The Windows 11 Services configuration defaults are provided on this page. The settings below are gathered from a Windows 11 Pro PC (clean install, rather than upgrade).
Updated on June 13, 2024 for Windows 11 Pro 23H2.
Note that some of these services may not be found in your system, depending upon the edition of Windows 11 you’ve installed. Also, you may find some non-Microsoft services (e.g., Intel services) in the list, which you may not find on your computer.
Windows 11 Default Services Configuration
Name | Startup Type | Log On As |
---|---|---|
ActiveX Installer (AxInstSV) | Manual | Local System |
Agent Activation Runtime_1768de | Manual | Local System |
AllJoyn Router Service | Manual (Trigger Start) | Local Service |
App Readiness | Manual | Local System |
Application Identity | Manual (Trigger Start) | Local Service |
Application Information | Manual (Trigger Start) | Local System |
Application Layer Gateway Service | Manual | Local Service |
Application Management | Manual | Local System |
AppX Deployment Service (AppXSVC) | Manual (Trigger Start) | Local System |
AssignedAccessManager Service | Manual (Trigger Start) | Local System |
Auto Time Zone Updater | Disabled | Local Service |
AVCTP service | Manual (Trigger Start) | Local Service |
Background Intelligent Transfer Service | Automatic (Delayed Start) | Local System |
Background Tasks Infrastructure Service | Automatic | Local System |
Base Filtering Engine | Automatic | Local Service |
BitLocker Drive Encryption Service | Manual (Trigger Start) | Local System |
Block Level Backup Engine Service | Manual | Local System |
Bluetooth Audio Gateway Service | Manual (Trigger Start) | Local Service |
Bluetooth Support Service | Manual (Trigger Start) | Local Service |
Bluetooth User Support Service_1768de | Manual (Trigger Start) | Local System |
BranchCache | Manual | Network Service |
Capability Access Manager Service | Manual (Trigger Start) | Local System |
CaptureService_1768de | Manual | Local System |
Cellular Time | Manual (Trigger Start) | Local Service |
Certificate Propagation | Manual (Trigger Start) | Local System |
Client License Service (ClipSVC) | Manual (Trigger Start) | Local System |
Clipboard User Service_1768de | Automatic (Delayed Start) | Local System |
Cloud Backup and Restore Service_1768de | Manual | Local System |
CNG Key Isolation | Manual (Trigger Start) | Local System |
COM+ Event System | Automatic | Local Service |
COM+ System Application | Manual | Local System |
Connected Devices Platform Service | Automatic (Delayed Start, Trigger Start) | Local Service |
Connected Devices Platform User Service_1768de | Automatic | Local System |
Connected User Experiences and Telemetry | Automatic | Local System |
ConsentUX User Service_1768de | Manual | Local System |
Contact Data_1768de | Manual | Local System |
CoreMessaging | Automatic | Local Service |
Credential Manager | Manual | Local System |
CredentialEnrollmentManagerUserSvc_1768de | Manual | Local System |
Cryptographic Services | Automatic (Trigger Start) | Network Service |
Data Sharing Service | Manual (Trigger Start) | Local System |
Data Usage | Automatic | Local Service |
DCOM Server Process Launcher | Automatic | Local System |
Declared Configuration(DC) service | Manual (Trigger Start) | Local System |
Delivery Optimization | Automatic (Delayed Start, Trigger Start) | Network Service |
Device Association Service | Manual (Trigger Start) | Local System |
Device Install Service | Manual (Trigger Start) | Local System |
Device Management Enrollment Service | Manual | Local System |
Device Management Wireless Application Protocol (WAP) Push message Routing Service |
Manual (Trigger Start) | Local System |
Device Setup Manager | Manual (Trigger Start) | Local System |
DeviceAssociationBroker_1768de | Manual | Local System |
DevicePicker_1768de | Manual | Local System |
DevicesFlow_1768de | Manual | Local System |
DevQuery Background Discovery Broker | Manual (Trigger Start) | Local System |
DHCP Client | Automatic | Local Service |
Diagnostic Execution Service | Manual (Trigger Start) | Local System |
Diagnostic Policy Service | Automatic | Local Service |
Diagnostic Service Host | Manual | Local Service |
Diagnostic System Host | Manual | Local System |
DialogBlockingService | Disabled | Local System |
Display Enhancement Service | Manual (Trigger Start) | Local System |
Display Policy Service | Automatic | Local Service |
Distributed Link Tracking Client | Automatic | Local System |
Distributed Transaction Coordinator | Manual | Network Service |
DNS Client | Automatic (Trigger Start) | Network Service |
Downloaded Maps Manager | Automatic (Delayed Start) | Network Service |
Embedded Mode | Manual (Trigger Start) | Local System |
Encrypting File System (EFS) | Manual (Trigger Start) | Local System |
Enterprise App Management Service | Manual | Local System |
Extensible Authentication Protocol | Manual | Local System |
File History Service | Manual (Trigger Start) | Local System |
Function Discovery Provider Host | Manual | Local Service |
Function Discovery Resource Publication | Manual (Trigger Start) | Local Service |
GameDVR and Broadcast User Service_1768de | Manual | Local System |
GameInput Service | Manual (Trigger Start) | Local System |
Geolocation Service | Manual (Trigger Start) | Local System |
GraphicsPerfSvc | Manual (Trigger Start) | Local System |
Group Policy Client | Automatic (Trigger Start) | Local System |
Human Interface Device Service | Manual (Trigger Start) | Local System |
HV Host Service | Manual (Trigger Start) | Local System |
Hyper-V Data Exchange Service | Manual (Trigger Start) | Local System |
Hyper-V Guest Service Interface | Manual (Trigger Start) | Local System |
Hyper-V Guest Shutdown Service | Manual (Trigger Start) | Local System |
Hyper-V Heartbeat Service | Manual (Trigger Start) | Local System |
Hyper-V PowerShell Direct Service | Manual (Trigger Start) | Local System |
Hyper-V Remote Desktop Virtualization Service | Manual (Trigger Start) | Local System |
Hyper-V Time Synchronization Service | Manual (Trigger Start) | Local Service |
Hyper-V Volume Shadow Copy Requestor | Manual (Trigger Start) | Local System |
IKE and AuthIP IPsec Keying Modules | Manual (Trigger Start) | Local System |
Internet Connection Sharing (ICS) | Manual (Trigger Start) | Local System |
Inventory and Compatibility Appraisal service | Manual | Local System |
IP Helper | Automatic | Local System |
IP Translation Configuration Service | Manual (Trigger Start) | Local System |
IPsec Policy Agent | Manual (Trigger Start) | Network Service |
KtmRm for Distributed Transaction Coordinator | Manual (Trigger Start) | Network Service |
Language Experience Service | Manual | Local System |
Link-Layer Topology Discovery Mapper | Manual | Local Service |
Local Profile Assistant Service | Manual (Trigger Start) | Local Service |
Local Session Manager | Automatic | Local System |
McpManagementService | Manual | Local System |
MessagingService_1768de | Manual (Trigger Start) | Local System |
Microsoft (R) Diagnostics Hub Standard Collector Service | Manual | Local System |
Microsoft Account Sign-in Assistant | Manual (Trigger Start) | Local System |
Microsoft App-V Client | Disabled | Local System |
Microsoft Cloud Identity Service | Manual | Network Service |
Microsoft Defender Antivirus Network Inspection Service | Manual | Local Service |
Microsoft Defender Antivirus Service | Automatic | Local System |
Microsoft Defender Core Service | Automatic | Local System |
Microsoft Edge Elevation Service (MicrosoftEdgeElevationService) | Manual | Local System |
Microsoft Edge Update Service (edgeupdate) | Automatic (Delayed Start, Trigger Start) | Local System |
Microsoft Edge Update Service (edgeupdatem) | Manual (Trigger Start) | Local System |
Microsoft iSCSI Initiator Service | Manual | Local System |
Microsoft Keyboard Filter | Disabled | Local System |
Microsoft Passport | Manual (Trigger Start) | Local System |
Microsoft Passport Container | Manual (Trigger Start) | Local Service |
Microsoft Software Shadow Copy Provider | Manual | Local System |
Microsoft Storage Spaces SMP | Manual | Network Service |
Microsoft Store Install Service | Manual | Local System |
Microsoft Update Health Service | Disabled | Local System |
Microsoft Windows SMS Router Service. | Manual (Trigger Start) | Local Service |
Natural Authentication | Manual (Trigger Start) | Local System |
Net.Tcp Port Sharing Service | Disabled | Local Service |
Netlogon | Manual | Local System |
Network Connected Devices Auto-Setup | Manual (Trigger Start) | Local Service |
Network Connection Broker | Manual (Trigger Start) | Local System |
Network Connections | Manual | Local System |
Network Connectivity Assistant | Manual (Trigger Start) | Local System |
Network List Service | Manual | Network Service |
Network Location Awareness | Manual | Network Service |
Network Setup Service | Manual (Trigger Start) | Local System |
Network Store Interface Service | Automatic | Local Service |
NPSMSvc_1768de | Manual | Local System |
Offline Files | Manual (Trigger Start) | Local System |
OpenSSH Authentication Agent | Disabled | Local System |
Optimize drives | Manual | Local System |
P9RdrService_1768de | Manual (Trigger Start) | Local System |
Parental Controls | Manual | Local System |
Payments and NFC/SE Manager | Manual (Trigger Start) | Local Service |
Peer Name Resolution Protocol | Manual | Local Service |
Peer Networking Grouping | Manual | Local Service |
Peer Networking Identity Manager | Manual | Local Service |
PenService_1768de | Manual (Trigger Start) | Local System |
Performance Counter DLL Host | Manual | Local Service |
Performance Logs & Alerts | Manual | Local Service |
Phone Service | Manual (Trigger Start) | Local Service |
Plug and Play | Manual | Local System |
PNRP Machine Name Publication Service | Manual | Local Service |
Portable Device Enumerator Service | Manual (Trigger Start) | Local System |
Power | Automatic | Local System |
Print Spooler | Automatic | Local System |
Printer Extensions and Notifications | Manual | Local System |
PrintWorkflow_1768de | Manual (Trigger Start) | Local System |
Problem Reports Control Panel Support | Manual | Local System |
Program Compatibility Assistant Service | Automatic (Delayed Start, Trigger Start) | Local System |
Quality Windows Audio Video Experience | Manual | Local Service |
Radio Management Service | Manual | Local Service |
Recommended Troubleshooting Service | Manual | Local System |
Remote Access Auto Connection Manager | Manual | Local System |
Remote Access Connection Manager | Manual | Local System |
Remote Desktop Configuration | Manual | Local System |
Remote Desktop Services | Manual | Network Service |
Remote Desktop Services UserMode Port Redirector | Manual | Local System |
Remote Procedure Call (RPC) | Automatic | Network Service |
Remote Procedure Call (RPC) Locator | Manual | Network Service |
Remote Registry | Disabled | Local Service |
Retail Demo Service | Manual | Local System |
Routing and Remote Access | Disabled | Local System |
RPC Endpoint Mapper | Automatic | Network Service |
Secondary Logon | Manual | Local System |
Secure Socket Tunneling Protocol Service | Manual | Local Service |
Security Accounts Manager | Automatic | Local System |
Security Center | Automatic (Delayed Start) | Local Service |
Sensor Data Service | Manual (Trigger Start) | Local System |
Sensor Monitoring Service | Manual (Trigger Start) | Local Service |
Sensor Service | Manual (Trigger Start) | Local System |
Server | Automatic (Trigger Start) | Local System |
Shared PC Account Manager | Disabled | Local System |
Shell Hardware Detection | Automatic | Local System |
Smart Card | Manual (Trigger Start) | Local Service |
Smart Card Device Enumeration Service | Manual (Trigger Start) | Local System |
Smart Card Removal Policy | Manual | Local System |
SNMP Trap | Manual | Local Service |
Software Protection | Automatic (Delayed Start, Trigger Start) | Network Service |
Spatial Data Service | Manual | Local Service |
Spot Verifier | Manual (Trigger Start) | Local System |
SSDP Discovery | Manual | Local Service |
State Repository Service | Automatic | Local System |
Still Image Acquisition Events | Manual | Local System |
Storage Service | Automatic (Delayed Start, Trigger Start) | Local System |
Storage Tiers Management | Manual | Local System |
Sync Host_1768de | Automatic (Delayed Start) | Local System |
SysMain | Automatic | Local System |
System Event Notification Service | Automatic | Local System |
System Events Broker | Automatic (Trigger Start) | Local System |
System Guard Runtime Monitor Broker | Disabled | Local System |
Task Scheduler | Automatic | Local System |
TCP/IP NetBIOS Helper | Manual (Trigger Start) | Local Service |
Telephony | Manual | Network Service |
Text Input Management Service | Automatic (Trigger Start) | Local System |
Themes | Automatic | Local System |
Time Broker | Manual (Trigger Start) | Local Service |
Udk User Service_1768de | Manual | Local System |
Update Orchestrator Service | Automatic (Delayed Start) | Local System |
UPnP Device Host | Manual | Local Service |
User Data Access_1768de | Manual | Local System |
User Data Storage_1768de | Manual | Local System |
User Experience Virtualization Service | Disabled | Local System |
User Manager | Automatic (Trigger Start) | Local System |
User Profile Service | Automatic | Local System |
Virtual Disk | Manual | Local System |
Volume Shadow Copy | Manual | Local System |
Volumetric Audio Compositor Service | Manual | Local Service |
WaaSMedicSvc | Manual | Local System |
WalletService | Manual | Local System |
Warp JIT Service | Manual (Trigger Start) | Local Service |
Web Account Manager | Manual | Local System |
Web Threat Defense Service | Manual (Trigger Start) | Local Service |
Web Threat Defense User Service_1768de | Automatic | Local System |
WebClient | Manual (Trigger Start) | Local Service |
Wi-Fi Direct Services Connection Manager Service | Manual (Trigger Start) | Local Service |
Windows Audio | Automatic | Local Service |
Windows Audio Endpoint Builder | Automatic | Local System |
Windows Backup | Manual | Local System |
Windows Biometric Service | Manual (Trigger Start) | Local System |
Windows Camera Frame Server | Manual (Trigger Start) | Local Service |
Windows Camera Frame Server Monitor | Manual (Trigger Start) | Local System |
Windows Connect Now – Config Registrar | Manual | Local Service |
Windows Connection Manager | Automatic (Trigger Start) | Local Service |
Windows Defender Advanced Threat Protection Service | Manual | Local System |
Windows Defender Firewall | Automatic | Local Service |
Windows Encryption Provider Host Service | Manual (Trigger Start) | Local Service |
Windows Error Reporting Service | Manual (Trigger Start) | Local System |
Windows Event Collector | Manual | Network Service |
Windows Event Log | Automatic | Local Service |
Windows Font Cache Service | Automatic | Local Service |
Windows Image Acquisition (WIA) | Manual (Trigger Start) | Local Service |
Windows Insider Service | Manual (Trigger Start) | Local System |
Windows Installer | Manual | Local System |
Windows License Manager Service | Manual (Trigger Start) | Local Service |
Windows Management Instrumentation | Automatic | Local System |
Windows Management Service | Manual | Local System |
Windows Media Player Network Sharing Service | Manual | Network Service |
Windows Mixed Reality OpenXR Service | Manual | Local System |
Windows Mobile Hotspot Service | Manual (Trigger Start) | Local Service |
Windows Modules Installer | Automatic | Local System |
Windows Perception Service | Manual (Trigger Start) | Local Service |
Windows Perception Simulation Service | Manual | Local System |
Windows Push Notifications System Service | Automatic | Local System |
Windows Push Notifications User Service_1768de | Automatic | Local System |
Windows PushToInstall Service | Manual (Trigger Start) | Local System |
Windows Remote Management (WS-Management) | Manual | Network Service |
Windows Search | Automatic (Delayed Start) | Local System |
Windows Security Service | Manual | Local System |
Windows Time | Manual (Trigger Start) | Local Service |
Windows Update | Manual (Trigger Start) | Local System |
WinHTTP Web Proxy Auto-Discovery Service | Manual | Local Service |
Wired AutoConfig | Manual | Local System |
WLAN AutoConfig | Manual | Local System |
WMI Performance Adapter | Manual | Local System |
Work Folders | Manual | Local Service |
Workstation | Automatic | Network Service |
WWAN AutoConfig | Manual | Local System |
Xbox Accessory Management Service | Manual (Trigger Start) | Local System |
Xbox Live Auth Manager | Manual | Local System |
Xbox Live Game Save | Manual (Trigger Start) | Local System |
Xbox Live Networking Service | Manual | Local System |
Windows 11 Service Permissions
The Service permission (SDDL strings) defaults are provided below for each service:
Service Name : AJRouter Display Name : AllJoyn Router Service Image Path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CR;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : ALG Display Name : Application Layer Gateway Service Image Path : C:\Windows\System32\alg.exe Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : AppIDSvc Display Name : Application Identity Image Path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : NT Authority\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : Appinfo Display Name : Application Information Image Path : C:\Windows\system32\svchost.exe -k netsvcs -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CR;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : AppMgmt Display Name : Application Management Image Path : C:\Windows\system32\svchost.exe -k netsvcs -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLO;;;IU)(A;;CCLCSWLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : AppReadiness Display Name : App Readiness Image Path : C:\Windows\System32\svchost.exe -k AppReadiness -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : AppVClient Display Name : Microsoft App-V Client Image Path : C:\Windows\system32\AppVClient.exe Startup Type : Disabled Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : AppXSvc Display Name : AppX Deployment Service (AppXSVC) Image Path : C:\Windows\system32\svchost.exe -k wsappx -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464D:(A;;LCRP;;;AC)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCLCSWRPWPDTLOCRRC;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWRPLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : AssignedAccessManagerSvc Display Name : AssignedAccessManager Service Image Path : C:\Windows\system32\svchost.exe -k AssignedAccessManagerSvc Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : AudioEndpointBuilder Display Name : Windows Audio Endpoint Builder Image Path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : Audiosrv Display Name : Windows Audio Image Path : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Auto Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCLCSWLORC;;;AC)(A;;CCLCSWLORC;;;S-1-15-3-1024-1692970155-4054893335-185714091-3362601943-3526593181-1159816984-2199008581-497492991) Service Name : autotimesvc Display Name : Cellular Time Image Path : C:\Windows\system32\svchost.exe -k autoTimeSvc Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : AxInstSV Display Name : ActiveX Installer (AxInstSV) Image Path : C:\Windows\system32\svchost.exe -k AxInstSVGroup Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : BDESVC Display Name : BitLocker Drive Encryption Service Image Path : C:\Windows\System32\svchost.exe -k netsvcs -p Startup Type : Manual (Triggered) Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCDCLCSWRPWPDTLORCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLORCWDWO;;;BA)(A;;CCLCSWRPLORC;;;BU)(A;;CCLCSWRPLORC;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : BFE Display Name : Base Filtering Engine Image Path : C:\Windows\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p Startup Type : Auto Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCLORC;;;AU)(A;;CCDCLCSWRPLORCWDWO;;;SY)(A;;CCLCSWRPLORCWDWO;;;BA)(A;;CCLCLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : BITS Display Name : Background Intelligent Transfer Service Image Path : C:\Windows\System32\svchost.exe -k netsvcs -p Startup Type : Manual Log On As : LocalSystem Permissions : O:BAG:BAD:(A;CI;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;SAFA;WDWO;;;BA) Service Name : BrokerInfrastructure Display Name : Background Tasks Infrastructure Service Image Path : C:\Windows\system32\svchost.exe -k DcomLaunch -p Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCLORC;;;AU)(A;;CCDCLCSWRPWPDTLORCWDWO;;;SY)(A;;CCLCSWRPWPDTLORCWDWO;;;BA)(A;;CCLCRPLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : BTAGService Display Name : Bluetooth Audio Gateway Service Image Path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : BthAvctpSvc Display Name : AVCTP service Image Path : C:\Windows\system32\svchost.exe -k LocalService -p Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : bthserv Display Name : Bluetooth Support Service Image Path : C:\Windows\system32\svchost.exe -k LocalService -p Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : camsvc Display Name : Capability Access Manager Service Image Path : C:\Windows\system32\svchost.exe -k osprivacy -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : CDPSvc Display Name : Connected Devices Platform Service Image Path : C:\Windows\system32\svchost.exe -k LocalService -p Startup Type : Auto (Delayed, Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CR;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : CertPropSvc Display Name : Certificate Propagation Image Path : C:\Windows\system32\svchost.exe -k netsvcs Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:BAG:BAD:(A;CI;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRRC;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;RPWP;;;S-1-5-80-446051430-1559341753-4161941529-1950928533-810483104)S:(AU;SAFA;WDWO;;;BA) Service Name : ClipSVC Display Name : Client License Service (ClipSVC) Image Path : C:\Windows\System32\svchost.exe -k wsappx -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCDCLCSWRPWPDTLOCRRC;;;SY)(A;;CCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;LCRPLO;;;AC)(A;;CCLCSWRPLOCRRC;;;SU)(A;;LCRP;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : cloudidsvc Display Name : Microsoft Cloud Identity Service Image Path : C:\Windows\system32\svchost.exe -k CloudIdServiceGroup -p Startup Type : Manual Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLORC;;;AU)(A;;CCLCSWRPLORC;;;AC)(A;;CCLCSWRPLORC;;;S-1-15-3-1024-1065365936-1281604716-3511738428-1654721687-432734479-3232135806-4053264122-3456934681) Service Name : COMSysApp Display Name : COM+ System Application Image Path : C:\Windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : CoreMessagingRegistrar Display Name : CoreMessaging Image Path : C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork -p Startup Type : Auto Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCLCSWRPWPDTLOCRRC;;;BA)(A;;CCLCSWRPLOCRRC;;;SU)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWRPLOCRRC;;;AC) Service Name : CryptSvc Display Name : Cryptographic Services Image Path : C:\Windows\system32\svchost.exe -k NetworkService -p Startup Type : Auto (Triggered) Log On As : NT Authority\NetworkService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;SO)(A;;CCLCSWLORC;;;AC)(A;;CCLCSWLORC;;;S-1-15-3-1024-3203351429-2120443784-2872670797-1918958302-2829055647-4275794519-765664414-2751773334) Service Name : CscService Display Name : Offline Files Image Path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : DcomLaunch Display Name : DCOM Server Process Launcher Image Path : C:\Windows\system32\svchost.exe -k DcomLaunch -p Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCLORC;;;AU)(A;;CCDCLCSWRPWPDTLORCWDWO;;;SY)(A;;CCLCSWRPWPDTLORCWDWO;;;BA)(A;;CCLCLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : dcsvc Display Name : Declared Configuration(DC) service Image Path : C:\Windows\system32\svchost.exe -k netsvcs -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : defragsvc Display Name : Optimize drives Image Path : C:\Windows\system32\svchost.exe -k defragsvc Startup Type : Manual Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : DeviceAssociationService Display Name : Device Association Service Image Path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : DeviceInstall Display Name : Device Install Service Image Path : C:\Windows\system32\svchost.exe -k DcomLaunch -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : DevQueryBroker Display Name : DevQuery Background Discovery Broker Image Path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : Dhcp Display Name : DHCP Client Image Path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Auto Log On As : NT Authority\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;NO)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLOCRRC;;;S-1-2-1)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : diagnosticshub.standardcollector.service Display Name : Microsoft (R) Diagnostics Hub Standard Collector Service Image Path : C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : diagsvc Display Name : Diagnostic Execution Service Image Path : C:\Windows\System32\svchost.exe -k diagnostics Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : DiagTrack Display Name : Connected User Experiences and Telemetry Image Path : C:\Windows\System32\svchost.exe -k utcsvc -p Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : DialogBlockingService Display Name : DialogBlockingService Image Path : C:\Windows\system32\svchost.exe -k DialogBlockingService Startup Type : Disabled Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : DispBrokerDesktopSvc Display Name : Display Policy Service Image Path : C:\Windows\system32\svchost.exe -k LocalService -p Startup Type : Auto Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : DisplayEnhancementService Display Name : Display Enhancement Service Image Path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;LCRPCR;;;AC)(A;;LCRPCR;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : DmEnrollmentSvc Display Name : Device Management Enrollment Service Image Path : C:\Windows\system32\svchost.exe -k netsvcs -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : dmwappushservice Display Name : Device Management Wireless Application Protocol (WAP) Push message Routing Service Image Path : C:\Windows\system32\svchost.exe -k netsvcs -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;LCRP;;;AC)(A;;LCRP;;;IU)(A;;LCRP;;;AU) Service Name : Dnscache Display Name : DNS Client Image Path : C:\Windows\system32\svchost.exe -k NetworkService -p Startup Type : Auto (Triggered) Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;CI;CCLCSWRPLORC;;;BU)(A;CI;CCLCSWRPDTLORC;;;BA)(A;CI;CCLCSWRPDTLORC;;;SY)(A;;CCLCSWRPLORC;;;IU)(A;CI;CCLCSWRPLORC;;;NS)(A;CI;CCLCSWRPLORC;;;LS)(A;CI;CCLCSWRPDTLORC;;;NO)(A;CI;CCLCSWDTLOCRRC;;;S-1-5-80-2940520708-3855866260-481812779-327648279-1710889582)(A;CI;CCLCSWRPLORC;;;AC)(A;CI;CCLCSWRPLORC;;;S-1-15-3-1)(A;CI;CCLCSWRPLORC;;;S-1-15-3-2)(A;CI;CCLCSWRPLORC;;;S-1-15-3-3)S:(AU;FA;CCLCSWRPDTLORC;;;WD) Service Name : DoSvc Display Name : Delivery Optimization Image Path : C:\Windows\System32\svchost.exe -k NetworkService -p Startup Type : Auto (Delayed, Triggered) Log On As : NT Authority\NetworkService Permissions : O:SYG:SYD:(A;;CCLCSWRPLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;DCWPRC;;;S-1-5-80-3055155277-3816794035-3994065555-2874236192-2193176987)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : dot3svc Display Name : Wired AutoConfig Image Path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : DPS Display Name : Diagnostic Policy Service Image Path : C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork -p Startup Type : Auto Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRRC;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : DsmSvc Display Name : Device Setup Manager Image Path : C:\Windows\system32\svchost.exe -k netsvcs -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;RP;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : DsSvc Display Name : Data Sharing Service Image Path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;LCRP;;;WD)(A;;LCRP;;;AC) Service Name : DusmSvc Display Name : Data Usage Image Path : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Auto Log On As : NT Authority\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : EapHost Display Name : Extensible Authentication Protocol Image Path : C:\Windows\System32\svchost.exe -k netsvcs -p Startup Type : Manual Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : edgeupdate Display Name : Microsoft Edge Update Service (edgeupdate) Image Path : "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svc Startup Type : Auto (Delayed, Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : edgeupdatem Display Name : Microsoft Edge Update Service (edgeupdatem) Image Path : "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /medsvc Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : EFS Display Name : Encrypting File System (EFS) Image Path : C:\Windows\System32\lsass.exe Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPLOCRRC;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWRPLOCRRC;;;SU)(A;;LCRP;;;AU)(A;;LCRP;;;AC)S:(AU;SAFA;DCSDWDWO;;;WD) Service Name : embeddedmode Display Name : Embedded Mode Image Path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464D:(A;;LCRP;;;AC)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCLCSWRPWPDTLOCRRC;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWRPLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : EntAppSvc Display Name : Enterprise App Management Service Image Path : C:\Windows\system32\svchost.exe -k appmodel -p Startup Type : Manual Log On As : LocalSystem Permissions : O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464D:(A;;LCRP;;;AC)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCLCSWRPWPDTLOCRRC;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWRPLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : EventLog Display Name : Windows Event Log Image Path : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Auto Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;LCLO;;;AC)S:(AU;SA;DCRPWPDTCRSDWDWO;;;WD)(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : EventSystem Display Name : COM+ Event System Image Path : C:\Windows\system32\svchost.exe -k LocalService -p Startup Type : Auto Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : fdPHost Display Name : Function Discovery Provider Host Image Path : C:\Windows\system32\svchost.exe -k LocalService -p Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : FDResPub Display Name : Function Discovery Resource Publication Image Path : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;NO)S:AI(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : fhsvc Display Name : File History Service Image Path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLOCRRC;;;AU) Service Name : FontCache Display Name : Windows Font Cache Service Image Path : C:\Windows\system32\svchost.exe -k LocalService -p Startup Type : Auto Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;RP;;;IU)(A;;RP;;;SU)(A;;CCLCSWRPLOCRRC;;;AC)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : FrameServer Display Name : Windows Camera Frame Server Image Path : C:\Windows\System32\svchost.exe -k Camera Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : FrameServerMonitor Display Name : Windows Camera Frame Server Monitor Image Path : C:\Windows\System32\svchost.exe -k CameraMonitor Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : GameInputSvc Display Name : GameInput Service Image Path : C:\Windows\System32\GameInputSvc.exe Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : gpsvc Display Name : Group Policy Client Image Path : C:\Windows\system32\svchost.exe -k netsvcs -p Startup Type : Auto (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCLCSWLOCRRC;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;SAFA;DCSDWDWO;;;WD) Service Name : GraphicsPerfSvc Display Name : GraphicsPerfSvc Image Path : C:\Windows\System32\svchost.exe -k GraphicsPerfSvcGroup Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : hidserv Display Name : Human Interface Device Service Image Path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : HvHost Display Name : HV Host Service Image Path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : icssvc Display Name : Windows Mobile Hotspot Service Image Path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : NT Authority\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;LCRP;;;WD)(A;;CCLCSWRPLOCRRC;;;S-1-15-2-155514346-2573954481-755741238-1654018636-1233331829-3075935687-2861478708)(A;;CCLCSWRPLOCRRC;;;S-1-15-2-1121366727-2517420131-1100342901-1044639592-4216533239-371662368-2140263060)(A;;CCLCSWRPLOCRRC;;;S-1-15-2-2543942650-389403887-2808249486-612059083-208952635-835677591-2189227231)(A;;CCLCSWRPLOCRRC;;;S-1-15-2-3801529221-2855318152-1555692692-2306892612-2338533892-3542301781-2904385964) Service Name : IKEEXT Display Name : IKE and AuthIP IPsec Keying Modules Image Path : C:\Windows\system32\svchost.exe -k netsvcs -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : InstallService Display Name : Microsoft Store Install Service Image Path : C:\Windows\System32\svchost.exe -k netsvcs -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : InventorySvc Display Name : Inventory and Compatibility Appraisal service Image Path : C:\Windows\system32\svchost.exe -k InvSvcGroup -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;LCRP;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : iphlpsvc Display Name : IP Helper Image Path : C:\Windows\System32\svchost.exe -k NetSvcs -p Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : IpxlatCfgSvc Display Name : IP Translation Configuration Service Image Path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWRPWPLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : KeyIso Display Name : CNG Key Isolation Image Path : C:\Windows\system32\lsass.exe Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWRPLOCRRC;;;SU)(A;;CCLCSWLOCRRC;;;SU)(A;;CR;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : KtmRm Display Name : KtmRm for Distributed Transaction Coordinator Image Path : C:\Windows\System32\svchost.exe -k NetworkServiceAndNoImpersonation -p Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;CCLCSWRPLOCRRC;;;S-1-2-0)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWLORC;;;AU)(A;;CCLCSWRPLOCRRC;;;SU)(A;;CCLCSWLORC;;;S-1-5-80-2818357584-3387065753-4000393942-342927828-138088443)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : LanmanServer Display Name : Server Image Path : C:\Windows\system32\svchost.exe -k netsvcs -p Startup Type : Auto (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : LanmanWorkstation Display Name : Workstation Image Path : C:\Windows\System32\svchost.exe -k NetworkService -p Startup Type : Auto Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : lfsvc Display Name : Geolocation Service Image Path : C:\Windows\system32\svchost.exe -k netsvcs -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD: Service Name : LicenseManager Display Name : Windows License Manager Service Image Path : C:\Windows\System32\svchost.exe -k LocalService -p Startup Type : Manual (Triggered) Log On As : NT Authority\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : lltdsvc Display Name : Link-Layer Topology Discovery Mapper Image Path : C:\Windows\System32\svchost.exe -k LocalService -p Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : lmhosts Display Name : TCP/IP NetBIOS Helper Image Path : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : LSM Display Name : Local Session Manager Image Path : C:\Windows\system32\svchost.exe -k DcomLaunch -p Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSW;;;AU)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;SY)(A;;CCLCSWLORC;;;BA)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : LxpSvc Display Name : Language Experience Service Image Path : C:\Windows\system32\svchost.exe -k netsvcs Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : MapsBroker Display Name : Downloaded Maps Manager Image Path : C:\Windows\System32\svchost.exe -k NetworkService -p Startup Type : Auto (Delayed) Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;LCRP;;;AU)(A;;LCRP;;;AC) Service Name : McpManagementService Display Name : McpManagementService Image Path : C:\Windows\system32\svchost.exe -k McpManagementServiceGroup Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : MDCoreSvc Display Name : Microsoft Defender Core Service Image Path : "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpDefenderCoreService.exe" Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPLOCRRC;;;BU)(A;;CCLCSWRPWPLOCRRC;;;SY)(A;;CCLCSWRPWPLOCRRC;;;BA)(A;;CCLCSWRPWPLOCRRC;;;IU)(A;;CCLCSWRPWPLOCRRC;;;SU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-80-1913148863-3492339771-4165695881-2087618961-4109116736)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-80-30551196-2029750602-3680353947-2336859763-523537544)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : MicrosoftEdgeElevationService Display Name : Microsoft Edge Elevation Service (MicrosoftEdgeElevationService) Image Path : "C:\Program Files (x86)\Microsoft\Edge\Application\125.0.2535.92\elevation_service.exe" Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : MixedRealityOpenXRSvc Display Name : Windows Mixed Reality OpenXR Service Image Path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : mpssvc Display Name : Windows Defender Firewall Image Path : C:\Windows\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p Startup Type : Auto Log On As : NT Authority\LocalService Permissions : O:SYG:SYD:(A;;CCLCLORC;;;AU)(A;;CCDCLCSWRPLORCWDWO;;;SY)(A;;CCLCSWRPLORCWDWO;;;BA)(A;;CCLCLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : MSDTC Display Name : Distributed Transaction Coordinator Image Path : C:\Windows\System32\msdtc.exe Startup Type : Manual Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;CCLCSWRPLORC;;;S-1-2-0)(A;;CCDCLCSWRPWPDTLORC;;;SY)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;BA)(A;;CCLCSWRPLORC;;;IU)(A;;CCLCSWLORC;;;AU)(A;;CCLCSWRPLORC;;;SU)(A;;CCLCSWLORC;;;S-1-5-80-3960419045-2460139048-4046793004-1809597027-2250574426)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : MSiSCSI Display Name : Microsoft iSCSI Initiator Service Image Path : C:\Windows\system32\svchost.exe -k netsvcs -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : msiserver Display Name : Windows Installer Image Path : C:\Windows\system32\msiexec.exe /V Startup Type : Manual Log On As : LocalSystem Permissions : O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464D:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCLCSWRPWPDTLOCRRC;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWRPLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : MsKeyboardFilter Display Name : Microsoft Keyboard Filter Image Path : C:\Windows\system32\svchost.exe -k netsvcs -p Startup Type : Disabled Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : NaturalAuthentication Display Name : Natural Authentication Image Path : C:\Windows\system32\svchost.exe -k netsvcs -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWRPLOCRRC;;;AC)(A;;CCLCSWLOCRRC;;;SU)(A;;CR;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : NcaSvc Display Name : Network Connectivity Assistant Image Path : C:\Windows\System32\svchost.exe -k NetSvcs -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : NcbService Display Name : Network Connection Broker Image Path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : NcdAutoSetup Display Name : Network Connected Devices Auto-Setup Image Path : C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork -p Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : Netlogon Display Name : Netlogon Image Path : C:\Windows\system32\lsass.exe Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : Netman Display Name : Network Connections Image Path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : netprofm Display Name : Network List Service Image Path : C:\Windows\System32\svchost.exe -k netprofm -p Startup Type : Manual Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : NetSetupSvc Display Name : Network Setup Service Image Path : C:\Windows\System32\svchost.exe -k netsvcs -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRP;;;NS)(A;;CCLCSWRP;;;LS)(A;;CCLCSWRP;;;AC)(A;;CCLCSWRP;;;BU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCLCSWRP;;;NO)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464) Service Name : NetTcpPortSharing Display Name : Net.Tcp Port Sharing Service Image Path : C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe Startup Type : Disabled Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;AU)(A;;LCRP;;;IU)(A;;LCRP;;;SU) Service Name : NgcCtnrSvc Display Name : Microsoft Passport Container Image Path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCDCLCSWRPWPDTLORCWDWO;;;SY)(A;;CCLCSWRPWPDTLORCWDWO;;;BA)(A;;CCLCLORC;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : NgcSvc Display Name : Microsoft Passport Image Path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCLORC;;;AU)(A;;CCDCLCSWRPWPDTLORCWDWO;;;SY)(A;;CCLCSWRPLORCWDWO;;;BA)(A;;CCLCLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : NlaSvc Display Name : Network Location Awareness Image Path : C:\Windows\System32\svchost.exe -k netprofm -p Startup Type : Manual Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : nsi Display Name : Network Store Interface Service Image Path : C:\Windows\system32\svchost.exe -k LocalService -p Startup Type : Auto Log On As : NT Authority\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : p2pimsvc Display Name : Peer Networking Identity Manager Image Path : C:\Windows\System32\svchost.exe -k LocalServicePeerNet Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(D;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BG)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLORC;;;SO)(A;;CCLCSWRPLORC;;;IU)(A;;CCLCSWRPLORC;;;RD)(A;;CCLCSWRPLORC;;;BU) Service Name : p2psvc Display Name : Peer Networking Grouping Image Path : C:\Windows\System32\svchost.exe -k LocalServicePeerNet Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(D;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BG)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLORC;;;SO)(A;;CCLCSWRPLORC;;;IU)(A;;CCLCSWRPLORC;;;RD)(A;;CCLCSWRPLORC;;;BU) Service Name : PcaSvc Display Name : Program Compatibility Assistant Service Image Path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Auto (Delayed, Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CR;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : PeerDistSvc Display Name : BranchCache Image Path : C:\Windows\System32\svchost.exe -k PeerDist Startup Type : Manual Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SO)(A;;CCLCSWRPLORC;;;IU)(A;;CCLCSWRPLORC;;;RD)(A;;CCLCSWRPLORC;;;SU)(A;;CCLCSWRPLORC;;;BU)(A;;LCRPLO;;;AC)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : perceptionsimulation Display Name : Windows Perception Simulation Service Image Path : C:\Windows\system32\PerceptionSimulation\PerceptionSimulationService.exe Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : PerfHost Display Name : Performance Counter DLL Host Image Path : C:\Windows\SysWow64\perfhost.exe Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : PhoneSvc Display Name : Phone Service Image Path : C:\Windows\system32\svchost.exe -k LocalService -p Startup Type : Manual (Triggered) Log On As : NT Authority\LocalService Permissions : O:SYG:SYD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;LCRP;;;WD)(A;;LCRP;;;AC) Service Name : pla Display Name : Performance Logs & Alerts Image Path : C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork -p Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCR;;;SO)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCLCRPLOCR;;;WD)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : PlugPlay Display Name : Plug and Play Image Path : C:\Windows\system32\svchost.exe -k DcomLaunch -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : PNRPAutoReg Display Name : PNRP Machine Name Publication Service Image Path : C:\Windows\System32\svchost.exe -k LocalServicePeerNet Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(D;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BG)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLORC;;;SO)(A;;CCLCSWRPLORC;;;IU)(A;;CCLCSWRPLORC;;;RD) Service Name : PNRPsvc Display Name : Peer Name Resolution Protocol Image Path : C:\Windows\System32\svchost.exe -k LocalServicePeerNet Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(D;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BG)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLORC;;;SO)(A;;CCLCSWRPLORC;;;IU)(A;;CCLCSWRPLORC;;;RD)(A;;CCLCSWRPLORC;;;BU) Service Name : PolicyAgent Display Name : IPsec Policy Agent Image Path : C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : NT Authority\NetworkService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : Power Display Name : Power Image Path : C:\Windows\system32\svchost.exe -k DcomLaunch -p Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : PrintNotify Display Name : Printer Extensions and Notifications Image Path : C:\Windows\system32\svchost.exe -k print Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : ProfSvc Display Name : User Profile Service Image Path : C:\Windows\system32\svchost.exe -k UserProfileService -p Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : PushToInstall Display Name : Windows PushToInstall Service Image Path : C:\Windows\System32\svchost.exe -k netsvcs -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : QWAVE Display Name : Quality Windows Audio Video Experience Image Path : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPLO;;;IU)(A;;CCLCSWRPLO;;;NS)(A;;CCLCSWRPLO;;;UD)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA) Service Name : RasAuto Display Name : Remote Access Auto Connection Manager Image Path : C:\Windows\System32\svchost.exe -k netsvcs -p Startup Type : Manual Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;AU) Service Name : RasMan Display Name : Remote Access Connection Manager Image Path : C:\Windows\System32\svchost.exe -k netsvcs Startup Type : Manual Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLOCRRC;;;S-1-15-3-1024-1068037383-729401668-2768096886-125909118-1680096985-174794564-3112554050-3241210738) Service Name : RemoteAccess Display Name : Routing and Remote Access Image Path : C:\Windows\System32\svchost.exe -k netsvcs Startup Type : Disabled Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;AU) Service Name : RemoteRegistry Display Name : Remote Registry Image Path : C:\Windows\system32\svchost.exe -k localService -p Startup Type : Disabled Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : RetailDemo Display Name : Retail Demo Service Image Path : C:\Windows\System32\svchost.exe -k rdxgroup Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : RmSvc Display Name : Radio Management Service Image Path : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;CI;CCLCSWRPWPDTLOCRRC;;;LS)(A;CI;CCDCLCSWRPWPDTLOCRRC;;;SY)(A;CI;CCDCLCSWRPWPDTLOCRRC;;;BA)(A;CI;CCLCSWRPWPDTLOCRRC;;;BU) Service Name : RpcEptMapper Display Name : RPC Endpoint Mapper Image Path : C:\Windows\system32\svchost.exe -k RPCSS -p Startup Type : Auto Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;CCLCLORC;;;AU)(A;;CCDCLCSWRPWPDTLORCWDWO;;;SY)(A;;CCLCSWRPWPDTLORCWDWO;;;BA)(A;;CCLCRPLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : RpcLocator Display Name : Remote Procedure Call (RPC) Locator Image Path : C:\Windows\system32\locator.exe Startup Type : Manual Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : RpcSs Display Name : Remote Procedure Call (RPC) Image Path : C:\Windows\system32\svchost.exe -k rpcss -p Startup Type : Auto Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;CCLCLORC;;;AU)(A;;CCDCLCSWRPWPDTLORCWDWO;;;SY)(A;;CCLCSWRPWPDTLORCWDWO;;;BA)(A;;CCLCLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : SamSs Display Name : Security Accounts Manager Image Path : C:\Windows\system32\lsass.exe Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLO;;;IU)(A;;CCLCSWLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : SCardSvr Display Name : Smart Card Image Path : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:BAG:BAD:(A;CI;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRRC;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;SAFA;WDWO;;;BA) Service Name : ScDeviceEnum Display Name : Smart Card Device Enumeration Service Image Path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:BAG:BAD:(A;CI;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRRC;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;RPWP;;;S-1-5-80-3993802144-2555107232-3516638766-2735499450-3275915967)S:(AU;SAFA;WDWO;;;BA) Service Name : Schedule Display Name : Task Scheduler Image Path : C:\Windows\system32\svchost.exe -k netsvcs -p Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWLORC;;;AU)(A;;CCLCSWRPDTLOCRRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCLCSWLORC;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : SCPolicySvc Display Name : Smart Card Removal Policy Image Path : C:\Windows\system32\svchost.exe -k netsvcs Startup Type : Manual Log On As : LocalSystem Permissions : O:BAG:BAD:(A;CI;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRRC;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;SAFA;WDWO;;;BA) Service Name : SDRSVC Display Name : Windows Backup Image Path : C:\Windows\system32\svchost.exe -k SDRSVC Startup Type : Manual Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : seclogon Display Name : Secondary Logon Image Path : C:\Windows\system32\svchost.exe -k netsvcs -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPDTLOCRRC;;;IU)(A;;CCLCSWDTLOCRRC;;;SU)(A;;CCLCSWRPDTLOCRRC;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : SecurityHealthService Display Name : Windows Security Service Image Path : C:\Windows\system32\SecurityHealthService.exe Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPLORC;;;BU)(A;;CCLCSWRPLOCRRC;;;SY)(A;;CCLCSWRPLOCRRC;;;BA)(A;;CCLCSWRPLORC;;;IU)(A;;CCLCSWRPLORC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;S-1-5-80-1601830629-990752416-3372939810-977361409-3075122917)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-80-259296475-4084429506-1152984619-38739575-565535606)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : SEMgrSvc Display Name : Payments and NFC/SE Manager Image Path : C:\Windows\system32\svchost.exe -k LocalService -p Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD: Service Name : SENS Display Name : System Event Notification Service Image Path : C:\Windows\system32\svchost.exe -k netsvcs -p Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCR;;;SO)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;LCLORC;;;AC)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : Sense Display Name : Windows Defender Advanced Threat Protection Service Image Path : "C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe" Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;OICIIO;GA;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRRCWDWO;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWRPLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : SensorDataService Display Name : Sensor Data Service Image Path : C:\Windows\System32\SensorDataService.exe Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : SensorService Display Name : Sensor Service Image Path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;LCRPCR;;;AC)(A;;LCRPCR;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : SensrSvc Display Name : Sensor Monitoring Service Image Path : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;LCRPCR;;;AC)(A;;LCRPCR;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : SessionEnv Display Name : Remote Desktop Configuration Image Path : C:\Windows\System32\svchost.exe -k netsvcs -p Startup Type : Manual Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;RPWP;;;S-1-5-80-446051430-1559341753-4161941529-1950928533-810483104)(A;;RPWP;;;S-1-5-80-4130899010-3337817248-2959896732-3640118089-1866760602) Service Name : SgrmBroker Display Name : System Guard Runtime Monitor Broker Image Path : C:\Windows\system32\Sgrm\SgrmBroker.exe Startup Type : Disabled Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : SharedAccess Display Name : Internet Connection Sharing (ICS) Image Path : C:\Windows\System32\svchost.exe -k netsvcs -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWRPWPLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;S-1-5-80-3935728946-315639613-922904133-3250794525-491832002)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : SharedRealitySvc Display Name : Spatial Data Service Image Path : C:\Windows\system32\svchost.exe -k LocalService -p Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CR;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : ShellHWDetection Display Name : Shell Hardware Detection Image Path : C:\Windows\System32\svchost.exe -k netsvcs -p Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : shpamsvc Display Name : Shared PC Account Manager Image Path : C:\Windows\System32\svchost.exe -k netsvcs -p Startup Type : Disabled Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : smphost Display Name : Microsoft Storage Spaces SMP Image Path : C:\Windows\System32\svchost.exe -k smphost Startup Type : Manual Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCRP;;;AU)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCLCSWLOCRRC;;;S-1-5-32-582)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : SmsRouter Display Name : Microsoft Windows SMS Router Service. Image Path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : NT Authority\LocalService Permissions : O:SYG:SYD:(A;;CCLCLORC;;;AU)(A;;CCDCLCSWRPWPDTLORCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLORCWDWO;;;BA)(A;;CCLCRPLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : SNMPTrap Display Name : SNMP Trap Image Path : C:\Windows\System32\snmptrap.exe Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : spectrum Display Name : Windows Perception Service Image Path : C:\Windows\system32\spectrum.exe Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;LCRP;;;LS)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : Spooler Display Name : Print Spooler Image Path : C:\Windows\System32\spoolsv.exe Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : sppsvc Display Name : Software Protection Image Path : C:\Windows\system32\sppsvc.exe Startup Type : Auto (Delayed, Triggered) Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;CCDCLCSWRPWPDTLOCRRC;;;SY)(A;;CCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;LCRPLO;;;AC)(A;;CCLCSWRPLOCRRC;;;SU)(A;;LCRP;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : SSDPSRV Display Name : SSDP Discovery Image Path : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPLORC;;;SO)(A;;CCLCSWRPLORC;;;IU)(A;;CCLCSWRPWPDTLOCRRC;;;LS)(A;;CCLCSWRPWPDTLOCRRC;;;NS) Service Name : ssh-agent Display Name : OpenSSH Authentication Agent Image Path : C:\Windows\System32\OpenSSH\ssh-agent.exe Startup Type : Disabled Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;RP;;;AU) Service Name : SstpSvc Display Name : Secure Socket Tunneling Protocol Service Image Path : C:\Windows\system32\svchost.exe -k LocalService -p Startup Type : Manual Log On As : NT Authority\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;NO)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCLCSWRPLOCRRC;;;S-1-15-3-1024-1068037383-729401668-2768096886-125909118-1680096985-174794564-3112554050-3241210738)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : StateRepository Display Name : State Repository Service Image Path : C:\Windows\system32\svchost.exe -k appmodel -p Startup Type : Auto Log On As : LocalSystem Permissions : O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464D:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCLCSWRPWPDTLOCRRC;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWRPLOCRRC;;;SU)(A;;LCRP;;;AC)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : StiSvc Display Name : Windows Image Acquisition (WIA) Image Path : C:\Windows\system32\svchost.exe -k imgsvc Startup Type : Manual (Triggered) Log On As : NT Authority\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CR;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : StorSvc Display Name : Storage Service Image Path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Auto (Delayed, Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : svsvc Display Name : Spot Verifier Image Path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : swprv Display Name : Microsoft Software Shadow Copy Provider Image Path : C:\Windows\System32\svchost.exe -k swprv Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : SysMain Display Name : SysMain Image Path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : SystemEventsBroker Display Name : System Events Broker Image Path : C:\Windows\system32\svchost.exe -k DcomLaunch -p Startup Type : Auto (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCLORC;;;AU)(A;;CCDCLCSWRPWPDTLORCWDWO;;;SY)(A;;CCLCSWRPWPDTLORCWDWO;;;BA)(A;;CCLCRPLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : TapiSrv Display Name : Telephony Image Path : C:\Windows\System32\svchost.exe -k NetworkService -p Startup Type : Manual Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWRPLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : TermService Display Name : Remote Desktop Services Image Path : C:\Windows\System32\svchost.exe -k NetworkService Startup Type : Manual Log On As : NT Authority\NetworkService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : TextInputManagementService Display Name : Text Input Management Service Image Path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Auto (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCLCSWRPLOCRRC;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWRPLOCRRC;;;SU)(A;;RP;;;WD) Service Name : Themes Display Name : Themes Image Path : C:\Windows\System32\svchost.exe -k netsvcs -p Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : TieringEngineService Display Name : Storage Tiers Management Image Path : C:\Windows\system32\TieringEngineService.exe Startup Type : Manual Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : TimeBrokerSvc Display Name : Time Broker Image Path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCLORC;;;AU)(A;;CCDCLCSWRPWPDTLORCWDWO;;;SY)(A;;CCLCSWRPWPDTLORCWDWO;;;BA)(A;;CCLCRPLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : TokenBroker Display Name : Web Account Manager Image Path : C:\Windows\system32\svchost.exe -k netsvcs -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : TrkWks Display Name : Distributed Link Tracking Client Image Path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : TroubleshootingSvc Display Name : Recommended Troubleshooting Service Image Path : C:\Windows\system32\svchost.exe -k netsvcs -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : TrustedInstaller Display Name : Windows Modules Installer Image Path : C:\Windows\servicing\TrustedInstaller.exe Startup Type : Manual Log On As : localSystem Permissions : O:BAG:BAD:(A;CI;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRRC;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;SAFA;WDWO;;;BA) Service Name : tzautoupdate Display Name : Auto Time Zone Updater Image Path : C:\Windows\system32\svchost.exe -k LocalService -p Startup Type : Disabled Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : UevAgentService Display Name : User Experience Virtualization Service Image Path : C:\Windows\system32\AgentService.exe Startup Type : Disabled Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : uhssvc Display Name : Microsoft Update Health Service Image Path : "C:\Program Files\Microsoft Update Health Tools\uhssvc.exe" Startup Type : Disabled Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : UmRdpService Display Name : Remote Desktop Services UserMode Port Redirector Image Path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;RPWP;;;S-1-5-80-446051430-1559341753-4161941529-1950928533-810483104) Service Name : upnphost Display Name : UPnP Device Host Image Path : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPLORC;;;SO)(A;;CCLCSWRPLORC;;;IU)(A;;CCLCSWRPWPDTLOCRRC;;;LS)(A;;CCLCSWRPWPDTLOCRRC;;;NS) Service