File details
File name: alg.exe
Name: Application Layer Gateway Service
Description: Microsoft® Windows® Operating System
Version: 6.0.6000.16386 (vista_rtm.061101-2205)
Product version: 6.0.6000.16386
Size: 58 KB
Original file name: ALG.exe.mui
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0017763369%
Privileged CPU:
0.0008475404%

User CPU:
0.00092879645239%

Privileged CPU time: 169021.89 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
129,135,755
CPU cycle count /min: 334,354
 | Memory utilization averages |
Committed memory:
35.17 MB
Peak committed memory: 36.25 MB
Paged memory:
1.43 MB
Peak paged memory: 1.48 MB
Paged system memory:
56.06 KB
Non-paged system memory: 3.06 KB
Working set memory:
2.19 MB
Peak working set memory: 3.98 MB
Min working set memory: 2.07 MB
Private memory:
1.43 MB
Page faults:
2,155
Page faults /min: 4
 | Process I/O averages |
Total read operations:
5
Read operations /min: 1
Total read transfer: 1.67 KB
Read transfer /min: 0 Bytes
Total write operations:
3
Write operations /min: 1
Total write transfer: 183 Bytes
Write transfer /min: 0 Bytes
Total other operations:
555
Other operations /min: 2
Total other transfer: 1.71 KB
Other Transfer /min: 3 Bytes
Resources
Handle count average: 75
Thread count average: 3
Thread resource averages
advapi32.dll

Total CPU: 0.000039520158%
Privileged CPU: 0.000012690089%
User CPU: 0.000026830068%
CPU Cycle count /sec: 824
Module memory size: 792 KB
Total CPU: 0.000023709723%
Privileged CPU: 0.000017673959%
User CPU: 0.000006035764%
CPU Cycle count /sec: 433
Module memory size: 68 KB
Process details
Runs as (owner): Local Service
Integrety level: System
Windows platform: 32-bit
Runs as a service: Yes
Parent Process
Process Command
C:\Windows\System32\alg.exe
Service details
Name: Υπηρεσία πύλης επιπέδου εφαρμογής
Service name: ALG
Service type:
Win32OwnProcess
Description: “Παρέχει υποστήριξη για προσθήκες πρωτοκόλλων άλλων κατασκευαστών για την Κοινόχρηστη σύνδεση στο Internet”
Network connectivity
TCP: localhost on port 49959
Image hashes
MD5: a1545b731579895d8cc44fc0481c1192
SHA-1: 1414ab5da123748f62207d663153b43d4dc4abf5
SHA-256: 6b0ee833ba39c142d625a03586ccd8f6c9c3136c603ce5df5bac1aa3423e3e7f
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File entropy: 6.35313
File packed: No
Import Table
advapi32.dll

SetServiceStatus
RegCloseKey
RegOpenKeyExW
RegisterServiceCtrlHandlerW
RegNotifyChangeKeyValue
StartServiceCtrlDispatcherW
RegQueryValueExW
RegEnumKeyExW
SystemFunction036
api-ms-win-core-delayload-l1-1-1.dll

ResolveDelayLoadedAPI
DelayLoadFailureHook
api-ms-win-core-errorhandling-l1-1-1.dll

UnhandledExceptionFilter
RaiseException
SetUnhandledExceptionFilter
GetLastError
api-ms-win-core-file-l1-2-0.dll

api-ms-win-core-handle-l1-1-0.dll

CloseHandle
DuplicateHandle
api-ms-win-core-heap-l1-2-0.dll

HeapDestroy
HeapSetInformation
HeapFree
GetProcessHeap
HeapAlloc
api-ms-win-core-interlocked-l1-2-0.dll

InterlockedCompareExchange
InterlockedDecrement
InterlockedIncrement
InterlockedExchange
api-ms-win-core-kernel32-legacy-l1-1-0.dll

BindIoCompletionCallback
WaitForMultipleObjects
api-ms-win-core-libraryloader-l1-1-1.dll

LoadResource
SizeofResource
GetModuleHandleA
GetModuleHandleW
FreeLibrary
GetModuleFileNameW
FindResourceExW
GetProcAddress
LoadLibraryExW
api-ms-win-core-memory-l1-1-1.dll

VirtualQuery
VirtualProtect
VirtualAlloc
api-ms-win-core-processthreads-l1-1-1.dll

GetCurrentProcessId
GetCurrentProcess
GetCurrentThreadId
TerminateProcess
GetStartupInfoW
CreateThread
api-ms-win-core-profile-l1-1-0.dll

api-ms-win-core-registry-l1-1-0.dll

RegCreateKeyExW
RegDeleteValueW
RegNotifyChangeKeyValue
RegSetValueExW
RegQueryInfoKeyW
RegOpenKeyExW
RegEnumKeyExW
RegCloseKey
RegEnumValueW
RegQueryValueExW
api-ms-win-core-string-l1-1-0.dll

api-ms-win-core-string-l2-1-0.dll

api-ms-win-core-string-obsolete-l1-1-0.dll

api-ms-win-core-synch-l1-2-0.dll

SetEvent
WaitForSingleObject
Sleep
CreateEventW
EnterCriticalSection
InitializeCriticalSection
DeleteCriticalSection
LeaveCriticalSection
api-ms-win-core-sysinfo-l1-2-0.dll

GetVersionExW
GetTickCount
GetSystemTimeAsFileTime
GetSystemInfo
api-ms-win-core-threadpool-legacy-l1-1-0.dll

DeleteTimerQueueEx
DeleteTimerQueueTimer
CreateTimerQueueTimer
CreateTimerQueue
cryptbase.dll

kernel32.dll

DeleteTimerQueueEx
CloseHandle
Sleep
WaitForMultipleObjects
CreateEventW
HeapSetInformation
WaitForSingleObject
SetEvent
CreateThread
DeleteTimerQueueTimer
CreateTimerQueueTimer
GetCurrentProcessId
DuplicateHandle
GetCurrentProcess
RaiseException
GetLastError
CreateTimerQueue
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSection
DeleteCriticalSection
InterlockedDecrement
InterlockedIncrement
InterlockedExchange
InterlockedCompareExchange
GetStartupInfoW
SetUnhandledExceptionFilter
BindIoCompletionCallback
WriteFile
ReadFile
HeapFree
GetProcessHeap
HeapAlloc
UnhandledExceptionFilter
TerminateProcess
GetSystemTimeAsFileTime
GetCurrentThreadId
GetTickCount
QueryPerformanceCounter
GetModuleHandleA
msvcrt.dll
mswsock.dll

AcceptEx
GetAcceptExSockaddrs
ole32.dll

CoCreateInstance
CoTaskMemFree
CoTaskMemAlloc
CoUninitialize
CoInitializeEx
CLSIDFromString
ws2_32.dll
