File details
File name: ui0detect.exe
Name: Interactive services detection
Description: Microsoft® Windows® Operating System
Version: 6.1.7600.16385 (win7_rtm.090713-1255)
Product version: 6.1.7600.16385
Size: 40 KB
Original file name: UI0Detect.exe.mui
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0051354251%
Privileged CPU:
0.0034708610%

User CPU:
0.00166456410177%

Privileged CPU time: 994623.83 ms
Privileged CPU time /min: 35 ms
CPU cycle count:
253,130,226
CPU cycle count /min: 23,216,938
Context switches /sec:
5
 | Memory utilization averages |
Committed memory:
102.07 MB
Peak committed memory: 108.62 MB
Paged memory:
2.85 MB
Peak paged memory: 2.9 MB
Paged system memory:
189.2 KB
Non-paged system memory: 9.19 KB
Working set memory:
5.88 MB
Peak working set memory: 7.32 MB
Min working set memory: 5.69 MB
Private memory:
2.85 MB
Page faults:
3,070,599
Page faults /min: 692
 | Process I/O averages |
Total read operations:
2,765
Read operations /min: 2
Total read transfer: 266.19 KB
Read transfer /min: 226 Bytes
Total write operations:
41,413
Write operations /min: 6
Total write transfer: 27.17 MB
Write transfer /min: 4.08 KB
Total other operations:
1,418
Other operations /min: 4
Total other transfer: 12.97 KB
Other Transfer /min: 22 Bytes
Resources
Handle count average: 112
Thread count average: 5
Thread resource averages
Total CPU: 0.014545756161%
Privileged CPU: 0.005008803781%
User CPU: 0.009536952381%
CPU Cycle count /sec: 295,463
Module memory size: 124 KB
Total CPU: 0.007262505813%
Privileged CPU: 0.006478850090%
User CPU: 0.000783655723%
CPU Cycle count /sec: 523,243
Module memory size: 440 KB
Total CPU: 0.000036009808%
Privileged CPU: 0.000021876352%
User CPU: 0.000014133456%
CPU Cycle count /sec: 685
Module memory size: 56 KB
Process details
Runs as (owner): System
Integrety level: System
Windows platform: 64-bit
Runs as a service: Yes
Parent Process
Process Commands
C:\Windows\system32\UI0Detect.exe
C:\Windows\System32\UI0Detect.exe
Service details
Name: Wykrywanie usług interakcyjnych
Service name: UI0Detect
Service type: Win32OwnProcess, InteractiveProcess
Description: “Włącza powiadamianie użytkownika o danych wprowadzonych przez użytkownika do usług interakcyjnych, które umożliwia dostęp do okien dialogowych utworzonych przez usługi interakcyjne w momencie ich pojawienia się. Jeśli ta usługa zostanie zatrzymana, powiadomienia o nowych oknach dialogowych usług interakcyjnych nie będą działały i nie będzie można uzyskać dostępu do tych okien. Jeśli ta usługa zost”
Image hashes
MD5: 3cbdec8d06b9968aba702eba076364a1
SHA-1: 6e0fcaccadbdb5e3293aa3523ec1006d92191c58
SHA-256: b8dab8aa804fc23021bfebd7ae4d40fbe648d6c6ba21cc008e26d1c084972f9b
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File entropy: 5.94408
File packed: No
Import Table
advapi32.dll

CheckTokenMembership
SetServiceStatus
ReportEventW
RegisterEventSourceW
DeregisterEventSource
RegisterServiceCtrlHandlerW
StartServiceCtrlDispatcherW
RevertToSelf
CreateProcessAsUserW
ImpersonateLoggedOnUser
gdi32.dll

kernel32.dll

CloseHandle
UnmapViewOfFile
DuplicateHandle
GetCurrentProcess
MapViewOfFile
CreateFileMappingW
GetProcessHeap
HeapFree
lstrcmpW
K32GetModuleBaseNameW
K32GetModuleInformation
GetLastError
K32EnumProcessModules
CompareStringW
lstrlenW
CompareFileTime
GetSystemTimeAsFileTime
K32GetModuleFileNameExW
OpenProcess
GetCurrentProcessId
SetLastError
GetTickCount
HeapSetInformation
GetCurrentThreadId
LocalFree
FormatMessageW
GetModuleHandleW
CreateEventW
DelayLoadFailureHook
GetProcAddress
FreeLibrary
InterlockedCompareExchange
LoadLibraryExA
Sleep
HeapAlloc
TerminateProcess
QueryPerformanceCounter
GetModuleHandleA
SetUnhandledExceptionFilter
GetStartupInfoA
InterlockedExchange
UnhandledExceptionFilter
LoadLibraryA
msvcrt.dll
ntdll.dll

WinSqmIsOptedIn
WinSqmSetDWORD
WinSqmEndSession
WinSqmStartSession
WinSqmSetString
WinSqmAddToAverageDWORD
WinSqmAddToStream
WinSqmIncrementDWORD
RtlAllocateAndInitializeSid
RtlFreeSid
WinSqmEventEnabled
WinSqmEventWrite
psapi.dll

GetModuleBaseNameW
EnumProcessModules
GetModuleFileNameExW
GetModuleInformation
shell32.dll

user32.dll

EnumWindows
RegisterShellHookWindow
SetWindowLongW
RegisterWindowMessageW
PostQuitMessage
IsWindow
DestroyWindow
DefWindowProcW
SetTimer
GetLastInputInfo
MoveWindow
GetSystemMetrics
KillTimer
SetShellWindow
SystemParametersInfoW
ShowWindow
GetWindowTextW
RegisterClassW
GetWindow
UnregisterClassW
DispatchMessageW
GetMessageW
GetUserObjectInformationW
GetThreadDesktop
GetProcessWindowStation
LoadStringW
FlashWindowEx
DestroyIcon
LoadIconW
GetWindowRect
FindWindowW
SendMessageW
GetWindowLongW
GetClassLongW
PostMessageW
GetWindowThreadProcessId
GetWindowInfo
GetClassNameW
LoadCursorW
GetWindowTextLengthW
SetTaskmanWindow
CreateWindowExW
version.dll

GetFileVersionInfoW
GetFileVersionInfoSizeW
VerQueryValueW
winsta.dll

WinStationGetSessionIds
WinStationRevertFromServicesSession
WinStationSwitchToServicesSession
wtsapi32.dll

WTSUnRegisterSessionNotification
WTSRegisterSessionNotification
WTSDisconnectSession
WTSQueryUserToken