System/Kernel


PS C:\xampp\htdocs\uploads> cmd /c ver
 
Microsoft Windows [Version 10.0.17763.2746]
 
PS C:\xampp\htdocs\uploads> systeminfo ; Get-ComputerInfo
 
Host Name:                 SERVER
OS Name:                   Microsoft Windows Server 2019 Standard
OS Version:                10.0.17763 N/A Build 17763
OS Manufacturer:           Microsoft Corporation
OS Configuration:          Primary Domain Controller
OS Build Type:             Multiprocessor Free
Registered Owner:          Windows User
Registered Organization:   
Product ID:                00429-70000-00000-AA169
Original Install Date:     5/28/2021, 2:52:51 AM
System Boot Time:          1/8/2025, 12:36:30 PM
System Manufacturer:       VMware, Inc.
System Model:              VMware7,1
System Type:               x64-based PC
Processor(s):              1 Processor(s) Installed.
                           [01]: AMD64 Family 25 Model 1 Stepping 1 AuthenticAMD ~2650 Mhz
BIOS Version:              VMware, Inc. VMW71.00V.21100432.B64.2301110304, 1/11/2023
Windows Directory:         C:\Windows
System Directory:          C:\Windows\system32
Boot Device:               \Device\HarddiskVolume2
System Locale:             en-us;English (United States)
Input Locale:              en-us;English (United States)
Time Zone:                 (UTC-08:00) Pacific Time (US & Canada)
Total Physical Memory:     2,047 MB
Available Physical Memory: 276 MB
Virtual Memory: Max Size:  2,672 MB
Virtual Memory: Available: 782 MB
Virtual Memory: In Use:    1,890 MB
Page File Location(s):     C:\pagefile.sys
Domain:                    access.offsec
Logon Server:              N/A
Hotfix(s):                 13 Hotfix(s) Installed.
                           [01]: KB5009472
                           [02]: KB4512577
                           [03]: KB4535680
                           [04]: KB4577586
                           [05]: KB4589208
                           [06]: KB5003243
                           [07]: KB5003711
                           [08]: KB5005112
                           [09]: KB5011551
                           [10]: KB5006754
                           [11]: KB5009642
                           [12]: KB5011574
                           [13]: KB5005701
Network Card(s):           1 NIC(s) Installed.
                           [01]: vmxnet3 Ethernet Adapter
                                 Connection Name: Ethernet0 2
                                 DHCP Enabled:    No
                                 IP address(es)
                                 [01]: 192.168.224.187
Hyper-V Requirements:      A hypervisor has been detected. Features required for Hyper-V will not be displayed.
 
 
WindowsBuildLabEx                                       : 17763.1.amd64fre.rs5_release.180914-1434
WindowsCurrentVersion                                   : 6.3
WindowsEditionId                                        : ServerStandard
WindowsInstallationType                                 : Server
WindowsInstallDateFromRegistry                          : 5/28/2021 10:52:51 AM
WindowsProductId                                        : 00429-70000-00000-AA169
WindowsProductName                                      : Windows Server 2019 Standard
WindowsRegisteredOrganization                           : 
WindowsRegisteredOwner                                  : Windows User
WindowsSystemRoot                                       : C:\Windows
WindowsVersion                                          : 1809
BiosCharacteristics                                     : 
BiosBIOSVersion                                         : 
BiosBuildNumber                                         : 
BiosCaption                                             : 
BiosCodeSet                                             : 
BiosCurrentLanguage                                     : 
BiosDescription                                         : 
BiosEmbeddedControllerMajorVersion                      : 
BiosEmbeddedControllerMinorVersion                      : 
BiosFirmwareType                                        : 
BiosIdentificationCode                                  : 
BiosInstallableLanguages                                : 
BiosInstallDate                                         : 
BiosLanguageEdition                                     : 
BiosListOfLanguages                                     : 
BiosManufacturer                                        : 
BiosName                                                : 
BiosOtherTargetOS                                       : 
BiosPrimaryBIOS                                         : 
BiosReleaseDate                                         : 
BiosSeralNumber                                         : 
BiosSMBIOSBIOSVersion                                   : 
BiosSMBIOSMajorVersion                                  : 
BiosSMBIOSMinorVersion                                  : 
BiosSMBIOSPresent                                       : 
BiosSoftwareElementState                                : 
BiosStatus                                              : 
BiosSystemBiosMajorVersion                              : 
BiosSystemBiosMinorVersion                              : 
BiosTargetOperatingSystem                               : 
BiosVersion                                             : 
CsAdminPasswordStatus                                   : 
CsAutomaticManagedPagefile                              : 
CsAutomaticResetBootOption                              : 
CsAutomaticResetCapability                              : 
CsBootOptionOnLimit                                     : 
CsBootOptionOnWatchDog                                  : 
CsBootROMSupported                                      : 
CsBootStatus                                            : 
CsBootupState                                           : 
CsCaption                                               : 
CsChassisBootupState                                    : 
CsChassisSKUNumber                                      : 
CsCurrentTimeZone                                       : 
CsDaylightInEffect                                      : 
CsDescription                                           : 
CsDNSHostName                                           : 
CsDomain                                                : 
CsDomainRole                                            : 
CsEnableDaylightSavingsTime                             : 
CsFrontPanelResetStatus                                 : 
CsHypervisorPresent                                     : 
CsInfraredSupported                                     : 
CsInitialLoadInfo                                       : 
CsInstallDate                                           : 
CsKeyboardPasswordStatus                                : 
CsLastLoadInfo                                          : 
CsManufacturer                                          : 
CsModel                                                 : 
CsName                                                  : 
CsNetworkAdapters                                       : 
CsNetworkServerModeEnabled                              : 
CsNumberOfLogicalProcessors                             : 
CsNumberOfProcessors                                    : 
CsProcessors                                            : 
CsOEMStringArray                                        : 
CsPartOfDomain                                          : 
CsPauseAfterReset                                       : 
CsPCSystemType                                          : 
CsPCSystemTypeEx                                        : 
CsPowerManagementCapabilities                           : 
CsPowerManagementSupported                              : 
CsPowerOnPasswordStatus                                 : 
CsPowerState                                            : 
CsPowerSupplyState                                      : 
CsPrimaryOwnerContact                                   : 
CsPrimaryOwnerName                                      : 
CsResetCapability                                       : 
CsResetCount                                            : 
CsResetLimit                                            : 
CsRoles                                                 : 
CsStatus                                                : 
CsSupportContactDescription                             : 
CsSystemFamily                                          : 
CsSystemSKUNumber                                       : 
CsSystemType                                            : 
CsThermalState                                          : 
CsTotalPhysicalMemory                                   : 
CsPhyicallyInstalledMemory                              : 
CsUserName                                              : 
CsWakeUpType                                            : 
CsWorkgroup                                             : 
OsName                                                  : 
OsType                                                  : 
OsOperatingSystemSKU                                    : 
OsVersion                                               : 
OsCSDVersion                                            : 
OsBuildNumber                                           : 
OsHotFixes                                              : 
OsBootDevice                                            : 
OsSystemDevice                                          : 
OsSystemDirectory                                       : 
OsSystemDrive                                           : 
OsWindowsDirectory                                      : 
OsCountryCode                                           : 
OsCurrentTimeZone                                       : 
OsLocaleID                                              : 
OsLocale                                                : 
OsLocalDateTime                                         : 
OsLastBootUpTime                                        : 
OsUptime                                                : 
OsBuildType                                             : 
OsCodeSet                                               : 
OsDataExecutionPreventionAvailable                      : 
OsDataExecutionPrevention32BitApplications              : 
OsDataExecutionPreventionDrivers                        : 
OsDataExecutionPreventionSupportPolicy                  : 
OsDebug                                                 : 
OsDistributed                                           : 
OsEncryptionLevel                                       : 
OsForegroundApplicationBoost                            : 
OsTotalVisibleMemorySize                                : 
OsFreePhysicalMemory                                    : 
OsTotalVirtualMemorySize                                : 
OsFreeVirtualMemory                                     : 
OsInUseVirtualMemory                                    : 
OsTotalSwapSpaceSize                                    : 
OsSizeStoredInPagingFiles                               : 
OsFreeSpaceInPagingFiles                                : 
OsPagingFiles                                           : 
OsHardwareAbstractionLayer                              : 
OsInstallDate                                           : 
OsManufacturer                                          : 
OsMaxNumberOfProcesses                                  : 
OsMaxProcessMemorySize                                  : 
OsMuiLanguages                                          : 
OsNumberOfLicensedUsers                                 : 
OsNumberOfProcesses                                     : 
OsNumberOfUsers                                         : 
OsOrganization                                          : 
OsArchitecture                                          : 
OsLanguage                                              : 
OsProductSuites                                         : 
OsOtherTypeDescription                                  : 
OsPAEEnabled                                            : 
OsPortableOperatingSystem                               : 
OsPrimary                                               : 
OsProductType                                           : 
OsRegisteredUser                                        : 
OsSerialNumber                                          : 
OsServicePackMajorVersion                               : 
OsServicePackMinorVersion                               : 
OsStatus                                                : 
OsSuites                                                : 
OsServerLevel                                           : FullServer
KeyboardLayout                                          : 
TimeZone                                                : (UTC-08:00) Pacific Time (US & Canada)
LogonServer                                             : 
PowerPlatformRole                                       : Desktop
HyperVisorPresent                                       : 
HyperVRequirementDataExecutionPreventionAvailable       : 
HyperVRequirementSecondLevelAddressTranslation          : 
HyperVRequirementVirtualizationFirmwareEnabled          : 
HyperVRequirementVMMonitorModeExtensions                : 
DeviceGuardSmartStatus                                  : Off
DeviceGuardRequiredSecurityProperties                   : 
DeviceGuardAvailableSecurityProperties                  : 
DeviceGuardSecurityServicesConfigured                   : 
DeviceGuardSecurityServicesRunning                      : 
DeviceGuardCodeIntegrityPolicyEnforcementStatus         : 
DeviceGuardUserModeCodeIntegrityPolicyEnforcementStatus : 
  • Microsoft Windows [Version 10.0.17763.2746]
  • OS Name: Microsoft Windows Server 2019 Standard
  • System Type: x64-based PC
  • Processor(s): 1 Processor(s) Installed.
  • Hotfix(s): 13 Hotfix(s) Installed.
    • [01]: KB5009472
    • [02]: KB4512577
    • [03]: KB4535680
    • [04]: KB4577586
    • [05]: KB4589208
    • [06]: KB5003243
    • [07]: KB5003711
    • [08]: KB5005112
    • [09]: KB5011551
    • [10]: KB5006754
    • [11]: KB5009642
    • [12]: KB5011574
    • [13]: KB5005701

Networks


PS C:\xampp\htdocs\uploads> ipconfig /all ; arp -a ; print route
 
Windows IP Configuration
 
   Host Name . . . . . . . . . . . . : SERVER
   Primary Dns Suffix  . . . . . . . : access.offsec
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No
   DNS Suffix Search List. . . . . . : access.offsec
 
Ethernet adapter Ethernet0 2:
 
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : vmxnet3 Ethernet Adapter
   Physical Address. . . . . . . . . : 00-50-56-9E-A1-DC
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
   IPv4 Address. . . . . . . . . . . : 192.168.224.187(Preferred) 
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : 192.168.224.254
   DNS Servers . . . . . . . . . . . : 192.168.224.254
   NetBIOS over Tcpip. . . . . . . . : Enabled
 
Interface: 192.168.224.187 --- 0x7
  Internet Address      Physical Address      Type
  192.168.224.254       00-50-56-9e-b8-c6     dynamic   
  192.168.224.255       ff-ff-ff-ff-ff-ff     static    
  224.0.0.22            01-00-5e-00-00-16     static    
  224.0.0.251           01-00-5e-00-00-fb     static    
  224.0.0.252           01-00-5e-00-00-fc     static    
  255.255.255.255       ff-ff-ff-ff-ff-ff     static    
Unable to initialize device PRN
PS C:\xampp\htdocs\uploads> netstat -ano | Select-String LIST
 
  TCP    0.0.0.0:80             0.0.0.0:0              LISTENING       3316
  TCP    0.0.0.0:88             0.0.0.0:0              LISTENING       632
  TCP    0.0.0.0:135            0.0.0.0:0              LISTENING       888
  TCP    0.0.0.0:389            0.0.0.0:0              LISTENING       632
  TCP    0.0.0.0:443            0.0.0.0:0              LISTENING       3316
  TCP    0.0.0.0:445            0.0.0.0:0              LISTENING       4
  TCP    0.0.0.0:464            0.0.0.0:0              LISTENING       632
  TCP    0.0.0.0:593            0.0.0.0:0              LISTENING       888
  TCP    0.0.0.0:636            0.0.0.0:0              LISTENING       632
  TCP    0.0.0.0:3268           0.0.0.0:0              LISTENING       632
  TCP    0.0.0.0:3269           0.0.0.0:0              LISTENING       632
  TCP    0.0.0.0:5985           0.0.0.0:0              LISTENING       4
  TCP    0.0.0.0:9389           0.0.0.0:0              LISTENING       2188
  TCP    0.0.0.0:47001          0.0.0.0:0              LISTENING       4
  TCP    0.0.0.0:49664          0.0.0.0:0              LISTENING       488
  TCP    0.0.0.0:49665          0.0.0.0:0              LISTENING       408
  TCP    0.0.0.0:49666          0.0.0.0:0              LISTENING       632
  TCP    0.0.0.0:49668          0.0.0.0:0              LISTENING       1188
  TCP    0.0.0.0:49669          0.0.0.0:0              LISTENING       1280
  TCP    0.0.0.0:49670          0.0.0.0:0              LISTENING       632
  TCP    0.0.0.0:49671          0.0.0.0:0              LISTENING       632
  TCP    0.0.0.0:49674          0.0.0.0:0              LISTENING       1932
  TCP    0.0.0.0:49679          0.0.0.0:0              LISTENING       624
  TCP    0.0.0.0:49701          0.0.0.0:0              LISTENING       2228
  TCP    0.0.0.0:49795          0.0.0.0:0              LISTENING       2200
  TCP    127.0.0.1:53           0.0.0.0:0              LISTENING       2228
  TCP    192.168.224.187:53     0.0.0.0:0              LISTENING       2228
  TCP    192.168.224.187:139    0.0.0.0:0              LISTENING       4
  TCP    [::]:80                [::]:0                 LISTENING       3316
  TCP    [::]:88                [::]:0                 LISTENING       632
  TCP    [::]:135               [::]:0                 LISTENING       888
  TCP    [::]:443               [::]:0                 LISTENING       3316
  TCP    [::]:445               [::]:0                 LISTENING       4
  TCP    [::]:464               [::]:0                 LISTENING       632
  TCP    [::]:593               [::]:0                 LISTENING       888
  TCP    [::]:5985              [::]:0                 LISTENING       4
  TCP    [::]:9389              [::]:0                 LISTENING       2188
  TCP    [::]:47001             [::]:0                 LISTENING       4
  TCP    [::]:49664             [::]:0                 LISTENING       488
  TCP    [::]:49665             [::]:0                 LISTENING       408
  TCP    [::]:49666             [::]:0                 LISTENING       632
  TCP    [::]:49668             [::]:0                 LISTENING       1188
  TCP    [::]:49669             [::]:0                 LISTENING       1280
  TCP    [::]:49670             [::]:0                 LISTENING       632
  TCP    [::]:49671             [::]:0                 LISTENING       632
  TCP    [::]:49674             [::]:0                 LISTENING       1932
  TCP    [::]:49679             [::]:0                 LISTENING       624
  TCP    [::]:49701             [::]:0                 LISTENING       2228
  TCP    [::]:49795             [::]:0                 LISTENING       2200
  TCP    [::1]:53               [::]:0                 LISTENING       2228

Users & Groups


PS C:\xampp\htdocs\uploads> net users ; ls C:\Users
 
User accounts for \\SERVER
 
-------------------------------------------------------------------------------
Administrator            Guest                    krbtgt                   
svc_apache               svc_mssql                
The command completed successfully.
 
 
 
    Directory: C:\Users
 
 
Mode                LastWriteTime         Length Name                                                                  
----                -------------         ------ ----                                                                  
d-----         1/8/2025   6:28 AM                Administrator                                                         
d-r---        5/28/2021   3:53 AM                Public                                                                
d-----         1/8/2025   6:27 AM                svc_apache                                                            
d-----         4/8/2022   2:40 AM                svc_mssql                                                             

svc_mssql

PS C:\xampp\htdocs\uploads> net localgroup ; net group /DOMAIN
 
Aliases for \\SERVER
 
-------------------------------------------------------------------------------
*Access Control Assistance Operators
*Account Operators
*Administrators
*Allowed RODC Password Replication Group
*Backup Operators
*Cert Publishers
*Certificate Service DCOM Access
*Cryptographic Operators
*Denied RODC Password Replication Group
*Distributed COM Users
*DnsAdmins
*Event Log Readers
*Guests
*Hyper-V Administrators
*IIS_IUSRS
*Incoming Forest Trust Builders
*Network Configuration Operators
*Performance Log Users
*Performance Monitor Users
*Pre-Windows 2000 Compatible Access
*Print Operators
*RAS and IAS Servers
*RDS Endpoint Servers
*RDS Management Servers
*RDS Remote Access Servers
*Remote Desktop Users
*Remote Management Users
*Replicator
*Server Operators
*Storage Replica Administrators
*Terminal Server License Servers
*Users
*Windows Authorization Access Group
The command completed successfully.
 
 
Group Accounts for \\SERVER
 
-------------------------------------------------------------------------------
*Cloneable Domain Controllers
*DnsUpdateProxy
*Domain Admins
*Domain Computers
*Domain Controllers
*Domain Guests
*Domain Users
*Enterprise Admins
*Enterprise Key Admins
*Enterprise Read-only Domain Controllers
*Group Policy Creator Owners
*Key Admins
*Protected Users
*Read-only Domain Controllers
*Schema Admins
The command completed successfully.

Processes


PS C:\xampp\htdocs\uploads> Get-WmiObject Win32_Process | % { $s = (Get-CimInstance Win32_Service | ? { $_.ProcessId -eq $_.ProcessId }).Name -join ", "; $u = $_.GetOwner(); [PSCustomObject]@{ Name = $_.Name; PID = $_.ProcessId; User = "$($u.Domain)$($u.User)"; Services = $s } } | ft -AutoSize
 
Name                                       PID User             Services                                               
----                                       --- ----             --------                                               
System Idle Process                          0                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
System                                       4                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
Registry                                    88                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
smss.exe                                   280                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
csrss.exe                                  384                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
wininit.exe                                488                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
csrss.exe                                  496                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
winlogon.exe                               552                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
services.exe                               624                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
lsass.exe                                  632                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
svchost.exe                                836                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
svchost.exe                                888                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
dwm.exe                                    972                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
svchost.exe                               1012                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
svchost.exe                               1020                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
svchost.exe                                336                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
svchost.exe                                408                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
svchost.exe                                480                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
svchost.exe                               1112                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
svchost.exe                               1188                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
svchost.exe                               1280                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
svchost.exe                               1308                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
svchost.exe                               1816                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
fontdrvhost.exe                           1364                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
fontdrvhost.exe                           1432                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
spoolsv.exe                               1932                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
svchost.exe                               2124                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
svchost.exe                               2132                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
ismserv.exe                               2172                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
Microsoft.ActiveDirectory.WebServices.exe 2188                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
dfsrs.exe                                 2200                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
vm3dservice.exe                           2208                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
vmtoolsd.exe                              2220                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
dns.exe                                   2228                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
VGAuthService.exe                         2236                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
MsMpEng.exe                               2296                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
dfssvc.exe                                2304                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
vm3dservice.exe                           2440                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
vds.exe                                   2752                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
WmiPrvSE.exe                              2852                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
dllhost.exe                               2904                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
msdtc.exe                                 2844                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
LogonUI.exe                               3128                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
httpd.exe                                 3316 ACCESSsvc_apache ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
httpd.exe                                 3336 ACCESSsvc_apache ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
TrustedInstaller.exe                      4908                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
GenValObj.exe                             1428                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
taskhostw.exe                                8                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
TiWorker.exe                              4800                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
SecurityHealthService.exe                 1836                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
cmd.exe                                   2640 ACCESSsvc_apache ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
conhost.exe                               4732 ACCESSsvc_apache ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
cmd.exe                                   4148 ACCESSsvc_apache ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
powershell.exe                            1124 ACCESSsvc_apache ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
VSSVC.exe                                 1208                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
svchost.exe                               4696                  ADWS, AJRouter, ALG, ApacheHTTPServer, AppIDSvc, App...
  • spoolsv.exe
  • vds.exe
  • GenValObj.exe
  • TiWorker.exe
  • VSSVC.exe

Tasks


PS C:\xampp\htdocs\uploads> Get-ScheduledTask | where {$_.TaskPath -notlike "\Microsoft*" } | ft TaskName,TaskPath,State
 
PS C:\xampp\htdocs\uploads> cmd /c schtasks /QUERY /FO TABLE
 
Folder: \
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
INFO: There are no scheduled tasks presently available at your access level.
 
Folder: \Microsoft
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
INFO: There are no scheduled tasks presently available at your access level.
 
Folder: \Microsoft\Windows
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
Server Initial Configuration Task        N/A                    Disabled       
 
Folder: \Microsoft\Windows\.NET Framework
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
.NET Framework NGEN v4.0.30319           N/A                    Ready          
.NET Framework NGEN v4.0.30319 64        N/A                    Ready          
.NET Framework NGEN v4.0.30319 64 Critic N/A                    Disabled       
.NET Framework NGEN v4.0.30319 Critical  N/A                    Disabled       
 
Folder: \Microsoft\Windows\Active Directory Rights Management Services Client
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
AD RMS Rights Policy Template Management N/A                    Disabled       
AD RMS Rights Policy Template Management N/A                    Ready          
 
Folder: \Microsoft\Windows\AppID
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
PolicyConverter                          N/A                    Disabled       
VerifiedPublisherCertStoreCheck          N/A                    Disabled       
 
Folder: \Microsoft\Windows\Application Experience
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
Microsoft Compatibility Appraiser        4/22/2025 3:33:15 AM   Ready          
ProgramDataUpdater                       N/A                    Ready          
StartupAppTask                           N/A                    Ready          
 
Folder: \Microsoft\Windows\ApplicationData
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
appuriverifierdaily                      N/A                    Ready          
appuriverifierinstall                    N/A                    Ready          
CleanupTemporaryState                    N/A                    Ready          
DsSvcCleanup                             N/A                    Ready          
 
Folder: \Microsoft\Windows\AppxDeploymentClient
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
Pre-staged app cleanup                   N/A                    Disabled       
 
Folder: \Microsoft\Windows\Autochk
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
Proxy                                    N/A                    Ready          
 
Folder: \Microsoft\Windows\BitLocker
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
BitLocker Encrypt All Drives             N/A                    Ready          
BitLocker MDM policy Refresh             N/A                    Ready          
 
Folder: \Microsoft\Windows\Bluetooth
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
UninstallDeviceTask                      N/A                    Disabled       
 
Folder: \Microsoft\Windows\BrokerInfrastructure
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
BgTaskRegistrationMaintenanceTask        N/A                    Ready          
 
Folder: \Microsoft\Windows\Chkdsk
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
ProactiveScan                            N/A                    Ready          
SyspartRepair                            N/A                    Ready          
 
Folder: \Microsoft\Windows\Clip
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
License Validation                       N/A                    Disabled       
 
Folder: \Microsoft\Windows\CloudExperienceHost
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
CreateObjectTask                         N/A                    Ready          
 
Folder: \Microsoft\Windows\Customer Experience Improvement Program
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
Consolidator                             4/21/2025 12:00:00 PM  Ready          
UsbCeip                                  N/A                    Ready          
 
Folder: \Microsoft\Windows\Data Integrity Scan
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
Data Integrity Scan                      5/9/2025 8:42:05 AM    Ready          
Data Integrity Scan for Crash Recovery   N/A                    Ready          
 
Folder: \Microsoft\Windows\Defrag
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
ScheduledDefrag                          N/A                    Ready          
 
Folder: \Microsoft\Windows\Device Information
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
Device                                   4/22/2025 3:22:35 AM   Ready          
 
Folder: \Microsoft\Windows\Diagnosis
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
Scheduled                                N/A                    Ready          
 
Folder: \Microsoft\Windows\DirectX
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
DXGIAdapterCache                         N/A                    Ready          
 
Folder: \Microsoft\Windows\DiskCleanup
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
SilentCleanup                            N/A                    Ready          
 
Folder: \Microsoft\Windows\DiskDiagnostic
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
Microsoft-Windows-DiskDiagnosticDataColl N/A                    Disabled       
Microsoft-Windows-DiskDiagnosticResolver N/A                    Disabled       
 
Folder: \Microsoft\Windows\DiskFootprint
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
Diagnostics                              N/A                    Ready          
StorageSense                             N/A                    Ready          
 
Folder: \Microsoft\Windows\EDP
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
EDP App Launch Task                      N/A                    Ready          
EDP Auth Task                            N/A                    Ready          
EDP Inaccessible Credentials Task        N/A                    Ready          
StorageCardEncryption Task               N/A                    Ready          
 
Folder: \Microsoft\Windows\ExploitGuard
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
ExploitGuard MDM policy Refresh          N/A                    Ready          
 
Folder: \Microsoft\Windows\File Classification Infrastructure
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
Property Definition Sync                 N/A                    Disabled       
 
Folder: \Microsoft\Windows\Flighting
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
INFO: There are no scheduled tasks presently available at your access level.
 
Folder: \Microsoft\Windows\Flighting\FeatureConfig
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
ReconcileFeatures                        N/A                    Ready          
 
Folder: \Microsoft\Windows\Flighting\OneSettings
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
RefreshCache                             4/21/2025 3:25:20 PM   Ready          
 
Folder: \Microsoft\Windows\InstallService
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
ScanForUpdates                           N/A                    Disabled       
ScanForUpdatesAsUser                     N/A                    Disabled       
SmartRetry                               N/A                    Disabled       
WakeUpAndContinueUpdates                 N/A                    Disabled       
WakeUpAndScanForUpdates                  N/A                    Disabled       
 
Folder: \Microsoft\Windows\License Manager
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
TempSignedLicenseExchange                N/A                    Ready          
 
Folder: \Microsoft\Windows\Location
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
Notifications                            N/A                    Ready          
WindowsActionDialog                      N/A                    Ready          
 
Folder: \Microsoft\Windows\Maintenance
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
WinSAT                                   N/A                    Ready          
 
Folder: \Microsoft\Windows\Maps
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
MapsToastTask                            N/A                    Disabled       
MapsUpdateTask                           N/A                    Disabled       
 
Folder: \Microsoft\Windows\MemoryDiagnostic
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
ProcessMemoryDiagnosticEvents            N/A                    Disabled       
RunFullMemoryDiagnostic                  N/A                    Disabled       
 
Folder: \Microsoft\Windows\Mobile Broadband Accounts
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
MNO Metadata Parser                      N/A                    Ready          
 
Folder: \Microsoft\Windows\MUI
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
LPRemove                                 N/A                    Ready          
 
Folder: \Microsoft\Windows\Multimedia
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
SystemSoundsService                      N/A                    Disabled       
 
Folder: \Microsoft\Windows\NetTrace
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
GatherNetworkInfo                        N/A                    Ready          
 
Folder: \Microsoft\Windows\Offline Files
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
Background Synchronization               N/A                    Disabled       
Logon Synchronization                    N/A                    Disabled       
 
Folder: \Microsoft\Windows\PLA
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
Server Manager Performance Monitor       N/A                    Disabled       
 
Folder: \Microsoft\Windows\Plug and Play
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
Device Install Group Policy              N/A                    Ready          
Device Install Reboot Required           N/A                    Ready          
Sysprep Generalize Drivers               N/A                    Ready          
 
Folder: \Microsoft\Windows\Power Efficiency Diagnostics
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
AnalyzeSystem                            N/A                    Queued         
 
Folder: \Microsoft\Windows\PushToInstall
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
LoginCheck                               N/A                    Disabled       
Registration                             N/A                    Disabled       
 
Folder: \Microsoft\Windows\RecoveryEnvironment
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
VerifyWinRE                              N/A                    Disabled       
 
Folder: \Microsoft\Windows\Server Manager
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
CleanupOldPerfLogs                       N/A                    Ready          
ServerManager                            N/A                    Ready          
 
Folder: \Microsoft\Windows\Servicing
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
StartComponentCleanup                    N/A                    Running        
 
Folder: \Microsoft\Windows\SharedPC
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
Account Cleanup                          N/A                    Disabled       
 
Folder: \Microsoft\Windows\Shell
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
CreateObjectTask                         N/A                    Ready          
IndexerAutomaticMaintenance              N/A                    Ready          
 
Folder: \Microsoft\Windows\Software Inventory Logging
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
Collection                               N/A                    Disabled       
Configuration                            N/A                    Ready          
 
Folder: \Microsoft\Windows\SpacePort
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
SpaceAgentTask                           N/A                    Ready          
SpaceManagerTask                         N/A                    Ready          
 
Folder: \Microsoft\Windows\Speech
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
HeadsetButtonPress                       N/A                    Ready          
 
Folder: \Microsoft\Windows\Storage Tiers Management
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
Storage Tiers Management Initialization  N/A                    Ready          
Storage Tiers Optimization               N/A                    Disabled       
 
Folder: \Microsoft\Windows\TextServicesFramework
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
MsCtfMonitor                             N/A                    Ready          
 
Folder: \Microsoft\Windows\Time Synchronization
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
ForceSynchronizeTime                     N/A                    Ready          
SynchronizeTime                          N/A                    Ready          
 
Folder: \Microsoft\Windows\Time Zone
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
SynchronizeTimeZone                      N/A                    Ready          
 
Folder: \Microsoft\Windows\UPnP
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
UPnPHostConfig                           N/A                    Disabled       
 
Folder: \Microsoft\Windows\Windows Defender
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
Windows Defender Cache Maintenance       N/A                    Ready          
Windows Defender Cleanup                 N/A                    Ready          
Windows Defender Scheduled Scan          4/22/2025 5:42:37 AM   Ready          
Windows Defender Verification            N/A                    Ready          
 
Folder: \Microsoft\Windows\Windows Error Reporting
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
QueueReporting                           4/21/2025 8:43:41 AM   Ready          
 
Folder: \Microsoft\Windows\Windows Filtering Platform
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
BfeOnServiceStartTypeChange              N/A                    Ready          
 
Folder: \Microsoft\Windows\Windows Media Sharing
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
UpdateLibrary                            N/A                    Ready          
 
Folder: \Microsoft\Windows\WindowsColorSystem
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
Calibration Loader                       N/A                    Ready          
 
Folder: \Microsoft\Windows\WindowsUpdate
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
Scheduled Start                          N/A                    Ready          
 
Folder: \Microsoft\Windows\Wininet
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
CacheTask                                N/A                    Ready          
 
Folder: \Microsoft\Windows\Workplace Join
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
Automatic-Device-Join                    N/A                    Ready          
Recovery-Check                           N/A                    Disabled       

Services


PS C:\xampp\htdocs\uploads> wmic service where "State='Running'" get Name,PathName,StartName | Out-String -Stream | Where-Object { $_ -match 'S' -and $_ -notmatch 'C:\Windows\System32' } | Select-Object -First 100
Name                    PathName                                                                           StartName                    
ADWS                    C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exe                          LocalSystem                  
ApacheHTTPServer        "C:\Xampp\apache\bin\httpd.exe" -k runservice                                      ACCESS\svc_apache            
BFE                     C:\Windows\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p                NT AUTHORITY\LocalService    
BrokerInfrastructure    C:\Windows\system32\svchost.exe -k DcomLaunch -p                                   LocalSystem                  
CDPSvc                  C:\Windows\system32\svchost.exe -k LocalService -p                                 NT AUTHORITY\LocalService    
COMSysApp               C:\Windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}  LocalSystem                  
CoreMessagingRegistrar  C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork -p                        NT AUTHORITY\LocalService    
CryptSvc                C:\Windows\system32\svchost.exe -k NetworkService -p                               NT Authority\NetworkService  
DcomLaunch              C:\Windows\system32\svchost.exe -k DcomLaunch -p                                   LocalSystem                  
Dfs                     C:\Windows\system32\dfssvc.exe                                                     LocalSystem                  
DFSR                    C:\Windows\system32\DFSRs.exe                                                      LocalSystem                  
Dhcp                    C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p                NT Authority\LocalService    
DiagTrack               C:\Windows\System32\svchost.exe -k utcsvc -p                                       LocalSystem                  
DNS                     C:\Windows\system32\dns.exe                                                        LocalSystem                  
Dnscache                C:\Windows\system32\svchost.exe -k NetworkService -p                               NT AUTHORITY\NetworkService  
DPS                     C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork -p                        NT AUTHORITY\LocalService    
DsmSvc                  C:\Windows\system32\svchost.exe -k netsvcs -p                                      LocalSystem                  
DsSvc                   C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p                 LocalSystem                  
EventLog                C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p                NT AUTHORITY\LocalService    
EventSystem             C:\Windows\system32\svchost.exe -k LocalService -p                                 NT AUTHORITY\LocalService    
FontCache               C:\Windows\system32\svchost.exe -k LocalService -p                                 NT AUTHORITY\LocalService    
gpsvc                   C:\Windows\system32\svchost.exe -k netsvcs -p                                      LocalSystem                  
IKEEXT                  C:\Windows\system32\svchost.exe -k netsvcs -p                                      LocalSystem                  
iphlpsvc                C:\Windows\System32\svchost.exe -k NetSvcs -p                                      LocalSystem                  
IsmServ                 C:\Windows\System32\ismserv.exe                                                    LocalSystem                  
Kdc                     C:\Windows\System32\lsass.exe                                                      LocalSystem                  
KeyIso                  C:\Windows\system32\lsass.exe                                                      LocalSystem                  
LanmanServer            C:\Windows\System32\svchost.exe -k smbsvcs                                         LocalSystem                  
LanmanWorkstation       C:\Windows\System32\svchost.exe -k NetworkService -p                               NT AUTHORITY\NetworkService  
lmhosts                 C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p                NT AUTHORITY\LocalService    
LSM                                                                                                                                     
mpssvc                  C:\Windows\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p                NT Authority\LocalService    
MSDTC                   C:\Windows\System32\msdtc.exe                                                      NT AUTHORITY\NetworkService  
NcbService              C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p                 LocalSystem                  
Netlogon                C:\Windows\system32\lsass.exe                                                      LocalSystem                  
Netman                  C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p                 LocalSystem                  
netprofm                C:\Windows\System32\svchost.exe -k LocalService -p                                 NT AUTHORITY\LocalService    
NlaSvc                  C:\Windows\System32\svchost.exe -k NetworkService -p                               NT AUTHORITY\NetworkService  
nsi                     C:\Windows\system32\svchost.exe -k LocalService -p                                 NT Authority\LocalService    
PcaSvc                  C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p                 LocalSystem                  
PlugPlay                C:\Windows\system32\svchost.exe -k DcomLaunch -p                                   LocalSystem                  
PolicyAgent             C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted -p              NT Authority\NetworkService  
Power                   C:\Windows\system32\svchost.exe -k DcomLaunch -p                                   LocalSystem                  
ProfSvc                 C:\Windows\system32\svchost.exe -k netsvcs -p                                      LocalSystem                  
RpcEptMapper            C:\Windows\system32\svchost.exe -k RPCSS -p                                        NT AUTHORITY\NetworkService  
RpcSs                   C:\Windows\system32\svchost.exe -k rpcss -p                                        NT AUTHORITY\NetworkService  
SamSs                   C:\Windows\system32\lsass.exe                                                      LocalSystem                  
Schedule                C:\Windows\system32\svchost.exe -k netsvcs -p                                      LocalSystem                  
SecurityHealthService   C:\Windows\system32\SecurityHealthService.exe                                      LocalSystem                  
SENS                    C:\Windows\system32\svchost.exe -k netsvcs -p                                      LocalSystem                  
ShellHWDetection        C:\Windows\System32\svchost.exe -k netsvcs -p                                      LocalSystem                  
Spooler                 C:\Windows\System32\spoolsv.exe                                                    LocalSystem                  
swprv                   C:\Windows\System32\svchost.exe -k swprv                                           LocalSystem                  
SysMain                 C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p                 LocalSystem                  
SystemEventsBroker      C:\Windows\system32\svchost.exe -k DcomLaunch -p                                   LocalSystem                  
Themes                  C:\Windows\System32\svchost.exe -k netsvcs -p                                      LocalSystem                  
TimeBrokerSvc           C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p                NT AUTHORITY\LocalService    
TrustedInstaller        C:\Windows\servicing\TrustedInstaller.exe                                          localSystem                  
UALSVC                  C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p                 LocalSystem                  
UserManager             C:\Windows\system32\svchost.exe -k netsvcs -p                                      LocalSystem                  
UsoSvc                  C:\Windows\system32\svchost.exe -k netsvcs -p                                      LocalSystem                  
vds                     C:\Windows\System32\vds.exe                                                        LocalSystem                  
VGAuthService           "C:\Program Files\VMware\VMware Tools\VMware VGAuth\VGAuthService.exe"             LocalSystem                  
VM3DService             C:\Windows\system32\vm3dservice.exe                                                LocalSystem                  
VMTools                 "C:\Program Files\VMware\VMware Tools\vmtoolsd.exe"                                LocalSystem                  
W32Time                 C:\Windows\system32\svchost.exe -k LocalService                                    NT AUTHORITY\LocalService    
Wcmsvc                  C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p                NT Authority\LocalService    
WdiSystemHost           C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p                 LocalSystem                  
WinDefend               "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MsMpEng.exe"     LocalSystem                  
WinHttpAutoProxySvc     C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p                NT AUTHORITY\LocalService    
Winmgmt                 C:\Windows\system32\svchost.exe -k netsvcs -p                                      localSystem                  
WinRM                   C:\Windows\System32\svchost.exe -k NetworkService -p                               NT AUTHORITY\NetworkService  
WpnService              C:\Windows\system32\svchost.exe -k netsvcs -p                                      LocalSystem                  
  • ApacheHTTPServer "C:\Xampp\apache\bin\httpd.exe" -k runservice ACCESS\svc_apache
  • Dfs C:\Windows\system32\dfssvc.exe LocalSystem
  • DFSR C:\Windows\system32\DFSRs.exe LocalSystem
  • DNS C:\Windows\system32\dns.exe LocalSystem
  • IsmServ C:\Windows\System32\ismserv.exe LocalSystem
  • Spooler C:\Windows\System32\spoolsv.exe LocalSystem

Installed Programs


PS C:\xampp\htdocs\uploads> Get-ItemProperty "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*", "HKLM:\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*", "HKCU:\Software\Microsoft\Windows\CurrentVersion\Uninstall\*" -ErrorAction SilentlyContinue | Select-Object -ExpandProperty DisplayName -ErrorAction SilentlyContinue | Where-Object { $_ } | Sort-Object -Unique
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.24.28127
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.24.28127
Microsoft Visual C++ 2019 X64 Additional Runtime - 14.24.28127
Microsoft Visual C++ 2019 X64 Minimum Runtime - 14.24.28127
Microsoft Visual C++ 2019 X86 Additional Runtime - 14.24.28127
Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.24.28127
VMware Tools
Windows 10 Update Assistant

Firewall & AV


PS C:\xampp\htdocs\uploads> netsh firewall show config
 
Domain profile configuration (current):
-------------------------------------------------------------------
Operational mode                  = Disable
Exception mode                    = Enable
Multicast/broadcast response mode = Enable
Notification mode                 = Disable
 
Service configuration for Domain profile:
Mode     Customized  Name
-------------------------------------------------------------------
Enable   No          File and Printer Sharing
 
Allowed programs configuration for Domain profile:
Mode     Traffic direction    Name / Program
-------------------------------------------------------------------
 
Port configuration for Domain profile:
Port   Protocol  Mode    Traffic direction     Name
-------------------------------------------------------------------
80     TCP       Enable  Inbound               Port 80 for Apache
5985   TCP       Enable  Inbound               WinRM-HTTP
 
Standard profile configuration:
-------------------------------------------------------------------
Operational mode                  = Disable
Exception mode                    = Enable
Multicast/broadcast response mode = Enable
Notification mode                 = Disable
 
Service configuration for Standard profile:
Mode     Customized  Name
-------------------------------------------------------------------
Enable   No          File and Printer Sharing
Enable   Yes         Network Discovery
 
Allowed programs configuration for Standard profile:
Mode     Traffic direction    Name / Program
-------------------------------------------------------------------
 
Port configuration for Standard profile:
Port   Protocol  Mode    Traffic direction     Name
-------------------------------------------------------------------
80     TCP       Enable  Inbound               Port 80 for Apache
5985   TCP       Enable  Inbound               WinRM-HTTP
 
Log configuration:
-------------------------------------------------------------------
File location   = C:\Windows\system32\LogFiles\Firewall\pfirewall.log
Max file size   = 4096 KB
Dropped packets = Disable
Connections     = Disable
 
IMPORTANT: Command executed successfully.
However, "netsh firewall" is deprecated;
use "netsh advfirewall firewall" instead.
For more information on using "netsh advfirewall firewall" commands
instead of "netsh firewall", see KB article 947709
at https://go.microsoft.com/fwlink/?linkid=121488 .
PS C:\xampp\htdocs\uploads> Get-MpComputerStatus ; Get-MpPreference | Select-Object -Property ExclusionPath
 
 
AMEngineVersion                  : 1.1.19200.6
AMProductVersion                 : 4.18.2203.5
AMRunningMode                    : Normal
AMServiceEnabled                 : True
AMServiceVersion                 : 4.18.2203.5
AntispywareEnabled               : True
AntispywareSignatureAge          : 1066
AntispywareSignatureLastUpdated  : 5/20/2022 8:53:35 PM
AntispywareSignatureVersion      : 1.367.249.0
AntivirusEnabled                 : True
AntivirusSignatureAge            : 1066
AntivirusSignatureLastUpdated    : 5/20/2022 8:53:35 PM
AntivirusSignatureVersion        : 1.367.249.0
BehaviorMonitorEnabled           : False
ComputerID                       : E33EB5FC-3DD7-4CD6-9658-468890E50242
ComputerState                    : 0
DefenderSignaturesOutOfDate      : False
DeviceControlDefaultEnforcement  : Unknown
DeviceControlPoliciesLastUpdated : 4/21/2025 7:45:19 AM
DeviceControlState               : Disabled
FullScanAge                      : 4294967295
FullScanEndTime                  : 
FullScanOverdue                  : False
FullScanRequired                 : False
FullScanSignatureVersion         : 
FullScanStartTime                : 
IoavProtectionEnabled            : False
IsTamperProtected                : False
IsVirtualMachine                 : True
LastFullScanSource               : 0
LastQuickScanSource              : 2
NISEnabled                       : False
NISEngineVersion                 : 0.0.0.0
NISSignatureAge                  : 4294967295
NISSignatureLastUpdated          : 
NISSignatureVersion              : 0.0.0.0
OnAccessProtectionEnabled        : False
ProductStatus                    : 524288
QuickScanAge                     : 0
QuickScanEndTime                 : 4/21/2025 7:35:10 AM
QuickScanOverdue                 : False
QuickScanSignatureVersion        : 1.367.249.0
QuickScanStartTime               : 4/21/2025 7:34:51 AM
RealTimeProtectionEnabled        : False
RealTimeScanDirection            : 0
RebootRequired                   : False
TamperProtectionSource           : N/A
TDTMode                          : N/A
TDTStatus                        : N/A
TDTTelemetry                     : N/A
PSComputerName                   : 
 
ExclusionPath : {N/A: Must be and administrator to view exclusions}

Session Architecture


PS C:\xampp\htdocs\uploads> [Environment]::Is64BitProcess
True

Installed .NET Frameworks


PS C:\xampp\htdocs\uploads> cmd /c dir /A:D C:\Windows\Microsoft.NET\Framework ; cmd /c reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP" ; cmd /c reg query "HKLM\SOFTWARE\Microsoft\Net Framework Setup\NDP" /s
 Volume in drive C has no label.
 Volume Serial Number is 5C30-DCD7
 
 Directory of C:\Windows\Microsoft.NET\Framework
 
09/15/2018  12:19 AM    <DIR>          .
09/15/2018  12:19 AM    <DIR>          ..
09/15/2018  12:19 AM    <DIR>          v1.0.3705
09/15/2018  12:19 AM    <DIR>          v1.1.4322
09/15/2018  12:19 AM    <DIR>          v2.0.50727
04/21/2025  07:34 AM    <DIR>          v4.0.30319
               0 File(s)              0 bytes
               6 Dir(s)   9,694,744,576 bytes free
 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\CDF
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4.0
 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Net Framework Setup\NDP\CDF
 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Net Framework Setup\NDP\CDF\v4.0
    HttpNamespaceReservationInstalled    REG_DWORD    0x1
    NetTcpPortSharingInstalled    REG_DWORD    0x1
    NonHttpActivationInstalled    REG_DWORD    0x1
    SMSvcHostPath    REG_SZ    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\
    WMIInstalled    REG_DWORD    0x1
 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Net Framework Setup\NDP\v4
 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Net Framework Setup\NDP\v4\Client
    CBS    REG_DWORD    0x1
    Install    REG_DWORD    0x1
    InstallPath    REG_SZ    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\
    Release    REG_DWORD    0x70bf6
    Servicing    REG_DWORD    0x0
    TargetVersion    REG_SZ    4.0.0
    Version    REG_SZ    4.7.03190
 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Net Framework Setup\NDP\v4\Client\1033
    CBS    REG_DWORD    0x1
    Install    REG_DWORD    0x1
    Release    REG_DWORD    0x70bf6
    Servicing    REG_DWORD    0x0
    TargetVersion    REG_SZ    4.0.0
    Version    REG_SZ    4.7.03190
 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Net Framework Setup\NDP\v4\Full
    CBS    REG_DWORD    0x1
    Install    REG_DWORD    0x1
    InstallPath    REG_SZ    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\
    Release    REG_DWORD    0x70bf6
    Servicing    REG_DWORD    0x0
    TargetVersion    REG_SZ    4.0.0
    Version    REG_SZ    4.7.03190
 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Net Framework Setup\NDP\v4\Full\1033
    CBS    REG_DWORD    0x1
    Install    REG_DWORD    0x1
    Release    REG_DWORD    0x70bf6
    Servicing    REG_DWORD    0x0
    TargetVersion    REG_SZ    4.0.0
    Version    REG_SZ    4.7.03190
 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Net Framework Setup\NDP\v4.0
    (Default)    REG_SZ    deprecated
 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Net Framework Setup\NDP\v4.0\Client
    Install    REG_DWORD    0x1
    Version    REG_SZ    4.0.0.0

.NET 4.7.03190