File details
File name: lsm.exe
Name: Local Session Manager Service
Description: Microsoft® Windows® Operating System
Version: 6.1.7600.16385 (win7_rtm.090713-1255)
Product version: 6.1.7600.16385
Size: 261.5 KB
Original file name: lsm.exe.mui
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0017599336%
Privileged CPU:
0.0010917595%

User CPU:
0.00066817405716%

Privileged CPU time: 2823404.12 ms
Privileged CPU time /min: 628 ms
CPU cycle count:
412,384,457
CPU cycle count /min: 7,214,812
Context switches /sec:
14
 | Memory utilization averages |
Committed memory:
18.13 MB
Peak committed memory: 20.1 MB
Paged memory:
1.55 MB
Peak paged memory: 3.19 MB
Paged system memory:
30.39 KB
Non-paged system memory: 4.21 KB
Working set memory:
2.34 MB
Peak working set memory: 3.45 MB
Min working set memory: 2.03 MB
Private memory:
1.55 MB
Page faults:
3,415
Page faults /min: 7
 | Process I/O averages |
Total read operations:
27
Read operations /min: 1
Total read transfer: 116.11 KB
Read transfer /min: 2.2 KB
Total write operations:
4
Write operations /min: 1
Total write transfer: 1.94 KB
Write transfer /min: 0 Bytes
Total other operations:
140
Other operations /min: 1
Total other transfer: 1.75 KB
Other Transfer /min: 5 Bytes
Resources
Handle count average: 173
Thread count average: 11
Thread resource averages
ntdll.dll

Total CPU: 0.046164153144%
Privileged CPU: 0.030022801145%
User CPU: 0.016141351999%
CPU Cycle count /sec: 1,587,218
Context switches /sec: 19
Module memory size: 1.23 MB
ntdll.dll

Total CPU: 0.013246967190%
Privileged CPU: 0.007895196769%
User CPU: 0.005351770421%
CPU Cycle count /sec: 136,762
Context switches /sec: 1
Module memory size: 1.23 MB
ntdll.dll

Total CPU: 0.005971638958%
Privileged CPU: 0.003985995896%
User CPU: 0.001985643062%
CPU Cycle count /sec: 58,938
Module memory size: 1.23 MB
Total CPU: 0.000494297570%
Privileged CPU: 0.000390604593%
User CPU: 0.000103692977%
CPU Cycle count /sec: 7,182
Module memory size: 272 KB
Total CPU: 0.000019736569%
Privileged CPU: 0.000000000000%
User CPU: 0.000019736569%
CPU Cycle count /sec: 324
Module memory size: 532 KB
Process details
Runs as (owner): System
Integrety level: System
Windows platform: 32-bit
Parent Process
Process Commands
C:\Windows\system32\lsm.exe
C:\Windows\system32\lsm.exe
C:\Windows\System32\lsm.exe
Image hashes
MD5: 8aea9a37c1a3565a204d37c5e72ab791
SHA-1: e16beae2233832547bac23fbd82d5321cfc5d645
SHA-256: 939903f93ff37525a6c4b5cba29cdeee6d6055c42d605e80ae787f2a76f9870e
PE image details
Langauge*: Microsoft Visual C++
File entropy: 6.50647
File packed: No
Import Table
advapi32.dll

TraceMessage
GetTraceEnableFlags
GetTraceEnableLevel
GetTraceLoggerHandle
RegisterTraceGuidsW
UnregisterTraceGuids
RegCloseKey
RegQueryValueExW
RegOpenKeyExW
SetSecurityDescriptorDacl
SetEntriesInAclW
SetSecurityDescriptorGroup
SetSecurityDescriptorOwner
InitializeSecurityDescriptor
GetTokenInformation
OpenProcessToken
OpenThreadToken
RegNotifyChangeKeyValue
AdjustTokenPrivileges
CloseServiceHandle
OpenSCManagerW
RevertToSelf
ImpersonateLoggedOnUser
LogonUserW
OpenServiceW
RegSetValueExW
NotifyServiceStatusChangeW
AccessCheckAndAuditAlarmW
SetThreadToken
DuplicateTokenEx
AuditFree
AuditQuerySystemPolicy
QueryServiceStatus
CreateWellKnownSid
MakeSelfRelativeSD
MakeAbsoluteSD
CheckTokenMembership
QueryServiceConfigW
StartServiceW
DuplicateToken
LookupAccountSidW
AddAce
GetAce
InitializeAcl
CopySid
GetLengthSid
GetAclInformation
GetSecurityDescriptorDacl
LsaFreeMemory
LsaGetUserName
ControlTraceW
StartTraceW
EnableTrace
QueryTraceW
ReportEventW
DeregisterEventSource
RegisterEventSourceW
IsValidSecurityDescriptor
RegCreateKeyExW
RegConnectRegistryW
RegOpenCurrentUser
I_ScSendTSMessage
RegEnumKeyExW
RegDeleteKeyW
GetSecurityDescriptorLength
PerfSetCounterRefValue
PerfCreateInstance
PerfStopProvider
PerfSetCounterSetInfo
PerfStartProvider
api-ms-win-core-errorhandling-l1-1-0.dll

SetUnhandledExceptionFilter
UnhandledExceptionFilter
GetLastError
api-ms-win-core-handle-l1-1-0.dll

CloseHandle
DuplicateHandle
api-ms-win-core-heap-l1-1-0.dll

api-ms-win-core-interlocked-l1-1-0.dll

InterlockedIncrement
InterlockedDecrement
InterlockedExchange
InterlockedCompareExchange
api-ms-win-core-libraryloader-l1-1-0.dll

LoadStringW
GetModuleHandleW
GetProcAddress
FreeLibrary
GetModuleHandleA
LoadLibraryExA
api-ms-win-core-localregistry-l1-1-0.dll

RegNotifyChangeKeyValue
RegQueryValueExW
RegOpenKeyExW
RegSetValueExW
RegCloseKey
api-ms-win-core-misc-l1-1-0.dll

api-ms-win-core-processthreads-l1-1-0.dll

OpenProcessToken
OpenThreadToken
GetCurrentThread
ProcessIdToSessionId
SetThreadToken
GetCurrentProcess
GetProcessId
GetCurrentThreadId
GetCurrentProcessId
TerminateProcess
api-ms-win-core-profile-l1-1-0.dll

api-ms-win-core-synch-l1-1-0.dll

WaitForSingleObject
OpenEventW
SetEvent
InitializeCriticalSection
OpenProcess
CreateEventW
WaitForMultipleObjectsEx
ResetEvent
DeleteCriticalSection
api-ms-win-core-sysinfo-l1-1-0.dll

GetTickCount
GetSystemTimeAsFileTime
GetTickCount64
api-ms-win-core-threadpool-l1-1-0.dll

api-ms-win-security-base-l1-1-0.dll

SetSecurityDescriptorGroup
CopySid
InitializeSecurityDescriptor
GetTokenInformation
AdjustTokenPrivileges
SetSecurityDescriptorDacl
GetLengthSid
IsValidSid
DuplicateTokenEx
GetSecurityDescriptorLength
CreateWellKnownSid
MakeSelfRelativeSD
MakeAbsoluteSD
CheckTokenMembership
DuplicateToken
AddAce
GetAce
InitializeAcl
GetAclInformation
GetSecurityDescriptorDacl
RevertToSelf
ImpersonateLoggedOnUser
AccessCheckAndAuditAlarmW
IsValidSecurityDescriptor
EqualSid
SetSecurityDescriptorOwner
api-ms-win-service-management-l1-1-0.dll

OpenSCManagerW
OpenServiceW
StartServiceW
CloseServiceHandle
api-ms-win-service-management-l2-1-0.dll

QueryServiceConfigW
NotifyServiceStatusChangeW
api-ms-win-service-winsvc-l1-1-0.dll

