Created
September 26, 2017 06:45
-
-
Save jcolebrand/170673e45bf8a659552f22f2071c30d6 to your computer and use it in GitHub Desktop.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
>>>>>> OS Version | |
SystemDirectory : C:\Windows\system32 | |
Organization : | |
BuildNumber : 14393 | |
RegisteredUser : Windows User | |
SerialNumber : 00376-30818-63755-AA823 | |
Version : 10.0.14393 | |
>>>>>> Computer Info | |
PSComputerName : WIN-CDPNLUMSTOE | |
AdminPasswordStatus : 3 | |
BootupState : Normal boot | |
ChassisBootupState : 3 | |
KeyboardPasswordStatus : 3 | |
PowerOnPasswordStatus : 3 | |
PowerSupplyState : 3 | |
PowerState : 0 | |
FrontPanelResetStatus : 3 | |
ThermalState : 3 | |
Status : OK | |
Name : WIN-CDPNLUMSTOE | |
PowerManagementCapabilities : | |
PowerManagementSupported : | |
__GENUS : 2 | |
__CLASS : Win32_ComputerSystem | |
__SUPERCLASS : CIM_UnitaryComputerSystem | |
__DYNASTY : CIM_ManagedSystemElement | |
__RELPATH : Win32_ComputerSystem.Name="WIN-CDPNLUMSTOE" | |
__PROPERTY_COUNT : 64 | |
__DERIVATION : {CIM_UnitaryComputerSystem, CIM_ComputerSystem, CIM_System, CIM_LogicalElement...} | |
__SERVER : WIN-CDPNLUMSTOE | |
__NAMESPACE : root\cimv2 | |
__PATH : \\WIN-CDPNLUMSTOE\root\cimv2:Win32_ComputerSystem.Name="WIN-CDPNLUMSTOE" | |
AutomaticManagedPagefile : True | |
AutomaticResetBootOption : True | |
AutomaticResetCapability : True | |
BootOptionOnLimit : | |
BootOptionOnWatchDog : | |
BootROMSupported : True | |
BootStatus : | |
Caption : WIN-CDPNLUMSTOE | |
ChassisSKUNumber : | |
CreationClassName : Win32_ComputerSystem | |
CurrentTimeZone : -420 | |
DaylightInEffect : True | |
Description : AT/AT COMPATIBLE | |
DNSHostName : WIN-CDPNLUMSTOE | |
Domain : WORKGROUP | |
DomainRole : 2 | |
EnableDaylightSavingsTime : True | |
HypervisorPresent : True | |
InfraredSupported : False | |
InitialLoadInfo : | |
InstallDate : | |
LastLoadInfo : | |
Manufacturer : innotek GmbH | |
Model : VirtualBox | |
NameFormat : | |
NetworkServerModeEnabled : True | |
NumberOfLogicalProcessors : 4 | |
NumberOfProcessors : 1 | |
OEMLogoBitmap : | |
OEMStringArray : {vboxVer_5.1.28, vboxRev_117968} | |
PartOfDomain : False | |
PauseAfterReset : -1 | |
PCSystemType : 2 | |
PCSystemTypeEx : 2 | |
PrimaryOwnerContact : | |
PrimaryOwnerName : Windows User | |
ResetCapability : 1 | |
ResetCount : -1 | |
ResetLimit : -1 | |
Roles : {LM_Workstation, LM_Server, NT, Server_NT} | |
SupportContactDescription : | |
SystemFamily : Virtual Machine | |
SystemSKUNumber : | |
SystemStartupDelay : | |
SystemStartupOptions : | |
SystemStartupSetting : | |
SystemType : x64-based PC | |
TotalPhysicalMemory : 10615312384 | |
UserName : WIN-CDPNLUMSTOE\Administrator | |
WakeUpType : 6 | |
Workgroup : WORKGROUP | |
Scope : System.Management.ManagementScope | |
Path : \\WIN-CDPNLUMSTOE\root\cimv2:Win32_ComputerSystem.Name="WIN-CDPNLUMSTOE" | |
Options : System.Management.ObjectGetOptions | |
ClassPath : \\WIN-CDPNLUMSTOE\root\cimv2:Win32_ComputerSystem | |
Properties : {AdminPasswordStatus, AutomaticManagedPagefile, AutomaticResetBootOption, AutomaticResetCapability...} | |
SystemProperties : {__GENUS, __CLASS, __SUPERCLASS, __DYNASTY...} | |
Qualifiers : {dynamic, Locale, provider, UUID} | |
Site : | |
Container : | |
>>>>>> CPU Info | |
PSComputerName : WIN-CDPNLUMSTOE | |
Availability : 3 | |
CpuStatus : 0 | |
CurrentVoltage : | |
DeviceID : CPU0 | |
ErrorCleared : | |
ErrorDescription : | |
LastErrorCode : | |
LoadPercentage : 1 | |
Status : OK | |
StatusInfo : 3 | |
AddressWidth : 64 | |
DataWidth : 64 | |
ExtClock : | |
L2CacheSize : | |
L2CacheSpeed : | |
MaxClockSpeed : 2794 | |
PowerManagementSupported : False | |
ProcessorType : | |
Revision : 17921 | |
SocketDesignation : | |
Version : | |
VoltageCaps : | |
__GENUS : 2 | |
__CLASS : Win32_Processor | |
__SUPERCLASS : CIM_Processor | |
__DYNASTY : CIM_ManagedSystemElement | |
__RELPATH : Win32_Processor.DeviceID="CPU0" | |
__PROPERTY_COUNT : 57 | |
__DERIVATION : {CIM_Processor, CIM_LogicalDevice, CIM_LogicalElement, CIM_ManagedSystemElement} | |
__SERVER : WIN-CDPNLUMSTOE | |
__NAMESPACE : root\cimv2 | |
__PATH : \\WIN-CDPNLUMSTOE\root\cimv2:Win32_Processor.DeviceID="CPU0" | |
Architecture : 9 | |
AssetTag : | |
Caption : Intel64 Family 6 Model 70 Stepping 1 | |
Characteristics : | |
ConfigManagerErrorCode : | |
ConfigManagerUserConfig : | |
CreationClassName : Win32_Processor | |
CurrentClockSpeed : 2794 | |
Description : Intel64 Family 6 Model 70 Stepping 1 | |
Family : 2 | |
InstallDate : | |
L3CacheSize : 0 | |
L3CacheSpeed : 0 | |
Level : 6 | |
Manufacturer : GenuineIntel | |
Name : Intel(R) Core(TM) i7-4980HQ CPU @ 2.80GHz | |
NumberOfCores : 4 | |
NumberOfEnabledCore : | |
NumberOfLogicalProcessors : 4 | |
OtherFamilyDescription : | |
PartNumber : | |
PNPDeviceID : | |
PowerManagementCapabilities : | |
ProcessorId : | |
Role : CPU | |
SecondLevelAddressTranslationExtensions : False | |
SerialNumber : | |
Stepping : | |
SystemCreationClassName : Win32_ComputerSystem | |
SystemName : WIN-CDPNLUMSTOE | |
ThreadCount : | |
UniqueId : | |
UpgradeMethod : 2 | |
VirtualizationFirmwareEnabled : False | |
VMMonitorModeExtensions : False | |
Scope : System.Management.ManagementScope | |
Path : \\WIN-CDPNLUMSTOE\root\cimv2:Win32_Processor.DeviceID="CPU0" | |
Options : System.Management.ObjectGetOptions | |
ClassPath : \\WIN-CDPNLUMSTOE\root\cimv2:Win32_Processor | |
Properties : {AddressWidth, Architecture, AssetTag, Availability...} | |
SystemProperties : {__GENUS, __CLASS, __SUPERCLASS, __DYNASTY...} | |
Qualifiers : {dynamic, Locale, provider, UUID} | |
Site : | |
Container : | |
>>>>>> Board Info | |
PSComputerName : WIN-CDPNLUMSTOE | |
Status : OK | |
Name : Base Board | |
PoweredOn : True | |
__GENUS : 2 | |
__CLASS : Win32_BaseBoard | |
__SUPERCLASS : CIM_Card | |
__DYNASTY : CIM_ManagedSystemElement | |
__RELPATH : Win32_BaseBoard.Tag="Base Board" | |
__PROPERTY_COUNT : 29 | |
__DERIVATION : {CIM_Card, CIM_PhysicalPackage, CIM_PhysicalElement, CIM_ManagedSystemElement} | |
__SERVER : WIN-CDPNLUMSTOE | |
__NAMESPACE : root\cimv2 | |
__PATH : \\WIN-CDPNLUMSTOE\root\cimv2:Win32_BaseBoard.Tag="Base Board" | |
Caption : Base Board | |
ConfigOptions : | |
CreationClassName : Win32_BaseBoard | |
Depth : | |
Description : Base Board | |
Height : | |
HostingBoard : True | |
HotSwappable : False | |
InstallDate : | |
Manufacturer : Oracle Corporation | |
Model : | |
OtherIdentifyingInfo : | |
PartNumber : | |
Product : VirtualBox | |
Removable : False | |
Replaceable : False | |
RequirementsDescription : | |
RequiresDaughterBoard : False | |
SerialNumber : 0 | |
SKU : | |
SlotLayout : | |
SpecialRequirements : | |
Tag : Base Board | |
Version : 1.2 | |
Weight : | |
Width : | |
Scope : System.Management.ManagementScope | |
Path : \\WIN-CDPNLUMSTOE\root\cimv2:Win32_BaseBoard.Tag="Base Board" | |
Options : System.Management.ObjectGetOptions | |
ClassPath : \\WIN-CDPNLUMSTOE\root\cimv2:Win32_BaseBoard | |
Properties : {Caption, ConfigOptions, CreationClassName, Depth...} | |
SystemProperties : {__GENUS, __CLASS, __SUPERCLASS, __DYNASTY...} | |
Qualifiers : {dynamic, Locale, provider, UUID} | |
Site : | |
Container : | |
>>>>>> Installed Files | |
Directory: C:\Program Files\Docker\Docker | |
Mode LastWriteTime Length Name | |
---- ------------- ------ ---- | |
d----- 9/15/2017 1:47 PM resources | |
-a---- 9/15/2017 1:47 PM 47616 Bugsnag.dll | |
-a---- 9/15/2017 1:47 PM 103936 Bugsnag.pdb | |
-a---- 9/15/2017 1:47 PM 9728 com.docker.service | |
-a---- 9/15/2017 1:47 PM 178 com.docker.service.config | |
-a---- 9/15/2017 1:47 PM 331432 concrt140.dll | |
-a---- 9/15/2017 1:47 PM 3561992 Docker for windows Installer.exe | |
-a---- 9/15/2017 1:47 PM 1813464 Docker for Windows.exe | |
-a---- 9/15/2017 1:47 PM 620 Docker for Windows.exe.config | |
-a---- 9/15/2017 1:47 PM 99840 Docker for Windows.pdb | |
-a---- 9/15/2017 1:47 PM 85504 Docker.Backend.dll | |
-a---- 9/15/2017 1:47 PM 175 Docker.Backend.dll.config | |
-a---- 9/15/2017 1:47 PM 171520 Docker.Backend.pdb | |
-a---- 9/15/2017 1:47 PM 77824 Docker.Core.dll | |
-a---- 9/15/2017 1:47 PM 172 Docker.Core.dll.config | |
-a---- 9/15/2017 1:47 PM 200192 Docker.Core.pdb | |
-a---- 9/15/2017 1:47 PM 17920 Docker.Service.pdb | |
-a---- 9/15/2017 1:47 PM 12800 Docker.Watchguard.exe | |
-a---- 9/15/2017 1:47 PM 2068480 Docker.Watchguard.pdb | |
-a---- 9/15/2017 1:47 PM 313344 Docker.Win32Helpers.dll | |
-a---- 9/15/2017 1:47 PM 2093056 Docker.Win32Helpers.pdb | |
-a---- 9/15/2017 1:47 PM 1565184 Docker.WPF.dll | |
-a---- 9/15/2017 1:47 PM 617 Docker.WPF.dll.config | |
-a---- 9/15/2017 1:47 PM 435712 Docker.WPF.pdb | |
-a---- 9/15/2017 1:47 PM 21984 DockerCli.exe | |
-a---- 9/15/2017 1:47 PM 528 DockerCli.exe.config | |
-a---- 9/15/2017 1:47 PM 36352 DockerCli.pdb | |
-a---- 9/15/2017 1:47 PM 2098 installationmanifest.json | |
-a---- 9/15/2017 1:47 PM 12800 InstallerCli.exe | |
-a---- 9/15/2017 1:47 PM 528 InstallerCli.exe.config | |
-a---- 9/15/2017 1:47 PM 19968 InstallerCli.pdb | |
-a---- 9/15/2017 1:47 PM 36864 Microsoft.Management.Infrastructure.dll | |
-a---- 9/15/2017 1:47 PM 89944 Microsoft.Toolkit.Uwp.Notifications.dll | |
-a---- 9/15/2017 1:47 PM 284160 Microsoft.Toolkit.Uwp.Notifications.pdb | |
-a---- 9/15/2017 1:47 PM 641696 msvcp140.dll | |
-a---- 9/15/2017 1:47 PM 526336 Newtonsoft.Json.dll | |
-a---- 9/15/2017 1:47 PM 524800 NLog.dll | |
-a---- 9/15/2017 1:47 PM 1445376 NLog.pdb | |
-a---- 9/15/2017 1:47 PM 360448 System.Management.Automation.dll | |
-a---- 9/15/2017 1:47 PM 185544 System.Net.Http.Formatting.dll | |
-a---- 9/15/2017 1:47 PM 28216 System.Runtime.WindowsRuntime.dll | |
-a---- 9/15/2017 1:47 PM 30312 System.Runtime.WindowsRuntime.UI.Xaml.dll | |
-a---- 9/15/2017 1:47 PM 77664 System.ValueTuple.dll | |
-a---- 9/15/2017 1:47 PM 389296 vccorlib140.dll | |
-a---- 9/15/2017 1:47 PM 87728 vcruntime140.dll | |
>>>>>> Installed Resources | |
Directory: C:\Program Files\Docker\Docker\resources | |
Mode LastWriteTime Length Name | |
---- ------------- ------ ---- | |
d----- 9/15/2017 1:47 PM bin | |
d----- 9/15/2017 1:47 PM qemu-img | |
-a---- 9/15/2017 1:47 PM 3009536 com.docker.9pdb.exe | |
-a---- 9/15/2017 1:47 PM 13536256 com.docker.cloud.proxy.exe | |
-a---- 9/15/2017 1:47 PM 10019415 com.docker.db.exe | |
-a---- 9/15/2017 1:47 PM 13536256 com.docker.proxy.exe | |
-a---- 9/15/2017 1:47 PM 35451239 dockerd.exe | |
-a---- 9/15/2017 1:47 PM 5066 DockerDebugInfo.ps1 | |
-a---- 9/15/2017 1:47 PM 1857 ForceRemoveDocker.ps1 | |
-a---- 9/15/2017 1:47 PM 19196 LICENSE.rtf | |
-a---- 9/15/2017 1:47 PM 80248832 mobylinux.iso | |
-a---- 9/15/2017 1:47 PM 13920 MobyLinux.ps1 | |
-a---- 9/15/2017 1:47 PM 96256 nsenter.tar | |
-a---- 9/15/2017 1:47 PM 277583 OSS-LICENSES.txt | |
-a---- 9/15/2017 1:47 PM 40 sha1 | |
-a---- 9/15/2017 1:47 PM 53941 tile-error.png | |
-a---- 9/15/2017 1:47 PM 85139 tile-icon.png | |
