File details
File name: alg.exe
Name: Application Layer Gateway Service
Description: Microsoft® Windows® Operating System
Version: 6.0.6000.16386 (vista_rtm.061101-2205)
Product version: 6.0.6000.16386
Size: 57.5 KB
Original file name: ALG.exe.mui
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0007646808%
Privileged CPU:
0.0003823404%

User CPU:
0.00038234038464%

Privileged CPU time: 31.25 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
145,228,508
CPU cycle count /min: 1,081,811
 | Memory utilization averages |
Committed memory:
27.23 MB
Peak committed memory: 27.73 MB
Paged memory:
1.18 MB
Peak paged memory: 1.23 MB
Paged system memory:
29.6 KB
Non-paged system memory: 4.19 KB
Working set memory:
224 KB
Peak working set memory: 3.91 MB
Min working set memory: 116 KB
Private memory:
1.18 MB
Page faults:
1,276
Page faults /min: 10
 | Process I/O averages |
Total read operations:
4
Read operations /min: 1
Total read transfer: 236 Bytes
Read transfer /min: 2 Bytes
Total write operations:
4
Write operations /min: 1
Total write transfer: 260 Bytes
Write transfer /min: 2 Bytes
Total other operations:
516
Other operations /min: 4
Total other transfer: 2.6 KB
Other Transfer /min: 20 Bytes
Resources
Handle count average: 77
Thread count average: 4
Thread resource averages
advapi32.dll

Total CPU: 0.000191396261%
Privileged CPU: 0.000000000000%
User CPU: 0.000191396261%
CPU Cycle count /sec: 4,638
Module memory size: 764 KB
Total CPU: 0.000191394201%
Privileged CPU: 0.000191394201%
User CPU: 0.000000000000%
CPU Cycle count /sec: 2,739
Module memory size: 64 KB
Process details
Runs as (owner): Local Service
Integrety level: System
Windows platform: 32-bit
Runs as a service: Yes
Parent Process
Process Command
C:\Windows\System32\alg.exe
Service details
Name: Υπηρεσία πύλης επιπέδου εφαρμογής
Service name: ALG
Service type:
Win32OwnProcess
Description: “Παρέχει υποστήριξη για προσθήκες πρωτοκόλλων άλλων κατασκευαστών για την Κοινόχρηστη σύνδεση στο Internet”
Network connectivity
TCP: localhost on port 49159
Image hashes
MD5: e69fb0e3112c40fdc0ef7d21a52dc951
SHA-1: 14c785ed9ff7eddcb066a5e62dc8fde9fe28af75
SHA-256: 6fb299330edef77dc91fc279d90d8adea138ec98342116121f5879b50070963d
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File entropy: 6.35313
File packed: No
Import Table
advapi32.dll

SetServiceStatus
RegCloseKey
RegOpenKeyExW
RegisterServiceCtrlHandlerW
RegNotifyChangeKeyValue
StartServiceCtrlDispatcherW
RegQueryValueExW
RegEnumKeyExW
SystemFunction036
api-ms-win-core-delayload-l1-1-1.dll

ResolveDelayLoadedAPI
DelayLoadFailureHook
api-ms-win-core-errorhandling-l1-1-1.dll

UnhandledExceptionFilter
RaiseException
SetUnhandledExceptionFilter
GetLastError
api-ms-win-core-file-l1-2-0.dll

api-ms-win-core-handle-l1-1-0.dll

CloseHandle
DuplicateHandle
api-ms-win-core-heap-l1-2-0.dll

HeapDestroy
HeapSetInformation
HeapFree
GetProcessHeap
HeapAlloc
api-ms-win-core-interlocked-l1-2-0.dll

InterlockedCompareExchange
InterlockedDecrement
InterlockedIncrement
InterlockedExchange
api-ms-win-core-kernel32-legacy-l1-1-0.dll

BindIoCompletionCallback
WaitForMultipleObjects
api-ms-win-core-libraryloader-l1-1-1.dll

LoadResource
SizeofResource
GetModuleHandleA
GetModuleHandleW
FreeLibrary
GetModuleFileNameW
FindResourceExW
GetProcAddress
LoadLibraryExW
api-ms-win-core-memory-l1-1-1.dll

VirtualQuery
VirtualProtect
VirtualAlloc
api-ms-win-core-processthreads-l1-1-1.dll

GetCurrentProcessId
GetCurrentProcess
GetCurrentThreadId
TerminateProcess
GetStartupInfoW
CreateThread
api-ms-win-core-profile-l1-1-0.dll

api-ms-win-core-registry-l1-1-0.dll

RegCreateKeyExW
RegDeleteValueW
RegNotifyChangeKeyValue
RegSetValueExW
RegQueryInfoKeyW
RegOpenKeyExW
RegEnumKeyExW
RegCloseKey
RegEnumValueW
RegQueryValueExW
api-ms-win-core-string-l1-1-0.dll

api-ms-win-core-string-l2-1-0.dll

api-ms-win-core-string-obsolete-l1-1-0.dll

api-ms-win-core-synch-l1-2-0.dll

SetEvent
WaitForSingleObject
Sleep
CreateEventW
EnterCriticalSection
InitializeCriticalSection
DeleteCriticalSection
LeaveCriticalSection
api-ms-win-core-sysinfo-l1-2-0.dll

GetVersionExW
GetTickCount
GetSystemTimeAsFileTime
GetSystemInfo
api-ms-win-core-threadpool-legacy-l1-1-0.dll

DeleteTimerQueueEx
DeleteTimerQueueTimer
CreateTimerQueueTimer
CreateTimerQueue
cryptbase.dll

kernel32.dll

DeleteTimerQueueEx
CloseHandle
Sleep
WaitForMultipleObjects
CreateEventW
HeapSetInformation
WaitForSingleObject
SetEvent
CreateThread
DeleteTimerQueueTimer
CreateTimerQueueTimer
GetCurrentProcessId
DuplicateHandle
GetCurrentProcess
RaiseException
GetLastError
CreateTimerQueue
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSection
DeleteCriticalSection
InterlockedDecrement
InterlockedIncrement
InterlockedExchange
InterlockedCompareExchange
GetStartupInfoW
SetUnhandledExceptionFilter
BindIoCompletionCallback
WriteFile
ReadFile
HeapFree
GetProcessHeap
HeapAlloc
UnhandledExceptionFilter
TerminateProcess
GetSystemTimeAsFileTime
GetCurrentThreadId
GetTickCount
QueryPerformanceCounter
GetModuleHandleA
msvcrt.dll
mswsock.dll

AcceptEx
GetAcceptExSockaddrs
ole32.dll

CoCreateInstance
CoTaskMemFree
CoTaskMemAlloc
CoUninitialize
CoInitializeEx
CLSIDFromString
ws2_32.dll
