Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Why is my Windows Vista basic laptop so slow?


  • Please log in to reply

#16
chipper1

chipper1

    Member

  • Topic Starter
  • Member
  • PipPip
  • 80 posts
What are your thoughts on that? In how best I can fix it? Thanks :)
  • 0

Advertisements


#17
Ztruker

Ztruker

    Member 5k

  • Technician
  • 7,091 posts
ntkrpamp.exe is a Microsoft program and is not the cause of the problem. Usually this is caused by other software or a device driver.

I see you use Norton (Symantec) Anti-virus. You could try uninstalling it and reinstalling it as that is a prime candidate for this kind of problem.

Download, install and run Codestuff Starter. You need to unzip it once you download it before installing.

Once you run it, click on File / Save as HTML.

Zip the saved html file then upload it here using the Browse and Attach This File buttons below the message input area.

This will let me see everything that is running on your computer and hopefully help to figure out what is causing the problem.
  • 0

#18
chipper1

chipper1

    Member

  • Topic Starter
  • Member
  • PipPip
  • 80 posts
OK thanks, how do I unzip it?? I use to have norton but have not used it since the subscription ran out. Shoukld I just uninstall it?
  • 0

#19
chipper1

chipper1

    Member

  • Topic Starter
  • Member
  • PipPip
  • 80 posts
OK I have downloaded it now...but cant figure out what to do now? I can see the box with all the information in it?
  • 0

#20
chipper1

chipper1

    Member

  • Topic Starter
  • Member
  • PipPip
  • 80 posts
OK I have saved it but when I goto choose file I can not find it also I type in CodeStuff Starter which is what I savd it as and it doesnt bring it up??
  • 0

#21
Ztruker

Ztruker

    Member 5k

  • Technician
  • 7,091 posts
Run it again only save it to your Desktop. Much easier to find that way.
  • 0

#22
chipper1

chipper1

    Member

  • Topic Starter
  • Member
  • PipPip
  • 80 posts
CodeStuff Starter

Still trying to figure out how to highlight it all or save it??? 1 hout and counting...
  • 0

#23
chipper1

chipper1

    Member

  • Topic Starter
  • Member
  • PipPip
  • 80 posts
So annoying as i have the box right there and have saved it to desktop and keep going to file, save as HTML, save as CodeStuff Starter, in documents, then I goto choose file below and its not there???

Edited by chipper1, 27 December 2011 - 06:45 PM.

  • 0

#24
chipper1

chipper1

    Member

  • Topic Starter
  • Member
  • PipPip
  • 80 posts
OK here it is

Attached Files


  • 0

#25
chipper1

chipper1

    Member

  • Topic Starter
  • Member
  • PipPip
  • 80 posts
Display Name Name State Startup Type Service Type Controls Accepted Executable Description Log On As Group Error Control Exit Code
Application Experience AeLookupSvc Running Automatic Share Process Stop C:\Windows\system32\svchost.exe -k netsvcs Processes application compatibility cache requests for applications as they are launched localSystem Normal The operation completed successfully (0)
Application Information Appinfo Running Manual Share Process Stop, Session Change C:\Windows\system32\svchost.exe -k netsvcs Facilitates the running of interactive applications with additional administrative privileges. If this service is stopped, users will be unable to launch applications with the additional administrative privileges they may require to perform desired user tasks. LocalSystem Normal The operation completed successfully (0)
Application Layer Gateway Service ALG Stopped Manual Own Process C:\Windows\System32\alg.exe Provides support for 3rd party protocol plug-ins for Internet Connection Sharing NT AUTHORITY\LocalService Normal No attempts to start the service have been made since the last boot (1077)
Background Intelligent Transfer Service BITS Running Automatic Share Process Stop, Shutdown, Session Change C:\Windows\System32\svchost.exe -k netsvcs Transfers files in the background using idle network bandwidth. If the service is disabled, then any applications that depend on BITS, such as Windows Update or MSN Explorer, will be unable to automatically download programs and other information. LocalSystem Normal The operation completed successfully (0)
Base Filtering Engine BFE Running Automatic Share Process Stop C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork The Base Filtering Engine (BFE) is a service that manages firewall and Internet Protocol security (IPsec) policies and implements user mode filtering. Stopping or disabling the BFE service will significantly reduce the security of the system. It will also result in unpredictable behavior in IPsec management and firewall applications. NT AUTHORITY\LocalService NetworkProvider Normal The operation completed successfully (0)
Certificate Propagation CertPropSvc Stopped Manual Share Process C:\Windows\system32\svchost.exe -k netsvcs Propagates certificates from smart cards. LocalSystem Normal No attempts to start the service have been made since the last boot (1077)
CNG Key Isolation KeyIso Running Manual Share Process Stop C:\Windows\system32\lsass.exe The CNG key isolation service is hosted in the LSA process. The service provides key process isolation to private keys and associated cryptographic operations as required by the Common Criteria. The service stores and uses long-lived keys in a secure process complying with Common Criteria requirements. LocalSystem Normal The operation completed successfully (0)
COM+ Event System EventSystem Running Automatic Share Process Stop C:\Windows\system32\svchost.exe -k LocalService Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start. NT AUTHORITY\LocalService Normal The operation completed successfully (0)
COM+ System Application COMSysApp Stopped Manual Own Process C:\Windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. LocalSystem Normal No attempts to start the service have been made since the last boot (1077)
Computer Browser Browser Running Automatic Share Process Stop C:\Windows\System32\svchost.exe -k netsvcs Maintains an updated list of computers on the network and supplies this list to computers designated as browsers. If this service is stopped, this list will not be updated or maintained. If this service is disabled, any services that explicitly depend on it will fail to start. LocalSystem NetworkProvider Normal The operation completed successfully (0)
Cryptographic Services CryptSvc Running Automatic Share Process Stop, Shutdown, Session Change C:\Windows\system32\svchost.exe -k NetworkService Provides four management services: Catalog Database Service, which confirms the signatures of Windows files and allows new programs to be installed; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; Automatic Root Certificate Update Service, which retrieves root certificates from Windows Update and enable scenarios such as SSL; and Key Service, which helps enroll this computer for certificates. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. NT Authority\NetworkService Normal The operation completed successfully (0)
Cyberlink RichVideo Service(CRVS) RichVideo Running Automatic Own Process (Interactive) Stop "C:\Program Files\CyberLink\Shared Files\RichVideo.exe" LocalSystem Normal The operation completed successfully (0)
DCOM Server Process Launcher DcomLaunch Running Automatic Share Process C:\Windows\system32\svchost.exe -k DcomLaunch Provides launch functionality for DCOM services. LocalSystem COM Infrastructure Normal The operation completed successfully (0)
Desktop Window Manager Session Manager UxSms Running Automatic Share Process Stop, Shutdown, Session Change C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted Provides Desktop Window Manager startup and maintenance services localSystem UIGroup Normal The operation completed successfully (0)
DFS Replication DFSR Stopped Manual Own Process C:\Windows\system32\DFSR.exe Enables you to synchronize folders on multiple servers across local or wide area network (WAN) network connections. This service uses the Remote Differential Compression (RDC) protocol to update only the portions of files that have changed since the last replication. LocalSystem Normal No attempts to start the service have been made since the last boot (1077)
DHCP Client Dhcp Running Automatic Share Process Stop, Shutdown C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted Registers and updates IP addresses and DNS records for this computer. If this service is stopped, this computer will not receive dynamic IP addresses and DNS updates. If this service is disabled, any services that explicitly depend on it will fail to start. NT Authority\LocalService TDI Normal The operation completed successfully (0)
Diagnostic Policy Service DPS Running Automatic Share Process Stop, Shutdown C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork The Diagnostic Policy Service enables problem detection, troubleshooting and resolution for Windows components. If this service is stopped, diagnostics will no longer function. If this service is disabled, any services that explicitly depend on it will fail to start. NT AUTHORITY\LocalService Normal The operation completed successfully (0)
Diagnostic Service Host WdiServiceHost Stopped Manual Share Process C:\Windows\System32\svchost.exe -k wdisvc The Diagnostic Service Host service enables problem detection, troubleshooting and resolution for Windows components. If this service is stopped, some diagnostics will no longer function. If this service is disabled, any services that explicitly depend on it will fail to start. NT AUTHORITY\LocalService Normal No attempts to start the service have been made since the last boot (1077)
Diagnostic System Host WdiSystemHost Running Manual Share Process Stop, Shutdown C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted The Diagnostic System Host service enables problem detection, troubleshooting and resolution for Windows components. If this service is stopped, some diagnostics will no longer function. If this service is disabled, any services that explicitly depend on it will fail to start. LocalSystem Normal The operation completed successfully (0)
Distributed Link Tracking Client TrkWks Running Automatic Share Process Stop, Shutdown C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted Maintains links between NTFS files within a computer or across computers in a network. LocalSystem Normal The operation completed successfully (0)
Distributed Transaction Coordinator MSDTC Stopped Manual Own Process C:\Windows\System32\msdtc.exe Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will not occur. If this service is disabled, any services that explicitly depend on it will fail to start. NT AUTHORITY\NetworkService Normal No attempts to start the service have been made since the last boot (1077)
DNS Client Dnscache Running Automatic Share Process Stop, Param Change, Net Bind Change, Power Event C:\Windows\system32\svchost.exe -k NetworkService The DNS Client service (dnscache) caches Domain Name System (DNS) names and registers the full computer name for this computer. If the service is stopped, DNS names will continue to be resolved. However, the results of DNS name queries will not be cached and the computer's name will not be registered. If the service is disabled, any services that explicitly depend on it will fail to start. NT AUTHORITY\NetworkService TDI Normal The operation completed successfully (0)
eDataSecurity Service eDataSecurity Service Running Automatic Own Process Stop "C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe" eDataSecurity Service LocalSystem Normal The operation completed successfully (0)
ePerformance Service AcerMemUsageCheckService Running Automatic Own Process (Interactive) Stop, Shutdown, Power Event C:\Acer\Empowering Technology\ePerformance\MemCheck.exe Monitor memory usage and provide the ability to release unused memory. LocalSystem Ignore The operation completed successfully (0)
eRecovery Service eRecoveryService Running Automatic Own Process Stop, Shutdown C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe Acer eRecovery Management LocalSystem Normal The operation completed successfully (0)
Extensible Authentication Protocol EapHost Running Manual Share Process Stop, Shutdown, Session Change C:\Windows\System32\svchost.exe -k netsvcs The Extensible Authentication Protocol (EAP) service provides network authentication in such scenarios as 802.1x wired and wireless, VPN, and Network Access Protection (NAP). EAP also provides application programming interfaces (APIs) that are used by network access clients, including wireless and VPN clients, during the authentication process. If you disable this service, this computer is prevented from accessing networks that require EAP authentication. localSystem Normal The operation completed successfully (0)
Function Discovery Provider Host fdPHost Running Manual Share Process Stop, Session Change C:\Windows\system32\svchost.exe -k LocalService Host process for Function Discovery providers. NT AUTHORITY\LocalService Normal The operation completed successfully (0)
Function Discovery Resource Publication FDResPub Running Automatic Share Process Stop, Shutdown, Power Event C:\Windows\system32\svchost.exe -k LocalService Publishes this computer and resources attached to this computer so they can be discovered over the network. If this service is stopped, network resources will no longer be published and they will not be discovered by other computers on the network. NT AUTHORITY\LocalService Normal The operation completed successfully (0)
Group Policy Client gpsvc Running Automatic Own Process Stop C:\Windows\system32\svchost.exe -k GPSvcGroup The service is responsible for applying settings configured by administrators for the computer and users through the Group Policy component. If the service is stopped or disabled, the settings will not be applied and applications and components will not be manageable through Group Policy. Any components or applications that depend on the Group Policy component might not be functional if the service is stopped or disabled. LocalSystem ProfSvc_Group Normal The operation completed successfully (0)
Health Key and Certificate Management hkmsvc Stopped Manual Share Process C:\Windows\System32\svchost.exe -k netsvcs Provides X.509 certificate and key management services for the Network Access Protection Agent (NAPAgent). Enforcement technologies that use X.509 certificates may not function properly without this service localSystem Normal No attempts to start the service have been made since the last boot (1077)
Human Interface Device Access hidserv Running Automatic Share Process Stop, Shutdown, Session Change C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted Enables generic input access to Human Interface Devices (HID), which activates and maintains the use of predefined hot buttons on keyboards, remote controls, and other multimedia devices. If this service is stopped, hot buttons controlled by this service will no longer function. If this service is disabled, any services that explicitly depend on it will fail to start. LocalSystem Normal The operation completed successfully (0)
IKE and AuthIP IPsec Keying Modules IKEEXT Running Automatic Share Process Stop, Shutdown, Power Event C:\Windows\system32\svchost.exe -k netsvcs The IKEEXT service hosts the Internet Key Exchange (IKE) and Authenticated Internet Protocol (AuthIP) keying modules. These keying modules are used for authentication and key exchange in Internet Protocol security (IPsec). Stopping or disabling the IKEEXT service will disable IKE and AuthIP key exchange with peer computers. IPsec is typically configured to use IKE or AuthIP; therefore, stopping or disabling the IKEEXT service might result in an IPsec failure and might compromise the security of the system. It is strongly recommended that you have the IKEEXT service running. LocalSystem Normal The operation completed successfully (0)
Interactive Services Detection UI0Detect Stopped Manual Own Process (Interactive) C:\Windows\system32\UI0Detect.exe Enables user notification of user input for interactive services, which enables access to dialogs created by interactive services when they appear. If this service is stopped, notifications of new interactive service dialogs will no longer function and there may no longer be access to interactive service dialogs. If this service is disabled, both notifications of and access to new interactive service dialogs will no longer function. LocalSystem Normal No attempts to start the service have been made since the last boot (1077)
Internet Connection Sharing (ICS) SharedAccess Stopped Disabled Share Process C:\Windows\System32\svchost.exe -k netsvcs Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network. LocalSystem Normal No attempts to start the service have been made since the last boot (1077)
IP Helper iphlpsvc Running Automatic Share Process Stop, Shutdown, Param Change C:\Windows\System32\svchost.exe -k NetSvcs Provides automatic IPv6 connectivity over an IPv4 network. If this service is stopped, the machine will only have IPv6 connectivity if it is connected to a native IPv6 network. LocalSystem Normal The operation completed successfully (0)
IPsec Policy Agent PolicyAgent Running Automatic Share Process Stop, Shutdown C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted Internet Protocol security (IPsec) supports network-level peer authentication, data origin authentication, data integrity, data confidentiality (encryption), and replay protection. This service enforces IPsec policies created through the IP Security Policies snap-in or the command-line tool "netsh ipsec". If you stop this service, you may experience network connectivity issues if your policy requires that connections use IPsec. Also,remote management of Windows Firewall is not available when this service is stopped. NT Authority\NetworkService Normal The operation completed successfully (0)
KtmRm for Distributed Transaction Coordinator KtmRm Running Automatic Share Process Stop C:\Windows\System32\svchost.exe -k NetworkService Coordinates transactions between MSDTC and the Kernel Transaction Manager (KTM). NT AUTHORITY\NetworkService Normal The operation completed successfully (0)
LightScribeService Direct Disc Labeling Service LightScribeService Running Automatic Own Process Stop "C:\Program Files\Common Files\LightScribe\LSSrvc.exe" Used by the LightScribe software components to support 3rd party disc labeling applications using the LightScribe COM Application Programming Interface (LSCAPI). This service needs to run for LightScribe direct disc labeling to work. LocalSystem Ignore The operation completed successfully (0)
Link-Layer Topology Discovery Mapper lltdsvc Stopped Manual Share Process C:\Windows\System32\svchost.exe -k LocalService Creates a Network Map, consisting of PC and device topology (connectivity) information, and metadata describing each PC and device. If this service is disabled, the Network Map will not function properly. NT AUTHORITY\LocalService Normal No attempts to start the service have been made since the last boot (1077)
Machine Debug Manager MDM Running Automatic Own Process (Interactive) Stop "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE" Supports local and remote debugging for Visual Studio and script debuggers. If this service is stopped, the debuggers will not function properly. LocalSystem Normal The operation completed successfully (0)
Microsoft .NET Framework NGEN v2.0.50727_X86 clr_optimization_v2.0.50727_32 Stopped Disabled Own Process C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe Microsoft .NET Framework NGEN LocalSystem Ignore No attempts to start the service have been made since the last boot (1077)
Microsoft .NET Framework NGEN v4.0.30319_X86 clr_optimization_v4.0.30319_32 Stopped Automatic Own Process C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe Microsoft .NET Framework NGEN LocalSystem Ignore The operation completed successfully (0)
Microsoft Antimalware Service MsMpSvc Running Automatic Own Process Stop, Shutdown, Power Event, Session Change "C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe" Helps protect users from malware and other potentially unwanted software LocalSystem COM Infrastructure Normal The operation completed successfully (0)
Microsoft iSCSI Initiator Service MSiSCSI Stopped Manual Share Process C:\Windows\system32\svchost.exe -k netsvcs Manages Internet SCSI (iSCSI) sessions from this computer to remote iSCSI target devices. If this service is stopped, this computer will not be able to login or access iSCSI targets. If this service is disabled, any services that explicitly depend on it will fail to start. LocalSystem iSCSI Normal No attempts to start the service have been made since the last boot (1077)
Microsoft Network Inspection NisSrv Running Manual Own Process Stop, Shutdown "C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe" Helps guard against intrusion attempts targeting known and newly discovered vulnerabilities in network protocols NT AUTHORITY\LocalService Normal The operation completed successfully (0)
Microsoft Software Shadow Copy Provider swprv Stopped Manual Own Process C:\Windows\System32\svchost.exe -k swprv Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabled, any services that explicitly depend on it will fail to start. LocalSystem Normal The operation completed successfully (0)
Multimedia Class Scheduler MMCSS Running Automatic Share Process Stop, Session Change C:\Windows\system32\svchost.exe -k netsvcs Enables relative prioritization of work based on system-wide task priorities. This is intended mainly for multimedia applications. If this service is stopped, individual tasks resort to their default priority. LocalSystem Normal The operation completed successfully (0)
Net.Tcp Port Sharing Service NetTcpPortSharing Stopped Disabled Share Process "C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe" Provides ability to share TCP ports over the net.tcp protocol. NT AUTHORITY\LocalService Normal No attempts to start the service have been made since the last boot (1077)
Netlogon Netlogon Stopped Manual Share Process C:\Windows\system32\lsass.exe Maintains a secure channel between this computer and the domain controller for authenticating users and services. If this service is stopped, the computer may not authenticate users and services and the domain controller cannot register DNS records. If this service is disabled, any services that explicitly depend on it will fail to start. LocalSystem MS_WindowsRemoteValidation Normal No attempts to start the service have been made since the last boot (1077)
Network Access Protection Agent napagent Stopped Manual Share Process C:\Windows\System32\svchost.exe -k NetworkService Enables Network Access Protection (NAP) functionality on client computers NT AUTHORITY\NetworkService Normal No attempts to start the service have been made since the last boot (1077)
Network Connections Netman Running Manual Share Process Stop, Session Change C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections. LocalSystem Normal The operation completed successfully (0)
Network List Service netprofm Running Automatic Share Process Stop, Shutdown, Session Change C:\Windows\System32\svchost.exe -k LocalService Identifies the networks to which the computer has connected, collects and stores properties for these networks, and notifies applications when these properties change. NT AUTHORITY\LocalService Normal The operation completed successfully (0)
Network Location Awareness NlaSvc Running Automatic Share Process Stop, Shutdown, Session Change C:\Windows\System32\svchost.exe -k NetworkService Collects and stores configuration information for the network and notifies programs when this information is modified. If this service is stopped, configuration information might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. NT AUTHORITY\NetworkService Normal The operation completed successfully (0)
Network Store Interface Service nsi Running Automatic Share Process Stop, Shutdown C:\Windows\system32\svchost.exe -k LocalService This service delivers network notifications (e.g. interface addition/deleting etc) to user mode clients. Stopping this service will cause loss of network connectivity. If this service is disabled, any other services that explicitly depend on this service will fail to start. NT Authority\LocalService Normal The operation completed successfully (0)
NVIDIA Display Driver Service nvsvc Running Automatic Own Process Stop, Session Change C:\Windows\system32\nvvsvc.exe Provides system and desktop level support to the NVIDIA display driver LocalSystem Video Normal The operation completed successfully (0)
Office Source Engine ose Stopped Manual Own Process "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE" Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports. LocalSystem Normal No attempts to start the service have been made since the last boot (1077)
Parental Controls WPCSvc Stopped Manual Share Process C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted This service enables Windows Parental Controls on the system. If this service is not running, Parental controls will not work. NT Authority\LocalService Normal No attempts to start the service have been made since the last boot (1077)
Peer Name Resolution Protocol PNRPsvc Stopped Manual Share Process C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted Enables Serverless Peer Name Resolution over the Internet. If disabled, some Peer to Peer and Collaborative applications, such as Windows Meetings, may not function NT AUTHORITY\LocalService Normal No attempts to start the service have been made since the last boot (1077)
Peer Networking Grouping p2psvc Stopped Manual Share Process C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted Provides Peer Networking Grouping services NT AUTHORITY\LocalService Normal No attempts to start the service have been made since the last boot (1077)
Peer Networking Identity Manager p2pimsvc Stopped Manual Share Process C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted Provides Identity service for Peer Networking NT AUTHORITY\LocalService Normal No attempts to start the service have been made since the last boot (1077)
Performance Logs & Alerts pla Stopped Manual Share Process C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork Performance Logs and Alerts Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. If this service is disabled, any services that explicitly depend on it will fail to start. NT AUTHORITY\LocalService Normal No attempts to start the service have been made since the last boot (1077)
Plug and Play PlugPlay Running Automatic Share Process Shutdown, Session Change C:\Windows\system32\svchost.exe -k DcomLaunch Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability. LocalSystem PlugPlay Normal The operation completed successfully (0)
PnP-X IP Bus Enumerator IPBusEnum Stopped Manual Share Process C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted The PnP-X bus enumerator service manages the virtual network bus. It discovers network connected devices using the SSDP/WS discovery protocols and gives them presence in PnP. If this service is stopped or disabled, presence of NCD devices will not be maintained in PnP. All pnpx based scenarios will stop functioning. LocalSystem Normal No attempts to start the service have been made since the last boot (1077)
PNRP Machine Name Publication Service PNRPAutoReg Stopped Manual Share Process C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted This service publishes a machine name using the Peer Name Resolution Protocol. Configuration is managed via the netsh context 'p2p pnrp peer' NT AUTHORITY\LocalService Normal No attempts to start the service have been made since the last boot (1077)
Portable Device Enumerator Service WPDBusEnum Running Automatic Share Process Stop, Power Event, Session Change C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted Enforces group policy for removable mass-storage devices. Enables applications such as Windows Media Player and Image Import Wizard to transfer and synchronize content using removable mass-storage devices. LocalSystem Normal The operation completed successfully (0)
Print Spooler Spooler Running Automatic Own Process (Interactive) Stop, Shutdown, Power Event, Session Change C:\Windows\System32\spoolsv.exe Loads files to memory for later printing LocalSystem SpoolerGroup Normal The operation completed successfully (0)
Problem Reports and Solutions Control Panel Support wercplsupport Stopped Manual Share Process C:\Windows\System32\svchost.exe -k netsvcs This service provides support for viewing, sending and deletion of system-level problem reports for the Problem Reports and Solutions control panel. localSystem Normal The operation completed successfully (0)
Process Monitor LVPrcSrv Running Automatic Own Process Stop "C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe" Injector service LocalSystem Normal The operation completed successfully (0)
Program Compatibility Assistant Service PcaSvc Running Automatic Share Process Stop C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted Provides support for the Program Compatibility Assistant. If this service is stopped, the Program Compatibility Assistant will not function properly. If this service is disabled, any services that depend on it will fail to start. LocalSystem Normal The operation completed successfully (0)
Protected Storage ProtectedStorage Running Manual Share Process Stop C:\Windows\system32\lsass.exe Provides protected storage for sensitive data, such as passwords, to prevent access by unauthorized services, processes, or users. LocalSystem Normal The operation completed successfully (0)
Quality Windows Audio Video Experience QWAVE Stopped Manual Share Process C:\Windows\system32\svchost.exe -k LocalService Quality Windows Audio Video Experience (qWave) is a networking platform for Audio Video (AV) streaming applications on IP home networks. qWave enhances AV streaming performance and reliability by ensuring network quality-of-service (QoS) for AV applications. It provides mechanisms for admission control, run time monitoring and enforcement, application feedback, and traffic prioritization. NT AUTHORITY\LocalService Normal No attempts to start the service have been made since the last boot (1077)
ReadyBoost EMDMgmt Running Automatic Share Process Stop, Shutdown, Power Event C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted Provides support for improving system performance using ReadyBoost. LocalSystem Ignore The operation completed successfully (0)
Remote Access Auto Connection Manager RasAuto Stopped Manual Share Process C:\Windows\system32\svchost.exe -k netsvcs Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address. localSystem Normal No attempts to start the service have been made since the last boot (1077)
Remote Access Connection Manager RasMan Running Manual Share Process Shutdown, Power Event, Session Change C:\Windows\system32\svchost.exe -k netsvcs Manages dial-up and virtual private network (VPN) connections from this computer to the Internet or other remote networks. If this service is disabled, any services that explicitly depend on it will fail to start. localSystem Normal The operation completed successfully (0)
Remote Procedure Call (RPC) RpcSs Running Automatic Share Process Power Event C:\Windows\system32\svchost.exe -k rpcss Serves as the endpoint mapper and COM Service Control Manager. If this service is stopped or disabled, programs using COM or Remote Procedure Call (RPC) services will not function properly. NT AUTHORITY\NetworkService COM Infrastructure Normal The operation completed successfully (0)
Remote Procedure Call (RPC) Locator RpcLocator Stopped Manual Own Process C:\Windows\system32\locator.exe Manages the RPC name service database. NT AUTHORITY\NetworkService Normal No attempts to start the service have been made since the last boot (1077)
Remote Registry RemoteRegistry Stopped Manual Share Process C:\Windows\system32\svchost.exe -k regsvc Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start. NT AUTHORITY\LocalService Normal No attempts to start the service have been made since the last boot (1077)
Routing and Remote Access RemoteAccess Stopped Disabled Share Process C:\Windows\system32\svchost.exe -k netsvcs Offers routing services to businesses in local area and wide area network environments. localSystem Normal No attempts to start the service have been made since the last boot (1077)
Secondary Logon seclogon Running Automatic Share Process Stop, Pause/Continue, Session Change C:\Windows\system32\svchost.exe -k netsvcs Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. LocalSystem Normal The operation completed successfully (0)
Secure Socket Tunneling Protocol Service SstpSvc Running Manual Share Process Stop C:\Windows\system32\svchost.exe -k LocalService Provides support for the Secure Socket Tunneling Protocol (SSTP) to connect to remote computers using VPN. If this service is disabled, users will not be able to use SSTP to access remote servers. NT Authority\LocalService Normal The operation completed successfully (0)
Security Accounts Manager SamSs Running Automatic Share Process C:\Windows\system32\lsass.exe The startup of this service signals other services that the Security Accounts Manager (SAM) is ready to accept requests. Disabling this service will prevent other services in the system from being notified when the SAM is ready, which may in turn cause those services to fail to start correctly. This service should not be disabled. LocalSystem MS_WindowsLocalValidation Normal The operation completed successfully (0)
Security Center wscsvc Running Automatic Share Process Stop, Shutdown, Session Change C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted Monitors system security settings and configurations. NT AUTHORITY\LocalService Normal The operation completed successfully (0)
Server LanmanServer Running Automatic Share Process Stop, Pause/Continue, Shutdown C:\Windows\system32\svchost.exe -k netsvcs Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. LocalSystem Normal The operation completed successfully (0)
Shell Hardware Detection ShellHWDetection Running Automatic Share Process Stop, Shutdown, Session Change C:\Windows\System32\svchost.exe -k netsvcs Provides notifications for AutoPlay hardware events. LocalSystem ShellSvcGroup Ignore The operation completed successfully (0)
SL UI Notification Service SLUINotify Stopped Manual Share Process C:\Windows\system32\svchost.exe -k LocalService Provides Software Licensing activation and notification NT AUTHORITY\LocalService Normal No attempts to start the service have been made since the last boot (1077)
Smart Card SCardSvr Stopped Manual Share Process C:\Windows\system32\svchost.exe -k LocalService Manages access to smart cards read by this computer. If this service is stopped, this computer will be unable to read smart cards. If this service is disabled, any services that explicitly depend on it will fail to start. NT AUTHORITY\LocalService SmartCardGroup Normal No attempts to start the service have been made since the last boot (1077)
Smart Card Removal Policy SCPolicySvc Stopped Manual Share Process C:\Windows\system32\svchost.exe -k netsvcs Allows the system to be configured to lock the user desktop upon smart card removal. LocalSystem Normal No attempts to start the service have been made since the last boot (1077)
SNMP Trap SNMPTRAP Stopped Manual Own Process C:\Windows\System32\snmptrap.exe Receives trap messages generated by local or remote Simple Network Management Protocol (SNMP) agents and forwards the messages to SNMP management programs running on this computer. If this service is stopped, SNMP-based programs on this computer will not receive SNMP trap messages. If this service is disabled, any services that explicitly depend on it will fail to start. NT AUTHORITY\LocalService Normal No attempts to start the service have been made since the last boot (1077)
Software Licensing slsvc Running Automatic Own Process Stop, Shutdown C:\Windows\system32\SLsvc.exe Enables the download, installation and enforcement of digital licenses for Windows and Windows applications. If the service is disabled, the operating system and licensed applications may run in a notification mode. NT AUTHORITY\NetworkService ProfSvc_Group Normal The operation completed successfully (0)
SSDP Discovery SSDPSRV Running Manual Share Process Stop, Shutdown C:\Windows\system32\svchost.exe -k LocalService Discovers networked devices and services that use the SSDP discovery protocol, such as UPnP devices. Also announces SSDP devices and services running on the local computer. If this service is stopped, SSDP-based devices will not be discovered. If this service is disabled, any services that explicitly depend on it will fail to start. NT AUTHORITY\LocalService Normal The operation completed successfully (0)
Superfetch SysMain Running Automatic Share Process Stop, Shutdown, Power Event, Session Change C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted Maintains and improves system performance over time. LocalSystem Ignore The operation completed successfully (0)
System Event Notification Service SENS Running Automatic Share Process Stop, Power Event C:\Windows\system32\svchost.exe -k netsvcs Monitors system events and notifies subscribers to COM+ Event System of these events. LocalSystem ProfSvc_Group Normal The operation completed successfully (0)
Tablet PC Input Service TabletInputService Running Automatic Share Process Stop, Shutdown, Session Change C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted Enables Tablet PC pen and ink functionality LocalSystem PlugPlay Normal The operation completed successfully (0)
Task Scheduler Schedule Running Automatic Share Process Stop, Shutdown, Power Event, Session Change C:\Windows\system32\svchost.exe -k netsvcs Enables a user to configure and schedule automated tasks on this computer. If this service is stopped, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start. LocalSystem SchedulerGroup Normal The operation completed successfully (0)
TCP/IP NetBIOS Helper lmhosts Running Automatic Share Process Stop C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted Provides support for the NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution for clients on the network, therefore enabling users to share files, print, and log on to the network. If this service is stopped, these functions might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. NT AUTHORITY\LocalService TDI Normal The operation completed successfully (0)
Telephony TapiSrv Running Manual Share Process Stop, Pause/Continue C:\Windows\System32\svchost.exe -k NetworkService Provides Telephony API (TAPI) support for programs that control telephony devices on the local computer and, through the LAN, on servers that are also running the service. NT AUTHORITY\NetworkService Normal The operation completed successfully (0)
Terminal Services TermService Running Automatic Share Process Stop C:\Windows\System32\svchost.exe -k NetworkService Allows users to connect interactively to a remote computer. Remote Desktop and Terminal Server depend on this service. To prevent remote use of this computer, clear the checkboxes on the Remote tab of the System properties control panel item. NT Authority\NetworkService Normal The operation completed successfully (0)
Terminal Services Configuration SessionEnv Stopped Manual Share Process C:\Windows\System32\svchost.exe -k netsvcs Terminal Services Configuration service (TSCS) is responsible for all Terminal Services and Remote Desktop related configuration and session maintenance activities that require SYSTEM context. These include per-session temporary folders, TS themes, and TS certificates. localSystem Normal No attempts to start the service have been made since the last boot (1077)
Themes Themes Running Automatic Share Process Stop, Shutdown C:\Windows\System32\svchost.exe -k netsvcs Provides user experience theme management. LocalSystem ProfSvc_Group Normal The operation completed successfully (0)
Thread Ordering Server THREADORDER Stopped Manual Share Process C:\Windows\system32\svchost.exe -k LocalService Provides ordered execution for a group of threads within a specific period of time. NT AUTHORITY\LocalService Normal No attempts to start the service have been made since the last boot (1077)
TPM Base Services TBS Stopped Automatic Share Process C:\Windows\System32\svchost.exe -k LocalService Enables access to the Trusted Platform Module (TPM), which provides hardware-based cryptographic services to system components and applications. If this service is stopped or disabled, applications will be unable to use keys protected by the TPM. NT AUTHORITY\LocalService Normal The operation completed successfully (0)
UPnP Device Host upnphost Running Automatic Share Process Stop, Shutdown C:\Windows\system32\svchost.exe -k LocalService Allows UPnP devices to be hosted on this computer. If this service is stopped, any hosted UPnP devices will stop functioning and no additional hosted devices can be added. If this service is disabled, any services that explicitly depend on it will fail to start. NT AUTHORITY\LocalService Normal The operation completed successfully (0)
User Profile Service ProfSvc Running Automatic Share Process Stop, Shutdown C:\Windows\system32\svchost.exe -k netsvcs This service is responsible for loading and unloading user profiles. If this service is stopped or disabled, users will no longer be able to successfully logon or logoff, applications may have problems getting to users' data, and components registered to receive profile event notifications will not receive them. LocalSystem ProfSvc_Group Normal The operation completed successfully (0)
Virtual Disk vds Stopped Manual Own Process C:\Windows\System32\vds.exe Provides management services for disks, volumes, file systems, and storage arrays. LocalSystem Normal No attempts to start the service have been made since the last boot (1077)
Volume Shadow Copy VSS Stopped Manual Own Process C:\Windows\system32\vssvc.exe Manages and implements Volume Shadow Copies used for backup and other purposes. If this service is stopped, shadow copies will be unavailable for backup and the backup may fail. If this service is disabled, any services that explicitly depend on it will fail to start. LocalSystem Normal The operation completed successfully (0)
WebClient WebClient Running Automatic Share Process Stop, Shutdown C:\Windows\system32\svchost.exe -k LocalService Enables Windows-based programs to create, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start. NT AUTHORITY\LocalService NetworkProvider Normal The operation completed successfully (0)
Windows Audio Audiosrv Running Automatic Share Process Stop, Shutdown, Power Event, Session Change C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted Manages audio for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start NT AUTHORITY\LocalService AudioGroup Normal The operation completed successfully (0)
Windows Audio Endpoint Builder AudioEndpointBuilder Running Automatic Share Process Stop, Shutdown, Power Event, Session Change C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted Manages audio devices for the Windows Audio service. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start LocalSystem AudioGroup Normal The operation completed successfully (0)
Windows Backup SDRSVC Stopped Manual Own Process C:\Windows\system32\svchost.exe -k SDRSVC Provides Windows Backup and Restore capabilities. localSystem Normal No attempts to start the service have been made since the last boot (1077)
Windows CardSpace idsvc Stopped Manual Share Process "C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe" Securely enables the creation, management, and disclosure of digital identities. LocalSystem Normal No attempts to start the service have been made since the last boot (1077)
Windows Color System WcsPlugInService Stopped Manual Share Process C:\Windows\system32\svchost.exe -k wcssvc The WcsPlugInService service hosts third-party Windows Color System color device model and gamut map model plug-in modules. These plug-in modules are vendor-specific extensions to the Windows Color System baseline color device and gamut map models. Stopping or disabling the WcsPlugInService service will disable this extensibility feature, and the Windows Color System will use its baseline model processing rather than the vendor's desired processing. This might result in inaccurate color rendering. NT AUTHORITY\LocalService Normal No attempts to start the service have been made since the last boot (1077)
Windows Connect Now - Config Registrar wcncsvc Stopped Manual Share Process C:\Windows\System32\svchost.exe -k LocalService Act as a Registrar, issues network credential to Enrollee. If this service is disabled, the Windows Connect Now - Config Registrar will not function properly. NT AUTHORITY\LocalService Normal No attempts to start the service have been made since the last boot (1077)
Windows Defender WinDefend Stopped Automatic Share Process C:\Windows\System32\svchost.exe -k secsvcs Scan your computer for unwanted software, schedule scans, and get the latest unwanted software definitions. LocalSystem COM Infrastructure Normal The operation completed successfully (0)
Windows Driver Foundation - User-mode Driver Framework wudfsvc Running Automatic Share Process C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted Manages user-mode driver host processes LocalSystem PlugPlay Normal The operation completed successfully (0)
Windows Error Reporting Service WerSvc Running Automatic Share Process Stop, Pause/Continue, Session Change C:\Windows\System32\svchost.exe -k WerSvcGroup Allows errors to be reported when programs stop working or responding and allows existing solutions to be delivered. Also allows logs to be generated for diagnostic and repair services. If this service is stopped, error reporting might not work correctly and results of diagnostic services and repairs might not be displayed. localSystem Ignore The operation completed successfully (0)
Windows Event Collector Wecsvc Stopped Manual Share Process C:\Windows\system32\svchost.exe -k NetworkService This service manages persistent subscriptions to events from remote sources that support WS-Management protocol. This includes Windows Vista event logs, hardware and IPMI-enabled event sources. The service stores forwarded events in a local Event Log. If this service is stopped or disabled event subscriptions cannot be created and forwarded events cannot be accepted. NT AUTHORITY\NetworkService Normal No attempts to start the service have been made since the last boot (1077)
Windows Event Log Eventlog Running Automatic Share Process Stop, Shutdown C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted This service manages events and event logs. It supports logging events, querying events, subscribing to events, archiving event logs, and managing event metadata. It can display events in both XML and plain text format. Stopping this service may compromise security and reliability of the system. NT AUTHORITY\LocalService Event Log Normal The operation completed successfully (0)
Windows Firewall MpsSvc Running Automatic Share Process Stop C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork Windows Firewall helps protect your computer by preventing unauthorized users from gaining access to your computer through the Internet or a network. NT Authority\LocalService NetworkProvider Normal The operation completed successfully (0)
Windows Font Cache Service FontCache Running Automatic Share Process Stop, Shutdown C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation Optimizes performance of applications by caching commonly used font data. Applications will start this service if it is not already running. It can be disabled, though doing so will degrade application performance. NT AUTHORITY\LocalService Normal The operation completed successfully (0)
Windows Image Acquisition (WIA) stisvc Running Automatic Own Process Stop, Pause/Continue, Shutdown, Param Change, Power Event C:\Windows\system32\svchost.exe -k imgsvc Provides image acquisition services for scanners and cameras NT Authority\LocalService Normal The operation completed successfully (0)
Windows Installer msiserver Stopped Manual Own Process C:\Windows\system32\msiexec /V Adds, modifies, and removes applications provided as a Windows Installer (*.msi) package. If this service is disabled, any services that explicitly depend on it will fail to start. LocalSystem Normal No attempts to start the service have been made since the last boot (1077)
Windows Management Instrumentation Winmgmt Running Automatic Share Process Stop, Pause/Continue, Shutdown C:\Windows\system32\svchost.exe -k netsvcs Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. localSystem Ignore The operation completed successfully (0)
Windows Media Center Extender Service Mcx2Svc Stopped Disabled Share Process C:\Windows\system32\svchost.exe -k LocalService Allows Windows Media Center Extender devices to locate and connect to the computer. NT Authority\LocalService Normal No attempts to start the service have been made since the last boot (1077)
Windows Media Center Receiver Service ehRecvr Stopped Manual Own Process C:\Windows\ehome\ehRecvr.exe Windows Media Center Service for TV and FM broadcast reception NT AUTHORITY\networkService Ignore No attempts to start the service have been made since the last boot (1077)
Windows Media Center Scheduler Service ehSched Stopped Manual Own Process C:\Windows\ehome\ehsched.exe Starts and stops recording of TV programs within Windows Media Center NT AUTHORITY\networkService Ignore No attempts to start the service have been made since the last boot (1077)
Windows Media Center Service Launcher ehstart Stopped Automatic Share Process C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork Starts Windows Media Center Scheduler and Windows Media Center Receiver services at startup if TV is enabled within Windows Media Center. NT AUTHORITY\LocalService Ignore The operation completed successfully (0)
Windows Media Player Network Sharing Service WMPNetworkSvc Running Manual Own Process Stop "C:\Program Files\Windows Media Player\wmpnetwk.exe" Shares Windows Media Player libraries to other networked players and media devices using Universal Plug and Play NT AUTHORITY\NetworkService Normal The operation completed successfully (0)
Windows Modules Installer TrustedInstaller Stopped Manual Own Process C:\Windows\servicing\TrustedInstaller.exe Enables installation, modification, and removal of Windows updates and optional components. If this service is disabled, install or uninstall of Windows updates might fail for this computer. localSystem ProfSvc_Group Normal The operation completed successfully (0)
Windows Presentation Foundation Font Cache 3.0.0.0 FontCache3.0.0.0 Stopped Manual Own Process C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe Optimizes performance of Windows Presentation Foundation (WPF) applications by caching commonly used font data. WPF applications will start this service if it is not already running. It can be disabled, though doing so will degrade the performance of WPF applications. NT Authority\LocalService Normal No attempts to start the service have been made since the last boot (1077)
Windows Presentation Foundation Font Cache 4.0.0.0 WPFFontCache_v0400 Stopped Manual Own Process C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe Optimizes performance of Windows Presentation Foundation (WPF) applications by caching commonly used font data. WPF applications will start this service if it is not already running. It can be disabled, though doing so will degrade the performance of WPF applications. NT AUTHORITY\LocalService Normal No attempts to start the service have been made since the last boot (1077)
Windows Remote Management (WS-Management) WinRM Stopped Manual Share Process C:\Windows\System32\svchost.exe -k NetworkService Windows Remote Management (WinRM) service implements the WS-Management protocol for remote management. WS-Management is a standard web services protocol used for remote software and hardware management. The WinRM service listens on the network for WS-Management requests and processes them. The WinRM Service needs to be configured with a listener using winrm.cmd command line tool or through Group Policy in order for it to listen over the network. The WinRM service provides access to WMI data and enables event collection. Event collection and subscription to events require that the service is running. WinRM messages use HTTP and HTTPS as transports. The WinRM service does not depend on IIS but is preconfigured to share a port with IIS on the same machine. The WinRM service reserves the /wsman URL prefix. To prevent conflicts with IIS, administrators should ensure that any websites hosted on IIS do not use the /wsman URL prefix. NT AUTHORITY\NetworkService Normal No attempts to start the service have been made since the last boot (1077)
Windows Search WSearch Stopped Automatic Own Process C:\Windows\system32\SearchIndexer.exe /Embedding Provides content indexing and property caching for file, email and other content (via extensibility APIs). The service responds to file and email notifications to index modified content. If the service is stopped or disabled, the Explorer will not be able to display virtual folder views of items, and search in the Explorer will fall back to item-by-item slow search. LocalSystem Normal The operation completed successfully (0)
Windows Time W32Time Running Automatic Share Process Stop, Shutdown, Param Change, Net Bind Change, Hardware Profile Change, Power Event C:\Windows\system32\svchost.exe -k LocalService Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. NT AUTHORITY\LocalService Normal The operation completed successfully (0)
Windows Update wuauserv Running Automatic Share Process Stop, Shutdown, Power Event, Session Change C:\Windows\system32\svchost.exe -k netsvcs Enables the detection, download, and installation of updates for Windows and other programs. If this service is disabled, users of this computer will not be able to use Windows Update or its automatic updating feature, and programs will not be able to use the Windows Update Agent (WUA) API. LocalSystem Normal The operation completed successfully (0)
WinHTTP Web Proxy Auto-Discovery Service WinHttpAutoProxySvc Stopped Manual Share Process C:\Windows\system32\svchost.exe -k LocalService WinHTTP implements the client HTTP stack and provides developers with a Win32 API and COM Automation component for sending HTTP requests and receiving responses. In addition, WinHTTP provides support for auto-discovering a proxy configuration via its implementation of the Web Proxy Auto-Discovery (WPAD) protocol. NT AUTHORITY\LocalService Normal The operation completed successfully (0)
Wired AutoConfig dot3svc Stopped Manual Share Process C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted This service performs IEEE 802.1X authentication on Ethernet interfaces localSystem TDI Normal No attempts to start the service have been made since the last boot (1077)
WLAN AutoConfig Wlansvc Running Automatic Share Process Stop, Shutdown, Power Event, Session Change C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted This service enumerates WLAN adapters, manages WLAN connections and profiles. LocalSystem TDI Normal The operation completed successfully (0)
WMI Performance Adapter wmiApSrv Stopped Manual Own Process C:\Windows\system32\wbem\WmiApSrv.exe Provides performance library information from Windows Management Instrumentation (WMI) providers to clients on the network. This service only runs when Performance Data Helper is activated. localSystem Normal No attempts to start the service have been made since the last boot (1077)
Workstation LanmanWorkstation Running Automatic Share Process Stop, Pause/Continue, Shutdown, Power Event C:\Windows\System32\svchost.exe -k LocalService Creates and maintains client network connections to remote servers using the SMB protocol. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. NT AUTHORITY\LocalService NetworkProvider Normal The operation completed successfully (0)
  • 0

Advertisements


#26
chipper1

chipper1

    Member

  • Topic Starter
  • Member
  • PipPip
  • 80 posts
ok

Attached Files


  • 0

#27
Ztruker

Ztruker

    Member 5k

  • Technician
  • 7,091 posts
Thanks, the last one is readable but it's only the services tab. Also need Startup and Processes tab, which I should have mentioned before. At least now you now how to do it :whistling:

I see you are using Microsoft Security Essentials for anti-virus, which is a good choice. Please open it (right click on the MSE icon in the Taskbar and select Open) then click on Scan.
  • 0

#28
chipper1

chipper1

    Member

  • Topic Starter
  • Member
  • PipPip
  • 80 posts

Thanks, the last one is readable but it's only the services tab. Also need Startup and Processes tab, which I should have mentioned before. At least now you now how to do it :whistling:

I see you are using Microsoft Security Essentials for anti-virus, which is a good choice. Please open it (right click on the MSE icon in the Taskbar and select Open) then click on Scan.


Name Value Section Enabled Description Company
Adobe ARM "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" Registry - Machine Run 1 Adobe Reader and Acrobat Manager Adobe Systems Incorporated
Adobe Reader Speed Launcher "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" Registry - Machine Run 1 Adobe Acrobat SpeedLauncher (Adobe Acrobat) Adobe Systems Incorporated
MSC "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey Registry - Machine Run 1 Microsoft Security Client User Interface (Microsoft Security Client) Microsoft Corporation
TkBellExe "C:\Program Files\Real\RealPlayer\update\realsched.exe" -osboot Registry - Machine Run 1 RealNetworks Scheduler (RealPlayer (32-bit) ) RealNetworks, Inc.
WMPNSCFG C:\Program Files\Windows Media Player\WMPNSCFG.exe Registry - User Run 1 Windows Media Player Network Sharing Service Configuration Application (Microsoft® Windows® Operating System) Microsoft Corporation

Generated by CodeStuff Starter. http://CodeStuff.mirrorz.com


Process PID Mem usage Executable Priority Page fault count Mem usage (peak) Paged pool (peak) Paged pool Nonpaged pool (peak) Nonpaged pool Pagefile (peak) Pagefile
Idle 0
System 4 00 (Normal)
RichVideo.exe 292 61,440 C:\Program Files\CyberLink\Shared Files\RichVideo.exe 20 (Normal)* 1,546 3,891,200 111,040 109,312 3,072 2,488 1,216,512 1,179,648
eDSService.exe 436 118,784 C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe 20 (Normal)* 3,531 6,344,704 110,160 104,888 4,736 3,736 2,654,208 1,802,240
smss.exe 444 53,248 C:\Windows\System32\smss.exe 20 (Normal)* 430 786,432 31,456 8,792 4,992 720 344,064 303,104
MemCheck.exe 460 1,024,000 C:\Acer\Empowering Technology\ePerformance\MemCheck.exe 20 (Normal)* 74,009 11,177,984 186,176 185,072 7,020 6,532 18,329,600 18,264,064
csrss.exe 512 1,593,344 C:\Windows\system32\csrss.exe 20 (Normal)* 16,763 5,144,576 249,272 229,720 5,792 5,352 2,240,512 2,240,512
wininit.exe 564 69,632 C:\Windows\system32\wininit.exe 80 (High)* 1,780 4,218,880 117,800 96,336 7,856 4,448 1,548,288 1,396,736
services.exe 608 3,133,440 C:\Windows\system32\services.exe 20 (Normal)* 51,245 7,024,640 102,776 82,360 38,944 7,440 4,317,184 3,186,688
lsass.exe 620 3,125,248 C:\Windows\system32\lsass.exe 20 (Normal)* 118,099 7,548,928 113,976 110,880 15,328 11,424 3,878,912 3,727,360
lsm.exe 628 1,073,152 C:\Windows\system32\lsm.exe 20 (Normal)* 20,366 3,760,128 60,384 59,016 4,104 3,400 23,158,784 2,146,304
svchost.exe 816 2,658,304 C:\Windows\system32\svchost.exe 20 (Normal) 352,114 5,595,136 95,296 88,232 6,128 4,536 3,342,336 3,260,416
nvvsvc.exe 860 65,536 C:\Windows\system32\nvvsvc.exe 20 (Normal)* 1,923 3,342,336 78,304 71,784 3,680 2,560 1,249,280 1,228,800
MDM.EXE 880 491,520 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE 20 (Normal)* 10,143 4,349,952 110,920 109,608 3,312 2,728 1,552,384 1,552,384
svchost.exe 888 2,670,592 C:\Windows\system32\svchost.exe 20 (Normal) 45,946 5,713,920 93,240 92,856 8,912 8,336 4,071,424 3,948,544
MsMpEng.exe 928 42,434,560 C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe 20 (Normal) 10,624,549 258,068,480 248,200 160,048 44,280 18,560 426,524,672 94,773,248
wmpnetwk.exe 996 643,072 C:\Program Files\Windows Media Player\wmpnetwk.exe 20 (Normal) 18,038 8,581,120 185,704 183,104 10,720 7,456 6,230,016 6,053,888
svchost.exe 1084 4,317,184 C:\Windows\System32\svchost.exe 20 (Normal) 5,282,194 11,702,272 145,920 120,432 16,808 13,400 18,317,312 17,055,744
svchost.exe 1156 37,109,760 C:\Windows\System32\svchost.exe 20 (Normal) 1,065,012 74,661,888 201,840 162,232 18,992 16,064 82,100,224 51,138,560
svchost.exe 1168 10,366,976 C:\Windows\system32\svchost.exe 20 (Normal) 2,062,852 394,141,696 1,090,120 247,664 121,144 75,120 525,672,448 95,821,824
svchost.exe 1276 868,352 C:\Windows\system32\svchost.exe 20 (Normal)* 8,166 4,554,752 63,472 62,944 3,976 3,488 2,289,664 2,195,456
SLsvc.exe 1292 983,040 C:\Windows\system32\SLsvc.exe 20 (Normal) 16,127 16,035,840 91,744 90,704 3,888 3,008 13,606,912 6,291,456
svchost.exe 1336 4,870,144 C:\Windows\system32\svchost.exe 20 (Normal) 67,152 12,562,432 164,824 162,272 68,612 28,816 10,862,592 10,375,168
LVPrcSrv.exe 1452 1,437,696 C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe 20 (Normal)* 71,058 3,993,600 91,072 90,032 6,728 5,320 2,519,040 2,465,792
svchost.exe 1492 9,105,408 C:\Windows\system32\svchost.exe 20 (Normal) 162,571 21,106,688 165,840 161,456 30,172 23,096 42,344,448 28,590,080
LSSrvc.exe 1548 61,440 C:\Program Files\Common Files\LightScribe\LSSrvc.exe 20 (Normal)* 1,409 3,489,792 70,952 69,912 3,016 2,432 1,073,152 1,052,672
svchost.exe 1712 69,632 C:\Windows\system32\svchost.exe 20 (Normal) 4,272 8,871,936 124,680 123,640 8,136 6,504 5,935,104 5,042,176
spoolsv.exe 1752 991,232 C:\Windows\System32\spoolsv.exe 20 (Normal) 25,648 9,953,280 162,032 160,472 11,240 9,080 6,909,952 6,656,000
svchost.exe 1776 6,950,912 C:\Windows\system32\svchost.exe 20 (Normal) 158,711 43,790,336 119,656 113,528 28,160 25,056 54,112,256 17,219,584
chrome.exe 1796 116,703,232 C:\Users\neil\AppData\Local\Google\Chrome\Application\chrome.exe 20 (Normal) 8,906,977 172,802,048 203,408 185,856 49,440 25,480 190,488,576 114,311,168
svchost.exe 1816 94,208 C:\Windows\System32\svchost.exe 20 (Normal) 1,946 2,060,288 30,656 30,432 2,448 1,960 638,976 610,304
svchost.exe 1996 73,728 C:\Windows\system32\svchost.exe 20 (Normal) 3,518 5,775,360 83,344 82,304 8,592 7,112 2,387,968 2,330,624
WUDFHost.exe 2160 73,728 C:\Windows\system32\WUDFHost.exe 20 (Normal) 3,943 5,222,400 80,400 78,336 4,048 3,312 3,252,224 3,244,032
eRecoveryService.exe 2168 741,376 C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe 20 (Normal)* 18,426 11,792,384 163,968 157,696 7,740 7,252 16,035,840 15,990,784
NisSrv.exe 2524 73,728 C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe 20 (Normal) 7,383 17,494,016 112,272 110,320 9,296 7,328 14,249,984 7,200,768
taskeng.exe 2952 450,560 C:\Windows\system32\taskeng.exe 4000 (Below Normal) 9,689 5,521,408 120,160 112,536 5,216 4,568 2,191,360 2,113,536
svchost.exe 3524 69,632 C:\Windows\system32\svchost.exe 20 (Normal) 11,508 38,293,504 173,168 173,168 3,720 3,232 1,814,528 1,814,528
Starter.exe 3804 11,837,440 C:\Users\Public\Starter\Starter.exe 20 (Normal) 5,248 11,857,920 179,024 149,512 6,280 6,048 10,854,400 10,383,360
chrome.exe 4512 37,781,504 C:\Users\neil\AppData\Local\Google\Chrome\Application\chrome.exe 20 (Normal) 15,314 39,198,720 341,656 274,944 11,604 9,748 28,143,616 25,403,392
ehmsas.exe 5700 65,536 C:\Windows\ehome\ehmsas.exe 20 (Normal) 1,297 3,502,080 91,056 89,976 2,696 2,208 999,424 958,464
consent.exe 6292 5,259,264 C:\Windows\system32\consent.exe 80 (High) 1,802 5,419,008 155,184 124,296 4,192 4,000 2,764,800 2,666,496
chrome.exe 6304 13,594,624 C:\Users\neil\AppData\Local\Google\Chrome\Application\chrome.exe 20 (Normal) 3,036,177 52,559,872 272,664 257,360 13,792 9,504 61,087,744 19,070,976
csrss.exe 6464 4,874,240 C:\Windows\system32\csrss.exe 20 (Normal)* 62,058 10,514,432 345,016 288,536 8,464 8,320 6,119,424 6,066,176
winlogon.exe 6692 921,600 C:\Windows\system32\winlogon.exe 80 (High)* 4,056 6,799,360 118,864 91,976 7,136 3,448 3,133,440 2,088,960
Dwm.exe 6768 372,736 C:\Windows\system32\Dwm.exe 20 (Normal) 5,789 16,670,720 101,720 86,016 3,256 2,584 32,903,168 1,085,440
rundll32.exe 6784 360,448 C:\Windows\system32\rundll32.exe 20 (Normal)* 8,145 9,371,648 157,224 130,192 5,920 4,344 17,399,808 3,723,264
Explorer.EXE 7064 26,886,144 C:\Windows\Explorer.EXE 20 (Normal) 446,600 44,064,768 503,304 394,384 40,432 36,152 85,307,392 56,094,720
taskeng.exe 7080 3,358,720 C:\Windows\system32\taskeng.exe 20 (Normal) 28,226 21,446,656 172,936 159,560 10,104 9,056 40,423,424 10,047,488
rundll32.exe 7380 1,011,712 C:\Windows\system32\rundll32.exe 20 (Normal) 1,952 5,386,240 145,496 145,328 4,552 4,248 6,340,608 6,340,608
ehtray.exe 7476 372,736 C:\Windows\ehome\ehtray.exe 20 (Normal) 4,443 4,931,584 134,720 133,432 3,696 2,976 1,363,968 1,323,008
TeaTimer.exe 7488 1,810,432 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe 20 (Normal) 43,861 14,274,560 170,560 146,496 4,864 4,272 6,860,800 6,828,032
AdobeARM.exe 7532 479,232 C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe 20 (Normal) 8,495 17,514,496 166,704 165,592 8,224 7,592 9,256,960 5,021,696
wmpnscfg.exe 7564 413,696 C:\Program Files\Windows Media Player\wmpnscfg.exe 20 (Normal) 3,520 4,481,024 101,568 101,424 3,800 3,312 1,626,112 1,585,152
msseces.exe 7616 421,888 C:\Program Files\Microsoft Security Client\msseces.exe 20 (Normal) 7,670 11,173,888 150,864 149,872 8,376 7,888 7,049,216 6,987,776
chrome.exe 7836 66,789,376 C:\Users\neil\AppData\Local\Google\Chrome\Application\chrome.exe 20 (Normal) 10,953,540 78,290,944 535,480 446,024 134,992 43,512 116,158,464 98,992,128

Generated by CodeStuff Starter. http://CodeStuff.mirrorz.com
  • 0

#29
chipper1

chipper1

    Member

  • Topic Starter
  • Member
  • PipPip
  • 80 posts
Hope you got the most recent info. It frooze again today and had to turn off at the wall. I ran the whocrashed but it didnt give me a report for this one?
  • 0

#30
chipper1

chipper1

    Member

  • Topic Starter
  • Member
  • PipPip
  • 80 posts
I also tried to download anti freeze but it failed to install and said it Requires elevation?
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP