File details
File name: MWSOEMON.EXE
Name: My Web Search Bar for Internet Explorer, email clients, and messenger clients
Description: My Web Search Plugin Loader
Version: 1,2,2,7
Product version: 2,3,0,0
Size: 37.51 KB
Original file name: mwsoemon.exe
Digital certificate
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0014796432%
Privileged CPU:
0.0003504891%

User CPU:
0.00112915414662%

Privileged CPU time: 187219.35 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
176,982,944
CPU cycle count /min: 5,409,384
 | Memory utilization averages |
Committed memory:
39.17 MB
Peak committed memory: 43.76 MB
Paged memory:
809.6 KB
Peak paged memory: 846.4 KB
Paged system memory:
59.5 KB
Non-paged system memory: 3.05 KB
Working set memory:
594 KB
Peak working set memory: 3 MB
Min working set memory: 521.2 KB
Private memory:
809.6 KB
Page faults:
2,944
Page faults /min: 218
 | Process I/O averages |
Total read operations:
19
Read operations /min: 1
Total read transfer: 21.9 KB
Read transfer /min: 8 Bytes
Total other operations:
129
Other operations /min: 6
Total other transfer: 18.21 KB
Other Transfer /min: 79 Bytes
 | GUI Object Averages |
GDI objects:
9
Peak GDI objects: 11
USER objects:
3
Peak USER objects: 4
Resources
Handle count average: 69
Thread count average: 2
Thread resource averages
Total CPU: 0.000531288718%
Privileged CPU: 0.000489647867%
User CPU: 0.000041640851%
CPU Cycle count /sec: 11,317
Module memory size: 32 KB
Process details
Runs as (owner): User
Integrety level: Undefined
Windows platform: 32-bit
Parent Processes
Process Commands
"C:\Program Files1\MYWEBS~1\bar\1.bin\mwsoemon.exe"
"C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE"
"C:\Program Files2\MYWEBS~1\bar\1.bin\mwsoemon.exe"
Startup files (all users) run details
Name: MyWebSearch Email Plugin
Command: C:\Program Files2\MYWEBS~1\bar\1.bin\mwsoemon.exe
Startup files (user) run details
Name: MyWebSearch Email Plugin
Command: C:\Program Files1\MYWEBS~1\bar\1.bin\mwsoemon.exe
Image hashes
MD5: 83d7eeb3e14f14c489d44a4d32d7fb44
SHA-1: e8d58e81cc8a12ed5a3bf5e82b2b0bb07193c667
SHA-256: 3382edcd0b5ef3e092e7d95f91567bac3f683c4fb3709f2d5f24bc1cea33b94f
PE image details
File packed: No
Import Table
advapi32.dll

RegOpenKeyExA
RegQueryValueExA
RegFlushKey
RegSetValueExA
RegCreateKeyExA
RegDeleteValueA
RegCloseKey
kernel32.dll

ReleaseMutex
InitializeCriticalSection
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
CreateEventA
lstrcmpA
CreateFileA
lstrcpyA
CreateDirectoryA
lstrcatA
WaitForMultipleObjects
GetTickCount
GetSystemTimeAsFileTime
FlushFileBuffers
WriteFile
GetStartupInfoA
ExitProcess
GetCommandLineA
GetModuleHandleA
DebugBreak
HeapAlloc
GetProcessHeap
HeapReAlloc
CreateMutexA
MultiByteToWideChar
WideCharToMultiByte
lstrlenW
CreateThread
Sleep
FreeLibrary
GetProcAddress
LoadLibraryA
SetThreadPriority
GetCurrentThread
GetFileAttributesA
GetCurrentProcessId
OpenProcess
LocalFree
GetVersionExA
GetDriveTypeA
lstrcpynA
CreateFileMappingA
SetLastError
DuplicateHandle
GetCurrentProcess
OpenFileMappingA
MapViewOfFile
UnmapViewOfFile
SetEvent
WaitForSingleObject
ResetEvent
GetModuleFileNameA
lstrlenA
GetLastError
HeapFree
CloseHandle
ole32.dll

shell32.dll

SHGetPathFromIDListA
SHGetMalloc
SHGetSpecialFolderLocation
user32.dll

MsgWaitForMultipleObjects
GetMessageA
TranslateMessage
GetKeyboardType
IsWindow
DestroyWindow
UnhookWindowsHookEx
CharNextA
wsprintfA
SetWindowsHookExA
DispatchMessageA
CreateDialogIndirectParamA
version.dll

GetFileVersionInfoSizeA
VerQueryValueA
GetFileVersionInfoA