Showing posts with label IT. Show all posts
Showing posts with label IT. Show all posts

Blog Moved

Wednesday, February 23, 2011

This blog has moved to http://www.orchilles.com/

Windows 7 Service Pack 1 (Release Candidate)

Wednesday, October 27, 2010

Microsoft announced today the Release Candidate (RC) of Windows 7 and Windows Server 2008 R2 Service Pack 1 (SP1) to the public. For those unaware of how these software rollouts "work," the RC release generally signals that a final build is almost ready. The only new features added to the SP1 are the Windows Server 2008 R2-related virtualization technologies, Dynamic Memory and RemoteFX, and while Windows 7 SP1 will enable PCs to take advantage of these server-based features to provide a more scalable and richer VDI experience for end users, there are no additional new features specific to Windows 7.

If you do choose to install this Release Candidate make sure to backup your system. Microsoft usually makes you uninstall the RC before installing the final build of the service pack.

Download here.

Running ESXi 4.1 on VMware Workstation 7.0 and above

Sunday, September 26, 2010

VMware is ditching ESX for ESXi which is smaller and, best of all, free. I have been running ESX 4.0 as a virtual machine in Windows using VMware Workstation for some time now but was never able to get ESXi to run as a virtual machine. One of the students in the SANS Security 577: Virtualization Security Fundamentals class asked me if it was possible to run ESXi on VMware Workstation. Which made me wonder, now that ESXi will be the main hypervisor being pushed by VMware, would it be possible?

The answer is YES! But with a few prerequisites:
  • VMware Workstation 7.0 or above (7.1.1 officially supports vSphere 4.1 guests)
  • Dual-Core or better CPU with Intel VT or AMD-V support (may have to turn on in BIOS).
  • At least 2GB of free RAM (I suggest 4GB-8GB)
Once you have downloaded VMware ESXi 4.1 and installed VMware Workstation you are ready to begin:
  1. Open VMware Workstation
  2. File-New-Virtual Machine...
  3. Custom
  4. Hardware compatibility: Workstation 6.5-7.0
  5. Installer disc image file (iso): Click Browse... and select the iso file for VMware ESXi that you downloaded. Click Next.
  6. Click the VMware ESX check box and select ESX Server 4.0 from Version drop down. Click Next.
  7. Select the Virtual machine name and location. Click Next.
  8. Processors must be at least 2 processors with 1 core each. Increase if your system can handle it. Click Next.
  9. Memory must be at least 2048MB but if you can increase it, go for it. Click Next.
  10. Select what type of network connection. Click Next.
  11. For I/O Adapter select LSI Logic for SCSI Adapter. Click Next.
  12. Create a new virtual disk. Click Next.
  13. Virtual disk type: SCSI. Click Next.
  14. Select the size of the disk. Remember you will be running virtual machines with local storage so plan accordingly. I recommend storing as a single file for performance. Click Next.
  15. Specify the disk file name and location. Click Next.
  16. Select Customize Hardware.
  17. Click Floppy-Remove. Then add more network adapters if desired. Click OK
  18. Click Finish.
  19. Install ESXi as usual.
If this does not work for you or you have questions or comments please comment below.

I will be teaching the SANS Security 577: Virutalization Security Fundamentals course as a co-mentor with Robert Rounsavall in Miami, FL on Thursday October 28, 2010 6:00pm-8:00pm through Thursday November 18, 2010 at Terremark's NAP of the Americas. Register early!

Till next time,
Jorge Orchilles

I'm Back!

Monday, August 23, 2010

After a long break from blogging mostly due to the fact that I finally published Microsoft Windows 7 Administrator's Reference, finished a Master's of Science in Management Information Systems, and was hired by a Fortune 20 financial institution to perform vulnerability assessment/ethical hacking/penetration testing, I am officially back to blogging!

Many things coming soon:
  • SANS Security 577 Virtualization Security Fundamentals course review
  • Speaking engagement and presentation at Hacker Halted titled "Vulnerability Ass... Penetration What?
  • Hacker Halted conference. If you want to attend email me for a student code!!!!! $100 before September 15.
Glad to be back and hope you are too.

Till next time,
Jorge Orchilles

Windows 7 is safer as a standard user

Tuesday, March 30, 2010

This should be common sense and not require a whole research paper but Beyond Trust released a study stating that Windows 7 is safer when using it as a standard user.
I highlighted this fact in my book but would like to share the results of the study as well:


Microsoft and their partners regularly identify new security vulnerabilities in Microsoft software. In 2009 Microsoft published nearly 75 security bulletins documenting and providing patches for nearly 200 vulnerabilities. By examining all of the published Microsoft vulnerabilities in 2009 and all of the published Windows 7 vulnerabilities to date, this report quantifies the continued effectiveness of removing administrator rights at mitigating vulnerabilities in Microsoft software.
Key findings from this report show that removing administrator rights will better protect companies against the exploitation of:
  • 90% of Critical Windows 7 vulnerabilities reported to date
  • 100% of Microsoft Office vulnerabilities reported in 2009
  • 94% of Internet Explorer and 100% of IE 8 vulnerabilities reported in 2009
  • 64% of all Microsoft vulnerabilities reported in 2009
So please, use a standard user for day to day use like most Mac and *nix users do!

Final edits in! Microsoft Windows 7 Administrator's Reference

Tuesday, March 23, 2010

Today I turned in the final revisions and edits to my first book coming out in the end of April: Microsoft Windows 7 Administrator's Reference! If you are a Windows power user or system administrator or want to be one this is the book for you!
It is available for pre-order and purchase at:
Writing a book and getting it published is a long journey but I can say I am one step closer to making this dream a reality.

Till next time,
Jorge Orchilles

Podcasts

Saturday, March 20, 2010

Jorge Orchilles is now podcasting! I am co-hosting the SMB Minute podcast with Tim Krabec and Aaron. The SMB Minute podcast is aimed at the Small and Medium Business market. Whether you are the designated IT guy/gal or own your own business, this podcast will give you an insight of what is going on in the Information Technology/Systems/Security world. You can subscribe to it on iTunes and it will automatically sync with your iPod every week when the podcast is released. Season 2 will begin release this week.

These are other podcasts I listen to in no particular order:
SANS Audiocasts with John Strand
PaulDotCom Security Weekly
Exotic Liability
Social Engineer
Security Justice
The Hacker News Network
Network Security Podcast
ThreatPost
Security Wire Weekly

And if you want to hear almost all of these people doing a podcast at ShmooCon 2010, check out the Podcaster's Meetup

Emerging Threats to Infrastructure

Thursday, March 18, 2010

I recently presented my talk on Emerging Threats to Infrastructure to the Jacksonville ISACA chapter and targeted it for auditors. Thanks to all that made that possible and Blue Cross Blue Shield of Florida for hosting the event (loved the campus). It is the first time I present this topic and will be modifying it for a presentation April 8th for the South Florida HIMMS chapter. I will also be presenting it April 10th at the Hack Miami hacker space and will make it much more technical with include more technical demos.

I recorded the first talk and am debating whether to post now or after the other presentations although they will be different.


Till next time,
Jorge Orchilles

Windows 7 Book Announcement and "God Mode"

Monday, January 4, 2010

I have been slacking on the blog posts recently due to a few projects I am/was working on.

First I would like to announce that I am finishing a Windows 7 book titled: Microsoft Windows 7 Administrator's Reference. My publisher is Syngress and the book is expected to be available March 2010.

Second, I have completed the Master's of Science in Management Information Systems program at Florida International University. This program is aimed at working professionals and people with experience in both management and information systems. I recommend this program to anyone in the South Florida area. It is Saturday's only for a full year and worth every penny.

Lastly, as I have been working on the Windows 7 book I was waiting to release the how-to for Windows 7 GodMode. Since news and blogs are releasing it already, I decided what the heck, here it is:

Microsoft developers included a so called “God Mode” in Windows 7. In reality this is not a mode but a simple and single container with multiple shortcuts to Windows 7 options that are available through other methods. This may be helpful for administrators and power users alike to configure and manage single Windows 7 desktops.

To create a God Mode shortcut:
1. Right click on the Desktop or anywhere in Windows Explorer where you would like this shortcut.
2. Select New – Folder
3. Name the folder: GodMode.{ED7BA470-8E54-465E-825C-99712043E01C}
4. The folder icon will change to a Control Panel icon

To use God Mode, simply double click the Control Panel icon just created called “GodMode”. A Windows Explorer window will open with shortcuts for many different configuration options in Windows 7. All of these options are available through other methods, mostly though the standard Control Panel shortcuts.

Warning:
The “GodMode” hack appears to work on Windows 7 32-bit and 64-bit versions. It also seems to work on 32-bit versions of Windows Vista and Windows Server 2008. Many users have reported problems with “GodMode” in 64-bit editions of Windows Vista and Windows Server 2008. If “GodMode” crashes the system, rebooting to safe mode and removing the shortcut should solve the issues.

Till next time,
Jorge Orchilles

Time to change your password

Tuesday, October 6, 2009

The BBC has released these three articles in the last two days suggesting that over 20,000 Microsoft web-based email accounts have been hacked. This includes Hotmail and Live email accounts. The third article suggests that GMail is being targeted as well:

Here are some best practices for passwords and email use:

  • Do change your passwords on a regular basis (every six months or so)
  • Do use long complex pass-phrases rather than passwords where you can
  • Do change all of your passwords if you notice something suspicious
  • Do take identity theft seriously
  • Do use up-to-date anti-virus and a firewall
  • Do NOT click on links in emails, EVER
  • Do NOT use the same password at multiple sites
Hope your accounts have not been compromised!

Till next time,
Jorge Orchilles

Windows 7 Security Video

Monday, September 21, 2009

I have posted the video of the Windows 7 Security presentation I did for South Florida ISSA. Enjoy

Windows 7 Security Presentation from Jorge Orchilles on Vimeo.

Windows 7 Security Presentation

Friday, September 18, 2009

Yesterday I had the honor of presenting to the South Florida ISSA my talk on Windows 7 Security. Here is the presentation.

Update on Google Voice Hacking

Thursday, July 30, 2009

Following up with my original post on hacking Google Voice, it was brought to my attention that Apple has blocked the Google Voice App from the App Store, meaning iPhone users will not be getting the Google Voice app like the fortunate BlackBerry and Android users. Google has confirmed that the rejection was because of AT&T. The reason given is that it is against AT&T's business model as the software allows free SMS and cheaper long distance calling. Furthermore, I believe that Apple is also behind this as they see Google as competition now instead of a partner when their iPhone launched. Google went behind Apple's back and made the Android mobile platform, now they are working on browsers and operating systems.

In my opinion, this is a smart move for Apple and AT&T both but it does not hide where the future of communication is heading. Grab on to a cheap unlimited data plan with a reliable and fast network as the days of paying for "voice and minutes" will soon be a thing of the past. Additionally, this move shows the competition Google is giving everyone and the steps they are taking to block Google out.

Till next time,
Jorge Orchilles

Windows 7 and VMWare vSphere Client 4

In my last Windows 7 blog post I wrote about an issue I was having running VMWare vSphere Client 4.0 on Windows 7 RTM 64 bit. Further research shows that this issue occurs in all versions of Windows 7. VMWare will most likely have to release a patch for their software as Windows 7 is now final. Thanks to this VMWare community post I was pointed to the right direction to fix it.

Problem
Although vSphere Client installs fine, when you try to connect to any server you get this error:
Error parsing the server "serverIP" "clients.xml" file. Login will continue, contact your system administrator.
Immediately followed by this error:
The type initializer for 'VirtualInfrastructure.Utils.HttpWebRequestProxy' threw an exception.
Solution
  1. Obtain a copy of C:\Program Files\Microsoft.NET\Framework\v2.0.50727\System.dll from a non Windows 7 machine that has .NET 3.5 SP1 installed. You can also download the file from here (recommended for step 3)
  2. Create a folder in the Windows 7 machine where the vSphere client is installed and copy the file from step 1 into this folder. For this example, create the folder under the vSphere client launcher installation directory and call it Lib+ (C:\Program Files (x86)\VMware\Infrastructure\Virtual Infrastructure Client\Launcher\Lib+) for 32 bit versions (C:\Program Files\VMware\Infrastructure\Virtual Infrastructure Client\Launcher\Lib+)
  3. Copy the VpxClient.exe.config from the zip in step 1 and put it in the "Launder" directory, overwriting the current file. What this is doing is adding a runtime option so you can run vSphere in developer mode.
  4. In the same "Launcher" directory (doesn't matter where really) right click and create a new "Text Document" and name it VpxClient.cmd (remove the .txt part) Open the file with notepad and for 64 bit put this in:
    @echo Off
    SET DEVPATH=%ProgramFiles(x86)%\VMware\Infrastructure\Virtual Infrastructure Client\Launcher\Lib+
    "%ProgramFiles(x86)%\VMware\Infrastructure\Virtual Infrastructure Client\Launcher\VpxClient.exe"
    For 32 bit:
    @echo Off
    SET DEVPATH=%ProgramFiles%\VMware\Infrastructure\Virtual Infrastructure Client\Launcher\Lib+
    "%ProgramFiles%\VMware\Infrastructure\Virtual Infrastructure Client\Launcher\VpxClient.exe"
  5. Thanks to the people on the VMWare communities forum that pointed me in the right direction for this. Hopefully VMWare comes out with a fix soon. For now this will do, it beats running a VM to administer other VM's :)

    Till Next Time,
    Jorge Orchilles

Some Windows 7 RTM Observations Part I

Tuesday, July 28, 2009

Here are a few of my finding on Windows 7 RTM as I have installed and/or upgraded on some of my test systems:

Dell Latitude E6400 with Windows RC1 64bit formatted for a clean install of Windows 7 RTM 64bit. You can upgrade from Windows 7 beta or RC1 to RTM by doing the following, however it is NOT recommended:
  • Extract the contents of the RTM iso to an empty directory.
  • Go to sources folder and open cversion.ini in notepad.
  • Change MinClient to 7000.0 and MinServer to 7000.0 and save the file.
  • Run setup from this directory and choose to upgrade
Clean install took about 20 minutes and weighs in at 15GB with default settings (not much to configure anyways). Installed almost all drivers except 3. Wireless and wired network interfaces worked out of the box. Even though Windows 7 detects most of your drivers go to your manufacturers site and try to download and install the latest drivers. If Windows 7 drivers are not out try Vista version of same version and bits.

Apple MacBook Pro running clean install of Windows 7 RTM 64bit in VMWare Fusion. The VM has 1GB of RAM and 1 CPU core assigned. Installed in under 20 minutes. Runs very smooth!

Next I will be upgrading a Vista Ultimate 32 bit to Windows 7 RTM Ultimate 32 bit. It currently has 32GB of used space, let's see how it goes.

Some customizations I make
As soon as I am on the desktop I make a few customizations depending on the role of the machine, I am testing a corporate environment machine and a stand alone so the configurations are different. Here are some I do right off the bat:
  • Notification Area - I set this to always show all icons and notifications on the taskbar. One of the changes to Windows 7 is that you can set the behavior of certain icons on your taskbar. I like seeing all the icons so I set it like this. Often you are troubleshooting a home users machine and see the taskbar almost reaching the start button!
  • Stop and/or set services I do not use to manual or disabled. I have two blogs on Windows 7 services. A full list, and the services you can disable or set to manual

Issues so far
VMWare vSphere Client 4.0 does not work on Windows 7 RTM 64bit running in a VM in fusion, it does work on a Windows XP VM in fusion. It does not work on a host Windows 7 RC1 64 bit install either. The program runs from the short cut. However when you try to connect you get an error "Error parsing the server "" "clients.xml" file. Login will continue, contact your system administrator." Immediately followed by this error: "The type initializer for 'VirtualInfrastructure.Utils.HttpWebRequestProxy' threw an exception." Anyone else seeing this issue?

Update
I found a solution for the vSphere issue on WIndows 7 and posted here.

Till Next Time,
Jorge Orchilles

Installing VMWare ESXi 4

Continuing the idea of building your own home lab I have recently installed VMWare ESXi on a dedicated workstation to serve as another lab machine so I decided to document the process and share. It is pretty straight forward with very little custom configuration needed. Before you begin make sure you have everything backed up from the system you will be installing ESXi on as the install will wipe the drive, deleting everything on it. Furthermore make sure the machine you will be installing ESXi has compatible hardware. With that said let's begin:

  • Go to the VMWare ESXi page and register for the software. You will need to have an account with VMWare and the link will be sent to your email along with the registration.
  • Download the iso and burn it with ImgBurn or your favorite ISO burning software. Windows 7 has built in ISO burning finally!
  • Boot ESXi server from CD.
  • Press enter on the ESXi Installer option.
  • Welcome to the VMWare ESXi 4.0.0 Installation screen – Press Enter
  • F11 to Accept Agreement
  • Select Disk to install. You want to install ESXi on the fastest hard drive in the machine. Note everything on that drive will be overwritten.
  • Wait for ESXi to install and ask for a reboot, remove the CD, and reboot.

The first boot up always takes a while for me on certain systems; be patient and wait for the screen to be gray and yellow with the IP to manage the host. Before going to the IP let's finish setting up the ESXi server so you can unplug the monitor and keyboard and administer the machine from your workstation. Here is how:

  • Press F2 to customize the system
  • Press Enter to configure Password. Set your password, this will be the password for the user "root"
  • Next go to Configure Management Network. In this part you can configure the network you will use to manage the ESXi server.
  • If you go to IP Configuration you will be able to set a static IP so you can connect to the ESXi server without having to check its DHCP IP.
  • Once done changing settings in the Configure Management Network option you will need to restart the Management Network.
  • Take a look at the other options you can modify and press Esc to Log out.
  • Note the Configure Lockdown Mode option where you will be able to block access to remote users logging in with "root" This is a security measure you will want to set later.

You should now be on the first screen where it says the ESXi's IP. From here you can unplug the keyboard and monitor as the rest of the configuration you will do from another workstation on the network. Once on another machine on the same network as the ESXi server open a web browser and navigate to the IP you set for the host. You will probably get a certification error, ignore this and continue to the site. The site allows you to download the vSphere client. Download and install this on a Window machine, can even be a VM if you are running another host OS. Note: I have not been able to get VSphere Client to work on Windows 7 RTM yet.

  • Open vSphere Client and put the IP of the ESXi host, username: root and password you set.
  • Accept the certificate and wait for the system to login.
  • Once in you can double click inventory and then your host.
  • Go to the Configuration tab and click License Features under Software
  • Click Edit on the top right and input the license key VMWare gave you when you registered.

And there you have it. You now have an ESXi server to start loading virtual machines on. You can even create your own virtual network as an isolated network to test things you wouldn't normally on a live network. Finally here is a link for further ESXi documentation. I hope you found this educational and interesting and it gives you the kick start to get your own lab running.

Till Next Time,

Jorge Orchilles

Windows 7 RTM Services you can disable

Monday, July 27, 2009

My last post provides a list of ALL Windows 7 services for Windows 7 RTM Ultimate 64 bit. This post is shorter and lists the services you can disable without crashing the system. Please read all my warning from the last post before doing this! Here is what I have disabled and have a pretty secure and quick Windows 7:

  • Adaptive brightness – disable if your machine does not have an ambient light sensor
  • Application Experience - disabled without noticing issues. Still researching
  • BitLocker Drive Encryption Service – disable if you do not use encryption (which you should)
  • Bluetooth Support Service – disable if you do not use Bluetooth devices
  • BranchCache – disable if not connected to any LAN
  • Certificate Propagation – disable if you do not use a smart card
  • Computer Browser – disable if not connected to any LAN
  • Credential Manager – disable if you do not save passwords
  • Desktop Windows Manager Session Manager - disable if not using Aero theme
  • DHCP Client – disable if static network configuration
  • Diagnostic Policy Service - disable if you don't want Windows troubleshooting assitance
  • Distributed Link Tracking Client – disable if not on LAN
  • DNS Client – disable if static DNS
  • Encrypting File System (EFS) – disable if not using EFS
  • Fax – disable if not using fax services
  • HomeGroup Listener – disable if not using homegroup
  • HomeGroup Provider – disable if not using homegroup
  • Microsoft iSCSI Initiator Service – disable unless using iSCSI
  • Netlogon – disable if not on domain
  • Network Access Protection Agent – disable if not on domain or corporate network
  • Offline Files – disable if not using offline files
  • Parental Controls – disable if not using
  • Portable Device Enumerator Service - disable if no portable devices used
  • Print Spooler – disable if not printer
  • Protected Storage - disable if not used (not secure)
  • Remote Registry – disable if not using
  • Secondary Logon – disable if only one user account
  • Security Center - disable if using another security suite
  • Server - if not on a LAN
  • Smart Card – disable if no smart card
  • Smart Card Removal Policy – disable if not smart card
  • SNMP trap – disable if not connecting to SNMP devices
  • Tablet PC Input Service – disable if not tablet hardware
  • TCP/IP NetBIOS Helper - disable if not using NetBIOS
  • Volume Shadow Copy – Disable if system restore or Windows backup is disabled
  • Windows Backup – disable if using another form of backup
  • Windows Biometric Service –disable if no biometric devices
  • Windows Error Reporting Services – disable if don't like error reports
  • Windows Firewall – disable if another firewall is in place
  • Windows Media services – disable if not sharing media
  • Windows Search – disable if not using search or have third party
  • Windows Time – disable if do not want to connect to time server
  • Windows Update – disable if no updates (not recommended)
  • Wired AutoConfig – disable if not using 802.1x authentication on ethernet interface
  • WLAN AutoConfig – disable if no Wireless adapter
  • WWAN AutoConfig – disable if no broadband wireless adapter

Once again before disabling or stopping any service make sure to read the description and ensure you are performing the correct action. When in doubt set the service to manual and test it out first. I hope your Windows 7 tweaking continues to be successful and please do not hesitate to leave a comment or question.

Till Next Time,

Jorge Orchilles

Windows 7 RTM Services

One of the first steps I take when I finish a fresh Windows XP or Vista install is to stop and/or disable all the unnecessary services on the current machine; Windows 7 is no different. In this post I will attempt to list all Windows 7 RTM services with their default state, safe state, and my notes on the service. If you have never explored the services of a Windows system, now would be a good time to do so. In Windows 7 there are three different ways to get to the services management console:

  1. Click the Microsoft Icon on the bottom left (old start menu), type services.msc in the search box and hit enter
  2. Right click on the Computer icon either on the desktop or start menu, select manage, in the window that opens go to Services and Applications and then click on Services
  3. Open the Control Panel, double click Administrative Tools (need to be in large or small icon view) and double click services

You should now see a list of services: the name, description, startup type, status, and log on as account. You may double click a service to bring up the options for it as well as read a description. I recommend you become familiar with a service before changing anything.

By default Microsoft sets many of these services to start automatically. This is done to ensure the Windows install works on a typical deployment. However running services that you do not need to run automatically can be a security risk as well as have the ability to slow down your system. One of the issues with Windows Vista was the number of services running by default and their unsecure state. Thankfully, Windows 7 has less of these unnecessary services starting by default. Windows 7 also has some new services that Vista or XP did not have and therefore I have created this list of all the services, their default state in Windows 7 RTM Ultimate 64 bit, their safe state, and my notes to assist you in deciding whether to set it to manual or disable. Keep in mind that the safe state will usually be Manual as Windows will still be able to start the service if needed. If you set the service to disable, it will not be able to start and you might encounter issues. Additionally the state that you should set the services varies depending on the purpose of the machine. An example would be a machine that does not have a printer would not need Printer Spooler enabled; if you disable this on a machine with a printer you will not be able to print.

Display Name

Service Name

Default

Safe Setting

Notes

ActiveX Installer (AxInstSV)

AxInstSV

Manual

Manual

Do not disable! This is for your own safety.

Adaptive Brightness

SensrSvc

Manual

Manual

Disable if no ambient light sensor on machine

Application Experience

AeLookupSvc

Manual (Started)

Manual

Application Host Helper Service

AppHostSvc

Not Installed

Not Installed

Application Identity

AppIDSvc

Manual

Manual

Application Information

Appinfo

Manual (Started)

Manual

Application Layer Gateway Service

ALG

Manual

Manual

Application Management

AppMgmt

Manual

Manual

ASP.NET State Service

aspnet_state

Not Installed

Not Installed

Background Intelligent Transfer Service

BITS

Manual

Manual

Used for Windows Updates

Base Filtering Engine

BFE

Automatic (Started)

Automatic

BitLocker Drive Encryption Service

BDESVC

Manual

Manual

Used for encyrption

Block Level Backup Engine Service

wbengine

Manual

Manual

Bluetooth Support Service

bthserv

Manual

Manual

Disable if no Bluetooth devices

BranchCache

PeerDistSvc

Manual

Manual

Disable if not on a network

Certificate Propagation

CertPropSvc

Manual

Disabled *

Disable if no smart card

Client for NFS

NfsClnt

Not Installed

Not Installed

CNG Key Isolation

KeyIso

Manual

Manual

COM+ Event System

EventSystem

Automatic (Started)

Automatic

COM+ System Application

COMSysApp

Manual (Started)

Manual

Computer Browser

Browser

Manual

Manual

If computer is not connected to a network

Credential Manager

VaultSvc

Manual

Manual

Cryptographic Services

CryptSvc

Automatic (Started)

Automatic

DCOM Server Process Launcher

DcomLaunch

Automatic (Started)

Automatic

Desktop Window Manager Session Manager

UxSms

Automatic (Started)

Automatic

DHCP Client

Dhcp

Automatic (Started)

Automatic

Can disable if static IP

Diagnostic Policy Service

DPS

Automatic (Started)

Automatic

Diagnostic Service Host

WdiServiceHost

Manual (Started)

Manual

Diagnostic System Host

WdiSystemHost

Manual (Started)

Manual

Disk Defragmenter

defragsvc

Manual

Manual

Distributed Link Tracking Client

TrkWks

Automatic (Started)

Disabled *

Disable if not on a network

Distributed Transaction Coordinator

MSDTC

Manual (Started)

Manual

DNS Client

Dnscache

Automatic (Started)

Automatic

Can disable if static DNS

Encrypting File System (EFS)

EFS

Manual

Manual

Extensible Authentication Protocol

EapHost

Manual

Manual

Fax

Fax

Manual

Manual

What is a fax?

Function Discovery Provider Host

fdPHost

Manual

Manual

Function Discovery Resource Publication

FDResPub

Automatic (Started)

Automatic

Group Policy Client

gpsvc

Automatic (Started)

Automatic

For corporate networks with AD

Health Key and Certificate Management

hkmsvc

Manual

Manual

HomeGroup Listener

HomeGroupListener

Manual

Manual

For home networks

HomeGroup Provider

HomeGroupProvider

Manual

Manual

For home networks

Human Interface Device Access

hidserv

Manual

Manual

IIS Admin Service

IISADMIN

Not Installed

Not Installed

IKE and AuthIP IPsec Keying Modules

IKEEXT

Manual

Manual

Indexing Service

CISVC

Not Installed

Not Installed

Slowed down Vista

Interactive Services Detection

UI0Detect

Manual

Manual

Internet Connection Sharing (ICS)

SharedAccess

Disabled

Disabled

Keep disabled unless your machine is a gateway

IP Helper

iphlpsvc

Automatic (Started)

Automatic

If no IPv6 you can disable

IPsec Policy Agent

PolicyAgent

Manual

Manual

KtmRm for Distributed Transaction Coordinator

KtmRm

Manual

Manual

Link-Layer Topology Discovery Mapper

lltdsvc

Manual

Manual

LPD Service

LPDSVC

Not Installed

Not Installed

Media Center Extender Service

Mcx2Svc

Disabled

Disabled

Message Queuing

MSMQ

Not Installed

Not Installed

Message Queuing Triggers

MSMQTriggers

Not Installed

Not Installed

Microsoft .NET Framework NGEN v2.0.50727

clr_optimization_v2.0.50727

Manual

Manual

Microsoft FTP Service

ftpsvc

Not Installed

Not Installed

Microsoft iSCSI Initiator Service

MSiSCSI

Manual

Disabled *

Disable unless you have iSCSI

Microsoft Software Shadow Copy Provider

swprv

Manual

Manual

Multimedia Class Scheduler

MMCSS

Automatic (Started)

Automatic

Net.Msmq Listener Adapter

NetMsmqActivator

Not Installed

Not Installed

Net.Pipe Listener Adapter

NetPipeActivator

Not Installed

Not Installed

Net.Tcp Listener Adapter

NetTcpActivator

Not Installed

Not Installed

Net.Tcp Port Sharing Service

NetTcpPortSharing

Disabled

Disabled

Netlogon

Netlogon

Manual

Disabled *

Disable if not in a corporate network

Network Access Protection Agent

napagent

Manual

Disabled *

Disable if not in a corporate network

Network Connections

Netman

Manual (Started)

Manual

Network List Service

netprofm

Manual (Started)

Manual

Network Location Awareness

NlaSvc

Automatic (Started)

Automatic

Network Store Interface Service

nsi

Automatic (Started)

Automatic

Offline Files

CscService

Automatic (Started)

Disabled *

Can disable if not using offline files

Parental Controls

WPCSvc

Manual

Disabled *

Can disable if not using

Peer Name Resolution Protocol

PNRPsvc

Manual

Manual

Peer Networking Grouping

p2psvc

Manual

Manual

Peer Networking Identity Manager

p2pimsvc

Manual

Manual

Performance Logs & Alerts

pla

Manual

Manual

Plug and Play

PlugPlay

Automatic (Started)

Automatic

PnP-X IP Bus Enumerator

IPBusEnum

Manual

Manual

PNRP Machine Name Publication Service

PNRPAutoReg

Manual

Manual

Portable Device Enumerator Service

WPDBusEnum

Manual (Started)

Manual

Power

Power

Automatic (Started)

Automatic

Print Spooler

Spooler

Automatic (Started)

Automatic

Can disable if no printer

Problem Reports and Solutions Control Panel Support

wercplsupport

Manual

Manual

Program Compatibility Assistant Service

PcaSvc

Manual

Manual

Protected Storage

ProtectedStorage

Manual

Manual

Quality Windows Audio Video Experience

QWAVE

Manual

Manual

Remote Access Auto Connection Manager

RasAuto

Manual

Manual

Remote Access Connection Manager

RasMan

Manual

Manual

Remote Desktop Configuration

SessionEnv

Manual

Manual

Remote Desktop Services

TermService

Manual

Manual

Remote Desktop Services UserMode Port Redirector

UmRdpService

Manual

Manual

Remote Procedure Call (RPC)

RpcSs

Automatic (Started)

Automatic

Remote Procedure Call (RPC) Locator

RpcLocator

Manual

Manual

Remote Registry

RemoteRegistry

Manual

Disabled *

Should disable

RIP Listener

iprip

Not Installed

Not Installed

Routing and Remote Access

RemoteAccess

Disabled

Disabled

RPC Endpoint Mapper

RpcEptMapper

Automatic (Started)

Automatic

SeaPort

SeaPort

Not Installed

Not Installed

Secondary Logon

seclogon

Manual

Manual

Disable if only one user

Secure Socket Tunneling Protocol Service

SstpSvc

Manual

Manual

Security Accounts Manager

SamSs

Automatic (Started)

Automatic

Security Center

wscsvc

Automatic (Delayed Start, Not Started)

Automatic (Delayed Start)

Server

LanmanServer

Automatic (Started)

Automatic

Shell Hardware Detection

ShellHWDetection

Automatic (Started)

Automatic

Simple TCP/IP Services

simptcp

Not Installed

Not Installed

Smart Card

SCardSvr

Manual

Disabled *

Disable if no smart card

Smart Card Removal Policy

SCPolicySvc

Manual

Disabled *

Disable if no smart card

SNMP Service

SNMP

Not Installed

Not Installed

SNMP Trap

SNMPTRAP

Manual

Disabled *

Disable if not using SNMP

Software Protection

sppsvc

Automatic (Delayed Start, Not Started)

Automatic (Delayed Start)

SPP Notification Service

sppuinotify

Manual

Manual

SSDP Discovery

SSDPSRV

Manual (Started)

Manual

Superfetch

SysMain

Automatic (Started)

Automatic

System Event Notification Service

SENS

Automatic (Started)

Automatic

Tablet PC Input Service

TabletInputService

Manual

Manual

Disable if not on tablet

Task Scheduler

Schedule

Automatic (Started)

Automatic

TCP/IP NetBIOS Helper

lmhosts

Automatic (Started)

Automatic

Telephony

TapiSrv

Manual

Manual

Telnet

TlntSvr

Not Installed

Not Installed

Themes

Themes

Automatic (Started)

Automatic

Thread Ordering Server

THREADORDER

Manual

Manual

TPM Base Services

TBS

Manual

Manual

UPnP Device Host

upnphost

Manual

Manual

User Profile Service

ProfSvc

Automatic (Started)

Automatic

Virtual Disk

vds

Manual

Manual

Volume Shadow Copy

VSS

Manual

Manual

Used for system restore. Disable if backing up via different method.

Web Management Service

WMSVC

Not Installed

Not Installed

WebClient

WebClient

Manual

Manual

If disabled you cannot surf the web

Windows Audio

AudioSrv

Automatic (Started)

Automatic

Windows Audio Endpoint Builder

AudioEndpointBuilder

Automatic (Started)

Automatic

Windows Backup

SDRSVC

Manual

Manual

Disable if you do not backup

Windows Biometric Service

WbioSrvc

Manual

Manual

Disable if no biometric device

Windows CardSpace

idsvc

Manual

Manual

Windows Color System

WcsPlugInService

Manual

Manual

Windows Connect Now - Config Registrar

wcncsvc

Manual

Manual

Windows Defender

WinDefend

Automatic (Delayed Start, Not Started)

Automatic (Delayed Start)

Windows Driver Foundation - User-mode Driver Framework

wudfsvc

Manual

Manual

Windows Error Reporting Service

WerSvc

Manual

Manual

Disable if you do not want Windows error reports

Windows Event Collector

Wecsvc

Manual

Manual

Windows Event Log

EventLog

Automatic (Started)

Automatic

Windows Firewall

MpsSvc

Automatic (Started)

Automatic

Disable if using third party firewall

Windows Font Cache Service

FontCache

Manual

Manual

Windows Image Acquisition (WIA)

stisvc

Manual

Manual

Windows Installer

msiserver

Manual

Manual

Will not be able to install anything if disabled

Windows Live Family Safety

fsssvc

Not Installed

Not Installed

Additional component to parental controls

Windows Management Instrumentation

Winmgmt

Automatic (Started)

Automatic

Windows Media Center Receiver Service

ehRecvr

Manual

Manual

Disable if you do not share media via Windows Media Player

Windows Media Center Scheduler Service

ehSched

Manual

Manual

Disable if you do not share media via Windows Media Player

Windows Media Player Network Sharing Service

WMPNetworkSvc

Manual (Started)

Disabled *

Disable if you do not share media via Windows Media Player

Windows Modules Installer

TrustedInstaller

Manual

Manual

Windows Presentation Foundation Font Cache 3.0.0.0

FontCache3.0.0.0

Manual

Manual

Windows Process Activation Service

WAS

Not Installed

Not Installed

Windows Remote Management (WS-Management)

WinRM

Manual

Manual

Windows Search

WSearch

Automatic (Delayed Start, Started)

Disabled

Disable to increase speed and do not search on the desktop

Windows Time

W32Time

Manual

Manual

Disable if you do not want to update the time with a server

Windows Update

wuauserv

Automatic (Delayed Start, Not Started)

Automatic (Delayed Start)

Disable if you do not want Windows updates (bad idea)

WinHTTP Web Proxy Auto-Discovery Service

WinHttpAutoProxySvc

Manual (Started)

Manual

Wired AutoConfig

dot3svc

Manual

Manual

For ethernet 802.1X authentication

WLAN AutoConfig

Wlansvc

Manual

Manual

Disable if no wireless LAN adapter

WMI Performance Adapter

wmiApSrv

Manual

Manual

Workstation

LanmanWorkstation

Automatic (Started)

Automatic

Do not disable

World Wide Web Publishing Service

W3SVC

Not Installed

Not Installed

Install to run a webserver

WWAN AutoConfig

WwanSvc

Manual

Manual

Disable if no wireless broadband adapter

I hope this can assist you in securing your Windows 7 machine and gives a slightly better understanding of the services in Windows 7. In my opinion the default state of most of these services are set correctly to assist in compatiability with systems, however a good system administrator will need to tweak these to make their system secure and slightly quicker. As always please do not hesitate to comment with questions or opinions.

Till Next Time,

Jorge Orchilles