File details
File name: pwecsrvc.exe
Name: Passport Web Edition Client Service Driver
Description: Passport Web Edition Client Service Driver
Version: 2, 1, 0, 3
Size: 20.1 KB
Original file name: pwecsrvc.exe
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0003075283%
Privileged CPU:
0.0002314729%

User CPU:
0.00007605539127%

Privileged CPU time: 140.62 ms
Privileged CPU time /min: 0 ms
Context switches /sec:
3
 | Memory utilization averages |
Committed memory:
64.53 MB
Peak committed memory: 65.53 MB
Paged memory:
27.55 MB
Peak paged memory: 27.57 MB
Paged system memory:
35.18 KB
Non-paged system memory: 5.21 KB
Working set memory:
4.95 MB
Peak working set memory: 4.95 MB
Min working set memory: 4.91 MB
Private memory:
27.55 MB
Page faults:
1,292
Page faults /min: 1
 | Process I/O averages |
Total read operations:
18
Read operations /min: 1
Total read transfer: 17.91 KB
Read transfer /min: 19 Bytes
Total write operations:
17
Write operations /min: 1
Total write transfer: 1.43 KB
Write transfer /min: 2 Bytes
Total other operations:
1,661
Other operations /min: 2
Total other transfer: 155.81 KB
Other Transfer /min: 168 Bytes
 | GUI Object Averages |
GDI objects:
11
USER objects:
11
Resources
Handle count average: 103
Thread count average: 6
Thread resource averages
Total CPU: 0.000232374222%
Privileged CPU: 0.000232374222%
User CPU: 0.000000000000%
Context switches /sec: 1
Module memory size: 20 KB
Total CPU: 0.000051652372%
Privileged CPU: 0.000000000000%
User CPU: 0.000051652372%
Context switches /sec: 1
Module memory size: 352 KB
Process details
Runs as (owner): User
Integrety level: Undefined
Windows platform: 32-bit
Parent Process
Process Command
"C:\Program Files\NCR\Passport Web Edition\pwecsrvc.exe"
Startup files (all users) run details
Name: Passport Web Edition Client
Command: C:\Program Files\NCR\Passport Web Edition\pwecsrvc.exe
Network connectivity
TCP: localhost on port 80
Image hashes
MD5: a244dc912fb9ac44aff70d022e9375cf
SHA-1: 2ae1192fe43872fdf4ca4068330485d9f3c9d2d8
SHA-256: 73cd13c7620988d41e9ca8db0d8988ce11de40d1875e7c1fcafc861fbcd1c102
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File packed: No
Import Table
advapi32.dll

QueryServiceStatus
DeregisterEventSource
InitializeSecurityDescriptor
SetSecurityDescriptorDacl
RegOpenKeyA
RegCreateKeyA
RegCloseKey
RegQueryValueExA
RegSetValueExA
RegisterEventSourceA
CloseServiceHandle
DeleteService
ControlService
RegDeleteValueA
OpenSCManagerA
OpenServiceA
ReportEventA
kernel32.dll

GetLastError
CreateThread
WaitForSingleObject
Sleep
OpenEventA
SetEvent
CloseHandle
SetCurrentDirectoryA
CreateDirectoryA
GetModuleFileNameA
CreateEventA
GetModuleHandleA
GetStartupInfoA
msvcrt.dll
ole32.dll

pwecdrvr.dll

pptcLogString
pptcStopHttpServer
pptcStartHttpServer
rpcrt4.dll

UuidToStringA
RpcStringFreeA
user32.dll

PostQuitMessage
DefWindowProcA
PostMessageA
DispatchMessageA
CreateWindowExA
ShowWindow
TranslateMessage
GetMessageA
RegisterClassA