File details
File name: CrExtPv4.exe
Version: 1.0.4.34
Size: 1.23 MB
Original file name: CrExtProc.exe
Digital certificate
Certificate authority:
VeriSign
Effective date: 4/9/2012
Expiration date: 5/6/2015
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0374197629%
Privileged CPU:
0.0223241975%

User CPU:
0.01509556542003%

Privileged CPU time: 2077.14 ms
Privileged CPU time /min: 1 ms
CPU cycle count:
718,007,191
CPU cycle count /min: 16,197,696
Context switches /sec:
15
 | Memory utilization averages |
Committed memory:
117.2 MB
Peak committed memory: 125.02 MB
Paged memory:
10.49 MB
Peak paged memory: 11.46 MB
Paged system memory:
135.11 KB
Non-paged system memory: 12.57 KB
Working set memory:
5.09 MB
Peak working set memory: 19.64 MB
Min working set memory: 4.21 MB
Private memory:
10.49 MB
Page faults:
11,047
Page faults /min: 7
 | Process I/O averages |
Total read operations:
137
Read operations /min: 1
Total read transfer: 277.15 KB
Read transfer /min: 228 Bytes
Total write operations:
1
Write operations /min: 1
Total write transfer: 116 Bytes
Write transfer /min: 0 Bytes
Total other operations:
8,321
Other operations /min: 4
Total other transfer: 233.12 KB
Other Transfer /min: 102 Bytes
 | GUI Object Averages |
GDI objects:
67
Peak GDI objects: 74
USER objects:
38
Peak USER objects: 45
Resources
Handle count average: 282
Thread count average: 10
Thread resource averages
Total CPU: 0.015589483899%
Privileged CPU: 0.009054376296%
User CPU: 0.006535107603%
CPU Cycle count /sec: 426,542
Context switches /sec: 2
Module memory size: 1.25 MB
Process details
Runs as (owner): User
Integrety level: Low
Windows platform: 64-bit
Parent Processes
Process Commands
"C:\Program Files\FilmFanatic\bar\1.bin\CrExtPpa.exe" /context="91fbdd335935d6fab2f0f46ec3451b3a18a24a23¿FilmFanatic¿00000043400001000" /extensionVersionStr="1.2.2" /browserVersion="10.0.9200.16453" /browserVersionStr="10.0.9200.16453"
"C:\Program Files\CouponAlert_2p\bar\1.bin\CrExtP2p.exe" /context="0072613205726085b1c6214db362695a458cc3e5¿CouponAlert_2p¿0000003c800001000" /extensionVersionStr="1.0.2" /browserVersion="8.0.7601.17514" /browserVersionStr="8.0.7601.17514"
"C:\Program Files\CouponAlert_2p\bar\1.bin\CrExtP2p.exe" /context="0072613205726085b1c6214db362695a458cc3e5¿CouponAlert_2p¿00000009000003000" /extensionVersionStr="1.0.2" /browserVersion="8.0.7601.17514" /browserVersionStr="8.0.7601.17514"
"C:\Program Files1\YOURLO~2\bar\1.bin\CrExtP20.exe" /context="e060dccb724729a4d17ba3a0e443b752794583e0¿yourlocallotto1_20¿00000047400001000" /extensionVersionStr="1.0.1" /browserVersion="8.0.7601.17514" /browserVersionStr="8.0.7601.17514"
"C:\Program Files\DictionaryBoss\bar\1.bin\CrExtPv4.exe" /context="98c04b7e5a161d5bfabff90ad2d71698ba9029a2¿DictionaryBoss¿0000006d400001000" /extensionVersionStr="1.1" /browserVersion="8.0.7601.17514" /browserVersionStr="8.0.7601.17514"
Image hashes
MD5: 7edafac1518da60b6da06d68affda75f
SHA-1: 3a657aceb92289972efa3565b6fedd7238c3a4b1
SHA-256: 9317c10f11cfe367b05b6672b474dfeb9c8f08400bc1e83c8ba307080b3476e0
PE image details
Subsystem: Windows GUI
File packed: No
Import Table
advapi32.dll

RegQueryInfoKeyW
RegOpenKeyExW
RegQueryValueExW
OpenProcessToken
CreateProcessAsUserW
GetSidSubAuthorityCount
GetSidSubAuthority
RegSetValueExW
RegDeleteValueW
RegCreateKeyExW
RegEnumKeyExW
RegEnumValueW
RegDeleteKeyW
GetTokenInformation
RegCloseKey
crypt32.dll

CertCloseStore
CryptMsgClose
CertFindCertificateInStore
CryptMsgGetParam
CertFreeCertificateContext
CryptQueryObject
gdi32.dll

CreateCompatibleDC
CreateCompatibleBitmap
SelectObject
DeleteObject
BitBlt
DeleteDC
GetStockObject
GetObjectW
GetDeviceCaps
CreateSolidBrush
kernel32.dll

CreateEventW
SetCurrentDirectoryW
SetEvent
DeleteCriticalSection
RaiseException
InterlockedExchange
SwitchToThread
FindResourceW
Sleep
InitializeCriticalSectionAndSpinCount
SetLastError
CreateThread
WaitForSingleObject
LoadLibraryW
FreeLibrary
GetCommandLineW
CompareStringW
CreateFileW
SetNamedPipeHandleState
GetLocalTime
WriteFile
GetCommandLineA
GetFileSize
ReadFile
CreateMutexW
ReleaseMutex
ResetEvent
GetExitCodeThread
InterlockedExchangeAdd
InterlockedDecrement
CreateIoCompletionPort
TerminateThread
GetSystemInfo
PostQueuedCompletionStatus
GetQueuedCompletionStatus
InterlockedIncrement
CancelWaitableTimer
CreateWaitableTimerW
SetWaitableTimer
FindResourceExW
GetFileAttributesW
GlobalUnlock
GlobalLock
GlobalAlloc
MulDiv
lstrcmpW
SetFilePointer
GetCurrentDirectoryW
OpenMutexW
GetModuleHandleA
GlobalFree
InitializeSListHead
GetThreadTimes
LeaveCriticalSection
FlushFileBuffers
WriteConsoleW
SetStdHandle
GetConsoleMode
GetConsoleCP
IsValidLocale
EnumSystemLocalesA
GetLocaleInfoA
GetUserDefaultLCID
GetSystemTimeAsFileTime
GetFileType
SetHandleCount
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetLocaleInfoW
GetStdHandle
ExitProcess
TlsFree
IsValidCodePage
GetOEMCP
GetACP
HeapCreate
IsDebuggerPresent
SetUnhandledExceptionFilter
UnhandledExceptionFilter
LCMapStringW
GetCPInfo
ExitThread
RtlUnwind
GetStartupInfoW
HeapSetInformation
FindClose
FindNextFileW
FindFirstFileW
GetModuleHandleExW
DeleteFileW
TlsSetValue
TlsGetValue
TlsAlloc
GetPrivateProfileSectionW
QueryPerformanceCounter
GetComputerNameW
UnmapViewOfFile
CreateFileMappingW
MapViewOfFileEx
OutputDebugStringW
ReleaseSemaphore
CreateSemaphoreW
InitializeCriticalSection
WideCharToMultiByte
GetStringTypeW
HeapSize
HeapReAlloc
HeapDestroy
InterlockedPopEntrySList
VirtualAlloc
VirtualFree
IsProcessorFeaturePresent
HeapAlloc
GetProcessHeap
HeapFree
InterlockedPushEntrySList
LoadLibraryA
LocalAlloc
EnterCriticalSection
GetCurrentThreadId
FlushInstructionCache
LockResource
LoadResource
SizeofResource
lstrlenW
lstrcatW
lstrcpyW
GetVersionExW
InterlockedCompareExchange
GetCurrentProcessId
GetModuleFileNameW
CreateDirectoryW
LocalFree
TerminateProcess
ResumeThread
GetModuleHandleW
GetProcAddress
GetExitCodeProcess
QueueUserAPC
GetCurrentThread
GetCurrentProcess
DuplicateHandle
CloseHandle
lstrlenA
MultiByteToWideChar
WaitForMultipleObjectsEx
GetTickCount
GetLastError
ole32.dll

OleUninitialize
OleInitialize
StringFromGUID2
CoReleaseMarshalData
CoGetClassObject
OleLockRunning
StringFromCLSID
CLSIDFromString
CoUnmarshalInterface
CreateStreamOnHGlobal
CoTaskMemFree
CoAddRefServerProcess
CoReleaseServerProcess
CoTaskMemAlloc
CoRevokeClassObject
CoCreateInstance
CoUninitialize
CoMarshalInterface
CLSIDFromProgID
CoGetCurrentLogicalThreadId
CoInitialize
rpcrt4.dll

RpcAsyncInitializeHandle
RpcServerRegisterIfEx
RpcServerUnregisterIf
RpcAsyncAbortCall
RpcServerUseProtseqEpW
RpcStringFreeW
RpcBindingFree
RpcBindingFromStringBindingW
RpcStringBindingComposeW
NdrAsyncServerCall
RpcAsyncCompleteCall
NdrAsyncClientCall
setupapi.dll

SetupGetFileCompressionInfoW
SetupDecompressOrCopyFileW
shlwapi.dll

PathRemoveFileSpecW
PathAppendW
StrChrW
PathCombineW
UrlCanonicalizeW
UrlUnescapeW
UrlCreateFromPathW
UrlIsW
SHDeleteKeyW
PathFindFileNameW
PathRenameExtensionW
urlmon.dll

CoInternetGetSecurityUrl
CoInternetGetSession
user32.dll

PostQuitMessage
CallMsgFilterW
TranslateMessage
PeekMessageW
FindWindowW
GetDlgItem
GetWindowRect
SetRect
IsRectEmpty
CopyRect
EnumDisplayMonitors
GetMonitorInfoW
SetDlgItemTextW
UnregisterClassA
SetWindowLongW
GetWindowLongW
MsgWaitForMultipleObjectsEx
DispatchMessageW
DefWindowProcW
CallWindowProcW
DestroyWindow
MessageBoxW
SetTimer
GetMessageW
KillTimer
PostThreadMessageW
GetActiveWindow
RegisterClassExW
GetClassInfoExW
SetClipboardData
GetClipboardData
CloseClipboard
OpenClipboard
BringWindowToTop
GetForegroundWindow
SetForegroundWindow
AdjustWindowRectEx
EqualRect
InflateRect
PostMessageW
SetParent
GetTopWindow
EnumChildWindows
RegisterWindowMessageW
GetWindowTextLengthW
GetWindowTextW
SetWindowTextW
BeginPaint
EndPaint
IsChild
GetFocus
SetFocus
GetWindow
SendMessageW
GetClassNameW
GetSysColor
SetWindowPos
RedrawWindow
CreateAcceleratorTableW
ClientToScreen
GetParent
ScreenToClient
MoveWindow
SetCapture
ReleaseCapture
FillRect
InvalidateRgn
InvalidateRect
GetDC
ReleaseDC
DestroyAcceleratorTable
GetClientRect
SetRectEmpty
GetDesktopWindow
ShowWindow
IsWindow
CharUpperW
CharNextW
CreateWindowExW
CreateDialogParamW
LoadCursorW
userenv.dll

version.dll

GetFileVersionInfoSizeW
GetFileVersionInfoW
VerQueryValueW
wintrust.dll
