File details
File name: svchost.exe
Name: Host Process for Windows Services
Description: Microsoft® Windows® Operating System
Version: 6.1.7600.16385 (win7_rtm.090713-1255)
Product version: 6.1.7600.16385
Size: 26.5 KB
Original file name: svchost.exe.mui
Windows file protection:
Yes
Digital certificate
Certificate authority:
Microsoft Corporation
Expiration date: 6/13/2014
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0000679292%
Privileged CPU:
0.0000405613%

User CPU:
0.00002736794478%

Privileged CPU time: 473591.74 ms
Privileged CPU time /min: 126 ms
CPU cycle count:
273,571,011
CPU cycle count /min: 1,553,311
 | Memory utilization averages |
Committed memory:
106.85 MB
Peak committed memory: 164.45 MB
Paged memory:
12.93 MB
Peak paged memory: 29.72 MB
Paged system memory:
99.31 KB
Non-paged system memory: 22.47 KB
Working set memory:
11.38 MB
Peak working set memory: 28.35 MB
Min working set memory: 540 KB
Private memory:
12.93 MB
Page faults:
1,074,694
Page faults /min: 286
 | Process I/O averages |
Total read operations:
150,556
Read operations /min: 40
Total read transfer: 381.06 MB
Read transfer /min: 104.04 KB
Total write operations:
13,129
Write operations /min: 4
Total write transfer: 27.79 MB
Write transfer /min: 7.59 KB
Total other operations:
5,167,216
Other operations /min: 1,378
Total other transfer: 138.03 MB
Other Transfer /min: 37.69 KB
Resources
Handle count average: 342
Thread count average: 12
Thread resource averages
ntdll.dll

Total CPU: 0.195703938024%
Privileged CPU: 0.160201046866%
User CPU: 0.035502891158%
CPU Cycle count /sec: 7,290,500
Context switches /sec: 15
Module memory size: 1.66 MB
Total CPU: 0.006012182991%
Privileged CPU: 0.005469730390%
User CPU: 0.000542452601%
CPU Cycle count /sec: 196,357
Module memory size: 688 KB
Total CPU: 0.003518478541%
Privileged CPU: 0.000708216237%
User CPU: 0.002810262304%
CPU Cycle count /sec: 138,645
Module memory size: 824 KB
Total CPU: 0.000165747555%
Privileged CPU: 0.000165747555%
User CPU: 0.000000000000%
CPU Cycle count /sec: 6,901
Module memory size: 412 KB
Total CPU: 0.000122434709%
Privileged CPU: 0.000075344348%
User CPU: 0.000047090361%
CPU Cycle count /sec: 5,263
Module memory size: 124 KB
wevtsvc.dll

Total CPU: 0.000115472694%
Privileged CPU: 0.000094138015%
User CPU: 0.000021334678%
CPU Cycle count /sec: 5,356
Module memory size: 1.59 MB
Total CPU: 0.000060274838%
Privileged CPU: 0.000045206128%
User CPU: 0.000015068709%
CPU Cycle count /sec: 1,890
Module memory size: 116 KB
mmdevapi.dll

Total CPU: 0.000037667631%
Privileged CPU: 0.000022600579%
User CPU: 0.000015067052%
CPU Cycle count /sec: 1,512
Module memory size: 300 KB
schedsvc.dll

Total CPU: 0.000030137693%
Privileged CPU: 0.000030137693%
User CPU: 0.000000000000%
CPU Cycle count /sec: 1,070
Module memory size: 1.07 MB
Total CPU: 0.000022602821%
Privileged CPU: 0.000007534274%
User CPU: 0.000015068547%
CPU Cycle count /sec: 731
Module memory size: 100 KB
Total CPU: 0.000018834454%
Privileged CPU: 0.000018834454%
User CPU: 0.000000000000%
CPU Cycle count /sec: 623
Module memory size: 44 KB
Process details
Runs as (owner): Local Service
Integrety level: System
Windows platform: 64-bit
Runs as a service: Yes
Parent Process
Child Processes
Process Commands
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k DcomLaunch
Hosted services
AcfXAudioService
ActiveX Installer (AxInstSV) (AxInstSV)

AeLookupSvc
Akamai
AllUserInstallAgent
AppHostSvc
AppIDSvc

Appinfo

Application Experience (AeLookupSvc)

Application Management (AppMgmt)

AppMgmt
AppReadiness
AppXSvc
ASBroker
ASChannel
AudioEndpointBuilder
AudioSrv
AxInstSV
Background Intelligent Transfer Service (BITS)

Base Filtering Engine (BFE)

BDESVC

BFE
BITS
Bluetooth Support Service (bthserv)

BranchCache (PeerDistSvc)

BrokerInfrastructure
Browser

BsBackup
BsCache
BsFileScan
BsFire
BsMailProxy
BsMain
BthHFSrv
bthserv
Certificate Propagation (CertPropSvc)

CertPropSvc
Cryptographic Services (CryptSvc)

CryptSvc
CscService
DCOM Server Process Launcher (DcomLaunch)

DcomLaunch
defragsvc
Desktop Window Manager Session Manager (UxSms)

DeviceAssociationService
DeviceInstall
Dhcp
DHCP Client (Dhcp)

Diagnostic Policy Service (DPS)

Diagnostic Service Host (WdiServiceHost)

Diagnostic System Host (WdiSystemHost)

Distributed Link Tracking Client (TrkWks)

DNS Client (Dnscache)

Dnscache
dot3svc
DPS
drvsvc
DsmSvc
EapHost
ehstart
EMDMgmt
Eventlog
EventSystem

Extensible Authentication Protocol (EapHost)

ezGOSvc
ezSharedSvc
fdPHost

FDResPub
fhsvc
FontCache
ftpsvc
Function Discovery Resource Publication (FDResPub)

FunshionSvr
getPlusHelper
gpsvc

Health Key and Certificate Management (hkmsvc)

HFGService
hidserv
hkmsvc
HomeGroup Listener (HomeGroupListener)

HomeGroup Provider (HomeGroupProvider)

HomeGroupListener
HomeGroupProvider
HPHNDUSVC
hpqcxs08
hpqddsvc
HPSLPSVC
HsfXAudioService
Human Interface Device Access (hidserv)

IKE and AuthIP IPsec Keying Modules (IKEEXT)

IKEEXT
Internet Connection Sharing (ICS) (SharedAccess)

IP Helper (iphlpsvc)

IPBusEnum
iphlpsvc
iprip
IPsec Policy Agent (PolicyAgent)

Irmon
Journal d’événements Windows (eventlog)

KtmRm
KtmRm for Distributed Transaction Coordinator (KtmRm)

LanmanServer
LanmanWorkstation
lfsvc
Link-Layer Topology Discovery Mapper (lltdsvc)

lltdsvc
lmhosts
LPDSVC
LSM
Mcx2Svc
Media Center Extender Service (Mcx2Svc)

METrsptSvr
MHN
Microsoft iSCSI Initiator Service (MSiSCSI)

Microsoft Software Shadow Copy Provider (swprv)

MMCSS
MpsSvc
MSiSCSI
MsKeyboardFilter
Multimedia Class Scheduler (MMCSS)

napagent
Network connectivity
TCP: localhost on port 1026
TCP: localhost on port 135
TCP: localhost on port 1027
Windows Firewall allowed program: Yes
Image hashes
MD5: dfde777faf31dc25e3624e8071073146
SHA-1: 73a63279a2e065babb9460777678897877d29945
PE image details
Langauge*: Microsoft Visual C++
File entropy: 5.87847
File packed: No
Import Table
advapi32.dll

