File details
File name: flashplayerplugin_11_5_502_149.exe
Name: Shockwave Flash
Description: Adobe Flash Player 11.5 r502
Version: 11,5,502,149
Size: 1.72 MB
Original file name: SAFlashPlayer.exe
Digital certificate
Certificate authority:
VeriSign
Effective date: 9/23/2012
Expiration date: 10/1/2015
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0118247359%
Privileged CPU:
0.0046533973%

User CPU:
0.00717133855792%

Privileged CPU time: 846711.58 ms
Privileged CPU time /min: 1,322 ms
CPU cycle count:
2,228,799
CPU cycle count /min: 33,355,204
Context switches /sec:
377
 | Memory utilization averages |
Committed memory:
129.99 MB
Peak committed memory: 150.18 MB
Paged memory:
17.54 MB
Peak paged memory: 35.24 MB
Paged system memory:
172.3 KB
Non-paged system memory: 13.21 KB
Working set memory:
16.68 MB
Peak working set memory: 32.67 MB
Min working set memory: 8.87 MB
Private memory:
17.54 MB
Page faults:
61,162
Page faults /min: 2,072
 | Process I/O averages |
Total read operations:
216,803
Read operations /min: 6,748
Total read transfer: 94.89 MB
Read transfer /min: 4.11 MB
Total write operations:
219,587
Write operations /min: 6,877
Total write transfer: 22.12 MB
Write transfer /min: 947.56 KB
Total other operations:
34,265
Other operations /min: 1,407
Total other transfer: 927.94 KB
Other Transfer /min: 35.12 KB
 | GUI Object Averages |
GDI objects:
17
Peak GDI objects: 16
USER objects:
23
Peak USER objects: 24
Resources
Handle count average: 269
Thread count average: 11
Thread resource averages
Total CPU: 0.524301478009%
Privileged CPU: 0.154070494318%
User CPU: 0.370230983691%
CPU Cycle count /sec: 15,959,584
Context switches /sec: 54
Module memory size: 1.74 MB
ntdll.dll

Total CPU: 0.078689572742%
Privileged CPU: 0.039659322027%
User CPU: 0.039030250715%
CPU Cycle count /sec: 5,201,500
Context switches /sec: 113
Module memory size: 1.66 MB
ntdll.dll

Total CPU: 0.053784814856%
Privileged CPU: 0.025332505784%
User CPU: 0.028452309072%
CPU Cycle count /sec: 2,951,364
Module memory size: 1.23 MB
Total CPU: 0.038181144178%
Privileged CPU: 0.017697403416%
User CPU: 0.020483740762%
CPU Cycle count /sec: 1,708,383
Context switches /sec: 14
Module memory size: 14.89 MB
wow64.dll

Total CPU: 0.030652141024%
Privileged CPU: 0.025543450853%
User CPU: 0.005108690171%
CPU Cycle count /sec: 649,736
Context switches /sec: 2
Module memory size: 276 KB
ntdll.dll

Total CPU: 0.028805402630%
Privileged CPU: 0.016317182488%
User CPU: 0.012488220142%
CPU Cycle count /sec: 2,371,215
Context switches /sec: 25
Module memory size: 1.4 MB
ntdll.dll

Total CPU: 0.017210217259%
Privileged CPU: 0.009216243886%
User CPU: 0.007993973373%
CPU Cycle count /sec: 1,647,642
Context switches /sec: 1
Module memory size: 1.23 MB
ntdll.dll

Total CPU: 0.000167105812%
Privileged CPU: 0.000000000000%
User CPU: 0.000167105812%
CPU Cycle count /sec: 60,832
Module memory size: 1.4 MB
Process details
Runs as (owner): User
Integrety level: Medium
Windows platform: 32-bit
Parent Processes
Child Process
Process Commands
"C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_5_502_149.exe" --proxy-stub-channel=Flash4172.65E0BD48.41 --host-broker-channel=Flash4172.65E0BD48.18467 --host-pid=4172 --host-npapi-version=22 --plugin-path="C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_149.dll"
"C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_5_502_149.exe" --channel=1988.0021F458.294309865 --proxy-stub-channel=Flash4172.65E0BD48.41 --plugin-path="C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_149.dll" --host-npapi-version=22 --type=renderer
"C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_5_502_149.exe" --channel=5640.0018F464.360013130 --proxy-stub-channel=Flash380.5DB573D8.41 --plugin-path="C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_149.dll" --host-npapi-version=27 --type=renderer
"C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_5_502_149.exe" --proxy-stub-channel=Flash380.5DB573D8.41 --host-broker-channel=Flash380.5DB573D8.18467 --host-pid=380 --host-npapi-version=27 --plugin-path="C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_149.dll"
"C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_5_502_149.exe" --proxy-stub-channel=Flash5216.5950FFD0.41 --host-broker-channel=Flash5216.5950FFD0.18467 --host-pid=5216 --host-npapi-version=27 --plugin-path="C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_149.dll"
Image hashes
MD5: 476fd5f12c0ff32cdf0a179320fcb726
SHA-1: ae68ed25e995d855d6fec47cc27b48525f9e5d4b
SHA-256: 9b2a6d0576b9ae9c9cbb1ce1e4836ec24b2a63a33c739c50eccc8c058d8943b1
PE image details
File packed: No
Import Table
advapi32.dll

DuplicateToken
DuplicateTokenEx
CreateRestrictedToken
SetThreadToken
ConvertStringSidToSidW
GetLengthSid
SetTokenInformation
ConvertStringSecurityDescriptorToSecurityDescriptorW
CheckTokenMembership
CreateWellKnownSid
CopySid
LookupPrivilegeValueW
EqualSid
RegSetValueExA
GetSecurityDescriptorSacl
RevertToSelf
RegDisablePredefinedCache
RegSetValueExW
RegOpenKeyExA
RegQueryValueExA
RegCreateKeyExA
RegOpenKeyExW
RegQueryValueExW
RegCloseKey
GetSecurityInfo
SetEntriesInAclW
SetSecurityInfo
FreeSid
AllocateAndInitializeSid
CreateProcessAsUserW
GetTokenInformation
OpenProcessToken
ConvertSidToStringSidW
RegQueryInfoKeyW
RegEnumKeyExW
RegCreateKeyExW
comdlg32.dll

CommDlgExtendedError
GetOpenFileNameW
GetSaveFileNameW
crypt32.dll

CertCreateCertificateContext
CertVerifySubjectCertificateContext
CertGetCertificateChain
CertFindCertificateInStore
CertEnumCertificatesInStore
CertFreeCertificateChain
CertOpenStore
CertFreeCertificateContext
CertAddStoreToCollection
CertVerifyRevocation
CertCloseStore
CertAddCertificateContextToStore
CertVerifyCertificateChainPolicy
CryptGetMessageCertificates
CryptVerifyMessageSignature
CertCompareCertificate
gdi32.dll

GetTextAlign
GetTextColor
CreateFontIndirectW
RemoveFontResourceW
CreateScalableFontResourceW
GetFontData
PlayEnhMetaFile
SetEnhMetaFileBits
CreateICW
GetCurrentObject
GetObjectW
GetEnhMetaFileBits
GetBkMode
CreateRectRgn
CombineRgn
CreateEnhMetaFileW
SetPolyFillMode
DeleteEnhMetaFile
GetObjectType
CloseEnhMetaFile
GetClipBox
SelectObject
DeleteDC
CreateDCW
DeleteObject
GetStretchBltMode
GetPolyFillMode
GetMiterLimit
AddFontResourceW
ExtEscape
CreateCompatibleBitmap
SetDIBits
Escape
CreateDCA
ResetDCW
SetWorldTransform
GetDeviceCaps
EndDoc
EndPage
StartPage
AbortDoc
GetRgnBox
StartDocW
GetEnhMetaFileHeader
GetDIBits
GetWorldTransform
EnumEnhMetaFile
PlayEnhMetaFileRecord
ModifyWorldTransform
imm32.dll

ImmGetOpenStatus
ImmCreateContext
kernel32.dll
mpr.dll

WNetAddConnection2W
WNetGetResourceInformationW
WNetGetUniversalNameW
ole32.dll

CoUnmarshalInterface
CoInitialize
CreateBindCtx
CoInitializeEx
GetHGlobalFromStream
CoMarshalInterface
CreateStreamOnHGlobal
StringFromCLSID
MkParseDisplayName
CoTaskMemFree
CoTaskMemAlloc
CoCreateInstance
CoUninitialize
ReleaseStgMedium
psapi.dll

GetMappedFileNameW
GetProcessImageFileNameW
secur32.dll

FreeContextBuffer
FreeCredentialsHandle
DeleteSecurityContext
ApplyControlToken
EncryptMessage
DecryptMessage
AcquireCredentialsHandleA
InitializeSecurityContextA
QueryContextAttributesA
QueryCredentialsAttributesA
shell32.dll

SHFileOperationW
ShellExecuteExW
ShellExecuteW
SHGetFolderPathW
SHBrowseForFolderW
SHGetPathFromIDListW
SHGetFolderPathA
SHCreateDirectoryExW
CommandLineToArgvW
shlwapi.dll

PathIsDirectoryW
AssocQueryStringW
UrlCanonicalizeW
PathCanonicalizeW
PathIsRelativeW
PathFindExtensionW
PathFileExistsA
PathAppendW
PathAddBackslashW
PathRemoveFileSpecW
PathCreateFromUrlW
UrlIsW
PathIsURLW
PathFileExistsW
urlmon.dll

user32.dll

GetDesktopWindow
GetThreadDesktop
GetProcessWindowStation
UserHandleGrantAccess
CloseWindowStation
CreateWindowStationW
CreateDesktopW
GetUserObjectInformationW
GetWindow
EnumWindows
LoadCursorW
LoadIconW
IsWindowEnabled
CloseWindow
GetAsyncKeyState
SetForegroundWindow
SetCursor
GetClientRect
MapWindowPoints
MonitorFromWindow
GetParent
GetTopWindow
ScreenToClient
SetCursorPos
ClientToScreen
GetWindowRect
EnumThreadWindows
GetActiveWindow
GetClipboardFormatNameA
GetClipboardData
GetPropW
GetDC
OpenClipboard
CloseClipboard
EmptyClipboard
SetClipboardData
IsClipboardFormatAvailable
EnumClipboardFormats
CountClipboardFormats
WaitMessage
GetClipboardSequenceNumber
GetClipboardOwner
GetPriorityClipboardFormat
GetOpenClipboardWindow
ChangeClipboardChain
GetClipboardViewer
SetClipboardViewer
RegisterClipboardFormatW
RegisterClipboardFormatA
DestroyWindow
RemovePropW
SetWindowsHookExW
GetQueueStatus
PeekMessageW
UnhookWindowsHookEx
AllowSetForegroundWindow
GetClassNameW
GetKeyState
UnregisterClassW
PostQuitMessage
CallMsgFilterW
TranslateMessage
DispatchMessageW
FindWindowExW
MsgWaitForMultipleObjectsEx
GetWindowThreadProcessId
AttachThreadInput
SetActiveWindow
SetFocus
GetFocus
EnableWindow
PostMessageW
IsWindowVisible
UpdateWindow
ShowWindow
CreateWindowExW
CloseDesktop
OpenInputDesktop
SetThreadDesktop
SetProcessWindowStation
SetWindowLongW
WaitForInputIdle
GetForegroundWindow
GetAncestor
SetTimer
KillTimer
MsgWaitForMultipleObjects
MessageBoxW
SetPropW
GetClassNameA
CallNextHookEx
DestroyIcon
InvalidateRect
GetUpdateRect
GetWindowLongW
SendMessageW
ValidateRect
RedrawWindow
IsWindow
GetClipboardFormatNameW
CallWindowProcW
DefWindowProcW
RegisterClassExW
RegisterWindowMessageW
WindowFromPoint
GetCursorPos
ReleaseDC
SetWindowPos
wininet.dll

InternetQueryDataAvailable
InternetWriteFile
HttpEndRequestA
InternetQueryOptionA
InternetErrorDlg
InternetSetOptionA
HttpAddRequestHeadersA
HttpSendRequestExA
InternetOpenA
InternetConnectA
HttpOpenRequestA
HttpSendRequestA
InternetCloseHandle
InternetReadFile
HttpQueryInfoA
winmm.dll

timeEndPeriod
timeGetTime
timeBeginPeriod
winspool.drv

EnumPrintersW
DocumentPropertiesW
GetPrinterW
ClosePrinter
SetPrinterW
DeviceCapabilitiesW
OpenPrinterW
EnumPrintersA