File details
File name: xoftspyservice.exe
Name: XoftspySE
Description: XoftSpy Service
Version: 1.1.0.1
Product version: 6.0.0.39
Size: 568.77 KB
Original file name: XoftSpyService.exe
Digital certificate
Certificate authority:
VeriSign
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0073388022%
Privileged CPU:
0.0041116109%

User CPU:
0.00322719120285%

Privileged CPU time: 437.5 ms
Privileged CPU time /min: 0 ms
 | Memory utilization averages |
Committed memory:
71.15 MB
Peak committed memory: 75.21 MB
Paged memory:
16.8 MB
Peak paged memory: 24.78 MB
Paged system memory:
68.17 KB
Non-paged system memory: 4.84 KB
Working set memory:
19.81 MB
Peak working set memory: 27.39 MB
Min working set memory: 4.64 MB
Private memory:
16.8 MB
Page faults:
8,677
Page faults /min: 0
 | Process I/O averages |
Total read operations:
11,400
Total read transfer: 11.17 MB
Total write operations:
7
Total write transfer: 372 Bytes
Total other operations:
1,341
Total other transfer: 111 KB
 | GUI Object Averages |
GDI objects:
4
Resources
Handle count average: 143
Thread count average: 3
Thread resource averages
Total CPU: 0.000145936614%
Privileged CPU: 0.000145936614%
User CPU: 0.000000000000%
Module memory size: 580 KB
Process details
Runs as (owner): System
Integrety level: Undefined
Windows platform: 32-bit
Runs as a service: Yes
Parent Process
Process Command
"C:\Program Files\Common Files\XoftSpySE\6\xoftspyservice.exe"
Service details
Name: XoftSpyService
Service type:
Win32OwnProcess
Description: “Provides scanning, cleaning, and quarantining of malware items.”
Image hashes
MD5: 547df50f6ab868184b7c1936ae1f527e
SHA-1: 4c88e2edb7fc2030f2c9bc7d5ec309d3952032dc
SHA-256: ce9b47e707cddb367fc4d5ca102233edddd97388f89e088a402cd8e77e10624e
PE image details
Subsystem: Windows GUI
File packed: No
Import Table
advapi32.dll

DeregisterEventSource
ReportEventW
RegisterEventSourceW
DeleteService
CreateServiceW
RegisterServiceCtrlHandlerW
StartServiceCtrlDispatcherW
RegisterServiceCtrlHandlerExW
RegQueryValueExW
CloseServiceHandle
QueryServiceStatus
ControlService
OpenServiceW
OpenSCManagerW
RegDeleteValueW
RegCreateKeyExW
RegSetValueExW
RegOpenKeyExW
RegEnumKeyExW
RegQueryInfoKeyW
RegCloseKey
RegDeleteKeyW
SetServiceStatus
kernel32.dll

GetCommandLineW
GetCurrentThreadId
SetEvent
CloseHandle
WaitForSingleObject
CreateEventW
CreateThread
GetVersionExW
CreateFileA
FlushFileBuffers
WriteConsoleW
GetConsoleOutputCP
WriteConsoleA
SetStdHandle
Sleep
LoadLibraryW
FindResourceExW
LockResource
InterlockedDecrement
InterlockedIncrement
GetModuleFileNameW
LoadLibraryExW
FindResourceW
LoadResource
SizeofResource
MultiByteToWideChar
GetLastError
EnterCriticalSection
RaiseException
LeaveCriticalSection
lstrcmpiW
GetModuleHandleW
GetProcAddress
lstrlenW
FreeLibrary
DeleteCriticalSection
InitializeCriticalSection
GetStringTypeW
GetStringTypeA
LCMapStringW
LCMapStringA
GetConsoleMode
GetConsoleCP
WideCharToMultiByte
GetLocaleInfoA
LoadLibraryA
GetACP
GetCPInfo
GetSystemTimeAsFileTime
GetCurrentProcessId
GetTickCount
QueryPerformanceCounter
GetStartupInfoA
GetFileType
SetHandleCount
GetEnvironmentStringsW
InitializeCriticalSectionAndSpinCount
IsValidCodePage
CreateFileW
GetFileSize
SetFilePointer
WriteFile
HeapDestroy
HeapAlloc
HeapFree
HeapReAlloc
HeapSize
GetProcessHeap
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
VirtualProtect
VirtualAlloc
GetSystemInfo
VirtualQuery
GetStartupInfoW
RtlUnwind
VirtualFree
HeapCreate
ExitProcess
GetStdHandle
GetModuleFileNameA
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
SetLastError
FreeEnvironmentStringsW
GetOEMCP
ole32.dll

CoTaskMemRealloc
CoCreateInstance
CoSuspendClassObjects
CoGetClassObject
CoInitializeSecurity
CoUninitialize
CoResumeClassObjects
CoInitializeEx
CoRegisterClassObject
CoRevokeClassObject
StringFromGUID2
CoTaskMemFree
CoTaskMemAlloc
shell32.dll

shlwapi.dll

PathRemoveFileSpecW
PathIsDirectoryW
user32.dll

UnregisterDeviceNotification
RegisterDeviceNotificationW
LoadStringW
PostThreadMessageW
CharUpperW
MessageBoxW
GetMessageW
TranslateMessage
DispatchMessageW
CharNextW