1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
|
❯ nc nanocorp.htb 6556
<<<check_mk>>>
Version: 2.1.0p10
BuildDate: Aug 19 2022
AgentOS: windows
Hostname: DC01
Architecture: 64bit
WorkingDirectory: C:\Windows\system32
ConfigFile: C:\Program Files (x86)\checkmk\service\check_mk.yml
LocalConfigFile: C:\ProgramData\checkmk\agent\check_mk.user.yml
AgentDirectory: C:\Program Files (x86)\checkmk\service
PluginsDirectory: C:\ProgramData\checkmk\agent\plugins
StateDirectory: C:\ProgramData\checkmk\agent\state
ConfigDirectory: C:\ProgramData\checkmk\agent\config
TempDirectory: C:\ProgramData\checkmk\agent\tmp
LogDirectory: C:\ProgramData\checkmk\agent\log
SpoolDirectory: C:\ProgramData\checkmk\agent\spool
LocalDirectory: C:\ProgramData\checkmk\agent\local
OnlyFrom:
<<<cmk_agent_ctl_status:sep(0)>>>
{"version":"2.1.0p10","agent_socket_operational":true,"ip_allowlist":[],"allow_legacy_pull":true,"connections":[]}
<<<wmi_cpuload:sep(124)>>>
[system_perf]
Name|ProcessorQueueLength|Timestamp_PerfTime|Frequency_PerfTime|WMIStatus
|0|293565971037|10000000|OK
[computer_system]
Name|NumberOfLogicalProcessors|NumberOfProcessors|WMIStatus
DC01|2|1|OK
<<<uptime>>>
29356
<<<mem>>>
MemTotal: 4193312 kB
MemFree: 1912776 kB
SwapTotal: 1441792 kB
SwapFree: 1647384 kB
PageTotal: 5635104 kB
PageFree: 3560160 kB
VirtualTotal: 137438953344 kB
VirtualFree: 137434635168 kB
<<<fileinfo:sep(124)>>>
1762926150
<<<df:sep(9)>>>
C:\ NTFS 22298620 17611764 4686856 79% C:\
<<<winperf_phydisk>>>
1762926150.93 234 10000000
2 instances: 0_C: _Total
-36 0 0 rawcount
-34 36408215003 36408215003 type(20570500)
-34 134073997509273041 134073997509273041 type(40030500)
1166 36408215003 36408215003 type(550500)
-32 26891695405 26891695405 type(20570500)
-32 134073997509273041 134073997509273041 type(40030500)
1168 26891695405 26891695405 type(550500)
-30 9516519598 9516519598 type(20570500)
-30 134073997509273041 134073997509273041 type(40030500)
1170 9516519598 9516519598 type(550500)
-28 2048476635 2048476635 average_timer
-28 591967 591967 average_base
-26 1121891629 1121891629 average_timer
-26 445390 445390 average_base
-24 926585006 926585006 average_timer
-24 146577 146577 average_base
-22 591967 591967 counter
-20 445390 445390 counter
-18 146577 146577 counter
-16 22306593792 22306593792 bulk_count
-14 19136152576 19136152576 bulk_count
-12 3170441216 3170441216 bulk_count
-10 22306593792 22306593792 average_bulk
-10 591967 591967 average_base
-8 19136152576 19136152576 average_bulk
-8 445390 445390 average_base
-6 3170441216 3170441216 average_bulk
-6 146577 146577 average_base
1248 275528287441 275528287441 type(20570500)
1248 134073997509273041 134073997509273041 type(40030500)
1250 10408 10408 counter
<<<winperf_if>>>
1762926150.94 510 10000000
1 instances: vmxnet3_Ethernet_Adapter
-122 27078369 bulk_count
-110 216814 bulk_count
-244 201648 bulk_count
-58 15166 bulk_count
10 10000000000 large_rawcount
-246 23293205 bulk_count
14 13447 bulk_count
16 188201 bulk_count
18 0 large_rawcount
20 0 large_rawcount
22 0 large_rawcount
-4 3785164 bulk_count
26 12119 bulk_count
28 3047 bulk_count
30 0 large_rawcount
32 0 large_rawcount
34 0 large_rawcount
1086 0 large_rawcount
1088 0 large_rawcount
1090 10 bulk_count
1092 0 bulk_count
