File details
File name: sppsvc.exe
Name: Microsoft Software Protection Platform Service
Description: Microsoft® Windows® Operating System
Version: 6.1.7600.16385 (win7_rtm.090713-1255)
Product version: 6.1.7600.16385
Size: 3.03 MB
Original file name: sppsvc.exe.mui
Windows file protection:
Yes
Digital certificate
Certificate authority:
Microsoft Corporation
Expiration date: 7/9/2013
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0157214962%
Privileged CPU:
0.0083644470%

User CPU:
0.00735704919285%

Privileged CPU time: 1087883.83 ms
Privileged CPU time /min: 256 ms
CPU cycle count:
11,022,425
CPU cycle count /min: 31,666,067
Context switches /sec:
2
 | Memory utilization averages |
Committed memory:
30.26 MB
Peak committed memory: 32.11 MB
Paged memory:
4.97 MB
Peak paged memory: 6.71 MB
Paged system memory:
37.23 KB
Non-paged system memory: 3.78 KB
Working set memory:
4.66 MB
Peak working set memory: 11.16 MB
Min working set memory: 4.03 MB
Private memory:
4.97 MB
Page faults:
6,052
Page faults /min: 29
 | Process I/O averages |
Total read operations:
5,108
Read operations /min: 3
Total read transfer: 12.67 MB
Read transfer /min: 12.34 KB
Total write operations:
48
Write operations /min: 1
Total write transfer: 2.4 MB
Write transfer /min: 1.6 KB
Total other operations:
2,895
Other operations /min: 14
Total other transfer: 8.34 KB
Other Transfer /min: 28 Bytes
Resources
Handle count average: 150
Thread count average: 4
Thread resource averages
ntdll.dll

Total CPU: 0.074152324974%
Privileged CPU: 0.021822179761%
User CPU: 0.052330145213%
CPU Cycle count /sec: 1,402,774
Module memory size: 1.23 MB
ntdll.dll

Total CPU: 0.027481433552%
Privileged CPU: 0.013242548855%
User CPU: 0.014238884697%
CPU Cycle count /sec: 666,001
Module memory size: 1.23 MB
ntdll.dll

Total CPU: 0.004216842722%
Privileged CPU: 0.001732604374%
User CPU: 0.002484238349%
CPU Cycle count /sec: 99,702
Module memory size: 1.23 MB
msvcrt.dll

Total CPU: 0.001108702121%
Privileged CPU: 0.001108644474%
User CPU: 0.000000057647%
CPU Cycle count /sec: 20,070
Module memory size: 688 KB
Total CPU: 0.000741694047%
Privileged CPU: 0.000619163119%
User CPU: 0.000122530929%
CPU Cycle count /sec: 14,693
Module memory size: 3.04 MB
msvcrt.dll

Total CPU: 0.000018161124%
Privileged CPU: 0.000018161124%
User CPU: 0.000000000000%
CPU Cycle count /sec: 488
Module memory size: 688 KB
Process details
Runs as (owner): User
Integrety level: System
Windows platform: 32-bit
Runs as a service: Yes
Parent Process
Process Command
C:\Windows\system32\sppsvc.exe
Service details
Name: Προστασία λογισμικού
Service name: sppsvc
Service type:
Win32OwnProcess
Description: “Επιτρέπει τη λήψη, εγκατάσταση και επιβολή των ψηφιακών αδειών χρήσης για τα Windows και τις εφαρμογές Windows. Αν η υπηρεσία είναι απενεργοποιημένη, το λειτουργικό σύστημα και οι εφαρμογές με άδεια χρήσης ενδέχεται να εκτελούνται σε κατάσταση ειδοποιήσεων. Συνιστάται η μη απενεργοποίηση της υπηρεσίας προστασίας λογισμικού.”
Image hashes
MD5: cf87a1de791347e75b98885214ced2b8
SHA-1: e37c4d715a3a6ae877e001ada718d98d963bc5de
SHA-256: 7af4e03d751c951a4e5fba28200dabfe6b3bf055490163eeeea84eba4d0f368a
PE image details
Subsystem: Windows Console
Langauge*: Microsoft Visual C++
File entropy: 7.35781
File packed: No
Import Table
advapi32.dll

