File details
File name: ehsched.exe
Name: Windows Media Center Scheduler Service
Description: Microsoft® Windows® Operating System
Version: 6.1.1000.18273 (longhorn_mc_dev(wmbla).080702-2311)
Product version: 6.1.1000.18273
Size: 119.5 KB
Original file name: ehSched.exe.mui
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0001673746%
Privileged CPU:
0.0000604909%

User CPU:
0.00010688368668%

Privileged CPU time: 62.4 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
1,171,212,146
CPU cycle count /min: 473,019
 | Memory utilization averages |
Committed memory:
32.94 MB
Peak committed memory: 33.94 MB
Paged memory:
1.64 MB
Peak paged memory: 1.7 MB
Paged system memory:
63.2 KB
Non-paged system memory: 4.94 KB
Working set memory:
4.56 MB
Peak working set memory: 4.84 MB
Min working set memory: 4.45 MB
Private memory:
1.64 MB
Page faults:
1,524
Page faults /min: 1
 | Process I/O averages |
Total read operations:
70
Read operations /min: 1
Total read transfer: 14.96 KB
Read transfer /min: 6 Bytes
Total write operations:
68
Write operations /min: 1
Total write transfer: 6.63 KB
Write transfer /min: 2 Bytes
Total other operations:
536
Other operations /min: 1
Total other transfer: 13.97 KB
Other Transfer /min: 3 Bytes
Resources
Handle count average: 78
Thread count average: 5
Thread resource averages
advapi32.dll

Total CPU: 0.000233575884%
Privileged CPU: 0.000124857558%
User CPU: 0.000108718326%
CPU Cycle count /sec: 19,576
Module memory size: 1.03 MB
Total CPU: 0.000212057311%
Privileged CPU: 0.000000000000%
User CPU: 0.000212057311%
CPU Cycle count /sec: 2,668
Module memory size: 132 KB
Process details
Runs as (owner): Network Service
Integrety level: System
Windows platform: 64-bit
Runs as a service: Yes
Parent Process
Process Command
C:\Windows\ehome\ehsched.exe
Service details
Name: Υπηρεσία χρονοδιαγράμματος Windows Media Center
Service name: ehSched
Service type:
Win32OwnProcess
Description: “Ξεκινά και σταματά την εγγραφή τηλεοπτικών προγραμμάτων στο Windows Media Center”
Image hashes
MD5: 1abc6436b0edaa3d496d9c827f92820d
SHA-1: 17691daea0035a353f72d0dedb6160a2b9d10312
SHA-256: 700bef8cc38d75c8003a4208d2af7a45f752a1bc88f7ecd28bdc38f773bb861f
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File entropy: 6.17789
File packed: No
Import Table
advapi32.dll

CloseServiceHandle
OpenServiceW
OpenSCManagerW
DeleteService
ControlService
DeregisterEventSource
ReportEventW
RegisterEventSourceW
SetServiceStatus
RegDeleteKeyW
RegDeleteValueW
RegCloseKey
RegCreateKeyExW
RegOpenKeyExW
RegQueryValueExW
RegSetValueExW
RegQueryInfoKeyW
AddAce
GetAce
GetAclInformation
AddAccessAllowedAce
InitializeAcl
GetLengthSid
IsValidSid
ChangeServiceConfig2W
CreateServiceW
RegEnumKeyExW
InitializeSecurityDescriptor
SetSecurityDescriptorDacl
LookupAccountNameW
RegGetValueW
GetTokenInformation
OpenThreadToken
RegisterServiceCtrlHandlerExW
StartServiceCtrlDispatcherW
GetSecurityDescriptorDacl
ConvertStringSecurityDescriptorToSecurityDescriptorW
CopySid
SetSecurityDescriptorOwner
SetSecurityDescriptorGroup
LookupAccountSidW
CreateWellKnownSid
OpenProcessToken
SetNamedSecurityInfoW
SetSecurityInfo
kernel32.dll

CloseHandle
SetEvent
GetModuleFileNameW
MultiByteToWideChar
GetLocalTime
LeaveCriticalSection
EnterCriticalSection
GetCurrentThread
FreeLibrary
SizeofResource
lstrcmpiW
FindResourceW
LoadLibraryExW
GetModuleHandleW
ResetEvent
CreateEventW
ExitThread
WaitForSingleObject
CreateThread
WaitForMultipleObjects
CancelWaitableTimer
OpenThread
CreateWaitableTimerW
GetCurrentThreadId
GetCommandLineW
HeapSetInformation
QueueUserWorkItem
SetWaitableTimer
GetSystemTimeAsFileTime
QueueUserAPC
OutputDebugStringW
OutputDebugStringA
UnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
GetCurrentProcessId
GetTickCount
QueryPerformanceCounter
GetModuleHandleA
SetUnhandledExceptionFilter
GetStartupInfoW
InterlockedCompareExchange
Sleep
LocalFree
InterlockedExchange
GetVersionExA
InterlockedDecrement
InterlockedIncrement
DeleteCriticalSection
InitializeCriticalSection
RaiseException
lstrlenW
GetLastError
HeapAlloc
GetProcessHeap
HeapFree
LoadResource
EncodeSystemPointer
GetProcAddress
LoadLibraryW
GetTickCount64
QueryPerformanceFrequency
CreateEventExW
msvcrt.dll
ole32.dll

CoRevertToSelf
CoTaskMemAlloc
CoCreateGuid
CoInitialize
CoInitializeEx
CoUninitialize
CoImpersonateClient
CoSetProxyBlanket
CoInitializeSecurity
StringFromGUID2
CoTaskMemFree
CoRegisterClassObject
CoRevokeClassObject
CoCreateInstance
CoTaskMemRealloc
CoReleaseServerProcess
CoAddRefServerProcess
slc.dll

SLGetWindowsInformationDWORD
user32.dll

TranslateMessage
RegisterDeviceNotificationW
UnregisterDeviceNotification
MsgWaitForMultipleObjectsEx
DispatchMessageW
UnregisterClassA
PeekMessageW
CharNextW
PostThreadMessageW