File details
File name: alg.exe
Name: Application Layer Gateway Service
Description: Microsoft® Windows® Operating System
Version: 5.1.2600.5512 (xpsp.080413-0852)
Product version: 5.1.2600.5512
Size: 43.5 KB
Original file name: ALG.exe
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0008665979%
Privileged CPU:
0.0005425924%

User CPU:
0.00032400551607%

Privileged CPU time: 2231.59 ms
Privileged CPU time /min: 0 ms
Context switches /sec:
1
 | Memory utilization averages |
Committed memory:
33.12 MB
Peak committed memory: 34.52 MB
Paged memory:
1.73 MB
Peak paged memory: 1.96 MB
Paged system memory:
51.06 KB
Non-paged system memory: 5.74 KB
Working set memory:
2.37 MB
Peak working set memory: 4.25 MB
Min working set memory: 2.23 MB
Private memory:
1.73 MB
Page faults:
1,557
Page faults /min: 4
 | Process I/O averages |
Total read operations:
21
Read operations /min: 1
Total read transfer: 45.85 KB
Read transfer /min: 127 Bytes
Total write operations:
18
Write operations /min: 1
Total write transfer: 10.62 KB
Write transfer /min: 22 Bytes
Total other operations:
702
Other operations /min: 2
Total other transfer: 55.7 KB
Other Transfer /min: 180 Bytes
 | GUI Object Averages |
GDI objects:
4
USER objects:
2
Resources
Handle count average: 110
Thread count average: 6
Thread resource averages
npggnt.des

Total CPU: 0.020669700738%
Privileged CPU: 0.000000000000%
User CPU: 0.020669700738%
Module memory size: 284 KB
Total CPU: 0.001742966891%
Privileged CPU: 0.000835597913%
User CPU: 0.000907368978%
Module memory size: 52 KB
ntdll.dll

Total CPU: 0.000850929595%
Privileged CPU: 0.000551149525%
User CPU: 0.000299780069%
Module memory size: 712 KB
advapi32.dll

Total CPU: 0.000422838700%
Privileged CPU: 0.000168842025%
User CPU: 0.000253996675%
Module memory size: 620 KB
xpsp2res.dll

Total CPU: 0.000005031250%
Privileged CPU: 0.000002515625%
User CPU: 0.000002515625%
Module memory size: 2.77 MB
ntdll.dll

Total CPU: 0.000001025467%
Privileged CPU: 0.000000615280%
User CPU: 0.000000410187%
Module memory size: 712 KB
Process details
Runs as (owner): System
Integrety level: Undefined
Windows platform: 32-bit
Runs as a service: Yes
Parent Processes
Process Commands
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS.0\System32\alg.exe
C:\windows\System32\alg.exe
C:\WINDOWS\System32\alg.exe
Service details
Name: Служба шлюза уровня приложения
Service name: ALG
Service type:
Win32OwnProcess
Description: “Поддерживает сторонние подключаемые модули протокола для общего доступа к Интернету и брандмауэра Windows.”
Network connectivity
TCP: h88-150-199-196.host.redstation.co.uk on port 3337
TCP: localhost on port 1032
TCP: localhost on port 1069
TCP: localhost on port 1035
TCP: localhost on port 1027
TCP: localhost on port 1043
TCP: localhost on port 1025
TCP: localhost on port 1034
TCP: localhost on port 1030
TCP: localhost on port 1028
TCP: localhost on port 1029
TCP: localhost on port 1047
Image hashes
MD5: 8c515081584a38aa007909cd02020b3d
SHA-1: ef5728c819f466bfe56c36bc9db3fac004ef3d50
SHA-256: a5e13ca10f702928e0de84c74d0ea8accb117fd76fbabc55220c75c4ffd596dc
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File entropy: 6.22290
File packed: No
Import Table
advapi32.dll

RegOpenKeyExW
RegEnumKeyExW
RegQueryValueExW
StartServiceCtrlDispatcherW
RegNotifyChangeKeyValue
RegisterServiceCtrlHandlerW
SetServiceStatus
RegCloseKey
SystemFunction036
kernel32.dll

GetStartupInfoW
GetModuleHandleA
CreateThread
UnhandledExceptionFilter
TerminateProcess
GetSystemTimeAsFileTime
CreateTimerQueueTimer
ReadFile
GetCurrentProcessId
WriteFile
BindIoCompletionCallback
UnregisterWait
RegisterWaitForSingleObject
HeapAlloc
DeleteTimerQueueTimer
GetProcessHeap
HeapFree
DuplicateHandle
GetCurrentProcess
QueryPerformanceCounter
GetTickCount
SetUnhandledExceptionFilter
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSection
GetLastError
CreateTimerQueue
DeleteCriticalSection
InterlockedIncrement
InterlockedDecrement
DeleteTimerQueueEx
CloseHandle
Sleep
WaitForMultipleObjects
CreateEventW
WaitForSingleObject
SetEvent
GetCurrentThreadId
msvcrt.dll
ole32.dll

CoCreateInstance
CoTaskMemFree
CoTaskMemAlloc
CoUninitialize
CoInitializeEx
CLSIDFromString
ws2_32.dll

WSAEnumNetworkEvents
WSAConnect
WSAEventSelect
WSASocketW