File details
File name: taskeng.exe
Name: Task Scheduler Engine
Description: Microsoft® Windows® Operating System
Version: 6.3.9600.16384 (winblue_rtm.130821-1623)
Product version: 6.3.9600.16384
Size: 458.5 KB
Original file name: taskeng.exe.mui
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0042909985%
Privileged CPU:
0.0033554016%

User CPU:
0.00093559691900%

Privileged CPU time: 8750 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
451,624,808
CPU cycle count /min: 4,085,592
 | Memory utilization averages |
Committed memory:
45.87 MB
Peak committed memory: 51.44 MB
Paged memory:
1.55 MB
Peak paged memory: 1.84 MB
Paged system memory:
89.25 KB
Non-paged system memory: 12.47 KB
Working set memory:
3.33 MB
Peak working set memory: 5.39 MB
Min working set memory: 3.33 MB
Private memory:
1.55 MB
Page faults:
3,260
Page faults /min: 27
 | Process I/O averages |
Total read operations:
121
Read operations /min: 6
Total read transfer: 250.02 KB
Read transfer /min: 10.73 KB
Total write operations:
1
Write operations /min: 1
Total write transfer: 1.04 KB
Write transfer /min: 35 Bytes
Total other operations:
1,730
Other operations /min: 13
Total other transfer: 33.29 KB
Other Transfer /min: 66 Bytes
 | GUI Object Averages |
GDI objects:
9
Peak GDI objects: 10
USER objects:
3
Peak USER objects: 3
Resources
Handle count average: 120
Thread count average: 3
Thread resource averages
Total CPU: 0.000162016372%
Privileged CPU: 0.000096902972%
User CPU: 0.000065113400%
CPU Cycle count /sec: 3,969
Module memory size: 476 KB
Process details
Runs as (owner): System
Integrety level: High
Windows platform: 64-bit
Parent Process
Child Processes
Process Commands
taskeng.exe {5A930668-1BBB-4F03-AF02-44E6B0C6B313}
taskeng.exe {C45204BB-4228-48F6-AABE-778D55223B7F}
taskeng.exe {FAB62FC2-D315-4DE3-9CA9-21F2493FA820}
taskeng.exe {355D210D-F420-4783-A03F-A2BA069BD7A3}
taskeng.exe {3B35F9CE-97C0-4E9B-B970-5FC58D3048CD}
Image hashes
MD5: 183360914efc9d25e2a13d335d5e9eb8
SHA-1: 3f125b0c65f748d78d29cc84b6b67cc74555dabf
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File entropy: 5.55590
File packed: No
Import Table
advapi32.dll

TraceMessage
GetTraceEnableFlags
GetTraceEnableLevel
GetTraceLoggerHandle
RegisterTraceGuidsW
UnregisterTraceGuids
AddAce
InitializeAcl
GetSecurityDescriptorControl
MakeAbsoluteSD
GetSecurityDescriptorSacl
GetSecurityDescriptorDacl
GetSecurityDescriptorGroup
GetSecurityDescriptorOwner
InitializeSecurityDescriptor
GetLengthSid
IsValidSid
CopySid
GetAclInformation
SetSecurityDescriptorOwner
SetSecurityDescriptorGroup
SetSecurityDescriptorDacl
GetSidSubAuthority
InitializeSid
GetSidLengthRequired
RegCloseKey
RegSetValueExW
RegOpenKeyExW
CheckTokenMembership
OpenThreadToken
RegEnumKeyExW
RegDeleteKeyW
RegNotifyChangeKeyValue
RegCreateKeyExW
RegGetValueW
RegQueryValueExW
RegQueryValueW
EventRegister
EventActivityIdControl
EventEnabled
EventWriteTransfer
EventWrite
EventUnregister
CreateWellKnownSid
CloseServiceHandle
QueryServiceStatus
StartServiceW
OpenServiceW
OpenSCManagerW
CryptCreateHash
CryptHashData
CryptGetHashParam
CryptDestroyHash
CryptAcquireContextW
CryptReleaseContext
api-ms-win-core-com-l1-1-0.dll

StringFromGUID2
IIDFromString
StringFromCLSID
CLSIDFromString
CoCreateInstance
CoInitializeSecurity
CoRevertToSelf
CoDisableCallCancellation
CoInitializeEx
CoEnableCallCancellation
CoUninitialize
CoCancelCall
CoImpersonateClient
CoDisconnectObject
CoTaskMemFree
CoMarshalInterface
CreateStreamOnHGlobal
api-ms-win-core-debug-l1-1-0.dll

api-ms-win-core-debug-l1-1-1.dll

OutputDebugStringA
DebugBreak
IsDebuggerPresent
api-ms-win-core-delayload-l1-1-1.dll

DelayLoadFailureHook
ResolveDelayLoadedAPI
api-ms-win-core-errorhandling-l1-1-0.dll

SetLastError
GetLastError
SetUnhandledExceptionFilter
UnhandledExceptionFilter
api-ms-win-core-errorhandling-l1-1-1.dll

GetLastError
UnhandledExceptionFilter
SetUnhandledExceptionFilter
SetLastError
api-ms-win-core-file-l1-1-0.dll

GetFileAttributesW
CreateDirectoryW
CreateFileW
ReadFile
GetFileSizeEx
FileTimeToLocalFileTime
api-ms-win-core-file-l1-1-1.dll

ReadFile
CreateFileW
CreateDirectoryW
GetFileSizeEx
GetFileAttributesW
api-ms-win-core-file-l1-2-0.dll

GetFileSizeEx
ReadFile
GetFileAttributesW
CreateFileW
CreateDirectoryW
api-ms-win-core-handle-l1-1-0.dll

api-ms-win-core-heap-l1-1-0.dll

HeapReAlloc
HeapSetInformation
GetProcessHeap
HeapCreate
HeapDestroy
HeapAlloc
HeapFree
HeapSize
api-ms-win-core-heap-l1-2-0.dll

HeapFree
HeapSize
HeapReAlloc
HeapCreate
GetProcessHeap
HeapSetInformation
HeapAlloc
HeapDestroy
api-ms-win-core-interlocked-l1-1-0.dll

InterlockedDecrement
InterlockedIncrement
InterlockedCompareExchange
InterlockedExchange
api-ms-win-core-interlocked-l1-1-1.dll

InterlockedCompareExchange
InterlockedDecrement
InterlockedIncrement
InterlockedExchange
api-ms-win-core-interlocked-l1-2-0.dll

InterlockedDecrement
InterlockedIncrement
InterlockedExchange
InterlockedCompareExchange
api-ms-win-core-libraryloader-l1-1-0.dll

GetModuleHandleW
GetProcAddress
FreeLibrary
LoadLibraryExA
GetModuleHandleA
LoadLibraryExW
api-ms-win-core-libraryloader-l1-1-1.dll

GetModuleHandleA
LoadLibraryExW
FreeLibrary
GetModuleHandleW
LoadStringW
GetModuleHandleExW
GetProcAddress
api-ms-win-core-misc-l1-1-0.dll

api-ms-win-core-processenvironment-l1-1-0.dll

SearchPathW
ExpandEnvironmentStringsW
GetCurrentDirectoryW
api-ms-win-core-processenvironment-l1-1-1.dll

SearchPathW
GetCurrentDirectoryW
ExpandEnvironmentStringsW
api-ms-win-core-processenvironment-l1-2-0.dll

ExpandEnvironmentStringsW
SearchPathW
GetCurrentDirectoryW
api-ms-win-core-processthreads-l1-1-0.dll

SetProcessShutdownParameters
SetThreadPriority
GetCurrentThread
GetStartupInfoW
GetCurrentThreadId
GetCurrentProcessId
TerminateProcess
GetCurrentProcess
CreateThread
GetThreadPriority
GetExitCodeProcess
CreateProcessW
OpenThreadToken
ResumeThread
api-ms-win-core-processthreads-l1-1-1.dll

CreateThread
SetThreadPriority
TerminateProcess
GetCurrentProcess
GetCurrentProcessId
GetStartupInfoW
GetCurrentThread
OpenThreadToken
SetProcessShutdownParameters
GetThreadPriority
ResumeThread
GetCurrentThreadId
CreateProcessW
GetExitCodeProcess
IsProcessorFeaturePresent
api-ms-win-core-profile-l1-1-0.dll

api-ms-win-core-registry-l1-1-0.dll

RegSetValueExW
RegCloseKey
RegOpenKeyExW
RegNotifyChangeKeyValue
RegCreateKeyExW
RegQueryValueExW
RegGetValueW
api-ms-win-core-shlwapi-legacy-l1-1-0.dll

PathIsPrefixW
PathFileExistsW
api-ms-win-core-string-l1-1-0.dll

api-ms-win-core-synch-l1-1-0.dll

DeleteCriticalSection
LeaveCriticalSection
CreateEventW
EnterCriticalSection
SetEvent
ResetEvent
SetWaitableTimer
CancelWaitableTimer
WaitForSingleObject
InitializeCriticalSection
api-ms-win-core-synch-l1-1-1.dll

InitializeCriticalSection
EnterCriticalSection
CreateWaitableTimerExW
SetWaitableTimer
SetEvent
LeaveCriticalSection
InitializeCriticalSectionAndSpinCount
CancelWaitableTimer
CreateEventW
WaitForMultipleObjectsEx
WaitForSingleObject
DeleteCriticalSection
Sleep
api-ms-win-core-synch-l1-2-0.dll

WaitForMultipleObjectsEx
CancelWaitableTimer
WaitForSingleObject
Sleep
LeaveCriticalSection
InitializeCriticalSectionAndSpinCount
DeleteCriticalSection
SetWaitableTimer
EnterCriticalSection
InitializeCriticalSection
CreateEventW
SetEvent
CreateWaitableTimerExW
api-ms-win-core-sysinfo-l1-1-0.dll

GetTickCount
GetSystemTimeAsFileTime
SystemTimeToFileTime
api-ms-win-core-sysinfo-l1-1-1.dll

GetSystemTimeAsFileTime
SystemTimeToFileTime
GetTickCount
api-ms-win-core-sysinfo-l1-2-0.dll

GetTickCount
GetSystemTimeAsFileTime
api-ms-win-core-threadpool-l1-1-0.dll

CreateTimerQueueTimer
DeleteTimerQueueTimer
api-ms-win-core-threadpool-l1-1-1.dll

UnregisterWaitEx
RegisterWaitForSingleObjectEx
DeleteTimerQueueTimer
CreateTimerQueueTimer
api-ms-win-core-threadpool-legacy-l1-1-0.dll

DeleteTimerQueueTimer
UnregisterWaitEx
CreateTimerQueueTimer
api-ms-win-core-threadpool-private-l1-1-0.dll

RegisterWaitForSingleObjectEx
api-ms-win-core-timezone-l1-1-0.dll

api-ms-win-core-wow64-l1-1-0.dll

api-ms-win-legacy-advapi32-l1-1-0.dll

api-ms-win-legacy-shlwapi-l1-1-0.dll

PathIsPrefixW
PathFileExistsW
api-ms-win-obsolete-kernelbase-l1-1-0.dll

api-ms-win-security-base-l1-1-0.dll

GetSecurityDescriptorGroup
GetSecurityDescriptorOwner
InitializeSecurityDescriptor
IsValidSid
GetAclInformation
SetSecurityDescriptorOwner
SetSecurityDescriptorGroup
SetSecurityDescriptorDacl
GetSidSubAuthority
InitializeSid
GetSidLengthRequired
GetSecurityDescriptorDacl
GetLengthSid
CopySid
CheckTokenMembership
MakeAbsoluteSD
GetSecurityDescriptorControl
InitializeAcl
AddAce
CreateWellKnownSid
GetSecurityDescriptorSacl
api-ms-win-security-base-l1-2-0.dll

IsValidSid
GetLengthSid
GetSecurityDescriptorSacl
GetSidSubAuthority
CreateWellKnownSid
SetSecurityDescriptorGroup
CopySid
SetSecurityDescriptorOwner
CheckTokenMembership
GetAclInformation
GetSecurityDescriptorControl
InitializeAcl
GetSecurityDescriptorGroup
MakeAbsoluteSD
SetSecurityDescriptorDacl
AddAce
InitializeSecurityDescriptor
InitializeSid
GetSidLengthRequired
GetSecurityDescriptorOwner
GetSecurityDescriptorDacl
api-ms-win-security-lsalookup-l2-1-0.dll

bcrypt.dll

BCryptCreateHash
BCryptDestroyHash
BCryptHashData
BCryptFinishHash
BCryptOpenAlgorithmProvider
BCryptGetProperty
BCryptCloseAlgorithmProvider
kernel32.dll

IsWow64Process
LocalAlloc
GetThreadPreferredUILanguages
SetThreadPreferredUILanguages
UnregisterWait
RegisterWaitForSingleObject
DelayLoadFailureHook
CreateWaitableTimerW
WaitForMultipleObjects
DeleteAtom
GetCurrentDirectoryW
DebugBreak
InitializeCriticalSectionAndSpinCount
HeapSetInformation
ExpandEnvironmentStringsW
LoadLibraryExW
FileTimeToLocalFileTime
FreeLibrary
SystemTimeToFileTime
UnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
GetSystemTimeAsFileTime
GetCurrentProcessId
GetCurrentThreadId
GetTickCount
QueryPerformanceCounter
CreateTimerQueueTimer
DeleteTimerQueueTimer
GetModuleHandleA
SetUnhandledExceptionFilter
OutputDebugStringA
GetStartupInfoW
InterlockedCompareExchange
LocalFree
InitializeCriticalSection
GetCurrentThread
SetThreadPriority
GetModuleHandleW
WaitForSingleObject
ResetEvent
CancelWaitableTimer
SetWaitableTimer
SetEvent
EnterCriticalSection
SetProcessShutdownParameters
CreateEventW
GetLastError
Sleep
UnregisterWaitEx
CloseHandle
LeaveCriticalSection
DeleteCriticalSection
InterlockedDecrement
InterlockedIncrement
InterlockedExchange
HeapFree
HeapAlloc
HeapDestroy
HeapCreate
GetProcessHeap
CreateDirectoryW
GetFileSizeEx
ReadFile
CreateFileW
OutputDebugStringW
DuplicateHandle
CreateProcessW
GetFileAttributesW
SearchPathW
GetThreadPriority
GetExitCodeProcess
TerminateThread
lstrlenW
HeapSize
HeapReAlloc
CreateThread
ResumeThread
mpr.dll

msvcrt.dll
ntdll.dll

NtSetInformationProcess
EtwEventRegister
EtwEventActivityIdControl
EtwEventEnabled
EtwEventWriteTransfer
EtwEventWrite
EtwEventUnregister
EtwUnregisterTraceGuids
EtwRegisterTraceGuidsW
EtwGetTraceLoggerHandle
EtwGetTraceEnableLevel
EtwGetTraceEnableFlags
EtwTraceMessage
RtlNtStatusToDosError
DbgPrintEx
ole32.dll

CoEnableCallCancellation
CoCancelCall
CoUninitialize
CoInitializeEx
CoDisconnectObject
CoRevertToSelf
CoImpersonateClient
CoMarshalInterface
CreateStreamOnHGlobal
CLSIDFromString
CoTaskMemFree
StringFromCLSID
IIDFromString
StringFromGUID2
CoCreateInstance
CoDisableCallCancellation
CoInitializeSecurity
rpcrt4.dll

RpcBindingFree
RpcBindingFromStringBindingW
RpcStringBindingComposeW
RpcAsyncInitializeHandle
I_RpcExceptionFilter
RpcAsyncCompleteCall
RpcAsyncCancelCall
NdrAsyncClientCall
RpcStringFreeW
RpcBindingSetAuthInfoExW
UuidCreateNil
secur32.dll

LsaDeregisterLogonProcess
GetUserNameExW
shell32.dll

shlwapi.dll

PathFileExistsW
PathIsPrefixW
PathIsDirectoryW
user32.dll

CreateWindowExW
RegisterClassW
UnregisterClassW
ShowWindow
UpdateWindow
DispatchMessageW
LoadStringW
ShutdownBlockReasonCreate
PostQuitMessage
DefWindowProcW
GetMonitorInfoW
AllowSetForegroundWindow
GetAncestor
MsgWaitForMultipleObjects
PeekMessageW
PostMessageW
EnumThreadWindows
MessageBoxW
GetWindowThreadProcessId
TranslateMessage
EnumWindows
GetUserObjectInformationW
GetThreadDesktop
GetProcessWindowStation
SetCursor
LoadCursorW
DestroyWindow
EnableWindow
IsWindow
xmllite.dll

CreateXmlReader
CreateXmlWriter
CreateXmlWriterOutputWithEncodingName