File details
File name: GoogleToolbarNotifier.exe
Name: GoogleToolbarNotifier
Description: GoogleToolbarNotifier
Version: 4, 1, 509, 1944
Size: 38.48 KB
Original file name: GoogleToolbarNotifier.exe
Digital certificate
Certificate authority:
VeriSign
Effective date: 6/18/2007
Expiration date: 6/18/2010
Resource utilization
 | CPU utilization averages |
Total CPU: 0.7708815334%
Privileged CPU:
0.0599850375%

User CPU:
0.71089649584082%

Total CPU time: 36 ms
Total CPU time /min: 1 ms
Privileged CPU time: 72511.83 ms
Privileged CPU time /min: 2 ms
User CPU time: 14.01 ms
User CPU time /min: 0 ms
CPU cycle count:
227,614,777
CPU cycle count /min: 16,370,148
Context switches /sec:
160
 | Memory utilization averages |
Committed memory:
79.65 MB
Peak committed memory: 84.71 MB
Paged memory:
3.65 MB
Peak paged memory: 3.86 MB
Paged system memory:
136.88 KB
Non-paged system memory: 12.78 KB
Working set memory:
1.79 MB
Peak working set memory: 8.53 MB
Min working set memory: 1021.79 KB
Private memory:
3.65 MB
Page faults:
34,454
Page faults /min: 105
 | Process I/O averages |
Total read operations:
944
Read operations /min: 8
Total read transfer: 177.52 KB
Read transfer /min: 10.81 KB
Total write operations:
9
Write operations /min: 1
Total write transfer: 5.71 KB
Write transfer /min: 40 Bytes
Total other operations:
4,987
Other operations /min: 38
Total other transfer: 117.46 KB
Other Transfer /min: 990 Bytes
 | GUI Object Averages |
GDI objects:
12
Peak GDI objects: 14
USER objects:
12
Peak USER objects: 15
Resources
Handle count average: 228
Thread count average: 6
Thread resource averages
Total CPU: 0.084352597030%
Privileged CPU: 0.063264447772%
User CPU: 0.021088149257%
Context switches /sec: 2
Module memory size: 1000 KB
ntdll.dll

Total CPU: 0.021417530622%
Privileged CPU: 0.000109866468%
User CPU: 0.021307664154%
CPU Cycle count /sec: 34,586
Module memory size: 1.66 MB
Total CPU: 0.017935400915%
Privileged CPU: 0.017928614129%
User CPU: 0.000006786786%
CPU Cycle count /sec: 44,868
Module memory size: 1000 KB
Total CPU: 0.014606983932%
Privileged CPU: 0.008532220346%
User CPU: 0.006074763586%
CPU Cycle count /sec: 136,654
Context switches /sec: 3
Module memory size: 48 KB
Total CPU: 0.005982734091%
Privileged CPU: 0.005982734091%
User CPU: 0.000000000000%
CPU Cycle count /sec: 341,511
Context switches /sec: 17
Module memory size: 316 KB
Total CPU: 0.005608150692%
Privileged CPU: 0.002804075346%
User CPU: 0.002804075346%
CPU Cycle count /sec: 79,603
Context switches /sec: 1
Module memory size: 996 KB
ntdll.dll

Total CPU: 0.003765510598%
Privileged CPU: 0.000355387880%
User CPU: 0.003410122719%
CPU Cycle count /sec: 8,662
Module memory size: 1.23 MB
Total CPU: 0.003049596210%
Privileged CPU: 0.001917473240%
User CPU: 0.001132122971%
CPU Cycle count /sec: 95,779
Module memory size: 252 KB
wininet.dll

Total CPU: 0.002991752419%
Privileged CPU: 0.000000000000%
User CPU: 0.002991752419%
CPU Cycle count /sec: 62,422
Module memory size: 980 KB
ntdll.dll

Total CPU: 0.002990632149%
Privileged CPU: 0.002990632149%
User CPU: 0.000000000000%
CPU Cycle count /sec: 3,795
Module memory size: 1.23 MB
Total CPU: 0.001676662564%
Privileged CPU: 0.001472020029%
User CPU: 0.000204642534%
CPU Cycle count /sec: 35,009
Module memory size: 996 KB
Total CPU: 0.001238825419%
Privileged CPU: 0.000000000000%
User CPU: 0.001238825419%
CPU Cycle count /sec: 415,614
Module memory size: 320 KB
ntdll.dll

Total CPU: 0.000198735042%
Privileged CPU: 0.000000000000%
User CPU: 0.000198735042%
CPU Cycle count /sec: 338
Module memory size: 1.67 MB
ntdll.dll

Total CPU: 0.000052644320%
Privileged CPU: 0.000041007155%
User CPU: 0.000011637165%
CPU Cycle count /sec: 1,064
Module memory size: 1.23 MB
Total CPU: 0.000027430509%
Privileged CPU: 0.000019118234%
User CPU: 0.000008312275%
CPU Cycle count /sec: 874
Module memory size: 840 KB
Process details
Runs as (owner): User
Integrety level: Medium
Windows platform: 64-bit
Parent Processes
Process Commands
"C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" -Embedding
"C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
"C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" -Embedding
"C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
"C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" -Embedding
Startup files (user) run details
Name: swg
Command: "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
Network connectivity
TCP: yh-in-f101.1e100.net on port 54538
TCP: syd01s12-in-f2.1e100.net on port 57284
TCP: syd01s06-in-f4.1e100.net on port 51012
TCP: syd01s04-in-f2.1e100.net on port 54553
TCP: sin01s05-in-f6.1e100.net on port 2287
TCP: ord08s07-in-f2.1e100.net on port 58171
TCP: ord08s06-in-f4.1e100.net on port 1249
TCP: ord08s05-in-f3.1e100.net on port 63410
TCP: nuq04s08-in-f2.1e100.net on port 3029
TCP: mia04s04-in-f3.1e100.net on port 51962
TCP: lhr14s20-in-f3.1e100.net on port 54299
TCP: lga15s35-in-f5.1e100.net on port 49170
Image hashes
MD5: 5d61be7db55b026a5d61a3eed09d0ead
SHA-1: 215950ce5d40907b041346f22b4e404ee591581d
SHA-256: d32cc7b31a6f98c60abc313abc7d1143681f72de2bb2604711a0ba20710caaae
PE image details
File entropy: 5.48802
File packed: No
Import Table
advapi32.dll

RegOpenKeyExW
RegQueryValueExW
RegCloseKey
kernel32.dll

ExitProcess
GetCommandLineA
GetStartupInfoA
GetModuleHandleA
GetCommandLineW
FreeLibrary
GetModuleFileNameW
CompareStringW
lstrlenW
GetProcAddress
lstrcmpiW
GetProcessHeap
HeapFree
LoadLibraryW
HeapAlloc
GetLocaleInfoA
GetACP
DeleteCriticalSection
InitializeCriticalSection
InterlockedExchange
GetVersionExA
EnterCriticalSection
LeaveCriticalSection
TerminateProcess
GetCurrentProcess
GetStartupInfoW
HeapReAlloc
HeapDestroy
HeapCreate
VirtualFree
VirtualAlloc
VirtualProtect
GetSystemInfo
VirtualQuery
MultiByteToWideChar
LCMapStringA
WideCharToMultiByte
GetLastError
LCMapStringW
TlsAlloc
SetLastError
GetCurrentThreadId
TlsFree
TlsSetValue
TlsGetValue
HeapSize
WriteFile
GetStdHandle
GetModuleFileNameA
UnhandledExceptionFilter
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
GetEnvironmentStringsW
SetHandleCount
GetFileType
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
RtlUnwind
GetCPInfo
GetStringTypeA
GetStringTypeW
GetOEMCP
LoadLibraryA