File details
File name: ehprivjob.exe
Name: Digital TV Tuner device registration application.
Description: Microsoft® Windows® Operating System
Version: 6.1.7600.16385 (win7_rtm.090713-1255)
Product version: 6.1.7600.16385
Size: 221 KB
Original file name: ehPrivJob.exe.mui
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0107787302%
Privileged CPU:
0.0053893651%

User CPU:
0.00538936511279%

Privileged CPU time: 15.6 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
244,528,438
 | Memory utilization averages |
Committed memory:
41.92 MB
Peak committed memory: 42.17 MB
Paged memory:
1.83 MB
Peak paged memory: 1.85 MB
Paged system memory:
81.05 KB
Non-paged system memory: 5.62 KB
Working set memory:
6.38 MB
Peak working set memory: 6.39 MB
Min working set memory: 6.38 MB
Private memory:
1.83 MB
Page faults:
1,770
Page faults /min: 0
 | Process I/O averages |
Total read operations:
1,391
Total read transfer: 70.63 KB
Total write operations:
1,394
Total write transfer: 22.57 KB
Total other operations:
301
Total other transfer: 8.67 KB
Resources
Handle count average: 121
Thread count average: 6
Thread resource averages
Total CPU: 0.022300351607%
Privileged CPU: 0.011150175803%
User CPU: 0.011150175803%
CPU Cycle count /sec: 765,409
Context switches /sec: 3
Module memory size: 232 KB
Process details
Runs as (owner): System
Integrety level: System
Windows platform: 32-bit
Runs as a service: Yes
Parent Process
Process Command
C:\Windows\ehome\ehPrivJob.exe /DoReindexSearchRoot
Scheduled task details
Name: UpdateRecordPath
Command: \Microsoft\Windows\Media Center\UpdateRecordPath
Scheduled tasks startup details
Name: \Microsoft\Windows\Media Center\DispatchRecoveryTasks
Image hashes
MD5: 2a5062cfccc713ed001c48d427a5790b
SHA-1: bbdffd828908d9b2d860d832b96898c417afa146
SHA-256: c07e64511a0e4d6260d19ebd8505cf30b38610b78a8fb77c1d7bda7a169b26e3
PE image details
Subsystem: Windows Console
Langauge*: Microsoft Visual C++
File entropy: 5.66326
File packed: No
Import Table
advapi32.dll

RegCloseKey
RegEnumKeyExW
RegCreateKeyExW
RegOpenKeyExW
RegSetValueExW
RegQueryValueExW
RegEnumKeyW
RegQueryInfoKeyW
ConvertStringSecurityDescriptorToSecurityDescriptorW
RegEnumValueW
ConvertStringSidToSidW
CreateWellKnownSid
EqualSid
GetAce
OpenThreadToken
ImpersonateSelf
AdjustTokenPrivileges
LookupPrivilegeValueW
SetNamedSecurityInfoW
GetNamedSecurityInfoW
GetSecurityInfo
RevertToSelf
SetEntriesInAclW
QueryServiceStatusEx
StartServiceW
ControlService
CloseServiceHandle
OpenServiceW
OpenSCManagerW
ConvertSidToStringSidW
GetTokenInformation
OpenProcessToken
ChangeServiceConfigW
iphlpapi.dll

kernel32.dll

lstrlenW
QueryFullProcessImageNameW
OpenProcess
MultiByteToWideChar
CloseHandle
LocalFree
SetEvent
CreateEventW
CreateDirectoryW
GetEnvironmentVariableW
OpenEventW
Sleep
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
WaitForSingleObject
GetModuleHandleW
WideCharToMultiByte
WaitForMultipleObjects
LocalAlloc
GetCurrentThread
CreateFileW
FindClose
FindNextFileW
FindFirstFileW
GetFileAttributesW
lstrlenA
InterlockedDecrement
GetSystemTime
WriteFile
SetFilePointer
GetCurrentProcessId
GetCurrentThreadId
GetLocalTime
GetWindowsDirectoryW
GetTickCount64
CompareStringW
GetCurrentProcess
CreateProcessW
CopyFileW
GetModuleFileNameW
GetTempPathW
DelayLoadFailureHook
FreeLibrary
InterlockedCompareExchange
LoadLibraryExA
GetStartupInfoW
SetUnhandledExceptionFilter
GetModuleHandleA
QueryPerformanceCounter
GetTickCount
GetSystemTimeAsFileTime
TerminateProcess
UnhandledExceptionFilter
InterlockedIncrement
GetProcAddress
LoadLibraryW
FlushFileBuffers
DeleteFileW
CompareFileTime
GetLastError
CreateThread
SetEndOfFile
MoveFileExW
OutputDebugStringW
CreateMutexW
OpenMutexW
ReleaseMutex
InterlockedExchange
msvcrt.dll
ole32.dll

CoUninitialize
CoInitializeEx
CoCreateInstance
StringFromGUID2
CoTaskMemFree
CLSIDFromString
StringFromCLSID
CoSetProxyBlanket
CoTaskMemAlloc
CoCreateGuid
StringFromIID
propsys.dll

PSUnregisterPropertySchema
PSRegisterPropertySchema
shlwapi.dll

PathFindFileNameW
UrlGetPartW
PathCombineW
slc.dll

SLInstallProofOfPurchase
SLGetPKeyInformation
SLConsumeWindowsRight
SLClose
SLOpen
slcext.dll

user32.dll

LoadStringW
CharLowerBuffW
wmdrmsdk.dll

ws2_32.dll

WSAStringToAddressW
GetNameInfoW