File details
File name: services.exe
Name: ระบบปฏิบัติการ Microsoft® Windows®
Description: โปรแกรม Services and Controller
Version: 6.2.9200.16384 (win8_rtm.120725-1247)
Product version: 6.2.9200.16384
Size: 401 KB
Original file name: services.exe.mui
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0038536623%
Privileged CPU:
0.0020083539%

User CPU:
0.00184530841867%

Privileged CPU time: 20185984.81 ms
Privileged CPU time /min: 15 ms
CPU cycle count:
105,390,026
CPU cycle count /min: 49,941,350
Context switches /sec:
71
 | Memory utilization averages |
Committed memory:
44.39 MB
Peak committed memory: 72.34 MB
Paged memory:
5.68 MB
Peak paged memory: 9.64 MB
Paged system memory:
109.98 KB
Non-paged system memory: 14.73 KB
Working set memory:
8.41 MB
Peak working set memory: 13.61 MB
Min working set memory: 7.3 MB
Private memory:
5.68 MB
Page faults:
45,382
Page faults /min: 65
 | Process I/O averages |
Total read operations:
30,900
Read operations /min: 25
Total read transfer: 13.97 MB
Read transfer /min: 50.04 KB
Total write operations:
4,601
Write operations /min: 1
Total write transfer: 322.91 KB
Write transfer /min: 216 Bytes
Total other operations:
276,665
Other operations /min: 116
Total other transfer: 4.21 MB
Other Transfer /min: 1.76 KB
Resources
Handle count average: 318
Thread count average: 10
Thread resource averages
ntdll.dll

Total CPU: 0.052648052492%
Privileged CPU: 0.031157968730%
User CPU: 0.021490083762%
CPU Cycle count /sec: 1,011,626
Context switches /sec: 6
Module memory size: 1.74 MB
ntdll.dll

Total CPU: 0.033780345284%
Privileged CPU: 0.018247292250%
User CPU: 0.015533053034%
CPU Cycle count /sec: 788,174
Context switches /sec: 10
Module memory size: 1.75 MB
ubpm.dll

Total CPU: 0.009360908482%
Privileged CPU: 0.001068730705%
User CPU: 0.008292177777%
CPU Cycle count /sec: 185,855
Context switches /sec: 13
Module memory size: 332 KB
ubpm.dll

Total CPU: 0.006414991407%
Privileged CPU: 0.000908541402%
User CPU: 0.005506450005%
CPU Cycle count /sec: 138,623
Context switches /sec: 1
Module memory size: 324 KB
Total CPU: 0.000928280126%
Privileged CPU: 0.000500464068%
User CPU: 0.000427816058%
CPU Cycle count /sec: 99,723
Context switches /sec: 5
Module memory size: 552 KB
ubpm.dll

Total CPU: 0.000314227867%
Privileged CPU: 0.000033828383%
User CPU: 0.000280399484%
CPU Cycle count /sec: 17,082
Module memory size: 324 KB
ubpm.dll

Total CPU: 0.000234583628%
Privileged CPU: 0.000051156818%
User CPU: 0.000183426810%
CPU Cycle count /sec: 9,116
Module memory size: 332 KB
ubpm.dll

Total CPU: 0.000190786427%
Privileged CPU: 0.000080416078%
User CPU: 0.000110370349%
CPU Cycle count /sec: 10,713
Module memory size: 332 KB
ubpm.dll

Total CPU: 0.000064035231%
Privileged CPU: 0.000016891309%
User CPU: 0.000047143922%
CPU Cycle count /sec: 12,025
Module memory size: 324 KB
Process details
Runs as (owner): User
Integrety level: System
Windows platform: 64-bit
Parent Process
Child Processes
Process Commands
C:\Windows\system32\services.exe
C:\Windows\System32\services.exe
C:\WINDOWS\system32\services.exe
Network connectivity
TCP: localhost on port 49159
TCP: localhost on port 49157
TCP: localhost on port 49295
TCP: localhost on port 49156
TCP: localhost on port 49166
TCP: localhost on port 49155
TCP: localhost on port 49158
TCP: localhost on port 49162
TCP: localhost on port 49165
TCP: localhost on port 49161
TCP: localhost on port 49167
TCP: localhost on port 49181
Image hashes
MD5: 8f226143046435c75c033b0c52e90ffe
SHA-1: 05037ff6dd5bea4d88578ded684062cf777f0ffd
SHA-256: 54fa316485b57d7b8104fe621f5f40dec35e3d57c3df46b5f7eacf57445fe7ca
PE image details
CLR assembly: Yes
CLR NGENed: No
Langauge*: Microsoft Visual C# / Basic .NET
File packed: No