Services on 192.168.111.2


User mode services:




Service name    :Alerter
Display Name    :Alerter
Binary Path     :C:\WINNT\System32\services.exe
Service is running in the security context of LocalSystem

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :Browser Display Name :Computer Browser Binary Path :C:\WINNT\System32\services.exe Service is running in the security context of LocalSystem The Computer Browser contains a denial of service attack where many spoofed
entries can be added. There are many occasions when the browse list is requested
from the maintainer or backup browser eg. when a user opens up their "Network
Neighbourhood" or when the Server Manger is opended and the whole list is sent
across the network. If enough entries are added to the browse list then it can grow
to hundreds of megabytes causing machines to hang and utilise available bandwidth
on the network cable. If this poses a risk on your network then this service should
be disabled.

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :EventLog Display Name :EventLog Binary Path :C:\WINNT\system32\services.exe Service is running in the security context of LocalSystem

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :LanmanServer Display Name :Server
Service name :LanmanWorkstation Display Name :Workstation
Service name :LicenseService Display Name :License Logging Service
Service name :LmHosts Display Name :TCP/IP NetBIOS Helper
Service name :Messenger Display Name :Messenger The Messenger service allows a user to send a message across the network that
will pop up on the target's computer screen. This can be abused in social
engineering attacks eg. one user trying to get another to change their password. Added
to this the name of user currently logged on to the system is registered in the
NetBIOS name table which can be retrieved remotely by issuing an nbtstat -A x.x.x.x
command. If this presents too much of a risk the Messenger service should be disabled.
Service name :MSFTPSVC Display Name :FTP Publishing Service
Service name :MSSQLServer Display Name :MSSQLServer The MSSQLServer service is the SQL Service. There are a number of issues with
this service that can often lead to a server compromise. Ensure that only trusted
users may access this machine.
Service name :NAV Alert Display Name :NAV Alert
Service name :NAV Auto-Protect Display Name :NAV Auto-Protect
Service name :NobleNet Portmapper Display Name :NobleNet Portmapper
Service name :Norton Program Scheduler Display Name :Norton Program Scheduler
Service name :NtLmSsp Display Name :NT LM Security Support Provider
Service name :PlugPlay Display Name :Plug and Play
Service name :ProtectedStorage Display Name :Protected Storage
Service name :RpcSs Display Name :Remote Procedure Call (RPC) Service
Service name :Schedule Display Name :Task Scheduler
Service name :Spooler Display Name :Spooler

Driver services:




Service name    :4mmdat
Display Name    :4mmdat
Binary Path: System32\DRIVERS\4mmdat.sys


Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :Afd Display Name :AFD Networking Support Environment Binary Path: \SystemRoot\System32\drivers\afd.sys

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :aic78xx Display Name :aic78xx Binary Path: \SystemRoot\System32\DRIVERS\aic78xx.sys

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :ati Display Name :ati Binary Path:

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :Beep Display Name :Beep Binary Path:

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :Cdaudio Display Name :Cdaudio Binary Path:

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :Cdrom Display Name :Cdrom Binary Path:

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :Disk Display Name :Disk Binary Path:

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :DLC Display Name :DLC Protocol Binary Path: \SystemRoot\System32\drivers\dlc.sys

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :Floppy Display Name :Floppy Binary Path:

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :i8042prt Display Name :i8042 Keyboard and PS/2 Mouse Port Driver Binary Path: System32\DRIVERS\i8042prt.sys

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :Kbdclass Display Name :Keyboard Class Driver Binary Path: System32\DRIVERS\kbdclass.sys

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :KSecDD Display Name :KSecDD Binary Path:

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :Mouclass Display Name :Mouse Class Driver Binary Path: System32\DRIVERS\mouclass.sys

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :Msfs Display Name :Msfs Binary Path:

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :NAVAP Display Name :NAVAP Binary Path: \??\C:\WINNT\System32\Drivers\navap.sys

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :NAVENG Display Name :NAVENG Binary Path: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20000817.018\NAVENG.Sys

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :NAVEX15 Display Name :NAVEX15 Binary Path: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20000817.018\NavEx15.Sys

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :NDIS Display Name :Microsoft NDIS System Driver Binary Path:

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :NE2000 Display Name :Novell NE2000 Adapter Driver Binary Path: \SystemRoot\System32\drivers\ne2000.sys

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :NetBIOS Display Name :NetBIOS Interface Binary Path: \SystemRoot\System32\drivers\netbios.sys

Group/User: NT AUTHORITY\INTERACTIVE
has permission to query this service's status
has permission to start this service
has permission to interrogate this service

Group/User: BUILTIN\Users
has permission to query this service's status
has permission to start this service
has permission to interrogate this service


Service name :NetBT Display Name :WINS Client(TCP/IP) Binary Path: \SystemRoot\System32\drivers\netbt.sys

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :Npfs Display Name :Npfs Binary Path:

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :ntbpf Display Name :ntbpf Binary Path: \??\C:\Program Files\Network Associates\CyberCop Scanner\Driver\ntbpf.sys

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :Null Display Name :Null Binary Path:

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :Parallel Display Name :Parallel Binary Path:

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :Parport Display Name :Parport Binary Path:

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :ParVdm Display Name :ParVdm Binary Path:

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :Serial Display Name :Serial Binary Path:

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :SymEvent Display Name :SymEvent Binary Path: \??\C:\WINNT\System32\Drivers\symevent.sys

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :Tcpip Display Name :TCP/IP Service Binary Path: \SystemRoot\System32\drivers\tcpip.sys

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


Service name :VgaSave Display Name :VgaSave Binary Path: \SystemRoot\System32\drivers\vga.sys

Group/User: \Everyone
has permission to query this service's status
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service

Group/User: BUILTIN\Power Users
has permission to query this service's status
has permission to start this service
has permission to stop this service
has permission to interrogate this service
has USER_DEFINED_CONTROL for this service


There are 20 user mode services running and 32 driver services running. Total = 52