File details
File name: Explorer.EXE
Name: Windows Explorer
Description: Microsoft® Windows® Operating System
Version: 6.00.2900.5512 (xpsp.080413-2105)
Product version: 6.00.2900.5512
Size: 1009.5 KB
Original file name: EXPLORER.EXE
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0150986047%
Privileged CPU:
0.0080262708%

User CPU:
0.00707233394217%

Privileged CPU time: 2356218.94 ms
Privileged CPU time /min: 54 ms
Context switches /sec:
66
 | Memory utilization averages |
Committed memory:
135.39 MB
Peak committed memory: 210.84 MB
Paged memory:
27.7 MB
Peak paged memory: 44.55 MB
Paged system memory:
174.03 KB
Non-paged system memory: 38.7 KB
Working set memory:
21.64 MB
Peak working set memory: 45.69 MB
Min working set memory: 12.8 MB
Private memory:
27.7 MB
Page faults:
487,727
Page faults /min: 254
 | Process I/O averages |
Total read operations:
71,377
Read operations /min: 25
Total read transfer: 18.64 MB
Read transfer /min: 51.4 KB
Total write operations:
1,342
Write operations /min: 1
Total write transfer: 18.63 MB
Write transfer /min: 7.36 KB
Total other operations:
4,099,510
Other operations /min: 1,841
Total other transfer: 153.05 MB
Other Transfer /min: 160.25 KB
 | GUI Object Averages |
GDI objects:
315
USER objects:
163
Resources
Handle count average: 570
Thread count average: 15
Thread resource averages
Total CPU: 2.136190621650%
Privileged CPU: 1.433323450668%
User CPU: 0.702867170982%
Context switches /sec: 2
Module memory size: 1012 KB
Total CPU: 2.061435773080%
Privileged CPU: 1.501856437509%
User CPU: 0.559579335572%
Context switches /sec: 59
Module memory size: 1012 KB
ntdll.dll

Total CPU: 0.975786773708%
Privileged CPU: 0.756033140786%
User CPU: 0.219753632922%
Module memory size: 712 KB
Total CPU: 0.916206952662%
Privileged CPU: 0.648147003442%
User CPU: 0.268059949220%
Context switches /sec: 32
Module memory size: 1012 KB
Total CPU: 0.745371840616%
Privileged CPU: 0.475380949636%
User CPU: 0.269990890980%
Context switches /sec: 25
Module memory size: 1012 KB
Total CPU: 0.433837397654%
Privileged CPU: 0.272926768898%
User CPU: 0.160910628756%
Context switches /sec: 9
Module memory size: 1012 KB
Total CPU: 0.388783095734%
Privileged CPU: 0.275727763509%
User CPU: 0.113055332226%
Context switches /sec: 9
Module memory size: 1012 KB
Total CPU: 0.369333324212%
Privileged CPU: 0.193674791965%
User CPU: 0.175658532247%
Context switches /sec: 17
Module memory size: 1.44 MB
shlwapi.dll

Total CPU: 0.140569978212%
Privileged CPU: 0.112840111227%
User CPU: 0.027729866985%
Context switches /sec: 6
Module memory size: 472 KB
ntdll.dll

Total CPU: 0.110943030112%
Privileged CPU: 0.082762732352%
User CPU: 0.028180297760%
Context switches /sec: 9
Module memory size: 712 KB
Total CPU: 0.085053184406%
Privileged CPU: 0.049058544473%
User CPU: 0.035994639933%
Context switches /sec: 45
Module memory size: 120 KB
Total CPU: 0.084405145389%
Privileged CPU: 0.054260450607%
User CPU: 0.030144694782%
Module memory size: 68 KB
ntdll.dll

Total CPU: 0.083963066033%
Privileged CPU: 0.059373200410%
User CPU: 0.024589865623%
Context switches /sec: 3
Module memory size: 712 KB
Total CPU: 0.055380714680%
Privileged CPU: 0.026799673937%
User CPU: 0.028581040742%
Context switches /sec: 9
Module memory size: 84 KB
normaliz.dll

Total CPU: 0.044215632083%
Privileged CPU: 0.005419059047%
User CPU: 0.038796573037%
Context switches /sec: 3
Module memory size: 36 KB
Total CPU: 0.043853990415%
Privileged CPU: 0.030974781792%
User CPU: 0.012879208623%
Context switches /sec: 5
Module memory size: 1020 KB
Total CPU: 0.042173183873%
Privileged CPU: 0.027631435198%
User CPU: 0.014541748675%
Context switches /sec: 44
Module memory size: 132 KB
shlwapi.dll

Total CPU: 0.041252296336%
Privileged CPU: 0.029964897411%
User CPU: 0.011287398925%
Context switches /sec: 10
Module memory size: 472 KB
Total CPU: 0.041101725127%
Privileged CPU: 0.024362716104%
User CPU: 0.016739009024%
Context switches /sec: 23
Module memory size: 136 KB
npggnt.des

Total CPU: 0.041050900531%
Privileged CPU: 0.000000000000%
User CPU: 0.041050900531%
Module memory size: 284 KB
Process details
Runs as (owner): User
Integrety level: Undefined
Windows platform: 32-bit
System Tray: Yes
Parent Processes
Process Commands
C:\WINDOWS\Explorer.EXE
"C:\WINDOWS\Explorer.EXE" /IDLIST,:2156:2380,/E,/S
C:\WINDOWS\explorer.exe
"C:\WINDOWS\explorer.exe" /select,"C:\Documents and Settings\Sandilands\Desktop\Abandoned.jpg"
Explorer.exe rundll.exe
Shell open command details
Name: SHCmdFile
Command: explorer.exe
Autoplay handler details
Name: MSOpenFolder
Command: SOFTWARE\Microsoft\Windows\ CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSOpenFolder
Network connectivity
TCP: a23-3-69-59.deploy.akamaitechnologies.com on port 1094
UDP: LISTENING on port 2818
TCP: 65.55.11.179 on port 1041
UDP: LISTENING on port 1668
TCP: localhost on port 4625
UDP: LISTENING on port 1052
UDP: LISTENING on port 2008
UDP: LISTENING on port 7277
UDP: LISTENING on port 1051
UDP: LISTENING on port 4635
UDP: LISTENING on port 4031
UDP: LISTENING on port 1238
Windows Firewall allowed program: Yes
Image hashes
MD5: 12896823fb95bfb3dc9b46bcaedc9923
SHA-1: 9d2bf84874abc5b6e9a2744b7865c193c08d362f
SHA-256: 1e675cb7df214172f7eb0497f7275556038a0d09c6e5a3e6862c5e26885ef455
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File entropy: 6.74403
File packed: No
Import Table
advapi32.dll

RegSetValueW
RegEnumKeyExW
GetUserNameW
RegNotifyChangeKeyValue
RegEnumValueW
RegQueryValueExA
RegOpenKeyExA
RegEnumKeyW
RegCloseKey
RegCreateKeyW
RegQueryInfoKeyW
RegOpenKeyExW
RegQueryValueExW
RegCreateKeyExW
RegSetValueExW
RegDeleteValueW
RegQueryValueW
RegGetValueW
GetTraceEnableFlags
GetTraceEnableLevel
GetTraceLoggerHandle
RegisterTraceGuidsW
UnregisterTraceGuids
EventRegister
EventUnregister
EventWrite
EventEnabled
GetLengthSid
GetTokenInformation
OpenProcessToken
TraceMessage
RegOpenKeyW
ConvertStringSidToSidW
CloseServiceHandle
OpenServiceW
OpenSCManagerW
QueryServiceStatus
CreateWellKnownSid
StartServiceW
CryptAcquireContextW
CryptCreateHash
CryptHashData
CryptGetHashParam
CryptDestroyHash
CryptReleaseContext
StartTraceW
EnableTraceEx
StopTraceW
LsaLookupSids
IsValidSid
GetSidSubAuthorityCount
GetSidSubAuthority
LsaOpenPolicy
LsaFreeMemory
LsaClose
OpenThreadToken
ConvertSidToStringSidW
ConvertStringSecurityDescriptorToSecurityDescriptorW
CheckTokenMembership
RegDeleteKeyExW
dwmapi.dll

DwmEnableBlurBehindWindow
DwmIsCompositionEnabled
DwmSetWindowAttribute
DwmQueryThumbnailSourceSize
DwmUnregisterThumbnail
DwmUpdateThumbnailProperties
DwmGetColorizationColor
DwmRegisterThumbnail
gdi32.dll

GetStockObject
CreatePatternBrush
OffsetViewportOrgEx
GetLayout
CombineRgn
CreateDIBSection
GetTextExtentPoint32W
StretchBlt
CreateRectRgnIndirect
CreateRectRgn
GetClipRgn
IntersectClipRect
GetViewportOrgEx
SetViewportOrgEx
SelectClipRgn
PatBlt
GetBkColor
CreateCompatibleDC
CreateCompatibleBitmap
OffsetWindowOrgEx
DeleteDC
SetBkColor
BitBlt
ExtTextOutW
GetTextExtentPointW
GetClipBox
GetObjectW
SetTextColor
SetBkMode
CreateFontIndirectW
DeleteObject
GetTextMetricsW
SelectObject
GetDeviceCaps
TranslateCharsetInfo
SetStretchBltMode
SetWindowOrgEx
LPtoDP
Polyline
CreatePen
GetTextColor
ExtCreateRegion
GetRegionData
SetLayout
GetRgnBox
GdiFlush
OffsetRgn
SetDIBits
CreateBitmap
GdiAlphaBlend
GetPixel
CreateSolidBrush
gdiplus.dll

GdipFree
GdipAlloc
GdiplusStartup
GdiplusShutdown
GdipDeleteGraphics
GdipDisposeImage
GdipGetImageWidth
GdipGetImageHeight
GdipCreateBitmapFromHBITMAP
GdipCreateFromHDC
GdipSetCompositingMode
GdipSetInterpolationMode
GdipDrawImageRectI
GdipCloneImage
GdipCreateBitmapFromStreamICM
GdipCreateBitmapFromStream
GdipLoadImageFromFileICM
GdipLoadImageFromFile
kernel32.dll

GetSystemDirectoryW
CreateThread
CreateJobObjectW
ExitProcess
SetProcessShutdownParameters
ReleaseMutex
CreateMutexW
SetPriorityClass
GetCurrentProcess
GetStartupInfoW
GetCommandLineW
SetErrorMode
LeaveCriticalSection
EnterCriticalSection
ResetEvent
LoadLibraryExA
CompareFileTime
GetSystemTimeAsFileTime
SetThreadPriority
GetCurrentThreadId
GetThreadPriority
GetCurrentThread
GetUserDefaultLangID
Sleep
GetBinaryTypeW
GetModuleHandleExW
SystemTimeToFileTime
GetLocalTime
GetCurrentProcessId
GetEnvironmentVariableW
UnregisterWait
GlobalGetAtomNameW
GetFileAttributesW
MoveFileW
lstrcmpW
LoadLibraryExW
FindClose
FindNextFileW
FindFirstFileW
lstrcmpiA
SetEvent
AssignProcessToJobObject
GetDateFormatW
GetTimeFormatW
FlushInstructionCache
lstrcpynW
GetSystemWindowsDirectoryW
SetLastError
GetProcessHeap
HeapFree
HeapReAlloc
HeapSize
HeapAlloc
GetUserDefaultLCID
ReadProcessMemory
OpenProcess
InterlockedCompareExchange
LoadLibraryA
QueryPerformanceCounter
UnhandledExceptionFilter
SetUnhandledExceptionFilter
VirtualFree
VirtualAlloc
ResumeThread
TerminateProcess
TerminateThread
GetSystemDefaultLCID
GetLocaleInfoW
CreateEventW
GetLastError
OpenEventW
DelayLoadFailureHook
WaitForSingleObject
GetTickCount
ExpandEnvironmentStringsW
GetModuleFileNameW
GetPrivateProfileStringW
lstrcmpiW
CreateProcessW
FreeLibrary
GetWindowsDirectoryW
LocalAlloc
CreateFileW
DeviceIoControl
LocalFree
GetQueuedCompletionStatus
CreateIoCompletionPort
SetInformationJobObject
CloseHandle
LoadLibraryW
GetModuleHandleW
ActivateActCtx
DeactivateActCtx
GetFileAttributesExW
GetProcAddress
DeleteCriticalSection
CreateEventA
HeapDestroy
InitializeCriticalSection
MulDiv
InitializeCriticalSectionAndSpinCount
lstrlenW
InterlockedDecrement
InterlockedIncrement
GlobalAlloc
InterlockedExchange
GetModuleHandleA
GetVersionExA
GlobalFree
GetProcessTimes
lstrcpyW
GetLongPathNameW
RegisterWaitForSingleObject
GetFileSize
ReadFile
RaiseException
OpenThread
GetSystemTime
GetPriorityClass
SearchPathW
GetSystemDefaultUILanguage
UnmapViewOfFile
MapViewOfFile
GetTimeZoneInformation
GetDynamicTimeZoneInformation
QueryPerformanceFrequency
GetTickCount64
MultiByteToWideChar
QueueUserWorkItem
GetProductInfo
DeleteFileW
GetProcessId
CompareStringW
QueryFullProcessImageNameW
CreateFileMappingW
WideCharToMultiByte
GlobalLock
GlobalUnlock
DuplicateHandle
GetCurrentDirectoryW
WaitForMultipleObjects
GetComputerNameW
ReleaseActCtx
CreateActCtxW
FindResourceExW
LoadResource
LockResource
QueryInformationJobObject
GetUserDefaultUILanguage
HeapSetInformation
GetVersionExW
RegisterApplicationRestart
SetProcessDEPPolicy
SetTermsrvAppInstallMode
CompareStringOrdinal
GetPrivateProfileIntW
SetFilePointer
FormatMessageW
WriteFile
msvcrt.dll
ntdll.dll

RtlNtStatusToDosError
NtQueryInformationProcess
WinSqmSetString
NtSetInformationProcess
WinSqmIsOptedIn
WinSqmAddToStreamEx
NtOpenThreadToken
NtOpenProcessToken
NtSetSystemInformation
WinSqmAddToStream
WinSqmEventEnabled
EtwEventWrite
EtwEventEnabled
RtlGetProductInfo
NtClose
NtQueryInformationToken
WinSqmSetDWORD
ole32.dll

CoFreeUnusedLibraries
RegisterDragDrop
CreateBindCtx
RevokeDragDrop
CoInitializeEx
CoUninitialize
OleInitialize
CoRevokeClassObject
CoRegisterClassObject
CoMarshalInterThreadInterfaceInStream
CoCreateInstance
OleUninitialize
DoDragDrop
StringFromGUID2
CoRegisterMessageFilter
CoCreateFreeThreadedMarshaler
PropVariantClear
ReleaseStgMedium
CreateStreamOnHGlobal
CoTaskMemFree
CoGetInterfaceAndReleaseStream
CoInitialize
CoGetMalloc
CoTaskMemAlloc
CLSIDFromString
CoGetClassObject
CoGetObject
powrprof.dll

CallNtPowerInformation
GetPwrCapabilities
PowerDeterminePlatformRole
propsys.dll

PropVariantToStringAlloc
PropVariantToUInt32
PropVariantToUInt64
PropVariantToBoolean
VariantToStringAlloc
VariantToStringWithDefault
PropVariantToString
VariantToBooleanWithDefault
VariantToInt32WithDefault
PSCreateMemoryPropertyStore
PropVariantToInt64
PSGetPropertyKeyFromName
PSPropertyKeyFromString
PSGetPropertyDescription
PSGetNameFromPropertyKey
rpcrt4.dll

