File details
File name: uuactokensvc.exe
Name: UACTokenSvc
Description: UACTokenSvc
Version: 1, 0, 0, 1
Size: 81.55 KB
Original file name: UACTokenSvc.exe
Digital certificate
Certificate authority:
VeriSign
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0000191174%
Privileged CPU:
0.0000155866%

User CPU:
0.00000353078540%

Privileged CPU time: 26.03 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
349,890,130
 | Memory utilization averages |
Committed memory:
28.43 MB
Peak committed memory: 33.54 MB
Paged memory:
813.33 KB
Peak paged memory: 885.33 KB
Paged system memory:
48.73 KB
Non-paged system memory: 3.84 KB
Working set memory:
553.33 KB
Peak working set memory: 2.73 MB
Min working set memory: 136 KB
Private memory:
813.33 KB
Page faults:
1,137
Page faults /min: 1
 | Process I/O averages |
Total read operations:
2
Read operations /min: 1
Total read transfer: 7.8 KB
Read transfer /min: 0 Bytes
Total write operations:
2
Write operations /min: 1
Total write transfer: 12 Bytes
Write transfer /min: 0 Bytes
Total other operations:
127
Other operations /min: 1
Total other transfer: 1.28 KB
Other Transfer /min: 0 Bytes
 | GUI Object Averages |
GDI objects:
4
USER objects:
1
Resources
Handle count average: 41
Thread count average: 2
Thread resource averages
Total CPU: 0.000031171968%
Privileged CPU: 0.000031171968%
User CPU: 0.000000000000%
CPU Cycle count /sec: 642
Module memory size: 84 KB
Process details
Runs as (owner): System
Integrety level: Undefined
Windows platform: 32-bit
Runs as a service: Yes
Parent Processes
Process Commands
"C:\Documents and Settings\user\Application Data\HP SimpleSave Application\uUACTokenSvc.exe"
"C:\Documents and Settings\user\Application Data\HP SimpleSave Application\uUACTokenSvc.exe"
"C:\users\user\appdata\Roaming\HP SimpleSave Application\uUACTokenSvc.exe"
Service details
Name: BackupService
Service type:
Win32OwnProcess
Image hashes
MD5: 68b86dd9d455a6a8de6d13c84fb5ce31
SHA-1: 037b02f8008a52e99714cde4538c643f8f840baa
SHA-256: ed02bcee2874f2e1b32cb0f6e44712bedf80abc3e8f233d258d485cce2714c17
PE image details
File packed: No
Import Table
advapi32.dll

RegisterServiceCtrlHandlerW
OpenProcessToken
LookupPrivilegeValueW
DuplicateTokenEx
SetTokenInformation
AdjustTokenPrivileges
CreateProcessAsUserW
DeleteService
ControlService
OpenServiceW
StartServiceW
OpenSCManagerW
CreateServiceW
StartServiceCtrlDispatcherW
SetServiceStatus
CloseServiceHandle
kernel32.dll

GetPrivateProfileStringW
WTSGetActiveConsoleSessionId
CreateToolhelp32Snapshot
Process32FirstW
ProcessIdToSessionId
Process32NextW
OpenProcess
GetLastError
OutputDebugStringW
CloseHandle
GetModuleFileNameW
GetStringTypeW
GetStringTypeA
SetStdHandle
ReadFile
IsBadCodePtr
IsBadReadPtr
MultiByteToWideChar
GetVersion
ExitProcess
RtlUnwind
RaiseException
HeapFree
TerminateProcess
GetCurrentProcess
HeapReAlloc
HeapAlloc
HeapSize
UnhandledExceptionFilter
FreeEnvironmentStringsA
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetEnvironmentStrings
GetCommandLineW
GetCommandLineA
SetHandleCount
GetStdHandle
GetFileType
GetStartupInfoA
GetModuleHandleA
GetModuleFileNameA
GetEnvironmentVariableA
GetVersionExA
HeapDestroy
HeapCreate
VirtualFree
WriteFile
SetFilePointer
FlushFileBuffers
WideCharToMultiByte
SetUnhandledExceptionFilter
VirtualAlloc
IsBadWritePtr
LCMapStringA
LCMapStringW
GetProcAddress
LoadLibraryA
shell32.dll

userenv.dll

wtsapi32.dll
