File details
File name: backgroundcontainer.dll
Name: Background Container
Description: Background Container
Version: 1.0.0.15
Size: 311.78 KB
Original file name: Backgrou.dll
Digital certificate
Certificate authority:
VeriSign
Effective date: 1/2/2013
Expiration date: 4/3/2016
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0051922123%
Privileged CPU:
0.0010087982%

User CPU:
0.00418341409031%

Privileged CPU time: 1220.42 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
446,261,934
CPU cycle count /min: 2,468,775
 | Memory utilization averages |
Committed memory:
83.7 MB
Peak committed memory: 88.55 MB
Paged memory:
4.42 MB
Peak paged memory: 5.15 MB
Paged system memory:
162.94 KB
Non-paged system memory: 16.58 KB
Working set memory:
3 MB
Peak working set memory: 9.42 MB
Min working set memory: 1.43 MB
Private memory:
4.42 MB
Page faults:
21,248
Page faults /min: 16
 | Process I/O averages |
Total read operations:
1,175
Read operations /min: 1
Total read transfer: 90.65 KB
Read transfer /min: 165 Bytes
Total write operations:
146
Write operations /min: 1
Total write transfer: 543.51 KB
Write transfer /min: 1016 Bytes
Total other operations:
4,077
Other operations /min: 4
Total other transfer: 57.93 KB
Other Transfer /min: 67 Bytes
 | GUI Object Averages |
GDI objects:
14
Peak GDI objects: 16
USER objects:
9
Peak USER objects: 10
Resources
Handle count average: 172
Thread count average: 6
Thread resource averages
rundll32.exe

Total CPU: 0.004465053532%
Privileged CPU: 0.003337664869%
User CPU: 0.001127388663%
CPU Cycle count /sec: 84,098
Module memory size: 64 KB
wow64.dll

Total CPU: 0.001851386370%
Privileged CPU: 0.001851386370%
User CPU: 0.000000000000%
CPU Cycle count /sec: 169,745
Module memory size: 292 KB
Total CPU: 0.000356125485%
Privileged CPU: 0.000282017592%
User CPU: 0.000074107893%
CPU Cycle count /sec: 18,696
Module memory size: 56 KB
wow64.dll

Total CPU: 0.000211061740%
Privileged CPU: 0.000152640353%
User CPU: 0.000058421387%
CPU Cycle count /sec: 4,104
Module memory size: 252 KB
ntdll.dll

Total CPU: 0.000106510721%
Privileged CPU: 0.000067411849%
User CPU: 0.000039098872%
CPU Cycle count /sec: 15,023
Module memory size: 1.66 MB
Total CPU: 0.000097786463%
Privileged CPU: 0.000043460333%
User CPU: 0.000054326130%
CPU Cycle count /sec: 3,340
Module memory size: 64 KB
Process details
Runs as (owner): User
Integrety level: Medium
Windows platform: 64-bit
Parent Processes
Process Commands
"C:\Windows\SysWOW64\rundll32.exe" "C:\users\user\appdata\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun
C:\Windows\SysWOW64\Rundll32.exe "C:\users\user\appdata\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun
"C:\Windows\SysWOW64\rundll32.exe" "C:\users\user\appdata\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun
C:\WINDOWS\SysWOW64\Rundll32.exe "C:\users\user\appdata\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun
"C:\Windows\SysWOW64\rundll32.exe" "C:\users\user\appdata\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun
Startup files (user) run details
Name: BackgroundContainer
Command: "C:\Windows\SysWOW64\Rundll32.exe" "C:\users\user\appdata\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun
Scheduled task details
Name: BackgroundContainer Startup Task
Command: \BackgroundContainer Startup Task
Scheduled tasks startup details
Name: \BackgroundContainer Startup Task
Network connectivity
UDP: LISTENING on port 55425
TCP: localhost on port 56691
Image hashes
MD5: fd42ea980fe1833b3a5eb429273cd1b2
SHA-1: d86451022ddd8348105c1d52fbfd2adb1e2dcc30
PE image details
File packed: No