Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

2001.12.4414.706 50.82%
2001.12.4414.706 1.64%
2001.12.4414.706 7.92%
2001.12.4414.706 2.19%
2001.12.4414.706 0.55%
2001.12.4414.706 3.55%
2001.12.4414.706 2.46%
2001.12.4414.706 0.55%
2001.12.4414.706 1.37%
2001.12.4414.706 0.27%
2001.12.4414.706 1.09%
2001.12.4414.706 0.55%
2001.12.4414.706 0.27%
2001.12.4414.706 0.82%
2001.12.4414.706 0.27%
2001.12.4414.706 1.09%
2001.12.4414.706 1.37%
2001.12.4414.706 1.64%
2001.12.4414.706 0.55%
2001.12.4414.706 0.27%
2001.12.4414.706 0.27%
2001.12.4414.701 3.01%
2001.12.4414.701 0.27%
2001.12.4414.701 0.27%
2001.12.4414.701 0.27%
View more

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
RegQueryInfoKeyW, SetThreadToken, CryptAcquireContextW, CryptGenRandom, CryptReleaseContext, RegSetValueExW, RegCreateKeyExW, RegisterServiceCtrlHandlerW, RegDeleteValueW, DeleteService, OpenSCManagerW, OpenServiceW, ChangeServiceConfigW, CreateServiceW, ChangeServiceConfig2W, CloseServiceHandle, ControlService, QueryServiceStatus, SetServiceStatus, RegEnumKeyExW, ConvertStringSecurityDescriptorToSecurityDescriptorW, MakeAbsoluteSD, MakeSelfRelativeSD, IsValidSecurityDescriptor, OpenThreadToken, OpenProcessToken, GetTokenInformation, GetLengthSid, InitializeAcl, AddAccessAllowedAce, GetSecurityDescriptorLength, RegDeleteKeyW, RegOpenKeyExW, RegQueryValueExW, DeregisterEventSource, ReportEventW, RegisterEventSourceW, RegOpenKeyW, AllocateAndInitializeSid, FreeSid, SetSecurityDescriptorDacl, SetSecurityDescriptorSacl, SetSecurityDescriptorGroup, SetSecurityDescriptorOwner, InitializeSecurityDescriptor, CheckTokenMembership, GetSidSubAuthority, GetSidSubAuthorityCount, GetSidIdentifierAuthority, IsValidSid, LookupAccountSidW, AdjustTokenPrivileges, LookupPrivilegeValueW, RegUnLoadKeyW, RegLoadKeyW, RegEnumValueW, RegCloseKey, EqualSid, GetUserNameW
comres.dll
COMResModuleInstance
kernel32.dll
GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, MultiByteToWideChar, ReleaseMutex, DebugBreak, RaiseException, CreateFileW, GetWindowsDirectoryW, CreateMutexW, GetLocalTime, WriteFile, SetFilePointer, lstrcatA, lstrcpyA, lstrlenA, InterlockedCompareExchange, GetModuleHandleW, LocalFree, GetSystemInfo, CreateSemaphoreW, Sleep, ReleaseSemaphore, SetLastError, GetComputerNameW, GetCurrentThread, WideCharToMultiByte, GetSystemDirectoryW, SearchPathW, GlobalFree, GlobalAlloc, GlobalMemoryStatusEx, ResetEvent, CreateThread, DuplicateHandle, CreateEventA, InitializeCriticalSection, PostQueuedCompletionStatus, InterlockedExchangeAdd, QueryPerformanceFrequency, CreateIoCompletionPort, InterlockedExchange, FreeLibraryAndExitThread, GetQueuedCompletionStatus, SetThreadPriority, OutputDebugStringA, GetTickCount, lstrcmpA, lstrcmpiW, GetModuleFileNameA, VirtualQueryEx, lstrcpynW, LockResource, LoadResource, FindResourceW, FindClose, DeleteFileW, SetFileAttributesW, FindNextFileW, FindFirstFileW, GetExitCodeProcess, CreateProcessW, ExpandEnvironmentStringsW, CreateDirectoryW, GetThreadContext, IsDebuggerPresent, LoadLibraryExW, GetModuleHandleA, FormatMessageW, GetFileAttributesW, GetModuleFileNameW, GetLastError, DisableThreadLibraryCalls, GetVersionExA, LoadLibraryW, GetProcAddress, FreeLibrary, lstrcatW, lstrcpyW, CreateEventW, WaitForSingleObject, CloseHandle, GetCurrentThreadId, SetEvent, GetUserDefaultLCID, InterlockedDecrement, CompareStringW, lstrcmpW, InterlockedIncrement, lstrlenW, LeaveCriticalSection, EnterCriticalSection, DeleteCriticalSection, LoadLibraryA, QueryPerformanceCounter, GetVersionExW
msvcrt.dll
DllMain
ntdll.dll
RtlDelete, RtlSplay, RtlInitializeCriticalSectionAndSpinCount, RtlDeleteCriticalSection, RtlInitializeCriticalSection
ole32.dll
StringFromCLSID, CoGetMalloc, CoGetObjectContext, FreePropVariantArray, PropVariantClear, PropVariantCopy, CoUnmarshalInterface, IIDFromString, StringFromIID, CoUninitialize, CoRevokeClassObject, CoRegisterClassObject, CoRevertToSelf, CoImpersonateClient, CoMarshalInterface, CreateStreamOnHGlobal, CoGetInterceptorFromTypeInfo, CoCreateInstance, CoEnableCallCancellation, CoDisableCallCancellation, StringFromGUID2, CoGetObject, CoCreateGuid, CLSIDFromString, CoGetClassObject, CoSetProxyBlanket, CoCancelCall, CoTaskMemFree, CoTaskMemAlloc, CoInitializeEx
rpcrt4.dll
NdrCStdStubBuffer_Release, NdrCStdStubBuffer2_Release, NdrDllUnregisterProxy, CStdStubBuffer_DebugServerRelease, CStdStubBuffer_DebugServerQueryInterface, NdrDllRegisterProxy, CStdStubBuffer_CountRefs, CStdStubBuffer_IsIIDSupported, CStdStubBuffer_Invoke, CStdStubBuffer_Disconnect, CStdStubBuffer_Connect, CStdStubBuffer_AddRef, CStdStubBuffer_QueryInterface, NdrStubCall2, NdrStubForwardingFunction, IUnknown_Release_Proxy, IUnknown_AddRef_Proxy, IUnknown_QueryInterface_Proxy, NdrOleFree, NdrOleAllocate, I_RpcBindingInqTransportType, NdrDllGetClassObject
user32.dll
wsprintfW, LoadStringW, DialogBoxParamW, EndDialog, SetDlgItemTextW, CloseWindowStation, GetProcessWindowStation, OpenWindowStationW, SetProcessWindowStation, GetDesktopWindow, GetWindowRect, GetClientRect, MapWindowPoints, SetWindowPos, OpenDesktopW, SetThreadDesktop, GetThreadDesktop, CloseDesktop, PeekMessageW, MsgWaitForMultipleObjects, PostThreadMessageW, wsprintfA
version.dll
VerQueryValueW
Export table
DllCanUnloadNow
DllGetClassObject
DllRegisterServer
DllUnregisterServer
LCEControlServer
NotifyLogoffUser
NotifyLogonUser
RegisterTheEventServiceAfterSetup
RegisterTheEventServiceDuringSetup
ServiceMain

es.dll

COM Services by Microsoft

Remove es.dll
Version:   2001.12.4414.701
MD5:   76abf3bb5a6d684641ec92b28240811d
SHA1:   bd71218f54e0f36580b2bacadd9bcef524c421b8
This is a Windows system installed file with Windows File Protection (WFP) enabled.

What is es.dll?

es.dll COM+ EventSystem Library for Microsoft Windows. COM+ is an evolution of Microsoft Component Object Model (COM) and Microsoft Transaction Server (MTS). COM+ builds on and extends applications written using COM, MTS, and other COM-based technologies. COM+ handles many of the resource management tasks that you previously had to program yourself, such as thread allocation and security.

About es.dll (from Microsoft)

COM+ also makes your applications more scalable by providing thread pooling, object pooling, and just-in-time object activation. COM+ also helps protect the integrity of your data by providing transac

DetailsDetails

File name:es.dll
Publisher:Microsoft Corporation
Product name:COM Services
Typical file path:C:\Windows\System32\es.dll
File version:2001.12.4414.701
Product version:03.00.00.4414
Size:240.5 KB (246,272 bytes)
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

BehaviorsBehaviors

Hosted services
Runs as a shared service under the Windows svcHost
  • Shared name is 'EventSystem'
  • Shared name is 'EventSystem'
  • Shared name is 'EventSystem'
  • Shared name is 'EventSystem'
  • Shared name is 'EventSystem'
  • Shared name is 'EventSystem'
  • Shared name is 'EventSystem'
  • Shared name is 'EventSystem'
  • Shared name is 'EventSystem'
  • Shared name is 'EventSystem'
  • Shared name is 'EventSystem'
  • Shared name is 'EventSystem'
  • Shared name is 'EventSystem'
  • Shared name is 'EventSystem'
  • Shared name is 'EventSystem'
  • Shared name is 'EventSystem'
  • Shared name is 'EventSystem'
  • Shared name is 'EventSystem'
  • Shared name is 'EventSystem'
  • Shared name is 'EventSystem'
  • Shared name is 'EventSystem'
  • Shared name is 'EventSystem'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 100.00%

Distribution by countryDistribution by country

United States installs about 34.21% of COM Services.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 34.19%
Intel 11.11%
American Megatrends 10.26%
Compaq 8.55%
Toshiba 6.84%
GIGABYTE 5.56%
ASUS 5.13%
Hewlett-Packard 5.13%
Sahara 4.27%
Lenovo 2.56%
Gateway 2.56%
Acer 2.14%
Sony 0.85%
MSI 0.85%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE