File details
File name: 3gmedint.exe
Name: MindSpark Toolbar Platform for Internet Explorer and Firefox
Description: Run a MindSpark DLL as an App
Version: 1, 0, 0, 3
Product version: 2, 3, 0, 0
Size: 21.53 KB
Original file name: t8MedInt.exe
Digital certificate
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0093983670%
Privileged CPU:
0.0007762804%

User CPU:
0.00862208661552%

Privileged CPU time: 362.86 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
522,086,133
CPU cycle count /min: 618,500
Context switches /sec:
20
 | Memory utilization averages |
Committed memory:
60.57 MB
Peak committed memory: 64.02 MB
Paged memory:
2.26 MB
Peak paged memory: 2.37 MB
Paged system memory:
101.71 KB
Non-paged system memory: 7.31 KB
Working set memory:
2.12 MB
Peak working set memory: 6.22 MB
Min working set memory: 1.73 MB
Private memory:
2.26 MB
Page faults:
4,154
Page faults /min: 9
 | Process I/O averages |
Total read operations:
135
Read operations /min: 1
Total read transfer: 139.04 KB
Read transfer /min: 183 Bytes
Total write operations:
28
Write operations /min: 1
Total write transfer: 21.4 KB
Write transfer /min: 82 Bytes
Total other operations:
3,185
Other operations /min: 3
Total other transfer: 83.26 KB
Other Transfer /min: 54 Bytes
 | GUI Object Averages |
GDI objects:
10
Peak GDI objects: 13
USER objects:
4
Peak USER objects: 6
Resources
Handle count average: 165
Thread count average: 4
Thread resource averages
Total CPU: 0.000838583229%
Privileged CPU: 0.000731278412%
User CPU: 0.000107304817%
CPU Cycle count /sec: 24,424
Module memory size: 20 KB
Total CPU: 0.000039393899%
Privileged CPU: 0.000039393899%
User CPU: 0.000000000000%
CPU Cycle count /sec: 1,122
Module memory size: 88 KB
Process details
Runs as (owner): User
Integrety level: Medium
Windows platform: 64-bit
Parent Processes
Child Process
Process Commands
C:\Program Files2\VIDEOD~2\bar\1.bin\4zmedint.exe C:\Program Files2\VIDEOD~2\bar\1.bin\4zRadio.DLL, R
C:\Program Files2\FILMFA~1\bar\1.bin\pamedint.exe C:\Program Files2\FILMFA~1\bar\1.bin\paRadio.DLL, R
C:\Program Files2\FILMFA~1\bar\1.bin\pamedint.exe C:\Program Files2\FILMFA~1\bar\1.bin\pascript.dll,#5 WeatherWidgetMultipleButton
C:\Program Files1\TELEVI~2\bar\1.bin\64medint.exe C:\Program Files1\TELEVI~2\bar\1.bin\64Radio.DLL, R
C:\Program Files1\TELEVI~2\bar\1.bin\64medint.exe C:\Program Files1\TELEVI~2\bar\1.bin\64script.dll,#5 WeatherWidgetMultipleButton
Network connectivity
TCP: ve-in-f105.1e100.net on port 51962
Image hashes
MD5: 04826c949a4de20b5a95ad88363ea3c6
SHA-1: 556c4fca5d890f17b7b5040a601b42452a205e29
SHA-256: 5a7c062dc4b60bf695c747f1e4ce0ec525bbbb58f1935e7956788d2fda4dea46
PE image details
File packed: No
Import Table
kernel32.dll

FreeLibrary
GetProcAddress
LoadLibraryExA
GetModuleFileNameA
lstrcpyA
lstrlenA
GetStartupInfoA
ExitProcess
GetCommandLineA
GetModuleHandleA
DebugBreak
HeapAlloc
GetProcessHeap
HeapReAlloc
HeapFree
user32.dll
