Display Name,Name,State,Startup Type,Service Type,Controls Accepted,Executable,Description,Log On As,Group,Error Control,Exit Code "ActiveX Installer (AxInstSV)","AxInstSV","Stopped","Manual","Share Process","","C:\Windows\system32\svchost.exe -k AxInstSVGroup","Provides User Account Control validation for the installation of ActiveX controls from the Internet and enables management of ActiveX control installation based on Group Policy settings. This service is started on demand and if disabled the installation of ActiveX controls will behave according to default browser settings.","LocalSystem","","Normal","No attempts to start the service have been made since the last boot (1077)" "Adaptive Brightness","SensrSvc","Stopped","Manual","Share Process","","C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation","Monitors ambient light sensors to detect changes in ambient light and adjust the display brightness. If this service is stopped or disabled, the display brightness will not adapt to lighting conditions.","NT AUTHORITY\LocalService","","Normal","No attempts to start the service have been made since the last boot (1077)" "Adobe Acrobat Update Service","AdobeARMservice","Running","Automatic","Own Process","Stop",""C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"","Adobe Acrobat Updater keeps your Adobe software up to date.","LocalSystem","","Ignore","The operation completed successfully (0)" "Adobe Flash Player Update Service","AdobeFlashPlayerUpdateSvc","Stopped","Manual","Own Process","","C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe","This service keeps your Adobe Flash Player installation up to date with the latest enhancements and security fixes.","LocalSystem","","Normal","No attempts to start the service have been made since the last boot (1077)" "AMD External Events Utility","AMD External Events Utility","Running","Automatic","Own Process","Stop, Shutdown, Session Change","C:\Windows\system32\atiesrxx.exe","","LocalSystem","Event Log","Normal","The operation completed successfully (0)" "AMD FUEL Service","AMD FUEL Service","Running","Automatic","Own Process","Stop, Shutdown, Power Event","C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe /launchService","Provides FUEL Functionality","LocalSystem","","Normal","The operation completed successfully (0)" "Application Experience","AeLookupSvc","Running","Manual","Share Process","Stop","C:\Windows\system32\svchost.exe -k netsvcs","Processes application compatibility cache requests for applications as they are launched","localSystem","","Normal","The operation completed successfully (0)" "Application Identity","AppIDSvc","Stopped","Manual","Share Process","","C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation","Determines and verifies the identity of an application. Disabling this service will prevent AppLocker from being enforced.","NT Authority\LocalService","ProfSvc_Group","Normal","No attempts to start the service have been made since the last boot (1077)" "Application Information","Appinfo","Running","Manual","Share Process","Stop, Session Change","C:\Windows\system32\svchost.exe -k netsvcs","Facilitates the running of interactive applications with additional administrative privileges. If this service is stopped, users will be unable to launch applications with the additional administrative privileges they may require to perform desired user tasks.","LocalSystem","","Normal","The operation completed successfully (0)" "Application Layer Gateway Service","ALG","Running","Manual","Own Process","Stop","C:\Windows\System32\alg.exe","Provides support for 3rd party protocol plug-ins for Internet Connection Sharing","NT AUTHORITY\LocalService","","Normal","The operation completed successfully (0)" "AtherosSvc","AtherosSvc","Running","Automatic","Own Process","Stop, Power Event","C:\Program Files (x86)\Bluetooth Suite\adminservice.exe","Atheros BT Stack Service Agent","LocalSystem","","Ignore","The operation completed successfully (0)" "Audio Service","STacSV","Running","Automatic","Own Process","Stop, Pause/Continue, Shutdown, Hardware Profile Change, Power Event","C:\Program Files\IDT\WDM\STacSV64.exe","Manages audio jack configurations.","LocalSystem","AudioGroup","Normal","The operation completed successfully (0)" "Background Intelligent Transfer Service","BITS","Running","Automatic","Share Process","Stop, Session Change","C:\Windows\System32\svchost.exe -k netsvcs","Transfers files in the background using idle network bandwidth. If the service is disabled, then any applications that depend on BITS, such as Windows Update or MSN Explorer, will be unable to automatically download programs and other information.","LocalSystem","","Normal","The operation completed successfully (0)" "Base Filtering Engine","BFE","Running","Automatic","Share Process","Stop, Power Event","C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork","The Base Filtering Engine (BFE) is a service that manages firewall and Internet Protocol security (IPsec) policies and implements user mode filtering. Stopping or disabling the BFE service will significantly reduce the security of the system. It will also result in unpredictable behavior in IPsec management and firewall applications.","NT AUTHORITY\LocalService","NetworkProvider","Normal","The operation completed successfully (0)" "BBUpdate","BBUpdate","Running","Automatic","Own Process","Stop",""C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE"","Enables the detection, download and installation of up-to-date configuration files for Bing Bar. Also provides server communication for the customer experience improvement program. Stopping or disabling this service may prevent you from getting the latest updates for Bing Bar, which may expose your computer to security vulnerabilities or functional flaws in the Bing Bar.","LocalSystem","","Normal","The operation completed successfully (0)" "Bing Bar Update Service","BBSvc","Stopped","Manual","Own Process","",""C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE"","Keeps Bing Bar up-to-date. Disabling this service might prevent updates and expose your computer to security vulnerabilities or functional flaws in Bing Bar.","LocalSystem","","Normal","No attempts to start the service have been made since the last boot (1077)" "BitLocker Drive Encryption Service","BDESVC","Stopped","Manual","Share Process","","C:\Windows\System32\svchost.exe -k netsvcs","BDESVC hosts the BitLocker Drive Encryption service. BitLocker Drive Encryption provides secure startup for the operating system, as well as full volume encryption for OS, fixed or removable volumes. This service allows BitLocker to prompt users for various actions related to their volumes when mounted, and unlocks volumes automatically without user interaction. Additionally, it stores recovery information to Active Directory, if available, and, if necessary, ensures the most recent recovery certificates are used. Stopping or disabling the service would prevent users from leveraging this functionality.","localSystem","","Normal","No attempts to start the service have been made since the last boot (1077)" "Block Level Backup Engine Service","wbengine","Stopped","Manual","Own Process","",""C:\Windows\system32\wbengine.exe"","The WBENGINE service is used by Windows Backup to perform backup and recovery operations. If this service is stopped by a user, it may cause the currently running backup or recovery operation to fail. Disabling this service may disable backup and recovery operations using Windows Backup on this computer.","localSystem","","Normal","No attempts to start the service have been made since the last boot (1077)" "Bluetooth Support Service","bthserv","Running","Manual","Share Process","Stop, Shutdown","C:\Windows\system32\svchost.exe -k bthsvcs","The Bluetooth service supports discovery and association of remote Bluetooth devices. Stopping or disabling this service may cause already installed Bluetooth devices to fail to operate properly and prevent new devices from being discovered or associated.","NT AUTHORITY\LocalService","","Normal","The operation completed successfully (0)" "Certificate Propagation","CertPropSvc","Stopped","Manual","Share Process","","C:\Windows\system32\svchost.exe -k netsvcs","Copies user certificates and root certificates from smart cards into the current user's certificate store, detects when a smart card is inserted into a smart card reader, and, if needed, installs the smart card Plug and Play minidriver.","LocalSystem","","Normal","No attempts to start the service have been made since the last boot (1077)" "CNG Key Isolation","KeyIso","Running","Manual","Share Process","Stop","C:\Windows\system32\lsass.exe","The CNG key isolation service is hosted in the LSA process. The service provides key process isolation to private keys and associated cryptographic operations as required by the Common Criteria. The service stores and uses long-lived keys in a secure process complying with Common Criteria requirements.","LocalSystem","","Normal","The operation completed successfully (0)" "COM+ Event System","EventSystem","Running","Automatic","Share Process","Stop","C:\Windows\system32\svchost.exe -k LocalService","Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start.","NT AUTHORITY\LocalService","","Normal","The operation completed successfully (0)" "COM+ System Application","COMSysApp","Stopped","Manual","Own Process","","C:\Windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}","Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.","LocalSystem","","Normal","No attempts to start the service have been made since the last boot (1077)" "Computer Browser","Browser","Running","Manual","Share Process","Stop","C:\Windows\System32\svchost.exe -k netsvcs","Maintains an updated list of computers on the network and supplies this list to computers designated as browsers. If this service is stopped, this list will not be updated or maintained. If this service is disabled, any services that explicitly depend on it will fail to start.","LocalSystem","NetworkProvider","Normal","The operation completed successfully (0)" "Credential Manager","VaultSvc","Stopped","Manual","Share Process","","C:\Windows\system32\lsass.exe","Provides secure storage and retrieval of credentials to users, applications and security service packages.","LocalSystem","","Normal","No attempts to start the service have been made since the last boot (1077)" "Cryptographic Services","CryptSvc","Running","Automatic","Share Process","Stop, Shutdown, Session Change","C:\Windows\system32\svchost.exe -k NetworkService","Provides four management services: Catalog Database Service, which confirms the signatures of Windows files and allows new programs to be installed; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; Automatic Root Certificate Update Service, which retrieves root certificates from Windows Update and enable scenarios such as SSL; and Key Service, which helps enroll this computer for certificates. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.","NT Authority\NetworkService","","Normal","The operation completed successfully (0)" "DCOM Server Process Launcher","DcomLaunch","Running","Automatic","Share Process","","C:\Windows\system32\svchost.exe -k DcomLaunch","The DCOMLAUNCH service launches COM and DCOM servers in response to object activation requests. If this service is stopped or disabled, programs using COM or DCOM will not function properly. It is strongly recommended that you have the DCOMLAUNCH service running.","LocalSystem","COM Infrastructure","Normal","The operation completed successfully (0)" "Desktop Window Manager Session Manager","UxSms","Running","Automatic","Share Process","Stop, Shutdown, Session Change","C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted","Provides Desktop Window Manager startup and maintenance services","localSystem","UIGroup","Normal","The operation completed successfully (0)" "DHCP Client","Dhcp","Running","Automatic","Share Process","Stop, Shutdown","C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted","Registers and updates IP addresses and DNS records for this computer. If this service is stopped, this computer will not receive dynamic IP addresses and DNS updates. If this service is disabled, any services that explicitly depend on it will fail to start.","NT Authority\LocalService","TDI","Normal","The operation completed successfully (0)" "Diagnostic Policy Service","DPS","Running","Automatic","Share Process","Stop, Shutdown","C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork","The Diagnostic Policy Service enables problem detection, troubleshooting and resolution for Windows components. If this service is stopped, diagnostics will no longer function.","NT AUTHORITY\LocalService","","Normal","The operation completed successfully (0)" "Diagnostic Service Host","WdiServiceHost","Running","Manual","Share Process","Stop, Shutdown","C:\Windows\System32\svchost.exe -k LocalService","The Diagnostic Service Host is used by the Diagnostic Policy Service to host diagnostics that need to run in a Local Service context. If this service is stopped, any diagnostics that depend on it will no longer function.","NT AUTHORITY\LocalService","","Normal","The operation completed successfully (0)" "Diagnostic System Host","WdiSystemHost","Running","Manual","Share Process","Stop, Shutdown","C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted","The Diagnostic System Host is used by the Diagnostic Policy Service to host diagnostics that need to run in a Local System context. If this service is stopped, any diagnostics that depend on it will no longer function.","LocalSystem","","Normal","The operation completed successfully (0)" "Disk Defragmenter","defragsvc","Stopped","Manual","Own Process","","C:\Windows\system32\svchost.exe -k defragsvc","Provides Disk Defragmentation Capabilities.","localSystem","","Normal","No attempts to start the service have been made since the last boot (1077)" "Distributed Link Tracking Client","TrkWks","Running","Automatic","Share Process","Stop, Shutdown","C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted","Maintains links between NTFS files within a computer or across computers in a network.","LocalSystem","","Normal","The operation completed successfully (0)" "Distributed Transaction Coordinator","MSDTC","Stopped","Manual","Own Process","","C:\Windows\System32\msdtc.exe","Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will fail. If this service is disabled, any services that explicitly depend on it will fail to start.","NT AUTHORITY\NetworkService","","Normal","No attempts to start the service have been made since the last boot (1077)" "DNS Client","Dnscache","Running","Automatic","Share Process","Stop, Param Change, Net Bind Change, Power Event","C:\Windows\system32\svchost.exe -k NetworkService","The DNS Client service (dnscache) caches Domain Name System (DNS) names and registers the full computer name for this computer. If the service is stopped, DNS names will continue to be resolved. However, the results of DNS name queries will not be cached and the computer's name will not be registered. If the service is disabled, any services that explicitly depend on it will fail to start.","NT AUTHORITY\NetworkService","TDI","Normal","The operation completed successfully (0)" "Encrypting File System (EFS)","EFS","Stopped","Manual","Share Process","","C:\Windows\System32\lsass.exe","Provides the core file encryption technology used to store encrypted files on NTFS file system volumes. If this service is stopped or disabled, applications will be unable to access encrypted files.","LocalSystem","","Normal","No attempts to start the service have been made since the last boot (1077)" "Extensible Authentication Protocol","EapHost","Running","Manual","Share Process","Stop, Shutdown, Session Change","C:\Windows\System32\svchost.exe -k netsvcs","The Extensible Authentication Protocol (EAP) service provides network authentication in such scenarios as 802.1x wired and wireless, VPN, and Network Access Protection (NAP). EAP also provides application programming interfaces (APIs) that are used by network access clients, including wireless and VPN clients, during the authentication process. If you disable this service, this computer is prevented from accessing networks that require EAP authentication.","localSystem","","Normal","The operation completed successfully (0)" "Fax","Fax","Stopped","Manual","Own Process","","C:\Windows\system32\fxssvc.exe","Enables you to send and receive faxes, utilizing fax resources available on this computer or on the network.","NT AUTHORITY\NetworkService","","Normal","No attempts to start the service have been made since the last boot (1077)" "Function Discovery Provider Host","fdPHost","Running","Manual","Share Process","Stop, Session Change","C:\Windows\system32\svchost.exe -k LocalService","The FDPHOST service hosts the Function Discovery (FD) network discovery providers. These FD providers supply network discovery services for the Simple Services Discovery Protocol (SSDP) and Web Services – Discovery (WS-D) protocol. Stopping or disabling the FDPHOST service will disable network discovery for these protocols when using FD. When this service is unavailable, network services using FD and relying on these discovery protocols will be unable to find network devices or resources.","NT AUTHORITY\LocalService","","Normal","The operation completed successfully (0)" "Function Discovery Resource Publication","FDResPub","Running","Automatic","Share Process","Stop, Shutdown, Power Event","C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation","Publishes this computer and resources attached to this computer so they can be discovered over the network. If this service is stopped, network resources will no longer be published and they will not be discovered by other computers on the network.","NT AUTHORITY\LocalService","","Normal","The operation completed successfully (0)" "GamesAppService","GamesAppService","Stopped","Manual","Own Process","",""C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe"","WT Games App Services","LocalSystem","","Normal","No attempts to start the service have been made since the last boot (1077)" "Group Policy Client","gpsvc","Running","Automatic","Share Process","Stop","C:\Windows\system32\svchost.exe -k netsvcs","The service is responsible for applying settings configured by administrators for the computer and users through the Group Policy component. If the service is stopped or disabled, the settings will not be applied and applications and components will not be manageable through Group Policy. Any components or applications that depend on the Group Policy component might not be functional if the service is stopped or disabled.","LocalSystem","ProfSvc_Group","Normal","The operation completed successfully (0)" "Health Key and Certificate Management","hkmsvc","Stopped","Manual","Share Process","","C:\Windows\System32\svchost.exe -k netsvcs","Provides X.509 certificate and key management services for the Network Access Protection Agent (NAPAgent). Enforcement technologies that use X.509 certificates may not function properly without this service","localSystem","","Normal","No attempts to start the service have been made since the last boot (1077)" "HomeGroup Listener","HomeGroupListener","Running","Manual","Share Process","Stop, Session Change","C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted","Makes local computer changes associated with configuration and maintenance of the homegroup-joined computer. If this service is stopped or disabled, your computer will not work properly in a homegroup and your homegroup might not work properly. It is recommended that you keep this service running.","LocalSystem","","Normal","The operation completed successfully (0)" "HomeGroup Provider","HomeGroupProvider","Running","Manual","Share Process","Stop","C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted","Performs networking tasks associated with configuration and maintenance of homegroups. If this service is stopped or disabled, your computer will be unable to detect other homegroups and your homegroup might not work properly. It is recommended that you keep this service running.","NT AUTHORITY\LocalService","","Normal","The operation completed successfully (0)" "HP Auto","HPAuto","Running","Automatic","Own Process","Stop, Pause/Continue, Shutdown, Param Change, Session Change",""C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe"","HP Usage Improvement Tracking","LocalSystem","","Normal","The operation completed successfully (0)" "HP Client Services","HPClientSvc","Running","Automatic","Own Process","Stop, Shutdown, Session Change",""C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe"","","LocalSystem","","Ignore","The operation completed successfully (0)" "HP CUE DeviceDiscovery Service","hpqddsvc","Running","Automatic","Share Process","Stop, Pause/Continue, Shutdown","C:\Windows\system32\svchost.exe -k hpdevmgmt","This service detects and monitors CUE devices on the system.","LocalSystem","","Normal","The operation completed successfully (0)" "HP Network Devices Support","HPSLPSVC","Running","Automatic","Share Process","Stop, Shutdown, Power Event, Session Change","C:\Windows\system32\svchost.exe -k HPService","Discovers and monitors the state and the configuration of the HP devices attached to your network. If the service is stopped, and your network devices change IP addresses, they might become unavailable","LocalSystem","","Normal","The operation completed successfully (0)" "HP Service","hpsrv","Running","Automatic","Own Process","Stop, Shutdown, Power Event, Session Change","C:\Windows\system32\Hpservice.exe","","LocalSystem","UIGroup","Normal","The operation completed successfully (0)" "HP Software Framework Service","hpqwmiex","Running","Manual","Own Process","Stop, Pause/Continue, Shutdown, Power Event",""C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe"","","LocalSystem","","Normal","The operation completed successfully (0)" "HP Support Assistant Service","HP Support Assistant Service","Running","Automatic","Own Process","Stop, Shutdown, Power Event",""C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"","HP Support Assistant Service","LocalSystem","","Normal","The operation completed successfully (0)" "hpqcxs08","hpqcxs08","Running","Manual","Share Process","Stop","C:\Windows\system32\svchost.exe -k hpdevmgmt","","LocalSystem","","Normal","The operation completed successfully (0)" "HPWMISVC","HPWMISVC","Running","Automatic","Own Process (Interactive)","Stop, Power Event, Session Change","C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe","","LocalSystem","","Normal","The operation completed successfully (0)" "Human Interface Device Access","hidserv","Running","Manual","Share Process","Stop, Shutdown, Session Change","C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted","Enables generic input access to Human Interface Devices (HID), which activates and maintains the use of predefined hot buttons on keyboards, remote controls, and other multimedia devices. If this service is stopped, hot buttons controlled by this service will no longer function. If this service is disabled, any services that explicitly depend on it will fail to start.","LocalSystem","","Normal","The operation completed successfully (0)" "IKE and AuthIP IPsec Keying Modules","IKEEXT","Running","Automatic","Share Process","Stop, Shutdown, Power Event","C:\Windows\system32\svchost.exe -k netsvcs","The IKEEXT service hosts the Internet Key Exchange (IKE) and Authenticated Internet Protocol (AuthIP) keying modules. These keying modules are used for authentication and key exchange in Internet Protocol security (IPsec). Stopping or disabling the IKEEXT service will disable IKE and AuthIP key exchange with peer computers. IPsec is typically configured to use IKE or AuthIP; therefore, stopping or disabling the IKEEXT service might result in an IPsec failure and might compromise the security of the system. It is strongly recommended that you have the IKEEXT service running.","LocalSystem","","Normal","The operation completed successfully (0)" "Interactive Services Detection","UI0Detect","Stopped","Manual","Own Process (Interactive)","","C:\Windows\system32\UI0Detect.exe","Enables user notification of user input for interactive services, which enables access to dialogs created by interactive services when they appear. If this service is stopped, notifications of new interactive service dialogs will no longer function and there might not be access to interactive service dialogs. If this service is disabled, both notifications of and access to new interactive service dialogs will no longer function.","LocalSystem","","Normal","No attempts to start the service have been made since the last boot (1077)" "Internet Connection Sharing (ICS)","SharedAccess","Running","Automatic","Share Process","Stop","C:\Windows\System32\svchost.exe -k netsvcs","Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network.","LocalSystem","","Normal","The operation completed successfully (0)" "IP Helper","iphlpsvc","Running","Automatic","Share Process","Stop, Param Change, Power Event","C:\Windows\System32\svchost.exe -k NetSvcs","Provides tunnel connectivity using IPv6 transition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS. If this service is stopped, the computer will not have the enhanced connectivity benefits that these technologies offer.","LocalSystem","","Normal","The operation completed successfully (0)" "IPsec Policy Agent","PolicyAgent","Running","Manual","Share Process","Stop, Shutdown","C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted","Internet Protocol security (IPsec) supports network-level peer authentication, data origin authentication, data integrity, data confidentiality (encryption), and replay protection. This service enforces IPsec policies created through the IP Security Policies snap-in or the command-line tool "netsh ipsec". If you stop this service, you may experience network connectivity issues if your policy requires that connections use IPsec. Also,remote management of Windows Firewall is not available when this service is stopped.","NT Authority\NetworkService","","Normal","The operation completed successfully (0)" "KtmRm for Distributed Transaction Coordinator","KtmRm","Stopped","Manual","Share Process","","C:\Windows\System32\svchost.exe -k NetworkServiceAndNoImpersonation","Coordinates transactions between the Distributed Transaction Coordinator (MSDTC) and the Kernel Transaction Manager (KTM). If it is not needed, it is recommended that this service remain stopped. If it is needed, both MSDTC and KTM will start this service automatically. If this service is disabled, any MSDTC transaction interacting with a Kernel Resource Manager will fail and any services that explicitly depend on it will fail to start.","NT AUTHORITY\NetworkService","","Normal","No attempts to start the service have been made since the last boot (1077)" "Link-Layer Topology Discovery Mapper","lltdsvc","Stopped","Manual","Share Process","","C:\Windows\System32\svchost.exe -k LocalService","Creates a Network Map, consisting of PC and device topology (connectivity) information, and metadata describing each PC and device. If this service is disabled, the Network Map will not function properly.","NT AUTHORITY\LocalService","","Normal","No attempts to start the service have been made since the last boot (1077)" "Media Center Extender Service","Mcx2Svc","Stopped","Disabled","Share Process","","C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation","Allows Media Center Extenders to locate and connect to the computer.","NT Authority\LocalService","","Normal","No attempts to start the service have been made since the last boot (1077)" "Microsoft .NET Framework NGEN v2.0.50727_X64","clr_optimization_v2.0.50727_64","Stopped","Disabled","Own Process","","C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe","Microsoft .NET Framework NGEN","LocalSystem","","Ignore","No attempts to start the service have been made since the last boot (1077)" "Microsoft .NET Framework NGEN v2.0.50727_X86","clr_optimization_v2.0.50727_32","Stopped","Disabled","Own Process","","C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe","Microsoft .NET Framework NGEN","LocalSystem","","Ignore","No attempts to start the service have been made since the last boot (1077)" "Microsoft .NET Framework NGEN v4.0.30319_X64","clr_optimization_v4.0.30319_64","Stopped","Automatic","Own Process","","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe","Microsoft .NET Framework NGEN","LocalSystem","","Ignore","The operation completed successfully (0)" "Microsoft .NET Framework NGEN v4.0.30319_X86","clr_optimization_v4.0.30319_32","Stopped","Automatic","Own Process","","C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe","Microsoft .NET Framework NGEN","LocalSystem","","Ignore","The operation completed successfully (0)" "Microsoft iSCSI Initiator Service","MSiSCSI","Stopped","Manual","Share Process","","C:\Windows\system32\svchost.exe -k netsvcs","Manages Internet SCSI (iSCSI) sessions from this computer to remote iSCSI target devices. If this service is stopped, this computer will not be able to login or access iSCSI targets. If this service is disabled, any services that explicitly depend on it will fail to start.","LocalSystem","iSCSI","Normal","No attempts to start the service have been made since the last boot (1077)" "Microsoft Software Shadow Copy Provider","swprv","Stopped","Manual","Own Process","","C:\Windows\System32\svchost.exe -k swprv","Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabled, any services that explicitly depend on it will fail to start.","LocalSystem","","Normal","No attempts to start the service have been made since the last boot (1077)" "Mozilla Maintenance Service","MozillaMaintenance","Stopped","Manual","Own Process","",""C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe"","The Mozilla Maintenance Service ensures that you have the latest and most secure version of Mozilla Firefox on your computer. Keeping Firefox up to date is very important for your online security, and Mozilla strongly recommends that you keep this service enabled.","LocalSystem","","Normal","No attempts to start the service have been made since the last boot (1077)" "Multimedia Class Scheduler","MMCSS","Running","Automatic","Share Process","Stop, Session Change","C:\Windows\system32\svchost.exe -k netsvcs","Enables relative prioritization of work based on system-wide task priorities. This is intended mainly for multimedia applications. If this service is stopped, individual tasks resort to their default priority.","LocalSystem","","Normal","The operation completed successfully (0)" "Nero Update","NAUpdate","Running","Automatic","Own Process","Stop",""C:\Program Files (x86)\Nero\Update\NASvc.exe"","Provides access to Nero application updates and manages Nero applications.","LocalSystem","","Ignore","The operation completed successfully (0)" "Net Driver HPZ12","Net Driver HPZ12","Running","Automatic","Own Process","Stop, Shutdown","C:\Windows\System32\svchost.exe -k HPZ12","","NT AUTHORITY\LocalService","","Normal","The operation completed successfully (0)" "Net.Tcp Port Sharing Service","NetTcpPortSharing","Stopped","Disabled","Share Process","",""C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe"","Provides ability to share TCP ports over the net.tcp protocol.","NT AUTHORITY\LocalService","","Normal","No attempts to start the service have been made since the last boot (1077)" "Netlogon","Netlogon","Stopped","Manual","Share Process","","C:\Windows\system32\lsass.exe","Maintains a secure channel between this computer and the domain controller for authenticating users and services. If this service is stopped, the computer may not authenticate users and services and the domain controller cannot register DNS records. If this service is disabled, any services that explicitly depend on it will fail to start.","LocalSystem","MS_WindowsRemoteValidation","Normal","No attempts to start the service have been made since the last boot (1077)" "Network Access Protection Agent","napagent","Stopped","Manual","Share Process","","C:\Windows\System32\svchost.exe -k NetworkService","The Network Access Protection (NAP) agent service collects and manages health information for client computers on a network. Information collected by NAP agent is used to make sure that the client computer has the required software and settings. If a client computer is not compliant with health policy, it can be provided with restricted network access until its configuration is updated. Depending on the configuration of health policy, client computers might be automatically updated so that users quickly regain full network access without having to manually update their computer.","NT AUTHORITY\NetworkService","","Normal","No attempts to start the service have been made since the last boot (1077)" "Network Connections","Netman","Running","Manual","Share Process","Stop, Session Change","C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted","Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections.","LocalSystem","","Normal","The operation completed successfully (0)" "Network List Service","netprofm","Running","Manual","Share Process","Stop, Session Change","C:\Windows\System32\svchost.exe -k LocalService","Identifies the networks to which the computer has connected, collects and stores properties for these networks, and notifies applications when these properties change.","NT AUTHORITY\LocalService","","Normal","The operation completed successfully (0)" "Network Location Awareness","NlaSvc","Running","Automatic","Share Process","Stop, Session Change","C:\Windows\System32\svchost.exe -k NetworkService","Collects and stores configuration information for the network and notifies programs when this information is modified. If this service is stopped, configuration information might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.","NT AUTHORITY\NetworkService","","Normal","The operation completed successfully (0)" "Network Store Interface Service","nsi","Running","Automatic","Share Process","Stop","C:\Windows\system32\svchost.exe -k LocalService","This service delivers network notifications (e.g. interface addition/deleting etc) to user mode clients. Stopping this service will cause loss of network connectivity. If this service is disabled, any other services that explicitly depend on this service will fail to start.","NT Authority\LocalService","","Normal","The operation completed successfully (0)" "Norton Internet Security","NIS","Running","Automatic","Own Process","Shutdown, Power Event, Session Change",""C:\Program Files (x86)\Norton Internet Security\Engine\20.1.1.2\ccSvcHst.exe" /s "NIS" /m "C:\Program Files (x86)\Norton Internet Security\Engine\20.1.1.2\diMaster.dll" /prefetch:1","Norton Internet Security","LocalSystem","","Normal","The operation completed successfully (0)" "Office Source Engine","ose","Stopped","Manual","Own Process","",""C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE"","Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports.","LocalSystem","","Normal","No attempts to start the service have been made since the last boot (1077)" "Parental Controls","WPCSvc","Stopped","Manual","Share Process","","C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted","This service is a stub for Windows Parental Control functionality that existed in Vista. It is provided for backward compatibility only.","NT Authority\LocalService","","Normal","No attempts to start the service have been made since the last boot (1077)" "Peer Name Resolution Protocol","PNRPsvc","Running","Manual","Share Process","Stop, Shutdown","C:\Windows\System32\svchost.exe -k LocalServicePeerNet","Enables serverless peer name resolution over the Internet using the Peer Name Resolution Protocol (PNRP). If disabled, some peer-to-peer and collaborative applications, such as Remote Assistance, may not function.","NT AUTHORITY\LocalService","","Normal","The operation completed successfully (0)" "Peer Networking Grouping","p2psvc","Running","Manual","Share Process","Stop, Shutdown","C:\Windows\System32\svchost.exe -k LocalServicePeerNet","Enables multi-party communication using Peer-to-Peer Grouping. If disabled, some applications, such as HomeGroup, may not function.","NT AUTHORITY\LocalService","","Normal","The operation completed successfully (0)" "Peer Networking Identity Manager","p2pimsvc","Running","Manual","Share Process","Stop, Shutdown","C:\Windows\System32\svchost.exe -k LocalServicePeerNet","Provides identity services for the Peer Name Resolution Protocol (PNRP) and Peer-to-Peer Grouping services. If disabled, the Peer Name Resolution Protocol (PNRP) and Peer-to-Peer Grouping services may not function, and some applications, such as HomeGroup and Remote Assistance, may not function correctly.","NT AUTHORITY\LocalService","","Normal","The operation completed successfully (0)" "Performance Counter DLL Host","PerfHost","Stopped","Manual","Own Process","","C:\Windows\SysWow64\perfhost.exe","Enables remote users and 64-bit processes to query performance counters provided by 32-bit DLLs. If this service is stopped, only local users and 32-bit processes will be able to query performance counters provided by 32-bit DLLs.","NT AUTHORITY\LocalService","","Normal","No attempts to start the service have been made since the last boot (1077)" "Performance Logs & Alerts","pla","Stopped","Manual","Share Process","","C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork","Performance Logs and Alerts Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. If this service is disabled, any services that explicitly depend on it will fail to start.","NT AUTHORITY\LocalService","","Normal","No attempts to start the service have been made since the last boot (1077)" "Plug and Play","PlugPlay","Running","Automatic","Share Process","Shutdown, Param Change, Session Change","C:\Windows\system32\svchost.exe -k DcomLaunch","Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability.","LocalSystem","PlugPlay","Normal","The operation completed successfully (0)" "Pml Driver HPZ12","Pml Driver HPZ12","Running","Automatic","Own Process","Stop, Shutdown","C:\Windows\System32\svchost.exe -k HPZ12","","NT AUTHORITY\LocalService","","Normal","The operation completed successfully (0)" "PnP-X IP Bus Enumerator","IPBusEnum","Stopped","Manual","Share Process","","C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted","The PnP-X bus enumerator service manages the virtual network bus. It discovers network connected devices using the SSDP/WS discovery protocols and gives them presence in PnP. If this service is stopped or disabled, presence of NCD devices will not be maintained in PnP. All pnpx based scenarios will stop functioning.","LocalSystem","","Normal","No attempts to start the service have been made since the last boot (1077)" "PNRP Machine Name Publication Service","PNRPAutoReg","Stopped","Manual","Share Process","","C:\Windows\System32\svchost.exe -k LocalServicePeerNet","This service publishes a machine name using the Peer Name Resolution Protocol. Configuration is managed via the netsh context 'p2p pnrp peer' ","NT AUTHORITY\LocalService","","Normal","No attempts to start the service have been made since the last boot (1077)" "Portable Device Enumerator Service","WPDBusEnum","Stopped","Manual","Share Process","","C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted","Enforces group policy for removable mass-storage devices. Enables applications such as Windows Media Player and Image Import Wizard to transfer and synchronize content using removable mass-storage devices.","LocalSystem","","Normal","The operation completed successfully (0)" "Power","Power","Running","Automatic","Share Process","Shutdown","C:\Windows\system32\svchost.exe -k DcomLaunch","Manages power policy and power policy notification delivery.","LocalSystem","PlugPlay","Normal","The operation completed successfully (0)" "Print Spooler","Spooler","Running","Automatic","Own Process (Interactive)","Stop, Power Event, Session Change","C:\Windows\System32\spoolsv.exe","Loads files to memory for later printing","LocalSystem","SpoolerGroup","Normal","The operation completed successfully (0)" "Problem Reports and Solutions Control Panel Support","wercplsupport","Stopped","Manual","Share Process","","C:\Windows\System32\svchost.exe -k netsvcs","This service provides support for viewing, sending and deletion of system-level problem reports for the Problem Reports and Solutions control panel.","localSystem","","Normal","The operation completed successfully (0)" "Program Compatibility Assistant Service","PcaSvc","Running","Automatic","Share Process","Stop","C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted","This service provides support for the Program Compatibility Assistant (PCA). PCA monitors programs installed and run by the user and detects known compatibility problems. If this service is stopped, PCA will not function properly.","LocalSystem","","Normal","The operation completed successfully (0)" "Protected Storage","ProtectedStorage","Running","Manual","Share Process","Stop","C:\Windows\system32\lsass.exe","Provides protected storage for sensitive data, such as passwords, to prevent access by unauthorized services, processes, or users.","LocalSystem","","Normal","The operation completed successfully (0)" "Quality Windows Audio Video Experience","QWAVE","Stopped","Manual","Share Process","","C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation","Quality Windows Audio Video Experience (qWave) is a networking platform for Audio Video (AV) streaming applications on IP home networks. qWave enhances AV streaming performance and reliability by ensuring network quality-of-service (QoS) for AV applications. It provides mechanisms for admission control, run time monitoring and enforcement, application feedback, and traffic prioritization.","NT AUTHORITY\LocalService","","Normal","No attempts to start the service have been made since the last boot (1077)" "Remote Access Auto Connection Manager","RasAuto","Stopped","Manual","Share Process","","C:\Windows\System32\svchost.exe -k netsvcs","Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address.","localSystem","","Normal","No attempts to start the service have been made since the last boot (1077)" "Remote Access Connection Manager","RasMan","Running","Manual","Share Process","Stop, Shutdown, Power Event, Session Change","C:\Windows\System32\svchost.exe -k netsvcs","Manages dial-up and virtual private network (VPN) connections from this computer to the Internet or other remote networks. If this service is disabled, any services that explicitly depend on it will fail to start.","localSystem","","Normal","The operation completed successfully (0)" "Remote Desktop Configuration","SessionEnv","Stopped","Manual","Share Process","","C:\Windows\System32\svchost.exe -k netsvcs","Remote Desktop Configuration service (RDCS) is responsible for all Remote Desktop Services and Remote Desktop related configuration and session maintenance activities that require SYSTEM context. These include per-session temporary folders, RD themes, and RD certificates.","localSystem","","Normal","No attempts to start the service have been made since the last boot (1077)" "Remote Desktop Services","TermService","Stopped","Manual","Share Process","","C:\Windows\System32\svchost.exe -k NetworkService","Allows users to connect interactively to a remote computer. Remote Desktop and Remote Desktop Session Host Server depend on this service. To prevent remote use of this computer, clear the checkboxes on the Remote tab of the System properties control panel item.","NT Authority\NetworkService","","Normal","No attempts to start the service have been made since the last boot (1077)" "Remote Procedure Call (RPC)","RpcSs","Running","Automatic","Share Process","Power Event","C:\Windows\system32\svchost.exe -k rpcss","The RPCSS service is the Service Control Manager for COM and DCOM servers. It performs object activations requests, object exporter resolutions and distributed garbage collection for COM and DCOM servers. If this service is stopped or disabled, programs using COM or DCOM will not function properly. It is strongly recommended that you have the RPCSS service running","NT AUTHORITY\NetworkService","COM Infrastructure","Normal","The operation completed successfully (0)" "Remote Procedure Call (RPC) Locator","RpcLocator","Stopped","Manual","Own Process","","C:\Windows\system32\locator.exe","In Windows 2003 and earlier versions of Windows, the Remote Procedure Call (RPC) Locator service manages the RPC name service database. In Windows Vista and later versions of Windows, this service does not provide any functionality and is present for application compatibility.","NT AUTHORITY\NetworkService","","Normal","No attempts to start the service have been made since the last boot (1077)" "Remote Registry","RemoteRegistry","Stopped","Manual","Share Process","","C:\Windows\system32\svchost.exe -k regsvc","Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start.","NT AUTHORITY\LocalService","","Normal","No attempts to start the service have been made since the last boot (1077)" "Routing and Remote Access","RemoteAccess","Stopped","Disabled","Share Process","","C:\Windows\System32\svchost.exe -k netsvcs","Offers routing services to businesses in local area and wide area network environments.","localSystem","","Normal","No attempts to start the service have been made since the last boot (1077)" "RPC Endpoint Mapper","RpcEptMapper","Running","Automatic","Share Process","","C:\Windows\system32\svchost.exe -k RPCSS","Resolves RPC interfaces identifiers to transport endpoints. If this service is stopped or disabled, programs using Remote Procedure Call (RPC) services will not function properly.","NT AUTHORITY\NetworkService","COM Infrastructure","Normal","The operation completed successfully (0)" "Secondary Logon","seclogon","Stopped","Manual","Share Process","","C:\Windows\system32\svchost.exe -k netsvcs","Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.","LocalSystem","","Normal","No attempts to start the service have been made since the last boot (1077)" "Secure Socket Tunneling Protocol Service","SstpSvc","Running","Manual","Share Process","Stop, Shutdown","C:\Windows\system32\svchost.exe -k LocalService","Provides support for the Secure Socket Tunneling Protocol (SSTP) to connect to remote computers using VPN. If this service is disabled, users will not be able to use SSTP to access remote servers.","NT Authority\LocalService","","Normal","The operation completed successfully (0)" "Security Accounts Manager","SamSs","Running","Automatic","Share Process","","C:\Windows\system32\lsass.exe","The startup of this service signals other services that the Security Accounts Manager (SAM) is ready to accept requests. Disabling this service will prevent other services in the system from being notified when the SAM is ready, which may in turn cause those services to fail to start correctly. This service should not be disabled.","LocalSystem","MS_WindowsLocalValidation","Normal","The operation completed successfully (0)" "Security Center","wscsvc","Running","Automatic","Share Process","Stop, Shutdown, Session Change","C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted","The WSCSVC (Windows Security Center) service monitors and reports security health settings on the computer. The health settings include firewall (on/off), antivirus (on/off/out of date), antispyware (on/off/out of date), Windows Update (automatically/manually download and install updates), User Account Control (on/off), and Internet settings (recommended/not recommended). The service provides COM APIs for independent software vendors to register and record the state of their products to the Security Center service. The Action Center (AC) UI uses the service to provide systray alerts and a graphical view of the security health states in the AC control panel. Network Access Protection (NAP) uses the service to report the security health states of clients to the NAP Network Policy Server to make network quarantine decisions. The service also has a public API that allows external consumers to programmatically retrieve the aggregated security health state of the system.","NT AUTHORITY\LocalService","","Normal","The operation completed successfully (0)" "Server","LanmanServer","Running","Automatic","Share Process","Stop, Pause/Continue","C:\Windows\system32\svchost.exe -k netsvcs","Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.","LocalSystem","","Normal","The operation completed successfully (0)" "Shell Hardware Detection","ShellHWDetection","Running","Automatic","Share Process","Stop, Session Change","C:\Windows\System32\svchost.exe -k netsvcs","Provides notifications for AutoPlay hardware events.","LocalSystem","ShellSvcGroup","Ignore","The operation completed successfully (0)" "Skype Updater","SkypeUpdate","Stopped","Automatic","Own Process","",""C:\Program Files (x86)\Skype\Updater\Updater.exe"","Enables the detection, download and installation of updates for Skype.","LocalSystem","","Ignore","The operation completed successfully (0)" "Smart Card","SCardSvr","Stopped","Manual","Share Process","","C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation","Manages access to smart cards read by this computer. If this service is stopped, this computer will be unable to read smart cards. If this service is disabled, any services that explicitly depend on it will fail to start.","NT AUTHORITY\LocalService","SmartCardGroup","Normal","No attempts to start the service have been made since the last boot (1077)" "Smart Card Removal Policy","SCPolicySvc","Stopped","Manual","Share Process","","C:\Windows\system32\svchost.exe -k netsvcs","Allows the system to be configured to lock the user desktop upon smart card removal.","LocalSystem","","Normal","No attempts to start the service have been made since the last boot (1077)" "SNMP Trap","SNMPTRAP","Stopped","Manual","Own Process","","C:\Windows\System32\snmptrap.exe","Receives trap messages generated by local or remote Simple Network Management Protocol (SNMP) agents and forwards the messages to SNMP management programs running on this computer. If this service is stopped, SNMP-based programs on this computer will not receive SNMP trap messages. If this service is disabled, any services that explicitly depend on it will fail to start.","NT AUTHORITY\LocalService","","Normal","No attempts to start the service have been made since the last boot (1077)" "Software Protection","sppsvc","Stopped","Automatic","Own Process","","C:\Windows\system32\sppsvc.exe","Enables the download, installation and enforcement of digital licenses for Windows and Windows applications. If the service is disabled, the operating system and licensed applications may run in a notification mode. It is strongly recommended that you not disable the Software Protection service.","NT AUTHORITY\NetworkService","","Normal","The operation completed successfully (0)" "SPP Notification Service","sppuinotify","Stopped","Manual","Share Process","","C:\Windows\system32\svchost.exe -k LocalService","Provides Software Licensing activation and notification","NT AUTHORITY\LocalService","","Normal","No attempts to start the service have been made since the last boot (1077)" "SSDP Discovery","SSDPSRV","Running","Manual","Share Process","Stop, Shutdown","C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation","Discovers networked devices and services that use the SSDP discovery protocol, such as UPnP devices. Also announces SSDP devices and services running on the local computer. If this service is stopped, SSDP-based devices will not be discovered. If this service is disabled, any services that explicitly depend on it will fail to start.","NT AUTHORITY\LocalService","","Normal","The operation completed successfully (0)" "Superfetch","SysMain","Running","Automatic","Share Process","Stop, Shutdown, Power Event, Session Change","C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted","Maintains and improves system performance over time.","LocalSystem","","Ignore","The operation completed successfully (0)" "System Event Notification Service","SENS","Running","Automatic","Share Process","Stop, Power Event","C:\Windows\system32\svchost.exe -k netsvcs","Monitors system events and notifies subscribers to COM+ Event System of these events.","LocalSystem","ProfSvc_Group","Normal","The operation completed successfully (0)" "Tablet PC Input Service","TabletInputService","Stopped","Manual","Share Process","","C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted","Enables Tablet PC pen and ink functionality","LocalSystem","PlugPlay","Normal","No attempts to start the service have been made since the last boot (1077)" "Task Scheduler","Schedule","Running","Automatic","Share Process","Stop, Power Event, Session Change","C:\Windows\system32\svchost.exe -k netsvcs","Enables a user to configure and schedule automated tasks on this computer. The service also hosts multiple Windows system-critical tasks. If this service is stopped or disabled, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start.","LocalSystem","SchedulerGroup","Normal","The operation completed successfully (0)" "TCP/IP NetBIOS Helper","lmhosts","Running","Automatic","Share Process","Stop","C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted","Provides support for the NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution for clients on the network, therefore enabling users to share files, print, and log on to the network. If this service is stopped, these functions might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.","NT AUTHORITY\LocalService","TDI","Normal","The operation completed successfully (0)" "Telephony","TapiSrv","Running","Manual","Share Process","Stop, Pause/Continue","C:\Windows\System32\svchost.exe -k NetworkService","Provides Telephony API (TAPI) support for programs that control telephony devices on the local computer and, through the LAN, on servers that are also running the service.","NT AUTHORITY\NetworkService","","Normal","The operation completed successfully (0)" "Themes","Themes","Running","Automatic","Share Process","Stop","C:\Windows\System32\svchost.exe -k netsvcs","Provides user experience theme management.","LocalSystem","ProfSvc_Group","Normal","The operation completed successfully (0)" "Thread Ordering Server","THREADORDER","Stopped","Manual","Share Process","","C:\Windows\system32\svchost.exe -k LocalService","Provides ordered execution for a group of threads within a specific period of time.","NT AUTHORITY\LocalService","","Normal","No attempts to start the service have been made since the last boot (1077)" "TPM Base Services","TBS","Stopped","Manual","Share Process","","C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation","Enables access to the Trusted Platform Module (TPM), which provides hardware-based cryptographic services to system components and applications. If this service is stopped or disabled, applications will be unable to use keys protected by the TPM.","NT AUTHORITY\LocalService","","Normal","No attempts to start the service have been made since the last boot (1077)" "UPnP Device Host","upnphost","Running","Manual","Share Process","Stop, Shutdown, Power Event","C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation","Allows UPnP devices to be hosted on this computer. If this service is stopped, any hosted UPnP devices will stop functioning and no additional hosted devices can be added. If this service is disabled, any services that explicitly depend on it will fail to start.","NT AUTHORITY\LocalService","","Normal","The operation completed successfully (0)" "User Profile Service","ProfSvc","Running","Automatic","Share Process","Stop, Shutdown","C:\Windows\system32\svchost.exe -k netsvcs","This service is responsible for loading and unloading user profiles. If this service is stopped or disabled, users will no longer be able to successfully logon or logoff, applications may have problems getting to users' data, and components registered to receive profile event notifications will not receive them.","LocalSystem","ProfSvc_Group","Normal","The operation completed successfully (0)" "Virtual Disk","vds","Stopped","Manual","Own Process","","C:\Windows\System32\vds.exe","Provides management services for disks, volumes, file systems, and storage arrays.","LocalSystem","","Normal","No attempts to start the service have been made since the last boot (1077)" "Volume Shadow Copy","VSS","Stopped","Manual","Own Process","","C:\Windows\system32\vssvc.exe","Manages and implements Volume Shadow Copies used for backup and other purposes. If this service is stopped, shadow copies will be unavailable for backup and the backup may fail. If this service is disabled, any services that explicitly depend on it will fail to start.","LocalSystem","","Normal","No attempts to start the service have been made since the last boot (1077)" "WebClient","WebClient","Stopped","Manual","Share Process","","C:\Windows\system32\svchost.exe -k LocalService","Enables Windows-based programs to create, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start.","NT AUTHORITY\LocalService","NetworkProvider","Normal","No attempts to start the service have been made since the last boot (1077)" "Windows Activation Technologies Service","WatAdminSvc","Stopped","Manual","Own Process","","C:\Windows\system32\Wat\WatAdminSvc.exe","Performs Windows 7 Validation.","LocalSystem","","Normal","No attempts to start the service have been made since the last boot (1077)" "Windows Audio","AudioSrv","Running","Automatic","Share Process","Stop, Power Event, Session Change","C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted","Manages audio for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start","NT AUTHORITY\LocalService","AudioGroup","Normal","The operation completed successfully (0)" "Windows Audio Endpoint Builder","AudioEndpointBuilder","Running","Automatic","Share Process","Stop, Power Event, Session Change","C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted","Manages audio devices for the Windows Audio service. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start","LocalSystem","AudioGroup","Normal","The operation completed successfully (0)" "Windows Backup","SDRSVC","Stopped","Manual","Own Process","","C:\Windows\system32\svchost.exe -k SDRSVC","Provides Windows Backup and Restore capabilities.","localSystem","","Normal","No attempts to start the service have been made since the last boot (1077)" "Windows Biometric Service","WbioSrvc","Stopped","Manual","Share Process","","C:\Windows\system32\svchost.exe -k WbioSvcGroup","The Windows biometric service gives client applications the ability to capture, compare, manipulate, and store biometric data without gaining direct access to any biometric hardware or samples. The service is hosted in a privileged SVCHOST process.","LocalSystem","SmartCardGroup","Normal","No attempts to start the service have been made since the last boot (1077)" "Windows CardSpace","idsvc","Stopped","Manual","Share Process","",""C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe"","Securely enables the creation, management, and disclosure of digital identities.","LocalSystem","","Normal","No attempts to start the service have been made since the last boot (1077)" "Windows Color System","WcsPlugInService","Stopped","Manual","Share Process","","C:\Windows\system32\svchost.exe -k wcssvc","The WcsPlugInService service hosts third-party Windows Color System color device model and gamut map model plug-in modules. These plug-in modules are vendor-specific extensions to the Windows Color System baseline color device and gamut map models. Stopping or disabling the WcsPlugInService service will disable this extensibility feature, and the Windows Color System will use its baseline model processing rather than the vendor's desired processing. This might result in inaccurate color rendering.","NT AUTHORITY\LocalService","","Normal","No attempts to start the service have been made since the last boot (1077)" "Windows Connect Now - Config Registrar","wcncsvc","Running","Manual","Share Process","Stop, Shutdown","C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation","WCNCSVC hosts the Windows Connect Now Configuration which is Microsoft's Implementation of Wi-Fi Protected Setup (WPS) protocol. This is used to configure Wireless LAN settings for an Access Point (AP) or a Wi-Fi Device. The service is started programmatically as needed.","NT AUTHORITY\LocalService","","Normal","The operation completed successfully (0)" "Windows Defender","WinDefend","Stopped","Manual","Share Process","","C:\Windows\System32\svchost.exe -k secsvcs","Protection against spyware and potentially unwanted software","LocalSystem","","Normal","No attempts to start the service have been made since the last boot (1077)" "Windows Driver Foundation - User-mode Driver Framework","wudfsvc","Running","Automatic","Share Process","","C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted","Manages user-mode driver host processes.","LocalSystem","PlugPlay","Normal","The operation completed successfully (0)" "Windows Error Reporting Service","WerSvc","Stopped","Manual","Share Process","","C:\Windows\System32\svchost.exe -k WerSvcGroup","Allows errors to be reported when programs stop working or responding and allows existing solutions to be delivered. Also allows logs to be generated for diagnostic and repair services. If this service is stopped, error reporting might not work correctly and results of diagnostic services and repairs might not be displayed.","localSystem","","Ignore","The operation completed successfully (0)" "Windows Event Collector","Wecsvc","Stopped","Manual","Share Process","","C:\Windows\system32\svchost.exe -k NetworkService","This service manages persistent subscriptions to events from remote sources that support WS-Management protocol. This includes Windows Vista event logs, hardware and IPMI-enabled event sources. The service stores forwarded events in a local Event Log. If this service is stopped or disabled event subscriptions cannot be created and forwarded events cannot be accepted.","NT AUTHORITY\NetworkService","","Normal","No attempts to start the service have been made since the last boot (1077)" "Windows Event Log","eventlog","Running","Automatic","Share Process","Stop, Shutdown","C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted","This service manages events and event logs. It supports logging events, querying events, subscribing to events, archiving event logs, and managing event metadata. It can display events in both XML and plain text format. Stopping this service may compromise security and reliability of the system.","NT AUTHORITY\LocalService","Event Log","Normal","The operation completed successfully (0)" "Windows Firewall","MpsSvc","Running","Automatic","Share Process","Stop","C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork","Windows Firewall helps protect your computer by preventing unauthorized users from gaining access to your computer through the Internet or a network.","NT Authority\LocalService","NetworkProvider","Normal","The operation completed successfully (0)" "Windows Font Cache Service","FontCache","Running","Automatic","Share Process","Stop, Shutdown","C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation","Optimizes performance of applications by caching commonly used font data. Applications will start this service if it is not already running. It can be disabled, though doing so will degrade application performance.","NT AUTHORITY\LocalService","","Normal","The operation completed successfully (0)" "Windows Image Acquisition (WIA)","stisvc","Running","Automatic","Own Process","Stop, Pause/Continue, Shutdown, Param Change, Power Event","C:\Windows\system32\svchost.exe -k imgsvc","Provides image acquisition services for scanners and cameras","NT Authority\LocalService","","Normal","The operation completed successfully (0)" "Windows Installer","msiserver","Stopped","Manual","Own Process","","C:\Windows\system32\msiexec.exe /V","Adds, modifies, and removes applications provided as a Windows Installer (*.msi) package. If this service is disabled, any services that explicitly depend on it will fail to start.","LocalSystem","","Normal","No attempts to start the service have been made since the last boot (1077)" "Windows Live ID Sign-in Assistant","wlidsvc","Running","Automatic","Own Process","Stop, Power Event, Session Change",""C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"","Enables Windows Live ID authentication.","LocalSystem","","Normal","The operation completed successfully (0)" "Windows Live Mesh remote connections service","wlcrasvc","Stopped","Disabled","Own Process","",""C:\Program Files\Windows Live\Mesh\wlcrasvc.exe"","Lets you connect over the Internet to this computer and work on it as if you were sitting in front it - you can run the programs on it and browse all the files and folders on it.","LocalSystem","","Normal","No attempts to start the service have been made since the last boot (1077)" "Windows Management Instrumentation","Winmgmt","Running","Automatic","Share Process","Stop, Pause/Continue, Shutdown","C:\Windows\system32\svchost.exe -k netsvcs","Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.","localSystem","","Ignore","The operation completed successfully (0)" "Windows Media Center Receiver Service","ehRecvr","Stopped","Manual","Own Process","","C:\Windows\ehome\ehRecvr.exe","Windows Media Center Service for TV and FM broadcast reception","NT AUTHORITY\networkService","","Ignore","No attempts to start the service have been made since the last boot (1077)" "Windows Media Center Scheduler Service","ehSched","Stopped","Manual","Own Process","","C:\Windows\ehome\ehsched.exe","Starts and stops recording of TV programs within Windows Media Center","NT AUTHORITY\networkService","","Ignore","No attempts to start the service have been made since the last boot (1077)" "Windows Media Player Network Sharing Service","WMPNetworkSvc","Running","Automatic","Own Process","Stop, Power Event, Session Change",""C:\Program Files\Windows Media Player\wmpnetwk.exe"","Shares Windows Media Player libraries to other networked players and media devices using Universal Plug and Play","NT AUTHORITY\NetworkService","","Normal","The operation completed successfully (0)" "Windows Mobile-2003-based device connectivity","WcesComm","Running","Automatic","Share Process","Stop, Shutdown, Power Event","C:\Windows\system32\svchost.exe -k WindowsMobile","Provides connectivity for Windows Mobile-2003-based devices","NT AUTHORITY\LocalService","","Normal","The operation completed successfully (0)" "Windows Mobile-based device connectivity","RapiMgr","Running","Automatic","Share Process","Stop, Session Change","C:\Windows\system32\svchost.exe -k WindowsMobile","Provides remote command and control to Windows Mobile-based devices.","NT AUTHORITY\LocalService","","Normal","The operation completed successfully (0)" "Windows Modules Installer","TrustedInstaller","Stopped","Manual","Own Process","","C:\Windows\servicing\TrustedInstaller.exe","Enables installation, modification, and removal of Windows updates and optional components. If this service is disabled, install or uninstall of Windows updates might fail for this computer.","localSystem","ProfSvc_Group","Normal","No attempts to start the service have been made since the last boot (1077)" "Windows Presentation Foundation Font Cache 3.0.0.0","FontCache3.0.0.0","Running","Manual","Own Process","Stop, Shutdown","C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe","Optimizes performance of Windows Presentation Foundation (WPF) applications by caching commonly used font data. WPF applications will start this service if it is not already running. It can be disabled, though doing so will degrade the performance of WPF applications.","NT Authority\LocalService","","Normal","The operation completed successfully (0)" "Windows Remote Management (WS-Management)","WinRM","Stopped","Manual","Share Process","","C:\Windows\System32\svchost.exe -k NetworkService","Windows Remote Management (WinRM) service implements the WS-Management protocol for remote management. WS-Management is a standard web services protocol used for remote software and hardware management. The WinRM service listens on the network for WS-Management requests and processes them. The WinRM Service needs to be configured with a listener using winrm.cmd command line tool or through Group Policy in order for it to listen over the network. The WinRM service provides access to WMI data and enables event collection. Event collection and subscription to events require that the service is running. WinRM messages use HTTP and HTTPS as transports. The WinRM service does not depend on IIS but is preconfigured to share a port with IIS on the same machine. The WinRM service reserves the /wsman URL prefix. To prevent conflicts with IIS, administrators should ensure that any websites hosted on IIS do not use the /wsman URL prefix.","NT AUTHORITY\NetworkService","","Normal","No attempts to start the service have been made since the last boot (1077)" "Windows Search","WSearch","Running","Automatic","Own Process","Stop, Shutdown, Power Event, Session Change","C:\Windows\system32\SearchIndexer.exe /Embedding","Provides content indexing, property caching, and search results for files, e-mail, and other content.","LocalSystem","","Normal","The operation completed successfully (0)" "Windows Time","W32Time","Stopped","Manual","Share Process","","C:\Windows\system32\svchost.exe -k LocalService","Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.","NT AUTHORITY\LocalService","","Normal","The operation completed successfully (0)" "Windows Update","wuauserv","Running","Automatic","Share Process","Stop, Shutdown, Power Event, Session Change","C:\Windows\system32\svchost.exe -k netsvcs","Enables the detection, download, and installation of updates for Windows and other programs. If this service is disabled, users of this computer will not be able to use Windows Update or its automatic updating feature, and programs will not be able to use the Windows Update Agent (WUA) API.","LocalSystem","","Normal","The operation completed successfully (0)" "WinHTTP Web Proxy Auto-Discovery Service","WinHttpAutoProxySvc","Stopped","Manual","Share Process","","C:\Windows\system32\svchost.exe -k LocalService","WinHTTP implements the client HTTP stack and provides developers with a Win32 API and COM Automation component for sending HTTP requests and receiving responses. In addition, WinHTTP provides support for auto-discovering a proxy configuration via its implementation of the Web Proxy Auto-Discovery (WPAD) protocol.","NT AUTHORITY\LocalService","","Normal","The operation completed successfully (0)" "Wired AutoConfig","dot3svc","Stopped","Manual","Share Process","","C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted","The Wired AutoConfig (DOT3SVC) service is responsible for performing IEEE 802.1X authentication on Ethernet interfaces. If your current wired network deployment enforces 802.1X authentication, the DOT3SVC service should be configured to run for establishing Layer 2 connectivity and/or providing access to network resources. Wired networks that do not enforce 802.1X authentication are unaffected by the DOT3SVC service.","localSystem","TDI","Normal","No attempts to start the service have been made since the last boot (1077)" "WLAN AutoConfig","Wlansvc","Running","Automatic","Share Process","Stop, Shutdown, Power Event, Session Change","C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted","The WLANSVC service provides the logic required to configure, discover, connect to, and disconnect from a wireless local area network (WLAN) as defined by IEEE 802.11 standards. It also contains the logic to turn your computer into a software access point so that other devices or computers can connect to your computer wirelessly using a WLAN adapter that can support this. Stopping or disabling the WLANSVC service will make all WLAN adapters on your computer inaccessible from the Windows networking UI. It is strongly recommended that you have the WLANSVC service running if your computer has a WLAN adapter.","LocalSystem","TDI","Normal","The operation completed successfully (0)" "WMI Performance Adapter","wmiApSrv","Stopped","Manual","Own Process","","C:\Windows\system32\wbem\WmiApSrv.exe","Provides performance library information from Windows Management Instrumentation (WMI) providers to clients on the network. This service only runs when Performance Data Helper is activated.","localSystem","","Normal","No attempts to start the service have been made since the last boot (1077)" "Workstation","LanmanWorkstation","Running","Automatic","Share Process","Stop, Pause/Continue, Power Event","C:\Windows\System32\svchost.exe -k NetworkService","Creates and maintains client network connections to remote servers using the SMB protocol. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.","NT AUTHORITY\NetworkService","NetworkProvider","Normal","The operation completed successfully (0)" "WWAN AutoConfig","WwanSvc","Stopped","Manual","Share Process","","C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork","This service manages mobile broadband (GSM & CDMA) data card/embedded module adapters and connections by auto-configuring the networks. It is strongly recommended that this service be kept running for best user experience of mobile broadband devices.","NT Authority\LocalService","TDI","Normal","No attempts to start the service have been made since the last boot (1077)" "ZAtheros Bt&Wlan Coex Agent","ZAtheros Bt&Wlan Coex Agent","Running","Automatic","Own Process","Stop, Power Event","C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe","Co-existence Coordinator Service between 11a/b/g/n Wireless LAN and Bluetooth.","LocalSystem","","Ignore","The operation completed successfully (0)"