File details
File name: ehtray.exe
Name: Media Center Tray Applet
Description: Microsoft® Windows® Operating System
Version: 6.0.6001.18000 (longhorn_rtm.080118-1840)
Product version: 6.0.6001.18000
Size: 123 KB
Original file name: ehtray.exe
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0028909377%
Privileged CPU:
0.0019229605%

User CPU:
0.00096797712700%

Total CPU time: 3 ms
Total CPU time /min: 0 ms
Privileged CPU time: 40159.71 ms
Privileged CPU time /min: 3 ms
User CPU time: 0.93 ms
User CPU time /min: 0 ms
CPU cycle count:
341,728,941
CPU cycle count /min: 2,428,854
 | Memory utilization averages |
Committed memory:
66.57 MB
Peak committed memory: 67.69 MB
Paged memory:
1.93 MB
Peak paged memory: 2.03 MB
Paged system memory:
126.09 KB
Non-paged system memory: 3.34 KB
Working set memory:
1.86 MB
Peak working set memory: 6.09 MB
Min working set memory: 913.67 KB
Private memory:
1.93 MB
Page faults:
5,328
Page faults /min: 10
 | Process I/O averages |
Total read operations:
14
Read operations /min: 1
Total read transfer: 3.97 KB
Read transfer /min: 13 Bytes
Total write operations:
4
Write operations /min: 1
Total write transfer: 470 Bytes
Write transfer /min: 3 Bytes
Total other operations:
1,552
Other operations /min: 4
Total other transfer: 13.92 KB
Other Transfer /min: 49 Bytes
 | GUI Object Averages |
GDI objects:
17
USER objects:
8
Resources
Handle count average: 95
Thread count average: 2
Thread resource averages
Total CPU: 0.001415096476%
Privileged CPU: 0.001015510112%
User CPU: 0.000399586364%
CPU Cycle count /sec: 35,212
Context switches /sec: 1
Module memory size: 136 KB
rpcrt4.dll

Total CPU: 0.000414808908%
Privileged CPU: 0.000414808908%
User CPU: 0.000000000000%
CPU Cycle count /sec: 1,511
Module memory size: 780 KB
Process details
Runs as (owner): User
Integrety level: Medium
Windows platform: 32-bit
Parent Processes
Process Commands
"C:\Windows\ehome\ehtray.exe"
"C:\WINDOWS\ehome\ehtray.exe"
"C:\Windows\ehome\EHTray.exe"
Startup files (user) run details
Name: ehTray.exe
Command: C:\Windows\ehome\ehTray.exe
Startup files (all users) run details
Name: ehTray
Command: C:\WINDOWS\ehome\ehtray.exe
Image hashes
MD5: bf08674925f151bd4537b89a493e3e0c
SHA-1: 60bc596427695f4371333234b370fb4af0cb6297
SHA-256: 6a97562e998a2b90649ff7986313ad33823053ff98bbe163ad39aaa5e01fc545
PE image details
File entropy: 6.34907
File packed: No
Import Table
advapi32.dll

RegQueryValueExA
RegEnumValueW
FreeSid
CheckTokenMembership
AllocateAndInitializeSid
RegCloseKey
RegQueryValueExW
RegOpenKeyExW
InitiateSystemShutdownW
AdjustTokenPrivileges
LookupPrivilegeValueW
OpenProcessToken
RegSetValueExW
RegCreateKeyExW
RegNotifyChangeKeyValue
RegCreateKeyW
RegOpenKeyExA
RegQueryInfoKeyW
gdi32.dll

GetTextExtentExPointW
CreateCompatibleDC
GetDeviceCaps
CreateFontIndirectW
DeleteDC
CreateSolidBrush
GetRgnBox
OffsetRgn
CreateDIBSection
SelectObject
SetTextColor
SetBkColor
GetLayout
ExtTextOutW
CreateRectRgn
DeleteObject
CombineRgn
hid.dll

