File details
File name: svchost.exe
Name: ระบบปฏิบัติการ Microsoft® Windows®
Description: Host Process for Windows Services
Version: 6.2.9200.16384 (win8_rtm.120725-1247)
Product version: 6.2.9200.16384
Size: 29 KB
Original file name: svchost.exe.mui
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0010679525%
Privileged CPU:
0.0005636195%

User CPU:
0.00050433301624%

Privileged CPU time: 869270.53 ms
Privileged CPU time /min: 39 ms
CPU cycle count:
248,271,087
CPU cycle count /min: 137,935,302
Context switches /sec:
27
 | Memory utilization averages |
Committed memory:
259.92 MB
Peak committed memory: 408.49 MB
Paged memory:
23.87 MB
Peak paged memory: 93.76 MB
Paged system memory:
152.27 KB
Non-paged system memory: 39 KB
Working set memory:
24.35 MB
Peak working set memory: 100.01 MB
Min working set memory: 14.88 MB
Private memory:
23.87 MB
Page faults:
595,840
Page faults /min: 618
 | Process I/O averages |
Total read operations:
32,608
Read operations /min: 22
Total read transfer: 84.91 MB
Read transfer /min: 86.74 KB
Total write operations:
10,162
Write operations /min: 8
Total write transfer: 42.7 MB
Write transfer /min: 34.52 KB
Total other operations:
528,108
Other operations /min: 576
Total other transfer: 35.62 MB
Other Transfer /min: 26.32 KB
Resources
Handle count average: 609
Thread count average: 18
Thread resource averages
Total CPU: 15.695421979507%
Privileged CPU: 7.835652640104%
User CPU: 7.859769339403%
CPU Cycle count /sec: 441,580,360
Context switches /sec: 588
Module memory size: 3.21 MB
wuaueng.dll

Total CPU: 1.934084063480%
Privileged CPU: 0.757339495955%
User CPU: 1.176744567524%
CPU Cycle count /sec: 37,295,891
Context switches /sec: 12
Module memory size: 3.2 MB
Total CPU: 1.591794609119%
Privileged CPU: 0.662956769688%
User CPU: 0.928837839431%
CPU Cycle count /sec: 39,373,067
Context switches /sec: 92
Module memory size: 3.15 MB
Total CPU: 1.590869480587%
Privileged CPU: 0.367638517440%
User CPU: 1.223230963147%
CPU Cycle count /sec: 18,705,978
Context switches /sec: 6
Module memory size: 1.28 MB
wuaueng.dll

Total CPU: 1.103682460994%
Privileged CPU: 0.415679241692%
User CPU: 0.688003219302%
CPU Cycle count /sec: 24,608,892
Context switches /sec: 3
Module memory size: 3.21 MB
Total CPU: 1.042569593082%
Privileged CPU: 0.479756403744%
User CPU: 0.562813189339%
CPU Cycle count /sec: 26,584,626
Context switches /sec: 16
Module memory size: 344 KB
Total CPU: 0.751690615114%
Privileged CPU: 0.268395575289%
User CPU: 0.483295039825%
CPU Cycle count /sec: 11,952,362
Context switches /sec: 189
Module memory size: 3.21 MB
cryptnet.dll

Total CPU: 0.664678862038%
Privileged CPU: 0.574782733519%
User CPU: 0.089896128519%
CPU Cycle count /sec: 6,460,752
Module memory size: 152 KB
Total CPU: 0.453875685317%
Privileged CPU: 0.138288676730%
User CPU: 0.315587008587%
CPU Cycle count /sec: 9,640,293
Context switches /sec: 7
Module memory size: 3.11 MB
Total CPU: 0.420018317987%
Privileged CPU: 0.184824418982%
User CPU: 0.235193899006%
CPU Cycle count /sec: 9,396,026
Context switches /sec: 11
Module memory size: 3.11 MB
Total CPU: 0.291275574806%
Privileged CPU: 0.266600290938%
User CPU: 0.024675283867%
CPU Cycle count /sec: 7,028,862
Context switches /sec: 73
Module memory size: 1.29 MB
wbemcore.dll

Total CPU: 0.137133898305%
Privileged CPU: 0.021560422036%
User CPU: 0.115573476269%
CPU Cycle count /sec: 3,751,209
Context switches /sec: 6
Module memory size: 1.3 MB
shcore.dll

Total CPU: 0.093283480501%
Privileged CPU: 0.051344628395%
User CPU: 0.041938852106%
CPU Cycle count /sec: 1,110,012
Module memory size: 600 KB
sechost.dll

Total CPU: 0.072216499447%
Privileged CPU: 0.020483086349%
User CPU: 0.051733413098%
CPU Cycle count /sec: 1,633,468
Context switches /sec: 2
Module memory size: 288 KB
Total CPU: 0.066335050187%
Privileged CPU: 0.052844591368%
User CPU: 0.013490458818%
CPU Cycle count /sec: 1,112,496
Context switches /sec: 2
Module memory size: 340 KB
Total CPU: 0.065690123031%
Privileged CPU: 0.065690123031%
User CPU: 0.000000000000%
CPU Cycle count /sec: 824,088
Module memory size: 80 KB
ntdll.dll

Total CPU: 0.063332495654%
Privileged CPU: 0.037845502014%
User CPU: 0.025486993640%
CPU Cycle count /sec: 1,362,422
Context switches /sec: 5
Module memory size: 1.74 MB
Total CPU: 0.046064467639%
Privileged CPU: 0.009618308738%
User CPU: 0.036446158901%
CPU Cycle count /sec: 732,762
Context switches /sec: 13
Module memory size: 792 KB
Total CPU: 0.040443860327%
Privileged CPU: 0.018148547898%
User CPU: 0.022295312428%
CPU Cycle count /sec: 2,317,568
Module memory size: 224 KB
ntdll.dll

Total CPU: 0.030472020943%
Privileged CPU: 0.018250031186%
User CPU: 0.012221989757%
CPU Cycle count /sec: 751,407
Context switches /sec: 3
Module memory size: 1.75 MB
Process details
Runs as (owner): User
Integrety level: Undefined
Windows platform: 64-bit
Runs as a service: Yes
Parent Process
Child Processes
Process Commands
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k WbioSvcGroup
C:\Windows\system32\svchost.exe -k RPCSS
Hosted services
AeLookupSvc
AllUserInstallAgent
AppHostSvc
AppIDSvc
Appinfo
AppMgmt
AudioEndpointBuilder
Audiosrv
AxInstSV
BDESVC
BFE
BITS
BrokerInfrastructure
Browser
BsFileScan
BsMailProxy
BsMain
BthHFSrv
bthserv
CertPropSvc
CryptSvc
CscService
DcomLaunch
defragsvc
DeviceAssociationService
DeviceInstall
Dhcp
Dnscache
dot3svc
DPS
DsmSvc
Eaphost
EventLog
EventSystem
fdPHost
FDResPub
fhsvc
FontCache
ftpsvc
FunshionSvr
gpsvc
hidserv
hkmsvc
HomeGroupListener
HomeGroupProvider
hpqcxs08
hpqddsvc
HPSLPSVC
HsfXAudioService
IKEEXT
iphlpsvc
iprip
Irmon
KPSSVC
KtmRm
LanmanServer
LanmanWorkstation
lltdsvc
lmhosts
LPDSVC
LSM
Mcx2Svc
MMCSS
MpsSvc
MSiSCSI
napagent
NcaSvc
NcdAutoSetup
Net Driver HPZ12
Netman
netprofm
NlaSvc
nsi
p2pimsvc
p2psvc
PcaSvc
PeerDistSvc
pla
PlugPlay
Pml Driver HPZ12
PNRPAutoReg
PNRPsvc
PolicyAgent
Power
PPTVService
PrintNotify
ProfSvc
QWAVE
RaMgmtSvc
RapiMgr
RasAuto
RasMan
RemoteAccess
RemoteRegistry
RpcEptMapper
RPCHTTPLBS
RpcSs
sacsvr
SCardSvr
Schedule
SCPolicySvc
SDRSVC
seclogon
SENS
SensrSvc
SessionEnv
SharedAccess
ShellHWDetection
sina_live_deamon
SSDPSRV
SstpSvc
stisvc
StorSvc
svsvc
swprv
SysMain
SystemEventsBroker
TabletInputService
TapiSrv
TermService
Themes
Network connectivity
TCP: vh013.pbt.microsoft.com on port 50006
UDP: LISTENING on port 57639
TCP: 192.168.0.1 on port 53356
UDP: LISTENING on port 62502
TCP: localhost on port 135
UDP: LISTENING on port 5355
UDP: LISTENING on port 61439
UDP: LISTENING on port 68
TCP: localhost on port 49153
UDP: LISTENING on port 62179
UDP: LISTENING on port 4500
TCP: 2.16.216.200 on port 50019
Image hashes
MD5: ede27eace742ee2888c5dd36400a2ec0
SHA-1: 27dacbb2d894d42f2bb5e4385e7c4ef103993ec3
SHA-256: 4ae0c5191fe9d93e1be2b99c0c64bf3ca43272cd66003139476192f946f0bec4
PE image details
CLR assembly: Yes
CLR NGENed: No
Langauge*: Microsoft Visual C# / Basic .NET
File packed: No