File details
File name: ycmmirage.exe
Name: YCMMirag Application
Description: YouCam Mirage
Version: 1.0.0.526
Size: 133.29 KB
Original file name: YCMMirag.exe
Digital certificate
Certificate authority:
VeriSign
Effective date: 2/16/2009
Expiration date: 4/12/2012
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0011963436%
Privileged CPU:
0.0005993161%

User CPU:
0.00059702756587%

Privileged CPU time: 276517.46 ms
Privileged CPU time /min: 141 ms
CPU cycle count:
221,051,138
CPU cycle count /min: 45,655,266
Context switches /sec:
6
 | Memory utilization averages |
Committed memory:
77.67 MB
Peak committed memory: 81.84 MB
Paged memory:
2.21 MB
Peak paged memory: 2.41 MB
Paged system memory:
145.3 KB
Non-paged system memory: 11 KB
Working set memory:
1.5 MB
Peak working set memory: 6.28 MB
Min working set memory: 1.21 MB
Private memory:
2.21 MB
Page faults:
2,704,365
Page faults /min: 1,795
 | Process I/O averages |
Total read operations:
1,906
Read operations /min: 3
Total read transfer: 3.73 MB
Read transfer /min: 4.15 KB
Total write operations:
48
Write operations /min: 1
Total write transfer: 83.23 KB
Write transfer /min: 18 Bytes
Total other operations:
2,853,524
Other operations /min: 1,986
Total other transfer: 35.95 MB
Other Transfer /min: 18.42 KB
 | GUI Object Averages |
GDI objects:
17
Peak GDI objects: 20
USER objects:
9
Peak USER objects: 10
Resources
Handle count average: 128
Thread count average: 3
Thread resource averages
Total CPU: 0.255900336099%
Privileged CPU: 0.176499524858%
User CPU: 0.079400811241%
CPU Cycle count /sec: 8,707,825
Context switches /sec: 7
Module memory size: 128 KB
ntdll.dll

Total CPU: 0.000109384426%
Privileged CPU: 0.000109384426%
User CPU: 0.000000000000%
CPU Cycle count /sec: 614
Module memory size: 1.66 MB
Process details
Runs as (owner): User
Integrety level: Undefined
Windows platform: 64-bit
Runs as a service: Yes
Parent Processes
Process Commands
"C:\Program Files\CyberLink\YouCam\YCMMirage.exe"
"C:\Program Files\Hewlett-Packard\Media\Webcam\YCMMirage.exe"
"C:\Program Files\CyberLink\YouCam\YCMMirage.exe"
Scheduled task details
Name: MirageAgent
Command: \MirageAgent
Scheduled tasks startup details
Name: \MirageAgent
Startup files (all users) run details
Name: YouCam Mirage
Command: "C:\Program Files\CyberLink\YouCam\YCMMirage.exe"
Image hashes
MD5: b7f55e2ae978d3d34f7876ee5d689aae
SHA-1: 4133dce0b73894bb1127c51137c717c382ed7670
SHA-256: 2a950042529dc2c6495e691557043b5b15e483079f4135675e495c121f7c0ed0
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++ 8.0
File packed: No
Import Table
advapi32.dll

RegQueryValueExW
RegOpenKeyExW
RegCloseKey
kernel32.dll

ResetEvent
GetSystemTimeAsFileTime
GetCurrentProcessId
GetCurrentThreadId
GetTickCount
QueryPerformanceCounter
GetPrivateProfileStringW
OutputDebugStringW
GetLastError
CreateEventW
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
WaitForSingleObject
InterlockedExchange
OpenMutexW
CreateFileW
CloseHandle
GetModuleFileNameW
DeviceIoControl
IsDebuggerPresent
SetUnhandledExceptionFilter
UnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
GetStartupInfoW
InterlockedCompareExchange
Sleep
msvcr80.dll
ole32.dll

CoCreateInstance
CoUninitialize
CoInitialize
shell32.dll

shlwapi.dll

PathAppendW
PathRemoveFileSpecW
user32.dll

LoadIconW
UnregisterDeviceNotification
DispatchMessageW
TranslateMessage
GetMessageW
RegisterDeviceNotificationW
PostQuitMessage
KillTimer
EndPaint
BeginPaint
DefWindowProcW
SetTimer
UpdateWindow
ShowWindow
CreateWindowExW
FindWindowW
RegisterClassExW
LoadCursorW
wtsapi32.dll

WTSUnRegisterSessionNotification
WTSRegisterSessionNotification