TraceMessage
RegCloseKey
GetTraceEnableFlags
GetTraceEnableLevel
GetTraceLoggerHandle
RegisterTraceGuidsW
UnregisterTraceGuids
SetServiceStatus
RegOpenKeyExW
RegQueryValueExW
RegisterServiceCtrlHandlerW
StartServiceCtrlDispatcherW
FreeSid
RegDeleteKeyW
RegCreateKeyExW
CheckTokenMembership
AllocateAndInitializeSid
ConvertStringSidToSidW
RegEnumKeyW
RegQueryInfoKeyW
ConvertStringSecurityDescriptorToSecurityDescriptorW
RegSetKeySecurity
RegDeleteValueW
RegSetValueExW
CryptGenRandom
CryptAcquireContextW
CryptReleaseContext
DeregisterEventSource
ReportEventW
RegisterEventSourceW
EqualSid
OpenProcessToken
ConvertSidToStringSidW
LookupAccountNameW
RegEnumKeyExW
CryptDestroyHash
CryptHashData
CryptCreateHash
CryptGetHashParam
CryptDestroyKey
CryptEncrypt
CryptDecrypt
CryptImportKey
CryptSignHashA
CryptVerifySignatureA
CryptExportKey
CryptGenKey
RegisterTraceGuidsA
GetTokenInformation
RegQueryValueExA
RegisterServiceCtrlHandlerA
StartServiceCtrlDispatcherA
RegOpenKeyExA
kernel32.dll

Sleep
InitializeCriticalSectionAndSpinCount
WaitForSingleObject
GetCurrentThreadId
DeleteTimerQueueEx
ReleaseSemaphore
LoadLibraryW
SetThreadPriority
GetThreadPriority
DuplicateHandle
GetCurrentProcess
GetCurrentThread
OpenThread
GetTickCount
ReleaseMutex
CreateSemaphoreW
IsWow64Process
OpenMutexW
CreateMutexW
ExpandEnvironmentStringsW
GetTimeFormatW
GetDateFormatW
FileTimeToSystemTime
SetFileAttributesW
GetFileAttributesW
ChangeTimerQueueTimer
CreateDirectoryW
WriteFile
CreateFileW
GetFileSizeEx
QueueUserWorkItem
ReadFile
GetFileSize
MultiByteToWideChar
OpenProcess
GetCurrentProcessId
GetSystemInfo
CompareFileTime
SystemTimeToFileTime
GetSystemTimeAsFileTime
DeleteTimerQueue
WaitForMultipleObjects
GetDevicePowerState
CreateSemaphoreA
InterlockedExchangeAdd
GetPrivateProfileStringW
GetPrivateProfileSectionW
GetFullPathNameW
InitializeCriticalSection
SetLastError
VirtualProtect
VirtualFree
VirtualAlloc
GetLocalTime
MoveFileExW
CopyFileW
FlushFileBuffers
DeleteFileW
SetFilePointer
CreateFileMappingW
MapViewOfFile
GetModuleHandleW
UnmapViewOfFile
GetSystemDefaultUILanguage
GetUserDefaultUILanguage
GetComputerNameW
DeviceIoControl
GetLocaleInfoW
GetSystemDirectoryW
LCMapStringW
WideCharToMultiByte
GetVersionExA
GetVersion
VirtualQuery
UnhandledExceptionFilter
TerminateProcess
QueryPerformanceCounter
GetModuleHandleA
SetUnhandledExceptionFilter
InterlockedExchange
UnregisterWaitEx
SetEvent
GetModuleHandleExW
GetProcAddress
CreateTimerQueue
CreateTimerQueueTimer
CreateEventW
RegisterWaitForSingleObject
RaiseException
InterlockedDecrement
GetVersionExW
InterlockedIncrement
GetLastError
HeapSetInformation
DeleteTimerQueueTimer
LeaveCriticalSection
LocalFree
EnterCriticalSection
LocalAlloc
DeleteCriticalSection
FreeLibrary
CloseHandle
DecodePointer
EncodePointer
InterlockedCompareExchange
HeapFree
GetProcessHeap
HeapAlloc
lstrlenW
ExitThread
CreateProcessA
SetCurrentDirectoryA
ExitProcess
OpenEventA
msvcrt.dll
ntdll.dll

NtQueryInformationThread
NtSetInformationThread
RtlUnwind
RtlFreeHeap
RtlAllocateHeap
RtlInitUnicodeString
RtlEnterCriticalSection
RtlLeaveCriticalSection
RtlCopyUnicodeString
RtlCompareUnicodeString
ole32.dll

CoInitializeSecurity
CoUninitialize
CoInitializeEx
rpcrt4.dll

NdrServerCall2
RpcServerRegisterIfEx
RpcServerUseProtseqEpW
RpcServerListen
RpcServerUnregisterIf
RpcMgmtStopServerListening
I_RpcBindingInqLocalClientPID
RpcServerInqCallAttributesW
RpcRaiseException
RpcStringFreeW
RpcRevertToSelfEx
RpcImpersonateClient
UuidCreate
UuidFromStringW
UuidToStringW
I_RpcMapWin32Status
user32.dll

wsprintfA
GetDesktopWindow