1094 2484 large_rawcount
<<<winperf_processor>>>
1762926150.95 238 10000000
3 instances: 0 1 _Total
-232 269127812500 267834375000 268481093750 100nsec_timer_inv
-96 16756093750 17038593750 16897343750 100nsec_timer
-94 7682187500 8691562500 8186875000 100nsec_timer
-90 7826738 8231768 16058506 counter
458 123750000 775000000 449375000 100nsec_timer
460 64843750 628750000 346796875 100nsec_timer
1096 772962 657102 1430064 counter
1098 0 0 0 rawcount
1508 266444050300 266901393959 266672722129 100nsec_timer
1510 266444050300 266901393959 266672722129 100nsec_timer
1512 0 0 0 100nsec_timer
1514 0 0 0 100nsec_timer
1516 4589477 4176547 8766024 bulk_count
1518 0 0 0 bulk_count
1520 0 0 0 bulk_count
<<<services>>>
ADWS running/auto Active Directory Web Services
AJRouter stopped/demand AllJoyn Router Service
ALG stopped/demand Application Layer Gateway Service
AppIDSvc stopped/demand Application Identity
Appinfo stopped/demand Application Information
AppMgmt stopped/demand Application Management
AppReadiness stopped/demand App Readiness
AppVClient stopped/disabled Microsoft App-V Client
AppXSvc stopped/demand AppX Deployment Service (AppXSVC)
AudioEndpointBuilder stopped/demand Windows Audio Endpoint Builder
Audiosrv stopped/demand Windows Audio
AxInstSV stopped/disabled ActiveX Installer (AxInstSV)
BFE running/auto Base Filtering Engine
BITS stopped/demand Background Intelligent Transfer Service
BrokerInfrastructure running/auto Background Tasks Infrastructure Service
bthserv stopped/demand Bluetooth Support Service
camsvc running/demand Capability Access Manager Service
CDPSvc running/auto Connected Devices Platform Service
CertPropSvc running/demand Certificate Propagation
CheckmkService running/auto Checkmk Service
ClipSVC stopped/demand Client License Service (ClipSVC)
COMSysApp running/demand COM+ System Application
CoreMessagingRegistrar running/auto CoreMessaging
CryptSvc running/auto Cryptographic Services
CscService stopped/disabled Offline Files
DcomLaunch running/auto DCOM Server Process Launcher
dcsvc stopped/demand Declared Configuration(DC) service
defragsvc stopped/demand Optimize drives
DeviceAssociationService stopped/demand Device Association Service
DeviceInstall stopped/demand Device Install Service
DevQueryBroker stopped/demand DevQuery Background Discovery Broker
Dfs running/auto DFS Namespace
DFSR running/auto DFS Replication
Dhcp running/auto DHCP Client
diagnosticshub.standardcollector.service stopped/demand Microsoft (R) Diagnostics Hub Standard Collector Service
DiagTrack running/auto Connected User Experiences and Telemetry
DispBrokerDesktopSvc running/auto Display Policy Service
DmEnrollmentSvc stopped/demand Device Management Enrollment Service
dmwappushservice stopped/disabled Device Management Wireless Application Protocol (WAP) Push message Routing Service
DNS running/auto DNS Server
Dnscache running/auto DNS Client
DoSvc stopped/demand Delivery Optimization
dot3svc stopped/demand Wired AutoConfig
DPS running/auto Diagnostic Policy Service
DsmSvc running/demand Device Setup Manager
DsRoleSvc stopped/demand DS Role Server
DsSvc running/demand Data Sharing Service
EapHost stopped/demand Extensible Authentication Protocol
edgeupdate stopped/auto Microsoft Edge Update Service (edgeupdate)
edgeupdatem stopped/demand Microsoft Edge Update Service (edgeupdatem)
EFS stopped/demand Encrypting File System (EFS)
embeddedmode stopped/demand Embedded Mode
EntAppSvc stopped/demand Enterprise App Management Service
EventLog running/auto Windows Event Log
EventSystem running/auto COM+ Event System
fdPHost stopped/demand Function Discovery Provider Host
FDResPub stopped/demand Function Discovery Resource Publication
FontCache running/auto Windows Font Cache Service
FrameServer stopped/demand Windows Camera Frame Server
FrameServerMonitor stopped/demand Windows Camera Frame Server Monitor
gpsvc running/auto Group Policy Client
GraphicsPerfSvc stopped/disabled GraphicsPerfSvc
hidserv stopped/demand Human Interface Device Service
HvHost stopped/demand HV Host Service
IKEEXT running/auto IKE and AuthIP IPsec Keying Modules
InstallService stopped/demand Microsoft Store Install Service
iphlpsvc running/auto IP Helper
IsmServ running/auto Intersite Messaging
Kdc running/auto Kerberos Key Distribution Center
KdsSvc stopped/demand Microsoft Key Distribution Service
KeyIso running/demand CNG Key Isolation
KPSSVC stopped/demand KDC Proxy Server service (KPS)
KtmRm stopped/demand KtmRm for Distributed Transaction Coordinator
LanmanServer running/auto Server
LanmanWorkstation running/auto Workstation
lfsvc stopped/disabled Geolocation Service
LicenseManager running/demand Windows License Manager Service
lltdsvc stopped/disabled Link-Layer Topology Discovery Mapper
lmhosts stopped/demand TCP/IP NetBIOS Helper
LSM running/auto Local Session Manager
MapsBroker stopped/disabled Downloaded Maps Manager
McpManagementService stopped/demand McpManagementService
MicrosoftEdgeElevationService stopped/demand Microsoft Edge Elevation Service (MicrosoftEdgeElevationService)
mpssvc running/auto Windows Defender Firewall
MSDTC running/auto Distributed Transaction Coordinator
MSiSCSI stopped/demand Microsoft iSCSI Initiator Service
msiserver stopped/demand Windows Installer
NcaSvc stopped/demand Network Connectivity Assistant
NcbService running/demand Network Connection Broker
Netlogon running/auto Netlogon
Netman stopped/demand Network Connections
netprofm running/demand Network List Service
NetSetupSvc stopped/demand Network Setup Service
NetTcpPortSharing stopped/disabled Net.Tcp Port Sharing Service
NgcCtnrSvc stopped/demand Microsoft Passport Container
NgcSvc stopped/demand Microsoft Passport
NlaSvc running/auto Network Location Awareness
nsi running/auto Network Store Interface Service
NTDS running/auto Active Directory Domain Services
NtFrs stopped/disabled File Replication
PcaSvc running/auto Program Compatibility Assistant Service
PerfHost stopped/demand Performance Counter DLL Host
pla stopped/demand Performance Logs & Alerts
PlugPlay running/demand Plug and Play
PolicyAgent running/demand IPsec Policy Agent
Power running/auto Power
PrintNotify stopped/demand Printer Extensions and Notifications
ProfSvc running/auto User Profile Service
PushToInstall stopped/disabled Windows PushToInstall Service
QWAVE stopped/demand Quality Windows Audio Video Experience
RasAuto stopped/demand Remote Access Auto Connection Manager
RasMan running/auto Remote Access Connection Manager
RemoteAccess stopped/disabled Routing and Remote Access
RemoteRegistry stopped/auto Remote Registry
RmSvc stopped/disabled Radio Management Service
RpcEptMapper running/auto RPC Endpoint Mapper
RpcLocator stopped/demand Remote Procedure Call (RPC) Locator
RpcSs running/auto Remote Procedure Call (RPC)
RSoPProv stopped/demand Resultant Set of Policy Provider
sacsvr stopped/demand Special Administration Console Helper
SamSs running/auto Security Accounts Manager
SCardSvr stopped/demand Smart Card
ScDeviceEnum stopped/disabled Smart Card Device Enumeration Service
Schedule running/auto Task Scheduler
SCPolicySvc stopped/demand Smart Card Removal Policy
seclogon running/demand Secondary Logon
SecurityHealthService stopped/demand Windows Security Service
SEMgrSvc stopped/disabled Payments and NFC/SE Manager
SENS running/auto System Event Notification Service
Sense stopped/demand Windows Defender Advanced Threat Protection Service
SensorDataService stopped/disabled Sensor Data Service
SensorService stopped/demand Sensor Service
SensrSvc stopped/demand Sensor Monitoring Service
SessionEnv running/demand Remote Desktop Configuration
SgrmBroker stopped/demand System Guard Runtime Monitor Broker
SharedAccess stopped/disabled Internet Connection Sharing (ICS)
ShellHWDetection running/auto Shell Hardware Detection
shpamsvc stopped/disabled Shared PC Account Manager
smphost stopped/demand Microsoft Storage Spaces SMP
SNMPTRAP stopped/demand SNMP Trap
Spooler stopped/disabled Print Spooler
sppsvc stopped/auto Software Protection
SSDPSRV stopped/disabled SSDP Discovery
ssh-agent stopped/disabled OpenSSH Authentication Agent
SstpSvc running/demand Secure Socket Tunneling Protocol Service
StateRepository running/auto State Repository Service
StiSvc stopped/demand Windows Image Acquisition (WIA)
StorSvc running/auto Storage Service
svsvc stopped/demand Spot Verifier
swprv stopped/demand Microsoft Software Shadow Copy Provider
SysMain running/auto SysMain
SystemEventsBroker running/auto System Events Broker
TabletInputService running/demand Touch Keyboard and Handwriting Panel Service
tapisrv running/demand Telephony
TermService running/demand Remote Desktop Services
Themes stopped/disabled Themes
TieringEngineService stopped/demand Storage Tiers Management
TimeBrokerSvc running/demand Time Broker
TokenBroker running/demand Web Account Manager
TrkWks stopped/demand Distributed Link Tracking Client
TrustedInstaller stopped/demand Windows Modules Installer
tzautoupdate stopped/disabled Auto Time Zone Updater
UALSVC running/auto User Access Logging Service
UevAgentService stopped/disabled User Experience Virtualization Service
UmRdpService running/demand Remote Desktop Services UserMode Port Redirector
upnphost stopped/disabled UPnP Device Host
UserManager running/auto User Manager
UsoSvc running/auto Update Orchestrator Service
VaultSvc stopped/demand Credential Manager
vds running/demand Virtual Disk
VGAuthService running/auto VMware Alias Manager and Ticket Service
vm3dservice running/auto VMware SVGA Helper Service
vmicguestinterface stopped/demand Hyper-V Guest Service Interface
vmicheartbeat stopped/demand Hyper-V Heartbeat Service
vmickvpexchange stopped/demand Hyper-V Data Exchange Service
vmicshutdown stopped/demand Hyper-V Guest Shutdown Service
vmictimesync stopped/demand Hyper-V Time Synchronization Service
vmicvmsession stopped/demand Hyper-V PowerShell Direct Service
vmicvss stopped/demand Hyper-V Volume Shadow Copy Requestor
VMTools running/auto VMware Tools
vmvss stopped/demand VMware Snapshot Provider
VSS stopped/demand Volume Shadow Copy
W32Time running/auto Windows Time
WaaSMedicSvc stopped/demand Windows Update Medic Service
WalletService stopped/disabled WalletService
WarpJITSvc stopped/demand Warp JIT Service
WbioSrvc stopped/demand Windows Biometric Service
Wcmsvc running/auto Windows Connection Manager
WdiServiceHost stopped/demand Diagnostic Service Host
WdiSystemHost stopped/demand Diagnostic System Host
WdNisSvc running/demand Microsoft Defender Antivirus Network Inspection Service
Wecsvc stopped/demand Windows Event Collector
WEPHOSTSVC stopped/demand Windows Encryption Provider Host Service
wercplsupport stopped/demand Problem Reports Control Panel Support
WerSvc stopped/demand Windows Error Reporting Service
WiaRpc stopped/demand Still Image Acquisition Events
WinDefend running/auto Microsoft Defender Antivirus Service
WinHttpAutoProxySvc running/demand WinHTTP Web Proxy Auto-Discovery Service
Winmgmt running/auto Windows Management Instrumentation
WinRM running/auto Windows Remote Management (WS-Management)
wisvc stopped/disabled Windows Insider Service
wlidsvc stopped/demand Microsoft Account Sign-in Assistant
wmiApSrv stopped/demand WMI Performance Adapter
WMPNetworkSvc stopped/demand Windows Media Player Network Sharing Service
WPDBusEnum stopped/demand Portable Device Enumerator Service
WpnService running/auto Windows Push Notifications System Service
WSearch stopped/disabled Windows Search
wuauserv stopped/demand Windows Update
CaptureService_1dab18 stopped/demand CaptureService_1dab18
cbdhsvc_1dab18 running/auto Clipboard User Service_1dab18
CDPUserSvc_1dab18 running/auto Connected Devices Platform User Service_1dab18
ConsentUxUserSvc_1dab18 stopped/demand ConsentUX User Service_1dab18
CredentialEnrollmentManagerUserSvc_1dab18 stopped/demand CredentialEnrollmentManagerUserSvc_1dab18
DeviceAssociationBrokerSvc_1dab18 stopped/demand DeviceAssociationBroker_1dab18
DevicePickerUserSvc_1dab18 stopped/disabled DevicePicker_1dab18
DevicesFlowUserSvc_1dab18 stopped/demand DevicesFlow_1dab18
PimIndexMaintenanceSvc_1dab18 stopped/demand Contact Data_1dab18
PrintWorkflowUserSvc_1dab18 stopped/demand PrintWorkflow_1dab18
UdkUserSvc_1dab18 stopped/demand Udk User Service_1dab18
UnistoreSvc_1dab18 stopped/demand User Data Storage_1dab18
UserDataSvc_1dab18 stopped/demand User Data Access_1dab18
WpnUserService_1dab18 running/auto Windows Push Notifications User Service_1dab18
<<<checkmk_agent_plugins_win:sep(0)>>>
pluginsdir C:\ProgramData\checkmk\agent\plugins
localdir C:\ProgramData\checkmk\agent\local
<<<logwatch>>>
[[[Active Directory Web Services]]]
[[[Application]]]
[[[DFS Replication]]]
[[[Directory Service]]]
[[[DNS Server]]]
[[[HardwareEvents]]]
[[[Internet Explorer]]]
[[[Key Management Service]]]
[[[Security]]]
[[[System]]]
W Nov 11 21:04:11 0.1014 Microsoft-Windows-DNS-Client One of the files in the registry database had to be recovered by use of a log or alternate copy. The recovery was successful.
[[[Windows PowerShell:missing]]]
<<<ps:sep(9)>>>
(SYSTEM,0,8,0,0,0,0,536962187500,0,4,29352) System Idle Process
(SYSTEM,0,144,0,4,0,0,869218750,2319,128,29352) System
(SYSTEM,0,19480,0,100,1,0,35312500,0,4,29357) Registry
(SYSTEM,0,1232,0,352,1,312500,2031250,60,2,29352) smss.exe
(SYSTEM,0,6544,0,448,2,12656250,51875000,494,11,29348) csrss.exe
(SYSTEM,0,6072,0,548,1,468750,1093750,176,10,29348) csrss.exe
(SYSTEM,0,7168,0,556,1,312500,781250,151,1,29348) wininit.exe
(\\NT AUTHORITY\SYSTEM,2844,14816,0,616,2,937500,2187500,222,2,29347) winlogon.exe
(SYSTEM,0,14288,0,688,5,15156250,12500000,645,7,29347) services.exe
(\\NT AUTHORITY\SYSTEM,58712,70108,0,704,57,953906250,446875000,2253,30,29347) lsass.exe
(\\NT AUTHORITY\SYSTEM,7212,24124,0,904,7,5781250,8906250,1024,10,29344) svchost.exe
(\\Font Driver Host\UMFD-0,1500,3900,0,928,1,625000,2343750,39,5,29344) fontdrvhost.exe
(\\Font Driver Host\UMFD-1,1564,4016,0,936,1,156250,468750,39,5,29344) fontdrvhost.exe
(\\NT AUTHORITY\NETWORK SERVICE,6404,13376,0,1008,6,48437500,28437500,939,9,29344) svchost.exe
(\\NT AUTHORITY\SYSTEM,2884,11456,0,444,2,12187500,10000000,340,4,29344) svchost.exe
(\\Window Manager\DWM-1,17408,43448,0,780,17,3281250,2343750,635,16,29344) dwm.exe
(\\NT AUTHORITY\NETWORK SERVICE,10312,25736,0,1004,10,13906250,12500000,701,30,29343) svchost.exe
(\\NT AUTHORITY\LOCAL SERVICE,3136,7756,0,1056,3,937500,1875000,132,3,29343) svchost.exe
(\\NT AUTHORITY\LOCAL SERVICE,1804,12580,0,1064,1,156250,312500,177,2,29343) svchost.exe
(\\NT AUTHORITY\LOCAL SERVICE,1648,7552,0,1072,1,0,0,197,4,29343) svchost.exe
(\\NT AUTHORITY\SYSTEM,1996,10208,0,1080,1,156250,625000,212,1,29343) svchost.exe
(\\NT AUTHORITY\LOCAL SERVICE,2204,8044,0,1148,2,3281250,3906250,225,5,29343) svchost.exe
(\\NT AUTHORITY\NETWORK SERVICE,3468,10584,0,1212,3,32187500,43281250,301,11,29343) svchost.exe
(\\NT AUTHORITY\LOCAL SERVICE,14916,19816,0,1256,14,50156250,32031250,384,7,29343) svchost.exe
(\\NT AUTHORITY\LOCAL SERVICE,10904,21168,0,1364,10,8593750,5000000,429,12,29343) svchost.exe
(\\NT AUTHORITY\SYSTEM,3380,14360,0,1404,3,11093750,21875000,315,7,29343) svchost.exe
(\\NT AUTHORITY\SYSTEM,2840,12392,0,1412,2,16406250,43593750,216,5,29343) svchost.exe
(\\NT AUTHORITY\LOCAL SERVICE,2864,9416,0,1440,2,5000000,1250000,442,4,29343) svchost.exe
(\\NT AUTHORITY\LOCAL SERVICE,1432,6420,0,1496,1,156250,156250,150,2,29343) svchost.exe
(\\NT AUTHORITY\NETWORK SERVICE,4160,13468,0,1560,4,468750,625000,394,4,29343) svchost.exe
(\\NT AUTHORITY\SYSTEM,1900,8912,0,1576,1,156250,2656250,185,2,29343) svchost.exe
(\\NT AUTHORITY\LOCAL SERVICE,1968,9208,0,1664,1,156250,156250,291,3,29343) svchost.exe
(\\NT AUTHORITY\SYSTEM,5448,16108,0,1672,5,16406250,46406250,382,11,29343) svchost.exe
(\\NT AUTHORITY\SYSTEM,2104,13076,0,1712,2,312500,468750,198,2,29343) svchost.exe
(\\NT AUTHORITY\LOCAL SERVICE,1672,7096,0,1752,1,0,312500,166,5,29343) svchost.exe
(\\NT AUTHORITY\LOCAL SERVICE,1788,7932,0,1760,1,1093750,2812500,170,2,29343) svchost.exe
(\\NT AUTHORITY\SYSTEM,1508,7600,0,1820,1,0,156250,162,2,29343) svchost.exe
(\\NT AUTHORITY\SYSTEM,3860,12068,0,1888,3,3125000,6718750,306,4,29343) svchost.exe
(\\NT AUTHORITY\NETWORK SERVICE,2224,9860,0,1964,2,4531250,5156250,224,5,29343) svchost.exe
(\\NT AUTHORITY\LOCAL SERVICE,2816,11192,0,2020,2,4218750,3906250,435,4,29343) svchost.exe
(\\NT AUTHORITY\SYSTEM,2712,10888,0,2052,2,468750,2812500,363,5,29343) svchost.exe
(\\NT AUTHORITY\SYSTEM,1468,7276,0,2064,1,0,312500,158,3,29343) svchost.exe
(\\NT AUTHORITY\LOCAL SERVICE,1368,7512,0,2192,1,312500,0,126,1,29343) svchost.exe
(\\NT AUTHORITY\SYSTEM,2152,9872,0,2276,2,0,312500,226,4,29343) svchost.exe
(\\NT AUTHORITY\SYSTEM,2484,9556,0,2556,2,2187500,2343750,207,5,29343) svchost.exe
(\\NT AUTHORITY\NETWORK SERVICE,1884,7852,0,2712,1,4375000,625000,165,3,29342) svchost.exe
(\\NT AUTHORITY\SYSTEM,2340,9488,0,3000,2,1875000,2031250,209,6,29334) svchost.exe
(\\NT AUTHORITY\NETWORK SERVICE,4240,15376,0,2128,4,238750000,173593750,276,6,29334) svchost.exe
(\\NT AUTHORITY\SYSTEM,58440,76552,0,2152,57,560937500,98125000,554,14,29334) Microsoft.ActiveDirectory.WebServices.exe
(\\NT AUTHORITY\SYSTEM,13516,30616,0,1428,13,10156250,9843750,485,8,29334) svchost.exe
(\\NT AUTHORITY\SYSTEM,7944,18764,0,2288,7,7187500,15156250,295,15,29334) check_mk_agent.exe
(\\NT AUTHORITY\SYSTEM,17128,26020,0,2228,16,58437500,34062500,420,16,29334) dfsrs.exe
(\\NT AUTHORITY\SYSTEM,2644,8728,0,2764,2,0,937500,271,4,29334) svchost.exe
(\\NT AUTHORITY\SYSTEM,1988,6700,0,2596,1,0,0,160,7,29334) ismserv.exe
(\\NT AUTHORITY\SYSTEM,69216,71304,0,2520,67,6406250,4062500,5396,16,29334) dns.exe
(\\NT AUTHORITY\LOCAL SERVICE,1648,7428,0,2856,1,0,312500,155,1,29334) svchost.exe
(\\NT AUTHORITY\SYSTEM,5404,13684,0,2600,5,19062500,5937500,157,3,29334) svchost.exe
(\\NT AUTHORITY\SYSTEM,1548,7068,0,1900,1,0,468750,139,2,29334) svchost.exe
(\\NT AUTHORITY\SYSTEM,1892,6396,0,3076,1,312500,0,156,11,29334) dfssvc.exe
(\\NT AUTHORITY\SYSTEM,1572,6792,0,3132,1,156250,0,128,3,29334) vm3dservice.exe
(\\NT AUTHORITY\SYSTEM,10924,24776,0,3148,10,15156250,14218750,406,13,29334) vmtoolsd.exe
(\\NT AUTHORITY\SYSTEM,2480,11028,0,3156,2,0,156250,167,2,29334) VGAuthService.exe
(\\NT AUTHORITY\SYSTEM,11232,21244,0,3176,10,262968750,131718750,448,22,29334) svchost.exe
(SYSTEM,0,226144,0,3192,185,5933437500,3702968750,645,23,29334) MsMpEng.exe
(\\NT AUTHORITY\NETWORK SERVICE,3236,13952,0,3232,3,937500,937500,272,5,29334) svchost.exe
(\\NT AUTHORITY\SYSTEM,1516,12084,0,3240,1,0,156250,140,1,29334) svchost.exe
(\\NT AUTHORITY\NETWORK SERVICE,2320,9328,0,3348,2,0,156250,247,7,29334) svchost.exe
(\\NT AUTHORITY\SYSTEM,1692,7076,0,3504,1,156250,2031250,134,4,29334) vm3dservice.exe
(\\NT AUTHORITY\SYSTEM,2440,11604,0,3864,2,312500,625000,209,11,29333) vds.exe
(\\NT AUTHORITY\SYSTEM,2116,8488,0,3884,2,0,0,137,7,29333) cmk-agent-ctl.exe
(\\NT AUTHORITY\SYSTEM,1476,6660,0,3696,1,1250000,625000,114,2,29333) AggregatorHost.exe
(\\NT AUTHORITY\SYSTEM,3840,14696,0,3484,3,2187500,1093750,279,10,29333) dllhost.exe
(\\NT AUTHORITY\NETWORK SERVICE,2896,11140,0,4228,2,468750,625000,238,9,29332) msdtc.exe
(\\NT AUTHORITY\NETWORK SERVICE,11864,24084,0,4252,11,206718750,182187500,414,9,29332) WmiPrvSE.exe
(\\NT AUTHORITY\SYSTEM,2372,4028,0,4484,2,468750,468750,220,3,29332) MicrosoftEdgeUpdate.exe
(SYSTEM,0,10976,0,4004,3,312500,468750,210,4,29328) NisSrv.exe
(\\NT AUTHORITY\SYSTEM,3580,14244,0,2960,3,156250,625000,403,12,29306) svchost.exe
(\\NT AUTHORITY\SYSTEM,11424,45656,0,5260,11,1875000,6875000,463,9,29305) LogonUI.exe