RpcBindingFree
RpcBindingSetAuthInfoExW
RpcStringFreeW
RpcBindingFromStringBindingW
RpcStringBindingComposeW
I_RpcExceptionFilter
NdrClientCall2
secur32.dll

shell32.dll

SHGetFolderPathW
ExtractIconExW
SHGetSpecialFolderLocation
ShellExecuteExW
SHGetSpecialFolderPathW
SHBindToParent
SHParseDisplayName
SHChangeNotify
SHGetDesktopFolder
SHAddToRecentDocs
DuplicateIcon
SHUpdateRecycleBinIcon
SHGetFolderLocation
SHGetPathFromIDListA
SHGetPathFromIDListW
SHGetPropertyStoreForWindow
SHGetStockIconInfo
Shell_GetCachedImageIndexW
SHGetLocalizedName
SHCreateDataObject
SHCreateShellItemArrayFromShellItem
SHGetKnownFolderPath
SHCreateShellItemArrayFromIDLists
SHBindToFolderIDListParentEx
SHGetFileInfoW
SHCreateItemWithParent
SHGetKnownFolderIDList
SHBindToObject
SHGetNameFromIDList
SHCreateShellItem
ShellExecuteW
SHEnableServiceObject
SHGetIDListFromObject
SHChangeNotifyRegisterThread
SHCreateItemFromIDList
SHFileOperationW
SHGetFolderPathEx
Shell_NotifyIconW
Shell_NotifyIconGetRect
SHEvaluateSystemCommandTemplate
SHCreateItemFromParsingName
DragQueryFileW
SHBindToFolderIDListParent
SHGetFolderPathAndSubDirW
shlwapi.dll

StrCpyNW
StrRetToBufW
StrRetToStrW
SHQueryValueExW
PathIsNetworkPathW
AssocCreate
StrCatW
StrCpyW
SHGetValueW
StrCmpNIW
PathRemoveBlanksW
PathRemoveArgsW
PathFindFileNameW
StrStrIW
PathGetArgsW
StrToIntW
SHRegGetBoolUSValueW
SHRegWriteUSValueW
SHRegCloseUSKey
SHRegCreateUSKeyW
SHRegGetUSValueW
SHSetValueW
PathAppendW
PathUnquoteSpacesW
PathQuoteSpacesW
SHSetThreadRef
SHCreateThreadRef
PathCombineW
SHStrDupW
PathIsPrefixW
PathParseIconLocationW
AssocQueryKeyW
AssocQueryStringW
StrCmpW
SHRegQueryUSValueW
SHRegOpenUSKeyW
SHRegSetUSValueW
PathIsDirectoryW
PathFileExistsW
PathGetDriveNumberW
StrChrW
PathFindExtensionW
PathRemoveFileSpecW
PathStripToRootW
SHOpenRegStream2W
StrDupW
SHDeleteValueW
StrCatBuffW
SHDeleteKeyW
StrCmpIW
wnsprintfW
StrCmpNW
SHStrDupA
PathCommonPrefixW
PathRemoveExtensionW
PathIsFileSpecW
StrChrIW
SHRegGetValueW
StrTrimW
SHQueryInfoKeyW
SHCreateStreamOnFileW
PathIsRootW
PathStripPathW
ChrCmpIW
PathMatchSpecW
StrPBrkW
slc.dll

SLGetWindowsInformationDWORD
user32.dll
uxtheme.dll

GetThemeBackgroundContentRect
GetThemeBool
GetThemePartSize
DrawThemeParentBackground
OpenThemeData
DrawThemeBackground
GetThemeTextExtent
DrawThemeText
CloseThemeData
SetWindowTheme
GetThemeBackgroundRegion
GetThemeMargins
GetThemeColor
GetThemeFont
GetThemeRect
IsAppThemed
BufferedPaintInit
IsCompositionActive
GetThemeMetric
GetWindowTheme
EndBufferedPaint
BeginBufferedPaint
DrawThemeTextEx
BufferedPaintUnInit
IsThemeActive
IsThemePartDefined
DrawThemeIcon
GetBufferedPaintBits
BufferedPaintClear
GetThemeBackgroundExtent
GetThemeInt