File details
File name: vds.exe
Name: Virtual Disk Service
Description: Microsoft® Windows® Operating System
Version: 6.0.6001.18000 (longhorn_rtm.080118-1840)
Product version: 6.0.6001.18000
Size: 444 KB
Original file name: vds.exe.mui
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0000027284%
Privileged CPU:
0.0000020575%

User CPU:
0.00000067091676%

Privileged CPU time: 468003 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
107,717,861
 | Memory utilization averages |
Committed memory:
52.93 MB
Peak committed memory: 57.39 MB
Paged memory:
3.16 MB
Peak paged memory: 3.72 MB
Paged system memory:
102.66 KB
Non-paged system memory: 7.75 KB
Working set memory:
6.8 MB
Peak working set memory: 6.83 MB
Min working set memory: 6.8 MB
Private memory:
3.16 MB
Page faults:
1,975
Page faults /min: 0
 | Process I/O averages |
Total read operations:
3
Total read transfer: 172 Bytes
Total write operations:
3
Total write transfer: 188 Bytes
Total other operations:
1,145
Total other transfer: 1.52 KB
Resources
Handle count average: 100
Thread count average: 3
Process details
Runs as (owner): System
Integrety level: System
Windows platform: 64-bit
Runs as a service: Yes
Parent Process
Process Command
C:\Windows\System32\vds.exe
Service details
Name: Disque virtuel
Service name: vds
Service type:
Win32OwnProcess
Description: “Fournit des services de gestion des disques, des volumes, des systèmes de fichiers et des groupes de stockage.”
Image hashes
MD5: 294945381dfa7ce58cecf0a9896af327
SHA-1: c263b8632a79d761bcf0aec1d67ccf808f2c7fa4
SHA-256: 67414c6d79d2826bc86bb37349c9d74db4b667310cbc1abfd103e26332ae4a00
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File entropy: 6.40737
File packed: No
Import Table
advapi32.dll

SetServiceStatus
CloseServiceHandle
OpenServiceW
OpenSCManagerW
FreeSid
SetServiceObjectSecurity
AddAccessAllowedAce
GetLengthSid
IsValidSid
MakeAbsoluteSD
QueryServiceObjectSecurity
ChangeServiceConfig2W
CreateServiceW
DeleteService
ControlService
RegCloseKey
RegSetValueExW
RegOpenKeyW
GetSecurityDescriptorLength
MakeSelfRelativeSD
RegisterServiceCtrlHandlerW
StartServiceCtrlDispatcherW
RegQueryValueExW
RegEnumKeyExW
InitiateSystemShutdownExW
RegCreateKeyExW
RegOpenKeyExW
RegDeleteValueW
api-ms-win-core-debug-l1-1-0.dll

api-ms-win-core-errorhandling-l1-1-0.dll

GetLastError
SetUnhandledExceptionFilter
UnhandledExceptionFilter
SetLastError
api-ms-win-core-file-l1-1-0.dll

DefineDosDeviceW
DeleteVolumeMountPointW
GetVolumePathNameW
FindFirstVolumeW
FindNextVolumeW
FindVolumeClose
GetDriveTypeW
CreateFileW
SetFilePointerEx
WriteFile
QueryDosDeviceW
RemoveDirectoryW
api-ms-win-core-handle-l1-1-0.dll

api-ms-win-core-heap-l1-1-0.dll

HeapFree
HeapSetInformation
HeapAlloc
GetProcessHeap
api-ms-win-core-interlocked-l1-1-0.dll

InterlockedCompareExchange
InterlockedDecrement
InterlockedExchange
InterlockedIncrement
api-ms-win-core-io-l1-1-0.dll

api-ms-win-core-libraryloader-l1-1-0.dll

GetModuleFileNameW
GetProcAddress
GetModuleHandleW
FreeLibrary
LoadLibraryExA
GetModuleHandleA
api-ms-win-core-localregistry-l1-1-0.dll

RegCreateKeyExW
RegCloseKey
RegSetValueExW
RegDeleteValueW
RegOpenKeyExW
RegEnumKeyExW
RegQueryValueExW
api-ms-win-core-misc-l1-1-0.dll

lstrlenW
lstrcmpiW
LocalFree
FormatMessageW
Sleep
api-ms-win-core-processenvironment-l1-1-0.dll

api-ms-win-core-processthreads-l1-1-0.dll

SetThreadToken
OpenProcessToken
GetCurrentThreadId
OpenThreadToken
ResumeThread
GetStartupInfoW
GetCurrentProcessId
CreateThread
TerminateProcess
GetCurrentProcess
api-ms-win-core-profile-l1-1-0.dll

api-ms-win-core-string-l1-1-0.dll

api-ms-win-core-synch-l1-1-0.dll

WaitForSingleObject
InitializeCriticalSection
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
SetEvent
CreateEventW
ReleaseSemaphore
api-ms-win-core-sysinfo-l1-1-0.dll

