File details
File name: alg.exe
Name: Application Layer Gateway Service
Description: Microsoft® Windows® Operating System
Version: 6.1.7600.16385 (win7_rtm.090713-1255)
Product version: 6.1.7600.16385
Size: 77.5 KB
Original file name: ALG.exe.mui
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0001254936%
Privileged CPU:
0.0000839046%

User CPU:
0.00004158900218%

Privileged CPU time: 45956.77 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
83,460,451
CPU cycle count /min: 356,658
 | Memory utilization averages |
Committed memory:
29.61 MB
Peak committed memory: 31.32 MB
Paged memory:
1.7 MB
Peak paged memory: 1.78 MB
Paged system memory:
58.97 KB
Non-paged system memory: 8.43 KB
Working set memory:
3.08 MB
Peak working set memory: 5.27 MB
Min working set memory: 2.87 MB
Private memory:
1.7 MB
Page faults:
3,912
Page faults /min: 8
 | Process I/O averages |
Total read operations:
1
Read operations /min: 1
Total read transfer: 15.09 KB
Read transfer /min: 378 Bytes
Total other operations:
296
Other operations /min: 2
Total other transfer: 7.74 KB
Other Transfer /min: 9 Bytes
Resources
Handle count average: 78
Thread count average: 4
Thread resource averages
sechost.dll

Total CPU: 0.000183022204%
Privileged CPU: 0.000067448561%
User CPU: 0.000115573643%
CPU Cycle count /sec: 2,166
Module memory size: 124 KB
Total CPU: 0.000180057129%
Privileged CPU: 0.000154024148%
User CPU: 0.000026032980%
CPU Cycle count /sec: 2,460
Module memory size: 88 KB
Process details
Runs as (owner): Local Service
Integrety level: System
Windows platform: 64-bit
Runs as a service: Yes
Parent Process
Process Commands
C:\Windows\System32\alg.exe
C:\windows\System32\alg.exe
Service details
Name: Υπηρεσία πύλης επιπέδου εφαρμογής
Service name: ALG
Service type:
Win32OwnProcess
Description: “Παρέχει υποστήριξη για προσθήκες πρωτοκόλλων άλλων κατασκευαστών για την Κοινόχρηστη σύνδεση στο Internet”
Network connectivity
TCP: localhost on port 49205
TCP: localhost on port 49215
TCP: localhost on port 49158
TCP: localhost on port 54163
TCP: localhost on port 65351
TCP: localhost on port 55368
Image hashes
MD5: 3290d6946b5e30e70414990574883ddb
SHA-1: be0144e3235ffde0787e9f1cd34c828ec87d8e19
SHA-256: 0e9294e1991572256b3cda6b031db9f39ca601385515ee59f1f601725b889663
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File entropy: 6.35313
File packed: No
Import Table
advapi32.dll

SetServiceStatus
RegCloseKey
RegOpenKeyExW
RegisterServiceCtrlHandlerW
RegNotifyChangeKeyValue
StartServiceCtrlDispatcherW
RegQueryValueExW
RegEnumKeyExW
SystemFunction036
api-ms-win-core-delayload-l1-1-1.dll

ResolveDelayLoadedAPI
DelayLoadFailureHook
api-ms-win-core-errorhandling-l1-1-1.dll

UnhandledExceptionFilter
RaiseException
SetUnhandledExceptionFilter
GetLastError
api-ms-win-core-file-l1-2-0.dll

api-ms-win-core-handle-l1-1-0.dll

CloseHandle
DuplicateHandle
api-ms-win-core-heap-l1-2-0.dll

HeapDestroy
HeapSetInformation
HeapFree
GetProcessHeap
HeapAlloc
api-ms-win-core-interlocked-l1-2-0.dll

InterlockedCompareExchange
InterlockedDecrement
InterlockedIncrement
InterlockedExchange
api-ms-win-core-kernel32-legacy-l1-1-0.dll

BindIoCompletionCallback
WaitForMultipleObjects
api-ms-win-core-libraryloader-l1-1-1.dll

LoadResource
SizeofResource
GetModuleHandleA
GetModuleHandleW
FreeLibrary
GetModuleFileNameW
FindResourceExW
GetProcAddress
LoadLibraryExW
api-ms-win-core-memory-l1-1-1.dll

VirtualQuery
VirtualProtect
VirtualAlloc
api-ms-win-core-processthreads-l1-1-1.dll

GetCurrentProcessId
GetCurrentProcess
GetCurrentThreadId
TerminateProcess
GetStartupInfoW
CreateThread
api-ms-win-core-profile-l1-1-0.dll

api-ms-win-core-registry-l1-1-0.dll

RegCreateKeyExW
RegDeleteValueW
RegNotifyChangeKeyValue
RegSetValueExW
RegQueryInfoKeyW
RegOpenKeyExW
RegEnumKeyExW
RegCloseKey
RegEnumValueW
RegQueryValueExW
api-ms-win-core-string-l1-1-0.dll

api-ms-win-core-string-l2-1-0.dll

api-ms-win-core-string-obsolete-l1-1-0.dll

api-ms-win-core-synch-l1-2-0.dll

SetEvent
WaitForSingleObject
Sleep
CreateEventW
EnterCriticalSection
InitializeCriticalSection
DeleteCriticalSection
LeaveCriticalSection
api-ms-win-core-sysinfo-l1-2-0.dll

GetVersionExW
GetTickCount
GetSystemTimeAsFileTime
GetSystemInfo
api-ms-win-core-threadpool-legacy-l1-1-0.dll

DeleteTimerQueueEx
DeleteTimerQueueTimer
CreateTimerQueueTimer
CreateTimerQueue
cryptbase.dll

kernel32.dll

DeleteTimerQueueEx
CloseHandle
Sleep
WaitForMultipleObjects
CreateEventW
HeapSetInformation
WaitForSingleObject
SetEvent
CreateThread
DeleteTimerQueueTimer
CreateTimerQueueTimer
GetCurrentProcessId
DuplicateHandle
GetCurrentProcess
RaiseException
GetLastError
CreateTimerQueue
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSection
DeleteCriticalSection
InterlockedDecrement
InterlockedIncrement
InterlockedExchange
InterlockedCompareExchange
GetStartupInfoW
SetUnhandledExceptionFilter
BindIoCompletionCallback
WriteFile
ReadFile
HeapFree
GetProcessHeap
HeapAlloc
UnhandledExceptionFilter
TerminateProcess
GetSystemTimeAsFileTime
GetCurrentThreadId
GetTickCount
QueryPerformanceCounter
GetModuleHandleA
msvcrt.dll
mswsock.dll

AcceptEx
GetAcceptExSockaddrs
ole32.dll

CoCreateInstance
CoTaskMemFree
CoTaskMemAlloc
CoUninitialize
CoInitializeEx
CLSIDFromString
ws2_32.dll
