Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

5.5.0.03040 28.13%
5.3.0.05310 18.75%
5.2.1.05130 4.69%
5.2.0.12300 1.56%
5.0.3.05060 15.63%
5.0.0.06050 4.69%
4.2.0.11050 1.56%
4.2.0.10070 4.69%
4.0.00.13310 7.81%
3.1.00.13250 7.81%
3.0.00.13060 1.56%
2.3.00.04130 1.56%
2.2.00.04040 1.56%

Relationships

Parent process
Child process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
CreateServiceW, RegEnumKeyExW, SetServiceStatus, RegisterEventSourceW, ReportEventW, DeregisterEventSource, RegQueryInfoKeyW, RegSetValueExW, RegQueryValueExW, RegOpenKeyExW, RegCreateKeyExW, RegCloseKey, RegDeleteValueW, RegDeleteKeyW, ControlService, ChangeServiceConfigW, OpenSCManagerW, OpenServiceW, QueryServiceConfigW, CloseServiceHandle, EqualSid, GetSecurityDescriptorDacl, AllocateAndInitializeSid, GetLengthSid, InitializeAcl, AddAccessDeniedAce, AddAccessAllowedAce, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, FreeSid, AdjustTokenPrivileges, OpenProcessToken, GetTokenInformation, LookupPrivilegeValueW, ChangeServiceConfig2W, CreateProcessAsUserW, SetTokenInformation, DuplicateTokenEx, RegisterServiceCtrlHandlerExW, StartServiceCtrlDispatcherW, DeleteService
crypt32.dll
CertFreeCertificateContext, CryptMsgClose, CertGetNameStringW, CertFindCertificateInStore, CryptMsgGetParam, CryptQueryObject, CertCloseStore
imm32.dll
ImmDisableIME
kernel32.dll
DuplicateHandle, OpenProcess, GetCurrentProcessId, MultiByteToWideChar, LoadLibraryExW, CancelWaitableTimer, SetWaitableTimer, CreateWaitableTimerW, GetCommandLineW, CreateFileW, CreateSemaphoreW, OpenSemaphoreW, OpenWaitableTimerW, GetCurrentThreadId, GetTickCount, HeapFree, HeapAlloc, GetProcessHeap, GetPrivateProfileIntW, QueryPerformanceCounter, GetStartupInfoW, GetModuleHandleA, ExitProcess, HeapSize, HeapReAlloc, HeapDestroy, GetVersionExA, GetSystemDefaultLCID, lstrcpynW, GetModuleFileNameW, lstrcatW, lstrcmpiW, InterlockedDecrement, InterlockedIncrement, FindResourceW, FindResourceExW, LoadResource, LockResource, SizeofResource, DeleteCriticalSection, InitializeCriticalSection, LeaveCriticalSection, EnterCriticalSection, Sleep, CreateThread, lstrcpyW, ResetEvent, ReleaseMutex, OpenFileMappingW, WaitForSingleObject, TerminateThread, SetEvent, WaitForMultipleObjects, LoadLibraryW, GetProcAddress, FreeLibrary, GlobalAlloc, GlobalFree, CreateFileMappingW, CreateMutexW, OpenMutexW, CreateEventW, OpenEventW, LocalAlloc, LocalFree, SetLastError, GetCurrentProcess, GetLastError, CloseHandle, lstrcmpW, lstrlenW, GetVersionExW, GetThreadLocale, GetLocaleInfoA, GetACP, InterlockedExchange, GetUserDefaultLCID, GetSystemTimeAsFileTime, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, TerminateProcess, HeapSetInformation, InterlockedCompareExchange, DecodePointer, WTSGetActiveConsoleSessionId, CreateProcessW, RaiseException, GetModuleHandleW, LoadLibraryA, InitializeCriticalSectionAndSpinCount, EncodePointer
msvcr100.dll
DllMain
msvcr70.dll
DllMain
msvcr80.dll
DllMain
ole32.dll
CoInitializeEx, CoUninitialize, CoSuspendClassObjects, StringFromGUID2, CoCreateInstance, CoResumeClassObjects, CoTaskMemRealloc, CoCreateFreeThreadedMarshaler, CoTaskMemFree, CoTaskMemAlloc, CoInitializeSecurity, CoRevokeClassObject, CoGetCurrentProcess, CoReleaseMarshalData, CreateStreamOnHGlobal, CoUnmarshalInterface, CLSIDFromString, CoInitialize, CoRegisterClassObject, CoMarshalInterface, CoAddRefServerProcess, CoReleaseServerProcess
psapi.dll
EnumProcessModules, GetModuleFileNameExW
shlwapi.dll
PathFileExistsW, PathFindExtensionW
user32.dll
CloseWindowStation, SetProcessWindowStation, PostMessageW, wsprintfW, RegisterDeviceNotificationW, MessageBoxW, MsgWaitForMultipleObjects, IsWindow, RegisterWindowMessageW, CharNextW, LoadStringW, CharUpperW, TranslateMessage, PeekMessageW, PostThreadMessageW, UnregisterDeviceNotification, DispatchMessageW, GetMessageW, GetSystemMetrics, OpenInputDesktop, GetUserObjectInformationW, CloseDesktop, GetProcessWindowStation, OpenWindowStationW, UnregisterClassA
version.dll
GetFileVersionInfoSizeW, GetFileVersionInfoW, VerQueryValueW
wintrust.dll
WinVerifyTrust

VESMgr.exe

VAIO Event Service by Sony Corporation (Signed)

Remove VESMgr.exe
Version:   4.0.00.13310
MD5:   693a3fdd279c345105fff9dde277849b
SHA1:   2d9bd62a0465900ceb0d1f7ebb771f3bd8605202
SHA256:   88c337245ea521a29c2093275cdd23a7616e39a49d6d4314baad3fccb3612141

Overview

vesmgr.exe runs as a service under the name VAIO Event Service with extensive SYSTEM privileges (full administrator access). It is installed with a couple of know programs including VAIO Event Service published by Sony Corporation, VAIO Event Service from Sony Corporation and VAIO Event Service by Sony Corporation. The file is digitally signed by Sony Corporation which was issued by the Thawte Consulting (Pty) Ltd. certificate authority (CA).

DetailsDetails

File name:vesmgr.exe
Publisher:Sony Corporation
Product name:VAIO Event Service
Description:VAIO Event Service (Service Module)
Typical file path:C:\Program Files\sony\vaio event service\vesmgr.exe
File version:4.0.00.13310
Product version:4.0.00
Size:177.84 KB (182,112 bytes)
Certificate
Issued to:Sony Corporation
Authority (CA):Thawte Consulting (Pty) Ltd.
Expiration date:Tuesday, January 4, 2011
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 10.0
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
Sony Corporation
6% remove
This utility is pre-installed on factory PC and provides an eventing model platform to manage function keys with relation to the volume control as well as interfaces with the VAIO Control Center utility.

BehaviorsBehaviors

Service
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'VAIO Event Service'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00015156%
0.028634%
Kernel CPU:0.00008283%
0.013761%
User CPU:0.00006872%
0.014873%
Kernel CPU time:1,196,179 ms/min
100,923,805ms/min
CPU cycles:13,486/sec
17,470,203/sec
Memory
Private memory:7.07 MB
21.59 MB
Private (maximum):7.84 MB
Private (minimum):3.79 MB
Non-paged memory:7.07 MB
21.59 MB
Virtual memory:80.8 MB
140.96 MB
Virtual memory (peak):97.47 MB
169.69 MB
Working set:5.44 MB
18.61 MB
Working set (peak):11.36 MB
37.95 MB
Page faults:6,785/min
2,039/min
I/O
I/O read transfer:29 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O write transfer:2 Bytes/sec
274.99 KB/min
I/O write operations:1/sec
227/min
I/O other transfer:8 Bytes/sec
448.09 KB/min
I/O other operations:1/sec
1,671/min
Resource allocations
Threads:14
12
Handles:318
600

BehaviorsProcess properties

Integrety level:System
Platform:32-bit
Command line:"C:\Program Files\sony\vaio event service\vesmgr.exe"
Owner:SYSTEM
Windows Service
Service name:VAIO Event Service
Description:“Proporciona el servicio de gestión de eventos de hardware de VAIO. Durante la finalización de este servicio, algunas funciones, como el botón S, Hotkey y la administración de energía original de VAIO, presentan limitaciones”
Type:Win32OwnProcess
Parent process:services.exe (Services and Controller app by Microsoft)

ResourcesThreads

Averages
 
ADVAPI32.dll
Total CPU:0.00021040%
0.272967%
Kernel CPU:0.00011689%
0.107585%
User CPU:0.00009351%
0.165382%
CPU cycles:5,427/sec
5,741,424/sec
Memory:792 KB
1.16 MB
msvcr70.dll (Microsoft Visual Studio .NET by Microsoft)
Total CPU:0.00003721%
Kernel CPU:0.00001081%
User CPU:0.00002640%
CPU cycles:845/sec
Memory:336 KB
ntdll.dll
Total CPU:0.00000406%
Kernel CPU:0.00000406%
User CPU:0.00000000%
Memory:1.16 MB
ole32.dll
Total CPU:0.00000406%
Kernel CPU:0.00000406%
User CPU:0.00000000%
CPU cycles:310/sec
Memory:1.27 MB
VESMgr.exe (main module)
Total CPU:0.00000406%
Kernel CPU:0.00000000%
User CPU:0.00000406%
CPU cycles:127/sec
Memory:184 KB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 51.56%
Windows Vista Home Premium 20.31%
Windows 7 Home Basic 10.94%
Windows 7 Professional 9.38%
Microsoft Windows XP 4.69%
Windows 7 Ultimate 1.56%
Windows 8 Pro with Media Center 1.56%

Distribution by countryDistribution by country

United States installs about 45.31% of VAIO Event Service.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Sony 96.00%
Dell 4.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE