File details
File name: aspnet_state.exe
Name: Microsoft® .NET Framework
Description: Microsoft ASP.NET State Server
Version: 2.0.50727.4016 (NetFxQFE.050727-4000)
Product version: 2.0.50727.4016
Size: 30.32 KB
Original file name: aspnet_state.exe
Digital certificate
Certificate authority:
Microsoft Corporation
Expiration date: 1/10/2013
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0000371650%
Privileged CPU:
0.0000072399%

User CPU:
0.00002992502855%

Privileged CPU time: 156001 ms
Privileged CPU time /min: 3 ms
CPU cycle count:
281,428,443
CPU cycle count /min: 6,214
 | Memory utilization averages |
Committed memory:
43.78 MB
Peak committed memory: 46.94 MB
Paged memory:
1.54 MB
Peak paged memory: 2.57 MB
Paged system memory:
77.13 KB
Non-paged system memory: 40.16 KB
Working set memory:
4.81 MB
Peak working set memory: 4.86 MB
Min working set memory: 4.81 MB
Private memory:
1.54 MB
Page faults:
1,771
Page faults /min: 1
 | Process I/O averages |
Total read operations:
5
Read operations /min: 1
Total read transfer: 19.22 KB
Read transfer /min: 0 Bytes
Total write operations:
2
Write operations /min: 1
Total write transfer: 28 Bytes
Write transfer /min: 0 Bytes
Total other operations:
1,035
Other operations /min: 1
Total other transfer: 5.67 KB
Other Transfer /min: 0 Bytes
Resources
Handle count average: 79
Thread count average: 4
Process details
Runs as (owner): User
Integrety level: System
Windows platform: 32-bit
Runs as a service: Yes
Parent Process
Process Command
C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
Service details
Name: ASP.NET-Zustandsdienst
Service name: aspnet_state
Service type:
Win32OwnProcess
Description: “Stellt die Unterstützung für nicht aktive Sitzungszustände von ASP.NET bereit. Wenn der Dienst angehalten wird, werden nicht aktive Anforderungen nicht verarbeitet. Wenn der Dienst deaktiviert ist, können die explizit abhängigen Dienste nicht gestartet werden.”
Network connectivity
TCP: localhost on port 42424
Image hashes
MD5: 40c145f12ff461a0220303bda134f598
SHA-1: 162d3902e21fe602b5e1c2b4f2b6a387a7af5115
SHA-256: 27623be626417151f62200127b8c68f35fb78d21e4d14b69e2b20f81c5d84c61
PE image details
CLR assembly: Yes
CLR NGENed: No
Langauge*: Microsoft Visual C# / Basic .NET
File packed: No
Import Table
advapi32.dll

RegQueryValueExW
RegisterServiceCtrlHandlerW
StartServiceCtrlDispatcherW
RegCloseKey
RegOpenKeyExW
SetServiceStatus
kernel32.dll

SetWaitableTimer
CloseHandle
CreateThread
CreateWaitableTimerW
CreateEventW
SetConsoleCtrlHandler
FormatMessageW
InterlockedIncrement
InterlockedDecrement
GetSystemTimeAsFileTime
lstrlenW
WideCharToMultiByte
FileTimeToSystemTime
FileTimeToLocalFileTime
QueryPerformanceCounter
GetTickCount
GetCurrentThreadId
GetCurrentProcessId
TerminateProcess
Sleep
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetSystemInfo
WaitForSingleObject
SetEvent
GetProcessAffinityMask
SwitchToThread
MultiByteToWideChar
GetLastError
GetVersionExW
GetSystemDirectoryW
LoadLibraryW
HeapReAlloc
InterlockedCompareExchange
InterlockedExchange
HeapFree
HeapAlloc
HeapDestroy
GetProcAddress
HeapCreate
FreeLibrary
GetCurrentProcess
mscoree.dll
msvcr80.dll
mswsock.dll

AcceptEx
GetAcceptExSockaddrs
ole32.dll

CoUninitialize
CoInitializeEx
webengine.dll

InitializeLibrary
PrintResourceString
XspLogEvent
AttachHandleToThreadPool
PerfCounterInitialize
AspnetLoadResourceDLL
LoadLibraryUsingFullPath
GetXSPHeap
ws2_32.dll

WSASend
WSAGetOverlappedResult
WSAAddressToStringA
WSARecv
WSASocketW
Export Table