How can I find what SC.exe is doing?


kelper

Well-known member
Pro User
VIP
Local time
7:12 PM
Posts
2,804
Location
The Highlands of Scotland
OS
Windows 11 Pro 24H2 26100.2894
If I power down my laptop, the next time I log in, after all the startup programs are running, I see three sc.exe windows open and close in quick succession.
I'm pretty sure these started after the following Acer updates.

1701370991688.png

I wonder what they do and why they need to run over and over again. I have asked on the Acer forum.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 24H2 26100.2894
    Computer type
    Laptop
    Manufacturer/Model
    Acer Swift SF114-34
    CPU
    Pentium Silver N6000 1.10GHz
    Memory
    4GB
    Screen Resolution
    1920 x 1080
    Hard Drives
    SSD
    Cooling
    fanless
    Internet Speed
    150 Mbps
    Browser
    Brave
    Antivirus
    Webroot Secure Anywhere
    Other Info
    System 3

    ASUS T100TA Transformer
    Processor Intel Atom Z3740 @ 1.33GHz
    Installed RAM 2.00 GB (1.89 GB usable)
    System type 32-bit operating system, x64-based processor

    Edition Windows 10 Home
    Version 22H2 build 19045.3570
  • Operating System
    Windows 11 Pro 23H2 22631.2506
    Computer type
    Laptop
    Manufacturer/Model
    HP Mini 210-1090NR PC (bought in late 2009!)
    CPU
    Atom N450 1.66GHz
    Memory
    2GB
    Browser
    Brave
    Antivirus
    Webroot
Depending on how it's being started, you might find it with AutoRuns (sysinternals.com, then click Process Utilities on the left). There is a search, so you could find sc.exe.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 24H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Intel NUC12WSHi7
    CPU
    12th Gen Intel Core i7-1260P, 2100 MHz
    Motherboard
    NUC12WSBi7
    Memory
    64 GB
    Graphics Card(s)
    Intel Iris Xe
    Sound Card
    built-in Realtek HD audio
    Monitor(s) Displays
    Dell U3219Q
    Screen Resolution
    3840x2160 @ 60Hz
    Hard Drives
    Samsung SSD 990 PRO 1TB
    Keyboard
    CODE 104-Key Mechanical with Cherry MX Clears
    Antivirus
    Microsoft Defender
  • Operating System
    Linux Mint 21.2 (Cinnamon)
    Computer type
    PC/Desktop
    Manufacturer/Model
    Intel NUC8i5BEH
    CPU
    Intel Core i5-8259U CPU @ 2.30GHz
    Memory
    32 GB
    Graphics card(s)
    Iris Plus 655
    Keyboard
    CODE 104-Key Mechanical with Cherry MX Clears
Did you see these pages about what it is?
 

My Computers

System One System Two

  • OS
    Win11 Pro RTM
    Computer type
    Laptop
    Manufacturer/Model
    Dell Vostro 3400
    CPU
    Intel Core i5 11th Gen. 2.40GHz
    Memory
    12GB
    Hard Drives
    256GB SSD NVMe M.2
  • Operating System
    Windows 11 Pro RTM x64
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Vostro 5890
    CPU
    Intel Core i5 10th Gen. 2.90GHz
    Memory
    16GB
    Graphics card(s)
    Onboard, no VGA, using a DisplayPort-to-VGA adapter
    Monitor(s) Displays
    24" Dell
    Hard Drives
    512GB SSD NVMe, 4TB Seagate HDD
    Browser
    Firefox, Edge
    Antivirus
    Windows Defender/Microsoft Security

My Computers

System One System Two

  • OS
    Windows 11 Pro 24H2 26100.2894
    Computer type
    Laptop
    Manufacturer/Model
    Acer Swift SF114-34
    CPU
    Pentium Silver N6000 1.10GHz
    Memory
    4GB
    Screen Resolution
    1920 x 1080
    Hard Drives
    SSD
    Cooling
    fanless
    Internet Speed
    150 Mbps
    Browser
    Brave
    Antivirus
    Webroot Secure Anywhere
    Other Info
    System 3

    ASUS T100TA Transformer
    Processor Intel Atom Z3740 @ 1.33GHz
    Installed RAM 2.00 GB (1.89 GB usable)
    System type 32-bit operating system, x64-based processor

    Edition Windows 10 Home
    Version 22H2 build 19045.3570
  • Operating System
    Windows 11 Pro 23H2 22631.2506
    Computer type
    Laptop
    Manufacturer/Model
    HP Mini 210-1090NR PC (bought in late 2009!)
    CPU
    Atom N450 1.66GHz
    Memory
    2GB
    Browser
    Brave
    Antivirus
    Webroot
Do you have any Acer software on your machine like Acer Care Center? It looks to me like WU may have updated the software without uninstalling the old version first.
WU may even have installed an older version on top of the newer one.
You might try uninstalling both Acer Care and Acer Quick Access app. I would use Revo. Then reinstall from Acer Support.
Latest Acer Care Center is dated 11/7/23
Latest Acer Quick Access is 9/20/22
It's worth a shot.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 24H2 26100.2314
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 7080
    CPU
    i9-10900 10 core 20 threads
    Motherboard
    DELL 0J37VM
    Memory
    32 gb
    Graphics Card(s)
    none-Intel UHD Graphics 630
    Sound Card
    Integrated Realtek
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    1tb Solidigm m.2 nvme+256gb SKHynix m.2 nvme /External drives 512gb Samsung m.2 sata+1tb Kingston m2.nvme+ 4gb Solidigm nvme
    PSU
    500w
    Case
    MT
    Cooling
    Dell Premium
    Keyboard
    Logitech wired
    Mouse
    Logitech wireless
    Internet Speed
    so slow I'm too embarrassed to tell
    Browser
    Firefox
    Antivirus
    Defender+MWB Premium
  • Operating System
    Windows 10 Pro 22H2 19045.3930
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 9020
    CPU
    i7-4770
    Memory
    24 gb
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    256 gb Toshiba BG4 M.2 NVE SSB and 1 tb hdd
    PSU
    500w
    Case
    MT
    Cooling
    Dell factory
    Mouse
    Logitech wireless
    Keyboard
    Logitech wired
    Internet Speed
    still not telling
    Browser
    Firefox
    Antivirus
    Defender+MWB Premium
Great advice, and I'm honoured to share a birthday with you!
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 24H2 26100.2894
    Computer type
    Laptop
    Manufacturer/Model
    Acer Swift SF114-34
    CPU
    Pentium Silver N6000 1.10GHz
    Memory
    4GB
    Screen Resolution
    1920 x 1080
    Hard Drives
    SSD
    Cooling
    fanless
    Internet Speed
    150 Mbps
    Browser
    Brave
    Antivirus
    Webroot Secure Anywhere
    Other Info
    System 3

    ASUS T100TA Transformer
    Processor Intel Atom Z3740 @ 1.33GHz
    Installed RAM 2.00 GB (1.89 GB usable)
    System type 32-bit operating system, x64-based processor

    Edition Windows 10 Home
    Version 22H2 build 19045.3570
  • Operating System
    Windows 11 Pro 23H2 22631.2506
    Computer type
    Laptop
    Manufacturer/Model
    HP Mini 210-1090NR PC (bought in late 2009!)
    CPU
    Atom N450 1.66GHz
    Memory
    2GB
    Browser
    Brave
    Antivirus
    Webroot
I'm honoured to share a birthday with you!
Well, right back at 'cha. If both of us were born on 11/28 it must be a special day. This was the BIG ONE for me but at least now I have a bona fide excuse if I come across as a blathering idiot.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 24H2 26100.2314
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 7080
    CPU
    i9-10900 10 core 20 threads
    Motherboard
    DELL 0J37VM
    Memory
    32 gb
    Graphics Card(s)
    none-Intel UHD Graphics 630
    Sound Card
    Integrated Realtek
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    1tb Solidigm m.2 nvme+256gb SKHynix m.2 nvme /External drives 512gb Samsung m.2 sata+1tb Kingston m2.nvme+ 4gb Solidigm nvme
    PSU
    500w
    Case
    MT
    Cooling
    Dell Premium
    Keyboard
    Logitech wired
    Mouse
    Logitech wireless
    Internet Speed
    so slow I'm too embarrassed to tell
    Browser
    Firefox
    Antivirus
    Defender+MWB Premium
  • Operating System
    Windows 10 Pro 22H2 19045.3930
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 9020
    CPU
    i7-4770
    Memory
    24 gb
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    256 gb Toshiba BG4 M.2 NVE SSB and 1 tb hdd
    PSU
    500w
    Case
    MT
    Cooling
    Dell factory
    Mouse
    Logitech wireless
    Keyboard
    Logitech wired
    Internet Speed
    still not telling
    Browser
    Firefox
    Antivirus
    Defender+MWB Premium
@kelper ,

I am just wondering whether SC is issuing Stop commands and then Start commands because the old version of the software was running, so it had to be stopped to initiate the update, and then once updated, SC issued a Start command to activate the updated service.

In dealing with active malware services, we do have to stop the malware service before we can delete it.

Just a thought . . .

Have a great day.

Regards,
Phil
 

My Computers

System One System Two

  • OS
    Windows 11 Pro Version 24H2 (Build 26100.3037)
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell XPS8930 SE
    CPU
    Intel i7-9700K 4700 MHz
    Motherboard
    Dell XPS 8930
    Memory
    32 GB (4 x 8GB SK Hynix DDR4 @1333 MHz) (2666 MHz)
    Graphics Card(s)
    NVIDIA GeForce RTX 2060 (6 GB) GDDR6 300 MHz
    Sound Card
    None
    Monitor(s) Displays
    Dell UltraSharp U2518D 25"
    Screen Resolution
    2560 x 1440
    Hard Drives
    NVMe Intel 1024 TB
    Seagate 2 TB, SATA-III
    PSU
    850 W Gold Standard
    Case
    Dell XPS 8930 Base (Special Edition)
    Cooling
    Air
    Keyboard
    Dell 0G4D2W
    Mouse
    Dell MOCZUL
    Internet Speed
    Download 553 Mbps, Upload 686 Mbps
    Browser
    Google Chrome
    Antivirus
    ESET Smart Security Premium, plus Malwarebytes Premium
    Other Info
    BIOS Version 1.1.31
  • Operating System
    Windows 11 Pro Version 23H2 (Build 22631.4830)
    Computer type
    Laptop
    Manufacturer/Model
    Dell XPS 15 7590
    CPU
    i7-9750H 4.5 GHz
    Motherboard
    Dell XPS 15 7590
    Memory
    16 GB (2 x 8GB @ 1333 MHz) DDR4-2666 MHz
    Graphics card(s)
    NVIDIA GeForce 1650 4 GB GDDR5
    Sound Card
    None
    Monitor(s) Displays
    Dell XPS 15 7590, 15.6" InfinityEdge Anti-Glare, Non-Touch
    Screen Resolution
    1920 x 1080
    Hard Drives
    512 GB M.2 PCle NVMe SK Hynix
    PSU
    130W Power Adapter
    Case
    Dell XPS 15 7590
    Cooling
    Air
    Mouse
    Logitech M510
    Keyboard
    Laptop
    Internet Speed
    Download: 400 Mbps, Upload: 203 Mbps
    Browser
    Google Chrome
    Antivirus
    ESET Smart Security Premium, plus Malwarebytes Premium
    Other Info
    BIOS Version 1.34.0
sc.exe should only be used to uninstall service, install service and manage service states, it shouldn't run every time.
 

My Computer

System One

  • OS
    Windows 11 Pro 23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    MSI / MS-7B29
    CPU
    Intel i3 8100 @3.6Ghz
    Motherboard
    H310M PRO-VDH (MS-7B29)
    Memory
    1 x 16GB DDR4 @2400 MHz
    Graphics Card(s)
    Nvidia GeForce GT 1030 2GB SDDR4
    Sound Card
    Realtek VEN_10EC&DEV_0887 / NVIDIA VEN_10DE&DEV_0081
    Monitor(s) Displays
    Acer V226HQL
    Screen Resolution
    1920 x 1080
    Hard Drives
    SSD 500 GB Crucial MX500 / HDD 1 TB TOSHIBA DT01ACA100
    PSU
    ATX, details unknown
    Case
    Everest 551B
    Cooling
    details unknown
    Keyboard
    Mechanical Gaming Hydra R7 - Rampage
    Mouse
    Logitech G703
    Internet Speed
    Down: 28Mbps / Up: 19Mbps
    Browser
    Microsoft Edge
    Antivirus
    Microsoft Defender Antivirus
    Other Info
    Bluetooth: TP Link 5.0 Nano USB adapter UB500
    WLAN: D-Link 150 Pico USB adapter, N standard
    Web camera: Logitech C270 HD 720p @30fps
    Microphone: Trust MICO, model 23790
@zebal ,

sc.exe should only be used to uninstall service, install service and manage service states, it shouldn't run every time.

I agree, in general, BUT we do not know how the Acer updater is programmed. You cannot alter a running service without stopping it. My guess is that the programmer is using SC in the background to stop the target service, then updating that service, and then restarting the updated service. That would explain why @kelper reports:
If I power down my laptop, the next time I log in, after all the startup programs are running, I see three sc.exe windows open and close in quick succession.

What I can't figure out is why it is updating every time he restarts his computer . . . Perhaps it is an Acer Updater glitch . . .

It will be interesting to learn what information he gets from his Acer Forum post . . .

If it were my computer, I would run an SFC /scannow and a DISM /Online /Cleanup-Image /ScanHealth just to be sure that there is not any OS corruption.

Just my two cents. Have a great day.

Regards,
Phil
 

My Computers

System One System Two

  • OS
    Windows 11 Pro Version 24H2 (Build 26100.3037)
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell XPS8930 SE
    CPU
    Intel i7-9700K 4700 MHz
    Motherboard
    Dell XPS 8930
    Memory
    32 GB (4 x 8GB SK Hynix DDR4 @1333 MHz) (2666 MHz)
    Graphics Card(s)
    NVIDIA GeForce RTX 2060 (6 GB) GDDR6 300 MHz
    Sound Card
    None
    Monitor(s) Displays
    Dell UltraSharp U2518D 25"
    Screen Resolution
    2560 x 1440
    Hard Drives
    NVMe Intel 1024 TB
    Seagate 2 TB, SATA-III
    PSU
    850 W Gold Standard
    Case
    Dell XPS 8930 Base (Special Edition)
    Cooling
    Air
    Keyboard
    Dell 0G4D2W
    Mouse
    Dell MOCZUL
    Internet Speed
    Download 553 Mbps, Upload 686 Mbps
    Browser
    Google Chrome
    Antivirus
    ESET Smart Security Premium, plus Malwarebytes Premium
    Other Info
    BIOS Version 1.1.31
  • Operating System
    Windows 11 Pro Version 23H2 (Build 22631.4830)
    Computer type
    Laptop
    Manufacturer/Model
    Dell XPS 15 7590
    CPU
    i7-9750H 4.5 GHz
    Motherboard
    Dell XPS 15 7590
    Memory
    16 GB (2 x 8GB @ 1333 MHz) DDR4-2666 MHz
    Graphics card(s)
    NVIDIA GeForce 1650 4 GB GDDR5
    Sound Card
    None
    Monitor(s) Displays
    Dell XPS 15 7590, 15.6" InfinityEdge Anti-Glare, Non-Touch
    Screen Resolution
    1920 x 1080
    Hard Drives
    512 GB M.2 PCle NVMe SK Hynix
    PSU
    130W Power Adapter
    Case
    Dell XPS 15 7590
    Cooling
    Air
    Mouse
    Logitech M510
    Keyboard
    Laptop
    Internet Speed
    Download: 400 Mbps, Upload: 203 Mbps
    Browser
    Google Chrome
    Antivirus
    ESET Smart Security Premium, plus Malwarebytes Premium
    Other Info
    BIOS Version 1.34.0
My guess is that the programmer is using SC in the background to stop the target service, then updating that service, and then restarting the updated service. That would explain why @kelper reports:
Agree with you, and if that's the case then Acer coders do a bad job for sure since there are API's to manage services, sc.exe is for use by admins not programmers.

I think the OP might get best help by contacting Acer, at least to confirm that's the case.
 

My Computer

System One

  • OS
    Windows 11 Pro 23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    MSI / MS-7B29
    CPU
    Intel i3 8100 @3.6Ghz
    Motherboard
    H310M PRO-VDH (MS-7B29)
    Memory
    1 x 16GB DDR4 @2400 MHz
    Graphics Card(s)
    Nvidia GeForce GT 1030 2GB SDDR4
    Sound Card
    Realtek VEN_10EC&DEV_0887 / NVIDIA VEN_10DE&DEV_0081
    Monitor(s) Displays
    Acer V226HQL
    Screen Resolution
    1920 x 1080
    Hard Drives
    SSD 500 GB Crucial MX500 / HDD 1 TB TOSHIBA DT01ACA100
    PSU
    ATX, details unknown
    Case
    Everest 551B
    Cooling
    details unknown
    Keyboard
    Mechanical Gaming Hydra R7 - Rampage
    Mouse
    Logitech G703
    Internet Speed
    Down: 28Mbps / Up: 19Mbps
    Browser
    Microsoft Edge
    Antivirus
    Microsoft Defender Antivirus
    Other Info
    Bluetooth: TP Link 5.0 Nano USB adapter UB500
    WLAN: D-Link 150 Pico USB adapter, N standard
    Web camera: Logitech C270 HD 720p @30fps
    Microphone: Trust MICO, model 23790
I managed to catch it on video and export one frame. As I said in post #1 I have already contacted ACER.

Whatever ACER have done, it should have run once, not on every boot or log in.

1701448567024.png
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 24H2 26100.2894
    Computer type
    Laptop
    Manufacturer/Model
    Acer Swift SF114-34
    CPU
    Pentium Silver N6000 1.10GHz
    Memory
    4GB
    Screen Resolution
    1920 x 1080
    Hard Drives
    SSD
    Cooling
    fanless
    Internet Speed
    150 Mbps
    Browser
    Brave
    Antivirus
    Webroot Secure Anywhere
    Other Info
    System 3

    ASUS T100TA Transformer
    Processor Intel Atom Z3740 @ 1.33GHz
    Installed RAM 2.00 GB (1.89 GB usable)
    System type 32-bit operating system, x64-based processor

    Edition Windows 10 Home
    Version 22H2 build 19045.3570
  • Operating System
    Windows 11 Pro 23H2 22631.2506
    Computer type
    Laptop
    Manufacturer/Model
    HP Mini 210-1090NR PC (bought in late 2009!)
    CPU
    Atom N450 1.66GHz
    Memory
    2GB
    Browser
    Brave
    Antivirus
    Webroot
I ran sysinternals Autoruns; could this be the culprit?

1701449191636.png
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 24H2 26100.2894
    Computer type
    Laptop
    Manufacturer/Model
    Acer Swift SF114-34
    CPU
    Pentium Silver N6000 1.10GHz
    Memory
    4GB
    Screen Resolution
    1920 x 1080
    Hard Drives
    SSD
    Cooling
    fanless
    Internet Speed
    150 Mbps
    Browser
    Brave
    Antivirus
    Webroot Secure Anywhere
    Other Info
    System 3

    ASUS T100TA Transformer
    Processor Intel Atom Z3740 @ 1.33GHz
    Installed RAM 2.00 GB (1.89 GB usable)
    System type 32-bit operating system, x64-based processor

    Edition Windows 10 Home
    Version 22H2 build 19045.3570
  • Operating System
    Windows 11 Pro 23H2 22631.2506
    Computer type
    Laptop
    Manufacturer/Model
    HP Mini 210-1090NR PC (bought in late 2009!)
    CPU
    Atom N450 1.66GHz
    Memory
    2GB
    Browser
    Brave
    Antivirus
    Webroot
As I said in post #1 I have already contacted ACER.
Forums are ruled by users, I would look to see if there is a contact form for users or something where you could contact support, Acer itself.

I ran sysinternals Autoruns; could this be the culprit?
Very likely no because the error say service is already running and can't started for second time, and the Acer program which is using the sc.exe doesn't need cmd, it would instead use shell functions to run external executable.

I suggest you listen to what @glasskuter said, get rid of Acer manufacturer bloatware, any acer programs which are not essential or those which are not drivers but utilities.
 

My Computer

System One

  • OS
    Windows 11 Pro 23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    MSI / MS-7B29
    CPU
    Intel i3 8100 @3.6Ghz
    Motherboard
    H310M PRO-VDH (MS-7B29)
    Memory
    1 x 16GB DDR4 @2400 MHz
    Graphics Card(s)
    Nvidia GeForce GT 1030 2GB SDDR4
    Sound Card
    Realtek VEN_10EC&DEV_0887 / NVIDIA VEN_10DE&DEV_0081
    Monitor(s) Displays
    Acer V226HQL
    Screen Resolution
    1920 x 1080
    Hard Drives
    SSD 500 GB Crucial MX500 / HDD 1 TB TOSHIBA DT01ACA100
    PSU
    ATX, details unknown
    Case
    Everest 551B
    Cooling
    details unknown
    Keyboard
    Mechanical Gaming Hydra R7 - Rampage
    Mouse
    Logitech G703
    Internet Speed
    Down: 28Mbps / Up: 19Mbps
    Browser
    Microsoft Edge
    Antivirus
    Microsoft Defender Antivirus
    Other Info
    Bluetooth: TP Link 5.0 Nano USB adapter UB500
    WLAN: D-Link 150 Pico USB adapter, N standard
    Web camera: Logitech C270 HD 720p @30fps
    Microphone: Trust MICO, model 23790
@kelper ,

Could be . . . SC will not run in PowerShell. It needs CMD.

