Summary Operating System Windows 10 Pro 64-bit CPU Intel Core i3 5005U @ 2.00GHz 48 °C Broadwell-U 14nm Technology RAM 4.00GB Single-Channel DDR3 @ 800MHz (11-11-11-28) Motherboard Acer ZORO_BH (U3E1) Graphics Generic PnP Monitor (1366x768@60Hz) Intel HD Graphics 5500 (Acer Incorporated [ALI]) Storage 931GB Western Digital WDC WD10JPVX-22JC3T0 (SATA ) 36 °C Optical Drives MATSHITA DVD-RAM UJ8HC Audio Realtek High Definition Audio Operating System Windows 10 Pro 64-bit Computer type: Notebook Installation Date: 16-03-2021 21:44:59 Serial Number: xxxxxxx Windows Security Center User Account Control (UAC) Enabled Notify level 2 - Default Windows Update AutoUpdate Not configured Windows Defender Windows Defender Disabled Firewall Firewall Enabled Display Name Kaspersky Internet Security Antivirus Windows Defender Antivirus Disabled Virus Signature Database Up to date Kaspersky Internet Security Antivirus Enabled Virus Signature Database Up to date .NET Frameworks installed v4.8 Full v4.8 Client v3.5 SP1 v3.0 SP2 v2.0 SP2 Internet Explorer Version 11.789.19041.0 PowerShell Version 5.1.19041.1 Environment Variables USERPROFILE C:\Users\Admin SystemRoot C:\WINDOWS User Variables MOZ_PLUGIN_PATH C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\ OneDrive C:\Users\Admin\OneDrive OneDriveConsumer C:\Users\Admin\OneDrive Path C:\Users\Admin\AppData\Local\Microsoft\WindowsApps TEMP C:\Users\Admin\AppData\Local\Temp TMP C:\Users\Admin\AppData\Local\Temp Machine Variables ComSpec C:\WINDOWS\system32\cmd.exe DriverData C:\Windows\System32\Drivers\DriverData NUMBER_OF_PROCESSORS 4 OS Windows_NT Path C:\WINDOWS\system32 C:\WINDOWS C:\WINDOWS\System32\Wbem C:\WINDOWS\System32\WindowsPowerShell\v1.0\ C:\WINDOWS\System32\OpenSSH\ PATHEXT .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC PROCESSOR_ARCHITECTURE AMD64 PROCESSOR_IDENTIFIER Intel64 Family 6 Model 61 Stepping 4, GenuineIntel PROCESSOR_LEVEL 6 PROCESSOR_REVISION 3d04 PSModulePath %ProgramFiles%\WindowsPowerShell\Modules C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules TEMP C:\WINDOWS\TEMP TMP C:\WINDOWS\TEMP USERNAME SYSTEM windir C:\WINDOWS Battery AC Line Online Battery Charge % 100 % Battery State High Remaining Battery Time Unknown Power Profile Active power scheme Balanced Hibernation Enabled Turn Off Monitor after: (On AC Power) Never Turn Off Monitor after: (On Battery Power) 5 min Turn Off Hard Disk after: (On AC Power) 20 min Turn Off Hard Disk after: (On Battery Power) 10 min Suspend after: (On AC Power) Never Suspend after: (On Battery Power) 15 min Screen saver Disabled Uptime Current Session Current Time 18-03-2021 08:43:28 Current Uptime 59,699 sec (0 d, 16 h, 34 m, 59 s) Last Boot Time 17-03-2021 16:08:29 Services Running Adobe Acrobat Update Service Running AnyDesk Service Running Application Information Running AppX Deployment Service (AppXSVC) Running AVCTP service Running Background Tasks Infrastructure Service Running Base Filtering Engine Running Bluetooth Audio Gateway Service Running Bluetooth Support Service Running Capability Access Manager Service Running Client License Service (ClipSVC) Running Clipboard User Service_b40220 Running CNG Key Isolation Running COM+ Event System Running Connected Devices Platform Service Running Connected Devices Platform User Service_b40220 Running Connected User Experiences and Telemetry Running CoreMessaging Running Credential Manager Running Cryptographic Services Running Data Usage Running DCOM Server Process Launcher Running Delivery Optimization Running Device Association Service Running DHCP Client Running Diagnostic Policy Service Running Diagnostic Service Host Running Diagnostic System Host Running Display Enhancement Service Running Display Policy Service Running Distributed Link Tracking Client Running DNS Client Running Foxit Reader Update Service Running Geolocation Service Running IKE and AuthIP IPsec Keying Modules Running Intel HD Graphics Control Panel Service Running IP Helper Running IPsec Policy Agent Running Kaspersky Anti-Virus Service 21.2 Running Kaspersky Password Manager Service Running Kaspersky VPN Secure Connection Service 5.2 Running Local Session Manager Running Microsoft Account Sign-in Assistant Running Microsoft Passport Running Microsoft Passport Container Running Microsoft Store Install Service Running Network Connection Broker Running Network List Service Running Network Location Awareness Running Network Store Interface Service Running Office Software Protection Platform Running Peer Name Resolution Protocol Running Peer Networking Identity Manager Running Plug and Play Running Power Running Print Spooler Running Program Compatibility Assistant Service Running Radio Management Service Running Remote Access Connection Manager Running Remote Procedure Call (RPC) Running RPC Endpoint Mapper Running Secure Socket Tunneling Protocol Service Running Security Accounts Manager Running Security Center Running Server Running Shell Hardware Detection Running SSDP Discovery Running State Repository Service Running Storage Service Running Sync Host_b40220 Running SysMain Running System Event Notification Service Running System Events Broker Running System Guard Runtime Monitor Broker Running Task Scheduler Running TCP/IP NetBIOS Helper Running Telephony Running Themes Running Time Broker Running Touch Keyboard and Handwriting Panel Service Running Update Orchestrator Service Running User Manager Running User Profile Service Running Web Account Manager Running Windows Audio Running Windows Audio Endpoint Builder Running Windows Connection Manager Running Windows Defender Firewall Running Windows Event Log Running Windows Font Cache Service Running Windows Image Acquisition (WIA) Running Windows License Manager Service Running Windows Management Instrumentation Running Windows Modules Installer Running Windows Presentation Foundation Font Cache 3.0.0.0 Running Windows Push Notifications System Service Running Windows Push Notifications User Service_b40220 Running Windows Search Running Windows Security Service Running Windows Update Running WinHTTP Web Proxy Auto-Discovery Service Running WLAN AutoConfig Running Workstation Stopped ActiveX Installer (AxInstSV) Stopped Agent Activation Runtime_b40220 Stopped AllJoyn Router Service Stopped App Readiness Stopped Application Identity Stopped Application Layer Gateway Service Stopped Application Management Stopped AssignedAccessManager Service Stopped Auto Time Zone Updater Stopped Background Intelligent Transfer Service Stopped BitLocker Drive Encryption Service Stopped Block Level Backup Engine Service Stopped Bluetooth User Support Service_b40220 Stopped BranchCache Stopped CaptureService_b40220 Stopped Cellular Time Stopped Certificate Propagation Stopped COM+ System Application Stopped ConsentUX_b40220 Stopped Contact Data_b40220 Stopped CredentialEnrollmentManagerUserSvc_b40220 Stopped Data Sharing Service Stopped Device Install Service Stopped Device Management Enrollment Service Stopped Device Management Wireless Application Protocol (WAP) Push message Routing Service Stopped Device Setup Manager Stopped DeviceAssociationBroker_b40220 Stopped DevicePicker_b40220 Stopped DevicesFlow_b40220 Stopped DevQuery Background Discovery Broker Stopped Diagnostic Execution Service Stopped DialogBlockingService Stopped Distributed Transaction Coordinator Stopped Downloaded Maps Manager Stopped Embedded Mode Stopped Encrypting File System (EFS) Stopped Enterprise App Management Service Stopped Extensible Authentication Protocol Stopped Fax Stopped File History Service Stopped Function Discovery Provider Host Stopped Function Discovery Resource Publication Stopped GameDVR and Broadcast User Service_b40220 Stopped GraphicsPerfSvc Stopped Group Policy Client Stopped Human Interface Device Service Stopped HV Host Service Stopped Hyper-V Data Exchange Service Stopped Hyper-V Guest Service Interface Stopped Hyper-V Guest Shutdown Service Stopped Hyper-V Heartbeat Service Stopped Hyper-V PowerShell Direct Service Stopped Hyper-V Remote Desktop Virtualization Service Stopped Hyper-V Time Synchronization Service Stopped Hyper-V Volume Shadow Copy Requestor Stopped Intel Content Protection HECI Service Stopped Internet Connection Sharing (ICS) Stopped IP Translation Configuration Service Stopped Kaspersky Volume Shadow Copy Service Bridge 21.2 Stopped KtmRm for Distributed Transaction Coordinator Stopped Language Experience Service Stopped Link-Layer Topology Discovery Mapper Stopped Local Profile Assistant Service Stopped Malwarebytes Service Stopped MessagingService_b40220 Stopped Microsoft Diagnostics Hub Standard Collector Service Stopped Microsoft App-V Client Stopped Microsoft Defender Antivirus Network Inspection Service Stopped Microsoft Defender Antivirus Service Stopped Microsoft Edge Update Service (edgeupdate) Stopped Microsoft Edge Update Service (edgeupdatem) Stopped Microsoft iSCSI Initiator Service Stopped Microsoft Keyboard Filter Stopped Microsoft SharePoint Workspace Audit Service Stopped Microsoft Software Shadow Copy Provider Stopped Microsoft Storage Spaces SMP Stopped Microsoft Windows SMS Router Service. Stopped Mozilla Maintenance Service Stopped Natural Authentication Stopped Net.Tcp Port Sharing Service Stopped Netlogon Stopped Network Connected Devices Auto-Setup Stopped Network Connections Stopped Network Connectivity Assistant Stopped Network Setup Service Stopped Office Source Engine Stopped Offline Files Stopped OpenSSH Authentication Agent Stopped Optimize drives Stopped Parental Controls Stopped Payments and NFC/SE Manager Stopped Peer Networking Grouping Stopped Performance Counter DLL Host Stopped Performance Logs & Alerts Stopped Phone Service Stopped PNRP Machine Name Publication Service Stopped Portable Device Enumerator Service Stopped Printer Extensions and Notifications Stopped PrintWorkflow_b40220 Stopped Problem Reports Control Panel Support Stopped Quality Windows Audio Video Experience Stopped Recommended Troubleshooting Service Stopped Remote Access Auto Connection Manager Stopped Remote Desktop Configuration Stopped Remote Desktop Services Stopped Remote Desktop Services UserMode Port Redirector Stopped Remote Procedure Call (RPC) Locator Stopped Remote Registry Stopped Retail Demo Service Stopped Routing and Remote Access Stopped Secondary Logon Stopped Sensor Data Service Stopped Sensor Monitoring Service Stopped Sensor Service Stopped Shared PC Account Manager Stopped Smart Card Stopped Smart Card Device Enumeration Service Stopped Smart Card Removal Policy Stopped SNMP Trap Stopped Software Protection Stopped Spatial Data Service Stopped Spot Verifier Stopped Still Image Acquisition Events Stopped Storage Tiers Management Stopped Udk User Service_b40220 Stopped UPnP Device Host Stopped User Data Access_b40220 Stopped User Data Storage_b40220 Stopped User Experience Virtualization Service Stopped Virtual Disk Stopped Volume Shadow Copy Stopped Volumetric Audio Compositor Service Stopped WalletService Stopped WarpJITSvc Stopped WebClient Stopped Wi-Fi Direct Services Connection Manager Service Stopped Windows Backup Stopped Windows Biometric Service Stopped Windows Camera Frame Server Stopped Windows Connect Now - Config Registrar Stopped Windows Defender Advanced Threat Protection Service Stopped Windows Encryption Provider Host Service Stopped Windows Error Reporting Service Stopped Windows Event Collector Stopped Windows Insider Service Stopped Windows Installer Stopped Windows Management Service Stopped Windows Media Player Network Sharing Service Stopped Windows Mixed Reality OpenXR Service Stopped Windows Mobile Hotspot Service Stopped Windows Perception Service Stopped Windows Perception Simulation Service Stopped Windows PushToInstall Service Stopped Windows Remote Management (WS-Management) Stopped Windows Time Stopped Windows Update Medic Service Stopped Wired AutoConfig Stopped WMI Performance Adapter Stopped Work Folders Stopped WPS Office Cloud Service Stopped WWAN AutoConfig Stopped Xbox Accessory Management Service Stopped Xbox Live Auth Manager Stopped Xbox Live Game Save Stopped Xbox Live Networking Service TimeZone TimeZone GMT +5:30 Hours Language English (United States) Location India Format English (India) Currency ? Date Format dd-MM-yyyy Time Format HH:mm:ss Scheduler 18-03-2021 08:51; MicrosoftEdgeUpdateTaskMachineUA 18-03-2021 12:00; Adobe Acrobat Update Task 18-03-2021 20:46; OneDrive Standalone Update Task-S-1-5-21-3076391084-2480122960-4283986350-1002 18-03-2021 23:51; MicrosoftEdgeUpdateTaskMachineCore 19-03-2021 02:58; OneDrive Standalone Update Task-S-1-5-21-3076391084-2480122960-4283986350-500 CCleanerSkipUAC CreateExplorerShellUnelevatedTask Hotfixes Installed 17-03-2021 Windows Malicious Software Removal Tool x64 - v5.87 (KB890830) After the download, this tool runs one time to check your computer for infection by specific, prevalent malicious software (including Blaster, Sasser, and Mydoom) and helps remove any infection that is found. If an infection is found, the tool will display a status report the next time that you start your computer. A new version of the tool will be offered every month. If you want to manually run the tool on your computer, you can download a copy from the Microsoft Download Center, or you can run an online version from microsoft.com. This tool is not a replacement for an antivirus product. To help protect your computer, you should use an antivirus product. 17-03-2021 2021-02 Cumulative Update for .NET Framework 3.5 and 4.8 for Windows 10, version 20H2 for x64 (KB4601050) A security issue has been identified in a Microsoft software product that could affect your system. You can help protect your system by installing this update from Microsoft. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article. After you install this update, you may have to restart your system. Not Installed 17-03-2021 2021-01 Update for Windows 10 Version 20H2 for x64-based Systems (KB4023057) Installation Status In Progress A security issue has been identified in a Microsoft software product that could affect your system. You can help protect your system by installing this update from Microsoft. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article. After you install this update, you may have to restart your system. System Folders Application Data C:\ProgramData Cookies C:\Users\Admin\AppData\Local\Microsoft\Windows\INetCookies Desktop D:\Users\Hari\Desktop Documents C:\Users\Public\Documents Fonts C:\WINDOWS\Fonts Global Favorites D:\Users\Hari\Favorites Internet History C:\Users\Admin\AppData\Local\Microsoft\Windows\History Local Application Data C:\Users\Admin\AppData\Local Music C:\Users\Public\Music Path for burning CD C:\Users\Admin\AppData\Local\Microsoft\Windows\Burn\Burn Physical Desktop D:\Users\Hari\Desktop Pictures C:\Users\Public\Pictures Program Files C:\Program Files Public Desktop C:\Users\Public\Desktop Start Menu C:\ProgramData\Microsoft\Windows\Start Menu Start Menu Programs C:\ProgramData\Microsoft\Windows\Start Menu\Programs Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup Templates C:\ProgramData\Microsoft\Windows\Templates Temporary Internet Files C:\Users\Admin\AppData\Local\Microsoft\Windows\INetCache User Favorites D:\Users\Hari\Favorites Videos C:\Users\Public\Videos Windows Directory C:\WINDOWS Windows/System C:\WINDOWS\system32 Process List AnyDesk.exe Process ID 3900 User SYSTEM Domain NT AUTHORITY Path C:\Program Files (x86)\AnyDesk\AnyDesk.exe Memory Usage 5.50 MB Peak Memory Usage 28 MB ApplicationFrameHost.exe Process ID 8656 User Admin Domain PINKYPC Path C:\Windows\System32\ApplicationFrameHost.exe Memory Usage 26 MB Peak Memory Usage 28 MB armsvc.exe Process ID 3892 User SYSTEM Domain NT AUTHORITY Path C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe Memory Usage 1.18 MB Peak Memory Usage 6.45 MB audiodg.exe Process ID 13928 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\audiodg.exe Memory Usage 16 MB Peak Memory Usage 23 MB avp.exe Process ID 3940 User SYSTEM Domain NT AUTHORITY Path C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 21.2\avp.exe Memory Usage 241 MB Peak Memory Usage 314 MB avp.exe Process ID 8420 User SYSTEM Domain NT AUTHORITY Path C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 21.2\avp.exe Memory Usage 40 MB Peak Memory Usage 61 MB avpui.exe Process ID 12488 User Admin Domain PINKYPC Path C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 21.2\avpui.exe Memory Usage 7.52 MB Peak Memory Usage 165 MB CompPkgSrv.exe Process ID 11920 User Admin Domain PINKYPC Path C:\Windows\System32\CompPkgSrv.exe Memory Usage 8.64 MB Peak Memory Usage 8.77 MB conhost.exe Process ID 11788 User Admin Domain PINKYPC Path C:\Windows\System32\conhost.exe Memory Usage 8.61 MB Peak Memory Usage 12 MB csrss.exe Process ID 12124 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\csrss.exe Memory Usage 5.52 MB Peak Memory Usage 18 MB csrss.exe Process ID 708 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\csrss.exe Memory Usage 3.37 MB Peak Memory Usage 5.52 MB ctfmon.exe Process ID 12832 User Admin Domain PINKYPC Path C:\Windows\System32\ctfmon.exe Memory Usage 16 MB Peak Memory Usage 18 MB dllhost.exe Process ID 13220 User Admin Domain PINKYPC Path C:\Windows\System32\dllhost.exe Memory Usage 6.94 MB Peak Memory Usage 7.14 MB dwm.exe Process ID 10096 User DWM-4 Domain Window Manager Path C:\Windows\System32\dwm.exe Memory Usage 72 MB Peak Memory Usage 82 MB explorer.exe Process ID 11132 User Admin Domain PINKYPC Path C:\Windows\explorer.exe Memory Usage 113 MB Peak Memory Usage 129 MB firefox.exe Process ID 10844 User Admin Domain PINKYPC Path C:\Program Files\Mozilla Firefox\firefox.exe Memory Usage 38 MB Peak Memory Usage 38 MB firefox.exe Process ID 6880 User Admin Domain PINKYPC Path C:\Program Files\Mozilla Firefox\firefox.exe Memory Usage 25 MB Peak Memory Usage 25 MB firefox.exe Process ID 11428 User Admin Domain PINKYPC Path C:\Program Files\Mozilla Firefox\firefox.exe Memory Usage 181 MB Peak Memory Usage 395 MB firefox.exe Process ID 11668 User Admin Domain PINKYPC Path C:\Program Files\Mozilla Firefox\firefox.exe Memory Usage 368 MB Peak Memory Usage 412 MB firefox.exe Process ID 12516 User Admin Domain PINKYPC Path C:\Program Files\Mozilla Firefox\firefox.exe Memory Usage 90 MB Peak Memory Usage 113 MB firefox.exe Process ID 9144 User Admin Domain PINKYPC Path C:\Program Files\Mozilla Firefox\firefox.exe Memory Usage 142 MB Peak Memory Usage 142 MB firefox.exe Process ID 10472 User Admin Domain PINKYPC Path C:\Program Files\Mozilla Firefox\firefox.exe Memory Usage 103 MB Peak Memory Usage 542 MB firefox.exe Process ID 9752 User Admin Domain PINKYPC Path C:\Program Files\Mozilla Firefox\firefox.exe Memory Usage 214 MB Peak Memory Usage 271 MB fontdrvhost.exe Process ID 1020 User UMFD-0 Domain Font Driver Host Path C:\Windows\System32\fontdrvhost.exe Memory Usage 608 KB Peak Memory Usage 3.59 MB fontdrvhost.exe Process ID 6948 User UMFD-4 Domain Font Driver Host Path C:\Windows\System32\fontdrvhost.exe Memory Usage 5.40 MB Peak Memory Usage 5.41 MB FoxitReader.exe Process ID 9808 User Admin Domain PINKYPC Path C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitReader.exe Memory Usage 54 MB Peak Memory Usage 68 MB FoxitReaderConnectedPDFService.exe Process ID 8044 User Admin Domain PINKYPC Path C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitReaderConnectedPDFService.exe Memory Usage 14 MB Peak Memory Usage 15 MB FoxitReaderUpdateService.exe Process ID 3952 User SYSTEM Domain NT AUTHORITY Path C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitReaderUpdateService.exe Memory Usage 1.70 MB Peak Memory Usage 7.88 MB igfxCUIService.exe Process ID 2504 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\igfxCUIService.exe Memory Usage 4.64 MB Peak Memory Usage 9.79 MB igfxEM.exe Process ID 11100 User Admin Domain PINKYPC Path C:\Windows\System32\igfxEM.exe Memory Usage 12 MB Peak Memory Usage 14 MB igfxHK.exe Process ID 12608 User Admin Domain PINKYPC Path C:\Windows\System32\igfxHK.exe Memory Usage 9.76 MB Peak Memory Usage 11 MB igfxTray.exe Process ID 12528 User Admin Domain PINKYPC Path C:\Windows\System32\igfxTray.exe Memory Usage 11 MB Peak Memory Usage 12 MB kpm_service.exe Process ID 4000 User SYSTEM Domain NT AUTHORITY Path C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_service.exe Memory Usage 9.94 MB Peak Memory Usage 38 MB ksde.exe Process ID 1436 User SYSTEM Domain NT AUTHORITY Path C:\Program Files (x86)\Kaspersky Lab\Kaspersky VPN 5.2\ksde.exe Memory Usage 22 MB Peak Memory Usage 44 MB ksdeui.exe Process ID 8668 User Admin Domain PINKYPC Path C:\Program Files (x86)\Kaspersky Lab\Kaspersky VPN 5.2\ksdeui.exe Memory Usage 4.40 MB Peak Memory Usage 20 MB lsass.exe Process ID 868 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\lsass.exe Memory Usage 16 MB Peak Memory Usage 22 MB Memory Compression Process ID 2392 User SYSTEM Domain NT AUTHORITY Memory Usage 105 MB Peak Memory Usage 155 MB MoUsoCoreWorker.exe Process ID 13536 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\MoUsoCoreWorker.exe Memory Usage 15 MB Peak Memory Usage 22 MB notepad.exe Process ID 11396 User Admin Domain PINKYPC Path C:\Windows\System32\notepad.exe Memory Usage 14 MB Peak Memory Usage 14 MB OSPPSVC.EXE Process ID 12596 User NETWORK SERVICE Domain NT AUTHORITY Path C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE Memory Usage 12 MB Peak Memory Usage 14 MB plugins_nms.exe Process ID 10632 User Admin Domain PINKYPC Path C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 21.2\plugins_nms.exe Memory Usage 8.11 MB Peak Memory Usage 13 MB PresentationFontCache.exe Process ID 6272 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe Memory Usage 2.49 MB Peak Memory Usage 21 MB RAVCpl64.exe Process ID 10352 User Admin Domain PINKYPC Path C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe Memory Usage 14 MB Peak Memory Usage 15 MB Registry Process ID 100 User SYSTEM Domain NT AUTHORITY Memory Usage 50 MB Peak Memory Usage 95 MB RuntimeBroker.exe Process ID 9092 User Admin Domain PINKYPC Path C:\Windows\System32\RuntimeBroker.exe Memory Usage 18 MB Peak Memory Usage 18 MB RuntimeBroker.exe Process ID 6788 User Admin Domain PINKYPC Path C:\Windows\System32\RuntimeBroker.exe Memory Usage 38 MB Peak Memory Usage 38 MB RuntimeBroker.exe Process ID 3268 User Admin Domain PINKYPC Path C:\Windows\System32\RuntimeBroker.exe Memory Usage 13 MB Peak Memory Usage 21 MB RuntimeBroker.exe Process ID 4496 User Admin Domain PINKYPC Path C:\Windows\System32\RuntimeBroker.exe Memory Usage 9.28 MB Peak Memory Usage 11 MB RuntimeBroker.exe Process ID 10220 User Admin Domain PINKYPC Path C:\Windows\System32\RuntimeBroker.exe Memory Usage 28 MB Peak Memory Usage 33 MB SearchApp.exe Process ID 9868 User Admin Domain PINKYPC Path C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe Memory Usage 78 MB Peak Memory Usage 163 MB SearchFilterHost.exe Process ID 11496 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\SearchFilterHost.exe Memory Usage 7.25 MB Peak Memory Usage 7.26 MB SearchIndexer.exe Process ID 6716 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\SearchIndexer.exe Memory Usage 19 MB Peak Memory Usage 30 MB SearchProtocolHost.exe Process ID 14300 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\SearchProtocolHost.exe Memory Usage 19 MB Peak Memory Usage 20 MB SecurityHealthService.exe Process ID 2300 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\SecurityHealthService.exe Memory Usage 5.49 MB Peak Memory Usage 13 MB services.exe Process ID 860 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\services.exe Memory Usage 6.43 MB Peak Memory Usage 14 MB SettingSyncHost.exe Process ID 11800 User Admin Domain PINKYPC Path C:\Windows\System32\SettingSyncHost.exe Memory Usage 5.09 MB Peak Memory Usage 14 MB SgrmBroker.exe Process ID 3492 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\SgrmBroker.exe Memory Usage 4.09 MB Peak Memory Usage 8.21 MB Signal.exe Process ID 9832 User Admin Domain PINKYPC Path C:\Users\Admin\AppData\Local\Programs\signal-desktop\Signal.exe Memory Usage 199 MB Peak Memory Usage 200 MB Signal.exe Process ID 10372 User Admin Domain PINKYPC Path C:\Users\Admin\AppData\Local\Programs\signal-desktop\Signal.exe Memory Usage 94 MB Peak Memory Usage 130 MB Signal.exe Process ID 9420 User Admin Domain PINKYPC Path C:\Users\Admin\AppData\Local\Programs\signal-desktop\Signal.exe Memory Usage 34 MB Peak Memory Usage 34 MB Signal.exe Process ID 12324 User Admin Domain PINKYPC Path C:\Users\Admin\AppData\Local\Programs\signal-desktop\Signal.exe Memory Usage 173 MB Peak Memory Usage 187 MB sihost.exe Process ID 1428 User Admin Domain PINKYPC Path C:\Windows\System32\sihost.exe Memory Usage 25 MB Peak Memory Usage 26 MB smartscreen.exe Process ID 11772 User Admin Domain PINKYPC Path C:\Windows\System32\smartscreen.exe Memory Usage 37 MB Peak Memory Usage 37 MB smss.exe Process ID 476 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\smss.exe Memory Usage 496 KB Peak Memory Usage 1.23 MB Speccy64.exe Process ID 10736 User Admin Domain PINKYPC Path C:\Program Files\Speccy\Speccy64.exe Memory Usage 32 MB Peak Memory Usage 32 MB spoolsv.exe Process ID 3544 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\spoolsv.exe Memory Usage 5.32 MB Peak Memory Usage 16 MB StartMenuExperienceHost.exe Process ID 876 User Admin Domain PINKYPC Path C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe Memory Usage 65 MB Peak Memory Usage 75 MB svchost.exe Process ID 4136 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 12 MB Peak Memory Usage 21 MB svchost.exe Process ID 4280 User NETWORK SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 1.65 MB Peak Memory Usage 7.79 MB svchost.exe Process ID 4316 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 2.36 MB Peak Memory Usage 6.42 MB svchost.exe Process ID 4448 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 5.06 MB Peak Memory Usage 14 MB svchost.exe Process ID 4488 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 1.13 MB Peak Memory Usage 5.82 MB svchost.exe Process ID 4392 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 12 MB Peak Memory Usage 20 MB svchost.exe Process ID 5152 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 11 MB Peak Memory Usage 21 MB svchost.exe Process ID 5320 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 2.88 MB Peak Memory Usage 8.37 MB svchost.exe Process ID 5684 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 16 MB Peak Memory Usage 20 MB svchost.exe Process ID 5996 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 3.90 MB Peak Memory Usage 8.82 MB svchost.exe Process ID 2532 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 4.18 MB Peak Memory Usage 10 MB svchost.exe Process ID 8128 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 8.95 MB Peak Memory Usage 16 MB svchost.exe Process ID 6408 User NETWORK SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 9.38 MB Peak Memory Usage 16 MB svchost.exe Process ID 6996 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 5.93 MB Peak Memory Usage 12 MB svchost.exe Process ID 3020 User NETWORK SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 5.21 MB Peak Memory Usage 9.42 MB svchost.exe Process ID 2924 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 5.46 MB Peak Memory Usage 9.76 MB svchost.exe Process ID 2544 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 4.40 MB Peak Memory Usage 12 MB svchost.exe Process ID 5444 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 31 MB Peak Memory Usage 65 MB svchost.exe Process ID 2676 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 5.31 MB Peak Memory Usage 14 MB svchost.exe Process ID 1696 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 2.46 MB Peak Memory Usage 17 MB svchost.exe Process ID 8152 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 2.84 MB Peak Memory Usage 11 MB svchost.exe Process ID 984 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 3.02 MB Peak Memory Usage 7.70 MB svchost.exe Process ID 8180 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 7.54 MB Peak Memory Usage 8.14 MB svchost.exe Process ID 1732 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 7.28 MB Peak Memory Usage 13 MB svchost.exe Process ID 992 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 20 MB Peak Memory Usage 33 MB svchost.exe Process ID 676 User NETWORK SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 11 MB Peak Memory Usage 14 MB svchost.exe Process ID 10884 User Admin Domain PINKYPC Path C:\Windows\System32\svchost.exe Memory Usage 25 MB Peak Memory Usage 35 MB svchost.exe Process ID 908 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 5.13 MB Peak Memory Usage 8.29 MB svchost.exe Process ID 9588 User Admin Domain PINKYPC Path C:\Windows\System32\svchost.exe Memory Usage 29 MB Peak Memory Usage 32 MB svchost.exe Process ID 1276 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 5.29 MB Peak Memory Usage 10 MB svchost.exe Process ID 1300 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 2.88 MB Peak Memory Usage 7.98 MB svchost.exe Process ID 1316 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 4.28 MB Peak Memory Usage 11 MB svchost.exe Process ID 1324 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 6.83 MB Peak Memory Usage 12 MB svchost.exe Process ID 9788 User Admin Domain PINKYPC Path C:\Windows\System32\svchost.exe Memory Usage 17 MB Peak Memory Usage 18 MB svchost.exe Process ID 1548 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 4.37 MB Peak Memory Usage 11 MB svchost.exe Process ID 1556 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 1.89 MB Peak Memory Usage 5.95 MB svchost.exe Process ID 11560 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 5.29 MB Peak Memory Usage 5.78 MB svchost.exe Process ID 11704 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 7.97 MB Peak Memory Usage 8.39 MB svchost.exe Process ID 1580 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 4.02 MB Peak Memory Usage 8.73 MB svchost.exe Process ID 1612 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 8.88 MB Peak Memory Usage 16 MB svchost.exe Process ID 1752 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 9.82 MB Peak Memory Usage 20 MB svchost.exe Process ID 1872 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 2.89 MB Peak Memory Usage 7.18 MB svchost.exe Process ID 1900 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 2.95 MB Peak Memory Usage 7.71 MB svchost.exe Process ID 2008 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 6.80 MB Peak Memory Usage 9.66 MB svchost.exe Process ID 2036 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 11 MB Peak Memory Usage 22 MB svchost.exe Process ID 784 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 3.48 MB Peak Memory Usage 7.44 MB svchost.exe Process ID 1156 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 7.34 MB Peak Memory Usage 9.45 MB svchost.exe Process ID 2168 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 3.76 MB Peak Memory Usage 7.71 MB svchost.exe Process ID 2176 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 4.78 MB Peak Memory Usage 7.21 MB svchost.exe Process ID 2192 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 59 MB Peak Memory Usage 86 MB svchost.exe Process ID 2208 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 1.39 MB Peak Memory Usage 5.86 MB svchost.exe Process ID 2348 User NETWORK SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 7.61 MB Peak Memory Usage 12 MB svchost.exe Process ID 2408 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 4.71 MB Peak Memory Usage 8.53 MB svchost.exe Process ID 6552 User Admin Domain PINKYPC Path C:\Windows\System32\svchost.exe Memory Usage 12 MB Peak Memory Usage 13 MB svchost.exe Process ID 2516 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 5.48 MB Peak Memory Usage 9.68 MB svchost.exe Process ID 2580 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 3.84 MB Peak Memory Usage 8.10 MB svchost.exe Process ID 2596 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 3.16 MB Peak Memory Usage 7.77 MB svchost.exe Process ID 2684 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 14 MB Peak Memory Usage 21 MB svchost.exe Process ID 3040 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 9.93 MB Peak Memory Usage 13 MB svchost.exe Process ID 2668 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 2.54 MB Peak Memory Usage 6.71 MB svchost.exe Process ID 3036 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 4.67 MB Peak Memory Usage 10 MB svchost.exe Process ID 3216 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 7.01 MB Peak Memory Usage 18 MB svchost.exe Process ID 3440 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 7.38 MB Peak Memory Usage 14 MB svchost.exe Process ID 3608 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 9.71 MB Peak Memory Usage 27 MB svchost.exe Process ID 4088 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 1.24 MB Peak Memory Usage 7.10 MB svchost.exe Process ID 3648 User NETWORK SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 2.57 MB Peak Memory Usage 8.38 MB svchost.exe Process ID 3784 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 2.34 MB Peak Memory Usage 8.53 MB svchost.exe Process ID 12428 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 11 MB Peak Memory Usage 11 MB svchost.exe Process ID 3792 User NETWORK SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 3.84 MB Peak Memory Usage 9.59 MB svchost.exe Process ID 3912 User NETWORK SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 7.91 MB Peak Memory Usage 13 MB svchost.exe Process ID 3920 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 27 MB Peak Memory Usage 63 MB svchost.exe Process ID 9008 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 13 MB Peak Memory Usage 13 MB svchost.exe Process ID 9600 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 9.21 MB Peak Memory Usage 9.27 MB svchost.exe Process ID 3932 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 15 MB Peak Memory Usage 35 MB svchost.exe Process ID 3968 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 5.31 MB Peak Memory Usage 12 MB svchost.exe Process ID 4056 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 3.60 MB Peak Memory Usage 9.49 MB svchost.exe Process ID 3300 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 2.86 MB Peak Memory Usage 8.75 MB svchost.exe Process ID 3256 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 1.41 MB Peak Memory Usage 5.99 MB svchost.exe Process ID 12588 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 6.59 MB Peak Memory Usage 6.59 MB svchost.exe Process ID 14280 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 5.95 MB Peak Memory Usage 6.05 MB System Process ID 4 Memory Usage 808 KB Peak Memory Usage 4.61 MB System Idle Process Process ID 0 taskhostw.exe Process ID 9980 User Admin Domain PINKYPC Path C:\Windows\System32\taskhostw.exe Memory Usage 13 MB Peak Memory Usage 14 MB TextInputHost.exe Process ID 10796 User Admin Domain PINKYPC Path C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\InputApp\TextInputHost.exe Memory Usage 38 MB Peak Memory Usage 44 MB TiWorker.exe Process ID 1268 User SYSTEM Domain NT AUTHORITY Path C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.860_none_e73d0c67262f5c28\TiWorker.exe Memory Usage 29 MB Peak Memory Usage 29 MB TrustedInstaller.exe Process ID 10664 User SYSTEM Domain NT AUTHORITY Path C:\Windows\servicing\TrustedInstaller.exe Memory Usage 7.27 MB Peak Memory Usage 7.30 MB UserOOBEBroker.exe Process ID 10108 User Admin Domain PINKYPC Path C:\Windows\System32\oobe\UserOOBEBroker.exe Memory Usage 8.84 MB Peak Memory Usage 8.92 MB wininit.exe Process ID 788 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\wininit.exe Memory Usage 3.32 MB Peak Memory Usage 7.02 MB winlogon.exe Process ID 8988 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\winlogon.exe Memory Usage 9.82 MB Peak Memory Usage 14 MB WinStore.App.exe Process ID 12008 User Admin Domain PINKYPC Path C:\Program Files\WindowsApps\Microsoft.WindowsStore_12011.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe Memory Usage 1.44 MB Peak Memory Usage 57 MB WmiPrvSE.exe Process ID 9516 User NETWORK SERVICE Domain NT AUTHORITY Path C:\Windows\SysWOW64\wbem\WmiPrvSE.exe Memory Usage 3.84 MB Peak Memory Usage 10 MB WmiPrvSE.exe Process ID 13980 User NETWORK SERVICE Domain NT AUTHORITY Path C:\Windows\System32\wbem\WmiPrvSE.exe Memory Usage 21 MB Peak Memory Usage 21 MB WmiPrvSE.exe Process ID 7204 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\wbem\WmiPrvSE.exe Memory Usage 9.11 MB Peak Memory Usage 9.11 MB WUDFHost.exe Process ID 10056 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\WUDFHost.exe Memory Usage 8.09 MB Peak Memory Usage 8.82 MB YourPhone.exe Process ID 10684 User Admin Domain PINKYPC Path C:\Program Files\WindowsApps\Microsoft.YourPhone_1.21021.117.0_x64__8wekyb3d8bbwe\YourPhone.exe Memory Usage 41 MB Peak Memory Usage 57 MB Security Options Accounts: Administrator account status Disabled Accounts: Block Microsoft accounts Not Defined Accounts: Guest account status Disabled Accounts: Limit local account use of blank passwords to console logon only Enabled Accounts: Rename administrator account Administrator Accounts: Rename guest account Guest Audit: Audit the access of global system objects Disabled Audit: Audit the use of Backup and Restore privilege Disabled Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings Not Defined Audit: Shut down system immediately if unable to log security audits Disabled DCOM: Machine Access Restrictions in Security Descriptor Definition Language (SDDL) syntax Not Defined DCOM: Machine Launch Restrictions in Security Descriptor Definition Language (SDDL) syntax Not Defined Devices: Allow undock without having to log on Enabled Devices: Allowed to format and eject removable media Not Defined Devices: Prevent users from installing printer drivers Disabled Devices: Restrict CD-ROM access to locally logged-on user only Not Defined Devices: Restrict floppy access to locally logged-on user only Not Defined Domain controller: Allow server operators to schedule tasks Not Defined Domain controller: Allow vulnerable Netlogon secure channel connections Not Defined Domain controller: LDAP server channel binding token requirements Not Defined Domain controller: LDAP server signing requirements Not Defined Domain controller: Refuse machine account password changes Not Defined Domain member: Digitally encrypt or sign secure channel data (always) Enabled Domain member: Digitally encrypt secure channel data (when possible) Enabled Domain member: Digitally sign secure channel data (when possible) Enabled Domain member: Disable machine account password changes Disabled Domain member: Maximum machine account password age 30 days Domain member: Require strong (Windows 2000 or later) session key Enabled Interactive logon: Display user information when the session is locked Not Defined Interactive logon: Do not require CTRL+ALT+DEL Not Defined Interactive logon: Don't display last signed-in Disabled Interactive logon: Don't display username at sign-in Not Defined Interactive logon: Machine account lockout threshold Not Defined Interactive logon: Machine inactivity limit Not Defined Interactive logon: Message text for users attempting to log on Interactive logon: Message title for users attempting to log on Interactive logon: Number of previous logons to cache (in case domain controller is not available) 10 logons Interactive logon: Prompt user to change password before expiration 5 days Interactive logon: Require Domain Controller authentication to unlock workstation Disabled Interactive logon: Require Windows Hello for Business or smart card Disabled Interactive logon: Smart card removal behavior No Action Microsoft network client: Digitally sign communications (always) Disabled Microsoft network client: Digitally sign communications (if server agrees) Enabled Microsoft network client: Send unencrypted password to third-party SMB servers Disabled Microsoft network server: Amount of idle time required before suspending session 15 minutes Microsoft network server: Attempt S4U2Self to obtain claim information Not Defined Microsoft network server: Digitally sign communications (always) Disabled Microsoft network server: Digitally sign communications (if client agrees) Disabled Microsoft network server: Disconnect clients when logon hours expire Enabled Microsoft network server: Server SPN target name validation level Not Defined Minimum password length audit Not Defined Network access: Allow anonymous SID/Name translation Disabled Network access: Do not allow anonymous enumeration of SAM accounts Enabled Network access: Do not allow anonymous enumeration of SAM accounts and shares Disabled Network access: Do not allow storage of passwords and credentials for network authentication Disabled Network access: Let Everyone permissions apply to anonymous users Disabled Network access: Named Pipes that can be accessed anonymously Network access: Remotely accessible registry paths System\CurrentControlSet\Control\ProductOptions,System\CurrentControlSet\Control\Server Applications,Software\Microsoft\Windows NT\CurrentVersion Network access: Remotely accessible registry paths and sub-paths System\CurrentControlSet\Control\Print\Printers,System\CurrentControlSet\Services\Eventlog,Software\Microsoft\OLAP Server,Software\Microsoft\Windows NT\CurrentVersion\Print,Software\Microsoft\Windows NT\CurrentVersion\Windows,System\CurrentControlSet\Control\ContentIndex,System\CurrentControlSet\Control\Terminal Server,System\CurrentControlSet\Control\Terminal Server\UserConfig,System\CurrentControlSet\Control\Terminal Server\DefaultUserConfiguration,Software\Microsoft\Windows NT\CurrentVersion\Perflib,System\CurrentControlSet\Services\SysmonLog Network access: Restrict anonymous access to Named Pipes and Shares Enabled Network access: Restrict clients allowed to make remote calls to SAM Network access: Shares that can be accessed anonymously Not Defined Network access: Sharing and security model for local accounts Classic - local users authenticate as themselves Network security: Allow Local System to use computer identity for NTLM Not Defined Network security: Allow LocalSystem NULL session fallback Not Defined Network security: Allow PKU2U authentication requests to this computer to use online identities. Not Defined Network security: Configure encryption types allowed for Kerberos Not Defined Network security: Do not store LAN Manager hash value on next password change Enabled Network security: Force logoff when logon hours expire Disabled Network security: LAN Manager authentication level Not Defined Network security: LDAP client signing requirements Negotiate signing Network security: Minimum session security for NTLM SSP based (including secure RPC) clients Require 128-bit encryption Network security: Minimum session security for NTLM SSP based (including secure RPC) servers Require 128-bit encryption Network security: Restrict NTLM: Add remote server exceptions for NTLM authentication Not Defined Network security: Restrict NTLM: Add server exceptions in this domain Not Defined Network security: Restrict NTLM: Audit Incoming NTLM Traffic Not Defined Network security: Restrict NTLM: Audit NTLM authentication in this domain Not Defined Network security: Restrict NTLM: Incoming NTLM traffic Not Defined Network security: Restrict NTLM: NTLM authentication in this domain Not Defined Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers Not Defined Recovery console: Allow automatic administrative logon Disabled Recovery console: Allow floppy copy and access to all drives and all folders Disabled Relax minimum password length limits Not Defined Shutdown: Allow system to be shut down without having to log on Enabled Shutdown: Clear virtual memory pagefile Disabled System cryptography: Force strong key protection for user keys stored on the computer Not Defined System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing Disabled System objects: Require case insensitivity for non-Windows subsystems Enabled System objects: Strengthen default permissions of internal system objects (e.g. Symbolic Links) Enabled System settings: Optional subsystems System settings: Use Certificate Rules on Windows Executables for Software Restriction Policies Disabled User Account Control: Admin Approval Mode for the Built-in Administrator account Disabled User Account Control: Allow UIAccess applications to prompt for elevation without using the secure desktop Disabled User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode Prompt for consent for non-Windows binaries User Account Control: Behavior of the elevation prompt for standard users Prompt for credentials User Account Control: Detect application installations and prompt for elevation Disabled User Account Control: Only elevate executables that are signed and validated Disabled User Account Control: Only elevate UIAccess applications that are installed in secure locations Enabled User Account Control: Run all administrators in Admin Approval Mode Enabled User Account Control: Switch to the secure desktop when prompting for elevation Enabled User Account Control: Virtualize file and registry write failures to per-user locations Enabled Device Tree ACPI x64-based PC Microsoft ACPI-Compliant System ACPI Fixed Feature Button ACPI Lid ACPI Power Button ACPI Processor Aggregator ACPI Sleep Button ACPI Thermal Zone Intel Core i3-5005U CPU @ 2.00GHz Intel Core i3-5005U CPU @ 2.00GHz Intel Core i3-5005U CPU @ 2.00GHz Intel Core i3-5005U CPU @ 2.00GHz Microsoft AC Adapter Microsoft ACPI-Compliant Control Method Battery Trusted Platform Module 2.0 PCI Express Root Complex Intel Management Engine Interface Intel Serial IO DMA Controller Intel Serial IO I2C Host Controller - 9CE2 Microsoft Windows Management Interface for ACPI Mobile 5th Generation Intel Core Host Bridge - OPI - 1604 Mobile 5th Generation Intel Core PCI Express Root Port #1 - 9C90 Mobile 5th Generation Intel Core SMBus Controller - 9CA2 Motherboard resources Motherboard resources Intel(R) HD Graphics 5500 Generic PnP Monitor Intel(R) USB 3.0 eXtensible Host Controller - 1.0 (Microsoft) USB Root Hub (USB 3.0) Realtek USB 2.0 Card Reader Bluetooth USB Module Bluetooth Device (Personal Area Network) Bluetooth Device (RFCOMM Protocol TDI) Microsoft Bluetooth LE Enumerator Microsoft Bluetooth Enumerator 17faa2a1 Bluetooth Peripheral Device Bluetooth Peripheral Device Bluetooth Peripheral Device Bluetooth Peripheral Device Galaxy A30 A2DP SNK Galaxy A30 Avrcp Transport Galaxy A30 Avrcp Transport Galaxy J6+ Galaxy J6+ A2DP SNK Galaxy J6+ Avrcp Transport Galaxy J6+ Avrcp Transport Headset Audio Gateway Service Headset Audio Gateway Service Object Push Service Object Push Service Personal Area Network NAP Service Personal Area Network NAP Service Personal Area Network Service Personal Area Network Service Phonebook Access Pse Service Phonebook Access Pse Service Sim Access Service SMS/MMS SMS/MMS Galaxy A30 Hands-Free HF Galaxy A30 Hands-Free HF Audio Galaxy J6+ Hands-Free HF Galaxy J6+ Hands-Free HF Audio USB Composite Device HD WebCam USB Composite Device Remote NDIS based Internet Sharing Device USB Mass Storage Device ZTE MMC Storage USB Device High Definition Audio Controller Realtek High Definition Audio Microphone (Realtek High Definition Audio) Speakers (Realtek High Definition Audio) Mobile 5th Generation Intel(R) Core(TM) PCI Express Root Port #3 - 9C94 Realtek PCIe GBE Family Controller Mobile 5th Generation Intel(R) Core(TM) PCI Express Root Port #4 - 9C96 Qualcomm Atheros QCA9377 Wireless Network Adapter Microsoft Wi-Fi Direct Virtual Adapter #3 Microsoft Wi-Fi Direct Virtual Adapter #4 Mobile 5th Generation Intel(R) Core(TM) USB EHCI Controller - 9CA6 USB Root Hub Generic USB Hub Mobile 5th Generation Intel(R) Core(TM) Base SKU LPC Controller - 9CC5 Direct memory access controller High precision event timer Legacy device Microsoft ACPI-Compliant Embedded Controller Motherboard resources Motherboard resources Programmable interrupt controller Standard PS/2 Keyboard System CMOS/real time clock System timer Standard SATA AHCI Controller MATSHITA DVD-RAM UJ8HC WDC WD10JPVX-22JC3T0 Intel(R) Serial IO I2C Host Controller - 9CE1 I2C HID Device HID-compliant mouse HID-compliant touch pad Microsoft Input Configuration Device Synaptics HID Device CPU Intel Core i3 5005U Cores 2 Threads 4 Name Intel Core i3 5005U Code Name Broadwell-U Package Socket 1168 BGA Technology 14nm Specification Intel Core i3-5005U CPU @ 2.00GHz Family 6 Extended Family 6 Model D Extended Model 3D Stepping 4 Revision E0/F0 Instructions MMX, SSE, SSE2, SSE3, SSSE3, SSE4.1, SSE4.2, Intel 64, NX, VMX, AES, AVX, AVX2, FMA3 Virtualization Supported, Enabled Hyperthreading Supported, Enabled Bus Speed 100.0 MHz Stock Core Speed 2000 MHz Stock Bus Speed 100 MHz Average Temperature 48 °C Caches L1 Data Cache Size 2 x 32 KBytes L1 Instructions Cache Size 2 x 32 KBytes L2 Unified Cache Size 2 x 256 KBytes L3 Unified Cache Size 3072 KBytes Cores Core 0 Core Speed 2000.2 MHz Multiplier x 20.0 Bus Speed 100.0 MHz Temperature 48 °C Threads APIC ID: 0, 1 Core 1 Core Speed 800.1 MHz Multiplier x 8.0 Bus Speed 100.0 MHz Temperature 47 °C Threads APIC ID: 2, 3 RAM Memory slots Total memory slots 2 Used memory slots 1 Free memory slots 1 Memory Type DDR3 Size 4096 MBytes Channels # Single DRAM Frequency 800.1 MHz CAS# Latency (CL) 11 clocks RAS# to CAS# Delay (tRCD) 11 clocks RAS# Precharge (tRP) 11 clocks Cycle Time (tRAS) 28 clocks Command Rate (CR) 1T Physical Memory Memory Usage 76 % Total Physical 3.92 GB Available Physical 931 MB Total Virtual 6.55 GB Available Virtual 3.05 GB SPD Number Of SPD Modules 1 Slot #1 Type DDR3 Size 4096 MBytes Manufacturer SK Hynix Max Bandwidth PC3-12800 (800 MHz) Part Number HMT451S6BFR8A-PB Serial Number 559860074 Week/year 34 / 14 Timing table JEDEC #1 Frequency 381.0 MHz CAS# Latency 5.0 RAS# To CAS# 5 RAS# Precharge 5 tRAS 14 tRC 19 Voltage 1.350 V JEDEC #2 Frequency 457.1 MHz CAS# Latency 6.0 RAS# To CAS# 6 RAS# Precharge 6 tRAS 16 tRC 22 Voltage 1.350 V JEDEC #3 Frequency 533.3 MHz CAS# Latency 7.0 RAS# To CAS# 7 RAS# Precharge 7 tRAS 19 tRC 26 Voltage 1.350 V JEDEC #4 Frequency 609.5 MHz CAS# Latency 8.0 RAS# To CAS# 8 RAS# Precharge 8 tRAS 22 tRC 30 Voltage 1.350 V JEDEC #5 Frequency 685.7 MHz CAS# Latency 9.0 RAS# To CAS# 9 RAS# Precharge 9 tRAS 24 tRC 33 Voltage 1.350 V JEDEC #6 Frequency 761.9 MHz CAS# Latency 10.0 RAS# To CAS# 10 RAS# Precharge 10 tRAS 27 tRC 37 Voltage 1.350 V JEDEC #7 Frequency 800.0 MHz CAS# Latency 11.0 RAS# To CAS# 11 RAS# Precharge 11 tRAS 28 tRC 39 Voltage 1.350 V Motherboard Manufacturer Acer Model ZORO_BH (U3E1) Version Type2 - A01 Board Version Chipset Vendor Intel Chipset Model Broadwell-U Chipset Revision 09 Southbridge Vendor Intel Southbridge Model Broadwell-U PCH L-P Southbridge Revision 03 BIOS Brand Insyde Corp. Version V1.37 Date 16-02-2016 PCI Data Graphics Monitor Name Generic PnP Monitor on Intel HD Graphics 5500 Current Resolution 1366x768 pixels Work Resolution 1366x728 pixels State Enabled, Primary Monitor Width 1366 Monitor Height 768 Monitor BPP 32 bits per pixel Monitor Frequency 60 Hz Device \\.\DISPLAY1\Monitor0 Intel HD Graphics 5500 Manufacturer Intel Model HD Graphics 5500 Device ID 8086-1616 Revision A Subvendor Acer Incorporated [ALI] (1025) Current Performance Level Level 0 Current GPU Clock 850 MHz Driver version 20.19.15.4703 Count of performance levels : 1 Level 1 - "Perf Level 0" GPU Clock 850 MHz Storage Hard drives WDC WD10JPVX-22JC3T0 Manufacturer Western Digital Heads 16 Cylinders 121,601 Tracks 31,008,255 Sectors 1,953,520,065 SATA type SATA-III 6.0Gb/s Device type Fixed ATA Standard ACS2 Serial Number WD-WX51A555ALUP Firmware Version Number 01.01A01 LBA Size 48-bit LBA Power On Count 3660 times Power On Time 280.5 days Speed 5400 RPM Features S.M.A.R.T., APM, NCQ Max. Transfer Mode SATA III 6.0Gb/s Used Transfer Mode SATA III 6.0Gb/s Interface SATA Capacity 931 GB Real size 1,000,204,886,016 bytes RAID Type None S.M.A.R.T Status Good Temperature 36 °C Temperature Range OK (less than 50 °C) S.M.A.R.T attributes 01 Attribute name Read Error Rate Real value 0 Current 200 Worst 200 Threshold 51 Raw Value 0000000000 Status Good 03 Attribute name Spin-Up Time Real value 1583 ms Current 188 Worst 178 Threshold 21 Raw Value 000000062F Status Good 04 Attribute name Start/Stop Count Real value 32,048 Current 68 Worst 68 Threshold 0 Raw Value 0000007D30 Status Good 05 Attribute name Reallocated Sectors Count Real value 0 Current 200 Worst 200 Threshold 140 Raw Value 0000000000 Status Good 07 Attribute name Seek Error Rate Real value 0 Current 200 Worst 200 Threshold 0 Raw Value 0000000000 Status Good 09 Attribute name Power-On Hours (POH) Real value 280d 11h Current 91 Worst 91 Threshold 0 Raw Value 0000001A4B Status Good 0A Attribute name Spin Retry Count Real value 0 Current 100 Worst 100 Threshold 0 Raw Value 0000000000 Status Good 0B Attribute name Recalibration Retries Real value 0 Current 100 Worst 100 Threshold 0 Raw Value 0000000000 Status Good 0C Attribute name Device Power Cycle Count Real value 3,660 Current 97 Worst 97 Threshold 0 Raw Value 0000000E4C Status Good BF Attribute name G-sense error rate Real value 753 Current 1 Worst 1 Threshold 0 Raw Value 00000002F1 Status Good C0 Attribute name Power-off Retract Count Real value 83 Current 200 Worst 200 Threshold 0 Raw Value 0000000053 Status Good C1 Attribute name Load/Unload Cycle Count Real value 76,835 Current 175 Worst 175 Threshold 0 Raw Value 0000012C23 Status Good C2 Attribute name Temperature Real value 36 °C Current 111 Worst 96 Threshold 0 Raw Value 0000000024 Status Good C4 Attribute name Reallocation Event Count Real value 0 Current 200 Worst 200 Threshold 0 Raw Value 0000000000 Status Good C5 Attribute name Current Pending Sector Count Real value 0 Current 200 Worst 200 Threshold 0 Raw Value 0000000000 Status Good C6 Attribute name Uncorrectable Sector Count Real value 0 Current 100 Worst 253 Threshold 0 Raw Value 0000000000 Status Good C7 Attribute name UltraDMA CRC Error Count Real value 0 Current 200 Worst 200 Threshold 0 Raw Value 0000000000 Status Good C8 Attribute name Write Error Rate / Multi-Zone Error Rate Real value 0 Current 100 Worst 253 Threshold 0 Raw Value 0000000000 Status Good Partition 0 Partition ID Disk #0, Partition #0 File System NTFS Volume Serial Number 8417E261 Size 499 MB Used Space 36.5 MB (7%) Free Space 463 MB (93%) Partition 1 Partition ID Disk #0, Partition #1 Disk Letter C: File System NTFS Volume Serial Number 0E1C588E Size 243 GB Used Space 206 GB (84%) Free Space 37.1 GB (16%) Partition 2 Partition ID Disk #0, Partition #2 Disk Letter D: File System NTFS Volume Serial Number EED484B5 Size 341 GB Used Space 207 GB (60%) Free Space 134 GB (40%) Partition 3 Partition ID Disk #0, Partition #3 Disk Letter E: File System NTFS Volume Serial Number 80E25899 Size 345 GB Used Space 301 GB (87%) Free Space 43 GB (13%) Optical Drives MATSHITA DVD-RAM UJ8HC Media Type DVD Writer Name MATSHITA DVD-RAM UJ8HC Availability Running/Full Power Capabilities Random Access, Supports Writing, Supports Removable Media Read capabilities CD-R, CD-RW, CD-ROM, DVD-RAM, DVD-ROM, DVD-R, DVD-RW, DVD+R, DVD+RW, DVD-R DL, DVD+R DL Write capabilities CD-R, CD-RW, DVD-RAM, DVD-R, DVD-RW, DVD+R, DVD+RW, DVD-R DL, DVD+R DL Config Manager Error Code Device is working properly Config Manager User Config FALSE Drive F: Media Loaded FALSE SCSI Bus 1 SCSI Logical Unit 0 SCSI Port 0 SCSI Target Id 0 Status OK Audio Sound Card Realtek High Definition Audio Playback Device Speakers (Realtek High Definition Audio) Recording Device Microphone (Realtek High Definition Audio) Peripherals Standard PS/2 Keyboard Device Kind Keyboard Device Name Standard PS/2 Keyboard Vendor Acer Incorporated [ALI] Location Mobile 5th Generation Intel Core Base SKU LPC Controller - 9CC5 Driver Date 6-21-2006 Version 10.0.19041.1 File C:\WINDOWS\system32\DRIVERS\i8042prt.sys File C:\WINDOWS\system32\DRIVERS\kbdclass.sys HID-compliant mouse Device Kind Mouse Device Name HID-compliant mouse Vendor SYN Location I2C HID Device Driver Date 6-21-2006 Version 10.0.19041.1 File C:\WINDOWS\system32\DRIVERS\mouhid.sys File C:\WINDOWS\system32\DRIVERS\mouclass.sys MMC Storage Device Kind Portable Device Device Name MMC Storage Vendor ZTE Comment G:\ Location Volume Driver Date 6-21-2006 Version 10.0.19041.746 File C:\WINDOWS\system32\DRIVERS\WUDFRd.sys Printers AnyDesk Printer (Default Printer) Printer Port AD_Port Print Processor winprint Availability Always Priority 1 Duplex None Print Quality 600 * 600 dpi Color Status Unknown Driver Driver Name AnyDesk v4 Printer Driver (v6.03) Driver Path C:\WINDOWS\System32\DriverStore\FileRepository\ntprint.inf_amd64_ec1e73781eaf7fda\Amd64\mxdwdrv.dll Fax Printer Port SHRFAX: Print Processor winprint Availability Always Priority 1 Duplex None Print Quality 200 * 200 dpi Monochrome Status Unknown Driver Driver Name Microsoft Shared Fax Driver (v4.00) Driver Path C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSDRV.DLL Microsoft Print to PDF Printer Port PORTPROMPT: Print Processor winprint Availability Always Priority 1 Duplex None Print Quality 600 * 600 dpi Color Status Unknown Driver Driver Name Microsoft Print To PDF (v6.03) Driver Path C:\WINDOWS\System32\DriverStore\FileRepository\ntprint.inf_amd64_ec1e73781eaf7fda\Amd64\mxdwdrv.dll Microsoft XPS Document Writer Printer Port PORTPROMPT: Print Processor winprint Availability Always Priority 1 Duplex None Print Quality 600 * 600 dpi Color Status Unknown Driver Driver Name Microsoft XPS Document Writer v4 (v6.03) Driver Path C:\WINDOWS\System32\DriverStore\FileRepository\ntprint.inf_amd64_ec1e73781eaf7fda\Amd64\mxdwdrv.dll OneNote for Windows 10 Printer Port Microsoft.Office.OneNote_16001.13801.20202.0_x64__8wekyb3d8bbwe_microsoft.onenoteim_S-1-5-21-3076391084-2480122960-4283986350-1002 Print Processor winprint Availability Always Priority 1 Duplex None Print Quality 300 * 300 dpi Color Status Unknown Driver Driver Name Microsoft Software Printer Driver (v6.03) Driver Path C:\WINDOWS\System32\DriverStore\FileRepository\ntprint.inf_amd64_ec1e73781eaf7fda\Amd64\mxdwdrv.dll Network You are connected to the internet Connected through Remote NDIS based Internet Sharing Device IP Address 192.168.0.153 Subnet mask 255.255.255.0 Gateway server 192.168.0.1 Preferred DNS server 192.168.0.1 DHCP Enabled DHCP server 192.168.0.1 External IP Address 42.110.180.1 Adapter Type Ethernet NetBIOS over TCP/IP Enabled via DHCP NETBIOS Node Type Hybrid node Link Speed 3.8 KBps Computer Name NetBIOS Name PINKYPC DNS Name PinkyPC Membership Part of workgroup Workgroup WORKGROUP Remote Desktop Disabled Console State Active Domain PINKYPC WinInet Info LAN Connection Local system uses a local area network to connect to the Internet Local system has RAS to connect to the Internet Wi-Fi Info Using native Wi-Fi API version 2 Available access points count 1 Wi-Fi (nishACT) SSID nishACT Frequency 2462000 kHz Channel Number 11 Name nishACT Signal Strength/Quality 19 Security Enabled State The interface is not connected to any network Dot11 Type Infrastructure BSS network Network Connectible Network Flags There is a profile for this network Cipher Algorithm to be used when joining this network AES-CCMP algorithm Default Auth used to join this network for the first time 802.11i RSNA algorithm that uses PSK WinHTTPInfo WinHTTPSessionProxyType No proxy Session Proxy Session Proxy Bypass Connect Retries 5 Connect Timeout (ms) 60,000 HTTP Version HTTP 1.1 Max Connects Per 1.0 Servers INFINITE Max Connects Per Servers INFINITE Max HTTP automatic redirects 10 Max HTTP status continue 10 Send Timeout (ms) 30,000 IEProxy Auto Detect Yes IEProxy Auto Config IEProxy IEProxy Bypass Default Proxy Config Access Type No proxy Default Config Proxy Default Config Proxy Bypass Sharing and Discovery Network Discovery Disabled File and Printer Sharing Enabled File and printer sharing service Enabled Simple File Sharing Enabled Administrative Shares Enabled Network access: Sharing and security model for local accounts Classic - local users authenticate as themselves Adapters List Enabled Bluetooth Device (Personal Area Network) Connection Name Bluetooth Network Connection DHCP enabled Yes MAC Address 5C-93-A2-7A-91-86 Kaspersky Security Data Escort Adapter Connection Name Ethernet 3 DHCP enabled No MAC Address 00-FF-81-11-18-30 Qualcomm Atheros QCA9377 Wireless Network Adapter Connection Name Wi-Fi DHCP enabled Yes MAC Address 5C-93-A2-7A-91-85 Realtek PCIe GBE Family Controller Connection Name Ethernet DHCP enabled Yes MAC Address 2C-60-0C-C6-F2-C4 Remote NDIS based Internet Sharing Device Connection Name Ethernet 2 NetBIOS over TCPIP Yes DHCP enabled Yes MAC Address 36-4B-50-B7-EF-DA IP Address 192.168.0.153 Subnet mask 255.255.255.0 Gateway server 192.168.0.1 DHCP 192.168.0.1 DNS Server 192.168.0.1 Network Shares No network shares Current TCP Connections AnyDesk.exe (3900) Local 0.0.0.0:7070 LISTEN Local 192.168.0.153:62207 ESTABLISHED Remote 51.89.98.181:80 (Querying... ) (HTTP) avp.exe (3940) Local 127.0.0.1:49681 LISTEN Local 192.168.0.153:63384 ESTABLISHED Remote 130.117.190.132:443 (Querying... ) (HTTPS) Local 127.0.0.1:49681 ESTABLISHED Remote 127.0.0.1:63923 (Querying... ) Local 127.0.0.1:49681 ESTABLISHED Remote 127.0.0.1:63908 (Querying... ) Local 127.0.0.1:49677 ESTABLISHED Remote 127.0.0.1:49678 (Querying... ) Local 192.168.0.153:63598 ESTABLISHED Remote 82.202.185.208:443 (Querying... ) (HTTPS) Local 127.0.0.1:49681 ESTABLISHED Remote 127.0.0.1:62327 (Querying... ) Local 127.0.0.1:49681 ESTABLISHED Remote 127.0.0.1:63546 (Querying... ) Local 127.0.0.1:49681 ESTABLISHED Remote 127.0.0.1:63561 (Querying... ) Local 127.0.0.1:49681 ESTABLISHED Remote 127.0.0.1:63572 (Querying... ) Local 127.0.0.1:49681 ESTABLISHED Remote 127.0.0.1:63640 (Querying... ) Local 127.0.0.1:49681 ESTABLISHED Remote 127.0.0.1:63639 (Querying... ) Local 127.0.0.1:63597 ESTABLISHED Remote 127.0.0.1:63596 (Querying... ) Local 127.0.0.1:63596 ESTABLISHED Remote 127.0.0.1:63597 (Querying... ) Local 192.168.0.153:64085 ESTABLISHED Remote 180.87.4.149:443 (Querying... ) (HTTPS) Local 192.168.0.153:64086 ESTABLISHED Remote 180.87.4.149:443 (Querying... ) (HTTPS) Local 192.168.0.153:63536 ESTABLISHED Remote 77.74.181.72:443 (Querying... ) (HTTPS) Local 127.0.0.1:49683 ESTABLISHED Remote 127.0.0.1:49682 (Querying... ) Local 127.0.0.1:49678 ESTABLISHED Remote 127.0.0.1:49677 (Querying... ) Local 127.0.0.1:49704 ESTABLISHED Remote 127.0.0.1:49703 (Querying... ) Local 127.0.0.1:49703 ESTABLISHED Remote 127.0.0.1:49704 (Querying... ) Local 127.0.0.1:49682 ESTABLISHED Remote 127.0.0.1:49683 (Querying... ) Local 192.168.0.153:63206 ESTABLISHED Remote 180.87.4.157:443 (Querying... ) (HTTPS) avp.exe (8420) Local 127.0.0.1:63990 ESTABLISHED Remote 127.0.0.1:63991 (Querying... ) Local 127.0.0.1:63991 ESTABLISHED Remote 127.0.0.1:63990 (Querying... ) Local 127.0.0.1:64054 ESTABLISHED Remote 127.0.0.1:64055 (Querying... ) Local 127.0.0.1:64055 ESTABLISHED Remote 127.0.0.1:64054 (Querying... ) Local 192.168.0.153:63992 ESTABLISHED Remote 37.48.82.67:443 (Querying... ) (HTTPS) C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitReader.exe (9808) Local 192.168.0.153:62287 CLOSE-WAIT Remote 3.224.74.126:443 (Querying... ) (HTTPS) Local 192.168.0.153:62288 CLOSE-WAIT Remote 3.224.74.126:443 (Querying... ) (HTTPS) Local 192.168.0.153:62292 CLOSE-WAIT Remote 52.7.147.82:80 (Querying... ) (HTTP) Local 192.168.0.153:62293 CLOSE-WAIT Remote 52.7.147.82:80 (Querying... ) (HTTP) Local 127.0.0.1:62289 ESTABLISHED Remote 127.0.0.1:44430 (Querying... ) C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitReaderConnectedPDFService.exe (8044) Local 127.0.0.1:44430 LISTEN Local 127.0.0.1:44430 ESTABLISHED Remote 127.0.0.1:62289 (Querying... ) C:\Program Files\Mozilla Firefox\firefox.exe (10472) Local 127.0.0.1:62258 ESTABLISHED Remote 127.0.0.1:62257 (Querying... ) Local 127.0.0.1:62257 ESTABLISHED Remote 127.0.0.1:62258 (Querying... ) C:\Program Files\Mozilla Firefox\firefox.exe (10844) Local 127.0.0.1:62841 ESTABLISHED Remote 127.0.0.1:62842 (Querying... ) Local 127.0.0.1:62842 ESTABLISHED Remote 127.0.0.1:62841 (Querying... ) C:\Program Files\Mozilla Firefox\firefox.exe (11668) Local 127.0.0.1:63546 ESTABLISHED Remote 127.0.0.1:49681 (Querying... ) Local 192.168.0.153:63718 ESTABLISHED Remote 199.232.194.133:443 (Querying... ) (HTTPS) Local 127.0.0.1:62240 ESTABLISHED Remote 127.0.0.1:62241 (Querying... ) Local 127.0.0.1:62327 ESTABLISHED Remote 127.0.0.1:49681 (Querying... ) Local 127.0.0.1:63908 ESTABLISHED Remote 127.0.0.1:49681 (Querying... ) Local 127.0.0.1:63923 ESTABLISHED Remote 127.0.0.1:49681 (Querying... ) Local 192.168.0.153:63436 ESTABLISHED Remote 34.223.130.205:443 (Querying... ) (HTTPS) Local 127.0.0.1:63640 ESTABLISHED Remote 127.0.0.1:49681 (Querying... ) Local 127.0.0.1:63639 ESTABLISHED Remote 127.0.0.1:49681 (Querying... ) Local 127.0.0.1:63572 ESTABLISHED Remote 127.0.0.1:49681 (Querying... ) Local 192.168.0.153:63646 ESTABLISHED Remote 54.192.66.66:443 (Querying... ) (HTTPS) Local 127.0.0.1:63561 ESTABLISHED Remote 127.0.0.1:49681 (Querying... ) Local 127.0.0.1:62241 ESTABLISHED Remote 127.0.0.1:62240 (Querying... ) Local 192.168.0.153:63674 ESTABLISHED Remote 54.179.40.96:443 (Querying... ) (HTTPS) Local 192.168.0.153:63689 ESTABLISHED Remote 13.251.70.152:443 (Querying... ) (HTTPS) C:\Program Files\Mozilla Firefox\firefox.exe (12516) Local 127.0.0.1:62247 ESTABLISHED Remote 127.0.0.1:62246 (Querying... ) Local 127.0.0.1:62246 ESTABLISHED Remote 127.0.0.1:62247 (Querying... ) C:\Program Files\Mozilla Firefox\firefox.exe (9144) Local 127.0.0.1:62251 ESTABLISHED Remote 127.0.0.1:62252 (Querying... ) Local 127.0.0.1:62252 ESTABLISHED Remote 127.0.0.1:62251 (Querying... ) C:\Program Files\Mozilla Firefox\firefox.exe (9752) Local 127.0.0.1:62315 ESTABLISHED Remote 127.0.0.1:62314 (Querying... ) Local 127.0.0.1:62314 ESTABLISHED Remote 127.0.0.1:62315 (Querying... ) C:\Users\Admin\AppData\Local\Programs\signal-desktop\Signal.exe (12324) Local 192.168.0.153:62630 ESTABLISHED Remote 76.223.92.165:443 (Querying... ) (HTTPS) C:\Windows\System32\smartscreen.exe (11772) Local 192.168.0.153:64000 ESTABLISHED Remote 23.209.113.232:443 (Querying... ) (HTTPS) kpm_service.exe (4000) Local 127.0.0.1:49687 ESTABLISHED Remote 127.0.0.1:49686 (Querying... ) Local 127.0.0.1:49686 ESTABLISHED Remote 127.0.0.1:49687 (Querying... ) ksde.exe (1436) Local 192.168.0.153:62632 CLOSE-WAIT Remote 81.19.104.172:443 (Querying... ) (HTTPS) Local 192.168.0.153:63403 ESTABLISHED Remote 82.202.185.211:443 (Querying... ) (HTTPS) Local 127.0.0.1:49719 ESTABLISHED Remote 127.0.0.1:49720 (Querying... ) Local 127.0.0.1:49720 ESTABLISHED Remote 127.0.0.1:49719 (Querying... ) Local 127.0.0.1:63399 ESTABLISHED Remote 127.0.0.1:63400 (Querying... ) Local 127.0.0.1:63400 ESTABLISHED Remote 127.0.0.1:63399 (Querying... ) lsass.exe (868) Local 0.0.0.0:49664 LISTEN services.exe (860) Local 0.0.0.0:49671 LISTEN spoolsv.exe (3544) Local 0.0.0.0:49670 LISTEN svchost.exe (1612) Local 0.0.0.0:49667 LISTEN svchost.exe (1752) Local 0.0.0.0:49666 LISTEN svchost.exe (4136) Local 192.168.0.153:62215 ESTABLISHED Remote 40.90.189.152:443 (Querying... ) (HTTPS) svchost.exe (5684) Local 0.0.0.0:5040 LISTEN svchost.exe (6408) Local 0.0.0.0:7680 LISTEN svchost.exe (676) Local 0.0.0.0:135 (DCE) LISTEN System Process Local 192.168.0.153:63996 TIME-WAIT Remote 52.152.110.14:443 (Querying... ) (HTTPS) Local 192.168.0.153:63648 TIME-WAIT Remote 104.18.225.52:443 (Querying... ) (HTTPS) Local 192.168.0.153:63556 TIME-WAIT Remote 172.217.174.77:443 (Querying... ) (HTTPS) Local 192.168.0.153:63554 TIME-WAIT Remote 157.240.192.16:443 (Querying... ) (HTTPS) Local 192.168.0.153:63544 TIME-WAIT Remote 172.67.133.233:80 (Querying... ) (HTTP) Local 192.168.0.153:63645 TIME-WAIT Remote 151.101.158.133:443 (Querying... ) (HTTPS) Local 192.168.0.153:63642 TIME-WAIT Remote 151.101.158.133:443 (Querying... ) (HTTPS) Local 192.168.0.153:63543 TIME-WAIT Remote 172.67.133.233:80 (Querying... ) (HTTP) Local 127.0.0.1:63980 TIME-WAIT Remote 127.0.0.1:63979 (Querying... ) Local 192.168.0.153:63632 TIME-WAIT Remote 35.186.241.3:443 (Querying... ) (HTTPS) Local 192.168.0.153:63562 TIME-WAIT Remote 142.250.183.3:443 (Querying... ) (HTTPS) Local 127.0.0.1:63982 TIME-WAIT Remote 127.0.0.1:63981 (Querying... ) Local 127.0.0.1:63497 TIME-WAIT Remote 127.0.0.1:49681 (Querying... ) Local 127.0.0.1:63498 TIME-WAIT Remote 127.0.0.1:49681 (Querying... ) Local 192.168.0.153:63902 TIME-WAIT Remote 13.250.173.68:443 (Querying... ) (HTTPS) Local 192.168.0.153:63541 TIME-WAIT Remote 142.250.183.46:443 (Querying... ) (HTTPS) Local 192.168.0.153:63505 TIME-WAIT Remote 104.16.95.65:443 (Querying... ) (HTTPS) Local 192.168.0.153:63504 TIME-WAIT Remote 172.217.163.67:443 (Querying... ) (HTTPS) Local 192.168.0.153:63503 TIME-WAIT Remote 192.0.73.2:443 (Querying... ) (HTTPS) Local 192.168.0.153:63502 TIME-WAIT Remote 172.67.133.233:80 (Querying... ) (HTTP) Local 192.168.0.153:63560 TIME-WAIT Remote 142.250.192.35:80 (Querying... ) (HTTP) Local 192.168.0.153:63983 TIME-WAIT Remote 180.87.4.149:443 (Querying... ) (HTTPS) Local 192.168.0.153:63962 TIME-WAIT Remote 172.67.133.233:80 (Querying... ) (HTTP) Local 192.168.0.153:63943 TIME-WAIT Remote 52.152.90.172:443 (Querying... ) (HTTPS) Local 192.168.0.153:63935 TIME-WAIT Remote 172.67.133.233:80 (Querying... ) (HTTP) Local 192.168.0.153:63934 TIME-WAIT Remote 172.67.133.233:80 (Querying... ) (HTTP) Local 192.168.0.153:63907 TIME-WAIT Remote 69.173.159.63:443 (Querying... ) (HTTPS) Local 192.168.0.153:63905 TIME-WAIT Remote 13.250.173.68:443 (Querying... ) (HTTPS) Local 192.168.0.153:63904 TIME-WAIT Remote 13.250.173.68:443 (Querying... ) (HTTPS) Local 192.168.0.153:63903 TIME-WAIT Remote 13.250.173.68:443 (Querying... ) (HTTPS) Local 192.168.0.153:63501 TIME-WAIT Remote 216.58.196.164:443 (Querying... ) (HTTPS) Local 192.168.0.153:63500 TIME-WAIT Remote 172.67.133.233:80 (Querying... ) (HTTP) Local 192.168.0.153:63901 TIME-WAIT Remote 13.250.173.68:443 (Querying... ) (HTTPS) Local 192.168.0.153:63864 TIME-WAIT Remote 172.217.174.234:443 (Querying... ) (HTTPS) Local 192.168.0.153:63711 TIME-WAIT Remote 13.33.171.50:443 (Querying... ) (HTTPS) System Process Local 0.0.0.0:445 (Windows shares) LISTEN Local 192.168.0.153:139 (NetBIOS session service) LISTEN wininit.exe (788) Local 0.0.0.0:49665 LISTEN Generated with Speccy v1.32.774