File details
File name: explorer.exe
Version: 0.0.0.0
Size: 248 KB
Original file name: clean avira.exe
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0016025260%
Privileged CPU:
0.0011048252%

User CPU:
0.00049770081763%

Privileged CPU time: 27939.78 ms
Privileged CPU time /min: 39 ms
CPU cycle count:
401,264,640
CPU cycle count /min: 867,670,951
Context switches /sec:
426
 | Memory utilization averages |
Committed memory:
174.28 MB
Peak committed memory: 176.22 MB
Paged memory:
19.27 MB
Peak paged memory: 21.99 MB
Paged system memory:
260.84 KB
Non-paged system memory: 36.21 KB
Working set memory:
1.04 MB
Peak working set memory: 16.45 MB
Min working set memory: 560 KB
Private memory:
19.27 MB
Page faults:
1,285,051
Page faults /min: 1,802
 | Process I/O averages |
Total read operations:
3,103
Read operations /min: 4
Total read transfer: 371.63 MB
Read transfer /min: 533.6 KB
Total write operations:
33,712
Write operations /min: 47
Total write transfer: 461.58 MB
Write transfer /min: 662.76 KB
Total other operations:
99,647
Other operations /min: 140
Total other transfer: 539.45 KB
Other Transfer /min: 775 Bytes
 | GUI Object Averages |
GDI objects:
9
Peak GDI objects: 9
USER objects:
5
Peak USER objects: 6
Resources
Handle count average: 303
Thread count average: 13
Thread resource averages
Total CPU: 0.044100603134%
Privileged CPU: 0.021890902415%
User CPU: 0.022209700718%
CPU Cycle count /sec: 19,149,968
Context switches /sec: 70
Module memory size: 272 KB
ntdll.dll

Total CPU: 0.000073410249%
Privileged CPU: 0.000073410249%
User CPU: 0.000000000000%
CPU Cycle count /sec: 2,970
Module memory size: 1.66 MB
Process details
Runs as (owner): User
Integrety level: Medium
Windows platform: 64-bit
Process Command
"C:\users\user\appdata\Roaming\explorer.exe" ..
User start menu folder details
Name: 93f19dda2412c86ad7520ba4198f39a0.exe
Image hashes
MD5: 3e16895e2b2c7847590d8f53b54430ed
SHA-1: d4284c19d8bcbbb8d55906d02d0ae60fa6fd2293
SHA-256: 7edd8c818364c38716194c442614bca2eeba7e24fcca28e9380d1ff0dca94a78
PE image details
CLR assembly: Yes
CLR NGENed: No
Langauge*: Microsoft Visual C# / Basic .NET
File packed: No