Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

e56ae 50.00%
161ef 50.00%
(Note, the developer publishes each variation of this file with the same version, but the hashes are unique.)

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
RegCloseKey, RegOpenKeyExA, RegDeleteValueA, RegQueryValueExA, RegOpenKeyA, RegCreateKeyA, RegSetValueExA
gdi32.dll
SetBkMode, EnumFontFamiliesExA, GetObjectA, CreateSolidBrush, CreateFontIndirectA, FillRgn, SelectObject, SetTextAlign, BeginPath, TextOutA, EndPath, PathToRegion, PaintRgn, OffsetRgn, GetStockObject, FrameRgn, GetRegionData, ExtCreateRegion, CreateRectRgnIndirect, CreatePolygonRgn, CreateEllipticRgn, CombineRgn, CreateRectRgn, DeleteObject, CreateRoundRectRgn
kernel32.dll
GetEnvironmentStringsW, GetEnvironmentStrings, WideCharToMultiByte, SetHandleCount, FreeEnvironmentStringsA, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, GetProcAddress, HeapReAlloc, VirtualAlloc, VirtualFree, HeapCreate, HeapDestroy, GetStdHandle, GetFileType, RtlUnwind, WriteFile, GetLastError, SetFilePointer, MultiByteToWideChar, GetCPInfo, GetACP, GetOEMCP, LoadLibraryA, SetStdHandle, GetStringTypeA, GlobalUnlock, GetStringTypeW, ReadFile, LCMapStringA, LCMapStringW, FlushFileBuffers, GlobalFree, GlobalAlloc, GlobalSize, GlobalReAlloc, GlobalLock, FreeEnvironmentStringsW, GetVersionExA, GetEnvironmentVariableA, GetModuleFileNameA, ExitProcess, HeapAlloc, HeapFree, GetModuleHandleA, GetStartupInfoA, GetCommandLineA, GetVersion, CloseHandle
shell32.dll
Shell_NotifyIconA
user32.dll
GetMessageA, DestroyIcon, GetSystemMetrics, MoveWindow, GetWindowLongA, LoadIconA, LoadImageA, SetWindowRgn, GetDC, ReleaseDC, DrawIconEx, OffsetRect, InflateRect, CopyRect, RegisterClassExA, DestroyWindow, UpdateWindow, CreateWindowExA, TranslateMessage, DispatchMessageA, ShowWindow, PostQuitMessage, FindWindowA, PostMessageA, SendMessageA, RegisterWindowMessageA, KillTimer, DefWindowProcA, GetForegroundWindow, GetClassNameA, GetWindowRect, SetWindowPos, SetTimer
winmm.dll
PlaySoundA

tponscr.exe

Remove tponscr.exe
MD5:   e56aed1ad96125ae952f9b2b1d468177
SHA1:   2e0667049e3d535ad248de35a6f0fa8fe4b0abf8
SHA256:   5dba1097be0bac507c53abe3e4c0a4e0de04f022cfc9404dc79d1c6232cae8bf

Overview

tponscr.exe executes as a process with the local user's privileges typically within the context of its parent TPHKMGR.exe.

DetailsDetails

File name:tponscr.exe
Typical file path:C:\Program Files\lenovo\pkgmgr\hotkey\tponscr.exe
Size:76 KB (77,824 bytes)
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00006152%
0.028634%
Kernel CPU:0.00004614%
0.013761%
User CPU:0.00001538%
0.014873%
Kernel CPU time:94 ms/min
100,923,805ms/min
Memory
Private memory:956 KB
21.59 MB
Private (maximum):2.82 MB
Private (minimum):2.64 MB
Non-paged memory:956 KB
21.59 MB
Virtual memory:31.68 MB
140.96 MB
Virtual memory (peak):31.68 MB
169.69 MB
Working set:2.82 MB
18.61 MB
Working set (peak):2.82 MB
37.95 MB
Page faults:805/min
2,039/min
I/O
I/O other transfer:0 Bytes/sec
448.09 KB/min
I/O other operations:1/sec
1,671/min
Resource allocations
Threads:1
12
Handles:33
600
GUI GDI count:23
103
GUI USER count:6
49

BehaviorsProcess properties

Integrety level:Undefined
Platform:32-bit
Command line:"C:\Program Files\lenovo\pkgmgr\hotkey\tponscr.exe"
Owner:User
Parent process:TPHKMGR.exe

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 100.00%

Distribution by countryDistribution by country

United States installs about 50.00% of tponscr.exe.
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE