File details
File name: WLIDSVC.EXE
Name: Microsoft® CoReXT
Description: Microsoft® Windows Live ID Service
Version: 7.250.4226.0
Size: 2.18 MB
Original file name: Wlidsvc.exe
Digital certificate
Certificate authority:
Microsoft Corporation
Effective date: 12/7/2009
Expiration date: 3/7/2011
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0000987463%
Privileged CPU:
0.0000706625%

User CPU:
0.00002808382374%

Privileged CPU time: 156 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
1,848,082,965
CPU cycle count /min: 15,358,884
Context switches /sec:
2
 | Memory utilization averages |
Committed memory:
85.54 MB
Peak committed memory: 88.04 MB
Paged memory:
7.26 MB
Peak paged memory: 8.43 MB
Paged system memory:
134.28 KB
Non-paged system memory: 22.02 KB
Working set memory:
15.58 MB
Peak working set memory: 15.63 MB
Min working set memory: 15.52 MB
Private memory:
7.26 MB
Page faults:
6,489
Page faults /min: 16
 | Process I/O averages |
Total read operations:
17
Read operations /min: 1
Total read transfer: 9.11 KB
Read transfer /min: 23 Bytes
Total write operations:
5
Write operations /min: 1
Total write transfer: 3.27 KB
Write transfer /min: 8 Bytes
Total other operations:
1,301
Other operations /min: 3
Total other transfer: 36.75 KB
Other Transfer /min: 94 Bytes
Resources
Handle count average: 368
Thread count average: 10
Thread resource averages
ntdll.dll

Total CPU: 0.000141810999%
Privileged CPU: 0.000113570936%
User CPU: 0.000028240063%
CPU Cycle count /sec: 25,647
Module memory size: 1.66 MB
Total CPU: 0.000112955405%
Privileged CPU: 0.000056477702%
User CPU: 0.000056477702%
CPU Cycle count /sec: 1,545
Module memory size: 2.21 MB
Process details
Runs as (owner): System
Integrety level: System
Windows platform: 64-bit
Runs as a service: Yes
Parent Process
Child Process
Process Command
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
Service details
Name: wlidsvc
Image hashes
MD5: 3396e5fdde8ec3b7299d86cfa8fd7001
SHA-1: 36b66b5ee153eeb248bbad52f3cd36fd30ab016f
PE image details
File entropy: 6.00959
File packed: No
Import Table
advapi32.dll

CryptDestroyHash
CryptDestroyKey
MakeAbsoluteSD
ConvertStringSecurityDescriptorToSecurityDescriptorW
RegDeleteKeyW
RegDeleteValueW
RegCloseKey
RegCreateKeyExW
RegOpenKeyExW
RegQueryValueExW
RegSetValueExW
RegQueryInfoKeyW
DeregisterEventSource
ReportEventW
RegisterEventSourceW
SetServiceStatus
CloseServiceHandle
OpenServiceW
OpenSCManagerW
RegEnumKeyExW
CreateServiceW
DeleteService
ControlService
RegisterServiceCtrlHandlerExW
StartServiceCtrlDispatcherW
SetThreadToken
GetTokenInformation
OpenThreadToken
CheckTokenMembership
CryptSetProvParam
CryptGetUserKey
AllocateAndInitializeSid
GetLengthSid
SetSecurityDescriptorDacl
SetSecurityDescriptorGroup
SetSecurityDescriptorOwner
IsValidSecurityDescriptor
AccessCheck
FreeSid
OpenProcessToken
InitializeSecurityDescriptor
InitializeAcl
AddAccessAllowedAce
RegNotifyChangeKeyValue
CryptGetProvParam
CryptGetKeyParam
CryptDeriveKey
CryptVerifySignatureW
CryptSignHashW
CredWriteDomainCredentialsW
CredReadW
CreateProcessAsUserW
CryptImportKey
CryptExportKey
EqualSid
GetSidSubAuthorityCount
GetSidLengthRequired
GetSidIdentifierAuthority
InitializeSid
GetSidSubAuthority
IsValidSid
RegQueryValueExA
RegEnumValueA
CryptCreateHash
CryptSetHashParam
CryptGetHashParam
CryptHashData
CryptAcquireContextA
CryptGenKey
CryptContextAddRef
RegEnumValueW
ImpersonateSelf
CredWriteW
CredDeleteW
CredEnumerateW
CredFree
CryptDecrypt
CryptDuplicateKey
CryptEncrypt
RegOpenCurrentUser
ConvertSidToStringSidW
DuplicateToken
ImpersonateLoggedOnUser
SetTokenInformation
RevertToSelf
CryptGenRandom
CryptReleaseContext
CryptAcquireContextW
crypt32.dll

CryptAcquireCertificatePrivateKey
CertEnumCertificatesInStore
CertCompareCertificate
CryptUnprotectData
CryptExportPublicKeyInfo
CryptEncodeObjectEx
CryptSignAndEncodeCertificate
CertGetCertificateChain
CertFreeCertificateChain
CryptSignMessage
CertGetNameStringA
CryptVerifyMessageSignature
CertVerifyCertificateChainPolicy
CryptImportPublicKeyInfo
CertSetCertificateContextProperty
CryptProtectData
CertGetIssuerCertificateFromStore
CertFreeCertificateContext
CertGetNameStringW
CertVerifySubjectCertificateContext
CertCreateCertificateContext
CertCloseStore
CertDeleteCertificateFromStore
CertFindCertificateInStore
CertOpenStore
CertAddCertificateContextToStore
CertGetCertificateContextProperty
CertDuplicateCertificateContext
iphlpapi.dll

NotifyAddrChange
CancelIPChangeNotify
kernel32.dll
netapi32.dll

NetUserModalsGet
NetApiBufferFree
ole32.dll

CLSIDFromProgID
CreateStreamOnHGlobal
CoTaskMemAlloc
CoTaskMemRealloc
CoUninitialize
CoInitializeEx
CoRevokeClassObject
CoRegisterClassObject
CoInitializeSecurity
CoTaskMemFree
CoSuspendClassObjects
StringFromGUID2
CoCreateInstance
CoResumeClassObjects
CoSetProxyBlanket
CoRevertToSelf
CoImpersonateClient
PropVariantClear
psapi.dll

rpcrt4.dll

RpcServerRegisterIf
RpcServerListen
UuidToStringA
RpcStringFreeA
UuidToStringW
RpcStringFreeW
RpcServerUseProtseqEpW
RpcImpersonateClient
RpcRevertToSelf
I_RpcBindingInqLocalClientPID
RpcMgmtStopServerListening
NdrServerCall2
RpcServerUnregisterIf
UuidCreate
sensapi.dll

shell32.dll

SHCreateDirectoryExW
SHGetFolderPathW
SHGetSpecialFolderPathW
shlwapi.dll

PathFileExistsW
SHCopyKeyW
SHStrDupW
PathIsDirectoryW
PathCombineW
SHDeleteKeyW
sqmapi.dll

SqmSetAppId
SqmAddToStreamString
SqmIncrement
SqmSet
SqmGetSession
SqmReadSharedMachineId
SqmCreateNewId
SqmWriteSharedMachineId
SqmSetMachineId
SqmEndSession
SqmSetAppVersion
SqmStartUpload
SqmStartSession
SqmAddToStreamDWord
user32.dll

MessageBoxW
GetMessageW
DispatchMessageW
TranslateMessage
CharUpperW
PostThreadMessageW
CharNextW
LoadStringW
userenv.dll

CreateEnvironmentBlock
DestroyEnvironmentBlock
UnloadUserProfile
version.dll

GetFileVersionInfoSizeW
GetFileVersionInfoW
VerQueryValueW
wer.dll

WerReportSubmit
WerReportCreate
WerReportCloseHandle
WerReportSetParameter
WerReportAddFile
winhttp.dll

WinHttpAddRequestHeaders
WinHttpQueryAuthSchemes
WinHttpSetStatusCallback
WinHttpCrackUrl
WinHttpCloseHandle
WinHttpSetOption
WinHttpOpen
WinHttpReadData
WinHttpQueryDataAvailable
WinHttpCreateUrl
WinHttpConnect
WinHttpQueryHeaders
WinHttpReceiveResponse
WinHttpOpenRequest
WinHttpSendRequest
WinHttpGetIEProxyConfigForCurrentUser
WinHttpGetProxyForUrl
WinHttpSetTimeouts
winscard.dll

SCardFreeMemory
SCardListReadersW
SCardEstablishContext
SCardReleaseContext
wintrust.dll

WTHelperGetProvSignerFromChain
WTHelperProvDataFromStateData
WinVerifyTrustEx
ws2_32.dll

WSACreateEvent
WSACloseEvent
wtsapi32.dll

WTSFreeMemory
WTSEnumerateSessionsW
WTSQueryUserToken