File details
File name: ehsched.exe
Name: Windows Media Center Scheduler Service
Description: Microsoft® Windows® Operating System
Version: 6.1.7600.16385 (win7_rtm.090713-1255)
Product version: 6.1.7600.16385
Size: 124.5 KB
Original file name: ehSched.exe.mui
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0509231206%
Privileged CPU:
0.0003397283%

User CPU:
0.05058339227567%

 | Memory utilization averages |
Min working set memory: 0 Bytes
Process details
Runs as (owner): Network Service
Windows platform: 64-bit
Runs as a service: Yes
Parent Process
Process Command
C:\Windows\ehome\ehsched.exe
Service details
Name: Υπηρεσία χρονοδιαγράμματος Windows Media Center
Service name: ehSched
Service type:
Win32OwnProcess
Description: “Ξεκινά και σταματά την εγγραφή τηλεοπτικών προγραμμάτων στο Windows Media Center”
Image hashes
MD5: 4705e8ef9934482c5bb488ce28afc681
SHA-1: 0827ddf85ccd2455aea261cd2ff5a9cfacb31b3b
SHA-256: 359e9ec5693ce0be89082e1d5d8f5c5439a5b985010ff0cb45c11e3cfe30637d
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File entropy: 6.17789
File packed: No
Import Table
advapi32.dll

CloseServiceHandle
OpenServiceW
OpenSCManagerW
DeleteService
ControlService
DeregisterEventSource
ReportEventW
RegisterEventSourceW
SetServiceStatus
RegDeleteKeyW
RegDeleteValueW
RegCloseKey
RegCreateKeyExW
RegOpenKeyExW
RegQueryValueExW
RegSetValueExW
RegQueryInfoKeyW
AddAce
GetAce
GetAclInformation
AddAccessAllowedAce
InitializeAcl
GetLengthSid
IsValidSid
ChangeServiceConfig2W
CreateServiceW
RegEnumKeyExW
InitializeSecurityDescriptor
SetSecurityDescriptorDacl
LookupAccountNameW
RegGetValueW
GetTokenInformation
OpenThreadToken
RegisterServiceCtrlHandlerExW
StartServiceCtrlDispatcherW
GetSecurityDescriptorDacl
ConvertStringSecurityDescriptorToSecurityDescriptorW
CopySid
SetSecurityDescriptorOwner
SetSecurityDescriptorGroup
LookupAccountSidW
CreateWellKnownSid
OpenProcessToken
SetNamedSecurityInfoW
SetSecurityInfo
kernel32.dll

CloseHandle
SetEvent
GetModuleFileNameW
MultiByteToWideChar
GetLocalTime
LeaveCriticalSection
EnterCriticalSection
GetCurrentThread
FreeLibrary
SizeofResource
lstrcmpiW
FindResourceW
LoadLibraryExW
GetModuleHandleW
ResetEvent
CreateEventW
ExitThread
WaitForSingleObject
CreateThread
WaitForMultipleObjects
CancelWaitableTimer
OpenThread
CreateWaitableTimerW
GetCurrentThreadId
GetCommandLineW
HeapSetInformation
QueueUserWorkItem
SetWaitableTimer
GetSystemTimeAsFileTime
QueueUserAPC
OutputDebugStringW
OutputDebugStringA
UnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
GetCurrentProcessId
GetTickCount
QueryPerformanceCounter
GetModuleHandleA
SetUnhandledExceptionFilter
GetStartupInfoW
InterlockedCompareExchange
Sleep
LocalFree
InterlockedExchange
GetVersionExA
InterlockedDecrement
InterlockedIncrement
DeleteCriticalSection
InitializeCriticalSection
RaiseException
lstrlenW
GetLastError
HeapAlloc
GetProcessHeap
HeapFree
LoadResource
EncodeSystemPointer
GetProcAddress
LoadLibraryW
GetTickCount64
QueryPerformanceFrequency
CreateEventExW
msvcrt.dll
ole32.dll

CoRevertToSelf
CoTaskMemAlloc
CoCreateGuid
CoInitialize
CoInitializeEx
CoUninitialize
CoImpersonateClient
CoSetProxyBlanket
CoInitializeSecurity
StringFromGUID2
CoTaskMemFree
CoRegisterClassObject
CoRevokeClassObject
CoCreateInstance
CoTaskMemRealloc
CoReleaseServerProcess
CoAddRefServerProcess
slc.dll

SLGetWindowsInformationDWORD
user32.dll

TranslateMessage
RegisterDeviceNotificationW
UnregisterDeviceNotification
MsgWaitForMultipleObjectsEx
DispatchMessageW
UnregisterClassA
PeekMessageW
CharNextW
PostThreadMessageW