[size=3][color="blue"][b]~~~ Service Information report ~~~[/b][/color][/size] Microsoftr Windows VistaT Home Premium Service Pack 1 6.0.6001 12/19/2009 10:36:08 PM [color="red"][b]~~~Running Processes~~~[/b][/color] System Idle Process PID: 0 Path: Parent PID: 0 System PID: 4 Path: Parent PID: 0 smss.exe PID: 552 Path: Parent PID: 4 csrss.exe PID: 640 Path: C:\Windows\system32\csrss.exe Parent PID: 628 wininit.exe PID: 684 Path: C:\Windows\system32\wininit.exe Parent PID: 628 csrss.exe PID: 696 Path: C:\Windows\system32\csrss.exe Parent PID: 676 services.exe PID: 728 Path: C:\Windows\system32\services.exe Parent PID: 684 winlogon.exe PID: 756 Path: C:\Windows\system32\winlogon.exe Parent PID: 676 lsass.exe PID: 772 Path: C:\Windows\system32\lsass.exe Parent PID: 684 lsm.exe PID: 784 Path: C:\Windows\system32\lsm.exe Parent PID: 684 svchost.exe PID: 924 Path: C:\Windows\system32\svchost.exe Parent PID: 728 PresentationFontCache.exe PID: 968 Path: C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe Parent PID: 728 svchost.exe PID: 1020 Path: C:\Windows\system32\svchost.exe Parent PID: 728 svchost.exe PID: 1056 Path: C:\Windows\System32\svchost.exe Parent PID: 728 svchost.exe PID: 1156 Path: C:\Windows\System32\svchost.exe Parent PID: 728 svchost.exe PID: 1188 Path: C:\Windows\System32\svchost.exe Parent PID: 728 svchost.exe PID: 1200 Path: C:\Windows\system32\svchost.exe Parent PID: 728 audiodg.exe PID: 1276 Path: Parent PID: 1156 SLsvc.exe PID: 1304 Path: C:\Windows\system32\SLsvc.exe Parent PID: 728 svchost.exe PID: 1340 Path: C:\Windows\system32\svchost.exe Parent PID: 728 svchost.exe PID: 1452 Path: C:\Windows\system32\svchost.exe Parent PID: 728 spoolsv.exe PID: 1648 Path: C:\Windows\System32\spoolsv.exe Parent PID: 728 svchost.exe PID: 1676 Path: C:\Windows\system32\svchost.exe Parent PID: 728 agrsmsvc.exe PID: 1988 Path: C:\Windows\system32\agrsmsvc.exe Parent PID: 728 AppleMobileDeviceService.exe PID: 2016 Path: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe Parent PID: 728 mDNSResponder.exe PID: 328 Path: C:\Program Files\Bonjour\mDNSResponder.exe Parent PID: 728 CFSvcs.exe PID: 348 Path: C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe Parent PID: 728 hasplms.exe PID: 1400 Path: C:\Windows\system32\hasplms.exe Parent PID: 728 svchost.exe PID: 1744 Path: C:\Windows\system32\svchost.exe Parent PID: 728 upeksvr.exe PID: 1952 Path: C:\Program Files\Protector Suite QL\upeksvr.exe Parent PID: 1104 sqlservr.exe PID: 576 Path: C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe Parent PID: 728 svchost.exe PID: 2236 Path: C:\Windows\System32\svchost.exe Parent PID: 728 SyncServices.exe PID: 2260 Path: C:\Program Files\Maxtor\Utils\SyncServices.exe Parent PID: 728 pinger.exe PID: 2452 Path: C:\Toshiba\IVP\ISM\pinger.exe Parent PID: 728 svchost.exe PID: 2464 Path: C:\Windows\System32\svchost.exe Parent PID: 728 svchost.exe PID: 2476 Path: C:\Windows\system32\svchost.exe Parent PID: 728 PSIService.exe PID: 2488 Path: C:\Windows\system32\PSIService.exe Parent PID: 728 retrorun.exe PID: 2524 Path: C:\Program Files\Retrospect\Retrospect Express HD 2.0\retrorun.exe Parent PID: 728 RoxWatch9.exe PID: 2612 Path: C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe Parent PID: 728 sqlbrowser.exe PID: 2700 Path: C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe Parent PID: 728 sqlwriter.exe PID: 2720 Path: C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe Parent PID: 728 svchost.exe PID: 2744 Path: C:\Windows\system32\svchost.exe Parent PID: 728 swupdtmr.exe PID: 2772 Path: c:\Toshiba\IVP\swupdate\swupdtmr.exe Parent PID: 728 TNaviSrv.exe PID: 2820 Path: C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe Parent PID: 728 TODDSrv.exe PID: 2844 Path: C:\Windows\system32\TODDSrv.exe Parent PID: 728 TosCoSrv.exe PID: 2876 Path: C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe Parent PID: 728 TosBtSrv.exe PID: 2928 Path: C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe Parent PID: 728 ULCDRSvr.exe PID: 2956 Path: C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe Parent PID: 728 svchost.exe PID: 2972 Path: C:\Windows\System32\svchost.exe Parent PID: 728 SearchIndexer.exe PID: 2996 Path: C:\Windows\system32\SearchIndexer.exe Parent PID: 728 SDWinSec.exe PID: 3100 Path: C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe Parent PID: 728 dwm.exe PID: 3800 Path: C:\Windows\system32\Dwm.exe Parent PID: 1188 TOSCDSPD.exe PID: 4008 Path: C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe Parent PID: 3864 ehtray.exe PID: 4056 Path: C:\Windows\ehome\ehtray.exe Parent PID: 3864 ehmsas.exe PID: 2216 Path: C:\Windows\ehome\ehmsas.exe Parent PID: 924 rstrui.exe PID: 2304 Path: C:\Windows\System32\rstrui.exe Parent PID: 3864 wuauclt.exe PID: 2312 Path: C:\Windows\system32\wuauclt.exe Parent PID: 1200 ieuser.exe PID: 3264 Path: C:\Program Files\Internet Explorer\ieuser.exe Parent PID: 2320 iexplore.exe PID: 4028 Path: C:\Program Files\Internet Explorer\iexplore.exe Parent PID: 2320 wercon.exe PID: 3776 Path: C:\Windows\system32\WerCon.exe Parent PID: 3068 GoogleToolbarUser_32.exe PID: 1296 Path: C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe Parent PID: 3264 taskeng.exe PID: 3484 Path: C:\Windows\system32\taskeng.exe Parent PID: 1200 RacAgent.exe PID: 2608 Path: C:\Windows\system32\RacAgent.exe Parent PID: 3484 rundll32.exe PID: 3572 Path: C:\Windows\system32\Rundll32.exe Parent PID: 3864 WerFault.exe PID: 836 Path: C:\Windows\system32\werfault.exe Parent PID: 2972 explorer.exe PID: 840 Path: C:\Windows\Explorer.EXE Parent PID: 836 explorer.exe PID: 2652 Path: C:\Windows\Explorer.exe Parent PID: 840 rundll32.exe PID: 2008 Path: C:\Windows\system32\Rundll32.exe Parent PID: 2652 driver_service_info[1].exe PID: 4004 Path: C:\Users\Tony\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8ZE98YSG\driver_service_info[1].exe Parent PID: 3264 cmd.exe PID: 2356 Path: C:\Windows\system32\cmd.exe Parent PID: 4004 WmiPrvSE.exe PID: 3384 Path: C:\Windows\system32\wbem\wmiprvse.exe Parent PID: 924 cscript.exe PID: 4048 Path: C:\Windows\system32\cscript.exe Parent PID: 2356 findstr.exe PID: 1548 Path: C:\Windows\system32\findstr.exe Parent PID: 2356 [color="red"][b]~~~Running Services by PID~~~[/b][/color] [b]PID: 1200[/b] Application Experience Application Information Background Intelligent Transfer Service Computer Browser Extensible Authentication Protocol Group Policy Client IKE and AuthIP IPsec Keying Modules IP Helper Server Multimedia Class Scheduler User Profile Service Remote Access Connection Manager Task Scheduler Secondary Logon System Event Notification Service Shell Hardware Detection Themes Problem Reports and Solutions Control Panel Support Windows Management Instrumentation Windows Update [b]PID: 1988[/b] Agere Modem Call Progress Audio [b]PID: 2016[/b] Apple Mobile Device [b]PID: 1188[/b] Windows Audio Endpoint Builder ReadyBoost Human Interface Device Access Network Connections Program Compatibility Assistant Service Superfetch Tablet PC Input Service Distributed Link Tracking Client Desktop Window Manager Session Manager Diagnostic System Host WLAN AutoConfig Portable Device Enumerator Service Windows Driver Foundation - User-mode Driver Framework [b]PID: 1156[/b] Windows Audio DHCP Client Windows Event Log TCP/IP NetBIOS Helper Security Center [b]PID: 1676[/b] Base Filtering Engine Diagnostic Policy Service Windows Firewall [b]PID: 328[/b] Bonjour Service [b]PID: 348[/b] ConfigFree Service [b]PID: 1452[/b] Cryptographic Services DNS Client KtmRm for Distributed Transaction Coordinator Network Location Awareness Telephony Terminal Services [b]PID: 924[/b] DCOM Server Process Launcher Plug and Play [b]PID: 1340[/b] COM+ Event System Function Discovery Resource Publication Workstation Network Store Interface Service SSDP Discovery Secure Socket Tunneling Protocol Service Windows Time WebClient WinHTTP Web Proxy Auto-Discovery Service [b]PID: 968[/b] Windows Presentation Foundation Font Cache 3.0.0.0 [b]PID: 1400[/b] HASP License Manager [b]PID: 1744[/b] hpqcxs08 HP CUE DeviceDiscovery Service [b]PID: 772[/b] CNG Key Isolation Security Accounts Manager [b]PID: 576[/b] SQL Server (MSSMLBIZ) [b]PID: 2236[/b] Net Driver HPZ12 [b]PID: 2260[/b] MaxSyncService [b]PID: 2452[/b] pinger [b]PID: 2464[/b] Pml Driver HPZ12 [b]PID: 2476[/b] IPsec Policy Agent [b]PID: 2488[/b] ProtexisLicensing [b]PID: 2524[/b] Retrospect Express HD Launcher [b]PID: 2612[/b] Roxio Hard Drive Watcher 9 [b]PID: 1020[/b] Remote Procedure Call (RPC) [b]PID: 3100[/b] SBSD Security Center Service [b]PID: 1304[/b] Software Licensing [b]PID: 1648[/b] Print Spooler [b]PID: 2700[/b] SQL Server Browser [b]PID: 2720[/b] SQL Server VSS Writer [b]PID: 2744[/b] Windows Image Acquisition (WIA) [b]PID: 2772[/b] Swupdtmr [b]PID: 2820[/b] TOSHIBA Navi Support Service [b]PID: 2844[/b] TOSHIBA Optical Disc Drive Service [b]PID: 2876[/b] TOSHIBA Power Saver [b]PID: 2928[/b] TOSHIBA Bluetooth Service [b]PID: 2956[/b] Ulead Burning Helper [b]PID: 2972[/b] Windows Error Reporting Service [b]PID: 1056[/b] Windows Defender [b]PID: 2996[/b] Windows Search [color="red"][b]~~~Running Services Configuration~~~[/b][/color] PID: 1200 Service: AeLookupSvc Displayed: Application Experience Image: C:\Windows\system32\svchost.exe -k netsvcs Start Mode: [b]Auto[/b] PID: 1988 Service: AgereModemAudio Displayed: Agere Modem Call Progress Audio Image: C:\Windows\system32\agrsmsvc.exe Start Mode: [b]Auto[/b] PID: 1200 Service: Appinfo Displayed: Application Information Image: C:\Windows\system32\svchost.exe -k netsvcs Start Mode: [b]Manual[/b] PID: 2016 Service: Apple Mobile Device Displayed: Apple Mobile Device Image: "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe" Start Mode: [b]Auto[/b] PID: 1188 Service: AudioEndpointBuilder Displayed: Windows Audio Endpoint Builder Image: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted Start Mode: [b]Auto[/b] PID: 1156 Service: Audiosrv Displayed: Windows Audio Image: C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted Start Mode: [b]Auto[/b] PID: 1676 Service: BFE Displayed: Base Filtering Engine Image: C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork Start Mode: [b]Auto[/b] PID: 1200 Service: BITS Displayed: Background Intelligent Transfer Service Image: C:\Windows\system32\svchost.exe -k netsvcs Start Mode: [b]Auto[/b] PID: 328 Service: Bonjour Service Displayed: Bonjour Service Image: "C:\Program Files\Bonjour\mDNSResponder.exe" Start Mode: [b]Auto[/b] PID: 1200 Service: Browser Displayed: Computer Browser Image: C:\Windows\system32\svchost.exe -k netsvcs Start Mode: [b]Auto[/b] PID: 348 Service: CFSvcs Displayed: ConfigFree Service Image: C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe Start Mode: [b]Auto[/b] PID: 1452 Service: CryptSvc Displayed: Cryptographic Services Image: C:\Windows\system32\svchost.exe -k NetworkService Start Mode: [b]Auto[/b] PID: 924 Service: DcomLaunch Displayed: DCOM Server Process Launcher Image: C:\Windows\system32\svchost.exe -k DcomLaunch Start Mode: [b]Auto[/b] PID: 1156 Service: Dhcp Displayed: DHCP Client Image: C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted Start Mode: [b]Auto[/b] PID: 1452 Service: Dnscache Displayed: DNS Client Image: C:\Windows\system32\svchost.exe -k NetworkService Start Mode: [b]Auto[/b] PID: 1676 Service: DPS Displayed: Diagnostic Policy Service Image: C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork Start Mode: [b]Auto[/b] PID: 1200 Service: EapHost Displayed: Extensible Authentication Protocol Image: C:\Windows\System32\svchost.exe -k netsvcs Start Mode: [b]Manual[/b] PID: 1188 Service: EMDMgmt Displayed: ReadyBoost Image: C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted Start Mode: [b]Auto[/b] PID: 1156 Service: Eventlog Displayed: Windows Event Log Image: C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted Start Mode: [b]Auto[/b] PID: 1340 Service: EventSystem Displayed: COM+ Event System Image: C:\Windows\system32\svchost.exe -k LocalService Start Mode: [b]Auto[/b] PID: 1340 Service: FDResPub Displayed: Function Discovery Resource Publication Image: C:\Windows\system32\svchost.exe -k LocalService Start Mode: [b]Auto[/b] PID: 968 Service: FontCache3.0.0.0 Displayed: Windows Presentation Foundation Font Cache 3.0.0.0 Image: C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe Start Mode: [b]Auto[/b] PID: 1200 Service: gpsvc Displayed: Group Policy Client Image: C:\Windows\system32\svchost.exe -k netsvcs Start Mode: [b]Auto[/b] PID: 1400 Service: hasplms Displayed: HASP License Manager Image: C:\Windows\system32\hasplms.exe -run Start Mode: [b]Auto[/b] PID: 1188 Service: hidserv Displayed: Human Interface Device Access Image: C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted Start Mode: [b]Auto[/b] PID: 1200 Service: IKEEXT Displayed: IKE and AuthIP IPsec Keying Modules Image: C:\Windows\system32\svchost.exe -k netsvcs Start Mode: [b]Auto[/b] PID: 1200 Service: iphlpsvc Displayed: IP Helper Image: C:\Windows\System32\svchost.exe -k NetSvcs Start Mode: [b]Auto[/b] PID: 772 Service: KeyIso Displayed: CNG Key Isolation Image: C:\Windows\system32\lsass.exe Start Mode: [b]Manual[/b] PID: 1452 Service: KtmRm Displayed: KtmRm for Distributed Transaction Coordinator Image: C:\Windows\System32\svchost.exe -k NetworkService Start Mode: [b]Auto[/b] PID: 1200 Service: LanmanServer Displayed: Server Image: C:\Windows\system32\svchost.exe -k netsvcs Start Mode: [b]Auto[/b] PID: 1340 Service: LanmanWorkstation Displayed: Workstation Image: C:\Windows\System32\svchost.exe -k LocalService Start Mode: [b]Auto[/b] PID: 1156 Service: lmhosts Displayed: TCP/IP NetBIOS Helper Image: C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted Start Mode: [b]Auto[/b] PID: 1200 Service: MMCSS Displayed: Multimedia Class Scheduler Image: C:\Windows\system32\svchost.exe -k netsvcs Start Mode: [b]Auto[/b] PID: 1676 Service: MpsSvc Displayed: Windows Firewall Image: C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork Start Mode: [b]Auto[/b] PID: 576 Service: MSSQL$MSSMLBIZ Displayed: SQL Server (MSSMLBIZ) Image: "C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ Start Mode: [b]Auto[/b] PID: 2236 Service: Net Driver HPZ12 Displayed: Net Driver HPZ12 Image: C:\Windows\System32\svchost.exe -k HPZ12 Start Mode: [b]Auto[/b] PID: 1188 Service: Netman Displayed: Network Connections Image: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted Start Mode: [b]Manual[/b] PID: 1340 Service: nsi Displayed: Network Store Interface Service Image: C:\Windows\system32\svchost.exe -k LocalService Start Mode: [b]Auto[/b] PID: 2260 Service: NTService1 Displayed: MaxSyncService Image: "C:\Program Files\Maxtor\Utils\SyncServices.exe" Start Mode: [b]Auto[/b] PID: 1188 Service: PcaSvc Displayed: Program Compatibility Assistant Service Image: C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted Start Mode: [b]Auto[/b] PID: 2452 Service: pinger Displayed: pinger Image: C:\Toshiba\IVP\ISM\pinger.exe Start Mode: [b]Auto[/b] PID: 924 Service: PlugPlay Displayed: Plug and Play Image: C:\Windows\system32\svchost.exe -k DcomLaunch Start Mode: [b]Auto[/b] PID: 2464 Service: Pml Driver HPZ12 Displayed: Pml Driver HPZ12 Image: C:\Windows\System32\svchost.exe -k HPZ12 Start Mode: [b]Auto[/b] PID: 2476 Service: PolicyAgent Displayed: IPsec Policy Agent Image: C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted Start Mode: [b]Auto[/b] PID: 1200 Service: ProfSvc Displayed: User Profile Service Image: C:\Windows\system32\svchost.exe -k netsvcs Start Mode: [b]Auto[/b] PID: 1200 Service: RasMan Displayed: Remote Access Connection Manager Image: C:\Windows\system32\svchost.exe -k netsvcs Start Mode: [b]Manual[/b] PID: 2524 Service: RetroExpLauncher Displayed: Retrospect Express HD Launcher Image: "C:\Program Files\Retrospect\Retrospect Express HD 2.0\retrorun.exe" Start Mode: [b]Auto[/b] PID: 2612 Service: RoxWatch9 Displayed: Roxio Hard Drive Watcher 9 Image: "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe" Start Mode: [b]Auto[/b] PID: 1020 Service: RpcSs Displayed: Remote Procedure Call (RPC) Image: C:\Windows\system32\svchost.exe -k rpcss Start Mode: [b]Auto[/b] PID: 772 Service: SamSs Displayed: Security Accounts Manager Image: C:\Windows\system32\lsass.exe Start Mode: [b]Auto[/b] PID: 3100 Service: SBSDWSCService Displayed: SBSD Security Center Service Image: C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe Start Mode: [b]Auto[/b] PID: 1200 Service: Schedule Displayed: Task Scheduler Image: C:\Windows\System32\svchost.exe -k netsvcs Start Mode: [b]Auto[/b] PID: 1200 Service: seclogon Displayed: Secondary Logon Image: C:\Windows\system32\svchost.exe -k netsvcs Start Mode: [b]Auto[/b] PID: 1200 Service: SENS Displayed: System Event Notification Service Image: C:\Windows\system32\svchost.exe -k netsvcs Start Mode: [b]Auto[/b] PID: 1200 Service: ShellHWDetection Displayed: Shell Hardware Detection Image: C:\Windows\System32\svchost.exe -k netsvcs Start Mode: [b]Auto[/b] PID: 1304 Service: slsvc Displayed: Software Licensing Image: C:\Windows\system32\SLsvc.exe Start Mode: [b]Auto[/b] PID: 1648 Service: Spooler Displayed: Print Spooler Image: C:\Windows\System32\spoolsv.exe Start Mode: [b]Auto[/b] PID: 2700 Service: SQLBrowser Displayed: SQL Server Browser Image: "C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe" Start Mode: [b]Auto[/b] PID: 2720 Service: SQLWriter Displayed: SQL Server VSS Writer Image: "C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" Start Mode: [b]Auto[/b] PID: 1340 Service: SSDPSRV Displayed: SSDP Discovery Image: C:\Windows\system32\svchost.exe -k LocalService Start Mode: [b]Manual[/b] PID: 1340 Service: SstpSvc Displayed: Secure Socket Tunneling Protocol Service Image: C:\Windows\system32\svchost.exe -k LocalService Start Mode: [b]Manual[/b] PID: 2744 Service: stisvc Displayed: Windows Image Acquisition (WIA) Image: C:\Windows\system32\svchost.exe -k imgsvc Start Mode: [b]Auto[/b] PID: 2772 Service: Swupdtmr Displayed: Swupdtmr Image: c:\Toshiba\IVP\swupdate\swupdtmr.exe Start Mode: [b]Auto[/b] PID: 1188 Service: SysMain Displayed: Superfetch Image: C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted Start Mode: [b]Auto[/b] PID: 1188 Service: TabletInputService Displayed: Tablet PC Input Service Image: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted Start Mode: [b]Auto[/b] PID: 1452 Service: TapiSrv Displayed: Telephony Image: C:\Windows\System32\svchost.exe -k NetworkService Start Mode: [b]Manual[/b] PID: 1452 Service: TermService Displayed: Terminal Services Image: C:\Windows\System32\svchost.exe -k NetworkService Start Mode: [b]Auto[/b] PID: 1200 Service: Themes Displayed: Themes Image: C:\Windows\System32\svchost.exe -k netsvcs Start Mode: [b]Auto[/b] PID: 2820 Service: TNaviSrv Displayed: TOSHIBA Navi Support Service Image: C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe Start Mode: [b]Auto[/b] PID: 2844 Service: TODDSrv Displayed: TOSHIBA Optical Disc Drive Service Image: C:\Windows\system32\TODDSrv.exe Start Mode: [b]Auto[/b] PID: 2876 Service: TosCoSrv Displayed: TOSHIBA Power Saver Image: "C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe" Start Mode: [b]Auto[/b] PID: 2928 Service: TOSHIBA Bluetooth Service Displayed: TOSHIBA Bluetooth Service Image: C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe Start Mode: [b]Auto[/b] PID: 1188 Service: TrkWks Displayed: Distributed Link Tracking Client Image: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted Start Mode: [b]Auto[/b] PID: 2956 Service: UleadBurningHelper Displayed: Ulead Burning Helper Image: C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe Start Mode: [b]Auto[/b] PID: 1188 Service: UxSms Displayed: Desktop Window Manager Session Manager Image: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted Start Mode: [b]Auto[/b] PID: 1340 Service: W32Time Displayed: Windows Time Image: C:\Windows\system32\svchost.exe -k LocalService Start Mode: [b]Auto[/b] PID: 1188 Service: WdiSystemHost Displayed: Diagnostic System Host Image: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted Start Mode: [b]Manual[/b] PID: 1340 Service: WebClient Displayed: WebClient Image: C:\Windows\system32\svchost.exe -k LocalService Start Mode: [b]Auto[/b] PID: 1200 Service: wercplsupport Displayed: Problem Reports and Solutions Control Panel Support Image: C:\Windows\System32\svchost.exe -k netsvcs Start Mode: [b]Manual[/b] PID: 2972 Service: WerSvc Displayed: Windows Error Reporting Service Image: C:\Windows\System32\svchost.exe -k WerSvcGroup Start Mode: [b]Auto[/b] PID: 1056 Service: WinDefend Displayed: Windows Defender Image: C:\Windows\System32\svchost.exe -k secsvcs Start Mode: [b]Auto[/b] PID: 1200 Service: Winmgmt Displayed: Windows Management Instrumentation Image: C:\Windows\system32\svchost.exe -k netsvcs Start Mode: [b]Auto[/b] PID: 1188 Service: Wlansvc Displayed: WLAN AutoConfig Image: C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted Start Mode: [b]Auto[/b] PID: 1188 Service: WPDBusEnum Displayed: Portable Device Enumerator Service Image: C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted Start Mode: [b]Auto[/b] PID: 1156 Service: wscsvc Displayed: Security Center Image: C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted Start Mode: [b]Auto[/b] PID: 2996 Service: WSearch Displayed: Windows Search Image: C:\Windows\system32\SearchIndexer.exe /Embedding Start Mode: [b]Auto[/b] PID: 1200 Service: wuauserv Displayed: Windows Update Image: C:\Windows\system32\svchost.exe -k netsvcs Start Mode: [b]Auto[/b] PID: 1188 Service: wudfsvc Displayed: Windows Driver Foundation - User-mode Driver Framework Image: C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted Start Mode: [b]Auto[/b] [color="red"][b]~~~Inactive Services Configuration~~~[/b][/color] Service: Adobe Version Cue CS4 Displayed: Adobe Version Cue CS4 Path: "C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe" -win32service Start Mode: [b]Manual[/b] Service: ALG Displayed: Application Layer Gateway Service Path: C:\Windows\System32\alg.exe Start Mode: [b]Manual[/b] Service: Autodesk Licensing Service Displayed: Autodesk Licensing Service Path: "C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe" Start Mode: [b]Manual[/b] Service: CertPropSvc Displayed: Certificate Propagation Path: C:\Windows\system32\svchost.exe -k netsvcs Start Mode: [b]Manual[/b] Service: clr_optimization_v2.0.50727_32 Displayed: Microsoft .NET Framework NGEN v2.0.50727_X86 Path: C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe Start Mode: [b]Manual[/b] Service: COMSysApp Displayed: COM+ System Application Path: C:\Windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} Start Mode: [b]Manual[/b] Service: DFSR Displayed: DFS Replication Path: C:\Windows\system32\DFSR.exe Start Mode: [b]Manual[/b] Service: dot3svc Displayed: Wired AutoConfig Path: C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted Start Mode: [b]Manual[/b] Service: ehRecvr Displayed: Windows Media Center Receiver Service Path: C:\Windows\ehome\ehRecvr.exe Start Mode: [b]Manual[/b] Service: ehSched Displayed: Windows Media Center Scheduler Service Path: C:\Windows\ehome\ehsched.exe Start Mode: [b]Manual[/b] Service: ehstart Displayed: Windows Media Center Service Launcher Path: C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork Start Mode: [b]Auto[/b] Service: fdPHost Displayed: Function Discovery Provider Host Path: C:\Windows\system32\svchost.exe -k LocalService Start Mode: [b]Manual[/b] Service: FLEXnet Licensing Service Displayed: FLEXnet Licensing Service Path: "C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe" Start Mode: [b]Manual[/b] Service: GoogleDesktopManager Displayed: GoogleDesktopManager Path: "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" Start Mode: [b]Manual[/b] Service: gusvc Displayed: Google Software Updater Path: "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" Start Mode: [b]Manual[/b] Service: hkmsvc Displayed: Health Key and Certificate Management Path: C:\Windows\System32\svchost.exe -k netsvcs Start Mode: [b]Manual[/b] Service: hpqcxs08 Displayed: hpqcxs08 Path: C:\Windows\system32\svchost.exe -k hpdevmgmt Start Mode: [b]Manual[/b] Service: hpqddsvc Displayed: HP CUE DeviceDiscovery Service Path: C:\Windows\system32\svchost.exe -k hpdevmgmt Start Mode: [b]Auto[/b] Service: IDriverT Displayed: InstallDriver Table Manager Path: "C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe" Start Mode: [b]Manual[/b] Service: idsvc Displayed: Windows CardSpace Path: "C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe" Start Mode: [b]Manual[/b] Service: IPBusEnum Displayed: PnP-X IP Bus Enumerator Path: C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted Start Mode: [b]Manual[/b] Service: iPod Service Displayed: iPod Service Path: "C:\Program Files\iPod\bin\iPodService.exe" Start Mode: [b]Manual[/b] Service: lltdsvc Displayed: Link-Layer Topology Discovery Mapper Path: C:\Windows\System32\svchost.exe -k LocalService Start Mode: [b]Manual[/b] Service: Mcx2Svc Displayed: Windows Media Center Extender Service Path: C:\Windows\system32\svchost.exe -k LocalService Start Mode: [b]Disabled[/b] Service: Microsoft Office Groove Audit Service Displayed: Microsoft Office Groove Audit Service Path: "C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe" Start Mode: [b]Manual[/b] Service: MSDTC Displayed: Distributed Transaction Coordinator Path: C:\Windows\System32\msdtc.exe Start Mode: [b]Manual[/b] Service: MSiSCSI Displayed: Microsoft iSCSI Initiator Service Path: C:\Windows\system32\svchost.exe -k netsvcs Start Mode: [b]Manual[/b] Service: msiserver Displayed: Windows Installer Path: C:\Windows\system32\msiexec.exe /V Start Mode: [b]Manual[/b] Service: MSSQLServerADHelper Displayed: SQL Server Active Directory Helper Path: "C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe" Start Mode: [b]Disabled[/b] Service: napagent Displayed: Network Access Protection Agent Path: C:\Windows\System32\svchost.exe -k NetworkService Start Mode: [b]Manual[/b] Service: Netlogon Displayed: Netlogon Path: C:\Windows\system32\lsass.exe Start Mode: [b]Manual[/b] Service: netprofm Displayed: Network List Service Path: C:\Windows\System32\svchost.exe -k LocalService Start Mode: [b]Auto[/b] Service: NetTcpPortSharing Displayed: Net.Tcp Port Sharing Service Path: "C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe" Start Mode: [b]Disabled[/b] Service: NlaSvc Displayed: Network Location Awareness Path: C:\Windows\System32\svchost.exe -k NetworkService Start Mode: [b]Auto[/b] Service: odserv Displayed: Microsoft Office Diagnostics Service Path: "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE" Start Mode: [b]Manual[/b] Service: ose Displayed: Office Source Engine Path: "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE" Start Mode: [b]Manual[/b] Service: p2pimsvc Displayed: Peer Networking Identity Manager Path: C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted Start Mode: [b]Manual[/b] Service: p2psvc Displayed: Peer Networking Grouping Path: C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted Start Mode: [b]Manual[/b] Service: pla Displayed: Performance Logs & Alerts Path: C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork Start Mode: [b]Manual[/b] Service: PNRPAutoReg Displayed: PNRP Machine Name Publication Service Path: C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted Start Mode: [b]Manual[/b] Service: PNRPsvc Displayed: Peer Name Resolution Protocol Path: C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted Start Mode: [b]Manual[/b] Service: ProtectedStorage Displayed: Protected Storage Path: C:\Windows\system32\lsass.exe Start Mode: [b]Manual[/b] Service: ProtexisLicensing Displayed: ProtexisLicensing Path: C:\Windows\system32\PSIService.exe Start Mode: [b]Auto[/b] Service: QWAVE Displayed: Quality Windows Audio Video Experience Path: C:\Windows\system32\svchost.exe -k LocalService Start Mode: [b]Manual[/b] Service: RasAuto Displayed: Remote Access Auto Connection Manager Path: C:\Windows\system32\svchost.exe -k netsvcs Start Mode: [b]Manual[/b] Service: RemoteAccess Displayed: Routing and Remote Access Path: C:\Windows\system32\svchost.exe -k netsvcs Start Mode: [b]Disabled[/b] Service: RemoteRegistry Displayed: Remote Registry Path: C:\Windows\system32\svchost.exe -k regsvc Start Mode: [b]Manual[/b] Service: Roxio UPnP Renderer 9 Displayed: Roxio UPnP Renderer 9 Path: "C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe" Start Mode: [b]Manual[/b] Service: Roxio Upnp Server 9 Displayed: Roxio Upnp Server 9 Path: "C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe" Start Mode: [b]Auto[/b] Service: RoxLiveShare9 Displayed: LiveShare P2P Server 9 Path: "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe" Start Mode: [b]Auto[/b] Service: RoxMediaDB9 Displayed: RoxMediaDB9 Path: "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe" Start Mode: [b]Manual[/b] Service: RpcLocator Displayed: Remote Procedure Call (RPC) Locator Path: C:\Windows\system32\locator.exe Start Mode: [b]Manual[/b] Service: SCardSvr Displayed: Smart Card Path: C:\Windows\system32\svchost.exe -k LocalService Start Mode: [b]Manual[/b] Service: SCPolicySvc Displayed: Smart Card Removal Policy Path: C:\Windows\system32\svchost.exe -k netsvcs Start Mode: [b]Manual[/b] Service: SDRSVC Displayed: Windows Backup Path: C:\Windows\system32\svchost.exe -k SDRSVC Start Mode: [b]Manual[/b] Service: SessionEnv Displayed: Terminal Services Configuration Path: C:\Windows\System32\svchost.exe -k netsvcs Start Mode: [b]Manual[/b] Service: SharedAccess Displayed: Internet Connection Sharing (ICS) Path: C:\Windows\System32\svchost.exe -k netsvcs Start Mode: [b]Auto[/b] Service: SLUINotify Displayed: SL UI Notification Service Path: C:\Windows\system32\svchost.exe -k LocalService Start Mode: [b]Manual[/b] Service: SNMPTRAP Displayed: SNMP Trap Path: C:\Windows\System32\snmptrap.exe Start Mode: [b]Manual[/b] Service: swprv Displayed: Microsoft Software Shadow Copy Provider Path: C:\Windows\System32\svchost.exe -k swprv Start Mode: [b]Manual[/b] Service: TBS Displayed: TPM Base Services Path: C:\Windows\System32\svchost.exe -k LocalService Start Mode: [b]Auto[/b] Service: THREADORDER Displayed: Thread Ordering Server Path: C:\Windows\system32\svchost.exe -k LocalService Start Mode: [b]Manual[/b] Service: TrustedInstaller Displayed: Windows Modules Installer Path: C:\Windows\servicing\TrustedInstaller.exe Start Mode: [b]Manual[/b] Service: UI0Detect Displayed: Interactive Services Detection Path: C:\Windows\system32\UI0Detect.exe Start Mode: [b]Manual[/b] Service: upnphost Displayed: UPnP Device Host Path: C:\Windows\system32\svchost.exe -k LocalService Start Mode: [b]Manual[/b] Service: vds Displayed: Virtual Disk Path: C:\Windows\System32\vds.exe Start Mode: [b]Manual[/b] Service: VSS Displayed: Volume Shadow Copy Path: C:\Windows\system32\vssvc.exe Start Mode: [b]Manual[/b] Service: wcncsvc Displayed: Windows Connect Now - Config Registrar Path: C:\Windows\System32\svchost.exe -k LocalService Start Mode: [b]Manual[/b] Service: WcsPlugInService Displayed: Windows Color System Path: C:\Windows\system32\svchost.exe -k wcssvc Start Mode: [b]Manual[/b] Service: WdiServiceHost Displayed: Diagnostic Service Host Path: C:\Windows\System32\svchost.exe -k wdisvc Start Mode: [b]Manual[/b] Service: Wecsvc Displayed: Windows Event Collector Path: C:\Windows\system32\svchost.exe -k NetworkService Start Mode: [b]Manual[/b] Service: WinHttpAutoProxySvc Displayed: WinHTTP Web Proxy Auto-Discovery Service Path: C:\Windows\system32\svchost.exe -k LocalService Start Mode: [b]Manual[/b] Service: WinRM Displayed: Windows Remote Management (WS-Management) Path: C:\Windows\System32\svchost.exe -k NetworkService Start Mode: [b]Manual[/b] Service: wmiApSrv Displayed: WMI Performance Adapter Path: C:\Windows\system32\wbem\WmiApSrv.exe Start Mode: [b]Manual[/b] Service: WMPNetworkSvc Displayed: Windows Media Player Network Sharing Service Path: "C:\Program Files\Windows Media Player\wmpnetwk.exe" Start Mode: [b]Manual[/b] Service: WPCSvc Displayed: Parental Controls Path: C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted Start Mode: [b]Manual[/b] [color="red"][b]~~~ svchost Export ~~~[/b][/color] HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost LocalService REG_MULTI_SZ nsi lltdsvc SSDPSRV upnphost SCardSvr w32time EventSystem RemoteRegistry WinHttpAutoProxySvc lanmanworkstation TBS SLUINotify THREADORDER fdrespub netprofm fdphost wcncsvc QWAVE Mcx2Svc WebClient SstpSvc LocalSystemNetworkRestricted REG_MULTI_SZ hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum NetworkServiceNetworkRestricted REG_MULTI_SZ PolicyAgent LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc ehstart NetworkService REG_MULTI_SZ CryptSvc DHCP TermService KtmRm DNSCache NapAgent nlasvc WinRM WECSVC Tapisrv termsvcs REG_MULTI_SZ TermService WerSvcGroup REG_MULTI_SZ wersvc netsvcs REG_MULTI_SZ AeLookupSvc wercplsupport Themes CertPropSvc SCPolicySvc lanmanserver gpsvc IKEEXT AudioSrv FastUserSwitchingCompatibility Ias Irmon Nla Ntmssvc NWCWorkstation Nwsapagent Rasauto Rasman Remoteaccess SENS Sharedaccess SRService Tapisrv Wmi WmdmPmSp TermService wuauserv BITS ShellHWDetection LogonHours PCAudit helpsvc uploadmgr iphlpsvc seclogon AppInfo msiscsi MMCSS ProfSvc EapHost winmgmt schedule SessionEnv browser hkmsvc swprv REG_MULTI_SZ swprv LocalServiceNetworkRestricted REG_MULTI_SZ DHCP eventlog AudioSrv LmHosts wscsvc p2pimsvc PNRPSvc p2psvc WPCSvc PnrpAutoReg rpcss REG_MULTI_SZ RpcSs regsvc REG_MULTI_SZ RemoteRegistry wcssvc REG_MULTI_SZ WcsPlugInService DcomLaunch REG_MULTI_SZ PlugPlay DcomLaunch wdisvc REG_MULTI_SZ WdiServiceHost sdrsvc REG_MULTI_SZ sdrsvc imgsvc REG_MULTI_SZ StiSvc secsvcs REG_MULTI_SZ WinDefend HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\LocalService AuthenticationCapabilities REG_DWORD 0x2000 CoInitializeSecurityParam REG_DWORD 0x1 HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\LocalServiceNetworkRestricted DefaultRpcStackSize REG_DWORD 0x40 HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\LocalSystemNetworkRestricted CoInitializeSecurityParam REG_DWORD 0x1 HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\netsvcs AuthenticationCapabilities REG_DWORD 0x3020 CoInitializeSecurityParam REG_DWORD 0x1 HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\NetworkService CoInitializeSecurityParam REG_DWORD 0x1 DefaultRpcStackSize REG_DWORD 0x1c HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\SDRSVC CoInitializeSecurityParam REG_DWORD 0x0 HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\swprv CoInitializeSecurityParam REG_DWORD 0x0 HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\termsvcs CoInitializeSecurityParam REG_DWORD 0x1 HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\wcssvc CoInitializeSecurityParam REG_DWORD 0x1 CoInitializeSecurityAppID REG_SZ {CD11FAB6-1C0E-45e1-BA31-5C6008EF2607} HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\wercplsupport AuthenticationCapabilities REG_DWORD 0x3020 CoInitializeSecurityParam REG_DWORD 0x1 [b]~~~End of Report~~~[/b]