[collector:] client ino-rut-vlt01.powershell powershell XymonPS [date] Wed 10 Dec 20:30:17 2025 [clock] epoch: 1765359018 local: Wed 10 Dec 20:30:17 2025 UTC: Wed 10 Dec 09:30:17 2025 Time Synchronisation type: NT5DS Leap Indicator: 0(no warning) Stratum: 5 (secondary reference - syncd by (S)NTP) Precision: -23 (119.209ns per tick) Root Delay: 0.0069766s Root Dispersion: 0.0934821s ReferenceId: 0x0A023F2F (source IP: 10.2.63.47) Last Successful Sync Time: 10/12/2025 8:21:44 PM Source: INO-RUT-DC02.inside.inoxihp.com.au Poll Interval: 10 (1024s) [clientversion] 2.42 [uname] Microsoft Windows Server 2022 Datacenter (build 20348) [cpu] up: 13 days, 0 users, 146 procs, load=7.72% CPU states: total 7.72% cores: 6 CPU PID Image Name Pri Time MemUsage 2.1% 2180 BackupFP 8 02:25:28 592440k 1.1% 4068 SVC:MBAMService 8 11:52:45 265496k 0.9% 6148 SVC:IDriveService 8 10:07:56 516924k 0.9% 4 System 8 02:10:27 144k 0.6% 3820 SVC:WinDefend 8 08:05:30 332812k 0.6% 3076 SVC:CryptSvc 8 00:31:12 23932k 0.2% 1304 SVC:MSSQL$AUTODESKVAULT 8 02:32:33 19415184k 0.2% 12000 SVC:swprv 8 00:00:03 14208k 0.2% 8572 AdskIdentityManager 8 02:51:03 20432k 0.1% 768 SVC:KeyIso/Netlogon/SamSs 9 00:53:30 29184k 0.1% 4228 SVC:BASupportExpressStandalone 13 01:03:09 54960k 0.1% 3384 SVC:Mesh Agent 8 02:13:59 5762772k 0.1% 11520 SVC:VSS 8 00:00:01 22480k 0.1% 1392 SVC:EventLog 8 02:09:52 46244k 0.1% 3504 SVC:SQLWriter 8 00:03:15 55944k 0.1% 12668 WmiPrvSE 8 00:03:12 37984k 0.1% 7084 powershell 8 01:27:29 161248k 0.0% 3280 SVC:Winmgmt 8 00:42:27 34664k 0.0% 760 services 9 00:15:13 16804k 0.0% 13736 powershell 8 00:00:00 84148k 0.0% 10524 SVC:LTService 8 00:05:04 33540k 0.0% 12084 BASupSysInf 6 00:01:25 19548k 0.0% 2732 SVC:AdskLicensingService 8 00:28:38 25180k 0.0% 10404 w3wp 8 00:00:58 187432k 0.0% 3784 SVC:Windows Agent Service 8 00:21:38 323408k 0.0% 1896 SVC:EventSystem 8 00:00:16 8756k 0.0% 5368 SVC:WSearch 8 00:06:47 26632k 0.0% 7492 SVC:DPS 8 00:11:44 22864k 0.0% 8556 SVC:WdNisSvc 8 00:01:48 13928k 0.0% 2788 SVC:Autodesk CER Service 8 00:12:45 28504k 0.0% 12892 SVC:sppsvc 8 00:00:00 12780k 0.0% 1008 SVC:RpcEptMapper/RpcSs 8 00:10:03 33152k 0.0% 1228 SVC:Dnscache 8 00:07:18 10028k 0.0% 6112 cscript 4 00:00:00 19092k 0.0% 5244 dllhost 8 00:00:00 12928k 0.0% 3844 SVC:XymonPSClient 8 00:00:00 6596k 0.0% 5348 SVC:VeeamEndpointBackupSvc 8 00:01:01 96952k 0.0% 3756 SVC:UsoSvc 8 00:00:12 13936k 0.0% 3720 SVC:TrkWks 8 00:00:03 6080k 0.0% 5548 w3wp 8 00:01:40 519040k 0.0% 5880 adsk_hive_host 8 00:00:43 26440k 0.0% 3952 SVC:WinRM 8 00:00:06 12840k 0.0% 4420 fdhost 8 00:00:07 7512k 0.0% 4992 Veeam.Guest.Interaction.Proxy 8 00:00:00 10168k 0.0% 4056 SVC:WpnService 8 00:00:00 11196k 0.0% 4304 SVC:RasMan 8 00:00:12 13604k 0.0% 4048 SVC:VeeamDeploySvc 8 00:00:07 20088k 0.0% 5132 AggregatorHost 8 00:00:19 10880k 0.0% 3964 SVC:W3SVC/WAS 8 00:00:08 13612k 0.0% 5060 conhost 8 00:00:00 10784k 0.0% 4024 SVC:VeeamTransportSvc 8 00:00:01 10724k 0.0% 6068 SVC:SQLTELEMETRY$AUTODESKVAULT 6 00:02:49 72356k 0.0% 9588 SVC:MSDTC 8 00:00:00 11380k 0.0% 9636 conhost 4 11028k 0.0% 9872 SVC:WdiSystemHost 8 00:00:00 6320k 0.0% 9492 conhost 8 00:00:00 10864k 0.0% 8992 SVC:MSSQLFDLauncher$AUTODESKVA 8 00:00:00 4604k 0.0% 9168 SVC:SolarWinds.MSP.RpcServerSe 8 00:01:38 77484k 0.0% 9332 SVC:StateRepository 8 00:00:09 12120k 0.0% 13352 conhost 6 00:00:00 11012k 0.0% 13920 conhost 8 00:00:00 11036k 0.0% 14216 SVC:LTSvcMon 8 00:00:10 7096k 0.0% 10840 WmiPrvSE 8 00:00:04 14612k 0.0% 9908 SVC:UALSVC 8 00:00:02 21144k 0.0% 9960 SVC:ScreenConnect Client (69e7 8 00:00:00 41244k 0.0% 10308 SVC:DsSvc 8 00:00:00 11144k 0.0% 7064 SVC:BASupportExpressSrvcUpdate 8 00:01:55 25508k 0.0% 7092 conhost 8 00:03:10 15284k 0.0% 7188 NableSixtyFourBitManager 8 00:00:04 66884k 0.0% 6932 AdskLicensingAgent 8 00:00:01 23836k 0.0% 6152 SVC:WaaSMedicSvc 8 00:00:00 8300k 0.0% 6620 SVC:DispBrokerDesktopSvc 8 00:00:00 7472k 0.0% 6756 conhost 8 00:00:00 10788k 0.0% 8136 NableReactiveManagement 8 00:00:14 45524k 0.0% 8772 WmiPrvSE 8 00:00:00 9652k 0.0% 8836 SVC:CDPSvc 8 00:00:00 12012k 0.0% 7964 SVC:PcaSvc 8 00:00:05 13236k 0.0% 7324 SVC:StorSvc 8 00:00:01 15516k 0.0% 7432 conhost 8 00:00:00 10784k 0.0% 7712 w3wp 8 00:00:02 45376k 0.0% 3600 SVC:SysMain 8 00:00:01 7248k 0.0% 1172 SVC:SolarWinds.MSP.CacheServic 8 00:01:31 54052k 0.0% 1152 SVC:TimeBrokerSvc 8 00:00:00 6500k 0.0% 1464 dwm 13 00:01:27 51920k 0.0% 1324 LogonUI 13 00:00:16 53796k 0.0% 1096 SVC:SecurityHealthService 8 00:00:00 11656k 0.0% 1048 SVC:W32Time 8 00:00:12 8872k 0.0% 1144 SVC:NcbService 8 00:00:00 8680k 0.0% 1136 SVC:Dhcp 8 00:00:39 8436k 0.0% 1740 SVC:CertPropSvc 8 00:00:00 6644k 0.0% 1700 SVC:gpsvc 8 00:00:06 18664k 0.0% 1800 SVC:UmRdpService 8 00:00:00 7028k 0.0% 1768 SVC:netprofm 8 00:00:10 11744k 0.0% 1556 SVC:ProfSvc 8 00:00:00 11672k 0.0% 1480 SVC:BFE/mpssvc 8 00:01:01 19192k 0.0% 1656 SVC:UserManager 8 00:00:00 8164k 0.0% 1572 SVC:NlaSvc 8 00:00:00 13112k 0.0% 616 wininit 13 00:00:00 7296k 0.0% 520 csrss 13 00:04:18 7068k 0.0% 688 winlogon 13 00:00:00 10588k 0.0% 624 csrss 13 00:00:01 6044k 0.0% 148 Registry 8 00:01:01 112796k 0.0% 0 Idle 0 8k 0.0% 472 SVC:LSM 8 00:01:20 9708k 0.0% 408 smss 11 00:00:00 1256k 0.0% 948 SVC:SSDPSRV 8 00:01:04 8420k 0.0% 936 fontdrvhost 8 00:00:00 4560k 0.0% 1040 SVC:lmhosts 8 00:00:00 5760k 0.0% 1028 SVC:nsi 8 00:00:15 9064k 0.0% 848 SVC:Backup Service Controller 8 00:00:26 10744k 0.0% 732 SVC:TermService 8 00:00:47 16176k 0.0% 928 fontdrvhost 8 00:00:02 7544k 0.0% 900 SVC:BrokerInfrastructure/DcomL 8 00:01:01 17408k 0.0% 1840 SVC:Schedule 8 00:01:08 16860k 0.0% 2988 SVC:MsDtsServer160 8 00:00:00 24204k 0.0% 2892 SVC:AzureAttestService 8 00:00:00 6256k 0.0% 3108 SVC:FlexNet Licensing Service 8 00:00:29 14132k 0.0% 3100 SVC:DiagTrack 8 00:01:35 44360k 0.0% 2836 SVC:Autodesk Data Management S 8 00:00:03 38972k 0.0% 2824 SVC:Autodesk Data Management J 8 00:00:29 30600k 0.0% 2872 SVC:AutomationManagerAgent 8 00:01:02 164248k 0.0% 2844 SVC:Autodesk Access Service Ho 8 00:00:58 55352k 0.0% 3472 SVC:SstpSvc 8 00:00:00 7652k 0.0% 3332 SVC:MDCoreSvc 8 00:00:16 24712k 0.0% 3552 SVC:SQLBrowser 8 00:00:00 6228k 0.0% 3512 SVC:LanmanServer 8 00:01:00 9416k 0.0% 3120 SVC:HelpDeskService 8 00:00:37 8556k 0.0% 3116 SVC:FOSWindowsService 8 00:00:52 65404k 0.0% 3204 SVC:SSISTELEMETRY160 6 00:00:16 52928k 0.0% 3128 SVC:IISADMIN 8 00:01:04 28904k 0.0% 2224 SVC:ShellHWDetection 8 00:00:00 8956k 0.0% 2192 SVC:WinHttpAutoProxySvc 8 00:00:09 8152k 0.0% 2296 SVC:FontCache 8 00:00:00 7084k 0.0% 2272 SVC:CoreMessagingRegistrar 8 00:00:16 6400k 0.0% 2056 SVC:SENS 8 00:00:01 9540k 0.0% 1964 SVC:Themes 8 00:00:00 6024k 0.0% 2164 SVC:Wcmsvc 8 00:00:01 9232k 0.0% 2124 SVC:LanmanWorkstation 8 00:00:36 9980k 0.0% 2548 SVC:iphlpsvc 8 00:00:01 10936k 0.0% 2536 SVC:PolicyAgent 8 00:00:09 7788k 0.0% 2752 SVC:AppHostSvc 8 00:00:12 15448k 0.0% 2620 SVC:Spooler 8 00:00:21 30484k 0.0% 2364 SVC:PME.Agent.PmeService 8 00:00:02 34876k 0.0% 2324 SVC:Windows Agent Maintenance 8 00:00:11 33072k 0.0% 2524 SVC:IKEEXT 8 00:00:01 8736k 0.0% 2416 SVC:SessionEnv 8 00:00:00 10376k [disk] Filesystem 1K-blocks Used Avail Capacity Mounted Label Summary(Total\Avail GB) C 209074172 91759916 117314256 44% /FIXED/C:\ 199.39\111.88 E 3145709564 1818978192 1326731372 58% /FIXED/E:\ Vault_Data 2999.98\1265.27 [memory] memory Total Used physical: 65535 32387 virtual: 9728 79 page: 75263 32568 [msgs:EventlogSummary] LogMode MaximumSizeInBytes RecordCount LogName ------- ------------------ ----------- ------- Circular 20971520 32317 Security Circular 20971520 61861 System Circular 20971520 43466 Application [msgs:eventlog_Security] [msgs:eventlog_System] Information - 12/10/2025 20:27:49 - [98] - Microsoft-Windows-Ntfs - Volume Vault_Data (\Device\HarddiskVolumeShadowCopy1060) is healthy. No action is needed. Information - 12/10/2025 20:27:48 - [98] - Microsoft-Windows-Ntfs - Volume ?? (\Device\HarddiskVolumeShadowCopy1059) is healthy. No action is needed. Information - 12/10/2025 20:27:34 - [4] - Virtual Disk Service - Service stopped. Information - 12/10/2025 20:27:24 - [98] - Microsoft-Windows-Ntfs - Volume System Reserved (\Device\HarddiskVolumeShadowCopy1058) is healthy. No action is needed. Information - 12/10/2025 20:27:24 - [98] - Microsoft-Windows-Ntfs - Volume ?? (\Device\HarddiskVolumeShadowCopy1057) is healthy. No action is needed. Information - 12/10/2025 20:27:09 - [3] - Virtual Disk Service - Service started. [msgs:eventlog_Application] Information - 12/10/2025 20:30:13 - [16394] - Microsoft-Windows-Security-SPP - Offline downlevel migration succeeded. Information - 12/10/2025 20:28:20 - [105] - Backup Manager - Backup finished for data source VssMsSqlBackupPlugin with session status Completed. Selected size: 53.9G; Selected count: 62; Processed size: 53.9G; Processed count: 62; Sent size: 8.07M; Errors count: 0; Removed files count: 0. [procs] PID User WorkingSet/Peak VirtualMem/Peak PagedMem/Peak NPS Handles %CPU Start Time Elapsed Name Command 2180 NT AUTHORITY\SYSTEM 592440/932548 5398208/5637984 578520/924928 60 898 2.1 2025-11-29 11:44:54 16365 BackupFP "C:\Program Files\Backup Manager\BackupFP.exe" 4068 Unknown 265496/1026096 5170396/6188724 438368/1261556 70 4363 1.1 2025-11-27 02:12:52 19817 SVC:MBAMService 6148 NT AUTHORITY\SYSTEM 516924/890100 5277992/5774012 483868/920576 61 4086 0.9 2025-11-27 02:15:17 19815 SVC:IDriveService "C:\Program Files (x86)\IDriveWindows\id_service.exe" 4 Unknown 144/5960 3968/19008 44/72 0 2602 0.9 2025-11-27 02:12:49 19817 System 3820 Unknown 332812/1168636 2152943520/2154002512 349628/1152004 246 1002 0.6 2025-11-27 02:12:52 19817 SVC:WinDefend 3076 NT AUTHORITY\NETWORK SERVICE 23932/84064 2152398120/2152442560 13212/72300 31 363 0.6 2025-11-27 02:12:51 19817 SVC:CryptSvc C:\Windows\system32\svchost.exe -k NetworkService -p -s CryptSvc 1304 NT SERVICE\MSSQL$AUTODESKVAULT 19415184/19415892 131392932/131422504 19785148/19791972 353 1245 0.2 2025-11-27 02:15:18 19815 SVC:MSSQL$AUTODESKVAULT "C:\VaultData\Microsoft SQL Server\MSSQL16.AUTODESKVAULT\MSSQL\Binn\sqlservr.exe" -sAUTODESKVAULT 12000 NT AUTHORITY\SYSTEM 14208/206268 2151802708/2151998292 3320/195904 15 359 0.2 2025-12-10 20:27:20 3 SVC:swprv C:\Windows\System32\svchost.exe -k swprv 8572 IIS APPPOOL\AutodeskFSPool 20432/20856 4318400/4333436 5920/6584 20 278 0.2 2025-11-28 07:15:37 18075 AdskIdentityManager "C:\Program Files\Autodesk\AdskIdentityManager\1.14.0.3/AdskIdentityManager.exe" --process_name Autodesk.IDSDK.DefaultProcess-v2 --server_name Autodesk.IDSDK.DefaultServer-v2 768 NT AUTHORITY\SYSTEM 29184/30604 2151782744/2151785912 12620/14472 32 1834 0.1 2025-11-27 02:12:50 19817 SVC:KeyIso/Netlogon/SamSs C:\Windows\system32\lsass.exe 4228 NT AUTHORITY\SYSTEM 54960/57684 181976/187572 41024/41184 43 437 0.1 2025-12-05 00:10:20 8420 SVC:BASupportExpressStandaloneService_N_Central "C:\Program Files (x86)\BeAnywhere Support Express\GetSupportService_N-Central\BASupSrvc.exe" 3384 NT AUTHORITY\SYSTEM 5762772/5762780 10166952/10170360 5866660/5866660 68 347 0.1 2025-11-27 02:12:51 19817 SVC:Mesh Agent "C:\Program Files\Mesh Agent\MeshAgent.exe" 11520 NT AUTHORITY\SYSTEM 22480/33468 2151830000/2151841236 9164/15048 22 580 0.1 2025-12-10 20:27:00 3 SVC:VSS C:\Windows\system32\vssvc.exe 1392 NT AUTHORITY\LOCAL SERVICE 46244/79468 2151835996/2152517252 56640/72208 20 1641 0.1 2025-11-27 02:12:51 19817 SVC:EventLog C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p -s EventLog 3504 NT AUTHORITY\SYSTEM 55944/57960 4381224/4460772 45024/50240 22 407 0.1 2025-11-27 02:12:51 19817 SVC:SQLWriter "C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" 12668 NT AUTHORITY\NETWORK SERVICE 37984/43176 2151831712/2151855116 18596/21744 26 1605 0.1 2025-12-10 00:17:36 1213 WmiPrvSE C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding 7084 NT AUTHORITY\SYSTEM 161248/186096 2152409492/2152448944 114964/141128 39 588 0.1 2025-11-27 02:12:54 19817 powershell "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy RemoteSigned -NoLogo -NonInteractive -NoProfile -WindowStyle Hidden -File "C:\Program Files\XYMON\xymonclient.ps1" 3280 NT AUTHORITY\SYSTEM 34664/43812 2151851772/2151873852 19588/28972 23 577 0.0 2025-11-27 02:12:51 19817 SVC:Winmgmt C:\Windows\system32\svchost.exe -k netsvcs -p -s Winmgmt 760 Unknown 16804/61516 2151768788/2152835076 8364/15628 16 789 0.0 2025-11-27 02:12:50 19817 services 13736 NT AUTHORITY\SYSTEM 84148/124524 2152349124/2152357540 71556/112180 31 634 0.0 0 powershell powershell -noprofile -nologo -command - 10524 NT AUTHORITY\SYSTEM 33540/256184 5001696/5192540 133284/320132 65 2259 0.0 2025-12-09 08:50:19 2140 SVC:LTService C:\Windows\LTSvc\LTSVC.exe -sLTService 12084 NT AUTHORITY\SYSTEM 19548/48940 108056/129340 6344/29444 18 271 0.0 2025-12-10 02:41:24 1069 BASupSysInf C:\PROGRA~2\BEANYW~1\GETSUP~1\BASupSysInf.exe -pldpipeid 2WoCsuA0MvLT9DJbSyfdowXH7rGdfArriE9SwlPBm5OKO2Nf0G7SJbUQGqSywkCd 2732 NT AUTHORITY\LOCAL SERVICE 25180/27544 5448196/5452628 23240/24760 16 214 0.0 2025-11-27 02:12:51 19817 SVC:AdskLicensingService "C:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\Current\AdskLicensingService\AdskLicensingService.exe" 10404 IIS APPPOOL\AutodeskFSPool 187432/256756 2166426584/2166522060 301068/327316 76 1346 0.0 2025-12-10 09:23:20 667 w3wp c:\windows\system32\inetsrv\w3wp.exe -ap "AutodeskFSPool" -v "v4.0" -l "webengine4.dll" -a \\.\pipe\iisipm91164642-f5fd-41f1-9659-e460c84e8212 -h "C:\inetpub\temp\apppools\AutodeskFSPool\AutodeskFSPool.config" -w "" -m 0 -t 20 -ta 0 3784 NT AUTHORITY\SYSTEM 323408/358096 947084/997520 294564/337048 119 2320 0.0 2025-11-27 02:12:51 19817 SVC:Windows Agent Service "C:\Program Files (x86)\N-able Technologies\Windows Agent\bin\agent.exe" 1896 NT AUTHORITY\LOCAL SERVICE 8756/9440 2151756436/2151760536 2428/3244 10 193 0.0 2025-11-27 02:12:51 19817 SVC:EventSystem C:\Windows\system32\svchost.exe -k LocalService -p -s EventSystem 5368 NT AUTHORITY\SYSTEM 26632/27284 2152388668/2152393280 21668/23088 44 683 0.0 2025-11-27 04:48:36 19662 SVC:WSearch C:\Windows\system32\SearchIndexer.exe /Embedding 7492 NT AUTHORITY\LOCAL SERVICE 22864/26088 2151832784/2152364968 19096/21696 17 311 0.0 2025-11-27 02:14:53 19815 SVC:DPS C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork -p -s DPS 8556 Unknown 13928/15008 2151782912/2151785248 5984/7388 12 215 0.0 2025-11-27 02:13:05 19817 SVC:WdNisSvc 2788 NT AUTHORITY\LOCAL SERVICE 28504/29324 5483444/5487544 24396/25340 18 343 0.0 2025-11-27 02:12:51 19817 SVC:Autodesk CER Service "C:\Program Files\Autodesk\Autodesk CER\service\cer_service.exe" 12892 Unknown 12780/12836 2151763128/2151765252 4232/6028 11 230 0.0 2025-12-10 20:30:12 0 SVC:sppsvc 1008 NT AUTHORITY\NETWORK SERVICE 33152/33324 2151781512/2151794984 25808/26172 18 1439 0.0 2025-11-27 02:12:51 19817 SVC:RpcEptMapper/RpcSs C:\Windows\system32\svchost.exe -k RPCSS -p 1228 NT AUTHORITY\NETWORK SERVICE 10028/10280 2151768256/2151771328 3656/3984 16 325 0.0 2025-11-27 02:12:51 19817 SVC:Dnscache C:\Windows\system32\svchost.exe -k NetworkService -p -s Dnscache 6112 NT AUTHORITY\SYSTEM 19092/19092 2151795592/2151795592 6204/6212 18 432 0.0 0 cscript "C:\Windows\System32\Cscript.exe" C:\Windows\system32\slmgr.vbs //NOLOGO /dli 5244 NT AUTHORITY\SYSTEM 12928/12996 2152300188/2152306988 3768/3988 18 211 0.0 2025-11-27 02:12:53 19817 dllhost C:\Windows\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683} 3844 NT AUTHORITY\SYSTEM 6596/6780 4267956/4272496 1880/2180 8 124 0.0 2025-11-27 02:12:52 19817 SVC:XymonPSClient "C:\Program Files\XYMON\nssm.exe" 5348 NT AUTHORITY\SYSTEM 96952/119216 4985412/5043648 54728/56092 66 1084 0.0 2025-11-27 02:12:53 19817 SVC:VeeamEndpointBackupSvc "C:\Program Files\Veeam\Endpoint Backup\Veeam.EndPoint.Service.exe" 3756 NT AUTHORITY\SYSTEM 13936/13976 2151769292/2151771344 3492/3612 15 252 0.0 2025-11-27 02:12:51 19817 SVC:UsoSvc C:\Windows\system32\svchost.exe -k netsvcs -p -s UsoSvc 3720 NT AUTHORITY\SYSTEM 6080/6100 2151744788/2151746840 1328/1456 8 143 0.0 2025-11-27 02:12:51 19817 SVC:TrkWks C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s TrkWks 5548 IIS APPPOOL\AutodeskDMPool 519040/799336 2166359292/2166369140 661560/955604 74 1447 0.0 2025-12-10 09:18:39 672 w3wp c:\windows\system32\inetsrv\w3wp.exe -ap "AutodeskDMPool" -v "v4.0" -l "webengine4.dll" -a \\.\pipe\iisipmeeb64098-1596-42d7-890f-5755ae7b006b -h "C:\inetpub\temp\apppools\AutodeskDMPool\AutodeskDMPool.config" -w "" -m 0 -t 20 -ta 0 5880 NT AUTHORITY\SYSTEM 26440/36796 4352228/4365456 8180/8376 19 260 0.0 2025-11-27 02:12:53 19817 adsk_hive_host "C:\Program Files\Common Files\Autodesk Shared\Interoperability Engine Manager\1.3.2.2\bin\adsk_hive_host.exe" --duplexpipe fe0c2e5c-d8d5-4b4b-af54-346b6d9c285d 3952 NT AUTHORITY\NETWORK SERVICE 12840/12956 2151781748/2151783288 3280/3900 13 240 0.0 2025-11-27 02:12:52 19817 SVC:WinRM C:\Windows\System32\svchost.exe -k NetworkService -p -s WinRM 4420 NT SERVICE\MSSQLFDLauncher$AUTOD 7512/7796 4316300/4389264 39096/39600 12 259 0.0 2025-11-27 02:15:22 19815 fdhost "C:\VaultData\Microsoft SQL Server\MSSQL16.AUTODESKVAULT\MSSQL\Binn\fdhost.exe" "MSSQL16.AUTODESKVAULTG9a3ed1f2fd7b8f4546fa39bfc933bebf90169ml6" "MSSQL16.AUTODESKVAULT" "MSSQL16.AUTODESKVAULT" "12" "" "16384" "M" "0" "" "" "" 4992 NT AUTHORITY\SYSTEM 10168/10260 51428/60392 1948/2396 17 239 0.0 2025-11-27 02:12:52 19817 Veeam.Guest.Interaction.Proxy "C:\Program Files (x86)\Veeam\Backup Transport\GuestInteraction\Veeam.Guest.Interaction.Proxy.exe" 4056 NT AUTHORITY\SYSTEM 11196/11264 2151753564/2151758688 1404/1716 8 127 0.0 2025-11-27 02:12:52 19817 SVC:WpnService C:\Windows\system32\svchost.exe -k netsvcs -p -s WpnService 4304 NT AUTHORITY\SYSTEM 13604/13700 2151777936/2151781548 3556/3852 24 428 0.0 2025-11-27 02:12:52 19817 SVC:RasMan C:\Windows\System32\svchost.exe -k netsvcs 4048 NT AUTHORITY\SYSTEM 20088/20876 86884/97264 4580/5404 26 404 0.0 2025-11-27 02:12:52 19817 SVC:VeeamDeploySvc "C:\Windows\Veeam\Backup\VeeamDeploymentSvc.exe" -port 6160 5132 NT AUTHORITY\SYSTEM 10880/22256 2151747420/2151760024 6116/8984 8 123 0.0 2025-11-27 02:12:52 19817 AggregatorHost AggregatorHost.exe 3964 NT AUTHORITY\SYSTEM 13612/13612 2151775648/2151778212 5876/6152 16 264 0.0 2025-11-27 02:12:52 19817 SVC:W3SVC/WAS C:\Windows\system32\svchost.exe -k iissvcs 5060 NT AUTHORITY\SYSTEM 10784/10820 2151756576/2151758116 6192/6276 7 86 0.0 2025-11-27 02:12:52 19817 conhost \??\C:\Windows\system32\conhost.exe 0x4 4024 NT AUTHORITY\SYSTEM 10724/11516 55196/61600 2396/2684 17 237 0.0 2025-11-27 02:12:52 19817 SVC:VeeamTransportSvc "C:\Program Files (x86)\Veeam\Backup Transport\VeeamTransportSvc.exe" 6068 NT SERVICE\SQLTELEMETRY$AUTODESK 72356/120444 4832948/4848276 59652/116384 34 670 0.0 2025-11-27 02:15:22 19815 SVC:SQLTELEMETRY$AUTODESKVAULT "C:\VaultData\Microsoft SQL Server\MSSQL16.AUTODESKVAULT\MSSQL\Binn\sqlceip.exe" -Service AUTODESKVAULT 9588 NT AUTHORITY\NETWORK SERVICE 11380/12580 2151764472/2151767432 3016/4140 14 242 0.0 2025-11-27 02:15:17 19815 SVC:MSDTC C:\Windows\System32\msdtc.exe 9636 NT AUTHORITY\SYSTEM 11028/11028 2151757608/2151757608 6260/6260 8 86 0.0 0 conhost \??\C:\Windows\system32\conhost.exe 0x4 9872 NT AUTHORITY\SYSTEM 6320/6388 2151744956/2151748540 1380/1760 8 126 0.0 2025-12-10 20:13:46 16 SVC:WdiSystemHost C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s WdiSystemHost 9492 NT SERVICE\MSSQLFDLauncher$AUTOD 10864/10900 2151756576/2151757604 6196/6252 7 86 0.0 2025-11-27 02:15:22 19815 conhost \??\C:\Windows\system32\conhost.exe 0x4 8992 NT SERVICE\MSSQLFDLauncher$AUTOD 4604/4748 4249168/4254160 888/1004 6 78 0.0 2025-11-27 02:15:22 19815 SVC:MSSQLFDLauncher$AUTODESKVAULT "C:\VaultData\Microsoft SQL Server\MSSQL16.AUTODESKVAULT\MSSQL\Binn\fdlauncher.exe" -s MSSQL16.AUTODESKVAULT 9168 NT AUTHORITY\SYSTEM 77484/139924 300840/376620 48760/123284 67 667 0.0 2025-11-27 02:13:24 19817 SVC:SolarWinds.MSP.RpcServerService "C:\Program Files (x86)\MspPlatform\RequestHandlerAgent\RequestHandlerAgent.exe" 9332 NT AUTHORITY\SYSTEM 12120/14184 2151755740/2151759328 4552/6604 9 131 0.0 2025-11-27 02:14:55 19815 SVC:StateRepository C:\Windows\system32\svchost.exe -k appmodel -p -s StateRepository 13352 NT AUTHORITY\SYSTEM 11012/11048 2151756584/2151757612 6196/6268 7 86 0.0 2025-12-10 02:41:25 1069 conhost \??\C:\Windows\system32\conhost.exe 0x4 13920 NT AUTHORITY\SYSTEM 11036/11036 2151757608/2151757608 6264/6264 8 86 0.0 0 conhost \??\C:\Windows\system32\conhost.exe 0x4 14216 NT AUTHORITY\SYSTEM 7096/43936 4815720/4821852 35844/36228 29 516 0.0 2025-12-09 07:43:46 2206 SVC:LTSvcMon C:\Windows\LTSvc\LTSvcMon.exe -sLTService 10840 NT AUTHORITY\LOCAL SERVICE 14612/26988 2151773992/2151779148 5256/18216 13 192 0.0 2025-12-10 15:34:46 295 WmiPrvSE C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding 9908 NT AUTHORITY\SYSTEM 21144/24496 2152872424/2152884992 9720/12708 24 370 0.0 2025-11-27 02:15:22 19815 SVC:UALSVC C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p -s UALSVC 9960 NT AUTHORITY\SYSTEM 41244/41440 202056/214856 25484/25956 34 590 0.0 2025-12-10 17:56:02 154 SVC:ScreenConnect Client (69e7721040ec1250) "C:\Program Files (x86)\ScreenConnect Client (69e7721040ec1250)\ScreenConnect.ClientService.exe" "?e=Access&y=Guest&h=sc.viatek.com.au&p=8041&s=e5ed623a-911a-49b7-9d28-108e87e42822&k=BgIAAACkAABSU0ExAAgAAAEAAQCpFbFNTaYP9amF8McjmZ%2bQ8kLvvhOdthUPFJ78pr76tgUjzgIRnjzFiPwsqi3KH%2bAEGdBbu140Eu8gE8DXpk8y0v9cshavNO51TVuWILGYq54M%2bBpwafW1VRm7r8nJ%2fbpM58Hbc%2fArVsmsigBtGQ03Sse8wIfZ8ZkcfpiApbfZ94oT2gRUGDhLOh%2bbMDJXXzL%2bkCr5oO14ZoU9GzOu1GIPVuArDftfmD9D5O53gdE9njSXgqArzh%2bu06zB9Elvwke8PCvQTLHUpLHkYIOkCt1xNBIihW7ixPWPxb%2f0ZxzZ3sepeYefPryGzmthvqVHmX%2bOysNHAeTxvjOLuUYoCtKt&v=AQAAANCMnd8BFdERjHoAwE%2fCl%2bsBAAAAvNPXVaZ1lUKV0pdTHBSWzQAAAAACAAAAAAAQZgAAAAEAACAAAAALTxgR0FAU1S7Mw9BsZwIsttAG%2b5QOTYHJ2bxHdh5JYQAAAAAOgAAAAAIAACAAAAD%2fvPeS8yjVbZIad5RKpudGqQpuFrOFTURIUZNLQN9zU6AEAAB3gGj3NJzsTdjTdUKwEs1sxwl7C5yB3mi%2f1RTBy6DIvWryJSLC5PSv8I4b5Nhyv4AbNlqU9dSSU%2bsdirfSYBlq%2fSe%2fSRuh2N6xBY87CVPXCn7nqE0Cal7AasSjunc9w7xoBfCuH3cEURtIoMCIbBYbET2NUqK9hG%2bx4d718kLEigTsHjf4JBuLRZyEbZeDVqloEg7zhm2DXfovF48AEClhGpxiaMacX2wYHxlL258jwzlxRC6upO3IQM2NQl1GWylJH1%2f5bXwYwoE%2fDWZQ2zu5CB8dcxXYJPk%2fHkwnPwtL74Ej5QP3y6YAsJqSxr7wjBgYi1Nw94e9Ar3yyj5%2bQ%2bX3E5HubTIQbb3DssmOlHZoVR7vbgGbHy3sze7%2b0qtW6n6lnUzBS%2bm2nWZgbJOlI6q2cjpj2hnc6lwMS%2bdU%2b5D10vIGwyqSHf2ZmI%2bHlmZu4UnPdz8SwztRW%2btS5rdxJPHmifOrkca8Dsn5lwGccrlFIA172%2fb3TQ1Ohv3ay1dDIN%2fSxnt4pcv9qdTqZYCdlvrz7xyr7gEMW8VesqYeZ19SAfk%2bC0NflqKOo1eG6Osgq4l35TX2Ps2GBytm9d5Cb3%2fB29ivtq8sSF4YEXBhl6Sh7auZFixfqxiXFq31NIN5ChBWmwsg5wEf%2bLE9A0qlKCVmIYpXntfpm30t43DWw8IcsjRr8%2fopFVqcDpuitL0SxGsHspEfDIPTa7c0ecdzLFfLnfIT6RDjI%2fffDPhxAIiD1kHfVA672exdPnhTwMyuEvjo0j3PNgmUvEYQwd8HE%2bgYU4ZMh3Fb0tp7tQETxQamV8l7tk07UnN00YNInazxXfQ%2fG2eDl%2bBAZyXQXhcFjZ%2bZJRiQs17JpZhSJzJw%2fS1vgvPptzYVBwE5VMFxHraJTXAP6fC68pLZPnFk1xZjf87MVTlQzoKw2buBZrkaj%2fp1peb3d5i9vOP%2b5O5pRPpwigx1CgUA5D9N0iFAI61VlvVW9ZVSExTGPh1%2fCk8XhhEd3mNKzAlbjpHm9JmdkrDeED8GfuJts%2bID%2fVNm1MkcLkXVjOQPPiQS4yU6zIA8hsIoyv%2bl%2fodA%2fyjFeCZACLe8BOrmiNAvYPo89gx%2f%2fQ3uHElvVy8Uy%2fVngv%2fvIEMwOl%2f%2f722JIKMIzwpY642lUOI0rrMr%2ffMv4EjmEm6jx6SC1C3taeqbagkHTM1sp%2bUrQXJwqI%2bgMOQp99yGFa4RwNUJ4W9SwRFxgS09%2baQlFA6kkPlwafC%2bTr%2fPezOinCTMSKgO5lk98KuRkLHg29L6thgltjoPg1LR9ZBwjL1DDw1b5VIeS5z8cTfzYyyw%2fhKxMz8pQKUMrL2cgEM6caSGliJn3FHFQ521qlMk0svUCwzW1H6i7LIfqXfKvyHwRvKxbIpEE3YXKnTN62HcD%2bSAagUunfg4dj9byaOBchuY04o5lpOiYFgUAmkRfg8mtEgqr0teXCJX1063Fxe%2fTy8sr2vMCUJMYcdibYXB7PXL9LC9AP0tV1vtwBLaby5jmB6xe4%2fgdcn8ZzAmKtNvEG06UI0XCKvxgahfc68NrU7t7QorjzMNgEz7eRqxcBPU%2bK4wngZTPkAAAACqn2nW%2bddJBZ3FJJ3H7iJM81aYPBuZ78EOwB8KOXGkjmtuMHDuq0lmkw6EpF%2bd7tDd86c43z%2bx3AQUkPY%2fCROp&c=Inorail%20Pty%20Ltd&c=INX%20-%20Servers&c=&c=&c=&c=&c=&c=" 10308 NT AUTHORITY\SYSTEM 11144/11180 2152821396/2152827032 6388/6688 15 193 0.0 2025-11-27 06:12:52 19577 SVC:DsSvc C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s DsSvc 7064 NT AUTHORITY\SYSTEM 25508/42932 131256/154888 10532/28148 24 358 0.0 2025-12-05 00:09:54 8420 SVC:BASupportExpressSrvcUpdater_N_Central "C:\Program Files (x86)\BeAnywhere Support Express\GetSupportService_N-Central\BASupSrvcUpdater.exe" 7092 NT AUTHORITY\SYSTEM 15284/16296 2151770448/2151771624 9104/10280 10 148 0.0 2025-11-27 02:12:54 19817 conhost \??\C:\Windows\system32\conhost.exe 0x4 7188 NT AUTHORITY\SYSTEM 66884/71976 4909324/4964248 56156/69920 28 572 0.0 2025-11-27 02:12:57 19817 NableSixtyFourBitManager "C:\Program Files (x86)\N-able Technologies\Windows Agent\bin\NableSixtyFourBitManager.exe" 6932 IIS APPPOOL\AutodeskFSPool 23836/24216 2151829228/2151841516 7424/8340 22 346 0.0 2025-12-10 09:23:22 667 AdskLicensingAgent "C:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\15.5.0.13374\AdskLicensingAgent/AdskLicensingAgent.exe" -r 0 -n /analytics/v1/connect?analyticsagentid=analytics-5b02e78e-172c-489f-a4a6-d66651a98cb6 --no-gui -c 2 -i analytics-5b02e78e-172c-489f-a4a6-d66651a98cb6 6152 Unknown 8300/8336 2151749248/2151755396 1632/1960 9 176 0.0 2025-11-27 02:12:53 19817 SVC:WaaSMedicSvc 6620 NT AUTHORITY\LOCAL SERVICE 7472/7516 2151745608/2151751244 1384/1692 8 124 0.0 2025-11-27 02:12:54 19817 SVC:DispBrokerDesktopSvc C:\Windows\system32\svchost.exe -k LocalService -p -s DispBrokerDesktopSvc 6756 NT AUTHORITY\SYSTEM 10788/10824 2151756576/2151757604 6204/6260 7 86 0.0 2025-11-27 02:12:57 19817 conhost \??\C:\Windows\system32\conhost.exe 0x4 8136 NT AUTHORITY\SYSTEM 45524/50272 4816116/4873300 34832/39852 25 674 0.0 2025-11-27 02:12:57 19817 NableReactiveManagement "C:\Program Files (x86)\N-able Technologies\Reactive\bin\NableReactiveManagement.exe" 8772 NT AUTHORITY\SYSTEM 9652/9944 2151753524/2151757268 2268/6048 12 182 0.0 2025-12-10 20:27:10 3 WmiPrvSE C:\Windows\system32\wbem\wmiprvse.exe -Embedding 8836 NT AUTHORITY\LOCAL SERVICE 12012/12056 2151772428/2151779600 2276/2772 11 211 0.0 2025-11-27 02:14:53 19815 SVC:CDPSvc C:\Windows\system32\svchost.exe -k LocalService -p -s CDPSvc 7964 NT AUTHORITY\SYSTEM 13236/14232 2151767476/2151777040 4224/5132 12 248 0.0 2025-11-27 02:13:18 19817 SVC:PcaSvc C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc 7324 NT AUTHORITY\SYSTEM 15516/16116 2151777640/2151788632 3216/4036 14 261 0.0 2025-11-27 02:13:22 19817 SVC:StorSvc C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p 7432 NT AUTHORITY\SYSTEM 10784/10824 2151756576/2151758112 6200/6284 7 86 0.0 2025-11-27 02:12:57 19817 conhost \??\C:\Windows\system32\conhost.exe 0x4 7712 IIS APPPOOL\DefaultAppPool 45376/45528 2166202524/2166209692 71712/72016 37 842 0.0 2025-12-10 09:14:37 676 w3wp c:\windows\system32\inetsrv\w3wp.exe -ap "DefaultAppPool" -v "v4.0" -l "webengine4.dll" -a \\.\pipe\iisipma5db5358-5da6-48ba-9aa8-cde775673e5b -h "C:\inetpub\temp\apppools\DefaultAppPool\DefaultAppPool.config" -w "" -m 0 -t 20 -ta 0 3600 NT AUTHORITY\SYSTEM 7248/7264 2155941260/2155944336 1920/2000 9 144 0.0 2025-11-27 02:12:51 19817 SVC:SysMain C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p -s SysMain 1172 NT AUTHORITY\LOCAL SERVICE 54052/58460 4834600/4840748 42952/47648 34 635 0.0 2025-11-27 02:13:22 19817 SVC:SolarWinds.MSP.CacheService "C:\Program Files (x86)\MspPlatform\FileCacheServiceAgent\FileCacheServiceAgent.exe" 1152 NT AUTHORITY\LOCAL SERVICE 6500/6528 2151747484/2151750512 1508/1700 8 142 0.0 2025-11-27 02:12:51 19817 SVC:TimeBrokerSvc C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p -s TimeBrokerSvc 1464 Window Manager\DWM-1 51920/60620 2151948560/2151964852 29248/46208 29 626 0.0 2025-11-27 02:12:51 19817 dwm "dwm.exe" 1324 NT AUTHORITY\SYSTEM 53796/65676 2151981104/2151988964 11964/32876 27 454 0.0 2025-11-27 02:12:51 19817 LogonUI "LogonUI.exe" /flags:0x2 /state0:0xa3b19855 /state1:0x41c64e6d 1096 Unknown 11656/12028 2151756720/2151758260 2580/2716 11 196 0.0 2025-12-03 20:13:02 10097 SVC:SecurityHealthService 1048 NT AUTHORITY\LOCAL SERVICE 8872/8952 2151755832/2151758396 1984/2184 13 232 0.0 2025-11-27 02:12:51 19817 SVC:W32Time C:\Windows\system32\svchost.exe -k LocalService -s W32Time 1144 NT AUTHORITY\SYSTEM 8680/8820 2151748136/2151755308 1836/2320 11 194 0.0 2025-11-27 02:12:51 19817 SVC:NcbService C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s NcbService 1136 NT AUTHORITY\LOCAL SERVICE 8436/8596 2151754932/2151758536 2544/2956 11 241 0.0 2025-11-27 02:12:51 19817 SVC:Dhcp C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p -s Dhcp 1740 NT AUTHORITY\SYSTEM 6644/6672 2151745800/2151747852 1416/1524 8 145 0.0 2025-11-27 02:12:51 19817 SVC:CertPropSvc C:\Windows\system32\svchost.exe -k netsvcs -s CertPropSvc 1700 NT AUTHORITY\SYSTEM 18664/19200 2151793108/2151802612 4120/4568 20 376 0.0 2025-11-27 02:12:51 19817 SVC:gpsvc C:\Windows\system32\svchost.exe -k netsvcs -p -s gpsvc 1800 NT AUTHORITY\SYSTEM 7028/7064 2151751312/2151753984 1384/1568 8 138 0.0 2025-11-27 02:12:51 19817 SVC:UmRdpService C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s UmRdpService 1768 NT AUTHORITY\LOCAL SERVICE 11744/11800 2151763908/2151777736 3548/4144 14 453 0.0 2025-11-27 02:12:51 19817 SVC:netprofm C:\Windows\System32\svchost.exe -k LocalService -p -s netprofm 1556 NT AUTHORITY\SYSTEM 11672/11700 2151773224/2151776300 2308/2476 11 210 0.0 2025-11-27 02:12:51 19817 SVC:ProfSvc C:\Windows\system32\svchost.exe -k netsvcs -p -s ProfSvc 1480 NT AUTHORITY\LOCAL SERVICE 19192/21932 2151786104/2151794664 9076/11472 33 435 0.0 2025-11-27 02:12:51 19817 SVC:BFE/mpssvc C:\Windows\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p 1656 NT AUTHORITY\SYSTEM 8164/8376 2151751572/2151756012 1880/2044 9 177 0.0 2025-11-27 02:12:51 19817 SVC:UserManager C:\Windows\system32\svchost.exe -k netsvcs -p -s UserManager 1572 NT AUTHORITY\NETWORK SERVICE 13112/13412 2151779272/2151791636 4036/5104 17 399 0.0 2025-11-27 02:12:51 19817 SVC:NlaSvc C:\Windows\System32\svchost.exe -k NetworkService -p -s NlaSvc 616 Unknown 7296/7368 2151748948/2151761376 1372/1912 11 156 0.0 2025-11-27 02:12:50 19817 wininit 520 Unknown 7068/7148 2151785440/2151786404 2424/2532 30 929 0.0 2025-11-27 02:12:50 19817 csrss 688 NT AUTHORITY\SYSTEM 10588/16448 2151811900/2151825220 2472/7344 12 214 0.0 2025-11-27 02:12:50 19817 winlogon winlogon.exe 624 Unknown 6044/14252 2151766200/2151775328 1832/2040 11 172 0.0 2025-11-27 02:12:50 19817 csrss 148 Unknown 112796/331616 122816/335808 3276/106692 10 0 0.0 2025-11-27 02:12:47 19817 Registry 0 8/8 8/8 60/60 0 0 0.0 0 Idle 472 NT AUTHORITY\SYSTEM 9708/9824 2151757496/2151763132 2544/2780 12 297 0.0 2025-11-27 02:12:51 19817 SVC:LSM C:\Windows\system32\svchost.exe -k DcomLaunch -p -s LSM 408 Unknown 1256/1284 2151718576/2151726612 1072/1140 3 57 0.0 2025-11-27 02:12:49 19817 smss 948 NT AUTHORITY\LOCAL SERVICE 8420/8520 2151756720/2151761332 2448/2608 15 225 0.0 2025-11-27 02:13:22 19817 SVC:SSDPSRV C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p -s SSDPSRV 936 Font Driver Host\UMFD-1 4560/39176 2151748520/2151784512 1868/2900 6 39 0.0 2025-11-27 02:12:50 19817 fontdrvhost "fontdrvhost.exe" 1040 NT AUTHORITY\LOCAL SERVICE 5760/5796 2151745296/2151746836 1292/1460 8 119 0.0 2025-11-27 02:12:51 19817 SVC:lmhosts C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p -s lmhosts 1028 NT AUTHORITY\LOCAL SERVICE 9064/9104 2151748024/2151749564 4552/4684 20 151 0.0 2025-11-27 02:12:51 19817 SVC:nsi C:\Windows\system32\svchost.exe -k LocalService -p -s nsi 848 NT AUTHORITY\SYSTEM 10744/69764 4292508/4359792 2320/2448 11 196 0.0 2025-11-29 11:44:52 16365 SVC:Backup Service Controller "C:\Program Files\Backup Manager\ProcessController.exe" serve 732 NT AUTHORITY\NETWORK SERVICE 16176/16964 2151812408/2151822996 6040/7364 23 644 0.0 2025-11-27 02:12:51 19817 SVC:TermService C:\Windows\System32\svchost.exe -k termsvcs -s TermService 928 Font Driver Host\UMFD-0 7544/39204 2151886672/2151889928 4140/4196 8 39 0.0 2025-11-27 02:12:50 19817 fontdrvhost "fontdrvhost.exe" 900 NT AUTHORITY\SYSTEM 17408/17484 2151773560/2151779536 7444/7636 16 934 0.0 2025-11-27 02:12:50 19817 SVC:BrokerInfrastructure/DcomLaunch/PlugPlay/Power/SystemEventsBroker C:\Windows\system32\svchost.exe -k DcomLaunch -p 1840 NT AUTHORITY\SYSTEM 16860/22600 2151786168/2151801112 5880/6648 18 374 0.0 2025-11-27 02:12:51 19817 SVC:Schedule C:\Windows\system32\svchost.exe -k netsvcs -p -s Schedule 2988 NT SERVICE\MsDtsServer160 24204/24240 18693128/18730252 55868/56276 23 283 0.0 2025-11-27 02:15:18 19815 SVC:MsDtsServer160 "C:\VaultData\Microsoft SQL Server\160\DTS\Binn\MsDtsSrvr.exe" 2892 NT AUTHORITY\SYSTEM 6256/6284 2151744900/2151746952 1284/1392 8 113 0.0 2025-11-27 02:12:51 19817 SVC:AzureAttestService C:\Windows\system32\svchost.exe -k AzureAttestService -s AzureAttestService 3108 NT AUTHORITY\SYSTEM 14132/16060 4307204/4314224 4688/4916 15 265 0.0 2025-11-27 02:12:51 19817 SVC:FlexNet Licensing Service 64 "C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe" 3100 NT AUTHORITY\SYSTEM 44360/73668 2151866636/2151913576 24956/54568 25 567 0.0 2025-11-27 02:12:51 19817 SVC:DiagTrack C:\Windows\System32\svchost.exe -k utcsvc -p 2836 NT AUTHORITY\SYSTEM 38972/39020 4826560/4892356 32492/32772 27 365 0.0 2025-11-27 02:12:51 19817 SVC:Autodesk Data Management Server Revit Dynamo Extension Service "C:\Program Files\Autodesk\Vault Server 2026\DynamoHelperService\Connectivity.DynamoHelperService.exe" 2824 NT AUTHORITY\SYSTEM 30600/30852 4817496/4839312 31960/32372 22 452 0.0 2025-11-27 02:12:51 19817 SVC:Autodesk Data Management Job Dispatch "C:\Program Files\Autodesk\Vault Server 2026\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe" 2872 NT AUTHORITY\SYSTEM 164248/190520 424716/501144 135940/173992 82 1221 0.0 2025-11-27 02:12:51 19817 SVC:AutomationManagerAgent "C:\Program Files (x86)\N-able Technologies\AutomationManagerAgent\AutomationManager.AgentService.exe" 2844 NT AUTHORITY\SYSTEM 55352/67096 2151850984/2151878072 27048/27128 500 339 0.0 2025-11-27 02:12:51 19817 SVC:Autodesk Access Service Host "C:\Program Files\Autodesk\AdODIS\V1\Setup\AdskAccessServiceHost.exe" 3472 NT AUTHORITY\LOCAL SERVICE 7652/7684 2151752948/2151756028 1724/1868 42 160 0.0 2025-11-27 02:12:51 19817 SVC:SstpSvc C:\Windows\system32\svchost.exe -k LocalService -p -s SstpSvc 3332 Unknown 24712/25336 2151793928/2151800108 11300/11816 17 513 0.0 2025-11-27 02:12:51 19817 SVC:MDCoreSvc 3552 NT AUTHORITY\LOCAL SERVICE 6228/6316 32640/37764 1744/1968 12 160 0.0 2025-11-27 02:12:51 19817 SVC:SQLBrowser "C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe" 3512 NT AUTHORITY\SYSTEM 9416/9500 2151753876/2151760044 2436/2700 11 210 0.0 2025-11-27 02:12:51 19817 SVC:LanmanServer C:\Windows\System32\svchost.exe -k smbsvcs -s LanmanServer 3120 NT AUTHORITY\SYSTEM 8556/8592 4291876/4299052 2320/2388 11 225 0.0 2025-11-27 02:12:51 19817 SVC:HelpDeskService "C:\Program Files (x86)\HelpDeskHost\HelpDesk\\RPCHelpDeskServiceUAC.exe" 3116 NT AUTHORITY\SYSTEM 65404/66908 4890032/5235560 43944/46628 37 976 0.0 2025-11-27 02:14:54 19815 SVC:FOSWindowsService "C:\Program Files\Autodesk\File Operations System\WindowsService\FOS.WindowsService.exe" 3204 NT SERVICE\SSISTELEMETRY160 52928/53104 4814912/4828952 36488/36880 32 915 0.0 2025-11-27 02:15:22 19815 SVC:SSISTELEMETRY160 "C:\VaultData\Microsoft SQL Server\160\DTS\Binn\sqlceip.exe" -Service default MSIS 3128 NT AUTHORITY\SYSTEM 28904/29048 2151793796/2151798920 17568/17936 19 246 0.0 2025-11-27 02:12:51 19817 SVC:IISADMIN C:\Windows\system32\inetsrv\inetinfo.exe 2224 NT AUTHORITY\SYSTEM 8956/8988 2151754664/2151761836 1932/2376 13 191 0.0 2025-11-27 02:12:51 19817 SVC:ShellHWDetection C:\Windows\System32\svchost.exe -k netsvcs -p -s ShellHWDetection 2192 NT AUTHORITY\LOCAL SERVICE 8152/8344 2151751664/2151755476 2172/2556 10 186 0.0 2025-11-27 02:12:51 19817 SVC:WinHttpAutoProxySvc C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p -s WinHttpAutoProxySvc 2296 NT AUTHORITY\LOCAL SERVICE 7084/7284 2151777660/2151781572 1816/1960 9 142 0.0 2025-11-27 02:12:51 19817 SVC:FontCache C:\Windows\system32\svchost.exe -k LocalService -p -s FontCache 2272 NT AUTHORITY\LOCAL SERVICE 6400/6428 2151753176/2151756252 1344/1472 7 126 0.0 2025-11-27 02:12:51 19817 SVC:CoreMessagingRegistrar C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork -p 2056 NT AUTHORITY\SYSTEM 9540/9784 2151758608/2151762212 2104/2412 14 209 0.0 2025-11-27 02:12:51 19817 SVC:SENS C:\Windows\system32\svchost.exe -k netsvcs -p -s SENS 1964 NT AUTHORITY\SYSTEM 6024/6056 2151747576/2151749628 1260/1380 8 121 0.0 2025-11-27 02:12:51 19817 SVC:Themes C:\Windows\System32\svchost.exe -k netsvcs -p -s Themes 2164 NT AUTHORITY\LOCAL SERVICE 9232/9368 2151751388/2151759072 2028/2784 13 290 0.0 2025-11-27 02:12:51 19817 SVC:Wcmsvc C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p 2124 NT AUTHORITY\NETWORK SERVICE 9980/10056 2151762040/2151765116 2340/2484 12 231 0.0 2025-11-27 02:12:51 19817 SVC:LanmanWorkstation C:\Windows\System32\svchost.exe -k NetworkService -p -s LanmanWorkstation 2548 NT AUTHORITY\SYSTEM 10936/11148 2152810972/2152821308 2780/3516 16 358 0.0 2025-11-27 02:12:51 19817 SVC:iphlpsvc C:\Windows\System32\svchost.exe -k NetSvcs -p -s iphlpsvc 2536 NT AUTHORITY\NETWORK SERVICE 7788/7888 2151746656/2151751680 1776/2036 13 173 0.0 2025-11-27 02:12:51 19817 SVC:PolicyAgent C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted -p -s PolicyAgent 2752 NT AUTHORITY\SYSTEM 15448/15680 2151803520/2151805572 7384/7824 14 211 0.0 2025-11-27 02:12:51 19817 SVC:AppHostSvc C:\Windows\system32\svchost.exe -k apphost -s AppHostSvc 2620 NT AUTHORITY\SYSTEM 30484/31460 2151851560/2151894132 9932/12324 29 581 0.0 2025-11-27 02:12:51 19817 SVC:Spooler C:\Windows\System32\spoolsv.exe 2364 NT AUTHORITY\SYSTEM 34876/35132 4764024/4770940 27144/27512 19 343 0.0 2025-11-27 02:13:26 19817 SVC:PME.Agent.PmeService "C:\Program Files (x86)\MspPlatform\PME\PME.Agent.exe" 2324 NT AUTHORITY\SYSTEM 33072/33288 162348/175024 19908/20944 25 452 0.0 2025-11-27 02:15:27 19815 SVC:Windows Agent Maintenance Service "C:\Program Files (x86)\N-able Technologies\Windows Agent\bin\AgentMaint.exe" 2524 NT AUTHORITY\SYSTEM 8736/8768 2151754468/2151759080 2676/2900 14 278 0.0 2025-11-27 02:12:51 19817 SVC:IKEEXT C:\Windows\system32\svchost.exe -k netsvcs -p -s IKEEXT 2416 NT AUTHORITY\SYSTEM 10376/10416 2151759332/2151762408 2340/2500 16 246 0.0 2025-11-27 02:12:51 19817 SVC:SessionEnv C:\Windows\System32\svchost.exe -k netsvcs -p -s SessionEnv [netstat] PacketsReceived=286946377 ReceivedHeaderErrors=0 ReceivedAddressErrors=1107951 DatagramsForwarded=0 UnknownProtocolsReceived=0 ReceivedPacketsDiscarded=215311 ReceivedPacketsDelivered=285903916 OutputRequests=835695533 RoutingDiscards=0 DiscardedOutputPackets=53269 OutputPacketNoRoute=6 ReassemblyRequired=0 ReassemblySuccessful=0 ReassemblyFailures=0 DatagramsSuccessfullyFragmented=0 DatagramsFailingFragmentation=0 FragmentsCreated=0 PacketsReceived=675858 ReceivedHeaderErrors=0 ReceivedAddressErrors=0 DatagramsForwarded=0 UnknownProtocolsReceived=0 ReceivedPacketsDiscarded=82953 ReceivedPacketsDelivered=593150 OutputRequests=13741 RoutingDiscards=0 DiscardedOutputPackets=0 OutputPacketNoRoute=0 ReassemblyRequired=0 ReassemblySuccessful=0 ReassemblyFailures=0 DatagramsSuccessfullyFragmented=0 DatagramsFailingFragmentation=0 FragmentsCreated=0 tcpActiveOpens=479285 tcpPassiveOpens=296538 tcpFailedConnectionAttempts=74889 tcpResetConnections=48329 tcpCurrentConnections=25 tcpSegmentsReceived=288231310 tcpSegmentsSent=821922786 tcpSegmentsRetransmitted=18498544 tcpActiveOpens=2995 tcpPassiveOpens=2967 tcpFailedConnectionAttempts=28 tcpResetConnections=240 tcpCurrentConnections=6 tcpSegmentsReceived=769041 tcpSegmentsSent=755741 tcpSegmentsRetransmitted=112 udpDatagramsReceived=2653659 udpNoPorts=204807 udpReceiveErrors=0 udpDatagramsSent=262010 udpDatagramsReceived=481150 udpNoPorts=82953 udpReceiveErrors=0 udpDatagramsSent=310 [ports] Active Connections Proto Local Address Foreign Address State TCP 0.0.0.0:80 0.0.0.0:0 LISTENING TCP 0.0.0.0:135 0.0.0.0:0 LISTENING TCP 0.0.0.0:445 0.0.0.0:0 LISTENING TCP 0.0.0.0:3389 0.0.0.0:0 LISTENING TCP 0.0.0.0:5000 0.0.0.0:0 LISTENING TCP 0.0.0.0:5948 0.0.0.0:0 LISTENING TCP 0.0.0.0:5985 0.0.0.0:0 LISTENING TCP 0.0.0.0:6160 0.0.0.0:0 LISTENING TCP 0.0.0.0:6162 0.0.0.0:0 LISTENING TCP 0.0.0.0:6183 0.0.0.0:0 LISTENING TCP 0.0.0.0:6184 0.0.0.0:0 LISTENING TCP 0.0.0.0:6190 0.0.0.0:0 LISTENING TCP 0.0.0.0:6290 0.0.0.0:0 LISTENING TCP 0.0.0.0:8000 0.0.0.0:0 LISTENING TCP 0.0.0.0:11731 0.0.0.0:0 LISTENING TCP 0.0.0.0:47001 0.0.0.0:0 LISTENING TCP 0.0.0.0:49664 0.0.0.0:0 LISTENING TCP 0.0.0.0:49665 0.0.0.0:0 LISTENING TCP 0.0.0.0:49666 0.0.0.0:0 LISTENING TCP 0.0.0.0:49667 0.0.0.0:0 LISTENING TCP 0.0.0.0:49668 0.0.0.0:0 LISTENING TCP 0.0.0.0:49669 0.0.0.0:0 LISTENING TCP 0.0.0.0:49670 0.0.0.0:0 LISTENING TCP 0.0.0.0:49676 0.0.0.0:0 LISTENING TCP 0.0.0.0:49683 0.0.0.0:0 LISTENING TCP 0.0.0.0:49810 0.0.0.0:0 LISTENING TCP 0.0.0.0:61885 0.0.0.0:0 LISTENING TCP 10.2.63.49:139 0.0.0.0:0 LISTENING TCP 10.2.63.49:52607 206.148.0.39:443 ESTABLISHED TCP 10.2.63.49:55982 103.36.248.58:443 ESTABLISHED TCP 10.2.63.49:55992 103.36.248.58:443 ESTABLISHED TCP 10.2.63.49:60092 8.38.48.118:443 ESTABLISHED TCP 10.2.63.49:60341 206.148.0.209:443 ESTABLISHED TCP 10.2.63.49:62158 206.148.0.208:443 TIME_WAIT TCP 10.2.63.49:62162 206.148.0.208:443 TIME_WAIT TCP 10.2.63.49:62165 104.18.110.87:443 TIME_WAIT TCP 10.2.63.49:62168 206.148.0.208:443 TIME_WAIT TCP 10.2.63.49:62169 10.2.63.47:135 TIME_WAIT TCP 10.2.63.49:62170 10.2.63.47:49690 TIME_WAIT TCP 10.2.63.49:62171 66.129.107.58:443 TIME_WAIT TCP 10.2.63.49:62174 206.148.0.208:443 TIME_WAIT TCP 10.2.63.49:62175 10.2.63.47:49669 TIME_WAIT TCP 10.2.63.49:62185 66.129.107.58:443 TIME_WAIT TCP 10.2.63.49:62203 206.148.0.208:443 TIME_WAIT TCP 10.2.63.49:62214 125.253.56.44:443 ESTABLISHED TCP 10.2.63.49:62312 10.2.63.48:445 ESTABLISHED TCP 10.2.63.49:62422 10.2.63.48:445 ESTABLISHED TCP 10.2.63.49:62426 10.2.63.48:445 ESTABLISHED TCP 10.2.63.49:62427 10.2.63.48:445 ESTABLISHED TCP 127.0.0.1:445 127.0.0.1:61820 ESTABLISHED TCP 127.0.0.1:3389 127.0.0.1:62213 CLOSE_WAIT TCP 127.0.0.1:6290 127.0.0.1:49677 ESTABLISHED TCP 127.0.0.1:9395 0.0.0.0:0 LISTENING TCP 127.0.0.1:42000 0.0.0.0:0 LISTENING TCP 127.0.0.1:43227 0.0.0.0:0 LISTENING TCP 127.0.0.1:49565 127.0.0.1:49566 ESTABLISHED TCP 127.0.0.1:49566 127.0.0.1:49565 ESTABLISHED TCP 127.0.0.1:49571 127.0.0.1:49572 ESTABLISHED TCP 127.0.0.1:49572 127.0.0.1:49571 ESTABLISHED TCP 127.0.0.1:49674 0.0.0.0:0 LISTENING TCP 127.0.0.1:49674 127.0.0.1:62159 TIME_WAIT TCP 127.0.0.1:49674 127.0.0.1:62184 TIME_WAIT TCP 127.0.0.1:49674 127.0.0.1:62189 TIME_WAIT TCP 127.0.0.1:49674 127.0.0.1:62193 TIME_WAIT TCP 127.0.0.1:49674 127.0.0.1:62198 TIME_WAIT TCP 127.0.0.1:49674 127.0.0.1:62200 TIME_WAIT TCP 127.0.0.1:49674 127.0.0.1:62207 TIME_WAIT TCP 127.0.0.1:49677 127.0.0.1:6290 ESTABLISHED TCP 127.0.0.1:50086 0.0.0.0:0 LISTENING TCP 127.0.0.1:50086 127.0.0.1:62149 ESTABLISHED TCP 127.0.0.1:50086 127.0.0.1:62151 ESTABLISHED TCP 127.0.0.1:50147 127.0.0.1:62781 ESTABLISHED TCP 127.0.0.1:50154 0.0.0.0:0 LISTENING TCP 127.0.0.1:61820 127.0.0.1:445 ESTABLISHED TCP 127.0.0.1:62139 127.0.0.1:3389 TIME_WAIT TCP 127.0.0.1:62149 127.0.0.1:50086 ESTABLISHED TCP 127.0.0.1:62151 127.0.0.1:50086 ESTABLISHED TCP 127.0.0.1:62180 127.0.0.1:64902 TIME_WAIT TCP 127.0.0.1:62188 127.0.0.1:80 TIME_WAIT TCP 127.0.0.1:62191 127.0.0.1:64902 TIME_WAIT TCP 127.0.0.1:62193 127.0.0.1:49674 TIME_WAIT TCP 127.0.0.1:62194 127.0.0.1:64902 TIME_WAIT TCP 127.0.0.1:62196 127.0.0.1:49674 TIME_WAIT TCP 127.0.0.1:62197 127.0.0.1:3389 TIME_WAIT TCP 127.0.0.1:62199 127.0.0.1:64902 TIME_WAIT TCP 127.0.0.1:62200 127.0.0.1:49674 TIME_WAIT TCP 127.0.0.1:62204 127.0.0.1:49674 TIME_WAIT TCP 127.0.0.1:62205 127.0.0.1:64902 TIME_WAIT TCP 127.0.0.1:62208 127.0.0.1:80 TIME_WAIT TCP 127.0.0.1:62209 127.0.0.1:64902 TIME_WAIT TCP 127.0.0.1:62210 127.0.0.1:49674 TIME_WAIT TCP 127.0.0.1:62211 127.0.0.1:49674 TIME_WAIT TCP 127.0.0.1:62212 127.0.0.1:64902 TIME_WAIT TCP 127.0.0.1:62213 127.0.0.1:3389 FIN_WAIT_2 TCP 127.0.0.1:62215 127.0.0.1:49674 TIME_WAIT TCP 127.0.0.1:62781 0.0.0.0:0 LISTENING TCP 127.0.0.1:62781 127.0.0.1:50147 ESTABLISHED TCP 127.0.0.1:64902 0.0.0.0:0 LISTENING TCP [::]:80 [::]:0 LISTENING TCP [::]:135 [::]:0 LISTENING TCP [::]:445 [::]:0 LISTENING TCP [::]:3389 [::]:0 LISTENING TCP [::]:5985 [::]:0 LISTENING TCP [::]:6160 [::]:0 LISTENING TCP [::]:6162 [::]:0 LISTENING TCP [::]:6183 [::]:0 LISTENING TCP [::]:6184 [::]:0 LISTENING TCP [::]:6190 [::]:0 LISTENING TCP [::]:6290 [::]:0 LISTENING TCP [::]:8000 [::]:0 LISTENING TCP [::]:11731 [::]:0 LISTENING TCP [::]:47001 [::]:0 LISTENING TCP [::]:49664 [::]:0 LISTENING TCP [::]:49665 [::]:0 LISTENING TCP [::]:49666 [::]:0 LISTENING TCP [::]:49667 [::]:0 LISTENING TCP [::]:49668 [::]:0 LISTENING TCP [::]:49669 [::]:0 LISTENING TCP [::]:49670 [::]:0 LISTENING TCP [::]:49676 [::]:0 LISTENING TCP [::]:49683 [::]:0 LISTENING TCP [::]:49810 [::]:0 LISTENING TCP [::]:61885 [::]:0 LISTENING TCP [::1]:80 [::1]:49969 ESTABLISHED TCP [::1]:9395 [::]:0 LISTENING TCP [::1]:49969 [::1]:80 ESTABLISHED TCP [::1]:50154 [::]:0 LISTENING TCP [fe80::c02a:7289:617b:f4c8%9]:80 [fe80::c02a:7289:617b:f4c8%9]:61969 ESTABLISHED TCP [fe80::c02a:7289:617b:f4c8%9]:80 [fe80::c02a:7289:617b:f4c8%9]:62148 ESTABLISHED TCP [fe80::c02a:7289:617b:f4c8%9]:61969 [fe80::c02a:7289:617b:f4c8%9]:80 ESTABLISHED TCP [fe80::c02a:7289:617b:f4c8%9]:62148 [fe80::c02a:7289:617b:f4c8%9]:80 ESTABLISHED UDP 0.0.0.0:123 *:* UDP 0.0.0.0:500 *:* UDP 0.0.0.0:1434 *:* UDP 0.0.0.0:3389 *:* UDP 0.0.0.0:4500 *:* UDP 0.0.0.0:5353 *:* UDP 0.0.0.0:5355 *:* UDP 0.0.0.0:42000 *:* UDP 0.0.0.0:43212 *:* UDP 0.0.0.0:56965 *:* UDP 0.0.0.0:60348 *:* UDP 0.0.0.0:62298 *:* UDP 0.0.0.0:62299 *:* UDP 10.2.63.49:137 *:* UDP 10.2.63.49:138 *:* UDP 10.2.63.49:1900 *:* UDP 10.2.63.49:62303 *:* UDP 127.0.0.1:1900 *:* UDP 127.0.0.1:50201 127.0.0.1:50201 UDP 127.0.0.1:51641 127.0.0.1:51641 UDP 127.0.0.1:59507 127.0.0.1:59507 UDP 127.0.0.1:61790 127.0.0.1:61790 UDP 127.0.0.1:61792 127.0.0.1:61792 UDP 127.0.0.1:62300 127.0.0.1:62300 UDP 127.0.0.1:62304 *:* UDP [::]:123 *:* UDP [::]:500 *:* UDP [::]:1434 *:* UDP [::]:3389 *:* UDP [::]:4500 *:* UDP [::]:5353 *:* UDP [::]:5355 *:* UDP [::]:56965 *:* UDP [::]:62299 *:* UDP [::1]:1900 *:* UDP [::1]:62302 *:* UDP [fe80::c02a:7289:617b:f4c8%9]:1900 *:* UDP [fe80::c02a:7289:617b:f4c8%9]:62301 *:* [ipconfig] Windows IP Configuration Host Name . . . . . . . . . . . . : INO-RUT-VLT01 Primary Dns Suffix . . . . . . . : inside.inoxihp.com.au Node Type . . . . . . . . . . . . : Hybrid IP Routing Enabled. . . . . . . . : No WINS Proxy Enabled. . . . . . . . : No DNS Suffix Search List. . . . . . : inside.inoxihp.com.au Ethernet adapter Ethernet Instance 0: Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Intel(R) 82574L Gigabit Network Connection Physical Address. . . . . . . . . : 52-54-00-B7-FB-29 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes Link-local IPv6 Address . . . . . : fe80::c02a:7289:617b:f4c8%9(Preferred) IPv4 Address. . . . . . . . . . . : 10.2.63.49(Preferred) Subnet Mask . . . . . . . . . . . : 255.255.255.0 Default Gateway . . . . . . . . . : 10.2.63.1 DHCPv6 IAID . . . . . . . . . . . : 106058752 DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-2F-B6-8E-1E-52-54-00-B7-FB-29 DNS Servers . . . . . . . . . . . : 10.2.63.45 10.2.63.47 NetBIOS over Tcpip. . . . . . . . : Enabled [route] =========================================================================== Interface List 9...52 54 00 b7 fb 29 ......Intel(R) 82574L Gigabit Network Connection 1...........................Software Loopback Interface 1 =========================================================================== IPv4 Route Table =========================================================================== Active Routes: Network Destination Netmask Gateway Interface Metric 0.0.0.0 0.0.0.0 10.2.63.1 10.2.63.49 281 10.2.63.0 255.255.255.0 On-link 10.2.63.49 281 10.2.63.49 255.255.255.255 On-link 10.2.63.49 281 10.2.63.255 255.255.255.255 On-link 10.2.63.49 281 127.0.0.0 255.0.0.0 On-link 127.0.0.1 331 127.0.0.1 255.255.255.255 On-link 127.0.0.1 331 127.255.255.255 255.255.255.255 On-link 127.0.0.1 331 224.0.0.0 240.0.0.0 On-link 127.0.0.1 331 224.0.0.0 240.0.0.0 On-link 10.2.63.49 281 255.255.255.255 255.255.255.255 On-link 127.0.0.1 331 255.255.255.255 255.255.255.255 On-link 10.2.63.49 281 =========================================================================== Persistent Routes: Network Address Netmask Gateway Address Metric 0.0.0.0 0.0.0.0 10.2.63.1 Default =========================================================================== IPv6 Route Table =========================================================================== Active Routes: If Metric Network Destination Gateway 1 331 ::1/128 On-link 9 281 fe80::/64 On-link 9 281 fe80::c02a:7289:617b:f4c8/128 On-link 1 331 ff00::/8 On-link 9 281 ff00::/8 On-link =========================================================================== Persistent Routes: None [ifstat] 10.2.63.49 72943692050 1242957267998 [svcs] Name StartupType Status DisplayName AdskLicensingService automatic started Autodesk Desktop Licensing Service AJRouter manual stopped AllJoyn Router Service ALG manual stopped Application Layer Gateway Service AppHostSvc automatic started Application Host Helper Service AppIDSvc manual stopped Application Identity Appinfo manual stopped Application Information AppMgmt manual stopped Application Management AppReadiness manual stopped App Readiness AppVClient automatic stopped Microsoft App-V Client AppXSvc manual stopped AppX Deployment Service (AppXSVC) aspnet_state manual stopped ASP.NET State Service AudioEndpointBuilder manual stopped Windows Audio Endpoint Builder Audiosrv manual stopped Windows Audio Autodesk_Access_Service_Host automatic started Autodesk Access Service Host Autodesk_CER_Service automatic started Autodesk CER Service Autodesk_Data_Management_Job_Dispatch automatic started Autodesk Data Management Job Dispatch Autodesk_Data_Management_Server_Revit_Dynamo_Extension_Service automatic started Autodesk Data Management Server Revit Dynamo Extension Service AutomationManagerAgent automatic started Automation Manager Agent AxInstSV manual stopped ActiveX Installer (AxInstSV) AzureAttestService automatic started AzureAttestService Backup_Service_Controller automatic started Backup Service Controller BASupportExpressSrvcUpdater_N_Central automatic started N-able Take Control Updater Service (N-Central) BASupportExpressStandaloneService_N_Central automatic started N-able Take Control Service (N-Central) BFE automatic started Base Filtering Engine BITS manual stopped Background Intelligent Transfer Service BrokerInfrastructure automatic started Background Tasks Infrastructure Service bthserv manual stopped Bluetooth Support Service camsvc manual stopped Capability Access Manager Service CDPSvc automatic started Connected Devices Platform Service CertPropSvc manual started Certificate Propagation ClipSVC manual stopped Client License Service (ClipSVC) COMSysApp manual stopped COM+ System Application CoreMessagingRegistrar automatic started CoreMessaging CryptSvc automatic started Cryptographic Services CscService disabled stopped Offline Files DcomLaunch automatic started DCOM Server Process Launcher dcsvc manual stopped Declared Configuration(DC) service defragsvc manual stopped Optimize drives DeviceAssociationService manual stopped Device Association Service DeviceInstall manual stopped Device Install Service DevQueryBroker manual stopped DevQuery Background Discovery Broker Dhcp automatic started DHCP Client diagnosticshub.standardcollector.service manual stopped Microsoft (R) Diagnostics Hub Standard Collector Service DiagTrack automatic started Connected User Experiences and Telemetry DispBrokerDesktopSvc automatic started Display Policy Service DmEnrollmentSvc manual stopped Device Management Enrollment Service dmwappushservice disabled stopped Device Management Wireless Application Protocol (WAP) Push message Routing Service Dnscache automatic started DNS Client DoSvc manual stopped Delivery Optimization dot3svc manual stopped Wired AutoConfig DPS automatic started Diagnostic Policy Service DsmSvc manual stopped Device Setup Manager DsSvc manual started Data Sharing Service EapHost manual stopped Extensible Authentication Protocol edgeupdate automatic stopped Microsoft Edge Update Service (edgeupdate) edgeupdatem manual stopped Microsoft Edge Update Service (edgeupdatem) EFS manual stopped Encrypting File System (EFS) embeddedmode manual stopped Embedded Mode EntAppSvc manual stopped Enterprise App Management Service EventLog automatic started Windows Event Log EventSystem automatic started COM+ Event System fdPHost manual stopped Function Discovery Provider Host FDResPub manual stopped Function Discovery Resource Publication FlexNet_Licensing_Service_64 automatic started FlexNet Licensing Service 64 FontCache automatic started Windows Font Cache Service FOSWindowsService automatic started Autodesk File Operations System Service FrameServer manual stopped Windows Camera Frame Server FrameServerMonitor manual stopped Windows Camera Frame Server Monitor GoogleChromeElevationService manual stopped Google Chrome Elevation Service (GoogleChromeElevationService) GoogleUpdaterInternalService143.0.7482.0 disabled stopped Google Updater Internal Service (GoogleUpdaterInternalService143.0.7482.0) GoogleUpdaterService143.0.7482.0 disabled stopped Google Updater Service (GoogleUpdaterService143.0.7482.0) gpsvc automatic started Group Policy Client GraphicsPerfSvc disabled stopped GraphicsPerfSvc HelpDeskService automatic started HelpDeskService hidserv manual stopped Human Interface Device Service HvHost manual stopped HV Host Service IDriveService automatic started IDriveService IISADMIN automatic started IIS Admin Service IKEEXT automatic started IKE and AuthIP IPsec Keying Modules InstallService manual stopped Microsoft Store Install Service iphlpsvc automatic started IP Helper KeyIso manual started CNG Key Isolation KPSSVC manual stopped KDC Proxy Server service (KPS) KtmRm manual stopped KtmRm for Distributed Transaction Coordinator LanmanServer automatic started Server LanmanWorkstation automatic started Workstation lfsvc disabled stopped Geolocation Service LicenseManager manual stopped Windows License Manager Service lltdsvc manual stopped Link-Layer Topology Discovery Mapper lmhosts manual started TCP/IP NetBIOS Helper LSM automatic started Local Session Manager LTService automatic started Viatek Technology Monitoring Service LTSvcMon automatic started Viatek Technology Monitoring Service Watchdog Service MapsBroker disabled stopped Downloaded Maps Manager MBAMService automatic started Malwarebytes Service MBVpnTunnelService manual stopped MBVpnTunnelService McpManagementService manual stopped McpManagementService MDCoreSvc automatic started Microsoft Defender Core Service Mesh_Agent automatic started Mesh Agent MicrosoftEdgeElevationService manual stopped Microsoft Edge Elevation Service (MicrosoftEdgeElevationService) mpssvc automatic started Windows Defender Firewall MSDTC automatic started Distributed Transaction Coordinator MsDtsServer160 automatic started SQL Server Integration Services 16.0 MSiSCSI manual stopped Microsoft iSCSI Initiator Service msiserver manual stopped Windows Installer MSSQL$AUTODESKVAULT automatic started SQL Server (AUTODESKVAULT) MSSQLFDLauncher$AUTODESKVAULT manual started SQL Full-text Filter Daemon Launcher (AUTODESKVAULT) NcaSvc manual stopped Network Connectivity Assistant NcbService manual started Network Connection Broker Netlogon automatic started Netlogon Netman manual stopped Network Connections netprofm automatic started Network List Service NetSetupSvc manual stopped Network Setup Service NetTcpPortSharing manual stopped Net.Tcp Port Sharing Service NgcCtnrSvc manual stopped Microsoft Passport Container NgcSvc manual stopped Microsoft Passport NlaSvc automatic started Network Location Awareness nsi automatic started Network Store Interface Service PcaSvc automatic started Program Compatibility Assistant Service PerfHost manual stopped Performance Counter DLL Host pla manual stopped Performance Logs & Alerts PlugPlay manual started Plug and Play PME.Agent.PmeService automatic started PME Agent PolicyAgent manual started IPsec Policy Agent Power automatic started Power PrintNotify manual stopped Printer Extensions and Notifications ProfSvc automatic started User Profile Service PushToInstall disabled stopped Windows PushToInstall Service QWAVE manual stopped Quality Windows Audio Video Experience RasAuto manual stopped Remote Access Auto Connection Manager RasMan automatic started Remote Access Connection Manager RemoteAccess disabled stopped Routing and Remote Access RemoteRegistry automatic stopped Remote Registry RmSvc disabled stopped Radio Management Service RpcEptMapper automatic started RPC Endpoint Mapper RpcLocator manual stopped Remote Procedure Call (RPC) Locator RpcSs automatic started Remote Procedure Call (RPC) RSoPProv manual stopped Resultant Set of Policy Provider sacsvr manual stopped Special Administration Console Helper SamSs automatic started Security Accounts Manager SCardSvr manual stopped Smart Card ScDeviceEnum disabled stopped Smart Card Device Enumeration Service Schedule automatic started Task Scheduler SCPolicySvc manual stopped Smart Card Removal Policy ScreenConnect_Client_(69e7721040ec1250) automatic started ScreenConnect Client (69e7721040ec1250) seclogon manual stopped Secondary Logon SecurityHealthService manual started Windows Security Service SEMgrSvc disabled stopped Payments and NFC/SE Manager SENS automatic started System Event Notification Service Sense manual stopped Windows Defender Advanced Threat Protection Service SensorDataService disabled stopped Sensor Data Service SensorService manual stopped Sensor Service SensrSvc manual stopped Sensor Monitoring Service SessionEnv manual started Remote Desktop Configuration SharedAccess manual stopped Internet Connection Sharing (ICS) ShellHWDetection automatic started Shell Hardware Detection shpamsvc manual stopped Shared PC Account Manager smphost manual stopped Microsoft Storage Spaces SMP SNMPTRAP manual stopped SNMP Trap SolarWinds.MSP.CacheService automatic started File Cache Service Agent SolarWinds.MSP.RpcServerService automatic started Request Handler Agent Spooler automatic started Print Spooler sppsvc automatic started Software Protection SQLAgent$AUTODESKVAULT manual stopped SQL Server Agent (AUTODESKVAULT) SQLBrowser automatic started SQL Server Browser SQLTELEMETRY$AUTODESKVAULT automatic started SQL Server CEIP service (AUTODESKVAULT) SQLWriter automatic started SQL Server VSS Writer SSDPSRV manual started SSDP Discovery ssh-agent disabled stopped OpenSSH Authentication Agent SSISTELEMETRY160 automatic started SQL Server Integration Services CEIP service 16.0 SstpSvc manual started Secure Socket Tunneling Protocol Service StateRepository automatic started State Repository Service StiSvc manual stopped Windows Image Acquisition (WIA) StorSvc automatic started Storage Service svsvc manual stopped Spot Verifier swprv automatic started Microsoft Software Shadow Copy Provider SysMain automatic started SysMain SystemEventsBroker automatic started System Events Broker TabletInputService manual stopped Touch Keyboard and Handwriting Panel Service tapisrv manual stopped Telephony TermService manual started Remote Desktop Services Themes automatic started Themes TieringEngineService manual stopped Storage Tiers Management TimeBrokerSvc manual started Time Broker TokenBroker manual stopped Web Account Manager TrkWks automatic started Distributed Link Tracking Client TrustedInstaller manual stopped Windows Modules Installer tzautoupdate manual stopped Auto Time Zone Updater UALSVC automatic started User Access Logging Service UevAgentService disabled stopped User Experience Virtualization Service UmRdpService manual started Remote Desktop Services UserMode Port Redirector upnphost manual stopped UPnP Device Host UserManager automatic started User Manager UsoSvc automatic started Update Orchestrator Service VaultSvc manual stopped Credential Manager vds manual stopped Virtual Disk VeeamDeploySvc automatic started Veeam Installer Service VeeamEndpointBackupSvc automatic started Veeam Agent for Microsoft Windows VeeamTransportSvc automatic started Veeam Data Mover Service VG.LocalAgent manual stopped Autodesk Vault Gateway Local Agent vmicguestinterface manual stopped Hyper-V Guest Service Interface vmicheartbeat manual stopped Hyper-V Heartbeat Service vmickvpexchange manual stopped Hyper-V Data Exchange Service vmicshutdown manual stopped Hyper-V Guest Shutdown Service vmictimesync manual stopped Hyper-V Time Synchronization Service vmicvmsession manual stopped Hyper-V PowerShell Direct Service vmicvss manual stopped Hyper-V Volume Shadow Copy Requestor VSInstallerElevationService manual stopped Visual Studio Installer Elevation Service VSS automatic started Volume Shadow Copy VSStandardCollectorService150 manual stopped Visual Studio Standard Collector Service 150 W32Time automatic started Windows Time w3logsvc manual stopped W3C Logging Service W3SVC automatic started World Wide Web Publishing Service WaaSMedicSvc manual started Windows Update Medic Service WalletService disabled stopped WalletService WarpJITSvc manual stopped Warp JIT Service WAS manual started Windows Process Activation Service WbioSrvc manual stopped Windows Biometric Service Wcmsvc automatic started Windows Connection Manager WdiServiceHost manual stopped Diagnostic Service Host WdiSystemHost manual started Diagnostic System Host WdNisSvc manual started Microsoft Defender Antivirus Network Inspection Service Wecsvc manual stopped Windows Event Collector WEPHOSTSVC manual stopped Windows Encryption Provider Host Service wercplsupport manual stopped Problem Reports Control Panel Support WerSvc manual stopped Windows Error Reporting Service WiaRpc manual stopped Still Image Acquisition Events WinDefend automatic started Microsoft Defender Antivirus Service Windows_Agent_Maintenance_Service automatic started Windows Agent Maintenance Service Windows_Agent_Service automatic started Windows Agent Service WinHttpAutoProxySvc manual started WinHTTP Web Proxy Auto-Discovery Service Winmgmt automatic started Windows Management Instrumentation WinRM automatic started Windows Remote Management (WS-Management) wisvc manual stopped Windows Insider Service wlidsvc manual stopped Microsoft Account Sign-in Assistant wmiApSrv manual stopped WMI Performance Adapter WMPNetworkSvc manual stopped Windows Media Player Network Sharing Service WPDBusEnum manual stopped Portable Device Enumerator Service WpnService automatic started Windows Push Notifications System Service WSearch manual started Windows Search wuauserv automatic stopped Windows Update XymonPSClient automatic started XymonPSClient [uptime] sec: 1189046 13 days 18 hours 17 minutes 25 seconds Bootup: 20251127021247.500000+660 [who] SESSIONNAME USERNAME ID STATE TYPE DEVICE >services 0 Disc console 1 Conn 31c5ce94259d4... 65536 Listen rdp-tcp 65537 Listen Total sessions created: 2 Total sessions disconnected: 0 Total sessions reconnected: 0 [users] [iis_sites] Default Web Site IIS://localhost/W3SVC/1 SiteID: 1 LogFileDirectory C:\inetpub\logs\LogFiles ServerBindings :80: ServerState 2 [XymonConfig] XymonSettings serversList : xymon.twilightcomputer.au serverUrl : serverHttpUsername : serverHttpTimeoutMs : 100000 wanteddisksList : {3} clientname : ino-rut-vlt01 clientbbwinmembug : 1 clientsoftware : powershell clientclass : powershell loopinterval : 300 maxlogage : 60 MaxEvents : 5000 slowscanrate : 72 reportevt : 1 EnableWin32_Product : 0 EnableWin32_QuickFixEngineering : 0 EnableWMISections : 0 EnableDiskPart : 0 ClientProcessPriority : Normal clientlogpath : c:\program files\xymon\logs XymonAcceptUTF8 : 0 GetProcessInfoCommandLine : 1 GetProcessInfoOwner : 1 localdatalocation : C:\Program Files\XYMON\local servergiflocation : /xymon/gifs/ servers : xymon.twilightcomputer.au clientlogfile : c:\program files\xymon\logs\xymonclient.log clientlogretain : 3 clientconfigfile : c:\program files\xymon\clientconfig.cfg clientfqdn : 0 clientlower : 1 clientremotecfgexec : 1 enableiissection : 1 externalscriptlocation : c:\program files\xymon\ext externaldatalocation : c:\program files\xymon\tmp HaveCmd Name Value ---- ----- qwinsta True query True XymonClientVersion : xymonclient.ps1 2.42 2019-03-11 zak.beck@accenture.com clientname ino-rut-vlt01 [XymonPSClientInfo] Collection number: 3962 Last transmission method: TCP Id : 7084 Handles : 563 CPU : 5250.28125 SI : 0 Name : powershell