File details
File name: tbhostsupport.dll
Name: TBHostSupport
Description: TBHostSupport
Version: 1.0.0.2
Size: 447.28 KB
Original file name: TBHostSu.dll
Digital certificate
Certificate authority:
VeriSign
Effective date: 1/2/2013
Expiration date: 4/3/2016
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0872254669%
Privileged CPU:
0.0013539569%

User CPU:
0.08587150993077%

Privileged CPU time: 807621.54 ms
Privileged CPU time /min: 1,367 ms
CPU cycle count:
409,346,031
CPU cycle count /min: 1,209,585,161
 | Memory utilization averages |
Committed memory:
57.66 MB
Peak committed memory: 69.98 MB
Paged memory:
2.45 MB
Peak paged memory: 2.68 MB
Paged system memory:
104.99 KB
Non-paged system memory: 8.15 KB
Working set memory:
2.85 MB
Peak working set memory: 5.55 MB
Min working set memory: 2.81 MB
Private memory:
2.45 MB
Page faults:
35,127,054
Page faults /min: 121,482
 | Process I/O averages |
Total read operations:
218
Read operations /min: 1
Total read transfer: 39.84 KB
Read transfer /min: 48 Bytes
Total write operations:
432
Total write transfer: 30.38 KB
Total other operations:
1,455
Other operations /min: 1
Total other transfer: 79 KB
Other Transfer /min: 7 Bytes
 | GUI Object Averages |
GDI objects:
14
Peak GDI objects: 16
USER objects:
5
Peak USER objects: 5
Resources
Handle count average: 71
Thread count average: 2
Thread resource averages
Total CPU: 4.359139443854%
Privileged CPU: 3.848266379556%
User CPU: 0.510873064298%
CPU Cycle count /sec: 112,309,274
Context switches /sec: 10
Module memory size: 56 KB
Total CPU: 0.072908395860%
Privileged CPU: 0.061825686391%
User CPU: 0.011082709468%
Module memory size: 44 KB
Process details
Runs as (owner): User
Integrety level: Medium
Windows platform: 64-bit
Hosted Process
Parent Process
Process Commands
"C:\Windows\SysWOW64\Rundll32.exe" "C:\users\user\appdata\Local\TBHostSupport\TBHostSupport.dll",DLLRunTBHostSupportPlugin
"C:\WINDOWS\system32\Rundll32.exe" "C:\Documents and Settings\user\Application Data\TBHostSupport\TBHostSupport.dll",DLLRunTBHostSupportPlugin
"C:\Windows\SysWOW64\Rundll32.exe" "C:\users\user\appdata\Local\TBHostSupport\TBHostSupport.dll",DLLRunTBHostSupportPlugin
"C:\Windows\SysWOW64\Rundll32.exe" "C:\users\user\appdata\Local\TBHostSupport\TBHostSupport.dll",DLLRunTBHostSupportPlugin
Startup files (user) run details
Name: TBHostSupport
Command: "C:\Windows\SysWOW64\Rundll32.exe" "C:\users\user\appdata\Local\TBHostSupport\TBHostSupport.dll",DLLRunTBHostSupportPlugin
Image hashes
MD5: 9fd16d3cc543eb20f067dd6537432082
SHA-1: 60a882dfb633b1179ec55f395f1862192babe03a
PE image details
File packed: No
Import Table
advapi32.dll

RegSetValueExW
RegCreateKeyExW
RegOpenKeyExW
RegCloseKey
SetSecurityDescriptorSacl
GetSecurityDescriptorSacl
SetSecurityDescriptorDacl
InitializeSecurityDescriptor
ConvertStringSecurityDescriptorToSecurityDescriptorW
LookupAccountSidW
GetTokenInformation
OpenProcessToken
kernel32.dll

CreateToolhelp32Snapshot
GetCurrentProcessId
Thread32First
GetCurrentThreadId
Thread32Next
GetModuleHandleW
GetModuleFileNameW
GetVersionExW
LoadLibraryW
GetProcAddress
FreeLibrary
GetModuleHandleExW
CreateMutexW
GetLastError
OpenProcess
VirtualAllocEx
WriteProcessMemory
SetThreadPriority
CreateRemoteThread
WaitForSingleObject
Process32FirstW
Process32NextW
ReleaseMutex
InitializeCriticalSectionAndSpinCount
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentVariableW
SetFilePointerEx
GetCurrentThread
GetThreadPriority
CloseHandle
Sleep
ResumeThread
GetThreadContext
SuspendThread
OpenThread
VirtualFree
VirtualAlloc
VirtualQuery
GetSystemInfo
FlushInstructionCache
VirtualProtectEx
GetCurrentProcess
SetStdHandle
CreateFileW
VirtualFreeEx
HeapReAlloc
GetConsoleMode
GetConsoleCP
InterlockedIncrement
InterlockedDecrement
GetStringTypeW
EncodePointer
DecodePointer
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
HeapAlloc
HeapFree
GetCommandLineA
GetStdHandle
GetFileType
WriteConsoleW
RaiseException
RtlUnwind
GetCPInfo
IsProcessorFeaturePresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
SetLastError
TerminateProcess
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetStartupInfoW
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
IsDebuggerPresent
ExitProcess
HeapSize
WriteFile
GetProcessHeap
IsValidCodePage
GetACP
GetOEMCP
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetModuleFileNameA
QueryPerformanceCounter
GetSystemTimeAsFileTime
OutputDebugStringW
LoadLibraryExW
FlushFileBuffers
ole32.dll

psapi.dll

GetModuleFileNameExW
EnumProcessModules
shell32.dll

user32.dll
