File details
File name: dmwu.exe
Size: 353.62 KB
Digital certificate
Certificate authority:
VeriSign
Expiration date: 6/9/2012
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0228405357%
Privileged CPU:
0.0000950557%

User CPU:
0.02274548000774%

Privileged CPU time: 4071.63 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
456,025,570
 | Memory utilization averages |
Committed memory:
71.1 MB
Peak committed memory: 75.58 MB
Paged memory:
3.89 MB
Peak paged memory: 4.03 MB
Paged system memory:
108.77 KB
Non-paged system memory: 9.01 KB
Working set memory:
9.42 MB
Peak working set memory: 9.59 MB
Min working set memory: 9.04 MB
Private memory:
3.89 MB
Page faults:
528,201
Page faults /min: 0
 | Process I/O averages |
Total read operations:
694
Total read transfer: 1.59 MB
Total other operations:
11,047
Total other transfer: 163.63 KB
Resources
Handle count average: 389
Thread count average: 8
Thread resource averages
sechost.dll

Total CPU: 0.010156870360%
Privileged CPU: 0.008834361198%
User CPU: 0.001322509161%
CPU Cycle count /sec: 478,136
Context switches /sec: 9
Module memory size: 100 KB
Total CPU: 0.000370294993%
Privileged CPU: 0.000158697854%
User CPU: 0.000211597139%
CPU Cycle count /sec: 9,287
Module memory size: 364 KB
Total CPU: 0.000158698904%
Privileged CPU: 0.000105799269%
User CPU: 0.000052899635%
CPU Cycle count /sec: 6,359
Module memory size: 812 KB
Process details
Runs as (owner): System
Integrety level: System
Windows platform: 32-bit
Runs as a service: Yes
Parent Process
Process Command
C:\Windows\System32\dmwu.exe
Service details
Name: WebOptimizer
Service type:
Win32OwnProcess
Network connectivity
UDP: LISTENING on port 49155
Image hashes
MD5: 302a025cab861cfbc06dda6d6f67e790
SHA-1: c760da366298da9bcb4646fd2bd6df2887615cd5
SHA-256: 46247fd2747052e6ccc8cf5519c5d2980c07fe8dbee6abff70d4e10f5e02dc32
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++ 10.0
File packed: No
Import Table
advapi32.dll

RegOpenCurrentUser
DeregisterEventSource
RegisterEventSourceW
RegQueryValueExW
RegSetValueExW
RegCreateKeyExW
StartServiceCtrlDispatcherW
RegisterServiceCtrlHandlerW
SetServiceStatus
ChangeServiceConfig2W
StartServiceW
QueryServiceStatusEx
CloseServiceHandle
OpenServiceW
OpenSCManagerW
CreateProcessAsUserW
DuplicateTokenEx
ReportEventW
RegNotifyChangeKeyValue
RegOpenKeyExW
RegCloseKey
RevertToSelf
ImpersonateLoggedOnUser
OpenProcessToken
kernel32.dll

WriteFile
OutputDebugStringW
CreateDirectoryW
GetLocalTime
FlushFileBuffers
InterlockedIncrement
DeleteFileW
lstrcmpiW
lstrlenA
LockResource
SizeofResource
LoadResource
GetTempPathW
GetTickCount
GetFileAttributesW
WaitForMultipleObjects
GetModuleHandleW
GetProcAddress
CreateThread
ResetEvent
CreateEventW
Sleep
TerminateThread
WaitForSingleObject
SetEvent
Process32NextW
CloseHandle
GetLastError
OpenProcess
Process32FirstW
GetVersionExW
CreateFileW
GetModuleHandleExW
TerminateProcess
InterlockedDecrement
GetCurrentThreadId
FindResourceW
MultiByteToWideChar
GetModuleFileNameW
FindResourceExW
LocalAlloc
FormatMessageW
HeapDestroy
HeapAlloc
HeapFree
HeapReAlloc
HeapSize
GetProcessHeap
RaiseException
InitializeCriticalSectionAndSpinCount
EncodePointer
DecodePointer
InterlockedExchange
InterlockedCompareExchange
HeapSetInformation
GetStartupInfoW
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
CreateToolhelp32Snapshot
LeaveCriticalSection
EnterCriticalSection
LocalFree
DeleteCriticalSection
InitializeCriticalSection
WideCharToMultiByte
lstrlenW
msvcp100.dll
msvcr100.dll
ole32.dll

CoCreateGuid
OleRun
CoInitialize
CoUninitialize
CoTaskMemFree
CoCreateInstance
StringFromCLSID
shell32.dll

ShellExecuteW
SHGetMalloc
SHGetPathFromIDListW
SHGetSpecialFolderLocation
shlwapi.dll

urlmon.dll

user32.dll

PostThreadMessageW
DispatchMessageW
TranslateMessage
MsgWaitForMultipleObjects
RegisterClassW
CreateWindowExW
SetWindowLongW
GetMessageW
DestroyWindow
DefWindowProcW
wsprintfW
KillTimer
SetTimer
PeekMessageW
PostMessageW
userenv.dll

DestroyEnvironmentBlock
CreateEnvironmentBlock
wtsapi32.dll

WTSEnumerateSessionsW
WTSFreeMemory
WTSQuerySessionInformationW