File details
File name: vds.exe
Name: Virtual Disk Service
Description: Microsoft® Windows® Operating System
Version: 6.1.7600.16385 (win7_rtm.090713-1255)
Product version: 6.1.7600.16385
Size: 443 KB
Original file name: vds.exe.mui
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0054098555%
Privileged CPU:
0.0032826488%

User CPU:
0.00212720675211%

Privileged CPU time: 561662.88 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
353,596,950
CPU cycle count /min: 1,371,163
Context switches /sec:
1
 | Memory utilization averages |
Committed memory:
38.77 MB
Peak committed memory: 39.95 MB
Paged memory:
1.96 MB
Peak paged memory: 2.02 MB
Paged system memory:
73.87 KB
Non-paged system memory: 7.44 KB
Working set memory:
2.96 MB
Peak working set memory: 5.99 MB
Min working set memory: 2.81 MB
Private memory:
1.96 MB
Page faults:
4,658
Page faults /min: 6
 | Process I/O averages |
Total read operations:
1
Total read transfer: 11.33 KB
Total other operations:
983
Other operations /min: 2
Total other transfer: 8.22 KB
Other Transfer /min: 39 Bytes
Resources
Handle count average: 131
Thread count average: 9
Thread resource averages
sechost.dll

Total CPU: 0.005144979403%
Privileged CPU: 0.002152902527%
User CPU: 0.002992076875%
CPU Cycle count /sec: 149,946
Module memory size: 100 KB
Total CPU: 0.004274082083%
Privileged CPU: 0.003983948870%
User CPU: 0.000290133212%
CPU Cycle count /sec: 99,603
Module memory size: 452 KB
vdsutil.dll

Total CPU: 0.002863280260%
Privileged CPU: 0.000000000000%
User CPU: 0.002863280260%
CPU Cycle count /sec: 30,754
Module memory size: 160 KB
Process details
Runs as (owner): System
Integrety level: System
Windows platform: 32-bit
Runs as a service: Yes
Parent Process
Process Commands
C:\Windows\System32\vds.exe
C:\windows\System32\vds.exe
Service details
Name: Disque virtuel
Service name: vds
Service type:
Win32OwnProcess
Description: “Fournit des services de gestion des disques, des volumes, des systèmes de fichiers et des groupes de stockage.”
Image hashes
MD5: c3cd30495687c2a2f66a65ca6fd89be9
SHA-1: 51b15a8587a70db5f1dacf1a4ed77fbd98df881e
SHA-256: 582e4706c1d6a151020d14b26c7bf166f4e42bdd6e410f30ec452469270c5e9b
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File entropy: 6.40737
File packed: No
Import Table
advapi32.dll

SetServiceStatus
CloseServiceHandle
OpenServiceW
OpenSCManagerW
FreeSid
SetServiceObjectSecurity
AddAccessAllowedAce
GetLengthSid
IsValidSid
MakeAbsoluteSD
QueryServiceObjectSecurity
ChangeServiceConfig2W
CreateServiceW
DeleteService
ControlService
RegCloseKey
RegSetValueExW
RegOpenKeyW
GetSecurityDescriptorLength
MakeSelfRelativeSD
RegisterServiceCtrlHandlerW
StartServiceCtrlDispatcherW
RegQueryValueExW
RegEnumKeyExW
InitiateSystemShutdownExW
RegCreateKeyExW
RegOpenKeyExW
RegDeleteValueW
api-ms-win-core-debug-l1-1-0.dll

api-ms-win-core-errorhandling-l1-1-0.dll

GetLastError
SetUnhandledExceptionFilter
UnhandledExceptionFilter
SetLastError
api-ms-win-core-file-l1-1-0.dll

DefineDosDeviceW
DeleteVolumeMountPointW
GetVolumePathNameW
FindFirstVolumeW
FindNextVolumeW
FindVolumeClose
GetDriveTypeW
CreateFileW
SetFilePointerEx
WriteFile
QueryDosDeviceW
RemoveDirectoryW
api-ms-win-core-handle-l1-1-0.dll

api-ms-win-core-heap-l1-1-0.dll

HeapFree
HeapSetInformation
HeapAlloc
GetProcessHeap
api-ms-win-core-interlocked-l1-1-0.dll

InterlockedCompareExchange
InterlockedDecrement
InterlockedExchange
InterlockedIncrement
api-ms-win-core-io-l1-1-0.dll

api-ms-win-core-libraryloader-l1-1-0.dll

GetModuleFileNameW
GetProcAddress
GetModuleHandleW
FreeLibrary
LoadLibraryExA
GetModuleHandleA
api-ms-win-core-localregistry-l1-1-0.dll

