB5044280 12 1
MS17-013: Security Update for Microsoft Graphics Component (4013075): Microsoft has released a set of patches for Windows XP, 2003, Vista, 2008, 7, 2008 R2, 2012, 8.1, RT 8.1, 2012 R2, 10, and 2016. Additionally, Microsoft has released a set of patches for Office 2007, Office 2010, Word Viewer, Skype for Business 2016, Lync 2010, Lync 2010 Attendee, Lync 2013, Lync Basic 2013, Live Meeting 2007 Console, and Silverlight 5. 12 1
Install KB5002806 12 1
Security Updates for Microsoft .NET Framework (October 2024): Microsoft has released security updates for Microsoft .NET Framework. 11 1
Install KB4504707 11 1
Install KB4493218 11 1
Install KB4461625 11 1
Install KB4504702 9 1
Security Updates for Microsoft PowerPoint Products (March 2021): Microsoft has released the following security updates to address this issue: -KB4493227 -KB4504702 -KB4493224 9 1
MS09-035: Vulnerabilities in Visual Studio Active Template Library Could Allow Remote Code Execution (969706): Microsoft has released a set of patches for Visual Studio .NET 2003, Visual Studio 2005 and 2008, as well as Visual C++ 2005 and 2008. 9 3
Install KB3178687 8 1
Install KB3115197 8 1
Install KB5002683 8 1
Install KB3178702 8 1
Security Updates for Microsoft Excel Products (December 2025): Microsoft has released KB5002820 to address this issue. 6 1
Security Updates for Microsoft Publisher Products (September 2024): Microsoft has released KB5002566 to address this issue. 6 1
Visual Studio Tools for Applications Elevation of Privilege (CVE-2025-29803): Upgrade to VSTA 16.0.35907.0, 17.0.35906.0 or later. 6 6
Install KB4032216 5 1
Oracle MySQL Connectors (October 2024 CPU): Apply the appropriate patch according to the October 2024 Oracle Critical Patch Update advisory. 5 1
Apache Log4j 1.2 JMSAppender Remote Code Execution (CVE-2021-4104): Upgrade to Apache Log4j version 2.16.0 or later since 1.x is end of life. Upgrading to the latest versions for Apache Log4j is highly recommended as intermediate versions / patches have known high severity vulnerabilities and the vendor is updating their advisories often as new research and knowledge about the impact of Log4j is discovered. Refer to https://logging.apache.org/log4j/2.x/security.html for the latest versions. 5 5
Install KB5002426 4 1
MS13-094: Vulnerability in Microsoft Outlook Could Allow Information Disclosure (2894514): Microsoft has released a set of patches for Office 2007, 2010, 2013 and 2013 RT. 4 2
Install MS18-01 3 1
Install KB3203467 3 1
Security Updates for Microsoft Publisher Products (April 2020): Microsoft has released the following security updates to address this issue: -KB3162033 -KB4011097 -KB4032216 3 1
Install MS18-01 3 1
Install KB5002221 3 1
JQuery 1.2 < 3.5.0 Multiple XSS: Upgrade to JQuery version 3.5.0 or later. 2 1
VMware Tools 10.x / 11.x / 12.x < 12.1.5 DoS (VMSA-2022-0029): Upgrade to VMware Tools version 12.1.5 or later. 2 1
Install KB4484455 2 1
Install KB3213626 2 1
Install KB3115246 2 1
Install KB3054834 2 1
Install KB2881029 2 1
Install KB5002566 2 1
Install KB3213551 2 1
Install KB3191932 2 1
Curl Use-After-Free < 7.87 (CVE-2022-43552): Upgrade Curl to version 7.87.0 or later 2 2
MS12-021: Vulnerability in Visual Studio Could Allow Elevation of Privilege (2651019): Microsoft has released a set of patches for Microsoft Visual Studio 2008 SP1, 2010, and 2010 SP1. 2 2
Curl 7.84 <= 8.2.1 Header DoS (CVE-2023-38039): Upgrade Curl to version 8.3.0 or later 2 2
Security Update for Microsoft Visual Studio Code Python Extension (July 2025): Update the Microsoft Visual Studio Code Python Extension to version 2025.8.1 or later. 1 1
Install KB4504738 1 1
Install KB3213636 1 1
Install KB3191908 1 1
Install KB3115248 1 1
Install KB3114885 1 1
Install KB3114565 1 1
Install KB3114400 1 1
Install KB2965313 1 1
Install KB2920812 1 1
Install KB2889841 1 1
Install KB2579115 1 1
MS11-049: Vulnerability in the Microsoft XML Editor Could Allow Information Disclosure (2543893): Microsoft has released a set of patches for InfoPath 2007 and 2010, SQL Server 2005, 2008, and 2008 R2, SQL Server Management Studio Express 2005, Visual Studio 2005, 2008, and 2010. 1 1
MS11-067: Vulnerability in Microsoft Report Viewer Could Allow Information Disclosure (2578230): Microsoft has released a set of patches for Microsoft Visual Studio 2005 SP1 and the Microsoft Report Viewer 2005 SP1 Redistributable Package. 1 1
Security Updates for Windows Malicious Software Removal Tool (January 2023): Microsoft has released version 5.109 to address this issue. 1 1
Node.js Module node-tar < 6.2.1 DoS: Upgrade to node-tar version 6.2.1 or later. 1 1
Install KB5002622 1 1
Install KB3115419 1 1
Install KB3115279 1 1
Security Updates for Microsoft OneNote Products (April 2025): Microsoft has released KB5002622 to address this issue. 1 1
KB4483229: Windows 10 Version 1607 and Windows Server 2016 December 2018 OOB Security Update: Apply Cumulative Update KB4483229. 1 1
Security Updates for SQL Server Management Studio (April 2025): Microsoft has released SSMS version 20.2.1 to address this issue. 1 1
Veeam Agent for Microsoft Windows 6.x < 6.3.2.1205 Privilege Escalation (CVE-2025-24287): Upgrade to Veeam Agent for Microsoft Windows version 6.3.2.1205 or later. 0 1
Microsoft Azure Data Studio < 1.48.0 Elevation of Privilege Vulnerability (CVE-2024-26203): Upgrade to Microsoft Azure Data Studio version 1.48.0 or later. 0 5
© 2026 Tenable™, Inc. All rights reserved.