NoelC Posted December 13, 2016 Author Posted December 13, 2016 (edited) Horses for courses. You prefer a Thoroughbred and I like a stable of Clydesdales. Do you by chance have PassMark PerformanceTest handy to where you could run it under each different OS, and post the comparative results? At least some of the tests show 3D rendering performance, which no doubt you'd be most interested in. I'd be more interested in disk and CPU performance for my needs... Speaking of which, could XP handle 12 cores / 24 logical processors? FWIW, I've never had to reinstall any Windows OS more than once. That's just a matter of knowing how to maintain it properly - and MSFN is as good a source as any for how-to on that subject. I have always thought that Microsoft's provision of "Refresh" and other similar capabilities in the WinRE environment were a cop-out, and that they should make the system more robust so it would not NEED reinstallation when someone mucks it up. -Noel Edited December 13, 2016 by NoelC 2
cc333 Posted December 14, 2016 Posted December 14, 2016 NoelC: My Mac Pro is quite similar to your system (I'm using x5680s though, because they offer 98% of the performance at 50% of the cost of a pair of x5690s), and XP handles 12 physical cores/24 logical cores perfectly (the 32 GB of RAM mostly goes to waste, but that's expected of any 32-bit OS, especially those with broken/absent PAE support). Windows 7 flies on it, and 8.1 is surprisingly decent, even with an old laptop drive as its boot disk (it was all I had at the time, and I didn't want to wipe any of the other 3.5" disks in my system). c
NoelC Posted December 14, 2016 Author Posted December 14, 2016 Thanks. I wasn't sure when the multi-core support was added. -Noel
jaclaz Posted December 14, 2016 Posted December 14, 2016 OT, but not much more OT than the other peeps, for *some* reasons I never fancied horses, let alone Thoroughbred. I know that it is largely irrational , but I always have the feeling that horses are somewhat unpredictable and whimsical, while - stubborn as they may be - I like donkeys and mules: Spoiler as - all in all - at the end of the day they do their work without much fuss. jaclaz 1
NoelC Posted December 14, 2016 Author Posted December 14, 2016 4 hours ago, jaclaz said: OT, but not much more OT than the other peeps You never, EVER, have to worry about what's OT in any of my threads. I think "on topic" is an invalid concept and many things can be learned from a freely ranging conversation. I enjoyed your image. It reminded me a bit of a particular Greek donkey that wasn't quite so apt to work without complaint. Or at least without music. -Noel
aviv00 Posted December 15, 2016 Posted December 15, 2016 (edited) Can u share process hacker pic pls and action center working ? and clicking on clock open window ? thx Edited December 15, 2016 by aviv00
NoelC Posted December 15, 2016 Author Posted December 15, 2016 (edited) 24 minutes ago, aviv00 said: Can u share process hacker with process running You didn't quote anyone... Assuming you're asking me about my tweaked/augmented Win 10 setup... aerohost.exe is part of Aero Glass for Win 8+. ClassicStartMenu.exe is Classic Shell's start menu replacement. conhost.exe is there because I have a beta build of Aero Glass for Win 8+ running. ProcessHacker.exe is the tool shown in the above screen grab. ShellFolderFixUI.exe positions Explorer windows per where they were used last. TSVNCache.exe is part of Tortoise SVN, which is a SubVersion client used to access software. 2 vmtoolsd.exe processes are because this Win 10 system is running in a VMware virtual machine. Windows10FirewallControl.exe and Windows10FirewallServices.exe are part of the Sphinx firewall. WizMouse.exe helps with sending mouse wheel events to the windows under the cursor All these things work very well together. Some other pertinent information... Spoiler ------------------------------------------------------------------------------------------- TaskList /V /FO:CSV /NH (processes running): "aerohost.exe","1600","Services","0","1,152 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "ClassicStartMenu.exe","4084","Console","1","11,876 K","Running","W10VM\NoelC","0:00:00","StartHookWindow" "cmd.exe","1320","Console","1","3,308 K","Running","W10VM\NoelC","0:00:00","Administrator: CMD - gettasklist" "conhost.exe","2896","Console","1","7,472 K","Running","Window Manager\DWM-1","0:00:00","CicMarshalWnd" "conhost.exe","4976","Console","1","18,624 K","Running","W10VM\NoelC","0:00:00","CicMarshalWnd" "csrss.exe","688","Services","0","4,032 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "csrss.exe","768","Console","1","7,168 K","Running","NT AUTHORITY\SYSTEM","0:00:01","N/A" "dasHost.exe","2308","Services","0","11,536 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:00","N/A" "dllhost.exe","2864","Services","0","13,108 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "dwm.exe","1216","Console","1","118,916 K","Running","Window Manager\DWM-1","0:00:09","dwm.exe" "explorer.exe","3812","Console","1","109,068 K","Running","W10VM\NoelC","0:00:08","N/A" "gsort.exe","1360","Console","1","5,108 K","Unknown","W10VM\NoelC","0:00:00","N/A" "lsass.exe","856","Services","0","12,108 K","Unknown","NT AUTHORITY\SYSTEM","0:00:01","N/A" "Memory Compression","2432","Services","0","8 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "msdtc.exe","2968","Services","0","9,648 K","Unknown","NT AUTHORITY\NETWORK SERVICE","0:00:07","N/A" "MsMpEng.exe","2364","Services","0","99,280 K","Unknown","NT AUTHORITY\SYSTEM","0:00:59","N/A" "NisSrv.exe","3456","Services","0","5,804 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:00","N/A" "services.exe","840","Services","0","7,608 K","Unknown","NT AUTHORITY\SYSTEM","0:00:42","N/A" "ShellExperienceHost.exe","4424","Console","1","52,736 K","Running","W10VM\NoelC","0:00:00","Start" "ShellFolderFixUI.exe","4404","Console","1","9,592 K","Running","W10VM\NoelC","0:00:00","ShellFolderFix" "sihost.exe","3516","Console","1","18,856 K","Running","W10VM\NoelC","0:00:00","N/A" "smss.exe","580","Services","0","1,208 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "spoolsv.exe","1872","Services","0","19,500 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "svchost.exe","1016","Services","0","20,080 K","Unknown","NT AUTHORITY\NETWORK SERVICE","0:00:01","N/A" "svchost.exe","1072","Services","0","21,176 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:01","N/A" "svchost.exe","1104","Services","0","67,136 K","Unknown","NT AUTHORITY\SYSTEM","0:00:43","N/A" "svchost.exe","1188","Services","0","15,272 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:01","N/A" "svchost.exe","1376","Services","0","6,592 K","Unknown","NT AUTHORITY\NETWORK SERVICE","0:00:00","N/A" "svchost.exe","1492","Services","0","15,436 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:04","N/A" "svchost.exe","1516","Services","0","9,240 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:00","N/A" "svchost.exe","184","Services","0","9,392 K","Unknown","NT AUTHORITY\NETWORK SERVICE","0:00:00","N/A" "svchost.exe","2356","Services","0","16,696 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "svchost.exe","2476","Services","0","12,524 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:00","N/A" "svchost.exe","756","Services","0","36,228 K","Unknown","NT AUTHORITY\SYSTEM","0:00:05","N/A" "svchost.exe","944","Services","0","18,788 K","Unknown","NT AUTHORITY\SYSTEM","0:00:01","N/A" "System Idle Process","0","Services","0","4 K","Unknown","NT AUTHORITY\SYSTEM","3:50:23","N/A" "System","4","Services","0","1,888 K","Unknown","N/A","0:01:35","N/A" "taskhostw.exe","3560","Console","1","16,456 K","Running","W10VM\NoelC","0:00:00","Task Host Window" "tasklist.exe","4476","Console","1","8,272 K","Unknown","W10VM\NoelC","0:00:00","N/A" "TSVNCache.exe","4792","Console","1","24,908 K","Running","W10VM\NoelC","0:00:00","TSVNCacheWindow" "vmtoolsd.exe","2348","Services","0","15,960 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "vmtoolsd.exe","3064","Console","1","37,464 K","Running","W10VM\NoelC","0:00:01","N/A" "Windows10FirewallControl.exe","4144","Console","1","16,324 K","Running","W10VM\NoelC","0:00:06","N/A" "Windows10FirewallService.exe","1256","Services","0","13,772 K","Unknown","NT AUTHORITY\SYSTEM","0:00:01","N/A" "wininit.exe","760","Services","0","5,216 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "winlogon.exe","1008","Console","1","11,028 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "WizMouse.exe","4560","Console","1","720 K","Running","W10VM\NoelC","0:00:00","N/A" "WmiPrvSE.exe","4092","Services","0","8,524 K","Unknown","NT AUTHORITY\NETWORK SERVICE","0:00:00","N/A" ------------------------------------------------------------------------------------------- TaskList /SVC /FO:CSV /NH (services running): "dllhost.exe","2864","COMSysApp" "lsass.exe","856","SamSs" "msdtc.exe","2968","MSDTC" "MsMpEng.exe","2364","WinDefend" "NisSrv.exe","3456","WdNisSvc" "spoolsv.exe","1872","Spooler" "svchost.exe","1016","CryptSvc,Dnscache,LanmanWorkstation,NlaSvc,TermService" "svchost.exe","1072","Dhcp,EventLog,lmhosts,TimeBrokerSvc,wscsvc" "svchost.exe","1104","AudioEndpointBuilder,DeviceAssociationService,SysMain,TrkWks,UmRdpService" "svchost.exe","1188","EventSystem,FontCache,netprofm,nsi,WdiServiceHost,WinHttpAutoProxySvc" "svchost.exe","1376","PolicyAgent" "svchost.exe","1492","BFE,CoreMessagingRegistrar,DPS" "svchost.exe","1516","Audiosrv" "svchost.exe","184","RpcEptMapper,RpcSs" "svchost.exe","2356","StateRepository,tiledatamodelsvc" "svchost.exe","2476","stisvc" "svchost.exe","756","Browser,CertPropSvc,DsmSvc,IKEEXT,iphlpsvc,LanmanServer,ProfSvc,Schedule,SENS,SessionEnv,ShellHWDetection,Themes,UserManager,Winmgmt,WpnService" "svchost.exe","944","BrokerInfrastructure,DcomLaunch,LSM,PlugPlay,Power,SystemEventsBroker" "vmtoolsd.exe","2348","VMTools" "Windows10FirewallService.exe","1256","Windows10FirewallService" ------------------------------------------------------------------------------------------- TaskList /M /FO:CSV /NH (modules loaded): "aerohost.exe","1600","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,imagehlp.dll,ucrtbase.dll,DWMGlass.dll,shcore.dll,msvcrt.dll,combase.dll,RPCRT4.dll,bcryptPrimitives.dll,SHLWAPI.dll,GDI32.dll,gdi32full.dll,dwmapi.dll,win32u.dll,USER32.dll,COMCTL32.dll,ADVAPI32.dll,sechost.dll,SspiCli.dll,ntmarta.dll,kernel.appcore.dll,WTSAPI32.dll,WINSTA.dll,dbghelp.dll" "ClassicStartMenu.exe","4084","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,USER32.dll,win32u.dll,GDI32.dll,gdi32full.dll,ADVAPI32.dll,msvcrt.dll,sechost.dll,RPCRT4.dll,SHELL32.dll,cfgmgr32.dll,windows.storage.dll,combase.dll,ucrtbase.dll,bcryptPrimitives.dll,powrprof.dll,shlwapi.dll,kernel.appcore.dll,shcore.dll,profapi.dll,ole32.dll,ClassicStartMenuDLL.dll,COMDLG32.dll,UxTheme.dll,COMCTL32.dll,OLEAUT32.dll,msvcp_win.dll,WTSAPI32.dll,WINTRUST.dll,MSIMG32.dll,Secur32.dll,MSASN1.dll,CRYPT32.dll,NETAPI32.dll,dwmapi.dll,OLEACC.dll,WINMM.dll,PROPSYS.dll,WININET.dll,WINMMBASE.dll,SSPICLI.DLL,NETUTILS.DLL,LOGONCLI.DLL,IMM32.DLL,clbcatq.dll,MSCTF.dll" "cmd.exe","1320","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,cmdext.dll,ADVAPI32.dll,sechost.dll,RPCRT4.dll" "conhost.exe","2896","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,ConhostV1.dll,win32u.dll,USER32.dll,GDI32.dll,gdi32full.dll,IMM32.dll,OLEAUT32.dll,msvcp_win.dll,ucrtbase.dll,combase.dll,RPCRT4.dll,bcryptPrimitives.dll,uxtheme.dll,MSCTF.dll,sechost.dll,dwmapi.dll,kernel.appcore.dll,comctl32.DLL,SHCORE.dll" "conhost.exe","4976","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,ConhostV2.dll,combase.dll,ucrtbase.dll,RPCRT4.dll,bcryptPrimitives.dll,GDI32.dll,gdi32full.dll,USER32.dll,win32u.dll,IMM32.dll,OLEAUT32.dll,msvcp_win.dll,PROPSYS.dll,sechost.dll,shcore.dll,kernel.appcore.dll,uxtheme.dll,SHELL32.dll,cfgmgr32.dll,windows.storage.dll,powrprof.dll,advapi32.dll,shlwapi.dll,profapi.dll,ole32.dll,clbcatq.dll,LINKINFO.dll,MSCTF.dll,dwmapi.dll,comctl32.DLL" "dasHost.exe","2308","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,RPCRT4.dll,sechost.dll,cfgmgr32.dll,bcryptPrimitives.dll,DAFWSD.dll,OLEAUT32.dll,msvcp_win.dll,ucrtbase.dll,combase.dll,WS2_32.dll,FirewallAPI.dll,IPHLPAPI.DLL,deviceassociation.dll,wsdapi.dll,NSI.dll,webservices.dll,fwbase.dll,bcrypt.dll,CRYPT32.dll,MSASN1.dll,dhcpcsvc6.DLL,dhcpcsvc.DLL,mswsock.dll,wshqos.dll,wshtcpip.DLL,wship6.dll,WINNSI.DLL,powrprof.dll,CRYPTSP.dll,rsaenh.dll,CRYPTBASE.dll,XmlLite.dll,WINHTTP.dll,webio.dll,SspiCli.dll,DNSAPI.dll,kernel.appcore.dll,clbcatq.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,MLANG.dll" "dllhost.exe","2864","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,ucrtbase.dll,combase.dll,RPCRT4.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,clbcatq.