File details
File name: svchost.exe
Name: Host Process for Windows Services
Description: Microsoft® Windows® Operating System
Version: 6.3.9600.16384 (winblue_rtm.130821-1623)
Product version: 6.3.9600.16384
Size: 36.88 KB
Original file name: svchost.exe.mui
Windows file protection:
Yes
Digital certificate
Certificate authority:
Microsoft Corporation
Expiration date: 6/13/2014
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0002590374%
Privileged CPU:
0.0001438124%

User CPU:
0.00011522501726%

Privileged CPU time: 47427.56 ms
Privileged CPU time /min: 63 ms
CPU cycle count:
400,199,680
CPU cycle count /min: 351,614,694
 | Memory utilization averages |
Committed memory:
281.99 MB
Peak committed memory: 152.28 MB
Paged memory:
20.62 MB
Peak paged memory: 57.69 MB
Paged system memory:
212.98 KB
Non-paged system memory: 32.03 KB
Working set memory:
72.71 MB
Peak working set memory: 110.84 MB
Min working set memory: 25.33 MB
Private memory:
20.62 MB
Page faults:
771,350
Page faults /min: 1,298
 | Process I/O averages |
Total read operations:
16,450
Read operations /min: 30
Total read transfer: 46.44 MB
Read transfer /min: 84.44 KB
Total write operations:
9,708
Write operations /min: 16
Total write transfer: 27.43 MB
Write transfer /min: 44.77 KB
Total other operations:
248,346
Other operations /min: 380
Total other transfer: 16.14 MB
Other Transfer /min: 25.18 KB
Resources
Handle count average: 666
Thread count average: 17
Thread resource averages
sechost.dll

Total CPU: 0.084748732769%
Privileged CPU: 0.038602997994%
User CPU: 0.046145734775%
CPU Cycle count /sec: 2,008,959
Module memory size: 348 KB
dab.dll

Total CPU: 0.021057521722%
Privileged CPU: 0.002987648381%
User CPU: 0.018069873341%
CPU Cycle count /sec: 465,020
Module memory size: 108 KB
ntdll.dll

Total CPU: 0.018658260176%
Privileged CPU: 0.013509322702%
User CPU: 0.005148937474%
CPU Cycle count /sec: 433,893
Context switches /sec: 1
Module memory size: 1.66 MB
combase.dll

Total CPU: 0.011135518838%
Privileged CPU: 0.004307760167%
User CPU: 0.006827758671%
CPU Cycle count /sec: 208,560
Module memory size: 1.84 MB
Total CPU: 0.000972135198%
Privileged CPU: 0.000900125183%
User CPU: 0.000072010015%
CPU Cycle count /sec: 26,773
Module memory size: 392 KB
httpprxm.dll

Total CPU: 0.000899022367%
Privileged CPU: 0.000755178788%
User CPU: 0.000143843579%
CPU Cycle count /sec: 14,112
Module memory size: 128 KB
Total CPU: 0.000755767184%
Privileged CPU: 0.000611811530%
User CPU: 0.000143955655%
CPU Cycle count /sec: 18,109
Module memory size: 264 KB
wevtsvc.dll

Total CPU: 0.000570375198%
Privileged CPU: 0.000229535880%
User CPU: 0.000340839318%
CPU Cycle count /sec: 14,256
Module memory size: 1.61 MB
Total CPU: 0.000538831172%
Privileged CPU: 0.000466987016%
User CPU: 0.000071844156%
CPU Cycle count /sec: 17,244
Module memory size: 868 KB
ssdpapi.dll

Total CPU: 0.000360332655%
Privileged CPU: 0.000324299390%
User CPU: 0.000036033266%
CPU Cycle count /sec: 11,785
Module memory size: 76 KB
Total CPU: 0.000289663872%
Privileged CPU: 0.000181039921%
User CPU: 0.000108623952%
CPU Cycle count /sec: 6,274
Module memory size: 144 KB
taskcomp.dll

Total CPU: 0.000287520488%
Privileged CPU: 0.000035940061%
User CPU: 0.000251580427%
CPU Cycle count /sec: 7,943
Module memory size: 496 KB
Total CPU: 0.000180209174%
Privileged CPU: 0.000090104087%
User CPU: 0.000090105087%
CPU Cycle count /sec: 5,082
Module memory size: 524 KB
msvcrt.dll

Total CPU: 0.000161914489%
Privileged CPU: 0.000161914489%
User CPU: 0.000000000000%
CPU Cycle count /sec: 4,554
Module memory size: 668 KB
fundisc.dll

Total CPU: 0.000143843859%
Privileged CPU: 0.000000000000%
User CPU: 0.000143843859%
CPU Cycle count /sec: 545
Module memory size: 160 KB
rpcss.dll

Total CPU: 0.000109093033%
Privileged CPU: 0.000109093033%
User CPU: 0.000000000000%
CPU Cycle count /sec: 5,637
Module memory size: 756 KB
shcore.dll

Total CPU: 0.000057537197%
Privileged CPU: 0.000021576447%
User CPU: 0.000035960749%
CPU Cycle count /sec: 1,041
Module memory size: 644 KB
Total CPU: 0.000053892641%
Privileged CPU: 0.000017964214%
User CPU: 0.000035928427%
CPU Cycle count /sec: 2,393
Module memory size: 252 KB
Total CPU: 0.000035995920%
Privileged CPU: 0.000035995920%
User CPU: 0.000000000000%
CPU Cycle count /sec: 1,216
Module memory size: 1.3 MB
Total CPU: 0.000035987833%
Privileged CPU: 0.000011994273%
User CPU: 0.000023993560%
CPU Cycle count /sec: 439
Module memory size: 48 KB
Process details
Runs as (owner): Network Service
Integrety level: System
Windows platform: 64-bit
Runs as a service: Yes
Child Processes
Process Commands
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\system32\svchost.exe -k netsvcs
Hosted services
AcfXAudioService
ActiveX Installer (AxInstSV) (AxInstSV)

AeLookupSvc
Akamai
AllUserInstallAgent
AppHostSvc
AppIDSvc

Appinfo

Application Experience (AeLookupSvc)

Application Management (AppMgmt)

AppMgmt
AppReadiness
AppXSvc
ASBroker
ASChannel
AudioEndpointBuilder
AudioSrv
AxInstSV
Background Intelligent Transfer Service (BITS)

Base Filtering Engine (BFE)

BDESVC

BFE
BITS
Bluetooth Support Service (bthserv)

BranchCache (PeerDistSvc)

BrokerInfrastructure
Browser

BsBackup
BsFileScan
BsFire
BsMailProxy
BsMain
bthserv
Certificate Propagation (CertPropSvc)

CertPropSvc
Cryptographic Services (CryptSvc)

CryptSvc
CscService
DCOM Server Process Launcher (DcomLaunch)

DcomLaunch
defragsvc
Desktop Window Manager Session Manager (UxSms)

DeviceAssociationService
DeviceInstall
Dhcp
DHCP Client (Dhcp)

Diagnostic Policy Service (DPS)

Diagnostic Service Host (WdiServiceHost)

Diagnostic System Host (WdiSystemHost)

Distributed Link Tracking Client (TrkWks)

DNS Client (Dnscache)

Dnscache
dot3svc
DPS
drvsvc
DsmSvc
EapHost
ehstart
EMDMgmt
Eventlog
EventSystem

Extensible Authentication Protocol (EapHost)

ezGOSvc
ezSharedSvc
fdPHost

FDResPub
fhsvc
FontCache
ftpsvc
Function Discovery Resource Publication (FDResPub)

FunshionSvr
getPlusHelper
gpsvc

Health Key and Certificate Management (hkmsvc)

HFGService
hidserv
hkmsvc
HomeGroup Listener (HomeGroupListener)

HomeGroup Provider (HomeGroupProvider)

HomeGroupListener
HomeGroupProvider
HPHNDUSVC
hpqcxs08
hpqddsvc
HPSLPSVC
HsfXAudioService
Human Interface Device Access (hidserv)

IKE and AuthIP IPsec Keying Modules (IKEEXT)

IKEEXT
Internet Connection Sharing (ICS) (SharedAccess)

IP Helper (iphlpsvc)

IPBusEnum
iphlpsvc
iprip
IPsec Policy Agent (PolicyAgent)

Irmon
Journal d’événements Windows (eventlog)

KtmRm
KtmRm for Distributed Transaction Coordinator (KtmRm)

LanmanServer
LanmanWorkstation
lfsvc
Link-Layer Topology Discovery Mapper (lltdsvc)

lltdsvc
lmhosts
LPDSVC
LSM
Mcx2Svc
Media Center Extender Service (Mcx2Svc)