I don't see it in my Autoruns.

Have a great day.

Regards,
Phil
 

My Computers

System One System Two

  • OS
    Windows 11 Pro Version 24H2 (Build 26100.3037)
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell XPS8930 SE
    CPU
    Intel i7-9700K 4700 MHz
    Motherboard
    Dell XPS 8930
    Memory
    32 GB (4 x 8GB SK Hynix DDR4 @1333 MHz) (2666 MHz)
    Graphics Card(s)
    NVIDIA GeForce RTX 2060 (6 GB) GDDR6 300 MHz
    Sound Card
    None
    Monitor(s) Displays
    Dell UltraSharp U2518D 25"
    Screen Resolution
    2560 x 1440
    Hard Drives
    NVMe Intel 1024 TB
    Seagate 2 TB, SATA-III
    PSU
    850 W Gold Standard
    Case
    Dell XPS 8930 Base (Special Edition)
    Cooling
    Air
    Keyboard
    Dell 0G4D2W
    Mouse
    Dell MOCZUL
    Internet Speed
    Download 553 Mbps, Upload 686 Mbps
    Browser
    Google Chrome
    Antivirus
    ESET Smart Security Premium, plus Malwarebytes Premium
    Other Info
    BIOS Version 1.1.31
  • Operating System
    Windows 11 Pro Version 23H2 (Build 22631.4830)
    Computer type
    Laptop
    Manufacturer/Model
    Dell XPS 15 7590
    CPU
    i7-9750H 4.5 GHz
    Motherboard
    Dell XPS 15 7590
    Memory
    16 GB (2 x 8GB @ 1333 MHz) DDR4-2666 MHz
    Graphics card(s)
    NVIDIA GeForce 1650 4 GB GDDR5
    Sound Card
    None
    Monitor(s) Displays
    Dell XPS 15 7590, 15.6" InfinityEdge Anti-Glare, Non-Touch
    Screen Resolution
    1920 x 1080
    Hard Drives
    512 GB M.2 PCle NVMe SK Hynix
    PSU
    130W Power Adapter
    Case
    Dell XPS 15 7590
    Cooling
    Air
    Mouse
    Logitech M510
    Keyboard
    Laptop
    Internet Speed
    Download: 400 Mbps, Upload: 203 Mbps
    Browser
    Google Chrome
    Antivirus
    ESET Smart Security Premium, plus Malwarebytes Premium
    Other Info
    BIOS Version 1.34.0
The "SafeBoot\AlternateShell" registry entry is totally normal. It is the name of the shell used when booting to "Safe mode with Command Prompt." It's not the culprit. I agree with zebal/glasskuter. Uninstall the Acer stuff and see if it goes away. If not, we can dig deeper.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 24H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Intel NUC12WSHi7
    CPU
    12th Gen Intel Core i7-1260P, 2100 MHz
    Motherboard
    NUC12WSBi7
    Memory
    64 GB
    Graphics Card(s)
    Intel Iris Xe
    Sound Card
    built-in Realtek HD audio
    Monitor(s) Displays
    Dell U3219Q
    Screen Resolution
    3840x2160 @ 60Hz
    Hard Drives
    Samsung SSD 990 PRO 1TB
    Keyboard
    CODE 104-Key Mechanical with Cherry MX Clears
    Antivirus
    Microsoft Defender
  • Operating System
    Linux Mint 21.2 (Cinnamon)
    Computer type
    PC/Desktop
    Manufacturer/Model
    Intel NUC8i5BEH
    CPU
    Intel Core i5-8259U CPU @ 2.30GHz
    Memory
    32 GB
    Graphics card(s)
    Iris Plus 655
    Keyboard
    CODE 104-Key Mechanical with Cherry MX Clears
@pseymour ,

I don't have that entry in my Registry. That said, I am not contesting that the registry entry is "totally normal." What I am curious about is why Autoruns is showing that CMD is running . . .

I don't think that @kelper is booted into Safe Mode. This must be some kind of special Acer thing! 🤷‍♂️ I am not convinced that it is normal, but I am eager to learn from my mistakes!

I do agree that it would be wise to uninstall any Acer "bloatware," but only if you have backed up your computer first. You never know when you'll have to roll back. I would also create a System Restore Point. You can't have "too much backup," as someone here reminds us! 😎

Just my two cents. Have a great day.

Regards,
Phil
 

My Computers

System One System Two

  • OS
    Windows 11 Pro Version 24H2 (Build 26100.3037)
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell XPS8930 SE
    CPU
    Intel i7-9700K 4700 MHz
    Motherboard
    Dell XPS 8930
    Memory
    32 GB (4 x 8GB SK Hynix DDR4 @1333 MHz) (2666 MHz)
    Graphics Card(s)
    NVIDIA GeForce RTX 2060 (6 GB) GDDR6 300 MHz
    Sound Card
    None
    Monitor(s) Displays
    Dell UltraSharp U2518D 25"
    Screen Resolution
    2560 x 1440
    Hard Drives
    NVMe Intel 1024 TB
    Seagate 2 TB, SATA-III
    PSU
    850 W Gold Standard
    Case
    Dell XPS 8930 Base (Special Edition)
    Cooling
    Air
    Keyboard
    Dell 0G4D2W
    Mouse
    Dell MOCZUL
    Internet Speed
    Download 553 Mbps, Upload 686 Mbps
    Browser
    Google Chrome
    Antivirus
    ESET Smart Security Premium, plus Malwarebytes Premium
    Other Info
    BIOS Version 1.1.31
  • Operating System
    Windows 11 Pro Version 23H2 (Build 22631.4830)
    Computer type
    Laptop
    Manufacturer/Model
    Dell XPS 15 7590
    CPU
    i7-9750H 4.5 GHz
    Motherboard
    Dell XPS 15 7590
    Memory
    16 GB (2 x 8GB @ 1333 MHz) DDR4-2666 MHz
    Graphics card(s)
    NVIDIA GeForce 1650 4 GB GDDR5
    Sound Card
    None
    Monitor(s) Displays
    Dell XPS 15 7590, 15.6" InfinityEdge Anti-Glare, Non-Touch
    Screen Resolution
    1920 x 1080
    Hard Drives
    512 GB M.2 PCle NVMe SK Hynix
    PSU
    130W Power Adapter
    Case
    Dell XPS 15 7590
    Cooling
    Air
    Mouse
    Logitech M510
    Keyboard
    Laptop
    Internet Speed
    Download: 400 Mbps, Upload: 203 Mbps
    Browser
    Google Chrome
    Antivirus
    ESET Smart Security Premium, plus Malwarebytes Premium
    Other Info
    BIOS Version 1.34.0
MSFT article for AlternateShell I don't take what you said as argument; just posting that for completeness.

AutoRuns isn't showing that cmd is running. It's just showing that cmd.exe is the shell that would be loaded if one were to boot to Safe Mode with Command Prompt on that system.

Anyway, I came back to post a Sysmon config file for tracking sc.exe process creation, in case this thread comes to that. :-)
 

Attachments

My Computers

System One System Two

  • OS
    Windows 11 Pro 24H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Intel NUC12WSHi7
    CPU
    12th Gen Intel Core i7-1260P, 2100 MHz
    Motherboard
    NUC12WSBi7
    Memory
    64 GB
    Graphics Card(s)
    Intel Iris Xe
    Sound Card
    built-in Realtek HD audio
    Monitor(s) Displays
    Dell U3219Q
    Screen Resolution
    3840x2160 @ 60Hz
    Hard Drives
    Samsung SSD 990 PRO 1TB
    Keyboard
    CODE 104-Key Mechanical with Cherry MX Clears
    Antivirus
    Microsoft Defender
  • Operating System
    Linux Mint 21.2 (Cinnamon)
    Computer type
    PC/Desktop
    Manufacturer/Model
    Intel NUC8i5BEH
    CPU
    Intel Core i5-8259U CPU @ 2.30GHz
    Memory
    32 GB
    Graphics card(s)
    Iris Plus 655
    Keyboard
    CODE 104-Key Mechanical with Cherry MX Clears
@pseymour ,

Thank you for your reply. I am still confused. I must be getting too old!

@kelper is showing the Autoruns printout for his Logon tab. Why would that entry be listed?

Here is my Logon tab:

Screenshot 2023-12-01 140216.png

I have no such entry. Obviously, I am starting up a lot more junk than he is, but I think that entry is being loaded on startup on his computer, based on what little I know, . . . and I do concede to not being a Windows expert.

I have to be away now for a few hours. This is my afternoon every week to update, backup, and scan my computers. I will check back. I am always eager to learn new tricks and understand the internal workings of Windows. Thank you for sharing your expertise.

Have a great day.

Regards,
Phil
 

My Computers

System One System Two

  • OS
    Windows 11 Pro Version 24H2 (Build 26100.3037)
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell XPS8930 SE
    CPU
    Intel i7-9700K 4700 MHz
    Motherboard
    Dell XPS 8930
    Memory
    32 GB (4 x 8GB SK Hynix DDR4 @1333 MHz) (2666 MHz)
    Graphics Card(s)
    NVIDIA GeForce RTX 2060 (6 GB) GDDR6 300 MHz
    Sound Card
    None
    Monitor(s) Displays
    Dell UltraSharp U2518D 25"
    Screen Resolution
    2560 x 1440
    Hard Drives
    NVMe Intel 1024 TB
    Seagate 2 TB, SATA-III
    PSU
    850 W Gold Standard
    Case
    Dell XPS 8930 Base (Special Edition)
    Cooling
    Air
    Keyboard
    Dell 0G4D2W
    Mouse
    Dell MOCZUL
    Internet Speed
    Download 553 Mbps, Upload 686 Mbps
    Browser
    Google Chrome
    Antivirus
    ESET Smart Security Premium, plus Malwarebytes Premium
    Other Info
    BIOS Version 1.1.31
  • Operating System
    Windows 11 Pro Version 23H2 (Build 22631.4830)
    Computer type
    Laptop
    Manufacturer/Model
    Dell XPS 15 7590
    CPU
    i7-9750H 4.5 GHz
    Motherboard
    Dell XPS 15 7590
    Memory
    16 GB (2 x 8GB @ 1333 MHz) DDR4-2666 MHz
    Graphics card(s)
    NVIDIA GeForce 1650 4 GB GDDR5
    Sound Card
    None
    Monitor(s) Displays
    Dell XPS 15 7590, 15.6" InfinityEdge Anti-Glare, Non-Touch
    Screen Resolution
    1920 x 1080
    Hard Drives
    512 GB M.2 PCle NVMe SK Hynix
    PSU
    130W Power Adapter
    Case
    Dell XPS 15 7590
    Cooling
    Air
    Mouse
    Logitech M510
    Keyboard
    Laptop
    Internet Speed
    Download: 400 Mbps, Upload: 203 Mbps
    Browser
    Google Chrome
    Antivirus
    ESET Smart Security Premium, plus Malwarebytes Premium
    Other Info
    BIOS Version 1.34.0
I'm wary of hijacking OP's thread with this AlternateShell thing. You also don't show an entry for
Code:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
whereas I have entries for both on all of my Win11 computers. I also checked several Win11 machines where I work. Why those don't show in AutoRuns for your machine, I do not know.

Regardless, the executable in the AlternateShell entry does not load during a normal startup. That's not what that registry value is for (see the MSFT article I linked earlier).

Again, AutoRuns isn't showing that cmd is running. In fact, neither is OP's screenshot. The screenshot shows sc.exe is running. It can be started by a cmd.exe process, but it doesn't have to be. You can run "sc.exe query" from the Run dialog box just fine, although it'll scroll by very quickly and you won't be able to read it. :-) In that instance, the parent process will be explorer.exe, not cmd.exe. You can run sc.exe from PowerShell also, although that's a little silly, because PowerShell has cmdlets for most of what sc.exe does.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 24H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Intel NUC12WSHi7
    CPU
    12th Gen Intel Core i7-1260P, 2100 MHz
    Motherboard
    NUC12WSBi7
    Memory
    64 GB
    Graphics Card(s)
    Intel Iris Xe
    Sound Card
    built-in Realtek HD audio
    Monitor(s) Displays
    Dell U3219Q
    Screen Resolution
    3840x2160 @ 60Hz
    Hard Drives
    Samsung SSD 990 PRO 1TB
    Keyboard
    CODE 104-Key Mechanical with Cherry MX Clears
    Antivirus
    Microsoft Defender
  • Operating System
    Linux Mint 21.2 (Cinnamon)
    Computer type
    PC/Desktop
    Manufacturer/Model
    Intel NUC8i5BEH
    CPU
    Intel Core i5-8259U CPU @ 2.30GHz
    Memory
    32 GB
    Graphics card(s)
    Iris Plus 655
    Keyboard
    CODE 104-Key Mechanical with Cherry MX Clears

Latest Support Threads

Back
Top Bottom