File details
File name: powerpnt.exe
Name: Microsoft Office 2003
Description: Microsoft Office PowerPoint
Version: 11.0.6564
Size: 5.86 MB
Original file name: POWERPNT.EXE
Digital certificate
Certificate authority:
Microsoft Corporation
Effective date: 1/5/2005
Expiration date: 4/5/2006
Resource utilization
 | CPU utilization averages |
Total CPU: 0.5787785084%
Privileged CPU:
0.2232694990%

User CPU:
0.35550900943479%

Privileged CPU time: 10895.67 ms
Privileged CPU time /min: 3,947 ms
Context switches /sec:
267
 | Memory utilization averages |
Committed memory:
188.14 MB
Peak committed memory: 189.99 MB
Paged memory:
105.18 MB
Peak paged memory: 107.31 MB
Paged system memory:
79.06 KB
Non-paged system memory: 12.7 KB
Working set memory:
113.16 MB
Peak working set memory: 115.27 MB
Min working set memory: 49.21 MB
Private memory:
105.18 MB
Page faults:
88,916
Page faults /min: 32,209
 | Process I/O averages |
Total read operations:
3,108
Read operations /min: 1,126
Total read transfer: 11.9 MB
Read transfer /min: 4.31 MB
Total write operations:
12
Write operations /min: 4
Total write transfer: 5.46 KB
Write transfer /min: 1.98 KB
Total other operations:
17,280
Other operations /min: 6,260
Total other transfer: 462.69 KB
Other Transfer /min: 167.6 KB
 | GUI Object Averages |
GDI objects:
159
USER objects:
59
Resources
Handle count average: 251
Thread count average: 9
Thread resource averages
Total CPU: 8.859902864786%
Privileged CPU: 2.968491445609%
User CPU: 5.891411419177%
Context switches /sec: 133
Module memory size: 5.88 MB
winmm.dll

Total CPU: 0.394795373665%
Privileged CPU: 0.022241992883%
User CPU: 0.372553380783%
Module memory size: 180 KB
Process details
Runs as (owner): User
Integrety level: Undefined
Windows platform: 32-bit
Parent Process
Child Process
Process Command
"C:\Program Files\Microsoft Office|office11|powerpnt.exe" /s "C:\DOCUME~1\user\LocalS~1\Temp\Terra9_-_202234_.pps"
Image hashes
MD5: 158e662ffc0bf340d4d4354f1d3bb4d0
SHA-1: df5050a1c6bb10b51affb678b0dbb5642fa38155
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File packed: No
Import Table
advapi32.dll

RegOpenKeyExW
RegCloseKey
RegSetValueExW
RegCreateKeyExW
RegQueryValueExW
RegDeleteValueW
RegEnumKeyExW
RegEnumValueW
RegDeleteKeyW
GetUserNameW
RegSetValueExA
RegOpenKeyExA
RegQueryValueExA
RegOpenKeyA
gdi32.dll

GetViewportOrgEx
GetTextAlign
SelectObject
Ellipse
RoundRect
SetPixel
Escape
SetRectRgn
PlayMetaFileRecord
PlayEnhMetaFileRecord
CreatePatternBrush
CreateBitmap
OffsetWindowOrgEx
ExtCreatePen
CreatePen
SetROP2
ExtSelectClipRgn
RestoreDC
SaveDC
Polyline
GetPixel
OffsetViewportOrgEx
ResetDCW
EndPage
StartPage
SetAbortProc
StartDocW
AbortDoc
EndDoc
CreateICW
GetNearestColor
FillRgn
CreateCompatibleDC
CreateDIBSection
AnimatePalette
Pie
CreateCompatibleBitmap
CreateDIBPatternBrushPt
CreateBrushIndirect
BitBlt
DPtoLP
GetCurrentObject
LPtoDP
Rectangle
SetMetaFileBitsEx
GetEnhMetaFileW
GetEnhMetaFileHeader
GetWinMetaFileBits
EnumEnhMetaFile
EnumMetaFile
SetDIBits
GetBitmapBits
GetEnhMetaFileBits
StretchDIBits
GetMetaFileBitsEx
GetObjectType
DeleteMetaFile
DeleteEnhMetaFile
GetOutlineTextMetricsW
ExtEscape
GetTextCharsetInfo
GetFontData
EnumFontFamiliesExW
ExcludeClipRect
IntersectClipRect
GetTextFaceW
SetTextAlign
CreateDIBitmap
SetStretchBltMode
StretchBlt
CreateSolidBrush
GetClipBox
GetTextMetricsW
CreateFontIndirectW
GdiFlush
SetDIBColorTable
GetObjectA
SetLayout
Polygon
SetBkMode
SetTextColor
MoveToEx
LineTo
CreateDCW
SetMapMode
SetWindowOrgEx
DeleteDC
GetRasterizerCaps
CreatePalette
GetSystemPaletteUse
GetDeviceCaps
GetSystemPaletteEntries
GetPaletteEntries
UpdateColors
GetRgnBox
SelectPalette
RealizePalette
PatBlt
GetBkColor
GetTextColor
SelectClipRgn
RectVisible
CreateRectRgn
OffsetRgn
CreateRectRgnIndirect
CombineRgn
DeleteObject
SetBkColor
ExtTextOutW
SetViewportOrgEx
GetStockObject
GetObjectW
GetClipRgn
kernel32.dll

