Content Type
Profiles
Forums
Events
Posts posted by NoelC
-
-
Touché! That's what I like so much about you, jaclaz, you simultaneously present complementary AND complimentary viewpoints.
And working PRE-10 Windows installations are what allow us to have the free time to play with words. People sure are going to miss that.
In other news, elsewhere I've been learning about the secret, unmodifiable firewall rules we are all subjected to when the Windows Firewall service is run. Microsoft is distracting us with stupid bugs while secretly shoehorning nasty s*** into Windows in order to take over control. To Microsoft, regarding that, I say...
Spoiler-Noel
0 -
That's not punny!
-Noel
0 -
I think the word you were looking for was "complements".
-Noel
0 -
Just a hunch, but I'm guessing the fault lies in the servicing database maintenance tools (e.g.,, DISM, et. al.) rather than in cleanmgr.exe.
It's probably not a big problem; maybe a number is 1 byte too small (causing 0 to go to 0xFFFFFFFF). Notably when there IS something to clean up the number is more reasonable. The 3.99 TB appeared after I ran a cleanup. But that showed the second problem - the process taking over an hour to complete - which I suspect could be related to the problem Windows 7 people are seeing where update checks take a really long time.
This seems to me to be new levels of bloat, never before seen even at Microsoft.
-Noel
0 -
Take the 10 out of the thread subject and this thread is all quite on topic.
I find it fascinating what people have been able to do with component mix and match using debugging tools et. al. I'm reminded of a good DJ remixing good music to make even better music. Makes me want to go and play some chill remixes.
I wonder what Windows could become if Microsoft would just open the source code up to the world.
-Noel
2 -
Oh yeah, thanks for noticing the firewall sub-question, Tarun...
I forgot to mention: Sphinx Windows Firewall Control version 8 has just been released. It's breakthrough claim to fame is that you can manage the setup with names, rather than addresses. It takes care of the ongoing correlation between names and addresses by watching DNS traffic. VERY slick. It handles things like content delivery networks and banks of servers adeptly. You can take controlling things to a whole next level (e.g., describing just what sites a particular program can and cannot contact, or enabling/disabling Windows Update from contacting the several servers with mutable addresses that it normally talks to, etc.) and still not be overwhelmed with ongoing maintenance. I run a tight ship and often go weeks at a time without messing with my firewall configuration (I've been testing version 8 betas for a while).
I'm willing to share my Sphinx configs as examples/starting points. PM or EMail me if interested.
-Noel
0 -
Where do you think you're more likely to get the ransomware from...
- Do you download executables from the wild Internet and run them?
- Or do you think you'll get the ransomware from web pages?
Nothing can really help you much with the former. If you're going to download software and run it then it would be a good idea to vet it in a virtual machine before ever allowing it near your critical systems.
If I were looking for an active protection program I'd probably look into the MalwareBytes Antimalware product, then at least scan every executable before running it, and maybe consider installing the active protection components. It's one of the better scanners, though I have no experience with the preventative side of the product. I only scan with it myself.
For the second possibility I follow a very good strategy for having all my systems just avoid visiting sites that host malware. It involves downloading various blacklists of host systems and domains and compiling those lists into input data for a DNS proxy program I run called "Dual DHCP/DNS Server", modified to handle large lists. Another almost as effective strategy involves gathering the same info and putting it into your system's hosts file, though beware: Some folks claim that's a bad approach in that it can introduce undue overhead into Windows networking. I personally have not seen any problems.
You can read more on these approaches here:
http://win10epicfail.proboards.com/thread/105/build-own-hosts-file
The better way to do it, and the way I'm doing it now for my systems, is described in post 12 of the thread at the above link - I now use the Dual DNS/DHCP Server package to blacklist sites. If a site being resolved to an address survives a lookup in the blacklists, it's considered legit and is forwarded to an online OpenDNS server to be resolved. I can't emphasize enough how effective this strategy is at not only reducing the chance you'll be infected by malware but also to improve the performance and pleasure of your browsing experience.
Beyond the above, all of what I mentioned in the original post of this thread still applies. Disable ActiveX, don't run things in iFrames, remove all the Add-ons you don't know you need, etc. Don't be afraid to take control of your security setup. Not everything is configured to be as secure as it can be out of the box!
-Noel
0 -
13 hours ago, jaclaz said:
About the Internet (actually seemingly DHCP) mess, if it wasn't broken, why would they (attempt to) fix it?
I didn't say it wasn't broken. What I said was that there is some question whether a recent Windows Update was at fault (yes, I'm picking nits).
People are apparently uncovering evidence that the problem is occurring in systems that have not been updated. One theory is that it was latent and something triggered it.
But it doesn't really matter, for the purpose of criticizing Microsoft for releasing untested code, whether it was broken by a recent Windows Update or came with the "Anniversary" version, or whatever.
-Noel
0 -
24 minutes ago, aviv00 said:
Can u share process hacker with process running
You didn't quote anyone... Assuming you're asking me about my tweaked/augmented Win 10 setup...
- aerohost.exe is part of Aero Glass for Win 8+.
- ClassicStartMenu.exe is Classic Shell's start menu replacement.
- conhost.exe is there because I have a beta build of Aero Glass for Win 8+ running.
- ProcessHacker.exe is the tool shown in the above screen grab.
- ShellFolderFixUI.exe positions Explorer windows per where they were used last.
- TSVNCache.exe is part of Tortoise SVN, which is a SubVersion client used to access software.
- 2 vmtoolsd.exe processes are because this Win 10 system is running in a VMware virtual machine.
- Windows10FirewallControl.exe and Windows10FirewallServices.exe are part of the Sphinx firewall.
- WizMouse.exe helps with sending mouse wheel events to the windows under the cursor
All these things work very well together.
Some other pertinent information...
Spoiler------------------------------------------------------------------------------------------- TaskList /V /FO:CSV /NH (processes running): "aerohost.exe","1600","Services","0","1,152 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "ClassicStartMenu.exe","4084","Console","1","11,876 K","Running","W10VM\NoelC","0:00:00","StartHookWindow" "cmd.exe","1320","Console","1","3,308 K","Running","W10VM\NoelC","0:00:00","Administrator: CMD - gettasklist" "conhost.exe","2896","Console","1","7,472 K","Running","Window Manager\DWM-1","0:00:00","CicMarshalWnd" "conhost.exe","4976","Console","1","18,624 K","Running","W10VM\NoelC","0:00:00","CicMarshalWnd" "csrss.exe","688","Services","0","4,032 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "csrss.exe","768","Console","1","7,168 K","Running","NT AUTHORITY\SYSTEM","0:00:01","N/A" "dasHost.exe","2308","Services","0","11,536 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:00","N/A" "dllhost.exe","2864","Services","0","13,108 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "dwm.exe","1216","Console","1","118,916 K","Running","Window Manager\DWM-1","0:00:09","dwm.exe" "explorer.exe","3812","Console","1","109,068 K","Running","W10VM\NoelC","0:00:08","N/A" "gsort.exe","1360","Console","1","5,108 K","Unknown","W10VM\NoelC","0:00:00","N/A" "lsass.exe","856","Services","0","12,108 K","Unknown","NT AUTHORITY\SYSTEM","0:00:01","N/A" "Memory Compression","2432","Services","0","8 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "msdtc.exe","2968","Services","0","9,648 K","Unknown","NT AUTHORITY\NETWORK SERVICE","0:00:07","N/A" "MsMpEng.exe","2364","Services","0","99,280 K","Unknown","NT AUTHORITY\SYSTEM","0:00:59","N/A" "NisSrv.exe","3456","Services","0","5,804 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:00","N/A" "services.exe","840","Services","0","7,608 K","Unknown","NT AUTHORITY\SYSTEM","0:00:42","N/A" "ShellExperienceHost.exe","4424","Console","1","52,736 K","Running","W10VM\NoelC","0:00:00","Start" "ShellFolderFixUI.exe","4404","Console","1","9,592 K","Running","W10VM\NoelC","0:00:00","ShellFolderFix" "sihost.exe","3516","Console","1","18,856 K","Running","W10VM\NoelC","0:00:00","N/A" "smss.exe","580","Services","0","1,208 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "spoolsv.exe","1872","Services","0","19,500 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "svchost.exe","1016","Services","0","20,080 K","Unknown","NT AUTHORITY\NETWORK SERVICE","0:00:01","N/A" "svchost.exe","1072","Services","0","21,176 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:01","N/A" "svchost.exe","1104","Services","0","67,136 K","Unknown","NT AUTHORITY\SYSTEM","0:00:43","N/A" "svchost.exe","1188","Services","0","15,272 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:01","N/A" "svchost.exe","1376","Services","0","6,592 K","Unknown","NT AUTHORITY\NETWORK SERVICE","0:00:00","N/A" "svchost.exe","1492","Services","0","15,436 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:04","N/A" "svchost.exe","1516","Services","0","9,240 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:00","N/A" "svchost.exe","184","Services","0","9,392 K","Unknown","NT AUTHORITY\NETWORK SERVICE","0:00:00","N/A" "svchost.exe","2356","Services","0","16,696 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "svchost.exe","2476","Services","0","12,524 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:00","N/A" "svchost.exe","756","Services","0","36,228 K","Unknown","NT AUTHORITY\SYSTEM","0:00:05","N/A" "svchost.exe","944","Services","0","18,788 K","Unknown","NT AUTHORITY\SYSTEM","0:00:01","N/A" "System Idle Process","0","Services","0","4 K","Unknown","NT AUTHORITY\SYSTEM","3:50:23","N/A" "System","4","Services","0","1,888 K","Unknown","N/A","0:01:35","N/A" "taskhostw.exe","3560","Console","1","16,456 K","Running","W10VM\NoelC","0:00:00","Task Host Window" "tasklist.exe","4476","Console","1","8,272 K","Unknown","W10VM\NoelC","0:00:00","N/A" "TSVNCache.exe","4792","Console","1","24,908 K","Running","W10VM\NoelC","0:00:00","TSVNCacheWindow" "vmtoolsd.exe","2348","Services","0","15,960 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "vmtoolsd.exe","3064","Console","1","37,464 K","Running","W10VM\NoelC","0:00:01","N/A" "Windows10FirewallControl.exe","4144","Console","1","16,324 K","Running","W10VM\NoelC","0:00:06","N/A" "Windows10FirewallService.exe","1256","Services","0","13,772 K","Unknown","NT AUTHORITY\SYSTEM","0:00:01","N/A" "wininit.exe","760","Services","0","5,216 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "winlogon.exe","1008","Console","1","11,028 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "WizMouse.exe","4560","Console","1","720 K","Running","W10VM\NoelC","0:00:00","N/A" "WmiPrvSE.exe","4092","Services","0","8,524 K","Unknown","NT AUTHORITY\NETWORK SERVICE","0:00:00","N/A" ------------------------------------------------------------------------------------------- TaskList /SVC /FO:CSV /NH (services running): "dllhost.exe","2864","COMSysApp" "lsass.exe","856","SamSs" "msdtc.exe","2968","MSDTC" "MsMpEng.exe","2364","WinDefend" "NisSrv.exe","3456","WdNisSvc" "spoolsv.exe","1872","Spooler" "svchost.exe","1016","CryptSvc,Dnscache,LanmanWorkstation,NlaSvc,TermService" "svchost.exe","1072","Dhcp,EventLog,lmhosts,TimeBrokerSvc,wscsvc" "svchost.exe","1104","AudioEndpointBuilder,DeviceAssociationService,SysMain,TrkWks,UmRdpService" "svchost.exe","1188","EventSystem,FontCache,netprofm,nsi,WdiServiceHost,WinHttpAutoProxySvc" "svchost.exe","1376","PolicyAgent" "svchost.exe","1492","BFE,CoreMessagingRegistrar,DPS" "svchost.exe","1516","Audiosrv" "svchost.exe","184","RpcEptMapper,RpcSs" "svchost.exe","2356","StateRepository,tiledatamodelsvc" "svchost.exe","2476","stisvc" "svchost.exe","756","Browser,CertPropSvc,DsmSvc,IKEEXT,iphlpsvc,LanmanServer,ProfSvc,Schedule,SENS,SessionEnv,ShellHWDetection,Themes,UserManager,Winmgmt,WpnService" "svchost.exe","944","BrokerInfrastructure,DcomLaunch,LSM,PlugPlay,Power,SystemEventsBroker" "vmtoolsd.exe","2348","VMTools" "Windows10FirewallService.exe","1256","Windows10FirewallService" ------------------------------------------------------------------------------------------- TaskList /M /FO:CSV /NH (modules loaded): "aerohost.exe","1600","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,imagehlp.dll,ucrtbase.dll,DWMGlass.dll,shcore.dll,msvcrt.dll,combase.dll,RPCRT4.dll,bcryptPrimitives.dll,SHLWAPI.dll,GDI32.dll,gdi32full.dll,dwmapi.dll,win32u.dll,USER32.dll,COMCTL32.dll,ADVAPI32.dll,sechost.dll,SspiCli.dll,ntmarta.dll,kernel.appcore.dll,WTSAPI32.dll,WINSTA.dll,dbghelp.dll" "ClassicStartMenu.exe","4084","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,USER32.dll,win32u.dll,GDI32.dll,gdi32full.dll,ADVAPI32.dll,msvcrt.dll,sechost.dll,RPCRT4.dll,SHELL32.dll,cfgmgr32.dll,windows.storage.dll,combase.dll,ucrtbase.dll,bcryptPrimitives.dll,powrprof.dll,shlwapi.dll,kernel.appcore.dll,shcore.dll,profapi.dll,ole32.dll,ClassicStartMenuDLL.dll,COMDLG32.dll,UxTheme.dll,COMCTL32.dll,OLEAUT32.dll,msvcp_win.dll,WTSAPI32.dll,WINTRUST.dll,MSIMG32.dll,Secur32.dll,MSASN1.dll,CRYPT32.dll,NETAPI32.dll,dwmapi.dll,OLEACC.dll,WINMM.dll,PROPSYS.dll,WININET.dll,WINMMBASE.dll,SSPICLI.DLL,NETUTILS.DLL,LOGONCLI.DLL,IMM32.DLL,clbcatq.dll,MSCTF.dll" "cmd.exe","1320","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,cmdext.dll,ADVAPI32.dll,sechost.dll,RPCRT4.dll" "conhost.exe","2896","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,ConhostV1.dll,win32u.dll,USER32.dll,GDI32.dll,gdi32full.dll,IMM32.dll,OLEAUT32.dll,msvcp_win.dll,ucrtbase.dll,combase.dll,RPCRT4.dll,bcryptPrimitives.dll,uxtheme.dll,MSCTF.dll,sechost.dll,dwmapi.dll,kernel.appcore.dll,comctl32.DLL,SHCORE.dll" "conhost.exe","4976","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,ConhostV2.dll,combase.dll,ucrtbase.dll,RPCRT4.dll,bcryptPrimitives.dll,GDI32.dll,gdi32full.dll,USER32.dll,win32u.dll,IMM32.dll,OLEAUT32.dll,msvcp_win.dll,PROPSYS.dll,sechost.dll,shcore.dll,kernel.appcore.dll,uxtheme.dll,SHELL32.dll,cfgmgr32.dll,windows.storage.dll,powrprof.dll,advapi32.dll,shlwapi.dll,profapi.dll,ole32.dll,clbcatq.dll,LINKINFO.dll,MSCTF.dll,dwmapi.dll,comctl32.DLL" "dasHost.exe","2308","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,RPCRT4.dll,sechost.dll,cfgmgr32.dll,bcryptPrimitives.dll,DAFWSD.dll,OLEAUT32.dll,msvcp_win.dll,ucrtbase.dll,combase.dll,WS2_32.dll,FirewallAPI.dll,IPHLPAPI.DLL,deviceassociation.dll,wsdapi.dll,NSI.dll,webservices.dll,fwbase.dll,bcrypt.dll,CRYPT32.dll,MSASN1.dll,dhcpcsvc6.DLL,dhcpcsvc.DLL,mswsock.dll,wshqos.dll,wshtcpip.DLL,wship6.dll,WINNSI.DLL,powrprof.dll,CRYPTSP.dll,rsaenh.dll,CRYPTBASE.dll,XmlLite.dll,WINHTTP.dll,webio.dll,SspiCli.dll,DNSAPI.dll,kernel.appcore.dll,clbcatq.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,MLANG.dll" "dllhost.exe","2864","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,ucrtbase.dll,combase.dll,RPCRT4.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,clbcatq.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,sechost.dll,COMSVCS.DLL,OLEAUT32.dll,msvcp_win.dll,ole32.dll,CRYPTSP.dll,rsaenh.dll,bcrypt.dll,CRYPTBASE.dll,txflog.dll,es.dll,PROPSYS.dll,shcore.dll,sxs.dll,ADVAPI32.dll,XOLEHLP.dll,MSDTCPRX.DLL,WS2_32.dll,CLUSAPI.dll,RESUTILS.dll,MTXCLU.DLL,ktmw32.dll,DNSAPI.dll,NSI.dll,IPHLPAPI.DLL,wkscli.dll,cscapi.dll,netutils.dll,sspicli.dll,mswsock.dll,fwpuclnt.dll,rasadhlp.dll,catsrv.dll,MfcSubs.dll,catsrvps.dll,catsrvut.dll" "dwm.exe","1216","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,apphelp.dll,msvcrt.dll,advapi32.dll,sechost.dll,RPCRT4.dll,gdi32.dll,gdi32full.dll,USER32.dll,win32u.dll,dwmredir.dll,udwm.dll,dwmcore.dll,dxgi.dll,dcomp.dll,OLEAUT32.dll,msvcp_win.dll,ucrtbase.dll,combase.dll,kernel.appcore.dll,bcryptPrimitives.dll,CoreMessaging.dll,IMM32.DLL,uxtheme.dll,dwmghost.dll,dwmapi.dll,WindowsCodecs.dll,clbcatq.dll,UIAnimation.dll,d3d11.dll,ism32k.dll,shcore.dll,CoreUIComponents.dll,wintypes.dll,avrt.dll,Windows.Gaming.Input.dll,cfgmgr32.dll,twinapi.appcore.dll,bcrypt.dll,vm3dum64.dll,D3D10Level9.dll,OneCoreUAPCommonProxyStub.dll,d2d1.dll,CRYPT32.dll,MSASN1.dll,XmlLite.dll,Cabinet.dll,DWMGlass.dll,SHLWAPI.dll,COMCTL32.dll,dbghelp.dll,WTSAPI32.dll,WINSTA.dll,ole32.dll,VERSION.dll,shell32.dll,windows.storage.dll,powrprof.dll,profapi.dll,DUser.dll,atlthunk.dll,MSIMG32.dll,MSCTF.dll" "explorer.exe","3812","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,OLEAUT32.dll,msvcp_win.dll,ucrtbase.dll,combase.dll,RPCRT4.dll,bcryptPrimitives.dll,USER32.dll,win32u.dll,GDI32.dll,gdi32full.dll,SHCORE.dll,SHLWAPI.dll,SHELL32.dll,cfgmgr32.dll,windows.storage.dll,powrprof.dll,advapi32.dll,sechost.dll,kernel.appcore.dll,profapi.dll,CRYPT32.dll,PROPSYS.dll,MSASN1.dll,MrmCoreR.dll,UxTheme.dll,dwmapi.dll,twinapi.appcore.dll,TWINAPI.dll,SspiCli.dll,USERENV.dll,bcrypt.dll,settingsynccore.dll,cryptsp.dll,IMM32.DLL,MSCTF.dll,ole32.dll,clbcatq.dll,ActXPrxy.dll,SharedStartModel.dll,XmlLite.dll,CoreMessaging.dll,VEEventDispatcher.dll,msvcp110_win.dll,IDStore.dll,SAMLIB.dll,Bcp47Langs.dll,settingsyncpolicy.dll,policymanager.dll,TokenBroker.dll,TOKENBINDING.dll,wintypes.dll,WINSTA.dll,comctl32.dll,SndVolSSO.DLL,MMDevApi.dll,DEVOBJ.dll,OLEACC.dll,OneCoreCommonProxyStub.dll,usermgrproxy.dll,dataexchange.dll,d3d11.dll,dcomp.dll,dxgi.dll,COMDLG32.dll,VERSION.dll,WINMM.dll,WINMMBASE.dll,explorerframe.dll,UxTSB.dll,MSIMG32.dll,dbghelp.dll,Windows.StateRepository.dll,StateRepository.Core.dll,Windows.UI.dll,thumbcache.dll,edputil.dll,coml2.dll,TwinUI.dll,windows.immersiveshell.serviceprovider.dll,WindowsCodecs.dll,Secur32.dll,samcli.dll,netutils.dll,WLDP.DLL,WINTRUST.dll,WTSAPI32.dll,SLC.dll,sppc.dll,ClassicStartMenuDLL.dll,NETAPI32.dll,WININET.dll,LOGONCLI.DLL,taskschd.dll,twinui.appcore.dll,twinui.pcshell.dll,DWMGlass.dll,PhotoMetadataHandler.dll,apphelp.dll,gameux.dll,gdiplus.dll,ApplicationFrame.dll,d2d1.dll,msxml6.dll,dbghelp.dll,ntshrui.dll,srvcli.dll,cscapi.dll,CoreUIComponents.dll,Windows.UI.Immersive.dll,wpncore.dll,winsqlite3.dll,cdp.dll,WINHTTP.dll,urlmon.dll,CRYPTBASE.dll,WS2_32.dll,ncrypt.dll,IPHLPAPI.DLL,iertutil.dll,NTASN1.dll,LINKINFO.dll,NotificationController.dll,AboveLockAppHost.dll,npsm.dll,Windows.Web.dll,execmodelproxy.dll,Windows.Networking.Connectivity.dll,npmproxy.dll,NSI.dll,wlanapi.dll,ieframe.dll,WKSCLI.DLL,wwapi.dll,wlidprov.dll,NInput.dll,vm3dum64.dll,D3D10Level9.dll,UIAnimation.dll,NotificationObjFactory.dll,dsreg.dll,NotificationControllerPS.dll,DPAPI.DLL,rmclient.dll,NetworkExplorer.dll,MPR.dll,ntlanman.dll,drprov.dll,davclnt.dll,DAVHLPR.dll,mswsock.dll,fontext.dll,TortoiseOverlays.dll,TortoiseStub.dll,DeviceCenter.dll,DUI70.dll,TortoiseSVN.dll,libapr_tsvn.dll,libsvn_tsvn.dll,MSVCP140.dll,intl3_tsvn.dll,VCRUNTIME140.dll,libaprutil_tsvn.dll,libsasl.dll,WLDAP32.dll,crshhndl.dll,MFPlat.DLL,RTWorkQ.DLL,stobject.dll,WMICLNT.dll,resourcepolicyclient.dll,EhStorShell.dll,SETUPAPI.dll,cscui.dll,InputSwitch.dll,sxs.dll,BatMeter.dll,Windows.UI.Shell.dll,wincorlib.DLL,rsaenh.dll,es.dll,prnfldr.dll,Windows.Internal.Shell.Broker.dll,ntoskrnl.exe,dxp.dll,SHDOCVW.dll,atlthunk.dll,Syncreg.dll,Actioncenter.dll,wevtapi.dll,wcmapi.dll,wpdshserviceobj.dll,PortableDeviceTypes.dll,PortableDeviceApi.dll,SettingMonitor.dll,cscobj.dll,AUDIOSES.DLL,srchadmin.dll,pnidui.dll,netprofm.dll,NetworkUXBroker.dll,EthernetMediaManager.dll,SyncCenter.dll,imapi2.dll,imagehlp.dll,hgcpl.dll,DUser.dll,provsvc.dll,gpapi.dll,bthprops.cpl,dhcpcsvc6.DLL,dhcpcsvc.DLL,MLANG.dll,wdmaud.drv,AVRT.dll,ksuser.dll,msacm32.drv,MSACM32.dll,midimap.dll,ntmarta.dll,msiltcfg.dll,msi.dll,Windows.ApplicationModel.dll,ShellFolderFix.dll,pcacli.dll,sfc_os.dll,DEVRTL.dll,wscinterop.dll,WSCAPI.dll,wscui.cpl,werconcpl.dll,framedynos.dll,wer.dll,hcproviders.dll,ieproxy.dll,wshirda.dll,netjoin.dll,NETPROVFW.DLL,JOINUTIL.DLL,oledb32.dll,MSDART.DLL,comsvcs.dll,tquery.dll" "gsort.exe","4804","ntdll.dll,wow64.dll,wow64win.dll,wow64cpu.dll" "lsass.exe","856","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,RPCRT4.dll,lsasrv.dll,msvcrt.dll,WS2_32.dll,SspiCli.dll,sechost.dll,MSASN1.dll,samsrv.dll,ucrtbase.dll,CRYPT32.dll,bcrypt.dll,ncrypt.dll,NTASN1.dll,bcryptprimitives.dll,msprivs.DLL,netprovfw.dll,JOINUTIL.DLL,negoexts.DLL,CRYPTSP.dll,CRYPTBASE.dll,pku2u.DLL,cryptdll.dll,wdigest.DLL,rsaenh.dll,schannel.DLL,kerberos.DLL,KerbClientShared.dll,mswsock.dll,msv1_0.DLL,NtlmShared.dll,netlogon.DLL,powrprof.dll,gmsaclient.dll,advapi32.dll,USERENV.dll,WLDAP32.dll,profapi.dll,netutils.dll,DNSAPI.dll,NSI.dll,IPHLPAPI.DLL,cloudAP.DLL,MicrosoftAccountCloudAP.dll,combase.dll,DPAPI.DLL,tspkg.DLL,PCPKsp.dll,ntmarta.dll,PCPTPM12.dll,tbs.dll,efslsaext.dll,dpapisrv.dll,SspiSrv.dll,winsta.dll,scecli.DLL,wevtapi.dll,logoncli.dll,DSPARSE.dll,certpoleng.dll" "msdtc.exe","2968","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,combase.dll,ucrtbase.dll,RPCRT4.dll,bcryptPrimitives.dll,msvcrt.dll,MSDTCTM.dll,OLEAUT32.dll,msvcp_win.dll,sechost.dll,ole32.dll,GDI32.dll,gdi32full.dll,USER32.dll,win32u.dll,WS2_32.dll,MSDTCPRX.dll,ADVAPI32.dll,MSDTCLOG.dll,MTXCLU.DLL,WINMM.dll,CLUSAPI.dll,bcrypt.dll,ktmw32.dll,RESUTILS.dll,MSWSOCK.dll,XOLEHLP.dll,DNSAPI.dll,WINMMBASE.dll,NSI.dll,cfgmgr32.dll,CRYPTSP.dll,IPHLPAPI.DLL,kernel.appcore.dll,COMRES.DLL,msdtcVSp1res.dll,mtxoci.dll,wkscli.dll,cscapi.dll,netutils.dll,sspicli.dll,ntmarta.dll,clbcatq.dll,FirewallAPI.dll,fwbase.dll,FWPolicyIOMgr.dll" "sed.exe","3856","ntdll.dll,wow64.dll,wow64win.dll,wow64cpu.dll" "ShellExperienceHost.exe","4424","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,combase.dll,wincorlib.DLL,ucrtbase.dll,RPCRT4.dll,bcryptPrimitives.dll,OLEAUT32.dll,msvcp_win.dll,kernel.appcore.dll,Windows.UI.Xaml.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,Bcp47Langs.dll,iertutil.dll,CoreMessaging.dll,sechost.dll,advapi32.dll,shcore.dll,IMM32.DLL,twinapi.appcore.dll,bcrypt.dll,WinTypes.dll,Windows.UI.dll,uxtheme.dll,ActXPrxy.dll,dwmapi.dll,CoreUIComponents.dll,dxgi.dll,StartUI.dll,policymanager.dll,msvcp110_win.dll,d3d11.dll,Windows.UI.Shell.SharedUtilities.dll,vm3dum64.dll,D3D10Level9.dll,QuickActions.dll,Windows.UI.ActionCenter.dll,ole32.dll,QuickActionsDataModel.dll,MrmCoreR.dll,SHLWAPI.dll,d2d1.dll,CRYPT32.dll,MSASN1.dll,profapi.dll,msctf.dll,windows.ui.core.textinput.dll,TextInputFramework.dll,Windows.UI.Immersive.dll,DataExchange.dll,dcomp.dll,OneCoreUAPCommonProxyStub.dll,CRYPTBASE.dll,Windows.Globalization.dll,SharedStartModel.dll,XmlLite.dll,VEEventDispatcher.dll,NotificationObjFactory.dll,urlmon.dll,SHELL32.dll,cfgmgr32.dll,windows.storage.dll,powrprof.dll,PROPSYS.dll,SLC.dll,sppc.dll,dwrite.dll,threadpoolwinrt.dll,twinapi.dll,Windows.Graphics.dll,Windows.Globalization.Fontgroups.dll,fontgroupsoverride.dll,Windows.Storage.ApplicationData.dll,Windows.StateRepository.dll,StateRepository.Core.dll,windowscodecs.dll,PhotoMetadataHandler.dll,rmclient.dll,directmanipulation.dll,NotificationControllerPS.dll,globcollationhost.dll,winsta.dll,RTMediaFrame.dll,MFPlat.DLL,RTWorkQ.DLL" "ShellFolderFixUI.exe","4404","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,USER32.dll,UxTheme.dll,win32u.dll,GDI32.dll,msvcrt.dll,gdi32full.dll,combase.dll,COMDLG32.dll,ucrtbase.dll,shcore.dll,MSIMG32.dll,RPCRT4.dll,SHLWAPI.dll,bcryptPrimitives.dll,SHELL32.dll,COMCTL32.dll,cfgmgr32.dll,windows.storage.dll,powrprof.dll,advapi32.dll,sechost.dll,kernel.appcore.dll,profapi.dll,ole32.dll,WINSPOOL.DRV,OLEAUT32.dll,msvcp_win.dll,bcrypt.dll,IMM32.dll,WININET.dll,gdiplus.dll,WINMM.dll,WINMMBASE.dll,dwmapi.dll,ShellFolderFix.dll,MSCTF.dll" "sihost.exe","3516","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,combase.dll,ucrtbase.dll,RPCRT4.dll,bcryptPrimitives.dll,sechost.dll,advapi32.dll,CoreMessaging.dll,CoreUIComponents.dll,ntmarta.dll,kernel.appcore.dll,user32.dll,wintypes.dll,win32u.dll,GDI32.dll,gdi32full.dll,shcore.dll,IMM32.DLL,clbcatq.dll,desktopshellext.dll,shlwapi.dll,msvcp_win.dll,wtsapi32.dll,WINSTA.dll,Windows.Shell.ServiceHostBuilder.dll,ActXPrxy.dll,modernexecserver.dll,ResourcePolicyClient.dll,VEEventDispatcher.dll,OLEAUT32.dll,powrprof.dll,msvcp110_win.dll,twinapi.appcore.dll,bcrypt.dll,uxtheme.dll,ClipboardServer.dll,RMCLIENT.dll,activationmanager.dll,AppointmentActivation.dll,ole32.dll,usermgrproxy.dll,usermgrcli.dll,OneCoreUAPCommonProxyStub.dll,ExecModelClient.dll,windowmanagement.dll,NotificationPlatformComponent.dll,AppContracts.dll,ShareHost.dll,Windows.Storage.dll,profapi.dll,WpPortingLibrary.dll,OneCoreCommonProxyStub.dll,Windows.System.Launcher.dll,dsclient.dll,execmodelproxy.dll,twinui.appcore.dll,daxexec.dll,FLTLIB.DLL,container.dll,IPHLPAPI.DLL,Windows.StateRepository.dll,StateRepository.Core.dll,licensemanagerapi.dll,dwmapi.dll,AppXDeploymentClient.dll" "spoolsv.exe","1872","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,USER32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcrt.dll,sechost.dll,RPCRT4.dll,advapi32.dll,DNSAPI.dll,bcrypt.dll,WS2_32.dll,NSI.dll,IPHLPAPI.DLL,combase.dll,ucrtbase.dll,bcryptPrimitives.dll,kernel.appcore.dll,SspiCli.dll,powrprof.dll,mswsock.dll,WTSAPI32.dll,WINSTA.dll,WINNSI.DLL,rasadhlp.dll,fwpuclnt.dll,localspl.dll,CRYPT32.dll,MSASN1.dll,cfgmgr32.dll,srvcli.dll,SETUPAPI.dll,sfc_os.dll,SPOOLSS.DLL,ole32.dll,Secur32.dll,winspool.drv,PrintIsolationProxy.dll,hpinkstsBB11LM.dll,OLEAUT32.dll,msvcp_win.dll,SHLWAPI.dll,PSAPI.DLL,USERENV.dll,SHELL32.dll,profapi.dll,windows.storage.dll,shcore.dll,VERSION.dll,wshirda.dll,FXSMON.DLL,tcpmon.dll,snmpapi.dll,wsnmp32.dll,usbmon.dll,DEVOBJ.dll,WINTRUST.dll,WSDMon.dll,wsdapi.dll,netutils.dll,deviceassociation.dll,WINHTTP.dll,webservices.dll,FirewallAPI.dll,fwbase.dll,clbcatq.dll,msxml6.dll,FunDisc.dll,XmlLite.dll,fdPnp.dll,ATL.DLL,WSDCHNGR.DLL,drvstore.dll,dhcpcsvc6.DLL,dhcpcsvc.DLL,winprint.dll,gpapi.dll,DSROLE.dll,win32spl.dll,inetpp.dll,CRYPTSP.dll,rsaenh.dll,cscapi.dll,CRYPTBASE.dll,bidispl.dll,WSDPrintProxy.dll,ondemandconnroutehelper.dll,webio.dll,HTTPAPI.dll" "svchost.exe","1016","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,termsrv.dll,WS2_32.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,clbcatq.dll,lsmproxy.dll,advapi32.dll,sspicli.dll,REGAPI.dll,rdpcorets.dll,OLEAUT32.dll,msvcp_win.dll,IPHLPAPI.DLL,rfxvmt.dll,pdh.dll,SHELL32.dll,CRYPTBASE.dll,bcrypt.dll,cfgmgr32.dll,ncrypt.dll,windows.storage.dll,USERENV.dll,WINHTTP.dll,powrprof.dll,profapi.dll,shlwapi.dll,shcore.dll,Secur32.dll,SETUPAPI.dll,NTASN1.dll,AUTHZ.dll,PROPSYS.dll,wer.dll,tlscsp.dll,DPAPI.DLL,umb.dll,ATL.DLL,nlasvc.dll,dhcpcsvc.DLL,WINNSI.DLL,ncsi.dll,NSI.dll,DEVOBJ.dll,ntmarta.dll,ssdpapi.dll,WMICLNT.dll,dhcpcsvc6.DLL,WlanApi.dll,mswsock.dll,wshqos.dll,wshtcpip.DLL,wship6.dll,wkscli.dll,netjoin.dll,JoinUtil.dll,netutils.dll,dnsrslvr.dll,DNSAPI.dll,Fwpuclnt.dll,dnsext.dll,winsta.dll,wevtapi.dll,gpapi.dll,wtsapi32.dll,wkssvc.dll,DSPARSE.dll,taskschd.dll,cryptsvc.dll,crypttpmeksvc.dll,cryptcatsvc.dll,VSSAPI.DLL,VssTrace.DLL,samcli.dll,SAMLIB.dll,ES.DLL,ESENT.dll" "svchost.exe","1072","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,lmhsvc.dll,WS2_32.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,nrpsrv.DLL,wevtsvc.dll,bcrypt.dll,powrprof.dll,sspicli.dll,mswsock.dll,gpapi.dll,dhcpcore.dll,DNSAPI.dll,NSI.dll,IPHLPAPI.DLL,firewallapi.dll,fwbase.dll,dhcpcore6.dll,WINNSI.DLL,dhcpcsvc6.DLL,dhcpcsvc.DLL,CRYPTBASE.dll,timebrokerserver.dll,BrokerLib.dll,bi.dll,msvcp_win.dll,profapi.dll,clbcatq.dll,NgcCtnr.dll,DPAPI.DLL,twinapi.appcore.dll,usermgrcli.dll,ole32.dll,coml2.dll,OneCoreCommonProxyStub.dll,execmodelproxy.dll,winrnr.dll,rasadhlp.dll,NLAapi.dll,napinsp.dll,pnrpnsp.dll,fwpuclnt.dll,wscsvc.dll,netutils.dll,OLEAUT32.dll,wbemprox.dll,wbemcomn.dll,wbemsvc.dll,fastprox.dll,WINHTTP.dll,ADVAPI32.dll,USERENV.dll" "svchost.exe","1104","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,cfgmgr32.dll,ADVAPI32.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,PortableDeviceApi.dll,clbcatq.dll,SHLWAPI.dll,SETUPAPI.dll,DEVOBJ.dll,portabledeviceconnectapi.dll,powrprof.dll,shcore.dll,WTSAPI32.dll,WINSTA.dll,audioendpointbuilder.dll,bcrypt.dll,MMDevAPI.DLL,PROPSYS.dll,OLEAUT32.dll,msvcp_win.dll,umrdp.dll,WINSPOOL.DRV,umb.dll,ATL.DLL,sspicli.dll,das.dll,RMCLIENT.dll,profapi.dll,sysmain.dll,trkwks.dll,ntmarta.dll,ncrypt.dll,USERENV.dll,netutils.dll,NTASN1.dll,fhcfg.dll,ole32.dll,SHELL32.dll,windows.storage.dll,wevtapi.dll,MPR.dll,XmlLite.dll,EFSUTIL.dll,NETAPI32.dll,DSROLE.dll,SRVCLI.DLL,bi.dll,SystemEventsBrokerClient.dll,taskschd.dll,coml2.dll,OneCoreCommonProxyStub.dll,ActXPrxy.dll" "svchost.exe","1188","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,es.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,nsisvc.dll,clbcatq.dll,OLEAUT32.dll,msvcp_win.dll,advapi32.dll,NSI.dll,fntcache.dll,profapi.dll,FontProvider.dll,netprofmsvc.dll,nlaapi.dll,npmproxy.dll,ole32.dll,IPHLPAPI.DLL,windows.devices.radios.dll,cfgmgr32.dll,WINNSI.DLL,WS2_32.dll,gpapi.dll,winhttp.dll,mswsock.dll,powrprof.dll,dhcpcsvc6.DLL,DNSAPI.dll,dhcpcsvc.DLL,rasadhlp.dll,sxs.dll,wdi.dll,perftrack.dll,PROPSYS.dll,shcore.dll,cdpsvc.dll,sbservicetrigger.dll,cdp.dll,VEEventDispatcher.dll,ncrypt.dll,SspiCli.dll,bcrypt.dll,msvcp110_win.dll,NTASN1.dll" "svchost.exe","1376","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,ipsecsvc.dll,msvcrt.dll,FirewallAPI.dll,AUTHZ.dll,fwpuclnt.dll,FwRemoteSvr.DLL,bcrypt.dll,combase.dll,bcryptPrimitives.dll,fwbase.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,kernel.appcore.dll,clbcatq.dll,OLEAUT32.dll,msvcp_win.dll,WS2_32.dll,mswsock.dll,IPHLPAPI.DLL,NSI.dll,dhcpcsvc6.DLL,dhcpcsvc.DLL,sspicli.dll" "svchost.exe","1492","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,coremessaging.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,bfe.dll,WS2_32.dll,AUTHZ.dll,SspiCli.dll,wevtapi.dll,bcrypt.dll,dps.dll,clbcatq.dll,taskschd.dll,OLEAUT32.dll,msvcp_win.dll,gpapi.dll,wdi.dll,diagperf.dll,pnpts.dll,srumsvc.dll,IPHLPAPI.DLL,ESENT.dll,CRYPTBASE.DLL,eeprov.dll,powrprof.dll,shcore.dll,DEVOBJ.dll,cfgmgr32.dll,appsruprov.dll,nduprov.dll,wpnsruprov.dll,ncuprov.dll,NSI.dll,WINNSI.DLL,energyprov.dll,advapi32.dll,srumapi.dll,ole32.dll,ktmw32.dll,radardt.dll,ntmarta.dll,VERSION.dll" "svchost.exe","1516","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,audiosrv.dll,msvcp_win.dll,MMDevAPI.DLL,PROPSYS.dll,AUDIOSRVPOLICYMANAGER.dll,DEVOBJ.dll,OLEAUT32.dll,cfgmgr32.dll,shcore.dll,POWRPROF.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,clbcatq.dll,winsta.dll,wtsapi32.dll,coreaudiopolicymanagerext.dll,audioses.dll,wintypes.dll,deviceaccess.dll" "svchost.exe","184","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,rpcepmap.dll,WLDP.DLL,msvcrt.dll,combase.dll,bcryptPrimitives.dll,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,sspicli.dll,RpcRtRemote.dll,rpcss.dll,WS2_32.dll,mswsock.dll,powrprof.dll,FirewallAPI.dll,fwbase.dll,clbcatq.dll,wshhyperv.dll,fwpuclnt.dll,bcrypt.dll,advapi32.dll,kernel.appcore.dll,OLEAUT32.dll,msvcp_win.dll,capauthz.dll" "svchost.exe","2356","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,windows.staterepository.dll,StateRepository.Core.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,clbcatq.dll,tileobjserver.dll,advapi32.dll,msvcp110_win.dll,ESENT.dll,shcore.dll,urlmon.dll,shlwapi.dll,iertutil.dll,USERENV.dll,profapi.dll,wtsapi32.dll,WINSTA.dll,windows.storage.dll,powrprof.dll,SspiCli.dll,CRYPTBASE.DLL,ActXPrxy.dll,Bcrypt.dll,mrmcorer.dll,OLEAUT32.dll,msvcp_win.dll" "svchost.exe","2476","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,wiaservc.dll,msvcrt.dll,ADVAPI32.dll,USER32.dll,win32u.dll,GDI32.dll,gdi32full.dll,OLEAUT32.dll,msvcp_win.dll,combase.dll,bcryptPrimitives.dll,ole32.dll,VERSION.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,wiatrace.dll,kernel.appcore.dll,sspicli.dll,msv1_0.DLL,NtlmShared.dll,bcrypt.dll,cryptdll.dll,powrprof.dll,cfgmgr32.dll,clbcatq.dll,SETUPAPI.dll,WSDCHNGR.DLL,deviceassociation.dll,DEVOBJ.dll,FunDisc.dll,XmlLite.dll,fdPnp.dll,ATL.DLL,WSDScDrv.dll,wsdapi.dll,WS2_32.dll,gdiplus.dll,NSI.dll,IPHLPAPI.DLL,webservices.dll,FirewallAPI.dll,fwbase.dll,mswsock.dll,dhcpcsvc6.DLL,dhcpcsvc.DLL,WINNSI.DLL,WSDScanProxy.dll,WINHTTP.dll,ondemandconnroutehelper.dll,webio.dll,DNSAPI.dll,HTTPAPI.dll" "svchost.exe","756","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,devicesetupmanager.dll,cfgmgr32.dll,powrprof.dll,USERENV.dll,ntmarta.dll,profapi.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,clbcatq.dll,netprofm.dll,themeservice.dll,profsvc.dll,OLEAUT32.dll,msvcp_win.dll,gpsvc.dll,SYSNTFY.dll,nlaapi.dll,winsta.dll,DSROLE.dll,profsvcext.dll,WLDAP32.dll,SHELL32.dll,netutils.dll,logoncli.dll,windows.storage.dll,advapi32.dll,shlwapi.dll,shcore.dll,gpapi.dll,schedsvc.dll,UBPM.dll,EventAggregation.dll,SspiCli.dll,sens.dll,AUTHZ.dll,WS2_32.dll,WMICLNT.dll,bcrypt.dll,taskcomp.dll,cryptsp.dll,WPTaskScheduler.dll,CSystemEventsBrokerClient.dll,wkscli.dll,netjoin.dll,mswsock.dll,JoinUtil.dll,wtsapi32.dll,DABAPI.dll,TimeBrokerClient.dll,usermgr.dll,wintypes.dll,npmproxy.dll,usermgrproxy.dll,shsvcs.dll,DEVOBJ.dll,DevPropMgr.dll,PROPSYS.dll,DeviceDriverRetrievalClient.dll,SETUPAPI.dll,newdev.dll,UxTheme.dll,devrtl.DLL,FVEAPI.dll,wevtapi.dll,certprop.dll,WinSCard.dll,WMsgAPI.dll,ProximityService.dll,ProximityCommon.dll,IPHLPAPI.DLL,ProximityCommonPal.dll,ProximityServicePAL.dll,firewallapi.dll,fwbase.dll,HID.DLL,sessenv.dll,samcli.dll,XmlLite.dll,rsaenh.dll,DPAPI.dll,CRYPTBASE.dll,ncrypt.dll,NTASN1.dll,ikeext.dll,NSI.dll,fwpuclnt.dll,srvsvc.dll,WINNSI.DLL,SSCORE.DLL,dhcpcsvc6.DLL,sscoreext.dll,dhcpcsvc.DLL,mi.dll,miutils.dll,wmidcom.dll,RESUTILS.DLL,CLUSAPI.dll,DNSAPI.dll,browser.dll,rasadhlp.dll,SAMLIB.dll,DeviceMetadataRetrievalClient.dll,WINHTTP.dll,Cabinet.dll,wer.dll,ondemandconnroutehelper.dll,wmisvc.dll,wbemcomn.dll,wpnservice.dll,iphlpsvc.dll,rtutils.dll,NetSetupApi.dll,wpncore.dll,cdp.dll,winsqlite3.dll,urlmon.dll,iertutil.dll,VEEventDispatcher.dll,msvcp110_win.dll,sqmapi.dll,httpprxm.dll,adhsvc.dll,httpprxc.dll,ACTIVEDS.dll,adsldpc.dll,WDSCORE.dll,hnetcfgclient.dll,ole32.dll,VSSAPI.DLL,VssTrace.DLL,sxs.dll,ES.DLL,NETAPI32.DLL,SECUR32.DLL,cscapi.dll,wbemcore.dll,FastProx.dll,esscli.dll,wbemsvc.dll,wmiutils.dll,repdrvfs.dll,wmiprvsd.dll,NCObjAPI.DLL,wbemess.dll,FWPolicyIOMgr.dll,srvcli.dll,usermgrcli.dll,apphelp.dll,ncprov.dll,webio.dll,FlightSettings.dll,bcd.dll,policymanager.dll,Comctl32.dll" "svchost.exe","944","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,umpnpmgr.dll,msvcrt.dll,WLDP.DLL,combase.dll,bcryptPrimitives.dll,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,umpo.dll,umpoext.dll,cfgmgr32.dll,powrprof.dll,dxgi.dll,tdh.dll,win32u.dll,gdi32.dll,gdi32full.dll,USER32.dll,mintdh.dll,OLEAUT32.dll,msvcp_win.dll,gpapi.dll,HID.DLL,windows.storage.dll,advapi32.dll,shlwapi.dll,kernel.appcore.dll,shcore.dll,profapi.dll,rpcss.dll,SspiCli.dll,bisrv.dll,ntmarta.dll,EventAggregation.dll,psmsrv.dll,DEVOBJ.dll,ResourcePolicyClient.dll,VEEventDispatcher.dll,msvcp110_win.dll,twinapi.appcore.dll,bcrypt.dll,lsm.dll,SYSNTFY.dll,clbcatq.dll,embeddedmodesvcapi.dll,psmserviceexthost.dll,resourcepolicyserver.dll,CRYPTSP.dll,Userenv.dll,systemeventsbrokerserver.dll,BrokerLib.dll,DAB.dll,bi.dll,lsmproxy.dll,usermgrcli.dll,CRYPTBASE.DLL,wtsapi32.dll,WINSTA.dll,OneCoreUAPCommonProxyStub.dll,RmClient.dll,BackgroundMediaPolicy.dll,ACPBackgroundManagerPolicy.dll,CbtBackgroundManagerPolicy.dll,SmartCardBackgroundPolicy.dll,Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll,SebBackgroundManagerPolicy.dll,ole32.dll,coml2.dll,OneCoreCommonProxyStub.dll,ActXPrxy.dll,execmodelproxy.dll,rsaenh.dll,licensemanagerapi.dll,capauthz.dll" "taskhostw.exe","3560","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,RPCRT4.dll,combase.dll,ucrtbase.dll,bcryptPrimitives.dll,OLEAUT32.dll,msvcp_win.dll,imm32.dll,USER32.dll,win32u.dll,GDI32.dll,gdi32full.dll,kernel.appcore.dll,sechost.dll,uxtheme.dll,dwmapi.dll,clbcatq.dll,wininet.dll,MsCtfMonitor.dll,MSCTF.dll,WINSTA.dll,MSUTB.dll,iertutil.dll,advapi32.dll,shcore.dll,InputService.dll,CoreMessaging.dll,CoreUIComponents.dll,wintypes.dll,EditBufferTestHook.dll,TextInputFramework.dll,ESENT.dll,ole32.dll,PlaySndSrv.dll,windows.storage.dll,powrprof.dll,shlwapi.dll,profapi.dll,MTFServer.dll,WINMM.dll,WINMMBASE.dll,cfgmgr32.dll,InputLocaleManager.dll,kbdus.dll,policymanager.dll,msvcp110_win.dll,CRYPTBASE.DLL" "tasklist.exe","1548","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,ADVAPI32.dll,msvcrt.dll,sechost.dll,RPCRT4.dll,USER32.dll,win32u.dll,GDI32.dll,gdi32full.dll,OLEAUT32.dll,msvcp_win.dll,VERSION.dll,MPR.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,WS2_32.dll,SHLWAPI.dll,framedynos.dll,dbghelp.dll,SspiCli.dll,netutils.dll,srvcli.dll,IMM32.DLL,kernel.appcore.dll,clbcatq.dll,wbemprox.dll,wbemcomn.dll,bcrypt.dll,Winsta.dll,wbemsvc.dll,fastprox.dll,wmiutils.dll" "TSVNCache.exe","4792","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,USER32.dll,win32u.dll,libsvn_tsvn.dll,libapr_tsvn.dll,GDI32.dll,gdi32full.dll,ADVAPI32.dll,WS2_32.dll,msvcrt.dll,sechost.dll,RPCRT4.dll,SHELL32.dll,libaprutil_tsvn.dll,ole32.dll,cfgmgr32.dll,combase.dll,WLDAP32.dll,windows.storage.dll,ucrtbase.dll,intl3_tsvn.dll,powrprof.dll,bcryptPrimitives.dll,shlwapi.dll,libsasl.dll,kernel.appcore.dll,shcore.dll,VCRUNTIME140.dll,profapi.dll,CRYPT32.dll,MSVCP140.dll,MSASN1.dll,CRYPTBASE.DLL,VERSION.dll,Secur32.dll,SSPICLI.DLL,MSWSOCK.dll,IMM32.DLL,crshhndl.dll,uxtheme.dll,PROPSYS.dll,OLEAUT32.dll,msvcp_win.dll,ntmarta.dll,MSCTF.dll,dwmapi.dll" "vmtoolsd.exe","2348","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,ADVAPI32.dll,msvcrt.dll,sechost.dll,RPCRT4.dll,ole32.dll,combase.dll,ucrtbase.dll,bcryptPrimitives.dll,GDI32.dll,gdi32full.dll,USER32.dll,win32u.dll,VERSION.dll,intl.dll,glib-2.0.dll,gmodule-2.0.dll,MSVCR90.dll,gobject-2.0.dll,gthread-2.0.dll,WS2_32.dll,vmtools.dll,SHELL32.dll,cfgmgr32.dll,windows.storage.dll,iconv.dll,powrprof.dll,shlwapi.dll,kernel.appcore.dll,shcore.dll,profapi.dll,OLEAUT32.dll,msvcp_win.dll,IpHlpApi.dll,ntmarta.dll,hgfsServer.dll,hgfs.dll,MPR.dll,hgfsUsability.dll,USERENV.dll,vix.dll,Secur32.dll,SSPICLI.DLL,autoLogon.dll,MSVCP90.dll,autoUpgrade.dll,WTSAPI32.dll,bitMapper.dll,deployPkgPlugin.dll,deployPkg.dll,diskWiper.dll,guestInfo.dll,hwUpgradeHelper.dll,SETUPAPI.dll,powerOps.dll,resolutionSet.dll,PSAPI.DLL,timeSync.dll,vmbackup.dll,clbcatq.dll,wbemprox.dll,wbemcomn.dll,bcrypt.dll,NSI.dll,dhcpcsvc6.DLL,dhcpcsvc.DLL,wbemsvc.dll,fastprox.dll,comsvcs.dll,CRYPTSP.dll,rsaenh.dll,CRYPTBASE.dll,sxs.dll,DNSAPI.dll,WINNSI.DLL,perfos.dll,perfproc.dll,perfdisk.dll,WMICLNT.dll" "vmtoolsd.exe","3064","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,ADVAPI32.dll,msvcrt.dll,sechost.dll,RPCRT4.dll,ole32.dll,combase.dll,ucrtbase.dll,bcryptPrimitives.dll,GDI32.dll,gdi32full.dll,USER32.dll,win32u.dll,VERSION.dll,intl.dll,glib-2.0.dll,MSVCR90.dll,gmodule-2.0.dll,gobject-2.0.dll,gthread-2.0.dll,WS2_32.dll,vmtools.dll,SHELL32.dll,cfgmgr32.dll,windows.storage.dll,powrprof.dll,shlwapi.dll,kernel.appcore.dll,shcore.dll,profapi.dll,OLEAUT32.dll,msvcp_win.dll,iconv.dll,IMM32.DLL,IpHlpApi.dll,uxtheme.dll,MSCTF.dll,hgfsServer.dll,hgfs.dll,MPR.dll,hgfsUsability.dll,USERENV.dll,vix.dll,Secur32.dll,SSPICLI.DLL,desktopEvents.dll,WTSAPI32.dll,MSVCP90.dll,dndcp.dll,sigc-2.0.dll,unity.dll,PSAPI.DLL,glibmm-2.4.dll,dwmapi.dll,WINSTA.dll,clbcatq.dll,dataexchange.dll,d3d11.dll,dcomp.dll,dxgi.dll,twinapi.appcore.dll,bcrypt.dll,VMToolsHook64.dll,gdiplus.dll,PROPSYS.dll,Windows.Shell.ServiceHostBuilder.dll,ActXPrxy.dll,WinTypes.dll,comctl32.dll,WindowsCodecs.dll,msxml3.dll,AppxPackaging.dll,OpcServices.DLL,urlmon.dll,XmlLite.dll,iertutil.dll,msxml6.dll,CRYPT32.dll,MSASN1.dll,mrmcorer.dll,Windows.UI.dll,Bcp47Langs.dll,LINKINFO.dll,apphelp.dll,gameux.dll,WININET.dll,TwinUI.dll,ieframe.dll,NETAPI32.dll,NETUTILS.DLL,WKSCLI.DLL,MLANG.dll,IconCodecService.dll,thumbcache.dll,edputil.dll" "Windows10FirewallControl.exe","4144","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,USER32.dll,win32u.dll,GDI32.dll,gdi32full.dll,comdlg32.dll,msvcrt.dll,combase.dll,MSIMG32.dll,ucrtbase.dll,RPCRT4.dll,bcryptPrimitives.dll,shcore.dll,SHLWAPI.dll,SHELL32.dll,COMCTL32.dll,cfgmgr32.dll,windows.storage.dll,powrprof.dll,advapi32.dll,sechost.dll,kernel.appcore.dll,profapi.dll,ole32.dll,WINSPOOL.DRV,OLEAUT32.dll,msvcp_win.dll,WS2_32.dll,iphlpapi.dll,NETAPI32.dll,VERSION.dll,WINMM.dll,USERENV.dll,MPR.dll,WINMMBASE.dll,bcrypt.dll,SAMCLI.DLL,NETUTILS.DLL,IMM32.DLL,uxtheme.dll,RICHED20.DLL,msls31.dll,USP10.dll,clbcatq.dll,sxs.dll,MSCTF.dll,WINNSI.DLL,NSI.dll,dwmapi.dll,WindowsCodecs.dll,upnp.dll,WINHTTP.dll,SSDPAPI.dll" "Windows10FirewallService.exe","1256","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,USER32.dll,fwpuclnt.dll,win32u.dll,msvcrt.dll,GDI32.dll,gdi32full.dll,RPCRT4.dll,ADVAPI32.dll,bcrypt.dll,sechost.dll,SHELL32.dll,cfgmgr32.dll,windows.storage.dll,combase.dll,ucrtbase.dll,bcryptPrimitives.dll,powrprof.dll,shlwapi.dll,kernel.appcore.dll,shcore.dll,profapi.dll,ole32.dll,OLEAUT32.dll,msvcp_win.dll,WS2_32.dll,USERENV.dll,CRYPT32.dll,MSWSOCK.dll,MSASN1.dll,PSAPI.DLL,wevtapi.dll,iphlpapi.dll,DNSAPI.dll,NSI.dll,VERSION.dll,NETAPI32.dll,SAMCLI.DLL,NETUTILS.DLL,clbcatq.dll,secur32.dll,SSPICLI.DLL,security.dll,wshqos.dll,wshtcpip.DLL,wship6.dll,dhcpcsvc6.DLL,dhcpcsvc.DLL,sxs.dll,browcli.dll,cscapi.dll" "winlogon.exe","1008","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,sechost.dll,RPCRT4.dll,powrprof.dll,bcrypt.dll,ucrtbase.dll,advapi32.dll,profapi.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,IMM32.DLL,winsta.dll,UXINIT.dll,shcore.dll,combase.dll,bcryptPrimitives.dll,UxTheme.dll,CRYPT32.dll,MSASN1.dll,DPAPI.dll,CRYPTBASE.dll,dwminit.dll,SspiCli.dll,apphelp.dll,UxTSB.dll,ole32.dll,MSIMG32.dll,dbghelp.dll,usermgrcli.dll,ntmarta.dll,CRYPTSP.dll,rsaenh.dll,WindowsCodecs.dll,MPR.dll" "WizMouse.exe","4560","ntdll.dll,wow64.dll,wow64win.dll,wow64cpu.dll" "WmiPrvSE.exe","4092","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,FastProx.dll,wbemcomn.dll,NCObjAPI.DLL,combase.dll,WS2_32.dll,bcrypt.dll,ucrtbase.dll,sechost.dll,RPCRT4.dll,bcryptPrimitives.dll,advapi32.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,kernel.appcore.dll,clbcatq.dll,wbemprox.dll,OLEAUT32.dll,msvcp_win.dll,wbemsvc.dll,wmiutils.dll,cimwin32.dll,powrprof.dll,framedynos.dll,SspiCli.dll,winbrand.dll" ------------------------------------------------------------------------------------------- SCHTASKS /Query /FO CSV (states of all scheduled tasks): "\Adobe Acrobat Update Task","N/A","Disabled" "\Adobe Uninstaller","N/A","Disabled" "\AdobeAAMUpdater-1.0-W10PVM-NoelC","N/A","Disabled" "\Aero Glass","N/A","Running" "\DisableLockScreen","N/A","Ready" "\DisableLockScreen","N/A","Ready" "\GoogleUpdateTaskMachineCore","N/A","Disabled" "\GoogleUpdateTaskMachineCore","N/A","Disabled" "\GoogleUpdateTaskMachineUA","N/A","Disabled" "\SpeechRuntimeTask","N/A","Disabled" "\WizMouse","N/A","Ready" "\WizMouse","N/A","Ready" "\Microsoft\VisualStudio\VSIX Auto Update 14","N/A","Disabled" "\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319","N/A","Disabled" "\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64","N/A","Disabled" "\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Critical","N/A","Disabled" "\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Critical","N/A","Disabled" "\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)","N/A","Disabled" "\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)","N/A","Disabled" "\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)","N/A","Disabled" "\Microsoft\Windows\AppID\EDP Policy Manager","N/A","Disabled" "\Microsoft\Windows\AppID\EDP Policy Manager","N/A","Disabled" "\Microsoft\Windows\AppID\PolicyConverter","N/A","Disabled" "\Microsoft\Windows\AppID\SmartScreenSpecific","N/A","Disabled" "\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck","N/A","Disabled" "\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser","N/A","Disabled" "\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser","N/A","Disabled" "\Microsoft\Windows\Application Experience\ProgramDataUpdater","N/A","Disabled" "\Microsoft\Windows\Application Experience\StartupAppTask","N/A","Disabled" "\Microsoft\Windows\ApplicationData\appuriverifierdaily","N/A","Disabled" "\Microsoft\Windows\ApplicationData\appuriverifierinstall","N/A","Disabled" "\Microsoft\Windows\ApplicationData\appuriverifierinstall","N/A","Disabled" "\Microsoft\Windows\ApplicationData\CleanupTemporaryState","N/A","Disabled" "\Microsoft\Windows\ApplicationData\DsSvcCleanup","N/A","Disabled" "\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup","N/A","Disabled" "\Microsoft\Windows\Autochk\Proxy","N/A","Disabled" "\Microsoft\Windows\Bluetooth\UninstallDeviceTask","N/A","Disabled" "\Microsoft\Windows\CertificateServicesClient\AikCertEnrollTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\CryptoPolicyTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\KeyPreGenTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\KeyPreGenTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\KeyPreGenTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\KeyPreGenTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\KeyPreGenTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\SystemTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\SystemTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\SystemTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\UserTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\UserTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\UserTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\UserTask-Roam","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\UserTask-Roam","N/A","Ready" "\Microsoft\Windows\Chkdsk\ProactiveScan","N/A","Ready" "\Microsoft\Windows\Clip\License Validation","N/A","Disabled" "\Microsoft\Windows\CloudExperienceHost\CreateObjectTask","N/A","Disabled" "\Microsoft\Windows\Customer Experience Improvement Program\Consolidator","N/A","Disabled" "\Microsoft\Windows\Customer Experience Improvement Program\HypervisorFlightingTask","N/A","Disabled" "\Microsoft\Windows\Customer Experience Improvement Program\KernelCeipTask","N/A","Disabled" "\Microsoft\Windows\Customer Experience Improvement Program\UsbCeip","N/A","Disabled" "\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan","12/25/2016 6:36:00 PM","Ready" "\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan","12/30/2016 11:27:52 AM","Ready" "\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan for Crash Recovery","N/A","Ready" "\Microsoft\Windows\Defrag\ScheduledDefrag","N/A","Ready" "\Microsoft\Windows\Device Information\Device","N/A","Disabled" "\Microsoft\Windows\Device Information\Device","N/A","Disabled" "\Microsoft\Windows\Device Setup\Metadata Refresh","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\HandleCommand","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\HandleWnsCommand","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\IntegrityCheck","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\LocateCommandUserSession","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceAccountChange","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceAccountChange","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceConnectedToNetwork","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceLocationRightsChange","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePeriodic1","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePeriodic24","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePeriodic6","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePolicyChange","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePolicyChange","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceScreenOnOff","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceScreenOnOff","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceSettingChange","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterUserDevice","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterUserDevice","N/A","Disabled" "\Microsoft\Windows\Diagnosis\Scheduled","N/A","Ready" "\Microsoft\Windows\DiskCleanup\SilentCleanup","N/A","Disabled" "\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector","N/A","Disabled" "\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver","N/A","Disabled" "\Microsoft\Windows\DiskFootprint\Diagnostics","N/A","Ready" "\Microsoft\Windows\DiskFootprint\StorageSense","N/A","Ready" "\Microsoft\Windows\DUSM\dusmtask","N/A","Disabled" "\Microsoft\Windows\EDP\EDP App Launch Task","N/A","Disabled" "\Microsoft\Windows\EDP\EDP Auth Task","N/A","Disabled" "\Microsoft\Windows\EnterpriseMgmt\MDMMaintenenceTask","N/A","Disabled" "\Microsoft\Windows\ErrorDetails\EnableErrorDetailsUpdate","N/A","Disabled" "\Microsoft\Windows\ErrorDetails\ErrorDetailsUpdate","N/A","Disabled" "\Microsoft\Windows\Feedback\Siuf\DmClient","N/A","Disabled" "\Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload","N/A","Disabled" "\Microsoft\Windows\File Classification Infrastructure\Property Definition Sync","N/A","Disabled" "\Microsoft\Windows\FileHistory\File History (maintenance mode)","N/A","Disabled" "\Microsoft\Windows\LanguageComponentsInstaller\Installation","N/A","Disabled" "\Microsoft\Windows\LanguageComponentsInstaller\Installation","N/A","Disabled" "\Microsoft\Windows\LanguageComponentsInstaller\Uninstallation","N/A","Disabled" "\Microsoft\Windows\License Manager\TempSignedLicenseExchange","N/A","Disabled" "\Microsoft\Windows\Location\Notifications","N/A","Disabled" "\Microsoft\Windows\Location\WindowsActionDialog","N/A","Disabled" "\Microsoft\Windows\Maintenance\WinSAT","N/A","Ready" "\Microsoft\Windows\Management\Provisioning\Logon","N/A","Disabled" "\Microsoft\Windows\Maps\MapsToastTask","N/A","Disabled" "\Microsoft\Windows\Maps\MapsUpdateTask","N/A","Disabled" "\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents","N/A","Ready" "\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents","N/A","Ready" "\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents","N/A","Ready" "\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents","N/A","Ready" "\Microsoft\Windows\MemoryDiagnostic\RunFullMemoryDiagnostic","N/A","Ready" "\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser","N/A","Disabled" "\Microsoft\Windows\MUI\LPRemove","N/A","Disabled" "\Microsoft\Windows\Multimedia\SystemSoundsService","N/A","Running" "\Microsoft\Windows\NetCfg\BindingWorkItemQueueHandler","N/A","Disabled" "\Microsoft\Windows\NetTrace\GatherNetworkInfo","N/A","Disabled" "\Microsoft\Windows\NlaSvc\WiFiTask","N/A","Disabled" "\Microsoft\Windows\Offline Files\Background Synchronization","N/A","Disabled" "\Microsoft\Windows\Offline Files\Logon Synchronization","N/A","Disabled" "\Microsoft\Windows\PI\Secure-Boot-Update","N/A","Disabled" "\Microsoft\Windows\PI\Sqm-Tasks","N/A","Disabled" "\Microsoft\Windows\Plug and Play\Device Install Group Policy","N/A","Ready" "\Microsoft\Windows\Plug and Play\Device Install Reboot Required","N/A","Ready" "\Microsoft\Windows\Plug and Play\Plug and Play Cleanup","N/A","Ready" "\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers","N/A","Ready" "\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem","N/A","Disabled" "\Microsoft\Windows\Ras\MobilityManager","N/A","Disabled" "\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE","N/A","Disabled" "\Microsoft\Windows\Registry\RegIdleBackup","N/A","Ready" "\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask","N/A","Disabled" "\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask","N/A","Disabled" "\Microsoft\Windows\RetailDemo\CleanupOfflineContent","N/A","Disabled" "\Microsoft\Windows\Servicing\StartComponentCleanup","N/A","Disabled" "\Microsoft\Windows\SettingSync\BackupTask","N/A","Disabled" "\Microsoft\Windows\SettingSync\NetworkStateChangeTask","N/A","Disabled" "\Microsoft\Windows\SettingSync\NetworkStateChangeTask","N/A","Disabled" "\Microsoft\Windows\Setup\SetupCleanupTask","N/A","Disabled" "\Microsoft\Windows\SharedPC\Account Cleanup","N/A","Disabled" "\Microsoft\Windows\Shell\CreateObjectTask","N/A","Disabled" "\Microsoft\Windows\Shell\FamilySafetyMonitor","N/A","Disabled" "\Microsoft\Windows\Shell\FamilySafetyMonitorToastTask","N/A","Disabled" "\Microsoft\Windows\Shell\FamilySafetyRefreshTask","N/A","Disabled" "\Microsoft\Windows\Shell\IndexerAutomaticMaintenance","N/A","Disabled" "\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask","N/A","Disabled" "\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskLogon","N/A","Disabled" "\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskNetwork","N/A","Disabled" "\Microsoft\Windows\SpacePort\SpaceAgentTask","N/A","Ready" "\Microsoft\Windows\SpacePort\SpaceAgentTask","N/A","Ready" "\Microsoft\Windows\SpacePort\SpaceManagerTask","N/A","Ready" "\Microsoft\Windows\SpacePort\SpaceManagerTask","N/A","Ready" "\Microsoft\Windows\Speech\SpeechModelDownloadTask","N/A","Disabled" "\Microsoft\Windows\Storage Tiers Management\Storage Tiers Management Initialization","N/A","Disabled" "\Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization","N/A","Disabled" "\Microsoft\Windows\Subscription\EnableLicenseAcquisition","N/A","Disabled" "\Microsoft\Windows\Subscription\EnableLicenseAcquisition","N/A","Disabled" "\Microsoft\Windows\Subscription\EnableLicenseAcquisition","N/A","Disabled" "\Microsoft\Windows\Subscription\LicenseAcquisition","N/A","Disabled" "\Microsoft\Windows\Subscription\LicenseAcquisition","N/A","Disabled" "\Microsoft\Windows\Subscription\LicenseAcquisition","N/A","Disabled" "\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate","N/A","Disabled" "\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance","N/A","Disabled" "\Microsoft\Windows\Sysmain\ResPriStaticDbSync","N/A","Disabled" "\Microsoft\Windows\Sysmain\WsSwapAssessmentTask","N/A","Disabled" "\Microsoft\Windows\SystemRestore\SR","N/A","Ready" "\Microsoft\Windows\Task Manager\Interactive","N/A","Ready" "\Microsoft\Windows\TextServicesFramework\MsCtfMonitor","N/A","Running" "\Microsoft\Windows\Time Synchronization\ForceSynchronizeTime","N/A","Ready" "\Microsoft\Windows\Time Synchronization\SynchronizeTime","N/A","Ready" "\Microsoft\Windows\Time Zone\SynchronizeTimeZone","N/A","Ready" "\Microsoft\Windows\TPM\Tpm-HASCertRetr","N/A","Disabled" "\Microsoft\Windows\TPM\Tpm-Maintenance","N/A","Disabled" "\Microsoft\Windows\TPM\Tpm-Maintenance","N/A","Disabled" "\Microsoft\Windows\TPM\Tpm-Maintenance","N/A","Disabled" "\Microsoft\Windows\TPM\Tpm-Maintenance","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\Maintenance Install","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\Policy Install","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\Reboot","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\Refresh Settings","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\Resume On Boot","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\Schedule Scan","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\Schedule Scan","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\Schedule Scan","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\USO_RebootDisplay","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_WnfDisplay","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\USO_WnfDisplay","N/A","Disabled" "\Microsoft\Windows\UPnP\UPnPHostConfig","N/A","Disabled" "\Microsoft\Windows\User Profile Service\HiveUploadTask","N/A","Disabled" "\Microsoft\Windows\WCM\WiFiTask","N/A","Disabled" "\Microsoft\Windows\WDI\ResolutionHost","N/A","Disabled" "\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance","N/A","Ready" "\Microsoft\Windows\Windows Defender\Windows Defender Cleanup","N/A","Ready" "\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan","N/A","Ready" "\Microsoft\Windows\Windows Defender\Windows Defender Verification","N/A","Ready" "\Microsoft\Windows\Windows Error Reporting\QueueReporting","N/A","Disabled" "\Microsoft\Windows\Windows Error Reporting\QueueReporting","N/A","Disabled" "\Microsoft\Windows\Windows Error Reporting\QueueReporting","N/A","Disabled" "\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange","N/A","Disabled" "\Microsoft\Windows\Windows Media Sharing\UpdateLibrary","N/A","Disabled" "\Microsoft\Windows\WindowsColorSystem\Calibration Loader","N/A","Disabled" "\Microsoft\Windows\WindowsColorSystem\Calibration Loader","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUFirmwareInstall","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUScheduledInstall","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUSessionConnect","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUSessionConnect","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUSessionConnect","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUSessionConnect","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUSessionConnect","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\Automatic App Update","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\Automatic App Update","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\Scheduled Start","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\Scheduled Start","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\Scheduled Start","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\Scheduled Start","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\sih","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\sihboot","N/A","Disabled" "\Microsoft\Windows\Wininet\CacheTask","N/A","Running" "\Microsoft\Windows\WOF\WIM-Hash-Management","N/A","Ready" "\Microsoft\Windows\WOF\WIM-Hash-Management","N/A","Ready" "\Microsoft\Windows\WOF\WIM-Hash-Validation","N/A","Ready" "\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization","N/A","Disabled" "\Microsoft\Windows\Work Folders\Work Folders Maintenance Work","N/A","Disabled" "\Microsoft\Windows\Workplace Join\Automatic-Device-Join","N/A","Disabled" "\Microsoft\XblGameSave\XblGameSaveTask","N/A","Disabled" "\Microsoft\XblGameSave\XblGameSaveTaskLogon","N/A","Disabled" "\OfficeSoftwareProtectionPlatform\SvcRestartTask","N/A","Disabled" ------------------------------------------------------------------------------------------- SC qc (configurations of all services): C:\TEMP>SC qc "AdobeARMservice" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AdobeARMservice TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Adobe Acrobat Update Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "AdobeUpdateService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AdobeUpdateService TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : AdobeUpdateService DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "AGSService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AGSService TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Adobe Genuine Software Integrity Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "AJRouter" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AJRouter TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : AllJoyn Router Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "ALG" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: ALG TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\alg.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Application Layer Gateway Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "AppIDSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AppIDSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : ProfSvc_Group TAG : 0 DISPLAY_NAME : Application Identity DEPENDENCIES : RpcSs : AppID : CryptSvc SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "Appinfo" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Appinfo TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Application Information DEPENDENCIES : RpcSs : ProfSvc SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "AppMgmt" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AppMgmt TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Application Management DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "AppReadiness" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AppReadiness TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k AppReadiness LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : App Readiness DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "AppVClient" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AppVClient TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\AppVClient.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Microsoft App-V Client DEPENDENCIES : RpcSS : netprofm : AppvVfs : AppVStrm SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "AppXSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AppXSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k wsappx LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : AppX Deployment Service (AppXSVC) DEPENDENCIES : rpcss : staterepository SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "aspnet_state" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: aspnet_state TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : ASP.NET State Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "AudioEndpointBuilder" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AudioEndpointBuilder TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : AudioGroup TAG : 0 DISPLAY_NAME : Windows Audio Endpoint Builder DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Audiosrv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Audiosrv TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : AudioGroup TAG : 0 DISPLAY_NAME : Windows Audio DEPENDENCIES : AudioEndpointBuilder : RpcSs SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "AxInstSV" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AxInstSV TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k AxInstSVGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : ActiveX Installer (AxInstSV) DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "BDESVC" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: BDESVC TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : BitLocker Drive Encryption Service DEPENDENCIES : SERVICE_START_NAME : localSystem C:\TEMP>SC qc "BFE" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: BFE TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork LOAD_ORDER_GROUP : NetworkProvider TAG : 0 DISPLAY_NAME : Base Filtering Engine DEPENDENCIES : RpcSs SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "BITS" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: BITS TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START (DELAYED) ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Background Intelligent Transfer Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "BrokerInfrastructure" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: BrokerInfrastructure TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k DcomLaunch LOAD_ORDER_GROUP : COM Infrastructure TAG : 0 DISPLAY_NAME : Background Tasks Infrastructure Service DEPENDENCIES : RpcEptMapper : DcomLaunch : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Browser" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Browser TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : NetworkProvider TAG : 0 DISPLAY_NAME : Computer Browser DEPENDENCIES : LanmanWorkstation : LanmanServer SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "BthHFSrv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: BthHFSrv TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Bluetooth Handsfree Service DEPENDENCIES : bthserv SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "bthserv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: bthserv TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Bluetooth Support Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "CDPSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: CDPSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START (DELAYED) ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Connected Devices Platform Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "CDPUserSvc_354e6" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: CDPUserSvc_354e6 TYPE : e0 USER_SHARE_PROCESS INSTANCE START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : CDPUserSvc_354e6 DEPENDENCIES : SERVICE_START_NAME : C:\TEMP>SC qc "CertPropSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: CertPropSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Certificate Propagation DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "ClipSVC" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: ClipSVC TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k wsappx LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Client License Service (ClipSVC) DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "COMSysApp" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: COMSysApp TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : COM+ System Application DEPENDENCIES : RpcSs : EventSystem : SENS SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "CoreMessagingRegistrar" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: CoreMessagingRegistrar TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : CoreMessaging DEPENDENCIES : rpcss SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "CryptSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: CryptSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Cryptographic Services DEPENDENCIES : RpcSs SERVICE_START_NAME : NT Authority\NetworkService C:\TEMP>SC qc "CscService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: CscService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : ProfSvc_Group TAG : 0 DISPLAY_NAME : Offline Files DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "DcomLaunch" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DcomLaunch TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k DcomLaunch LOAD_ORDER_GROUP : COM Infrastructure TAG : 0 DISPLAY_NAME : DCOM Server Process Launcher DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "DcpSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DcpSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : DataCollectionPublishingService DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "defragsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: defragsvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k defragsvc LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Optimize drives DEPENDENCIES : RPCSS SERVICE_START_NAME : localSystem C:\TEMP>SC qc "DeviceAssociationService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DeviceAssociationService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Device Association Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "DeviceInstall" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DeviceInstall TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k DcomLaunch LOAD_ORDER_GROUP : PlugPlay TAG : 0 DISPLAY_NAME : Device Install Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "DevQueryBroker" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DevQueryBroker TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : DevQuery Background Discovery Broker DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Dhcp" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Dhcp TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : DHCP Client DEPENDENCIES : NSI : Tdx : Afd SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "diagnosticshub.standardcollector.service" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: diagnosticshub.standardcollector.service TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Microsoft (R) Diagnostics Hub Standard Collector Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "DiagTrack" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DiagTrack TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k utcsvc LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Connected User Experiences and Telemetry DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "DmEnrollmentSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DmEnrollmentSvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Device Management Enrollment Service DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "dmwappushservice" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: dmwappushservice TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : dmwappushsvc DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Dnscache" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Dnscache TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : DNS Client DEPENDENCIES : Tdx : nsi SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "DoSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DoSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Delivery Optimization DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "dot3svc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: dot3svc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : Wired AutoConfig DEPENDENCIES : RpcSs : Ndisuio : Eaphost SERVICE_START_NAME : localSystem C:\TEMP>SC qc "DPS" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DPS TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Diagnostic Policy Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "DsmSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DsmSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Device Setup Manager DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "DsSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DsSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Data Sharing Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "EapHost" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: EapHost TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Extensible Authentication Protocol DEPENDENCIES : RPCSS : KeyIso SERVICE_START_NAME : localSystem C:\TEMP>SC qc "EFS" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: EFS TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\lsass.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Encrypting File System (EFS) DEPENDENCIES : RPCSS SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "embeddedmode" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: embeddedmode TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Embedded Mode DEPENDENCIES : BrokerInfrastructure SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "EntAppSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: EntAppSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k appmodel LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Enterprise App Management Service DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "EventLog" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: EventLog TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : Event Log TAG : 0 DISPLAY_NAME : Windows Event Log DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "EventSystem" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: EventSystem TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : COM+ Event System DEPENDENCIES : rpcss SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "Fax" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Fax TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\fxssvc.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Fax DEPENDENCIES : TapiSrv : RpcSs : Spooler SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "fdPHost" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: fdPHost TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Function Discovery Provider Host DEPENDENCIES : RpcSs : http SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "FDResPub" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: FDResPub TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Function Discovery Resource Publication DEPENDENCIES : RpcSs : http SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "fhsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: fhsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : File History Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "FontCache" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: FontCache TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : AudioGroup TAG : 0 DISPLAY_NAME : Windows Font Cache Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "FontCache3.0.0.0" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: FontCache3.0.0.0 TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Presentation Foundation Font Cache 3.0.0.0 DEPENDENCIES : SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "FrameServer" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: FrameServer TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k Camera LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Camera Frame Server DEPENDENCIES : rpcss SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "gpsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: gpsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : ProfSvc_Group TAG : 0 DISPLAY_NAME : Group Policy Client DEPENDENCIES : RPCSS : Mup SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "gupdate" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: gupdate TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Google Update Service (gupdate) DEPENDENCIES : RPCSS SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "gupdatem" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: gupdatem TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Google Update Service (gupdatem) DEPENDENCIES : RPCSS SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "hidserv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: hidserv TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Human Interface Device Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "HomeGroupListener" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: HomeGroupListener TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : HomeGroup Listener DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "HomeGroupProvider" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: HomeGroupProvider TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : HomeGroup Provider DEPENDENCIES : netprofm : fdrespub : fdphost SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "HvHost" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: HvHost TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : HV Host Service DEPENDENCIES : hvservice SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "icssvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: icssvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : Windows Mobile Hotspot Service DEPENDENCIES : RpcSs : wcmsvc SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "IKEEXT" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: IKEEXT TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : IKE and AuthIP IPsec Keying Modules DEPENDENCIES : BFE : nsi SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "iphlpsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: iphlpsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k NetSvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : IP Helper DEPENDENCIES : RpcSS : Tdx : winmgmt : tcpip : nsi : WinHttpAutoProxySvc SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "IpOverUsbSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: IpOverUsbSvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : "C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Phone IP over USB Transport (IpOverUsbSvc) DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "irmon" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: irmon TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : Infrared monitor service DEPENDENCIES : irda SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "KeyIso" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: KeyIso TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\lsass.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : CNG Key Isolation DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "KtmRm" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: KtmRm TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k NetworkServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : KtmRm for Distributed Transaction Coordinator DEPENDENCIES : RPCSS : SamSS SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "LanmanServer" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: LanmanServer TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Server DEPENDENCIES : SamSS : Srv2 SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "LanmanWorkstation" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: LanmanWorkstation TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : NetworkProvider TAG : 0 DISPLAY_NAME : Workstation DEPENDENCIES : Bowser : MRxSmb20 : NSI SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "lfsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: lfsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Geolocation Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "LicenseManager" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: LicenseManager TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows License Manager Service DEPENDENCIES : rpcss SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "lltdsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: lltdsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Link-Layer Topology Discovery Mapper DEPENDENCIES : rpcss : lltdio SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "lmhosts" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: lmhosts TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : TCP/IP NetBIOS Helper DEPENDENCIES : Afd SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "LSM" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: LSM TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k DcomLaunch LOAD_ORDER_GROUP : COM Infrastructure TAG : 0 DISPLAY_NAME : Local Session Manager DEPENDENCIES : RpcEptMapper : DcomLaunch : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "MapsBroker" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: MapsBroker TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : NetworkService TAG : 0 DISPLAY_NAME : Downloaded Maps Manager DEPENDENCIES : rpcss SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "MBAMService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: MBAMService TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : MBAMService DEPENDENCIES : MBAMProtector SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "MessagingService_354e6" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: MessagingService_354e6 TYPE : e0 USER_SHARE_PROCESS INSTANCE START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : MessagingService_354e6 DEPENDENCIES : SERVICE_START_NAME : C:\TEMP>SC qc "MpsSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: MpsSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork LOAD_ORDER_GROUP : NetworkProvider TAG : 0 DISPLAY_NAME : Windows Firewall DEPENDENCIES : mpsdrv : bfe SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "MSDTC" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: MSDTC TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\msdtc.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Distributed Transaction Coordinator DEPENDENCIES : RPCSS : SamSS SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "MSiSCSI" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: MSiSCSI TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : iSCSI TAG : 0 DISPLAY_NAME : Microsoft iSCSI Initiator Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "msiserver" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: msiserver TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\msiexec.exe /V LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Installer DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "NcaSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: NcaSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k NetSvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network Connectivity Assistant DEPENDENCIES : BFE : dnscache : NSI : iphlpsvc SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "NcbService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: NcbService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network Connection Broker DEPENDENCIES : RpcSS : tcpip SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "NcdAutoSetup" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: NcdAutoSetup TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network Connected Devices Auto-Setup DEPENDENCIES : netprofm SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "Netlogon" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Netlogon TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\lsass.exe LOAD_ORDER_GROUP : MS_WindowsRemoteValidation TAG : 0 DISPLAY_NAME : Netlogon DEPENDENCIES : LanmanWorkstation SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Netman" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Netman TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network Connections DEPENDENCIES : RpcSs : nsi SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "netprofm" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: netprofm TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network List Service DEPENDENCIES : RpcSs : nlasvc SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "NetSetupSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: NetSetupSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network Setup Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "NetTcpPortSharing" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: NetTcpPortSharing TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Net.Tcp Port Sharing Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "NgcCtnrSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: NgcCtnrSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : Cryptography TAG : 0 DISPLAY_NAME : Microsoft Passport Container DEPENDENCIES : RpcSs SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "NgcSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: NgcSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : Cryptography TAG : 0 DISPLAY_NAME : Microsoft Passport DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "NlaSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: NlaSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network Location Awareness DEPENDENCIES : NSI : RpcSs : TcpIp : Dhcp : Eventlog SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "nlsX86cc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: nlsX86cc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\SysWOW64\nlssrv32.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Nalpeiron Licensing Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "nsi" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: nsi TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network Store Interface Service DEPENDENCIES : rpcss : nsiproxy SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "OneSyncSvc_354e6" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: OneSyncSvc_354e6 TYPE : e0 USER_SHARE_PROCESS INSTANCE START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Sync Host_354e6 DEPENDENCIES : SERVICE_START_NAME : C:\TEMP>SC qc "p2pimsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: p2pimsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Peer Networking Identity Manager DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "p2psvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: p2psvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Peer Networking Grouping DEPENDENCIES : p2pimsvc : PNRPSvc SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "PcaSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PcaSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Program Compatibility Assistant Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "PeerDistSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PeerDistSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k PeerDist LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : BranchCache DEPENDENCIES : http SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "PerfHost" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PerfHost TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\SysWow64\perfhost.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Performance Counter DLL Host DEPENDENCIES : RPCSS SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "PhoneSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PhoneSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Phone Service DEPENDENCIES : RpcSs SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "PimIndexMaintenanceSvc_354e6" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PimIndexMaintenanceSvc_354e6 TYPE : e0 USER_SHARE_PROCESS INSTANCE START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Contact Data_354e6 DEPENDENCIES : SERVICE_START_NAME : C:\TEMP>SC qc "pla" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: pla TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Performance Logs & Alerts DEPENDENCIES : RPCSS SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "PlugPlay" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PlugPlay TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k DcomLaunch LOAD_ORDER_GROUP : PlugPlay TAG : 0 DISPLAY_NAME : Plug and Play DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "PNRPAutoReg" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PNRPAutoReg TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : PNRP Machine Name Publication Service DEPENDENCIES : pnrpsvc SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "PNRPsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PNRPsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Peer Name Resolution Protocol DEPENDENCIES : p2pimsvc SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "PolicyAgent" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PolicyAgent TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : IPsec Policy Agent DEPENDENCIES : Tcpip : bfe SERVICE_START_NAME : NT Authority\NetworkService C:\TEMP>SC qc "Power" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Power TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k DcomLaunch LOAD_ORDER_GROUP : Plugplay TAG : 0 DISPLAY_NAME : Power DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "PrintNotify" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PrintNotify TYPE : 120 WIN32_SHARE_PROCESS (interactive) START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k print LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Printer Extensions and Notifications DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "ProfSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: ProfSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : profsvc_group TAG : 0 DISPLAY_NAME : User Profile Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "PSEXESVC" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PSEXESVC TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\PSEXESVC.EXE LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : PsExec DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "QWAVE" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: QWAVE TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Quality Windows Audio Video Experience DEPENDENCIES : rpcss : psched : QWAVEdrv : LLTDIO SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "RasAuto" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RasAuto TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Access Auto Connection Manager DEPENDENCIES : RasAcd SERVICE_START_NAME : localSystem C:\TEMP>SC qc "RasMan" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RasMan TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Access Connection Manager DEPENDENCIES : SstpSvc SERVICE_START_NAME : localSystem C:\TEMP>SC qc "RemoteAccess" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RemoteAccess TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Routing and Remote Access DEPENDENCIES : RpcSS : Bfe : RasMan : Http : +NetBIOSGroup SERVICE_START_NAME : localSystem C:\TEMP>SC qc "RemoteRegistry" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RemoteRegistry TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k localService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Registry DEPENDENCIES : RPCSS SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "RetailDemo" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RetailDemo TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Retail Demo Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "RmSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RmSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Radio Management Service DEPENDENCIES : RpcSs SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "RpcEptMapper" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RpcEptMapper TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k RPCSS LOAD_ORDER_GROUP : COM Infrastructure TAG : 0 DISPLAY_NAME : RPC Endpoint Mapper DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "RpcLocator" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RpcLocator TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\locator.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Procedure Call (RPC) Locator DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "RpcSs" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RpcSs TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k rpcss LOAD_ORDER_GROUP : COM Infrastructure TAG : 0 DISPLAY_NAME : Remote Procedure Call (RPC) DEPENDENCIES : RpcEptMapper : DcomLaunch SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "SamSs" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SamSs TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\lsass.exe LOAD_ORDER_GROUP : MS_WindowsLocalValidation TAG : 0 DISPLAY_NAME : Security Accounts Manager DEPENDENCIES : RPCSS SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SCardSvr" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SCardSvr TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : SmartCardGroup TAG : 0 DISPLAY_NAME : Smart Card DEPENDENCIES : wudfsvc SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "ScDeviceEnum" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: ScDeviceEnum TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Smart Card Device Enumeration Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Schedule" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Schedule TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : SchedulerGroup TAG : 0 DISPLAY_NAME : Task Scheduler DEPENDENCIES : RPCSS : SystemEventsBroker SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SCPolicySvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SCPolicySvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Smart Card Removal Policy DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SDRSVC" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SDRSVC TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k SDRSVC LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Backup DEPENDENCIES : RPCSS SERVICE_START_NAME : localSystem C:\TEMP>SC qc "seclogon" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: seclogon TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Secondary Logon DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SENS" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SENS TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : ProfSvc_Group TAG : 0 DISPLAY_NAME : System Event Notification Service DEPENDENCIES : EventSystem SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Sense" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Sense TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Defender Advanced Threat Protection Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SensorDataService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SensorDataService TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\SensorDataService.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Sensor Data Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SensorService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SensorService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Sensor Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SensrSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SensrSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Sensor Monitoring Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "SessionEnv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SessionEnv TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Desktop Configuration DEPENDENCIES : RPCSS : LanmanWorkstation SERVICE_START_NAME : localSystem C:\TEMP>SC qc "SharedAccess" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SharedAccess TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Internet Connection Sharing (ICS) DEPENDENCIES : BFE SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "ShellHWDetection" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: ShellHWDetection TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : ShellSvcGroup TAG : 0 DISPLAY_NAME : Shell Hardware Detection DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "shpamsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: shpamsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Shared PC Account Manager DEPENDENCIES : RpcSs : ProfSvc SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SkypeUpdate" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SkypeUpdate TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : "C:\Program Files (x86)\Skype\Updater\Updater.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Skype Updater DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "smphost" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: smphost TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k smphost LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Microsoft Storage Spaces SMP DEPENDENCIES : RPCSS SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "SmsRouter" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SmsRouter TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Microsoft Windows SMS Router Service. DEPENDENCIES : RpcSs : NdisUio SERVICE_START_NAME : localSystem C:\TEMP>SC qc "SNMPTRAP" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SNMPTRAP TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\snmptrap.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : SNMP Trap DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "Spooler" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Spooler TYPE : 110 WIN32_OWN_PROCESS (interactive) START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\spoolsv.exe LOAD_ORDER_GROUP : SpoolerGroup TAG : 0 DISPLAY_NAME : Print Spooler DEPENDENCIES : RPCSS : http SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "sppsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: sppsvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START (DELAYED) ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\sppsvc.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Software Protection DEPENDENCIES : RpcSs SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "SQLWriter" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SQLWriter TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : SQL Server VSS Writer DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SSDPSRV" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SSDPSRV TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : SSDP Discovery DEPENDENCIES : HTTP SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "SstpSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SstpSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Secure Socket Tunneling Protocol Service DEPENDENCIES : SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "StateRepository" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: StateRepository TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k appmodel LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : State Repository Service DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "stisvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: stisvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k imgsvc LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Image Acquisition (WIA) DEPENDENCIES : RpcSs SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "StorSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: StorSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Storage Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "svsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: svsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Spot Verifier DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "swprv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: swprv TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k swprv LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Microsoft Software Shadow Copy Provider DEPENDENCIES : RPCSS SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SysMain" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SysMain TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Superfetch DEPENDENCIES : rpcss : fileinfo SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SystemEventsBroker" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SystemEventsBroker TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k DcomLaunch LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : System Events Broker DEPENDENCIES : RpcEptMapper : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "TabletInputService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: TabletInputService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : PlugPlay TAG : 0 DISPLAY_NAME : Touch Keyboard and Handwriting Panel Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "TapiSrv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: TapiSrv TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Telephony DEPENDENCIES : RpcSs SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "Te.Service" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Te.Service TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : "C:\Program Files (x86)\Windows Kits\10\Testing\Runtimes\TAEF\Wex.Services.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Te.Service DEPENDENCIES : RpcSs : SecLogon SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "TermService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: TermService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Desktop Services DEPENDENCIES : RPCSS SERVICE_START_NAME : NT Authority\NetworkService C:\TEMP>SC qc "Themes" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Themes TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : ProfSvc_Group TAG : 0 DISPLAY_NAME : Themes DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "TieringEngineService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: TieringEngineService TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\TieringEngineService.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Storage Tiers Management DEPENDENCIES : SERVICE_START_NAME : localSystem C:\TEMP>SC qc "tiledatamodelsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: tiledatamodelsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k appmodel LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Tile Data model server DEPENDENCIES : rpcss : staterepository SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "TimeBrokerSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: TimeBrokerSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Time Broker DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "TrkWks" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: TrkWks TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Distributed Link Tracking Client DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "TrustedInstaller" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: TrustedInstaller TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\servicing\TrustedInstaller.exe LOAD_ORDER_GROUP : ProfSvc_Group TAG : 0 DISPLAY_NAME : Windows Modules Installer DEPENDENCIES : SERVICE_START_NAME : localSystem C:\TEMP>SC qc "tzautoupdate" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: tzautoupdate TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Auto Time Zone Updater DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "UevAgentService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: UevAgentService TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\AgentService.exe LOAD_ORDER_GROUP : ProfSvc_Group TAG : 0 DISPLAY_NAME : User Experience Virtualization Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "UI0Detect" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: UI0Detect TYPE : 110 WIN32_OWN_PROCESS (interactive) START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\UI0Detect.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Interactive Services Detection DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "UmRdpService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: UmRdpService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Desktop Services UserMode Port Redirector DEPENDENCIES : TermService : RDPDR SERVICE_START_NAME : localSystem C:\TEMP>SC qc "UnistoreSvc_354e6" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: UnistoreSvc_354e6 TYPE : e0 USER_SHARE_PROCESS INSTANCE START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : User Data Storage_354e6 DEPENDENCIES : SERVICE_START_NAME : C:\TEMP>SC qc "upnphost" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: upnphost TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : UPnP Device Host DEPENDENCIES : SSDPSRV : HTTP SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "UserDataSvc_354e6" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: UserDataSvc_354e6 TYPE : e0 USER_SHARE_PROCESS INSTANCE START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : User Data Access_354e6 DEPENDENCIES : SERVICE_START_NAME : C:\TEMP>SC qc "UserManager" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: UserManager TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : User Manager DEPENDENCIES : RpcSs : ProfSvc SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "UsoSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: UsoSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Update Orchestrator Service for Windows Update DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "VaultSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: VaultSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\lsass.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Credential Manager DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vds" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vds TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\vds.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Virtual Disk DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vmicguestinterface" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmicguestinterface TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Hyper-V Guest Service Interface DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vmicheartbeat" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmicheartbeat TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k ICService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Hyper-V Heartbeat Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vmickvpexchange" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmickvpexchange TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Hyper-V Data Exchange Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vmicrdv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmicrdv TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k ICService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Hyper-V Remote Desktop Virtualization Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vmicshutdown" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmicshutdown TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Hyper-V Guest Shutdown Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vmictimesync" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmictimesync TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Hyper-V Time Synchronization Service DEPENDENCIES : VmGid SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "vmicvmsession" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmicvmsession TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Hyper-V PowerShell Direct Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vmicvss" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmicvss TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Hyper-V Volume Shadow Copy Requestor DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "VMTools" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: VMTools TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\VMware\VMware Tools\vmtoolsd.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : VMware Tools DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vmvss" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmvss TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\dllhost.exe /Processid:{285B064C-1AD3-46A0-919B-0D4FDB090059} LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : VMware Snapshot Provider DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "VMware Physical Disk Helper Service" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: VMware Physical Disk Helper Service TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : "C:\Program Files\VMware\VMware Tools\vmacthlp.exe" LOAD_ORDER_GROUP : Base TAG : 0 DISPLAY_NAME : VMware Physical Disk Helper Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "VSS" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: VSS TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\vssvc.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Volume Shadow Copy DEPENDENCIES : RPCSS SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "VSStandardCollectorService140" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: VSStandardCollectorService140 TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : "C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Visual Studio Standard Collector Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "W32Time" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: W32Time TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Time DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "WalletService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WalletService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k appmodel LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : WalletService DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "wbengine" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wbengine TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\WINDOWS\system32\wbengine.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Block Level Backup Engine Service DEPENDENCIES : SERVICE_START_NAME : localSystem C:\TEMP>SC qc "WbioSrvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WbioSrvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k WbioSvcGroup LOAD_ORDER_GROUP : SmartCardGroup TAG : 0 DISPLAY_NAME : Windows Biometric Service DEPENDENCIES : RpcSs : WUDFSvc SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Wcmsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Wcmsvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : Windows Connection Manager DEPENDENCIES : RpcSs SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "wcncsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wcncsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Connect Now - Config Registrar DEPENDENCIES : rpcss SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "WdiServiceHost" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WdiServiceHost TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Diagnostic Service Host DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "WdiSystemHost" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WdiSystemHost TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Diagnostic System Host DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "WdNisSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WdNisSvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\Windows Defender\NisSrv.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Defender Network Inspection Service DEPENDENCIES : WdNisDrv SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "WebClient" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WebClient TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : NetworkProvider TAG : 0 DISPLAY_NAME : WebClient DEPENDENCIES : MRxDAV SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "Wecsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Wecsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Event Collector DEPENDENCIES : HTTP : Eventlog SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "WEPHOSTSVC" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WEPHOSTSVC TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k WepHostSvcGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Encryption Provider Host Service DEPENDENCIES : rpcss SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "wercplsupport" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wercplsupport TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Problem Reports and Solutions Control Panel Support DEPENDENCIES : SERVICE_START_NAME : localSystem C:\TEMP>SC qc "WerSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WerSvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k WerSvcGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Error Reporting Service DEPENDENCIES : SERVICE_START_NAME : localSystem C:\TEMP>SC qc "WiaRpc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WiaRpc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Still Image Acquisition Events DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "WinDefend" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WinDefend TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\Windows Defender\MsMpEng.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Defender Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Windows10FirewallService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Windows10FirewallService TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\Windows10FirewallControl\Windows10FirewallService.exe" LOAD_ORDER_GROUP : NetworkProvider TAG : 0 DISPLAY_NAME : Windows10FirewallService DEPENDENCIES : BFE SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "WinHttpAutoProxySvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WinHttpAutoProxySvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : WinHTTP Web Proxy Auto-Discovery Service DEPENDENCIES : Dhcp SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "Winmgmt" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Winmgmt TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Management Instrumentation DEPENDENCIES : RPCSS SERVICE_START_NAME : localSystem C:\TEMP>SC qc "WinRM" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WinRM TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Remote Management (WS-Management) DEPENDENCIES : RPCSS : HTTP SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "wisvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wisvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Insider Service DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "WlanSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WlanSvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : WLAN AutoConfig DEPENDENCIES : nativewifip : RpcSs : Ndisuio : wcmsvc SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "wlidsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wlidsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Microsoft Account Sign-in Assistant DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "wmiApSrv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wmiApSrv TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\wbem\WmiApSrv.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : WMI Performance Adapter DEPENDENCIES : SERVICE_START_NAME : localSystem C:\TEMP>SC qc "WMPNetworkSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WMPNetworkSvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\Windows Media Player\wmpnetwk.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Media Player Network Sharing Service DEPENDENCIES : http : WSearch SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "workfolderssvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: workfolderssvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalService LOAD_ORDER_GROUP : LocalService TAG : 0 DISPLAY_NAME : Work Folders DEPENDENCIES : RpcSs : wsearch SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "WPDBusEnum" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WPDBusEnum TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Portable Device Enumerator Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "WpnService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WpnService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Push Notifications System Service DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "WpnUserService_354e6" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WpnUserService_354e6 TYPE : e0 USER_SHARE_PROCESS INSTANCE START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Push Notifications User Service_354e6 DEPENDENCIES : SERVICE_START_NAME : C:\TEMP>SC qc "wscsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wscsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START (DELAYED) ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Security Center DEPENDENCIES : RpcSs : WinMgmt SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "WSearch" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WSearch TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\SearchIndexer.exe /Embedding LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Search DEPENDENCIES : RPCSS SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "wuauserv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wuauserv TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Update DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "wudfsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wudfsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : PlugPlay TAG : 0 DISPLAY_NAME : Windows Driver Foundation - User-mode Driver Framework DEPENDENCIES : WudfPf SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "WwanSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WwanSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : WWAN AutoConfig DEPENDENCIES : RpcSs : NdisUio SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "XblAuthManager" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: XblAuthManager TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Xbox Live Auth Manager DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "XblGameSave" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: XblGameSave TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Xbox Live Game Save DEPENDENCIES : UserManager : XblAuthManager SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "XboxNetApiSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: XboxNetApiSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Xbox Live Networking Service DEPENDENCIES : BFE : mpssvc : IKEEXT : KeyIso SERVICE_START_NAME : LocalSystem ------------------------------------------------------------------------------------------- WMIC qfe list (list of all installed updates): Caption CSName Description FixComments HotFixID InstallDate InstalledBy InstalledOn Name ServicePackInEffect Status http://support.microsoft.com/?kbid=3176936 W10VM Update KB3176936 NT AUTHORITY\SYSTEM 8/24/2016 http://support.microsoft.com/?kbid=3199986 W10VM Update KB3199986 NT AUTHORITY\SYSTEM 11/6/2016 http://support.microsoft.com/?kbid=3202790 W10VM Security Update KB3202790 NT AUTHORITY\SYSTEM 11/8/2016 http://support.microsoft.com/?kbid=3209498 W10VM Security Update KB3209498 NT AUTHORITY\SYSTEM 12/13/2016 http://support.microsoft.com/?kbid=3206632 W10VM Security Update KB3206632 NT AUTHORITY\SYSTEM 12/13/2016 -------------------------------------------------------------------------------------------
-Noel
1 -
I guess it boils down to what you consider the "operating system" to be.
Me, I always think of what the system can be made into (because, like you xpclient, that's what I do with it), with the goals being high usability, an strong level of stability, and minimal maintenance. Windows 10 gets 95% of the way on the first, maybe does a bit worse on the second, and is way worse - in the wrong ballpark worse - for the last. It's just not better, or even as good.
Do you think of anything as improved when you think of Windows 10? Apps? Cortana? Easier to keep running? Mobile? Cloud storage? 3D? Security? All of these things are what MICROSOFT wants us to think of, and their marketeers are relentless at telling us that, but do any of them actually do something better than what we already had? I really, really have tried to find the good in it, but I just can't answer yes.
I did tweak XP too (and all those that came before; remember tweaking DOS with SMARTDRV in high memory?), but we've never had the tremendous resources of the Internet that we have right now, today. All that shared knowledge and experience took a while to accumulate, and good apps took a long time to write. Decades. Dibya and others still using XP are probably using it more adeptly today than I did more than 10 years ago.
Was XP truly better out of the box? Or did we just expect less of it? Or NEED less of it? Certainly our computers were nowhere near as powerful back then, our monitors and networks not as good - and frankly even we users have learned a lot since then. I still use skills and good habits today that I learned going all the way back to before Windows or even Microsoft existed.
-Noel
0 -
One wonders how, without that internet connection, they'd be reading the instructions to "reboot your PC" in the first place. And is that not most everyone's first action anyway?
Probably they'd visit the web with their iPhone or Android and do a Google web search.
For what it's worth, there is not a consensus that a recent Windows Update caused the "DHCP connectivity" problem. It might have been latent and triggered by something. Microsoft's response may just be damage control, since a lot of the web "journalists" are attributing the problem to Windows Update, whether or not it's true.
-Noel
0 -
The other day, when I ran it, Disk Cleanup literally ran for over an hour, consuming roughly 2 cores of CPU continuously.
And now note how much space Disk Cleanup claims to be able to free on drive C: through Windows Update Cleanup vs. how big drive C: really is.
This is yet another good example (couple of examples) of why Microsoft needs to test its own software, and not send it out to the world in an unfinished state...
It takes a new level of not caring to turn Disk Cleanup into a CPU-intensive activity, then to report a bogus result like what's shown above! Thinking about what must be going on in Redmond, I'm seriously reminded of the old "if an infinite number of monkeys..." joke. And I'm not laughing.
-Noel
0 -
This is EXACTLY why I don't use the Windows Advanced Firewall interface any more. Microsoft adding rules to support its own desires at your expense to allow a computer to communicate online - without of course any input from you whether you WANT that done. No thanks. That's not why the firewall feature is in there.
W/regard to your specific firewall question... I normally keep all the Windows Advanced Firewall rules deleted, and the Firewall state set to Off. I verified that my list was empty not too long ago, so this is an opportunity for me to see whether some recent process has added some rules back in...
Lo and behold there are new firewall entries (%&#*@ Microsoft)!
In the Inbound Rules section:
- Two new rules for "DIAL protocol server (HTTP-In)", one for the Domain profile and one for Private. These describe themselves as "Inbound rule for DIAL protocol server to allow remote control of Apps using HTTP. [TCP 10247]".
In the Outbound Rules section:
- No new Outbound Rules appeared.
And, if it's at all interesting...
Here's the list of scheduled tasks I have allowed/disabled in my up-to-date Win 10 build 14393.579 system (noting that I don't do Apps at all, not even Cortana):
Spoiler------------------------------------------------------------------------------------------- SCHTASKS /Query /FO CSV (states of all scheduled tasks): "\Adobe Acrobat Update Task","N/A","Disabled" "\Adobe Uninstaller","N/A","Disabled" "\AdobeAAMUpdater-1.0-W10PVM-NoelC","N/A","Disabled" "\Aero Glass","N/A","Running" "\DisableLockScreen","N/A","Ready" "\DisableLockScreen","N/A","Ready" "\GoogleUpdateTaskMachineCore","N/A","Disabled" "\GoogleUpdateTaskMachineCore","N/A","Disabled" "\GoogleUpdateTaskMachineUA","N/A","Disabled" "\SpeechRuntimeTask","N/A","Disabled" "\WizMouse","N/A","Ready" "\WizMouse","N/A","Ready" "\Microsoft\VisualStudio\VSIX Auto Update 14","N/A","Disabled" "\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319","N/A","Disabled" "\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64","N/A","Disabled" "\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Critical","N/A","Disabled" "\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Critical","N/A","Disabled" "\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)","N/A","Disabled" "\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)","N/A","Disabled" "\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)","N/A","Disabled" "\Microsoft\Windows\AppID\EDP Policy Manager","N/A","Disabled" "\Microsoft\Windows\AppID\EDP Policy Manager","N/A","Disabled" "\Microsoft\Windows\AppID\PolicyConverter","N/A","Disabled" "\Microsoft\Windows\AppID\SmartScreenSpecific","N/A","Disabled" "\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck","N/A","Disabled" "\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser","N/A","Disabled" "\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser","N/A","Disabled" "\Microsoft\Windows\Application Experience\ProgramDataUpdater","N/A","Disabled" "\Microsoft\Windows\Application Experience\StartupAppTask","N/A","Disabled" "\Microsoft\Windows\ApplicationData\appuriverifierdaily","N/A","Disabled" "\Microsoft\Windows\ApplicationData\appuriverifierinstall","N/A","Disabled" "\Microsoft\Windows\ApplicationData\appuriverifierinstall","N/A","Disabled" "\Microsoft\Windows\ApplicationData\CleanupTemporaryState","N/A","Disabled" "\Microsoft\Windows\ApplicationData\DsSvcCleanup","N/A","Disabled" "\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup","N/A","Disabled" "\Microsoft\Windows\Autochk\Proxy","N/A","Disabled" "\Microsoft\Windows\Bluetooth\UninstallDeviceTask","N/A","Disabled" "\Microsoft\Windows\CertificateServicesClient\AikCertEnrollTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\CryptoPolicyTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\KeyPreGenTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\KeyPreGenTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\KeyPreGenTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\KeyPreGenTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\KeyPreGenTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\SystemTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\SystemTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\SystemTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\UserTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\UserTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\UserTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\UserTask-Roam","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\UserTask-Roam","N/A","Ready" "\Microsoft\Windows\Chkdsk\ProactiveScan","N/A","Ready" "\Microsoft\Windows\Clip\License Validation","N/A","Disabled" "\Microsoft\Windows\CloudExperienceHost\CreateObjectTask","N/A","Disabled" "\Microsoft\Windows\Customer Experience Improvement Program\Consolidator","N/A","Disabled" "\Microsoft\Windows\Customer Experience Improvement Program\HypervisorFlightingTask","N/A","Disabled" "\Microsoft\Windows\Customer Experience Improvement Program\KernelCeipTask","N/A","Disabled" "\Microsoft\Windows\Customer Experience Improvement Program\UsbCeip","N/A","Disabled" "\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan","12/26/2016 11:35:55 AM","Ready" "\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan","12/30/2016 8:31:43 AM","Ready" "\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan for Crash Recovery","N/A","Ready" "\Microsoft\Windows\Defrag\ScheduledDefrag","N/A","Ready" "\Microsoft\Windows\Device Information\Device","N/A","Disabled" "\Microsoft\Windows\Device Information\Device","N/A","Disabled" "\Microsoft\Windows\Device Setup\Metadata Refresh","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\HandleCommand","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\HandleWnsCommand","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\IntegrityCheck","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\LocateCommandUserSession","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceAccountChange","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceAccountChange","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceConnectedToNetwork","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceLocationRightsChange","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePeriodic1","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePeriodic24","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePeriodic6","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePolicyChange","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePolicyChange","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceScreenOnOff","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceScreenOnOff","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceSettingChange","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterUserDevice","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterUserDevice","N/A","Disabled" "\Microsoft\Windows\Diagnosis\Scheduled","N/A","Ready" "\Microsoft\Windows\DiskCleanup\SilentCleanup","N/A","Disabled" "\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector","N/A","Disabled" "\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver","N/A","Disabled" "\Microsoft\Windows\DiskFootprint\Diagnostics","N/A","Ready" "\Microsoft\Windows\DiskFootprint\StorageSense","N/A","Ready" "\Microsoft\Windows\DUSM\dusmtask","N/A","Disabled" "\Microsoft\Windows\EDP\EDP App Launch Task","N/A","Disabled" "\Microsoft\Windows\EDP\EDP Auth Task","N/A","Disabled" "\Microsoft\Windows\EnterpriseMgmt\MDMMaintenenceTask","N/A","Disabled" "\Microsoft\Windows\ErrorDetails\EnableErrorDetailsUpdate","N/A","Disabled" "\Microsoft\Windows\ErrorDetails\ErrorDetailsUpdate","N/A","Disabled" "\Microsoft\Windows\Feedback\Siuf\DmClient","N/A","Disabled" "\Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload","N/A","Disabled" "\Microsoft\Windows\File Classification Infrastructure\Property Definition Sync","N/A","Disabled" "\Microsoft\Windows\FileHistory\File History (maintenance mode)","N/A","Disabled" "\Microsoft\Windows\LanguageComponentsInstaller\Installation","N/A","Disabled" "\Microsoft\Windows\LanguageComponentsInstaller\Installation","N/A","Disabled" "\Microsoft\Windows\LanguageComponentsInstaller\Uninstallation","N/A","Disabled" "\Microsoft\Windows\License Manager\TempSignedLicenseExchange","N/A","Disabled" "\Microsoft\Windows\Location\Notifications","N/A","Disabled" "\Microsoft\Windows\Location\WindowsActionDialog","N/A","Disabled" "\Microsoft\Windows\Maintenance\WinSAT","N/A","Ready" "\Microsoft\Windows\Management\Provisioning\Logon","N/A","Disabled" "\Microsoft\Windows\Maps\MapsToastTask","N/A","Disabled" "\Microsoft\Windows\Maps\MapsUpdateTask","N/A","Disabled" "\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents","N/A","Ready" "\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents","N/A","Ready" "\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents","N/A","Ready" "\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents","N/A","Ready" "\Microsoft\Windows\MemoryDiagnostic\RunFullMemoryDiagnostic","N/A","Ready" "\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser","N/A","Disabled" "\Microsoft\Windows\MUI\LPRemove","N/A","Disabled" "\Microsoft\Windows\Multimedia\SystemSoundsService","N/A","Running" "\Microsoft\Windows\NetCfg\BindingWorkItemQueueHandler","N/A","Disabled" "\Microsoft\Windows\NetTrace\GatherNetworkInfo","N/A","Disabled" "\Microsoft\Windows\NlaSvc\WiFiTask","N/A","Disabled" "\Microsoft\Windows\Offline Files\Background Synchronization","N/A","Disabled" "\Microsoft\Windows\Offline Files\Logon Synchronization","N/A","Disabled" "\Microsoft\Windows\PI\Secure-Boot-Update","N/A","Disabled" "\Microsoft\Windows\PI\Sqm-Tasks","N/A","Disabled" "\Microsoft\Windows\Plug and Play\Device Install Group Policy","N/A","Ready" "\Microsoft\Windows\Plug and Play\Device Install Reboot Required","N/A","Ready" "\Microsoft\Windows\Plug and Play\Plug and Play Cleanup","N/A","Ready" "\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers","N/A","Ready" "\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem","N/A","Disabled" "\Microsoft\Windows\Ras\MobilityManager","N/A","Disabled" "\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE","N/A","Disabled" "\Microsoft\Windows\Registry\RegIdleBackup","N/A","Ready" "\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask","N/A","Disabled" "\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask","N/A","Disabled" "\Microsoft\Windows\RetailDemo\CleanupOfflineContent","N/A","Disabled" "\Microsoft\Windows\Servicing\StartComponentCleanup","N/A","Disabled" "\Microsoft\Windows\SettingSync\BackupTask","N/A","Disabled" "\Microsoft\Windows\SettingSync\NetworkStateChangeTask","N/A","Disabled" "\Microsoft\Windows\SettingSync\NetworkStateChangeTask","N/A","Disabled" "\Microsoft\Windows\Setup\SetupCleanupTask","N/A","Disabled" "\Microsoft\Windows\SharedPC\Account Cleanup","N/A","Disabled" "\Microsoft\Windows\Shell\CreateObjectTask","N/A","Disabled" "\Microsoft\Windows\Shell\FamilySafetyMonitor","N/A","Disabled" "\Microsoft\Windows\Shell\FamilySafetyMonitorToastTask","N/A","Disabled" "\Microsoft\Windows\Shell\FamilySafetyRefreshTask","N/A","Disabled" "\Microsoft\Windows\Shell\IndexerAutomaticMaintenance","N/A","Disabled" "\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask","11/20/2116 11:18:11 AM","Ready" "\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskLogon","N/A","Disabled" "\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskNetwork","N/A","Disabled" "\Microsoft\Windows\SpacePort\SpaceAgentTask","N/A","Ready" "\Microsoft\Windows\SpacePort\SpaceAgentTask","N/A","Ready" "\Microsoft\Windows\SpacePort\SpaceManagerTask","N/A","Ready" "\Microsoft\Windows\SpacePort\SpaceManagerTask","N/A","Ready" "\Microsoft\Windows\Speech\SpeechModelDownloadTask","N/A","Disabled" "\Microsoft\Windows\Storage Tiers Management\Storage Tiers Management Initialization","N/A","Disabled" "\Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization","N/A","Disabled" "\Microsoft\Windows\Subscription\EnableLicenseAcquisition","N/A","Disabled" "\Microsoft\Windows\Subscription\EnableLicenseAcquisition","N/A","Disabled" "\Microsoft\Windows\Subscription\EnableLicenseAcquisition","N/A","Disabled" "\Microsoft\Windows\Subscription\LicenseAcquisition","N/A","Disabled" "\Microsoft\Windows\Subscription\LicenseAcquisition","N/A","Disabled" "\Microsoft\Windows\Subscription\LicenseAcquisition","N/A","Disabled" "\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate","N/A","Disabled" "\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance","N/A","Disabled" "\Microsoft\Windows\Sysmain\ResPriStaticDbSync","N/A","Disabled" "\Microsoft\Windows\Sysmain\WsSwapAssessmentTask","N/A","Disabled" "\Microsoft\Windows\SystemRestore\SR","N/A","Ready" "\Microsoft\Windows\Task Manager\Interactive","N/A","Ready" "\Microsoft\Windows\TextServicesFramework\MsCtfMonitor","N/A","Running" "\Microsoft\Windows\Time Synchronization\ForceSynchronizeTime","N/A","Ready" "\Microsoft\Windows\Time Synchronization\SynchronizeTime","N/A","Ready" "\Microsoft\Windows\Time Zone\SynchronizeTimeZone","N/A","Ready" "\Microsoft\Windows\TPM\Tpm-HASCertRetr","N/A","Disabled" "\Microsoft\Windows\TPM\Tpm-Maintenance","N/A","Disabled" "\Microsoft\Windows\TPM\Tpm-Maintenance","N/A","Disabled" "\Microsoft\Windows\TPM\Tpm-Maintenance","N/A","Disabled" "\Microsoft\Windows\TPM\Tpm-Maintenance","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\Maintenance Install","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\Policy Install","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\Reboot","N/A","Ready" "\Microsoft\Windows\UpdateOrchestrator\Refresh Settings","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\Resume On Boot","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\Schedule Scan","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\Schedule Scan","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\Schedule Scan","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\USO_RebootDisplay","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_WnfDisplay","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\USO_WnfDisplay","N/A","Disabled" "\Microsoft\Windows\UPnP\UPnPHostConfig","N/A","Disabled" "\Microsoft\Windows\User Profile Service\HiveUploadTask","N/A","Disabled" "\Microsoft\Windows\WCM\WiFiTask","N/A","Disabled" "\Microsoft\Windows\WDI\ResolutionHost","N/A","Disabled" "\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance","N/A","Ready" "\Microsoft\Windows\Windows Defender\Windows Defender Cleanup","N/A","Ready" "\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan","N/A","Ready" "\Microsoft\Windows\Windows Defender\Windows Defender Verification","N/A","Ready" "\Microsoft\Windows\Windows Error Reporting\QueueReporting","N/A","Disabled" "\Microsoft\Windows\Windows Error Reporting\QueueReporting","N/A","Disabled" "\Microsoft\Windows\Windows Error Reporting\QueueReporting","N/A","Disabled" "\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange","N/A","Ready" "\Microsoft\Windows\Windows Media Sharing\UpdateLibrary","N/A","Disabled" "\Microsoft\Windows\WindowsColorSystem\Calibration Loader","N/A","Disabled" "\Microsoft\Windows\WindowsColorSystem\Calibration Loader","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUFirmwareInstall","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUScheduledInstall","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUSessionConnect","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUSessionConnect","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUSessionConnect","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUSessionConnect","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUSessionConnect","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\Automatic App Update","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\Automatic App Update","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\Scheduled Start","N/A","Ready" "\Microsoft\Windows\WindowsUpdate\Scheduled Start","N/A","Ready" "\Microsoft\Windows\WindowsUpdate\Scheduled Start","N/A","Ready" "\Microsoft\Windows\WindowsUpdate\Scheduled Start","N/A","Ready" "\Microsoft\Windows\WindowsUpdate\sih","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\sihboot","N/A","Disabled" "\Microsoft\Windows\Wininet\CacheTask","N/A","Running" "\Microsoft\Windows\WOF\WIM-Hash-Management","N/A","Ready" "\Microsoft\Windows\WOF\WIM-Hash-Management","N/A","Ready" "\Microsoft\Windows\WOF\WIM-Hash-Validation","N/A","Ready" "\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization","N/A","Disabled" "\Microsoft\Windows\Work Folders\Work Folders Maintenance Work","N/A","Disabled" "\Microsoft\Windows\Workplace Join\Automatic-Device-Join","N/A","Disabled" "\Microsoft\XblGameSave\XblGameSaveTask","N/A","Disabled" "\Microsoft\XblGameSave\XblGameSaveTaskLogon","N/A","Disabled" "\OfficeSoftwareProtectionPlatform\SvcRestartTask","N/A","Disabled" -------------------------------------------------------------------------------------------
Because I take regular status readings of the above, I noticed that something (other than me) has re-enabled the following tasks. Doesn't really matter for me since I keep the Windows Update service disabled and (as you) protected from succeeding via the firewall. In any case, I re-disabled them.
\Microsoft\Windows\UpdateOrchestrator\Reboot \Microsoft\Windows\WindowsUpdate\Scheduled Start
Microsoft has crossed onto the slippery slope of changing configuration parameters that should EXCLUSIVELY remain the purview of the user. It's one thing to set things to default on a new installation; it's another entirely to change parameters. They need to be put in prison over this.
-Noel
1 -
4 hours ago, jaclaz said:
OT, but not much more OT than the other peeps
You never, EVER, have to worry about what's OT in any of my threads. I think "on topic" is an invalid concept and many things can be learned from a freely ranging conversation.
I enjoyed your image. It reminded me a bit of a particular Greek donkey that wasn't quite so apt to work without complaint. Or at least without music.
-Noel
0 -
You have done much with XP. Congratulations. It is impressive.
A few days ago I was testing with an image that was 90,000 pixels on a side. Not really possible with a 32 bit address space. It illustrates why I prefer x64. Personally I found that, while some things were slower overall (e.g., the file system), Win 8.1 didn't "get sluggish under load" as quickly as Win 7. I've found myself craving more than 48 GB of RAM lately, though. The more powerful the system, the bigger the jobs we tend to give it.
Though it seems like there is a "war" brewing here, I'd say it's not - it's healthy conversation and we're all learning. What's funny is this is a thread where most or all of us agree that we're not interested in changing to Win 10 on our hardware, so has become a discussion on "how new a system can I tolerate".
-Noel
0 -
Thanks. I wasn't sure when the multi-core support was added.
-Noel
0 -
If you count 8.0 and 8.1 together, we probably number more than XP users at this point. Something like 8-9% of all Windows systems.
Microsoft just doesn't care about quality in general.
By the way, there's a bit of a hoohah about Microsoft publishing and unpublishing and publishing etc. updates going on right now. See:
-Noel
1 -
FYI, Sphinx Firewall version 8.1 is released.
This one uses a quite innovative name-based configuration process, which turns hard work into a breeze to keep up to date.
I've been using all the betas and now the released version on all my systems, and if you're looking for serious firewall sophistication I highly recommend it.
-Noel
0 -
Horses for courses. You prefer a Thoroughbred and I like a stable of Clydesdales.
Do you by chance have PassMark PerformanceTest handy to where you could run it under each different OS, and post the comparative results? At least some of the tests show 3D rendering performance, which no doubt you'd be most interested in. I'd be more interested in disk and CPU performance for my needs... Speaking of which, could XP handle 12 cores / 24 logical processors?
FWIW, I've never had to reinstall any Windows OS more than once. That's just a matter of knowing how to maintain it properly - and MSFN is as good a source as any for how-to on that subject. I have always thought that Microsoft's provision of "Refresh" and other similar capabilities in the WinRE environment were a cop-out, and that they should make the system more robust so it would not NEED reinstallation when someone mucks it up.
-Noel
2 -
Sorry; I had forgotten.
-Noel
0 -
My recent experience - and it DOES actually speak to my decision not to put Win 10 on my hardware - is that ATI (AMD) isn't doing as well at writing drivers as they once did. Every Windows 8.1 compatible driver release after November 2015 has been missing features I actually use. Two things, specifically, that are somewhat related: The ability to define a custom calibration, and the ability to auto load that as a preset. They deprecated the auto load first, but I found a workaround. The last straw came in mid 2016 when they just removed the ability to calibrate the output per port entirely.
There's an old saying: "Make everything as simple as possible, but no simpler". They chose to make it simpler.
So here I am, with a still decent ATI Radeon HD 7850 but unable to use drivers newer than November 2015. Imagine what drivers may be required to run the latest Windows 10 release. MAYBE those older drivers would work. Or maybe not.
I really hate the "Dumbing Down of Things".
-Noel
0 -
Gaming has financed a lot of advances in desktop computing.
The integration of Win 10 with Xbox may ultimately provide your particular recipient some extra value, so given an emphasis on gaming, Win 10 may be as good a choice as any.
What video card are you thinking of putting into it? One of the top-end nVidias?
-Noel
0 -
I don't have any Apps besides Settings, but for me when I start Settings I see a console window titled C:\WINDOWS\system32\ApplicationFrameHost.exe open. I presume that's because ModernFrame-x64-Debug.dll is a Debug build.
Is what you're seeing something different than this, UCyborg?
-Noel
0 -
2 hours ago, Dibya said:
Never mind , Windows XP is faster than 10. any body against this statement?
Does it really matter? XP was a toy, plain and simple, because it was 32 bit. Maybe it worked well enough for the things you needed. It didn't for mine.
MANY tasks require access to a larger address space (and freedom from fragmentation issues) now when processing real world problems. XP x64 was a start on the right path, but it took until late Vista or the release of 7 for x64 to be a serious system all on its own. It took until Windows 7 or 8 to get most everything in the system up to native 64 bit.
And it's not like the later systems are fundamentally different architectures than XP. They're all a derivative of a Vax/VMS virtual memory system under the covers (re-implemented as NT by Dave Cutler).
Even today you can carve off a lot of the extra fat, and lo and behold the kernel underneath isn't bad at all. Not surprisingly, a trimmed, lean system is pretty fast, even by comparison to your beloved XP.
The last time I EVER remember having any disk corruption was back around 2003 or 2004 when running XP. NTFS on newer systems is more reliable than ever, and beyond that I run ReFS on several of my disk partitions.
I remember a very specific incident in about 2003 when I still worked for an engineering firm... I had to copy about 5 gigabytes of data in multiple folders from one system to another, and I absolutely could NOT get XP to do it all in one shot. It would just fail with some esoteric error code or another. So I had to break the job down to multiple incremental XCOPY commands and run them more than once to get it done. By contrast, I haven't had to worry about the amount of data I was copying with any newer 64 bit Windows system. Nowadays hardly anyone worries that a video file of a few gigabytes is going to copy correctly.
Systems today simply DO more than XP, and run longer.
My systems running 7 and 8.1 today are at least 10x faster than the ones I ran XP on, and while I had to reboot XP every few weeks, these run for months. The last time I remember having to regularly reboot my systems because of things that either stopped working or crashes because of things like resource leaks chewing up the entire available pool was in XP and early Vista.
I agree that every new system gets a bit slower, mostly because no one at Microsoft really gives a d*** whether the code is optimized. They never have. Here's a statement for you: If it HAD been optimized, XP (and any Windows system before or since) could have been quite a lot faster than they actually were. Microsoft had a stated policy for a long time that they never polished or optimized anything once it was working, since the world cares more about innovation than they do efficiency. So they just moved on.
XP was great for its day. That day is not this day.
-Noel
P.S., I think that if you feel strongly about something, you should feel free to post it as often and in as many places as you like, and be prepared for debate. I've also been told my criticisms of Win 10 are repetitive and negative. To those who feel that way I say: Feel free to read something else.
2
Aero Glass for Win8.1+ 1.5.1.724
in Aero Glass For Windows 8+
Posted
It's working okay for me... Since it's not a basic compatibility problem can you please describe what's going wrong for you?
-Noel