File details
File name: backupnowezsvr.exe
Name: NTI Backup Now EZ
Description: Backup Now EZ Module
Version: 2.0.2.8
Size: 44.25 KB
Original file name: IScheduleSvc.exe
Digital certificate
Certificate authority:
VeriSign
Effective date: 10/26/2008
Expiration date: 12/21/2011
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0000260540%
Privileged CPU:
0.0000164598%

User CPU:
0.00000959421269%

Privileged CPU time: 187.2 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
1,039,646,238
CPU cycle count /min: 10,155,566
 | Memory utilization averages |
Committed memory:
93.71 MB
Peak committed memory: 94.71 MB
Paged memory:
4.14 MB
Peak paged memory: 4.17 MB
Paged system memory:
154.18 KB
Non-paged system memory: 6.13 KB
Working set memory:
8.9 MB
Peak working set memory: 9.18 MB
Min working set memory: 8.77 MB
Private memory:
4.14 MB
Page faults:
3,429
Page faults /min: 1
 | Process I/O averages |
Total read operations:
34
Read operations /min: 1
Total read transfer: 5.95 KB
Read transfer /min: 0 Bytes
Total write operations:
18
Write operations /min: 1
Total write transfer: 2.84 KB
Write transfer /min: 0 Bytes
Total other operations:
1,028
Other operations /min: 1
Total other transfer: 4.37 KB
Other Transfer /min: 0 Bytes
Resources
Handle count average: 146
Thread count average: 8
Thread resource averages
Total CPU: 0.000010984864%
Privileged CPU: 0.000008238648%
User CPU: 0.000002746216%
CPU Cycle count /sec: 27,839
Module memory size: 496 KB
Total CPU: 0.000010984803%
Privileged CPU: 0.000008238602%
User CPU: 0.000002746201%
CPU Cycle count /sec: 178
Module memory size: 52 KB
Total CPU: 0.000008238638%
Privileged CPU: 0.000003661618%
User CPU: 0.000004577020%
CPU Cycle count /sec: 46,681
Module memory size: 420 KB
advapi32.dll

Total CPU: 0.000002746210%
Privileged CPU: 0.000002746210%
User CPU: 0.000000000000%
CPU Cycle count /sec: 69
Module memory size: 792 KB
Process details
Runs as (owner): System
Integrety level: System
Windows platform: 32-bit
Runs as a service: Yes
Parent Process
Process Command
"C:\Program Files\NewTech Infosystems\Backup Now EZ\BackupNowEZSvr.exe"
Service details
Name: NTI BackupNowEZSvr
Service type: Win32OwnProcess, InteractiveProcess
Description: “NTI BackupNowEZ Manage backup/Sync jobs and etc...”
Image hashes
MD5: a23e6b28095f026c0b2bdc2650459423
SHA-1: b0c2851ce745767a87bb22705efce3c79e3a13da
SHA-256: 182882417928f05bab144451db860d350b8500c0bd0487296911eef02d74c5b6
PE image details
Subsystem: Windows Console
Langauge*: Microsoft Visual C++ 9.0
File packed: No
Import Table
advapi32.dll

OpenServiceW
SetSecurityDescriptorDacl
GetUserNameW
StartServiceCtrlDispatcherW
ChangeServiceConfig2W
DeleteService
ControlService
QueryServiceStatusEx
StartServiceW
InitializeSecurityDescriptor
CloseServiceHandle
CreateServiceW
OpenSCManagerW
SetServiceStatus
RegisterServiceCtrlHandlerW
kernel32.dll

InterlockedExchange
InterlockedCompareExchange
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
QueryPerformanceCounter
FreeLibrary
GetSystemTimeAsFileTime
GetCurrentProcessId
DisconnectNamedPipe
FlushFileBuffers
lstrcpynA
WideCharToMultiByte
GetCurrentThreadId
WriteFile
ReadFile
SetFilePointer
CreateFileW
CreateDirectoryW
LeaveCriticalSection
EnterCriticalSection
Sleep
GetModuleFileNameW
GetStdHandle
GetCommandLineW
GetCurrentProcess
OutputDebugStringW
WaitForSingleObject
ResetEvent
SetEvent
CreateEventW
DeleteCriticalSection
InitializeCriticalSection
GetTickCount
LoadLibraryW
GetProcAddress
GetModuleHandleW
GetExitCodeThread
CreateThread
ConnectNamedPipe
SetLastError
CreateNamedPipeW
GetProcessHeap
HeapFree
FormatMessageW
lstrlenW
HeapAlloc
CloseHandle
GetLastError
msvcp90.dll
msvcr90.dll
ole32.dll

CoInitializeSecurity
CoInitialize
CoUninitialize
shlwapi.dll

PathFileExistsW
PathRemoveFileSpecW
user32.dll

MsgWaitForMultipleObjects
GetMessageW
PostThreadMessageW