File details
File name: 5zbarsvc.exe
Name: PRODUCTVERS_NAME
Description: PRODUCTVERS_TITLE
Version: 1, 0, 0, 9
Product version: 2, 3, 0, 0
Size: 41.51 KB
Original file name: TWOLETTERPREFIXVERSsvc.exe
Digital certificate
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0003197402%
Privileged CPU:
0.0001983807%

User CPU:
0.00012135952940%

Privileged CPU time: 7819.08 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
126,752,096
CPU cycle count /min: 509,650
 | Memory utilization averages |
Committed memory:
23.35 MB
Peak committed memory: 27 MB
Paged memory:
885.74 KB
Peak paged memory: 1.1 MB
Paged system memory:
35.52 KB
Non-paged system memory: 4.12 KB
Working set memory:
1.69 MB
Peak working set memory: 2.97 MB
Min working set memory: 1.69 MB
Private memory:
885.74 KB
Page faults:
1,687
Page faults /min: 9
 | Process I/O averages |
Total read operations:
27
Read operations /min: 1
Total read transfer: 15.48 KB
Read transfer /min: 37 Bytes
Total write operations:
28
Write operations /min: 1
Total write transfer: 129 Bytes
Write transfer /min: 2 Bytes
Total other operations:
215
Other operations /min: 3
Total other transfer: 2.3 KB
Other Transfer /min: 10 Bytes
Resources
Handle count average: 73
Thread count average: 4
Thread resource averages
Total CPU: 0.000627031308%
Privileged CPU: 0.000312998853%
User CPU: 0.000314032455%
CPU Cycle count /sec: 12,752
Module memory size: 36 KB
sechost.dll

Total CPU: 0.000208373097%
Privileged CPU: 0.000200481006%
User CPU: 0.000007892091%
CPU Cycle count /sec: 2,052
Module memory size: 100 KB
wow64.dll

Total CPU: 0.000125285991%
Privileged CPU: 0.000125285991%
User CPU: 0.000000000000%
CPU Cycle count /sec: 1,444
Module memory size: 252 KB
ntdll.dll

Total CPU: 0.000017302091%
Privileged CPU: 0.000017302091%
User CPU: 0.000000000000%
CPU Cycle count /sec: 143
Module memory size: 1.67 MB
wow64.dll

Total CPU: 0.000014772576%
Privileged CPU: 0.000000000000%
User CPU: 0.000014772576%
CPU Cycle count /sec: 22
Module memory size: 252 KB
wow64.dll

Total CPU: 0.000013270790%
Privileged CPU: 0.000013270790%
User CPU: 0.000000000000%
CPU Cycle count /sec: 224
Module memory size: 252 KB
Process details
Runs as (owner): System
Integrety level: System
Windows platform: 32-bit
Runs as a service: Yes
Parent Processes
Process Commands
C:\Program Files1\ALLIN1~2\bar\1.bin\8hbarsvc.exe
C:\Program Files1\VIDEOS~2\bar\1.bin\1ebarsvc.exe
C:\Program Files1\HEADLI~2\bar\1.bin\29barsvc.exe
C:\Program Files1\FROMDO~2\bar\1.bin\65barsvc.exe
C:\Program Files1\VIDEOD~2\bar\1.bin\4zbarsvc.exe
Service details
Name: Allin1ConvertService
Service name: Allin1Convert_8hService
Service type:
Win32OwnProcess
User start menu folder details
Name: 4zbarsvc.exe
Image hashes
MD5: 622fcf264119f7df127be353f796b319
SHA-1: 56cf4f2ac44c6add5cdcd419ba4b99d22dc7a0e3
SHA-256: 6689d8f62f860178685496ef45520967afaeff94cfbcc64cf77074f21577e0a2
PE image details
File packed: No
Import Table
advapi32.dll

OpenThreadToken
RevertToSelf
RegCreateKeyExA
RegSetValueExA
RegCloseKey
OpenServiceA
ControlService
DeleteService
OpenSCManagerA
CreateServiceA
StartServiceA
QueryServiceStatus
CloseServiceHandle
RegisterEventSourceA
ReportEventA
DeregisterEventSource
SetServiceStatus
RegisterServiceCtrlHandlerA
StartServiceCtrlDispatcherA
ImpersonateNamedPipeClient
InitializeSecurityDescriptor
DuplicateTokenEx
kernel32.dll

FreeLibrary
FormatMessageA
LoadLibraryExA
LockResource
LoadResource
FindResourceA
CloseHandle
CreateDirectoryA
CopyFileA
DeleteFileA
MoveFileA
_lclose
_lwrite
_llseek
_lcreat
_lopen
GetLocalTime
GetModuleFileNameA
GetCurrentThreadId
WaitForSingleObject
WaitForMultipleObjects
GetProcAddress
DisconnectNamedPipe
WriteFile
GetOverlappedResult
ReadFile
ConnectNamedPipe
SetLastError
ResetEvent
CreateNamedPipeA
CreateEventA
SetEvent
FreeResource
ExpandEnvironmentStringsA
GetVersionExA
GetLastError
LocalAlloc
lstrcpyA
lstrcmpiA
Sleep
LocalFree
EnterCriticalSection
LeaveCriticalSection
CreateThread
lstrlenA
HeapFree
HeapReAlloc
GetProcessHeap
HeapAlloc
DebugBreak
DeleteCriticalSection
InitializeCriticalSection
GetModuleHandleA
GetCommandLineA
ExitProcess
GetStartupInfoA
GetCurrentThread
lstrcpynA
shlwapi.dll

SHDeleteValueA
SHDeleteKeyA
user32.dll
