The Windows 10 Services configuration defaults are provided on this page. The settings below are gathered from a Windows 10 Pro PC (clean install, rather than upgrade).
Last updated on April 27, 2024 – Windows 10 Pro v22H2 is the current version as of this revision. The Service permission (SDDL strings) defaults are also included for each service.
Windows 10 Default Services Configuration
Note that some of these services may not be found in your system, depending upon the edition of Windows 10 you’ve installed. Regardless, this list should be a useful reference.
Name | Startup Type | Log On As |
ActiveX Installer (AxInstSV) | Manual | Local System |
Agent Activation Runtime_84853d | Manual | Local System |
AllJoyn Router Service | Manual (Trigger Start) | Local Service |
App Readiness | Manual | Local System |
Application Identity | Manual (Trigger Start) | Local Service |
Application Information | Manual (Trigger Start) | Local System |
Application Layer Gateway Service | Manual | Local Service |
Application Management | Manual | Local System |
AppX Deployment Service (AppXSVC) | Manual (Trigger Start) | Local System |
AssignedAccessManager Service | Manual (Trigger Start) | Local System |
Auto Time Zone Updater | Disabled | Local Service |
AVCTP service | Manual (Trigger Start) | Local Service |
Background Intelligent Transfer Service | Manual | Local System |
Background Tasks Infrastructure Service | Automatic | Local System |
Base Filtering Engine | Automatic | Local Service |
BitLocker Drive Encryption Service | Manual (Trigger Start) | Local System |
Block Level Backup Engine Service | Manual | Local System |
Bluetooth Audio Gateway Service | Manual (Trigger Start) | Local Service |
Bluetooth Support Service | Manual (Trigger Start) | Local Service |
Bluetooth User Support Service_84853d | Manual (Trigger Start) | Local System |
BranchCache | Manual | Network Service |
Capability Access Manager Service | Manual | Local System |
CaptureService_84853d | Manual | Local System |
Cellular Time | Manual (Trigger Start) | Local Service |
Certificate Propagation | Manual (Trigger Start) | Local System |
Client License Service (ClipSVC) | Manual (Trigger Start) | Local System |
Clipboard User Service_84853d | Manual | Local System |
CNG Key Isolation | Manual (Trigger Start) | Local System |
COM+ Event System | Automatic | Local Service |
COM+ System Application | Manual | Local System |
Connected Devices Platform Service | Automatic (Delayed Start, Trigger Start) | Local Service |
Connected Devices Platform User Service_84853d |
Automatic | Local System |
Connected User Experiences and Telemetry | Automatic | Local System |
ConsentUX_84853d | Manual | Local System |
Contact Data_84853d | Manual | Local System |
CoreMessaging | Automatic | Local Service |
Credential Manager | Manual | Local System |
CredentialEnrollmentManagerUserSvc_84853d | Manual | Local System |
Cryptographic Services | Automatic | Network Service |
Data Sharing Service | Manual (Trigger Start) | Local System |
Data Usage | Automatic | Local Service |
DCOM Server Process Launcher | Automatic | Local System |
debugregsvc | Automatic | Local System |
Declared Configuration(DC) service | Manual (Trigger Start) | Local System |
Delivery Optimization | Manual (Trigger Start) | Network Service |
Developer Tools Service | Manual | Local System |
Device Association Service | Manual (Trigger Start) | Local System |
Device Install Service | Manual (Trigger Start) | Local System |
Device Management Enrollment Service | Manual | Local System |
Device Management Wireless Application Protocol (WAP) Push message Routing Service |
Manual (Trigger Start) | Local System |
Device Setup Manager | Manual (Trigger Start) | Local System |
DeviceAssociationBroker_84853d | Manual | Local System |
DevicePicker_84853d | Manual | Local System |
DevicesFlow_84853d | Manual | Local System |
DevQuery Background Discovery Broker | Manual (Trigger Start) | Local System |
DHCP Client | Automatic | Local Service |
Diagnostic Execution Service | Manual (Trigger Start) | Local System |
Diagnostic Policy Service | Automatic | Local Service |
Diagnostic Service Host | Manual | Local Service |
Diagnostic System Host | Manual | Local System |
DialogBlockingService | Disabled | Local System |
Display Enhancement Service | Manual (Trigger Start) | Local System |
Display Policy Service | Automatic (Delayed Start) | Local Service |
Distributed Link Tracking Client | Automatic | Local System |
Distributed Transaction Coordinator | Manual | Network Service |
DNS Client | Automatic (Trigger Start) | Network Service |
Downloaded Maps Manager | Automatic (Delayed Start) | Network Service |
Embedded Mode | Manual (Trigger Start) | Local System |
Encrypting File System (EFS) | Manual (Trigger Start) | Local System |
Enterprise App Management Service | Manual | Local System |
Extensible Authentication Protocol | Manual | Local System |
Fax | Manual | Network Service |
File History Service | Automatic (Delayed Start, Trigger Start) | Local System |
Function Discovery Provider Host | Manual | Local Service |
Function Discovery Resource Publication | Manual (Trigger Start) | Local Service |
GameDVR and Broadcast User Service_84853d | Manual | Local System |
GameInput Service | Manual (Trigger Start) | Local System |
Geolocation Service | Manual (Trigger Start) | Local System |
GraphicsPerfSvc | Manual (Trigger Start) | Local System |
Group Policy Client | Automatic (Trigger Start) | Local System |
Human Interface Device Service | Manual (Trigger Start) | Local System |
HV Host Service | Manual (Trigger Start) | Local System |
Hyper-V Data Exchange Service | Manual (Trigger Start) | Local System |
Hyper-V Guest Service Interface | Manual (Trigger Start) | Local System |
Hyper-V Guest Shutdown Service | Manual (Trigger Start) | Local System |
Hyper-V Heartbeat Service | Manual (Trigger Start) | Local System |
Hyper-V PowerShell Direct Service | Manual (Trigger Start) | Local System |
Hyper-V Remote Desktop Virtualization Service |
Manual (Trigger Start) | Local System |
Hyper-V Time Synchronization Service | Manual (Trigger Start) | Local Service |
Hyper-V Volume Shadow Copy Requestor | Manual (Trigger Start) | Local System |
IKE and AuthIP IPsec Keying Modules | Manual (Trigger Start) | Local System |
Intel(R) Content Protection HECI Service | Manual | Local System |
Intel(R) HD Graphics Control Panel Service |
Automatic | Local System |
Internet Connection Sharing (ICS) | Manual (Trigger Start) | Local System |
IP Helper | Automatic | Local System |
IP Translation Configuration Service | Manual (Trigger Start) | Local System |
IPsec Policy Agent | Manual (Trigger Start) | Network Service |
KtmRm for Distributed Transaction Coordinator |
Manual (Trigger Start) | Network Service |
Language Experience Service | Manual | Local System |
Link-Layer Topology Discovery Mapper | Manual | Local Service |
Local Profile Assistant Service | Manual (Trigger Start) | Local Service |
Local Session Manager | Automatic | Local System |
McpManagementService | Manual | Local System |
MessagingService_84853d | Manual (Trigger Start) | Local System |
Microsoft (R) Diagnostics Hub Standard Collector Service |
Manual | Local System |
Microsoft Account Sign-in Assistant | Manual (Trigger Start) | Local System |
Microsoft App-V Client | Disabled | Local System |
Microsoft Cloud Identity Service | Manual | Network Service |
Microsoft Defender Antivirus Network Inspection Service |
Manual | Local Service |
Microsoft Defender Antivirus Service | Automatic | Local System |
Microsoft Edge Elevation Service (MicrosoftEdgeElevationService) |
Manual | Local System |
Microsoft Edge Update Service (edgeupdate) |
Automatic (Delayed Start, Trigger Start) | Local System |
Microsoft Edge Update Service (edgeupdatem) |
Manual (Trigger Start) | Local System |
Microsoft iSCSI Initiator Service | Manual | Local System |
Microsoft Keyboard Filter | Disabled | Local System |
Microsoft Passport | Manual (Trigger Start) | Local System |
Microsoft Passport Container | Manual (Trigger Start) | Local Service |
Microsoft Software Shadow Copy Provider | Manual | Local System |
Microsoft Storage Spaces SMP | Manual | Network Service |
Microsoft Store Install Service | Manual | Local System |
Microsoft Windows SMS Router Service. | Manual (Trigger Start) | Local Service |
Natural Authentication | Manual (Trigger Start) | Local System |
Net.Tcp Port Sharing Service | Disabled | Local Service |
Netlogon | Manual | Local System |
Network Connected Devices Auto-Setup | Manual (Trigger Start) | Local Service |
Network Connection Broker | Manual (Trigger Start) | Local System |
Network Connections | Manual | Local System |
Network Connectivity Assistant | Manual (Trigger Start) | Local System |
Network List Service | Manual | Local Service |
Network Location Awareness | Automatic | Network Service |
Network Setup Service | Manual (Trigger Start) | Local System |
Network Store Interface Service | Automatic | Local Service |
Offline Files | Disabled | Local System |
OpenSSH Authentication Agent | Disabled | Local System |
OpenSSH SSH Server | Manual | Local System |
Optimize drives | Manual | Local System |
Parental Controls | Manual | Local System |
Payments and NFC/SE Manager | Manual (Trigger Start) | Local Service |
Peer Name Resolution Protocol | Manual | Local Service |
Peer Networking Grouping | Manual | Local Service |
Peer Networking Identity Manager | Manual | Local Service |
Performance Counter DLL Host | Manual | Local Service |
Performance Logs & Alerts | Manual | Local Service |
Phone Service | Manual (Trigger Start) | Local Service |
Plug and Play | Manual | Local System |
PNRP Machine Name Publication Service | Manual | Local Service |
Portable Device Enumerator Service | Manual (Trigger Start) | Local System |
Power | Automatic | Local System |
Print Spooler | Automatic | Local System |
Printer Extensions and Notifications | Manual | Local System |
PrintWorkflow_84853d | Manual (Trigger Start) | Local System |
Problem Reports Control Panel Support | Manual | Local System |
Program Compatibility Assistant Service | Manual | Local System |
Quality Windows Audio Video Experience | Manual | Local Service |
Radio Management Service | Manual | Local Service |
Recommended Troubleshooting Service | Manual | Local System |
Remote Access Auto Connection Manager | Manual | Local System |
Remote Access Connection Manager | Manual | Local System |
Remote Desktop Configuration | Manual | Local System |
Remote Desktop Services | Manual | Network Service |
Remote Desktop Services UserMode Port Redirector |
Manual | Local System |
Remote Procedure Call (RPC) | Automatic | Network Service |
Remote Procedure Call (RPC) Locator | Manual | Network Service |
Remote Registry | Disabled | Local Service |
Retail Demo Service | Manual | Local System |
Routing and Remote Access | Disabled | Local System |
RPC Endpoint Mapper | Automatic | Network Service |
Secondary Logon | Manual | Local System |
Secure Socket Tunneling Protocol Service | Manual | Local Service |
Security Accounts Manager | Automatic | Local System |
Security Center | Automatic (Delayed Start) | Local Service |
Sensor Data Service | Manual (Trigger Start) | Local System |
Sensor Monitoring Service | Manual (Trigger Start) | Local Service |
Sensor Service | Manual (Trigger Start) | Local System |
Server | Automatic (Trigger Start) | Local System |
Shared PC Account Manager | Disabled | Local System |
Shell Hardware Detection | Automatic | Local System |
Smart Card | Manual (Trigger Start) | Local Service |
Smart Card Device Enumeration Service | Manual (Trigger Start) | Local System |
Smart Card Removal Policy | Manual | Local System |
SNMP Service | Automatic | Local System |
SNMP Trap | Manual | Local Service |
Software Protection | Automatic (Delayed Start, Trigger Start) | Network Service |
Spatial Data Service | Manual | Local Service |
Spot Verifier | Manual (Trigger Start) | Local System |
SSDP Discovery | Manual | Local Service |
SshdBroker | Manual | Local System |
State Repository Service | Manual | Local System |
Still Image Acquisition Events | Manual | Local System |
Storage Service | Automatic (Delayed Start, Trigger Start) | Local System |
Storage Tiers Management | Manual | Local System |
Sync Host_84853d | Automatic (Delayed Start) | Local System |
SysMain | Automatic | Local System |
System Event Notification Service | Automatic | Local System |
System Events Broker | Automatic (Trigger Start) | Local System |
System Guard Runtime Monitor Broker | Automatic (Delayed Start, Trigger Start) | Local System |
Task Scheduler | Automatic | Local System |
TCP/IP NetBIOS Helper | Manual (Trigger Start) | Local Service |
Telephony | Manual | Network Service |
Themes | Automatic | Local System |
Time Broker | Manual (Trigger Start) | Local Service |
Touch Keyboard and Handwriting Panel Service |
Manual (Trigger Start) | Local System |
Udk User Service_84853d | Manual | Local System |
Update Orchestrator Service | Automatic (Delayed Start) | Local System |
UPnP Device Host | Manual | Local Service |
User Data Access_84853d | Manual | Local System |
User Data Storage_84853d | Manual | Local System |
User Experience Virtualization Service | Disabled | Local System |
User Manager | Automatic (Trigger Start) | Local System |
User Profile Service | Automatic | Local System |
Virtual Disk | Manual | Local System |
Volume Shadow Copy | Manual | Local System |
Volumetric Audio Compositor Service | Manual | Local Service |
WalletService | Manual | Local System |
WarpJITSvc | Manual (Trigger Start) | Local Service |
Web Account Manager | Manual | Local System |
Web Management | Disabled | Local System |
WebClient | Manual (Trigger Start) | Local Service |
Wi-Fi Direct Services Connection Manager Service |
Manual (Trigger Start) | Local Service |
Windows Audio | Automatic | Local Service |
Windows Audio Endpoint Builder | Automatic | Local System |
Windows Backup | Manual | Local System |
Windows Biometric Service | Manual (Trigger Start) | Local System |
Windows Camera Frame Server | Manual (Trigger Start) | Local System |
Windows Connect Now – Config Registrar | Manual | Local Service |
Windows Connection Manager | Automatic (Trigger Start) | Local Service |
Windows Defender Advanced Threat Protection Service |
Manual | Local System |
Windows Defender Firewall | Automatic | Local Service |
Windows Encryption Provider Host Service | Manual (Trigger Start) | Local Service |
Windows Error Reporting Service | Manual (Trigger Start) | Local System |
Windows Event Collector | Manual | Network Service |
Windows Event Log | Automatic | Local Service |
Windows Font Cache Service | Automatic | Local Service |
Windows Image Acquisition (WIA) | Manual (Trigger Start) | Local Service |
Windows Insider Service | Manual (Trigger Start) | Local System |
Windows Installer | Manual | Local System |
Windows License Manager Service | Manual (Trigger Start) | Local Service |
Windows Management Instrumentation | Automatic | Local System |
Windows Management Service | Manual | Local System |
Windows Media Player Network Sharing Service |
Manual | Network Service |
Windows Mixed Reality OpenXR Service | Manual | Local System |
Windows Mobile Hotspot Service | Manual (Trigger Start) | Local Service |
Windows Modules Installer | Manual | Local System |
Windows Perception Service | Manual (Trigger Start) | Local Service |
Windows Perception Simulation Service | Manual | Local System |
Windows Presentation Foundation Font Cache 3.0.0.0 |
Manual | Local Service |
Windows Push Notifications System Service | Automatic | Local System |
Windows Push Notifications User Service_84853d |
Automatic | Local System |
Windows PushToInstall Service | Manual (Trigger Start) | Local System |
Windows Remote Management (WS-Management) | Manual | Network Service |
Windows Search | Automatic (Delayed Start) | Local System |
Windows Security Service | Manual | Local System |
Windows Time | Manual (Trigger Start) | Local Service |
Windows Update | Manual (Trigger Start) | Local System |
Windows Update Medic Service | Manual | Local System |
WinHTTP Web Proxy Auto-Discovery Service | Manual | Local Service |
Wired AutoConfig | Manual | Local System |
WLAN AutoConfig | Manual | Local System |
WMI Performance Adapter | Manual | Local System |
Work Folders | Manual | Local Service |
Workstation | Automatic | Network Service |
WWAN AutoConfig | Manual | Local System |
Xbox Accessory Management Service | Manual (Trigger Start) | Local System |
Xbox Live Auth Manager | Manual | Local System |
Xbox Live Game Save | Manual (Trigger Start) | Local System |
Xbox Live Networking Service | Manual | Local System |
Service Permissions
Service Name : AJRouter Display Name : AllJoyn Router Service Image Path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CR;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : ALG Display Name : Application Layer Gateway Service Image Path : C:\WINDOWS\System32\alg.exe Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : AppIDSvc Display Name : Application Identity Image Path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : NT Authority\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : Appinfo Display Name : Application Information Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CR;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : AppMgmt Display Name : Application Management Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLO;;;IU)(A;;CCLCSWLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : AppReadiness Display Name : App Readiness Image Path : C:\WINDOWS\System32\svchost.exe -k AppReadiness -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : AppVClient Display Name : Microsoft App-V Client Image Path : C:\WINDOWS\system32\AppVClient.exe Startup Type : Disabled Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : AppXSvc Display Name : AppX Deployment Service (AppXSVC) Image Path : C:\WINDOWS\system32\svchost.exe -k wsappx -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464D:(A;;LCRP;;;AC)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCLCSWRPWPDTLOCRRC;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWRPLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : AssignedAccessManagerSvc Display Name : AssignedAccessManager Service Image Path : C:\WINDOWS\system32\svchost.exe -k AssignedAccessManagerSvc Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : AudioEndpointBuilder Display Name : Windows Audio Endpoint Builder Image Path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : Audiosrv Display Name : Windows Audio Image Path : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Auto Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCLCSWLORC;;;AC)(A;;CCLCSWLORC;;;S-1-15-3-1024-1692970155-4054893335-185714091-3362601943-3526593181-1159816984-2199008581-497492991) Service Name : autotimesvc Display Name : Cellular Time Image Path : C:\WINDOWS\system32\svchost.exe -k autoTimeSvc Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : AxInstSV Display Name : ActiveX Installer (AxInstSV) Image Path : C:\WINDOWS\system32\svchost.exe -k AxInstSVGroup Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : BDESVC Display Name : BitLocker Drive Encryption Service Image Path : C:\WINDOWS\System32\svchost.exe -k netsvcs -p Startup Type : Manual (Triggered) Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCDCLCSWRPWPDTLORCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLORCWDWO;;;BA)(A;;CCLCSWRPLORC;;;BU)(A;;CCLCSWRPLORC;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : BFE Display Name : Base Filtering Engine Image Path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p Startup Type : Auto Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCLORC;;;AU)(A;;CCDCLCSWRPLORCWDWO;;;SY)(A;;CCLCSWRPLORCWDWO;;;BA)(A;;CCLCLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : BITS Display Name : Background Intelligent Transfer Service Image Path : C:\WINDOWS\System32\svchost.exe -k netsvcs -p Startup Type : Manual Log On As : LocalSystem Permissions : O:BAG:BAD:(A;CI;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;SAFA;WDWO;;;BA) Service Name : BrokerInfrastructure Display Name : Background Tasks Infrastructure Service Image Path : C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCLORC;;;AU)(A;;CCDCLCSWRPWPDTLORCWDWO;;;SY)(A;;CCLCSWRPWPDTLORCWDWO;;;BA)(A;;CCLCRPLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : BTAGService Display Name : Bluetooth Audio Gateway Service Image Path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : BthAvctpSvc Display Name : AVCTP service Image Path : C:\WINDOWS\system32\svchost.exe -k LocalService -p Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : bthserv Display Name : Bluetooth Support Service Image Path : C:\WINDOWS\system32\svchost.exe -k LocalService -p Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : camsvc Display Name : Capability Access Manager Service Image Path : C:\WINDOWS\system32\svchost.exe -k appmodel -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : CDPSvc Display Name : Connected Devices Platform Service Image Path : C:\WINDOWS\system32\svchost.exe -k LocalService -p Startup Type : Auto (Delayed, Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CR;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : CertPropSvc Display Name : Certificate Propagation Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:BAG:BAD:(A;CI;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRRC;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;RPWP;;;S-1-5-80-446051430-1559341753-4161941529-1950928533-810483104)S:(AU;SAFA;WDWO;;;BA) Service Name : ClipSVC Display Name : Client License Service (ClipSVC) Image Path : C:\WINDOWS\System32\svchost.exe -k wsappx -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCDCLCSWRPWPDTLOCRRC;;;SY)(A;;CCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;LCRPLO;;;AC)(A;;CCLCSWRPLOCRRC;;;SU)(A;;LCRP;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : cloudidsvc Display Name : Microsoft Cloud Identity Service Image Path : C:\WINDOWS\system32\svchost.exe -k CloudIdServiceGroup -p Startup Type : Manual Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLORC;;;AU)(A;;CCLCSWRPLORC;;;AC)(A;;CCLCSWRPLORC;;;S-1-15-3-1024-1065365936-1281604716-3511738428-1654721687-432734479-3232135806-4053264122-3456934681) Service Name : COMSysApp Display Name : COM+ System Application Image Path : C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : CoreMessagingRegistrar Display Name : CoreMessaging Image Path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork -p Startup Type : Auto Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCLCSWRPWPDTLOCRRC;;;BA)(A;;CCLCSWRPLOCRRC;;;SU)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWRPLOCRRC;;;AC) Service Name : cphs Display Name : Intel(R) Content Protection HECI Service Image Path : C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : CryptSvc Display Name : Cryptographic Services Image Path : C:\WINDOWS\system32\svchost.exe -k NetworkService -p Startup Type : Auto Log On As : NT Authority\NetworkService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;SO)(A;;CCLCSWLORC;;;AC)(A;;CCLCSWLORC;;;S-1-15-3-1024-3203351429-2120443784-2872670797-1918958302-2829055647-4275794519-765664414-2751773334) Service Name : CscService Display Name : Offline Files Image Path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Disabled Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : DcomLaunch Display Name : DCOM Server Process Launcher Image Path : C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCLORC;;;AU)(A;;CCDCLCSWRPWPDTLORCWDWO;;;SY)(A;;CCLCSWRPWPDTLORCWDWO;;;BA)(A;;CCLCLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : dcsvc Display Name : Declared Configuration(DC) service Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : debugregsvc Display Name : debugregsvc Image Path : C:\WINDOWS\System32\svchost.exe -k DevToolsGroup Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCLCSWLORC;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : defragsvc Display Name : Optimize drives Image Path : C:\WINDOWS\system32\svchost.exe -k defragsvc Startup Type : Manual Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : DeveloperToolsService Display Name : Developer Tools Service Image Path : C:\WINDOWS\System32\DeveloperToolsSvc.exe Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : DeviceAssociationService Display Name : Device Association Service Image Path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : DeviceInstall Display Name : Device Install Service Image Path : C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : DevQueryBroker Display Name : DevQuery Background Discovery Broker Image Path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : Dhcp Display Name : DHCP Client Image Path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Auto Log On As : NT Authority\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;NO)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLOCRRC;;;S-1-2-1)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : diagnosticshub.standardcollector.service Display Name : Microsoft (R) Diagnostics Hub Standard Collector Service Image Path : C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : diagsvc Display Name : Diagnostic Execution Service Image Path : C:\WINDOWS\System32\svchost.exe -k diagnostics Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : DiagTrack Display Name : Connected User Experiences and Telemetry Image Path : C:\WINDOWS\System32\svchost.exe -k utcsvc -p Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : DialogBlockingService Display Name : DialogBlockingService Image Path : C:\WINDOWS\system32\svchost.exe -k DialogBlockingService Startup Type : Disabled Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : DispBrokerDesktopSvc Display Name : Display Policy Service Image Path : C:\WINDOWS\system32\svchost.exe -k LocalService -p Startup Type : Auto (Delayed) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : DisplayEnhancementService Display Name : Display Enhancement Service Image Path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;LCRPCR;;;AC)(A;;LCRPCR;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : DmEnrollmentSvc Display Name : Device Management Enrollment Service Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : dmwappushservice Display Name : Device Management Wireless Application Protocol (WAP) Push message Routing Service Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;LCRP;;;AC)(A;;LCRP;;;IU)(A;;LCRP;;;AU) Service Name : Dnscache Display Name : DNS Client Image Path : C:\WINDOWS\system32\svchost.exe -k NetworkService -p Startup Type : Auto (Triggered) Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;CI;CCLCSWRPLORC;;;BU)(A;CI;CCLCSWRPDTLORC;;;BA)(A;CI;CCLCSWRPDTLORC;;;SY)(A;;CCLCSWRPLORC;;;IU)(A;CI;CCLCSWRPLORC;;;NS)(A;CI;CCLCSWRPLORC;;;LS)(A;CI;CCLCSWRPDTLORC;;;NO)(A;CI;CCLCSWDTLOCRRC;;;S-1-5-80-2940520708-3855866260-481812779-327648279-1710889582)(A;CI;CCLCSWRPLORC;;;AC)(A;CI;CCLCSWRPLORC;;;S-1-15-3-1)(A;CI;CCLCSWRPLORC;;;S-1-15-3-2)(A;CI;CCLCSWRPLORC;;;S-1-15-3-3)S:(AU;FA;CCLCSWRPDTLORC;;;WD) Service Name : DoSvc Display Name : Delivery Optimization Image Path : C:\WINDOWS\System32\svchost.exe -k NetworkService -p Startup Type : Manual (Triggered) Log On As : NT Authority\NetworkService Permissions : O:SYG:SYD:(A;;CCLCSWRPLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;DCRC;;;S-1-5-80-3055155277-3816794035-3994065555-2874236192-2193176987)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : dot3svc Display Name : Wired AutoConfig Image Path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : DPS Display Name : Diagnostic Policy Service Image Path : C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork -p Startup Type : Auto Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRRC;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : DsmSvc Display Name : Device Setup Manager Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;RP;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : DsSvc Display Name : Data Sharing Service Image Path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;LCRP;;;WD)(A;;LCRP;;;AC) Service Name : DusmSvc Display Name : Data Usage Image Path : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Auto Log On As : NT Authority\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : Eaphost Display Name : Extensible Authentication Protocol Image Path : C:\WINDOWS\System32\svchost.exe -k netsvcs -p Startup Type : Manual Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : edgeupdate Display Name : Microsoft Edge Update Service (edgeupdate) Image Path : "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svc Startup Type : Auto (Delayed, Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : edgeupdatem Display Name : Microsoft Edge Update Service (edgeupdatem) Image Path : "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /medsvc Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : EFS Display Name : Encrypting File System (EFS) Image Path : C:\WINDOWS\System32\lsass.exe Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPLOCRRC;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWRPLOCRRC;;;SU)(A;;LCRP;;;AU)(A;;LCRP;;;AC)S:(AU;SAFA;DCSDWDWO;;;WD) Service Name : embeddedmode Display Name : Embedded Mode Image Path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464D:(A;;LCRP;;;AC)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCLCSWRPWPDTLOCRRC;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWRPLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : EntAppSvc Display Name : Enterprise App Management Service Image Path : C:\WINDOWS\system32\svchost.exe -k appmodel -p Startup Type : Manual Log On As : LocalSystem Permissions : O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464D:(A;;LCRP;;;AC)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCLCSWRPWPDTLOCRRC;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWRPLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : EventLog Display Name : Windows Event Log Image Path : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Auto Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;LCLO;;;AC)S:(AU;SA;DCRPWPDTCRSDWDWO;;;WD)(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : EventSystem Display Name : COM+ Event System Image Path : C:\WINDOWS\system32\svchost.exe -k LocalService -p Startup Type : Auto Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : Fax Display Name : Fax Image Path : C:\WINDOWS\system32\fxssvc.exe Startup Type : Manual Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;LCRP;;;WD)(A;;CCLCSWRPWPDTLOCRRC;;;S-1-5-80-2117685068-4011115449-2646761356-2137676340-222423812)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;AU) Service Name : fdPHost Display Name : Function Discovery Provider Host Image Path : C:\WINDOWS\system32\svchost.exe -k LocalService -p Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : FDResPub Display Name : Function Discovery Resource Publication Image Path : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation -p Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;NO)S:AI(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : fhsvc Display Name : File History Service Image Path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Auto (Delayed, Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLOCRRC;;;AU) Service Name : FontCache Display Name : Windows Font Cache Service Image Path : C:\WINDOWS\system32\svchost.exe -k LocalService -p Startup Type : Auto Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;RP;;;IU)(A;;RP;;;SU)(A;;CCLCSWRPLOCRRC;;;AC)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : FontCache3.0.0.0 Display Name : Windows Presentation Foundation Font Cache 3.0.0.0 Image Path : C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe Startup Type : Manual Log On As : NT Authority\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;RP;;;IU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : FrameServer Display Name : Windows Camera Frame Server Image Path : C:\WINDOWS\System32\svchost.exe -k Camera Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : GameInputSvc Display Name : GameInput Service Image Path : C:\WINDOWS\System32\GameInputSvc.exe Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : gpsvc Display Name : Group Policy Client Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p Startup Type : Auto (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCLCSWLOCRRC;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;SAFA;DCSDWDWO;;;WD) Service Name : GraphicsPerfSvc Display Name : GraphicsPerfSvc Image Path : C:\WINDOWS\System32\svchost.exe -k GraphicsPerfSvcGroup Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : hidserv Display Name : Human Interface Device Service Image Path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : HvHost Display Name : HV Host Service Image Path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : icssvc Display Name : Windows Mobile Hotspot Service Image Path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : NT Authority\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;LCRP;;;WD)(A;;CCLCSWRPLOCRRC;;;S-1-15-2-155514346-2573954481-755741238-1654018636-1233331829-3075935687-2861478708)(A;;CCLCSWRPLOCRRC;;;S-1-15-2-1121366727-2517420131-1100342901-1044639592-4216533239-371662368-2140263060)(A;;CCLCSWRPLOCRRC;;;S-1-15-2-2543942650-389403887-2808249486-612059083-208952635-835677591-2189227231)(A;;CCLCSWRPLOCRRC;;;S-1-15-2-3801529221-2855318152-1555692692-2306892612-2338533892-3542301781-2904385964) Service Name : igfxCUIService2.0.0.0 Display Name : Intel(R) HD Graphics Control Panel Service Image Path : C:\WINDOWS\system32\igfxCUIService.exe Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : IKEEXT Display Name : IKE and AuthIP IPsec Keying Modules Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : InstallService Display Name : Microsoft Store Install Service Image Path : C:\WINDOWS\System32\svchost.exe -k netsvcs -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : iphlpsvc Display Name : IP Helper Image Path : C:\WINDOWS\System32\svchost.exe -k NetSvcs -p Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : IpxlatCfgSvc Display Name : IP Translation Configuration Service Image Path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWRPWPLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : KeyIso Display Name : CNG Key Isolation Image Path : C:\WINDOWS\system32\lsass.exe Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWRPLOCRRC;;;SU)(A;;CCLCSWLOCRRC;;;SU)(A;;CR;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : KtmRm Display Name : KtmRm for Distributed Transaction Coordinator Image Path : C:\WINDOWS\System32\svchost.exe -k NetworkServiceAndNoImpersonation -p Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;CCLCSWRPLOCRRC;;;S-1-2-0)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWLORC;;;AU)(A;;CCLCSWRPLOCRRC;;;SU)(A;;CCLCSWLORC;;;S-1-5-80-2818357584-3387065753-4000393942-342927828-138088443)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : LanmanServer Display Name : Server Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p Startup Type : Auto (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : LanmanWorkstation Display Name : Workstation Image Path : C:\WINDOWS\System32\svchost.exe -k NetworkService -p Startup Type : Auto Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : lfsvc Display Name : Geolocation Service Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD: Service Name : LicenseManager Display Name : Windows License Manager Service Image Path : C:\WINDOWS\System32\svchost.exe -k LocalService -p Startup Type : Manual (Triggered) Log On As : NT Authority\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : lltdsvc Display Name : Link-Layer Topology Discovery Mapper Image Path : C:\WINDOWS\System32\svchost.exe -k LocalService -p Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : lmhosts Display Name : TCP/IP NetBIOS Helper Image Path : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : LSM Display Name : Local Session Manager Image Path : C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSW;;;AU)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;SY)(A;;CCLCSWLORC;;;BA)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : LxpSvc Display Name : Language Experience Service Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : MapsBroker Display Name : Downloaded Maps Manager Image Path : C:\WINDOWS\System32\svchost.exe -k NetworkService -p Startup Type : Auto (Delayed) Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;LCRP;;;AU)(A;;LCRP;;;AC) Service Name : McpManagementService Display Name : McpManagementService Image Path : C:\WINDOWS\system32\svchost.exe -k McpManagementServiceGroup Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : MicrosoftEdgeElevationService Display Name : Microsoft Edge Elevation Service (MicrosoftEdgeElevationService) Image Path : "C:\Program Files (x86)\Microsoft\Edge\Application\124.0.2478.67\elevation_service.exe" Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : MixedRealityOpenXRSvc Display Name : Windows Mixed Reality OpenXR Service Image Path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : mpssvc Display Name : Windows Defender Firewall Image Path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p Startup Type : Auto Log On As : NT Authority\LocalService Permissions : O:SYG:SYD:(A;;CCLCLORC;;;AU)(A;;CCDCLCSWRPLORCWDWO;;;SY)(A;;CCLCSWRPLORCWDWO;;;BA)(A;;CCLCLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : MSDTC Display Name : Distributed Transaction Coordinator Image Path : C:\WINDOWS\System32\msdtc.exe Startup Type : Manual Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;CCLCSWRPLORC;;;S-1-2-0)(A;;CCDCLCSWRPWPDTLORC;;;SY)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;BA)(A;;CCLCSWRPLORC;;;IU)(A;;CCLCSWLORC;;;AU)(A;;CCLCSWRPLORC;;;SU)(A;;CCLCSWLORC;;;S-1-5-80-3960419045-2460139048-4046793004-1809597027-2250574426)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : MSiSCSI Display Name : Microsoft iSCSI Initiator Service Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : msiserver Display Name : Windows Installer Image Path : C:\WINDOWS\system32\msiexec.exe /V Startup Type : Manual Log On As : LocalSystem Permissions : O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464D:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCLCSWRPWPDTLOCRRC;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWRPLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : MsKeyboardFilter Display Name : Microsoft Keyboard Filter Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p Startup Type : Disabled Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : NaturalAuthentication Display Name : Natural Authentication Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWRPLOCRRC;;;AC)(A;;CCLCSWLOCRRC;;;SU)(A;;CR;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : NcaSvc Display Name : Network Connectivity Assistant Image Path : C:\WINDOWS\System32\svchost.exe -k NetSvcs -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : NcbService Display Name : Network Connection Broker Image Path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : NcdAutoSetup Display Name : Network Connected Devices Auto-Setup Image Path : C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork -p Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : Netlogon Display Name : Netlogon Image Path : C:\WINDOWS\system32\lsass.exe Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : Netman Display Name : Network Connections Image Path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : netprofm Display Name : Network List Service Image Path : C:\WINDOWS\System32\svchost.exe -k LocalService -p Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : NetSetupSvc Display Name : Network Setup Service Image Path : C:\WINDOWS\System32\svchost.exe -k netsvcs -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRP;;;NS)(A;;CCLCSWRP;;;LS)(A;;CCLCSWRP;;;AC)(A;;CCLCSWRP;;;BU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCLCSWRP;;;NO)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464) Service Name : NetTcpPortSharing Display Name : Net.Tcp Port Sharing Service Image Path : C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe Startup Type : Disabled Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;AU)(A;;LCRP;;;IU)(A;;LCRP;;;SU) Service Name : NgcCtnrSvc Display Name : Microsoft Passport Container Image Path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCDCLCSWRPWPDTLORCWDWO;;;SY)(A;;CCLCSWRPWPDTLORCWDWO;;;BA)(A;;CCLCLORC;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : NgcSvc Display Name : Microsoft Passport Image Path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCLORC;;;AU)(A;;CCDCLCSWRPWPDTLORCWDWO;;;SY)(A;;CCLCSWRPLORCWDWO;;;BA)(A;;CCLCLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : NlaSvc Display Name : Network Location Awareness Image Path : C:\WINDOWS\System32\svchost.exe -k NetworkService -p Startup Type : Auto Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;CI;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;CI;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCLCSWRPLORC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCLCSWRPRC;;;S-1-5-80-3141615172-2057878085-1754447212-2405740020-3916490453) Service Name : nsi Display Name : Network Store Interface Service Image Path : C:\WINDOWS\system32\svchost.exe -k LocalService -p Startup Type : Auto Log On As : NT Authority\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : p2pimsvc Display Name : Peer Networking Identity Manager Image Path : C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(D;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BG)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLORC;;;SO)(A;;CCLCSWRPLORC;;;IU)(A;;CCLCSWRPLORC;;;RD)(A;;CCLCSWRPLORC;;;BU) Service Name : p2psvc Display Name : Peer Networking Grouping Image Path : C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(D;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BG)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLORC;;;SO)(A;;CCLCSWRPLORC;;;IU)(A;;CCLCSWRPLORC;;;RD)(A;;CCLCSWRPLORC;;;BU) Service Name : PcaSvc Display Name : Program Compatibility Assistant Service Image Path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CR;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : PeerDistSvc Display Name : BranchCache Image Path : C:\WINDOWS\System32\svchost.exe -k PeerDist Startup Type : Manual Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SO)(A;;CCLCSWRPLORC;;;IU)(A;;CCLCSWRPLORC;;;RD)(A;;CCLCSWRPLORC;;;SU)(A;;CCLCSWRPLORC;;;BU)(A;;LCRPLO;;;AC)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : perceptionsimulation Display Name : Windows Perception Simulation Service Image Path : C:\WINDOWS\system32\PerceptionSimulation\PerceptionSimulationService.exe Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : PerfHost Display Name : Performance Counter DLL Host Image Path : C:\WINDOWS\SysWow64\perfhost.exe Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : PhoneSvc Display Name : Phone Service Image Path : C:\WINDOWS\system32\svchost.exe -k LocalService -p Startup Type : Manual (Triggered) Log On As : NT Authority\LocalService Permissions : O:SYG:SYD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;LCRP;;;WD)(A;;LCRP;;;AC) Service Name : pla Display Name : Performance Logs & Alerts Image Path : C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork -p Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCR;;;SO)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCLCRPLOCR;;;WD)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : PlugPlay Display Name : Plug and Play Image Path : C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : PNRPAutoReg Display Name : PNRP Machine Name Publication Service Image Path : C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(D;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BG)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLORC;;;SO)(A;;CCLCSWRPLORC;;;IU)(A;;CCLCSWRPLORC;;;RD) Service Name : PNRPsvc Display Name : Peer Name Resolution Protocol Image Path : C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(D;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BG)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLORC;;;SO)(A;;CCLCSWRPLORC;;;IU)(A;;CCLCSWRPLORC;;;RD)(A;;CCLCSWRPLORC;;;BU) Service Name : PolicyAgent Display Name : IPsec Policy Agent Image Path : C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : NT Authority\NetworkService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : Power Display Name : Power Image Path : C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : PrintNotify Display Name : Printer Extensions and Notifications Image Path : C:\WINDOWS\system32\svchost.exe -k print Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : ProfSvc Display Name : User Profile Service Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : PushToInstall Display Name : Windows PushToInstall Service Image Path : C:\WINDOWS\System32\svchost.exe -k netsvcs -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : QWAVE Display Name : Quality Windows Audio Video Experience Image Path : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation -p Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPLO;;;IU)(A;;CCLCSWRPLO;;;NS)(A;;CCLCSWRPLO;;;UD)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA) Service Name : RasAuto Display Name : Remote Access Auto Connection Manager Image Path : C:\WINDOWS\System32\svchost.exe -k netsvcs -p Startup Type : Manual Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;AU) Service Name : RasMan Display Name : Remote Access Connection Manager Image Path : C:\WINDOWS\System32\svchost.exe -k netsvcs Startup Type : Manual Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLOCRRC;;;S-1-15-3-1024-1068037383-729401668-2768096886-125909118-1680096985-174794564-3112554050-3241210738) Service Name : RemoteAccess Display Name : Routing and Remote Access Image Path : C:\WINDOWS\System32\svchost.exe -k netsvcs Startup Type : Disabled Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;AU) Service Name : RemoteRegistry Display Name : Remote Registry Image Path : C:\WINDOWS\system32\svchost.exe -k localService -p Startup Type : Disabled Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : RetailDemo Display Name : Retail Demo Service Image Path : C:\WINDOWS\System32\svchost.exe -k rdxgroup Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : RmSvc Display Name : Radio Management Service Image Path : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;CI;CCLCSWRPWPDTLOCRRC;;;LS)(A;CI;CCDCLCSWRPWPDTLOCRRC;;;SY)(A;CI;CCDCLCSWRPWPDTLOCRRC;;;BA)(A;CI;CCLCSWRPWPDTLOCRRC;;;BU) Service Name : RpcEptMapper Display Name : RPC Endpoint Mapper Image Path : C:\WINDOWS\system32\svchost.exe -k RPCSS -p Startup Type : Auto Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;CCLCLORC;;;AU)(A;;CCDCLCSWRPWPDTLORCWDWO;;;SY)(A;;CCLCSWRPWPDTLORCWDWO;;;BA)(A;;CCLCRPLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : RpcLocator Display Name : Remote Procedure Call (RPC) Locator Image Path : C:\WINDOWS\system32\locator.exe Startup Type : Manual Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : RpcSs Display Name : Remote Procedure Call (RPC) Image Path : C:\WINDOWS\system32\svchost.exe -k rpcss -p Startup Type : Auto Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;CCLCLORC;;;AU)(A;;CCDCLCSWRPWPDTLORCWDWO;;;SY)(A;;CCLCSWRPWPDTLORCWDWO;;;BA)(A;;CCLCLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : SamSs Display Name : Security Accounts Manager Image Path : C:\WINDOWS\system32\lsass.exe Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLO;;;IU)(A;;CCLCSWLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : SCardSvr Display Name : Smart Card Image Path : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:BAG:BAD:(A;CI;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRRC;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;SAFA;WDWO;;;BA) Service Name : ScDeviceEnum Display Name : Smart Card Device Enumeration Service Image Path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:BAG:BAD:(A;CI;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRRC;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;RPWP;;;S-1-5-80-3993802144-2555107232-3516638766-2735499450-3275915967)S:(AU;SAFA;WDWO;;;BA) Service Name : Schedule Display Name : Task Scheduler Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWLORC;;;AU)(A;;CCLCSWRPDTLOCRRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCLCSWLORC;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : SCPolicySvc Display Name : Smart Card Removal Policy Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs Startup Type : Manual Log On As : LocalSystem Permissions : O:BAG:BAD:(A;CI;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRRC;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;SAFA;WDWO;;;BA) Service Name : SDRSVC Display Name : Windows Backup Image Path : C:\WINDOWS\system32\svchost.exe -k SDRSVC Startup Type : Manual Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : seclogon Display Name : Secondary Logon Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPDTLOCRRC;;;IU)(A;;CCLCSWDTLOCRRC;;;SU)(A;;CCLCSWRPDTLOCRRC;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : SecurityHealthService Display Name : Windows Security Service Image Path : C:\WINDOWS\system32\SecurityHealthService.exe Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPLORC;;;BU)(A;;CCLCSWRPLOCRRC;;;SY)(A;;CCLCSWRPLOCRRC;;;BA)(A;;CCLCSWRPLORC;;;IU)(A;;CCLCSWRPLORC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;S-1-5-80-1601830629-990752416-3372939810-977361409-3075122917)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-80-259296475-4084429506-1152984619-38739575-565535606)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : SEMgrSvc Display Name : Payments and NFC/SE Manager Image Path : C:\WINDOWS\system32\svchost.exe -k LocalService -p Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD: Service Name : SENS Display Name : System Event Notification Service Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCR;;;SO)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;LCLORC;;;AC)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : Sense Display Name : Windows Defender Advanced Threat Protection Service Image Path : "C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe" Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;OICIIO;GA;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRRCWDWO;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWRPLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : SensorDataService Display Name : Sensor Data Service Image Path : C:\WINDOWS\System32\SensorDataService.exe Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : SensorService Display Name : Sensor Service Image Path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;LCRPCR;;;AC)(A;;LCRPCR;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : SensrSvc Display Name : Sensor Monitoring Service Image Path : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation -p Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;LCRPCR;;;AC)(A;;LCRPCR;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : SessionEnv Display Name : Remote Desktop Configuration Image Path : C:\WINDOWS\System32\svchost.exe -k netsvcs -p Startup Type : Manual Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;RPWP;;;S-1-5-80-446051430-1559341753-4161941529-1950928533-810483104)(A;;RPWP;;;S-1-5-80-4130899010-3337817248-2959896732-3640118089-1866760602) Service Name : SgrmBroker Display Name : System Guard Runtime Monitor Broker Image Path : C:\WINDOWS\system32\SgrmBroker.exe Startup Type : Auto (Delayed, Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : SharedAccess Display Name : Internet Connection Sharing (ICS) Image Path : C:\WINDOWS\System32\svchost.exe -k netsvcs -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWRPWPLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;S-1-5-80-3935728946-315639613-922904133-3250794525-491832002)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : SharedRealitySvc Display Name : Spatial Data Service Image Path : C:\WINDOWS\system32\svchost.exe -k LocalService -p Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CR;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : ShellHWDetection Display Name : Shell Hardware Detection Image Path : C:\WINDOWS\System32\svchost.exe -k netsvcs -p Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : shpamsvc Display Name : Shared PC Account Manager Image Path : C:\WINDOWS\System32\svchost.exe -k netsvcs -p Startup Type : Disabled Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : smphost Display Name : Microsoft Storage Spaces SMP Image Path : C:\WINDOWS\System32\svchost.exe -k smphost Startup Type : Manual Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCRP;;;AU)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCLCSWLOCRRC;;;S-1-5-32-582)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : SmsRouter Display Name : Microsoft Windows SMS Router Service. Image Path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : NT Authority\LocalService Permissions : O:SYG:SYD:(A;;CCLCLORC;;;AU)(A;;CCDCLCSWRPWPDTLORCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLORCWDWO;;;BA)(A;;CCLCRPLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : SNMP Display Name : SNMP Service Image Path : C:\WINDOWS\System32\snmp.exe Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : SNMPTRAP Display Name : SNMP Trap Image Path : C:\WINDOWS\System32\snmptrap.exe Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : spectrum Display Name : Windows Perception Service Image Path : C:\WINDOWS\system32\spectrum.exe Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;LCRP;;;LS)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : Spooler Display Name : Print Spooler Image Path : C:\WINDOWS\System32\spoolsv.exe Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : sppsvc Display Name : Software Protection Image Path : C:\WINDOWS\system32\sppsvc.exe Startup Type : Auto (Delayed, Triggered) Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;CCDCLCSWRPWPDTLOCRRC;;;SY)(A;;CCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;LCRPLO;;;AC)(A;;CCLCSWRPLOCRRC;;;SU)(A;;LCRP;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : SSDPSRV Display Name : SSDP Discovery Image Path : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation -p Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPLORC;;;SO)(A;;CCLCSWRPLORC;;;IU)(A;;CCLCSWRPWPDTLOCRRC;;;LS)(A;;CCLCSWRPWPDTLOCRRC;;;NS) Service Name : ssh-agent Display Name : OpenSSH Authentication Agent Image Path : C:\WINDOWS\System32\OpenSSH\ssh-agent.exe Startup Type : Disabled Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;RP;;;AU) Service Name : sshd Display Name : OpenSSH SSH Server Image Path : C:\WINDOWS\System32\OpenSSH\sshd.exe Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : SshdBroker Display Name : SshdBroker Image Path : C:\WINDOWS\system32\svchost.exe -k SshBrokerGroup Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : SstpSvc Display Name : Secure Socket Tunneling Protocol Service Image Path : C:\WINDOWS\system32\svchost.exe -k LocalService -p Startup Type : Manual Log On As : NT Authority\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;NO)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCLCSWRPLOCRRC;;;S-1-15-3-1024-1068037383-729401668-2768096886-125909118-1680096985-174794564-3112554050-3241210738)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : StateRepository Display Name : State Repository Service Image Path : C:\WINDOWS\system32\svchost.exe -k appmodel -p Startup Type : Manual Log On As : LocalSystem Permissions : O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464D:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCLCSWRPWPDTLOCRRC;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWRPLOCRRC;;;SU)(A;;LCRP;;;AC)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : stisvc Display Name : Windows Image Acquisition (WIA) Image Path : C:\WINDOWS\system32\svchost.exe -k imgsvc Startup Type : Manual (Triggered) Log On As : NT Authority\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CR;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : StorSvc Display Name : Storage Service Image Path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Auto (Delayed, Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : svsvc Display Name : Spot Verifier Image Path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : swprv Display Name : Microsoft Software Shadow Copy Provider Image Path : C:\WINDOWS\System32\svchost.exe -k swprv Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : SysMain Display Name : SysMain Image Path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : SystemEventsBroker Display Name : System Events Broker Image Path : C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p Startup Type : Auto (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCLORC;;;AU)(A;;CCDCLCSWRPWPDTLORCWDWO;;;SY)(A;;CCLCSWRPWPDTLORCWDWO;;;BA)(A;;CCLCRPLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : TabletInputService Display Name : Touch Keyboard and Handwriting Panel Service Image Path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;RP;;;WD) Service Name : TapiSrv Display Name : Telephony Image Path : C:\WINDOWS\System32\svchost.exe -k NetworkService -p Startup Type : Manual Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWRPLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : TermService Display Name : Remote Desktop Services Image Path : C:\WINDOWS\System32\svchost.exe -k NetworkService Startup Type : Manual Log On As : NT Authority\NetworkService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : Themes Display Name : Themes Image Path : C:\WINDOWS\System32\svchost.exe -k netsvcs -p Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : TieringEngineService Display Name : Storage Tiers Management Image Path : C:\WINDOWS\system32\TieringEngineService.exe Startup Type : Manual Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : TimeBrokerSvc Display Name : Time Broker Image Path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCLORC;;;AU)(A;;CCDCLCSWRPWPDTLORCWDWO;;;SY)(A;;CCLCSWRPWPDTLORCWDWO;;;BA)(A;;CCLCRPLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : TokenBroker Display Name : Web Account Manager Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : TrkWks Display Name : Distributed Link Tracking Client Image Path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : TroubleshootingSvc Display Name : Recommended Troubleshooting Service Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : TrustedInstaller Display Name : Windows Modules Installer Image Path : C:\WINDOWS\servicing\TrustedInstaller.exe Startup Type : Manual Log On As : localSystem Permissions : O:BAG:BAD:(A;CI;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRRC;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;SAFA;WDWO;;;BA) Service Name : tzautoupdate Display Name : Auto Time Zone Updater Image Path : C:\WINDOWS\system32\svchost.exe -k LocalService -p Startup Type : Disabled Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : UevAgentService Display Name : User Experience Virtualization Service Image Path : C:\WINDOWS\system32\AgentService.exe Startup Type : Disabled Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : UmRdpService Display Name : Remote Desktop Services UserMode Port Redirector Image Path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;RPWP;;;S-1-5-80-446051430-1559341753-4161941529-1950928533-810483104) Service Name : upnphost Display Name : UPnP Device Host Image Path : C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation -p Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPLORC;;;SO)(A;;CCLCSWRPLORC;;;IU)(A;;CCLCSWRPWPDTLOCRRC;;;LS)(A;;CCLCSWRPWPDTLOCRRC;;;NS) Service Name : UserManager Display Name : User Manager Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p Startup Type : Auto (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : UsoSvc Display Name : Update Orchestrator Service Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p Startup Type : Auto (Delayed) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : VacSvc Display Name : Volumetric Audio Compositor Service Image Path : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : VaultSvc Display Name : Credential Manager Image Path : C:\WINDOWS\system32\lsass.exe Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWRPLOCRRC;;;SU)(A;;CR;;;AU)(A;;LCRP;;;NS)(A;;LCRP;;;LS)(A;;LCRP;;;AC)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : vds Display Name : Virtual Disk Image Path : C:\WINDOWS\System32\vds.exe Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;AU)(A;;RPWPDT;;;BO)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : vmicguestinterface Display Name : Hyper-V Guest Service Interface Image Path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : vmicheartbeat Display Name : Hyper-V Heartbeat Service Image Path : C:\WINDOWS\system32\svchost.exe -k ICService -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : vmickvpexchange Display Name : Hyper-V Data Exchange Service Image Path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : vmicrdv Display Name : Hyper-V Remote Desktop Virtualization Service Image Path : C:\WINDOWS\system32\svchost.exe -k ICService -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : vmicshutdown Display Name : Hyper-V Guest Shutdown Service Image Path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : vmictimesync Display Name : Hyper-V Time Synchronization Service Image Path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : vmicvmsession Display Name : Hyper-V PowerShell Direct Service Image Path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : vmicvss Display Name : Hyper-V Volume Shadow Copy Requestor Image Path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : VSS Display Name : Volume Shadow Copy Image Path : C:\WINDOWS\system32\vssvc.exe Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : W32Time Display Name : Windows Time Image Path : C:\WINDOWS\system32\svchost.exe -k LocalService Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCLCSWRPLOCRRC;;;LS)(A;;CCSWWPLORC;;;LS)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-80-3169285310-278349998-1452333686-3865143136-4212226833) Service Name : WaaSMedicSvc Display Name : Windows Update Medic Service Image Path : C:\WINDOWS\system32\svchost.exe -k wusvcs -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : WalletService Display Name : WalletService Image Path : C:\WINDOWS\System32\svchost.exe -k appmodel -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WarpJITSvc Display Name : WarpJITSvc Image Path : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted Startup Type : Manual (Triggered) Log On As : NT Authority\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : wbengine Display Name : Block Level Backup Engine Service Image Path : "C:\WINDOWS\system32\wbengine.exe" Startup Type : Manual Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WbioSrvc Display Name : Windows Biometric Service Image Path : C:\WINDOWS\system32\svchost.exe -k WbioSvcGroup Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CR;;;AU)(A;;CCLCRP;;;AC)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : Wcmsvc Display Name : Windows Connection Manager Image Path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Auto (Triggered) Log On As : NT Authority\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU) Service Name : wcncsvc Display Name : Windows Connect Now - Config Registrar Image Path : C:\WINDOWS\System32\svchost.exe -k LocalServiceAndNoImpersonation -p Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;IU)(A;;CCLCSWRPWPDTLOCRRC;;;LS)(A;;CCLCSWRPWPDTLOCRSDRC;;;NO)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WdiServiceHost Display Name : Diagnostic Service Host Image Path : C:\WINDOWS\System32\svchost.exe -k LocalService -p Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWWPDTLOCRRC;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;S-1-5-80-2970612574-78537857-698502321-558674196-1451644582)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WdiSystemHost Display Name : Diagnostic System Host Image Path : C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWWPDTLOCRRC;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;S-1-5-80-2970612574-78537857-698502321-558674196-1451644582)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WdNisSvc Display Name : Microsoft Defender Antivirus Network Inspection Service Image Path : "C:\Program Files\Windows Defender\NisSrv.exe" Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPLOCRRC;;;BU)(A;;CCLCSWRPLOCRRC;;;SY)(A;;CCLCSWRPLOCRRC;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWRPLOCRRC;;;SU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-80-1913148863-3492339771-4165695881-2087618961-4109116736)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WebClient Display Name : WebClient Image Path : C:\WINDOWS\system32\svchost.exe -k LocalService -p Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WebManagement Display Name : Web Management Image Path : C:\WINDOWS\system32\WebManagement.exe Startup Type : Disabled Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : Wecsvc Display Name : Windows Event Collector Image Path : C:\WINDOWS\system32\svchost.exe -k NetworkService -p Startup Type : Manual Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WEPHOSTSVC Display Name : Windows Encryption Provider Host Service Image Path : C:\WINDOWS\system32\svchost.exe -k WepHostSvcGroup Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : wercplsupport Display Name : Problem Reports Control Panel Support Image Path : C:\WINDOWS\System32\svchost.exe -k netsvcs -p Startup Type : Manual Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WerSvc Display Name : Windows Error Reporting Service Image Path : C:\WINDOWS\System32\svchost.exe -k WerSvcGroup Startup Type : Manual (Triggered) Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WFDSConMgrSvc Display Name : Wi-Fi Direct Services Connection Manager Service Image Path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WiaRpc Display Name : Still Image Acquisition Events Image Path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCLCSWRPLOCRRC;;;S-1-5-80-3182985763-1431228038-2757062859-428472846-3914011746)(A;;CR;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WinDefend Display Name : Microsoft Defender Antivirus Service Image Path : "C:\Program Files\Windows Defender\MsMpEng.exe" Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPLOCRRC;;;BU)(A;;CCLCSWRPLOCRRC;;;SY)(A;;CCLCSWRPLOCRRC;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWRPLOCRRC;;;SU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-80-1913148863-3492339771-4165695881-2087618961-4109116736)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WinHttpAutoProxySvc Display Name : WinHTTP Web Proxy Auto-Discovery Service Image Path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPLOSDRC;;;SY)(A;;CCLCSWRPLOSDRC;;;BA)(A;;CCLCSWRPLORC;;;AU)(A;;CCLCSWRPLORC;;;IU)(A;;CCLCSWRPLORC;;;SU)(A;;LCRPLO;;;AC)(A;;LCRPLO;;;S-1-15-3-1)(A;;LCRPLO;;;S-1-15-3-2)(A;;LCRPLO;;;S-1-15-3-3)S:(AU;FA;CCLCSWRPLOSDRC;;;WD) Service Name : Winmgmt Display Name : Windows Management Instrumentation Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p Startup Type : Auto Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WinRM Display Name : Windows Remote Management (WS-Management) Image Path : C:\WINDOWS\System32\svchost.exe -k NetworkService -p Startup Type : Manual Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : wisvc Display Name : Windows Insider Service Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WlanSvc Display Name : WLAN AutoConfig Image Path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;RPWPDT;;;S-1-5-80-3906544942-1489856346-3706913989-164347954-1900376235) Service Name : wlidsvc Display Name : Microsoft Account Sign-in Assistant Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU) Service Name : wlpasvc Display Name : Local Profile Assistant Service Image Path : C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : NT Authority\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCLCSWRPWPDTLOCRRC;;;LS)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLORC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCLCSWLORC;;;S-1-15-2-155514346-2573954481-755741238-1654018636-1233331829-3075935687-2861478708)(A;;CCLCSWLORC;;;S-1-15-2-3083765670-2301828090-3288705196-2597965991-2057664196-4044987863-2761340229)(A;;CCLCSWLORC;;;S-1-15-2-3784866113-3187381476-3433752343-3391928953-3760210436-1684329488-1912184601) Service Name : WManSvc Display Name : Windows Management Service Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : wmiApSrv Display Name : WMI Performance Adapter Image Path : C:\WINDOWS\system32\wbem\WmiApSrv.exe Startup Type : Manual Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WMPNetworkSvc Display Name : Windows Media Player Network Sharing Service Image Path : "C:\Program Files\Windows Media Player\wmpnetwk.exe" Startup Type : Manual Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : workfolderssvc Display Name : Work Folders Image Path : C:\WINDOWS\System32\svchost.exe -k LocalService -p Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WpcMonSvc Display Name : Parental Controls Image Path : C:\WINDOWS\system32\svchost.exe -k LocalService Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WPDBusEnum Display Name : Portable Device Enumerator Service Image Path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WpnService Display Name : Windows Push Notifications System Service Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU) Service Name : wscsvc Display Name : Security Center Image Path : C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Auto (Delayed) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPLORC;;;BU)(A;;CCLCSWRPLOCRRC;;;SY)(A;;CCLCSWRPLOCRRC;;;BA)(A;;CCLCSWRPLORC;;;IU)(A;;CCLCSWRPLORC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;S-1-5-80-1601830629-990752416-3372939810-977361409-3075122917)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-80-259296475-4084429506-1152984619-38739575-565535606)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WSearch Display Name : Windows Search Image Path : C:\WINDOWS\system32\SearchIndexer.exe /Embedding Startup Type : Auto (Delayed) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCLCSWLORC;;;S-1-15-3-1024-724741592-1210917904-489960769-637019204-3345707629-3097053430-1727148295-85063603) Service Name : wuauserv Display Name : Windows Update Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : WwanSvc Display Name : WWAN AutoConfig Image Path : C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCLCRPLO;;;LS)(A;;LC;;;AC) Service Name : XblAuthManager Display Name : Xbox Live Auth Manager Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : XblGameSave Display Name : Xbox Live Game Save Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : XboxGipSvc Display Name : Xbox Accessory Management Service Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : XboxNetApiSvc Display Name : Xbox Live Networking Service Image Path : C:\WINDOWS\system32\svchost.exe -k netsvcs -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : AarSvc_xxxxxx Display Name : Agent Activation Runtime_xxxxxx Image Path : C:\WINDOWS\system32\svchost.exe -k AarSvcGroup -p Startup Type : Manual Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : BcastDVRUserService_xxxxxx Display Name : GameDVR and Broadcast User Service_xxxxxx Image Path : C:\WINDOWS\system32\svchost.exe -k BcastDVRUserService Startup Type : Manual Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;IU)(A;;CCLCSWRPWPDTLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;AC)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA) Service Name : BluetoothUserService_xxxxxx Display Name : Bluetooth User Support Service_xxxxxx Image Path : C:\WINDOWS\system32\svchost.exe -k BthAppGroup -p Startup Type : Manual (Triggered) Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : CaptureService_xxxxxx Display Name : CaptureService_xxxxxx Image Path : C:\WINDOWS\system32\svchost.exe -k LocalService -p Startup Type : Manual Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : cbdhsvc_xxxxxx Display Name : Clipboard User Service_xxxxxx Image Path : C:\WINDOWS\system32\svchost.exe -k ClipboardSvcGroup -p Startup Type : Manual Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CR;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : CDPUserSvc_xxxxxx Display Name : Connected Devices Platform User Service_xxxxxx Image Path : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup Startup Type : Auto Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CR;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : ConsentUxUserSvc_xxxxxx Display Name : ConsentUX_xxxxxx Image Path : C:\WINDOWS\system32\svchost.exe -k DevicesFlow Startup Type : Manual Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;IU)(A;;CCLCSWRPWPDTLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA) Service Name : CredentialEnrollmentManagerUserSvc_xxxxxx Display Name : CredentialEnrollmentManagerUserSvc_xxxxxx Image Path : C:\WINDOWS\system32\CredentialEnrollmentManager.exe Startup Type : Manual Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;IU)(A;;CCLCSWRPWPDTLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;AC) Service Name : DeviceAssociationBrokerSvc_xxxxxx Display Name : DeviceAssociationBroker_xxxxxx Image Path : C:\WINDOWS\system32\svchost.exe -k DevicesFlow -p Startup Type : Manual Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;IU)(A;;CCLCSWRPWPDTLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;AC) Service Name : DevicePickerUserSvc_xxxxxx Display Name : DevicePicker_xxxxxx Image Path : C:\WINDOWS\system32\svchost.exe -k DevicesFlow Startup Type : Manual Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;IU)(A;;CCLCSWRPWPDTLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;AC)(A;;CCLCSWRPWPDTLOCRRC;;;S-1-5-21-2702878673-795188819-444038987-2781) Service Name : DevicesFlowUserSvc_xxxxxx Display Name : DevicesFlow_xxxxxx Image Path : C:\WINDOWS\system32\svchost.exe -k DevicesFlow Startup Type : Manual Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;IU)(A;;CCLCSWRPWPDTLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;AC)(A;;CCLCSWRPWPDTLOCRRC;;;S-1-5-21-2702878673-795188819-444038987-2781) Service Name : MessagingService_xxxxxx Display Name : MessagingService_xxxxxx Image Path : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup Startup Type : Manual (Triggered) Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : OneSyncSvc_xxxxxx Display Name : Sync Host_xxxxxx Image Path : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup Startup Type : Auto Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;LCRP;;;AC)(A;;LCRP;;;IU)(A;;LCRP;;;AU) Service Name : PimIndexMaintenanceSvc_xxxxxx Display Name : Contact Data_xxxxxx Image Path : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup Startup Type : Manual Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;IU)(A;;CCLCSWRPWPDTLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;AC)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA) Service Name : PrintWorkflowUserSvc_xxxxxx Display Name : PrintWorkflow_xxxxxx Image Path : C:\WINDOWS\system32\svchost.exe -k PrintWorkflow Startup Type : Manual (Triggered) Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;IU)(A;;CCLCSWRPWPDTLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;AC)(A;;CCLCSWRPWPDTLOCRRC;;;S-1-15-3-1024-4044835139-2658482041-3127973164-329287231-3865880861-1938685643-461067658-1087000422)(A;;CCLCSWRPWPDTLOCRRC;;;S-1-5-21-2702878673-795188819-444038987-2781) Service Name : UdkUserSvc_xxxxxx Display Name : Udk User Service_xxxxxx Image Path : C:\WINDOWS\system32\svchost.exe -k UdkSvcGroup Startup Type : Manual Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;IU)(A;;CCLCSWRPWPDTLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;AC)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA) Service Name : UnistoreSvc_xxxxxx Display Name : User Data Storage_xxxxxx Image Path : C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup Startup Type : Manual Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;IU)(A;;CCLCSWRPWPDTLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;AC)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA) Service Name : UserDataSvc_xxxxxx Display Name : User Data Access_xxxxxx Image Path : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup Startup Type : Manual Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;IU)(A;;CCLCSWRPWPDTLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;AC)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA) Service Name : WpnUserService_xxxxxx Display Name : Windows Push Notifications User Service_xxxxxx Image Path : C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup Startup Type : Auto Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;IU)(A;;CCLCSWRPWPDTLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;AC)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)
One small request: If you liked this post, please share this?
One "tiny" share from you would seriously help a lot with the growth of this blog. Some great suggestions:- Pin it!
- Share it to your favorite blog + Facebook, Reddit
- Tweet it!
Some said that setting wired auto-config and WLAN to automatic in Windows 10 services stopped limited access. Is this information action? If so why are they set to manual? Will setting them to automatic cause further Wifi issues such as not being able to access the internet at all?
I have latest build of win 10. my computer freezes after inactivity.But if I disable services locking up or freezing stops Therefore one of standard services is at fault
Cabt figure out which one is likely. Many others have tried to figure out win 10 freezing issue many to no avail. Any comment or help would help.
install “intel_haxm” software it will fix your PC freezing issue
Thank you! One of the services on my laptop was disabled and I didn’t know what the default setting was. Found it on your page and all is working well again. Thank you!
Thank you my pc was totally goosed now appears to be functioning ok glad you posted this probably saved me a fortune.
Thank you very much. After years of tweaking and recording tweaks, recently I didn’t. I lost track of what each service should be as default. Knew most, but you listed all, I followed directly and everything is great!
You saved me a lot of time so thanks again!!
As I can see so far everything looks good, except that for WlanSvc (WLAN AutoConfig) startup type needs to be Automatic.
But no matter…
THANK YOU!!!
This helped me out so much. Thank you kindly for posting such a wealth of information! I, for one, greatly appreciated your time and effort. I went through my services one by one to make sure the settings were all correct. Thanks again!!