The svchost.exe file is a common host process name for services running from the dynamic link library. The most basic system processes are that these processes are the basic conditions for system operation, with these processes, the system can run normally): smss.exe Session Manager csrss.exe sub-system server process winlogon.exe management user (guest services.exe contains many system services, lsass.exe manages IP Security Policies and starts ISAKMP/Oakley IKE) and IP Security drivers. System Service)
Generate a session key and assign the service credenet ticket for Interactive Client/Server Authentication ). System Service)
The svchost.exe package contains many system services, svchost.exe SPOOLSV. EXE, which load the file into the memory for later printing. System Service)
System Processes attached to the pinyin icon in the explorer.exe Resource Manager internat.exe tray are not necessary. You can use the service manager to increase or decrease these processes as needed.): mstask.exe allows programs to run at a specified time. System Service)
Regsvc.exe allows remote registry operations. System Service)
Winmgmt.exe provides System Management Information System Services ).
Inetinfo.exe provides FTP connection and management through the management unit of Internet Information Service. System Service)
Tlntsvr.exe allows a remote user to log on to the system and run the console program using the command line. System Service)
Allows you to manage Web and FTP services through the management units of Internet Information Services. System Service)
Tftpd.exe implements the TFTP Internet standard. The user name and password are not required for this standard. Part of the Remote Installation service. System Service)
Termsrv.exe provides a multi-session environment that allows client devices to access virtual Windows 2000 Professional desktop sessions and Windows-based programs running on servers. System Service)
Dns.exe responds to the query and update request for the Domain Name System DNS) Name. System Service)
The following services are rarely used. All services in the same region are secure. If this is not necessary, disable tcpsvcs.exe to provide the ability to remotely start Windows 2000 Professional installation on the client's computer on PXE. System Service)
The following TCP/IP Services are supported: Character Generator, Daytime, Discard, Echo, and Quote of the Day. System Service)
Ismserv.exe allows sending and receiving messages between Windows Advanced Server sites. System Service)
Ups.exe manages the Uninterruptible Power UPS that is connected to the computer ). System Service)
Wins.exe provides the NetBIOS Name Service for TCP/IP customers who register and resolve NetBIOS names. System Service)
Llssrv.exe License Logging Servicesystem service)
Ntfrs.exe maintains file synchronization between multiple servers in the file directory. System Service)
RsSub.exe controls the media used to remotely store data. System Service)
Locator.exe manages the RPC Name Service database. System Service)
Lserver.exe registers the client license. System Service)
Dfssvc.exe manages logical volumes distributed on the LAN or WAN. System Service)
Clipsrv.exe supports "Clipboard viewer", so that you can view the clipboard page remotely. System Service)
Msdtc.exe is a parallel transaction that is distributed in more than two databases, message queues, file systems, or other transaction protection resource managers. System Service)
Faxsvc.exe helps you send and receive faxes. System Service)
Cisvc.exe Indexing Servicesystem service)
Dmadmin.exe System Management Service for disk management requests. System Service)
Mnmsrvc.exe allows authorized users to remotely access Windows desktops using NetMeeting. System Service)
Netdde.exe provides Dynamic Data Exchange (DDE) network transmission and security features. System Service)
Smlogsvc.exe configure Performance Logs and alarms. System Service)
Rsvp.exe provides network signal and local communication control installation for programs and control applications that depend on QoS. System Service)
RsEng.exe is a service and management tool that stores infrequently used data. System Service)
RsFsa.exe Manages objects stored remotely. System Service)
Grovel.exe scans duplicate files on the zero-backup storage SIS) volume and points the duplicate files to a data storage point to save disk space. System Service)
SCardSvr.exe manages and controls access to smart cards inserted into smart card readers. System Service)
Snmp.exe contains a proxy program that can monitor activities of network devices and report to the Network Console workstation. System Service)
Snmptrap.exe Receives trap messages generated by local or remote SNMP agents, and then transmits the messages to the SNMP manager running on this computer. System Service)
UtilMan.exe starts and configures the auxiliary tool from a window. System Service)
Msiexec.exe installs, repairs, and deletes software based on the commands in the. MSI file. System Service)
The Svchost.exe file of win2kruntime is a common host process name for services running from the dynamic Connection Library. The Svhost.exe file is located in the % systemroot % \ system32 folder of the system. At the startup time, svchost.exe checks the location in the Registry to build the list of services to be loaded. This will allow multiple svchost.exe to run at the same time. Each session of svchost.execontains a set of services, so that the unique service depends on how and where svchost.exe is started. This makes it easier to control and locate errors.
The Svchost.exe group is identified by the following registry values.
HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows NT \ CurrentVersion \ Svchost each value under this key represents an independent Svchost group, and when you are watching the active process, it is shown as a separate example. Each key value is of the REG_MULTI_SZ type and includes services running in the Svchost group. Each Svchost group contains one or more service names selected from the registry value. The service parameter value contains a ServiceDLL value.
HKEY_LOCAL_MACHINE \ System \ CurrentControlSet \ Services \ Service
For more information, see the services that are running in the Svchost list.
Start-run-press cmd and then enter tlist-s tlist. It should be the winter in the win2k toolbox)
Tlist displays a list of active processes. Switch-s to display the list of active services in each process. If you want more information about the process, you can tap the tlist pid.
Tlist displays two examples of svchost.exe running.
0 System Process 8 System 132 smss.exe 160 csrss.exe Title: 180 winlogon.exe Title: NetDDE Agent 208services.exe Svcs: AppMgmt, Browser, Dhcp, dmserver, Dnscache, Eventlog, lanmanserver, LanmanWorkstation, LmHosts, Messenger, plugPlay, ProtectedStorage, seclogon, TrkWks, W32Time, Wmi 220 lsass.exe Svcs: Netlogon, yyagent, SamSs 404 svchost.exe Svcs: RpcSs 452 kernel Svcs: Spooler 544 cisvc.exe Svcs: cisvc 5 56 svchost.exe Svcs: EventSystem, Netman, NtmsSvc, RasMan, SENS, TapiSrv 580 regsvc.exe Svcs: Limit 596 limit Svcs: Schedule 660 snmp.exe Svcs: SNMP 728 winmgmt.exe Svcs: WinMgmt 852 limit Title: oleMainThreadWndName 812 assumer.exe Title: Program Manager 1032 OSA. EXE Title: Reminder 1300 cmd.exe Title: D: \ WINNT5 \ System32 \ cmd.exe-tlist-s 1080 MAPISP32.EXE Title: WMS Idle 12XX r Undll32.exe Title: 1000 mmc.exe Title: Device Manager 1144 tlist.exe in this example, the Registry sets two groups.
Alibaba \ Software \ Microsoft \ Windows NT \ CurrentVersion \ Svchost: netsvcs: Reg_Multi_SZ: EventSystem Ias Iprip Irmon Netman Nwsapagent Rasauto Rasman Remoteaccess SENS Sharedaccess Tapisrv Ntmssvc rpcss: kernel: RpcSs
This is part of the user mode Win32 subsystem. Csrss stands for the customer/server operation subsystem and is a basic subsystem that must always run. Csrss controls windows, creates or deletes threads, and some 16-bit virtual MS-DOS environments.
Assumer.exe is a user's shell. I really don't know how to translate the shell.) in this case, it looks like a task bar, a desktop, and so on. This process does not run as an important process in windows as you think. You can stop it from the task manager or restart it. Generally, it does not have any negative impact on the system.
Internat.exe can be disabled from the task manager.
Internat.exe starts running at startup. It loads different input points specified by the user. The Input Point is from the Registry location HKEY_USERS \. DEFAULT \ Keyboard Layout \ Preload to load the content.
Internat.exe loads the "EN" icon into the system's icon area, allowing users to easily convert different input points. When the process is stopped, the icon disappears, but the input point can still be changed through the control panel.
The lsass.exe process cannot be switched off from the task manager.
This is a local security authorization service, and it will generate a process for authorized users using the winlogon service. This process is executed by using an authorized package, such as the default msgina. dll. If the authorization succeeds, lsass will generate the user's access token. Do not use the token to start the initial shell. Other user-initiated processes will inherit the token.
The mstask.exe process cannot be switched off from the task manager. This is a task scheduling service, which allows you to determine the running of a task at a specific time in advance.
The process smss.exe cannot be switched off from the task manager.
This is a session management subsystem that starts user sessions. This process is a reflection of the running winlogon,win32csrss.exe threads and set system variables of many concurrent activities. After it starts these processes, it waits until Winlogon or Csrss ends. If these processes are normal, the system will shut down. If something unexpected occurs, smss.exe will suspend the system to stop responding ).
Spoolsv.exe cannot be switched off from the task manager. Buffer spooler) service is used to manage print and fax jobs in the buffer pool.
Service.exe cannot be switched off from the task manager. Most of the system's core mode processes are running as system processes.
System Idle Process cannot be switched off from the task manager. This process runs on each processor as a single thread and distributes the Time of the processor when the system does not process other threads.
Taskmagr.exe can be disabled in the task manager.
This process is the task manager.
Winlogon.exe is a process used to manage user logon and launch. Winlogon is activated when you press CTRL + ALT + DEL to display the security dialog box.
Winmgmt.exe winmgmt is the core component of win2000 Client Management. This process is initialized when the client application is connected or when the administrator needs its own services