File details
File name: ehsched.exe
Name: Windows Media Center Scheduler Service
Description: Microsoft® Windows® Operating System
Version: 6.1.7600.16385 (win7_rtm.090713-1255)
Product version: 6.1.7600.16385
Size: 92.5 KB
Original file name: ehSched.exe.mui
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0160315644%
Privileged CPU:
0.0129085324%

User CPU:
0.00312303202332%

Privileged CPU time: 62.4 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
219,287,101
 | Memory utilization averages |
Committed memory:
33.13 MB
Peak committed memory: 33.38 MB
Paged memory:
992 KB
Peak paged memory: 1008 KB
Paged system memory:
66.99 KB
Non-paged system memory: 3.91 KB
Working set memory:
3.65 MB
Peak working set memory: 3.68 MB
Min working set memory: 3.64 MB
Private memory:
992 KB
Page faults:
1,085
Page faults /min: 0
 | Process I/O averages |
Total read operations:
1
Total read transfer: 71.39 KB
Total other operations:
406
Total other transfer: 1.04 KB
Resources
Handle count average: 113
Thread count average: 7
Thread resource averages
sechost.dll

Total CPU: 0.005630547974%
Privileged CPU: 0.002815273987%
User CPU: 0.002815273987%
CPU Cycle count /sec: 137,811
Module memory size: 100 KB
Total CPU: 0.002815065642%
Privileged CPU: 0.002815065642%
User CPU: 0.000000000000%
CPU Cycle count /sec: 128,669
Module memory size: 104 KB
Process details
Runs as (owner): Network Service
Integrety level: System
Windows platform: 32-bit
Runs as a service: Yes
Parent Process
Process Command
C:\Windows\ehome\ehsched.exe
Service details
Name: Υπηρεσία χρονοδιαγράμματος Windows Media Center
Service name: ehSched
Service type:
Win32OwnProcess
Description: “Ξεκινά και σταματά την εγγραφή τηλεοπτικών προγραμμάτων στο Windows Media Center”
Image hashes
MD5: d389bff34f80caede417bf9d1507996a
SHA-1: 2cca2fc2e326c652588733a5cde76fc24ea298e8
SHA-256: 12859b9925d7a4631de61a820922f43f56ed23c2af014cbf36322685e5cf641e
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File entropy: 6.17789
File packed: No
Import Table
advapi32.dll

CloseServiceHandle
OpenServiceW
OpenSCManagerW
DeleteService
ControlService
DeregisterEventSource
ReportEventW
RegisterEventSourceW
SetServiceStatus
RegDeleteKeyW
RegDeleteValueW
RegCloseKey
RegCreateKeyExW
RegOpenKeyExW
RegQueryValueExW
RegSetValueExW
RegQueryInfoKeyW
AddAce
GetAce
GetAclInformation
AddAccessAllowedAce
InitializeAcl
GetLengthSid
IsValidSid
ChangeServiceConfig2W
CreateServiceW
RegEnumKeyExW
InitializeSecurityDescriptor
SetSecurityDescriptorDacl
LookupAccountNameW
RegGetValueW
GetTokenInformation
OpenThreadToken
RegisterServiceCtrlHandlerExW
StartServiceCtrlDispatcherW
GetSecurityDescriptorDacl
ConvertStringSecurityDescriptorToSecurityDescriptorW
CopySid
SetSecurityDescriptorOwner
SetSecurityDescriptorGroup
LookupAccountSidW
CreateWellKnownSid
OpenProcessToken
SetNamedSecurityInfoW
SetSecurityInfo
kernel32.dll

CloseHandle
SetEvent
GetModuleFileNameW
MultiByteToWideChar
GetLocalTime
LeaveCriticalSection
EnterCriticalSection
GetCurrentThread
FreeLibrary
SizeofResource
lstrcmpiW
FindResourceW
LoadLibraryExW
GetModuleHandleW
ResetEvent
CreateEventW
ExitThread
WaitForSingleObject
CreateThread
WaitForMultipleObjects
CancelWaitableTimer
OpenThread
CreateWaitableTimerW
GetCurrentThreadId
GetCommandLineW
HeapSetInformation
QueueUserWorkItem
SetWaitableTimer
GetSystemTimeAsFileTime
QueueUserAPC
OutputDebugStringW
OutputDebugStringA
UnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
GetCurrentProcessId
GetTickCount
QueryPerformanceCounter
GetModuleHandleA
SetUnhandledExceptionFilter
GetStartupInfoW
InterlockedCompareExchange
Sleep
LocalFree
InterlockedExchange
GetVersionExA
InterlockedDecrement
InterlockedIncrement
DeleteCriticalSection
InitializeCriticalSection
RaiseException
lstrlenW
GetLastError
HeapAlloc
GetProcessHeap
HeapFree
LoadResource
EncodeSystemPointer
GetProcAddress
LoadLibraryW
GetTickCount64
QueryPerformanceFrequency
CreateEventExW
msvcrt.dll
ole32.dll

CoRevertToSelf
CoTaskMemAlloc
CoCreateGuid
CoInitialize
CoInitializeEx
CoUninitialize
CoImpersonateClient
CoSetProxyBlanket
CoInitializeSecurity
StringFromGUID2
CoTaskMemFree
CoRegisterClassObject
CoRevokeClassObject
CoCreateInstance
CoTaskMemRealloc
CoReleaseServerProcess
CoAddRefServerProcess
slc.dll

SLGetWindowsInformationDWORD
user32.dll

TranslateMessage
RegisterDeviceNotificationW
UnregisterDeviceNotification
MsgWaitForMultipleObjectsEx
DispatchMessageW
UnregisterClassA
PeekMessageW
CharNextW
PostThreadMessageW