MHN
Microsoft iSCSI Initiator Service (MSiSCSI)

Microsoft Software Shadow Copy Provider (swprv)

MMCSS
MpsSvc
MSiSCSI
Multimedia Class Scheduler (MMCSS)

napagent
NcaSvc
NcbService
NcdAutoSetup
necusb
Network connectivity
TCP: localhost on port 135
UDP: LISTENING on port 52629
UDP: LISTENING on port 59280
UDP: LISTENING on port 5355
UDP: LISTENING on port 64831
Image hashes
MD5: e4ca434f251681590d0538bc21c32d2f
SHA-1: 4eea9bdfe0eb41759d96ec9bd224c4519314a8fa
PE image details
Langauge*: Microsoft Visual C++
File entropy: 5.87847
File packed: No
Import Table
advapi32.dll

GetTokenInformation
InitializeSecurityDescriptor
SetSecurityDescriptorOwner
SetSecurityDescriptorGroup
SetEntriesInAclW
SetSecurityDescriptorDacl
StartServiceCtrlDispatcherW
RegDisablePredefinedCacheEx
EventRegister
EventEnabled
EventWrite
RegQueryValueExW
RegOpenKeyExW
RegCloseKey
RegisterServiceCtrlHandlerW
SetServiceStatus
OpenProcessToken
api-ms-win-core-crt-l1-1-0.dll

memcmp
memcpy
_except_handler4_common
api-ms-win-core-crt-l2-1-0.dll

exit
_initterm
_initterm_e
__wgetmainargs
api-ms-win-core-delayload-l1-1-1.dll

ResolveDelayLoadedAPI
DelayLoadFailureHook
api-ms-win-core-errorhandling-l1-1-0.dll

SetErrorMode
GetLastError
SetUnhandledExceptionFilter
UnhandledExceptionFilter
api-ms-win-core-errorhandling-l1-1-1.dll

GetLastError
SetErrorMode
UnhandledExceptionFilter
SetUnhandledExceptionFilter
api-ms-win-core-handle-l1-1-0.dll

api-ms-win-core-heap-l1-1-0.dll

HeapAlloc
GetProcessHeap
HeapSetInformation
HeapFree
api-ms-win-core-heap-l1-2-0.dll

GetProcessHeap
HeapAlloc
HeapSetInformation
HeapFree
api-ms-win-core-heap-obsolete-l1-1-0.dll

api-ms-win-core-libraryloader-l1-1-1.dll

LoadLibraryExW
GetProcAddress
FreeLibrary
api-ms-win-core-localization-l1-1-1.dll

api-ms-win-core-localization-l1-2-0.dll

api-ms-win-core-localization-l1-2-1.dll

api-ms-win-core-processenvironment-l1-1-0.dll

ExpandEnvironmentStringsW
GetCommandLineW
api-ms-win-core-processenvironment-l1-1-1.dll

ExpandEnvironmentStringsW
GetCommandLineW
api-ms-win-core-processenvironment-l1-2-0.dll

ExpandEnvironmentStringsW
GetCommandLineW
api-ms-win-core-processthreads-l1-1-0.dll

TerminateProcess
GetCurrentProcess
OpenProcessToken
GetCurrentProcessId
GetCurrentThreadId
api-ms-win-core-processthreads-l1-1-1.dll

ExitProcess
SetProcessAffinityUpdateMode
OpenProcessToken
TerminateProcess
GetCurrentThreadId
GetCurrentProcess
GetCurrentProcessId
IsProcessorFeaturePresent
api-ms-win-core-processthreads-l1-1-2.dll

SetProcessAffinityUpdateMode
OpenProcessToken
GetCurrentThreadId
ExitProcess
GetCurrentProcess
TerminateProcess
GetCurrentProcessId
api-ms-win-core-profile-l1-1-0.dll

api-ms-win-core-registry-l1-1-0.dll

RegOpenKeyExW
RegQueryValueExW
RegDisablePredefinedCacheEx
RegCloseKey
api-ms-win-core-sidebyside-l1-1-0.dll

DeactivateActCtx
ReleaseActCtx
ActivateActCtx
CreateActCtxW
api-ms-win-core-string-l1-1-0.dll

