File details
File name: defrag.exe
Name: Windows Disk Defragmenter
Description: Disk Defragmenter Module
Version: 6.1.7600.16385 (win7_rtm.090713-1255)
Product version: 6.1.7600.16385
Size: 179 KB
Original file name: Defrag.EXE.MUI
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0014582865%
Privileged CPU:
0.0012597085%

User CPU:
0.00019857802047%

Privileged CPU time: 21.84 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
243,702,056
CPU cycle count /min: 170,485
Context switches /sec:
2
 | Memory utilization averages |
Committed memory:
26.43 MB
Peak committed memory: 27.43 MB
Paged memory:
2.05 MB
Peak paged memory: 2.11 MB
Paged system memory:
50.57 KB
Non-paged system memory: 7.48 KB
Working set memory:
1.57 MB
Peak working set memory: 5.16 MB
Min working set memory: 1.55 MB
Private memory:
2.05 MB
Page faults:
1,659
Page faults /min: 2
 | Process I/O averages |
Total read operations:
1
Read operations /min: 1
Total read transfer: 17.06 KB
Read transfer /min: 17 Bytes
Total other operations:
925
Other operations /min: 2
Total other transfer: 192.38 KB
Other Transfer /min: 730 Bytes
Resources
Handle count average: 83
Thread count average: 5
Thread resource averages
Total CPU: 0.003597415552%
Privileged CPU: 0.002783609676%
User CPU: 0.000813805876%
CPU Cycle count /sec: 59,552
Module memory size: 192 KB
Process details
Runs as (owner): System
Integrety level: System
Windows platform: 64-bit
Runs as a service: Yes
Parent Processes
Process Command
C:\Windows\system32\defrag.exe -c
Scheduled task details
Name: ManualDefrag
Command: \Microsoft\Windows\Defrag\ManualDefrag
Image hashes
MD5: 8fd0ec6eb52f9efe15b7a605c827932c
SHA-1: 8dbf4ecae1bbad74c91fa37603353ecfdc47425e
SHA-256: 62e449589e1f082e8de3fa4d775871e1c66a272e3bd1fe5cc33eeeb40351cd13
PE image details
Subsystem: Windows Console
Langauge*: Microsoft Visual C++
File entropy: 7.28274
File packed: No
Import Table
advapi32.dll

FreeSid
CheckTokenMembership
AllocateAndInitializeSid
RegCloseKey
RegQueryValueExW
RegOpenKeyExW
RegSetValueExW
RegCreateKeyExW
DeregisterEventSource
ReportEventW
RegisterEventSourceW
SetSecurityDescriptorDacl
SetEntriesInAclW
InitializeSecurityDescriptor
GetSecurityDescriptorDacl
RegDeleteKeyValueW
CreateWellKnownSid
DuplicateToken
GetTokenInformation
OpenProcessToken
TraceMessage
GetTraceEnableFlags
GetTraceEnableLevel
GetTraceLoggerHandle
RegisterTraceGuidsW
UnregisterTraceGuids
ConvertStringSecurityDescriptorToSecurityDescriptorW
CloseTrace
StartTraceW
EnableTrace
ControlTraceW
kernel32.dll

GetLastError
GlobalLock
GlobalFree
GlobalReAlloc
GlobalUnlock
GlobalSize
GlobalAlloc
HeapFree
GetProcessHeap
HeapAlloc
SetLastError
InterlockedIncrement
InterlockedDecrement
EnterCriticalSection
LeaveCriticalSection
Sleep
InitializeCriticalSectionAndSpinCount
DeleteCriticalSection
CloseHandle
WriteFile
GetFileSize
CreateFileW
ReleaseMutex
FormatMessageW
GetCurrentThreadId
lstrlenW
GetTimeFormatW
GetDateFormatW
WaitForSingleObject
ExpandEnvironmentStringsW
LoadLibraryW
OutputDebugStringA
IsDebuggerPresent
SetFilePointer
GetLocalTime
WideCharToMultiByte
LocalFree
SetErrorMode
DeleteFileW
GetDiskFreeSpaceExW
GetTempFileNameW
GetVolumeInformationW
DeviceIoControl
GetDriveTypeW
GetConsoleOutputCP
WriteConsoleW
GetConsoleMode
GetFileType
GetStdHandle
VerifyVersionInfoW
VerSetConditionMask
GetCurrentProcess
ReleaseSemaphore
SetEvent
SetThreadUILanguage
CreateSemaphoreW
WaitForMultipleObjects
SetConsoleCtrlHandler
ResetEvent
CreateEventW
GetVolumePathNamesForVolumeNameW
GetVolumeNameForVolumeMountPointW
DuplicateHandle
OpenProcess
FreeLibrary
HeapSetInformation
UnhandledExceptionFilter
TerminateProcess
GetSystemTimeAsFileTime
GetCurrentProcessId
GetTickCount
QueryPerformanceCounter
GetModuleHandleA
SetUnhandledExceptionFilter
InterlockedCompareExchange
InterlockedExchange
LoadLibraryExW
GetVolumePathNameW
MoveFileExW
FindFirstFileW
FindNextFileW
FindClose
CreateDirectoryW
GetFileAttributesW
InitializeCriticalSection
CreateThread
InterlockedPopEntrySList
InitializeSListHead
RtlCaptureStackBackTrace
InterlockedPushEntrySList
GetModuleHandleW
msvcrt.dll
ntdll.dll

NtWaitForSingleObject
NtFsControlFile
NtQueryVolumeInformationFile
RtlAllocateHeap
RtlFreeHeap
EtwTraceMessage
RtlNtStatusToDosError
RtlGetLastNtStatus
RtlSetThreadErrorMode
ole32.dll

CoCreateInstanceEx
CoInitializeEx
CoRegisterClassObject
ReleaseStgMedium
CoCreateGuid
CoTaskMemFree
CoTaskMemAlloc
StringFromCLSID
CoUninitialize
CoCreateInstance
CoDisconnectObject
sxshared.dll

SxTracerGetThreadContextRetail
SxTracerDebuggerBreak
SxTracerShouldTrackFailure
user32.dll

virtdisk.dll

GetStorageDependencyInformation