File details
File name: nfsclnt.exe
Name: Client for NFS service
Description: Microsoft® Windows® Operating System
Version: 6.1.7600.16385 (win7_rtm.090713-1255)
Product version: 6.1.7600.16385
Size: 64 KB
Original file name: nfsclnt.exe.mui
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0000195857%
Privileged CPU:
0.0000053518%

User CPU:
0.00001423387793%

Privileged CPU time: 19.52 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
68,611,471
CPU cycle count /min: 35,142
 | Memory utilization averages |
Committed memory:
30.29 MB
Peak committed memory: 32.14 MB
Paged memory:
2.27 MB
Peak paged memory: 2.33 MB
Paged system memory:
51.4 KB
Non-paged system memory: 12.67 KB
Working set memory:
2.71 MB
Peak working set memory: 5.33 MB
Min working set memory: 2.64 MB
Private memory:
2.27 MB
Page faults:
1,563
Page faults /min: 1
Resources
Handle count average: 111
Thread count average: 7
Thread resource averages
Total CPU: 0.000035088726%
Privileged CPU: 0.000023392484%
User CPU: 0.000011696242%
CPU Cycle count /sec: 308
Module memory size: 124 KB
Total CPU: 0.000035088706%
Privileged CPU: 0.000011696235%
User CPU: 0.000023392471%
CPU Cycle count /sec: 617
Module memory size: 88 KB
Process details
Runs as (owner): Network Service
Integrety level: System
Windows platform: 64-bit
Runs as a service: Yes
Parent Process
Process Command
C:\Windows\system32\nfsclnt.exe
Service details
Name: Client für NFS
Service name: NfsClnt
Service type:
Win32OwnProcess
Description: “Ermöglicht diesem Computer, auf Dateien auf NFS-Freigaben zuzugreifen.”
Image hashes
MD5: 311654ef177acd01a2b16c34ba3f0960
SHA-1: 74b5b1e0088b762c747992592c5de2ea470975ae
SHA-256: 99cead3fb22a893e22c4120e443b8d65e3f036fbb61bcf58194bab51d770c582
PE image details
CLR assembly: Yes
CLR NGENed: No
Langauge*: Microsoft Visual C# / Basic .NET
File packed: No
Import Table
advapi32.dll

RegCloseKey
RegQueryValueExA
RegOpenKeyExW
RegQueryValueExW
RegEnumValueA
RegEnumKeyExW
ReportEventW
LsaNtStatusToWinError
SetServiceStatus
RegisterServiceCtrlHandlerW
DeregisterEventSource
StartServiceCtrlDispatcherW
RegisterEventSourceW
RegNotifyChangeKeyValue
RegGetValueW
GetSecurityDescriptorLength
MakeSelfRelativeSD
AllocateAndInitializeSid
FreeSid
InitializeSecurityDescriptor
AddAccessAllowedAceEx
AddAccessAllowedAce
InitializeAcl
GetLengthSid
AdjustTokenPrivileges
OpenProcessToken
SetSecurityDescriptorDacl
kernel32.dll

GetTickCount64
QueryDosDeviceW
GetCurrentProcessId
SleepEx
GlobalAlloc
LeaveCriticalSection
InterlockedExchange
InitializeSRWLock
GetComputerNameA
GetComputerNameW
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
GetProcessHeap
HeapAlloc
HeapFree
CreateMutexW
InitializeCriticalSection
GetSystemTimes
InterlockedIncrement
UnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
GetCurrentThreadId
GetTickCount
QueryPerformanceCounter
GetModuleHandleA
SetUnhandledExceptionFilter
InterlockedCompareExchange
SetLastError
Sleep
CreateThread
ResetEvent
CreateFileW
DeviceIoControl
LocalAlloc
FormatMessageW
LocalFree
DeleteCriticalSection
CloseHandle
WaitForMultipleObjects
WaitForSingleObject
ReleaseMutex
GetLastError
CreateEventW
GetSystemTimeAsFileTime
SetEvent
GlobalFree
EnterCriticalSection
msvcrt.dll
netapi32.dll

DsGetDcNameW
NetApiBufferFree
ntdll.dll

RtlInitUnicodeString
RtlNtStatusToDosError
NtClose
NtFsControlFile
NtOpenFile
NtDeviceIoControlFile
RtlCopyLuid
NtQueryInformationToken
NtOpenThreadToken
RtlRandomEx
RtlAppendStringToString
RtlIpv6AddressToStringA
RtlIpv4AddressToStringA
RtlInitAnsiString
RtlFreeHeap
RtlAllocateHeap
RtlCharToInteger
rpcrt4.dll

RpcServerUseProtseqEpW
RpcServerListen
NdrServerCall2
RpcMgmtStopServerListening
RpcServerRegisterIf
RpcImpersonateClient
RpcRevertToSelf
RpcMgmtWaitServerListen
ws2_32.dll
