File details
File name: defrag.exe
Name: Windows Disk Defragmenter
Description: Disk Defragmenter Module
Version: 6.1.7600.16385 (win7_rtm.090713-1255)
Product version: 6.1.7600.16385
Size: 172 KB
Original file name: Defrag.EXE.MUI
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0077621211%
Privileged CPU:
0.0034403059%

User CPU:
0.00432181524927%

Privileged CPU time: 15.6 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
147,239,695
CPU cycle count /min: 306,855
Context switches /sec:
1
 | Memory utilization averages |
Committed memory:
20.36 MB
Peak committed memory: 20.77 MB
Paged memory:
985.33 KB
Peak paged memory: 1020 KB
Paged system memory:
33.64 KB
Non-paged system memory: 3.47 KB
Working set memory:
2.74 MB
Peak working set memory: 3.52 MB
Min working set memory: 2.74 MB
Private memory:
985.33 KB
Page faults:
1,046
Page faults /min: 2
Resources
Handle count average: 81
Thread count average: 5
Thread resource averages
Total CPU: 0.015320142199%
Privileged CPU: 0.006053376233%
User CPU: 0.009266765966%
CPU Cycle count /sec: 239,500
Module memory size: 184 KB
Process details
Runs as (owner): System
Integrety level: System
Windows platform: 32-bit
Runs as a service: Yes
Parent Processes
Process Commands
"C:\Windows\system32\defrag.exe" -p 3c0 -s 0000098C -b C:
C:\Windows\system32\defrag.exe -c
"C:\Windows\system32\defrag.exe" -p 3f8 -s 000007F0 -b C:
C: /a /v
Scheduled task details
Name: ManualDefrag
Command: \Microsoft\Windows\Defrag\ManualDefrag
Image hashes
MD5: 9e759edde1e45a4e55752cd2ed321f89
SHA-1: 380e867c6625aeed69b5c86ed42ed9e98b9c23b3
SHA-256: 364c98de9b220fc3d2e26a48296359c71df1b3774eb9153e964f6486037c5b98
PE image details
Subsystem: Windows Console
Langauge*: Microsoft Visual C++
File entropy: 7.28274
File packed: No
Import Table
advapi32.dll

FreeSid
CheckTokenMembership
AllocateAndInitializeSid
RegCloseKey
RegQueryValueExW
RegOpenKeyExW
RegSetValueExW
RegCreateKeyExW
DeregisterEventSource
ReportEventW
RegisterEventSourceW
SetSecurityDescriptorDacl
SetEntriesInAclW
InitializeSecurityDescriptor
GetSecurityDescriptorDacl
RegDeleteKeyValueW
CreateWellKnownSid
DuplicateToken
GetTokenInformation
OpenProcessToken
TraceMessage
GetTraceEnableFlags
GetTraceEnableLevel
GetTraceLoggerHandle
RegisterTraceGuidsW
UnregisterTraceGuids
ConvertStringSecurityDescriptorToSecurityDescriptorW
CloseTrace
StartTraceW
EnableTrace
ControlTraceW
kernel32.dll

GetLastError
GlobalLock
GlobalFree
GlobalReAlloc
GlobalUnlock
GlobalSize
GlobalAlloc
HeapFree
GetProcessHeap
HeapAlloc
SetLastError
InterlockedIncrement
InterlockedDecrement
EnterCriticalSection
LeaveCriticalSection
Sleep
InitializeCriticalSectionAndSpinCount
DeleteCriticalSection
CloseHandle
WriteFile
GetFileSize
CreateFileW
ReleaseMutex
FormatMessageW
GetCurrentThreadId
lstrlenW
GetTimeFormatW
GetDateFormatW
WaitForSingleObject
ExpandEnvironmentStringsW
LoadLibraryW
OutputDebugStringA
IsDebuggerPresent
SetFilePointer
GetLocalTime
WideCharToMultiByte
LocalFree
SetErrorMode
DeleteFileW
GetDiskFreeSpaceExW
GetTempFileNameW
GetVolumeInformationW
DeviceIoControl
GetDriveTypeW
GetConsoleOutputCP
WriteConsoleW
GetConsoleMode
GetFileType
GetStdHandle
VerifyVersionInfoW
VerSetConditionMask
GetCurrentProcess
ReleaseSemaphore
SetEvent
SetThreadUILanguage
CreateSemaphoreW
WaitForMultipleObjects
SetConsoleCtrlHandler
ResetEvent
CreateEventW
GetVolumePathNamesForVolumeNameW
GetVolumeNameForVolumeMountPointW
DuplicateHandle
OpenProcess
FreeLibrary
HeapSetInformation
UnhandledExceptionFilter
TerminateProcess
GetSystemTimeAsFileTime
GetCurrentProcessId
GetTickCount
QueryPerformanceCounter
GetModuleHandleA
SetUnhandledExceptionFilter
InterlockedCompareExchange
InterlockedExchange
LoadLibraryExW
GetVolumePathNameW
MoveFileExW
FindFirstFileW
FindNextFileW
FindClose
CreateDirectoryW
GetFileAttributesW
InitializeCriticalSection
CreateThread
InterlockedPopEntrySList
InitializeSListHead
RtlCaptureStackBackTrace
InterlockedPushEntrySList
GetModuleHandleW
msvcrt.dll
ntdll.dll

NtWaitForSingleObject
NtFsControlFile
NtQueryVolumeInformationFile
RtlAllocateHeap
RtlFreeHeap
EtwTraceMessage
RtlNtStatusToDosError
RtlGetLastNtStatus
RtlSetThreadErrorMode
ole32.dll

CoCreateInstanceEx
CoInitializeEx
CoRegisterClassObject
ReleaseStgMedium
CoCreateGuid
CoTaskMemFree
CoTaskMemAlloc
StringFromCLSID
CoUninitialize
CoCreateInstance
CoDisconnectObject
sxshared.dll

SxTracerGetThreadContextRetail
SxTracerDebuggerBreak
SxTracerShouldTrackFailure
user32.dll

virtdisk.dll

GetStorageDependencyInformation