kernel32.dll

lstrcmpiW
GetModuleFileNameW
lstrcmpW
GlobalDeleteAtom
WaitForSingleObject
SetThreadExecutionState
OpenEventW
LoadLibraryExW
CreateMutexW
SetProcessWorkingSetSize
Sleep
OpenProcess
WTSGetActiveConsoleSessionId
ProcessIdToSessionId
GetCurrentProcessId
ExitProcess
GetCommandLineW
GetStartupInfoW
SetProcessShutdownParameters
GetCurrentThread
GetModuleHandleW
MulDiv
GlobalFree
GetProcessHeap
HeapAlloc
HeapReAlloc
CompareFileTime
GetFileAttributesExW
GetFileAttributesW
QueryPerformanceCounter
GetCurrentThreadId
GetSystemTimeAsFileTime
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
InterlockedDecrement
lstrlenW
CreateEventW
CloseHandle
LocalReAlloc
LocalAlloc
LocalFree
QueueUserAPC
InterlockedIncrement
GetCurrentProcess
SystemTimeToTzSpecificLocalTime
GetThreadLocale
GetTimeFormatW
ExpandEnvironmentStringsW
SetLastError
FormatMessageW
GlobalAddAtomW
GetLastError
InitializeCriticalSection
DeleteCriticalSection
GetProcAddress
LoadLibraryA
GetUserGeoID
ResetEvent
CompareStringW
FreeLibrary
LoadLibraryW
EnterCriticalSection
HeapFree
LeaveCriticalSection
GetTickCount
RegisterApplicationRestart
GetSystemInfo
VirtualAlloc
VirtualProtect
HeapSetInformation
EncodeSystemPointer
FlushFileBuffers
CreateFileA
WriteConsoleW
GetConsoleOutputCP
WriteConsoleA
SetStdHandle
GetConsoleMode
GetConsoleCP
GetLocaleInfoA
GetStringTypeW
GetStringTypeA
LCMapStringW
LCMapStringA
RtlUnwind
GetOEMCP
GetACP
GetCPInfo
OutputDebugStringA
VirtualFree
HeapCreate
TlsFree
TlsSetValue
TlsAlloc
TlsGetValue
GetFileType
SetHandleCount
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetEnvironmentStrings
FreeEnvironmentStringsA
GetModuleFileNameA
GetStdHandle
GetStartupInfoA
GetCommandLineA
WideCharToMultiByte
MultiByteToWideChar
WriteFile
GetModuleHandleA
FindResourceExW
FindResourceW
LoadResource
LockResource
SizeofResource
RaiseException
SetFilePointer
GetVersionExA
HeapDestroy
HeapSize
VirtualQuery
ntdll.dll

wcscmp
towlower
iswdigit
memmove
_vsnwprintf
wcslen
iswspace
RtlUnwind
wcstol
NtQueryVirtualMemory
ole32.dll

CoInitializeEx
CoUninitialize
CoCreateInstance
GetRunningObjectTable
CoSetProxyBlanket
powrprof.dll

setupapi.dll

SetupDiDestroyDeviceInfoList
SetupDiGetDeviceInstanceIdW
SetupDiGetDeviceInterfaceDetailW
SetupDiOpenDeviceInterfaceW
SetupDiCreateDeviceInfoList
shell32.dll

ShellExecuteW
CommandLineToArgvW
SHParseDisplayName
SHGetFolderPathW
SHCreateQueryCancelAutoPlayMoniker
SHGetMalloc
SHGetDesktopFolder
Shell_NotifyIconW
shlwapi.dll

PathAppendW
StrRetToBufW
PathIsDirectoryEmptyW
PathFileExistsW
PathRemoveFileSpecW
PathAddBackslashW
StrStrIW
StrChrIW
slc.dll

SLGetWindowsInformationDWORD
user32.dll

GetDoubleClickTime
LoadMenuW
GetSubMenu
DestroyMenu
LoadCursorW
SetMenuDefaultItem
GetForegroundWindow
SendMessageW
GetRawInputData
GetKeyState
DeregisterShellHookWindow
RegisterShellHookWindow
ShowWindow
SetWindowRgn
BeginPaint
CreateWindowExW
EndPaint
UnregisterHotKey
PostQuitMessage
RegisterHotKey
GetWindowThreadProcessId
DefWindowProcW
PeekMessageW
DispatchMessageW
WaitMessage
MsgWaitForMultipleObjectsEx
LoadImageW
GetSystemMetrics
RemoveMenu
GetRawInputDeviceInfoW
RegisterRawInputDevices
LoadStringW
MessageBoxW
SendInput
GetCursorPos
TrackPopupMenu
DestroyIcon
SendMessageCallbackW
DialogBoxParamW
ExitWindowsEx
IsDlgButtonChecked
GetDesktopWindow
SendMessageTimeoutW
SetForegroundWindow
EndDialog
SetDlgItemTextW
MonitorFromRect
GetMonitorInfoW
GetWindowRect
SetWindowPos
KillTimer
SetTimer
FindWindowW
GetFocus
PostMessageW
RegisterClassW
RegisterWindowMessageW
SystemParametersInfoW
ShutdownBlockReasonCreate
ShutdownBlockReasonDestroy
UnregisterClassA
wininet.dll

InternetOpenW
InternetOpenUrlW
InternetCloseHandle
winmm.dll

mixerSetControlDetails
mixerGetControlDetailsW
mixerOpen
mixerGetLineControlsW
mixerGetLineInfoW
waveOutGetNumDevs
waveOutMessage
mixerGetID
winsta.dll

WinStationGetTermSrvCountersValue
wtsapi32.dll

WTSUnRegisterSessionNotification
WTSRegisterSessionNotification