File details
File name: YahooMessenger.exe
Name: Yahoo! Messenger
Description: Yahoo! Messenger
Version: 11,5,0,0228
Size: 6.29 MB
Digital certificate
Certificate authority:
VeriSign
Effective date: 8/12/2009
Expiration date: 9/2/2012
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0092818036%
Privileged CPU:
0.0053992612%

User CPU:
0.00388254241758%

Privileged CPU time: 4387766.89 ms
Privileged CPU time /min: 42 ms
CPU cycle count:
300,558,733
CPU cycle count /min: 56,194,805
Context switches /sec:
330
 | Memory utilization averages |
Committed memory:
254.61 MB
Peak committed memory: 276.41 MB
Paged memory:
67.55 MB
Peak paged memory: 78.78 MB
Paged system memory:
351.83 KB
Non-paged system memory: 84.97 KB
Working set memory:
40.52 MB
Peak working set memory: 66.51 MB
Min working set memory: 20.24 MB
Private memory:
67.55 MB
Page faults:
561,012
Page faults /min: 465
 | Process I/O averages |
Total read operations:
89,354
Read operations /min: 271
Total read transfer: 11.77 MB
Read transfer /min: 31.56 KB
Total write operations:
22,432
Write operations /min: 11
Total write transfer: 3.67 MB
Write transfer /min: 4.58 KB
Total other operations:
240,767
Other operations /min: 509
Total other transfer: 11.64 MB
Other Transfer /min: 29.25 KB
 | GUI Object Averages |
GDI objects:
765
Peak GDI objects: 605
USER objects:
242
Peak USER objects: 266
Resources
Handle count average: 864
Thread count average: 25
Thread resource averages
msvcr80.dll

Total CPU: 0.146863470033%
Privileged CPU: 0.045139890889%
User CPU: 0.101723579145%
CPU Cycle count /sec: 4,713,828
Context switches /sec: 7
Module memory size: 620 KB
Total CPU: 0.099492748607%
Privileged CPU: 0.033947701381%
User CPU: 0.065545047227%
CPU Cycle count /sec: 6,307,797
Context switches /sec: 22
Module memory size: 6.4 MB
Total CPU: 0.091880903668%
Privileged CPU: 0.055342462315%
User CPU: 0.036538441352%
CPU Cycle count /sec: 3,433,500
Context switches /sec: 34
Module memory size: 13.69 MB
Total CPU: 0.078027660216%
Privileged CPU: 0.000822643887%
User CPU: 0.077205016329%
CPU Cycle count /sec: 1,377,841
Module memory size: 680 KB
Total CPU: 0.058671142776%
Privileged CPU: 0.040994516468%
User CPU: 0.017676626308%
CPU Cycle count /sec: 4,718,630
Module memory size: 11.77 MB
msvcr80.dll

Total CPU: 0.046929034321%
Privileged CPU: 0.011228697145%
User CPU: 0.035700337176%
CPU Cycle count /sec: 257,618
Context switches /sec: 16
Module memory size: 620 KB
ntdll.dll

Total CPU: 0.037022748135%
Privileged CPU: 0.023369916284%
User CPU: 0.013652831851%
CPU Cycle count /sec: 1,243,098
Context switches /sec: 1
Module memory size: 1.4 MB
ntdll.dll

Total CPU: 0.029093002614%
Privileged CPU: 0.001250164135%
User CPU: 0.027842838478%
CPU Cycle count /sec: 1,986,571
Context switches /sec: 1
Module memory size: 1.66 MB
Total CPU: 0.028028162185%
Privileged CPU: 0.000101058170%
User CPU: 0.027927104015%
CPU Cycle count /sec: 3,099,644
Context switches /sec: 50
Module memory size: 11.72 MB
ntdll.dll

Total CPU: 0.023362889616%
Privileged CPU: 0.017852774140%
User CPU: 0.005510115475%
Context switches /sec: 1
Module memory size: 712 KB
msvcrt.dll

Total CPU: 0.022027026276%
Privileged CPU: 0.000086392505%
User CPU: 0.021940633772%
CPU Cycle count /sec: 651,094
Module memory size: 688 KB
ntdll.dll

Total CPU: 0.016691691704%
Privileged CPU: 0.011348790209%
User CPU: 0.005342901495%
CPU Cycle count /sec: 554,469
Context switches /sec: 1
Module memory size: 1.23 MB
msvcrt.dll

Total CPU: 0.014674222617%
Privileged CPU: 0.000884879852%
User CPU: 0.013789342764%
CPU Cycle count /sec: 484,402
Module memory size: 708 KB
Total CPU: 0.013589619131%
Privileged CPU: 0.006011025280%
User CPU: 0.007578593851%
Context switches /sec: 149
Module memory size: 15.88 MB
Total CPU: 0.012707580112%
Privileged CPU: 0.005667213883%
User CPU: 0.007040366229%
CPU Cycle count /sec: 1,006,123
Module memory size: 11.77 MB
Total CPU: 0.012292185292%
Privileged CPU: 0.007822299731%
User CPU: 0.004469885561%
CPU Cycle count /sec: 4,642,153
Module memory size: 11.77 MB
Total CPU: 0.011587184900%
Privileged CPU: 0.004794509081%
User CPU: 0.006792675819%
CPU Cycle count /sec: 1,079,960
Context switches /sec: 49
Module memory size: 13.69 MB
ntdll.dll

Total CPU: 0.011393583602%
Privileged CPU: 0.007655063983%
User CPU: 0.003738519619%
CPU Cycle count /sec: 204,321
Module memory size: 1.52 MB
Total CPU: 0.008972797081%
Privileged CPU: 0.007050054849%
User CPU: 0.001922742232%
CPU Cycle count /sec: 2,884,220
Module memory size: 11.77 MB
wow64cpu.dll

Total CPU: 0.008687849750%
Privileged CPU: 0.005287353600%
User CPU: 0.003400496149%
CPU Cycle count /sec: 315,989
Module memory size: 32 KB
Process details
Runs as (owner): User
Integrety level: High
Windows platform: 32-bit
System Tray: Yes
Parent Processes
Child Processes
Process Commands
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" /CookieProxy
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"
"C:\Program Files1\Yahoo!\Messenger\YahooMessenger.exe" -quiet
C:\Program Files1\Yahoo!\Messenger\YahooMessenger.exe /CookieProxy
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"
Startup files (user) run details
Name: Yahoo! Pager
Command: "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
Scheduled task details
CLSID: {FF8FDDAA-FA1C-4738-BB7B-E5395E714A5C}
Command: \{FF8FDDAA-FA1C-4738-BB7B-E5395E714A5C}
Network connectivity
TCP: sip120-p1.voice.ne1.yahoo.com on port 62306
TCP: sip120-p1.voice.ne1.yahoo.com on port 53790
TCP: sip120p1.us1.voice.gq1.yahoo.com on port 64885
TCP: sip119-p2.voice.ne1.yahoo.com on port 1062
TCP: sip118-p1.voice.ne1.yahoo.com on port 1061
TCP: sip116-p2.voice.ne1.yahoo.com on port 1322
TCP: sip116-p1.voice.ne1.yahoo.com on port 51899
TCP: sip116.voice.ne1.yahoo.com on port 2099
TCP: sip115.voice.ne1.yahoo.com on port 49468
TCP: sip114-p2.voice.ne1.yahoo.com on port 57506
TCP: sip114-p1.voice.ne1.yahoo.com on port 1063
TCP: sip113.voice.ne1.yahoo.com on port 2580
Windows Firewall allowed program: Yes
Image hashes
MD5: 127cd00925c1a2b759765c5b9600de30
SHA-1: 437329a7a24ef7adbb25dbb5d20755e528923773
SHA-256: 22a9710b84873622eb1027552f3e7cc3e054ff367010149822f476a143556335
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++ 8.0
File entropy: 6.47214
File packed: No
Import Table
advapi32.dll

RegEnumKeyExW
RegCloseKey
RegQueryValueExW
RegOpenKeyExW
RegSetValueExW
RegCreateKeyExW
ReportEventA
DeregisterEventSource
RegQueryInfoKeyW
RegEnumValueW
RegDeleteKeyW
RegDeleteValueW
RegEnumKeyW
RegisterEventSourceA
SetSecurityDescriptorDacl
InitializeSecurityDescriptor
comctl32.dll

ImageList_GetIconSize
ImageList_Draw
CreateToolbarEx
ImageList_AddMasked
CreateStatusWindowW
ImageList_BeginDrag
ImageList_EndDrag
ImageList_DragMove
ImageList_DragEnter
_TrackMouseEvent
ImageList_GetImageCount
InitCommonControlsEx
ImageList_Create
ImageList_Add
ImageList_Destroy
ImageList_ReplaceIcon
ImageList_DragLeave
comdlg32.dll

GetSaveFileNameW
PrintDlgW
ChooseColorW
GetOpenFileNameW
ChooseFontW
connectionwizard.dll

cwCleanup
cwTestStop
cwVipTestStart
cwLoginServerTestStart
cwStopLogging
cwStartLogging
cwInitialize
cwCsTestStart
crypt32.dll

CertCloseStore
CertFreeCertificateContext
CertGetNameStringW
CertGetEnhancedKeyUsage
CertFindCertificateInStore
CryptMsgGetParam
CryptMsgClose
CryptQueryObject
CryptUnprotectData
CryptProtectData
gdi32.dll

SaveDC
RestoreDC
CreateBitmap
PatBlt
SetBkColor
MoveToEx
LineTo
CreatePen
SetTextColor
GetStockObject
GetObjectW
CreateSolidBrush
BitBlt
CreateCompatibleDC
CreateCompatibleBitmap
SelectObject
DeleteDC
GetDeviceCaps
DeleteObject
FrameRgn
CreatePolygonRgn
CreateRoundRectRgn
EnumFontFamiliesExW
SelectClipRgn
RoundRect
SetROP2
LPtoDP
GetTextExtentPoint32W
GetTextFaceW
GetTextMetricsW
CreateFontIndirectW
SetBkMode
ExtTextOutW
TextOutW
GetBkColor
GetBkMode
Rectangle
FillRgn
CombineRgn
CreateRectRgn
CreatePatternBrush
StretchBlt
CreateFontW
EndDoc
EndPage
StartPage
StartDocW
GetTextExtentPointW
SetStretchBltMode
CreateDIBSection
CreateDCW
GetPixel
GetTextExtentExPointW
gdiplus.dll

GdiplusShutdown
GdiplusStartup
imm32.dll

ImmReleaseContext
ImmGetContext
ImmAssociateContext
ImmGetCompositionStringW
iphlpapi.dll

kernel32.dll

GetLocaleInfoA
VirtualAlloc
GetThreadLocale
IsProcessorFeaturePresent
GetProcessHeap
GetStartupInfoW
UnhandledExceptionFilter
SetUnhandledExceptionFilter
VirtualFree
LoadLibraryExW
IsDebuggerPresent
QueryPerformanceCounter
FlushConsoleInputBuffer
GetStdHandle
GetFileType
GetVersion
InitializeCriticalSectionAndSpinCount
HeapSize
HeapReAlloc
HeapFree
HeapAlloc
HeapDestroy
HeapCreate
WritePrivateProfileStringA
Beep
CreateMutexW
ReleaseMutex
GetCurrentProcessId
WritePrivateProfileSectionW
GetSystemTimeAsFileTime
GetPrivateProfileStringA
GetSystemTime
GetCPInfoExW
GetACP
GetVersionExA
SetErrorMode
CreateProcessW
GetExitCodeProcess
TerminateProcess
lstrcpyW
GetTimeFormatW
GetDateFormatW
lstrcmpA
GetTempFileNameW
CompareFileTime
MoveFileW
RemoveDirectoryW
GetSystemDirectoryW
GetWindowsDirectoryW
GetSystemWindowsDirectoryW
GetFileAttributesExW
CreateFileA
DosDateTimeToFileTime
LocalFileTimeToFileTime
SetFileTime
LoadLibraryW
CreateSemaphoreW
InterlockedExchange
ResumeThread
OutputDebugStringW
CreateThread
WaitForMultipleObjects
ExitThread
TerminateThread
WritePrivateProfileStringW
InterlockedCompareExchange
FormatMessageW
WaitForSingleObject
InterlockedIncrement
GetLocalTime
SetEvent
ResetEvent
GlobalDeleteAtom
GlobalAddAtomW
FindFirstFileW
FindNextFileW
FindClose
CreateEventW
Sleep
GetFileTime
FileTimeToSystemTime
SizeofResource
LockResource
LoadResource
FindResourceW
FindResourceExW
lstrcmpiW
EnterCriticalSection
LeaveCriticalSection
GetLastError
SetLastError
lstrlenW
FlushInstructionCache
GetCurrentProcess
lstrcmpW
MulDiv
GetModuleFileNameW
GlobalUnlock
GlobalLock
GlobalAlloc
RaiseException
GetCurrentThreadId
MultiByteToWideChar
InterlockedDecrement
DeleteCriticalSection
lstrlenA
InitializeCriticalSection
CreateDirectoryA
GetFileAttributesA
FileTimeToDosDateTime
FileTimeToLocalFileTime
GetTempFileNameA
GetTempPathA
SetFileAttributesA
WideCharToMultiByte
GetShortPathNameW
GlobalMemoryStatus
CloseHandle
CreateFileW
lstrcpynW
GetPrivateProfileStringW
GlobalFree
GlobalHandle
WriteFile
SetFilePointer
SetEndOfFile
lstrcpynA
DeleteFileW
SetFileAttributesW
GetFileAttributesW
CreateDirectoryW
GetComputerNameW
LocalFree
LocalAlloc
CopyFileW
GetProcAddress
GetModuleHandleW
GetPrivateProfileIntW
GetTempPathW
GetVersionExW
GetSystemInfo
ReadFile
GetFileSize
GetTickCount
FreeLibrary
LoadLibraryA
DllMain
msimg32.dll

msvcp80.dll
msvcr80.dll
ole32.dll

CoTaskMemAlloc
CoCreateInstance
CreateStreamOnHGlobal
OleInitialize
OleUninitialize
CoTaskMemFree
StringFromCLSID
CoReleaseMarshalData
CoMarshalInterface
CoUnmarshalInterface
CoUninitialize
CoTaskMemRealloc
CoRevokeClassObject
CoRegisterClassObject
OleRun
DoDragDrop
ReleaseStgMedium
CoGetMalloc
RegisterDragDrop
RevokeDragDrop
CoSetProxyBlanket
CoInitializeSecurity
OleGetClipboard
CLSIDFromString
CLSIDFromProgID
CoGetClassObject
CoCreateGuid
OleLockRunning
StringFromGUID2
CoInitialize
OleCreateStaticFromData
OleDuplicateData
OleSetContainedObject
StgCreateDocfileOnILockBytes
CreateILockBytesOnHGlobal
PropVariantClear
pcre.dll

pcre_compile
pcre_exec
pcre_free
rmc_audio.dll

rmc_audio_release_pin
rmc_audio_release
rmc_audio_create
rmc_audio_pin_start
rmc_audio_register_callback
rmc_audio_create_local_play_pin
rmc_audio_stop
rmc_audio_pin_stop
rmc_audio_start
rmc_audio_create_rendering_pin
rmc_audio_unregister_callback
secur32.dll

setupapi.dll

SetupDiGetDeviceRegistryPropertyW
SetupDiEnumDeviceInfo
SetupDiGetClassDevsW
SetupDiDestroyDeviceInfoList
shell32.dll

ShellExecuteW
ShellExecuteExW
SHGetFolderPathW
SHGetFileInfoW
DragQueryFileW
DragAcceptFiles
SHFileOperationW
SHAppBarMessage
Shell_NotifyIconW
SHGetMalloc
SHBrowseForFolderW
SHGetPathFromIDListW
SHCreateDirectoryExW
shlwapi.dll

PathStripPathW
UrlCreateFromPathW
PathFileExistsW
StrCmpNW
PathRemoveExtensionW
StrToIntW
PathIsURLW
PathFindExtensionW
PathCanonicalizeW
PathAppendW
PathIsRelativeW
UrlIsW
SHDeleteKeyW
PathFindFileNameW
wnsprintfW
PathCombineW
StrCpyNW
UrlEscapeW
StrCmpNIW
StrCmpNA
StrStrIW
PathIsDirectoryW
StrCpyW
SHCreateStreamOnFileW
SHStrDupW
PathFileExistsA
PathAddBackslashW
PathRemoveFileSpecW
urlmon.dll

user32.dll
version.dll

VerQueryValueW
GetFileVersionInfoW
GetFileVersionInfoSizeW
wininet.dll

InternetSetOptionW
InternetGetCookieW
InternetCloseHandle
InternetCrackUrlW
HttpSendRequestW
HttpOpenRequestW
InternetConnectW
InternetOpenW
InternetGetConnectedStateExW
InternetSetCookieW
HttpQueryInfoW
InternetSetCookieExW
InternetGetCookieExW
HttpOpenRequestA
InternetConnectA
HttpSendRequestExA
InternetWriteFile
HttpEndRequestA
InternetSetOptionA
HttpQueryInfoA
InternetReadFileExA
InternetSetStatusCallbackA
InternetOpenA
InternetReadFile
InternetQueryOptionW
InternetGetCookieA
InternetGetCookieExA
HttpEndRequestW
InternetQueryOptionA
HttpAddRequestHeadersA
winmm.dll

wintrust.dll

ws2_32.dll

wtsapi32.dll

WTSRegisterSessionNotification
WTSUnRegisterSessionNotification
xmllite.dll

CreateXmlWriter
CreateXmlReader
ylog.dll

ylog_debug
ylog_warning
ylog_error
ymdm_audio.dll

ymdm_audio_device_release
ymdm_audio_device_get_info
ymdm_audio_device_count_devices
ymdm_audio_device_create
ymdm_audio_device_display_name
ymdm_video.dll

ymdm_video_capt_device_count
ymdm_video_capt_device_get_info
ymdm_video_capt_device_create
ymdm_video_capt_device_release