File details
File name: fsssvc.exe
Name: Windows Live Family Safety Service
Description: Windows Live Family Safety Service
Version: 14.0.8064.0206
Size: 520.86 KB
Original file name: fsssvc.exe
Digital certificate
Certificate authority:
Microsoft Corporation
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0000250578%
Privileged CPU:
0.0000195678%

User CPU:
0.00000548997313%

Privileged CPU time: 499.2 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
1,380,832,826
CPU cycle count /min: 137,623
 | Memory utilization averages |
Committed memory:
78.23 MB
Peak committed memory: 84.43 MB
Paged memory:
5.01 MB
Peak paged memory: 5.07 MB
Paged system memory:
138.73 KB
Non-paged system memory: 10.02 KB
Working set memory:
6.42 MB
Peak working set memory: 9.64 MB
Min working set memory: 6.42 MB
Private memory:
5.01 MB
Page faults:
12,311
Page faults /min: 1
 | Process I/O averages |
Total read operations:
31
Read operations /min: 1
Total read transfer: 2.57 KB
Read transfer /min: 0 Bytes
Total write operations:
29
Write operations /min: 1
Total write transfer: 3.09 KB
Write transfer /min: 0 Bytes
Total other operations:
8,034
Other operations /min: 1
Total other transfer: 106.86 KB
Other Transfer /min: 5 Bytes
Resources
Handle count average: 323
Thread count average: 9
Thread resource averages
advapi32.dll

Total CPU: 0.000011010023%
Privileged CPU: 0.000003670008%
User CPU: 0.000007340015%
CPU Cycle count /sec: 187
Module memory size: 792 KB
Total CPU: 0.000008563351%
Privileged CPU: 0.000007951683%
User CPU: 0.000000611668%
CPU Cycle count /sec: 203
Module memory size: 716 KB
ntdll.dll

Total CPU: 0.000001223336%
Privileged CPU: 0.000001223336%
User CPU: 0.000000000000%
CPU Cycle count /sec: 14
Module memory size: 1.16 MB
Process details
Runs as (owner): System
Integrety level: System
Windows platform: 32-bit
Runs as a service: Yes
Parent Process
Process Command
"C:\Program Files\Windows Live\Family Safety\fsssvc.exe"
Service details
Name: Windows Live Family Safety
Service name: fsssvc
Service type:
Win32OwnProcess
Description: “This service enables Family Safety on the computer. If this service is not running, Family Safety will not work.”
Image hashes
MD5: 9b1622ebeb31b3411b13382ffcb8737d
SHA-1: d5e01a0fb7c6d16b336a6cdbbaf6764acc81eb94
SHA-256: 528cbde1b92eb27b0fe7d7f5944a3828c26e51a27532bb434d66a3886aed3901
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++ 9.0
File packed: No
Import Table
advapi32.dll

RegDeleteKeyW
RegDeleteValueW
RegCloseKey
RegCreateKeyExW
RegOpenKeyExW
RegQueryValueExW
RegSetValueExW
SetServiceStatus
DeregisterEventSource
ReportEventW
RegisterEventSourceW
CloseServiceHandle
OpenServiceW
OpenSCManagerW
RegQueryInfoKeyW
RegEnumKeyExW
CreateServiceW
DeleteService
ControlService
RegisterServiceCtrlHandlerW
StartServiceCtrlDispatcherW
AuditSetSystemPolicy
ChangeServiceConfigW
StartServiceW
QueryServiceStatus
LogonUserW
AllocateAndInitializeSid
FreeSid
LookupAccountSidW
OpenProcessToken
CheckTokenMembership
RegEnumValueW
LookupAccountNameW
ConvertStringSidToSidW
ConvertSidToStringSidW
CreateWellKnownSid
AdjustTokenPrivileges
LookupPrivilegeValueW
EventWrite
EventUnregister
EventRegister
CreateProcessAsUserW
EqualSid
GetTokenInformation
RegOpenKeyExA
OpenThreadToken
SetThreadToken
RevertToSelf
RegOpenCurrentUser
DuplicateToken
GetSidLengthRequired
InitializeSid
GetSidSubAuthority
SetSecurityDescriptorDacl
SetSecurityDescriptorGroup
SetSecurityDescriptorOwner
CopySid
IsValidSid
GetLengthSid
UnregisterTraceGuids
RegisterTraceGuidsW
GetTraceLoggerHandle
GetTraceEnableLevel
GetTraceEnableFlags
TraceMessage
GetSecurityDescriptorLength
MakeSelfRelativeSD
InitializeSecurityDescriptor
GetSecurityDescriptorOwner
GetSecurityDescriptorGroup
GetSecurityDescriptorDacl
GetSecurityDescriptorSacl
MakeAbsoluteSD
GetSecurityDescriptorControl
GetAclInformation
InitializeAcl
AddAce
CryptDecrypt
CryptCreateHash
CryptDeriveKey
CryptHashData
ImpersonateLoggedOnUser
GetUserNameW
CryptDestroyKey
CryptDestroyHash
CryptGenRandom
CryptAcquireContextW
CryptReleaseContext
crypt32.dll

CertGetNameStringA
CertFreeCertificateContext
CryptUnprotectData
CryptProtectData
CertCreateCertificateContext
CertVerifyCertificateChainPolicy
CryptHashPublicKeyInfo
fwpuclnt.dll

FwpmTransactionBegin0
FwpmEngineOpen0
FwpmTransactionCommit0
FwpmSubLayerDeleteByKey0
FwpmCalloutDeleteByKey0
FwpmFilterDeleteByKey0
FwpmTransactionAbort0
FwpmSubLayerAdd0
FwpmFilterAdd0
FwpmEngineClose0
FwpmCalloutAdd0
iphlpapi.dll

CancelIPChangeNotify
NotifyAddrChange
kernel32.dll

CallbackMayRunLong
CreateThreadpool
SetThreadpoolThreadMinimum
SetThreadpoolThreadMaximum
CloseThreadpool
ResetEvent
GlobalFree
LCMapStringEx
ExpandEnvironmentStringsW
GetFileAttributesW
SetFileAttributesW
CreateDirectoryW
ConvertFiberToThread
WaitForMultipleObjectsEx
OpenThread
SetThreadpoolTimer
TlsSetValue
TlsGetValue
TlsFree
TlsAlloc
VirtualLock
VirtualUnlock
IsWow64Process
GetComputerNameW
EnumResourceNamesW
GetSystemDefaultLCID
GetSystemDefaultUILanguage
QueryPerformanceFrequency
CloseThreadpoolWait
WaitForThreadpoolWaitCallbacks
CreateThreadpoolTimer
SetThreadpoolWait
CloseThreadpoolTimer
LocalFree
TrySubmitThreadpoolCallback
CreateThreadpoolWait
QueueUserAPC
HeapDestroy
HeapAlloc
HeapFree
HeapReAlloc
HeapSize
GetProcessHeap
VirtualQuery
VirtualProtect
VirtualAlloc
ResumeThread
FlushInstructionCache
GetThreadContext
SetThreadContext
SuspendThread
SetLastError
SetDllDirectoryW
GetCommandLineW
LoadLibraryExW
FindResourceW
LoadResource
SizeofResource
MultiByteToWideChar
FreeLibrary
GetModuleFileNameW
lstrcmpiW
GetModuleHandleW
GetProcAddress
GetLastError
DeleteCriticalSection
InitializeCriticalSection
LeaveCriticalSection
EnterCriticalSection
RaiseException
lstrlenW
WaitForThreadpoolTimerCallbacks
InterlockedExchange
Sleep
InterlockedCompareExchange
GetStartupInfoW
SetUnhandledExceptionFilter
QueryPerformanceCounter
GetTickCount
GetCurrentThreadId
GetCurrentProcessId
GetSystemTimeAsFileTime
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
IsDebuggerPresent
CompareStringW
LockResource
FindResourceExW
CloseHandle
WaitForSingleObject
GetThreadUILanguage
CreateThread
CreateEventW
SetEvent
InterlockedIncrement
InterlockedDecrement
GetCurrentThread
HeapSetInformation
GetOverlappedResult
InitializeSRWLock
AcquireSRWLockShared
ReleaseSRWLockShared
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
MoveFileExW
DeleteFileW
GetTempFileNameW
GetTempPathW
GetTickCount64
GetVersionExW
WideCharToMultiByte
CreateFileW
ReadFile
WriteFile
GetFileSize
SetFilePointer
FindFirstFileW
FindNextFileW
FindClose
GetSystemInfo
DeviceIoControl
SleepEx
WakeAllConditionVariable
SetThreadPriority
InitializeConditionVariable
OpenProcess
QueryFullProcessImageNameW
SwitchToFiber
DeleteFiber
IsThreadAFiber
SleepConditionVariableSRW
CreateFiberEx
ConvertThreadToFiber
InitializeCriticalSectionAndSpinCount
DecodePointer
EncodePointer
IsProcessorFeaturePresent
LoadLibraryW
GlobalAlloc
GetLongPathNameW
GetShortPathNameW
GetFullPathNameW
FileTimeToSystemTime
FileTimeToLocalFileTime
SystemTimeToFileTime
GetLocalTime
CreateMutexW
ReleaseMutex
DeleteTimerQueueTimer
ChangeTimerQueueTimer
CreateTimerQueueTimer
CreateTimerQueue
DeleteTimerQueueEx
InterlockedExchangeAdd
GetSystemDirectoryW
GetACP
GetLocaleInfoA
GetThreadLocale
GetVersionExA
lstrlenA
WaitForMultipleObjects
CreateIoCompletionPort
ReadDirectoryChangesW
PostQueuedCompletionStatus
CancelIo
GetQueuedCompletionStatus
BindIoCompletionCallback
QueueUserWorkItem
LCMapStringW
CompareFileTime
GetFileTime
msvcp110.dll
msvcp80.dll
msvcp90.dll
msvcr110.dll
msvcr80.dll
msvcr90.dll
netapi32.dll

NetGetJoinInformation
NetUserGetLocalGroups
NetApiBufferFree
ole32.dll

CoTaskMemRealloc
CoTaskMemAlloc
CoUninitialize
CoTaskMemFree
CoInitializeEx
CoSetProxyBlanket
StringFromGUID2
OleRun
CoRevokeClassObject
CoRegisterClassObject
CoResumeClassObjects
CoInitializeSecurity
CoDisconnectObject
CoCreateGuid
CoCreateInstance
StringFromCLSID
CreateStreamOnHGlobal
CoRevertToSelf
CoImpersonateClient
CLSIDFromProgID
CoSuspendClassObjects
CLSIDFromString
CoReleaseServerProcess
CoAddRefServerProcess
CoGetCallContext
psapi.dll

rpcrt4.dll

MesDecodeBufferHandleCreate
NdrMesTypeFree2
NdrMesTypeDecode2
MesHandleFree
MesEncodeDynBufferHandleCreate
NdrMesTypeEncode2
secur32.dll

LsaGetLogonSessionData
LsaFreeReturnBuffer
shell32.dll

SHFileOperationW
SHGetKnownFolderPath
SHGetFolderPathW
shlwapi.dll

UrlCanonicalizeA
UrlEscapeA
PathCombineW
PathFindExtensionW
PathRemoveBackslashW
PathIsDirectoryW
PathCanonicalizeW
PathRemoveFileSpecW
PathFindFileNameW
StrRChrW
SHCreateStreamOnFileEx
UrlApplySchemeW
UrlGetPartW
UrlCombineW
UrlCanonicalizeW
PathAppendW
urlmon.dll

CoInternetCreateSecurityManager
user32.dll

DispatchMessageW
TranslateMessage
CharUpperW
CharNextW
LoadStringW
GetMessageW
PostThreadMessageW
MessageBoxW
UnregisterClassA
userenv.dll

CreateEnvironmentBlock
DestroyEnvironmentBlock
version.dll

VerQueryValueW
GetFileVersionInfoW
GetFileVersionInfoSizeW
webservices.dll

WsAddCustomHeader
WsWriteXmlBufferToBytes
WsFreeWriter
WsCreateWriter
WsGetFaultErrorProperty
WsCall
WsCreateServiceProxyFromTemplate
WsFreeHeap
WsFreeError
WsFreeServiceProxy
WsCloseServiceProxy
WsOpenServiceProxy
WsAbandonCall
WsCreateHeap
WsCreateError
WsAlloc
WsGetErrorProperty
WsGetErrorString
wevtapi.dll

EvtClose
EvtRender
EvtSubscribe
winhttp.dll

WinHttpConnect
WinHttpOpenRequest
WinHttpOpen
WinHttpGetIEProxyConfigForCurrentUser
WinHttpGetProxyForUrl
WinHttpCrackUrl
WinHttpCloseHandle
WinHttpSendRequest
WinHttpReadData
WinHttpQueryDataAvailable
WinHttpReceiveResponse
WinHttpQueryHeaders
WinHttpSetOption
WinHttpSetCredentials
wininet.dll

InternetCrackUrlA
DetectAutoProxyUrl
InternetCreateUrlA
wintrust.dll

WTHelperGetProvCertFromChain
WTHelperGetProvSignerFromChain
WinVerifyTrust
WTHelperProvDataFromStateData
ws2_32.dll

InetNtopW
getaddrinfo
freeaddrinfo
WSAAddressToStringA
WSAAddressToStringW
wtsapi32.dll

WTSQuerySessionInformationW
WTSFreeMemory
WTSQueryUserToken
WTSEnumerateSessionsW