File details
File name: smss.exe
Name: Windows NT-sessionsstyring
Description: Microsoft® Windows® Operativsystem
Version: 5.1.2600.5512 (xpsp.080413-2111)
Product version: 5.1.2600.5512
Size: 49.5 KB
Original file name: smss.exe
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0002528726%
Privileged CPU:
0.0000933425%

User CPU:
0.00015953009785%

Privileged CPU time: 1578.12 ms
Privileged CPU time /min: 0 ms
 | Memory utilization averages |
Committed memory:
3.73 MB
Peak committed memory: 14.33 MB
Paged memory:
178 KB
Peak paged memory: 1.64 MB
Paged system memory:
6.04 KB
Non-paged system memory: 640 Bytes
Working set memory:
238 KB
Peak working set memory: 622 KB
Min working set memory: 236 KB
Private memory:
178 KB
Page faults:
290
Page faults /min: 0
 | Process I/O averages |
Total read operations:
10
Total read transfer: 4.04 KB
Total write operations:
6
Total write transfer: 3.44 KB
Total other operations:
365
Total other transfer: 3.48 KB
Resources
Handle count average: 19
Thread count average: 3
Process details
Runs as (owner): System
Integrety level: Undefined
Windows platform: 32-bit
Child Processes
Process Command
\SystemRoot\System32\smss.exe
Image hashes
MD5: 3d0f7d67af801c313be733b2f05bfa0e
SHA-1: 1425e49cc8c14135bdd4113784c9e3a2aea710d0
SHA-256: bed849c7a344217a94d94de705924d70e9c307d184609d9bb2ebc3ab6561a98c
PE image details
Subsystem: Native (none required)
File packed: No
Import Table
ntdll.dll

NtTerminateProcess
NtRaiseHardError
RtlInitUnicodeString
RtlAdjustPrivilege
RtlFreeHeap
RtlUpcaseUnicodeChar
RtlUnicodeStringToInteger
RtlAllocateHeap
RtlFreeUnicodeString
DbgPrintEx
RtlExtendedIntegerMultiply
NtQueryVolumeInformationFile
NtOpenFile
NtClose
wcslen
wcscpy
NtQueryInformationProcess
NtCreatePagingFile
NtSetInformationFile
NtQueryInformationFile
DbgPrint
NtQuerySystemInformation
_allmul
NtSetSecurityObject
RtlSetOwnerSecurityDescriptor
RtlSetDaclSecurityDescriptor
RtlAddAccessAllowedAce
RtlCreateAcl
RtlCreateSecurityDescriptor
RtlAllocateAndInitializeSid
RtlDosPathNameToNtPathName_U
RtlExpandEnvironmentStrings_U
NtQueryValueKey
swprintf
NtOpenKey
NtSetValueKey
NtCreateKey
NtCreateFile
NtReadFile
_chkstk
wcsstr
_wcsupr
NtMakeTemporaryObject
NtCreateSymbolicLinkObject
NtOpenDirectoryObject
wcsncpy
RtlAnsiStringToUnicodeString
RtlInitAnsiString
_stricmp
NtCreateSection
LdrVerifyImageMatchesChecksum
NtCreateDirectoryObject
RtlSetEnvironmentVariable
LdrUnloadDll
LdrGetProcedureAddress
RtlInitString
LdrLoadDll
RtlCompareUnicodeString
RtlEqualString
memmove
_wcsicmp
RtlCreateUnicodeString
RtlDosSearchPath_U
RtlQueryEnvironmentVariable_U
RtlEqualUnicodeString
RtlAppendUnicodeToString
RtlAppendUnicodeStringToString
NtWaitForSingleObject
NtResumeThread
RtlDestroyProcessParameters
RtlCreateUserProcess
RtlCreateProcessParameters
RtlUnlockBootStatusData
RtlGetSetBootStatusData
RtlLockBootStatusData
NtDisplayString
sprintf
NtDuplicateObject
RtlLengthSid
RtlGetAce
RtlPrefixUnicodeString
NtQuerySymbolicLinkObject
NtOpenSymbolicLinkObject
NtQueryDirectoryObject
NtRequestWaitReplyPort
RtlFindMessage
NtSetEvent
NtSetSystemInformation
NtCreateEvent
RtlLeaveCriticalSection
RtlEnterCriticalSection
wcscat
LdrQueryImageFileExecutionOptions
NtDelayExecution
NtInitializeRegistry
RtlQueryRegistryValues
NtDeleteValueKey
RtlCreateEnvironment
RtlCreateUserThread
NtCreatePort
RtlInitializeCriticalSection
NtSetInformationProcess
RtlCreateTagHeap
NtSetInformationThread
NtQueryInformationToken
NtOpenThreadToken
NtImpersonateClientOfPort
NtConnectPort
NtCompleteConnectPort
NtAcceptConnectPort
NtOpenProcess
NtReplyWaitReceivePort
RtlExitUserThread
NtReplyPort
RtlSetThreadIsCritical
NtWaitForMultipleObjects
RtlSetProcessIsCritical
RtlUnicodeStringToAnsiString
NtAdjustPrivilegesToken
NtOpenProcessToken
RtlUnhandledExceptionFilter
RtlUnwind
NtQueryVirtualMemory
DbgBreakPoint
RtlNormalizeProcessParams