CompareStringW
WideCharToMultiByte
api-ms-win-core-string-obsolete-l1-1-0.dll

lstrcmpiW
lstrlenW
lstrcmpW
api-ms-win-core-synch-l1-1-1.dll

InitializeSRWLock
AcquireSRWLockShared
EnterCriticalSection
LeaveCriticalSection
ReleaseSRWLockShared
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
InitializeCriticalSection
api-ms-win-core-synch-l1-2-0.dll

AcquireSRWLockShared
InitializeSRWLock
AcquireSRWLockExclusive
EnterCriticalSection
LeaveCriticalSection
ReleaseSRWLockExclusive
ReleaseSRWLockShared
api-ms-win-core-sysinfo-l1-1-1.dll

GetSystemTimeAsFileTime
GetTickCount
api-ms-win-core-sysinfo-l1-2-0.dll

GetSystemTimeAsFileTime
GetTickCount
api-ms-win-core-sysinfo-l1-2-1.dll

GetSystemTimeAsFileTime
GetTickCount
api-ms-win-core-threadpool-l1-1-1.dll

RegisterWaitForSingleObjectEx
api-ms-win-core-threadpool-private-l1-1-0.dll

RegisterWaitForSingleObjectEx
api-ms-win-obsolete-kernelbase-l1-1-0.dll

lstrcmpW
lstrlenW
LocalAlloc
lstrcmpiW
LocalFree
api-ms-win-security-base-l1-1-0.dll

SetSecurityDescriptorDacl
AddAccessAllowedAce
SetSecurityDescriptorOwner
SetSecurityDescriptorGroup
GetTokenInformation
InitializeSecurityDescriptor
GetLengthSid
InitializeAcl
api-ms-win-security-base-l1-2-0.dll

GetLengthSid
InitializeAcl
InitializeSecurityDescriptor
GetTokenInformation
SetSecurityDescriptorGroup
SetSecurityDescriptorOwner
AddAccessAllowedAce
SetSecurityDescriptorDacl
api-ms-win-service-core-l1-1-0.dll

StartServiceCtrlDispatcherW
SetServiceStatus
api-ms-win-service-core-l1-1-1.dll

SetServiceStatus
StartServiceCtrlDispatcherW
api-ms-win-service-winsvc-l1-1-0.dll

RegisterServiceCtrlHandlerW
api-ms-win-service-winsvc-l1-2-0.dll

RegisterServiceCtrlHandlerW
kernel32.dll

LocalAlloc
CloseHandle
DelayLoadFailureHook
GetProcAddress
GetLastError
FreeLibrary
InterlockedCompareExchange
LoadLibraryExA
InterlockedExchange
Sleep
SetUnhandledExceptionFilter
GetModuleHandleA
QueryPerformanceCounter
GetTickCount
GetSystemTimeAsFileTime
UnhandledExceptionFilter
DeactivateActCtx
LoadLibraryExW
ActivateActCtx
LeaveCriticalSection
lstrcmpW
EnterCriticalSection
RegCloseKey
RegOpenKeyExW
HeapSetInformation
lstrcmpiW
lstrlenW
LCMapStringW
RegQueryValueExW
ReleaseActCtx
CreateActCtxW
ExpandEnvironmentStringsW
GetCommandLineW
ExitProcess
SetProcessAffinityUpdateMode
RegDisablePredefinedCacheEx
InitializeCriticalSection
GetProcessHeap
SetErrorMode
RegisterWaitForSingleObjectEx
LocalFree
HeapFree
WideCharToMultiByte
HeapAlloc
GetCurrentThreadId
GetCurrentProcessId
TerminateProcess
GetCurrentProcess
RegisterWaitForSingleObject
LoadLibraryA
msvcrt.dll
ntdll.dll

RtlAllocateHeap
RtlLengthRequiredSid
RtlSubAuthoritySid
RtlInitializeSid
RtlCopySid
RtlSubAuthorityCountSid
RtlInitializeCriticalSection
RtlSetProcessIsCritical
RtlImageNtHeader
RtlUnhandledExceptionFilter
EtwEventWrite
EtwEventEnabled
EtwEventRegister
RtlFreeHeap
NtSetInformationProcess
rpcrt4.dll

RpcMgmtSetServerStackSize
I_RpcMapWin32Status
RpcServerUnregisterIf
RpcMgmtWaitServerListen
RpcMgmtStopServerListening
RpcServerUnregisterIfEx
RpcServerRegisterIf
RpcServerUseProtseqEpW
RpcServerListen
I_RpcServerDisableExceptionFilter