-a---- 9/15/2017 1:47 PM 6 UpdateChannel | |
-a---- 9/15/2017 1:47 PM 17976326 vpnkit.exe | |
-a---- 9/15/2017 1:47 PM 1516 WinContainers.ps1 | |
-a---- 9/15/2017 1:47 PM 5644 WinContainersDiags.ps1 | |
-a---- 9/15/2017 1:47 PM 87040 zlib1.dll | |
>>>>>> Get-VMHost | |
LogicalProcessorCount : 4 | |
ResourceMeteringSaveInterval : 01:00:00 | |
HostNumaStatus : {WIN-CDPNLUMSTOE} | |
NumaStatus : {} | |
IovSupport : False | |
IovSupportReasons : {The Virtualization Infrastructure Driver (VID) is not running. Ensure that the VID is properly installed and enabled., SR-IOV cannot be used on | |
this computer because the processor does not support second level address translation (SLAT). For Intel processors, this feature might be referred | |
to as Extended Page Tables (EPT). For AMD processors, this feature might be referred to as Rapid Virtualization Indexing (RVI) or Nested Page | |
Tables (NPT)., To use SR-IOV on this system, the system BIOS must be updated to allow Windows to control PCI Express. Contact your system | |
manufacturer for an update., SR-IOV cannot be used on this system as the PCI Express hardware does not support Access Control Services (ACS) at any | |
root port. Contact your system vendor for further information.} | |
InternalNetworkAdapters : {HNS Internal NIC Port, HNS Internal NIC Port} | |
ExternalNetworkAdapters : {} | |
SupportedVmVersions : {5.0, 6.2, 7.0, 7.1...} | |
SecureBootTemplates : {MicrosoftWindows, MicrosoftUEFICertificateAuthority} | |
EnableEnhancedSessionMode : False | |
FibreChannelWwnn : C003FF0000FFFF00 | |
FibreChannelWwpnMaximum : C003FF7421E9FFFF | |
FibreChannelWwpnMinimum : C003FF7421E90000 | |
MacAddressMaximum : 00155D020FFF | |
MacAddressMinimum : 00155D020F00 | |
NumaSpanningEnabled : True | |
VirtualHardDiskPath : C:\Users\Public\Documents\Hyper-V\Virtual Hard Disks | |
VirtualMachinePath : C:\ProgramData\Microsoft\Windows\Hyper-V | |
FullyQualifiedDomainName : WORKGROUP | |
MemoryCapacity : 10615312384 | |
Name : WIN-CDPNLUMSTOE | |
MaximumStorageMigrations : 2 | |
MaximumVirtualMachineMigrations : 2 | |
UseAnyNetworkForMigration : False | |
VirtualMachineMigrationAuthenticationType : CredSSP | |
VirtualMachineMigrationEnabled : False | |
VirtualMachineMigrationPerformanceOption : Compression | |
CimSession : CimSession: . | |
ComputerName : WIN-CDPNLUMSTOE | |
IsDeleted : False | |
>>>>>> Get-WindowsOptionalFeature | |
FeatureName State | |
----------- ----- | |
NetFx4ServerFeatures Enabled | |
NetFx4 Enabled | |
NetFx4Extended-ASPNET45 Disabled | |
MicrosoftWindowsPowerShellRoot Enabled | |
MicrosoftWindowsPowerShell Enabled | |
iSCSITargetServer-PowerShell Disabled | |
PKIClient-PSH-Cmdlets Disabled | |
KeyDistributionService-PSH-Cmdlets Enabled | |
TlsSessionTicketKey-PSH-Cmdlets Enabled | |
Tpm-PSH-Cmdlets Enabled | |
MicrosoftWindowsPowerShellV2 Enabled | |
WindowsPowerShellWebAccess Disabled | |
DataCenterBridging-LLDP-Tools Disabled | |
Server-Psh-Cmdlets Enabled | |
MicrosoftWindowsPowerShellISE Enabled | |
RemoteAccessMgmtTools Disabled | |
RemoteAccessPowerShell Disabled | |
RasServerAdminTools Disabled | |
DamgmtTools Disabled | |
WSS-Product-Package Disabled | |
ActiveDirectory-PowerShell Disabled | |
DirectoryServices-DomainController Disabled | |
DirectoryServices-ISM-Smtp Disabled | |
HostGuardianService-Package Disabled | |
DirectoryServices-AdministrativeCenter Disabled | |
RemoteAccess Disabled | |
RemoteAccessServer Disabled | |
RasRoutingProtocols Disabled | |
Web-Application-Proxy Disabled | |
RightsManagementServices-Role Disabled | |
RightsManagementServices Disabled | |
RMS-Federation Disabled | |
RightsManagementServices-AdminTools Disabled | |
IIS-WebServerRole Disabled | |
IIS-WebServer Disabled | |
IIS-CommonHttpFeatures Disabled | |
IIS-Security Disabled | |
IIS-RequestFiltering Disabled | |
IIS-StaticContent Disabled | |
IIS-DefaultDocument Disabled | |
IIS-DirectoryBrowsing Disabled | |
IIS-HttpErrors Disabled | |
IIS-HttpRedirect Disabled | |
IIS-WebDAV Disabled | |
IIS-ApplicationDevelopment Disabled | |
IIS-WebSockets Disabled | |
IIS-ApplicationInit Disabled | |
IIS-NetFxExtensibility Disabled | |
IIS-NetFxExtensibility45 Disabled | |
IIS-ISAPIExtensions Disabled | |
IIS-ISAPIFilter Disabled | |
IIS-ASPNET Disabled | |
IIS-ASPNET45 Disabled | |
IIS-ASP Disabled | |
IIS-CGI Disabled | |
IIS-ServerSideIncludes Disabled | |
IIS-HealthAndDiagnostics Disabled | |
IIS-HttpLogging Disabled | |
IIS-LoggingLibraries Disabled | |
IIS-RequestMonitor Disabled | |
IIS-HttpTracing Disabled | |
IIS-CustomLogging Disabled | |
IIS-ODBCLogging Disabled | |
IIS-CertProvider Disabled | |
IIS-BasicAuthentication Disabled | |
IIS-WindowsAuthentication Disabled | |
IIS-DigestAuthentication Disabled | |
IIS-ClientCertificateMappingAuthentication Disabled | |
IIS-IISCertificateMappingAuthentication Disabled | |
IIS-URLAuthorization Disabled | |
IIS-IPSecurity Disabled | |
IIS-Performance Disabled | |
IIS-HttpCompressionStatic Disabled | |
IIS-HttpCompressionDynamic Disabled | |
IIS-WebServerManagementTools Disabled | |
IIS-ManagementConsole Disabled | |
IIS-LegacySnapIn Disabled | |
IIS-ManagementScriptingTools Disabled | |
IIS-ManagementService Disabled | |
IIS-IIS6ManagementCompatibility Disabled | |
IIS-Metabase Disabled | |
IIS-WMICompatibility Disabled | |
IIS-LegacyScripts Disabled | |
IIS-FTPServer Disabled | |
IIS-FTPSvc Disabled | |
IIS-FTPExtensibility Disabled | |
WAS-WindowsActivationService Disabled | |
WAS-ProcessModel Disabled | |
WAS-NetFxEnvironment Disabled | |
WAS-ConfigurationAPI Disabled | |
IIS-HostableWebCore Disabled | |
MSMQ Disabled | |
MSMQ-Services Disabled | |
MSMQ-Server Disabled | |
MSMQ-Triggers Disabled | |
MSMQ-ADIntegration Disabled | |
MSMQ-HTTP Disabled | |
MSMQ-Multicast Disabled | |
MSMQ-DCOMProxy Disabled | |
MSMQ-RoutingServer Disabled | |
WCF-Services45 Enabled | |
WCF-HTTP-Activation45 Disabled | |
WCF-TCP-Activation45 Disabled | |
WCF-Pipe-Activation45 Disabled | |
WCF-MSMQ-Activation45 Disabled | |
WCF-TCP-PortSharing45 Enabled | |
IdentityServer-SecurityTokenService Disabled | |
ManagementOdata Disabled | |
DSC-Service Disabled | |
ADCertificateServicesRole Disabled | |
CertificateServices Disabled | |
OnlineRevocationServices Disabled | |
WebEnrollmentServices Disabled | |
NetworkDeviceEnrollmentServices Disabled | |
CertificateEnrollmentPolicyServer Disabled | |
CertificateEnrollmentServer Disabled | |
IPAMServerFeature Disabled | |
DeviceHealthAttestationService Disabled | |
BITSExtensions-AdminPack Disabled | |
Gateway-UI Disabled | |
BITSExtensions-Upload Disabled | |
WCF-HTTP-Activation Disabled | |
WCF-NonHTTP-Activation Disabled | |
Smtpsvc-Admin-Update-Name Disabled | |
Smtpsvc-Service-Update-Name Disabled | |
WebAccess Disabled | |
Microsoft-Windows-Web-Services-for-Management-IIS-Extension Disabled | |
BusScan-ScanServer Disabled | |
Printing-InternetPrinting-Server Disabled | |
RPC-HTTP_Proxy Disabled | |
Gateway Disabled | |
UpdateServices Disabled | |
UpdateServices-Services Disabled | |
UpdateServices-Database Disabled | |
UpdateServices-WidDatabase Disabled | |
WorkFolders-Server Disabled | |
FSRM-Infrastructure Disabled | |
Microsoft-Windows-FCI-Client-Package Disabled | |
UpdateServices-RSAT Disabled | |
UpdateServices-API Disabled | |
UpdateServices-UI Disabled | |
FSRM-Infrastructure-Services Disabled | |
DirectoryServices-ADAM Disabled | |
IPAMClientFeature Disabled | |
Microsoft-Windows-ServerEssentials-ServerSetup Disabled | |
AuthManager Disabled | |
ServerCore-WOW64 Enabled | |
Printing-Server-Foundation-Features Disabled | |
Printing-Server-Role Disabled | |
Printing-LPDPrintService Disabled | |
Printing-Client Enabled | |
Printing-Client-Gui Enabled | |
ServerCore-EA-IME-WOW64 Enabled | |
NetFx3ServerFeatures Disabled | |
NetFx3 DisabledWithPayloadRemoved | |
Server-Shell Enabled | |
Internet-Explorer-Optional-amd64 Enabled | |
Server-Gui-Mgmt Enabled | |
Server-Gui-Mgmt_onecore Disabled | |
RSAT Enabled | |
Storage-Replica-AdminPack Disabled | |
Server-Manager-RSAT-File-Services Disabled | |
Server-RSAT-SNMP Disabled | |
DNS-Server-Tools Disabled | |
WINS-Server-Tools Disabled | |
DfsMgmt Disabled | |
ADCertificateServicesManagementTools Disabled | |
CertificateServicesManagementTools Disabled | |
OnlineRevocationServicesManagementTools Disabled | |
RSAT-AD-Tools-Feature Disabled | |
RSAT-ADDS-Tools-Feature Disabled | |
DirectoryServices-DomainController-Tools Disabled | |
DirectoryServices-ADAM-Tools Disabled | |
BitLocker-RemoteAdminTool Disabled | |
BdeAducExtTool Disabled | |
NPSMMC Disabled | |
Licensing-UI Disabled | |
Licensing-Diagnosis-UI Disabled | |
Microsoft-Windows-Deployment-Services-Admin-Pack Disabled | |
DHCPServer-Tools Disabled | |
FailoverCluster-Mgmt Disabled | |
NetworkLoadBalancingManagementClient Disabled | |
NFS-Administration Disabled | |
WindowsServerBackupSnapin Enabled | |
FaxServiceConfigRole Disabled | |
NPSManagementTools Disabled | |
RightsManagementServicesManagementTools Disabled | |
Security-SPP-Vmw Disabled | |
FSRM-Management Disabled | |
Windows-Defender-Gui Enabled | |
Microsoft-Hyper-V Enabled | |
Microsoft-Hyper-V-Offline Enabled | |
Microsoft-Hyper-V-Online Enabled | |
RSAT-Hyper-V-Tools-Feature Enabled | |
Microsoft-Hyper-V-Management-Clients Enabled | |
Microsoft-Hyper-V-Management-PowerShell Enabled | |
VmHostAgent Disabled | |
AppServer Disabled | |
Microsoft-Windows-Deployment-Services Disabled | |
Microsoft-Windows-Deployment-Services-Deployment-Server Disabled | |
Microsoft-Windows-Deployment-Services-Transport-Server Disabled | |
BitLocker Disabled | |
Bitlocker-Utilities Disabled | |
ShieldedVMToolsAdminPack Disabled | |
BitLocker-NetworkUnlock Disabled | |
SearchEngine-Server-Package Disabled | |
File-Services-Search-Service Disabled | |
FaxServiceRole Disabled | |
NPAS-Role Disabled | |
OEM-Appliance-OOBE Disabled | |
ServerMediaFoundation Disabled | |
MediaPlayback Enabled | |
WindowsMediaPlayer Enabled | |
WebDAV-Redirector Disabled | |
LegacyComponents Disabled | |
DirectPlay Disabled | |
Printing-LPRPortMonitor Disabled | |
Printing-InternetPrinting-Client Disabled | |
Printing-AdminTools-Collection Disabled | |
Windows-Identity-Foundation Disabled | |
Microsoft-Hyper-V-Common-Drivers-Package Enabled | |
Microsoft-Hyper-V-Guest-Integration-Drivers-Package Enabled | |
Microsoft-Windows-NetFx-VCRedist-Package Enabled | |
Microsoft-Windows-Printing-PrintToPDFServices-Package Enabled | |
Microsoft-Windows-Printing-XPSServices-Package Enabled | |
Microsoft-Windows-Client-EmbeddedExp-Package Enabled | |
Printing-PrintToPDFServices-Features Enabled | |
Printing-XPSServices-Features Enabled | |
MSRDC-Infrastructure Disabled | |
TelnetClient Enabled | |
TFTP Disabled | |
TIFFIFilter Disabled | |
SMB1Protocol Enabled | |
MultiPoint-Connector Disabled | |
MultiPoint-Connector-Services Disabled | |
MultiPoint-Tools Disabled | |
ServerManager-Core-RSAT Enabled | |
ServerManager-Core-RSAT-Role-Tools Enabled | |
ServerManager-Core-RSAT-Feature-Tools Disabled | |
FailoverCluster-AdminPak Disabled | |
FailoverCluster-PowerShell Disabled | |
HardenedFabricEncryptionTask Disabled | |
ServicesForNFS-ServerAndClient Disabled | |
ServerForNFS-Infrastructure Disabled | |
ClientForNFS-Infrastructure Disabled | |
SimpleTCP Disabled | |
SmbDirect Enabled | |
Windows-Defender-Features Enabled | |
Windows-Defender Enabled | |
EnhancedStorage Disabled | |
Microsoft-Windows-GroupPolicy-ServerAdminTools-Update Disabled | |
RSAT-RDS-Tools-Feature Disabled | |
BiometricFramework Disabled | |
WindowsServerBackup Disabled | |
DFSR-Infrastructure-ServerEdition Disabled | |
DNS-Server-Full-Role Disabled | |
Windows-Internal-Database Disabled | |
iSCSITargetStorageProviders Disabled | |
BITS Disabled | |
LightweightServer Disabled | |
MultipathIo Disabled | |
NetworkLoadBalancingFullServer Disabled | |
Containers Enabled | |
PeerDist Disabled | |
RemoteAssistance Disabled | |
ServerCore-EA-IME Enabled | |
DataCenterBridging Disabled | |
DiskIo-QoS Disabled | |
Server-Drivers-General Enabled | |
Server-Drivers-Printers Enabled | |
SNMP Disabled | |
WMISnmpProvider Disabled | |
WindowsStorageManagementService Disabled | |
Remote-Desktop-Services Disabled | |
SessionDirectory Disabled | |
SBMgr-UI Disabled | |
VolumeActivation-Full-Role Disabled | |
WirelessNetworking Disabled | |
Xps-Foundation-Xps-Viewer Disabled | |
SMBBW Disabled | |
SetupAndBootEventCollection Disabled | |
RasCMAK Disabled | |
DFSN-Server Disabled | |
DHCPServer Disabled | |
FailoverCluster-AutomationServer Disabled | |
FailoverCluster-CmdInterface Disabled | |
FRS-Infrastructure Disabled | |
FileServerVSSAgent Disabled | |
WINSRuntime Disabled | |
iSCSITargetServer Disabled | |
iSNS_Service Disabled | |
P2P-PnrpOnly Disabled | |
QWAVE Disabled | |
ServerMigration Disabled | |
SMBHashGeneration Disabled | |
Licensing Disabled | |
FailoverCluster-FullServer Disabled | |
CCFFilter Disabled | |
Dedup-Core Disabled | |
MultiPoint-Role Disabled | |
ResumeKeyFilter Disabled | |
SmbWitness Disabled | |
FabricShieldedTools Disabled | |
RasRip Disabled | |
SearchEngine-Client-Package Enabled | |
Client-DeviceLockdown Disabled | |
Client-EmbeddedShellLauncher Disabled | |
Client-EmbeddedBootExp Disabled | |
Client-EmbeddedLogon Disabled | |
Client-KeyboardFilter Disabled | |
Client-UnifiedWriteFilter Disabled | |
FileAndStorage-Services Enabled | |
Storage-Services Enabled | |
File-Services Disabled | |
CoreFileServer Disabled | |
ServerCore-Drivers-General Enabled | |
ServerCore-Drivers-General-WOW64 Enabled | |
>>>>>> bcdedit | |
Windows Boot Manager | |
-------------------- | |
identifier {bootmgr} | |
device partition=\Device\HarddiskVolume1 | |
description Windows Boot Manager | |
locale en-US | |
inherit {globalsettings} | |
bootshutdowndisabled Yes | |
default {current} | |
resumeobject {65b59142-9a6d-11e7-8ca8-b81d8bcd4177} | |
displayorder {current} | |
toolsdisplayorder {memdiag} | |
timeout 30 | |
Windows Boot Loader | |
------------------- | |
identifier {current} | |
device partition=C: | |
path \Windows\system32\winload.exe | |
description Windows Server 2016 | |
locale en-US | |
inherit {bootloadersettings} | |
recoverysequence {65b59144-9a6d-11e7-8ca8-b81d8bcd4177} | |
recoveryenabled Yes | |
allowedinmemorysettings 0x15000075 | |
osdevice partition=C: | |
systemroot \Windows | |
resumeobject {65b59142-9a6d-11e7-8ca8-b81d8bcd4177} | |
nx OptOut | |
hypervisorlaunchtype Auto | |
>>>>>> Get-Process | |
Handles NPM(K) PM(K) WS(K) CPU(s) Id SI ProcessName | |
------- ------ ----- ----- ------ -- -- ----------- | |
221 14 4144 18436 0.17 4068 1 ApplicationFrameHost | |
141 10 9332 13456 0.20 2724 1 com.docker.proxy | |
666 48 86228 89944 2.28 1952 0 com.docker.service | |
84 7 4868 8968 0.05 596 1 conhost | |
82 7 1128 4980 0.00 2984 0 conhost | |
82 7 1124 4976 0.02 3440 0 conhost | |
185 12 4596 17516 4.20 3976 1 conhost | |
286 12 1984 4248 0.17 472 0 csrss | |
256 13 2332 4504 1.58 568 1 csrss | |
86 6 1240 6020 0.02 1176 1 dllhost | |
582 49 61216 66504 2.22 3656 1 Docker for Windows | |
30 3 352 2052 0.02 3428 0 Docker.Watchguard | |
239 17 20256 33912 2.22 2964 0 dockerd | |
353 36 55360 92672 6.66 972 1 dwm | |
1455 65 24700 86184 6.06 2124 1 explorer | |
0 0 0 4 0 0 Idle | |
950 23 5848 14384 0.67 708 0 lsass | |
263 12 3060 11184 0.14 3692 0 MpCmdRun | |
194 13 2688 9352 0.09 3016 0 msdtc | |
455 65 114312 118256 16.70 1712 0 MsMpEng | |
209 16 9392 27876 3.70 3484 1 notepad++ | |
932 41 204252 229620 5.47 3892 1 powershell | |
440 22 10576 28768 0.58 3044 1 RuntimeBroker | |
944 64 65196 115176 1.39 3124 1 SearchUI | |
307 12 4168 7296 0.67 700 0 services | |
896 36 22608 64704 1.08 992 1 ShellExperienceHost | |
394 15 4288 19128 0.45 2756 1 sihost | |
51 3 456 1244 0.22 364 0 smss | |
438 22 6092 15584 0.09 1864 0 spoolsv | |
511 18 15316 23460 1.39 76 0 svchost | |
450 25 11112 18288 0.25 88 0 svchost | |
645 22 6004 19332 0.67 808 0 svchost | |
442 34 10180 16244 0.50 828 0 svchost | |
617 17 4088 9296 1.17 868 0 svchost | |
776 37 9400 25544 0.64 1080 0 svchost | |
651 38 8944 22124 0.58 1188 0 svchost | |
2183 110 42208 68956 8.69 1268 0 svchost | |
165 10 1992 7056 0.06 1356 0 svchost | |
144 11 1432 6456 0.03 1768 0 svchost | |
383 19 6104 18984 0.27 1908 0 svchost | |
202 11 2016 7888 0.06 2012 0 svchost | |
227 24 5968 17100 0.41 2044 0 svchost | |
297 18 4420 19364 0.11 2744 1 svchost | |
208 18 1804 6696 0.03 3112 0 svchost | |
94 7 1428 6120 0.02 3208 0 svchost | |
1127 0 128 140 44.41 4 0 System | |
307 24 4616 15004 0.33 880 1 taskhostw | |
166 9 6844 11076 1.78 5000 0 TiWorker | |
99 8 1892 6668 0.13 4800 0 TrustedInstaller | |
174 10 2012 7036 0.55 428 0 VBoxService | |
228 13 2348 9692 0.39 3568 1 VBoxTray | |
157 12 2712 12116 1.14 2628 0 vmcompute | |
692 23 12728 38368 0.58 2068 0 vmms | |
109 9 1216 4956 0.08 560 0 wininit | |
193 9 2040 8696 0.19 624 1 winlogon | |
138 9 1980 7880 0.11 3928 0 WmiPrvSE | |
279 16 7084 15840 0.27 4172 0 WmiPrvSE | |
>>>>>> Services | |
Image Name PID Services | |
========================= ======== ============================================ | |
svchost.exe 808 BrokerInfrastructure, DcomLaunch, LSM, | |
PlugPlay, Power, SystemEventsBroker | |
svchost.exe 868 RpcEptMapper, RpcSs | |
svchost.exe 88 NcbService, PcaSvc, TrkWks, UALSVC, wudfsvc | |
svchost.exe 76 Dhcp, EventLog, lmhosts, TimeBrokerSvc | |
svchost.exe 828 BFE, CoreMessagingRegistrar, DPS, MpsSvc | |
svchost.exe 1080 CDPSvc, EventSystem, FontCache, | |
LicenseManager, netprofm, nsi, W32Time, | |
WinHttpAutoProxySvc | |
svchost.exe 1188 CryptSvc, Dnscache, LanmanWorkstation, | |
NlaSvc, WinRM | |
svchost.exe 1268 gpsvc, hns, IKEEXT, iphlpsvc, lfsvc, | |
NetSetupSvc, ProfSvc, Schedule, SENS, | |
ShellHWDetection, Themes, UserManager, | |
Winmgmt, WpnService, wuauserv | |
svchost.exe 1356 Wcmsvc | |
svchost.exe 1768 PolicyAgent | |
svchost.exe 1908 DiagTrack | |
svchost.exe 2012 LanmanServer | |
svchost.exe 2044 StateRepository, tiledatamodelsvc | |
svchost.exe 2744 CDPUserSvc_2c5fc, OneSyncSvc_2c5fc | |
svchost.exe 3112 SSDPSRV | |
svchost.exe 3208 ClipSVC | |
>>>>>> Environment | |
Name Value | |
---- ----- | |
ALLUSERSPROFILE C:\ProgramData | |
APPDATA C:\Users\Administrator\AppData\Roaming | |
AWE_DIR C:\Program Files (x86)\Khrona LLC\Awesomium SDK\1.6.6\ | |
CommonProgramFiles C:\Program Files\Common Files | |
CommonProgramFiles(x86) C:\Program Files (x86)\Common Files | |
CommonProgramW6432 C:\Program Files\Common Files | |
COMPUTERNAME WIN-CDPNLUMSTOE | |
ComSpec C:\Windows\system32\cmd.exe | |
HOMEDRIVE C: | |
HOMEPATH \Users\Administrator | |
LOCALAPPDATA C:\Users\Administrator\AppData\Local | |
LOGONSERVER \\WIN-CDPNLUMSTOE | |
NUMBER_OF_PROCESSORS 4 | |
OS Windows_NT | |
Path C:\Program Files\Docker\Docker\Resources\bin;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Users\Adminis | |
trator\AppData\Local\Microsoft\WindowsApps | |
PATHEXT .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC;.CPL | |
PROCESSOR_ARCHITECTURE AMD64 | |
PROCESSOR_IDENTIFIER Intel64 Family 6 Model 70 Stepping 1, GenuineIntel | |
PROCESSOR_LEVEL 6 | |
PROCESSOR_REVISION 4601 | |
ProgramData C:\ProgramData | |
ProgramFiles C:\Program Files | |
ProgramFiles(x86) C:\Program Files (x86) | |
ProgramW6432 C:\Program Files | |
PSModulePath C:\Users\Administrator\Documents\WindowsPowerShell\Modules;C:\Program Files\WindowsPowerShell\Modules;C:\Windows\system32\WindowsPowerShell\v1.0\Modules | |
PUBLIC C:\Users\Public | |
SystemDrive C: | |
SystemRoot C:\Windows | |
TEMP C:\Users\ADMINI~1\AppData\Local\Temp | |
TMP C:\Users\ADMINI~1\AppData\Local\Temp | |
USERDOMAIN WIN-CDPNLUMSTOE | |
USERDOMAIN_ROAMINGPROFILE WIN-CDPNLUMSTOE | |
USERNAME Administrator | |
USERPROFILE C:\Users\Administrator | |
windir C:\Windows | |
>>>>>> Get-VM Details | |
>>>>>> Get-VM Version | |
>>>>>> Get-VMComPort | |
>>>>>> Get-VMDvdDrive | |
>>>>>> Get-VMIntegrationService | |
>>>>>> Get-VMMemory | |
>>>>>> Get-VMProcessor | |
>>>>>> Get-VMScsiController | |
>>>>>> Get-VMSecurity | |
>>>>>> SystemStartOptions | |
Windows Boot Manager | |
-------------------- | |
identifier {bootmgr} | |
device partition=\Device\HarddiskVolume1 | |
description Windows Boot Manager | |
locale en-US | |
inherit {globalsettings} | |
bootshutdowndisabled Yes | |
default {current} | |
resumeobject {65b59142-9a6d-11e7-8ca8-b81d8bcd4177} | |
displayorder {current} | |
toolsdisplayorder {memdiag} | |
timeout 30 | |
Windows Boot Loader | |
------------------- | |
identifier {current} | |
device partition=C: | |
path \Windows\system32\winload.exe | |
description Windows Server 2016 | |
locale en-US | |
inherit {bootloadersettings} | |
recoverysequence {65b59144-9a6d-11e7-8ca8-b81d8bcd4177} | |
recoveryenabled Yes | |
allowedinmemorysettings 0x15000075 | |
osdevice partition=C: | |
systemroot \Windows | |
resumeobject {65b59142-9a6d-11e7-8ca8-b81d8bcd4177} | |
nx OptOut | |
hypervisorlaunchtype Auto | |
SystemStartOptions : NOEXECUTE=OPTOUT HYPERVISORLAUNCHTYPE=AUTO | |
PSPath : Microsoft.PowerShell.Core\Registry::HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control | |
PSParentPath : Microsoft.PowerShell.Core\Registry::HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet | |
PSChildName : Control | |
PSDrive : HKLM | |
PSProvider : Microsoft.PowerShell.Core\Registry | |
>>>>>> Get-WinEvent SMB | |
ProviderName: Microsoft-Windows-SMBClient | |
TimeCreated Id LevelDisplayName Message | |
----------- -- ---------------- ------- | |
9/25/2017 11:18:26 PM 30810 Information Added a TCP/IP transport interface. | |
Name: vEthernet (Container NIC 6412b757) | |
InterfaceIndex: 0x1D | |
Guidance: | |
