Sysinternals Handle - Detected 30 times


  • Community Moderator

    In my VM the application Sysinternals Handle is detected 30 times:

    4de5d42d-5fb7-45bb-89bc-86dcfd632864-image.png

    e690eeba-a8b3-4b68-aaec-2ad019edf1d7-image.png


    Here all locations where it is found (used the "Export" button):

    "product","vendor","version","status","solution","file"
    "Sysinternals Handle","Sysinternals","4.11","ok","","C:\Program Files (x86)\Microsoft Visual Studio\Installer\resources\app\layout\handle.exe"
    "Sysinternals Handle","Sysinternals","4.11","ok","","C:\Program Files (x86)\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\handle.exe"
    "Sysinternals Handle","Sysinternals","4.11","ok","","C:\Users\OLLI\AppData\Local\Temp\ciljrb3q.cwk\resources\app\layout\handle.exe"
    "Sysinternals Handle","Sysinternals","4.11","ok","","C:\Users\OLLI\AppData\Local\Temp\ciljrb3q.cwk\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\handle.exe"
    "Sysinternals Handle","Sysinternals","4.11","ok","","C:\Users\OLLI\AppData\Local\Temp\ez3x2rkx.huk\resources\app\layout\handle.exe"
    "Sysinternals Handle","Sysinternals","4.11","ok","","C:\Users\OLLI\AppData\Local\Temp\ez3x2rkx.huk\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\handle.exe"
    "Sysinternals Handle","Sysinternals","4.11","ok","","C:\Users\OLLI\AppData\Local\Temp\f4gkbuar.fd3\resources\app\layout\handle.exe"
    "Sysinternals Handle","Sysinternals","4.11","ok","","C:\Users\OLLI\AppData\Local\Temp\f4gkbuar.fd3\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\handle.exe"
    "Sysinternals Handle","Sysinternals","4.11","ok","","C:\Users\OLLI\AppData\Local\Temp\kzlaptcj.qr1\resources\app\layout\handle.exe"
    "Sysinternals Handle","Sysinternals","4.11","ok","","C:\Users\OLLI\AppData\Local\Temp\kzlaptcj.qr1\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\handle.exe"
    "Sysinternals Handle","Sysinternals","4.11","ok","","C:\Users\OLLI\AppData\Local\Temp\mvadmhub.ktr\resources\app\layout\handle.exe"
    "Sysinternals Handle","Sysinternals","4.11","ok","","C:\Users\OLLI\AppData\Local\Temp\mvadmhub.ktr\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\handle.exe"
    "Sysinternals Handle","Sysinternals","4.11","ok","","C:\Users\OLLI\AppData\Local\Temp\nnsiect0.o5t\resources\app\layout\handle.exe"
    "Sysinternals Handle","Sysinternals","4.11","ok","","C:\Users\OLLI\AppData\Local\Temp\nnsiect0.o5t\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\handle.exe"
    "Sysinternals Handle","Sysinternals","4.11","ok","","C:\Users\OLLI\AppData\Local\Temp\oayt15eq.vj1\resources\app\layout\handle.exe"
    "Sysinternals Handle","Sysinternals","4.11","ok","","C:\Users\OLLI\AppData\Local\Temp\oayt15eq.vj1\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\handle.exe"
    "Sysinternals Handle","Sysinternals","4.11","ok","","C:\Users\OLLI\AppData\Local\Temp\omow5kmg.c0c\resources\app\layout\handle.exe"
    "Sysinternals Handle","Sysinternals","4.11","ok","","C:\Users\OLLI\AppData\Local\Temp\omow5kmg.c0c\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\handle.exe"
    "Sysinternals Handle","Sysinternals","4.11","ok","","C:\Users\OLLI\AppData\Local\Temp\s5wb0klh.yuy\resources\app\layout\handle.exe"
    "Sysinternals Handle","Sysinternals","4.11","ok","","C:\Users\OLLI\AppData\Local\Temp\s5wb0klh.yuy\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\handle.exe"
    "Sysinternals Handle","Sysinternals","4.11","ok","","C:\Users\OLLI\AppData\Local\Temp\si0ng3jb.idu\resources\app\layout\handle.exe"
    "Sysinternals Handle","Sysinternals","4.11","ok","","C:\Users\OLLI\AppData\Local\Temp\si0ng3jb.idu\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\handle.exe"
    "Sysinternals Handle","Sysinternals","4.11","ok","","C:\Users\OLLI\AppData\Local\Temp\tkazlyxl.hbe\resources\app\layout\handle.exe"
    "Sysinternals Handle","Sysinternals","4.11","ok","","C:\Users\OLLI\AppData\Local\Temp\tkazlyxl.hbe\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\handle.exe"
    "Sysinternals Handle","Sysinternals","4.11","ok","","C:\Users\OLLI\AppData\Local\Temp\uurrdkbr.yym\resources\app\layout\handle.exe"
    "Sysinternals Handle","Sysinternals","4.11","ok","","C:\Users\OLLI\AppData\Local\Temp\uurrdkbr.yym\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\handle.exe"
    "Sysinternals Handle","Sysinternals","4.11","ok","","C:\Users\OLLI\AppData\Local\Temp\vgosvl3r.4sb\resources\app\layout\handle.exe"
    "Sysinternals Handle","Sysinternals","4.11","ok","","C:\Users\OLLI\AppData\Local\Temp\vgosvl3r.4sb\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\handle.exe"
    "Sysinternals Handle","Sysinternals","4.11","ok","","C:\Users\OLLI\AppData\Local\Temp\ynhh1jkc.zp3\resources\app\layout\handle.exe"
    "Sysinternals Handle","Sysinternals","4.11","ok","","C:\Users\OLLI\AppData\Local\Temp\ynhh1jkc.zp3\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\handle.exe"
    

    Here the file info from the first EXE file:

    File name and path:     C:\Program Files (x86)\Microsoft Visual Studio\Installer\resources\app\layout\handle.exe
    Product Name:           Sysinternals Handle
    Internal Name:          Nthandle
    Original Filename:      Nthandle.exe
    
    File Description:       Handle viewer
    Company:                Sysinternals - www.sysinternals.com
    Legal Copyright:        Copyright (C) 1997-2017 Mark Russinovich
    Legal Trademarks:       
    Comments:               
    
    File Version String:    4.11
    File Version:           4.11.0.0
    Product Version String: 4.11
    Product Version:        4.11.0.0
    


  • Community Moderator

    The first two are installed with Visual Studio.
    But the others? I have no idea.
    Maybe you @Tom install Visual Studio in a Sandbox?


  • VulnDetect Team Member

    Do you know if this is installed by Visual Studio?

    In that case, perhaps we should bundle it with Visual Studio.


Log in to reply