GetCurrentThread
SetThreadPriority
WaitForMultipleObjects
ResumeThread
CreateThread
SystemTimeToFileTime
GetSystemTime
IsDBCSLeadByte
Sleep
QueryDosDeviceW
GetLogicalDrives
RemoveDirectoryW
SetFileAttributesW
GetSystemDefaultLCID
CompareFileTime
GetUserDefaultLCID
MoveFileExW
GetDriveTypeW
FormatMessageW
GetLocaleInfoW
GetThreadLocale
GetDateFormatW
GetTimeFormatW
GetComputerNameW
FileTimeToSystemTime
GetTimeZoneInformation
FileTimeToLocalFileTime
IsValidCodePage
IsDBCSLeadByteEx
QueryPerformanceFrequency
QueryPerformanceCounter
OutputDebugStringW
SearchPathW
UnmapViewOfFile
MapViewOfFile
CreateFileMappingA
SetThreadExecutionState
GetShortPathNameW
GetFileSize
FindNextFileW
CompareStringW
TlsGetValue
TlsSetValue
VirtualProtect
GetCurrentProcessId
GetSystemTimeAsFileTime
GetStartupInfoA
ResetEvent
GetACP
GetStringTypeExW
SizeofResource
GetSystemDirectoryW
lstrcmpiA
MultiByteToWideChar
LoadLibraryA
FreeLibrary
GetSystemDefaultLangID
GetFullPathNameW
GetLongPathNameW
WriteFile
CreateDirectoryW
FindFirstFileW
FindClose
CreateFileW
SetFileTime
ReadFile
SetFilePointer
GetDiskFreeSpaceW
VirtualAlloc
TerminateProcess
UnhandledExceptionFilter
FindResourceW
LoadResource
LockResource
CopyFileW
GetTempPathW
GetTempFileNameW
InterlockedDecrement
LeaveCriticalSection
EnterCriticalSection
DeleteCriticalSection
InitializeCriticalSection
InterlockedIncrement
GetLocalTime
MulDiv
CreateProcessW
GetCurrentProcess
SetProcessWorkingSetSize
WaitForSingleObject
SetErrorMode
GetTickCount
CloseHandle
SetEvent
GetCurrentThreadId
GlobalGetAtomNameW
GlobalDeleteAtom
SetCurrentDirectoryW
SetUnhandledExceptionFilter
GetCurrentDirectoryW
GlobalAddAtomW
OutputDebugStringA
GetModuleFileNameW
SetLastError
GetLastError
LoadLibraryW
DeleteFileW
GetStartupInfoW
GetVersion
GetFileAttributesW
GetProcAddress
GetModuleHandleW
GetModuleHandleA
GetCommandLineW
ExitProcess
GlobalSize
GlobalUnlock
GlobalLock
GlobalFree
GlobalAlloc
GlobalMemoryStatus
InterlockedExchange
LocalAlloc
FormatMessageA
LoadLibraryExW
OpenFile
LoadLibraryExA
LocalFree
CreateEventW
RaiseException
msvcrt.dll
ole32.dll

CoIsOle1Class
StringFromCLSID
OleDuplicateData
SetConvertStg
WriteFmtUserTypeStg
WriteClassStg
ReadFmtUserTypeStg
ReadClassStg
CoTreatAsClass
OleMetafilePictFromIconAndLabel
OleGetIconOfClass
OleGetIconOfFile
GetClassFile
CoGetMalloc
OleQueryLinkFromData
OleIsCurrentClipboard
OleSetClipboard
OleGetClipboard
CreateGenericComposite
CreateItemMoniker
OleFlushClipboard
OleRegGetUserType
OleQueryCreateFromData
StgCreateDocfile
CoInitialize
CoUninitialize
GetRunningObjectTable
FreePropVariantArray
CreateFileMoniker
MkParseDisplayName
CreateBindCtx
CreateClassMoniker
OleIsRunning
OleLoad
OleRun
OleCreate
OleCreateLinkFromData
OleCreateFromData
OleCreateLink
OleCreateLinkToFile
OleCreateFromFile
CoGetClassObject
OleRegEnumVerbs
CoRegisterMessageFilter
StgOpenStorage
StgCreateStorageEx
StgIsStorageFile
StgCreateDocfileOnILockBytes
StgOpenStorageOnILockBytes
CreateILockBytesOnHGlobal
GetHGlobalFromStream
GetHGlobalFromILockBytes
StringFromGUID2
OleLockRunning
OleSetMenuDescriptor
CoFileTimeNow
DoDragDrop
CoRegisterClassObject
CoRevokeClassObject
OleCreateEmbeddingHelper
OleRegEnumFormatEtc
CreateDataAdviseHolder
CreateOleAdviseHolder
OleRegGetMiscStatus
OleTranslateAccelerator
OleCreateMenuDescriptor
OleDestroyMenuDescriptor
CoCreateInstanceEx
CLSIDFromProgID
CLSIDFromString
CoTaskMemFree
ReleaseStgMedium
CreateStreamOnHGlobal
OleSaveToStream
WriteClassStm
CoFreeUnusedLibraries
OleUninitialize
OleInitialize
CoDisconnectObject
CoCreateInstance
RegisterDragDrop
RevokeDragDrop
CoLockObjectExternal
ProgIDFromCLSID
user32.dll