QueryServiceStatus
I_ScSendTSMessage
kernel32.dll

QueueUserWorkItem
GetComputerNameW
WaitForMultipleObjects
RegisterWaitForSingleObject
LoadLibraryW
DelayLoadFailureHook
HeapAlloc
GetProcessHeap
HeapFree
ExpandEnvironmentStringsW
SetLastError
OutputDebugStringA
RtlCaptureStackBackTrace
LocalSize
SleepEx
GetVersionExW
CreateProcessW
DebugBreak
IsDebuggerPresent
GetSystemDirectoryW
RegCreateKeyExW
RegOpenCurrentUser
RegEnumKeyExW
VerifyVersionInfoW
VerSetConditionMask
LocalAlloc
UnhandledExceptionFilter
TerminateProcess
GetSystemTimeAsFileTime
GetCurrentProcessId
GetCurrentThreadId
GetTickCount
QueryPerformanceCounter
GetModuleHandleA
FormatMessageW
DeleteCriticalSection
GetProcAddress
InitializeCriticalSection
InterlockedCompareExchange
GetProcessId
UnregisterWaitEx
OpenProcess
DuplicateHandle
InterlockedExchange
ProcessIdToSessionId
HeapSetInformation
SetUnhandledExceptionFilter
CreateEventW
WaitForSingleObject
Sleep
InterlockedDecrement
InterlockedIncrement
WaitForMultipleObjectsEx
GetCurrentThread
GetCurrentProcess
CloseHandle
LocalFree
ResetEvent
OpenEventW
GetLastError
SetEvent
FreeLibrary
msvcrt.dll
ntdll.dll

NtDelayExecution
RtlUnhandledExceptionFilter
EtwUnregisterTraceGuids
EtwRegisterTraceGuidsW
EtwGetTraceLoggerHandle
EtwGetTraceEnableLevel
EtwGetTraceEnableFlags
EtwTraceMessage
EtwEventWrite
RtlInitializeResource
EtwEventUnregister
RtlDeleteResource
NtNotifyChangeSession
RtlInsertElementGenericTable
RtlLookupElementGenericTable
RtlDeleteElementGenericTable
NtOpenEvent
RtlInitUnicodeString
RtlInitializeGenericTable
RtlEnumerateGenericTable
NtOpenSession
NtSetSystemInformation
NtQuerySystemTime
NtFreeVirtualMemory
NtAllocateVirtualMemory
RtlConnectToSm
RtlSendMsgToSm
NtDuplicateToken
RtlRaiseException
RtlAcquireResourceExclusive
RtlAcquireResourceShared
RtlReleaseResource
NtQuerySystemInformation
RtlEqualSid
NtSetSecurityObject
NtQuerySecurityObject
NtOpenSymbolicLinkObject
NtQueryDirectoryObject
NtCreateDirectoryObject
NtQueryValueKey
NtOpenKey
NtDuplicateObject
NtQueryInformationProcess
RtlMapGenericMask
RtlGetAce
RtlQueryInformationAcl
RtlGetDaclSecurityDescriptor
RtlCreateUserSecurityObject
RtlGetOwnerSecurityDescriptor
RtlDeleteAce
RtlSetGroupSecurityDescriptor
RtlCopySecurityDescriptor
RtlGetGroupSecurityDescriptor
NtTerminateProcess
NtWaitForSingleObject
RtlPrefixUnicodeString
NtClose
NtCreateEvent
RtlNumberGenericTableElements
RtlFreeSid
RtlSetDaclSecurityDescriptor
RtlAddAccessAllowedAce
RtlCreateAcl
RtlCreateSecurityDescriptor
RtlLengthSid
RtlAllocateAndInitializeSid
NtCreatePort
NtCompleteConnectPort
NtAcceptConnectPort
NtReplyPort
DbgPrint
NtOpenProcess
NtCreateSection
NtReplyWaitReceivePort
RtlNtStatusToDosError
NtQueryLicenseValue
RtlLeaveCriticalSection
RtlEnterCriticalSection
RtlAdjustPrivilege
NtQueryInformationToken
EtwEventRegister
DbgBreakPoint
rpcrt4.dll

RpcServerTestCancel
NdrAsyncServerCall
NdrServerCall2
RpcImpersonateClient
RpcRevertToSelf
I_RpcMapWin32Status
UuidCreate
UuidToStringW
RpcAsyncCompleteCall
RpcServerSubscribeForNotification
RpcServerInqCallAttributesW
RpcServerInqDefaultPrincNameW
RpcServerRegisterAuthInfoW
RpcServerUnsubscribeForNotification
I_RpcBindingIsClientLocal
I_RpcBindingInqLocalClientPID
RpcServerUseProtseqEpW
RpcServerRegisterIfEx
RpcServerListen
RpcBindingToStringBindingW
RpcStringBindingParseW
RpcMgmtWaitServerListen
RpcStringFreeW
UuidFromStringW
sysntfy.dll

wmsgapi.dll
