File details
File name: slui.exe
Name: Windows Activation Client
Description: Microsoft® Windows® Operating System
Version: 6.1.7600.16385 (win7_rtm.090713-1255)
Product version: 6.1.7600.16385
Size: 341.5 KB
Original file name: slui.exe.mui
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0001322542%
Privileged CPU:
0.0000946406%

User CPU:
0.00003761356616%

Privileged CPU time: 78 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
560,700,125
CPU cycle count /min: 113,236,271
Context switches /sec:
259
 | Memory utilization averages |
Committed memory:
116.14 MB
Peak committed memory: 126.16 MB
Paged memory:
3.96 MB
Peak paged memory: 4.09 MB
Paged system memory:
224.91 KB
Non-paged system memory: 13.25 KB
Working set memory:
2.05 MB
Peak working set memory: 8.77 MB
Min working set memory: 236 KB
Private memory:
3.96 MB
Page faults:
23,011
Page faults /min: 68
 | Process I/O averages |
Total read operations:
481
Read operations /min: 1
Total read transfer: 9.37 KB
Read transfer /min: 29 Bytes
Total other operations:
1,330
Other operations /min: 4
Total other transfer: 15.42 KB
Other Transfer /min: 47 Bytes
 | GUI Object Averages |
GDI objects:
51
Peak GDI objects: 56
USER objects:
36
Peak USER objects: 39
Resources
Handle count average: 171
Thread count average: 8
Thread resource averages
ntdll.dll

Total CPU: 0.001150892925%
Privileged CPU: 0.001150892925%
User CPU: 0.000000000000%
CPU Cycle count /sec: 4,942
Module memory size: 1.66 MB
Total CPU: 0.000382534587%
Privileged CPU: 0.000210184339%
User CPU: 0.000172350248%
CPU Cycle count /sec: 3,955,338
Context switches /sec: 126
Module memory size: 356 KB
Process details
Runs as (owner): User
Integrety level: High
Windows platform: 64-bit
Parent Process
Process Command
C:\WINDOWS\System32\slui.exe -Embedding
Image hashes
MD5: c5ce5ce799387e82b7698a0ee5544a6d
SHA-1: ed37fdb169bb539271c117d3e8a5f14fd8df1c0d
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File packed: No
Import Table
advapi32.dll

TraceMessage
RegCloseKey
RegOpenKeyExW
RegQueryValueExW
DeregisterEventSource
GetTraceEnableFlags
GetTraceEnableLevel
GetTraceLoggerHandle
RegisterTraceGuidsW
RegDeleteKeyW
ReportEventW
RegisterEventSourceW
RegCreateKeyExW
RegEnumKeyW
RegQueryInfoKeyW
RegSetValueExW
RegSetKeySecurity
ConvertStringSecurityDescriptorToSecurityDescriptorW
RegDeleteValueW
FreeSid
LsaClose
LsaFreeMemory
CheckTokenMembership
AllocateAndInitializeSid
LsaQueryInformationPolicy
LsaOpenPolicy
kernel32.dll

HeapAlloc
GetProcessHeap
HeapFree
GetLastError
VirtualQuery
LockResource
LoadResource
FindResourceExW
LeaveCriticalSection
EnterCriticalSection
EncodePointer
DecodePointer
CloseHandle
UnregisterWaitEx
HeapSetInformation
InterlockedIncrement
WaitForSingleObject
LocalFree
InitializeCriticalSectionAndSpinCount
GetModuleFileNameW
SetEvent
InterlockedDecrement
CreateEventW
RegisterApplicationRestart
RegisterWaitForSingleObject
InterlockedCompareExchange
FreeLibrary
GetProcAddress
GetModuleHandleExW
SetLastError
GetSystemTime
SystemTimeToFileTime
LoadLibraryW
FreeLibraryAndExitThread
SetThreadPriority
GetCurrentThread
CreateThread
GetModuleHandleW
GetCommandLineW
DeleteCriticalSection
CheckElevationEnabled
FormatMessageW
ExpandEnvironmentStringsW
LoadLibraryExW
GetVersionExW
LocalAlloc
GetSystemDirectoryW
GetUserDefaultLCID
Sleep
GetStartupInfoA
SetUnhandledExceptionFilter
GetModuleHandleA
QueryPerformanceCounter
GetTickCount
GetCurrentThreadId
GetCurrentProcessId
GetSystemTimeAsFileTime
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
InterlockedExchange
msvcrt.dll
ntdll.dll

ole32.dll

StringFromGUID2
CoAllowSetForegroundWindow
CoRegisterClassObject
CoResumeClassObjects
CoMarshalInterThreadInterfaceInStream
CoReleaseServerProcess
CoSuspendClassObjects
CoUninitialize
CoInitializeEx
CoAddRefServerProcess
CoCreateInstance
CoRevokeClassObject
CoGetInterfaceAndReleaseStream
CoInitializeSecurity
rpcrt4.dll

I_RpcMapWin32Status
UuidFromStringW
RpcStringFreeW
UuidToStringW
shell32.dll

Shell_NotifyIconW
CommandLineToArgvW
ShellExecuteExW
slc.dll

SLRegisterWindowsEvent
SLClose
SLOpen
SLUnregisterWindowsEvent
sppcommdlg.dll

user32.dll

SetCursor
SendMessageW
SetSysColors
SystemParametersInfoW
GetSysColor
MessageBoxW
GetDesktopWindow
CallWindowProcW
SetForegroundWindow
GetMessageW
TranslateMessage
DispatchMessageW
LoadIconW
CopyIcon
LoadCursorW
CreateWindowExW
DefWindowProcW
GetCursorPos
KillTimer
PostQuitMessage
SetTimer
GetWindowLongW
DestroyIcon
DestroyWindow
SetWindowLongW
PostMessageW
AllowSetForegroundWindow
RegisterClassW
winbrand.dll