A TCP/IP binding was added to the specified network adapter for the SMB client. The SMB client can now send and receive SMB traffic on this | |
network adapter using TCP/IP. You should expect this event when a computer restarts or when a previously disabled network adaptor is | |
re-enabled. No user action is required. | |
9/25/2017 11:18:24 PM 30810 Information Added a TCP/IP transport interface. | |
Name: vEthernet (Container NIC 6412b757) | |
InterfaceIndex: 0x1D | |
Guidance: | |
A TCP/IP binding was added to the specified network adapter for the SMB client. The SMB client can now send and receive SMB traffic on this | |
network adapter using TCP/IP. You should expect this event when a computer restarts or when a previously disabled network adaptor is | |
re-enabled. No user action is required. | |
9/25/2017 11:18:24 PM 30810 Information Added a TCP/IP transport interface. | |
Name: vEthernet (Container NIC 6412b757) | |
InterfaceIndex: 0x1D | |
Guidance: | |
A TCP/IP binding was added to the specified network adapter for the SMB client. The SMB client can now send and receive SMB traffic on this | |
network adapter using TCP/IP. You should expect this event when a computer restarts or when a previously disabled network adaptor is | |
re-enabled. No user action is required. | |
9/25/2017 11:16:02 PM 30810 Information Added a TCP/IP transport interface. | |
Name: isatap.{C420BD56-5715-49BF-9382-5EA99AA48563} | |
InterfaceIndex: 0x6 | |
Guidance: | |
A TCP/IP binding was added to the specified network adapter for the SMB client. The SMB client can now send and receive SMB traffic on this | |
network adapter using TCP/IP. You should expect this event when a computer restarts or when a previously disabled network adaptor is | |
re-enabled. No user action is required. | |
9/25/2017 11:16:02 PM 30810 Information Added a TCP/IP transport interface. | |
Name: isatap.{C420BD56-5715-49BF-9382-5EA99AA48563} | |
InterfaceIndex: 0x6 | |
Guidance: | |
A TCP/IP binding was added to the specified network adapter for the SMB client. The SMB client can now send and receive SMB traffic on this | |
network adapter using TCP/IP. You should expect this event when a computer restarts or when a previously disabled network adaptor is | |
re-enabled. No user action is required. | |
9/25/2017 11:16:02 PM 30810 Information Added a TCP/IP transport interface. | |
Name: isatap.{70EA4F39-FE0F-4040-B718-ACAC00765808} | |
InterfaceIndex: 0x8 | |
Guidance: | |
A TCP/IP binding was added to the specified network adapter for the SMB client. The SMB client can now send and receive SMB traffic on this | |
network adapter using TCP/IP. You should expect this event when a computer restarts or when a previously disabled network adaptor is | |
re-enabled. No user action is required. | |
9/25/2017 11:16:02 PM 30810 Information Added a TCP/IP transport interface. | |
Name: isatap.{70EA4F39-FE0F-4040-B718-ACAC00765808} | |
InterfaceIndex: 0x8 | |
Guidance: | |
A TCP/IP binding was added to the specified network adapter for the SMB client. The SMB client can now send and receive SMB traffic on this | |
network adapter using TCP/IP. You should expect this event when a computer restarts or when a previously disabled network adaptor is | |
re-enabled. No user action is required. | |
9/25/2017 11:16:02 PM 30810 Information Added a TCP/IP transport interface. | |
Name: isatap.attlocal.net | |
InterfaceIndex: 0x5 | |
Guidance: | |
A TCP/IP binding was added to the specified network adapter for the SMB client. The SMB client can now send and receive SMB traffic on this | |
network adapter using TCP/IP. You should expect this event when a computer restarts or when a previously disabled network adaptor is | |
re-enabled. No user action is required. | |
9/25/2017 11:16:02 PM 30810 Information Added a TCP/IP transport interface. | |
Name: isatap.attlocal.net | |
InterfaceIndex: 0x5 | |
Guidance: | |
A TCP/IP binding was added to the specified network adapter for the SMB client. The SMB client can now send and receive SMB traffic on this | |
network adapter using TCP/IP. You should expect this event when a computer restarts or when a previously disabled network adaptor is | |
re-enabled. No user action is required. | |
9/25/2017 11:16:00 PM 30810 Information Added a TCP/IP transport interface. | |
Name: vEthernet (HNS Internal NIC) 3 | |
InterfaceIndex: 0xD | |
Guidance: | |
A TCP/IP binding was added to the specified network adapter for the SMB client. The SMB client can now send and receive SMB traffic on this | |
network adapter using TCP/IP. You should expect this event when a computer restarts or when a previously disabled network adaptor is | |
re-enabled. No user action is required. | |
9/25/2017 11:16:00 PM 30810 Information Added a TCP/IP transport interface. | |
Name: vEthernet (HNS Internal NIC) 2 | |
InterfaceIndex: 0x9 | |
Guidance: | |
A TCP/IP binding was added to the specified network adapter for the SMB client. The SMB client can now send and receive SMB traffic on this | |
network adapter using TCP/IP. You should expect this event when a computer restarts or when a previously disabled network adaptor is | |
re-enabled. No user action is required. | |
9/25/2017 11:16:00 PM 30810 Information Added a TCP/IP transport interface. | |
Name: Ethernet | |
InterfaceIndex: 0x4 | |
Guidance: | |
A TCP/IP binding was added to the specified network adapter for the SMB client. The SMB client can now send and receive SMB traffic on this | |
network adapter using TCP/IP. You should expect this event when a computer restarts or when a previously disabled network adaptor is | |
re-enabled. No user action is required. | |
9/25/2017 11:16:00 PM 30810 Information Added a TCP/IP transport interface. | |
Name: vEthernet (HNS Internal NIC) 3 | |
InterfaceIndex: 0xD | |
Guidance: | |
A TCP/IP binding was added to the specified network adapter for the SMB client. The SMB client can now send and receive SMB traffic on this | |
network adapter using TCP/IP. You should expect this event when a computer restarts or when a previously disabled network adaptor is | |
re-enabled. No user action is required. | |
9/25/2017 11:16:00 PM 30810 Information Added a TCP/IP transport interface. | |
Name: vEthernet (HNS Internal NIC) 2 | |
InterfaceIndex: 0x9 | |
Guidance: | |
A TCP/IP binding was added to the specified network adapter for the SMB client. The SMB client can now send and receive SMB traffic on this | |
network adapter using TCP/IP. You should expect this event when a computer restarts or when a previously disabled network adaptor is | |
re-enabled. No user action is required. | |
9/25/2017 11:16:00 PM 30810 Information Added a TCP/IP transport interface. | |
Name: Ethernet | |
InterfaceIndex: 0x4 | |
Guidance: | |
A TCP/IP binding was added to the specified network adapter for the SMB client. The SMB client can now send and receive SMB traffic on this | |
network adapter using TCP/IP. You should expect this event when a computer restarts or when a previously disabled network adaptor is | |
re-enabled. No user action is required. | |
9/25/2017 11:16:00 PM 30812 Information Added a TDI transport interface. | |
Name: \Device\NetBT_Tcpip_{11D49D60-7969-42DD-BE9E-876FCD3EFA13} | |
Guidance: | |
A TDI (NetBIOS) binding was added to the specified network adapter for the SMB client. The SMB client can now send and receive SMB traffic | |
on this network adapter using TDI. You should expect this event when a computer restarts or when a previously disabled network adaptor is | |
re-enabled. No user action is required. | |
9/25/2017 11:16:00 PM 30812 Information Added a TDI transport interface. | |
Name: \Device\NetBT_Tcpip_{70EA4F39-FE0F-4040-B718-ACAC00765808} | |
Guidance: | |
A TDI (NetBIOS) binding was added to the specified network adapter for the SMB client. The SMB client can now send and receive SMB traffic | |
on this network adapter using TDI. You should expect this event when a computer restarts or when a previously disabled network adaptor is | |
re-enabled. No user action is required. | |
9/25/2017 11:16:00 PM 30812 Information Added a TDI transport interface. | |
Name: \Device\NetBT_Tcpip_{C420BD56-5715-49BF-9382-5EA99AA48563} | |
Guidance: | |
A TDI (NetBIOS) binding was added to the specified network adapter for the SMB client. The SMB client can now send and receive SMB traffic | |
on this network adapter using TDI. You should expect this event when a computer restarts or when a previously disabled network adaptor is | |
re-enabled. No user action is required. | |
9/25/2017 11:14:24 PM 30810 Information Added a TCP/IP transport interface. | |
Name: vEthernet (Container NIC 533cedaa) | |
InterfaceIndex: 0x27 | |
Guidance: | |
A TCP/IP binding was added to the specified network adapter for the SMB client. The SMB client can now send and receive SMB traffic on this | |
network adapter using TCP/IP. You should expect this event when a computer restarts or when a previously disabled network adaptor is | |
re-enabled. No user action is required. | |
9/25/2017 11:14:23 PM 30810 Information Added a TCP/IP transport interface. | |
Name: vEthernet (Container NIC 533cedaa) | |
InterfaceIndex: 0x27 | |
Guidance: | |
A TCP/IP binding was added to the specified network adapter for the SMB client. The SMB client can now send and receive SMB traffic on this | |
network adapter using TCP/IP. You should expect this event when a computer restarts or when a previously disabled network adaptor is | |
re-enabled. No user action is required. | |
ProviderName: Microsoft-Windows-SMBServer | |
TimeCreated Id LevelDisplayName Message | |
----------- -- ---------------- ------- | |
9/25/2017 11:16:10 PM 1012 Information The network name information changed. | |
Change Type: Add | |
Net Name: * | |
IP Address: fe80::10de:923b:b866:221d | |
Flags: 0x1 | |
Interface Index: 4 | |
Capability: 0x0 | |
Link Speed: 1000000000 | |
Guidance: | |
You should expect this event on a Windows Failover Cluster node during failover operations, at system startup, or during network | |
configuration. No user action is required. | |
9/25/2017 11:16:10 PM 1012 Information The network name information changed. | |
Change Type: Add | |
Net Name: * | |
IP Address: 10.0.2.15 | |
Flags: 0x1 | |
Interface Index: 4 | |
Capability: 0x0 | |
Link Speed: 1000000000 | |
Guidance: | |
You should expect this event on a Windows Failover Cluster node during failover operations, at system startup, or during network | |
configuration. No user action is required. | |
9/25/2017 11:16:10 PM 1012 Information The network name information changed. | |
Change Type: Add | |
Net Name: * | |
IP Address: fe80::1de4:bff7:36fb:ee92 | |
Flags: 0x1 | |
Interface Index: 13 | |
Capability: 0x1 | |
Link Speed: 10000000000 | |
Guidance: | |
You should expect this event on a Windows Failover Cluster node during failover operations, at system startup, or during network | |
