Nessus Report

Report generated by Tenable Nessus™

Server 4

Fri, 16 Jan 2026 18:25:25 India Standard Time

TABLE OF CONTENTS
Vulnerabilities by HostExpand All | Collapse All
172.17.100.35
20
72
22
7
1747
Critical
High
Medium
Low
Info
Scan Information
Start time: Fri Jan 16 16:15:22 2026
End time: Fri Jan 16 17:05:06 2026
Host Information
Netbios Name: LIVETECHROBO
IP: 172.17.100.35
MAC Address: 00:50:56:BC:FC:73
OS: Microsoft Windows 10 Pro Build 19045
Vulnerabilities

249132 - KB5063709: Windows 10 version 21H2 / Windows 10 Version 22H2 Security Update (August 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5063709. It is, therefore, affected by multiple vulnerabilities

- Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
(CVE-2025-53766)

- Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. (CVE-2025-49751)

- Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. (CVE-2025-49743)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5063709
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.017
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/08/12, Modified: 2025/10/29
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5063709

- C:\WINDOWS\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.19041.5965
Should be : 10.0.19041.6216
270379 - KB5066791: Windows 10 version 21H2 / Windows 10 Version 22H2 Security Update (October 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5066791. It is, therefore, affected by multiple vulnerabilities

- tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka Predictor heap-buffer-overflow. (CVE-2016-9535)

- In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image. (CVE-2025-47827)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5066791
Risk Factor
High
CVSS v3.0 Base Score
9.9 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
9.2
EPSS Score
0.0824
CVSS v2.0 Base Score
7.5 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
6.2 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2016-9535
CVE CVE-2025-24052
CVE CVE-2025-24990
CVE CVE-2025-25004
CVE CVE-2025-47827
CVE CVE-2025-48813
CVE CVE-2025-49708
CVE CVE-2025-50152
CVE CVE-2025-50175
CVE CVE-2025-53139
CVE CVE-2025-53150
CVE CVE-2025-53768
CVE CVE-2025-54957
CVE CVE-2025-55325
CVE CVE-2025-55326
CVE CVE-2025-55328
CVE CVE-2025-55331
CVE CVE-2025-55332
CVE CVE-2025-55333
CVE CVE-2025-55335
CVE CVE-2025-55336
CVE CVE-2025-55338
CVE CVE-2025-55340
CVE CVE-2025-55678
CVE CVE-2025-55679
CVE CVE-2025-55680
CVE CVE-2025-55681
CVE CVE-2025-55685
CVE CVE-2025-55686
CVE CVE-2025-55687
CVE CVE-2025-55689
CVE CVE-2025-55692
CVE CVE-2025-55695
CVE CVE-2025-55696
CVE CVE-2025-55699
CVE CVE-2025-55700
CVE CVE-2025-55701
CVE CVE-2025-58714
CVE CVE-2025-58715
CVE CVE-2025-58716
CVE CVE-2025-58717
CVE CVE-2025-58718
CVE CVE-2025-58719
CVE CVE-2025-58720
CVE CVE-2025-58722
CVE CVE-2025-58725
CVE CVE-2025-58726
CVE CVE-2025-58727
CVE CVE-2025-58728
CVE CVE-2025-58729
CVE CVE-2025-58730
CVE CVE-2025-58732
CVE CVE-2025-58733
CVE CVE-2025-58734
CVE CVE-2025-58735
CVE CVE-2025-58736
CVE CVE-2025-58738
CVE CVE-2025-58739
CVE CVE-2025-59185
CVE CVE-2025-59187
CVE CVE-2025-59190
CVE CVE-2025-59191
CVE CVE-2025-59192
CVE CVE-2025-59193
CVE CVE-2025-59195
CVE CVE-2025-59196
CVE CVE-2025-59197
CVE CVE-2025-59198
CVE CVE-2025-59199
CVE CVE-2025-59200
CVE CVE-2025-59201
CVE CVE-2025-59202
CVE CVE-2025-59203
CVE CVE-2025-59204
CVE CVE-2025-59205
CVE CVE-2025-59207
CVE CVE-2025-59208
CVE CVE-2025-59209
CVE CVE-2025-59211
CVE CVE-2025-59214
CVE CVE-2025-59230
CVE CVE-2025-59242
CVE CVE-2025-59244
CVE CVE-2025-59253
CVE CVE-2025-59254
CVE CVE-2025-59255
CVE CVE-2025-59259
CVE CVE-2025-59275
CVE CVE-2025-59277
CVE CVE-2025-59278
CVE CVE-2025-59280
CVE CVE-2025-59282
CVE CVE-2025-59294
CVE CVE-2025-59295
MSKB 5066791
XREF MSFT:MS25-5066791
XREF CISA-KNOWN-EXPLOITED:2025/11/04
XREF IAVA:2025-A-0775-S
XREF IAVA:2025-A-0776-S
Plugin Information
Published: 2025/10/14, Modified: 2025/11/18
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5066791

- C:\WINDOWS\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.19041.5965
Should be : 10.0.19041.6456

58134 - Microsoft Silverlight SEoL
-
Synopsis
An unsupported version of Microsoft Silverlight is installed on the remote host.
Description
According to its version, the installation of the Microsoft Silverlight on the remote host is no longer maintained by its vendor or provider.

Lack of support implies that no new security patches for the product will be released by the vendor. As a result, it is likely to contain security vulnerabilities.
See Also
Solution
Microsoft Silverlight has been discontinued. Please refer to the vendor for support.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
References
XREF IAVA:0001-A-0559
Plugin Information
Published: 2012/02/27, Modified: 2024/08/09
Plugin Output

tcp/0


Path : C:\Program Files\Microsoft Silverlight\5.1.50907.0
Installed version : 5.1.50907.0
Security End of Life : October 11, 2021
Time since Security End of Life (Est.) : >= 4 years

214965 - Mozilla Firefox < 135.0
-
Synopsis
A web browser installed on the remote Windows host is affected by multiple vulnerabilities.
Description
The version of Firefox installed on the remote Windows host is prior to 135.0. It is, therefore, affected by multiple vulnerabilities as referenced in the mfsa2025-07 advisory.

- Memory safety bugs present in Firefox 134 and Thunderbird 134. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. (CVE-2025-1020)

- An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. (CVE-2025-1009)

- An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially exploitable crash. (CVE-2025-1010)

- The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user.
This could have been leveraged to perform a potential spoofing attack. (CVE-2025-1018)

- A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage this to achieve code execution. (CVE-2025-1011)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Mozilla Firefox version 135.0 or later.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0018
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/02/04, Modified: 2025/11/18
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Mozilla Firefox
Installed version : 134.0
Fixed version : 135.0
233423 - Mozilla Firefox < 136.0.4
-
Synopsis
A web browser installed on the remote Windows host is affected by a vulnerability.
Description
The version of Firefox installed on the remote Windows host is prior to 136.0.4. It is, therefore, affected by a vulnerability as referenced in the mfsa2025-19 advisory.

- Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in our IPC code. A compromised child process could cause the parent process to return an unintentionally powerful handle, leading to a sandbox escape. The original vulnerability was being exploited in the wild. This only affects Firefox on Windows. Other operating systems are unaffected.
(CVE-2025-2857)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Mozilla Firefox version 136.0.4 or later.
Risk Factor
Critical
CVSS v3.0 Base Score
10.0 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.1
EPSS Score
0.0005
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-2857
XREF IAVA:2025-A-0204-S
Plugin Information
Published: 2025/03/28, Modified: 2025/11/18
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Mozilla Firefox
Installed version : 134.0
Fixed version : 136.0.4
234924 - Mozilla Firefox < 138.0
-
Synopsis
A web browser installed on the remote Windows host is affected by multiple vulnerabilities.
Description
The version of Firefox installed on the remote Windows host is prior to 138.0. It is, therefore, affected by multiple vulnerabilities as referenced in the mfsa2025-28 advisory.

- Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. (CVE-2025-4091)

- A process isolation vulnerability in Firefox stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox escape. (CVE-2025-4083)

- Mozilla Firefox's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM- level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation. (CVE-2025-2817)

- Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate privileges. This bug only affects Firefox for macOS.
Other versions of Firefox are unaffected. (CVE-2025-4082)

- An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive information or escalate privileges. (CVE-2025-4085)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Mozilla Firefox version 138.0 or later.
Risk Factor
Critical
CVSS v3.0 Base Score
9.1 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
CVSS v3.0 Temporal Score
7.9 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0005
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/04/29, Modified: 2025/11/18
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Mozilla Firefox
Installed version : 134.0
Fixed version : 138.0
236890 - Mozilla Firefox < 138.0.4
-
Synopsis
A web browser installed on the remote Windows host is affected by multiple vulnerabilities.
Description
The version of Firefox installed on the remote Windows host is prior to 138.0.4. It is, therefore, affected by multiple vulnerabilities as referenced in the mfsa2025-36 advisory.

- An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes. (CVE-2025-4919)

- An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object.
(CVE-2025-4918)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Mozilla Firefox version 138.0.4 or later.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.8 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0002
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.8 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-4918
CVE CVE-2025-4919
XREF IAVA:2025-A-0362-S
Plugin Information
Published: 2025/05/17, Modified: 2025/11/18
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Mozilla Firefox
Installed version : 134.0
Fixed version : 138.0.4
238072 - Mozilla Firefox < 139.0.4
-
Synopsis
A web browser installed on the remote Windows host is affected by multiple vulnerabilities.
Description
The version of Firefox installed on the remote Windows host is prior to 139.0.4. It is, therefore, affected by multiple vulnerabilities as referenced in the mfsa2025-47 advisory.

- An integer overflow was present in <code>OrderedHashTable</code> used by the JavaScript engine (CVE-2025-49710)

- Certain canvas operations could have lead to memory corruption. (CVE-2025-49709)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Mozilla Firefox version 139.0.4 or later.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0004
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-49709
CVE CVE-2025-49710
XREF IAVA:2025-A-0409-S
Plugin Information
Published: 2025/06/10, Modified: 2025/11/18
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Mozilla Firefox
Installed version : 134.0
Fixed version : 139.0.4
240334 - Mozilla Firefox < 140.0
-
Synopsis
A web browser installed on the remote Windows host is affected by multiple vulnerabilities.
Description
The version of Firefox installed on the remote Windows host is prior to 140.0. It is, therefore, affected by multiple vulnerabilities as referenced in the mfsa2025-51 advisory.

- Memory safety bugs present in Firefox 139 and Thunderbird 139. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. (CVE-2025-6436)

- If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requires a secure transport established without errors. (CVE-2025-6433)

- A use-after-free in FontFaceSet resulted in a potentially exploitable crash. (CVE-2025-6424)

- An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. (CVE-2025-6425)

- The executable file warning did not warn users before opening files with the <code>terminal</code>
extension. This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.
(CVE-2025-6426)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Mozilla Firefox version 140.0 or later.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.8 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0004
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.8 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/06/24, Modified: 2025/11/18
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Mozilla Firefox
Installed version : 134.0
Fixed version : 140.0
242555 - Mozilla Firefox < 141.0
-
Synopsis
A web browser installed on the remote Windows host is affected by multiple vulnerabilities.
Description
The version of Firefox installed on the remote Windows host is prior to 141.0. It is, therefore, affected by multiple vulnerabilities as referenced in the mfsa2025-56 advisory.

- Memory safety bugs present in Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. (CVE-2025-8044)

- On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack.
Baseline-JIT, however, read the entire 64 bits. (CVE-2025-8027)

- On arm64, a WASM <code>brtable</code> instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect computation of the branch address.
(CVE-2025-8028)

- In the address bar, Firefox for Android truncated the display of URLs from the end instead of prioritizing the origin. (CVE-2025-8041)

- Firefox for Android allowed a sandboxed iframe without the <code>allow-downloads</code> attribute to start downloads. (CVE-2025-8042)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Mozilla Firefox version 141.0 or later.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.8 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0005
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.8 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/07/22, Modified: 2025/11/18
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Mozilla Firefox
Installed version : 134.0
Fixed version : 141.0
252321 - Mozilla Firefox < 142.0
-
Synopsis
A web browser installed on the remote Windows host is affected by multiple vulnerabilities.
Description
The version of Firefox installed on the remote Windows host is prior to 142.0. It is, therefore, affected by multiple vulnerabilities as referenced in the mfsa2025-64 advisory.

- Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. (CVE-2025-9187)

- An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents slightly different privileges from the content process.
(CVE-2025-9179)

- Same-origin policy bypass in the Graphics: Canvas2D component. (CVE-2025-9180)

- Uninitialized memory in the JavaScript Engine component. (CVE-2025-9181)

- Spoofing issue in the Address Bar component of Firefox Focus for Android. (CVE-2025-9186)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Mozilla Firefox version 142.0 or later.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0002
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/08/19, Modified: 2025/11/18
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Mozilla Firefox
Installed version : 134.0
Fixed version : 142.0
270393 - Mozilla Firefox < 144.0
-
Synopsis
A web browser installed on the remote Windows host is affected by multiple vulnerabilities.
Description
The version of Firefox installed on the remote Windows host is prior to 144.0. It is, therefore, affected by multiple vulnerabilities as referenced in the mfsa2025-81 advisory.

- Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code.
(CVE-2025-11721)

- Use-after-free in MediaTrackGraphImpl::GetInstance() (CVE-2025-11708)

- A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. (CVE-2025-11709)

- A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised process. (CVE-2025-11710)

- There was a way to change the value of JavaScript Object properties that were supposed to be non- writeable. (CVE-2025-11711)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Mozilla Firefox version 144.0 or later.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0002
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/10/14, Modified: 2025/11/18
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Mozilla Firefox
Installed version : 134.0
Fixed version : 144.0
271841 - Mozilla Firefox < 144.0.2
-
Synopsis
A web browser installed on the remote Windows host is affected by a vulnerability.
Description
The version of Firefox installed on the remote Windows host is prior to 144.0.2. It is, therefore, affected by a vulnerability as referenced in the mfsa2025-86 advisory.

- Starting with Firefox 142, it was possible for a compromised child process to trigger a use-after-free in the GPU or browser process using WebGPU-related IPC calls. This may have been usable to escape the child process sandbox. (CVE-2025-12380)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Mozilla Firefox version 144.0.2 or later.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0002
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-12380
XREF IAVA:2025-A-0805-S
Plugin Information
Published: 2025/10/28, Modified: 2025/11/18
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Mozilla Firefox
Installed version : 134.0
Fixed version : 144.0.2
274834 - Mozilla Firefox < 145.0
-
Synopsis
A web browser installed on the remote Windows host is affected by multiple vulnerabilities.
Description
The version of Firefox installed on the remote Windows host is prior to 145.0. It is, therefore, affected by multiple vulnerabilities as referenced in the mfsa2025-87 advisory.

- Memory safety bugs present in Firefox 144 and Thunderbird 144. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. (CVE-2025-13027)

- Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability affects Firefox < 145 and Thunderbird < 145. (CVE-2025-13023, CVE-2025-13026)

- Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability affects Firefox < 145 and Thunderbird < 145. (CVE-2025-13021, CVE-2025-13022, CVE-2025-13025)

- Race condition in the Graphics component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Firefox ESR < 115.30, Thunderbird < 145, and Thunderbird < 140.5. (CVE-2025-13012)

- Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Thunderbird < 145, and Thunderbird < 140.5. (CVE-2025-13016)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Mozilla Firefox version 145.0 or later.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.8 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0002
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.8 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/11/11, Modified: 2025/11/19
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Mozilla Firefox
Installed version : 134.0
Fixed version : 145.0
124198 - Oracle Java SE 1.7.0_221 / 1.8.0_211 / 1.11.0_3 / 1.12.0_1 Multiple Vulnerabilities (Apr 2019 CPU)
-
Synopsis
The remote Windows host contains a programming platform that is affected by multiple vulnerabilities.
Description
The version of Oracle (formerly Sun) Java SE or Java for Business installed on the remote host is prior to 7 Update 221, 8 Update 211, 11 Update 3, or 12 Update 1. It is, therefore, affected by multiple vulnerabilities related to the following components :

- 2D
- Libraries
- RMI
- Windows DLL

Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Oracle JDK / JRE 12 Update 1 , 11 Update 3, 8 Update 211 / 7 Update 221 or later. If necessary, remove any affected versions.
Risk Factor
Medium
CVSS v3.0 Base Score
9.0 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.1 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.1181
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:POC/RL:OF/RC:C)
References
BID 107911
BID 107915
BID 107917
BID 107918
BID 107922
CVE CVE-2019-2602
CVE CVE-2019-2684
CVE CVE-2019-2697
CVE CVE-2019-2698
CVE CVE-2019-2699
Plugin Information
Published: 2019/04/19, Modified: 2024/12/20
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre1.8.0_161\
Installed version : 8.0.161.12 / build 8.0.161
Fixed version : Upgrade to version 8.0.211 or greater
130011 - Oracle Java SE 1.7.0_241 / 1.8.0_231 / 1.11.0_5 / 1.13.0_1 Multiple Vulnerabilities (Oct 2019 CPU) (Windows)
-
Synopsis
The remote Windows host contains a programming platform that is affected by multiple vulnerabilities.
Description
The version of Oracle (formerly Sun) Java SE or Java for Business installed on the remote host is prior to 7 Update 241, 8 Update 231, 11 Update 5, or 13 Update 1. It is, therefore, affected by multiple vulnerabilities related to the following components :

- 2D
- Libraries
- Kerberos
- Networking
- JavaFX
- Hotspot
- Scripting
- Javadoc
- Deployment
- Concurrency
- JAXP
- Serialization
- Security

Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Oracle JDK / JRE 13 Update 1, 11 Update 5, 8 Update 231 / 7 Update 241 or later. If necessary, remove any affected versions.
Risk Factor
High
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0247
CVSS v2.0 Base Score
7.5 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.5 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2019/10/17, Modified: 2024/12/20
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre1.8.0_161\
Installed version : 8.0.161.12 / build 8.0.161
Fixed version : Upgrade to version 8.0.231 or greater
234624 - Oracle Java SE Multiple Vulnerabilities (April 2025 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities
Description
The versions of Java installed on the remote host are affected by multiple vulnerabilities as referenced in the April 2025 CPU advisory.

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX (gstreamer)). Supported versions that are affected are Oracle Java SE: 8u441, 8u441-perf; Oracle GraalVM Enterprise Edition: 20.3.17 and 21.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE, Oracle GraalVM Enterprise Edition. (CVE-2024-47606)

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX (WebKitGTK)). Supported versions that are affected are Oracle Java SE: 8u441; Oracle GraalVM Enterprise Edition: 20.3.17 and 21.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE, Oracle GraalVM Enterprise Edition. (CVE-2024-54534)

- Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Node (Node.js)). Supported versions that are affected are Oracle GraalVM for JDK: 17.0.14 and 21.0.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle GraalVM for JDK executes to compromise Oracle GraalVM for JDK. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle GraalVM for JDK accessible data as well as unauthorized access to critical data or complete access to all Oracle GraalVM for JDK accessible data. (CVE-2025-23083)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the April 2025 Oracle Critical Patch Update advisory.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.1 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0067
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/04/18, Modified: 2025/08/12
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre1.8.0_161\
Installed version : 8.0.161.12 / build 8.0.161
Fixed version : Upgrade to version 8.0.451 or greater
111163 - Oracle Java SE Multiple Vulnerabilities (July 2018 CPU)
-
Synopsis
The remote Windows host contains a programming platform that is affected by multiple vulnerabilities.
Description
The version of Oracle (formerly Sun) Java SE or Java for Business installed on the remote host is prior to 10 Update 2, 8 Update 181, 7 Update 191, or 6 Update 201. It is, therefore, affected by multiple vulnerabilities related to the following components :

- Concurrency. A difficult to exploit vulnerability allows an unauthenticated attacker with network access via multiple protocols to compromise Java SE (CVE-2018-2952)

- Deployment. A difficult to exploit vulnerability allows an unauthenticated attacker with network access via multiple protocols to compromise Java SE (CVE-2018-2964)

- JSSE. A difficult to exploit vulnerability allows an unauthenticated attacker with network access via multiple protocols to compromise Java SE (CVE-2018-2973)

- Java DB. A difficult to exploit vulnerability allows an unauthenticated attacker with network access via multiple protocols to compromise Java SE. (CVE-2018-2938)

- JavaFX. A difficult to exploit vulnerability allows an unauthenticated attacker with network access via multiple protocols to compromise Java SE. (CVE-2018-2941)

- Libraries. An easily exploitable vulnerability allows an unauthenticated attacker with network access via multiple protocols to compromise Java SE. (CVE-2018-2940)

- Security. A difficult to exploit vulnerability allows an unauthenticated attacker with network access via multiple protocols to compromise Java SE (CVE-2018-2972)

- Windows DLL. A difficult to exploit vulnerability allows an unauthenticated attacker with network access via multiple protocols to compromise Java SE (CVE-2018-2942)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Oracle JDK / JRE 10 Update 2, 8 Update 181 / 7 Update 191 / 6 Update 201 or later. If necessary, remove any affected versions.

Note that an Extended Support contract with Oracle is needed to obtain JDK / JRE 6 Update 95 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
9.0 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.5
EPSS Score
0.0183
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
References
BID 104765
BID 104768
BID 104773
BID 104774
BID 104775
BID 104780
BID 104781
BID 104782
CVE CVE-2018-2938
CVE CVE-2018-2940
CVE CVE-2018-2941
CVE CVE-2018-2942
CVE CVE-2018-2952
CVE CVE-2018-2964
CVE CVE-2018-2972
CVE CVE-2018-2973
Plugin Information
Published: 2018/07/20, Modified: 2025/01/27
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre1.8.0_161\
Installed version : 8.0.161.12 / build 8.0.161
Fixed version : Upgrade to version 8.0.181 or greater
242293 - Oracle Java SE Multiple Vulnerabilities (July 2025 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities
Description
The versions of Java installed on the remote host are affected by multiple vulnerabilities as referenced in the July 2025 CPU advisory.

- Vulnerability in Oracle Java SE (component: JavaFX (libxml2)). Supported versions that are affected are Oracle Java SE: 8u451-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE. (CVE-2024-40896)

- Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u451, 8u451-perf, 11.0.27, 17.0.15, 21.0.7, 24.0.1; Oracle GraalVM for JDK: 17.0.15, 21.0.7 and 24.0.1; Oracle GraalVM Enterprise Edition: 21.3.14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. (CVE-2025-30749)

- Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u451-perf, 11.0.27, 17.0.15, 21.0.7, 24.0.1; Oracle GraalVM for JDK: 17.0.15, 21.0.7 and 24.0.1; Oracle GraalVM Enterprise Edition: 21.3.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. While the vulnerability is in Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. (CVE-2025-50059)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the July 2025 Oracle Critical Patch Update advisory.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.8 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0023
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.8 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/07/18, Modified: 2025/10/30
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre1.8.0_161\
Installed version : 8.0.161.12 / build 8.0.161
Fixed version : Upgrade to version 8.0.461 or greater
118228 - Oracle Java SE Multiple Vulnerabilities (October 2018 CPU)
-
Synopsis
The remote Windows host contains a programming platform that is affected by multiple vulnerabilities.
Description
The version of Oracle (formerly Sun) Java SE or Java for Business installed on the remote host is prior to 11 Update 1, 8 Update 191, 7 Update 201, or 6 Update 211. It is, therefore, affected by multiple vulnerabilities related to the following components :

- An unspecified vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE in the Deployment (libpng) subcomponent could allow an unauthenticated, remote attacker with network access via HTTP to compromise Java SE, Java SE Embedded. (CVE-2018-13785)

- An unspecified vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE in the Hotspot subcomponent could allow an unauthenticated, remote attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. (CVE-2018-3169)

- An unspecified vulnerability in the Java SE component of Oracle Java SE in the JavaFX subcomponent could allow an unauthenticated, remote attacker with network access via multiple protocols to compromise Java SE.
(CVE-2018-3209)

- An unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE in the JNDI subcomponent could allow an unauthenticated, remote attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit.
(CVE-2018-3149)
- An unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE in the JSSE subcomponent could allow an unauthenticated, remote attacker with network access via SSL/TLS to compromise Java SE, Java SE Embedded, JRockit.
(CVE-2018-3180)

- An unspecified vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE in the Networking subcomponent could allow an unauthenticated, remote attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded.
(CVE-2018-3139)

- An unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE in the Scripting subcomponent could allow an unauthenticated, remote attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. (CVE-2018-3183)

- An unspecified vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE in the Security subcomponent could allow an unauthenticated, remote attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. (CVE-2018-3136)

- An unspecified vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE in the Serviceability subcomponent could allow a low privileged attacker with logon to the infrastructure where Java SE, Java SE Embedded executes to compromise Java SE, Java SE Embedded. (CVE-2018-3211)

- An unspecified vulnerability in the Java SE component of Oracle Java SE in the Sound subcomponent could allow an unauthenticated, remote attacker with network access via multiple protocols to compromise Java SE.
(CVE-2018-3157)

- An unspecified vulnerability in the Java SE component of Oracle Java SE in the Utility subcomponent could allow an unauthenticated, remote attacker with network access via multiple protocols to compromise Java SE.
(CVE-2018-3150)

Please consult the CVRF details for the applicable CVEs for additional information.

Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Oracle JDK / JRE 11 Update 1, 8 Update 191 / 7 Update 201 / 6 Update 211 or later. If necessary, remove any affected versions.

Note that an Extended Support contract with Oracle is needed to obtain JDK / JRE 6 Update 95 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
9.0 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.3
EPSS Score
0.0225
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
References
BID 105587
BID 105590
BID 105591
BID 105595
BID 105597
BID 105599
BID 105601
BID 105602
BID 105608
BID 105615
BID 105617
BID 105622
CVE CVE-2018-3136
CVE CVE-2018-3139
CVE CVE-2018-3149
CVE CVE-2018-3150
CVE CVE-2018-3157
CVE CVE-2018-3169
CVE CVE-2018-3180
CVE CVE-2018-3183
CVE CVE-2018-3209
CVE CVE-2018-3211
CVE CVE-2018-3214
CVE CVE-2018-13785
Plugin Information
Published: 2018/10/19, Modified: 2024/12/20
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre1.8.0_161\
Installed version : 8.0.161.12 / build 8.0.161
Fixed version : Upgrade to version 8.0.191 or greater
180360 - 7-Zip < 23.00 Multiple Vulnerabilities
-
Synopsis
A compression utility installed on the remote Windows host is affected by multiple vulnerabilities.
Description
The version of 7-Zip installed on the remote Windows host is below 23.00. It is, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability exists in 7-zip due to an integer underflow. An unauthenticated, remote attacker can exploit this, by tricking a user into opening a specially crafted archive, to execute arbitrary code on the system. (CVE-2023-31102)

- A remote code execution vulnerability exists in 7-zip due to an out-of-bounds write. An unauthenticated, remote attacker can exploit this, by tricking a user into opening a specially crafted archive, to execute arbitrary code on the system. (CVE-2023-40481)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to 7-Zip version 23.00 or later.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.374
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-31102
CVE CVE-2023-40481
XREF IAVA:2023-A-0440-S
Plugin Information
Published: 2023/08/31, Modified: 2024/11/22
Plugin Output

tcp/445/cifs


Path : C:\Program Files\7-Zip
Installed version : 19.0.0.0
Fixed version : 23.00
209231 - 7-Zip < 24.01 Heap-based Buffer Overflow
-
Synopsis
The 7-zip instance installed on the remote host is affected by a heap based buffer overflow vulnerability.
Description
The version of 7-Zip installed on the remote Windows host is below 24.01. It is, therefore, affected by multiple vulnerabilities:

- The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains a heap-based buffer overflow that allows an attacker to overwrite two bytes at multiple offsets beyond the allocated buffer size:
buffer+512*i-2, for i=9, i=10, i=11, etc. (CVE-2023-52168)

- The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a filename listed in the file system image. This has security relevance in some known web-service use cases where untrusted users can upload files and have them extracted by a server-side 7-Zip process. (CVE-2023-52169)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to 7-zip version 24.01 or later.
Risk Factor
High
CVSS v3.0 Base Score
8.4 (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.3 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.0039
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
References
Plugin Information
Published: 2024/10/17, Modified: 2024/10/18
Plugin Output

tcp/445/cifs


Path : C:\Program Files\7-Zip
Installed version : 19.0.0.0
Fixed version : 24.01
211725 - 7-Zip < 24.07 RCE (ZDI-24-1532)
-
Synopsis
The remote host is missing a security update.
Description
The version of 7-Zip installed on the remote host is prior to 24.07. It is, therefore, affected by a remote code execution vulnerability as referenced in the ZDI-24-1532 advisory.

- This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip.
Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the implementation of Zstandard decompression. The issue results from the lack of proper validation of user-supplied data, which can result in an integer underflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. (CVE-2024-11477)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to 7-Zip version 24.07 or later.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.3951
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-11477
XREF IAVA:2024-A-0765-S
Plugin Information
Published: 2024/11/22, Modified: 2025/01/24
Plugin Output

tcp/445/cifs


Path : C:\Program Files\7-Zip
Installed version : 19.0.0.0
Fixed version : 24.07
214542 - 7-Zip < 24.09 (ZDI-25-045)
-
Synopsis
The remote host is missing a security update.
Description
The version of 7-Zip installed on the remote host is prior to 24.09. It is, therefore, affected by a vulnerability as referenced in the ZDI-25-045 advisory.

- The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to 7-Zip version 24.09 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.0 (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.3263
CVSS v2.0 Base Score
6.2 (CVSS2#AV:L/AC:H/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.1 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-0411
XREF IAVA:2025-A-0042-S
XREF CISA-KNOWN-EXPLOITED:2025/02/27
Plugin Information
Published: 2025/01/23, Modified: 2025/08/12
Plugin Output

tcp/445/cifs


Path : C:\Program Files\7-Zip
Installed version : 19.0.0.0
Fixed version : 24.09
242639 - 7-Zip < 25.00
-
Synopsis
The remote host is missing a security update.
Description
The version of 7-Zip installed on the remote host is prior to 25.00. It is, therefore, affected by multiple vulnerabilities:

- 7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. Interaction with this product is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the handling of symbolic links in ZIP files. Crafted data in a ZIP file can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of a service account. (CVE-2025-11001, CVE-2025-11002)

- An error in Z-zip's RAR5 handler's error correction for corrupted items can lead to a buffer overflow, resulting in memory corruption and denial of service.
(CVE-2025-53816)

- A Null pointer dereference in 7-Zip's implementation of the Compound handler can lead to denial of service at specific values. (CVE-2025-53817)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to 7-Zip version 25.00 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.0 (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
9.2
EPSS Score
0.0031
CVSS v2.0 Base Score
6.2 (CVSS2#AV:L/AC:H/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-11001
CVE CVE-2025-11002
CVE CVE-2025-53816
CVE CVE-2025-53817
XREF IAVA:2025-A-0540-S
Plugin Information
Published: 2025/07/23, Modified: 2025/11/20
Plugin Output

tcp/445/cifs


Path : C:\Program Files\7-Zip
Installed version : 19.0.0.0
Fixed version : 25.00
241563 - KB5062554: Windows 10 version 21H2 / Windows 10 Version 22H2 Security Update (July 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5062554. It is, therefore, affected by multiple vulnerabilities

- Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally.
(CVE-2025-49659)

- Improper link resolution before file access ('link following') in Windows Update Service allows an authorized attacker to elevate privileges locally. (CVE-2025-48799)

- Improper link resolution before file access ('link following') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally. (CVE-2025-48820)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5062554
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.1
EPSS Score
0.0027
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-36350
CVE CVE-2025-36357
CVE CVE-2025-47159
CVE CVE-2025-47971
CVE CVE-2025-47972
CVE CVE-2025-47973
CVE CVE-2025-47975
CVE CVE-2025-47976
CVE CVE-2025-47980
CVE CVE-2025-47981
CVE CVE-2025-47982
CVE CVE-2025-47984
CVE CVE-2025-47985
CVE CVE-2025-47986
CVE CVE-2025-47987
CVE CVE-2025-47991
CVE CVE-2025-47996
CVE CVE-2025-47999
CVE CVE-2025-48000
CVE CVE-2025-48001
CVE CVE-2025-48003
CVE CVE-2025-48799
CVE CVE-2025-48800
CVE CVE-2025-48803
CVE CVE-2025-48804
CVE CVE-2025-48805
CVE CVE-2025-48806
CVE CVE-2025-48808
CVE CVE-2025-48811
CVE CVE-2025-48814
CVE CVE-2025-48815
CVE CVE-2025-48816
CVE CVE-2025-48817
CVE CVE-2025-48818
CVE CVE-2025-48819
CVE CVE-2025-48820
CVE CVE-2025-48821
CVE CVE-2025-48822
CVE CVE-2025-48823
CVE CVE-2025-49658
CVE CVE-2025-49659
CVE CVE-2025-49660
CVE CVE-2025-49661
CVE CVE-2025-49664
CVE CVE-2025-49665
CVE CVE-2025-49667
CVE CVE-2025-49675
CVE CVE-2025-49678
CVE CVE-2025-49679
CVE CVE-2025-49680
CVE CVE-2025-49682
CVE CVE-2025-49683
CVE CVE-2025-49684
CVE CVE-2025-49685
CVE CVE-2025-49686
CVE CVE-2025-49687
CVE CVE-2025-49689
CVE CVE-2025-49690
CVE CVE-2025-49691
CVE CVE-2025-49721
CVE CVE-2025-49722
CVE CVE-2025-49723
CVE CVE-2025-49724
CVE CVE-2025-49725
CVE CVE-2025-49726
CVE CVE-2025-49727
CVE CVE-2025-49730
CVE CVE-2025-49732
CVE CVE-2025-49733
CVE CVE-2025-49740
CVE CVE-2025-49742
CVE CVE-2025-49744
CVE CVE-2025-49760
CVE CVE-2025-55230
MSKB 5062554
XREF MSFT:MS25-5062554
XREF IAVA:2025-A-0507-S
XREF IAVA:2025-A-0506-S
XREF IAVA:2025-A-0631-S
XREF CWE:20
XREF CWE:23
XREF CWE:59
XREF CWE:73
XREF CWE:122
XREF CWE:125
XREF CWE:126
XREF CWE:190
XREF CWE:191
XREF CWE:197
XREF CWE:200
XREF CWE:284
XREF CWE:306
XREF CWE:326
XREF CWE:349
XREF CWE:353
XREF CWE:362
XREF CWE:367
XREF CWE:400
XREF CWE:415
XREF CWE:416
XREF CWE:476
XREF CWE:591
XREF CWE:693
XREF CWE:787
XREF CWE:820
XREF CWE:822
XREF CWE:843
XREF CWE:862
Plugin Information
Published: 2025/07/08, Modified: 2025/10/29
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5062554

- C:\WINDOWS\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.19041.5965
Should be : 10.0.19041.6093
261804 - KB5065429: Windows 10 version 21H2 / Windows 10 Version 22H2 Security Update (September 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5065429. It is, therefore, affected by multiple vulnerabilities

- SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vulnerabilities could perform relay attacks and make the users subject to elevation of privilege attacks. The SMB Server already supports mechanisms for hardening against relay attacks: SMB Server signing SMB Server Extended Protection for Authentication (EPA) Microsoft is releasing this CVE to provide customers with audit capabilities to help them to assess their environment and to identify any potential device or software incompatibility issues before deploying SMB Server hardening measures that protect against relay attacks. If you have not already enabled SMB Server hardening measures, we advise customers to take the following actions to be protected from these relay attacks:
Assess your environment by utilizing the audit capabilities that we are exposing in the September 2025 security updates. See Support for Audit Events to deploy SMB Server HardeningSMB Server Signing & SMB Server EPA. Adopt appropriate SMB Server hardening measures. (CVE-2025-55234)

- Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally. (CVE-2025-49734)

- Stack-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. (CVE-2025-54099)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5065429
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.1
EPSS Score
0.0073
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/09/09, Modified: 2025/10/29
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5065429

- C:\WINDOWS\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.19041.5965
Should be : 10.0.19041.6328
274787 - KB5068781: Windows 10 version 21H2 / Windows 10 Version 22H2 Security Update (November 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5068781. It is, therefore, affected by multiple vulnerabilities

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2025-59509, CVE-2025-59513, CVE-2025-60706, CVE-2025-62208, CVE-2025-62209)
- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-60724, CVE-2025-60714, CVE-2025-60715, CVE-2025-62452)

- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges.
(CVE-2025-59505, CVE-2025-59506, CVE-2025-59507, CVE-2025-59508, CVE-2025-59511, CVE-2025-59512, CVE-2025-59514, CVE-2025-59515, CVE-2025-60703, CVE-2025-60704, CVE-2025-60705, CVE-2025-60707, CVE-2025-60709, CVE-2025-60716, CVE-2025-60717, CVE-2025-60719, CVE-2025-60720, CVE-2025-62213, CVE-2025-62215, CVE-2025-62217, CVE-2025-62218, CVE-2025-62219)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5068781
Risk Factor
Critical
CVSS v3.0 Base Score
7.0 (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.0009
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/11/11, Modified: 2025/11/14
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5068781

- C:\WINDOWS\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.19041.5965
Should be : 10.0.19041.6575
277988 - KB5071546: Windows 10 version 21H2 / Windows 10 Version 22H2 Security Update (December 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5071546. It is, therefore, affected by multiple vulnerabilities

- Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. (CVE-2025-62549)

- Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. (CVE-2025-62457)

- Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. (CVE-2025-62458)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5071546
Risk Factor
Critical
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
8.1
EPSS Score
0.0821
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/12/09, Modified: 2025/12/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5071546

- C:\WINDOWS\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.19041.5965
Should be : 10.0.19041.6691
192147 - Microsoft Azure Data Studio < 1.48.0 Elevation of Privilege Vulnerability (CVE-2024-26203)
-
Synopsis
An application installed on the remote Windows host is affected by an elevation of privilege vulnerability.
Description
The version of Microsoft Azure Data Studio installed on the remote Windows host is prior to 1.48.0. It is, therefore, affected by an unspecified elevation of privilege vulnerability.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Microsoft Azure Data Studio version 1.48.0 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.3 (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.4 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0214
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-26203
XREF IAVA:2024-A-0157
Plugin Information
Published: 2024/03/15, Modified: 2024/03/18
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Azure Data Studio\
Installed version : 1.32.0.0
Fixed version : 1.48.0

178245 - Microsoft Paint 3D Code Execution (July 2023)
-
Synopsis
The Windows app installed on the remote host is affected by code execution vulnerabilities.
Description
The Windows 'Paint 3D' app installed on the remote host is affected by multiple code execution vulnerabilities. An attacker who successfully exploited one of the vulnerabilities could execute arbitrary code. Exploitation of the vulnerabilities requires that a program process a specially crafted file.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade the Windows 'Paint 3D' app to version 6.2305.16087.0, or later via the Microsoft Store.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.0374
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
References
Plugin Information
Published: 2023/07/13, Modified: 2025/05/23
Plugin Output

tcp/0


Path : C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe
Installed version : 6.1907.29027.0
Fixed version : 6.2305.16087.0
158710 - Microsoft Paint 3D Code Execution (March 2022)
-
Synopsis
The Windows app installed on the remote host is affected by a code execution vulnerability..
Description
The Windows 'Paint 3D' app installed on the remote host is affected by a code execution vulnerability. An attacker who successfully exploited the vulnerability could execute arbitrary code. Exploitation of the vulnerability requires that a program process a specially crafted file.
See Also
Solution
Upgrade the Windows 'Paint 3D' app to version 6.2105.4017.0, or later via the Microsoft Store.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.0056
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
References
Plugin Information
Published: 2022/03/08, Modified: 2025/05/23
Plugin Output

tcp/0


Path : C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe
Installed version : 6.1907.29027.0
Fixed version : 6.2105.4017.0
171636 - Microsoft Print 3D app Remote Code Execution (February 2023)
-
Synopsis
The Microsoft Print 3D app installed on the remote host may be affected by a remote code execution vulnerability.
Description
The Microsoft Print 3D app installed on the remote Windows host may be affected by a remote code execution vulnerability.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to the Microsoft 3D Builder app via the Windows App Store.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.0077
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.0 (CVSS2#E:F/RL:OF/RC:C)
References
Plugin Information
Published: 2023/02/20, Modified: 2024/03/27
Plugin Output

tcp/0


Path : C:\Program Files\WindowsApps\Microsoft.Print3D_3.3.311.0_x64__8wekyb3d8bbwe
Installed version : 3.3.311.0
Fixed version : Upgrade to the Microsoft 3D Builder app to 3.3.791 or later via the Windows App Store.

221618 - Mozilla Firefox < 136.0
-
Synopsis
A web browser installed on the remote Windows host is affected by multiple vulnerabilities.
Description
The version of Firefox installed on the remote Windows host is prior to 136.0. It is, therefore, affected by multiple vulnerabilities as referenced in the mfsa2025-14 advisory.

- Malicious pages could use Firefox for Android to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range could have used this to trick the user into using their passkey to log the attacker's computer into the target account. (CVE-2024-9956)

- On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use- after-free in the Browser process. This could have led to a sandbox escape. (CVE-2025-1930)

- Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. (CVE-2025-1939)

- It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potentially exploitable crash. (CVE-2025-1931)

- An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of- bounds access. Only affected version 122 and later. (CVE-2025-1932)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Mozilla Firefox version 136.0 or later.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0018
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/03/04, Modified: 2025/11/18
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Mozilla Firefox
Installed version : 134.0
Fixed version : 136.0
233647 - Mozilla Firefox < 137.0
-
Synopsis
A web browser installed on the remote Windows host is affected by multiple vulnerabilities.
Description
The version of Firefox installed on the remote Windows host is prior to 137.0. It is, therefore, affected by multiple vulnerabilities as referenced in the mfsa2025-20 advisory.

- Memory safety bugs present in Firefox 136 and Thunderbird 136. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. (CVE-2025-3034)

- Memory safety bugs present in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. (CVE-2025-3030)

- JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after- free. (CVE-2025-3028)

- An attacker could read 32 bits of values spilled onto the stack in a JIT compiled function.
(CVE-2025-3031)

- Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks. (CVE-2025-3032)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Mozilla Firefox version 137.0 or later.
Risk Factor
Critical
CVSS v3.0 Base Score
8.1 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.3 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0005
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.8 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/04/01, Modified: 2025/11/18
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Mozilla Firefox
Installed version : 134.0
Fixed version : 137.0
237298 - Mozilla Firefox < 139.0
-
Synopsis
A web browser installed on the remote Windows host is affected by multiple vulnerabilities.
Description
The version of Firefox installed on the remote Windows host is prior to 139.0. It is, therefore, affected by multiple vulnerabilities as referenced in the mfsa2025-42 advisory.

- Memory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10.
Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. (CVE-2025-5268)

- A double-free could have occurred in `vpxcodecencinitmulti` after a failed allocation when initializing the encoder for WebRTC. This could have caused memory corruption and a potentially exploitable crash.
(CVE-2025-5283)

- Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin leak attacks. (CVE-2025-5263)

- Due to insufficient escaping of the newline character in the Copy as cURL feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system.
(CVE-2025-5264)

- Due to insufficient escaping of the ampersand character in the Copy as cURL feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.
(CVE-2025-5265)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Mozilla Firefox version 139.0 or later.
Risk Factor
High
CVSS v3.0 Base Score
8.1 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.1 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0009
CVSS v2.0 Base Score
9.4 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N)
CVSS v2.0 Temporal Score
7.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/05/27, Modified: 2025/11/18
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Mozilla Firefox
Installed version : 134.0
Fixed version : 139.0
265449 - Mozilla Firefox < 143.0
-
Synopsis
A web browser installed on the remote Windows host is affected by multiple vulnerabilities.
Description
The version of Firefox installed on the remote Windows host is prior to 143.0. It is, therefore, affected by multiple vulnerabilities as referenced in the mfsa2025-73 advisory.

- Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142.
Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. (CVE-2025-10537)

- Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. (CVE-2025-10527)

- Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
(CVE-2025-10528)

- Same-origin policy bypass in the Layout component. This vulnerability affects Firefox < 143, Firefox ESR <
140.3, Thunderbird < 143, and Thunderbird < 140.3. (CVE-2025-10529)

- Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability affects Firefox < 143 and Thunderbird < 143. (CVE-2025-10530)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Mozilla Firefox version 143.0 or later.
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0005
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/09/19, Modified: 2025/11/18
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Mozilla Firefox
Installed version : 134.0
Fixed version : 143.0
266291 - Mozilla Firefox < 143.0.3
-
Synopsis
A web browser installed on the remote Windows host is affected by multiple vulnerabilities.
Description
The version of Firefox installed on the remote Windows host is prior to 143.0.3. It is, therefore, affected by multiple vulnerabilities as referenced in the mfsa2025-80 advisory.

- Sandbox escape due to integer overflow in the Graphics: Canvas2D component. This vulnerability affects Firefox < 143.0.3. (CVE-2025-11152)

- JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability affects Firefox < 143.0.3.
(CVE-2025-11153)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Mozilla Firefox version 143.0.3 or later.
Risk Factor
High
CVSS v3.0 Base Score
8.6 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.5
EPSS Score
0.0002
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:C/A:P)
CVSS v2.0 Temporal Score
6.7 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-11152
CVE CVE-2025-11153
XREF IAVA:2025-A-0715-S
Plugin Information
Published: 2025/09/30, Modified: 2025/11/18
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Mozilla Firefox
Installed version : 134.0
Fixed version : 143.0.3
277971 - Mozilla Firefox < 146.0
-
Synopsis
A web browser installed on the remote Windows host is affected by multiple vulnerabilities.
Description
The version of Firefox installed on the remote Windows host is prior to 146.0. It is, therefore, affected by multiple vulnerabilities as referenced in the mfsa2025-92 advisory.

- Privilege escalation in the Netmonitor component. This vulnerability affects Firefox < 146 and Firefox ESR < 140.6. (CVE-2025-14328, CVE-2025-14329)

- Use-after-free in the WebRTC: Signaling component. This vulnerability affects Firefox < 146 and Firefox ESR < 140.6. (CVE-2025-14321)

- Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability affects Firefox < 146, Firefox ESR < 115.31, and Firefox ESR < 140.6. (CVE-2025-14322)

- Privilege escalation in the DOM: Notifications component. This vulnerability affects Firefox < 146, Firefox ESR < 115.31, and Firefox ESR < 140.6. (CVE-2025-14323)

- JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability affects Firefox < 146, Firefox ESR < 115.31, and Firefox ESR < 140.6. (CVE-2025-14324)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Mozilla Firefox version 146.0 or later.
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0004
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/12/09, Modified: 2025/12/12
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Mozilla Firefox
Installed version : 134.0
Fixed version : 146.0
279186 - Mozilla Firefox < 146.0.1
-
Synopsis
A web browser installed on the remote Windows host is affected by multiple vulnerabilities.
Description
The version of Firefox installed on the remote Windows host is prior to 146.0.1. It is, therefore, affected by multiple vulnerabilities as referenced in the mfsa2025-98 advisory.

- Memory safety bugs present in Firefox 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
(CVE-2025-14861)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Mozilla Firefox version 146.0.1 or later.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0004
References
Plugin Information
Published: 2025/12/18, Modified: 2025/12/18
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Mozilla Firefox
Installed version : 134.0
Fixed version : 146.0.1

205291 - Notepad++ < 8.1.1 Arbitrary Code Execution
-
Synopsis
The text editor on the remote Windows host is affected by a arbitary code execution.
Description
The version of Notepad++ installed on the remote host is prior to 8.1.1. It is, therefore, affected by a arbitary code execution vulnerability in the dbghelp.exe file, allowing a attacker with local access to abuse the uncontrolled search path to execute arbitrary code and gain access.
Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Notepad++ 8.1.1 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0006
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-6401
XREF IAVA:2024-A-0463
Plugin Information
Published: 2024/08/09, Modified: 2025/06/20
Plugin Output

tcp/0


Path : C:\Program Files (x86)\Notepad++
Installed version : 6.9.0.0
Fixed version : 8.1.1

208192 - Notepad++ < 8.4.1 DLL hijacking vulnerability
-
Synopsis
The text editor on the remote Windows host is affected by DLL hijacking
Description
Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll and run arbitrary code in the context of Notepad++.
Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Notepad++ 8.4.1 or later.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0004
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:POC/RL:OF/RC:C)
References
Plugin Information
Published: 2024/10/04, Modified: 2025/09/22
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Notepad++
Installed version : 6.9.0.0
Fixed version : 8.4.1

181867 - Notepad++ < 8.5.7 Multiple Buffer Overflow Vulnerabilities
-
Synopsis
The text editor on the remote Windows host is affected by multiple vulnerabilties.
Description
The version of Notepad++ installed on the remote host is prior to 8.5.7. It is, therefore, affected by multiple buffer overflow vulnerabilties. An authenticated, local attacker could exploit these to cause a denial of service condition or the execution of arbitrary code.
Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Notepad++ 8.5.7 or later.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0011
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:POC/RL:OF/RC:C)
References
Plugin Information
Published: 2023/09/26, Modified: 2023/09/27
Plugin Output

tcp/0


Path : C:\Program Files (x86)\Notepad++
Installed version : 6.9.0.0
Fixed version : 8.5.7

240630 - Notepad++ < 8.8.2 Privilege Escalation (CVE-2025-49144)
-
Synopsis
A text editor on the remote Windows host is affected by privilege escalation.
Description
The version of Notepad++ installed on the remote host is prior to 8.8.2. It is, therefore, affected by a privilege escalation vulnerability:

- Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.8.1 installer that allows unprivileged users to gain SYSTEM-level privileges through insecure executable search paths. An attacker could use social engineering or clickjacking to trick users into downloading both the legitimate installer and a malicious executable to the same directory (typically Downloads folder - which is known as Vulnerable directory). Upon running the installer, the attack executes automatically with SYSTEM privileges. This issue has been fixed and will be released in version 8.8.2.
(CVE-2025-49144) Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Notepad++ 8.8.2 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.3 (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
VPR Score
8.4
EPSS Score
0.0001
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-49144
XREF IAVA:2025-A-0452
Plugin Information
Published: 2025/06/26, Modified: 2025/11/10
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Notepad++
Installed version : 6.9.0.0
Fixed version : 8.8.2
193574 - Oracle Java (Apr 2024 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities
Description
The 8u401, 20.3.13, 21.3.9, 11.0.23, 17.0.10, 21.0.3, 22, and perf versions of Java installed on the remote host are affected by multiple vulnerabilities as referenced in the April 2024 CPU advisory.

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX (WebKitGTK)). Supported versions that are affected are Oracle Java SE: 8u401; Oracle GraalVM Enterprise Edition: 20.3.13 and 21.3.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE, Oracle GraalVM Enterprise Edition.(CVE-2023-41993)

- Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Node (Node.js)). Supported versions that are affected are Oracle GraalVM for JDK: 17.0.10, 21.0.2 and 22. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle GraalVM for JDK executes to compromise Oracle GraalVM for JDK. While the vulnerability is in Oracle GraalVM for JDK, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle GraalVM for JDK accessible data as well as unauthorized access to critical data or complete access to all Oracle GraalVM for JDK accessible data.
(CVE-2024-21892)

- Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u401, 8u401-perf, 11.0.23, 17.0.10, 21.0.3, 22; Oracle GraalVM for JDK: 17.0.10, 21.0.3, 22; Oracle GraalVM Enterprise Edition: 20.3.13 and 21.3.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. (CVE-2024-21011)


Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the April 2024 Oracle Critical Patch Update advisory.
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.2153
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-32643
CVE CVE-2023-41993
CVE CVE-2024-20954
CVE CVE-2024-21002
CVE CVE-2024-21003
CVE CVE-2024-21004
CVE CVE-2024-21005
CVE CVE-2024-21011
CVE CVE-2024-21012
CVE CVE-2024-21068
CVE CVE-2024-21085
CVE CVE-2024-21094
CVE CVE-2024-21098
CVE CVE-2024-21892
XREF IAVA:2024-A-0239
XREF CISA-KNOWN-EXPLOITED:2023/10/16
XREF IAVA:2024-A-0239
Plugin Information
Published: 2024/04/19, Modified: 2025/03/14
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre1.8.0_161\
Installed version : 8.0.161.12 / build 8.0.161
Fixed version : Upgrade to version 8.0.411 or greater
132992 - Oracle Java SE 1.7.0_251 / 1.8.0_241 / 1.11.0_6 / 1.13.0_2 Multiple Vulnerabilities (Jan 2020 CPU)
-
Synopsis
The remote Windows host contains a programming platform that is affected by multiple vulnerabilities.
Description
The version of Oracle (formerly Sun) Java SE or Java for Business installed on the remote host is prior to 7 Update 251, 8 Update 241, 11 Update 6, or 13 Update 2. It is, therefore, affected by multiple vulnerabilities:

- Oracle Java SE and Java SE Embedded are prone to a severe division by zero, over 'Multiple' protocol.
This issue affects the 'SQLite' component.(CVE-2019-16168)

- Oracle Java SE and Java SE Embedded are prone to format string vulnerability, leading to a read uninitialized stack data over 'Multiple' protocol. This issue affects the 'libxst' component.
(CVE-2019-13117, CVE-2019-13118)

- Oracle Java SE and Java SE Embedded are prone to a remote security vulnerability. An unauthenticated remote attacker can exploit this over 'Kerberos' protocol. This issue affects the 'Security' component.
(CVE-2020-2601, CVE-2020-2590)

- Oracle Java SE/Java SE Embedded are prone to a remote security vulnerability. An unauthenticated remote attacker can exploit this overmultiple protocols. This issue affects the 'Serialization' component.
(CVE-2020-2604, CVE-2020-2583)

- Oracle Java SE/Java SE Embedded are prone to a remote security vulnerability. Tn unauthenticated remote attacker can exploit this over multiple protocols. This issue affects the 'Networking' component.
(CVE-2020-2593, CVE-2020-2659)

- Oracle Java SE are prone to a remote security vulnerability. An unauthenticated remote attacker can exploit this over multiple protocols. This issue affects the 'Libraries' component. (CVE-2020-2654)

- Oracle Java SE are prone to a multiple security vulnerability. An unauthenticated remote attacker can exploit this over multiple protocols. This issue affects the 'JavaFX' component. (CVE-2020-2585)

- Oracle Java SE are prone to a multiple security vulnerability. An unauthenticate remote attacker can exploit this over 'HTTPS' protocols. This issue affects the 'JSSE' component. (CVE-2020-2655)

Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Oracle JDK / JRE 13 Update 2 , 11 Update 6, 8 Update 241 / 7 Update 251 or later. If necessary, remove any affected versions.
Risk Factor
Medium
CVSS v3.0 Base Score
8.1 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.1 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0457
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2020/01/16, Modified: 2024/12/20
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre1.8.0_161\
Installed version : 8.0.161.12 / build 8.0.161
Fixed version : Upgrade to version 8.0.241 or greater
135592 - Oracle Java SE 1.7.0_261 / 1.8.0_251 / 1.11.0_7 / 1.14.0_1 Multiple Vulnerabilities (Apr 2020 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities
Description
The version of Oracle (formerly Sun) Java SE or Java for Business installed on the remote host is prior to 7 Update 261, 8 Update 251, 11 Update 7, or 14 Update 1. It is, therefore, affected by multiple vulnerabilities related to the following components :

- Oracle Java SE and Java SE Embedded are prone to a buffer overflow attack, over 'Multiple' protocol.
This issue affects the 'JavaFX (libxslt)' component. Successful attacks of this vulnerability allow unauthenticated attacker with network access to takeover of Java SE. (CVE-2019-18197)

- Oracle Java SE and Java SE Embedded are prone to partial denial of service (partial DOS) vulnerability.
An unauthenticated remote attacker can exploit this over 'Multiple' protocol. This issue affects the 'Scripting' component. (CVE-2020-2754, CVE-2020-2755)

- Oracle Java SE and Java SE Embedded are prone to partial denial of service (partial DOS) vulnerability.
An unauthenticated remote attacker can exploit this over 'Multiple' protocol. This issue affects the 'Serialization' component. (CVE-2020-2756, CVE-2020-2757)

- Oracle Java SE prone to unauthorized read access vulnerability. An unauthenticated remote attacker can exploit this over 'Multiple' protocol can result in unauthorized read access to a subset of Java SE accessible data. This issue affects the 'Advanced Management Console' component. (CVE-2020-2764)

- Oracle Java SE and Java SE Embedded are prone to unauthorized write/read access vulnerability. An unauthenticated remote attacker over 'HTTPS' can read, update, insert or delete access to some of Java SE accessible data. This issue affects the 'JSSE' component. (CVE-2020-2767)

- Oracle Java SE and Java SE Embedded are prone to partial denial of service (partial DOS) vulnerability.
An unauthenticated remote attacker can exploit this over 'Multiple' protocol. This issue affects the 'Scripting' component. (CVE-2020-2773)

It is also affected by other vulnerabilities; please see vendor advisories for more information.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Oracle JDK / JRE 14 Update 1 , 11 Update 7, 8 Update 251 , 7 Update 261 or later.
If necessary, remove any affected versions.
Risk Factor
Medium
CVSS v3.0 Base Score
8.3 (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.3
EPSS Score
0.0429
CVSS v2.0 Base Score
5.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:N)
CVSS v2.0 Temporal Score
4.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2020/04/16, Modified: 2024/12/20
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre1.8.0_161\
Installed version : 8.0.161.12 / build 8.0.161
Fixed version : Upgrade to version 8.0.251 or greater
138522 - Oracle Java SE 1.7.0_271 / 1.8.0_261 / 1.11.0_8 / 1.14.0_2 Multiple Vulnerabilities (Jul 2020 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities
Description
The version of Oracle (formerly Sun) Java SE or Java for Business installed on the remote host is prior to 7 Update 271, 8 Update 261, 11 Update 8, or 14 Update 2. It is, therefore, affected by multiple vulnerabilities related to the following components as referenced in the July 2020 CPU advisory:

- Vulnerability in the Java SE product of Oracle Java SE (component: JavaFX). The supported version that is affected is Java SE: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE.
Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). (CVE-2020-14664)

- Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251.
Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). (CVE-2020-14583)

- Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE, Java SE Embedded accessible data. Note:
This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). (CVE-2020-14593)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the July 2020 Oracle Critical Patch Update advisory.
Risk Factor
Medium
CVSS v3.0 Base Score
8.3 (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.3
EPSS Score
0.0183
CVSS v2.0 Base Score
5.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:N)
CVSS v2.0 Temporal Score
4.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2020/07/16, Modified: 2024/12/20
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre1.8.0_161\
Installed version : 8.0.161.12 / build 8.0.161
Fixed version : Upgrade to version 8.0.261 or greater
154344 - Oracle Java SE 1.7.0_321 / 1.8.0_311 / 1.11.0_13 / 1.17.0_1 Multiple Vulnerabilities (October 2021 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities.
Description
The version of Oracle (formerly Sun) Java SE or Java for Business installed on the remote host is prior to 7 Update 321, 8 Update 311, 11 Update 13, or 17 Update 1. It is, therefore, affected by multiple vulnerabilities as referenced in the October 2021 CPU advisory:

- Vulnerability in the Java SE product of Oracle Java SE (component: JavaFX (libxml)). The supported version that is affected is Java SE: 8u301. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Java SE as well as unauthorized update, insert or delete access to some of Java SE accessible data and unauthorized read access to a subset of Java SE accessible data. This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). (CVE-2021-3517)

- Vulnerability in the Java SE product of Oracle Java SE (component: Deployment). The supported version that is affected is Java SE: 8u301. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Java SE. This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). (CVE-2021-35560)

- Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via Kerberos to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Oracle GraalVM Enterprise Edition accessible data. (CVE-2021-35567)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the October 2021 Oracle Critical Patch Update advisory.
Risk Factor
High
CVSS v3.0 Base Score
8.6 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.0056
CVSS v2.0 Base Score
7.5 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.5 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2021/10/22, Modified: 2024/12/20
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre1.8.0_161\
Installed version : 8.0.161.12 / build 8.0.161
Fixed version : Upgrade to version 8.0.311 or greater
109202 - Oracle Java SE Multiple Vulnerabilities (April 2018 CPU)
-
Synopsis
The remote Windows host contains a programming platform that is affected by multiple vulnerabilities.
Description
The version of Oracle (formerly Sun) Java SE or Java for Business installed on the remote host is prior to 10 Update 1, 8 Update 171, 7 Update 181, or 6 Update 191. It is, therefore, affected by multiple vulnerabilities related to the following components :

- AWT
- Concurrency
- Hotspot
- Install
- JAXP
- JMX
- Libraries
- RMI
- Security
- Serialization
See Also
Solution
Upgrade to Oracle JDK / JRE 10 Update 1, 8 Update 171 / 7 Update 181 / 6 Update 191 or later. If necessary, remove any affected versions.

Note that an Extended Support contract with Oracle is needed to obtain JDK / JRE 6 Update 95 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
8.3 (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.3
EPSS Score
0.0346
CVSS v2.0 Base Score
5.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:N)
CVSS v2.0 Temporal Score
4.3 (CVSS2#E:U/RL:OF/RC:C)
References
BID 103796
BID 103810
BID 103817
BID 103832
BID 103848
BID 103849
BID 103872
CVE CVE-2018-2783
CVE CVE-2018-2790
CVE CVE-2018-2794
CVE CVE-2018-2795
CVE CVE-2018-2796
CVE CVE-2018-2797
CVE CVE-2018-2798
CVE CVE-2018-2799
CVE CVE-2018-2800
CVE CVE-2018-2811
CVE CVE-2018-2814
CVE CVE-2018-2815
CVE CVE-2018-2825
CVE CVE-2018-2826
Plugin Information
Published: 2018/04/20, Modified: 2024/12/20
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre1.8.0_161\
Installed version : 8.0.161.12 / build 8.0.161
Fixed version : Upgrade to version 8.0.171 or greater
174511 - Oracle Java SE Multiple Vulnerabilities (April 2023 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities.
Description
The version of Oracle (formerly Sun) Java SE or Java for Business installed on the remote host is affected by multiple vulnerabilities as referenced in the April 2023 CPU advisory:

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. (CVE-2023-21930)

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. (CVE-2023-21939)

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. (CVE-2023-21954)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the April 2023 Oracle Critical Patch Update advisory.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.0
EPSS Score
0.0175
CVSS v2.0 Base Score
7.1 (CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:N)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2023/04/20, Modified: 2023/04/21
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre1.8.0_161\
Installed version : 8.0.161.12 / build 8.0.161
Fixed version : Upgrade to version 8.0.371 or greater
189116 - Oracle Java SE Multiple Vulnerabilities (January 2024 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities.
Description
The version of Oracle (formerly Sun) Java SE or Java for Business installed on the remote host is affected by multiple vulnerabilities as referenced in the January 2024 CPU advisory:

- Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u391, 8u391-perf, 11.0.21, 17.0.9, 21.0.1; Oracle GraalVM for JDK: 17.0.9, 21.0.1; Oracle GraalVM Enterprise Edition: 20.3.12, 21.3.8 and 22.3.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. (CVE-2024-20918)

- Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u391, 8u391-perf, 11.0.21, 17.0.9, 21.0.1; Oracle GraalVM for JDK: 17.0.9, 21.0.1; Oracle GraalVM Enterprise Edition: 20.3.12, 21.3.8 and 22.3.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. (CVE-2024-20921)

- Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 17.0.9; Oracle GraalVM for JDK: 17.0.9; Oracle GraalVM Enterprise Edition: 21.3.8 and 22.3.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. (CVE-2024-20932)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the January 2024 Oracle Critical Patch Update advisory.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.0
EPSS Score
0.0055
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N)
CVSS v2.0 Temporal Score
5.8 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2024/01/17, Modified: 2024/04/19
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre1.8.0_161\
Installed version : 8.0.161.12 / build 8.0.161
Fixed version : Upgrade to version 8.0.401 or greater
163304 - Oracle Java SE Multiple Vulnerabilities (July 2022 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities.
Description
The version of Oracle (formerly Sun) Java SE or Java for Business installed on the remote host is affected by multiple vulnerabilities as referenced in the July 2022 CPU advisory:

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u343, 8u333, 11.0.15.1, 17.0.3.1, 18.0.1.1; Oracle GraalVM Enterprise Edition: 20.3.6, 21.3.2 and 22.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. (CVE-2022-21540)

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u343, 8u333, 11.0.15.1, 17.0.3.1, 18.0.1.1; Oracle GraalVM Enterprise Edition: 20.3.6, 21.3.2 and 22.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. (CVE-2022-21541)

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 17.0.3.1; Oracle GraalVM Enterprise Edition: 21.3.2 and 22.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. (CVE-2022-21549)

- Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Native Image (Gson)). Supported versions that are affected are Oracle GraalVM Enterprise Edition: 20.3.6, 21.3.2 and 22.1.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle GraalVM Enterprise Edition executes to compromise Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GraalVM Enterprise Edition. (CVE-2022-25647)

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP (Xalan-J)). Supported versions that are affected are Oracle Java SE: 7u343, 8u333, 11.0.15.1, 17.0.3.1, 18.0.1.1; Oracle GraalVM Enterprise Edition: 20.3.6, 21.3.2 and 22.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data.
(CVE-2022-34169)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the July 2022 Oracle Critical Patch Update advisory.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0877
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVSS v2.0 Temporal Score
4.1 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-21540
CVE CVE-2022-21541
CVE CVE-2022-21549
CVE CVE-2022-25647
CVE CVE-2022-34169
XREF IAVA:2022-A-0287-S
XREF IAVA:2023-A-0558
Plugin Information
Published: 2022/07/20, Modified: 2023/10/24
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre1.8.0_161\
Installed version : 8.0.161.12 / build 8.0.161
Fixed version : Upgrade to version 8.0.341 or greater
178485 - Oracle Java SE Multiple Vulnerabilities (July 2023 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities.
Description
The version of Oracle (formerly Sun) Java SE or Java for Business installed on the remote host is affected by multiple vulnerabilities as referenced in the July 2023 CPU advisory:

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (component: Utility). Supported versions that are affected are Oracle Java SE: 11.0.19, 17.0.7, 20.0.1; Oracle GraalVM Enterprise Edition: 20.3.10, 21.3.6, 22.3.2; Oracle GraalVM for JDK: 17.0.7 and 20.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK. (CVE-2023-22036)

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u371-perf, 11.0.19, 17.0.7, 20.0.1; Oracle GraalVM Enterprise Edition: 20.3.10, 21.3.6, 22.3.2; Oracle GraalVM for JDK: 17.0.7 and 20.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK executes to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK accessible data. (CVE-2023-22041)

- Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u371. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data. (CVE-2023-22043)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the July 2023 Oracle Critical Patch Update advisory.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
VPR Score
4.4
EPSS Score
0.0069
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)
STIG Severity
I
References
Plugin Information
Published: 2023/07/19, Modified: 2024/01/31
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre1.8.0_161\
Installed version : 8.0.161.12 / build 8.0.161
Fixed version : Upgrade to version 8.0.381 or greater
209282 - Oracle Java SE Multiple Vulnerabilities (October 2024 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities
Description
The versions of Java installed on the remote host are affected by multiple vulnerabilities as referenced in the October 2024 CPU advisory.

- Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Node (Node.js)). Supported versions that are affected are Oracle GraalVM for JDK: 17.0.12, 21.0.4 and 23. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GraalVM for JDK. Successful attacks of this vulnerability can result in takeover of Oracle GraalVM for JDK. (CVE-2024-36138)

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component:
JavaFX (WebKitGTK)). Supported versions that are affected are Oracle Java SE: 8u421; Oracle GraalVM Enterprise Edition: 20.3.15 and 21.3.11. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE, Oracle GraalVM Enterprise Edition. (CVE-2023-42950)

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component:
JavaFX (libxml2)). Supported versions that are affected are Oracle Java SE: 8u421; Oracle GraalVM Enterprise Edition: 20.3.15 and 21.3.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. (CVE-2024-25062)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the October 2024 Oracle Critical Patch Update advisory.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.7 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.0074
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)
CVSS v2.0 Temporal Score
6.1 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2024/10/18, Modified: 2025/11/05
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre1.8.0_161\
Installed version : 8.0.161.12 / build 8.0.161
Fixed version : Upgrade to version 8.0.431 or greater
271249 - Oracle Java SE Multiple Vulnerabilities (October 2025 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities
Description
The 8u461, 11.0.28, 17.0.16, 21.0.8, 25, versions of Java installed on the remote host are affected by multiple vulnerabilities as referenced in the October 2025 CPU advisory.

- Vulnerability in Oracle Java SE (component: JavaFX (WebKitGTK)). Supported versions that are affected are Oracle Java SE: 8u461-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE. (CVE-2025-31257)

- Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u461, 8u461-perf, 11.0.28, 17.0.16, 21.0.8, 25; Oracle GraalVM for JDK: 17.0.16 and 21.0.8; Oracle GraalVM Enterprise Edition: 21.3.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. (CVE-2025-53057)

- Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 8u461, 8u461-perf, 11.0.28, 17.0.16, 21.0.8, 25; Oracle GraalVM for JDK: 17.0.16 and 21.0.8; Oracle GraalVM Enterprise Edition: 21.3.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. (CVE-2025-53066)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the October 2025 Oracle Critical Patch Update advisory.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
9.2
EPSS Score
0.0009
CVSS v2.0 Base Score
7.6 (CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
Plugin Information
Published: 2025/10/23, Modified: 2025/12/23
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre1.8.0_161\
Installed version : 8.0.161.12 / build 8.0.161
Fixed version : Upgrade to version 8.0.471 or greater
242073 - RARLAB WinRAR < 7.12 Beta 1 Directory Traversal Remote Code Execution (CVE-2025-6218)
-
Synopsis
The remote Windows host has an application installed which is affected by a directory traversal remote code execution vulnerability.
Description
The remote host is running RARLAB WinRAR, an archive manager for Windows, whose reported version is prior to 7.12 Beta 1. It is, therefore, affected by a vulnerability:

- RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of file paths within archive files. A crafted file path can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27198. (CVE-2025-6218)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to RARLAB WinRAR version 7.12 Beta 1 or later.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
9.4
EPSS Score
0.0029
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.0 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2025-6218
XREF IAVA:2025-A-0227
XREF ZDI:ZDI-25-409
XREF CISA-KNOWN-EXPLOITED:2025/12/30
Plugin Information
Published: 2025/07/14, Modified: 2025/12/09
Plugin Output

tcp/445/cifs


Path : C:\Program Files\WinRAR\WinRAR.exe
Installed version : 5.90.0.0
Fixed version : 7.12 Beta 1
248462 - RARLAB WinRAR < 7.13 Directory Traversal (CVE-2025-8088)
-
Synopsis
The remote Windows host has an application installed which is affected by a directory traversal vulnerability.
Description
The remote host is running RARLAB WinRAR, an archive manager for Windows, whose reported version is prior to 7.13. It is, therefore, affected by a vulnerability:

- A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET. (CVE-2025-8088)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to RARLAB WinRAR version 7.13 or later.
Risk Factor
Critical
CVSS v4.0 Base Score
8.4 (CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
9.5
EPSS Score
0.0562
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2025-8088
XREF CISA-KNOWN-EXPLOITED:2025/09/02
XREF IAVA:2025-A-0608
Plugin Information
Published: 2025/08/11, Modified: 2025/08/21
Plugin Output

tcp/445/cifs


Path : C:\Program Files\WinRAR\WinRAR.exe
Installed version : 5.90.0.0
Fixed version : 7.13

42873 - SSL Medium Strength Cipher Suites Supported (SWEET32)
-
Synopsis
The remote service supports the use of medium strength SSL ciphers.
Description
The remote host supports the use of SSL ciphers that offer medium strength encryption. Nessus regards medium strength as any encryption that uses key lengths at least 64 bits and less than 112 bits, or else that uses the 3DES encryption suite.

Note that it is considerably easier to circumvent medium strength encryption if the attacker is on the same physical network.
See Also
Solution
Reconfigure the affected application if possible to avoid use of medium strength ciphers.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
VPR Score
6.1
EPSS Score
0.4002
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
References
Plugin Information
Published: 2009/11/23, Modified: 2025/02/12
Plugin Output

tcp/3389/msrdp


Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

249128 - Security Updates for Microsoft Excel Products (August 2025)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. They are, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-53735, CVE-2025-53737, CVE-2025-53739, CVE-2025-53741)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002758 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0011
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-53735
CVE CVE-2025-53737
CVE CVE-2025-53739
CVE CVE-2025-53741
MSKB 5002758
XREF MSFT:MS25-5002758
XREF IAVA:2025-A-0594-S
XREF CWE:122
XREF CWE:416
XREF CWE:787
XREF CWE:843
Plugin Information
Published: 2025/08/12, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.5495.1000
Fixed version : 16.0.5513.1000
277999 - Security Updates for Microsoft Excel Products (December 2025)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. They are, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-62553, CVE-2025-62564, CVE-2025-62563, CVE-2025-62556, CVE-2025-62561, CVE-2025-62560)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002820 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0008
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-62553
CVE CVE-2025-62556
CVE CVE-2025-62560
CVE CVE-2025-62561
CVE CVE-2025-62563
CVE CVE-2025-62564
MSKB 5002820
XREF MSFT:MS25-5002820
XREF IAVA:2025-A-0912
Plugin Information
Published: 2025/12/09, Modified: 2025/12/12
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.5495.1000
Fixed version : 16.0.5530.1000
241564 - Security Updates for Microsoft Excel Products (July 2025)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. They are, therefore, affected by multiple vulnerabilities:

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2025-48812)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-49697, CVE-2025-49711)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002749 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
8.4 (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0006
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-48812
CVE CVE-2025-49697
CVE CVE-2025-49711
MSKB 5002749
XREF MSFT:MS25-5002749
XREF IAVA:2025-A-0487-S
XREF CWE:122
XREF CWE:125
XREF CWE:416
Plugin Information
Published: 2025/07/08, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.5495.1000
Fixed version : 16.0.5508.1001
238089 - Security Updates for Microsoft Excel Products (June 2025)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. They are, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002735 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0006
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-47165
MSKB 5002735
XREF MSFT:MS25-5002735
XREF IAVA:2025-A-0413-S
XREF CWE:416
Plugin Information
Published: 2025/06/10, Modified: 2025/09/17
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.5495.1000
Fixed version : 16.0.5504.1000
235850 - Security Updates for Microsoft Excel Products (May 2025)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. They are, therefore, affected by multiple remote code execution vulnerabilities. An attacker can exploit these to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002717 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0012
CVSS v2.0 Base Score
6.6 (CVSS2#AV:L/AC:M/Au:S/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-29977
CVE CVE-2025-29979
CVE CVE-2025-30375
CVE CVE-2025-30376
CVE CVE-2025-30379
CVE CVE-2025-30381
CVE CVE-2025-30383
MSKB 5002717
XREF MSFT:MS25-5002717
XREF IAVA:2025-A-0332-S
XREF CWE:122
XREF CWE:125
XREF CWE:416
XREF CWE:763
XREF CWE:787
XREF CWE:822
XREF CWE:843
Plugin Information
Published: 2025/05/13, Modified: 2025/09/17
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.5495.1000
Fixed version : 16.0.5500.1000
274788 - Security Updates for Microsoft Excel Products (Novermber 2025)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. They are, therefore, affected by multiple vulnerabilities:

- Microsoft Excel allows an unauthorized attacker to disclose information locally.
(CVE-2025-59240, CVE-2025-62200, CVE-2025-62201, CVE-2025-62202, CVE-2025-62203, CVE-2025-60726)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-62199, CVE-2025-60727)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002811 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0006
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-59240
CVE CVE-2025-62200
CVE CVE-2025-62201
CVE CVE-2025-62202
CVE CVE-2025-62203
CVE CVE-2025-60726
CVE CVE-2025-60727
MSKB 5002811
XREF MSFT:MS25-5002811
XREF IAVA:2025-A-0845
XREF CWE:125
XREF CWE:416
XREF CWE:843
Plugin Information
Published: 2025/11/11, Modified: 2025/11/14
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.5495.1000
Fixed version : 16.0.5526.1002
270389 - Security Updates for Microsoft Excel Products (October 2025)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. They are, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-59223, CVE-2025-59224, CVE-2025-59225, CVE-2025-59231, CVE-2025-59233)

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2025-59232, CVE-2025-59235)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002794 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0011
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-59223
CVE CVE-2025-59224
CVE CVE-2025-59225
CVE CVE-2025-59231
CVE CVE-2025-59232
CVE CVE-2025-59233
CVE CVE-2025-59235
MSKB 5002794
XREF MSFT:MS25-5002794
XREF IAVA:2025-A-0756-S
XREF CWE:125
XREF CWE:416
XREF CWE:843
Plugin Information
Published: 2025/10/14, Modified: 2025/11/18
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.5495.1000
Fixed version : 16.0.5522.1000
261813 - Security Updates for Microsoft Excel Products (September 2025)
-
Synopsis
The Microsoft Excel Products are missing a security update.
Description
The Microsoft Excel Products are missing a security update. They are, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-54896, CVE-2025-54898, CVE-2025-54899, CVE-2025-54900, CVE-2025-54902, CVE-2025-54903, CVE-2025-54904)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002782 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0006
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-54896
CVE CVE-2025-54898
CVE CVE-2025-54899
CVE CVE-2025-54900
CVE CVE-2025-54902
CVE CVE-2025-54903
CVE CVE-2025-54904
MSKB 5002782
XREF MSFT:MS25-5002782
XREF IAVA:2025-A-0664-S
XREF CWE:122
XREF CWE:125
XREF CWE:416
XREF CWE:590
Plugin Information
Published: 2025/09/09, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



Product : Excel 2016
- C:\Program Files\Microsoft Office\Office16\Excel.exe has not been patched.
Remote version : 16.0.5495.1000
Fixed version : 16.0.5517.1000
249124 - Security Updates for Microsoft Office Products (August 2025)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. They are, therefore, affected by multiple vulnerabilities.

- A Remote Code Execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-53731, CVE-2025-53740)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following updates to address these issues:
- KB5002756
Risk Factor
High
CVSS v3.0 Base Score
8.4 (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0005
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-53731
CVE CVE-2025-53740
MSKB 5002756
XREF MSFT:MS25-5002756
XREF IAVA:2025-A-0596
XREF CWE:416
Plugin Information
Published: 2025/08/12, Modified: 2025/09/17
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002756
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.5495.1002
Should be : 16.0.5513.1000
277985 - Security Updates for Microsoft Office Products (December 2025)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. They are, therefore, affected by multiple vulnerabilities.

- A Remote Code Execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-62552, CVE-2025-62557, CVE-2025-62554, CVE-2025-62553, CVE-2025-62561, CVE-2025-62563)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following updates to address these issues:
- KB5002812
- KB5002818
- KB5002819
Risk Factor
High
CVSS v3.0 Base Score
8.4 (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
VPR Score
7.4
EPSS Score
0.0015
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-62552
CVE CVE-2025-62553
CVE CVE-2025-62554
CVE CVE-2025-62557
CVE CVE-2025-62561
CVE CVE-2025-62563
MSKB 5002812
MSKB 5002818
MSKB 5002819
MSKB 5002818
XREF MSFT:MS25-5002812
XREF MSFT:MS25-5002818
XREF MSFT:MS25-5002819
XREF IAVA:2025-A-0914
Plugin Information
Published: 2025/12/09, Modified: 2025/12/12
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002819
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.5495.1002
Should be : 16.0.5530.1001

Product : Microsoft Office 2016
KB : 5002818
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.5495.1000
Should be : 16.0.5530.1000

Product : Microsoft Office 2016
KB : 5002812
- C:\Program Files\Common Files\Microsoft Shared\Office16\acecore.dll has not been patched.
Remote version : 16.0.5413.1000
Should be : 16.0.5530.1000
241553 - Security Updates for Microsoft Office Products (July 2025)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. They are, therefore, affected by multiple vulnerabilities.

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2025-48812)

- A Remote Code Execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-49695, CVE-2025-49696, CVE-2025-49697, CVE-2025-49698, CVE-2025-49699, CVE-2025-49700, CVE-2025-49702)

- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges.
(CVE-2025-47994)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following updates to address these issues:
- KB4464583
- KB5001941
- KB5002655
- KB5002734
- KB5002742
Risk Factor
High
CVSS v3.0 Base Score
8.4 (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
VPR Score
7.3
EPSS Score
0.0015
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-47994
CVE CVE-2025-48812
CVE CVE-2025-49695
CVE CVE-2025-49696
CVE CVE-2025-49697
CVE CVE-2025-49698
CVE CVE-2025-49699
CVE CVE-2025-49700
CVE CVE-2025-49702
MSKB 4464583
MSKB 5001941
MSKB 5002655
MSKB 5002734
MSKB 5002742
XREF MSFT:MS25-4464583
XREF MSFT:MS25-5001941
XREF MSFT:MS25-5002655
XREF MSFT:MS25-5002733
XREF MSFT:MS25-5002734
XREF MSFT:MS25-5002742
XREF IAVA:2025-A-0488-S
XREF CWE:122
XREF CWE:125
XREF CWE:416
XREF CWE:502
XREF CWE:843
Plugin Information
Published: 2025/07/08, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 4464583
- C:\Program Files\Microsoft Office\Office16\css7data0009.dll has not been patched.
Remote version : 16.0.4266.1001
Should be : 16.0.5508.1000

Product : Microsoft Office 2016
KB : 5002655
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso99lwin32client.dll has not been patched.
Remote version : 16.0.5463.1000
Should be : 16.0.5508.1000

Product : Microsoft Office 2016
KB : 5002734
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.5495.1000
Should be : 16.0.5508.1001

Product : Microsoft Office 2016
KB : 5002742
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.5495.1002
Should be : 16.0.5508.1001
238088 - Security Updates for Microsoft Office Products (June 2025)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. They are, therefore, affected by multiple remote code execution vulnerabilities. An attacker can exploit these to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following updates to address these issues:
- KB5002616
- KB5002730
Risk Factor
High
CVSS v3.0 Base Score
8.4 (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0016
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-47162
CVE CVE-2025-47164
CVE CVE-2025-47167
CVE CVE-2025-47173
CVE CVE-2025-47953
MSKB 5002616
MSKB 5002730
XREF MSFT:MS25-5002616
XREF MSFT:MS25-5002730
XREF IAVA:2025-A-0416-S
XREF CWE:122
XREF CWE:416
XREF CWE:641
XREF CWE:843
Plugin Information
Published: 2025/06/10, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002616
- C:\Program Files\Microsoft Office\Office16\oart.dll has not been patched.
Remote version : 16.0.5449.1000
Should be : 16.0.5504.1000

Product : Microsoft Office 2016
KB : 5002730
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.5495.1002
Should be : 16.0.5504.1002
235849 - Security Updates for Microsoft Office Products (May 2025)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. It is, therefore, affected by multiple remote code execution vulnerabilities. An attacker can exploit these to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following updates to address these issues:
- KB5002695
- KB5002711
- KB5002716
Risk Factor
High
CVSS v3.0 Base Score
8.4 (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0006
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-30377
CVE CVE-2025-30379
CVE CVE-2025-30386
CVE CVE-2025-32704
MSKB 5002695
MSKB 5002711
MSKB 5002716
XREF MSFT:MS25-5002695
XREF MSFT:MS25-5002711
XREF MSFT:MS25-5002716
XREF IAVA:2025-A-0337-S
XREF CWE:125
XREF CWE:126
XREF CWE:416
XREF CWE:763
Plugin Information
Published: 2025/05/13, Modified: 2025/09/17
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002716
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.5495.1000
Should be : 16.0.5500.1000

Product : Microsoft Office 2016
KB : 5002695
- C:\Program Files\Microsoft Office\Office16\gkexcel.dll has not been patched.
Remote version : 16.0.5487.1000
Should be : 16.0.5500.1001

Product : Microsoft Office 2016
KB : 5002711
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.5495.1002
Should be : 16.0.5500.1002
274786 - Security Updates for Microsoft Office Products (November 2025)
-
Synopsis
The Microsoft Office Products are affected by Remote Code Execution Vulnerability.
Description
The Microsoft Office Products are missing security updates. They are, therefore, affected by multiple vulnerabilities:

- Microsoft Excel allows an unauthorized attacker to disclose information locally.
(CVE-2025-62202, CVE-2025-60726)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-62199, CVE-2025-60727)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following updates to address these issues:
- KB5002809
Risk Factor
High
CVSS v3.0 Base Score
8.4 (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0006
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-62199
CVE CVE-2025-62202
CVE CVE-2025-60726
CVE CVE-2025-60727
MSKB 5002809
MSKB 5002810
XREF MSFT:MS25-5002809
XREF MSFT:MS25-5002810
XREF IAVA:2025-A-0846
XREF CWE:416
Plugin Information
Published: 2025/11/11, Modified: 2025/11/14
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002809
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.5495.1002
Should be : 16.0.5526.1000

Product : Microsoft Office 2016
KB : 5002810
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.5495.1000
Should be : 16.0.5526.1000
270387 - Security Updates for Microsoft Office Products (October 2025)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. They are, therefore, affected by multiple vulnerabilities.

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-59226, CVE-2025-59227, CVE-2025-59234)

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2025-59232, CVE-2025-59235)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following updates to address these issues:
- KB5002341
- KB5002719
- KB5002757
- KB5002792
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0006
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-59226
CVE CVE-2025-59227
CVE CVE-2025-59232
CVE CVE-2025-59234
CVE CVE-2025-59235
MSKB 5002341
MSKB 5002719
MSKB 5002757
MSKB 5002792
XREF MSFT:MS25-5002341
XREF MSFT:MS25-5002719
XREF MSFT:MS25-5002757
XREF MSFT:MS25-5002792
XREF IAVA:2025-A-0759-S
XREF CWE:125
XREF CWE:416
Plugin Information
Published: 2025/10/14, Modified: 2025/11/18
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002341
- C:\Program Files\Microsoft Office\Office16\stslist.dll has not been patched.
Remote version : 16.0.5377.1000
Should be : 16.0.5522.1000

Product : Microsoft Office 2016
KB : 5002719
- C:\Program Files\Common Files\Microsoft Shared\Office16\acees.dll has not been patched.
Remote version : 16.0.5495.1000
Should be : 16.0.5522.1000

Product : Microsoft Office 2016
KB : 5002757
- C:\Program Files\Microsoft Office\Office16\graph.exe has not been patched.
Remote version : 16.0.5495.1000
Should be : 16.0.5522.1000

Product : Microsoft Office 2016
KB : 5002792
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.5495.1002
Should be : 16.0.5522.1000
261796 - Security Updates for Microsoft Office Products (September 2025)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates. They are, therefore, affected by multiple vulnerabilities.

- A Remote Code Execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-54906, CVE-2025-54910)

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2025-54901)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following updates to address these issues:
- KB5002576
- KB5002762
- KB5002766
- KB5002781
Risk Factor
High
CVSS v3.0 Base Score
8.4 (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0006
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-54901
CVE CVE-2025-54906
CVE CVE-2025-54910
MSKB 5002576
MSKB 5002762
MSKB 5002766
MSKB 5002781
XREF MSFT:MS25-5002576
XREF MSFT:MS25-5002762
XREF MSFT:MS25-5002766
XREF MSFT:MS25-5002781
XREF IAVA:2025-A-0666-S
XREF CWE:122
XREF CWE:126
XREF CWE:416
Plugin Information
Published: 2025/09/09, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2016
KB : 5002576
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso40uiwin32client.dll has not been patched.
Remote version : 16.0.5435.1000
Should be : 16.0.5517.1000

Product : Microsoft Office 2016
KB : 5002762
- C:\Program Files\Microsoft Office\Office16\gkexcel.dll has not been patched.
Remote version : 16.0.5487.1000
Should be : 16.0.5517.1000

Product : Microsoft Office 2016
KB : 5002766
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso99lwin32client.dll has not been patched.
Remote version : 16.0.5463.1000
Should be : 16.0.5513.1000

Product : Microsoft Office 2016
KB : 5002781
- C:\Program Files\Common Files\Microsoft Shared\Office16\mso.dll has not been patched.
Remote version : 16.0.5495.1002
Should be : 16.0.5517.1000
249134 - Security Updates for Microsoft PowerPoint Products (August 2025)
-
Synopsis
The Microsoft PowerPoint Products are missing a security update.
Description
The Microsoft PowerPoint Products are missing a security update. They are, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002765 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
5.9
EPSS Score
0.0006
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-53761
MSKB 5002765
XREF MSFT:MS25-5002765
XREF IAVA:2025-A-0597-S
XREF CWE:416
Plugin Information
Published: 2025/08/12, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



Product : PowerPoint 2016
- C:\Program Files\Microsoft Office\Office16\ppcore.dll has not been patched.
Remote version : 16.0.5483.1000
Fixed version : 16.0.5513.1000
241542 - Security Updates for Microsoft PowerPoint Products (July 2025)
-
Synopsis
The Microsoft PowerPoint Products are missing a security update.
Description
The Microsoft PowerPoint Products are missing a security update. They are, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002746 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
5.9
EPSS Score
0.0006
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-49705
MSKB 5002746
XREF MSFT:MS25-5002746
XREF IAVA:2025-A-0490-S
XREF CWE:122
Plugin Information
Published: 2025/07/08, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



Product : PowerPoint 2016
- C:\Program Files\Microsoft Office\Office16\ppcore.dll has not been patched.
Remote version : 16.0.5483.1000
Fixed version : 16.0.5508.1000
238086 - Security Updates for Microsoft PowerPoint Products (June 2025)
-
Synopsis
The Microsoft PowerPoint Products are missing a security update.
Description
The Microsoft PowerPoint Products are missing a security update. They are, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002689 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0006
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-47175
MSKB 5002689
XREF MSFT:MS25-5002689
XREF IAVA:2025-A-0418-S
XREF CWE:416
Plugin Information
Published: 2025/06/10, Modified: 2025/09/17
Plugin Output

tcp/445/cifs



Product : PowerPoint 2016
- C:\Program Files\Microsoft Office\Office16\ppcore.dll has not been patched.
Remote version : 16.0.5483.1000
Fixed version : 16.0.5504.1000
270692 - Security Updates for Microsoft PowerPoint Products (October 2025)
-
Synopsis
The Microsoft PowerPoint Products are missing a security update.
Description
The Microsoft PowerPoint Products are missing a security update. They are, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002790 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
5.9
EPSS Score
0.0006
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-59238
MSKB 5002790
XREF MSFT:MS25-5002790
XREF IAVA:2025-A-0758
XREF CWE:416
Plugin Information
Published: 2025/10/17, Modified: 2025/10/17
Plugin Output

tcp/445/cifs



Product : PowerPoint 2016
- C:\Program Files\Microsoft Office\Office16\ppcore.dll has not been patched.
Remote version : 16.0.5483.1000
Fixed version : 16.0.5522.1000
261805 - Security Updates for Microsoft PowerPoint Products (September 2025)
-
Synopsis
The Microsoft PowerPoint Products are missing a security update.
Description
The Microsoft PowerPoint Products are missing a security update. They are, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002779 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
5.9
EPSS Score
0.0006
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-54908
MSKB 5002779
XREF MSFT:MS25-5002779
XREF IAVA:2025-A-0667-S
XREF CWE:416
Plugin Information
Published: 2025/09/09, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



Product : PowerPoint 2016
- C:\Program Files\Microsoft Office\Office16\ppcore.dll has not been patched.
Remote version : 16.0.5483.1000
Fixed version : 16.0.5517.1000
249121 - Security Updates for Microsoft Word Products (August 2025)
-
Synopsis
The Microsoft Word Products are affected by a multiple vulnerabilities.
Description
The Microsoft Word Products are missing a security update. They are, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-53733, CVE-2025-53738)

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2025-53736)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002763 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
8.4 (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0011
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-53733
CVE CVE-2025-53736
CVE CVE-2025-53738
MSKB 5002763
XREF MSFT:MS25-5002763
XREF IAVA:2025-A-0606-S
XREF CWE:126
XREF CWE:416
XREF CWE:681
Plugin Information
Published: 2025/08/12, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.5495.1002
Fixed version : 16.0.5513.1000
277989 - Security Updates for Microsoft Word Products (December 2025)
-
Synopsis
The Microsoft Word Products are affected by multiple vulnerabilities.
Description
The Microsoft Word Products are missing a security update. They are, therefore, affected by multiple remote code execution vulnerabilities. An attacker can exploit these to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002806 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
7.4
EPSS Score
0.0008
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-62555
CVE CVE-2025-62558
CVE CVE-2025-62559
CVE CVE-2025-62562
MSKB 5002806
XREF MSFT:MS25-5002806
XREF IAVA:2025-A-0918
Plugin Information
Published: 2025/12/09, Modified: 2025/12/12
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.5495.1002
Fixed version : 16.0.5530.1000
241561 - Security Updates for Microsoft Word Products (July 2025)
-
Synopsis
The Microsoft Word Products are affected by a remote code execution vulnerability.
Description
The Microsoft Word Products are missing security updates. They are, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002745 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0006
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-49703
MSKB 5002745
XREF MSFT:MS25-5002745
XREF IAVA:2025-A-0495-S
XREF CWE:416
Plugin Information
Published: 2025/07/08, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.5495.1002
Fixed version : 16.0.5508.1000
238093 - Security Updates for Microsoft Word Products (June 2025)
-
Synopsis
The Microsoft Word Products are affected by multiple vulnerabilities.
Description
The Microsoft Word Products are missing security updates. They are, therefore, affected by multiple remote code execution vulnerabilities. An attacker can exploit these to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002710 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
5.9
EPSS Score
0.0006
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-47168
CVE CVE-2025-47169
MSKB 5002710
XREF MSFT:MS25-5002710
XREF IAVA:2025-A-0412-S
XREF CWE:122
XREF CWE:416
Plugin Information
Published: 2025/06/10, Modified: 2025/09/17
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.5495.1002
Fixed version : 16.0.5504.1000
270364 - Security Updates for Microsoft Word Products (October 2025)
-
Synopsis
The Microsoft Word Products are affected by multiple vulnerabilities.
Description
The Microsoft Word Products are missing a security update. They are, therefore, affected by multiple remote code execution vulnerabilities. An attacker can exploit these to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002789 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0006
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-59221
CVE CVE-2025-59222
MSKB 5002789
XREF MSFT:MS25-5002789
XREF IAVA:2025-A-0762
XREF CWE:416
Plugin Information
Published: 2025/10/14, Modified: 2025/10/17
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.5495.1002
Fixed version : 16.0.5522.1000
261814 - Security Updates for Microsoft Word Products (September 2025)
-
Synopsis
The Microsoft Word Products are affected by a multiple vulnerabilities.
Description
The Microsoft Word Products are missing a security update. They are, therefore, affected by an information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002780 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.1 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H)
VPR Score
5.2
EPSS Score
0.0005
CVSS v2.0 Base Score
6.3 (CVSS2#AV:L/AC:M/Au:N/C:C/I:N/A:C)
STIG Severity
I
References
CVE CVE-2025-54905
MSKB 5002780
XREF MSFT:MS25-5002780
XREF IAVA:2025-A-0672-S
XREF CWE:822
Plugin Information
Published: 2025/09/09, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



Product : Word 2016
- C:\Program Files\Microsoft Office\Office16\WinWord.exe has not been patched.
Remote version : 16.0.5495.1002
Fixed version : 16.0.5517.1000
241560 - Security Updates for Outlook (July 2025)
-
Synopsis
The Microsoft Outlook application installed on the remote host is missing a security update.
Description
The Microsoft Outlook application installed on the remote host is missing a security update. It is, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002747 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.0 (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0006
CVSS v2.0 Base Score
6.2 (CVSS2#AV:L/AC:H/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-49699
MSKB 5002747
XREF MSFT:MS25-5002747
XREF IAVA:2025-A-0489
XREF CWE:416
Plugin Information
Published: 2025/07/08, Modified: 2025/09/17
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.5483.1000
Fixed version : 16.0.5507.1000
233416 - VMware Tools 11.x / 12.x < 12.5.1 Authentication Bypass (VMSA-2025-0005)
-
Synopsis
The virtualization tool suite is installed on the remote Windows host is affected by an authentication bypass vulnerability.
Description
The version of VMware Tools installed on the remote Windows host is 11.x or 12.x prior to 12.5.1. It is, therefore, affected by an authentication bypass vulnerability:

- VMware Tools for Windows contains an authentication bypass vulnerability due to improper access control. A malicious actor with non-administrative privileges on a guest VM may gain ability to perform certain high privilege operations within that VM. (CVE-2025-22230)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to VMware Tools version 12.5.1 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0003
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-22230
XREF VMSA:2025-0005
XREF IAVA:2025-A-0199-S
Plugin Information
Published: 2025/03/27, Modified: 2025/05/16
Plugin Output

tcp/445/cifs


Path : C:\Program Files\VMware\VMware Tools\
Installed version : 12.3.5.46049
Fixed version : 12.5.1
266420 - VMware Tools 11.x < 12.5.4 / 13.x < 13.0.5 Multiple Vulnerabilities (VMSA-2025-0015)
-
Synopsis
The virtualization tool suite installed on the remote host is affected by multiple vulnerabilities.
Description
The version of VMware Tools installed on the remote host is 11.x or 12.x prior to 12.5.4, or 13.x prior to 13.0.5.
It is, therefore, affected by multiple vulnerabilities as disclosed in the VMSA-2025-0015 advisory:

- VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM. (CVE-2025-41244)

- VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls. A malicious actor with non-administrative privileges on a guest VM, who is already authenticated through vCenter or ESX may exploit this issue to access other guest VMs. Successful exploitation requires knowledge of credentials of the targeted VMs and vCenter or ESX. (CVE-2025-41246)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to VMware Tools version 12.5.4, 13.0.5 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
9.2
EPSS Score
0.0002
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-41244
CVE CVE-2025-41246
XREF VMSA:2025-0015
XREF IAVA:2025-A-0712
XREF CISA-KNOWN-EXPLOITED:2025/11/20
Plugin Information
Published: 2025/10/02, Modified: 2025/10/30
Plugin Output

tcp/445/cifs


Path : C:\Program Files\VMware\VMware Tools\
Installed version : 12.3.5.46049
Fixed version : 12.5.4
CVE(s) : CVE-2025-41244 CVE-2025-41246
180174 - WinRAR < 6.23 RCE
-
Synopsis
The remote Windows host has an application installed which is affected by a remote code execution vulnerability.
Description
The remote host is running WinRAR, an archive manager for Windows.

The version of WinRAR installed on the remote host is affected by a an improper validation of user-supplied data, which can result in memory access past the end of an allocated buffer which can be exploited remotely and may allow attackers to execute code in the context of the current process.
See Also
Solution
Upgrade to WinRAR version 6.23 or later.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.7
EPSS Score
0.9385
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2023-38831
CVE CVE-2023-40477
XREF CISA-KNOWN-EXPLOITED:2023/09/14
XREF IAVA:2023-A-0436-S
Exploitable With
Core Impact (true) Metasploit (true)
Plugin Information
Published: 2023/08/24, Modified: 2024/05/03
Plugin Output

tcp/445/cifs


Path : C:\Program Files\WinRAR\WinRAR.exe
Installed version : 5.90.0.0
Fixed version : 6.23
192940 - WinRAR < 7.00 Multiple Vulnerabilities
-
Synopsis
The remote Windows host has an application installed which is affected by multiple vulnerabilities.
Description
The remote host is running WinRAR, an archive manager for Windows, whose reported version is prior to 7.00. It is, therefore, affected by multiple vulnerabilties:

- The vulnerability exists due to an error within the archive extraction functionality. A remote attacker can use a specially crafted archive to bypass the Mark-Of-The-Web protection mechanism and potentially compromise the affected system. (CVE-2024-30370)

- RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a different issue than CVE-2024-33899. (CVE-2024-36052)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to WinRAR version 7.00 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
CVSS v3.0 Temporal Score
6.7 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0042
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N)
CVSS v2.0 Temporal Score
3.9 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2024-30370
CVE CVE-2024-36052
XREF IAVA:2024-A-0194-S
XREF IAVA:2024-A-0303-S
Plugin Information
Published: 2024/04/05, Modified: 2025/06/23
Plugin Output

tcp/445/cifs


Path : C:\Program Files\WinRAR\WinRAR.exe
Installed version : 5.90.0.0
Fixed version : 7.0
166555 - WinVerifyTrust Signature Validation CVE-2013-3900 Mitigation (EnableCertPaddingCheck)
-
Synopsis
The remote Windows host is potentially missing a mitigation for a remote code execution vulnerability.
Description
The remote system may be in a vulnerable state to CVE-2013-3900 due to a missing or misconfigured registry keys:
- HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck
- HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck An unauthenticated, remote attacker could exploit this, by sending specially crafted requests, to execute arbitrary code on an affected host.
See Also
Solution
Add and enable registry value EnableCertPaddingCheck:
- HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck

Additionally, on 64 Bit OS systems, Add and enable registry value EnableCertPaddingCheck:

- HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.0
EPSS Score
0.7941
CVSS v2.0 Base Score
7.6 (CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.6 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2013-3900
XREF CISA-KNOWN-EXPLOITED:2022/07/10
XREF IAVA:2013-A-0227
Plugin Information
Published: 2022/10/26, Modified: 2025/12/17
Plugin Output

tcp/445/cifs



Nessus detected the following potentially insecure registry key configuration:
- Software\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck is not present in the registry.
- Software\Wow6432Node\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck is not present in the registry.

177383 - Microsoft OneNote Spoofing(June 2023)
-
Synopsis
The Microsoft OneNote Products are affected by a spoofing vulnerability.
Description
The Microsoft OneNote Products are missing a security update. It is, therefore, affected by a spoofing vulnerability.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade the Windows 'Microsoft OneNote' app to version 16.0.14326.21450 or later via the Microsoft Store.
Risk Factor
High
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
5.9 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0496
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N)
CVSS v2.0 Temporal Score
6.1 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2023-33140
XREF IAVA:2023-A-0303-S
Plugin Information
Published: 2023/06/16, Modified: 2025/05/23
Plugin Output

tcp/0


Path : C:\Program Files\WindowsApps\Microsoft.Office.OneNote_16001.12026.20112.0_x64__8wekyb3d8bbwe
Installed version : 16001.12026.20112.0
Fixed version : 16001.14326.21450.0
150373 - Microsoft Paint 3D Multiple Vulnerabilities (June 2021)
-
Synopsis
The Windows app installed on the remote host is affected by multiple vulnerabilities.
Description
The Windows 'Paint 3D' app installed on the remote host is affected by multiple remote code execution vulnerabilities. An attacker can exploit these to bypass authentication and execute unauthorized arbitrary commands.
See Also
Solution
Upgrade the Windows 'Paint 3D' app to version 6.2105.4017.0, or later via the Microsoft Store.
Risk Factor
Medium
CVSS v3.0 Base Score
6.6 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L)
CVSS v3.0 Temporal Score
5.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0191
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
References
Plugin Information
Published: 2021/06/08, Modified: 2025/05/23
Plugin Output

tcp/0


Path : C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe
Installed version : 6.1907.29027.0
Fixed version : 6.2105.4017.0

216412 - Mozilla Firefox < 135.0.1
-
Synopsis
A web browser installed on the remote Windows host is affected by a vulnerability.
Description
The version of Firefox installed on the remote Windows host is prior to 135.0.1. It is, therefore, affected by a vulnerability as referenced in the mfsa2025-12 advisory.

- Memory safety bugs present in Firefox 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
(CVE-2025-1414)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Mozilla Firefox version 135.0.1 or later.
Risk Factor
High
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L)
CVSS v3.0 Temporal Score
5.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.3
EPSS Score
0.0007
CVSS v2.0 Base Score
7.5 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.5 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2025-1414
XREF IAVA:2025-A-0125-S
Plugin Information
Published: 2025/02/18, Modified: 2025/11/18
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Mozilla Firefox
Installed version : 134.0
Fixed version : 135.0.1
234433 - Mozilla Firefox < 137.0.2
-
Synopsis
A web browser installed on the remote Windows host is affected by a vulnerability.
Description
The version of Firefox installed on the remote Windows host is prior to 137.0.2. It is, therefore, affected by a vulnerability as referenced in the mfsa2025-25 advisory.

- A race condition existed in nsHttpTransaction that could have been exploited to cause memory corruption, potentially leading to an exploitable condition. (CVE-2025-3608)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Mozilla Firefox version 137.0.2 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N)
CVSS v3.0 Temporal Score
5.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.0
EPSS Score
0.0002
CVSS v2.0 Base Score
6.1 (CVSS2#AV:N/AC:H/Au:N/C:C/I:P/A:N)
CVSS v2.0 Temporal Score
4.5 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-3608
XREF IAVA:2025-A-0280-S
Plugin Information
Published: 2025/04/15, Modified: 2025/11/18
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Mozilla Firefox
Installed version : 134.0
Fixed version : 137.0.2
126821 - Oracle Java SE 1.7.0_231 / 1.8.0_221 / 1.11.0_4 / 1.12.0_2 Multiple Vulnerabilities (Jul 2019 CPU)
-
Synopsis
The remote Windows host contains a programming platform that is affected by multiple vulnerabilities.
Description
The version of Oracle (formerly Sun) Java SE or Java for Business installed on the remote host is prior to 7 Update 231, 8 Update 221, 11 Update 4, or 12 Update 2. It is, therefore, affected by multiple vulnerabilities:

- Unspecified vulnerabilities in the utilities and JCE subcomponents of Oracle Java SE, which could allow an unauthenticated remote attacker to cause a partial denial of service. (CVE-2019-2762, CVE-2019-2769, CVE-2019-2842)

- An unspecified vulnerability in the security subcomponent of Oracle Java SE, which could allow an unauthenticated local attacker to gain unauthorized access to critical Java SE data. (CVE-2019-2745)

- Unspecified vulnerabilities in the networking and security subcomponents of Oracle Java SE, which could allow an unauthenticated remote attacker to gain unauthorized access to Java SE data. Exploitation of this vulnerability requires user interaction. (CVE-2019-2766, CVE-2019-2786, CVE-2019-2818)

- An unspecified vulnerability in the networking subcomponent of Oracle Java SE, which could allow an unauthenticated remote attacker unauthorized read, update, insert or delete access to Java SE data. (CVE-2019-2816)

- An unspecified vulnerability in the JSSE subcomponent of Oracle Java SE, which could allow an unauthenticated, remote attacker to gain unauthorized access to critical Java SE data. Exploitation of this vulnerability requires user interaction. (CVE-2019-2821)

- A use after free vulnerability exists in the libpng subcomponent of Oracle Java SE. An unauthenticated, remote attacker can exploit this to cause a complete denial of service condition in Java SE. Exploitation of this vulnerability requires user interaction.
(CVE-2019-7317)

Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Oracle JDK / JRE 12 Update 2 , 11 Update 4, 8 Update 221 / 7 Update 231 or later. If necessary, remove any affected versions.
Risk Factor
Medium
CVSS v3.0 Base Score
5.3 (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
4.8 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0156
CVSS v2.0 Base Score
5.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:N)
CVSS v2.0 Temporal Score
4.5 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
BID 108098
BID 109184
BID 109185
BID 109186
BID 109187
BID 109188
BID 109189
BID 109201
BID 109206
BID 109210
BID 109212
CVE CVE-2019-2745
CVE CVE-2019-2762
CVE CVE-2019-2766
CVE CVE-2019-2769
CVE CVE-2019-2786
CVE CVE-2019-2816
CVE CVE-2019-2818
CVE CVE-2019-2821
CVE CVE-2019-2842
CVE CVE-2019-6129
CVE CVE-2019-7317
XREF IAVA:2019-A-0255
XREF CEA-ID:CEA-2021-0025
Plugin Information
Published: 2019/07/19, Modified: 2025/02/25
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre1.8.0_161\
Installed version : 8.0.161.12 / build 8.0.161
Fixed version : Upgrade to version 8.0.221 or greater
141800 - Oracle Java SE 1.7.0_281 / 1.8.0_271 / 1.11.0_9 / 1.15.0_1 Multiple Vulnerabilities (Oct 2020 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities
Description
The version of Oracle (formerly Sun) Java SE or Java for Business installed on the remote host is prior to 7 Update 281, 8 Update 271, 11 Update 9, or 15 Update 1. It is, therefore, affected by multiple vulnerabilities related to the following components as referenced in the October 2020 CPU advisory:

- Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: Java).
Supported versions that are affected are 19.3.3 and 20.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle GraalVM Enterprise Edition accessible data. (CVE-2020-14803)

- Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data as well as unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service.
(CVE-2020-14792)

- Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JNDI). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. (CVE-2020-14781)


Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the October 2020 Oracle Critical Patch Update advisory.
Risk Factor
Medium
CVSS v3.0 Base Score
5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
CVSS v3.0 Temporal Score
4.6 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.3
EPSS Score
0.0025
CVSS v2.0 Base Score
5.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:N)
CVSS v2.0 Temporal Score
4.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-14779
CVE CVE-2020-14781
CVE CVE-2020-14782
CVE CVE-2020-14792
CVE CVE-2020-14796
CVE CVE-2020-14797
CVE CVE-2020-14798
CVE CVE-2020-14803
XREF IAVA:2020-A-0477-S
XREF CEA-ID:CEA-2021-0004
Plugin Information
Published: 2020/10/22, Modified: 2024/12/20
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre1.8.0_161\
Installed version : 8.0.161.12 / build 8.0.161
Fixed version : Upgrade to version 8.0.271 or greater
145218 - Oracle Java SE 1.7.0_291 / 1.8.0_281 / 1.11.0_10 / 1.15.0_2 Information Disclosure (Windows Jan 2021 CPU)
-
Synopsis
The remote host is affected by an information disclosure vulnerability.
Description
The version of Oracle (formerly Sun) Java SE or Java for Business installed on the remote host is prior to 7 Update 291, 8 Update 281, 11 Update 10, or 15 Update 2. It is, therefore, affected by an information disclosure vulnerability as referenced in the January 2021 CPU advisory. Specifically, an unauthenticated, remote attacker can gain unauthorized read access to some data accessible to Java SE and Java SE Embedded. Only Java deployments that load and run untrusted code and rely on the Java sandbox for security are affected. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator).

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the January 2021 Oracle Critical Patch Update advisory.
Risk Factor
Medium
CVSS v3.0 Base Score
5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
CVSS v3.0 Temporal Score
4.6 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
1.4
EPSS Score
0.0006
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
3.7 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2020-14803
XREF CEA-ID:CEA-2021-0004
Plugin Information
Published: 2021/01/20, Modified: 2024/12/20
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre1.8.0_161\
Installed version : 8.0.161.12 / build 8.0.161
Fixed version : Upgrade to version 8.0.281 or greater
148960 - Oracle Java SE 1.7.0_301 / 1.8.0_291 / 1.11.0_11 / 1.16.0_1 Multiple Vulnerabilities (Apr 2021 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities.
Description
The version of Oracle (formerly Sun) Java SE or Java for Business installed on the remote host is prior to 7 Update 301, 8 Update 291, 11 Update 11, or 16 Update 1. It is, therefore, affected by multiple vulnerabilities as referenced in the April 2021 CPU advisory:

- A vulnerability in Java SE, SE Embedded and Oracle GraalVM Enterprise Edition allows unauthenticated remote attacker to compromise the system which can result in an unauthorized creation, deletion or modification access to critical data. (CVE-2021-2161)

- A vulnerability in Java SE, SE Embedded and Oracle GraalVM Enterprise Edition allows unauthenticated remote attacker with a human interaction from a person other than the attacker to compromise the system which can result in an unauthorized creation, deletion or modification access to critical data. (CVE-2021-2163)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the April 2021 Oracle Critical Patch Update advisory.
Risk Factor
Medium
CVSS v3.0 Base Score
5.9 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)
CVSS v3.0 Temporal Score
5.2 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0032
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)
CVSS v2.0 Temporal Score
3.2 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-2161
CVE CVE-2021-2163
XREF IAVA:2021-A-0195
XREF CEA-ID:CEA-2021-0025
Plugin Information
Published: 2021/04/23, Modified: 2024/12/20
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre1.8.0_161\
Installed version : 8.0.161.12 / build 8.0.161
Fixed version : Upgrade to version 8.0.291 or greater
156887 - Oracle Java SE 1.7.0_331 / 1.8.0_321 / 1.11.0_14 / 1.17.0_2 Multiple Vulnerabilities (January 2022 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities.
Description
The version of Oracle (formerly Sun) Java SE or Java for Business installed on the remote host is affected by multiple vulnerabilities as referenced in the January 2022 CPU advisory:

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D).
Supported versions that are affected are Oracle Java SE: 7u321, 8u311; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. (CVE-2022-21349)

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component:
Hotspot). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.01; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs.
(CVE-2022-21291)

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component:
Hotspot). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.01; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs.
(CVE-2022-21305)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the January 2022 Oracle Critical Patch Update advisory.
Risk Factor
Medium
CVSS v3.0 Base Score
5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
CVSS v3.0 Temporal Score
4.8 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
2.2
EPSS Score
0.0646
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N)
CVSS v2.0 Temporal Score
3.9 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2022/01/20, Modified: 2024/12/20
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre1.8.0_161\
Installed version : 8.0.161.12 / build 8.0.161
Fixed version : Upgrade to version 8.0.321 or greater
161241 - Oracle Java SE Multiple Vulnerabilities (April 2022 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities.
Description
The version of Oracle (formerly Sun) Java SE or Java for Business installed on the remote host is affected by multiple vulnerabilities as referenced in the April 2022 CPU advisory:

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component:
Libraries). Supported versions that are affected are Oracle Java SE: 17.0.2 and 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note:
This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. (CVE-2022-21449)

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component:
Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18;
Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. (CVE-2022-21476)

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component:
JAXP). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. (CVE-2022-21426)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the April 2022 Oracle Critical Patch Update advisory.
Risk Factor
Medium
CVSS v3.0 Base Score
5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
CVSS v3.0 Temporal Score
4.8 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.2886
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N)
CVSS v2.0 Temporal Score
3.9 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2022/05/17, Modified: 2024/11/27
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre1.8.0_161\
Installed version : 8.0.161.12 / build 8.0.161
Fixed version : Upgrade to version 8.0.331 or greater
170161 - Oracle Java SE Multiple Vulnerabilities (January 2023 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities.
Description
The version of Oracle (formerly Sun) Java SE or Java for Business installed on the remote host is affected by multiple vulnerabilities as referenced in the January 2023 CPU advisory:

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization). Supported versions that are affected are Oracle Java SE: 8u351, 8u351-perf;
Oracle GraalVM Enterprise Edition: 20.3.8 and 21.3.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data.
(CVE-2023-21830)

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 11.0.17, 17.0.5, 19.0.1;
Oracle GraalVM Enterprise Edition: 20.3.8, 21.3.4 and 22.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via DTLS to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition.
(CVE-2023-21835)

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Sound). Supported versions that are affected are Oracle Java SE: 8u351, 8u351-perf, 11.0.17, 17.0.5, 19.0.1; Oracle GraalVM Enterprise Edition: 20.3.8, 21.3.4 and 22.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. (CVE-2023-21843)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the January 2023 Oracle Critical Patch Update advisory.
Risk Factor
Medium
CVSS v3.0 Base Score
5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
CVSS v3.0 Temporal Score
4.6 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
1.4
EPSS Score
0.0009
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N)
CVSS v2.0 Temporal Score
3.7 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-21830
CVE CVE-2023-21835
CVE CVE-2023-21843
XREF IAVA:2023-A-0042
Plugin Information
Published: 2023/01/19, Modified: 2023/01/23
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre1.8.0_161\
Installed version : 8.0.161.12 / build 8.0.161
Fixed version : Upgrade to version 8.0.361 or greater
214532 - Oracle Java SE Multiple Vulnerabilities (January 2025 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities
Description
The 8u431, 11.0.26, 17.0.14, 20.3.16, 21.0.5, 21.3.12, 23.0.2, and perf versions of Java installed on the remote host are affected by multiple vulnerabilities as referenced in the January 2025 CPU advisory.

- Vulnerability in Oracle Java SE (component: Install (Sparkle)). The supported version that is affected is Oracle Java SE: 8u431. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Java SE executes to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Java SE, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Java SE. Note: Only applies to the macOS autoupdater. (CVE-2025-0509)

- Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u431-perf, 11.0.26, 17.0.14, 21.0.5, 23.0.2; Oracle GraalVM for JDK: 17.0.14, 21.0.5, 23.0.2; Oracle GraalVM Enterprise Edition: 20.3.16 and 21.3.12. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. (CVE-2025-21502)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the January 2025 Oracle Critical Patch Update advisory.
Risk Factor
High
CVSS v3.0 Base Score
6.8 (CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
5.9 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.0003
CVSS v2.0 Base Score
7.2 (CVSS2#AV:A/AC:L/Au:M/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-0509
CVE CVE-2025-21502
XREF IAVA:2025-A-0049-S
Plugin Information
Published: 2025/01/23, Modified: 2025/08/06
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre1.8.0_161\
Installed version : 8.0.161.12 / build 8.0.161
Fixed version : Upgrade to version 8.0.441 or greater
202704 - Oracle Java SE Multiple Vulnerabilities (July2024 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities.
Description
The version of Oracle (formerly Sun) Java SE or Java for Business installed on the remote host is affected by multiple vulnerabilities as referenced in the July 2024 CPU advisory:

- Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM Enterprise Edition: 20.3.14 and 21.3.10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. (CVE-2024-21147)

- Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM Enterprise Edition: 20.3.14 and 21.3.10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. (CVE-2024-21145)

- Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM Enterprise Edition: 20.3.14 and 21.3.10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. (CVE-2024-21140)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the July 2024 Oracle Critical Patch Update advisory.
Risk Factor
High
CVSS v3.0 Base Score
4.8 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)
CVSS v3.0 Temporal Score
4.2 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.0
EPSS Score
0.0019
CVSS v2.0 Base Score
7.1 (CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:N)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2024/07/19, Modified: 2025/06/18
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre1.8.0_161\
Installed version : 8.0.161.12 / build 8.0.161
Fixed version : Upgrade to version 8.0.421 or greater
166316 - Oracle Java SE Multiple Vulnerabilities (October 2022 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities.
Description
The version of Oracle (formerly Sun) Java SE or Java for Business installed on the remote host is affected by multiple vulnerabilities as referenced in the October 2022 CPU advisory:

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JGSS). Supported versions that are affected are Oracle Java SE: 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 21.3.3 and 22.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. (CVE-2022-21618)

- VVulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JNDI). Supported versions that are affected are Oracle Java SE: 8u341, 8u345-perf, 11.0.16.1, 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. (CVE-2022-21624)

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u341, 8u345-perf, 11.0.16.1; Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. (CVE-2022-21626)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the October 2022 Oracle Critical Patch Update advisory.
Risk Factor
Medium
CVSS v3.0 Base Score
5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
CVSS v3.0 Temporal Score
4.9 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
2.2
EPSS Score
0.0021
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N)
CVSS v2.0 Temporal Score
4.1 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2022/10/20, Modified: 2023/10/09
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre1.8.0_161\
Installed version : 8.0.161.12 / build 8.0.161
Fixed version : Upgrade to version 8.0.351 or greater

51192 - SSL Certificate Cannot Be Trusted
-
Synopsis
The SSL certificate for this service cannot be trusted.
Description
The server's X.509 certificate cannot be trusted. This situation can occur in three different ways, in which the chain of trust can be broken, as stated below :

- First, the top of the certificate chain sent by the server might not be descended from a known public certificate authority. This can occur either when the top of the chain is an unrecognized, self-signed certificate, or when intermediate certificates are missing that would connect the top of the certificate chain to a known public certificate authority.

- Second, the certificate chain may contain a certificate that is not valid at the time of the scan. This can occur either when the scan occurs before one of the certificate's 'notBefore' dates, or after one of the certificate's 'notAfter' dates.

- Third, the certificate chain may contain a signature that either didn't match the certificate's information or could not be verified. Bad signatures can be fixed by getting the certificate with the bad signature to be re-signed by its issuer. Signatures that could not be verified are the result of the certificate's issuer using a signing algorithm that Nessus either does not support or does not recognize.

If the remote host is a public host in production, any break in the chain makes it more difficult for users to verify the authenticity and identity of the web server. This could make it easier to carry out man-in-the-middle attacks against the remote host.
See Also
Solution
Purchase or generate a proper SSL certificate for this service.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
CVSS v2.0 Base Score
6.4 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N)
Plugin Information
Published: 2010/12/15, Modified: 2025/06/16
Plugin Output

tcp/3389/msrdp


The following certificate was at the top of the certificate
chain sent by the remote host, but it is signed by an unknown
certificate authority :

|-Subject : CN=LiveTechRobo
|-Issuer : CN=LiveTechRobo
57582 - SSL Self-Signed Certificate
-
Synopsis
The SSL certificate chain for this service ends in an unrecognized self-signed certificate.
Description
The X.509 certificate chain for this service is not signed by a recognized certificate authority. If the remote host is a public host in production, this nullifies the use of SSL as anyone could establish a man-in-the-middle attack against the remote host.

Note that this plugin does not check for certificate chains that end in a certificate that is not self-signed, but is signed by an unrecognized certificate authority.
Solution
Purchase or generate a proper SSL certificate for this service.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
CVSS v2.0 Base Score
6.4 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N)
Plugin Information
Published: 2012/01/17, Modified: 2022/06/14
Plugin Output

tcp/3389/msrdp


The following certificate was found at the top of the certificate
chain sent by the remote host, but is self-signed and was not
found in the list of known certificate authorities :

|-Subject : CN=LiveTechRobo

238078 - Security Updates for Outlook (June 2025)
-
Synopsis
The Microsoft Outlook application installed on the remote host is missing a security update.
Description
The Microsoft Outlook application installed on the remote host is missing a security update. It is, therefore, affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5002683 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
6.7 (CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0007
CVSS v2.0 Base Score
6.0 (CVSS2#AV:L/AC:H/Au:S/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-47171
MSKB 5002683
XREF MSFT:MS25-5002683
XREF IAVA:2025-A-0415-S
XREF CWE:20
Plugin Information
Published: 2025/06/10, Modified: 2025/09/17
Plugin Output

tcp/445/cifs



Product : Outlook 2016
- C:\Program Files\Microsoft Office\Office16\Outlook.exe has not been patched.
Remote version : 16.0.5483.1000
Fixed version : 16.0.5504.1000

104743 - TLS Version 1.0 Protocol Detection
-
Synopsis
The remote service encrypts traffic using an older version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.0. TLS 1.0 has a number of cryptographic design flaws. Modern implementations of TLS 1.0 mitigate these problems, but newer versions of TLS like 1.2 and 1.3 are designed against these flaws and should be used whenever possible.

As of March 31, 2020, Endpoints that aren’t enabled for TLS 1.2 and higher will no longer function properly with major web browsers and major vendors.

PCI DSS v3.2 requires that TLS 1.0 be disabled entirely by June 30, 2018, except for POS POI terminals (and the SSL/TLS termination points to which they connect) that can be verified as not being susceptible to any known exploits.
See Also
Solution
Enable support for TLS 1.2 and 1.3, and disable support for TLS 1.0.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N)
CVSS v2.0 Base Score
6.1 (CVSS2#AV:N/AC:H/Au:N/C:C/I:P/A:N)
References
XREF CWE:327
Plugin Information
Published: 2017/11/22, Modified: 2023/04/19
Plugin Output

tcp/3389/msrdp

TLSv1 is enabled and the server supports at least one cipher.
157288 - TLS Version 1.1 Deprecated Protocol
-
Synopsis
The remote service encrypts traffic using an older version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.1. TLS 1.1 lacks support for current and recommended cipher suites. Ciphers that support encryption before MAC computation, and authenticated encryption modes such as GCM cannot be used with TLS 1.1

As of March 31, 2020, Endpoints that are not enabled for TLS 1.2 and higher will no longer function properly with major web browsers and major vendors.
See Also
Solution
Enable support for TLS 1.2 and/or 1.3, and disable support for TLS 1.1.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N)
CVSS v2.0 Base Score
6.1 (CVSS2#AV:N/AC:H/Au:N/C:C/I:P/A:N)
References
XREF CWE:327
Plugin Information
Published: 2022/04/04, Modified: 2024/05/14
Plugin Output

tcp/3389/msrdp

TLSv1.1 is enabled and the server supports at least one cipher.

236832 - VMware Tools 11.x / 12.x < 12.5.2 Insecure File Handling (VMSA-2025-0007)
-
Synopsis
The virtualization tool suite is installed on the remote host is affected by an insecure file handling vulnerability.
Description
The version of VMware Tools installed on the remote host is 11.x or 12.x prior to 12.5.2. It is, therefore, affected by an insecure file handling vulnerability:

- VMware Tools contains an insecure file handling vulnerability. A malicious actor with non-administrative privileges on a guest VM may tamper the local files to trigger insecure file operations within that VM. (CVE-2025-22247)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to VMware Tools version 12.5.2 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
6.1 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N)
VPR Score
5.0
EPSS Score
0.0001
CVSS v2.0 Base Score
5.2 (CVSS2#AV:L/AC:L/Au:S/C:P/I:C/A:N)
STIG Severity
I
References
CVE CVE-2025-22247
XREF VMSA:2025-0007
XREF IAVA:2025-A-0324-S
Plugin Information
Published: 2025/05/16, Modified: 2025/10/02
Plugin Output

tcp/445/cifs


Path : C:\Program Files\VMware\VMware Tools\
Installed version : 12.3.5.46049
Fixed version : 12.5.2
247827 - VMware Tools 11.x / 12.x < 12.5.3 / 13.x < 13.0.1.0 vSockets Information Disclosure (VMSA-2025-0013)
-
Synopsis
The virtualization tool suite is installed on the remote Windows host is affected by an information disclosure vulnerability.
Description
The version of VMware Tools installed on the remote Windows host is 11.x, 12.x prior to 12.5.3, or 13.x prior to 13.0.1.0. It is, therefore, affected by an information disclosure vulnerbility:

- VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of an uninitialised memory in vSockets. A malicious actor with local administrative privileges on a virtual machine may be able to exploit this issue to leak memory from processes communicating with vSockets. (CVE-2025-41239)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to VMware Tools version 12.5.3 or 13.0.1.0 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
6.2 (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
VPR Score
4.4
EPSS Score
0.0001
CVSS v2.0 Base Score
4.9 (CVSS2#AV:L/AC:L/Au:N/C:C/I:N/A:N)
References
CVE CVE-2025-41239
XREF VMSA:2025-0013
Plugin Information
Published: 2025/08/11, Modified: 2025/08/11
Plugin Output

tcp/445/cifs


Path : C:\Program Files\VMware\VMware Tools\
Installed version : 12.3.5.46049
Fixed version : 12.5.3
234002 - WinRAR < 7.11 Mark of the Web Bypass (CVE-2025-31334)
-
Synopsis
The remote Windows host has an application installed which is affected by a mark of the web bypass vulnerability.
Description
The remote host is running WinRAR, an archive manager for Windows, whose reported version is prior to 7.11. It is, therefore, affected by a vulnerability:

- Issue that bypasses the 'Mark of the Web' security warning function for files when opening a symbolic link that points to an executable file exists in WinRAR versions prior to 7.11. If a symbolic link specially crafted by an attacker is opened on the affected product, arbitrary code may be executed. (CVE-2025-31334)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to WinRAR version 7.11 or later.
Risk Factor
High
CVSS v3.0 Base Score
6.8 (CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0007
CVSS v2.0 Base Score
8.5 (CVSS2#AV:N/AC:M/Au:S/C:C/I:C/A:C)
STIG Severity
II
References
CVE CVE-2025-31334
XREF IAVA:2025-A-0227
Plugin Information
Published: 2025/04/08, Modified: 2025/04/11
Plugin Output

tcp/445/cifs


Path : C:\Program Files\WinRAR\WinRAR.exe
Installed version : 5.90.0.0
Fixed version : 7.11
249179 - 7-Zip < 25.01
-
Synopsis
The remote host is missing a security update.
Description
The version of 7-Zip installed on the remote host is prior to 25.01. It is, therefore, affected by a security bypass vulnerability. The code for handling symbolic links has been changed to provide greater security when extracting files from archives. Command line switch -snld20 can be used to bypass default security checks when creating symbolic links.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to 7-Zip version 25.01 or later.
Risk Factor
Low
CVSS v3.0 Base Score
3.6 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N)
VPR Score
3.2
EPSS Score
0.0001
CVSS v2.0 Base Score
2.1 (CVSS2#AV:L/AC:L/Au:N/C:N/I:P/A:N)
STIG Severity
I
References
CVE CVE-2025-55188
XREF IAVA:2025-A-0572
Plugin Information
Published: 2025/08/13, Modified: 2025/08/15
Plugin Output

tcp/445/cifs


Path : C:\Program Files\7-Zip
Installed version : 19.0.0.0
Fixed version : 25.01

10114 - ICMP Timestamp Request Remote Date Disclosure
-
Synopsis
It is possible to determine the exact time set on the remote host.
Description
The remote host answers to an ICMP timestamp request. This allows an attacker to know the date that is set on the targeted machine, which may assist an unauthenticated, remote attacker in defeating time-based authentication protocols.

Timestamps returned from machines running Windows Vista / 7 / 2008 / 2008 R2 are deliberately incorrect, but usually within 1000 seconds of the actual system time.
Solution
Filter out the ICMP timestamp requests (13), and the outgoing ICMP timestamp replies (14).
Risk Factor
Low
VPR Score
2.2
EPSS Score
0.0037
CVSS v2.0 Base Score
2.1 (CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:N)
References
Plugin Information
Published: 1999/08/01, Modified: 2024/10/07
Plugin Output

icmp/0

This host returns non-standard timestamps (high bit is set)
The ICMP timestamps might be in little endian format (not in network format)
The remote clock is synchronized with the local clock.

192814 - Microsoft Windows 10 22H2 SEoL
-
Synopsis
An unsupported version of Microsoft Windows is installed on the remote host.
Description
Microsoft Windows 10 22H2 is no longer maintained by its vendor or provider.

Lack of support implies that no new security patches for the product will be released by the vendor. As a result, it may contain security vulnerabilities.
See Also
Solution
Upgrade to a version of Microsoft Windows that is currently supported.
Risk Factor
Low
Plugin Information
Published: 2024/04/02, Modified: 2025/12/22
Plugin Output

tcp/0


OS : Microsoft Windows 10 22H2
Security End of Life : October 13, 2025
Time since Security End of Life (Est.) : >= 1 month
213851 - Mozilla Firefox SEoL (134.x)
-
Synopsis
An unsupported version of Mozilla Firefox is installed on the remote host.
Description
According to its version, Mozilla Firefox version install on the remote host has reached end of support. It is, therefore, no longer maintained by its vendor or provider.

Lack of support implies that no new security patches for the product will be released by the vendor. As a result, it may contain security vulnerabilities.
See Also
Solution
Upgrade to a version of Mozilla Firefox that is currently supported.
Risk Factor
Low
Plugin Information
Published: 2025/01/10, Modified: 2025/01/10
Plugin Output

tcp/0


Path : C:\Program Files\Mozilla Firefox
Installed version : 134.0
Security End of Life : February 4, 2025
Time since Security End of Life (Est.) : >= 6 months

152020 - Oracle Java SE 1.7.0_311 / 1.8.0_301 / 1.11.0_12 / 1.16.0_2 Multiple Vulnerabilities (July 2021 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities.
Description
The version of Oracle (formerly Sun) Java SE or Java for Business installed on the remote host is prior to 7 Update 301, 8 Update 291, 11 Update 11, or 16 Update 1. It is, therefore, affected by multiple vulnerabilities as referenced in the July 2021 CPU advisory:

- Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u301, 8u291, 11.0.11, 16.0.1; Oracle GraalVM Enterprise Edition: 20.3.2 and 21.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Oracle GraalVM Enterprise Edition accessible data. This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). (CVE-2021-2341)

- Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Library). Supported versions that are affected are Java SE: 7u301, 8u291, 11.0.11, 16.0.1; Oracle GraalVM Enterprise Edition: 20.3.2 and 21.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Oracle GraalVM Enterprise Edition accessible data. This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). (CVE-2021-2369)

- Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 8u291, 11.0.11, 16.0.1; Oracle GraalVM Enterprise Edition: 20.3.2 and 21.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Java SE, Oracle GraalVM Enterprise Edition. This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). (CVE-2021-2388)

- Vulnerability in the Java SE product of Oracle Java SE (component: JNDI). The supported version that is affected is Java SE: 7u301. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE. This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. (CVE-2021-2432)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the July 2021 Oracle Critical Patch Update advisory.
Risk Factor
Medium
CVSS v3.0 Base Score
3.7 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)
CVSS v3.0 Temporal Score
3.5 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.006
CVSS v2.0 Base Score
5.1 (CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
4.2 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-2341
CVE CVE-2021-2369
CVE CVE-2021-2388
CVE CVE-2021-2432
XREF IAVA:2021-A-0327-S
Plugin Information
Published: 2021/07/23, Modified: 2025/05/28
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre1.8.0_161\
Installed version : 8.0.161.12 / build 8.0.161
Fixed version : Upgrade to version 8.0.301 or greater
121231 - Oracle Java SE 1.7.x < 1.7.0_211 / 1.8.x < 1.8.0_201 / 1.11.x < 1.11.0_2 Multiple Vulnerabilities (January 2019 CPU)
-
Synopsis
The remote Windows host contains a programming platform that is affected by multiple vulnerabilities.
Description
The version of Oracle (formerly Sun) Java SE or Java for Business installed on the remote host is prior to 7 Update 211, 8 Update 201, 11 Update 2. It is, therefore, affected by multiple vulnerabilities related to the following components :

- An issue in libjpeg 9a, a divide-by-zero error, could allow remote attackers to cause a denial of service condition via a crafted file. (CVE-2018-11212)

- An unspecified vulnerability in Oracle Java SE in the Networking subcomponent could allow an unauthenticated, remote attacker with network access via multiple protocols to compromise Java SE.
(CVE-2019-2426)

- An unspecified vulnerability in Oracle Java SE in the Deployment subcomponent could allow an unauthenticated, remote attacker with network access via multiple protocols to compromise Java SE.
(CVE-2019-2449)

- An unspecified vulnerability in Oracle Java SE in the Libraries subcomponent could allow an unauthenticated, remote attacker with network access via multiple protocols to compromise Java SE.
(CVE-2019-2422)

Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Oracle JDK / JRE 11 Update 2, 8 Update 201 / 7 Update 211 or later. If necessary, remove any affected versions.
Risk Factor
Medium
CVSS v3.0 Base Score
3.7 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
CVSS v3.0 Temporal Score
3.4 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0346
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
3.4 (CVSS2#E:POC/RL:OF/RC:C)
References
BID 106583
BID 106590
BID 106596
BID 106597
CVE CVE-2018-11212
CVE CVE-2019-2422
CVE CVE-2019-2426
CVE CVE-2019-2449
Plugin Information
Published: 2019/01/17, Modified: 2024/12/20
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre1.8.0_161\
Installed version : 8.0.161.12 / build 8.0.161
Fixed version : Upgrade to version 8.0.201 or greater
183295 - Oracle Java SE Multiple Vulnerabilities (October 2023 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities.
Description
The version of Oracle (formerly Sun) Java SE or Java for Business installed on the remote host is affected by multiple vulnerabilities as referenced in the October 2023 CPU advisory:

- Vulnerability in Oracle Java SE (component: CORBA). Supported versions that are affected are Oracle Java SE: 8u381 and 8u381-perf. Easily exploitable vulnerability allows unauthenticated attacker with network access via CORBA to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data. (CVE-2023-22067)

- Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u381, 8u381-perf, 11.0.20, 17.0.8, 20.0.2; Oracle GraalVM for JDK: 17.0.8 and 20.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Java SE, Oracle GraalVM for JDK. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK. (CVE-2023-22081)

- CVE-2023-22025Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u381-perf, 17.0.8, 20.0.2; Oracle GraalVM for JDK: 17.0.8 and 20.0.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK accessible data. (CVE-2023-22025)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the October 2023 Oracle Critical Patch Update advisory.
Risk Factor
Medium
CVSS v3.0 Base Score
3.7 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
CVSS v3.0 Temporal Score
3.2 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
1.4
EPSS Score
0.0018
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N)
CVSS v2.0 Temporal Score
3.7 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-22067
CVE CVE-2023-22081
CVE CVE-2023-22025
XREF IAVA:2023-A-0561
Plugin Information
Published: 2023/10/18, Modified: 2025/06/13
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre1.8.0_161\
Installed version : 8.0.161.12 / build 8.0.161
Fixed version : Upgrade to version 8.0.391 or greater
91231 - 7-Zip Installed
-
Synopsis
A compression utility is installed on the remote Windows host.
Description
7-Zip, a compressed archive manager, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0734
Plugin Information
Published: 2016/05/19, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Path : C:\Program Files\7-Zip
Version : 19.0.0.0

92413 - 7-Zip Recent Files
-
Synopsis
Nessus was able to enumerate recently accessed 7-Zip compressed files on the remote host.
Description
Nessus was able to query 7-Zip settings on the remote Windows host to find recently accessed compressed files.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

Techrobot
- D:\Techexcel.zip\
46180 - Additional DNS Hostnames
-
Synopsis
Nessus has detected potential virtual hosts.
Description
Hostnames different from the current hostname have been collected by miscellaneous plugins. Nessus has generated a list of hostnames that point to the remote host. Note that these are only the alternate hostnames for vhosts discovered on a web server.

Different web servers may be hosted on name-based virtual hosts.
See Also
Solution
If you want to test them, re-scan using the special vhost syntax, such as :

www.example.com[192.0.32.10]
Risk Factor
None
Plugin Information
Published: 2010/04/29, Modified: 2022/08/15
Plugin Output

tcp/0

The following hostnames point to the remote host :
- livetechrobo

16193 - Antivirus Software Check
-
Synopsis
An antivirus application is installed on the remote host.
Description
An antivirus application is installed on the remote host, and its engine and virus definitions are up to date.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2005/01/18, Modified: 2025/05/27
Plugin Output

tcp/445/cifs


Kaspersky :
Kaspersky Anti-Virus is installed on the remote host :

Product name : Kaspersky Endpoint Security for Windows
Version : 21.15.8.493
Installation path : C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0
Virus signatures : 01/14/2026

130590 - Apache Tomcat Installed (Windows)
-
Synopsis
Apache Tomcat is installed on the remote Windows host.
Description
Apache Tomcat, a web server, was found on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0535
Plugin Information
Published: 2019/11/06, Modified: 2025/12/18
Plugin Output

tcp/0


Path : D:\Techexcel\Lucee\tomcat\bin\Tomcat9.exe
Version : unknown
Product : Apache Tomcat
92415 - Application Compatibility Cache
-
Synopsis
Nessus was able to gather application compatibility settings on the remote host.
Description
Nessus was able to generate a report on the application compatibility cache on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

Application compatibility cache report attached.
34097 - BIOS Info (SMB)
-
Synopsis
BIOS info could be read.
Description
It is possible to get information about the BIOS via the host's SMB interface.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/08, Modified: 2024/06/11
Plugin Output

tcp/0


Version : 6.00
Release date : 20201112000000.000000+000
Secure boot : disabled
34096 - BIOS Info (WMI)
-
Synopsis
The BIOS info could be read.
Description
It is possible to get information about the BIOS via the host's WMI interface.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/05, Modified: 2025/12/15
Plugin Output

tcp/0


Vendor : Phoenix Technologies LTD
Version : 6.00
Release date : 20201112000000.000000+000
UUID : EE134D56-E4BC-9FFD-8340-6DD9E25CEDCC
Secure boot : disabled
92416 - BagMRU Folder History
-
Synopsis
Nessus was able to enumerate folders that were opened in Windows Explorer.
Description
Nessus was able to enumerate folders that were opened in Windows Explorer. Microsoft Windows maintains folder settings using a registry key known as shellbags or BagMRU. The generated folder list report contains folders local to the system, folders from past mounted network drives, and folders from mounted devices.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

BagMRU report attached.

42799 - Broken Web Servers
-
Synopsis
Tests on this web server have been disabled.
Description
The remote web server seems password protected or misconfigured. Further tests on it were disabled so that the whole scan is not slowed down.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/11/13, Modified: 2011/08/17
Plugin Output

tcp/2323/www


This web server was declared broken by :
web_config_is_remotely_accessible.nasl
for the following reason :
The web server failed to respond at least 20 times for 463 s.

42799 - Broken Web Servers
-
Synopsis
Tests on this web server have been disabled.
Description
The remote web server seems password protected or misconfigured. Further tests on it were disabled so that the whole scan is not slowed down.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/11/13, Modified: 2011/08/17
Plugin Output

tcp/5357/www


This web server was declared broken by :
httpver.nasl
for the following reason :
The web server returns 503 when / is requested.

42799 - Broken Web Servers
-
Synopsis
Tests on this web server have been disabled.
Description
The remote web server seems password protected or misconfigured. Further tests on it were disabled so that the whole scan is not slowed down.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/11/13, Modified: 2011/08/17
Plugin Output

tcp/5800/www


This web server was declared broken by :
jira_cve-2021-26086.nbin
for the following reason :
The web server failed to respond at least 20 times for 374 s.

96533 - Chrome Browser Extension Enumeration
-
Synopsis
One or more Chrome browser extensions are installed on the remote host.
Description
Nessus was able to enumerate Chrome browser extensions installed on the remote host.
See Also
Solution
Make sure that the use and configuration of these extensions comply with your organization's acceptable use and security policies.
Risk Factor
None
References
XREF IAVT:0001-T-0511
Plugin Information
Published: 2017/01/16, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


User : Administrator
|- Browser : Chrome
|- Add-on information :

Name : YouTube
Version : 4.2.8
Update Date : Jan. 15, 2026 at 10:34:45 GMT
Path : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0

Name : Google Docs Offline
Description : Edit, create, and view your documents, spreadsheets, and presentations — all without internet access.
Version : 1.42.0
Update Date : Jan. 15, 2026 at 10:34:46 GMT
Path : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.42.0_0

Name : Chrome Web Store Payments
Description : Chrome Web Store Payments
Version : 1.0.0.6
Update Date : Jan. 15, 2026 at 10:34:46 GMT
Path : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0

User : Techexcel
|- Browser : Chrome
|- Add-on information :

Name : Google Docs Offline
Description : Edit, create, and view your documents, spreadsheets, and presentations — all without internet access.
Version : 1.53.0
Update Date : Jan. 15, 2026 at 10:36:13 GMT
Path : C:\Users\Techexcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.53.0_0

Name : Chrome Web Store Payments
Description : Chrome Web Store Payments
Version : 1.0.0.6
Update Date : Jan. 15, 2026 at 10:36:14 GMT
Path : C:\Users\Techexcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0

User : Techrobot
|- Browser : Chrome
|- Add-on information :

Name : Google Docs Offline
Description : Edit, create, and view your documents, spreadsheets, and presentations — all without internet access.
Version : 1.100.1
Update Date : Jan. 16, 2026 at 09:33:42 GMT
Path : C:\Users\Techrobot\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.100.1_0

Name : Cegid Peoplenet ClickOnce launcher
Description : This extension enables ClickOnce apps in Google Chrome.
Version : 2.0
Update Date : Jan. 16, 2026 at 09:33:42 GMT
Path : C:\Users\Techrobot\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkncabbipkgbconhaajbapbhokpbgkdc\2.0_0

Name : UiPath Browser Automation 23.4
Description : Expands your browser automation capabilities from Studio desktop.
Version : 23.4.2
Update Date : Jan. 16, 2026 at 09:33:42 GMT
Path : C:\Users\Techrobot\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmejkhcmhgilmppjodlgaklnmdmmhhcl\23.4.2_0

Name : Chrome Web Store Payments
Description : Chrome Web Store Payments
Version : 1.0.0.6
Update Date : Jan. 16, 2026 at 09:33:42 GMT
Path : C:\Users\Techrobot\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0

45590 - Common Platform Enumeration (CPE)
-
Synopsis
It was possible to enumerate CPE names that matched on the remote system.
Description
By using information obtained from a Nessus scan, this plugin reports CPE (Common Platform Enumeration) matches for various hardware and software products found on a host.

Note that if an official CPE is not available for the product, this plugin computes the best possible CPE based on the information available from the scan.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/04/21, Modified: 2025/09/29
Plugin Output

tcp/0


The remote operating system matched the following CPE :

cpe:/o:microsoft:windows_10_22h2:10.0.19045.5965:-:~~pro~~x64~ -> Microsoft Windows 10 22h2

Following application CPE's matched on the remote system :

cpe:/a:7-zip:7-zip:19.0.0.0 -> 7-Zip -
cpe:/a:apache:tomcat -> Apache Software Foundation Tomcat
cpe:/a:google:chrome:143.0.7499.193 -> Google Chrome
cpe:/a:haxx:curl:8.9.1.0 -> Haxx Curl
cpe:/a:kaspersky:kaspersky_anti-virus:21.15.8.493 -> Kaspersky Anti-virus
cpe:/a:microsoft:.net_framework:2.0.50727 -> Microsoft .NET Framework
cpe:/a:microsoft:.net_framework:3.0 -> Microsoft .NET Framework
cpe:/a:microsoft:.net_framework:3.0.6920.9163 -> Microsoft .NET Framework
cpe:/a:microsoft:.net_framework:3.5 -> Microsoft .NET Framework
cpe:/a:microsoft:.net_framework:4.8.1 -> Microsoft .NET Framework
cpe:/a:microsoft:.net_framework:4.8.9290.0 -> Microsoft .NET Framework
cpe:/a:microsoft:excel:16.0.5495.1000:0 -> Microsoft Excel
cpe:/a:microsoft:excelcnv:16.0.5495.1000:0
cpe:/a:microsoft:groove:16.0.4723.1000:0 -> Microsoft Groove
cpe:/a:microsoft:ie:11.3636.19041.0 -> Microsoft Internet Explorer
cpe:/a:microsoft:internet_explorer:11.0.19041.5915 -> Microsoft Internet Explorer
cpe:/a:microsoft:office:2016:0 -> Microsoft Office
cpe:/a:microsoft:office_compatibility_pack -> Microsoft Office Compatibility Pack Service Pack 2
cpe:/a:microsoft:office_compatibility_pack:16.0.4266.1001 -> Microsoft Office Compatibility Pack Service Pack 2
cpe:/a:microsoft:office_compatibility_pack:16.0.5495.1000 -> Microsoft Office Compatibility Pack Service Pack 2
cpe:/a:microsoft:onedrive:23.194.917.1 -> Microsoft OneDrive
cpe:/a:microsoft:onedrive:23.23.129.2 -> Microsoft OneDrive
cpe:/a:microsoft:onedrive:25.222.1112.2 -> Microsoft OneDrive
cpe:/a:microsoft:onedrive:25.224.1116.3 -> Microsoft OneDrive
cpe:/a:microsoft:onedrive:25.238.1204.1 -> Microsoft OneDrive
cpe:/a:microsoft:onenote:16.0.5472.1000 -> Microsoft OneNote
cpe:/a:microsoft:onenote:16.0.5472.1000:0 -> Microsoft OneNote
cpe:/a:microsoft:outlook:16.0.5483.1000:0 -> Microsoft Outlook
cpe:/a:microsoft:powerpoint:16.0.5483.1000:0 -> Microsoft PowerPoint
cpe:/a:microsoft:publisher:16.0.5460.1000:0 -> Microsoft Publisher
cpe:/a:microsoft:remote_desktop_connection:10.0.19041.5965 -> Microsoft Remote Desktop Connection
cpe:/a:microsoft:silverlight:5.1.50907.0 -> Microsoft Silverlight
cpe:/a:microsoft:sql_server_management_studio:2019.150.18390.0 -> Microsoft SQL Server Management Studio
cpe:/a:microsoft:visual_studio_tools_for_applications:15.0.27520
cpe:/a:microsoft:windows_defender:4.18.2203.5 -> Microsoft Windows Defender
cpe:/a:microsoft:word:16.0.5495.1002:0 -> Microsoft Word
cpe:/a:microsoft:wordcnv:16.0.4266.1001:0
cpe:/a:mozilla:firefox:134.0 -> Mozilla Firefox
cpe:/a:mozilla:firefox:134.0.0 -> Mozilla Firefox
cpe:/a:notepad-plus-plus:notepad%2b%2b:6.9.0.0 -> notepad-plus-plus Notepad++
cpe:/a:oracle:jre:8.0.161 -> Oracle JRE
cpe:/a:oracle:jre:8.0.161.12 -> Oracle JRE
cpe:/a:rarlab:winrar:5.90.0.0 -> RARLAB WinRAR
cpe:/a:smartbedded:meteobridge_firmware
cpe:/a:vmware:tools:12.3.5.46049 -> VMWare Tools
x-cpe:/a:microsoft:azure_data_studio:1.32.0.0
x-cpe:/a:microsoft:odbc_driver_for_sql_server:17.10.6.1
x-cpe:/a:microsoft:ole_db_driver_for_sql_server:18.7.4.0
24270 - Computer Manufacturer Information (WMI)
-
Synopsis
It is possible to obtain the name of the remote computer manufacturer.
Description
By making certain WMI queries, it is possible to obtain the model of the remote computer as well as the name of its manufacturer and its serial number.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/02/02, Modified: 2025/12/15
Plugin Output

tcp/0


Computer Manufacturer : VMware, Inc.
Computer Model : VMware Virtual Platform
Computer SerialNumber : VMware-56 4d 13 ee bc e4 fd 9f-83 40 6d d9 e2 5c ed cc
Computer Type : Other

Computer Physical CPU's : 2
Computer Logical CPU's : 8
CPU0
Architecture : x64
Physical Cores: 4
Logical Cores : 4
CPU1
Architecture : x64
Physical Cores: 4
Logical Cores : 4

Computer Memory : 8191 MB
RAM slot #0
Form Factor: DIMM
Type : DRAM
Capacity : 8192 MB
171860 - Curl Installed (Windows)
-
Synopsis
Curl is installed on the remote Windows host.
Description
Curl, a command line tool for transferring data with URLs, was detected on the remote Windows host.

Please note, if the installation is located in either the Windows\System32 or Windows\SysWOW64 directory, it will be considered as managed by the OS. In this case, paranoid scanning is require to trigger downstream vulnerabilty checks. Paranoid scanning has no affect on this plugin itself.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/02/23, Modified: 2025/12/15
Plugin Output

tcp/0


Nessus detected 2 installs of Curl:

Path : c:\windows\system32\curl.exe
Version : 8.9.1.0
Managed by OS : True

Path : c:\windows\syswow64\curl.exe
Version : 8.9.1.0
Managed by OS : True

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/135/epmap


The following DCERPC services are available locally :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 04eeb297-cbf4-466b-8a2a-bfd6a2f10bba, version 1.0
Description : Unknown RPC service
Annotation : EFSK RPC Interface
Type : Local RPC service
Named pipe : LRPC-c061b4a543d309957c

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : df1941c5-fe89-4e79-bf10-463657acf44d, version 1.0
Description : Unknown RPC service
Annotation : EFS RPC Interface
Type : Local RPC service
Named pipe : LRPC-c061b4a543d309957c

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : samss lpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : SidKey Local End Point

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : protected_storage

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsasspirpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsapolicylookup

Object UUID : 6c637067-6569-746e-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : LRPC-c5739097d8610cfc94

Object UUID : 24d1f7c7-76af-4f28-9ccd-7f6cb6468601
UUID : 2eb08e3e-639f-4fba-97b1-14f878961076, version 1.0
Description : Unknown RPC service
Annotation : Group Policy RPC Interface
Type : Local RPC service
Named pipe : LRPC-a8dde0996ac1b8279a

Object UUID : bae10e73-0001-0000-9dab-7d0f635c171a
UUID : 509bc7ae-77be-4ee8-b07c-0d096bb44345, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE511BA5CCDC8E14959581F9623D25

Object UUID : bae10e73-0001-0000-9dab-7d0f635c171a
UUID : 509bc7ae-77be-4ee8-b07c-0d096bb44345, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b854eef76b37e2fdb0

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9435cc56-1d9c-4924-ac7d-b60a2c3520e1, version 1.0
Description : Unknown RPC service
Annotation : SPPSVC Default RPC Interface
Type : Local RPC service
Named pipe : SPPCTransportEndpoint-00001

Object UUID : 3bdb59a0-d736-4d44-9074-c1ee0000000a
UUID : f3f09ffd-fbcf-4291-944d-70ad6e0e73bb, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-0eb170520fca2c29f9

Object UUID : 5252504b-4950-534e-e05f-ee12d83c0000
UUID : 9b3e3722-556d-48ad-4b50-525250494453, version 236.27
Description : Unknown RPC service
Annotation : PRRUniversal#3ECAA87801600B4E:15576
Type : Local RPC service
Named pipe : PRRUniversal#3ECAA87801600B4E:15576

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : d2716e94-25cb-4820-bc15-537866578562, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE385ADF4B5DD6378151BDE8B7CA0E

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : d2716e94-25cb-4820-bc15-537866578562, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-29c075455bd6c681c7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0c53aa2e-fb1c-49c5-bfb6-c54f8e5857cd, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE385ADF4B5DD6378151BDE8B7CA0E

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0c53aa2e-fb1c-49c5-bfb6-c54f8e5857cd, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-29c075455bd6c681c7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 923c9623-db7f-4b34-9e6d-e86580f8ca2a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE385ADF4B5DD6378151BDE8B7CA0E

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 923c9623-db7f-4b34-9e6d-e86580f8ca2a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-29c075455bd6c681c7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e8748f69-a2a4-40df-9366-62dbeb696e26, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE385ADF4B5DD6378151BDE8B7CA0E

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e8748f69-a2a4-40df-9366-62dbeb696e26, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-29c075455bd6c681c7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c8ba73d2-3d55-429c-8e9a-c44f006f69fc, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE385ADF4B5DD6378151BDE8B7CA0E

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c8ba73d2-3d55-429c-8e9a-c44f006f69fc, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-29c075455bd6c681c7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 43890c94-bfd7-4655-ad6a-b4a68397cdcb, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE385ADF4B5DD6378151BDE8B7CA0E

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 43890c94-bfd7-4655-ad6a-b4a68397cdcb, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-29c075455bd6c681c7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a4b8d482-80ce-40d6-934d-b22a01a44fe7, version 1.0
Description : Unknown RPC service
Annotation : LicenseManager
Type : Local RPC service
Named pipe : LicenseServiceEndpoint

Object UUID : 0000000a-0000-0000-0000-000000000000
UUID : 8ec21e98-b5ce-4916-a3d6-449fa428a007, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEA15970D7CDA7C81B4E4E1E821A55

Object UUID : 0000000a-0000-0000-0000-000000000000
UUID : 8ec21e98-b5ce-4916-a3d6-449fa428a007, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-bd978fa79c02b341db

Object UUID : 0000000a-0000-0000-0000-000000000000
UUID : 0fc77b1a-95d8-4a2e-a0c0-cff54237462b, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEA15970D7CDA7C81B4E4E1E821A55

Object UUID : 0000000a-0000-0000-0000-000000000000
UUID : 0fc77b1a-95d8-4a2e-a0c0-cff54237462b, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-bd978fa79c02b341db

Object UUID : 0000000a-0000-0000-0000-000000000000
UUID : b1ef227e-dfa5-421e-82bb-67a6a129c496, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEA15970D7CDA7C81B4E4E1E821A55

Object UUID : 0000000a-0000-0000-0000-000000000000
UUID : b1ef227e-dfa5-421e-82bb-67a6a129c496, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-bd978fa79c02b341db

Object UUID : 5252504b-4950-534e-ce92-53b45c370000
UUID : 9b3e3722-c887-827a-4b50-525250494453, version 229.116
Description : Unknown RPC service
Annotation : PRRUniversal#E030401CD715D291:14172
Type : Local RPC service
Named pipe : PRRUniversal#E030401CD715D291:14172

Object UUID : 9b3e3722-fb3c-0007-4b50-525250524944
UUID : 9b3e3722-d801-7233-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : PR_REMOTE_MANAGER_PROP
Type : Local RPC service
Named pipe : PRRNameService:14172

Object UUID : 9b3e3722-fb3c-0007-4b50-525250524944
UUID : 9b3e3722-d801-7233-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : PR_REMOTE_MANAGER_PROP
Type : Local RPC service
Named pipe : PRRUniversal#E030401CD715D291:14172

Object UUID : 9b3e3722-e72a-000f-4b50-525250524944
UUID : 9b3e3722-e474-f035-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : cpnPRAGUE_REMOTE_API
Type : Local RPC service
Named pipe : PRRNameService:14172

Object UUID : 9b3e3722-e72a-000f-4b50-525250524944
UUID : 9b3e3722-e474-f035-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : cpnPRAGUE_REMOTE_API
Type : Local RPC service
Named pipe : PRRUniversal#E030401CD715D291:14172

Object UUID : 03294b44-0000-0000-ce92-53b45c370000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:14172

Object UUID : 03294b44-0000-0000-ce92-53b45c370000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#E030401CD715D291:14172

Object UUID : b08669ee-8cb5-43a5-a017-84fe0000000a
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WMsgKRpc05BCE1517A

Object UUID : 52ef130c-08fd-4388-86b3-6edf0000000a
UUID : 12e65dd8-887f-41ef-91bf-8d816c42c2e7, version 1.0
Description : Unknown RPC service
Annotation : Secure Desktop LRPC interface
Type : Local RPC service
Named pipe : WMsgKRpc05BCE1517A

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0497b57d-2e66-424f-a0c6-157cd5d41700, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-40f3c3873b7279c09e

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 201ef99a-7fa0-444c-9399-19ba84f12a1a, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-40f3c3873b7279c09e

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5f54ce7d-5b79-4175-8584-cb65313a0e98, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-40f3c3873b7279c09e

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fd7a0523-dc70-43dd-9b2e-9c5ed48225b1, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-40f3c3873b7279c09e

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 58e604e8-9adb-4d2e-a464-3b0683fb1480, version 1.0
Description : Unknown RPC service
Annotation : AppInfo
Type : Local RPC service
Named pipe : LRPC-40f3c3873b7279c09e

Object UUID : 5252504b-4950-534e-669d-ed8954180000
UUID : 9b3e3722-f389-3caf-4b50-525250494453, version 236.27
Description : Unknown RPC service
Annotation : PRRUniversal#B5C9F786273F6C9E:6228
Type : Local RPC service
Named pipe : PRRUniversal#B5C9F786273F6C9E:6228

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3473dd4d-2e88-4006-9cba-22570909dd10, version 5.0
Description : Unknown RPC service
Annotation : WinHttp Auto-Proxy Service
Type : Local RPC service
Named pipe : LRPC-a966b57886cdec5882

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3473dd4d-2e88-4006-9cba-22570909dd10, version 5.0
Description : Unknown RPC service
Annotation : WinHttp Auto-Proxy Service
Type : Local RPC service
Named pipe : 55878e06-1c9c-441e-bcb0-1cab6143cbd9

Object UUID : 5252504b-4950-534e-98b5-06bb842c0000
UUID : 9b3e3722-39c4-20eb-4b50-525250494453, version 229.116
Description : Unknown RPC service
Annotation : PRRUniversal#E6E311364E0319D2:11396
Type : Local RPC service
Named pipe : PRRUniversal#E6E311364E0319D2:11396

Object UUID : 9b3e3722-fb3c-0007-4b50-525250524944
UUID : 9b3e3722-d801-7233-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : PR_REMOTE_MANAGER_PROP
Type : Local RPC service
Named pipe : PRRNameService:11396

Object UUID : 9b3e3722-fb3c-0007-4b50-525250524944
UUID : 9b3e3722-d801-7233-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : PR_REMOTE_MANAGER_PROP
Type : Local RPC service
Named pipe : PRRUniversal#E6E311364E0319D2:11396

Object UUID : 9b3e3722-e72a-000f-4b50-525250524944
UUID : 9b3e3722-e474-f035-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : cpnPRAGUE_REMOTE_API
Type : Local RPC service
Named pipe : PRRNameService:11396

Object UUID : 9b3e3722-e72a-000f-4b50-525250524944
UUID : 9b3e3722-e474-f035-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : cpnPRAGUE_REMOTE_API
Type : Local RPC service
Named pipe : PRRUniversal#E6E311364E0319D2:11396

Object UUID : 0870fd84-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:11396

Object UUID : 0870fd84-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#E6E311364E0319D2:11396

Object UUID : 084cd0a4-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:11396

Object UUID : 084cd0a4-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#E6E311364E0319D2:11396

Object UUID : 073c637c-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:11396

Object UUID : 073c637c-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#E6E311364E0319D2:11396

Object UUID : 104320a4-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:11396

Object UUID : 104320a4-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#E6E311364E0319D2:11396

Object UUID : 0a48cb34-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:11396

Object UUID : 0a48cb34-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#E6E311364E0319D2:11396

Object UUID : 0744312c-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:11396

Object UUID : 0744312c-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#E6E311364E0319D2:11396

Object UUID : 106234d4-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:11396

Object UUID : 106234d4-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#E6E311364E0319D2:11396

Object UUID : 0a7efb7c-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:11396

Object UUID : 0a7efb7c-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#E6E311364E0319D2:11396

Object UUID : 08461e8c-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:11396

Object UUID : 08461e8c-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#E6E311364E0319D2:11396

Object UUID : 073f9584-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:11396

Object UUID : 073f9584-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#E6E311364E0319D2:11396

Object UUID : 0a4554fc-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:11396

Object UUID : 0a4554fc-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#E6E311364E0319D2:11396

Object UUID : 0856c1d4-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:11396

Object UUID : 0856c1d4-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#E6E311364E0319D2:11396

Object UUID : 0a35b80c-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:11396

Object UUID : 0a35b80c-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#E6E311364E0319D2:11396

Object UUID : 0a734634-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:11396

Object UUID : 0a734634-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#E6E311364E0319D2:11396

Object UUID : 073f9f4c-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:11396

Object UUID : 073f9f4c-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#E6E311364E0319D2:11396

Object UUID : 0a720e0c-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:11396

Object UUID : 0a720e0c-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#E6E311364E0319D2:11396

Object UUID : 0a51b96c-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:11396

Object UUID : 0a51b96c-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#E6E311364E0319D2:11396

Object UUID : 0a4addc4-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:11396

Object UUID : 0a4addc4-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#E6E311364E0319D2:11396

Object UUID : 10b73094-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:11396

Object UUID : 10b73094-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#E6E311364E0319D2:11396

Object UUID : 0a83ce44-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:11396

Object UUID : 0a83ce44-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#E6E311364E0319D2:11396

Object UUID : 1063675c-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:11396

Object UUID : 1063675c-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#E6E311364E0319D2:11396

Object UUID : 0a595114-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:11396

Object UUID : 0a595114-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#E6E311364E0319D2:11396

Object UUID : 1040976c-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:11396

Object UUID : 1040976c-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#E6E311364E0319D2:11396

Object UUID : 062d497c-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:11396

Object UUID : 062d497c-0000-0000-98b5-06bb842c0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#E6E311364E0319D2:11396

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : d2716e94-25cb-4820-bc15-537866578562, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEE4208CE89BC5992B0677C6D72685

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : d2716e94-25cb-4820-bc15-537866578562, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-d2a07941dd0cbc26a9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0c53aa2e-fb1c-49c5-bfb6-c54f8e5857cd, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEE4208CE89BC5992B0677C6D72685

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0c53aa2e-fb1c-49c5-bfb6-c54f8e5857cd, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-d2a07941dd0cbc26a9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 923c9623-db7f-4b34-9e6d-e86580f8ca2a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEE4208CE89BC5992B0677C6D72685

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 923c9623-db7f-4b34-9e6d-e86580f8ca2a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-d2a07941dd0cbc26a9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 06bba54a-be05-49f9-b0a0-30f790261023, version 1.0
Description : Unknown RPC service
Annotation : Security Center
Type : Local RPC service
Named pipe : OLE509EC1D941D4FBC491231178E5AC

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 06bba54a-be05-49f9-b0a0-30f790261023, version 1.0
Description : Unknown RPC service
Annotation : Security Center
Type : Local RPC service
Named pipe : LRPC-9f1fa779d21011611b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : be6293d3-2827-4dda-8057-8588240124c9, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-5ca0a66196f10a4d46

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 54b4c689-969a-476f-8dc2-990885e9f562, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-5ca0a66196f10a4d46

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0767a036-0d22-48aa-ba69-b619480f38cb, version 1.0
Description : Unknown RPC service
Annotation : PcaSvc
Type : Local RPC service
Named pipe : LRPC-46336f5e195fb2d8f4

Object UUID : 5252504b-4950-534e-f2c8-32cf68240000
UUID : 9b3e3722-22cb-a121-4b50-525250494453, version 229.116
Description : Unknown RPC service
Annotation : PRRUniversal#FB0F249049038F7C:9320
Type : Local RPC service
Named pipe : PRRUniversal#FB0F249049038F7C:9320

Object UUID : 9b3e3722-fb3c-0007-4b50-525250524944
UUID : 9b3e3722-d801-7233-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : PR_REMOTE_MANAGER_PROP
Type : Local RPC service
Named pipe : PRRNameService:9320

Object UUID : 9b3e3722-fb3c-0007-4b50-525250524944
UUID : 9b3e3722-d801-7233-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : PR_REMOTE_MANAGER_PROP
Type : Local RPC service
Named pipe : PRRUniversal#FB0F249049038F7C:9320

Object UUID : 9b3e3722-e72a-000f-4b50-525250524944
UUID : 9b3e3722-e474-f035-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : cpnPRAGUE_REMOTE_API
Type : Local RPC service
Named pipe : PRRNameService:9320

Object UUID : 9b3e3722-e72a-000f-4b50-525250524944
UUID : 9b3e3722-e474-f035-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : cpnPRAGUE_REMOTE_API
Type : Local RPC service
Named pipe : PRRUniversal#FB0F249049038F7C:9320

Object UUID : 034d6aec-0000-0000-f2c8-32cf68240000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:9320

Object UUID : 034d6aec-0000-0000-f2c8-32cf68240000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#FB0F249049038F7C:9320

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c27f3c08-92ba-478c-b446-b419c4cef0e2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b5987dbb85080b58fb

Object UUID : ccb8aa07-7225-4ea0-8501-4b3c1b1acd43
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEA807EABCA2C8391D15A298381731

Object UUID : ccb8aa07-7225-4ea0-8501-4b3c1b1acd43
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-ad2d46fa1144244b2f

Object UUID : 582a47b2-bcd8-4d3c-8acb-fe09d5bd6eec
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEA807EABCA2C8391D15A298381731

Object UUID : 582a47b2-bcd8-4d3c-8acb-fe09d5bd6eec
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-ad2d46fa1144244b2f

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7df1ceae-de4e-4e6f-ab14-49636e7c2052, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-bfa36c10fd9d0e9249

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : d4051bde-9cdd-4910-b393-4aa85ec3c482, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEEE03AF26DE15FFC4B7F36765EC6F

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : d4051bde-9cdd-4910-b393-4aa85ec3c482, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6326a598951f1ef755

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4c9dbf19-d39e-4bb9-90ee-8f7179b20283, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEEE03AF26DE15FFC4B7F36765EC6F

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4c9dbf19-d39e-4bb9-90ee-8f7179b20283, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6326a598951f1ef755

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fd8be72b-a9cd-4b2c-a9ca-4ded242fbe4d, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEEE03AF26DE15FFC4B7F36765EC6F

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fd8be72b-a9cd-4b2c-a9ca-4ded242fbe4d, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6326a598951f1ef755

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 95095ec8-32ea-4eb0-a3e2-041f97b36168, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEEE03AF26DE15FFC4B7F36765EC6F

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 95095ec8-32ea-4eb0-a3e2-041f97b36168, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6326a598951f1ef755

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e38f5360-8572-473e-b696-1b46873beeab, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEEE03AF26DE15FFC4B7F36765EC6F

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e38f5360-8572-473e-b696-1b46873beeab, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6326a598951f1ef755

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : d22895ef-aff4-42c5-a5b2-b14466d34ab4, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEEE03AF26DE15FFC4B7F36765EC6F

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : d22895ef-aff4-42c5-a5b2-b14466d34ab4, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6326a598951f1ef755

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 98cd761e-e77d-41c8-a3c0-0fb756d90ec2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEEE03AF26DE15FFC4B7F36765EC6F

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 98cd761e-e77d-41c8-a3c0-0fb756d90ec2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6326a598951f1ef755

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1d45e083-478f-437c-9618-3594ced8c235, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEEE03AF26DE15FFC4B7F36765EC6F

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1d45e083-478f-437c-9618-3594ced8c235, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6326a598951f1ef755

Object UUID : 00000001-0000-0000-0000-000000000000
UUID : 8ec21e98-b5ce-4916-a3d6-449fa428a007, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE975AEBA879C05FC1D87D8EDFD2BC

Object UUID : 00000001-0000-0000-0000-000000000000
UUID : 8ec21e98-b5ce-4916-a3d6-449fa428a007, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-21ddfc9bc306bcf5f3

Object UUID : 00000001-0000-0000-0000-000000000000
UUID : 0fc77b1a-95d8-4a2e-a0c0-cff54237462b, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE975AEBA879C05FC1D87D8EDFD2BC

Object UUID : 00000001-0000-0000-0000-000000000000
UUID : 0fc77b1a-95d8-4a2e-a0c0-cff54237462b, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-21ddfc9bc306bcf5f3

Object UUID : 00000001-0000-0000-0000-000000000000
UUID : b1ef227e-dfa5-421e-82bb-67a6a129c496, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE975AEBA879C05FC1D87D8EDFD2BC

Object UUID : 00000001-0000-0000-0000-000000000000
UUID : b1ef227e-dfa5-421e-82bb-67a6a129c496, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-21ddfc9bc306bcf5f3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4b112204-0e19-11d3-b42b-0000f81feb9f, version 1.0
Description : SSDP service
Windows process : unknow
Type : Local RPC service
Named pipe : LRPC-42ae62d992b578aa7e

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 6b5bdd1e-528c-422c-af8c-a4079be4fe48, version 1.0
Description : Unknown RPC service
Annotation : Remote Fw APIs
Type : Local RPC service
Named pipe : ipsec

Object UUID : 9425c9d0-3d54-4ff2-9232-7f6c207950dd
UUID : 906b0ce0-c70b-1067-b317-00dd010662da, version 1.0
Description : Distributed Transaction Coordinator
Windows process : msdtc.exe
Type : Local RPC service
Named pipe : LRPC-c3b3501f62381499e4

Object UUID : d39748e6-bc27-4256-a876-77cbefa877d1
UUID : 906b0ce0-c70b-1067-b317-00dd010662da, version 1.0
Description : Distributed Transaction Coordinator
Windows process : msdtc.exe
Type : Local RPC service
Named pipe : LRPC-c3b3501f62381499e4

Object UUID : 978c3ee2-feb8-4ece-bb23-088e045af4dd
UUID : 906b0ce0-c70b-1067-b317-00dd010662da, version 1.0
Description : Distributed Transaction Coordinator
Windows process : msdtc.exe
Type : Local RPC service
Named pipe : LRPC-c3b3501f62381499e4

Object UUID : 60669149-c33f-47a2-ae4a-6c8f0915e6be
UUID : 906b0ce0-c70b-1067-b317-00dd010662da, version 1.0
Description : Distributed Transaction Coordinator
Windows process : msdtc.exe
Type : Local RPC service
Named pipe : OLE1BC7209B1AFB209B96AFBAA2D23C

Object UUID : 60669149-c33f-47a2-ae4a-6c8f0915e6be
UUID : 906b0ce0-c70b-1067-b317-00dd010662da, version 1.0
Description : Distributed Transaction Coordinator
Windows process : msdtc.exe
Type : Local RPC service
Named pipe : LRPC-1c21845b18a816ae6a

Object UUID : 5252504b-4950-534e-c888-0fcf140e0000
UUID : 9b3e3722-1472-38e0-4b50-525250494453, version 229.116
Description : Unknown RPC service
Annotation : PRRUniversal#FAEBE4664900B1D0:3604
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 9b3e3722-fb3c-0007-4b50-525250524944
UUID : 9b3e3722-d801-7233-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : PR_REMOTE_MANAGER_PROP
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 9b3e3722-fb3c-0007-4b50-525250524944
UUID : 9b3e3722-d801-7233-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : PR_REMOTE_MANAGER_PROP
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 9b3e3722-e72a-000f-4b50-525250524944
UUID : 9b3e3722-e474-f035-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : cpnPRAGUE_REMOTE_API
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 9b3e3722-e72a-000f-4b50-525250524944
UUID : 9b3e3722-e474-f035-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : cpnPRAGUE_REMOTE_API
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 05e80fa0-0000-0000-c888-0fcf140e0000
UUID : 9b3e3722-bab3-e001-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : ai_loader_remote_object
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 05e80fa0-0000-0000-c888-0fcf140e0000
UUID : 9b3e3722-bab3-e001-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : ai_loader_remote_object
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 9b3e3722-abb6-0007-4b50-525250524944
UUID : 9b3e3722-7551-7dee-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : cpTEMPFILE_MEMMANAGER
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 9b3e3722-abb6-0007-4b50-525250524944
UUID : 9b3e3722-7551-7dee-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : cpTEMPFILE_MEMMANAGER
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 00000000-0000-0000-c888-0fcf140e0000
UUID : 9b3e3722-bab3-e001-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : ai_loader_remote_object
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 00000000-0000-0000-c888-0fcf140e0000
UUID : 9b3e3722-bab3-e001-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : ai_loader_remote_object
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 0099e724-0000-0000-c888-0fcf140e0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 0099e724-0000-0000-c888-0fcf140e0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 9b3e3722-8790-000c-4b50-525250524944
UUID : 9b3e3722-1441-c93d-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : cpTASK_MANAGER_TASK_TYPE_NAME
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 9b3e3722-8790-000c-4b50-525250524944
UUID : 9b3e3722-1441-c93d-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : cpTASK_MANAGER_TASK_TYPE_NAME
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 9b3e3722-a517-000d-4b50-525250524944
UUID : 9b3e3722-f9a8-d5cb-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : cpTASK_MANAGER_PROFILE_NAME
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 9b3e3722-a517-000d-4b50-525250524944
UUID : 9b3e3722-f9a8-d5cb-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : cpTASK_MANAGER_PROFILE_NAME
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 9b3e3722-b19c-0002-4b50-525250524944
UUID : 9b3e3722-050c-2b49-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : cpTASK_MANAGER_TASK_ID
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 9b3e3722-b19c-0002-4b50-525250524944
UUID : 9b3e3722-050c-2b49-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : cpTASK_MANAGER_TASK_ID
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 9b3e3722-1931-0005-4b50-525250524944
UUID : 9b3e3722-a39b-5baa-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : npAVS_HTTP_REQ
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 9b3e3722-1931-0005-4b50-525250524944
UUID : 9b3e3722-a39b-5baa-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : npAVS_HTTP_REQ
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 9b3e3722-4d95-0005-4b50-525250524944
UUID : 9b3e3722-f7aa-5ba3-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : npAVS_HTTP_RSP
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 9b3e3722-4d95-0005-4b50-525250524944
UUID : 9b3e3722-f7aa-5ba3-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : npAVS_HTTP_RSP
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 9b3e3722-b87a-0007-4b50-525250524944
UUID : 9b3e3722-86c2-73eb-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : MESSAGE_IS_INCOMING
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 9b3e3722-b87a-0007-4b50-525250524944
UUID : 9b3e3722-86c2-73eb-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : MESSAGE_IS_INCOMING
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 9b3e3722-5916-0003-4b50-525250524944
UUID : 9b3e3722-0276-35b6-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : MESSAGE_CHECK_ONLY
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 9b3e3722-5916-0003-4b50-525250524944
UUID : 9b3e3722-0276-35b6-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : MESSAGE_CHECK_ONLY
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 9b3e3722-20c7-000f-4b50-525250524944
UUID : 9b3e3722-c49b-fe45-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : PROTOCOL_TYPE
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 9b3e3722-20c7-000f-4b50-525250524944
UUID : 9b3e3722-c49b-fe45-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : PROTOCOL_TYPE
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 9b3e3722-c384-0000-4b50-525250524944
UUID : 9b3e3722-6122-0a2a-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : npENGINE_VIRTUAL_OBJECT_NAME
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 9b3e3722-c384-0000-4b50-525250524944
UUID : 9b3e3722-6122-0a2a-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : npENGINE_VIRTUAL_OBJECT_NAME
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 9b3e3722-7401-0008-4b50-525250524944
UUID : 9b3e3722-62c7-816c-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : npUserContext
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 9b3e3722-7401-0008-4b50-525250524944
UUID : 9b3e3722-62c7-816c-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : npUserContext
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 9b3e3722-0568-0001-4b50-525250524944
UUID : 9b3e3722-1d09-1186-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : npAVS_SCAN_AREA_ID
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 9b3e3722-0568-0001-4b50-525250524944
UUID : 9b3e3722-1d09-1186-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : npAVS_SCAN_AREA_ID
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 9b3e3722-618e-000d-4b50-525250524944
UUID : 9b3e3722-7819-d199-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : antimalware.am_core_dll.registered
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 9b3e3722-618e-000d-4b50-525250524944
UUID : 9b3e3722-7819-d199-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : antimalware.am_core_dll.registered
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 9b3e3722-4dfb-000b-4b50-525250524944
UUID : 9b3e3722-56be-b1b4-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : npSCAN_OBJECT_CONTEXT
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 9b3e3722-4dfb-000b-4b50-525250524944
UUID : 9b3e3722-56be-b1b4-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : npSCAN_OBJECT_CONTEXT
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 9b3e3722-5c94-000c-4b50-525250524944
UUID : 9b3e3722-7dc3-c215-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : npENGINE_OBJECT_READONLY_tERROR
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 9b3e3722-5c94-000c-4b50-525250524944
UUID : 9b3e3722-7dc3-c215-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : npENGINE_OBJECT_READONLY_tERROR
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 9b3e3722-66bb-0002-4b50-525250524944
UUID : 9b3e3722-b130-2d78-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : npENGINE_OBJECT_EXECUTABLE_PARENT_IO_hOBJECT
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 9b3e3722-66bb-0002-4b50-525250524944
UUID : 9b3e3722-b130-2d78-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : npENGINE_OBJECT_EXECUTABLE_PARENT_IO_hOBJECT
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 9b3e3722-0726-0007-4b50-525250524944
UUID : 9b3e3722-dfbb-7d89-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : npENGINE_OBJECT_SET_WRITE_ACCESS_tERROR
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 9b3e3722-0726-0007-4b50-525250524944
UUID : 9b3e3722-dfbb-7d89-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : npENGINE_OBJECT_SET_WRITE_ACCESS_tERROR
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 9b3e3722-21ab-0008-4b50-525250524944
UUID : 9b3e3722-da96-8fb3-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : npENGINE_INTEGRAL_PARENT_IO
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 9b3e3722-21ab-0008-4b50-525250524944
UUID : 9b3e3722-da96-8fb3-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : npENGINE_INTEGRAL_PARENT_IO
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 9b3e3722-554f-0006-4b50-525250524944
UUID : 9b3e3722-3fdc-66a9-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : npOBJECT_STARTUP
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 9b3e3722-554f-0006-4b50-525250524944
UUID : 9b3e3722-3fdc-66a9-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : npOBJECT_STARTUP
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 9b3e3722-ae59-0004-4b50-525250524944
UUID : 9b3e3722-49dd-4e78-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : antimalware.oas.PenderPtr
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 9b3e3722-ae59-0004-4b50-525250524944
UUID : 9b3e3722-49dd-4e78-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : antimalware.oas.PenderPtr
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 9b3e3722-e77b-0006-4b50-525250524944
UUID : 9b3e3722-d7d6-630a-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : native file io object is a stream really
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 9b3e3722-e77b-0006-4b50-525250524944
UUID : 9b3e3722-d7d6-630a-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : native file io object is a stream really
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 9b3e3722-54e6-0005-4b50-525250524944
UUID : 9b3e3722-97cf-5c32-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : native file io object streams
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 9b3e3722-54e6-0005-4b50-525250524944
UUID : 9b3e3722-97cf-5c32-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : native file io object streams
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 9b3e3722-c572-000b-4b50-525250524944
UUID : 9b3e3722-7d85-bb8f-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : npTM_PROFILE
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 9b3e3722-c572-000b-4b50-525250524944
UUID : 9b3e3722-7d85-bb8f-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : npTM_PROFILE
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 9b3e3722-2be7-0004-4b50-525250524944
UUID : 9b3e3722-2175-40a9-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : cpTEMPFILE_SYSCACHED
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 9b3e3722-2be7-0004-4b50-525250524944
UUID : 9b3e3722-2175-40a9-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : cpTEMPFILE_SYSCACHED
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 06a8e010-0000-0000-c888-0fcf140e0000
UUID : 9b3e3722-b8eb-3e0b-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : TaskManager
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 06a8e010-0000-0000-c888-0fcf140e0000
UUID : 9b3e3722-b8eb-3e0b-4b50-52524f424a53, version 229.116
Description : Unknown RPC service
Annotation : TaskManager
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 9b3e3722-aa75-0009-4b50-525250524944
UUID : 9b3e3722-b9de-913a-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : DEFER_THREAD_INIT
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 9b3e3722-aa75-0009-4b50-525250524944
UUID : 9b3e3722-b9de-913a-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : DEFER_THREAD_INIT
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 9b3e3722-1e7b-0004-4b50-525250524944
UUID : 9b3e3722-6afd-4748-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : MAILER_PID
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 9b3e3722-1e7b-0004-4b50-525250524944
UUID : 9b3e3722-6afd-4748-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : MAILER_PID
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 9b3e3722-487b-0006-4b50-525250524944
UUID : 9b3e3722-2a49-6623-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : npMESSAGE_IS_COMPLETE
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 9b3e3722-487b-0006-4b50-525250524944
UUID : 9b3e3722-2a49-6623-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : npMESSAGE_IS_COMPLETE
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 9b3e3722-cf60-000f-4b50-525250524944
UUID : 9b3e3722-93c9-f5ca-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : NO_NEED_TREATMENT
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 9b3e3722-cf60-000f-4b50-525250524944
UUID : 9b3e3722-93c9-f5ca-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : NO_NEED_TREATMENT
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 9b3e3722-7820-0006-4b50-525250524944
UUID : 9b3e3722-9839-6e01-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : MAILER_TID
Type : Local RPC service
Named pipe : PRRNameService:3604

Object UUID : 9b3e3722-7820-0006-4b50-525250524944
UUID : 9b3e3722-9839-6e01-4b50-525250524f50, version 229.116
Description : Unknown RPC service
Annotation : MAILER_TID
Type : Local RPC service
Named pipe : PRRUniversal#FAEBE4664900B1D0:3604

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 650a7e26-eab8-5533-ce43-9c1dfce11511, version 1.0
Description : Unknown RPC service
Annotation : Vpn APIs
Type : Local RPC service
Named pipe : RasmanLrpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 650a7e26-eab8-5533-ce43-9c1dfce11511, version 1.0
Description : Unknown RPC service
Annotation : Vpn APIs
Type : Local RPC service
Named pipe : VpnikeRpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 650a7e26-eab8-5533-ce43-9c1dfce11511, version 1.0
Description : Unknown RPC service
Annotation : Vpn APIs
Type : Local RPC service
Named pipe : LRPC-9be3b6871823677179

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 98716d03-89ac-44c7-bb8c-285824e51c4a, version 1.0
Description : Unknown RPC service
Annotation : XactSrv service
Type : Local RPC service
Named pipe : LRPC-4eff0310e144ca643f

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1a0d010f-1c33-432c-b0f5-8cf4e8053099, version 1.0
Description : Unknown RPC service
Annotation : IdSegSrv service
Type : Local RPC service
Named pipe : LRPC-4eff0310e144ca643f

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a398e520-d59a-4bdd-aa7a-3c1e0303a511, version 1.0
Description : Unknown RPC service
Annotation : IKE/Authip API
Type : Local RPC service
Named pipe : LRPC-a4c064c5bd738ebca5

Object UUID : 49541cea-a719-4e75-8d58-a3a7bfff960e
UUID : 850cee52-3038-4277-b9b4-e05db8b2c35c, version 1.0
Description : Unknown RPC service
Annotation : Device Association Framework Association RPC Interface
Type : Local RPC service
Named pipe : LRPC-382a445cff28fe5a82

Object UUID : 80b4038a-1d09-4c05-b1b6-249a4c2e0736
UUID : a1d4eae7-39f8-4bca-8e72-832767f5082a, version 1.0
Description : Unknown RPC service
Annotation : Device Association Framework Inbound RPC Interface
Type : Local RPC service
Named pipe : LRPC-382a445cff28fe5a82

Object UUID : 145857ef-d848-4a7e-b544-c1984d26cf05
UUID : 2e7d4935-59d2-4312-a2c8-41900aa5495f, version 1.0
Description : Unknown RPC service
Annotation : Device Association Framework Challenge RPC Interface
Type : Local RPC service
Named pipe : LRPC-382a445cff28fe5a82

Object UUID : 289e5e0f-414a-4de9-8d17-244507fffc07
UUID : bd84cd86-9825-4376-813d-334c543f89b1, version 1.0
Description : Unknown RPC service
Annotation : Device Association Framework Query RPC Interface
Type : Local RPC service
Named pipe : LRPC-382a445cff28fe5a82

Object UUID : 1475c123-1193-4379-81ac-302c4383421d
UUID : 5b665b9a-a086-4e26-ae24-96ab050b0ec3, version 1.0
Description : Unknown RPC service
Annotation : Device Association Framework AEP Store Access RPC Interface
Type : Local RPC service
Named pipe : LRPC-382a445cff28fe5a82

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : dd490425-5325-4565-b774-7e27d6c09c24, version 1.0
Description : Unknown RPC service
Annotation : Base Firewall Engine API
Type : Local RPC service
Named pipe : LRPC-517a177df5e1d51322

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7f9d11bf-7fb9-436b-a812-b2d50c5d4c03, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-517a177df5e1d51322

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7f9d11bf-7fb9-436b-a812-b2d50c5d4c03, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-a08010277f7ff44c01

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f47433c3-3e9d-4157-aad4-83aa1f5c2d4c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-517a177df5e1d51322

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f47433c3-3e9d-4157-aad4-83aa1f5c2d4c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-a08010277f7ff44c01

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f47433c3-3e9d-4157-aad4-83aa1f5c2d4c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-7ef11af249051167bd

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2fb92682-6599-42dc-ae13-bd2ca89bd11c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-517a177df5e1d51322

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2fb92682-6599-42dc-ae13-bd2ca89bd11c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-a08010277f7ff44c01

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2fb92682-6599-42dc-ae13-bd2ca89bd11c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-7ef11af249051167bd

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2fb92682-6599-42dc-ae13-bd2ca89bd11c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-948aeac2a361efdf24

Object UUID : 314c8427-4ad7-4233-995a-bbd062ed11e9
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-f3058ba81c6fb85d37

Object UUID : 9575918f-89b5-49cd-9307-f9fc0d9a5b05
UUID : ba4aa15a-be94-47fb-9bfb-fef110e7efad, version 1.0
Description : Unknown RPC service
Annotation : DevQueryBroker client query RPC interface
Type : Local RPC service
Named pipe : LRPC-744d79699d344d29e4

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 552d076a-cb29-4e44-8b6a-d15e59e2c0af, version 1.0
Description : Unknown RPC service
Annotation : IP Transition Configuration endpoint
Type : Local RPC service
Named pipe : LRPC-cfa9a88f17bd8a8d4d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Local RPC service
Named pipe : LRPC-cfa9a88f17bd8a8d4d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Local RPC service
Named pipe : TeredoDiagnostics

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Local RPC service
Named pipe : TeredoControl

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Local RPC service
Named pipe : LRPC-cfa9a88f17bd8a8d4d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Local RPC service
Named pipe : TeredoDiagnostics

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Local RPC service
Named pipe : TeredoControl

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Local RPC service
Named pipe : LRPC-cfa9a88f17bd8a8d4d

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Local RPC service
Named pipe : TeredoDiagnostics

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Local RPC service
Named pipe : TeredoControl

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : abfb6ca3-0c5e-4734-9285-0aee72fe8d1c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE8BC2347CDBA033C7AE462D9887A6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : abfb6ca3-0c5e-4734-9285-0aee72fe8d1c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6c31d9542b7e2ee2ba

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b37f900a-eae4-4304-a2ab-12bb668c0188, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE8BC2347CDBA033C7AE462D9887A6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b37f900a-eae4-4304-a2ab-12bb668c0188, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6c31d9542b7e2ee2ba

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e7f76134-9ef5-4949-a2d6-3368cc0988f3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE8BC2347CDBA033C7AE462D9887A6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e7f76134-9ef5-4949-a2d6-3368cc0988f3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6c31d9542b7e2ee2ba

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7aeb6705-3ae6-471a-882d-f39c109edc12, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE8BC2347CDBA033C7AE462D9887A6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7aeb6705-3ae6-471a-882d-f39c109edc12, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6c31d9542b7e2ee2ba

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f44e62af-dab1-44c2-8013-049a9de417d6, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE8BC2347CDBA033C7AE462D9887A6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f44e62af-dab1-44c2-8013-049a9de417d6, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6c31d9542b7e2ee2ba

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c2d1b5dd-fa81-4460-9dd6-e7658b85454b, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE8BC2347CDBA033C7AE462D9887A6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c2d1b5dd-fa81-4460-9dd6-e7658b85454b, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6c31d9542b7e2ee2ba

Object UUID : 73736573-6f69-656e-6e76-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : LRPC-eb8a0da0a07f50ab6b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-eb8a0da0a07f50ab6b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : SessEnvPrivateRpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f2c9b409-c1c9-4100-8639-d8ab1486694a, version 1.0
Description : Unknown RPC service
Annotation : Witness Client Upcall Server
Type : Local RPC service
Named pipe : LRPC-9fda8f3ebeac855884

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : eb081a0d-10ee-478a-a1dd-50995283e7a8, version 3.0
Description : Unknown RPC service
Annotation : Witness Client Test Interface
Type : Local RPC service
Named pipe : LRPC-9fda8f3ebeac855884

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7f1343fe-50a9-4927-a778-0c5859517bac, version 1.0
Description : Unknown RPC service
Annotation : DfsDs service
Type : Local RPC service
Named pipe : LRPC-9fda8f3ebeac855884

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 30adc50c-5cbc-46ce-9a0e-91914789e23c, version 1.0
Description : Unknown RPC service
Annotation : NRP server endpoint
Type : Local RPC service
Named pipe : DNSResolver

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 30adc50c-5cbc-46ce-9a0e-91914789e23c, version 1.0
Description : Unknown RPC service
Annotation : NRP server endpoint
Type : Local RPC service
Named pipe : LRPC-ced965b7d0ec27d35a

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 30b044a5-a225-43f0-b3a4-e060df91f9c1, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-dddd9e016fbcbe0f7b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b58aa02e-2884-4e97-8176-4ee06d794184, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-7694ad5b8deec5f2f3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b18fbab6-56f8-4702-84e0-41053293a869, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : OLE8D0E7FF822208799EA54D50E55CE

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b18fbab6-56f8-4702-84e0-41053293a869, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : LRPC-731d742d6c04d1e77f

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3c7f20-1c8d-4654-a1b3-51563b298bda, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : OLE8D0E7FF822208799EA54D50E55CE

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3c7f20-1c8d-4654-a1b3-51563b298bda, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : LRPC-731d742d6c04d1e77f

Object UUID : 736e6573-0000-0000-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : senssvc

Object UUID : 736e6573-0000-0000-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : LRPC-f99741c443dfad2caa

Object UUID : f2add560-eb85-4170-82a2-a48e789690cd
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-17cd685210e2b82024

Object UUID : 045ad40c-5920-4757-90a5-ae0e7e6f6838
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-17cd685210e2b82024

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4c8d0bef-d7f1-49f0-9102-caa05f58d114, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : nlaplg

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4c8d0bef-d7f1-49f0-9102-caa05f58d114, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : nlaapi

Object UUID : 666f7270-6c69-7365-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6, version 1.0
Description : Unknown RPC service
Annotation : DHCPv6 Client LRPC Endpoint
Type : Local RPC service
Named pipe : dhcpcsvc6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5, version 1.0
Description : DHCP Client Service
Windows process : svchost.exe
Annotation : DHCP Client LRPC Endpoint
Type : Local RPC service
Named pipe : dhcpcsvc6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5, version 1.0
Description : DHCP Client Service
Windows process : svchost.exe
Annotation : DHCP Client LRPC Endpoint
Type : Local RPC service
Named pipe : dhcpcsvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0a74ef1c-41a4-4e06-83ae-dc74fb1cdd53, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : LRPC-05ae4f4b3c93d3ff05

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1ff70682-0a51-30e8-076d-740be8cee98b, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : LRPC-05ae4f4b3c93d3ff05

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 378e52b0-c0a9-11cf-822d-00aa0051e40f, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : LRPC-05ae4f4b3c93d3ff05

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 33d84484-3626-47ee-8c6f-e7e98b113be1, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-05ae4f4b3c93d3ff05

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 33d84484-3626-47ee-8c6f-e7e98b113be1, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 33d84484-3626-47ee-8c6f-e7e98b113be1, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-1f98a44e801465c836

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-05ae4f4b3c93d3ff05

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-1f98a44e801465c836

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-05ae4f4b3c93d3ff05

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-1f98a44e801465c836

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7ea70bcf-48af-4f6a-8968-6a440754d5fa, version 1.0
Description : Unknown RPC service
Annotation : NSI server endpoint
Type : Local RPC service
Named pipe : LRPC-545d392bd5466c0661

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f6beaff7-1e19-4fbb-9f8f-b89e2018337c, version 1.0
Description : Unknown RPC service
Annotation : Event log TCPIP
Type : Local RPC service
Named pipe : eventlog

Object UUID : fdd099c6-df06-4904-83b4-a87a27903c70
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-79279e991bf8bd8c54

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5222821f-d5e2-4885-84f1-5f6185a0ec41, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-bb53dd0e51e5878322

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 880fd55e-43b9-11e0-b1a8-cf4edfd72085, version 1.0
Description : Unknown RPC service
Annotation : KAPI Service endpoint
Type : Local RPC service
Named pipe : LRPC-79279e991bf8bd8c54

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 880fd55e-43b9-11e0-b1a8-cf4edfd72085, version 1.0
Description : Unknown RPC service
Annotation : KAPI Service endpoint
Type : Local RPC service
Named pipe : OLEB148A5836E2C790873FCF317C6C7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 880fd55e-43b9-11e0-b1a8-cf4edfd72085, version 1.0
Description : Unknown RPC service
Annotation : KAPI Service endpoint
Type : Local RPC service
Named pipe : LRPC-0466b9261a7d776084

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e40f7b57-7a25-4cd3-a135-7f7d3df9d16b, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c89baaa762e726fcd0

Object UUID : b5ccd5ef-4238-440b-bba0-999f828f1cfe
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b58f5dba4392a6e87a

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a500d4c6-0dd1-4543-bc0c-d5f93486eaf8, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b58f5dba4392a6e87a

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a500d4c6-0dd1-4543-bc0c-d5f93486eaf8, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3b1c8d9ab406ccfcc0

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000001
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WMsgKRpc09E641

Object UUID : 52ef130c-08fd-4388-86b3-6edf00000001
UUID : 12e65dd8-887f-41ef-91bf-8d816c42c2e7, version 1.0
Description : Unknown RPC service
Annotation : Secure Desktop LRPC interface
Type : Local RPC service
Named pipe : WMsgKRpc09E641

Object UUID : 6d726574-7273-0076-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : LRPC-ef4ff0a8c4c79a5c3f

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4bec6bb8-b5c2-4b6f-b2c1-5da5cf92d0d9, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 085b0334-e454-4d91-9b8c-4134f9e793f3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8782d3b9-ebbd-4644-a3d8-e8725381919b, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3b338d89-6cfa-44b8-847e-531531bc9992, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : bdaa0970-413b-4a3e-9e5d-f6dc9d7e0760, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5824833b-3c1a-4ad2-bdfd-c31d19e23ed2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0361ae94-0316-4c6c-8ad8-c594375800e2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : dd59071b-3215-4c59-8481-972edadc0f6a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : dd59071b-3215-4c59-8481-972edadc0f6a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2d98a740-581d-41b9-aa0d-a88b9d5ce938, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2d98a740-581d-41b9-aa0d-a88b9d5ce938, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2d98a740-581d-41b9-aa0d-a88b9d5ce938, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-238e87105a963dc0a3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8bfc3be1-6def-4e2d-af74-7c47cd0ade4a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8bfc3be1-6def-4e2d-af74-7c47cd0ade4a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8bfc3be1-6def-4e2d-af74-7c47cd0ade4a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-238e87105a963dc0a3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1b37ca91-76b1-4f5e-a3c7-2abfc61f2bb0, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1b37ca91-76b1-4f5e-a3c7-2abfc61f2bb0, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1b37ca91-76b1-4f5e-a3c7-2abfc61f2bb0, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-238e87105a963dc0a3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c605f9fb-f0a3-4e2a-a073-73560f8d9e3e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c605f9fb-f0a3-4e2a-a073-73560f8d9e3e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c605f9fb-f0a3-4e2a-a073-73560f8d9e3e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-238e87105a963dc0a3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3e2735-cea0-4ecc-a9e2-41a2d81aed4e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3e2735-cea0-4ecc-a9e2-41a2d81aed4e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3e2735-cea0-4ecc-a9e2-41a2d81aed4e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-238e87105a963dc0a3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2513bcbe-6cd4-4348-855e-7efb3c336dd3, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2513bcbe-6cd4-4348-855e-7efb3c336dd3, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2513bcbe-6cd4-4348-855e-7efb3c336dd3, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-238e87105a963dc0a3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2513bcbe-6cd4-4348-855e-7efb3c336dd3, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEA0496F43D05CEE5F940E897CA26A

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 20c40295-8dba-48e6-aebf-3e78ef3bb144, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 20c40295-8dba-48e6-aebf-3e78ef3bb144, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 20c40295-8dba-48e6-aebf-3e78ef3bb144, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-238e87105a963dc0a3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 20c40295-8dba-48e6-aebf-3e78ef3bb144, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEA0496F43D05CEE5F940E897CA26A

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-238e87105a963dc0a3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEA0496F43D05CEE5F940E897CA26A

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-238e87105a963dc0a3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEA0496F43D05CEE5F940E897CA26A

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3304c0da6fe7a55a97

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-238e87105a963dc0a3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEA0496F43D05CEE5F940E897CA26A

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3304c0da6fe7a55a97

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-238e87105a963dc0a3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEA0496F43D05CEE5F940E897CA26A

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3304c0da6fe7a55a97

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2c7fd9ce-e706-4b40-b412-953107ef9bb0, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c521facf-09a9-42c5-b155-72388595cbf0, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1832bcf6-cab8-41d4-85d2-c9410764f75a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4dace966-a243-4450-ae3f-9b7bcb5315b8, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 178d84be-9291-4994-82c6-3f909aca5a03, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e53d94ca-7464-4839-b044-09a2fb8b3ae5, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fae436b0-b864-4a87-9eda-298547cd82f2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 082a3471-31b6-422a-b931-a54401960c62, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 6982a06e-5fe2-46b1-b39c-a2c545bfa069, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0ff1f646-13bb-400a-ab50-9a78f2b7a85a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4ed8abcc-f1e2-438b-981f-bb0e8abc010c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 95406f0b-b239-4318-91bb-cea3a46ff0dc, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d47017b-b33b-46ad-9e18-fe96456c5078, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 7cd4a68a-505e-456b-b11e-ca76a5dd491c
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 7cd4a68a-505e-456b-b11e-ca76a5dd491c
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 7cd4a68a-505e-456b-b11e-ca76a5dd491c
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-238e87105a963dc0a3

Object UUID : 7cd4a68a-505e-456b-b11e-ca76a5dd491c
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEA0496F43D05CEE5F940E897CA26A

Object UUID : 7cd4a68a-505e-456b-b11e-ca76a5dd491c
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3304c0da6fe7a55a97

Object UUID : 7cd4a68a-505e-456b-b11e-ca76a5dd491c
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-24a3c80bd9880b4457

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-238e87105a963dc0a3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEA0496F43D05CEE5F940E897CA26A

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3304c0da6fe7a55a97

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-24a3c80bd9880b4457

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-cf025998eb158061ba

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-238e87105a963dc0a3

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEA0496F43D05CEE5F940E897CA26A

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3304c0da6fe7a55a97

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-24a3c80bd9880b4457

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-cf025998eb158061ba

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-238e87105a963dc0a3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEA0496F43D05CEE5F940E897CA26A

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3304c0da6fe7a55a97

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-24a3c80bd9880b4457

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-cf025998eb158061ba

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-9a2362325de33ce799

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-238e87105a963dc0a3

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEA0496F43D05CEE5F940E897CA26A

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3304c0da6fe7a55a97

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-24a3c80bd9880b4457

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-cf025998eb158061ba

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-9a2362325de33ce799

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : csebpub

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-238e87105a963dc0a3

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLEA0496F43D05CEE5F940E897CA26A

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3304c0da6fe7a55a97

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-24a3c80bd9880b4457

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-cf025998eb158061ba

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-9a2362325de33ce799

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : csebpub

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : dabrpc

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000000
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WMsgKRpc09CA30

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000000
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WindowsShutdown

Object UUID : 765294ba-60bc-48b8-92e9-89fd77769d91
UUID : d95afe70-a6d5-4259-822e-2c84da1ddb0d, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WMsgKRpc09CA30

Object UUID : 765294ba-60bc-48b8-92e9-89fd77769d91
UUID : d95afe70-a6d5-4259-822e-2c84da1ddb0d, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WindowsShutdown

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : audit

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : securityevent

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : LSARPC_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : lsacap

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : LSA_IDPEXT_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : LSA_EAS_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : lsapolicylookup

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : lsasspirpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : protected_storage

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : SidKey Local End Point

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : samss lpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : audit

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : securityevent

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : LSARPC_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : lsacap

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : LSA_IDPEXT_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : LSA_EAS_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : lsapolicylookup

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : lsasspirpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : protected_storage

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : SidKey Local End Point

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : samss lpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : audit

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : securityevent

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSARPC_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsacap

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSA_IDPEXT_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSA_EAS_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsapolicylookup

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsasspirpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : protected_storage

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : SidKey Local End Point

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : samss lpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : audit

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : securityevent

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSARPC_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsacap

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSA_IDPEXT_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSA_EAS_ENDPOINT

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/445/cifs


The following DCERPC services are available remotely :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 04eeb297-cbf4-466b-8a2a-bfd6a2f10bba, version 1.0
Description : Unknown RPC service
Annotation : EFSK RPC Interface
Type : Remote RPC service
Named pipe : \pipe\efsrpc
Netbios name : \\LIVETECHROBO

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : df1941c5-fe89-4e79-bf10-463657acf44d, version 1.0
Description : Unknown RPC service
Annotation : EFS RPC Interface
Type : Remote RPC service
Named pipe : \pipe\efsrpc
Netbios name : \\LIVETECHROBO

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 650a7e26-eab8-5533-ce43-9c1dfce11511, version 1.0
Description : Unknown RPC service
Annotation : Vpn APIs
Type : Remote RPC service
Named pipe : \PIPE\ROUTER
Netbios name : \\LIVETECHROBO

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\SessEnvPublicRpc
Netbios name : \\LIVETECHROBO

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7f1343fe-50a9-4927-a778-0c5859517bac, version 1.0
Description : Unknown RPC service
Annotation : DfsDs service
Type : Remote RPC service
Named pipe : \PIPE\wkssvc
Netbios name : \\LIVETECHROBO

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1ff70682-0a51-30e8-076d-740be8cee98b, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\LIVETECHROBO

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 378e52b0-c0a9-11cf-822d-00aa0051e40f, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\LIVETECHROBO

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 33d84484-3626-47ee-8c6f-e7e98b113be1, version 2.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\LIVETECHROBO

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\LIVETECHROBO

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\LIVETECHROBO

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f6beaff7-1e19-4fbb-9f8f-b89e2018337c, version 1.0
Description : Unknown RPC service
Annotation : Event log TCPIP
Type : Remote RPC service
Named pipe : \pipe\eventlog
Netbios name : \\LIVETECHROBO

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000000
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\InitShutdown
Netbios name : \\LIVETECHROBO

Object UUID : 765294ba-60bc-48b8-92e9-89fd77769d91
UUID : d95afe70-a6d5-4259-822e-2c84da1ddb0d, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\InitShutdown
Netbios name : \\LIVETECHROBO

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Remote RPC service
Named pipe : \pipe\lsass
Netbios name : \\LIVETECHROBO

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Remote RPC service
Named pipe : \pipe\lsass
Netbios name : \\LIVETECHROBO

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Remote RPC service
Named pipe : \pipe\lsass
Netbios name : \\LIVETECHROBO

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Remote RPC service
Named pipe : \pipe\lsass
Netbios name : \\LIVETECHROBO

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49664/dce-rpc


The following DCERPC services are available on TCP port 49664 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Remote RPC service
TCP Port : 49664
IP : 172.17.100.35

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Remote RPC service
TCP Port : 49664
IP : 172.17.100.35

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Remote RPC service
TCP Port : 49664
IP : 172.17.100.35

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Remote RPC service
TCP Port : 49664
IP : 172.17.100.35

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49665/dce-rpc


The following DCERPC services are available on TCP port 49665 :

Object UUID : 765294ba-60bc-48b8-92e9-89fd77769d91
UUID : d95afe70-a6d5-4259-822e-2c84da1ddb0d, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49665
IP : 172.17.100.35

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49666/dce-rpc


The following DCERPC services are available on TCP port 49666 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f6beaff7-1e19-4fbb-9f8f-b89e2018337c, version 1.0
Description : Unknown RPC service
Annotation : Event log TCPIP
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.35

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49667/dce-rpc


The following DCERPC services are available on TCP port 49667 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49667
IP : 172.17.100.35

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49667
IP : 172.17.100.35

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49668/dce-rpc


The following DCERPC services are available on TCP port 49668 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49668
IP : 172.17.100.35

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49669/dce-rpc


The following DCERPC services are available on TCP port 49669 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 367abb81-9844-35f1-ad32-98f038001003, version 2.0
Description : Service Control Manager
Windows process : svchost.exe
Type : Remote RPC service
TCP Port : 49669
IP : 172.17.100.35

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49670/dce-rpc


The following DCERPC services are available on TCP port 49670 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 6b5bdd1e-528c-422c-af8c-a4079be4fe48, version 1.0
Description : Unknown RPC service
Annotation : Remote Fw APIs
Type : Remote RPC service
TCP Port : 49670
IP : 172.17.100.35

139785 - DISM Package List (Windows)
-
Synopsis
Use DISM to extract package info from the host.
Description
Using the Deployment Image Servicing Management tool, this plugin enumerates installed packages.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2020/08/25, Modified: 2025/12/15
Plugin Output

tcp/445/cifs

The following packages were enumerated using the Deployment Image Servicing and Management Tool:

Package : Microsoft-OneCore-ApplicationModel-Sync-Desktop-FOD-Package~31bf3856ad364e35~amd64~~10.0.19041.4355
State : Installed
Release Type : OnDemand Pack
Install Time : 3/10/2025 12:15 PM

Package : Microsoft-OneCore-DirectX-Database-FOD-Package~31bf3856ad364e35~amd64~~10.0.19041.5198
State : Installed
Release Type : OnDemand Pack
Install Time : 3/10/2025 12:15 PM

Package : Microsoft-Windows-Client-LanguagePack-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.5965
State : Installed
Release Type : Language Pack
Install Time : 6/23/2025 7:04 AM

Package : Microsoft-Windows-FodMetadata-Package~31bf3856ad364e35~amd64~~10.0.19041.1
State : Installed
Release Type : Feature Pack
Install Time : 12/7/2019 9:50 AM

Package : Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~10.0.19041.1
State : Installed
Release Type : Foundation
Install Time : 12/7/2019 9:18 AM

Package : Microsoft-Windows-Hello-Face-Package~31bf3856ad364e35~amd64~~10.0.19041.5737
State : Installed
Release Type : OnDemand Pack
Install Time : 4/19/2025 5:50 PM

Package : Microsoft-Windows-InternetExplorer-Optional-Package~31bf3856ad364e35~amd64~~11.0.19041.5794
State : Installed
Release Type : OnDemand Pack
Install Time : 5/27/2025 6:08 PM

Package : Microsoft-Windows-LanguageFeatures-Basic-en-gb-Package~31bf3856ad364e35~amd64~~10.0.19041.1
State : Installed
Release Type : OnDemand Pack
Install Time : 3/10/2025 9:09 AM

Package : Microsoft-Windows-LanguageFeatures-Basic-en-us-Package~31bf3856ad364e35~amd64~~10.0.19041.1
State : Installed
Release Type : OnDemand Pack
Install Time : 12/7/2019 9:52 AM

Package : Microsoft-Windows-LanguageFeatures-Handwriting-en-us-Package~31bf3856ad364e35~amd64~~10.0.19041.1
State : Installed
Release Type : OnDemand Pack
Install Time : 12/7/2019 9:52 AM

Package : Microsoft-Windows-LanguageFeatures-OCR-en-gb-Package~31bf3856ad364e35~amd64~~10.0.19041.1
State : Installed
Release Type : OnDemand Pack
Install Time : 3/10/2025 9:09 AM

Package : Microsoft-Windows-LanguageFeatures-OCR-en-us-Package~31bf3856ad364e35~amd64~~10.0.19041.1
State : Installed
Release Type : OnDemand Pack
Install Time : 12/7/2019 9:52 AM

Package : Microsoft-Windows-LanguageFeatures-Speech-en-us-Package~31bf3856ad364e35~amd64~~10.0.19041.1
State : Installed
Release Type : OnDemand Pack
Install Time : 12/7/2019 9:52 AM

Package : Microsoft-Windows-LanguageFeatures-TextToSpeech-en-us-Package~31bf3856ad364e35~amd64~~10.0.19041.1
State : Installed
Release Type : OnDemand Pack
Install Time : 12/7/2019 9:52 AM

Package : Microsoft-Windows-MediaPlayer-Package~31bf3856ad364e35~amd64~~10.0.19041.5965
State : Installed
Release Type : OnDemand Pack
Install Time : 6/23/2025 7:04 AM

Package : Microsoft-Windows-MSPaint-FoD-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.4597
State : Installed
Release Type : OnDemand Pack
Install Time : 3/10/2025 12:15 PM

Package : Microsoft-Windows-MSPaint-FoD-Package~31bf3856ad364e35~amd64~~10.0.19041.5553
State : Installed
Release Type : OnDemand Pack
Install Time : 3/28/2025 8:54 AM

Package : Microsoft-Windows-MSPaint-FoD-Package~31bf3856ad364e35~wow64~en-US~10.0.19041.1
State : Installed
Release Type : OnDemand Pack
Install Time : 12/7/2019 9:52 AM

Package : Microsoft-Windows-MSPaint-FoD-Package~31bf3856ad364e35~wow64~~10.0.19041.1
State : Installed
Release Type : OnDemand Pack
Install Time : 12/7/2019 9:52 AM

Package : Microsoft-Windows-NetFx3-OnDemand-Package~31bf3856ad364e35~amd64~~10.0.19041.1
State : Installed
Release Type : OnDemand Pack
Install Time : 9/14/2023 8:03 PM

Package : Microsoft-Windows-Notepad-FoD-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.488
State : Installed
Release Type : OnDemand Pack
Install Time : 4/14/2022 3:25 AM

Package : Microsoft-Windows-Notepad-FoD-Package~31bf3856ad364e35~amd64~~10.0.19041.5794
State : Installed
Release Type : OnDemand Pack
Install Time : 5/27/2025 6:08 PM

Package : Microsoft-Windows-Notepad-FoD-Package~31bf3856ad364e35~wow64~en-US~10.0.19041.1
State : Installed
Release Type : OnDemand Pack
Install Time : 12/7/2019 9:52 AM

Package : Microsoft-Windows-Notepad-FoD-Package~31bf3856ad364e35~wow64~~10.0.19041.1
State : Installed
Release Type : OnDemand Pack
Install Time : 12/7/2019 9:52 AM

Package : Microsoft-Windows-PowerShell-ISE-FOD-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1
State : Installed
Release Type : OnDemand Pack
Install Time : 12/7/2019 9:53 AM

Package : Microsoft-Windows-PowerShell-ISE-FOD-Package~31bf3856ad364e35~amd64~~10.0.19041.1
State : Installed
Release Type : OnDemand Pack
Install Time : 12/7/2019 9:53 AM

Package : Microsoft-Windows-PowerShell-ISE-FOD-Package~31bf3856ad364e35~wow64~en-US~10.0.19041.1
State : Installed
Release Type : OnDemand Pack
Install Time : 12/7/2019 9:53 AM

Package : Microsoft-Windows-PowerShell-ISE-FOD-Package~31bf3856ad364e35~wow64~~10.0.19041.1
State : Installed
Release Type : OnDemand Pack
Install Time : 12/7/2019 9:53 AM

Package : Microsoft-Windows-Printing-PMCPPC-FoD-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1
State : Installed
Release Type : OnDemand Pack
Install Time : 12/7/2019 9:54 AM

Package : Microsoft-Windows-Printing-PMCPPC-FoD-Package~31bf3856ad364e35~amd64~~10.0.19041.3636
State : Installed
Release Type : OnDemand Pack
Install Time : 3/10/2025 12:15 PM

Package : Microsoft-Windows-Printing-WFS-FoD-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.3636
State : Installed
Release Type : OnDemand Pack
Install Time : 3/10/2025 12:15 PM

Package : Microsoft-Windows-Printing-WFS-FoD-Package~31bf3856ad364e35~amd64~~10.0.19041.5794
State : Installed
Release Type : OnDemand Pack
Install Time : 5/27/2025 6:08 PM

Package : Microsoft-Windows-QuickAssist-Package~31bf3856ad364e35~amd64~~10.0.19041.5794
State : Installed
Release Type : OnDemand Pack
Install Time : 5/27/2025 6:08 PM

Package : Microsoft-Windows-StepsRecorder-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1
State : Installed
Release Type : OnDemand Pack
Install Time : 12/7/2019 9:53 AM

Package : Microsoft-Windows-StepsRecorder-Package~31bf3856ad364e35~amd64~~10.0.19041.3636
State : Installed
Release Type : OnDemand Pack
Install Time : 3/10/2025 12:15 PM

Package : Microsoft-Windows-StepsRecorder-Package~31bf3856ad364e35~wow64~en-US~10.0.19041.1
State : Installed
Release Type : OnDemand Pack
Install Time : 12/7/2019 9:53 AM

Package : Microsoft-Windows-StepsRecorder-Package~31bf3856ad364e35~wow64~~10.0.19041.1
State : Installed
Release Type : OnDemand Pack
Install Time : 12/7/2019 9:53 AM

Package : Microsoft-Windows-TabletPCMath-Package~31bf3856ad364e35~amd64~~10.0.19041.4355
State : Installed
Release Type : OnDemand Pack
Install Time : 3/10/2025 12:15 PM

Package : Microsoft-Windows-UserExperience-Desktop-Package~31bf3856ad364e35~amd64~~10.0.19041.5915
State : Installed
Release Type : OnDemand Pack
Install Time : 6/23/2025 7:04 AM

Package : Microsoft-Windows-WordPad-FoD-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1
State : Installed
Release Type : OnDemand Pack
Install Time : 12/7/2019 9:53 AM

Package : Microsoft-Windows-WordPad-FoD-Package~31bf3856ad364e35~amd64~~10.0.19041.5965
State : Installed
Release Type : OnDemand Pack
Install Time : 6/23/2025 7:04 AM

Package : Microsoft-Windows-WordPad-FoD-Package~31bf3856ad364e35~wow64~en-US~10.0.19041.1
State : Installed
Release Type : OnDemand Pack
Install Time : 12/7/2019 9:53 AM

Package : Microsoft-Windows-WordPad-FoD-Package~31bf3856ad364e35~wow64~~10.0.19041.1
State : Installed
Release Type : OnDemand Pack
Install Time : 12/7/2019 9:53 AM

Package : OpenSSH-Client-Package~31bf3856ad364e35~amd64~~10.0.19041.5737
State : Installed
Release Type : OnDemand Pack
Install Time : 4/19/2025 5:50 PM

Package : Package_for_DotNetRollup_481~31bf3856ad364e35~amd64~~10.0.9310.1
State : Installed
Release Type : Update
Install Time : 5/3/2025 5:48 PM

Package : Package_for_DotNetRollup~31bf3856ad364e35~amd64~~10.0.4672.2
State : Installed
Release Type : Update
Install Time : 10/31/2023 5:50 AM

Package : Package_for_KB4562830~31bf3856ad364e35~amd64~~10.0.1.3
State : Installed
Release Type : Update
Install Time : 4/14/2022 3:30 AM

Package : Package_for_KB5007401~31bf3856ad364e35~amd64~~19041.1378.1.1
State : Installed
Release Type : Update
Install Time : 4/14/2022 2:51 AM

Package : Package_for_KB5011048~31bf3856ad364e35~amd64~~10.0.9195.7
State : Installed
Release Type : Update
Install Time : 10/31/2023 5:50 AM

Package : Package_for_KB5015684~31bf3856ad364e35~amd64~~19041.1799.1.2
State : Installed
Release Type : Update
Install Time : 9/22/2023 2:32 PM

Package : Package_for_KB5033052~31bf3856ad364e35~amd64~~19041.3635.1.13
State : Installed
Release Type : Update
Install Time : 3/10/2025 12:15 PM

Package : Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.5965.1.5
State : Installed
Release Type : Security Update
Install Time : 6/23/2025 7:04 AM

Package : Package_for_ServicingStack_1613~31bf3856ad364e35~amd64~~19041.1613.1.1
State : Installed
Release Type : Update
Install Time : 4/14/2022 2:52 AM

Package : Package_for_ServicingStack_3385~31bf3856ad364e35~amd64~~19041.3385.1.0
State : Installed
Release Type : Update
Install Time : 9/14/2023 8:11 PM

Package : Package_for_ServicingStack_3562~31bf3856ad364e35~amd64~~19041.3562.1.0
State : Installed
Release Type : Update
Install Time : 10/10/2023 8:17 PM

Package : Package_for_ServicingStack_3684~31bf3856ad364e35~amd64~~19041.3684.1.2
State : Installed
Release Type : Update
Install Time : 11/17/2023 3:09 PM

Package : Package_for_ServicingStack_5425~31bf3856ad364e35~amd64~~19041.5425.1.2
State : Installed
Release Type : Update
Install Time : 3/10/2025 9:12 AM

Package : Package_for_ServicingStack_5547~31bf3856ad364e35~amd64~~19041.5547.1.1
State : Installed
Release Type : Update
Install Time : 3/13/2025 7:30 PM

Package : Package_for_ServicingStack_5676~31bf3856ad364e35~amd64~~19041.5676.1.3
State : Installed
Release Type : Update
Install Time : 4/12/2025 1:39 AM

Package : Package_for_ServicingStack_5853~31bf3856ad364e35~amd64~~19041.5853.1.1
State : Installed
Release Type : Security Update
Install Time : 5/15/2025 8:24 PM

Package : Package_for_ServicingStack_5911~31bf3856ad364e35~amd64~~19041.5911.1.1
State : Installed
Release Type : Update
Install Time : 6/13/2025 4:56 AM

84239 - Debugging Log Report
-
Synopsis
This plugin gathers the logs written by other plugins and reports them.
Description
Logs generated by other plugins are reported by this plugin. Plugin debugging must be enabled in the policy in order for this plugin to run.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2015/06/17, Modified: 2025/07/14
Plugin Output

tcp/0

Plugin debug log(s) have been attached.
55472 - Device Hostname
-
Synopsis
It was possible to determine the remote system hostname.
Description
This plugin reports a device's hostname collected via SSH or WMI.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/06/30, Modified: 2025/12/15
Plugin Output

tcp/0


Hostname : LIVETECHROBO
LIVETECHROBO (WMI)
54615 - Device Type
-
Synopsis
It is possible to guess the remote device type.
Description
Based on the remote operating system, it is possible to determine what the remote system type is (eg: a printer, router, general-purpose computer, etc).
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/05/23, Modified: 2025/03/12
Plugin Output

tcp/0

Remote device type : general-purpose
Confidence level : 100
71246 - Enumerate Local Group Memberships
-
Synopsis
Nessus was able to connect to a host via SMB to retrieve a list of local Groups and their Members.
Description
Nessus was able to connect to a host via SMB to retrieve a list of local Groups and their Members.

Note: Unable to query local Domain Controllers during Agent scans.
Rendering Group data obtained by plugin 171956.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/12/06, Modified: 2025/12/15
Plugin Output

tcp/0

Group Name : Access Control Assistance Operators
Host Name : LIVETECHROBO
Group SID : S-1-5-32-579
Members :

Group Name : Administrators
Host Name : LIVETECHROBO
Group SID : S-1-5-32-544
Members :
Name : Production
Domain : LIVETECHROBO
Class : Win32_UserAccount
SID : S-1-5-21-2193062927-1383316644-2198579232-500
Name : LKPAdmin
Domain : LIVETECHROBO
Class : Win32_UserAccount
SID : S-1-5-21-2193062927-1383316644-2198579232-1001
Name : Techrobot
Domain : LIVETECHROBO
Class : Win32_UserAccount
SID : S-1-5-21-2193062927-1383316644-2198579232-1004
Name : Techexcel
Domain : LIVETECHROBO
Class : Win32_UserAccount
SID : S-1-5-21-2193062927-1383316644-2198579232-1005
Name : tidua
Domain : LIVETECHROBO
Class : Win32_UserAccount
SID : S-1-5-21-2193062927-1383316644-2198579232-1009

Group Name : Backup Operators
Host Name : LIVETECHROBO
Group SID : S-1-5-32-551
Members :

Group Name : Cryptographic Operators
Host Name : LIVETECHROBO
Group SID : S-1-5-32-569
Members :

Group Name : Device Owners
Host Name : LIVETECHROBO
Group SID : S-1-5-32-583
Members :

Group Name : Distributed COM Users
Host Name : LIVETECHROBO
Group SID : S-1-5-32-562
Members :

Group Name : Event Log Readers
Host Name : LIVETECHROBO
Group SID : S-1-5-32-573
Members :

Group Name : Guests
Host Name : LIVETECHROBO
Group SID : S-1-5-32-546
Members :
Name : Guest
Domain : LIVETECHROBO
Class : Win32_UserAccount
SID : S-1-5-21-2193062927-1383316644-2198579232-501

Group Name : Hyper-V Administrators
Host Name : LIVETECHROBO
Group SID : S-1-5-32-578
Members :

Group Name : IIS_IUSRS
Host Name : LIVETECHROBO
Group SID : S-1-5-32-568
Members :
Name : IUSR
Domain : LIVETECHROBO
Class : Win32_SystemAccount
SID : S-1-5-17

Group Name : Network Configuration Operators
Host Name : LIVETECHROBO
Group SID : S-1-5-32-556
Members :

Group Name : Performance Log Users
Host Name : LIVETECHROBO
Group SID : S-1-5-32-559
Members :

Group Name : Performance Monitor Users
Host Name : LIVETECHROBO
Group SID : S-1-5-32-558
Members :
Name : MSSQLSERVER
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :
Name : SQLSERVERAGENT
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :

Group Name : Power Users
Host Name : LIVETECHROBO
Group SID : S-1-5-32-547
Members :

Group Name : Remote Desktop Users
Host Name : LIVETECHROBO
Group SID : S-1-5-32-555
Members :
Name : Techrobot
Domain : LIVETECHROBO
Class : Win32_UserAccount
SID : S-1-5-21-2193062927-1383316644-2198579232-1004

Group Name : Remote Management Users
Host Name : LIVETECHROBO
Group SID : S-1-5-32-580
Members :

Group Name : Replicator
Host Name : LIVETECHROBO
Group SID : S-1-5-32-552
Members :

Group Name : System Managed Accounts Group
Host Name : LIVETECHROBO
Group SID : S-1-5-32-581
Members :
Name : DefaultAccount
Domain : LIVETECHROBO
Class : Win32_UserAccount
SID : S-1-5-21-2193062927-1383316644-2198579232-503

Group Name : Users
Host Name : LIVETECHROBO
Group SID : S-1-5-32-545
Members :
Name : INTERACTIVE
Domain : LIVETECHROBO
Class : Win32_SystemAccount
SID : S-1-5-4
Name : Authenticated Users
Domain : LIVETECHROBO
Class : Win32_SystemAccount
SID : S-1-5-11
Name : Techrobot
Domain : LIVETECHROBO
Class : Win32_UserAccount
SID : S-1-5-21-2193062927-1383316644-2198579232-1004
Name : Techexcel
Domain : LIVETECHROBO
Class : Win32_UserAccount
SID : S-1-5-21-2193062927-1383316644-2198579232-1005
Name : Techapp
Domain : LIVETECHROBO
Class : Win32_UserAccount
SID : S-1-5-21-2193062927-1383316644-2198579232-1006
Name : tidua
Domain : LIVETECHROBO
Class : Win32_UserAccount
SID : S-1-5-21-2193062927-1383316644-2198579232-1009

Group Name : KLAdmins
Host Name : LIVETECHROBO
Group SID : S-1-5-21-2193062927-1383316644-2198579232-1002
Members :
Name : ksnproxy
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :

Group Name : KLOperators
Host Name : LIVETECHROBO
Group SID : S-1-5-21-2193062927-1383316644-2198579232-1003
Members :

Group Name : SQLRUserGroup
Host Name : LIVETECHROBO
Group SID : S-1-5-21-2193062927-1383316644-2198579232-1008
Members :
Name : MSSQLLaunchpad
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :

Group Name : SQLServer2005SQLBrowserUser$TECHEXCEL-ROBOT
Host Name : LIVETECHROBO
Group SID : S-1-5-21-2193062927-1383316644-2198579232-1007
Members :
Name : SQLBrowser
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :
72684 - Enumerate Users via WMI
-
Synopsis
Nessus was able to connect to a host via SMB to retrieve a list of users using WMI.
Description
Nessus was able to connect to a host via SMB to retrieve a list of users using WMI. Only identities that the authenticated SMB user has permissions to view will be retrieved by this plugin.

Note: Unable to query local Domain Controllers during Agent scans.
Rendering User data obtained by plugin 171956.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2014/02/25, Modified: 2025/12/15
Plugin Output

tcp/0


Name : DefaultAccount
SID : S-1-5-21-2193062927-1383316644-2198579232-503
Disabled : True
Lockout : False
Change password : True
Source : Local

Name : Guest
SID : S-1-5-21-2193062927-1383316644-2198579232-501
Disabled : True
Lockout : False
Change password : False
Source : Local

Name : LKPAdmin
SID : S-1-5-21-2193062927-1383316644-2198579232-1001
Disabled : False
Lockout : False
Change password : True
Source : Local

Name : Production
SID : S-1-5-21-2193062927-1383316644-2198579232-500
Disabled : False
Lockout : False
Change password : True
Source : Local

Name : Techapp
SID : S-1-5-21-2193062927-1383316644-2198579232-1006
Disabled : True
Lockout : False
Change password : False
Source : Local

Name : Techexcel
SID : S-1-5-21-2193062927-1383316644-2198579232-1005
Disabled : False
Lockout : False
Change password : False
Source : Local

Name : Techrobot
SID : S-1-5-21-2193062927-1383316644-2198579232-1004
Disabled : False
Lockout : False
Change password : False
Source : Local

Name : tidua
SID : S-1-5-21-2193062927-1383316644-2198579232-1009
Disabled : False
Lockout : False
Change password : False
Source : Local

Name : WDAGUtilityAccount
SID : S-1-5-21-2193062927-1383316644-2198579232-504
Disabled : True
Lockout : False
Change password : True
Source : Local

No. Of Users : 9
168980 - Enumerate the PATH Variables
-
Synopsis
Enumerates the PATH variable of the current scan user.
Description
Enumerates the PATH variables of the current scan user.
Solution
Ensure that directories listed here are in line with corporate policy.
Risk Factor
None
Plugin Information
Published: 2022/12/21, Modified: 2025/12/18
Plugin Output

tcp/0

Nessus has enumerated the path of the current scan user :

C:\ProgramData\Oracle\Java\javapath
C:\Program Files\Microsoft MPI\Bin\
C:\WINDOWS\system32
C:\WINDOWS
C:\WINDOWS\System32\Wbem
C:\WINDOWS\System32\WindowsPowerShell\v1.0\
C:\WINDOWS\System32\OpenSSH\
D:\Program Files\Microsoft SQL Server\Client SDK\ODBC\170\Tools\Binn\
D:\Program Files (x86)\Microsoft SQL Server\150\Tools\Binn\
D:\Program Files\Microsoft SQL Server\150\Tools\Binn\
D:\Program Files\Microsoft SQL Server\150\DTS\Binn\
D:\Program Files (x86)\Microsoft SQL Server\150\DTS\Binn\
C:\Program Files\Azure Data Studio\bin
C:\Users\tidua\AppData\Local\Microsoft\WindowsApps
117530 - Errors in nessusd.dump
-
Synopsis
This plugin parses information from the nessusd.dump log file and reports on errors.
Description
This plugin parses information from the nessusd.dump log file and reports on errors.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2018/09/17, Modified: 2024/11/04
Plugin Output

tcp/0

The nessusd.dump log file contained errors from the following plugins:

- smb_nt_ms23_aug_sqlserver_odbc_driver.nasl reported 1 error
- smb_enum_software_versions.nasl reported 3 errors
- upnp_search.nasl reported 3 errors
- onvif_detect.nbin reported 6 errors
- wmi_start_server_svc.nbin reported 4 errors
35716 - Ethernet Card Manufacturer Detection
-
Synopsis
The manufacturer can be identified from the Ethernet OUI.
Description
Each ethernet MAC address starts with a 24-bit Organizationally Unique Identifier (OUI). These OUIs are registered by IEEE.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/02/19, Modified: 2020/05/13
Plugin Output

tcp/0


The following card manufacturers were identified :

00:50:56:BC:FC:73 : VMware, Inc.
86420 - Ethernet MAC Addresses
-
Synopsis
This plugin gathers MAC addresses from various sources and consolidates them into a list.
Description
This plugin gathers MAC addresses discovered from both remote probing of the host (e.g. SNMP and Netbios) and from running local checks (e.g. ifconfig). It then consolidates the MAC addresses into a single, unique, and uniform list.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2015/10/16, Modified: 2025/06/10
Plugin Output

tcp/0

The following is a consolidated list of detected MAC addresses:
- 00:50:56:BC:FC:73
92439 - Explorer Search History
-
Synopsis
Nessus was able to gather a list of items searched for in the Windows UI.
Description
Nessus was able to gather evidence of cached search results from Windows Explorer searches.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0


Explorer search history report attached.

96534 - Firefox Browser Extension Enumeration
-
Synopsis
One or more Firefox browser extensions are installed on the remote host.
Description
Nessus was able to enumerate Firefox browser extensions installed on the remote host.
See Also
Solution
Make sure that the use and configuration of these extensions comply with your organization's acceptable use and security policies.
Risk Factor
None
References
XREF IAVT:0001-T-0510
Plugin Information
Published: 2017/01/16, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


User : Administrator
|- Browser : Firefox
|- Extension information :

Name : DoH Roll-Out
Description : This used to be a Mozilla add-on that supported the roll-out of DoH, but now only exists as a stub to enable migrations.
Version : 2.0.0
Install Date : Apr. 18, 2022 at 06:58:35 GMT
Update Date : Apr. 18, 2022 at 06:59:13 GMT
Path : C:\Program Files\Mozilla Firefox\browser\features\doh-rollout@mozilla.org.xpi
ID : doh-rollout@mozilla.org
Note : The file indicated by 'Path' was not found at the path specified. The extension may have been updated or removed since extensions.json was last updated.
Status : Enabled

Name : Form Autofill
Version : 1.0.1
Install Date : Oct. 1, 2018 at 17:50:06 GMT
Update Date : Apr. 18, 2022 at 06:59:13 GMT
Path : C:\Program Files\Mozilla Firefox\browser\features\formautofill@mozilla.org.xpi
ID : formautofill@mozilla.org
Status : Enabled

Name : Picture-In-Picture
Description : Fixes for web compatibility with Picture-in-Picture
Version : 1.0.0
Install Date : Apr. 18, 2022 at 06:59:13 GMT
Update Date : Apr. 18, 2022 at 06:59:13 GMT
Path : C:\Program Files\Mozilla Firefox\browser\features\pictureinpicture@mozilla.org.xpi
ID : pictureinpicture@mozilla.org
Status : Enabled

Name : Firefox Screenshots
Description : Take clips and screenshots from the Web and save them temporarily or permanently.
Version : 39.0.1
Install Date : Oct. 1, 2018 at 17:50:06 GMT
Update Date : Apr. 18, 2022 at 06:59:13 GMT
Path : C:\Program Files\Mozilla Firefox\browser\features\screenshots@mozilla.org.xpi
ID : screenshots@mozilla.org
Status : Enabled

Name : WebCompat Reporter
Description : Report site compatibility issues on webcompat.com
Version : 1.4.2
Install Date : Oct. 1, 2018 at 17:50:06 GMT
Update Date : Apr. 18, 2022 at 06:59:13 GMT
Path : C:\Program Files\Mozilla Firefox\browser\features\webcompat-reporter@mozilla.org.xpi
ID : webcompat-reporter@mozilla.org
Status : Disabled

Name : Web Compatibility Interventions
Description : Urgent post-release fixes for web compatibility.
Version : 31.0.0
Install Date : Oct. 1, 2018 at 17:50:06 GMT
Update Date : Apr. 18, 2022 at 06:59:13 GMT
Path : C:\Program Files\Mozilla Firefox\browser\features\webcompat@mozilla.org.xpi
ID : webcompat@mozilla.org
Status : Enabled

User : Techrobot
|- Browser : Firefox
|- Extension information :

Name : Form Autofill
Version : 1.0.1
Install Date : Apr. 18, 2022 at 06:59:13 GMT
Update Date : Feb. 4, 2025 at 15:03:01 GMT
Path : C:\Program Files\Mozilla Firefox\browser\features\formautofill@mozilla.org.xpi
ID : formautofill@mozilla.org
Status : Enabled

Name : Picture-In-Picture
Description : Fixes for web compatibility with Picture-in-Picture
Version : 1.0.0
Install Date : Apr. 18, 2022 at 06:59:13 GMT
Update Date : Jan. 9, 2025 at 21:05:23 GMT
Path : C:\Program Files\Mozilla Firefox\browser\features\pictureinpicture@mozilla.org.xpi
ID : pictureinpicture@mozilla.org
Status : Enabled

Name : Firefox Screenshots
Description : Take clips and screenshots from the Web and save them temporarily or permanently.
Version : 39.0.1
Install Date : Apr. 18, 2022 at 06:59:13 GMT
Update Date : Feb. 4, 2025 at 15:03:01 GMT
Path : C:\Program Files\Mozilla Firefox\browser\features\screenshots@mozilla.org.xpi
ID : screenshots@mozilla.org
Status : Disabled

Name : WebCompat Reporter
Description : Report site compatibility issues on webcompat.com
Version : 2.1.0
Install Date : Apr. 18, 2022 at 06:59:13 GMT
Update Date : Jul. 11, 2024 at 19:51:56 GMT
Path : C:\Program Files\Mozilla Firefox\browser\features\webcompat-reporter@mozilla.org.xpi
ID : webcompat-reporter@mozilla.org
Status : Disabled

Name : Web Compatibility Interventions
Description : Urgent post-release fixes for web compatibility.
Version : 135.0.0
Install Date : Apr. 18, 2022 at 06:59:13 GMT
Update Date : Feb. 4, 2025 at 15:03:01 GMT
Path : C:\Program Files\Mozilla Firefox\browser\features\webcompat@mozilla.org.xpi
ID : webcompat@mozilla.org
Status : Enabled

Name : UiPath Web Automation 23.4
Description : UiPath component for browser interaction
Version : 23.4.1
Install Date : Apr. 25, 2022 at 13:34:12 GMT
Update Date : Oct. 18, 2023 at 15:15:09 GMT
Path : C:\Users\Techrobot\AppData\Roaming\Mozilla\Firefox\Profiles\a79dff6k.default-release\extensions\extension4ff@uipath.com.xpi
ID : extension4ff@uipath.com
Status : Enabled

Name : UiPath Web Automation 23.4
Description : UiPath component for browser interaction
Version : 23.4.1
Install Date : Feb. 5, 2025 at 07:34:43 GMT
Update Date : Feb. 5, 2025 at 07:34:43 GMT
Path : C:\Users\Techrobot\AppData\Roaming\Mozilla\Firefox\Profiles\lr6hw9dq.default-release-1\extensions\extension4ff@uipath.com.xpi
ID : extension4ff@uipath.com
Status : Enabled

56310 - Firewall Rule Enumeration
-
Synopsis
A firewall is configured on the remote host.
Description
Using the supplied credentials, Nessus was able to get a list of firewall rules from the remote host.

Note: The output for this plugin can be very long, and is not shown by default. To display it, enable verbose reporting in scan settings.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/09/28, Modified: 2020/09/11
Plugin Output

tcp/0

report output too big - ending list here

34196 - Google Chrome Detection (Windows)
-
Synopsis
The remote Windows host contains a web browser.
Description
Google Chrome, a web browser from Google, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0511
Plugin Information
Published: 2008/09/12, Modified: 2025/07/10
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Google\Chrome\Application
Version : 143.0.7499.193

Note that Nessus only looked in the registry for evidence of Google
Chrome. If there are multiple users on this host, you may wish to
enable the 'Perform thorough tests' setting and re-scan. This will
cause Nessus to scan each local user's directory for installs.

10107 - HTTP Server Type and Version
-
Synopsis
A web server is running on the remote host.
Description
This plugin attempts to determine the type and the version of the remote web server.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0931
Plugin Information
Published: 2000/01/04, Modified: 2020/10/30
Plugin Output

tcp/2323/www

The remote web server type is :

Microsoft-HTTPAPI/2.0

12053 - Host Fully Qualified Domain Name (FQDN) Resolution
-
Synopsis
It was possible to resolve the name of the remote host.
Description
Nessus was able to resolve the fully qualified domain name (FQDN) of the remote host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2004/02/11, Modified: 2025/03/13
Plugin Output

tcp/0


172.17.100.35 resolves as LiveTechRobo.

24260 - HyperText Transfer Protocol (HTTP) Information
-
Synopsis
Some information about the remote HTTP configuration can be extracted.
Description
This test gives some information about the remote HTTP protocol - the version used, whether HTTP Keep-Alive is enabled, etc...

This test is informational only and does not denote any security problem.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/01/30, Modified: 2024/02/26
Plugin Output

tcp/2323/www


Response Code : HTTP/1.1 400 Bad Request

Protocol version : HTTP/1.1
HTTP/2 TLS Support: No
HTTP/2 Cleartext Support: No
SSL : no
Keep-Alive : no
Options allowed : (Not implemented)
Headers :

Content-Type: text/html; charset=us-ascii
Server: Microsoft-HTTPAPI/2.0
Date: Fri, 16 Jan 2026 10:51:33 GMT
Connection: close
Content-Length: 334

Response Body :

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN""http://www.w3.org/TR/html4/strict.dtd">
<HTML><HEAD><TITLE>Bad Request</TITLE>
<META HTTP-EQUIV="Content-Type" Content="text/html; charset=us-ascii"></HEAD>
<BODY><h2>Bad Request - Invalid Hostname</h2>
<hr><p>HTTP Error 400. The request hostname is invalid.</p>
</BODY></HTML>

24260 - HyperText Transfer Protocol (HTTP) Information
-
Synopsis
Some information about the remote HTTP configuration can be extracted.
Description
This test gives some information about the remote HTTP protocol - the version used, whether HTTP Keep-Alive is enabled, etc...

This test is informational only and does not denote any security problem.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/01/30, Modified: 2024/02/26
Plugin Output

tcp/5800/www


Response Code : HTTP/1.0 200 OK

Protocol version : HTTP/1.0
HTTP/2 TLS Support: No
HTTP/2 Cleartext Support: No
SSL : no
Keep-Alive : no
Headers :


Response Body :

<HTML>
<HEAD><TITLE>TightVNC desktop [livetechrobo]</TITLE></HEAD>
<BODY>
<APPLET ARCHIVE="tightvnc-jviewer.jar" CODE="com.glavsoft.viewer.Viewer" WIDTH=1 HEIGHT=1>
<PARAM NAME="PORT" VALUE="5900">
<PARAM NAME="OpenNewWindow" VALUE="YES">

</APPLET><BR>
<A HREF="http://www.tightvnc.com/">www.TightVNC.com</A>
</BODY>
</HTML>

171410 - IP Assignment Method Detection
-
Synopsis
Enumerates the IP address assignment method(static/dynamic).
Description
Enumerates the IP address assignment method(static/dynamic).
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/02/14, Modified: 2025/12/15
Plugin Output

tcp/0

+ Loopback Pseudo-Interface 1
+ IPv4
- Address : 127.0.0.1
Assign Method : static
+ IPv6
- Address : ::1
Assign Method : static
+ LAN
+ IPv4
- Address : 172.17.100.35
Assign Method : static
+ IPv6
- Address : fe80::72d1:e757:1c1a:f1bf%6
Assign Method : dynamic

179947 - Intel CPUID detection
-
Synopsis
The processor CPUID was detected on the remote host.
Description
The CPUID of the Intel processor was detected on the remote host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/08/18, Modified: 2025/12/15
Plugin Output

tcp/135/epmap

Nessus was able to extract the following cpuid: C06F2

92421 - Internet Explorer Typed URLs
-
Synopsis
Nessus was able to enumerate URLs that were manually typed into the Internet Explorer address bar.
Description
Nessus was able to generate a list URLs that were manually typed into the Internet Explorer address bar.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2024/05/08
Plugin Output

tcp/0

http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141

Internet Explorer typed URL report attached.

148499 - Java Detection and Identification (Windows)
-
Synopsis
Java is installed on the remote Windows host.
Description
One or more instances of Java are installed on the remote Windows host. This may include private JREs bundled with the Java Development Kit (JDK).

- This plugin attempts to detect Oracle and non-Oracle JRE instances such as Zulu Java, Amazon Corretto, AdoptOpenJDK, IBM Java, etc

- Additional instances of Java may be discovered if 'Perform thorough tests' is enabled.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0690
Plugin Information
Published: 2021/04/14, Modified: 2025/12/16
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre1.8.0_161\
Version : 8.0.161.12
Application : Oracle Java
Binary Location : C:\Program Files\Java\jre1.8.0_161\bin\java.exe
Details : This Java install appears to be Oracle Java, confirmed by associated
files (high confidence).
Detection Method : Found in Registry

65743 - Java JRE Enabled (Internet Explorer)
-
Synopsis
The remote host has Java JRE enabled for Internet Explorer.
Description
Java JRE is enabled in Internet Explorer. Internet Explorer is no longer supported by Microsoft.
See Also
Solution
Apply Microsoft 'Fix it' 50994 unless Java is needed.
Risk Factor
None
Plugin Information
Published: 2013/03/29, Modified: 2024/10/02
Plugin Output

tcp/445/cifs


Java is enabled for the following ActiveX controls and SIDs :
ActiveX CLSIDs :
{8AD9C840-044E-11D1-B3E9-00805F499D93}
{CAFEEFAC-0017-0000-FFFF-ABCDEFFEDCBA}
{CAFEEFAC-0017-0001-FFFF-ABCDEFFEDCBA}
{CAFEEFAC-0017-0002-FFFF-ABCDEFFEDCBA}
{CAFEEFAC-0017-0003-FFFF-ABCDEFFEDCBA}
{CAFEEFAC-0017-0004-FFFF-ABCDEFFEDCBA}
{CAFEEFAC-0017-0005-FFFF-ABCDEFFEDCBA}
{CAFEEFAC-0017-0006-FFFF-ABCDEFFEDCBA}
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}

User SIDs :
S-1-5-21-2193062927-1383316644-2198579232-1004
S-1-5-21-2193062927-1383316644-2198579232-1009

Note that this check may be incomplete as Nessus can only check the
SIDs of logged on users.
65739 - Java JRE Universally Enabled
-
Synopsis
Java JRE has not been universally disabled on the remote host.
Description
Java JRE has not been universally disabled on the remote host via the Java control panel.
Note that while Java can be individually disabled for each browser, universally disabling Java prevents it from running for all users and browsers.
Functionality to disable Java universally in Windows may not be available in all versions of Java.
See Also
Solution
Disable Java universally unless it is needed.
Risk Factor
None
Plugin Information
Published: 2013/03/29, Modified: 2024/10/02
Plugin Output

tcp/445/cifs

53513 - Link-Local Multicast Name Resolution (LLMNR) Detection
-
Synopsis
The remote device supports LLMNR.
Description
The remote device answered to a Link-local Multicast Name Resolution (LLMNR) request. This protocol provides a name lookup service similar to NetBIOS or DNS. It is enabled by default on modern Windows versions.
See Also
Solution
Make sure that use of this software conforms to your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2011/04/21, Modified: 2023/10/17
Plugin Output

udp/5355/llmnr


According to LLMNR, the name of the remote host is 'LiveTechRobo'.

160301 - Link-Local Multicast Name Resolution (LLMNR) Service Detection
-
Synopsis
Verify status of the LLMNR service on the remote host.
Description
The Link-Local Multicast Name Resolution (LLMNR) service allows both IPv4 and IPv6 hosts to perform name resolution for hosts on the same local link
See Also
Solution
Make sure that use of this software conforms to your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2022/04/28, Modified: 2022/12/29
Plugin Output

tcp/445/cifs


LLMNR Key SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast not found.

92424 - MUICache Program Execution History
-
Synopsis
Nessus was able to enumerate recently executed programs on the remote host.
Description
Nessus was able to query the MUIcache registry key to find evidence of program execution.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/16
Plugin Output

tcp/0

c:\windows\system32\mmc.exe.applicationcompany : Microsoft Corporation
c:\windows\system32\mmc.exe.friendlyappname : Microsoft Management Console
langid : .
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.574\lib\net45\ffmpeg\bin\ffmpeg.exe.friendlyappname : ffmpeg.exe
c:\windows\regedit.exe.applicationcompany : Microsoft Corporation
c:\windows\system32\msiexec.exe.applicationcompany : Microsoft Corporation
c:\windows\system32\shell32.dll.applicationcompany : Microsoft Corporation
c:\program files\common files\microsoft shared\office16\msoxmled.exe.applicationcompany : Microsoft Corporation
c:\windows\system32\explorerframe.dll.applicationcompany : Microsoft Corporation
c:\users\techrobot\appdata\local\programs\uipath\studio\uipath.studio.exe.friendlyappname : UiPath Studio
c:\program files\windows nt\accessories\wordpad.exe.applicationcompany : Microsoft Corporation
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.584\lib\net45\ffmpeg\bin\ffmpeg.exe.friendlyappname : ffmpeg.exe
d:\lkpsoft\cdsl secure\cdsl secure\cdsl files\cdslsecureappinstaller_22.06.08-p1\cdslsecureappinstaller.exe.friendlyappname : CDSLSecureappInstaller.exe
c:\windows\system32\appresolver.dll.applicationcompany : Microsoft Corporation
c:\windows\system32\mmc.exe.friendlyappname : Microsoft Management Console
c:\program files (x86)\common files\microsoft shared\office14\msoxmled.exe.friendlyappname : XML Editor
c:\program files (x86)\jam software\treesize free\treesizefree.exe.applicationcompany : JAM Software
c:\windows\system32\openwith.exe.applicationcompany : Microsoft Corporation
c:\windows\system32\compmgmtlauncher.exe.applicationcompany : Microsoft Corporation
c:\program files\microsoft office\office16\excel.exe.applicationcompany : Microsoft Corporation
c:\users\techrobot\appdata\local\uipath\app-21.4.4\uipath.studio.exe.friendlyappname : UiPath Studio
c:\windows\system32\cryptext.dll.applicationcompany : Microsoft Corporation
c:\users\techrobot\appdata\local\uipath\uipath.studio.exe.friendlyappname : UiPath Studio
d:\lkpsoft\cdsl secure\cdsl secure\cdsl files\dotnet_framework_4.0\dotnet framework 4.0\dotnetfx40_full_x86_x64.exe.friendlyappname : Microsoft .NET Framework 4 Setup
c:\users\techrobot\appdata\local\uipath\uipath.studio.exe.applicationcompany : UiPath
c:\windows\system32\openwith.exe.friendlyappname : Pick an app
c:\program files (x86)\windows media player\wmplayer.exe.friendlyappname : Windows Media Player
d:\lkpsoft\cdsl secure\cdsl secure\cdsl files\dotnet_framework_4.0\dotnet framework 4.0\dotnetfx40_full_x86_x64.exe.applicationcompany : Microsoft Corporation
c:\windows\system32\cryptext.dll.friendlyappname : Crypto Shell Extensions
c:\users\techrobot\appdata\local\programs\uipath\studio\uipathassistant\uipath.assistant.exe.applicationcompany : UiPath
c:\program files\internet explorer\iexplore.exe.applicationcompany : Microsoft Corporation
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.579\lib\net45\ffmpeg\bin\ffmpeg.exe.friendlyappname : ffmpeg.exe
c:\program files\microsoft office\office16\winword.exe.friendlyappname : Word 2016
c:\program files\microsoft office\office16\winword.exe.applicationcompany : Microsoft Corporation
c:\users\techrobot\downloads\pk\pkzip.exe.friendlyappname : PKZIP.EXE
c:\program files\mozilla firefox\firefox.exe.applicationcompany : Mozilla Corporation
c:\users\techrobot\documents\uipath\techexcelrpa\ffmpeg\bin\ffmpeg.exe.friendlyappname : ffmpeg.exe
c:\program files\winrar\winrar.exe.friendlyappname : WinRAR archiver
c:\windows\system32\wfs.exe.applicationcompany : Microsoft Corporation
c:\windows\explorer.exe.friendlyappname : Windows Explorer
c:\program files (x86)\common files\microsoft shared\office14\msoxmled.exe.applicationcompany : Microsoft Corporation
c:\windows\system32\mspaint.exe.friendlyappname : Paint
c:\windows\system32\notepad.exe.friendlyappname : Notepad
c:\windows\system32\msiexec.exe.friendlyappname : Windows® installer
c:\users\techrobot\appdata\local\uipath\app-21.4.4\uipath.studio.exe.applicationcompany : UiPath
c:\program files (x86)\windows media player\wmplayer.exe.applicationcompany : Microsoft Corporation
c:\program files\winrar\winrar.exe.applicationcompany : Alexander Roshal
c:\windows\system32\dfshim.dll.applicationcompany : Microsoft Corporation
c:\users\techrobot\appdata\local\squirreltemp\update.exe.applicationcompany : GitHub
c:\windows\system32\dfshim.dll.friendlyappname : ClickOnce Application Deployment Support Library
c:\program files (x86)\jam software\treesize free\treesizefree.exe.friendlyappname : TreeSize Free hard disk space manager
c:\users\techrobot\appdata\local\squirreltemp\update.exe.friendlyappname : Update
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.430\lib\net45\ffmpeg\bin\ffmpeg.exe.friendlyappname : ffmpeg.exe
c:\program files\microsoft office\office16\mspub.exe.friendlyappname : Publisher 2016
c:\windows\system32\mmc.exe.applicationcompany : Microsoft Corporation
c:\windows\system32\fsquirt.exe.friendlyappname : fsquirt
c:\windows\system32\shell32.dll.friendlyappname : Windows Shell Common Dll
c:\program files\common files\microsoft shared\office16\msoxmled.exe.friendlyappname : Office XML Handler
c:\program files\microsoft office\office16\excel.exe.friendlyappname : Excel 2016
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.548\lib\net45\ffmpeg\bin\ffmpeg.exe.friendlyappname : ffmpeg.exe
c:\program files (x86)\notepad++\updater\gup.exe.friendlyappname : GUP : a free (LGPL) Generic Updater
c:\windows\system32\notepad.exe.applicationcompany : Microsoft Corporation
c:\users\techrobot\appdata\local\programs\uipath\studio\net461\uipath.executor.exe.friendlyappname : UiPath Executor
c:\windows\regedit.exe.friendlyappname : Registry Editor
c:\program files (x86)\microsoft office\office14\winword.exe.applicationcompany : Microsoft Corporation
c:\program files (x86)\notepad++\updater\gup.exe.applicationcompany : Don HO don.h@free.fr
c:\users\techrobot\appdata\local\programs\uipath\studio\uipath.studio.exe.applicationcompany : UiPath
c:\program files (x86)\microsoft office\office14\winword.exe.friendlyappname : Microsoft Word
c:\windows\system32\compmgmtlauncher.exe.friendlyappname : Computer Management Snapin Launcher
c:\program files\microsoft office\office16\mspub.exe.applicationcompany : Microsoft Corporation
c:\program files\mozilla firefox\firefox.exe.friendlyappname : Firefox
c:\windows\system32\explorerframe.dll.friendlyappname : ExplorerFrame
c:\users\techrobot\appdata\local\programs\uipath\studio\uipathassistant\uipath.assistant.exe.friendlyappname : UiPath.Assistant
c:\users\techrobot\appdata\local\programs\uipath\studio\net461\uipath.executor.exe.applicationcompany : UiPath
d:\lkpsoft\cdsl secure\cdsl secure\cdsl files\pkzip_pkunzip\pk\pkzip.exe.friendlyappname : PKZIP.EXE
c:\program files\internet explorer\iexplore.exe.friendlyappname : Internet Explorer
c:\windows\system32\wfs.exe.friendlyappname : Microsoft Windows Fax and Scan
langid : .
c:\windows\system32\fsquirt.exe.applicationcompany : Microsoft Corporation
c:\windows\system32\appresolver.dll.friendlyappname : App Resolver
c:\program files\windows nt\accessories\wordpad.exe.friendlyappname : WordPad
c:\windows\explorer.exe.applicationcompany : Microsoft Corporation
c:\windows\system32\mspaint.exe.applicationcompany : Microsoft Corporation
@%systemroot%\system32\srvsvc.dll,-100 : Server
@%systemroot%\system32\drivers\wpdupfltr.sys,-100 : WPD Upper Class Filter Driver
@combase.dll,-5013 : The DCOMLAUNCH service launches COM and DCOM servers in response to object activation requests. If this service is stopped or disabled, programs using COM or DCOM will not function properly. It is strongly recommended that you have the DCOMLAUNCH service running.
@%systemroot%\system32\axinstsv.dll,-103 : ActiveX Installer (AxInstSV)
@winlangdb.dll,-1691 : English (Barbados)
@%systemroot%\system32\appxdeploymentserver.dll,-1 : AppX Deployment Service (AppXSVC)
@%systemroot%\system32\smphost.dll,-101 : Host service for the Microsoft Storage Spaces management provider. If this service is stopped or disabled, Storage Spaces cannot be managed.
@%systemroot%\system32\wlidsvc.dll,-100 : Microsoft Account Sign-in Assistant
@%systemroot%\system32\wcncsvc.dll,-3 : Windows Connect Now - Config Registrar
@%systemroot%\system32\efssvc.dll,-100 : Encrypting File System (EFS)
@%windir%\system32\drivers\pacer.sys,-101 : QoS Packet Scheduler
@%systemroot%\system32\lltdres.dll,-6 : Link-Layer Topology Discovery Mapper I/O Driver
@%systemroot%\system32\drivers\rdpdr.sys,-100 : Remote Desktop Device Redirector Driver
@%systemroot%\system32\aphostres.dll,-10002 : Sync Host
@c:\windows\system32\rdpendp.dll,-1001 : Remote Audio
@%systemroot%\system32\workfolderssvc.dll,-101 : This service syncs files with the Work Folders server, enabling you to use the files on any of the PCs and devices on which you've set up Work Folders.
@%systemroot%\system32\ci.dll,-100 : Isolated User Mode (IUM)
@%systemroot%\system32\wscsvc.dll,-200 : Security Center
@%systemroot%\system32\consentuxclient.dll,-101 : Allows ConnectUX and PC Settings to Connect and Pair with WiFi displays and Bluetooth devices.
@%systemroot%\system32\qwave.dll,-1 : Quality Windows Audio Video Experience
@%systemroot%\system32\cloudidsvc.dll,-100 : Microsoft Cloud Identity Service
@%systemroot%\system32\wiarpc.dll,-2 : Still Image Acquisition Events
@%systemroot%\system32\xboxgipsvc.dll,-101 : This service manages connected Xbox Accessories.
@%systemroot%\system32\powrprof.dll,-12 : Favors performance, but may use more energy.
@%systemroot%\system32\tapisrv.dll,-10100 : Telephony
@%systemroot%\system32\drivers\winnat.sys,-10001 : Windows NAT Driver
@%systemroot%\system32\drivers\appvstrm.sys,-101 : AppvStrm
@%systemroot%\system32\wpcrefreshtask.dll,-100 : Parental Controls
@c:\windows\system32\ieframe.dll,-12385 : Favorites Bar
@%systemroot%\system32\rmapi.dll,-1001 : Radio Management Service
@%systemroot%\system32\wpnservice.dll,-2 : This service runs in session 0 and hosts the notification platform and connection provider which handles the connection between the device and WNS server.
@%systemroot%\system32\p2psvc.dll,-8006 : Peer Networking Grouping
@%systemroot%\system32\drivers\spaceparser.sys,-1001 : Space Parser
@c:\windows\system32\snippingtool.exe,-15051 : Snipping Tool
@%systemroot%\system32\sensorservice.dll,-1001 : A service for sensors that manages different sensors' functionality. Manages Simple Device Orientation (SDO) and History for sensors. Loads the SDO sensor that reports device orientation changes. If this service is stopped or disabled, the SDO sensor will not be loaded and so auto-rotation will not occur. History collection from Sensors will also be stopped.
@%systemroot%\system32\drivers\scfilter.sys,-11 : Smart card PnP Class Filter Driver
@%systemroot%\system32\sysmain.dll,-1001 : Maintains and improves system performance over time.
@%systemroot%\system32\diagsvcs\diagnosticshub.standardcollector.serviceres.dll,-1001 : Diagnostics Hub Standard Collector Service. When running, this service collects real time ETW events and processes them.
@%systemroot%\system32\assignedaccessmanagersvc.dll,-100 : AssignedAccessManager Service
@%systemroot%\system32\gameinputsvc.exe,-102 : Enables keyboards, mice, gamepads, and other input devices to be used with the GameInput API.
@%systemroot%\system32\graphicsperfsvc.dll,-101 : Graphics performance monitor service
@%systemroot%\system32\fdphost.dll,-100 : Function Discovery Provider Host
@%systemroot%\system32\frameserver.dll,-101 : Enables multiple clients to access video frames from camera devices.
@%systemroot%\system32\ncbservice.dll,-501 : Brokers connections that allow Windows Store Apps to receive notifications from the internet.
@%systemroot%\system32\walletservice.dll,-1000 : WalletService
@%systemroot%\system32\netlogon.dll,-102 : Netlogon
@%systemroot%\system32\phoneserviceres.dll,-10001 : Manages the telephony state on the device
@%systemroot%\system32\dialogblockingservice.dll,-101 : Dialog Blocking Service
@%systemroot%\system32\ngcrecovery.dll,-100 : Windows Hello Recovery Key Encryption
@%systemroot%\system32\umpnpmgr.dll,-100 : Device Install Service
@%systemroot%\system32\drivers\wdf01000.sys,-1000 : Kernel Mode Driver Frameworks service
@%systemroot%\system32\ci.dll,-101 : Enclave
@%systemroot%\system32\bthserv.dll,-101 : Bluetooth Support Service
@%systemroot%\system32\vds.exe,-112 : Provides management services for disks, volumes, file systems, and storage arrays.
@%systemroot%\system32\urlmon.dll,-4200 : Open File - Security Warning
@%systemroot%\system32\sstpsvc.dll,-201 : Provides support for the Secure Socket Tunneling Protocol (SSTP) to connect to remote computers using VPN. If this service is disabled, users will not be able to use SSTP to access remote servers.
@%systemroot%\system32\qmgr.dll,-1001 : Transfers files in the background using idle network bandwidth. If the service is disabled, then any applications that depend on BITS, such as Windows Update or MSN Explorer, will be unable to automatically download programs and other information.
@%systemroot%\system32\netman.dll,-110 : Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections.
@c:\windows\system32\speech\speechux\sapi.cpl,-5555 : Windows Speech Recognition
@%systemroot%\system32\taskmgr.exe,-33551 : Manage running apps and view system performance
@%programfiles%\windows defender advanced threat protection\mssense.exe,-1001 : Windows Defender Advanced Threat Protection Service
@c:\windows\system32\mstsc.exe,-4000 : Remote Desktop Connection
@c:\windows\system32\windows.storage.dll,-10152 : File folder
@%systemroot%\system32\drivers\volmgrx.sys,-100 : Dynamic Volume Manager
@%systemroot%\system32\das.dll,-101 : Enables pairing between the system and wired or wireless devices.
@combase.dll,-5011 : The RPCSS service is the Service Control Manager for COM and DCOM servers. It performs object activations requests, object exporter resolutions and distributed garbage collection for COM and DCOM servers. If this service is stopped or disabled, programs using COM or DCOM will not function properly. It is strongly recommended that you have the RPCSS service running.
@%systemroot%\system32\mprmsg.dll,-32006 : WAN Miniport (PPTP)
@%systemroot%\system32\wlidsvc.dll,-101 : Enables user sign-in through Microsoft account identity services. If this service is stopped, users will not be able to logon to the computer with their Microsoft account.
@%systemroot%\system32\dmwappushsvc.dll,-200 : Device Management Wireless Application Protocol (WAP) Push message Routing Service
@%systemroot%\system32\windows.warp.jitservice.dll,-101 : Provides a JIT out of process service for WARP when running with ACG enabled.
@%systemroot%\system32\pnrpauto.dll,-8003 : This service publishes a machine name using the Peer Name Resolution Protocol. Configuration is managed via the netsh context 'p2p pnrp peer'
@%systemroot%\system32\icsvc.dll,-202 : Provides a mechanism to exchange data between the virtual machine and the operating system running on the physical computer.
@%systemroot%\system32\diagsvc.dll,-100 : Diagnostic Execution Service
@%systemroot%\system32\icsvc.dll,-301 : Hyper-V Guest Shutdown Service
@%systemroot%\system32\wcmsvc.dll,-4098 : Makes automatic connect/disconnect decisions based on the network connectivity options currently available to the PC and enables management of network connectivity based on Group Policy settings.
@%systemroot%\system32\aarsvc.dll,-101 : Runtime for activating conversational agent applications
@%windir%\system32\mstsc.exe,-4001 : Use your computer to connect to a computer that is located elsewhere and run programs or access files.
@windows.storage.dll,-34583 : Saved Pictures
@%systemroot%\system32\wfdsconmgrsvc.dll,-9001 : Manages connections to wireless services, including wireless display and docking.
@%systemroot%\system32\drivers\fsdepends.sys,-10001 : File System Dependency Minifilter
@%systemroot%\system32\phoneserviceres.dll,-10000 : Phone Service
@%systemroot%\system32\wcncsvc.dll,-4 : WCNCSVC hosts the Windows Connect Now Configuration which is Microsoft's Implementation of Wireless Protected Setup (WPS) protocol. This is used to configure Wireless LAN settings for an Access Point (AP) or a Wireless Device. The service is started programmatically as needed.
c:\windows\system32,@elscore.dll,-7 : Microsoft Devanagari to Latin Transliteration
@%systemroot%\system32\defragsvc.dll,-102 : Helps the computer run more efficiently by optimizing files on storage drives.
@%systemroot%\system32\upnphost.dll,-214 : Allows UPnP devices to be hosted on this computer. If this service is stopped, any hosted UPnP devices will stop functioning and no additional hosted devices can be added. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\xboxnetapisvc.dll,-101 : This service supports the Windows.Networking.XboxLive application programming interface.
@%systemroot%\system32\tabsvc.dll,-100 : Touch Keyboard and Handwriting Panel Service
@%systemroot%\system32\tcpipcfg.dll,-50004 : NetIO Legacy TDI Support Driver
@c:\windows\system32\authfwgp.dll,-20 : Windows Defender Firewall with Advanced Security
@%systemroot%\system32\windows.devices.picker.dll,-1006 : DevicePicker
@%windir%\system32\systemeventsbrokerserver.dll,-1002 : Coordinates execution of background work for WinRT application. If this service is stopped or disabled, then background work might not be triggered.
@%systemroot%\system32\snippingtool.exe,-15052 : Capture a portion of your screen so you can save, annotate, or share the image.
@%systemroot%\system32\assignedaccessmanagersvc.dll,-101 : AssignedAccessManager Service supports kiosk experience in Windows.
@%systemroot%\system32\deviceaccess.dll,-108 : Enables apps to pair devices
@%systemroot%\system32\ipnathlp.dll,-106 : Internet Connection Sharing (ICS)
@c:\program files\common files\microsoft shared\ink\mip.exe,-291 : Math Input Panel
@c:\windows\system32\filemgmt.dll,-2204 : Services
@%systemroot%\system32\wkssvc.dll,-1000 : Redirected Buffering Sub System
@%systemroot%\system32\mprmsg.dll,-32012 : Remote Access IPv6 ARP Driver
@%systemroot%\system32\bthavctpsvc.dll,-102 : This is Audio Video Control Transport Protocol service
@%systemroot%\system32\alg.exe,-112 : Application Layer Gateway Service
@%systemroot%\system32\sensrsvc.dll,-1001 : Monitors various sensors in order to expose data and adapt to system and user state. If this service is stopped or disabled, the display brightness will not adapt to lighting conditions. Stopping this service may affect other system functionality and features as well.
@%systemroot%\system32\drivers\msseccore.sys,-1001 : Microsoft Security Core Boot Driver
@%systemroot%\system32\microsoft.bluetooth.userservice.dll,-101 : Bluetooth User Support Service
@%systemroot%\system32\schedsvc.dll,-100 : Task Scheduler
@%systemroot%\system32\sstpsvc.dll,-202 : WAN Miniport (SSTP)
@c:\windows\system32\windowspowershell\v1.0\powershell.exe,-101 : Windows PowerShell ISE
@%systemroot%\system32\sysmain.dll,-1000 : SysMain
@%systemroot%\system32\windows.sharedpc.accountmanager.dll,-101 : Manages profiles and accounts on a SharedPC configured device
@%systemroot%\system32\tzautoupdate.dll,-201 : Automatically sets the system time zone.
@%systemroot%\system32\drivers\ndu.sys,-10001 : Windows Network Data Usage Monitoring Driver
@%systemroot%\system32\userdataaccessres.dll,-10002 : Handles storage of structured user data, including contact info, calendars, messages, and other content. If you stop or disable this service, apps that use this data might not work correctly.
@c:\progra~1\common~1\micros~1\office16\oregres.dll,-467 : Office 2016 Upload Center
@%systemroot%\system32\securityhealthagent.dll,-1001 : Windows Security Service handles unified device protection and health information
@%systemroot%\system32\peerdistsvc.dll,-9000 : BranchCache
c:\windows\system32,@elscore.dll,-6 : Microsoft Cyrillic to Latin Transliteration
@comres.dll,-2798 : Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will fail. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\bfe.dll,-1002 : The Base Filtering Engine (BFE) is a service that manages firewall and Internet Protocol security (IPsec) policies and implements user mode filtering. Stopping or disabling the BFE service will significantly reduce the security of the system. It will also result in unpredictable behavior in IPsec management and firewall applications.
@%systemroot%\system32\usermgr.dll,-100 : User Manager
@%systemroot%\system32\wevtsvc.dll,-201 : This service manages events and event logs. It supports logging events, querying events, subscribing to events, archiving event logs, and managing event metadata. It can display events in both XML and plain text format. Stopping this service may compromise security and reliability of the system.
@%systemroot%\system32\drivers\ndisvirtualbus.sys,-200 : Microsoft Virtual Network Adapter Enumerator
@%systemroot%\system32\tieringengineservice.exe,-701 : Optimizes the placement of data in storage tiers on all tiered storage spaces in the system.
@%systemroot%\system32\searchindexer.exe,-103 : Windows Search
@%systemroot%\system32\drivers\wudfrd.sys,-1000 : Windows Driver Foundation - User-mode Driver Framework Reflector
@combase.dll,-5012 : DCOM Server Process Launcher
@%systemroot%\system32\bdesvc.dll,-100 : BitLocker Drive Encryption Service
@%systemroot%\system32\das.dll,-100 : Device Association Service
@%systemroot%\system32\termsrv.dll,-267 : Allows users to connect interactively to a remote computer. Remote Desktop and Remote Desktop Session Host Server depend on this service. To prevent remote use of this computer, clear the checkboxes on the Remote tab of the System properties control panel item.
@%systemroot%\syswow64\perfhost.exe,-1 : Enables remote users and 64-bit processes to query performance counters provided by 32-bit DLLs. If this service is stopped, only local users and 32-bit processes will be able to query performance counters provided by 32-bit DLLs.
@%systemroot%\system32\scdeviceenum.dll,-101 : Creates software device nodes for all smart card readers accessible to a given session. If this service is disabled, WinRT APIs will not be able to enumerate smart card readers.
@%systemroot%\system32\rdxservice.dll,-257 : The Retail Demo service controls device activity while the device is in retail demo mode.
@%systemroot%\system32\rasmans.dll,-200 : Remote Access Connection Manager
@%systemroot%\system32\sdrsvc.dll,-102 : Provides Windows Backup and Restore capabilities.
@c:\windows\system32\msxml3r.dll,-1 : XML Document
@%systemroot%\system32\wdi.dll,-501 : The Diagnostic System Host is used by the Diagnostic Policy Service to host diagnostics that need to run in a Local System context. If this service is stopped, any diagnostics that depend on it will no longer function.
@%systemroot%\system32\drivers\pdc.sys,-100 : PDC
@%systemroot%\system32\dot3svc.dll,-1102 : Wired AutoConfig
@%systemroot%\system32\capabilityaccessmanager.dll,-1 : Capability Access Manager Service
@%systemroot%\system32\ngcctnrsvc.dll,-1 : Microsoft Passport Container
@%systemroot%\system32\gameinputsvc.exe,-101 : GameInput Service
@%systemroot%\system32\spectrum.exe,-101 : Windows Perception Service
@%systemroot%\system32\installservice.dll,-201 : Provides infrastructure support for the Microsoft Store. This service is started on demand and if disabled then installations will not function properly.
@c:\windows\system32\ieframe.dll,-912 : HTML Document
@%systemroot%\system32\drivers\fltmgr.sys,-10001 : FltMgr
@%systemroot%\system32\usosvc.dll,-101 : Update Orchestrator Service
@%systemroot%\system32\pla.dll,-500 : Performance Logs & Alerts
@%systemroot%\system32\alg.exe,-113 : Provides support for 3rd party protocol plug-ins for Internet Connection Sharing
@%systemroot%\system32\bcastdvruserservice.dll,-101 : This user service is used for Game Recordings and Live Broadcasts
@%systemroot%\system32\presentationhost.exe,-3309 : Windows Presentation Foundation Font Cache 3.0.0.0
@%systemroot%\system32\dot3svc.dll,-1103 : The Wired AutoConfig (DOT3SVC) service is responsible for performing IEEE 802.1X authentication on Ethernet interfaces. If your current wired network deployment enforces 802.1X authentication, the DOT3SVC service should be configured to run for establishing Layer 2 connectivity and/or providing access to network resources. Wired networks that do not enforce 802.1X authentication are unaffected by the DOT3SVC service.
@%systemroot%\system32\msimsg.dll,-27 : Windows Installer
@%systemroot%\system32\drivers\tsusbflt.sys,-1000 : Remote Desktop USB Hub Class Filter Driver
@comres.dll,-2946 : KtmRm for Distributed Transaction Coordinator
@%systemroot%\system32\cdpsvc.dll,-100 : Connected Devices Platform Service
@%windir%\system32\rpcepmap.dll,-1002 : Resolves RPC interfaces identifiers to transport endpoints. If this service is stopped or disabled, programs using Remote Procedure Call (RPC) services will not function properly.
@c:\progra~1\common~1\micros~1\office16\oregres.dll,-416 : Office 2016 Language Preferences
@c:\windows\system32\presentationhost.exe,-3300 : Windows Markup File
@%systemroot%\system32\swprv.dll,-102 : Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\wpdbusenum.dll,-101 : Enforces group policy for removable mass-storage devices. Enables applications such as Windows Media Player and Image Import Wizard to transfer and synchronize content using removable mass-storage devices.
@keyiso.dll,-101 : The CNG key isolation service is hosted in the LSA process. The service provides key process isolation to private keys and associated cryptographic operations as required by the Common Criteria. The service stores and uses long-lived keys in a secure process complying with Common Criteria requirements.
@%systemroot%\system32\drivers\bindflt.sys,-100 : Windows Bind Filter Driver
@%systemroot%\system32\xblgamesave.dll,-101 : This service syncs save data for Xbox Live save enabled games. If this service is stopped, game save data will not upload to or download from Xbox Live.
@%systemroot%\system32\embeddedmodesvc.dll,-202 : The Embedded Mode service enables scenarios related to Background Applications. Disabling this service will prevent Background Applications from being activated.
@c:\windows\system32\fxsresm.dll,-114 : Windows Fax and Scan
@cryptext.dll,-6113 : PKCS #7 Signature
@%systemroot%\system32\w32time.dll,-201 : Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\embeddedmodesvc.dll,-201 : Embedded Mode
@%systemroot%\system32\audiosrv.dll,-200 : Windows Audio
@%systemroot%\system32\clipsvc.dll,-104 : Provides infrastructure support for the Microsoft Store. This service is started on demand and if disabled applications bought using Windows Store will not behave correctly.
@%systemroot%\system32\ipnathlp.dll,-107 : Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network.
@%systemroot%\system32\captureservice.dll,-101 : Enables optional screen capture functionality for applications that call the Windows.Graphics.Capture API.
@%systemroot%\system32\firewallcontrolpanel.dll,-12122 : Windows Defender Firewall
@%systemroot%\system32\drivers\vwifibus.sys,-257 : Virtual Wireless Bus Driver
@%systemroot%\system32\dispbroker.desktop.dll,-101 : Display Policy Service
@%systemroot%\system32\rasauto.dll,-201 : Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address.
@c:\windows\system32\quickassist.exe,-806 : Quick Assist
@%systemroot%\system32\netprofmsvc.dll,-203 : Identifies the networks to which the computer has connected, collects and stores properties for these networks, and notifies applications when these properties change.
@%systemroot%\system32\drivers\storqosflt.sys,-101 : Storage QoS Filter Driver
@%systemroot%\system32\sgrmbroker.exe,-101 : Monitors and attests to the integrity of the Windows platform.
@%systemroot%\system32\userdataaccessres.dll,-10003 : User Data Storage
@%systemroot%\system32\fdrespub.dll,-100 : Function Discovery Resource Publication
@%systemroot%\system32\drivers\appvvemgr.sys,-101 : AppvVemgr
@%systemroot%\system32\agentservice.exe,-101 : Provides support for application and OS settings roaming
@%systemroot%\system32\keyboardfiltersvc.dll,-101 : Microsoft Keyboard Filter
@%systemroot%\system32\wbengine.exe,-104 : Block Level Backup Engine Service
@%systemroot%\servicing\trustedinstaller.exe,-101 : Enables installation, modification, and removal of Windows updates and optional components. If this service is disabled, install or uninstall of Windows updates might fail for this computer.
@%systemroot%\system32\pcasvc.dll,-1 : Program Compatibility Assistant Service
@%systemroot%\system32\wdi.dll,-503 : The Diagnostic Service Host is used by the Diagnostic Policy Service to host diagnostics that need to run in a Local Service context. If this service is stopped, any diagnostics that depend on it will no longer function.
@%systemroot%\system32\bthavctpsvc.dll,-101 : AVCTP service
@%programfiles%\windows defender\mpasdesc.dll,-242 : Helps guard against intrusion attempts targeting known and newly discovered vulnerabilities in network protocols
@%systemroot%\system32\windows.management.service.dll,-101 : Performs management including Provisioning and Enrollment activities
@c:\windows\system32\spool\drivers\x64\3\printconfig.dll,-2 : This service opens custom printer dialog boxes and handles notifications from a remote print server or a printer. If you turn off this service, you won’t be able to see printer extensions or notifications.
@%systemroot%\system32\drivers\gpuenergydrv.sys,-100 : GPU Energy Driver
@%systemroot%\system32\xblauthmanager.dll,-101 : Provides authentication and authorization services for interacting with Xbox Live. If this service is stopped, some applications may not operate correctly.
@%systemroot%\system32\wiaservc.dll,-9 : Windows Image Acquisition (WIA)
@%systemroot%\system32\drivers\afd.sys,-1000 : Ancillary Function Driver for Winsock
@%systemroot%\system32\powrprof.dll,-11 : Power saver
@%systemroot%\system32\autotimesvc.dll,-6 : Cellular Time
@comres.dll,-947 : COM+ System Application
@%systemroot%\system32\mprmsg.dll,-32005 : WAN Miniport (L2TP)
@%systemroot%\servicing\trustedinstaller.exe,-100 : Windows Modules Installer
@gpapi.dll,-113 : The service is responsible for applying settings configured by administrators for the computer and users through the Group Policy component. If the service is disabled, the settings will not be applied and applications and components will not be manageable through Group Policy. Any components or applications that depend on the Group Policy component might not be functional if the service is disabled.
@%systemroot%\system32\rasmans.dll,-201 : Manages dial-up and virtual private network (VPN) connections from this computer to the Internet or other remote networks. If this service is disabled, any services that explicitly depend on it will fail to start.
@c:\windows\system32\wdc.dll,-10030 : Resource Monitor
@%systemroot%\system32\certprop.dll,-14 : Allows the system to be configured to lock the user desktop upon smart card removal.
@%systemroot%\system32\windows.devices.picker.dll,-1007 : This user service is used for managing the Miracast, DLNA, and DIAL UI
@%systemroot%\system32\pla.dll,-501 : Performance Logs and Alerts Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\rmapi.dll,-1002 : Radio Management and Airplane Mode Service
@%systemroot%\system32\tokenbroker.dll,-100 : Web Account Manager
c:\windows\system32,@elscore.dll,-2 : Microsoft Script Detection
@combase.dll,-5010 : Remote Procedure Call (RPC)
@%systemroot%\system32\installservice.dll,-200 : Microsoft Store Install Service
@%systemroot%\system32\icsvcext.dll,-501 : Hyper-V Volume Shadow Copy Requestor
@%systemroot%\system32\rdxservice.dll,-256 : Retail Demo Service
@c:\windows\system32\mdsched.exe,-4001 : Windows Memory Diagnostic
@%systemroot%\system32\naturalauth.dll,-100 : Natural Authentication
@%systemroot%\system32\netlogon.dll,-103 : Maintains a secure channel between this computer and the domain controller for authenticating users and services. If this service is stopped, the computer may not authenticate users and services and the domain controller cannot register DNS records. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\scardsvr.dll,-5 : Manages access to smart cards read by this computer. If this service is stopped, this computer will be unable to read smart cards. If this service is disabled, any services that explicitly depend on it will fail to start.
@c:\windows\system32\windowspowershell\v1.0\powershell.exe,-102 : Windows PowerShell ISE (x86)
@comres.dll,-2947 : Coordinates transactions between the Distributed Transaction Coordinator (MSDTC) and the Kernel Transaction Manager (KTM). If it is not needed, it is recommended that this service remain stopped. If it is needed, both MSDTC and KTM will start this service automatically. If this service is disabled, any MSDTC transaction interacting with a Kernel Resource Manager will fail and any services that explicitly depend on it will fail to start.
@%systemroot%\system32\drivers\sgrmagent.sys,-1001 : System Guard Runtime Monitor Agent
@%systemroot%\system32\dnsapi.dll,-101 : DNS Client
c:\windows\system32,@elscore.dll,-9 : Microsoft Bengali to Latin Transliteration
@c:\windows\system32\pmcsnap.dll,-700 : Print Management
@%systemroot%\system32\drivers\hwpolicy.sys,-101 : Hardware Policy Driver
@%systemroot%\system32\shsvcs.dll,-12288 : Shell Hardware Detection
@%programfiles%\windows defender\mpasdesc.dll,-310 : Microsoft Defender Antivirus Service
@%systemroot%\system32\dmwappushsvc.dll,-201 : Routes Wireless Application Protocol (WAP) Push messages received by the device and synchronizes Device Management sessions
@c:\windows\system32\msimsg.dll,-34 : Windows Installer Package
@%systemroot%\system32\mprdim.dll,-200 : Routing and Remote Access
@%systemroot%\system32\nlasvc.dll,-1 : Network Location Awareness
@%systemroot%\system32\srvsvc.dll,-101 : Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\consentuxclient.dll,-100 : ConsentUX
@%systemroot%\system32\icsvcext.dll,-602 : Provides a platform for communication between the virtual machine and the operating system running on the physical computer.
@%systemroot%\system32\appxdeploymentserver.dll,-2 : Provides infrastructure support for deploying Store applications. This service is started on demand and if disabled Store applications will not be deployed to the system, and may not function properly.
c:\windows\system32,@elscore.dll,-8 : Microsoft Malayalam to Latin Transliteration
@%systemroot%\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8200 : Provides ability to share TCP ports over the net.tcp protocol.
@%systemroot%\system32\schedsvc.dll,-101 : Enables a user to configure and schedule automated tasks on this computer. The service also hosts multiple Windows system-critical tasks. If this service is stopped or disabled, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\capabilityaccessmanager.dll,-2 : Provides facilities for managing UWP apps access to app capabilities as well as checking an app's access to specific app capabilities
@%systemroot%\system32\drivers\nwifi.sys,-101 : NativeWiFi Filter
@c:\windows\system32\comres.dll,-3410 : Component Services
@%programfiles%\windows media player\wmpnetwk.exe,-101 : Windows Media Player Network Sharing Service
@%systemroot%\system32\msinfo32.exe,-130 : Display detailed information about your computer.
@%systemroot%\system32\diagtrack.dll,-3002 : The Connected User Experiences and Telemetry service enables features that support in-application and connected user experiences. Additionally, this service manages the event driven collection and transmission of diagnostic and usage information (used to improve the experience and quality of the Windows Platform) when the diagnostics and usage privacy option settings are enabled under Feedback and Diagnostics.
@%systemroot%\system32\printworkflowservice.dll,-101 : Provides support for Print Workflow applications. If you turn off this service, you may not be able to print successfully.
@%systemroot%\system32\ncdautosetup.dll,-100 : Network Connected Devices Auto-Setup
c:\windows\system32,@elscore.dll,-1 : Microsoft Language Detection
@%systemroot%\system32\hidserv.dll,-101 : Human Interface Device Service
@%systemroot%\system32\firewallapi.dll,-23090 : Windows Defender Firewall
@%systemroot%\system32\ngcctnrsvc.dll,-2 : Manages local user identity keys used to authenticate user to identity providers as well as TPM virtual smart cards. If this service is disabled, local user identity keys and TPM virtual smart cards will not be accessible. It is recommended that you do not reconfigure this service.
@c:\windows\system32\mycomput.dll,-300 : Computer Management
@%systemroot%\system32\quickassist.exe,-807 : Connect to another user's computer to help troubleshoot problems
@%systemroot%\system32\drivers\mshidumdf.sys,-100 : Pass-through HID to UMDF Driver
@%systemroot%\system32\swprv.dll,-103 : Microsoft Software Shadow Copy Provider
@windows.storage.dll,-21824 : Camera Roll
@%systemroot%\system32\scdeviceenum.dll,-100 : Smart Card Device Enumeration Service
@gpapi.dll,-112 : Group Policy Client
@%systemroot%\system32\wkssvc.dll,-1008 : DFS Namespace Client Driver
@%systemroot%\system32\eapsvc.dll,-1 : Extensible Authentication Protocol
@%systemroot%\system32\naturalauth.dll,-101 : Signal aggregator service, that evaluates signals based on time, network, geolocation, bluetooth and cdf factors. Supported features are Device Unlock, Dynamic Lock and Dynamo MDM policies
@%systemroot%\system32\eapsvc.dll,-2 : The Extensible Authentication Protocol (EAP) service provides network authentication in such scenarios as 802.1x wired and wireless, VPN, and Network Access Protection (NAP). EAP also provides application programming interfaces (APIs) that are used by network access clients, including wireless and VPN clients, during the authentication process. If you disable this service, this computer is prevented from accessing networks that require EAP authentication.
@%systemroot%\system32\drivers\uevagentdriver.sys,-101 : UevAgentDriver
@%systemroot%\system32\locator.exe,-3 : In Windows 2003 and earlier versions of Windows, the Remote Procedure Call (RPC) Locator service manages the RPC name service database. In Windows Vista and later versions of Windows, this service does not provide any functionality and is present for application compatibility.
@%systemroot%\system32\microsoft.graphics.display.displayenhancementservice.dll,-1001 : A service for managing display enhancement such as brightness control.
@%systemroot%\system32\wercplsupport.dll,-100 : This service provides support for viewing, sending and deletion of system-level problem reports for the Problem Reports control panel.
@%systemroot%\system32\w32time.dll,-200 : Windows Time
c:\windows\system32,@elscore.dll,-5 : Microsoft Transliteration Engine
@%systemroot%\system32\cscsvc.dll,-200 : Offline Files
@%systemroot%\system32\microsoft.bluetooth.userservice.dll,-102 : The Bluetooth user service supports proper functionality of Bluetooth features relevant to each user session.
@%systemroot%\system32\drivers\clfs.sys,-100 : Common Log (CLFS)
@waasmedicsvc.dll,-100 : Windows Update Medic Service
@%systemroot%\system32\drivers\ndis.sys,-200 : NDIS System Driver
@%systemroot%\system32\usosvc.dll,-102 : Manages Windows Updates. If stopped, your devices will not be able to download and install the latest updates.
@%windir%\immersivecontrolpanel\systemsettings.exe,-651 : Change settings and customize the functionality of your computer
@%systemroot%\system32\tetheringservice.dll,-4098 : Provides the ability to share a cellular data connection with another device.
@%systemroot%\system32\windowsudk.shellcommon.dll,-100 : Udk User Service
@%systemroot%\system32\ncasvc.dll,-3008 : Provides DirectAccess status notification for UI components
@%systemroot%\system32\drivers\wudfpf.sys,-1000 : User Mode Driver Frameworks Platform Driver
@firewallapi.dll,-50323 : SNMP Trap
@%systemroot%\system32\wdi.dll,-500 : Diagnostic System Host
@%systemroot%\system32\fdrespub.dll,-101 : Publishes this computer and resources attached to this computer so they can be discovered over the network. If this service is stopped, network resources will no longer be published and they will not be discovered by other computers on the network.
@%windir%\system32\bisrv.dll,-101 : Windows infrastructure service that controls which background tasks can run on the system.
@%systemroot%\system32\drivers\hvservice.sys,-16 : Hypervisor/Virtual Machine Support Driver
@%systemroot%\system32\wiaservc.dll,-10 : Provides image acquisition services for scanners and cameras
@%systemroot%\system32\certprop.dll,-12 : Copies user certificates and root certificates from smart cards into the current user's certificate store, detects when a smart card is inserted into a smart card reader, and, if needed, installs the smart card Plug and Play minidriver.
@%systemroot%\system32\hnetcfgclient.dll,-201 : HNetCfg Client
@%systemroot%\system32\pnrpsvc.dll,-8000 : Peer Name Resolution Protocol
@%systemroot%\system32\autotimesvc.dll,-7 : This service sets time based on NITZ messages from a Mobile Network
@%systemroot%\system32\iscsidsc.dll,-5000 : Microsoft iSCSI Initiator Service
@%systemroot%\system32\windowspowershell\v1.0\powershell.exe,-124 : Document Encryption
@%systemroot%\system32\trkwks.dll,-2 : Maintains links between NTFS files within a computer or across computers in a network.
@%systemroot%\system32\appvclient.exe,-101 : Manages App-V users and virtual applications
@c:\windows\system32\unregmp2.exe,-9935 : MPEG-2 TS Video
@c:\progra~1\pcheal~1\pcheal~1.exe,-130 : PC Health Check
@%systemroot%\system32\wpcrefreshtask.dll,-101 : Enforces parental controls for child accounts in Windows. If this service is stopped or disabled, parental controls may not be enforced.
@%systemroot%\system32\drivers\cnghwassist.sys,-100 : CNG Hardware Assist algorithm provider
@%systemroot%\system32\svsvc.dll,-102 : Verifies potential file system corruptions.
@%systemroot%\system32\lltdres.dll,-2 : Creates a Network Map, consisting of PC and device topology (connectivity) information, and metadata describing each PC and device. If this service is disabled, the Network Map will not function properly.
@%systemroot%\system32\powrprof.dll,-15 : Balanced
@%systemroot%\system32\lltdres.dll,-5 : Link-Layer Topology Discovery Responder
@c:\windows\regedit.exe,-16 : Registry Editor
@%systemroot%\system32\tetheringservice.dll,-4097 : Windows Mobile Hotspot Service
@%systemroot%\system32\drivers\appvvfs.sys,-101 : AppvVfs
@%systemroot%\system32\mitigationclient.dll,-104 : Enables automatic mitigation for known problems by applying recommended troubleshooting. If stopped, your device will not get recommended troubleshooting for problems on your device.
@%systemroot%\system32\windows.warp.jitservice.dll,-100 : WarpJITSvc
c:\windows\system32,@elscore.dll,-4 : Microsoft Simplified Chinese to Traditional Chinese Transliteration
@%systemroot%\system32\drivers\http.sys,-1 : HTTP Service
@%systemroot%\system32\sessenv.dll,-1027 : Remote Desktop Configuration service (RDCS) is responsible for all Remote Desktop Services and Remote Desktop related configuration and session maintenance activities that require SYSTEM context. These include per-session temporary folders, RD themes, and RD certificates.
@%systemroot%\system32\windowsudk.shellcommon.dll,-101 : Shell components service
@%programfiles%\windows defender\mpasdesc.dll,-240 : Helps protect users from malware and other potentially unwanted software
@winlangdb.dll,-1121 : English (United States)
@%systemroot%\system32\rasauto.dll,-200 : Remote Access Auto Connection Manager
@%systemroot%\system32\wbengine.exe,-105 : The WBENGINE service is used by Windows Backup to perform backup and recovery operations. If this service is stopped by a user, it may cause the currently running backup or recovery operation to fail. Disabling this service may disable backup and recovery operations using Windows Backup on this computer.
@%systemroot%\system32\mprdim.dll,-201 : Offers routing services to businesses in local area and wide area network environments.
@%systemroot%\system32\defragsvc.dll,-101 : Optimize drives
@%systemroot%\system32\presentationhost.exe,-3310 : Optimizes performance of Windows Presentation Foundation (WPF) applications by caching commonly used font data. WPF applications will start this service if it is not already running. It can be disabled, though doing so will degrade the performance of WPF applications.
@%systemroot%\system32\dcsvc.dll,-102 : Process Declared Configuration documents recevied from MDM and other channels and perform configurations on device
@%systemroot%\system32\mprmsg.dll,-32001 : Remote Access NDIS TAPI Driver
@%systemroot%\system32\fxsresm.dll,-122 : Enables you to send and receive faxes, utilizing fax resources available on this computer or on the network.
@%systemroot%\system32\fveui.dll,-844 : BitLocker Data Recovery Agent
@%systemroot%\system32\drivers\mssecflt.sys,-1001 : Microsoft Security Events Component Minifilter
@%systemroot%\system32\icsvc.dll,-801 : Hyper-V Guest Service Interface
@%systemroot%\system32\diagsvcs\diagnosticshub.standardcollector.serviceres.dll,-1000 : Microsoft (R) Diagnostics Hub Standard Collector Service
@%systemroot%\system32\wsmsvc.dll,-101 : Windows Remote Management (WS-Management)
@%systemroot%\system32\ssdpsrv.dll,-100 : SSDP Discovery
@%systemroot%\system32\drivers\indirectkmd.sys,-100 : Indirect Displays Kernel-Mode Driver
@%systemroot%\system32\pnrpsvc.dll,-8005 : Provides identity services for the Peer Name Resolution Protocol (PNRP) and Peer-to-Peer Grouping services. If disabled, the Peer Name Resolution Protocol (PNRP) and Peer-to-Peer Grouping services may not function, and some applications, such as HomeGroup and Remote Assistance, may not function correctly.
@c:\windows\system32\spool\drivers\x64\3\printconfig.dll,-1 : Printer Extensions and Notifications
@%systemroot%\system32\vssvc.exe,-101 : Manages and implements Volume Shadow Copies used for backup and other purposes. If this service is stopped, shadow copies will be unavailable for backup and the backup may fail. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\peerdistsvc.dll,-9001 : This service caches network content from peers on the local subnet.
@%systemroot%\system32\storsvc.dll,-101 : Provides enabling services for storage settings and external storage expansion
@%systemroot%\system32\credentialenrollmentmanager.exe,-100 : CredentialEnrollmentManagerUserSvc
@%systemroot%\system32\lpasvc.dll,-1000 : Local Profile Assistant Service
@%systemroot%\system32\captureservice.dll,-100 : CaptureService
@%windir%\regedit.exe,-16 : Registry Editor
@%systemroot%\system32\webclnt.dll,-104 : WebDav Client Redirector Driver
@%systemroot%\system32\webclnt.dll,-100 : WebClient
@c:\windows\system32\wsecedit.dll,-718 : Local Security Policy
@%systemroot%\system32\smphost.dll,-102 : Microsoft Storage Spaces SMP
@%systemroot%\system32\drivers\netbt.sys,-2 : NETBT
@%systemroot%\system32\drivers\fileinfo.sys,-100 : File Information FS MiniFilter
@%systemroot%\system32\drivers\wcifs.sys,-100 : Windows Container Isolation
@%systemroot%\system32\drivers\ahcache.sys,-102 : Application Compatibility Cache
@%systemroot%\system32\axinstsv.dll,-104 : Provides User Account Control validation for the installation of ActiveX controls from the Internet and enables management of ActiveX control installation based on Group Policy settings. This service is started on demand and if disabled the installation of ActiveX controls will behave according to default browser settings.
@%systemroot%\system32\windows.internal.management.dll,-100 : Device Management Enrollment Service
@%systemroot%\system32\languageoverlayserver.dll,-100 : Language Experience Service
@enterpriseappmgmtsvc.dll,-2 : Enables enterprise application management.
@%systemroot%\system32\wpdbusenum.dll,-100 : Portable Device Enumerator Service
@%systemroot%\system32\wercplsupport.dll,-101 : Problem Reports Control Panel Support
@%systemroot%\system32\srpapi.dll,-102 : Smartlocker Filter Driver
@%systemroot%\system32\netsetupsvc.dll,-3 : Network Setup Service
@%systemroot%\system32\webclnt.dll,-101 : Enables Windows-based programs to create, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start.
@c:\windows\system32\ieframe.dll,-10046 : Internet Shortcut
@%programfiles%\windows defender\mpasdesc.dll,-330 : Microsoft Defender Antivirus Mini-Filter Driver
@%systemroot%\system32\wdc.dll,-10031 : Monitor the usage and performance of the following resources in real time: CPU, Disk, Network and Memory.
@%systemroot%\system32\windows.management.service.dll,-100 : Windows Management Service
@%systemroot%\system32\cscsvc.dll,-201 : The Offline Files service performs maintenance activities on the Offline Files cache, responds to user logon and logoff events, implements the internals of the public API, and dispatches interesting events to those interested in Offline Files activities and changes in cache state.
@comres.dll,-2450 : COM+ Event System
@%systemroot%\system32\userdataaccessres.dll,-15001 : Contact Data
@%systemroot%\system32\tabsvc.dll,-101 : Enables Touch Keyboard and Handwriting Panel pen and ink functionality
@%systemroot%\system32\powrprof.dll,-14 : Automatically balances performance with energy consumption on capable hardware.
@%systemroot%\system32\msconfig.exe,-6001 : Perform advanced troubleshooting and system configuration
@%systemroot%\system32\wkssvc.dll,-2001 : Browser
@%systemroot%\system32\ngcsvc.dll,-101 : Provides process isolation for cryptographic keys used to authenticate to a user’s associated identity providers. If this service is disabled, all uses and management of these keys will not be available, which includes machine logon and single-sign on for apps and websites. This service starts and stops automatically. It is recommended that you do not reconfigure this service.
@%systemroot%\system32\wlansvc.dll,-258 : The WLANSVC service provides the logic required to configure, discover, connect to, and disconnect from a wireless local area network (WLAN) as defined by IEEE 802.11 standards. It also contains the logic to turn your computer into a software access point so that other devices or computers can connect to your computer wirelessly using a WLAN adapter that can support this. Stopping or disabling the WLANSVC service will make all WLAN adapters on your computer inaccessible from the Windows networking UI. It is strongly recommended that you have the WLANSVC service running if your computer has a WLAN adapter.
@%systemroot%\system32\wbem\wmisvc.dll,-205 : Windows Management Instrumentation
@%systemroot%\system32\walletservice.dll,-1001 : Hosts objects used by clients of the wallet
@%systemroot%\system32\icsvc.dll,-102 : Monitors the state of this virtual machine by reporting a heartbeat at regular intervals. This service helps you identify running virtual machines that have stopped responding.
@c:\windows\system32\notepad.exe,-469 : Text Document
@%systemroot%\system32\cbdhsvc.dll,-101 : This user service is used for Clipboard scenarios
@c:\windows\system32\odbcint.dll,-1694 : ODBC Data Sources (64-bit)
@c:\windows\system32\windows.ui.immersive.dll,-38304 : Public Account Pictures
@%systemroot%\system32\dnsapi.dll,-103 : Domain Name System (DNS) Server Trust
@searchfolder.dll,-32822 : Everywhere
@%systemroot%\system32\icsvc.dll,-401 : Hyper-V Time Synchronization Service
@%systemroot%\system32\wbiosrvc.dll,-101 : The Windows biometric service gives client applications the ability to capture, compare, manipulate, and store biometric data without gaining direct access to any biometric hardware or samples. The service is hosted in a privileged SVCHOST process.
@%systemroot%\system32\appinfo.dll,-101 : Facilitates the running of interactive applications with additional administrative privileges. If this service is stopped, users will be unable to launch applications with the additional administrative privileges they may require to perform desired user tasks.
@%systemroot%\system32\srvsvc.dll,-104 : Server SMB 2.xxx Driver
@%systemroot%\system32\searchindexer.exe,-104 : Provides content indexing, property caching, and search results for files, e-mail, and other content.
@%systemroot%\system32\ncbservice.dll,-500 : Network Connection Broker
@%systemroot%\system32\msimsg.dll,-32 : Adds, modifies, and removes applications provided as a Windows Installer (*.msi, *.msp) package. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\coremessaging.dll,-2 : Manages communication between system components.
@%systemroot%\system32\drivers\bam.sys,-100 : Background Activity Moderator Driver
@%systemroot%\system32\mprmsg.dll,-32002 : Remote Access NDIS WAN Driver
@%systemroot%\system32\bcastdvruserservice.dll,-100 : GameDVR and Broadcast User Service
@%systemroot%\system32\umrdp.dll,-1001 : Allows the redirection of Printers/Drives/Ports for RDP connections
@%systemroot%\system32\sensordataservice.exe,-102 : Delivers data from a variety of sensors
@%systemroot%\system32\icsvc.dll,-902 : Provides a mechanism to manage virtual machine with PowerShell via VM session without a virtual network.
@%systemroot%\system32\drivers\wfplwfs.sys,-6000 : Microsoft Windows Filtering Platform
@%systemroot%\system32\efssvc.dll,-101 : Provides the core file encryption technology used to store encrypted files on NTFS file system volumes. If this service is stopped or disabled, applications will be unable to access encrypted files.
@%systemroot%\system32\appvclient.exe,-102 : Microsoft App-V Client
@%systemroot%\system32\flightsettings.dll,-103 : Windows Insider Service
@%systemroot%\system32\spectrum.exe,-102 : Enables spatial perception, spatial input, and holographic rendering.
@%systemroot%\system32\ncdautosetup.dll,-101 : Network Connected Devices Auto-Setup service monitors and installs qualified devices that connect to a qualified network. Stopping or disabling this service will prevent Windows from discovering and installing qualified network connected devices automatically. Users can still manually add network connected devices to a PC through the user interface.
@%systemroot%\system32\wwansvc.dll,-257 : WWAN AutoConfig
@%systemroot%\system32\wsmsvc.dll,-102 : Windows Remote Management (WinRM) service implements the WS-Management protocol for remote management. WS-Management is a standard web services protocol used for remote software and hardware management. The WinRM service listens on the network for WS-Management requests and processes them. The WinRM Service needs to be configured with a listener using winrm.cmd command line tool or through Group Policy in order for it to listen over the network. The WinRM service provides access to WMI data and enables event collection. Event collection and subscription to events require that the service is running. WinRM messages use HTTP and HTTPS as transports. The WinRM service does not depend on IIS but is preconfigured to share a port with IIS on the same machine. The WinRM service reserves the /wsman URL prefix. To prevent conflicts with IIS, administrators should ensure that any websites hosted on IIS do not use the /wsman URL prefix.
@%systemroot%\system32\mprmsg.dll,-32007 : Remote Access PPPOE Driver
@appmgmts.dll,-3251 : Processes installation, removal, and enumeration requests for software deployed through Group Policy. If the service is disabled, users will be unable to install, remove, or enumerate software deployed through Group Policy. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\ngcsvc.dll,-100 : Microsoft Passport
@%systemroot%\system32\wscsvc.dll,-201 : The WSCSVC (Windows Security Center) service monitors and reports security health settings on the computer. The health settings include firewall (on/off), antivirus (on/off/out of date), antispyware (on/off/out of date), Windows Update (automatically/manually download and install updates), User Account Control (on/off), and Internet settings (recommended/not recommended). The service provides COM APIs for independent software vendors to register and record the state of their products to the Security Center service. The Security and Maintenance UI uses the service to provide systray alerts and a graphical view of the security health states in the Security and Maintenance control panel. Network Access Protection (NAP) uses the service to report the security health states of clients to the NAP Network Policy Server to make network quarantine decisions. The service also has a public API that allows external consumers to programmatically retrieve the aggregated security health state of the system.
@%systemroot%\system32\sensorservice.dll,-1000 : Sensor Service
@%systemroot%\system32\tokenbroker.dll,-101 : This service is used by Web Account Manager to provide single-sign-on to apps and services.
@%systemroot%\system32\dps.dll,-500 : Diagnostic Policy Service
@%systemroot%\system32\sensordataservice.exe,-101 : Sensor Data Service
@%systemroot%\system32\printworkflowservice.dll,-100 : PrintWorkflow
@%systemroot%\system32\cdpsvc.dll,-101 : This service is used for Connected Devices Platform scenarios
@%systemroot%\system32\sppsvc.exe,-101 : Software Protection
@comres.dll,-2451 : Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\drivers\ndiscap.sys,-5000 : Microsoft NDIS Capture
@%systemroot%\system32\mitigationclient.dll,-103 : Recommended Troubleshooting Service
@%systemroot%\system32\ajrouter.dll,-1 : Routes AllJoyn messages for the local AllJoyn clients. If this service is stopped the AllJoyn clients that do not have their own bundled routers will be unable to run.
@%systemroot%\system32\wecsvc.dll,-201 : This service manages persistent subscriptions to events from remote sources that support WS-Management protocol. This includes Windows Vista event logs, hardware and IPMI-enabled event sources. The service stores forwarded events in a local Event Log. If this service is stopped or disabled event subscriptions cannot be created and forwarded events cannot be accepted.
@%systemroot%\system32\pushtoinstall.dll,-201 : Provides infrastructure support for the Microsoft Store. This service is started automatically and if disabled then remote installations will not function properly.
@%systemroot%\system32\cscsvc.dll,-202 : Offline Files Driver
@%systemroot%\system32\icsvcext.dll,-601 : Hyper-V Remote Desktop Virtualization Service
@%windir%\system32\drivers\netbios.sys,-503 : NetBIOS Interface
@%systemroot%\system32\lmhsvc.dll,-102 : Provides support for the NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution for clients on the network, therefore enabling users to share files, print, and log on to the network. If this service is stopped, these functions might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\wbem\wmiapsrv.exe,-110 : WMI Performance Adapter
@c:\windows\immersivecontrolpanel\systemsettings.exe,-650 : Settings
@%systemroot%\system32\icsvc.dll,-901 : Hyper-V PowerShell Direct Service
@%systemroot%\system32\psr.exe,-1702 : Capture steps with screenshots to save or share.
c:\windows\system32,@elscore.dll,-3 : Microsoft Traditional Chinese to Simplified Chinese Transliteration
@%systemroot%\system32\umpnpmgr.dll,-101 : Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability.
@%systemroot%\system32\polstore.dll,-5011 : Internet Protocol security (IPsec) supports network-level peer authentication, data origin authentication, data integrity, data confidentiality (encryption), and replay protection. This service enforces IPsec policies created through the IP Security Policies snap-in or the command-line tool ""netsh ipsec"". If you stop this service, you may experience network connectivity issues if your policy requires that connections use IPsec. Also,remote management of Windows Defender Firewall is not available when this service is stopped.
@%systemroot%\system32\windows.sharedpc.accountmanager.dll,-100 : Shared PC Account Manager
@%systemroot%\system32\wpnuserservice.dll,-1 : Windows Push Notifications User Service
@%systemroot%\system32\windows.staterepository.dll,-2 : Provides required infrastructure support for the application model.
@%systemroot%\system32\winhttp.dll,-101 : WinHTTP implements the client HTTP stack and provides developers with a Win32 API and COM Automation component for sending HTTP requests and receiving responses. In addition, WinHTTP provides support for auto-discovering a proxy configuration via its implementation of the Web Proxy Auto-Discovery (WPAD) protocol.
@%systemroot%\system32\iscsidsc.dll,-5001 : Manages Internet SCSI (iSCSI) sessions from this computer to remote iSCSI target devices. If this service is stopped, this computer will not be able to login or access iSCSI targets. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\appidsvc.dll,-100 : Application Identity
@%systemroot%\system32\icsvc.dll,-402 : Synchronizes the system time of this virtual machine with the system time of the physical computer.
@%systemroot%\system32\drivers\mountmgr.sys,-100 : Mount Point Manager
@%systemroot%\system32\keyboardfiltersvc.dll,-102 : Controls keystroke filtering and mapping
@%systemroot%\system32\icsvc.dll,-302 : Provides a mechanism to shut down the operating system of this virtual machine from the management interfaces on the physical computer.
@c:\windows\system32\iscsicpl.dll,-5001 : iSCSI Initiator
@%systemroot%\system32\hvhostsvc.dll,-101 : Provides an interface for the Hyper-V hypervisor to provide per-partition performance counters to the host operating system.
@%systemroot%\system32\icsvc.dll,-201 : Hyper-V Data Exchange Service
@%systemroot%\system32\dosvc.dll,-101 : Performs content delivery optimization tasks
@%systemroot%\system32\iphlpsvc.dll,-501 : Provides tunnel connectivity using IPv6 transition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS. If this service is stopped, the computer will not have the enhanced connectivity benefits that these technologies offer.
@%systemroot%\system32\pnrpsvc.dll,-8004 : Peer Networking Identity Manager
@%systemroot%\system32\drivers\wcnfs.sys,-100 : Windows Container Name Virtualization
@%systemroot%\system32\cdpusersvc.dll,-100 : Connected Devices Platform User Service
@c:\progra~1\common~1\micros~1\office16\oregres.dll,-315 : OneDrive for Business
@%systemroot%\system32\shell32.dll,-50176 : File Operation
@%systemroot%\system32\audiosrv.dll,-201 : Manages audio for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start
@c:\windows\system32\msconfig.exe,-5006 : System Configuration
@%systemroot%\system32\samsrv.dll,-2 : The startup of this service signals other services that the Security Accounts Manager (SAM) is ready to accept requests. Disabling this service will prevent other services in the system from being notified when the SAM is ready, which may in turn cause those services to fail to start correctly. This service should not be disabled.
@%systemroot%\system32\bridgeres.dll,-1 : Microsoft MAC Bridge
@searchfolder.dll,-32820 : Indexed Locations
@%systemroot%\system32\lpasvc.dll,-1001 : This service provides profile management for subscriber identity modules
@windows.storage.dll,-21826 : Captures
@%windir%\system32\systemeventsbrokerserver.dll,-1001 : System Events Broker
@%systemroot%\system32\appidsvc.dll,-101 : Determines and verifies the identity of an application. Disabling this service will prevent AppLocker from being enforced.
@%systemroot%\system32\languageoverlayserver.dll,-101 : Provides infrastructure support for deploying and configuring localized Windows resources. This service is started on demand and, if disabled, additional Windows languages will not be deployed to the system, and Windows may not function properly.
@%systemroot%\system32\cdpusersvc.dll,-101 : This user service is used for Connected Devices Platform scenarios
@%systemroot%\system32\drivers\partmgr.sys,-100 : Partition driver
@%systemroot%\system32\wbiosrvc.dll,-100 : Windows Biometric Service
@%systemroot%\system32\ipxlatcfg.dll,-500 : IP Translation Configuration Service
@%programfiles%\windows defender\mpasdesc.dll,-390 : Microsoft Defender Antivirus Boot Driver
@%systemroot%\system32\certprop.dll,-11 : Certificate Propagation
@c:\windows\system32\ulib.dll,-1000 : Recovered File Fragments
@%systemroot%\system32\pnrpsvc.dll,-8001 : Enables serverless peer name resolution over the Internet using the Peer Name Resolution Protocol (PNRP). If disabled, some peer-to-peer and collaborative applications, such as Remote Assistance, may not function.
@%systemroot%\system32\appreadiness.dll,-1001 : Gets apps ready for use the first time a user signs in to this PC and when adding new apps.
@%systemroot%\system32\wephostsvc.dll,-100 : Windows Encryption Provider Host Service
@%systemroot%\system32\wkssvc.dll,-100 : Workstation
c:\windows\system32,@elscore.dll,-10 : Microsoft Hangul Decomposition Transliteration
@%systemroot%\system32\audioendpointbuilder.dll,-205 : Manages audio devices for the Windows Audio service. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start
@c:\windows\system32\recoverydrive.exe,-500 : Recovery Drive
@%systemroot%\system32\mprmsg.dll,-32013 : IP Traffic Filter Driver
@%systemroot%\system32\firewallapi.dll,-23091 : Windows Defender Firewall helps protect your computer by preventing unauthorized users from gaining access to your computer through the Internet or a network.
@c:\windows\system32\searchfolder.dll,-9023 : Saved Search
@%systemroot%\system32\cbdhsvc.dll,-100 : Clipboard User Service
@%systemroot%\system32\ikeext.dll,-502 : The IKEEXT service hosts the Internet Key Exchange (IKE) and Authenticated Internet Protocol (AuthIP) keying modules. These keying modules are used for authentication and key exchange in Internet Protocol security (IPsec). Stopping or disabling the IKEEXT service will disable IKE and AuthIP key exchange with peer computers. IPsec is typically configured to use IKE or AuthIP; therefore, stopping or disabling the IKEEXT service might result in an IPsec failure and might compromise the security of the system. It is strongly recommended that you have the IKEEXT service running.
@%systemroot%\system32\dcsvc.dll,-101 : Declared Configuration(DC) service
@%programfiles%\windows defender advanced threat protection\mssense.exe,-1002 : Windows Defender Advanced Threat Protection service helps protect against advanced threats by monitoring and reporting security events that happen on the computer.
@%systemroot%\system32\wdc.dll,-10025 : Diagnose performance issues and collect performance data.
@%systemroot%\syswow64\perfhost.exe,-2 : Performance Counter DLL Host
@%systemroot%\system32\moshost.dll,-100 : Downloaded Maps Manager
@%systemroot%\system32\wephostsvc.dll,-101 : Windows Encryption Provider Host Service brokers encryption related functionalities from 3rd Party Encryption Providers to processes that need to evaluate and apply EAS policies. Stopping this will compromise EAS compliancy checks that have been established by the connected Mail Accounts
@%systemroot%\system32\nsisvc.dll,-201 : This service delivers network notifications (e.g. interface addition/deleting etc) to user mode clients. Stopping this service will cause loss of network connectivity. If this service is disabled, any other services that explicitly depend on this service will fail to start.
@%systemroot%\system32\drivers\luafv.sys,-100 : UAC File Virtualization
@%systemroot%\system32\pushtoinstall.dll,-200 : Windows PushToInstall Service
@%systemroot%\system32\mprmsg.dll,-32000 : RAS Asynchronous Media Driver
@%systemroot%\system32\netsetupsvc.dll,-4 : The Network Setup Service manages the installation of network drivers and permits the configuration of low-level network settings. If this service is stopped, any driver installations that are in-progress may be cancelled.
@%systemroot%\system32\drivers\mshidkmdf.sys,-100 : Pass-through HID to KMDF Filter Driver
@%systemroot%\system32\semgrsvc.dll,-1002 : Manages payments and Near Field Communication (NFC) based secure elements.
@%systemroot%\system32\dialogblockingservice.dll,-100 : DialogBlockingService
@%systemroot%\system32\smsroutersvc.dll,-10001 : Microsoft Windows SMS Router Service.
@%systemroot%\system32\wersvc.dll,-100 : Windows Error Reporting Service
@%systemroot%\system32\securityhealthagent.dll,-1002 : Windows Security Service
@%commonprogramfiles%\microsoft shared\ink\mip.exe,-292 : Math Input Panel
@%systemroot%\system32\wuaueng.dll,-106 : Enables the detection, download, and installation of updates for Windows and other programs. If this service is disabled, users of this computer will not be able to use Windows Update or its automatic updating feature, and programs will not be able to use the Windows Update Agent (WUA) API.
@%systemroot%\system32\ncasvc.dll,-3009 : Network Connectivity Assistant
@c:\program files\common files\system\wab32res.dll,-10100 : Contacts
@regsvc.dll,-1 : Remote Registry
@%systemroot%\system32\microsoft.graphics.display.displayenhancementservice.dll,-1000 : Display Enhancement Service
@%systemroot%\system32\appreadiness.dll,-1000 : App Readiness
@%systemroot%\system32\wcmsvc.dll,-4097 : Windows Connection Manager
@%systemroot%\system32\cryptsvc.dll,-1002 : Provides three management services: Catalog Database Service, which confirms the signatures of Windows files and allows new programs to be installed; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Automatic Root Certificate Update Service, which retrieves root certificates from Windows Update and enable scenarios such as SSL. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8201 : Net.Tcp Port Sharing Service
@%systemroot%\system32\umpo.dll,-101 : Manages power policy and power policy notification delivery.
@%systemroot%\system32\p2psvc.dll,-8007 : Enables multi-party communication using Peer-to-Peer Grouping. If disabled, some applications, such as HomeGroup, may not function.
@%systemroot%\system32\vds.exe,-100 : Virtual Disk
@%systemroot%\system32\pmcsnap.dll,-710 : Manages local printers and remote print servers.
@%systemroot%\system32\drivers\filecrypt.sys,-100 : FileCrypt
@appmgmts.dll,-3250 : Application Management
@%systemroot%\system32\powrprof.dll,-13 : High performance
@enterpriseappmgmtsvc.dll,-1 : Enterprise App Management Service
@%systemroot%\system32\recoverydrive.exe,-600 : Create a recovery drive
@%systemroot%\system32\icsvc.dll,-802 : Provides an interface for the Hyper-V host to interact with specific services running inside the virtual machine.
@%systemroot%\system32\wiarpc.dll,-1 : Launches applications associated with still image acquisition events.
@%systemroot%\system32\sharedrealitysvc.dll,-100 : Spatial Data Service
@%systemroot%\system32\graphicsperfsvc.dll,-100 : GraphicsPerfSvc
@%systemroot%\system32\drivers\fvevol.sys,-100 : BitLocker Drive Encryption Filter Driver
@%systemroot%\system32\mixedrealityruntime.dll,-102 : Enables Mixed Reality OpenXR runtime functionality
@%systemroot%\system32\drivers\mssecwfp.sys,-1001 : Microsoft Security WFP Callout Driver
@%systemroot%\system32\lfsvc.dll,-1 : Geolocation Service
@firewallapi.dll,-50324 : Receives trap messages generated by local or remote Simple Network Management Protocol (SNMP) agents and forwards the messages to SNMP management programs running on this computer. If this service is stopped, SNMP-based programs on this computer will not receive SNMP trap messages. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\drivers\mup.sys,-101 : MUP
@%systemroot%\system32\audioendpointbuilder.dll,-204 : Windows Audio Endpoint Builder
@%systemroot%\system32\drivers\wimmount.sys,-101 : WIMMount
@%systemroot%\system32\aarsvc.dll,-100 : Agent Activation Runtime
@%systemroot%\system32\moshost.dll,-101 : Windows service for application access to downloaded maps. This service is started on-demand by application accessing downloaded maps. Disabling this service will prevent apps from accessing maps.
@%systemroot%\system32\drivers\vwififlt.sys,-259 : Virtual WiFi Filter Driver
@%systemroot%\system32\messagingservice.dll,-100 : MessagingService
@%systemroot%\system32\scardsvr.dll,-1 : Smart Card
@c:\windows\system32\wdc.dll,-10021 : Performance Monitor
@c:\windows\system32\miguiresource.dll,-201 : Task Scheduler
@%systemroot%\system32\drivers\dam.sys,-100 : Desktop Activity Moderator Driver
@%systemroot%\system32\dps.dll,-501 : The Diagnostic Policy Service enables problem detection, troubleshooting and resolution for Windows components. If this service is stopped, diagnostics will no longer function.
@%windir%\system32\lsm.dll,-1002 : Core Windows Service that manages local user sessions. Stopping or disabling this service will result in system instability.
@%systemroot%\system32\deviceaccess.dll,-107 : DeviceAssociationBroker
@%systemroot%\system32\wwansvc.dll,-258 : This service manages mobile broadband (GSM & CDMA) data card/embedded module adapters and connections by auto-configuring the networks. It is strongly recommended that this service be kept running for best user experience of mobile broadband devices.
@%systemroot%\system32\cloudidsvc.dll,-101 : Supports integrations with Microsoft cloud identity services. If disabled, tenant restrictions will not be enforced properly.
@%systemroot%\system32\windows.staterepository.dll,-1 : State Repository Service
@%systemroot%\system32\lltdres.dll,-1 : Link-Layer Topology Discovery Mapper
@%systemroot%\system32\btagservice.dll,-101 : Bluetooth Audio Gateway Service
@%systemroot%\system32\srpapi.dll,-100 : AppID Driver
@%systemroot%\system32\usermgr.dll,-101 : User Manager provides the runtime components required for multi-user interaction. If this service is stopped, some applications may not operate correctly.
@%systemroot%\system32\ajrouter.dll,-2 : AllJoyn Router Service
@%systemroot%\system32\wecsvc.dll,-200 : Windows Event Collector
@%systemroot%\system32\dusmsvc.dll,-2 : Network data usage, data limit, restrict background data, metered networks.
@%systemroot%\system32\drivers\nsiproxy.sys,-2 : NSI Proxy Service Driver
@%systemroot%\system32\sens.dll,-201 : Monitors system events and notifies subscribers to COM+ Event System of these events.
@%systemroot%\system32\bthserv.dll,-102 : The Bluetooth service supports discovery and association of remote Bluetooth devices. Stopping or disabling this service may cause already installed Bluetooth devices to fail to operate properly and prevent new devices from being discovered or associated.
@%systemroot%\system32\drivers\tcpip.sys,-10001 : TCP/IP Protocol Driver
@%systemroot%\system32\ssdpsrv.dll,-101 : Discovers networked devices and services that use the SSDP discovery protocol, such as UPnP devices. Also announces SSDP devices and services running on the local computer. If this service is stopped, SSDP-based devices will not be discovered. If this service is disabled, any services that explicitly depend on it will fail to start.
@windows.storage.dll,-21825 : 3D Objects
@%systemroot%\system32\vac.dll,-200 : Volumetric Audio Compositor Service
@c:\progra~1\common~1\micros~1\office16\oregres.dll,-438 : Telemetry Log for Office 2016
@%systemroot%\system32\aphostres.dll,-10001 : This service synchronizes mail, contacts, calendar and various other user data. Mail and other applications dependent on this functionality will not work properly when this service is not running.
@%systemroot%\system32\drivers\mmcss.sys,-100 : Multimedia Class Scheduler
@%systemroot%\system32\tzautoupdate.dll,-200 : Auto Time Zone Updater
@c:\windows\system32\dfrgui.exe,-103 : Defragment and Optimize Drives
@%systemroot%\system32\profsvc.dll,-301 : This service is responsible for loading and unloading user profiles. If this service is stopped or disabled, users will no longer be able to successfully sign in or sign out, apps might have problems getting to users' data, and components registered to receive profile event notifications won't receive them.
@%systemroot%\system32\vaultsvc.dll,-1003 : Credential Manager
@%systemroot%\system32\certprop.dll,-13 : Smart Card Removal Policy
@comres.dll,-948 : Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\seclogon.dll,-7000 : Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\mprmsg.dll,-32014 : Remote Access LEGACY NDIS WAN Driver
@%systemroot%\system32\devicesflowbroker.dll,-104 : Allows ConnectUX and PC Settings to Connect and Pair with WiFi displays and Bluetooth devices.
@%systemroot%\system32\vac.dll,-201 : Hosts spatial analysis for Mixed Reality audio simulation.
@%systemroot%\system32\fhsvc.dll,-102 : Protects user files from accidental loss by copying them to a backup location
@waasmedicsvc.dll,-101 : Enables remediation and protection of Windows Update components.
@%programfiles%\windows defender\mpasdesc.dll,-320 : Microsoft Defender Antivirus Network Inspection Service
@%systemroot%\system32\wbem\wmisvc.dll,-204 : Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\bdesvc.dll,-101 : BDESVC hosts the BitLocker Drive Encryption service. BitLocker Drive Encryption provides secure startup for the operating system, as well as full volume encryption for OS, fixed or removable volumes. This service allows BitLocker to prompt users for various actions related to their volumes when mounted, and unlocks volumes automatically without user interaction. Additionally, it stores recovery information to Active Directory, if available, and, if necessary, ensures the most recent recovery certificates are used. Stopping or disabling the service would prevent users from leveraging this functionality.
@%systemroot%\system32\btagservice.dll,-102 : Service supporting the audio gateway role of the Bluetooth Handsfree Profile.
@%systemroot%\system32\dfrgui.exe,-172 : Optimizes files and fragments on your volumes so that your computer runs faster and more efficiently.
@%systemroot%\system32\iphlpsvc.dll,-500 : IP Helper
@%systemroot%\system32\perceptionsimulation\perceptionsimulationservice.exe,-102 : Enables spatial perception simulation, virtual camera management and spatial input simulation.
@%systemroot%\system32\sppsvc.exe,-100 : Enables the download, installation and enforcement of digital licenses for Windows and Windows applications. If the service is disabled, the operating system and licensed applications may run in a notification mode. It is strongly recommended that you not disable the Software Protection service.
@%systemroot%\system32\vaultsvc.dll,-1004 : Provides secure storage and retrieval of credentials to users, applications and security service packages.
@%systemroot%\system32\vssvc.exe,-102 : Volume Shadow Copy
@%systemroot%\system32\icsvc.dll,-101 : Hyper-V Heartbeat Service
@%systemroot%\system32\pnrpauto.dll,-8002 : PNRP Machine Name Publication Service
@%systemroot%\system32\devquerybroker.dll,-100 : DevQuery Background Discovery Broker
@%systemroot%\system32\perceptionsimulation\perceptionsimulationservice.exe,-101 : Windows Perception Simulation Service
@%systemroot%\system32\fveui.dll,-843 : BitLocker Drive Encryption
@%systemroot%\system32\tapisrv.dll,-10101 : Provides Telephony API (TAPI) support for programs that control telephony devices on the local computer and, through the LAN, on servers that are also running the service.
@%systemroot%\system32\licensemanagersvc.dll,-201 : Provides infrastructure support for the Microsoft Store. This service is started on demand and if disabled then content acquired through the Microsoft Store will not function properly.
@%systemroot%\system32\drivers\ehstorclass.sys,-100 : Enhanced Storage Filter Driver
@c:\windows\system32\wshext.dll,-4804 : JavaScript File
@%systemroot%\system32\drivers\mslldp.sys,-200 : Microsoft Link-Layer Discovery Protocol
@%systemroot%\system32\frameserver.dll,-100 : Windows Camera Frame Server
@%systemroot%\system32\userdataaccessres.dll,-14000 : Provides apps access to structured user data, including contact info, calendars, messages, and other content. If you stop or disable this service, apps that use this data might not work correctly.
@c:\windows\system32\miguiresource.dll,-101 : Event Viewer
@%systemroot%\system32\wkssvc.dll,-1002 : SMB MiniRedirector Wrapper and Engine
@%systemroot%\system32\hidserv.dll,-102 : Activates and maintains the use of hot buttons on keyboards, remote controls, and other multimedia devices. It is recommended that you keep this service running.
@%systemroot%\system32\wbem\wmiapsrv.exe,-111 : Provides performance library information from Windows Management Instrumentation (WMI) providers to clients on the network. This service only runs when Performance Data Helper is activated.
@%systemroot%\system32\wuaueng.dll,-400 : Windows Update
@%programfiles%\windows media player\wmpnetwk.exe,-102 : Shares Windows Media Player libraries to other networked players and media devices using Universal Plug and Play
@%systemroot%\system32\drivers\ndisimplatform.sys,-501 : Microsoft Network Adapter Multiplexor Protocol
@%systemroot%\system32\qwave.dll,-2 : Quality Windows Audio Video Experience (qWave) is a networking platform for Audio Video (AV) streaming applications on IP home networks. qWave enhances AV streaming performance and reliability by ensuring network quality-of-service (QoS) for AV applications. It provides mechanisms for admission control, run time monitoring and enforcement, application feedback, and traffic prioritization.
@%systemroot%\system32\sessenv.dll,-1026 : Remote Desktop Configuration
@%systemroot%\system32\userdataaccessres.dll,-15000 : Indexes contact data for fast contact searching. If you stop or disable this service, contacts might be missing from your search results.
@%systemroot%\system32\netprofmsvc.dll,-202 : Network List Service
@%systemroot%\system32\appinfo.dll,-100 : Application Information
@%systemroot%\system32\mixedrealityruntime.dll,-101 : Windows Mixed Reality OpenXR Service
@comres.dll,-2797 : Distributed Transaction Coordinator
@%systemroot%\system32\spoolsv.exe,-2 : This service spools print jobs and handles interaction with the printer. If you turn off this service, you won’t be able to print or see your printers.
@%systemroot%\system32\drivers\mpsdrv.sys,-23092 : Windows Defender Firewall Authorization Driver
@%systemroot%\system32\userdataaccessres.dll,-14001 : User Data Access
@%systemroot%\system32\themeservice.dll,-8193 : Provides user experience theme management.
@%systemroot%\system32\dispbroker.desktop.dll,-102 : Manages the connection and configuration of local and remote displays
@c:\windows\system32\psr.exe,-1701 : Steps Recorder
@%windir%\system32\timebrokerserver.dll,-1002 : Coordinates execution of background work for WinRT application. If this service is stopped or disabled, then background work might not be triggered.
@%systemroot%\system32\wlansvc.dll,-257 : WLAN AutoConfig
@%windir%\system32\speech\speechux\sapi.cpl,-5556 : Dictate text and control your computer by voice.
@%systemroot%\system32\fdphost.dll,-101 : The FDPHOST service hosts the Function Discovery (FD) network discovery providers. These FD providers supply network discovery services for the Simple Services Discovery Protocol (SSDP) and Web Services – Discovery (WS-D) protocol. Stopping or disabling the FDPHOST service will disable network discovery for these protocols when using FD. When this service is unavailable, network services using FD and relying on these discovery protocols will be unable to find network devices or resources.
@%systemroot%\system32\drivers\ndproxy.sys,-6000 : NDIS Proxy Driver
@%systemroot%\system32\drivers\qwavedrv.sys,-1 : QWAVE driver
@%systemroot%\system32\svsvc.dll,-101 : Spot Verifier
@%systemroot%\system32\diagsvc.dll,-101 : Executes diagnostic actions for troubleshooting support
@%systemroot%\system32\agentservice.exe,-102 : User Experience Virtualization Service
@%systemroot%\system32\cryptsvc.dll,-1001 : Cryptographic Services
@%systemroot%\system32\wfdsconmgrsvc.dll,-9000 : Wi-Fi Direct Services Connection Manager Service
@%systemroot%\system32\mprmsg.dll,-32011 : Remote Access IP ARP Driver
@%systemroot%\system32\devquerybroker.dll,-101 : Enables apps to discover devices with a backgroud task
@%programfiles%\windows defender\mpasdesc.dll,-370 : Microsoft Defender Antivirus Network Inspection System Driver
@%systemroot%\system32\nlasvc.dll,-2 : Collects and stores configuration information for the network and notifies programs when this information is modified. If this service is stopped, configuration information might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\licensemanagersvc.dll,-200 : Windows License Manager Service
@%systemroot%\system32\sharedrealitysvc.dll,-101 : This service is used for Spatial Perception scenarios
@c:\windows\system32\taskmgr.exe,-32420 : Task Manager
@%systemroot%\system32\drivers\verifierext.sys,-1000 : Driver Verifier Extension
@%systemroot%\system32\devicesflowbroker.dll,-103 : DevicesFlow
@%systemroot%\system32\wkssvc.dll,-101 : Creates and maintains client network connections to remote servers using the SMB protocol. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\dssvc.dll,-10002 : Provides data brokering between applications.
@%systemroot%\system32\themeservice.dll,-8192 : Themes
@%systemroot%\system32\credentialenrollmentmanager.exe,-101 : Credential Enrollment Manager
@%systemroot%\system32\pcasvc.dll,-2 : This service provides support for the Program Compatibility Assistant (PCA). PCA monitors programs installed and run by the user and detects known compatibility problems. If this service is stopped, PCA will not function properly.
@%systemroot%\system32\dnsapi.dll,-102 : The DNS Client service (dnscache) caches Domain Name System (DNS) names and registers the full computer name for this computer. If the service is stopped, DNS names will continue to be resolved. However, the results of DNS name queries will not be cached and the computer's name will not be registered. If the service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\wkssvc.dll,-1006 : SMB 2.0 MiniRedirector
@%systemroot%\system32\powrprof.dll,-10 : Saves energy by reducing your computer’s performance where possible.
@%windir%\system32\fxsresm.dll,-115 : Send and receive faxes or scan pictures and documents.
@%systemroot%\system32\fhsvc.dll,-101 : File History Service
@%systemroot%\system32\lfsvc.dll,-2 : This service monitors the current location of the system and manages geofences (a geographical location with associated events). If you turn off this service, applications will be unable to use or receive notifications for geolocation or geofences.
@%systemroot%\system32\flightsettings.dll,-104 : Provides infrastructure support for the Windows Insider Program. This service must remain enabled for the Windows Insider Program to work.
@%systemroot%\system32\workfolderssvc.dll,-102 : Work Folders
@c:\windows\system32\msinfo32.exe,-100 : System Information
@%systemroot%\system32\drivers\tunnel.sys,-500 : Microsoft Tunnel Miniport Adapter Driver
@c:\windows\system32\ieframe.dll,-24585 : Cascading Style Sheet Document
@%systemroot%\system32\tieringengineservice.exe,-702 : Storage Tiers Management
@%systemroot%\system32\dhcpcore.dll,-101 : Registers and updates IP addresses and DNS records for this computer. If this service is stopped, this computer will not receive dynamic IP addresses and DNS updates. If this service is disabled, any services that explicitly depend on it will fail to start.
@regsvc.dll,-2 : Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\clipsvc.dll,-103 : Client License Service (ClipSVC)
@%systemroot%\system32\fntcache.dll,-101 : Optimizes performance of applications by caching commonly used font data. Applications will start this service if it is not already running. It can be disabled, though doing so will degrade application performance.
@c:\progra~1\common~1\micros~1\office16\oregres.dll,-436 : Telemetry Dashboard for Office 2016
@%systemroot%\system32\icsvcext.dll,-502 : Coordinates the communications that are required to use Volume Shadow Copy Service to back up applications and data on this virtual machine from the operating system on the physical computer.
@%systemroot%\system32\hvhostsvc.dll,-100 : HV Host Service
@%systemroot%\system32\sdrsvc.dll,-107 : Windows Backup
@%systemroot%\system32\locator.exe,-2 : Remote Procedure Call (RPC) Locator
@%systemroot%\system32\messagingservice.dll,-101 : Service supporting text messaging and related functionality.
@%systemroot%\system32\ipxlatcfg.dll,-501 : Configures and enables translation from v4 to v6 and vice versa
@%systemroot%\system32\drivers\volsnap.sys,-100 : Volume Shadow Copy driver
@%systemroot%\system32\mycomput.dll,-112 : Manages disks and provides access to other tools to manage local and remote computers.
@%systemroot%\system32\wpnservice.dll,-1 : Windows Push Notifications System Service
@%systemroot%\system32\dssvc.dll,-10003 : Data Sharing Service
@%systemroot%\system32\sensrsvc.dll,-1000 : Sensor Monitoring Service
@%systemroot%\system32\seclogon.dll,-7001 : Secondary Logon
@%systemroot%\system32\samsrv.dll,-1 : Security Accounts Manager
@%systemroot%\system32\wpnuserservice.dll,-2 : This service hosts Windows notification platform which provides support for local and push notifications. Supported notifications are tile, toast and raw.
@%systemroot%\system32\umrdp.dll,-1000 : Remote Desktop Services UserMode Port Redirector
@%systemroot%\system32\windows.internal.management.dll,-101 : Performs Device Enrollment Activities for Device Management
@%systemroot%\system32\drivers\iorate.sys,-101 : Disk I/O Rate Filter Driver
@%windir%\system32\bisrv.dll,-100 : Background Tasks Infrastructure Service
@%systemroot%\system32\shsvcs.dll,-12289 : Provides notifications for AutoPlay hardware events.
@%systemroot%\system32\netman.dll,-109 : Network Connections
@%systemroot%\system32\drivers\filetrace.sys,-10001 : FileTrace
@%systemroot%\system32\devicesetupmanager.dll,-1001 : Enables the detection, download and installation of device-related software. If this service is disabled, devices may be configured with outdated software, and may not work correctly.
@%systemroot%\system32\wersvc.dll,-101 : Allows errors to be reported when programs stop working or responding and allows existing solutions to be delivered. Also allows logs to be generated for diagnostic and repair services. If this service is stopped, error reporting might not work correctly and results of diagnostic services and repairs might not be displayed.
@%systemroot%\system32\dosvc.dll,-100 : Delivery Optimization
@%systemroot%\system32\storsvc.dll,-100 : Storage Service
@%systemroot%\system32\smsroutersvc.dll,-10002 : Routes messages based on rules to appropriate clients.
@%systemroot%\system32\ngcrecovery.dll,-100 : Windows Hello Recovery Key Encryption
@%systemroot%\system32\windowspowershell\v1.0\powershell.exe,-124 : Document Encryption
@%systemroot%\system32\wuaueng.dll,-400 : Windows Update
@%systemroot%\system32\dnsapi.dll,-103 : Domain Name System (DNS) Server Trust
@%systemroot%\system32\ci.dll,-100 : Isolated User Mode (IUM)
@%systemroot%\system32\fveui.dll,-844 : BitLocker Data Recovery Agent
@%systemroot%\system32\fveui.dll,-843 : BitLocker Drive Encryption
@%systemroot%\system32\ci.dll,-101 : Enclave
@%systemroot%\system32\srvsvc.dll,-100 : Server
@%systemroot%\system32\drivers\wpdupfltr.sys,-100 : WPD Upper Class Filter Driver
@combase.dll,-5013 : The DCOMLAUNCH service launches COM and DCOM servers in response to object activation requests. If this service is stopped or disabled, programs using COM or DCOM will not function properly. It is strongly recommended that you have the DCOMLAUNCH service running.
@%systemroot%\system32\axinstsv.dll,-103 : ActiveX Installer (AxInstSV)
@winlangdb.dll,-1691 : English (Barbados)
@%systemroot%\system32\appxdeploymentserver.dll,-1 : AppX Deployment Service (AppXSVC)
@%systemroot%\system32\smphost.dll,-101 : Host service for the Microsoft Storage Spaces management provider. If this service is stopped or disabled, Storage Spaces cannot be managed.
@%systemroot%\system32\wlidsvc.dll,-100 : Microsoft Account Sign-in Assistant
@%systemroot%\system32\wcncsvc.dll,-3 : Windows Connect Now - Config Registrar
@%systemroot%\system32\efssvc.dll,-100 : Encrypting File System (EFS)
@%windir%\system32\drivers\pacer.sys,-101 : QoS Packet Scheduler
@%systemroot%\system32\lltdres.dll,-6 : Link-Layer Topology Discovery Mapper I/O Driver
@%systemroot%\system32\drivers\rdpdr.sys,-100 : Remote Desktop Device Redirector Driver
@%systemroot%\system32\aphostres.dll,-10002 : Sync Host
@c:\windows\system32\rdpendp.dll,-1001 : Remote Audio
@%systemroot%\system32\workfolderssvc.dll,-101 : This service syncs files with the Work Folders server, enabling you to use the files on any of the PCs and devices on which you've set up Work Folders.
@%systemroot%\system32\ci.dll,-100 : Isolated User Mode (IUM)
@%systemroot%\system32\wscsvc.dll,-200 : Security Center
@%systemroot%\system32\consentuxclient.dll,-101 : Allows ConnectUX and PC Settings to Connect and Pair with WiFi displays and Bluetooth devices.
@%systemroot%\system32\qwave.dll,-1 : Quality Windows Audio Video Experience
@%systemroot%\system32\cloudidsvc.dll,-100 : Microsoft Cloud Identity Service
@%systemroot%\system32\wiarpc.dll,-2 : Still Image Acquisition Events
@%systemroot%\system32\xboxgipsvc.dll,-101 : This service manages connected Xbox Accessories.
@%systemroot%\system32\powrprof.dll,-12 : Favors performance, but may use more energy.
@%systemroot%\system32\tapisrv.dll,-10100 : Telephony
@%systemroot%\system32\drivers\winnat.sys,-10001 : Windows NAT Driver
@%systemroot%\system32\drivers\appvstrm.sys,-101 : AppvStrm
@%systemroot%\system32\wpcrefreshtask.dll,-100 : Parental Controls
@c:\windows\system32\ieframe.dll,-12385 : Favorites Bar
@%systemroot%\system32\rmapi.dll,-1001 : Radio Management Service
@%systemroot%\system32\wpnservice.dll,-2 : This service runs in session 0 and hosts the notification platform and connection provider which handles the connection between the device and WNS server.
@%systemroot%\system32\p2psvc.dll,-8006 : Peer Networking Grouping
@%systemroot%\system32\drivers\spaceparser.sys,-1001 : Space Parser
@c:\windows\system32\snippingtool.exe,-15051 : Snipping Tool
@%systemroot%\system32\sensorservice.dll,-1001 : A service for sensors that manages different sensors' functionality. Manages Simple Device Orientation (SDO) and History for sensors. Loads the SDO sensor that reports device orientation changes. If this service is stopped or disabled, the SDO sensor will not be loaded and so auto-rotation will not occur. History collection from Sensors will also be stopped.
@%systemroot%\system32\drivers\scfilter.sys,-11 : Smart card PnP Class Filter Driver
@%systemroot%\system32\sysmain.dll,-1001 : Maintains and improves system performance over time.
@%systemroot%\system32\diagsvcs\diagnosticshub.standardcollector.serviceres.dll,-1001 : Diagnostics Hub Standard Collector Service. When running, this service collects real time ETW events and processes them.
@%systemroot%\system32\assignedaccessmanagersvc.dll,-100 : AssignedAccessManager Service
@%systemroot%\system32\gameinputsvc.exe,-102 : Enables keyboards, mice, gamepads, and other input devices to be used with the GameInput API.
@%systemroot%\system32\graphicsperfsvc.dll,-101 : Graphics performance monitor service
@%systemroot%\system32\fdphost.dll,-100 : Function Discovery Provider Host
@%systemroot%\system32\frameserver.dll,-101 : Enables multiple clients to access video frames from camera devices.
@%systemroot%\system32\ncbservice.dll,-501 : Brokers connections that allow Windows Store Apps to receive notifications from the internet.
@%systemroot%\system32\walletservice.dll,-1000 : WalletService
@%systemroot%\system32\netlogon.dll,-102 : Netlogon
@%systemroot%\system32\phoneserviceres.dll,-10001 : Manages the telephony state on the device
@%systemroot%\system32\dialogblockingservice.dll,-101 : Dialog Blocking Service
@%systemroot%\system32\ngcrecovery.dll,-100 : Windows Hello Recovery Key Encryption
@%systemroot%\system32\umpnpmgr.dll,-100 : Device Install Service
@%systemroot%\system32\drivers\wdf01000.sys,-1000 : Kernel Mode Driver Frameworks service
@%systemroot%\system32\ci.dll,-101 : Enclave
@%systemroot%\system32\bthserv.dll,-101 : Bluetooth Support Service
@%systemroot%\system32\vds.exe,-112 : Provides management services for disks, volumes, file systems, and storage arrays.
@%systemroot%\system32\urlmon.dll,-4200 : Open File - Security Warning
@%systemroot%\system32\sstpsvc.dll,-201 : Provides support for the Secure Socket Tunneling Protocol (SSTP) to connect to remote computers using VPN. If this service is disabled, users will not be able to use SSTP to access remote servers.
@%systemroot%\system32\qmgr.dll,-1001 : Transfers files in the background using idle network bandwidth. If the service is disabled, then any applications that depend on BITS, such as Windows Update or MSN Explorer, will be unable to automatically download programs and other information.
@%systemroot%\system32\netman.dll,-110 : Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections.
@c:\windows\system32\speech\speechux\sapi.cpl,-5555 : Windows Speech Recognition
@%systemroot%\system32\taskmgr.exe,-33551 : Manage running apps and view system performance
@%programfiles%\windows defender advanced threat protection\mssense.exe,-1001 : Windows Defender Advanced Threat Protection Service
@c:\windows\system32\mstsc.exe,-4000 : Remote Desktop Connection
@c:\windows\system32\windows.storage.dll,-10152 : File folder
@%systemroot%\system32\drivers\volmgrx.sys,-100 : Dynamic Volume Manager
@%systemroot%\system32\das.dll,-101 : Enables pairing between the system and wired or wireless devices.
@combase.dll,-5011 : The RPCSS service is the Service Control Manager for COM and DCOM servers. It performs object activations requests, object exporter resolutions and distributed garbage collection for COM and DCOM servers. If this service is stopped or disabled, programs using COM or DCOM will not function properly. It is strongly recommended that you have the RPCSS service running.
@%systemroot%\system32\mprmsg.dll,-32006 : WAN Miniport (PPTP)
@%systemroot%\system32\wlidsvc.dll,-101 : Enables user sign-in through Microsoft account identity services. If this service is stopped, users will not be able to logon to the computer with their Microsoft account.
@%systemroot%\system32\dmwappushsvc.dll,-200 : Device Management Wireless Application Protocol (WAP) Push message Routing Service
@%systemroot%\system32\windows.warp.jitservice.dll,-101 : Provides a JIT out of process service for WARP when running with ACG enabled.
@%systemroot%\system32\pnrpauto.dll,-8003 : This service publishes a machine name using the Peer Name Resolution Protocol. Configuration is managed via the netsh context 'p2p pnrp peer'
@%systemroot%\system32\icsvc.dll,-202 : Provides a mechanism to exchange data between the virtual machine and the operating system running on the physical computer.
@%systemroot%\system32\diagsvc.dll,-100 : Diagnostic Execution Service
@%systemroot%\system32\icsvc.dll,-301 : Hyper-V Guest Shutdown Service
@%systemroot%\system32\wcmsvc.dll,-4098 : Makes automatic connect/disconnect decisions based on the network connectivity options currently available to the PC and enables management of network connectivity based on Group Policy settings.
@%systemroot%\system32\aarsvc.dll,-101 : Runtime for activating conversational agent applications
@%windir%\system32\mstsc.exe,-4001 : Use your computer to connect to a computer that is located elsewhere and run programs or access files.
@windows.storage.dll,-34583 : Saved Pictures
@%systemroot%\system32\wfdsconmgrsvc.dll,-9001 : Manages connections to wireless services, including wireless display and docking.
@%systemroot%\system32\drivers\fsdepends.sys,-10001 : File System Dependency Minifilter
@%systemroot%\system32\phoneserviceres.dll,-10000 : Phone Service
@%systemroot%\system32\wcncsvc.dll,-4 : WCNCSVC hosts the Windows Connect Now Configuration which is Microsoft's Implementation of Wireless Protected Setup (WPS) protocol. This is used to configure Wireless LAN settings for an Access Point (AP) or a Wireless Device. The service is started programmatically as needed.
c:\windows\system32,@elscore.dll,-7 : Microsoft Devanagari to Latin Transliteration
@%systemroot%\system32\defragsvc.dll,-102 : Helps the computer run more efficiently by optimizing files on storage drives.
@%systemroot%\system32\upnphost.dll,-214 : Allows UPnP devices to be hosted on this computer. If this service is stopped, any hosted UPnP devices will stop functioning and no additional hosted devices can be added. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\xboxnetapisvc.dll,-101 : This service supports the Windows.Networking.XboxLive application programming interface.
@%systemroot%\system32\tabsvc.dll,-100 : Touch Keyboard and Handwriting Panel Service
@%systemroot%\system32\tcpipcfg.dll,-50004 : NetIO Legacy TDI Support Driver
@c:\windows\system32\authfwgp.dll,-20 : Windows Defender Firewall with Advanced Security
@%systemroot%\system32\windows.devices.picker.dll,-1006 : DevicePicker
@%windir%\system32\systemeventsbrokerserver.dll,-1002 : Coordinates execution of background work for WinRT application. If this service is stopped or disabled, then background work might not be triggered.
@%systemroot%\system32\snippingtool.exe,-15052 : Capture a portion of your screen so you can save, annotate, or share the image.
@%systemroot%\system32\assignedaccessmanagersvc.dll,-101 : AssignedAccessManager Service supports kiosk experience in Windows.
@%systemroot%\system32\deviceaccess.dll,-108 : Enables apps to pair devices
@%systemroot%\system32\ipnathlp.dll,-106 : Internet Connection Sharing (ICS)
@c:\program files\common files\microsoft shared\ink\mip.exe,-291 : Math Input Panel
@c:\windows\system32\filemgmt.dll,-2204 : Services
@%systemroot%\system32\wkssvc.dll,-1000 : Redirected Buffering Sub System
@%systemroot%\system32\mprmsg.dll,-32012 : Remote Access IPv6 ARP Driver
@%systemroot%\system32\bthavctpsvc.dll,-102 : This is Audio Video Control Transport Protocol service
@%systemroot%\system32\alg.exe,-112 : Application Layer Gateway Service
@%systemroot%\system32\sensrsvc.dll,-1001 : Monitors various sensors in order to expose data and adapt to system and user state. If this service is stopped or disabled, the display brightness will not adapt to lighting conditions. Stopping this service may affect other system functionality and features as well.
@%systemroot%\system32\drivers\msseccore.sys,-1001 : Microsoft Security Core Boot Driver
@%systemroot%\system32\microsoft.bluetooth.userservice.dll,-101 : Bluetooth User Support Service
@%systemroot%\system32\schedsvc.dll,-100 : Task Scheduler
@%systemroot%\system32\sstpsvc.dll,-202 : WAN Miniport (SSTP)
@c:\windows\system32\windowspowershell\v1.0\powershell.exe,-101 : Windows PowerShell ISE
@%systemroot%\system32\sysmain.dll,-1000 : SysMain
@%systemroot%\system32\windows.sharedpc.accountmanager.dll,-101 : Manages profiles and accounts on a SharedPC configured device
@%systemroot%\system32\tzautoupdate.dll,-201 : Automatically sets the system time zone.
@%systemroot%\system32\drivers\ndu.sys,-10001 : Windows Network Data Usage Monitoring Driver
@%systemroot%\system32\userdataaccessres.dll,-10002 : Handles storage of structured user data, including contact info, calendars, messages, and other content. If you stop or disable this service, apps that use this data might not work correctly.
@c:\progra~1\common~1\micros~1\office16\oregres.dll,-467 : Office 2016 Upload Center
@%systemroot%\system32\securityhealthagent.dll,-1001 : Windows Security Service handles unified device protection and health information
@%systemroot%\system32\peerdistsvc.dll,-9000 : BranchCache
c:\windows\system32,@elscore.dll,-6 : Microsoft Cyrillic to Latin Transliteration
@comres.dll,-2798 : Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will fail. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\bfe.dll,-1002 : The Base Filtering Engine (BFE) is a service that manages firewall and Internet Protocol security (IPsec) policies and implements user mode filtering. Stopping or disabling the BFE service will significantly reduce the security of the system. It will also result in unpredictable behavior in IPsec management and firewall applications.
@%systemroot%\system32\usermgr.dll,-100 : User Manager
@%systemroot%\system32\wevtsvc.dll,-201 : This service manages events and event logs. It supports logging events, querying events, subscribing to events, archiving event logs, and managing event metadata. It can display events in both XML and plain text format. Stopping this service may compromise security and reliability of the system.
@%systemroot%\system32\drivers\ndisvirtualbus.sys,-200 : Microsoft Virtual Network Adapter Enumerator
@%systemroot%\system32\tieringengineservice.exe,-701 : Optimizes the placement of data in storage tiers on all tiered storage spaces in the system.
@%systemroot%\system32\searchindexer.exe,-103 : Windows Search
@%systemroot%\system32\drivers\wudfrd.sys,-1000 : Windows Driver Foundation - User-mode Driver Framework Reflector
@combase.dll,-5012 : DCOM Server Process Launcher
@%systemroot%\system32\bdesvc.dll,-100 : BitLocker Drive Encryption Service
@%systemroot%\system32\das.dll,-100 : Device Association Service
@%systemroot%\system32\termsrv.dll,-267 : Allows users to connect interactively to a remote computer. Remote Desktop and Remote Desktop Session Host Server depend on this service. To prevent remote use of this computer, clear the checkboxes on the Remote tab of the System properties control panel item.
@%systemroot%\syswow64\perfhost.exe,-1 : Enables remote users and 64-bit processes to query performance counters provided by 32-bit DLLs. If this service is stopped, only local users and 32-bit processes will be able to query performance counters provided by 32-bit DLLs.
@%systemroot%\system32\scdeviceenum.dll,-101 : Creates software device nodes for all smart card readers accessible to a given session. If this service is disabled, WinRT APIs will not be able to enumerate smart card readers.
@%systemroot%\system32\rdxservice.dll,-257 : The Retail Demo service controls device activity while the device is in retail demo mode.
@%systemroot%\system32\rasmans.dll,-200 : Remote Access Connection Manager
@%systemroot%\system32\sdrsvc.dll,-102 : Provides Windows Backup and Restore capabilities.
@c:\windows\system32\msxml3r.dll,-1 : XML Document
@%systemroot%\system32\wdi.dll,-501 : The Diagnostic System Host is used by the Diagnostic Policy Service to host diagnostics that need to run in a Local System context. If this service is stopped, any diagnostics that depend on it will no longer function.
@%systemroot%\system32\drivers\pdc.sys,-100 : PDC
@%systemroot%\system32\dot3svc.dll,-1102 : Wired AutoConfig
@%systemroot%\system32\capabilityaccessmanager.dll,-1 : Capability Access Manager Service
@%systemroot%\system32\ngcctnrsvc.dll,-1 : Microsoft Passport Container
@%systemroot%\system32\gameinputsvc.exe,-101 : GameInput Service
@%systemroot%\system32\spectrum.exe,-101 : Windows Perception Service
@%systemroot%\system32\installservice.dll,-201 : Provides infrastructure support for the Microsoft Store. This service is started on demand and if disabled then installations will not function properly.
@c:\windows\system32\ieframe.dll,-912 : HTML Document
@%systemroot%\system32\drivers\fltmgr.sys,-10001 : FltMgr
@%systemroot%\system32\usosvc.dll,-101 : Update Orchestrator Service
@%systemroot%\system32\pla.dll,-500 : Performance Logs & Alerts
@%systemroot%\system32\alg.exe,-113 : Provides support for 3rd party protocol plug-ins for Internet Connection Sharing
@%systemroot%\system32\bcastdvruserservice.dll,-101 : This user service is used for Game Recordings and Live Broadcasts
@%systemroot%\system32\presentationhost.exe,-3309 : Windows Presentation Foundation Font Cache 3.0.0.0
@%systemroot%\system32\dot3svc.dll,-1103 : The Wired AutoConfig (DOT3SVC) service is responsible for performing IEEE 802.1X authentication on Ethernet interfaces. If your current wired network deployment enforces 802.1X authentication, the DOT3SVC service should be configured to run for establishing Layer 2 connectivity and/or providing access to network resources. Wired networks that do not enforce 802.1X authentication are unaffected by the DOT3SVC service.
@%systemroot%\system32\msimsg.dll,-27 : Windows Installer
@%systemroot%\system32\drivers\tsusbflt.sys,-1000 : Remote Desktop USB Hub Class Filter Driver
@comres.dll,-2946 : KtmRm for Distributed Transaction Coordinator
@%systemroot%\system32\cdpsvc.dll,-100 : Connected Devices Platform Service
@%windir%\system32\rpcepmap.dll,-1002 : Resolves RPC interfaces identifiers to transport endpoints. If this service is stopped or disabled, programs using Remote Procedure Call (RPC) services will not function properly.
@c:\progra~1\common~1\micros~1\office16\oregres.dll,-416 : Office 2016 Language Preferences
@c:\windows\system32\presentationhost.exe,-3300 : Windows Markup File
@%systemroot%\system32\swprv.dll,-102 : Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\wpdbusenum.dll,-101 : Enforces group policy for removable mass-storage devices. Enables applications such as Windows Media Player and Image Import Wizard to transfer and synchronize content using removable mass-storage devices.
@keyiso.dll,-101 : The CNG key isolation service is hosted in the LSA process. The service provides key process isolation to private keys and associated cryptographic operations as required by the Common Criteria. The service stores and uses long-lived keys in a secure process complying with Common Criteria requirements.
@%systemroot%\system32\drivers\bindflt.sys,-100 : Windows Bind Filter Driver
@%systemroot%\system32\xblgamesave.dll,-101 : This service syncs save data for Xbox Live save enabled games. If this service is stopped, game save data will not upload to or download from Xbox Live.
@%systemroot%\system32\embeddedmodesvc.dll,-202 : The Embedded Mode service enables scenarios related to Background Applications. Disabling this service will prevent Background Applications from being activated.
@c:\windows\system32\fxsresm.dll,-114 : Windows Fax and Scan
@cryptext.dll,-6113 : PKCS #7 Signature
@%systemroot%\system32\w32time.dll,-201 : Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\embeddedmodesvc.dll,-201 : Embedded Mode
@%systemroot%\system32\audiosrv.dll,-200 : Windows Audio
@%systemroot%\system32\clipsvc.dll,-104 : Provides infrastructure support for the Microsoft Store. This service is started on demand and if disabled applications bought using Windows Store will not behave correctly.
@%systemroot%\system32\ipnathlp.dll,-107 : Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network.
@%systemroot%\system32\captureservice.dll,-101 : Enables optional screen capture functionality for applications that call the Windows.Graphics.Capture API.
@%systemroot%\system32\firewallcontrolpanel.dll,-12122 : Windows Defender Firewall
@%systemroot%\system32\drivers\vwifibus.sys,-257 : Virtual Wireless Bus Driver
@%systemroot%\system32\dispbroker.desktop.dll,-101 : Display Policy Service
@%systemroot%\system32\rasauto.dll,-201 : Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address.
@c:\windows\system32\quickassist.exe,-806 : Quick Assist
@%systemroot%\system32\netprofmsvc.dll,-203 : Identifies the networks to which the computer has connected, collects and stores properties for these networks, and notifies applications when these properties change.
@%systemroot%\system32\drivers\storqosflt.sys,-101 : Storage QoS Filter Driver
@%systemroot%\system32\sgrmbroker.exe,-101 : Monitors and attests to the integrity of the Windows platform.
@%systemroot%\system32\userdataaccessres.dll,-10003 : User Data Storage
@%systemroot%\system32\fdrespub.dll,-100 : Function Discovery Resource Publication
@%systemroot%\system32\drivers\appvvemgr.sys,-101 : AppvVemgr
@%systemroot%\system32\agentservice.exe,-101 : Provides support for application and OS settings roaming
@%systemroot%\system32\keyboardfiltersvc.dll,-101 : Microsoft Keyboard Filter
@%systemroot%\system32\wbengine.exe,-104 : Block Level Backup Engine Service
@%systemroot%\servicing\trustedinstaller.exe,-101 : Enables installation, modification, and removal of Windows updates and optional components. If this service is disabled, install or uninstall of Windows updates might fail for this computer.
@%systemroot%\system32\pcasvc.dll,-1 : Program Compatibility Assistant Service
@%systemroot%\system32\wdi.dll,-503 : The Diagnostic Service Host is used by the Diagnostic Policy Service to host diagnostics that need to run in a Local Service context. If this service is stopped, any diagnostics that depend on it will no longer function.
@%systemroot%\system32\bthavctpsvc.dll,-101 : AVCTP service
@%programfiles%\windows defender\mpasdesc.dll,-242 : Helps guard against intrusion attempts targeting known and newly discovered vulnerabilities in network protocols
@%systemroot%\system32\windows.management.service.dll,-101 : Performs management including Provisioning and Enrollment activities
@c:\windows\system32\spool\drivers\x64\3\printconfig.dll,-2 : This service opens custom printer dialog boxes and handles notifications from a remote print server or a printer. If you turn off this service, you won’t be able to see printer extensions or notifications.
@%systemroot%\system32\drivers\gpuenergydrv.sys,-100 : GPU Energy Driver
@%systemroot%\system32\xblauthmanager.dll,-101 : Provides authentication and authorization services for interacting with Xbox Live. If this service is stopped, some applications may not operate correctly.
@%systemroot%\system32\wiaservc.dll,-9 : Windows Image Acquisition (WIA)
@%systemroot%\system32\drivers\afd.sys,-1000 : Ancillary Function Driver for Winsock
@%systemroot%\system32\powrprof.dll,-11 : Power saver
@%systemroot%\system32\autotimesvc.dll,-6 : Cellular Time
@comres.dll,-947 : COM+ System Application
@%systemroot%\system32\mprmsg.dll,-32005 : WAN Miniport (L2TP)
@%systemroot%\servicing\trustedinstaller.exe,-100 : Windows Modules Installer
@gpapi.dll,-113 : The service is responsible for applying settings configured by administrators for the computer and users through the Group Policy component. If the service is disabled, the settings will not be applied and applications and components will not be manageable through Group Policy. Any components or applications that depend on the Group Policy component might not be functional if the service is disabled.
@%systemroot%\system32\rasmans.dll,-201 : Manages dial-up and virtual private network (VPN) connections from this computer to the Internet or other remote networks. If this service is disabled, any services that explicitly depend on it will fail to start.
@c:\windows\system32\wdc.dll,-10030 : Resource Monitor
@%systemroot%\system32\certprop.dll,-14 : Allows the system to be configured to lock the user desktop upon smart card removal.
@%systemroot%\system32\windows.devices.picker.dll,-1007 : This user service is used for managing the Miracast, DLNA, and DIAL UI
@%systemroot%\system32\pla.dll,-501 : Performance Logs and Alerts Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\rmapi.dll,-1002 : Radio Management and Airplane Mode Service
@%systemroot%\system32\tokenbroker.dll,-100 : Web Account Manager
c:\windows\system32,@elscore.dll,-2 : Microsoft Script Detection
@combase.dll,-5010 : Remote Procedure Call (RPC)
@%systemroot%\system32\installservice.dll,-200 : Microsoft Store Install Service
@%systemroot%\system32\icsvcext.dll,-501 : Hyper-V Volume Shadow Copy Requestor
@%systemroot%\system32\rdxservice.dll,-256 : Retail Demo Service
@c:\windows\system32\mdsched.exe,-4001 : Windows Memory Diagnostic
@%systemroot%\system32\naturalauth.dll,-100 : Natural Authentication
@%systemroot%\system32\netlogon.dll,-103 : Maintains a secure channel between this computer and the domain controller for authenticating users and services. If this service is stopped, the computer may not authenticate users and services and the domain controller cannot register DNS records. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\scardsvr.dll,-5 : Manages access to smart cards read by this computer. If this service is stopped, this computer will be unable to read smart cards. If this service is disabled, any services that explicitly depend on it will fail to start.
@c:\windows\system32\windowspowershell\v1.0\powershell.exe,-102 : Windows PowerShell ISE (x86)
@comres.dll,-2947 : Coordinates transactions between the Distributed Transaction Coordinator (MSDTC) and the Kernel Transaction Manager (KTM). If it is not needed, it is recommended that this service remain stopped. If it is needed, both MSDTC and KTM will start this service automatically. If this service is disabled, any MSDTC transaction interacting with a Kernel Resource Manager will fail and any services that explicitly depend on it will fail to start.
@%systemroot%\system32\drivers\sgrmagent.sys,-1001 : System Guard Runtime Monitor Agent
@%systemroot%\system32\dnsapi.dll,-101 : DNS Client
c:\windows\system32,@elscore.dll,-9 : Microsoft Bengali to Latin Transliteration
@c:\windows\system32\pmcsnap.dll,-700 : Print Management
@%systemroot%\system32\drivers\hwpolicy.sys,-101 : Hardware Policy Driver
@%systemroot%\system32\shsvcs.dll,-12288 : Shell Hardware Detection
@%programfiles%\windows defender\mpasdesc.dll,-310 : Microsoft Defender Antivirus Service
@%systemroot%\system32\dmwappushsvc.dll,-201 : Routes Wireless Application Protocol (WAP) Push messages received by the device and synchronizes Device Management sessions
@c:\windows\system32\msimsg.dll,-34 : Windows Installer Package
@%systemroot%\system32\mprdim.dll,-200 : Routing and Remote Access
@%systemroot%\system32\nlasvc.dll,-1 : Network Location Awareness
@%systemroot%\system32\srvsvc.dll,-101 : Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\consentuxclient.dll,-100 : ConsentUX
@%systemroot%\system32\icsvcext.dll,-602 : Provides a platform for communication between the virtual machine and the operating system running on the physical computer.
@%systemroot%\system32\appxdeploymentserver.dll,-2 : Provides infrastructure support for deploying Store applications. This service is started on demand and if disabled Store applications will not be deployed to the system, and may not function properly.
c:\windows\system32,@elscore.dll,-8 : Microsoft Malayalam to Latin Transliteration
@%systemroot%\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8200 : Provides ability to share TCP ports over the net.tcp protocol.
@%systemroot%\system32\schedsvc.dll,-101 : Enables a user to configure and schedule automated tasks on this computer. The service also hosts multiple Windows system-critical tasks. If this service is stopped or disabled, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\capabilityaccessmanager.dll,-2 : Provides facilities for managing UWP apps access to app capabilities as well as checking an app's access to specific app capabilities
@%systemroot%\system32\drivers\nwifi.sys,-101 : NativeWiFi Filter
@c:\windows\system32\comres.dll,-3410 : Component Services
@%programfiles%\windows media player\wmpnetwk.exe,-101 : Windows Media Player Network Sharing Service
@%systemroot%\system32\msinfo32.exe,-130 : Display detailed information about your computer.
@%systemroot%\system32\diagtrack.dll,-3002 : The Connected User Experiences and Telemetry service enables features that support in-application and connected user experiences. Additionally, this service manages the event driven collection and transmission of diagnostic and usage information (used to improve the experience and quality of the Windows Platform) when the diagnostics and usage privacy option settings are enabled under Feedback and Diagnostics.
@%systemroot%\system32\printworkflowservice.dll,-101 : Provides support for Print Workflow applications. If you turn off this service, you may not be able to print successfully.
@%systemroot%\system32\ncdautosetup.dll,-100 : Network Connected Devices Auto-Setup
c:\windows\system32,@elscore.dll,-1 : Microsoft Language Detection
@%systemroot%\system32\hidserv.dll,-101 : Human Interface Device Service
@%systemroot%\system32\firewallapi.dll,-23090 : Windows Defender Firewall
@%systemroot%\system32\ngcctnrsvc.dll,-2 : Manages local user identity keys used to authenticate user to identity providers as well as TPM virtual smart cards. If this service is disabled, local user identity keys and TPM virtual smart cards will not be accessible. It is recommended that you do not reconfigure this service.
@c:\windows\system32\mycomput.dll,-300 : Computer Management
@%systemroot%\system32\quickassist.exe,-807 : Connect to another user's computer to help troubleshoot problems
@%systemroot%\system32\drivers\mshidumdf.sys,-100 : Pass-through HID to UMDF Driver
@%systemroot%\system32\swprv.dll,-103 : Microsoft Software Shadow Copy Provider
@windows.storage.dll,-21824 : Camera Roll
@%systemroot%\system32\scdeviceenum.dll,-100 : Smart Card Device Enumeration Service
@gpapi.dll,-112 : Group Policy Client
@%systemroot%\system32\wkssvc.dll,-1008 : DFS Namespace Client Driver
@%systemroot%\system32\eapsvc.dll,-1 : Extensible Authentication Protocol
@%systemroot%\system32\naturalauth.dll,-101 : Signal aggregator service, that evaluates signals based on time, network, geolocation, bluetooth and cdf factors. Supported features are Device Unlock, Dynamic Lock and Dynamo MDM policies
@%systemroot%\system32\eapsvc.dll,-2 : The Extensible Authentication Protocol (EAP) service provides network authentication in such scenarios as 802.1x wired and wireless, VPN, and Network Access Protection (NAP). EAP also provides application programming interfaces (APIs) that are used by network access clients, including wireless and VPN clients, during the authentication process. If you disable this service, this computer is prevented from accessing networks that require EAP authentication.
@%systemroot%\system32\drivers\uevagentdriver.sys,-101 : UevAgentDriver
@%systemroot%\system32\locator.exe,-3 : In Windows 2003 and earlier versions of Windows, the Remote Procedure Call (RPC) Locator service manages the RPC name service database. In Windows Vista and later versions of Windows, this service does not provide any functionality and is present for application compatibility.
@%systemroot%\system32\microsoft.graphics.display.displayenhancementservice.dll,-1001 : A service for managing display enhancement such as brightness control.
@%systemroot%\system32\wercplsupport.dll,-100 : This service provides support for viewing, sending and deletion of system-level problem reports for the Problem Reports control panel.
@%systemroot%\system32\w32time.dll,-200 : Windows Time
c:\windows\system32,@elscore.dll,-5 : Microsoft Transliteration Engine
@%systemroot%\system32\cscsvc.dll,-200 : Offline Files
@%systemroot%\system32\microsoft.bluetooth.userservice.dll,-102 : The Bluetooth user service supports proper functionality of Bluetooth features relevant to each user session.
@%systemroot%\system32\drivers\clfs.sys,-100 : Common Log (CLFS)
@waasmedicsvc.dll,-100 : Windows Update Medic Service
@%systemroot%\system32\drivers\ndis.sys,-200 : NDIS System Driver
@%systemroot%\system32\usosvc.dll,-102 : Manages Windows Updates. If stopped, your devices will not be able to download and install the latest updates.
@%windir%\immersivecontrolpanel\systemsettings.exe,-651 : Change settings and customize the functionality of your computer
@%systemroot%\system32\tetheringservice.dll,-4098 : Provides the ability to share a cellular data connection with another device.
@%systemroot%\system32\windowsudk.shellcommon.dll,-100 : Udk User Service
@%systemroot%\system32\ncasvc.dll,-3008 : Provides DirectAccess status notification for UI components
@%systemroot%\system32\drivers\wudfpf.sys,-1000 : User Mode Driver Frameworks Platform Driver
@firewallapi.dll,-50323 : SNMP Trap
@%systemroot%\system32\wdi.dll,-500 : Diagnostic System Host
@%systemroot%\system32\fdrespub.dll,-101 : Publishes this computer and resources attached to this computer so they can be discovered over the network. If this service is stopped, network resources will no longer be published and they will not be discovered by other computers on the network.
@%windir%\system32\bisrv.dll,-101 : Windows infrastructure service that controls which background tasks can run on the system.
@%systemroot%\system32\drivers\hvservice.sys,-16 : Hypervisor/Virtual Machine Support Driver
@%systemroot%\system32\wiaservc.dll,-10 : Provides image acquisition services for scanners and cameras
@%systemroot%\system32\certprop.dll,-12 : Copies user certificates and root certificates from smart cards into the current user's certificate store, detects when a smart card is inserted into a smart card reader, and, if needed, installs the smart card Plug and Play minidriver.
@%systemroot%\system32\hnetcfgclient.dll,-201 : HNetCfg Client
@%systemroot%\system32\pnrpsvc.dll,-8000 : Peer Name Resolution Protocol
@%systemroot%\system32\autotimesvc.dll,-7 : This service sets time based on NITZ messages from a Mobile Network
@%systemroot%\system32\iscsidsc.dll,-5000 : Microsoft iSCSI Initiator Service
@%systemroot%\system32\windowspowershell\v1.0\powershell.exe,-124 : Document Encryption
@%systemroot%\system32\trkwks.dll,-2 : Maintains links between NTFS files within a computer or across computers in a network.
@%systemroot%\system32\appvclient.exe,-101 : Manages App-V users and virtual applications
@c:\windows\system32\unregmp2.exe,-9935 : MPEG-2 TS Video
@c:\progra~1\pcheal~1\pcheal~1.exe,-130 : PC Health Check
@%systemroot%\system32\wpcrefreshtask.dll,-101 : Enforces parental controls for child accounts in Windows. If this service is stopped or disabled, parental controls may not be enforced.
@%systemroot%\system32\drivers\cnghwassist.sys,-100 : CNG Hardware Assist algorithm provider
@%systemroot%\system32\svsvc.dll,-102 : Verifies potential file system corruptions.
@%systemroot%\system32\lltdres.dll,-2 : Creates a Network Map, consisting of PC and device topology (connectivity) information, and metadata describing each PC and device. If this service is disabled, the Network Map will not function properly.
@%systemroot%\system32\powrprof.dll,-15 : Balanced
@%systemroot%\system32\lltdres.dll,-5 : Link-Layer Topology Discovery Responder
@c:\windows\regedit.exe,-16 : Registry Editor
@%systemroot%\system32\tetheringservice.dll,-4097 : Windows Mobile Hotspot Service
@%systemroot%\system32\drivers\appvvfs.sys,-101 : AppvVfs
@%systemroot%\system32\mitigationclient.dll,-104 : Enables automatic mitigation for known problems by applying recommended troubleshooting. If stopped, your device will not get recommended troubleshooting for problems on your device.
@%systemroot%\system32\windows.warp.jitservice.dll,-100 : WarpJITSvc
c:\windows\system32,@elscore.dll,-4 : Microsoft Simplified Chinese to Traditional Chinese Transliteration
@%systemroot%\system32\drivers\http.sys,-1 : HTTP Service
@%systemroot%\system32\sessenv.dll,-1027 : Remote Desktop Configuration service (RDCS) is responsible for all Remote Desktop Services and Remote Desktop related configuration and session maintenance activities that require SYSTEM context. These include per-session temporary folders, RD themes, and RD certificates.
@%systemroot%\system32\windowsudk.shellcommon.dll,-101 : Shell components service
@%programfiles%\windows defender\mpasdesc.dll,-240 : Helps protect users from malware and other potentially unwanted software
@winlangdb.dll,-1121 : English (United States)
@%systemroot%\system32\rasauto.dll,-200 : Remote Access Auto Connection Manager
@%systemroot%\system32\wbengine.exe,-105 : The WBENGINE service is used by Windows Backup to perform backup and recovery operations. If this service is stopped by a user, it may cause the currently running backup or recovery operation to fail. Disabling this service may disable backup and recovery operations using Windows Backup on this computer.
@%systemroot%\system32\mprdim.dll,-201 : Offers routing services to businesses in local area and wide area network environments.
@%systemroot%\system32\defragsvc.dll,-101 : Optimize drives
@%systemroot%\system32\presentationhost.exe,-3310 : Optimizes performance of Windows Presentation Foundation (WPF) applications by caching commonly used font data. WPF applications will start this service if it is not already running. It can be disabled, though doing so will degrade the performance of WPF applications.
@%systemroot%\system32\dcsvc.dll,-102 : Process Declared Configuration documents recevied from MDM and other channels and perform configurations on device
@%systemroot%\system32\mprmsg.dll,-32001 : Remote Access NDIS TAPI Driver
@%systemroot%\system32\fxsresm.dll,-122 : Enables you to send and receive faxes, utilizing fax resources available on this computer or on the network.
@%systemroot%\system32\fveui.dll,-844 : BitLocker Data Recovery Agent
@%systemroot%\system32\drivers\mssecflt.sys,-1001 : Microsoft Security Events Component Minifilter
@%systemroot%\system32\icsvc.dll,-801 : Hyper-V Guest Service Interface
@%systemroot%\system32\diagsvcs\diagnosticshub.standardcollector.serviceres.dll,-1000 : Microsoft (R) Diagnostics Hub Standard Collector Service
@%systemroot%\system32\wsmsvc.dll,-101 : Windows Remote Management (WS-Management)
@%systemroot%\system32\ssdpsrv.dll,-100 : SSDP Discovery
@%systemroot%\system32\drivers\indirectkmd.sys,-100 : Indirect Displays Kernel-Mode Driver
@%systemroot%\system32\pnrpsvc.dll,-8005 : Provides identity services for the Peer Name Resolution Protocol (PNRP) and Peer-to-Peer Grouping services. If disabled, the Peer Name Resolution Protocol (PNRP) and Peer-to-Peer Grouping services may not function, and some applications, such as HomeGroup and Remote Assistance, may not function correctly.
@c:\windows\system32\spool\drivers\x64\3\printconfig.dll,-1 : Printer Extensions and Notifications
@%systemroot%\system32\vssvc.exe,-101 : Manages and implements Volume Shadow Copies used for backup and other purposes. If this service is stopped, shadow copies will be unavailable for backup and the backup may fail. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\peerdistsvc.dll,-9001 : This service caches network content from peers on the local subnet.
@%systemroot%\system32\storsvc.dll,-101 : Provides enabling services for storage settings and external storage expansion
@%systemroot%\system32\credentialenrollmentmanager.exe,-100 : CredentialEnrollmentManagerUserSvc
@%systemroot%\system32\lpasvc.dll,-1000 : Local Profile Assistant Service
@%systemroot%\system32\captureservice.dll,-100 : CaptureService
@%windir%\regedit.exe,-16 : Registry Editor
@%systemroot%\system32\webclnt.dll,-104 : WebDav Client Redirector Driver
@%systemroot%\system32\webclnt.dll,-100 : WebClient
@c:\windows\system32\wsecedit.dll,-718 : Local Security Policy
@%systemroot%\system32\smphost.dll,-102 : Microsoft Storage Spaces SMP
@%systemroot%\system32\drivers\netbt.sys,-2 : NETBT
@%systemroot%\system32\drivers\fileinfo.sys,-100 : File Information FS MiniFilter
@%systemroot%\system32\drivers\wcifs.sys,-100 : Windows Container Isolation
@%systemroot%\system32\drivers\ahcache.sys,-102 : Application Compatibility Cache
@%systemroot%\system32\axinstsv.dll,-104 : Provides User Account Control validation for the installation of ActiveX controls from the Internet and enables management of ActiveX control installation based on Group Policy settings. This service is started on demand and if disabled the installation of ActiveX controls will behave according to default browser settings.
@%systemroot%\system32\windows.internal.management.dll,-100 : Device Management Enrollment Service
@%systemroot%\system32\languageoverlayserver.dll,-100 : Language Experience Service
@enterpriseappmgmtsvc.dll,-2 : Enables enterprise application management.
@%systemroot%\system32\wpdbusenum.dll,-100 : Portable Device Enumerator Service
@%systemroot%\system32\wercplsupport.dll,-101 : Problem Reports Control Panel Support
@%systemroot%\system32\srpapi.dll,-102 : Smartlocker Filter Driver
@%systemroot%\system32\netsetupsvc.dll,-3 : Network Setup Service
@%systemroot%\system32\webclnt.dll,-101 : Enables Windows-based programs to create, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start.
@c:\windows\system32\ieframe.dll,-10046 : Internet Shortcut
@%programfiles%\windows defender\mpasdesc.dll,-330 : Microsoft Defender Antivirus Mini-Filter Driver
@%systemroot%\system32\wdc.dll,-10031 : Monitor the usage and performance of the following resources in real time: CPU, Disk, Network and Memory.
@%systemroot%\system32\windows.management.service.dll,-100 : Windows Management Service
@%systemroot%\system32\cscsvc.dll,-201 : The Offline Files service performs maintenance activities on the Offline Files cache, responds to user logon and logoff events, implements the internals of the public API, and dispatches interesting events to those interested in Offline Files activities and changes in cache state.
@comres.dll,-2450 : COM+ Event System
@%systemroot%\system32\userdataaccessres.dll,-15001 : Contact Data
@%systemroot%\system32\tabsvc.dll,-101 : Enables Touch Keyboard and Handwriting Panel pen and ink functionality
@%systemroot%\system32\powrprof.dll,-14 : Automatically balances performance with energy consumption on capable hardware.
@%systemroot%\system32\msconfig.exe,-6001 : Perform advanced troubleshooting and system configuration
@%systemroot%\system32\wkssvc.dll,-2001 : Browser
@%systemroot%\system32\ngcsvc.dll,-101 : Provides process isolation for cryptographic keys used to authenticate to a user’s associated identity providers. If this service is disabled, all uses and management of these keys will not be available, which includes machine logon and single-sign on for apps and websites. This service starts and stops automatically. It is recommended that you do not reconfigure this service.
@%systemroot%\system32\wlansvc.dll,-258 : The WLANSVC service provides the logic required to configure, discover, connect to, and disconnect from a wireless local area network (WLAN) as defined by IEEE 802.11 standards. It also contains the logic to turn your computer into a software access point so that other devices or computers can connect to your computer wirelessly using a WLAN adapter that can support this. Stopping or disabling the WLANSVC service will make all WLAN adapters on your computer inaccessible from the Windows networking UI. It is strongly recommended that you have the WLANSVC service running if your computer has a WLAN adapter.
@%systemroot%\system32\wbem\wmisvc.dll,-205 : Windows Management Instrumentation
@%systemroot%\system32\walletservice.dll,-1001 : Hosts objects used by clients of the wallet
@%systemroot%\system32\icsvc.dll,-102 : Monitors the state of this virtual machine by reporting a heartbeat at regular intervals. This service helps you identify running virtual machines that have stopped responding.
@c:\windows\system32\notepad.exe,-469 : Text Document
@%systemroot%\system32\cbdhsvc.dll,-101 : This user service is used for Clipboard scenarios
@c:\windows\system32\odbcint.dll,-1694 : ODBC Data Sources (64-bit)
@c:\windows\system32\windows.ui.immersive.dll,-38304 : Public Account Pictures
@%systemroot%\system32\dnsapi.dll,-103 : Domain Name System (DNS) Server Trust
@searchfolder.dll,-32822 : Everywhere
@%systemroot%\system32\icsvc.dll,-401 : Hyper-V Time Synchronization Service
@%systemroot%\system32\wbiosrvc.dll,-101 : The Windows biometric service gives client applications the ability to capture, compare, manipulate, and store biometric data without gaining direct access to any biometric hardware or samples. The service is hosted in a privileged SVCHOST process.
@%systemroot%\system32\appinfo.dll,-101 : Facilitates the running of interactive applications with additional administrative privileges. If this service is stopped, users will be unable to launch applications with the additional administrative privileges they may require to perform desired user tasks.
@%systemroot%\system32\srvsvc.dll,-104 : Server SMB 2.xxx Driver
@%systemroot%\system32\searchindexer.exe,-104 : Provides content indexing, property caching, and search results for files, e-mail, and other content.
@%systemroot%\system32\ncbservice.dll,-500 : Network Connection Broker
@%systemroot%\system32\msimsg.dll,-32 : Adds, modifies, and removes applications provided as a Windows Installer (*.msi, *.msp) package. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\coremessaging.dll,-2 : Manages communication between system components.
@%systemroot%\system32\drivers\bam.sys,-100 : Background Activity Moderator Driver
@%systemroot%\system32\mprmsg.dll,-32002 : Remote Access NDIS WAN Driver
@%systemroot%\system32\bcastdvruserservice.dll,-100 : GameDVR and Broadcast User Service
@%systemroot%\system32\umrdp.dll,-1001 : Allows the redirection of Printers/Drives/Ports for RDP connections
@%systemroot%\system32\sensordataservice.exe,-102 : Delivers data from a variety of sensors
@%systemroot%\system32\icsvc.dll,-902 : Provides a mechanism to manage virtual machine with PowerShell via VM session without a virtual network.
@%systemroot%\system32\drivers\wfplwfs.sys,-6000 : Microsoft Windows Filtering Platform
@%systemroot%\system32\efssvc.dll,-101 : Provides the core file encryption technology used to store encrypted files on NTFS file system volumes. If this service is stopped or disabled, applications will be unable to access encrypted files.
@%systemroot%\system32\appvclient.exe,-102 : Microsoft App-V Client
@%systemroot%\system32\flightsettings.dll,-103 : Windows Insider Service
@%systemroot%\system32\spectrum.exe,-102 : Enables spatial perception, spatial input, and holographic rendering.
@%systemroot%\system32\ncdautosetup.dll,-101 : Network Connected Devices Auto-Setup service monitors and installs qualified devices that connect to a qualified network. Stopping or disabling this service will prevent Windows from discovering and installing qualified network connected devices automatically. Users can still manually add network connected devices to a PC through the user interface.
@%systemroot%\system32\wwansvc.dll,-257 : WWAN AutoConfig
@%systemroot%\system32\wsmsvc.dll,-102 : Windows Remote Management (WinRM) service implements the WS-Management protocol for remote management. WS-Management is a standard web services protocol used for remote software and hardware management. The WinRM service listens on the network for WS-Management requests and processes them. The WinRM Service needs to be configured with a listener using winrm.cmd command line tool or through Group Policy in order for it to listen over the network. The WinRM service provides access to WMI data and enables event collection. Event collection and subscription to events require that the service is running. WinRM messages use HTTP and HTTPS as transports. The WinRM service does not depend on IIS but is preconfigured to share a port with IIS on the same machine. The WinRM service reserves the /wsman URL prefix. To prevent conflicts with IIS, administrators should ensure that any websites hosted on IIS do not use the /wsman URL prefix.
@%systemroot%\system32\mprmsg.dll,-32007 : Remote Access PPPOE Driver
@appmgmts.dll,-3251 : Processes installation, removal, and enumeration requests for software deployed through Group Policy. If the service is disabled, users will be unable to install, remove, or enumerate software deployed through Group Policy. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\ngcsvc.dll,-100 : Microsoft Passport
@%systemroot%\system32\wscsvc.dll,-201 : The WSCSVC (Windows Security Center) service monitors and reports security health settings on the computer. The health settings include firewall (on/off), antivirus (on/off/out of date), antispyware (on/off/out of date), Windows Update (automatically/manually download and install updates), User Account Control (on/off), and Internet settings (recommended/not recommended). The service provides COM APIs for independent software vendors to register and record the state of their products to the Security Center service. The Security and Maintenance UI uses the service to provide systray alerts and a graphical view of the security health states in the Security and Maintenance control panel. Network Access Protection (NAP) uses the service to report the security health states of clients to the NAP Network Policy Server to make network quarantine decisions. The service also has a public API that allows external consumers to programmatically retrieve the aggregated security health state of the system.
@%systemroot%\system32\sensorservice.dll,-1000 : Sensor Service
@%systemroot%\system32\tokenbroker.dll,-101 : This service is used by Web Account Manager to provide single-sign-on to apps and services.
@%systemroot%\system32\dps.dll,-500 : Diagnostic Policy Service
@%systemroot%\system32\sensordataservice.exe,-101 : Sensor Data Service
@%systemroot%\system32\printworkflowservice.dll,-100 : PrintWorkflow
@%systemroot%\system32\cdpsvc.dll,-101 : This service is used for Connected Devices Platform scenarios
@%systemroot%\system32\sppsvc.exe,-101 : Software Protection
@comres.dll,-2451 : Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\drivers\ndiscap.sys,-5000 : Microsoft NDIS Capture
@%systemroot%\system32\mitigationclient.dll,-103 : Recommended Troubleshooting Service
@%systemroot%\system32\ajrouter.dll,-1 : Routes AllJoyn messages for the local AllJoyn clients. If this service is stopped the AllJoyn clients that do not have their own bundled routers will be unable to run.
@%systemroot%\system32\wecsvc.dll,-201 : This service manages persistent subscriptions to events from remote sources that support WS-Management protocol. This includes Windows Vista event logs, hardware and IPMI-enabled event sources. The service stores forwarded events in a local Event Log. If this service is stopped or disabled event subscriptions cannot be created and forwarded events cannot be accepted.
@%systemroot%\system32\pushtoinstall.dll,-201 : Provides infrastructure support for the Microsoft Store. This service is started automatically and if disabled then remote installations will not function properly.
@%systemroot%\system32\cscsvc.dll,-202 : Offline Files Driver
@%systemroot%\system32\icsvcext.dll,-601 : Hyper-V Remote Desktop Virtualization Service
@%windir%\system32\drivers\netbios.sys,-503 : NetBIOS Interface
@%systemroot%\system32\lmhsvc.dll,-102 : Provides support for the NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution for clients on the network, therefore enabling users to share files, print, and log on to the network. If this service is stopped, these functions might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\wbem\wmiapsrv.exe,-110 : WMI Performance Adapter
@c:\windows\immersivecontrolpanel\systemsettings.exe,-650 : Settings
@%systemroot%\system32\icsvc.dll,-901 : Hyper-V PowerShell Direct Service
@%systemroot%\system32\psr.exe,-1702 : Capture steps with screenshots to save or share.
c:\windows\system32,@elscore.dll,-3 : Microsoft Traditional Chinese to Simplified Chinese Transliteration
@%systemroot%\system32\umpnpmgr.dll,-101 : Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability.
@%systemroot%\system32\polstore.dll,-5011 : Internet Protocol security (IPsec) supports network-level peer authentication, data origin authentication, data integrity, data confidentiality (encryption), and replay protection. This service enforces IPsec policies created through the IP Security Policies snap-in or the command-line tool ""netsh ipsec"". If you stop this service, you may experience network connectivity issues if your policy requires that connections use IPsec. Also,remote management of Windows Defender Firewall is not available when this service is stopped.
@%systemroot%\system32\windows.sharedpc.accountmanager.dll,-100 : Shared PC Account Manager
@%systemroot%\system32\wpnuserservice.dll,-1 : Windows Push Notifications User Service
@%systemroot%\system32\windows.staterepository.dll,-2 : Provides required infrastructure support for the application model.
@%systemroot%\system32\winhttp.dll,-101 : WinHTTP implements the client HTTP stack and provides developers with a Win32 API and COM Automation component for sending HTTP requests and receiving responses. In addition, WinHTTP provides support for auto-discovering a proxy configuration via its implementation of the Web Proxy Auto-Discovery (WPAD) protocol.
@%systemroot%\system32\iscsidsc.dll,-5001 : Manages Internet SCSI (iSCSI) sessions from this computer to remote iSCSI target devices. If this service is stopped, this computer will not be able to login or access iSCSI targets. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\appidsvc.dll,-100 : Application Identity
@%systemroot%\system32\icsvc.dll,-402 : Synchronizes the system time of this virtual machine with the system time of the physical computer.
@%systemroot%\system32\drivers\mountmgr.sys,-100 : Mount Point Manager
@%systemroot%\system32\keyboardfiltersvc.dll,-102 : Controls keystroke filtering and mapping
@%systemroot%\system32\icsvc.dll,-302 : Provides a mechanism to shut down the operating system of this virtual machine from the management interfaces on the physical computer.
@c:\windows\system32\iscsicpl.dll,-5001 : iSCSI Initiator
@%systemroot%\system32\hvhostsvc.dll,-101 : Provides an interface for the Hyper-V hypervisor to provide per-partition performance counters to the host operating system.
@%systemroot%\system32\icsvc.dll,-201 : Hyper-V Data Exchange Service
@%systemroot%\system32\dosvc.dll,-101 : Performs content delivery optimization tasks
@%systemroot%\system32\iphlpsvc.dll,-501 : Provides tunnel connectivity using IPv6 transition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS. If this service is stopped, the computer will not have the enhanced connectivity benefits that these technologies offer.
@%systemroot%\system32\pnrpsvc.dll,-8004 : Peer Networking Identity Manager
@%systemroot%\system32\drivers\wcnfs.sys,-100 : Windows Container Name Virtualization
@%systemroot%\system32\cdpusersvc.dll,-100 : Connected Devices Platform User Service
@c:\progra~1\common~1\micros~1\office16\oregres.dll,-315 : OneDrive for Business
@%systemroot%\system32\shell32.dll,-50176 : File Operation
@%systemroot%\system32\audiosrv.dll,-201 : Manages audio for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start
@c:\windows\system32\msconfig.exe,-5006 : System Configuration
@%systemroot%\system32\samsrv.dll,-2 : The startup of this service signals other services that the Security Accounts Manager (SAM) is ready to accept requests. Disabling this service will prevent other services in the system from being notified when the SAM is ready, which may in turn cause those services to fail to start correctly. This service should not be disabled.
@%systemroot%\system32\bridgeres.dll,-1 : Microsoft MAC Bridge
@searchfolder.dll,-32820 : Indexed Locations
@%systemroot%\system32\lpasvc.dll,-1001 : This service provides profile management for subscriber identity modules
@windows.storage.dll,-21826 : Captures
@%windir%\system32\systemeventsbrokerserver.dll,-1001 : System Events Broker
@%systemroot%\system32\appidsvc.dll,-101 : Determines and verifies the identity of an application. Disabling this service will prevent AppLocker from being enforced.
@%systemroot%\system32\languageoverlayserver.dll,-101 : Provides infrastructure support for deploying and configuring localized Windows resources. This service is started on demand and, if disabled, additional Windows languages will not be deployed to the system, and Windows may not function properly.
@%systemroot%\system32\cdpusersvc.dll,-101 : This user service is used for Connected Devices Platform scenarios
@%systemroot%\system32\drivers\partmgr.sys,-100 : Partition driver
@%systemroot%\system32\wbiosrvc.dll,-100 : Windows Biometric Service
@%systemroot%\system32\ipxlatcfg.dll,-500 : IP Translation Configuration Service
@%programfiles%\windows defender\mpasdesc.dll,-390 : Microsoft Defender Antivirus Boot Driver
@%systemroot%\system32\certprop.dll,-11 : Certificate Propagation
@c:\windows\system32\ulib.dll,-1000 : Recovered File Fragments
@%systemroot%\system32\pnrpsvc.dll,-8001 : Enables serverless peer name resolution over the Internet using the Peer Name Resolution Protocol (PNRP). If disabled, some peer-to-peer and collaborative applications, such as Remote Assistance, may not function.
@%systemroot%\system32\appreadiness.dll,-1001 : Gets apps ready for use the first time a user signs in to this PC and when adding new apps.
@%systemroot%\system32\wephostsvc.dll,-100 : Windows Encryption Provider Host Service
@%systemroot%\system32\wkssvc.dll,-100 : Workstation
c:\windows\system32,@elscore.dll,-10 : Microsoft Hangul Decomposition Transliteration
@%systemroot%\system32\audioendpointbuilder.dll,-205 : Manages audio devices for the Windows Audio service. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start
@c:\windows\system32\recoverydrive.exe,-500 : Recovery Drive
@%systemroot%\system32\mprmsg.dll,-32013 : IP Traffic Filter Driver
@%systemroot%\system32\firewallapi.dll,-23091 : Windows Defender Firewall helps protect your computer by preventing unauthorized users from gaining access to your computer through the Internet or a network.
@c:\windows\system32\searchfolder.dll,-9023 : Saved Search
@%systemroot%\system32\cbdhsvc.dll,-100 : Clipboard User Service
@%systemroot%\system32\ikeext.dll,-502 : The IKEEXT service hosts the Internet Key Exchange (IKE) and Authenticated Internet Protocol (AuthIP) keying modules. These keying modules are used for authentication and key exchange in Internet Protocol security (IPsec). Stopping or disabling the IKEEXT service will disable IKE and AuthIP key exchange with peer computers. IPsec is typically configured to use IKE or AuthIP; therefore, stopping or disabling the IKEEXT service might result in an IPsec failure and might compromise the security of the system. It is strongly recommended that you have the IKEEXT service running.
@%systemroot%\system32\dcsvc.dll,-101 : Declared Configuration(DC) service
@%programfiles%\windows defender advanced threat protection\mssense.exe,-1002 : Windows Defender Advanced Threat Protection service helps protect against advanced threats by monitoring and reporting security events that happen on the computer.
@%systemroot%\system32\wdc.dll,-10025 : Diagnose performance issues and collect performance data.
@%systemroot%\syswow64\perfhost.exe,-2 : Performance Counter DLL Host
@%systemroot%\system32\moshost.dll,-100 : Downloaded Maps Manager
@%systemroot%\system32\wephostsvc.dll,-101 : Windows Encryption Provider Host Service brokers encryption related functionalities from 3rd Party Encryption Providers to processes that need to evaluate and apply EAS policies. Stopping this will compromise EAS compliancy checks that have been established by the connected Mail Accounts
@%systemroot%\system32\nsisvc.dll,-201 : This service delivers network notifications (e.g. interface addition/deleting etc) to user mode clients. Stopping this service will cause loss of network connectivity. If this service is disabled, any other services that explicitly depend on this service will fail to start.
@%systemroot%\system32\drivers\luafv.sys,-100 : UAC File Virtualization
@%systemroot%\system32\pushtoinstall.dll,-200 : Windows PushToInstall Service
@%systemroot%\system32\mprmsg.dll,-32000 : RAS Asynchronous Media Driver
@%systemroot%\system32\netsetupsvc.dll,-4 : The Network Setup Service manages the installation of network drivers and permits the configuration of low-level network settings. If this service is stopped, any driver installations that are in-progress may be cancelled.
@%systemroot%\system32\drivers\mshidkmdf.sys,-100 : Pass-through HID to KMDF Filter Driver
@%systemroot%\system32\semgrsvc.dll,-1002 : Manages payments and Near Field Communication (NFC) based secure elements.
@%systemroot%\system32\dialogblockingservice.dll,-100 : DialogBlockingService
@%systemroot%\system32\smsroutersvc.dll,-10001 : Microsoft Windows SMS Router Service.
@%systemroot%\system32\wersvc.dll,-100 : Windows Error Reporting Service
@%systemroot%\system32\securityhealthagent.dll,-1002 : Windows Security Service
@%commonprogramfiles%\microsoft shared\ink\mip.exe,-292 : Math Input Panel
@%systemroot%\system32\wuaueng.dll,-106 : Enables the detection, download, and installation of updates for Windows and other programs. If this service is disabled, users of this computer will not be able to use Windows Update or its automatic updating feature, and programs will not be able to use the Windows Update Agent (WUA) API.
@%systemroot%\system32\ncasvc.dll,-3009 : Network Connectivity Assistant
@c:\program files\common files\system\wab32res.dll,-10100 : Contacts
@regsvc.dll,-1 : Remote Registry
@%systemroot%\system32\microsoft.graphics.display.displayenhancementservice.dll,-1000 : Display Enhancement Service
@%systemroot%\system32\appreadiness.dll,-1000 : App Readiness
@%systemroot%\system32\wcmsvc.dll,-4097 : Windows Connection Manager
@%systemroot%\system32\cryptsvc.dll,-1002 : Provides three management services: Catalog Database Service, which confirms the signatures of Windows files and allows new programs to be installed; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Automatic Root Certificate Update Service, which retrieves root certificates from Windows Update and enable scenarios such as SSL. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8201 : Net.Tcp Port Sharing Service
@%systemroot%\system32\umpo.dll,-101 : Manages power policy and power policy notification delivery.
@%systemroot%\system32\p2psvc.dll,-8007 : Enables multi-party communication using Peer-to-Peer Grouping. If disabled, some applications, such as HomeGroup, may not function.
@%systemroot%\system32\vds.exe,-100 : Virtual Disk
@%systemroot%\system32\pmcsnap.dll,-710 : Manages local printers and remote print servers.
@%systemroot%\system32\drivers\filecrypt.sys,-100 : FileCrypt
@appmgmts.dll,-3250 : Application Management
@%systemroot%\system32\powrprof.dll,-13 : High performance
@enterpriseappmgmtsvc.dll,-1 : Enterprise App Management Service
@%systemroot%\system32\recoverydrive.exe,-600 : Create a recovery drive
@%systemroot%\system32\icsvc.dll,-802 : Provides an interface for the Hyper-V host to interact with specific services running inside the virtual machine.
@%systemroot%\system32\wiarpc.dll,-1 : Launches applications associated with still image acquisition events.
@%systemroot%\system32\sharedrealitysvc.dll,-100 : Spatial Data Service
@%systemroot%\system32\graphicsperfsvc.dll,-100 : GraphicsPerfSvc
@%systemroot%\system32\drivers\fvevol.sys,-100 : BitLocker Drive Encryption Filter Driver
@%systemroot%\system32\mixedrealityruntime.dll,-102 : Enables Mixed Reality OpenXR runtime functionality
@%systemroot%\system32\drivers\mssecwfp.sys,-1001 : Microsoft Security WFP Callout Driver
@%systemroot%\system32\lfsvc.dll,-1 : Geolocation Service
@firewallapi.dll,-50324 : Receives trap messages generated by local or remote Simple Network Management Protocol (SNMP) agents and forwards the messages to SNMP management programs running on this computer. If this service is stopped, SNMP-based programs on this computer will not receive SNMP trap messages. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\drivers\mup.sys,-101 : MUP
@%systemroot%\system32\audioendpointbuilder.dll,-204 : Windows Audio Endpoint Builder
@%systemroot%\system32\drivers\wimmount.sys,-101 : WIMMount
@%systemroot%\system32\aarsvc.dll,-100 : Agent Activation Runtime
@%systemroot%\system32\moshost.dll,-101 : Windows service for application access to downloaded maps. This service is started on-demand by application accessing downloaded maps. Disabling this service will prevent apps from accessing maps.
@%systemroot%\system32\drivers\vwififlt.sys,-259 : Virtual WiFi Filter Driver
@%systemroot%\system32\messagingservice.dll,-100 : MessagingService
@%systemroot%\system32\scardsvr.dll,-1 : Smart Card
@c:\windows\system32\wdc.dll,-10021 : Performance Monitor
@c:\windows\system32\miguiresource.dll,-201 : Task Scheduler
@%systemroot%\system32\drivers\dam.sys,-100 : Desktop Activity Moderator Driver
@%systemroot%\system32\dps.dll,-501 : The Diagnostic Policy Service enables problem detection, troubleshooting and resolution for Windows components. If this service is stopped, diagnostics will no longer function.
@%windir%\system32\lsm.dll,-1002 : Core Windows Service that manages local user sessions. Stopping or disabling this service will result in system instability.
@%systemroot%\system32\deviceaccess.dll,-107 : DeviceAssociationBroker
@%systemroot%\system32\wwansvc.dll,-258 : This service manages mobile broadband (GSM & CDMA) data card/embedded module adapters and connections by auto-configuring the networks. It is strongly recommended that this service be kept running for best user experience of mobile broadband devices.
@%systemroot%\system32\cloudidsvc.dll,-101 : Supports integrations with Microsoft cloud identity services. If disabled, tenant restrictions will not be enforced properly.
@%systemroot%\system32\windows.staterepository.dll,-1 : State Repository Service
@%systemroot%\system32\lltdres.dll,-1 : Link-Layer Topology Discovery Mapper
@%systemroot%\system32\btagservice.dll,-101 : Bluetooth Audio Gateway Service
@%systemroot%\system32\srpapi.dll,-100 : AppID Driver
@%systemroot%\system32\usermgr.dll,-101 : User Manager provides the runtime components required for multi-user interaction. If this service is stopped, some applications may not operate correctly.
@%systemroot%\system32\ajrouter.dll,-2 : AllJoyn Router Service
@%systemroot%\system32\wecsvc.dll,-200 : Windows Event Collector
@%systemroot%\system32\dusmsvc.dll,-2 : Network data usage, data limit, restrict background data, metered networks.
@%systemroot%\system32\drivers\nsiproxy.sys,-2 : NSI Proxy Service Driver
@%systemroot%\system32\sens.dll,-201 : Monitors system events and notifies subscribers to COM+ Event System of these events.
@%systemroot%\system32\bthserv.dll,-102 : The Bluetooth service supports discovery and association of remote Bluetooth devices. Stopping or disabling this service may cause already installed Bluetooth devices to fail to operate properly and prevent new devices from being discovered or associated.
@%systemroot%\system32\drivers\tcpip.sys,-10001 : TCP/IP Protocol Driver
@%systemroot%\system32\ssdpsrv.dll,-101 : Discovers networked devices and services that use the SSDP discovery protocol, such as UPnP devices. Also announces SSDP devices and services running on the local computer. If this service is stopped, SSDP-based devices will not be discovered. If this service is disabled, any services that explicitly depend on it will fail to start.
@windows.storage.dll,-21825 : 3D Objects
@%systemroot%\system32\vac.dll,-200 : Volumetric Audio Compositor Service
@c:\progra~1\common~1\micros~1\office16\oregres.dll,-438 : Telemetry Log for Office 2016
@%systemroot%\system32\aphostres.dll,-10001 : This service synchronizes mail, contacts, calendar and various other user data. Mail and other applications dependent on this functionality will not work properly when this service is not running.
@%systemroot%\system32\drivers\mmcss.sys,-100 : Multimedia Class Scheduler
@%systemroot%\system32\tzautoupdate.dll,-200 : Auto Time Zone Updater
@c:\windows\system32\dfrgui.exe,-103 : Defragment and Optimize Drives
@%systemroot%\system32\profsvc.dll,-301 : This service is responsible for loading and unloading user profiles. If this service is stopped or disabled, users will no longer be able to successfully sign in or sign out, apps might have problems getting to users' data, and components registered to receive profile event notifications won't receive them.
@%systemroot%\system32\vaultsvc.dll,-1003 : Credential Manager
@%systemroot%\system32\certprop.dll,-13 : Smart Card Removal Policy
@comres.dll,-948 : Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\seclogon.dll,-7000 : Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\mprmsg.dll,-32014 : Remote Access LEGACY NDIS WAN Driver
@%systemroot%\system32\devicesflowbroker.dll,-104 : Allows ConnectUX and PC Settings to Connect and Pair with WiFi displays and Bluetooth devices.
@%systemroot%\system32\vac.dll,-201 : Hosts spatial analysis for Mixed Reality audio simulation.
@%systemroot%\system32\fhsvc.dll,-102 : Protects user files from accidental loss by copying them to a backup location
@waasmedicsvc.dll,-101 : Enables remediation and protection of Windows Update components.
@%programfiles%\windows defender\mpasdesc.dll,-320 : Microsoft Defender Antivirus Network Inspection Service
@%systemroot%\system32\wbem\wmisvc.dll,-204 : Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\bdesvc.dll,-101 : BDESVC hosts the BitLocker Drive Encryption service. BitLocker Drive Encryption provides secure startup for the operating system, as well as full volume encryption for OS, fixed or removable volumes. This service allows BitLocker to prompt users for various actions related to their volumes when mounted, and unlocks volumes automatically without user interaction. Additionally, it stores recovery information to Active Directory, if available, and, if necessary, ensures the most recent recovery certificates are used. Stopping or disabling the service would prevent users from leveraging this functionality.
@%systemroot%\system32\btagservice.dll,-102 : Service supporting the audio gateway role of the Bluetooth Handsfree Profile.
@%systemroot%\system32\dfrgui.exe,-172 : Optimizes files and fragments on your volumes so that your computer runs faster and more efficiently.
@%systemroot%\system32\iphlpsvc.dll,-500 : IP Helper
@%systemroot%\system32\perceptionsimulation\perceptionsimulationservice.exe,-102 : Enables spatial perception simulation, virtual camera management and spatial input simulation.
@%systemroot%\system32\sppsvc.exe,-100 : Enables the download, installation and enforcement of digital licenses for Windows and Windows applications. If the service is disabled, the operating system and licensed applications may run in a notification mode. It is strongly recommended that you not disable the Software Protection service.
@%systemroot%\system32\vaultsvc.dll,-1004 : Provides secure storage and retrieval of credentials to users, applications and security service packages.
@%systemroot%\system32\vssvc.exe,-102 : Volume Shadow Copy
@%systemroot%\system32\icsvc.dll,-101 : Hyper-V Heartbeat Service
@%systemroot%\system32\pnrpauto.dll,-8002 : PNRP Machine Name Publication Service
@%systemroot%\system32\devquerybroker.dll,-100 : DevQuery Background Discovery Broker
@%systemroot%\system32\perceptionsimulation\perceptionsimulationservice.exe,-101 : Windows Perception Simulation Service
@%systemroot%\system32\fveui.dll,-843 : BitLocker Drive Encryption
@%systemroot%\system32\tapisrv.dll,-10101 : Provides Telephony API (TAPI) support for programs that control telephony devices on the local computer and, through the LAN, on servers that are also running the service.
@%systemroot%\system32\licensemanagersvc.dll,-201 : Provides infrastructure support for the Microsoft Store. This service is started on demand and if disabled then content acquired through the Microsoft Store will not function properly.
@%systemroot%\system32\drivers\ehstorclass.sys,-100 : Enhanced Storage Filter Driver
@c:\windows\system32\wshext.dll,-4804 : JavaScript File
@%systemroot%\system32\drivers\mslldp.sys,-200 : Microsoft Link-Layer Discovery Protocol
@%systemroot%\system32\frameserver.dll,-100 : Windows Camera Frame Server
@%systemroot%\system32\userdataaccessres.dll,-14000 : Provides apps access to structured user data, including contact info, calendars, messages, and other content. If you stop or disable this service, apps that use this data might not work correctly.
@c:\windows\system32\miguiresource.dll,-101 : Event Viewer
@%systemroot%\system32\wkssvc.dll,-1002 : SMB MiniRedirector Wrapper and Engine
@%systemroot%\system32\hidserv.dll,-102 : Activates and maintains the use of hot buttons on keyboards, remote controls, and other multimedia devices. It is recommended that you keep this service running.
@%systemroot%\system32\wbem\wmiapsrv.exe,-111 : Provides performance library information from Windows Management Instrumentation (WMI) providers to clients on the network. This service only runs when Performance Data Helper is activated.
@%systemroot%\system32\wuaueng.dll,-400 : Windows Update
@%programfiles%\windows media player\wmpnetwk.exe,-102 : Shares Windows Media Player libraries to other networked players and media devices using Universal Plug and Play
@%systemroot%\system32\drivers\ndisimplatform.sys,-501 : Microsoft Network Adapter Multiplexor Protocol
@%systemroot%\system32\qwave.dll,-2 : Quality Windows Audio Video Experience (qWave) is a networking platform for Audio Video (AV) streaming applications on IP home networks. qWave enhances AV streaming performance and reliability by ensuring network quality-of-service (QoS) for AV applications. It provides mechanisms for admission control, run time monitoring and enforcement, application feedback, and traffic prioritization.
@%systemroot%\system32\sessenv.dll,-1026 : Remote Desktop Configuration
@%systemroot%\system32\userdataaccessres.dll,-15000 : Indexes contact data for fast contact searching. If you stop or disable this service, contacts might be missing from your search results.
@%systemroot%\system32\netprofmsvc.dll,-202 : Network List Service
@%systemroot%\system32\appinfo.dll,-100 : Application Information
@%systemroot%\system32\mixedrealityruntime.dll,-101 : Windows Mixed Reality OpenXR Service
@comres.dll,-2797 : Distributed Transaction Coordinator
@%systemroot%\system32\spoolsv.exe,-2 : This service spools print jobs and handles interaction with the printer. If you turn off this service, you won’t be able to print or see your printers.
@%systemroot%\system32\drivers\mpsdrv.sys,-23092 : Windows Defender Firewall Authorization Driver
@%systemroot%\system32\userdataaccessres.dll,-14001 : User Data Access
@%systemroot%\system32\themeservice.dll,-8193 : Provides user experience theme management.
@%systemroot%\system32\dispbroker.desktop.dll,-102 : Manages the connection and configuration of local and remote displays
@c:\windows\system32\psr.exe,-1701 : Steps Recorder
@%windir%\system32\timebrokerserver.dll,-1002 : Coordinates execution of background work for WinRT application. If this service is stopped or disabled, then background work might not be triggered.
@%systemroot%\system32\wlansvc.dll,-257 : WLAN AutoConfig
@%windir%\system32\speech\speechux\sapi.cpl,-5556 : Dictate text and control your computer by voice.
@%systemroot%\system32\fdphost.dll,-101 : The FDPHOST service hosts the Function Discovery (FD) network discovery providers. These FD providers supply network discovery services for the Simple Services Discovery Protocol (SSDP) and Web Services – Discovery (WS-D) protocol. Stopping or disabling the FDPHOST service will disable network discovery for these protocols when using FD. When this service is unavailable, network services using FD and relying on these discovery protocols will be unable to find network devices or resources.
@%systemroot%\system32\drivers\ndproxy.sys,-6000 : NDIS Proxy Driver
@%systemroot%\system32\drivers\qwavedrv.sys,-1 : QWAVE driver
@%systemroot%\system32\svsvc.dll,-101 : Spot Verifier
@%systemroot%\system32\diagsvc.dll,-101 : Executes diagnostic actions for troubleshooting support
@%systemroot%\system32\agentservice.exe,-102 : User Experience Virtualization Service
@%systemroot%\system32\cryptsvc.dll,-1001 : Cryptographic Services
@%systemroot%\system32\wfdsconmgrsvc.dll,-9000 : Wi-Fi Direct Services Connection Manager Service
@%systemroot%\system32\mprmsg.dll,-32011 : Remote Access IP ARP Driver
@%systemroot%\system32\devquerybroker.dll,-101 : Enables apps to discover devices with a backgroud task
@%programfiles%\windows defender\mpasdesc.dll,-370 : Microsoft Defender Antivirus Network Inspection System Driver
@%systemroot%\system32\nlasvc.dll,-2 : Collects and stores configuration information for the network and notifies programs when this information is modified. If this service is stopped, configuration information might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\licensemanagersvc.dll,-200 : Windows License Manager Service
@%systemroot%\system32\sharedrealitysvc.dll,-101 : This service is used for Spatial Perception scenarios
@c:\windows\system32\taskmgr.exe,-32420 : Task Manager
@%systemroot%\system32\drivers\verifierext.sys,-1000 : Driver Verifier Extension
@%systemroot%\system32\devicesflowbroker.dll,-103 : DevicesFlow
@%systemroot%\system32\wkssvc.dll,-101 : Creates and maintains client network connections to remote servers using the SMB protocol. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\dssvc.dll,-10002 : Provides data brokering between applications.
@%systemroot%\system32\themeservice.dll,-8192 : Themes
@%systemroot%\system32\credentialenrollmentmanager.exe,-101 : Credential Enrollment Manager
@%systemroot%\system32\pcasvc.dll,-2 : This service provides support for the Program Compatibility Assistant (PCA). PCA monitors programs installed and run by the user and detects known compatibility problems. If this service is stopped, PCA will not function properly.
@%systemroot%\system32\dnsapi.dll,-102 : The DNS Client service (dnscache) caches Domain Name System (DNS) names and registers the full computer name for this computer. If the service is stopped, DNS names will continue to be resolved. However, the results of DNS name queries will not be cached and the computer's name will not be registered. If the service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\wkssvc.dll,-1006 : SMB 2.0 MiniRedirector
@%systemroot%\system32\powrprof.dll,-10 : Saves energy by reducing your computer’s performance where possible.
@%windir%\system32\fxsresm.dll,-115 : Send and receive faxes or scan pictures and documents.
@%systemroot%\system32\fhsvc.dll,-101 : File History Service
@%systemroot%\system32\lfsvc.dll,-2 : This service monitors the current location of the system and manages geofences (a geographical location with associated events). If you turn off this service, applications will be unable to use or receive notifications for geolocation or geofences.
@%systemroot%\system32\flightsettings.dll,-104 : Provides infrastructure support for the Windows Insider Program. This service must remain enabled for the Windows Insider Program to work.
@%systemroot%\system32\workfolderssvc.dll,-102 : Work Folders
@c:\windows\system32\msinfo32.exe,-100 : System Information
@%systemroot%\system32\drivers\tunnel.sys,-500 : Microsoft Tunnel Miniport Adapter Driver
@c:\windows\system32\ieframe.dll,-24585 : Cascading Style Sheet Document
@%systemroot%\system32\tieringengineservice.exe,-702 : Storage Tiers Management
@%systemroot%\system32\dhcpcore.dll,-101 : Registers and updates IP addresses and DNS records for this computer. If this service is stopped, this computer will not receive dynamic IP addresses and DNS updates. If this service is disabled, any services that explicitly depend on it will fail to start.
@regsvc.dll,-2 : Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\clipsvc.dll,-103 : Client License Service (ClipSVC)
@%systemroot%\system32\fntcache.dll,-101 : Optimizes performance of applications by caching commonly used font data. Applications will start this service if it is not already running. It can be disabled, though doing so will degrade application performance.
@c:\progra~1\common~1\micros~1\office16\oregres.dll,-436 : Telemetry Dashboard for Office 2016
@%systemroot%\system32\icsvcext.dll,-502 : Coordinates the communications that are required to use Volume Shadow Copy Service to back up applications and data on this virtual machine from the operating system on the physical computer.
@%systemroot%\system32\hvhostsvc.dll,-100 : HV Host Service
@%systemroot%\system32\sdrsvc.dll,-107 : Windows Backup
@%systemroot%\system32\locator.exe,-2 : Remote Procedure Call (RPC) Locator
@%systemroot%\system32\messagingservice.dll,-101 : Service supporting text messaging and related functionality.
@%systemroot%\system32\ipxlatcfg.dll,-501 : Configures and enables translation from v4 to v6 and vice versa
@%systemroot%\system32\drivers\volsnap.sys,-100 : Volume Shadow Copy driver
@%systemroot%\system32\mycomput.dll,-112 : Manages disks and provides access to other tools to manage local and remote computers.
@%systemroot%\system32\wpnservice.dll,-1 : Windows Push Notifications System Service
@%systemroot%\system32\dssvc.dll,-10003 : Data Sharing Service
@%systemroot%\system32\sensrsvc.dll,-1000 : Sensor Monitoring Service
@%systemroot%\system32\seclogon.dll,-7001 : Secondary Logon
@%systemroot%\system32\samsrv.dll,-1 : Security Accounts Manager
@%systemroot%\system32\wpnuserservice.dll,-2 : This service hosts Windows notification platform which provides support for local and push notifications. Supported notifications are tile, toast and raw.
@%systemroot%\system32\umrdp.dll,-1000 : Remote Desktop Services UserMode Port Redirector
@%systemroot%\system32\windows.internal.management.dll,-101 : Performs Device Enrollment Activities for Device Management
@%systemroot%\system32\drivers\iorate.sys,-101 : Disk I/O Rate Filter Driver
@%windir%\system32\bisrv.dll,-100 : Background Tasks Infrastructure Service
@%systemroot%\system32\shsvcs.dll,-12289 : Provides notifications for AutoPlay hardware events.
@%systemroot%\system32\netman.dll,-109 : Network Connections
@%systemroot%\system32\drivers\filetrace.sys,-10001 : FileTrace
@%systemroot%\system32\devicesetupmanager.dll,-1001 : Enables the detection, download and installation of device-related software. If this service is disabled, devices may be configured with outdated software, and may not work correctly.
@%systemroot%\system32\wersvc.dll,-101 : Allows errors to be reported when programs stop working or responding and allows existing solutions to be delivered. Also allows logs to be generated for diagnostic and repair services. If this service is stopped, error reporting might not work correctly and results of diagnostic services and repairs might not be displayed.
@%systemroot%\system32\dosvc.dll,-100 : Delivery Optimization
@%systemroot%\system32\storsvc.dll,-100 : Storage Service
@%systemroot%\system32\smsroutersvc.dll,-10002 : Routes messages based on rules to appropriate clients.

MUICache report attached.

51351 - Microsoft .NET Framework Detection
-
Synopsis
A software framework is installed on the remote host.
Description
Microsoft .NET Framework, a software framework for Microsoft Windows operating systems, is installed on the remote host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0655
Plugin Information
Published: 2010/12/20, Modified: 2025/10/15
Plugin Output

tcp/445/cifs


Nessus detected 5 installs of Microsoft .NET Framework:

Path : C:\Windows\Microsoft.NET\Framework64\v2.0.50727
Version : 2.0.50727
Full Version : 2.0.50727.4927
SP : 2

Path : C:\Windows\Microsoft.NET\Framework64\v3.0
Version : 3.0
Full Version : 3.0.30729.4926
SP : 2

Path : C:\WINDOWS\Microsoft.NET\Framework64\v3.5\
Version : 3.5
Full Version : 3.5.30729.4926
SP : 1

Path : C:\Windows\Microsoft.NET\Framework64\v4.0.30319\
Version : 4.8.1
Full Version : 4.8.09037
Install Type : Full
Release : 533325

Path : C:\Windows\Microsoft.NET\Framework64\v4.0.30319\
Version : 4.8.1
Full Version : 4.8.09037
Install Type : Client
Release : 533325
99364 - Microsoft .NET Security Rollup Enumeration
-
Synopsis
This plugin enumerates installed Microsoft .NET security rollups.
Description
Nessus was able to enumerate the Microsoft .NET security rollups installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2017/04/14, Modified: 2025/10/23
Plugin Output

tcp/445/cifs


Nessus detected 2 installs of Microsoft .NET Framework:

Path : C:\WINDOWS\winsxs\*system.printing_31bf3856ad364e35*
Version : 3.0.6920.9163
.NET Version : 3.5
Associated KB : 5044023
Latest effective update level : 10_2024

Path : C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorlib.dll
Version : 4.8.9290.0
.NET Version : 4.8.1
Associated KB : 5049621
Latest effective update level : 01_2025

192148 - Microsoft Azure Data Studio Installed (Windows)
-
Synopsis
Microsoft Azure Data Studio is installed on the remote Windows host.
Description
Microsoft Azure Data Studio is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2024/03/15, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\Program Files\Azure Data Studio\
Version : 1.32.0.0
162560 - Microsoft Internet Explorer Installed
-
Synopsis
A web browser is installed on the remote Windows host.
Description
Microsoft Internet Explorer, a web browser bundled with Microsoft Windows, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2022/06/28, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\WINDOWS\system32\mshtml.dll
Version : 11.0.19041.5915

72367 - Microsoft Internet Explorer Version Detection
-
Synopsis
Internet Explorer is installed on the remote host.
Description
The remote Windows host contains Internet Explorer, a web browser created by Microsoft.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0509
Plugin Information
Published: 2014/02/06, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Version : 11.3636.19041.0
66424 - Microsoft Malicious Software Removal Tool Installed
-
Synopsis
An antimalware application is installed on the remote Windows host.
Description
The Microsoft Malicious Software Removal Tool is installed on the remote host. This tool is an application that attempts to detect and remove known malware from Windows systems.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/05/15, Modified: 2023/01/10
Plugin Output

tcp/445/cifs


File : C:\WINDOWS\system32\MRT.exe
Version : 5.134.25060.1001
Release at last run : unknown
Report infection information to Microsoft : Yes
174413 - Microsoft ODBC Driver for SQL Server Installed (Windows)
-
Synopsis
Microsoft ODBC Driver for SQL Server is installed on the remote Windows host.
Description
Microsoft ODBC Driver for SQL Server is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/04/17, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Path : C:\Windows\System32\msodbcsql17.dll
Version : 17.10.6.1
174405 - Microsoft OLE DB Driver for SQL Server Installed (Windows)
-
Synopsis
Microsoft OLE DB Driver for SQL Server is installed on the remote Windows host.
Description
Microsoft OLE DB Driver for SQL Server is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/04/17, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Path : C:\Windows\System32\msoledbsql.dll
Version : 18.7.4.0
93232 - Microsoft Office Compatibility Pack Installed (credentialed check)
-
Synopsis
A compatibility application is installed on the remote host.
Description
Microsoft Office Compatibility Pack, used to enable older versions of Microsoft Office applications to view and edit files created with newer versions of Microsoft Office applications, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0663
Plugin Information
Published: 2016/08/30, Modified: 2025/09/29
Plugin Output

tcp/445/cifs


Office Compatibility Pack is installed with the following components:

Component : Excel Converter
Version : 16.0.5495.1000
Path : C:\Program Files\Microsoft Office\Office16\Excelcnv.exe

Component : Word Converter
Version : 16.0.4266.1001
Path : C:\Program Files\Microsoft Office\Office16\Wordconv.exe
27524 - Microsoft Office Detection
-
Synopsis
The remote Windows host contains an office suite.
Description
Microsoft Office is installed on the remote host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0505
Plugin Information
Published: 2007/10/23, Modified: 2025/10/14
Plugin Output

tcp/445/cifs


The remote host has the following Microsoft Office 2016 Service Pack 0 components installed :

- Excel : 16.0.5495.1000
- ExcelCnv : 16.0.5495.1000
- PowerPoint : 16.0.5483.1000
- WordCnv : 16.0.4266.1001
- Word : 16.0.5495.1002
- Groove : 16.0.4723.1000
- OneNote : 16.0.5472.1000
- Publisher : 16.0.5460.1000
- Outlook : 16.0.5483.1000

92425 - Microsoft Office File History
-
Synopsis
Nessus was able to enumerate files opened in Microsoft Office on the remote host.
Description
Nessus was able to gather evidence of files that were opened using any Microsoft Office application. The report was extracted from Office MRU (Most Recently Used) registry keys.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

item 1
item 4
item 5
item 3
item 2
item 1
item 1
item 4
item 5
item 3
item 2
item 1
item 1
item 4
item 5
item 3
item 2
item 1
item 1
item 4
item 5
item 3
item 2
item 1
item 1
item 4
item 5
item 3
item 2
item 1
item 1
item 4
item 5
item 3
item 2
item 1
item 1
item 4
item 5
item 3
item 2
item 1
item 1
item 4
item 5
item 3
item 2
item 1
item 1
item 4
item 5
item 3
item 2
item 1
C:\\Users\Techrobot\AppData\Roaming\Microsoft\Office\Recent\CDASWEB Certificate Import For Clients.doc.LNK
C:\\Users\Techrobot\AppData\Roaming\Microsoft\Office\Recent\HDFC_BRS_Sheet.xlsx.LNK
C:\\Users\Techrobot\AppData\Roaming\Microsoft\Office\Recent\index.dat
C:\\Users\Techrobot\AppData\Roaming\Microsoft\Office\Recent\MCX_PeakMargin56630_20250402_01.csv.LNK
C:\\Users\Techrobot\AppData\Roaming\Microsoft\Office\Recent\MCX_PeakMargin56630_20250402_03.csv.LNK
C:\\Users\Techrobot\AppData\Roaming\Microsoft\Office\Recent\Templates.LNK

User AppData recent used file report attached
Office MRU registry report attached.
92361 - Microsoft Office Macros Configuration
-
Synopsis
Nessus was able to collect and report Office macro configuration data for active accounts on the remote host.
Description
Nessus was able to collect Office macro configuration information for active accounts on the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/16
Plugin Output

tcp/0

Office macros information attached.

138603 - Microsoft OneDrive Installed
-
Synopsis
A file hosting application is installed on the remote host.
Description
Microsoft OneDrive, a file hosting service, is installed on the remote host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2020/07/17, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Nessus detected 5 installs of Microsoft OneDrive:

Path : C:\Users\Techexcel\AppData\Local\Microsoft\OneDrive\
Version : 23.23.129.2

Path : C:\Users\Techrobot\AppData\Local\Microsoft\OneDrive\
Version : 25.224.1116.3

Path : C:\Users\tidua\AppData\Local\Microsoft\OneDrive\
Version : 25.238.1204.1

Path : C:\Users\LKPAdmin\AppData\Local\Microsoft\OneDrive\
Version : 23.194.917.1

Path : C:\Users\Administrator\AppData\Local\Microsoft\OneDrive\
Version : 25.222.1112.2

77605 - Microsoft OneNote Detection
-
Synopsis
The remote Windows host contains Microsoft OneNote.
Description
Microsoft OneNote is installed on the remote host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0664
Plugin Information
Published: 2014/09/10, Modified: 2025/09/29
Plugin Output

tcp/0


Path : C:\Program Files\Microsoft Office\Office16\OneNote.exe
Version : 16.0.5472.1000
124120 - Microsoft Outlook Attachment Previewing Enabled
-
Synopsis
Microsoft Outlook application that is installed on the remote host has attachment previewing enabled.
Description
Microsoft Outlook application that is installed on the remote host has attachment previewing enabled.
Solution
Disable attachment previewing settings.
Risk Factor
None
Plugin Information
Published: 2019/04/17, Modified: 2019/04/17
Plugin Output

tcp/0

Outlook application in Microsoft Office 2016 has attachment previewing enabled.

57033 - Microsoft Patch Bulletin Feasibility Check
-
Synopsis
Nessus is able to check for Microsoft patch bulletins.
Description
Using credentials supplied in the scan policy, Nessus is able to collect information about the software and patches installed on the remote Windows host and will use that information to check for missing Microsoft security updates.

Note that this plugin is purely informational.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/06, Modified: 2021/07/12
Plugin Output

tcp/445/cifs



Nessus is able to test for missing patches using :
Nessus

125835 - Microsoft Remote Desktop Connection Installed
-
Synopsis
A graphical interface connection utility is installed on the remote Windows host
Description
Microsoft Remote Desktop Connection (also known as Remote Desktop Protocol or Terminal Services Client) is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2019/06/12, Modified: 2022/10/10
Plugin Output

tcp/0


Path : C:\WINDOWS\\System32\\mstsc.exe
Version : 10.0.19041.5965
118095 - Microsoft SQL Server Management Studio (SSMS) Installed
-
Synopsis
A SQL Server Management solution is installed on the remote Windows host.
Description
Microsoft SQL Server Management Studio (SSMS) is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0805
Plugin Information
Published: 2018/10/12, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\Program Files (x86)\Microsoft SQL Server Management Studio 18\Common7\IDE\
Version : 2019.150.18390.0

93962 - Microsoft Security Rollup Enumeration
-
Synopsis
This plugin enumerates installed Microsoft security rollups.
Description
Nessus was able to enumerate the Microsoft security rollups installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/10/11, Modified: 2025/11/18
Plugin Output

tcp/445/cifs


Cumulative Rollup : 06_2025 [KB5060533]
Cumulative Rollup : 05_2025
Cumulative Rollup : 04_2025
Cumulative Rollup : 03_2025
Cumulative Rollup : 02_2025
Cumulative Rollup : 01_2025
Cumulative Rollup : 12_2024
Cumulative Rollup : 11_2024
Cumulative Rollup : 10_2024
Cumulative Rollup : 09_2024
Cumulative Rollup : 08_2024
Cumulative Rollup : 07_2024
Cumulative Rollup : 06_2024
Cumulative Rollup : 05_2024
Cumulative Rollup : 04_2024
Cumulative Rollup : 03_2024
Cumulative Rollup : 02_2024
Cumulative Rollup : 01_2024
Cumulative Rollup : 12_2023
Cumulative Rollup : 11_2023
Cumulative Rollup : 10_2023
Cumulative Rollup : 09_2023
Cumulative Rollup : 08_2023
Cumulative Rollup : 07_2023
Cumulative Rollup : 06_2023
Cumulative Rollup : 05_2023
Cumulative Rollup : 04_2023
Cumulative Rollup : 03_2023
Cumulative Rollup : 02_2023
Cumulative Rollup : 01_2023
Cumulative Rollup : 12_2022
Cumulative Rollup : 11_2022

Latest effective update level : 06_2025
File checked : C:\WINDOWS\system32\ntoskrnl.exe
File version : 10.0.19041.5965
Associated KB : 5060533
42399 - Microsoft Silverlight Detection
-
Synopsis
The remote host has Microsoft Silverlight installed.
Description
A version of Microsoft's Silverlight is installed on this host.

Microsoft Silverlight is a web application framework that provides functionalities similar to those in Adobe Flash, integrating multimedia, graphics, animations and interactivity into a single runtime environment.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0666
Plugin Information
Published: 2009/11/05, Modified: 2022/10/10
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Microsoft Silverlight\5.1.50907.0
Version : 5.1.50907.0
50346 - Microsoft Update Installed
-
Synopsis
A software updating service is installed.
Description
Microsoft Update, an expanded version of Windows Update, is installed on the remote Windows host. This service provides updates for the operating system and Internet Explorer as well as other Windows software such as Microsoft Office, Exchange, and SQL Server.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/10/26, Modified: 2022/02/01
Plugin Output

tcp/445/cifs

265694 - Microsoft Visual Studio Tools for Applications Installed (Windows)
-
Synopsis
The remote Windows host has an integrated development environment installed.
Description
Microsoft Visual Studio Tools for Applications (VSTA) is a set of tools that independent software vendors (ISVs) can use to build customization abilities into their applications for both automation and extensibility, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/09/22, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\Program Files\Common Files\Microsoft Shared\VSTA\15.0\Bin\VstaCore.dll
Version : 15.0.27520
product_version : 2017

10902 - Microsoft Windows 'Administrators' Group User List
-
Synopsis
There is at least one user in the 'Administrators' group.
Description
Using the supplied credentials, it is possible to extract the member list of the 'Administrators' group. Members of this group have complete access to the remote system.
Solution
Verify that each member of the group should have this type of access.
Risk Factor
None
Plugin Information
Published: 2002/03/15, Modified: 2018/05/16
Plugin Output

tcp/445/cifs


The following users are members of the 'Administrators' group :

- LIVETECHROBO\Production (User)
- LIVETECHROBO\LKPAdmin (User)
- LIVETECHROBO\Techrobot (User)
- LIVETECHROBO\Techexcel (User)
- LIVETECHROBO\tidua (User)
48763 - Microsoft Windows 'CWDIllegalInDllSearch' Registry Setting
-
Synopsis
CWDIllegalInDllSearch Settings: Improper settings could allow code execution attacks.
Description
Windows Hosts can be hardened against DLL hijacking attacks by setting the The 'CWDIllegalInDllSearch' registry entry in to one of the following settings:

- 0xFFFFFFFF (Removes the current working directory from the default DLL search order)

- 1 (Blocks a DLL Load from the current working directory if the current working directory is set to a WebDAV folder)

- 2 (Blocks a DLL Load from the current working directory if the current working directory is set to a remote folder)
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/08/26, Modified: 2019/12/20
Plugin Output

tcp/445/cifs


Name : SYSTEM\CurrentControlSet\Control\Session Manager\CWDIllegalInDllSearch
Value : Registry Key Empty or Missing

92370 - Microsoft Windows ARP Table
-
Synopsis
Nessus was able to collect and report ARP table information from the remote host.
Description
Nessus was able to collect ARP table information from the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2025/12/15
Plugin Output

tcp/0

172.17.100.10 : 78-64-a0-ba-d1-47
172.17.100.19 : 00-50-56-88-d2-f4
172.17.100.31 : d4-f5-ef-60-4d-20
172.17.100.33 : d4-f5-ef-60-36-fc
172.17.100.34 : 00-50-56-bc-53-be
172.17.100.38 : 00-50-56-88-a7-ac
172.17.100.39 : 00-50-56-bc-4f-46
172.17.100.50 : 00-50-56-88-59-f9
172.17.100.53 : 00-50-56-88-ef-ed
172.17.100.56 : 00-50-56-88-08-9c
172.17.100.59 : 00-50-56-88-e7-eb
172.17.100.62 : 00-50-56-bc-30-36
172.17.100.68 : 00-50-56-93-38-d4
172.17.100.69 : 00-50-56-93-20-59
172.17.100.73 : 40-a8-f0-20-84-35
172.17.100.78 : 00-50-56-bc-8d-b9
172.17.100.79 : 00-50-56-bc-fe-be
172.17.100.81 : 00-50-56-93-1e-75
172.17.100.83 : 00-50-56-bc-b4-9f
172.17.100.91 : 00-50-56-88-23-83
172.17.100.93 : 00-50-56-bc-85-97
172.17.100.95 : 00-50-56-bc-16-9d
172.17.100.111 : 00-50-56-88-dc-d2
172.17.100.112 : 00-50-56-bc-7d-2b
172.17.100.116 : 00-50-56-88-63-80
172.17.100.117 : 00-50-56-bc-4d-ab
172.17.100.131 : 5c-ba-2c-3b-7d-e8
172.17.100.132 : 5c-ba-2c-3b-ee-48
172.17.100.133 : 5c-ba-2c-3b-2e-6e
172.17.100.140 : 00-50-56-88-13-c1
172.17.100.141 : 00-50-56-88-57-a4
172.17.100.146 : 00-50-56-93-e4-72
172.17.100.154 : 00-50-56-bc-f3-c3
172.17.100.160 : 00-50-56-88-49-b4
172.17.100.167 : 00-50-56-bc-74-6f
172.17.100.183 : 00-50-56-bc-ed-d0
172.17.100.186 : 00-50-56-bc-ad-94
172.17.100.189 : 00-50-56-bc-6b-55
172.17.100.190 : 00-50-56-88-d4-3e
172.17.100.222 : 24-5e-be-5c-14-77
172.17.100.223 : 24-5e-be-5c-14-76
172.17.100.224 : 00-50-56-88-8f-dc
172.17.100.254 : 1a-c2-41-87-f6-3d
172.17.100.255 : ff-ff-ff-ff-ff-ff
224.0.0.22 : 01-00-5e-00-00-16
224.0.0.251 : 01-00-5e-00-00-fb
224.0.0.252 : 01-00-5e-00-00-fc
239.255.255.250 : 01-00-5e-7f-ff-fa
255.255.255.255 : ff-ff-ff-ff-ff-ff

Extended ARP table information attached.
70615 - Microsoft Windows AutoRuns Boot Execute
-
Synopsis
Report programs that startup associates with session manager subsystem.
Description
Report registry startup locations associated with the session manager subsystem during boot time.

These registry keys start-up with the smss.exe service during boot time and perform system tasks that cannot be performed while Windows is running.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0

+ HKLM\System\CurrentControlSet\Control\Session Manager\bootexecute
- autocheck autochk *

70616 - Microsoft Windows AutoRuns Codecs
-
Synopsis
Report programs set to normally start with multimedia.
Description
Codecs are encoders and decoders for digital data streams commonly associated with video and audio playback.

The following keys are codecs that are set to start automatically to control different types of digital media encoding and decoding.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
- wave : wdmaud.drv
- vidc.yvu9 : tsbyuv.dll
- vidc.mrle : msrle32.dll
- vidc.iyuv : iyuv_32.dll
- wavemapper : msacm32.drv
- msacm.msadpcm : msadp32.acm
- mixer : wdmaud.drv
- vidc.yuy2 : msyuv.dll
- vidc.uyvy : msyuv.dll
- vidc.msvc : msvidc32.dll
- msacm.imaadpcm : imaadp32.acm
- msacm.msg711 : msg711.acm
- msacm.msgsm610 : msgsm32.acm
- msacm.l3acm : C:\Windows\System32\l3codeca.acm
- midi : wdmaud.drv
- aux : wdmaud.drv
- vidc.yvyu : msyuv.dll
- midimapper : midimap.dll
- vidc.i420 : iyuv_32.dll


+ HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32
- wave : wdmaud.drv
- vidc.yvu9 : tsbyuv.dll
- vidc.mrle : msrle32.dll
- vidc.iyuv : iyuv_32.dll
- wavemapper : msacm32.drv
- msacm.msadpcm : msadp32.acm
- mixer : wdmaud.drv
- vidc.yuy2 : msyuv.dll
- vidc.uyvy : msyuv.dll
- vidc.msvc : msvidc32.dll
- msacm.imaadpcm : imaadp32.acm
- msacm.msg711 : msg711.acm
- msacm.msgsm610 : msgsm32.acm
- msacm.l3acm : C:\Windows\SysWOW64\l3codeca.acm
- midi : wdmaud.drv
- vidc.cvid : iccvid.dll
- aux : wdmaud.drv
- vidc.yvyu : msyuv.dll
- midimapper : midimap.dll
- vidc.i420 : iyuv_32.dll


+ HKLM\Software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance
+ CLSID : {129D7E40-C10D-11D0-AFB9-00AA00B67A42}
- Name : DV Muxer
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {1643E180-90F5-11CE-97D5-00AA0055595A}
- Name : Color Space Converter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {187463A0-5BB7-11D3-ACBE-0080C75E246E}
- Name : WM ASF Reader
- Value : C:\Windows\System32\qasf.dll

+ CLSID : {1B544C20-FD0B-11CE-8C63-00AA0044B51E}
- Name : AVI Splitter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {1DA08500-9EDC-11CF-BC10-00AA00AC74F6}
- Name : VGA 16 Color Ditherer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {1f26a602-2b5c-4b63-b8e8-9ea5c1a7dc2e}
- Name : SBE2MediaTypeProfile
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {212690FB-83E5-4526-8FD7-74478B7939CD}
- Name : Microsoft DTV-DVD Video Decoder
- Value : C:\Windows\System32\msmpeg2vdec.dll

+ CLSID : {280A3020-86CF-11D1-ABE6-00A0C905F375}
- Name : AC3 Parser Filter
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {2DB47AE5-CF39-43C2-B4D6-0CD8D90946F4}
- Name : StreamBufferSink
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {301056D0-6DFF-11D2-9EEB-006008039E37}
- Name : MJPEG Decompressor
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {336475D0-942A-11CE-A870-00AA002FEAB5}
- Name : MPEG-I Stream Splitter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {33FACFE0-A9BE-11D0-A520-00A0D10129C0}
- Name : SAMI (CC) Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {370A1D5D-DDEB-418C-81CD-189E0D4FA443}
- Name : VBI Codec
- Value : C:\Windows\System32\VBICodec.ax

+ CLSID : {3AE86B20-7BE8-11D1-ABE6-00A0C905F375}
- Name : MPEG-2 Splitter
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {3D07A539-35CA-447C-9B05-8D85CE924F9E}
- Name : Closed Captions Analysis Filter
- Value : C:\Windows\System32\cca.dll

+ CLSID : {3E458037-0CA6-41aa-A594-2AA6C02D709B}
- Name : SBE2FileScan
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {42150CD9-CA9A-4EA5-9939-30EE037F6E74}
- Name : Microsoft MPEG-2 Video Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {48025243-2D39-11CE-875D-00608CB78066}
- Name : Internal Script Command Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {4A2286E0-7BEF-11CE-9BD9-0000E202599C}
- Name : MPEG Audio Decoder
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {4EB31670-9FC6-11CF-AF6E-00AA00B67A42}
- Name : DV Splitter
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {51B4ABF3-748F-4E3B-A276-C828330E926A}
- Name : Video Mixing Renderer 9
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {5F5AFF4A-2F7F-4279-88C2-CD88EB39D144}
- Name : Microsoft MPEG-2 Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {6A08CF80-0E18-11CF-A24D-0020AFD79767}
- Name : ACM Wrapper
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {6BC1CFFA-8FC1-4261-AC22-CFB4CC38DB50}
- Name : Video Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {6CFAD761-735D-4AA5-8AFC-AF91A7D61EBA}
- Name : MPEG-2 Video Stream Analyzer
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {6E8D4A20-310C-11D0-B79A-00AA003767A7}
- Name : Line 21 Decoder
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {6F26A6CD-967B-47FD-874A-7AED2C9D25A2}
- Name : Video Port Manager
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {70E102B0-5556-11CE-97C0-00AA0055595A}
- Name : Video Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {7B3BC2A0-AA50-4ae7-BD44-B03649EC87C2}
- Name : VPS Decoder
- Value : C:\Windows\System32\WSTPager.ax

+ CLSID : {7C23220E-55BB-11D3-8B16-00C04FB6BD3D}
- Name : WM ASF Writer
- Value : C:\Windows\System32\qasf.dll

+ CLSID : {814B9800-1C88-11D1-BAD9-00609744111A}
- Name : VBI Surface Allocator
- Value : %SystemRoot%\System32\vbisurf.ax

+ CLSID : {8596E5F0-0DA5-11D0-BD21-00A0C911CE86}
- Name : File writer
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {9B8C4620-2C1A-11D0-8493-00A02438AD48}
- Name : DVD Navigator
- Value : C:\Windows\System32\qdvd.dll

+ CLSID : {A0025E90-E45B-11D1-ABE9-00A0C905F375}
- Name : Overlay Mixer2
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {A888DF60-1E90-11CF-AC98-00AA004C0FA9}
- Name : AVI Draw
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {ACD453BC-C58A-44D1-BBF5-BFB325BE2D78}
- Name : Microsoft MPEG-2 Audio Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {AD6C8934-F31B-4F43-B5E4-0541C1452F6F}
- Name : WST Pager
- Value : C:\Windows\System32\WSTPager.ax

+ CLSID : {AFB6C280-2C41-11D3-8A60-0000F81E0E4A}
- Name : MPEG-2 Demultiplexer
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {B1B77C00-C3E4-11CF-AF79-00AA00B67A42}
- Name : DV Video Decoder
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {C1F400A0-3F08-11D3-9F0B-006008039E37}
- Name : SampleGrabber
- Value : C:\Windows\System32\qedit.dll

+ CLSID : {C1F400A4-3F08-11D3-9F0B-006008039E37}
- Name : Null Renderer
- Value : C:\Windows\System32\qedit.dll

+ CLSID : {C666E115-BB62-4027-A113-82D643FE2D99}
- Name : MPEG-2 Sections and Tables
- Value : C:\Windows\System32\Mpeg2Data.ax

+ CLSID : {C6B400E2-20A7-4E58-A2FE-24619682CE6C}
- Name : Microsoft AC3 Encoder
- Value : C:\Windows\System32\msac3enc.dll

+ CLSID : {C9F5FE02-F851-4EB5-99EE-AD602AF1E619}
- Name : StreamBufferSource
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {CC58E280-8AA1-11D1-B3F1-00AA003761C5}
- Name : Smart Tee
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {CD8743A1-3736-11D0-9E69-00C04FD7C15B}
- Name : Overlay Mixer
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {CF49D4E0-1115-11CE-B03A-0020AF0BA770}
- Name : AVI Decompressor
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D3588AB0-0781-11CE-B03A-0020AF0BA770}
- Name : AVI/WAV File Source
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A1-7548-11CF-A520-0080C77EF58A}
- Name : Wave Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A2-7548-11CF-A520-0080C77EF58A}
- Name : MIDI Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A3-7548-11CF-A520-0080C77EF58A}
- Name : Multi-file Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A5-7548-11CF-A520-0080C77EF58A}
- Name : File stream renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E1F1A0B8-BEEE-490D-BA7C-066C40B5E2B9}
- Name : Microsoft DTV-DVD Audio Decoder
- Value : C:\Windows\System32\msmpeg2adec.dll

+ CLSID : {E2448508-95DA-4205-9A27-7EC81E723B1A}
- Name : StreamBufferSink2
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {E2510970-F137-11CE-8B67-00AA00A3F1A6}
- Name : AVI Mux
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {E4206432-01A1-4BEE-B3E1-3702C8EDC574}
- Name : Line 21 Decoder 2
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E436EBB5-524F-11CE-9F53-0020AF0BA770}
- Name : File Source (Async.)
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E436EBB6-524F-11CE-9F53-0020AF0BA770}
- Name : File Source (URL)
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {F8388A40-D5BB-11D0-BE5A-0080C706568E}
- Name : Infinite Pin Tee Filter
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {FA10746C-9B63-4B6C-BC49-FC300EA5F256}
- Name : Enhanced Video Renderer
- Value : C:\Windows\System32\evr.dll

+ CLSID : {FC772AB0-0C7F-11D3-8FF2-00A0C9224CF4}
- Name : BDA MPEG2 Transport Information Filter
- Value : C:\Windows\System32\psisrndr.ax

+ CLSID : {FEB50740-7BEF-11CE-9BD9-0000E202599C}
- Name : MPEG Video Decoder
- Value : C:\Windows\System32\quartz.dll


+ HKLM\Software\Wow6432Node\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance
+ CLSID : {129D7E40-C10D-11D0-AFB9-00AA00B67A42}
- Name : DV Muxer
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {1643E180-90F5-11CE-97D5-00AA0055595A}
- Name : Color Space Converter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {187463A0-5BB7-11D3-ACBE-0080C75E246E}
- Name : WM ASF Reader
- Value : C:\Windows\System32\qasf.dll

+ CLSID : {1B544C20-FD0B-11CE-8C63-00AA0044B51E}
- Name : AVI Splitter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {1DA08500-9EDC-11CF-BC10-00AA00AC74F6}
- Name : VGA 16 Color Ditherer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {1f26a602-2b5c-4b63-b8e8-9ea5c1a7dc2e}
- Name : SBE2MediaTypeProfile
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {212690FB-83E5-4526-8FD7-74478B7939CD}
- Name : Microsoft DTV-DVD Video Decoder
- Value : C:\Windows\System32\msmpeg2vdec.dll

+ CLSID : {280A3020-86CF-11D1-ABE6-00A0C905F375}
- Name : AC3 Parser Filter
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {2DB47AE5-CF39-43C2-B4D6-0CD8D90946F4}
- Name : StreamBufferSink
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {301056D0-6DFF-11D2-9EEB-006008039E37}
- Name : MJPEG Decompressor
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {336475D0-942A-11CE-A870-00AA002FEAB5}
- Name : MPEG-I Stream Splitter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {33FACFE0-A9BE-11D0-A520-00A0D10129C0}
- Name : SAMI (CC) Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {370A1D5D-DDEB-418C-81CD-189E0D4FA443}
- Name : VBI Codec
- Value : C:\Windows\System32\VBICodec.ax

+ CLSID : {3AE86B20-7BE8-11D1-ABE6-00A0C905F375}
- Name : MPEG-2 Splitter
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {3D07A539-35CA-447C-9B05-8D85CE924F9E}
- Name : Closed Captions Analysis Filter
- Value : C:\Windows\System32\cca.dll

+ CLSID : {3E458037-0CA6-41aa-A594-2AA6C02D709B}
- Name : SBE2FileScan
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {42150CD9-CA9A-4EA5-9939-30EE037F6E74}
- Name : Microsoft MPEG-2 Video Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {48025243-2D39-11CE-875D-00608CB78066}
- Name : Internal Script Command Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {4A2286E0-7BEF-11CE-9BD9-0000E202599C}
- Name : MPEG Audio Decoder
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {4EB31670-9FC6-11CF-AF6E-00AA00B67A42}
- Name : DV Splitter
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {51B4ABF3-748F-4E3B-A276-C828330E926A}
- Name : Video Mixing Renderer 9
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {5F5AFF4A-2F7F-4279-88C2-CD88EB39D144}
- Name : Microsoft MPEG-2 Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {6A08CF80-0E18-11CF-A24D-0020AFD79767}
- Name : ACM Wrapper
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {6BC1CFFA-8FC1-4261-AC22-CFB4CC38DB50}
- Name : Video Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {6CFAD761-735D-4AA5-8AFC-AF91A7D61EBA}
- Name : MPEG-2 Video Stream Analyzer
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {6E8D4A20-310C-11D0-B79A-00AA003767A7}
- Name : Line 21 Decoder
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {6F26A6CD-967B-47FD-874A-7AED2C9D25A2}
- Name : Video Port Manager
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {70E102B0-5556-11CE-97C0-00AA0055595A}
- Name : Video Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {7B3BC2A0-AA50-4ae7-BD44-B03649EC87C2}
- Name : VPS Decoder
- Value : C:\Windows\System32\WSTPager.ax

+ CLSID : {7C23220E-55BB-11D3-8B16-00C04FB6BD3D}
- Name : WM ASF Writer
- Value : C:\Windows\System32\qasf.dll

+ CLSID : {814B9800-1C88-11D1-BAD9-00609744111A}
- Name : VBI Surface Allocator
- Value : %SystemRoot%\System32\vbisurf.ax

+ CLSID : {8596E5F0-0DA5-11D0-BD21-00A0C911CE86}
- Name : File writer
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {9B8C4620-2C1A-11D0-8493-00A02438AD48}
- Name : DVD Navigator
- Value : C:\Windows\System32\qdvd.dll

+ CLSID : {A0025E90-E45B-11D1-ABE9-00A0C905F375}
- Name : Overlay Mixer2
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {A888DF60-1E90-11CF-AC98-00AA004C0FA9}
- Name : AVI Draw
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {ACD453BC-C58A-44D1-BBF5-BFB325BE2D78}
- Name : Microsoft MPEG-2 Audio Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {AD6C8934-F31B-4F43-B5E4-0541C1452F6F}
- Name : WST Pager
- Value : C:\Windows\System32\WSTPager.ax

+ CLSID : {AFB6C280-2C41-11D3-8A60-0000F81E0E4A}
- Name : MPEG-2 Demultiplexer
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {B1B77C00-C3E4-11CF-AF79-00AA00B67A42}
- Name : DV Video Decoder
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {C1F400A0-3F08-11D3-9F0B-006008039E37}
- Name : SampleGrabber
- Value : C:\Windows\System32\qedit.dll

+ CLSID : {C1F400A4-3F08-11D3-9F0B-006008039E37}
- Name : Null Renderer
- Value : C:\Windows\System32\qedit.dll

+ CLSID : {C666E115-BB62-4027-A113-82D643FE2D99}
- Name : MPEG-2 Sections and Tables
- Value : C:\Windows\System32\Mpeg2Data.ax

+ CLSID : {C6B400E2-20A7-4E58-A2FE-24619682CE6C}
- Name : Microsoft AC3 Encoder
- Value : C:\Windows\System32\msac3enc.dll

+ CLSID : {C9F5FE02-F851-4EB5-99EE-AD602AF1E619}
- Name : StreamBufferSource
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {CC58E280-8AA1-11D1-B3F1-00AA003761C5}
- Name : Smart Tee
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {CD8743A1-3736-11D0-9E69-00C04FD7C15B}
- Name : Overlay Mixer
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {CF49D4E0-1115-11CE-B03A-0020AF0BA770}
- Name : AVI Decompressor
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D3588AB0-0781-11CE-B03A-0020AF0BA770}
- Name : AVI/WAV File Source
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A1-7548-11CF-A520-0080C77EF58A}
- Name : Wave Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A2-7548-11CF-A520-0080C77EF58A}
- Name : MIDI Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A3-7548-11CF-A520-0080C77EF58A}
- Name : Multi-file Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A5-7548-11CF-A520-0080C77EF58A}
- Name : File stream renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E1F1A0B8-BEEE-490D-BA7C-066C40B5E2B9}
- Name : Microsoft DTV-DVD Audio Decoder
- Value : C:\Windows\System32\msmpeg2adec.dll

+ CLSID : {E2448508-95DA-4205-9A27-7EC81E723B1A}
- Name : StreamBufferSink2
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {E2510970-F137-11CE-8B67-00AA00A3F1A6}
- Name : AVI Mux
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {E4206432-01A1-4BEE-B3E1-3702C8EDC574}
- Name : Line 21 Decoder 2
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E436EBB5-524F-11CE-9F53-0020AF0BA770}
- Name : File Source (Async.)
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E436EBB6-524F-11CE-9F53-0020AF0BA770}
- Name : File Source (URL)
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {F8388A40-D5BB-11D0-BE5A-0080C706568E}
- Name : Infinite Pin Tee Filter
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {FA10746C-9B63-4B6C-BC49-FC300EA5F256}
- Name : Enhanced Video Renderer
- Value : C:\Windows\System32\evr.dll

+ CLSID : {FC772AB0-0C7F-11D3-8FF2-00A0C9224CF4}
- Name : BDA MPEG2 Transport Information Filter
- Value : C:\Windows\System32\psisrndr.ax

+ CLSID : {FEB50740-7BEF-11CE-9BD9-0000E202599C}
- Name : MPEG Video Decoder
- Value : C:\Windows\System32\quartz.dll


+ HKLM\Software\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance
+ CLSID : {41945702-8302-44A6-9445-AC98E8AFA086}
- Name : Microsoft Raw Image Decoder
- Value : %SystemRoot%\system32\MSRAWImage.dll

+ CLSID : {5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}
- Name : Microsoft Camera Raw Decoder
- Value : C:\Windows\System32\WindowsCodecsRaw.dll


+ HKLM\Software\Wow6432Node\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance
+ CLSID : {41945702-8302-44A6-9445-AC98E8AFA086}
- Name : Microsoft Raw Image Decoder
- Value : %SystemRoot%\system32\MSRAWImage.dll

+ CLSID : {5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}
- Name : Microsoft Camera Raw Decoder
- Value : C:\Windows\System32\WindowsCodecsRaw.dll


70617 - Microsoft Windows AutoRuns Explorer
-
Synopsis
Reports programs that startup associates with the explorer process.
Description
Report the startup locations associated with the explorer.exe process.

These items could add controls to menus, add extensions for common protocols such as HTTP or FTP, or set control user activity with the desktop and control panels.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\SOFTWARE\Classes\Protocols\Filter
+ CLSID : {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
- Name : application/octet-stream
- Value : C:\WINDOWS\System32\mscoree.dll

+ CLSID : {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
- Name : application/x-complus
- Value : C:\WINDOWS\System32\mscoree.dll

+ CLSID : {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
- Name : application/x-msdownload
- Value : C:\WINDOWS\System32\mscoree.dll

+ CLSID : {807583E5-5146-11D5-A672-00B0D022E945}
- Name : text/xml
- Value : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\MSOXMLMF.DLL


+ HKLM\SOFTWARE\Classes\Protocols\Handler
+ CLSID : {3050F406-98B5-11CF-BB82-00AA00BDCE0B}
- Name : about
- Value : C:\Windows\System32\mshtml.dll

+ CLSID : {3dd53d40-7b8b-11D0-b013-00aa0059ce02}
- Name : cdl
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {12D51199-0DB5-46FE-A120-47A3D7D937CC}
- Name : dvd
- Value : C:\Windows\System32\msvidctl.dll

+ CLSID : {79eac9e7-baf9-11ce-8c82-00aa004ba90b}
- Name : file
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {79eac9e3-baf9-11ce-8c82-00aa004ba90b}
- Name : ftp
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {79eac9e2-baf9-11ce-8c82-00aa004ba90b}
- Name : http
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {79eac9e5-baf9-11ce-8c82-00aa004ba90b}
- Name : https
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {9D148291-B9C8-11D0-A4CC-0000F80149F6}
- Name : its
- Value : C:\Windows\System32\itss.dll

+ CLSID : {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B}
- Name : javascript
- Value : C:\Windows\System32\mshtml.dll

+ CLSID : {79eac9e7-baf9-11ce-8c82-00aa004ba90b}
- Name : local
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B}
- Name : mailto
- Value : C:\Windows\System32\mshtml.dll

+ CLSID : {05300401-BCBC-11d0-85E3-00C04FD85AB4}
- Name : mhtml
- Value : C:\Windows\System32\inetcomm.dll

+ CLSID : {79eac9e6-baf9-11ce-8c82-00aa004ba90b}
- Name : mk
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {314111c7-a502-11d2-bbca-00c04f8ec294}
- Name : ms-help
- Value : C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll

+ CLSID : {9D148291-B9C8-11D0-A4CC-0000F80149F6}
- Name : ms-its
- Value : C:\Windows\System32\itss.dll

+ CLSID : {3459B272-CC19-4448-86C9-DDC3B4B2FAD3}
- Name : mso-minsb.16
- Value : C:\Program Files\Microsoft Office\Office16\MSOSB.DLL

+ CLSID : {5504BE45-A83B-4808-900A-3A5C36E7F77A}
- Name : osf.16
- Value : C:\Program Files\Microsoft Office\Office16\MSOSB.DLL

+ CLSID : {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B}
- Name : res
- Value : C:\Windows\System32\mshtml.dll

+ CLSID : {14654CA6-5711-491D-B89A-58E571679951}
- Name : tbauth
- Value : C:\Windows\System32\tbauth.dll

+ CLSID : {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E}
- Name : tv
- Value : C:\Windows\System32\msvidctl.dll

+ CLSID : {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B}
- Name : vbscript
- Value : C:\Windows\System32\mshtml.dll

+ CLSID : {14654CA6-5711-491D-B89A-58E571679951}
- Name : windows.tbauth
- Value : C:\Windows\System32\tbauth.dll


+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
+ CLSID : {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
- Name : webcheck
- Value :


+ HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
+ CLSID : {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
- Name : webcheck
- Value :


+ HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers
+ CLSID : {23170F69-40C1-278A-1000-000100020000}
- Name : 7-Zip
- Value : C:\Program Files\7-Zip\7-zip.dll

+ CLSID : {B298D29A-A6ED-11DE-BA8C-A68E55D89593}
- Name : ANotepad++64
- Value : C:\Program Files (x86)\Notepad++\NppShell_06.dll

+ CLSID : {AE81D5A2-A34B-4D93-8DF8-540DBCE48043}
- Name : Kaspersky Anti-Virus 21.15
- Value : C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\x64\shellex.dll

+ CLSID : {e2bf9676-5f8f-435c-97eb-11607a5bedf7}
- Name : ModernSharing
- Value : %SystemRoot%\system32\ntshrui.dll

+ CLSID : {09799AFB-AD67-11d1-ABCD-00C04FC30936}
- Name : Open With
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {A470F8CF-A1E8-4f65-8335-227475AA5C46}
- Name : Open With EncryptionMenu
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}
- Name : Sharing
- Value : %SystemRoot%\system32\ntshrui.dll

+ CLSID : {B41DB860-64E4-11D2-9906-E49FADC173CA}
- Name : WinRAR
- Value : C:\Program Files\WinRAR\rarext.dll

+ CLSID : {B41DB860-8EE4-11D2-9906-E49FADC173CA}
- Name : WinRAR32
- Value :

+ CLSID : {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3}
- Name : WorkFolders
- Value : C:\Windows\System32\WorkfoldersShell.dll

+ CLSID : {90AA3A4E-1CBA-4233-B8BB-535773D48449}
- Name : Taskband Pin
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
- Name : Start Menu Pin
- Value : %SystemRoot%\system32\shell32.dll


+ HKLM\Software\Classes\*\ShellEx\PropertySheetHandlers
+ CLSID : {7444C719-39BF-11D1-8CD9-00C04FC29D45}
- Name : CryptoSignMenu
- Value : %SystemRoot%\system32\cryptext.dll

+ CLSID : {748F920F-FB24-4D09-B360-BAF6F199AD6D}
- Name : FCI Properties
- Value : C:\Windows\System32\srmshell.dll

+ CLSID : {1f2e5c40-9550-11ce-99d2-00aa006e086c}
- Name :
- Value : %SystemRoot%\system32\rshx32.dll

+ CLSID : {3EA48300-8CF6-101B-84FB-666CCB9BCD32}
- Name : OLE DocFile Property Page
- Value : %SystemRoot%\system32\docprop.dll

+ CLSID : {883373C3-BF89-11D1-BE35-080036B11A03}
- Name : Summary Properties Page
- Value : %SystemRoot%\system32\shell32.dll


+ HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers
+ CLSID : {f3d06e7c-1e45-4a26-847e-f9fcdee59be0}
- Name : CopyAsPathMenu
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {7BA4C740-9E81-11CF-99D3-00AA004AE837}
- Name : SendTo
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {474C98EE-CF3D-41f5-80E3-4AAB0AB04301}
- Name :
- Value : %SystemRoot%\System32\cscui.dll

+ CLSID : {596AB062-B4D2-4215-9F74-E9109B0A8153}
- Name :
- Value : %SystemRoot%\system32\twext.dll

+ CLSID : {a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
- Name : Start Menu Pin
- Value : %SystemRoot%\system32\shell32.dll


+ HKLM\Software\Classes\AllFileSystemObjects\ShellEx\PropertySheetHandlers
+ CLSID : {596AB062-B4D2-4215-9F74-E9109B0A8153}
- Name :
- Value : %SystemRoot%\system32\twext.dll

+ CLSID : {7EFA68C6-086B-43e1-A2D2-55A113531240}
- Name :
- Value : %SystemRoot%\System32\cscui.dll


+ HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers
+ CLSID : {23170F69-40C1-278A-1000-000100020000}
- Name : 7-Zip
- Value : C:\Program Files\7-Zip\7-zip.dll

+ CLSID : {A470F8CF-A1E8-4f65-8335-227475AA5C46}
- Name : EncryptionMenu
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {AE81D5A2-A34B-4D93-8DF8-540DBCE48043}
- Name : Kaspersky Anti-Virus 21.15
- Value : C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\x64\shellex.dll

+ CLSID : {474C98EE-CF3D-41f5-80E3-4AAB0AB04301}
- Name : Offline Files
- Value : %SystemRoot%\System32\cscui.dll

+ CLSID : {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}
- Name : Sharing
- Value : %SystemRoot%\system32\ntshrui.dll

+ CLSID : {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3}
- Name : WorkFolders
- Value : C:\Windows\System32\WorkfoldersShell.dll

+ CLSID : {596AB062-B4D2-4215-9F74-E9109B0A8153}
- Name :
- Value : %SystemRoot%\system32\twext.dll


+ HKLM\Software\Classes\Directory\Shellex\DragDropHandlers
+ CLSID : {23170F69-40C1-278A-1000-000100020000}
- Name : 7-Zip
- Value : C:\Program Files\7-Zip\7-zip.dll


+ HKLM\Software\Classes\Directory\Shellex\PropertySheetHandlers
+ CLSID : {7EFA68C6-086B-43e1-A2D2-55A113531240}
- Name : Offline Files
- Value : %SystemRoot%\System32\cscui.dll

+ CLSID : {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}
- Name : Sharing
- Value : %SystemRoot%\system32\ntshrui.dll

+ CLSID : {1f2e5c40-9550-11ce-99d2-00aa006e086c}
- Name :
- Value : %SystemRoot%\system32\rshx32.dll

+ CLSID : {4a7ded0a-ad25-11d0-98a8-0800361b1103}
- Name :
- Value : %SystemRoot%\system32\mydocs.dll

+ CLSID : {596AB062-B4D2-4215-9F74-E9109B0A8153}
- Name :
- Value : %SystemRoot%\system32\twext.dll

+ CLSID : {ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}
- Name :
- Value : C:\Windows\System32\DfsShlEx.dll

+ CLSID : {ef43ecfe-2ab9-4632-bf21-58909dd177f0}
- Name :
- Value : %SystemRoot%\system32\shell32.dll


+ HKLM\Software\Classes\Directory\Shellex\CopyHookHandlers
+ CLSID : {217FC9C0-3AEA-1069-A2DB-08002B30309D}
- Name : FileSystem
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {40dd6e20-7c17-11ce-a804-00aa003ca9f6}
- Name : Sharing
- Value : %SystemRoot%\system32\ntshrui.dll


+ HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers
+ CLSID : {D969A300-E7FF-11d0-A93B-00A0C90F2719}
- Name : New
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}
- Name : Sharing
- Value : %SystemRoot%\system32\ntshrui.dll

+ CLSID : {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3}
- Name : WorkFolders
- Value : C:\Windows\System32\WorkfoldersShell.dll


+ HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers
+ CLSID : {23170F69-40C1-278A-1000-000100020000}
- Name : 7-Zip
- Value : C:\Program Files\7-Zip\7-zip.dll

+ CLSID : {AE81D5A2-A34B-4D93-8DF8-540DBCE48043}
- Name : Kaspersky Anti-Virus 21.15
- Value : C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\x64\shellex.dll

+ CLSID : {3dad6c5d-2167-4cae-9914-f99e41c12cfa}
- Name : Library Location
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {474C98EE-CF3D-41f5-80E3-4AAB0AB04301}
- Name : Offline Files
- Value : %SystemRoot%\System32\cscui.dll

+ CLSID : {470C0EBD-5D73-4d58-9CED-E91E22E23282}
- Name : PintoStartScreen
- Value : C:\Windows\System32\appresolver.dll

+ CLSID : {B41DB860-64E4-11D2-9906-E49FADC173CA}
- Name : WinRAR
- Value : C:\Program Files\WinRAR\rarext.dll

+ CLSID : {B41DB860-8EE4-11D2-9906-E49FADC173CA}
- Name : WinRAR32
- Value :

+ CLSID : {a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
- Name : Start Menu Pin
- Value : %SystemRoot%\system32\shell32.dll


+ HKLM\Software\Classes\Folder\ShellEx\DragDropHandlers
+ CLSID : {B41DB860-64E4-11D2-9906-E49FADC173CA}
- Name : WinRAR
- Value : C:\Program Files\WinRAR\rarext.dll

+ CLSID : {B41DB860-8EE4-11D2-9906-E49FADC173CA}
- Name : WinRAR32
- Value :

+ CLSID : {BD472F60-27FA-11cf-B8B4-444553540000}
- Name :
- Value : %SystemRoot%\system32\zipfldr.dll


+ HKLM\Software\Classes\Folder\ShellEx\PropertySheetHandlers
+ CLSID : {748F920F-FB24-4D09-B360-BAF6F199AD6D}
- Name : FCI Properties
- Value : C:\Windows\System32\srmshell.dll

+ CLSID : {7EFA68C6-086B-43e1-A2D2-55A113531240}
- Name : Offline Files
- Value : %SystemRoot%\System32\cscui.dll


+ HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers
+ CLSID : {BBACC218-34EA-4666-9D7A-C78F2274A524}
- Name : OneDrive1
- Value :

+ CLSID : {5AB7172C-9C11-405C-8DD5-AF20F3606282}
- Name : OneDrive2
- Value :

+ CLSID : {A78ED123-AB77-406B-9962-2A5D9D2F7F30}
- Name : OneDrive3
- Value :

+ CLSID : {F241C880-6982-4CE5-8CF7-7085BA96DA5A}
- Name : OneDrive4
- Value :

+ CLSID : {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}
- Name : OneDrive5
- Value :

+ CLSID : {9AA2F32D-362A-42D9-9328-24A483E2CCC3}
- Name : OneDrive6
- Value :

+ CLSID : {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C}
- Name : OneDrive7
- Value :

+ CLSID : {8BA85C75-763B-4103-94EB-9470F12FE0F7}
- Name : SkyDrivePro1 (ErrorConflict)
- Value : C:\PROGRA~1\MICROS~1\Office16\GROOVEEX.DLL

+ CLSID : {CD55129A-B1A1-438E-A425-CEBC7DC684EE}
- Name : SkyDrivePro2 (SyncInProgress)
- Value : C:\PROGRA~1\MICROS~1\Office16\GROOVEEX.DLL

+ CLSID : {E768CD3B-BDDC-436D-9C13-E1B39CA257B1}
- Name : SkyDrivePro3 (InSync)
- Value : C:\PROGRA~1\MICROS~1\Office16\GROOVEEX.DLL

+ CLSID : {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}
- Name : EnhancedStorageShell
- Value : C:\Windows\System32\EhStorShell.dll

+ CLSID : {4E77131D-3629-431c-9818-C5679DC83E81}
- Name : Offline Files
- Value : %SystemRoot%\System32\cscui.dll


+ HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers
+ CLSID : {BBACC218-34EA-4666-9D7A-C78F2274A524}
- Name : OneDrive1
- Value :

+ CLSID : {5AB7172C-9C11-405C-8DD5-AF20F3606282}
- Name : OneDrive2
- Value :

+ CLSID : {A78ED123-AB77-406B-9962-2A5D9D2F7F30}
- Name : OneDrive3
- Value :

+ CLSID : {F241C880-6982-4CE5-8CF7-7085BA96DA5A}
- Name : OneDrive4
- Value :

+ CLSID : {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}
- Name : OneDrive5
- Value :

+ CLSID : {9AA2F32D-362A-42D9-9328-24A483E2CCC3}
- Name : OneDrive6
- Value :

+ CLSID : {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C}
- Name : OneDrive7
- Value :

+ CLSID : {8BA85C75-763B-4103-94EB-9470F12FE0F7}
- Name : SkyDrivePro1 (ErrorConflict)
- Value : C:\PROGRA~1\MICROS~1\Office16\GROOVEEX.DLL

+ CLSID : {CD55129A-B1A1-438E-A425-CEBC7DC684EE}
- Name : SkyDrivePro2 (SyncInProgress)
- Value : C:\PROGRA~1\MICROS~1\Office16\GROOVEEX.DLL

+ CLSID : {E768CD3B-BDDC-436D-9C13-E1B39CA257B1}
- Name : SkyDrivePro3 (InSync)
- Value : C:\PROGRA~1\MICROS~1\Office16\GROOVEEX.DLL



HKU : \Users\tidua : S-1-5-21-2193062927-1383316644-2198579232-1009

+ HKU\S-1-5-21-2193062927-1383316644-2198579232-1009\Software\Classes\*\ShellEx\ContextMenuHandlers
+ CLSID : {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}
- Name : FileSyncEx
- Value :


+ HKU\S-1-5-21-2193062927-1383316644-2198579232-1009\Software\Classes\Directory\ShellEx\ContextMenuHandlers
+ CLSID : {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}
- Name : FileSyncEx
- Value :


HKU : \Users\Techrobot : S-1-5-21-2193062927-1383316644-2198579232-1004

+ HKU\S-1-5-21-2193062927-1383316644-2198579232-1004\Software\Classes\*\ShellEx\ContextMenuHandlers
+ CLSID : {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}
- Name : FileSyncEx
- Value :


+ HKU\S-1-5-21-2193062927-1383316644-2198579232-1004\Software\Classes\Directory\ShellEx\ContextMenuHandlers
+ CLSID : {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}
- Name : FileSyncEx
- Value :

70619 - Microsoft Windows AutoRuns Internet Explorer
-
Synopsis
Report programs that startup associates with Internet Explorer.
Description
Report registry startup locations associated with the Internet Explorer (IE) application.

The startup values include Internet Explorer plugins to extend the functionality of IE, browser toolbars, hooks into browser controls, and settings.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
+ CLSID : {1FD49718-1D00-4B19-AF5F-070AF6D5D54C}
- Name : IEToEdge BHO
- Value : C:\Program Files (x86)\Microsoft\Edge\Application\92.0.902.67\BHO\ie_to_edge_bho_64.dll

+ CLSID : {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
- Value : C:\Program Files\Java\jre1.8.0_161\bin\ssv.dll

+ CLSID : {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}
- Value : C:\PROGRA~1\MICROS~1\Office16\GROOVEEX.DLL

+ CLSID : {DBC80044-A445-435b-BC74-9C25C1C588A9}
- Value : C:\Program Files\Java\jre1.8.0_161\bin\jp2ssv.dll


HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
+ CLSID : {1FD49718-1D00-4B19-AF5F-070AF6D5D54C}
- Name : IEToEdge BHO
- Value : C:\Program Files (x86)\Microsoft\Edge\Application\92.0.902.67\BHO\ie_to_edge_bho_64.dll

+ CLSID : {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}
- Value : C:\PROGRA~1\MICROS~1\Office16\GROOVEEX.DLL


HKLM\Software\Microsoft\Internet Explorer\Extensions
+ CLSID : {2670000A-7350-4f3c-8081-5663EE0C6C49}
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}
- Value : CLSID is not set in HKCR\CLSID\


HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Extensions
+ CLSID : {2670000A-7350-4f3c-8081-5663EE0C6C49}
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}
- Value : CLSID is not set in HKCR\CLSID\


70620 - Microsoft Windows AutoRuns Known DLLs
-
Synopsis
DLLs listed to be shared by processes.
Description
The known DLLs registry setting is used to define DLLs that are shared between processes without a process having to search for the DLL location.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0

+ HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs
- imagehlp : IMAGEHLP.dll
- shcore : SHCORE.dll
- oleaut32 : OLEAUT32.dll
- normaliz : NORMALIZ.dll
- msvcrt : MSVCRT.dll
- shell32 : SHELL32.dll
- msctf : MSCTF.dll
- gdi32 : gdi32.dll
- nsi : NSI.dll
- advapi32 : advapi32.dll
- coml2 : coml2.dll
- _wowarmhw : wowarmhw.dll
- clbcatq : clbcatq.dll
- wow64win : wow64win.dll
- shlwapi : SHLWAPI.dll
- psapi : PSAPI.DLL
- imm32 : IMM32.dll
- combase : combase.dll
- user32 : user32.dll
- sechost : sechost.dll
- _xtajit : xtajit.dll
- _wow64cpu : wow64cpu.dll
- wow64 : wow64.dll
- rpcrt4 : rpcrt4.dll
- kernel32 : kernel32.dll
- ws2_32 : WS2_32.dll
- wldap32 : WLDAP32.dll
- ole32 : ole32.dll
- difxapi : difxapi.dll
- setupapi : Setupapi.dll
- comdlg32 : COMDLG32.dll
- gdiplus : gdiplus.dll
70613 - Microsoft Windows AutoRuns LSA Providers
-
Synopsis
Programs set to start as Local Security Authority.
Description
An LSA (Local Security Authority) is an application that can be used to authorize users to their systems. The reported autoruns are available to provide this service or features to this service.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0



+ HKLM\SYSTEM\CurrentControlSet\Control\Lsa\authentication packages
- msv1_0


+ HKLM\SYSTEM\CurrentControlSet\Control\Lsa\notification packages
- scecli


+ HKLM\SYSTEM\CurrentControlSet\Control\Lsa\security packages
- ""
70621 - Microsoft Windows AutoRuns Logon
-
Synopsis
Report programs that start-up from the most common registry locations.
Description
Report the most common startup locations used by programs. These are commonly associated with programs that start automatically when the computer is turned on, users log in, users log off, or remote sessions are started.

Such keys can be set from a program install, GPO, or through a malicious process to maintain persistence.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd
- rdpclip


+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\userinit
- C:\Windows\system32\userinit.exe


+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\vmapplet
- SystemPropertiesPerformance.exe /pagefile


+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\shell
- explorer.exe


+ HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot
- AlternateShell : cmd.exe


+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Name : vmware user process
- Value : "C:\Program Files\VMware\VMware Tools\vmtoolsd.exe" -n vmusr

- Name : securityhealth
- Value : %windir%\system32\SecurityHealthSystray.exe

- Name : tvncontrol
- Value : "C:\Program Files\TightVNC\tvnserver.exe" -controlservice -slave


+ HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
- Name : sunjavaupdatesched
- Value : "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"


+ HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components
+ CLSID : >{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
- Name : Microsoft Windows Media Player
- Value : %SystemRoot%\system32\unregmp2.exe /ShowWMP

+ CLSID : {2C7339CF-2B09-4501-B3F3-F3508C9228ED}
- Name : Themes Setup
- Value : /UserInstall

+ CLSID : {49210152-871f-4ffa-961d-a172abcbc09d}
- Name : Google Platform Experience Helper
- Value : "C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe" --first-run

+ CLSID : {6BF52A52-394A-11d3-B153-00C04F79FAA6}
- Name : Microsoft Windows Media Player
- Value : %SystemRoot%\system32\unregmp2.exe /FirstLogon

+ CLSID : {89820200-ECBD-11cf-8B85-00AA005B4340}
- Name : Windows Desktop Update
- Value : U

+ CLSID : {89820200-ECBD-11cf-8B85-00AA005B4383}
- Name : Web Platform Customizations
- Value : C:\Windows\System32\ie4uinit.exe -UserConfig

+ CLSID : {89B4C1CD-B018-4511-B0A1-5476DBF70820}
- Name :
- Value : C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install

+ CLSID : {8A69D345-D564-463c-AFF1-A69D9E530F96}
- Name : Google Chrome
- Value : "C:\Program Files\Google\Chrome\Application\143.0.7499.193\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --channel=stable

+ CLSID : {9459C573-B17A-45AE-9F64-1857B5D58CEE}
- Name : Microsoft Edge
- Value : "C:\Program Files (x86)\Microsoft\Edge\Application\92.0.902.67\Installer\setup.exe" --configure-user-settings --verbose-logging --system-level --msedge


+ HKLM\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components
+ CLSID : >{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
- Name : Microsoft Windows Media Player
- Value : %SystemRoot%\system32\unregmp2.exe /ShowWMP

+ CLSID : {6BF52A52-394A-11d3-B153-00C04F79FAA6}
- Name : Microsoft Windows Media Player
- Value : %SystemRoot%\system32\unregmp2.exe /FirstLogon

+ CLSID : {89B4C1CD-B018-4511-B0A1-5476DBF70820}
- Name :
- Value : C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install


+ HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows
- iconservicelib : IconCodecService.dll
- Load :



HKU : \Users\tidua : S-1-5-21-2193062927-1383316644-2198579232-1009

+ HKU\S-1-5-21-2193062927-1383316644-2198579232-1009\Software\Microsoft\Windows\CurrentVersion\Run
- Name : onedrive
- Value : "C:\Users\tidua\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background


+ HKU\S-1-5-21-2193062927-1383316644-2198579232-1009\Software\Microsoft\Windows\CurrentVersion\RunOnce
- Name : delete cached update binary
- Value : C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\tidua\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe"

- Name : uninstall 25.238.1204.0001
- Value : C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\tidua\AppData\Local\Microsoft\OneDrive\25.238.1204.0001"

- Name : delete cached standalone update binary
- Value : C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\tidua\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe"


HKU : \Users\Techrobot : S-1-5-21-2193062927-1383316644-2198579232-1004

+ HKU\S-1-5-21-2193062927-1383316644-2198579232-1004\Software\Microsoft\Windows\CurrentVersion\Run
- Name : onedrive
- Value : "C:\Users\Techrobot\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background


+ HKU\S-1-5-21-2193062927-1383316644-2198579232-1004\Software\Microsoft\Windows\CurrentVersion\RunOnce
- Name : delete cached update binary
- Value : C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Techrobot\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe"

- Name : uninstall 25.222.1112.0002
- Value : C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Techrobot\AppData\Local\Microsoft\OneDrive\25.222.1112.0002"

- Name : application restart #0
- Value : C:\Program Files\Google\Chrome\Application\chrome.exe --allow-pre-commit-input --disable-background-timer-throttling --disable-backgrounding-occluded-windows --disable-features=ThreadPoolCap<ThreadPoolCap --disable-renderer-backgrounding --disable-search-engine-choice-screen --hide-crash-restore-bubble --new-window --no-first-run --silent-debugger-extension-api --restore-last-session --restart

- Name : delete cached standalone update binary
- Value : C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Techrobot\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe"

70622 - Microsoft Windows AutoRuns Network Providers
-
Synopsis
Report programs set to automatically start-up as a Network Provider.
Description
The DLLs listed under the registry key are used to provide network services for new protocols.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order\ProviderOrder
- RDPNP : %SystemRoot%\System32\drprov.dll
- LanmanWorkstation : %SystemRoot%\System32\ntlanman.dll
- webclient : %SystemRoot%\System32\davclnt.dll

+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\HwOrder\ProviderOrder
- RDPNP : %SystemRoot%\System32\drprov.dll
- LanmanWorkstation : %SystemRoot%\System32\ntlanman.dll
- webclient : %SystemRoot%\System32\davclnt.dll
70623 - Microsoft Windows AutoRuns Print Monitor
-
Synopsis
Report programs set to start automatically as a print monitor.
Description
Report the DLLs that control print monitor functions for multiple programs and systems.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0

+ HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
- Appmon : AppMon.dll
- Local Port : localspl.dll
- Microsoft Shared Fax Monitor : FXSMON.DLL
- Standard TCP/IP Port : tcpmon.dll
- USB Monitor : usbmon.dll
- WSD Port : APMon.dll
70618 - Microsoft Windows AutoRuns Registry Hijack Possible Locations
-
Synopsis
Report common registry keys used to hijack execution.
Description
Report common registry keys that can be used to hijack system process execution.

These registry keys can be used to either replace execution or shim a process in the middle of execution to hijack control. Confirm that everything listed here is set to the appropriate settings and that it doesn't look like another process is taking control of the process's execution.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\SOFTWARE\Classes\Exefile\Shell\Open\Command
- Command : "%1" %*


+ HKLM\Software\Classes\.exe : exefile
- open : "%1" %*
- runas : "%1" %*
- runasuser :


+ HKLM\Software\Classes\.cmd : cmdfile
- edit : %SystemRoot%\System32\NOTEPAD.EXE %1
- open : "%1" %*
- print : %SystemRoot%\System32\NOTEPAD.EXE /p %1
- runas : %SystemRoot%\System32\cmd.exe /C "%1" %*
- runasuser :


+ HKLM\Software\Classes\.htm : htmlfile
- Edit : "C:\Program Files\Microsoft Office\Office16\msohtmed.exe" %1
- open : "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1
- Print : "C:\Program Files\Microsoft Office\Office16\msohtmed.exe" /p %1
- printto : "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\mshtml.dll",PrintHTML "%1" "%2" "%3" "%4"


+ HKLM\Software\Classes\.html : htmlfile
- Edit : "C:\Program Files\Microsoft Office\Office16\msohtmed.exe" %1
- open : "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1
- Print : "C:\Program Files\Microsoft Office\Office16\msohtmed.exe" /p %1
- printto : "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\mshtml.dll",PrintHTML "%1" "%2" "%3" "%4"


+ HKLM\Software\Classes\.doc : Word.Document.8
- Edit : "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" /vu "%1"
- New : "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" /n /f "%1"
- OnenotePrintto : "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" /j "%1" "%2"
- Open : "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" /n "%1" /o "%u"
- OpenAsReadOnly : "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" /h /n "%1"
- Print : "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" /i "%1"
- Printto : "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" /j "%1" "%2"
- ViewProtected : "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" /vp "%1"


+ HKLM\Software\Classes\.docx : Word.Document.12
- Edit : "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" /vu "%1"
- New : "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" /n /f "%1"
- OnenotePrintto : "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" /j "%1" "%2"
- Open : "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" /n "%1" /o "%u"
- OpenAsReadOnly : "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" /h /n "%1"
- Print : "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" /i "%1"
- Printto : "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" /j "%1" "%2"
- ViewProtected : "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" /vp "%1"


+ HKLM\Software\Classes\.vbs : VBSFile
- Edit : "%SystemRoot%\System32\Notepad.exe" %1
- Open : "%SystemRoot%\System32\WScript.exe" "%1" %*
- Open2 : "%SystemRoot%\System32\CScript.exe" "%1" %*
- Print : "%SystemRoot%\System32\Notepad.exe" /p %1


+ HKLM\Software\Classes\.txt : txtfile
- open : %SystemRoot%\system32\NOTEPAD.EXE %1
- print : %SystemRoot%\system32\NOTEPAD.EXE /p %1
- printto : %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4"


+ HKLM\Software\Classes\.xls : Excel.Sheet.8
- Edit : "C:\Program Files\Microsoft Office\Office16\EXCEL.EXE" /dde
- New : "C:\Program Files\Microsoft Office\Office16\EXCEL.EXE" /dde /n
- Open : "C:\Program Files\Microsoft Office\Office16\EXCEL.EXE" /dde
- OpenAsReadOnly : "C:\Program Files\Microsoft Office\Office16\EXCEL.EXE" /h /dde
- Print : "C:\Program Files\Microsoft Office\Office16\EXCEL.EXE" /dde
- Printto : "C:\Program Files\Microsoft Office\Office16\EXCEL.EXE" /dde
- ViewProtected : "C:\Program Files\Microsoft Office\Office16\EXCEL.EXE" /dde


+ HKLM\Software\Classes\.xml : xmlfile
- edit : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\MSOXMLED.EXE" /verb edit "%1"
- open : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\MSOXMLED.EXE" /verb open "%1"


+ HKLM\Software\Classes\.pif : piffile
- open : "%1" %*


+ HKLM\Software\Classes\.txt : txtfile
- open : %SystemRoot%\system32\NOTEPAD.EXE %1
- print : %SystemRoot%\system32\NOTEPAD.EXE /p %1
- printto : %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4"



70624 - Microsoft Windows AutoRuns Report
-
Synopsis
Generate a CSV report of all autoruns.
Description
Collect all autoruns listed in the Windows autoruns plugins and report the primary content in a CSV report.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+Enabled Autoruns Detection Types
- LSA Provider
- Boot Execute
- WinLogon
- Known DLLs
- Winsock Provider
- Service
- Explorer
- Logon
- Codecs
- Driver
- Image Hijack
- Network Provider
- Scheduled Tasks
- Print Monitor
- Internet Explorer


The attached CSV contains information about Windows autoruns.
70625 - Microsoft Windows AutoRuns Scheduled Tasks
-
Synopsis
Report processes that start-up via the scheduled task manager.
Description
This plugin lists the scheduled tasks for the system. The scheduled tasks are often used to update software, for systems administrators to run processes, and can be used by malware to spread on systems.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0

report output too big - ending list here

70626 - Microsoft Windows AutoRuns Services and Drivers
-
Synopsis
Report programs that are set to start automatically on boot as a service or driver.
Description
Report the registry keys that track programs that are set to start on boot as a service.

These programs can start as a system wide service or be loaded as a driver.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\System\CurrentControlSet\Services
Drivers :
+ @%SystemRoot%\system32\AJRouter.dll,-2
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\AJRouter.dll,-1

+ @%SystemRoot%\system32\Alg.exe,-112
- %SystemRoot%\System32\alg.exe
- Load on Demand
- @%SystemRoot%\system32\Alg.exe,-113

+ @%systemroot%\system32\appidsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\appidsvc.dll,-101

+ @%systemroot%\system32\appinfo.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\appinfo.dll,-101

+ @appmgmts.dll,-3250
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @appmgmts.dll,-3251

+ @%SystemRoot%\System32\AppReadiness.dll,-1000
- %SystemRoot%\System32\svchost.exe -k AppReadiness -p
- Load on Demand
- @%SystemRoot%\System32\AppReadiness.dll,-1001

+ @%systemroot%\system32\AppVClient.exe,-102
- %systemroot%\system32\AppVClient.exe
- disabled
- @%systemroot%\system32\AppVClient.exe,-101

+ @%SystemRoot%\system32\appxdeploymentserver.dll,-1
- %systemroot%\system32\svchost.exe -k wsappx -p
- Load on Demand
- @%SystemRoot%\system32\appxdeploymentserver.dll,-2

+ @%SystemRoot%\system32\assignedaccessmanagersvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k AssignedAccessManagerSvc
- Load on Demand
- @%SystemRoot%\system32\assignedaccessmanagersvc.dll,-101

+ @%SystemRoot%\system32\AudioEndpointBuilder.dll,-204
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Auto Load
- @%SystemRoot%\System32\AudioEndpointBuilder.dll,-205

+ @%SystemRoot%\system32\audiosrv.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p
- Auto Load
- @%SystemRoot%\System32\audiosrv.dll,-201

+ @%SystemRoot%\System32\autotimesvc.dll,-6
- %SystemRoot%\system32\svchost.exe -k autoTimeSvc
- Load on Demand
- @%SystemRoot%\System32\autotimesvc.dll,-7

+ Kaspersky Endpoint Security Service (KES.21.15)
- "C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avp.exe" -r
- Auto Load
- Provides computer protection against viruses, other malicious applications, and network attacks.

+ Kaspersky Seamless Update Service (KES.21.15)
- "C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avpsus.exe"
- Auto Load
- Lets you install and roll back critical and approved updates of application modules.

+ @%SystemRoot%\system32\AxInstSV.dll,-103
- %SystemRoot%\system32\svchost.exe -k AxInstSVGroup
- Load on Demand
- @%SystemRoot%\system32\AxInstSV.dll,-104

+ AzureAttestService
- C:\WINDOWS\system32\svchost.exe -k AzureAttestService
- Auto Load
-

+ @%SystemRoot%\system32\bdesvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\bdesvc.dll,-101

+ @%SystemRoot%\system32\bfe.dll,-1001
- %systemroot%\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p
- Auto Load
- @%SystemRoot%\system32\bfe.dll,-1002

+ Background Intelligent Transfer Service
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\qmgr.dll,-1001

+ @%windir%\system32\bisrv.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @%windir%\system32\bisrv.dll,-101

+ @%SystemRoot%\system32\BTAGService.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\BTAGService.dll,-102

+ @%SystemRoot%\system32\BthAvctpSvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\BthAvctpSvc.dll,-102

+ @%SystemRoot%\System32\bthserv.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\System32\bthserv.dll,-102

+ @%SystemRoot%\system32\CapabilityAccessManager.dll,-1
- %SystemRoot%\system32\svchost.exe -k appmodel -p
- Load on Demand
- @%SystemRoot%\system32\CapabilityAccessManager.dll,-2

+ @%SystemRoot%\system32\cdpsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @%SystemRoot%\system32\cdpsvc.dll,-101

+ @%SystemRoot%\System32\certprop.dll,-11
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\certprop.dll,-12

+ @%SystemRoot%\system32\ClipSVC.dll,-103
- %SystemRoot%\System32\svchost.exe -k wsappx -p
- Load on Demand
- @%SystemRoot%\system32\ClipSVC.dll,-104

+ @%SystemRoot%\system32\cloudidsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k CloudIdServiceGroup -p
- Load on Demand
- @%SystemRoot%\system32\cloudidsvc.dll,-101

+ @comres.dll,-947
- %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
- Load on Demand
- @comres.dll,-948

+ @%SystemRoot%\system32\coremessaging.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork -p
- Auto Load
- @%SystemRoot%\system32\coremessaging.dll,-2

+ @%SystemRoot%\system32\cryptsvc.dll,-1001
- %SystemRoot%\system32\svchost.exe -k NetworkService -p
- Auto Load
- @%SystemRoot%\system32\cryptsvc.dll,-1002

+ @%systemroot%\system32\cscsvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\cscsvc.dll,-201

+ @combase.dll,-5012
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @combase.dll,-5013

+ @%systemroot%\system32\dcsvc.dll,-101
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\dcsvc.dll,-102

+ @%SystemRoot%\system32\defragsvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k defragsvc
- Load on Demand
- @%SystemRoot%\system32\defragsvc.dll,-102

+ @%SystemRoot%\system32\das.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\das.dll,-101

+ @%SystemRoot%\system32\umpnpmgr.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Load on Demand
- @%SystemRoot%\system32\umpnpmgr.dll,-101

+ @%SystemRoot%\system32\DevQueryBroker.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\DevQueryBroker.dll,-101

+ @%SystemRoot%\system32\dhcpcore.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\dhcpcore.dll,-101

+ @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000
- %SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe
- Load on Demand
- @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1001

+ @%systemroot%\system32\DiagSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k diagnostics
- Load on Demand
- @%systemroot%\system32\DiagSvc.dll,-101

+ @%SystemRoot%\system32\diagtrack.dll,-3001
- %SystemRoot%\System32\svchost.exe -k utcsvc -p
- Auto Load
- @%SystemRoot%\system32\diagtrack.dll,-3002

+ @%SystemRoot%\system32\DialogBlockingService.dll,-100
- %SystemRoot%\system32\svchost.exe -k DialogBlockingService
- disabled
- @%SystemRoot%\system32\DialogBlockingService.dll,-101

+ @%SystemRoot%\system32\dispbroker.desktop.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @%SystemRoot%\system32\dispbroker.desktop.dll,-102

+ @%SystemRoot%\System32\Microsoft.Graphics.Display.DisplayEnhancementService.dll,-1000
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\Microsoft.Graphics.Display.DisplayEnhancementService.dll,-1001

+ @%systemroot%\system32\Windows.Internal.Management.dll,-100
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\Windows.Internal.Management.dll,-101

+ @%SystemRoot%\system32\dmwappushsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\dmwappushsvc.dll,-201

+ @%SystemRoot%\System32\dnsapi.dll,-101
- %SystemRoot%\system32\svchost.exe -k NetworkService -p
- Auto Load
- @%SystemRoot%\System32\dnsapi.dll,-102

+ @%systemroot%\system32\dosvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Auto Load
- @%systemroot%\system32\dosvc.dll,-101

+ @%systemroot%\system32\dot3svc.dll,-1102
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\dot3svc.dll,-1103

+ @%systemroot%\system32\dps.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork -p
- Auto Load
- @%systemroot%\system32\dps.dll,-501

+ @%SystemRoot%\system32\DeviceSetupManager.dll,-1000
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\DeviceSetupManager.dll,-1001

+ @%SystemRoot%\system32\dssvc.dll,-10003
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\dssvc.dll,-10002

+ @%SystemRoot%\System32\dusmsvc.dll,-1
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p
- Auto Load
- @%SystemRoot%\System32\dusmsvc.dll,-2

+ @%systemroot%\system32\eapsvc.dll,-1
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\eapsvc.dll,-2

+ Microsoft Edge Update Service (edgeupdate)
- "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svc
- Auto Load
- Keeps your Microsoft software up to date. If this service is disabled or stopped, your Microsoft software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Microsoft software using it.

+ Microsoft Edge Update Service (edgeupdatem)
- "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /medsvc
- Load on Demand
- Keeps your Microsoft software up to date. If this service is disabled or stopped, your Microsoft software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Microsoft software using it.

+ @%SystemRoot%\system32\efssvc.dll,-100
- %SystemRoot%\System32\lsass.exe
- Load on Demand
- @%SystemRoot%\system32\efssvc.dll,-101

+ @%SystemRoot%\system32\embeddedmodesvc.dll,-201
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\embeddedmodesvc.dll,-202

+ @EnterpriseAppMgmtSvc.dll,-1
- %systemroot%\system32\svchost.exe -k appmodel -p
- Load on Demand
- @EnterpriseAppMgmtSvc.dll,-2

+ @%SystemRoot%\system32\wevtsvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\wevtsvc.dll,-201

+ @comres.dll,-2450
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @comres.dll,-2451

+ Fax
- %systemroot%\system32\fxssvc.exe
- disabled
- @%systemroot%\system32\fxsresm.dll,-122

+ @%systemroot%\system32\fdPHost.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%systemroot%\system32\fdPHost.dll,-101

+ @%systemroot%\system32\fdrespub.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- Load on Demand
- @%systemroot%\system32\fdrespub.dll,-101

+ @%systemroot%\system32\fhsvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\fhsvc.dll,-102

+ @%systemroot%\system32\FntCache.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @%systemroot%\system32\FntCache.dll,-101

+ @%SystemRoot%\system32\PresentationHost.exe,-3309
- %systemroot%\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
- Load on Demand
- @%SystemRoot%\system32\PresentationHost.exe,-3310

+ @%systemroot%\system32\FrameServer.dll,-100
- %SystemRoot%\System32\svchost.exe -k Camera
- Load on Demand
- @%systemroot%\system32\FrameServer.dll,-101

+ @%systemroot%\system32\GameInputSvc.exe,-101
- %SystemRoot%\System32\GameInputSvc.exe
- Load on Demand
- @%systemroot%\system32\GameInputSvc.exe,-102

+ Google Chrome Elevation Service (GoogleChromeElevationService)
- "C:\Program Files\Google\Chrome\Application\143.0.7499.193\elevation_service.exe"
- Load on Demand
- Provides encryption services and a secure way for recovering Google Chrome if it gets out of date. If this service is disabled, Google Chrome may lose access to encrypted data, and Google Chrome may not be able recover itself.

+ Google Updater Internal Service (GoogleUpdaterInternalService144.0.7547.0)
- "C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.0\updater.exe" --system --windows-service --service=update-internal
- Auto Load
- Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it.

+ Google Updater Service (GoogleUpdaterService144.0.7547.0)
- "C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.0\updater.exe" --system --windows-service --service=update
- Auto Load
- Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it.

+ @gpapi.dll,-112
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @gpapi.dll,-113

+ @%SystemRoot%\system32\GraphicsPerfSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k GraphicsPerfSvcGroup
- Load on Demand
- @%SystemRoot%\system32\GraphicsPerfSvc.dll,-101

+ @%SystemRoot%\System32\hidserv.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\hidserv.dll,-102

+ @%SystemRoot%\system32\hvhostsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\hvhostsvc.dll,-101

+ @%SystemRoot%\System32\tetheringservice.dll,-4097
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\tetheringservice.dll,-4098

+ @%SystemRoot%\system32\ikeext.dll,-501
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\system32\ikeext.dll,-502

+ @%SystemRoot%\system32\InstallService.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\InstallService.dll,-201

+ @%SystemRoot%\system32\iphlpsvc.dll,-500
- %SystemRoot%\System32\svchost.exe -k NetSvcs -p
- Auto Load
- @%SystemRoot%\system32\iphlpsvc.dll,-501

+ @%Systemroot%\system32\ipxlatcfg.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%Systemroot%\system32\ipxlatcfg.dll,-501

+ @keyiso.dll,-100
- %SystemRoot%\system32\lsass.exe
- Load on Demand
- @keyiso.dll,-101

+ Kaspersky Security Center Network Agent
- "C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\klnagent.exe"
- Auto Load
- Network Agent coordinates interaction between the Administration Server and Kaspersky applications installed on devices.

+ Kaspersky Security Network proxy server
- "C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\ksnproxy.exe"
- Load on Demand
- The KSN proxy service retranslates requests to Kaspersky Security Network and caches the responses.

+ @comres.dll,-2946
- %SystemRoot%\System32\svchost.exe -k NetworkServiceAndNoImpersonation -p
- Load on Demand
- @comres.dll,-2947

+ @%systemroot%\system32\srvsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%systemroot%\system32\srvsvc.dll,-101

+ @%systemroot%\system32\wkssvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Auto Load
- @%systemroot%\system32\wkssvc.dll,-101

+ @%SystemRoot%\System32\lfsvc.dll,-1
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\System32\lfsvc.dll,-2

+ @%SystemRoot%\system32\licensemanagersvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\licensemanagersvc.dll,-201

+ @%SystemRoot%\system32\lltdres.dll,-1
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\lltdres.dll,-2

+ @%SystemRoot%\system32\lmhsvc.dll,-101
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\lmhsvc.dll,-102

+ @%windir%\system32\lsm.dll,-1001
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @%windir%\system32\lsm.dll,-1002

+ Apache Tomcat 9.0 Lucee
- D:\Techexcel\Lucee\tomcat\bin\Tomcat9.exe //RS//Lucee
- disabled
- Apache Tomcat 9.0.45 Server - https://tomcat.apache.org/

+ @%SystemRoot%\system32\LanguageOverlayServer.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\LanguageOverlayServer.dll,-101

+ @%SystemRoot%\System32\moshost.dll,-100
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Auto Load
- @%SystemRoot%\System32\moshost.dll,-101

+ @%SystemRoot%\system32\McpManagementService.dll,-100
- %SystemRoot%\system32\svchost.exe -k McpManagementServiceGroup
- Load on Demand
- @%SystemRoot%\system32\McpManagementService.dll,-101

+ Microsoft Edge Elevation Service (MicrosoftEdgeElevationService)
- "C:\Program Files (x86)\Microsoft\Edge\Application\92.0.902.67\elevation_service.exe"
- Load on Demand
- Keeps Microsoft Edge up to update. If this service is disabled, the application will not be kept up to date.

+ @%SystemRoot%\system32\MixedRealityRuntime.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\MixedRealityRuntime.dll,-102

+ Mozilla Maintenance Service
- "C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe"
- Load on Demand
- The Mozilla Maintenance Service ensures that you have the latest and most secure version of Mozilla Firefox on your computer. Keeping Firefox up to date is very important for your online security, and Mozilla strongly recommends that you keep this service enabled.

+ @%SystemRoot%\system32\FirewallAPI.dll,-23090
- %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p
- Auto Load
- @%SystemRoot%\system32\FirewallAPI.dll,-23091

+ @comres.dll,-2797
- %SystemRoot%\System32\msdtc.exe
- Load on Demand
- @comres.dll,-2798

+ @%SystemRoot%\system32\iscsidsc.dll,-5000
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\iscsidsc.dll,-5001

+ @%SystemRoot%\system32\msimsg.dll,-27
- %systemroot%\system32\msiexec.exe /V
- Load on Demand
- @%SystemRoot%\system32\msimsg.dll,-32

+ @%SystemRoot%\system32\KeyboardFilterSvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\system32\KeyboardFilterSvc.dll,-102

+ MS-MPI Launch Service
- "C:\Program Files\Microsoft MPI\Bin\msmpilaunchsvc.exe"
- Load on Demand
- Service for launching MS-MPI applications

+ SQL Full-text Filter Daemon Launcher (MSSQLSERVER)
- "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL15.MSSQLSERVER
- Load on Demand
- Service to launch full-text filter daemon process which will perform document filtering and word breaking for SQL Server full-text search. Disabling this service will make full-text search features of SQL Server unavailable.

+ SQL Server Launchpad (MSSQLSERVER)
- "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\launchpad.exe" -launcher RLauncher.dll -launcher Pythonlauncher.dll -launcher commonlauncher.dll -pipename sqlsatellitelaunch -timeout 600000 -logPath "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\LOG\ExtensibilityLog" -workingDir "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExtensibilityData" -externalLanguagesTempDir "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLanguagesTemp" -externalLanguagesDir "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLanguages" -externalLibrariesTempDir "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLibrariesTemp" -externalLibrariesDir "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLibraries" -satelliteDllPath "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlsatellite.dll"
- Auto Load
- Service to launch Advanced Analytics Extensions Launchpad process that enables integration with Microsoft R Open using standard T-SQL statements. Disabling this service will make Advanced Analytics features of SQL Server unavailable.

+ SQL Server (MSSQLSERVER)
- "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER
- disabled
- Provides storage, processing and controlled access of data, and rapid transaction processing.

+ @%systemroot%\system32\NaturalAuth.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\NaturalAuth.dll,-101

+ @%SystemRoot%\system32\ncasvc.dll,-3009
- %SystemRoot%\System32\svchost.exe -k NetSvcs -p
- Load on Demand
- @%SystemRoot%\system32\ncasvc.dll,-3008

+ @%SystemRoot%\system32\ncbservice.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\ncbservice.dll,-501

+ @%SystemRoot%\system32\NcdAutoSetup.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork -p
- Load on Demand
- @%SystemRoot%\system32\NcdAutoSetup.dll,-101

+ @%SystemRoot%\System32\netlogon.dll,-102
- %systemroot%\system32\lsass.exe
- Load on Demand
- @%SystemRoot%\System32\netlogon.dll,-103

+ @%SystemRoot%\system32\netman.dll,-109
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\netman.dll,-110

+ @%SystemRoot%\system32\netprofmsvc.dll,-202
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\netprofmsvc.dll,-203

+ @%SystemRoot%\system32\NetSetupSvc.dll,-3
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\NetSetupSvc.dll,-4

+ @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8201
- %systemroot%\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
- disabled
- @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8200

+ @%SystemRoot%\System32\NgcCtnrSvc.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\NgcCtnrSvc.dll,-2

+ @%SystemRoot%\System32\ngcsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\ngcsvc.dll,-101

+ @%SystemRoot%\System32\nlasvc.dll,-1
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Auto Load
- @%SystemRoot%\System32\nlasvc.dll,-2

+ @%SystemRoot%\system32\nsisvc.dll,-200
- %systemroot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @%SystemRoot%\system32\nsisvc.dll,-201

+ Office 64 Source Engine
- "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
- Load on Demand
- Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports.

+ @%SystemRoot%\system32\pnrpsvc.dll,-8004
- %SystemRoot%\System32\svchost.exe -k LocalServicePeerNet
- Load on Demand
- @%SystemRoot%\system32\pnrpsvc.dll,-8005

+ @%SystemRoot%\system32\p2psvc.dll,-8006
- %SystemRoot%\System32\svchost.exe -k LocalServicePeerNet
- Load on Demand
- @%SystemRoot%\system32\p2psvc.dll,-8007

+ @%SystemRoot%\system32\pcasvc.dll,-1
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\pcasvc.dll,-2

+ @%SystemRoot%\system32\peerdistsvc.dll,-9000
- %SystemRoot%\System32\svchost.exe -k PeerDist
- Load on Demand
- @%SystemRoot%\system32\peerdistsvc.dll,-9001

+ @%systemroot%\system32\PerceptionSimulation\PerceptionSimulationService.exe,-101
- %systemroot%\system32\PerceptionSimulation\PerceptionSimulationService.exe
- Load on Demand
- @%systemroot%\system32\PerceptionSimulation\PerceptionSimulationService.exe,-102

+ @%systemroot%\sysWow64\perfhost.exe,-2
- %SystemRoot%\SysWow64\perfhost.exe
- Load on Demand
- @%systemroot%\SysWow64\perfhost.exe,-1

+ @%SystemRoot%\system32\PhoneserviceRes.dll,-10000
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\PhoneserviceRes.dll,-10001

+ @%systemroot%\system32\pla.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork -p
- Load on Demand
- @%systemroot%\system32\pla.dll,-501

+ @%SystemRoot%\system32\umpnpmgr.dll,-200
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Load on Demand
- @%SystemRoot%\system32\umpnpmgr.dll,-101

+ @%SystemRoot%\system32\pnrpauto.dll,-8002
- %SystemRoot%\System32\svchost.exe -k LocalServicePeerNet
- Load on Demand
- @%SystemRoot%\system32\pnrpauto.dll,-8003

+ @%SystemRoot%\system32\pnrpsvc.dll,-8000
- %SystemRoot%\System32\svchost.exe -k LocalServicePeerNet
- Load on Demand
- @%SystemRoot%\system32\pnrpsvc.dll,-8001

+ @%SystemRoot%\System32\polstore.dll,-5010
- %SystemRoot%\system32\svchost.exe -k NetworkServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\polstore.dll,-5011

+ @%SystemRoot%\system32\umpo.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @%SystemRoot%\system32\umpo.dll,-101

+ @%systemroot%\system32\profsvc.dll,-300
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%systemroot%\system32\profsvc.dll,-301

+ @%SystemRoot%\system32\pushtoinstall.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\pushtoinstall.dll,-201

+ @%SystemRoot%\system32\qwave.dll,-1
- %windir%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- Load on Demand
- @%SystemRoot%\system32\qwave.dll,-2

+ @%Systemroot%\system32\rasauto.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%Systemroot%\system32\rasauto.dll,-201

+ @%Systemroot%\system32\rasmans.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Auto Load
- @%Systemroot%\system32\rasmans.dll,-201

+ @%Systemroot%\system32\mprdim.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs
- disabled
- @%Systemroot%\system32\mprdim.dll,-201

+ Remote Registry
- %SystemRoot%\system32\svchost.exe -k localService -p
- Load on Demand
- @regsvc.dll,-2

+ @%SystemRoot%\System32\RDXService.dll,-256
- %SystemRoot%\System32\svchost.exe -k rdxgroup
- Load on Demand
- @%SystemRoot%\System32\RDXService.dll,-257

+ @%SystemRoot%\system32\RMapi.dll,-1001
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\RMapi.dll,-1002

+ @%windir%\system32\RpcEpMap.dll,-1001
- %SystemRoot%\system32\svchost.exe -k RPCSS -p
- Auto Load
- @%windir%\system32\RpcEpMap.dll,-1002

+ @%systemroot%\system32\Locator.exe,-2
- %SystemRoot%\system32\locator.exe
- Load on Demand
- @%systemroot%\system32\Locator.exe,-3

+ @combase.dll,-5010
- %SystemRoot%\system32\svchost.exe -k rpcss -p
- Auto Load
- @combase.dll,-5011

+ @%SystemRoot%\system32\samsrv.dll,-1
- %SystemRoot%\system32\lsass.exe
- Auto Load
- @%SystemRoot%\system32\samsrv.dll,-2

+ @%SystemRoot%\System32\SCardSvr.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
- Load on Demand
- @%SystemRoot%\System32\SCardSvr.dll,-5

+ @%SystemRoot%\System32\ScDeviceEnum.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\ScDeviceEnum.dll,-101

+ @%SystemRoot%\system32\schedsvc.dll,-100
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\system32\schedsvc.dll,-101

+ @%SystemRoot%\System32\certprop.dll,-13
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\certprop.dll,-14

+ @%SystemRoot%\system32\sdrsvc.dll,-107
- %SystemRoot%\system32\svchost.exe -k SDRSVC
- Load on Demand
- @%SystemRoot%\system32\sdrsvc.dll,-102

+ @%SystemRoot%\system32\seclogon.dll,-7001
- %windir%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\seclogon.dll,-7000

+ SecPod Saner Agent
- "C:\Program Files (x86)\SecPod Saner\Agent\bin\spsaneragnt.exe"
- Auto Load
- An agent for vulnerability detection and mitigation, works with SecPod's SanerNow Advanced Vulnerability Management platform.

+ SecPod Saner Upgrade Controller v2
- "C:\Program Files (x86)\SecPod Saner\Upgrader\bin\spupgradecontroller.exe"
- Load on Demand
- Controller for monitoring SecPod's SanerNow agent upgrade.

+ @%systemroot%\system32\SecurityHealthAgent.dll,-1002
- %SystemRoot%\system32\SecurityHealthService.exe
- Load on Demand
- @%systemroot%\system32\SecurityHealthAgent.dll,-1001

+ @%SystemRoot%\System32\SEMgrSvc.dll,-1001
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\System32\SEMgrSvc.dll,-1002

+ @%SystemRoot%\system32\Sens.dll,-200
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\system32\Sens.dll,-201

+ @%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1001
- "%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe"
- Load on Demand
- @%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1002

+ @%SystemRoot%\system32\SensorDataService.exe,-101
- %SystemRoot%\System32\SensorDataService.exe
- Load on Demand
- @%SystemRoot%\system32\SensorDataService.exe,-102

+ @%SystemRoot%\System32\sensorservice.dll,-1000
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\sensorservice.dll,-1001

+ @%SystemRoot%\System32\sensrsvc.dll,-1000
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- Load on Demand
- @%SystemRoot%\System32\sensrsvc.dll,-1001

+ @%SystemRoot%\System32\SessEnv.dll,-1026
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\System32\SessEnv.dll,-1027

+ @%SystemRoot%\system32\ipnathlp.dll,-106
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\ipnathlp.dll,-107

+ @%SystemRoot%\system32\SharedRealitySvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\SharedRealitySvc.dll,-101

+ @%SystemRoot%\System32\shsvcs.dll,-12288
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\System32\shsvcs.dll,-12289

+ @%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-101

+ @%SystemRoot%\System32\smphost.dll,-102
- %SystemRoot%\System32\svchost.exe -k smphost
- Load on Demand
- @%SystemRoot%\System32\smphost.dll,-101

+ @%SystemRoot%\System32\SmsRouterSvc.dll,-10001
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\SmsRouterSvc.dll,-10002

+ @firewallapi.dll,-50323
- %SystemRoot%\System32\snmptrap.exe
- Load on Demand
- @firewallapi.dll,-50324

+ @%systemroot%\system32\spectrum.exe,-101
- %systemroot%\system32\spectrum.exe
- Load on Demand
- @%systemroot%\system32\spectrum.exe,-102

+ @%SystemRoot%\system32\sppsvc.exe,-101
- %SystemRoot%\system32\sppsvc.exe
- Auto Load
- @%SystemRoot%\system32\sppsvc.exe,-100

+ SQL Server Browser
- "C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe"
- disabled
- Provides SQL Server connection information to client computers.

+ SQL Server Agent (MSSQLSERVER)
- "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER
- disabled
- Executes jobs, monitors SQL Server, fires alerts, and allows automation of some administrative tasks.

+ SQL Server CEIP service (MSSQLSERVER)
- "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlceip.exe" -Service
- Auto Load
- CEIP service for Sql server

+ SQL Server VSS Writer
- "C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
- Auto Load
- Provides the interface to backup/restore Microsoft SQL server through the Windows VSS infrastructure.

+ @%systemroot%\system32\ssdpsrv.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- Load on Demand
- @%systemroot%\system32\ssdpsrv.dll,-101

+ OpenSSH Authentication Agent
- %SystemRoot%\System32\OpenSSH\ssh-agent.exe
- disabled
- Agent to hold private keys used for public key authentication.

+ @%SystemRoot%\system32\sstpsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\sstpsvc.dll,-201

+ @%SystemRoot%\system32\windows.staterepository.dll,-1
- %SystemRoot%\system32\svchost.exe -k appmodel -p
- Load on Demand
- @%SystemRoot%\system32\windows.staterepository.dll,-2

+ @%SystemRoot%\system32\wiaservc.dll,-9
- %SystemRoot%\system32\svchost.exe -k imgsvc
- Load on Demand
- @%SystemRoot%\system32\wiaservc.dll,-10

+ @%SystemRoot%\System32\StorSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Auto Load
- @%SystemRoot%\System32\StorSvc.dll,-101

+ @%SystemRoot%\system32\svsvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\svsvc.dll,-102

+ @%SystemRoot%\System32\swprv.dll,-103
- %SystemRoot%\System32\svchost.exe -k swprv
- Load on Demand
- @%SystemRoot%\System32\swprv.dll,-102

+ @%SystemRoot%\system32\sysmain.dll,-1000
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\sysmain.dll,-1001

+ @%windir%\system32\SystemEventsBrokerServer.dll,-1001
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @%windir%\system32\SystemEventsBrokerServer.dll,-1002

+ @%SystemRoot%\system32\TabSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\TabSvc.dll,-101

+ @%SystemRoot%\system32\tapisrv.dll,-10100
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Load on Demand
- @%SystemRoot%\system32\tapisrv.dll,-10101

+ @%SystemRoot%\System32\termsrv.dll,-268
- %SystemRoot%\System32\svchost.exe -k NetworkService
- Load on Demand
- @%SystemRoot%\System32\termsrv.dll,-267

+ @%SystemRoot%\System32\themeservice.dll,-8192
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\System32\themeservice.dll,-8193

+ @%SystemRoot%\system32\TieringEngineService.exe,-702
- %SystemRoot%\system32\TieringEngineService.exe
- Load on Demand
- @%SystemRoot%\system32\TieringEngineService.exe,-701

+ @%windir%\system32\TimeBrokerServer.dll,-1001
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%windir%\system32\TimeBrokerServer.dll,-1002

+ @%systemroot%\system32\tokenbroker.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\tokenbroker.dll,-101

+ @%SystemRoot%\system32\trkwks.dll,-1
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\trkwks.dll,-2

+ @%SystemRoot%\system32\MitigationClient.dll,-103
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\MitigationClient.dll,-104

+ @%SystemRoot%\servicing\TrustedInstaller.exe,-100
- %SystemRoot%\servicing\TrustedInstaller.exe
- Load on Demand
- @%SystemRoot%\servicing\TrustedInstaller.exe,-101

+ TightVNC Server
- "C:\Program Files\TightVNC\tvnserver.exe" -service
- Auto Load
-

+ @%SystemRoot%\system32\tzautoupdate.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\tzautoupdate.dll,-201

+ @%systemroot%\system32\AgentService.exe,-102
- %systemroot%\system32\AgentService.exe
- disabled
- @%systemroot%\system32\AgentService.exe,-101

+ Microsoft Update Health Service
- "C:\Program Files\Microsoft Update Health Tools\uhssvc.exe"
- disabled
- Maintains Update Health

+ @%SystemRoot%\system32\umrdp.dll,-1000
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\umrdp.dll,-1001

+ @%systemroot%\system32\upnphost.dll,-213
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- Load on Demand
- @%systemroot%\system32\upnphost.dll,-214

+ @%systemroot%\system32\usermgr.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%systemroot%\system32\usermgr.dll,-101

+ @%systemroot%\system32\usosvc.dll,-101
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%systemroot%\system32\usosvc.dll,-102

+ @%SystemRoot%\system32\vac.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\vac.dll,-201

+ @%SystemRoot%\system32\vaultsvc.dll,-1003
- %SystemRoot%\system32\lsass.exe
- Load on Demand
- @%SystemRoot%\system32\vaultsvc.dll,-1004

+ @%SystemRoot%\system32\vds.exe,-100
- %SystemRoot%\System32\vds.exe
- Load on Demand
- @%SystemRoot%\system32\vds.exe,-112

+ VMware Alias Manager and Ticket Service
- "C:\Program Files\VMware\VMware Tools\VMware VGAuth\VGAuthService.exe"
- Auto Load
- Alias Manager and Ticket Service

+ @oem1.inf,%VM3DSERVICE_DISPLAYNAME%;VMware SVGA Helper Service
- %SystemRoot%\system32\vm3dservice.exe
- Auto Load
- @oem1.inf,%VM3DSERVICE_DESCRIPTION%;Helps VMware SVGA driver by collecting and conveying user mode information

+ @%systemroot%\system32\icsvc.dll,-801
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-802

+ @%systemroot%\system32\icsvc.dll,-101
- %systemroot%\system32\svchost.exe -k ICService -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-102

+ @%systemroot%\system32\icsvc.dll,-201
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-202

+ @%systemroot%\system32\icsvcext.dll,-601
- %systemroot%\system32\svchost.exe -k ICService -p
- Load on Demand
- @%systemroot%\system32\icsvcext.dll,-602

+ @%systemroot%\system32\icsvc.dll,-301
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-302

+ @%systemroot%\system32\icsvc.dll,-401
- %systemroot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-402

+ @%systemroot%\system32\icsvc.dll,-901
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-902

+ @%systemroot%\system32\icsvcext.dll,-501
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvcext.dll,-502

+ VMware Tools
- "C:\Program Files\VMware\VMware Tools\vmtoolsd.exe"
- Auto Load
- Provides support for synchronizing objects between the host and guest operating systems.

+ VMware Snapshot Provider
- C:\WINDOWS\system32\dllhost.exe /Processid:{0D7128C9-B843-49CB-A202-40976AA7645B}
- Load on Demand
- VMware Snapshot Provider

+ @%systemroot%\system32\vssvc.exe,-102
- %systemroot%\system32\vssvc.exe
- Load on Demand
- @%systemroot%\system32\vssvc.exe,-101

+ @%SystemRoot%\system32\w32time.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\w32time.dll,-201

+ @WaaSMedicSvc.dll,-100
- %systemroot%\system32\svchost.exe -k wusvcs -p
- Load on Demand
- @WaaSMedicSvc.dll,-101

+ @%SystemRoot%\System32\WalletService.dll,-1000
- %SystemRoot%\System32\svchost.exe -k appmodel -p
- Load on Demand
- @%SystemRoot%\System32\WalletService.dll,-1001

+ @%SystemRoot%\System32\Windows.WARP.JITService.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\Windows.WARP.JITService.dll,-101

+ @%systemroot%\system32\wbengine.exe,-104
- "%systemroot%\system32\wbengine.exe"
- Load on Demand
- @%systemroot%\system32\wbengine.exe,-105

+ @%systemroot%\system32\wbiosrvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k WbioSvcGroup
- Load on Demand
- @%systemroot%\system32\wbiosrvc.dll,-101

+ @%SystemRoot%\System32\wcmsvc.dll,-4097
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Auto Load
- @%SystemRoot%\System32\wcmsvc.dll,-4098

+ @%SystemRoot%\system32\wcncsvc.dll,-3
- %SystemRoot%\System32\svchost.exe -k LocalServiceAndNoImpersonation -p
- Load on Demand
- @%SystemRoot%\system32\wcncsvc.dll,-4

+ @%systemroot%\system32\wdi.dll,-502
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- Load on Demand
- @%systemroot%\system32\wdi.dll,-503

+ @%systemroot%\system32\wdi.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\wdi.dll,-501

+ @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320
- "%ProgramData%\Microsoft\Windows Defender\platform\4.18.2203.5-0\NisSrv.exe"
- Load on Demand
- @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-242

+ @%systemroot%\system32\webclnt.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%systemroot%\system32\webclnt.dll,-101

+ @%SystemRoot%\system32\wecsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k NetworkService -p
- Load on Demand
- @%SystemRoot%\system32\wecsvc.dll,-201

+ @%systemroot%\system32\wephostsvc.dll,-100
- %systemroot%\system32\svchost.exe -k WepHostSvcGroup
- Load on Demand
- @%systemroot%\system32\wephostsvc.dll,-101

+ @%SystemRoot%\System32\wercplsupport.dll,-101
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\System32\wercplsupport.dll,-100

+ @%SystemRoot%\System32\wersvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k WerSvcGroup
- Load on Demand
- @%SystemRoot%\System32\wersvc.dll,-101

+ @%SystemRoot%\System32\wfdsconmgrsvc.dll,-9000
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\wfdsconmgrsvc.dll,-9001

+ @%SystemRoot%\system32\wiarpc.dll,-2
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\wiarpc.dll,-1

+ @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310
- "C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2203.5-0\MsMpEng.exe"
- Load on Demand
- @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-240

+ @%SystemRoot%\system32\winhttp.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\winhttp.dll,-101

+ @%Systemroot%\system32\wbem\wmisvc.dll,-205
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%Systemroot%\system32\wbem\wmisvc.dll,-204

+ @%Systemroot%\system32\wsmsvc.dll,-101
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Load on Demand
- @%Systemroot%\system32\wsmsvc.dll,-102

+ @%SystemRoot%\system32\flightsettings.dll,-103
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\flightsettings.dll,-104

+ @%SystemRoot%\System32\wlansvc.dll,-257
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\wlansvc.dll,-258

+ @%SystemRoot%\system32\wlidsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\wlidsvc.dll,-101

+ @%SystemRoot%\system32\lpasvc.dll,-1000
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\lpasvc.dll,-1001

+ @%systemroot%\system32\Windows.Management.Service.dll,-100
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\Windows.Management.Service.dll,-101

+ @%Systemroot%\system32\wbem\wmiapsrv.exe,-110
- %systemroot%\system32\wbem\WmiApSrv.exe
- Load on Demand
- @%Systemroot%\system32\wbem\wmiapsrv.exe,-111

+ @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101
- "%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe"
- Load on Demand
- @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-102

+ @%systemroot%\system32\workfolderssvc.dll,-102
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- Load on Demand
- @%systemroot%\system32\workfolderssvc.dll,-101

+ @%systemroot%\system32\WpcRefreshTask.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService
- Load on Demand
- @%systemroot%\system32\WpcRefreshTask.dll,-101

+ @%SystemRoot%\system32\wpdbusenum.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\wpdbusenum.dll,-101

+ @%SystemRoot%\system32\wpnservice.dll,-1
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\system32\wpnservice.dll,-2

+ @%SystemRoot%\System32\wscsvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p
- Auto Load
- @%SystemRoot%\System32\wscsvc.dll,-201

+ @%systemroot%\system32\SearchIndexer.exe,-103
- %systemroot%\system32\SearchIndexer.exe /Embedding
- Auto Load
- @%systemroot%\system32\SearchIndexer.exe,-104

+ Windows Update
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\wuaueng.dll,-106

+ @%SystemRoot%\System32\wwansvc.dll,-257
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\wwansvc.dll,-258

+ Xbox Live Auth Manager
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- disabled
- @%systemroot%\system32\XblAuthManager.dll,-101

+ Xbox Live Game Save
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- disabled
- @%systemroot%\system32\XblGameSave.dll,-101

+ Xbox Accessory Management Service
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- disabled
- @%systemroot%\system32\xboxgipsvc.dll,-101

+ Xbox Live Networking Service
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- disabled
- @%systemroot%\system32\XboxNetApiSvc.dll,-101

+ @xinputhid.inf,%xinputhid.SvcDesc%;XINPUT HID Filter Driver
- \SystemRoot\System32\drivers\xinputhid.sys
- Load on Demand
-


Services :
+ @%SystemRoot%\system32\AJRouter.dll,-2
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\AJRouter.dll,-1

+ @%SystemRoot%\system32\Alg.exe,-112
- %SystemRoot%\System32\alg.exe
- Load on Demand
- @%SystemRoot%\system32\Alg.exe,-113

+ @%systemroot%\system32\appidsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\appidsvc.dll,-101

+ @%systemroot%\system32\appinfo.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\appinfo.dll,-101

+ @appmgmts.dll,-3250
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @appmgmts.dll,-3251

+ @%SystemRoot%\System32\AppReadiness.dll,-1000
- %SystemRoot%\System32\svchost.exe -k AppReadiness -p
- Load on Demand
- @%SystemRoot%\System32\AppReadiness.dll,-1001

+ @%systemroot%\system32\AppVClient.exe,-102
- %systemroot%\system32\AppVClient.exe
- disabled
- @%systemroot%\system32\AppVClient.exe,-101

+ @%SystemRoot%\system32\appxdeploymentserver.dll,-1
- %systemroot%\system32\svchost.exe -k wsappx -p
- Load on Demand
- @%SystemRoot%\system32\appxdeploymentserver.dll,-2

+ @%SystemRoot%\system32\assignedaccessmanagersvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k AssignedAccessManagerSvc
- Load on Demand
- @%SystemRoot%\system32\assignedaccessmanagersvc.dll,-101

+ @%SystemRoot%\system32\AudioEndpointBuilder.dll,-204
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Auto Load
- @%SystemRoot%\System32\AudioEndpointBuilder.dll,-205

+ @%SystemRoot%\system32\audiosrv.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p
- Auto Load
- @%SystemRoot%\System32\audiosrv.dll,-201

+ @%SystemRoot%\System32\autotimesvc.dll,-6
- %SystemRoot%\system32\svchost.exe -k autoTimeSvc
- Load on Demand
- @%SystemRoot%\System32\autotimesvc.dll,-7

+ Kaspersky Endpoint Security Service (KES.21.15)
- "C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avp.exe" -r
- Auto Load
- Provides computer protection against viruses, other malicious applications, and network attacks.

+ Kaspersky Seamless Update Service (KES.21.15)
- "C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avpsus.exe"
- Auto Load
- Lets you install and roll back critical and approved updates of application modules.

+ @%SystemRoot%\system32\AxInstSV.dll,-103
- %SystemRoot%\system32\svchost.exe -k AxInstSVGroup
- Load on Demand
- @%SystemRoot%\system32\AxInstSV.dll,-104

+ AzureAttestService
- C:\WINDOWS\system32\svchost.exe -k AzureAttestService
- Auto Load
-

+ @%SystemRoot%\system32\bdesvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\bdesvc.dll,-101

+ @%SystemRoot%\system32\bfe.dll,-1001
- %systemroot%\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p
- Auto Load
- @%SystemRoot%\system32\bfe.dll,-1002

+ Background Intelligent Transfer Service
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\qmgr.dll,-1001

+ @%windir%\system32\bisrv.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @%windir%\system32\bisrv.dll,-101

+ @%SystemRoot%\system32\BTAGService.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\BTAGService.dll,-102

+ @%SystemRoot%\system32\BthAvctpSvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\BthAvctpSvc.dll,-102

+ @%SystemRoot%\System32\bthserv.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\System32\bthserv.dll,-102

+ @%SystemRoot%\system32\CapabilityAccessManager.dll,-1
- %SystemRoot%\system32\svchost.exe -k appmodel -p
- Load on Demand
- @%SystemRoot%\system32\CapabilityAccessManager.dll,-2

+ @%SystemRoot%\system32\cdpsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @%SystemRoot%\system32\cdpsvc.dll,-101

+ @%SystemRoot%\System32\certprop.dll,-11
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\certprop.dll,-12

+ @%SystemRoot%\system32\ClipSVC.dll,-103
- %SystemRoot%\System32\svchost.exe -k wsappx -p
- Load on Demand
- @%SystemRoot%\system32\ClipSVC.dll,-104

+ @%SystemRoot%\system32\cloudidsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k CloudIdServiceGroup -p
- Load on Demand
- @%SystemRoot%\system32\cloudidsvc.dll,-101

+ @comres.dll,-947
- %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
- Load on Demand
- @comres.dll,-948

+ @%SystemRoot%\system32\coremessaging.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork -p
- Auto Load
- @%SystemRoot%\system32\coremessaging.dll,-2

+ @%SystemRoot%\system32\cryptsvc.dll,-1001
- %SystemRoot%\system32\svchost.exe -k NetworkService -p
- Auto Load
- @%SystemRoot%\system32\cryptsvc.dll,-1002

+ @%systemroot%\system32\cscsvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\cscsvc.dll,-201

+ @combase.dll,-5012
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @combase.dll,-5013

+ @%systemroot%\system32\dcsvc.dll,-101
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\dcsvc.dll,-102

+ @%SystemRoot%\system32\defragsvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k defragsvc
- Load on Demand
- @%SystemRoot%\system32\defragsvc.dll,-102

+ @%SystemRoot%\system32\das.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\das.dll,-101

+ @%SystemRoot%\system32\umpnpmgr.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Load on Demand
- @%SystemRoot%\system32\umpnpmgr.dll,-101

+ @%SystemRoot%\system32\DevQueryBroker.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\DevQueryBroker.dll,-101

+ @%SystemRoot%\system32\dhcpcore.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\dhcpcore.dll,-101

+ @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000
- %SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe
- Load on Demand
- @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1001

+ @%systemroot%\system32\DiagSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k diagnostics
- Load on Demand
- @%systemroot%\system32\DiagSvc.dll,-101

+ @%SystemRoot%\system32\diagtrack.dll,-3001
- %SystemRoot%\System32\svchost.exe -k utcsvc -p
- Auto Load
- @%SystemRoot%\system32\diagtrack.dll,-3002

+ @%SystemRoot%\system32\DialogBlockingService.dll,-100
- %SystemRoot%\system32\svchost.exe -k DialogBlockingService
- disabled
- @%SystemRoot%\system32\DialogBlockingService.dll,-101

+ @%SystemRoot%\system32\dispbroker.desktop.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @%SystemRoot%\system32\dispbroker.desktop.dll,-102

+ @%SystemRoot%\System32\Microsoft.Graphics.Display.DisplayEnhancementService.dll,-1000
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\Microsoft.Graphics.Display.DisplayEnhancementService.dll,-1001

+ @%systemroot%\system32\Windows.Internal.Management.dll,-100
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\Windows.Internal.Management.dll,-101

+ @%SystemRoot%\system32\dmwappushsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\dmwappushsvc.dll,-201

+ @%SystemRoot%\System32\dnsapi.dll,-101
- %SystemRoot%\system32\svchost.exe -k NetworkService -p
- Auto Load
- @%SystemRoot%\System32\dnsapi.dll,-102

+ @%systemroot%\system32\dosvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Auto Load
- @%systemroot%\system32\dosvc.dll,-101

+ @%systemroot%\system32\dot3svc.dll,-1102
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\dot3svc.dll,-1103

+ @%systemroot%\system32\dps.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork -p
- Auto Load
- @%systemroot%\system32\dps.dll,-501

+ @%SystemRoot%\system32\DeviceSetupManager.dll,-1000
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\DeviceSetupManager.dll,-1001

+ @%SystemRoot%\system32\dssvc.dll,-10003
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\dssvc.dll,-10002

+ @%SystemRoot%\System32\dusmsvc.dll,-1
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p
- Auto Load
- @%SystemRoot%\System32\dusmsvc.dll,-2

+ @%systemroot%\system32\eapsvc.dll,-1
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\eapsvc.dll,-2

+ Microsoft Edge Update Service (edgeupdate)
- "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svc
- Auto Load
- Keeps your Microsoft software up to date. If this service is disabled or stopped, your Microsoft software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Microsoft software using it.

+ Microsoft Edge Update Service (edgeupdatem)
- "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /medsvc
- Load on Demand
- Keeps your Microsoft software up to date. If this service is disabled or stopped, your Microsoft software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Microsoft software using it.

+ @%SystemRoot%\system32\efssvc.dll,-100
- %SystemRoot%\System32\lsass.exe
- Load on Demand
- @%SystemRoot%\system32\efssvc.dll,-101

+ @%SystemRoot%\system32\embeddedmodesvc.dll,-201
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\embeddedmodesvc.dll,-202

+ @EnterpriseAppMgmtSvc.dll,-1
- %systemroot%\system32\svchost.exe -k appmodel -p
- Load on Demand
- @EnterpriseAppMgmtSvc.dll,-2

+ @%SystemRoot%\system32\wevtsvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\wevtsvc.dll,-201

+ @comres.dll,-2450
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @comres.dll,-2451

+ Fax
- %systemroot%\system32\fxssvc.exe
- disabled
- @%systemroot%\system32\fxsresm.dll,-122

+ @%systemroot%\system32\fdPHost.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%systemroot%\system32\fdPHost.dll,-101

+ @%systemroot%\system32\fdrespub.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- Load on Demand
- @%systemroot%\system32\fdrespub.dll,-101

+ @%systemroot%\system32\fhsvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\fhsvc.dll,-102

+ @%systemroot%\system32\FntCache.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @%systemroot%\system32\FntCache.dll,-101

+ @%SystemRoot%\system32\PresentationHost.exe,-3309
- %systemroot%\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
- Load on Demand
- @%SystemRoot%\system32\PresentationHost.exe,-3310

+ @%systemroot%\system32\FrameServer.dll,-100
- %SystemRoot%\System32\svchost.exe -k Camera
- Load on Demand
- @%systemroot%\system32\FrameServer.dll,-101

+ @%systemroot%\system32\GameInputSvc.exe,-101
- %SystemRoot%\System32\GameInputSvc.exe
- Load on Demand
- @%systemroot%\system32\GameInputSvc.exe,-102

+ Google Chrome Elevation Service (GoogleChromeElevationService)
- "C:\Program Files\Google\Chrome\Application\143.0.7499.193\elevation_service.exe"
- Load on Demand
- Provides encryption services and a secure way for recovering Google Chrome if it gets out of date. If this service is disabled, Google Chrome may lose access to encrypted data, and Google Chrome may not be able recover itself.

+ Google Updater Internal Service (GoogleUpdaterInternalService144.0.7547.0)
- "C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.0\updater.exe" --system --windows-service --service=update-internal
- Auto Load
- Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it.

+ Google Updater Service (GoogleUpdaterService144.0.7547.0)
- "C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.0\updater.exe" --system --windows-service --service=update
- Auto Load
- Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it.

+ @gpapi.dll,-112
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @gpapi.dll,-113

+ @%SystemRoot%\system32\GraphicsPerfSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k GraphicsPerfSvcGroup
- Load on Demand
- @%SystemRoot%\system32\GraphicsPerfSvc.dll,-101

+ @%SystemRoot%\System32\hidserv.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\hidserv.dll,-102

+ @%SystemRoot%\system32\hvhostsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\hvhostsvc.dll,-101

+ @%SystemRoot%\System32\tetheringservice.dll,-4097
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\tetheringservice.dll,-4098

+ @%SystemRoot%\system32\ikeext.dll,-501
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\system32\ikeext.dll,-502

+ @%SystemRoot%\system32\InstallService.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\InstallService.dll,-201

+ @%SystemRoot%\system32\iphlpsvc.dll,-500
- %SystemRoot%\System32\svchost.exe -k NetSvcs -p
- Auto Load
- @%SystemRoot%\system32\iphlpsvc.dll,-501

+ @%Systemroot%\system32\ipxlatcfg.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%Systemroot%\system32\ipxlatcfg.dll,-501

+ @keyiso.dll,-100
- %SystemRoot%\system32\lsass.exe
- Load on Demand
- @keyiso.dll,-101

+ Kaspersky Security Center Network Agent
- "C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\klnagent.exe"
- Auto Load
- Network Agent coordinates interaction between the Administration Server and Kaspersky applications installed on devices.

+ Kaspersky Security Network proxy server
- "C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\ksnproxy.exe"
- Load on Demand
- The KSN proxy service retranslates requests to Kaspersky Security Network and caches the responses.

+ @comres.dll,-2946
- %SystemRoot%\System32\svchost.exe -k NetworkServiceAndNoImpersonation -p
- Load on Demand
- @comres.dll,-2947

+ @%systemroot%\system32\srvsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%systemroot%\system32\srvsvc.dll,-101

+ @%systemroot%\system32\wkssvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Auto Load
- @%systemroot%\system32\wkssvc.dll,-101

+ @%SystemRoot%\System32\lfsvc.dll,-1
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\System32\lfsvc.dll,-2

+ @%SystemRoot%\system32\licensemanagersvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\licensemanagersvc.dll,-201

+ @%SystemRoot%\system32\lltdres.dll,-1
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\lltdres.dll,-2

+ @%SystemRoot%\system32\lmhsvc.dll,-101
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\lmhsvc.dll,-102

+ @%windir%\system32\lsm.dll,-1001
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @%windir%\system32\lsm.dll,-1002

+ Apache Tomcat 9.0 Lucee
- D:\Techexcel\Lucee\tomcat\bin\Tomcat9.exe //RS//Lucee
- disabled
- Apache Tomcat 9.0.45 Server - https://tomcat.apache.org/

+ @%SystemRoot%\system32\LanguageOverlayServer.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\LanguageOverlayServer.dll,-101

+ @%SystemRoot%\System32\moshost.dll,-100
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Auto Load
- @%SystemRoot%\System32\moshost.dll,-101

+ @%SystemRoot%\system32\McpManagementService.dll,-100
- %SystemRoot%\system32\svchost.exe -k McpManagementServiceGroup
- Load on Demand
- @%SystemRoot%\system32\McpManagementService.dll,-101

+ Microsoft Edge Elevation Service (MicrosoftEdgeElevationService)
- "C:\Program Files (x86)\Microsoft\Edge\Application\92.0.902.67\elevation_service.exe"
- Load on Demand
- Keeps Microsoft Edge up to update. If this service is disabled, the application will not be kept up to date.

+ @%SystemRoot%\system32\MixedRealityRuntime.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\MixedRealityRuntime.dll,-102

+ Mozilla Maintenance Service
- "C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe"
- Load on Demand
- The Mozilla Maintenance Service ensures that you have the latest and most secure version of Mozilla Firefox on your computer. Keeping Firefox up to date is very important for your online security, and Mozilla strongly recommends that you keep this service enabled.

+ @%SystemRoot%\system32\FirewallAPI.dll,-23090
- %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p
- Auto Load
- @%SystemRoot%\system32\FirewallAPI.dll,-23091

+ @comres.dll,-2797
- %SystemRoot%\System32\msdtc.exe
- Load on Demand
- @comres.dll,-2798

+ @%SystemRoot%\system32\iscsidsc.dll,-5000
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\iscsidsc.dll,-5001

+ @%SystemRoot%\system32\msimsg.dll,-27
- %systemroot%\system32\msiexec.exe /V
- Load on Demand
- @%SystemRoot%\system32\msimsg.dll,-32

+ @%SystemRoot%\system32\KeyboardFilterSvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\system32\KeyboardFilterSvc.dll,-102

+ MS-MPI Launch Service
- "C:\Program Files\Microsoft MPI\Bin\msmpilaunchsvc.exe"
- Load on Demand
- Service for launching MS-MPI applications

+ SQL Full-text Filter Daemon Launcher (MSSQLSERVER)
- "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL15.MSSQLSERVER
- Load on Demand
- Service to launch full-text filter daemon process which will perform document filtering and word breaking for SQL Server full-text search. Disabling this service will make full-text search features of SQL Server unavailable.

+ SQL Server Launchpad (MSSQLSERVER)
- "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\launchpad.exe" -launcher RLauncher.dll -launcher Pythonlauncher.dll -launcher commonlauncher.dll -pipename sqlsatellitelaunch -timeout 600000 -logPath "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\LOG\ExtensibilityLog" -workingDir "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExtensibilityData" -externalLanguagesTempDir "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLanguagesTemp" -externalLanguagesDir "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLanguages" -externalLibrariesTempDir "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLibrariesTemp" -externalLibrariesDir "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLibraries" -satelliteDllPath "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlsatellite.dll"
- Auto Load
- Service to launch Advanced Analytics Extensions Launchpad process that enables integration with Microsoft R Open using standard T-SQL statements. Disabling this service will make Advanced Analytics features of SQL Server unavailable.

+ SQL Server (MSSQLSERVER)
- "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER
- disabled
- Provides storage, processing and controlled access of data, and rapid transaction processing.

+ @%systemroot%\system32\NaturalAuth.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\NaturalAuth.dll,-101

+ @%SystemRoot%\system32\ncasvc.dll,-3009
- %SystemRoot%\System32\svchost.exe -k NetSvcs -p
- Load on Demand
- @%SystemRoot%\system32\ncasvc.dll,-3008

+ @%SystemRoot%\system32\ncbservice.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\ncbservice.dll,-501

+ @%SystemRoot%\system32\NcdAutoSetup.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork -p
- Load on Demand
- @%SystemRoot%\system32\NcdAutoSetup.dll,-101

+ @%SystemRoot%\System32\netlogon.dll,-102
- %systemroot%\system32\lsass.exe
- Load on Demand
- @%SystemRoot%\System32\netlogon.dll,-103

+ @%SystemRoot%\system32\netman.dll,-109
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\netman.dll,-110

+ @%SystemRoot%\system32\netprofmsvc.dll,-202
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\netprofmsvc.dll,-203

+ @%SystemRoot%\system32\NetSetupSvc.dll,-3
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\NetSetupSvc.dll,-4

+ @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8201
- %systemroot%\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
- disabled
- @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8200

+ @%SystemRoot%\System32\NgcCtnrSvc.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\NgcCtnrSvc.dll,-2

+ @%SystemRoot%\System32\ngcsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\ngcsvc.dll,-101

+ @%SystemRoot%\System32\nlasvc.dll,-1
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Auto Load
- @%SystemRoot%\System32\nlasvc.dll,-2

+ @%SystemRoot%\system32\nsisvc.dll,-200
- %systemroot%\system32\svchost.exe -k LocalService -p
- Auto Load
- @%SystemRoot%\system32\nsisvc.dll,-201

+ Office 64 Source Engine
- "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
- Load on Demand
- Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports.

+ @%SystemRoot%\system32\pnrpsvc.dll,-8004
- %SystemRoot%\System32\svchost.exe -k LocalServicePeerNet
- Load on Demand
- @%SystemRoot%\system32\pnrpsvc.dll,-8005

+ @%SystemRoot%\system32\p2psvc.dll,-8006
- %SystemRoot%\System32\svchost.exe -k LocalServicePeerNet
- Load on Demand
- @%SystemRoot%\system32\p2psvc.dll,-8007

+ @%SystemRoot%\system32\pcasvc.dll,-1
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\pcasvc.dll,-2

+ @%SystemRoot%\system32\peerdistsvc.dll,-9000
- %SystemRoot%\System32\svchost.exe -k PeerDist
- Load on Demand
- @%SystemRoot%\system32\peerdistsvc.dll,-9001

+ @%systemroot%\system32\PerceptionSimulation\PerceptionSimulationService.exe,-101
- %systemroot%\system32\PerceptionSimulation\PerceptionSimulationService.exe
- Load on Demand
- @%systemroot%\system32\PerceptionSimulation\PerceptionSimulationService.exe,-102

+ @%systemroot%\sysWow64\perfhost.exe,-2
- %SystemRoot%\SysWow64\perfhost.exe
- Load on Demand
- @%systemroot%\SysWow64\perfhost.exe,-1

+ @%SystemRoot%\system32\PhoneserviceRes.dll,-10000
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\PhoneserviceRes.dll,-10001

+ @%systemroot%\system32\pla.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork -p
- Load on Demand
- @%systemroot%\system32\pla.dll,-501

+ @%SystemRoot%\system32\umpnpmgr.dll,-200
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Load on Demand
- @%SystemRoot%\system32\umpnpmgr.dll,-101

+ @%SystemRoot%\system32\pnrpauto.dll,-8002
- %SystemRoot%\System32\svchost.exe -k LocalServicePeerNet
- Load on Demand
- @%SystemRoot%\system32\pnrpauto.dll,-8003

+ @%SystemRoot%\system32\pnrpsvc.dll,-8000
- %SystemRoot%\System32\svchost.exe -k LocalServicePeerNet
- Load on Demand
- @%SystemRoot%\system32\pnrpsvc.dll,-8001

+ @%SystemRoot%\System32\polstore.dll,-5010
- %SystemRoot%\system32\svchost.exe -k NetworkServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\polstore.dll,-5011

+ @%SystemRoot%\system32\umpo.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @%SystemRoot%\system32\umpo.dll,-101

+ @%systemroot%\system32\profsvc.dll,-300
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%systemroot%\system32\profsvc.dll,-301

+ @%SystemRoot%\system32\pushtoinstall.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\pushtoinstall.dll,-201

+ @%SystemRoot%\system32\qwave.dll,-1
- %windir%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- Load on Demand
- @%SystemRoot%\system32\qwave.dll,-2

+ @%Systemroot%\system32\rasauto.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%Systemroot%\system32\rasauto.dll,-201

+ @%Systemroot%\system32\rasmans.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Auto Load
- @%Systemroot%\system32\rasmans.dll,-201

+ @%Systemroot%\system32\mprdim.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs
- disabled
- @%Systemroot%\system32\mprdim.dll,-201

+ Remote Registry
- %SystemRoot%\system32\svchost.exe -k localService -p
- Load on Demand
- @regsvc.dll,-2

+ @%SystemRoot%\System32\RDXService.dll,-256
- %SystemRoot%\System32\svchost.exe -k rdxgroup
- Load on Demand
- @%SystemRoot%\System32\RDXService.dll,-257

+ @%SystemRoot%\system32\RMapi.dll,-1001
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\RMapi.dll,-1002

+ @%windir%\system32\RpcEpMap.dll,-1001
- %SystemRoot%\system32\svchost.exe -k RPCSS -p
- Auto Load
- @%windir%\system32\RpcEpMap.dll,-1002

+ @%systemroot%\system32\Locator.exe,-2
- %SystemRoot%\system32\locator.exe
- Load on Demand
- @%systemroot%\system32\Locator.exe,-3

+ @combase.dll,-5010
- %SystemRoot%\system32\svchost.exe -k rpcss -p
- Auto Load
- @combase.dll,-5011

+ @%SystemRoot%\system32\samsrv.dll,-1
- %SystemRoot%\system32\lsass.exe
- Auto Load
- @%SystemRoot%\system32\samsrv.dll,-2

+ @%SystemRoot%\System32\SCardSvr.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
- Load on Demand
- @%SystemRoot%\System32\SCardSvr.dll,-5

+ @%SystemRoot%\System32\ScDeviceEnum.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\ScDeviceEnum.dll,-101

+ @%SystemRoot%\system32\schedsvc.dll,-100
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\system32\schedsvc.dll,-101

+ @%SystemRoot%\System32\certprop.dll,-13
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\certprop.dll,-14

+ @%SystemRoot%\system32\sdrsvc.dll,-107
- %SystemRoot%\system32\svchost.exe -k SDRSVC
- Load on Demand
- @%SystemRoot%\system32\sdrsvc.dll,-102

+ @%SystemRoot%\system32\seclogon.dll,-7001
- %windir%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\seclogon.dll,-7000

+ SecPod Saner Agent
- "C:\Program Files (x86)\SecPod Saner\Agent\bin\spsaneragnt.exe"
- Auto Load
- An agent for vulnerability detection and mitigation, works with SecPod's SanerNow Advanced Vulnerability Management platform.

+ SecPod Saner Upgrade Controller v2
- "C:\Program Files (x86)\SecPod Saner\Upgrader\bin\spupgradecontroller.exe"
- Load on Demand
- Controller for monitoring SecPod's SanerNow agent upgrade.

+ @%systemroot%\system32\SecurityHealthAgent.dll,-1002
- %SystemRoot%\system32\SecurityHealthService.exe
- Load on Demand
- @%systemroot%\system32\SecurityHealthAgent.dll,-1001

+ @%SystemRoot%\System32\SEMgrSvc.dll,-1001
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\System32\SEMgrSvc.dll,-1002

+ @%SystemRoot%\system32\Sens.dll,-200
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\system32\Sens.dll,-201

+ @%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1001
- "%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe"
- Load on Demand
- @%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1002

+ @%SystemRoot%\system32\SensorDataService.exe,-101
- %SystemRoot%\System32\SensorDataService.exe
- Load on Demand
- @%SystemRoot%\system32\SensorDataService.exe,-102

+ @%SystemRoot%\System32\sensorservice.dll,-1000
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\sensorservice.dll,-1001

+ @%SystemRoot%\System32\sensrsvc.dll,-1000
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- Load on Demand
- @%SystemRoot%\System32\sensrsvc.dll,-1001

+ @%SystemRoot%\System32\SessEnv.dll,-1026
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\System32\SessEnv.dll,-1027

+ @%SystemRoot%\system32\ipnathlp.dll,-106
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\ipnathlp.dll,-107

+ @%SystemRoot%\system32\SharedRealitySvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\SharedRealitySvc.dll,-101

+ @%SystemRoot%\System32\shsvcs.dll,-12288
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\System32\shsvcs.dll,-12289

+ @%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- disabled
- @%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-101

+ @%SystemRoot%\System32\smphost.dll,-102
- %SystemRoot%\System32\svchost.exe -k smphost
- Load on Demand
- @%SystemRoot%\System32\smphost.dll,-101

+ @%SystemRoot%\System32\SmsRouterSvc.dll,-10001
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\SmsRouterSvc.dll,-10002

+ @firewallapi.dll,-50323
- %SystemRoot%\System32\snmptrap.exe
- Load on Demand
- @firewallapi.dll,-50324

+ @%systemroot%\system32\spectrum.exe,-101
- %systemroot%\system32\spectrum.exe
- Load on Demand
- @%systemroot%\system32\spectrum.exe,-102

+ @%SystemRoot%\system32\sppsvc.exe,-101
- %SystemRoot%\system32\sppsvc.exe
- Auto Load
- @%SystemRoot%\system32\sppsvc.exe,-100

+ SQL Server Browser
- "C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe"
- disabled
- Provides SQL Server connection information to client computers.

+ SQL Server Agent (MSSQLSERVER)
- "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER
- disabled
- Executes jobs, monitors SQL Server, fires alerts, and allows automation of some administrative tasks.

+ SQL Server CEIP service (MSSQLSERVER)
- "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlceip.exe" -Service
- Auto Load
- CEIP service for Sql server

+ SQL Server VSS Writer
- "C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
- Auto Load
- Provides the interface to backup/restore Microsoft SQL server through the Windows VSS infrastructure.

+ @%systemroot%\system32\ssdpsrv.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- Load on Demand
- @%systemroot%\system32\ssdpsrv.dll,-101

+ OpenSSH Authentication Agent
- %SystemRoot%\System32\OpenSSH\ssh-agent.exe
- disabled
- Agent to hold private keys used for public key authentication.

+ @%SystemRoot%\system32\sstpsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\sstpsvc.dll,-201

+ @%SystemRoot%\system32\windows.staterepository.dll,-1
- %SystemRoot%\system32\svchost.exe -k appmodel -p
- Load on Demand
- @%SystemRoot%\system32\windows.staterepository.dll,-2

+ @%SystemRoot%\system32\wiaservc.dll,-9
- %SystemRoot%\system32\svchost.exe -k imgsvc
- Load on Demand
- @%SystemRoot%\system32\wiaservc.dll,-10

+ @%SystemRoot%\System32\StorSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Auto Load
- @%SystemRoot%\System32\StorSvc.dll,-101

+ @%SystemRoot%\system32\svsvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\svsvc.dll,-102

+ @%SystemRoot%\System32\swprv.dll,-103
- %SystemRoot%\System32\svchost.exe -k swprv
- Load on Demand
- @%SystemRoot%\System32\swprv.dll,-102

+ @%SystemRoot%\system32\sysmain.dll,-1000
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\sysmain.dll,-1001

+ @%windir%\system32\SystemEventsBrokerServer.dll,-1001
- %SystemRoot%\system32\svchost.exe -k DcomLaunch -p
- Auto Load
- @%windir%\system32\SystemEventsBrokerServer.dll,-1002

+ @%SystemRoot%\system32\TabSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\TabSvc.dll,-101

+ @%SystemRoot%\system32\tapisrv.dll,-10100
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Load on Demand
- @%SystemRoot%\system32\tapisrv.dll,-10101

+ @%SystemRoot%\System32\termsrv.dll,-268
- %SystemRoot%\System32\svchost.exe -k NetworkService
- Load on Demand
- @%SystemRoot%\System32\termsrv.dll,-267

+ @%SystemRoot%\System32\themeservice.dll,-8192
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\System32\themeservice.dll,-8193

+ @%SystemRoot%\system32\TieringEngineService.exe,-702
- %SystemRoot%\system32\TieringEngineService.exe
- Load on Demand
- @%SystemRoot%\system32\TieringEngineService.exe,-701

+ @%windir%\system32\TimeBrokerServer.dll,-1001
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%windir%\system32\TimeBrokerServer.dll,-1002

+ @%systemroot%\system32\tokenbroker.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\tokenbroker.dll,-101

+ @%SystemRoot%\system32\trkwks.dll,-1
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Auto Load
- @%SystemRoot%\system32\trkwks.dll,-2

+ @%SystemRoot%\system32\MitigationClient.dll,-103
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\MitigationClient.dll,-104

+ @%SystemRoot%\servicing\TrustedInstaller.exe,-100
- %SystemRoot%\servicing\TrustedInstaller.exe
- Load on Demand
- @%SystemRoot%\servicing\TrustedInstaller.exe,-101

+ TightVNC Server
- "C:\Program Files\TightVNC\tvnserver.exe" -service
- Auto Load
-

+ @%SystemRoot%\system32\tzautoupdate.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%SystemRoot%\system32\tzautoupdate.dll,-201

+ @%systemroot%\system32\AgentService.exe,-102
- %systemroot%\system32\AgentService.exe
- disabled
- @%systemroot%\system32\AgentService.exe,-101

+ Microsoft Update Health Service
- "C:\Program Files\Microsoft Update Health Tools\uhssvc.exe"
- disabled
- Maintains Update Health

+ @%SystemRoot%\system32\umrdp.dll,-1000
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\umrdp.dll,-1001

+ @%systemroot%\system32\upnphost.dll,-213
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
- Load on Demand
- @%systemroot%\system32\upnphost.dll,-214

+ @%systemroot%\system32\usermgr.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%systemroot%\system32\usermgr.dll,-101

+ @%systemroot%\system32\usosvc.dll,-101
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%systemroot%\system32\usosvc.dll,-102

+ @%SystemRoot%\system32\vac.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\vac.dll,-201

+ @%SystemRoot%\system32\vaultsvc.dll,-1003
- %SystemRoot%\system32\lsass.exe
- Load on Demand
- @%SystemRoot%\system32\vaultsvc.dll,-1004

+ @%SystemRoot%\system32\vds.exe,-100
- %SystemRoot%\System32\vds.exe
- Load on Demand
- @%SystemRoot%\system32\vds.exe,-112

+ VMware Alias Manager and Ticket Service
- "C:\Program Files\VMware\VMware Tools\VMware VGAuth\VGAuthService.exe"
- Auto Load
- Alias Manager and Ticket Service

+ @oem1.inf,%VM3DSERVICE_DISPLAYNAME%;VMware SVGA Helper Service
- %SystemRoot%\system32\vm3dservice.exe
- Auto Load
- @oem1.inf,%VM3DSERVICE_DESCRIPTION%;Helps VMware SVGA driver by collecting and conveying user mode information

+ @%systemroot%\system32\icsvc.dll,-801
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-802

+ @%systemroot%\system32\icsvc.dll,-101
- %systemroot%\system32\svchost.exe -k ICService -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-102

+ @%systemroot%\system32\icsvc.dll,-201
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-202

+ @%systemroot%\system32\icsvcext.dll,-601
- %systemroot%\system32\svchost.exe -k ICService -p
- Load on Demand
- @%systemroot%\system32\icsvcext.dll,-602

+ @%systemroot%\system32\icsvc.dll,-301
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-302

+ @%systemroot%\system32\icsvc.dll,-401
- %systemroot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-402

+ @%systemroot%\system32\icsvc.dll,-901
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-902

+ @%systemroot%\system32\icsvcext.dll,-501
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\icsvcext.dll,-502

+ VMware Tools
- "C:\Program Files\VMware\VMware Tools\vmtoolsd.exe"
- Auto Load
- Provides support for synchronizing objects between the host and guest operating systems.

+ VMware Snapshot Provider
- C:\WINDOWS\system32\dllhost.exe /Processid:{0D7128C9-B843-49CB-A202-40976AA7645B}
- Load on Demand
- VMware Snapshot Provider

+ @%systemroot%\system32\vssvc.exe,-102
- %systemroot%\system32\vssvc.exe
- Load on Demand
- @%systemroot%\system32\vssvc.exe,-101

+ @%SystemRoot%\system32\w32time.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\w32time.dll,-201

+ @WaaSMedicSvc.dll,-100
- %systemroot%\system32\svchost.exe -k wusvcs -p
- Load on Demand
- @WaaSMedicSvc.dll,-101

+ @%SystemRoot%\System32\WalletService.dll,-1000
- %SystemRoot%\System32\svchost.exe -k appmodel -p
- Load on Demand
- @%SystemRoot%\System32\WalletService.dll,-1001

+ @%SystemRoot%\System32\Windows.WARP.JITService.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\Windows.WARP.JITService.dll,-101

+ @%systemroot%\system32\wbengine.exe,-104
- "%systemroot%\system32\wbengine.exe"
- Load on Demand
- @%systemroot%\system32\wbengine.exe,-105

+ @%systemroot%\system32\wbiosrvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k WbioSvcGroup
- Load on Demand
- @%systemroot%\system32\wbiosrvc.dll,-101

+ @%SystemRoot%\System32\wcmsvc.dll,-4097
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Auto Load
- @%SystemRoot%\System32\wcmsvc.dll,-4098

+ @%SystemRoot%\system32\wcncsvc.dll,-3
- %SystemRoot%\System32\svchost.exe -k LocalServiceAndNoImpersonation -p
- Load on Demand
- @%SystemRoot%\system32\wcncsvc.dll,-4

+ @%systemroot%\system32\wdi.dll,-502
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- Load on Demand
- @%systemroot%\system32\wdi.dll,-503

+ @%systemroot%\system32\wdi.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%systemroot%\system32\wdi.dll,-501

+ @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320
- "%ProgramData%\Microsoft\Windows Defender\platform\4.18.2203.5-0\NisSrv.exe"
- Load on Demand
- @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-242

+ @%systemroot%\system32\webclnt.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService -p
- Load on Demand
- @%systemroot%\system32\webclnt.dll,-101

+ @%SystemRoot%\system32\wecsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k NetworkService -p
- Load on Demand
- @%SystemRoot%\system32\wecsvc.dll,-201

+ @%systemroot%\system32\wephostsvc.dll,-100
- %systemroot%\system32\svchost.exe -k WepHostSvcGroup
- Load on Demand
- @%systemroot%\system32\wephostsvc.dll,-101

+ @%SystemRoot%\System32\wercplsupport.dll,-101
- %SystemRoot%\System32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\System32\wercplsupport.dll,-100

+ @%SystemRoot%\System32\wersvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k WerSvcGroup
- Load on Demand
- @%SystemRoot%\System32\wersvc.dll,-101

+ @%SystemRoot%\System32\wfdsconmgrsvc.dll,-9000
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\wfdsconmgrsvc.dll,-9001

+ @%SystemRoot%\system32\wiarpc.dll,-2
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\wiarpc.dll,-1

+ @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310
- "C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2203.5-0\MsMpEng.exe"
- Load on Demand
- @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-240

+ @%SystemRoot%\system32\winhttp.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\winhttp.dll,-101

+ @%Systemroot%\system32\wbem\wmisvc.dll,-205
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%Systemroot%\system32\wbem\wmisvc.dll,-204

+ @%Systemroot%\system32\wsmsvc.dll,-101
- %SystemRoot%\System32\svchost.exe -k NetworkService -p
- Load on Demand
- @%Systemroot%\system32\wsmsvc.dll,-102

+ @%SystemRoot%\system32\flightsettings.dll,-103
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\flightsettings.dll,-104

+ @%SystemRoot%\System32\wlansvc.dll,-257
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\wlansvc.dll,-258

+ @%SystemRoot%\system32\wlidsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%SystemRoot%\system32\wlidsvc.dll,-101

+ @%SystemRoot%\system32\lpasvc.dll,-1000
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\system32\lpasvc.dll,-1001

+ @%systemroot%\system32\Windows.Management.Service.dll,-100
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\Windows.Management.Service.dll,-101

+ @%Systemroot%\system32\wbem\wmiapsrv.exe,-110
- %systemroot%\system32\wbem\WmiApSrv.exe
- Load on Demand
- @%Systemroot%\system32\wbem\wmiapsrv.exe,-111

+ @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101
- "%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe"
- Load on Demand
- @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-102

+ @%systemroot%\system32\workfolderssvc.dll,-102
- %SystemRoot%\System32\svchost.exe -k LocalService -p
- Load on Demand
- @%systemroot%\system32\workfolderssvc.dll,-101

+ @%systemroot%\system32\WpcRefreshTask.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService
- Load on Demand
- @%systemroot%\system32\WpcRefreshTask.dll,-101

+ @%SystemRoot%\system32\wpdbusenum.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\wpdbusenum.dll,-101

+ @%SystemRoot%\system32\wpnservice.dll,-1
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Auto Load
- @%SystemRoot%\system32\wpnservice.dll,-2

+ @%SystemRoot%\System32\wscsvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p
- Auto Load
- @%SystemRoot%\System32\wscsvc.dll,-201

+ @%systemroot%\system32\SearchIndexer.exe,-103
- %systemroot%\system32\SearchIndexer.exe /Embedding
- Auto Load
- @%systemroot%\system32\SearchIndexer.exe,-104

+ Windows Update
- %systemroot%\system32\svchost.exe -k netsvcs -p
- Load on Demand
- @%systemroot%\system32\wuaueng.dll,-106

+ @%SystemRoot%\System32\wwansvc.dll,-257
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p
- Load on Demand
- @%SystemRoot%\System32\wwansvc.dll,-258

+ Xbox Live Auth Manager
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- disabled
- @%systemroot%\system32\XblAuthManager.dll,-101

+ Xbox Live Game Save
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- disabled
- @%systemroot%\system32\XblGameSave.dll,-101

+ Xbox Accessory Management Service
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- disabled
- @%systemroot%\system32\xboxgipsvc.dll,-101

+ Xbox Live Networking Service
- %SystemRoot%\system32\svchost.exe -k netsvcs -p
- disabled
- @%systemroot%\system32\XboxNetApiSvc.dll,-101
70629 - Microsoft Windows AutoRuns Winlogon
-
Synopsis
Report programs that startup associates with the winlogon process.
Description
Report the startup locations associated with the winlogon process.

These values could add features to the logon process, assist in authentication, or set screen savers.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers
+ CLSID : {01A30791-40AE-4653-AB2E-FD210019AE88}
- Name : Automatic Redeployment Credential Provider
- Value : %systemroot%\system32\mgmtrefreshcredprov.dll

+ CLSID : {1b283861-754f-4022-ad47-a5eaaa618894}
- Name : Smartcard Reader Selection Provider
- Value : %SystemRoot%\system32\SmartcardCredentialProvider.dll

+ CLSID : {1ee7337f-85ac-45e2-a23c-37c753209769}
- Name : Smartcard WinRT Provider
- Value : %SystemRoot%\system32\SmartcardCredentialProvider.dll

+ CLSID : {2135f72a-90b5-4ed3-a7f1-8bb705ac276a}
- Name : PicturePasswordLogonProvider
- Value : %SystemRoot%\system32\credprovslegacy.dll

+ CLSID : {25CBB996-92ED-457e-B28C-4774084BD562}
- Name : GenericProvider
- Value : %SystemRoot%\system32\credprovs.dll

+ CLSID : {27FBDB57-B613-4AF2-9D7E-4FA7A66C21AD}
- Name : TrustedSignal Credential Provider
- Value : %systemroot%\system32\TrustedSignalCredProv.dll

+ CLSID : {3dd6bec0-8193-4ffe-ae25-e08e39ea4063}
- Name : NPProvider
- Value : %SystemRoot%\system32\credprovs.dll

+ CLSID : {48B4E58D-2791-456C-9091-D524C6C706F2}
- Name : Secondary Authentication Factor Credential Provider
- Value : C:\Windows\System32\devicengccredprov.dll

+ CLSID : {600e7adb-da3e-41a4-9225-3c0399e88c0c}
- Name : CngCredUICredentialProvider
- Value : %systemroot%\system32\cngcredui.dll

+ CLSID : {60b78e88-ead8-445c-9cfd-0b87f74ea6cd}
- Name : PasswordProvider
- Value : %SystemRoot%\system32\credprovs.dll

+ CLSID : {8AF662BF-65A0-4D0A-A540-A338A999D36F}
- Name : FaceCredentialProvider
- Value : C:\Windows\System32\FaceCredentialProvider.dll

+ CLSID : {8FD7E19C-3BF7-489B-A72C-846AB3678C96}
- Name : Smartcard Credential Provider
- Value : %SystemRoot%\system32\SmartcardCredentialProvider.dll

+ CLSID : {94596c7e-3744-41ce-893e-bbf09122f76a}
- Name : Smartcard Pin Provider
- Value : %SystemRoot%\system32\SmartcardCredentialProvider.dll

+ CLSID : {BEC09223-B018-416D-A0AC-523971B639F5}
- Name : WinBio Credential Provider
- Value : %SystemRoot%\System32\BioCredProv.dll

+ CLSID : {C5D7540A-CD51-453B-B22B-05305BA03F07}
- Name : Cloud Experience Credential Provider
- Value : C:\Windows\System32\cxcredprov.dll

+ CLSID : {C885AA15-1764-4293-B82A-0586ADD46B35}
- Name : IrisCredentialProvider
- Value : C:\Windows\System32\FaceCredentialProvider.dll

+ CLSID : {cb82ea12-9f71-446d-89e1-8d0924e1256e}
- Name : PINLogonProvider
- Value : %SystemRoot%\system32\credprovslegacy.dll

+ CLSID : {D6886603-9D2F-4EB2-B667-1971041FA96B}
- Name : NGC Credential Provider
- Value : C:\Windows\System32\ngccredprov.dll

+ CLSID : {e74e57b0-6c6d-44d5-9cda-fb2df5ed7435}
- Name : CertCredProvider
- Value : %systemroot%\system32\certCredProvider.dll

+ CLSID : {f64945df-4fa9-4068-a2fb-61af319edd33}
- Name : RdpCredentialProvider
- Value : %windir%\system32\rdpcredentialprovider.dll

+ CLSID : {F8A0B131-5F68-486c-8040-7E8FC3C85BB6}
- Name : WLIDCredentialProvider
- Value : %SystemRoot%\system32\wlidcredprov.dll

+ CLSID : {F8A1793B-7873-4046-B2A7-1F318747F427}
- Name : FIDO Credential Provider
- Value : %systemroot%\system32\fidocredprov.dll


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Provider Filters
+ CLSID : {DDC0EED2-ADBE-40b6-A217-EDE16A79A0DE}
- Name : GenericFilter
- Value : %SystemRoot%\system32\credprovs.dll


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\PLAP Providers
+ CLSID : {5537E283-B1E7-4EF8-9C6E-7AB0AFE5056D}
- Name : RasProvider
- Value : %SystemRoot%\system32\rasplap.dll




70630 - Microsoft Windows AutoRuns Winsock Provider
-
Synopsis
Report Winsock providers extensions.
Description
A Winsock provider is a type of Layered Service Provider (LSP) that can be used to control protocols by inserting itself into the TCP/IP stack. This can commonly be used to help filter web traffic, enable QoS type services, or anything to hook network traffic controls.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries
- Name : @%SystemRoot%\System32\mswsock.dll,-60100
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60101
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60102
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60200
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60201
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60202
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : AF_UNIX
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-100
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-101
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-102
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-103
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : Hyper-V RAW
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : MSAFD L2CAP [Bluetooth]
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : MSAFD RfComm [Bluetooth]
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : vSockets DGRAM
- PackedCatalogItem : %windir%\system32\vsocklib.dll

- Name : vSockets STREAM
- PackedCatalogItem : %windir%\system32\vsocklib.dll


+ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries
- LibararyPath : %SystemRoot%\system32\napinsp.dll
- LibararyPath : %SystemRoot%\system32\pnrpnsp.dll
- LibararyPath : %SystemRoot%\system32\pnrpnsp.dll
- LibararyPath : %SystemRoot%\system32\wshbth.dll
- LibararyPath : %SystemRoot%\system32\NLAapi.dll
- LibararyPath : %SystemRoot%\System32\mswsock.dll
- LibararyPath : %SystemRoot%\System32\winrnr.dll


+ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64
- Name : @%SystemRoot%\System32\mswsock.dll,-60100
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60101
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60102
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60200
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60201
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60202
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : AF_UNIX
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-100
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-101
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-102
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-103
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : Hyper-V RAW
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : MSAFD L2CAP [Bluetooth]
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : MSAFD RfComm [Bluetooth]
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : vSockets DGRAM
- PackedCatalogItem : %windir%\system32\vsocklib.dll

- Name : vSockets STREAM
- PackedCatalogItem : %windir%\system32\vsocklib.dll


+ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64
- LibararyPath : %SystemRoot%\system32\napinsp.dll
- LibararyPath : %SystemRoot%\system32\pnrpnsp.dll
- LibararyPath : %SystemRoot%\system32\pnrpnsp.dll
- LibararyPath : %SystemRoot%\system32\wshbth.dll
- LibararyPath : %SystemRoot%\system32\NLAapi.dll
- LibararyPath : %SystemRoot%\System32\mswsock.dll
- LibararyPath : %SystemRoot%\System32\winrnr.dll

92371 - Microsoft Windows DNS Cache
-
Synopsis
Nessus was able to collect and report DNS cache information from the remote host.
Description
Nessus was able to collect details of the DNS cache from the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2025/12/15
Plugin Output

tcp/0

1.0.0.127.in-addr.arpa
cloud.uipath.com
cloud.uipath.com
dc1-file.ksn.kaspersky-labs.com
dc1-file.ksn.kaspersky-labs.com
dc1-pp.ksn.kaspersky-labs.com
dc1-pp.ksn.kaspersky-labs.com
dc1-st.ksn.kaspersky-labs.com
dc1-st.ksn.kaspersky-labs.com
dc1.ksn.kaspersky-labs.com
dc1.ksn.kaspersky-labs.com
download.uipath.com
download.uipath.com
ds.kaspersky.com
ds.kaspersky.com
gallery.uipath.com
gallery.uipath.com
insights.uipath.com
insights.uipath.com
licensing.uipath.com
licensing.uipath.com
telemetry.uipath.com
telemetry.uipath.com
uipath.com
uipath.com
www.cloud.uipath.com
www.cloud.uipath.com
www.download.uipath.com
www.download.uipath.com
www.gallery.uipath.com
www.gallery.uipath.com
www.insights.uipath.com
www.insights.uipath.com
www.licensing.uipath.com
www.licensing.uipath.com
www.myget.org
www.myget.org
www.nuget.org
www.nuget.org
www.telemetry.uipath.com
www.telemetry.uipath.com
www.uipath.com
www.uipath.com

DNS cache information attached.
92363 - Microsoft Windows Device Logs
-
Synopsis
Nessus was able to collect available device logs from the remote host.
Description
Nessus was able to collect available device logs from the remote Windows host and add them as attachments.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

Device logs attached.
92364 - Microsoft Windows Environment Variables
-
Synopsis
Nessus was able to collect and report environment variables from the remote host.
Description
Nessus was able to collect system and active account environment variables on the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0757
Plugin Information
Published: 2016/07/19, Modified: 2022/06/24
Plugin Output

tcp/0

Global Environment Variables :
msmpi_benchmarks : C:\Program Files\Microsoft MPI\Benchmarks\
processor_level : 6
comspec : %SystemRoot%\system32\cmd.exe
number_of_processors : 8
username : SYSTEM
os : Windows_NT
temp : %SystemRoot%\TEMP
processor_revision : cf02
path : C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Microsoft MPI\Bin\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;D:\Program Files\Microsoft SQL Server\Client SDK\ODBC\170\Tools\Binn\;D:\Program Files (x86)\Microsoft SQL Server\150\Tools\Binn\;D:\Program Files\Microsoft SQL Server\150\Tools\Binn\;D:\Program Files\Microsoft SQL Server\150\DTS\Binn\;D:\Program Files (x86)\Microsoft SQL Server\150\DTS\Binn\;C:\Program Files\Azure Data Studio\bin
tmp : %SystemRoot%\TEMP
msmpi_bin : C:\Program Files\Microsoft MPI\Bin\
processor_identifier : Intel64 Family 6 Model 207 Stepping 2, GenuineIntel
driverdata : C:\Windows\System32\Drivers\DriverData
pathext : .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
processor_architecture : AMD64
psmodulepath : %ProgramFiles%\WindowsPowerShell\Modules;%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules;D:\Program Files (x86)\Microsoft SQL Server\150\Tools\PowerShell\Modules\
windir : %SystemRoot%

Active User Environment Variables
- S-1-5-21-2193062927-1383316644-2198579232-1009
onedrive : C:\Users\tidua\OneDrive
temp : %USERPROFILE%\AppData\Local\Temp
path : %USERPROFILE%\AppData\Local\Microsoft\WindowsApps;
tmp : %USERPROFILE%\AppData\Local\Temp
- S-1-5-21-2193062927-1383316644-2198579232-1004
onedrive : C:\Users\Techrobot\OneDrive
temp : %USERPROFILE%\AppData\Local\Temp
path : %USERPROFILE%\AppData\Local\Microsoft\WindowsApps;
tmp : %USERPROFILE%\AppData\Local\Temp
uipath_user_service_path : C:\Users\Techrobot\AppData\Local\UiPath\app-21.4.4\net461\..\UiPath.Service.UserHost.exe
uipath_language : en
92365 - Microsoft Windows Hosts File
-
Synopsis
Nessus was able to collect the hosts file from the remote host.
Description
Nessus was able to collect the hosts file from the remote Windows host and report it as attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2020/01/27
Plugin Output

tcp/0

Windows hosts file attached.

MD5: ac173a8fa839040e0bce1a36ec09ab27
SHA-1: d2a943969a0ec43ab9d6f8ef5424e77c26388e3e
SHA-256: 685c1ca19cff48ffe52eb34b82582a5364baffe439432c89e325debad37acc7c
187318 - Microsoft Windows Installed
-
Synopsis
The remote host is running Microsoft Windows.
Description
The remote host is running Microsoft Windows.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/12/27, Modified: 2025/12/10
Plugin Output

tcp/0


OS Name : Microsoft Windows 10 22H2
Vendor : Microsoft
Product : Windows
Release : 10 22H2
Edition : Pro
Version : 10.0.19045.5965
Role : client
Kernel : Windows NT 10.0
Architecture : x64
CPE v2.2 : cpe:/o:microsoft:windows_10_22h2:10.0.19045.5965:-:~~pro~~x64~
CPE v2.3 : cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.5965:-:*:*:pro:*:x64:*
Type : local
Method : SMB
Confidence : 100

20811 - Microsoft Windows Installed Software Enumeration (credentialed check)
-
Synopsis
It is possible to enumerate installed software.
Description
This plugin lists software potentially installed on the remote host by crawling the registry entries in :

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall HKLM\SOFTWARE\Microsoft\Updates

Note that these entries do not necessarily mean the applications are actually installed on the remote host - they may have been left behind by uninstallers, or the associated files may have been manually removed.
Solution
Remove any applications that are not compliant with your organization's acceptable use and security policies.
Risk Factor
None
References
XREF IAVT:0001-T-0501
Plugin Information
Published: 2006/01/26, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


The following software are installed on the remote host :

7-Zip 19.00 (x64) [version 19.00]
Google Chrome [version 143.0.7499.193] [installed on 2026/01/09]
Kaspersky Security Center Network Agent [version 13.2.0.1511]
GDR 2130 for SQL Server 2019 (KB5046859) (64-bit) [version 15.0.2130.3] [installed on 2025/07/08]
Lucee [version 5.3.8.201] [installed on 2023/01/17]
Microsoft Edge [version 92.0.902.67] [installed on 2023/11/28]
Microsoft Edge Update [version 1.3.147.37]
Microsoft Edge WebView2 Runtime [version 119.0.2151.72] [installed on 2023/11/25]
Microsoft Help Viewer 2.3 [version 2.3.28107]
Microsoft SQL Server 2019 (64-bit)
Mozilla Firefox (x64 en-US) [version 134.0]
Mozilla Maintenance Service [version 134.0]
Notepad++ [version 6.9]
Microsoft Office Standard 2016 [version 16.0.4266.1001]
SecPod Saner [version 6.3.0.1]
TreeSize Free V4.4.2 [version 4.4.2] [installed on 2024/11/29]
WinRAR 5.90 (64-bit) [version 5.90.0]
wkhtmltopdf
Kaspersky Endpoint Security for Windows [version 11.15.8.493]
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.36.32532 [version 14.36.32532] [installed on 2025/03/11]
Microsoft SQL Server 2019 Setup (English) [version 15.0.2130.3] [installed on 2025/03/10]
SQL Server Management Studio for Reporting Services [version 15.0.18390.0] [installed on 2023/01/17]
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 [version 12.0.30501.0]
Microsoft ODBC Driver 17 for SQL Server [version 17.10.6.1] [installed on 2025/03/10]
SQL Server 2019 Common Files [version 15.0.2000.5] [installed on 2025/03/10]
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 [version 12.0.21005] [installed on 2023/01/17]
UiPath Studio [version 23.8.0.0] [installed on 2023/09/11]
Microsoft Update Health Tools [version 3.74.0.0] [installed on 2023/11/11]
SQL Server 2019 XEvent [version 15.0.2000.5] [installed on 2025/03/10]
Java 8 Update 161 (64-bit) [version 8.0.1610.12] [installed on 2023/01/18]
VMware Tools [version 12.3.5.22544099] [installed on 2025/03/11]
SQL Server 2019 SQL Diagnostics [version 15.0.2000.5] [installed on 2023/01/17]
Microsoft VSS Writer for SQL Server 2019 [version 15.0.2000.5] [installed on 2025/03/10]
Microsoft SQL Server 2019 T-SQL Language Service [version 15.0.2000.5] [installed on 2023/01/17]
SQL Server Management Studio [version 15.0.18390.0] [installed on 2023/01/17]
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.36.32532 [version 14.36.32532.0]
Integration Services [version 15.0.2000.168] [installed on 2023/01/17]
Java Auto Updater [version 2.8.161.12] [installed on 2023/01/18]
SSMS Post Install Tasks [version 15.0.18390.0] [installed on 2023/01/17]
Microsoft Analysis Services OLE DB Provider [version 15.0.2000.568] [installed on 2023/01/17]
Microsoft SQL Server 2019 RsFx Driver [version 15.0.2000.5] [installed on 2023/01/17]
Browser for SQL Server 2019 [version 15.0.2000.5] [installed on 2025/03/10]
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 [version 9.0.30729.6161] [installed on 2022/04/18]
SQL Server 2019 Database Engine Shared [version 15.0.2000.5] [installed on 2023/01/17]
SQL Server 2019 Shared Management Objects [version 15.0.2000.5] [installed on 2023/01/17]
Java SE Development Kit 8 Update 161 (64-bit) [version 8.0.1610.12] [installed on 2023/01/18]
Azure Data Studio [version 1.32.0] [installed on 2023/01/17]
Windows PC Health Check [version 3.6.2204.08001] [installed on 2023/09/14]
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.36.32532 [version 14.36.32532] [installed on 2025/03/11]
Microsoft OLE DB Driver for SQL Server [version 18.7.4.0] [installed on 2025/03/10]
SQL Server 2019 DMF [version 15.0.2000.5] [installed on 2023/01/17]
Kaspersky Endpoint Security for Windows [version 12.3.0.493] [installed on 2024/03/13]
Microsoft MPI (10.0.12498.5) [version 10.0.12498.5] [installed on 2023/01/17]
Microsoft Silverlight [version 5.1.50907.0] [installed on 2024/06/29]
SQL Server 2019 Shared Management Objects Extensions [version 15.0.2000.5] [installed on 2023/01/17]
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.36.32532 [version 14.36.32532.0]
Microsoft Access database engine 2010 (English) [version 14.0.4763.1000] [installed on 2025/03/08]
Security Update for Microsoft Office 2016 (KB5002635) 64-Bit Edition
Update for Microsoft Office 2016 (KB5002585) 64-Bit Edition
Update for Microsoft PowerPoint 2016 (KB5002632) 64-Bit Edition
Update for Microsoft Office 2016 (KB5002244) 64-Bit Edition
Security Update for Microsoft Office 2016 (KB5002588) 64-Bit Edition
Update for Microsoft Office 2016 (KB3213650) 64-Bit Edition
Update for Microsoft Office 2016 (KB4484145) 64-Bit Edition
Security Update for Microsoft Office 2016 (KB5002469) 64-Bit Edition
Update for Microsoft Office 2016 (KB3114524) 64-Bit Edition
Update for Microsoft Office 2016 (KB4011259) 64-Bit Edition
Update for Microsoft Office 2016 (KB2920717) 64-Bit Edition
Security Update for Microsoft Publisher 2016 (KB5002566) 64-Bit Edition
Definition Update for Microsoft Office 2016 (KB3115407) 64-Bit Edition
Security Update for Microsoft Office 2016 (KB4484103) 64-Bit Edition
Security Update for Microsoft Word 2016 (KB5002702) 64-Bit Edition
Security Update for Microsoft Office 2016 (KB5002575) 64-Bit Edition
Update for Microsoft Office 2016 (KB4022193) 64-Bit Edition
Security Update for Microsoft Office 2016 (KB4462148) 64-Bit Edition
Security Update for Microsoft Office 2016 (KB3085538) 64-Bit Edition
Security Update for Microsoft Office 2016 (KB4475581) 64-Bit Edition
Update for Microsoft Office 2016 (KB5002050) 64-Bit Edition
Security Update for Microsoft Office 2016 (KB5002700) 64-Bit Edition
Security Update for Microsoft Visio 2016 (KB5002634) 64-Bit Edition
Security Update for Microsoft Office 2016 (KB4484432) 64-Bit Edition
Update for Microsoft Office 2016 (KB4484104) 64-Bit Edition
Update for Microsoft Office 2016 (KB3115081) 64-Bit Edition
Security Update for Microsoft Office 2016 (KB3213551) 64-Bit Edition
Update for Microsoft Office 2016 (KB3118262) 64-Bit Edition
Update for Microsoft Office 2016 (KB5002251) 64-Bit Edition
Update for Microsoft Office 2016 (KB2920720) 64-Bit Edition
Security Update for Microsoft Excel 2016 (KB5002704) 64-Bit Edition
Security Update for Microsoft Project 2016 (KB5002652) 64-Bit Edition
Update for Microsoft Office 2016 (KB4011634) 64-Bit Edition
Update for Microsoft Office 2016 (KB3114903) 64-Bit Edition
Update for Microsoft Office 2016 (KB3118263) 64-Bit Edition
Security Update for Microsoft Office 2016 (KB3191869) 64-Bit Edition
Update for Microsoft Office 2016 (KB5002466) 64-Bit Edition
Update for Microsoft Office 2016 (KB4011621) 64-Bit Edition
Security Update for Microsoft Office 2016 (KB4475587) 64-Bit Edition
Update for Microsoft Office 2016 (KB3191929) 64-Bit Edition
Update for Microsoft Office 2016 (KB4011629) 64-Bit Edition
Update for Microsoft Office 2016 (KB2920724) 64-Bit Edition
Update for Skype for Business 2016 (KB5002567) 64-Bit Edition
Security Update for Microsoft Access 2016 (KB5002701) 64-Bit Edition
Update for Microsoft Office 2016 (KB4464587) 64-Bit Edition
Security Update for Microsoft Outlook 2016 (KB5002656) 64-Bit Edition
Security Update for Microsoft Office 2016 (KB5002669) 64-Bit Edition
Update for Microsoft Office 2016 (KB3118264) 64-Bit Edition
Update for Microsoft Office 2016 (KB4011035) 64-Bit Edition
Security Update for Microsoft OneNote 2016 (KB5002622) 64-Bit Edition
Update for Microsoft OneDrive for Business (KB4022219) 64-Bit Edition
Security Update for Microsoft Office 2016 (KB4022176) 64-Bit Edition
Update for Microsoft Office 2016 (KB4462117) 64-Bit Edition
Update for Microsoft Office 2016 (KB2920678) 64-Bit Edition
Update for Microsoft Visio Viewer 2016 (KB2920709) 64-Bit Edition
Security Update for Microsoft Office 2016 (KB5002179) 64-Bit Edition
Security Update for Microsoft Office 2016 (KB5002703) 64-Bit Edition
Update for Microsoft Office 2016 (KB4464538) 64-Bit Edition
Security Update for Microsoft Office 2016 (KB5002573) 64-Bit Edition
Update for Microsoft Office 2016 (KB4032254) 64-Bit Edition
Security Update for Microsoft Office 2016 (KB4011574) 64-Bit Edition
Microsoft Excel MUI (English) 2016 [version 16.0.4266.1001] [installed on 2025/04/12]
Microsoft PowerPoint MUI (English) 2016 [version 16.0.4266.1001] [installed on 2025/04/12]
Microsoft Publisher MUI (English) 2016 [version 16.0.4266.1001] [installed on 2025/04/12]
Microsoft Outlook MUI (English) 2016 [version 16.0.4266.1001] [installed on 2025/04/12]
Microsoft Word MUI (English) 2016 [version 16.0.4266.1001] [installed on 2025/04/12]
Microsoft Office Proofing Tools 2016 - English [version 16.0.4266.1001] [installed on 2025/04/12]
Outils de vérification linguistique 2016 de Microsoft Office - Français [version 16.0.4266.1001] [installed on 2025/04/12]
Herramientas de corrección de Microsoft Office 2016: español [version 16.0.4266.1001] [installed on 2025/04/12]
Microsoft Office Proofing (English) 2016 [version 16.0.4266.1001] [installed on 2025/04/12]
Microsoft Office Shared MUI (English) 2016 [version 16.0.4266.1001] [installed on 2025/04/12]
Microsoft OneNote MUI (English) 2016 [version 16.0.4266.1001] [installed on 2025/04/12]
Microsoft Groove MUI (English) 2016 [version 16.0.4266.1001] [installed on 2025/04/12]
Microsoft Office 32-bit Components 2016 [version 16.0.4266.1001] [installed on 2025/04/12]
Microsoft Office Shared 32-bit MUI (English) 2016 [version 16.0.4266.1001] [installed on 2025/04/12]
Microsoft Access database engine 2016 (English) [version 16.0.4519.1000] [installed on 2025/04/12]
Microsoft Office OSM MUI (English) 2016 [version 16.0.4266.1001] [installed on 2025/04/12]
Microsoft Office OSM UX MUI (English) 2016 [version 16.0.4266.1001] [installed on 2025/04/12]
Microsoft Office Shared Setup Metadata MUI (English) 2016 [version 16.0.4266.1001] [installed on 2025/04/12]
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 [version 12.0.21005] [installed on 2023/01/19]
Microsoft Visual Studio Tools for Applications 2017 x86 Hosting Support [version 15.0.27520] [installed on 2023/01/17]
SQL Server 2019 Connection Info [version 15.0.2000.5] [installed on 2023/01/17]
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 [version 9.0.30729.6161] [installed on 2022/04/18]
SQL Server Management Studio for Analysis Services [version 15.0.18390.0] [installed on 2023/01/17]
SQL Server 2019 Database Engine Services [version 15.0.2000.5] [installed on 2023/01/17]
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 [version 12.0.21005] [installed on 2023/01/19]
Visual Studio 2017 Isolated Shell for SSMS [version 15.0.28307.421] [installed on 2023/01/17]
Microsoft SQL Server 2012 Native Client [version 11.4.7515.2] [installed on 2025/03/10]
Microsoft Visual Studio Tools for Applications 2017 x64 Hosting Support [version 15.0.27520] [installed on 2023/01/17]
SQL Server 2019 sql_inst_mr [version 15.0.2000.5] [installed on 2023/01/17]
TightVNC [version 2.8.11.0] [installed on 2022/04/26]
SQL Server 2019 Advanced Analytics [version 15.0.2000.5] [installed on 2023/01/17]
SQL Server 2019 Full text search [version 15.0.2000.5] [installed on 2023/01/17]
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.36.32532 [version 14.36.32532] [installed on 2025/03/11]
SQL Server 2019 Batch Parser [version 15.0.2000.5] [installed on 2023/01/17]
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.36.32532 [version 14.36.32532] [installed on 2025/03/11]
Update for x64-based Windows Systems (KB5001716) [version 8.94.0.0] [installed on 2025/03/11]
SAP Crystal Reports runtime engine for .NET Framework 4 (32-bit) [version 13.0.2.469] [installed on 2024/04/29]
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 [version 12.0.21005] [installed on 2023/01/17]
Microsoft SQL Server Management Studio - 18.10 [version 15.0.18390.0]
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 [version 12.0.30501.0]
Microsoft Visual Studio Tools for Applications 2017 [version 15.0.27520]
178102 - Microsoft Windows Installed Software Version Enumeration
-
Synopsis
Enumerates installed software versions.
Description
This plugin enumerates the installed software version by interrogating information obtained from various registry entries and files on disk. This plugin provides a best guess at the software version and a confidence level for that version.

Note that the versions detected here do not necessarily indicate the actual installed version nor do they necessarily mean that the application is actually installed on the remote host. In some cases there may be artifacts left behind by uninstallers on the system.
Solution
Remove any applications that are not compliant with your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2023/07/10, Modified: 2024/07/15
Plugin Output

tcp/445/cifs


The following software information is available on the remote host :

- Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.36.32532
Best Confidence Version : 14.36.32532.0
Version Confidence Level : 3
All Possible Versions : 14.36.32532.0
Other Version Data
[DisplayName] :
Raw Value : Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.36.32532
[UninstallString] :
Raw Value : "C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\VC_redist.x64.exe" /uninstall
Parsed File Path : C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\VC_redist.x64.exe
Parsed File Version : 14.36.32532.0
[DisplayVersion] :
Raw Value : 14.36.32532.0
[DisplayIcon] :
Raw Value : C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\VC_redist.x64.exe,0
Parsed File Path : C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\VC_redist.x64.exe
Parsed File Version : 14.36.32532.0

- Update for Microsoft Office 2016 (KB4464587) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Microsoft Office 2016 (KB4464587) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00C1-0000-1000-0000000FF1CE}" "{AD26BCAC-856E-4AE9-B86A-32D08FB5F60E}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Microsoft Office Proofing Tools 2016 - English
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 2
All Possible Versions : 16.0.4266.1001
Other Version Data
[InstallDate] :
Raw Value : 2025/04/12
[InstallLocation] :
Raw Value : C:\Program Files\Microsoft Office\
[UninstallString] :
Raw Value : MsiExec.exe /X{90160000-001F-0409-1000-0000000FF1CE}
[VersionMinor] :
Raw Value : 0
[Version] :
Raw Value : 268439722
[VersionMajor] :
Raw Value : 16
[Publisher] :
Raw Value : Microsoft Corporation
[DisplayVersion] :
Raw Value : 16.0.4266.1001
[DisplayName] :
Raw Value : Microsoft Office Proofing Tools 2016 - English

- Microsoft Office 32-bit Components 2016
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 2
All Possible Versions : 16.0.4266.1001
Other Version Data
[InstallDate] :
Raw Value : 2025/04/12
[InstallLocation] :
Raw Value : C:\Program Files\Microsoft Office\
[UninstallString] :
Raw Value : MsiExec.exe /X{90160000-00C1-0000-1000-0000000FF1CE}
[VersionMinor] :
Raw Value : 0
[Version] :
Raw Value : 268439722
[VersionMajor] :
Raw Value : 16
[Publisher] :
Raw Value : Microsoft Corporation
[DisplayVersion] :
Raw Value : 16.0.4266.1001
[DisplayName] :
Raw Value : Microsoft Office 32-bit Components 2016

- Update for Microsoft Office 2016 (KB3114903) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Microsoft Office 2016 (KB3114903) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{92281B72-2A8C-40A4-BD15-58CCDF7DEDB1}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Security Update for Microsoft Office 2016 (KB5002703) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Security Update for Microsoft Office 2016 (KB5002703) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{F43D48AE-3C81-4C25-931B-3EF3FBD14BA6}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Security Update for Microsoft Office 2016 (KB3213551) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Security Update for Microsoft Office 2016 (KB3213551) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-006E-0409-1000-0000000FF1CE}" "{7AFED019-B612-489B-B369-2920C6B5A96D}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Update for Microsoft Office 2016 (KB4484145) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Microsoft Office 2016 (KB4484145) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{21CF7F22-5D29-458B-BFF0-4D2CED6475AE}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Microsoft Visual Studio Tools for Applications 2017 x86 Hosting Support
Best Confidence Version : 15.0.27520
Version Confidence Level : 2
All Possible Versions : 15.0.27520
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251685760
[DisplayName] :
Raw Value : Microsoft Visual Studio Tools for Applications 2017 x86 Hosting Support
[UninstallString] :
Raw Value : MsiExec.exe /X{9594C97E-6A20-38B3-81BB-2778C4780BE1}
[InstallDate] :
Raw Value : 2023/01/17
[DisplayVersion] :
Raw Value : 15.0.27520
[VersionMinor] :
Raw Value : 0

- Microsoft Edge
Best Confidence Version : 92.0.902.67
Version Confidence Level : 2
All Possible Versions : 92.0.902.67
Other Version Data
[InstallDate] :
Raw Value : 2023/11/28
[DisplayIcon] :
Raw Value : C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe,0
Parsed File Path : C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
[InstallLocation] :
Raw Value : C:\Program Files (x86)\Microsoft\Edge\Application
[UninstallString] :
Raw Value : "C:\Program Files (x86)\Microsoft\Edge\Application\92.0.902.67\Installer\setup.exe" --uninstall --msedge --system-level --verbose-logging
Parsed File Path : C:\Program Files (x86)\Microsoft\Edge\Application\92.0.902.67\Installer\setup.exe
[VersionMinor] :
Raw Value : 67
[Version] :
Raw Value : 92.0.902.67
[VersionMajor] :
Raw Value : 902
[DisplayVersion] :
Raw Value : 92.0.902.67
[DisplayName] :
Raw Value : Microsoft Edge

- Java 8 Update 161 (64-bit)
Best Confidence Version : 8.0.1610.12
Version Confidence Level : 2
All Possible Versions : 8.0.1610.12
Other Version Data
[InstallDate] :
Raw Value : 2023/01/18
[InstallLocation] :
Raw Value : C:\Program Files\Java\jre1.8.0_161\
[UninstallString] :
Raw Value : MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F64180161F0}
[VersionMinor] :
Raw Value : 0
[Version] :
Raw Value : 134219338
[VersionMajor] :
Raw Value : 8
[Publisher] :
Raw Value : Oracle Corporation
[DisplayVersion] :
Raw Value : 8.0.1610.12
[DisplayName] :
Raw Value : Java 8 Update 161 (64-bit)

- Update for Microsoft Office 2016 (KB4011621) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Microsoft Office 2016 (KB4011621) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{9B7089F6-2B38-443A-B007-5DFAF6872D85}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Microsoft ODBC Driver 17 for SQL Server
Best Confidence Version : 17.10.6.1
Version Confidence Level : 2
All Possible Versions : 17.10.6.1
Other Version Data
[VersionMajor] :
Raw Value : 17
[Version] :
Raw Value : 285868038
[DisplayName] :
Raw Value : Microsoft ODBC Driver 17 for SQL Server
[UninstallString] :
Raw Value : MsiExec.exe /I{0E0F96AC-80DE-4400-A40C-429D63293651}
[InstallDate] :
Raw Value : 2025/03/10
[DisplayVersion] :
Raw Value : 17.10.6.1
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 10

- SQL Server 2019 SQL Diagnostics
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 SQL Diagnostics
[UninstallString] :
Raw Value : MsiExec.exe /I{28ED6838-D8E5-454C-A813-12C5EB447CAB}
[InstallDate] :
Raw Value : 2023/01/17
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501
Best Confidence Version : 12.0.30501.0
Version Confidence Level : 3
All Possible Versions : 12.0.30501.0
Other Version Data
[DisplayName] :
Raw Value : Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501
[UninstallString] :
Raw Value : "C:\ProgramData\Package Cache\{050d4fc8-5d48-4b8f-8972-47c82c46020f}\vcredist_x64.exe" /uninstall
Parsed File Path : C:\ProgramData\Package Cache\{050d4fc8-5d48-4b8f-8972-47c82c46020f}\vcredist_x64.exe
Parsed File Version : 12.0.30501.0
[DisplayVersion] :
Raw Value : 12.0.30501.0
[DisplayIcon] :
Raw Value : C:\ProgramData\Package Cache\{050d4fc8-5d48-4b8f-8972-47c82c46020f}\vcredist_x64.exe,0
Parsed File Path : C:\ProgramData\Package Cache\{050d4fc8-5d48-4b8f-8972-47c82c46020f}\vcredist_x64.exe
Parsed File Version : 12.0.30501.0

- Update for Microsoft Office 2016 (KB4484104) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Microsoft Office 2016 (KB4484104) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{7157818F-C6EA-4070-AE3F-212DF98C9A83}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Security Update for Microsoft Office 2016 (KB5002700) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Security Update for Microsoft Office 2016 (KB5002700) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{64499CCB-747B-4284-B47B-689A64E34E9D}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Security Update for Microsoft Office 2016 (KB4475587) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Security Update for Microsoft Office 2016 (KB4475587) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{9CB39928-B629-4CE1-BAB7-2D6F397916B4}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Best Confidence Version : 9.0.30729.6161
Version Confidence Level : 2
All Possible Versions : 9.0.30729.6161
Other Version Data
[VersionMajor] :
Raw Value : 9
[Version] :
Raw Value : 151025673
[DisplayName] :
Raw Value : Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
[UninstallString] :
Raw Value : MsiExec.exe /X{9BE518E6-ECC6-35A9-88E4-87755C07200F}
[InstallDate] :
Raw Value : 2022/04/18
[DisplayVersion] :
Raw Value : 9.0.30729.6161
[VersionMinor] :
Raw Value : 0

- Update for Microsoft Office 2016 (KB4011629) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Microsoft Office 2016 (KB4011629) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{A8ABD88B-9B75-4A34-A33B-D50E6ABD46A3}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Notepad++

Version Confidence Level : 3
All Possible Versions : , 6.9, 6.9.0.0
Other Version Data
[VersionMajor] :
Raw Value : 6
[DisplayName] :
Raw Value : Notepad++
[UninstallString] :
Raw Value : C:\Program Files (x86)\Notepad++\uninstall.exe
Parsed File Path : C:\Program Files (x86)\Notepad++\uninstall.exe

[DisplayVersion] :
Raw Value : 6.9
[VersionMinor] :
Raw Value : 9
[DisplayIcon] :
Raw Value : C:\Program Files (x86)\Notepad++\notepad++.exe
Parsed File Path : C:\Program Files (x86)\Notepad++\notepad++.exe
Parsed File Version : 6.9.0.0

- Microsoft Outlook MUI (English) 2016
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 2
All Possible Versions : 16.0.4266.1001
Other Version Data
[InstallDate] :
Raw Value : 2025/04/12
[InstallLocation] :
Raw Value : C:\Program Files\Microsoft Office\
[UninstallString] :
Raw Value : MsiExec.exe /X{90160000-001A-0409-1000-0000000FF1CE}
[VersionMinor] :
Raw Value : 0
[Version] :
Raw Value : 268439722
[VersionMajor] :
Raw Value : 16
[Publisher] :
Raw Value : Microsoft Corporation
[DisplayVersion] :
Raw Value : 16.0.4266.1001
[DisplayName] :
Raw Value : Microsoft Outlook MUI (English) 2016

- TreeSize Free V4.4.2
Best Confidence Version : 51.1052.0.0
Version Confidence Level : 3
All Possible Versions : 51.1052.0.0, 4.4.2, 4.4.2.514
Other Version Data
[VersionMajor] :
Raw Value : 4
[InstallLocation] :
Raw Value : C:\Program Files (x86)\JAM Software\TreeSize Free\
[DisplayName] :
Raw Value : TreeSize Free V4.4.2
[UninstallString] :
Raw Value : "C:\Program Files (x86)\JAM Software\TreeSize Free\unins000.exe"
Parsed File Path : C:\Program Files (x86)\JAM Software\TreeSize Free\unins000.exe
Parsed File Version : 51.1052.0.0
[InstallDate] :
Raw Value : 2024/11/29
[DisplayVersion] :
Raw Value : 4.4.2
[VersionMinor] :
Raw Value : 4
[DisplayIcon] :
Raw Value : C:\Program Files (x86)\JAM Software\TreeSize Free\TreeSizeFree.exe
Parsed File Path : C:\Program Files (x86)\JAM Software\TreeSize Free\TreeSizeFree.exe
Parsed File Version : 4.4.2.514

- Microsoft Office OSM UX MUI (English) 2016
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 2
All Possible Versions : 16.0.4266.1001
Other Version Data
[InstallDate] :
Raw Value : 2025/04/12
[InstallLocation] :
Raw Value : C:\Program Files\Microsoft Office\
[UninstallString] :
Raw Value : MsiExec.exe /X{90160000-00E2-0409-1000-0000000FF1CE}
[VersionMinor] :
Raw Value : 0
[Version] :
Raw Value : 268439722
[VersionMajor] :
Raw Value : 16
[Publisher] :
Raw Value : Microsoft Corporation
[DisplayVersion] :
Raw Value : 16.0.4266.1001
[DisplayName] :
Raw Value : Microsoft Office OSM UX MUI (English) 2016

- Definition Update for Microsoft Office 2016 (KB3115407) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Definition Update for Microsoft Office 2016 (KB3115407) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{3DBF9257-2612-4385-BCE3-E9D4C41CC8CB}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- SQL Server 2019 XEvent
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 XEvent
[UninstallString] :
Raw Value : MsiExec.exe /I{228C3DC2-695E-4FC7-87E4-6A9CE905DA9B}
[InstallDate] :
Raw Value : 2023/01/17
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Outils de vérification linguistique 2016 de Microsoft Office - Français
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 2
All Possible Versions : 16.0.4266.1001
Other Version Data
[InstallDate] :
Raw Value : 2025/04/12
[InstallLocation] :
Raw Value : C:\Program Files\Microsoft Office\
[UninstallString] :
Raw Value : MsiExec.exe /X{90160000-001F-040C-1000-0000000FF1CE}
[VersionMinor] :
Raw Value : 0
[Version] :
Raw Value : 268439722
[VersionMajor] :
Raw Value : 16
[Publisher] :
Raw Value : Microsoft Corporation
[DisplayVersion] :
Raw Value : 16.0.4266.1001
[DisplayName] :
Raw Value : Outils de vérification linguistique 2016 de Microsoft Office - Français

- Update for Microsoft Office 2016 (KB5002244) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Microsoft Office 2016 (KB5002244) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{12433ADA-1793-45D6-B5E3-58C3A490C101}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Update for Microsoft Office 2016 (KB5002585) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Microsoft Office 2016 (KB5002585) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{045F9C15-C717-4BA4-B3EB-74CB3916021E}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Update for Microsoft Office 2016 (KB4011634) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Microsoft Office 2016 (KB4011634) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{8F860F8B-E4DC-4F1E-90EB-0EA6779C6367}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Security Update for Microsoft Word 2016 (KB5002702) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Security Update for Microsoft Word 2016 (KB5002702) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-001B-0409-1000-0000000FF1CE}" "{4B7C0765-56B0-4EF3-A1B5-BEA16E307D2E}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Security Update for Microsoft Office 2016 (KB4022176) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Security Update for Microsoft Office 2016 (KB4022176) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-006E-0409-1000-0000000FF1CE}" "{C48E4AFE-6590-49B5-B830-D0DEC86212E5}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- WinRAR 5.90 (64-bit)
Best Confidence Version : 5.90.0.0
Version Confidence Level : 3
All Possible Versions : 5.90.0.0, 5.90.0
Other Version Data
[VersionMajor] :
Raw Value : 5
[InstallLocation] :
Raw Value : C:\Program Files\WinRAR\
[DisplayName] :
Raw Value : WinRAR 5.90 (64-bit)
[UninstallString] :
Raw Value : C:\Program Files\WinRAR\uninstall.exe
Parsed File Path : C:\Program Files\WinRAR\uninstall.exe
Parsed File Version : 5.90.0.0
[DisplayVersion] :
Raw Value : 5.90.0
[Publisher] :
Raw Value : win.rar GmbH
[VersionMinor] :
Raw Value : 90
[DisplayIcon] :
Raw Value : C:\Program Files\WinRAR\WinRAR.exe
Parsed File Path : C:\Program Files\WinRAR\WinRAR.exe
Parsed File Version : 5.90.0.0

- Security Update for Microsoft Excel 2016 (KB5002704) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Security Update for Microsoft Excel 2016 (KB5002704) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0016-0409-1000-0000000FF1CE}" "{87B7810A-906B-402E-B62E-AACC4018E4E3}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Update for Microsoft Visio Viewer 2016 (KB2920709) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Microsoft Visio Viewer 2016 (KB2920709) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{E2481EA3-9B05-44DA-AFE0-FA07BCA70824}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Security Update for Microsoft Publisher 2016 (KB5002566) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Security Update for Microsoft Publisher 2016 (KB5002566) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{3B394307-FBFC-40FF-81C7-5D87535100D8}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Microsoft Office Standard 2016
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 2
All Possible Versions : 16.0.4266.1001
Other Version Data
[InstallDate] :
Raw Value : 2025/04/12
[DisplayIcon] :
Raw Value : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Office Setup Controller\OSETUP.DLL,1
[InstallLocation] :
Raw Value : C:\Program Files\Microsoft Office\
[UninstallString] :
Raw Value : MsiExec.exe /X{90160000-0012-0000-1000-0000000FF1CE}
[VersionMinor] :
Raw Value : 0
[VersionMajor] :
Raw Value : 16
[Version] :
Raw Value : 268439722
[Publisher] :
Raw Value : Microsoft Corporation
[DisplayVersion] :
Raw Value : 16.0.4266.1001
[DisplayName] :
Raw Value : Microsoft Office Standard 2016

- Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Best Confidence Version : 9.0.30729.6161
Version Confidence Level : 2
All Possible Versions : 9.0.30729.6161
Other Version Data
[VersionMajor] :
Raw Value : 9
[Version] :
Raw Value : 151025673
[DisplayName] :
Raw Value : Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
[UninstallString] :
Raw Value : MsiExec.exe /X{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}
[InstallDate] :
Raw Value : 2022/04/18
[DisplayVersion] :
Raw Value : 9.0.30729.6161
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- SSMS Post Install Tasks
Best Confidence Version : 15.0.18390.0
Version Confidence Level : 2
All Possible Versions : 15.0.18390.0
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251676630
[DisplayName] :
Raw Value : SSMS Post Install Tasks
[UninstallString] :
Raw Value : MsiExec.exe /I{4CB8C759-75FE-492C-8CEB-EEB9D07E2E8D}
[InstallDate] :
Raw Value : 2023/01/17
[DisplayVersion] :
Raw Value : 15.0.18390.0
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Update for Microsoft Office 2016 (KB2920724) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Microsoft Office 2016 (KB2920724) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{AA7A282E-E962-4C45-9A74-16C49FD88FF1}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- SQL Server 2019 Common Files
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Common Files
[UninstallString] :
Raw Value : MsiExec.exe /I{0FB552DD-543E-48E7-A6F4-2F8D82723C6A}
[InstallDate] :
Raw Value : 2025/03/10
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft Visual C++ 2022 X86 Additional Runtime - 14.36.32532
Best Confidence Version : 14.36.32532
Version Confidence Level : 2
All Possible Versions : 14.36.32532
Other Version Data
[VersionMajor] :
Raw Value : 14
[Version] :
Raw Value : 237272852
[DisplayName] :
Raw Value : Microsoft Visual C++ 2022 X86 Additional Runtime - 14.36.32532
[UninstallString] :
Raw Value : MsiExec.exe /I{C2C59CAB-8766-4ABD-A8EF-1151A36C41E5}
[InstallDate] :
Raw Value : 2025/03/11
[DisplayVersion] :
Raw Value : 14.36.32532
[VersionMinor] :
Raw Value : 36

- Integration Services
Best Confidence Version : 15.0.2000.168
Version Confidence Level : 2
All Possible Versions : 15.0.2000.168
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : Integration Services
[UninstallString] :
Raw Value : MsiExec.exe /I{4938A647-7EA4-4496-A843-5E338B91C07E}
[InstallDate] :
Raw Value : 2023/01/17
[DisplayVersion] :
Raw Value : 15.0.2000.168
[VersionMinor] :
Raw Value : 0

- Microsoft Publisher MUI (English) 2016
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 2
All Possible Versions : 16.0.4266.1001
Other Version Data
[InstallDate] :
Raw Value : 2025/04/12
[InstallLocation] :
Raw Value : C:\Program Files\Microsoft Office\
[UninstallString] :
Raw Value : MsiExec.exe /X{90160000-0019-0409-1000-0000000FF1CE}
[VersionMinor] :
Raw Value : 0
[Version] :
Raw Value : 268439722
[VersionMajor] :
Raw Value : 16
[Publisher] :
Raw Value : Microsoft Corporation
[DisplayVersion] :
Raw Value : 16.0.4266.1001
[DisplayName] :
Raw Value : Microsoft Publisher MUI (English) 2016

- Security Update for Microsoft Outlook 2016 (KB5002656) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Security Update for Microsoft Outlook 2016 (KB5002656) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-001A-0409-1000-0000000FF1CE}" "{ADF58D96-F3B6-46A9-BDDB-1AE470E4DFD2}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Security Update for Microsoft Office 2016 (KB3085538) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Security Update for Microsoft Office 2016 (KB3085538) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{5A84393A-E440-48A1-BB99-AD1244AC0C35}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Microsoft OLE DB Driver for SQL Server
Best Confidence Version : 18.7.4.0
Version Confidence Level : 2
All Possible Versions : 18.7.4.0
Other Version Data
[VersionMajor] :
Raw Value : 18
[Version] :
Raw Value : 302448644
[DisplayName] :
Raw Value : Microsoft OLE DB Driver for SQL Server
[UninstallString] :
Raw Value : MsiExec.exe /I{76EB75D2-CCF6-41A9-90B6-922DE9146276}
[InstallDate] :
Raw Value : 2025/03/10
[DisplayVersion] :
Raw Value : 18.7.4.0
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 7

- SQL Server 2019 sql_inst_mr
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 sql_inst_mr
[UninstallString] :
Raw Value : MsiExec.exe /I{B0523C0B-B56B-4C63-9B00-5A91EFF8F948}
[InstallDate] :
Raw Value : 2023/01/17
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Java Auto Updater
Best Confidence Version : 2.8.161.12
Version Confidence Level : 2
All Possible Versions : 52.7.34945, 2.8.161.12
Other Version Data
[VersionMajor] :
Raw Value : 2
[Version] :
Raw Value : 34078881
Parsed Version : 52.7.34945
[DisplayName] :
Raw Value : Java Auto Updater
[InstallDate] :
Raw Value : 2023/01/18
[DisplayVersion] :
Raw Value : 2.8.161.12
[VersionMinor] :
Raw Value : 8

- Update for Microsoft Office 2016 (KB2920717) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Microsoft Office 2016 (KB2920717) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{39BB0471-6969-4C29-B8BC-2AD561BEC25E}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Visual Studio 2017 Isolated Shell for SSMS
Best Confidence Version : 15.0.28307.421
Version Confidence Level : 2
All Possible Versions : 15.0.28307.421
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251686547
[DisplayName] :
Raw Value : Visual Studio 2017 Isolated Shell for SSMS
[UninstallString] :
Raw Value : MsiExec.exe /I{AAA9F15B-AF45-4562-9991-93A848D3A902}
[InstallDate] :
Raw Value : 2023/01/17
[DisplayVersion] :
Raw Value : 15.0.28307.421
[VersionMinor] :
Raw Value : 0

- Windows PC Health Check
Best Confidence Version : 3.6.2204.08001
Version Confidence Level : 2
All Possible Versions : 80.114.28776, 3.6.2204.08001
Other Version Data
[VersionMajor] :
Raw Value : 3
[Version] :
Raw Value : 50727068
Parsed Version : 80.114.28776
[DisplayName] :
Raw Value : Windows PC Health Check
[UninstallString] :
Raw Value : MsiExec.exe /X{6798C408-2636-448C-8AC6-F4E341102D27}
[InstallDate] :
Raw Value : 2023/09/14
[DisplayVersion] :
Raw Value : 3.6.2204.08001
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 6

- Update for Microsoft PowerPoint 2016 (KB5002632) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Microsoft PowerPoint 2016 (KB5002632) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{10929B15-1EF7-4828-A19D-85D36B428AB6}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Microsoft Access database engine 2016 (English)
Best Confidence Version : 16.0.4519.1000
Version Confidence Level : 2
All Possible Versions : 16.0.4519.1000
Other Version Data
[VersionMajor] :
Raw Value : 16
[Version] :
Raw Value : 268439975
[DisplayName] :
Raw Value : Microsoft Access database engine 2016 (English)
[UninstallString] :
Raw Value : MsiExec.exe /I{90160000-00D1-0409-1000-0000000FF1CE}
[InstallDate] :
Raw Value : 2025/04/12
[DisplayVersion] :
Raw Value : 16.0.4519.1000
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Security Update for Microsoft Office 2016 (KB5002179) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Security Update for Microsoft Office 2016 (KB5002179) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{EDF05809-6D10-4578-ABF7-006B449A3232}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Update for Microsoft Office 2016 (KB2920678) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Microsoft Office 2016 (KB2920678) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{D6AE0D54-13A7-4B0D-A862-8AEF7D4796A6}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- wkhtmltox 0.12.2.1
Best Confidence Version :
Version Confidence Level :
All Possible Versions :
Other Version Data
[DisplayName] :
Raw Value : wkhtmltox 0.12.2.1
[UninstallString] :
Raw Value : "D:\Techexcel\Lucee\tomcat\webapps\ROOT\wkhtmltopdf\uninstall.exe"
Parsed File Path : D:\Techexcel\Lucee\tomcat\webapps\ROOT\wkhtmltopdf\uninstall.exe

- SQL Server 2019 Advanced Analytics
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Advanced Analytics
[UninstallString] :
Raw Value : MsiExec.exe /I{BD408334-78B9-4024-A8B5-53184C2E8CB3}
[InstallDate] :
Raw Value : 2023/01/17
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- SQL Server 2019 Shared Management Objects Extensions
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Shared Management Objects Extensions
[UninstallString] :
Raw Value : MsiExec.exe /I{8DDAEBCA-4267-4E16-9FE0-D87F21D36891}
[InstallDate] :
Raw Value : 2023/01/17
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft Analysis Services OLE DB Provider
Best Confidence Version : 15.0.2000.568
Version Confidence Level : 2
All Possible Versions : 15.0.2000.568
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : Microsoft Analysis Services OLE DB Provider
[UninstallString] :
Raw Value : MsiExec.exe /I{9786E83E-B71A-4526-B58F-64F35C7E2CFE}
[InstallDate] :
Raw Value : 2023/01/17
[DisplayVersion] :
Raw Value : 15.0.2000.568
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- 7-Zip 19.00 (x64)
Best Confidence Version : 19.0.0.0
Version Confidence Level : 3
All Possible Versions : 19.0.0.0, 19.00
Other Version Data
[VersionMajor] :
Raw Value : 19
[InstallLocation] :
Raw Value : C:\Program Files\7-Zip\
[DisplayName] :
Raw Value : 7-Zip 19.00 (x64)
[UninstallString] :
Raw Value : C:\Program Files\7-Zip\Uninstall.exe
Parsed File Path : C:\Program Files\7-Zip\Uninstall.exe
Parsed File Version : 19.0.0.0
[DisplayVersion] :
Raw Value : 19.00
[Publisher] :
Raw Value : Igor Pavlov
[VersionMinor] :
Raw Value : 0
[DisplayIcon] :
Raw Value : C:\Program Files\7-Zip\7zFM.exe
Parsed File Path : C:\Program Files\7-Zip\7zFM.exe
Parsed File Version : 19.0.0.0

- Update for Microsoft Office 2016 (KB3115081) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Microsoft Office 2016 (KB3115081) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{78D7B4DE-619F-4312-9707-DF354A48D110}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Security Update for Microsoft Office 2016 (KB5002588) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Security Update for Microsoft Office 2016 (KB5002588) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{1340D09E-2B5D-4829-BBC9-42559CB6CBA2}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- SQL Server 2019 Database Engine Shared
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Database Engine Shared
[UninstallString] :
Raw Value : MsiExec.exe /I{DE5B7937-D5B5-4157-BC30-BB87F021CFF0}
[InstallDate] :
Raw Value : 2025/03/10
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- SAP Crystal Reports runtime engine for .NET Framework 4 (32-bit)
Best Confidence Version : 13.0.2.469
Version Confidence Level : 2
All Possible Versions : 13.0.2.469
Other Version Data
[VersionMajor] :
Raw Value : 13
[Version] :
Raw Value : 218103810
[DisplayName] :
Raw Value : SAP Crystal Reports runtime engine for .NET Framework 4 (32-bit)
[UninstallString] :
Raw Value : MsiExec.exe /I{F4404924-FF02-4515-9458-5C6F7E7E2C22}
[InstallDate] :
Raw Value : 2024/04/29
[DisplayVersion] :
Raw Value : 13.0.2.469
[VersionMinor] :
Raw Value : 0

- Update for Microsoft Office 2016 (KB4464538) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Microsoft Office 2016 (KB4464538) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{FAA26414-1C5D-494E-934A-54BC84176EAB}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Microsoft SQL Server 2019 RsFx Driver
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : Microsoft SQL Server 2019 RsFx Driver
[UninstallString] :
Raw Value : MsiExec.exe /I{5825CDC4-4E99-4CF9-91FE-DB60C0E2F5EA}
[InstallDate] :
Raw Value : 2023/01/17
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft Edge WebView2 Runtime
Best Confidence Version : 119.0.2151.72
Version Confidence Level : 2
All Possible Versions : 119.0.2151.72
Other Version Data
[InstallDate] :
Raw Value : 2023/11/25
[DisplayIcon] :
Raw Value : C:\Program Files (x86)\Microsoft\EdgeWebView\Application\119.0.2151.72\msedgewebview2.exe,0
Parsed File Path : C:\Program Files (x86)\Microsoft\EdgeWebView\Application\119.0.2151.72\msedgewebview2.exe
[InstallLocation] :
Raw Value : C:\Program Files (x86)\Microsoft\EdgeWebView\Application
[UninstallString] :
Raw Value : "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\119.0.2151.72\Installer\setup.exe" --uninstall --msedgewebview --system-level --verbose-logging
Parsed File Path : C:\Program Files (x86)\Microsoft\EdgeWebView\Application\119.0.2151.72\Installer\setup.exe
[VersionMinor] :
Raw Value : 72
[Version] :
Raw Value : 119.0.2151.72
[VersionMajor] :
Raw Value : 2151
[DisplayVersion] :
Raw Value : 119.0.2151.72
[DisplayName] :
Raw Value : Microsoft Edge WebView2 Runtime

- Update for Microsoft Office 2016 (KB4022193) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Microsoft Office 2016 (KB4022193) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{5246AFBE-4C9E-45C4-8ABB-544458942F3E}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Mozilla Firefox (x64 en-US)
Best Confidence Version : 1.0.0.0
Version Confidence Level : 3
All Possible Versions : 1.0.0.0, 134.0, 134.0.0.3375
Other Version Data
[InstallLocation] :
Raw Value : C:\Program Files\Mozilla Firefox
[DisplayName] :
Raw Value : Mozilla Firefox (x64 en-US)
[UninstallString] :
Raw Value : "C:\Program Files\Mozilla Firefox\uninstall\helper.exe"
Parsed File Path : C:\Program Files\Mozilla Firefox\uninstall\helper.exe
Parsed File Version : 1.0.0.0
[DisplayVersion] :
Raw Value : 134.0
[Publisher] :
Raw Value : Mozilla
[DisplayIcon] :
Raw Value : C:\Program Files\Mozilla Firefox\firefox.exe,0
Parsed File Path : C:\Program Files\Mozilla Firefox\firefox.exe
Parsed File Version : 134.0.0.3375

- Microsoft Visual Studio Tools for Applications 2017
Best Confidence Version : 15.0.27520.0
Version Confidence Level : 3
All Possible Versions : 15.0.27520.0, 15.0.27520
Other Version Data
[DisplayName] :
Raw Value : Microsoft Visual Studio Tools for Applications 2017
[UninstallString] :
Raw Value : "C:\ProgramData\Package Cache\{f895a2f1-ae3f-4212-8af1-7fa1f8c212ea}\vsta_setup.exe" /uninstall
Parsed File Path : C:\ProgramData\Package Cache\{f895a2f1-ae3f-4212-8af1-7fa1f8c212ea}\vsta_setup.exe
Parsed File Version : 15.0.27520.0
[DisplayVersion] :
Raw Value : 15.0.27520
[DisplayIcon] :
Raw Value : C:\ProgramData\Package Cache\{f895a2f1-ae3f-4212-8af1-7fa1f8c212ea}\vsta_setup.exe,0
Parsed File Path : C:\ProgramData\Package Cache\{f895a2f1-ae3f-4212-8af1-7fa1f8c212ea}\vsta_setup.exe
Parsed File Version : 15.0.27520.0

- Security Update for Microsoft Office 2016 (KB4484103) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Security Update for Microsoft Office 2016 (KB4484103) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{3F3A5408-670D-47BC-A868-D0FA4652AC3E}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Microsoft Groove MUI (English) 2016
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 2
All Possible Versions : 16.0.4266.1001
Other Version Data
[InstallDate] :
Raw Value : 2025/04/12
[InstallLocation] :
Raw Value : C:\Program Files\Microsoft Office\
[UninstallString] :
Raw Value : MsiExec.exe /X{90160000-00BA-0409-1000-0000000FF1CE}
[VersionMinor] :
Raw Value : 0
[Version] :
Raw Value : 268439722
[VersionMajor] :
Raw Value : 16
[Publisher] :
Raw Value : Microsoft Corporation
[DisplayVersion] :
Raw Value : 16.0.4266.1001
[DisplayName] :
Raw Value : Microsoft Groove MUI (English) 2016

- Update for Microsoft Office 2016 (KB4462117) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Microsoft Office 2016 (KB4462117) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{D45B13D8-9AF6-46EB-BC5C-08DDB255AFCF}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Update for Microsoft Office 2016 (KB3114524) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Microsoft Office 2016 (KB3114524) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{264B346A-CBF3-4ED6-A2F6-21E47CA8017F}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Microsoft Visual Studio Tools for Applications 2017 x64 Hosting Support
Best Confidence Version : 15.0.27520
Version Confidence Level : 2
All Possible Versions : 15.0.27520
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251685760
[DisplayName] :
Raw Value : Microsoft Visual Studio Tools for Applications 2017 x64 Hosting Support
[UninstallString] :
Raw Value : MsiExec.exe /X{AFFB9D8D-6E58-38A0-A7DD-F6F1F4247B36}
[InstallDate] :
Raw Value : 2023/01/17
[DisplayVersion] :
Raw Value : 15.0.27520
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft MPI (10.0.12498.5)
Best Confidence Version : 10.0.12498.5
Version Confidence Level : 2
All Possible Versions : 10.0.12498.5
Other Version Data
[InstallDate] :
Raw Value : 2023/01/17
[InstallLocation] :
Raw Value : C:\Program Files\Microsoft MPI\
[UninstallString] :
Raw Value : MsiExec.exe /X{8499ACD3-C1E3-45AB-BF96-DA491727EBE1}
[VersionMinor] :
Raw Value : 0
[Version] :
Raw Value : 167784658
[VersionMajor] :
Raw Value : 10
[Publisher] :
Raw Value : Microsoft Corporation
[DisplayVersion] :
Raw Value : 10.0.12498.5
[DisplayName] :
Raw Value : Microsoft MPI (10.0.12498.5)

- Microsoft SQL Server Management Studio - 18.10
Best Confidence Version : 15.0.18390.0
Version Confidence Level : 3
All Possible Versions : 15.0.18390.0
Other Version Data
[DisplayName] :
Raw Value : Microsoft SQL Server Management Studio - 18.10
[UninstallString] :
Raw Value : "C:\ProgramData\Package Cache\{c09f71ef-fff8-435a-bdc9-3c242a7c36f3}\SSMS-Setup-ENU.exe" /uninstall
Parsed File Path : C:\ProgramData\Package Cache\{c09f71ef-fff8-435a-bdc9-3c242a7c36f3}\SSMS-Setup-ENU.exe
Parsed File Version : 15.0.18390.0
[DisplayVersion] :
Raw Value : 15.0.18390.0
[DisplayIcon] :
Raw Value : C:\ProgramData\Package Cache\{c09f71ef-fff8-435a-bdc9-3c242a7c36f3}\SSMS-Setup-ENU.exe,0
Parsed File Path : C:\ProgramData\Package Cache\{c09f71ef-fff8-435a-bdc9-3c242a7c36f3}\SSMS-Setup-ENU.exe
Parsed File Version : 15.0.18390.0

- Security Update for Microsoft Office 2016 (KB4484432) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Security Update for Microsoft Office 2016 (KB4484432) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{684C44A0-9B0B-4A2A-9C2F-6163E35A7FCA}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Update for Microsoft Office 2016 (KB3191929) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Microsoft Office 2016 (KB3191929) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{A65F3D82-7DC0-42EE-9374-AA7BA1AA586A}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- GDR 2130 for SQL Server 2019 (KB5046859) (64-bit)
Best Confidence Version : 2019.150.2130.3
Version Confidence Level : 3
All Possible Versions : 2019.150.2130.3, 15.0.2130.3
Other Version Data
[DisplayName] :
Raw Value : GDR 2130 for SQL Server 2019 (KB5046859) (64-bit)
[UninstallString] :
Raw Value : "C:\Program Files\Microsoft SQL Server\150\Setup Bootstrap\Update Cache\KB5046859\GDR\setup.exe" /Action=RemovePatch /AllInstances
Parsed File Path : C:\Program Files\Microsoft SQL Server\150\Setup Bootstrap\Update Cache\KB5046859\GDR\setup.exe
Parsed File Version : 2019.150.2130.3
[InstallDate] :
Raw Value : 2025/07/08
[DisplayVersion] :
Raw Value : 15.0.2130.3
[Publisher] :
Raw Value : Microsoft Corporation

- SQL Server Management Studio for Reporting Services
Best Confidence Version : 15.0.18390.0
Version Confidence Level : 2
All Possible Versions : 15.0.18390.0
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251676630
[DisplayName] :
Raw Value : SQL Server Management Studio for Reporting Services
[UninstallString] :
Raw Value : MsiExec.exe /I{0278A8F5-4DDC-40FF-95CC-1D4725CA074B}
[InstallDate] :
Raw Value : 2023/01/17
[DisplayVersion] :
Raw Value : 15.0.18390.0
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005
Best Confidence Version : 12.0.21005
Version Confidence Level : 2
All Possible Versions : 12.0.21005
Other Version Data
[VersionMajor] :
Raw Value : 12
[Version] :
Raw Value : 201347597
[DisplayName] :
Raw Value : Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005
[UninstallString] :
Raw Value : MsiExec.exe /X{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}
[InstallDate] :
Raw Value : 2023/01/17
[DisplayVersion] :
Raw Value : 12.0.21005
[VersionMinor] :
Raw Value : 0

- Security Update for Microsoft Office 2016 (KB4462148) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Security Update for Microsoft Office 2016 (KB4462148) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{5585F39F-1DE1-4DB1-B227-292E55E5433A}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Microsoft Visual C++ 2022 X64 Additional Runtime - 14.36.32532
Best Confidence Version : 14.36.32532
Version Confidence Level : 2
All Possible Versions : 14.36.32532
Other Version Data
[VersionMajor] :
Raw Value : 14
[Version] :
Raw Value : 237272852
[DisplayName] :
Raw Value : Microsoft Visual C++ 2022 X64 Additional Runtime - 14.36.32532
[UninstallString] :
Raw Value : MsiExec.exe /I{0025DD72-A959-45B5-A0A3-7EFEB15A8050}
[InstallDate] :
Raw Value : 2025/03/11
[DisplayVersion] :
Raw Value : 14.36.32532
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 36

- Update for Skype for Business 2016 (KB5002567) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Skype for Business 2016 (KB5002567) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{AC7565EF-E108-49D4-9F46-5A1AEC72B27B}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Update for Microsoft Office 2016 (KB3118263) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Microsoft Office 2016 (KB3118263) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{94848838-9497-4F39-8294-CFB65614776A}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Kaspersky Security Center Network Agent
Best Confidence Version : 13.2.0.1511
Version Confidence Level : 2
All Possible Versions : 13.2.0.1511
Other Version Data
[InstallDate] :
Raw Value : 2022/10/22
[DisplayIcon] :
Raw Value : C:\WINDOWS\Installer\{BCF4CF24-88AB-45E1-A6E6-40C8278A70C5}\setup2.ico
[InstallLocation] :
Raw Value : C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\
[UninstallString] :
Raw Value : MsiExec.exe /I{BCF4CF24-88AB-45E1-A6E6-40C8278A70C5} /l*v "C:\WINDOWS\Temp\$klnagent-uninstall.log"
[VersionMinor] :
Raw Value : 2
[Version] :
Raw Value : 218234880
[VersionMajor] :
Raw Value : 13
[DisplayVersion] :
Raw Value : 13.2.0.1511
[DisplayName] :
Raw Value : Kaspersky Security Center Network Agent

- Security Update for Microsoft Visio 2016 (KB5002634) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Security Update for Microsoft Visio 2016 (KB5002634) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00C1-0000-1000-0000000FF1CE}" "{676A222D-7381-4C0D-B571-082AD7E0DF0C}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Update for Microsoft OneDrive for Business (KB4022219) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Microsoft OneDrive for Business (KB4022219) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00C1-0409-1000-0000000FF1CE}" "{BEE8A3FB-432A-4F06-8A38-F12ADB043344}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Microsoft Office OSM MUI (English) 2016
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 2
All Possible Versions : 16.0.4266.1001
Other Version Data
[InstallDate] :
Raw Value : 2025/04/12
[InstallLocation] :
Raw Value : C:\Program Files\Microsoft Office\
[UninstallString] :
Raw Value : MsiExec.exe /X{90160000-00E1-0409-1000-0000000FF1CE}
[VersionMinor] :
Raw Value : 0
[Version] :
Raw Value : 268439722
[VersionMajor] :
Raw Value : 16
[Publisher] :
Raw Value : Microsoft Corporation
[DisplayVersion] :
Raw Value : 16.0.4266.1001
[DisplayName] :
Raw Value : Microsoft Office OSM MUI (English) 2016

- Update for Microsoft Office 2016 (KB5002466) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Microsoft Office 2016 (KB5002466) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{99F237BE-40BE-48F7-B7F9-86D8393BF294}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- SQL Server Management Studio
Best Confidence Version : 15.0.18390.0
Version Confidence Level : 2
All Possible Versions : 15.0.18390.0
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251676630
[DisplayName] :
Raw Value : SQL Server Management Studio
[UninstallString] :
Raw Value : MsiExec.exe /I{3F338A1B-1DCF-458F-8189-416B09B7D077}
[InstallDate] :
Raw Value : 2023/01/17
[DisplayVersion] :
Raw Value : 15.0.18390.0
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft Help Viewer 2.3
Best Confidence Version : 2.3.28107
Version Confidence Level : 2
All Possible Versions : 51.119.37191, 2.3.28107
Other Version Data
[InstallDate] :
Raw Value : 2023/01/17
[DisplayIcon] :
Raw Value : msiexec.exe
[InstallLocation] :
Raw Value : C:\Program Files (x86)\Microsoft Help Viewer\v2.3\
[UninstallString] :
Raw Value : MsiExec.exe /X{BEFC10C1-7032-3C8E-80BC-621A77BFEABD}
[VersionMinor] :
Raw Value : 3
[VersionMajor] :
Raw Value : 2
[Version] :
Raw Value : 33779147
Parsed Version : 51.119.37191
[DisplayVersion] :
Raw Value : 2.3.28107
[DisplayName] :
Raw Value : Microsoft Help Viewer 2.3

- Microsoft Access database engine 2010 (English)
Best Confidence Version : 14.0.4763.1000
Version Confidence Level : 2
All Possible Versions : 14.0.4763.1000
Other Version Data
[VersionMajor] :
Raw Value : 14
[Version] :
Raw Value : 234885787
[DisplayName] :
Raw Value : Microsoft Access database engine 2010 (English)
[UninstallString] :
Raw Value : MsiExec.exe /I{90140000-00D1-0409-1000-0000000FF1CE}
[InstallDate] :
Raw Value : 2025/03/08
[DisplayVersion] :
Raw Value : 14.0.4763.1000
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Security Update for Microsoft Office 2016 (KB4011574) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Security Update for Microsoft Office 2016 (KB4011574) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{FF3C4299-6B38-4207-845A-DD8AEBAE2475}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Microsoft SQL Server 2012 Native Client
Best Confidence Version : 11.4.7515.2
Version Confidence Level : 2
All Possible Versions : 11.4.7515.2
Other Version Data
[VersionMajor] :
Raw Value : 11
[Version] :
Raw Value : 184819035
[DisplayName] :
Raw Value : Microsoft SQL Server 2012 Native Client
[UninstallString] :
Raw Value : MsiExec.exe /I{ADA823D7-2A3F-4FC6-96AC-C11656168D1E}
[InstallDate] :
Raw Value : 2025/03/10
[DisplayVersion] :
Raw Value : 11.4.7515.2
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 4

- Security Update for Microsoft Access 2016 (KB5002701) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Security Update for Microsoft Access 2016 (KB5002701) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00C1-0000-1000-0000000FF1CE}" "{AC7EBEF3-69BA-479A-8FC1-AA9B6FD37A53}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Update for Microsoft Office 2016 (KB5002050) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Microsoft Office 2016 (KB5002050) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{630DCCC9-9E19-4EB4-8036-0EB9D242D024}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Microsoft Edge Update
Best Confidence Version : 1.3.147.37
Version Confidence Level : 2
All Possible Versions : 1.3.147.37
Other Version Data
[Version] :
Raw Value : 1.3.147.37
[DisplayName] :
Raw Value : Microsoft Edge Update
[DisplayVersion] :
Raw Value : 1.3.147.37

- Update for Microsoft Office 2016 (KB5002251) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Microsoft Office 2016 (KB5002251) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{81D6DC5B-D707-4D4F-9B80-D780D6E292CF}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Microsoft Word MUI (English) 2016
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 2
All Possible Versions : 16.0.4266.1001
Other Version Data
[InstallDate] :
Raw Value : 2025/04/12
[InstallLocation] :
Raw Value : C:\Program Files\Microsoft Office\
[UninstallString] :
Raw Value : MsiExec.exe /X{90160000-001B-0409-1000-0000000FF1CE}
[VersionMinor] :
Raw Value : 0
[Version] :
Raw Value : 268439722
[VersionMajor] :
Raw Value : 16
[Publisher] :
Raw Value : Microsoft Corporation
[DisplayVersion] :
Raw Value : 16.0.4266.1001
[DisplayName] :
Raw Value : Microsoft Word MUI (English) 2016

- Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.36.32532
Best Confidence Version : 14.36.32532
Version Confidence Level : 2
All Possible Versions : 14.36.32532
Other Version Data
[VersionMajor] :
Raw Value : 14
[Version] :
Raw Value : 237272852
[DisplayName] :
Raw Value : Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.36.32532
[UninstallString] :
Raw Value : MsiExec.exe /I{73F77E4E-5A17-46E5-A5FC-8A061047725F}
[InstallDate] :
Raw Value : 2025/03/11
[DisplayVersion] :
Raw Value : 14.36.32532
[VersionMinor] :
Raw Value : 36

- Microsoft Office Shared MUI (English) 2016
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 2
All Possible Versions : 16.0.4266.1001
Other Version Data
[InstallDate] :
Raw Value : 2025/04/12
[InstallLocation] :
Raw Value : C:\Program Files\Microsoft Office\
[UninstallString] :
Raw Value : MsiExec.exe /X{90160000-006E-0409-1000-0000000FF1CE}
[VersionMinor] :
Raw Value : 0
[Version] :
Raw Value : 268439722
[VersionMajor] :
Raw Value : 16
[Publisher] :
Raw Value : Microsoft Corporation
[DisplayVersion] :
Raw Value : 16.0.4266.1001
[DisplayName] :
Raw Value : Microsoft Office Shared MUI (English) 2016

- Update for x64-based Windows Systems (KB5001716)
Best Confidence Version : 8.94.0.0
Version Confidence Level : 2
All Possible Versions : 8.94.0.0
Other Version Data
[VersionMajor] :
Raw Value : 8
[Version] :
Raw Value : 140378112
[DisplayName] :
Raw Value : Update for x64-based Windows Systems (KB5001716)
[UninstallString] :
Raw Value : MsiExec.exe /X{DA80A019-4C3B-4DAA-ACA1-6937D7CAAF9E}
[InstallDate] :
Raw Value : 2025/03/11
[DisplayVersion] :
Raw Value : 8.94.0.0
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 94

- Microsoft OneNote MUI (English) 2016
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 2
All Possible Versions : 16.0.4266.1001
Other Version Data
[InstallDate] :
Raw Value : 2025/04/12
[InstallLocation] :
Raw Value : C:\Program Files\Microsoft Office\
[UninstallString] :
Raw Value : MsiExec.exe /X{90160000-00A1-0409-1000-0000000FF1CE}
[VersionMinor] :
Raw Value : 0
[Version] :
Raw Value : 268439722
[VersionMajor] :
Raw Value : 16
[Publisher] :
Raw Value : Microsoft Corporation
[DisplayVersion] :
Raw Value : 16.0.4266.1001
[DisplayName] :
Raw Value : Microsoft OneNote MUI (English) 2016

- Update for Microsoft Office 2016 (KB4011035) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Microsoft Office 2016 (KB4011035) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{B7A5BB62-6724-414A-8915-942E141B5965}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- SQL Server 2019 Shared Management Objects
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Shared Management Objects
[UninstallString] :
Raw Value : MsiExec.exe /I{A8581199-F913-443B-B058-8E8BF317E71C}
[InstallDate] :
Raw Value : 2023/01/17
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft Excel MUI (English) 2016
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 2
All Possible Versions : 16.0.4266.1001
Other Version Data
[InstallDate] :
Raw Value : 2025/04/12
[InstallLocation] :
Raw Value : C:\Program Files\Microsoft Office\
[UninstallString] :
Raw Value : MsiExec.exe /X{90160000-0016-0409-1000-0000000FF1CE}
[VersionMinor] :
Raw Value : 0
[Version] :
Raw Value : 268439722
[VersionMajor] :
Raw Value : 16
[Publisher] :
Raw Value : Microsoft Corporation
[DisplayVersion] :
Raw Value : 16.0.4266.1001
[DisplayName] :
Raw Value : Microsoft Excel MUI (English) 2016

- Microsoft Update Health Tools
Best Confidence Version : 3.74.0.0
Version Confidence Level : 2
All Possible Versions : 85.24.4882, 3.74.0.0
Other Version Data
[VersionMajor] :
Raw Value : 3
[Version] :
Raw Value : 55181312
Parsed Version : 85.24.4882
[DisplayName] :
Raw Value : Microsoft Update Health Tools
[UninstallString] :
Raw Value : MsiExec.exe /X{1FC1A6C2-576E-489A-9B4A-92D21F542136}
[InstallDate] :
Raw Value : 2023/11/11
[DisplayVersion] :
Raw Value : 3.74.0.0
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 74

- SQL Server 2019 Full text search
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Full text search
[UninstallString] :
Raw Value : MsiExec.exe /I{BFF9440C-BC5B-4326-A861-916CC3788A4A}
[InstallDate] :
Raw Value : 2023/01/17
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- TightVNC
Best Confidence Version : 2.8.11.0
Version Confidence Level : 2
All Possible Versions : 52.7.34609, 2.8.11.0
Other Version Data
[VersionMajor] :
Raw Value : 2
[Version] :
Raw Value : 34078731
Parsed Version : 52.7.34609
[DisplayName] :
Raw Value : TightVNC
[UninstallString] :
Raw Value : MsiExec.exe /I{B7458EC3-2AA0-4DB4-8FC4-FBB73CC44948}
[InstallDate] :
Raw Value : 2022/04/26
[DisplayVersion] :
Raw Value : 2.8.11.0
[Publisher] :
Raw Value : GlavSoft LLC.
[VersionMinor] :
Raw Value : 8

- Microsoft SQL Server 2019 T-SQL Language Service
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : Microsoft SQL Server 2019 T-SQL Language Service
[UninstallString] :
Raw Value : MsiExec.exe /I{31D27B41-A051-49D8-907A-62E0F4A2188C}
[InstallDate] :
Raw Value : 2023/01/17
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft SQL Server 2019 Setup (English)
Best Confidence Version : 15.0.2130.3
Version Confidence Level : 2
All Possible Versions : 15.0.2130.3
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660370
[DisplayName] :
Raw Value : Microsoft SQL Server 2019 Setup (English)
[UninstallString] :
Raw Value : MsiExec.exe /X{00BAE2D3-6B55-487A-AE65-2262FD59B457}
[InstallDate] :
Raw Value : 2025/03/10
[DisplayVersion] :
Raw Value : 15.0.2130.3
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005
Best Confidence Version : 12.0.21005
Version Confidence Level : 2
All Possible Versions : 12.0.21005
Other Version Data
[VersionMajor] :
Raw Value : 12
[Version] :
Raw Value : 201347597
[DisplayName] :
Raw Value : Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005
[UninstallString] :
Raw Value : MsiExec.exe /X{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}
[InstallDate] :
Raw Value : 2023/01/17
[DisplayVersion] :
Raw Value : 12.0.21005
[VersionMinor] :
Raw Value : 0

- Update for Microsoft Office 2016 (KB2920720) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Microsoft Office 2016 (KB2920720) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{8683D594-A08C-451F-82C3-51D6FB730A6C}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Security Update for Microsoft Office 2016 (KB5002575) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Security Update for Microsoft Office 2016 (KB5002575) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00C1-0000-1000-0000000FF1CE}" "{4D611CD4-014D-4935-8445-2A4EC5229EDA}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- VMware Tools
Best Confidence Version : 12.3.5.22544099
Version Confidence Level : 2
All Possible Versions : 12.3.5.22544099
Other Version Data
[InstallDate] :
Raw Value : 2025/03/11
[InstallLocation] :
Raw Value : C:\Program Files\VMware\VMware Tools\
[UninstallString] :
Raw Value : MsiExec.exe /I{27B78D8E-F8B9-4AF5-BF9C-8DDD583EAB6B}
[VersionMinor] :
Raw Value : 3
[Version] :
Raw Value : 201523205
[VersionMajor] :
Raw Value : 12
[Publisher] :
Raw Value : VMware, Inc.
[DisplayVersion] :
Raw Value : 12.3.5.22544099
[DisplayName] :
Raw Value : VMware Tools

- Security Update for Microsoft OneNote 2016 (KB5002622) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Security Update for Microsoft OneNote 2016 (KB5002622) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{BE062AE4-F1BC-4ABB-97EE-899DE28978BA}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Microsoft Office Shared Setup Metadata MUI (English) 2016
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 2
All Possible Versions : 16.0.4266.1001
Other Version Data
[InstallDate] :
Raw Value : 2025/04/12
[InstallLocation] :
Raw Value : C:\Program Files\Microsoft Office\
[UninstallString] :
Raw Value : MsiExec.exe /X{90160000-0115-0409-1000-0000000FF1CE}
[VersionMinor] :
Raw Value : 0
[Version] :
Raw Value : 268439722
[VersionMajor] :
Raw Value : 16
[Publisher] :
Raw Value : Microsoft Corporation
[DisplayVersion] :
Raw Value : 16.0.4266.1001
[DisplayName] :
Raw Value : Microsoft Office Shared Setup Metadata MUI (English) 2016

- Update for Microsoft Office 2016 (KB4032254) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Microsoft Office 2016 (KB4032254) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{FC118D77-E399-4BD1-BA89-03675D9E7CE8}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Security Update for Microsoft Office 2016 (KB5002669) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Security Update for Microsoft Office 2016 (KB5002669) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00E1-0409-1000-0000000FF1CE}" "{B1A792C6-3E74-4CF3-8319-4D6724BAABB3}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- SQL Server 2019 Connection Info
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Connection Info
[UninstallString] :
Raw Value : MsiExec.exe /I{FD730873-33D1-4D1F-9AE0-E259586F8827}
[InstallDate] :
Raw Value : 2023/01/17
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Kaspersky Endpoint Security for Windows
Best Confidence Version : 12.3.0.493
Version Confidence Level : 2
All Possible Versions : 12.3.0.493
Other Version Data
[VersionMajor] :
Raw Value : 12
[Version] :
Raw Value : 201523200
[InstallLocation] :
Raw Value : C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\
[DisplayName] :
Raw Value : Kaspersky Endpoint Security for Windows
[UninstallString] :
Raw Value : msiexec.exe /x {8409A30E-CDF7-4800-B389-FB0A8FB6CE2C}
[InstallDate] :
Raw Value : 2024/03/13
[DisplayVersion] :
Raw Value : 12.3.0.493
[VersionMinor] :
Raw Value : 3

- Lucee
Best Confidence Version : 5.3.8.201
Version Confidence Level : 2
All Possible Versions : 5.3.8.201
Other Version Data
[VersionMajor] :
Raw Value : 5
[InstallLocation] :
Raw Value : D:\Techexcel\Lucee
[DisplayName] :
Raw Value : Lucee
[UninstallString] :
Raw Value : "D:\Techexcel\Lucee\uninstall.exe"
Parsed File Path : D:\Techexcel\Lucee\uninstall.exe
[InstallDate] :
Raw Value : 2023/01/17
[DisplayVersion] :
Raw Value : 5.3.8.201
[Publisher] :
Raw Value : Lucee Association Switzerland
[VersionMinor] :
Raw Value : 3
[DisplayIcon] :
Raw Value : D:\Techexcel\Lucee/lucee.ico

- Update for Microsoft Office 2016 (KB4011259) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Microsoft Office 2016 (KB4011259) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{328D548A-FC7C-40E0-A87B-9676C059315B}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Java SE Development Kit 8 Update 161 (64-bit)
Best Confidence Version : 8.0.1610.12
Version Confidence Level : 2
All Possible Versions : 8.0.1610.12
Other Version Data
[InstallDate] :
Raw Value : 2023/01/18
[InstallLocation] :
Raw Value : C:\Program Files\Java\jdk1.8.0_161\
[UninstallString] :
Raw Value : MsiExec.exe /X{64A3A4F4-B792-11D6-A78A-00B0D0180161}
[VersionMinor] :
Raw Value : 0
[Version] :
Raw Value : 134219338
[VersionMajor] :
Raw Value : 8
[Publisher] :
Raw Value : Oracle Corporation
[DisplayVersion] :
Raw Value : 8.0.1610.12
[DisplayName] :
Raw Value : Java SE Development Kit 8 Update 161 (64-bit)

- Security Update for Microsoft Office 2016 (KB5002635) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Security Update for Microsoft Office 2016 (KB5002635) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{03A3B9C2-8D1D-4D46-B57E-1349055E5DED}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Herramientas de corrección de Microsoft Office 2016: español
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 2
All Possible Versions : 16.0.4266.1001
Other Version Data
[InstallDate] :
Raw Value : 2025/04/12
[InstallLocation] :
Raw Value : C:\Program Files\Microsoft Office\
[UninstallString] :
Raw Value : MsiExec.exe /X{90160000-001F-0C0A-1000-0000000FF1CE}
[VersionMinor] :
Raw Value : 0
[Version] :
Raw Value : 268439722
[VersionMajor] :
Raw Value : 16
[Publisher] :
Raw Value : Microsoft Corporation
[DisplayVersion] :
Raw Value : 16.0.4266.1001
[DisplayName] :
Raw Value : Herramientas de corrección de Microsoft Office 2016: español

- Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.36.32532
Best Confidence Version : 14.36.32532
Version Confidence Level : 2
All Possible Versions : 14.36.32532
Other Version Data
[VersionMajor] :
Raw Value : 14
[Version] :
Raw Value : 237272852
[DisplayName] :
Raw Value : Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.36.32532
[UninstallString] :
Raw Value : MsiExec.exe /I{D5D19E2F-7189-42FE-8103-92CD1FA457C2}
[InstallDate] :
Raw Value : 2025/03/11
[DisplayVersion] :
Raw Value : 14.36.32532
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 36

- Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501
Best Confidence Version : 12.0.30501.0
Version Confidence Level : 3
All Possible Versions : 12.0.30501.0
Other Version Data
[DisplayName] :
Raw Value : Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501
[UninstallString] :
Raw Value : "C:\ProgramData\Package Cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe" /uninstall
Parsed File Path : C:\ProgramData\Package Cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe
Parsed File Version : 12.0.30501.0
[DisplayVersion] :
Raw Value : 12.0.30501.0
[DisplayIcon] :
Raw Value : C:\ProgramData\Package Cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe,0
Parsed File Path : C:\ProgramData\Package Cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe
Parsed File Version : 12.0.30501.0

- Kaspersky Endpoint Security for Windows
Best Confidence Version : 11.15.8.493
Version Confidence Level : 2
All Possible Versions : 11.15.8.493
Other Version Data
[InstallLocation] :
Raw Value : C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\
[DisplayName] :
Raw Value : Kaspersky Endpoint Security for Windows
[DisplayVersion] :
Raw Value : 11.15.8.493

- UiPath Studio
Best Confidence Version : 23.8.0.0
Version Confidence Level : 2
All Possible Versions : 23.8.0.0
Other Version Data
[VersionMajor] :
Raw Value : 23
[Version] :
Raw Value : 386400256
[DisplayName] :
Raw Value : UiPath Studio
[UninstallString] :
Raw Value : MsiExec.exe /I{1B28EF98-8E38-4713-880A-A17E8C799366}
[InstallDate] :
Raw Value : 2023/09/11
[DisplayVersion] :
Raw Value : 23.8.0.0
[Publisher] :
Raw Value : UiPath
[VersionMinor] :
Raw Value : 8

- Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005
Best Confidence Version : 12.0.21005
Version Confidence Level : 2
All Possible Versions : 12.0.21005
Other Version Data
[VersionMajor] :
Raw Value : 12
[Version] :
Raw Value : 201347597
[DisplayName] :
Raw Value : Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005
[UninstallString] :
Raw Value : MsiExec.exe /X{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}
[InstallDate] :
Raw Value : 2023/01/19
[DisplayVersion] :
Raw Value : 12.0.21005
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- SQL Server 2019 Database Engine Services
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Database Engine Services
[UninstallString] :
Raw Value : MsiExec.exe /I{E3E84B2C-FCF6-469F-9FE7-5E8934DB69AD}
[InstallDate] :
Raw Value : 2023/01/17
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Browser for SQL Server 2019
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : Browser for SQL Server 2019
[UninstallString] :
Raw Value : MsiExec.exe /X{5E366957-8D78-4BB5-A790-96F97A9766BD}
[InstallDate] :
Raw Value : 2025/03/10
[DisplayVersion] :
Raw Value : 15.0.2000.5
[VersionMinor] :
Raw Value : 0

- Update for Microsoft Office 2016 (KB3118264) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Microsoft Office 2016 (KB3118264) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{B2437330-4140-4B97-8041-3D337D716DC9}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Azure Data Studio
Best Confidence Version : 51.1052.0.0
Version Confidence Level : 3
All Possible Versions : 51.1052.0.0, 1.32.0, 1.32.0.0
Other Version Data
[VersionMajor] :
Raw Value : 1
[InstallLocation] :
Raw Value : C:\Program Files\Azure Data Studio\
[DisplayName] :
Raw Value : Azure Data Studio
[UninstallString] :
Raw Value : "C:\Program Files\Azure Data Studio\unins000.exe"
Parsed File Path : C:\Program Files\Azure Data Studio\unins000.exe
Parsed File Version : 51.1052.0.0
[InstallDate] :
Raw Value : 2023/01/17
[DisplayVersion] :
Raw Value : 1.32.0
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 32
[DisplayIcon] :
Raw Value : C:\Program Files\Azure Data Studio\azuredatastudio.exe
Parsed File Path : C:\Program Files\Azure Data Studio\azuredatastudio.exe
Parsed File Version : 1.32.0.0

- Microsoft Office Proofing (English) 2016
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 2
All Possible Versions : 16.0.4266.1001
Other Version Data
[InstallDate] :
Raw Value : 2025/04/12
[InstallLocation] :
Raw Value : C:\Program Files\Microsoft Office\
[UninstallString] :
Raw Value : MsiExec.exe /X{90160000-002C-0409-1000-0000000FF1CE}
[VersionMinor] :
Raw Value : 0
[Version] :
Raw Value : 268439722
[VersionMajor] :
Raw Value : 16
[Publisher] :
Raw Value : Microsoft Corporation
[DisplayVersion] :
Raw Value : 16.0.4266.1001
[DisplayName] :
Raw Value : Microsoft Office Proofing (English) 2016

- Google Chrome
Best Confidence Version : 143.0.7499.193
Version Confidence Level : 3
All Possible Versions : 143.0.7499.193
Other Version Data
[InstallDate] :
Raw Value : 2026/01/09
[DisplayIcon] :
Raw Value : C:\Program Files\Google\Chrome\Application\chrome.exe,0
Parsed File Path : C:\Program Files\Google\Chrome\Application\chrome.exe
Parsed File Version : 143.0.7499.193
[InstallLocation] :
Raw Value : C:\Program Files\Google\Chrome\Application
[UninstallString] :
Raw Value : "C:\Program Files\Google\Chrome\Application\143.0.7499.193\Installer\setup.exe" --uninstall --channel=stable --system-level --verbose-logging
Parsed File Path : C:\Program Files\Google\Chrome\Application\143.0.7499.193\Installer\setup.exe
Parsed File Version : 143.0.7499.193
[VersionMinor] :
Raw Value : 193
[Version] :
Raw Value : 143.0.7499.193
[VersionMajor] :
Raw Value : 7499
[DisplayVersion] :
Raw Value : 143.0.7499.193
[DisplayName] :
Raw Value : Google Chrome

- Security Update for Microsoft Office 2016 (KB3191869) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Security Update for Microsoft Office 2016 (KB3191869) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{96648CB1-EA94-4DA9-AD15-1D38037B63AF}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Security Update for Microsoft Office 2016 (KB5002573) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Security Update for Microsoft Office 2016 (KB5002573) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00C1-0409-1000-0000000FF1CE}" "{FBDF2571-2C0F-406E-9A78-B6FBD61209CE}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- SecPod Saner
Best Confidence Version : 6.3.0.0
Version Confidence Level : 3
All Possible Versions : 6.3.0.0, 6.3.0.1
Other Version Data
[InstallLocation] :
Raw Value : C:\Program Files (x86)\SecPod Saner
[DisplayName] :
Raw Value : SecPod Saner
[UninstallString] :
Raw Value : "C:\Program Files (x86)\SecPod Saner\Agent\bin\spsaneruninstall.exe"
Parsed File Path : C:\Program Files (x86)\SecPod Saner\Agent\bin\spsaneruninstall.exe
Parsed File Version : 6.3.0.0
[DisplayVersion] :
Raw Value : 6.3.0.1
[DisplayIcon] :
Raw Value : C:\Program Files (x86)\SecPod Saner\Agent\icon.ico

- Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005
Best Confidence Version : 12.0.21005
Version Confidence Level : 2
All Possible Versions : 12.0.21005
Other Version Data
[VersionMajor] :
Raw Value : 12
[Version] :
Raw Value : 201347597
[DisplayName] :
Raw Value : Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005
[UninstallString] :
Raw Value : MsiExec.exe /X{929FBD26-9020-399B-9A7A-751D61F0B942}
[InstallDate] :
Raw Value : 2023/01/19
[DisplayVersion] :
Raw Value : 12.0.21005
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Security Update for Microsoft Office 2016 (KB4475581) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Security Update for Microsoft Office 2016 (KB4475581) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{602BFD6C-5400-403B-A39D-8F4EE35E3D0C}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- SQL Server 2019 Batch Parser
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Batch Parser
[UninstallString] :
Raw Value : MsiExec.exe /I{D459615B-83B0-408F-8F39-6CC07C277BA6}
[InstallDate] :
Raw Value : 2023/01/17
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft Silverlight
Best Confidence Version : 5.1.50907.0
Version Confidence Level : 2
All Possible Versions : 132.0.9507, 5.1.50907.0
Other Version Data
[InstallDate] :
Raw Value : 2024/06/29
[InstallLocation] :
Raw Value : C:\Program Files\Microsoft Silverlight\
[UninstallString] :
Raw Value : MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
[VersionMinor] :
Raw Value : 1
[Version] :
Raw Value : 84002523
Parsed Version : 132.0.9507
[VersionMajor] :
Raw Value : 5
[Publisher] :
Raw Value : Microsoft Corporation
[DisplayVersion] :
Raw Value : 5.1.50907.0
[DisplayName] :
Raw Value : Microsoft Silverlight

- SQL Server 2019 DMF
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 DMF
[UninstallString] :
Raw Value : MsiExec.exe /I{814D5077-C93F-42E2-B875-717007C186B9}
[InstallDate] :
Raw Value : 2023/01/17
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.36.32532
Best Confidence Version : 14.36.32532.0
Version Confidence Level : 3
All Possible Versions : 14.36.32532.0
Other Version Data
[DisplayName] :
Raw Value : Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.36.32532
[UninstallString] :
Raw Value : "C:\ProgramData\Package Cache\{410c0ee1-00bb-41b6-9772-e12c2828b02f}\VC_redist.x86.exe" /uninstall
Parsed File Path : C:\ProgramData\Package Cache\{410c0ee1-00bb-41b6-9772-e12c2828b02f}\VC_redist.x86.exe
Parsed File Version : 14.36.32532.0
[DisplayVersion] :
Raw Value : 14.36.32532.0
[DisplayIcon] :
Raw Value : C:\ProgramData\Package Cache\{410c0ee1-00bb-41b6-9772-e12c2828b02f}\VC_redist.x86.exe,0
Parsed File Path : C:\ProgramData\Package Cache\{410c0ee1-00bb-41b6-9772-e12c2828b02f}\VC_redist.x86.exe
Parsed File Version : 14.36.32532.0

- Microsoft VSS Writer for SQL Server 2019
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : Microsoft VSS Writer for SQL Server 2019
[UninstallString] :
Raw Value : MsiExec.exe /I{2C33F4D4-E9A5-4DE1-ACFE-3A13464E6703}
[InstallDate] :
Raw Value : 2025/03/10
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft Office Shared 32-bit MUI (English) 2016
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 2
All Possible Versions : 16.0.4266.1001
Other Version Data
[InstallDate] :
Raw Value : 2025/04/12
[InstallLocation] :
Raw Value : C:\Program Files\Microsoft Office\
[UninstallString] :
Raw Value : MsiExec.exe /X{90160000-00C1-0409-1000-0000000FF1CE}
[VersionMinor] :
Raw Value : 0
[Version] :
Raw Value : 268439722
[VersionMajor] :
Raw Value : 16
[Publisher] :
Raw Value : Microsoft Corporation
[DisplayVersion] :
Raw Value : 16.0.4266.1001
[DisplayName] :
Raw Value : Microsoft Office Shared 32-bit MUI (English) 2016

- Microsoft PowerPoint MUI (English) 2016
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 2
All Possible Versions : 16.0.4266.1001
Other Version Data
[InstallDate] :
Raw Value : 2025/04/12
[InstallLocation] :
Raw Value : C:\Program Files\Microsoft Office\
[UninstallString] :
Raw Value : MsiExec.exe /X{90160000-0018-0409-1000-0000000FF1CE}
[VersionMinor] :
Raw Value : 0
[Version] :
Raw Value : 268439722
[VersionMajor] :
Raw Value : 16
[Publisher] :
Raw Value : Microsoft Corporation
[DisplayVersion] :
Raw Value : 16.0.4266.1001
[DisplayName] :
Raw Value : Microsoft PowerPoint MUI (English) 2016

- Microsoft SQL Server 2019 (64-bit)
Best Confidence Version : 15.0.2130.3
Version Confidence Level : 3
All Possible Versions : 15.0.2130.3
Other Version Data
[DisplayName] :
Raw Value : Microsoft SQL Server 2019 (64-bit)
[UninstallString] :
Raw Value : "C:\Program Files\Microsoft SQL Server\150\Setup Bootstrap\SQL2019\x64\SetupARP.exe"
Parsed File Path : C:\Program Files\Microsoft SQL Server\150\Setup Bootstrap\SQL2019\x64\SetupARP.exe
Parsed File Version : 15.0.2130.3
[Publisher] :
Raw Value : Microsoft Corporation
[DisplayIcon] :
Raw Value : "C:\Program Files\Microsoft SQL Server\150\Setup Bootstrap\SQL2019\x64\SetupARP.exe"
Parsed File Path : C:\Program Files\Microsoft SQL Server\150\Setup Bootstrap\SQL2019\x64\SetupARP.exe
Parsed File Version : 15.0.2130.3

- SQL Server Management Studio for Analysis Services
Best Confidence Version : 15.0.18390.0
Version Confidence Level : 2
All Possible Versions : 15.0.18390.0
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251676630
[DisplayName] :
Raw Value : SQL Server Management Studio for Analysis Services
[UninstallString] :
Raw Value : MsiExec.exe /I{A1CAC3E0-B321-40FE-8907-4739297D5338}
[InstallDate] :
Raw Value : 2023/01/17
[DisplayVersion] :
Raw Value : 15.0.18390.0
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Mozilla Maintenance Service
Best Confidence Version : 1.0.0.0
Version Confidence Level : 3
All Possible Versions : 1.0.0.0, 134.0
Other Version Data
[DisplayName] :
Raw Value : Mozilla Maintenance Service
[UninstallString] :
Raw Value : "C:\Program Files (x86)\Mozilla Maintenance Service\uninstall.exe"
Parsed File Path : C:\Program Files (x86)\Mozilla Maintenance Service\uninstall.exe
Parsed File Version : 1.0.0.0
[DisplayVersion] :
Raw Value : 134.0
[Publisher] :
Raw Value : Mozilla
[DisplayIcon] :
Raw Value : C:\Program Files (x86)\Mozilla Maintenance Service\Uninstall.exe,0
Parsed File Path : C:\Program Files (x86)\Mozilla Maintenance Service\Uninstall.exe
Parsed File Version : 1.0.0.0

- Update for Microsoft Office 2016 (KB3213650) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Microsoft Office 2016 (KB3213650) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00C1-0000-1000-0000000FF1CE}" "{18224882-1EA1-460B-8899-DD7F013C1EC7}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Security Update for Microsoft Office 2016 (KB5002469) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Security Update for Microsoft Office 2016 (KB5002469) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{228EAA41-0576-440E-8AFB-FCE20C72A6A7}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Update for Microsoft Office 2016 (KB3118262) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Update for Microsoft Office 2016 (KB3118262) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0012-0000-1000-0000000FF1CE}" "{7D634991-F4C0-4761-9F90-54F69A8199EB}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

- Security Update for Microsoft Project 2016 (KB5002652) 64-Bit Edition
Best Confidence Version : 16.0.4266.1001
Version Confidence Level : 3
All Possible Versions : 16.0.4266.1001
Other Version Data
[DisplayName] :
Raw Value : Security Update for Microsoft Project 2016 (KB5002652) 64-Bit Edition
[UninstallString] :
Raw Value : "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00C1-0000-1000-0000000FF1CE}" "{8BE28313-0C15-4C31-B5F8-08959E44EA66}" "1033" "0"
Parsed File Path : C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe
Parsed File Version : 16.0.4266.1001
[Publisher] :
Raw Value : Microsoft

92366 - Microsoft Windows Last Boot Time
-
Synopsis
Nessus was able to collect the remote host's last boot time in a human readable format.
Description
Nessus was able to collect and report the remote host's last boot time as an ISO 8601 timestamp.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/07/09
Plugin Output

tcp/0

Last reboot : 2026-01-03T18:07:07+05:30 (20260103180707.500000+330)

161502 - Microsoft Windows Logged On Users
-
Synopsis
Nessus was able to determine the logged on users from the registry
Description
Using the HKU registry, Nessus was able to enumerate the SIDs of logged on users
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2022/05/25, Modified: 2025/10/01
Plugin Output

tcp/445/cifs

Logged on users :
- S-1-5-21-2193062927-1383316644-2198579232-1004
Domain : LIVETECHROBO
Username : Techrobot
- S-1-5-21-2193062927-1383316644-2198579232-1009
Domain : LIVETECHROBO
Username : tidua
63080 - Microsoft Windows Mounted Devices
-
Synopsis
It is possible to get a list of mounted devices that may have been connected to the remote system in the past.
Description
By connecting to the remote host with the supplied credentials, this plugin enumerates mounted devices that have been connected to the remote host in the past.
See Also
Solution
Make sure that the mounted drives agree with your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2012/11/28, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Name : \??\volume{019c4c46-bb59-11ec-bd63-806e6f6e6963}
Data : \??\FDC#GENERIC_FLOPPY_DRIVE#6&1b0d1d81&0&0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Raw data : 5c003f003f005c004600440043002300470045004e0045005200490043005f0046004c004f005000500059005f004400520049005600450023003600260031006200300064003100640038003100260030002600300023007b00350033006600350036003300300064002d0062003600620066002d0031003100640030002d0039003400660032002d003000300061003000630039003100650066006200380062007d00

Name : \??\volume{4721c763-95c8-11ed-bd76-005056bc53be}
Data : \??\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Raw data : 5c003f003f005c00530043005300490023004300640052006f006d002600560065006e005f004d007300660074002600500072006f0064005f005600690072007400750061006c005f004400560044002d0052004f004d002300320026003100660034006100640066006600650026003000260030003000300030003000310023007b00350033006600350036003300300064002d0062003600620066002d0031003100640030002d0039003400660032002d003000300061003000630039003100650066006200380062007d00

Name : \dosdevices\j:
Data : Z]^X
Raw data : 5a5d5e580000100000000000

Name : \dosdevices\g:
Data : Q
Raw data : b510cd510000100000000000

Name : \??\volume{019c4c45-bb59-11ec-bd63-806e6f6e6963}
Data : \??\IDE#CdRomNECVMWar_VMware_IDE_CDR10_______________1.00____#5&2a3267f0&0&1.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Raw data : 5c003f003f005c0049004400450023004300640052006f006d004e004500430056004d005700610072005f0056004d0077006100720065005f004900440045005f00430044005200310030005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f0031002e00300030005f005f005f005f002300350026003200610033003200360037006600300026003000260031002e0030002e00300023007b00350033006600350036003300300064002d0062003600620066002d0031003100640030002d0039003400660032002d003000300061003000630039003100650066006200380062007d00

Name : \dosdevices\e:
Data : Z]^X@$
Raw data : 5a5d5e580000402400000000

Name : \dosdevices\a:
Data : \??\FDC#GENERIC_FLOPPY_DRIVE#6&1b0d1d81&0&0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Raw data : 5c003f003f005c004600440043002300470045004e0045005200490043005f0046004c004f005000500059005f004400520049005600450023003600260031006200300064003100640038003100260030002600300023007b00350033006600350036003300300064002d0062003600620066002d0031003100640030002d0039003400660032002d003000300061003000630039003100650066006200380062007d00

Name : \dosdevices\c:
Data : Q@$
Raw data : b510cd510000402400000000

Name : \dosdevices\d:
Data :
Raw data : 0201dad10000100000000000

92372 - Microsoft Windows NetBIOS over TCP/IP Info
-
Synopsis
Nessus was able to collect and report NBT information from the remote host.
Description
Nessus was able to collect details for NetBIOS over TCP/IP from the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2025/12/15
Plugin Output

tcp/0

NBT information attached.
First 10 lines of all CSVs:
nbtstat_local.csv:
Interface,Name,Suffix,Type,Status,MAC
172.17.100.35,LIVETECHROBO,<20>,UNIQUE,Registered,00:50:56:BC:FC:73
172.17.100.35,LIVETECHROBO,<00>,UNIQUE,Registered,00:50:56:BC:FC:73
172.17.100.35,WORKGROUP,<00>,GROUP,Registered,00:50:56:BC:FC:73

103871 - Microsoft Windows Network Adapters
-
Synopsis
Identifies the network adapters installed on the remote host.
Description
Using the supplied credentials, this plugin enumerates and reports the installed network adapters on the remote Windows host.
Solution
Make sure that all of the installed network adapters agrees with your organization's acceptable use and security policies.
Risk Factor
None
References
XREF IAVT:0001-T-0758
Plugin Information
Published: 2017/10/17, Modified: 2022/02/01
Plugin Output

tcp/445/cifs

Network Adapter Driver Description : Intel(R) 82574L Gigabit Network Connection
Network Adapter Driver Version : 12.17.10.8
65791 - Microsoft Windows Portable Devices
-
Synopsis
It is possible to get a list of portable devices that may have been connected to the remote system in the past.
Description
By connecting to the remote host with the supplied credentials, this plugin enumerates portable devices that have been connected to the remote host in the past.
See Also
Solution
Make sure that use of the portable devices agrees with your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2013/04/03, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Friendly name : DATA
Device : SWD#WPDBUSENUM#{21F23E32-BECD-11EC-BD72-806E6F6E6963}#0000000000100000

Friendly name : DATA
Device : SWD#WPDBUSENUM#{21F23E32-BECD-11EC-BD72-806E6F6E6963}#0000000001000000

Friendly name : System Reserved
Device : SWD#WPDBUSENUM#{A7E00F2D-97F3-11ED-BD79-005056BC53BE}#0000000000100000

Friendly name : OS
Device : SWD#WPDBUSENUM#{A7E00F2D-97F3-11ED-BD79-005056BC53BE}#0000000024400000

92367 - Microsoft Windows PowerShell Execution Policy
-
Synopsis
Nessus was able to collect and report the PowerShell execution policy for the remote host.
Description
Nessus was able to collect and report the PowerShell execution policy for the remote Windows host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2020/06/12
Plugin Output

tcp/0

HKLM\SOFTWARE\Microsoft\PowerShell\1\ShellIds\Microsoft.PowerShell\ExecutionPolicy : Restricted
HKLM\SOFTWARE\Wow6432Node\Microsoft\PowerShell\1\ShellIds\Microsoft.PowerShell\ExecutionPolicy : Restricted
70329 - Microsoft Windows Process Information
-
Synopsis
Use WMI to obtain running process information.
Description
Report details on the running processes on the machine.

This plugin is informative only and could be used for forensic investigation, malware detection, and to confirm that your system processes conform to your system policies.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/08, Modified: 2025/12/15
Plugin Output

tcp/0

Process Overview :
SID: Process (PID)
0 : System Idle Process (0)
0 : |- System (4)
0 : |- Memory Compression (2080)
0 : |- smss.exe (476)
10 : csrss.exe (13076)
0 : Registry (140)
10 : explorer.exe (15576)
10 : |- tvnserver.exe (14364)
10 : |- SecurityHealthSystray.exe (17368)
10 : OneDrive.Sync.Service.exe (16212)
1 : OneDrive.Sync.Service.exe (18140)
10 : OneDrive.exe (18912)
1 : chrome.exe (20024)
1 : |- chrome.exe (10692)
1 : |- chrome.exe (13304)
1 : |- chrome.exe (13460)
1 : |- chrome.exe (14012)
1 : |- chrome.exe (14592)
1 : |- cmd.exe (14932)
1 : |- UiPath.BrowserBridge.Portable.exe (13352)
1 : |- conhost.exe (4772)
1 : |- chrome.exe (15984)
1 : |- chrome.exe (17064)
1 : |- chrome.exe (17924)
1 : |- chrome.exe (19084)
1 : |- cmd.exe (19756)
1 : |- conhost.exe (16132)
1 : |- ChromeNativeMessaging.exe (17008)
0 : csrss.exe (588)
1 : explorer.exe (6228)
1 : |- UiPath.Assistant.exe (744)
1 : |- UiPath.Assistant.exe (2524)
1 : |- UiPath.Assistant.exe (5096)
1 : |- UiPath.Assistant.exe (512)
1 : |- UiPath.Service.UserHost.exe (7332)
1 : |- UiPath.Executor.exe (10596)
1 : |- UiPath.Executor.exe (1304)
1 : |- UiPath.Executor.exe (18848)
1 : |- ffmpeg.exe (21276)
1 : |- conhost.exe (20576)
1 : |- UiPath.Assistant.exe (8744)
1 : |- SecurityHealthSystray.exe (9812)
1 : |- tvnserver.exe (9932)
1 : |- vmtoolsd.exe (9968)
10 : winlogon.exe (6280)
10 : |- fontdrvhost.exe (13448)
10 : |- LogonUI.exe (20540)
10 : |- dwm.exe (7460)
0 : wininit.exe (716)
0 : |- fontdrvhost.exe (460)
0 : |- services.exe (860)
0 : |- svchost.exe (1000)
10 : |- RuntimeBroker.exe (10312)
1 : |- RuntimeBroker.exe (12800)
10 : |- ShellExperienceHost.exe (15328)
0 : |- WmiPrvSE.exe (16940)
10 : |- StartMenuExperienceHost.exe (17552)
10 : |- RuntimeBroker.exe (17656)
0 : |- WmiPrvSE.exe (17800)
10 : |- SearchApp.exe (18328)
10 : |- RuntimeBroker.exe (18376)
10 : |- dllhost.exe (18736)
0 : |- WmiPrvSE.exe (2396)
10 : |- RuntimeBroker.exe (3140)
0 : |- WmiPrvSE.exe (3716)
1 : |- dllhost.exe (5372)
10 : |- TextInputHost.exe (6248)
1 : |- StartMenuExperienceHost.exe (7068)
1 : |- RuntimeBroker.exe (7256)
1 : |- ShellExperienceHost.exe (7324)
1 : |- UserOOBEBroker.exe (7456)
1 : |- SearchApp.exe (7584)
0 : |- unsecapp.exe (7772)
1 : |- RuntimeBroker.exe (8000)
1 : |- RuntimeBroker.exe (8328)
1 : |- ApplicationFrameHost.exe (8748)
1 : |- LockApp.exe (8860)
1 : |- RuntimeBroker.exe (8976)
1 : |- SystemSettingsBroker.exe (9332)
1 : |- TextInputHost.exe (9588)
0 : |- svchost.exe (1020)
0 : |- svchost.exe (10252)
0 : |- svchost.exe (1072)
0 : |- svchost.exe (10752)
1 : |- svchost.exe (10776)
10 : |- svchost.exe (10848)
1 : |- svchost.exe (10932)
0 : |- svchost.exe (1116)
10 : |- rdpclip.exe (5428)
0 : |- klnagent.exe (11396)
0 : |- vapm.exe (18004)
0 : |- svchost.exe (1148)
0 : |- svchost.exe (1168)
0 : |- svchost.exe (1232)
0 : |- svchost.exe (1312)
0 : |- svchost.exe (1320)
0 : |- svchost.exe (14436)
0 : |- svchost.exe (1448)
0 : |- svchost.exe (1504)
10 : |- svchost.exe (15148)
0 : |- svchost.exe (1532)
10 : |- taskhostw.exe (13800)
1 : |- taskhostw.exe (4212)
1 : |- taskhostw.exe (5760)
1 : |- UiPath.RobotJS.UserHost.exe (5824)
1 : |- taskhostw.exe (5836)
0 : |- svchost.exe (1648)
0 : |- svchost.exe (1656)
0 : |- svchost.exe (1752)
0 : |- svchost.exe (1816)
10 : |- sihost.exe (12400)
1 : |- sihost.exe (5668)
0 : |- svchost.exe (1836)
0 : |- WUDFHost.exe (1880)
0 : |- svchost.exe (1896)
0 : |- svchost.exe (1904)
0 : |- svchost.exe (1912)
0 : |- svchost.exe (2072)
0 : |- svchost.exe (2164)
0 : |- svchost.exe (21700)
0 : |- svchost.exe (2172)
0 : |- svchost.exe (22180)
0 : |- svchost.exe (2288)
0 : |- svchost.exe (2332)
0 : |- svchost.exe (2352)
0 : |- svchost.exe (2496)
0 : |- svchost.exe (2516)
0 : |- svchost.exe (2672)
0 : |- svchost.exe (2680)
0 : |- svchost.exe (2692)
0 : |- svchost.exe (2772)
0 : |- svchost.exe (2784)
0 : |- svchost.exe (2968)
0 : |- svchost.exe (3088)
0 : |- svchost.exe (3196)
0 : |- svchost.exe (3224)
0 : |- svchost.exe (3272)
0 : |- svchost.exe (3456)
0 : |- svchost.exe (3464)
0 : |- svchost.exe (3516)
0 : |- svchost.exe (3524)
0 : |- svchost.exe (3532)
0 : |- dasHost.exe (4068)
0 : |- svchost.exe (3540)
0 : |- svchost.exe (3548)
0 : |- AggregatorHost.exe (6936)
0 : |- avp.exe (3604)
10 : |- avpui.exe (14172)
1 : |- avpui.exe (9320)
0 : |- svchost.exe (3704)
0 : |- svchost.exe (3724)
0 : |- sqlwriter.exe (3736)
0 : |- tvnserver.exe (3748)
1 : |- tvnserver.exe (21072)
0 : |- vmtoolsd.exe (3788)
0 : |- VGAuthService.exe (3804)
0 : |- vm3dservice.exe (3824)
1 : |- vm3dservice.exe (3344)
0 : |- svchost.exe (3860)
0 : |- svchost.exe (3920)
0 : |- svchost.exe (4000)
0 : |- svchost.exe (4216)
0 : |- svchost.exe (4396)
0 : |- svchost.exe (4600)
0 : |- dllhost.exe (4636)
0 : |- msdtc.exe (4648)
0 : |- svchost.exe (516)
0 : |- svchost.exe (5180)
0 : |- svchost.exe (5252)
0 : |- SearchIndexer.exe (5484)
1 : |- svchost.exe (5696)
1 : |- svchost.exe (5732)
0 : |- svchost.exe (5976)
1 : |- ctfmon.exe (10648)
10 : |- ctfmon.exe (17356)
0 : |- svchost.exe (5996)
0 : |- svchost.exe (6448)
0 : |- svchost.exe (6580)
1 : |- svchost.exe (6588)
10 : |- svchost.exe (6896)
0 : |- svchost.exe (7316)
0 : |- svchost.exe (7476)
0 : |- svchost.exe (7484)
0 : |- avpsus.exe (752)
0 : |- svchost.exe (7560)
0 : |- spsaneragnt.exe (7592)
0 : |- spfileindexer.exe (4860)
0 : |- svchost.exe (8316)
0 : |- svchost.exe (8536)
0 : |- svchost.exe (9112)
0 : |- svchost.exe (9412)
10 : |- svchost.exe (9520)
0 : |- SecurityHealthService.exe (9848)
0 : |- lsass.exe (868)
1 : csrss.exe (724)
1 : winlogon.exe (788)
1 : |- dwm.exe (1280)
1 : |- fontdrvhost.exe (88)

Process_Information_172.17.100.35.csv : information about the running process.
70331 - Microsoft Windows Process Module Information
-
Synopsis
Use WMI to obtain running process module information.
Description
Report details on the running processes modules on the machine.

This plugin is informative only and could be used for forensic investigation, malware detection, and to that confirm your system processes conform to your system policies.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/08, Modified: 2025/12/15
Plugin Output

tcp/0

Process_Modules_172.17.100.35.csv : lists the loaded modules for each process.

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/135/epmap


The Win32 process 'svchost.exe' is listening on this port (pid 516).

This process 'svchost.exe' (pid 516) is hosting the following Windows services :
RpcEptMapper (@%windir%\system32\RpcEpMap.dll,-1001)
RpcSs (@combase.dll,-5010)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/137/netbios-ns


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/138


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/139/smb


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/500


The Win32 process 'svchost.exe' is listening on this port (pid 3456).

This process 'svchost.exe' (pid 3456) is hosting the following Windows services :
IKEEXT (@%SystemRoot%\system32\ikeext.dll,-501)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/1900


The Win32 process 'svchost.exe' is listening on this port (pid 5252).

This process 'svchost.exe' (pid 5252) is hosting the following Windows services :
SSDPSRV (@%systemroot%\system32\ssdpsrv.dll,-100)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/2323/www


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/3389/msrdp


The Win32 process 'svchost.exe' is listening on this port (pid 1116).

This process 'svchost.exe' (pid 1116) is hosting the following Windows services :
TermService (@%SystemRoot%\System32\termsrv.dll,-268)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/3389


The Win32 process 'svchost.exe' is listening on this port (pid 1116).

This process 'svchost.exe' (pid 1116) is hosting the following Windows services :
TermService (@%SystemRoot%\System32\termsrv.dll,-268)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/3702


The Win32 process 'svchost.exe' is listening on this port (pid 7560).

This process 'svchost.exe' (pid 7560) is hosting the following Windows services :
FDResPub (@%systemroot%\system32\fdrespub.dll,-100)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/4500


The Win32 process 'svchost.exe' is listening on this port (pid 3456).

This process 'svchost.exe' (pid 3456) is hosting the following Windows services :
IKEEXT (@%SystemRoot%\system32\ikeext.dll,-501)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/5040


The Win32 process 'svchost.exe' is listening on this port (pid 5180).

This process 'svchost.exe' (pid 5180) is hosting the following Windows services :
CDPSvc (@%SystemRoot%\system32\cdpsvc.dll,-100)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/5050


The Win32 process 'svchost.exe' is listening on this port (pid 5180).

This process 'svchost.exe' (pid 5180) is hosting the following Windows services :
CDPSvc (@%SystemRoot%\system32\cdpsvc.dll,-100)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/5353


The Win32 process 'svchost.exe' is listening on this port (pid 2672).

This process 'svchost.exe' (pid 2672) is hosting the following Windows services :
Dnscache (@%SystemRoot%\System32\dnsapi.dll,-101)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/5355/llmnr


The Win32 process 'svchost.exe' is listening on this port (pid 2672).

This process 'svchost.exe' (pid 2672) is hosting the following Windows services :
Dnscache (@%SystemRoot%\System32\dnsapi.dll,-101)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/5357/www


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/5800/www


The Win32 process 'tvnserver.exe' is listening on this port (pid 3748).

This process 'tvnserver.exe' (pid 3748) is hosting the following Windows services :
tvnserver (TightVNC Server)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/5900/vnc


The Win32 process 'tvnserver.exe' is listening on this port (pid 3748).

This process 'tvnserver.exe' (pid 3748) is hosting the following Windows services :
tvnserver (TightVNC Server)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/15000


The Win32 process 'klnagent.exe' is listening on this port (pid 11396).

This process 'klnagent.exe' (pid 11396) is hosting the following Windows services :
klnagent (Kaspersky Security Center Network Agent)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49664/dce-rpc


The Win32 process 'lsass.exe' is listening on this port (pid 868).

This process 'lsass.exe' (pid 868) is hosting the following Windows services :
EFS (@%SystemRoot%\system32\efssvc.dll,-100)
KeyIso (@keyiso.dll,-100)
SamSs (@%SystemRoot%\system32\samsrv.dll,-1)
VaultSvc (@%SystemRoot%\system32\vaultsvc.dll,-1003)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49665/dce-rpc


The Win32 process 'wininit.exe' is listening on this port (pid 716).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49666/dce-rpc


The Win32 process 'svchost.exe' is listening on this port (pid 1232).

This process 'svchost.exe' (pid 1232) is hosting the following Windows services :
EventLog (@%SystemRoot%\system32\wevtsvc.dll,-200)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49667/dce-rpc


The Win32 process 'svchost.exe' is listening on this port (pid 1532).

This process 'svchost.exe' (pid 1532) is hosting the following Windows services :
Schedule (@%SystemRoot%\system32\schedsvc.dll,-100)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49668/dce-rpc


The Win32 process 'svchost.exe' is listening on this port (pid 2968).

This process 'svchost.exe' (pid 2968) is hosting the following Windows services :
SessionEnv (@%SystemRoot%\System32\SessEnv.dll,-1026)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49669/dce-rpc


The Win32 process 'services.exe' is listening on this port (pid 860).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49670/dce-rpc


The Win32 process 'svchost.exe' is listening on this port (pid 3464).

This process 'svchost.exe' (pid 3464) is hosting the following Windows services :
PolicyAgent (@%SystemRoot%\System32\polstore.dll,-5010)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/50008


The Win32 process 'svchost.exe' is listening on this port (pid 5252).

This process 'svchost.exe' (pid 5252) is hosting the following Windows services :
SSDPSRV (@%systemroot%\system32\ssdpsrv.dll,-100)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/51969


The Win32 process 'svchost.exe' is listening on this port (pid 7560).

This process 'svchost.exe' (pid 7560) is hosting the following Windows services :
FDResPub (@%systemroot%\system32\fdrespub.dll,-100)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/51971


The Win32 process 'dasHost.exe' is listening on this port (pid 4068).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/62039


The Win32 process 'svchost.exe' is listening on this port (pid 3088).

This process 'svchost.exe' (pid 3088) is hosting the following Windows services :
Winmgmt (@%Systemroot%\system32\wbem\wmisvc.dll,-205)

126527 - Microsoft Windows SAM user enumeration
-
Synopsis
Nessus was able to enumerate domain users from the local SAM.
Description
Using the domain security identifier (SID), Nessus was able to enumerate the domain users on the remote Windows system using the Security Accounts Manager.

Note: Unable to obtain SMB SAMR user data during Agent scans.
Rendering User data obtained by plugin 171956
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2019/07/08, Modified: 2025/06/04
Plugin Output

tcp/0

- DefaultAccount (id S-1-5-21-2193062927-1383316644-503, A user account managed by the system.)
- Guest (id S-1-5-21-2193062927-1383316644-501, Built-in account for guest access to the computer/domain, Guest account)
- LKPAdmin (id S-1-5-21-2193062927-1383316644-1001)

17651 - Microsoft Windows SMB : Obtains the Password Policy
-
Synopsis
It is possible to retrieve the remote host's password policy using the supplied credentials.
Description
Using the supplied credentials it was possible to extract the password policy for the remote Windows host. The password policy must conform to the Informational System Policy.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2005/03/30, Modified: 2015/01/12
Plugin Output

tcp/445/cifs

The following password policy is defined on the remote host:

Minimum password len: 0
Password history len: 0
Maximum password age (d): 42
Password must meet complexity requirements: Disabled
Minimum password age (d): 0
Forced logoff time (s): Not set
Locked account time (s): 1800
Time between failed logon (s): 1800
Number of invalid logon before locked out (s): 0
38689 - Microsoft Windows SMB Last Logged On User Disclosure
-
Synopsis
Nessus was able to identify the last logged on user on the remote host.
Description
By connecting to the remote host with the supplied credentials, Nessus was able to identify the username associated with the last successful logon.

Microsoft documentation notes that interactive console logons change the DefaultUserName registry entry to be the last logged-on user.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/05/05, Modified: 2019/09/02
Plugin Output

tcp/445/cifs


Last Successful logon : .\Techrobot
10394 - Microsoft Windows SMB Log In Possible
-
Synopsis
It was possible to log into the remote host.
Description
The remote host is running a Microsoft Windows operating system or Samba, a CIFS/SMB server for Unix. It was possible to log into it using one of the following accounts :

- Guest account
- Supplied credentials
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2000/05/09, Modified: 2025/07/21
Plugin Output

tcp/445/cifs

- The SMB tests will be done as tidua/******
10859 - Microsoft Windows SMB LsaQueryInformationPolicy Function SID Enumeration
-
Synopsis
It is possible to obtain the host SID for the remote host.
Description
By emulating the call to LsaQueryInformationPolicy(), it was possible to obtain the host SID (Security Identifier).

The host SID can then be used to get the list of local users.
See Also
Solution
You can prevent anonymous lookups of the host SID by setting the 'RestrictAnonymous' registry setting to an appropriate value.

Refer to the 'See also' section for guidance.
Risk Factor
None
Plugin Information
Published: 2002/02/13, Modified: 2024/01/31
Plugin Output

tcp/445/cifs


The remote host SID value is : S-1-5-21-2193062927-1383316644-2198579232

The value of 'RestrictAnonymous' setting is : 0
10785 - Microsoft Windows SMB NativeLanManager Remote System Information Disclosure
-
Synopsis
It was possible to obtain information about the remote operating system.
Description
Nessus was able to obtain the remote operating system name and version (Windows and/or Samba) by sending an authentication request to port 139 or 445. Note that this plugin requires SMB to be enabled on the host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/10/17, Modified: 2021/09/20
Plugin Output

tcp/445/cifs

Nessus was able to obtain the following information about the host, by
parsing the SMB2 Protocol's NTLM SSP message:

Target Name: LIVETECHROBO
NetBIOS Domain Name: LIVETECHROBO
NetBIOS Computer Name: LIVETECHROBO
DNS Domain Name: LiveTechRobo
DNS Computer Name: LiveTechRobo
DNS Tree Name: unknown
Product Version: 10.0.19041
48942 - Microsoft Windows SMB Registry : OS Version and Processor Architecture
-
Synopsis
It was possible to determine the processor architecture, build lab strings, and Windows OS version installed on the remote system.
Description
Nessus was able to determine the processor architecture, build lab strings, and the Windows OS version installed on the remote system by connecting to the remote registry with the supplied credentials.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/08/31, Modified: 2022/02/01
Plugin Output

tcp/445/cifs

Operating system version = 10.19045
Architecture = x64
Build lab extended = 19041.1.amd64fre.vb_release.191206-1406
11457 - Microsoft Windows SMB Registry : Winlogon Cached Password Weakness
-
Synopsis
User credentials are stored in memory.
Description
The registry key 'HKLM\Software\Microsoft\WindowsNT\CurrentVersion\ Winlogon\CachedLogonsCount' is not 0. Using a value greater than 0 for the CachedLogonsCount key indicates that the remote Windows host locally caches the passwords of the users when they login, in order to continue to allow the users to login in the case of the failure of the primary domain controller (PDC).

Cached logon credentials could be accessed by an attacker and subjected to brute force attacks.
See Also
Solution
Consult Microsoft documentation and best practices.
Risk Factor
None
Plugin Information
Published: 2003/03/24, Modified: 2018/06/05
Plugin Output

tcp/445/cifs


Max cached logons : 10
10400 - Microsoft Windows SMB Registry Remotely Accessible
-
Synopsis
Access the remote Windows Registry.
Description
It was possible to access the remote Windows Registry using the login / password combination used for the Windows local checks (SMB tests).
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2000/05/09, Modified: 2025/12/16
Plugin Output

tcp/445/cifs

44401 - Microsoft Windows SMB Service Config Enumeration
-
Synopsis
It was possible to enumerate configuration parameters of remote services.
Description
Nessus was able to obtain, via the SMB protocol, the launch parameters of each active service on the remote host (executable path, logon type, etc.).
Solution
Ensure that each service is configured properly.
Risk Factor
None
References
XREF IAVT:0001-T-0752
Plugin Information
Published: 2010/02/05, Modified: 2022/05/16
Plugin Output

tcp/445/cifs


The following services are set to start automatically :

AVP.KES.21.15 startup parameters :
Display name : Kaspersky Endpoint Security Service (KES.21.15)
Service name : AVP.KES.21.15
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avp.exe" -r

AudioEndpointBuilder startup parameters :
Display name : Windows Audio Endpoint Builder
Service name : AudioEndpointBuilder
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p

Audiosrv startup parameters :
Display name : Windows Audio
Service name : Audiosrv
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : AudioEndpointBuilder/RpcSs/

AzureAttestService startup parameters :
Display name : AzureAttestService
Service name : AzureAttestService
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k AzureAttestService

BFE startup parameters :
Display name : Base Filtering Engine
Service name : BFE
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p
Dependencies : RpcSs/

BITS startup parameters :
Display name : Background Intelligent Transfer Service
Service name : BITS
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/

BrokerInfrastructure startup parameters :
Display name : Background Tasks Infrastructure Service
Service name : BrokerInfrastructure
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p
Dependencies : RpcEptMapper/DcomLaunch/RpcSs/

CDPSvc startup parameters :
Display name : Connected Devices Platform Service
Service name : CDPSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalService -p
Dependencies : ncbservice/RpcSS/Tcpip/

CDPUserSvc_50c7d startup parameters :
Display name : Connected Devices Platform User Service_50c7d
Service name : CDPUserSvc_50c7d
Executable path : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup

CDPUserSvc_5bcf85da startup parameters :
Display name : Connected Devices Platform User Service_5bcf85da
Service name : CDPUserSvc_5bcf85da
Executable path : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup

CoreMessagingRegistrar startup parameters :
Display name : CoreMessaging
Service name : CoreMessagingRegistrar
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork -p
Dependencies : rpcss/

CryptSvc startup parameters :
Display name : Cryptographic Services
Service name : CryptSvc
Log on as : NT Authority\NetworkService
Executable path : C:\WINDOWS\system32\svchost.exe -k NetworkService -p
Dependencies : RpcSs/

DPS startup parameters :
Display name : Diagnostic Policy Service
Service name : DPS
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork -p

DcomLaunch startup parameters :
Display name : DCOM Server Process Launcher
Service name : DcomLaunch
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p

DeviceAssociationService startup parameters :
Display name : Device Association Service
Service name : DeviceAssociationService
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p

Dhcp startup parameters :
Display name : DHCP Client
Service name : Dhcp
Log on as : NT Authority\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : NSI/Afd/

DiagTrack startup parameters :
Display name : Connected User Experiences and Telemetry
Service name : DiagTrack
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k utcsvc -p
Dependencies : RpcSs/

DispBrokerDesktopSvc startup parameters :
Display name : Display Policy Service
Service name : DispBrokerDesktopSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalService -p
Dependencies : RpcSS/

Dnscache startup parameters :
Display name : DNS Client
Service name : Dnscache
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\system32\svchost.exe -k NetworkService -p
Dependencies : nsi/Afd/

DoSvc startup parameters :
Display name : Delivery Optimization
Service name : DoSvc
Log on as : NT Authority\NetworkService
Executable path : C:\WINDOWS\System32\svchost.exe -k NetworkService -p
Dependencies : rpcss/

DusmSvc startup parameters :
Display name : Data Usage
Service name : DusmSvc
Log on as : NT Authority\LocalService
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : RpcSs/

EventLog startup parameters :
Display name : Windows Event Log
Service name : EventLog
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p

EventSystem startup parameters :
Display name : COM+ Event System
Service name : EventSystem
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalService -p
Dependencies : rpcss/

FontCache startup parameters :
Display name : Windows Font Cache Service
Service name : FontCache
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalService -p

GoogleUpdaterInternalService144.0.7547.0 startup parameters :
Display name : Google Updater Internal Service (GoogleUpdaterInternalService144.0.7547.0)
Service name : GoogleUpdaterInternalService144.0.7547.0
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.0\updater.exe" --system --windows-service --service=update-internal
Dependencies : RPCSS/

GoogleUpdaterService144.0.7547.0 startup parameters :
Display name : Google Updater Service (GoogleUpdaterService144.0.7547.0)
Service name : GoogleUpdaterService144.0.7547.0
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.0\updater.exe" --system --windows-service --service=update
Dependencies : RPCSS/

IKEEXT startup parameters :
Display name : IKE and AuthIP IPsec Keying Modules
Service name : IKEEXT
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p
Dependencies : BFE/nsi/

LSM startup parameters :
Display name : Local Session Manager
Service name : LSM
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p
Dependencies : RpcEptMapper/DcomLaunch/RpcSs/

LanmanServer startup parameters :
Display name : Server
Service name : LanmanServer
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p
Dependencies : SamSS/Srv2/

LanmanWorkstation startup parameters :
Display name : Workstation
Service name : LanmanWorkstation
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\System32\svchost.exe -k NetworkService -p
Dependencies : Bowser/MRxSmb20/NSI/

MSSQLLaunchpad startup parameters :
Display name : SQL Server Launchpad (MSSQLSERVER)
Service name : MSSQLLaunchpad
Log on as : NT Service\MSSQLLaunchpad
Executable path : "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\launchpad.exe" -launcher RLauncher.dll -launcher Pythonlauncher.dll -launcher commonlauncher.dll -pipename sqlsatellitelaunch -timeout 600000 -logPath "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\LOG\ExtensibilityLog" -workingDir "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExtensibilityData" -externalLanguagesTempDir "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLanguagesTemp" -externalLanguagesDir "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLanguages" -externalLibrariesTempDir "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLibrariesTemp" -externalLibrariesDir "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLibraries" -satelliteDllPath "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlsatellite.dll"
Dependencies : MSSQLServer/

MapsBroker startup parameters :
Display name : Downloaded Maps Manager
Service name : MapsBroker
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\System32\svchost.exe -k NetworkService -p
Dependencies : rpcss/

NlaSvc startup parameters :
Display name : Network Location Awareness
Service name : NlaSvc
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\System32\svchost.exe -k NetworkService -p
Dependencies : NSI/RpcSs/TcpIp/Dhcp/Eventlog/

OneSyncSvc_50c7d startup parameters :
Display name : Sync Host_50c7d
Service name : OneSyncSvc_50c7d
Executable path : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup

OneSyncSvc_5bcf85da startup parameters :
Display name : Sync Host_5bcf85da
Service name : OneSyncSvc_5bcf85da
Executable path : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup

Power startup parameters :
Display name : Power
Service name : Power
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p

ProfSvc startup parameters :
Display name : User Profile Service
Service name : ProfSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/

RasMan startup parameters :
Display name : Remote Access Connection Manager
Service name : RasMan
Log on as : localSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k netsvcs
Dependencies : SstpSvc/DnsCache/

RpcEptMapper startup parameters :
Display name : RPC Endpoint Mapper
Service name : RpcEptMapper
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\system32\svchost.exe -k RPCSS -p

RpcSs startup parameters :
Display name : Remote Procedure Call (RPC)
Service name : RpcSs
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\system32\svchost.exe -k rpcss -p
Dependencies : RpcEptMapper/DcomLaunch/

SENS startup parameters :
Display name : System Event Notification Service
Service name : SENS
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p
Dependencies : EventSystem/

SQLTELEMETRY startup parameters :
Display name : SQL Server CEIP service (MSSQLSERVER)
Service name : SQLTELEMETRY
Log on as : NT Service\SQLTELEMETRY
Executable path : "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlceip.exe" -Service

SQLWriter startup parameters :
Display name : SQL Server VSS Writer
Service name : SQLWriter
Log on as : LocalSystem
Executable path : "C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"

SamSs startup parameters :
Display name : Security Accounts Manager
Service name : SamSs
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\lsass.exe
Dependencies : RPCSS/

Schedule startup parameters :
Display name : Task Scheduler
Service name : Schedule
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p
Dependencies : RPCSS/SystemEventsBroker/

SecPod Saner Agent startup parameters :
Display name : SecPod Saner Agent
Service name : SecPod Saner Agent
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\SecPod Saner\Agent\bin\spsaneragnt.exe"

ShellHWDetection startup parameters :
Display name : Shell Hardware Detection
Service name : ShellHWDetection
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/

StorSvc startup parameters :
Display name : Storage Service
Service name : StorSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p

SysMain startup parameters :
Display name : SysMain
Service name : SysMain
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : rpcss/fileinfo/

SystemEventsBroker startup parameters :
Display name : System Events Broker
Service name : SystemEventsBroker
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p
Dependencies : RpcEptMapper/RpcSs/

Themes startup parameters :
Display name : Themes
Service name : Themes
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k netsvcs -p

TrkWks startup parameters :
Display name : Distributed Link Tracking Client
Service name : TrkWks
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/

UserManager startup parameters :
Display name : User Manager
Service name : UserManager
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/ProfSvc/

UsoSvc startup parameters :
Display name : Update Orchestrator Service
Service name : UsoSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

VGAuthService startup parameters :
Display name : VMware Alias Manager and Ticket Service
Service name : VGAuthService
Log on as : LocalSystem
Executable path : "C:\Program Files\VMware\VMware Tools\VMware VGAuth\VGAuthService.exe"

VMTools startup parameters :
Display name : VMware Tools
Service name : VMTools
Log on as : LocalSystem
Executable path : "C:\Program Files\VMware\VMware Tools\vmtoolsd.exe"

WSearch startup parameters :
Display name : Windows Search
Service name : WSearch
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\SearchIndexer.exe /Embedding
Dependencies : RPCSS/BrokerInfrastructure/

Wcmsvc startup parameters :
Display name : Windows Connection Manager
Service name : Wcmsvc
Log on as : NT Authority\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : RpcSs/NSI/

Winmgmt startup parameters :
Display name : Windows Management Instrumentation
Service name : Winmgmt
Log on as : localSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p
Dependencies : RPCSS/

WpnService startup parameters :
Display name : Windows Push Notifications System Service
Service name : WpnService
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

WpnUserService_50c7d startup parameters :
Display name : Windows Push Notifications User Service_50c7d
Service name : WpnUserService_50c7d
Executable path : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup

WpnUserService_5bcf85da startup parameters :
Display name : Windows Push Notifications User Service_5bcf85da
Service name : WpnUserService_5bcf85da
Executable path : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup

avpsus.KES.21.15 startup parameters :
Display name : Kaspersky Seamless Update Service (KES.21.15)
Service name : avpsus.KES.21.15
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avpsus.exe"

edgeupdate startup parameters :
Display name : Microsoft Edge Update Service (edgeupdate)
Service name : edgeupdate
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svc
Dependencies : RPCSS/

gpsvc startup parameters :
Display name : Group Policy Client
Service name : gpsvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p
Dependencies : RPCSS/Mup/

iphlpsvc startup parameters :
Display name : IP Helper
Service name : iphlpsvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k NetSvcs -p
Dependencies : RpcSS/winmgmt/tcpip/nsi/WinHttpAutoProxySvc/

klnagent startup parameters :
Display name : Kaspersky Security Center Network Agent
Service name : klnagent
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\klnagent.exe"

mpssvc startup parameters :
Display name : Windows Defender Firewall
Service name : mpssvc
Log on as : NT Authority\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p
Dependencies : mpsdrv/bfe/

nsi startup parameters :
Display name : Network Store Interface Service
Service name : nsi
Log on as : NT Authority\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalService -p
Dependencies : rpcss/nsiproxy/

sppsvc startup parameters :
Display name : Software Protection
Service name : sppsvc
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\system32\sppsvc.exe
Dependencies : RpcSs/

tvnserver startup parameters :
Display name : TightVNC Server
Service name : tvnserver
Log on as : LocalSystem
Executable path : "C:\Program Files\TightVNC\tvnserver.exe" -service

vm3dservice startup parameters :
Display name : VMware SVGA Helper Service
Service name : vm3dservice
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\vm3dservice.exe

wscsvc startup parameters :
Display name : Security Center
Service name : wscsvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : RpcSs/

The following services must be started manually :

AJRouter startup parameters :
Display name : AllJoyn Router Service
Service name : AJRouter
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p

ALG startup parameters :
Display name : Application Layer Gateway Service
Service name : ALG
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\System32\alg.exe

AarSvc_50c7d startup parameters :
Display name : Agent Activation Runtime_50c7d
Service name : AarSvc_50c7d
Executable path : C:\WINDOWS\system32\svchost.exe -k AarSvcGroup -p

AarSvc_5bcf85da startup parameters :
Display name : Agent Activation Runtime_5bcf85da
Service name : AarSvc_5bcf85da
Executable path : C:\WINDOWS\system32\svchost.exe -k AarSvcGroup -p

AppIDSvc startup parameters :
Display name : Application Identity
Service name : AppIDSvc
Log on as : NT Authority\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : RpcSs/AppID/CryptSvc/

AppMgmt startup parameters :
Display name : Application Management
Service name : AppMgmt
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p

AppReadiness startup parameters :
Display name : App Readiness
Service name : AppReadiness
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k AppReadiness -p

AppXSvc startup parameters :
Display name : AppX Deployment Service (AppXSVC)
Service name : AppXSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k wsappx -p
Dependencies : rpcss/staterepository/

Appinfo startup parameters :
Display name : Application Information
Service name : Appinfo
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/ProfSvc/

AssignedAccessManagerSvc startup parameters :
Display name : AssignedAccessManager Service
Service name : AssignedAccessManagerSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k AssignedAccessManagerSvc

AxInstSV startup parameters :
Display name : ActiveX Installer (AxInstSV)
Service name : AxInstSV
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k AxInstSVGroup
Dependencies : rpcss/

BDESVC startup parameters :
Display name : BitLocker Drive Encryption Service
Service name : BDESVC
Log on as : localSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k netsvcs -p

BTAGService startup parameters :
Display name : Bluetooth Audio Gateway Service
Service name : BTAGService
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
Dependencies : rpcss/

BcastDVRUserService_50c7d startup parameters :
Display name : GameDVR and Broadcast User Service_50c7d
Service name : BcastDVRUserService_50c7d
Executable path : C:\WINDOWS\system32\svchost.exe -k BcastDVRUserService

BcastDVRUserService_5bcf85da startup parameters :
Display name : GameDVR and Broadcast User Service_5bcf85da
Service name : BcastDVRUserService_5bcf85da
Executable path : C:\WINDOWS\system32\svchost.exe -k BcastDVRUserService

BluetoothUserService_50c7d startup parameters :
Display name : Bluetooth User Support Service_50c7d
Service name : BluetoothUserService_50c7d
Executable path : C:\WINDOWS\system32\svchost.exe -k BthAppGroup -p

BluetoothUserService_5bcf85da startup parameters :
Display name : Bluetooth User Support Service_5bcf85da
Service name : BluetoothUserService_5bcf85da
Executable path : C:\WINDOWS\system32\svchost.exe -k BthAppGroup -p

BthAvctpSvc startup parameters :
Display name : AVCTP service
Service name : BthAvctpSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalService -p
Dependencies : rpcss/

COMSysApp startup parameters :
Display name : COM+ System Application
Service name : COMSysApp
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
Dependencies : RpcSs/EventSystem/SENS/

CaptureService_50c7d startup parameters :
Display name : CaptureService_50c7d
Service name : CaptureService_50c7d
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalService -p

CaptureService_5bcf85da startup parameters :
Display name : CaptureService_5bcf85da
Service name : CaptureService_5bcf85da
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalService -p

CertPropSvc startup parameters :
Display name : Certificate Propagation
Service name : CertPropSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs
Dependencies : RpcSs/

ClipSVC startup parameters :
Display name : Client License Service (ClipSVC)
Service name : ClipSVC
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k wsappx -p
Dependencies : rpcss/

ConsentUxUserSvc_50c7d startup parameters :
Display name : ConsentUX_50c7d
Service name : ConsentUxUserSvc_50c7d
Executable path : C:\WINDOWS\system32\svchost.exe -k DevicesFlow

ConsentUxUserSvc_5bcf85da startup parameters :
Display name : ConsentUX_5bcf85da
Service name : ConsentUxUserSvc_5bcf85da
Executable path : C:\WINDOWS\system32\svchost.exe -k DevicesFlow

CredentialEnrollmentManagerUserSvc_50c7d startup parameters :
Display name : CredentialEnrollmentManagerUserSvc_50c7d
Service name : CredentialEnrollmentManagerUserSvc_50c7d
Executable path : C:\WINDOWS\system32\CredentialEnrollmentManager.exe

CredentialEnrollmentManagerUserSvc_5bcf85da startup parameters :
Display name : CredentialEnrollmentManagerUserSvc_5bcf85da
Service name : CredentialEnrollmentManagerUserSvc_5bcf85da
Executable path : C:\WINDOWS\system32\CredentialEnrollmentManager.exe

CscService startup parameters :
Display name : Offline Files
Service name : CscService
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/

DevQueryBroker startup parameters :
Display name : DevQuery Background Discovery Broker
Service name : DevQueryBroker
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p

DeviceAssociationBrokerSvc_50c7d startup parameters :
Display name : DeviceAssociationBroker_50c7d
Service name : DeviceAssociationBrokerSvc_50c7d
Executable path : C:\WINDOWS\system32\svchost.exe -k DevicesFlow -p

DeviceAssociationBrokerSvc_5bcf85da startup parameters :
Display name : DeviceAssociationBroker_5bcf85da
Service name : DeviceAssociationBrokerSvc_5bcf85da
Executable path : C:\WINDOWS\system32\svchost.exe -k DevicesFlow -p

DeviceInstall startup parameters :
Display name : Device Install Service
Service name : DeviceInstall
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p

DevicePickerUserSvc_50c7d startup parameters :
Display name : DevicePicker_50c7d
Service name : DevicePickerUserSvc_50c7d
Executable path : C:\WINDOWS\system32\svchost.exe -k DevicesFlow

DevicePickerUserSvc_5bcf85da startup parameters :
Display name : DevicePicker_5bcf85da
Service name : DevicePickerUserSvc_5bcf85da
Executable path : C:\WINDOWS\system32\svchost.exe -k DevicesFlow

DevicesFlowUserSvc_50c7d startup parameters :
Display name : DevicesFlow_50c7d
Service name : DevicesFlowUserSvc_50c7d
Executable path : C:\WINDOWS\system32\svchost.exe -k DevicesFlow

DevicesFlowUserSvc_5bcf85da startup parameters :
Display name : DevicesFlow_5bcf85da
Service name : DevicesFlowUserSvc_5bcf85da
Executable path : C:\WINDOWS\system32\svchost.exe -k DevicesFlow

DisplayEnhancementService startup parameters :
Display name : Display Enhancement Service
Service name : DisplayEnhancementService
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p

DmEnrollmentSvc startup parameters :
Display name : Device Management Enrollment Service
Service name : DmEnrollmentSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

DsSvc startup parameters :
Display name : Data Sharing Service
Service name : DsSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p

DsmSvc startup parameters :
Display name : Device Setup Manager
Service name : DsmSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/

EFS startup parameters :
Display name : Encrypting File System (EFS)
Service name : EFS
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\lsass.exe
Dependencies : RPCSS/

Eaphost startup parameters :
Display name : Extensible Authentication Protocol
Service name : Eaphost
Log on as : localSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k netsvcs -p
Dependencies : RPCSS/KeyIso/

EntAppSvc startup parameters :
Display name : Enterprise App Management Service
Service name : EntAppSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k appmodel -p
Dependencies : rpcss/

FDResPub startup parameters :
Display name : Function Discovery Resource Publication
Service name : FDResPub
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
Dependencies : RpcSs/http/fdphost/

FontCache3.0.0.0 startup parameters :
Display name : Windows Presentation Foundation Font Cache 3.0.0.0
Service name : FontCache3.0.0.0
Log on as : NT Authority\LocalService
Executable path : C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe

FrameServer startup parameters :
Display name : Windows Camera Frame Server
Service name : FrameServer
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k Camera
Dependencies : rpcss/

GameInputSvc startup parameters :
Display name : GameInput Service
Service name : GameInputSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\GameInputSvc.exe

GoogleChromeElevationService startup parameters :
Display name : Google Chrome Elevation Service (GoogleChromeElevationService)
Service name : GoogleChromeElevationService
Log on as : LocalSystem
Executable path : "C:\Program Files\Google\Chrome\Application\143.0.7499.193\elevation_service.exe"
Dependencies : RPCSS/

GraphicsPerfSvc startup parameters :
Display name : GraphicsPerfSvc
Service name : GraphicsPerfSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k GraphicsPerfSvcGroup

HvHost startup parameters :
Display name : HV Host Service
Service name : HvHost
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : hvservice/

InstallService startup parameters :
Display name : Microsoft Store Install Service
Service name : InstallService
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

IpxlatCfgSvc startup parameters :
Display name : IP Translation Configuration Service
Service name : IpxlatCfgSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : nsi/

KeyIso startup parameters :
Display name : CNG Key Isolation
Service name : KeyIso
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\lsass.exe
Dependencies : RpcSs/

KtmRm startup parameters :
Display name : KtmRm for Distributed Transaction Coordinator
Service name : KtmRm
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\System32\svchost.exe -k NetworkServiceAndNoImpersonation -p
Dependencies : RPCSS/SamSS/

LicenseManager startup parameters :
Display name : Windows License Manager Service
Service name : LicenseManager
Log on as : NT Authority\LocalService
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalService -p
Dependencies : rpcss/

LxpSvc startup parameters :
Display name : Language Experience Service
Service name : LxpSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs

MSDTC startup parameters :
Display name : Distributed Transaction Coordinator
Service name : MSDTC
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\System32\msdtc.exe
Dependencies : RPCSS/SamSS/

MSSQLFDLauncher startup parameters :
Display name : SQL Full-text Filter Daemon Launcher (MSSQLSERVER)
Service name : MSSQLFDLauncher
Log on as : NT Service\MSSQLFDLauncher
Executable path : "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL15.MSSQLSERVER

MSiSCSI startup parameters :
Display name : Microsoft iSCSI Initiator Service
Service name : MSiSCSI
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p

McpManagementService startup parameters :
Display name : McpManagementService
Service name : McpManagementService
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k McpManagementServiceGroup
Dependencies : RpcSs/

MessagingService_50c7d startup parameters :
Display name : MessagingService_50c7d
Service name : MessagingService_50c7d
Executable path : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup

MessagingService_5bcf85da startup parameters :
Display name : MessagingService_5bcf85da
Service name : MessagingService_5bcf85da
Executable path : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup

MicrosoftEdgeElevationService startup parameters :
Display name : Microsoft Edge Elevation Service (MicrosoftEdgeElevationService)
Service name : MicrosoftEdgeElevationService
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Microsoft\Edge\Application\92.0.902.67\elevation_service.exe"
Dependencies : RPCSS/

MixedRealityOpenXRSvc startup parameters :
Display name : Windows Mixed Reality OpenXR Service
Service name : MixedRealityOpenXRSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : rpcss/

MozillaMaintenance startup parameters :
Display name : Mozilla Maintenance Service
Service name : MozillaMaintenance
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe"

MsMpiLaunchSvc startup parameters :
Display name : MS-MPI Launch Service
Service name : MsMpiLaunchSvc
Log on as : LocalSystem
Executable path : "C:\Program Files\Microsoft MPI\Bin\msmpilaunchsvc.exe"

NaturalAuthentication startup parameters :
Display name : Natural Authentication
Service name : NaturalAuthentication
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/ProfSvc/Schedule/

NcaSvc startup parameters :
Display name : Network Connectivity Assistant
Service name : NcaSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k NetSvcs -p
Dependencies : BFE/dnscache/NSI/iphlpsvc/

NcbService startup parameters :
Display name : Network Connection Broker
Service name : NcbService
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSS/tcpip/BrokerInfrastructure/

NcdAutoSetup startup parameters :
Display name : Network Connected Devices Auto-Setup
Service name : NcdAutoSetup
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork -p
Dependencies : netprofm/

NetSetupSvc startup parameters :
Display name : Network Setup Service
Service name : NetSetupSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/

Netlogon startup parameters :
Display name : Netlogon
Service name : Netlogon
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\lsass.exe
Dependencies : LanmanWorkstation/

Netman startup parameters :
Display name : Network Connections
Service name : Netman
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/nsi/

NgcCtnrSvc startup parameters :
Display name : Microsoft Passport Container
Service name : NgcCtnrSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : RpcSs/

NgcSvc startup parameters :
Display name : Microsoft Passport
Service name : NgcSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/

PNRPAutoReg startup parameters :
Display name : PNRP Machine Name Publication Service
Service name : PNRPAutoReg
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet
Dependencies : pnrpsvc/

PNRPsvc startup parameters :
Display name : Peer Name Resolution Protocol
Service name : PNRPsvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet
Dependencies : p2pimsvc/

PcaSvc startup parameters :
Display name : Program Compatibility Assistant Service
Service name : PcaSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/

PeerDistSvc startup parameters :
Display name : BranchCache
Service name : PeerDistSvc
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\System32\svchost.exe -k PeerDist
Dependencies : http/

PerfHost startup parameters :
Display name : Performance Counter DLL Host
Service name : PerfHost
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\SysWow64\perfhost.exe
Dependencies : RPCSS/

PhoneSvc startup parameters :
Display name : Phone Service
Service name : PhoneSvc
Log on as : NT Authority\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalService -p
Dependencies : RpcSs/

PimIndexMaintenanceSvc_50c7d startup parameters :
Display name : Contact Data_50c7d
Service name : PimIndexMaintenanceSvc_50c7d
Executable path : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup

PimIndexMaintenanceSvc_5bcf85da startup parameters :
Display name : Contact Data_5bcf85da
Service name : PimIndexMaintenanceSvc_5bcf85da
Executable path : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup

PlugPlay startup parameters :
Display name : Plug and Play
Service name : PlugPlay
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p

PolicyAgent startup parameters :
Display name : IPsec Policy Agent
Service name : PolicyAgent
Log on as : NT Authority\NetworkService
Executable path : C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted -p
Dependencies : Tcpip/bfe/

PrintNotify startup parameters :
Display name : Printer Extensions and Notifications
Service name : PrintNotify
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k print
Dependencies : RpcSs/

PrintWorkflowUserSvc_50c7d startup parameters :
Display name : PrintWorkflow_50c7d
Service name : PrintWorkflowUserSvc_50c7d
Executable path : C:\WINDOWS\system32\svchost.exe -k PrintWorkflow

PrintWorkflowUserSvc_5bcf85da startup parameters :
Display name : PrintWorkflow_5bcf85da
Service name : PrintWorkflowUserSvc_5bcf85da
Executable path : C:\WINDOWS\system32\svchost.exe -k PrintWorkflow

PushToInstall startup parameters :
Display name : Windows PushToInstall Service
Service name : PushToInstall
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

QWAVE startup parameters :
Display name : Quality Windows Audio Video Experience
Service name : QWAVE
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
Dependencies : rpcss/psched/QWAVEdrv/LLTDIO/

RasAuto startup parameters :
Display name : Remote Access Auto Connection Manager
Service name : RasAuto
Log on as : localSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k netsvcs -p
Dependencies : RasAcd/

RemoteRegistry startup parameters :
Display name : Remote Registry
Service name : RemoteRegistry
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k localService -p
Dependencies : RPCSS/

RetailDemo startup parameters :
Display name : Retail Demo Service
Service name : RetailDemo
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k rdxgroup

RmSvc startup parameters :
Display name : Radio Management Service
Service name : RmSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
Dependencies : RpcSs/

RpcLocator startup parameters :
Display name : Remote Procedure Call (RPC) Locator
Service name : RpcLocator
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\system32\locator.exe

SCPolicySvc startup parameters :
Display name : Smart Card Removal Policy
Service name : SCPolicySvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs
Dependencies : RpcSs/

SCardSvr startup parameters :
Display name : Smart Card
Service name : SCardSvr
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation

SDRSVC startup parameters :
Display name : Windows Backup
Service name : SDRSVC
Log on as : localSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k SDRSVC
Dependencies : RPCSS/

SEMgrSvc startup parameters :
Display name : Payments and NFC/SE Manager
Service name : SEMgrSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalService -p
Dependencies : RpcSs/

SNMPTRAP startup parameters :
Display name : SNMP Trap
Service name : SNMPTRAP
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\System32\snmptrap.exe

SSDPSRV startup parameters :
Display name : SSDP Discovery
Service name : SSDPSRV
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
Dependencies : HTTP/NSI/

ScDeviceEnum startup parameters :
Display name : Smart Card Device Enumeration Service
Service name : ScDeviceEnum
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted

SecPod Saner Upgrade Controller v2 startup parameters :
Display name : SecPod Saner Upgrade Controller v2
Service name : SecPod Saner Upgrade Controller v2
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\SecPod Saner\Upgrader\bin\spupgradecontroller.exe"

SecurityHealthService startup parameters :
Display name : Windows Security Service
Service name : SecurityHealthService
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\SecurityHealthService.exe
Dependencies : RpcSs/

Sense startup parameters :
Display name : Windows Defender Advanced Threat Protection Service
Service name : Sense
Log on as : LocalSystem
Executable path : "C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe"

SensorDataService startup parameters :
Display name : Sensor Data Service
Service name : SensorDataService
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\SensorDataService.exe

SensorService startup parameters :
Display name : Sensor Service
Service name : SensorService
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p

SensrSvc startup parameters :
Display name : Sensor Monitoring Service
Service name : SensrSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation -p

SessionEnv startup parameters :
Display name : Remote Desktop Configuration
Service name : SessionEnv
Log on as : localSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k netsvcs -p
Dependencies : RPCSS/LanmanWorkstation/

SharedAccess startup parameters :
Display name : Internet Connection Sharing (ICS)
Service name : SharedAccess
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k netsvcs -p
Dependencies : BFE/

SharedRealitySvc startup parameters :
Display name : Spatial Data Service
Service name : SharedRealitySvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalService -p
Dependencies : RpcSS/

SmsRouter startup parameters :
Display name : Microsoft Windows SMS Router Service.
Service name : SmsRouter
Log on as : NT Authority\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : RpcSs/

SstpSvc startup parameters :
Display name : Secure Socket Tunneling Protocol Service
Service name : SstpSvc
Log on as : NT Authority\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalService -p

StateRepository startup parameters :
Display name : State Repository Service
Service name : StateRepository
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k appmodel -p
Dependencies : rpcss/

TabletInputService startup parameters :
Display name : Touch Keyboard and Handwriting Panel Service
Service name : TabletInputService
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/

TapiSrv startup parameters :
Display name : Telephony
Service name : TapiSrv
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\System32\svchost.exe -k NetworkService -p
Dependencies : RpcSs/

TermService startup parameters :
Display name : Remote Desktop Services
Service name : TermService
Log on as : NT Authority\NetworkService
Executable path : C:\WINDOWS\System32\svchost.exe -k NetworkService
Dependencies : RPCSS/

TieringEngineService startup parameters :
Display name : Storage Tiers Management
Service name : TieringEngineService
Log on as : localSystem
Executable path : C:\WINDOWS\system32\TieringEngineService.exe

TimeBrokerSvc startup parameters :
Display name : Time Broker
Service name : TimeBrokerSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p

TokenBroker startup parameters :
Display name : Web Account Manager
Service name : TokenBroker
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p
Dependencies : UserManager/

TroubleshootingSvc startup parameters :
Display name : Recommended Troubleshooting Service
Service name : TroubleshootingSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

TrustedInstaller startup parameters :
Display name : Windows Modules Installer
Service name : TrustedInstaller
Log on as : localSystem
Executable path : C:\WINDOWS\servicing\TrustedInstaller.exe

UdkUserSvc_50c7d startup parameters :
Display name : Udk User Service_50c7d
Service name : UdkUserSvc_50c7d
Executable path : C:\WINDOWS\system32\svchost.exe -k UdkSvcGroup

UdkUserSvc_5bcf85da startup parameters :
Display name : Udk User Service_5bcf85da
Service name : UdkUserSvc_5bcf85da
Executable path : C:\WINDOWS\system32\svchost.exe -k UdkSvcGroup

UmRdpService startup parameters :
Display name : Remote Desktop Services UserMode Port Redirector
Service name : UmRdpService
Log on as : localSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : TermService/RDPDR/

UnistoreSvc_50c7d startup parameters :
Display name : User Data Storage_50c7d
Service name : UnistoreSvc_50c7d
Executable path : C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup

UnistoreSvc_5bcf85da startup parameters :
Display name : User Data Storage_5bcf85da
Service name : UnistoreSvc_5bcf85da
Executable path : C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup

UserDataSvc_50c7d startup parameters :
Display name : User Data Access_50c7d
Service name : UserDataSvc_50c7d
Executable path : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup

UserDataSvc_5bcf85da startup parameters :
Display name : User Data Access_5bcf85da
Service name : UserDataSvc_5bcf85da
Executable path : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup

VSS startup parameters :
Display name : Volume Shadow Copy
Service name : VSS
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\vssvc.exe
Dependencies : RPCSS/

VacSvc startup parameters :
Display name : Volumetric Audio Compositor Service
Service name : VacSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : RpcSs/

VaultSvc startup parameters :
Display name : Credential Manager
Service name : VaultSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\lsass.exe
Dependencies : rpcss/

W32Time startup parameters :
Display name : Windows Time
Service name : W32Time
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalService

WEPHOSTSVC startup parameters :
Display name : Windows Encryption Provider Host Service
Service name : WEPHOSTSVC
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k WepHostSvcGroup
Dependencies : rpcss/

WFDSConMgrSvc startup parameters :
Display name : Wi-Fi Direct Services Connection Manager Service
Service name : WFDSConMgrSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : RpcSs/

WMPNetworkSvc startup parameters :
Display name : Windows Media Player Network Sharing Service
Service name : WMPNetworkSvc
Log on as : NT AUTHORITY\NetworkService
Executable path : "C:\Program Files\Windows Media Player\wmpnetwk.exe"
Dependencies : http/WSearch/

WManSvc startup parameters :
Display name : Windows Management Service
Service name : WManSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

WPDBusEnum startup parameters :
Display name : Portable Device Enumerator Service
Service name : WPDBusEnum
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : RpcSs/

WaaSMedicSvc startup parameters :
Display name : Windows Update Medic Service
Service name : WaaSMedicSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k wusvcs -p
Dependencies : rpcss/

WalletService startup parameters :
Display name : WalletService
Service name : WalletService
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k appmodel -p

WarpJITSvc startup parameters :
Display name : WarpJITSvc
Service name : WarpJITSvc
Log on as : NT Authority\LocalService
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted

WbioSrvc startup parameters :
Display name : Windows Biometric Service
Service name : WbioSrvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k WbioSvcGroup
Dependencies : RpcSs/

WdNisSvc startup parameters :
Display name : Microsoft Defender Antivirus Network Inspection Service
Service name : WdNisSvc
Log on as : NT AUTHORITY\LocalService
Executable path : "C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2203.5-0\NisSrv.exe"
Dependencies : WdNisDrv/

WdiServiceHost startup parameters :
Display name : Diagnostic Service Host
Service name : WdiServiceHost
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalService -p

WdiSystemHost startup parameters :
Display name : Diagnostic System Host
Service name : WdiSystemHost
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p

WebClient startup parameters :
Display name : WebClient
Service name : WebClient
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalService -p
Dependencies : MRxDAV/

Wecsvc startup parameters :
Display name : Windows Event Collector
Service name : Wecsvc
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\system32\svchost.exe -k NetworkService -p
Dependencies : HTTP/Eventlog/

WerSvc startup parameters :
Display name : Windows Error Reporting Service
Service name : WerSvc
Log on as : localSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k WerSvcGroup

WiaRpc startup parameters :
Display name : Still Image Acquisition Events
Service name : WiaRpc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/

WinDefend startup parameters :
Display name : Microsoft Defender Antivirus Service
Service name : WinDefend
Log on as : LocalSystem
Executable path : "C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2203.5-0\MsMpEng.exe"
Dependencies : RpcSs/

WinHttpAutoProxySvc startup parameters :
Display name : WinHTTP Web Proxy Auto-Discovery Service
Service name : WinHttpAutoProxySvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : Dhcp/

WinRM startup parameters :
Display name : Windows Remote Management (WS-Management)
Service name : WinRM
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\System32\svchost.exe -k NetworkService -p
Dependencies : RPCSS/HTTP/

WlanSvc startup parameters :
Display name : WLAN AutoConfig
Service name : WlanSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : nativewifip/RpcSs/Ndisuio/wcmsvc/

WpcMonSvc startup parameters :
Display name : Parental Controls
Service name : WpcMonSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalService

WwanSvc startup parameters :
Display name : WWAN AutoConfig
Service name : WwanSvc
Log on as : localSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/NdisUio/

autotimesvc startup parameters :
Display name : Cellular Time
Service name : autotimesvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k autoTimeSvc
Dependencies : rpcss/

bthserv startup parameters :
Display name : Bluetooth Support Service
Service name : bthserv
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalService -p

camsvc startup parameters :
Display name : Capability Access Manager Service
Service name : camsvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k appmodel -p

cbdhsvc_50c7d startup parameters :
Display name : Clipboard User Service_50c7d
Service name : cbdhsvc_50c7d
Executable path : C:\WINDOWS\system32\svchost.exe -k ClipboardSvcGroup -p

cbdhsvc_5bcf85da startup parameters :
Display name : Clipboard User Service_5bcf85da
Service name : cbdhsvc_5bcf85da
Executable path : C:\WINDOWS\system32\svchost.exe -k ClipboardSvcGroup -p

cloudidsvc startup parameters :
Display name : Microsoft Cloud Identity Service
Service name : cloudidsvc
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\system32\svchost.exe -k CloudIdServiceGroup -p

dcsvc startup parameters :
Display name : Declared Configuration(DC) service
Service name : dcsvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

defragsvc startup parameters :
Display name : Optimize drives
Service name : defragsvc
Log on as : localSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k defragsvc
Dependencies : RPCSS/

diagnosticshub.standardcollector.service startup parameters :
Display name : Microsoft (R) Diagnostics Hub Standard Collector Service
Service name : diagnosticshub.standardcollector.service
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe

diagsvc startup parameters :
Display name : Diagnostic Execution Service
Service name : diagsvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k diagnostics
Dependencies : RpcSs/

dmwappushservice startup parameters :
Display name : Device Management Wireless Application Protocol (WAP) Push message Routing Service
Service name : dmwappushservice
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

dot3svc startup parameters :
Display name : Wired AutoConfig
Service name : dot3svc
Log on as : localSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/Ndisuio/Eaphost/

edgeupdatem startup parameters :
Display name : Microsoft Edge Update Service (edgeupdatem)
Service name : edgeupdatem
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /medsvc
Dependencies : RPCSS/

embeddedmode startup parameters :
Display name : Embedded Mode
Service name : embeddedmode
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : BrokerInfrastructure/

fdPHost startup parameters :
Display name : Function Discovery Provider Host
Service name : fdPHost
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalService -p
Dependencies : RpcSs/http/

fhsvc startup parameters :
Display name : File History Service
Service name : fhsvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p
Dependencies : RpcSs/

hidserv startup parameters :
Display name : Human Interface Device Service
Service name : hidserv
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p

icssvc startup parameters :
Display name : Windows Mobile Hotspot Service
Service name : icssvc
Log on as : NT Authority\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : RpcSs/wcmsvc/

ksnproxy startup parameters :
Display name : Kaspersky Security Network proxy server
Service name : ksnproxy
Log on as : NT SERVICE\ksnproxy
Executable path : "C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\ksnproxy.exe"

lfsvc startup parameters :
Display name : Geolocation Service
Service name : lfsvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/

lltdsvc startup parameters :
Display name : Link-Layer Topology Discovery Mapper
Service name : lltdsvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalService -p
Dependencies : rpcss/lltdio/

lmhosts startup parameters :
Display name : TCP/IP NetBIOS Helper
Service name : lmhosts
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : Afd/

msiserver startup parameters :
Display name : Windows Installer
Service name : msiserver
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\msiexec.exe /V
Dependencies : rpcss/

netprofm startup parameters :
Display name : Network List Service
Service name : netprofm
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalService -p
Dependencies : RpcSs/nlasvc/

ose64 startup parameters :
Display name : Office 64 Source Engine
Service name : ose64
Log on as : LocalSystem
Executable path : "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"

p2pimsvc startup parameters :
Display name : Peer Networking Identity Manager
Service name : p2pimsvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet

p2psvc startup parameters :
Display name : Peer Networking Grouping
Service name : p2psvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet
Dependencies : p2pimsvc/PNRPSvc/

perceptionsimulation startup parameters :
Display name : Windows Perception Simulation Service
Service name : perceptionsimulation
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\PerceptionSimulation\PerceptionSimulationService.exe
Dependencies : rpcss/

pla startup parameters :
Display name : Performance Logs & Alerts
Service name : pla
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork -p
Dependencies : RPCSS/

seclogon startup parameters :
Display name : Secondary Logon
Service name : seclogon
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p

smphost startup parameters :
Display name : Microsoft Storage Spaces SMP
Service name : smphost
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\System32\svchost.exe -k smphost
Dependencies : RPCSS/

spectrum startup parameters :
Display name : Windows Perception Service
Service name : spectrum
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\spectrum.exe
Dependencies : rpcss/

stisvc startup parameters :
Display name : Windows Image Acquisition (WIA)
Service name : stisvc
Log on as : NT Authority\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k imgsvc
Dependencies : RpcSs/

svsvc startup parameters :
Display name : Spot Verifier
Service name : svsvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p

swprv startup parameters :
Display name : Microsoft Software Shadow Copy Provider
Service name : swprv
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k swprv
Dependencies : RPCSS/

tzautoupdate startup parameters :
Display name : Auto Time Zone Updater
Service name : tzautoupdate
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalService -p

upnphost startup parameters :
Display name : UPnP Device Host
Service name : upnphost
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
Dependencies : SSDPSRV/HTTP/

vds startup parameters :
Display name : Virtual Disk
Service name : vds
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\vds.exe
Dependencies : RpcSs/

vmicguestinterface startup parameters :
Display name : Hyper-V Guest Service Interface
Service name : vmicguestinterface
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p

vmicheartbeat startup parameters :
Display name : Hyper-V Heartbeat Service
Service name : vmicheartbeat
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k ICService -p

vmickvpexchange startup parameters :
Display name : Hyper-V Data Exchange Service
Service name : vmickvpexchange
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p

vmicrdv startup parameters :
Display name : Hyper-V Remote Desktop Virtualization Service
Service name : vmicrdv
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k ICService -p

vmicshutdown startup parameters :
Display name : Hyper-V Guest Shutdown Service
Service name : vmicshutdown
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p

vmictimesync startup parameters :
Display name : Hyper-V Time Synchronization Service
Service name : vmictimesync
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : VmGid/

vmicvmsession startup parameters :
Display name : Hyper-V PowerShell Direct Service
Service name : vmicvmsession
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p

vmicvss startup parameters :
Display name : Hyper-V Volume Shadow Copy Requestor
Service name : vmicvss
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p

vmvss startup parameters :
Display name : VMware Snapshot Provider
Service name : vmvss
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\dllhost.exe /Processid:{0D7128C9-B843-49CB-A202-40976AA7645B}
Dependencies : rpcss/

wbengine startup parameters :
Display name : Block Level Backup Engine Service
Service name : wbengine
Log on as : localSystem
Executable path : "C:\WINDOWS\system32\wbengine.exe"

wcncsvc startup parameters :
Display name : Windows Connect Now - Config Registrar
Service name : wcncsvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalServiceAndNoImpersonation -p
Dependencies : rpcss/

wercplsupport startup parameters :
Display name : Problem Reports Control Panel Support
Service name : wercplsupport
Log on as : localSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k netsvcs -p

wisvc startup parameters :
Display name : Windows Insider Service
Service name : wisvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

wlidsvc startup parameters :
Display name : Microsoft Account Sign-in Assistant
Service name : wlidsvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/

wlpasvc startup parameters :
Display name : Local Profile Assistant Service
Service name : wlpasvc
Log on as : NT Authority\LocalService
Executable path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p
Dependencies : WwanSvc/RpcSs/

wmiApSrv startup parameters :
Display name : WMI Performance Adapter
Service name : wmiApSrv
Log on as : localSystem
Executable path : C:\WINDOWS\system32\wbem\WmiApSrv.exe

workfolderssvc startup parameters :
Display name : Work Folders
Service name : workfolderssvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\System32\svchost.exe -k LocalService -p
Dependencies : RpcSs/wsearch/

wuauserv startup parameters :
Display name : Windows Update
Service name : wuauserv
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p
Dependencies : rpcss/

The following services are disabled :

AppVClient startup parameters :
Display name : Microsoft App-V Client
Service name : AppVClient
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\AppVClient.exe
Dependencies : RpcSS/netprofm/AppvVfs/AppVStrm/

DialogBlockingService startup parameters :
Display name : DialogBlockingService
Service name : DialogBlockingService
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k DialogBlockingService

Fax startup parameters :
Display name : Fax
Service name : Fax
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\WINDOWS\system32\fxssvc.exe
Dependencies : TapiSrv/RpcSs/Spooler/

Lucee startup parameters :
Display name : Apache Tomcat 9.0 Lucee
Service name : Lucee
Log on as : .\Techapp
Executable path : D:\Techexcel\Lucee\tomcat\bin\Tomcat9.exe //RS//Lucee
Dependencies : Tcpip/Afd/

MSSQLSERVER startup parameters :
Display name : SQL Server (MSSQLSERVER)
Service name : MSSQLSERVER
Log on as : .\Techapp
Executable path : "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER
Dependencies : KEYISO/

MsKeyboardFilter startup parameters :
Display name : Microsoft Keyboard Filter
Service name : MsKeyboardFilter
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p

NetTcpPortSharing startup parameters :
Display name : Net.Tcp Port Sharing Service
Service name : NetTcpPortSharing
Log on as : NT AUTHORITY\LocalService
Executable path : C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe

RemoteAccess startup parameters :
Display name : Routing and Remote Access
Service name : RemoteAccess
Log on as : localSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k netsvcs
Dependencies : RpcSS/Bfe/RasMan/Http/+NetBIOSGroup/

SQLBrowser startup parameters :
Display name : SQL Server Browser
Service name : SQLBrowser
Log on as : NT AUTHORITY\LOCALSERVICE
Executable path : "C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe"

SQLSERVERAGENT startup parameters :
Display name : SQL Server Agent (MSSQLSERVER)
Service name : SQLSERVERAGENT
Log on as : .\Techapp
Executable path : "D:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER
Dependencies : MSSQLSERVER/

Spooler startup parameters :
Display name : Print Spooler
Service name : Spooler
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\spoolsv.exe
Dependencies : RPCSS/http/

UevAgentService startup parameters :
Display name : User Experience Virtualization Service
Service name : UevAgentService
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\AgentService.exe

XblAuthManager startup parameters :
Display name : Xbox Live Auth Manager
Service name : XblAuthManager
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/

XblGameSave startup parameters :
Display name : Xbox Live Game Save
Service name : XblGameSave
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p
Dependencies : UserManager/XblAuthManager/

XboxGipSvc startup parameters :
Display name : Xbox Accessory Management Service
Service name : XboxGipSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p

XboxNetApiSvc startup parameters :
Display name : Xbox Live Networking Service
Service name : XboxNetApiSvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p
Dependencies : BFE/mpssvc/IKEEXT/KeyIso/

shpamsvc startup parameters :
Display name : Shared PC Account Manager
Service name : shpamsvc
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\svchost.exe -k netsvcs -p
Dependencies : RpcSs/ProfSvc/

ssh-agent startup parameters :
Display name : OpenSSH Authentication Agent
Service name : ssh-agent
Log on as : LocalSystem
Executable path : C:\WINDOWS\System32\OpenSSH\ssh-agent.exe

uhssvc startup parameters :
Display name : Microsoft Update Health Service
Service name : uhssvc
Log on as : LocalSystem
Executable path : "C:\Program Files\Microsoft Update Health Tools\uhssvc.exe"
Dependencies : EventLog/

11011 - Microsoft Windows SMB Service Detection
-
Synopsis
A file / print sharing service is listening on the remote host.
Description
The remote service understands the CIFS (Common Internet File System) or Server Message Block (SMB) protocol, used to provide shared access to files, printers, etc between nodes on a network.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2002/06/05, Modified: 2021/02/11
Plugin Output

tcp/139/smb


An SMB server is running on this port.

11011 - Microsoft Windows SMB Service Detection
-
Synopsis
A file / print sharing service is listening on the remote host.
Description
The remote service understands the CIFS (Common Internet File System) or Server Message Block (SMB) protocol, used to provide shared access to files, printers, etc between nodes on a network.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2002/06/05, Modified: 2021/02/11
Plugin Output

tcp/445/cifs


A CIFS server is running on this port.
10456 - Microsoft Windows SMB Service Enumeration
-
Synopsis
It is possible to enumerate remote services.
Description
This plugin implements the SvcOpenSCManager() and SvcEnumServices() calls to obtain, using the SMB protocol, the list of active and inactive services of the remote host.

An attacker may use this feature to gain better knowledge of the remote host.
Solution
To prevent the listing of the services from being obtained, you should either have tight login restrictions, so that only trusted users can access your host, and/or you should filter incoming traffic to this port.
Risk Factor
None
References
XREF IAVT:0001-T-0751
Plugin Information
Published: 2000/07/03, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Active Services :

Application Information [ Appinfo ]
Windows Audio Endpoint Builder [ AudioEndpointBuilder ]
Windows Audio [ Audiosrv ]
Kaspersky Endpoint Security Service (KES.21.15) [ AVP.KES.21.15 ]
Kaspersky Seamless Update Service (KES.21.15) [ avpsus.KES.21.15 ]
AzureAttestService [ AzureAttestService ]
Base Filtering Engine [ BFE ]
Background Tasks Infrastructure Service [ BrokerInfrastructure ]
AVCTP service [ BthAvctpSvc ]
Capability Access Manager Service [ camsvc ]
Connected Devices Platform Service [ CDPSvc ]
Certificate Propagation [ CertPropSvc ]
COM+ System Application [ COMSysApp ]
CoreMessaging [ CoreMessagingRegistrar ]
Cryptographic Services [ CryptSvc ]
DCOM Server Process Launcher [ DcomLaunch ]
Device Association Service [ DeviceAssociationService ]
DevQuery Background Discovery Broker [ DevQueryBroker ]
DHCP Client [ Dhcp ]
Connected User Experiences and Telemetry [ DiagTrack ]
Display Policy Service [ DispBrokerDesktopSvc ]
DNS Client [ Dnscache ]
Diagnostic Policy Service [ DPS ]
Data Usage [ DusmSvc ]
Encrypting File System (EFS) [ EFS ]
Windows Event Log [ EventLog ]
COM+ Event System [ EventSystem ]
Function Discovery Provider Host [ fdPHost ]
Function Discovery Resource Publication [ FDResPub ]
Windows Font Cache Service [ FontCache ]
Group Policy Client [ gpsvc ]
IKE and AuthIP IPsec Keying Modules [ IKEEXT ]
Microsoft Store Install Service [ InstallService ]
IP Helper [ iphlpsvc ]
CNG Key Isolation [ KeyIso ]
Kaspersky Security Center Network Agent [ klnagent ]
Server [ LanmanServer ]
Workstation [ LanmanWorkstation ]
Geolocation Service [ lfsvc ]
Windows License Manager Service [ LicenseManager ]
TCP/IP NetBIOS Helper [ lmhosts ]
Local Session Manager [ LSM ]
Windows Defender Firewall [ mpssvc ]
Distributed Transaction Coordinator [ MSDTC ]
Network Connection Broker [ NcbService ]
Network Connected Devices Auto-Setup [ NcdAutoSetup ]
Network List Service [ netprofm ]
Network Location Awareness [ NlaSvc ]
Network Store Interface Service [ nsi ]
Program Compatibility Assistant Service [ PcaSvc ]
Plug and Play [ PlugPlay ]
IPsec Policy Agent [ PolicyAgent ]
Power [ Power ]
User Profile Service [ ProfSvc ]
Remote Access Connection Manager [ RasMan ]
Remote Registry [ RemoteRegistry ]
Radio Management Service [ RmSvc ]
RPC Endpoint Mapper [ RpcEptMapper ]
Remote Procedure Call (RPC) [ RpcSs ]
Security Accounts Manager [ SamSs ]
Task Scheduler [ Schedule ]
SecPod Saner Agent [ SecPod Saner Agent ]
Windows Security Service [ SecurityHealthService ]
Payments and NFC/SE Manager [ SEMgrSvc ]
System Event Notification Service [ SENS ]
Remote Desktop Configuration [ SessionEnv ]
Shell Hardware Detection [ ShellHWDetection ]
Software Protection [ sppsvc ]
SQL Server VSS Writer [ SQLWriter ]
SSDP Discovery [ SSDPSRV ]
Secure Socket Tunneling Protocol Service [ SstpSvc ]
State Repository Service [ StateRepository ]
Storage Service [ StorSvc ]
SysMain [ SysMain ]
System Events Broker [ SystemEventsBroker ]
Touch Keyboard and Handwriting Panel Service [ TabletInputService ]
Remote Desktop Services [ TermService ]
Themes [ Themes ]
Time Broker [ TimeBrokerSvc ]
Web Account Manager [ TokenBroker ]
Distributed Link Tracking Client [ TrkWks ]
Windows Modules Installer [ TrustedInstaller ]
TightVNC Server [ tvnserver ]
Remote Desktop Services UserMode Port Redirector [ UmRdpService ]
User Manager [ UserManager ]
Update Orchestrator Service [ UsoSvc ]
Credential Manager [ VaultSvc ]
VMware Alias Manager and Ticket Service [ VGAuthService ]
VMware SVGA Helper Service [ vm3dservice ]
VMware Tools [ VMTools ]
Windows Connection Manager [ Wcmsvc ]
Diagnostic Service Host [ WdiServiceHost ]
Diagnostic System Host [ WdiSystemHost ]
WinHTTP Web Proxy Auto-Discovery Service [ WinHttpAutoProxySvc ]
Windows Management Instrumentation [ Winmgmt ]
Windows Push Notifications System Service [ WpnService ]
Security Center [ wscsvc ]
Windows Search [ WSearch ]
Clipboard User Service_50c7d [ cbdhsvc_50c7d ]
Connected Devices Platform User Service_50c7d [ CDPUserSvc_50c7d ]
Sync Host_50c7d [ OneSyncSvc_50c7d ]
Udk User Service_50c7d [ UdkUserSvc_50c7d ]
Windows Push Notifications User Service_50c7d [ WpnUserService_50c7d ]
Clipboard User Service_5bcf85da [ cbdhsvc_5bcf85da ]
Connected Devices Platform User Service_5bcf85da [ CDPUserSvc_5bcf85da ]
Sync Host_5bcf85da [ OneSyncSvc_5bcf85da ]
Contact Data_5bcf85da [ PimIndexMaintenanceSvc_5bcf85da ]
User Data Storage_5bcf85da [ UnistoreSvc_5bcf85da ]
User Data Access_5bcf85da [ UserDataSvc_5bcf85da ]
Windows Push Notifications User Service_5bcf85da [ WpnUserService_5bcf85da ]

Inactive Services :

AllJoyn Router Service [ AJRouter ]
Application Layer Gateway Service [ ALG ]
Application Identity [ AppIDSvc ]
Application Management [ AppMgmt ]
App Readiness [ AppReadiness ]
Microsoft App-V Client [ AppVClient ]
AppX Deployment Service (AppXSVC) [ AppXSvc ]
AssignedAccessManager Service [ AssignedAccessManagerSvc ]
Cellular Time [ autotimesvc ]
ActiveX Installer (AxInstSV) [ AxInstSV ]
BitLocker Drive Encryption Service [ BDESVC ]
Background Intelligent Transfer Service [ BITS ]
Bluetooth Audio Gateway Service [ BTAGService ]
Bluetooth Support Service [ bthserv ]
Client License Service (ClipSVC) [ ClipSVC ]
Microsoft Cloud Identity Service [ cloudidsvc ]
Offline Files [ CscService ]
Declared Configuration(DC) service [ dcsvc ]
Optimize drives [ defragsvc ]
Device Install Service [ DeviceInstall ]
Microsoft (R) Diagnostics Hub Standard Collector Service [ diagnosticshub.standardcollector.service ]
Diagnostic Execution Service [ diagsvc ]
DialogBlockingService [ DialogBlockingService ]
Display Enhancement Service [ DisplayEnhancementService ]
Device Management Enrollment Service [ DmEnrollmentSvc ]
Device Management Wireless Application Protocol (WAP) Push message Routing Service [ dmwappushservice ]
Delivery Optimization [ DoSvc ]
Wired AutoConfig [ dot3svc ]
Device Setup Manager [ DsmSvc ]
Data Sharing Service [ DsSvc ]
Extensible Authentication Protocol [ Eaphost ]
Microsoft Edge Update Service (edgeupdate) [ edgeupdate ]
Microsoft Edge Update Service (edgeupdatem) [ edgeupdatem ]
Embedded Mode [ embeddedmode ]
Enterprise App Management Service [ EntAppSvc ]
Fax [ Fax ]
File History Service [ fhsvc ]
Windows Presentation Foundation Font Cache 3.0.0.0 [ FontCache3.0.0.0 ]
Windows Camera Frame Server [ FrameServer ]
GameInput Service [ GameInputSvc ]
Google Chrome Elevation Service (GoogleChromeElevationService) [ GoogleChromeElevationService ]
Google Updater Internal Service (GoogleUpdaterInternalService144.0.7547.0) [ GoogleUpdaterInternalService144.0.7547.0 ]
Google Updater Service (GoogleUpdaterService144.0.7547.0) [ GoogleUpdaterService144.0.7547.0 ]
GraphicsPerfSvc [ GraphicsPerfSvc ]
Human Interface Device Service [ hidserv ]
HV Host Service [ HvHost ]
Windows Mobile Hotspot Service [ icssvc ]
IP Translation Configuration Service [ IpxlatCfgSvc ]
Kaspersky Security Network proxy server [ ksnproxy ]
KtmRm for Distributed Transaction Coordinator [ KtmRm ]
Link-Layer Topology Discovery Mapper [ lltdsvc ]
Apache Tomcat 9.0 Lucee [ Lucee ]
Language Experience Service [ LxpSvc ]
Downloaded Maps Manager [ MapsBroker ]
McpManagementService [ McpManagementService ]
Microsoft Edge Elevation Service (MicrosoftEdgeElevationService) [ MicrosoftEdgeElevationService ]
Windows Mixed Reality OpenXR Service [ MixedRealityOpenXRSvc ]
Mozilla Maintenance Service [ MozillaMaintenance ]
Microsoft iSCSI Initiator Service [ MSiSCSI ]
Windows Installer [ msiserver ]
Microsoft Keyboard Filter [ MsKeyboardFilter ]
MS-MPI Launch Service [ MsMpiLaunchSvc ]
SQL Full-text Filter Daemon Launcher (MSSQLSERVER) [ MSSQLFDLauncher ]
SQL Server Launchpad (MSSQLSERVER) [ MSSQLLaunchpad ]
SQL Server (MSSQLSERVER) [ MSSQLSERVER ]
Natural Authentication [ NaturalAuthentication ]
Network Connectivity Assistant [ NcaSvc ]
Netlogon [ Netlogon ]
Network Connections [ Netman ]
Network Setup Service [ NetSetupSvc ]
Net.Tcp Port Sharing Service [ NetTcpPortSharing ]
Microsoft Passport Container [ NgcCtnrSvc ]
Microsoft Passport [ NgcSvc ]
Office 64 Source Engine [ ose64 ]
Peer Networking Identity Manager [ p2pimsvc ]
Peer Networking Grouping [ p2psvc ]
BranchCache [ PeerDistSvc ]
Windows Perception Simulation Service [ perceptionsimulation ]
Performance Counter DLL Host [ PerfHost ]
Phone Service [ PhoneSvc ]
Performance Logs & Alerts [ pla ]
PNRP Machine Name Publication Service [ PNRPAutoReg ]
Peer Name Resolution Protocol [ PNRPsvc ]
Printer Extensions and Notifications [ PrintNotify ]
Windows PushToInstall Service [ PushToInstall ]
Quality Windows Audio Video Experience [ QWAVE ]
Remote Access Auto Connection Manager [ RasAuto ]
Routing and Remote Access [ RemoteAccess ]
Retail Demo Service [ RetailDemo ]
Remote Procedure Call (RPC) Locator [ RpcLocator ]
Smart Card [ SCardSvr ]
Smart Card Device Enumeration Service [ ScDeviceEnum ]
Smart Card Removal Policy [ SCPolicySvc ]
Windows Backup [ SDRSVC ]
Secondary Logon [ seclogon ]
SecPod Saner Upgrade Controller v2 [ SecPod Saner Upgrade Controller v2 ]
Windows Defender Advanced Threat Protection Service [ Sense ]
Sensor Data Service [ SensorDataService ]
Sensor Service [ SensorService ]
Sensor Monitoring Service [ SensrSvc ]
Internet Connection Sharing (ICS) [ SharedAccess ]
Spatial Data Service [ SharedRealitySvc ]
Shared PC Account Manager [ shpamsvc ]
Microsoft Storage Spaces SMP [ smphost ]
Microsoft Windows SMS Router Service. [ SmsRouter ]
SNMP Trap [ SNMPTRAP ]
Windows Perception Service [ spectrum ]
Print Spooler [ Spooler ]
SQL Server Browser [ SQLBrowser ]
SQL Server Agent (MSSQLSERVER) [ SQLSERVERAGENT ]
SQL Server CEIP service (MSSQLSERVER) [ SQLTELEMETRY ]
OpenSSH Authentication Agent [ ssh-agent ]
Windows Image Acquisition (WIA) [ stisvc ]
Spot Verifier [ svsvc ]
Microsoft Software Shadow Copy Provider [ swprv ]
Telephony [ TapiSrv ]
Storage Tiers Management [ TieringEngineService ]
Recommended Troubleshooting Service [ TroubleshootingSvc ]
Auto Time Zone Updater [ tzautoupdate ]
User Experience Virtualization Service [ UevAgentService ]
Microsoft Update Health Service [ uhssvc ]
UPnP Device Host [ upnphost ]
Volumetric Audio Compositor Service [ VacSvc ]
Virtual Disk [ vds ]
Hyper-V Guest Service Interface [ vmicguestinterface ]
Hyper-V Heartbeat Service [ vmicheartbeat ]
Hyper-V Data Exchange Service [ vmickvpexchange ]
Hyper-V Remote Desktop Virtualization Service [ vmicrdv ]
Hyper-V Guest Shutdown Service [ vmicshutdown ]
Hyper-V Time Synchronization Service [ vmictimesync ]
Hyper-V PowerShell Direct Service [ vmicvmsession ]
Hyper-V Volume Shadow Copy Requestor [ vmicvss ]
VMware Snapshot Provider [ vmvss ]
Volume Shadow Copy [ VSS ]
Windows Time [ W32Time ]
Windows Update Medic Service [ WaaSMedicSvc ]
WalletService [ WalletService ]
WarpJITSvc [ WarpJITSvc ]
Block Level Backup Engine Service [ wbengine ]
Windows Biometric Service [ WbioSrvc ]
Windows Connect Now - Config Registrar [ wcncsvc ]
Microsoft Defender Antivirus Network Inspection Service [ WdNisSvc ]
WebClient [ WebClient ]
Windows Event Collector [ Wecsvc ]
Windows Encryption Provider Host Service [ WEPHOSTSVC ]
Problem Reports Control Panel Support [ wercplsupport ]
Windows Error Reporting Service [ WerSvc ]
Wi-Fi Direct Services Connection Manager Service [ WFDSConMgrSvc ]
Still Image Acquisition Events [ WiaRpc ]
Microsoft Defender Antivirus Service [ WinDefend ]
Windows Remote Management (WS-Management) [ WinRM ]
Windows Insider Service [ wisvc ]
WLAN AutoConfig [ WlanSvc ]
Microsoft Account Sign-in Assistant [ wlidsvc ]
Local Profile Assistant Service [ wlpasvc ]
Windows Management Service [ WManSvc ]
WMI Performance Adapter [ wmiApSrv ]
Windows Media Player Network Sharing Service [ WMPNetworkSvc ]
Work Folders [ workfolderssvc ]
Parental Controls [ WpcMonSvc ]
Portable Device Enumerator Service [ WPDBusEnum ]
Windows Update [ wuauserv ]
WWAN AutoConfig [ WwanSvc ]
Xbox Live Auth Manager [ XblAuthManager ]
Xbox Live Game Save [ XblGameSave ]
Xbox Accessory Management Service [ XboxGipSvc ]
Xbox Live Networking Service [ XboxNetApiSvc ]
Agent Activation Runtime_50c7d [ AarSvc_50c7d ]
GameDVR and Broadcast User Service_50c7d [ BcastDVRUserService_50c7d ]
Bluetooth User Support Service_50c7d [ BluetoothUserService_50c7d ]
CaptureService_50c7d [ CaptureService_50c7d ]
ConsentUX_50c7d [ ConsentUxUserSvc_50c7d ]
CredentialEnrollmentManagerUserSvc_50c7d [ CredentialEnrollmentManagerUserSvc_50c7d ]
DeviceAssociationBroker_50c7d [ DeviceAssociationBrokerSvc_50c7d ]
DevicePicker_50c7d [ DevicePickerUserSvc_50c7d ]
DevicesFlow_50c7d [ DevicesFlowUserSvc_50c7d ]
MessagingService_50c7d [ MessagingService_50c7d ]
Contact Data_50c7d [ PimIndexMaintenanceSvc_50c7d ]
PrintWorkflow_50c7d [ PrintWorkflowUserSvc_50c7d ]
User Data Storage_50c7d [ UnistoreSvc_50c7d ]
User Data Access_50c7d [ UserDataSvc_50c7d ]
Agent Activation Runtime_5bcf85da [ AarSvc_5bcf85da ]
GameDVR and Broadcast User Service_5bcf85da [ BcastDVRUserService_5bcf85da ]
Bluetooth User Support Service_5bcf85da [ BluetoothUserService_5bcf85da ]
CaptureService_5bcf85da [ CaptureService_5bcf85da ]
ConsentUX_5bcf85da [ ConsentUxUserSvc_5bcf85da ]
CredentialEnrollmentManagerUserSvc_5bcf85da [ CredentialEnrollmentManagerUserSvc_5bcf85da ]
DeviceAssociationBroker_5bcf85da [ DeviceAssociationBrokerSvc_5bcf85da ]
DevicePicker_5bcf85da [ DevicePickerUserSvc_5bcf85da ]
DevicesFlow_5bcf85da [ DevicesFlowUserSvc_5bcf85da ]
MessagingService_5bcf85da [ MessagingService_5bcf85da ]
PrintWorkflow_5bcf85da [ PrintWorkflowUserSvc_5bcf85da ]
Udk User Service_5bcf85da [ UdkUserSvc_5bcf85da ]

92373 - Microsoft Windows SMB Sessions
-
Synopsis
Nessus was able to collect and report SMB session information from the remote host.
Description
Nessus was able to collect details of SMB sessions from the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2025/12/15
Plugin Output

tcp/0

tidua
techrobot
techrobot
TechRobot

Extended SMB session information attached.

23974 - Microsoft Windows SMB Share Hosting Office Files
-
Synopsis
The remote share contains Office-related files.
Description
This plugin connects to the remotely accessible SMB shares and attempts to find office related files (such as .doc, .ppt, .xls, .pdf etc).
Solution
Make sure that the files containing confidential information have proper access controls set on them.
Risk Factor
None
Plugin Information
Published: 2007/01/04, Modified: 2011/03/21
Plugin Output

tcp/445/cifs


Here is a list of office files which have been found on the remote SMB
shares :

+ C$ :

- C:\Program Files\Microsoft Office\Office16\1033\PROTTPLN.DOC
- C:\Windows\WinSxS\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.19041.3636_none_8cb7714fdf31ec17\MsoIrmProtector.doc
- C:\Windows\WinSxS\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.19041.3636_none_8262c6fdaad12a1c\MsoIrmProtector.doc
- C:\Windows\SysWOW64\MSDRM\MsoIrmProtector.doc
- C:\Windows\System32\MSDRM\MsoIrmProtector.doc
- C:\Program Files\Microsoft Office\Office16\1033\PROTTPLV.DOC
- C:\Program Files\Microsoft Office\Office16\1033\PROTTPLN.PPT
- C:\Windows\WinSxS\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.19041.3636_none_8cb7714fdf31ec17\MsoIrmProtector.ppt
- C:\Windows\WinSxS\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.19041.3636_none_8262c6fdaad12a1c\MsoIrmProtector.ppt
- C:\Windows\SysWOW64\MSDRM\MsoIrmProtector.ppt
- C:\Windows\System32\MSDRM\MsoIrmProtector.ppt
- C:\Program Files\Microsoft Office\Office16\1033\PROTTPLV.PPT
- C:\Program Files\Microsoft Office\Office16\1033\PROTTPLN.XLS
- C:\Program Files\Microsoft Office\Office16\1033\PROTTPLV.XLS
- C:\Windows\WinSxS\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.19041.3636_none_8cb7714fdf31ec17\MsoIrmProtector.xls
- C:\Windows\WinSxS\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.19041.3636_none_8262c6fdaad12a1c\MsoIrmProtector.xls
- C:\Windows\SysWOW64\MSDRM\MsoIrmProtector.xls
- C:\Windows\System32\MSDRM\MsoIrmProtector.xls
- C:\Program Files\Microsoft Office\Office16\SAMPLES\SOLVSAMP.XLS
- C:\Users\Techrobot\AppData\Local\Programs\UiPath\Studio\ProjectTemplates\Business Project\Legacy\VisualBasic\Project_Notebook.ja.xlsx
- C:\Users\Techrobot\AppData\Local\Programs\UiPath\Studio\ProjectTemplates\Business Project\Legacy\VisualBasic\Project_Notebook.xlsx
- C:\Users\Techrobot\AppData\Local\Programs\UiPath\Studio\ProjectTemplates\Business Project\Windows\VisualBasic\Project_Notebook.ja.xlsx
- C:\Users\Techrobot\AppData\Local\Programs\UiPath\Studio\ProjectTemplates\Business Project\Windows\VisualBasic\Project_Notebook.xlsx
- C:\Users\Techrobot\AppData\Local\UiPath\app-21.4.4\ProjectTemplates\Create Rich HTML Email\Project_Notebook.xlsx
- C:\Users\Techrobot\AppData\Local\UiPath\app-21.4.4\ProjectTemplates\Create Rich HTML Email\Suppliers.xlsx
- C:\Users\Techrobot\AppData\Local\UiPath\app-21.4.4\ProjectTemplates\Download File from Website\Project_Notebook.xlsx
- C:\Users\Techrobot\AppData\Local\UiPath\app-21.4.4\ProjectTemplates\Enter Excel Data into Website\Project_Notebook.xlsx
- C:\Users\Techrobot\AppData\Local\UiPath\app-21.4.4\ProjectTemplates\Enter Excel Data into Website\suppliers.xlsx
- C:\Users\Techrobot\AppData\Local\UiPath\app-21.4.4\ProjectTemplates\Save Excel Attachments and Merge\Project_Notebook.xlsx
- C:\Windows\SHELLNEW\EXCEL12.XLSX
- C:\Users\Techrobot\AppData\Local\UiPath\app-21.4.4\ProjectTemplates\Split Excel Sheet Into Multiple Sheets\Project_Notebook.xlsx
- C:\Users\Techrobot\AppData\Local\UiPath\app-21.4.4\ProjectTemplates\Split Excel Sheet Into Multiple Sheets\OutputTemplate.xlsx
- C:\Users\Techrobot\AppData\Local\UiPath\app-21.4.4\ProjectTemplates\Split Excel Sheet Into Multiple Sheets\InputData.xlsx
- C:\Users\Techrobot\AppData\Local\UiPath\app-21.4.4\ProjectTemplates\Save Outlook Attachments\Project_Notebook.xlsx
- C:\Users\Techrobot\AppData\Local\UiPath\app-21.4.4\ProjectTemplates\Create PowerPoint Presentation from Data Scraping\Project_Notebook.xlsx
- C:\Users\Techrobot\AppData\Local\UiPath\app-21.4.4\ProjectTemplates\Create PowerPoint Presentation from Data Scraping\Opportunities Report Template.xlsx
- C:\Users\Techrobot\AppData\Local\UiPath\app-21.4.4\ProjectTemplates\Complete Word Template from Excel and Email\Project_Notebook.xlsx
- C:\Users\Techrobot\AppData\Local\UiPath\app-21.4.4\ProjectTemplates\Complete Word Template from Excel and Email\People.xlsx
- C:\Users\Techrobot\AppData\Local\UiPath\app-21.4.4\ProjectTemplates\Business Project\Project_Notebook.xlsx
- C:\Users\Techrobot\AppData\Local\UiPath\app-21.4.4\ProjectTemplates\Business Project\Project_Notebook.ja.xlsx
- C:\Program Files (x86)\Microsoft SQL Server Management Studio 18\Licenses\1033\SSMS License Terms.docx
- C:\Program Files (x86)\Microsoft SQL Server Management Studio 18\Licenses\Third Party Notices SQL Server.docx
- C:\Users\Techrobot\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Word Document Building Blocks\1033\TM02835233[[fn=Text Sidebar (Annual Report Red and Black design)]].docx
- C:\Users\Techrobot\AppData\Local\UiPath\app-21.4.4\ProjectTemplates\Create Rich HTML Email\EmailTemplate.docx
- C:\Users\Techrobot\AppData\Local\UiPath\app-21.4.4\ProjectTemplates\Create Rich HTML Email\Email Body.docx
- C:\Users\Techrobot\AppData\Local\UiPath\app-21.4.4\ProjectTemplates\Complete Word Template from Excel and Email\WelcomeTemplate.docx
- C:\Users\Techrobot\AppData\Local\UiPath\app-21.4.4\ProjectTemplates\Complete Word Template from Excel and Email\CompletedAttachment.docx
- C:\Users\Techrobot\AppData\Local\UiPath\app-21.4.4\ProjectTemplates\Create PowerPoint Presentation from Data Scraping\Report Template.pptx

+ D$ :

- D:\lkpsoft\CDSL Secure\CDSL Secure\CDSL Files\20y_Certificate\CDASWEB Certificate Import For Clients.doc
- D:\lkpsoft\CDSL Secure\CDSL Secure\CDSL Files\Silverlight_Pre-requisites\SL5Installables\Browser Setting for Windows Module Auto release\Chrome\Browser settings for Google Chrome .doc
- D:\lkpsoft\CDSL Secure\CDSL Secure\CDSL Files\Silverlight_Pre-requisites\SL5Installables\Browser Setting for Windows Module Auto release\Firefox\Browser settings for Firefox .doc
- D:\lkpsoft\CDSL Secure\CDSL Secure\CDSL Files\Silverlight_Pre-requisites\SL5Installables\Silverlight Pre requisite\SL5 Pre Requisite Instructions.doc
- D:\lkpsoft\CDSL Secure\CDSL Secure\CDSL Files\Silverlight_Pre-requisites\SL5Installables\Silverlight Pre requisite\Silverlight Pre requisite\SL5 Pre Requisite Instructions.doc
- D:\lkpsoft\CDSL Secure\CDSL Secure\CDSL Files\Silverlight_Pre-requisites\SL5Installables\Pre-requisite for Windows Module Auto release\Pre requisite Installable for Auto Release-Update for Windows Module user Manual.doc
- D:\lkpsoft\CDSL Secure\CDSL Secure\CDSL Files\Silverlight_Pre-requisites\SL5Installables\DP Configuration - DBA Module\DP Configuration In DBA module.doc
- D:\lkpsoft\CDSL Secure\CDSL Secure\CDSL Files\Silverlight_Pre-requisites\SL5Installables\Browser Setting for Windows Module Auto release\Internet Explorer\Browser settings for Internet explorer.doc
- D:\Techexcel\AppData\AppData\Local\Programs\UiPath\Studio\ProjectTemplates\Business Project\Legacy\VisualBasic\Project_Notebook.ja.xlsx
- D:\Techexcel\AppData\AppData\Local\Programs\UiPath\Studio\ProjectTemplates\Business Project\Legacy\VisualBasic\Project_Notebook.xlsx
- D:\Techexcel\AppData\AppData\Local\Programs\UiPath\Studio\ProjectTemplates\Business Project\Windows\VisualBasic\Project_Notebook.ja.xlsx
- D:\Techexcel\AppData\AppData\Local\Programs\UiPath\Studio\ProjectTemplates\Business Project\Windows\VisualBasic\Project_Notebook.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\01-Apr-2025\01_04_2025_09-03-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\01-Apr-2025\01_04_2025_11-34-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\01-Apr-2025\01_04_2025_12-49-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\02-Apr-2024\02_04_2024_03-16-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\02-Apr-2024\02_04_2024_05-31-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\02-Apr-2024\02_04_2024_09-01-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\02-Apr-2024\02_04_2024_11-16-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\02-Apr-2024\02_04_2024_12-31-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\03-Apr-2024\03_04_2024_11-16-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\03-Apr-2024\03_04_2024_12-32-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\03-Apr-2025\03_04_2025_03-18-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\03-Apr-2025\03_04_2025_06-05-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\03-Apr-2025\03_04_2025_09-03-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\03-Apr-2025\03_04_2025_11-18-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\03-Apr-2025\03_04_2025_12-38-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\03-Apr-2025\03_04_2025_12-48-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\04-Apr-2025\04_04_2025_11-19-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\04-Apr-2025\04_04_2025_12-34-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\05-Apr-2024\05_04_2024_03-16-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\05-Apr-2024\05_04_2024_05-32-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\05-Apr-2024\05_04_2024_09-11-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\05-Apr-2024\05_04_2024_11-16-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\05-Apr-2024\05_04_2024_12-32-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\05-Apr-2025\05_04_2025_03-19-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\06-Apr-2024\06_04_2024_11-17-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\06-Apr-2024\06_04_2024_12-32-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\07-Apr-2024\07_04_2024_03-17-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\07-Apr-2024\07_04_2024_05-32-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\07-Apr-2024\07_04_2024_09-02-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\07-Apr-2024\07_04_2024_09-11-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\07-Apr-2024\07_04_2024_09-16-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\07-Apr-2024\07_04_2024_11-17-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\08-Apr-2024\08_04_2024_03-16-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\08-Apr-2024\08_04_2024_03-22-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\08-Apr-2024\08_04_2024_03-27-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\08-Apr-2024\08_04_2024_03-33-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\08-Apr-2024\08_04_2024_05-31-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\08-Apr-2024\08_04_2024_09-04-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\08-Apr-2024\08_04_2024_11-23-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\08-Apr-2024\08_04_2024_12-32-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\09-Apr-2024\09_04_2024_11-16-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\09-Apr-2024\09_04_2024_12-35-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\09-Apr-2025\09_04_2025_03-18-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\09-Apr-2025\09_04_2025_03-32-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\09-Apr-2025\09_04_2025_06-03-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\09-Apr-2025\09_04_2025_09-03-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\09-Apr-2025\09_04_2025_11-19-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\09-Apr-2025\09_04_2025_12-35-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\10-Apr-2025\10_04_2025_11-18-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\10-Apr-2025\10_04_2025_12-38-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\11-Apr-2024\11_04_2024_03-17-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\11-Apr-2024\11_04_2024_05-34-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\11-Apr-2024\11_04_2024_09-07-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\11-Apr-2024\11_04_2024_11-22-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\11-Apr-2024\11_04_2024_12-31-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\11-Apr-2025\11_04_2025_03-23-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\12-Apr-2024\12_04_2024_12-31-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\12-Apr-2025\12_04_2025_03-19-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\12-Apr-2025\12_04_2025_06-03-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\12-Apr-2025\12_04_2025_09-04-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\12-Apr-2025\12_04_2025_11-19-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\12-Apr-2025\12_04_2025_12-35-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\13-Apr-2024\13_04_2024_03-17-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\13-Apr-2024\13_04_2024_05-32-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\14-Apr-2025\14_04_2025_03-19-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\14-Apr-2025\14_04_2025_06-04-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\14-Apr-2025\14_04_2025_09-02-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\14-Apr-2025\14_04_2025_11-17-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\14-Apr-2025\14_04_2025_12-34-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\15-Apr-2024\15_04_2024_03-16-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\15-Apr-2024\15_04_2024_05-31-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\15-Apr-2024\15_04_2024_05-41-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\15-Apr-2025\15_04_2025_11-26-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\15-Apr-2025\15_04_2025_12-32-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\16-Apr-2024\16_04_2024_03-27-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\16-Apr-2024\16_04_2024_05-31-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\16-Apr-2024\16_04_2024_09-02-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\16-Apr-2024\16_04_2024_11-25-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\16-Apr-2024\16_04_2024_12-33-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\16-Apr-2025\16_04_2025_03-17-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\17-Apr-2024\17_04_2024_12-31-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\17-Apr-2025\17_04_2025_03-17-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\17-Apr-2025\17_04_2025_03-43-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\17-Apr-2025\17_04_2025_06-02-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\17-Apr-2025\17_04_2025_09-02-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\17-Apr-2025\17_04_2025_11-26-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\17-Apr-2025\17_04_2025_12-34-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\18-Apr-2024\18_04_2024_03-17-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\18-Apr-2025\18_04_2025_12-34-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\19-Apr-2024\19_04_2024_03-18-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\19-Apr-2024\19_04_2024_05-33-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\19-Apr-2024\19_04_2024_05-44-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\19-Apr-2024\19_04_2024_09-03-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\19-Apr-2024\19_04_2024_11-16-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\19-Apr-2024\19_04_2024_12-32-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\19-Apr-2025\19_04_2025_03-19-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\21-Apr-2024\21_04_2024_03-17-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\21-Apr-2024\21_04_2024_05-32-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\21-Apr-2024\21_04_2024_09-02-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\21-Apr-2024\21_04_2024_11-17-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\21-Apr-2024\21_04_2024_12-32-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\21-Apr-2025\21_04_2025_03-17-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\21-Apr-2025\21_04_2025_06-03-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\21-Apr-2025\21_04_2025_06-30-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\22-Apr-2024\22_04_2024_12-31-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\22-Apr-2025\22_04_2025_03-22-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\22-Apr-2025\22_04_2025_06-07-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\22-Apr-2025\22_04_2025_09-03-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\22-Apr-2025\22_04_2025_11-17-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\22-Apr-2025\22_04_2025_12-43-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\23-Apr-2024\23_04_2024_03-16-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\23-Apr-2024\23_04_2024_05-35-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\23-Apr-2025\23_04_2025_12-33-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\24-Apr-2024\24_04_2024_03-16-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\24-Apr-2024\24_04_2024_05-35-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\24-Apr-2024\24_04_2024_05-49-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\24-Apr-2024\24_04_2024_06-00-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\24-Apr-2024\24_04_2024_09-03-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\24-Apr-2024\24_04_2024_11-16-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\24-Apr-2024\24_04_2024_12-32-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\25-Apr-2024\25_04_2024_11-16-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\25-Apr-2024\25_04_2024_12-32-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\25-Apr-2025\25_04_2025_03-22-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\25-Apr-2025\25_04_2025_06-02-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\25-Apr-2025\25_04_2025_09-02-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\25-Apr-2025\25_04_2025_11-25-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\25-Apr-2025\25_04_2025_12-33-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\26-Apr-2024\26_04_2024_03-20-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\26-Apr-2025\26_04_2025_12-34-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\27-Apr-2024\27_04_2024_03-17-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\27-Apr-2024\27_04_2024_06-17-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\27-Apr-2024\27_04_2024_09-02-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\27-Apr-2024\27_04_2024_11-17-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\27-Apr-2024\27_04_2024_12-32-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\28-Apr-2024\28_04_2024_03-17-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\28-Apr-2024\28_04_2024_06-17-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\29-Apr-2024\29_04_2024_01-50-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\29-Apr-2024\29_04_2024_02-28-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\29-Apr-2024\29_04_2024_03-16-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\29-Apr-2024\29_04_2024_06-43-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\29-Apr-2024\29_04_2024_09-17-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\29-Apr-2024\29_04_2024_11-16-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\29-Apr-2024\29_04_2024_12-32-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\29-Apr-2025\29_04_2025_03-17-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\30-Apr-2024\30_04_2024_12-31-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\30-Apr-2025\30_04_2025_03-17-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\30-Apr-2025\30_04_2025_06-03-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\30-Apr-2025\30_04_2025_09-03-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\30-Apr-2025\30_04_2025_11-24-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\April\30-Apr-2025\30_04_2025_12-34-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\01-Aug-2024\01_08_2024_03-17-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\01-Aug-2024\01_08_2024_03-28-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\01-Aug-2025\01_08_2025_12-32-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\02-Aug-2024\02_08_2024_03-24-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\02-Aug-2024\02_08_2024_06-02-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\02-Aug-2024\02_08_2024_09-02-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\02-Aug-2024\02_08_2024_11-31-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\02-Aug-2024\02_08_2024_12-32-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\02-Aug-2025\02_08_2025_03-19-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\02-Aug-2025\02_08_2025_06-04-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\04-Aug-2025\04_08_2025_03-27-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\04-Aug-2025\04_08_2025_06-02-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\04-Aug-2025\04_08_2025_09-02-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\04-Aug-2025\04_08_2025_11-17-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\04-Aug-2025\04_08_2025_12-37-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\05-Aug-2024\05_08_2024_04-01-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\05-Aug-2024\05_08_2024_06-08-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\05-Aug-2024\05_08_2024_10-16-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\06-Aug-2024\06_08_2024_01-00-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\06-Aug-2024\06_08_2024_03-17-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\06-Aug-2024\06_08_2024_06-02-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\06-Aug-2024\06_08_2024_09-03-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\06-Aug-2024\06_08_2024_11-17-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\06-Aug-2024\06_08_2024_11-29-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\06-Aug-2024\06_08_2024_11-39-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\06-Aug-2024\06_08_2024_11-55-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\07-Aug-2024\07_08_2024_06-02-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\07-Aug-2024\07_08_2024_09-02-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\07-Aug-2024\07_08_2024_11-17-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\07-Aug-2024\07_08_2024_12-33-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\07-Aug-2025\07_08_2025_03-22-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\07-Aug-2025\07_08_2025_06-04-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\07-Aug-2025\07_08_2025_09-02-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\07-Aug-2025\07_08_2025_11-17-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\08-Aug-2025\08_08_2025_06-04-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\08-Aug-2025\08_08_2025_09-02-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\08-Aug-2025\08_08_2025_11-24-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\08-Aug-2025\08_08_2025_12-32-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\09-Aug-2024\09_08_2024_03-19-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\09-Aug-2024\09_08_2024_06-02-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\09-Aug-2024\09_08_2024_09-22-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\09-Aug-2024\09_08_2024_11-20-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\10-Aug-2024\10_08_2024_09-02-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\10-Aug-2024\10_08_2024_11-18-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\10-Aug-2024\10_08_2024_12-33-PM\HDFC_BRS_Sheet.xlsx
- D:\Techexcel\Upload\BRS_Pending\August\11-Aug-2025\11_08_2025_03-17-PM\HDFC_BRS_Sheet.xlsx


Note that Nessus has limited the report to 255 files although there
may be more.
11777 - Microsoft Windows SMB Share Hosting Possibly Copyrighted Material
-
Synopsis
The remote host may contain material (movies/audio) infringing copyright.
Description
This plugin displays a list of media files (such as .mp3, .ogg, .mpg, .avi) which have been found on the remote SMB shares.

Some of these files may contain copyrighted materials, such as commercial movies or music files, that are being shared without the owner's permission.

If any of these files actually contain copyrighted material, and if they are freely swapped around, your organization might be held liable for copyright infringement by associations such as the RIAA or the MPAA.
Solution
Delete the files infringing copyright.
Risk Factor
None
Plugin Information
Published: 2003/06/26, Modified: 2012/11/29
Plugin Output

tcp/445/cifs


Here is a list of files which have been found on the remote SMB shares.
Some of these files may contain copyrighted materials, such as commercial
movies or music files.

+ C$ :

C:\Users\Techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\audioCues\browser\media\quickFixes.mp3
C:\Users\Techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\audioCues\browser\media\taskCompleted.mp3
C:\Users\Techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\audioCues\browser\media\taskFailed.mp3
C:\Users\Techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\audioCues\browser\media\terminalBell.mp3
C:\Users\Techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\audioCues\browser\media\warning.mp3
C:\Users\Techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\audioCues\browser\media\foldedAreas.mp3
C:\Users\Techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\audioCues\browser\media\error.mp3
C:\Users\Techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\audioCues\browser\media\diffLineInserted.mp3
C:\Users\Techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\audioCues\browser\media\diffLineDeleted.mp3
C:\Users\Techexcel\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\platform\audioCues\browser\media\break.mp3
C:\Program Files\WindowsApps\Microsoft.XboxApp_48.104.4001.0_x64__8wekyb3d8bbwe\Assets\AchievementUnlocked.mp3
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.5965.1.5\amd64_ppi-ppiskype-c-a_31bf3856ad364e35_10.0.19041.5678_none_e6a31335888e3272\f\lync_lobbywaiting.wma

60119 - Microsoft Windows SMB Share Permissions Enumeration
-
Synopsis
It was possible to enumerate the permissions of remote network shares.
Description
By using the supplied credentials, Nessus was able to enumerate the permissions of network shares. User permissions are enumerated for each network share that has a list of access control entries (ACEs).
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2012/07/25, Modified: 2022/08/11
Plugin Output

tcp/445/cifs


Share path : \\LIVETECHROBO\Logs
Local path : C:\Users\Techrobot\AppData\Local\UiPath\Logs
[*] Allow ACE for LIVETECHROBO\Techapp (S-1-5-21-2193062927-1383316644-2198579232-1006): 0x001301bf
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: NO
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: YES
FILE_ADD_FILE: YES
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: NO
DELETE: YES
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: NO
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: YES
FILE_CREATE_PIPE_INSTANCE: YES
FILE_WRITE_ATTRIBUTES: YES
[*] Allow ACE for LIVETECHROBO\Techexcel (S-1-5-21-2193062927-1383316644-2198579232-1005): 0x001f01ff
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: YES
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: YES
FILE_ADD_FILE: YES
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: YES
DELETE: YES
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: YES
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: YES
FILE_CREATE_PIPE_INSTANCE: YES
FILE_WRITE_ATTRIBUTES: YES
[*] Allow ACE for LIVETECHROBO\Techrobot (S-1-5-21-2193062927-1383316644-2198579232-1004): 0x001f01ff
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: YES
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: YES
FILE_ADD_FILE: YES
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: YES
DELETE: YES
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: YES
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: YES
FILE_CREATE_PIPE_INSTANCE: YES
FILE_WRITE_ATTRIBUTES: YES

Share path : \\LIVETECHROBO\Packages
Local path : C:\ProgramData\UiPath\Packages
[*] Allow ACE for LIVETECHROBO\Techexcel (S-1-5-21-2193062927-1383316644-2198579232-1005): 0x001f01ff
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: YES
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: YES
FILE_ADD_FILE: YES
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: YES
DELETE: YES
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: YES
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: YES
FILE_CREATE_PIPE_INSTANCE: YES
FILE_WRITE_ATTRIBUTES: YES
[*] Allow ACE for LIVETECHROBO\Techrobot (S-1-5-21-2193062927-1383316644-2198579232-1004): 0x001f01ff
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: YES
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: YES
FILE_ADD_FILE: YES
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: YES
DELETE: YES
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: YES
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: YES
FILE_CREATE_PIPE_INSTANCE: YES
FILE_WRITE_ATTRIBUTES: YES

Share path : \\LIVETECHROBO\Techexcel
Local path : D:\Techexcel
[*] Allow ACE for Everyone (S-1-1-0): 0x001200a9
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: NO
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: NO
FILE_ADD_FILE: NO
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: NO
DELETE: NO
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: NO
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: NO
FILE_CREATE_PIPE_INSTANCE: NO
FILE_WRITE_ATTRIBUTES: NO
[*] Allow ACE for LIVETECHROBO\Techapp (S-1-5-21-2193062927-1383316644-2198579232-1006): 0x001200a9
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: NO
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: NO
FILE_ADD_FILE: NO
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: NO
DELETE: NO
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: NO
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: NO
FILE_CREATE_PIPE_INSTANCE: NO
FILE_WRITE_ATTRIBUTES: NO
[*] Allow ACE for LIVETECHROBO\Techexcel (S-1-5-21-2193062927-1383316644-2198579232-1005): 0x001200a9
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: NO
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: NO
FILE_ADD_FILE: NO
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: NO
DELETE: NO
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: NO
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: NO
FILE_CREATE_PIPE_INSTANCE: NO
FILE_WRITE_ATTRIBUTES: NO
[*] Allow ACE for LIVETECHROBO\Techrobot (S-1-5-21-2193062927-1383316644-2198579232-1004): 0x001200a9
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: NO
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: NO
FILE_ADD_FILE: NO
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: NO
DELETE: NO
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: NO
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: NO
FILE_CREATE_PIPE_INSTANCE: NO
FILE_WRITE_ATTRIBUTES: NO
10396 - Microsoft Windows SMB Shares Access
-
Synopsis
It is possible to access a network share.
Description
The remote has one or more Windows shares that can be accessed through the network with the given credentials.

Depending on the share rights, it may allow an attacker to read / write confidential data.
Solution
To restrict access under Windows, open Explorer, do a right click on each share, go to the 'sharing' tab, and click on 'permissions'.
Risk Factor
None
Plugin Information
Published: 2000/05/09, Modified: 2021/10/04
Plugin Output

tcp/445/cifs


The following shares can be accessed as tidua :

- ADMIN$ - (readable,writable)
+ Content of this share :
..
addins
appcompat
apppatch
AppReadiness
assembly
bcastdvr
bfsvc.exe
BitLockerDiscoveryVolumeContents
Boot
bootstat.dat
Branding
CbsTemp
comsetup.log
Containers
CSC
Cursors
debug
diagerr.xml
diagnostics
DiagTrack
diagwrn.xml
DigitalLocker
Downloaded Program Files
DtcInstall.log
ELAMBKUP
en-US
explorer.exe
Fonts
GameBarPresenceWriter
Globalization
Help
HelpPane.exe
hh.exe
IdentityCRL
IME
ImmersiveControlPanel
InboxApps
INF
InputMethod
Installer
L2Schemas
LanguageOverlayCache
LiveKernelReports
Logs
Media
mib.bin
Microsoft.NET
Migration
Minidump
ModemLogs
notepad.exe
nsr2658.tmp
OCR
Offline Web Pages
Panther
PCHEALTH
Performance
PFRO.log
PLA
PolicyDefinitions
Prefetch
PrintDialog
Professional.xml
Provisioning
regedit.exe
Registration
RemotePackages
rescache
Resources
SchCache
schemas
security
ServiceProfiles
ServiceState
servicing
Setup
setuperr.log
ShellComponents
ShellExperiences
SHELLNEW
SKB
SoftwareDistribution
Speech
Speech_OneCore
splwow64.exe
System
system.ini
System32
SystemApps

- C$ - (readable,writable)
+ Content of this share :
$WinREAgent
CDASLogs
CDSLSecureapp
CDSLSecureapp___ol
Documents and Settings
DumpStack.log
DumpStack.log.tmp
inetpub
MSOCache
pagefile.sys
PerfLogs
Program Files
Program Files (x86)
ProgramData
Recovery
Reports
swapfile.sys
System Volume Information
Techexcel Setup
Users
Windows

- D$ - (readable,writable)
+ Content of this share :
15770340001410_10072025_1200.CSV
Download
Firefox Setup 134.0.exe
Firefox_Installer_134.zip
impt
lkpsoft
pagefile.sys
Program Files
Program Files (x86)
System Volume Information
Techexcel
Win

- Techexcel - (readable)
+ Content of this share :
..
AppData
AppData.zip
Downloads
Export
FirefoxUpdateDisable.reg
HDFCBRSExcelSheet
IE 8-11 Version.reg
Import
newTemp
OdinData
OMNISYSDATA
RPALog
RPASettings
Temp
UiPathStudio.msi
UiPathStudioSetup.exe
Upload

- G$ - (readable,writable)
+ Content of this share :
$WINRE_BACKUP_PARTITION.MARKER
Boot
bootmgr
BOOTNXT
BOOTSECT.BAK
Recovery
System Volume Information
10395 - Microsoft Windows SMB Shares Enumeration
-
Synopsis
It is possible to enumerate remote network shares.
Description
By connecting to the remote host, Nessus was able to enumerate the network share names.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2000/05/09, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Here are the SMB shares available on the remote host when logged in as tidua:

- ADMIN$
- C$
- D$
- G$
- IPC$
- Logs
- Packages
- Techexcel
100871 - Microsoft Windows SMB Versions Supported (remote check)
-
Synopsis
It was possible to obtain information about the version of SMB running on the remote host.
Description
Nessus was able to obtain the version of SMB running on the remote host by sending an authentication request to port 139 or 445.

Note that this plugin is a remote check and does not work on agents.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2017/06/19, Modified: 2019/11/22
Plugin Output

tcp/445/cifs


The remote host supports the following versions of SMB :
SMBv2
106716 - Microsoft Windows SMB2 and SMB3 Dialects Supported (remote check)
-
Synopsis
It was possible to obtain information about the dialects of SMB2 and SMB3 available on the remote host.
Description
Nessus was able to obtain the set of SMB2 and SMB3 dialects running on the remote host by sending an authentication request to port 139 or 445.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2018/02/09, Modified: 2020/03/11
Plugin Output

tcp/445/cifs


The remote host supports the following SMB dialects :
_version_ _introduced in windows version_
2.0.2 Windows 2008
2.1 Windows 7
3.0 Windows 8
3.0.2 Windows 8.1
3.1.1 Windows 10

The remote host does NOT support the following SMB dialects :
_version_ _introduced in windows version_
2.2.2 Windows 8 Beta
2.2.4 Windows 8 Beta
3.1 Windows 10

92368 - Microsoft Windows Scripting Host Settings
-
Synopsis
Nessus was able to collect and report the Windows scripting host settings from the remote host.
Description
Nessus was able to collect system and user level Windows scripting host settings from the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings\displaylogo : 1
HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings\usewinsafer : 1
HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings\silentterminate : 0
HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings\activedebugging : 1
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\displaylogo : 1
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\usewinsafer : 1
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\silentterminate : 0
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\activedebugging : 1

Windows scripting host configuration attached.

200493 - Microsoft Windows Start Menu Software Version Enumeration
-
Synopsis
Enumerates Start Menu software versions.
Description
This plugin enumerates the installed software version by interrogating information obtained from various registry entries and files on disk. This plugin provides a best guess at the software version and a confidence level for that version.

Note that the versions detected here do not necessarily indicate the actual installed version nor do they necessarily mean that the application is actually installed on the remote host. In some cases there may be artifacts left behind by uninstallers on the system.
Solution
Remove any applications that are not compliant with your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2024/06/13, Modified: 2025/12/15
Plugin Output

tcp/445/cifs

The following software information is available on the remote host :

- Excel 2016.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Excel 2016.lnk
Target : C:\WINDOWS\Installer\{90160000-0012-0000-1000-0000000FF1CE}\xlicons.exe
Version : 16.0.4266.1001

- Firefox Private Browsing.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Firefox Private Browsing.lnk
Target : C:\Program Files\Mozilla Firefox\private_browsing.exe
Version : 134.0.0.3375

- Firefox.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Firefox.lnk
Target : C:\Program Files\Mozilla Firefox\firefox.exe
Version : 134.0.0.3375

- Google Chrome.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Google Chrome.lnk
Target : C:\Program Files\Google\Chrome\Application\chrome.exe
Version : 143.0.7499.193

- Immersive Control Panel.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Immersive Control Panel.lnk
Target : C:\WINDOWS\System32\Control.exe
Version : 10.0.19041.5794

- Microsoft Edge.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Edge.lnk
Target : C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
Version : unknown

- OneDrive for Business.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\OneDrive for Business.lnk
Target : C:\WINDOWS\Installer\{90160000-0012-0000-1000-0000000FF1CE}\grv_icons.exe
Version : 16.0.4266.1001

- OneNote 2016.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\OneNote 2016.lnk
Target : C:\WINDOWS\Installer\{90160000-0012-0000-1000-0000000FF1CE}\joticon.exe
Version : 16.0.4266.1001

- Outlook 2016.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Outlook 2016.lnk
Target : C:\WINDOWS\Installer\{90160000-0012-0000-1000-0000000FF1CE}\outicon.exe
Version : 16.0.4266.1001

- PC Health Check.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\PC Health Check.lnk
Target : C:\Program Files\PCHealthCheck\PCHealthCheck.exe
Version : 3.6.2204.8001

- PowerPoint 2016.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\PowerPoint 2016.lnk
Target : C:\WINDOWS\Installer\{90160000-0012-0000-1000-0000000FF1CE}\pptico.exe
Version : 16.0.4266.1001

- Publisher 2016.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Publisher 2016.lnk
Target : C:\WINDOWS\Installer\{90160000-0012-0000-1000-0000000FF1CE}\pubs.exe
Version : 16.0.4266.1001

- Word 2016.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Word 2016.lnk
Target : C:\WINDOWS\Installer\{90160000-0012-0000-1000-0000000FF1CE}\wordicon.exe
Version : 16.0.4266.1001

- 7-Zip File Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\7-Zip\7-Zip File Manager.lnk
Target : C:\Program Files\7-Zip\7zFM.exe
Version : 19.0.0.0

- 7-Zip Help.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\7-Zip\7-Zip Help.lnk
Target : C:\Program Files\7-Zip\7-zip.chm
Version : unknown

- Speech Recognition.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessibility\Speech Recognition.lnk
Target : C:\WINDOWS\Speech\Common\sapisvr.exe
Version : 5.3.24006.0

- Math Input Panel.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Math Input Panel.lnk
Target : C:\Program Files\Common Files\Microsoft Shared\Ink\mip.exe
Version : 10.0.19041.4355

- Notepad.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Notepad.lnk
Target : C:\WINDOWS\system32\notepad.exe
Version : 10.0.19041.5794

- Paint.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Paint.lnk
Target : C:\WINDOWS\system32\mspaint.exe
Version : 10.0.19041.5553

- Quick Assist.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Quick Assist.lnk
Target : C:\WINDOWS\system32\quickassist.exe
Version : 10.0.19041.5794

- Remote Desktop Connection.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Remote Desktop Connection.lnk
Target : C:\WINDOWS\system32\mstsc.exe
Version : 10.0.19041.5965

- Snipping Tool.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Snipping Tool.lnk
Target : C:\WINDOWS\system32\SnippingTool.exe
Version : 10.0.19041.5794

- Steps Recorder.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Steps Recorder.lnk
Target : C:\WINDOWS\system32\psr.exe
Version : 10.0.19041.3636

- Windows Fax and Scan.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Windows Fax and Scan.lnk
Target : C:\WINDOWS\system32\WFS.exe
Version : 10.0.19041.4355

- Windows Media Player.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Windows Media Player.lnk
Target : C:\Program Files (x86)\Windows Media Player\wmplayer.exe
Version : 12.0.19041.3636

- Wordpad.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Wordpad.lnk
Target : C:\Program Files\Windows NT\Accessories\wordpad.exe
Version : 10.0.19041.5965

- Character Map.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\System Tools\Character Map.lnk
Target : C:\WINDOWS\system32\charmap.exe
Version : 5.2.3668.0

- Component Services.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Component Services.lnk
Target : C:\WINDOWS\system32\comexp.msc
Version : unknown

- Computer Management.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Computer Management.lnk
Target : C:\WINDOWS\system32\compmgmt.msc
Version : unknown

- dfrgui.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\dfrgui.lnk
Target : C:\WINDOWS\system32\dfrgui.exe
Version : 10.0.19041.3636

- Disk Cleanup.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Disk Cleanup.lnk
Target : C:\WINDOWS\system32\cleanmgr.exe
Version : 10.0.19041.5915

- Event Viewer.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Event Viewer.lnk
Target : C:\WINDOWS\system32\eventvwr.msc
Version : unknown

- iSCSI Initiator.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\iSCSI Initiator.lnk
Target : C:\WINDOWS\system32\iscsicpl.exe
Version : 10.0.19041.1

- Memory Diagnostics Tool.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Memory Diagnostics Tool.lnk
Target : C:\WINDOWS\system32\MdSched.exe
Version : 10.0.19041.1

- ODBC Data Sources (32-bit).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\ODBC Data Sources (32-bit).lnk
Target : C:\WINDOWS\syswow64\odbcad32.exe
Version : 10.0.19041.1

- ODBC Data Sources (64-bit).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\ODBC Data Sources (64-bit).lnk
Target : C:\WINDOWS\system32\odbcad32.exe
Version : 10.0.19041.1

- Performance Monitor.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Performance Monitor.lnk
Target : C:\WINDOWS\system32\perfmon.msc
Version : unknown

- Print Management.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Print Management.lnk
Target : C:\WINDOWS\system32\printmanagement.msc
Version : unknown

- RecoveryDrive.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\RecoveryDrive.lnk
Target : C:\WINDOWS\system32\RecoveryDrive.exe
Version : 10.0.19041.5965

- Registry Editor.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Registry Editor.lnk
Target : C:\WINDOWS\regedit.exe
Version : 10.0.19041.4355

- Resource Monitor.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Resource Monitor.lnk
Target : C:\WINDOWS\system32\perfmon.exe
Version : 10.0.19041.1

- Security Configuration Management.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Security Configuration Management.lnk
Target : C:\WINDOWS\system32\secpol.msc
Version : unknown

- services.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\services.lnk
Target : C:\WINDOWS\system32\services.msc
Version : unknown

- System Configuration.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\System Configuration.lnk
Target : C:\WINDOWS\system32\msconfig.exe
Version : 10.0.19041.3636

- System Information.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\System Information.lnk
Target : C:\WINDOWS\system32\msinfo32.exe
Version : 10.0.19041.3636

- Task Scheduler.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Task Scheduler.lnk
Target : C:\WINDOWS\system32\taskschd.msc
Version : unknown

- Windows Defender Firewall with Advanced Security.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Windows Defender Firewall with Advanced Security.lnk
Target : C:\WINDOWS\system32\WF.msc
Version : unknown

- Azure Data Studio.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Azure Data Studio\Azure Data Studio.lnk
Target : C:\Program Files\Azure Data Studio\azuredatastudio.exe
Version : 1.32.0.0

- About Java.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Java\About Java.lnk
Target : C:\Program Files\Java\jre1.8.0_161\bin\javacpl.exe
Version : 11.161.2.12

- Check For Updates.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Java\Check For Updates.lnk
Target : C:\Program Files\Java\jre1.8.0_161\bin\javacpl.exe
Version : 11.161.2.12

- Configure Java.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Java\Configure Java.lnk
Target : C:\Program Files\Java\jre1.8.0_161\bin\javacpl.exe
Version : 11.161.2.12

- Java Mission Control.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Java Development Kit\Java Mission Control.lnk
Target : C:\Program Files\Java\jdk1.8.0_161\bin\jmc.exe
Version : unknown

- Kaspersky Endpoint Security for Windows.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Kaspersky Endpoint Security for Windows\Kaspersky Endpoint Security for Windows.lnk
Target : C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avpui.exe
Version : 21.15.8.493

- Lucee-Tomcat Service Control.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Lucee\Lucee-Tomcat Service Control.lnk
Target : D:\Techexcel\Lucee\tomcat\bin\Luceew.exe
Version : unknown

- Lucee-Tomcat Service Monitor.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Lucee\Lucee-Tomcat Service Monitor.lnk
Target : D:\Techexcel\Lucee\tomcat\bin\Luceew.exe
Version : unknown

- Tomcat Host Config.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Lucee\Tomcat Host Config.lnk
Target : C:\WINDOWS\system32\notepad.exe
Version : 10.0.19041.5794

- Uninstall Lucee.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Lucee\Uninstall Lucee.lnk
Target : D:\Techexcel\Lucee\uninstall.exe
Version : unknown

- Office 2016 Language Preferences.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office 2016 Tools\Office 2016 Language Preferences.lnk
Target : C:\WINDOWS\Installer\{90160000-0012-0000-1000-0000000FF1CE}\misc.exe
Version : 16.0.4266.1001

- Office 2016 Upload Center.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office 2016 Tools\Office 2016 Upload Center.lnk
Target : C:\WINDOWS\Installer\{90160000-0012-0000-1000-0000000FF1CE}\msouc.exe
Version : 16.0.4266.1001

- Telemetry Dashboard for Office 2016.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office 2016 Tools\Telemetry Dashboard for Office 2016.lnk
Target : C:\WINDOWS\Installer\{90160000-0012-0000-1000-0000000FF1CE}\osmadminicon.exe
Version : 16.0.4266.1001

- Telemetry Log for Office 2016.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office 2016 Tools\Telemetry Log for Office 2016.lnk
Target : C:\WINDOWS\Installer\{90160000-0012-0000-1000-0000000FF1CE}\osmclienticon.exe
Version : 16.0.4266.1001

- Microsoft Silverlight.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Silverlight\Microsoft Silverlight.lnk
Target : C:\Program Files\Microsoft Silverlight\5.1.50907.0\Silverlight.Configuration.exe
Version : 5.1.50907.0

- SQL Server 2019 Import and Export Data (64-bit).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2019\SQL Server 2019 Import and Export Data (64-bit).lnk
Target : D:\Program Files\Microsoft SQL Server\150\DTS\Binn\DTSWizard.exe
Version : unknown

- SQL Server 2019 Configuration Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2019\Configuration Tools\SQL Server 2019 Configuration Manager.lnk
Target : C:\Windows\SysWOW64\mmc.exe
Version : 10.0.19041.5965

- SQL Server 2019 Error and Usage Reporting.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2019\Configuration Tools\SQL Server 2019 Error and Usage Reporting.lnk
Target : C:\Program Files\Microsoft SQL Server\150\Shared\SqlWtsn.exe
Version : 15.0.2000.5

- SQL Server 2019 Installation Center (64-bit).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2019\Configuration Tools\SQL Server 2019 Installation Center (64-bit).lnk
Target : C:\Program Files\Microsoft SQL Server\150\Setup Bootstrap\SQL2019\x64\LandingPage.exe
Version : 15.0.2130.3

- Analysis Services Deployment Wizard 18.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server Tools 18\Analysis Services Deployment Wizard 18.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server Management Studio 18\Common7\IDE\Microsoft.AnalysisServices.Deployment.exe
Version : 15.0.19714.0

- Microsoft SQL Server Management Studio 18.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server Tools 18\Microsoft SQL Server Management Studio 18.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server Management Studio 18\Common7\IDE\Ssms.exe
Version : 2019.150.18390.0

- Database Engine Tuning Advisor 18.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server Tools 18\Performance Tools\Database Engine Tuning Advisor 18.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server Management Studio 18\Common7\DTASHELL.EXE
Version : 15.0.18390.0

- SQL Server Profiler 18.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server Tools 18\Performance Tools\SQL Server Profiler 18.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server Management Studio 18\Common7\PROFILER.EXE
Version : 2019.150.18390.0

- Notepad++.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Notepad++\Notepad++.lnk
Target : C:\Program Files (x86)\Notepad++\notepad++.exe
Version : 6.9.0.0

- Task Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\System Tools\Task Manager.lnk
Target : C:\WINDOWS\system32\taskmgr.exe
Version : 10.0.19041.5794

- TightVNC Viewer.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\TightVNC\TightVNC Viewer.lnk
Target : C:\Program Files\TightVNC\tvnviewer.exe
Version : 2.8.11.0

- Visit TightVNC Web Site.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\TightVNC\Visit TightVNC Web Site.lnk
Target : C:\Program Files\TightVNC\TightVNC Web Site.url
Version : unknown

- Run TightVNC Server.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\TightVNC\TightVNC Server (Application Mode)\Run TightVNC Server.lnk
Target : C:\Program Files\TightVNC\tvnserver.exe
Version : 2.8.11.0

- TightVNC Server - Control Interface.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\TightVNC\TightVNC Server (Application Mode)\TightVNC Server - Control Interface.lnk
Target : C:\Program Files\TightVNC\tvnserver.exe
Version : 2.8.11.0

- TightVNC Server - Offline Configuration.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\TightVNC\TightVNC Server (Application Mode)\TightVNC Server - Offline Configuration.lnk
Target : C:\Program Files\TightVNC\tvnserver.exe
Version : 2.8.11.0

- Register TightVNC Service.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\TightVNC\TightVNC Server (Service Mode)\Register TightVNC Service.lnk
Target : C:\Program Files\TightVNC\tvnserver.exe
Version : 2.8.11.0

- Start TightVNC Service.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\TightVNC\TightVNC Server (Service Mode)\Start TightVNC Service.lnk
Target : C:\Program Files\TightVNC\tvnserver.exe
Version : 2.8.11.0

- Stop TightVNC Service.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\TightVNC\TightVNC Server (Service Mode)\Stop TightVNC Service.lnk
Target : C:\Program Files\TightVNC\tvnserver.exe
Version : 2.8.11.0

- TightVNC Service - Control Interface.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\TightVNC\TightVNC Server (Service Mode)\TightVNC Service - Control Interface.lnk
Target : C:\Program Files\TightVNC\tvnserver.exe
Version : 2.8.11.0

- TightVNC Service - Offline Configuration.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\TightVNC\TightVNC Server (Service Mode)\TightVNC Service - Offline Configuration.lnk
Target : C:\Program Files\TightVNC\tvnserver.exe
Version : 2.8.11.0

- Unregister TightVNC Service.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\TightVNC\TightVNC Server (Service Mode)\Unregister TightVNC Service.lnk
Target : C:\Program Files\TightVNC\tvnserver.exe
Version : 2.8.11.0

- TreeSize Free (Administrator).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\TreeSize Free\TreeSize Free (Administrator).lnk
Target : C:\Program Files (x86)\JAM Software\TreeSize Free\TreeSizeFree.exe
Version : 4.4.2.514

- TreeSize Free Help.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\TreeSize Free\TreeSize Free Help.lnk
Target : C:\Program Files (x86)\JAM Software\TreeSize Free\TreeSizeFree.chm
Version : unknown

- TreeSize Free.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\TreeSize Free\TreeSize Free.lnk
Target : C:\Program Files (x86)\JAM Software\TreeSize Free\TreeSizeFree.exe
Version : 4.4.2.514

- start VM Statistics Logging.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\VMware\VMware Tools\start VM Statistics Logging.lnk
Target : C:\Windows\System32\perfmon.msc
Version : unknown

- Windows PowerShell ISE (x86).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Windows PowerShell\Windows PowerShell ISE (x86).lnk
Target : C:\WINDOWS\syswow64\WindowsPowerShell\v1.0\PowerShell_ISE.exe
Version : 10.0.19041.1

- Windows PowerShell ISE.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Windows PowerShell\Windows PowerShell ISE.lnk
Target : C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell_ISE.exe
Version : 10.0.19041.1

- Console RAR manual.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\WinRAR\Console RAR manual.lnk
Target : C:\Program Files\WinRAR\Rar.txt
Version : unknown

- What is new in the latest version.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\WinRAR\What is new in the latest version.lnk
Target : C:\Program Files\WinRAR\WhatsNew.txt
Version : unknown

- WinRAR help.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\WinRAR\WinRAR help.lnk
Target : C:\Program Files\WinRAR\WinRAR.chm
Version : unknown

- WinRAR.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\WinRAR\WinRAR.lnk
Target : C:\Program Files\WinRAR\WinRAR.exe
Version : 5.90.0.0
58452 - Microsoft Windows Startup Software Enumeration
-
Synopsis
It is possible to enumerate startup software.
Description
This plugin lists software that is configured to run on system startup by crawling the registry entries in :

- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersi on\Run
Solution
Review the list of applications and remove any that are not compliant with your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2012/03/23, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


The following startup item was found :

SecurityHealth - %windir%\system32\SecurityHealthSystray.exe
SunJavaUpdateSched - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
VMware User Process - C:\Program Files\VMware\VMware Tools\vmtoolsd.exe
tvncontrol - C:\Program Files\TightVNC\tvnserver.exe
38153 - Microsoft Windows Summary of Missing Patches
-
Synopsis
The remote host is missing several Microsoft security patches.
Description
This plugin summarizes updates for Microsoft Security Bulletins or Knowledge Base (KB) security updates that have not been installed on the remote Windows host based on the results of either a credentialed check using the supplied credentials or a check done using a supported third-party patch management tool.

Note the results of missing patches also include superseded patches.

Review the summary and apply any missing updates in order to be up to date.
Solution
Run Windows Update on the remote host or use a patch management solution.
Risk Factor
None
Plugin Information
Published: 2009/04/24, Modified: 2019/06/13
Plugin Output

tcp/445/cifs

The patches for the following bulletins or KBs are missing on the remote host :

- KB5002717 ( https://support.microsoft.com/en-us/help/5002717 )
- KB5002683 ( https://support.microsoft.com/en-us/help/5002683 )
- KB5002689 ( https://support.microsoft.com/en-us/help/5002689 )
- KB5002710 ( https://support.microsoft.com/en-us/help/5002710 )
- KB5002735 ( https://support.microsoft.com/en-us/help/5002735 )
- KB5002745 ( https://support.microsoft.com/en-us/help/5002745 )
- KB5002746 ( https://support.microsoft.com/en-us/help/5002746 )
- KB5002747 ( https://support.microsoft.com/en-us/help/5002747 )
- KB5002749 ( https://support.microsoft.com/en-us/help/5002749 )
- KB5062554 ( https://support.microsoft.com/en-us/help/5062554 )
- KB5002758 ( https://support.microsoft.com/en-us/help/5002758 )
- KB5002763 ( https://support.microsoft.com/en-us/help/5002763 )
- KB5002765 ( https://support.microsoft.com/en-us/help/5002765 )
- KB5063709 ( https://support.microsoft.com/en-us/help/5063709 )
- KB5002779 ( https://support.microsoft.com/en-us/help/5002779 )
- KB5002780 ( https://support.microsoft.com/en-us/help/5002780 )
- KB5002782 ( https://support.microsoft.com/en-us/help/5002782 )
- KB5065429 ( https://support.microsoft.com/en-us/help/5065429 )
- KB5002789 ( https://support.microsoft.com/en-us/help/5002789 )
- KB5002790 ( https://support.microsoft.com/en-us/help/5002790 )
- KB5002794 ( https://support.microsoft.com/en-us/help/5002794 )
- KB5066791 ( https://support.microsoft.com/en-us/help/5066791 )
- KB5002811 ( https://support.microsoft.com/en-us/help/5002811 )
- KB5068781 ( https://support.microsoft.com/en-us/help/5068781 )
- KB5002806 ( https://support.microsoft.com/en-us/help/5002806 )
- KB5002820 ( https://support.microsoft.com/en-us/help/5002820 )
- KB5071546 ( https://support.microsoft.com/en-us/help/5071546 )

92369 - Microsoft Windows Time Zone Information
-
Synopsis
Nessus was able to collect and report time zone information from the remote host.
Description
Nessus was able to collect time zone information from the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2023/06/06
Plugin Output

tcp/0

HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\TimeZoneKeyName : India Standard Time
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\StandardName : @tzres.dll,-492
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\DaylightName : @tzres.dll,-491
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\DynamicDaylightTimeDisabled : 0x00000000
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\StandardBias : 0x00000000
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\DaylightBias : 0xFFFFFFC4
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\Bias : 0xFFFFFEB6
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\ActiveTimeBias : 0xFFFFFEB6
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\DaylightStart : 00000000000000000000000000000000
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\StandardStart : 00000000000000000000000000000000
20862 - Mozilla Foundation Application Detection
-
Synopsis
The remote Windows host contains one or more applications from the Mozilla Foundation.
Description
There is at least one instance of Firefox, Thunderbird, SeaMonkey, or the Mozilla browser installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0672
Plugin Information
Published: 2006/02/05, Modified: 2025/08/18
Plugin Output

tcp/0



Product : Mozilla Firefox
Path : C:\Program Files\Mozilla Firefox
Version : 134.0
19506 - Nessus Scan Information
-
Synopsis
This plugin displays information about the Nessus scan.
Description
This plugin displays, for each tested host, information about the scan itself :

- The version of the plugin set.
- The type of scanner (Nessus or Nessus Home).
- The version of the Nessus Engine.
- The port scanner(s) used.
- The port range scanned.
- The ping round trip time
- Whether credentialed or third-party patch management checks are possible.
- Whether the display of superseded patches is enabled
- The date of the scan.
- The duration of the scan.
- The number of hosts scanned in parallel.
- The number of checks done in parallel.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2005/08/26, Modified: 2025/10/29
Plugin Output

tcp/0

Information about this scan :

Nessus version : 10.11.1
Nessus build : 20021
Plugin feed version : 202601041845
Scanner edition used : Nessus
Scanner OS : WINDOWS
Scanner distribution : win-x86-64
Scan type : Normal
Scan name : Server 4
Scan policy used : Server
Scanner IP : 172.17.100.38
Port scanner(s) : wmi_netstat
Port range : 1-65535
Ping RTT : Unavailable
Thorough tests : no
Experimental tests : no
Scan for Unpatched Vulnerabilities : yes
Plugin debugging enabled : yes (at debugging level 4)
Paranoia level : 0
Report verbosity : 2
Safe checks : yes
Optimize the test : yes
Credentialed checks : yes, as '172.17.100.35\tidua' via SMB
Patch management checks : None
Display superseded patches : yes (supersedence plugin did not launch)
CGI scanning : disabled
Web application tests : disabled
Max hosts : 2
Max checks : 2
Recv timeout : 5
Backports : None
Allow post-scan editing : Yes
Nessus Plugin Signature Checking : Enabled
Audit File Signature Checking : Disabled
Scan Start Date : 2026/1/16 16:15 India Standard Time (UTC +05:30)
Scan duration : 2963 sec
Scan for malware : no
58651 - Netstat Active Connections
-
Synopsis
Active connections are enumerated via the 'netstat' command.
Description
This plugin runs 'netstat' on the remote machine to enumerate all active 'ESTABLISHED' or 'LISTENING' tcp/udp connections.

Note: The output for this plugin can be very long, and is not shown by default. To display it, enable verbose reporting in scan settings.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2012/04/10, Modified: 2021/06/29
Plugin Output

tcp/0


Netstat output :

Active Connections

Proto Local Address Foreign Address State PID
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING 516
TCP 0.0.0.0:445 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:2323 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:3389 0.0.0.0:0 LISTENING 1116
TCP 0.0.0.0:5040 0.0.0.0:0 LISTENING 5180
TCP 0.0.0.0:5357 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:5800 0.0.0.0:0 LISTENING 3748
TCP 0.0.0.0:5900 0.0.0.0:0 LISTENING 3748
TCP 0.0.0.0:49664 0.0.0.0:0 LISTENING 868
TCP 0.0.0.0:49665 0.0.0.0:0 LISTENING 716
TCP 0.0.0.0:49666 0.0.0.0:0 LISTENING 1232
TCP 0.0.0.0:49667 0.0.0.0:0 LISTENING 1532
TCP 0.0.0.0:49668 0.0.0.0:0 LISTENING 2968
TCP 0.0.0.0:49669 0.0.0.0:0 LISTENING 860
TCP 0.0.0.0:49670 0.0.0.0:0 LISTENING 3464
TCP 0.0.0.0:62039 0.0.0.0:0 LISTENING 3088
TCP 127.0.0.1:2323 0.0.0.0:0 LISTENING 4
TCP 127.0.0.1:30523 0.0.0.0:0 LISTENING 11396
TCP 127.0.0.1:49715 0.0.0.0:0 LISTENING 3604
TCP 127.0.0.1:50081 0.0.0.0:0 LISTENING 11396
TCP 172.17.100.35:135 172.17.100.38:56953 ESTABLISHED 516
TCP 172.17.100.35:139 0.0.0.0:0 LISTENING 4
TCP 172.17.100.35:445 172.17.100.38:56952 ESTABLISHED 4
TCP 172.17.100.35:445 172.17.100.62:63641 ESTABLISHED 4
TCP 172.17.100.35:445 172.17.100.62:63642 ESTABLISHED 4
TCP 172.17.100.35:445 172.17.100.62:63643 ESTABLISHED 4
TCP 172.17.100.35:445 172.17.100.62:63644 ESTABLISHED 4
TCP 172.17.100.35:445 192.168.150.117:50033 ESTABLISHED 4
TCP 172.17.100.35:5900 172.17.100.33:51691 ESTABLISHED 3748
TCP 172.17.100.35:5900 172.17.100.33:59903 ESTABLISHED 3748
TCP 172.17.100.35:5900 172.17.100.62:54857 ESTABLISHED 3748
TCP 172.17.100.35:5900 172.17.100.62:65018 ESTABLISHED 3748
TCP 172.17.100.35:50684 74.125.130.188:5228 ESTABLISHED 14012
TCP 172.17.100.35:51563 192.168.150.54:445 ESTABLISHED 4
TCP 172.17.100.35:52052 4.145.79.82:443 ESTABLISHED 3860
TCP 172.17.100.35:53000 151.101.193.91:443 ESTABLISHED 14012
TCP 172.17.100.35:53064 8.8.8.8:443 ESTABLISHED 14012
TCP 172.17.100.35:53694 172.17.100.31:445 ESTABLISHED 4
TCP 172.17.100.35:53695 172.17.100.31:51433 ESTABLISHED 18848
TCP 172.17.100.35:53696 172.17.100.31:51433 ESTABLISHED 18848
TCP 172.17.100.35:53702 20.213.196.212:443 ESTABLISHED 18848
TCP 172.17.100.35:53831 43.228.176.221:443 ESTABLISHED 14012
TCP 172.17.100.35:53840 43.228.176.221:443 ESTABLISHED 14012
TCP 172.17.100.35:53841 43.228.176.221:443 ESTABLISHED 14012
TCP 172.17.100.35:53843 43.228.176.221:443 ESTABLISHED 14012
TCP 172.17.100.35:54025 43.228.176.221:443 ESTABLISHED 14012
TCP 172.17.100.35:54048 172.17.100.31:51433 ESTABLISHED 18848
TCP 172.17.100.35:54107 142.250.67.234:443 ESTABLISHED 14012
TCP 172.17.100.35:54131 4.1.82.185:443 ESTABLISHED 3604
TCP 172.17.100.35:54144 103.216.76.97:443 TIME_WAIT 0
TCP 172.17.100.35:54145 103.216.76.97:443 TIME_WAIT 0
TCP 172.17.100.35:54146 103.216.76.97:443 TIME_WAIT 0
TCP 172.17.100.35:54147 103.216.76.97:443 TIME_WAIT 0
TCP 172.17.100.35:54148 103.216.76.97:443 TIME_WAIT 0
TCP 172.17.100.35:54149 103.216.76.97:443 TIME_WAIT 0
TCP 172.17.100.35:54150 103.216.76.97:443 TIME_WAIT 0
TCP 172.17.100.35:54151 103.216.76.97:443 TIME_WAIT 0
TCP 172.17.100.35:54152 103.216.76.97:443 TIME_WAIT 0
TCP 172.17.100.35:54153 103.216.76.97:443 TIME_WAIT 0
TCP 172.17.100.35:54158 192.168.10.20:13000 TIME_WAIT 0
TCP 172.17.100.35:54159 4.1.82.185:443 TIME_WAIT 0
TCP 172.17.100.35:54161 175.100.160.199:443 ESTABLISHED 14012
TCP 172.17.100.35:54163 175.100.160.199:443 FIN_WAIT_2 14012
TCP 172.17.100.35:54169 82.202.184.184:443 CLOSE_WAIT 752
TCP 172.17.100.35:54170 79.133.170.66:443 TIME_WAIT 0
TCP 172.17.100.35:54173 172.217.174.74:443 ESTABLISHED 18764
TCP 172.17.100.35:54174 185.201.3.104:443 ESTABLISHED 3604
TCP 172.17.100.35:54185 192.168.10.20:13000 TIME_WAIT 0
TCP 172.17.100.35:54186 4.1.82.185:443 TIME_WAIT 0
TCP 172.17.100.35:54187 175.100.160.199:443 ESTABLISHED 14012
TCP 172.17.100.35:54188 175.100.160.199:443 ESTABLISHED 14012
TCP 172.17.100.35:54189 142.250.205.196:443 ESTABLISHED 14012
TCP 172.17.100.35:54190 175.100.160.199:443 ESTABLISHED 14012
TCP 172.17.100.35:54191 175.100.160.199:443 ESTABLISHED 14012
TCP 172.17.100.35:54192 175.100.160.199:443 ESTABLISHED 14012
TCP 172.17.100.35:54193 175.100.160.199:443 ESTABLISHED 14012
TCP 172.17.100.35:62039 172.17.100.38:56956 ESTABLISHED 3088
TCP [::]:135 [::]:0 LISTENING 516
TCP [::]:445 [::]:0 LISTENING 4
TCP [::]:2323 [::]:0 LISTENING 4
TCP [::]:3389 [::]:0 LISTENING 1116
TCP [::]:5357 [::]:0 LISTENING 4
TCP [::]:49664 [::]:0 LISTENING 868
TCP [::]:49665 [::]:0 LISTENING 716
TCP [::]:49666 [::]:0 LISTENING 1232
TCP [::]:49667 [::]:0 LISTENING 1532
TCP [::]:49668 [::]:0 LISTENING 2968
TCP [::]:49669 [::]:0 LISTENING 860
TCP [::]:49670 [::]:0 LISTENING 3464
TCP [::]:62039 [::]:0 LISTENING 3088
TCP [::1]:29831 [::]:0 LISTENING 744
TCP [::1]:30523 [::]:0 LISTENING 11396
TCP [::1]:42050 [::]:0 LISTENING 16212
TCP [::1]:42050 [::]:0 LISTENING 18140
TCP [::1]:50081 [::]:0 LISTENING 11396
UDP 0.0.0.0:500 *:* 3456
UDP 0.0.0.0:3389 *:* 1116
UDP 0.0.0.0:3702 *:* 7560
UDP 0.0.0.0:3702 *:* 4068
UDP 0.0.0.0:3702 *:* 4068
UDP 0.0.0.0:3702 *:* 7560
UDP 0.0.0.0:4500 *:* 3456
UDP 0.0.0.0:5050 *:* 5180
UDP 0.0.0.0:5353 *:* 2672
UDP 0.0.0.0:5353 *:* 20024
UDP 0.0.0.0:5353 *:* 20024
UDP 0.0.0.0:5355 *:* 2672
UDP 0.0.0.0:15000 *:* 11396
UDP 0.0.0.0:51969 *:* 7560
UDP 0.0.0.0:51971 *:* 4068
UDP 127.0.0.1:1900 *:* 5252
UDP 127.0.0.1:50009 *:* 5252
UDP 127.0.0.1:63739 *:* 3196
UDP 172.17.100.35:137 *:* 4
UDP 172.17.100.35:138 *:* 4
UDP 172.17.100.35:1900 *:* 5252
UDP 172.17.100.35:50008 *:* 5252
UDP [::]:500 *:* 3456
UDP [::]:3389 *:* 1116
UDP [::]:3702 *:* 4068
UDP [::]:3702 *:* 4068
UDP [::]:3702 *:* 7560
UDP [::]:3702 *:* 7560
UDP [::]:4500 *:* 3456
UDP [::]:5353 *:* 2672
UDP [::]:5353 *:* 20024
UDP [::]:5355 *:* 2672
UDP [::]:15000 *:* 11396
UDP [::]:51970 *:* 7560
UDP [::]:51972 *:* 4068
UDP [::1]:1900 *:* 5252
UDP [::1]:50007 *:* 5252
UDP [fe80::72d1:e757:1c1a:f1bf%6]:1900 *:* 5252
UDP [fe80::72d1:e757:1c1a:f1bf%6]:50006 *:* 5252
64582 - Netstat Connection Information
-
Synopsis
Nessus was able to parse the results of the 'netstat' command on the remote host.
Description
The remote host has listening ports or established connections that Nessus was able to extract from the results of the 'netstat' command.

Note: The output for this plugin can be very long, and is not shown by default. To display it, enable verbose reporting in scan settings.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/02/13, Modified: 2023/05/23
Plugin Output

tcp/0

tcp4 (listen)
src: [host=0.0.0.0, port=135]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=445]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=2323]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=3389]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=5040]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=5357]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=5800]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=5900]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49664]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49665]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49666]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49667]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49668]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49669]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49670]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=62039]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=127.0.0.1, port=2323]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=127.0.0.1, port=30523]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=127.0.0.1, port=49715]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=127.0.0.1, port=50081]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=172.17.100.35, port=135]
dst: [host=172.17.100.38, port=56953]

tcp4 (listen)
src: [host=172.17.100.35, port=139]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=172.17.100.35, port=445]
dst: [host=172.17.100.38, port=56952]

tcp4 (established)
src: [host=172.17.100.35, port=445]
dst: [host=172.17.100.62, port=63641]

tcp4 (established)
src: [host=172.17.100.35, port=445]
dst: [host=172.17.100.62, port=63642]

tcp4 (established)
src: [host=172.17.100.35, port=445]
dst: [host=172.17.100.62, port=63643]

tcp4 (established)
src: [host=172.17.100.35, port=445]
dst: [host=172.17.100.62, port=63644]

tcp4 (established)
src: [host=172.17.100.35, port=445]
dst: [host=192.168.150.117, port=50033]

tcp4 (established)
src: [host=172.17.100.35, port=5900]
dst: [host=172.17.100.33, port=51691]

tcp4 (established)
src: [host=172.17.100.35, port=5900]
dst: [host=172.17.100.33, port=59903]

tcp4 (established)
src: [host=172.17.100.35, port=5900]
dst: [host=172.17.100.62, port=54857]

tcp4 (established)
src: [host=172.17.100.35, port=5900]
dst: [host=172.17.100.62, port=65018]

tcp4 (established)
src: [host=172.17.100.35, port=50684]
dst: [host=74.125.130.188, port=5228]

tcp4 (established)
src: [host=172.17.100.35, port=51563]
dst: [host=192.168.150.54, port=445]

tcp4 (established)
src: [host=172.17.100.35, port=52052]
dst: [host=4.145.79.82, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=53000]
dst: [host=151.101.193.91, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=53064]
dst: [host=8.8.8.8, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=53694]
dst: [host=172.17.100.31, port=445]

tcp4 (established)
src: [host=172.17.100.35, port=53695]
dst: [host=172.17.100.31, port=51433]

tcp4 (established)
src: [host=172.17.100.35, port=53696]
dst: [host=172.17.100.31, port=51433]

tcp4 (established)
src: [host=172.17.100.35, port=53702]
dst: [host=20.213.196.212, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=53831]
dst: [host=43.228.176.221, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=53840]
dst: [host=43.228.176.221, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=53841]
dst: [host=43.228.176.221, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=53843]
dst: [host=43.228.176.221, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=54025]
dst: [host=43.228.176.221, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=54048]
dst: [host=172.17.100.31, port=51433]

tcp4 (established)
src: [host=172.17.100.35, port=54107]
dst: [host=142.250.67.234, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=54131]
dst: [host=4.1.82.185, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=54144]
dst: [host=103.216.76.97, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=54145]
dst: [host=103.216.76.97, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=54146]
dst: [host=103.216.76.97, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=54147]
dst: [host=103.216.76.97, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=54148]
dst: [host=103.216.76.97, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=54149]
dst: [host=103.216.76.97, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=54150]
dst: [host=103.216.76.97, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=54151]
dst: [host=103.216.76.97, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=54152]
dst: [host=103.216.76.97, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=54153]
dst: [host=103.216.76.97, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=54158]
dst: [host=192.168.10.20, port=13000]

tcp4 (established)
src: [host=172.17.100.35, port=54159]
dst: [host=4.1.82.185, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=54161]
dst: [host=175.100.160.199, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=54163]
dst: [host=175.100.160.199, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=54169]
dst: [host=82.202.184.184, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=54170]
dst: [host=79.133.170.66, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=54173]
dst: [host=172.217.174.74, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=54174]
dst: [host=185.201.3.104, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=54185]
dst: [host=192.168.10.20, port=13000]

tcp4 (established)
src: [host=172.17.100.35, port=54186]
dst: [host=4.1.82.185, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=54187]
dst: [host=175.100.160.199, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=54188]
dst: [host=175.100.160.199, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=54189]
dst: [host=142.250.205.196, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=54190]
dst: [host=175.100.160.199, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=54191]
dst: [host=175.100.160.199, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=54192]
dst: [host=175.100.160.199, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=54193]
dst: [host=175.100.160.199, port=443]

tcp4 (established)
src: [host=172.17.100.35, port=62039]
dst: [host=172.17.100.38, port=56956]

tcp6 (listen)
src: [host=[::], port=135]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=445]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=2323]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=3389]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=5357]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49664]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49665]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49666]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49667]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49668]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49669]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49670]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=62039]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::1], port=29831]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::1], port=30523]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::1], port=42050]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::1], port=42050]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::1], port=50081]
dst: [host=[::], port=0]

udp4 (listen)
src: [host=0.0.0.0, port=500]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=3389]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=3702]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=3702]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=3702]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=3702]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=4500]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=5050]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=5353]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=5353]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=5353]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=5355]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=15000]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=51969]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=51971]
dst: [host=*, port=*]

udp4 (listen)
src: [host=127.0.0.1, port=1900]
dst: [host=*, port=*]

udp4 (listen)
src: [host=127.0.0.1, port=50009]
dst: [host=*, port=*]

udp4 (listen)
src: [host=127.0.0.1, port=63739]
dst: [host=*, port=*]

udp4 (listen)
src: [host=172.17.100.35, port=137]
dst: [host=*, port=*]

udp4 (listen)
src: [host=172.17.100.35, port=138]
dst: [host=*, port=*]

udp4 (listen)
src: [host=172.17.100.35, port=1900]
dst: [host=*, port=*]

udp4 (listen)
src: [host=172.17.100.35, port=50008]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=500]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=3389]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=3702]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=3702]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=3702]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=3702]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=4500]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=5353]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=5353]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=5355]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=15000]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=51970]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=51972]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::1], port=1900]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::1], port=50007]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[fe80::72d1:e757:1c1a:f1bf%6], port=1900]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[fe80::72d1:e757:1c1a:f1bf%6], port=50006]
dst: [host=*, port=*]
34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/0


Nessus was able to find 36 open ports.

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/135/epmap

Port 135/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/137/netbios-ns

Port 137/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/138

Port 138/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/139/smb

Port 139/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/445/cifs

Port 445/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/500

Port 500/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/1900

Port 1900/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/2323/www

Port 2323/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/3389/msrdp

Port 3389/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/3389

Port 3389/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/3702

Port 3702/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/4500

Port 4500/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/5040

Port 5040/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/5050

Port 5050/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/5353

Port 5353/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/5355/llmnr

Port 5355/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/5357/www

Port 5357/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/5800/www

Port 5800/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/5900/vnc

Port 5900/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/15000

Port 15000/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49664/dce-rpc

Port 49664/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49665/dce-rpc

Port 49665/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49666/dce-rpc

Port 49666/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49667/dce-rpc

Port 49667/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49668/dce-rpc

Port 49668/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49669/dce-rpc

Port 49669/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49670/dce-rpc

Port 49670/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/50008

Port 50008/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/51969

Port 51969/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/51971

Port 51971/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/62039

Port 62039/tcp was found to be open

24272 - Network Interfaces Enumeration (WMI)
-
Synopsis
Nessus was able to obtain the list of network interfaces on the remote host.
Description
Nessus was able, via WMI queries, to extract a list of network interfaces on the remote host and the IP addresses attached to them.
Note that this plugin only enumerates IPv6 addresses for systems running Windows Vista or later.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/02/03, Modified: 2025/12/15
Plugin Output

tcp/0

+ Network Interface Information :

- Network Interface = [00000001] Intel(R) 82574L Gigabit Network Connection
- MAC Address = 00:50:56:BC:FC:73
- IPAddress/IPSubnet = 172.17.100.35/255.255.255.0
- IPAddress/IPSubnet = fe80::72d1:e757:1c1a:f1bf/64


+ Routing Information :

Destination Netmask Gateway
----------- ------- -------
0.0.0.0 0.0.0.0 172.17.100.10
127.0.0.0 255.0.0.0 0.0.0.0
127.0.0.1 255.255.255.255 0.0.0.0
127.255.255.255 255.255.255.255 0.0.0.0
172.17.100.0 255.255.255.0 0.0.0.0
172.17.100.35 255.255.255.255 0.0.0.0
172.17.100.255 255.255.255.255 0.0.0.0
224.0.0.0 240.0.0.0 0.0.0.0
224.0.0.0 240.0.0.0 0.0.0.0
255.255.255.255 255.255.255.255 0.0.0.0
255.255.255.255 255.255.255.255 0.0.0.0
181646 - Notepad++ Installed (Windows)
-
Synopsis
Notepad++ is installed on the remote Windows host.
Description
Notepad++ is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/09/20, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\Program Files (x86)\Notepad++
Version : 6.9.0.0
209654 - OS Fingerprints Detected
-
Synopsis
Multiple OS fingerprints were detected.
Description
Using a combination of remote probes (TCP/IP, SMB, HTTP, NTP, SNMP, etc), it was possible to gather one or more fingerprints from the remote system. While the highest-confidence result was reported in plugin 11936, “OS Identification”, the complete set of fingerprints detected are reported here.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/02/26, Modified: 2025/03/03
Plugin Output

tcp/0


Following OS Fingerprints were found

Remote operating system : Microsoft Windows Server 2019
Confidence level : 56
Method : MLSinFP
Type : unknown
Fingerprint : unknown

Remote operating system : Windows
Confidence level : 50
Method : Misc
Type : general-purpose
Fingerprint : unknown

Remote operating system : Microsoft Windows 10 Pro Build 19045
Confidence level : 100
Method : SMB_OS
Type : general-purpose
Fingerprint : unknown

Remote operating system : Microsoft Windows 10 Pro Build 19045
Confidence level : 70
Method : HTTP
Type : general-purpose
Fingerprint : HTTP:Server: Microsoft-HTTPAPI/2.0


Remote operating system : Microsoft Windows 10 Pro Build 19045
Confidence level : 70
Method : SinFP
Type : general-purpose
Fingerprint : SinFP:
P1:B11113:F0x12:W65392:O0204ffff:M1460:
P2:B11113:F0x12:W65535:O0204ffff0103030801010402:M1460:
P3:B00000:F0x00:W0:O0:M0
P4:191601_7_p=49669

Following fingerprints could not be used to determine OS :
SSLcert:!:i/CN:LiveTechRobos/CN:LiveTechRobo
154c58f6843e420e9f268c42cd933c844ec89ae6
11936 - OS Identification
-
Synopsis
It is possible to guess the remote operating system.
Description
Using a combination of remote probes (e.g., TCP/IP, SMB, HTTP, NTP, SNMP, etc.), it is possible to guess the name of the remote operating system in use. It is also possible sometimes to guess the version of the operating system.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2003/12/09, Modified: 2025/06/03
Plugin Output

tcp/0


Remote operating system : Microsoft Windows 10 Pro Build 19045
Confidence level : 100
Method : SMB_OS


The remote host is running Microsoft Windows 10 Pro Build 19045

117887 - OS Security Patch Assessment Available
-
Synopsis
Nessus was able to log in to the remote host using the provided credentials and enumerate OS security patch levels.
Description
Nessus was able to determine OS security patch levels by logging into the remote host and running commands to determine the version of the operating system and its components. The remote host was identified as an operating system or device that Nessus supports for patch and update assessment. The necessary information was obtained to perform these checks.
Solution
n/a
Risk Factor
None
References
XREF IAVB:0001-B-0516
Plugin Information
Published: 2018/10/02, Modified: 2021/07/12
Plugin Output

tcp/445/cifs

OS Security Patch Assessment is available.

Account : 172.17.100.35\tidua
Protocol : SMB

92426 - OpenSaveMRU History
-
Synopsis
Nessus was able to enumerate opened and saved files on the remote host.
Description
Nessus was able to generate a report on files that were opened using the shell dialog box or saved using the shell dialog box. This is the box that appears when you attempt to save a document or open a document in Windows Explorer.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

Open / Save report attached.

71462 - Oracle Java JRE Premier Support and Extended Support Version Detection
-
Synopsis
The remote host contains one or more versions of the Oracle Java JRE that require long-term support.
Description
According to its version, there is at least one install of Oracle (formerly Sun) Java JRE that is potentially under either Premier Support or Extended Support.

Note that both support programs require vendor contracts. Premier Support provides upgrades and security fixes for five years after the general availability (GA) date. Extended Support provides upgrades and security fixes for three years after Premier Support ends.
See Also
Solution
To continue receiving updates and security fixes, contact the vendor regarding Premier Support or Extended Support contracts.
Risk Factor
None
Plugin Information
Published: 2013/12/16, Modified: 2022/04/11
Plugin Output

tcp/445/cifs



The following Java JRE installs are in Extended Support status :

Path : C:\Program Files\Java\jre1.8.0_161
Version : 8.0.161.12
Support dates : 2022-03-01 (end of Premier Support) / 2030-12-01 (end of Extended Support)

33545 - Oracle Java Runtime Environment (JRE) Detection
-
Synopsis
There is a Java runtime environment installed on the remote Windows host.
Description
One or more instances of Oracle's (formerly Sun's) Java Runtime Environment (JRE) is installed on the remote host. This may include private JREs bundled with the Java Development Kit (JDK).

- Additional instances of Java may be discovered if thorough tests are enabled.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0690
Plugin Information
Published: 2008/07/18, Modified: 2022/10/10
Plugin Output

tcp/0


Path : C:\Program Files\Java\jre1.8.0_161\
Version : 8.0.161.12
Binary Location : C:\Program Files\Java\jre1.8.0_161\bin\java.exe
66334 - Patch Report
-
Synopsis
The remote host is missing several patches.
Description
The remote host is missing one or more security patches. This plugin lists the newest version of each patch to install to make sure the remote host is up-to-date.

Note: Because the 'Show missing patches that have been superseded' setting in your scan policy depends on this plugin, it will always run and cannot be disabled.
Solution
Install the patches listed below.
Risk Factor
None
Plugin Information
Published: 2013/07/08, Modified: 2025/12/15
Plugin Output

tcp/0



. You need to take the following 21 actions :

+ Install the following Microsoft patches :
- KB5071546 (6 vulnerabilities)The following KBs would be covered:
KB5063709, KB5065429, KB5066791, KB5060533, KB5068781,
KB5062554
- KB5002820 (8 vulnerabilities)The following KBs would be covered:
KB5002758, KB5002782, KB5002794, KB5002704, KB5002717,
KB5002735, KB5002811, KB5002749
- KB5002806 (6 vulnerabilities)The following KBs would be covered:
KB5002763, KB5002780, KB5002702, KB5002710, KB5002789,
KB5002745
- KB5002790 (5 vulnerabilities)The following KBs would be covered:
KB5002765, KB5002779, KB5002586, KB5002689, KB5002746
- KB5002747
- KB5002683 (1 vulnerabilities)The following KBs would be covered:
KB5002656

[ 7-Zip < 25.01 (249179) ]

+ Action to take : Upgrade to 7-Zip version 25.01 or later.

+ Impact : Taking this action will resolve the following 11 different vulnerabilities :
CVE-2025-55188, CVE-2025-53817, CVE-2025-53816, CVE-2025-11002, CVE-2025-11001
CVE-2025-0411, CVE-2024-11477, CVE-2023-52169, CVE-2023-52168, CVE-2023-40481
CVE-2023-31102


[ Microsoft Azure Data Studio < 1.48.0 Elevation of Privilege Vulnerability (CVE-2024-26203) (192147) ]

+ Action to take : Upgrade to Microsoft Azure Data Studio version 1.48.0 or later.


[ Microsoft OneNote Spoofing(June 2023) (177383) ]

+ Action to take : Upgrade the Windows 'Microsoft OneNote' app to version 16.0.14326.21450 or later via the Microsoft Store.


[ Microsoft Paint 3D Code Execution (July 2023) (178245) ]

+ Action to take : Upgrade the Windows 'Paint 3D' app to version 6.2305.16087.0, or later via the Microsoft Store.

+ Impact : Taking this action will resolve the following 6 different vulnerabilities :
CVE-2023-35374, CVE-2023-32047, CVE-2022-23282, CVE-2021-31983, CVE-2021-31946
CVE-2021-31945


[ Microsoft Print 3D app Remote Code Execution (February 2023) (171636) ]

+ Action to take : Upgrade to the Microsoft 3D Builder app via the Windows App Store.


[ Mozilla Firefox < 146.0.1 (279186) ]

+ Action to take : Upgrade to Mozilla Firefox version 146.0.1 or later.

+ Impact : Taking this action will resolve the following 162 different vulnerabilities :
CVE-2025-9187, CVE-2025-9186, CVE-2025-9185, CVE-2025-9184, CVE-2025-9183
CVE-2025-9182, CVE-2025-9181, CVE-2025-9180, CVE-2025-9179, CVE-2025-8364
CVE-2025-8044, CVE-2025-8043, CVE-2025-8042, CVE-2025-8041, CVE-2025-8040
CVE-2025-8039, CVE-2025-8038, CVE-2025-8037, CVE-2025-8036, CVE-2025-8035
CVE-2025-8034, CVE-2025-8033, CVE-2025-8032, CVE-2025-8031, CVE-2025-8030
CVE-2025-8029, CVE-2025-8028, CVE-2025-8027, CVE-2025-6436, CVE-2025-6435
CVE-2025-6434, CVE-2025-6433, CVE-2025-6432, CVE-2025-6431, CVE-2025-6430
CVE-2025-6429, CVE-2025-6428, CVE-2025-6427, CVE-2025-6426, CVE-2025-6425
CVE-2025-6424, CVE-2025-5283, CVE-2025-5272, CVE-2025-5271, CVE-2025-5270
CVE-2025-5268, CVE-2025-5267, CVE-2025-5266, CVE-2025-5265, CVE-2025-5264
CVE-2025-5263, CVE-2025-49710, CVE-2025-49709, CVE-2025-4919, CVE-2025-4918
CVE-2025-4092, CVE-2025-4091, CVE-2025-4090, CVE-2025-4089, CVE-2025-4088
CVE-2025-4087, CVE-2025-4086, CVE-2025-4085, CVE-2025-4083, CVE-2025-4082
CVE-2025-3608, CVE-2025-3035, CVE-2025-3034, CVE-2025-3033, CVE-2025-3032
CVE-2025-3031, CVE-2025-3030, CVE-2025-3029, CVE-2025-3028, CVE-2025-2857
CVE-2025-2817, CVE-2025-1943, CVE-2025-1942, CVE-2025-1941, CVE-2025-1940
CVE-2025-1939, CVE-2025-1938, CVE-2025-1937, CVE-2025-1936, CVE-2025-1935
CVE-2025-1934, CVE-2025-1933, CVE-2025-1932, CVE-2025-1931, CVE-2025-1930
CVE-2025-14861, CVE-2025-14860, CVE-2025-14333, CVE-2025-14332, CVE-2025-14331
CVE-2025-14330, CVE-2025-14329, CVE-2025-14328, CVE-2025-14327, CVE-2025-14326
CVE-2025-14325, CVE-2025-14324, CVE-2025-14323, CVE-2025-14322, CVE-2025-14321
CVE-2025-1414, CVE-2025-13027, CVE-2025-13026, CVE-2025-13025, CVE-2025-13024
CVE-2025-13023, CVE-2025-13022, CVE-2025-13021, CVE-2025-13020, CVE-2025-13019
CVE-2025-13018, CVE-2025-13017, CVE-2025-13016, CVE-2025-13015, CVE-2025-13014
CVE-2025-13013, CVE-2025-13012, CVE-2025-12380, CVE-2025-11721, CVE-2025-11720
CVE-2025-11719, CVE-2025-11718, CVE-2025-11717, CVE-2025-11716, CVE-2025-11715
CVE-2025-11714, CVE-2025-11713, CVE-2025-11712, CVE-2025-11711, CVE-2025-11710
CVE-2025-11709, CVE-2025-11708, CVE-2025-11153, CVE-2025-11152, CVE-2025-10537
CVE-2025-10536, CVE-2025-10535, CVE-2025-10534, CVE-2025-10533, CVE-2025-10532
CVE-2025-10531, CVE-2025-10530, CVE-2025-10529, CVE-2025-10528, CVE-2025-10527
CVE-2025-1020, CVE-2025-1019, CVE-2025-1018, CVE-2025-1017, CVE-2025-1016
CVE-2025-1014, CVE-2025-1013, CVE-2025-1012, CVE-2025-1011, CVE-2025-1010
CVE-2025-1009, CVE-2024-9956


[ Notepad++ < 8.8.2 Privilege Escalation (CVE-2025-49144) (240630) ]

+ Action to take : Upgrade to Notepad++ 8.8.2 or later.

+ Impact : Taking this action will resolve the following 7 different vulnerabilities :
CVE-2025-49144, CVE-2023-6401, CVE-2023-40166, CVE-2023-40164, CVE-2023-40036
CVE-2023-40031, CVE-2022-32168


[ Oracle Java SE Multiple Vulnerabilities (October 2025 CPU) (271249) ]

+ Action to take : Apply the appropriate patch according to the October 2025 Oracle Critical Patch Update advisory.

+ Impact : Taking this action will resolve the following 305 different vulnerabilities :
CVE-2025-6558, CVE-2025-61748, CVE-2025-53066, CVE-2025-53057, CVE-2025-50106
CVE-2025-50063, CVE-2025-50059, CVE-2025-43265, CVE-2025-43240, CVE-2025-43228
CVE-2025-43227, CVE-2025-43216, CVE-2025-43212, CVE-2025-43211, CVE-2025-32415
CVE-2025-32414, CVE-2025-31278, CVE-2025-31273, CVE-2025-31257, CVE-2025-30761
CVE-2025-30754, CVE-2025-30752, CVE-2025-30749, CVE-2025-30698, CVE-2025-30691
CVE-2025-27113, CVE-2025-24928, CVE-2025-24855, CVE-2025-24189, CVE-2025-24162
CVE-2025-24158, CVE-2025-24150, CVE-2025-24143, CVE-2025-23085, CVE-2025-23084
CVE-2025-23083, CVE-2025-21587, CVE-2025-21502, CVE-2025-0509, CVE-2024-56171
CVE-2024-55549, CVE-2024-54543, CVE-2024-54534, CVE-2024-54508, CVE-2024-54505
CVE-2024-54502, CVE-2024-54479, CVE-2024-47778, CVE-2024-47777, CVE-2024-47776
CVE-2024-47775, CVE-2024-47606, CVE-2024-47597, CVE-2024-47596, CVE-2024-47546
CVE-2024-47545, CVE-2024-47544, CVE-2024-44309, CVE-2024-44308, CVE-2024-44296
CVE-2024-44244, CVE-2024-44187, CVE-2024-44185, CVE-2024-40896, CVE-2024-40866
CVE-2024-36138, CVE-2024-27856, CVE-2024-25062, CVE-2024-22020, CVE-2024-21892
CVE-2024-21235, CVE-2024-21217, CVE-2024-21211, CVE-2024-21210, CVE-2024-21208
CVE-2024-21147, CVE-2024-21145, CVE-2024-21144, CVE-2024-21140, CVE-2024-21138
CVE-2024-21131, CVE-2024-21098, CVE-2024-21094, CVE-2024-21085, CVE-2024-21068
CVE-2024-21012, CVE-2024-21011, CVE-2024-21005, CVE-2024-21004, CVE-2024-21003
CVE-2024-21002, CVE-2024-20954, CVE-2024-20952, CVE-2024-20945, CVE-2024-20932
CVE-2024-20926, CVE-2024-20925, CVE-2024-20923, CVE-2024-20922, CVE-2024-20921
CVE-2024-20919, CVE-2024-20918, CVE-2023-41993, CVE-2023-32643, CVE-2023-25193
CVE-2023-22081, CVE-2023-22067, CVE-2023-22051, CVE-2023-22049, CVE-2023-22045
CVE-2023-22044, CVE-2023-22043, CVE-2023-22041, CVE-2023-22036, CVE-2023-22025
CVE-2023-22006, CVE-2023-21968, CVE-2023-21967, CVE-2023-21954, CVE-2023-21951
CVE-2023-21950, CVE-2023-21949, CVE-2023-21948, CVE-2023-21939, CVE-2023-21938
CVE-2023-21937, CVE-2023-21930, CVE-2023-21843, CVE-2023-21835, CVE-2023-21830
CVE-2022-45688, CVE-2022-39399, CVE-2022-34169, CVE-2022-25647, CVE-2022-21628
CVE-2022-21626, CVE-2022-21624, CVE-2022-21619, CVE-2022-21618, CVE-2022-21549
CVE-2022-21541, CVE-2022-21540, CVE-2022-21496, CVE-2022-21476, CVE-2022-21449
CVE-2022-21443, CVE-2022-21434, CVE-2022-21426, CVE-2022-21366, CVE-2022-21365
CVE-2022-21360, CVE-2022-21349, CVE-2022-21341, CVE-2022-21340, CVE-2022-21305
CVE-2022-21299, CVE-2022-21296, CVE-2022-21294, CVE-2022-21293, CVE-2022-21291
CVE-2022-21283, CVE-2022-21282, CVE-2022-21277, CVE-2022-21271, CVE-2022-21248
CVE-2021-35603, CVE-2021-35588, CVE-2021-35586, CVE-2021-35578, CVE-2021-35567
CVE-2021-35565, CVE-2021-35564, CVE-2021-35561, CVE-2021-35560, CVE-2021-35559
CVE-2021-35556, CVE-2021-35550, CVE-2021-3522, CVE-2021-3517, CVE-2021-2432
CVE-2021-2388, CVE-2021-2369, CVE-2021-2341, CVE-2021-2163, CVE-2021-2161
CVE-2020-2830, CVE-2020-2816, CVE-2020-2805, CVE-2020-2803, CVE-2020-2800
CVE-2020-2781, CVE-2020-2778, CVE-2020-2773, CVE-2020-2767, CVE-2020-2764
CVE-2020-2757, CVE-2020-2756, CVE-2020-2755, CVE-2020-2754, CVE-2020-2659
CVE-2020-2655, CVE-2020-2654, CVE-2020-2604, CVE-2020-2601, CVE-2020-2593
CVE-2020-2590, CVE-2020-2585, CVE-2020-2583, CVE-2020-14803, CVE-2020-14798
CVE-2020-14797, CVE-2020-14796, CVE-2020-14792, CVE-2020-14782, CVE-2020-14781
CVE-2020-14779, CVE-2020-14664, CVE-2020-14621, CVE-2020-14593, CVE-2020-14583
CVE-2020-14581, CVE-2020-14579, CVE-2020-14578, CVE-2020-14577, CVE-2020-14573
CVE-2020-14562, CVE-2020-14556, CVE-2019-7317, CVE-2019-6129, CVE-2019-2999
CVE-2019-2996, CVE-2019-2992, CVE-2019-2989, CVE-2019-2988, CVE-2019-2987
CVE-2019-2983, CVE-2019-2981, CVE-2019-2978, CVE-2019-2977, CVE-2019-2975
CVE-2019-2973, CVE-2019-2964, CVE-2019-2962, CVE-2019-2958, CVE-2019-2949
CVE-2019-2945, CVE-2019-2933, CVE-2019-2894, CVE-2019-2842, CVE-2019-2821
CVE-2019-2818, CVE-2019-2816, CVE-2019-2786, CVE-2019-2769, CVE-2019-2766
CVE-2019-2762, CVE-2019-2745, CVE-2019-2699, CVE-2019-2698, CVE-2019-2697
CVE-2019-2684, CVE-2019-2602, CVE-2019-2449, CVE-2019-2426, CVE-2019-2422
CVE-2019-18197, CVE-2019-16168, CVE-2019-13118, CVE-2019-13117, CVE-2019-11068
CVE-2018-3214, CVE-2018-3211, CVE-2018-3209, CVE-2018-3183, CVE-2018-3180
CVE-2018-3169, CVE-2018-3157, CVE-2018-3150, CVE-2018-3149, CVE-2018-3139
CVE-2018-3136, CVE-2018-2973, CVE-2018-2972, CVE-2018-2964, CVE-2018-2952
CVE-2018-2942, CVE-2018-2941, CVE-2018-2940, CVE-2018-2938, CVE-2018-2826
CVE-2018-2825, CVE-2018-2815, CVE-2018-2814, CVE-2018-2811, CVE-2018-2800
CVE-2018-2799, CVE-2018-2798, CVE-2018-2797, CVE-2018-2796, CVE-2018-2795
CVE-2018-2794, CVE-2018-2790, CVE-2018-2783, CVE-2018-13785, CVE-2018-11212



[ RARLAB WinRAR < 7.13 Directory Traversal (CVE-2025-8088) (248462) ]

+ Action to take : Upgrade to RARLAB WinRAR version 7.13 or later.

+ Impact : Taking this action will resolve the following 7 different vulnerabilities :
CVE-2025-8088, CVE-2025-6218, CVE-2025-31334, CVE-2024-36052, CVE-2024-30370
CVE-2023-40477, CVE-2023-38831


[ Security Updates for Microsoft Excel Products (December 2025) (277999) ]

+ Action to take : Microsoft has released KB5002820 to address this issue.

+ Impact : Taking this action will resolve the following 42 different vulnerabilities :
CVE-2025-62564, CVE-2025-62563, CVE-2025-62561, CVE-2025-62560, CVE-2025-62556
CVE-2025-62553, CVE-2025-62203, CVE-2025-62202, CVE-2025-62201, CVE-2025-62200
CVE-2025-60727, CVE-2025-60726, CVE-2025-59240, CVE-2025-59235, CVE-2025-59233
CVE-2025-59232, CVE-2025-59231, CVE-2025-59225, CVE-2025-59224, CVE-2025-59223
CVE-2025-54904, CVE-2025-54903, CVE-2025-54902, CVE-2025-54900, CVE-2025-54899
CVE-2025-54898, CVE-2025-54896, CVE-2025-53741, CVE-2025-53739, CVE-2025-53737
CVE-2025-53735, CVE-2025-49711, CVE-2025-49697, CVE-2025-48812, CVE-2025-47165
CVE-2025-30383, CVE-2025-30381, CVE-2025-30379, CVE-2025-30376, CVE-2025-30375
CVE-2025-29979, CVE-2025-29977


[ Security Updates for Microsoft Office Products (December 2025) (277985) ]

+ Action to take : Microsoft has released the following updates to address these issues:
- KB5002812
- KB5002818
- KB5002819

+ Impact : Taking this action will resolve the following 38 different vulnerabilities :
CVE-2025-62563, CVE-2025-62561, CVE-2025-62557, CVE-2025-62554, CVE-2025-62553
CVE-2025-62552, CVE-2025-62202, CVE-2025-62199, CVE-2025-60727, CVE-2025-60726
CVE-2025-59235, CVE-2025-59234, CVE-2025-59232, CVE-2025-59227, CVE-2025-59226
CVE-2025-54910, CVE-2025-54906, CVE-2025-54901, CVE-2025-53740, CVE-2025-53731
CVE-2025-49702, CVE-2025-49700, CVE-2025-49699, CVE-2025-49698, CVE-2025-49697
CVE-2025-49696, CVE-2025-49695, CVE-2025-48812, CVE-2025-47994, CVE-2025-47953
CVE-2025-47173, CVE-2025-47167, CVE-2025-47164, CVE-2025-47162, CVE-2025-32704
CVE-2025-30386, CVE-2025-30379, CVE-2025-30377


[ Security Updates for Microsoft PowerPoint Products (October 2025) (270692) ]

+ Action to take : Microsoft has released KB5002790 to address this issue.

+ Impact : Taking this action will resolve the following 5 different vulnerabilities :
CVE-2025-59238, CVE-2025-54908, CVE-2025-53761, CVE-2025-49705, CVE-2025-47175



[ Security Updates for Microsoft Word Products (December 2025) (277989) ]

+ Action to take : Microsoft has released KB5002806 to address this issue.

+ Impact : Taking this action will resolve the following 13 different vulnerabilities :
CVE-2025-62562, CVE-2025-62559, CVE-2025-62558, CVE-2025-62555, CVE-2025-59222
CVE-2025-59221, CVE-2025-54905, CVE-2025-53738, CVE-2025-53736, CVE-2025-53733
CVE-2025-49703, CVE-2025-47169, CVE-2025-47168


[ Security Updates for Outlook (July 2025) (241560) ]

+ Action to take : Microsoft has released KB5002747 to address this issue.

+ Impact : Taking this action will resolve the following 2 different vulnerabilities :
CVE-2025-49699, CVE-2025-47171


[ VMware Tools 11.x < 12.5.4 / 13.x < 13.0.5 Multiple Vulnerabilities (VMSA-2025-0015) (266420) ]

+ Action to take : Upgrade to VMware Tools version 12.5.4, 13.0.5 or later.

+ Impact : Taking this action will resolve the following 5 different vulnerabilities :
CVE-2025-41246, CVE-2025-41244, CVE-2025-41239, CVE-2025-22247, CVE-2025-22230


122422 - RARLAB WinRAR Installed (Windows)
-
Synopsis
An archive manager is installed on the remote Windows host.
Description
RARLAB WinRaR, an archive manager, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0706
Plugin Information
Published: 2019/02/26, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Path : C:\Program Files\WinRAR\WinRAR.exe
Version : 5.90.0.0

92428 - Recent File History
-
Synopsis
Nessus was able to enumerate recently opened files on the remote host.
Description
Nessus was able to gather evidence of files opened by file type from the remote host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

C:\\Users\tidua\AppData\Roaming\Microsoft\Windows\Recent\desktop.ini

Recent files found in registry and appdata attached.
92429 - Recycle Bin Files
-
Synopsis
Nessus was able to enumerate files in the recycle bin on the remote host.
Description
Nessus was able to generate a list of all files found in $Recycle.Bin subdirectories.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

C:\\$Recycle.Bin\\.
C:\\$Recycle.Bin\\..
C:\\$Recycle.Bin\\S-1-5-18
C:\\$Recycle.Bin\\S-1-5-21-2193062927-1383316644-2198579232-1000
C:\\$Recycle.Bin\\S-1-5-21-2193062927-1383316644-2198579232-1001
C:\\$Recycle.Bin\\S-1-5-21-2193062927-1383316644-2198579232-1004
C:\\$Recycle.Bin\\S-1-5-21-2193062927-1383316644-2198579232-1005
C:\\$Recycle.Bin\\S-1-5-21-2193062927-1383316644-2198579232-1009
C:\\$Recycle.Bin\\S-1-5-21-2193062927-1383316644-2198579232-500
C:\\$Recycle.Bin\\S-1-5-18\.
C:\\$Recycle.Bin\\S-1-5-18\..
C:\\$Recycle.Bin\\S-1-5-18\desktop.ini
C:\\$Recycle.Bin\\S-1-5-21-2193062927-1383316644-2198579232-1000\.
C:\\$Recycle.Bin\\S-1-5-21-2193062927-1383316644-2198579232-1000\..
C:\\$Recycle.Bin\\S-1-5-21-2193062927-1383316644-2198579232-1000\desktop.ini
C:\\$Recycle.Bin\\S-1-5-21-2193062927-1383316644-2198579232-1001\.
C:\\$Recycle.Bin\\S-1-5-21-2193062927-1383316644-2198579232-1001\..
C:\\$Recycle.Bin\\S-1-5-21-2193062927-1383316644-2198579232-1001\desktop.ini
C:\\$Recycle.Bin\\S-1-5-21-2193062927-1383316644-2198579232-1004\.
C:\\$Recycle.Bin\\S-1-5-21-2193062927-1383316644-2198579232-1004\..
C:\\$Recycle.Bin\\S-1-5-21-2193062927-1383316644-2198579232-1004\desktop.ini
C:\\$Recycle.Bin\\S-1-5-21-2193062927-1383316644-2198579232-1005\.
C:\\$Recycle.Bin\\S-1-5-21-2193062927-1383316644-2198579232-1005\..
C:\\$Recycle.Bin\\S-1-5-21-2193062927-1383316644-2198579232-1005\desktop.ini
C:\\$Recycle.Bin\\S-1-5-21-2193062927-1383316644-2198579232-1009\.
C:\\$Recycle.Bin\\S-1-5-21-2193062927-1383316644-2198579232-1009\..
C:\\$Recycle.Bin\\S-1-5-21-2193062927-1383316644-2198579232-1009\desktop.ini
C:\\$Recycle.Bin\\S-1-5-21-2193062927-1383316644-2198579232-500\.
C:\\$Recycle.Bin\\S-1-5-21-2193062927-1383316644-2198579232-500\..
C:\\$Recycle.Bin\\S-1-5-21-2193062927-1383316644-2198579232-500\desktop.ini
92430 - Registry Editor Last Accessed
-
Synopsis
Nessus was able to find the last key accessed by the Registry Editor when it was closed on the remote host.
Description
Nessus was able to find evidence of the last key that was opened when the Registry Editor was closed for each user.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

Techrobot
- Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters

10940 - Remote Desktop Protocol Service Detection
-
Synopsis
The remote host has an remote desktop protocol service enabled.
Description
The Remote Desktop Protocol allows a user to remotely obtain a graphical login (and therefore act as a local user on the remote host).

If an attacker gains a valid login and password, this service could be used to gain further access on the remote host. An attacker may also use this service to mount a dictionary attack against the remote host to try to log in remotely.

Note that RDP (the Remote Desktop Protocol) is vulnerable to Man-in-the-middle attacks, making it easy for attackers to steal the credentials of legitimate users by impersonating the Windows server.
Solution
Disable the service if you do not use it, and do not allow this service to run across the Internet.
Risk Factor
None
Plugin Information
Published: 2002/04/20, Modified: 2023/08/21
Plugin Output

tcp/3389/msrdp

277650 - Remote Services Not Using Post-Quantum Ciphers
-
Synopsis
Reports remote services that do not offer post-quantum ciphers.
Description
This plugin reports network services that do not offer post-quantum ciphers. Tenable makes no attempt to determine whether the remote service would be vulnerable to a post-quantum attack.

However, cryptography that depends on the classic difficulty of solving the discrete logarithm problem or on the classic difficulty of large prime factorization is broken by Shor's algorithm. Examples of this are RSA asymmetric encryption and Diffie-Hellman key exchange.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/08, Modified: 2025/12/08
Plugin Output

tcp/3389/msrdp

The target TLS server offers no post-quantum ciphers.

62042 - SMB QuickFixEngineering (QFE) Enumeration
-
Synopsis
The remote host has quick-fix engineering updates installed.
Description
By connecting to the host with the supplied credentials, this plugin enumerates quick-fix engineering updates installed on the remote host via the registry.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2012/09/11, Modified: 2022/02/01
Plugin Output

tcp/0


Here is a list of quick-fix engineering updates installed on the
remote system :

KB4562830, Installed on: 2022/04/14
KB5007401, Installed on: 2022/04/14
KB5011048, Installed on: 2023/10/31
KB5011651, Installed on: 2022/04/14
KB5015684, Installed on: 2023/09/22
KB5030841, Installed on: 2023/10/31
KB5033052, Installed on: 2025/03/10
KB5056578, Installed on: 2025/05/03
42897 - SMB Registry : Start the Registry Service during the scan (WMI)
-
Synopsis
The registry service was enabled for the duration of the scan.
Description
To perform a full credentialed scan, Nessus needs the ability to connect to the remote registry service (RemoteRegistry). If the service is down, this plugin will attempt to start for the duration of the scan.

For this plugin to work, you need to select the option 'Start the Remote Registry service during the scan' on the credentials page when you add your Windows credentials.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/11/25, Modified: 2025/12/15
Plugin Output

tcp/0


The registry service was successfully started for the duration of the scan.

56984 - SSL / TLS Versions Supported
-
Synopsis
The remote service encrypts communications.
Description
This plugin detects which SSL and TLS versions are supported by the remote service for encrypting communications.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/01, Modified: 2025/06/16
Plugin Output

tcp/3389/msrdp


This port supports TLSv1.0/TLSv1.1/TLSv1.2.
10863 - SSL Certificate Information
-
Synopsis
This plugin displays the SSL certificate.
Description
This plugin connects to every SSL-related port and attempts to extract and dump the X.509 certificate.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/05/19, Modified: 2021/02/03
Plugin Output

tcp/3389/msrdp

Subject Name:

Common Name: LiveTechRobo

Issuer Name:

Common Name: LiveTechRobo

Serial Number: 64 CD 80 A0 39 3B FB 91 41 E7 DF 57 32 C5 39 BE

Version: 3

Signature Algorithm: SHA-256 With RSA Encryption

Not Valid Before: Jan 02 12:37:11 2026 GMT
Not Valid After: Jul 04 12:37:11 2026 GMT

Public Key Info:

Algorithm: RSA Encryption
Key Length: 2048 bits
Public Key: 00 BD 53 C9 F8 D5 A5 A6 CE 80 D9 3B 19 F1 A4 CD 3B 2E 28 FC
80 EB 55 99 24 75 09 97 A4 CF 01 F5 3C C5 B7 8E 09 42 4E 17
F4 45 8D 13 FE 32 19 C5 5D 1B 04 28 C1 6A 39 FF 10 57 3E BA
D9 23 05 CA C8 03 58 73 21 ED BD 30 01 4E BF 71 AC BE FC 45
4F 1C 89 DC 42 86 C0 98 30 81 C6 3F 87 DB 74 1A F7 C4 A9 AE
9E A3 76 D4 E9 EE 1A B5 49 A8 16 62 DF 97 16 B4 55 28 7D C1
B1 C9 1B E3 E6 E7 E5 6C 2F 1D 70 05 D3 2F 64 5F 7B 08 6F 46
2C CA D7 21 EC 14 40 7E 9C 59 81 83 4A 29 9F 57 71 3A EF 72
C1 23 D0 CE F9 04 87 AC 88 22 F7 7F 73 57 43 E9 37 04 01 85
E6 FF 24 25 28 B0 FA 4A F9 5A B9 34 0F 25 82 20 AE 83 9B A4
73 34 3C 1B BB 3B 56 AE 85 6B E9 10 C5 74 7F DA CF 65 50 77
C8 B3 56 DE 5F 91 EE D6 4B E1 4B 81 9C 02 BE 4E 9C 15 67 9D
47 B9 DE 13 B2 65 D5 FA 93 C7 3C 5C EF 0A 48 86 B9
Exponent: 01 00 01

Signature Length: 256 bytes / 2048 bits
Signature: 00 88 30 42 10 07 93 F3 9C 9F 7B 36 E7 B7 48 4A 20 10 9B A5
A2 95 26 EA AE 07 D8 CB 58 05 25 FB E7 DA D5 5E 6C 41 90 FC
0A 77 C9 32 BB 0F C0 5B D1 40 EA AA 33 80 FE 27 26 E3 8B BB
81 6E F5 95 99 73 DA D7 EA 36 EC D0 F6 F5 18 AA 50 26 B0 02
B5 90 59 07 50 0B D4 92 A2 F7 DF BA 55 E2 96 B9 BC DE B5 67
70 60 DC 89 C5 C2 9A AC DD 07 D0 CF 55 88 14 F0 6E D2 E3 31
86 7F DC F8 07 5A C6 6E 14 C5 1B AE 7B 20 B5 47 4F 10 6E 30
40 B8 03 1B 6E 8A 17 A7 7F 0A 6F 41 38 1B FB 9A E1 03 32 CC
A2 7E 99 11 0B E6 2D CC EC 3E 9F EC 94 57 43 F5 EB 69 C9 AF
91 66 45 27 D8 10 2D 48 83 7E 0B 3B FB D0 32 C2 63 AB 6A BD
E2 FC C8 70 F4 9C 46 C5 7B EC FD 0F 23 E9 CB 3C 22 FC AD F4
61 34 A7 34 AB E1 E3 7E 0A 59 EF BC 89 35 E7 99 B5 70 A1 E8
FF F6 42 86 18 D2 29 58 36 19 7E 30 E2 D2 37 24 1D

Extension: Extended Key Usage(2.5.29.37)
Critical: 0
Purpose#1: Web Server Authentication (1.3.6.1.5.5.7.3.1)


Extension: Key Usage(2.5.29.15)
Critical: 0
Key Usage: Key Encipherment, Data Encipherment


Fingerprints :

SHA-256 Fingerprint: EA 82 2F 63 F7 7F 05 82 A7 12 34 D4 F9 D8 67 67 8D 45 58 C7
79 08 7E 6B 51 BA 59 FF 08 44 8D 9E
SHA-1 Fingerprint: 15 4C 58 F6 84 3E 42 0E 9F 26 8C 42 CD 93 3C 84 4E C8 9A E6
MD5 Fingerprint: 33 BA 97 91 8D 6E D7 6C 28 FB 0C 73 E3 15 AB 09


PEM certificate :

-----BEGIN CERTIFICATE-----
MIIC3DCCAcSgAwIBAgIQZM2AoDk7+5FB599XMsU5vjANBgkqhkiG9w0BAQsFADAXMRUwEwYDVQQDEwxMaXZlVGVjaFJvYm8wHhcNMjYwMTAyMTIzNzExWhcNMjYwNzA0MTIzNzExWjAXMRUwEwYDVQQDEwxMaXZlVGVjaFJvYm8wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC9U8n41aWmzoDZOxnxpM07Lij8gOtVmSR1CZekzwH1PMW3jglCThf0RY0T/jIZxV0bBCjBajn/EFc+utkjBcrIA1hzIe29MAFOv3GsvvxFTxyJ3EKGwJgwgcY/h9t0GvfEqa6eo3bU6e4atUmoFmLflxa0VSh9wbHJG+Pm5+VsLx1wBdMvZF97CG9GLMrXIewUQH6cWYGDSimfV3E673LBI9DO+QSHrIgi939zV0PpNwQBheb/JCUosPpK+Vq5NA8lgiCug5ukczQ8G7s7Vq6Fa+kQxXR/2s9lUHfIs1beX5Hu1kvhS4GcAr5OnBVnnUe53hOyZdX6k8c8XO8KSIa5AgMBAAGjJDAiMBMGA1UdJQQMMAoGCCsGAQUFBwMBMAsGA1UdDwQEAwIEMDANBgkqhkiG9w0BAQsFAAOCAQEAiDBCEAeT85yfezbnt0hKIBCbpaKVJuquB9jLWAUl++fa1V5sQZD8CnfJMrsPwFvRQOqqM4D+Jybji7uBbvWVmXPa1+o27ND29RiqUCawArWQWQdQC9SSovffulXilrm83rVncGDcicXCmqzdB9DPVYgU8G7S4zGGf9z4B1rGbhTFG657ILVHTxBuMEC4AxtuihenfwpvQTgb+5rhAzLMon6ZEQvmLczsPp/slFdD9etpya+RZkUn2BAtSIN+Czv70DLCY6tqveL8yHD0nEbFe+z9DyPpyzwi/K30YTSnNKvh434KWe+8iTXnmbVwoej/9kKGGNIpWDYZfjDi0jckHQ==
-----END CERTIFICATE-----
70544 - SSL Cipher Block Chaining Cipher Suites Supported
-
Synopsis
The remote service supports the use of SSL Cipher Block Chaining ciphers, which combine previous blocks with subsequent ones.
Description
The remote host supports the use of SSL ciphers that operate in Cipher Block Chaining (CBC) mode. These cipher suites offer additional security over Electronic Codebook (ECB) mode, but have the potential to leak information if used improperly.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/22, Modified: 2021/02/03
Plugin Output

tcp/3389/msrdp


Here is the list of SSL CBC ciphers supported by the remote server :

Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}
21643 - SSL Cipher Suites Supported
-
Synopsis
The remote service encrypts communications using SSL.
Description
This plugin detects which SSL ciphers are supported by the remote service for encrypting communications.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2006/06/05, Modified: 2024/09/11
Plugin Output

tcp/3389/msrdp


Here is the list of SSL ciphers supported by the remote server :
Each group is reported per SSL Version.

SSL Version : TLSv12
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA256 0x00, 0x9E DHE RSA AES-GCM(128) SHA256
DHE-RSA-AES256-SHA384 0x00, 0x9F DHE RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA256 0xC0, 0x2F ECDHE RSA AES-GCM(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x30 ECDHE RSA AES-GCM(256) SHA384
RSA-AES128-SHA256 0x00, 0x9C RSA RSA AES-GCM(128) SHA256
RSA-AES256-SHA384 0x00, 0x9D RSA RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256


SSL Version : TLSv11
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1


SSL Version : TLSv1
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

Note that this service does not encrypt traffic by default but does
support upgrading to an encrypted connection using STARTTLS.
57041 - SSL Perfect Forward Secrecy Cipher Suites Supported
-
Synopsis
The remote service supports the use of SSL Perfect Forward Secrecy ciphers, which maintain confidentiality even if the key is stolen.
Description
The remote host supports the use of SSL ciphers that offer Perfect Forward Secrecy (PFS) encryption. These cipher suites ensure that recorded SSL traffic cannot be broken at a future date if the server's private key is compromised.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/07, Modified: 2021/03/09
Plugin Output

tcp/3389/msrdp


Here is the list of SSL PFS ciphers supported by the remote server :

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA256 0x00, 0x9E DHE RSA AES-GCM(128) SHA256
DHE-RSA-AES256-SHA384 0x00, 0x9F DHE RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA256 0xC0, 0x2F ECDHE RSA AES-GCM(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x30 ECDHE RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}
156899 - SSL/TLS Recommended Cipher Suites
-
Synopsis
The remote host advertises discouraged SSL/TLS ciphers.
Description
The remote host has open SSL/TLS ports which advertise discouraged cipher suites. It is recommended to only enable support for the following cipher suites:

TLSv1.3:
- 0x13,0x01 TLS13_AES_128_GCM_SHA256
- 0x13,0x02 TLS13_AES_256_GCM_SHA384
- 0x13,0x03 TLS13_CHACHA20_POLY1305_SHA256

TLSv1.2:
- 0xC0,0x2B ECDHE-ECDSA-AES128-GCM-SHA256
- 0xC0,0x2F ECDHE-RSA-AES128-GCM-SHA256
- 0xC0,0x2C ECDHE-ECDSA-AES256-GCM-SHA384
- 0xC0,0x30 ECDHE-RSA-AES256-GCM-SHA384
- 0xCC,0xA9 ECDHE-ECDSA-CHACHA20-POLY1305
- 0xCC,0xA8 ECDHE-RSA-CHACHA20-POLY1305

This is the recommended configuration for the vast majority of services, as it is highly secure and compatible with nearly every client released in the last five (or more) years.
See Also
Solution
Only enable support for recommened cipher suites.
Risk Factor
None
Plugin Information
Published: 2022/01/20, Modified: 2024/02/12
Plugin Output

tcp/3389/msrdp

The remote host has listening SSL/TLS ports which advertise the discouraged cipher suites outlined below:


Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA256 0x00, 0x9E DHE RSA AES-GCM(128) SHA256
DHE-RSA-AES256-SHA384 0x00, 0x9F DHE RSA AES-GCM(256) SHA384
RSA-AES128-SHA256 0x00, 0x9C RSA RSA AES-GCM(128) SHA256
RSA-AES256-SHA384 0x00, 0x9D RSA RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

160486 - Server Message Block (SMB) Protocol Version Detection
-
Synopsis
Verify the version of SMB on the remote host.
Description
The Server Message Block (SMB) Protocol provides shared access to files and printers across nodes on a network.
See Also
Solution
Disable SMB version 1 and block all versions of SMB at the network boundary by blocking TCP port 445 with related protocols on UDP ports 137-138 and TCP port 139, for all boundary devices.
Risk Factor
None
Plugin Information
Published: 2022/05/04, Modified: 2022/05/04
Plugin Output

tcp/445/cifs

- SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\SMB2 : Key not found.
- SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\SMB3 : Key not found.
- SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\SMB1 : Key not found.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/2323/www

A web server is running on this port.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/5357/www

A web server is running on this port.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/5800/www

A web server is running on this port.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/5900/vnc

A vnc server is running on this port.

278501 - Smartbedded Meteobridge Web Detection
-
Synopsis
The web UI for Smartbedded Meteobridge was detected on the remote host.
Description
Smartbedded Meteobridge, a dedicated weather monitoring application, is running on the remote host.

Note: Basic HTTP Authentication credentials are required to obtain the version.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/12, Modified: 2025/12/15
Plugin Output

tcp/2323/www


URL : http://172.17.100.35:2323/cgi-bin/meteobridge
Version : unknown
Authenticated : False

278501 - Smartbedded Meteobridge Web Detection
-
Synopsis
The web UI for Smartbedded Meteobridge was detected on the remote host.
Description
Smartbedded Meteobridge, a dedicated weather monitoring application, is running on the remote host.

Note: Basic HTTP Authentication credentials are required to obtain the version.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/12, Modified: 2025/12/15
Plugin Output

tcp/5800/www


URL : http://172.17.100.35:5800/cgi-bin/meteobridge
Version : unknown
Authenticated : False

161455 - Supersedence Data Builder
-
Synopsis
Supersedence data.
Description
Collects and stores supersedence patch data for various patch types.
Solution
N/A
Risk Factor
None
Plugin Information
Published: 2022/05/24, Modified: 2025/07/14
Plugin Output

tcp/0

Supersedence patch data summary :
- MSKB : 27


Plugin debug log has been attached.

121010 - TLS Version 1.1 Protocol Detection
-
Synopsis
The remote service encrypts traffic using an older version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.1.
TLS 1.1 lacks support for current and recommended cipher suites.
Ciphers that support encryption before MAC computation, and authenticated encryption modes such as GCM cannot be used with TLS 1.1

As of March 31, 2020, Endpoints that are not enabled for TLS 1.2 and higher will no longer function properly with major web browsers and major vendors.
See Also
Solution
Enable support for TLS 1.2 and/or 1.3, and disable support for TLS 1.1.
Risk Factor
None
References
XREF CWE:327
Plugin Information
Published: 2019/01/08, Modified: 2023/04/19
Plugin Output

tcp/3389/msrdp

TLSv1.1 is enabled and the server supports at least one cipher.
136318 - TLS Version 1.2 Protocol Detection
-
Synopsis
The remote service encrypts traffic using a version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.2.
See Also
Solution
N/A
Risk Factor
None
Plugin Information
Published: 2020/05/04, Modified: 2020/05/04
Plugin Output

tcp/3389/msrdp

TLSv1.2 is enabled and the server supports at least one cipher.

117885 - Target Credential Issues by Authentication Protocol - Intermittent Authentication Failure
-
Synopsis
Nessus was able to log in to the remote host using the provided credentials, but there were intermittent authentication failures.
Description
Nessus was able to successfully authenticate to the remote host on an authentication protocol at least once using credentials provided in the scan policy.

However, one or more plugins failed to authenticate to the remote host on the same port and protocol using the same credential set that was previously successful. This may indicate an intermittent authentication problem with the remote host, which could be caused by session rate limits, session concurrency limits, or other issues preventing consistent authentication success.

These intermittent authentication failures may have affected the results of some plugins. See plugin output for failure details.
Solution
n/a
Risk Factor
None
References
XREF IAVB:0001-B-0509
Plugin Information
Published: 2018/10/02, Modified: 2024/03/25
Plugin Output

tcp/445/cifs


Nessus was able to successfully log into the remote host as :

User: '172.17.100.35\tidua'
Port: 445
Proto: SMB
Method: password


Successful authentication was reported by the following plugin :

Plugin : smb_login.nasl
Plugin ID : 10394
Plugin Name : Microsoft Windows SMB Log In Possible

However, one or more subsequent plugins failed to authenticate to the
remote host on the same port and protocol using the same credential
set that previously succeeded. This may indicate an intermittent
authentication problem with the remote host which may have affected
the results of the following plugins.

Error message statistics :

1 Failed to open a socket on port 445. This failure may have prevented
a login attempt. The failure references the previously successful
login account for tracking purposes.


Failure Details :

- Plugin : mswsp_overflow.nasl
Plugin ID : 102683
Plugin Name : Microsoft Windows Search Remote Code Execution Vulnerability (CVE-2017-8543)
Message :
Failed to open a socket on port 445. This failure may have prevented
a login attempt. The failure references the previously successful
login account for tracking purposes.
141118 - Target Credential Status by Authentication Protocol - Valid Credentials Provided
-
Synopsis
Valid credentials were provided for an available authentication protocol.
Description
Nessus was able to determine that valid credentials were provided for an authentication protocol available on the remote target because it was able to successfully authenticate directly to the remote target using that authentication protocol at least once. Authentication was successful because the authentication protocol service was available remotely, the service was able to be identified, the authentication protocol was able to be negotiated successfully, and a set of credentials provided in the scan policy for that authentication protocol was accepted by the remote service. See plugin output for details, including protocol, port, and account.

Please note the following :

- This plugin reports per protocol, so it is possible for valid credentials to be provided for one protocol and not another. For example, authentication may succeed via SSH but fail via SMB, while no credentials were provided for an available SNMP service.

- Providing valid credentials for all available authentication protocols may improve scan coverage, but the value of successful authentication for a given protocol may vary from target to target depending upon what data (if any) is gathered from the target via that protocol. For example, successful authentication via SSH is more valuable for Linux targets than for Windows targets, and likewise successful authentication via SMB is more valuable for Windows targets than for Linux targets.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2020/10/15, Modified: 2024/03/25
Plugin Output

tcp/445/cifs


Nessus was able to log in to the remote host via the following :

User: '172.17.100.35\tidua'
Port: 445
Proto: SMB
Method: password

64814 - Terminal Services Use SSL/TLS
-
Synopsis
The remote Terminal Services use SSL/TLS.
Description
The remote Terminal Services is configured to use SSL/TLS.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/02/22, Modified: 2023/07/10
Plugin Output

tcp/3389/msrdp

Subject Name:

Common Name: LiveTechRobo

Issuer Name:

Common Name: LiveTechRobo

Serial Number: 64 CD 80 A0 39 3B FB 91 41 E7 DF 57 32 C5 39 BE

Version: 3

Signature Algorithm: SHA-256 With RSA Encryption

Not Valid Before: Jan 02 12:37:11 2026 GMT
Not Valid After: Jul 04 12:37:11 2026 GMT

Public Key Info:

Algorithm: RSA Encryption
Key Length: 2048 bits
Public Key: 00 BD 53 C9 F8 D5 A5 A6 CE 80 D9 3B 19 F1 A4 CD 3B 2E 28 FC
80 EB 55 99 24 75 09 97 A4 CF 01 F5 3C C5 B7 8E 09 42 4E 17
F4 45 8D 13 FE 32 19 C5 5D 1B 04 28 C1 6A 39 FF 10 57 3E BA
D9 23 05 CA C8 03 58 73 21 ED BD 30 01 4E BF 71 AC BE FC 45
4F 1C 89 DC 42 86 C0 98 30 81 C6 3F 87 DB 74 1A F7 C4 A9 AE
9E A3 76 D4 E9 EE 1A B5 49 A8 16 62 DF 97 16 B4 55 28 7D C1
B1 C9 1B E3 E6 E7 E5 6C 2F 1D 70 05 D3 2F 64 5F 7B 08 6F 46
2C CA D7 21 EC 14 40 7E 9C 59 81 83 4A 29 9F 57 71 3A EF 72
C1 23 D0 CE F9 04 87 AC 88 22 F7 7F 73 57 43 E9 37 04 01 85
E6 FF 24 25 28 B0 FA 4A F9 5A B9 34 0F 25 82 20 AE 83 9B A4
73 34 3C 1B BB 3B 56 AE 85 6B E9 10 C5 74 7F DA CF 65 50 77
C8 B3 56 DE 5F 91 EE D6 4B E1 4B 81 9C 02 BE 4E 9C 15 67 9D
47 B9 DE 13 B2 65 D5 FA 93 C7 3C 5C EF 0A 48 86 B9
Exponent: 01 00 01

Signature Length: 256 bytes / 2048 bits
Signature: 00 88 30 42 10 07 93 F3 9C 9F 7B 36 E7 B7 48 4A 20 10 9B A5
A2 95 26 EA AE 07 D8 CB 58 05 25 FB E7 DA D5 5E 6C 41 90 FC
0A 77 C9 32 BB 0F C0 5B D1 40 EA AA 33 80 FE 27 26 E3 8B BB
81 6E F5 95 99 73 DA D7 EA 36 EC D0 F6 F5 18 AA 50 26 B0 02
B5 90 59 07 50 0B D4 92 A2 F7 DF BA 55 E2 96 B9 BC DE B5 67
70 60 DC 89 C5 C2 9A AC DD 07 D0 CF 55 88 14 F0 6E D2 E3 31
86 7F DC F8 07 5A C6 6E 14 C5 1B AE 7B 20 B5 47 4F 10 6E 30
40 B8 03 1B 6E 8A 17 A7 7F 0A 6F 41 38 1B FB 9A E1 03 32 CC
A2 7E 99 11 0B E6 2D CC EC 3E 9F EC 94 57 43 F5 EB 69 C9 AF
91 66 45 27 D8 10 2D 48 83 7E 0B 3B FB D0 32 C2 63 AB 6A BD
E2 FC C8 70 F4 9C 46 C5 7B EC FD 0F 23 E9 CB 3C 22 FC AD F4
61 34 A7 34 AB E1 E3 7E 0A 59 EF BC 89 35 E7 99 B5 70 A1 E8
FF F6 42 86 18 D2 29 58 36 19 7E 30 E2 D2 37 24 1D

Extension: Extended Key Usage(2.5.29.37)
Critical: 0
Purpose#1: Web Server Authentication (1.3.6.1.5.5.7.3.1)


Extension: Key Usage(2.5.29.15)
Critical: 0
Key Usage: Key Encipherment, Data Encipherment

161691 - The Microsoft Windows Support Diagnostic Tool (MSDT) RCE Workaround Detection (CVE-2022-30190)
-
Synopsis
Checks for the HKEY_CLASSES_ROOT\ms-msdt registry key.
Description
The remote host has the HKEY_CLASSES_ROOT\ms-msdt registry key. This is a known exposure for CVE-2022-30190.

Note that Nessus has not tested for CVE-2022-30190. It is only checking if the registry key exists. The recommendation is to apply the latest patch.
See Also
Solution
Apply the latest Cumulative Update.
Risk Factor
None
Plugin Information
Published: 2022/05/31, Modified: 2022/07/28
Plugin Output

tcp/445/cifs

The HKEY_CLASSES_ROOT\ms-msdt registry key exists on the target. This may indicate that the target is vulnerable to CVE-2022-30190, if the vendor patch is not applied.

56468 - Time of Last System Startup
-
Synopsis
The system has been started.
Description
Using the supplied credentials, Nessus was able to determine when the host was last started.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/10/12, Modified: 2018/06/19
Plugin Output

tcp/0


20260103180707.500000+330

10287 - Traceroute Information
-
Synopsis
It was possible to obtain traceroute information.
Description
Makes a traceroute to the remote host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 1999/11/27, Modified: 2023/12/04
Plugin Output

udp/0

For your information, here is the traceroute from 172.17.100.38 to 172.17.100.35 :
172.17.100.38
172.17.100.35

Hop Count: 1

92434 - User Download Folder Files
-
Synopsis
Nessus was able to enumerate downloaded files on the remote host.
Description
Nessus was able to generate a report of all files listed in the default user download folder.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/16
Plugin Output

tcp/0

C:\\Users\Administrator\Downloads\ChromeSetup.exe
C:\\Users\Administrator\Downloads\desktop.ini
C:\\Users\LKPAdmin\Downloads\desktop.ini
C:\\Users\Public\Downloads\desktop.ini
C:\\Users\Techexcel\Downloads\desktop.ini
C:\\Users\Techrobot\Downloads\160e843f-8d3c-4889-ba50-055616c16b99.tmp
C:\\Users\Techrobot\Downloads\1b6fa449-4605-4587-856e-79b6857a1072.tmp
C:\\Users\Techrobot\Downloads\1fc5b7b3-d80f-4d6a-afdd-37297f8b49f0.tmp
C:\\Users\Techrobot\Downloads\437be60d-d6a6-4568-97f1-b2d00a2a12c4.tmp
C:\\Users\Techrobot\Downloads\451152f8-c257-4799-add4-34086308c530.tmp
C:\\Users\Techrobot\Downloads\4IR-KKkx.pdf.part
C:\\Users\Techrobot\Downloads\62d8c49e-e6e1-436b-9e98-9286e614de62.tmp
C:\\Users\Techrobot\Downloads\7979f7c4-4b86-4106-bb7b-f178160e1b99.tmp
C:\\Users\Techrobot\Downloads\be732b95-68d3-4d72-ba19-1895d0ccc108.tmp
C:\\Users\Techrobot\Downloads\c78f2841-befe-4961-b260-c48ad159c4ad.tmp
C:\\Users\Techrobot\Downloads\c81dee59-9202-478c-887a-c2f888f82677.tmp
C:\\Users\Techrobot\Downloads\cd5be8b5-3936-438f-9d69-0002ab12b866.tmp
C:\\Users\Techrobot\Downloads\ClickOnceForGoogleChome.exe
C:\\Users\Techrobot\Downloads\CRR32bit\CRRuntime_32bit_13_0_2.msi
C:\\Users\Techrobot\Downloads\desktop.ini
C:\\Users\Techrobot\Downloads\e29bea47-3bc8-423c-902f-308957c73bc3.tmp
C:\\Users\Techrobot\Downloads\eadedfdf-8e8c-45cc-bcba-3434c50ffc05.tmp
C:\\Users\Techrobot\Downloads\edea0895-8052-4181-ba4d-ae6ebd044868.tmp
C:\\Users\Techrobot\Downloads\f0dfc6b7-b932-4007-b64c-a529020ba73f.tmp
C:\\Users\Techrobot\Downloads\fb4a9990-355a-429a-b1da-eea1120b15a3.tmp
C:\\Users\Techrobot\Downloads\fd85d6f1-9a38-4590-8617-157991fd427d.tmp
C:\\Users\Techrobot\Downloads\Firefox Installer.exe
C:\\Users\Techrobot\Downloads\IRkul-eK.pdf.part
C:\\Users\Techrobot\Downloads\kiU-yl0v.pdf.part
C:\\Users\Techrobot\Downloads\MCX_ProductMaster.csv
C:\\Users\Techrobot\Downloads\PDFFontRegister.reg
C:\\Users\Techrobot\Downloads\PDFFontRegister.zip
C:\\Users\Techrobot\Downloads\pk\msvbvm50.dll
C:\\Users\Techrobot\Downloads\pk\PKUNZIP.EXE
C:\\Users\Techrobot\Downloads\pk\PKZIP.EXE
C:\\Users\Techrobot\Downloads\pk\VEDAS32.DLL
C:\\Users\Techrobot\Downloads\PKZIP_PKUNZIP.zip
C:\\Users\Techrobot\Downloads\reports.application
C:\\Users\Techrobot\Downloads\RPA.zip
C:\\Users\Techrobot\Downloads\SAP_Crystal_32bit.zip
C:\\Users\Techrobot\Downloads\SCRIP_011123.TXT
C:\\Users\Techrobot\Downloads\SYMPHONYClient_Registration_09102025_09112025_1109202512495086172576563230.zip
C:\\Users\Techrobot\Downloads\SYMPHONYClient_Registration_09102025_09112025_1209202511233841451509960557.zip
C:\\Users\Techrobot\Downloads\SYMPHONYClient_Registration_30072025_31072025_3107202511383938249579727932.zip
C:\\Users\Techrobot\Downloads\TechExcelRPA-Chrome.1.0.430.zip
C:\\Users\Techrobot\Downloads\TechExcelRPA-Chrome.1.0.499.nupkg
C:\\Users\Techrobot\Downloads\TechExcelRPA-Chrome.1.0.499.nupkg.zip
C:\\Users\Techrobot\Downloads\TPKG4t9B.pdf.part
C:\\Users\Techrobot\Downloads\tXhyTv_0.pdf.part
C:\\Users\Techrobot\Downloads\UiPathStudioSetup.exe
C:\\Users\Techrobot\Downloads\Z2H0WBIV.pdf.part
C:\\Users\tidua\Downloads\desktop.ini

Download folder content report attached.
92431 - User Shell Folders Settings
-
Synopsis
Nessus was able to find the folder paths for user folders on the remote host.
Description
Nessus was able to gather a list of settings from the target system that store common user folder locations. A few of the more common locations are listed below :

- Administrative Tools
- AppData
- Cache
- CD Burning
- Cookies
- Desktop
- Favorites
- Fonts
- History
- Local AppData
- My Music
- My Pictures
- My Video
- NetHood
- Personal
- PrintHood
- Programs
- Recent
- SendTo
- Start Menu
- Startup
- Templates
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/16
Plugin Output

tcp/0

tidua
- {7d1d3a04-debb-4115-95cf-2f29da2920da} : C:\Users\tidua\Searches
- {1b3ea5dc-b587-4786-b4ef-bd1dc332aeae} : C:\Users\tidua\AppData\Roaming\Microsoft\Windows\Libraries
- {374de290-123f-4565-9164-39c4925e467b} : C:\Users\tidua\Downloads
- recent : C:\Users\tidua\AppData\Roaming\Microsoft\Windows\Recent
- my video : C:\Users\tidua\Videos
- my music : C:\Users\tidua\Music
- {56784854-c6cb-462b-8169-88e350acb882} : C:\Users\tidua\Contacts
- {bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968} : C:\Users\tidua\Links
- {a520a1a4-1780-4ff6-bd18-167343c5af16} : C:\Users\tidua\AppData\LocalLow
- sendto : C:\Users\tidua\AppData\Roaming\Microsoft\Windows\SendTo
- start menu : C:\Users\tidua\AppData\Roaming\Microsoft\Windows\Start Menu
- cookies : C:\Users\tidua\AppData\Local\Microsoft\Windows\INetCookies
- personal : C:\Users\tidua\Documents
- administrative tools : C:\Users\tidua\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
- startup : C:\Users\tidua\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
- nethood : C:\Users\tidua\AppData\Roaming\Microsoft\Windows\Network Shortcuts
- history : C:\Users\tidua\AppData\Local\Microsoft\Windows\History
- {4c5c32ff-bb9d-43b0-b5b4-2d72e54eaaa4} : C:\Users\tidua\Saved Games
- {00bcfc5a-ed94-4e48-96a1-3f6217f21990} : C:\Users\tidua\AppData\Local\Microsoft\Windows\RoamingTiles
- !do not use this registry key : Use the SHGetFolderPath or SHGetKnownFolderPath function instead
- local appdata : C:\Users\tidua\AppData\Local
- my pictures : C:\Users\tidua\Pictures
- templates : C:\Users\tidua\AppData\Roaming\Microsoft\Windows\Templates
- printhood : C:\Users\tidua\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
- cache : C:\Users\tidua\AppData\Local\Microsoft\Windows\INetCache
- desktop : C:\Users\tidua\Desktop
- programs : C:\Users\tidua\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
- fonts : C:\WINDOWS\Fonts
- cd burning : C:\Users\tidua\AppData\Local\Microsoft\Windows\Burn\Burn
- favorites : C:\Users\tidua\Favorites
- appdata : C:\Users\tidua\AppData\Roaming

Techrobot
- {7d1d3a04-debb-4115-95cf-2f29da2920da} : C:\Users\Techrobot\Searches
- {1b3ea5dc-b587-4786-b4ef-bd1dc332aeae} : C:\Users\Techrobot\AppData\Roaming\Microsoft\Windows\Libraries
- {374de290-123f-4565-9164-39c4925e467b} : C:\Users\Techrobot\Downloads
- recent : C:\Users\Techrobot\AppData\Roaming\Microsoft\Windows\Recent
- my video : C:\Users\Techrobot\Videos
- my music : C:\Users\Techrobot\Music
- {56784854-c6cb-462b-8169-88e350acb882} : C:\Users\Techrobot\Contacts
- {bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968} : C:\Users\Techrobot\Links
- {a520a1a4-1780-4ff6-bd18-167343c5af16} : C:\Users\Techrobot\AppData\LocalLow
- sendto : C:\Users\Techrobot\AppData\Roaming\Microsoft\Windows\SendTo
- start menu : C:\Users\Techrobot\AppData\Roaming\Microsoft\Windows\Start Menu
- cookies : C:\Users\Techrobot\AppData\Local\Microsoft\Windows\INetCookies
- personal : C:\Users\Techrobot\Documents
- administrative tools : C:\Users\Techrobot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
- startup : C:\Users\Techrobot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
- nethood : C:\Users\Techrobot\AppData\Roaming\Microsoft\Windows\Network Shortcuts
- history : C:\Users\Techrobot\AppData\Local\Microsoft\Windows\History
- {4c5c32ff-bb9d-43b0-b5b4-2d72e54eaaa4} : C:\Users\Techrobot\Saved Games
- {00bcfc5a-ed94-4e48-96a1-3f6217f21990} : C:\Users\Techrobot\AppData\Local\Microsoft\Windows\RoamingTiles
- !do not use this registry key : Use the SHGetFolderPath or SHGetKnownFolderPath function instead
- local appdata : C:\Users\Techrobot\AppData\Local
- my pictures : C:\Users\Techrobot\Pictures
- templates : C:\Users\Techrobot\AppData\Roaming\Microsoft\Windows\Templates
- printhood : C:\Users\Techrobot\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
- cache : C:\Users\Techrobot\AppData\Local\Microsoft\Windows\INetCache
- desktop : C:\Users\Techrobot\Desktop
- programs : C:\Users\Techrobot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
- fonts : C:\WINDOWS\Fonts
- cd burning : C:\Users\Techrobot\AppData\Local\Microsoft\Windows\Burn\Burn
- favorites : C:\Users\Techrobot\Favorites
- appdata : C:\Users\Techrobot\AppData\Roaming
92435 - UserAssist Execution History
-
Synopsis
Nessus was able to enumerate program execution history on the remote host.
Description
Nessus was able to gather evidence from the UserAssist registry key that has a list of programs that have been executed.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2019/11/12
Plugin Output

tcp/0

{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\google chrome.lnk
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.94\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.591\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.494\lib\net45\ffmpeg\bin\ffmpeg.exe
ueme_ctlsession
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\snippingtool.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\rundll32.exe
c:\users\techrobot\downloads\e2openclickoncehelper.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.118\lib\net45\ffmpeg\bin\ffmpeg.exe
\\172.17.100.31\techexcel_dp\uipathrobot_start.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.584\lib\net45\ffmpeg\bin\ffmpeg.exe
microsoft.windows.sechealthui_cw5n1h2txyewy!sechealthui
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.561\lib\net45\ffmpeg\bin\ffmpeg.exe
microsoft.microsoftstickynotes_8wekyb3d8bbwe!app
kasperskylab.kis.ui.toasts
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\microsoft sql server tools 18\microsoft sql server management studio 18.lnk
uipath.studio.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.569\lib\net45\ffmpeg\bin\ffmpeg.exe
microsoft.internetexplorer.default
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\notepad.lnk
{6d809377-6af0-444b-8957-a3773f02200e}\microsoft office\office16\excel.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.458\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\appdata\local\squirreltemp\updatemonitor\uipath.studio.updatemonitor.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\mmc.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\google chrome.lnk
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.430\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa\1.0.2404\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\cdslsecureapp\cdslsecureapp\cdslsecureapp.exe
c:\users\techrobot\downloads\firefox installer.exe
c:\users\techrobot\appdata\local\squirreltemp\update.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.170\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa\1.0.2391\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.559\lib\net45\ffmpeg\bin\ffmpeg.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\task scheduler.lnk
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.590\lib\net45\ffmpeg\bin\ffmpeg.exe
microsoft.windows.photos_8wekyb3d8bbwe!app
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.99\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.570\lib\net45\ffmpeg\bin\ffmpeg.exe
microsoft.microsoftedge_8wekyb3d8bbwe!microsoftedge
c:\users\techrobot\downloads\m4clickoncehelper.exe
microsoft.autogenerated.{923dd477-5846-686b-a659-0fccd73851a8}
com.squirrel.uipath.uipath.studio
d:\lkpsoft\cdsl secure\cdsl secure\cdsl files\cdslsecureappinstaller_22.06.08-p1\cdslsecureappinstaller.exe
microsoft.xboxgamingoverlay_8wekyb3d8bbwe!app
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.582\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.564\lib\net45\ffmpeg\bin\ffmpeg.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\uipath studio.lnk
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.574\lib\net45\ffmpeg\bin\ffmpeg.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\notepad++\updater\gup.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\system tools\task manager.lnk
microsoft.windows.search_cw5n1h2txyewy!cortanaui
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\paint.lnk
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.96\lib\net45\ffmpeg\bin\ffmpeg.exe
chrome._crx_kmejkhcmhgodlgaklnmdmmhhcl
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\notepad.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.567\lib\net45\ffmpeg\bin\ffmpeg.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\internet explorer.lnk
c:\users\techrobot\documents\uipath\techexcelrpa_chrome\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.517\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa\1.0.2402\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.201\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\desktop\cdslsecureapp.lnk
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.489\lib\net45\ffmpeg\bin\ffmpeg.exe
microsoft.windows.explorer
ueme_ctlcuacount:ctor
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.576\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa\1.0.2410\lib\net45\ffmpeg\bin\ffmpeg.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\msiexec.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\optionalfeatures.exe
uipathassistant\uipath.assistant.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\uipath\uipath assistant.lnk
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.89\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\uipath.uiautomation.activities\21.4.4\build\uiexplorer_x64.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.337\lib\net45\ffmpeg\bin\ffmpeg.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\notepad++\notepad++.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.263\lib\net45\ffmpeg\bin\ffmpeg.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\file explorer.lnk
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.175\lib\net45\ffmpeg\bin\ffmpeg.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\dcomcnfg.exe
c:\users\techrobot\.nuget\packages\uipath.uiautomation.activities.runtime.design\24.10.11\build\net461\uiexplorer.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.179\lib\net45\ffmpeg\bin\ffmpeg.exe
{f38bf404-1d43-42f2-9305-67de0b28fc23}\regedit.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.84\lib\net45\ffmpeg\bin\ffmpeg.exe
d:\techexcel\downloads\uipathrobot_start.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.108\lib\net45\ffmpeg\bin\ffmpeg.exe
d:\lkpsoft\cdsl secure\cdsl secure\cdsl files\dotnet_framework_4.0\dotnet framework 4.0\dotnetfx40_full_x86_x64.exe
microsoft.getstarted_8wekyb3d8bbwe!app
microsoft.windows.controlpanel
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.583\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.376\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.316\lib\net45\ffmpeg\bin\ffmpeg.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\system tools\control panel.lnk
microsoft.windows.search_cw5n1h2txyewy!runtimebroker07f4358a809ac99a64a67c1
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\winver.exe
{6d809377-6af0-444b-8957-a3773f02200e}\winrar\winrar.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.251\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.357\lib\net45\ffmpeg\bin\ffmpeg.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\uipath assistant.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\windowspowershell\v1.0\powershell.exe
c:\users\techrobot\appdata\local\programs\uipath\studio\net461\uipath.executor.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\kaspersky lab\kes.12.1.0\avpui.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\registry editor.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\computer management.lnk
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.580\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.160\lib\net45\ffmpeg\bin\ffmpeg.exe
microsoft.windows.windowsinstaller
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\firefox.lnk
c:\users\techrobot\appdata\local\uipath\app-21.4.4\net461\uipath.executor.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\dxdiag.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.484\lib\net45\ffmpeg\bin\ffmpeg.exe
microsoft.microsoftofficehub_8wekyb3d8bbwe!microsoft.microsoftofficehub
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.562\lib\net45\ffmpeg\bin\ffmpeg.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\cloudnotifications.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.548\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.585\lib\net45\ffmpeg\bin\ffmpeg.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\jam software\treesize free\treesizefree.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\system tools\command prompt.lnk
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.97\lib\net45\ffmpeg\bin\ffmpeg.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft sql server management studio 18\common7\ide\ssms.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\excel 2016.lnk
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.306\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.162\lib\net45\ffmpeg\bin\ffmpeg.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\mspaint.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\cdslsecureapp.lnk
microsoft.lockapp_cw5n1h2txyewy!windowsdefaultlockscreen
d:\techexcel\uipathstudiosetup.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.186\lib\net45\ffmpeg\bin\ffmpeg.exe
308046b0af4a39cb
c:\cdslsecureapp\cdslsecureapp\cdslsecureappmaintenancetool.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\sessionmsg.exe
microsoft.windowsmaps_8wekyb3d8bbwe!app
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.158\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.573\lib\net45\ffmpeg\bin\ffmpeg.exe
microsoft.windowsfeedbackhub_8wekyb3d8bbwe!app
d:\lkpsoft\cdsl secure\cdsl secure\cdsl files\pkzip_pkunzip\pk\pkzip.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.530\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\appdata\local\programs\uipath\studio\net472\uipath.executor.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.577\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.499\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa\1.0.2416\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.348\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\appdata\local\uipath\app-21.4.4\uipath.explorer.launcher.exe
microsoft.windows.mediaplayer32
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.563\lib\net45\ffmpeg\bin\ffmpeg.exe
electron.app.uipath.assistant
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.571\lib\net45\ffmpeg\bin\ffmpeg.exe
d:\techexcel setup\uipathstudiosetup.exe
microsoft.windows.startmenuexperiencehost_cw5n1h2txyewy!app
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.209\lib\net45\ffmpeg\bin\ffmpeg.exe
microsoft.people_8wekyb3d8bbwe!x4c7a3b7dy2188y46d4ya362y19ac5a5805e5x
c:\users\techrobot\desktop\uipath studio.lnk
microsoft.zunevideo_8wekyb3d8bbwe!microsoft.zunevideo
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.104\lib\net45\ffmpeg\bin\ffmpeg.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\uipath\uipath studio.lnk
c:\users\public\desktop\google chrome.lnk
microsoft.autogenerated.{8abd94fb-e7d6-84a6-a997-c918edde0ae5}
microsoft.windows.shell.rundialog
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.581\lib\net45\ffmpeg\bin\ffmpeg.exe
microsoft.windows.shellexperiencehost_cw5n1h2txyewy!app
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.579\lib\net45\ffmpeg\bin\ffmpeg.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\snipping tool.lnk
c:\users\public\desktop\notepad++.lnk
c:\users\techrobot\downloads\pk\pkzip.exe
microsoft.windowscalculator_8wekyb3d8bbwe!app
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.173\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.498\lib\net45\ffmpeg\bin\ffmpeg.exe
repo..tion_c860a0771a90e39c_02ad8329efd25da7
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.237\lib\net45\ffmpeg\bin\ffmpeg.exe
windows.immersivecontrolpanel_cw5n1h2txyewy!microsoft.windows.immersivecontrolpanel
msedge
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.560\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\desktop\uipath assistant.lnk
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.565\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.566\lib\net45\ffmpeg\bin\ffmpeg.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\cmd.exe
c:\users\techrobot\appdata\local\uipath\app-21.4.4\uipath.studio.exe
c:\users\techrobot\appdata\local\temp\~nsua.tmp\un_a.exe
c:\users\techrobot\.nuget\packages\uipath.uiautomation.activities\23.10.8\build\uiexplorer.exe
c:\users\techrobot\downloads\clickonceforgooglechome.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.87\lib\net45\ffmpeg\bin\ffmpeg.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\ping.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.307\lib\net45\ffmpeg\bin\ffmpeg.exe
d:\lkpsoft\cdsl secure\silverlight_x64\silverlight_x64.exe
c:\users\techrobot\appdata\local\uipath\app-21.4.4\uipath\uipath.microsoftoffice.tools.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.586\lib\net45\ffmpeg\bin\ffmpeg.exe
{6d809377-6af0-444b-8957-a3773f02200e}\7-zip\7zg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.477\lib\net45\ffmpeg\bin\ffmpeg.exe
microsoft.autogenerated.{c1c6f8ac-40a3-0f5c-146f-65a9dc70bbb4}
microsoft.skydrive.desktop
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.150\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\public\desktop\firefox.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\openwith.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\firefox.lnk
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.383\lib\net45\ffmpeg\bin\ffmpeg.exe
{6d809377-6af0-444b-8957-a3773f02200e}\microsoft office\office16\winword.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.125\lib\net45\ffmpeg\bin\ffmpeg.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\services.msc
c:\users\techrobot\.nuget\packages\techexcelrpa\1.0.2393\lib\net45\ffmpeg\bin\ffmpeg.exe
d:\lkpsoft\cdsl secure\cdsl secure\cdsl files\pkzip_pkunzip\pk\pkunzip.exe
repo..tion_c860a0771a90e39c_3fd8bb45842128d3
microsoft.windows.cloudexperiencehost_cw5n1h2txyewy!app
chrome
c:\users\techrobot\desktop\treesizefreesetup.exe
d:\firefox setup 134.0.exe
c:\users\techrobot\documents\uipath\techexcelrpa\ffmpeg\bin\ffmpeg.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\windows powershell\windows powershell.lnk
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\cdslsecureapp\cdslsecureapp.lnk
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.91\lib\net45\ffmpeg\bin\ffmpeg.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\google chrome.lnk
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.94\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.591\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.494\lib\net45\ffmpeg\bin\ffmpeg.exe
ueme_ctlsession
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\snippingtool.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\rundll32.exe
c:\users\techrobot\downloads\e2openclickoncehelper.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.118\lib\net45\ffmpeg\bin\ffmpeg.exe
\\172.17.100.31\techexcel_dp\uipathrobot_start.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.584\lib\net45\ffmpeg\bin\ffmpeg.exe
microsoft.windows.sechealthui_cw5n1h2txyewy!sechealthui
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.561\lib\net45\ffmpeg\bin\ffmpeg.exe
kasperskylab.kis.ui.toasts
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\microsoft sql server tools 18\microsoft sql server management studio 18.lnk
uipath.studio.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.569\lib\net45\ffmpeg\bin\ffmpeg.exe
microsoft.internetexplorer.default
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\notepad.lnk
{6d809377-6af0-444b-8957-a3773f02200e}\microsoft office\office16\excel.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.458\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\appdata\local\squirreltemp\updatemonitor\uipath.studio.updatemonitor.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\mmc.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\google chrome.lnk
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.430\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa\1.0.2404\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\cdslsecureapp\cdslsecureapp\cdslsecureapp.exe
c:\users\techrobot\downloads\firefox installer.exe
c:\users\techrobot\appdata\local\squirreltemp\update.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.170\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa\1.0.2391\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.559\lib\net45\ffmpeg\bin\ffmpeg.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\task scheduler.lnk
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.590\lib\net45\ffmpeg\bin\ffmpeg.exe
microsoft.windows.photos_8wekyb3d8bbwe!app
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.99\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.570\lib\net45\ffmpeg\bin\ffmpeg.exe
microsoft.microsoftedge_8wekyb3d8bbwe!microsoftedge
c:\users\techrobot\downloads\m4clickoncehelper.exe
microsoft.autogenerated.{923dd477-5846-686b-a659-0fccd73851a8}
com.squirrel.uipath.uipath.studio
d:\lkpsoft\cdsl secure\cdsl secure\cdsl files\cdslsecureappinstaller_22.06.08-p1\cdslsecureappinstaller.exe
microsoft.xboxgamingoverlay_8wekyb3d8bbwe!app
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.582\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.564\lib\net45\ffmpeg\bin\ffmpeg.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\uipath studio.lnk
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.574\lib\net45\ffmpeg\bin\ffmpeg.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\notepad++\updater\gup.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\system tools\task manager.lnk
microsoft.windows.search_cw5n1h2txyewy!cortanaui
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.96\lib\net45\ffmpeg\bin\ffmpeg.exe
chrome._crx_kmejkhcmhgodlgaklnmdmmhhcl
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\notepad.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.567\lib\net45\ffmpeg\bin\ffmpeg.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\internet explorer.lnk
c:\users\techrobot\documents\uipath\techexcelrpa_chrome\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.517\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa\1.0.2402\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.201\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\desktop\cdslsecureapp.lnk
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.489\lib\net45\ffmpeg\bin\ffmpeg.exe
microsoft.windows.explorer
ueme_ctlcuacount:ctor
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.576\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa\1.0.2410\lib\net45\ffmpeg\bin\ffmpeg.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\msiexec.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\optionalfeatures.exe
uipathassistant\uipath.assistant.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\uipath\uipath assistant.lnk
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.89\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\uipath.uiautomation.activities\21.4.4\build\uiexplorer_x64.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.337\lib\net45\ffmpeg\bin\ffmpeg.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\notepad++\notepad++.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.263\lib\net45\ffmpeg\bin\ffmpeg.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\file explorer.lnk
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.175\lib\net45\ffmpeg\bin\ffmpeg.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\dcomcnfg.exe
c:\users\techrobot\.nuget\packages\uipath.uiautomation.activities.runtime.design\24.10.11\build\net461\uiexplorer.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.179\lib\net45\ffmpeg\bin\ffmpeg.exe
{f38bf404-1d43-42f2-9305-67de0b28fc23}\regedit.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.84\lib\net45\ffmpeg\bin\ffmpeg.exe
d:\techexcel\downloads\uipathrobot_start.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.108\lib\net45\ffmpeg\bin\ffmpeg.exe
d:\lkpsoft\cdsl secure\cdsl secure\cdsl files\dotnet_framework_4.0\dotnet framework 4.0\dotnetfx40_full_x86_x64.exe
microsoft.windows.controlpanel
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.583\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.376\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.316\lib\net45\ffmpeg\bin\ffmpeg.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\system tools\control panel.lnk
microsoft.windows.search_cw5n1h2txyewy!runtimebroker07f4358a809ac99a64a67c1
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\winver.exe
{6d809377-6af0-444b-8957-a3773f02200e}\winrar\winrar.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.251\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.357\lib\net45\ffmpeg\bin\ffmpeg.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\uipath assistant.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\windowspowershell\v1.0\powershell.exe
c:\users\techrobot\appdata\local\programs\uipath\studio\net461\uipath.executor.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\kaspersky lab\kes.12.1.0\avpui.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\registry editor.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\computer management.lnk
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.580\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.160\lib\net45\ffmpeg\bin\ffmpeg.exe
microsoft.windows.windowsinstaller
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\firefox.lnk
c:\users\techrobot\appdata\local\uipath\app-21.4.4\net461\uipath.executor.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\dxdiag.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.484\lib\net45\ffmpeg\bin\ffmpeg.exe
microsoft.microsoftofficehub_8wekyb3d8bbwe!microsoft.microsoftofficehub
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.562\lib\net45\ffmpeg\bin\ffmpeg.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\cloudnotifications.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.548\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.585\lib\net45\ffmpeg\bin\ffmpeg.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\jam software\treesize free\treesizefree.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\system tools\command prompt.lnk
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.97\lib\net45\ffmpeg\bin\ffmpeg.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft sql server management studio 18\common7\ide\ssms.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\excel 2016.lnk
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.306\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.162\lib\net45\ffmpeg\bin\ffmpeg.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\cdslsecureapp.lnk
microsoft.lockapp_cw5n1h2txyewy!windowsdefaultlockscreen
d:\techexcel\uipathstudiosetup.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.186\lib\net45\ffmpeg\bin\ffmpeg.exe
308046b0af4a39cb
c:\cdslsecureapp\cdslsecureapp\cdslsecureappmaintenancetool.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\sessionmsg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.158\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.573\lib\net45\ffmpeg\bin\ffmpeg.exe
microsoft.windowsfeedbackhub_8wekyb3d8bbwe!app
d:\lkpsoft\cdsl secure\cdsl secure\cdsl files\pkzip_pkunzip\pk\pkzip.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.530\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\appdata\local\programs\uipath\studio\net472\uipath.executor.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.577\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.499\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa\1.0.2416\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.348\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\appdata\local\uipath\app-21.4.4\uipath.explorer.launcher.exe
microsoft.windows.mediaplayer32
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.563\lib\net45\ffmpeg\bin\ffmpeg.exe
electron.app.uipath.assistant
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.571\lib\net45\ffmpeg\bin\ffmpeg.exe
d:\techexcel setup\uipathstudiosetup.exe
microsoft.windows.startmenuexperiencehost_cw5n1h2txyewy!app
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.209\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\desktop\uipath studio.lnk
microsoft.zunevideo_8wekyb3d8bbwe!microsoft.zunevideo
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.104\lib\net45\ffmpeg\bin\ffmpeg.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\uipath\uipath studio.lnk
c:\users\public\desktop\google chrome.lnk
microsoft.autogenerated.{8abd94fb-e7d6-84a6-a997-c918edde0ae5}
microsoft.windows.shell.rundialog
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.581\lib\net45\ffmpeg\bin\ffmpeg.exe
microsoft.windows.shellexperiencehost_cw5n1h2txyewy!app
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.579\lib\net45\ffmpeg\bin\ffmpeg.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\snipping tool.lnk
c:\users\public\desktop\notepad++.lnk
c:\users\techrobot\downloads\pk\pkzip.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.173\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.498\lib\net45\ffmpeg\bin\ffmpeg.exe
repo..tion_c860a0771a90e39c_02ad8329efd25da7
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.237\lib\net45\ffmpeg\bin\ffmpeg.exe
windows.immersivecontrolpanel_cw5n1h2txyewy!microsoft.windows.immersivecontrolpanel
msedge
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.560\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\desktop\uipath assistant.lnk
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.565\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.566\lib\net45\ffmpeg\bin\ffmpeg.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\cmd.exe
c:\users\techrobot\appdata\local\uipath\app-21.4.4\uipath.studio.exe
c:\users\techrobot\appdata\local\temp\~nsua.tmp\un_a.exe
c:\users\techrobot\.nuget\packages\uipath.uiautomation.activities\23.10.8\build\uiexplorer.exe
c:\users\techrobot\downloads\clickonceforgooglechome.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.87\lib\net45\ffmpeg\bin\ffmpeg.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\ping.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.307\lib\net45\ffmpeg\bin\ffmpeg.exe
d:\lkpsoft\cdsl secure\silverlight_x64\silverlight_x64.exe
c:\users\techrobot\appdata\local\uipath\app-21.4.4\uipath\uipath.microsoftoffice.tools.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.586\lib\net45\ffmpeg\bin\ffmpeg.exe
{6d809377-6af0-444b-8957-a3773f02200e}\7-zip\7zg.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.477\lib\net45\ffmpeg\bin\ffmpeg.exe
microsoft.autogenerated.{c1c6f8ac-40a3-0f5c-146f-65a9dc70bbb4}
microsoft.skydrive.desktop
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.150\lib\net45\ffmpeg\bin\ffmpeg.exe
c:\users\public\desktop\firefox.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\openwith.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\firefox.lnk
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.383\lib\net45\ffmpeg\bin\ffmpeg.exe
{6d809377-6af0-444b-8957-a3773f02200e}\microsoft office\office16\winword.exe
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.125\lib\net45\ffmpeg\bin\ffmpeg.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\services.msc
c:\users\techrobot\.nuget\packages\techexcelrpa\1.0.2393\lib\net45\ffmpeg\bin\ffmpeg.exe
d:\lkpsoft\cdsl secure\cdsl secure\cdsl files\pkzip_pkunzip\pk\pkunzip.exe
repo..tion_c860a0771a90e39c_3fd8bb45842128d3
microsoft.windows.cloudexperiencehost_cw5n1h2txyewy!app
chrome
c:\users\techrobot\desktop\treesizefreesetup.exe
d:\firefox setup 134.0.exe
c:\users\techrobot\documents\uipath\techexcelrpa\ffmpeg\bin\ffmpeg.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\windows powershell\windows powershell.lnk
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\cdslsecureapp\cdslsecureapp.lnk
c:\users\techrobot\.nuget\packages\techexcelrpa-chrome\1.0.91\lib\net45\ffmpeg\bin\ffmpeg.exe

Extended userassist report attached.

105793 - VMware Tools Detection
-
Synopsis
A virtual machine management application is installed on the remote host.
Description
VMware Tools, a suite of utilities that enhances the performance of the virtual machines guest operating system is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0738
Plugin Information
Published: 2018/01/13, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Path : C:\Program Files\VMware\VMware Tools\
Version : 12.3.5.46049

20094 - VMware Virtual Machine Detection
-
Synopsis
The remote host is a VMware virtual machine.
Description
According to the MAC address of its network adapter, the remote host is a VMware virtual machine.
Solution
Since it is physically accessible through the network, ensure that its configuration matches your organization's security policy.
Risk Factor
None
Plugin Information
Published: 2005/10/27, Modified: 2019/12/11
Plugin Output

tcp/0


The remote host is a VMware virtual machine.

19288 - VNC Server Security Type Detection
-
Synopsis
A VNC server is running on the remote host.
Description
This script checks the remote VNC server protocol version and the available 'security types'.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2005/07/22, Modified: 2021/07/13
Plugin Output

tcp/5900/vnc


The remote VNC server supports the following security types :\n\n 2 (VNC authentication)
16 (Tight)
65792 - VNC Server Unencrypted Communication Detection
-
Synopsis
A VNC server with one or more unencrypted 'security-types' is running on the remote host.
Description
This script checks the remote VNC server protocol version and the available 'security types' to determine if any unencrypted 'security-types' are in use or available.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/04/03, Modified: 2014/03/12
Plugin Output

tcp/5900/vnc


The remote VNC server supports the following security type
which does not perform full data communication encryption :

2 (VNC authentication)
16 (Tight)
10342 - VNC Software Detection
-
Synopsis
The remote host is running a remote display software (VNC).
Description
The remote host is running VNC (Virtual Network Computing), which uses the RFB (Remote Framebuffer) protocol to provide remote access to graphical user interfaces and thus permits a console on the remote host to be displayed on another.
See Also
Solution
Make sure use of this software is done in accordance with your organization's security policy and filter incoming traffic to this port.
Risk Factor
None
Plugin Information
Published: 2000/03/07, Modified: 2017/06/12
Plugin Output

tcp/5900/vnc


The highest RFB protocol version supported by the server is :

3.8

24269 - WMI Available
-
Synopsis
WMI queries can be made against the remote host.
Description
The supplied credentials can be used to make WMI (Windows Management Instrumentation) requests against the remote host over DCOM.

These requests can be used to gather information about the remote host, such as its current state, network interface configuration, etc.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/02/03, Modified: 2025/12/15
Plugin Output

tcp/445/cifs

The remote host returned the following caption from Win32_OperatingSystem:

Microsoft Windows 10 Pro

51187 - WMI Encryptable Volume Enumeration
-
Synopsis
The remote Windows host has encryptable volumes available.
Description
By connecting to the remote host with the supplied credentials, this plugin enumerates encryptable volume information available on the remote host via WMI.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/12/15, Modified: 2025/12/15
Plugin Output

tcp/0


Here is a list of encryptable volumes available on the remote system :

+ DriveLetter C:

- BitLocker Version : None
- Conversion Status : Fully Decrypted
- DeviceID : \\?\Volume{51cd10b5-0000-0000-0000-402400000000}\
- Encryption Method : None
- Identification Field : None
- Key Protectors : None Found
- Lock Status : Unlocked
- Percentage Encrypted : 0.0%
- Protection Status : Protection Off
- Size : 119.43 GB

+ DriveLetter D:

- Automatic Unlock : Disabled
- BitLocker Version : None
- Conversion Status : Fully Decrypted
- DeviceID : \\?\Volume{d1da0102-0000-0000-0000-100000000000}\
- Encryption Method : None
- Identification Field : None
- Key Protectors : None Found
- Lock Status : Unlocked
- Percentage Encrypted : 0.0%
- Protection Status : Protection Off
- Size : 200.00 GB
52001 - WMI QuickFixEngineering (QFE) Enumeration
-
Synopsis
The remote Windows host has quick-fix engineering updates installed.
Description
By connecting to the remote host with the supplied credentials, this plugin enumerates quick-fix engineering updates installed on the remote host via WMI.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/02/16, Modified: 2025/12/15
Plugin Output

tcp/0


Here is a list of quick-fix engineering updates installed on the
remote system :

+ KB5056578
- Description : Update
- InstalledOn : 5/3/2025
- SystemName : LIVETECHROBO
- InstalledBy : NT AUTHORITY\SYSTEM
- Caption : http://support.microsoft.com/?kbid=5056578

+ KB5030841
- Description : Update
- InstalledOn : 10/31/2023
- SystemName : LIVETECHROBO
- InstalledBy : NT AUTHORITY\SYSTEM
- Caption : http://support.microsoft.com/?kbid=5030841

+ KB4562830
- Description : Update
- InstalledOn : 4/14/2022
- SystemName : LIVETECHROBO
- InstalledBy : NT AUTHORITY\SYSTEM
- Caption : https://support.microsoft.com/help/4562830

+ KB5007401
- Description : Update
- InstalledOn : 4/14/2022
- SystemName : LIVETECHROBO
- InstalledBy : NT AUTHORITY\SYSTEM
- Caption : https://support.microsoft.com/help/5007401

+ KB5011048
- Description : Update
- InstalledOn : 10/31/2023
- SystemName : LIVETECHROBO
- InstalledBy : NT AUTHORITY\SYSTEM
- Caption : http://support.microsoft.com/?kbid=5011048

+ KB5015684
- Description : Update
- InstalledOn : 9/22/2023
- SystemName : LIVETECHROBO
- InstalledBy : NT AUTHORITY\SYSTEM
- Caption : https://support.microsoft.com/help/5015684

+ KB5033052
- Description : Update
- InstalledOn : 3/10/2025
- SystemName : LIVETECHROBO
- InstalledBy : NT AUTHORITY\SYSTEM
- Caption : https://support.microsoft.com/help/5033052

+ KB5060533
- Description : Security Update
- InstalledOn : 6/23/2025
- SystemName : LIVETECHROBO
- InstalledBy : NT AUTHORITY\SYSTEM
- Caption : https://support.microsoft.com/help/5060533

+ KB5011651
- Description : Update
- InstalledOn : 4/14/2022
- SystemName : LIVETECHROBO
- InstalledBy : NT AUTHORITY\SYSTEM

+ KB5029709
- Description : Update
- InstalledOn : 9/14/2023
- SystemName : LIVETECHROBO
- InstalledBy : NT AUTHORITY\SYSTEM

+ KB5031539
- Description : Update
- InstalledOn : 10/10/2023
- SystemName : LIVETECHROBO
- InstalledBy : NT AUTHORITY\SYSTEM

+ KB5032392
- Description : Update
- InstalledOn : 11/17/2023
- SystemName : LIVETECHROBO
- InstalledBy : NT AUTHORITY\SYSTEM

+ KB5050111
- Description : Update
- InstalledOn : 3/10/2025
- SystemName : LIVETECHROBO
- InstalledBy : NT AUTHORITY\SYSTEM

+ KB5052916
- Description : Update
- InstalledOn : 3/13/2025
- SystemName : LIVETECHROBO
- InstalledBy : NT AUTHORITY\SYSTEM

+ KB5054682
- Description : Update
- InstalledOn : 4/12/2025
- SystemName : LIVETECHROBO
- InstalledBy : NT AUTHORITY\SYSTEM

+ KB5058526
- Description : Security Update
- InstalledOn : 5/15/2025
- SystemName : LIVETECHROBO
- InstalledBy : NT AUTHORITY\SYSTEM

+ KB5059504
- Description : Update
- InstalledOn : 6/13/2025
- SystemName : LIVETECHROBO
- InstalledBy : NT AUTHORITY\SYSTEM
44871 - WMI Windows Feature Enumeration
-
Synopsis
It is possible to enumerate Windows features using WMI.
Description
Nessus was able to enumerate the server features of the remote host by querying the 'Win32_ServerFeature' class of the '\Root\cimv2' WMI namespace for Windows Server versions or the 'Win32_OptionalFeature' class of the '\Root\cimv2' WMI namespace for Windows Desktop versions.

Note that Features can only be enumerated for Windows 7 and later for desktop versions.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0754
Plugin Information
Published: 2010/02/24, Modified: 2025/12/15
Plugin Output

tcp/0


Nessus enumerated the following Windows features :

- Internet-Explorer-Optional-amd64
- MSRDC-Infrastructure
- MediaPlayback
- MicrosoftWindowsPowerShellV2
- MicrosoftWindowsPowerShellV2Root
- NetFx3
- NetFx4-AdvSrvs
- Printing-Foundation-Features
- Printing-Foundation-InternetPrinting-Client
- Printing-PrintToPDFServices-Features
- Printing-XPSServices-Features
- SearchEngine-Client-Package
- SmbDirect
- TelnetClient
- WCF-Services45
- WCF-TCP-PortSharing45
- WindowsMediaPlayer
- WorkFolders-Client
92436 - WinRAR History
-
Synopsis
Nessus was able to enumerate files opened with WinRAR on the remote host.
Description
Nessus was able to gather evidence of compressed files that were opened by WinRAR. Note that only compressed files that were opened and not extracted through the explorer shortcut or command line interface were reported.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

D:\Techexcel\Export\Odin\July\18072024\18072024094819.zip
C:\Users\Techrobot\Downloads\RPA.zip
D:\Techexcel\Upload\CDSL\April\03-04-2025\Focaps\EOD\Success\SOH_EXP_030000_123_F_202504020000_999_C_0_0_P0.zip
D:\Techexcel\Upload\NSE_CASH\July\10-07-2024\BhavCopy_NSE_CM_0_0_0_20240710_F_0000.csv.zip

WinRAR report attached.

162174 - Windows Always Installed Elevated Status
-
Synopsis
Windows AlwaysInstallElevated policy status was found on the remote Windows host
Description
Windows AlwaysInstallElevated policy status was found on the remote Windows host.
You can use the AlwaysInstallElevated policy to install a Windows Installer package with elevated (system) privileges This option is equivalent to granting full administrative rights, which can pose a massive security risk. Microsoft strongly discourages the use of this setting.
Solution
If enabled, disable AlwaysInstallElevated policy per your corporate security guidelines.
Risk Factor
None
Plugin Information
Published: 2022/06/14, Modified: 2022/06/14
Plugin Output

tcp/445/cifs

AlwaysInstallElevated policy is not enabled under HKEY_LOCAL_MACHINE.
AlwaysInstallElevated policy is not enabled under HKEY_USERS user:S-1-5-21-2193062927-1383316644-2198579232-1004
AlwaysInstallElevated policy is not enabled under HKEY_USERS user:S-1-5-21-2193062927-1383316644-2198579232-1009

48337 - Windows ComputerSystemProduct Enumeration (WMI)
-
Synopsis
It is possible to obtain product information from the remote host using WMI.
Description
By querying the WMI class 'Win32_ComputerSystemProduct', it is possible to extract product information about the computer system such as UUID, IdentifyingNumber, vendor, etc.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/08/16, Modified: 2025/12/15
Plugin Output

tcp/0


+ Computer System Product
- IdentifyingNumber : VMware-56 4d 13 ee bc e4 fd 9f-83 40 6d d9 e2 5c ed cc
- Description : Computer System Product
- Vendor : VMware, Inc.
- Name : VMware Virtual Platform
- UUID : EE134D56-E4BC-9FFD-8340-6DD9E25CEDCC
- Version : None

159817 - Windows Credential Guard Status
-
Synopsis
Retrieves the status of Windows Credential Guard.
Description
Retrieves the status of Windows Credential Guard.
Credential Guard prevents attacks such as such as Pass-the-Hash or Pass-The-Ticket by protecting NTLM password hashes, Kerberos Ticket Granting Tickets, and credentials stored by applications as domain credentials.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2022/04/18, Modified: 2023/08/25
Plugin Output

tcp/445/cifs


Windows Credential Guard is not fully enabled.
The following registry keys have not been set :
- System\CurrentControlSet\Control\DeviceGuard\RequirePlatformSecurityFeatures : Key not found.
- System\CurrentControlSet\Control\LSA\LsaCfgFlags : Key not found.
- System\CurrentControlSet\Control\DeviceGuard\EnableVirtualizationBasedSecurity : Key not found.
58181 - Windows DNS Server Enumeration
-
Synopsis
Nessus enumerated the DNS servers being used by the remote Windows host.
Description
Nessus was able to enumerate the DNS servers configured on the remote Windows host by looking in the registry.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2012/03/01, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Nessus enumerated DNS servers for the following interfaces :

Interface: {426eb1cc-8498-458f-9b7b-c49af5ca7afc}
Network Connection : LAN
NameServer: 4.2.2.2,8.8.8.8

131023 - Windows Defender Installed
-
Synopsis
Windows Defender is installed on the remote Windows host.
Description
Windows Defender, an antivirus component of Microsoft Windows is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2019/11/15, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2203.5-0\
Version : 4.18.2203.5
Disabled : 1
Engine Version : 1.1.25010.7
Malware Signature Timestamp : Mar. 11, 2025 at 09:11:36 GMT
Malware Signature Version : 1.423.343.0
Signatures Last Updated : Mar. 11, 2025 at 13:41:00 GMT

164690 - Windows Disabled Command Prompt Enumeration
-
Synopsis
This plugin determines if the DisableCMD policy is enabled or disabled on the remote host for each local user.
Description
The remote host may employ the DisableCMD policy on a per user basis. Enumerated local users may have the following registry key:
'HKLM\Software\Policies\Microsoft\Windows\System\DisableCMD'

- Unset or 0: The command prompt is enabled normally.
- 1: The command promt is disabled.
- 2: The command prompt is disabled however windows batch processing is allowed.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2022/09/06, Modified: 2022/10/05
Plugin Output

tcp/445/cifs


Username: Production
SID: S-1-5-21-2193062927-1383316644-2198579232-500
DisableCMD: Unset

Username: Techapp
SID: S-1-5-21-2193062927-1383316644-2198579232-1006
DisableCMD: Unset

Username: WDAGUtilityAccount
SID: S-1-5-21-2193062927-1383316644-2198579232-504
DisableCMD: Unset

Username: Techexcel
SID: S-1-5-21-2193062927-1383316644-2198579232-1005
DisableCMD: Unset

Username: tidua
SID: S-1-5-21-2193062927-1383316644-2198579232-1009
DisableCMD: Unset

Username: Guest
SID: S-1-5-21-2193062927-1383316644-2198579232-501
DisableCMD: Unset

Username: DefaultAccount
SID: S-1-5-21-2193062927-1383316644-2198579232-503
DisableCMD: Unset

Username: Techrobot
SID: S-1-5-21-2193062927-1383316644-2198579232-1004
DisableCMD: Unset

Username: LKPAdmin
SID: S-1-5-21-2193062927-1383316644-2198579232-1001
DisableCMD: Unset

72482 - Windows Display Driver Enumeration
-
Synopsis
Nessus was able to enumerate one or more of the display drivers on the remote host.
Description
Nessus was able to enumerate one or more of the display drivers on the remote host via WMI.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0756
Plugin Information
Published: 2014/02/06, Modified: 2025/12/15
Plugin Output

tcp/0


Device Name : VMware SVGA 3D
Driver File Version : 9.17.6.5
Driver Date : 08/25/2023
Video Processor : VMware Virtual SVGA 3D Graphics Adapter
171956 - Windows Enumerate Accounts
-
Synopsis
Enumerate Windows accounts.
Description
Enumerate Windows accounts.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/02/28, Modified: 2025/12/15
Plugin Output

tcp/0

Windows accounts enumerated. Results output to DB.
User data gathered in scan starting at : 2026/1/16 16:15 India Standard Time
92423 - Windows Explorer Recently Executed Programs
-
Synopsis
Nessus was able to enumerate recently executed programs on the remote host.
Description
Nessus was able to find evidence of program execution using Windows Explorer registry logs and settings.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2019/08/15
Plugin Output

tcp/0

chrome.exePO :i+00/D:\\1Y[BDTechexcelDQWM^0\U.A.TechexcelT1ZUpload>QWM^0\jT.g%BUploadJ1YT-MCX8QWM^0\jT.?MCXV10\1January@QWM^0\jT.January`10\'V16-01-2026F0\10\'V."916-01-2026
mmc.exePO :i+00/D:\\1QWM^TechexcelDQWM^mW*.A@DTechexcelb1R.]RPASettingsHQWM^mW..aRPASettings
SnippingTool.exeU//D:\tY^Hg3(w,/J>Vhn10V|PTechexcel SetupP0VN0V|P.3ZTechexcel Setup
ReportsDownload.exePO :i+00/D:\\1Y[BDTechexcelDQWM^0\M.A.TechexcelT1ZUpload>QWM^0\H.g%BUploadN1[YCDSL:EY+0\H.?:=CDSLV1/\fJanuary@Y+0\M.6oe`January`10\16-01-2026F/\f0\M.D16-01-2026`10\DepositoryF0\0\H. ^DepositoryV10\Curdate@0\0\H. ^CurdateV10\.Pending@0\0\L. +Pending
IEXPLORE.EXEPO :i+00/D:\\1+X3TechexcelDQWM^X&.A3TechexcelT1X@gUpload>QWM^XY,.g\n3UploadV1Xn-BSE_FNO@QWM^X,.BSE_FNOJ1X,May8Xn-X,.May`1X,29-05-2024FX,X,./29-05-2024
firefox.exePO :i+00/D:\\1EZe=TechexcelDQWM^\Z&.ATechexcelT1EY+Upload>QWM^\Z,.g@%UploadJ1YT-MCX8QWM^\Zq-.?MCXZ1\Zn-FebruaryBAX6\Zq-.P[OFebruary`1\Zn-28-02-2025F\Zn-\Zn-.f7[O28-02-2025
a
services.msc\1
C:\Program Files (x86)\Microsoft\\1
\\TechE_Live_DB\1
drivers\1
notepad\1
\\172.17.100.35\1
services.msc\1
%temp%\1
winver\1
\\192.168.150.54\1
\\172.17.100.31\upload$\Alert_files\1
\\172.17.100.31\techexcel$\Lucee\tomcat\webapps\ROOT\Reports\\1
regedit\1
wmimgmt.msc\1
\\172.17.100.222\1
\\172.17.100.31\upload$\1
dxdiag\1
\\192.168.150.164\\1
\\172.17.100.31\1
c:\Windows\1
ping 192.168.150.54\1
yezuxwhqpavgcfrtsonlmkdjib
\\172.17.100.62\1
dcomcnfg\1
gpedit.msc\1
\\172.17.100.31\\1
control\1
cmd\1
chrome.exe
regedit.exe+;4
ReportsDownload.exe+
UiPath.Studio.exeq
WinRAR.exee?
SnippingTool.exeLT3
mmc.exe
firefox.exe
iexplore.exe
x@_dP/N

MRU programs details in attached report.
92418 - Windows Explorer Typed Paths
-
Synopsis
Nessus was able to enumerate the directory paths that users visited by typing the full directory path into Windows Explorer.
Description
Nessus was able to enumerate the directory paths that users visited by manually typing the full directory path into Windows Explorer. The generated folder list report contains folders local to the system, folders from past mounted network drives, and folders from mounted devices.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

D:\Techexcel
D:\
\\192.168.150.54
\\172.17.100.31\Techexcel_DP\xaml
\\172.17.100.31\techexcel_dp\ROOT\RPAVideo
\\TechE_Live_DB\techexcel$
\\172.17.100.31
D:\Techexcel\Upload\BSE_CASH\July
\\172.17.100.31\Techexcel_DP
\\172.17.100.31\techexcel$

Extended explorer typed paths report attached.

159929 - Windows LSA Protection Status
-
Synopsis
Windows LSA Protection is disabled on the remote Windows host.
Description
The LSA Protection validates users for local and remote sign-ins and enforces local security policies to prevent reading memory and code injection by non-protected processes. This provides added security for the credentials that the LSA stores and manages. This protects against Pass-the-Hash or Mimikatz-style attacks.
Solution
Enable LSA Protection per your corporate security guidelines.
Risk Factor
None
Plugin Information
Published: 2022/04/20, Modified: 2025/06/16
Plugin Output

tcp/445/cifs


LSA Protection Key \SYSTEM\CurrentControlSet\Control\Lsa\RunAsPPL not found.

148541 - Windows Language Settings Detection
-
Synopsis
This plugin enumerates language files on a windows host.
Description
By connecting to the remote host with the supplied credentials, this plugin enumerates language IDs listed on the host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2021/04/14, Modified: 2022/02/01
Plugin Output

tcp/0

Default Install Language Code: 1033

Default Active Language Code: 1033

Other common microsoft Language packs may be scanned as well.
92422 - Windows Mapped Network Drives
-
Synopsis
Nessus was able to enumerate mapped network drives on the remote host.
Description
Nessus was able to generate a report of mapped network drives on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

b : \\192.168.150.54\cdas
mrulist : cba
c : \\192.168.150.54\cdas\REPORTS
a : \\192.168.150.54\Download


Extended mapped network drive report attached.

10150 - Windows NetBIOS / SMB Remote Host Information Disclosure
-
Synopsis
It was possible to obtain the network name of the remote host.
Description
The remote host is listening on UDP port 137 or TCP port 445, and replies to NetBIOS nbtscan or SMB requests.

Note that this plugin gathers information to be used in other plugins, but does not itself generate a report.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 1999/10/12, Modified: 2021/02/10
Plugin Output

udp/137/netbios-ns

The following 3 NetBIOS names have been gathered :

LIVETECHROBO = File Server Service
LIVETECHROBO = Computer name
WORKGROUP = Workgroup / Domain name

The remote host has the following MAC address on its adapter :

00:50:56:bc:fc:73

77668 - Windows Prefetch Folder
-
Synopsis
Nessus was able to retrieve the Windows prefetch folder file list.
Description
Nessus was able to retrieve and display the contents of the Windows prefetch folder (%systemroot%\prefetch\*). This information shows programs that have run with the prefetch and superfetch mechanisms enabled.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2014/09/12, Modified: 2018/11/15
Plugin Output

tcp/0

+ HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters
rootdirpath :
enableprefetcher : 3

+ Prefetch file list :
- \WINDOWS\prefetch\143.0.7499.171_CHROME_INSTALL-961F2C40.pf
- \WINDOWS\prefetch\143.0.7499.193_CHROME_INSTALL-0097E7B5.pf
- \WINDOWS\prefetch\7Z1900-X64.EXE-A11F8DBD.pf
- \WINDOWS\prefetch\7ZA.EXE-531F3181.pf
- \WINDOWS\prefetch\7ZA.EXE-CC238194.pf
- \WINDOWS\prefetch\7ZFM.EXE-69B8961D.pf
- \WINDOWS\prefetch\7ZG.EXE-0F8C4081.pf
- \WINDOWS\prefetch\ACCESSDATABASEENGINE_X64.EXE-3024F5A1.pf
- \WINDOWS\prefetch\ACCESSDATABASEENGINE_X64_2016-E6ABFC49.pf
- \WINDOWS\prefetch\APPLICATIONFRAMEHOST.EXE-CCEEF759.pf
- \WINDOWS\prefetch\ATBROKER.EXE-2E15A492.pf
- \WINDOWS\prefetch\AUDIODG.EXE-BDFD3029.pf
- \WINDOWS\prefetch\AVP.EXE-9D84BA9B.pf
- \WINDOWS\prefetch\AVPSUS.EXE-F41A52C2.pf
- \WINDOWS\prefetch\AVPUI.EXE-4147118F.pf
- \WINDOWS\prefetch\AVPUI.EXE-EFBF6819.pf
- \WINDOWS\prefetch\BACKGROUNDTASKHOST.EXE-56AD17C3.pf
- \WINDOWS\prefetch\BACKGROUNDTASKHOST.EXE-5B3CF9A0.pf
- \WINDOWS\prefetch\BACKGROUNDTASKHOST.EXE-D61F7B44.pf
- \WINDOWS\prefetch\BACKGROUNDTRANSFERHOST.EXE-11AE310D.pf
- \WINDOWS\prefetch\BACKGROUNDTRANSFERHOST.EXE-75FFE0A9.pf
- \WINDOWS\prefetch\BACKGROUNDTRANSFERHOST.EXE-F2F36CB7.pf
- \WINDOWS\prefetch\CDSLSECUREAPP.EXE-A2EA3AF9.pf
- \WINDOWS\prefetch\CDSLSECUREAPPINSTALLER.EXE-9029306D.pf
- \WINDOWS\prefetch\CDSLSECUREAPPMAINTENANCETOOL.-583200DE.pf
- \WINDOWS\prefetch\CHROME.EXE-5A1054AF.pf
- \WINDOWS\prefetch\CHROME.EXE-5A1054B0.pf
- \WINDOWS\prefetch\CHROME.EXE-5A1054B1.pf
- \WINDOWS\prefetch\CHROME.EXE-5A1054B2.pf
- \WINDOWS\prefetch\CHROME.EXE-5A1054B3.pf
- \WINDOWS\prefetch\CHROME.EXE-5A1054B7.pf
- \WINDOWS\prefetch\CHROMENATIVEMESSAGING.EXE-E77309E8.pf
- \WINDOWS\prefetch\CLOUDNOTIFICATIONS.EXE-32AFFBA5.pf
- \WINDOWS\prefetch\CMD.EXE-4A81B364.pf
- \WINDOWS\prefetch\CMD.EXE-AC113AA8.pf
- \WINDOWS\prefetch\CODESETUP-STABLE-97DEC172D325-5EA223CC.pf
- \WINDOWS\prefetch\CONHOST.EXE-1F3E9D7E.pf
- \WINDOWS\prefetch\CONSENT.EXE-531BD9EA.pf
- \WINDOWS\prefetch\CSRSS.EXE-3FE41F7E.pf
- \WINDOWS\prefetch\CTFMON.EXE-9450846B.pf
- \WINDOWS\prefetch\DCOMCNFG.EXE-BA37D09D.pf
- \WINDOWS\prefetch\DFSVC.EXE-3D1775F1.pf
- \WINDOWS\prefetch\DLLHOST.EXE-041F1888.pf
- \WINDOWS\prefetch\DLLHOST.EXE-0AD6AC16.pf
- \WINDOWS\prefetch\DLLHOST.EXE-1E749759.pf
- \WINDOWS\prefetch\DLLHOST.EXE-2E884D3E.pf
- \WINDOWS\prefetch\DLLHOST.EXE-5A984E5F.pf
- \WINDOWS\prefetch\DLLHOST.EXE-88F23425.pf
- \WINDOWS\prefetch\DLLHOST.EXE-9037274D.pf
- \WINDOWS\prefetch\DLLHOST.EXE-B9B46003.pf
- \WINDOWS\prefetch\DLLHOST.EXE-F1C96DE4.pf
- \WINDOWS\prefetch\DLLHOST.EXE-FB0FFB65.pf
- \WINDOWS\prefetch\DOTNET.EXE-929FC1A1.pf
- \WINDOWS\prefetch\DOTNETFX40_FULL_X86_X64.EXE-C260ABFC.pf
- \WINDOWS\prefetch\DWM.EXE-6FFD3DA8.pf
- \WINDOWS\prefetch\E2OPENCLICKONCEHELPER.EXE-DA4B2C32.pf
- \WINDOWS\prefetch\ELEVATION_SERVICE.EXE-11F33CDC.pf
- \WINDOWS\prefetch\ELEVATION_SERVICE.EXE-592562E3.pf
- \WINDOWS\prefetch\ELEVATION_SERVICE.EXE-92178B98.pf
- \WINDOWS\prefetch\EXCEL.EXE-E0855370.pf
- \WINDOWS\prefetch\EXPLORER.EXE-A80E4F97.pf
- \WINDOWS\prefetch\FFMPEG.EXE-CB53BC5B.pf
- \WINDOWS\prefetch\FFMPEG.EXE-F0F8BF80.pf
- \WINDOWS\prefetch\FILECOAUTH.EXE-0FDAB899.pf
- \WINDOWS\prefetch\FILECOAUTH.EXE-705A0515.pf
- \WINDOWS\prefetch\FILECOAUTH.EXE-E4506E14.pf
- \WINDOWS\prefetch\FILECOAUTH.EXE-E9C683EA.pf
- \WINDOWS\prefetch\FILESYNCCONFIG.EXE-4E7D3B65.pf
- \WINDOWS\prefetch\FILESYNCCONFIG.EXE-55302AED.pf
- \WINDOWS\prefetch\FILESYNCCONFIG.EXE-86C6B7B8.pf
- \WINDOWS\prefetch\FILESYNCCONFIG.EXE-E667E3A8.pf
- \WINDOWS\prefetch\FIREFOX INSTALLER.EXE-4CB9BBF3.pf
- \WINDOWS\prefetch\FIREFOX INSTALLER.EXE-F66B8DC5.pf
- \WINDOWS\prefetch\FIREFOX SETUP 62.0.3.EXE-CC25BB9B.pf
- \WINDOWS\prefetch\FIREFOX.EXE-A606B53C.pf
- \WINDOWS\prefetch\FIREFOX.EXE-A606B53D.pf
- \WINDOWS\prefetch\FIREFOX.EXE-A606B541.pf
- \WINDOWS\prefetch\FONTDRVHOST.EXE-31E45F6D.pf
- \WINDOWS\prefetch\FSQUIRT.EXE-BBD9646E.pf
- \WINDOWS\prefetch\GAMEBAR.EXE-81633501.pf
- \WINDOWS\prefetch\GAMEBAR.EXE-9ED2879F.pf
- \WINDOWS\prefetch\GAMEBAR.EXE-A4611E03.pf
- \WINDOWS\prefetch\GOOGLEUPDATE.EXE-940F89F2.pf
- \WINDOWS\prefetch\GUP.EXE-033D0AF7.pf
- \WINDOWS\prefetch\IEXPLORE.EXE-4B6C9215.pf
- \WINDOWS\prefetch\IEXPLORE.EXE-908C99F8.pf
- \WINDOWS\prefetch\INJECTOR_X64.EXE-F6A58070.pf
- \WINDOWS\prefetch\INSTALLER.EXE-4F64A7B1.pf
- \WINDOWS\prefetch\KLCSLDCL.EXE-7E64952A.pf
- \WINDOWS\prefetch\KLNAGENT.EXE-05A890AA.pf
- \WINDOWS\prefetch\KLRBTAGT.EXE-B58B9E62.pf
- \WINDOWS\prefetch\KLSCFLAG.EXE-FCCB14B1.pf
- \WINDOWS\prefetch\KLSHWMSG.EXE-15D6FFE6.pf
- \WINDOWS\prefetch\KSNPROXY.EXE-2C24AEE4.pf
- \WINDOWS\prefetch\LOGONUI.EXE-09140401.pf
- \WINDOWS\prefetch\M4CLICKONCEHELPER.EXE-34DCF333.pf
- \WINDOWS\prefetch\M4CLICKONCEHELPER.EXE-672EC55A.pf
- \WINDOWS\prefetch\MAKECAB.EXE-0F1704A4.pf
- \WINDOWS\prefetch\MANAGE-BDE.EXE-37A0B125.pf
- \WINDOWS\prefetch\MICROSOFT.NOTES.EXE-9EB27B95.pf
- \WINDOWS\prefetch\MICROSOFT.PHOTOS.EXE-F2E34A5F.pf
- \WINDOWS\prefetch\MMC.EXE-381384EF.pf
- \WINDOWS\prefetch\MMC.EXE-667E9CA3.pf
- \WINDOWS\prefetch\MMC.EXE-7FBB0956.pf
- \WINDOWS\prefetch\MMC.EXE-CAB79805.pf
- \WINDOWS\prefetch\MMC.EXE-CDBE5CC0.pf
- \WINDOWS\prefetch\MMC.EXE-DF337A6C.pf
- \WINDOWS\prefetch\MMC.EXE-F4299786.pf
- \WINDOWS\prefetch\MOUSOCOREWORKER.EXE-681A8FEE.pf
- \WINDOWS\prefetch\MPCMDRUN.EXE-2B018492.pf
- \WINDOWS\prefetch\MSEDGE.EXE-5FEA7C53.pf
- \WINDOWS\prefetch\MSEDGE.EXE-78F14B8A.pf
- \WINDOWS\prefetch\MSEDGE.EXE-D411B376.pf
- \WINDOWS\prefetch\MSIEXEC.EXE-A2D55CB6.pf
- \WINDOWS\prefetch\MSIEXEC.EXE-E09A077A.pf
- \WINDOWS\prefetch\NETSH.EXE-F1B6DA12.pf
- \WINDOWS\prefetch\NETSTAT.EXE-5A5A908F.pf
- \WINDOWS\prefetch\NGENTASK.EXE-BB7F7010.pf
- \WINDOWS\prefetch\NOTEPAD++.EXE-76BDBB33.pf
- \WINDOWS\prefetch\NOTEPAD.EXE-D8414F97.pf
- \WINDOWS\prefetch\NPP.6.9.INSTALLER.EXE-BC32180C.pf
- \WINDOWS\prefetch\OLKFULLTRUSTEXECUTOR.EXE-ED12CC9C.pf
- \WINDOWS\prefetch\ONEDRIVE.EXE-0C9976D8.pf
- \WINDOWS\prefetch\ONEDRIVE.EXE-483E25DF.pf
- \WINDOWS\prefetch\ONEDRIVE.EXE-EA0F5C7A.pf
- \WINDOWS\prefetch\ONEDRIVE.SYNC.SERVICE.EXE-1CC3967F.pf
- \WINDOWS\prefetch\ONEDRIVE.SYNC.SERVICE.EXE-34F67E7C.pf
- \WINDOWS\prefetch\ONEDRIVESETUP.EXE-36291420.pf
- \WINDOWS\prefetch\ONEDRIVESETUP.EXE-53DBE06F.pf
- \WINDOWS\prefetch\ONEDRIVESETUP.EXE-ADFC0EFD.pf
- \WINDOWS\prefetch\Op-EXPLORER.EXE-A80E4F97-000000F5.pf
- \WINDOWS\prefetch\Op-MSEDGE.EXE-78F14B85-00000001.pf
- \WINDOWS\prefetch\Op-SEARCHAPP.EXE-0F10B1A6-00000002.pf
- \WINDOWS\prefetch\OPENWITH.EXE-5C93E816.pf
- \WINDOWS\prefetch\OPTIONALFEATURES.EXE-27133C71.pf
- \WINDOWS\prefetch\PHONEEXPERIENCEHOST.EXE-018D962A.pf
- \WINDOWS\prefetch\PILOTSHUBAPP.EXE-6594B37F.pf
- \WINDOWS\prefetch\POWERSHELL.EXE-920BBA2A.pf
- \WINDOWS\prefetch\QTWEBENGINEPROCESS.EXE-A871F32C.pf
- \WINDOWS\prefetch\RDPCLIP.EXE-9067FA0E.pf
- \WINDOWS\prefetch\REGEDIT.EXE-90FEEA06.pf
- \WINDOWS\prefetch\REPORTS.EXE-593E9B72.pf
- \WINDOWS\prefetch\REPORTSDOWNLOAD.EXE-09F68180.pf
- \WINDOWS\prefetch\REPORTSDOWNLOAD.EXE-0F78EDAC.pf
- \WINDOWS\prefetch\REPORTSDOWNLOAD.EXE-209B8B08.pf
- \WINDOWS\prefetch\REPORTSDOWNLOAD.EXE-2124C708.pf
- \WINDOWS\prefetch\REPORTSDOWNLOAD.EXE-39E1E99A.pf
- \WINDOWS\prefetch\REPORTSDOWNLOAD.EXE-85014B43.pf
- \WINDOWS\prefetch\REPORTSDOWNLOAD.EXE-C67C42F7.pf
- \WINDOWS\prefetch\REPORTSDOWNLOAD.EXE-CC5F6247.pf
- \WINDOWS\prefetch\REPORTSDOWNLOAD.EXE-CED1878D.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-01F3F290.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-022FEC8C.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-034BCE46.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-035AF558.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-03C2DCDB.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-04B222A3.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-0550210E.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-05A7E950.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-060DBE19.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-063696FB.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-073BF7C1.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-078C1F1B.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-07BA29ED.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-089B6685.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-08A3B501.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-09D8F936.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-0A23FAC2.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-0B47432B.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-0B69E33C.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-0BCD3E86.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-0C97E2F8.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-0C9C1A63.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-0CE07A35.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-0CEAE8AC.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-0D54104E.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-0DB21C7A.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-0EBE8777.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-0F93B14E.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-0F95F3EE.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-0FC94AB2.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-105196BA.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-106C42C6.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-1099BD53.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-117A19F4.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-12091DD4.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-123BF8EE.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-13734F4F.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-139B07C5.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-13EE39E3.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-16C04B1B.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-179F8367.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-18832387.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-18ED54F9.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-1B438E95.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-1C0A2D83.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-1DD21B97.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-1EF2688A.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-1F420A1E.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-1F923C4F.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-1FCB8302.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-1FF2193E.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-20230491.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-2041D103.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-208CF7B6.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-214FA1E0.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-21D5D633.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-2206609E.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-2293B357.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-22AB26A7.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-2306E369.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-2345380F.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-23B211D0.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-23EA2E5B.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-2412CDA1.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-24324F90.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-26609BD7.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-270ACAA1.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-2766F4D6.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-27C7E41B.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-293CE51E.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-29A13386.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-29DB2A11.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-2A83595D.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-2B9AB938.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-2C59A7EE.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-2CE7CA5C.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-2CF8639D.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-2D1EFC42.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-2D9955B1.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-2E2C87AA.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-2E903238.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-2EC7CAD7.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-2FBCA1FA.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-30797366.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-30819CDA.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-3146968A.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-3259C236.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-330110BF.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-331CB80F.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-33CB8542.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-33D0A0C4.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-33F1A43A.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-34288323.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-342F9F7D.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-3584D771.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-35CB0B2F.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-36494CFC.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-374E2B28.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-379B2E9D.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-37B945C1.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-37D0C5BC.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-380F5B37.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-3819AB79.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-385AD0EC.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-38A38FDA.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-38C35E31.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-395104AF.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-397A02D3.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-3ABAE597.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-3AE123C2.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-3C094D7C.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-3C284753.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-3D1C115A.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-3DA0A8AD.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-3E306C54.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-3EB89530.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-3F4A6783.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-3F9EC9A5.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-3FD24A10.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-401B9D84.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-41B377A3.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-4242FD70.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-42AFC942.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-430C0988.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-43286120.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-435F3072.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-4367CEAE.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-43766D36.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-44A19A6B.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-44AB6480.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-45F51341.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-467448AC.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-4793CB16.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-4810DADC.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-482650FE.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-48603916.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-48D3AEE6.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-494E272A.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-49689E9D.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-4AEC4558.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-4B34EB5B.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-4BA100E8.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-4C35D5B0.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-4C5C688C.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-4C5EFF68.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-4D090368.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-4D897CC8.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-4D8E7019.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-4DDF80E2.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-4EDBCE3F.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-4FE23DB2.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-50ABF942.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-517D50E5.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-52A1607F.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-5350A257.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-54361BAA.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-548C4699.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-54ACDB8A.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-5627F023.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-564FB326.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-56AF8386.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-56FAD0F6.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-57331D94.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-57865F2E.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-57A9C445.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-581448CA.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-5821D41A.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-58E33AA9.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-591E28FA.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-596D12BA.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-59C3761E.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-59EF50CE.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-5A0BCBE1.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-5A5822DE.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-5B078BEE.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-5B1CE9F5.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-5B2DDC0E.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-5B61F630.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-5B78C8C2.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-5DA8363B.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-5E0AD4CD.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-5E964037.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-5EF31873.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-5F5FFDA8.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-5F6EB3F1.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-6062E082.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-6080F3A5.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-60956B6D.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-60E4219F.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-61B54C38.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-62202552.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-6226A773.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-626409B2.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-6296ED35.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-62F1FDD7.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-62FC0682.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-632FC0AA.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-63853EE9.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-6552E9FE.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-65CCC3AE.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-666D52E1.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-668A7729.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-668C723E.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-67274167.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-67C32CB0.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-68B3AEBB.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-69BDAA5C.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-69C0E91B.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-69E52150.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-6AA33EE6.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-6AE09815.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-6B541B13.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-6B59D56E.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-6B712DF8.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-6B739E8F.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-6BF1CC54.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-6C301CC4.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-6C32B91D.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-6DAEA853.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-6DE8A4FB.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-6DF9870D.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-6E5E2CDA.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-6E62CF2F.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-6E667836.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-6E9D130A.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-6EAF8C14.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-6EC14FA9.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-6EE6268D.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-6F264BBA.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-6F6A9A8B.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-6FC9319F.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-70A6EBB1.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-71A2A24D.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-71A5E848.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-71AD62F5.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-72A63B87.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-72D1BC18.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-731CB47C.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-732A8583.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-7347EF63.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-734FD7EB.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-737EFC63.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-7403BC4C.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-74895A9E.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-74DA0DF8.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-76202122.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-76677553.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-766B1017.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-774DA092.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-77C72750.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-7892E15F.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-7AA9BB7D.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-7B90926C.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-7BE3DF2D.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-7C02B56F.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-7C9D857F.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-7CC6EC80.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-7CFE3469.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-7D34FDFC.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-7D7F69AF.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-7E045122.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-7EB200B1.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-7EC62B69.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-7F76149E.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-801DFC6D.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-8098A33F.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-80ADA3E9.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-80F78575.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-8183F8F7.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-82C6625A.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-82DFB812.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-83221761.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-83CC128A.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-83D52C6F.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-850B32B6.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-853D2E1E.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-85C6D7DF.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-86121542.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-86255528.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-8681D95C.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-883CDFE5.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-892197D1.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-8ADEF0A4.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-8AF96143.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-8B594CE0.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-8B6F5779.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-8C1228AC.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-8C2E5BF9.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-8D0F3040.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-8D7B9272.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-8DEA0FE5.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-8F21587B.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-900892FB.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-90B2E374.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-90FC6FF6.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-9283CB19.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-92B77C95.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-936A5A5C.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-93947498.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-94218DE2.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-94F01B7E.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-958E0F05.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-96502513.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-96B18951.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-97225921.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-972D40FB.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-97F5C61F.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-986C73DB.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-989F5C2F.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-98CF8630.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-98EB4DA0.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-9991FB13.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-9AB82FBA.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-9C5C6509.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-9D4F27C9.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-9E37FE76.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-9E5ECA39.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-9EA6B834.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-9F29CE69.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-9F31810A.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-9F944429.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-9F96B581.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-9FBD0CD7.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-A10DD873.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-A2173BFB.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-A3687A20.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-A4A659F3.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-A616F67F.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-A6483C75.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-A64DDC5C.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-A732109A.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-A949F57B.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-A9B27CE8.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-AA328B67.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-AA4DA8F5.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-AB2CDF6D.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-AB7E4843.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-ABE8AC05.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-ABF94523.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-ACB3083B.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-AE3649B7.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-AED3AF69.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-AF187C33.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-AF5470C7.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-AF5F3AB0.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-B028958D.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-B052204A.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-B0BF9019.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-B15EC316.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-B1E578F6.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-B209912E.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-B2406FB1.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-B26465CA.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-B266F2F2.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-B36490CF.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-B3EFC756.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-B3FD0910.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-B428F705.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-B4B198D3.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-B4DD52B8.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-B56907D4.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-B62AEEF0.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-B6692CBA.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-B7C02D32.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-B8024A8B.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-B80A85F4.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-B876EC59.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-BB4CB3EE.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-BB52BA33.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-BB6392EF.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-BBA1B3AB.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-BBA6D04C.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-BBBC9C13.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-BDB13F0D.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-BDD21E10.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-BE166857.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-BF0D1720.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-BF13FC68.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-BF89C7FE.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-BFA7FCF5.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-BFC0058B.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-C059E28A.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-C0C3D3F6.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-C157BDC5.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-C3A8FA02.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-C404F385.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-C52CF41E.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-C5E37FF9.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-C5E780FF.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-C7038832.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-C73E40A5.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-C75289ED.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-C7A6B39D.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-C7A8DA1A.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-C81135BE.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-C89947EC.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-C99E28B3.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-C9E77527.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-CA8AE0EF.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-CAB42518.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-CB5D9AFF.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-CBD5B04F.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-CDE3BCE5.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-CE21EB5E.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-CE77FF85.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-CF6ABD64.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-D05243DB.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-D0B281C6.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-D0B4E0D7.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-D0EEDAE4.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-D122367C.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-D1454347.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-D1700CA1.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-D1C854FD.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-D2CB619E.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-D30080A4.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-D37F209F.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-D3F51D7F.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-D42AED19.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-D535F5C4.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-D5FADAD2.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-D6848CD0.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-D6956DFC.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-D695E017.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-D7565CD8.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-D7B97B6B.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-D7F34F97.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-D84B9F54.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-D897DF25.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-D8B55B4A.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-DA0C6CAF.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-DA932A02.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-DB18ED01.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-DB85E0E0.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-DBC38760.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-DBE60EBD.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-DF6E8D0B.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-DFAAB5E3.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-DFAF5DF1.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-E0FEE840.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-E14BE932.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-E29DF4A2.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-E2A8C096.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-E2C8C7F7.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-E34FF549.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-E3CF788F.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-E3FCAC99.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-E4669604.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-E54ADE66.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-E61B19E7.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-E7237F5D.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-E82EBC7B.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-E903BBE9.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-E99F44A8.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-E9F52A9E.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-EA9D74AD.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-EAB47548.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-EAF89A0A.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-EB94CCA0.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-EBC6D305.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-EBF4DBD4.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-EC233EE5.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-EC752309.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-ECD2B585.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-ECE31B9F.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-ED6E5EF2.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-ED71B0C1.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-EDFECD6F.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-EE74F1C7.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-F090FC93.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-F2EFB41A.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-F34EFF10.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-F47ED10E.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-F56F3DD2.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-F69E8D25.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-F6BA2C27.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-F6CFD3C7.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-F70098E5.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-F721BA46.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-F7596A16.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-F86F0AC8.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-F9283CB8.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-F94ABBBB.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-FA1D788F.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-FA22ADDE.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-FA7641FD.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-FC1E000D.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-FCDB84DF.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-FD1088EC.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-FD204EFE.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-FD3E8BC5.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-FD4BBD71.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-FDD5B80E.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-FE53D0C7.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-FE577E7A.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-FE674671.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-FE7398AA.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-FEC43189.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-FEE9D07B.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-FF311B00.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-FF3FA5F8.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-FF57DBF7.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-FF67F6B5.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-FFA80F71.pf
- \WINDOWS\prefetch\RUNDLL32.EXE-FFBE4721.pf
- \WINDOWS\prefetch\RUNONCE.EXE-0E293DD6.pf
- \WINDOWS\prefetch\RUNTIMEBROKER.EXE-25819C5C.pf
- \WINDOWS\prefetch\RUNTIMEBROKER.EXE-32BFE2E0.pf
- \WINDOWS\prefetch\RUNTIMEBROKER.EXE-42B01191.pf
- \WINDOWS\prefetch\RUNTIMEBROKER.EXE-473FF36E.pf
- \WINDOWS\prefetch\RUNTIMEBROKER.EXE-4D685B77.pf
- \WINDOWS\prefetch\RUNTIMEBROKER.EXE-524B7FB1.pf
- \WINDOWS\prefetch\RUNTIMEBROKER.EXE-5BC1CB41.pf
- \WINDOWS\prefetch\RUNTIMEBROKER.EXE-72C0C855.pf
- \WINDOWS\prefetch\RUNTIMEBROKER.EXE-81D26DAE.pf
- \WINDOWS\prefetch\RUNTIMEBROKER.EXE-81F7ACEB.pf
- \WINDOWS\prefetch\RUNTIMEBROKER.EXE-C2227512.pf
- \WINDOWS\prefetch\RUNTIMEBROKER.EXE-E51086A0.pf
- \WINDOWS\prefetch\RUNTIMEBROKER.EXE-F4C9B956.pf
- \WINDOWS\prefetch\RUNTIMEBROKER.EXE-F8D7A95B.pf
- \WINDOWS\prefetch\SANERNOW_WINDOWS_X86_6.3.EXE-AC5CE623.pf
- \WINDOWS\prefetch\SCHTASKS.EXE-5CA45734.pf
- \WINDOWS\prefetch\SEARCHAPP.EXE-1778858F.pf
- \WINDOWS\prefetch\SEARCHAPP.EXE-46A24228.pf
- \WINDOWS\prefetch\SEARCHAPP.EXE-4F359FAD.pf
- \WINDOWS\prefetch\SEARCHAPP.EXE-95363964.pf
- \WINDOWS\prefetch\SEARCHFILTERHOST.EXE-77482212.pf
- \WINDOWS\prefetch\SEARCHPROTOCOLHOST.EXE-0CB8CADE.pf
- \WINDOWS\prefetch\SECHEALTHUI.EXE-D6B58CEB.pf
- \WINDOWS\prefetch\SECURITYHEALTHHOST.EXE-A928C304.pf
- \WINDOWS\prefetch\SECURITYHEALTHSERVICE.EXE-EE3BC4CB.pf
- \WINDOWS\prefetch\SECURITYHEALTHSYSTRAY.EXE-41AD6DE1.pf
- \WINDOWS\prefetch\SESSIONMSG.EXE-B52942BF.pf
- \WINDOWS\prefetch\SETTINGSYNCHOST.EXE-2521C7ED.pf
- \WINDOWS\prefetch\SETUP.EXE-03072343.pf
- \WINDOWS\prefetch\SETUP.EXE-10E8CF06.pf
- \WINDOWS\prefetch\SETUP.EXE-10E8CF0A.pf
- \WINDOWS\prefetch\SETUP.EXE-197BD465.pf
- \WINDOWS\prefetch\SETUP.EXE-3E0EB7F8.pf
- \WINDOWS\prefetch\SETUP.EXE-7C941064.pf
- \WINDOWS\prefetch\SETUP.EXE-7C941068.pf
- \WINDOWS\prefetch\SETUP.EXE-C147F6A1.pf
- \WINDOWS\prefetch\SETUP.EXE-C435A5B8.pf
- \WINDOWS\prefetch\SETUP.EXE-C435A5BC.pf
- \WINDOWS\prefetch\SETUP.EXE-D5138034.pf
- \WINDOWS\prefetch\SETUP.EXE-D5138038.pf
- \WINDOWS\prefetch\SHELLEXPERIENCEHOST.EXE-23D7A593.pf
- \WINDOWS\prefetch\SHELLEXPERIENCEHOST.EXE-63F4127E.pf
- \WINDOWS\prefetch\SHELLEXPERIENCEHOST.EXE-8818CC2E.pf
- \WINDOWS\prefetch\SHELLEXPERIENCEHOST.EXE-A0A2DEC2.pf
- \WINDOWS\prefetch\SHELLEXPERIENCEHOST.EXE-EF3EE583.pf
- \WINDOWS\prefetch\SIHCLIENT.EXE-A872A8BF.pf
- \WINDOWS\prefetch\SIHOST.EXE-2C4C53BA.pf
- \WINDOWS\prefetch\SMARTSCREEN.EXE-9B5E4173.pf
- \WINDOWS\prefetch\SMSS.EXE-E9C28FC6.pf
- \WINDOWS\prefetch\SPFILEINDEXER.EXE-CA6DCA16.pf
- \WINDOWS\prefetch\SPPEXTCOMOBJ.EXE-BB03B3D6.pf
- \WINDOWS\prefetch\SPPSVC.EXE-B0F8131B.pf
- \WINDOWS\prefetch\SSMS.EXE-BC263518.pf
- \WINDOWS\prefetch\STARTMENUEXPERIENCEHOST.EXE-865C418A.pf
- \WINDOWS\prefetch\STARTMENUEXPERIENCEHOST.EXE-D80E778C.pf
- \WINDOWS\prefetch\SVCHOST.EXE-04BDDB9C.pf
- \WINDOWS\prefetch\SVCHOST.EXE-0C2D202C.pf
- \WINDOWS\prefetch\SVCHOST.EXE-0D126A9F.pf
- \WINDOWS\prefetch\SVCHOST.EXE-0E4FE292.pf
- \WINDOWS\prefetch\SVCHOST.EXE-0F2113E4.pf
- \WINDOWS\prefetch\SVCHOST.EXE-24568AC4.pf
- \WINDOWS\prefetch\SVCHOST.EXE-262D494C.pf
- \WINDOWS\prefetch\SVCHOST.EXE-2C8F9E34.pf
- \WINDOWS\prefetch\SVCHOST.EXE-2FA0E8A6.pf
- \WINDOWS\prefetch\SVCHOST.EXE-4AB5FCB7.pf
- \WINDOWS\prefetch\SVCHOST.EXE-5E731DE3.pf
- \WINDOWS\prefetch\SVCHOST.EXE-5EAAEC8A.pf
- \WINDOWS\prefetch\SVCHOST.EXE-62975899.pf
- \WINDOWS\prefetch\SVCHOST.EXE-6C525542.pf
- \WINDOWS\prefetch\SVCHOST.EXE-6CAF587C.pf
- \WINDOWS\prefetch\SVCHOST.EXE-7B41F868.pf
- \WINDOWS\prefetch\SVCHOST.EXE-84ADBFA7.pf
- \WINDOWS\prefetch\SVCHOST.EXE-868216AE.pf
- \WINDOWS\prefetch\SVCHOST.EXE-86AA6B35.pf
- \WINDOWS\prefetch\SVCHOST.EXE-8929E8DF.pf
- \WINDOWS\prefetch\SVCHOST.EXE-8D87DCC8.pf
- \WINDOWS\prefetch\SVCHOST.EXE-97CD69B8.pf
- \WINDOWS\prefetch\SVCHOST.EXE-98090C0A.pf
- \WINDOWS\prefetch\SVCHOST.EXE-A8007E45.pf
- \WINDOWS\prefetch\SVCHOST.EXE-AD0331FB.pf
- \WINDOWS\prefetch\SVCHOST.EXE-AFDE613F.pf
- \WINDOWS\prefetch\SVCHOST.EXE-B4F4C581.pf
- \WINDOWS\prefetch\SVCHOST.EXE-BA748B25.pf
- \WINDOWS\prefetch\SVCHOST.EXE-D5B495F2.pf
- \WINDOWS\prefetch\SVCHOST.EXE-D6693F60.pf
- \WINDOWS\prefetch\SVCHOST.EXE-D8FFFCDA.pf
- \WINDOWS\prefetch\SVCHOST.EXE-E8225EF5.pf
- \WINDOWS\prefetch\SVCHOST.EXE-EBA34E64.pf
- \WINDOWS\prefetch\SVCHOST.EXE-F0CB7C91.pf
- \WINDOWS\prefetch\SVCHOST.EXE-FB615678.pf
- \WINDOWS\prefetch\SYSTEMPROPERTIESADVANCED.EXE-68C7C4F0.pf
- \WINDOWS\prefetch\SYSTEMSETTINGS.EXE-01D72268.pf
- \WINDOWS\prefetch\SYSTEMSETTINGSADMINFLOWS.EXE-389031F2.pf
- \WINDOWS\prefetch\TASKHOSTW.EXE-3E0B74C8.pf
- \WINDOWS\prefetch\TASKLIST.EXE-C6CEE193.pf
- \WINDOWS\prefetch\TASKMGR.EXE-5F5F473D.pf
- \WINDOWS\prefetch\TEXTINPUTHOST.EXE-1557F467.pf
- \WINDOWS\prefetch\TEXTINPUTHOST.EXE-34D0F476.pf
- \WINDOWS\prefetch\TEXTINPUTHOST.EXE-E14D757C.pf
- \WINDOWS\prefetch\TEXTINPUTHOST.EXE-F963AD44.pf
- \WINDOWS\prefetch\TEXTINPUTHOST.EXE-FD41BC9F.pf
- \WINDOWS\prefetch\TIWORKER.EXE-8755861B.pf
- \WINDOWS\prefetch\TREESIZEFREE.EXE-CBDF8646.pf
- \WINDOWS\prefetch\TREESIZEFREESETUP.TMP-D1F718AB.pf
- \WINDOWS\prefetch\TRUSTEDINSTALLER.EXE-3CC531E5.pf
- \WINDOWS\prefetch\TSTHEME.EXE-14AC78EA.pf
- \WINDOWS\prefetch\TVNSERVER.EXE-2FBEBBEC.pf
- \WINDOWS\prefetch\UIEXPLORER.EXE-4058E152.pf
- \WINDOWS\prefetch\UIEXPLORER.EXE-83A24B6B.pf
- \WINDOWS\prefetch\UIEXPLORER.EXE-FBE7C6BB.pf
- \WINDOWS\prefetch\UIPATH.ASSISTANT.EXE-4E0B9827.pf
- \WINDOWS\prefetch\UIPATH.ASSISTANT.EXE-4E0B9828.pf
- \WINDOWS\prefetch\UIPATH.ASSISTANT.EXE-4E0B9829.pf
- \WINDOWS\prefetch\UIPATH.ASSISTANT.EXE-4E0B982A.pf
- \WINDOWS\prefetch\UIPATH.ASSISTANT.EXE-4E0B982F.pf
- \WINDOWS\prefetch\UIPATH.BROWSERBRIDGE.PORTABLE-C0E52F6F.pf
- \WINDOWS\prefetch\UIPATH.EXECUTOR.EXE-92F94F03.pf
- \WINDOWS\prefetch\UIPATH.MICROSOFTOFFICE.TOOLS.-C3FC8D86.pf
- \WINDOWS\prefetch\UIPATH.SERVICE.USERHOST.EXE-BAA4A794.pf
- \WINDOWS\prefetch\UIPATH.STUDIO.EXE-4E4412F8.pf
- \WINDOWS\prefetch\UIPATH.STUDIO.EXE-C2B46EEE.pf
- \WINDOWS\prefetch\UIPATH.STUDIO.PROJECT.EXE-A4FB65E7.pf
- \WINDOWS\prefetch\UIPATH.STUDIO.PROJECT.EXE-A9F482B9.pf
- \WINDOWS\prefetch\UIPATH.STUDIO.UPDATEMONITOR.E-ABFD1243.pf
- \WINDOWS\prefetch\UIPATH.VISION.HOST.EXE-78CBC489.pf
- \WINDOWS\prefetch\UNSECAPP.EXE-A02905A6.pf
- \WINDOWS\prefetch\UN_A.EXE-2270A34C.pf
- \WINDOWS\prefetch\UP2DATE.EXE-DB2AD41F.pf
- \WINDOWS\prefetch\UPDATE.EXE-53AF2DBD.pf
- \WINDOWS\prefetch\UPDATER.EXE-C41BD367.pf
- \WINDOWS\prefetch\UPFC.EXE-BDDF79D6.pf
- \WINDOWS\prefetch\USEROOBEBROKER.EXE-D2992F42.pf
- \WINDOWS\prefetch\VAPM.EXE-5B938E8A.pf
- \WINDOWS\prefetch\VCREDIST.EXE-BC035AB2.pf
- \WINDOWS\prefetch\VCREDIST_X86.EXE-0D0919F8.pf
- \WINDOWS\prefetch\VCREDIST_X86.EXE-E52FDB13.pf
- \WINDOWS\prefetch\VC_REDIST.X64.EXE-5411C114.pf
- \WINDOWS\prefetch\VC_REDIST.X86.EXE-B5FDBB27.pf
- \WINDOWS\prefetch\VIDEO.UI.EXE-AFCA0C73.pf
- \WINDOWS\prefetch\VM3DSERVICE.EXE-AA69D4F7.pf
- \WINDOWS\prefetch\VMTOOLSD.EXE-CD82EC13.pf
- \WINDOWS\prefetch\VSSVC.EXE-B8AFC319.pf
- \WINDOWS\prefetch\WAB.EXE-8608506E.pf
- \WINDOWS\prefetch\WEBVIEWHOST.EXE-EC271199.pf
- \WINDOWS\prefetch\WINLOGON.EXE-B020DC41.pf
- \WINDOWS\prefetch\WINRAR.EXE-94E7D80C.pf
- \WINDOWS\prefetch\WINSAT.EXE-DE36CB46.pf
- \WINDOWS\prefetch\WINVER.EXE-D053C8CF.pf
- \WINDOWS\prefetch\WINWORD.EXE-2607D2B5.pf
- \WINDOWS\prefetch\WKHTMLTOX-0.11.0_RC1-INSTALLE-AC1BD0DC.pf
- \WINDOWS\prefetch\WKHTMLTOX-0.12.2.1_MSVC2013-W-6FFD7CD5.pf
- \WINDOWS\prefetch\WLRMDR.EXE-C2B47318.pf
- \WINDOWS\prefetch\WMIADAP.EXE-F8DFDFA2.pf
- \WINDOWS\prefetch\WMIAPSRV.EXE-29F35ED0.pf
- \WINDOWS\prefetch\WMIPRVSE.EXE-1628051C.pf
- \WINDOWS\prefetch\WMIPRVSE.EXE-6768A320.pf
- \WINDOWS\prefetch\WSCRIPT.EXE-52CF1F0C.pf
- \WINDOWS\prefetch\WUAUCLT.EXE-70318591.pf
- \WINDOWS\prefetch\WUDFHOST.EXE-AFFEF87C.pf
- \WINDOWS\prefetch\WWAHOST.EXE-8655EF97.pf

63620 - Windows Product Key Retrieval
-
Synopsis
This plugin retrieves the Windows Product key of the remote Windows host.
Description
Using the supplied credentials, Nessus was able to obtain the retrieve the Windows host's partial product key'.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/01/18, Modified: 2013/01/18
Plugin Output

tcp/445/cifs


Product key : XXXXX-XXXXX-XXXXX-XXXXX-27JXM

Note that all but the final portion of the key has been obfuscated.
160576 - Windows Services Registry ACL
-
Synopsis
Checks Windows Registry for Service ACLs
Description
Checks Windows Registry for Service ACLs.
Solution
N/A
Risk Factor
None
Plugin Information
Published: 2022/05/05, Modified: 2024/01/15
Plugin Output

tcp/445/cifs

report output too big - ending list here

85736 - Windows Store Application Enumeration
-
Synopsis
It is possible to obtain the list of applications installed from the Windows Store.
Description
This plugin connects to the remote Windows host with the supplied credentials and uses WMI and Powershell to enumerate applications installed on the host from the Windows Store.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2015/09/02, Modified: 2025/12/15
Plugin Output

tcp/0


-1527c705-839a-4832-9118-54d4Bd6a0c89
Version : 10.0.18362.449
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.FilePicker_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-c5e2524a-ea46-4f67-841f-6a9465d9d515
Version : 10.0.18362.449
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.FileExplorer_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-E2A4F912-2574-4A75-9BB0-0D023378592B
Version : 10.0.18362.449
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.AppResolverUX_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-F46D4000-FD22-4DB4-AC8E-4E1DDDE828FE
Version : 10.0.18362.449
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.AddSuggestedFoldersToLibraryDialog_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.AccountsControl
Version : 10.0.18362.449
InstallLocation : C:\Windows\SystemApps\Microsoft.AccountsControl_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.AsyncTextService
Version : 10.0.18362.449
InstallLocation : C:\Windows\SystemApps\Microsoft.AsyncTextService_8wekyb3d8bbwe
Architecture : Neutral
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.CredDialogHost
Version : 10.0.18362.449
InstallLocation : C:\Windows\SystemApps\microsoft.creddialoghost_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.ECApp
Version : 10.0.18362.449
InstallLocation : C:\Windows\SystemApps\Microsoft.ECApp_8wekyb3d8bbwe
Architecture : Neutral
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.LockApp
Version : 10.0.18362.449
InstallLocation : C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Win32WebViewHost
Version : 10.0.18362.449
InstallLocation : C:\Windows\SystemApps\Microsoft.Win32WebViewHost_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.CapturePicker
Version : 10.0.18362.449
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.CapturePicker_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.NarratorQuickStart
Version : 10.0.18362.449
InstallLocation : C:\Windows\SystemApps\microsoft.windows.narratorquickstart_8wekyb3d8bbwe
Architecture : Neutral
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.PeopleExperienceHost
Version : 10.0.18362.449
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.SecHealthUI
Version : 10.0.18362.449
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.SecureAssessmentBrowser
Version : 10.0.18362.449
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.XGpuEjectDialog
Version : 10.0.18362.449
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Windows.CBSPreview
Version : 10.0.18362.449
InstallLocation : C:\Windows\SystemApps\Windows.CBSPreview_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-windows.immersivecontrolpanel
Version : 10.0.2.1000
InstallLocation : C:\Windows\ImmersiveControlPanel
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Windows.PrintDialog
Version : 6.2.1.0
InstallLocation : C:\Windows\PrintDialog
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Services.Store.Engagement
Version : 10.0.18101.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.Services.Store.Engagement_10.0.18101.0_x86__8wekyb3d8bbwe
Architecture : X86
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Services.Store.Engagement
Version : 10.0.18101.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.Services.Store.Engagement_10.0.18101.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.VCLibs.140.00
Version : 14.0.26706.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.26706.0_x86__8wekyb3d8bbwe
Architecture : X86
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.NET.Native.Runtime.1.7
Version : 1.7.25531.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.NET.Native.Runtime.1.7_1.7.25531.0_x86__8wekyb3d8bbwe
Architecture : X86
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.NET.Native.Framework.1.7
Version : 1.7.25531.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.NET.Native.Framework.1.7_1.7.25531.0_x86__8wekyb3d8bbwe
Architecture : X86
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.UI.Xaml.2.0
Version : 2.1810.18004.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.UI.Xaml.2.0_2.1810.18004.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.NET.Native.Runtime.1.7
Version : 1.7.25531.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.NET.Native.Runtime.1.7_1.7.25531.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.NET.Native.Framework.1.7
Version : 1.7.25531.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.NET.Native.Framework.1.7_1.7.25531.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Advertising.Xaml
Version : 10.1808.3.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1808.3.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Print3D
Version : 3.3.311.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.Print3D_3.3.311.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Wallet
Version : 2.4.18324.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.Wallet_2.4.18324.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Xbox.TCUI
Version : 1.23.28002.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.Xbox.TCUI_1.23.28002.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.XboxSpeechToTextOverlay
Version : 1.17.29001.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.XboxSpeechToTextOverlay_1.17.29001.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-1527c705-839a-4832-9118-54d4Bd6a0c89
Version : 10.0.19041.1023
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.FilePicker_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-c5e2524a-ea46-4f67-841f-6a9465d9d515
Version : 10.0.19041.1503
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.FileExplorer_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-E2A4F912-2574-4A75-9BB0-0D023378592B
Version : 10.0.19041.1023
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.AppResolverUX_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-F46D4000-FD22-4DB4-AC8E-4E1DDDE828FE
Version : 10.0.19041.1023
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.AddSuggestedFoldersToLibraryDialog_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.AAD.BrokerPlugin
Version : 1000.19041.1023.0
InstallLocation : C:\Windows\SystemApps\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.AccountsControl
Version : 10.0.19041.1023
InstallLocation : C:\Windows\SystemApps\Microsoft.AccountsControl_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.AsyncTextService
Version : 10.0.19041.1023
InstallLocation : C:\Windows\SystemApps\Microsoft.AsyncTextService_8wekyb3d8bbwe
Architecture : Neutral
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.BioEnrollment
Version : 10.0.19041.1023
InstallLocation : C:\Windows\SystemApps\Microsoft.BioEnrollment_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.CredDialogHost
Version : 10.0.19041.1023
InstallLocation : C:\Windows\SystemApps\microsoft.creddialoghost_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.ECApp
Version : 10.0.19041.1023
InstallLocation : C:\Windows\SystemApps\Microsoft.ECApp_8wekyb3d8bbwe
Architecture : Neutral
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.LockApp
Version : 10.0.19041.1023
InstallLocation : C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.MicrosoftEdgeDevToolsClient
Version : 1000.19041.1023.0
InstallLocation : C:\Windows\SystemApps\Microsoft.MicrosoftEdgeDevToolsClient_8wekyb3d8bbwe
Architecture : Neutral
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.MicrosoftEdge
Version : 44.19041.1266.0
InstallLocation : C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe
Architecture : Neutral
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Win32WebViewHost
Version : 10.0.19041.1023
InstallLocation : C:\Windows\SystemApps\Microsoft.Win32WebViewHost_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.Apprep.ChxApp
Version : 1000.19041.1023.0
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.AssignedAccessLockApp
Version : 1000.19041.1023.0
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.AssignedAccessLockApp_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.CallingShellApp
Version : 1000.19041.1023.0
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.CallingShellApp_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.CapturePicker
Version : 10.0.19041.1023
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.CapturePicker_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.CloudExperienceHost
Version : 10.0.19041.1266
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.ContentDeliveryManager
Version : 10.0.19041.1023
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.NarratorQuickStart
Version : 10.0.19041.1023
InstallLocation : C:\Windows\SystemApps\microsoft.windows.narratorquickstart_8wekyb3d8bbwe
Architecture : Neutral
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.OOBENetworkCaptivePortal
Version : 10.0.19041.1023
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.OOBENetworkCaptivePortal_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.OOBENetworkConnectionFlow
Version : 10.0.19041.1023
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.OOBENetworkConnectionFlow_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.ParentalControls
Version : 1000.19041.1023.0
InstallLocation : C:\Windows\SystemApps\ParentalControls_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.PeopleExperienceHost
Version : 10.0.19041.1023
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.PinningConfirmationDialog
Version : 1000.19041.1023.0
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.PinningConfirmationDialog_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.Search
Version : 1.14.4.19041
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.SecHealthUI
Version : 10.0.19041.1023
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.SecureAssessmentBrowser
Version : 10.0.19041.1023
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.ShellExperienceHost
Version : 10.0.19041.1320
InstallLocation : C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.StartMenuExperienceHost
Version : 10.0.19041.1023
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.XGpuEjectDialog
Version : 10.0.19041.1023
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.XboxGameCallableUI
Version : 1000.19041.1023.0
InstallLocation : C:\Windows\SystemApps\Microsoft.XboxGameCallableUI_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-MicrosoftWindows.Client.CBS
Version : 120.2212.4170.0
InstallLocation : C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy
Architecture : X64
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-MicrosoftWindows.UndockedDevKit
Version : 10.0.19041.1023
InstallLocation : C:\Windows\SystemApps\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-NcsiUwpApp
Version : 1000.19041.1023.0
InstallLocation : C:\Windows\SystemApps\NcsiUwpApp_8wekyb3d8bbwe
Architecture : Neutral
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Windows.CBSPreview
Version : 10.0.19041.1023
InstallLocation : C:\Windows\SystemApps\Windows.CBSPreview_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.MSPaint
Version : 6.1907.29027.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.NET.Native.Framework.2.2
Version : 2.2.27405.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.NET.Native.Framework.2.2_2.2.27405.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.NET.Native.Runtime.2.2
Version : 2.2.27328.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.NET.Native.Runtime.2.2_2.2.27328.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Office.OneNote
Version : 16001.12026.20112.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.Office.OneNote_16001.12026.20112.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.VCLibs.140.00.UWPDesktop
Version : 14.0.27629.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00.UWPDesktop_14.0.27629.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.VCLibs.140.00
Version : 14.0.27323.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.WindowsSoundRecorder
Version : 10.1906.1972.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.WindowsSoundRecorder_10.1906.1972.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.MicrosoftEdge.Stable
Version : 109.0.1518.55
InstallLocation : C:\Program Files\WindowsApps\Microsoft.MicrosoftEdge.Stable_109.0.1518.55_neutral__8wekyb3d8bbwe
Architecture : Neutral
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.MicrosoftEdge.Stable
Version : 116.0.1938.76
InstallLocation : C:\Program Files\WindowsApps\Microsoft.MicrosoftEdge.Stable_116.0.1938.76_neutral__8wekyb3d8bbwe
Architecture : Neutral
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.UI.Xaml.2.3
Version : 2.32002.13001.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.UI.Xaml.2.3_2.32002.13001.0_x86__8wekyb3d8bbwe
Architecture : X86
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.UI.Xaml.2.3
Version : 2.32002.13001.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.UI.Xaml.2.3_2.32002.13001.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.NET.Native.Framework.1.7
Version : 1.7.27413.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.NET.Native.Framework.1.7_1.7.27413.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.NET.Native.Framework.1.7
Version : 1.7.27413.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.NET.Native.Framework.1.7_1.7.27413.0_x86__8wekyb3d8bbwe
Architecture : X86
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.UI.Xaml.2.0
Version : 2.1810.18004.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.UI.Xaml.2.0_2.1810.18004.0_x86__8wekyb3d8bbwe
Architecture : X86
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.NET.Native.Runtime.2.2
Version : 2.2.28604.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.NET.Native.Runtime.2.2_2.2.28604.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.NET.Native.Runtime.2.2
Version : 2.2.28604.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.NET.Native.Runtime.2.2_2.2.28604.0_x86__8wekyb3d8bbwe
Architecture : X86
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.NET.Native.Runtime.1.7
Version : 1.7.27422.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.NET.Native.Runtime.1.7_1.7.27422.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.NET.Native.Runtime.1.7
Version : 1.7.27422.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.NET.Native.Runtime.1.7_1.7.27422.0_x86__8wekyb3d8bbwe
Architecture : X86
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.UI.Xaml.2.4
Version : 2.42007.9001.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.UI.Xaml.2.4_2.42007.9001.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.UI.Xaml.2.4
Version : 2.42007.9001.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.UI.Xaml.2.4_2.42007.9001.0_x86__8wekyb3d8bbwe
Architecture : X86
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.NET.Native.Framework.2.2
Version : 2.2.29512.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.NET.Native.Framework.2.2_2.2.29512.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.NET.Native.Framework.2.2
Version : 2.2.29512.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.NET.Native.Framework.2.2_2.2.29512.0_x86__8wekyb3d8bbwe
Architecture : X86
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Advertising.Xaml
Version : 10.1811.1.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Advertising.Xaml
Version : 10.1811.1.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe
Architecture : X86
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.UI.Xaml.2.7
Version : 7.2208.15002.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.UI.Xaml.2.7_7.2208.15002.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.UI.Xaml.2.7
Version : 7.2208.15002.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.UI.Xaml.2.7_7.2208.15002.0_x86__8wekyb3d8bbwe
Architecture : X86
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.VCLibs.140.00
Version : 14.0.32530.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.32530.0_x86__8wekyb3d8bbwe
Architecture : X86
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.VCLibs.140.00
Version : 14.0.32530.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.32530.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.VCLibs.140.00.UWPDesktop
Version : 14.0.32530.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00.UWPDesktop_14.0.32530.0_x86__8wekyb3d8bbwe
Architecture : X86
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.VCLibs.140.00.UWPDesktop
Version : 14.0.32530.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00.UWPDesktop_14.0.32530.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Services.Store.Engagement
Version : 10.0.23012.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.Services.Store.Engagement_10.0.23012.0_x86__8wekyb3d8bbwe
Architecture : X86
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Services.Store.Engagement
Version : 10.0.23012.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.Services.Store.Engagement_10.0.23012.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.UI.Xaml.2.8
Version : 8.2306.22001.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.UI.Xaml.2.8_8.2306.22001.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.UI.Xaml.2.8
Version : 8.2306.22001.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.UI.Xaml.2.8_8.2306.22001.0_x86__8wekyb3d8bbwe
Architecture : X86
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.WindowsAppRuntime.1.3
Version : 3000.934.1904.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.3_3000.934.1904.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.WindowsAppRuntime.1.3
Version : 3000.934.1904.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe
Architecture : X86
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.XboxSpeechToTextOverlay
Version : 1.21.13002.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.XboxSpeechToTextOverlay_1.21.13002.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.XboxGameOverlay
Version : 1.54.4001.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.XboxGameOverlay_1.54.4001.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Xbox.TCUI
Version : 1.24.10001.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.Xbox.TCUI_1.24.10001.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Print3D
Version : 3.3.791.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.Print3D_3.3.791.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.MixedReality.Portal
Version : 2000.21051.1282.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.MixedReality.Portal_2000.21051.1282.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Office.OneNote
Version : 16001.14326.21452.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.Office.OneNote_16001.14326.21452.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.549981C3F5F10
Version : 4.2308.1005.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.ScreenSketch
Version : 10.2008.3001.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.ScreenSketch_10.2008.3001.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.XboxApp
Version : 48.104.4001.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.XboxApp_48.104.4001.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.WindowsSoundRecorder
Version : 10.2103.28.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.WindowsSoundRecorder_10.2103.28.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.MSPaint
Version : 6.2305.16087.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.MSPaint_6.2305.16087.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-c5e2524a-ea46-4f67-841f-6a9465d9d515
Version : 10.0.19041.1949
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.FileExplorer_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.CloudExperienceHost
Version : 10.0.19041.3393
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.Search
Version : 1.14.10.19041
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.SecHealthUI
Version : 10.0.19041.1865
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.SecureAssessmentBrowser
Version : 10.0.19041.2311
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.ShellExperienceHost
Version : 10.0.19041.1949
InstallLocation : C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-MicrosoftWindows.Client.CBS
Version : 1000.19044.1000.0
InstallLocation : C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy
Architecture : X64
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Winget.Source
Version : 2023.928.1007.378
InstallLocation : C:\Program Files\WindowsApps\Microsoft.Winget.Source_2023.928.1007.378_neutral__8wekyb3d8bbwe
Architecture : Neutral
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-1527c705-839a-4832-9118-54d4Bd6a0c89
Version : 10.0.19041.3570
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.FilePicker_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-c5e2524a-ea46-4f67-841f-6a9465d9d515
Version : 10.0.19041.3570
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.FileExplorer_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-E2A4F912-2574-4A75-9BB0-0D023378592B
Version : 10.0.19041.3570
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.AppResolverUX_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-F46D4000-FD22-4DB4-AC8E-4E1DDDE828FE
Version : 10.0.19041.3570
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.AddSuggestedFoldersToLibraryDialog_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.AccountsControl
Version : 10.0.19041.3570
InstallLocation : C:\Windows\SystemApps\Microsoft.AccountsControl_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.AsyncTextService
Version : 10.0.19041.3570
InstallLocation : C:\Windows\SystemApps\Microsoft.AsyncTextService_8wekyb3d8bbwe
Architecture : Neutral
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.CredDialogHost
Version : 10.0.19041.3570
InstallLocation : C:\Windows\SystemApps\microsoft.creddialoghost_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.ECApp
Version : 10.0.19041.3570
InstallLocation : C:\Windows\SystemApps\Microsoft.ECApp_8wekyb3d8bbwe
Architecture : Neutral
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.LockApp
Version : 10.0.19041.3570
InstallLocation : C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.MicrosoftEdgeDevToolsClient
Version : 1000.19041.3570.0
InstallLocation : C:\Windows\SystemApps\Microsoft.MicrosoftEdgeDevToolsClient_8wekyb3d8bbwe
Architecture : Neutral
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Win32WebViewHost
Version : 10.0.19041.3570
InstallLocation : C:\Windows\SystemApps\Microsoft.Win32WebViewHost_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.Apprep.ChxApp
Version : 1000.19041.3570.0
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.AssignedAccessLockApp
Version : 1000.19041.3570.0
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.AssignedAccessLockApp_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.CallingShellApp
Version : 1000.19041.3570.0
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.CallingShellApp_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.CapturePicker
Version : 10.0.19041.3570
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.CapturePicker_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.NarratorQuickStart
Version : 10.0.19041.3570
InstallLocation : C:\Windows\SystemApps\microsoft.windows.narratorquickstart_8wekyb3d8bbwe
Architecture : Neutral
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.ParentalControls
Version : 1000.19041.3570.0
InstallLocation : C:\Windows\SystemApps\ParentalControls_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.PeopleExperienceHost
Version : 10.0.19041.3570
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.PinningConfirmationDialog
Version : 1000.19041.3570.0
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.PinningConfirmationDialog_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.SecHealthUI
Version : 10.0.19041.3570
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.SecureAssessmentBrowser
Version : 10.0.19041.3570
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.XGpuEjectDialog
Version : 10.0.19041.3570
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.XboxGameCallableUI
Version : 1000.19041.3570.0
InstallLocation : C:\Windows\SystemApps\Microsoft.XboxGameCallableUI_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Windows.CBSPreview
Version : 10.0.19041.3570
InstallLocation : C:\Windows\SystemApps\Windows.CBSPreview_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.WindowsAppRuntime.1.4
Version : 4000.1049.117.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.4_4000.1049.117.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.WindowsAppRuntime.1.4
Version : 4000.1049.117.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.4_4000.1049.117.0_x86__8wekyb3d8bbwe
Architecture : X86
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.MicrosoftEdge.Stable
Version : 119.0.2151.72
InstallLocation : C:\Program Files\WindowsApps\Microsoft.MicrosoftEdge.Stable_119.0.2151.72_neutral__8wekyb3d8bbwe
Architecture : Neutral
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.VCLibs.140.00
Version : 14.0.33519.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.33519.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.VCLibs.140.00
Version : 14.0.33519.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.33519.0_x86__8wekyb3d8bbwe
Architecture : X86
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.VCLibs.140.00.UWPDesktop
Version : 14.0.33728.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00.UWPDesktop_14.0.33728.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.VCLibs.140.00.UWPDesktop
Version : 14.0.33728.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00.UWPDesktop_14.0.33728.0_x86__8wekyb3d8bbwe
Architecture : X86
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.WindowsAppRuntime.1.4
Version : 4000.1309.2056.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.4_4000.1309.2056.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.WindowsAppRuntime.1.4
Version : 4000.1309.2056.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe
Architecture : X86
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.UI.Xaml.2.7
Version : 7.2409.9001.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.UI.Xaml.2.7_7.2409.9001.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.UI.Xaml.2.7
Version : 7.2409.9001.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.UI.Xaml.2.7_7.2409.9001.0_x86__8wekyb3d8bbwe
Architecture : X86
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.WindowsAppRuntime.1.5
Version : 5001.373.1736.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.5_5001.373.1736.0_x86__8wekyb3d8bbwe
Architecture : X86
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.WindowsAppRuntime.1.5
Version : 5001.373.1736.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.UI.Xaml.2.8
Version : 8.2501.31001.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.UI.Xaml.2.8_8.2501.31001.0_x86__8wekyb3d8bbwe
Architecture : X86
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.UI.Xaml.2.8
Version : 8.2501.31001.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.UI.Xaml.2.8_8.2501.31001.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-1527c705-839a-4832-9118-54d4Bd6a0c89
Version : 10.0.19041.4239
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.FilePicker_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-c5e2524a-ea46-4f67-841f-6a9465d9d515
Version : 10.0.19041.4239
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.FileExplorer_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-E2A4F912-2574-4A75-9BB0-0D023378592B
Version : 10.0.19041.4239
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.AppResolverUX_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-F46D4000-FD22-4DB4-AC8E-4E1DDDE828FE
Version : 10.0.19041.4239
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.AddSuggestedFoldersToLibraryDialog_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.AAD.BrokerPlugin
Version : 1000.19041.4239.0
InstallLocation : C:\Windows\SystemApps\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.AccountsControl
Version : 10.0.19041.4239
InstallLocation : C:\Windows\SystemApps\Microsoft.AccountsControl_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.AsyncTextService
Version : 10.0.19041.4239
InstallLocation : C:\Windows\SystemApps\Microsoft.AsyncTextService_8wekyb3d8bbwe
Architecture : Neutral
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.BioEnrollment
Version : 10.0.19041.4239
InstallLocation : C:\Windows\SystemApps\Microsoft.BioEnrollment_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.CredDialogHost
Version : 10.0.19041.4239
InstallLocation : C:\Windows\SystemApps\microsoft.creddialoghost_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.ECApp
Version : 10.0.19041.4597
InstallLocation : C:\Windows\SystemApps\Microsoft.ECApp_8wekyb3d8bbwe
Architecture : Neutral
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.LockApp
Version : 10.0.19041.4239
InstallLocation : C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.MicrosoftEdgeDevToolsClient
Version : 1000.19041.4239.0
InstallLocation : C:\Windows\SystemApps\Microsoft.MicrosoftEdgeDevToolsClient_8wekyb3d8bbwe
Architecture : Neutral
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Win32WebViewHost
Version : 10.0.19041.4239
InstallLocation : C:\Windows\SystemApps\Microsoft.Win32WebViewHost_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.Apprep.ChxApp
Version : 1000.19041.4239.0
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.AssignedAccessLockApp
Version : 1000.19041.4239.0
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.AssignedAccessLockApp_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.CallingShellApp
Version : 1000.19041.4239.0
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.CallingShellApp_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.CapturePicker
Version : 10.0.19041.4239
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.CapturePicker_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.CloudExperienceHost
Version : 10.0.19041.5198
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.ContentDeliveryManager
Version : 10.0.19041.4239
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.NarratorQuickStart
Version : 10.0.19041.4239
InstallLocation : C:\Windows\SystemApps\microsoft.windows.narratorquickstart_8wekyb3d8bbwe
Architecture : Neutral
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.OOBENetworkCaptivePortal
Version : 10.0.19041.4239
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.OOBENetworkCaptivePortal_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.OOBENetworkConnectionFlow
Version : 10.0.19041.4239
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.OOBENetworkConnectionFlow_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.ParentalControls
Version : 1000.19041.4239.0
InstallLocation : C:\Windows\SystemApps\ParentalControls_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.PeopleExperienceHost
Version : 10.0.19041.4239
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.PinningConfirmationDialog
Version : 1000.19041.4239.0
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.PinningConfirmationDialog_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.SecHealthUI
Version : 10.0.19041.4239
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.SecureAssessmentBrowser
Version : 10.0.19041.4239
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.ShellExperienceHost
Version : 10.0.19041.5072
InstallLocation : C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.StartMenuExperienceHost
Version : 10.0.19041.5438
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.XGpuEjectDialog
Version : 10.0.19041.4239
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.XboxGameCallableUI
Version : 1000.19041.4239.0
InstallLocation : C:\Windows\SystemApps\Microsoft.XboxGameCallableUI_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-MicrosoftWindows.Client.CBS
Version : 1000.19061.1000.0
InstallLocation : C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy
Architecture : X64
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-MicrosoftWindows.UndockedDevKit
Version : 10.0.19041.4239
InstallLocation : C:\Windows\SystemApps\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-NcsiUwpApp
Version : 1000.19041.4239.0
InstallLocation : C:\Windows\SystemApps\NcsiUwpApp_8wekyb3d8bbwe
Architecture : Neutral
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Windows.CBSPreview
Version : 10.0.19041.4239
InstallLocation : C:\Windows\SystemApps\Windows.CBSPreview_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Getstarted
Version : 10.2312.1.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.Getstarted_10.2312.1.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.GetHelp
Version : 10.2409.22951.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.GetHelp_10.2409.22951.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.People
Version : 10.2202.100.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.People_10.2202.100.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.XboxIdentityProvider
Version : 12.115.1001.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.XboxIdentityProvider_12.115.1001.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.MicrosoftStickyNotes
Version : 6.1.4.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.MicrosoftStickyNotes_6.1.4.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.BingWeather
Version : 4.54.63007.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.BingWeather_4.54.63007.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.MSPaint
Version : 6.2410.13017.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.MSPaint_6.2410.13017.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.BingSearch
Version : 1.1.34.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.BingSearch_1.1.34.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.WindowsAppRuntime.1.6
Version : 6000.424.1611.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.6_6000.424.1611.0_x86__8wekyb3d8bbwe
Architecture : X86
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.WindowsCalculator
Version : 11.2502.2.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_11.2502.2.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-microsoft.windowscommunicationsapps
Version : 16005.14326.22342.0
InstallLocation : C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.WindowsAlarms
Version : 11.2503.4.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.WindowsAlarms_11.2503.4.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.WebpImageExtension
Version : 1.2.10.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.WebpImageExtension_1.2.10.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Office.OneNote
Version : 16001.14326.22348.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.Office.OneNote_16001.14326.22348.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.SkypeApp
Version : 15.150.3125.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.150.3125.0_x64__kzf8qxf38zg5c
Architecture : X64
Publisher : CN=Skype Software Sarl, O=Microsoft Corporation, L=Luxembourg, S=Luxembourg, C=LU

-Microsoft.Windows.DevHome
Version : 0.2100.858.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.Windows.DevHome_0.2100.858.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.WindowsFeedbackHub
Version : 1.2505.1101.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.WindowsFeedbackHub_1.2505.1101.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.WebMediaExtensions
Version : 1.2.14.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.WebMediaExtensions_1.2.14.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.MicrosoftSolitaireCollection
Version : 4.22.5200.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.22.5200.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.XboxGamingOverlay
Version : 7.325.5191.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_7.325.5191.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.WindowsAppRuntime.1.7
Version : 7000.522.1444.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.7_7000.522.1444.0_x86__8wekyb3d8bbwe
Architecture : X86
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.VP9VideoExtensions
Version : 1.2.6.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.VP9VideoExtensions_1.2.6.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.WindowsAppRuntime.1.7
Version : 7000.522.1444.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.7_7000.522.1444.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.WindowsAppRuntime.1.6
Version : 6000.519.329.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.OutlookForWindows
Version : 1.2025.604.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.OutlookForWindows_1.2025.604.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.WindowsAppRuntime.1.6
Version : 6000.519.329.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.6_6000.519.329.0_x86__8wekyb3d8bbwe
Architecture : X86
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.HEIFImageExtension
Version : 1.2.20.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.HEIFImageExtension_1.2.20.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.Search
Version : 1.14.18.19041
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.StorePurchaseApp
Version : 22505.1401.0.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.StorePurchaseApp_22505.1401.0.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.DesktopAppInstaller
Version : 1.26.400.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.DesktopAppInstaller_1.26.400.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.WindowsStore
Version : 22505.1401.17.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.WindowsStore_22505.1401.17.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.WindowsCamera
Version : 2025.2505.2.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.WindowsCamera_2025.2505.2.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.ZuneMusic
Version : 11.2505.2.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.ZuneMusic_11.2505.2.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.ZuneVideo
Version : 10.25051.10031.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.25051.10031.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.Photos
Version : 2025.11060.26001.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2025.11060.26001.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.MicrosoftOfficeHub
Version : 19.2507.31211.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2507.31211.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.YourPhone
Version : 1.25061.44.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.YourPhone_1.25061.44.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Microsoft3DViewer
Version : 7.2506.10022.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.Microsoft3DViewer_7.2506.10022.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.MicrosoftOfficeHub
Version : 19.2507.37101.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2507.37101.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.WindowsMaps
Version : 11.2506.3.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.WindowsMaps_11.2506.3.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.BingSearch
Version : 1.1.33.0
InstallLocation : C:\Program Files\WindowsApps\Microsoft.BingSearch_1.1.33.0_x64__8wekyb3d8bbwe
Architecture : X64
Publisher : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
204960 - Windows System Driver Enumeration (Windows)
-
Synopsis
One or more kernel or file system drivers were enumerated on the remote Windows host.
Description
One or more kernel or file system drivers were enumerated on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2024/08/01, Modified: 2025/12/15
Plugin Output

tcp/0


Total : 393

Name : 1394ohci
Path : C:\WINDOWS\system32\drivers\1394ohci.sys
Service Type : Kernel Driver
Description : 1394 OHCI Compliant Host Controller
State : Stopped

Name : 3ware
Path : C:\WINDOWS\system32\drivers\3ware.sys
Service Type : Kernel Driver
Description : 3ware
State : Stopped

Name : ACPI
Path : C:\WINDOWS\system32\drivers\ACPI.sys
Service Type : Kernel Driver
Description : Microsoft ACPI Driver
State : Running

Name : AcpiDev
Path : C:\WINDOWS\system32\drivers\AcpiDev.sys
Service Type : Kernel Driver
Description : ACPI Devices driver
State : Stopped

Name : acpiex
Path : C:\WINDOWS\system32\Drivers\acpiex.sys
Service Type : Kernel Driver
Description : Microsoft ACPIEx Driver
State : Running

Name : acpipagr
Path : C:\WINDOWS\system32\drivers\acpipagr.sys
Service Type : Kernel Driver
Description : ACPI Processor Aggregator Driver
State : Stopped

Name : AcpiPmi
Path : C:\WINDOWS\system32\drivers\acpipmi.sys
Service Type : Kernel Driver
Description : ACPI Power Meter Driver
State : Stopped

Name : acpitime
Path : C:\WINDOWS\system32\drivers\acpitime.sys
Service Type : Kernel Driver
Description : ACPI Wake Alarm Driver
State : Stopped

Name : Acx01000
Path : C:\WINDOWS\system32\drivers\Acx01000.sys
Service Type : Kernel Driver
Description : Acx01000
State : Stopped

Name : ADP80XX
Path : C:\WINDOWS\system32\drivers\ADP80XX.SYS
Service Type : Kernel Driver
Description : ADP80XX
State : Stopped

Name : AFD
Path : C:\WINDOWS\system32\drivers\afd.sys
Service Type : Kernel Driver
Description : Ancillary Function Driver for Winsock
State : Running

Name : afunix
Path : C:\WINDOWS\system32\drivers\afunix.sys
Service Type : Kernel Driver
Description : afunix
State : Running

Name : ahcache
Path : C:\WINDOWS\system32\DRIVERS\ahcache.sys
Service Type : Kernel Driver
Description : Application Compatibility Cache
State : Running

Name : amdgpio2
Path : C:\WINDOWS\system32\drivers\amdgpio2.sys
Service Type : Kernel Driver
Description : AMD GPIO Client Driver
State : Stopped

Name : amdi2c
Path : C:\WINDOWS\system32\drivers\amdi2c.sys
Service Type : Kernel Driver
Description : AMD I2C Controller Service
State : Stopped

Name : AmdK8
Path : C:\WINDOWS\system32\drivers\amdk8.sys
Service Type : Kernel Driver
Description : AMD K8 Processor Driver
State : Stopped

Name : AmdPPM
Path : C:\WINDOWS\system32\drivers\amdppm.sys
Service Type : Kernel Driver
Description : AMD Processor Driver
State : Stopped

Name : amdsata
Path : C:\WINDOWS\system32\drivers\amdsata.sys
Service Type : Kernel Driver
Description : amdsata
State : Stopped

Name : amdsbs
Path : C:\WINDOWS\system32\drivers\amdsbs.sys
Service Type : Kernel Driver
Description : amdsbs
State : Stopped

Name : amdxata
Path : C:\WINDOWS\system32\drivers\amdxata.sys
Service Type : Kernel Driver
Description : amdxata
State : Stopped

Name : AppID
Path : C:\WINDOWS\system32\drivers\appid.sys
Service Type : Kernel Driver
Description : AppID Driver
State : Stopped

Name : applockerfltr
Path : C:\WINDOWS\system32\drivers\applockerfltr.sys
Service Type : Kernel Driver
Description : Smartlocker Filter Driver
State : Stopped

Name : AppvStrm
Path : C:\WINDOWS\system32\drivers\AppvStrm.sys
Service Type : File System Driver
Description : AppvStrm
State : Stopped

Name : AppvVemgr
Path : C:\WINDOWS\system32\drivers\AppvVemgr.sys
Service Type : File System Driver
Description : AppvVemgr
State : Stopped

Name : AppvVfs
Path : C:\WINDOWS\system32\drivers\AppvVfs.sys
Service Type : File System Driver
Description : AppvVfs
State : Stopped

Name : arcsas
Path : C:\WINDOWS\system32\drivers\arcsas.sys
Service Type : Kernel Driver
Description : Adaptec SAS/SATA-II RAID Storport's Miniport Driver
State : Stopped

Name : AsyncMac
Path : C:\WINDOWS\system32\drivers\asyncmac.sys
Service Type : Kernel Driver
Description : RAS Asynchronous Media Driver
State : Stopped

Name : atapi
Path : C:\WINDOWS\system32\drivers\atapi.sys
Service Type : Kernel Driver
Description : IDE Channel
State : Running

Name : b06bdrv
Path : C:\WINDOWS\system32\drivers\bxvbda.sys
Service Type : Kernel Driver
Description : QLogic Network Adapter VBD
State : Stopped

Name : bam
Path : C:\WINDOWS\system32\drivers\bam.sys
Service Type : Kernel Driver
Description : Background Activity Moderator Driver
State : Running

Name : BasicDisplay
Path : C:\WINDOWS\system32\DriverStore\FileRepository\basicdisplay.inf_amd64_19e58b6267591a82\BasicDisplay.sys
Service Type : Kernel Driver
Description : BasicDisplay
State : Running

Name : BasicRender
Path : C:\WINDOWS\system32\DriverStore\FileRepository\basicrender.inf_amd64_d3f5994a67770b50\BasicRender.sys
Service Type : Kernel Driver
Description : BasicRender
State : Running

Name : bcmfn2
Path : C:\WINDOWS\system32\drivers\bcmfn2.sys
Service Type : Kernel Driver
Description : bcmfn2 Service
State : Stopped

Name : Beep
Path : C:\WINDOWS\system32\drivers\Beep.sys
Service Type : Kernel Driver
Description : Beep
State : Running

Name : bindflt
Path : C:\WINDOWS\system32\drivers\bindflt.sys
Service Type : File System Driver
Description : Windows Bind Filter Driver
State : Running

Name : bowser
Path : C:\WINDOWS\system32\DRIVERS\bowser.sys
Service Type : File System Driver
Description : Browser
State : Running

Name : BthA2dp
Path : C:\WINDOWS\system32\drivers\BthA2dp.sys
Service Type : Kernel Driver
Description : Microsoft Bluetooth A2dp driver
State : Stopped

Name : BthEnum
Path : C:\WINDOWS\system32\drivers\BthEnum.sys
Service Type : Kernel Driver
Description : Bluetooth Enumerator Service
State : Stopped

Name : BthHFEnum
Path : C:\WINDOWS\system32\drivers\bthhfenum.sys
Service Type : Kernel Driver
Description : Microsoft Bluetooth Hands-Free Profile driver
State : Stopped

Name : BthLEEnum
Path : C:\WINDOWS\system32\drivers\Microsoft.Bluetooth.Legacy.LEEnumerator.sys
Service Type : Kernel Driver
Description : Bluetooth Low Energy Driver
State : Stopped

Name : BthMini
Path : C:\WINDOWS\system32\drivers\BTHMINI.sys
Service Type : Kernel Driver
Description : Bluetooth Radio Driver
State : Stopped

Name : BTHMODEM
Path : C:\WINDOWS\system32\drivers\bthmodem.sys
Service Type : Kernel Driver
Description : Bluetooth Modem Communications Driver
State : Stopped

Name : BTHPORT
Path : C:\WINDOWS\system32\drivers\BTHport.sys
Service Type : Kernel Driver
Description : Bluetooth Port Driver
State : Stopped

Name : BTHUSB
Path : C:\WINDOWS\system32\drivers\BTHUSB.sys
Service Type : Kernel Driver
Description : Bluetooth Radio USB Driver
State : Stopped

Name : bttflt
Path : C:\WINDOWS\system32\drivers\bttflt.sys
Service Type : Kernel Driver
Description : Microsoft Hyper-V VHDPMEM BTT Filter
State : Stopped

Name : buttonconverter
Path : C:\WINDOWS\system32\drivers\buttonconverter.sys
Service Type : Kernel Driver
Description : Service for Portable Device Control devices
State : Stopped

Name : CAD
Path : C:\WINDOWS\system32\drivers\CAD.sys
Service Type : Kernel Driver
Description : Charge Arbitration Driver
State : Stopped

Name : cdfs
Path : C:\WINDOWS\system32\DRIVERS\cdfs.sys
Service Type : File System Driver
Description : CD/DVD File System Reader
State : Stopped

Name : cdrom
Path : C:\WINDOWS\system32\drivers\cdrom.sys
Service Type : Kernel Driver
Description : CD-ROM Driver
State : Running

Name : cht4iscsi
Path : C:\WINDOWS\system32\drivers\cht4sx64.sys
Service Type : Kernel Driver
Description : cht4iscsi
State : Stopped

Name : cht4vbd
Path : C:\WINDOWS\system32\drivers\cht4vx64.sys
Service Type : Kernel Driver
Description : Chelsio Virtual Bus Driver
State : Stopped

Name : CimFS
Path : C:\WINDOWS\system32\drivers\CimFS.sys
Service Type : File System Driver
Description : CimFS
State : Running

Name : circlass
Path : C:\WINDOWS\system32\drivers\circlass.sys
Service Type : Kernel Driver
Description : Consumer IR Devices
State : Stopped

Name : CldFlt
Path : C:\WINDOWS\system32\drivers\cldflt.sys
Service Type : File System Driver
Description : Windows Cloud Files Filter Driver
State : Running

Name : CLFS
Path : C:\WINDOWS\system32\drivers\CLFS.sys
Service Type : Kernel Driver
Description : Common Log (CLFS)
State : Running

Name : CmBatt
Path : C:\WINDOWS\system32\drivers\CmBatt.sys
Service Type : Kernel Driver
Description : Microsoft ACPI Control Method Battery Driver
State : Running

Name : CNG
Path : C:\WINDOWS\system32\Drivers\cng.sys
Service Type : Kernel Driver
Description : CNG
State : Running

Name : cnghwassist
Path : C:\WINDOWS\system32\DRIVERS\cnghwassist.sys
Service Type : Kernel Driver
Description : CNG Hardware Assist algorithm provider
State : Stopped

Name : CompositeBus
Path : C:\WINDOWS\system32\DriverStore\FileRepository\compositebus.inf_amd64_7500cffa210c6946\CompositeBus.sys
Service Type : Kernel Driver
Description : Composite Bus Enumerator Driver
State : Running

Name : condrv
Path : C:\WINDOWS\system32\drivers\condrv.sys
Service Type : Kernel Driver
Description : Console Driver
State : Running

Name : CSC
Path : C:\WINDOWS\system32\drivers\csc.sys
Service Type : Kernel Driver
Description : Offline Files Driver
State : Running

Name : dam
Path : C:\WINDOWS\system32\drivers\dam.sys
Service Type : Kernel Driver
Description : Desktop Activity Moderator Driver
State : Stopped

Name : Dfsc
Path : C:\WINDOWS\system32\Drivers\dfsc.sys
Service Type : File System Driver
Description : DFS Namespace Client Driver
State : Running

Name : disk
Path : C:\WINDOWS\system32\drivers\disk.sys
Service Type : Kernel Driver
Description : Disk Driver
State : Running

Name : dmvsc
Path : C:\WINDOWS\system32\drivers\dmvsc.sys
Service Type : Kernel Driver
Description : dmvsc
State : Stopped

Name : drmkaud
Path : C:\WINDOWS\system32\drivers\drmkaud.sys
Service Type : Kernel Driver
Description : Microsoft Trusted Audio Drivers
State : Stopped

Name : DXGKrnl
Path : C:\WINDOWS\system32\drivers\dxgkrnl.sys
Service Type : Kernel Driver
Description : LDDM Graphics Subsystem
State : Running

Name : e1i65x64
Path : C:\WINDOWS\system32\drivers\e1i65x64.sys
Service Type : Kernel Driver
Description : Intel(R) PRO/1000 PCI Express Network Connection Driver I
State : Running

Name : ebdrv
Path : C:\WINDOWS\system32\drivers\evbda.sys
Service Type : Kernel Driver
Description : QLogic 10 Gigabit Ethernet Adapter VBD
State : Stopped

Name : EhStorClass
Path : C:\WINDOWS\system32\drivers\EhStorClass.sys
Service Type : Kernel Driver
Description : Enhanced Storage Filter Driver
State : Running

Name : EhStorTcgDrv
Path : C:\WINDOWS\system32\drivers\EhStorTcgDrv.sys
Service Type : Kernel Driver
Description : Microsoft driver for storage devices supporting IEEE 1667 and TCG protocols
State : Stopped

Name : ErrDev
Path : C:\WINDOWS\system32\drivers\errdev.sys
Service Type : Kernel Driver
Description : Microsoft Hardware Error Device Driver
State : Stopped

Name : exfat
Path : C:\WINDOWS\system32\drivers\exfat.sys
Service Type : File System Driver
Description : exFAT File System Driver
State : Stopped

Name : fastfat
Path : C:\WINDOWS\system32\drivers\fastfat.sys
Service Type : File System Driver
Description : FAT12/16/32 File System Driver
State : Stopped

Name : fdc
Path : C:\WINDOWS\system32\drivers\fdc.sys
Service Type : Kernel Driver
Description : Floppy Disk Controller Driver
State : Running

Name : FileCrypt
Path : C:\WINDOWS\system32\drivers\filecrypt.sys
Service Type : File System Driver
Description : FileCrypt
State : Running

Name : FileInfo
Path : C:\WINDOWS\system32\drivers\fileinfo.sys
Service Type : File System Driver
Description : File Information FS MiniFilter
State : Running

Name : Filetrace
Path : C:\WINDOWS\system32\drivers\filetrace.sys
Service Type : File System Driver
Description : Filetrace
State : Stopped

Name : flpydisk
Path : C:\WINDOWS\system32\drivers\flpydisk.sys
Service Type : Kernel Driver
Description : Floppy Disk Driver
State : Running

Name : FltMgr
Path : C:\WINDOWS\system32\drivers\fltmgr.sys
Service Type : File System Driver
Description : FltMgr
State : Running

Name : FsDepends
Path : C:\WINDOWS\system32\drivers\FsDepends.sys
Service Type : File System Driver
Description : File System Dependency Minifilter
State : Stopped

Name : fvevol
Path : C:\WINDOWS\system32\DRIVERS\fvevol.sys
Service Type : Kernel Driver
Description : BitLocker Drive Encryption Filter Driver
State : Running

Name : gencounter
Path : C:\WINDOWS\system32\drivers\vmgencounter.sys
Service Type : Kernel Driver
Description : Microsoft Hyper-V Generation Counter
State : Running

Name : genericusbfn
Path : C:\WINDOWS\system32\DriverStore\FileRepository\genericusbfn.inf_amd64_53931f0ae21d6d2c\genericusbfn.sys
Service Type : Kernel Driver
Description : Generic USB Function Class
State : Stopped

Name : GPIOClx0101
Path : C:\WINDOWS\system32\Drivers\msgpioclx.sys
Service Type : Kernel Driver
Description : Microsoft GPIO Class Extension Driver
State : Stopped

Name : GpuEnergyDrv
Path : C:\WINDOWS\system32\drivers\gpuenergydrv.sys
Service Type : Kernel Driver
Description : GPU Energy Driver
State : Running

Name : HdAudAddService
Path : C:\WINDOWS\system32\drivers\HdAudio.sys
Service Type : Kernel Driver
Description : Microsoft 1.1 UAA Function Driver for High Definition Audio Service
State : Stopped

Name : HDAudBus
Path : C:\WINDOWS\system32\drivers\HDAudBus.sys
Service Type : Kernel Driver
Description : Microsoft UAA Bus Driver for High Definition Audio
State : Stopped

Name : HidBatt
Path : C:\WINDOWS\system32\drivers\HidBatt.sys
Service Type : Kernel Driver
Description : HID UPS Battery Driver
State : Stopped

Name : HidBth
Path : C:\WINDOWS\system32\drivers\hidbth.sys
Service Type : Kernel Driver
Description : Microsoft Bluetooth HID Miniport
State : Stopped

Name : hidi2c
Path : C:\WINDOWS\system32\drivers\hidi2c.sys
Service Type : Kernel Driver
Description : Microsoft I2C HID Miniport Driver
State : Stopped

Name : hidinterrupt
Path : C:\WINDOWS\system32\drivers\hidinterrupt.sys
Service Type : Kernel Driver
Description : Common Driver for HID Buttons implemented with interrupts
State : Stopped

Name : HidIr
Path : C:\WINDOWS\system32\drivers\hidir.sys
Service Type : Kernel Driver
Description : Microsoft Infrared HID Driver
State : Stopped

Name : hidspi
Path : C:\WINDOWS\system32\drivers\hidspi.sys
Service Type : Kernel Driver
Description : Microsoft SPI HID Miniport Driver
State : Stopped

Name : HidSpiCx
Path : C:\WINDOWS\system32\drivers\HidSpiCx.sys
Service Type : Kernel Driver
Description : HidSpi KMDF Class Extension
State : Stopped

Name : HidUsb
Path : C:\WINDOWS\system32\drivers\hidusb.sys
Service Type : Kernel Driver
Description : Microsoft HID Class Driver
State : Stopped

Name : HpSAMD
Path : C:\WINDOWS\system32\drivers\HpSAMD.sys
Service Type : Kernel Driver
Description : HpSAMD
State : Stopped

Name : HTTP
Path : C:\WINDOWS\system32\drivers\HTTP.sys
Service Type : Kernel Driver
Description : HTTP Service
State : Running

Name : hvcrash
Path : C:\WINDOWS\system32\drivers\hvcrash.sys
Service Type : Kernel Driver
Description : hvcrash
State : Stopped

Name : hvservice
Path : C:\WINDOWS\system32\drivers\hvservice.sys
Service Type : Kernel Driver
Description : Hypervisor/Virtual Machine Support Driver
State : Stopped

Name : HwNClx0101
Path : C:\WINDOWS\system32\Drivers\mshwnclx.sys
Service Type : Kernel Driver
Description : Microsoft Hardware Notifications Class Extension Driver
State : Stopped

Name : hwpolicy
Path : C:\WINDOWS\system32\drivers\hwpolicy.sys
Service Type : Kernel Driver
Description : Hardware Policy Driver
State : Stopped

Name : hyperkbd
Path : C:\WINDOWS\system32\drivers\hyperkbd.sys
Service Type : Kernel Driver
Description : hyperkbd
State : Stopped

Name : HyperVideo
Path : C:\WINDOWS\system32\drivers\HyperVideo.sys
Service Type : Kernel Driver
Description : HyperVideo
State : Stopped

Name : i8042prt
Path : C:\WINDOWS\system32\drivers\i8042prt.sys
Service Type : Kernel Driver
Description : PS/2 Keyboard and Mouse Port Driver
State : Running

Name : iagpio
Path : C:\WINDOWS\system32\drivers\iagpio.sys
Service Type : Kernel Driver
Description : Intel Serial IO GPIO Controller Driver
State : Stopped

Name : iai2c
Path : C:\WINDOWS\system32\drivers\iai2c.sys
Service Type : Kernel Driver
Description : Intel(R) Serial IO I2C Host Controller
State : Stopped

Name : iaLPSS2i_GPIO2
Path : C:\WINDOWS\system32\drivers\iaLPSS2i_GPIO2.sys
Service Type : Kernel Driver
Description : Intel(R) Serial IO GPIO Driver v2
State : Stopped

Name : iaLPSS2i_GPIO2_BXT_P
Path : C:\WINDOWS\system32\drivers\iaLPSS2i_GPIO2_BXT_P.sys
Service Type : Kernel Driver
Description : Intel(R) Serial IO GPIO Driver v2
State : Stopped

Name : iaLPSS2i_GPIO2_CNL
Path : C:\WINDOWS\system32\drivers\iaLPSS2i_GPIO2_CNL.sys
Service Type : Kernel Driver
Description : Intel(R) Serial IO GPIO Driver v2
State : Stopped

Name : iaLPSS2i_GPIO2_GLK
Path : C:\WINDOWS\system32\drivers\iaLPSS2i_GPIO2_GLK.sys
Service Type : Kernel Driver
Description : Intel(R) Serial IO GPIO Driver v2
State : Stopped

Name : iaLPSS2i_I2C
Path : C:\WINDOWS\system32\drivers\iaLPSS2i_I2C.sys
Service Type : Kernel Driver
Description : Intel(R) Serial IO I2C Driver v2
State : Stopped

Name : iaLPSS2i_I2C_BXT_P
Path : C:\WINDOWS\system32\drivers\iaLPSS2i_I2C_BXT_P.sys
Service Type : Kernel Driver
Description : Intel(R) Serial IO I2C Driver v2
State : Stopped

Name : iaLPSS2i_I2C_CNL
Path : C:\WINDOWS\system32\drivers\iaLPSS2i_I2C_CNL.sys
Service Type : Kernel Driver
Description : Intel(R) Serial IO I2C Driver v2
State : Stopped

Name : iaLPSS2i_I2C_GLK
Path : C:\WINDOWS\system32\drivers\iaLPSS2i_I2C_GLK.sys
Service Type : Kernel Driver
Description : Intel(R) Serial IO I2C Driver v2
State : Stopped

Name : iaLPSSi_GPIO
Path : C:\WINDOWS\system32\drivers\iaLPSSi_GPIO.sys
Service Type : Kernel Driver
Description : Intel(R) Serial IO GPIO Controller Driver
State : Stopped

Name : iaLPSSi_I2C
Path : C:\WINDOWS\system32\drivers\iaLPSSi_I2C.sys
Service Type : Kernel Driver
Description : Intel(R) Serial IO I2C Controller Driver
State : Stopped

Name : iaStorAVC
Path : C:\WINDOWS\system32\drivers\iaStorAVC.sys
Service Type : Kernel Driver
Description : Intel Chipset SATA RAID Controller
State : Stopped

Name : iaStorV
Path : C:\WINDOWS\system32\drivers\iaStorV.sys
Service Type : Kernel Driver
Description : Intel RAID Controller Windows 7
State : Stopped

Name : ibbus
Path : C:\WINDOWS\system32\drivers\ibbus.sys
Service Type : Kernel Driver
Description : Mellanox InfiniBand Bus/AL (Filter Driver)
State : Stopped

Name : IndirectKmd
Path : C:\WINDOWS\system32\drivers\IndirectKmd.sys
Service Type : Kernel Driver
Description : Indirect Displays Kernel-Mode Driver
State : Stopped

Name : intelide
Path : C:\WINDOWS\system32\drivers\intelide.sys
Service Type : Kernel Driver
Description : intelide
State : Running

Name : intelpep
Path : C:\WINDOWS\system32\drivers\intelpep.sys
Service Type : Kernel Driver
Description : Intel(R) Power Engine Plug-in Driver
State : Running

Name : intelpmax
Path : C:\WINDOWS\system32\drivers\intelpmax.sys
Service Type : Kernel Driver
Description : Intel(R) Dynamic Device Peak Power Manager Driver
State : Stopped

Name : intelppm
Path : C:\WINDOWS\system32\drivers\intelppm.sys
Service Type : Kernel Driver
Description : Intel Processor Driver
State : Running

Name : iorate
Path : C:\WINDOWS\system32\drivers\iorate.sys
Service Type : Kernel Driver
Description : Disk I/O Rate Filter Driver
State : Running

Name : IpFilterDriver
Path : C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
Service Type : Kernel Driver
Description : IP Traffic Filter Driver
State : Stopped

Name : IPMIDRV
Path : C:\WINDOWS\system32\drivers\IPMIDrv.sys
Service Type : Kernel Driver
Description : IPMIDRV
State : Stopped

Name : IPNAT
Path : C:\WINDOWS\system32\drivers\ipnat.sys
Service Type : Kernel Driver
Description : IP Network Address Translator
State : Stopped

Name : IPT
Path : C:\WINDOWS\system32\drivers\ipt.sys
Service Type : Kernel Driver
Description : IPT
State : Stopped

Name : isapnp
Path : C:\WINDOWS\system32\drivers\isapnp.sys
Service Type : Kernel Driver
Description : isapnp
State : Stopped

Name : iScsiPrt
Path : C:\WINDOWS\system32\drivers\msiscsi.sys
Service Type : Kernel Driver
Description : iScsiPort Driver
State : Stopped

Name : ItSas35i
Path : C:\WINDOWS\system32\drivers\ItSas35i.sys
Service Type : Kernel Driver
Description : ItSas35i
State : Stopped

Name : kbdclass
Path : C:\WINDOWS\system32\drivers\kbdclass.sys
Service Type : Kernel Driver
Description : Keyboard Class Driver
State : Running

Name : kbdhid
Path : C:\WINDOWS\system32\drivers\kbdhid.sys
Service Type : Kernel Driver
Description : Keyboard HID Driver
State : Stopped

Name : kbldfltr
Path : C:\WINDOWS\system32\drivers\kbldfltr.sys
Service Type : Kernel Driver
Description : kbldfltr
State : Stopped

Name : kdnic
Path : C:\WINDOWS\system32\drivers\kdnic.sys
Service Type : Kernel Driver
Description : Microsoft Kernel Debug Network Miniport (NDIS 6.20)
State : Running

Name : klbackupdisk.KES-21-15
Path : C:\WINDOWS\system32\DRIVERS\KES-21-15\klbackupdisk.sys
Service Type : Kernel Driver
Description : Kaspersky Lab klbackupdisk.KES-21-15
State : Running

Name : klbackupflt.KES-21-15
Path : C:\WINDOWS\system32\DRIVERS\KES-21-15\klbackupflt.sys
Service Type : File System Driver
Description : Kaspersky Lab klbackupflt.KES-21-15
State : Running

Name : klelam
Path : C:\WINDOWS\system32\DRIVERS\klelam.sys
Service Type : Kernel Driver
Description : klelam
State : Stopped

Name : klflt.KES-21-15
Path : C:\WINDOWS\system32\DRIVERS\KES-21-15\klflt.sys
Service Type : Kernel Driver
Description : Kaspersky Lab Kernel DLL.KES-21-15
State : Running

Name : klfltdev.KES-21-15
Path : C:\WINDOWS\system32\DRIVERS\KES-21-15\klfltdev.sys
Service Type : Kernel Driver
Description : Kaspersky Lab KLFltDev.KES-21-15
State : Running

Name : klgse.KES-21-15
Path : C:\WINDOWS\system32\DRIVERS\KES-21-15\klgse.sys
Service Type : File System Driver
Description : Kaspersky Lab Security Extender Driver.KES-21-15
State : Running

Name : KLHK.KES-21-15
Path : C:\WINDOWS\system32\DRIVERS\KES-21-15\klhk.sys
Service Type : Kernel Driver
Description : Kaspersky Lab service driver.KES-21-15
State : Running

Name : KLIF.KES-21-15
Path : C:\WINDOWS\system32\DRIVERS\KES-21-15\klif.sys
Service Type : File System Driver
Description : Kaspersky Lab Driver.KES-21-15
State : Running

Name : klim6
Path : C:\WINDOWS\system32\DRIVERS\klim6.sys
Service Type : Kernel Driver
Description : Kaspersky Anti-Virus NDIS 6 Filter
State : Running

Name : klpd.KES-21-15
Path : C:\WINDOWS\system32\DRIVERS\KES-21-15\klpd.sys
Service Type : File System Driver
Description : Kaspersky Lab format recognizer driver.KES-21-15
State : Running

Name : klpnpflt.KES-21-15
Path : C:\WINDOWS\system32\DRIVERS\KES-21-15\klpnpflt.sys
Service Type : Kernel Driver
Description : Kaspersky Lab klpnpflt.KES-21-15
State : Running

Name : klupd_KES-21-15_arkmon
Path : C:\WINDOWS\system32\Drivers\klupd_KES-21-15_arkmon.sys
Service Type : Kernel Driver
Description : klupd_KES-21-15_arkmon
State : Running

Name : klupd_KES-21-15_klark
Path : C:\WINDOWS\system32\Drivers\klupd_KES-21-15_klark.sys
Service Type : Kernel Driver
Description : klupd_KES-21-15_klark
State : Running

Name : klupd_KES-21-15_klbg
Path : C:\WINDOWS\system32\Drivers\klupd_KES-21-15_klbg.sys
Service Type : Kernel Driver
Description : klupd_KES-21-15_klbg
State : Running

Name : klupd_KES-21-15_mark
Path : C:\WINDOWS\system32\Drivers\klupd_KES-21-15_mark.sys
Service Type : Kernel Driver
Description : klupd_KES-21-15_mark
State : Running

Name : klwfp
Path : C:\WINDOWS\system32\DRIVERS\klwfp.sys
Service Type : Kernel Driver
Description : klwfp
State : Running

Name : klwtp.KES-21-15
Path : C:\WINDOWS\system32\DRIVERS\KES-21-15\klwtp.sys
Service Type : Kernel Driver
Description : klwtp.KES-21-15
State : Running

Name : kneps.KES-21-15
Path : C:\WINDOWS\system32\DRIVERS\KES-21-15\kneps.sys
Service Type : Kernel Driver
Description : kneps.KES-21-15
State : Running

Name : KSecDD
Path : C:\WINDOWS\system32\Drivers\ksecdd.sys
Service Type : Kernel Driver
Description : KSecDD
State : Running

Name : KSecPkg
Path : C:\WINDOWS\system32\Drivers\ksecpkg.sys
Service Type : Kernel Driver
Description : KSecPkg
State : Running

Name : ksthunk
Path : C:\WINDOWS\system32\drivers\ksthunk.sys
Service Type : Kernel Driver
Description : Kernel Streaming Thunks
State : Stopped

Name : lltdio
Path : C:\WINDOWS\system32\drivers\lltdio.sys
Service Type : Kernel Driver
Description : Link-Layer Topology Discovery Mapper I/O Driver
State : Running

Name : LSI_SAS
Path : C:\WINDOWS\system32\drivers\lsi_sas.sys
Service Type : Kernel Driver
Description : LSI_SAS
State : Running

Name : LSI_SAS2i
Path : C:\WINDOWS\system32\drivers\lsi_sas2i.sys
Service Type : Kernel Driver
Description : LSI_SAS2i
State : Stopped

Name : LSI_SAS3i
Path : C:\WINDOWS\system32\drivers\lsi_sas3i.sys
Service Type : Kernel Driver
Description : LSI_SAS3i
State : Stopped

Name : LSI_SSS
Path : C:\WINDOWS\system32\drivers\lsi_sss.sys
Service Type : Kernel Driver
Description : LSI_SSS
State : Stopped

Name : luafv
Path : C:\WINDOWS\system32\drivers\luafv.sys
Service Type : File System Driver
Description : UAC File Virtualization
State : Running

Name : mausbhost
Path : C:\WINDOWS\system32\drivers\mausbhost.sys
Service Type : Kernel Driver
Description : MA-USB Host Controller Driver
State : Stopped

Name : mausbip
Path : C:\WINDOWS\system32\drivers\mausbip.sys
Service Type : Kernel Driver
Description : MA-USB IP Filter Driver
State : Stopped

Name : MbbCx
Path : C:\WINDOWS\system32\drivers\MbbCx.sys
Service Type : Kernel Driver
Description : MBB Network Adapter Class Extension
State : Stopped

Name : megasas
Path : C:\WINDOWS\system32\drivers\megasas.sys
Service Type : Kernel Driver
Description : megasas
State : Stopped

Name : megasas2i
Path : C:\WINDOWS\system32\drivers\MegaSas2i.sys
Service Type : Kernel Driver
Description : megasas2i
State : Stopped

Name : megasas35i
Path : C:\WINDOWS\system32\drivers\megasas35i.sys
Service Type : Kernel Driver
Description : megasas35i
State : Stopped

Name : megasr
Path : C:\WINDOWS\system32\drivers\megasr.sys
Service Type : Kernel Driver
Description : megasr
State : Stopped

Name : Microsoft_Bluetooth_AvrcpTransport
Path : C:\WINDOWS\system32\drivers\Microsoft.Bluetooth.AvrcpTransport.sys
Service Type : Kernel Driver
Description : Microsoft Bluetooth Avrcp Transport Driver
State : Stopped

Name : mlx4_bus
Path : C:\WINDOWS\system32\drivers\mlx4_bus.sys
Service Type : Kernel Driver
Description : Mellanox ConnectX Bus Enumerator
State : Stopped

Name : MMCSS
Path : C:\WINDOWS\system32\drivers\mmcss.sys
Service Type : Kernel Driver
Description : Multimedia Class Scheduler
State : Running

Name : Modem
Path : C:\WINDOWS\system32\drivers\modem.sys
Service Type : Kernel Driver
Description : Modem
State : Stopped

Name : monitor
Path : C:\WINDOWS\system32\drivers\monitor.sys
Service Type : Kernel Driver
Description : Microsoft Monitor Class Function Driver Service
State : Running

Name : mouclass
Path : C:\WINDOWS\system32\drivers\mouclass.sys
Service Type : Kernel Driver
Description : Mouse Class Driver
State : Running

Name : mouhid
Path : C:\WINDOWS\system32\drivers\mouhid.sys
Service Type : Kernel Driver
Description : Mouse HID Driver
State : Stopped

Name : mountmgr
Path : C:\WINDOWS\system32\drivers\mountmgr.sys
Service Type : Kernel Driver
Description : Mount Point Manager
State : Running

Name : mpsdrv
Path : C:\WINDOWS\system32\drivers\mpsdrv.sys
Service Type : Kernel Driver
Description : Windows Defender Firewall Authorization Driver
State : Running

Name : MRxDAV
Path : C:\WINDOWS\system32\drivers\mrxdav.sys
Service Type : File System Driver
Description : WebDav Client Redirector Driver
State : Stopped

Name : mrxsmb
Path : C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
Service Type : File System Driver
Description : SMB MiniRedirector Wrapper and Engine
State : Running

Name : mrxsmb20
Path : C:\WINDOWS\system32\DRIVERS\mrxsmb20.sys
Service Type : File System Driver
Description : SMB 2.0 MiniRedirector
State : Running

Name : MsBridge
Path : C:\WINDOWS\system32\drivers\bridge.sys
Service Type : Kernel Driver
Description : Microsoft MAC Bridge
State : Stopped

Name : Msfs
Path : C:\WINDOWS\system32\drivers\Msfs.sys
Service Type : File System Driver
Description : Msfs
State : Running

Name : msgpiowin32
Path : C:\WINDOWS\system32\drivers\msgpiowin32.sys
Service Type : Kernel Driver
Description : Common Driver for Buttons, DockMode and Laptop/Slate Indicator
State : Stopped

Name : mshidkmdf
Path : C:\WINDOWS\system32\drivers\mshidkmdf.sys
Service Type : Kernel Driver
Description : Pass-through HID to KMDF Filter Driver
State : Stopped

Name : mshidumdf
Path : C:\WINDOWS\system32\drivers\mshidumdf.sys
Service Type : Kernel Driver
Description : Pass-through HID to UMDF Driver
State : Stopped

Name : msisadrv
Path : C:\WINDOWS\system32\drivers\msisadrv.sys
Service Type : Kernel Driver
Description : msisadrv
State : Running

Name : MSKSSRV
Path : C:\WINDOWS\system32\drivers\MSKSSRV.sys
Service Type : Kernel Driver
Description : Microsoft Streaming Service Proxy
State : Stopped

Name : MsLldp
Path : C:\WINDOWS\system32\drivers\mslldp.sys
Service Type : Kernel Driver
Description : Microsoft Link-Layer Discovery Protocol
State : Running

Name : MSPCLOCK
Path : C:\WINDOWS\system32\drivers\MSPCLOCK.sys
Service Type : Kernel Driver
Description : Microsoft Streaming Clock Proxy
State : Stopped

Name : MSPQM
Path : C:\WINDOWS\system32\drivers\MSPQM.sys
Service Type : Kernel Driver
Description : Microsoft Streaming Quality Manager Proxy
State : Stopped

Name : MsQuic
Path : C:\WINDOWS\system32\drivers\msquic.sys
Service Type : Kernel Driver
Description : MsQuic
State : Running

Name : MsRPC
Path : C:\WINDOWS\system32\drivers\MsRPC.sys
Service Type : Kernel Driver
Description : MsRPC
State : Stopped

Name : MsSecCore
Path : C:\WINDOWS\system32\drivers\msseccore.sys
Service Type : Kernel Driver
Description : Microsoft Security Core Boot Driver
State : Running

Name : MsSecFlt
Path : C:\WINDOWS\system32\drivers\mssecflt.sys
Service Type : Kernel Driver
Description : Microsoft Security Events Component Minifilter
State : Stopped

Name : MsSecWfp
Path : C:\WINDOWS\system32\drivers\mssecwfp.sys
Service Type : Kernel Driver
Description : Microsoft Security WFP Callout Driver
State : Stopped

Name : mssmbios
Path : C:\WINDOWS\system32\drivers\mssmbios.sys
Service Type : Kernel Driver
Description : Microsoft System Management BIOS Driver
State : Running

Name : MSTEE
Path : C:\WINDOWS\system32\drivers\MSTEE.sys
Service Type : Kernel Driver
Description : Microsoft Streaming Tee/Sink-to-Sink Converter
State : Stopped

Name : MTConfig
Path : C:\WINDOWS\system32\drivers\MTConfig.sys
Service Type : Kernel Driver
Description : Microsoft Input Configuration Driver
State : Stopped

Name : Mup
Path : C:\WINDOWS\system32\Drivers\mup.sys
Service Type : File System Driver
Description : Mup
State : Running

Name : mvumis
Path : C:\WINDOWS\system32\drivers\mvumis.sys
Service Type : Kernel Driver
Description : mvumis
State : Stopped

Name : NativeWifiP
Path : C:\WINDOWS\system32\DRIVERS\nwifi.sys
Service Type : Kernel Driver
Description : NativeWiFi Filter
State : Stopped

Name : ndfltr
Path : C:\WINDOWS\system32\drivers\ndfltr.sys
Service Type : Kernel Driver
Description : NetworkDirect Service
State : Stopped

Name : NDIS
Path : C:\WINDOWS\system32\drivers\ndis.sys
Service Type : Kernel Driver
Description : NDIS System Driver
State : Running

Name : NdisCap
Path : C:\WINDOWS\system32\drivers\ndiscap.sys
Service Type : Kernel Driver
Description : Microsoft NDIS Capture
State : Running

Name : NdisImPlatform
Path : C:\WINDOWS\system32\drivers\NdisImPlatform.sys
Service Type : Kernel Driver
Description : Microsoft Network Adapter Multiplexor Protocol
State : Stopped

Name : NdisTapi
Path : C:\WINDOWS\system32\DRIVERS\ndistapi.sys
Service Type : Kernel Driver
Description : Remote Access NDIS TAPI Driver
State : Running

Name : Ndisuio
Path : C:\WINDOWS\system32\drivers\ndisuio.sys
Service Type : Kernel Driver
Description : NDIS Usermode I/O Protocol
State : Stopped

Name : NdisVirtualBus
Path : C:\WINDOWS\system32\drivers\NdisVirtualBus.sys
Service Type : Kernel Driver
Description : Microsoft Virtual Network Adapter Enumerator
State : Running

Name : NdisWan
Path : C:\WINDOWS\system32\drivers\ndiswan.sys
Service Type : Kernel Driver
Description : Remote Access NDIS WAN Driver
State : Running

Name : ndiswanlegacy
Path : C:\WINDOWS\system32\DRIVERS\ndiswan.sys
Service Type : Kernel Driver
Description : Remote Access LEGACY NDIS WAN Driver
State : Stopped

Name : NDKPing
Path : C:\WINDOWS\system32\drivers\NDKPing.sys
Service Type : Kernel Driver
Description : NDKPing Driver
State : Stopped

Name : ndproxy
Path : C:\WINDOWS\system32\DRIVERS\NDProxy.sys
Service Type : Kernel Driver
Description : NDIS Proxy Driver
State : Running

Name : Ndu
Path : C:\WINDOWS\system32\drivers\Ndu.sys
Service Type : Kernel Driver
Description : Windows Network Data Usage Monitoring Driver
State : Running

Name : NetAdapterCx
Path : C:\WINDOWS\system32\drivers\NetAdapterCx.sys
Service Type : Kernel Driver
Description : Network Adapter Wdf Class Extension Library
State : Stopped

Name : NetBIOS
Path : C:\WINDOWS\system32\drivers\netbios.sys
Service Type : File System Driver
Description : NetBIOS Interface
State : Running

Name : NetBT
Path : C:\WINDOWS\system32\DRIVERS\netbt.sys
Service Type : Kernel Driver
Description : NetBT
State : Running

Name : netvsc
Path : C:\WINDOWS\system32\drivers\netvsc.sys
Service Type : Kernel Driver
Description : netvsc
State : Stopped

Name : Npfs
Path : C:\WINDOWS\system32\drivers\Npfs.sys
Service Type : File System Driver
Description : Npfs
State : Running

Name : npsvctrig
Path : C:\WINDOWS\system32\drivers\npsvctrig.sys
Service Type : Kernel Driver
Description : Named pipe service trigger provider
State : Running

Name : nsiproxy
Path : C:\WINDOWS\system32\drivers\nsiproxy.sys
Service Type : Kernel Driver
Description : NSI Proxy Service Driver
State : Running

Name : Ntfs
Path : C:\WINDOWS\system32\drivers\Ntfs.sys
Service Type : File System Driver
Description : Ntfs
State : Running

Name : Null
Path : C:\WINDOWS\system32\drivers\Null.sys
Service Type : Kernel Driver
Description : Null
State : Running

Name : nvdimm
Path : C:\WINDOWS\system32\drivers\nvdimm.sys
Service Type : Kernel Driver
Description : Microsoft NVDIMM device driver
State : Stopped

Name : nvraid
Path : C:\WINDOWS\system32\drivers\nvraid.sys
Service Type : Kernel Driver
Description : nvraid
State : Stopped

Name : nvstor
Path : C:\WINDOWS\system32\drivers\nvstor.sys
Service Type : Kernel Driver
Description : nvstor
State : Stopped

Name : Parport
Path : C:\WINDOWS\system32\drivers\parport.sys
Service Type : Kernel Driver
Description : Parallel port driver
State : Stopped

Name : partmgr
Path : C:\WINDOWS\system32\drivers\partmgr.sys
Service Type : Kernel Driver
Description : Partition driver
State : Running

Name : pci
Path : C:\WINDOWS\system32\drivers\pci.sys
Service Type : Kernel Driver
Description : PCI Bus Driver
State : Running

Name : pciide
Path : C:\WINDOWS\system32\drivers\pciide.sys
Service Type : Kernel Driver
Description : pciide
State : Stopped

Name : pcmcia
Path : C:\WINDOWS\system32\drivers\pcmcia.sys
Service Type : Kernel Driver
Description : pcmcia
State : Stopped

Name : pcw
Path : C:\WINDOWS\system32\drivers\pcw.sys
Service Type : Kernel Driver
Description : Performance Counters for Windows Driver
State : Running

Name : pdc
Path : C:\WINDOWS\system32\drivers\pdc.sys
Service Type : Kernel Driver
Description : pdc
State : Running

Name : PEAUTH
Path : C:\WINDOWS\system32\drivers\peauth.sys
Service Type : Kernel Driver
Description : PEAUTH
State : Running

Name : percsas2i
Path : C:\WINDOWS\system32\drivers\percsas2i.sys
Service Type : Kernel Driver
Description : percsas2i
State : Stopped

Name : percsas3i
Path : C:\WINDOWS\system32\drivers\percsas3i.sys
Service Type : Kernel Driver
Description : percsas3i
State : Stopped

Name : PktMon
Path : C:\WINDOWS\system32\drivers\PktMon.sys
Service Type : Kernel Driver
Description : Packet Monitor Driver
State : Stopped

Name : pmem
Path : C:\WINDOWS\system32\drivers\pmem.sys
Service Type : Kernel Driver
Description : Microsoft persistent memory disk driver
State : Stopped

Name : PNPMEM
Path : C:\WINDOWS\system32\drivers\pnpmem.sys
Service Type : Kernel Driver
Description : Microsoft Memory Module Driver
State : Stopped

Name : portcfg
Path : C:\WINDOWS\system32\drivers\portcfg.sys
Service Type : Kernel Driver
Description : portcfg
State : Stopped

Name : PptpMiniport
Path : C:\WINDOWS\system32\drivers\raspptp.sys
Service Type : Kernel Driver
Description : WAN Miniport (PPTP)
State : Running

Name : Processor
Path : C:\WINDOWS\system32\drivers\processr.sys
Service Type : Kernel Driver
Description : Processor Driver
State : Stopped

Name : Psched
Path : C:\WINDOWS\system32\drivers\pacer.sys
Service Type : Kernel Driver
Description : QoS Packet Scheduler
State : Running

Name : QWAVEdrv
Path : C:\WINDOWS\system32\drivers\qwavedrv.sys
Service Type : Kernel Driver
Description : QWAVE driver
State : Stopped

Name : Ramdisk
Path : C:\WINDOWS\system32\DRIVERS\ramdisk.sys
Service Type : Kernel Driver
Description : Windows RAM Disk Driver
State : Stopped

Name : RasAcd
Path : C:\WINDOWS\system32\DRIVERS\rasacd.sys
Service Type : Kernel Driver
Description : Remote Access Auto Connection Driver
State : Stopped

Name : RasAgileVpn
Path : C:\WINDOWS\system32\drivers\AgileVpn.sys
Service Type : Kernel Driver
Description : WAN Miniport (IKEv2)
State : Running

Name : Rasl2tp
Path : C:\WINDOWS\system32\drivers\rasl2tp.sys
Service Type : Kernel Driver
Description : WAN Miniport (L2TP)
State : Running

Name : RasPppoe
Path : C:\WINDOWS\system32\DRIVERS\raspppoe.sys
Service Type : Kernel Driver
Description : Remote Access PPPOE Driver
State : Running

Name : RasSstp
Path : C:\WINDOWS\system32\drivers\rassstp.sys
Service Type : Kernel Driver
Description : WAN Miniport (SSTP)
State : Running

Name : rdbss
Path : C:\WINDOWS\system32\DRIVERS\rdbss.sys
Service Type : File System Driver
Description : Redirected Buffering Sub System
State : Running

Name : rdpbus
Path : C:\WINDOWS\system32\drivers\rdpbus.sys
Service Type : Kernel Driver
Description : Remote Desktop Device Redirector Bus Driver
State : Running

Name : RDPDR
Path : C:\WINDOWS\system32\drivers\rdpdr.sys
Service Type : Kernel Driver
Description : Remote Desktop Device Redirector Driver
State : Running

Name : RdpVideoMiniport
Path : C:\WINDOWS\system32\drivers\rdpvideominiport.sys
Service Type : Kernel Driver
Description : Remote Desktop Video Miniport Driver
State : Running

Name : rdyboost
Path : C:\WINDOWS\system32\drivers\rdyboost.sys
Service Type : Kernel Driver
Description : ReadyBoost
State : Running

Name : ReFS
Path : C:\WINDOWS\system32\drivers\ReFS.sys
Service Type : File System Driver
Description : ReFS
State : Stopped

Name : ReFSv1
Path : C:\WINDOWS\system32\drivers\ReFSv1.sys
Service Type : File System Driver
Description : ReFSv1
State : Stopped

Name : RFCOMM
Path : C:\WINDOWS\system32\drivers\rfcomm.sys
Service Type : Kernel Driver
Description : Bluetooth Device (RFCOMM Protocol TDI)
State : Stopped

Name : rhproxy
Path : C:\WINDOWS\system32\drivers\rhproxy.sys
Service Type : Kernel Driver
Description : Resource Hub proxy driver
State : Stopped

Name : RsFx0600
Path : C:\WINDOWS\system32\DRIVERS\RsFx0600.sys
Service Type : File System Driver
Description : RsFx0600 Driver
State : Stopped

Name : rspndr
Path : C:\WINDOWS\system32\drivers\rspndr.sys
Service Type : Kernel Driver
Description : Link-Layer Topology Discovery Responder
State : Running

Name : s3cap
Path : C:\WINDOWS\system32\drivers\vms3cap.sys
Service Type : Kernel Driver
Description : s3cap
State : Stopped

Name : sbp2port
Path : C:\WINDOWS\system32\drivers\sbp2port.sys
Service Type : Kernel Driver
Description : SBP-2 Transport/Protocol Bus Driver
State : Stopped

Name : scfilter
Path : C:\WINDOWS\system32\DRIVERS\scfilter.sys
Service Type : Kernel Driver
Description : Smart card PnP Class Filter Driver
State : Stopped

Name : scmbus
Path : C:\WINDOWS\system32\drivers\scmbus.sys
Service Type : Kernel Driver
Description : Microsoft Storage Class Memory Bus Driver
State : Stopped

Name : sdbus
Path : C:\WINDOWS\system32\drivers\sdbus.sys
Service Type : Kernel Driver
Description : sdbus
State : Running

Name : SDFRd
Path : C:\WINDOWS\system32\drivers\SDFRd.sys
Service Type : Kernel Driver
Description : SDF Reflector
State : Stopped

Name : sdstor
Path : C:\WINDOWS\system32\drivers\sdstor.sys
Service Type : Kernel Driver
Description : SD Storage Port Driver
State : Running

Name : SerCx
Path : C:\WINDOWS\system32\drivers\SerCx.sys
Service Type : Kernel Driver
Description : Serial UART Support Library
State : Stopped

Name : SerCx2
Path : C:\WINDOWS\system32\drivers\SerCx2.sys
Service Type : Kernel Driver
Description : Serial UART Support Library
State : Stopped

Name : Serenum
Path : C:\WINDOWS\system32\drivers\serenum.sys
Service Type : Kernel Driver
Description : Serenum Filter Driver
State : Stopped

Name : Serial
Path : C:\WINDOWS\system32\drivers\serial.sys
Service Type : Kernel Driver
Description : Serial port driver
State : Stopped

Name : sermouse
Path : C:\WINDOWS\system32\drivers\sermouse.sys
Service Type : Kernel Driver
Description : Serial Mouse Driver
State : Stopped

Name : sfloppy
Path : C:\WINDOWS\system32\drivers\sfloppy.sys
Service Type : Kernel Driver
Description : High-Capacity Floppy Disk Drive
State : Stopped

Name : SiSRaid2
Path : C:\WINDOWS\system32\drivers\SiSRaid2.sys
Service Type : Kernel Driver
Description : SiSRaid2
State : Stopped

Name : SiSRaid4
Path : C:\WINDOWS\system32\drivers\sisraid4.sys
Service Type : Kernel Driver
Description : SiSRaid4
State : Stopped

Name : SmartSAMD
Path : C:\WINDOWS\system32\drivers\SmartSAMD.sys
Service Type : Kernel Driver
Description : SmartSAMD
State : Stopped

Name : smbdirect
Path : C:\WINDOWS\system32\DRIVERS\smbdirect.sys
Service Type : File System Driver
Description : smbdirect
State : Stopped

Name : spaceparser
Path : C:\WINDOWS\system32\drivers\spaceparser.sys
Service Type : Kernel Driver
Description : Space Parser
State : Stopped

Name : spaceport
Path : C:\WINDOWS\system32\drivers\spaceport.sys
Service Type : Kernel Driver
Description : Storage Spaces Driver
State : Running

Name : SpatialGraphFilter
Path : C:\WINDOWS\system32\drivers\SpatialGraphFilter.sys
Service Type : Kernel Driver
Description : Holographic Spatial Graph Filter
State : Stopped

Name : SpbCx
Path : C:\WINDOWS\system32\drivers\SpbCx.sys
Service Type : Kernel Driver
Description : Simple Peripheral Bus Support Library
State : Stopped

Name : srv2
Path : C:\WINDOWS\system32\DRIVERS\srv2.sys
Service Type : File System Driver
Description : Server SMB 2.xxx Driver
State : Running

Name : srvnet
Path : C:\WINDOWS\system32\DRIVERS\srvnet.sys
Service Type : File System Driver
Description : srvnet
State : Running

Name : stexstor
Path : C:\WINDOWS\system32\drivers\stexstor.sys
Service Type : Kernel Driver
Description : stexstor
State : Stopped

Name : storahci
Path : C:\WINDOWS\system32\drivers\storahci.sys
Service Type : Kernel Driver
Description : Microsoft Standard SATA AHCI Driver
State : Stopped

Name : storflt
Path : C:\WINDOWS\system32\drivers\vmstorfl.sys
Service Type : Kernel Driver
Description : Microsoft Hyper-V Storage Accelerator
State : Stopped

Name : stornvme
Path : C:\WINDOWS\system32\drivers\stornvme.sys
Service Type : Kernel Driver
Description : Microsoft Standard NVM Express Driver
State : Stopped

Name : storqosflt
Path : C:\WINDOWS\system32\drivers\storqosflt.sys
Service Type : File System Driver
Description : Storage QoS Filter Driver
State : Running

Name : storufs
Path : C:\WINDOWS\system32\drivers\storufs.sys
Service Type : Kernel Driver
Description : Microsoft Universal Flash Storage (UFS) Driver
State : Stopped

Name : storvsc
Path : C:\WINDOWS\system32\drivers\storvsc.sys
Service Type : Kernel Driver
Description : storvsc
State : Stopped

Name : swenum
Path : C:\WINDOWS\system32\DriverStore\FileRepository\swenum.inf_amd64_16a14542b63c02af\swenum.sys
Service Type : Kernel Driver
Description : Software Bus Driver
State : Running

Name : Synth3dVsc
Path : C:\WINDOWS\system32\drivers\Synth3dVsc.sys
Service Type : Kernel Driver
Description : Synth3dVsc
State : Stopped

Name : Tcpip
Path : C:\WINDOWS\system32\drivers\tcpip.sys
Service Type : Kernel Driver
Description : TCP/IP Protocol Driver
State : Running

Name : Tcpip6
Path : C:\WINDOWS\system32\drivers\tcpip.sys
Service Type : Kernel Driver
Description : @todo.dll,-100;Microsoft IPv6 Protocol Driver
State : Stopped

Name : tcpipreg
Path : C:\WINDOWS\system32\drivers\tcpipreg.sys
Service Type : Kernel Driver
Description : TCP/IP Registry Compatibility
State : Running

Name : tdx
Path : C:\WINDOWS\system32\DRIVERS\tdx.sys
Service Type : Kernel Driver
Description : NetIO Legacy TDI Support Driver
State : Running

Name : Telemetry
Path : C:\WINDOWS\system32\drivers\IntelTA.sys
Service Type : Kernel Driver
Description : Intel(R) Telemetry Service
State : Running

Name : terminpt
Path : C:\WINDOWS\system32\drivers\terminpt.sys
Service Type : Kernel Driver
Description : Microsoft Remote Desktop Input Driver
State : Running

Name : TPM
Path : C:\WINDOWS\system32\drivers\tpm.sys
Service Type : Kernel Driver
Description : TPM
State : Stopped

Name : TsUsbFlt
Path : C:\WINDOWS\system32\drivers\tsusbflt.sys
Service Type : Kernel Driver
Description : Remote Desktop USB Hub Class Filter Driver
State : Stopped

Name : TsUsbGD
Path : C:\WINDOWS\system32\drivers\TsUsbGD.sys
Service Type : Kernel Driver
Description : Remote Desktop Generic USB Device
State : Stopped

Name : tsusbhub
Path : C:\WINDOWS\system32\drivers\tsusbhub.sys
Service Type : Kernel Driver
Description : Remote Desktop USB Hub
State : Running

Name : tunnel
Path : C:\WINDOWS\system32\drivers\tunnel.sys
Service Type : Kernel Driver
Description : Microsoft Tunnel Miniport Adapter Driver
State : Stopped

Name : UASPStor
Path : C:\WINDOWS\system32\drivers\uaspstor.sys
Service Type : Kernel Driver
Description : USB Attached SCSI (UAS) Driver
State : Running

Name : UcmCx0101
Path : C:\WINDOWS\system32\Drivers\UcmCx.sys
Service Type : Kernel Driver
Description : USB Connector Manager KMDF Class Extension
State : Stopped

Name : UcmTcpciCx0101
Path : C:\WINDOWS\system32\Drivers\UcmTcpciCx.sys
Service Type : Kernel Driver
Description : UCM-TCPCI KMDF Class Extension
State : Stopped

Name : UcmUcsiAcpiClient
Path : C:\WINDOWS\system32\drivers\UcmUcsiAcpiClient.sys
Service Type : Kernel Driver
Description : UCM-UCSI ACPI Client
State : Stopped

Name : UcmUcsiCx0101
Path : C:\WINDOWS\system32\Drivers\UcmUcsiCx.sys
Service Type : Kernel Driver
Description : UCM-UCSI KMDF Class Extension
State : Stopped

Name : UCPD
Path : C:\WINDOWS\system32\drivers\UCPD.sys
Service Type : File System Driver
Description : UCPD
State : Running

Name : Ucx01000
Path : C:\WINDOWS\system32\drivers\ucx01000.sys
Service Type : Kernel Driver
Description : USB Host Support Library
State : Running

Name : UdeCx
Path : C:\WINDOWS\system32\drivers\udecx.sys
Service Type : Kernel Driver
Description : USB Device Emulation Support Library
State : Stopped

Name : udfs
Path : C:\WINDOWS\system32\DRIVERS\udfs.sys
Service Type : File System Driver
Description : udfs
State : Stopped

Name : UEFI
Path : C:\WINDOWS\system32\DriverStore\FileRepository\uefi.inf_amd64_c1628ffa62c8e54c\UEFI.sys
Service Type : Kernel Driver
Description : Microsoft UEFI Driver
State : Stopped

Name : UevAgentDriver
Path : C:\WINDOWS\system32\drivers\UevAgentDriver.sys
Service Type : File System Driver
Description : UevAgentDriver
State : Stopped

Name : Ufx01000
Path : C:\WINDOWS\system32\drivers\ufx01000.sys
Service Type : Kernel Driver
Description : USB Function Class Extension
State : Stopped

Name : UfxChipidea
Path : C:\WINDOWS\system32\DriverStore\FileRepository\ufxchipidea.inf_amd64_1c78775fffab6a0a\UfxChipidea.sys
Service Type : Kernel Driver
Description : USB Chipidea Controller
State : Stopped

Name : ufxsynopsys
Path : C:\WINDOWS\system32\drivers\ufxsynopsys.sys
Service Type : Kernel Driver
Description : USB Synopsys Controller
State : Stopped

Name : umbus
Path : C:\WINDOWS\system32\DriverStore\FileRepository\umbus.inf_amd64_b78a9c5b6fd62c27\umbus.sys
Service Type : Kernel Driver
Description : UMBus Enumerator Driver
State : Running

Name : UmPass
Path : C:\WINDOWS\system32\drivers\umpass.sys
Service Type : Kernel Driver
Description : Microsoft UMPass Driver
State : Stopped

Name : UrsChipidea
Path : C:\WINDOWS\system32\DriverStore\FileRepository\urschipidea.inf_amd64_78ad1c14e33df968\urschipidea.sys
Service Type : Kernel Driver
Description : Chipidea USB Role-Switch Driver
State : Running

Name : UrsCx01000
Path : C:\WINDOWS\system32\drivers\urscx01000.sys
Service Type : Kernel Driver
Description : USB Role-Switch Support Library
State : Running

Name : UrsSynopsys
Path : C:\WINDOWS\system32\DriverStore\FileRepository\urssynopsys.inf_amd64_057fa37902020500\urssynopsys.sys
Service Type : Kernel Driver
Description : Synopsys USB Role-Switch Driver
State : Stopped

Name : usbaudio
Path : C:\WINDOWS\system32\drivers\usbaudio.sys
Service Type : Kernel Driver
Description : USB Audio Driver (WDM)
State : Stopped

Name : usbaudio2
Path : C:\WINDOWS\system32\drivers\usbaudio2.sys
Service Type : Kernel Driver
Description : USB Audio 2.0 Service
State : Stopped

Name : usbccgp
Path : C:\WINDOWS\system32\drivers\usbccgp.sys
Service Type : Kernel Driver
Description : Microsoft USB Generic Parent Driver
State : Running

Name : usbcir
Path : C:\WINDOWS\system32\drivers\usbcir.sys
Service Type : Kernel Driver
Description : eHome Infrared Receiver (USBCIR)
State : Stopped

Name : usbehci
Path : C:\WINDOWS\system32\drivers\usbehci.sys
Service Type : Kernel Driver
Description : Microsoft USB 2.0 Enhanced Host Controller Miniport Driver
State : Running

Name : usbhub
Path : C:\WINDOWS\system32\drivers\usbhub.sys
Service Type : Kernel Driver
Description : Microsoft USB Standard Hub Driver
State : Running

Name : USBHUB3
Path : C:\WINDOWS\system32\drivers\UsbHub3.sys
Service Type : Kernel Driver
Description : SuperSpeed Hub
State : Running

Name : usbohci
Path : C:\WINDOWS\system32\drivers\usbohci.sys
Service Type : Kernel Driver
Description : Microsoft USB Open Host Controller Miniport Driver
State : Stopped

Name : usbprint
Path : C:\WINDOWS\system32\drivers\usbprint.sys
Service Type : Kernel Driver
Description : Microsoft USB PRINTER Class
State : Stopped

Name : usbser
Path : C:\WINDOWS\system32\drivers\usbser.sys
Service Type : Kernel Driver
Description : Microsoft USB Serial Driver
State : Stopped

Name : USBSTOR
Path : C:\WINDOWS\system32\drivers\USBSTOR.SYS
Service Type : Kernel Driver
Description : USB Mass Storage Driver
State : Running

Name : usbuhci
Path : C:\WINDOWS\system32\drivers\usbuhci.sys
Service Type : Kernel Driver
Description : Microsoft USB Universal Host Controller Miniport Driver
State : Stopped

Name : USBXHCI
Path : C:\WINDOWS\system32\drivers\USBXHCI.SYS
Service Type : Kernel Driver
Description : USB xHCI Compliant Host Controller
State : Running

Name : vdrvroot
Path : C:\WINDOWS\system32\drivers\vdrvroot.sys
Service Type : Kernel Driver
Description : Microsoft Virtual Drive Enumerator
State : Running

Name : VerifierExt
Path : C:\WINDOWS\system32\drivers\VerifierExt.sys
Service Type : Kernel Driver
Description : Driver Verifier Extension
State : Stopped

Name : vhdmp
Path : C:\WINDOWS\system32\drivers\vhdmp.sys
Service Type : Kernel Driver
Description : vhdmp
State : Stopped

Name : vhf
Path : C:\WINDOWS\system32\drivers\vhf.sys
Service Type : Kernel Driver
Description : Virtual HID Framework (VHF) Driver
State : Stopped

Name : Vid
Path : C:\WINDOWS\system32\drivers\Vid.sys
Service Type : Kernel Driver
Description : Vid
State : Running

Name : VirtualRender
Path : C:\WINDOWS\system32\DriverStore\FileRepository\vrd.inf_amd64_81fbd405ff2470fc\vrd.sys
Service Type : Kernel Driver
Description : VirtualRender
State : Stopped

Name : vm3dmp
Path : C:\WINDOWS\system32\DRIVERS\vm3dmp.sys
Service Type : Kernel Driver
Description : vm3dmp
State : Running

Name : vm3dmp-debug
Path : C:\WINDOWS\system32\DRIVERS\vm3dmp-debug.sys
Service Type : Kernel Driver
Description : vm3dmp-debug
State : Stopped

Name : vm3dmp-stats
Path : C:\WINDOWS\system32\DRIVERS\vm3dmp-stats.sys
Service Type : Kernel Driver
Description : vm3dmp-stats
State : Stopped

Name : vm3dmp_loader
Path : C:\WINDOWS\system32\DRIVERS\vm3dmp_loader.sys
Service Type : Kernel Driver
Description : vm3dmp_loader
State : Running

Name : vmbus
Path : C:\WINDOWS\system32\drivers\vmbus.sys
Service Type : Kernel Driver
Description : Virtual Machine Bus
State : Stopped

Name : VMBusHID
Path : C:\WINDOWS\system32\drivers\VMBusHID.sys
Service Type : Kernel Driver
Description : VMBusHID
State : Stopped

Name : vmci
Path : C:\WINDOWS\system32\drivers\vmci.sys
Service Type : Kernel Driver
Description : VMware VMCI Bus Driver
State : Running

Name : vmgid
Path : C:\WINDOWS\system32\drivers\vmgid.sys
Service Type : Kernel Driver
Description : Microsoft Hyper-V Guest Infrastructure Driver
State : Stopped

Name : VMMemCtl
Path : C:\WINDOWS\system32\DRIVERS\vmmemctl.sys
Service Type : Kernel Driver
Description : Memory Control Driver
State : Running

Name : vmmouse
Path : C:\WINDOWS\system32\drivers\vmmouse.sys
Service Type : Kernel Driver
Description : VMware Pointing Device
State : Running

Name : volmgr
Path : C:\WINDOWS\system32\drivers\volmgr.sys
Service Type : Kernel Driver
Description : Volume Manager Driver
State : Running

Name : volmgrx
Path : C:\WINDOWS\system32\drivers\volmgrx.sys
Service Type : Kernel Driver
Description : Dynamic Volume Manager
State : Running

Name : volsnap
Path : C:\WINDOWS\system32\drivers\volsnap.sys
Service Type : Kernel Driver
Description : Volume Shadow Copy driver
State : Running

Name : volume
Path : C:\WINDOWS\system32\drivers\volume.sys
Service Type : Kernel Driver
Description : Volume driver
State : Running

Name : vpci
Path : C:\WINDOWS\system32\drivers\vpci.sys
Service Type : Kernel Driver
Description : Microsoft Hyper-V Virtual PCI Bus
State : Stopped

Name : vsmraid
Path : C:\WINDOWS\system32\drivers\vsmraid.sys
Service Type : Kernel Driver
Description : vsmraid
State : Stopped

Name : vsock
Path : C:\WINDOWS\system32\DRIVERS\vsock.sys
Service Type : Kernel Driver
Description : vSockets Virtual Machine Communication Interface Sockets driver
State : Running

Name : VSTXRAID
Path : C:\WINDOWS\system32\drivers\vstxraid.sys
Service Type : Kernel Driver
Description : VIA StorX Storage RAID Controller Windows Driver
State : Stopped

Name : vwifibus
Path : C:\WINDOWS\system32\drivers\vwifibus.sys
Service Type : Kernel Driver
Description : Virtual Wireless Bus Driver
State : Stopped

Name : vwififlt
Path : C:\WINDOWS\system32\drivers\vwififlt.sys
Service Type : Kernel Driver
Description : Virtual WiFi Filter Driver
State : Running

Name : WacomPen
Path : C:\WINDOWS\system32\drivers\wacompen.sys
Service Type : Kernel Driver
Description : Wacom Serial Pen HID Driver
State : Stopped

Name : wanarp
Path : C:\WINDOWS\system32\DRIVERS\wanarp.sys
Service Type : Kernel Driver
Description : Remote Access IP ARP Driver
State : Running

Name : wanarpv6
Path : C:\WINDOWS\system32\DRIVERS\wanarp.sys
Service Type : Kernel Driver
Description : Remote Access IPv6 ARP Driver
State : Stopped

Name : wcifs
Path : C:\WINDOWS\system32\drivers\wcifs.sys
Service Type : File System Driver
Description : Windows Container Isolation
State : Running

Name : wcnfs
Path : C:\WINDOWS\system32\drivers\wcnfs.sys
Service Type : File System Driver
Description : Windows Container Name Virtualization
State : Stopped

Name : WdBoot
Path : C:\WINDOWS\system32\drivers\wd\WdBoot.sys
Service Type : Kernel Driver
Description : Microsoft Defender Antivirus Boot Driver
State : Stopped

Name : Wdf01000
Path : C:\WINDOWS\system32\drivers\Wdf01000.sys
Service Type : Kernel Driver
Description : Kernel Mode Driver Frameworks service
State : Running

Name : WdFilter
Path : C:\WINDOWS\system32\drivers\wd\WdFilter.sys
Service Type : File System Driver
Description : Microsoft Defender Antivirus Mini-Filter Driver
State : Stopped

Name : wdiwifi
Path : C:\WINDOWS\system32\DRIVERS\wdiwifi.sys
Service Type : Kernel Driver
Description : WDI Driver Framework
State : Stopped

Name : WdmCompanionFilter
Path : C:\WINDOWS\system32\drivers\WdmCompanionFilter.sys
Service Type : Kernel Driver
Description : WdmCompanionFilter
State : Stopped

Name : WdNisDrv
Path : C:\WINDOWS\system32\drivers\wd\WdNisDrv.sys
Service Type : Kernel Driver
Description : Microsoft Defender Antivirus Network Inspection System Driver
State : Stopped

Name : WFPLWFS
Path : C:\WINDOWS\system32\drivers\wfplwfs.sys
Service Type : Kernel Driver
Description : Microsoft Windows Filtering Platform
State : Running

Name : WIMMount
Path : C:\WINDOWS\system32\drivers\wimmount.sys
Service Type : File System Driver
Description : WIMMount
State : Stopped

Name : WindowsTrustedRT
Path : C:\WINDOWS\system32\drivers\WindowsTrustedRT.sys
Service Type : Kernel Driver
Description : Windows Trusted Execution Environment Class Extension
State : Running

Name : WindowsTrustedRTProxy
Path : C:\WINDOWS\system32\drivers\WindowsTrustedRTProxy.sys
Service Type : Kernel Driver
Description : Microsoft Windows Trusted Runtime Secure Service
State : Running

Name : WinMad
Path : C:\WINDOWS\system32\drivers\winmad.sys
Service Type : Kernel Driver
Description : WinMad Service
State : Stopped

Name : WinNat
Path : C:\WINDOWS\system32\drivers\winnat.sys
Service Type : Kernel Driver
Description : Windows NAT Driver
State : Stopped

Name : WINUSB
Path : C:\WINDOWS\system32\drivers\WinUSB.SYS
Service Type : Kernel Driver
Description : WinUsb Driver
State : Stopped

Name : WinVerbs
Path : C:\WINDOWS\system32\drivers\winverbs.sys
Service Type : Kernel Driver
Description : WinVerbs Service
State : Stopped

Name : WmiAcpi
Path : C:\WINDOWS\system32\drivers\wmiacpi.sys
Service Type : Kernel Driver
Description : Microsoft Windows Management Interface for ACPI
State : Stopped

Name : Wof
Path : C:\WINDOWS\system32\drivers\Wof.sys
Service Type : File System Driver
Description : Windows Overlay File System Filter Driver
State : Running

Name : WpdUpFltr
Path : C:\WINDOWS\system32\drivers\WpdUpFltr.sys
Service Type : Kernel Driver
Description : WPD Upper Class Filter Driver
State : Running

Name : ws2ifsl
Path : C:\WINDOWS\system32\drivers\ws2ifsl.sys
Service Type : Kernel Driver
Description : Windows Socket 2.0 Non-IFS Service Provider Support Environment
State : Running

Name : WudfPf
Path : C:\WINDOWS\system32\drivers\WudfPf.sys
Service Type : Kernel Driver
Description : User Mode Driver Frameworks Platform Driver
State : Stopped

Name : WUDFRd
Path : C:\WINDOWS\system32\drivers\WUDFRd.sys
Service Type : Kernel Driver
Description : Windows Driver Foundation - User-mode Driver Framework Reflector
State : Running

Name : WUDFWpdFs
Path : C:\WINDOWS\system32\drivers\WUDFRd.sys
Service Type : Kernel Driver
Description : WPD File System driver
State : Running

Name : xboxgip
Path : C:\WINDOWS\system32\drivers\xboxgip.sys
Service Type : Kernel Driver
Description : Xbox Game Input Protocol Driver
State : Stopped

Name : xinputhid
Path : C:\WINDOWS\system32\drivers\xinputhid.sys
Service Type : Kernel Driver
Description : XINPUT HID Filter Driver
State : Stopped

Name : klids.KES-21-15
Path : \??\C:\ProgramData\Kaspersky Lab\KES.21.15\Bases\klids.sys
Service Type : Kernel Driver
Description : klids.KES-21-15
State : Running
Compliance 'FAILED'
Compliance 'SKIPPED'
Compliance 'PASSED'
Compliance 'INFO', 'WARNING', 'ERROR'
Remediations
Suggested Remediations
Taking the following actions across 3 hosts would resolve 32% of the vulnerabilities on the network.
Action to take Vulns Hosts
Oracle Java SE Multiple Vulnerabilities (October 2025 CPU): Apply the appropriate patch according to the October 2025 Oracle Critical Patch Update advisory. 305 1
Mozilla Thunderbird < 140.6: Upgrade to Mozilla Thunderbird version 140.6 or later. 272 1
Oracle Database Multiple Vulnerabilities (April 2012 CPU): Apply the appropriate patch according to the April 2012 Oracle Critical Patch Update advisory. 174 1
Mozilla Firefox < 146.0.1: Upgrade to Mozilla Firefox version 146.0.1 or later. 162 1
Wireshark 2.0.x < 2.0.16 DMP dissector DoS: Upgrade to Wireshark version 2.0.16 or later. 98 1
Security Updates for Microsoft Excel Products (December 2025): Microsoft has released KB5002820 to address this issue. 42 1
Install KB5071544 42 1
Security Updates for Microsoft Office Products (December 2025): Microsoft has released the following updates to address these issues: - KB5002812 - KB5002818 - KB5002819 38 1
Security Updates for Microsoft .NET Framework (January 2025): Microsoft has released security updates for Microsoft .NET Framework. 28 1
Security Updates for Microsoft SQL Server OLE DB Driver (July 2024): Microsoft has released security updates for the Microsoft SQL OLE DB Driver. 28 1
Security Updates for Microsoft SQL Server ODBC Driver (April 2024): Microsoft has released security updates for the Microsoft SQL Driver. 25 1
7-Zip < 25.01: Upgrade to 7-Zip version 25.01 or later. 22 2
Notepad++ < 8.8.2 Privilege Escalation (CVE-2025-49144): Upgrade to Notepad++ 8.8.2 or later. 21 3
RARLAB WinRAR < 7.13 Directory Traversal (CVE-2025-8088): Upgrade to RARLAB WinRAR version 7.13 or later. 21 3
Security Updates for Microsoft Word Products (December 2025): Microsoft has released KB5002806 to address this issue. 13 1
Mozilla Thunderbird < 146.0: Upgrade to Mozilla Thunderbird version 146.0 or later. 13 1
Security Updates for Microsoft .NET Core (December 2022): Update .NET Core Runtime to version 3.1.32 or 6.0.12 or 7.0.1. 11 1
VMware Tools 11.x < 12.5.4 / 13.x < 13.0.5 Multiple Vulnerabilities (VMSA-2025-0015): Upgrade to VMware Tools version 12.5.4, 13.0.5 or later. 10 2
Install KB5071543 9 1
Security Updates for Microsoft SQL Server (November 2025): Microsoft has released security updates for Microsoft SQL Server. 9 1
Install KB5002820 8 1
Install KB5071546 6 1
Install KB5002806 6 1
Microsoft Paint 3D Code Execution (July 2023): Upgrade the Windows 'Paint 3D' app to version 6.2305.16087.0, or later via the Microsoft Store. 6 1
Install KB5002790 5 1
Security Updates for Microsoft PowerPoint Products (October 2025): Microsoft has released KB5002790 to address this issue. 5 1
Oracle MySQL Connectors (October 2024 CPU): Apply the appropriate patch according to the October 2024 Oracle Critical Patch Update advisory. 5 1
Git for Windows < 2.45.1 Multiple Vulnerabilities: Upgrade to Git for Windows 2.45.1 or later. 5 1
Security Updates for Outlook (July 2025): Microsoft has released KB5002747 to address this issue. 2 1
JQuery 1.2 < 3.5.0 Multiple XSS: Upgrade to JQuery version 3.5.0 or later. 2 1
Security Updates for Microsoft ASP.NET Core (December 2022): Update ASP.NET Core Runtime to version 3.1.32 or 6.0.12 or 7.0.1. 2 1
Install KB5002683 1 1
Microsoft OneNote Spoofing(June 2023): Upgrade the Windows 'Microsoft OneNote' app to version 16.0.14326.21450 or later via the Microsoft Store. 1 1
Microsoft Print 3D app Remote Code Execution (February 2023): Upgrade to the Microsoft 3D Builder app via the Windows App Store. 1 1
Apache Log4j 1.2 JMSAppender Remote Code Execution (CVE-2021-4104): Upgrade to Apache Log4j version 2.16.0 or later since 1.x is end of life. Upgrading to the latest versions for Apache Log4j is highly recommended as intermediate versions / patches have known high severity vulnerabilities and the vendor is updating their advisories often as new research and knowledge about the impact of Log4j is discovered. Refer to https://logging.apache.org/log4j/2.x/security.html for the latest versions. 1 1
Visual Studio Tools for Applications Elevation of Privilege (CVE-2025-29803): Upgrade to VSTA 16.0.35907.0, 17.0.35906.0 or later. 1 1
Curl Use-After-Free < 7.87 (CVE-2022-43552): Upgrade Curl to version 7.87.0 or later 1 1
MS13-045: Vulnerability in Windows Essentials Could Allow Information Disclosure (2813707): Microsoft has released a patch for Windows Essentials 2012. 1 1
Microsoft Azure Data Studio < 1.48.0 Elevation of Privilege Vulnerability (CVE-2024-26203): Upgrade to Microsoft Azure Data Studio version 1.48.0 or later. 0 3
© 2026 Tenable™, Inc. All rights reserved.