Name : UserManager Display Name : User Manager Image Path : C:\Windows\system32\svchost.exe -k netsvcs -p Startup Type : Auto (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : UsoSvc Display Name : Update Orchestrator Service Image Path : C:\Windows\system32\svchost.exe -k netsvcs -p Startup Type : Auto (Delayed) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : VacSvc Display Name : Volumetric Audio Compositor Service Image Path : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : VaultSvc Display Name : Credential Manager Image Path : C:\Windows\system32\lsass.exe Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWRPLOCRRC;;;SU)(A;;CR;;;AU)(A;;LCRP;;;NS)(A;;LCRP;;;LS)(A;;LCRP;;;AC)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : vds Display Name : Virtual Disk Image Path : C:\Windows\System32\vds.exe Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;AU)(A;;RPWPDT;;;BO)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : vmicguestinterface Display Name : Hyper-V Guest Service Interface Image Path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : vmicheartbeat Display Name : Hyper-V Heartbeat Service Image Path : C:\Windows\system32\svchost.exe -k ICService -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : vmickvpexchange Display Name : Hyper-V Data Exchange Service Image Path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : vmicrdv Display Name : Hyper-V Remote Desktop Virtualization Service Image Path : C:\Windows\system32\svchost.exe -k ICService -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : vmicshutdown Display Name : Hyper-V Guest Shutdown Service Image Path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : vmictimesync Display Name : Hyper-V Time Synchronization Service Image Path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : vmicvmsession Display Name : Hyper-V PowerShell Direct Service Image Path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : vmicvss Display Name : Hyper-V Volume Shadow Copy Requestor Image Path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : VSS Display Name : Volume Shadow Copy Image Path : C:\Windows\system32\vssvc.exe Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : W32Time Display Name : Windows Time Image Path : C:\Windows\system32\svchost.exe -k LocalService Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCLCSWRPLOCRRC;;;LS)(A;;CCSWWPLORC;;;LS)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-80-3169285310-278349998-1452333686-3865143136-4212226833) Service Name : WaaSMedicSvc Display Name : WaaSMedicSvc Image Path : C:\Windows\system32\svchost.exe -k wusvcs -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : WalletService Display Name : WalletService Image Path : C:\Windows\System32\svchost.exe -k appmodel -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WarpJITSvc Display Name : Warp JIT Service Image Path : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted Startup Type : Manual (Triggered) Log On As : NT Authority\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : wbengine Display Name : Block Level Backup Engine Service Image Path : "C:\Windows\system32\wbengine.exe" Startup Type : Manual Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WbioSrvc Display Name : Windows Biometric Service Image Path : C:\Windows\system32\svchost.exe -k WbioSvcGroup Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CR;;;AU)(A;;CCLCRP;;;AC)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : Wcmsvc Display Name : Windows Connection Manager Image Path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Auto (Triggered) Log On As : NT Authority\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU) Service Name : wcncsvc Display Name : Windows Connect Now - Config Registrar Image Path : C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation -p Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;IU)(A;;CCLCSWRPWPDTLOCRRC;;;LS)(A;;CCLCSWRPWPDTLOCRSDRC;;;NO)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WdiServiceHost Display Name : Diagnostic Service Host Image Path : C:\Windows\System32\svchost.exe -k LocalService -p Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWWPDTLOCRRC;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;S-1-5-80-2970612574-78537857-698502321-558674196-1451644582)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WdiSystemHost Display Name : Diagnostic System Host Image Path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWWPDTLOCRRC;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;S-1-5-80-2970612574-78537857-698502321-558674196-1451644582)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WdNisSvc Display Name : Microsoft Defender Antivirus Network Inspection Service Image Path : "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\NisSrv.exe" Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPLOCRRC;;;BU)(A;;CCLCSWRPLOCRRC;;;SY)(A;;CCLCSWRPLOCRRC;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWRPLOCRRC;;;SU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-80-1913148863-3492339771-4165695881-2087618961-4109116736)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WebClient Display Name : WebClient Image Path : C:\Windows\system32\svchost.exe -k LocalService -p Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : webthreatdefsvc Display Name : Web Threat Defense Service Image Path : C:\Windows\system32\svchost.exe -k WebThreatDefense -p Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : Wecsvc Display Name : Windows Event Collector Image Path : C:\Windows\system32\svchost.exe -k NetworkService -p Startup Type : Manual Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WEPHOSTSVC Display Name : Windows Encryption Provider Host Service Image Path : C:\Windows\system32\svchost.exe -k WepHostSvcGroup Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : wercplsupport Display Name : Problem Reports Control Panel Support Image Path : C:\Windows\System32\svchost.exe -k netsvcs -p Startup Type : Manual Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WerSvc Display Name : Windows Error Reporting Service Image Path : C:\Windows\System32\svchost.exe -k WerSvcGroup Startup Type : Manual (Triggered) Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WFDSConMgrSvc Display Name : Wi-Fi Direct Services Connection Manager Service Image Path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WiaRpc Display Name : Still Image Acquisition Events Image Path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCLCSWRPLOCRRC;;;S-1-5-80-3182985763-1431228038-2757062859-428472846-3914011746)(A;;CR;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WinDefend Display Name : Microsoft Defender Antivirus Service Image Path : "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MsMpEng.exe" Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPLOCRRC;;;BU)(A;;CCLCSWRPLOCRRC;;;SY)(A;;CCLCSWRPLOCRRC;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWRPLOCRRC;;;SU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-80-1913148863-3492339771-4165695881-2087618961-4109116736)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WinHttpAutoProxySvc Display Name : WinHTTP Web Proxy Auto-Discovery Service Image Path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPLOSDRC;;;SY)(A;;CCLCSWRPLOSDRC;;;BA)(A;;CCLCSWRPLORC;;;AU)(A;;CCLCSWRPLORC;;;IU)(A;;CCLCSWRPLORC;;;SU)(A;;LCRPLO;;;AC)(A;;LCRPLO;;;S-1-15-3-1)(A;;LCRPLO;;;S-1-15-3-2)(A;;LCRPLO;;;S-1-15-3-3)S:(AU;FA;CCLCSWRPLOSDRC;;;WD) Service Name : Winmgmt Display Name : Windows Management Instrumentation Image Path : C:\Windows\system32\svchost.exe -k netsvcs -p Startup Type : Auto Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WinRM Display Name : Windows Remote Management (WS-Management) Image Path : C:\Windows\System32\svchost.exe -k NetworkService -p Startup Type : Manual Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : wisvc Display Name : Windows Insider Service Image Path : C:\Windows\system32\svchost.exe -k netsvcs -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WlanSvc Display Name : WLAN AutoConfig Image Path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;LCRPWP;;;S-1-5-80-3635958274-2059881490-2225992882-984577281-633327304)(A;;RPWPDT;;;S-1-5-80-3906544942-1489856346-3706913989-164347954-1900376235) Service Name : wlidsvc Display Name : Microsoft Account Sign-in Assistant Image Path : C:\Windows\system32\svchost.exe -k netsvcs -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU) Service Name : wlpasvc Display Name : Local Profile Assistant Service Image Path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Manual (Triggered) Log On As : NT Authority\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRRC;;;LS)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLORC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCLCSWLORC;;;S-1-15-2-155514346-2573954481-755741238-1654018636-1233331829-3075935687-2861478708)(A;;CCLCSWLORC;;;S-1-15-2-3083765670-2301828090-3288705196-2597965991-2057664196-4044987863-2761340229)(A;;CCLCSWLORC;;;S-1-15-2-3784866113-3187381476-3433752343-3391928953-3760210436-1684329488-1912184601) Service Name : WManSvc Display Name : Windows Management Service Image Path : C:\Windows\system32\svchost.exe -k netsvcs -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : wmiApSrv Display Name : WMI Performance Adapter Image Path : C:\Windows\system32\wbem\WmiApSrv.exe Startup Type : Manual Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WMPNetworkSvc Display Name : Windows Media Player Network Sharing Service Image Path : "C:\Program Files\Windows Media Player\wmpnetwk.exe" Startup Type : Manual Log On As : NT AUTHORITY\NetworkService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : workfolderssvc Display Name : Work Folders Image Path : C:\Windows\System32\svchost.exe -k LocalService -p Startup Type : Manual Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WpcMonSvc Display Name : Parental Controls Image Path : C:\Windows\system32\svchost.exe -k LocalService Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WPDBusEnum Display Name : Portable Device Enumerator Service Image Path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WpnService Display Name : Windows Push Notifications System Service Image Path : C:\Windows\system32\svchost.exe -k netsvcs -p Startup Type : Auto Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU) Service Name : wscsvc Display Name : Security Center Image Path : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p Startup Type : Auto (Delayed) Log On As : NT AUTHORITY\LocalService Permissions : O:SYG:SYD:(A;;CCLCSWRPLORC;;;BU)(A;;CCLCSWRPLOCRRC;;;SY)(A;;CCLCSWRPLOCRRC;;;BA)(A;;CCLCSWRPLORC;;;IU)(A;;CCLCSWRPLORC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;S-1-5-80-1601830629-990752416-3372939810-977361409-3075122917)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-80-259296475-4084429506-1152984619-38739575-565535606)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WSearch Display Name : Windows Search Image Path : C:\Windows\system32\SearchIndexer.exe /Embedding Startup Type : Auto (Delayed) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCLCSWLORC;;;S-1-15-3-1024-724741592-1210917904-489960769-637019204-3345707629-3097053430-1727148295-85063603) Service Name : wuauserv Display Name : Windows Update Image Path : C:\Windows\system32\svchost.exe -k netsvcs -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOSDRCWDWO;;;WD) Service Name : WwanSvc Display Name : WWAN AutoConfig Image Path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Manual Log On As : localSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCLCRPLO;;;LS)(A;;LC;;;AC) Service Name : XblAuthManager Display Name : Xbox Live Auth Manager Image Path : C:\Windows\system32\svchost.exe -k netsvcs -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : XblGameSave Display Name : Xbox Live Game Save Image Path : C:\Windows\system32\svchost.exe -k netsvcs -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : XboxGipSvc Display Name : Xbox Accessory Management Service Image Path : C:\Windows\system32\svchost.exe -k netsvcs -p Startup Type : Manual (Triggered) Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : XboxNetApiSvc Display Name : Xbox Live Networking Service Image Path : C:\Windows\system32\svchost.exe -k netsvcs -p Startup Type : Manual Log On As : LocalSystem Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : AarSvc_5b697 Display Name : Agent Activation Runtime_5b697 Image Path : C:\Windows\system32\svchost.exe -k AarSvcGroup -p Startup Type : Manual Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : BcastDVRUserService_5b697 Display Name : GameDVR and Broadcast User Service_5b697 Image Path : C:\Windows\system32\svchost.exe -k BcastDVRUserService Startup Type : Manual Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;IU)(A;;CCLCSWRPWPDTLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;AC)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA) Service Name : BluetoothUserService_5b697 Display Name : Bluetooth User Support Service_5b697 Image Path : C:\Windows\system32\svchost.exe -k BthAppGroup -p Startup Type : Manual (Triggered) Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : CaptureService_5b697 Display Name : CaptureService_5b697 Image Path : C:\Windows\system32\svchost.exe -k LocalService -p Startup Type : Manual Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : cbdhsvc_5b697 Display Name : Clipboard User Service_5b697 Image Path : C:\Windows\system32\svchost.exe -k ClipboardSvcGroup -p Startup Type : Auto Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CR;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : CDPUserSvc_5b697 Display Name : Connected Devices Platform User Service_5b697 Image Path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup Startup Type : Auto Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CR;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : CloudBackupRestoreSvc_5b697 Display Name : Cloud Backup and Restore Service_5b697 Image Path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup Startup Type : Manual Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : ConsentUxUserSvc_5b697 Display Name : ConsentUX User Service_5b697 Image Path : C:\Windows\system32\svchost.exe -k DevicesFlow Startup Type : Manual Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;IU)(A;;CCLCSWRPWPDTLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA) Service Name : CredentialEnrollmentManagerUserSvc_5b697 Display Name : CredentialEnrollmentManagerUserSvc_5b697 Image Path : C:\Windows\system32\CredentialEnrollmentManager.exe Startup Type : Manual Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;IU)(A;;CCLCSWRPWPDTLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;AC) Service Name : DeviceAssociationBrokerSvc_5b697 Display Name : DeviceAssociationBroker_5b697 Image Path : C:\Windows\system32\svchost.exe -k DevicesFlow -p Startup Type : Manual Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;IU)(A;;CCLCSWRPWPDTLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;AC) Service Name : DevicePickerUserSvc_5b697 Display Name : DevicePicker_5b697 Image Path : C:\Windows\system32\svchost.exe -k DevicesFlow Startup Type : Manual Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;IU)(A;;CCLCSWRPWPDTLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;AC)(A;;CCLCSWRPWPDTLOCRRC;;;S-1-5-21-2702878673-795188819-444038987-2781) Service Name : DevicesFlowUserSvc_5b697 Display Name : DevicesFlow_5b697 Image Path : C:\Windows\system32\svchost.exe -k DevicesFlow Startup Type : Manual Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;IU)(A;;CCLCSWRPWPDTLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;AC)(A;;CCLCSWRPWPDTLOCRRC;;;S-1-5-21-2702878673-795188819-444038987-2781) Service Name : MessagingService_5b697 Display Name : MessagingService_5b697 Image Path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup Startup Type : Manual (Triggered) Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : NPSMSvc_5b697 Display Name : NPSMSvc_5b697 Image Path : C:\Windows\system32\svchost.exe -k LocalService -p Startup Type : Manual Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CR;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : OneSyncSvc_5b697 Display Name : Sync Host_5b697 Image Path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup Startup Type : Auto Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;LCRP;;;AC)(A;;LCRP;;;IU)(A;;LCRP;;;AU) Service Name : P9RdrService_5b697 Display Name : P9RdrService_5b697 Image Path : C:\Windows\system32\svchost.exe -k P9RdrService -p Startup Type : Manual (Triggered) Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : PenService_5b697 Display Name : PenService_5b697 Image Path : C:\Windows\system32\svchost.exe -k PenService Startup Type : Manual (Triggered) Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : PimIndexMaintenanceSvc_5b697 Display Name : Contact Data_5b697 Image Path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup Startup Type : Manual Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;IU)(A;;CCLCSWRPWPDTLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;AC)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA) Service Name : PrintWorkflowUserSvc_5b697 Display Name : PrintWorkflow_5b697 Image Path : C:\Windows\system32\svchost.exe -k PrintWorkflow Startup Type : Manual (Triggered) Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;IU)(A;;CCLCSWRPWPDTLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;AC)(A;;CCLCSWRPWPDTLOCRRC;;;S-1-15-3-1024-4044835139-2658482041-3127973164-329287231-3865880861-1938685643-461067658-1087000422)(A;;CCLCSWRPWPDTLOCRRC;;;S-1-5-21-2702878673-795188819-444038987-2781) Service Name : UdkUserSvc_5b697 Display Name : Udk User Service_5b697 Image Path : C:\Windows\system32\svchost.exe -k UdkSvcGroup Startup Type : Manual Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;IU)(A;;CCLCSWRPWPDTLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;AC)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA) Service Name : UnistoreSvc_5b697 Display Name : User Data Storage_5b697 Image Path : C:\Windows\System32\svchost.exe -k UnistackSvcGroup Startup Type : Manual Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;IU)(A;;CCLCSWRPWPDTLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;AC)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA) Service Name : UserDataSvc_5b697 Display Name : User Data Access_5b697 Image Path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup Startup Type : Manual Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;IU)(A;;CCLCSWRPWPDTLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;AC)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA) Service Name : webthreatdefusersvc_5b697 Display Name : Web Threat Defense User Service_5b697 Image Path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p Startup Type : Auto Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Service Name : WpnUserService_5b697 Display Name : Windows Push Notifications User Service_5b697 Image Path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup Startup Type : Auto Log On As : Permissions : O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;IU)(A;;CCLCSWRPWPDTLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;AC)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)
To automatically backup the services configuration to a registry file, check out the article Backup Windows Services Startup Type Configuration. To delete a 3rd party service, check out How to Delete a Service in Windows.
One small request: If you liked this post, please share this?
One "tiny" share from you would seriously help a lot with the growth of this blog. Some great suggestions:- Pin it!
- Share it to your favorite blog + Facebook, Reddit
- Tweet it!
3.13.23 — Thank you SO much for this comprehensive list of Service settings. It will make all the difference. I tried to do a re-installation because so many things aren’t working as they should, like Task Scheduler. It’s off in the Services and won’t turn on, or in its native setting [i.e., Win Tools in the Control Panel], it’s looking for a remote computer for a single-user PC. This has to be the solution beyond doing a re-installation; thank you.