File details
File name: services.exe
Name: Sistema operacional Microsoft® Windows®
Description: Aplicativo de serviços e controle
Version: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Product version: 5.1.2600.2180
Size: 106 KB
Original file name: services.exe
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0003522850%
Privileged CPU:
0.0001944178%

User CPU:
0.00015786723696%

Privileged CPU time: 2250 ms
Privileged CPU time /min: 0 ms
 | Memory utilization averages |
Committed memory:
35.06 MB
Peak committed memory: 36.04 MB
Paged memory:
2.5 MB
Peak paged memory: 2.5 MB
Paged system memory:
35.43 KB
Non-paged system memory: 6.5 KB
Working set memory:
1.43 MB
Peak working set memory: 3.75 MB
Min working set memory: 496 KB
Private memory:
2.5 MB
Page faults:
1,735
Page faults /min: 0
 | Process I/O averages |
Total read operations:
1,272
Total read transfer: 74.25 KB
Total write operations:
1,220
Total write transfer: 61.27 KB
Total other operations:
4,234
Total other transfer: 31.06 KB
 | GUI Object Averages |
GDI objects:
4
Resources
Handle count average: 272
Thread count average: 15
Process details
Runs as (owner): User
Integrety level: Undefined
Windows platform: 32-bit
Runs as a service: Yes
Parent Process
Child Processes
Process Command
C:\WINDOWS\system32\services.exe
Service details
Name: Log de eventos
Service name: Eventlog
Service type:
Win32ShareProcess
Description: “Registra mensagens de eventos emitidas por Windows-based programs and components to be viewed in Event Viewer. This service cannot be stopped.”
Image hashes
MD5: cc73c4430c2fc27fde16a0a4e3678148
SHA-1: 99bfc701c125ad44a2949e43e1e253be9d3627fc
SHA-256: 2a65b9b800fbc7995a0fc623588860ad464fc29b15e814b4ad97066011e267d4
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File packed: No
Import Table
advapi32.dll

AllocateLocallyUniqueId
RegOpenKeyW
ConvertSidToStringSidW
AllocateAndInitializeSid
FreeSid
LogonUserExW
LsaStorePrivateData
LsaLookupNames
AddAccessAllowedAce
SetTokenInformation
StartServiceCtrlDispatcherW
RegisterServiceCtrlHandlerW
SetServiceStatus
SystemFunction029
SystemFunction005
CheckTokenMembership
LsaQueryInformationPolicy
OpenThreadToken
RegNotifyChangeKeyValue
InitializeSecurityDescriptor
SetSecurityDescriptorOwner
GetSecurityDescriptorDacl
GetLengthSid
CopySid
InitializeAcl
AddAce
SetSecurityDescriptorDacl
LsaOpenPolicy
LsaLookupSids
LsaFreeMemory
LsaClose
GetTokenInformation
RegCloseKey
RegQueryValueExW
RegOpenKeyExW
InitiateSystemShutdownW
RevertToSelf
CreateProcessAsUserW
ImpersonateLoggedOnUser
kernel32.dll

GetCurrentThread
CreateMutexW
ReleaseMutex
ExitThread
FormatMessageW
lstrcmpiW
SetProcessShutdownParameters
DelayLoadFailureHook
RaiseException
GetExitCodeThread
SetConsoleCtrlHandler
SetErrorMode
SetUnhandledExceptionFilter
LoadLibraryA
QueryPerformanceCounter
GetCurrentThreadId
GetCurrentProcess
UnhandledExceptionFilter
GetModuleHandleA
OpenEventW
LocalAlloc
LocalFree
Sleep
LeaveCriticalSection
EnterCriticalSection
SetLastError
CloseHandle
CreateThread
GetLastError
CreateProcessW
ExpandEnvironmentStringsW
InitializeCriticalSection
HeapAlloc
HeapFree
TerminateProcess
WaitForSingleObject
HeapCreate
FreeLibrary
GetProcAddress
GetModuleHandleExW
InterlockedCompareExchange
CreateNamedPipeW
ReadFile
CancelIo
GetOverlappedResult
WaitForMultipleObjects
ConnectNamedPipe
TransactNamedPipe
WriteFile
GetTickCount
GetSystemTimeAsFileTime
GetModuleHandleW
GetComputerNameW
CreateEventW
SetEvent
ResetEvent
DeviceIoControl
CreateFileW
ResumeThread
GetCurrentProcessId
LoadLibraryW
GetDriveTypeW
msvcrt.dll
ncobjapi.dll

WmiCreateObjectWithFormat
WmiEventSourceConnect
WmiSetAndCommitObject
ntdll.dll

RtlCreateSecurityDescriptor
RtlAddAccessAllowedAce
RtlCreateAcl
NtCreateKey
NtQueryValueKey
NtSetValueKey
NtDeleteValueKey
NtEnumerateKey
NtQuerySecurityObject
RtlFreeHeap
NtOpenKey
NtDeleteKey
RtlSetControlSecurityDescriptor
RtlValidSecurityDescriptor
RtlLengthSecurityDescriptor
NtPrivilegeObjectAuditAlarm
NtPrivilegeCheck
NtOpenThreadToken
NtAccessCheckAndAuditAlarm
NtSetInformationThread
NtAdjustPrivilegesToken
NtDuplicateToken
NtOpenProcessToken
RtlSetDaclSecurityDescriptor
RtlQuerySecurityObject
RtlSetSecurityObject
RtlValidRelativeSecurityDescriptor
RtlMapGenericMask
RtlCopyUnicodeString
NtSetInformationFile
NtQueryInformationFile
RtlAppendUnicodeStringToString
RtlAppendUnicodeToString
NtWaitForSingleObject
NtQueryDirectoryFile
NtDeleteFile
NtSetInformationProcess
RtlUnhandledExceptionFilter
NtSetEvent
RtlGetAce
RtlQueryInformationAcl
RtlGetDaclSecurityDescriptor
RtlAllocateHeap
RtlConvertSharedToExclusive
RtlConvertExclusiveToShared
RtlRegisterWait
RtlGetNtProductType
RtlEqualUnicodeString
RtlLengthSid
RtlCopySid
NtOpenDirectoryObject
NtQueryDirectoryObject
RtlUnicodeStringToAnsiString
RtlInitAnsiString
RtlAnsiStringToUnicodeString
RtlNewSecurityObject
RtlAddAce
RtlSetOwnerSecurityDescriptor
RtlSetGroupSecurityDescriptor
RtlSetSaclSecurityDescriptor
RtlSubAuthorityCountSid
RtlCompareUnicodeString
NtLoadDriver
NtUnloadDriver
RtlExpandEnvironmentStrings_U
RtlAdjustPrivilege
NtFlushKey
NtOpenFile
RtlDosPathNameToNtPathName_U
NtOpenSymbolicLinkObject
NtQuerySymbolicLinkObject
RtlFreeUnicodeString
RtlAreAllAccessesGranted
NtDeleteObjectAuditAlarm
NtCloseObjectAuditAlarm
RtlQueueWorkItem
RtlCopyLuid
RtlDeregisterWait
RtlReleaseResource
RtlAcquireResourceExclusive
RtlAcquireResourceShared
RtlInitializeResource
RtlDeleteSecurityObject
RtlLockBootStatusData
RtlGetSetBootStatusData
RtlUnlockBootStatusData
NtInitializeRegistry
NtQueryKey
NtClose
RtlInitUnicodeString
NtSetSystemEnvironmentValue
RtlNtStatusToDosError
NtShutdownSystem
NtQueryInformationToken
RtlMakeSelfRelativeSD
RtlInitializeSid
RtlLengthRequiredSid
RtlSubAuthoritySid
NtSetSecurityObject
rpcrt4.dll

RpcServerRegisterAuthInfoW
RpcBindingFree
RpcEpResolveBinding
RpcBindingFromStringBindingW
RpcStringBindingComposeW
NdrClientCall2
RpcAsyncCompleteCall
RpcAsyncInitializeHandle
NdrAsyncServerCall
RpcServerListen
RpcMgmtStopServerListening
RpcMgmtWaitServerListen
RpcServerUnregisterIf
NdrAsyncClientCall
NdrServerCall2
I_RpcBindingIsClientLocal
RpcRevertToSelf
I_RpcMapWin32Status
RpcImpersonateClient
RpcStringBindingParseW
RpcStringFreeW
RpcBindingToStringBindingW
RpcServerRegisterIfEx
RpcServerUseProtseqEpW
RpcServerRegisterIf
scesrv.dll

ScesrvInitializeServer
ScesrvTerminateServer
umpnpmgr.dll

RegisterScmCallback
PNP_SetActiveService
PNP_GetDeviceRegProp
PNP_GetDeviceListSize
PNP_GetDeviceList
PNP_HwProfFlags
RegisterServiceNotification
DeleteServicePlugPlayRegKeys
user32.dll

LoadStringW
wsprintfW
BroadcastSystemMessageW
MessageBoxW
RegisterServicesProcess
userenv.dll

UnloadUserProfile
CreateEnvironmentBlock
LoadUserProfileW
DestroyEnvironmentBlock