GetTickCount
GetSystemTimeAsFileTime
api-ms-win-security-base-l1-1-0.dll

DuplicateTokenEx
FreeSid
AddAccessAllowedAce
GetLengthSid
IsValidSid
MakeAbsoluteSD
GetSecurityDescriptorLength
MakeSelfRelativeSD
AdjustTokenPrivileges
api-ms-win-service-core-l1-1-0.dll

StartServiceCtrlDispatcherW
SetServiceStatus
api-ms-win-service-management-l1-1-0.dll

CloseServiceHandle
OpenSCManagerW
OpenServiceW
DeleteService
CreateServiceW
api-ms-win-service-management-l2-1-0.dll

QueryServiceObjectSecurity
SetServiceObjectSecurity
ChangeServiceConfig2W
api-ms-win-service-winsvc-l1-1-0.dll

RegisterServiceCtrlHandlerW
ControlService
clusapi.dll

kernel32.dll

FindNextVolumeMountPointW
VirtualAlloc
FindVolumeMountPointClose
CreateSemaphoreW
GetVolumeNameForVolumeMountPointW
FindFirstVolumeMountPointW
LoadLibraryW
GetVolumePathNamesForVolumeNameW
SetVolumeMountPointW
WaitForMultipleObjects
DelayLoadFailureHook
GetSystemDirectoryW
ReadFile
VirtualFree
GetFileAttributesW
GetCurrentThread
GetCurrentThreadId
GetModuleFileNameW
OutputDebugStringW
GetCommandLineW
HeapSetInformation
DeviceIoControl
CreateFileW
WaitForSingleObject
GetProcAddress
ReleaseSemaphore
LocalFree
FormatMessageW
InterlockedDecrement
lstrlenW
FreeLibrary
Sleep
QueryDosDeviceW
FindVolumeClose
FindNextVolumeW
RemoveDirectoryW
FindFirstVolumeW
GetLastError
CreateThread
CreateEventW
lstrcmpiW
DeleteVolumeMountPointW
DefineDosDeviceW
GetVolumePathNameW
SetFilePointerEx
WriteFile
ResumeThread
SetLastError
HeapAlloc
WideCharToMultiByte
UnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
GetSystemTimeAsFileTime
GetCurrentProcessId
GetTickCount
QueryPerformanceCounter
GetModuleHandleA
SetUnhandledExceptionFilter
GetStartupInfoW
InterlockedCompareExchange
SetEvent
CloseHandle
InterlockedIncrement
InitializeCriticalSection
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InterlockedExchange
HeapFree
GetProcessHeap
GetModuleHandleW
msvcrt.dll
netapi32.dll

ntdll.dll

RtlInitializeResource
RtlDeleteResource
RtlReleaseResource
RtlAcquireResourceShared
RtlAcquireResourceExclusive
RtlConvertSharedToExclusive
RtlConvertExclusiveToShared
RtlAdjustPrivilege
NtQueryVolumeInformationFile
RtlCompareMemory
ole32.dll

CoInitializeEx
CoInitializeSecurity
CLSIDFromString
CoTaskMemAlloc
CoRevertToSelf
CoImpersonateClient
StringFromGUID2
CoCreateInstance
CoCreateGuid
CoTaskMemRealloc
CoUninitialize
CoTaskMemFree
osuninst.dll

setupapi.dll

SetupDiEnumDeviceInterfaces
CM_Get_Parent
CM_Reenumerate_DevNode_Ex
SetupDiEnumDeviceInfo
CM_Get_DevNode_Status
SetupDiGetCustomDevicePropertyW
SetupDiCallClassInstaller
SetupDiGetClassDevsW
SetupDiDestroyDeviceInfoList
CM_Query_And_Remove_SubTreeW
SetupDiGetDeviceInterfaceDetailW
shlwapi.dll

user32.dll

RegisterDeviceNotificationW
PeekMessageW
UnregisterDeviceNotification
GetMessageW
DefWindowProcW
CharNextW
PostThreadMessageW
LoadStringW
MessageBoxW
DispatchMessageW
vdsutil.dll
