File details
File name: 49srchmn.exe
Name: MindSpark Toolbar Platform SearchScope Monitor
Description: MindSpark Toolbar Platform SearchScope Monitor
Version: 1, 0, 0, 13
Product version: 2, 3, 0, 0
Size: 43.73 KB
Original file name: t8SrchMn.exe
Digital certificate
Certificate authority:
VeriSign
Effective date: 4/9/2012
Expiration date: 5/6/2015
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0002966804%
Privileged CPU:
0.0001119363%

User CPU:
0.00018474412890%

Privileged CPU time: 52539.38 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
732,227,025
CPU cycle count /min: 1,434,107
 | Memory utilization averages |
Committed memory:
35.92 MB
Peak committed memory: 45.98 MB
Paged memory:
857.33 KB
Peak paged memory: 1.16 MB
Paged system memory:
62.5 KB
Non-paged system memory: 4.81 KB
Working set memory:
756.67 KB
Peak working set memory: 2.97 MB
Min working set memory: 707.33 KB
Private memory:
857.33 KB
Page faults:
890
Page faults /min: 2
 | Process I/O averages |
Total read operations:
1
Read operations /min: 1
Total read transfer: 18.44 KB
Read transfer /min: 16 Bytes
Total other operations:
185
Other operations /min: 1
Total other transfer: 23.87 KB
Other Transfer /min: 0 Bytes
 | GUI Object Averages |
GDI objects:
4
Peak GDI objects: 4
USER objects:
2
Peak USER objects: 2
Resources
Handle count average: 51
Thread count average: 2
Thread resource averages
Total CPU: 0.000076311559%
Privileged CPU: 0.000070871919%
User CPU: 0.000005439640%
CPU Cycle count /sec: 1,285
Module memory size: 48 KB
Process details
Runs as (owner): User
Integrety level: Undefined
Windows platform: 32-bit
Parent Processes
Process Commands
"C:\Program Files1\VIDEOD~2\bar\1.bin\4zsrchmn.exe" /m=2 /w /h
"C:\ARCHIV~1\VIDEOD~2\bar\1.bin\4zsrchmn.exe" /m=2 /w /h
"C:\Program Files\VideoScavenger_1e\bar\1.bin\1eSrchMn.exe" /m=2 /w /h
"C:\Program Files2\VIDEOD~2\bar\1.bin\4zsrchmn.exe" /m=2 /w /h /r
"C:\Program Files\Zwinky_5q\bar\2.bin\5qSrchMn.exe" /m=2 /w /h
Startup files (all users) run details
Name: Allin1Convert Search Scope Monitor
Command: "C:\Program Files1\ALLIN1~2\bar\1.bin\8hsrchmn.exe" /m=2 /w /h
Image hashes
MD5: fb85f333d10b1475650c4304f99a1ece
SHA-1: 8ace75f6c2417666ad9d60837b72d78b394c3944
SHA-256: bed200cccbab9d0b7f5ff299b74a0ff52731366da956960fc3ea45edaaf9cb10
PE image details
File packed: No
Import Table
advapi32.dll

RegCloseKey
RegQueryValueExA
RegFlushKey
RegSetValueExA
RegCreateKeyExA
RegDeleteValueA
RegDeleteKeyA
RegQueryInfoKeyA
RegEnumKeyExA
RegNotifyChangeKeyValue
RegOpenKeyExA
kernel32.dll

GetModuleFileNameA
lstrlenW
OpenMutexA
GetStartupInfoA
ExitProcess
GetCommandLineA
GetModuleHandleA
InitializeCriticalSection
DeleteCriticalSection
DebugBreak
HeapAlloc
GetProcessHeap
HeapReAlloc
HeapFree
LeaveCriticalSection
EnterCriticalSection
LocalFree
GetProcAddress
lstrcpynA
GetVersionExA
GetFileAttributesA
LoadLibraryExA
CreateProcessA
FreeLibrary
ResetEvent
GetLastError
CreateEventA
SetLastError
GetSystemDirectoryA
CompareFileTime
GetSystemTimeAsFileTime
GetTickCount
SystemTimeToFileTime
GetSystemTime
lstrcmpiA
Sleep
CreateFileMappingA
DuplicateHandle
GetCurrentProcess
OpenFileMappingA
MapViewOfFile
UnmapViewOfFile
FindResourceA
LoadResource
LockResource
lstrlenA
lstrcpyA
lstrcatA
CreateMutexA
WaitForSingleObject
ReleaseMutex
CloseHandle
GetDriveTypeA
GetLocalTime
ole32.dll

user32.dll

SetWindowsHookExA
MsgWaitForMultipleObjects
PeekMessageA
TranslateMessage
DispatchMessageA
UnhookWindowsHookEx
GetKeyboardType
CharNextA
wsprintfA
version.dll

GetFileVersionInfoSizeA
VerQueryValueA
GetFileVersionInfoA