@%systemroot%\system32\fveui.dll,-843 : BitLocker Drive Encryption
@%systemroot%\system32\fveui.dll,-844 : BitLocker Data Recovery Agent
c:\windows\system32,@elscore.dll,-9 : Microsoft Bengali to Latin Transliteration
c:\windows\system32,@elscore.dll,-5 : Microsoft Transliteration Engine
@%systemroot%\system32\ci.dll,-100 : Isolated User Mode (IUM)
c:\windows\system32,@elscore.dll,-4 : Microsoft Simplified Chinese to Traditional Chinese Transliteration
c:\windows\system32,@elscore.dll,-10 : Microsoft Hangul Decomposition Transliteration
c:\windows\system32,@elscore.dll,-6 : Microsoft Cyrillic to Latin Transliteration
@mqutil.dll,-6102 : Message Queuing
@%systemroot%\system32\ngcrecovery.dll,-100 : Windows Hello Recovery Key Encryption
c:\windows\system32,@elscore.dll,-3 : Microsoft Traditional Chinese to Simplified Chinese Transliteration
c:\windows\system32,@elscore.dll,-8 : Microsoft Malayalam to Latin Transliteration
c:\windows\system32,@elscore.dll,-1 : Microsoft Language Detection
@%systemroot%\system32\dnsapi.dll,-103 : Domain Name System (DNS) Server Trust
c:\windows\system32,@elscore.dll,-7 : Microsoft Devanagari to Latin Transliteration
c:\windows\system32,@elscore.dll,-2 : Microsoft Script Detection
@%systemroot%\system32\ci.dll,-101 : Enclave
@%systemroot%\system32\firewallcontrolpanel.dll,-12122 : Windows Defender Firewall
@%systemroot%\system32\wuaueng.dll,-400 : Windows Update
@%systemroot%\system32\windowspowershell\v1.0\powershell.exe,-124 : Document Encryption
@%systemroot%\system32\fveui.dll,-843 : BitLocker Drive Encryption
@%systemroot%\system32\fveui.dll,-844 : BitLocker Data Recovery Agent
c:\windows\system32,@elscore.dll,-9 : Microsoft Bengali to Latin Transliteration
@%systemroot%\system32\ci.dll,-100 : Isolated User Mode (IUM)
c:\windows\system32,@elscore.dll,-5 : Microsoft Transliteration Engine
c:\windows\system32,@elscore.dll,-4 : Microsoft Simplified Chinese to Traditional Chinese Transliteration
c:\windows\system32,@elscore.dll,-10 : Microsoft Hangul Decomposition Transliteration
c:\windows\system32,@elscore.dll,-6 : Microsoft Cyrillic to Latin Transliteration
@%systemroot%\system32\ngcrecovery.dll,-100 : Windows Hello Recovery Key Encryption
c:\windows\system32,@elscore.dll,-3 : Microsoft Traditional Chinese to Simplified Chinese Transliteration
c:\windows\system32,@elscore.dll,-8 : Microsoft Malayalam to Latin Transliteration
c:\windows\system32,@elscore.dll,-1 : Microsoft Language Detection
@%systemroot%\system32\dnsapi.dll,-103 : Domain Name System (DNS) Server Trust
c:\windows\system32,@elscore.dll,-7 : Microsoft Devanagari to Latin Transliteration
@%systemroot%\system32\ci.dll,-101 : Enclave
c:\windows\system32,@elscore.dll,-2 : Microsoft Script Detection
@%systemroot%\system32\wuaueng.dll,-400 : Windows Update
@%systemroot%\system32\windowspowershell\v1.0\powershell.exe,-124 : Document Encryption
@%systemroot%\system32\drivers\wpdupfltr.sys,-100 : WPD Upper Class Filter Driver
@combase.dll,-5013 : The DCOMLAUNCH service launches COM and DCOM servers in response to object activation requests. If this service is stopped or disabled, programs using COM or DCOM will not function properly. It is strongly recommended that you have the DCOMLAUNCH service running.
@%systemroot%\system32\axinstsv.dll,-103 : ActiveX Installer (AxInstSV)
@%systemroot%\system32\appxdeploymentserver.dll,-1 : AppX Deployment Service (AppXSVC)
@%windir%\system32\inetsrv\iisres.dll,-30014 : W3C Logging Service
@%systemroot%\system32\smphost.dll,-101 : Host service for the Microsoft Storage Spaces management provider. If this service is stopped or disabled, Storage Spaces cannot be managed.
@%systemroot%\system32\wlidsvc.dll,-100 : Microsoft Account Sign-in Assistant
@%systemroot%\system32\wcncsvc.dll,-3 : Windows Connect Now - Config Registrar
@%systemroot%\system32\efssvc.dll,-100 : Encrypting File System (EFS)
@%windir%\system32\drivers\pacer.sys,-101 : QoS Packet Scheduler
@%windir%\system32\inetsrv\iisres.dll,-30002 : The Windows Process Activation Service (WAS) provides process activation, resource management and health management services for message-activated applications.
@%systemroot%\system32\lltdres.dll,-6 : Link-Layer Topology Discovery Mapper I/O Driver
@%systemroot%\system32\drivers\rdpdr.sys,-100 : Remote Desktop Device Redirector Driver
@%systemroot%\system32\aphostres.dll,-10002 : Sync Host
@c:\windows\system32\rdpendp.dll,-1001 : Remote Audio
@%systemroot%\system32\devicesetupmanager.dll,-1000 : Device Setup Manager
@c:\programdata\microsoft\windows defender\platform\4.18.25090.3009-0\mpasdesc.dll,-240 : Helps protect users from malware and other potentially unwanted software
@%systemroot%\system32\workfolderssvc.dll,-101 : This service syncs files with the Work Folders server, enabling you to use the files on any of the PCs and devices on which you've set up Work Folders.
@%systemroot%\system32\ci.dll,-100 : Isolated User Mode (IUM)
@%systemroot%\system32\wscsvc.dll,-200 : Security Center
@%systemroot%\system32\consentuxclient.dll,-101 : Allows the system to request user consent to allow apps to access sensitive resources and information such as the device's location
@%systemroot%\system32\qwave.dll,-1 : Quality Windows Audio Video Experience
@%systemroot%\system32\cloudidsvc.dll,-100 : Microsoft Cloud Identity Service
@%systemroot%\system32\wiarpc.dll,-2 : Still Image Acquisition Events
@c:\programdata\microsoft\windows defender\platform\4.18.25080.5-0\mpasdesc.dll,-240 : Helps protect users from malware and other potentially unwanted software
@%systemroot%\system32\xboxgipsvc.dll,-101 : This service manages connected Xbox Accessories.
@peerdistsh.dll,-9002 : BranchCache - Hosted Cache Server (Uses HTTPS)
@%systemroot%\system32\powrprof.dll,-12 : Favors performance, but may use more energy.
@%systemroot%\system32\tapisrv.dll,-10100 : Telephony
@%systemroot%\system32\drivers\winnat.sys,-10001 : Windows NAT Driver
@c:\programdata\microsoft\windows defender\platform\4.18.25100.9008-0\mpasdesc.dll,-340 : Microsoft Defender Antivirus On-Access Malware Protection Mini-Filter Driver
@%systemroot%\system32\drivers\appvstrm.sys,-101 : AppvStrm
@%systemroot%\system32\wpcrefreshtask.dll,-100 : Parental Controls
@%systemroot%\system32\p9rdrservice.dll,-101 : Enables trigger-starting plan9 file servers.
@%systemroot%\system32\wpnservice.dll,-2 : This service runs in session 0 and hosts the notification platform and connection provider which handles the connection between the device and WNS server.
@%systemroot%\system32\p2psvc.dll,-8006 : Peer Networking Grouping
@%systemroot%\system32\sensorservice.dll,-1001 : A service for sensors that manages different sensors' functionality. Manages Simple Device Orientation (SDO) and History for sensors. Loads the SDO sensor that reports device orientation changes. If this service is stopped or disabled, the SDO sensor will not be loaded and so auto-rotation will not occur. History collection from Sensors will also be stopped.
@%systemroot%\system32\drivers\scfilter.sys,-11 : Smart card PnP Class Filter Driver
@%systemroot%\system32\sysmain.dll,-1001 : Maintains and improves system performance over time.
@%systemroot%\system32\diagsvcs\diagnosticshub.standardcollector.serviceres.dll,-1001 : Diagnostics Hub Standard Collector Service. When running, this service collects real time ETW events and processes them.
@%systemroot%\system32\assignedaccessmanagersvc.dll,-100 : AssignedAccessManager Service
@%systemroot%\system32\graphicsperfsvc.dll,-101 : Graphics performance monitor service
@%systemroot%\system32\fdphost.dll,-100 : Function Discovery Provider Host
@c:\programdata\microsoft\windows defender\platform\4.18.25110.6-0\mpasdesc.dll,-310 : Microsoft Defender Antivirus Service
@%systemroot%\system32\frameserver.dll,-101 : Enables multiple clients to access video frames from camera devices.
@%systemroot%\system32\ncbservice.dll,-501 : Brokers connections that allow Windows Store Apps to receive notifications from the internet.
@%systemroot%\system32\walletservice.dll,-1000 : WalletService
@%systemroot%\system32\penservice.dll,-100 : PenService
@%systemroot%\system32\netlogon.dll,-102 : Netlogon
@%systemroot%\system32\phoneserviceres.dll,-10001 : Manages the telephony state on the device
@%systemroot%\system32\dialogblockingservice.dll,-101 : Dialog Blocking Service
@%systemroot%\system32\ngcrecovery.dll,-100 : Windows Hello Recovery Key Encryption
@%systemroot%\system32\umpnpmgr.dll,-100 : Device Install Service
@%systemroot%\system32\drivers\wdf01000.sys,-1000 : Kernel Mode Driver Frameworks service
@%systemroot%\system32\ci.dll,-101 : Enclave
@%systemroot%\system32\bthserv.dll,-101 : Bluetooth Support Service
@%systemroot%\system32\vds.exe,-112 : Provides management services for disks, volumes, file systems, and storage arrays.
@%systemroot%\system32\urlmon.dll,-4200 : Open File - Security Warning
@%systemroot%\system32\sstpsvc.dll,-201 : Provides support for the Secure Socket Tunneling Protocol (SSTP) to connect to remote computers using VPN. If this service is disabled, users will not be able to use SSTP to access remote servers.
@%systemroot%\system32\qmgr.dll,-1001 : Transfers files in the background using idle network bandwidth. If the service is disabled, then any applications that depend on BITS, such as Windows Update or MSN Explorer, will be unable to automatically download programs and other information.
@%systemroot%\system32\netman.dll,-110 : Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections.
@%programfiles%\windows defender advanced threat protection\mssense.exe,-1001 : Windows Defender Advanced Threat Protection Service
@c:\windows\system32\windows.storage.dll,-10152 : File folder
@%systemroot%\system32\drivers\volmgrx.sys,-100 : Dynamic Volume Manager
@%systemroot%\system32\das.dll,-101 : Enables pairing between the system and wired or wireless devices.
@combase.dll,-5011 : The RPCSS service is the Service Control Manager for COM and DCOM servers. It performs object activations requests, object exporter resolutions and distributed garbage collection for COM and DCOM servers. If this service is stopped or disabled, programs using COM or DCOM will not function properly. It is strongly recommended that you have the RPCSS service running.
@%systemroot%\system32\mprmsg.dll,-32006 : WAN Miniport (PPTP)
@%systemroot%\system32\wlidsvc.dll,-101 : Enables user sign-in through Microsoft account identity services. If this service is stopped, users will not be able to logon to the computer with their Microsoft account.
@%systemroot%\system32\dmwappushsvc.dll,-200 : Device Management Wireless Application Protocol (WAP) Push message Routing Service
@%systemroot%\system32\windows.warp.jitservice.dll,-101 : Enables JIT compilation support in d3d10warp.dll for processes in which code generation is disabled.
@%systemroot%\system32\pnrpauto.dll,-8003 : This service publishes a machine name using the Peer Name Resolution Protocol. Configuration is managed via the netsh context 'p2p pnrp peer'
@%systemroot%\system32\icsvc.dll,-202 : Provides a mechanism to exchange data between the virtual machine and the operating system running on the physical computer.
@%systemroot%\system32\diagsvc.dll,-100 : Diagnostic Execution Service
@%systemroot%\system32\icsvc.dll,-301 : Hyper-V Guest Shutdown Service
@%systemroot%\system32\wcmsvc.dll,-4098 : Makes automatic connect/disconnect decisions based on the network connectivity options currently available to the PC and enables management of network connectivity based on Group Policy settings.
@%systemroot%\system32\aarsvc.dll,-101 : Runtime for activating conversational agent applications
@%systemroot%\system32\wfdsconmgrsvc.dll,-9001 : Manages connections to wireless services, including wireless display and docking.
@%systemroot%\system32\drivers\fsdepends.sys,-10001 : File System Dependency Minifilter
@c:\programdata\microsoft\windows defender\platform\4.18.25110.5-0\mpasdesc.dll,-240 : Helps protect users from malware and other potentially unwanted software
@%systemroot%\system32\firewallapi.dll,-54005 : OutBound Rule for the Microsoft Media Foundation's Capture SVC to open TCP port to enable RTSP
@%systemroot%\system32\phoneserviceres.dll,-10000 : Phone Service
@%systemroot%\system32\wcncsvc.dll,-4 : WCNCSVC hosts the Windows Connect Now Configuration which is Microsoft's Implementation of Wireless Protected Setup (WPS) protocol. This is used to configure Wireless LAN settings for an Access Point (AP) or a Wireless Device. The service is started programmatically as needed.
c:\windows\system32,@elscore.dll,-7 : Microsoft Devanagari to Latin Transliteration
@%systemroot%\system32\defragsvc.dll,-102 : Helps the computer run more efficiently by optimizing files on storage drives.
@mqutil.dll,-6104 : Provides a messaging infrastructure and development tool for creating distributed messaging applications for Windows-based networks and programs. If this service is stopped, distributed messages will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\upnphost.dll,-214 : Allows UPnP devices to be hosted on this computer. If this service is stopped, any hosted UPnP devices will stop functioning and no additional hosted devices can be added. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\xboxnetapisvc.dll,-101 : This service supports the Windows.Networking.XboxLive application programming interface.
@%systemroot%\system32\tabsvc.dll,-100 : Touch Keyboard and Handwriting Panel Service
@%systemroot%\system32\tcpipcfg.dll,-50004 : NetIO Legacy TDI Support Driver
@%systemroot%\system32\windows.devices.picker.dll,-1006 : DevicePicker
@%windir%\system32\systemeventsbrokerserver.dll,-1002 : Coordinates execution of background work for WinRT application. If this service is stopped or disabled, then background work might not be triggered.
@%systemroot%\system32\assignedaccessmanagersvc.dll,-101 : AssignedAccessManager Service supports kiosk experience in Windows.
@%systemroot%\system32\deviceaccess.dll,-108 : Enables apps to pair devices
@%windir%\system32\inetsrv\iisres.dll,-30008 : Enables this server to administer the IIS metabase. The IIS metabase stores configuration for the SMTP and FTP services. If this service is stopped, the server will be unable to configure SMTP or FTP. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\ipnathlp.dll,-106 : Internet Connection Sharing (ICS)
@c:\programdata\microsoft\windows defender\platform\4.18.25100.9008-0\mpasdesc.dll,-320 : Microsoft Defender Antivirus Network Inspection Service
@%systemroot%\system32\wkssvc.dll,-1000 : Redirected Buffering Sub System
@%systemroot%\system32\mprmsg.dll,-32012 : Remote Access IPv6 ARP Driver
@peerdistsh.dll,-9003 : BranchCache - Hosted Cache Client (Uses HTTPS)
@%systemroot%\system32\bthavctpsvc.dll,-102 : This is Audio Video Control Transport Protocol service
@%systemroot%\system32\alg.exe,-112 : Application Layer Gateway Service
@%systemroot%\system32\sensrsvc.dll,-1001 : Monitors various sensors in order to expose data and adapt to system and user state. If this service is stopped or disabled, the display brightness will not adapt to lighting conditions. Stopping this service may affect other system functionality and features as well.
@%systemroot%\system32\drivers\msseccore.sys,-1001 : Microsoft Security Core Boot Driver
@%systemroot%\system32\microsoft.bluetooth.userservice.dll,-101 : Bluetooth User Support Service
@%systemroot%\system32\sstpsvc.dll,-202 : WAN Miniport (SSTP)
@c:\programdata\microsoft\windows defender\platform\4.18.25110.5-0\mpasdesc.dll,-330 : Microsoft Defender Antivirus Mini-Filter Driver
@%systemroot%\system32\sysmain.dll,-1000 : SysMain
@%systemroot%\system32\windows.sharedpc.accountmanager.dll,-101 : Manages profiles and accounts on a SharedPC configured device
@%systemroot%\system32\tzautoupdate.dll,-201 : Automatically sets the system time zone.
@%systemroot%\system32\drivers\ndu.sys,-10001 : Windows Network Data Usage Monitoring Driver
@%systemroot%\system32\userdataaccessres.dll,-10002 : Handles storage of structured user data, including contact info, calendars, messages, and other content. If you stop or disable this service, apps that use this data might not work correctly.
@%systemroot%\system32\securityhealthagent.dll,-1001 : Windows Security Service handles unified device protection and health information
@c:\programdata\microsoft\windows defender\platform\4.18.25090.3009-0\mpasdesc.dll,-330 : Microsoft Defender Antivirus Mini-Filter Driver
@%systemroot%\system32\peerdistsvc.dll,-9000 : BranchCache
c:\windows\system32,@elscore.dll,-6 : Microsoft Cyrillic to Latin Transliteration
@comres.dll,-2798 : Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will fail. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\bfe.dll,-1002 : The Base Filtering Engine (BFE) is a service that manages firewall and Internet Protocol security (IPsec) policies and implements user mode filtering. Stopping or disabling the BFE service will significantly reduce the security of the system. It will also result in unpredictable behavior in IPsec management and firewall applications.
@%systemroot%\system32\wevtsvc.dll,-201 : This service manages events and event logs. It supports logging events, querying events, subscribing to events, archiving event logs, and managing event metadata. It can display events in both XML and plain text format. Stopping this service may compromise security and reliability of the system.
@%systemroot%\system32\drivers\ndisvirtualbus.sys,-200 : Microsoft Virtual Network Adapter Enumerator
@%systemroot%\system32\wshrm.dll,-102 : Reliable Multicast Protocol
@%systemroot%\system32\tieringengineservice.exe,-701 : Optimizes the placement of data in storage tiers on all tiered storage spaces in the system.
@%systemroot%\system32\searchindexer.exe,-103 : Windows Search
@%systemroot%\system32\drivers\wudfrd.sys,-1000 : Windows Driver Foundation - User-mode Driver Framework Reflector
@%systemroot%\system32\bdesvc.dll,-100 : BitLocker Drive Encryption Service
@%systemroot%\system32\das.dll,-100 : Device Association Service
@%systemroot%\system32\termsrv.dll,-267 : Allows users to connect interactively to a remote computer. Remote Desktop and Remote Desktop Session Host Server depend on this service. To prevent remote use of this computer, clear the checkboxes on the Remote tab of the System properties control panel item.
@%systemroot%\syswow64\perfhost.exe,-1 : Enables remote users and 64-bit processes to query performance counters provided by 32-bit DLLs. If this service is stopped, only local users and 32-bit processes will be able to query performance counters provided by 32-bit DLLs.
@c:\programdata\microsoft\windows defender\platform\4.18.25100.9008-0\mpasdesc.dll,-310 : Microsoft Defender Antivirus Service
@%systemroot%\system32\scdeviceenum.dll,-101 : Creates software device nodes for all smart card readers accessible to a given session. If this service is disabled, WinRT APIs will not be able to enumerate smart card readers.
@%systemroot%\system32\rdxservice.dll,-257 : The Retail Demo service controls device activity while the device is in retail demo mode.
@%systemroot%\system32\rasmans.dll,-200 : Remote Access Connection Manager
@%systemroot%\system32\sdrsvc.dll,-102 : Provides Windows Backup and Restore capabilities.
@c:\windows\system32\msxml3r.dll,-1 : XML Document
@%systemroot%\system32\wdi.dll,-501 : The Diagnostic System Host is used by the Diagnostic Policy Service to host diagnostics that need to run in a Local System context. If this service is stopped, any diagnostics that depend on it will no longer function.
@%systemroot%\system32\firewallapi.dll,-37302 : mDNS
@%systemroot%\system32\drivers\pdc.sys,-100 : PDC
@%systemroot%\system32\dot3svc.dll,-1102 : Wired AutoConfig
@%systemroot%\system32\capabilityaccessmanager.dll,-1 : Capability Access Manager Service
@c:\programdata\microsoft\windows defender\platform\4.18.25080.5-0\mpasdesc.dll,-242 : Helps guard against intrusion attempts targeting known and newly discovered vulnerabilities in network protocols
@%systemroot%\system32\ngcctnrsvc.dll,-1 : Microsoft Passport Container
@%systemroot%\system32\spectrum.exe,-101 : Windows Perception Service
@%systemroot%\system32\installservice.dll,-201 : Provides infrastructure support for the Microsoft Store. This service is started on demand and if disabled then installations will not function properly.
@c:\programdata\microsoft\windows defender\platform\4.18.25110.6-0\mpasdesc.dll,-240 : Helps protect users from malware and other potentially unwanted software
@%systemroot%\system32\drivers\fltmgr.sys,-10001 : FltMgr
@%systemroot%\system32\pla.dll,-500 : Performance Logs & Alerts
@c:\programdata\microsoft\windows defender\platform\4.18.25080.5-0\mpasdesc.dll,-330 : Microsoft Defender Antivirus Mini-Filter Driver
@%systemroot%\system32\alg.exe,-113 : Provides support for 3rd party protocol plug-ins for Internet Connection Sharing
@%systemroot%\system32\bcastdvruserservice.dll,-101 : This user service is used for Game Recordings and Live Broadcasts
@%systemroot%\system32\presentationhost.exe,-3309 : Windows Presentation Foundation Font Cache 3.0.0.0
@%systemroot%\system32\dot3svc.dll,-1103 : The Wired AutoConfig (DOT3SVC) service is responsible for performing IEEE 802.1X authentication on Ethernet interfaces. If your current wired network deployment enforces 802.1X authentication, the DOT3SVC service should be configured to run for establishing Layer 2 connectivity and/or providing access to network resources. Wired networks that do not enforce 802.1X authentication are unaffected by the DOT3SVC service.
@%systemroot%\system32\msimsg.dll,-27 : Windows Installer
@%systemroot%\system32\drivers\tsusbflt.sys,-1000 : Remote Desktop USB Hub Class Filter Driver
@c:\programdata\microsoft\windows defender\platform\4.18.25090.3009-0\mpasdesc.dll,-244 : Monitors the availability, health, and performance of various security components
@comres.dll,-2946 : KtmRm for Distributed Transaction Coordinator
@%systemroot%\system32\cdpsvc.dll,-100 : Connected Devices Platform Service
@%windir%\system32\rpcepmap.dll,-1002 : Resolves RPC interfaces identifiers to transport endpoints. If this service is stopped or disabled, programs using Remote Procedure Call (RPC) services will not function properly.
@%systemroot%\system32\swprv.dll,-102 : Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\wpdbusenum.dll,-101 : Enforces group policy for removable mass-storage devices. Enables applications such as Windows Media Player and Image Import Wizard to transfer and synchronize content using removable mass-storage devices.
@keyiso.dll,-101 : The CNG key isolation service is hosted in the LSA process. The service provides key process isolation to private keys and associated cryptographic operations as required by the Common Criteria. The service stores and uses long-lived keys in a secure process complying with Common Criteria requirements.
@%systemroot%\system32\drivers\bindflt.sys,-100 : Windows Bind Filter Driver
@%systemroot%\system32\xblgamesave.dll,-101 : This service syncs save data for Xbox Live save enabled games. If this service is stopped, game save data will not upload to or download from Xbox Live.
@c:\programdata\microsoft\windows defender\platform\4.18.25080.5-0\mpasdesc.dll,-390 : Microsoft Defender Antivirus Boot Driver
@%systemroot%\system32\embeddedmodesvc.dll,-202 : The Embedded Mode service enables scenarios related to Background Applications. Disabling this service will prevent Background Applications from being activated.
@%systemroot%\system32\w32time.dll,-201 : Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\embeddedmodesvc.dll,-201 : Embedded Mode
@c:\programdata\microsoft\windows defender\platform\4.18.25100.9008-0\mpasdesc.dll,-330 : Microsoft Defender Antivirus Mini-Filter Driver
@c:\programdata\microsoft\windows defender\platform\4.18.25110.6-0\mpasdesc.dll,-370 : Microsoft Defender Antivirus Network Inspection System Driver
@%systemroot%\system32\clipsvc.dll,-104 : Provides infrastructure support for the Microsoft Store. This service is started on demand and if disabled applications bought using Windows Store will not behave correctly.
@%systemroot%\system32\ipnathlp.dll,-107 : Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network.
@%systemroot%\system32\captureservice.dll,-101 : Enables optional screen capture functionality for applications that call the Windows.Graphics.Capture API.
@%systemroot%\system32\firewallcontrolpanel.dll,-12122 : Windows Defender Firewall
@%systemroot%\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8194 : Receives activation requests over the net.msmq and msmq.formatname protocols and passes them to the Windows Process Activation Service.
@%systemroot%\system32\drivers\vwifibus.sys,-257 : Virtual Wireless Bus Driver
@%systemroot%\system32\rasauto.dll,-201 : Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address.
@%systemroot%\system32\netprofmsvc.dll,-203 : Identifies the networks to which the computer has connected, collects and stores properties for these networks, and notifies applications when these properties change.
@%systemroot%\system32\drivers\storqosflt.sys,-101 : Storage QoS Filter Driver
@%systemroot%\system32\sgrmbroker.exe,-101 : Monitors and attests to the integrity of the Windows platform.
@%systemroot%\system32\userdataaccessres.dll,-10003 : User Data Storage
@%systemroot%\system32\fdrespub.dll,-100 : Function Discovery Resource Publication
@%systemroot%\system32\drivers\appvvemgr.sys,-101 : AppvVemgr
@%systemroot%\system32\agentservice.exe,-101 : Provides support for application and OS settings roaming
@%systemroot%\system32\keyboardfiltersvc.dll,-101 : Microsoft Keyboard Filter
@%systemroot%\system32\wbengine.exe,-104 : Block Level Backup Engine Service
@%systemroot%\servicing\trustedinstaller.exe,-101 : Enables installation, modification, and removal of Windows updates and optional components. If this service is disabled, install or uninstall of Windows updates might fail for this computer.
@%systemroot%\system32\pcasvc.dll,-1 : Program Compatibility Assistant Service
@%systemroot%\system32\wdi.dll,-503 : The Diagnostic Service Host is used by the Diagnostic Policy Service to host diagnostics that need to run in a Local Service context. If this service is stopped, any diagnostics that depend on it will no longer function.
@%systemroot%\system32\bthavctpsvc.dll,-101 : AVCTP service
@%systemroot%\system32\windows.management.service.dll,-101 : Performs management including Provisioning and Enrollment activities
@c:\windows\system32\spool\drivers\x64\3\printconfig.dll,-2 : This service opens custom printer dialog boxes and handles notifications from a remote print server or a printer. If you turn off this service, you won’t be able to see printer extensions or notifications.
@%systemroot%\system32\penservice.dll,-101 : Pen Service
@%systemroot%\system32\drivers\gpuenergydrv.sys,-100 : GPU Energy Driver
@%systemroot%\system32\xblauthmanager.dll,-101 : Provides authentication and authorization services for interacting with Xbox Live. If this service is stopped, some applications may not operate correctly.
@%systemroot%\system32\wiaservc.dll,-9 : Windows Image Acquisition (WIA)
@%systemroot%\system32\drivers\afd.sys,-1000 : Ancillary Function Driver for Winsock
@c:\programdata\microsoft\windows defender\platform\4.18.25110.5-0\mpasdesc.dll,-400 : Microsoft Defender Antivirus Boot Driver
@%systemroot%\system32\powrprof.dll,-11 : Power saver
@%systemroot%\system32\autotimesvc.dll,-6 : Cellular Time
@%systemroot%\system32\mprmsg.dll,-32005 : WAN Miniport (L2TP)
@%systemroot%\servicing\trustedinstaller.exe,-100 : Windows Modules Installer
@gpapi.dll,-113 : The service is responsible for applying settings configured by administrators for the computer and users through the Group Policy component. If the service is disabled, the settings will not be applied and applications and components will not be manageable through Group Policy. Any components or applications that depend on the Group Policy component might not be functional if the service is disabled.
@%systemroot%\system32\rasmans.dll,-201 : Manages dial-up and virtual private network (VPN) connections from this computer to the Internet or other remote networks. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\certprop.dll,-14 : Allows the system to be configured to lock the user desktop upon smart card removal.
@%systemroot%\system32\windows.devices.picker.dll,-1007 : This user service is used for managing the Miracast, DLNA, and DIAL UI
@%systemroot%\system32\pla.dll,-501 : Performance Logs and Alerts Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\rmapi.dll,-1002 : Radio Management and Airplane Mode Service
@%systemroot%\system32\tokenbroker.dll,-100 : Web Account Manager
c:\windows\system32,@elscore.dll,-2 : Microsoft Script Detection
@c:\programdata\microsoft\windows defender\platform\4.18.25090.3009-0\mpasdesc.dll,-400 : Microsoft Defender Antivirus Boot Driver
@%systemroot%\system32\installservice.dll,-200 : Microsoft Store Install Service
@c:\programdata\microsoft\windows defender\platform\4.18.25080.5-0\mpasdesc.dll,-310 : Microsoft Defender Antivirus Service
@%systemroot%\system32\rdxservice.dll,-256 : Retail Demo Service
@%systemroot%\system32\naturalauth.dll,-100 : Natural Authentication
@%systemroot%\system32\netlogon.dll,-103 : Maintains a secure channel between this computer and the domain controller for authenticating users and services. If this service is stopped, the computer may not authenticate users and services and the domain controller cannot register DNS records. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\scardsvr.dll,-5 : Manages access to smart cards read by this computer. If this service is stopped, this computer will be unable to read smart cards. If this service is disabled, any services that explicitly depend on it will fail to start.
@comres.dll,-2947 : Coordinates transactions between the Distributed Transaction Coordinator (MSDTC) and the Kernel Transaction Manager (KTM). If it is not needed, it is recommended that this service remain stopped. If it is needed, both MSDTC and KTM will start this service automatically. If this service is disabled, any MSDTC transaction interacting with a Kernel Resource Manager will fail and any services that explicitly depend on it will fail to start.
@%systemroot%\system32\drivers\sgrmagent.sys,-1001 : System Guard Runtime Monitor Agent
c:\windows\system32,@elscore.dll,-9 : Microsoft Bengali to Latin Transliteration
@%systemroot%\system32\drivers\hwpolicy.sys,-101 : Hardware Policy Driver
@%systemroot%\system32\icsvcvss.dll,-102 : Coordinates the communications that are required to use Volume Shadow Copy Service to back up applications and data on this virtual machine from the operating system on the physical computer.
@%systemroot%\system32\shsvcs.dll,-12288 : Shell Hardware Detection
@%systemroot%\system32\dmwappushsvc.dll,-201 : Routes Wireless Application Protocol (WAP) Push messages received by the device and synchronizes Device Management sessions
@c:\programdata\microsoft\windows defender\platform\4.18.25110.6-0\mpasdesc.dll,-242 : Helps guard against intrusion attempts targeting known and newly discovered vulnerabilities in network protocols
@%systemroot%\system32\mprdim.dll,-200 : Routing and Remote Access
@%systemroot%\system32\srvsvc.dll,-101 : Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\consentuxclient.dll,-100 : ConsentUX User Service
@%systemroot%\system32\icsvcext.dll,-602 : Provides a platform for communication between the virtual machine and the operating system running on the physical computer.
@%systemroot%\system32\appxdeploymentserver.dll,-2 : Provides infrastructure support for deploying Store applications. This service is started on demand and if disabled Store applications will not be deployed to the system, and may not function properly.
c:\windows\system32,@elscore.dll,-8 : Microsoft Malayalam to Latin Transliteration
@%systemroot%\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8200 : Provides ability to share TCP ports over the net.tcp protocol.
@%systemroot%\system32\schedsvc.dll,-101 : Enables a user to configure and schedule automated tasks on this computer. The service also hosts multiple Windows system-critical tasks. If this service is stopped or disabled, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\capabilityaccessmanager.dll,-2 : Provides facilities for managing UWP apps access to app capabilities as well as checking an app's access to specific app capabilities
@%systemroot%\system32\drivers\nwifi.sys,-101 : NativeWiFi Filter
@%programfiles%\windows media player\wmpnetwk.exe,-101 : Windows Media Player Network Sharing Service
@c:\programdata\microsoft\windows defender\platform\4.18.25110.6-0\mpasdesc.dll,-400 : Microsoft Defender Antivirus Boot Driver
@%systemroot%\system32\diagtrack.dll,-3002 : The Connected User Experiences and Telemetry service enables features that support in-application and connected user experiences. Additionally, this service manages the event driven collection and transmission of diagnostic and usage information (used to improve the experience and quality of the Windows Platform) when the diagnostics and usage privacy option settings are enabled under Feedback and Diagnostics.
@%systemroot%\system32\printworkflowservice.dll,-101 : Provides support for Print Workflow applications. If you turn off this service, you may not be able to print successfully.
@mqutil.dll,-6101 : Message Queuing Access Control
@%systemroot%\system32\netprofmsvc.dll,-208 : Network Location Awareness
@%systemroot%\system32\ncdautosetup.dll,-100 : Network Connected Devices Auto-Setup
c:\windows\system32,@elscore.dll,-1 : Microsoft Language Detection
@%systemroot%\system32\hidserv.dll,-101 : Human Interface Device Service
@c:\programdata\microsoft\windows defender\platform\4.18.25110.6-0\mpasdesc.dll,-390 : Microsoft Defender Antivirus Boot Driver
@%systemroot%\system32\ngcctnrsvc.dll,-2 : Manages local user identity keys used to authenticate user to identity providers as well as TPM virtual smart cards. If this service is disabled, local user identity keys and TPM virtual smart cards will not be accessible. It is recommended that you do not reconfigure this service.
@c:\programdata\microsoft\windows defender\platform\4.18.25100.9008-0\mpasdesc.dll,-245 : Microsoft Defender Core Service
@%systemroot%\system32\drivers\mshidumdf.sys,-100 : Pass-through HID to UMDF Driver
@%systemroot%\system32\swprv.dll,-103 : Microsoft Software Shadow Copy Provider
@%systemroot%\system32\scdeviceenum.dll,-100 : Smart Card Device Enumeration Service
@%systemroot%\system32\wkssvc.dll,-1008 : DFS Namespace Client Driver
@%systemroot%\system32\eapsvc.dll,-1 : Extensible Authentication Protocol
@c:\programdata\microsoft\windows defender\platform\4.18.25110.5-0\mpasdesc.dll,-390 : Microsoft Defender Antivirus Boot Driver
@%systemroot%\system32\naturalauth.dll,-101 : Signal aggregator service, that evaluates signals based on time, network, geolocation, bluetooth and cdf factors. Supported features are Device Unlock, Dynamic Lock and Dynamo MDM policies
@%systemroot%\system32\eapsvc.dll,-2 : The Extensible Authentication Protocol (EAP) service provides network authentication in such scenarios as 802.1x wired and wireless, VPN, and Network Access Protection (NAP). EAP also provides application programming interfaces (APIs) that are used by network access clients, including wireless and VPN clients, during the authentication process. If you disable this service, this computer is prevented from accessing networks that require EAP authentication.
@%systemroot%\system32\drivers\uevagentdriver.sys,-101 : UevAgentDriver
@%windir%\system32\inetsrv\iisres.dll,-30004 : Provides Web connectivity and administration through the Internet Information Services Manager
@%systemroot%\system32\locator.exe,-3 : In Windows 2003 and earlier versions of Windows, the Remote Procedure Call (RPC) Locator service manages the RPC name service database. In Windows Vista and later versions of Windows, this service does not provide any functionality and is present for application compatibility.
@%systemroot%\system32\microsoft.graphics.display.displayenhancementservice.dll,-1001 : A service for managing display enhancement such as brightness control.
@%systemroot%\system32\wercplsupport.dll,-100 : This service provides support for viewing, sending and deletion of system-level problem reports for the Problem Reports control panel.
@%systemroot%\system32\w32time.dll,-200 : Windows Time
c:\windows\system32,@elscore.dll,-5 : Microsoft Transliteration Engine
@wlansvc.dll,-36864 : WLAN Service - WFD Application Services Platform Coordination Protocol (Uses UDP)
@%systemroot%\system32\cscsvc.dll,-200 : Offline Files
@%systemroot%\system32\microsoft.bluetooth.userservice.dll,-102 : The Bluetooth user service supports proper functionality of Bluetooth features relevant to each user session.
@%systemroot%\system32\drivers\clfs.sys,-100 : Common Log (CLFS)
@mqutil.dll,-6206 : Provides rule-based monitoring of messages arriving in a Message Queuing queue and, when the conditions of a rule are satisfied, invokes a COM component or a stand-alone executable program to process the message.
@waasmedicsvc.dll,-100 : Windows Update Medic Service
@%systemroot%\system32\drivers\ndis.sys,-200 : NDIS System Driver
@%systemroot%\system32\usosvc.dll,-102 : Manages Windows Updates. If stopped, your devices will not be able to download and install the latest updates.
@%systemroot%\system32\tetheringservice.dll,-4098 : Provides the ability to share a cellular data connection with another device.
@%systemroot%\system32\sstpsvc.dll,-200 : Secure Socket Tunneling Protocol Service
@%systemroot%\system32\ncasvc.dll,-3008 : Provides DirectAccess status notification for UI components
@%systemroot%\system32\drivers\wudfpf.sys,-1000 : User Mode Driver Frameworks Platform Driver
@firewallapi.dll,-50323 : SNMP Trap
@sstpsvc.dll,-35001 : Secure Socket Tunneling Protocol
@%systemroot%\system32\wdi.dll,-500 : Diagnostic System Host
@%systemroot%\system32\fdrespub.dll,-101 : Publishes this computer and resources attached to this computer so they can be discovered over the network. If this service is stopped, network resources will no longer be published and they will not be discovered by other computers on the network.
@%systemroot%\system32\sgrmbroker.exe,-100 : System Guard Runtime Monitor Broker
@c:\programdata\microsoft\windows defender\platform\4.18.25090.3009-0\mpasdesc.dll,-340 : Microsoft Defender Antivirus On-Access Malware Protection Mini-Filter Driver
@%windir%\system32\bisrv.dll,-101 : Windows infrastructure service that controls which background tasks can run on the system.
@%systemroot%\system32\wiaservc.dll,-10 : Provides image acquisition services for scanners and cameras
@%systemroot%\system32\certprop.dll,-12 : Copies user certificates and root certificates from smart cards into the current user's certificate store, detects when a smart card is inserted into a smart card reader, and, if needed, installs the smart card Plug and Play minidriver.
@%systemroot%\system32\hnetcfgclient.dll,-201 : HNetCfg Client
@%systemroot%\system32\pnrpsvc.dll,-8000 : Peer Name Resolution Protocol
@%systemroot%\system32\autotimesvc.dll,-7 : This service sets time based on NITZ messages from a Mobile Network
@%systemroot%\system32\iscsidsc.dll,-5000 : Microsoft iSCSI Initiator Service
@%systemroot%\system32\windowspowershell\v1.0\powershell.exe,-124 : Document Encryption
@c:\programdata\microsoft\windows defender\platform\4.18.25090.3009-0\mpasdesc.dll,-370 : Microsoft Defender Antivirus Network Inspection System Driver
@%systemroot%\system32\drivers\p9rdr.sys,-100 : Plan 9 Redirector Driver
@%systemroot%\system32\trkwks.dll,-2 : Maintains links between NTFS files within a computer or across computers in a network.
@%systemroot%\system32\appvclient.exe,-101 : Manages App-V users and virtual applications
@%systemroot%\system32\wpcrefreshtask.dll,-101 : Enforces parental controls for child accounts in Windows. If this service is stopped or disabled, parental controls may not be enforced.
@%systemroot%\system32\drivers\cnghwassist.sys,-100 : CNG Hardware Assist algorithm provider
@%systemroot%\system32\svsvc.dll,-102 : Verifies potential file system corruptions.
@%systemroot%\system32\lltdres.dll,-2 : Creates a Network Map, consisting of PC and device topology (connectivity) information, and metadata describing each PC and device. If this service is disabled, the Network Map will not function properly.
@c:\programdata\microsoft\windows defender\platform\4.18.25090.3009-0\mpasdesc.dll,-310 : Microsoft Defender Antivirus Service
@%systemroot%\system32\powrprof.dll,-15 : Balanced
@%systemroot%\system32\lltdres.dll,-5 : Link-Layer Topology Discovery Responder
@%systemroot%\system32\tetheringservice.dll,-4097 : Windows Mobile Hotspot Service
@%systemroot%\system32\drivers\appvvfs.sys,-101 : AppvVfs
@%systemroot%\system32\mitigationclient.dll,-104 : Enables automatic mitigation for known problems by applying recommended troubleshooting. If stopped, your device will not get recommended troubleshooting for problems on your device.
@%systemroot%\system32\windows.warp.jitservice.dll,-100 : Warp JIT Service
c:\windows\system32,@elscore.dll,-4 : Microsoft Simplified Chinese to Traditional Chinese Transliteration
@%systemroot%\system32\drivers\http.sys,-1 : HTTP Service
@%systemroot%\system32\sessenv.dll,-1027 : Remote Desktop Configuration service (RDCS) is responsible for all Remote Desktop Services and Remote Desktop related configuration and session maintenance activities that require SYSTEM context. These include per-session temporary folders, RD themes, and RD certificates.
@winlangdb.dll,-1121 : English (United States)
@%systemroot%\system32\rasauto.dll,-200 : Remote Access Auto Connection Manager
@%systemroot%\system32\wbengine.exe,-105 : The WBENGINE service is used by Windows Backup to perform backup and recovery operations. If this service is stopped by a user, it may cause the currently running backup or recovery operation to fail. Disabling this service may disable backup and recovery operations using Windows Backup on this computer.
@c:\programdata\microsoft\windows defender\platform\4.18.25080.5-0\mpasdesc.dll,-245 : Microsoft Defender Core Service
@%systemroot%\system32\mprdim.dll,-201 : Offers routing services to businesses in local area and wide area network environments.
@%systemroot%\system32\defragsvc.dll,-101 : Optimize drives
@c:\programdata\microsoft\windows defender\platform\4.18.25090.3009-0\mpasdesc.dll,-242 : Helps guard against intrusion attempts targeting known and newly discovered vulnerabilities in network protocols
@wifidisplay.dll,-100 : Wireless Display
@%systemroot%\system32\p9rdrservice.dll,-102 : P9RdrService
@%systemroot%\system32\presentationhost.exe,-3310 : Optimizes performance of Windows Presentation Foundation (WPF) applications by caching commonly used font data. WPF applications will start this service if it is not already running. It can be disabled, though doing so will degrade the performance of WPF applications.
@%systemroot%\system32\mprmsg.dll,-32001 : Remote Access NDIS TAPI Driver
@%systemroot%\system32\fxsresm.dll,-122 : Enables you to send and receive faxes, utilizing fax resources available on this computer or on the network.
@%systemroot%\system32\fveui.dll,-844 : BitLocker Data Recovery Agent
@%systemroot%\system32\drivers\mssecflt.sys,-1001 : Microsoft Security Events Component Minifilter
@%systemroot%\system32\icsvc.dll,-801 : Hyper-V Guest Service Interface
@%systemroot%\system32\diagsvcs\diagnosticshub.standardcollector.serviceres.dll,-1000 : Microsoft (R) Diagnostics Hub Standard Collector Service
@%systemroot%\system32\wsmsvc.dll,-101 : Windows Remote Management (WS-Management)
@%systemroot%\system32\ssdpsrv.dll,-100 : SSDP Discovery
@%systemroot%\system32\drivers\indirectkmd.sys,-100 : Indirect Displays Kernel-Mode Driver
@%systemroot%\system32\pnrpsvc.dll,-8005 : Provides identity services for the Peer Name Resolution Protocol (PNRP) and Peer-to-Peer Grouping services. If disabled, the Peer Name Resolution Protocol (PNRP) and Peer-to-Peer Grouping services may not function, and some applications, such as HomeGroup and Remote Assistance, may not function correctly.
@c:\windows\system32\spool\drivers\x64\3\printconfig.dll,-1 : Printer Extensions and Notifications
@%systemroot%\system32\icsvcvss.dll,-101 : Hyper-V Volume Shadow Copy Requestor
@%systemroot%\system32\icsvc.dll,-700 : Virtual Machine Monitoring
@c:\programdata\microsoft\windows defender\platform\4.18.25110.5-0\mpasdesc.dll,-242 : Helps guard against intrusion attempts targeting known and newly discovered vulnerabilities in network protocols
@%systemroot%\system32\vssvc.exe,-101 : Manages and implements Volume Shadow Copies used for backup and other purposes. If this service is stopped, shadow copies will be unavailable for backup and the backup may fail. If this service is disabled, any services that explicitly depend on it will fail to start.
@c:\programdata\microsoft\windows defender\platform\4.18.25100.9008-0\mpasdesc.dll,-400 : Microsoft Defender Antivirus Boot Driver
@%systemroot%\system32\peerdistsvc.dll,-9001 : This service caches network content from peers on the local subnet.
@%systemroot%\system32\storsvc.dll,-101 : Provides enabling services for storage settings and external storage expansion
@%systemroot%\system32\credentialenrollmentmanager.exe,-100 : CredentialEnrollmentManagerUserSvc
@%systemroot%\system32\lpasvc.dll,-1000 : Local Profile Assistant Service
@%systemroot%\system32\captureservice.dll,-100 : CaptureService
@%systemroot%\system32\webclnt.dll,-104 : WebDav Client Redirector Driver
@%systemroot%\system32\webclnt.dll,-100 : WebClient
@%systemroot%\system32\smphost.dll,-102 : Microsoft Storage Spaces SMP
@%windir%\system32\inetsrv\iisres.dll,-30007 : IIS Admin Service
@%systemroot%\system32\drivers\netbt.sys,-2 : NETBT
@%systemroot%\system32\drivers\fileinfo.sys,-100 : File Information FS MiniFilter
@%systemroot%\system32\drivers\wcifs.sys,-100 : Windows Container Isolation
@%systemroot%\system32\drivers\ahcache.sys,-102 : Application Compatibility Cache
@%systemroot%\system32\axinstsv.dll,-104 : Provides User Account Control validation for the installation of ActiveX controls from the Internet and enables management of ActiveX control installation based on Group Policy settings. This service is started on demand and if disabled the installation of ActiveX controls will behave according to default browser settings.
@%systemroot%\system32\windows.internal.management.dll,-100 : Device Management Enrollment Service
@%systemroot%\system32\languageoverlayserver.dll,-100 : Language Experience Service
@enterpriseappmgmtsvc.dll,-2 : Enables enterprise application management.
@winlangdb.dll,-1114 : English (India)
@c:\programdata\microsoft\windows defender\platform\4.18.25080.5-0\mpasdesc.dll,-320 : Microsoft Defender Antivirus Network Inspection Service
@%systemroot%\system32\firewallapi.dll,-38529 : Secure World Wide Web Services (QUIC)
@%systemroot%\system32\wercplsupport.dll,-101 : Problem Reports Control Panel Support
@%systemroot%\system32\srpapi.dll,-102 : Smartlocker Filter Driver
@%systemroot%\system32\netsetupsvc.dll,-3 : Network Setup Service
@%systemroot%\system32\webclnt.dll,-101 : Enables Windows-based programs to create, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\fodhelper.exe,-100 : Optional Features
@%systemroot%\system32\windows.management.service.dll,-100 : Windows Management Service
@%systemroot%\system32\cscsvc.dll,-201 : The Offline Files service performs maintenance activities on the Offline Files cache, responds to user logon and logoff events, implements the internals of the public API, and dispatches interesting events to those interested in Offline Files activities and changes in cache state.
@%systemroot%\system32\userdataaccessres.dll,-15001 : Contact Data
@%systemroot%\system32\tabsvc.dll,-101 : Enables Touch Keyboard and Handwriting Panel pen and ink functionality
@%systemroot%\system32\powrprof.dll,-14 : Automatically balances performance with energy consumption on capable hardware.
@%systemroot%\system32\frameservermonitor.dll,-100 : Windows Camera Frame Server Monitor
@%systemroot%\system32\wkssvc.dll,-2001 : Browser
@%systemroot%\system32\ngcsvc.dll,-101 : Provides process isolation for cryptographic keys used to authenticate to a user’s associated identity providers. If this service is disabled, all uses and management of these keys will not be available, which includes machine logon and single-sign on for apps and websites. This service starts and stops automatically. It is recommended that you do not reconfigure this service.
@%systemroot%\system32\wlansvc.dll,-258 : The WLANSVC service provides the logic required to configure, discover, connect to, and disconnect from a wireless local area network (WLAN) as defined by IEEE 802.11 standards. It also contains the logic to turn your computer into a software access point so that other devices or computers can connect to your computer wirelessly using a WLAN adapter that can support this. Stopping or disabling the WLANSVC service will make all WLAN adapters on your computer inaccessible from the Windows networking UI. It is strongly recommended that you have the WLANSVC service running if your computer has a WLAN adapter.
@%systemroot%\system32\wbem\wmisvc.dll,-205 : Windows Management Instrumentation
@%systemroot%\system32\walletservice.dll,-1001 : Hosts objects used by clients of the wallet
@%systemroot%\system32\icsvc.dll,-102 : Monitors the state of this virtual machine by reporting a heartbeat at regular intervals. This service helps you identify running virtual machines that have stopped responding.
@%systemroot%\system32\cbdhsvc.dll,-101 : This user service is used for Clipboard scenarios
@%systemroot%\system32\dnsapi.dll,-103 : Domain Name System (DNS) Server Trust
@%systemroot%\system32\icsvc.dll,-401 : Hyper-V Time Synchronization Service
@c:\programdata\microsoft\windows defender\platform\4.18.25100.9008-0\mpasdesc.dll,-370 : Microsoft Defender Antivirus Network Inspection System Driver
@%systemroot%\system32\wbiosrvc.dll,-101 : The Windows biometric service gives client applications the ability to capture, compare, manipulate, and store biometric data without gaining direct access to any biometric hardware or samples. The service is hosted in a privileged SVCHOST process.
@%systemroot%\system32\firewallapi.dll,-53500 : Recommended Troubleshooting
@%systemroot%\system32\appinfo.dll,-101 : Facilitates the running of interactive applications with additional administrative privileges. If this service is stopped, users will be unable to launch applications with the additional administrative privileges they may require to perform desired user tasks.
@%systemroot%\system32\firewallapi.dll,-11199 : Message Queuing
@%systemroot%\system32\srvsvc.dll,-104 : Server SMB 2.xxx Driver
@%systemroot%\system32\searchindexer.exe,-104 : Provides content indexing, property caching, and search results for files, e-mail, and other content.
@%systemroot%\system32\msimsg.dll,-32 : Adds, modifies, and removes applications provided as a Windows Installer (*.msi, *.msp) package. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\coremessaging.dll,-2 : Manages communication between system components.
@%systemroot%\system32\drivers\bam.sys,-100 : Background Activity Moderator Driver
@%systemroot%\system32\mprmsg.dll,-32002 : Remote Access NDIS WAN Driver
@%systemroot%\system32\bcastdvruserservice.dll,-100 : GameDVR and Broadcast User Service
@%systemroot%\system32\umrdp.dll,-1001 : Allows the redirection of Printers/Drives/Ports for RDP connections
@%systemroot%\system32\sensordataservice.exe,-102 : Delivers data from a variety of sensors
@%systemroot%\system32\icsvc.dll,-902 : Provides a mechanism to manage virtual machine with PowerShell via VM session without a virtual network.
@%systemroot%\system32\drivers\wfplwfs.sys,-6000 : Microsoft Windows Filtering Platform
@%systemroot%\microsoft.net\framework64\v4.0.30319\aspnet_rc.dll,-2 : Provides support for out-of-process session states for ASP.NET. If this service is stopped, out-of-process requests will not be processed. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\efssvc.dll,-101 : Provides the core file encryption technology used to store encrypted files on NTFS file system volumes. If this service is stopped or disabled, applications will be unable to access encrypted files.
@%systemroot%\system32\appvclient.exe,-102 : Microsoft App-V Client
@c:\programdata\microsoft\windows defender\platform\4.18.25090.3009-0\mpasdesc.dll,-245 : Microsoft Defender Core Service
@%systemroot%\system32\flightsettings.dll,-103 : Windows Insider Service
@%systemroot%\system32\spectrum.exe,-102 : Enables spatial perception, spatial input, and holographic rendering.
@%systemroot%\system32\ncdautosetup.dll,-101 : Network Connected Devices Auto-Setup service monitors and installs qualified devices that connect to a qualified network. Stopping or disabling this service will prevent Windows from discovering and installing qualified network connected devices automatically. Users can still manually add network connected devices to a PC through the user interface.
@%systemroot%\system32\wwansvc.dll,-257 : WWAN AutoConfig
@%systemroot%\system32\wsmsvc.dll,-102 : Windows Remote Management (WinRM) service implements the WS-Management protocol for remote management. WS-Management is a standard web services protocol used for remote software and hardware management. The WinRM service listens on the network for WS-Management requests and processes them. The WinRM Service needs to be configured with a listener using winrm.cmd command line tool or through Group Policy in order for it to listen over the network. The WinRM service provides access to WMI data and enables event collection. Event collection and subscription to events require that the service is running. WinRM messages use HTTP and HTTPS as transports. The WinRM service does not depend on IIS but is preconfigured to share a port with IIS on the same machine. The WinRM service reserves the /wsman URL prefix. To prevent conflicts with IIS, administrators should ensure that any websites hosted on IIS do not use the /wsman URL prefix.
@%systemroot%\system32\mprmsg.dll,-32007 : Remote Access PPPOE Driver
@appmgmts.dll,-3251 : Processes installation, removal, and enumeration requests for software deployed through Group Policy. If the service is disabled, users will be unable to install, remove, or enumerate software deployed through Group Policy. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\ngcsvc.dll,-100 : Microsoft Passport
@%systemroot%\system32\wscsvc.dll,-201 : The WSCSVC (Windows Security Center) service monitors and reports security health settings on the computer. The health settings include firewall (on/off), antivirus (on/off/out of date), antispyware (on/off/out of date), Windows Update (automatically/manually download and install updates), User Account Control (on/off), and Internet settings (recommended/not recommended). The service provides COM APIs for independent software vendors to register and record the state of their products to the Security Center service. The Security and Maintenance UI uses the service to provide systray alerts and a graphical view of the security health states in the Security and Maintenance control panel. Network Access Protection (NAP) uses the service to report the security health states of clients to the NAP Network Policy Server to make network quarantine decisions. The service also has a public API that allows external consumers to programmatically retrieve the aggregated security health state of the system.
@%systemroot%\system32\sensorservice.dll,-1000 : Sensor Service
@%systemroot%\system32\tokenbroker.dll,-101 : This service is used by Web Account Manager to provide single-sign-on to apps and services.
@%systemroot%\system32\dps.dll,-500 : Diagnostic Policy Service
@%systemroot%\system32\sensordataservice.exe,-101 : Sensor Data Service
@%systemroot%\system32\printworkflowservice.dll,-100 : PrintWorkflow
@%systemroot%\system32\cdpsvc.dll,-101 : This service is used for Connected Devices Platform scenarios
@%systemroot%\system32\sppsvc.exe,-101 : Software Protection
@comres.dll,-2451 : Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\drivers\ndiscap.sys,-5000 : Microsoft NDIS Capture
@%systemroot%\system32\mitigationclient.dll,-103 : Recommended Troubleshooting Service
@%systemroot%\system32\ajrouter.dll,-1 : Routes AllJoyn messages for the local AllJoyn clients. If this service is stopped the AllJoyn clients that do not have their own bundled routers will be unable to run.
@%systemroot%\system32\wecsvc.dll,-201 : This service manages persistent subscriptions to events from remote sources that support WS-Management protocol. This includes Windows Vista event logs, hardware and IPMI-enabled event sources. The service stores forwarded events in a local Event Log. If this service is stopped or disabled event subscriptions cannot be created and forwarded events cannot be accepted.
@%systemroot%\system32\pushtoinstall.dll,-201 : Provides infrastructure support for the Microsoft Store. This service is started automatically and if disabled then remote installations will not function properly.
@keyiso.dll,-100 : CNG Key Isolation
@%systemroot%\system32\cscsvc.dll,-202 : Offline Files Driver
@%systemroot%\system32\icsvcext.dll,-601 : Hyper-V Remote Desktop Virtualization Service
@c:\programdata\microsoft\windows defender\platform\4.18.25110.6-0\mpasdesc.dll,-330 : Microsoft Defender Antivirus Mini-Filter Driver
@%systemroot%\system32\windowsudkservices.shellcommon.dll,-101 : Shell components service
@%windir%\system32\drivers\netbios.sys,-503 : NetBIOS Interface
@%systemroot%\system32\lmhsvc.dll,-102 : Provides support for the NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution for clients on the network, therefore enabling users to share files, print, and log on to the network. If this service is stopped, these functions might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\wbem\wmiapsrv.exe,-110 : WMI Performance Adapter
@c:\programdata\microsoft\windows defender\platform\4.18.25100.9008-0\mpasdesc.dll,-244 : Monitors the availability, health, and performance of various security components
@%systemroot%\system32\icsvc.dll,-901 : Hyper-V PowerShell Direct Service
c:\windows\system32,@elscore.dll,-3 : Microsoft Traditional Chinese to Simplified Chinese Transliteration
@%systemroot%\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8196 : Receives activation requests over the net.pipe protocol and passes them to the Windows Process Activation Service.
@%systemroot%\system32\umpnpmgr.dll,-101 : Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability.
@%systemroot%\system32\polstore.dll,-5011 : Internet Protocol security (IPsec) supports network-level peer authentication, data origin authentication, data integrity, data confidentiality (encryption), and replay protection. This service enforces IPsec policies created through the IP Security Policies snap-in or the command-line tool ""netsh ipsec"". If you stop this service, you may experience network connectivity issues if your policy requires that connections use IPsec. Also,remote management of Windows Defender Firewall is not available when this service is stopped.
@%systemroot%\system32\windows.sharedpc.accountmanager.dll,-100 : Shared PC Account Manager
@%systemroot%\system32\wpnuserservice.dll,-1 : Windows Push Notifications User Service
@%systemroot%\system32\windows.staterepository.dll,-2 : Provides required infrastructure support for the application model.
@%systemroot%\system32\winhttp.dll,-101 : WinHTTP implements the client HTTP stack and provides developers with a Win32 API and COM Automation component for sending HTTP requests and receiving responses. In addition, WinHTTP provides support for auto-discovering a proxy configuration via its implementation of the Web Proxy Auto-Discovery (WPAD) protocol.
@%systemroot%\system32\iscsidsc.dll,-5001 : Manages Internet SCSI (iSCSI) sessions from this computer to remote iSCSI target devices. If this service is stopped, this computer will not be able to login or access iSCSI targets. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\appidsvc.dll,-100 : Application Identity
@%systemroot%\system32\icsvc.dll,-402 : Synchronizes the system time of this virtual machine with the system time of the physical computer.
@%systemroot%\system32\drivers\mountmgr.sys,-100 : Mount Point Manager
@%systemroot%\system32\keyboardfiltersvc.dll,-102 : Controls keystroke filtering and mapping
@%systemroot%\system32\icsvc.dll,-302 : Provides a mechanism to shut down the operating system of this virtual machine from the management interfaces on the physical computer.
@%systemroot%\microsoft.net\framework64\v4.0.30319\aspnet_rc.dll,-1 : ASP.NET State Service
@%systemroot%\system32\hvhostsvc.dll,-101 : Provides an interface for the Hyper-V hypervisor to provide per-partition performance counters to the host operating system.
@%systemroot%\system32\icsvc.dll,-201 : Hyper-V Data Exchange Service
@%systemroot%\system32\dosvc.dll,-101 : Performs content delivery optimization tasks
@%systemroot%\system32\iphlpsvc.dll,-501 : Provides tunnel connectivity using IPv6 transition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS. If this service is stopped, the computer will not have the enhanced connectivity benefits that these technologies offer.
@c:\programdata\microsoft\windows defender\platform\4.18.25110.6-0\mpasdesc.dll,-340 : Microsoft Defender Antivirus On-Access Malware Protection Mini-Filter Driver
@%systemroot%\system32\pnrpsvc.dll,-8004 : Peer Networking Identity Manager
@%systemroot%\system32\cdpusersvc.dll,-100 : Connected Devices Platform User Service
@%systemroot%\system32\audiosrv.dll,-201 : Manages audio for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start
@%systemroot%\system32\shell32.dll,-50176 : File Operation
@%systemroot%\system32\xboxnetapisvc.dll,-100 : Xbox Live Networking Service
@%systemroot%\system32\samsrv.dll,-2 : The startup of this service signals other services that the Security Accounts Manager (SAM) is ready to accept requests. Disabling this service will prevent other services in the system from being notified when the SAM is ready, which may in turn cause those services to fail to start correctly. This service should not be disabled.
@%systemroot%\system32\bridgeres.dll,-1 : Microsoft MAC Bridge
@%systemroot%\system32\lpasvc.dll,-1001 : This service provides profile management for subscriber identity modules
@%systemroot%\system32\appidsvc.dll,-101 : Determines and verifies the identity of an application. Disabling this service will prevent AppLocker from being enforced.
@%systemroot%\system32\languageoverlayserver.dll,-101 : Provides infrastructure support for deploying and configuring localized Windows resources. This service is started on demand and, if disabled, additional Windows languages will not be deployed to the system, and Windows may not function properly.
@%systemroot%\system32\cdpusersvc.dll,-101 : This user service is used for Connected Devices Platform scenarios
@%systemroot%\system32\drivers\partmgr.sys,-100 : Partition driver
@%systemroot%\system32\wbiosrvc.dll,-100 : Windows Biometric Service
@%systemroot%\system32\ipxlatcfg.dll,-500 : IP Translation Configuration Service
@c:\windows\system32\ulib.dll,-1000 : Recovered File Fragments
@%systemroot%\system32\wdi.dll,-502 : Diagnostic Service Host
@%systemroot%\system32\pnrpsvc.dll,-8001 : Enables serverless peer name resolution over the Internet using the Peer Name Resolution Protocol (PNRP). If disabled, some peer-to-peer and collaborative applications, such as Remote Assistance, may not function.
@peerdistsh.dll,-9000 : BranchCache - Content Retrieval (Uses HTTP)
@c:\programdata\microsoft\windows defender\platform\4.18.25110.5-0\mpasdesc.dll,-320 : Microsoft Defender Antivirus Network Inspection Service
@%systemroot%\system32\appreadiness.dll,-1001 : Gets apps ready for use the first time a user signs in to this PC and when adding new apps.
@%systemroot%\system32\wephostsvc.dll,-100 : Windows Encryption Provider Host Service
c:\windows\system32,@elscore.dll,-10 : Microsoft Hangul Decomposition Transliteration
@c:\programdata\microsoft\windows defender\platform\4.18.25100.9008-0\mpasdesc.dll,-242 : Helps guard against intrusion attempts targeting known and newly discovered vulnerabilities in network protocols
@%systemroot%\system32\audioendpointbuilder.dll,-205 : Manages audio devices for the Windows Audio service. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start
@%systemroot%\system32\mprmsg.dll,-32013 : IP Traffic Filter Driver
@c:\programdata\microsoft\windows defender\platform\4.18.25080.5-0\mpasdesc.dll,-244 : Monitors the availability, health, and performance of various security components
@%systemroot%\system32\firewallapi.dll,-23091 : Windows Defender Firewall helps protect your computer by preventing unauthorized users from gaining access to your computer through the Internet or a network.
@%systemroot%\system32\cbdhsvc.dll,-100 : Clipboard User Service
@%systemroot%\system32\ikeext.dll,-502 : The IKEEXT service hosts the Internet Key Exchange (IKE) and Authenticated Internet Protocol (AuthIP) keying modules. These keying modules are used for authentication and key exchange in Internet Protocol security (IPsec). Stopping or disabling the IKEEXT service will disable IKE and AuthIP key exchange with peer computers. IPsec is typically configured to use IKE or AuthIP; therefore, stopping or disabling the IKEEXT service might result in an IPsec failure and might compromise the security of the system. It is strongly recommended that you have the IKEEXT service running.
@%systemroot%\system32\dcsvc.dll,-101 : Declared Configuration(DC) service
@%programfiles%\windows defender advanced threat protection\mssense.exe,-1002 : Windows Defender Advanced Threat Protection service helps protect against advanced threats by monitoring and reporting security events that happen on the computer.
@%systemroot%\system32\frameservermonitor.dll,-101 : Monitors the health and state for the Windows Camera Frame Server service.
@%systemroot%\syswow64\perfhost.exe,-2 : Performance Counter DLL Host
@%systemroot%\system32\moshost.dll,-100 : Downloaded Maps Manager
@c:\programdata\microsoft\windows defender\platform\4.18.25100.9008-0\mpasdesc.dll,-390 : Microsoft Defender Antivirus Boot Driver
@%systemroot%\system32\wephostsvc.dll,-101 : Windows Encryption Provider Host Service brokers encryption related functionalities from 3rd Party Encryption Providers to processes that need to evaluate and apply EAS policies. Stopping this will compromise EAS compliancy checks that have been established by the connected Mail Accounts
@%systemroot%\system32\upnphost.dll,-213 : UPnP Device Host
@%systemroot%\system32\nsisvc.dll,-201 : This service delivers network notifications (e.g. interface addition/deleting etc) to user mode clients. Stopping this service will cause loss of network connectivity. If this service is disabled, any other services that explicitly depend on this service will fail to start.
@%systemroot%\system32\drivers\luafv.sys,-100 : UAC File Virtualization
@%systemroot%\system32\pushtoinstall.dll,-200 : Windows PushToInstall Service
@%systemroot%\system32\mprmsg.dll,-32000 : RAS Asynchronous Media Driver
@%systemroot%\system32\netsetupsvc.dll,-4 : The Network Setup Service manages the installation of network drivers and permits the configuration of low-level network settings. If this service is stopped, any driver installations that are in-progress may be cancelled.
@%systemroot%\system32\semgrsvc.dll,-1002 : Manages payments and Near Field Communication (NFC) based secure elements.
@%systemroot%\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8198 : Receives activation requests over the net.tcp protocol and passes them to the Windows Process Activation Service.
@%systemroot%\system32\dialogblockingservice.dll,-100 : DialogBlockingService
@%systemroot%\system32\smsroutersvc.dll,-10001 : Microsoft Windows SMS Router Service.
@%systemroot%\system32\wersvc.dll,-100 : Windows Error Reporting Service
@%systemroot%\system32\securityhealthagent.dll,-1002 : Windows Security Service
@%systemroot%\system32\wuaueng.dll,-106 : Enables the detection, download, and installation of updates for Windows and other programs. If this service is disabled, users of this computer will not be able to use Windows Update or its automatic updating feature, and programs will not be able to use the Windows Update Agent (WUA) API.
@%systemroot%\system32\ncasvc.dll,-3009 : Network Connectivity Assistant
@regsvc.dll,-1 : Remote Registry
@%systemroot%\system32\microsoft.graphics.display.displayenhancementservice.dll,-1000 : Display Enhancement Service
@%systemroot%\system32\appreadiness.dll,-1000 : App Readiness
@wlansvc.dll,-36865 : WLAN Service - WFD Services Kernel Mode Driver Rules
@%systemroot%\system32\drivers\executioncontext.sys,-101 : CPU Scheduler for High Performance I/O
@%systemroot%\system32\cryptsvc.dll,-1002 : Provides three management services: Catalog Database Service, which confirms the signatures of Windows files and allows new programs to be installed; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Automatic Root Certificate Update Service, which retrieves root certificates from Windows Update and enable scenarios such as SSL. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\umpo.dll,-101 : Manages power policy and power policy notification delivery.
@%systemroot%\system32\p2psvc.dll,-8007 : Enables multi-party communication using Peer-to-Peer Grouping. If disabled, some applications, such as HomeGroup, may not function.
@%systemroot%\system32\vds.exe,-100 : Virtual Disk
@%systemroot%\system32\drivers\filecrypt.sys,-100 : FileCrypt
@appmgmts.dll,-3250 : Application Management
@%systemroot%\system32\powrprof.dll,-13 : High performance
@c:\programdata\microsoft\windows defender\platform\4.18.25110.6-0\mpasdesc.dll,-320 : Microsoft Defender Antivirus Network Inspection Service
@enterpriseappmgmtsvc.dll,-1 : Enterprise App Management Service
@c:\programdata\microsoft\windows defender\platform\4.18.25090.3009-0\mpasdesc.dll,-320 : Microsoft Defender Antivirus Network Inspection Service
@%systemroot%\system32\icsvc.dll,-802 : Provides an interface for the Hyper-V host to interact with specific services running inside the virtual machine.
@%systemroot%\system32\fxsresm.dll,-118 : Fax
@%systemroot%\system32\wiarpc.dll,-1 : Launches applications associated with still image acquisition events.
@c:\programdata\microsoft\windows defender\platform\4.18.25110.5-0\mpasdesc.dll,-370 : Microsoft Defender Antivirus Network Inspection System Driver
@%systemroot%\system32\semgrsvc.dll,-1001 : Payments and NFC/SE Manager
@%systemroot%\system32\sharedrealitysvc.dll,-100 : Spatial Data Service
@%systemroot%\system32\graphicsperfsvc.dll,-100 : GraphicsPerfSvc
@%systemroot%\system32\drivers\fvevol.sys,-100 : BitLocker Drive Encryption Filter Driver
@%systemroot%\system32\mixedrealityruntime.dll,-102 : Enables Mixed Reality OpenXR runtime functionality
@%systemroot%\system32\drivers\mssecwfp.sys,-1001 : Microsoft Security WFP Callout Driver
@%systemroot%\system32\lfsvc.dll,-1 : Geolocation Service
@firewallapi.dll,-50324 : Receives trap messages generated by local or remote Simple Network Management Protocol (SNMP) agents and forwards the messages to SNMP management programs running on this computer. If this service is stopped, SNMP-based programs on this computer will not receive SNMP trap messages. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\drivers\mup.sys,-101 : MUP
@peerdistsh.dll,-9001 : BranchCache - Peer Discovery (Uses WSD)
@%systemroot%\system32\drivers\wimmount.sys,-101 : WIMMount
@%systemroot%\system32\aarsvc.dll,-100 : Agent Activation Runtime
@%systemroot%\system32\moshost.dll,-101 : Windows service for application access to downloaded maps. This service is started on-demand by application accessing downloaded maps. Disabling this service will prevent apps from accessing maps.
@%windir%\system32\inetsrv\iisres.dll,-30015 : Provides W3C logging for Internet Information Services (IIS). If this service is stopped, W3C logging configured by IIS will not work.
@%systemroot%\system32\drivers\vwififlt.sys,-259 : Virtual WiFi Filter Driver
@%systemroot%\system32\messagingservice.dll,-100 : MessagingService
@%systemroot%\system32\scardsvr.dll,-1 : Smart Card
@%systemroot%\system32\drivers\dam.sys,-100 : Desktop Activity Moderator Driver
@%systemroot%\system32\dps.dll,-501 : The Diagnostic Policy Service enables problem detection, troubleshooting and resolution for Windows components. If this service is stopped, diagnostics will no longer function.
@%windir%\system32\lsm.dll,-1002 : Core Windows Service that manages local user sessions. Stopping or disabling this service will result in system instability.
@%systemroot%\system32\deviceaccess.dll,-107 : DeviceAssociationBroker
@%systemroot%\system32\wwansvc.dll,-258 : This service manages mobile broadband (GSM & CDMA) data card/embedded module adapters and connections by auto-configuring the networks. It is strongly recommended that this service be kept running for best user experience of mobile broadband devices.
@%systemroot%\system32\cloudidsvc.dll,-101 : Supports integrations with Microsoft cloud identity services. If disabled, tenant restrictions will not be enforced properly.
@%systemroot%\system32\lltdres.dll,-1 : Link-Layer Topology Discovery Mapper
@%systemroot%\system32\btagservice.dll,-101 : Bluetooth Audio Gateway Service
@%systemroot%\system32\srpapi.dll,-100 : AppID Driver
@%systemroot%\system32\usermgr.dll,-101 : User Manager provides the runtime components required for multi-user interaction. If this service is stopped, some applications may not operate correctly.
@%systemroot%\system32\ajrouter.dll,-2 : AllJoyn Router Service
@%systemroot%\system32\wecsvc.dll,-200 : Windows Event Collector
@%systemroot%\system32\dusmsvc.dll,-2 : Network data usage, data limit, restrict background data, metered networks.
@%systemroot%\system32\drivers\nsiproxy.sys,-2 : NSI Proxy Service Driver
@%systemroot%\system32\xboxgipsvc.dll,-100 : Xbox Accessory Management Service
@%systemroot%\system32\sens.dll,-201 : Monitors system events and notifies subscribers to COM+ Event System of these events.
@%systemroot%\system32\bthserv.dll,-102 : The Bluetooth service supports discovery and association of remote Bluetooth devices. Stopping or disabling this service may cause already installed Bluetooth devices to fail to operate properly and prevent new devices from being discovered or associated.
@%systemroot%\system32\drivers\tcpip.sys,-10001 : TCP/IP Protocol Driver
@%systemroot%\system32\ssdpsrv.dll,-101 : Discovers networked devices and services that use the SSDP discovery protocol, such as UPnP devices. Also announces SSDP devices and services running on the local computer. If this service is stopped, SSDP-based devices will not be discovered. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\vac.dll,-200 : Volumetric Audio Compositor Service
@%systemroot%\system32\aphostres.dll,-10001 : This service synchronizes mail, contacts, calendar and various other user data. Mail and other applications dependent on this functionality will not work properly when this service is not running.
@%systemroot%\system32\drivers\mmcss.sys,-100 : Multimedia Class Scheduler
@%systemroot%\system32\tzautoupdate.dll,-200 : Auto Time Zone Updater
@%systemroot%\system32\profsvc.dll,-301 : This service is responsible for loading and unloading user profiles. If this service is stopped or disabled, users will no longer be able to successfully sign in or sign out, apps might have problems getting to users' data, and components registered to receive profile event notifications won't receive them.
@%systemroot%\system32\vaultsvc.dll,-1003 : Credential Manager
@%systemroot%\system32\certprop.dll,-13 : Smart Card Removal Policy
@comres.dll,-948 : Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\seclogon.dll,-7000 : Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\mprmsg.dll,-32014 : Remote Access LEGACY NDIS WAN Driver
@%systemroot%\system32\devicesflowbroker.dll,-104 : Allows ConnectUX and PC Settings to Connect and Pair with WiFi displays and Bluetooth devices.
@%systemroot%\system32\vac.dll,-201 : Hosts spatial analysis for Mixed Reality audio simulation.
@%systemroot%\system32\fhsvc.dll,-102 : Protects user files from accidental loss by copying them to a backup location
@waasmedicsvc.dll,-101 : Enables remediation and protection of Windows Update components.
@%systemroot%\system32\wbem\wmisvc.dll,-204 : Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\bdesvc.dll,-101 : BDESVC hosts the BitLocker Drive Encryption service. BitLocker Drive Encryption provides secure startup for the operating system, as well as full volume encryption for OS, fixed or removable volumes. This service allows BitLocker to prompt users for various actions related to their volumes when mounted, and unlocks volumes automatically without user interaction. Additionally, it stores recovery information to Active Directory, if available, and, if necessary, ensures the most recent recovery certificates are used. Stopping or disabling the service would prevent users from leveraging this functionality.
@%systemroot%\system32\firewallapi.dll,-60501 : Cloud Identity
@%systemroot%\system32\btagservice.dll,-102 : Service supporting the audio gateway role of the Bluetooth Handsfree Profile.
@%systemroot%\system32\perceptionsimulation\perceptionsimulationservice.exe,-102 : Enables spatial perception simulation, virtual camera management and spatial input simulation.
@%systemroot%\system32\sppsvc.exe,-100 : Enables the download, installation and enforcement of digital licenses for Windows and Windows applications. If the service is disabled, the operating system and licensed applications may run in a notification mode. It is strongly recommended that you not disable the Software Protection service.
@%systemroot%\system32\vaultsvc.dll,-1004 : Provides secure storage and retrieval of credentials to users, applications and security service packages.
@%systemroot%\system32\vssvc.exe,-102 : Volume Shadow Copy
@%systemroot%\system32\icsvc.dll,-101 : Hyper-V Heartbeat Service
@%systemroot%\system32\pnrpauto.dll,-8002 : PNRP Machine Name Publication Service
@%systemroot%\system32\perceptionsimulation\perceptionsimulationservice.exe,-101 : Windows Perception Simulation Service
@%systemroot%\system32\fveui.dll,-843 : BitLocker Drive Encryption
@%systemroot%\system32\tapisrv.dll,-10101 : Provides Telephony API (TAPI) support for programs that control telephony devices on the local computer and, through the LAN, on servers that are also running the service.
@%systemroot%\system32\licensemanagersvc.dll,-201 : Provides infrastructure support for the Microsoft Store. This service is started on demand and if disabled then content acquired through the Microsoft Store will not function properly.
@%systemroot%\system32\drivers\ehstorclass.sys,-100 : Enhanced Storage Filter Driver
@%systemroot%\system32\drivers\mslldp.sys,-200 : Microsoft Link-Layer Discovery Protocol
@%systemroot%\system32\frameserver.dll,-100 : Windows Camera Frame Server
@%systemroot%\system32\userdataaccessres.dll,-14000 : Provides apps access to structured user data, including contact info, calendars, messages, and other content. If you stop or disable this service, apps that use this data might not work correctly.
@%systemroot%\system32\wkssvc.dll,-1002 : SMB MiniRedirector Wrapper and Engine
@%systemroot%\system32\hidserv.dll,-102 : Activates and maintains the use of hot buttons on keyboards, remote controls, and other multimedia devices. It is recommended that you keep this service running.
@%systemroot%\system32\wbem\wmiapsrv.exe,-111 : Provides performance library information from Windows Management Instrumentation (WMI) providers to clients on the network. This service only runs when Performance Data Helper is activated.
@%systemroot%\system32\wuaueng.dll,-400 : Windows Update
@%programfiles%\windows media player\wmpnetwk.exe,-102 : Shares Windows Media Player libraries to other networked players and media devices using Universal Plug and Play
@%systemroot%\system32\drivers\ndisimplatform.sys,-501 : Microsoft Network Adapter Multiplexor Protocol
@c:\programdata\microsoft\windows defender\platform\4.18.25090.3009-0\mpasdesc.dll,-390 : Microsoft Defender Antivirus Boot Driver
@%systemroot%\system32\qwave.dll,-2 : Quality Windows Audio Video Experience (qWave) is a networking platform for Audio Video (AV) streaming applications on IP home networks. qWave enhances AV streaming performance and reliability by ensuring network quality-of-service (QoS) for AV applications. It provides mechanisms for admission control, run time monitoring and enforcement, application feedback, and traffic prioritization.
@c:\programdata\microsoft\windows defender\platform\4.18.25110.5-0\mpasdesc.dll,-310 : Microsoft Defender Antivirus Service
@%systemroot%\system32\userdataaccessres.dll,-15000 : Indexes contact data for fast contact searching. If you stop or disable this service, contacts might be missing from your search results.
@%systemroot%\system32\appinfo.dll,-100 : Application Information
@%systemroot%\system32\mixedrealityruntime.dll,-101 : Windows Mixed Reality OpenXR Service
@comres.dll,-2797 : Distributed Transaction Coordinator
@%systemroot%\system32\spoolsv.exe,-2 : This service spools print jobs and handles interaction with the printer. If you turn off this service, you won’t be able to print or see your printers.
@%systemroot%\system32\drivers\mpsdrv.sys,-23092 : Windows Defender Firewall Authorization Driver
@%systemroot%\system32\userdataaccessres.dll,-14001 : User Data Access
@%systemroot%\system32\themeservice.dll,-8193 : Provides user experience theme management.
@%systemroot%\system32\dispbroker.desktop.dll,-102 : Manages the connection and configuration of local and remote displays
@%windir%\system32\timebrokerserver.dll,-1002 : Coordinates execution of background work for WinRT application. If this service is stopped or disabled, then background work might not be triggered.
@%systemroot%\system32\wlansvc.dll,-257 : WLAN AutoConfig
@%systemroot%\system32\fdphost.dll,-101 : The FDPHOST service hosts the Function Discovery (FD) network discovery providers. These FD providers supply network discovery services for the Simple Services Discovery Protocol (SSDP) and Web Services – Discovery (WS-D) protocol. Stopping or disabling the FDPHOST service will disable network discovery for these protocols when using FD. When this service is unavailable, network services using FD and relying on these discovery protocols will be unable to find network devices or resources.
@%systemroot%\system32\firewallapi.dll,-38521 : World Wide Web Services (HTTP)
@%systemroot%\system32\drivers\ndproxy.sys,-6000 : NDIS Proxy Driver
@%systemroot%\system32\drivers\qwavedrv.sys,-1 : QWAVE driver
@%systemroot%\system32\svsvc.dll,-101 : Spot Verifier
@%systemroot%\system32\diagsvc.dll,-101 : Executes diagnostic actions for troubleshooting support
@%systemroot%\system32\agentservice.exe,-102 : User Experience Virtualization Service
@%systemroot%\system32\cryptsvc.dll,-1001 : Cryptographic Services
@%systemroot%\system32\wfdsconmgrsvc.dll,-9000 : Wi-Fi Direct Services Connection Manager Service
@%systemroot%\system32\mprmsg.dll,-32011 : Remote Access IP ARP Driver
@%systemroot%\system32\devquerybroker.dll,-101 : Enables apps to discover devices with a backgroud task
@%systemroot%\system32\licensemanagersvc.dll,-200 : Windows License Manager Service
@%systemroot%\system32\xblauthmanager.dll,-100 : Xbox Live Auth Manager
@%systemroot%\system32\netprofmsvc.dll,-209 : Collects and stores configuration information for the network and notifies programs when this information is modified. If this service is stopped, configuration information might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\sharedrealitysvc.dll,-101 : This service is used for Spatial Perception scenarios
@%systemroot%\system32\drivers\verifierext.sys,-1000 : Driver Verifier Extension
@%systemroot%\system32\devicesflowbroker.dll,-103 : DevicesFlow
@%systemroot%\system32\wkssvc.dll,-101 : Creates and maintains client network connections to remote servers using the SMB protocol. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\dssvc.dll,-10002 : Provides data brokering between applications.
@%systemroot%\system32\credentialenrollmentmanager.exe,-101 : Credential Enrollment Manager
@%systemroot%\system32\pcasvc.dll,-2 : This service provides support for the Program Compatibility Assistant (PCA). PCA monitors programs installed and run by the user and detects known compatibility problems. If this service is stopped, PCA will not function properly.
@c:\programdata\microsoft\windows defender\platform\4.18.25100.9008-0\mpasdesc.dll,-240 : Helps protect users from malware and other potentially unwanted software
@%systemroot%\system32\dnsapi.dll,-102 : The DNS Client service (dnscache) caches Domain Name System (DNS) names and registers the full computer name for this computer. If the service is stopped, DNS names will continue to be resolved. However, the results of DNS name queries will not be cached and the computer's name will not be registered. If the service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\wkssvc.dll,-1006 : SMB 2.0 MiniRedirector
@%windir%\system32\inetsrv\iisres.dll,-30012 : Provides administrative services for IIS, for example configuration history and Application Pool account mapping. If this service is stopped, configuration history and locking down files or directories with Application Pool specific Access Control Entries will not work.
@%systemroot%\system32\powrprof.dll,-10 : Saves energy by reducing your computer's performance where possible.
@%systemroot%\system32\fhsvc.dll,-101 : File History Service
@%systemroot%\system32\lfsvc.dll,-2 : This service monitors the current location of the system and manages geofences (a geographical location with associated events). If you turn off this service, applications will be unable to use or receive notifications for geolocation or geofences.
@%systemroot%\system32\flightsettings.dll,-104 : Provides infrastructure support for the Windows Insider Program. This service must remain enabled for the Windows Insider Program to work.
@%systemroot%\system32\workfolderssvc.dll,-102 : Work Folders
@%systemroot%\system32\drivers\tunnel.sys,-500 : Microsoft Tunnel Miniport Adapter Driver
@%systemroot%\system32\tieringengineservice.exe,-702 : Storage Tiers Management
@%systemroot%\system32\dhcpcore.dll,-101 : Registers and updates IP addresses and DNS records for this computer. If this service is stopped, this computer will not receive dynamic IP addresses and DNS updates. If this service is disabled, any services that explicitly depend on it will fail to start.
@regsvc.dll,-2 : Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\qmgr.dll,-1000 : Background Intelligent Transfer Service
@c:\programdata\microsoft\windows defender\platform\4.18.25080.5-0\mpasdesc.dll,-370 : Microsoft Defender Antivirus Network Inspection System Driver
@%systemroot%\system32\clipsvc.dll,-103 : Client License Service (ClipSVC)
@c:\programdata\microsoft\windows defender\platform\4.18.25110.5-0\mpasdesc.dll,-340 : Microsoft Defender Antivirus On-Access Malware Protection Mini-Filter Driver
@%systemroot%\system32\xblgamesave.dll,-100 : Xbox Live Game Save
@%systemroot%\system32\fntcache.dll,-101 : Optimizes performance of applications by caching commonly used font data. Applications will start this service if it is not already running. It can be disabled, though doing so will degrade application performance.
@%systemroot%\system32\hvhostsvc.dll,-100 : HV Host Service
@%systemroot%\system32\sdrsvc.dll,-107 : Windows Backup
@%systemroot%\system32\locator.exe,-2 : Remote Procedure Call (RPC) Locator
@%systemroot%\system32\messagingservice.dll,-101 : Service supporting text messaging and related functionality.
@%systemroot%\system32\firewallapi.dll,-38523 : Secure World Wide Web Services (HTTPS)
@%systemroot%\system32\ipxlatcfg.dll,-501 : Configures and enables translation from v4 to v6 and vice versa
@%systemroot%\system32\drivers\volsnap.sys,-100 : Volume Shadow Copy driver
@%systemroot%\system32\wpnservice.dll,-1 : Windows Push Notifications System Service
@%systemroot%\system32\dssvc.dll,-10003 : Data Sharing Service
@%systemroot%\system32\sensrsvc.dll,-1000 : Sensor Monitoring Service
@%systemroot%\system32\seclogon.dll,-7001 : Secondary Logon
@%systemroot%\system32\wpnuserservice.dll,-2 : This service hosts Windows notification platform which provides support for local and push notifications. Supported notifications are tile, toast and raw.
@%systemroot%\system32\windows.internal.management.dll,-101 : Performs Device Enrollment Activities for Device Management
@%systemroot%\system32\drivers\iorate.sys,-101 : Disk I/O Rate Filter Driver
@%systemroot%\system32\shsvcs.dll,-12289 : Provides notifications for AutoPlay hardware events.
@%systemroot%\system32\netman.dll,-109 : Network Connections
@%systemroot%\system32\drivers\filetrace.sys,-10001 : FileTrace
@%systemroot%\system32\devicesetupmanager.dll,-1001 : Enables the detection, download and installation of device-related software. If this service is disabled, devices may be configured with outdated software, and may not work correctly.
@%systemroot%\system32\wersvc.dll,-101 : Allows errors to be reported when programs stop working or responding and allows existing solutions to be delivered. Also allows logs to be generated for diagnostic and repair services. If this service is stopped, error reporting might not work correctly and results of diagnostic services and repairs might not be displayed.
@%systemroot%\system32\dosvc.dll,-100 : Delivery Optimization
@%systemroot%\system32\storsvc.dll,-100 : Storage Service
@%systemroot%\system32\smsroutersvc.dll,-10002 : Routes messages based on rules to appropriate clients.
@%systemroot%\system32\windowsudkservices.shellcommon.dll,-100 : Udk User Service
@%systemroot%\system32\drivers\wpdupfltr.sys,-100 : WPD Upper Class Filter Driver
@combase.dll,-5013 : The DCOMLAUNCH service launches COM and DCOM servers in response to object activation requests. If this service is stopped or disabled, programs using COM or DCOM will not function properly. It is strongly recommended that you have the DCOMLAUNCH service running.
@%systemroot%\system32\axinstsv.dll,-103 : ActiveX Installer (AxInstSV)
@%systemroot%\system32\appxdeploymentserver.dll,-1 : AppX Deployment Service (AppXSVC)
@%windir%\system32\inetsrv\iisres.dll,-30014 : W3C Logging Service
@%systemroot%\system32\smphost.dll,-101 : Host service for the Microsoft Storage Spaces management provider. If this service is stopped or disabled, Storage Spaces cannot be managed.
@%systemroot%\system32\wlidsvc.dll,-100 : Microsoft Account Sign-in Assistant
@%systemroot%\system32\wcncsvc.dll,-3 : Windows Connect Now - Config Registrar
@%systemroot%\system32\efssvc.dll,-100 : Encrypting File System (EFS)
@%windir%\system32\drivers\pacer.sys,-101 : QoS Packet Scheduler
@%windir%\system32\inetsrv\iisres.dll,-30002 : The Windows Process Activation Service (WAS) provides process activation, resource management and health management services for message-activated applications.
@%systemroot%\system32\lltdres.dll,-6 : Link-Layer Topology Discovery Mapper I/O Driver
@%systemroot%\system32\drivers\rdpdr.sys,-100 : Remote Desktop Device Redirector Driver
@%systemroot%\system32\aphostres.dll,-10002 : Sync Host
@c:\windows\system32\rdpendp.dll,-1001 : Remote Audio
@%systemroot%\system32\devicesetupmanager.dll,-1000 : Device Setup Manager
@c:\programdata\microsoft\windows defender\platform\4.18.25090.3009-0\mpasdesc.dll,-240 : Helps protect users from malware and other potentially unwanted software
@%systemroot%\system32\workfolderssvc.dll,-101 : This service syncs files with the Work Folders server, enabling you to use the files on any of the PCs and devices on which you've set up Work Folders.
@%systemroot%\system32\ci.dll,-100 : Isolated User Mode (IUM)
@%systemroot%\system32\wscsvc.dll,-200 : Security Center
@%systemroot%\system32\consentuxclient.dll,-101 : Allows the system to request user consent to allow apps to access sensitive resources and information such as the device's location
@%systemroot%\system32\qwave.dll,-1 : Quality Windows Audio Video Experience
@%systemroot%\system32\cloudidsvc.dll,-100 : Microsoft Cloud Identity Service
@%systemroot%\system32\wiarpc.dll,-2 : Still Image Acquisition Events
@c:\programdata\microsoft\windows defender\platform\4.18.25080.5-0\mpasdesc.dll,-240 : Helps protect users from malware and other potentially unwanted software
@%systemroot%\system32\xboxgipsvc.dll,-101 : This service manages connected Xbox Accessories.
@peerdistsh.dll,-9002 : BranchCache - Hosted Cache Server (Uses HTTPS)
@%systemroot%\system32\powrprof.dll,-12 : Favors performance, but may use more energy.
@%systemroot%\system32\tapisrv.dll,-10100 : Telephony
@%systemroot%\system32\drivers\winnat.sys,-10001 : Windows NAT Driver
@c:\programdata\microsoft\windows defender\platform\4.18.25100.9008-0\mpasdesc.dll,-340 : Microsoft Defender Antivirus On-Access Malware Protection Mini-Filter Driver
@%systemroot%\system32\drivers\appvstrm.sys,-101 : AppvStrm
@%systemroot%\system32\wpcrefreshtask.dll,-100 : Parental Controls
@%systemroot%\system32\p9rdrservice.dll,-101 : Enables trigger-starting plan9 file servers.
@%systemroot%\system32\wpnservice.dll,-2 : This service runs in session 0 and hosts the notification platform and connection provider which handles the connection between the device and WNS server.
@%systemroot%\system32\p2psvc.dll,-8006 : Peer Networking Grouping
@%systemroot%\system32\sensorservice.dll,-1001 : A service for sensors that manages different sensors' functionality. Manages Simple Device Orientation (SDO) and History for sensors. Loads the SDO sensor that reports device orientation changes. If this service is stopped or disabled, the SDO sensor will not be loaded and so auto-rotation will not occur. History collection from Sensors will also be stopped.
@%systemroot%\system32\drivers\scfilter.sys,-11 : Smart card PnP Class Filter Driver
@%systemroot%\system32\sysmain.dll,-1001 : Maintains and improves system performance over time.
@%systemroot%\system32\diagsvcs\diagnosticshub.standardcollector.serviceres.dll,-1001 : Diagnostics Hub Standard Collector Service. When running, this service collects real time ETW events and processes them.
@%systemroot%\system32\assignedaccessmanagersvc.dll,-100 : AssignedAccessManager Service
@%systemroot%\system32\graphicsperfsvc.dll,-101 : Graphics performance monitor service
@%systemroot%\system32\fdphost.dll,-100 : Function Discovery Provider Host
@c:\programdata\microsoft\windows defender\platform\4.18.25110.6-0\mpasdesc.dll,-310 : Microsoft Defender Antivirus Service
@%systemroot%\system32\frameserver.dll,-101 : Enables multiple clients to access video frames from camera devices.
@%systemroot%\system32\ncbservice.dll,-501 : Brokers connections that allow Windows Store Apps to receive notifications from the internet.
@%systemroot%\system32\walletservice.dll,-1000 : WalletService
@%systemroot%\system32\penservice.dll,-100 : PenService
@%systemroot%\system32\netlogon.dll,-102 : Netlogon
@%systemroot%\system32\phoneserviceres.dll,-10001 : Manages the telephony state on the device
@%systemroot%\system32\dialogblockingservice.dll,-101 : Dialog Blocking Service
@%systemroot%\system32\ngcrecovery.dll,-100 : Windows Hello Recovery Key Encryption
@%systemroot%\system32\umpnpmgr.dll,-100 : Device Install Service
@%systemroot%\system32\drivers\wdf01000.sys,-1000 : Kernel Mode Driver Frameworks service
@%systemroot%\system32\ci.dll,-101 : Enclave
@%systemroot%\system32\bthserv.dll,-101 : Bluetooth Support Service
@%systemroot%\system32\vds.exe,-112 : Provides management services for disks, volumes, file systems, and storage arrays.
@%systemroot%\system32\urlmon.dll,-4200 : Open File - Security Warning
@%systemroot%\system32\sstpsvc.dll,-201 : Provides support for the Secure Socket Tunneling Protocol (SSTP) to connect to remote computers using VPN. If this service is disabled, users will not be able to use SSTP to access remote servers.
@%systemroot%\system32\qmgr.dll,-1001 : Transfers files in the background using idle network bandwidth. If the service is disabled, then any applications that depend on BITS, such as Windows Update or MSN Explorer, will be unable to automatically download programs and other information.
@%systemroot%\system32\netman.dll,-110 : Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections.
@%programfiles%\windows defender advanced threat protection\mssense.exe,-1001 : Windows Defender Advanced Threat Protection Service
@c:\windows\system32\windows.storage.dll,-10152 : File folder
@%systemroot%\system32\drivers\volmgrx.sys,-100 : Dynamic Volume Manager
@%systemroot%\system32\das.dll,-101 : Enables pairing between the system and wired or wireless devices.
@combase.dll,-5011 : The RPCSS service is the Service Control Manager for COM and DCOM servers. It performs object activations requests, object exporter resolutions and distributed garbage collection for COM and DCOM servers. If this service is stopped or disabled, programs using COM or DCOM will not function properly. It is strongly recommended that you have the RPCSS service running.
@%systemroot%\system32\mprmsg.dll,-32006 : WAN Miniport (PPTP)
@%systemroot%\system32\wlidsvc.dll,-101 : Enables user sign-in through Microsoft account identity services. If this service is stopped, users will not be able to logon to the computer with their Microsoft account.
@%systemroot%\system32\dmwappushsvc.dll,-200 : Device Management Wireless Application Protocol (WAP) Push message Routing Service
@%systemroot%\system32\windows.warp.jitservice.dll,-101 : Enables JIT compilation support in d3d10warp.dll for processes in which code generation is disabled.
@%systemroot%\system32\pnrpauto.dll,-8003 : This service publishes a machine name using the Peer Name Resolution Protocol. Configuration is managed via the netsh context 'p2p pnrp peer'
@%systemroot%\system32\icsvc.dll,-202 : Provides a mechanism to exchange data between the virtual machine and the operating system running on the physical computer.
@%systemroot%\system32\diagsvc.dll,-100 : Diagnostic Execution Service
@%systemroot%\system32\icsvc.dll,-301 : Hyper-V Guest Shutdown Service
@%systemroot%\system32\wcmsvc.dll,-4098 : Makes automatic connect/disconnect decisions based on the network connectivity options currently available to the PC and enables management of network connectivity based on Group Policy settings.
@%systemroot%\system32\aarsvc.dll,-101 : Runtime for activating conversational agent applications
@%systemroot%\system32\wfdsconmgrsvc.dll,-9001 : Manages connections to wireless services, including wireless display and docking.
@%systemroot%\system32\drivers\fsdepends.sys,-10001 : File System Dependency Minifilter
@c:\programdata\microsoft\windows defender\platform\4.18.25110.5-0\mpasdesc.dll,-240 : Helps protect users from malware and other potentially unwanted software
@%systemroot%\system32\firewallapi.dll,-54005 : OutBound Rule for the Microsoft Media Foundation's Capture SVC to open TCP port to enable RTSP
@%systemroot%\system32\phoneserviceres.dll,-10000 : Phone Service
@%systemroot%\system32\wcncsvc.dll,-4 : WCNCSVC hosts the Windows Connect Now Configuration which is Microsoft's Implementation of Wireless Protected Setup (WPS) protocol. This is used to configure Wireless LAN settings for an Access Point (AP) or a Wireless Device. The service is started programmatically as needed.
c:\windows\system32,@elscore.dll,-7 : Microsoft Devanagari to Latin Transliteration
@%systemroot%\system32\defragsvc.dll,-102 : Helps the computer run more efficiently by optimizing files on storage drives.
@mqutil.dll,-6104 : Provides a messaging infrastructure and development tool for creating distributed messaging applications for Windows-based networks and programs. If this service is stopped, distributed messages will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\upnphost.dll,-214 : Allows UPnP devices to be hosted on this computer. If this service is stopped, any hosted UPnP devices will stop functioning and no additional hosted devices can be added. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\xboxnetapisvc.dll,-101 : This service supports the Windows.Networking.XboxLive application programming interface.
@%systemroot%\system32\tabsvc.dll,-100 : Touch Keyboard and Handwriting Panel Service
@%systemroot%\system32\tcpipcfg.dll,-50004 : NetIO Legacy TDI Support Driver
@%systemroot%\system32\windows.devices.picker.dll,-1006 : DevicePicker
@%windir%\system32\systemeventsbrokerserver.dll,-1002 : Coordinates execution of background work for WinRT application. If this service is stopped or disabled, then background work might not be triggered.
@%systemroot%\system32\assignedaccessmanagersvc.dll,-101 : AssignedAccessManager Service supports kiosk experience in Windows.
@%systemroot%\system32\deviceaccess.dll,-108 : Enables apps to pair devices
@%windir%\system32\inetsrv\iisres.dll,-30008 : Enables this server to administer the IIS metabase. The IIS metabase stores configuration for the SMTP and FTP services. If this service is stopped, the server will be unable to configure SMTP or FTP. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\ipnathlp.dll,-106 : Internet Connection Sharing (ICS)
@c:\programdata\microsoft\windows defender\platform\4.18.25100.9008-0\mpasdesc.dll,-320 : Microsoft Defender Antivirus Network Inspection Service
@%systemroot%\system32\wkssvc.dll,-1000 : Redirected Buffering Sub System
@%systemroot%\system32\mprmsg.dll,-32012 : Remote Access IPv6 ARP Driver
@peerdistsh.dll,-9003 : BranchCache - Hosted Cache Client (Uses HTTPS)
@%systemroot%\system32\bthavctpsvc.dll,-102 : This is Audio Video Control Transport Protocol service
@%systemroot%\system32\alg.exe,-112 : Application Layer Gateway Service
@%systemroot%\system32\sensrsvc.dll,-1001 : Monitors various sensors in order to expose data and adapt to system and user state. If this service is stopped or disabled, the display brightness will not adapt to lighting conditions. Stopping this service may affect other system functionality and features as well.
@%systemroot%\system32\drivers\msseccore.sys,-1001 : Microsoft Security Core Boot Driver
@%systemroot%\system32\microsoft.bluetooth.userservice.dll,-101 : Bluetooth User Support Service
@%systemroot%\system32\sstpsvc.dll,-202 : WAN Miniport (SSTP)
@c:\programdata\microsoft\windows defender\platform\4.18.25110.5-0\mpasdesc.dll,-330 : Microsoft Defender Antivirus Mini-Filter Driver
@%systemroot%\system32\sysmain.dll,-1000 : SysMain
@%systemroot%\system32\windows.sharedpc.accountmanager.dll,-101 : Manages profiles and accounts on a SharedPC configured device
@%systemroot%\system32\tzautoupdate.dll,-201 : Automatically sets the system time zone.
@%systemroot%\system32\drivers\ndu.sys,-10001 : Windows Network Data Usage Monitoring Driver
@%systemroot%\system32\userdataaccessres.dll,-10002 : Handles storage of structured user data, including contact info, calendars, messages, and other content. If you stop or disable this service, apps that use this data might not work correctly.
@%systemroot%\system32\securityhealthagent.dll,-1001 : Windows Security Service handles unified device protection and health information
@c:\programdata\microsoft\windows defender\platform\4.18.25090.3009-0\mpasdesc.dll,-330 : Microsoft Defender Antivirus Mini-Filter Driver
@%systemroot%\system32\peerdistsvc.dll,-9000 : BranchCache
c:\windows\system32,@elscore.dll,-6 : Microsoft Cyrillic to Latin Transliteration
@comres.dll,-2798 : Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will fail. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\bfe.dll,-1002 : The Base Filtering Engine (BFE) is a service that manages firewall and Internet Protocol security (IPsec) policies and implements user mode filtering. Stopping or disabling the BFE service will significantly reduce the security of the system. It will also result in unpredictable behavior in IPsec management and firewall applications.
@%systemroot%\system32\wevtsvc.dll,-201 : This service manages events and event logs. It supports logging events, querying events, subscribing to events, archiving event logs, and managing event metadata. It can display events in both XML and plain text format. Stopping this service may compromise security and reliability of the system.
@%systemroot%\system32\drivers\ndisvirtualbus.sys,-200 : Microsoft Virtual Network Adapter Enumerator
@%systemroot%\system32\wshrm.dll,-102 : Reliable Multicast Protocol
@%systemroot%\system32\tieringengineservice.exe,-701 : Optimizes the placement of data in storage tiers on all tiered storage spaces in the system.
@%systemroot%\system32\searchindexer.exe,-103 : Windows Search
@%systemroot%\system32\drivers\wudfrd.sys,-1000 : Windows Driver Foundation - User-mode Driver Framework Reflector
@%systemroot%\system32\bdesvc.dll,-100 : BitLocker Drive Encryption Service
@%systemroot%\system32\das.dll,-100 : Device Association Service
@%systemroot%\system32\termsrv.dll,-267 : Allows users to connect interactively to a remote computer. Remote Desktop and Remote Desktop Session Host Server depend on this service. To prevent remote use of this computer, clear the checkboxes on the Remote tab of the System properties control panel item.
@%systemroot%\syswow64\perfhost.exe,-1 : Enables remote users and 64-bit processes to query performance counters provided by 32-bit DLLs. If this service is stopped, only local users and 32-bit processes will be able to query performance counters provided by 32-bit DLLs.
@c:\programdata\microsoft\windows defender\platform\4.18.25100.9008-0\mpasdesc.dll,-310 : Microsoft Defender Antivirus Service
@%systemroot%\system32\scdeviceenum.dll,-101 : Creates software device nodes for all smart card readers accessible to a given session. If this service is disabled, WinRT APIs will not be able to enumerate smart card readers.
@%systemroot%\system32\rdxservice.dll,-257 : The Retail Demo service controls device activity while the device is in retail demo mode.
@%systemroot%\system32\rasmans.dll,-200 : Remote Access Connection Manager
@%systemroot%\system32\sdrsvc.dll,-102 : Provides Windows Backup and Restore capabilities.
@c:\windows\system32\msxml3r.dll,-1 : XML Document
@%systemroot%\system32\wdi.dll,-501 : The Diagnostic System Host is used by the Diagnostic Policy Service to host diagnostics that need to run in a Local System context. If this service is stopped, any diagnostics that depend on it will no longer function.
@%systemroot%\system32\firewallapi.dll,-37302 : mDNS
@%systemroot%\system32\drivers\pdc.sys,-100 : PDC
@%systemroot%\system32\dot3svc.dll,-1102 : Wired AutoConfig
@%systemroot%\system32\capabilityaccessmanager.dll,-1 : Capability Access Manager Service
@c:\programdata\microsoft\windows defender\platform\4.18.25080.5-0\mpasdesc.dll,-242 : Helps guard against intrusion attempts targeting known and newly discovered vulnerabilities in network protocols
@%systemroot%\system32\ngcctnrsvc.dll,-1 : Microsoft Passport Container
@%systemroot%\system32\spectrum.exe,-101 : Windows Perception Service
@%systemroot%\system32\installservice.dll,-201 : Provides infrastructure support for the Microsoft Store. This service is started on demand and if disabled then installations will not function properly.
@c:\programdata\microsoft\windows defender\platform\4.18.25110.6-0\mpasdesc.dll,-240 : Helps protect users from malware and other potentially unwanted software
@%systemroot%\system32\drivers\fltmgr.sys,-10001 : FltMgr
@%systemroot%\system32\pla.dll,-500 : Performance Logs & Alerts
@c:\programdata\microsoft\windows defender\platform\4.18.25080.5-0\mpasdesc.dll,-330 : Microsoft Defender Antivirus Mini-Filter Driver
@%systemroot%\system32\alg.exe,-113 : Provides support for 3rd party protocol plug-ins for Internet Connection Sharing
@%systemroot%\system32\bcastdvruserservice.dll,-101 : This user service is used for Game Recordings and Live Broadcasts
@%systemroot%\system32\presentationhost.exe,-3309 : Windows Presentation Foundation Font Cache 3.0.0.0
@%systemroot%\system32\dot3svc.dll,-1103 : The Wired AutoConfig (DOT3SVC) service is responsible for performing IEEE 802.1X authentication on Ethernet interfaces. If your current wired network deployment enforces 802.1X authentication, the DOT3SVC service should be configured to run for establishing Layer 2 connectivity and/or providing access to network resources. Wired networks that do not enforce 802.1X authentication are unaffected by the DOT3SVC service.
@%systemroot%\system32\msimsg.dll,-27 : Windows Installer
@%systemroot%\system32\drivers\tsusbflt.sys,-1000 : Remote Desktop USB Hub Class Filter Driver
@c:\programdata\microsoft\windows defender\platform\4.18.25090.3009-0\mpasdesc.dll,-244 : Monitors the availability, health, and performance of various security components
@comres.dll,-2946 : KtmRm for Distributed Transaction Coordinator
@%systemroot%\system32\cdpsvc.dll,-100 : Connected Devices Platform Service
@%windir%\system32\rpcepmap.dll,-1002 : Resolves RPC interfaces identifiers to transport endpoints. If this service is stopped or disabled, programs using Remote Procedure Call (RPC) services will not function properly.
@%systemroot%\system32\swprv.dll,-102 : Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\wpdbusenum.dll,-101 : Enforces group policy for removable mass-storage devices. Enables applications such as Windows Media Player and Image Import Wizard to transfer and synchronize content using removable mass-storage devices.
@keyiso.dll,-101 : The CNG key isolation service is hosted in the LSA process. The service provides key process isolation to private keys and associated cryptographic operations as required by the Common Criteria. The service stores and uses long-lived keys in a secure process complying with Common Criteria requirements.
@%systemroot%\system32\drivers\bindflt.sys,-100 : Windows Bind Filter Driver
@%systemroot%\system32\xblgamesave.dll,-101 : This service syncs save data for Xbox Live save enabled games. If this service is stopped, game save data will not upload to or download from Xbox Live.
@c:\programdata\microsoft\windows defender\platform\4.18.25080.5-0\mpasdesc.dll,-390 : Microsoft Defender Antivirus Boot Driver
@%systemroot%\system32\embeddedmodesvc.dll,-202 : The Embedded Mode service enables scenarios related to Background Applications. Disabling this service will prevent Background Applications from being activated.
@%systemroot%\system32\w32time.dll,-201 : Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\embeddedmodesvc.dll,-201 : Embedded Mode
@c:\programdata\microsoft\windows defender\platform\4.18.25100.9008-0\mpasdesc.dll,-330 : Microsoft Defender Antivirus Mini-Filter Driver
@c:\programdata\microsoft\windows defender\platform\4.18.25110.6-0\mpasdesc.dll,-370 : Microsoft Defender Antivirus Network Inspection System Driver
@%systemroot%\system32\clipsvc.dll,-104 : Provides infrastructure support for the Microsoft Store. This service is started on demand and if disabled applications bought using Windows Store will not behave correctly.
@%systemroot%\system32\ipnathlp.dll,-107 : Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network.
@%systemroot%\system32\captureservice.dll,-101 : Enables optional screen capture functionality for applications that call the Windows.Graphics.Capture API.
@%systemroot%\system32\firewallcontrolpanel.dll,-12122 : Windows Defender Firewall
@%systemroot%\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8194 : Receives activation requests over the net.msmq and msmq.formatname protocols and passes them to the Windows Process Activation Service.
@%systemroot%\system32\drivers\vwifibus.sys,-257 : Virtual Wireless Bus Driver
@%systemroot%\system32\rasauto.dll,-201 : Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address.
@%systemroot%\system32\netprofmsvc.dll,-203 : Identifies the networks to which the computer has connected, collects and stores properties for these networks, and notifies applications when these properties change.
@%systemroot%\system32\drivers\storqosflt.sys,-101 : Storage QoS Filter Driver
@%systemroot%\system32\sgrmbroker.exe,-101 : Monitors and attests to the integrity of the Windows platform.
@%systemroot%\system32\userdataaccessres.dll,-10003 : User Data Storage
@%systemroot%\system32\fdrespub.dll,-100 : Function Discovery Resource Publication
@%systemroot%\system32\drivers\appvvemgr.sys,-101 : AppvVemgr
@%systemroot%\system32\agentservice.exe,-101 : Provides support for application and OS settings roaming
@%systemroot%\system32\keyboardfiltersvc.dll,-101 : Microsoft Keyboard Filter
@%systemroot%\system32\wbengine.exe,-104 : Block Level Backup Engine Service
@%systemroot%\servicing\trustedinstaller.exe,-101 : Enables installation, modification, and removal of Windows updates and optional components. If this service is disabled, install or uninstall of Windows updates might fail for this computer.
@%systemroot%\system32\pcasvc.dll,-1 : Program Compatibility Assistant Service
@%systemroot%\system32\wdi.dll,-503 : The Diagnostic Service Host is used by the Diagnostic Policy Service to host diagnostics that need to run in a Local Service context. If this service is stopped, any diagnostics that depend on it will no longer function.
@%systemroot%\system32\bthavctpsvc.dll,-101 : AVCTP service
@%systemroot%\system32\windows.management.service.dll,-101 : Performs management including Provisioning and Enrollment activities
@c:\windows\system32\spool\drivers\x64\3\printconfig.dll,-2 : This service opens custom printer dialog boxes and handles notifications from a remote print server or a printer. If you turn off this service, you won’t be able to see printer extensions or notifications.
@%systemroot%\system32\penservice.dll,-101 : Pen Service
@%systemroot%\system32\drivers\gpuenergydrv.sys,-100 : GPU Energy Driver
@%systemroot%\system32\xblauthmanager.dll,-101 : Provides authentication and authorization services for interacting with Xbox Live. If this service is stopped, some applications may not operate correctly.
@%systemroot%\system32\wiaservc.dll,-9 : Windows Image Acquisition (WIA)
@%systemroot%\system32\drivers\afd.sys,-1000 : Ancillary Function Driver for Winsock
@c:\programdata\microsoft\windows defender\platform\4.18.25110.5-0\mpasdesc.dll,-400 : Microsoft Defender Antivirus Boot Driver
@%systemroot%\system32\powrprof.dll,-11 : Power saver
@%systemroot%\system32\autotimesvc.dll,-6 : Cellular Time
@%systemroot%\system32\mprmsg.dll,-32005 : WAN Miniport (L2TP)
@%systemroot%\servicing\trustedinstaller.exe,-100 : Windows Modules Installer
@gpapi.dll,-113 : The service is responsible for applying settings configured by administrators for the computer and users through the Group Policy component. If the service is disabled, the settings will not be applied and applications and components will not be manageable through Group Policy. Any components or applications that depend on the Group Policy component might not be functional if the service is disabled.
@%systemroot%\system32\rasmans.dll,-201 : Manages dial-up and virtual private network (VPN) connections from this computer to the Internet or other remote networks. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\certprop.dll,-14 : Allows the system to be configured to lock the user desktop upon smart card removal.
@%systemroot%\system32\windows.devices.picker.dll,-1007 : This user service is used for managing the Miracast, DLNA, and DIAL UI
@%systemroot%\system32\pla.dll,-501 : Performance Logs and Alerts Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\rmapi.dll,-1002 : Radio Management and Airplane Mode Service
@%systemroot%\system32\tokenbroker.dll,-100 : Web Account Manager
c:\windows\system32,@elscore.dll,-2 : Microsoft Script Detection
@c:\programdata\microsoft\windows defender\platform\4.18.25090.3009-0\mpasdesc.dll,-400 : Microsoft Defender Antivirus Boot Driver
@%systemroot%\system32\installservice.dll,-200 : Microsoft Store Install Service
@c:\programdata\microsoft\windows defender\platform\4.18.25080.5-0\mpasdesc.dll,-310 : Microsoft Defender Antivirus Service
@%systemroot%\system32\rdxservice.dll,-256 : Retail Demo Service
@%systemroot%\system32\naturalauth.dll,-100 : Natural Authentication
@%systemroot%\system32\netlogon.dll,-103 : Maintains a secure channel between this computer and the domain controller for authenticating users and services. If this service is stopped, the computer may not authenticate users and services and the domain controller cannot register DNS records. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\scardsvr.dll,-5 : Manages access to smart cards read by this computer. If this service is stopped, this computer will be unable to read smart cards. If this service is disabled, any services that explicitly depend on it will fail to start.
@comres.dll,-2947 : Coordinates transactions between the Distributed Transaction Coordinator (MSDTC) and the Kernel Transaction Manager (KTM). If it is not needed, it is recommended that this service remain stopped. If it is needed, both MSDTC and KTM will start this service automatically. If this service is disabled, any MSDTC transaction interacting with a Kernel Resource Manager will fail and any services that explicitly depend on it will fail to start.
@%systemroot%\system32\drivers\sgrmagent.sys,-1001 : System Guard Runtime Monitor Agent
c:\windows\system32,@elscore.dll,-9 : Microsoft Bengali to Latin Transliteration
@%systemroot%\system32\drivers\hwpolicy.sys,-101 : Hardware Policy Driver
@%systemroot%\system32\icsvcvss.dll,-102 : Coordinates the communications that are required to use Volume Shadow Copy Service to back up applications and data on this virtual machine from the operating system on the physical computer.
@%systemroot%\system32\shsvcs.dll,-12288 : Shell Hardware Detection
@%systemroot%\system32\dmwappushsvc.dll,-201 : Routes Wireless Application Protocol (WAP) Push messages received by the device and synchronizes Device Management sessions
@c:\programdata\microsoft\windows defender\platform\4.18.25110.6-0\mpasdesc.dll,-242 : Helps guard against intrusion attempts targeting known and newly discovered vulnerabilities in network protocols
@%systemroot%\system32\mprdim.dll,-200 : Routing and Remote Access
@%systemroot%\system32\srvsvc.dll,-101 : Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\consentuxclient.dll,-100 : ConsentUX User Service
@%systemroot%\system32\icsvcext.dll,-602 : Provides a platform for communication between the virtual machine and the operating system running on the physical computer.
@%systemroot%\system32\appxdeploymentserver.dll,-2 : Provides infrastructure support for deploying Store applications. This service is started on demand and if disabled Store applications will not be deployed to the system, and may not function properly.
c:\windows\system32,@elscore.dll,-8 : Microsoft Malayalam to Latin Transliteration
@%systemroot%\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8200 : Provides ability to share TCP ports over the net.tcp protocol.
@%systemroot%\system32\schedsvc.dll,-101 : Enables a user to configure and schedule automated tasks on this computer. The service also hosts multiple Windows system-critical tasks. If this service is stopped or disabled, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\capabilityaccessmanager.dll,-2 : Provides facilities for managing UWP apps access to app capabilities as well as checking an app's access to specific app capabilities
@%systemroot%\system32\drivers\nwifi.sys,-101 : NativeWiFi Filter
@%programfiles%\windows media player\wmpnetwk.exe,-101 : Windows Media Player Network Sharing Service
@c:\programdata\microsoft\windows defender\platform\4.18.25110.6-0\mpasdesc.dll,-400 : Microsoft Defender Antivirus Boot Driver
@%systemroot%\system32\diagtrack.dll,-3002 : The Connected User Experiences and Telemetry service enables features that support in-application and connected user experiences. Additionally, this service manages the event driven collection and transmission of diagnostic and usage information (used to improve the experience and quality of the Windows Platform) when the diagnostics and usage privacy option settings are enabled under Feedback and Diagnostics.
@%systemroot%\system32\printworkflowservice.dll,-101 : Provides support for Print Workflow applications. If you turn off this service, you may not be able to print successfully.
@mqutil.dll,-6101 : Message Queuing Access Control
@%systemroot%\system32\netprofmsvc.dll,-208 : Network Location Awareness
@%systemroot%\system32\ncdautosetup.dll,-100 : Network Connected Devices Auto-Setup
c:\windows\system32,@elscore.dll,-1 : Microsoft Language Detection
@%systemroot%\system32\hidserv.dll,-101 : Human Interface Device Service
@c:\programdata\microsoft\windows defender\platform\4.18.25110.6-0\mpasdesc.dll,-390 : Microsoft Defender Antivirus Boot Driver
@%systemroot%\system32\ngcctnrsvc.dll,-2 : Manages local user identity keys used to authenticate user to identity providers as well as TPM virtual smart cards. If this service is disabled, local user identity keys and TPM virtual smart cards will not be accessible. It is recommended that you do not reconfigure this service.
@c:\programdata\microsoft\windows defender\platform\4.18.25100.9008-0\mpasdesc.dll,-245 : Microsoft Defender Core Service
@%systemroot%\system32\drivers\mshidumdf.sys,-100 : Pass-through HID to UMDF Driver
@%systemroot%\system32\swprv.dll,-103 : Microsoft Software Shadow Copy Provider
@%systemroot%\system32\scdeviceenum.dll,-100 : Smart Card Device Enumeration Service
@%systemroot%\system32\wkssvc.dll,-1008 : DFS Namespace Client Driver
@%systemroot%\system32\eapsvc.dll,-1 : Extensible Authentication Protocol
@c:\programdata\microsoft\windows defender\platform\4.18.25110.5-0\mpasdesc.dll,-390 : Microsoft Defender Antivirus Boot Driver
@%systemroot%\system32\naturalauth.dll,-101 : Signal aggregator service, that evaluates signals based on time, network, geolocation, bluetooth and cdf factors. Supported features are Device Unlock, Dynamic Lock and Dynamo MDM policies
@%systemroot%\system32\eapsvc.dll,-2 : The Extensible Authentication Protocol (EAP) service provides network authentication in such scenarios as 802.1x wired and wireless, VPN, and Network Access Protection (NAP). EAP also provides application programming interfaces (APIs) that are used by network access clients, including wireless and VPN clients, during the authentication process. If you disable this service, this computer is prevented from accessing networks that require EAP authentication.
@%systemroot%\system32\drivers\uevagentdriver.sys,-101 : UevAgentDriver
@%windir%\system32\inetsrv\iisres.dll,-30004 : Provides Web connectivity and administration through the Internet Information Services Manager
@%systemroot%\system32\locator.exe,-3 : In Windows 2003 and earlier versions of Windows, the Remote Procedure Call (RPC) Locator service manages the RPC name service database. In Windows Vista and later versions of Windows, this service does not provide any functionality and is present for application compatibility.
@%systemroot%\system32\microsoft.graphics.display.displayenhancementservice.dll,-1001 : A service for managing display enhancement such as brightness control.
@%systemroot%\system32\wercplsupport.dll,-100 : This service provides support for viewing, sending and deletion of system-level problem reports for the Problem Reports control panel.
@%systemroot%\system32\w32time.dll,-200 : Windows Time
c:\windows\system32,@elscore.dll,-5 : Microsoft Transliteration Engine
@wlansvc.dll,-36864 : WLAN Service - WFD Application Services Platform Coordination Protocol (Uses UDP)
@%systemroot%\system32\cscsvc.dll,-200 : Offline Files
@%systemroot%\system32\microsoft.bluetooth.userservice.dll,-102 : The Bluetooth user service supports proper functionality of Bluetooth features relevant to each user session.
@%systemroot%\system32\drivers\clfs.sys,-100 : Common Log (CLFS)
@mqutil.dll,-6206 : Provides rule-based monitoring of messages arriving in a Message Queuing queue and, when the conditions of a rule are satisfied, invokes a COM component or a stand-alone executable program to process the message.
@waasmedicsvc.dll,-100 : Windows Update Medic Service
@%systemroot%\system32\drivers\ndis.sys,-200 : NDIS System Driver
@%systemroot%\system32\usosvc.dll,-102 : Manages Windows Updates. If stopped, your devices will not be able to download and install the latest updates.
@%systemroot%\system32\tetheringservice.dll,-4098 : Provides the ability to share a cellular data connection with another device.
@%systemroot%\system32\sstpsvc.dll,-200 : Secure Socket Tunneling Protocol Service
@%systemroot%\system32\ncasvc.dll,-3008 : Provides DirectAccess status notification for UI components
@%systemroot%\system32\drivers\wudfpf.sys,-1000 : User Mode Driver Frameworks Platform Driver
@firewallapi.dll,-50323 : SNMP Trap
@sstpsvc.dll,-35001 : Secure Socket Tunneling Protocol
@%systemroot%\system32\wdi.dll,-500 : Diagnostic System Host
@%systemroot%\system32\fdrespub.dll,-101 : Publishes this computer and resources attached to this computer so they can be discovered over the network. If this service is stopped, network resources will no longer be published and they will not be discovered by other computers on the network.
@%systemroot%\system32\sgrmbroker.exe,-100 : System Guard Runtime Monitor Broker
@c:\programdata\microsoft\windows defender\platform\4.18.25090.3009-0\mpasdesc.dll,-340 : Microsoft Defender Antivirus On-Access Malware Protection Mini-Filter Driver
@%windir%\system32\bisrv.dll,-101 : Windows infrastructure service that controls which background tasks can run on the system.
@%systemroot%\system32\wiaservc.dll,-10 : Provides image acquisition services for scanners and cameras
@%systemroot%\system32\certprop.dll,-12 : Copies user certificates and root certificates from smart cards into the current user's certificate store, detects when a smart card is inserted into a smart card reader, and, if needed, installs the smart card Plug and Play minidriver.
@%systemroot%\system32\hnetcfgclient.dll,-201 : HNetCfg Client
@%systemroot%\system32\pnrpsvc.dll,-8000 : Peer Name Resolution Protocol
@%systemroot%\system32\autotimesvc.dll,-7 : This service sets time based on NITZ messages from a Mobile Network
@%systemroot%\system32\iscsidsc.dll,-5000 : Microsoft iSCSI Initiator Service
@%systemroot%\system32\windowspowershell\v1.0\powershell.exe,-124 : Document Encryption
@c:\programdata\microsoft\windows defender\platform\4.18.25090.3009-0\mpasdesc.dll,-370 : Microsoft Defender Antivirus Network Inspection System Driver
@%systemroot%\system32\drivers\p9rdr.sys,-100 : Plan 9 Redirector Driver
@%systemroot%\system32\trkwks.dll,-2 : Maintains links between NTFS files within a computer or across computers in a network.
@%systemroot%\system32\appvclient.exe,-101 : Manages App-V users and virtual applications
@%systemroot%\system32\wpcrefreshtask.dll,-101 : Enforces parental controls for child accounts in Windows. If this service is stopped or disabled, parental controls may not be enforced.
@%systemroot%\system32\drivers\cnghwassist.sys,-100 : CNG Hardware Assist algorithm provider
@%systemroot%\system32\svsvc.dll,-102 : Verifies potential file system corruptions.
@%systemroot%\system32\lltdres.dll,-2 : Creates a Network Map, consisting of PC and device topology (connectivity) information, and metadata describing each PC and device. If this service is disabled, the Network Map will not function properly.
@c:\programdata\microsoft\windows defender\platform\4.18.25090.3009-0\mpasdesc.dll,-310 : Microsoft Defender Antivirus Service
@%systemroot%\system32\powrprof.dll,-15 : Balanced
@%systemroot%\system32\lltdres.dll,-5 : Link-Layer Topology Discovery Responder
@%systemroot%\system32\tetheringservice.dll,-4097 : Windows Mobile Hotspot Service
@%systemroot%\system32\drivers\appvvfs.sys,-101 : AppvVfs
@%systemroot%\system32\mitigationclient.dll,-104 : Enables automatic mitigation for known problems by applying recommended troubleshooting. If stopped, your device will not get recommended troubleshooting for problems on your device.
@%systemroot%\system32\windows.warp.jitservice.dll,-100 : Warp JIT Service
c:\windows\system32,@elscore.dll,-4 : Microsoft Simplified Chinese to Traditional Chinese Transliteration
@%systemroot%\system32\drivers\http.sys,-1 : HTTP Service
@%systemroot%\system32\sessenv.dll,-1027 : Remote Desktop Configuration service (RDCS) is responsible for all Remote Desktop Services and Remote Desktop related configuration and session maintenance activities that require SYSTEM context. These include per-session temporary folders, RD themes, and RD certificates.
@winlangdb.dll,-1121 : English (United States)
@%systemroot%\system32\rasauto.dll,-200 : Remote Access Auto Connection Manager
@%systemroot%\system32\wbengine.exe,-105 : The WBENGINE service is used by Windows Backup to perform backup and recovery operations. If this service is stopped by a user, it may cause the currently running backup or recovery operation to fail. Disabling this service may disable backup and recovery operations using Windows Backup on this computer.
@c:\programdata\microsoft\windows defender\platform\4.18.25080.5-0\mpasdesc.dll,-245 : Microsoft Defender Core Service
@%systemroot%\system32\mprdim.dll,-201 : Offers routing services to businesses in local area and wide area network environments.
@%systemroot%\system32\defragsvc.dll,-101 : Optimize drives
@c:\programdata\microsoft\windows defender\platform\4.18.25090.3009-0\mpasdesc.dll,-242 : Helps guard against intrusion attempts targeting known and newly discovered vulnerabilities in network protocols
@wifidisplay.dll,-100 : Wireless Display
@%systemroot%\system32\p9rdrservice.dll,-102 : P9RdrService
@%systemroot%\system32\presentationhost.exe,-3310 : Optimizes performance of Windows Presentation Foundation (WPF) applications by caching commonly used font data. WPF applications will start this service if it is not already running. It can be disabled, though doing so will degrade the performance of WPF applications.
@%systemroot%\system32\mprmsg.dll,-32001 : Remote Access NDIS TAPI Driver
@%systemroot%\system32\fxsresm.dll,-122 : Enables you to send and receive faxes, utilizing fax resources available on this computer or on the network.
@%systemroot%\system32\fveui.dll,-844 : BitLocker Data Recovery Agent
@%systemroot%\system32\drivers\mssecflt.sys,-1001 : Microsoft Security Events Component Minifilter
@%systemroot%\system32\icsvc.dll,-801 : Hyper-V Guest Service Interface
@%systemroot%\system32\diagsvcs\diagnosticshub.standardcollector.serviceres.dll,-1000 : Microsoft (R) Diagnostics Hub Standard Collector Service
@%systemroot%\system32\wsmsvc.dll,-101 : Windows Remote Management (WS-Management)
@%systemroot%\system32\ssdpsrv.dll,-100 : SSDP Discovery
@%systemroot%\system32\drivers\indirectkmd.sys,-100 : Indirect Displays Kernel-Mode Driver
@%systemroot%\system32\pnrpsvc.dll,-8005 : Provides identity services for the Peer Name Resolution Protocol (PNRP) and Peer-to-Peer Grouping services. If disabled, the Peer Name Resolution Protocol (PNRP) and Peer-to-Peer Grouping services may not function, and some applications, such as HomeGroup and Remote Assistance, may not function correctly.
@c:\windows\system32\spool\drivers\x64\3\printconfig.dll,-1 : Printer Extensions and Notifications
@%systemroot%\system32\icsvcvss.dll,-101 : Hyper-V Volume Shadow Copy Requestor
@%systemroot%\system32\icsvc.dll,-700 : Virtual Machine Monitoring
@c:\programdata\microsoft\windows defender\platform\4.18.25110.5-0\mpasdesc.dll,-242 : Helps guard against intrusion attempts targeting known and newly discovered vulnerabilities in network protocols
@%systemroot%\system32\vssvc.exe,-101 : Manages and implements Volume Shadow Copies used for backup and other purposes. If this service is stopped, shadow copies will be unavailable for backup and the backup may fail. If this service is disabled, any services that explicitly depend on it will fail to start.
@c:\programdata\microsoft\windows defender\platform\4.18.25100.9008-0\mpasdesc.dll,-400 : Microsoft Defender Antivirus Boot Driver
@%systemroot%\system32\peerdistsvc.dll,-9001 : This service caches network content from peers on the local subnet.
@%systemroot%\system32\storsvc.dll,-101 : Provides enabling services for storage settings and external storage expansion
@%systemroot%\system32\credentialenrollmentmanager.exe,-100 : CredentialEnrollmentManagerUserSvc
@%systemroot%\system32\lpasvc.dll,-1000 : Local Profile Assistant Service
@%systemroot%\system32\captureservice.dll,-100 : CaptureService
@%systemroot%\system32\webclnt.dll,-104 : WebDav Client Redirector Driver
@%systemroot%\system32\webclnt.dll,-100 : WebClient
@%systemroot%\system32\smphost.dll,-102 : Microsoft Storage Spaces SMP
@%windir%\system32\inetsrv\iisres.dll,-30007 : IIS Admin Service
@%systemroot%\system32\drivers\netbt.sys,-2 : NETBT
@%systemroot%\system32\drivers\fileinfo.sys,-100 : File Information FS MiniFilter
@%systemroot%\system32\drivers\wcifs.sys,-100 : Windows Container Isolation
@%systemroot%\system32\drivers\ahcache.sys,-102 : Application Compatibility Cache
@%systemroot%\system32\axinstsv.dll,-104 : Provides User Account Control validation for the installation of ActiveX controls from the Internet and enables management of ActiveX control installation based on Group Policy settings. This service is started on demand and if disabled the installation of ActiveX controls will behave according to default browser settings.
@%systemroot%\system32\windows.internal.management.dll,-100 : Device Management Enrollment Service
@%systemroot%\system32\languageoverlayserver.dll,-100 : Language Experience Service
@enterpriseappmgmtsvc.dll,-2 : Enables enterprise application management.
@winlangdb.dll,-1114 : English (India)
@c:\programdata\microsoft\windows defender\platform\4.18.25080.5-0\mpasdesc.dll,-320 : Microsoft Defender Antivirus Network Inspection Service
@%systemroot%\system32\firewallapi.dll,-38529 : Secure World Wide Web Services (QUIC)
@%systemroot%\system32\wercplsupport.dll,-101 : Problem Reports Control Panel Support
@%systemroot%\system32\srpapi.dll,-102 : Smartlocker Filter Driver
@%systemroot%\system32\netsetupsvc.dll,-3 : Network Setup Service
@%systemroot%\system32\webclnt.dll,-101 : Enables Windows-based programs to create, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\fodhelper.exe,-100 : Optional Features
@%systemroot%\system32\windows.management.service.dll,-100 : Windows Management Service
@%systemroot%\system32\cscsvc.dll,-201 : The Offline Files service performs maintenance activities on the Offline Files cache, responds to user logon and logoff events, implements the internals of the public API, and dispatches interesting events to those interested in Offline Files activities and changes in cache state.
@%systemroot%\system32\userdataaccessres.dll,-15001 : Contact Data
@%systemroot%\system32\tabsvc.dll,-101 : Enables Touch Keyboard and Handwriting Panel pen and ink functionality
@%systemroot%\system32\powrprof.dll,-14 : Automatically balances performance with energy consumption on capable hardware.
@%systemroot%\system32\frameservermonitor.dll,-100 : Windows Camera Frame Server Monitor
@%systemroot%\system32\wkssvc.dll,-2001 : Browser
@%systemroot%\system32\ngcsvc.dll,-101 : Provides process isolation for cryptographic keys used to authenticate to a user’s associated identity providers. If this service is disabled, all uses and management of these keys will not be available, which includes machine logon and single-sign on for apps and websites. This service starts and stops automatically. It is recommended that you do not reconfigure this service.
@%systemroot%\system32\wlansvc.dll,-258 : The WLANSVC service provides the logic required to configure, discover, connect to, and disconnect from a wireless local area network (WLAN) as defined by IEEE 802.11 standards. It also contains the logic to turn your computer into a software access point so that other devices or computers can connect to your computer wirelessly using a WLAN adapter that can support this. Stopping or disabling the WLANSVC service will make all WLAN adapters on your computer inaccessible from the Windows networking UI. It is strongly recommended that you have the WLANSVC service running if your computer has a WLAN adapter.
@%systemroot%\system32\wbem\wmisvc.dll,-205 : Windows Management Instrumentation
@%systemroot%\system32\walletservice.dll,-1001 : Hosts objects used by clients of the wallet
@%systemroot%\system32\icsvc.dll,-102 : Monitors the state of this virtual machine by reporting a heartbeat at regular intervals. This service helps you identify running virtual machines that have stopped responding.
@%systemroot%\system32\cbdhsvc.dll,-101 : This user service is used for Clipboard scenarios
@%systemroot%\system32\dnsapi.dll,-103 : Domain Name System (DNS) Server Trust
@%systemroot%\system32\icsvc.dll,-401 : Hyper-V Time Synchronization Service
@c:\programdata\microsoft\windows defender\platform\4.18.25100.9008-0\mpasdesc.dll,-370 : Microsoft Defender Antivirus Network Inspection System Driver
@%systemroot%\system32\wbiosrvc.dll,-101 : The Windows biometric service gives client applications the ability to capture, compare, manipulate, and store biometric data without gaining direct access to any biometric hardware or samples. The service is hosted in a privileged SVCHOST process.
@%systemroot%\system32\firewallapi.dll,-53500 : Recommended Troubleshooting
@%systemroot%\system32\appinfo.dll,-101 : Facilitates the running of interactive applications with additional administrative privileges. If this service is stopped, users will be unable to launch applications with the additional administrative privileges they may require to perform desired user tasks.
@%systemroot%\system32\firewallapi.dll,-11199 : Message Queuing
@%systemroot%\system32\srvsvc.dll,-104 : Server SMB 2.xxx Driver
@%systemroot%\system32\searchindexer.exe,-104 : Provides content indexing, property caching, and search results for files, e-mail, and other content.
@%systemroot%\system32\msimsg.dll,-32 : Adds, modifies, and removes applications provided as a Windows Installer (*.msi, *.msp) package. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\coremessaging.dll,-2 : Manages communication between system components.
@%systemroot%\system32\drivers\bam.sys,-100 : Background Activity Moderator Driver
@%systemroot%\system32\mprmsg.dll,-32002 : Remote Access NDIS WAN Driver
@%systemroot%\system32\bcastdvruserservice.dll,-100 : GameDVR and Broadcast User Service
@%systemroot%\system32\umrdp.dll,-1001 : Allows the redirection of Printers/Drives/Ports for RDP connections
@%systemroot%\system32\sensordataservice.exe,-102 : Delivers data from a variety of sensors
@%systemroot%\system32\icsvc.dll,-902 : Provides a mechanism to manage virtual machine with PowerShell via VM session without a virtual network.
@%systemroot%\system32\drivers\wfplwfs.sys,-6000 : Microsoft Windows Filtering Platform
@%systemroot%\microsoft.net\framework64\v4.0.30319\aspnet_rc.dll,-2 : Provides support for out-of-process session states for ASP.NET. If this service is stopped, out-of-process requests will not be processed. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\efssvc.dll,-101 : Provides the core file encryption technology used to store encrypted files on NTFS file system volumes. If this service is stopped or disabled, applications will be unable to access encrypted files.
@%systemroot%\system32\appvclient.exe,-102 : Microsoft App-V Client
@c:\programdata\microsoft\windows defender\platform\4.18.25090.3009-0\mpasdesc.dll,-245 : Microsoft Defender Core Service
@%systemroot%\system32\flightsettings.dll,-103 : Windows Insider Service
@%systemroot%\system32\spectrum.exe,-102 : Enables spatial perception, spatial input, and holographic rendering.
@%systemroot%\system32\ncdautosetup.dll,-101 : Network Connected Devices Auto-Setup service monitors and installs qualified devices that connect to a qualified network. Stopping or disabling this service will prevent Windows from discovering and installing qualified network connected devices automatically. Users can still manually add network connected devices to a PC through the user interface.
@%systemroot%\system32\wwansvc.dll,-257 : WWAN AutoConfig
@%systemroot%\system32\wsmsvc.dll,-102 : Windows Remote Management (WinRM) service implements the WS-Management protocol for remote management. WS-Management is a standard web services protocol used for remote software and hardware management. The WinRM service listens on the network for WS-Management requests and processes them. The WinRM Service needs to be configured with a listener using winrm.cmd command line tool or through Group Policy in order for it to listen over the network. The WinRM service provides access to WMI data and enables event collection. Event collection and subscription to events require that the service is running. WinRM messages use HTTP and HTTPS as transports. The WinRM service does not depend on IIS but is preconfigured to share a port with IIS on the same machine. The WinRM service reserves the /wsman URL prefix. To prevent conflicts with IIS, administrators should ensure that any websites hosted on IIS do not use the /wsman URL prefix.
@%systemroot%\system32\mprmsg.dll,-32007 : Remote Access PPPOE Driver
@appmgmts.dll,-3251 : Processes installation, removal, and enumeration requests for software deployed through Group Policy. If the service is disabled, users will be unable to install, remove, or enumerate software deployed through Group Policy. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\ngcsvc.dll,-100 : Microsoft Passport
@%systemroot%\system32\wscsvc.dll,-201 : The WSCSVC (Windows Security Center) service monitors and reports security health settings on the computer. The health settings include firewall (on/off), antivirus (on/off/out of date), antispyware (on/off/out of date), Windows Update (automatically/manually download and install updates), User Account Control (on/off), and Internet settings (recommended/not recommended). The service provides COM APIs for independent software vendors to register and record the state of their products to the Security Center service. The Security and Maintenance UI uses the service to provide systray alerts and a graphical view of the security health states in the Security and Maintenance control panel. Network Access Protection (NAP) uses the service to report the security health states of clients to the NAP Network Policy Server to make network quarantine decisions. The service also has a public API that allows external consumers to programmatically retrieve the aggregated security health state of the system.
@%systemroot%\system32\sensorservice.dll,-1000 : Sensor Service
@%systemroot%\system32\tokenbroker.dll,-101 : This service is used by Web Account Manager to provide single-sign-on to apps and services.
@%systemroot%\system32\dps.dll,-500 : Diagnostic Policy Service
@%systemroot%\system32\sensordataservice.exe,-101 : Sensor Data Service
@%systemroot%\system32\printworkflowservice.dll,-100 : PrintWorkflow
@%systemroot%\system32\cdpsvc.dll,-101 : This service is used for Connected Devices Platform scenarios
@%systemroot%\system32\sppsvc.exe,-101 : Software Protection
@comres.dll,-2451 : Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\drivers\ndiscap.sys,-5000 : Microsoft NDIS Capture
@%systemroot%\system32\mitigationclient.dll,-103 : Recommended Troubleshooting Service
@%systemroot%\system32\ajrouter.dll,-1 : Routes AllJoyn messages for the local AllJoyn clients. If this service is stopped the AllJoyn clients that do not have their own bundled routers will be unable to run.
@%systemroot%\system32\wecsvc.dll,-201 : This service manages persistent subscriptions to events from remote sources that support WS-Management protocol. This includes Windows Vista event logs, hardware and IPMI-enabled event sources. The service stores forwarded events in a local Event Log. If this service is stopped or disabled event subscriptions cannot be created and forwarded events cannot be accepted.
@%systemroot%\system32\pushtoinstall.dll,-201 : Provides infrastructure support for the Microsoft Store. This service is started automatically and if disabled then remote installations will not function properly.
@keyiso.dll,-100 : CNG Key Isolation
@%systemroot%\system32\cscsvc.dll,-202 : Offline Files Driver
@%systemroot%\system32\icsvcext.dll,-601 : Hyper-V Remote Desktop Virtualization Service
@c:\programdata\microsoft\windows defender\platform\4.18.25110.6-0\mpasdesc.dll,-330 : Microsoft Defender Antivirus Mini-Filter Driver
@%systemroot%\system32\windowsudkservices.shellcommon.dll,-101 : Shell components service
@%windir%\system32\drivers\netbios.sys,-503 : NetBIOS Interface
@%systemroot%\system32\lmhsvc.dll,-102 : Provides support for the NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution for clients on the network, therefore enabling users to share files, print, and log on to the network. If this service is stopped, these functions might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\wbem\wmiapsrv.exe,-110 : WMI Performance Adapter
@c:\programdata\microsoft\windows defender\platform\4.18.25100.9008-0\mpasdesc.dll,-244 : Monitors the availability, health, and performance of various security components
@%systemroot%\system32\icsvc.dll,-901 : Hyper-V PowerShell Direct Service
c:\windows\system32,@elscore.dll,-3 : Microsoft Traditional Chinese to Simplified Chinese Transliteration
@%systemroot%\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8196 : Receives activation requests over the net.pipe protocol and passes them to the Windows Process Activation Service.
@%systemroot%\system32\umpnpmgr.dll,-101 : Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability.
@%systemroot%\system32\polstore.dll,-5011 : Internet Protocol security (IPsec) supports network-level peer authentication, data origin authentication, data integrity, data confidentiality (encryption), and replay protection. This service enforces IPsec policies created through the IP Security Policies snap-in or the command-line tool ""netsh ipsec"". If you stop this service, you may experience network connectivity issues if your policy requires that connections use IPsec. Also,remote management of Windows Defender Firewall is not available when this service is stopped.
@%systemroot%\system32\windows.sharedpc.accountmanager.dll,-100 : Shared PC Account Manager
@%systemroot%\system32\wpnuserservice.dll,-1 : Windows Push Notifications User Service
@%systemroot%\system32\windows.staterepository.dll,-2 : Provides required infrastructure support for the application model.
@%systemroot%\system32\winhttp.dll,-101 : WinHTTP implements the client HTTP stack and provides developers with a Win32 API and COM Automation component for sending HTTP requests and receiving responses. In addition, WinHTTP provides support for auto-discovering a proxy configuration via its implementation of the Web Proxy Auto-Discovery (WPAD) protocol.
@%systemroot%\system32\iscsidsc.dll,-5001 : Manages Internet SCSI (iSCSI) sessions from this computer to remote iSCSI target devices. If this service is stopped, this computer will not be able to login or access iSCSI targets. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\appidsvc.dll,-100 : Application Identity
@%systemroot%\system32\icsvc.dll,-402 : Synchronizes the system time of this virtual machine with the system time of the physical computer.
@%systemroot%\system32\drivers\mountmgr.sys,-100 : Mount Point Manager
@%systemroot%\system32\keyboardfiltersvc.dll,-102 : Controls keystroke filtering and mapping
@%systemroot%\system32\icsvc.dll,-302 : Provides a mechanism to shut down the operating system of this virtual machine from the management interfaces on the physical computer.
@%systemroot%\microsoft.net\framework64\v4.0.30319\aspnet_rc.dll,-1 : ASP.NET State Service
@%systemroot%\system32\hvhostsvc.dll,-101 : Provides an interface for the Hyper-V hypervisor to provide per-partition performance counters to the host operating system.
@%systemroot%\system32\icsvc.dll,-201 : Hyper-V Data Exchange Service
@%systemroot%\system32\dosvc.dll,-101 : Performs content delivery optimization tasks
@%systemroot%\system32\iphlpsvc.dll,-501 : Provides tunnel connectivity using IPv6 transition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS. If this service is stopped, the computer will not have the enhanced connectivity benefits that these technologies offer.
@c:\programdata\microsoft\windows defender\platform\4.18.25110.6-0\mpasdesc.dll,-340 : Microsoft Defender Antivirus On-Access Malware Protection Mini-Filter Driver
@%systemroot%\system32\pnrpsvc.dll,-8004 : Peer Networking Identity Manager
@%systemroot%\system32\cdpusersvc.dll,-100 : Connected Devices Platform User Service
@%systemroot%\system32\audiosrv.dll,-201 : Manages audio for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start
@%systemroot%\system32\shell32.dll,-50176 : File Operation
@%systemroot%\system32\xboxnetapisvc.dll,-100 : Xbox Live Networking Service
@%systemroot%\system32\samsrv.dll,-2 : The startup of this service signals other services that the Security Accounts Manager (SAM) is ready to accept requests. Disabling this service will prevent other services in the system from being notified when the SAM is ready, which may in turn cause those services to fail to start correctly. This service should not be disabled.
@%systemroot%\system32\bridgeres.dll,-1 : Microsoft MAC Bridge
@%systemroot%\system32\lpasvc.dll,-1001 : This service provides profile management for subscriber identity modules
@%systemroot%\system32\appidsvc.dll,-101 : Determines and verifies the identity of an application. Disabling this service will prevent AppLocker from being enforced.
@%systemroot%\system32\languageoverlayserver.dll,-101 : Provides infrastructure support for deploying and configuring localized Windows resources. This service is started on demand and, if disabled, additional Windows languages will not be deployed to the system, and Windows may not function properly.
@%systemroot%\system32\cdpusersvc.dll,-101 : This user service is used for Connected Devices Platform scenarios
@%systemroot%\system32\drivers\partmgr.sys,-100 : Partition driver
@%systemroot%\system32\wbiosrvc.dll,-100 : Windows Biometric Service
@%systemroot%\system32\ipxlatcfg.dll,-500 : IP Translation Configuration Service
@c:\windows\system32\ulib.dll,-1000 : Recovered File Fragments
@%systemroot%\system32\wdi.dll,-502 : Diagnostic Service Host
@%systemroot%\system32\pnrpsvc.dll,-8001 : Enables serverless peer name resolution over the Internet using the Peer Name Resolution Protocol (PNRP). If disabled, some peer-to-peer and collaborative applications, such as Remote Assistance, may not function.
@peerdistsh.dll,-9000 : BranchCache - Content Retrieval (Uses HTTP)
@c:\programdata\microsoft\windows defender\platform\4.18.25110.5-0\mpasdesc.dll,-320 : Microsoft Defender Antivirus Network Inspection Service
@%systemroot%\system32\appreadiness.dll,-1001 : Gets apps ready for use the first time a user signs in to this PC and when adding new apps.
@%systemroot%\system32\wephostsvc.dll,-100 : Windows Encryption Provider Host Service
c:\windows\system32,@elscore.dll,-10 : Microsoft Hangul Decomposition Transliteration
@c:\programdata\microsoft\windows defender\platform\4.18.25100.9008-0\mpasdesc.dll,-242 : Helps guard against intrusion attempts targeting known and newly discovered vulnerabilities in network protocols
@%systemroot%\system32\audioendpointbuilder.dll,-205 : Manages audio devices for the Windows Audio service. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start
@%systemroot%\system32\mprmsg.dll,-32013 : IP Traffic Filter Driver
@c:\programdata\microsoft\windows defender\platform\4.18.25080.5-0\mpasdesc.dll,-244 : Monitors the availability, health, and performance of various security components
@%systemroot%\system32\firewallapi.dll,-23091 : Windows Defender Firewall helps protect your computer by preventing unauthorized users from gaining access to your computer through the Internet or a network.
@%systemroot%\system32\cbdhsvc.dll,-100 : Clipboard User Service
@%systemroot%\system32\ikeext.dll,-502 : The IKEEXT service hosts the Internet Key Exchange (IKE) and Authenticated Internet Protocol (AuthIP) keying modules. These keying modules are used for authentication and key exchange in Internet Protocol security (IPsec). Stopping or disabling the IKEEXT service will disable IKE and AuthIP key exchange with peer computers. IPsec is typically configured to use IKE or AuthIP; therefore, stopping or disabling the IKEEXT service might result in an IPsec failure and might compromise the security of the system. It is strongly recommended that you have the IKEEXT service running.
@%systemroot%\system32\dcsvc.dll,-101 : Declared Configuration(DC) service
@%programfiles%\windows defender advanced threat protection\mssense.exe,-1002 : Windows Defender Advanced Threat Protection service helps protect against advanced threats by monitoring and reporting security events that happen on the computer.
@%systemroot%\system32\frameservermonitor.dll,-101 : Monitors the health and state for the Windows Camera Frame Server service.
@%systemroot%\syswow64\perfhost.exe,-2 : Performance Counter DLL Host
@%systemroot%\system32\moshost.dll,-100 : Downloaded Maps Manager
@c:\programdata\microsoft\windows defender\platform\4.18.25100.9008-0\mpasdesc.dll,-390 : Microsoft Defender Antivirus Boot Driver
@%systemroot%\system32\wephostsvc.dll,-101 : Windows Encryption Provider Host Service brokers encryption related functionalities from 3rd Party Encryption Providers to processes that need to evaluate and apply EAS policies. Stopping this will compromise EAS compliancy checks that have been established by the connected Mail Accounts
@%systemroot%\system32\upnphost.dll,-213 : UPnP Device Host
@%systemroot%\system32\nsisvc.dll,-201 : This service delivers network notifications (e.g. interface addition/deleting etc) to user mode clients. Stopping this service will cause loss of network connectivity. If this service is disabled, any other services that explicitly depend on this service will fail to start.
@%systemroot%\system32\drivers\luafv.sys,-100 : UAC File Virtualization
@%systemroot%\system32\pushtoinstall.dll,-200 : Windows PushToInstall Service
@%systemroot%\system32\mprmsg.dll,-32000 : RAS Asynchronous Media Driver
@%systemroot%\system32\netsetupsvc.dll,-4 : The Network Setup Service manages the installation of network drivers and permits the configuration of low-level network settings. If this service is stopped, any driver installations that are in-progress may be cancelled.
@%systemroot%\system32\semgrsvc.dll,-1002 : Manages payments and Near Field Communication (NFC) based secure elements.
@%systemroot%\microsoft.net\framework64\v4.0.30319\servicemodelinstallrc.dll,-8198 : Receives activation requests over the net.tcp protocol and passes them to the Windows Process Activation Service.
@%systemroot%\system32\dialogblockingservice.dll,-100 : DialogBlockingService
@%systemroot%\system32\smsroutersvc.dll,-10001 : Microsoft Windows SMS Router Service.
@%systemroot%\system32\wersvc.dll,-100 : Windows Error Reporting Service
@%systemroot%\system32\securityhealthagent.dll,-1002 : Windows Security Service
@%systemroot%\system32\wuaueng.dll,-106 : Enables the detection, download, and installation of updates for Windows and other programs. If this service is disabled, users of this computer will not be able to use Windows Update or its automatic updating feature, and programs will not be able to use the Windows Update Agent (WUA) API.
@%systemroot%\system32\ncasvc.dll,-3009 : Network Connectivity Assistant
@regsvc.dll,-1 : Remote Registry
@%systemroot%\system32\microsoft.graphics.display.displayenhancementservice.dll,-1000 : Display Enhancement Service
@%systemroot%\system32\appreadiness.dll,-1000 : App Readiness
@wlansvc.dll,-36865 : WLAN Service - WFD Services Kernel Mode Driver Rules
@%systemroot%\system32\drivers\executioncontext.sys,-101 : CPU Scheduler for High Performance I/O
@%systemroot%\system32\cryptsvc.dll,-1002 : Provides three management services: Catalog Database Service, which confirms the signatures of Windows files and allows new programs to be installed; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Automatic Root Certificate Update Service, which retrieves root certificates from Windows Update and enable scenarios such as SSL. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\umpo.dll,-101 : Manages power policy and power policy notification delivery.
@%systemroot%\system32\p2psvc.dll,-8007 : Enables multi-party communication using Peer-to-Peer Grouping. If disabled, some applications, such as HomeGroup, may not function.
@%systemroot%\system32\vds.exe,-100 : Virtual Disk
@%systemroot%\system32\drivers\filecrypt.sys,-100 : FileCrypt
@appmgmts.dll,-3250 : Application Management
@%systemroot%\system32\powrprof.dll,-13 : High performance
@c:\programdata\microsoft\windows defender\platform\4.18.25110.6-0\mpasdesc.dll,-320 : Microsoft Defender Antivirus Network Inspection Service
@enterpriseappmgmtsvc.dll,-1 : Enterprise App Management Service
@c:\programdata\microsoft\windows defender\platform\4.18.25090.3009-0\mpasdesc.dll,-320 : Microsoft Defender Antivirus Network Inspection Service
@%systemroot%\system32\icsvc.dll,-802 : Provides an interface for the Hyper-V host to interact with specific services running inside the virtual machine.
@%systemroot%\system32\fxsresm.dll,-118 : Fax
@%systemroot%\system32\wiarpc.dll,-1 : Launches applications associated with still image acquisition events.
@c:\programdata\microsoft\windows defender\platform\4.18.25110.5-0\mpasdesc.dll,-370 : Microsoft Defender Antivirus Network Inspection System Driver
@%systemroot%\system32\semgrsvc.dll,-1001 : Payments and NFC/SE Manager
@%systemroot%\system32\sharedrealitysvc.dll,-100 : Spatial Data Service
@%systemroot%\system32\graphicsperfsvc.dll,-100 : GraphicsPerfSvc
@%systemroot%\system32\drivers\fvevol.sys,-100 : BitLocker Drive Encryption Filter Driver
@%systemroot%\system32\mixedrealityruntime.dll,-102 : Enables Mixed Reality OpenXR runtime functionality
@%systemroot%\system32\drivers\mssecwfp.sys,-1001 : Microsoft Security WFP Callout Driver
@%systemroot%\system32\lfsvc.dll,-1 : Geolocation Service
@firewallapi.dll,-50324 : Receives trap messages generated by local or remote Simple Network Management Protocol (SNMP) agents and forwards the messages to SNMP management programs running on this computer. If this service is stopped, SNMP-based programs on this computer will not receive SNMP trap messages. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\drivers\mup.sys,-101 : MUP
@peerdistsh.dll,-9001 : BranchCache - Peer Discovery (Uses WSD)
@%systemroot%\system32\drivers\wimmount.sys,-101 : WIMMount
@%systemroot%\system32\aarsvc.dll,-100 : Agent Activation Runtime
@%systemroot%\system32\moshost.dll,-101 : Windows service for application access to downloaded maps. This service is started on-demand by application accessing downloaded maps. Disabling this service will prevent apps from accessing maps.
@%windir%\system32\inetsrv\iisres.dll,-30015 : Provides W3C logging for Internet Information Services (IIS). If this service is stopped, W3C logging configured by IIS will not work.
@%systemroot%\system32\drivers\vwififlt.sys,-259 : Virtual WiFi Filter Driver
@%systemroot%\system32\messagingservice.dll,-100 : MessagingService
@%systemroot%\system32\scardsvr.dll,-1 : Smart Card
@%systemroot%\system32\drivers\dam.sys,-100 : Desktop Activity Moderator Driver
@%systemroot%\system32\dps.dll,-501 : The Diagnostic Policy Service enables problem detection, troubleshooting and resolution for Windows components. If this service is stopped, diagnostics will no longer function.
@%windir%\system32\lsm.dll,-1002 : Core Windows Service that manages local user sessions. Stopping or disabling this service will result in system instability.
@%systemroot%\system32\deviceaccess.dll,-107 : DeviceAssociationBroker
@%systemroot%\system32\wwansvc.dll,-258 : This service manages mobile broadband (GSM & CDMA) data card/embedded module adapters and connections by auto-configuring the networks. It is strongly recommended that this service be kept running for best user experience of mobile broadband devices.
@%systemroot%\system32\cloudidsvc.dll,-101 : Supports integrations with Microsoft cloud identity services. If disabled, tenant restrictions will not be enforced properly.
@%systemroot%\system32\lltdres.dll,-1 : Link-Layer Topology Discovery Mapper
@%systemroot%\system32\btagservice.dll,-101 : Bluetooth Audio Gateway Service
@%systemroot%\system32\srpapi.dll,-100 : AppID Driver
@%systemroot%\system32\usermgr.dll,-101 : User Manager provides the runtime components required for multi-user interaction. If this service is stopped, some applications may not operate correctly.
@%systemroot%\system32\ajrouter.dll,-2 : AllJoyn Router Service
@%systemroot%\system32\wecsvc.dll,-200 : Windows Event Collector
@%systemroot%\system32\dusmsvc.dll,-2 : Network data usage, data limit, restrict background data, metered networks.
@%systemroot%\system32\drivers\nsiproxy.sys,-2 : NSI Proxy Service Driver
@%systemroot%\system32\xboxgipsvc.dll,-100 : Xbox Accessory Management Service
@%systemroot%\system32\sens.dll,-201 : Monitors system events and notifies subscribers to COM+ Event System of these events.
@%systemroot%\system32\bthserv.dll,-102 : The Bluetooth service supports discovery and association of remote Bluetooth devices. Stopping or disabling this service may cause already installed Bluetooth devices to fail to operate properly and prevent new devices from being discovered or associated.
@%systemroot%\system32\drivers\tcpip.sys,-10001 : TCP/IP Protocol Driver
@%systemroot%\system32\ssdpsrv.dll,-101 : Discovers networked devices and services that use the SSDP discovery protocol, such as UPnP devices. Also announces SSDP devices and services running on the local computer. If this service is stopped, SSDP-based devices will not be discovered. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\vac.dll,-200 : Volumetric Audio Compositor Service
@%systemroot%\system32\aphostres.dll,-10001 : This service synchronizes mail, contacts, calendar and various other user data. Mail and other applications dependent on this functionality will not work properly when this service is not running.
@%systemroot%\system32\drivers\mmcss.sys,-100 : Multimedia Class Scheduler
@%systemroot%\system32\tzautoupdate.dll,-200 : Auto Time Zone Updater
@%systemroot%\system32\profsvc.dll,-301 : This service is responsible for loading and unloading user profiles. If this service is stopped or disabled, users will no longer be able to successfully sign in or sign out, apps might have problems getting to users' data, and components registered to receive profile event notifications won't receive them.
@%systemroot%\system32\vaultsvc.dll,-1003 : Credential Manager
@%systemroot%\system32\certprop.dll,-13 : Smart Card Removal Policy
@comres.dll,-948 : Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\seclogon.dll,-7000 : Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\mprmsg.dll,-32014 : Remote Access LEGACY NDIS WAN Driver
@%systemroot%\system32\devicesflowbroker.dll,-104 : Allows ConnectUX and PC Settings to Connect and Pair with WiFi displays and Bluetooth devices.
@%systemroot%\system32\vac.dll,-201 : Hosts spatial analysis for Mixed Reality audio simulation.
@%systemroot%\system32\fhsvc.dll,-102 : Protects user files from accidental loss by copying them to a backup location
@waasmedicsvc.dll,-101 : Enables remediation and protection of Windows Update components.
@%systemroot%\system32\wbem\wmisvc.dll,-204 : Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\bdesvc.dll,-101 : BDESVC hosts the BitLocker Drive Encryption service. BitLocker Drive Encryption provides secure startup for the operating system, as well as full volume encryption for OS, fixed or removable volumes. This service allows BitLocker to prompt users for various actions related to their volumes when mounted, and unlocks volumes automatically without user interaction. Additionally, it stores recovery information to Active Directory, if available, and, if necessary, ensures the most recent recovery certificates are used. Stopping or disabling the service would prevent users from leveraging this functionality.
@%systemroot%\system32\firewallapi.dll,-60501 : Cloud Identity
@%systemroot%\system32\btagservice.dll,-102 : Service supporting the audio gateway role of the Bluetooth Handsfree Profile.
@%systemroot%\system32\perceptionsimulation\perceptionsimulationservice.exe,-102 : Enables spatial perception simulation, virtual camera management and spatial input simulation.
@%systemroot%\system32\sppsvc.exe,-100 : Enables the download, installation and enforcement of digital licenses for Windows and Windows applications. If the service is disabled, the operating system and licensed applications may run in a notification mode. It is strongly recommended that you not disable the Software Protection service.
@%systemroot%\system32\vaultsvc.dll,-1004 : Provides secure storage and retrieval of credentials to users, applications and security service packages.
@%systemroot%\system32\vssvc.exe,-102 : Volume Shadow Copy
@%systemroot%\system32\icsvc.dll,-101 : Hyper-V Heartbeat Service
@%systemroot%\system32\pnrpauto.dll,-8002 : PNRP Machine Name Publication Service
@%systemroot%\system32\perceptionsimulation\perceptionsimulationservice.exe,-101 : Windows Perception Simulation Service
@%systemroot%\system32\fveui.dll,-843 : BitLocker Drive Encryption
@%systemroot%\system32\tapisrv.dll,-10101 : Provides Telephony API (TAPI) support for programs that control telephony devices on the local computer and, through the LAN, on servers that are also running the service.
@%systemroot%\system32\licensemanagersvc.dll,-201 : Provides infrastructure support for the Microsoft Store. This service is started on demand and if disabled then content acquired through the Microsoft Store will not function properly.
@%systemroot%\system32\drivers\ehstorclass.sys,-100 : Enhanced Storage Filter Driver
@%systemroot%\system32\drivers\mslldp.sys,-200 : Microsoft Link-Layer Discovery Protocol
@%systemroot%\system32\frameserver.dll,-100 : Windows Camera Frame Server
@%systemroot%\system32\userdataaccessres.dll,-14000 : Provides apps access to structured user data, including contact info, calendars, messages, and other content. If you stop or disable this service, apps that use this data might not work correctly.
@%systemroot%\system32\wkssvc.dll,-1002 : SMB MiniRedirector Wrapper and Engine
@%systemroot%\system32\hidserv.dll,-102 : Activates and maintains the use of hot buttons on keyboards, remote controls, and other multimedia devices. It is recommended that you keep this service running.
@%systemroot%\system32\wbem\wmiapsrv.exe,-111 : Provides performance library information from Windows Management Instrumentation (WMI) providers to clients on the network. This service only runs when Performance Data Helper is activated.
@%systemroot%\system32\wuaueng.dll,-400 : Windows Update
@%programfiles%\windows media player\wmpnetwk.exe,-102 : Shares Windows Media Player libraries to other networked players and media devices using Universal Plug and Play
@%systemroot%\system32\drivers\ndisimplatform.sys,-501 : Microsoft Network Adapter Multiplexor Protocol
@c:\programdata\microsoft\windows defender\platform\4.18.25090.3009-0\mpasdesc.dll,-390 : Microsoft Defender Antivirus Boot Driver
@%systemroot%\system32\qwave.dll,-2 : Quality Windows Audio Video Experience (qWave) is a networking platform for Audio Video (AV) streaming applications on IP home networks. qWave enhances AV streaming performance and reliability by ensuring network quality-of-service (QoS) for AV applications. It provides mechanisms for admission control, run time monitoring and enforcement, application feedback, and traffic prioritization.
@c:\programdata\microsoft\windows defender\platform\4.18.25110.5-0\mpasdesc.dll,-310 : Microsoft Defender Antivirus Service
@%systemroot%\system32\userdataaccessres.dll,-15000 : Indexes contact data for fast contact searching. If you stop or disable this service, contacts might be missing from your search results.
@%systemroot%\system32\appinfo.dll,-100 : Application Information
@%systemroot%\system32\mixedrealityruntime.dll,-101 : Windows Mixed Reality OpenXR Service
@comres.dll,-2797 : Distributed Transaction Coordinator
@%systemroot%\system32\spoolsv.exe,-2 : This service spools print jobs and handles interaction with the printer. If you turn off this service, you won’t be able to print or see your printers.
@%systemroot%\system32\drivers\mpsdrv.sys,-23092 : Windows Defender Firewall Authorization Driver
@%systemroot%\system32\userdataaccessres.dll,-14001 : User Data Access
@%systemroot%\system32\themeservice.dll,-8193 : Provides user experience theme management.
@%systemroot%\system32\dispbroker.desktop.dll,-102 : Manages the connection and configuration of local and remote displays
@%windir%\system32\timebrokerserver.dll,-1002 : Coordinates execution of background work for WinRT application. If this service is stopped or disabled, then background work might not be triggered.
@%systemroot%\system32\wlansvc.dll,-257 : WLAN AutoConfig
@%systemroot%\system32\fdphost.dll,-101 : The FDPHOST service hosts the Function Discovery (FD) network discovery providers. These FD providers supply network discovery services for the Simple Services Discovery Protocol (SSDP) and Web Services – Discovery (WS-D) protocol. Stopping or disabling the FDPHOST service will disable network discovery for these protocols when using FD. When this service is unavailable, network services using FD and relying on these discovery protocols will be unable to find network devices or resources.
@%systemroot%\system32\firewallapi.dll,-38521 : World Wide Web Services (HTTP)
@%systemroot%\system32\drivers\ndproxy.sys,-6000 : NDIS Proxy Driver
@%systemroot%\system32\drivers\qwavedrv.sys,-1 : QWAVE driver
@%systemroot%\system32\svsvc.dll,-101 : Spot Verifier
@%systemroot%\system32\diagsvc.dll,-101 : Executes diagnostic actions for troubleshooting support
@%systemroot%\system32\agentservice.exe,-102 : User Experience Virtualization Service
@%systemroot%\system32\cryptsvc.dll,-1001 : Cryptographic Services
@%systemroot%\system32\wfdsconmgrsvc.dll,-9000 : Wi-Fi Direct Services Connection Manager Service
@%systemroot%\system32\mprmsg.dll,-32011 : Remote Access IP ARP Driver
@%systemroot%\system32\devquerybroker.dll,-101 : Enables apps to discover devices with a backgroud task
@%systemroot%\system32\licensemanagersvc.dll,-200 : Windows License Manager Service
@%systemroot%\system32\xblauthmanager.dll,-100 : Xbox Live Auth Manager
@%systemroot%\system32\netprofmsvc.dll,-209 : Collects and stores configuration information for the network and notifies programs when this information is modified. If this service is stopped, configuration information might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\sharedrealitysvc.dll,-101 : This service is used for Spatial Perception scenarios
@%systemroot%\system32\drivers\verifierext.sys,-1000 : Driver Verifier Extension
@%systemroot%\system32\devicesflowbroker.dll,-103 : DevicesFlow
@%systemroot%\system32\wkssvc.dll,-101 : Creates and maintains client network connections to remote servers using the SMB protocol. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\dssvc.dll,-10002 : Provides data brokering between applications.
@%systemroot%\system32\credentialenrollmentmanager.exe,-101 : Credential Enrollment Manager
@%systemroot%\system32\pcasvc.dll,-2 : This service provides support for the Program Compatibility Assistant (PCA). PCA monitors programs installed and run by the user and detects known compatibility problems. If this service is stopped, PCA will not function properly.
@c:\programdata\microsoft\windows defender\platform\4.18.25100.9008-0\mpasdesc.dll,-240 : Helps protect users from malware and other potentially unwanted software
@%systemroot%\system32\dnsapi.dll,-102 : The DNS Client service (dnscache) caches Domain Name System (DNS) names and registers the full computer name for this computer. If the service is stopped, DNS names will continue to be resolved. However, the results of DNS name queries will not be cached and the computer's name will not be registered. If the service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\wkssvc.dll,-1006 : SMB 2.0 MiniRedirector
@%windir%\system32\inetsrv\iisres.dll,-30012 : Provides administrative services for IIS, for example configuration history and Application Pool account mapping. If this service is stopped, configuration history and locking down files or directories with Application Pool specific Access Control Entries will not work.
@%systemroot%\system32\powrprof.dll,-10 : Saves energy by reducing your computer's performance where possible.
@%systemroot%\system32\fhsvc.dll,-101 : File History Service
@%systemroot%\system32\lfsvc.dll,-2 : This service monitors the current location of the system and manages geofences (a geographical location with associated events). If you turn off this service, applications will be unable to use or receive notifications for geolocation or geofences.
@%systemroot%\system32\flightsettings.dll,-104 : Provides infrastructure support for the Windows Insider Program. This service must remain enabled for the Windows Insider Program to work.
@%systemroot%\system32\workfolderssvc.dll,-102 : Work Folders
@%systemroot%\system32\drivers\tunnel.sys,-500 : Microsoft Tunnel Miniport Adapter Driver
@%systemroot%\system32\tieringengineservice.exe,-702 : Storage Tiers Management
@%systemroot%\system32\dhcpcore.dll,-101 : Registers and updates IP addresses and DNS records for this computer. If this service is stopped, this computer will not receive dynamic IP addresses and DNS updates. If this service is disabled, any services that explicitly depend on it will fail to start.
@regsvc.dll,-2 : Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start.
@%systemroot%\system32\qmgr.dll,-1000 : Background Intelligent Transfer Service
@c:\programdata\microsoft\windows defender\platform\4.18.25080.5-0\mpasdesc.dll,-370 : Microsoft Defender Antivirus Network Inspection System Driver
@%systemroot%\system32\clipsvc.dll,-103 : Client License Service (ClipSVC)
@c:\programdata\microsoft\windows defender\platform\4.18.25110.5-0\mpasdesc.dll,-340 : Microsoft Defender Antivirus On-Access Malware Protection Mini-Filter Driver
@%systemroot%\system32\xblgamesave.dll,-100 : Xbox Live Game Save
@%systemroot%\system32\fntcache.dll,-101 : Optimizes performance of applications by caching commonly used font data. Applications will start this service if it is not already running. It can be disabled, though doing so will degrade application performance.
@%systemroot%\system32\hvhostsvc.dll,-100 : HV Host Service
@%systemroot%\system32\sdrsvc.dll,-107 : Windows Backup
@%systemroot%\system32\locator.exe,-2 : Remote Procedure Call (RPC) Locator
@%systemroot%\system32\messagingservice.dll,-101 : Service supporting text messaging and related functionality.
@%systemroot%\system32\firewallapi.dll,-38523 : Secure World Wide Web Services (HTTPS)
@%systemroot%\system32\ipxlatcfg.dll,-501 : Configures and enables translation from v4 to v6 and vice versa
@%systemroot%\system32\drivers\volsnap.sys,-100 : Volume Shadow Copy driver
@%systemroot%\system32\wpnservice.dll,-1 : Windows Push Notifications System Service
@%systemroot%\system32\dssvc.dll,-10003 : Data Sharing Service
@%systemroot%\system32\sensrsvc.dll,-1000 : Sensor Monitoring Service
@%systemroot%\system32\seclogon.dll,-7001 : Secondary Logon
@%systemroot%\system32\wpnuserservice.dll,-2 : This service hosts Windows notification platform which provides support for local and push notifications. Supported notifications are tile, toast and raw.
@%systemroot%\system32\windows.internal.management.dll,-101 : Performs Device Enrollment Activities for Device Management
@%systemroot%\system32\drivers\iorate.sys,-101 : Disk I/O Rate Filter Driver
@%systemroot%\system32\shsvcs.dll,-12289 : Provides notifications for AutoPlay hardware events.
@%systemroot%\system32\netman.dll,-109 : Network Connections
@%systemroot%\system32\drivers\filetrace.sys,-10001 : FileTrace
@%systemroot%\system32\devicesetupmanager.dll,-1001 : Enables the detection, download and installation of device-related software. If this service is disabled, devices may be configured with outdated software, and may not work correctly.
@%systemroot%\system32\wersvc.dll,-101 : Allows errors to be reported when programs stop working or responding and allows existing solutions to be delivered. Also allows logs to be generated for diagnostic and repair services. If this service is stopped, error reporting might not work correctly and results of diagnostic services and repairs might not be displayed.
@%systemroot%\system32\dosvc.dll,-100 : Delivery Optimization
@%systemroot%\system32\storsvc.dll,-100 : Storage Service
@%systemroot%\system32\smsroutersvc.dll,-10002 : Routes messages based on rules to appropriate clients.
@%systemroot%\system32\windowsudkservices.shellcommon.dll,-100 : Udk User Service
MUICache report attached.