File details
File name: ui0detect.exe
Name: Interactive services detection
Description: Microsoft® Windows® Operating System
Version: 6.1.7600.16385 (win7_rtm.090713-1255)
Product version: 6.1.7600.16385
Size: 35 KB
Original file name: UI0Detect.exe.mui
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0490358162%
Privileged CPU:
0.0291430227%

User CPU:
0.01989279351267%

Privileged CPU time: 66022.07 ms
Privileged CPU time /min: 1 ms
CPU cycle count:
424,420,110
CPU cycle count /min: 23,206,537
Context switches /sec:
4
 | Memory utilization averages |
Committed memory:
78.03 MB
Peak committed memory: 78.51 MB
Paged memory:
1.78 MB
Peak paged memory: 1.81 MB
Paged system memory:
124.44 KB
Non-paged system memory: 4.49 KB
Working set memory:
4.12 MB
Peak working set memory: 5.46 MB
Min working set memory: 4.03 MB
Private memory:
1.78 MB
Page faults:
2,113
Page faults /min: 131
 | Process I/O averages |
Total read operations:
2
Read operations /min: 1
Total read transfer: 601 Bytes
Read transfer /min: 6 Bytes
Total other operations:
391
Other operations /min: 11
Total other transfer: 3.29 KB
Other Transfer /min: 25 Bytes
 | GUI Object Averages |
GDI objects:
75
Peak GDI objects: 81
USER objects:
34
Peak USER objects: 39
Resources
Handle count average: 92
Thread count average: 5
Thread resource averages
sechost.dll

Total CPU: 0.030571036183%
Privileged CPU: 0.011833539087%
User CPU: 0.018737497096%
CPU Cycle count /sec: 672,703
Context switches /sec: 1
Module memory size: 100 KB
Total CPU: 0.028722156393%
Privileged CPU: 0.023004062646%
User CPU: 0.005718093747%
CPU Cycle count /sec: 939,031
Context switches /sec: 5
Module memory size: 48 KB
Process details
Runs as (owner): System
Integrety level: System
Windows platform: 32-bit
Runs as a service: Yes
Parent Processes
Child Process
Process Commands
C:\Windows\system32\UI0Detect.exe
C:\Windows\System32\UI0Detect.exe
UI0Detect.exe 220
Service details
Name: Wykrywanie usług interakcyjnych
Service name: UI0Detect
Service type: Win32OwnProcess, InteractiveProcess
Description: “Włącza powiadamianie użytkownika o danych wprowadzonych przez użytkownika do usług interakcyjnych, które umożliwia dostęp do okien dialogowych utworzonych przez usługi interakcyjne w momencie ich pojawienia się. Jeśli ta usługa zostanie zatrzymana, powiadomienia o nowych oknach dialogowych usług interakcyjnych nie będą działały i nie będzie można uzyskać dostępu do tych okien. Jeśli ta usługa zost”
Image hashes
MD5: 8344fd4fce927880aa1aa7681d4927e5
SHA-1: 4c0d16bd7c0c13d4d279dcfd3a7bc8b790da35f7
SHA-256: 1b54efa60a221e2b9ffe59bb41c7e7d8b5ac6826f1c5577456d81371d464255a
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File entropy: 5.94408
File packed: No
Import Table
advapi32.dll

CheckTokenMembership
SetServiceStatus
ReportEventW
RegisterEventSourceW
DeregisterEventSource
RegisterServiceCtrlHandlerW
StartServiceCtrlDispatcherW
RevertToSelf
CreateProcessAsUserW
ImpersonateLoggedOnUser
gdi32.dll

kernel32.dll

CloseHandle
UnmapViewOfFile
DuplicateHandle
GetCurrentProcess
MapViewOfFile
CreateFileMappingW
GetProcessHeap
HeapFree
lstrcmpW
K32GetModuleBaseNameW
K32GetModuleInformation
GetLastError
K32EnumProcessModules
CompareStringW
lstrlenW
CompareFileTime
GetSystemTimeAsFileTime
K32GetModuleFileNameExW
OpenProcess
GetCurrentProcessId
SetLastError
GetTickCount
HeapSetInformation
GetCurrentThreadId
LocalFree
FormatMessageW
GetModuleHandleW
CreateEventW
DelayLoadFailureHook
GetProcAddress
FreeLibrary
InterlockedCompareExchange
LoadLibraryExA
Sleep
HeapAlloc
TerminateProcess
QueryPerformanceCounter
GetModuleHandleA
SetUnhandledExceptionFilter
GetStartupInfoA
InterlockedExchange
UnhandledExceptionFilter
LoadLibraryA
msvcrt.dll
ntdll.dll

WinSqmIsOptedIn
WinSqmSetDWORD
WinSqmEndSession
WinSqmStartSession
WinSqmSetString
WinSqmAddToAverageDWORD
WinSqmAddToStream
WinSqmIncrementDWORD
RtlAllocateAndInitializeSid
RtlFreeSid
WinSqmEventEnabled
WinSqmEventWrite
psapi.dll

GetModuleBaseNameW
EnumProcessModules
GetModuleFileNameExW
GetModuleInformation
shell32.dll

user32.dll

EnumWindows
RegisterShellHookWindow
SetWindowLongW
RegisterWindowMessageW
PostQuitMessage
IsWindow
DestroyWindow
DefWindowProcW
SetTimer
GetLastInputInfo
MoveWindow
GetSystemMetrics
KillTimer
SetShellWindow
SystemParametersInfoW
ShowWindow
GetWindowTextW
RegisterClassW
GetWindow
UnregisterClassW
DispatchMessageW
GetMessageW
GetUserObjectInformationW
GetThreadDesktop
GetProcessWindowStation
LoadStringW
FlashWindowEx
DestroyIcon
LoadIconW
GetWindowRect
FindWindowW
SendMessageW
GetWindowLongW
GetClassLongW
PostMessageW
GetWindowThreadProcessId
GetWindowInfo
GetClassNameW
LoadCursorW
GetWindowTextLengthW
SetTaskmanWindow
CreateWindowExW
version.dll

GetFileVersionInfoW
GetFileVersionInfoSizeW
VerQueryValueW
winsta.dll

WinStationGetSessionIds
WinStationRevertFromServicesSession
WinStationSwitchToServicesSession
wtsapi32.dll

WTSUnRegisterSessionNotification
WTSRegisterSessionNotification
WTSDisconnectSession
WTSQueryUserToken