------------------------------------------------------------------------------------------- TaskList /V /FO:CSV /NH (processes running): "aerohost.exe","2152","Services","0","8,268 K","Unknown","NT AUTHORITY\SYSTEM","0:00:01","N/A" "ClassicStartMenu.exe","4804","Console","1","11,996 K","Unknown","W10VM\NoelC","0:00:00","N/A" "CLOCK32.EXE","2424","Console","1","9,628 K","Unknown","W10VM\NoelC","0:00:00","N/A" "cmd.exe","3404","Services","0","3,740 K","Unknown","W10VM\NoelC","0:00:00","N/A" "conhost.exe","3776","Services","0","11,528 K","Unknown","W10VM\NoelC","0:00:00","N/A" "conhost.exe","4008","Console","1","9,568 K","Unknown","Window Manager\DWM-1","0:00:00","N/A" "csrss.exe","652","Services","0","4,600 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "csrss.exe","736","Console","1","4,640 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "dasHost.exe","3020","Services","0","11,352 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:00","N/A" "dllhost.exe","3780","Services","0","13,428 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "dllhost.exe","5460","Services","0","6,056 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "dwm.exe","1160","Console","1","73,980 K","Unknown","Window Manager\DWM-1","0:00:03","N/A" "explorer.exe","4720","Console","1","88,872 K","Unknown","W10VM\NoelC","0:00:05","N/A" "fontdrvhost.exe","1044","Console","1","5,508 K","Unknown","Font Driver Host\UMFD-1","0:00:00","N/A" "fontdrvhost.exe","132","Services","0","4,372 K","Unknown","Font Driver Host\UMFD-0","0:00:00","N/A" "gsort.exe","5948","Services","0","6,332 K","Unknown","W10VM\NoelC","0:00:00","N/A" "lsass.exe","844","Services","0","13,244 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "msdtc.exe","3948","Services","0","10,036 K","Unknown","NT AUTHORITY\NETWORK SERVICE","0:00:04","N/A" "RuntimeBroker.exe","5348","Console","1","8,224 K","Unknown","W10VM\NoelC","0:00:00","N/A" "services.exe","812","Services","0","8,312 K","Unknown","NT AUTHORITY\SYSTEM","0:00:04","N/A" "ShellExperienceHost.exe","5044","Console","1","62,360 K","Unknown","W10VM\NoelC","0:00:00","N/A" "ShellFolderFixUI.exe","5584","Console","1","11,680 K","Unknown","W10VM\NoelC","0:00:00","N/A" "sihost.exe","4380","Console","1","20,000 K","Unknown","W10VM\NoelC","0:00:00","N/A" "smss.exe","532","Services","0","1,192 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "spoolsv.exe","2288","Services","0","19,908 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "svchost.exe","1000","Services","0","3,828 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "svchost.exe","1068","Services","0","7,376 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:00","N/A" "svchost.exe","1116","Services","0","12,236 K","Unknown","NT AUTHORITY\NETWORK SERVICE","0:00:00","N/A" "svchost.exe","1188","Services","0","7,928 K","Unknown","NT AUTHORITY\NETWORK SERVICE","0:00:00","N/A" "svchost.exe","1252","Services","0","6,520 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:00","N/A" "svchost.exe","1320","Services","0","13,296 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:01","N/A" "svchost.exe","1368","Services","0","5,876 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "svchost.exe","1376","Services","0","10,472 K","Unknown","NT AUTHORITY\SYSTEM","0:00:01","N/A" "svchost.exe","1384","Services","0","8,992 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:00","N/A" "svchost.exe","144","Services","0","19,376 K","Unknown","NT AUTHORITY\SYSTEM","0:00:01","N/A" "svchost.exe","1500","Services","0","8,000 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "svchost.exe","1536","Services","0","7,832 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "svchost.exe","1580","Services","0","13,756 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "svchost.exe","1680","Services","0","11,076 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:00","N/A" "svchost.exe","1712","Services","0","7,296 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "svchost.exe","1768","Services","0","11,100 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "svchost.exe","1820","Services","0","12,232 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:02","N/A" "svchost.exe","1944","Services","0","6,684 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "svchost.exe","1960","Services","0","6,912 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:00","N/A" "svchost.exe","2004","Services","0","7,880 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "svchost.exe","2016","Services","0","8,160 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:00","N/A" "svchost.exe","2076","Services","0","11,400 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "svchost.exe","2120","Services","0","7,892 K","Unknown","NT AUTHORITY\NETWORK SERVICE","0:00:00","N/A" "svchost.exe","2220","Services","0","8,876 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "svchost.exe","2472","Services","0","7,776 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "svchost.exe","2480","Services","0","6,768 K","Unknown","NT AUTHORITY\NETWORK SERVICE","0:00:00","N/A" "svchost.exe","2656","Services","0","15,904 K","Unknown","NT AUTHORITY\SYSTEM","0:00:07","N/A" "svchost.exe","2664","Services","0","16,320 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:02","N/A" "svchost.exe","2672","Services","0","6,432 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "svchost.exe","2688","Services","0","5,632 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "svchost.exe","2700","Services","0","15,220 K","Unknown","NT AUTHORITY\SYSTEM","0:00:01","N/A" "svchost.exe","2708","Services","0","10,160 K","Unknown","NT AUTHORITY\NETWORK SERVICE","0:00:00","N/A" "svchost.exe","2732","Services","0","9,672 K","Unknown","NT AUTHORITY\NETWORK SERVICE","0:00:00","N/A" "svchost.exe","2956","Services","0","5,516 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:00","N/A" "svchost.exe","2988","Services","0","9,172 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "svchost.exe","3056","Services","0","12,856 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "svchost.exe","3332","Services","0","8,340 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:00","N/A" "svchost.exe","4704","Services","0","7,096 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:00","N/A" "svchost.exe","5576","Services","0","8,744 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:00","N/A" "svchost.exe","588","Services","0","8,436 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "svchost.exe","8","Services","0","9,856 K","Unknown","NT AUTHORITY\NETWORK SERVICE","0:00:00","N/A" "System Idle Process","0","Services","0","8 K","Unknown","NT AUTHORITY\SYSTEM","48:39:30","N/A" "System","4","Services","0","484 K","Unknown","N/A","0:00:38","N/A" "taskhostw.exe","4448","Console","1","17,200 K","Unknown","W10VM\NoelC","0:00:00","N/A" "tasklist.exe","440","Services","0","7,852 K","Unknown","W10VM\NoelC","0:00:00","N/A" "TSVNCache.exe","4992","Console","1","13,628 K","Unknown","W10VM\NoelC","0:00:00","N/A" "vmtoolsd.exe","2744","Services","0","22,620 K","Unknown","NT AUTHORITY\SYSTEM","0:00:03","N/A" "vmtoolsd.exe","5424","Console","1","40,316 K","Unknown","W10VM\NoelC","0:00:02","N/A" "Windows10FirewallControl.exe","2852","Console","1","17,996 K","Unknown","W10VM\NoelC","0:00:00","N/A" "Windows10FirewallService.exe","2488","Services","0","14,720 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "wininit.exe","728","Services","0","6,504 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "winlogon.exe","856","Console","1","11,616 K","Unknown","NT AUTHORITY\SYSTEM","0:00:00","N/A" "WizMouse.exe","5592","Console","1","3,276 K","Unknown","W10VM\NoelC","0:00:00","N/A" "WmiPrvSE.exe","3868","Services","0","15,140 K","Unknown","NT AUTHORITY\NETWORK SERVICE","0:00:05","N/A" ------------------------------------------------------------------------------------------- TaskList /SVC /FO:CSV /NH (services running): "dllhost.exe","3780","COMSysApp" "lsass.exe","844","SamSs,VaultSvc" "msdtc.exe","3948","MSDTC" "spoolsv.exe","2288","Spooler" "svchost.exe","1000","PlugPlay" "svchost.exe","1068","Dhcp" "svchost.exe","1116","TermService" "svchost.exe","1188","Dnscache" "svchost.exe","1252","lmhosts" "svchost.exe","1320","EventLog" "svchost.exe","1368","Themes" "svchost.exe","1376","ProfSvc" "svchost.exe","1384","EventSystem" "svchost.exe","144","BrokerInfrastructure,DcomLaunch,Power,SystemEventsBroker" "svchost.exe","1500","SENS" "svchost.exe","1536","AudioEndpointBuilder" "svchost.exe","1580","Schedule" "svchost.exe","1680","Audiosrv" "svchost.exe","1712","UmRdpService" "svchost.exe","1768","StateRepository" "svchost.exe","1820","BFE,CoreMessagingRegistrar" "svchost.exe","1944","CertPropSvc" "svchost.exe","1960","nsi" "svchost.exe","2004","UserManager" "svchost.exe","2016","TimeBrokerSvc" "svchost.exe","2076","ShellHWDetection" "svchost.exe","2120","LanmanWorkstation" "svchost.exe","2220","SessionEnv" "svchost.exe","2472","IKEEXT" "svchost.exe","2480","PolicyAgent" "svchost.exe","2656","Winmgmt" "svchost.exe","2664","DPS" "svchost.exe","2672","DeviceAssociationService" "svchost.exe","2688","TrkWks" "svchost.exe","2700","tiledatamodelsvc" "svchost.exe","2708","NlaSvc" "svchost.exe","2732","CryptSvc" "svchost.exe","2956","WdiServiceHost" "svchost.exe","2988","LanmanServer" "svchost.exe","3056","iphlpsvc" "svchost.exe","3332","netprofm" "svchost.exe","4704","WinHttpAutoProxySvc" "svchost.exe","5576","wscsvc" "svchost.exe","588","LSM" "svchost.exe","8","RpcEptMapper,RpcSs" "vmtoolsd.exe","2744","VMTools" "Windows10FirewallService.exe","2488","Windows10FirewallService" ------------------------------------------------------------------------------------------- TaskList /M /FO:CSV /NH (modules loaded): "aerohost.exe","2152","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,imagehlp.dll,ucrtbase.dll,DWMGlass.dll,combase.dll,RPCRT4.dll,bcryptPrimitives.dll,shcore.dll,msvcrt.dll,SHLWAPI.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,USER32.dll,win32u.dll,COMCTL32.dll,ADVAPI32.dll,sechost.dll,SspiCli.dll,ntmarta.dll,kernel.appcore.dll,WTSAPI32.dll,WINSTA.dll,dbghelp.dll" "ClassicStartMenu.exe","4804","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,USER32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,ucrtbase.dll,ADVAPI32.dll,msvcrt.dll,sechost.dll,RPCRT4.dll,SHELL32.dll,cfgmgr32.dll,shcore.dll,combase.dll,bcryptPrimitives.dll,windows.storage.dll,shlwapi.dll,kernel.appcore.dll,powrprof.dll,profapi.dll,ole32.dll,ClassicStartMenuDLL.dll,COMDLG32.dll,COMCTL32.dll,UxTheme.dll,OLEAUT32.dll,WINTRUST.dll,MSASN1.dll,WTSAPI32.dll,Secur32.dll,CRYPT32.dll,MSIMG32.dll,NETAPI32.dll,dwmapi.dll,OLEACC.dll,WINMM.dll,PROPSYS.dll,WININET.dll,winmmbase.dll,SSPICLI.DLL,NETUTILS.DLL,LOGONCLI.DLL,IMM32.DLL,clbcatq.dll,MSCTF.dll" "CLOCK32.EXE","2424","ntdll.dll,wow64.dll,wow64win.dll,wow64cpu.dll" "cmd.exe","3404","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,cmdext.dll,ADVAPI32.dll,sechost.dll,RPCRT4.dll" "conhost.exe","3776","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,ConhostV2.dll,msvcp_win.dll,ucrtbase.dll,combase.dll,RPCRT4.dll,bcryptPrimitives.dll,GDI32.dll,gdi32full.dll,USER32.dll,win32u.dll,OLEAUT32.dll,advapi32.dll,sechost.dll,IMM32.dll,PROPSYS.dll,shcore.dll,SHELL32.dll,cfgmgr32.dll,windows.storage.dll,shlwapi.dll,kernel.appcore.dll,powrprof.dll,profapi.dll,clbcatq.dll,msctf.dll,ole32.dll" "conhost.exe","4008","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,ConhostV2.dll,msvcp_win.dll,ucrtbase.dll,combase.dll,RPCRT4.dll,bcryptPrimitives.dll,GDI32.dll,gdi32full.dll,USER32.dll,win32u.dll,OLEAUT32.dll,advapi32.dll,sechost.dll,IMM32.dll,PROPSYS.dll,shcore.dll,SHELL32.dll,cfgmgr32.dll,windows.storage.dll,shlwapi.dll,kernel.appcore.dll,powrprof.dll,profapi.dll,uxtheme.dll,MSCTF.dll,dwmapi.dll,comctl32.DLL,clbcatq.dll" "dasHost.exe","3020","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,RPCRT4.dll,sechost.dll,cfgmgr32.dll,ucrtbase.dll,bcryptPrimitives.dll,DAFWSD.dll,OLEAUT32.dll,msvcp_win.dll,combase.dll,WS2_32.dll,IPHLPAPI.DLL,FirewallAPI.dll,deviceassociation.dll,wsdapi.dll,NSI.dll,webservices.dll,fwbase.dll,bcrypt.dll,CRYPT32.dll,MSASN1.dll,dhcpcsvc6.DLL,dhcpcsvc.DLL,mswsock.dll,wshqos.dll,wshtcpip.DLL,wship6.dll,WINNSI.DLL,powrprof.dll,CRYPTSP.dll,rsaenh.dll,CRYPTBASE.dll,XmlLite.dll,WINHTTP.dll,webio.dll,SspiCli.dll,ondemandconnroutehelper.dll,kernel.appcore.dll,clbcatq.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,MLANG.dll" "dllhost.exe","3780","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,ucrtbase.dll,combase.dll,RPCRT4.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,clbcatq.dll,sechost.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,COMSVCS.DLL,OLEAUT32.dll,ole32.dll,CRYPTSP.dll,rsaenh.dll,bcrypt.dll,CRYPTBASE.dll,es.dll,txflog.dll,PROPSYS.dll,shcore.dll,sxs.dll,ADVAPI32.dll,XOLEHLP.dll,MSDTCPRX.DLL,WS2_32.dll,RESUTILS.dll,ktmw32.dll,CLUSAPI.dll,DNSAPI.dll,NSI.dll,MTXCLU.DLL,IPHLPAPI.DLL,wkscli.dll,cscapi.dll,netutils.dll,sspicli.dll,mswsock.dll,fwpuclnt.dll,rasadhlp.dll,catsrv.dll,MfcSubs.dll,catsrvps.dll,catsrvut.dll" "dllhost.exe","5460","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,ucrtbase.dll,combase.dll,RPCRT4.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,clbcatq.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,sechost.dll,IDStore.dll,bcrypt.dll,USERENV.dll,profapi.dll" "dwm.exe","1160","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,apphelp.dll,msvcrt.dll,advapi32.dll,sechost.dll,RPCRT4.dll,gdi32.dll,gdi32full.dll,msvcp_win.dll,ucrtbase.dll,USER32.dll,win32u.dll,dwmredir.dll,udwm.dll,combase.dll,bcryptPrimitives.dll,cfgmgr32.dll,SHELL32.dll,dwmcore.dll,shcore.dll,windows.storage.dll,shlwapi.dll,kernel.appcore.dll,powrprof.dll,profapi.dll,dxgi.dll,OLEAUT32.dll,dcomp.dll,CoreMessaging.dll,d2d1.dll,d3d11.dll,CRYPT32.dll,MSASN1.dll,D3DCOMPILER_47.dll,CRYPTSP.dll,IMM32.DLL,uxtheme.dll,dwmghost.dll,dwmapi.dll,WindowsCodecs.dll,avrt.dll,ism.dll,CoreUIComponents.dll,HID.DLL,ntmarta.dll,wintypes.dll,usermgrcli.dll,clbcatq.dll,UIAnimation.dll,Windows.Gaming.Input.dll,twinapi.appcore.dll,bcrypt.dll,dbghelp.dll,vm3dum64.dll,OneCoreUAPCommonProxyStub.dll,D3D10Level9.dll,XmlLite.dll,Cabinet.dll,DWMGlass.dll,COMCTL32.dll,dbghelp.dll,WTSAPI32.dll,WINSTA.dll,ole32.dll,VERSION.dll,DUser.dll,atlthunk.dll,MSIMG32.dll,MSCTF.dll" "explorer.exe","4720","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,combase.dll,ucrtbase.dll,RPCRT4.dll,bcryptPrimitives.dll,OLEAUT32.dll,msvcp_win.dll,MrmCoreR.dll,shcore.dll,powrprof.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,shlwapi.dll,windows.storage.dll,advapi32.dll,sechost.dll,kernel.appcore.dll,profapi.dll,TWINAPI.dll,SHELL32.dll,cfgmgr32.dll,PROPSYS.dll,winmm.dll,CRYPT32.dll,WINMMBASE.dll,MSASN1.dll,UxTheme.dll,dwmapi.dll,SspiCli.dll,USERENV.dll,twinapi.appcore.dll,WTSAPI32.dll,TextInputFramework.dll,bcrypt.dll,settingsynccore.dll,CoreUIComponents.dll,CoreMessaging.dll,ntmarta.dll,wintypes.dll,usermgrcli.dll,cryptsp.dll,IMM32.DLL,MSCTF.dll,ole32.dll,clbcatq.dll,appresolver.dll,Bcp47Langs.dll,SLC.dll,sppc.dll,urlmon.dll,iertutil.dll,CRYPTBASE.DLL,elscore.dll,OneCoreUAPCommonProxyStub.dll,StartTileData.dll,XmlLite.dll,IDStore.dll,SAMLIB.dll,wlidprov.dll,samcli.dll,Windows.StateRepository.dll,StateRepository.Core.dll,Windows.ApplicationModel.dll,AppXDeploymentClient.dll,dsreg.dll,msvcp110_win.dll,DPAPI.DLL,settingsyncpolicy.dll,policymanager.dll,WINSTA.dll,comctl32.dll,SndVolSSO.DLL,MMDevAPI.DLL,DEVOBJ.dll,OLEACC.dll,dataexchange.dll,d3d11.dll,dcomp.dll,dxgi.dll,COMDLG32.dll,VERSION.dll,explorerframe.dll,veeventdispatcher.dll,Windows.UI.dll,thumbcache.dll,edputil.dll,coml2.dll,twinui.pcshell.dll,wincorlib.DLL,CLIPC.dll,windows.immersiveshell.serviceprovider.dll,WindowsCodecs.dll,Secur32.dll,netutils.dll,WLDP.DLL,WINTRUST.dll,OneCoreCommonProxyStub.dll,twinui.appcore.dll,twinui.dll,PhotoMetadataHandler.dll,DWMGlass.dll,ApplicationFrame.dll,d2d1.dll,ntshrui.dll,dbghelp.dll,srvcli.dll,cscapi.dll,HolographicExtensions.dll,ResourcePolicyClient.dll,Windows.UI.Immersive.dll,LINKINFO.dll,AboveLockAppHost.dll,apphelp.dll,ieframe.dll,NETAPI32.dll,WKSCLI.DLL,npsm.dll,msIso.dll,Windows.Shell.BlueLightReduction.dll,Windows.CloudStore.dll,Windows.CloudStore.Schema.Shell.dll,mscms.dll,TaskFlowDataEngine.dll,cdp.dll,WS2_32.dll,ncrypt.dll,IPHLPAPI.DLL,WINHTTP.dll,NTASN1.dll,ActXPrxy.dll,TortoiseOverlays.dll,Windows.Networking.Connectivity.dll,TortoiseStub.dll,TortoiseSVN.dll,WININET.dll,intl3_tsvn.dll,libapr_tsvn.dll,VCRUNTIME140.dll,MSVCP140.dll,libsvn_tsvn.dll,MSWSOCK.dll,libsasl.dll,libaprutil_tsvn.dll,WLDAP32.dll,NInput.dll,crshhndl.dll,vm3dum64.dll,D3D10Level9.dll,UIAnimation.dll,cryptngc.dll,ClassicStartMenuDLL.dll,MSIMG32.dll,LOGONCLI.DLL,rmclient.dll,wshirda.dll,fontext.dll,MPR.dll,DeviceCenter.dll,DUI70.dll,MFPlat.DLL,RTWorkQ.DLL,stobject.dll,WMICLNT.dll,InputSwitch.dll,BatMeter.dll,Windows.UI.Shell.dll,sxs.dll,es.dll,prnfldr.dll,Windows.Internal.Shell.Broker.dll,ntoskrnl.exe,atlthunk.dll,dxp.dll,SETUPAPI.dll,SHDOCVW.dll,Actioncenter.dll,wevtapi.dll,Syncreg.dll,wpdshserviceobj.dll,PortableDeviceTypes.dll,AUDIOSES.DLL,AVRT.dll,PortableDeviceApi.dll,SettingMonitor.dll,msxml6.dll,pnidui.dll,cscui.dll,netprofm.dll,cscobj.dll,npmproxy.dll,NetworkUXBroker.dll,EthernetMediaManager.dll,SyncCenter.dll,wlanapi.dll,NotificationObjFactory.dll,NSI.dll,imapi2.dll,rsaenh.dll,imagehlp.dll,hgcpl.dll,DUser.dll,provsvc.dll,gpapi.dll,bthprops.cpl,dhcpcsvc6.DLL,dhcpcsvc.DLL,UxTSB.dll,wdmaud.drv,ksuser.dll,msacm32.drv,MSACM32.dll,midimap.dll,MLANG.dll,gdiplus.dll,msi.dll,wscinterop.dll,WSCAPI.dll,wscui.cpl,werconcpl.dll,framedynos.dll,wer.dll,hcproviders.dll,ieproxy.dll,vmhgfs.dll,drprov.dll,ntlanman.dll,davclnt.dll,DAVHLPR.dll" "fontdrvhost.exe","1044","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,ucrtbase.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,USER32.dll,win32u.dll,IMM32.DLL" "fontdrvhost.exe","132","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,ucrtbase.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,USER32.dll,win32u.dll" "gsort.exe","4984","ntdll.dll,wow64.dll,wow64win.dll,wow64cpu.dll" "lsass.exe","844","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,RPCRT4.dll,lsasrv.dll,msvcrt.dll,WS2_32.dll,SspiCli.dll,sechost.dll,MSASN1.dll,samsrv.dll,ucrtbase.dll,CRYPT32.dll,bcrypt.dll,ncrypt.dll,NTASN1.dll,bcryptprimitives.dll,msprivs.DLL,netprovfw.dll,JOINUTIL.DLL,negoexts.DLL,CRYPTBASE.dll,CRYPTSP.dll,kerberos.DLL,KerbClientShared.dll,cryptdll.dll,mswsock.dll,msv1_0.DLL,NtlmShared.dll,netlogon.DLL,powrprof.dll,advapi32.dll,USERENV.dll,profapi.dll,gmsaclient.dll,WLDAP32.dll,netutils.dll,DNSAPI.dll,NSI.dll,IPHLPAPI.DLL,tspkg.DLL,pku2u.DLL,cloudAP.DLL,MicrosoftAccountCloudAP.dll,combase.dll,DPAPI.DLL,rsaenh.dll,wdigest.DLL,schannel.DLL,PCPKsp.dll,ntmarta.dll,tbs.dll,efslsaext.dll,dpapisrv.dll,SspiSrv.dll,scecli.DLL,winsta.dll,DSPARSE.dll,wevtapi.dll,vaultsvc.dll,logoncli.dll,certpoleng.dll,ncryptsslp.dll,ncryptprov.dll,dssenh.dll,gpapi.dll,mskeyprotect.dll" "msdtc.exe","3948","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,combase.dll,ucrtbase.dll,RPCRT4.dll,bcryptPrimitives.dll,msvcrt.dll,MSDTCTM.dll,OLEAUT32.dll,msvcp_win.dll,sechost.dll,ole32.dll,GDI32.dll,gdi32full.dll,USER32.dll,win32u.dll,WS2_32.dll,ADVAPI32.dll,MSDTCPRX.dll,MTXCLU.DLL,WINMM.dll,CLUSAPI.dll,bcrypt.dll,XOLEHLP.dll,MSWSOCK.dll,DNSAPI.dll,NSI.dll,ktmw32.dll,RESUTILS.dll,CRYPTSP.dll,WINMMBASE.dll,cfgmgr32.dll,MSDTCLOG.dll,IPHLPAPI.DLL,kernel.appcore.dll,COMRES.DLL,msdtcVSp1res.dll,mtxoci.dll,wkscli.dll,cscapi.dll,netutils.dll,sspicli.dll,ntmarta.dll,clbcatq.dll,FirewallAPI.dll,fwbase.dll,FWPolicyIOMgr.dll" "RuntimeBroker.exe","5348","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,ucrtbase.dll,combase.dll,RPCRT4.dll,bcryptPrimitives.dll,powrprof.dll,kernel.appcore.dll,msvcrt.dll,ole32.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,USER32.dll,win32u.dll,sechost.dll,IMM32.DLL,clbcatq.dll,windows.storage.dll,advapi32.dll,shlwapi.dll,shcore.dll,profapi.dll,uxtheme.dll,OLEAUT32.dll" "sed.exe","3512","ntdll.dll,wow64.dll,wow64win.dll,wow64cpu.dll" "ShellExperienceHost.exe","5044","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,combase.dll,ucrtbase.dll,wincorlib.DLL,RPCRT4.dll,OLEAUT32.dll,bcryptPrimitives.dll,msvcp_win.dll,kernel.appcore.dll,Windows.UI.Xaml.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,shcore.dll,Bcp47Langs.dll,iertutil.dll,CoreMessaging.dll,sechost.dll,advapi32.dll,IMM32.DLL,twinapi.appcore.dll,bcrypt.dll,WinTypes.dll,Windows.UI.dll,TextInputFramework.dll,CoreUIComponents.dll,ntmarta.dll,usermgrcli.dll,OneCoreUAPCommonProxyStub.dll,uxtheme.dll,dwmapi.dll,urlmon.dll,windows.storage.dll,shlwapi.dll,powrprof.dll,profapi.dll,CRYPTBASE.DLL,dxgi.dll,d3d11.dll,dbghelp.dll,vm3dum64.dll,D3D10Level9.dll,StartUI.dll,StartTileData.dll,XmlLite.dll,cryptsp.dll,SspiCli.dll,d2d1.dll,CRYPT32.dll,MSASN1.dll,Windows.UI.Shell.SharedUtilities.dll,QuickActions.dll,Windows.UI.ActionCenter.dll,ole32.dll,mrmcorer.dll,QuickActionsDataModel.dll,msctf.dll,UiaManager.dll,windows.ui.core.textinput.dll,Windows.UI.Immersive.dll,DataExchange.dll,dcomp.dll,Windows.Storage.ApplicationData.dll,logoncli.dll,Windows.CloudStore.dll,USERENV.dll,Windows.CloudStore.Schema.Shell.dll,appresolver.dll,elscore.dll,SLC.dll,PROPSYS.dll,sppc.dll,threadpoolwinrt.dll,VEEventDispatcher.dll,msvcp110_win.dll,Windows.Shell.UnifiedTile.CuratedTileCollections.dll,clipc.dll,Windows.StateRepository.dll,StateRepository.Core.dll,policymanager.dll,Windows.Globalization.dll,dwrite.dll,twinapi.dll,Windows.Graphics.dll,Windows.Globalization.Fontgroups.dll,fontgroupsoverride.dll,NotificationObjFactory.dll,directmanipulation.dll,rmclient.dll,globcollationhost.dll,windowscodecs.dll,winsta.dll,PhotoMetadataHandler.dll,RTMediaFrame.dll" "ShellFolderFixUI.exe","5584","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,USER32.dll,win32u.dll,GDI32.dll,UxTheme.dll,msvcrt.dll,gdi32full.dll,msvcp_win.dll,combase.dll,ucrtbase.dll,RPCRT4.dll,bcryptPrimitives.dll,COMDLG32.dll,shcore.dll,MSIMG32.dll,SHLWAPI.dll,SHELL32.dll,COMCTL32.dll,cfgmgr32.dll,windows.storage.dll,advapi32.dll,sechost.dll,kernel.appcore.dll,powrprof.dll,profapi.dll,ole32.dll,WINSPOOL.DRV,OLEAUT32.dll,bcrypt.dll,IMM32.dll,gdiplus.dll,WININET.dll,WINMM.dll,winmmbase.dll,dwmapi.dll,ShellFolderFix.dll,MSCTF.dll,TextInputFramework.dll,CoreUIComponents.dll,CoreMessaging.dll,ntmarta.dll,usermgrcli.dll,wintypes.dll" "sihost.exe","4380","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,combase.dll,ucrtbase.dll,RPCRT4.dll,bcryptPrimitives.dll,sechost.dll,advapi32.dll,ntmarta.dll,CoreUIComponents.dll,CoreMessaging.dll,kernel.appcore.dll,user32.dll,win32u.dll,gdi32.dll,wintypes.dll,gdi32full.dll,msvcp_win.dll,SHCORE.dll,usermgrcli.dll,IMM32.DLL,clbcatq.dll,desktopshellext.dll,shlwapi.dll,wtsapi32.dll,WINSTA.dll,Windows.Shell.ServiceHostBuilder.dll,OneCoreUAPCommonProxyStub.dll,modernexecserver.dll,ResourcePolicyClient.dll,OLEAUT32.dll,twinapi.appcore.dll,powrprof.dll,bcrypt.dll,uxtheme.dll,ClipboardServer.dll,RMCLIENT.dll,activationmanager.dll,AppointmentActivation.dll,ole32.dll,usermgrproxy.dll,ExecModelClient.dll,windowmanagement.dll,NotificationPlatformComponent.dll,AppContracts.dll,ShareHost.dll,Windows.Storage.dll,profapi.dll,msvcp110_win.dll,WpPortingLibrary.dll,OneCoreCommonProxyStub.dll,Windows.System.Launcher.dll,dsclient.dll,execmodelproxy.dll,twinui.appcore.dll,UiaManager.dll,Windows.StateRepository.dll,StateRepository.Core.dll,daxexec.dll,FLTLIB.DLL,container.dll,IPHLPAPI.DLL,mssrch.dll,cryptdll.dll,ESENT.dll,TQUERY.DLL,licensemanagerapi.dll,dwmapi.dll" "spoolsv.exe","2288","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,USER32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,ucrtbase.dll,msvcrt.dll,sechost.dll,RPCRT4.dll,advapi32.dll,DNSAPI.dll,WS2_32.dll,bcrypt.dll,NSI.dll,IPHLPAPI.DLL,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,SspiCli.dll,powrprof.dll,mswsock.dll,WTSAPI32.dll,WINSTA.dll,WINNSI.DLL,rasadhlp.dll,fwpuclnt.dll,localspl.dll,CRYPT32.dll,MSASN1.dll,cfgmgr32.dll,srvcli.dll,SETUPAPI.dll,sfc_os.dll,SPOOLSS.DLL,ole32.dll,Secur32.dll,winspool.drv,PrintIsolationProxy.dll,AppMon.dll,profapi.dll,hpinkstsBB11LM.dll,OLEAUT32.dll,SHLWAPI.dll,PSAPI.DLL,USERENV.dll,SHELL32.dll,shcore.dll,windows.storage.dll,VERSION.dll,IPPMon.dll,wshirda.dll,tcpmon.dll,snmpapi.dll,wsnmp32.dll,usbmon.dll,DEVOBJ.dll,WINTRUST.dll,WSDMon.dll,wsdapi.dll,netutils.dll,deviceassociation.dll,WINHTTP.dll,webservices.dll,FirewallAPI.dll,fwbase.dll,clbcatq.dll,msxml6.dll,FunDisc.dll,XmlLite.dll,fdPnp.dll,ATL.DLL,WSDCHNGR.DLL,drvstore.dll,dhcpcsvc6.DLL,dhcpcsvc.DLL,winprint.dll,gpapi.dll,DSROLE.dll,win32spl.dll,CRYPTSP.dll,rsaenh.dll,CRYPTBASE.dll,cscapi.dll,bidispl.dll,WSDPrintProxy.dll,webio.dll,ondemandconnroutehelper.dll,HTTPAPI.dll" "svchost.exe","1000","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,umpnpmgr.dll,msvcrt.dll,WLDP.DLL,combase.dll,bcryptPrimitives.dll,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,advapi32.dll" "svchost.exe","1068","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,dhcpcore.dll,WS2_32.dll,DNSAPI.dll,powrprof.dll,NSI.dll,IPHLPAPI.DLL,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,advapi32.dll,firewallapi.dll,fwbase.dll,dhcpcore6.dll,SspiCli.dll,WINNSI.DLL,mswsock.dll,CRYPTBASE.dll,dhcpcsvc6.DLL,dhcpcsvc.DLL" "svchost.exe","1116","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,termsrv.dll,WS2_32.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,advapi32.dll,clbcatq.dll,lsmproxy.dll,sspicli.dll,REGAPI.dll,rdpcorets.dll,OLEAUT32.dll,IPHLPAPI.DLL,SHELL32.dll,cfgmgr32.dll,shcore.dll,windows.storage.dll,shlwapi.dll,powrprof.dll,profapi.dll,SETUPAPI.dll,rfxvmt.dll,pdh.dll,RDPBASE.dll,RDPSERVERBASE.dll,USERENV.dll,WINHTTP.dll,tlscsp.dll,CRYPTSP.dll,ntmarta.dll,bcrypt.dll,CRYPTBASE.dll,AUTHZ.dll,ncrypt.dll,PROPSYS.dll,NTASN1.dll,DPAPI.DLL,wer.dll,umb.dll,ATL.DLL,DEVOBJ.dll,mswsock.dll,winsta.dll" "svchost.exe","1188","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,dnsrslvr.dll,WS2_32.dll,NSI.dll,DNSAPI.dll,WINNSI.DLL,IPHLPAPI.DLL,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,advapi32.dll,Fwpuclnt.dll,bcrypt.dll,dnsext.dll,USERENV.dll,profapi.dll,gpapi.dll,dhcpcsvc6.DLL,dhcpcsvc.DLL,mswsock.dll,CRYPTBASE.dll" "svchost.exe","1252","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,lmhsvc.dll,WS2_32.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,advapi32.dll,nrpsrv.DLL,mswsock.dll,DNSAPI.dll,NSI.dll,IPHLPAPI.DLL,winrnr.dll,rasadhlp.dll,NLAapi.dll,pnrpnsp.dll,napinsp.dll,fwpuclnt.dll,bcrypt.dll" "svchost.exe","1320","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,wevtsvc.dll,WS2_32.dll,bcrypt.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,advapi32.dll,powrprof.dll,sspicli.dll,mswsock.dll,gpapi.dll" "svchost.exe","1368","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,themeservice.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,advapi32.dll,winsta.dll,ntmarta.dll" "svchost.exe","1376","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,profsvc.dll,OLEAUT32.dll,advapi32.dll,profapi.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,SYSNTFY.dll,profsvcext.dll,WLDAP32.dll,USERENV.dll,SHELL32.dll,netutils.dll,cfgmgr32.dll,shcore.dll,windows.storage.dll,shlwapi.dll,powrprof.dll,logoncli.dll,clbcatq.dll,gpapi.dll,SspiCli.dll,shacctprofile.dll,SAMLIB.dll,ntmarta.dll,CredentialMigrationHandler.dll,WTSAPI32.dll,Windows.CloudStore.dll,wintypes.dll,SettingSync.dll,wevtapi.dll,bcrypt.dll" "svchost.exe","1384","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,es.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,advapi32.dll,clbcatq.dll,OLEAUT32.dll,sxs.dll,ole32.dll,PROPSYS.dll,shcore.dll" "svchost.exe","144","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,umpo.dll,WLDP.DLL,msvcrt.dll,combase.dll,bcryptPrimitives.dll,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,advapi32.dll,umpoext.dll,cfgmgr32.dll,powrprof.dll,shcore.dll,tdh.dll,dxgi.dll,win32u.dll,gdi32.dll,gdi32full.dll,msvcp_win.dll,USER32.dll,mintdh.dll,OLEAUT32.dll,gpapi.dll,HID.DLL,windows.storage.dll,shlwapi.dll,kernel.appcore.dll,profapi.dll,rpcss.dll,SspiCli.dll,bisrv.dll,ntmarta.dll,EventAggregation.dll,ResourcePolicyClient.dll,psmsrv.dll,DEVOBJ.dll,twinapi.appcore.dll,bcrypt.dll,clbcatq.dll,embeddedmodesvcapi.dll,psmserviceexthost.dll,resourcepolicyserver.dll,CRYPTSP.dll,systemeventsbrokerserver.dll,BrokerLib.dll,DAB.dll,bi.dll,usermgrcli.dll,CRYPTBASE.DLL,rsaenh.dll,licensemanagerapi.dll,msvcp110_win.dll,wtsapi32.dll,WINSTA.dll,OneCoreUAPCommonProxyStub.dll,RmClient.dll,BackgroundMediaPolicy.dll,ACPBackgroundManagerPolicy.dll,CbtBackgroundManagerPolicy.dll,SmartCardBackgroundPolicy.dll,Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll,SebBackgroundManagerPolicy.dll,ole32.dll,coml2.dll,OneCoreCommonProxyStub.dll,execmodelproxy.dll,execmodelclient.dll,CoreMessaging.dll,USERENV.dll,capauthz.dll" "svchost.exe","1500","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,sens.dll,SYSNTFY.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,advapi32.dll,WS2_32.dll,WTSAPI32.dll,WINSTA.dll,clbcatq.dll,ES.DLL,OLEAUT32.dll,sxs.dll,ole32.dll,ntmarta.dll,WMICLNT.dll" "svchost.exe","1536","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,audioendpointbuilder.dll,cfgmgr32.dll,shcore.dll,MMDevAPI.DLL,PROPSYS.dll,DEVOBJ.dll,OLEAUT32.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,advapi32.dll,clbcatq.dll,powrprof.dll,wtsapi32.dll,WINSTA.dll" "svchost.exe","1580","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,schedsvc.dll,OLEAUT32.dll,UBPM.dll,EventAggregation.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,advapi32.dll,AUTHZ.dll,POWRPROF.dll,WMICLNT.dll,sspicli.dll,bcrypt.dll,taskcomp.dll,cryptsp.dll,ntmarta.dll,WPTaskScheduler.dll,CSystemEventsBrokerClient.dll,wkscli.dll,netjoin.dll,WS2_32.dll,mswsock.dll,JoinUtil.dll,wtsapi32.dll,netutils.dll,WINSTA.dll,DABAPI.dll,TimeBrokerClient.dll,CRYPTBASE.DLL,profapi.dll,wevtapi.dll,shlwapi.dll,SHELL32.dll,cfgmgr32.dll,shcore.dll,windows.storage.dll,PROPSYS.dll,clbcatq.dll,XmlLite.dll,userenv.dll,usermgrcli.dll,apphelp.dll" "svchost.exe","1680","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,audiosrv.dll,shcore.dll,MMDevAPI.DLL,DEVOBJ.dll,PROPSYS.dll,cfgmgr32.dll,OLEAUT32.dll,AUDIOSRVPOLICYMANAGER.dll,POWRPROF.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,advapi32.dll,clbcatq.dll,winsta.dll,wtsapi32.dll,coreaudiopolicymanagerext.dll,audioses.dll,wintypes.dll,AVRT.dll,Windows.StateRepository.dll,StateRepository.Core.dll,Windows.ApplicationModel.dll,twinapi.appcore.dll,bcrypt.dll,AppXDeploymentClient.dll,deviceaccess.dll" "svchost.exe","1712","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,umrdp.dll,ADVAPI32.dll,WINSPOOL.DRV,bcrypt.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,clbcatq.dll,umb.dll,ATL.DLL,SETUPAPI.dll,cfgmgr32.dll,DEVOBJ.dll,PROPSYS.dll,OLEAUT32.dll,shcore.dll,WINSTA.dll" "svchost.exe","1768","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,windows.staterepository.dll,advapi32.dll,StateRepository.Core.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,CRYPTBASE.DLL,clbcatq.dll" "svchost.exe","1820","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,coremessaging.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,advapi32.dll,bfe.dll,WS2_32.dll,AUTHZ.dll,SspiCli.dll,wevtapi.dll,bcrypt.dll,ktmw32.dll" "svchost.exe","1944","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,certprop.dll,cfgmgr32.dll,ADVAPI32.dll,bcrypt.dll,SETUPAPI.dll,SspiCli.dll,WINSTA.dll,WTSAPI32.dll,WMsgAPI.dll,WinSCard.dll,DEVOBJ.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll" "svchost.exe","1960","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,nsisvc.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,advapi32.dll,NSI.dll" "svchost.exe","2004","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,usermgr.dll,advapi32.dll,USERENV.dll,SspiCli.dll,profapi.dll,ntmarta.dll,wintypes.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,clbcatq.dll,usermgrproxy.dll,OLEAUT32.dll,wtsapi32.dll,WINSTA.dll" "svchost.exe","2016","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,timebrokerserver.dll,powrprof.dll,BrokerLib.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,advapi32.dll,bi.dll,clbcatq.dll,twinapi.appcore.dll,bcrypt.dll,usermgrcli.dll,ole32.dll,coml2.dll,OneCoreCommonProxyStub.dll,execmodelproxy.dll" "svchost.exe","2076","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,shsvcs.dll,cfgmgr32.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,advapi32.dll,clbcatq.dll,DEVOBJ.dll,FVEAPI.dll,bcrypt.dll,ProximityService.dll,WS2_32.dll,OLEAUT32.dll,ProximityCommon.dll,IPHLPAPI.DLL,MSWSOCK.dll,ProximityCommonPal.dll,ProximityServicePAL.dll,powrprof.dll,firewallapi.dll,fwbase.dll,wtsapi32.dll,WINSTA.dll,HID.DLL,OneCoreUAPCommonProxyStub.dll" "svchost.exe","2120","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,wkssvc.dll,netutils.dll,USERENV.dll,bcrypt.dll,profapi.dll,DSPARSE.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,advapi32.dll,SspiCli.dll,IPHLPAPI.DLL,WINNSI.DLL,NSI.dll,gpapi.dll,dsreg.dll,cryptsp.dll,msvcp110_win.dll,netjoin.dll,JOINUTIL.DLL,OLEAUT32.dll,clbcatq.dll,taskschd.dll" "svchost.exe","2220","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,sessenv.dll,SYSNTFY.dll,SHELL32.dll,cfgmgr32.dll,shcore.dll,windows.storage.dll,advapi32.dll,shlwapi.dll,powrprof.dll,profapi.dll,samcli.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,USERENV.dll,gpapi.dll,SETUPAPI.dll,DEVOBJ.dll,sspicli.dll,WS2_32.dll,mswsock.dll,DSROLE.dll,CRYPTSP.dll,rsaenh.dll,bcrypt.dll,DPAPI.dll,CRYPTBASE.dll,ncrypt.dll,NTASN1.dll,OLEAUT32.dll" "svchost.exe","2472","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,ikeext.dll,WS2_32.dll,MSASN1.dll,AUTHZ.dll,NSI.dll,CRYPTSP.dll,fwpuclnt.dll,bcrypt.dll,WLDP.DLL,CRYPT32.dll,WINTRUST.dll,advapi32.dll,mswsock.dll,SspiCli.dll,IPHLPAPI.DLL,dhcpcsvc6.DLL,dhcpcsvc.DLL,WINNSI.DLL,rsaenh.dll,CRYPTBASE.dll" "svchost.exe","2480","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,ipsecsvc.dll,msvcrt.dll,AUTHZ.dll,FirewallAPI.dll,fwpuclnt.dll,combase.dll,bcrypt.dll,bcryptPrimitives.dll,FwRemoteSvr.DLL,fwbase.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,advapi32.dll,kernel.appcore.dll,clbcatq.dll,OLEAUT32.dll,msvcp_win.dll,WS2_32.dll,mswsock.dll,IPHLPAPI.DLL,NSI.dll,dhcpcsvc6.DLL,dhcpcsvc.DLL,sspicli.dll" "svchost.exe","2656","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,wmisvc.dll,wbemcomn.dll,WS2_32.dll,bcrypt.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,advapi32.dll,clbcatq.dll,WMICLNT.dll,vssapi.dll,VssTrace.DLL,OLEAUT32.dll,samcli.dll,netutils.dll,SAMLIB.dll,PROPSYS.dll,shcore.dll,wbemcore.dll,esscli.dll,FastProx.dll,wbemsvc.dll,authZ.dll,wmiutils.dll,repdrvfs.dll,wmiprvsd.dll,NCObjAPI.DLL,wbemess.dll,cryptsp.dll,rsaenh.dll,CRYPTBASE.dll,SspiCli.dll,ncprov.dll" "svchost.exe","2664","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,dps.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,advapi32.dll,clbcatq.dll,taskschd.dll,OLEAUT32.dll,gpapi.dll,wdi.dll,srumsvc.dll,IPHLPAPI.DLL,ESENT.dll,CRYPTBASE.DLL,nduprov.dll,eeprov.dll,powrprof.dll,shcore.dll,DEVOBJ.dll,cfgmgr32.dll,appsruprov.dll,wpnsruprov.dll,ncuprov.dll,NSI.dll,WINNSI.DLL,energyprov.dll,windows.storage.dll,shlwapi.dll,profapi.dll,srumapi.dll,ole32.dll,radardt.dll,ntmarta.dll,WTSAPI32.dll,WINSTA.dll" "svchost.exe","2672","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,das.dll,cfgmgr32.dll,RMCLIENT.dll,advapi32.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,SspiCli.dll,profapi.dll" "svchost.exe","2688","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,trkwks.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,advapi32.dll,cfgmgr32.dll" "svchost.exe","2700","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,tileobjserver.dll,profapi.dll,msvcp110_win.dll,advapi32.dll,shcore.dll,urlmon.dll,iertutil.dll,windows.storage.dll,shlwapi.dll,powrprof.dll,CRYPTBASE.DLL,ESENT.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,clbcatq.dll,USERENV.dll,wtsapi32.dll,WINSTA.dll,SspiCli.dll,OneCoreUAPCommonProxyStub.dll,Windows.StateRepository.dll,StateRepository.Core.dll,Bcrypt.dll" "svchost.exe","2708","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,nlasvc.dll,cfgmgr32.dll,IPHLPAPI.DLL,dhcpcsvc.DLL,WINNSI.DLL,NSI.dll,WS2_32.dll,ncsi.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,advapi32.dll,sspicli.dll,ssdpapi.dll,powrprof.dll,WMICLNT.dll,dhcpcsvc6.DLL,bcrypt.dll,mswsock.dll,wshqos.dll,wshtcpip.DLL,wship6.dll,WlanApi.dll,profapi.dll,wkscli.dll,netutils.dll,wevtapi.dll,USERENV.dll,gpapi.dll,wtsapi32.dll,WINSTA.dll,DEVOBJ.dll,DNSAPI.dll,WINHTTP.dll" "svchost.exe","2732","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,cryptsvc.dll,CRYPT32.dll,MSASN1.dll,bcrypt.dll,WLDP.DLL,WINTRUST.dll,advapi32.dll,crypttpmeksvc.dll,OLEAUT32.dll,cryptcatsvc.dll,vssapi.dll,WS2_32.dll,VssTrace.DLL,samcli.dll,netutils.dll,SAMLIB.dll,clbcatq.dll,ES.DLL,PROPSYS.dll,shcore.dll,ESENT.dll" "svchost.exe","2956","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,wdi.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,advapi32.dll,perftrack.dll" "svchost.exe","2988","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,srvsvc.dll,cfgmgr32.dll,WS2_32.dll,IPHLPAPI.DLL,NSI.dll,WINNSI.DLL,WMICLNT.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,advapi32.dll,netutils.dll,SSCORE.DLL,sscoreext.dll,mi.dll,miutils.dll,wmidcom.dll,SspiCli.dll,DPAPI.DLL,FirewallAPI.DLL,fwbase.dll,RESUTILS.DLL,bcrypt.dll,CLUSAPI.dll,DNSAPI.dll,DSROLE.dll,mswsock.dll,rasadhlp.dll,dhcpcsvc6.DLL,dhcpcsvc.DLL,USERENV.dll,profapi.dll,gpapi.dll,OLEAUT32.dll,clbcatq.dll" "svchost.exe","3056","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,iphlpsvc.dll,cfgmgr32.dll,IPHLPAPI.DLL,advapi32.dll,NSI.dll,MSWSOCK.dll,WINNSI.DLL,FirewallAPI.dll,fwpuclnt.dll,WS2_32.dll,bcrypt.dll,NetSetupApi.dll,rtutils.dll,fwbase.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,setupapi.dll,sqmapi.dll,httpprxm.dll,adhsvc.dll,OLEAUT32.dll,httpprxc.dll,SspiCli.dll,wtsapi32.dll,powrprof.dll,WINSTA.dll,clbcatq.dll,DEVOBJ.dll,NetSetupShim.dll,WDSCORE.dll,netprofm.dll,cryptsp.dll,rsaenh.dll,WINHTTP.dll,CRYPTBASE.dll,WMICLNT.dll,wkscli.dll,netutils.dll,ACTIVEDS.dll,adsldpc.dll,WLDAP32.dll,DNSAPI.dll,ole32.dll,adsldp.dll,sxs.dll,NETAPI32.DLL,SECUR32.DLL,cscapi.dll,LOGONCLI.DLL,npmproxy.dll,hnetcfgclient.dll,wbemprox.dll,wbemcomn.dll,wbemsvc.dll,fastprox.dll,FWPolicyIOMgr.dll,dhcpcsvc6.DLL,dhcpcsvc.DLL" "svchost.exe","3332","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,netprofmsvc.dll,NSI.dll,nlaapi.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,advapi32.dll,clbcatq.dll,npmproxy.dll,ole32.dll,IPHLPAPI.DLL,windows.devices.radios.dll,OLEAUT32.dll,cfgmgr32.dll,WINNSI.DLL,WS2_32.dll,gpapi.dll,mswsock.dll" "svchost.exe","4704","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,winhttp.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,advapi32.dll,WS2_32.dll,mswsock.dll,IPHLPAPI.DLL,WINNSI.DLL,NSI.dll,powrprof.dll,dhcpcsvc6.DLL,DNSAPI.dll,dhcpcsvc.DLL,rasadhlp.dll,CFGMGR32.dll" "svchost.exe","5576","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,combase.dll,bcryptPrimitives.dll,kernel.appcore.dll,msvcrt.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,wscsvc.dll,netutils.dll,FirewallAPI.dll,fwbase.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,advapi32.dll,OLEAUT32.dll,clbcatq.dll,wbemprox.dll,WS2_32.dll,wbemcomn.dll,bcrypt.dll,wbemsvc.dll,fastprox.dll,ole32.dll,WINHTTP.dll,sspicli.dll,USERENV.dll,profapi.dll,gpapi.dll" "svchost.exe","588","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,lsm.dll,msvcrt.dll,combase.dll,bcryptPrimitives.dll,advapi32.dll,WLDP.DLL,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,SYSNTFY.dll,sspicli.dll,Userenv.dll,profapi.dll,DEVOBJ.dll,cfgmgr32.dll,kernel.appcore.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,clbcatq.dll,lsmproxy.dll" "svchost.exe","8","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,sechost.dll,RPCRT4.dll,ucrtbase.dll,rpcepmap.dll,WLDP.DLL,msvcrt.dll,combase.dll,bcryptPrimitives.dll,CRYPT32.dll,MSASN1.dll,WINTRUST.dll,advapi32.dll,sspicli.dll,RpcRtRemote.dll,rpcss.dll,WS2_32.dll,mswsock.dll,powrprof.dll,FirewallAPI.dll,fwbase.dll,clbcatq.dll,wshhyperv.dll,fwpuclnt.dll,bcrypt.dll,kernel.appcore.dll,OLEAUT32.dll,msvcp_win.dll,wtsapi32.dll,WINSTA.dll,capauthz.dll,shcore.dll" "taskhostw.exe","4448","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,RPCRT4.dll,combase.dll,ucrtbase.dll,bcryptPrimitives.dll,OLEAUT32.dll,msvcp_win.dll,imm32.dll,USER32.dll,win32u.dll,GDI32.dll,gdi32full.dll,kernel.appcore.dll,sechost.dll,uxtheme.dll,dwmapi.dll,clbcatq.dll,MsCtfMonitor.dll,MSCTF.dll,WINSTA.dll,MSUTB.dll,PlaySndSrv.dll,wininet.dll,iertutil.dll,advapi32.dll,shcore.dll,InputService.dll,TextInputFramework.dll,CoreUIComponents.dll,CoreMessaging.dll,wintypes.dll,ntmarta.dll,usermgrcli.dll,EditBufferTestHook.dll,ESENT.dll,ole32.dll,windows.storage.dll,shlwapi.dll,powrprof.dll,profapi.dll,MTFServer.dll,WINMM.dll,WINMMBASE.dll,cfgmgr32.dll,InputLocaleManager.dll,kbdus.dll,inputhost.dll,CRYPTBASE.DLL" "tasklist.exe","5340","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,ADVAPI32.dll,msvcrt.dll,sechost.dll,RPCRT4.dll,USER32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,ucrtbase.dll,OLEAUT32.dll,combase.dll,VERSION.dll,MPR.dll,bcryptPrimitives.dll,WS2_32.dll,SHLWAPI.dll,framedynos.dll,dbghelp.dll,netutils.dll,SspiCli.dll,srvcli.dll,kernel.appcore.dll,clbcatq.dll,wbemprox.dll,wbemcomn.dll,bcrypt.dll,Winsta.dll,wbemsvc.dll,fastprox.dll,wmiutils.dll" "TSVNCache.exe","4992","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,USER32.dll,win32u.dll,libsvn_tsvn.dll,GDI32.dll,libapr_tsvn.dll,gdi32full.dll,msvcp_win.dll,ucrtbase.dll,WS2_32.dll,ADVAPI32.dll,libaprutil_tsvn.dll,SHELL32.dll,sechost.dll,msvcrt.dll,RPCRT4.dll,cfgmgr32.dll,WLDAP32.dll,ole32.dll,shcore.dll,combase.dll,intl3_tsvn.dll,libsasl.dll,windows.storage.dll,bcryptPrimitives.dll,shlwapi.dll,CRYPT32.dll,kernel.appcore.dll,MSASN1.dll,powrprof.dll,profapi.dll,VCRUNTIME140.dll,MSWSOCK.dll,Secur32.dll,VERSION.dll,MSVCP140.dll,CRYPTBASE.DLL,SSPICLI.DLL,IMM32.DLL,crshhndl.dll,uxtheme.dll,PROPSYS.dll,OLEAUT32.dll,ntmarta.dll,MSCTF.dll,dwmapi.dll" "vmtoolsd.exe","2744","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,ADVAPI32.dll,msvcrt.dll,sechost.dll,RPCRT4.dll,ole32.dll,combase.dll,ucrtbase.dll,bcryptPrimitives.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,USER32.dll,win32u.dll,VERSION.dll,glib-2.0.dll,MSVCR90.dll,intl.dll,WS2_32.dll,SHELL32.dll,cfgmgr32.dll,shcore.dll,windows.storage.dll,shlwapi.dll,kernel.appcore.dll,powrprof.dll,profapi.dll,WINMM.dll,WINMMBASE.dll,vmtools.dll,iconv.dll,pcre.dll,OLEAUT32.dll,CRYPT32.dll,MSASN1.dll,gmodule-2.0.dll,gobject-2.0.dll,IpHlpApi.dll,SspiCli.dll,ntmarta.dll,hgfsServer.dll,hgfs.dll,MPR.dll,hgfsUsability.dll,USERENV.dll,vix.dll,Secur32.dll,autoLogon.dll,MSVCP90.dll,autoUpgrade.dll,WTSAPI32.dll,bitMapper.dll,deployPkgPlugin.dll,deployPkg.dll,diskWiper.dll,grabbitmqProxy.dll,guestInfo.dll,hwUpgradeHelper.dll,SETUPAPI.dll,gthread-2.0.dll,powerOps.dll,resolutionSet.dll,PSAPI.DLL,timeSync.dll,vmbackup.dll,libeay32.dll,ssleay32.dll,CRYPTSP.dll,rsaenh.dll,bcrypt.dll,CRYPTBASE.dll,clbcatq.dll,wbemprox.dll,wbemcomn.dll,NSI.dll,dhcpcsvc6.DLL,dhcpcsvc.DLL,wbemsvc.dll,mswsock.dll,wshqos.dll,wshtcpip.DLL,wship6.dll,fastprox.dll,comsvcs.dll,sxs.dll,wmiutils.dll,DNSAPI.dll,WINNSI.DLL,WmiPerfInst.dll,pdh.dll,perfos.dll" "vmtoolsd.exe","5424","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,ADVAPI32.dll,msvcrt.dll,sechost.dll,RPCRT4.dll,ole32.dll,combase.dll,ucrtbase.dll,bcryptPrimitives.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,USER32.dll,win32u.dll,intl.dll,VERSION.dll,MSVCR90.dll,glib-2.0.dll,vmtools.dll,WS2_32.dll,SHELL32.dll,cfgmgr32.dll,OLEAUT32.dll,shcore.dll,CRYPT32.dll,WINMM.dll,windows.storage.dll,MSASN1.dll,pcre.dll,shlwapi.dll,iconv.dll,kernel.appcore.dll,powrprof.dll,profapi.dll,WINMMBASE.dll,gmodule-2.0.dll,gobject-2.0.dll,IMM32.DLL,IpHlpApi.dll,SspiCli.dll,uxtheme.dll,MSCTF.dll,hgfsServer.dll,hgfs.dll,MPR.dll,hgfsUsability.dll,USERENV.dll,vix.dll,Secur32.dll,desktopEvents.dll,MSVCP90.dll,WTSAPI32.dll,dndcp.dll,sigc-2.0.dll,unity.dll,PSAPI.DLL,dwmapi.dll,glibmm-2.4.dll,WINSTA.dll,TextInputFramework.dll,CoreMessaging.dll,CoreUIComponents.dll,ntmarta.dll,wintypes.dll,usermgrcli.dll,clbcatq.dll,dataexchange.dll,d3d11.dll,dcomp.dll,dxgi.dll,twinapi.appcore.dll,bcrypt.dll,VMToolsHook64.dll,gdiplus.dll,PROPSYS.dll,comctl32.dll,WindowsCodecs.dll,msxml3.dll,AppxPackaging.dll,urlmon.dll,XmlLite.dll,OpcServices.DLL,iertutil.dll,CRYPTBASE.DLL,msxml6.dll,mrmcorer.dll,Windows.UI.dll,Bcp47Langs.dll,LINKINFO.dll,apphelp.dll,gameux.dll,ieframe.dll,NETAPI32.dll,DSREG.DLL,msvcp110_win.dll,NETUTILS.DLL,cryptsp.dll,WKSCLI.DLL,msIso.dll,MLANG.dll,WININET.dll,thumbcache.dll" "Windows10FirewallControl.exe","2852","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,USER32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,ucrtbase.dll,comdlg32.dll,msvcrt.dll,combase.dll,MSIMG32.dll,RPCRT4.dll,bcryptPrimitives.dll,shcore.dll,SHLWAPI.dll,SHELL32.dll,COMCTL32.dll,cfgmgr32.dll,windows.storage.dll,advapi32.dll,sechost.dll,kernel.appcore.dll,powrprof.dll,profapi.dll,ole32.dll,WINSPOOL.DRV,OLEAUT32.dll,WS2_32.dll,bcrypt.dll,NETAPI32.dll,VERSION.dll,WINMM.dll,iphlpapi.dll,USERENV.dll,MPR.dll,WINMMBASE.dll,SAMCLI.DLL,NETUTILS.DLL,IMM32.DLL,uxtheme.dll,RICHED20.DLL,msls31.dll,USP10.dll,clbcatq.dll,sxs.dll,MSCTF.dll,TextInputFramework.dll,CoreMessaging.dll,CoreUIComponents.dll,ntmarta.dll,usermgrcli.dll,wintypes.dll,dwmapi.dll,WINNSI.DLL,NSI.dll,WindowsCodecs.dll,upnp.dll,WINHTTP.dll,SSDPAPI.dll" "Windows10FirewallService.exe","2488","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,USER32.dll,win32u.dll,fwpuclnt.dll,msvcrt.dll,GDI32.dll,gdi32full.dll,RPCRT4.dll,msvcp_win.dll,ucrtbase.dll,bcrypt.dll,ADVAPI32.dll,sechost.dll,SHELL32.dll,cfgmgr32.dll,shcore.dll,combase.dll,bcryptPrimitives.dll,windows.storage.dll,shlwapi.dll,kernel.appcore.dll,powrprof.dll,profapi.dll,ole32.dll,OLEAUT32.dll,WS2_32.dll,USERENV.dll,CRYPT32.dll,MSWSOCK.dll,MSASN1.dll,PSAPI.DLL,wevtapi.dll,iphlpapi.dll,DNSAPI.dll,NSI.dll,VERSION.dll,NETAPI32.dll,SAMCLI.DLL,NETUTILS.DLL,clbcatq.dll,secur32.dll,SSPICLI.DLL,security.dll,wshqos.dll,wshtcpip.DLL,wship6.dll,dhcpcsvc6.DLL,dhcpcsvc.DLL,sxs.dll,browcli.dll,cscapi.dll" "winlogon.exe","856","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,sechost.dll,RPCRT4.dll,combase.dll,ucrtbase.dll,bcryptPrimitives.dll,powrprof.dll,advapi32.dll,bcrypt.dll,profapi.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,IMM32.DLL,SspiCli.dll,USERENV.dll,profext.dll,ntmarta.dll,firewallapi.dll,fwbase.dll,winsta.dll,UXINIT.dll,shcore.dll,UxTheme.dll,CRYPT32.dll,MSASN1.dll,DPAPI.dll,CRYPTBASE.dll,dwminit.dll,apphelp.dll,UxTSB.dll,ole32.dll,MSIMG32.dll,dbghelp.dll,usermgrcli.dll,CRYPTSP.dll,rsaenh.dll,WindowsCodecs.dll,MPR.dll" "WizMouse.exe","5592","ntdll.dll,wow64.dll,wow64win.dll,wow64cpu.dll" "WmiPrvSE.exe","3868","ntdll.dll,KERNEL32.DLL,KERNELBASE.dll,msvcrt.dll,FastProx.dll,combase.dll,NCObjAPI.DLL,ucrtbase.dll,RPCRT4.dll,wbemcomn.dll,WS2_32.dll,bcryptPrimitives.dll,bcrypt.dll,sechost.dll,advapi32.dll,user32.dll,win32u.dll,GDI32.dll,gdi32full.dll,msvcp_win.dll,kernel.appcore.dll,clbcatq.dll,OLEAUT32.dll,wbemsvc.dll,wmiutils.dll,cimwin32.dll,powrprof.dll,framedynos.dll,SspiCli.dll,DEVOBJ.dll,cfgmgr32.dll,NSI.dll,IPHLPAPI.DLL,dhcpcsvc6.DLL,dhcpcsvc.DLL,DNSAPI.dll,winbrand.dll,SECURITY.DLL,SECUR32.DLL,schannel.DLL,CRYPT32.dll,MSASN1.dll,NETAPI32.DLL,SAMCLI.DLL,SRVCLI.DLL,NETUTILS.DLL,LOGONCLI.DLL,SCHEDCLI.DLL,WKSCLI.DLL,DSROLE.DLL,cscapi.dll,ntevt.dll,ntmarta.dll,wevtapi.dll,PROVTHRD.dll" ------------------------------------------------------------------------------------------- SCHTASKS /Query /FO CSV (states of all scheduled tasks): "\Adobe Acrobat Update Task","N/A","Disabled" "\Adobe Uninstaller","N/A","Disabled" "\AdobeAAMUpdater-1.0-W10PVM-NoelC","N/A","Disabled" "\Aero Glass","N/A","Running" "\CCleanerSkipUAC","N/A","Disabled" "\DisableLockScreen","N/A","Ready" "\DisableLockScreen","N/A","Ready" "\GoogleUpdateTaskMachineCore","N/A","Disabled" "\GoogleUpdateTaskMachineCore","N/A","Disabled" "\GoogleUpdateTaskMachineUA","N/A","Disabled" "\LogSystemInfo","5/18/2017 4:00:00 PM","Running" "\LogSystemInfo","5/18/2017 4:00:00 PM","Running" "\NISTTimeSync","5/17/2017 4:20:48 PM","Ready" "\NISTTimeSync","5/17/2017 4:29:36 PM","Ready" "\SpeechRuntimeTask","N/A","Disabled" "\WizMouse","N/A","Ready" "\WizMouse","N/A","Ready" "\Microsoft\VisualStudio\VSIX Auto Update 14","N/A","Disabled" "\Microsoft\VisualStudio\VSIX Auto Update 15.0.26430.4","N/A","Disabled" "\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319","N/A","Disabled" "\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64","N/A","Disabled" "\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Critical","N/A","Disabled" "\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Critical","N/A","Disabled" "\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)","N/A","Disabled" "\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)","N/A","Disabled" "\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)","N/A","Disabled" "\Microsoft\Windows\AppID\EDP Policy Manager","N/A","Disabled" "\Microsoft\Windows\AppID\EDP Policy Manager","N/A","Disabled" "\Microsoft\Windows\AppID\PolicyConverter","N/A","Disabled" "\Microsoft\Windows\AppID\SmartScreenSpecific","N/A","Disabled" "\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck","N/A","Disabled" "\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser","N/A","Disabled" "\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser","N/A","Disabled" "\Microsoft\Windows\Application Experience\ProgramDataUpdater","N/A","Disabled" "\Microsoft\Windows\Application Experience\StartupAppTask","N/A","Disabled" "\Microsoft\Windows\ApplicationData\appuriverifierdaily","N/A","Disabled" "\Microsoft\Windows\ApplicationData\appuriverifierinstall","N/A","Disabled" "\Microsoft\Windows\ApplicationData\appuriverifierinstall","N/A","Disabled" "\Microsoft\Windows\ApplicationData\CleanupTemporaryState","N/A","Disabled" "\Microsoft\Windows\ApplicationData\DsSvcCleanup","N/A","Disabled" "\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup","N/A","Disabled" "\Microsoft\Windows\Autochk\Proxy","N/A","Disabled" "\Microsoft\Windows\BitLocker\BitLocker MDM policy Refresh","N/A","Disabled" "\Microsoft\Windows\Bluetooth\UninstallDeviceTask","N/A","Disabled" "\Microsoft\Windows\BrokerInfrastructure\BgTaskRegistrationMaintenanceTask","N/A","Disabled" "\Microsoft\Windows\CertificateServicesClient\AikCertEnrollTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\CryptoPolicyTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\KeyPreGenTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\KeyPreGenTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\KeyPreGenTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\KeyPreGenTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\KeyPreGenTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\SystemTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\SystemTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\SystemTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\UserTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\UserTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\UserTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\UserTask","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\UserTask-Roam","N/A","Ready" "\Microsoft\Windows\CertificateServicesClient\UserTask-Roam","N/A","Ready" "\Microsoft\Windows\Chkdsk\ProactiveScan","N/A","Ready" "\Microsoft\Windows\Clip\License Validation","N/A","Disabled" "\Microsoft\Windows\CloudExperienceHost\CreateObjectTask","N/A","Disabled" "\Microsoft\Windows\Customer Experience Improvement Program\Consolidator","N/A","Disabled" "\Microsoft\Windows\Customer Experience Improvement Program\HypervisorFlightingTask","N/A","Disabled" "\Microsoft\Windows\Customer Experience Improvement Program\KernelCeipTask","N/A","Disabled" "\Microsoft\Windows\Customer Experience Improvement Program\UsbCeip","N/A","Disabled" "\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan","6/15/2017 9:56:49 AM","Ready" "\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan","6/12/2017 7:31:53 AM","Ready" "\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan for Crash Recovery","N/A","Ready" "\Microsoft\Windows\Defrag\ScheduledDefrag","N/A","Ready" "\Microsoft\Windows\Device Information\Device","5/18/2017 4:47:22 AM","Ready" "\Microsoft\Windows\Device Information\Device","5/18/2017 3:37:08 AM","Ready" "\Microsoft\Windows\Device Setup\Metadata Refresh","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\HandleCommand","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\HandleWnsCommand","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\IntegrityCheck","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\LocateCommandUserSession","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceAccountChange","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceAccountChange","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceConnectedToNetwork","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceLocationRightsChange","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePeriodic1","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePeriodic24","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePeriodic6","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePolicyChange","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePolicyChange","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceProtectionStateChanged","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceScreenOnOff","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceScreenOnOff","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceSettingChange","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceSettingChange","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterUserDevice","N/A","Disabled" "\Microsoft\Windows\DeviceDirectoryClient\RegisterUserDevice","N/A","Disabled" "\Microsoft\Windows\Diagnosis\Scheduled","N/A","Ready" "\Microsoft\Windows\DiskCleanup\SilentCleanup","N/A","Disabled" "\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector","N/A","Disabled" "\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver","N/A","Disabled" "\Microsoft\Windows\DiskFootprint\Diagnostics","N/A","Ready" "\Microsoft\Windows\DiskFootprint\StorageSense","N/A","Ready" "\Microsoft\Windows\DUSM\dusmtask","N/A","Disabled" "\Microsoft\Windows\EDP\EDP App Launch Task","N/A","Disabled" "\Microsoft\Windows\EDP\EDP Auth Task","N/A","Disabled" "\Microsoft\Windows\EDP\EDP Inaccessible Credentials Task","N/A","Disabled" "\Microsoft\Windows\EDP\StorageCardEncryption Task","N/A","Disabled" "\Microsoft\Windows\EnterpriseMgmt\MDMMaintenenceTask","N/A","Disabled" "\Microsoft\Windows\ErrorDetails\EnableErrorDetailsUpdate","N/A","Disabled" "\Microsoft\Windows\ErrorDetails\ErrorDetailsUpdate","N/A","Disabled" "\Microsoft\Windows\Feedback\Siuf\DmClient","N/A","Disabled" "\Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload","N/A","Disabled" "\Microsoft\Windows\File Classification Infrastructure\Property Definition Sync","N/A","Disabled" "\Microsoft\Windows\FileHistory\File History (maintenance mode)","N/A","Disabled" "\Microsoft\Windows\LanguageComponentsInstaller\Installation","N/A","Disabled" "\Microsoft\Windows\LanguageComponentsInstaller\Installation","N/A","Disabled" "\Microsoft\Windows\LanguageComponentsInstaller\Uninstallation","N/A","Disabled" "\Microsoft\Windows\License Manager\TempSignedLicenseExchange","N/A","Disabled" "\Microsoft\Windows\Location\Notifications","N/A","Disabled" "\Microsoft\Windows\Location\WindowsActionDialog","N/A","Disabled" "\Microsoft\Windows\Maintenance\WinSAT","N/A","Ready" "\Microsoft\Windows\Management\Provisioning\Cellular","N/A","Disabled" "\Microsoft\Windows\Management\Provisioning\Logon","N/A","Disabled" "\Microsoft\Windows\Maps\MapsToastTask","N/A","Disabled" "\Microsoft\Windows\Maps\MapsUpdateTask","N/A","Disabled" "\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents","N/A","Ready" "\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents","N/A","Ready" "\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents","N/A","Ready" "\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents","N/A","Ready" "\Microsoft\Windows\MemoryDiagnostic\RunFullMemoryDiagnostic","N/A","Ready" "\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser","N/A","Disabled" "\Microsoft\Windows\MUI\LPRemove","N/A","Disabled" "\Microsoft\Windows\Multimedia\SystemSoundsService","N/A","Running" "\Microsoft\Windows\NetCfg\BindingWorkItemQueueHandler","N/A","Disabled" "\Microsoft\Windows\NetTrace\GatherNetworkInfo","N/A","Disabled" "\Microsoft\Windows\NlaSvc\WiFiTask","N/A","Disabled" "\Microsoft\Windows\Offline Files\Background Synchronization","N/A","Disabled" "\Microsoft\Windows\Offline Files\Logon Synchronization","N/A","Disabled" "\Microsoft\Windows\PI\Secure-Boot-Update","N/A","Disabled" "\Microsoft\Windows\PI\Sqm-Tasks","N/A","Disabled" "\Microsoft\Windows\Plug and Play\Device Install Group Policy","N/A","Ready" "\Microsoft\Windows\Plug and Play\Device Install Reboot Required","N/A","Ready" "\Microsoft\Windows\Plug and Play\Device Install Reboot Required","N/A","Ready" "\Microsoft\Windows\Plug and Play\Plug and Play Cleanup","N/A","Ready" "\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers","N/A","Ready" "\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem","N/A","Disabled" "\Microsoft\Windows\Ras\MobilityManager","N/A","Disabled" "\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE","N/A","Disabled" "\Microsoft\Windows\Registry\RegIdleBackup","N/A","Ready" "\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask","N/A","Disabled" "\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask","N/A","Disabled" "\Microsoft\Windows\RetailDemo\CleanupOfflineContent","N/A","Disabled" "\Microsoft\Windows\Servicing\StartComponentCleanup","N/A","Disabled" "\Microsoft\Windows\SettingSync\BackgroundUploadTask","N/A","Disabled" "\Microsoft\Windows\SettingSync\BackupTask","N/A","Disabled" "\Microsoft\Windows\SettingSync\NetworkStateChangeTask","N/A","Disabled" "\Microsoft\Windows\SettingSync\NetworkStateChangeTask","N/A","Disabled" "\Microsoft\Windows\Setup\SetupCleanupTask","N/A","Disabled" "\Microsoft\Windows\SharedPC\Account Cleanup","N/A","Disabled" "\Microsoft\Windows\Shell\CreateObjectTask","N/A","Disabled" "\Microsoft\Windows\Shell\FamilySafetyMonitor","N/A","Disabled" "\Microsoft\Windows\Shell\FamilySafetyMonitorToastTask","N/A","Disabled" "\Microsoft\Windows\Shell\FamilySafetyRefreshTask","N/A","Disabled" "\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask","4/23/2117 1:01:17 PM","Ready" "\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskLogon","N/A","Disabled" "\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskNetwork","N/A","Disabled" "\Microsoft\Windows\SpacePort\SpaceAgentTask","N/A","Ready" "\Microsoft\Windows\SpacePort\SpaceAgentTask","N/A","Ready" "\Microsoft\Windows\SpacePort\SpaceManagerTask","N/A","Ready" "\Microsoft\Windows\SpacePort\SpaceManagerTask","N/A","Ready" "\Microsoft\Windows\Speech\SpeechModelDownloadTask","N/A","Disabled" "\Microsoft\Windows\Storage Tiers Management\Storage Tiers Management Initialization","N/A","Disabled" "\Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization","N/A","Disabled" "\Microsoft\Windows\Subscription\EnableLicenseAcquisition","N/A","Disabled" "\Microsoft\Windows\Subscription\EnableLicenseAcquisition","N/A","Disabled" "\Microsoft\Windows\Subscription\EnableLicenseAcquisition","N/A","Disabled" "\Microsoft\Windows\Subscription\LicenseAcquisition","N/A","Disabled" "\Microsoft\Windows\Subscription\LicenseAcquisition","N/A","Disabled" "\Microsoft\Windows\Subscription\LicenseAcquisition","N/A","Disabled" "\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate","N/A","Disabled" "\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance","N/A","Disabled" "\Microsoft\Windows\Sysmain\ResPriStaticDbSync","N/A","Disabled" "\Microsoft\Windows\Sysmain\WsSwapAssessmentTask","N/A","Disabled" "\Microsoft\Windows\SystemRestore\SR","N/A","Ready" "\Microsoft\Windows\Task Manager\Interactive","N/A","Ready" "\Microsoft\Windows\TextServicesFramework\MsCtfMonitor","N/A","Running" "\Microsoft\Windows\Time Synchronization\ForceSynchronizeTime","N/A","Ready" "\Microsoft\Windows\Time Synchronization\SynchronizeTime","N/A","Ready" "\Microsoft\Windows\Time Zone\SynchronizeTimeZone","N/A","Ready" "\Microsoft\Windows\TPM\Tpm-HASCertRetr","N/A","Disabled" "\Microsoft\Windows\TPM\Tpm-Maintenance","N/A","Disabled" "\Microsoft\Windows\TPM\Tpm-Maintenance","N/A","Disabled" "\Microsoft\Windows\TPM\Tpm-Maintenance","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\Combined Scan Download Install","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\Maintenance Install","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\Policy Install","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\Reboot","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\Refresh Settings","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\Resume On Boot","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\Schedule Scan","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\Schedule Scan","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\Schedule Scan","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\USO_RebootDisplay","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_WnfDisplay","N/A","Disabled" "\Microsoft\Windows\UpdateOrchestrator\USO_WnfDisplay","N/A","Disabled" "\Microsoft\Windows\UPnP\UPnPHostConfig","N/A","Disabled" "\Microsoft\Windows\User Profile Service\HiveUploadTask","N/A","Disabled" "\Microsoft\Windows\WCM\WiFiTask","N/A","Disabled" "\Microsoft\Windows\WDI\ResolutionHost","N/A","Disabled" "\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance","N/A","Ready" "\Microsoft\Windows\Windows Defender\Windows Defender Cleanup","N/A","Ready" "\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan","N/A","Ready" "\Microsoft\Windows\Windows Defender\Windows Defender Verification","N/A","Ready" "\Microsoft\Windows\Windows Error Reporting\QueueReporting","N/A","Disabled" "\Microsoft\Windows\Windows Error Reporting\QueueReporting","N/A","Disabled" "\Microsoft\Windows\Windows Error Reporting\QueueReporting","N/A","Disabled" "\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange","N/A","Ready" "\Microsoft\Windows\Windows Media Sharing\UpdateLibrary","N/A","Disabled" "\Microsoft\Windows\WindowsColorSystem\Calibration Loader","N/A","Disabled" "\Microsoft\Windows\WindowsColorSystem\Calibration Loader","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUFirmwareInstall","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUScheduledInstall","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUSessionConnect","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUSessionConnect","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUSessionConnect","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUSessionConnect","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\AUSessionConnect","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\Automatic App Update","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\Automatic App Update","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\Scheduled Start","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\Scheduled Start","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\Scheduled Start","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\Scheduled Start","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\sih","N/A","Disabled" "\Microsoft\Windows\WindowsUpdate\sihboot","N/A","Disabled" "\Microsoft\Windows\Wininet\CacheTask","N/A","Running" "\Microsoft\Windows\WOF\WIM-Hash-Management","N/A","Ready" "\Microsoft\Windows\WOF\WIM-Hash-Management","N/A","Ready" "\Microsoft\Windows\WOF\WIM-Hash-Validation","N/A","Ready" "\Microsoft\Windows\Workplace Join\Automatic-Device-Join","N/A","Disabled" "\Microsoft\Windows\Workplace Join\Automatic-Device-Join","N/A","Disabled" "\Microsoft\Windows\WwanSvc\NotificationTask","N/A","Disabled" "\Microsoft\XblGameSave\XblGameSaveTask","N/A","Disabled" "\Microsoft\XblGameSave\XblGameSaveTaskLogon","N/A","Disabled" "\OfficeSoftwareProtectionPlatform\SvcRestartTask","N/A","Disabled" ------------------------------------------------------------------------------------------- SC qc (configurations of all services): C:\TEMP>SC qc "AdobeARMservice" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AdobeARMservice TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Adobe Acrobat Update Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "AdobeUpdateService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AdobeUpdateService TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : AdobeUpdateService DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "AGSService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AGSService TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Adobe Genuine Software Integrity Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "AJRouter" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AJRouter TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : AllJoyn Router Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "ALG" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: ALG TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\alg.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Application Layer Gateway Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "AppIDSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AppIDSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : ProfSvc_Group TAG : 0 DISPLAY_NAME : Application Identity DEPENDENCIES : RpcSs : AppID : CryptSvc SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "Appinfo" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Appinfo TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Application Information DEPENDENCIES : RpcSs : ProfSvc SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "AppMgmt" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AppMgmt TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Application Management DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "AppReadiness" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AppReadiness TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k AppReadiness LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : App Readiness DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "AppVClient" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AppVClient TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\AppVClient.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Microsoft App-V Client DEPENDENCIES : RpcSS : netprofm : AppvVfs : AppVStrm SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "AppXSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AppXSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k wsappx LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : AppX Deployment Service (AppXSVC) DEPENDENCIES : rpcss : staterepository SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "AudioEndpointBuilder" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AudioEndpointBuilder TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : AudioGroup TAG : 0 DISPLAY_NAME : Windows Audio Endpoint Builder DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Audiosrv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Audiosrv TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : AudioGroup TAG : 0 DISPLAY_NAME : Windows Audio DEPENDENCIES : AudioEndpointBuilder : RpcSs SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "AxInstSV" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: AxInstSV TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k AxInstSVGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : ActiveX Installer (AxInstSV) DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "BDESVC" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: BDESVC TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : BitLocker Drive Encryption Service DEPENDENCIES : SERVICE_START_NAME : localSystem C:\TEMP>SC qc "BFE" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: BFE TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork LOAD_ORDER_GROUP : NetworkProvider TAG : 0 DISPLAY_NAME : Base Filtering Engine DEPENDENCIES : RpcSs SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "BITS" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: BITS TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Background Intelligent Transfer Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "BrokerInfrastructure" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: BrokerInfrastructure TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k DcomLaunch LOAD_ORDER_GROUP : COM Infrastructure TAG : 0 DISPLAY_NAME : Background Tasks Infrastructure Service DEPENDENCIES : RpcEptMapper : DcomLaunch : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "BthHFSrv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: BthHFSrv TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Bluetooth Handsfree Service DEPENDENCIES : bthserv SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "bthserv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: bthserv TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Bluetooth Support Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "CDPSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: CDPSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Connected Devices Platform Service DEPENDENCIES : ncbservice : RpcSS : Tcpip SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "CDPUserSvc_2c367" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: CDPUserSvc_2c367 TYPE : e0 USER_SHARE_PROCESS INSTANCE START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Connected Devices Platform User Service_2c367 DEPENDENCIES : SERVICE_START_NAME : C:\TEMP>SC qc "CertPropSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: CertPropSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Certificate Propagation DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "ClipSVC" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: ClipSVC TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k wsappx LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Client License Service (ClipSVC) DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "COMSysApp" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: COMSysApp TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : COM+ System Application DEPENDENCIES : RpcSs : EventSystem : SENS SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "CoreMessagingRegistrar" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: CoreMessagingRegistrar TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : CoreMessaging DEPENDENCIES : rpcss SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "CryptSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: CryptSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Cryptographic Services DEPENDENCIES : RpcSs SERVICE_START_NAME : NT Authority\NetworkService C:\TEMP>SC qc "CscService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: CscService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : ProfSvc_Group TAG : 0 DISPLAY_NAME : Offline Files DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "DcomLaunch" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DcomLaunch TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k DcomLaunch LOAD_ORDER_GROUP : COM Infrastructure TAG : 0 DISPLAY_NAME : DCOM Server Process Launcher DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "defragsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: defragsvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k defragsvc LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Optimize drives DEPENDENCIES : RPCSS SERVICE_START_NAME : localSystem C:\TEMP>SC qc "DeviceAssociationService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DeviceAssociationService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Device Association Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "DeviceInstall" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DeviceInstall TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k DcomLaunch LOAD_ORDER_GROUP : PlugPlay TAG : 0 DISPLAY_NAME : Device Install Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "DevicesFlowUserSvc_2c367" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DevicesFlowUserSvc_2c367 TYPE : e0 USER_SHARE_PROCESS INSTANCE START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k DevicesFlow LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : DevicesFlow_2c367 DEPENDENCIES : SERVICE_START_NAME : C:\TEMP>SC qc "DevQueryBroker" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DevQueryBroker TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : DevQuery Background Discovery Broker DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Dhcp" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Dhcp TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : DHCP Client DEPENDENCIES : NSI : Tdx : Afd SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "diagnosticshub.standardcollector.service" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: diagnosticshub.standardcollector.service TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Microsoft (R) Diagnostics Hub Standard Collector Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "DiagTrack" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DiagTrack TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k utcsvc LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Connected User Experiences and Telemetry DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "DmEnrollmentSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DmEnrollmentSvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Device Management Enrollment Service DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "dmwappushservice" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: dmwappushservice TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : dmwappushsvc DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Dnscache" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Dnscache TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : DNS Client DEPENDENCIES : Tdx : nsi SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "DoSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DoSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Delivery Optimization DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "dot3svc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: dot3svc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : Wired AutoConfig DEPENDENCIES : RpcSs : Ndisuio : Eaphost SERVICE_START_NAME : localSystem C:\TEMP>SC qc "DPS" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DPS TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Diagnostic Policy Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "DsmSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DsmSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Device Setup Manager DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "DsSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DsSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Data Sharing Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "DusmSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: DusmSvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : Data Usage DEPENDENCIES : RpcSs SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "EapHost" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: EapHost TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Extensible Authentication Protocol DEPENDENCIES : RPCSS : KeyIso SERVICE_START_NAME : localSystem C:\TEMP>SC qc "EFS" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: EFS TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\lsass.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Encrypting File System (EFS) DEPENDENCIES : RPCSS SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "embeddedmode" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: embeddedmode TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Embedded Mode DEPENDENCIES : BrokerInfrastructure SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "EntAppSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: EntAppSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k appmodel LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Enterprise App Management Service DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "EventLog" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: EventLog TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : Event Log TAG : 0 DISPLAY_NAME : Windows Event Log DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "EventSystem" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: EventSystem TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : COM+ Event System DEPENDENCIES : rpcss SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "fdPHost" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: fdPHost TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Function Discovery Provider Host DEPENDENCIES : RpcSs : http SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "FDResPub" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: FDResPub TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Function Discovery Resource Publication DEPENDENCIES : RpcSs : http SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "fhsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: fhsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : File History Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "FontCache" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: FontCache TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : AudioGroup TAG : 0 DISPLAY_NAME : Windows Font Cache Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "FontCache3.0.0.0" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: FontCache3.0.0.0 TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Presentation Foundation Font Cache 3.0.0.0 DEPENDENCIES : SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "FrameServer" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: FrameServer TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k Camera LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Camera Frame Server DEPENDENCIES : rpcss SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "gpsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: gpsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : ProfSvc_Group TAG : 0 DISPLAY_NAME : Group Policy Client DEPENDENCIES : RPCSS : Mup SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "gupdate" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: gupdate TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Google Update Service (gupdate) DEPENDENCIES : RPCSS SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "gupdatem" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: gupdatem TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Google Update Service (gupdatem) DEPENDENCIES : RPCSS SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "hidserv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: hidserv TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Human Interface Device Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "HomeGroupListener" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: HomeGroupListener TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : HomeGroup Listener DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "HomeGroupProvider" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: HomeGroupProvider TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : HomeGroup Provider DEPENDENCIES : netprofm : fdrespub : fdphost SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "HvHost" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: HvHost TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : HV Host Service DEPENDENCIES : hvservice SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "icssvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: icssvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : Windows Mobile Hotspot Service DEPENDENCIES : RpcSs : wcmsvc SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "IKEEXT" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: IKEEXT TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : IKE and AuthIP IPsec Keying Modules DEPENDENCIES : BFE : nsi SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "iphlpsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: iphlpsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k NetSvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : IP Helper DEPENDENCIES : RpcSS : Tdx : winmgmt : tcpip : nsi : WinHttpAutoProxySvc SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "IpOverUsbSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: IpOverUsbSvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : "C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Phone IP over USB Transport (IpOverUsbSvc) DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "IpxlatCfgSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: IpxlatCfgSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : IP Translation Configuration Service DEPENDENCIES : nsi SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "irmon" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: irmon TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : Infrared monitor service DEPENDENCIES : irda SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "KeyIso" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: KeyIso TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\lsass.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : CNG Key Isolation DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "KtmRm" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: KtmRm TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k NetworkServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : KtmRm for Distributed Transaction Coordinator DEPENDENCIES : RPCSS : SamSS SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "LanmanServer" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: LanmanServer TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Server DEPENDENCIES : SamSS : Srv2 SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "LanmanWorkstation" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: LanmanWorkstation TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : NetworkProvider TAG : 0 DISPLAY_NAME : Workstation DEPENDENCIES : Bowser : MRxSmb20 : NSI SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "lfsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: lfsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Geolocation Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "LicenseManager" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: LicenseManager TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows License Manager Service DEPENDENCIES : rpcss SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "lltdsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: lltdsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Link-Layer Topology Discovery Mapper DEPENDENCIES : rpcss : lltdio SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "lmhosts" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: lmhosts TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : TCP/IP NetBIOS Helper DEPENDENCIES : Afd SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "LSM" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: LSM TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k DcomLaunch LOAD_ORDER_GROUP : COM Infrastructure TAG : 0 DISPLAY_NAME : Local Session Manager DEPENDENCIES : RpcEptMapper : DcomLaunch : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "MapsBroker" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: MapsBroker TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : NetworkService TAG : 0 DISPLAY_NAME : Downloaded Maps Manager DEPENDENCIES : rpcss SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "MessagingService_2c367" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: MessagingService_2c367 TYPE : e0 USER_SHARE_PROCESS INSTANCE START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : MessagingService_2c367 DEPENDENCIES : SERVICE_START_NAME : C:\TEMP>SC qc "MpsSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: MpsSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork LOAD_ORDER_GROUP : NetworkProvider TAG : 0 DISPLAY_NAME : Windows Firewall DEPENDENCIES : mpsdrv : bfe SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "MSDTC" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: MSDTC TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\msdtc.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Distributed Transaction Coordinator DEPENDENCIES : RPCSS : SamSS SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "MSiSCSI" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: MSiSCSI TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : iSCSI TAG : 0 DISPLAY_NAME : Microsoft iSCSI Initiator Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "msiserver" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: msiserver TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\msiexec.exe /V LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Installer DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "NaturalAuthentication" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: NaturalAuthentication TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Natural Authentication DEPENDENCIES : RpcSs : ProfSvc : Schedule SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "NcaSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: NcaSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k NetSvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network Connectivity Assistant DEPENDENCIES : BFE : dnscache : NSI : iphlpsvc SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "NcbService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: NcbService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network Connection Broker DEPENDENCIES : RpcSS : tcpip SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "NcdAutoSetup" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: NcdAutoSetup TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network Connected Devices Auto-Setup DEPENDENCIES : netprofm SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "Netlogon" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Netlogon TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\lsass.exe LOAD_ORDER_GROUP : MS_WindowsRemoteValidation TAG : 0 DISPLAY_NAME : Netlogon DEPENDENCIES : LanmanWorkstation SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Netman" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Netman TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network Connections DEPENDENCIES : RpcSs : nsi SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "netprofm" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: netprofm TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network List Service DEPENDENCIES : RpcSs : nlasvc SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "NetSetupSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: NetSetupSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network Setup Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "NetTcpPortSharing" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: NetTcpPortSharing TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Net.Tcp Port Sharing Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "NgcCtnrSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: NgcCtnrSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : Cryptography TAG : 0 DISPLAY_NAME : Microsoft Passport Container DEPENDENCIES : RpcSs SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "NgcSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: NgcSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : Cryptography TAG : 0 DISPLAY_NAME : Microsoft Passport DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "NlaSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: NlaSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network Location Awareness DEPENDENCIES : NSI : RpcSs : TcpIp : Dhcp : Eventlog SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "nlsX86cc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: nlsX86cc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\SysWOW64\nlssrv32.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Nalpeiron Licensing Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "nsi" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: nsi TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network Store Interface Service DEPENDENCIES : rpcss : nsiproxy SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "OneSyncSvc_2c367" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: OneSyncSvc_2c367 TYPE : e0 USER_SHARE_PROCESS INSTANCE START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Sync Host_2c367 DEPENDENCIES : SERVICE_START_NAME : C:\TEMP>SC qc "p2pimsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: p2pimsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Peer Networking Identity Manager DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "p2psvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: p2psvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Peer Networking Grouping DEPENDENCIES : p2pimsvc : PNRPSvc SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "PcaSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PcaSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Program Compatibility Assistant Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "PeerDistSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PeerDistSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k PeerDist LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : BranchCache DEPENDENCIES : http SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "PerfHost" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PerfHost TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\SysWow64\perfhost.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Performance Counter DLL Host DEPENDENCIES : RPCSS SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "PhoneSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PhoneSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Phone Service DEPENDENCIES : RpcSs SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "PimIndexMaintenanceSvc_2c367" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PimIndexMaintenanceSvc_2c367 TYPE : e0 USER_SHARE_PROCESS INSTANCE START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Contact Data_2c367 DEPENDENCIES : SERVICE_START_NAME : C:\TEMP>SC qc "pla" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: pla TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Performance Logs & Alerts DEPENDENCIES : RPCSS SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "PlugPlay" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PlugPlay TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k DcomLaunch LOAD_ORDER_GROUP : PlugPlay TAG : 0 DISPLAY_NAME : Plug and Play DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "PNRPAutoReg" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PNRPAutoReg TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : PNRP Machine Name Publication Service DEPENDENCIES : pnrpsvc SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "PNRPsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PNRPsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Peer Name Resolution Protocol DEPENDENCIES : p2pimsvc SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "PolicyAgent" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PolicyAgent TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : IPsec Policy Agent DEPENDENCIES : Tcpip : bfe SERVICE_START_NAME : NT Authority\NetworkService C:\TEMP>SC qc "Power" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Power TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k DcomLaunch LOAD_ORDER_GROUP : Plugplay TAG : 0 DISPLAY_NAME : Power DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "PrintNotify" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: PrintNotify TYPE : 120 WIN32_SHARE_PROCESS (interactive) START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k print LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Printer Extensions and Notifications DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "ProfSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: ProfSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : profsvc_group TAG : 0 DISPLAY_NAME : User Profile Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "QWAVE" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: QWAVE TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Quality Windows Audio Video Experience DEPENDENCIES : rpcss : psched : QWAVEdrv : LLTDIO SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "RasAuto" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RasAuto TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Access Auto Connection Manager DEPENDENCIES : RasAcd SERVICE_START_NAME : localSystem C:\TEMP>SC qc "RasMan" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RasMan TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Access Connection Manager DEPENDENCIES : SstpSvc SERVICE_START_NAME : localSystem C:\TEMP>SC qc "RemoteAccess" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RemoteAccess TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Routing and Remote Access DEPENDENCIES : RpcSS : Bfe : RasMan : Http : +NetBIOSGroup SERVICE_START_NAME : localSystem C:\TEMP>SC qc "RemoteRegistry" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RemoteRegistry TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k localService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Registry DEPENDENCIES : RPCSS SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "RetailDemo" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RetailDemo TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k rdxgroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Retail Demo Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "RmSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RmSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Radio Management Service DEPENDENCIES : RpcSs SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "RpcEptMapper" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RpcEptMapper TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k RPCSS LOAD_ORDER_GROUP : COM Infrastructure TAG : 0 DISPLAY_NAME : RPC Endpoint Mapper DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "RpcLocator" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RpcLocator TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\locator.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Procedure Call (RPC) Locator DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "RpcSs" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: RpcSs TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k rpcss LOAD_ORDER_GROUP : COM Infrastructure TAG : 0 DISPLAY_NAME : Remote Procedure Call (RPC) DEPENDENCIES : RpcEptMapper : DcomLaunch SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "SamSs" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SamSs TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\lsass.exe LOAD_ORDER_GROUP : MS_WindowsLocalValidation TAG : 0 DISPLAY_NAME : Security Accounts Manager DEPENDENCIES : RPCSS SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SCardSvr" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SCardSvr TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : SmartCardGroup TAG : 0 DISPLAY_NAME : Smart Card DEPENDENCIES : wudfsvc SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "ScDeviceEnum" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: ScDeviceEnum TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Smart Card Device Enumeration Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Schedule" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Schedule TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : SchedulerGroup TAG : 0 DISPLAY_NAME : Task Scheduler DEPENDENCIES : RPCSS : SystemEventsBroker SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SCPolicySvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SCPolicySvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Smart Card Removal Policy DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SDRSVC" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SDRSVC TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k SDRSVC LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Backup DEPENDENCIES : RPCSS SERVICE_START_NAME : localSystem C:\TEMP>SC qc "seclogon" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: seclogon TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Secondary Logon DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SecurityHealthService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SecurityHealthService TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\SecurityHealthService.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Defender Security Center Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SEMgrSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SEMgrSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Payments and NFC/SE Manager DEPENDENCIES : RpcSs SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "SENS" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SENS TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : ProfSvc_Group TAG : 0 DISPLAY_NAME : System Event Notification Service DEPENDENCIES : EventSystem SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Sense" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Sense TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Defender Advanced Threat Protection Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SensorDataService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SensorDataService TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\SensorDataService.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Sensor Data Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SensorService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SensorService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Sensor Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SensrSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SensrSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Sensor Monitoring Service DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "SessionEnv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SessionEnv TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Desktop Configuration DEPENDENCIES : RPCSS : LanmanWorkstation SERVICE_START_NAME : localSystem C:\TEMP>SC qc "SharedAccess" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SharedAccess TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Internet Connection Sharing (ICS) DEPENDENCIES : BFE SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "ShellHWDetection" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: ShellHWDetection TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : ShellSvcGroup TAG : 0 DISPLAY_NAME : Shell Hardware Detection DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "shpamsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: shpamsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Shared PC Account Manager DEPENDENCIES : RpcSs : ProfSvc SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SkypeUpdate" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SkypeUpdate TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : "C:\Program Files (x86)\Skype\Updater\Updater.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Skype Updater DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "smphost" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: smphost TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k smphost LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Microsoft Storage Spaces SMP DEPENDENCIES : RPCSS SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "SmsRouter" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SmsRouter TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Microsoft Windows SMS Router Service. DEPENDENCIES : RpcSs : NdisUio SERVICE_START_NAME : localSystem C:\TEMP>SC qc "SNMPTRAP" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SNMPTRAP TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\snmptrap.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : SNMP Trap DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "spectrum" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: spectrum TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\spectrum.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Perception Service DEPENDENCIES : rpcss SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "Spooler" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Spooler TYPE : 110 WIN32_OWN_PROCESS (interactive) START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\spoolsv.exe LOAD_ORDER_GROUP : SpoolerGroup TAG : 0 DISPLAY_NAME : Print Spooler DEPENDENCIES : RPCSS : http SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "sppsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: sppsvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START (DELAYED) ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\sppsvc.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Software Protection DEPENDENCIES : RpcSs SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "SSDPSRV" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SSDPSRV TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : SSDP Discovery DEPENDENCIES : HTTP SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "SstpSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SstpSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Secure Socket Tunneling Protocol Service DEPENDENCIES : SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "StateRepository" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: StateRepository TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k appmodel LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : State Repository Service DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "stisvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: stisvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k imgsvc LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Image Acquisition (WIA) DEPENDENCIES : RpcSs SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "StorSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: StorSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Storage Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "svsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: svsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Spot Verifier DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "swprv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: swprv TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k swprv LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Microsoft Software Shadow Copy Provider DEPENDENCIES : RPCSS SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SysMain" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SysMain TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Superfetch DEPENDENCIES : rpcss : fileinfo SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "SystemEventsBroker" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: SystemEventsBroker TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k DcomLaunch LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : System Events Broker DEPENDENCIES : RpcEptMapper : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "TabletInputService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: TabletInputService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : PlugPlay TAG : 0 DISPLAY_NAME : Touch Keyboard and Handwriting Panel Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "TapiSrv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: TapiSrv TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Telephony DEPENDENCIES : RpcSs SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "Te.Service" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Te.Service TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : "C:\Program Files (x86)\Windows Kits\10\Testing\Runtimes\TAEF\Wex.Services.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Te.Service DEPENDENCIES : RpcSs : SecLogon SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "TermService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: TermService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Desktop Services DEPENDENCIES : RPCSS SERVICE_START_NAME : NT Authority\NetworkService C:\TEMP>SC qc "Themes" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Themes TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : ProfSvc_Group TAG : 0 DISPLAY_NAME : Themes DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "TieringEngineService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: TieringEngineService TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\TieringEngineService.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Storage Tiers Management DEPENDENCIES : SERVICE_START_NAME : localSystem C:\TEMP>SC qc "tiledatamodelsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: tiledatamodelsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k appmodel LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Tile Data model server DEPENDENCIES : rpcss : staterepository SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "TimeBrokerSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: TimeBrokerSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 1 SYSTEM_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Time Broker DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "TokenBroker" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: TokenBroker TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : TokenBroker DEPENDENCIES : UserManager SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "TrkWks" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: TrkWks TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Distributed Link Tracking Client DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "TrustedInstaller" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: TrustedInstaller TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\servicing\TrustedInstaller.exe LOAD_ORDER_GROUP : ProfSvc_Group TAG : 0 DISPLAY_NAME : Windows Modules Installer DEPENDENCIES : SERVICE_START_NAME : localSystem C:\TEMP>SC qc "tzautoupdate" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: tzautoupdate TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Auto Time Zone Updater DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "UevAgentService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: UevAgentService TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\AgentService.exe LOAD_ORDER_GROUP : ProfSvc_Group TAG : 0 DISPLAY_NAME : User Experience Virtualization Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "UI0Detect" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: UI0Detect TYPE : 110 WIN32_OWN_PROCESS (interactive) START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\UI0Detect.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Interactive Services Detection DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "UmRdpService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: UmRdpService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Desktop Services UserMode Port Redirector DEPENDENCIES : TermService : RDPDR SERVICE_START_NAME : localSystem C:\TEMP>SC qc "UnistoreSvc_2c367" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: UnistoreSvc_2c367 TYPE : e0 USER_SHARE_PROCESS INSTANCE START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : User Data Storage_2c367 DEPENDENCIES : SERVICE_START_NAME : C:\TEMP>SC qc "upnphost" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: upnphost TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : UPnP Device Host DEPENDENCIES : SSDPSRV : HTTP SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "UserDataSvc_2c367" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: UserDataSvc_2c367 TYPE : e0 USER_SHARE_PROCESS INSTANCE START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : User Data Access_2c367 DEPENDENCIES : SERVICE_START_NAME : C:\TEMP>SC qc "UserManager" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: UserManager TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : User Manager DEPENDENCIES : RpcSs : ProfSvc SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "UsoSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: UsoSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Update Orchestrator Service DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "VaultSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: VaultSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\lsass.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Credential Manager DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vds" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vds TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\vds.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Virtual Disk DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "VGAuthService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: VGAuthService TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\VMware\VMware Tools\VMware VGAuth\VGAuthService.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : VMware Alias Manager and Ticket Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vmicguestinterface" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmicguestinterface TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Hyper-V Guest Service Interface DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vmicheartbeat" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmicheartbeat TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k ICService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Hyper-V Heartbeat Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vmickvpexchange" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmickvpexchange TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Hyper-V Data Exchange Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vmicrdv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmicrdv TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k ICService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Hyper-V Remote Desktop Virtualization Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vmicshutdown" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmicshutdown TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Hyper-V Guest Shutdown Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vmictimesync" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmictimesync TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Hyper-V Time Synchronization Service DEPENDENCIES : VmGid SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "vmicvmsession" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmicvmsession TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Hyper-V PowerShell Direct Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vmicvss" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmicvss TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Hyper-V Volume Shadow Copy Requestor DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "VMTools" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: VMTools TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\VMware\VMware Tools\vmtoolsd.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : VMware Tools DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "vmvss" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: vmvss TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\dllhost.exe /Processid:{CE343A91-39CE-4B63-8F1D-92C2E8E81CA5} LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : VMware Snapshot Provider DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "VMware Physical Disk Helper Service" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: VMware Physical Disk Helper Service TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : "C:\Program Files\VMware\VMware Tools\vmacthlp.exe" LOAD_ORDER_GROUP : Base TAG : 0 DISPLAY_NAME : VMware Physical Disk Helper Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "VMwareCAFCommAmqpListener" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: VMwareCAFCommAmqpListener TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\VMware\VMware Tools\VMware CAF\pme\bin\CommAmqpListener.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : VMware CAF AMQP Communication Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "VMwareCAFManagementAgentHost" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: VMwareCAFManagementAgentHost TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\VMware\VMware Tools\VMware CAF\pme\bin\ManagementAgentHost.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : VMware CAF Management Agent Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "VSS" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: VSS TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\vssvc.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Volume Shadow Copy DEPENDENCIES : RPCSS SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "VSStandardCollectorService150" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: VSStandardCollectorService150 TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : "C:\Program Files (x86)\Microsoft Visual Studio\Shared\Common\DiagnosticsHub.Collection.Service\StandardCollector.Service.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Visual Studio Standard Collector Service 150 DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "W32Time" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: W32Time TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Time DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "WalletService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WalletService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k appmodel LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : WalletService DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "wbengine" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wbengine TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\WINDOWS\system32\wbengine.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Block Level Backup Engine Service DEPENDENCIES : SERVICE_START_NAME : localSystem C:\TEMP>SC qc "WbioSrvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WbioSrvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k WbioSvcGroup LOAD_ORDER_GROUP : SmartCardGroup TAG : 0 DISPLAY_NAME : Windows Biometric Service DEPENDENCIES : RpcSs : WUDFSvc SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Wcmsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Wcmsvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : Windows Connection Manager DEPENDENCIES : RpcSs : NSI SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "wcncsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wcncsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceAndNoImpersonation LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Connect Now - Config Registrar DEPENDENCIES : rpcss SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "WdiServiceHost" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WdiServiceHost TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Diagnostic Service Host DEPENDENCIES : SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "WdiSystemHost" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WdiSystemHost TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Diagnostic System Host DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "WdNisSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WdNisSvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\Windows Defender\NisSrv.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Defender Antivirus Network Inspection Service DEPENDENCIES : WdNisDrv SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "WebClient" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WebClient TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : NetworkProvider TAG : 0 DISPLAY_NAME : WebClient DEPENDENCIES : MRxDAV SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "Wecsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Wecsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Event Collector DEPENDENCIES : HTTP : Eventlog SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "WEPHOSTSVC" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WEPHOSTSVC TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k WepHostSvcGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Encryption Provider Host Service DEPENDENCIES : rpcss SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "wercplsupport" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wercplsupport TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Problem Reports and Solutions Control Panel Support DEPENDENCIES : SERVICE_START_NAME : localSystem C:\TEMP>SC qc "WerSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WerSvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k WerSvcGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Error Reporting Service DEPENDENCIES : SERVICE_START_NAME : localSystem C:\TEMP>SC qc "WFDSConMgrSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WFDSConMgrSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Wi-Fi Direct Services Connection Manager Service DEPENDENCIES : RpcSs SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "WiaRpc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WiaRpc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Still Image Acquisition Events DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "WinDefend" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WinDefend TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\Windows Defender\MsMpEng.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Defender Antivirus Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "Windows10FirewallService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Windows10FirewallService TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\Windows10FirewallControl\Windows10FirewallService.exe" LOAD_ORDER_GROUP : NetworkProvider TAG : 0 DISPLAY_NAME : Windows10FirewallService DEPENDENCIES : BFE SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "WinHttpAutoProxySvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WinHttpAutoProxySvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : WinHTTP Web Proxy Auto-Discovery Service DEPENDENCIES : Dhcp SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "Winmgmt" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: Winmgmt TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Management Instrumentation DEPENDENCIES : RPCSS SERVICE_START_NAME : localSystem C:\TEMP>SC qc "WinRM" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WinRM TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k NetworkService LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Remote Management (WS-Management) DEPENDENCIES : RPCSS : HTTP SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "wisvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wisvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Insider Service DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "WlanSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WlanSvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : WLAN AutoConfig DEPENDENCIES : nativewifip : RpcSs : Ndisuio : wcmsvc SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "wlidsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wlidsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Microsoft Account Sign-in Assistant DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "wlpasvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wlpasvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalService LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : LPA Service DEPENDENCIES : WwanSvc : RpcSs SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "wmiApSrv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wmiApSrv TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\wbem\WmiApSrv.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : WMI Performance Adapter DEPENDENCIES : SERVICE_START_NAME : localSystem C:\TEMP>SC qc "WMPNetworkSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WMPNetworkSvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\Windows Media Player\wmpnetwk.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Media Player Network Sharing Service DEPENDENCIES : http : WSearch SERVICE_START_NAME : NT AUTHORITY\NetworkService C:\TEMP>SC qc "WPDBusEnum" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WPDBusEnum TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Portable Device Enumerator Service DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "WpnService" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WpnService TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Push Notifications System Service DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "WpnUserService_2c367" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WpnUserService_2c367 TYPE : e0 USER_SHARE_PROCESS INSTANCE START_TYPE : 4 DISABLED ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Push Notifications User Service_2c367 DEPENDENCIES : SERVICE_START_NAME : C:\TEMP>SC qc "wscsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wscsvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START (DELAYED) ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Security Center DEPENDENCIES : RpcSs : WinMgmt SERVICE_START_NAME : NT AUTHORITY\LocalService C:\TEMP>SC qc "WSearch" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WSearch TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\SearchIndexer.exe /Embedding LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Search DEPENDENCIES : RPCSS SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "wuauserv" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wuauserv TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Update DEPENDENCIES : rpcss SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "wudfsvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: wudfsvc TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted LOAD_ORDER_GROUP : PlugPlay TAG : 0 DISPLAY_NAME : Windows Driver Foundation - User-mode Driver Framework DEPENDENCIES : WudfPf SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "WwanSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: WwanSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : WWAN AutoConfig DEPENDENCIES : RpcSs : NdisUio SERVICE_START_NAME : NT Authority\LocalService C:\TEMP>SC qc "xbgm" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: xbgm TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Xbox Game Monitoring DEPENDENCIES : UserManager : XblAuthManager SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "XblAuthManager" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: XblAuthManager TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Xbox Live Auth Manager DEPENDENCIES : RpcSs SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "XblGameSave" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: XblGameSave TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Xbox Live Game Save DEPENDENCIES : UserManager : XblAuthManager SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "XboxGipSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: XboxGipSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Xbox Accessory Management Service DEPENDENCIES : SERVICE_START_NAME : LocalSystem C:\TEMP>SC qc "XboxNetApiSvc" [SC] QueryServiceConfig SUCCESS SERVICE_NAME: XboxNetApiSvc TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Xbox Live Networking Service DEPENDENCIES : BFE : mpssvc : IKEEXT : KeyIso SERVICE_START_NAME : LocalSystem ------------------------------------------------------------------------------------------- WMIC qfe list (list of all installed updates): Caption CSName Description FixComments HotFixID InstallDate InstalledBy InstalledOn Name ServicePackInEffect Status http://support.microsoft.com/?kbid=4016871 W10VM Security Update KB4016871 NT AUTHORITY\SYSTEM 5/10/2017 ------------------------------------------------------------------------------------------- BCDEDIT /ENUM ALL (list of all boot configuration options): Windows Boot Manager -------------------- identifier {bootmgr} device partition=\Device\HarddiskVolume1 description Windows Boot Manager locale en-US inherit {globalsettings} default {current} resumeobject {6d741390-158e-11e7-9a95-abb1e7dc212e} displayorder {current} toolsdisplayorder {memdiag} timeout 5 displaybootmenu Yes Windows Boot Loader ------------------- identifier {current} device partition=C: path \WINDOWS\system32\winload.exe description Windows 10 locale en-US inherit {bootloadersettings} recoverysequence {c3c04f4a-158e-11e7-9a95-abb1e7dc212e} displaymessageoverride Recovery recoveryenabled Yes allowedinmemorysettings 0x15000075 osdevice partition=C: systemroot \WINDOWS resumeobject {6d741390-158e-11e7-9a95-abb1e7dc212e} nx OptIn bootmenupolicy Standard Windows Boot Loader ------------------- identifier {c3c04f4a-158e-11e7-9a95-abb1e7dc212e} device ramdisk=[\Device\HarddiskVolume3]\Recovery\WindowsRE\Winre.wim,{c3c04f4b-158e-11e7-9a95-abb1e7dc212e} path \windows\system32\winload.exe description Windows Recovery Environment locale en-US inherit {bootloadersettings} displaymessage Recovery osdevice ramdisk=[\Device\HarddiskVolume3]\Recovery\WindowsRE\Winre.wim,{c3c04f4b-158e-11e7-9a95-abb1e7dc212e} systemroot \windows nx OptIn bootmenupolicy Standard winpe Yes Resume from Hibernate --------------------- identifier {6d741390-158e-11e7-9a95-abb1e7dc212e} device partition=C: path \WINDOWS\system32\winresume.exe description Windows Resume Application locale en-US inherit {resumeloadersettings} recoverysequence {c3c04f4a-158e-11e7-9a95-abb1e7dc212e} recoveryenabled Yes allowedinmemorysettings 0x15000075 filedevice partition=C: filepath \hiberfil.sys bootmenupolicy Standard debugoptionenabled No Windows Memory Tester --------------------- identifier {memdiag} device partition=\Device\HarddiskVolume1 path \boot\memtest.exe description Windows Memory Diagnostic locale en-US inherit {globalsettings} badmemoryaccess Yes EMS Settings ------------ identifier {emssettings} bootems No Debugger Settings ----------------- identifier {dbgsettings} debugtype Serial debugport 1 baudrate 115200 RAM Defects ----------- identifier {badmemory} Global Settings --------------- identifier {globalsettings} inherit {dbgsettings} {emssettings} {badmemory} Boot Loader Settings -------------------- identifier {bootloadersettings} inherit {globalsettings} {hypervisorsettings} Hypervisor Settings ------------------- identifier {hypervisorsettings} hypervisordebugtype Serial hypervisordebugport 1 hypervisorbaudrate 115200 Resume Loader Settings ---------------------- identifier {resumeloadersettings} inherit {globalsettings} Device options -------------- identifier {c3c04f4b-158e-11e7-9a95-abb1e7dc212e} description Windows Recovery ramdisksdidevice partition=\Device\HarddiskVolume3 ramdisksdipath \Recovery\WindowsRE\boot.sdi -------------------------------------------------------------------------------------------