File details
File name: firefox.exe
Name: Firefox
Description: Firefox
Version: 21.0
Size: 898.9 KB
Original file name: firefox.exe
Digital certificate
Certificate authority:
Thawte
Effective date: 9/27/2010
Expiration date: 10/30/2011
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0355706051%
Privileged CPU:
0.0169963874%

User CPU:
0.01857421769678%

Privileged CPU time: 127592768.77 ms
Privileged CPU time /min: 18,084 ms
CPU cycle count:
118,909,880
CPU cycle count /min: 523,210,093
Context switches /sec:
638
 | Memory utilization averages |
Committed memory:
656.91 MB
Peak committed memory: 583.22 MB
Paged memory:
333.81 MB
Peak paged memory: 413.8 MB
Paged system memory:
458.9 KB
Non-paged system memory: 99.54 KB
Working set memory:
320.6 MB
Peak working set memory: 418.7 MB
Min working set memory: 149.37 MB
Private memory:
333.81 MB
Page faults:
10,168,349
Page faults /min: 129,095
 | Process I/O averages |
Total read operations:
625,980
Read operations /min: 2,478
Total read transfer: 329.54 MB
Read transfer /min: 2.89 MB
Total write operations:
976,331
Write operations /min: 2,732
Total write transfer: 377.69 MB
Write transfer /min: 4.39 MB
Total other operations:
1,428,596
Other operations /min: 4,134
Total other transfer: 41.98 MB
Other Transfer /min: 232.89 KB
 | GUI Object Averages |
GDI objects:
329
Peak GDI objects: 499
USER objects:
66
Peak USER objects: 89
Resources
Handle count average: 658
Thread count average: 47
Thread resource averages
Total CPU: 0.750974733347%
Privileged CPU: 0.170115328661%
User CPU: 0.580859404686%
CPU Cycle count /sec: 17,723,916
Context switches /sec: 23
Module memory size: 904 KB
Total CPU: 0.104377657278%
Privileged CPU: 0.058841886262%
User CPU: 0.045535771016%
CPU Cycle count /sec: 1,095,150
Context switches /sec: 38
Module memory size: 19.81 MB
Total CPU: 0.102331266231%
Privileged CPU: 0.037181070765%
User CPU: 0.065150195466%
CPU Cycle count /sec: 854,816
Context switches /sec: 15
Module memory size: 760 KB
wow64.dll

Total CPU: 0.045620410611%
Privileged CPU: 0.045547505604%
User CPU: 0.000072905007%
CPU Cycle count /sec: 1,292,290
Context switches /sec: 2
Module memory size: 276 KB
wdmaud.drv

Total CPU: 0.032475102895%
Privileged CPU: 0.011328235980%
User CPU: 0.021146866914%
Context switches /sec: 20
Module memory size: 36 KB
ntdll.dll

Total CPU: 0.008054591058%
Privileged CPU: 0.000000000000%
User CPU: 0.008054591058%
CPU Cycle count /sec: 222,619
Module memory size: 1.4 MB
winmm.dll

Total CPU: 0.003957292499%
Privileged CPU: 0.001978646250%
User CPU: 0.001978646250%
CPU Cycle count /sec: 95,409
Module memory size: 200 KB
ntdll.dll

Total CPU: 0.003292076815%
Privileged CPU: 0.003118592073%
User CPU: 0.000173484741%
CPU Cycle count /sec: 210,122
Context switches /sec: 5
Module memory size: 1.66 MB
mswsock.dll

Total CPU: 0.002716169258%
Privileged CPU: 0.001810779505%
User CPU: 0.000905389753%
CPU Cycle count /sec: 22,020
Module memory size: 240 KB
rasman.dll

Total CPU: 0.000942483730%
Privileged CPU: 0.000942483730%
User CPU: 0.000000000000%
CPU Cycle count /sec: 2,682
Module memory size: 84 KB
d3d9.dll

Total CPU: 0.000932265145%
Privileged CPU: 0.000000000000%
User CPU: 0.000932265145%
CPU Cycle count /sec: 1,150
Module memory size: 1.76 MB
mswsock.dll

Total CPU: 0.000914798650%
Privileged CPU: 0.000653427607%
User CPU: 0.000261371043%
CPU Cycle count /sec: 18,661
Module memory size: 296 KB
ntdll.dll

Total CPU: 0.000910360373%
Privileged CPU: 0.000910360373%
User CPU: 0.000000000000%
CPU Cycle count /sec: 5,029
Module memory size: 1.23 MB
mswsock.dll

Total CPU: 0.000654229537%
Privileged CPU: 0.000327114768%
User CPU: 0.000327114768%
CPU Cycle count /sec: 12,474
Module memory size: 236 KB
mmdevapi.dll

Total CPU: 0.000252885476%
Privileged CPU: 0.000000000000%
User CPU: 0.000252885476%
CPU Cycle count /sec: 491
Module memory size: 228 KB
winmm.dll

Total CPU: 0.000132453129%
Privileged CPU: 0.000132453129%
User CPU: 0.000000000000%
CPU Cycle count /sec: 592
Module memory size: 132 KB
Total CPU: 0.000131733908%
Privileged CPU: 0.000000000000%
User CPU: 0.000131733908%
Module memory size: 248 KB
Total CPU: 0.000049183940%
Privileged CPU: 0.000049183940%
User CPU: 0.000000000000%
Module memory size: 1.1 MB
Total CPU: 0.000049183940%
Privileged CPU: 0.000000000000%
User CPU: 0.000049183940%
Module memory size: 1.09 MB
Process details
Runs as (owner): User
Integrety level: Medium
Windows platform: 64-bit
Parent Processes
Child Processes
Process Commands
"C:\Program Files\Mozilla Firefox\firefox.exe"
"C:\Program Files\Mozilla Firefox\firefox.exe"
"C:\Program Files\Mozilla Firefox\firefox.exe"
"C:\Program Files\Mozilla Firefox\firefox.exe"
"C:\Program Files\Mozilla Firefox\firefox.exe" -osint -url "httpC://data.smartfren.com/popbrowser.php?a=510289800598586&b=a00000370362fd"
Shell open command details
Name: gopher
Command: C:\Program Files1\MOZILL~1\FIREFOX.EXE -requestPending -osint -url "%1"
Scheduled task details
CLSID: {30950B1D-F704-4AA9-B20C-E6C28D3808C2}
Command: \{30950B1D-F704-4AA9-B20C-E6C28D3808C2}
Image hashes
MD5: 95110a1c5a1d228ac1ddf6ab67d00beb
SHA-1: d89a9491c714a55d3811eeac8930c77b90fd59e9
SHA-256: 57a6c516e2a06c5e4e9134d8c230a385254a21fba8bde0e6e30ec086812f1f0b
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++ 10.0
File entropy: 5.40881
File packed: No
Import Table
kernel32.dll

GetEnvironmentVariableW
GetProcessIoCounters
SetDllDirectoryW
GetCurrentProcess
SetEnvironmentVariableW
GetSystemTimeAsFileTime
WideCharToMultiByte
GetModuleFileNameW
MultiByteToWideChar
ExpandEnvironmentStringsW
IsDebuggerPresent
UnhandledExceptionFilter
GetCurrentProcessId
GetCurrentThreadId
GetTickCount
QueryPerformanceCounter
DecodePointer
SetUnhandledExceptionFilter
EncodePointer
HeapSetInformation
InterlockedCompareExchange
Sleep
InterlockedExchange
CloseHandle
GetProcAddress
GetLastError
CreateFileW
ReadFile
LoadLibraryExW
FreeLibrary
TerminateProcess
GetFileAttributesW
SearchPathW
VirtualAllocEx
VirtualProtectEx
LoadLibraryExA
GetModuleHandleW
SetFilePointerEx
QueryPerformanceFrequency
mozalloc.dll

moz_malloc
moz_xmalloc
moz_free
mozcrt19.dll

_lock
__dllonexit
_unlock
__set_app_type
_encode_pointer
_onexit
__p__commode
_adjust_fdiv
__setusermatherr
_configthreadlocale
_initterm_e
_initterm
__winitenv
exit
_XcptFilter
_exit
_cexit
__wgetmainargs
_amsg_exit
_fdopen
fclose
_dup
vfprintf
_decode_pointer
_except_handler4_common
_invoke_watson
_controlfp_s
_crt_debugger_hook
__p__fmode
wcsrchr
wcslen
memcpy
_vsnwprintf
strcmp
msvcr100.dll
nspr4.dll

PR_smprintf
PR_smprintf_free
PR_GetEnv
PR_SetEnv
plc4.dll

user32.dll

version.dll

GetFileVersionInfoSizeW
GetFileVersionInfoW
VerQueryValueW
xpcom.dll

NS_StringGetData
NS_LogInit
NS_CStringContainerFinish
NS_StringContainerInit
NS_CStringContainerInit2
NS_LogTerm
NS_StringContainerFinish
NS_CStringToUTF16
xul.dll

XRE_GetBinaryPath
XRE_GetFileFromPath
NS_SetDllDirectory
XRE_FreeAppData
XRE_CreateAppData
XRE_main