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,sechost.dll,COMSVCS.DLL,OLEAUT32.dll,msvcp_win.dll,ole32.dll,CRYPTSP.dll,rsaenh.dll,bcrypt.dll,CRYPTBASE.dll,txflog.dll,es.dll,PROPSYS.dll,shcore.dll,sxs.dll,ADVAPI32.dll,XOLEHLP.dll,MSDTCPRX.DLL,WS2_32.dll,CLUSAPI.dll,RESUTILS.dll,MTXCLU.DLL,ktmw32.dll,DNSAPI.dll,NSI.dll,IPHLPAPI.DLL,wkscli.dll,cscapi.dll,netutils.dll,sspicli.dll,mswsock.dll,fwpuclnt.dll,rasadhlp.dll,catsrv.dll,MfcSubs.dll,catsrvps.dll,catsrvut.dll" "dwm.exe","1216","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,apphelp.dll,msvcrt.dll,advapi32.dll,sechost.dll,RPCRT4.dll,gdi32.dll,gdi32full.dll,USER32.dll,win32u.dll,dwmredir.dll,udwm.dll,dwmcore.dll,dxgi.dll,dcomp.dll,OLEAUT32.dll,msvcp_win.dll,ucrtbase.dll,combase.dll,kernel.appcore.dll,bcryptPrimitives.dll,CoreMessaging.dll,IMM32.DLL,uxtheme.dll,dwmghost.dll,dwmapi.dll,WindowsCodecs.dll,clbcatq.dll,UIAnimation.dll,d3d11.dll,ism32k.dll,shcore.dll,CoreUIComponents.dll,wintypes.dll,avrt.dll,Windows.Gaming.Input.dll,cfgmgr32.dll,twinapi.appcore.dll,bcrypt.dll,vm3dum64.dll,D3D10Level9.dll,OneCoreUAPCommonProxyStub.dll,d2d1.dll,CRYPT32.dll,MSASN1.dll,XmlLite.dll,Cabinet.dll,DWMGlass.dll,SHLWAPI.dll,COMCTL32.dll,dbghelp.dll,WTSAPI32.dll,WINSTA.dll,ole32.dll,VERSION.dll,shell32.dll,windows.storage.dll,powrprof.dll,profapi.dll,DUser.dll,atlthunk.dll,MSIMG32.dll,MSCTF.dll" "explorer.exe","3812","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,OLEAUT32.dll,msvcp_win.dll,ucrtbase.dll,combase.dll,RPCRT4.dll,bcryptPrimitives.dll,USER32.dll,win32u.dll,GDI32.dll,gdi32full.dll,SHCORE.dll,SHLWAPI.dll,SHELL32.dll,cfgmgr32.dll,windows.storage.dll,powrprof.dll,advapi32.dll,sechost.dll,kernel.appcore.dll,profapi.dll,CRYPT32.dll,PROPSYS.dll,MSASN1.dll,MrmCoreR.dll,UxTheme.dll,dwmapi.dll,twinapi.appcore.dll,TWINAPI.dll,SspiCli.dll,USERENV.dll,bcrypt.dll,settingsynccore.dll,cryptsp.dll,IMM32.DLL,MSCTF.dll,ole32.dll,clbcatq.dll,ActXPrxy.dll,SharedStartModel.dll,XmlLite.dll,CoreMessaging.dll,VEEventDispatcher.dll,msvcp110_win.dll,IDStore.dll,SAMLIB.dll,Bcp47Langs.dll,settingsyncpolicy.dll,policymanager.dll,TokenBroker.dll,TOKENBINDING.dll,wintypes.dll,WINSTA.dll,comctl32.dll,SndVolSSO.DLL,MMDevApi.dll,DEVOBJ.dll,OLEACC.dll,OneCoreCommonProxyStub.dll,usermgrproxy.dll,dataexchange.dll,d3d11.dll,dcomp.dll,dxgi.dll,COMDLG32.dll,VERSION.dll,WINMM.dll,WINMMBASE.dll,explorerframe.dll,UxTSB.dll,MSIMG32.dll,dbghelp.dll,Windows.StateRepository.dll,StateRepository.Core.dll,Windows.UI.dll,thumbcache.dll,edputil.dll,coml2.dll,TwinUI.dll,windows.immersiveshell.serviceprovider.dll,WindowsCodecs.dll,Secur32.dll,samcli.dll,netutils.dll,WLDP.DLL,WINTRUST.dll,WTSAPI32.dll,SLC.dll,sppc.dll,ClassicStartMenuDLL.dll,NETAPI32.dll,WININET.dll,LOGONCLI.DLL,taskschd.dll,twinui.appcore.dll,twinui.pcshell.dll,DWMGlass.dll,PhotoMetadataHandler.dll,apphelp.dll,gameux.dll,gdiplus.dll,ApplicationFrame.dll,d2d1.dll,msxml6.dll,dbghelp.dll,ntshrui.dll,srvcli.dll,cscapi.dll,CoreUIComponents.dll,Windows.UI.Immersive.dll,wpncore.dll,winsqlite3.dll,cdp.dll,WINHTTP.dll,urlmon.dll,CRYPTBASE.dll,WS2_32.dll,ncrypt.dll,IPHLPAPI.DLL,iertutil.dll,NTASN1.dll,LINKINFO.dll,NotificationController.dll,AboveLockAppHost.dll,npsm.dll,Windows.Web.dll,execmodelproxy.dll,Windows.Networking.Connectivity.dll,npmproxy.dll,NSI.dll,wlanapi.dll,ieframe.dll,WKSCLI.DLL,wwapi.dll,wlidprov.dll,NInput.dll,vm3dum64.dll,D3D10Level9.dll,UIAnimation.dll,NotificationObjFactory.dll,dsreg.dll,NotificationControllerPS.dll,DPAPI.DLL,rmclient.dll,NetworkExplorer.dll,MPR.dll,ntlanman.dll,drprov.dll,davclnt.dll,DAVHLPR.dll,mswsock.dll,fontext.dll,TortoiseOverlays.dll,TortoiseStub.dll,DeviceCenter.dll,DUI70.dll,TortoiseSVN.dll,libapr_tsvn.dll,libsvn_tsvn.dll,MSVCP140.dll,intl3_tsvn.dll,VCRUNTIME140.dll,libaprutil_tsvn.dll,libsasl.dll,WLDAP32.dll,crshhndl.dll,MFPlat.DLL,RTWorkQ.DLL,stobject.dll,WMICLNT.dll,resourcepolicyclient.dll,EhStorShell.dll,SETUPAPI.dll,cscui.dll,InputSwitch.dll,sxs.dll,BatMeter.dll,Windows.UI.Shell.dll,wincorlib.DLL,rsaenh.dll,es.dll,prnfldr.dll,Windows.Internal.Shell.Broker.dll,ntoskrnl.exe,dxp.dll,SHDOCVW.dll,atlthunk.dll,Syncreg.dll,Actioncenter.dll,wevtapi.dll,wcmapi.dll,wpdshserviceobj.dll,PortableDeviceTypes.dll,PortableDeviceApi.dll,SettingMonitor.dll,cscobj.dll,AUDIOSES.DLL,srchadmin.dll,pnidui.dll,netprofm.dll,NetworkUXBroker.dll,EthernetMediaManager.dll,SyncCenter.dll,imapi2.dll,imagehlp.dll,hgcpl.dll,DUser.dll,provsvc.dll,gpapi.dll,bthprops.cpl,dhcpcsvc6.DLL,dhcpcsvc.DLL,MLANG.dll,wdmaud.drv,AVRT.dll,ksuser.dll,msacm32.drv,MSACM32.dll,midimap.dll,ntmarta.dll,msiltcfg.dll,msi.dll,Windows.ApplicationModel.dll,ShellFolderFix.dll,pcacli.dll,sfc_os.dll,DEVRTL.dll,wscinterop.dll,WSCAPI.dll,wscui.cpl,werconcpl.dll,framedynos.dll,wer.dll,hcproviders.dll,ieproxy.dll,wshirda.dll,netjoin.dll,NETPROVFW.DLL,JOINUTIL.DLL,oledb32.dll,MSDART.DLL,comsvcs.dll,tquery.dll" "gsort.exe","4804","ntdll.dll,wow64.dll,wow64win.dll,wow64cpu.dll" "lsass.exe","856","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,RPCRT4.dll,lsasrv.dll,msvcrt.dll,WS2_32.dll,SspiCli.dll,sechost.dll,MSASN1.dll,samsrv.dll,ucrtbase.dll,CRYPT32.dll,bcrypt.dll,ncrypt.dll,NTASN1.dll,bcryptprimitives.dll,msprivs.DLL,netprovfw.dll,JOINUTIL.DLL,negoexts.DLL,CRYPTSP.dll,CRYPTBASE.dll,pku2u.DLL,cryptdll.dll,wdigest.DLL,rsaenh.dll,schannel.DLL,kerberos.DLL,KerbClientShared.dll,mswsock.dll,msv1_0.DLL,NtlmShared.dll,netlogon.DLL,powrprof.dll,gmsaclient.dll,advapi32.dll,USERENV.dll,WLDAP32.dll,profapi.dll,netutils.dll,DNSAPI.dll,NSI.dll,IPHLPAPI.DLL,cloudAP.DLL,MicrosoftAccountCloudAP.dll,combase.dll,DPAPI.DLL,tspkg.DLL,PCPKsp.dll,ntmarta.dll,PCPTPM12.dll,tbs.dll,efslsaext.dll,dpapisrv.dll,SspiSrv.dll,winsta.dll,scecli.DLL,wevtapi.dll,logoncli.dll,DSPARSE.dll,certpoleng.dll" "msdtc.exe","2968","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,combase.dll,ucrtbase.dll,RPCRT4.dll,bcryptPrimitives.dll,msvcrt.dll,MSDTCTM.dll,OLEAUT32.dll,msvcp_win.dll,sechost.dll,ole32.dll,GDI32.dll,gdi32full.dll,USER32.dll,win32u.dll,WS2_32.dll,MSDTCPRX.dll,ADVAPI32.dll,MSDTCLOG.dll,MTXCLU.DLL,WINMM.dll,CLUSAPI.dll,bcrypt.dll,ktmw32.dll,RESUTILS.dll,MSWSOCK.dll,XOLEHLP.dll,DNSAPI.dll,WINMMBASE.dll,NSI.dll,cfgmgr32.dll,CRYPTSP.dll,IPHLPAPI.DLL,kernel.appcore.dll,COMRES.DLL,msdtcVSp1res.dll,mtxoci.dll,wkscli.dll,cscapi.dll,netutils.dll,sspicli.dll,ntmarta.dll,clbcatq.dll,FirewallAPI.dll,fwbase.dll,FWPolicyIOMgr.dll" "sed.exe","3856","ntdll.dll,wow64.dll,wow64win.dll,wow64cpu.dll" "ShellExperienceHost.exe","4424","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,combase.dll,wincorlib.DLL,ucrtbase.dll,RPCRT4.dll,bcryptPrimitives.dll,OLEAUT32.dll,msvcp_win.dll,kernel.appcore.dll,Windows.UI.Xaml.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,Bcp47Langs.dll,iertutil.dll,CoreMessaging.dll,sechost.dll,advapi32.dll,shcore.dll,IMM32.DLL,twinapi.appcore.dll,bcrypt.dll,WinTypes.dll,Windows.UI.dll,uxtheme.dll,ActXPrxy.dll,dwmapi.dll,CoreUIComponents.dll,dxgi.dll,StartUI.dll,policymanager.dll,msvcp110_win.dll,d3d11.dll,Windows.UI.Shell.SharedUtilities.dll,vm3dum64.dll,D3D10Level9.dll,QuickActions.dll,Windows.UI.ActionCenter.dll,ole32.dll,QuickActionsDataModel.dll,MrmCoreR.dll,SHLWAPI.dll,d2d1.dll,CRYPT32.dll,MSASN1.dll,profapi.dll,msctf.dll,windows.ui.core.textinput.dll,TextInputFramework.dll,Windows.UI.Immersive.dll,DataExchange.dll,dcomp.dll,OneCoreUAPCommonProxyStub.dll,CRYPTBASE.dll,Windows.Globalization.dll,SharedStartModel.dll,XmlLite.dll,VEEventDispatcher.dll,NotificationObjFactory.dll,urlmon.dll,SHELL32.dll,cfgmgr32.dll,windows.storage.dll,powrprof.dll,PROPSYS.dll,SLC.dll,sppc.dll,dwrite.dll,threadpoolwinrt.dll,twinapi.dll,Windows.Graphics.dll,Windows.Globalization.Fontgroups.dll,fontgroupsoverride.dll,Windows.Storage.ApplicationData.dll,Windows.StateRepository.dll,StateRepository.Core.dll,windowscodecs.dll,PhotoMetadataHandler.dll,rmclient.dll,directmanipulation.dll,NotificationControllerPS.dll,globcollationhost.dll,winsta.dll,RTMediaFrame.dll,MFPlat.DLL,RTWorkQ.DLL" "ShellFolderFixUI.exe","4404","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,USER32.dll,UxTheme.dll,win32u.dll,GDI32.dll,msvcrt.dll,gdi32full.dll,combase.dll,COMDLG32.dll,ucrtbase.dll,shcore.dll,MSIMG32.dll,RPCRT4.dll,SHLWAPI.dll,bcryptPrimitives.dll,SHELL32.dll,COMCTL32.dll,cfgmgr32.dll,windows.storage.dll,powrprof.dll,advapi32.dll,sechost.dll,kernel.appcore.dll,profapi.dll,ole32.dll,WINSPOOL.DRV,OLEAUT32.dll,msvcp_win.dll,bcrypt.dll,IMM32.dll,WININET.dll,gdiplus.dll,WINMM.dll,WINMMBASE.dll,dwmapi.dll,ShellFolderFix.dll,MSCTF.dll" "sihost.exe","3516","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,combase.dll,ucrtbase.dll,RPCRT4.dll,bcryptPrimitives.dll,sechost.dll,advapi32.dll,CoreMessaging.dll,CoreUIComponents.dll,ntmarta.dll,kernel.appcore.dll,user32.dll,wintypes.dll,win32u.dll,GDI32.dll,gdi32full.dll,shcore.dll,IMM32.DLL,clbcatq.dll,desktopshellext.dll,shlwapi.dll,msvcp_win.dll,wtsapi32.dll,WINSTA.dll,Windows.Shell.ServiceHostBuilder.dll,ActXPrxy.dll,modernexecserver.dll,ResourcePolicyClient.dll,VEEventDispatcher.dll,OLEAUT32.dll,powrprof.dll,msvcp110_win.dll,twinapi.appcore.dll,bcrypt.dll,uxtheme.dll,ClipboardServer.dll,RMCLIENT.dll,activationmanager.dll,AppointmentActivation.dll,ole32.dll,usermgrproxy.dll,usermgrcli.dll,OneCoreUAPCommonProxyStub.dll,ExecModelClient.dll,windowmanagement.dll,NotificationPlatformComponent.dll,AppContracts.dll,ShareHost.dll,Windows.Storage.dll,profapi.dll,WpPortingLibrary.dll,OneCoreCommonProxyStub.dll,Windows.System.Launcher.dll,dsclient.dll,execmodelproxy.dll,twinui.appcore.dll,daxexec.dll,FLTLIB.DLL,container.dll,IPHLPAPI.DLL,Windows.StateRepository.dll,StateRepository.Core.dll,licensemanagerapi.dll,dwmapi.dll,AppXDeploymentClient.dll" "spoolsv.exe","1872","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,USER32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcrt.dll,sechost.dll,RPCRT4.dll,advapi32.dll,DNSAPI.dll,bcrypt.dll,WS2_32.dll,NSI.dll,IPHLPAPI.DLL,combase.dll,ucrtbase.dll,bcryptPrimitives.dll,kernel.appcore.dll,SspiCli.dll,powrprof.dll,mswsock.dll,WTSAPI32.dll,WINSTA.dll,WINNSI.DLL,rasadhlp.dll,fwpuclnt.dll,localspl.dll,CRYPT32.dll,MSASN1.dll,cfgmgr32.dll,srvcli.dll,SETUPAPI.dll,sfc_os.dll,SPOOLSS.DLL,ole32.dll,Secur32.dll,winspool.drv,PrintIsolationProxy.dll,hpinkstsBB11LM.dll,OLEAUT32.dll,msvcp_win.dll,SHLWAPI.dll,PSAPI.DLL,USERENV.dll,SHELL32.dll,profapi.dll,windows.storage.dll,shcore.dll,VERSION.dll,wshirda.dll,FXSMON.DLL,tcpmon.dll,snmpapi.dll,wsnmp32.dll,usbmon.dll,DEVOBJ.dll,WINTRUST.dll,WSDMon.dll,wsdapi.dll,netutils.dll,deviceassociation.dll,WINHTTP.dll,webservices.dll,FirewallAPI.dll,fwbase.dll,clbcatq.dll,msxml6.dll,FunDisc.dll,XmlLite.dll,fdPnp.dll,ATL.DLL,WSDCHNGR.DLL,drvstore.dll,dhcpcsvc6.DLL,dhcpcsvc.DLL,winprint.dll,gpapi.dll,DSROLE.dll,win32spl.dll,inetpp.dll,CRYPTSP.dll,rsaenh.dll,cscapi.dll,CRYPTBASE.dll,bidispl.dll,WSDPrintProxy.dll,ondemandconnroutehelper.dll,webio.dll,HTTPAPI.dll" "svchost.exe","1016","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,termsrv.dll,WS2_32.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,clbcatq.dll,lsmproxy.dll,advapi32.dll,sspicli.dll,REGAPI.dll,rdpcorets.dll,OLEAUT32.dll,msvcp_win.dll,IPHLPAPI.DLL,rfxvmt.dll,pdh.dll,SHELL32.dll,CRYPTBASE.dll,bcrypt.dll,cfgmgr32.dll,ncrypt.dll,windows.storage.dll,USERENV.dll,WINHTTP.dll,powrprof.dll,profapi.dll,shlwapi.dll,shcore.dll,Secur32.dll,SETUPAPI.dll,NTASN1.dll,AUTHZ.dll,PROPSYS.dll,wer.dll,tlscsp.dll,DPAPI.DLL,umb.dll,ATL.DLL,nlasvc.dll,dhcpcsvc.DLL,WINNSI.DLL,ncsi.dll,NSI.dll,DEVOBJ.dll,ntmarta.dll,ssdpapi.dll,WMICLNT.dll,dhcpcsvc6.DLL,WlanApi.dll,mswsock.dll,wshqos.dll,wshtcpip.DLL,wship6.dll,wkscli.dll,netjoin.dll,JoinUtil.dll,netutils.dll,dnsrslvr.dll,DNSAPI.dll,Fwpuclnt.dll,dnsext.dll,winsta.dll,wevtapi.dll,gpapi.dll,wtsapi32.dll,wkssvc.dll,DSPARSE.dll,taskschd.dll,cryptsvc.dll,crypttpmeksvc.dll,cryptcatsvc.dll,VSSAPI.DLL,VssTrace.DLL,samcli.dll,SAMLIB.dll,ES.DLL,ESENT.dll" "svchost.exe","1072","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,lmhsvc.dll,WS2_32.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,nrpsrv.DLL,wevtsvc.dll,bcrypt.dll,powrprof.dll,sspicli.dll,mswsock.dll,gpapi.dll,dhcpcore.dll,DNSAPI.dll,NSI.dll,IPHLPAPI.DLL,firewallapi.dll,fwbase.dll,dhcpcore6.dll,WINNSI.DLL,dhcpcsvc6.DLL,dhcpcsvc.DLL,CRYPTBASE.dll,timebrokerserver.dll,BrokerLib.dll,bi.dll,msvcp_win.dll,profapi.dll,clbcatq.dll,NgcCtnr.dll,DPAPI.DLL,twinapi.appcore.dll,usermgrcli.dll,ole32.dll,coml2.dll,OneCoreCommonProxyStub.dll,execmodelproxy.dll,winrnr.dll,rasadhlp.dll,NLAapi.dll,napinsp.dll,pnrpnsp.dll,fwpuclnt.dll,wscsvc.dll,netutils.dll,OLEAUT32.dll,wbemprox.dll,wbemcomn.dll,wbemsvc.dll,fastprox.dll,WINHTTP.dll,ADVAPI32.dll,USERENV.dll" "svchost.exe","1104","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,cfgmgr32.dll,ADVAPI32.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,PortableDeviceApi.dll,clbcatq.dll,SHLWAPI.dll,SETUPAPI.dll,DEVOBJ.dll,portabledeviceconnectapi.dll,powrprof.dll,shcore.dll,WTSAPI32.dll,WINSTA.dll,audioendpointbuilder.dll,bcrypt.dll,MMDevAPI.DLL,PROPSYS.dll,OLEAUT32.dll,msvcp_win.dll,umrdp.dll,WINSPOOL.DRV,umb.dll,ATL.DLL,sspicli.dll,das.dll,RMCLIENT.dll,profapi.dll,sysmain.dll,trkwks.dll,ntmarta.dll,ncrypt.dll,USERENV.dll,netutils.dll,NTASN1.dll,fhcfg.dll,ole32.dll,SHELL32.dll,windows.storage.dll,wevtapi.dll,MPR.dll,XmlLite.dll,EFSUTIL.dll,NETAPI32.dll,DSROLE.dll,SRVCLI.DLL,bi.dll,SystemEventsBrokerClient.dll,taskschd.dll,coml2.dll,OneCoreCommonProxyStub.dll,ActXPrxy.dll" "svchost.exe","1188","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,es.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,nsisvc.dll,clbcatq.dll,OLEAUT32.dll,msvcp_win.dll,advapi32.dll,NSI.dll,fntcache.dll,profapi.dll,FontProvider.dll,netprofmsvc.dll,nlaapi.dll,npmproxy.dll,ole32.dll,IPHLPAPI.DLL,windows.devices.radios.dll,cfgmgr32.dll,WINNSI.DLL,WS2_32.dll,gpapi.dll,winhttp.dll,mswsock.dll,powrprof.dll,dhcpcsvc6.DLL,DNSAPI.dll,dhcpcsvc.DLL,rasadhlp.dll,sxs.dll,wdi.dll,perftrack.dll,PROPSYS.dll,shcore.dll,cdpsvc.dll,sbservicetrigger.dll,cdp.dll,VEEventDispatcher.dll,ncrypt.dll,SspiCli.dll,bcrypt.dll,msvcp110_win.dll,NTASN1.dll" "svchost.exe","1376","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,ipsecsvc.dll,msvcrt.dll,FirewallAPI.dll,AUTHZ.dll,fwpuclnt.dll,FwRemoteSvr.DLL,bcrypt.dll,combase.dll,bcryptPrimitives.dll,fwbase.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,kernel.appcore.dll,clbcatq.dll,OLEAUT32.dll,msvcp_win.dll,WS2_32.dll,mswsock.dll,IPHLPAPI.DLL,NSI.dll,dhcpcsvc6.DLL,dhcpcsvc.DLL,sspicli.dll" "svchost.exe","1492","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,coremessaging.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,bfe.dll,WS2_32.dll,AUTHZ.dll,SspiCli.dll,wevtapi.dll,bcrypt.dll,dps.dll,clbcatq.dll,taskschd.dll,OLEAUT32.dll,msvcp_win.dll,gpapi.dll,wdi.dll,diagperf.dll,pnpts.dll,srumsvc.dll,IPHLPAPI.DLL,ESENT.dll,CRYPTBASE.DLL,eeprov.dll,powrprof.dll,shcore.dll,DEVOBJ.dll,cfgmgr32.dll,appsruprov.dll,nduprov.dll,wpnsruprov.dll,ncuprov.dll,NSI.dll,WINNSI.DLL,energyprov.dll,advapi32.dll,srumapi.dll,ole32.dll,ktmw32.dll,radardt.dll,ntmarta.dll,VERSION.dll" "svchost.exe","1516","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,audiosrv.dll,msvcp_win.dll,MMDevAPI.DLL,PROPSYS.dll,AUDIOSRVPOLICYMANAGER.dll,DEVOBJ.dll,OLEAUT32.dll,cfgmgr32.dll,shcore.dll,POWRPROF.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,clbcatq.dll,winsta.dll,wtsapi32.dll,coreaudiopolicymanagerext.dll,audioses.dll,wintypes.dll,deviceaccess.dll" "svchost.exe","184","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,rpcepmap.dll,WLDP.DLL,msvcrt.dll,combase.dll,bcryptPrimitives.dll,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,sspicli.dll,RpcRtRemote.dll,rpcss.dll,WS2_32.dll,mswsock.dll,powrprof.dll,FirewallAPI.dll,fwbase.dll,clbcatq.dll,wshhyperv.dll,fwpuclnt.dll,bcrypt.dll,advapi32.dll,kernel.appcore.dll,OLEAUT32.dll,msvcp_win.dll,capauthz.dll" "svchost.exe","2356","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,windows.staterepository.dll,StateRepository.Core.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,clbcatq.dll,tileobjserver.dll,advapi32.dll,msvcp110_win.dll,ESENT.dll,shcore.dll,urlmon.dll,shlwapi.dll,iertutil.dll,USERENV.dll,profapi.dll,wtsapi32.dll,WINSTA.dll,windows.storage.dll,powrprof.dll,SspiCli.dll,CRYPTBASE.DLL,ActXPrxy.dll,Bcrypt.dll,mrmcorer.dll,OLEAUT32.dll,msvcp_win.dll" "svchost.exe","2476","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,wiaservc.dll,msvcrt.dll,ADVAPI32.dll,USER32.dll,win32u.dll,GDI32.dll,gdi32full.dll,OLEAUT32.dll,msvcp_win.dll,combase.dll,bcryptPrimitives.dll,ole32.dll,VERSION.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,wiatrace.dll,kernel.appcore.dll,sspicli.dll,msv1_0.DLL,NtlmShared.dll,bcrypt.dll,cryptdll.dll,powrprof.dll,cfgmgr32.dll,clbcatq.dll,SETUPAPI.dll,WSDCHNGR.DLL,deviceassociation.dll,DEVOBJ.dll,FunDisc.dll,XmlLite.dll,fdPnp.dll,ATL.DLL,WSDScDrv.dll,wsdapi.dll,WS2_32.dll,gdiplus.dll,NSI.dll,IPHLPAPI.DLL,webservices.dll,FirewallAPI.dll,fwbase.dll,mswsock.dll,dhcpcsvc6.DLL,dhcpcsvc.DLL,WINNSI.DLL,WSDScanProxy.dll,WINHTTP.dll,ondemandconnroutehelper.dll,webio.dll,DNSAPI.dll,HTTPAPI.dll" "svchost.exe","756","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,devicesetupmanager.dll,cfgmgr32.dll,powrprof.dll,USERENV.dll,ntmarta.dll,profapi.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,clbcatq.dll,netprofm.dll,themeservice.dll,profsvc.dll,OLEAUT32.dll,msvcp_win.dll,gpsvc.dll,SYSNTFY.dll,nlaapi.dll,winsta.dll,DSROLE.dll,profsvcext.dll,WLDAP32.dll,SHELL32.dll,netutils.dll,logoncli.dll,windows.storage.dll,advapi32.dll,shlwapi.dll,shcore.dll,gpapi.dll,schedsvc.dll,UBPM.dll,EventAggregation.dll,SspiCli.dll,sens.dll,AUTHZ.dll,WS2_32.dll,WMICLNT.dll,bcrypt.dll,taskcomp.dll,cryptsp.dll,WPTaskScheduler.dll,CSystemEventsBrokerClient.dll,wkscli.dll,netjoin.dll,mswsock.dll,JoinUtil.dll,wtsapi32.dll,DABAPI.dll,TimeBrokerClient.dll,usermgr.dll,wintypes.dll,npmproxy.dll,usermgrproxy.dll,shsvcs.dll,DEVOBJ.dll,DevPropMgr.dll,PROPSYS.dll,DeviceDriverRetrievalClient.dll,SETUPAPI.dll,newdev.dll,UxTheme.dll,devrtl.DLL,FVEAPI.dll,wevtapi.dll,certprop.dll,WinSCard.dll,WMsgAPI.dll,ProximityService.dll,ProximityCommon.dll,IPHLPAPI.DLL,ProximityCommonPal.dll,ProximityServicePAL.dll,firewallapi.dll,fwbase.dll,HID.DLL,sessenv.dll,samcli.dll,XmlLite.dll,rsaenh.dll,DPAPI.dll,CRYPTBASE.dll,ncrypt.dll,NTASN1.dll,ikeext.dll,NSI.dll,fwpuclnt.dll,srvsvc.dll,WINNSI.DLL,SSCORE.DLL,dhcpcsvc6.DLL,sscoreext.dll,dhcpcsvc.DLL,mi.dll,miutils.dll,wmidcom.dll,RESUTILS.DLL,CLUSAPI.dll,DNSAPI.dll,browser.dll,rasadhlp.dll,SAMLIB.dll,DeviceMetadataRetrievalClient.dll,WINHTTP.dll,Cabinet.dll,wer.dll,ondemandconnroutehelper.dll,wmisvc.dll,wbemcomn.dll,wpnservice.dll,iphlpsvc.dll,rtutils.dll,NetSetupApi.dll,wpncore.dll,cdp.dll,winsqlite3.dll,urlmon.dll,iertutil.dll,VEEventDispatcher.dll,msvcp110_win.dll,sqmapi.dll,httpprxm.dll,adhsvc.dll,httpprxc.dll,ACTIVEDS.dll,adsldpc.dll,WDSCORE.dll,hnetcfgclient.dll,ole32.dll,VSSAPI.DLL,VssTrace.DLL,sxs.dll,ES.DLL,NETAPI32.DLL,SECUR32.DLL,cscapi.dll,wbemcore.dll,FastProx.dll,esscli.dll,wbemsvc.dll,wmiutils.dll,repdrvfs.dll,wmiprvsd.dll,NCObjAPI.DLL,wbemess.dll,FWPolicyIOMgr.dll,srvcli.dll,usermgrcli.dll,apphelp.dll,ncprov.dll,webio.dll,FlightSettings.dll,bcd.dll,policymanager.dll,Comctl32.dll" "svchost.exe","944","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,umpnpmgr.dll,msvcrt.dll,WLDP.DLL,combase.dll,bcryptPrimitives.dll,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,umpo.dll,umpoext.dll,cfgmgr32.dll,powrprof.dll,dxgi.dll,tdh.dll,win32u.dll,gdi32.dll,gdi32full.dll,USER32.dll,mintdh.dll,OLEAUT32.dll,msvcp_win.dll,gpapi.dll,HID.DLL,windows.storage.dll,advapi32.dll,shlwapi.dll,kernel.appcore.dll,shcore.dll,profapi.dll,rpcss.dll,SspiCli.dll,bisrv.dll,ntmarta.dll,EventAggregation.dll,psmsrv.dll,DEVOBJ.dll,ResourcePolicyClient.dll,VEEventDispatcher.dll,msvcp110_win.dll,twinapi.appcore.dll,bcrypt.dll,lsm.dll,SYSNTFY.dll,clbcatq.dll,embeddedmodesvcapi.dll,psmserviceexthost.dll,resourcepolicyserver.dll,CRYPTSP.dll,Userenv.dll,systemeventsbrokerserver.dll,BrokerLib.dll,DAB.dll,bi.dll,lsmproxy.dll,usermgrcli.dll,CRYPTBASE.DLL,wtsapi32.dll,WINSTA.dll,OneCoreUAPCommonProxyStub.dll,RmClient.dll,BackgroundMediaPolicy.dll,ACPBackgroundManagerPolicy.dll,CbtBackgroundManagerPolicy.dll,SmartCardBackgroundPolicy.dll,Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll,SebBackgroundManagerPolicy.dll,ole32.dll,coml2.dll,OneCoreCommonProxyStub.dll,ActXPrxy.dll,execmodelproxy.dll,rsaenh.dll,licensemanagerapi.dll,capauthz.dll" "taskhostw.exe","3560","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,RPCRT4.dll,combase.dll,ucrtbase.dll,bcryptPrimitives.dll,OLEAUT32.dll,msvcp_win.dll,imm32.dll,USER32.dll,win32u.dll,GDI32.dll,gdi32full.dll,kernel.appcore.dll,sechost.dll,uxtheme.dll,dwmapi.dll,clbcatq.dll,wininet.dll,MsCtfMonitor.dll,MSCTF.dll,WINSTA.dll,MSUTB.dll,iertutil.dll,advapi32.dll,shcore.dll,InputService.dll,CoreMessaging.dll,CoreUIComponents.dll,wintypes.dll,EditBufferTestHook.dll,TextInputFramework.dll,ESENT.dll,ole32.dll,PlaySndSrv.dll,windows.storage.dll,powrprof.dll,shlwapi.dll,profapi.dll,MTFServer.dll,WINMM.dll,WINMMBASE.dll,cfgmgr32.dll,InputLocaleManager.dll,kbdus.dll,policymanager.dll,msvcp110_win.dll,CRYPTBASE.DLL" "tasklist.exe","1548","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,ADVAPI32.dll,msvcrt.dll,sechost.dll,RPCRT4.dll,USER32.dll,win32u.dll,GDI32.dll,gdi32full.dll,OLEAUT32.dll,msvcp_win.dll,VERSION.dll,MPR.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,WS2_32.dll,SHLWAPI.dll,framedynos.dll,dbghelp.dll,SspiCli.dll,netutils.dll,srvcli.dll,IMM32.DLL,kernel.appcore.dll,clbcatq.dll,wbemprox.dll,wbemcomn.dll,bcrypt.dll,Winsta.dll,wbemsvc.dll,fastprox.dll,wmiutils.dll" "TSVNCache.exe","4792","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,USER32.dll,win32u.dll,libsvn_tsvn.dll,libapr_tsvn.dll,GDI32.dll,gdi32full.dll,ADVAPI32.dll,WS2_32.dll,msvcrt.dll,sechost.dll,RPCRT4.dll,SHELL32.dll,libaprutil_tsvn.dll,ole32.dll,cfgmgr32.dll,combase.dll,WLDAP32.dll,windows.storage.dll,ucrtbase.dll,intl3_tsvn.dll,powrprof.dll,bcryptPrimitives.dll,shlwapi.dll,libsasl.dll,kernel.appcore.dll,shcore.dll,VCRUNTIME140.dll,profapi.dll,CRYPT32.dll,MSVCP140.dll,MSASN1.dll,CRYPTBASE.DLL,VERSION.dll,Secur32.dll,SSPICLI.DLL,MSWSOCK.dll,IMM32.DLL,crshhndl.dll,uxtheme.dll,PROPSYS.dll,OLEAUT32.dll,msvcp_win.dll,ntmarta.dll,MSCTF.dll,dwmapi.dll" "vmtoolsd.exe","2348","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,ADVAPI32.dll,msvcrt.dll,sechost.dll,RPCRT4.dll,ole32.dll,combase.dll,ucrtbase.dll,bcryptPrimitives.dll,GDI32.dll,gdi32full.dll,USER32.dll,win32u.dll,VERSION.dll,intl.dll,glib-2.0.dll,gmodule-2.0.dll,MSVCR90.dll,gobject-2.0.dll,gthread-2.0.dll,WS2_32.dll,vmtools.dll,SHELL32.dll,cfgmgr32.dll,windows.storage.dll,iconv.dll,powrprof.dll,shlwapi.dll,kernel.appcore.dll,shcore.dll,profapi.dll,OLEAUT32.dll,msvcp_win.dll,IpHlpApi.dll,ntmarta.dll,hgfsServer.dll,hgfs.dll,MPR.dll,hgfsUsability.dll,USERENV.dll,vix.dll,Secur32.dll,SSPICLI.DLL,autoLogon.dll,MSVCP90.dll,autoUpgrade.dll,WTSAPI32.dll,bitMapper.dll,deployPkgPlugin.dll,deployPkg.dll,diskWiper.dll,guestInfo.dll,hwUpgradeHelper.dll,SETUPAPI.dll,powerOps.dll,resolutionSet.dll,PSAPI.DLL,timeSync.dll,vmbackup.dll,clbcatq.dll,wbemprox.dll,wbemcomn.dll,bcrypt.dll,NSI.dll,dhcpcsvc6.DLL,dhcpcsvc.DLL,wbemsvc.dll,fastprox.dll,comsvcs.dll,CRYPTSP.dll,rsaenh.dll,CRYPTBASE.dll,sxs.dll,DNSAPI.dll,WINNSI.DLL,perfos.dll,perfproc.dll,perfdisk.dll,WMICLNT.dll" "vmtoolsd.exe","3064","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,ADVAPI32.dll,msvcrt.dll,sechost.dll,RPCRT4.dll,ole32.dll,combase.dll,ucrtbase.dll,bcryptPrimitives.dll,GDI32.dll,gdi32full.dll,USER32.dll,win32u.dll,VERSION.dll,intl.dll,glib-2.0.dll,MSVCR90.dll,gmodule-2.0.dll,gobject-2.0.dll,gthread-2.0.dll,WS2_32.dll,vmtools.dll,SHELL32.dll,cfgmgr32.dll,windows.storage.dll,powrprof.dll,shlwapi.dll,kernel.appcore.dll,shcore.dll,profapi.dll,OLEAUT32.dll,msvcp_win.dll,iconv.dll,IMM32.DLL,IpHlpApi.dll,uxtheme.dll,MSCTF.dll,hgfsServer.dll,hgfs.dll,MPR.dll,hgfsUsability.dll,USERENV.dll,vix.dll,Secur32.dll,SSPICLI.DLL,desktopEvents.dll,WTSAPI32.dll,MSVCP90.dll,dndcp.dll,sigc-2.0.dll,unity.dll,PSAPI.DLL,glibmm-2.4.dll,dwmapi.dll,WINSTA.dll,clbcatq.dll,dataexchange.dll,d3d11.dll,dcomp.dll,dxgi.dll,twinapi.appcore.dll,bcrypt.dll,VMToolsHook64.dll,gdiplus.dll,PROPSYS.dll,Windows.Shell.ServiceHostBuilder.dll,ActXPrxy.dll,WinTypes.dll,comctl32.dll,WindowsCodecs.dll,msxml3.dll,AppxPackaging.dll,OpcServices.DLL,urlmon.dll,XmlLite.dll,iertutil.dll,msxml6.dll,CRYPT32.dll,MSASN1.dll,mrmcorer.dll,Windows.UI.dll,Bcp47Langs.dll,LINKINFO.dll,apphelp.dll,gameux.dll,WININET.dll,TwinUI.dll,ieframe.dll,NETAPI32.dll,NETUTILS.DLL,WKSCLI.DLL,MLANG.dll,IconCodecService.dll,thumbcache.dll,edputil.dll" "Windows10FirewallControl.exe","4144","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,USER32.dll,win32u.dll,GDI32.dll,gdi32full.dll,comdlg32.dll,msvcrt.dll,combase.dll,MSIMG32.dll,ucrtbase.dll,RPCRT4.dll,bcryptPrimitives.dll,shcore.dll,SHLWAPI.dll,SHELL32.dll,COMCTL32.dll,cfgmgr32.dll,windows.storage.dll,powrprof.dll,advapi32.dll,sechost.dll,kernel.appcore.dll,profapi.dll,ole32.dll,WINSPOOL.DRV,OLEAUT32.dll,msvcp_win.dll,WS2_32.dll,iphlpapi.dll,NETAPI32.dll,VERSION.dll,WINMM.dll,USERENV.dll,MPR.dll,WINMMBASE.dll,bcrypt.dll,SAMCLI.DLL,NETUTILS.DLL,IMM32.DLL,uxtheme.dll,RICHED20.DLL,msls31.dll,USP10.dll,clbcatq.dll,sxs.dll,MSCTF.dll,WINNSI.DLL,NSI.dll,dwmapi.dll,WindowsCodecs.dll,upnp.dll,WINHTTP.dll,SSDPAPI.dll" "Windows10FirewallService.exe","1256","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,USER32.dll,fwpuclnt.dll,win32u.dll,msvcrt.dll,GDI32.dll,gdi32full.dll,RPCRT4.dll,ADVAPI32.dll,bcrypt.dll,sechost.dll,SHELL32.dll,cfgmgr32.dll,windows.storage.dll,combase.dll,ucrtbase.dll,bcryptPrimitives.dll,powrprof.dll,shlwapi.dll,kernel.appcore.dll,shcore.dll,profapi.dll,ole32.dll,OLEAUT32.dll,msvcp_win.dll,WS2_32.dll,USERENV.dll,CRYPT32.dll,MSWSOCK.dll,MSASN1.dll,PSAPI.DLL,wevtapi.dll,iphlpapi.dll,DNSAPI.dll,NSI.dll,VERSION.dll,NETAPI32.dll,SAMCLI.DLL,NETUTILS.DLL,clbcatq.dll,secur32.dll,SSPICLI.DLL,security.dll,wshqos.dll,wshtcpip.DLL,wship6.dll,dhcpcsvc6.DLL,dhcpcsvc.DLL,sxs.dll,browcli.dll,cscapi.dll" "winlogon.exe","1008","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,sechost.dll,RPCRT4.dll,powrprof.dll,bcrypt.dll,ucrtbase.dll,advapi32.dll,profapi.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,IMM32.DLL,winsta.dll,UXINIT.dll,shcore.dll,combase.dll,bcryptPrimitives.dll,UxTheme.dll,CRYPT32.dll,MSASN1.dll,DPAPI.dll,CRYPTBASE.dll,dwminit.dll,SspiCli.dll,apphelp.dll,UxTSB.dll,ole32.dll,MSIMG32.dll,dbghelp.dll,usermgrcli.dll,ntmarta.dll,CRYPTSP.dll,rsaenh.dll,WindowsCodecs.dll,MPR.dll" "WizMouse.exe","4560","ntdll.dll,wow64.dll,wow64win.dll,wow64cpu.dll" "WmiPrvSE.exe","4092","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,FastProx.dll,wbemcomn.dll,NCObjAPI.DLL,combase.dll,WS2_32.dll,bcrypt.dll,ucrtbase.dll,sechost.dll,RPCRT4.dll,bcryptPrimitives.dll,advapi32.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,kernel.appcore.dll,clbcatq.dll,wbemprox.dll,OLEAUT32.dll,msvcp_win.dll,wbemsvc.dll,wmiutils.dll,cimwin32.dll,powrprof.dll,framedynos.dll,SspiCli.dll,winbrand.dll" ------------------------------------------------------------------------------------------- SCHTASKS /Query /FO CSV (states of all scheduled tasks): "\Adobe Acrobat Update Task","N/A","Disabled" "\Adobe Uninstaller","N/A","Disabled" "\AdobeAAMUpdater-1.0-W10PVM-NoelC","N/A","Disabled" "\Aero Glass","N/A","Running" "\DisableLockScreen","N/A","Ready" "\DisableLockScreen","N/A","Ready" "\GoogleUpdateTaskMachineCore","N/A","Disabled" "\GoogleUpdateTaskMachineCore","N/A","Disabled" "\GoogleUpdateTaskMachineUA","N/A","Disabled" "\SpeechRuntimeTask","N/A","Disabled" "\WizMouse","N/A","Ready" "\WizMouse","N/A","Ready" "\Microsoft\VisualStudio\VSIX Auto Update 14","N/A","Disabled" "\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319","N/A","Disabled" "\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64","N/A","Disabled" "\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Critical","N/A","Disabled" "\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Critical","N/A","Disabled" "\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)","N/A","Disabled" "\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)","N/A","Disabled" "\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)","N/A","Disabled" "\Microsoft\Windows\AppID\EDP Policy Manager","N/A","Disabled" "\Microsoft\Windows\AppID\EDP Policy Manager","N/A","Disabled" "\Microsoft\Windows\AppID\PolicyConverter","N/A","Disabled" "\Microsoft\Windows\AppID\SmartScreenSpecific","N/A","Disabled" "\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck","N/A","Disabled" "\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser","N/A","Disabled" "\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser","N/A","Disabled" "\Microsoft\Windows\Application Experience\ProgramDataUpdater","N/A","Disabled" "\Microsoft\Windows\Application Experience\StartupAppTask","N/A","Disabled" "\Microsoft\Windows\ApplicationData\appuriverifierdaily","N/A","Disabled" "\Microsoft\Windows\ApplicationData\appuriverifierinstall","N/A","Disabled" "\Microsoft\Windows\ApplicationData\appuriverifierinstall","N/A","Disabled" "\Microsoft\Windows\ApplicationData\CleanupTemporaryState","N/A","Disabled" "\Microsoft\Windows\ApplicationData\DsSvcCleanup","N/A","Disabled" "\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup","N/A","Disabled" "\Microsoft\Windows\Autochk\Proxy","N/A","Disabled" "\Microsoft\Windows\Bluetooth\UninstallDeviceTask","N/A","Disabled" "\Microsoft\Windows\CertificateServicesClient\AikCertEnrollTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\CryptoPolicyTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\KeyPreGenTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\KeyPreGenTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\KeyPreGenTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\KeyPreGenTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\KeyPreGenTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\SystemTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\SystemTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\SystemTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\UserTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\UserTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\UserTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\UserTask-Roam","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\UserTask-Roam","N/A","Ready" "\Microsoft\Windows\Chkdsk\ProactiveScan","N/A","Ready" "\Microsoft\Windows\Clip\License Validation","N/A","Disabled" "\Microsoft\Windows\CloudExperienceHost\CreateObjectTask","N/A","Disabled" "\Microsoft\Windows\Customer Experience Improvement Program\Consolidator","N/A","Disabled" "\Microsoft\Windows\Customer Experience Improvement Program\HypervisorFlightingTask","N/A","Disabled" "\Microsoft\Windows\Customer Experience Improvement Program\KernelCeipTask","N/A","Disabled" "\Microsoft\Windows\Customer Experience Improvement Program\UsbCeip","N/A","Disabled" "\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan","12/25/2016 6:36:00 PM","Ready" "\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan","12/30/2016 11:27:52 AM","Ready" "\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan for Crash Recovery","N/A","Ready" "\Microsoft\Windows\Defrag\ScheduledDefrag","N/A","Ready" "\Microsoft\Windows\Device Information\Device","N/A","Disabled" "\Microsoft\Windows\Device Information\Device","N/A","Disabled" "\Microsoft\Windows\Device Setup\Metadata