File details
File name: toolbarupdaterservice.exe
Size: 239.22 KB
Digital certificate
Certificate authority:
The USERTRUST Network
Expiration date: 1/27/2013
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0199402587%
Privileged CPU:
0.0018645190%

User CPU:
0.01807573978867%

Privileged CPU time: 69.71 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
608,160,617
CPU cycle count /min: 4,143,924
 | Memory utilization averages |
Committed memory:
67.03 MB
Peak committed memory: 75.13 MB
Paged memory:
3.73 MB
Peak paged memory: 4.16 MB
Paged system memory:
100.57 KB
Non-paged system memory: 17.08 KB
Working set memory:
842 KB
Peak working set memory: 9.12 MB
Min working set memory: 777 KB
Private memory:
3.73 MB
Page faults:
4,740
Page faults /min: 17
 | Process I/O averages |
Total read operations:
246
Read operations /min: 2
Total read transfer: 662.93 KB
Read transfer /min: 7.19 KB
Total write operations:
283
Write operations /min: 3
Total write transfer: 1.26 MB
Write transfer /min: 14.19 KB
Total other operations:
3,080
Other operations /min: 23
Total other transfer: 34.62 KB
Other Transfer /min: 258 Bytes
Resources
Handle count average: 261
Thread count average: 8
Thread resource averages
wow64.dll

Total CPU: 0.001943363290%
Privileged CPU: 0.001435946582%
User CPU: 0.000507416708%
CPU Cycle count /sec: 52,691
Module memory size: 252 KB
ntdll.dll

Total CPU: 0.000781439117%
Privileged CPU: 0.000781439117%
User CPU: 0.000000000000%
CPU Cycle count /sec: 6,710
Module memory size: 1.66 MB
sechost.dll

Total CPU: 0.000720595139%
Privileged CPU: 0.000480396759%
User CPU: 0.000240198380%
CPU Cycle count /sec: 74,054
Module memory size: 100 KB
Total CPU: 0.000718180241%
Privileged CPU: 0.000365849378%
User CPU: 0.000352330863%
CPU Cycle count /sec: 20,814
Module memory size: 260 KB
wininet.dll

Total CPU: 0.000240201841%
Privileged CPU: 0.000240201841%
User CPU: 0.000000000000%
CPU Cycle count /sec: 29,116
Module memory size: 980 KB
Process details
Runs as (owner): System
Integrety level: System
Windows platform: 32-bit
Runs as a service: Yes
Parent Processes
Process Commands
"C:\Program Files\StartNow Toolbar\ToolbarUpdaterService.exe"
"C:\Program Files\StartNow Toolbar\ToolbarUpdaterService.exe"
Service details
Name: Toolbar Updater Service
Network connectivity
UDP: LISTENING on port 51656
UDP: LISTENING on port 60494
UDP: LISTENING on port 51832
Image hashes
MD5: 70eb41a4417ba0aa36ae12bf2b4d98f6
SHA-1: ee697048ccb7950d5b03a98a1b3850e84dfa16c1
SHA-256: 62c4aa714d27f9306338266ad757d701a2d07d68210d2db9754bb6589acc17f9
PE image details
Subsystem: Windows GUI
File packed: No
Import Table
advapi32.dll

RegDeleteValueW
FreeSid
SetSecurityDescriptorDacl
InitializeSecurityDescriptor
SetEntriesInAclW
AllocateAndInitializeSid
GetSidSubAuthority
GetSidSubAuthorityCount
GetSidIdentifierAuthority
IsValidSid
RegQueryValueExW
GetTokenInformation
AdjustTokenPrivileges
SetTokenInformation
LookupPrivilegeValueW
OpenProcessToken
CreateProcessAsUserW
DuplicateTokenEx
ControlService
StartServiceW
DeleteService
OpenServiceW
CloseServiceHandle
CreateServiceW
OpenSCManagerW
SetServiceStatus
RegisterServiceCtrlHandlerW
StartServiceCtrlDispatcherW
RegCreateKeyExW
RegSetValueExW
RegOpenKeyExW
RegEnumKeyExW
RegQueryInfoKeyW
RegCloseKey
RegDeleteKeyW
kernel32.dll

OpenProcess
WTSGetActiveConsoleSessionId
WaitForSingleObject
GetTickCount
CreateToolhelp32Snapshot
Process32FirstW
ProcessIdToSessionId
Process32NextW
HeapFree
GetProcessHeap
GetCurrentProcess
HeapAlloc
CreateThread
TerminateThread
WideCharToMultiByte
LocalFree
LocalAlloc
GetVersionExW
GetTempPathW
GetPrivateProfileStringW
GetPrivateProfileIntW
GetFileAttributesW
FindFirstFileW
FindNextFileW
CloseHandle
FindClose
CreateFileW
RemoveDirectoryW
LoadLibraryExW
CreateNamedPipeW
ConnectNamedPipe
ReadFile
DisconnectNamedPipe
WriteFile
SetLastError
LCMapStringA
LCMapStringW
GetCurrentProcessId
QueryPerformanceCounter
GetStartupInfoA
GetFileType
SetHandleCount
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetModuleFileNameA
GetStdHandle
ExitProcess
HeapCreate
VirtualAlloc
VirtualFree
InterlockedIncrement
InterlockedDecrement
DeleteCriticalSection
InitializeCriticalSection
DeleteFileW
GetModuleFileNameW
GetDateFormatA
GetTimeFormatA
GetCurrentThreadId
TlsFree
TlsSetValue
GetLastError
EnterCriticalSection
RaiseException
LeaveCriticalSection
lstrcmpiW
GetModuleHandleW
GetProcAddress
GetModuleHandleA
lstrlenW
FreeLibrary
MultiByteToWideChar
Sleep
ResetEvent
WaitForMultipleObjects
FindResourceExW
FindResourceW
LoadResource
LockResource
SizeofResource
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
InitializeCriticalSectionAndSpinCount
LoadLibraryA
SetFilePointer
GetConsoleCP
GetConsoleMode
SetStdHandle
FlushFileBuffers
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
CompareStringA
CompareStringW
SetEnvironmentVariableA
CreateFileA
TlsAlloc
TlsGetValue
IsValidCodePage
GetOEMCP
GetACP
GetCPInfo
GetTimeZoneInformation
IsDebuggerPresent
SetUnhandledExceptionFilter
UnhandledExceptionFilter
TerminateProcess
RtlUnwind
CreateDirectoryW
GetStartupInfoW
GetSystemTimeAsFileTime
HeapSize
HeapReAlloc
HeapDestroy
GetCurrentDirectoryW
netapi32.dll

NetApiBufferFree
NetUserEnum
ole32.dll

CoTaskMemFree
CoTaskMemRealloc
CoUninitialize
CoInitialize
CoCreateInstance
CoTaskMemAlloc
psapi.dll

EnumProcesses
GetModuleBaseNameW
urlmon.dll

user32.dll

userenv.dll

DestroyEnvironmentBlock
CreateEnvironmentBlock
GetProfilesDirectoryW
winspool.drv

FindFirstPrinterChangeNotification
OpenPrinterW
GetPrinterW
ClosePrinter
EnumPrintersW
wtsapi32.dll