GetTokenInformation
InitializeSecurityDescriptor
SetSecurityDescriptorOwner
SetSecurityDescriptorGroup
SetEntriesInAclW
SetSecurityDescriptorDacl
StartServiceCtrlDispatcherW
RegDisablePredefinedCacheEx
EventRegister
EventEnabled
EventWrite
RegQueryValueExW
RegOpenKeyExW
RegCloseKey
RegisterServiceCtrlHandlerW
SetServiceStatus
OpenProcessToken
api-ms-win-core-crt-l1-1-0.dll

memcmp
memcpy
_except_handler4_common
api-ms-win-core-crt-l2-1-0.dll

exit
_initterm
_initterm_e
__wgetmainargs
api-ms-win-core-delayload-l1-1-1.dll

ResolveDelayLoadedAPI
DelayLoadFailureHook
api-ms-win-core-errorhandling-l1-1-0.dll

SetErrorMode
GetLastError
SetUnhandledExceptionFilter
UnhandledExceptionFilter
api-ms-win-core-errorhandling-l1-1-1.dll

GetLastError
SetErrorMode
UnhandledExceptionFilter
SetUnhandledExceptionFilter
api-ms-win-core-handle-l1-1-0.dll

api-ms-win-core-heap-l1-1-0.dll

HeapAlloc
GetProcessHeap
HeapSetInformation
HeapFree
api-ms-win-core-heap-l1-2-0.dll

GetProcessHeap
HeapAlloc
HeapSetInformation
HeapFree
api-ms-win-core-heap-obsolete-l1-1-0.dll

api-ms-win-core-libraryloader-l1-1-1.dll

LoadLibraryExW
GetProcAddress
FreeLibrary
api-ms-win-core-libraryloader-l1-2-0.dll

FreeLibrary
GetProcAddress
LoadLibraryExW
api-ms-win-core-localization-l1-1-1.dll

api-ms-win-core-localization-l1-2-0.dll

api-ms-win-core-localization-l1-2-1.dll

api-ms-win-core-processenvironment-l1-1-0.dll

ExpandEnvironmentStringsW
GetCommandLineW
api-ms-win-core-processenvironment-l1-1-1.dll

ExpandEnvironmentStringsW
GetCommandLineW
api-ms-win-core-processenvironment-l1-2-0.dll

ExpandEnvironmentStringsW
GetCommandLineW
api-ms-win-core-processthreads-l1-1-0.dll

TerminateProcess
GetCurrentProcess
OpenProcessToken
GetCurrentProcessId
GetCurrentThreadId
api-ms-win-core-processthreads-l1-1-1.dll

ExitProcess
SetProcessAffinityUpdateMode
OpenProcessToken
TerminateProcess
GetCurrentThreadId
GetCurrentProcess
GetCurrentProcessId
IsProcessorFeaturePresent
api-ms-win-core-processthreads-l1-1-2.dll

SetProcessAffinityUpdateMode
OpenProcessToken
GetCurrentThreadId
ExitProcess
GetCurrentProcess
TerminateProcess
GetCurrentProcessId
api-ms-win-core-profile-l1-1-0.dll

api-ms-win-core-registry-l1-1-0.dll

RegOpenKeyExW
RegQueryValueExW
RegDisablePredefinedCacheEx
RegCloseKey
RegGetValueW
api-ms-win-core-sidebyside-l1-1-0.dll

DeactivateActCtx
ReleaseActCtx
ActivateActCtx
CreateActCtxW
api-ms-win-core-string-l1-1-0.dll

CompareStringW
WideCharToMultiByte
api-ms-win-core-string-obsolete-l1-1-0.dll

lstrcmpiW
lstrlenW
lstrcmpW
api-ms-win-core-synch-l1-1-1.dll

InitializeSRWLock
AcquireSRWLockShared
EnterCriticalSection
LeaveCriticalSection
ReleaseSRWLockShared
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
InitializeCriticalSection
api-ms-win-core-synch-l1-2-0.dll

AcquireSRWLockShared
InitializeSRWLock
AcquireSRWLockExclusive
EnterCriticalSection
LeaveCriticalSection
ReleaseSRWLockExclusive
ReleaseSRWLockShared
api-ms-win-core-sysinfo-l1-1-1.dll

GetSystemTimeAsFileTime
GetTickCount
api-ms-win-core-sysinfo-l1-2-0.dll

GetSystemTimeAsFileTime
GetTickCount
api-ms-win-core-sysinfo-l1-2-1.dll

GetSystemTimeAsFileTime
GetTickCount
api-ms-win-core-threadpool-l1-1-1.dll

RegisterWaitForSingleObjectEx
api-ms-win-core-threadpool-private-l1-1-0.dll

RegisterWaitForSingleObjectEx
api-ms-win-obsolete-kernelbase-l1-1-0.dll

lstrcmpW
lstrlenW
LocalAlloc
lstrcmpiW
LocalFree
api-ms-win-security-base-l1-1-0.dll

SetSecurityDescriptorDacl
AddAccessAllowedAce
SetSecurityDescriptorOwner
SetSecurityDescriptorGroup
GetTokenInformation
InitializeSecurityDescriptor
GetLengthSid
InitializeAcl
api-ms-win-security-base-l1-2-0.dll

GetLengthSid
InitializeAcl
InitializeSecurityDescriptor
GetTokenInformation
SetSecurityDescriptorGroup
SetSecurityDescriptorOwner
AddAccessAllowedAce
SetSecurityDescriptorDacl
api-ms-win-service-core-l1-1-0.dll

StartServiceCtrlDispatcherW
SetServiceStatus
api-ms-win-service-core-l1-1-1.dll

SetServiceStatus
StartServiceCtrlDispatcherW
api-ms-win-service-winsvc-l1-1-0.dll

RegisterServiceCtrlHandlerW
api-ms-win-service-winsvc-l1-2-0.dll

RegisterServiceCtrlHandlerW
kernel32.dll

LocalAlloc
CloseHandle
DelayLoadFailureHook
GetProcAddress
GetLastError
FreeLibrary
InterlockedCompareExchange
LoadLibraryExA
InterlockedExchange
Sleep
SetUnhandledExceptionFilter
GetModuleHandleA
QueryPerformanceCounter
GetTickCount
GetSystemTimeAsFileTime
UnhandledExceptionFilter
DeactivateActCtx
LoadLibraryExW
ActivateActCtx
LeaveCriticalSection
lstrcmpW
EnterCriticalSection
RegCloseKey
RegOpenKeyExW
HeapSetInformation
lstrcmpiW
lstrlenW
LCMapStringW
RegQueryValueExW
ReleaseActCtx
CreateActCtxW
ExpandEnvironmentStringsW
GetCommandLineW
ExitProcess
SetProcessAffinityUpdateMode
RegDisablePredefinedCacheEx
InitializeCriticalSection
GetProcessHeap
SetErrorMode
RegisterWaitForSingleObjectEx
LocalFree
HeapFree
WideCharToMultiByte
HeapAlloc
GetCurrentThreadId
GetCurrentProcessId
TerminateProcess
GetCurrentProcess
RegisterWaitForSingleObject
LoadLibraryA
ReleaseSRWLockShared
AcquireSRWLockShared
InitializeSRWLock
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
msvcrt.dll
ntdll.dll

RtlAllocateHeap
RtlLengthRequiredSid
RtlSubAuthoritySid
RtlInitializeSid
RtlCopySid
RtlSubAuthorityCountSid
RtlInitializeCriticalSection
RtlSetProcessIsCritical
RtlImageNtHeader
RtlUnhandledExceptionFilter
EtwEventWrite
EtwEventEnabled
EtwEventRegister
RtlFreeHeap
NtSetInformationProcess
rpcrt4.dll

RpcMgmtSetServerStackSize
I_RpcMapWin32Status
RpcServerUnregisterIf
RpcMgmtWaitServerListen
RpcMgmtStopServerListening
RpcServerUnregisterIfEx
RpcServerRegisterIf
RpcServerUseProtseqEpW
RpcServerListen
I_RpcServerDisableExceptionFilter