File details
File name: ehrecvr.exe
Name: Windows Media Center Receiver Service
Description: Microsoft® Windows® Operating System
Version: 6.1.7600.16385 (win7_rtm.090713-1255)
Product version: 6.1.7600.16385
Size: 680.5 KB
Original file name: ehRecvr.exe.mui
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0511348899%
Privileged CPU:
0.0507990363%

User CPU:
0.00033585364824%

Privileged CPU time: 166839.6 ms
Privileged CPU time /min: 817 ms
CPU cycle count:
223,204,899
CPU cycle count /min: 135,868,178
Context switches /sec:
22
 | Memory utilization averages |
Committed memory:
115.89 MB
Peak committed memory: 120.86 MB
Paged memory:
19.09 MB
Peak paged memory: 19.47 MB
Paged system memory:
191.28 KB
Non-paged system memory: 21.52 KB
Working set memory:
13.35 MB
Peak working set memory: 18.29 MB
Min working set memory: 11.38 MB
Private memory:
19.09 MB
Page faults:
9,343
Page faults /min: 53
 | Process I/O averages |
Total read operations:
324
Read operations /min: 3
Total read transfer: 5.31 MB
Read transfer /min: 26.06 KB
Total write operations:
12,132
Write operations /min: 3
Total write transfer: 60.12 MB
Write transfer /min: 132.04 KB
Total other operations:
20,152
Other operations /min: 83
Total other transfer: 697.75 KB
Other Transfer /min: 2.43 KB
Resources
Handle count average: 363
Thread count average: 23
Thread resource averages
ehglid.dll

Total CPU: 0.019122461086%
Privileged CPU: 0.015856668060%
User CPU: 0.003265793026%
CPU Cycle count /sec: 580,798
Module memory size: 764 KB
ntdll.dll

Total CPU: 0.016682485269%
Privileged CPU: 0.008341242634%
User CPU: 0.008341242634%
CPU Cycle count /sec: 314,456
Module memory size: 1.66 MB
psisdecd.dll

Total CPU: 0.013173500835%
Privileged CPU: 0.005641283850%
User CPU: 0.007532216984%
CPU Cycle count /sec: 350,014
Context switches /sec: 3
Module memory size: 616 KB
ksproxy.ax

Total CPU: 0.013029149595%
Privileged CPU: 0.004806484135%
User CPU: 0.008222665460%
CPU Cycle count /sec: 343,631
Context switches /sec: 1
Module memory size: 260 KB
psisrndr.ax

Total CPU: 0.004264466834%
Privileged CPU: 0.001116839499%
User CPU: 0.003147627335%
CPU Cycle count /sec: 110,908
Context switches /sec: 2
Module memory size: 120 KB
Total CPU: 0.002646910344%
Privileged CPU: 0.002208571961%
User CPU: 0.000438338383%
CPU Cycle count /sec: 84,306
Module memory size: 696 KB
Total CPU: 0.002181246461%
Privileged CPU: 0.000856216636%
User CPU: 0.001325029825%
CPU Cycle count /sec: 47,619
Module memory size: 3.5 MB
msnp.ax

Total CPU: 0.000722923286%
Privileged CPU: 0.000130008076%
User CPU: 0.000592915209%
CPU Cycle count /sec: 18,022
Module memory size: 296 KB
sechost.dll

Total CPU: 0.000380096114%
Privileged CPU: 0.000221605782%
User CPU: 0.000158490333%
CPU Cycle count /sec: 8,258
Module memory size: 124 KB
itvdata.dll

Total CPU: 0.000291531923%
Privileged CPU: 0.000000000000%
User CPU: 0.000291531923%
CPU Cycle count /sec: 10,529
Module memory size: 300 KB
quartz.dll

Total CPU: 0.000114247890%
Privileged CPU: 0.000114247890%
User CPU: 0.000000000000%
CPU Cycle count /sec: 137
Module memory size: 1.7 MB
msdri.dll

Total CPU: 0.000088537412%
Privileged CPU: 0.000048587745%
User CPU: 0.000039949667%
CPU Cycle count /sec: 409
Module memory size: 556 KB
sbe.dll

Total CPU: 0.000073875872%
Privileged CPU: 0.000052865418%
User CPU: 0.000021010454%
CPU Cycle count /sec: 117,219
Context switches /sec: 3
Module memory size: 1.08 MB
ehtrace.dll

Total CPU: 0.000005661578%
Privileged CPU: 0.000005661578%
User CPU: 0.000000000000%
CPU Cycle count /sec: 168
Module memory size: 200 KB
Process details
Runs as (owner): Network Service
Integrety level: System
Windows platform: 64-bit
Runs as a service: Yes
Parent Process
Process Command
C:\Windows\ehome\ehRecvr.exe
Service details
Name: Servicio Receptor de Windows Media Center
Service name: ehRecvr
Service type:
Win32OwnProcess
Description: “Servicio de Windows Media Center para la recepción de difusión de TV y FM.”
Image hashes
MD5: c4002b6b41975f057d98c439030cea07
SHA-1: 2ac6028981e07f7a6406da87b8158e17627da2a0
SHA-256: 3d2484fbb832efb90504dd406ed1cf3065139b1fe1646471811f3a5679ef75f1
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File entropy: 5.71523
File packed: No
Import Table
advapi32.dll