(\\NT AUTHORITY\SYSTEM,4040,18604,0,5960,3,25312500,60156250,317,1,29302) svchost.exe
(\\NANOCORP\web_svc,10096,1724,0,5040,9,2031250,1875000,172,1,29242) httpd.exe
(\\NANOCORP\web_svc,6560,728,0,5012,6,625000,1093750,140,4,29242) conhost.exe
(\\NANOCORP\web_svc,17660,3064,0,5440,17,1406250,2343750,481,153,29240) httpd.exe
(\\NT AUTHORITY\LOCAL SERVICE,2744,13636,0,5768,2,156250,625000,237,4,29186) svchost.exe
(\\NT AUTHORITY\LOCAL SERVICE,17228,20240,0,2916,16,21093750,107031250,303,22,29186) svchost.exe
(\\NT AUTHORITY\SYSTEM,4064,11876,0,5456,3,156250,3750000,259,6,29185) svchost.exe
(\\NT AUTHORITY\SYSTEM,7988,15728,0,1868,7,1093750,2031250,268,8,29185) svchost.exe
(\\NT AUTHORITY\SYSTEM,2896,12460,0,660,2,625000,625000,239,10,29183) svchost.exe
(\\NT AUTHORITY\SYSTEM,6176,10892,0,760,6,0,312500,193,4,28731) svchost.exe
(SYSTEM,0,6704,0,3276,1,2812500,8281250,243,8,28664) csrss.exe
(\\NT AUTHORITY\SYSTEM,2416,11092,0,1284,2,625000,3125000,253,2,28664) winlogon.exe
(\\Font Driver Host\UMFD-2,1624,4416,0,4968,1,468750,2187500,39,5,28661) fontdrvhost.exe
(\\Window Manager\DWM-2,11464,38460,0,4128,11,20781250,15937500,710,17,28661) dwm.exe
(\\NANOCORP\web_svc,2300,11428,0,1128,2,2812500,4843750,303,6,28658) rdpclip.exe
(\\NANOCORP\web_svc,4936,26792,0,1280,4,3281250,2031250,495,7,28658) sihost.exe
(\\NANOCORP\web_svc,2772,13416,0,3724,2,781250,2812500,220,3,28658) svchost.exe
(\\NANOCORP\web_svc,5136,26400,0,2212,5,1406250,781250,326,2,28658) svchost.exe
(\\NANOCORP\web_svc,2312,12040,0,2308,2,156250,468750,185,2,28657) taskhostw.exe
(\\NT AUTHORITY\SYSTEM,2888,15380,0,2812,2,3593750,625000,225,2,28657) svchost.exe
(\\NT AUTHORITY\SYSTEM,1576,7872,0,4936,1,156250,2343750,173,3,28657) svchost.exe
(\\NANOCORP\web_svc,3268,15260,0,6212,3,312500,937500,366,8,28657) ctfmon.exe
(\\NT AUTHORITY\SYSTEM,2008,11064,0,6372,1,312500,781250,166,1,28657) svchost.exe
(\\NANOCORP\web_svc,27664,92156,0,6620,27,56875000,78437500,1576,34,28656) explorer.exe
(\\NANOCORP\web_svc,12576,53956,0,7040,12,2500000,2343750,569,10,28652) StartMenuExperienceHost.exe
(\\NANOCORP\web_svc,10016,43164,0,7080,9,1875000,1562500,544,8,28651) TextInputHost.exe
(\\NANOCORP\web_svc,2636,16332,0,6056,2,156250,625000,192,1,28651) RuntimeBroker.exe
(\\NANOCORP\web_svc,31896,66860,0,5544,31,18906250,11406250,670,15,28650) SearchApp.exe
(\\NANOCORP\web_svc,20272,39004,0,6696,19,7187500,11250000,321,1,28648) RuntimeBroker.exe
(\\NANOCORP\web_svc,2280,13280,0,7224,2,781250,1250000,225,1,28646) RuntimeBroker.exe
(\\NT AUTHORITY\SYSTEM,7888,31016,0,7716,7,937500,2812500,355,5,28638) LogonUI.exe
(\\NANOCORP\web_svc,3132,12504,0,8108,3,0,156250,203,1,28635) AzureArcSysTray.exe
(\\NANOCORP\web_svc,2260,14528,0,3480,2,156250,156250,171,2,28538) svchost.exe
(\\NT AUTHORITY\LOCAL SERVICE,2412,14680,0,7748,2,156250,312500,178,2,22103) svchost.exe
(\\NANOCORP\monitoring_svc,69644,95052,0,6296,68,16562500,6250000,1325,13,2703) wsmprovhost.exe
(\\NT AUTHORITY\SYSTEM,1272,6288,0,4620,1,312500,0,120,2,2547) svchost.exe
(\\NANOCORP\web_svc,116868,129384,0,6900,114,48750000,19687500,765,14,2546) powershell.exe
(\\NANOCORP\web_svc,2660,6800,0,7972,2,1250000,10312500,86,2,2546) conhost.exe
<<<>>>
<<<>>>
<<<systemtime>>>
1762926156
|