File details
File name: csrss.exe
Name: Client Server Runtime Process
Description: Microsoft® Windows® Operating System
Version: 6.1.7600.16385 (win7_rtm.090713-1255)
Product version: 6.1.7600.16385
Size: 7.5 KB
Original file name: CSRSS.Exe.MUI
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0060897279%
Privileged CPU:
0.0034972036%

User CPU:
0.00259252432292%

Privileged CPU time: 59464545.91 ms
Privileged CPU time /min: 998 ms
CPU cycle count:
4,306,505
CPU cycle count /min: 187,918,505
Context switches /sec:
112
 | Memory utilization averages |
Committed memory:
106.72 MB
Peak committed memory: 152.21 MB
Paged memory:
5.66 MB
Peak paged memory: 10.48 MB
Paged system memory:
259.09 KB
Non-paged system memory: 18.75 KB
Working set memory:
11.26 MB
Peak working set memory: 21.93 MB
Min working set memory: 6.83 MB
Private memory:
5.66 MB
Page faults:
99,853
Page faults /min: 60
 | Process I/O averages |
Total read operations:
420,932
Read operations /min: 136
Total read transfer: 11.34 MB
Read transfer /min: 5.26 KB
Total other operations:
101,696
Other operations /min: 36
Total other transfer: 1.03 MB
Other Transfer /min: 510 Bytes
 | GUI Object Averages |
GDI objects:
166
Peak GDI objects: 233
USER objects:
80
Peak USER objects: 86
Resources
Handle count average: 746
Thread count average: 11
Thread resource averages
sechost.dll

Total CPU: 0.234824608414%
Privileged CPU: 0.234824608414%
User CPU: 0.000000000000%
CPU Cycle count /sec: 7,112,866
Context switches /sec: 13
Module memory size: 124 KB
lpk.dll

Total CPU: 0.101785175904%
Privileged CPU: 0.101785175904%
User CPU: 0.000000000000%
CPU Cycle count /sec: 3,683,494
Context switches /sec: 11
Module memory size: 56 KB
usp10.dll

Total CPU: 0.095567352690%
Privileged CPU: 0.095567352690%
User CPU: 0.000000000000%
CPU Cycle count /sec: 4,074,317
Context switches /sec: 16
Module memory size: 804 KB
advapi32.dll

Total CPU: 0.078185438646%
Privileged CPU: 0.078185438646%
User CPU: 0.000000000000%
CPU Cycle count /sec: 2,731,818
Context switches /sec: 10
Module memory size: 876 KB
Total CPU: 0.072170400815%
Privileged CPU: 0.072170400815%
User CPU: 0.000000000000%
CPU Cycle count /sec: 4,580,679
Context switches /sec: 34
Module memory size: 636 KB
rpcrt4.dll

Total CPU: 0.069408762801%
Privileged CPU: 0.069408762801%
User CPU: 0.000000000000%
CPU Cycle count /sec: 3,922,665
Context switches /sec: 42
Module memory size: 1.18 MB
rpcrt4.dll

Total CPU: 0.067826836228%
Privileged CPU: 0.067826836228%
User CPU: 0.000000000000%
CPU Cycle count /sec: 4,485,500
Context switches /sec: 18
Module memory size: 1.18 MB
usp10.dll

Total CPU: 0.061756484237%
Privileged CPU: 0.061756484237%
User CPU: 0.000000000000%
CPU Cycle count /sec: 3,688,262
Context switches /sec: 24
Module memory size: 808 KB
usp10.dll

Total CPU: 0.058298500273%
Privileged CPU: 0.058298500273%
User CPU: 0.000000000000%
CPU Cycle count /sec: 1,677,739
Context switches /sec: 5
Module memory size: 804 KB
rpcrt4.dll

Total CPU: 0.036255570797%
Privileged CPU: 0.036255570797%
User CPU: 0.000000000000%
CPU Cycle count /sec: 1,897,930
Context switches /sec: 12
Module memory size: 1.18 MB
winsrv.dll

Total CPU: 0.033066799809%
Privileged CPU: 0.033066779457%
User CPU: 0.000000020351%
CPU Cycle count /sec: 2,139,247
Context switches /sec: 46
Module memory size: 224 KB
winsrv.dll

Total CPU: 0.032141299859%
Privileged CPU: 0.032141071705%
User CPU: 0.000000228155%
CPU Cycle count /sec: 2,040,870
Context switches /sec: 28
Module memory size: 224 KB
winsrv.dll

Total CPU: 0.029598799525%
Privileged CPU: 0.029596722953%
User CPU: 0.000002076572%
CPU Cycle count /sec: 1,638,668
Context switches /sec: 31
Module memory size: 224 KB
gdi32.dll

Total CPU: 0.026936109552%
Privileged CPU: 0.026936109552%
User CPU: 0.000000000000%
CPU Cycle count /sec: 1,354,508
Context switches /sec: 8
Module memory size: 412 KB
advapi32.dll

Total CPU: 0.026026858959%
Privileged CPU: 0.026026858959%
User CPU: 0.000000000000%
CPU Cycle count /sec: 3,972,871
Context switches /sec: 19
Module memory size: 876 KB
msvcrt.dll

Total CPU: 0.025014617818%
Privileged CPU: 0.025014617818%
User CPU: 0.000000000000%
CPU Cycle count /sec: 1,425,141
Context switches /sec: 8
Module memory size: 636 KB
winsrv.dll

Total CPU: 0.022530875291%
Privileged CPU: 0.022526481801%
User CPU: 0.000004393490%
CPU Cycle count /sec: 1,052,490
Context switches /sec: 33
Module memory size: 224 KB
winsrv.dll

Total CPU: 0.019563697051%
Privileged CPU: 0.019561625622%
User CPU: 0.000002071429%
CPU Cycle count /sec: 1,559,823
Context switches /sec: 31
Module memory size: 224 KB
msvcrt.dll

Total CPU: 0.017372483877%
Privileged CPU: 0.017372483877%
User CPU: 0.000000000000%
CPU Cycle count /sec: 1,603,320
Context switches /sec: 7
Module memory size: 636 KB
winsrv.dll

Total CPU: 0.017183114608%
Privileged CPU: 0.017179640673%
User CPU: 0.000003473935%
CPU Cycle count /sec: 1,690,802
Context switches /sec: 42
Module memory size: 224 KB
Process details
Runs as (owner): System
Integrety level: System
Windows platform: 64-bit
Parent Process
Child Processes
Process Command
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrC:UserServerDllInitialization,3 ServerDll=winsrC:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
Scheduled task details
Name: \{1B908455-E233-4AF6-9EA8-FB47FE9E21E2}
Image hashes
MD5: 60c2862b4bf0fd9f582ef344c2b1ec72
SHA-1: 17542707a3d9fa13c569450fd978272ef7070a77
SHA-256: cb1c6018fc5c15483ac5bb96e5c2e2e115bb0c0e1314837d77201bab37e8c03a
PE image details
File entropy: 4.29124
File packed: No
Import Table
csrsrv.dll

CsrUnhandledExceptionFilter
CsrServerInitialization
ntdll.dll

RtlSetHeapInformation
RtlSetProcessIsCritical
NtTerminateThread
NtSetInformationProcess
RtlSetUnhandledExceptionFilter
NtTerminateProcess
RtlFreeAnsiString
RtlAllocateHeap
isspace
RtlUnicodeStringToAnsiString
RtlNormalizeProcessParams
DbgBreakPoint
RtlUnhandledExceptionFilter
RtlUnwind
_aullshr