Detailed explanation and suggestions of Win 7 service
Adaptive brightness
Monitor the ambient light sensor, detect the change of ambient light and adjust the brightness of the display. If this service is stopped or disabled, the display brightness will not be adjusted according to the lighting conditions.
The default operation mode of this service is manual. If you don't use smart devices such as touch screen to adjust the screen brightness, you can safely disable this function.
Application experience
Handles application compatibility cache requests for applications at startup.
The default operation mode of this service is automatic, and manual operation is recommended.
Application information
Using auxiliary administrative rights is helpful to the operation of interactive applications. If this service is stopped, users will not be able to start applications with the auxiliary administrative rights required to perform the required user tasks.
The default operation mode of this service is manual, and it is not recommended to change it.
Application layer gateway service
Third-party protocol plug-in support for Internet connection * * *
If a third-party firewall is installed, you don't need to use ICS to enjoy the Internet, and you can completely disable it.
application management
Handle installation, deletion and enumeration requests of software deployed through group policy. If this service is disabled, users will not be able to install, remove or enumerate software deployed through Group Policy. If this service is disabled, all services that directly depend on it will fail to start.
The default operation mode of this service is manual, which is mainly suitable for centralized management in large enterprise environment, and home users can safely disable this service.
Ati external event utility
This process will occur if the ATI graphics driver is installed. It is recommended to do it manually.
Background Intelligent Transfer Service
Use idle network bandwidth to transfer files in the background. If this service is disabled, any application that relies on BITS, such as Windows Update or MSN Explorer, will not be able to automatically download programs and other information.
This service is mainly used for WindowsUpdate or automatic update, and can be completely disabled if it is updated with an update package.
Basic filtering engine
Basic Filtering Engine (BFE) is a service that manages firewall and Internet Protocol Security (IPsec) policies and implements user mode filtering. Stopping or disabling BFE service will greatly reduce the security of the system. It can also lead to unpredictable behavior of IPsec management and firewall applications. It also provides dependent services for system firewall, VPN and IPsec, and is also a service for system security. If you use the third-party VPN dialing software, you can enjoy surfing the Internet without using the system firewall and ICS***. For the sake of system resources, turn it off, or don't touch it.
BitLocker drive encryption service
BDESVC hosts BitLocker drive encryption service. BitLocker drive encryption provides safe boot guarantee for operating system, and provides full volume encryption function for OS, fixed volume and removable volume. Through this service, BitLocker can prompt users to perform various operations related to the installed volume, and automatically unlock the volume without user interaction. In addition, it stores recovery information in Active Directory (if this method is available and needs to be executed) and ensures that the latest recovery certificate is used. Stopping or disabling this service will prevent users from using this feature. The default operation mode of this service is manual, and this function can be safely disabled without using BitLocker devices.
Block level backup engine service
An engine that performs block-level backup and recovery. It is estimated that it has nothing to do with the service used for backup and recovery. The default is manual, and it has never been started by him. Just leave it there. It doesn't matter.
Bluetooth support service
Bluetooth service supports the discovery and association of remote Bluetooth devices. Stopping or disabling this service may prevent the installed Bluetooth devices from operating normally and prevent the discovery and association of new devices. The default operation mode of this service is manual. If you don't use a Bluetooth device, you can safely disable this feature.
Certificate dissemination
Provide certificates for smart cards. The default running mode of this service is manual. If you don't use a smart card, you can safely disable the service.
CNG bond isolation
The CNG key isolation service is hosted in the LSA process. According to the requirements of general principles, this service provides key process isolation for private keys and related encryption operations. This service stores and uses long-term keys in a secure process that meets the requirements of general principles. If the wired auto-configuration /WLAN auto-configuration services are turned on and EAP (Extensible Authentication Protocol) is used, this service will be used. It is suggested that those without automatic wired network configuration and wireless network can be turned off.
COM+ event system
Support system event notification service (SENS), and provide automatic event distribution function for subscribed component object model (COM) components. If this service is stopped, SENS will shut down and cannot provide login and logout notifications. If this service is disabled, other services that explicitly depend on it will fail to start.
A very primitive and ancient service, the default running mode of this service is automatic, which is an important system service. If it is set to manual, it will also run automatically. If it is set to disabled, it doesn't seem to matter, but there will be many errors in the log. We'd better not move.
COM+ system application program
Manage the configuration and tracking of components based on component object model (COM+). If this service is stopped, most COM+-based components will not work properly. If this service is disabled, any services that explicitly depend on it will fail to start.
Obviously, the previous COM+ programs even IIS/. NET applications will use this service. As long as it is not disabled, it is basically a service that rarely runs.
Computer browser
Maintain an updated list of computers on the network and provide the list to computers for specified browsing. If the service is stopped, the list will not be updated or maintained. If this service is disabled, any services that directly depend on it will fail to start.
The default running mode of this service is automatic, but if you don't use LAN, this service can be disabled. Even if you want to use it in the local area network, it is only set to manual, because you can't say when to use it, and it will start itself after use.
Credential manager
Provide secure storage and retrieval of credentials for users, applications and security service packages.
The default operation mode of this service is manual, so it is recommended to keep the default value.
Encryption service
Provide four management services: directory database service, which is used to confirm the signature of Windows files and allow the installation of new programs; Protected root service for adding and deleting certificates of trusted root certification authorities from this computer; Automatic root certificate update service, which is used to retrieve the root certificate from Windows Update and enable SSL. Key service to help register this computer to obtain a certificate. If this service is stopped, these management services will not work properly. If this service is disabled, any services that explicitly depend on it will fail to start. Maintain and manage all certificates, keys and security databases of the system. In addition, visit the services required by some websites, such as Microsoft's website, WindowsUpdate or DRM's website. In many cases, it will provide and confirm the signature information of Windows files. It is strongly recommended that you never touch it and never want to disable this service.
DCOM server process launcher
DCOMLAUNCH service can start COM and DCOM servers that respond to object activation requests. If this service is stopped or disabled, programs using COM or DCOM will not work properly. It is strongly recommended that you run the DCOMLAUNCH service. The default operation mode of this service is automatic, so it's best not to tamper with it. The previous DCOM service, that is, remote service, was more basic than COM+. Look at the registry and you will know how many DCOM components there are in Windows system. Although it is okay to disable it, the temporary service set to manual will not start automatically and the icon on the taskbar will disappear, so it is best not to modify this option.
Desktop Window Manager Session Manager
Provides desktop window manager startup and maintenance services.
Aero style is a must, and all AeroGlass and Flip3D effects depend on this service. If you like this style, set it to automatic, otherwise disable it.
DHCP client
Register and update the IP address of this computer. If this service is stopped, computers will not be able to receive dynamic IP addresses and DNS updates. If this service is disabled, all services that explicitly depend on it will fail to start. The default operation mode of this service is automatic. If it is a manually specified IP, it can be completely disabled.
Diagnostic policy service
Diagnostic policy service can detect, troubleshoot and solve problems of Windows components. If this service is stopped, diagnostics will no longer run. The default operation mode of this service is automatic. Vista or IE7 sometimes pops up a dialog box asking if you need it to help find the cause of the fault. Only in the case of 1%, it will help to repair the network disconnection problem, and it is recommended to disable it.
Diagnostic service host
The diagnostic policy service uses the diagnostic service host to host diagnostics that need to be run in the local system context. If this service is stopped, any diagnostics that depend on this service will no longer run.
This is a service that helps the above-mentioned diagnostic strategy service to do specific things. It will be started together with the above services and can be disabled together.
Diagnostic system host
The diagnostic policy service uses the diagnostic system host to host diagnostics that need to be run in the local system context. If this service is stopped, any diagnostics that depend on this service will no longer run.
Basic and diagnostic policy service/diagnostic service hosts belong to the same type and can be disabled together.
Disk defragmenter
Provide disk defragmentation function.
The default operation mode of this service is manual, so it is recommended to keep the default value.
Distributed link tracking client
Maintain links between NTFS files of computers or computers in the network. The default operation mode of the service is automatic, but this function is not usually used and can be safely disabled.
Distributed transaction coordinator
Coordinate transactions across resource managers such as multiple databases, message queues, and file systems. If this service is stopped, these transactions will fail. If this service is disabled, other services that explicitly depend on it will fail to start. Many applications and server software, such as SQL and ExchangeBiztalk, depend on this service. You can not start it, but don't disable it. Manual operation is recommended.
DNS client
The DNS client service (dnscache) caches the domain name system (DNS) name and registers the full computer name of the computer. If the service is stopped, DNS name resolution will continue. However, the query results of DNS names will not be cached, and the computer name will not be registered. If this service is disabled, any services that explicitly depend on it will fail to start. ministrant
The default operating mode is automatic. If it is in a domain environment, it should be set to automatic. However, this service can reveal which websites you have visited, so for security reasons, ordinary users should disable it.
Encrypted file system (EFS)
Provides core file encryption technology for storing encrypted files on NTFS file system volumes. If this service is stopped or disabled, applications will not be able to access encrypted files.
The default operation mode of this service is manual, so it is recommended to keep the default value.
extensible authentication protocol,eap
Extensible Authentication Protocol (EAP) service provides network authentication in the following situations: 802. 1x wired and wireless, VPN and network access protection (NAP). EAP also provides an application programming interface (API) used by network access clients, including wireless clients and VPN clients. If this service is disabled, this computer will not be able to access networks that require EAP authentication. If this service is disabled, this computer will not be able to access networks that require EAP authentication. You don't need 802. 1x authentication, you don't need wireless network or VPN to start and don't disable it. Manual reservation is recommended.
Feature discovery provider host
The FDPHOST service hosts a functional discovery (FD) network discovery provider. These FD providers provide network discovery services for Simple Service Discovery Protocol (SSDP) and Web Service Discovery Protocol (WS-D). Stopping or disabling the FDPHOST service when using FD will disable network discovery for these protocols. When services are unavailable, network services that use FD and rely on these discovery protocols will not be able to find network services or resources.
PnP-X is related to SSDP. If there is no related device, disable it.
Function discovery resource publishing
Publish this computer and the resources connected to it so that these resources can be found on the network. If this service is stopped, network resources will no longer be published, and other computers on the network will not be able to discover these resources.
PnP-X is related to SSDP. If there is no relevant equipment, turn it off.
Group policy client
This service is responsible for applying the settings configured by the administrator for computers and users through the Group Policy component. If this service is stopped or disabled, settings will not be applied and applications and components will not be managed through Group Policy. If this service is stopped or disabled, any component or application that relies on Group Policy will not function properly.
Important services of the system automatically remain unchanged.
Health key and certificate management
Provide X.509 certificate and key management services for network access protection agent (NAPAgent). Without this service, coercive techniques using X.509 certificates may not work properly. Presumption is a service of NAP, in which it is mentioned that manual is the default implementation of a HealthRegistrationAuthority mechanism.
Homegroup provider
Perform network tasks related to the configuration and maintenance of master groups. If this service is stopped or disabled, your computer will not be able to detect other master groups, and your master groups may not work properly. It is recommended that you keep this service running.
If you don't use homegroups to enjoy pictures, videos and documents, you can disable this service.
Man-machine interface equipment access
Enables universal input access for intelligent interface devices (HID), which can activate and save predefined hotkeys on keyboards, remote controls and other multimedia devices. If this service is stopped, the hotkeys controlled by this service will no longer run. If this service is disabled, any services that depend on it will fail to start. If you don't want those special additional buttons on your machine or notebook keyboard to work, and you don't need game pads or anything like that, you can disable this service.
IKE and AuthIP IPsec key modules
The IKEEXT service hosts Internet key exchange (IKE) and authentication Internet protocol (AuthIP) key modules. These key modules are used for authentication and key exchange in Internet Protocol Security (IPSec). Stopping or disabling IKEEXT service will disable IKE/AuthIP key exchange with peer computers. IPSec is usually configured to use IKE or AuthIP, so stopping or disabling IKEEXT service will lead to IPSec failure and endanger the security of the system. It is strongly recommended to run the IKEEXT service. Mainly used for authentication of VPN and other network environments. If you don't use VPN or use a third-party VPN to dial, you can disable it.
interactive services detection
Enables user notification of user input of interactive services so that dialogs created by interactive services can be accessed when they appear. If this service is stopped, there will be no new interactive service dialog notifications, and the interactive service dialog may no longer be accessible. If this service is disabled, no new interactive service dialogs will be notified and these dialogs will be inaccessible. I don't know what interactive service is. The default is manual. Leave the default values.
Internet connection sharing (ICS)
Provide network address translation, addressing, name resolution and/or intrusion prevention services for home and small office networks. The default operating mode of this service is disabled. If you don't want this computer to act as an ICS host, you can disable this service, otherwise you need to enable it.
IP assistant
Provide automatic IPv6 connection on IPv4 network. If this service is stopped, when the computer connects to the local IPv6 network, it will only have IPv6 connections. It mainly provides IPv6 support. To put it bluntly, IPv4 and IPv6 are compatible with each other. Under the present circumstances, this is not particularly necessary. Actually, it doesn't hurt to set it to disable.
IPsec policy proxy
Internet Protocol Security (IPSec) supports peer-to-peer authentication, data original authentication, data integrity, data confidentiality (encryption) and network-level replay protection. This service enforces IPSec policies created through the IP Security Policy snap-in or the command-line tool "netsh ipsec". When this service is stopped, you may encounter network connectivity problems if the policy requires the connection to use IPSec. Similarly, when this service stops, remote management of Windows Firewall is no longer available. This service enforces IPSec policies created through the IP Security Policy snap-in or the command-line tool "netshipsec". When this service is stopped, you may encounter network connectivity problems if the policy requires the connection to use IPSec. Similarly, when this service stops, remote management of Windows Firewall is no longer available. Some companies require an open network environment and provide end-to-end secure connections between clients and servers on TCP/IP networks. In other cases, it is recommended to set it to disabled.
KtmRm of distributed transaction coordinator
Coordinate the transactions between the Distributed Transaction Coordinator (MSDTC) and the Kernel Transaction Manager (KTM). If not, it is recommended to keep the service stopped. If necessary, MSDTC and KTM will automatically start the service. If this service is disabled, any MSDTC transactions that interact with the kernel resource manager will fail, and any services that explicitly depend on it will fail to start. Coordinate the transaction between MSDTC and KTM. Vista provides another transaction service, which is more useful for developers. For ordinary users or non-developers, it is set to manual.
Link layer topology discovery mapper
Create a network diagram, which contains topology (connection) information of PCs and devices and metadata describing each PC and device. If this service is disabled, network mapping will not work properly.
The technology of LLTD (Linklayertopology Coverage) should be supported, which can accurately display the location of equipment supporting LLTD in the network structure, such as the wireless map of Vista, and keep the default manual.
Microsoft. NET framework NGEN version 2.0.50727_X86
Microsoft. NET framework NGEN
NET developers all know the usage of NGEN, just keep it manually by default. There will be many based on. NET FX3, so this service will be very useful.
Microsoft iSCSI initiator service
Manage Internet SCSI (iSCSI) sessions from this computer to remote iSCSI target devices. If this service is stopped, this computer will not be able to log on or access iSCSI target devices. If this service is disabled, all services that explicitly depend on it will not start. If the machine does not have iSCSI devices and does not need to connect and access remote iSCSI devices, please set it as disabled.
Microsoft software shadow copy provider
Manage software-based shadow copies made by the shadow copy service. If this service is stopped, software-based shadow copies will not be managed. If this service is disabled, any services that depend on it will fail to start. If you don't need shadow copy, you can set it to be disabled, which is basically not used by ordinary users.
Multimedia curriculum schedule
System-wide task priority enables the relative priority of work. This is mainly suitable for multimedia applications. If this service is stopped, individual tasks will use their default priorities. Mainly to set the priority for audio/video streams of some multimedia applications. Disabling it may cause problems with the sound card function. It is recommended to start the service. If it is set to manual, it will start automatically.
Net. Tcp port sharing service
Provides the function of sharing TCP ports through the net.tcp protocol * * *.
WCF should be used by ordinary users and non-developers, and it is best to disable it.
Netlogon
Maintain a secure channel between this computer and the domain controller for user and service authentication. If this service is stopped, computers may not be able to authenticate users and services, and domain controllers may not be able to register DNS records. If this service is disabled, any services that depend on it will fail to start. A service that communicates with domain services for authentication when logging in to active directory. After general verification, the domain server will register your DNS records, push software patches and policies. That will be used when logging in to the domain. The workgroup environment can be set to disabled.
Network access protection agent
The Network Access Protection (NAP) proxy service collects and manages the health information of client computers on the network. The information collected by the NAP agent is used to ensure that the client computer has the required software and settings. If the client computer is not compatible with the health policy, it can be provided with limited network access until its configuration is updated. Depending on the configuration of the health policy, client computers may be automatically updated so that users can quickly regain full network access without manually updating their computers. Enable the network access protection (NAP) function on the client computer, which is a client in the NAP architecture, and the default setting is manual.
network connections
Manage objects in the Network and Dial-up Connections folder, where you can view local area networks and remote connections. When you click on the network and dial-up connection, this service starts to work, mainly to obtain the objects of local area network and remote connection. This service will start as long as you are connected to the network. Don't turn off your phone.
Network list service
Identify the networks to which the computer is connected, collect and store the properties of these networks, and notify the application when these properties change.
This service lists the existing networks and displays the current connection status. Turning off the phone will cause the network to be abnormal, so don't touch it.
Network location awareness
Collect and store network configuration information, and notify the program when the information is modified. If this service is stopped, configuration information may not be available. If this service is disabled, all services that explicitly depend on it will fail to start. Is NLA, which can well support and mark multiple network cards, or provide you with enhanced functions when you switch and change from home, personal and corporate networks. In most cases, it will automatically start the network connection. Unlike NLA in XP, the shutdown is normal, but it will prompt that there is no network cable plugged in. Better not touch it.
Network store interface service
The service sends network notifications (for example, adding/deleting interfaces, etc.). ) to the user mode client. Stopping this service will cause the network connection to be disconnected. If this service is disabled, all other services that explicitly depend on it will fail to start. This is a service that supports NLA, such as saving files of various networks, so its running state will be the same as NLA, so it is best not to touch it.
Offline file
The offline file service performs maintenance activities in the offline file cache, responds to user login and logout events, implements the internal part of the public API, and distributes related events to users who care about offline file activities and cache changes. Offline file service. With this function, the system will locally cache the * * * content on the network, which can be disabled.
Peer name resolution protocol
Enables serverless peer name resolution on the Internet using the Peer Name Resolution Protocol (PNRP). If this feature is disabled, some peer-to-peer applications and collaborative applications, such as remote assistance, may not work. If you don't try P2P function or develop WCF, you can disable it along with the following two services.
Peer to peer network grouping
Peer to peer network identity manager
Performance log alert
Performance logs and alerts collect performance data from local or remote computers according to pre-configured schedule parameters, and then write the data into logs or trigger alerts. If this service is stopped, performance information will not be collected. If this service is disabled, all services that explicitly depend on it will fail to start. It will be used by many services, such as event log and task scheduler. Personally, I think it is also more resource-consuming, but it is not recommended to set it as disabled, and it can be done manually.
plug and play
Enables the computer to recognize and adapt to changes in hardware with little or no user input. Stopping or disabling this service will cause system instability. Plug and play, one of the most basic services, can't be turned off if you want.
PnP-X IP bus enumerator
The PnP-X bus enumerator service manages the virtual network bus. This service uses SSDP/WS discovery protocol to discover network connected devices and make them exist in PnP. If this service is stopped or disabled, NCD devices will not remain in PnP. All schemes based on pnpx will stop running. The PnP-X bus enumeration server -WindowsConnectNow(WCN) is one of the components of Microsoft's network and equipment platform, and it is an extension of plug and play, which supports some networked smart home appliances (such as networked rice cookers and refrigerators) to connect to your PC. It's useless, disable it!
PNRP machine name publishing service
This service publishes computer names using peer-to-peer name resolution protocol. This configuration is managed through the Netsh context "p2p pnrp Peer".
This is used to name and parse the publishing server in P2P network, which is generally unnecessary. Just silently recognize it.
Portable device enumerator service
Group policy that enforces removable mass storage devices. Support applications such as Windows Media Player and Image Import Wizard to use removable mass storage devices to transmit and synchronize content. If synchronization is not required, it is recommended to close it.
force
Manage power policies and power policy notification delivery.
The default operating mode of the service is automatic and remains the default mode.
Print spooler system
Load files into memory for later printing.
Needless to say, if there is a printer (including a virtual one), turn it on, and if not, turn it off.
Problem reporting and solution control panel support
This service supports viewing, sending and deleting system-level problem reports in the problem reports and solutions control panel. Opening it basically won't solve the problem of your computer. Disable it.
Program compatibility assistant service
This service provides support for the Program Compatibility Assistant (PCA). PCA monitors programs installed and run by users and detects known compatibility problems. If this service is stopped, PCA will not work properly. If you use Program CompatibilityAssistant or need to set the program to run in compatibility mode, such as Win98 or Windows2000, change it to automatic, and it is strongly recommended to set it to automatic.
Protected storage
Provide protective storage for sensitive data (such as passwords) to prevent unauthorized services, processes or users from accessing these data. Although the services handed down from 2000/XP are of little use, they should be kept, disabled or manually for security.