SetServiceStatus
RegCloseKey
RegOpenKeyExW
RegQueryValueExW
AddAce
GetAce
GetAclInformation
DeregisterEventSource
RegisterEventSourceW
ReportEventW
InitializeSecurityDescriptor
LookupAccountNameW
AddAccessAllowedAce
InitializeAcl
GetLengthSid
RegDeleteValueW
SetSecurityDescriptorDacl
RegisterServiceCtrlHandlerExW
StartServiceCtrlDispatcherW
RegSetValueExW
RegGetValueW
RegCreateKeyExW
CreateWellKnownSid
RegQueryInfoKeyW
RegEnumValueW
RegEnumKeyW
SetNamedSecurityInfoW
SetEntriesInAclW
GetNamedSecurityInfoW
LookupAccountSidW
GetTokenInformation
SetSecurityDescriptorGroup
SetSecurityDescriptorOwner
IsValidSid
CopySid
GetSecurityDescriptorDacl
OpenProcessToken
CloseServiceHandle
OpenServiceW
OpenSCManagerW
DeleteService
ControlService
RegEnumKeyExW
ChangeServiceConfig2W
CreateServiceW
RegDeleteKeyW
FreeSid
CheckTokenMembership
AllocateAndInitializeSid
SetSecurityInfo
ConvertStringSecurityDescriptorToSecurityDescriptorW
ehtrace.dll

ehAllocateEventBuffer
ehFreeEventBuffer
ehUnregisterTraceGUIDs
ehTraceEvent
ehRegisterTraceGUIDs
faultrep.dll

kernel32.dll

CreateEventW
SetPriorityClass
GetCurrentProcess
GetProfileIntW
GetCommandLineW
SetUnhandledExceptionFilter
HeapSetInformation
lstrlenW
EnterCriticalSection
LeaveCriticalSection
GetLocaleInfoW
GetUserDefaultUILanguage
GetTickCount
GetCurrentThreadId
GetSystemTimeAsFileTime
SleepEx
QueueUserAPC
GetCurrentThread
DuplicateHandle
GetCurrentProcessId
HeapReAlloc
CancelWaitableTimer
CreateWaitableTimerW
CreateThread
SetWaitableTimer
GetProcAddress
FreeLibrary
LoadLibraryExW
WaitForMultipleObjectsEx
WaitForMultipleObjects
WaitForSingleObject
ResetEvent
FindNextFileW
DeleteFileW
SetFileAttributesW
FindFirstFileW
GetFileAttributesW
ExitThread
LoadLibraryW
ExpandEnvironmentStringsW
LocalFree
OpenThread
GetProcessHeap
HeapAlloc
GetLastError
GetVersionExW
VirtualProtect
VirtualAlloc
GetSystemInfo
VirtualQuery
InterlockedExchange
InterlockedCompareExchange
GetStartupInfoW
GetModuleHandleA
InitializeCriticalSection
QueryPerformanceCounter
TerminateProcess
UnhandledExceptionFilter
OutputDebugStringW
GetLocalTime
EncodeSystemPointer
DecodeSystemPointer
GetTempPathW
MoveFileExW
OutputDebugStringA
Sleep
MultiByteToWideChar
SetEvent
CloseHandle
InterlockedDecrement
InterlockedIncrement
FindClose
DeleteCriticalSection
HeapFree
GetModuleHandleW
lstrcmpiW
GetModuleFileNameW
SizeofResource
LoadResource
FindResourceW
GetTickCount64
LocalAlloc
K32GetModuleBaseNameW
CreateDirectoryW
GetExitCodeThread
SystemTimeToTzSpecificLocalTime
FileTimeToSystemTime
lstrlenA
SetThreadExecutionState
GetVersionExA
RaiseException
msvcrt.dll
ole32.dll

CoTaskMemAlloc
CoCreateInstance
CoFreeUnusedLibrariesEx
CoWaitForMultipleHandles
CoCreateGuid
StringFromCLSID
StringFromGUID2
CoInitializeSecurity
CoTaskMemFree
CLSIDFromString
CoInitialize
CoDisconnectObject
CoInitializeEx
CoUninitialize
CoImpersonateClient
CoRevertToSelf
CoSuspendClassObjects
CoRegisterClassObject
CoRevokeClassObject
CoTaskMemRealloc
psapi.dll

shell32.dll

SHGetKnownFolderPath
SHSetLocalizedName
SHCreateDirectoryExW
shlwapi.dll

slc.dll

SLGetWindowsInformationDWORD
user32.dll

TranslateMessage
SetTimer
PostThreadMessageW
KillTimer
RegisterDeviceNotificationW
MsgWaitForMultipleObjectsEx
DispatchMessageW
PeekMessageW
LoadStringW
GetMessageW
UnregisterDeviceNotification
CharNextW
UnregisterClassA
version.dll

GetFileVersionInfoW
GetFileVersionInfoSizeW
VerQueryValueA
Export Table