File details
File name: 5zbrmon.exe
Name: VER_PRODUCT_NAME
Description: VER_DESCRIPTION
Version: 1,0,0,1
Product version: 2,3,0,0
Size: 29.39 KB
Original file name: VER_EXE_FILENAME.exe
Digital certificate
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0074463766%
Privileged CPU:
0.0005254625%

User CPU:
0.00692091410449%

Privileged CPU time: 4485.59 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
18,080,723
CPU cycle count /min: 734,297
Context switches /sec:
20
 | Memory utilization averages |
Committed memory:
50.02 MB
Peak committed memory: 54.12 MB
Paged memory:
1.25 MB
Peak paged memory: 1.56 MB
Paged system memory:
77.34 KB
Non-paged system memory: 4.69 KB
Working set memory:
2.13 MB
Peak working set memory: 4.1 MB
Min working set memory: 2.07 MB
Private memory:
1.25 MB
Page faults:
4,006
Page faults /min: 13
 | Process I/O averages |
Total read operations:
11
Read operations /min: 1
Total read transfer: 120.91 KB
Read transfer /min: 164 Bytes
Total write operations:
3
Write operations /min: 1
Total write transfer: 279 Bytes
Write transfer /min: 8 Bytes
Total other operations:
248
Other operations /min: 2
Total other transfer: 11.94 KB
Other Transfer /min: 31 Bytes
 | GUI Object Averages |
GDI objects:
9
Peak GDI objects: 10
USER objects:
4
Peak USER objects: 4
Resources
Handle count average: 82
Thread count average: 2
Thread resource averages
Total CPU: 0.002304041290%
Privileged CPU: 0.000000000000%
User CPU: 0.002304041290%
Module memory size: 2.26 MB
Total CPU: 0.001298141584%
Privileged CPU: 0.000934648415%
User CPU: 0.000363493169%
CPU Cycle count /sec: 27,148
Module memory size: 24 KB
Process details
Runs as (owner): User
Integrety level: Undefined
Windows platform: 32-bit
Parent Processes
Child Process
Process Commands
"C:\Program Files1\VIDEOD~2\bar\1.bin\4zbrmon.exe"
"C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\4zbrmon.exe"
"C:\Program Files\VideoScavenger_1e\bar\1.bin\1ebrmon.exe"
"C:\Program Files\Allin1Convert_8h\bar\1.bin\8hbrmon.exe"
"C:\Program Files\HeadlineAlley_29\bar\1.bin\29brmon.exe"
Startup files (all users) run details
Name: Zwinky_5q Browser Plugin Loader
Command: C:\Program Files1\ZWINKY~2\bar\2.bin\5qbrmon.exe
Image hashes
MD5: 35d6caaa9e4d82974a74dbdb53801f98
SHA-1: 0f78fe90af015b0a511ede007bd1791a341e891e
SHA-256: 5418b7bb40b097da6370ada1194f8b2d2d3eefa3ca36a6eb31d39df7791a25a3
PE image details
File packed: No
Import Table
kernel32.dll

Sleep
CloseHandle
FreeLibrary
GetProcAddress
LoadLibraryA
lstrcpyA
lstrlenA
GetModuleFileNameA
SetThreadPriority
GetCurrentThread
GetLastError
CreateEventA
LockResource
LoadResource
FindResourceA
LoadLibraryExA
GetStartupInfoA
ExitProcess
GetCommandLineA
GetModuleHandleA
InitializeCriticalSection
DeleteCriticalSection
HeapAlloc
GetProcessHeap
HeapReAlloc
HeapFree
LeaveCriticalSection
EnterCriticalSection
LocalFree
GetVersionExA
user32.dll

PeekMessageA
UnhookWindowsHookEx
DispatchMessageA
TranslateMessage
PostQuitMessage
CreateWindowExA
RegisterClassExA
SetWindowsHookExA
CharNextA
GetMessageA
DefWindowProcA