Refresh","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\HandleCommand","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\HandleWnsCommand","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\IntegrityCheck","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\LocateCommandUserSession","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceAccountChange","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceAccountChange","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceConnectedToNetwork","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceLocationRightsChange","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePeriodic1","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePeriodic24","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePeriodic6","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePolicyChange","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePolicyChange","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceScreenOnOff","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceScreenOnOff","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceSettingChange","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterUserDevice","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterUserDevice","N/A","Disabled" "\Microsoft\Windows\Diagnosis\Scheduled","N/A","Ready" "\Microsoft\Windows\DiskCleanup\SilentCleanup","N/A","Disabled" "\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector","N/A","Disabled" "\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver","N/A","Disabled" "\Microsoft\Windows\DiskFootprint\Diagnostics","N/A","Ready" "\Microsoft\Windows\DiskFootprint\StorageSense","N/A","Ready" "\Microsoft\Windows\DUSM\dusmtask","N/A","Disabled" "\Microsoft\Windows\EDP\EDP App Launch Task","N/A","Disabled" "\Microsoft\Windows\EDP\EDP Auth Task","N/A","Disabled" "\Microsoft\Windows\EnterpriseMgmt\MDMMaintenenceTask","N/A","Disabled" "\Microsoft\Windows\ErrorDetails\EnableErrorDetailsUpdate","N/A","Disabled" "\Microsoft\Windows\ErrorDetails\ErrorDetailsUpdate","N/A","Disabled" "\Microsoft\Windows\Feedback\Siuf\DmClient","N/A","Disabled" "\Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload","N/A","Disabled" "\Microsoft\Windows\File Classification Infrastructure\Property Definition Sync","N/A","Disabled" "\Microsoft\Windows\FileHistory\File History (maintenance mode)","N/A","Disabled" "\Microsoft\Windows\LanguageComponentsInstaller\Installation","N/A","Disabled" "\Microsoft\Windows\LanguageComponentsInstaller\Installation","N/A","Disabled" "\Microsoft\Windows\LanguageComponentsInstaller\Uninstallation","N/A","Disabled" "\Microsoft\Windows\License Manager\TempSignedLicenseExchange","N/A","Disabled" "\Microsoft\Windows\Location\Notifications","N/A","Disabled" "\Microsoft\Windows\Location\WindowsActionDialog","N/A","Disabled" "\Microsoft\Windows\Maintenance\WinSAT","N/A","Ready" "\Microsoft\Windows\Management\Provisioning\Logon","N/A","Disabled" "\Microsoft\Windows\Maps\MapsToastTask","N/A","Disabled" "\Microsoft\Windows\Maps\MapsUpdateTask","N/A","Disabled" "\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents","N/A","Ready" "\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents","N/A","Ready" "\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents","N/A","Ready" "\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents","N/A","Ready" "\Microsoft\Windows\MemoryDiagnostic\RunFullMemoryDiagnostic","N/A","Ready" "\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser","N/A","Disabled" "\Microsoft\Windows\MUI\LPRemove","N/A","Disabled" "\Microsoft\Windows\Multimedia\SystemSoundsService","N/A","Running" "\Microsoft\Windows\NetCfg\BindingWorkItemQueueHandler","N/A","Disabled" "\Microsoft\Windows\NetTrace\GatherNetworkInfo","N/A","Disabled" "\Microsoft\Windows\NlaSvc\WiFiTask","N/A","Disabled" "\Microsoft\Windows\Offline Files\Background Synchronization","N/A","Disabled" "\Microsoft\Windows\Offline Files\Logon Synchronization","N/A","Disabled" "\Microsoft\Windows\PI\Secure-Boot-Update","N/A","Disabled" "\Microsoft\Windows\PI\Sqm-Tasks","N/A","Disabled" "\Microsoft\Windows\Plug and Play\Device Install Group Policy","N/A","Ready" "\Microsoft\Windows\Plug and Play\Device Install Reboot Required","N/A","Ready" "\Microsoft\Windows\Plug and Play\Plug and Play Cleanup","N/A","Ready" "\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers","N/A","Ready" "\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem","N/A","Disabled" "\Microsoft\Windows\Ras\MobilityManager","N/A","Disabled" "\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE","N/A","Disabled" "\Microsoft\Windows\Registry\RegIdleBackup","N/A","Ready" "\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask","N/A","Disabled" "\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask","N/A","Disabled" "\Microsoft\Windows\RetailDemo\CleanupOfflineContent","N/A","Disabled" "\Microsoft\Windows\Servicing\StartComponentCleanup","N/A","Disabled" "\Microsoft\Windows\SettingSync\BackupTask","N/A","Disabled" "\Microsoft\Windows\SettingSync\NetworkStateChangeTask","N/A","Disabled" "\Microsoft\Windows\SettingSync\NetworkStateChangeTask","N/A","Disabled" "\Microsoft\Windows\Setup\SetupCleanupTask","N/A","Disabled" "\Microsoft\Windows\SharedPC\Account Cleanup","N/A","Disabled" "\Microsoft\Windows\Shell\CreateObjectTask","N/A","Disabled" "\Microsoft\Windows\Shell\FamilySafetyMonitor","N/A","Disabled" "\Microsoft\Windows\Shell\FamilySafetyMonitorToastTask","N/A","Disabled" "\Microsoft\Windows\Shell\FamilySafetyRefreshTask","N/A","Disabled" "\Microsoft\Windows\Shell\IndexerAutomaticMaintenance","N/A","Disabled" "\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask","N/A","Disabled" "\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskLogon","N/A","Disabled" "\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskNetwork","N/A","Disabled" "\Microsoft\Windows\SpacePort\SpaceAgentTask","N/A","Ready" "\Microsoft\Windows\SpacePort\SpaceAgentTask","N/A","Ready" "\Microsoft\Windows\SpacePort\SpaceManagerTask","N/A","Ready" "\Microsoft\Windows\SpacePort\SpaceManagerTask","N/A","Ready" "\Microsoft\Windows\Speech\SpeechModelDownloadTask","N/A","Disabled" "\Microsoft\Windows\Storage Tiers Management\Storage Tiers Management Initialization","N/A","Disabled" "\Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization","N/A","Disabled" "\Microsoft\Windows\Subscription\EnableLicenseAcquisition","N/A","Disabled" "\Microsoft\Windows\Subscription\EnableLicenseAcquisition","N/A","Disabled" "\Microsoft\Windows\Subscription\EnableLicenseAcquisition","N/A","Disabled" "\Microsoft\Windows\Subscription\LicenseAcquisition","N/A","Disabled" "\Microsoft\Windows\Subscription\LicenseAcquisition","N/A","Disabled" "\Microsoft\Windows\Subscription\LicenseAcquisition","N/A","Disabled" "\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate","N/A","Disabled" "\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance","N/A","Disabled" "\Microsoft\Windows\Sysmain\ResPriStaticDbSync","N/A","Disabled" "\Microsoft\Windows\Sysmain\WsSwapAssessmentTask","N/A","Disabled" "\Microsoft\Windows\SystemRestore\SR","N/A","Ready" "\Microsoft\Windows\Task Manager\Interactive","N/A","Ready" "\Microsoft\Windows\TextServicesFramework\MsCtfMonitor","N/A","Running" "\Microsoft\Windows\Time Synchronization\ForceSynchronizeTime","N/A","Ready" "\Microsoft\Windows\Time Synchronization\SynchronizeTime","N/A","Ready" "\Microsoft\Windows\Time Zone\SynchronizeTimeZone","N/A","Ready" "\Microsoft\Windows\TPM\Tpm-HASCertRetr","N/A","Disabled" "\Microsoft\Windows\TPM\Tpm-Maintenance","N/A","Disabled" "\Microsoft\Windows\TPM\Tpm-Maintenance","N/A","Disabled" "\Microsoft\Windows\TPM\Tpm-Maintenance","N/A","Disabled" "\Microsoft\Windows\TPM\Tpm-Maintenance","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\Maintenance Install","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\Policy Install","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\Reboot","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\Refresh Settings","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\Resume On Boot","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\Schedule Scan","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\Schedule Scan","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\Schedule Scan","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\USO_RebootDisplay","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_WnfDisplay","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\USO_WnfDisplay","N/A","Disabled" "\Microsoft\Windows\UPnP\UPnPHostConfig","N/A","Disabled" "\Microsoft\Windows\User Profile Service\HiveUploadTask","N/A","Disabled" "\Microsoft\Windows\WCM\WiFiTask","N/A","Disabled" "\Microsoft\Windows\WDI\ResolutionHost","N/A","Disabled" "\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance","N/A","Ready" "\Microsoft\Windows\Windows Defender\Windows Defender Cleanup","N/A","Ready" "\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan","N/A","Ready" "\Microsoft\Windows\Windows Defender\Windows Defender Verification","N/A","Ready" "\Microsoft\Windows\Windows Error Reporting\QueueReporting","N/A","Disabled" "\Microsoft\Windows\Windows Error Reporting\QueueReporting","N/A","Disabled" "\Microsoft\Windows\Windows Error Reporting\QueueReporting","N/A","Disabled" "\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange","N/A","Disabled" "\Microsoft\Windows\Windows Media Sharing\UpdateLibrary","N/A","Disabled" "\Microsoft\Windows\WindowsColorSystem\Calibration Loader","N/A","Disabled" "\Microsoft\Windows\WindowsColorSystem\Calibration Loader","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUFirmwareInstall","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUScheduledInstall","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUSessionConnect","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUSessionConnect","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUSessionConnect","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUSessionConnect","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUSessionConnect","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\Automatic App Update","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\Automatic App Update","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\Scheduled Start","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\Scheduled Start","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\Scheduled Start","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\Scheduled Start","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\sih","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\sihboot","N/A","Disabled" "\Microsoft\Windows\Wininet\CacheTask","N/A","Running" "\Microsoft\Windows\WOF\WIM-Hash-Management","N/A","Ready" "\Microsoft\Windows\WOF\WIM-Hash-Management","N/A","Ready" "\Microsoft\Windows\WOF\WIM-Hash-Validation","N/A","Ready" "\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization","N/A","Disabled" "\Microsoft\Windows\Work Folders\Work Folders Maintenance Work","N/A","Disabled" "\Microsoft\Windows\Workplace Join\Automatic-Device-Join","N/A","Disabled" "\Microsoft\XblGameSave\XblGameSaveTask","N/A","Disabled" "\Microsoft\XblGameSave\XblGameSaveTaskLogon","N/A","Disabled" "\OfficeSoftwareProtectionPlatform\SvcRestartTask","N/A","Disabled" ------------------------------------------------------------------------------------------- SC qc (configurations of all services): C:\TEMP>SC qc "AdobeARMservice" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AdobeARMservice TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Adobe Acrobat Update Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "AdobeUpdateService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AdobeUpdateService TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : AdobeUpdateService DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "AGSService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AGSService TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Adobe Genuine Software Integrity Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "AJRouter" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AJRouter TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : AllJoyn Router Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "ALG" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: ALG TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\alg.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Application Layer Gateway Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "AppIDSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AppIDSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : ProfSvc_Group TAG : 0 DISPLAY_NAME : Application Identity DEPENDENCIES : RpcSs : AppID : CryptSvc SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "Appinfo" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Appinfo TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Application Information DEPENDENCIES : RpcSs : ProfSvc SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "AppMgmt" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AppMgmt TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Application Management DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "AppReadiness" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AppReadiness TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k AppReadiness LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : App Readiness DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "AppVClient" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AppVClient TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\AppVClient.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Microsoft App-V Client DEPENDENCIES : RpcSS : netprofm : AppvVfs : AppVStrm SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "AppXSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AppXSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k wsappx LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : AppX Deployment Service (AppXSVC) DEPENDENCIES : rpcss : staterepository SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "aspnet_state" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: aspnet_state TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : ASP.NET State Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "AudioEndpointBuilder" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AudioEndpointBuilder TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : AudioGroup TAG : 0 DISPLAY_NAME : Windows Audio Endpoint Builder DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Audiosrv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Audiosrv TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : AudioGroup TAG : 0 DISPLAY_NAME : Windows Audio DEPENDENCIES : AudioEndpointBuilder : RpcSs SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "AxInstSV" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AxInstSV TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k AxInstSVGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : ActiveX Installer (AxInstSV) DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "BDESVC" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: BDESVC TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : BitLocker Drive Encryption Service DEPENDENCIES : SERVICE_START_NAME : localSystem C:\TEMP>SC qc "BFE" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: BFE TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork LOAD_ORDER_GROUP : NetworkProvider TAG : 0 DISPLAY_NAME : Base Filtering Engine DEPENDENCIES : RpcSs SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "BITS" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: BITS TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START (DELAYED) ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Background Intelligent Transfer Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "BrokerInfrastructure" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: BrokerInfrastructure TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k DcomLaunch LOAD_ORDER_GROUP : COM Infrastructure TAG : 0 DISPLAY_NAME : Background Tasks Infrastructure Service DEPENDENCIES : RpcEptMapper : DcomLaunch : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Browser" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Browser TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : NetworkProvider TAG : 0 DISPLAY_NAME : Computer Browser DEPENDENCIES : LanmanWorkstation : LanmanServer SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "BthHFSrv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: BthHFSrv TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Bluetooth Handsfree Service DEPENDENCIES : bthserv SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "bthserv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: bthserv TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Bluetooth Support Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "CDPSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: CDPSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START (DELAYED) ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Connected Devices Platform Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "CDPUserSvc_354e6" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: CDPUserSvc_354e6 TYPE : e0 USER_SHARE_PROCESS INSTANCE START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : CDPUserSvc_354e6 DEPENDENCIES : SERVICE_START_NAME : C:\TEMP>SC qc "CertPropSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: CertPropSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Certificate Propagation DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "ClipSVC" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: ClipSVC TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k wsappx LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Client License Service (ClipSVC) DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "COMSysApp" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: COMSysApp TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : COM+ System Application DEPENDENCIES : RpcSs : EventSystem : SENS SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "CoreMessagingRegistrar" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: CoreMessagingRegistrar TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : CoreMessaging DEPENDENCIES : rpcss SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "CryptSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: CryptSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Cryptographic Services DEPENDENCIES : RpcSs SERVICE_START_NAME : NT Authority\NetworkService C:\TEMP>SC qc "CscService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: CscService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : ProfSvc_Group TAG : 0 DISPLAY_NAME : Offline Files DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "DcomLaunch" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DcomLaunch TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k DcomLaunch LOAD_ORDER_GROUP : COM Infrastructure TAG : 0 DISPLAY_NAME : DCOM Server Process Launcher DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "DcpSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DcpSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : DataCollectionPublishingService DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "defragsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: defragsvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k defragsvc LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Optimize drives DEPENDENCIES : RPCSS SERVICE_START_NAME : localSystem C:\TEMP>SC qc "DeviceAssociationService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DeviceAssociationService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Device Association Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "DeviceInstall" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DeviceInstall TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k DcomLaunch LOAD_ORDER_GROUP : PlugPlay TAG : 0 DISPLAY_NAME : Device Install Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "DevQueryBroker" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DevQueryBroker TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : DevQuery Background Discovery Broker DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Dhcp" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Dhcp TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : DHCP Client DEPENDENCIES : NSI : Tdx : Afd SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "diagnosticshub.standardcollector.service" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: diagnosticshub.standardcollector.service TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Microsoft (R) Diagnostics Hub Standard Collector Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "DiagTrack" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DiagTrack TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k utcsvc LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Connected User Experiences and Telemetry DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "DmEnrollmentSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DmEnrollmentSvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Device Management Enrollment Service DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "dmwappushservice" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: dmwappushservice TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : dmwappushsvc DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Dnscache" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Dnscache TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : DNS Client DEPENDENCIES : Tdx : nsi SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "DoSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DoSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Delivery Optimization DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "dot3svc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: dot3svc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : Wired AutoConfig DEPENDENCIES : RpcSs : Ndisuio : Eaphost SERVICE_START_NAME : localSystem C:\TEMP>SC qc "DPS" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DPS TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Diagnostic Policy Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "DsmSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DsmSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Device Setup Manager DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "DsSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DsSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Data Sharing Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "EapHost" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: EapHost TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Extensible Authentication Protocol DEPENDENCIES : RPCSS : KeyIso SERVICE_START_NAME : localSystem C:\TEMP>SC qc "EFS" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: EFS TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\lsass.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Encrypting File System (EFS) DEPENDENCIES : RPCSS SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "embeddedmode" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: embeddedmode TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Embedded Mode DEPENDENCIES : BrokerInfrastructure SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "EntAppSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: EntAppSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k appmodel LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Enterprise App Management Service DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "EventLog" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: EventLog TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : Event Log TAG : 0 DISPLAY_NAME : Windows Event Log DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "EventSystem" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: EventSystem TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : COM+ Event System DEPENDENCIES : rpcss SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "Fax" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Fax TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\fxssvc.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Fax DEPENDENCIES : TapiSrv : RpcSs : Spooler SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "fdPHost" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: fdPHost TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Function Discovery Provider Host DEPENDENCIES : RpcSs : http SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "FDResPub" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: FDResPub TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Function Discovery Resource Publication DEPENDENCIES : RpcSs : http SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "fhsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: fhsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : File History Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "FontCache" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: FontCache TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : AudioGroup TAG : 0 DISPLAY_NAME : Windows Font Cache Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "FontCache3.0.0.0" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: FontCache3.0.0.0 TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Presentation Foundation Font Cache 3.0.0.0 DEPENDENCIES : SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "FrameServer" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: FrameServer TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k Camera LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Camera Frame Server DEPENDENCIES : rpcss SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "gpsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: gpsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : ProfSvc_Group TAG : 0 DISPLAY_NAME : Group Policy Client DEPENDENCIES : RPCSS : Mup SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "gupdate" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: gupdate TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Google Update Service (gupdate) DEPENDENCIES : RPCSS SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "gupdatem" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: gupdatem TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Google Update Service (gupdatem) DEPENDENCIES : RPCSS SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "hidserv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: hidserv TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Human Interface Device Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "HomeGroupListener" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: HomeGroupListener TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : HomeGroup Listener DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "HomeGroupProvider" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: HomeGroupProvider TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : HomeGroup Provider DEPENDENCIES : netprofm : fdrespub : fdphost SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "HvHost" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: HvHost TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : HV Host Service DEPENDENCIES : hvservice SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "icssvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: icssvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : Windows Mobile Hotspot Service DEPENDENCIES : RpcSs : wcmsvc SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "IKEEXT" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: IKEEXT TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : IKE and AuthIP IPsec Keying Modules DEPENDENCIES : BFE : nsi SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "iphlpsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: iphlpsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k NetSvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : IP Helper DEPENDENCIES : RpcSS : Tdx : winmgmt : tcpip : nsi : WinHttpAutoProxySvc SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "IpOverUsbSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: IpOverUsbSvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : "C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Phone IP over USB Transport (IpOverUsbSvc) DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "irmon" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: irmon TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : Infrared monitor service DEPENDENCIES : irda SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "KeyIso" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: KeyIso TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\lsass.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : CNG Key Isolation DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "KtmRm" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: KtmRm TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k NetworkServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : KtmRm for Distributed Transaction Coordinator DEPENDENCIES : RPCSS : SamSS SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "LanmanServer" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: LanmanServer TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Server DEPENDENCIES : SamSS : Srv2 SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "LanmanWorkstation" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: LanmanWorkstation TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : NetworkProvider TAG : 0 DISPLAY_NAME : Workstation DEPENDENCIES : Bowser : MRxSmb20 : NSI SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "lfsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: lfsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Geolocation Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "LicenseManager" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: LicenseManager TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows License Manager Service DEPENDENCIES : rpcss SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "lltdsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: lltdsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Link-Layer Topology Discovery Mapper DEPENDENCIES : rpcss : lltdio SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "lmhosts" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: lmhosts TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : TCP/IP NetBIOS Helper DEPENDENCIES : Afd SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "LSM" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: LSM TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k DcomLaunch LOAD_ORDER_GROUP : COM Infrastructure TAG : 0 DISPLAY_NAME : Local Session Manager DEPENDENCIES : RpcEptMapper : DcomLaunch : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "MapsBroker" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: MapsBroker TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : NetworkService TAG : 0 DISPLAY_NAME : Downloaded Maps Manager DEPENDENCIES : rpcss SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "MBAMService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: MBAMService TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : MBAMService DEPENDENCIES : MBAMProtector SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "MessagingService_354e6" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: MessagingService_354e6 TYPE : e0 USER_SHARE_PROCESS INSTANCE START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : MessagingService_354e6 DEPENDENCIES : SERVICE_START_NAME : C:\TEMP>SC qc "MpsSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: MpsSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork LOAD_ORDER_GROUP : NetworkProvider TAG : 0 DISPLAY_NAME : Windows Firewall DEPENDENCIES : mpsdrv : bfe SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "MSDTC" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: MSDTC TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\msdtc.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Distributed Transaction Coordinator DEPENDENCIES : RPCSS : SamSS SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "MSiSCSI" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: MSiSCSI TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : iSCSI TAG : 0 DISPLAY_NAME : Microsoft iSCSI Initiator Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "msiserver" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: msiserver TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\msiexec.exe /V LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Installer DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "NcaSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: NcaSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k NetSvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network Connectivity Assistant DEPENDENCIES : BFE : dnscache : NSI : iphlpsvc SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "NcbService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: NcbService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network Connection Broker DEPENDENCIES : RpcSS : tcpip SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "NcdAutoSetup" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: NcdAutoSetup TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network Connected Devices Auto-Setup DEPENDENCIES : netprofm SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "Netlogon" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Netlogon TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\lsass.exe LOAD_ORDER_GROUP : MS_WindowsRemoteValidation TAG : 0 DISPLAY_NAME : Netlogon DEPENDENCIES : LanmanWorkstation SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Netman" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Netman TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network Connections DEPENDENCIES : RpcSs : nsi SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "netprofm" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: netprofm TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network List Service DEPENDENCIES : RpcSs : nlasvc SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "NetSetupSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: NetSetupSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network Setup Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "NetTcpPortSharing" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: NetTcpPortSharing TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Net.Tcp Port Sharing Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "NgcCtnrSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: NgcCtnrSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : Cryptography TAG : 0 DISPLAY_NAME : Microsoft Passport Container DEPENDENCIES : RpcSs SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "NgcSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: NgcSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : Cryptography TAG : 0 DISPLAY_NAME : Microsoft Passport DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "NlaSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: NlaSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network Location Awareness DEPENDENCIES : NSI : RpcSs : TcpIp : Dhcp : Eventlog SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "nlsX86cc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: nlsX86cc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\SysWOW64\nlssrv32.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Nalpeiron Licensing Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "nsi" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: nsi TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network Store Interface Service DEPENDENCIES : rpcss : nsiproxy SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "OneSyncSvc_354e6" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: OneSyncSvc_354e6 TYPE : e0 USER_SHARE_PROCESS INSTANCE START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Sync Host_354e6 DEPENDENCIES : SERVICE_START_NAME : C:\TEMP>SC qc "p2pimsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: p2pimsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Peer Networking Identity Manager DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "p2psvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: p2psvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Peer Networking Grouping DEPENDENCIES : p2pimsvc : PNRPSvc SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "PcaSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PcaSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Program Compatibility Assistant Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "PeerDistSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PeerDistSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k PeerDist LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : BranchCache DEPENDENCIES : http SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "PerfHost" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PerfHost TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\SysWow64\perfhost.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Performance Counter DLL Host DEPENDENCIES : RPCSS SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "PhoneSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PhoneSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Phone Service DEPENDENCIES : RpcSs SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "PimIndexMaintenanceSvc_354e6" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PimIndexMaintenanceSvc_354e6 TYPE : e0 USER_SHARE_PROCESS INSTANCE START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Contact Data_354e6 DEPENDENCIES : SERVICE_START_NAME : C:\TEMP>SC qc "pla" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: pla TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Performance Logs & Alerts DEPENDENCIES : RPCSS SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "PlugPlay" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PlugPlay TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k DcomLaunch LOAD_ORDER_GROUP : PlugPlay TAG : 0 DISPLAY_NAME : Plug and Play DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "PNRPAutoReg" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PNRPAutoReg TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : PNRP Machine Name Publication Service DEPENDENCIES : pnrpsvc SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "PNRPsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PNRPsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Peer Name Resolution Protocol DEPENDENCIES : p2pimsvc SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "PolicyAgent" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PolicyAgent TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : IPsec Policy Agent DEPENDENCIES : Tcpip : bfe SERVICE_START_NAME : NT Authority\NetworkService C:\TEMP>SC qc "Power" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Power TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k DcomLaunch LOAD_ORDER_GROUP : Plugplay TAG : 0 DISPLAY_NAME : Power DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "PrintNotify" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PrintNotify TYPE : 120 WIN32_SHARE_PROCESS (interactive) START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k print LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Printer Extensions and Notifications DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "ProfSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: ProfSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : profsvc_group TAG : 0 DISPLAY_NAME : User Profile Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "PSEXESVC" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PSEXESVC TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\PSEXESVC.EXE LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : PsExec DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "QWAVE" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: QWAVE TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Quality Windows Audio Video Experience DEPENDENCIES : rpcss : psched : QWAVEdrv : LLTDIO SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "RasAuto" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RasAuto TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Access Auto Connection Manager DEPENDENCIES : RasAcd SERVICE_START_NAME : localSystem C:\TEMP>SC qc "RasMan" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RasMan TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Access Connection Manager DEPENDENCIES : SstpSvc SERVICE_START_NAME : localSystem C:\TEMP>SC qc "RemoteAccess" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RemoteAccess TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Routing and Remote Access DEPENDENCIES : RpcSS : Bfe : RasMan : Http : +NetBIOSGroup SERVICE_START_NAME : localSystem C:\TEMP>SC qc "RemoteRegistry" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RemoteRegistry TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k localService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Registry DEPENDENCIES : RPCSS SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "RetailDemo" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RetailDemo TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Retail Demo Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "RmSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RmSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Radio Management Service DEPENDENCIES : RpcSs SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "RpcEptMapper" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RpcEptMapper TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k RPCSS LOAD_ORDER_GROUP : COM Infrastructure TAG : 0 DISPLAY_NAME : RPC Endpoint Mapper DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "RpcLocator" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RpcLocator TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\locator.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Procedure Call (RPC) Locator DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "RpcSs" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RpcSs TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k rpcss LOAD_ORDER_GROUP : COM Infrastructure TAG : 0 DISPLAY_NAME : Remote Procedure Call (RPC) DEPENDENCIES : RpcEptMapper : DcomLaunch SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "SamSs" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SamSs TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\lsass.exe LOAD_ORDER_GROUP : MS_WindowsLocalValidation TAG : 0 DISPLAY_NAME : Security Accounts Manager DEPENDENCIES : RPCSS SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SCardSvr" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SCardSvr TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : SmartCardGroup TAG : 0 DISPLAY_NAME : Smart Card DEPENDENCIES : wudfsvc SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "ScDeviceEnum" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: ScDeviceEnum TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Smart Card Device Enumeration Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Schedule" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Schedule TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : SchedulerGroup TAG : 0 DISPLAY_NAME : Task Scheduler DEPENDENCIES : RPCSS : SystemEventsBroker SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SCPolicySvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SCPolicySvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Smart Card Removal Policy DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SDRSVC" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SDRSVC TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k SDRSVC LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Backup DEPENDENCIES : RPCSS SERVICE_START_NAME : localSystem C:\TEMP>SC qc "seclogon" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: seclogon TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Secondary Logon DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SENS" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SENS TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : ProfSvc_Group TAG : 0 DISPLAY_NAME : System Event Notification Service DEPENDENCIES : EventSystem SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Sense" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Sense TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Defender Advanced Threat Protection Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SensorDataService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SensorDataService TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\SensorDataService.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Sensor Data Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SensorService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SensorService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Sensor Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SensrSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SensrSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Sensor Monitoring Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "SessionEnv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SessionEnv TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Desktop Configuration DEPENDENCIES : RPCSS : LanmanWorkstation SERVICE_START_NAME : localSystem C:\TEMP>SC qc "SharedAccess" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SharedAccess TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Internet Connection Sharing (ICS) DEPENDENCIES : BFE SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "ShellHWDetection" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: ShellHWDetection TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : ShellSvcGroup TAG : 0 DISPLAY_NAME : Shell Hardware Detection DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "shpamsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: shpamsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Shared PC Account Manager DEPENDENCIES : RpcSs : ProfSvc SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SkypeUpdate" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SkypeUpdate TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : "C:\Program Files (x86)\Skype\Updater\Updater.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Skype Updater DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "smphost" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: smphost TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k smphost LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Microsoft Storage Spaces SMP DEPENDENCIES : RPCSS SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "SmsRouter" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SmsRouter TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Microsoft Windows SMS Router Service. DEPENDENCIES : RpcSs : NdisUio SERVICE_START_NAME : localSystem C:\TEMP>SC qc "SNMPTRAP" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SNMPTRAP TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\snmptrap.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : SNMP Trap DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "Spooler" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Spooler TYPE : 110 WIN32_OWN_PROCESS (interactive) START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\spoolsv.exe LOAD_ORDER_GROUP : SpoolerGroup TAG : 0 DISPLAY_NAME : Print Spooler DEPENDENCIES : RPCSS : http SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "sppsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: sppsvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START (DELAYED) ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\sppsvc.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Software Protection DEPENDENCIES : RpcSs SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "SQLWriter" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SQLWriter TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : SQL Server VSS Writer DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SSDPSRV" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SSDPSRV TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : SSDP Discovery DEPENDENCIES : HTTP SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "SstpSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SstpSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Secure Socket Tunneling Protocol Service DEPENDENCIES : SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "StateRepository" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: StateRepository TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k appmodel LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : State Repository Service DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "stisvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: stisvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k imgsvc LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Image Acquisition (WIA) DEPENDENCIES : RpcSs SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "StorSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: StorSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Storage Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "svsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: svsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Spot Verifier DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "swprv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: swprv TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k swprv LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Microsoft Software Shadow Copy Provider DEPENDENCIES : RPCSS SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SysMain" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SysMain TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Superfetch DEPENDENCIES : rpcss : fileinfo SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SystemEventsBroker" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SystemEventsBroker TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k DcomLaunch LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : System Events Broker DEPENDENCIES : RpcEptMapper : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "TabletInputService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: TabletInputService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : PlugPlay TAG : 0 DISPLAY_NAME : Touch Keyboard and Handwriting Panel Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "TapiSrv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: TapiSrv TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Telephony DEPENDENCIES : RpcSs SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "Te.Service" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Te.Service TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : "C:\Program Files (x86)\Windows Kits\10\Testing\Runtimes\TAEF\Wex.Services.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Te.Service DEPENDENCIES : RpcSs : SecLogon SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "TermService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: TermService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Desktop Services DEPENDENCIES : RPCSS SERVICE_START_NAME : NT Authority\NetworkService C:\TEMP>SC qc "Themes" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Themes TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : ProfSvc_Group TAG : 0 DISPLAY_NAME : Themes DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "TieringEngineService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: TieringEngineService TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\TieringEngineService.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Storage Tiers Management DEPENDENCIES : SERVICE_START_NAME : localSystem C:\TEMP>SC qc "tiledatamodelsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: tiledatamodelsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k appmodel LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Tile Data model server DEPENDENCIES : rpcss : staterepository SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "TimeBrokerSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: TimeBrokerSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Time Broker DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "TrkWks" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: TrkWks TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Distributed Link Tracking Client DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "TrustedInstaller" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: TrustedInstaller TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\servicing\TrustedInstaller.exe LOAD_ORDER_GROUP : ProfSvc_Group TAG : 0 DISPLAY_NAME : Windows Modules Installer DEPENDENCIES : SERVICE_START_NAME : localSystem C:\TEMP>SC qc "tzautoupdate" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: tzautoupdate TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Auto Time Zone Updater DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "UevAgentService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: UevAgentService TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\AgentService.exe LOAD_ORDER_GROUP : ProfSvc_Group TAG : 0 DISPLAY_NAME : User Experience Virtualization Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "UI0Detect" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: UI0Detect TYPE : 110 WIN32_OWN_PROCESS (interactive) START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\UI0Detect.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Interactive Services Detection DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "UmRdpService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: UmRdpService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Desktop Services UserMode Port Redirector DEPENDENCIES : TermService : RDPDR SERVICE_START_NAME : localSystem C:\TEMP>SC qc "UnistoreSvc_354e6" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: UnistoreSvc_354e6 TYPE : e0 USER_SHARE_PROCESS INSTANCE START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : User Data Storage_354e6 DEPENDENCIES : SERVICE_START_NAME : C:\TEMP>SC qc "upnphost" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: upnphost TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : UPnP Device Host DEPENDENCIES : SSDPSRV : HTTP SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "UserDataSvc_354e6" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: UserDataSvc_354e6 TYPE : e0 USER_SHARE_PROCESS INSTANCE START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : User Data Access_354e6 DEPENDENCIES : SERVICE_START_NAME : C:\TEMP>SC qc "UserManager" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: UserManager TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : User Manager DEPENDENCIES : RpcSs : ProfSvc SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "UsoSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: UsoSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Update Orchestrator Service for Windows Update DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "VaultSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: VaultSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\lsass.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Credential Manager DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vds" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vds TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\vds.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Virtual Disk DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vmicguestinterface" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmicguestinterface TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Hyper-V Guest Service Interface DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vmicheartbeat" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmicheartbeat TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k ICService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Hyper-V Heartbeat Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vmickvpexchange" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmickvpexchange TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Hyper-V Data Exchange Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vmicrdv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmicrdv TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k ICService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Hyper-V Remote Desktop Virtualization Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vmicshutdown" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmicshutdown TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Hyper-V Guest Shutdown Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vmictimesync" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmictimesync TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Hyper-V Time Synchronization Service DEPENDENCIES : VmGid SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "vmicvmsession" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmicvmsession TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Hyper-V PowerShell Direct Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vmicvss" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmicvss TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Hyper-V Volume Shadow Copy Requestor DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "VMTools" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: VMTools TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\VMware\VMware Tools\vmtoolsd.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : VMware Tools DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vmvss" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmvss TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\dllhost.exe /Processid:{285B064C-1AD3-46A0-919B-0D4FDB090059} LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : VMware Snapshot Provider DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "VMware Physical Disk Helper Service" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: VMware Physical Disk Helper Service TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : "C:\Program Files\VMware\VMware Tools\vmacthlp.exe" LOAD_ORDER_GROUP : Base TAG : 0 DISPLAY_NAME : VMware Physical Disk Helper Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "VSS" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: VSS TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\vssvc.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Volume Shadow Copy DEPENDENCIES : RPCSS SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "VSStandardCollectorService140" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: VSStandardCollectorService140 TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : "C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Visual Studio Standard Collector Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "W32Time" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: W32Time TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Time DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "WalletService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WalletService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k appmodel LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : WalletService DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "wbengine" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wbengine TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\WINDOWS\system32\wbengine.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Block Level Backup Engine Service DEPENDENCIES : SERVICE_START_NAME : localSystem C:\TEMP>SC qc "WbioSrvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WbioSrvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k WbioSvcGroup LOAD_ORDER_GROUP : SmartCardGroup TAG : 0 DISPLAY_NAME : Windows Biometric Service DEPENDENCIES : RpcSs : WUDFSvc SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Wcmsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Wcmsvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : Windows Connection Manager DEPENDENCIES : RpcSs SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "wcncsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wcncsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Connect Now - Config Registrar DEPENDENCIES : rpcss SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "WdiServiceHost" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WdiServiceHost TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Diagnostic Service Host DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "WdiSystemHost" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WdiSystemHost TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Diagnostic System Host DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "WdNisSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WdNisSvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\Windows Defender\NisSrv.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Defender Network Inspection Service DEPENDENCIES : WdNisDrv SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "WebClient" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WebClient TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : NetworkProvider TAG : 0 DISPLAY_NAME : WebClient DEPENDENCIES : MRxDAV SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "Wecsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Wecsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Event Collector DEPENDENCIES : HTTP : Eventlog SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "WEPHOSTSVC" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WEPHOSTSVC TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k WepHostSvcGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Encryption Provider Host Service DEPENDENCIES : rpcss SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "wercplsupport" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wercplsupport TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Problem Reports and Solutions Control Panel Support DEPENDENCIES : SERVICE_START_NAME : localSystem C:\TEMP>SC qc "WerSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WerSvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k WerSvcGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Error Reporting Service DEPENDENCIES : SERVICE_START_NAME : localSystem C:\TEMP>SC qc "WiaRpc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WiaRpc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Still Image Acquisition Events DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "WinDefend" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WinDefend TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\Windows Defender\MsMpEng.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Defender Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Windows10FirewallService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Windows10FirewallService TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\Windows10FirewallControl\Windows10FirewallService.exe" LOAD_ORDER_GROUP : NetworkProvider TAG : 0 DISPLAY_NAME : Windows10FirewallService DEPENDENCIES : BFE SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "WinHttpAutoProxySvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WinHttpAutoProxySvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : WinHTTP Web Proxy Auto-Discovery Service DEPENDENCIES : Dhcp SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "Winmgmt" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Winmgmt TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Management Instrumentation DEPENDENCIES : RPCSS SERVICE_START_NAME : localSystem C:\TEMP>SC qc "WinRM" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WinRM TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Remote Management (WS-Management) DEPENDENCIES : RPCSS : HTTP SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "wisvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wisvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Insider Service DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "WlanSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WlanSvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : WLAN AutoConfig DEPENDENCIES : nativewifip : RpcSs : Ndisuio : wcmsvc SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "wlidsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wlidsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Microsoft Account Sign-in Assistant DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "wmiApSrv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wmiApSrv TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\wbem\WmiApSrv.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : WMI Performance Adapter DEPENDENCIES : SERVICE_START_NAME : localSystem C:\TEMP>SC qc "WMPNetworkSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WMPNetworkSvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\Windows Media Player\wmpnetwk.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Media Player Network Sharing Service DEPENDENCIES : http : WSearch SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "workfolderssvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: workfolderssvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalService LOAD_ORDER_GROUP : LocalService TAG : 0 DISPLAY_NAME : Work Folders DEPENDENCIES : RpcSs : wsearch SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "WPDBusEnum" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WPDBusEnum TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Portable Device Enumerator Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "WpnService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WpnService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Push Notifications System Service DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "WpnUserService_354e6" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WpnUserService_354e6 TYPE : e0 USER_SHARE_PROCESS INSTANCE START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Push Notifications User Service_354e6 DEPENDENCIES : SERVICE_START_NAME : C:\TEMP>SC qc "wscsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wscsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START (DELAYED) ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Security Center DEPENDENCIES : RpcSs : WinMgmt SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "WSearch" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WSearch TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\SearchIndexer.exe /Embedding LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Search DEPENDENCIES : RPCSS SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "wuauserv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wuauserv TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Update DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "wudfsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wudfsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : PlugPlay TAG : 0 DISPLAY_NAME : Windows Driver Foundation - User-mode Driver Framework DEPENDENCIES : WudfPf SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "WwanSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WwanSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : WWAN AutoConfig DEPENDENCIES : RpcSs : NdisUio SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "XblAuthManager" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: XblAuthManager TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Xbox Live Auth Manager DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "XblGameSave" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: XblGameSave TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Xbox Live Game Save DEPENDENCIES : UserManager : XblAuthManager SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "XboxNetApiSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: XboxNetApiSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Xbox Live Networking Service DEPENDENCIES : BFE : mpssvc : IKEEXT : KeyIso SERVICE_START_NAME : LocalSystem ------------------------------------------------------------------------------------------- WMIC qfe list (list of all installed updates): Caption CSName Description FixComments HotFixID InstallDate InstalledBy InstalledOn Name ServicePackInEffect Status http://support.microsoft.com/?kbid=3176936 W10VM Update KB3176936 NT AUTHORITY\SYSTEM 8/24/2016 http://support.microsoft.com/?kbid=3199986 W10VM Update KB3199986 NT AUTHORITY\SYSTEM 11/6/2016 http://support.microsoft.com/?kbid=3202790 W10VM Security Update KB3202790 NT AUTHORITY\SYSTEM 11/8/2016 http://support.microsoft.com/?kbid=3209498 W10VM Security Update KB3209498 NT AUTHORITY\SYSTEM 12/13/2016 http://support.microsoft.com/?kbid=3206632 W10VM Security Update KB3206632 NT AUTHORITY\SYSTEM 12/13/2016 ------------------------------------------------------------------------------------------- -Noel Edited December 15, 2016 by NoelC 1
Jody Thornton Posted December 16, 2016 Posted December 16, 2016 On 12/14/2016 at 1:14 PM, NoelC said: You never, EVER, have to worry about what's OT in any of my threads. I think "on topic" is an invalid concept and many things can be learned from a freely ranging conversation. I enjoyed your image. It reminded me a bit of a particular Greek donkey that wasn't quite so apt to work without complaint. Or at least without music. -Noel I wish you were around when I wanted to discuss XP security two years (even if it was to an ad nauseum soap operatic degree). Holy crap was I tarred and feathered for that, and I even ditched the forum for awhile. I like how you think NoelC. Of course, I don't REALLY care about XP anymore, but if Dibya wants to shout to the hills about it, he should be able to. And yes that whole "stay on topic" people. Every forum mod does that. But conversation is an organic, fluid thing. Many folks drift off topic in real life, sp go ahead and do it here. 1
NoelC Posted December 16, 2016 Author Posted December 16, 2016 Take the 10 out of the thread subject and this thread is all quite on topic. I find it fascinating what people have been able to do with component mix and match using debugging tools et. al. I'm reminded of a good DJ remixing good music to make even better music. Makes me want to go and play some chill remixes. I wonder what Windows could become if Microsoft would just open the source code up to the world. -Noel 2
Jody Thornton Posted December 16, 2016 Posted December 16, 2016 I was hopeful for React OS, but I think that's a dead project now.
dencorso Posted December 16, 2016 Posted December 16, 2016 While I don't think its developers think of ReactOS as a dead project, and while I, too, have always hoped it might blosom into a viable successor for XP, I fear I have no choice but to agree the ReactOS project is deeply comatose and seems to have no prospects of awakening in the near future, so that, even if it does come to eventually, it'll be far too late to make any difference anymore. And while I'm not exacly a fan of unix, I do think the best candidate to become a viable alternative to Windows is TrueOS, a very mature distro of FreeBSD. ... the rest ...is ...silence. 1
Jody Thornton Posted December 16, 2016 Posted December 16, 2016 TrueOS? Hmmm the first I'm hearing of it. I shall check it out. Thanks Dencorso!
vinifera Posted December 19, 2016 Posted December 19, 2016 i'd call reactos more like obsolete project than dead if it was stable during vista days or even win7 days, that would be still ok but now ... its not worth it other than for "geeks" to i guess learn how OS works on code level ?
Jody Thornton Posted December 19, 2016 Posted December 19, 2016 See I thought the ReactOS team were going after a lighter windows-like build, so without the bloat. So ala Windows 2000, but compatible with today's applications.
Dibya Posted December 22, 2016 Posted December 22, 2016 (edited) On 12/19/2016 at 7:00 PM, JodyT said: See I thought the ReactOS team were going after a lighter windows-like build, so without the bloat. So ala Windows 2000, but compatible with today's applications. On 12/15/2016 at 7:09 PM, dencorso said: While I don't think its developers think of ReactOS as a dead project, and while I, too, have always hoped it might blosom into a viable successor for XP, I fear I have no choice but to agree the ReactOS project is deeply comatose and seems to have no prospects of awakening in the near future, so that, even if it does come to eventually, it'll be far too late to make any difference anymore. And while I'm not exacly a fan of unix, I do think the best candidate to become a viable alternative to Windows is TrueOS, a very mature distro of FreeBSD. ... the rest ...is ...silence. I wish to try True OS. ReactOs cannot run many things. This Christmas vacation i am going to run some pass mark bench on both xp /7/8.1/10 on my ivybridge pc or skylake gaming build. Anyway let see which os wins. Merry Christmas and Happy New year Edited December 22, 2016 by Dibya 2
Recommended Posts
Please sign in to comment
You will be able to leave a comment after signing in
Sign In Now