Should I block it?

No, this file is 100% safe to run.

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
gdi32.dll
DeleteDC, RealizePalette, SelectPalette, CreateDCA, CreatePalette, DeleteObject, BitBlt, SelectObject, CreateCompatibleDC, CreateDIBitmap
kernel32.dll
CreateThread, GlobalUnlock, GlobalLock, GlobalAlloc, GetTickCount, WideCharToMultiByte, IsBadReadPtr, GlobalAddAtomA, GlobalAddAtomW, GetModuleHandleA, GlobalFree, GlobalGetAtomNameA, GlobalDeleteAtom, GlobalGetAtomNameW, FreeConsole, GetEnvironmentVariableA, VirtualProtect, VirtualAlloc, GetProcAddress, GetLastError, LoadLibraryA, SetLastError, SetThreadPriority, GetCurrentThread, CreateProcessA, GetCommandLineA, GetStartupInfoA, SetEnvironmentVariableA, ReleaseMutex, WaitForSingleObject, CreateMutexA, OpenMutexA, GetCurrentThreadId, ReadFile, GetFileSize, CreateFileA, FindClose, FindFirstFileA, FindFirstFileW, VirtualQueryEx, GetExitCodeProcess, ReadProcessMemory, UnmapViewOfFile, ContinueDebugEvent, SetThreadContext, GetThreadContext, WaitForDebugEvent, CloseHandle, DebugActiveProcess, ResumeThread, CreateProcessW, GetCommandLineW, GetStartupInfoW, MapViewOfFile, DuplicateHandle, GetCurrentProcess, CreateFileMappingA, VirtualProtectEx, WriteProcessMemory, ExitProcess, GetLocalTime, CompareStringA, FlushFileBuffers, LCMapStringW, LCMapStringA, SetStdHandle, GetOEMCP, GetACP, GetCPInfo, CompareStringW, GetStringTypeW, GetStringTypeA, MultiByteToWideChar, SetFilePointer, HeapReAlloc, WriteFile, VirtualFree, HeapCreate, HeapDestroy, GetFileType, GetStdHandle, SetHandleCount, GetEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsW, FreeEnvironmentStringsA, UnhandledExceptionFilter, HeapFree, HeapAlloc, GetVersion, GetSystemTime, GetTimeZoneInformation, RtlUnwind, TerminateProcess, Sleep, EnterCriticalSection, LeaveCriticalSection, GetVersionExA, InitializeCriticalSection, GetCurrentProcessId, GetModuleFileNameW, GetShortPathNameW, GetModuleFileNameA, SuspendThread, GetShortPathNameA
user32.dll
GetDesktopWindow, MoveWindow, SetPropA, EnumThreadWindows, GetPropA, GetMessageA, BeginPaint, EndPaint, KillTimer, GetAsyncKeyState, GetSystemMetrics, SetTimer, SetWindowTextA, GetDlgItem, CreateDialogIndirectParamA, ShowWindow, UpdateWindow, LoadStringA, LoadStringW, FindWindowA, WaitForInputIdle, DestroyWindow, MessageBoxA, InSendMessage, UnpackDDElParam, FreeDDElParam, DefWindowProcA, LoadCursorA, RegisterClassW, CreateWindowExW, RegisterClassA, CreateWindowExA, GetWindowThreadProcessId, SendMessageW, SendMessageA, TranslateMessage, DispatchMessageA, EnumWindows, IsWindowUnicode, PackDDElParam, PostMessageW, PostMessageA, IsWindow, PeekMessageA

mystery age - the imperial staff.exe

By Big Fish Games (Signed)

Remove mystery age - the imperial staff.exe
MD5:   b073bc9bffa07ddfdafed0d748de9e0a
SHA1:   64cf382fd2a7d4427a0910d36f9b545db0740c97
SHA256:   e7c8dc958839b241cbade91829c8a8eeca159700a0b534c518d38d878b2ffc20

Overview

mystery age - the imperial staff.exe executes as a process with the local user's privileges usually within the context of Windows Explorer. The file is digitally signed by Big Fish Games which was issued by the VeriSign certificate authority (CA). This particular version is usually found on Windows 7 Ultimate (6.1.7600.0).

DetailsDetails

File name:mystery age - the imperial staff.exe
Typical file path:C:\Program Files\games\mystery age the imperial staff\mystery age - the imperial staff.exe
Size:2.14 MB (2,241,872 bytes)
Certificate
Issued to:Big Fish Games
Authority (CA):VeriSign
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00111185%
0.028634%
Kernel CPU:0.00011812%
0.013761%
User CPU:0.00099373%
0.014873%
Kernel CPU time:501,418 ms/min
100,923,805ms/min
Memory
Private memory:83.72 MB
21.59 MB
Private (maximum):73.2 MB
Private (minimum):31.9 MB
Non-paged memory:83.72 MB
21.59 MB
Virtual memory:151.4 MB
140.96 MB
Virtual memory (peak):160.54 MB
169.69 MB
Working set:69.89 MB
18.61 MB
Working set (peak):77.71 MB
37.95 MB
Resource allocations
Threads:6
12
Handles:142
600
GUI GDI count:18
103
GUI GDI peak:22
142
GUI USER count:12
49
GUI USER peak:14
71

BehaviorsProcess properties

Integrety level:Medium
Platform:32-bit
Command line:"C:\Program Files\games\mystery age the imperial staff\mystery age - the imperial staff.exe"
Owner:User
Parent processes:

ResourcesThreads

Averages
 
Mystery Age - The Imperial Staff.exe (main module)
Total CPU:7.73417522%
0.272967%
Kernel CPU:3.40083171%
0.107585%
User CPU:4.33334351%
0.165382%
CPU cycles:165,766,897/sec
5,741,424/sec
Context switches:544/sec
79/sec
Memory:3.71 MB
1.16 MB
dsound.dll
Total CPU:0.04187505%
Kernel CPU:0.00845466%
User CPU:0.03342039%
CPU cycles:1,202,028/sec
Context switches:32/sec
Memory:456 KB
yodm3d.dll (Yod'm 3D by Christian Salmon)
Total CPU:0.03235489%
Kernel CPU:0.02342940%
User CPU:0.00892549%
CPU cycles:20,001,486/sec
Context switches:1,135/sec
Memory:60 KB
msvcrt.dll
Total CPU:0.00390483%
Kernel CPU:0.00039845%
User CPU:0.00350638%
CPU cycles:616,493/sec
Context switches:6/sec
Memory:688 KB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 100.00%

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE