File details
File name: iexplore.exe
Name: Windows® Internet Explorer
Description: Internet Explorer
Version: 9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)
Product version: 9.00.8112.16421
Size: 730.8 KB
Original file name: IEXPLORE.EXE.MUI
Windows file protection:
Yes
Digital certificate
Certificate authority:
Microsoft Corporation
Effective date: 7/19/2010
Expiration date: 10/19/2011
Resource utilization
 | CPU utilization averages |
Total CPU: 0.2817825552%
Privileged CPU:
0.1686146563%

User CPU:
0.11316789889079%

Total CPU time: 1,238 ms
Total CPU time /min: 562 ms
Privileged CPU time: 15655628.56 ms
Privileged CPU time /min: 128 ms
User CPU time: 1132.05 ms
User CPU time /min: 531 ms
CPU cycle count:
153,451,741
CPU cycle count /min: 113,435,118
Context switches /sec:
168
 | Memory utilization averages |
Committed memory:
367.41 MB
Peak committed memory: 417.8 MB
Paged memory:
111.98 MB
Peak paged memory: 145.25 MB
Paged system memory:
414.88 KB
Non-paged system memory: 67.38 KB
Working set memory:
106.39 MB
Peak working set memory: 143.85 MB
Min working set memory: 56.46 MB
Private memory:
111.98 MB
Page faults:
1,237,020
Page faults /min: 7,317
 | Process I/O averages |
Total read operations:
80,692
Read operations /min: 268
Total read transfer: 50.94 MB
Read transfer /min: 620.67 KB
Total write operations:
20,365
Write operations /min: 164
Total write transfer: 38.99 MB
Write transfer /min: 546.78 KB
Total other operations:
228,108
Other operations /min: 2,283
Total other transfer: 12.07 MB
Other Transfer /min: 123.78 KB
 | GUI Object Averages |
GDI objects:
195
Peak GDI objects: 235
USER objects:
90
Peak USER objects: 130
Resources
Handle count average: 772
Thread count average: 28
Thread resource averages
ntdll.dll

Total CPU: 0.616010029504%
Privileged CPU: 0.036988883631%
User CPU: 0.579021145873%
CPU Cycle count /sec: 15,934,367
Context switches /sec: 36
Module memory size: 1.66 MB
ntdll.dll

Total CPU: 0.455457192595%
Privileged CPU: 0.028750194083%
User CPU: 0.426706998513%
CPU Cycle count /sec: 9,402,101
Module memory size: 1.15 MB
Total CPU: 0.403021536791%
Privileged CPU: 0.043404971318%
User CPU: 0.359616565472%
CPU Cycle count /sec: 9,973,137
Module memory size: 9.27 MB
Total CPU: 0.162547583050%
Privileged CPU: 0.036392917011%
User CPU: 0.126154666039%
CPU Cycle count /sec: 5,188,462
Context switches /sec: 6
Module memory size: 736 KB
rpcrt4.dll

Total CPU: 0.045851351623%
Privileged CPU: 0.000000000000%
User CPU: 0.045851351623%
CPU Cycle count /sec: 2,530,207
Module memory size: 780 KB
wow64.dll

Total CPU: 0.035005905596%
Privileged CPU: 0.011251160849%
User CPU: 0.023754744747%
CPU Cycle count /sec: 731,890
Context switches /sec: 8
Module memory size: 252 KB
iertutil.dll

Total CPU: 0.005918608717%
Privileged CPU: 0.003919720202%
User CPU: 0.001998888515%
CPU Cycle count /sec: 118,238
Module memory size: 1.71 MB
ntdll.dll

Total CPU: 0.004298608242%
Privileged CPU: 0.003093212249%
User CPU: 0.001205395993%
CPU Cycle count /sec: 294,173
Module memory size: 1.66 MB
msvcrt.dll

Total CPU: 0.001871806076%
Privileged CPU: 0.000000000000%
User CPU: 0.001871806076%
CPU Cycle count /sec: 2,973
Module memory size: 680 KB
ntdll.dll

Total CPU: 0.001537838411%
Privileged CPU: 0.000896514599%
User CPU: 0.000641323812%
CPU Cycle count /sec: 35,489
Module memory size: 1.23 MB
wow64.dll

Total CPU: 0.001315247288%
Privileged CPU: 0.000628965682%
User CPU: 0.000686281607%
CPU Cycle count /sec: 31,367
Module memory size: 252 KB
Total CPU: 0.000861619795%
Privileged CPU: 0.000264486953%
User CPU: 0.000597132842%
CPU Cycle count /sec: 20,659
Module memory size: 252 KB
ole32.dll

Total CPU: 0.000112888888%
Privileged CPU: 0.000056444444%
User CPU: 0.000056444444%
CPU Cycle count /sec: 4,107
Module memory size: 1.36 MB
wininet.dll

Total CPU: 0.000073323534%
Privileged CPU: 0.000000000000%
User CPU: 0.000073323534%
CPU Cycle count /sec: 23,488
Module memory size: 1.1 MB
Total CPU: 0.000056320672%
Privileged CPU: 0.000056320672%
User CPU: 0.000000000000%
CPU Cycle count /sec: 994
Module memory size: 688 KB
Process details
Runs as (owner): User
Integrety level: Low
Windows platform: 64-bit
Parent Processes
Child Process
Process Commands
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEC:6636 CREDAC:203246
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEC:6636 CREDAC:203082
"C:\Program Files\Internet Explorer\iexplore.exe"
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEC:6636 CREDAC:203009
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEC:5360 CREDAC:203009 APPIC:Microsoft.Website.90919896.2FB7905
Shell open command details
Name: gopher
Command: "C:\Program Files\Internet Explorer\iexplore.exe" -nohome
Scheduled task details
CLSID: {DC7ABF42-D45A-4D97-B5A3-E1981D317C8A}
Command: \{DC7ABF42-D45A-4D97-B5A3-E1981D317C8A}
Image hashes
MD5: 904e13ba41af2e353a32cf351ca53639
SHA-1: 78fac0d64fa0c26382e1025c4fd5d2dfd327c470
SHA-256: 172705bef76041566813a696126978bdba018c5212954c43b54706077d65987c
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File entropy: 6.58338
File packed: No
Import Table
advapi32.dll

EventWrite
GetTraceEnableFlags
RegQueryValueExW
EventUnregister
GetTraceLoggerHandle
TraceEvent
UnregisterTraceGuids
RegOpenKeyExW
EventRegister
GetTraceEnableLevel
RegCloseKey
RegisterTraceGuidsW
api-ms-win-downlevel-advapi32-l1-1-0.dll

RegGetValueW
RegOpenKeyExW
EventRegister
RegCloseKey
EventUnregister
EventWrite
RegQueryValueExW
api-ms-win-downlevel-shlwapi-l1-1-0.dll

kernel32.dll

Wow64DisableWow64FsRedirection
Wow64RevertWow64FsRedirection
TerminateProcess
CreateFileW
lstrlenW
VerifyVersionInfoW
GetLastError
GetProcAddress
LocalAlloc
IsWow64Process
HeapSetInformation
GetFileTime
DeleteCriticalSection
CloseHandle
GetWindowsDirectoryW
LocalFree
ExpandEnvironmentStringsW
LoadLibraryW
GetModuleHandleW
GetCurrentProcess
VerSetConditionMask
SetDllDirectoryW
CreateProcessW
SetErrorMode
GetCommandLineW
RaiseException
LoadLibraryA
GetSystemDefaultLCID
GetUserDefaultLCID
EnterCriticalSection
GetModuleFileNameW
LeaveCriticalSection
InitializeCriticalSectionAndSpinCount
GetVersionExA
FreeLibrary
UnhandledExceptionFilter
GetSystemTimeAsFileTime
GetCurrentProcessId
GetCurrentThreadId
GetTickCount
QueryPerformanceCounter
GetModuleHandleA
SetUnhandledExceptionFilter
GetStartupInfoW
InterlockedCompareExchange
Sleep
InterlockedExchange
GetCurrentDirectoryW
InitializeCriticalSection
GetVersionExW
SetLastError
SearchPathW
GetUserDefaultUILanguage
GetSystemDefaultUILanguage
UnmapViewOfFile
GetLocaleInfoW
CreateFileMappingW
MapViewOfFile
LoadLibraryExW
LoadResource
FindResourceExW
ReleaseMutex
LoadLibraryExA
SetProcessDEPPolicy
VirtualAlloc
GetNativeSystemInfo
msvcrt.dll
ntdll.dll

ole32.dll

CoUninitialize
CoInitialize
shell32.dll

shlwapi.dll

SHGetValueW
SHRegGetValueW
SHSetValueW
UrlApplySchemeW
PathIsURLW
UrlCanonicalizeW
PathFindFileNameW
UrlCreateFromPathW
StrStrW
PathCombineW
PathRemoveFileSpecW
PathAppendW
PathQuoteSpacesW
SHEnumValueW
user32.dll

IsWindowEnabled
LoadStringW
CharNextW
GetWindowThreadProcessId
SendMessageTimeoutW
FindWindowExW
MessageBoxW
IsWindowVisible
AllowSetForegroundWindow