File details
File name: winmail.exe
Name: Windows Mail
Description: Microsoft® Windows® Operating System
Version: 6.0.6000.16386 (vista_rtm.061101-2205)
Product version: 6.0.6000.16386
Size: 388 KB
Original file name: WinMail.exe.mui
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.1351873860%
Privileged CPU:
0.1021088939%

User CPU:
0.03307849212148%

Total CPU time: 127 ms
Total CPU time /min: 0 ms
Privileged CPU time: 50768.53 ms
Privileged CPU time /min: 16 ms
User CPU time: 30.04 ms
User CPU time /min: 0 ms
CPU cycle count:
1,131,120,706
CPU cycle count /min: 258,094,914
Context switches /sec:
42
 | Memory utilization averages |
Committed memory:
247.53 MB
Peak committed memory: 280.57 MB
Paged memory:
47.43 MB
Peak paged memory: 78.49 MB
Paged system memory:
338.79 KB
Non-paged system memory: 24.14 KB
Working set memory:
48.39 MB
Peak working set memory: 81.47 MB
Min working set memory: 20.47 MB
Private memory:
47.43 MB
Page faults:
1,493,385
Page faults /min: 644
 | Process I/O averages |
Total read operations:
9,452
Read operations /min: 5
Total read transfer: 204.24 MB
Read transfer /min: 90.62 KB
Total write operations:
5,797
Write operations /min: 4
Total write transfer: 205.96 MB
Write transfer /min: 87.91 KB
Total other operations:
377,152
Other operations /min: 192
Total other transfer: 17.5 MB
Other Transfer /min: 8.4 KB
 | GUI Object Averages |
GDI objects:
392
USER objects:
231
Resources
Handle count average: 701
Thread count average: 17
Thread resource averages
Total CPU: 0.135897602536%
Privileged CPU: 0.104924498597%
User CPU: 0.030973103939%
CPU Cycle count /sec: 3,291,369
Context switches /sec: 2
Module memory size: 400 KB
msoe.dll

Total CPU: 0.011116005658%
Privileged CPU: 0.003060649365%
User CPU: 0.008055356293%
CPU Cycle count /sec: 546,831
Module memory size: 1.58 MB
shlwapi.dll

Total CPU: 0.009130068919%
Privileged CPU: 0.003391414268%
User CPU: 0.005738654651%
CPU Cycle count /sec: 210,700
Module memory size: 356 KB
shlwapi.dll

Total CPU: 0.000944518007%
Privileged CPU: 0.000461276261%
User CPU: 0.000483241746%
CPU Cycle count /sec: 23,687
Module memory size: 356 KB
ntdll.dll

Total CPU: 0.000682448301%
Privileged CPU: 0.000534341124%
User CPU: 0.000148107176%
CPU Cycle count /sec: 111,207
Module memory size: 1.16 MB
esent.dll

Total CPU: 0.000679311975%
Privileged CPU: 0.000647317971%
User CPU: 0.000031994003%
CPU Cycle count /sec: 16,464
Module memory size: 1.41 MB
ntdll.dll

Total CPU: 0.000541720430%
Privileged CPU: 0.000478436681%
User CPU: 0.000063283749%
CPU Cycle count /sec: 34,042
Module memory size: 1.16 MB
Total CPU: 0.000271495620%
Privileged CPU: 0.000214063854%
User CPU: 0.000057431766%
CPU Cycle count /sec: 51,136
Module memory size: 11.79 MB
mswsock.dll

Total CPU: 0.000184510022%
Privileged CPU: 0.000144972160%
User CPU: 0.000039537862%
CPU Cycle count /sec: 10,995
Module memory size: 236 KB
Total CPU: 0.000066108523%
Privileged CPU: 0.000044072349%
User CPU: 0.000022036174%
CPU Cycle count /sec: 9,939
Module memory size: 11.79 MB
winmm.dll

Total CPU: 0.000063287345%
Privileged CPU: 0.000063287345%
User CPU: 0.000000000000%
CPU Cycle count /sec: 592
Module memory size: 200 KB
wdmaud.drv

Total CPU: 0.000061317909%
Privileged CPU: 0.000056901899%
User CPU: 0.000004416010%
CPU Cycle count /sec: 1,224
Module memory size: 188 KB
wininet.dll

Total CPU: 0.000046961142%
Privileged CPU: 0.000026089523%
User CPU: 0.000020871619%
CPU Cycle count /sec: 4,852
Module memory size: 1.11 MB
wininet.dll

Total CPU: 0.000039538206%
Privileged CPU: 0.000013179402%
User CPU: 0.000026358804%
CPU Cycle count /sec: 20,163
Module memory size: 1.11 MB
Total CPU: 0.000005220087%
Privileged CPU: 0.000000000000%
User CPU: 0.000005220087%
CPU Cycle count /sec: 204
Module memory size: 680 KB
Process details
Runs as (owner): User
Integrety level: Medium
Windows platform: 32-bit
System Tray: Yes
Parent Processes
Child Process
Process Commands
"C:\Program Files\Windows Mail\WinMail.exe"
"C:\Program Files\Windows Mail\WinMail.exe" /mailurC:"mailtC:?subject=A friend suggested this page on Film Annex&body=Hello,%0Aa friend of yours suggests you take a look at this content on Film AnneC:%0A%0AhttC://www.filmannex.com/%0A%0A-----------------------------------------------------------%0AFilm Annex Privacy StatemenC:%0AhttC://www.filmannex.com/FilmAnnex%0A%0ASuggestions and feedback are welcome at
[email protected]%0A%0AFilm Annex - New York, NY 10011, USA%0A20 West 20th Street, suite
Shell open command details
Name: snews
Command: "C:\Program Files\Windows Mail\WinMail.exe" /newsurC:"%1"
Network connectivity
UDP: LISTENING on port 53326
UDP: LISTENING on port 59345
UDP: LISTENING on port 59794
Image hashes
MD5: 7e6ea9cb72b5de84a5d700bed877e5f9
SHA-1: 85b6aa429350333343db149eb2198e7fc38c3e4f
SHA-256: 8261b7c2a776f59baefabeeaf8e9425cb0f4d3700ef63caa7095398368ed3c6e
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File entropy: 6.76986
File packed: No
Import Table
advapi32.dll

TraceEvent
GetTraceEnableFlags
GetTraceEnableLevel
GetTraceLoggerHandle
RegisterTraceGuidsA
UnregisterTraceGuids
RegCloseKey
RegSetValueW
RegOpenKeyExW
RegCreateKeyExW
RegSetValueExW
RegQueryValueExW
RegDeleteKeyW
kernel32.dll

FreeLibrary
LoadLibraryA
lstrlenW
GetFileAttributesW
GetFileAttributesA
GetLastError
ReleaseMutex
CloseHandle
WaitForSingleObject
CreateMutexW
GetCurrentProcess
GetModuleHandleA
ExpandEnvironmentStringsW
GetExitCodeProcess
CreateProcessW
GetModuleHandleW
HeapSetInformation
GetVersionExA
SetFileAttributesW
DeleteFileW
FindFirstFileExW
FindClose
FindNextFileW
FindFirstFileW
SetCurrentDirectoryW
GetCurrentDirectoryW
GetShortPathNameW
CreateDirectoryW
InterlockedCompareExchange
GetTickCount
QueryPerformanceCounter
SetUnhandledExceptionFilter
GetStartupInfoW
Sleep
InterlockedExchange
GetCurrentProcessId
GetSystemTimeAsFileTime
TerminateProcess
UnhandledExceptionFilter
GetProcAddress
SetConsoleCtrlHandler
GetCurrentThreadId
msoert2.dll

msvcrt.dll
ole32.dll

CoUninitialize
CoFreeAllLibraries
CoTaskMemFree
CoInitializeEx
CoCreateInstance
OleInitialize
CoFreeUnusedLibraries
CoFreeUnusedLibrariesEx
OleUninitialize
shell32.dll

SHCreateItemFromParsingName
SHGetSpecialFolderPathW
SHSetLocalizedName
SHGetSpecialFolderLocation
SHChangeNotify
shlwapi.dll

PathFindFileNameW
PathCombineW
SHRegGetPathW
SHRegGetValueA
StrStrIW
SHDeleteValueW
SHRegGetBoolUSValueA
PathRemoveBlanksW
PathRemoveFileSpecW
PathAddExtensionW
PathAppendW
StrCmpW
StrCmpNIW
SHDeleteKeyW
SHSetValueW
SHRegGetValueW
StrCmpIW
SHGetValueW
user32.dll

SetWindowsHookExA
GetGUIThreadInfo
IsChild
UnhookWindowsHookEx
GetLastActivePopup
GetPropW
GetParent
CallNextHookEx
SendMessageW
IsDialogMessageW
SetPropW
FindWindowW
GetWindowThreadProcessId
AllowSetForegroundWindow
SetForegroundWindow
SendMessageTimeoutA
MessageBoxW
LoadStringW