File details
File name: ehprivjob.exe
Name: Digital TV Tuner device registration application.
Description: Microsoft® Windows® Operating System
Version: 6.1.7600.16385 (win7_rtm.090713-1255)
Product version: 6.1.7600.16385
Size: 289 KB
Original file name: ehPrivJob.exe.mui
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0000602866%
Privileged CPU:
0.0000401911%

User CPU:
0.00002009553306%

Privileged CPU time: 62.4 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
328,277,262
CPU cycle count /min: 7,437
 | Memory utilization averages |
Committed memory:
70.54 MB
Peak committed memory: 72.54 MB
Paged memory:
3.78 MB
Peak paged memory: 3.86 MB
Paged system memory:
137.38 KB
Non-paged system memory: 14.61 KB
Working set memory:
1.84 MB
Peak working set memory: 9.36 MB
Min working set memory: 1.74 MB
Private memory:
3.78 MB
Page faults:
3,570
Page faults /min: 1
 | Process I/O averages |
Total read operations:
4
Read operations /min: 1
Total read transfer: 34.28 KB
Read transfer /min: 0 Bytes
Total other operations:
2,489
Other operations /min: 1
Total other transfer: 53.48 KB
Other Transfer /min: 0 Bytes
Resources
Handle count average: 191
Thread count average: 10
Thread resource averages
Total CPU: 0.000080853456%
Privileged CPU: 0.000080853456%
User CPU: 0.000000000000%
CPU Cycle count /sec: 2,824
Module memory size: 124 KB
msdri.dll

Total CPU: 0.000040426793%
Privileged CPU: 0.000000000000%
User CPU: 0.000040426793%
CPU Cycle count /sec: 219
Module memory size: 556 KB
Total CPU: 0.000040426604%
Privileged CPU: 0.000020213240%
User CPU: 0.000020213365%
CPU Cycle count /sec: 1,653
Module memory size: 696 KB
Process details
Runs as (owner): System
Integrety level: System
Windows platform: 64-bit
Runs as a service: Yes
Parent Process
Process Command
C:\Windows\ehome\ehPrivJob.exe /DoRecoveryTasks
Scheduled task details
Name: UpdateRecordPath
Command: \Microsoft\Windows\Media Center\UpdateRecordPath
Scheduled tasks startup details
Name: \Microsoft\Windows\Media Center\DispatchRecoveryTasks
Image hashes
MD5: c07d5582f2107acab4564e1dae977c64
SHA-1: b4c123c7d17a3c44e74880b4108766e8ce4b6a66
SHA-256: a9ae53f7d23ddc96a05f3b93f547abd1896233f3d835c6b07ad9e9781788bc32
PE image details
Subsystem: Windows Console
Langauge*: Microsoft Visual C++
File entropy: 5.66326
File packed: No
Import Table
advapi32.dll

RegCloseKey
RegEnumKeyExW
RegCreateKeyExW
RegOpenKeyExW
RegSetValueExW
RegQueryValueExW
RegEnumKeyW
RegQueryInfoKeyW
ConvertStringSecurityDescriptorToSecurityDescriptorW
RegEnumValueW
ConvertStringSidToSidW
CreateWellKnownSid
EqualSid
GetAce
OpenThreadToken
ImpersonateSelf
AdjustTokenPrivileges
LookupPrivilegeValueW
SetNamedSecurityInfoW
GetNamedSecurityInfoW
GetSecurityInfo
RevertToSelf
SetEntriesInAclW
QueryServiceStatusEx
StartServiceW
ControlService
CloseServiceHandle
OpenServiceW
OpenSCManagerW
ConvertSidToStringSidW
GetTokenInformation
OpenProcessToken
ChangeServiceConfigW
iphlpapi.dll

kernel32.dll

lstrlenW
QueryFullProcessImageNameW
OpenProcess
MultiByteToWideChar
CloseHandle
LocalFree
SetEvent
CreateEventW
CreateDirectoryW
GetEnvironmentVariableW
OpenEventW
Sleep
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
WaitForSingleObject
GetModuleHandleW
WideCharToMultiByte
WaitForMultipleObjects
LocalAlloc
GetCurrentThread
CreateFileW
FindClose
FindNextFileW
FindFirstFileW
GetFileAttributesW
lstrlenA
InterlockedDecrement
GetSystemTime
WriteFile
SetFilePointer
GetCurrentProcessId
GetCurrentThreadId
GetLocalTime
GetWindowsDirectoryW
GetTickCount64
CompareStringW
GetCurrentProcess
CreateProcessW
CopyFileW
GetModuleFileNameW
GetTempPathW
DelayLoadFailureHook
FreeLibrary
InterlockedCompareExchange
LoadLibraryExA
GetStartupInfoW
SetUnhandledExceptionFilter
GetModuleHandleA
QueryPerformanceCounter
GetTickCount
GetSystemTimeAsFileTime
TerminateProcess
UnhandledExceptionFilter
InterlockedIncrement
GetProcAddress
LoadLibraryW
FlushFileBuffers
DeleteFileW
CompareFileTime
GetLastError
CreateThread
SetEndOfFile
MoveFileExW
OutputDebugStringW
CreateMutexW
OpenMutexW
ReleaseMutex
InterlockedExchange
msvcrt.dll
ole32.dll

CoUninitialize
CoInitializeEx
CoCreateInstance
StringFromGUID2
CoTaskMemFree
CLSIDFromString
StringFromCLSID
CoSetProxyBlanket
CoTaskMemAlloc
CoCreateGuid
StringFromIID
propsys.dll

PSUnregisterPropertySchema
PSRegisterPropertySchema
shlwapi.dll

PathFindFileNameW
UrlGetPartW
PathCombineW
slc.dll

SLInstallProofOfPurchase
SLGetPKeyInformation
SLConsumeWindowsRight
SLClose
SLOpen
slcext.dll

user32.dll

LoadStringW
CharLowerBuffW
wmdrmsdk.dll

ws2_32.dll

WSAStringToAddressW
GetNameInfoW