File details
File name: ehrecvr.exe
Name: Windows Media Center Receiver Service
Description: Microsoft® Windows® Operating System
Version: 6.1.7600.16385 (win7_rtm.090713-1255)
Product version: 6.1.7600.16385
Size: 543 KB
Original file name: ehRecvr.exe.mui
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.4022652356%
Privileged CPU:
0.2011326178%

User CPU:
0.20113261781290%

Privileged CPU time: 436.8 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
1,913,596,762
 | Memory utilization averages |
Committed memory:
115.89 MB
Peak committed memory: 115.89 MB
Paged memory:
13.5 MB
Peak paged memory: 13.5 MB
Paged system memory:
208.08 KB
Non-paged system memory: 14.17 KB
Working set memory:
16.6 MB
Peak working set memory: 16.6 MB
Min working set memory: 16.52 MB
Private memory:
13.5 MB
Page faults:
29,241
Page faults /min: 0
 | Process I/O averages |
Total read operations:
45
Total read transfer: 78.99 KB
Total write operations:
5
Total write transfer: 20.05 KB
Total other operations:
6,135
Total other transfer: 505.81 KB
Resources
Handle count average: 436
Thread count average: 24
Thread resource averages
Total CPU: 0.218155954213%
Privileged CPU: 0.102057943706%
User CPU: 0.116098010508%
CPU Cycle count /sec: 4,952,708
Context switches /sec: 8
Module memory size: 552 KB
sechost.dll

Total CPU: 0.018563523934%
Privileged CPU: 0.018563523934%
User CPU: 0.000000000000%
CPU Cycle count /sec: 617,511
Context switches /sec: 2
Module memory size: 100 KB
Process details
Runs as (owner): User
Integrety level: System
Windows platform: 32-bit
Runs as a service: Yes
Parent Process
Process Command
C:\Windows\ehome\ehRecvr.exe
Service details
Name: Servicio Receptor de Windows Media Center
Service name: ehRecvr
Service type:
Win32OwnProcess
Description: “Servicio de Windows Media Center para la recepción de difusión de TV y FM.”
Image hashes
MD5: 1697c39978cd69f6fbc15302edcece1f
SHA-1: a2888a3a19ac29c3a1fa2cfafd68978428b4650b
SHA-256: e496fae102ee33ebd35ac745e8647976db9f91ef78e54eb962ff2d04d45b561a
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File entropy: 5.71523
File packed: No
Import Table
advapi32.dll

SetServiceStatus
RegCloseKey
RegOpenKeyExW
RegQueryValueExW
AddAce
GetAce
GetAclInformation
DeregisterEventSource
RegisterEventSourceW
ReportEventW
InitializeSecurityDescriptor
LookupAccountNameW
AddAccessAllowedAce
InitializeAcl
GetLengthSid
RegDeleteValueW
SetSecurityDescriptorDacl
RegisterServiceCtrlHandlerExW
StartServiceCtrlDispatcherW
RegSetValueExW
RegGetValueW
RegCreateKeyExW
CreateWellKnownSid
RegQueryInfoKeyW
RegEnumValueW
RegEnumKeyW
SetNamedSecurityInfoW
SetEntriesInAclW
GetNamedSecurityInfoW
LookupAccountSidW
GetTokenInformation
SetSecurityDescriptorGroup
SetSecurityDescriptorOwner
IsValidSid
CopySid
GetSecurityDescriptorDacl
OpenProcessToken
CloseServiceHandle
OpenServiceW
OpenSCManagerW
DeleteService
ControlService
RegEnumKeyExW
ChangeServiceConfig2W
CreateServiceW
RegDeleteKeyW
FreeSid
CheckTokenMembership
AllocateAndInitializeSid
SetSecurityInfo
ConvertStringSecurityDescriptorToSecurityDescriptorW
ehtrace.dll

ehAllocateEventBuffer
ehFreeEventBuffer
ehUnregisterTraceGUIDs
ehTraceEvent
ehRegisterTraceGUIDs
faultrep.dll

kernel32.dll

CreateEventW
SetPriorityClass
GetCurrentProcess
GetProfileIntW
GetCommandLineW
SetUnhandledExceptionFilter
HeapSetInformation
lstrlenW
EnterCriticalSection
LeaveCriticalSection
GetLocaleInfoW
GetUserDefaultUILanguage
GetTickCount
GetCurrentThreadId
GetSystemTimeAsFileTime
SleepEx
QueueUserAPC
GetCurrentThread
DuplicateHandle
GetCurrentProcessId
HeapReAlloc
CancelWaitableTimer
CreateWaitableTimerW
CreateThread
SetWaitableTimer
GetProcAddress
FreeLibrary
LoadLibraryExW
WaitForMultipleObjectsEx
WaitForMultipleObjects
WaitForSingleObject
ResetEvent
FindNextFileW
DeleteFileW
SetFileAttributesW
FindFirstFileW
GetFileAttributesW
ExitThread
LoadLibraryW
ExpandEnvironmentStringsW
LocalFree
OpenThread
GetProcessHeap
HeapAlloc
GetLastError
GetVersionExW
VirtualProtect
VirtualAlloc
GetSystemInfo
VirtualQuery
InterlockedExchange
InterlockedCompareExchange
GetStartupInfoW
GetModuleHandleA
InitializeCriticalSection
QueryPerformanceCounter
TerminateProcess
UnhandledExceptionFilter
OutputDebugStringW
GetLocalTime
EncodeSystemPointer
DecodeSystemPointer
GetTempPathW
MoveFileExW
OutputDebugStringA
Sleep
MultiByteToWideChar
SetEvent
CloseHandle
InterlockedDecrement
InterlockedIncrement
FindClose
DeleteCriticalSection
HeapFree
GetModuleHandleW
lstrcmpiW
GetModuleFileNameW
SizeofResource
LoadResource
FindResourceW
GetTickCount64
LocalAlloc
K32GetModuleBaseNameW
CreateDirectoryW
GetExitCodeThread
SystemTimeToTzSpecificLocalTime
FileTimeToSystemTime
lstrlenA
SetThreadExecutionState
GetVersionExA
RaiseException
msvcrt.dll
ole32.dll

CoTaskMemAlloc
CoCreateInstance
CoFreeUnusedLibrariesEx
CoWaitForMultipleHandles
CoCreateGuid
StringFromCLSID
StringFromGUID2
CoInitializeSecurity
CoTaskMemFree
CLSIDFromString
CoInitialize
CoDisconnectObject
CoInitializeEx
CoUninitialize
CoImpersonateClient
CoRevertToSelf
CoSuspendClassObjects
CoRegisterClassObject
CoRevokeClassObject
CoTaskMemRealloc
psapi.dll

shell32.dll

SHGetKnownFolderPath
SHSetLocalizedName
SHCreateDirectoryExW
shlwapi.dll

slc.dll

SLGetWindowsInformationDWORD
user32.dll

TranslateMessage
SetTimer
PostThreadMessageW
KillTimer
RegisterDeviceNotificationW
MsgWaitForMultipleObjectsEx
DispatchMessageW
PeekMessageW
LoadStringW
GetMessageW
UnregisterDeviceNotification
CharNextW
UnregisterClassA
version.dll

GetFileVersionInfoW
GetFileVersionInfoSizeW
VerQueryValueA
Export Table