RegCreateKeyExW
RegCloseKey
RegSetValueExW
RegDeleteValueW
RegOpenKeyExW
RegEnumKeyExW
RegQueryValueExW
api-ms-win-core-misc-l1-1-0.dll

lstrlenW
lstrcmpiW
LocalFree
FormatMessageW
Sleep
api-ms-win-core-processenvironment-l1-1-0.dll

api-ms-win-core-processthreads-l1-1-0.dll

SetThreadToken
OpenProcessToken
GetCurrentThreadId
OpenThreadToken
ResumeThread
GetStartupInfoW
GetCurrentProcessId
CreateThread
TerminateProcess
GetCurrentProcess
api-ms-win-core-profile-l1-1-0.dll

api-ms-win-core-string-l1-1-0.dll

api-ms-win-core-synch-l1-1-0.dll

WaitForSingleObject
InitializeCriticalSection
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
SetEvent
CreateEventW
ReleaseSemaphore
api-ms-win-core-sysinfo-l1-1-0.dll

GetTickCount
GetSystemTimeAsFileTime
api-ms-win-security-base-l1-1-0.dll

DuplicateTokenEx
FreeSid
AddAccessAllowedAce
GetLengthSid
IsValidSid
MakeAbsoluteSD
GetSecurityDescriptorLength
MakeSelfRelativeSD
AdjustTokenPrivileges
api-ms-win-service-core-l1-1-0.dll

StartServiceCtrlDispatcherW
SetServiceStatus
api-ms-win-service-management-l1-1-0.dll

CloseServiceHandle
OpenSCManagerW
OpenServiceW
DeleteService
CreateServiceW
api-ms-win-service-management-l2-1-0.dll

QueryServiceObjectSecurity
SetServiceObjectSecurity
ChangeServiceConfig2W
api-ms-win-service-winsvc-l1-1-0.dll

RegisterServiceCtrlHandlerW
ControlService
clusapi.dll

kernel32.dll

FindNextVolumeMountPointW
VirtualAlloc
FindVolumeMountPointClose
CreateSemaphoreW
GetVolumeNameForVolumeMountPointW
FindFirstVolumeMountPointW
LoadLibraryW
GetVolumePathNamesForVolumeNameW
SetVolumeMountPointW
WaitForMultipleObjects
DelayLoadFailureHook
GetSystemDirectoryW
ReadFile
VirtualFree
GetFileAttributesW
GetCurrentThread
GetCurrentThreadId
GetModuleFileNameW
OutputDebugStringW
GetCommandLineW
HeapSetInformation
DeviceIoControl
CreateFileW
WaitForSingleObject
GetProcAddress
ReleaseSemaphore
LocalFree
FormatMessageW
InterlockedDecrement
lstrlenW
FreeLibrary
Sleep
QueryDosDeviceW
FindVolumeClose
FindNextVolumeW
RemoveDirectoryW
FindFirstVolumeW
GetLastError
CreateThread
CreateEventW
lstrcmpiW
DeleteVolumeMountPointW
DefineDosDeviceW
GetVolumePathNameW
SetFilePointerEx
WriteFile
ResumeThread
SetLastError
HeapAlloc
WideCharToMultiByte
UnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
GetSystemTimeAsFileTime
GetCurrentProcessId
GetTickCount
QueryPerformanceCounter
GetModuleHandleA
SetUnhandledExceptionFilter
GetStartupInfoW
InterlockedCompareExchange
SetEvent
CloseHandle
InterlockedIncrement
InitializeCriticalSection
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InterlockedExchange
HeapFree
GetProcessHeap
GetModuleHandleW
msvcrt.dll
netapi32.dll

ntdll.dll

RtlInitializeResource
RtlDeleteResource
RtlReleaseResource
RtlAcquireResourceShared
RtlAcquireResourceExclusive
RtlConvertSharedToExclusive
RtlConvertExclusiveToShared
RtlAdjustPrivilege
NtQueryVolumeInformationFile
RtlCompareMemory
ole32.dll

CoInitializeEx
CoInitializeSecurity
CLSIDFromString
CoTaskMemAlloc
CoRevertToSelf
CoImpersonateClient
StringFromGUID2
CoCreateInstance
CoCreateGuid
CoTaskMemRealloc
CoUninitialize
CoTaskMemFree
osuninst.dll

setupapi.dll

SetupDiEnumDeviceInterfaces
CM_Get_Parent
CM_Reenumerate_DevNode_Ex
SetupDiEnumDeviceInfo
CM_Get_DevNode_Status
SetupDiGetCustomDevicePropertyW
SetupDiCallClassInstaller
SetupDiGetClassDevsW
SetupDiDestroyDeviceInfoList
CM_Query_And_Remove_SubTreeW
SetupDiGetDeviceInterfaceDetailW
shlwapi.dll

user32.dll

RegisterDeviceNotificationW
PeekMessageW
UnregisterDeviceNotification
GetMessageW
DefWindowProcW
CharNextW
PostThreadMessageW
LoadStringW
MessageBoxW
DispatchMessageW
vdsutil.dll
