|
|
| Current User |
| User Account | Auditor |
| Display Name | John W Dunn |
| Distinguished Name | CN=Auditor,CN=Users,DC=TestIps,DC=com |
| SID | S-1-5-21-4279025473-3018771506-1539134433-1105 |
| GUID | f9e4368b-54ee-45b6-8c2b-9dc9e8568c1e |
| Primary Group Id | 513 (Domain Users) |
| User Domain (NetBios) | TESTIPS |
| User Domain (DNS) | TestIps.com |
| Full Name | John Dunn |
| User Principal Name (UPN) | Auditor@TestIps.com |
| Email Address | Auditor@TestIps.com |
| Account Created | 2010-03-13 18:51:38 GMT |
| Password Last Changed | 2010-12-30 19:51:27 |
| Last Logon | 2011-01-02 05:47:51 (not replicated) |
| Last Failed Logon | 2010-12-30 19:50:57 (not replicated) |
| Account Expiration Date | Never |
| Object Protected From Deletion | No |
| Password Expired | No |
| User Can Change Password | Yes |
| Password Required | Yes |
| Home Directory Drive | D: |
| Home Directory Path | D:\users\Auditor |
| Profile Path | C:\users\Auditor |
| Logon Script Path | \\starlight\C\logons |
| Logon Count | 545 (not replicated) |
| User Account Control Value | x200 (512) |
| User Logon Server | SERVER2008 |
| Current User: Regional and Language Options [Top] |
| Current Format | English (South Africa) |
| Time Format | 14:18:09 |
| Short Date | 22-Jan-2011 |
| Long Date | 22 January 2011 |
| Short Date Format | dd-MMM-yyyy |
| Long Date Format | dd MMMM yyyy |
| Currency Symbol | R |
| Currency (International) | ZAR |
| System Locale | English (South Africa) |
| Client System: Description [Top] |
| Role | Workstation |
| NetBios Name | VISTAVANILLA |
| DNS Name | VistaVanilla.TestIps.com |
| Distinguished Name | CN=VISTAVANILLA,CN=Computers,DC=TestIps,DC=com |
| SID | S-1-5-21-4279025473-3018771506-1539134433-1106 |
| GUID | afd535a8-8d86-4827-b444-f015840616b9 |
| Domain Name (NetBios) | TESTIPS |
| Domain Name (DNS) | TestIps.com |
| Forest Name | TestIps.com |
| Site Name | Default-First-Site-Name |
| IP Address | 133.168.1.50 |
| Client System: Password, Account Lockout, Audit Policies [Top] |
| Password Policy | |
| Enforce Password History | 13 passwords remembered |
| Maximum Password Age | 42 days |
| Minimum Password Age | 0 days |
| Minimum Password Length | 6 characters |
| Password Complexity Requirements | Enabled |
| Passwords - Reversible Encryption | Disabled |
| Account Lockout Policy | |
| Account Lockout Duration |
90 minutes |
| Account Lockout Threshold | 7 invalid logon attempts |
| Reset Account Lockout Counter After | 10 minutes |
| Audit Policy | |
| Audit Account Logon Events | None |
| Audit Account Management | None |
| Audit Directory Service Access | Success |
| Audit Logon Events | None |
| Audit Object Access | None |
| Audit Policy Change | Success & Failure |
| Audit Privilege Use | Success & Failure |
| Audit Process Tracking | None |
| Audit System Events | Failure |
| Screen Saver | |
| Screen Saver Status | Enabled, secure |
| Screen Saver File | C:\Windows\system32\logon.scr |
| Screen Saver Wait Period | 540 seconds |
| Desktop Background | C:\Users\Public\Pictures\Sample Pictures\Toco Toucan.jpg |
| Client System: Event Logs [Top] |
| Log Name | Application |
| Created | 25-Feb-2010 10:19:18 |
| Log File | c:\windows\system32\winevt\logs\application.evtx |
| Maximum Log Size | 20,480 KB |
| Current Log Size | 7,475,200 bytes |
| Number of Records | 14,197 |
| When Event Log is Full | Overwrite events as needed (oldest events first) |
| Log Name | DFS Replication |
| Created | 25-Feb-2010 10:19:19 |
| Log File | c:\windows\system32\winevt\logs\dfs replication.evtx |
| Maximum Log Size | 15,168 KB |
| Current Log Size | 69,632 bytes |
| Number of Records | 6 |
| When Event Log is Full | Overwrite events as needed (oldest events first) |
| Log Name | Hardware Events |
| Created | 25-Feb-2010 10:19:19 |
| Log File | c:\windows\system32\winevt\logs\hardwareevents.evtx |
| Maximum Log Size | 20,480 KB |
| Current Log Size | 69,632 bytes |
| Number of Records | 0 |
| When Event Log is Full | Overwrite events as needed (oldest events first) |
| Log Name | Internet Explorer |
| Created | 25-Feb-2010 10:19:19 |
| Log File | c:\windows\system32\winevt\logs\internet explorer.evtx |
| Maximum Log Size | 1,028 KB |
| Current Log Size | 69,632 bytes |
| Number of Records | 0 |
| When Event Log is Full | Overwrite events as needed (oldest events first) |
| Log Name | Key Management Service |
| Created | 25-Feb-2010 10:19:18 |
| Log File | c:\windows\system32\winevt\logs\key management service.evtx |
| Maximum Log Size | 20,480 KB |
| Current Log Size | 69,632 bytes |
| Number of Records | 0 |
| When Event Log is Full | Overwrite events as needed (oldest events first) |
| Log Name | MS Office Diagnostics |
| Created | 25-Feb-2010 13:08:45 |
| Log File | c:\windows\system32\winevt\logs\odiag.evtx |
| Maximum Log Size | 16,384 KB |
| Current Log Size | 69,632 bytes |
| Number of Records | 36 |
| When Event Log is Full | Overwrite events as needed (oldest events first) |
| Log Name | MS Office Sessions |
| Created | 25-Feb-2010 13:08:45 |
| Log File | c:\windows\system32\winevt\logs\osession.evtx |
| Maximum Log Size | 16,384 KB |
| Current Log Size | 7,409,664 bytes |
| Number of Records | 21,238 |
| When Event Log is Full | Overwrite events as needed (oldest events first) |
| Log Name | Security |
| Created | 25-Feb-2010 10:19:18 |
| Log File | c:\windows\system32\winevt\logs\security.evtx |
| Maximum Log Size | 20,480 KB |
| Current Log Size | 20,975,616 bytes |
| Number of Records | 19,077 |
| When Event Log is Full | Overwrite events as needed (oldest events first) |
| Log Name | System |
| Created | 25-Feb-2010 10:19:18 |
| Log File | c:\windows\system32\winevt\logs\system.evtx |
| Maximum Log Size | 20,480 KB |
| Current Log Size | 20,975,616 bytes |
| Number of Records | 45,015 |
| When Event Log is Full | Overwrite events as needed (oldest events first) |
| Log Name | Windows PowerShell |
| Created | 10-Mar-2010 12:05:59 |
| Log File | c:\windows\system32\winevt\logs\windows powershell.evtx |
| Maximum Log Size | 15,360 KB |
| Current Log Size | 69,632 bytes |
| Number of Records | 0 |
| When Event Log is Full | Overwrite events as needed (oldest events first) |
| See also: SekChek’s Query Event Log Tool |
| Client System: Windows Security Centre (WSC) [Top] |
| WSC Status | OK |
| Windows Update Status | OK |
| - Important updates | Install updates automatically (recommended) |
| - Install new updates | Every day at 03:00 |
| - Recommended updates | No |
| - Allow all users to install | No |
| - Microsoft updates | Yes |
| - Configuration enforced | No |
| - Updates were installed | 31-Dec-2010 09:07:37 GMT |
| - Most recent check for updates | 02-Jan-2011 09:10:49 GMT |
| Firewall Status | OK |
| AntiVirus Status | Not monitored |
| AntiSpyware Status | OK |
| User Account Control Status | OK |
| Internet Settings | OK |
| Client System: Windows Firewall [Top] |
| Domain Profile | |
| Firewall State | On (recommended) |
| Inbound Connections |
Block, allow exceptions (default) |
| Outbound Connections | Allow (default) |
| Display Notifications |
Yes (default) |
| Allow Unicast Response | Yes (default) |
| Log File | C:\Windows\system32\LogFiles\Firewall\pfirewall.log |
| Log Size Limit (KB) | 4,096 |
| Log Dropped Packets | No (default) |
| Log Successful Connections | No (default) |
| Private Profile | |
| Firewall State | On (recommended) |
| Inbound Connections |
Block, allow exceptions (default) |
| Outbound Connections | Allow (default) |
| Display Notifications |
Yes (default) |
| Allow Unicast Response | Yes (default) |
| Log File | C:\Windows\system32\LogFiles\Firewall\pfirewall.log |
| Log Size Limit (KB) | 4,096 |
| Log Dropped Packets | No (default) |
| Log Successful Connections | No (default) |
| Public Profile | |
| Firewall State | On (recommended) |
| Inbound Connections | Block, allow exceptions (default) |
| Outbound Connections | Allow (default) |
| Display Notifications | Yes (default) |
| Allow Unicast Response | Yes (default) |
| Log File | C:\Windows\system32\LogFiles\Firewall\pfirewall.log |
| Log Size Limit (KB) | 4,096 |
| Log Dropped Packets | No (default) |
| Log Successful Connections | No (default) |
| See also: SekChek’s Windows Firewall Audit Tool |
| Client System: Operating System [Top] |
| OS Name | Microsoft® Windows Vista™ Enterprise |
| OS Architecture | 32-bit |
| OS Version | 6.0.6002 |
| OS Service Pack | Service Pack 2 |
| OS Install Language | English - United States |
| System Locale | English - South Africa |
| Registered User | Auditor |
| Registered Organisation | My Organisation |
| OS Serial Number | 11111-037-8567835-77777 |
| Country Code | 27 |
| System Times | |
| Time Zone | GMT +02:00 |
| Local Time | 22-Jan-2011 14:52:58 |
| OS Installed | 25-Feb-2010 10:21:36 |
| Last BootUp Time | 12-Jan-2011 03:23:23 |
| System Paths | |
| System Drive | C: |
| Windows Directory | C:\Windows |
| System Directory | C:\Windows\system32 |
| Memory | |
| Total Physical Memory | 1.171 GB |
| Free Physical Memory | 0.398 GB (33.95%) |
| Physical Memory: % Used |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||| (72.46%) |
| Total Virtual Memory | 2.595 GB |
| Free Virtual Memory | 1.201 GB (46.27%) |
| Virtual Memory: % Used |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||| (53.73%) |
| OS Recovery Configuration | |
| Write Event To System Log | Yes |
| Send Administrative Alert | No |
| Automatically Restart | Yes |
| Write Debugging Information | Kernel memory dump |
| Dump File | %SystemRoot%\MEMORY.DMP |
| Overwrite Existing File | Yes |
| Client System: Computer [Top] |
| Manufacturer | Microsoft Corporation |
| Model | Virtual Machine |
| System Type | X86-based PC |
| BIOS | American Megatrends Inc. 080002 , 2006-02-22 |
| Bus Clock Speed (MHz) | 100 |
| Processors | |
| Enabled Processors | 1 |
| Processor | Intel(R) Core(TM)2 Quad CPU Q8400 @ 2.66GHz |
| Processor Family | Pentium® III |
| Processor Address Width (bits) | 32 |
| Processor Data Width (bits) | 32 |
| Printers | |
| Printer 1 (port) | Send To OneNote 2007 (Send To Microsoft OneNote Port:) |
| Printer 2 (port) | Microsoft XPS Document Writer (XPSPort:) |
| Printer 3 (port) | \\jackal\HP LaserJet 3300 Series PCL 5 (DOT4_001) **default** |
| Monitor, Keyboard, Mouse | |
| Screen Colour Depth | 32 bits per pixel |
| Screen Refresh Rate | 75 Hz |
| Display Resolution | 1280 by 1024 pixels |
| Keyboard | Standard PS/2 Keyboard |
| Mouse | Microsoft PS/2 Mouse |
| Client System: Disk Drives [Top] |
| Drive | A: |
| Drive Type | Removable Disk |
| Volume Serial Number | Not mounted / not available |
| | |
| Drive | C: |
| Drive Type | Local Disk |
| Volume Serial Number | 1015-03AB |
| File System | NTFS |
| Capacity | 63.474 GB |
| Free Space |
14.779 GB (23.28%) |
| Disk Space: % Used |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||| (76.72%) |
| | |
| Drive | D: |
| Drive Type | Compact Disc |
| Volume Serial Number | Not mounted / not available |
| | |
| Drive | Z: |
| Drive Type | Network Drive |
| Volume Serial Number | Not mounted / not available |
| | |
| Client System: Network Adapter (IP-Enabled) [Top] |
| Network Connection Name | Local Area Connection |
| Connection Status | Connected |
| Network Connection Description | Intel 21140-Based PCI Fast Ethernet Adapter (Emulated) |
| Adapter Type | Ethernet 802.3 |
| Addresses | |
| IP Address | 133.168.1.50, fe80::9cae:581a:677f:718d |
| IP Subnet | 255.255.255.0, 64 |
| Default IP Gateway | 192.168.1.254 |
| Physical Address | 00:03:FF:19:25:01 |
| DHCP, DNS | |
| DHCP Enabled | No |
| DHCP Lease Obtained | |
| DHCP Lease Expires | |
| DHCP Server | |
| DNS Server Search Order | 133.168.1.10, 133.168.1.254 |
| DNS Enabled For WINS | No |
| WINS Primary Server | |
| Enable LMHOSTS Lookup | Yes |
| WINS LMHOSTS File | |
| TCP/IP Netbios Setting | Enable Netbios via DHCP |
| IP Filter Security Enabled | |
| Client System: Shares [Top] |
| Share Name | ADMIN$ |
| Path | C:\Windows |
| Description | Remote Admin |
| Share Type | Special Share |
| Share Name | Backup20100312 |
| Path | C:\Backup20100312 |
| Description | Auditor Comment |
| Share Type | File Share |
| Share Name | C |
| Path | C:\ |
| Share Type | File Share |
| Share Name | C$ |
| Path | C:\ |
| Description | Default share |
| Share Type | Special Share |
| Share Name | IPC$ |
| Description | Remote IPC |
| Share Type | Interprocess communication (IPC) |
| Share Name | print$ |
| Path | C:\Windows\system32\spool\drivers |
| Description | Printer Drivers |
| Share Type | File Share |
| Client System: Services [Top] |
| Display Name | Application Experience |
| Service Name (Logon As) | AeLookupSvc (localSystem) |
| State (Process Id) | Running (1044) |
| Start Type | Automatic |
| Path Name | C:\Windows\system32\svchost.exe -k netsvcs |
| Display Name | Application Information |
| Service Name (Logon As) | Appinfo (LocalSystem) |
| State (Process Id) | Running (1044) |
| Start Type | Manual |
| Path Name | C:\Windows\system32\svchost.exe -k netsvcs |
| Display Name | Application Layer Gateway Service |
| Service Name (Logon As) | ALG (NT AUTHORITY\LocalService) |
| State (Process Id) | Stopped |
| Start Type | Manual |
| Path Name | C:\Windows\System32\alg.exe |
| Display Name | Application Management |
| Service Name (Logon As) | AppMgmt (LocalSystem) |
| State (Process Id) | Stopped |
| Start Type | Manual |
| Path Name | C:\Windows\system32\svchost.exe -k netsvcs |
| Display Name | Background Intelligent Transfer Service |
| Service Name (Logon As) | BITS (LocalSystem) |
| State (Process Id) | Running (1044) |
| Start Type | Automatic |
| Path Name | C:\Windows\System32\svchost.exe -k netsvcs |
| Display Name | Base Filtering Engine |
| Service Name (Logon As) | BFE (NT AUTHORITY\LocalService) |
| State (Process Id) | Running (1612) |
| Start Type | Automatic |
| Path Name | C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork |
| Display Name | Block Level Backup Engine Service |
| Service Name (Logon As) | wbengine (localSystem) |
| State (Process Id) | Stopped |
| Start Type | Manual |
| Path Name | C:\Windows\system32\wbengine.exe |
| Display Name | Certificate Propagation |
| Service Name (Logon As) | CertPropSvc (LocalSystem) |
| State (Process Id) | Stopped |
| Start Type | Manual |
| Path Name | C:\Windows\system32\svchost.exe -k netsvcs |
| Display Name | CNG Key Isolation |
| Service Name (Logon As) | KeyIso (LocalSystem) |
| State (Process Id) | Running (612) |
| Start Type | Manual |
| Path Name | C:\Windows\system32\lsass.exe |
| Display Name | COM+ Event System |
| Service Name (Logon As) | EventSystem (NT AUTHORITY\LocalService) |
| State (Process Id) | Running (1188) |
| Start Type | Automatic |
| Path Name | C:\Windows\system32\svchost.exe -k LocalService |
| ==Truncated== | Sample only.... |
| Client System: Startup Programs [Top] |
| Program | Adobe Reader Speed Launcher |
| Command | "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" |
| Location | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| User Name | Public |
| Program | ccApp |
| Command | "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" |
| Location | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| User Name | Public |
| Program | GrooveMonitor |
| Command | "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" |
| Location | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| User Name | Public |
| Program | HP AutoIndexer |
| Command | C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppautoindexer.exe |
| Location | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| User Name | Public |
| Program | HP LaserJet Director |
| Command | C:\PROGRA~1\HEWLET~1\LASERJ~1\HPPDIR~1.EXE |
| Location | Common Startup |
| User Name | Public |
| Program | HP SchedIndexer |
| Command | C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppschedindexer.exe |
| Location | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| User Name | Public |
| Program | Sidebar |
| Command | C:\Program Files\Windows Sidebar\sidebar.exe /autoRun |
| Location | HKU\S-1-5-21-4279025473-3018771506-1539134433-1105\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| User Name | TESTIPS\Auditor |
| Program | VMUserServices |
| Command | C:\Program Files\Virtual Machine Additions\vmusrvc.exe |
| Location | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| User Name | Public |
| Program | vptray |
| Command | C:\PROGRA~1\SYMANT~1\VPTray.exe |
| Location | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| User Name | Public |
| Program | Windows Defender |
| Command | %ProgramFiles%\Windows Defender\MSASCui.exe -hide |
| Location | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| User Name | Public |
| Program | WinZip Quick Pick |
| Command | C:\PROGRA~1\WinZip\WZQKPICK.EXE |
| Location | Common Startup |
| User Name | Public |
| Client System: User Accounts [Top] |
| Account Name (SID) | Administrator (S-1-5-21-1668879600-1007756821-3384897010-500) |
| Full Name | |
| Description | Built-in account for administering the computer/domain |
| Privilege | Administrator |
| Password Expired | No |
| Cannot Change Password | No |
| Password Never Expires | Yes |
| Account Disabled | No |
| Account Locked | No |
| Number of Logons | 18 |
| Last Logon (GMT) | 09-Oct-2010 15:34:18 |
| Last Password Change | 11-Mar-2010 12:12:35 (297 days ago) |
| Account Name (SID) | Auditor (S-1-5-21-1668879600-1007756821-3384897010-1002) |
| Full Name | Auditor |
| Description | |
| Privilege | Administrator |
| Password Expired | Yes |
| Cannot Change Password | No |
| Password Never Expires | No |
| Account Disabled | No |
| Account Locked | No |
| Number of Logons | 36 |
| Last Logon (GMT) | 20-Oct-2010 20:28:09 |
| Last Password Change | 20-Oct-2010 22:07:57 (73 days ago) |
| Account Name (SID) | Guest (S-1-5-21-1668879600-1007756821-3384897010-501) |
| Full Name | |
| Description | Built-in account for guest access to the computer/domain |
| Privilege | Guest |
| Password Expired | No |
| Cannot Change Password | Yes |
| Password Never Expires | Yes |
| Account Disabled | Yes |
| Account Locked | No |
| Number of Logons | 0 |
| Last Logon (GMT) | 12-Mar-2010 19:28:14 |
| Last Password Change | |
| Account Name (SID) | VUSR_VISTAVANILLA (S-1-5-21-1668879600-1007756821-3384897010-1001) |
| Full Name | VSA Server Account |
| Description | Account for the Visual Studio Analyzer server components |
| Privilege | Guest |
| Password Expired | No |
| Cannot Change Password | No |
| Password Never Expires | Yes |
| Account Disabled | No |
| Account Locked | No |
| Number of Logons | 0 |
| Last Logon (GMT) | |
| Last Password Change | 11-Mar-2010 11:44:43 (297 days ago) |
| Client System: Group Accounts [Top] |
| Group Name (SID) | None (S-1-5-21-1668879600-1007756821-3384897010-513) |
| Group Type | Global |
| Description | Ordinary users |
| Group Members | Administrator |
| Guest |
| VUSR_VISTAVANILLA |
| Auditor |
| Group Name (SID) | Administrators (S-1-5-32-544) |
| Group Type | Local |
| Description | Administrators have complete and unrestricted access to the computer/domain |
| Group Members | VistaVanilla\Administrator |
| VistaVanilla\Auditor |
| TESTIPS\Domain Admins |
| Group Name (SID) | Backup Operators (S-1-5-32-551) |
| Group Type | Local |
| Description | Backup Operators can override security restrictions for the sole purpose of backing up or restoring files |
| Group Members | - |
| Group Name (SID) | Cryptographic Operators (S-1-5-32-569) |
| Group Type | Local |
| Description | Members are authorized to perform cryptographic operations. |
| Group Members | - |
| Group Name (SID) | Distributed COM Users (S-1-5-32-562) |
| Group Type | Local |
| Description | Members are allowed to launch, activate and use Distributed COM objects on this machine. |
| Group Members | - |
| Group Name (SID) | Event Log Readers (S-1-5-32-573) |
| Group Type | Local |
| Description | Members of this group can read event logs from local machine |
| Group Members | - |
| Group Name (SID) | Guests (S-1-5-32-546) |
| Group Type | Local |
| Description | Guests have the same access as members of the Users group by default, except for the Guest account which is further restricted |
| Group Members | VistaVanilla\Guest |
| Group Name (SID) | IIS_IUSRS (S-1-5-32-568) |
| Group Type | Local |
| Description | Built-in group used by Internet Information Services. |
| Group Members | NT AUTHORITY\IUSR |
| Group Name (SID) | Network Configuration Operators (S-1-5-32-556) |
| Group Type | Local |
| Description | Members in this group can have some administrative privileges to manage configuration of networking features |
| Group Members | - |
| Group Name (SID) | Performance Log Users (S-1-5-32-559) |
| Group Type | Local |
| Description | Members of this group may schedule logging of performance counters, enable trace providers, and collect event traces both locally and via remote access to this computer |
| Group Members | - |
| Group Name (SID) | Performance Monitor Users (S-1-5-32-558) |
| Group Type | Local |
| Description | Members of this group can access performance counter data locally and remotely |
| Group Members | - |
| Group Name (SID) | Power Users (S-1-5-32-547) |
| Group Type | Local |
| Description | Power Users are included for backwards compatibility and possess limited administrative powers |
| Group Members | - |
| Group Name (SID) | Remote Desktop Users (S-1-5-32-555) |
| Group Type | Local |
| Description | Members in this group are granted the right to logon remotely |
| Group Members | - |
| Group Name (SID) | Replicator (S-1-5-32-552) |
| Group Type | Local |
| Description | Supports file replication in a domain |
| Group Members | - |
| Group Name (SID) | Users (S-1-5-32-545) |
| Group Type | Local |
| Description | Users are prevented from making accidental or intentional system-wide changes and can run most applications |
| Group Members | NT AUTHORITY\INTERACTIVE |
| NT AUTHORITY\Authenticated Users |
| VistaVanilla\Auditor |
| TESTIPS\Domain Users |
| Group Name (SID) | Auditor Test (S-1-5-21-1668879600-1007756821-3384897010-1006) |
| Group Type | Local |
| Description | My Test Group |
| Group Members | - |
| Client System: System Accounts [Top] |
| Account Name (SID) | VISTAVANILLA\Everyone (S-1-1-0) |
| Account Type | WellKnownGroup |
| Account Name (SID) | VISTAVANILLA\LOCAL (S-1-2-0) |
| Account Type | WellKnownGroup |
| Account Name (SID) | VISTAVANILLA\CREATOR OWNER (S-1-3-0) |
| Account Type | WellKnownGroup |
| Account Name (SID) | VISTAVANILLA\CREATOR GROUP (S-1-3-1) |
| Account Type | WellKnownGroup |
| Account Name (SID) | VISTAVANILLA\CREATOR OWNER SERVER (S-1-3-2) |
| Account Type | WellKnownGroup |
| Account Name (SID) | VISTAVANILLA\CREATOR GROUP SERVER (S-1-3-3) |
| Account Type | WellKnownGroup |
| Account Name (SID) | VISTAVANILLA\OWNER RIGHTS (S-1-3-4) |
| Account Type | WellKnownGroup |
| Account Name (SID) | VISTAVANILLA\DIALUP (S-1-5-1) |
| Account Type | WellKnownGroup |
| Account Name (SID) | VISTAVANILLA\NETWORK (S-1-5-2) |
| Account Type | WellKnownGroup |
| Account Name (SID) | VISTAVANILLA\BATCH (S-1-5-3) |
| Account Type | WellKnownGroup |
| Account Name (SID) | VISTAVANILLA\INTERACTIVE (S-1-5-4) |
| Account Type | WellKnownGroup |
| Account Name (SID) | VISTAVANILLA\SERVICE (S-1-5-6) |
| Account Type | WellKnownGroup |
| Account Name (SID) | VISTAVANILLA\ANONYMOUS LOGON (S-1-5-7) |
| Account Type | WellKnownGroup |
| Account Name (SID) | VISTAVANILLA\PROXY (S-1-5-8) |
| Account Type | WellKnownGroup |
| Account Name (SID) | VISTAVANILLA\SYSTEM (S-1-5-18) |
| Account Type | WellKnownGroup |
| Account Name (SID) | VISTAVANILLA\ENTERPRISE DOMAIN CONTROLLERS (S-1-5-9) |
| Account Type | WellKnownGroup |
| Account Name (SID) | VISTAVANILLA\SELF (S-1-5-10) |
| Account Type | WellKnownGroup |
| Account Name (SID) | VISTAVANILLA\Authenticated Users (S-1-5-11) |
| Account Type | WellKnownGroup |
| Account Name (SID) | VISTAVANILLA\RESTRICTED (S-1-5-12) |
| Account Type | WellKnownGroup |
| Account Name (SID) | VISTAVANILLA\TERMINAL SERVER USER (S-1-5-13) |
| Account Type | WellKnownGroup |
| Account Name (SID) | VISTAVANILLA\REMOTE INTERACTIVE LOGON (S-1-5-14) |
| Account Type | WellKnownGroup |
| Account Name (SID) | VISTAVANILLA\IUSR (S-1-5-17) |
| Account Type | WellKnownGroup |
| Account Name (SID) | VISTAVANILLA\LOCAL SERVICE (S-1-5-19) |
| Account Type | WellKnownGroup |
| Account Name (SID) | VISTAVANILLA\NETWORK SERVICE (S-1-5-20) |
| Account Type | WellKnownGroup |
| Account Name (SID) | VISTAVANILLA\BUILTIN (S-1-5-32) |
| Account Type | Domain |
| Client System: Hot Fixes (QFE updates) [Top] |
| Click on a Hot Fix Id for more information. |
| Hot Fix 1 | KB2158563 (Update) |
| Installed On (By) | 2010-09-29 (S-1-5-18) |
| Hot Fix 2 | KB2160329 (Security Update) |
| Installed On (By) | 2010-08-13 (S-1-5-18) |
| Hot Fix 3 | KB2183461 (Security Update) |
| Installed On (By) | 2010-08-13 (S-1-5-18) |
| Hot Fix 4 | KB2207566 (Security Update) |
| Installed On (By) | 2010-10-14 (S-1-5-18) |
| Hot Fix 5 | KB2281679 (Security Update) |
| Installed On (By) | 2010-10-14 (S-1-5-18) |
| Hot Fix 6 | KB2286198 (Security Update) |
| Installed On (By) | 2010-08-03 (S-1-5-18) |
| Hot Fix 7 | KB2296011 (Security Update) |
| Installed On (By) | 2010-10-14 (S-1-5-18) |
| Hot Fix 8 | KB2296199 (Security Update) |
| Installed On (By) | 2010-12-15 (S-1-5-18) |
| Hot Fix 9 | KB2305420 (Security Update) |
| Installed On (By) | 2010-12-15 (S-1-5-18) |
| Hot Fix 10 | KB2345886 (Update) |
| Installed On (By) | 2010-10-14 (S-1-5-18) |
| Hot Fix 11 | KB2347290 (Security Update) |
| Installed On (By) | 2010-09-15 (S-1-5-18) |
| See also: SekChek’s List Missing Windows Updates Tool |
|