configuration. No user action is required. | |
9/25/2017 11:16:10 PM 1012 Information The network name information changed. | |
Change Type: Add | |
Net Name: * | |
IP Address: 172.23.128.1 | |
Flags: 0x1 | |
Interface Index: 13 | |
Capability: 0x1 | |
Link Speed: 10000000000 | |
Guidance: | |
You should expect this event on a Windows Failover Cluster node during failover operations, at system startup, or during network | |
configuration. No user action is required. | |
9/25/2017 11:16:10 PM 1012 Information The network name information changed. | |
Change Type: Add | |
Net Name: * | |
IP Address: fe80::5939:52e7:aaf3:5b70 | |
Flags: 0x1 | |
Interface Index: 9 | |
Capability: 0x1 | |
Link Speed: 10000000000 | |
Guidance: | |
You should expect this event on a Windows Failover Cluster node during failover operations, at system startup, or during network | |
configuration. No user action is required. | |
9/25/2017 11:16:10 PM 1012 Information The network name information changed. | |
Change Type: Add | |
Net Name: * | |
IP Address: 172.22.192.1 | |
Flags: 0x1 | |
Interface Index: 9 | |
Capability: 0x1 | |
Link Speed: 10000000000 | |
Guidance: | |
You should expect this event on a Windows Failover Cluster node during failover operations, at system startup, or during network | |
configuration. No user action is required. | |
9/25/2017 11:16:10 PM 1010 Information Endpoint added. | |
Name: WIN-CDPNLUMSTOE | |
Domain Name: WORKGROUP | |
Transport Name: \Device\NetBT_Tcpip_{11D49D60-7969-42DD-BE9E-876FCD3EFA13} | |
Transport Flags: 0x1 | |
Guidance: | |
You should expect this event when the server starts listening on an interface, such as during system restart or when enabling a network | |
adaptor. No user action is required. | |
9/25/2017 11:16:07 PM 1010 Information Endpoint added. | |
Name: WIN-CDPNLUMSTOE | |
Domain Name: WORKGROUP | |
Transport Name: \Device\NetBT_Tcpip_{70EA4F39-FE0F-4040-B718-ACAC00765808} | |
Transport Flags: 0x1 | |
Guidance: | |
You should expect this event when the server starts listening on an interface, such as during system restart or when enabling a network | |
adaptor. No user action is required. | |
9/25/2017 11:16:04 PM 1010 Information Endpoint added. | |
Name: WIN-CDPNLUMSTOE | |
Domain Name: WORKGROUP | |
Transport Name: \Device\NetBT_Tcpip_{C420BD56-5715-49BF-9382-5EA99AA48563} | |
Transport Flags: 0x1 | |
Guidance: | |
You should expect this event when the server starts listening on an interface, such as during system restart or when enabling a network | |
adaptor. No user action is required. | |
9/25/2017 11:16:00 PM 1010 Information Endpoint added. | |
Name: WIN-CDPNLUMSTOE | |
Domain Name: WORKGROUP | |
Transport Name: \Device\NetbiosSmb | |
Transport Flags: 0x1 | |
Guidance: | |
You should expect this event when the server starts listening on an interface, such as during system restart or when enabling a network | |
adaptor. No user action is required. | |
9/25/2017 11:16:00 PM 1025 Warning One or more named pipes or shares have been marked for access by anonymous users. This increases the security risk of the computer by | |
allowing unauthenticated users to connect to this server. | |
Registry Key: HKLM\System\CurrentControlSet\Services\LanmanServer\Parameters | |
Registry Values: NullSessionPipes, NullSessionShares | |
Default Value: Empty (or not present) | |
Current Value: Non-empty | |
Guidance: | |
You should expect this event when modifying the default values of NullSessionShares and NullSessionPipes. On a typical file server, these | |
settings do not exist or do not contain values, which is the most secure configuration. By default, domain controllers populate the | |
NullSessionShares entry with netlogon, samr, and lsarpc to allow legacy access methods. | |
9/25/2017 11:05:01 PM 1010 Information Endpoint added. | |
Name: WIN-CDPNLUMSTOE | |
Domain Name: WORKGROUP | |
Transport Name: \Device\NetBT_Tcpip_{C420BD56-5715-49BF-9382-5EA99AA48563} | |
Transport Flags: 0x1 | |
Guidance: | |
You should expect this event when the server starts listening on an interface, such as during system restart or when enabling a network | |
adaptor. No user action is required. | |
9/25/2017 10:34:36 PM 1010 Information Endpoint added. | |
Name: WIN-CDPNLUMSTOE | |
Domain Name: WORKGROUP | |
Transport Name: \Device\NetBT_Tcpip_{11D49D60-7969-42DD-BE9E-876FCD3EFA13} | |
Transport Flags: 0x1 | |
Guidance: | |
You should expect this event when the server starts listening on an interface, such as during system restart or when enabling a network | |
adaptor. No user action is required. | |
9/25/2017 10:34:25 PM 1011 Information Endpoint removed. | |
Name: | |
Domain Name: | |
Transport Name: \Device\NetBT_Tcpip_{11D49D60-7969-42DD-BE9E-876FCD3EFA13} | |
Guidance: | |
You should expect this event when the server stops listening on an interface, such as during shutdown or when disabling a network adaptor. | |
No user action is required. | |
9/25/2017 10:34:11 PM 1010 Information Endpoint added. | |
Name: WIN-CDPNLUMSTOE | |
Domain Name: WORKGROUP | |
Transport Name: \Device\NetBT_Tcpip_{11D49D60-7969-42DD-BE9E-876FCD3EFA13} | |
Transport Flags: 0x1 | |
Guidance: | |
You should expect this event when the server starts listening on an interface, such as during system restart or when enabling a network | |
adaptor. No user action is required. | |
9/25/2017 8:38:27 PM 1011 Information Endpoint removed. | |
Name: | |
Domain Name: | |
Transport Name: \Device\NetBT_Tcpip_{11D49D60-7969-42DD-BE9E-876FCD3EFA13} | |
Guidance: | |
You should expect this event when the server stops listening on an interface, such as during shutdown or when disabling a network adaptor. | |
No user action is required. | |
9/25/2017 7:39:39 PM 1027 Information The file and printer sharing firewall ports are currently closed. This is the default configuration for a system that is not sharing | |
content or is on a Public network. | |
Guidance: | |
You should expect this event when Windows Firewall is not configured to enable the File and Printer Sharing rule, which allows inbound SMB | |
traffic. This event occurs on a computer that does not have custom shares configured. Clients cannot access SMB shares on this computer | |
until SMB traffic is allowed through the firewall. | |
9/25/2017 7:39:39 PM 1012 Information The network name information changed. | |
Change Type: Add | |
Net Name: * | |
IP Address: fe80::10de:923b:b866:221d | |
Flags: 0x1 | |
Interface Index: 4 | |
Capability: 0x0 | |
Link Speed: 1000000000 | |
Guidance: | |
You should expect this event on a Windows Failover Cluster node during failover operations, at system startup, or during network | |
configuration. No user action is required. | |
9/25/2017 7:39:39 PM 1012 Information The network name information changed. | |
Change Type: Add | |
Net Name: * | |
IP Address: 10.0.2.15 | |
Flags: 0x1 | |
Interface Index: 4 | |
Capability: 0x0 | |
Link Speed: 1000000000 | |
Guidance: | |
You should expect this event on a Windows Failover Cluster node during failover operations, at system startup, or during network | |
configuration. No user action is required. | |
9/25/2017 7:39:39 PM 1012 Information The network name information changed. | |
Change Type: Add | |
Net Name: * | |
IP Address: fe80::5939:52e7:aaf3:5b70 | |
Flags: 0x1 | |
Interface Index: 9 | |
Capability: 0x1 | |
Link Speed: 10000000000 | |
Guidance: | |
You should expect this event on a Windows Failover Cluster node during failover operations, at system startup, or during network | |
configuration. No user action is required. | |
>>>>>> Get-WinEvent Hyper-V | |
ProviderName: Microsoft-Windows-Hyper-V-Compute | |
TimeCreated Id LevelDisplayName Message | |
----------- -- ---------------- ------- | |
9/25/2017 11:16:02 PM 1001 Information The Host Compute Service started successfully. | |
9/25/2017 7:39:33 PM 1001 Information The Host Compute Service started successfully. | |
9/25/2017 1:16:06 PM 1001 Information The Host Compute Service started successfully. | |
9/25/2017 1:07:46 PM 1001 Information The Host Compute Service started successfully. | |
9/20/2017 1:21:33 PM 1001 Information The Host Compute Service started successfully. | |
9/20/2017 1:20:17 PM 1001 Information The Host Compute Service started successfully. | |
9/18/2017 8:31:29 AM 1001 Information The Host Compute Service started successfully. | |
9/16/2017 7:46:25 PM 1001 Information The Host Compute Service started successfully. | |
9/16/2017 5:45:09 PM 1001 Information The Host Compute Service started successfully. | |
9/15/2017 1:51:18 PM 1001 Information The Host Compute Service started successfully. | |
9/15/2017 1:49:44 PM 1001 Information The Host Compute Service started successfully. | |
9/15/2017 1:49:22 PM 1001 Information The Host Compute Service started successfully. | |
ProviderName: Microsoft-Windows-Hyper-V-Compute | |
TimeCreated Id LevelDisplayName Message | |
----------- -- ---------------- ------- | |
9/25/2017 11:22:59 PM 2008 Information [339189e8dd56042e9e4c14c46737695cbb84e2fa1932ce31491dc10800a4236f] Query compute system notification, result 0x00000000, notification 1 / | |
0x00000000 | |
9/25/2017 11:22:59 PM 2009 Information [339189e8dd56042e9e4c14c46737695cbb84e2fa1932ce31491dc10800a4236f] Queue system notification: 1 / 0x00000000 | |
9/25/2017 11:22:59 PM 2002 Information [339189e8dd56042e9e4c14c46737695cbb84e2fa1932ce31491dc10800a4236f] Shut down compute system, result 0xC0370103 | |
9/25/2017 11:22:59 PM 2502 Information [339189e8dd56042e9e4c14c46737695cbb84e2fa1932ce31491dc10800a4236f] Query process notification, process ID 4616, result 0x00000000, | |
notification 65536 / 0x00000000 | |
9/25/2017 11:22:59 PM 2503 Information [339189e8dd56042e9e4c14c46737695cbb84e2fa1932ce31491dc10800a4236f] Queue process notification 65536 / 0x00000000, process ID 4616 | |
9/25/2017 11:18:27 PM 2500 Information [339189e8dd56042e9e4c14c46737695cbb84e2fa1932ce31491dc10800a4236f] Create process, parameters '{"ApplicationName":"","CommandLine":"c:\\wind | |
ows\\system32\\cmd.exe","User":"","WorkingDirectory":"C:\\","Environment":{},"EmulateConsole":true,"CreateStdInPipe":true,"CreateStdOutPipe" | |
:true,"CreateStdErrPipe":false,"ConsoleSize":[59,193]}', result 0x00000000, process ID 4616 | |
9/25/2017 11:18:27 PM 2008 Information [339189e8dd56042e9e4c14c46737695cbb84e2fa1932ce31491dc10800a4236f] Query compute system notification, result 0x00000000, notification 3 / | |
0x00000000 | |
9/25/2017 11:18:27 PM 2001 Information [339189e8dd56042e9e4c14c46737695cbb84e2fa1932ce31491dc10800a4236f] Start compute system, result 0xC0370103 | |
9/25/2017 11:18:27 PM 2009 Information [339189e8dd56042e9e4c14c46737695cbb84e2fa1932ce31491dc10800a4236f] Queue system notification: 3 / 0x00000000 | |
9/25/2017 11:18:24 PM 2008 Information [339189e8dd56042e9e4c14c46737695cbb84e2fa1932ce31491dc10800a4236f] Query compute system notification, result 0x00000000, notification 2 / | |
0x00000000 | |
9/25/2017 11:18:24 PM 2000 Information [339189e8dd56042e9e4c14c46737695cbb84e2fa1932ce31491dc10800a4236f] Create compute system, result 0xC0370103 | |
9/25/2017 11:18:24 PM 2009 Information [339189e8dd56042e9e4c14c46737695cbb84e2fa1932ce31491dc10800a4236f] Queue system notification: 2 / 0x00000000 | |
9/25/2017 11:18:23 PM 2010 Information [339189e8dd56042e9e4c14c46737695cbb84e2fa1932ce31491dc10800a4236f] Create Container, type 'Windows Container', settings '{"SystemType":"Cont | |
ainer","Name":"339189e8dd56042e9e4c14c46737695cbb84e2fa1932ce31491dc10800a4236f","Owner":"docker","IsDummy":false,"VolumePath":"\\\\?\\Volum | |
e{2d8c4158-9c97-11e7-9669-080027515f6a}","IgnoreFlushesDuringBoot":true,"LayerFolderPath":"C:\\ProgramData\\Docker\\windowsfilter\\339189e8d | |
d56042e9e4c14c46737695cbb84e2fa1932ce31491dc10800a4236f","Layers":[{"ID":"9de1d933-f01e-5cb2-a7a9-7c3e0e035106","Path":"C:\\ProgramData\\Doc | |
ker\\windowsfilter\\5f92b7dd505e5f25c0fd526e1ae1dd9c8061fa93481cf32ea0b1da5c42660a2f"},{"ID":"78c70cd7-80e8-5b06-9ade-5dc5e4cf5742","Path":" | |
C:\\ProgramData\\Docker\\windowsfilter\\0acae851dd6fb360107ee6734c9bfcc432a87fb4a8ce74135fdb1adacb27b369"}],"HostName":"339189e8dd56","Mappe | |
dDirectories":[],"HvPartition":false,"EndpointList":["6412b757-61e0-4572-a133-a8f93be703df"],"Servicing":false,"AllowUnqualifiedDNSQuery":tr | |
ue}' | |
9/25/2017 11:16:02 PM 1000 Information The Host Compute Service is starting. | |
9/25/2017 11:14:43 PM 2008 Information [5126f47924905d02ed7e9cacb228a779f806bd24a45fba64910ba8b486763966] Query compute system notification, result 0x00000000, notification 1 / | |
0x00000000 | |
9/25/2017 11:14:43 PM 2009 Information [5126f47924905d02ed7e9cacb228a779f806bd24a45fba64910ba8b486763966] Queue system notification: 1 / 0x00000000 | |
9/25/2017 11:14:43 PM 2002 Information [5126f47924905d02ed7e9cacb228a779f806bd24a45fba64910ba8b486763966] Shut down compute system, result 0xC0370103 | |
9/25/2017 11:14:43 PM 2502 Information [5126f47924905d02ed7e9cacb228a779f806bd24a45fba64910ba8b486763966] Query process notification, process ID 6924, result 0x00000000, | |
notification 65536 / 0x00000000 | |
9/25/2017 11:14:43 PM 2503 Information [5126f47924905d02ed7e9cacb228a779f806bd24a45fba64910ba8b486763966] Queue process notification 65536 / 0x00000000, process ID 6924 | |
9/25/2017 11:14:25 PM 2500 Information [5126f47924905d02ed7e9cacb228a779f806bd24a45fba64910ba8b486763966] Create process, parameters '{"ApplicationName":"","CommandLine":"c:\\wind | |
ows\\system32\\cmd.exe","User":"","WorkingDirectory":"C:\\","Environment":{},"EmulateConsole":true,"CreateStdInPipe":true,"CreateStdOutPipe" | |
:true,"CreateStdErrPipe":false,"ConsoleSize":[56,185]}', result 0x00000000, process ID 6924 | |
ProviderName: Microsoft-Windows-Hyper-V-VMMS | |
TimeCreated Id LevelDisplayName Message | |
----------- -- ---------------- ------- | |
9/25/2017 11:16:03 PM 19020 Information The WMI provider 'VmmsWmiEventProvider' has started. | |
9/25/2017 11:16:02 PM 19020 Information The WMI provider 'VmmsWmiInstanceAndMethodProvider' has started. | |
9/25/2017 11:16:02 PM 14094 Information Virtual Machine Management service is started successfully. | |
9/25/2017 11:16:02 PM 33483 Information Incremental Replication will timeout after 360 hours. Minimum value for timeout is 6 hours. | |
9/25/2017 11:16:02 PM 33834 Information Hyper-V would age out CDP reference points after 720 hours. | |
9/25/2017 11:16:02 PM 33481 Information Change tracking has defined following limits for pending log file size. | |
Error limit : 50% (Minimum value 10%. Maximum value 100%). | |
Warning limit : 40%. | |
Information limit : 30%. | |
9/25/2017 11:16:02 PM 33480 Information Change tracking has defined following limits for free disk space. | |
Free Disk space error limit 3072 MBs (Minimum value can be 1024 MBs). | |
Free Disk space warning limit 4915 MBs. | |
9/25/2017 11:16:02 PM 20410 Information Successfully started the Virtual Machine migration connection manager. | |
9/25/2017 11:16:02 PM 12514 Information Found a certificate for server authentication. Remote access to virtual machines is now possible. | |
9/25/2017 11:16:02 PM 15350 Error The virtualization infrastructure driver (VID) is not running. | |
9/25/2017 11:15:09 PM 19040 Information The WMI provider 'VmmsWmiInstanceAndMethodProvider' has shut down. | |
9/25/2017 11:15:09 PM 19040 Information The WMI provider 'VmmsWmiEventProvider' has shut down. | |
9/25/2017 11:15:09 PM 14100 Warning Shut down physical computer. Stopping/saving all virtual machines... | |
9/25/2017 7:39:34 PM 19020 Information The WMI provider 'VmmsWmiEventProvider' has started. | |
9/25/2017 7:39:34 PM 19020 Information The WMI provider 'VmmsWmiInstanceAndMethodProvider' has started. | |
9/25/2017 7:39:33 PM 14094 Information Virtual Machine Management service is started successfully. | |
9/25/2017 7:39:33 PM 33483 Information Incremental Replication will timeout after 360 hours. Minimum value for timeout is 6 hours. | |
9/25/2017 7:39:33 PM 33834 Information Hyper-V would age out CDP reference points after 720 hours. | |
9/25/2017 7:39:33 PM 33481 Information Change tracking has defined following limits for pending log file size. | |
Error limit : 50% (Minimum value 10%. Maximum value 100%). | |
Warning limit : 40%. | |
Information limit : 30%. | |
9/25/2017 7:39:33 PM 33480 Information Change tracking has defined following limits for free disk space. | |
Free Disk space error limit 3072 MBs (Minimum value can be 1024 MBs). | |
Free Disk space warning limit 4915 MBs. | |
ProviderName: Microsoft-Windows-Hyper-V-VMMS | |
TimeCreated Id LevelDisplayName Message | |
----------- -- ---------------- ------- | |
9/15/2017 1:50:50 PM 26002 Information Switch deleted, name='1CF3DBF4-05D2-4398-AF17-210B2B4C99F2', friendly name='DockerNAT'. | |
9/15/2017 1:50:50 PM 26026 Information Internal miniport deleted, name = '4D7A7800-D578-4D0F-AC7D-373EE0200E6E', friendly name = 'DockerNAT'. | |
9/15/2017 1:50:49 PM 26078 Information Ethernet switch port disconnected (switch name = '1CF3DBF4-05D2-4398-AF17-210B2B4C99F2', port name = | |
'0A252F08-20E9-457E-A8E9-BC64E9805088'). | |
9/15/2017 1:50:44 PM 26074 Information Ethernet switch port connected (switch name = '1CF3DBF4-05D2-4398-AF17-210B2B4C99F2', port name = '0A252F08-20E9-457E-A8E9-BC64E9805088', | |
adapter GUID = '{E89D9F0D-EC20-474C-BC23-D76306DE5CD7}'). | |
9/15/2017 1:50:44 PM 26012 Information Internal miniport created, name = '4D7A7800-D578-4D0F-AC7D-373EE0200E6E', friendly name = 'DockerNAT', MAC = 'DYNAMIC'. | |
9/15/2017 1:50:44 PM 26004 Information Switch port created, switch name = '1CF3DBF4-05D2-4398-AF17-210B2B4C99F2', switch friendly name = 'DockerNAT', port name = | |
'0A252F08-20E9-457E-A8E9-BC64E9805088', port friendly name='DockerNAT'. | |
9/15/2017 1:50:44 PM 26000 Information Switch created, name='1CF3DBF4-05D2-4398-AF17-210B2B4C99F2', friendly name='DockerNAT'. | |
9/15/2017 1:50:43 PM 26002 Information Switch deleted, name='C17CD4E8-DCF8-4D82-B070-040959E4AB0E', friendly name='DockerNAT'. | |
9/15/2017 1:50:43 PM 26026 Information Internal miniport deleted, name = '91B8F22E-9B8E-4AD9-A749-CD4A73DFB088', friendly name = 'DockerNAT'. | |
9/15/2017 1:50:43 PM 26078 Information Ethernet switch port disconnected (switch name = 'C17CD4E8-DCF8-4D82-B070-040959E4AB0E', port name = | |
'4C00EB73-B039-4476-8DC7-3B0BA3154468'). | |
9/15/2017 1:50:30 PM 26074 Information Ethernet switch port connected (switch name = 'C17CD4E8-DCF8-4D82-B070-040959E4AB0E', port name = '4C00EB73-B039-4476-8DC7-3B0BA3154468', | |
adapter GUID = '{7ECA6050-71DC-46C8-8FFF-CD2DCF372FD9}'). | |
9/15/2017 1:50:30 PM 26012 Information Internal miniport created, name = '91B8F22E-9B8E-4AD9-A749-CD4A73DFB088', friendly name = 'DockerNAT', MAC = 'DYNAMIC'. | |
9/15/2017 1:50:29 PM 26004 Information Switch port created, switch name = 'C17CD4E8-DCF8-4D82-B070-040959E4AB0E', switch friendly name = 'DockerNAT', port name = | |
'4C00EB73-B039-4476-8DC7-3B0BA3154468', port friendly name='DockerNAT'. | |
9/15/2017 1:50:29 PM 26000 Information Switch created, name='C17CD4E8-DCF8-4D82-B070-040959E4AB0E', friendly name='DockerNAT'. | |
ProviderName: Microsoft-Windows-Hyper-V-VMMS | |
TimeCreated Id LevelDisplayName Message | |
----------- -- ---------------- ------- | |
9/15/2017 1:50:49 PM 27301 Information The system successfully compacted 'c:\users\public\documents\hyper-v\virtual hard disks\mobylinuxvm.vhdx'. | |
9/15/2017 1:50:48 PM 27300 Information The system is compacting 'c:\users\public\documents\hyper-v\virtual hard disks\mobylinuxvm.vhdx'. | |
9/15/2017 1:50:47 PM 27301 Information The system successfully compacted 'c:\users\public\documents\hyper-v\virtual hard disks\mobylinuxvm.vhdx'. | |
9/15/2017 1:50:46 PM 27300 Information The system is compacting 'c:\users\public\documents\hyper-v\virtual hard disks\mobylinuxvm.vhdx'. | |
9/15/2017 1:50:43 PM 27301 Information The system successfully compacted 'c:\users\public\documents\hyper-v\virtual hard disks\mobylinuxvm.vhdx'. | |
9/15/2017 1:50:42 PM 27300 Information The system is compacting 'c:\users\public\documents\hyper-v\virtual hard disks\mobylinuxvm.vhdx'. | |
9/15/2017 1:50:35 PM 27311 Information The system successfully created 'C:\Users\Public\Documents\Hyper-V\Virtual Hard Disks\MobyLinuxVM.vhdx'. | |
9/15/2017 1:50:34 PM 27310 Information The system is creating 'C:\Users\Public\Documents\Hyper-V\Virtual Hard Disks\MobyLinuxVM.vhdx'. | |
>>>>>> Get-VMSwitch | |
Name : 03f34dae7fc3e40c53c6d804310f5d7c952e0f882b052b486fdfb66e31a44d8e | |
Id : 469cb82f-3ea9-4626-99e4-722de981d389 | |
Notes : | |
Extensions : {Microsoft Windows Filtering Platform, Microsoft Azure VFP Switch Extension, Microsoft NDIS Capture} | |
BandwidthReservationMode : Absolute | |
PacketDirectEnabled : False | |
EmbeddedTeamingEnabled : False | |
IovEnabled : False | |
SwitchType : Internal | |
AllowManagementOS : True | |
NetAdapterInterfaceDescription : | |
NetAdapterInterfaceDescriptions : | |
IovSupport : False | |
IovSupportReasons : | |
AvailableIPSecSA : 0 | |
NumberIPSecSAAllocated : 0 | |
AvailableVMQueues : 0 | |
NumberVmqAllocated : 0 | |
IovQueuePairCount : 0 | |
IovQueuePairsInUse : 0 | |
IovVirtualFunctionCount : 0 | |
IovVirtualFunctionsInUse : 0 | |
PacketDirectInUse : False | |
DefaultQueueVrssEnabledRequested : True | |
DefaultQueueVrssEnabled : False | |
DefaultQueueVmmqEnabledRequested : False | |
DefaultQueueVmmqEnabled : False | |
DefaultQueueVmmqQueuePairsRequested : 16 | |
DefaultQueueVmmqQueuePairs : 0 | |
BandwidthPercentage : 0 | |
DefaultFlowMinimumBandwidthAbsolute : 0 | |
DefaultFlowMinimumBandwidthWeight : 0 | |
CimSession : CimSession: . | |
ComputerName : WIN-CDPNLUMSTOE | |
IsDeleted : False | |
Name : nat | |
Id : e88316aa-73bc-496c-adf9-2bf7784af03b | |
Notes : | |
Extensions : {Microsoft Windows Filtering Platform, Microsoft Azure VFP Switch Extension, Microsoft NDIS Capture} | |
BandwidthReservationMode : Absolute | |
PacketDirectEnabled : False | |
EmbeddedTeamingEnabled : False | |
IovEnabled : False | |
SwitchType : Internal | |
AllowManagementOS : True | |
NetAdapterInterfaceDescription : | |
NetAdapterInterfaceDescriptions : | |
IovSupport : False | |
IovSupportReasons : | |
AvailableIPSecSA : 0 | |
NumberIPSecSAAllocated : 0 | |
AvailableVMQueues : 0 | |
NumberVmqAllocated : 0 | |
IovQueuePairCount : 0 | |
IovQueuePairsInUse : 0 | |
IovVirtualFunctionCount : 0 | |
IovVirtualFunctionsInUse : 0 | |
PacketDirectInUse : False | |
DefaultQueueVrssEnabledRequested : True | |
DefaultQueueVrssEnabled : False | |
DefaultQueueVmmqEnabledRequested : False | |
DefaultQueueVmmqEnabled : False | |
DefaultQueueVmmqQueuePairsRequested : 16 | |
DefaultQueueVmmqQueuePairs : 0 | |
BandwidthPercentage : 0 | |
DefaultFlowMinimumBandwidthAbsolute : 0 | |
DefaultFlowMinimumBandwidthWeight : 0 | |
CimSession : CimSession: . | |
ComputerName : WIN-CDPNLUMSTOE | |
IsDeleted : False | |
>>>>>> Which VM uses DockerNAT? | |
>>>>>> Get-VMNetworkAdapter | |
>>>>>> Get-NetNAT | |
Name : Hcad6d7dc-33f5-4763-92a4-893d6cadaa5b | |
ExternalIPInterfaceAddressPrefix : | |
InternalIPInterfaceAddressPrefix : 172.23.128.0/20 | |
IcmpQueryTimeout : 30 | |
TcpEstablishedConnectionTimeout : 1800 | |
TcpTransientConnectionTimeout : 120 | |
TcpFilteringBehavior : AddressDependentFiltering | |
UdpFilteringBehavior : AddressDependentFiltering | |
UdpIdleSessionTimeout : 120 | |
UdpInboundRefresh : False | |
Store : Local | |
Active : True | |
>>>>>> Get-NetIPAddress | |
IPAddress : fe80::1de4:bff7:36fb:ee92%13 | |
InterfaceIndex : 13 | |
InterfaceAlias : vEthernet (HNS Internal NIC) 3 | |
AddressFamily : IPv6 | |
Type : Unicast | |
PrefixLength : 64 | |
PrefixOrigin : WellKnown | |
SuffixOrigin : Link | |
AddressState : Preferred | |
ValidLifetime : Infinite ([TimeSpan]::MaxValue) | |
PreferredLifetime : Infinite ([TimeSpan]::MaxValue) | |
SkipAsSource : False | |
PolicyStore : ActiveStore | |
IPAddress : fe80::5efe:10.0.2.15%5 | |
InterfaceIndex : 5 | |
InterfaceAlias : isatap.attlocal.net | |
AddressFamily : IPv6 | |
Type : Unicast | |
PrefixLength : 128 | |
PrefixOrigin : WellKnown | |
SuffixOrigin : Link | |
AddressState : Deprecated | |
ValidLifetime : Infinite ([TimeSpan]::MaxValue) | |
PreferredLifetime : Infinite ([TimeSpan]::MaxValue) | |
SkipAsSource : False | |
PolicyStore : ActiveStore | |
IPAddress : fe80::5efe:172.22.192.1%8 | |
InterfaceIndex : 8 | |
InterfaceAlias : isatap.{70EA4F39-FE0F-4040-B718-ACAC00765808} | |
AddressFamily : IPv6 | |
Type : Unicast | |
PrefixLength : 128 | |
PrefixOrigin : WellKnown | |
SuffixOrigin : Link | |
AddressState : Deprecated | |
ValidLifetime : Infinite ([TimeSpan]::MaxValue) | |
PreferredLifetime : Infinite ([TimeSpan]::MaxValue) | |
SkipAsSource : False | |
PolicyStore : ActiveStore | |
IPAddress : fe80::5939:52e7:aaf3:5b70%9 | |
InterfaceIndex : 9 | |
InterfaceAlias : vEthernet (HNS Internal NIC) 2 | |
AddressFamily : IPv6 | |
Type : Unicast | |
PrefixLength : 64 | |
PrefixOrigin : WellKnown | |
SuffixOrigin : Link | |
AddressState : Preferred | |
ValidLifetime : Infinite ([TimeSpan]::MaxValue) | |
PreferredLifetime : Infinite ([TimeSpan]::MaxValue) | |
SkipAsSource : False | |
PolicyStore : ActiveStore | |
IPAddress : fe80::5efe:172.23.128.1%6 | |
InterfaceIndex : 6 | |
InterfaceAlias : isatap.{C420BD56-5715-49BF-9382-5EA99AA48563} | |
AddressFamily : IPv6 | |
Type : Unicast | |
PrefixLength : 128 | |
PrefixOrigin : WellKnown | |
SuffixOrigin : Link | |
AddressState : Deprecated | |
ValidLifetime : Infinite ([TimeSpan]::MaxValue) | |
PreferredLifetime : Infinite ([TimeSpan]::MaxValue) | |
SkipAsSource : False | |
PolicyStore : ActiveStore | |
IPAddress : fe80::10de:923b:b866:221d%4 | |
InterfaceIndex : 4 | |
InterfaceAlias : Ethernet | |
AddressFamily : IPv6 | |
Type : Unicast | |
PrefixLength : 64 | |
PrefixOrigin : WellKnown | |
SuffixOrigin : Link | |
AddressState : Preferred | |
ValidLifetime : Infinite ([TimeSpan]::MaxValue) | |
PreferredLifetime : Infinite ([TimeSpan]::MaxValue) | |
SkipAsSource : False | |
PolicyStore : ActiveStore | |
IPAddress : ::1 | |
InterfaceIndex : 1 | |
InterfaceAlias : Loopback Pseudo-Interface 1 | |
AddressFamily : IPv6 | |
Type : Unicast | |
PrefixLength : 128 | |
PrefixOrigin : WellKnown | |
SuffixOrigin : WellKnown | |
AddressState : Preferred | |
ValidLifetime : Infinite ([TimeSpan]::MaxValue) | |
PreferredLifetime : Infinite ([TimeSpan]::MaxValue) | |
SkipAsSource : False | |
PolicyStore : ActiveStore | |
IPAddress : 172.23.128.1 | |
InterfaceIndex : 13 | |
InterfaceAlias : vEthernet (HNS Internal NIC) 3 | |
AddressFamily : IPv4 | |
Type : Unicast | |
PrefixLength : 20 | |
PrefixOrigin : Manual | |
SuffixOrigin : Manual | |
AddressState : Preferred | |
ValidLifetime : Infinite ([TimeSpan]::MaxValue) | |
PreferredLifetime : Infinite ([TimeSpan]::MaxValue) | |
SkipAsSource : False | |
PolicyStore : ActiveStore | |
IPAddress : 172.22.192.1 | |
InterfaceIndex : 9 | |
InterfaceAlias : vEthernet (HNS Internal NIC) 2 | |
AddressFamily : IPv4 | |
Type : Unicast | |
PrefixLength : 20 | |
PrefixOrigin : Manual | |
SuffixOrigin : Manual | |
AddressState : Preferred | |
ValidLifetime : Infinite ([TimeSpan]::MaxValue) | |
PreferredLifetime : Infinite ([TimeSpan]::MaxValue) | |
SkipAsSource : False | |
PolicyStore : ActiveStore | |
IPAddress : 10.0.2.15 | |
InterfaceIndex : 4 | |
InterfaceAlias : Ethernet | |
AddressFamily : IPv4 | |
Type : Unicast | |
PrefixLength : 24 | |
PrefixOrigin : Dhcp | |
SuffixOrigin : Dhcp | |
AddressState : Preferred | |
ValidLifetime : 23:47:19 | |
PreferredLifetime : 23:47:19 | |
SkipAsSource : False | |
PolicyStore : ActiveStore | |
IPAddress : 127.0.0.1 | |
InterfaceIndex : 1 | |
InterfaceAlias : Loopback Pseudo-Interface 1 | |
AddressFamily : IPv4 | |
Type : Unicast | |
PrefixLength : 8 | |
PrefixOrigin : WellKnown | |
SuffixOrigin : WellKnown | |
AddressState : Preferred | |
ValidLifetime : Infinite ([TimeSpan]::MaxValue) | |
PreferredLifetime : Infinite ([TimeSpan]::MaxValue) | |
SkipAsSource : False | |
PolicyStore : ActiveStore | |
>>>>>> Get-NetIPInterface | |
ifIndex InterfaceAlias AddressFamily NlMtu(Bytes) InterfaceMetric Dhcp ConnectionState PolicyStore | |
------- -------------- ------------- ------------ --------------- ---- --------------- ----------- | |
13 vEthernet (HNS Internal NIC) 3 IPv6 1500 15 Enabled Connected ActiveStore | |
5 isatap.attlocal.net IPv6 1280 75 Disabled Disconnected ActiveStore | |
8 isatap.{70EA4F39-FE0F-4040-B... IPv6 1280 75 Disabled Disconnected ActiveStore | |
9 vEthernet (HNS Internal NIC) 2 IPv6 1500 15 Enabled Connected ActiveStore | |
6 isatap.{C420BD56-5715-49BF-9... IPv6 1280 75 Disabled Disconnected ActiveStore | |
4 Ethernet IPv6 1500 25 Enabled Connected ActiveStore | |
1 Loopback Pseudo-Interface 1 IPv6 4294967295 75 Disabled Connected ActiveStore | |
13 vEthernet (HNS Internal NIC) 3 IPv4 1500 15 Enabled Connected ActiveStore | |
9 vEthernet (HNS Internal NIC) 2 IPv4 1500 15 Enabled Connected ActiveStore | |
4 Ethernet IPv4 1500 25 Enabled Connected ActiveStore | |
1 Loopback Pseudo-Interface 1 IPv4 4294967295 75 Disabled Connected ActiveStore | |
>>>>>> First DNS server | |
Server: UnKnown | |
Address: 10.0.2.2 | |
Name: localhost.attlocal.net | |
Address: 127.0.0.1 | |
>>>>>> Test default DNS server | |
Server: UnKnown | |
Address: 10.0.2.2 | |
Name: www.google.com | |
Addresses: 2607:f8b0:4000:812::2004 | |
172.217.12.36 | |
>>>>>> Query DNS servers | |
PSComputerName : WIN-CDPNLUMSTOE | |
DHCPLeaseExpires : 20170927011558.000000-420 | |
Index : 0 | |
Description : Intel(R) PRO/1000 MT Desktop Adapter | |
DHCPEnabled : True | |
DHCPLeaseObtained : 20170926011558.000000-420 | |
DHCPServer : 10.0.2.2 | |
DNSDomain : attlocal.net | |
DNSDomainSuffixSearchOrder : {attlocal.net} | |
DNSEnabledForWINSResolution : False | |
DNSHostName : WIN-CDPNLUMSTOE | |
DNSServerSearchOrder : {10.0.2.2} | |
DomainDNSRegistrationEnabled : False | |
FullDNSRegistrationEnabled : True | |
IPAddress : {10.0.2.15, fe80::10de:923b:b866:221d} | |
IPConnectionMetric : 25 | |
IPEnabled : True | |
IPFilterSecurityEnabled : False | |
WINSEnableLMHostsLookup : True | |
WINSHostLookupFile : | |
WINSPrimaryServer : | |
WINSScopeID : | |
WINSSecondaryServer : | |
__GENUS : 2 | |
__CLASS : Win32_NetworkAdapterConfiguration | |
__SUPERCLASS : CIM_Setting | |
__DYNASTY : CIM_Setting | |
__RELPATH : Win32_NetworkAdapterConfiguration.Index=0 | |
__PROPERTY_COUNT : 61 | |
__DERIVATION : {CIM_Setting} | |
__SERVER : WIN-CDPNLUMSTOE | |
__NAMESPACE : root\cimv2 | |
__PATH : \\WIN-CDPNLUMSTOE\root\cimv2:Win32_NetworkAdapterConfiguration.Index=0 | |
ArpAlwaysSourceRoute : | |
ArpUseEtherSNAP : | |
Caption : [00000000] Intel(R) PRO/1000 MT Desktop Adapter | |
DatabasePath : %SystemRoot%\System32\drivers\etc | |
DeadGWDetectEnabled : | |
DefaultIPGateway : {10.0.2.2} | |
DefaultTOS : | |
DefaultTTL : | |
ForwardBufferMemory : | |
GatewayCostMetric : {0} | |
IGMPLevel : | |
InterfaceIndex : 4 | |
IPPortSecurityEnabled : | |
IPSecPermitIPProtocols : {} | |
IPSecPermitTCPPorts : {} | |
IPSecPermitUDPPorts : {} | |
IPSubnet : {255.255.255.0, 64} | |
IPUseZeroBroadcast : | |
IPXAddress : | |
IPXEnabled : | |
IPXFrameType : | |
IPXMediaType : | |
IPXNetworkNumber : | |
IPXVirtualNetNumber : | |
KeepAliveInterval : | |
KeepAliveTime : | |
MACAddress : 08:00:27:51:5F:6A | |
MTU : | |
NumForwardPackets : | |
PMTUBHDetectEnabled : | |
PMTUDiscoveryEnabled : | |
ServiceName : E1G60 | |
SettingID : {11D49D60-7969-42DD-BE9E-876FCD3EFA13} | |
TcpipNetbiosOptions : 0 | |
TcpMaxConnectRetransmissions : | |
TcpMaxDataRetransmissions : | |
TcpNumConnections : | |
TcpUseRFC1122UrgentPointer : | |
TcpWindowSize : 64240 | |
Scope : System.Management.ManagementScope | |
Path : \\WIN-CDPNLUMSTOE\root\cimv2:Win32_NetworkAdapterConfiguration.Index=0 | |
Options : System.Management.ObjectGetOptions | |
ClassPath : \\WIN-CDPNLUMSTOE\root\cimv2:Win32_NetworkAdapterConfiguration | |
Properties : {ArpAlwaysSourceRoute, ArpUseEtherSNAP, Caption, DatabasePath...} | |
SystemProperties : {__GENUS, __CLASS, __SUPERCLASS, __DYNASTY...} | |
Qualifiers : {dynamic, Locale, provider, UUID} | |
Site : | |
Container : | |
>>>>>> Internet settings | |
DisableCachingOfSSLPages : 1 | |
IE5_UA_Backup_Flag : 5.0 | |
PrivacyAdvanced : 1 | |
SecureProtocols : 2688 | |
User Agent : Mozilla/4.0 (compatible; MSIE 8.0; Win32) | |
CertificateRevocation : 1 | |
ZonesSecurityUpgrade : {137, 62, 146, 193...} | |
WarnonZoneCrossing : 1 | |
EnableNegotiate : 1 | |
MigrateProxy : 1 | |
ProxyEnable : 0 | |
PSPath : Microsoft.PowerShell.Core\Registry::HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings | |
PSParentPath : Microsoft.PowerShell.Core\Registry::HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion | |
PSChildName : Internet Settings | |
PSDrive : HKCU | |
PSProvider : Microsoft.PowerShell.Core\Registry | |
>>>>>> netstat -abno | |
Active Connections | |
Proto Local Address Foreign Address State PID | |
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING 868 | |
RpcSs | |
[svchost.exe] | |
TCP 0.0.0.0:445 0.0.0.0:0 LISTENING 4 | |
Can not obtain ownership information | |
TCP 0.0.0.0:2179 0.0.0.0:0 LISTENING 2068 | |
[vmms.exe] | |
TCP 0.0.0.0:5985 0.0.0.0:0 LISTENING 4 | |
Can not obtain ownership information | |
TCP 0.0.0.0:47001 0.0.0.0:0 LISTENING 4 | |
Can not obtain ownership information | |
TCP 0.0.0.0:49664 0.0.0.0:0 LISTENING 560 | |
Can not obtain ownership information | |
TCP 0.0.0.0:49665 0.0.0.0:0 LISTENING 76 | |
EventLog | |
[svchost.exe] | |
TCP 0.0.0.0:49666 0.0.0.0:0 LISTENING 1268 | |
Schedule | |
[svchost.exe] | |
TCP 0.0.0.0:49668 0.0.0.0:0 LISTENING 1864 | |
[spoolsv.exe] | |
TCP 0.0.0.0:49689 0.0.0.0:0 LISTENING 1768 | |
PolicyAgent | |
[svchost.exe] | |
TCP 0.0.0.0:49690 0.0.0.0:0 LISTENING 700 | |
Can not obtain ownership information | |
TCP 0.0.0.0:49695 0.0.0.0:0 LISTENING 708 | |
[lsass.exe] | |
TCP 10.0.2.15:139 0.0.0.0:0 LISTENING 4 | |
Can not obtain ownership information | |
TCP 10.0.2.15:49693 131.253.34.232:443 ESTABLISHED 1268 | |
ProfSvc | |
[svchost.exe] | |
TCP 10.0.2.15:49697 65.52.108.194:443 ESTABLISHED 1268 | |
ProfSvc | |
[svchost.exe] | |
TCP 10.0.2.15:49699 40.77.224.255:443 ESTABLISHED 2124 | |
[Explorer.EXE] | |
TCP 10.0.2.15:49717 65.52.108.192:443 ESTABLISHED 2124 | |
[Explorer.EXE] | |
TCP 10.0.2.15:49751 64.4.54.254:443 TIME_WAIT 0 | |
TCP 10.0.2.15:49752 64.4.54.254:443 TIME_WAIT 0 | |
TCP 172.22.192.1:53 0.0.0.0:0 LISTENING 2964 | |
[dockerd.exe] | |
TCP 172.22.192.1:139 0.0.0.0:0 LISTENING 4 | |
Can not obtain ownership information | |
TCP 172.23.128.1:53 0.0.0.0:0 LISTENING 2964 | |
[dockerd.exe] | |
TCP 172.23.128.1:139 0.0.0.0:0 LISTENING 4 | |
Can not obtain ownership information | |
TCP [::]:135 [::]:0 LISTENING 868 | |
RpcSs | |
[svchost.exe] | |
TCP [::]:445 [::]:0 LISTENING 4 | |
Can not obtain ownership information | |
TCP [::]:2179 [::]:0 LISTENING 2068 | |
[vmms.exe] | |
TCP [::]:5985 [::]:0 LISTENING 4 | |
Can not obtain ownership information | |
TCP [::]:47001 [::]:0 LISTENING 4 | |
Can not obtain ownership information | |
TCP [::]:49664 [::]:0 LISTENING 560 | |
Can not obtain ownership information | |
TCP [::]:49665 [::]:0 LISTENING 76 | |
EventLog | |
[svchost.exe] | |
TCP [::]:49666 [::]:0 LISTENING 1268 | |
Schedule | |
[svchost.exe] | |
TCP [::]:49668 [::]:0 LISTENING 1864 | |
[spoolsv.exe] | |
TCP [::]:49689 [::]:0 LISTENING 1768 | |
PolicyAgent | |
[svchost.exe] | |
TCP [::]:49690 [::]:0 LISTENING 700 | |
Can not obtain ownership information | |
TCP [::]:49695 [::]:0 LISTENING 708 | |
[lsass.exe] | |
UDP 0.0.0.0:123 *:* 1080 | |
W32Time | |
[svchost.exe] | |
UDP 0.0.0.0:500 *:* 1268 | |
IKEEXT | |
[svchost.exe] | |
UDP 0.0.0.0:4500 *:* 1268 | |
IKEEXT | |
[svchost.exe] | |
UDP 0.0.0.0:5050 *:* 1080 | |
CDPSvc | |
[svchost.exe] | |
UDP 0.0.0.0:5353 *:* 1188 | |
Dnscache | |
[svchost.exe] | |
UDP 0.0.0.0:5355 *:* 1188 | |
Dnscache | |
[svchost.exe] | |
UDP 10.0.2.15:137 *:* 4 | |
Can not obtain ownership information | |
UDP 10.0.2.15:138 *:* 4 | |
Can not obtain ownership information | |
UDP 10.0.2.15:1900 *:* 3112 | |
SSDPSRV | |
[svchost.exe] | |
UDP 10.0.2.15:59827 *:* 3112 | |
SSDPSRV | |
[svchost.exe] | |
UDP 127.0.0.1:1900 *:* 3112 | |
SSDPSRV | |
[svchost.exe] | |
UDP 127.0.0.1:59828 *:* 3112 | |
SSDPSRV | |
[svchost.exe] | |
UDP 172.22.192.1:53 *:* 2964 | |
[dockerd.exe] | |
UDP 172.22.192.1:137 *:* 4 | |
Can not obtain ownership information | |
UDP 172.22.192.1:138 *:* 4 | |
Can not obtain ownership information | |
UDP 172.22.192.1:1900 *:* 3112 | |
SSDPSRV | |
[svchost.exe] | |
UDP 172.22.192.1:59825 *:* 3112 | |
SSDPSRV | |
[svchost.exe] | |
UDP 172.23.128.1:53 *:* 2964 | |
[dockerd.exe] | |
UDP 172.23.128.1:137 *:* 4 | |
Can not obtain ownership information | |
UDP 172.23.128.1:138 *:* 4 | |
Can not obtain ownership information | |
UDP 172.23.128.1:1900 *:* 3112 | |
SSDPSRV | |
[svchost.exe] | |
UDP 172.23.128.1:59826 *:* 3112 | |
SSDPSRV | |
[svchost.exe] | |
UDP [::]:123 *:* 1080 | |
W32Time | |
[svchost.exe] | |
UDP [::]:500 *:* 1268 | |
IKEEXT | |
[svchost.exe] | |
UDP [::]:4500 *:* 1268 | |
IKEEXT | |
[svchost.exe] | |
UDP [::]:5353 *:* 1188 | |
Dnscache | |
[svchost.exe] | |
UDP [::]:5355 *:* 1188 | |
Dnscache | |
[svchost.exe] | |
UDP [::1]:1900 *:* 3112 | |
SSDPSRV | |
[svchost.exe] | |
UDP [::1]:59824 *:* 3112 | |
SSDPSRV | |
[svchost.exe] | |
UDP [fe80::10de:923b:b866:221d%4]:1900 *:* 3112 | |
SSDPSRV | |
[svchost.exe] | |
UDP [fe80::10de:923b:b866:221d%4]:59823 *:* 3112 | |
SSDPSRV | |
[svchost.exe] | |
UDP [fe80::1de4:bff7:36fb:ee92%13]:1900 *:* 3112 | |
SSDPSRV | |
[svchost.exe] | |
UDP [fe80::1de4:bff7:36fb:ee92%13]:59822 *:* 3112 | |
SSDPSRV | |
[svchost.exe] | |
UDP [fe80::5939:52e7:aaf3:5b70%9]:1900 *:* 3112 | |
SSDPSRV | |
[svchost.exe] | |
UDP [fe80::5939:52e7:aaf3:5b70%9]:59821 *:* 3112 | |
SSDPSRV | |
[svchost.exe] | |
>>>>>> netstat -rs | |
IPv4 Statistics | |
Packets Received = 1998 | |
Received Header Errors = 0 | |
Received Address Errors = 63 | |
Datagrams Forwarded = 0 | |
Unknown Protocols Received = 0 | |
Received Packets Discarded = 78 | |
Received Packets Delivered = 2708 | |
Output Requests = 1319 | |
Routing Discards = 0 | |
Discarded Output Packets = 0 | |
Output Packet No Route = 0 | |
Reassembly Required = 0 | |
Reassembly Successful = 0 | |
Reassembly Failures = 0 | |
Datagrams Successfully Fragmented = 0 | |
Datagrams Failing Fragmentation = 0 | |
Fragments Created = 0 | |
IPv6 Statistics | |
Packets Received = 18 | |
Received Header Errors = 0 | |
Received Address Errors = 15 | |
Datagrams Forwarded = 0 | |
Unknown Protocols Received = 0 | |
Received Packets Discarded = 70 | |
Received Packets Delivered = 3 | |
Output Requests = 192 | |
Routing Discards = 0 | |
Discarded Output Packets = 0 | |
Output Packet No Route = 6 | |
Reassembly Required = 0 | |
Reassembly Successful = 0 | |
Reassembly Failures = 0 | |
Datagrams Successfully Fragmented = 0 | |
Datagrams Failing Fragmentation = 0 | |
Fragments Created = 0 | |
ICMPv4 Statistics | |
Received Sent | |
Messages 0 4 | |
Errors 0 0 | |
Destination Unreachable 0 0 | |
Time Exceeded 0 0 | |
Parameter Problems 0 0 | |
Source Quenches 0 0 | |
Redirects 0 0 | |
Echo Replies 0 0 | |
Echos 0 4 | |
Timestamps 0 0 | |
Timestamp Replies 0 0 | |
Address Masks 0 0 | |
Address Mask Replies 0 0 | |
Router Solicitations 0 0 | |
Router Advertisements 0 0 | |
ICMPv6 Statistics | |
Received Sent | |
Messages 1 20 | |
Errors 0 0 | |
Destination Unreachable 0 0 | |
Packet Too Big 0 0 | |
Time Exceeded 0 0 | |
Parameter Problems 0 0 | |
Echos 0 0 | |
Echo Replies 0 0 | |
MLD Queries 0 0 | |
MLD Reports 0 0 | |
MLD Dones 0 0 | |
Router Solicitations 0 12 | |
Router Advertisements 0 0 | |
Neighbor Solicitations 0 4 | |
Neighbor Advertisements 1 4 | |
Redirects 0 0 | |
Router Renumberings 0 0 | |
TCP Statistics for IPv4 | |
Active Opens = 42 | |
Passive Opens = 0 | |
Failed Connection Attempts = 0 | |
Reset Connections = 4 | |
Current Connections = 4 | |
Segments Received = 1826 | |
Segments Sent = 888 | |
Segments Retransmitted = 0 | |
TCP Statistics for IPv6 | |
Active Opens = 2 | |
Passive Opens = 2 | |
Failed Connection Attempts = 0 | |
Reset Connections = 0 | |
Current Connections = 0 | |
Segments Received = 63 | |
Segments Sent = 63 | |
Segments Retransmitted = 0 | |
UDP Statistics for IPv4 | |
Datagrams Received = 296 | |
No Ports = 190 | |
Receive Errors = 0 | |
Datagrams Sent = 491 | |
UDP Statistics for IPv6 | |
Datagrams Received = 2 | |
No Ports = 70 | |
Receive Errors = 0 | |
Datagrams Sent = 105 | |
=========================================================================== | |
Interface List | |
9...00 15 5d 80 e5 17 ......Hyper-V Virtual Ethernet Adapter #2 | |
13...00 15 5d b6 45 8d ......Hyper-V Virtual Ethernet Adapter #3 | |
4...08 00 27 51 5f 6a ......Intel(R) PRO/1000 MT Desktop Adapter | |
1...........................Software Loopback Interface 1 | |
6...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #5 | |
8...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #6 | |
5...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #7 | |
=========================================================================== | |
IPv4 Route Table | |
=========================================================================== | |
Active Routes: | |
Network Destination Netmask Gateway Interface Metric | |
0.0.0.0 0.0.0.0 10.0.2.2 10.0.2.15 25 | |
10.0.2.0 255.255.255.0 On-link 10.0.2.15 281 | |
10.0.2.15 255.255.255.255 On-link 10.0.2.15 281 | |
10.0.2.255 255.255.255.255 On-link 10.0.2.15 281 | |
127.0.0.0 255.0.0.0 On-link 127.0.0.1 331 | |
127.0.0.1 255.255.255.255 On-link 127.0.0.1 331 | |
127.255.255.255 255.255.255.255 On-link 127.0.0.1 331 | |
172.22.192.0 255.255.240.0 On-link 172.22.192.1 271 | |
172.22.192.1 255.255.255.255 On-link 172.22.192.1 271 | |
172.22.207.255 255.255.255.255 On-link 172.22.192.1 271 | |
172.23.128.0 255.255.240.0 On-link 172.23.128.1 271 | |
172.23.128.1 255.255.255.255 On-link 172.23.128.1 271 | |
172.23.143.255 255.255.255.255 On-link 172.23.128.1 271 | |
224.0.0.0 240.0.0.0 On-link 127.0.0.1 331 | |
224.0.0.0 240.0.0.0 On-link 10.0.2.15 281 | |
224.0.0.0 240.0.0.0 On-link 172.23.128.1 271 | |
224.0.0.0 240.0.0.0 On-link 172.22.192.1 271 | |
255.255.255.255 255.255.255.255 On-link 127.0.0.1 331 | |
255.255.255.255 255.255.255.255 On-link 10.0.2.15 281 | |
255.255.255.255 255.255.255.255 On-link 172.23.128.1 271 | |
255.255.255.255 255.255.255.255 On-link 172.22.192.1 271 | |
=========================================================================== | |
Persistent Routes: | |
None | |
IPv6 Route Table | |
=========================================================================== | |
Active Routes: | |
If Metric Network Destination Gateway | |
1 331 ::1/128 On-link | |
4 281 fe80::/64 On-link | |
13 271 fe80::/64 On-link | |
9 271 fe80::/64 On-link | |
4 281 fe80::10de:923b:b866:221d/128 | |
On-link | |
13 271 fe80::1de4:bff7:36fb:ee92/128 | |
On-link | |
9 271 fe80::5939:52e7:aaf3:5b70/128 | |
On-link | |
1 331 ff00::/8 On-link | |
4 281 ff00::/8 On-link | |
13 271 ff00::/8 On-link | |
9 271 ff00::/8 On-link | |
=========================================================================== | |
Persistent Routes: | |
None | |
>>>>>> net share | |
New connections will be remembered. | |
There are no entries in the list. | |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment