Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

2,6,0,9 1.35%
2,6,0,9 4.05%
2,6,0,8 67.57%
2,6,0,8 1.35%
2,6,0,8 13.51%
2,6,0,7 4.05%
2,6,0,2 1.35%
2,3,6,0 5.41%
2,3,5,2 1.35%

Relationships

Parent processes
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegDeleteValueW, CryptDestroyKey, CryptEncrypt, CryptDestroyHash, CryptDeriveKey, GetCurrentHwProfileW, RegEnumKeyExW, RegQueryInfoKeyW, AllocateAndInitializeSid, CheckTokenMembership, FreeSid, RegDeleteKeyW, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, RegCloseKey, RegOpenKeyExW, RegQueryValueExW, RegCreateKeyExW, RegSetValueExW, CryptHashData, CryptAcquireContextW, CryptReleaseContext, CryptCreateHash, CryptDecrypt, RegOpenKeyExA, RegQueryValueExA, RegisterEventSourceA, ReportEventA, DeregisterEventSource
comctl32.dll
_TrackMouseEvent
gdi32.dll
DeleteObject, SelectObject, CreateFontIndirectW, GetObjectW, GetStockObject, GetDeviceCaps, DPtoLP, SetBkMode, SetTextColor
gdiplus.dll
GdiplusShutdown, GdipCreateBitmapFromStream, GdipGetImageWidth, GdipGetImageHeight, GdipGetImagePixelFormat, GdipCloneBitmapAreaI, GdipCloneImage, GdipAlloc, GdipDisposeImage, GdipFree, GdiplusStartup
kernel32.dll
CreateFileMappingW, OpenMutexW, GetLastError, OpenFileMappingW, MapViewOfFile, UnmapViewOfFile, WaitForSingleObject, ReleaseMutex, Sleep, SizeofResource, LockResource, LoadResource, FindResourceW, FindResourceExW, lstrlenW, CreateThread, TerminateThread, GetDiskFreeSpaceExW, lstrcpynW, GetCurrentProcess, FlushInstructionCache, CompareStringW, lstrcpyW, lstrcmpiW, MultiByteToWideChar, lstrcpynA, lstrlenA, SetLastError, EnterCriticalSection, LeaveCriticalSection, GetCurrentThreadId, RaiseException, MulDiv, WideCharToMultiByte, GetVersionExW, GetProcessHeap, HeapFree, CloseHandle, HeapAlloc, CreateEventA, CreateToolhelp32Snapshot, Process32FirstW, Process32NextW, OpenProcess, GetProcessTimes, GlobalFree, Module32FirstW, Module32NextW, GetModuleHandleW, GetProcAddress, GetLocaleInfoW, GetTimeZoneInformation, GlobalMemoryStatusEx, GetTempPathW, GetTempFileNameW, SetEvent, FreeLibrary, LoadLibraryExW, GetModuleFileNameW, CreateMutexW, InterlockedIncrement, OutputDebugStringW, GetVolumeInformationW, GetFileInformationByHandle, DeviceIoControl, SetFilePointerEx, ReadFile, SetFilePointer, WriteFile, FlushFileBuffers, InitializeCriticalSectionAndSpinCount, WaitForMultipleObjects, QueueUserAPC, CreateEventW, SleepEx, PostQueuedCompletionStatus, RemoveDirectoryW, DeleteFileW, CreateDirectoryW, DeleteCriticalSection, InitializeCriticalSection, RemoveDirectoryA, DeleteFileA, CreateDirectoryA, MoveFileW, CopyFileW, FindFirstFileW, FindClose, SetEndOfFile, CreateFileW, TlsFree, ReleaseSemaphore, DuplicateHandle, CreateSemaphoreA, LoadLibraryW, GetUserDefaultLCID, GetStringTypeExA, LCMapStringA, GetFileAttributesW, GetFileAttributesA, VirtualAlloc, CreateIoCompletionPort, SetWaitableTimer, GetQueuedCompletionStatus, InterlockedCompareExchange, TlsGetValue, TlsSetValue, HeapDestroy, HeapReAlloc, HeapSize, LoadLibraryA, QueryPerformanceCounter, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, TerminateProcess, GetStartupInfoW, CreateWaitableTimerA, SystemTimeToFileTime, GetTickCount, ResumeThread, ResetEvent, OpenEventA, GetCurrentProcessId, GetSystemTimeAsFileTime, FormatMessageA, LocalFree, FindNextFileW, IsProcessorFeaturePresent, VirtualFree, TlsAlloc, InterlockedExchangeAdd, InterlockedExchange, GlobalUnlock, GlobalLock, GlobalAlloc, InterlockedDecrement, GetEnvironmentVariableW, GlobalMemoryStatus, ExpandEnvironmentStringsA, PeekNamedPipe, GetStdHandle, GetFileType, GetVersion, GetModuleHandleA, SetThreadPriority, GetCurrentThread, GetVersionExA, FlushConsoleInputBuffer, GetSystemInfo
msvcp90.dll
DllMain
msvcr90.dll
DllMain
nspr4.dll
PR_Unlock, PR_Lock, PR_ExplodeTime, PR_LocalTimeParameters, PR_sscanf, PR_NewLock, PR_smprintf_free, PR_GetCurrentThread, PR_Malloc, PR_sprintf_append, PR_GMTParameters, PR_ntohl, PR_Free, PR_IntervalNow, PR_Realloc, PR_EnterMonitor, PR_ExitMonitor, PR_Notify, PR_DestroyMonitor, PR_Close, PR_Wait, PR_DestroyPollableEvent, PR_IntervalToMilliseconds, PR_Init, PR_CreateThreadPool, PR_QueueJob, PR_ShutdownThreadPool, PR_JoinThreadPool, PR_Listen, PR_Accept, PR_RecvFrom, PR_htonll, PR_NewPollableEvent, PR_GetError, PR_WaitForPollableEvent, PR_Calloc, PR_CreateThread, PR_JoinThread, PR_MicrosecondsToInterval, PR_Poll, PR_GetOSError, PR_SetPollableEvent, PR_htons, PR_htonl, PR_SetSocketOption, PR_DestroyLock, PR_TicksPerSecond, PR_Sleep, PR_snprintf, PR_SecondsToInterval, PR_Now, PR_MillisecondsToInterval, LL_Zero, PR_ImplodeTime, PR_GetLayersIdentity, PR_PushIOLayer, PR_CreateIOLayerStub, PR_GetUniqueIdentity, PR_GetDefaultIOMethods, PR_SetError, PR_PopIOLayer, PR_GetIdentitiesLayer, PR_GetSockName, PR_WaitCondVar, PR_NotifyCondVar, PR_NewCondVar, PR_DestroyCondVar, PR_NewUDPSocket, PR_NewTCPSocket, PR_ntohs, PR_NetAddrToString, PR_EnumerateHostEnt, PR_GetHostByName, PR_IntervalToSeconds, PR_Recv, PR_Send, PR_SendTo, PR_StringToNetAddr, PR_Bind, PR_InitializeNetAddr, PR_GetConnectStatus, PR_Connect, PR_GetSocketOption, PR_NewMonitor, PR_smprintf
nss3.dll
PK11_FreeSlot, PK11_GetBestSlot, PK11_FreeSymKey, PK11_ImportSymKey, SECITEM_FreeItem, PK11_ParamFromIV, PK11_DestroyContext, PK11_CreateContextBySymKey, PK11_CipherOp, PK11_DigestFinal, NSSBase64_EncodeItem, NSSBase64_DecodeBuffer, NSS_Initialize, CERT_VerifyCertNow, CERT_GetDefaultCertDB, CERT_DestroyCertificate, CERT_VerifyCertName, PK11_FindCertFromNickname, PK11_FindKeyByAnyCert, SECKEY_DestroyPrivateKey, BTOA_DataToAscii, PORT_Free, PK11_CreateDigestContext, PK11_DigestOp, PK11_DigestBegin, PORT_ZAlloc, PK11_NeedLogin, PK11_Authenticate, PK11_IsFriendly, PK11_InitPin, PK11_NeedUserInit, PK11_GetInternalKeySlot, PK11_SetPasswordFunc, SEC_DerSignData, PORT_ArenaZAlloc, NSS_Get_CERT_CertificateTemplate, SEC_ASN1EncodeItem, SECOID_SetAlgorithmID, CERT_CreateCertificate, CERT_CreateValidity, CERT_CreateCertificateRequest, NSS_Shutdown, PK11_HashBuf, CERT_FindCertByNickname, CERT_DecodeTrustString, PK11_ImportCert, CERT_ChangeCertTrust, PK11_RandomUpdate, PK11_GenerateKeyPair, SECKEY_CreateSubjectPublicKeyInfo, CERT_AsciiToName
ole32.dll
CreateStreamOnHGlobal, CoCreateInstance, CoTaskMemAlloc, CoTaskMemRealloc, CoTaskMemFree
pdh.dll
PdhCloseQuery, PdhOpenQueryW, PdhAddCounterW, PdhCollectQueryData, PdhExpandWildCardPathW, PdhLookupPerfNameByIndexW, PdhGetFormattedCounterValue, PdhRemoveCounter
plc4.dll
PL_strncasecmp, PL_strstr, PL_strpbrk, PL_strnstr, PL_strncpyz, PL_strncmp, PL_strndup, PL_strnrstr, PL_strcpy, PL_strcmp, PL_strrchr, PL_strrstr, PL_strdup, PL_strchr, PL_strfree, PL_strcasecmp, PL_strlen
rpcrt4.dll
UuidCreate
sensapi.dll
IsNetworkAlive
shell32.dll
ShellExecuteW, SHGetFolderPathA, ShellExecuteExW, SHGetFolderPathW, SHCreateDirectoryExW
smime3.dll
CERT_DecodeCertFromPackage
ssl3.dll
SSL_SetURL, SSL_AuthCertificateHook, SSL_OptionSet, SSL_ImportFD, SSL_RevealURL, SSL_ConfigSecureServer, SSL_ResetHandshake, SSL_PeerCertificate, SSL_ConfigServerSessionIDCache, NSS_SetDomesticPolicy, SSL_RevealPinArg, NSS_FindCertKEAType, SSL_OptionSetDefault
user32.dll
LoadCursorW, GetClassNameW, LoadStringW, LoadStringA, PostQuitMessage, SetFocus, DialogBoxParamW, EndDialog, DestroyMenu, GetMenuItemCount, AppendMenuW, GetMenuItemInfoW, MessageBeep, GetDC, MonitorFromPoint, PeekMessageW, PtInRect, InvalidateRect, CreatePopupMenu, RemoveMenu, UpdateWindow, ScreenToClient, GetCursorPos, GetDlgCtrlID, ReleaseCapture, DrawTextW, OffsetRect, TrackPopupMenuEx, ReleaseDC, GetCapture, SetCapture, SetCursor, IsWindow, CharNextW, GetWindowTextW, CallWindowProcW, DrawFocusRect, GetFocus, GetSysColor, UnregisterClassA, IsWindowEnabled, FillRect, EndPaint, BeginPaint, DestroyWindow, ShowWindow, SetDlgItemInt, SetDlgItemTextW, EnableWindow, GetDlgItemInt, SendMessageTimeoutW, DispatchMessageW, TranslateMessage, GetMessageW, LoadMenuW, LoadAcceleratorsW, LoadImageW, RegisterWindowMessageW, CreateWindowExW, SendMessageW, SetWindowTextW, GetDlgItem, CheckDlgButton, LoadBitmapW, SetWindowPos, MapWindowPoints, GetClientRect, GetParent, GetWindowRect, GetMonitorInfoW, GetClassInfoExW, wvsprintfW, DefWindowProcW, SetWindowLongW, SetRectEmpty, TranslateAcceleratorW, GetActiveWindow, PostMessageW, IsDlgButtonChecked, MessageBoxW, GetWindow, GetWindowLongW, MonitorFromWindow, KillTimer, SetTimer, RegisterClassExW, GetWindowTextLengthW, GetDesktopWindow, MessageBoxA, GetUserObjectInformationW, SystemParametersInfoW, GetProcessWindowStation, EnumWindows
winhttp.dll
WinHttpOpen, WinHttpSetStatusCallback, WinHttpCloseHandle, WinHttpGetProxyForUrl
wininet.dll
DetectAutoProxyUrl, InternetQueryOptionW
ws2_32.dll
WSALookupServiceNextW, WSALookupServiceEnd, WSALookupServiceBeginW, WSANSPIoctl, getaddrinfo, freeaddrinfo

PMB.exe

Pando Media Booster by Pando Networks (Signed)

Remove PMB.exe
Version:   2,6,0,8
MD5:   4458989c34fa84b5a75dd3abcfbe786a
SHA1:   14327d78e591c1583c7785fd08d5f3d72be5f048
SHA256:   d37cbb988e98929d65c4d22b030abebd2ce2ffe091b63424d0f55c16958daef1

Overview

pmb.exe executes as a process with the local user's privileges usually within the context of Windows Explorer. It is set to be run when the PC boots and the user logs into Windows (added to the Run registry key for the current user). It has been configured with a firewall exception which allows both inbound and outbound network communication without being blocked. It is installed with a couple of know programs including Pando Media Booster published by Pando Networks Inc., Pando Media Booster from Pando Networks Inc. and Pando Media Booster by Pando Networks Inc..

DetailsDetails

File name:pmb.exe
Product name:Pando Media Booster
Typical file path:C:\Program Files\pando networks\media booster\pmb.exe
File version:2,6,0,8
Size:2.95 MB (3,093,624 bytes)
Certificate
Issued to:Pando Networks
Authority (CA):Thawte
Effective date:Wednesday, April 4, 2012
Expiration date:Sunday, June 29, 2014
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 9.0
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
Pando Networks Inc.
  51% remove
Pando Media Booster (PMB) is an application by Pando Networks that is used by game and software publishers to ensure safe, complete and speedy downloads of large files. PMB is primarily used to download MMORPGs. Users of PMB participate in a secure, closed peer-to-peer network where users receive pieces of the download package from a Content Delivery Network (CDN) as well as other active users (peers). Unlike Pando, PMB cannot be used t...

BehaviorsBehaviors

Startup files (user) run
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'Pando Media Booster' → C:\Program Files\Pando Networks\Media Booster\PMB.exe
Windows firewall allowed programs
Exceptions allow programs to access to the Internet through an outbound connections
  • Firewall exception for 'C:\Program Files\Mozilla Firefox\Pando Networks\Media Booster\PMB.exe'
  • Firewall exception for 'C:\Program Files\Pando Networks\Media Booster\PMB.exe'
  • Firewall exception for 'C:\Program Files\Pando Networks\Media Booster\PMB.exe'
Network connections
Access through an approved Windows firewall exception
  • [TCP] 31.23.87.15:57495
  • [TCP] ip31-192-232-229.dynamic.vashetv.ru (31.192.232.229:56826)
  • [UDP] listens on port 56100
  • [UDP] listens on port 56959
  • [UDP] listens on port 56894
  • [UDP] listens on port 56841
  • [UDP] listens on port 58433
  • [UDP] listens on port 58978
  • [UDP] listens on port 56768
  • [UDP] listens on port 56574
  • [UDP] listens on port 57901

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.01830322%
    0.028634%
    Kernel CPU:0.00706443%
    0.013761%
    User CPU:0.01123879%
    0.014873%
    Kernel CPU time:10,842,214 ms/min
    100,923,805ms/min
    CPU cycles:3,703,303/sec
    17,470,203/sec
    Context switches:75/sec
    284/sec
    Memory
    Private memory:24.21 MB
    21.59 MB
    Private (maximum):25.8 MB
    Private (minimum):16.82 MB
    Non-paged memory:24.21 MB
    21.59 MB
    Virtual memory:132.87 MB
    140.96 MB
    Virtual memory (peak):140.21 MB
    169.69 MB
    Working set:20.99 MB
    18.61 MB
    Working set (peak):26.15 MB
    37.95 MB
    Page faults:46,978/min
    2,039/min
    I/O
    I/O read transfer:6.43 MB/sec
    1.02 MB/min
    I/O read operations:110/sec
    343/min
    I/O write transfer:189.18 KB/sec
    274.99 KB/min
    I/O write operations:1,508/sec
    227/min
    I/O other transfer:226.66 KB/sec
    448.09 KB/min
    I/O other operations:9,345/sec
    1,671/min
    Resource allocations
    Threads:25
    12
    Handles:447
    600
    GUI GDI count:17
    103
    GUI GDI peak:20
    142
    GUI USER count:9
    49
    GUI USER peak:12
    71

    BehaviorsProcess properties

    Integrety level:Medium
    Platform:64-bit
    Command line:"C:\Program Files\pando networks\media booster\pmb.exe"
    Owner:User
    Parent processes:

    ResourcesThreads

    Averages
     
    ntdll.dll
    Total CPU:0.14315047%
    0.272967%
    Kernel CPU:0.00003208%
    0.107585%
    User CPU:0.14311839%
    0.165382%
    CPU cycles:68,634/sec
    5,741,424/sec
    Memory:1.66 MB
    1.16 MB
    PMB.exe (main module)
    Total CPU:0.05511310%
    Kernel CPU:0.02087873%
    User CPU:0.03423437%
    CPU cycles:2,049,447/sec
    Context switches:8/sec
    Memory:2.97 MB
    MSVCR90.dll
    Total CPU:0.02455088%
    Kernel CPU:0.00682010%
    User CPU:0.01773077%
    CPU cycles:590,040/sec
    Memory:652 KB
    wow64.dll (Win32 Emulation on NT64 by Microsoft)
    Total CPU:0.00001526%
    Kernel CPU:0.00000763%
    User CPU:0.00000763%
    CPU cycles:231/sec
    Memory:252 KB

    Common loaded modules

    These are modules that are typiclaly loaded within the context of this process.

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Windows 7 Home Premium 27.03%
    Microsoft Windows XP 25.68%
    Windows 7 Ultimate 20.27%
    Windows 8 Pro 8.11%
    Windows 7 Professional 6.76%
    Windows 8 Pro with Media Center 4.05%
    Windows 8 4.05%
    Windows Vista Home Premium 2.70%
    Windows 7 Starter 1.35%

    Distribution by countryDistribution by country

    United States installs about 35.14% of Pando Media Booster.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    Toshiba 21.05%
    GIGABYTE 17.54%
    Hewlett-Packard 14.04%
    Acer 14.04%
    Dell 10.53%
    Compaq 7.02%
    Intel 3.51%
    Sony 3.51%
    Sahara 3.51%
    ASUS 3.51%
    American Megatrends 1.75%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE