Svchost Groups
- netsvcs
- LocalServiceAndNoImpersonation
- LocalSystemNetworkRestricted
- LocalServiceNetworkRestricted
- AxInstSVGroup
- LocalServiceNoNetwork
- bthsvcs
- NetworkService
- DcomLaunch
- defragsvc
- LocalService
- NetSvcs
- NetworkServiceAndNoImpersonation
- LocalServicePeerNet
- PeerDist
- NetworkServiceNetworkRestricted
- regsvc
- RPCSS
- rpcss
- SDRSVC
- imgsvc
- swprv
- WbioSvcGroup
- wcssvc
- WerSvcGroup
- secsvcs
Application Experience Service | ||
---|---|---|
Svchost Group | netsvcs | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k netsvcs | SeTcbPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\aelupsvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AeLookupSvc | |
Full Description | Processes application compatibility cache requests for applications as they are launched | |
Application Information Service | ||
Svchost Group | netsvcs | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k netsvcs | SeAssignPrimaryTokenPrivilege SeIncreaseQuotaPrivilege SeTcbPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeChangeNotifyPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\appinfo.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Appinfo | |
Full Description | Facilitates the running of interactive applications with additional administrative privileges. If this service is stopped, users will be unable to launch applications with the additional administrative privileges they may require to perform desired user | |
Software installation Service | ||
Svchost Group | netsvcs | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k netsvcs | SeCreateGlobalPrivilege SeImpersonatePrivilege SeIncreaseQuotaPrivilege SeShutdownPrivilege SeTakeOwnershipPrivilege |
Executable File Name | c:\windows\system32\appmgmts.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AppMgmt | |
Full Description | Processes installation, removal, and enumeration requests for software deployed through Group Policy. If the service is disabled, users will be unable to install, remove, or enumerate software deployed through Group Policy. If this service is disabled, an | |
BDE Service | ||
Svchost Group | netsvcs | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k netsvcs | SeChangeNotifyPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\bdesvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BDESVC | |
Full Description | BDESVC hosts the BitLocker Drive Encryption service. BitLocker Drive Encryption provides secure startup for the operating system, as well as full volume encryption for OS, fixed or removable volumes. This service allows BitLocker to prompt users for vario | |
Background Intelligent Transfer Service | ||
Svchost Group | netsvcs | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k netsvcs | SeCreateGlobalPrivilege SeImpersonatePrivilege SeTcbPrivilege SeAssignPrimaryTokenPrivilege SeIncreaseQuotaPrivilege |
Executable File Name | c:\windows\system32\qmgr.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS | |
Full Description | Transfers files in the background using idle network bandwidth. If the service is disabled, then any applications that depend on BITS, such as Windows Update or MSN Explorer, will be unable to automatically download programs and other information. | |
Computer Browser Service DLL | ||
Svchost Group | netsvcs | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k netsvcs | |
Executable File Name | c:\windows\system32\browser.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Browser | |
Full Description | Maintains an updated list of computers on the network and supplies this list to computers designated as browsers. If this service is stopped, this list will not be updated or maintained. If this service is disabled, any services that explicitly depend on | |
Microsoft Smartcard Certificate Propagation Service | ||
Svchost Group | netsvcs | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k netsvcs | SeCreateGlobalPrivilege SeTcbPrivilege SeChangeNotifyPrivilege SeImpersonatePrivilege SeTakeOwnershipPrivilege SeSecurityPrivilege |
Executable File Name | c:\windows\system32\certprop.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CertPropSvc | |
Full Description | Copies user certificates and root certificates from smart cards into the current users certificate store, detects when a smart card is inserted into a smart card reader, and, if needed, installs the smart card Plug and Play minidriver. | |
Microsoft EAPHost service | ||
Svchost Group | netsvcs | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k netsvcs | SeTcbPrivilege SeDebugPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\eapsvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EapHost | |
Full Description | The Extensible Authentication Protocol (EAP) service provides network authentication in such scenarios as 802.1x wired and wireless, VPN, and Network Access Protection (NAP). EAP also provides application programming interfaces (APIs) that are used by ne | |
Group Policy Client API | ||
Svchost Group | netsvcs | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k netsvcs | SeImpersonatePrivilege SeTcbPrivilege SeTakeOwnershipPrivilege SeIncreaseQuotaPrivilege SeAssignPrimaryTokenPrivilege SeSecurityPrivilege SeChangeNotifyPrivilege SeCreatePermanentPrivilege SeShutdownPrivilege SeLoadDriverPrivilege SeRestorePrivilege SeBackupPrivilege |
Executable File Name | c:\windows\system32\gpapi.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gpsvc | |
Full Description | The service is responsible for applying settings configured by administrators for the computer and users through the Group Policy component. If the service is stopped or disabled, the settings will not be applied and applications and components will not b | |
Key Management Service | ||
Svchost Group | netsvcs | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k netsvcs | SeChangeNotifyPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\kmsvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hkmsvc | |
Full Description | Provides X.509 certificate and key management services for the Network Access Protection Agent (NAPAgent). Enforcement technologies that use X.509 certificates may not function properly without this service | |
IKE extension | ||
Svchost Group | netsvcs | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k netsvcs | SeAuditPrivilege SeImpersonatePrivilege SeTcbPrivilege SeDebugPrivilege |
Executable File Name | c:\windows\system32\ikeext.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IKEEXT | |
Full Description | The IKEEXT service hosts the Internet Key Exchange (IKE) and Authenticated Internet Protocol (AuthIP) keying modules. These keying modules are used for authentication and key exchange in Internet Protocol security (IPsec). Stopping or disabling the IKEEXT | |
Server Service DLL | ||
Svchost Group | netsvcs | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k netsvcs | SeChangeNotifyPrivilege SeImpersonatePrivilege SeAuditPrivilege SeLoadDriverPrivilege |
Executable File Name | c:\windows\system32\srvsvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer | |
Full Description | Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. | |
Multimedia Class Scheduler Service | ||
Svchost Group | netsvcs | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k netsvcs | SeIncreaseBasePriorityPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\mmcss.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MMCSS | |
Full Description | Enables relative prioritization of work based on system-wide task priorities. This is intended mainly for multimedia applications. If this service is stopped, individual tasks resort to their default priority. | |
iSCSI Discovery api | ||
Svchost Group | netsvcs | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k netsvcs | SeAuditPrivilege SeChangeNotifyPrivilege SeCreateGlobalPrivilege SeCreatePermanentPrivilege SeImpersonatePrivilege SeTcbPrivilege |
Executable File Name | c:\windows\system32\iscsidsc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSiSCSI | |
Full Description | Manages Internet SCSI (iSCSI) sessions from this computer to remote iSCSI target devices. If this service is stopped, this computer will not be able to login or access iSCSI targets. If this service is disabled, any services that explicitly depend on it w | |
ProfSvc | ||
Svchost Group | netsvcs | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k netsvcs | SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\profsvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ProfSvc | |
Full Description | This service is responsible for loading and unloading user profiles. If this service is stopped or disabled, users will no longer be able to successfully logon or logoff, applications may have problems getting to users data, and components registered to | |
Remote Access AutoDial Manager | ||
Svchost Group | netsvcs | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k netsvcs | SeImpersonatePrivilege SeTcbPrivilege SeIncreaseQuotaPrivilege SeChangeNotifyPrivilege SeCreateGlobalPrivilege SeAssignPrimaryTokenPrivilege |
Executable File Name | c:\windows\system32\rasauto.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasAuto | |
Full Description | Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address. | |
Remote Access Connection Manager | ||
Svchost Group | netsvcs | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k netsvcs | SeImpersonatePrivilege SeIncreaseQuotaPrivilege SeTcbPrivilege SeChangeNotifyPrivilege SeCreateGlobalPrivilege SeAssignPrimaryTokenPrivilege |
Executable File Name | c:\windows\system32\rasmans.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan | |
Full Description | Manages dial-up and virtual private network (VPN) connections from this computer to the Internet or other remote networks. If this service is disabled, any services that explicitly depend on it will fail to start. | |
Dynamic Interface Manager | ||
Svchost Group | netsvcs | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k netsvcs | SeChangeNotifyPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege SeAuditPrivilege |
Executable File Name | c:\windows\system32\mprdim.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess | |
Full Description | Offers routing services to businesses in local area and wide area network environments. | |
Task Scheduler Service | ||
Svchost Group | netsvcs | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k netsvcs | SeIncreaseQuotaPrivilege SeChangeNotifyPrivilege SeAuditPrivilege SeImpersonatePrivilege SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeRestorePrivilege |
Executable File Name | c:\windows\system32\schedsvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Schedule | |
Full Description | Enables a user to configure and schedule automated tasks on this computer. The service also hosts multiple Windows system-critical tasks. If this service is stopped or disabled, these tasks will not be run at their scheduled times. If this service is disa | |
Microsoft Smartcard Certificate Propagation Service | ||
Svchost Group | netsvcs | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k netsvcs | SeCreateGlobalPrivilege SeTcbPrivilege SeChangeNotifyPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\certprop.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SCPolicySvc | |
Full Description | Allows the system to be configured to lock the user desktop upon smart card removal. | |
Secondary Logon Service DLL | ||
Svchost Group | netsvcs | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k netsvcs | SeTcbPrivilege SeRestorePrivilege SeBackupPrivilege SeAssignPrimaryTokenPrivilege SeIncreaseQuotaPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\seclogon.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\seclogon | |
Full Description | Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. | |
System Event Notification Service (SENS) | ||
Svchost Group | netsvcs | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k netsvcs | SeAuditPrivilege SeChangeNotifyPrivilege SeCreateGlobalPrivilege SeImpersonatePrivilege SeTcbPrivilege |
Executable File Name | c:\windows\system32\sens.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SENS | |
Full Description | Monitors system events and notifies subscribers to COM+ Event System of these events. | |
Remote Desktop Configuration service | ||
Svchost Group | netsvcs | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k netsvcs | SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\sessenv.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SessionEnv | |
Full Description | Remote Desktop Configuration service (RDCS) is responsible for all Remote Desktop Services and Remote Desktop related configuration and session maintenance activities that require SYSTEM context. These include per-session temporary folders, RD themes, and | |
Microsoft NAT Helper Components | ||
Svchost Group | netsvcs | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k netsvcs | SeChangeNotifyPrivilege SeCreateGlobalPrivilege SeImpersonatePrivilege SeLoadDriverPrivilege SeTakeOwnershipPrivilege |
Executable File Name | c:\windows\system32\ipnathlp.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess | |
Full Description | Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network. | |
Windows Shell Services Dll | ||
Svchost Group | netsvcs | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k netsvcs | SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\shsvcs.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ShellHWDetection | |
Full Description | Provides notifications for AutoPlay hardware events. | |
Windows Shell Theme Service Dll | ||
Svchost Group | netsvcs | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k netsvcs | SeAssignPrimaryTokenPrivilege SeDebugPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\themeservice.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Themes | |
Full Description | Provides user experience theme management. | |
Problem Reports and Solutions | ||
Svchost Group | netsvcs | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k netsvcs | SeImpersonatePrivilege SeTcbPrivilege |
Executable File Name | c:\windows\system32\wercplsupport.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wercplsupport | |
Full Description | This service provides support for viewing, sending and deletion of system-level problem reports for the Problem Reports and Solutions control panel. | |
WMI | ||
Svchost Group | netsvcs | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k netsvcs | |
Executable File Name | c:\windows\system32\wbem\wmisvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Winmgmt | |
Full Description | Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any | |
Windows Update Agent | ||
Svchost Group | netsvcs | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k netsvcs | SeAuditPrivilege SeCreateGlobalPrivilege SeCreatePageFilePrivilege SeTcbPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege SeIncreaseQuotaPrivilege SeShutdownPrivilege |
Executable File Name | c:\windows\system32\wuaueng.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv | |
Full Description | Enables the detection, download, and installation of updates for Windows and other programs. If this service is disabled, users of this computer will not be able to use Windows Update or its automatic updating feature, and programs will not be able to use |
LocalServiceAndNoImpersonation svchost group
Application Identity Service | ||
---|---|---|
Svchost Group | LocalServiceAndNoImpersonation | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation | SeChangeNotifyPrivilege |
Executable File Name | c:\windows\system32\appidsvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AppIDSvc | |
Full Description | Determines and verifies the identity of an application. Disabling this service will prevent AppLocker from being enforced. | |
Function Discovery Resource Publication Service | ||
Svchost Group | LocalServiceAndNoImpersonation | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation | SeChangeNotifyPrivilege |
Executable File Name | c:\windows\system32\fdrespub.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FDResPub | |
Full Description | Publishes this computer and resources attached to this computer so they can be discovered over the network. If this service is stopped, network resources will no longer be published and they will not be discovered by other computers on the network. | |
Windows Font Cache Service | ||
Svchost Group | LocalServiceAndNoImpersonation | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation | SeChangeNotifyPrivilege SeAuditPrivilege |
Executable File Name | c:\windows\system32\fntcache.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FontCache | |
Full Description | Optimizes performance of applications by caching commonly used font data. Applications will start this service if it is not already running. It can be disabled, though doing so will degrade application performance. | |
Media Center Resources | ||
Svchost Group | LocalServiceAndNoImpersonation | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation | SeChangeNotifyPrivilege |
Executable File Name | c:\windows\ehome\ehres.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Mcx2Svc | |
Full Description | Allows Media Center Extenders to locate and connect to the computer. | |
Windows NT | ||
Svchost Group | LocalServiceAndNoImpersonation | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation | SeChangeNotifyPrivilege |
Executable File Name | c:\windows\system32\qwave.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\QWAVE | |
Full Description | Quality Windows Audio Video Experience (qWave) is a networking platform for Audio Video (AV) streaming applications on IP home networks. qWave enhances AV streaming performance and reliability by ensuring network quality-of-service (QoS) for AV applicatio | |
Smart Card Resource Management Server | ||
Svchost Group | LocalServiceAndNoImpersonation | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation | SeCreateGlobalPrivilege SeChangeNotifyPrivilege |
Executable File Name | c:\windows\system32\scardsvr.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SCardSvr | |
Full Description | Manages access to smart cards read by this computer. If this service is stopped, this computer will be unable to read smart cards. If this service is disabled, any services that explicitly depend on it will fail to start. | |
Microsoft Windows ambient light service | ||
Svchost Group | LocalServiceAndNoImpersonation | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation | SeChangeNotifyPrivilege |
Executable File Name | c:\windows\system32\sensrsvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SensrSvc | |
Full Description | Monitors ambient light sensors to detect changes in ambient light and adjust the display brightness. If this service is stopped or disabled, the display brightness will not adapt to lighting conditions. | |
SSDP Service DLL | ||
Svchost Group | LocalServiceAndNoImpersonation | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation | SeChangeNotifyPrivilege SeCreateGlobalPrivilege |
Executable File Name | c:\windows\system32\ssdpsrv.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SSDPSRV | |
Full Description | Discovers networked devices and services that use the SSDP discovery protocol, such as UPnP devices. Also announces SSDP devices and services running on the local computer. If this service is stopped, SSDP-based devices will not be discovered. If this ser | |
TBS Service | ||
Svchost Group | LocalServiceAndNoImpersonation | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation | SeChangeNotifyPrivilege SeAuditPrivilege |
Executable File Name | c:\windows\system32\tbssvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TBS | |
Full Description | Enables access to the Trusted Platform Module (TPM), which provides hardware-based cryptographic services to system components and applications. If this service is stopped or disabled, applications will be unable to use keys protected by the TPM. | |
UPnP Device Host | ||
Svchost Group | LocalServiceAndNoImpersonation | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation | SeChangeNotifyPrivilege SeCreateGlobalPrivilege |
Executable File Name | c:\windows\system32\upnphost.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\upnphost | |
Full Description | Allows UPnP devices to be hosted on this computer. If this service is stopped, any hosted UPnP devices will stop functioning and no additional hosted devices can be added. If this service is disabled, any services that explicitly depend on it will fail to | |
Windows Connect Now – Config Registrar Service | ||
Svchost Group | LocalServiceAndNoImpersonation | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation | SeChangeNotifyPrivilege |
Executable File Name | c:\windows\system32\wcncsvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wcncsvc | |
Full Description | WCNCSVC hosts the Windows Connect Now Configuration which is Microsofts Implementation of Wi-Fi Protected Setup (WPS) protocol. This is used to configure Wireless LAN settings for an Access Point (AP) or a Wi-Fi Device. The service is started programmati |
LocalSystemNetworkRestricted svchost group
Windows Audio Service | ||
---|---|---|
Svchost Group | LocalSystemNetworkRestricted | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted | SeChangeNotifyPrivilege |
Executable File Name | c:\windows\system32\audiosrv.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AudioEndpointBuilder | |
Full Description | Manages audio devices for the Windows Audio service. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start | |
CSC Service DLL | ||
Svchost Group | LocalSystemNetworkRestricted | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted | SeTcbPrivilege SeImpersonatePrivilege SeIncreaseBasePriorityPrivilege |
Executable File Name | c:\windows\system32\cscsvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CscService | |
Full Description | The Offline Files service performs maintenance activities on the Offline Files cache, responds to user logon and logoff events, implements the internals of the public API, and dispatches interesting events to those interested in Offline Files activities a | |
Wired AutoConfig Service | ||
Svchost Group | LocalSystemNetworkRestricted | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted | SeChangeNotifyPrivilege SeImpersonatePrivilege SeAuditPrivilege SeTcbPrivilege |
Executable File Name | c:\windows\system32\dot3svc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dot3svc | |
Full Description | The Wired AutoConfig (DOT3SVC) service is responsible for performing IEEE 802.1X authentication on Ethernet interfaces. If your current wired network deployment enforces 802.1X authentication, the DOT3SVC service should be configured to run for establishi | |
HID Service | ||
Svchost Group | LocalSystemNetworkRestricted | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted | SeChangeNotifyPrivilege SeCreateGlobalPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\hidserv.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hidserv | |
Full Description | Enables generic input access to Human Interface Devices (HID), which activates and maintains the use of predefined hot buttons on keyboards, remote controls, and other multimedia devices. If this service is stopped, hot buttons controlled by this service | |
Windows HomeGroup | ||
Svchost Group | LocalSystemNetworkRestricted | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted | SeChangeNotifyPrivilege SeImpersonatePrivilege SeTcbPrivilege |
Executable File Name | c:\windows\system32\listsvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HomeGroupListener | |
Full Description | Makes local computer changes associated with configuration and maintenance of the homegroup-joined computer. If this service is stopped or disabled, your computer will not work properly in a homegroup and your homegroup might not work properly. It is reco | |
PnP-X IP Bus Enumerator DLL | ||
Svchost Group | LocalSystemNetworkRestricted | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted | SeChangeNotifyPrivilege SeCreateGlobalPrivilege SeImpersonatePrivilege SeLoadDriverPrivilege |
Executable File Name | c:\windows\system32\ipbusenum.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IPBusEnum | |
Full Description | The PnP-X bus enumerator service manages the virtual network bus. It discovers network connected devices using the SSDP/WS discovery protocols and gives them presence in PnP. If this service is stopped or disabled, presence of NCD devices will not be main | |
Network Connections Manager | ||
Svchost Group | LocalSystemNetworkRestricted | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted | SeImpersonatePrivilege SeChangeNotifyPrivilege SeLoadDriverPrivilege |
Executable File Name | c:\windows\system32\netman.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netman | |
Full Description | Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections. | |
Program Compatibility Assistant Service | ||
Svchost Group | LocalSystemNetworkRestricted | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted | SeDebugPrivilege |
Executable File Name | c:\windows\system32\pcasvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PcaSvc | |
Full Description | This service provides support for the Program Compatibility Assistant (PCA). PCA monitors programs installed and run by the user and detects known compatibility problems. If this service is stopped, PCA will not function properly. | |
Superfetch Service Host | ||
Svchost Group | LocalSystemNetworkRestricted | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted | SeTcbPrivilege SeProfileSingleProcessPrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeIncreaseBasePriorityPrivilege |
Executable File Name | c:\windows\system32\sysmain.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SysMain | |
Full Description | Maintains and improves system performance over time. | |
Microsoft Tablet PC Input Service | ||
Svchost Group | LocalSystemNetworkRestricted | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted | SeTcbPrivilege SeImpersonatePrivilege SeIncreaseQuotaPrivilege SeAssignPrimaryTokenPrivilege SeCreateGlobalPrivilege |
Executable File Name | c:\windows\system32\tabsvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TabletInputService | |
Full Description | Enables Tablet PC pen and ink functionality | |
Distributed Link Tracking Client | ||
Svchost Group | LocalSystemNetworkRestricted | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted | SeRestorePrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\trkwks.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TrkWks | |
Full Description | Maintains links between NTFS files within a computer or across computers in a network. | |
Remote Desktop Services Device Redirector Service | ||
Svchost Group | LocalSystemNetworkRestricted | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted | SeAuditPrivilege SeChangeNotifyPrivilege SeCreateGlobalPrivilege SeImpersonatePrivilege SeIncreaseQuotaPrivilege SeCreatePermanentPrivilege SeLoadDriverPrivilege SeDebugPrivilege |
Executable File Name | c:\windows\system32\umrdp.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UmRdpService | |
Full Description | Allows the redirection of Printers/Drives/Ports for RDP connections | |
Desktop Window Manager | ||
Svchost Group | LocalSystemNetworkRestricted | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted | SeAssignPrimaryTokenPrivilege SeCreateGlobalPrivilege SeIncreaseQuotaPrivilege SeSecurityPrivilege SeTcbPrivilege |
Executable File Name | c:\windows\system32\dwm.exe | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UxSms | |
Full Description | Provides Desktop Window Manager startup and maintenance services | |
Windows Diagnostic Infrastructure | ||
Svchost Group | LocalSystemNetworkRestricted | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted | SeChangeNotifyPrivilege SeImpersonatePrivilege SeTcbPrivilege SeDebugPrivilege SeAssignPrimaryTokenPrivilege SeIncreaseQuotaPrivilege SeProfileSingleProcessPrivilege SeSystemEnvironmentPrivilege |
Executable File Name | c:\windows\system32\wdi.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WdiSystemHost | |
Full Description | The Diagnostic System Host is used by the Diagnostic Policy Service to host diagnostics that need to run in a Local System context. If this service is stopped, any diagnostics that depend on it will no longer function. | |
Windows WLAN AutoConfig Service DLL | ||
Svchost Group | LocalSystemNetworkRestricted | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted | SeChangeNotifyPrivilege SeImpersonatePrivilege SeAuditPrivilege SeTcbPrivilege SeDebugPrivilege |
Executable File Name | c:\windows\system32\wlansvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Wlansvc | |
Full Description | The WLANSVC service provides the logic required to configure, discover, connect to, and disconnect from a wireless local area network (WLAN) as defined by IEEE 802.11 standards. It also contains the logic to turn your computer into a software access point | |
Portable Device Enumerator | ||
Svchost Group | LocalSystemNetworkRestricted | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted | SeAuditPrivilege SeChangeNotifyPrivilege SeCreateGlobalPrivilege SeCreatePermanentPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\wpdbusenum.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WPDBusEnum | |
Full Description | Enforces group policy for removable mass-storage devices. Enables applications such as Windows Media Player and Image Import Wizard to transfer and synchronize content using removable mass-storage devices. | |
Windows Driver Foundation – User-mode Driver Framework Service | ||
Svchost Group | LocalSystemNetworkRestricted | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted | SeChangeNotifyPrivilege SeAssignPrimaryTokenPrivilege SeIncreaseQuotaPrivilege SeTcbPrivilege |
Executable File Name | c:\windows\system32\wudfsvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wudfsvc | |
Full Description | Manages user-mode driver host processes. |
LocalServiceNetworkRestricted svchost group
Windows Audio Service | ||
---|---|---|
Svchost Group | LocalServiceNetworkRestricted | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted | SeChangeNotifyPrivilege SeImpersonatePrivilege SeIncreaseWorkingSetPrivilege |
Executable File Name | c:\windows\system32\audiosrv.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AudioSrv | |
Full Description | Manages audio for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start | |
DHCP Client Service | ||
Svchost Group | LocalServiceNetworkRestricted | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted | SeChangeNotifyPrivilege SeCreateGlobalPrivilege |
Executable File Name | c:\windows\system32\dhcpcore.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp | |
Full Description | Registers and updates IP addresses and DNS records for this computer. If this service is stopped, this computer will not receive dynamic IP addresses and DNS updates. If this service is disabled, any services that explicitly depend on it will fail to star | |
Event Logging Service | ||
Svchost Group | LocalServiceNetworkRestricted | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted | SeChangeNotifyPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\wevtsvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\eventlog | |
Full Description | This service manages events and event logs. It supports logging events, querying events, subscribing to events, archiving event logs, and managing event metadata. It can display events in both XML and plain text format. Stopping this service may compromis | |
Windows HomeGroup | ||
Svchost Group | LocalServiceNetworkRestricted | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted | SeChangeNotifyPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\provsvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HomeGroupProvider | |
Full Description | Performs networking tasks associated with configuration and maintenance of homegroups. If this service is stopped or disabled, your computer will be unable to detect other homegroups and your homegroup might not work properly. It is recommended that you k | |
TCPIP NetBios Transport Services DLL | ||
Svchost Group | LocalServiceNetworkRestricted | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted | SeCreateGlobalPrivilege |
Executable File Name | c:\windows\system32\lmhsvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lmhosts | |
Full Description | Provides support for the NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution for clients on the network, therefore enabling users to share files, print, and log on to the network. If this service is stopped, these functions might be unavailabl | |
WPC Filtering Service | ||
Svchost Group | LocalServiceNetworkRestricted | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted | SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\wpcsvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WPCSvc | |
Full Description | This service is a stub for Windows Parental Control functionality that existed in Vista. It is provided for backward compatibility only. | |
Windows Security Center Service | ||
Svchost Group | LocalServiceNetworkRestricted | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted | SeChangeNotifyPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\wscsvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc | |
Full Description | The WSCSVC (Windows Security Center) service monitors and reports security health settings on the computer. The health settings include firewall (on/off), antivirus (on/off/out of date), antispyware (on/off/out of date), Windows Update (automatically/man |
ActiveX Installer Service | ||
---|---|---|
Svchost Group | AxInstSVGroup | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k AxInstSVGroup | SeAssignPrimaryTokenPrivilege SeIncreaseQuotaPrivilege SeTcbPrivilege SeBackupPrivilege SeRestorePrivilege SeAuditPrivilege SeChangeNotifyPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\axinstsv.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AxInstSV | |
Full Description | Provides User Account Control validation for the installation of ActiveX controls from the Internet and enables management of ActiveX control installation based on Group Policy settings. This service is started on demand and if disabled the installation o |
LocalServiceNoNetwork svchost group
Base Filtering Engine | ||
---|---|---|
Svchost Group | LocalServiceNoNetwork | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork | SeAuditPrivilege |
Executable File Name | c:\windows\system32\bfe.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE | |
Full Description | The Base Filtering Engine (BFE) is a service that manages firewall and Internet Protocol security (IPsec) policies and implements user mode filtering. Stopping or disabling the BFE service will significantly reduce the security of the system. It will also | |
WDI Diagnostic Policy Service | ||
Svchost Group | LocalServiceNoNetwork | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork | SeChangeNotifyPrivilege SeCreateGlobalPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\dps.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DPS | |
Full Description | The Diagnostic Policy Service enables problem detection, troubleshooting and resolution for Windows components. If this service is stopped, diagnostics will no longer function. | |
Windows Firewall API | ||
Svchost Group | LocalServiceNoNetwork | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork | SeAssignPrimaryTokenPrivilege SeAuditPrivilege SeChangeNotifyPrivilege SeCreateGlobalPrivilege SeImpersonatePrivilege SeIncreaseQuotaPrivilege |
Executable File Name | c:\windows\system32\firewallapi.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MpsSvc | |
Full Description | Windows Firewall helps protect your computer by preventing unauthorized users from gaining access to your computer through the Internet or a network. | |
Performance Logs & Alerts | ||
Svchost Group | LocalServiceNoNetwork | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork | SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\pla.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\pla | |
Full Description | Performance Logs and Alerts Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. | |
WWAN Auto Config Service | ||
Svchost Group | LocalServiceNoNetwork | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork | SeChangeNotifyPrivilege SeImpersonatePrivilege SeAuditPrivilege |
Executable File Name | c:\windows\system32\wwansvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WwanSvc | |
Full Description | This service manages mobile broadband (GSM & CDMA) data card/embedded module adapters and connections by auto-configuring the networks. It is strongly recommended that this service be kept running for best user experience of mobile broadband devices. |
Bluetooth Support Service | ||
---|---|---|
Svchost Group | bthsvcs | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k bthsvcs | SeChangeNotifyPrivilege SeCreateGlobalPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\bthserv.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bthserv | |
Full Description | The Bluetooth service supports discovery and association of remote Bluetooth devices. Stopping or disabling this service may cause already installed Bluetooth devices to fail to operate properly and prevent new devices from being discovered or associated |
Cryptographic Services | ||
---|---|---|
Svchost Group | NetworkService | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k NetworkService | SeChangeNotifyPrivilege SeCreateGlobalPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\cryptsvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CryptSvc | |
Full Description | Provides four management services: Catalog Database Service, which confirms the signatures of Windows files and allows new programs to be installed; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this | |
DNS Client API DLL | ||
Svchost Group | NetworkService | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k NetworkService | SeChangeNotifyPrivilege SeCreateGlobalPrivilege |
Executable File Name | c:\windows\system32\dnsapi.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache | |
Full Description | The DNS Client service (dnscache) caches Domain Name System (DNS) names and registers the full computer name for this computer. If the service is stopped, DNS names will continue to be resolved. However, the results of DNS name queries will not be cached | |
Workstation Service DLL | ||
Svchost Group | NetworkService | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k NetworkService | SeChangeNotifyPrivilege SeImpersonatePrivilege SeAuditPrivilege |
Executable File Name | c:\windows\system32\wkssvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation | |
Full Description | Creates and maintains client network connections to remote servers using the SMB protocol. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. | |
Quarantine Agent Service Run-Time | ||
Svchost Group | NetworkService | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k NetworkService | SeChangeNotifyPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\qagentrt.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\napagent | |
Full Description | The Network Access Protection (NAP) agent service collects and manages health information for client computers on a network. Information collected by NAP agent is used to make sure that the client computer has the required software and settings. If a clie | |
Network Location Awareness 2 | ||
Svchost Group | NetworkService | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k NetworkService | SeCreateGlobalPrivilege SeImpersonatePrivilege SeAuditPrivilege |
Executable File Name | c:\windows\system32\nlasvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NlaSvc | |
Full Description | Collects and stores configuration information for the network and notifies programs when this information is modified. If this service is stopped, configuration information might be unavailable. If this service is disabled, any services that explicitly de | |
MicrosoftAr Windows(TM) Telephony Server | ||
Svchost Group | NetworkService | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k NetworkService | SeAuditPrivilege SeChangeNotifyPrivilege SeCreateGlobalPrivilege SeImpersonatePrivilege SeIncreaseQuotaPrivilege SeAssignPrimaryTokenPrivilege |
Executable File Name | c:\windows\system32\tapisrv.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TapiSrv | |
Full Description | Provides Telephony API (TAPI) support for programs that control telephony devices on the local computer and, through the LAN, on servers that are also running the service. | |
Remote Desktop Session Host Server Remote Connections Manager | ||
Svchost Group | NetworkService | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k NetworkService | SeAssignPrimaryTokenPrivilege SeAuditPrivilege SeChangeNotifyPrivilege SeCreateGlobalPrivilege SeImpersonatePrivilege SeIncreaseQuotaPrivilege |
Executable File Name | c:\windows\system32\termsrv.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TermService | |
Full Description | Allows users to connect interactively to a remote computer. Remote Desktop and Remote Desktop Session Host Server depend on this service. To prevent remote use of this computer, clear the checkboxes on the Remote tab of the System properties control pane | |
Event Collector Service | ||
Svchost Group | NetworkService | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k NetworkService | SeAuditPrivilege SeChangeNotifyPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\wecsvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Wecsvc | |
Full Description | This service manages persistent subscriptions to events from remote sources that support WS-Management protocol. This includes Windows Vista event logs, hardware and IPMI-enabled event sources. The service stores forwarded events in a local Event Log. If | |
WSMan Service | ||
Svchost Group | NetworkService | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k NetworkService | SeAssignPrimaryTokenPrivilege SeAuditPrivilege SeChangeNotifyPrivilege SeCreateGlobalPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\wsmsvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinRM | |
Full Description | Windows Remote Management (WinRM) service implements the WS-Management protocol for remote management. WS-Management is a standard web services protocol used for remote software and hardware management. The WinRM service listens on the network for WS-Mana |
Ole resource dll | ||
---|---|---|
Svchost Group | DcomLaunch | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k DcomLaunch | SeAssignPrimaryTokenPrivilege SeAuditPrivilege SeChangeNotifyPrivilege SeCreateGlobalPrivilege SeDebugPrivilege SeImpersonatePrivilege SeIncreaseQuotaPrivilege SeTcbPrivilege SeBackupPrivilege SeRestorePrivilege |
Executable File Name | c:\windows\system32\oleres.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DcomLaunch | |
Full Description | The DCOMLAUNCH service launches COM and DCOM servers in response to object activation requests. If this service is stopped or disabled, programs using COM or DCOM will not function properly. It is strongly recommended that you have the DCOMLAUNCH service | |
User-mode Plug-and-Play Service | ||
Svchost Group | DcomLaunch | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k DcomLaunch | SeTcbPrivilege SeSecurityPrivilege SeAssignPrimaryTokenPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeImpersonatePrivilege SeAuditPrivilege SeChangeNotifyPrivilege SeUndockPrivilege SeDebugPrivilege SeShutdownPrivilege |
Executable File Name | c:\windows\system32\umpnpmgr.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PlugPlay | |
Full Description | Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability. | |
User-mode Power Service | ||
Svchost Group | DcomLaunch | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k DcomLaunch | SeTcbPrivilege SeSecurityPrivilege SeAssignPrimaryTokenPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeImpersonatePrivilege SeAuditPrivilege SeChangeNotifyPrivilege SeUndockPrivilege SeDebugPrivilege |
Executable File Name | c:\windows\system32\umpo.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Power | |
Full Description | Manages power policy and power policy notification delivery. |
Microsoft\Disk Defragmenter | ||
---|---|---|
Svchost Group | defragsvc | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k defragsvc | SeChangeNotifyPrivilege SeImpersonatePrivilege SeIncreaseWorkingSetPrivilege SeTcbPrivilege SeSystemProfilePrivilege SeAuditPrivilege SeCreateGlobalPrivilege SeBackupPrivilege SeManageVolumePrivilege |
Executable File Name | c:\windows\system32\defragsvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\defragsvc | |
Full Description | Provides Disk Defragmentation Capabilities. |
COM+ Resources | ||
---|---|---|
Svchost Group | LocalService | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k LocalService | SeChangeNotifyPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\comres.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventSystem | |
Full Description | Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifica | |
Function Discovery Provider host service | ||
Svchost Group | LocalService | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k LocalService | SeChangeNotifyPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\fdphost.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\fdPHost | |
Full Description | The FDPHOST service hosts the Function Discovery (FD) network discovery providers. These FD providers supply network discovery services for the Simple Services Discovery Protocol (SSDP) and Web Services รข_” Discovery (WS-D) protocol. Stopping or disabling t | |
Link-Layer Topology Discovery Resources | ||
Svchost Group | LocalService | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k LocalService | SeImpersonatePrivilege SeChangeNotifyPrivilege |
Executable File Name | c:\windows\system32\lltdres.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lltdsvc | |
Full Description | Creates a Network Map, consisting of PC and device topology (connectivity) information, and metadata describing each PC and device. If this service is disabled, the Network Map will not function properly. | |
Network List Manager | ||
Svchost Group | LocalService | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k LocalService | SeImpersonatePrivilege SeChangeNotifyPrivilege |
Executable File Name | c:\windows\system32\netprofm.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\netprofm | |
Full Description | Identifies the networks to which the computer has connected, collects and stores properties for these networks, and notifies applications when these properties change. | |
Network Store Interface RPC server | ||
Svchost Group | LocalService | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k LocalService | SeCreateGlobalPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\nsisvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nsi | |
Full Description | This service delivers network notifications (e.g. interface addition/deleting etc) to user mode clients. Stopping this service will cause loss of network connectivity. If this service is disabled, any other services that explicitly depend on this service | |
SPP Notification Service | ||
Svchost Group | LocalService | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k LocalService | SeChangeNotifyPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\sppuinotify.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sppuinotify | |
Full Description | Provides Software Licensing activation and notification | |
Provides the facility of using Secure Socket Tunneling Protocol (SSTP) to connect to remote computers (using VPN). | ||
Svchost Group | LocalService | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k LocalService | SeChangeNotifyPrivilege |
Executable File Name | c:\windows\system32\sstpsvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SstpSvc | |
Full Description | Provides support for the Secure Socket Tunneling Protocol (SSTP) to connect to remote computers using VPN. If this service is disabled, users will not be able to use SSTP to access remote servers. | |
Multimedia Class Scheduler Service | ||
Svchost Group | LocalService | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k LocalService | SeChangeNotifyPrivilege |
Executable File Name | c:\windows\system32\mmcss.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\THREADORDER | |
Full Description | Provides ordered execution for a group of threads within a specific period of time. | |
Windows Time Service | ||
Svchost Group | LocalService | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k LocalService | SeAuditPrivilege SeChangeNotifyPrivilege SeCreateGlobalPrivilege SeSystemTimePrivilege |
Executable File Name | c:\windows\system32\w32time.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time | |
Full Description | Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. | |
Windows Diagnostic Infrastructure | ||
Svchost Group | LocalService | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k LocalService | SeChangeNotifyPrivilege SeImpersonatePrivilege SeSystemProfilePrivilege |
Executable File Name | c:\windows\system32\wdi.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WdiServiceHost | |
Full Description | The Diagnostic Service Host is used by the Diagnostic Policy Service to host diagnostics that need to run in a Local Service context. If this service is stopped, any diagnostics that depend on it will no longer function. | |
Web DAV Service DLL | ||
Svchost Group | LocalService | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k LocalService | SeImpersonatePrivilege SeCreateGlobalPrivilege |
Executable File Name | c:\windows\system32\webclnt.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WebClient | |
Full Description | Enables Windows-based programs to create, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start. | |
Windows HTTP Services | ||
Svchost Group | LocalService | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k LocalService | SeChangeNotifyPrivilege SeCreateGlobalPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\winhttp.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinHttpAutoProxySvc | |
Full Description | WinHTTP implements the client HTTP stack and provides developers with a Win32 API and COM Automation component for sending HTTP requests and receiving responses. In addition, WinHTTP provides support for auto-discovering a proxy configuration via its impl |
Service that offers IPv6 connectivity over an IPv4 network. | ||
---|---|---|
Svchost Group | NetSvcs | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k NetSvcs | SeCreateGlobalPrivilege SeImpersonatePrivilege SeLoadDriverPrivilege |
Executable File Name | c:\windows\system32\iphlpsvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\iphlpsvc | |
Full Description | Provides tunnel connectivity using IPv6 transition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS. If this service is stopped, the computer will not have the enhanced connectivity benefits that these technologies offer. |
NetworkServiceAndNoImpersonation svchost group
COM+ Resources | ||
---|---|---|
Svchost Group | NetworkServiceAndNoImpersonation | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k NetworkServiceAndNoImpersonation | SeChangeNotifyPrivilege |
Executable File Name | c:\windows\system32\comres.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\KtmRm | |
Full Description | Coordinates transactions between the Distributed Transaction Coordinator (MSDTC) and the Kernel Transaction Manager (KTM). If it is not needed, it is recommended that this service remain stopped. If it is needed, both MSDTC and KTM will start this service |
LocalServicePeerNet svchost group
PNRP Service Dll | ||
---|---|---|
Svchost Group | LocalServicePeerNet | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k LocalServicePeerNet | SeChangeNotifyPrivilege SeCreateGlobalPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\pnrpsvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\p2pimsvc | |
Full Description | Provides identity services for the Peer Name Resolution Protocol (PNRP) and Peer-to-Peer Grouping services. If disabled, the Peer Name Resolution Protocol (PNRP) and Peer-to-Peer Grouping services may not function, and some applications, such as HomeGrou | |
Peer-to-Peer Services | ||
Svchost Group | LocalServicePeerNet | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k LocalServicePeerNet | SeChangeNotifyPrivilege SeCreateGlobalPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\p2psvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\p2psvc | |
Full Description | Enables multi-party communication using Peer-to-Peer Grouping. If disabled, some applications, such as HomeGroup, may not function. | |
PNRP Auto Service Dll | ||
Svchost Group | LocalServicePeerNet | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k LocalServicePeerNet | SeChangeNotifyPrivilege SeCreateGlobalPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\pnrpauto.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PNRPAutoReg | |
Full Description | This service publishes a machine name using the Peer Name Resolution Protocol. Configuration is managed via the netsh context p2p pnrp peer | |
PNRP Service Dll | ||
Svchost Group | LocalServicePeerNet | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k LocalServicePeerNet | SeChangeNotifyPrivilege SeCreateGlobalPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\pnrpsvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PNRPsvc | |
Full Description | Enables serverless peer name resolution over the Internet using the Peer Name Resolution Protocol (PNRP). If disabled, some peer-to-peer and collaborative applications, such as Remote Assistance, may not function. |
BranchCache Service | ||
---|---|---|
Svchost Group | PeerDist | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k PeerDist | SeChangeNotifyPrivilege SeCreateGlobalPrivilege SeImpersonatePrivilege SeAuditPrivilege |
Executable File Name | c:\windows\system32\peerdistsvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PeerDistSvc | |
Full Description | This service caches network content from peers on the local subnet. |
NetworkServiceNetworkRestricted svchost group
Policy Storage dll | ||
---|---|---|
Svchost Group | NetworkServiceNetworkRestricted | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted | SeAuditPrivilege SeChangeNotifyPrivilege SeCreateGlobalPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\polstore.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PolicyAgent | |
Full Description | Internet Protocol security (IPsec) supports network-level peer authentication, data origin authentication, data integrity, data confidentiality (encryption), and replay protection. This service enforces IPsec policies created through the IP Security Poli |
Remote Registry Service | ||
---|---|---|
Svchost Group | regsvc | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k regsvc | SeCreateGlobalPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\regsvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry | |
Full Description | Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start. |
RPC Endpoint Mapper | ||
---|---|---|
Svchost Group | RPCSS | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k RPCSS | SeChangeNotifyPrivilege SeImpersonatePrivilege SeCreateGlobalPrivilege |
Executable File Name | c:\windows\system32\rpcepmap.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcEptMapper | |
Full Description | Resolves RPC interfaces identifiers to transport endpoints. If this service is stopped or disabled, programs using Remote Procedure Call (RPC) services will not function properly. |
Ole resource dll | ||
---|---|---|
Svchost Group | rpcss | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k rpcss | SeChangeNotifyPrivilege SeCreateGlobalPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\oleres.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcSs | |
Full Description | The RPCSS service is the Service Control Manager for COM and DCOM servers. It performs object activations requests, object exporter resolutions and distributed garbage collection for COM and DCOM servers. If this service is stopped or disabled, programs u |
MicrosoftAr Windows Backup Service | ||
---|---|---|
Svchost Group | SDRSVC | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k SDRSVC | SeBackupPrivilege SeRestorePrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeCreateSymbolicLinkPrivilege SeAssignPrimaryTokenPrivilege SeIncreaseQuotaPrivilege SeTcbPrivilege SeSystemEnvironmentPrivilege |
Executable File Name | c:\windows\system32\sdrsvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SDRSVC | |
Full Description | Provides Windows Backup and Restore capabilities. |
Still Image Devices Service | ||
---|---|---|
Svchost Group | imgsvc | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k imgsvc | SeChangeNotifyPrivilege SeCreateGlobalPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\wiaservc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\stisvc | |
Full Description | Provides image acquisition services for scanners and cameras |
MicrosoftAr Volume Shadow Copy Service software provider | ||
---|---|---|
Svchost Group | swprv | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k swprv | SeBackupPrivilege SeChangeNotifyPrivilege SeCreateGlobalPrivilege SeCreatePermanentPrivilege SeImpersonatePrivilege SeManageVolumePrivilege SeRestorePrivilege SeIncreaseBasePriorityPrivilege SeManageVolumePrivilege SeRestorePrivilege SeTcbPrivilege |
Executable File Name | c:\windows\system32\swprv.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swprv | |
Full Description | Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabled, any services that explicitly depend on it will fail to sta |
Windows Biometric Service | ||
---|---|---|
Svchost Group | WbioSvcGroup | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k WbioSvcGroup | SeAssignPrimaryTokenPrivilege SeIncreaseQuotaPrivilege SeTcbPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeChangeNotifyPrivilege SeImpersonatePrivilege |
Executable File Name | c:\windows\system32\wbiosrvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WbioSrvc | |
Full Description | The Windows biometric service gives client applications the ability to capture, compare, manipulate, and store biometric data without gaining direct access to any biometric hardware or samples. The service is hosted in a privileged SVCHOST process. |
WcsPlugInService DLL | ||
---|---|---|
Svchost Group | wcssvc | Privileges |
Svchost Command | C:\Windows\system32\svchost.exe -k wcssvc | SeChangeNotifyPrivilege |
Executable File Name | c:\windows\system32\wcspluginservice.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WcsPlugInService | |
Full Description | The WcsPlugInService service hosts third-party Windows Color System color device model and gamut map model plug-in modules. These plug-in modules are vendor-specific extensions to the Windows Color System baseline color device and gamut map models. Stoppi |
Windows Error Reporting Service | ||
---|---|---|
Svchost Group | WerSvcGroup | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k WerSvcGroup | SeDebugPrivilege SeTcbPrivilege SeImpersonatePrivilege SeAssignPrimaryTokenPrivilege |
Executable File Name | c:\windows\system32\wersvc.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WerSvc | |
Full Description | Allows errors to be reported when programs stop working or responding and allows existing solutions to be delivered. Also allows logs to be generated for diagnostic and repair services. If this service is stopped, error reporting might not work correctly |
Windows Defender Resource Module | ||
---|---|---|
Svchost Group | secsvcs | Privileges |
Svchost Command | C:\Windows\System32\svchost.exe -k secsvcs | SeImpersonatePrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeChangeNotifyPrivilege SeSecurityPrivilege SeShutdownPrivilege SeIncreaseQuotaPrivilege SeAssignPrimaryTokenPrivilege |
Executable File Name | c:\program files\windows defender\msmpres.dll | |
Registry Key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinDefend | |
Full Description | Protection against spyware and potentially unwanted software |