Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

f29b0 33.33%
58589 33.33%
7ecbc 33.33%
(Note, TVersity Inc. publishes each variation of this file with the same version, but the hashes are unique.)

Relationships

Parent process
Child process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
StartServiceCtrlDispatcherA, RegisterServiceCtrlHandlerExA, SetServiceStatus, DeleteService, ControlService, StartServiceA, QueryServiceStatus, OpenSCManagerA, OpenServiceA, CloseServiceHandle, ChangeServiceConfigA, CreateServiceA, RegisterEventSourceA, ReportEventA, DeregisterEventSource, RegDeleteValueW, RegDeleteValueA, RegSetValueExW, RegSetValueExA, RegQueryValueExW, RegQueryValueExA, RegDeleteKeyW, RegQueryInfoKeyA, RegDeleteKeyA, RegCreateKeyExW, RegOpenKeyExW, RegCreateKeyExA, RegOpenKeyExA, RegCloseKey
core_rl_magick_.dll
AcquireExceptionInfo, CloneImageInfo, CloneString, GetImageType, RotateImage, DestroyImage, CropImage, ResizeImage, ImagesToBlob, DestroyImageList, DestroyImageInfo, DestroyExceptionInfo, PingBlob, BlobToImage, DestroyMagick, InitializeMagick
easyhook32.dll
_LhWaitForPendingRemovals@0, _LhSetExclusiveACL@12, _LhInstallHook@16, _RtlGetLastErrorString@0, _RhInjectLibrary@28, _LhUninstallHook@4
fribidi.dll
fribidi_reorder_line, fribidi_shape, fribidi_join_arabic, fribidi_get_par_embedding_levels, fribidi_get_bidi_types, fribidi_get_joining_types
kernel32.dll
Sleep, LocalFree, lstrlenA, FormatMessageA, lstrcmpW, CreateEventA, ReleaseSemaphore, GetSystemInfo, VirtualFree, DuplicateHandle, GetCurrentProcess, GetCurrentThreadId, CreateSemaphoreA, DeleteFileW, GetTickCount, CreateEventW, WaitForSingleObject, SetEvent, LeaveCriticalSection, EnterCriticalSection, DeleteCriticalSection, InitializeCriticalSection, GetModuleHandleA, SetThreadExecutionState, WaitForMultipleObjects, FindCloseChangeNotification, FindFirstChangeNotificationW, ConnectNamedPipe, DisconnectNamedPipe, PeekNamedPipe, VirtualAlloc, CreateThread, FreeLibrary, WideCharToMultiByte, GetACP, lstrlenW, SetThreadPriority, GetThreadPriority, GetCurrentThread, MultiByteToWideChar, RemoveDirectoryW, GetModuleFileNameA, FindNextFileW, GetFileAttributesExW, GetDiskFreeSpaceExW, CreateFileW, GetTempFileNameW, FlushFileBuffers, GetTempPathW, FindFirstFileW, SetFilePointer, FindClose, CreateDirectoryW, TryEnterCriticalSection, GetSystemTimeAsFileTime, GetComputerNameA, QueryPerformanceCounter, GlobalMemoryStatus, HeapFree, GetProcessHeap, ReadFile, CreateNamedPipeA, GetLastError, GetCurrentProcessId, CreateToolhelp32Snapshot, Process32First, CloseHandle, Module32First, Module32Next, Process32Next, LoadLibraryA, InterlockedCompareExchange, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetProcAddress, GetLogicalDriveStringsA, GetVersionExA, InterlockedDecrement, InterlockedIncrement, InterlockedExchange, ExpandEnvironmentStringsW, SetErrorMode, SetConsoleCtrlHandler, CreateProcessW, LoadLibraryW, lstrcmpiA, WriteFile, ResetEvent, ExpandEnvironmentStringsA
libapr.dll
_apr_palloc@8, _apr_conv_utf8_to_ucs2@16, apr_pool_cleanup_null, _apr_pool_cleanup_register@16, _apr_pool_cleanup_kill@12, _apr_conv_ucs2_to_utf8@16, _apr_array_push@4, _apr_array_make@12, _apr_hash_set@16, _apr_hash_make@4, _apr_hash_get@12, _apr_sleep@8, _apr_thread_mutex_unlock@4, _apr_thread_mutex_lock@4, _apr_thread_mutex_create@12, _apr_thread_mutex_destroy@4, _apr_thread_cond_destroy@4, _apr_thread_cond_create@8, _apr_time_now@0, _apr_thread_detach@4, _apr_thread_cond_wait@8, _apr_thread_cond_timedwait@16, _apr_thread_data_set@16, _apr_thread_exit@8, _apr_thread_cond_signal@4, _apr_thread_create@20, _apr_thread_join@8, _apr_thread_cond_broadcast@4, _apr_thread_data_get@12, _apr_pool_cleanup_run@12, _apr_env_set@12, apr_psprintf, _apr_time_exp_lt@12, apr_pstrcat, _apr_pstrdup@8, _apr_hash_next@4, _apr_hash_this@16, _apr_hash_first@8, _apr_proc_wait@16, _apr_proc_create@24, _apr_procattr_dir_set@8, _apr_procattr_io_set@16, _apr_procattr_create@8, _apr_proc_kill@8, _apr_pool_destroy@4, _apr_strerror@12, _apr_pool_create_ex@16, _apr_file_close@4, _apr_file_open@20, _apr_dir_close@4, _apr_dir_open@12, _apr_dir_read@12, apr_os_level, _apr_stat@16, _apr_rfc822_date@12, _apr_pstrndup@12, _apr_pstrmemdup@12, _apr_filepath_get@12, _apr_file_lock@8, _apr_file_unlock@4, _apr_strftime@20, _apr_time_exp_gmt@12, _apr_time_exp_gmt_get@8, _apr_strtok@12, _apr_collapse_spaces@8, _apr_file_read_full@16, _apr_pmemdup@12, _apr_itoa@8, _apr_hash_copy@8, _apr_app_initialize@12, _apr_pool_allocator_get@4, _apr_allocator_max_free_set@8, apr_terminate, _apr_file_write@12, _apr_env_get@12, _apr_generate_random_bytes@8, _apr_is_empty_array@4, _apr_hash_count@4, _apr_threadkey_private_delete@4, _apr_threadkey_private_get@8, _apr_threadkey_private_set@8, _apr_threadkey_private_create@12, _apr_file_name_get@8, _apr_thread_mutex_trylock@4, _apr_pool_abort_get@4, _apr_array_pop@4, _apr_pool_clear@4, _apr_file_write_full@16, _apr_file_seek@12, _apr_file_info_get@12, _apr_file_ungetc@8, _apr_file_getc@8, _apr_dir_make_recursive@12, _apr_temp_dir_get@8, _apr_file_read@12, _apr_file_copy@16, _apr_file_remove@8, _apr_dir_remove@8, _apr_filepath_merge@20, _apr_thread_rwlock_unlock@4, _apr_thread_rwlock_wrlock@4, _apr_thread_rwlock_rdlock@4, _apr_thread_rwlock_create@8, apr_snprintf, _apr_threadattr_detach_set@8, _apr_threadattr_create@8, _apr_file_rename@12, _apr_file_mtime_set@16
libaprutil.dll
_apr_queue_pop@8, _apr_queue_trypush@8, _apr_queue_term@4, _apr_queue_interrupt_all@4, _apr_uuid_get@4, _apr_uuid_format@8, _apr_base64_encode_len@4, _apr_base64_encode@12, _apr_base64_decode_len@4, _apr_base64_decode@8, _apr_queue_size@4, _apr_queue_trypop@8, _apr_queue_create@12, _apr_queue_push@8, _apr_xml_parser_geterror@12, _apr_xml_parse_file@20, _apr_xml_parser_done@8, _apr_date_parse_rfc@4, _apr_xlate_open@16, _apr_xlate_conv_buffer@20, _apr_xlate_close@4, _apr_xml_parser_create@4, _apr_xml_parser_feed@12, _apr_md5@12, _apr_date_parse_http@4
libcurl.dll
curl_slist_append, curl_share_cleanup, curl_slist_free_all, curl_easy_strerror, curl_easy_perform, curl_easy_cleanup, curl_easy_init, curl_multi_add_handle, curl_multi_remove_handle, curl_easy_getinfo, curl_share_setopt, curl_multi_info_read, curl_multi_fdset, curl_multi_perform, curl_multi_cleanup, curl_multi_init, curl_global_init, curl_global_cleanup, curl_share_init, curl_easy_setopt
msvcp80.dll
DllMain
msvcr80.dll
DllMain
ole32.dll
CoInitializeEx, CoInitialize, CoFreeUnusedLibraries, CoTaskMemAlloc, CLSIDFromString, OleRun, StringFromGUID2, CoCreateInstance, GetRunningObjectTable, CreateItemMoniker, CoTaskMemFree, CoUninitialize
pthreadvc2.dll
pthread_cond_destroy, pthread_cond_signal, pthread_cond_wait, pthread_detach, pthread_cond_broadcast, pthread_cond_timedwait, pthread_self, pthread_getschedparam, sched_get_priority_min, sched_get_priority_max, pthread_setschedparam, sched_setscheduler, pthread_mutex_init, pthread_mutex_destroy, pthread_mutex_lock, pthread_mutex_unlock, pthread_cond_init, pthread_create
quartz.dll
AMGetErrorTextA
shell32.dll
ShellExecuteA
sqlite3.dll
sqlite3_finalize, sqlite3_column_text, sqlite3_column_type, sqlite3_column_bytes, sqlite3_column_name, sqlite3_step, sqlite3_column_count, sqlite3_prepare, sqlite3_errmsg, sqlite3_open, sqlite3_close, sqlite3_mprintf, sqlite3_free, sqlite3_changes
user32.dll
GetQueueStatus, RegisterWindowMessageA, DispatchMessageA, MsgWaitForMultipleObjects, PeekMessageA, wsprintfW, IsRectEmpty, PostThreadMessageA
winmm.dll
mixerGetControlDetailsA, mixerSetControlDetails, mixerGetDevCapsA, mixerClose, mixerGetLineInfoA, mixerGetLineControlsA, mixerGetID, mixerOpen, timeSetEvent, timeGetTime, waveOutGetPosition, waveOutClose, waveOutOpen, waveOutSetVolume, waveOutWrite
wmvcore.dll
WMCreateProfileManager, WMCreateIndexer
ws2_32.dll
WSAIoctl, WSASocketA

mediaserver.exe

By TVersity Inc. (Signed)

Remove mediaserver.exe
MD5:   58589716969f92844cf112c12da5352a
SHA1:   dad68a887cd2cdec2f116c49b0290ea79c87bc41

Overview

mediaserver.exe runs as a service under the name TVersityMediaServer (YesMediaServer) with extensive SYSTEM privileges (full administrator access). The file is digitally signed by TVersity Inc. which was issued by the The USERTRUST Network certificate authority (CA).

DetailsDetails

File name:mediaserver.exe
Typical file path:C:\ProgramData\tversity\media server\mediaserver.exe
Size:5.27 MB (5,521,192 bytes)
Build date:12/27/2011 12:09 PM
Certificate
Issued to:TVersity Inc.
Authority (CA):The USERTRUST Network
Effective date:Sunday, October 17, 2010
Expiration date:Thursday, October 17, 2013
Digital DNA
PE subsystem:Windows Console
File packed:No
Code language:Microsoft Visual C++ 8.0
.NET CLR:No
More details

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • TVersityMediaServer
  • 'YesMediaServer' (Yes Media Server)
  • 'TVersityMediaServer' (TVersity Media Server)
Network connections
  • [UDP] listens on port 1033

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.00118866%
    0.028634%
    Kernel CPU:0.00043235%
    0.013761%
    User CPU:0.00075632%
    0.014873%
    Kernel CPU time:18,406 ms/min
    100,923,805ms/min
    Memory
    Private memory:65.89 MB
    21.59 MB
    Private (maximum):63.38 MB
    Private (minimum):50.87 MB
    Non-paged memory:65.89 MB
    21.59 MB
    Virtual memory:223.89 MB
    140.96 MB
    Virtual memory (peak):226.35 MB
    169.69 MB
    Working set:63.38 MB
    18.61 MB
    Working set (peak):75.45 MB
    37.95 MB
    Resource allocations
    Threads:35
    12
    Handles:758
    600
    GUI GDI count:9
    103
    GUI USER count:18
    49

    BehaviorsProcess properties

    Integrety level:Undefined
    Platform:32-bit
    Command line:"C:\Program Files\yes streamer\mediaserver.exe"
    Owner:SYSTEM
    Windows Service
    Service name:YesMediaServer
    Display name:TVersityMediaServer
    Description:“The Windows service of the Yes Media Server software.”
    Type:Win32OwnProcess, InteractiveProcess
    Parent process:services.exe (by Microsoft)

    ResourcesThreads

    Averages
     
    MSVCR80.dll
    Total CPU:0.01012157%
    0.272967%
    Kernel CPU:0.00414228%
    0.107585%
    User CPU:0.00597929%
    0.165382%
    Memory:620 KB
    1.16 MB
    berkelium.dll (Chromium by The Chromium Authors)
    Total CPU:0.00915350%
    Kernel CPU:0.00150833%
    User CPU:0.00764518%
    Memory:27.74 MB
    msvcrt.dll
    Total CPU:0.00263395%
    Kernel CPU:0.00097415%
    User CPU:0.00165981%
    Memory:352 KB
    ntdll.dll
    Total CPU:0.00129677%
    Kernel CPU:0.00114068%
    User CPU:0.00015609%
    Memory:684 KB
    MediaServer.exe (main module)
    Total CPU:0.00039620%
    Kernel CPU:0.00028814%
    User CPU:0.00010805%
    Memory:5.38 MB
    dsound.dll
    Total CPU:0.00003602%
    Kernel CPU:0.00003602%
    User CPU:0.00000000%
    Memory:368 KB

    Common loaded modules

    These are modules that are typiclaly loaded within the context of this process.

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Windows 7 Home Premium 33.33%
    Microsoft Windows XP 33.33%
    Windows 7 Ultimate 33.33%

    Distribution by countryDistribution by country

    United States installs about 66.67% of mediaserver.exe.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    ASUS 66.67%
    American Megatrends 33.33%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE