------ REGISTRY:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost]
- HTTPFilter - HTTPFilter
- LocalService - Alerter, WebClient, LmHosts, RemoteRegistry, upnphost, SSDPSRV
- NetworkService - DnsCache
- DcomLaunch - DcomLaunch, TermService
- rpcss - RpcSs
- imgsvc - StiSvc
- termsvcs - TermService
- WudfServiceGroup - WUDFSvc
- netsvcs - 6to4, AppMgmt, AudioSrv, Browser, CryptSvc, DMServer, DHCP, ERSvc, EventSystem, FastUserSwitchingCompatibility, HidServ, Ias, Iprip, Irmon, LanmanServer, LanmanWorkstation, Messenger, Netman, Nla, Ntmssvc, NWCWorkstation, Nwsapagent, Rasauto, Rasman, Remoteaccess, Schedule, Seclogon, SENS, Sharedaccess, SRService, Tapisrv, Themes, TrkWks, W32Time, WZCSVC, Wmi, WmdmPmSp, winmgmt, wscsvc, xmlprov, MHN, BITS, wuauserv, ShellHWDetection, helpsvc, WmdmPmSN
------ SVCHOST SERVICES NOT RUNNING
STOPPED: AUTO_START: AudioSrv : Windows Audio
STOPPED: AUTO_START: BITS : Background Intelligent Transfer Service
STOPPED: AUTO_START: Browser : Computer Browser
STOPPED: AUTO_START: CryptSvc : Cryptographic Services
STOPPED: AUTO_START: dmserver : Logical Disk Manager
STOPPED: AUTO_START: Dnscache : DNS Client
STOPPED: AUTO_START: ERSvc : Error Reporting Service
STOPPED: AUTO_START: helpsvc : Help and Support
STOPPED: AUTO_START: lanmanworkstation : Workstation
STOPPED: AUTO_START: LmHosts : TCP/IP NetBIOS Helper
STOPPED: AUTO_START: RemoteRegistry : Remote Registry
STOPPED: AUTO_START: RpcSs : Remote Procedure Call (RPC)
STOPPED: AUTO_START: Schedule : Task Scheduler
STOPPED: AUTO_START: SENS : System Event Notification
STOPPED: AUTO_START: SharedAccess : Windows Firewall/Internet Connection Sharing (ICS)
STOPPED: AUTO_START: ShellHWDetection : Shell Hardware Detection
STOPPED: AUTO_START: srservice : System Restore Service
STOPPED: AUTO_START: SSDPSRV : SSDP Discovery Service
STOPPED: AUTO_START: TrkWks : Distributed Link Tracking Client
STOPPED: AUTO_START: WebClient : WebClient
STOPPED: AUTO_START: winmgmt : Windows Management Instrumentation
STOPPED: AUTO_START: wscsvc : Security Center
STOPPED: AUTO_START: wuauserv : Automatic Updates
STOPPED: AUTO_START: WZCSVC : Wireless Zero Configuration
STOPPED: DEMAND_START: AppMgmt : Application Management
STOPPED: DEMAND_START: EventSystem : COM+ Event System
STOPPED: DEMAND_START: FastUserSwitchingCompatibility : Fast User Switching Compatibility
STOPPED: DEMAND_START: HTTPFilter : HTTP SSL
STOPPED: DEMAND_START: MHN : MHN
STOPPED: DEMAND_START: Netman : Network Connections
STOPPED: DEMAND_START: Nla : Network Location Awareness (NLA)
STOPPED: DEMAND_START: RasAuto : Remote Access Auto Connection Manager
STOPPED: DEMAND_START: RasMan : Remote Access Connection Manager
STOPPED: DEMAND_START: stisvc : Windows Image Acquisition (WIA)
STOPPED: DEMAND_START: TapiSrv : Telephony
STOPPED: DEMAND_START: TermService : Terminal Services
STOPPED: DEMAND_START: upnphost : Universal Plug and Play Device Host
STOPPED: DEMAND_START: WmdmPmSN : Portable Media Serial Number Service
STOPPED: DEMAND_START: Wmi : Windows Management Instrumentation Driver Extensions
STOPPED: DEMAND_START: WudfSvc : Windows Driver Foundation - User-mode Driver Framework
STOPPED: DEMAND_START: xmlprov : Network Provisioning Service
STOPPED: DISABLED: Alerter : Alerter
STOPPED: DISABLED: HidServ : Human Interface Device Access
STOPPED: DISABLED: Messenger : Messenger
STOPPED: DISABLED: NtmsSvc : Removable Storage
STOPPED: DISABLED: RemoteAccess : Routing and Remote Access
------ SVCHOST CURRENTLY RUNNING:
1752- C:\WINDOWS\system32\svchost -k DcomLaunch
- DcomLaunch : DCOM Server Process Launcher
1928- C:\WINDOWS\System32\svchost.exe -k netsvcs
- Dhcp : DHCP Client
- lanmanserver : Server
- seclogon : Secondary Logon
- Themes : Themes
- W32Time : Windows Time
------ SVCHOST SUB-DEPENDENTS
HTTPFilter = 1
STOPPED: WMPNetworkSvc: Windows Media Player Network Sharing Service
upnphost = 1
STOPPED: WMPNetworkSvc: Windows Media Player Network Sharing Service
SSDPSRV = 3
STOPPED: McrdSvc: Media Center Extender Service
STOPPED: upnphost: Universal Plug and Play Device Host
STOPPED: WMPNetworkSvc: Windows Media Player Network Sharing Service
DMServer = 1
STOPPED: dmadmin: Logical Disk Manager Administrative Service
EventSystem = 1
STOPPED: SENS: System Event Notification
LanmanServer = 1
STOPPED: Browser: Computer Browser
LanmanWorkstation = 5
STOPPED: Alerter: Alerter
STOPPED: Browser: Computer Browser
STOPPED: Messenger: Messenger
STOPPED: Netlogon: Net Logon
STOPPED: RpcLocator: Remote Procedure Call (RPC) Locator
Netman = 1
STOPPED: SharedAccess: Windows Firewall/Internet Connection Sharing (ICS)
Rasman = 1
STOPPED: RasAuto: Remote Access Auto Connection Manager
Tapisrv = 2
STOPPED: RasAuto: Remote Access Auto Connection Manager
STOPPED: RasMan: Remote Access Connection Manager
winmgmt = 2
STOPPED: SharedAccess: Windows Firewall/Internet Connection Sharing (ICS)
STOPPED: wscsvc: Security Center
TermService = 1
STOPPED: FastUserSwitchingCompatibility: Fast User Switching Compatibility
RpcSs = 49
STOPPED: AudioSrv: Windows Audio
STOPPED: BITS: Background Intelligent Transfer Service
STOPPED: CiSvc: Indexing Service
STOPPED: COMSysApp: COM+ System Application
STOPPED: CryptSvc: Cryptographic Services
STOPPED: dmadmin: Logical Disk Manager Administrative Service
STOPPED: dmserver: Logical Disk Manager
STOPPED: ERSvc: Error Reporting Service
STOPPED: EventSystem: COM+ Event System
STOPPED: FastUserSwitchingCompatibility: Fast User Switching Compatibility
STOPPED: helpsvc: Help and Support
STOPPED: HidServ: Human Interface Device Access
STOPPED: iPodService: iPodService
STOPPED: McrdSvc: Media Center Extender Service
STOPPED: Messenger: Messenger
STOPPED: MHN: MHN
STOPPED: MSDTC: Distributed Transaction Coordinator
STOPPED: MSIServer: Windows Installer
STOPPED: Netman: Network Connections
STOPPED: NtmsSvc: Removable Storage
STOPPED: PolicyAgent: IPSEC Services
STOPPED: ProtectedStorage: Protected Storage
STOPPED: RasAuto: Remote Access Auto Connection Manager
STOPPED: RasMan: Remote Access Connection Manager
STOPPED: RDSessMgr: Remote Desktop Help Session Manager
STOPPED: RemoteAccess: Routing and Remote Access
STOPPED: RemoteRegistry: Remote Registry
STOPPED: RSVP: QoS RSVP
STOPPED: SamSs: Security Accounts Manager
STOPPED: Schedule: Task Scheduler
STOPPED: SENS: System Event Notification
STOPPED: SharedAccess: Windows Firewall/Internet Connection Sharing (ICS)
STOPPED: ShellHWDetection: Shell Hardware Detection
STOPPED: Spooler: Print Spooler
STOPPED: srservice: System Restore Service
STOPPED: stisvc: Windows Image Acquisition (WIA)
STOPPED: svcWRSSSDK: Webroot Spy Sweeper Engine
STOPPED: SwPrv: MS Software Shadow Copy Provider
STOPPED: TapiSrv: Telephony
STOPPED: TermService: Terminal Services
STOPPED: TlntSvr: Telnet
STOPPED: TrkWks: Distributed Link Tracking Client
STOPPED: usnjsvc: Messenger Sharing Folders USN Journal Reader service
STOPPED: VSS: Volume Shadow Copy
STOPPED: winmgmt: Windows Management Instrumentation
STOPPED: WmiApSrv: WMI Performance Adapter
STOPPED: wscsvc: Security Center
STOPPED: WZCSVC: Wireless Zero Configuration
STOPPED: xmlprov: Network Provisioning Service
TermService = 1
STOPPED: FastUserSwitchingCompatibility: Fast User Switching Compatibility
Edited by chou05, 15 June 2008 - 05:41 PM.