File details
File name: alg.exe
Name: Application Layer Gateway Service
Description: Microsoft® Windows® Operating System
Version: 5.1.2600.5512 (xpsp.080413-0852)
Product version: 5.1.2600.5512
Size: 43.5 KB
Original file name: ALG.exe
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0013363171%
Privileged CPU:
0.0011746659%

User CPU:
0.00016165126770%

Privileged CPU time: 109375 ms
Privileged CPU time /min: 213 ms
 | Memory utilization averages |
Committed memory:
32.21 MB
Peak committed memory: 33.06 MB
Paged memory:
1.1 MB
Peak paged memory: 1.13 MB
Paged system memory:
35.35 KB
Non-paged system memory: 4.54 KB
Working set memory:
2.52 MB
Peak working set memory: 3.51 MB
Min working set memory: 2.52 MB
Private memory:
1.1 MB
Page faults:
934
Page faults /min: 2
 | Process I/O averages |
Total read operations:
6
Read operations /min: 1
Total read transfer: 38.45 KB
Read transfer /min: 77 Bytes
Total write operations:
4
Write operations /min: 1
Total write transfer: 156 Bytes
Write transfer /min: 0 Bytes
Total other operations:
878
Other operations /min: 2
Total other transfer: 120.57 KB
Other Transfer /min: 241 Bytes
 | GUI Object Averages |
GDI objects:
4
Resources
Handle count average: 102
Thread count average: 5
Process details
Runs as (owner): System
Integrety level: Undefined
Windows platform: 32-bit
Runs as a service: Yes
Parent Process
Process Command
C:\WINDOWS\System32\alg.exe
Service details
Name: Usługa bramy warstwy aplikacji
Service name: ALG
Service type:
Win32OwnProcess
Description: “Zapewnia obsługę dodatków protokołów innych firm dla Udostępniania połączenia internetowego i Zapory systemu Windows.”
Network connectivity
TCP: localhost on port 1030
Image hashes
MD5: d1738dddff196c5cee6d867c136af745
SHA-1: 5fd9c6e105aac1664ea72b852fc021f34cbc2e3c
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File entropy: 6.22290
File packed: No
Import Table
advapi32.dll

RegOpenKeyExW
RegEnumKeyExW
RegQueryValueExW
StartServiceCtrlDispatcherW
RegNotifyChangeKeyValue
RegisterServiceCtrlHandlerW
SetServiceStatus
RegCloseKey
SystemFunction036
kernel32.dll

GetStartupInfoW
GetModuleHandleA
CreateThread
UnhandledExceptionFilter
TerminateProcess
GetSystemTimeAsFileTime
CreateTimerQueueTimer
ReadFile
GetCurrentProcessId
WriteFile
BindIoCompletionCallback
UnregisterWait
RegisterWaitForSingleObject
HeapAlloc
DeleteTimerQueueTimer
GetProcessHeap
HeapFree
DuplicateHandle
GetCurrentProcess
QueryPerformanceCounter
GetTickCount
SetUnhandledExceptionFilter
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSection
GetLastError
CreateTimerQueue
DeleteCriticalSection
InterlockedIncrement
InterlockedDecrement
DeleteTimerQueueEx
CloseHandle
Sleep
WaitForMultipleObjects
CreateEventW
WaitForSingleObject
SetEvent
GetCurrentThreadId
msvcrt.dll
ole32.dll

CoCreateInstance
CoTaskMemFree
CoTaskMemAlloc
CoUninitialize
CoInitializeEx
CLSIDFromString
ws2_32.dll

WSAEnumNetworkEvents
WSAConnect
WSAEventSelect
WSASocketW