vssvc.exe
Microsoft Volume Shadow Copy Service by Microsoft
| Version: | 6.0.6002.18005 (lh_sp2rtm.090410-1830) |
| MD5: | db3d19f850c6eb32bdcb9bc0836acddb |
| SHA1: | 2e5e65e474ab777328cc14e99073d7f22905e25c |
| SHA256: | d81ff1cda87a2fe83efd5b3fe01eff940952f8baee70bea3b2f6ef30e2121704 |
This is a Windows system installed file with Windows File Protection (WFP) enabled.
What is vssvc.exe?
The Volume Shadow Copy Service provides the backup infrastructure for the Microsoft Windows, as well as a mechanism for creating consistent point-in-time copies of data known as shadow copies. The Volume Shadow Copy Service can produce consistent shadow copies by coordinating with business applications, file-system services, backup applications, fast-recovery solutions, and storage hardware.
About vssvc.exe (from Microsoft)
“The Volume Shadow Copy Service (VSS) is a set of COM APIs that implements a framework to allow volume backups to be performed while applications on a system continue to write to the volumes. VSS provi”
Details
| File name: | vssvc.exe |
| Publisher: | Microsoft Corporation |
| Product name: | Microsoft® Volume Shadow Copy Service |
| Description: | Microsoft® Windows® Operating System |
| Typical file path: | C:\Windows\System32\vssvc.exe |
| Original name: | VSSVC.EXE.MUI |
| File version: | 6.0.6002.18005 (lh_sp2rtm.090410-1830) |
| Product version: | 6.0.6002.18005 |
| Size: | 1.01 MB (1,055,232 bytes) |
| Digital DNA |
| PE subsystem: | Windows GUI |
| Entropy: | 6.003843 |
| File packed: | No |
| Code language: | Microsoft Visual C++ |
| .NET CLR: | No |
More details
Behaviors
Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
- 'VSS' (Kötet árnyékmásolata)
- 'VSS'
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
| CPU |
| Total CPU: | 0.03953887% | |
| Kernel CPU: | 0.02958736% | |
| User CPU: | 0.00995151% | |
| Kernel CPU time: | 144,492 ms/min | |
| CPU cycles: | 46,270/sec | |
| Memory |
| Private memory: | 7.71 MB | |
| Private (maximum): | 10.73 MB | |
| Private (minimum): | 6.35 MB | |
| Non-paged memory: | 7.71 MB | |
| Virtual memory: | 71.5 MB | |
| Virtual memory (peak): | 75.45 MB | |
| Working set: | 6.17 MB | |
| Working set (peak): | 12.41 MB | |
| Page faults: | 6,952/min | |
| I/O |
| I/O read transfer: | 130 Bytes/sec | |
| I/O read operations: | 1/sec | |
| I/O write transfer: | 132 Bytes/sec | |
| I/O write operations: | 1/sec | |
| I/O other transfer: | 400 Bytes/sec | |
| I/O other operations: | 11/sec | |
| Resource allocations |
| Threads: | 5 | |
| Handles: | 160 | |
Process properties
| Integrety level: | System |
| Platform: | 32-bit |
| Command line: | C:\Windows\System32\vssvc.exe |
| Owner: | SYSTEM |
| Windows Service |
| Service name: | VSS |
| Display name: | Kötet árnyékmásolata |
| Description: | “Gere e implementa cópias sombra de volume utilizadas para cópia de segurança, entre outros propósitos. Se este serviço for parado, as cópias sombra não estarão disponíveis para cópia de segurança e esta poderá falhar. Se este serviço estiver desactivado, não será possível iniciar qualquer serviço que dependa explicitamente dele.” |
| Type: | Win32OwnProcess |
| Parent process: | services.exe (Services and Controller app by Microsoft) |
Threads
Averages
| RPCRT4.dll |
| Total CPU: | 0.02004733% | |
| Kernel CPU: | 0.00000000% | |
| User CPU: | 0.02004733% | |
| CPU cycles: | 213,108/sec | |
| Context switches: | 2/sec | |
| Memory: | 780 KB | |
| msvcrt.dll (Windows NT CRT DLL by Microsoft) |
| Total CPU: | 0.01575272% | |
| Kernel CPU: | 0.01152383% | |
| User CPU: | 0.00422888% | |
| CPU cycles: | 356,754/sec | |
| Context switches: | 4/sec | |
| Memory: | 680 KB | |
| vssvc.exe (main module) |
| Total CPU: | 0.00363402% | |
| Kernel CPU: | 0.00256349% | |
| User CPU: | 0.00107053% | |
| CPU cycles: | 60,189/sec | |
| Memory: | 1.02 MB | |
| ADVAPI32.dll |
| Total CPU: | 0.00152337% | |
| Kernel CPU: | 0.00004522% | |
| User CPU: | 0.00147815% | |
| CPU cycles: | 61,456/sec | |
| Context switches: | 1/sec | |
| Memory: | 792 KB | |
Common loaded modules
These are modules that are typiclaly loaded within the context of this process.
Distribution by Windows OS
| OS version | distribution |
| Windows 7 Home Premium |
57.50% |
|
| Windows 7 Ultimate |
25.50% |
|
| Windows 7 Professional |
9.00% |
|
| Windows Vista Home Premium |
4.50% |
|
| Windows 7 Home Basic |
2.00% |
|
| Windows 7 Starter |
1.00% |
|
| Windows Vista Home Basic |
0.50% |
|
Distribution by country
United States installs about 51.76% of Microsoft® Volume Shadow Copy Service.
Distribution by PC manufacturer
| PC Manufacturer | distribution |
| Dell |
25.19% |
|
| Hewlett-Packard |
20.61% |
|
| ASUS |
12.98% |
|
| Toshiba |
12.21% |
|
| Acer |
10.31% |
|
| Lenovo |
3.82% |
|
| Sony |
3.05% |
|
| GIGABYTE |
3.05% |
|
| Samsung |
2.29% |
|
| MSI |
2.29% |
|
| Gateway |
1.53% |
|
| Alienware |
0.76% |
|
| Medion |
0.76% |
|
| Intel |
0.76% |
|
| Sahara |
0.38% |
|