File details
File name: sppsvc.exe
Name: Microsoft Software Protection Platform Service
Description: Microsoft® Windows® Operating System
Version: 6.1.7600.16385 (win7_rtm.090713-1255)
Product version: 6.1.7600.16385
Size: 3.36 MB
Original file name: sppsvc.exe.mui
Windows file protection:
Yes
Digital certificate
Certificate authority:
Microsoft Corporation
Expiration date: 7/9/2013
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0017215272%
Privileged CPU:
0.0011942874%

User CPU:
0.00052723979297%

Privileged CPU time: 52651944.31 ms
Privileged CPU time /min: 1 ms
CPU cycle count:
785,534,710
CPU cycle count /min: 12,414,933
 | Memory utilization averages |
Committed memory:
40.08 MB
Peak committed memory: 41.87 MB
Paged memory:
4.53 MB
Peak paged memory: 5.29 MB
Paged system memory:
68.46 KB
Non-paged system memory: 8.63 KB
Working set memory:
7.59 MB
Peak working set memory: 10.65 MB
Min working set memory: 5.09 MB
Private memory:
4.53 MB
Page faults:
7,807
Page faults /min: 4
 | Process I/O averages |
Total read operations:
731
Read operations /min: 1
Total read transfer: 6.24 MB
Read transfer /min: 1.92 KB
Total write operations:
34
Write operations /min: 1
Total write transfer: 1.33 MB
Write transfer /min: 85 Bytes
Total other operations:
19,020
Other operations /min: 18
Total other transfer: 95.94 KB
Other Transfer /min: 86 Bytes
Resources
Handle count average: 159
Thread count average: 4
Thread resource averages
ntdll.dll

Total CPU: 0.003118191364%
Privileged CPU: 0.001336367728%
User CPU: 0.001781823637%
CPU Cycle count /sec: 112,580
Module memory size: 1.67 MB
msvcrt.dll

Total CPU: 0.001990883806%
Privileged CPU: 0.001990883806%
User CPU: 0.000000000000%
CPU Cycle count /sec: 51,900
Module memory size: 636 KB
Total CPU: 0.000176614861%
Privileged CPU: 0.000176614861%
User CPU: 0.000000000000%
CPU Cycle count /sec: 3,439
Module memory size: 3.37 MB
Process details
Runs as (owner): User
Integrety level: Undefined
Windows platform: 64-bit
Runs as a service: Yes
Parent Process
Process Command
C:\Windows\system32\sppsvc.exe
Service details
Name: Προστασία λογισμικού
Service name: sppsvc
Service type:
Win32OwnProcess
Description: “Επιτρέπει τη λήψη, εγκατάσταση και επιβολή των ψηφιακών αδειών χρήσης για τα Windows και τις εφαρμογές Windows. Αν η υπηρεσία είναι απενεργοποιημένη, το λειτουργικό σύστημα και οι εφαρμογές με άδεια χρήσης ενδέχεται να εκτελούνται σε κατάσταση ειδοποιήσεων. Συνιστάται η μη απενεργοποίηση της υπηρεσίας προστασίας λογισμικού.”
Image hashes
MD5: 913d843498553a1bc8f8dbad6358e49f
SHA-1: 9c063a440efcddddb29464583e6cafa40a459189
SHA-256: f8b931fdabf669d642cbdcd2ff31e07f8a5e2d5f72e11d4a8ff219ccfb5825e9
PE image details
Subsystem: Windows Console
Langauge*: Microsoft Visual C++
File entropy: 7.35781
File packed: No
Import Table
advapi32.dll

TraceMessage
RegCloseKey
GetTraceEnableFlags
GetTraceEnableLevel
GetTraceLoggerHandle
RegisterTraceGuidsW
UnregisterTraceGuids
SetServiceStatus
RegOpenKeyExW
RegQueryValueExW
RegisterServiceCtrlHandlerW
StartServiceCtrlDispatcherW
FreeSid
RegDeleteKeyW
RegCreateKeyExW
CheckTokenMembership
AllocateAndInitializeSid
ConvertStringSidToSidW
RegEnumKeyW
RegQueryInfoKeyW
ConvertStringSecurityDescriptorToSecurityDescriptorW
RegSetKeySecurity
RegDeleteValueW
RegSetValueExW
CryptGenRandom
CryptAcquireContextW
CryptReleaseContext
DeregisterEventSource
ReportEventW
RegisterEventSourceW
EqualSid
OpenProcessToken
ConvertSidToStringSidW
LookupAccountNameW
RegEnumKeyExW
CryptDestroyHash
CryptHashData
CryptCreateHash
CryptGetHashParam
CryptDestroyKey
CryptEncrypt
CryptDecrypt
CryptImportKey
CryptSignHashA
CryptVerifySignatureA
CryptExportKey
CryptGenKey
RegisterTraceGuidsA
GetTokenInformation
RegQueryValueExA
RegisterServiceCtrlHandlerA
StartServiceCtrlDispatcherA
RegOpenKeyExA
kernel32.dll

Sleep
InitializeCriticalSectionAndSpinCount
WaitForSingleObject
GetCurrentThreadId
DeleteTimerQueueEx
ReleaseSemaphore
LoadLibraryW
SetThreadPriority
GetThreadPriority
DuplicateHandle
GetCurrentProcess
GetCurrentThread
OpenThread
GetTickCount
ReleaseMutex
CreateSemaphoreW
IsWow64Process
OpenMutexW
CreateMutexW
ExpandEnvironmentStringsW
GetTimeFormatW
GetDateFormatW
FileTimeToSystemTime
SetFileAttributesW
GetFileAttributesW
ChangeTimerQueueTimer
CreateDirectoryW
WriteFile
CreateFileW
GetFileSizeEx
QueueUserWorkItem
ReadFile
GetFileSize
MultiByteToWideChar
OpenProcess
GetCurrentProcessId
GetSystemInfo
CompareFileTime
SystemTimeToFileTime
GetSystemTimeAsFileTime
DeleteTimerQueue
WaitForMultipleObjects
GetDevicePowerState
CreateSemaphoreA
InterlockedExchangeAdd
GetPrivateProfileStringW
GetPrivateProfileSectionW
GetFullPathNameW
InitializeCriticalSection
SetLastError
VirtualProtect
VirtualFree
VirtualAlloc
GetLocalTime
MoveFileExW
CopyFileW
FlushFileBuffers
DeleteFileW
SetFilePointer
CreateFileMappingW
MapViewOfFile
GetModuleHandleW
UnmapViewOfFile
GetSystemDefaultUILanguage
GetUserDefaultUILanguage
GetComputerNameW
DeviceIoControl
GetLocaleInfoW
GetSystemDirectoryW
LCMapStringW
WideCharToMultiByte
GetVersionExA
GetVersion
VirtualQuery
UnhandledExceptionFilter
TerminateProcess
QueryPerformanceCounter
GetModuleHandleA
SetUnhandledExceptionFilter
InterlockedExchange
UnregisterWaitEx
SetEvent
GetModuleHandleExW
GetProcAddress
CreateTimerQueue
CreateTimerQueueTimer
CreateEventW
RegisterWaitForSingleObject
RaiseException
InterlockedDecrement
GetVersionExW
InterlockedIncrement
GetLastError
HeapSetInformation
DeleteTimerQueueTimer
LeaveCriticalSection
LocalFree
EnterCriticalSection
LocalAlloc
DeleteCriticalSection
FreeLibrary
CloseHandle
DecodePointer
EncodePointer
InterlockedCompareExchange
HeapFree
GetProcessHeap
HeapAlloc
lstrlenW
ExitThread
CreateProcessA
SetCurrentDirectoryA
ExitProcess
OpenEventA
msvcrt.dll
ntdll.dll

NtQueryInformationThread
NtSetInformationThread
RtlUnwind
RtlFreeHeap
RtlAllocateHeap
RtlInitUnicodeString
RtlEnterCriticalSection
RtlLeaveCriticalSection
RtlCopyUnicodeString
RtlCompareUnicodeString
ole32.dll

CoInitializeSecurity
CoUninitialize
CoInitializeEx
rpcrt4.dll

NdrServerCall2
RpcServerRegisterIfEx
RpcServerUseProtseqEpW
RpcServerListen
RpcServerUnregisterIf
RpcMgmtStopServerListening
I_RpcBindingInqLocalClientPID
RpcServerInqCallAttributesW
RpcRaiseException
RpcStringFreeW
RpcRevertToSelfEx
RpcImpersonateClient
UuidCreate
UuidFromStringW
UuidToStringW
I_RpcMapWin32Status
user32.dll

wsprintfA
GetDesktopWindow