File details
File name: iexplore.exe
Name: Internet Explorer
Description: Microsoft® Windows® Operating System
Version: 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
Product version: 6.00.2900.2180
Size: 91 KB
Original file name: IEXPLORE.EXE
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.1235347092%
Privileged CPU:
0.0446715412%

User CPU:
0.07886316802016%

Privileged CPU time: 11798.21 ms
Privileged CPU time /min: 0 ms
Context switches /sec:
884
 | Memory utilization averages |
Committed memory:
459.81 MB
Peak committed memory: 468.89 MB
Paged memory:
169.69 MB
Peak paged memory: 177.67 MB
Paged system memory:
352.84 KB
Non-paged system memory: 39.17 KB
Working set memory:
53.59 MB
Peak working set memory: 133.4 MB
Min working set memory: 46.35 MB
Private memory:
169.69 MB
Page faults:
328,516
Page faults /min: 0
 | Process I/O averages |
Total read operations:
16,693
Total read transfer: 15 MB
Total write operations:
3,794
Total write transfer: 4.84 MB
Total other operations:
37,697
Total other transfer: 2.35 MB
 | GUI Object Averages |
GDI objects:
678
USER objects:
423
Resources
Handle count average: 1,708
Thread count average: 61
Thread resource averages
Total CPU: 20.951044035835%
Privileged CPU: 2.375679417411%
User CPU: 18.575364618424%
Context switches /sec: 576
Module memory size: 100 KB
winmm.dll

Total CPU: 0.185039023096%
Privileged CPU: 0.137184103329%
User CPU: 0.047854919766%
Context switches /sec: 65
Module memory size: 180 KB
mscorwks.dll

Total CPU: 0.044336804430%
Privileged CPU: 0.023625608383%
User CPU: 0.020711196047%
Context switches /sec: 4
Module memory size: 5.56 MB
ntdll.dll

Total CPU: 0.031658792499%
Privileged CPU: 0.019177974343%
User CPU: 0.012480818156%
Context switches /sec: 4
Module memory size: 704 KB
Total CPU: 0.020808695678%
Privileged CPU: 0.013317560248%
User CPU: 0.007491135430%
Context switches /sec: 8
Module memory size: 396 KB
Total CPU: 0.019516048381%
Privileged CPU: 0.009686943094%
User CPU: 0.009829105287%
Context switches /sec: 97
Module memory size: 2.93 MB
Total CPU: 0.018852252999%
Privileged CPU: 0.010256429230%
User CPU: 0.008595823769%
Context switches /sec: 12
Module memory size: 36 KB
Total CPU: 0.018179045130%
Privileged CPU: 0.012104870794%
User CPU: 0.006074174335%
Context switches /sec: 36
Module memory size: 10.14 MB
Total CPU: 0.015279361754%
Privileged CPU: 0.013706487883%
User CPU: 0.001572873872%
Context switches /sec: 10
Module memory size: 1.01 MB
Total CPU: 0.011708660679%
Privileged CPU: 0.005741496292%
User CPU: 0.005967164387%
Context switches /sec: 32
Module memory size: 644 KB
Total CPU: 0.009950083720%
Privileged CPU: 0.008291736433%
User CPU: 0.001658347287%
Module memory size: 572 KB
Total CPU: 0.009943982181%
Privileged CPU: 0.004971991090%
User CPU: 0.004971991090%
Context switches /sec: 46
Module memory size: 432 KB
Total CPU: 0.009427460084%
Privileged CPU: 0.006655614057%
User CPU: 0.002771846027%
Context switches /sec: 30
Module memory size: 4.22 MB
Total CPU: 0.008721377228%
Privileged CPU: 0.006175863932%
User CPU: 0.002545513296%
Module memory size: 616 KB
Total CPU: 0.007638790352%
Privileged CPU: 0.007638790352%
User CPU: 0.000000000000%
Context switches /sec: 3
Module memory size: 1.98 MB
Total CPU: 0.006550650981%
Privileged CPU: 0.004700968349%
User CPU: 0.001849682631%
Context switches /sec: 3
Module memory size: 396 KB
Total CPU: 0.005840456867%
Privileged CPU: 0.004043393216%
User CPU: 0.001797063651%
Context switches /sec: 18
Module memory size: 460 KB
Total CPU: 0.004056600367%
Privileged CPU: 0.002295404492%
User CPU: 0.001761195875%
Context switches /sec: 30
Module memory size: 4.27 MB
Total CPU: 0.003804245055%
Privileged CPU: 0.001709230386%
User CPU: 0.002095014670%
Context switches /sec: 5
Module memory size: 1.51 MB
Total CPU: 0.003738508836%
Privileged CPU: 0.002076847326%
User CPU: 0.001661661510%
Context switches /sec: 14
Module memory size: 1.21 MB
Process details
Runs as (owner): User
Integrety level: Undefined
Windows platform: 32-bit
Parent Processes
Child Process
Process Commands
"C:\Program Files\Internet Explorer\iexplore.exe" "httC://us.yhs4.search.yahoo.com/yhs/search?hspart=w3i&hsimp=yhs-defalttabtransfer&type=W3i_YT,191,8_4,Search,20120835,18367,0,4,0&p=Deal%20Slider%20install"
"C:\Program Files\Internet Explorer\iexplore.exe" "httC://us.yhs4.search.yahoo.com/yhs/search?hspart=w3i&hsimp=yhs-defalttabtransfer&type=W3i_YT,191,8_4,Search,20120835,18367,0,4,0&p=Deal%20Slider"
"C:\Program Files\Internet Explorer\iexplore.exe" httC://01NETcom.OurToolbar.com/SetupFinish
httC://dl.installiq.com/postback/V2/landing.aspx?npx=3763,8434,8437&rc=13&a=10074&f=utilitiesypage&cc=840&rd=False&pq=1&unique=False&ps=b1aeeba6-a7df-480e-b2a4-3b1be052934e&a2=US&pc=&bb=False&v=2872&s=musicoasis&ct=4&atid=-1&thankyou=http%3a%2f%2flan.music-oasis.com%2fLPQueue%2f1128%2f%3fa%3d13196%26f%3dmusicoasistypage
"C:\Program Files\Internet Explorer\IEXPLORE.EXE"
Shell open command details
Name: InternetShortcut
Command: "C:\Program Files\Internet Explorer\iexplore.exe" %1
Image hashes
MD5: e7484514c0464642be7b4dc2689354c8
SHA-1: a873c4a36f861dded9a4f5ddc6a8777bf94d1cc1
SHA-256: c09bc04058f1e2d4eae481490b998381486311e02ff782e99383c16d77c1b3bc
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File entropy: 5.74055
File packed: No
Import Table
kernel32.dll

UnhandledExceptionFilter
GetCommandLineA
lstrlenW
MultiByteToWideChar
CreateEventA
GetCurrentThreadId
lstrcatA
lstrlenA
lstrcmpiA
lstrcpyA
GetModuleFileNameA
FreeLibrary
GetProcAddress
LoadLibraryA
GetVersionExA
UnmapViewOfFile
CloseHandle
ReleaseMutex
SetEvent
WaitForSingleObject
CreateProcessA
lstrcpynA
GetCurrentProcessId
DuplicateHandle
GetCurrentProcess
CreateMutexA
MapViewOfFile
CreateFileMappingA
WaitForMultipleObjects
GetModuleFileNameW
OpenProcess
GetLastError
SetUnhandledExceptionFilter
LocalFree
LocalAlloc
GetModuleHandleA
ExitThread
GetStartupInfoA
SetErrorMode
TerminateProcess
QueryPerformanceCounter
GetTickCount
GetSystemTimeAsFileTime
msvcrt.dll
shlwapi.dll

SHGetValueA
SHRegGetBoolUSValueA
PathRemoveFileSpecA
PathAppendA
PathQuoteSpacesA
StrCpyNW
wnsprintfA
PathFindFileNameA
StrStrIA
user32.dll

GetShellWindow
GetClassNameA
SendMessageA
PeekMessageA
MsgWaitForMultipleObjects
DestroyWindow
TranslateMessage
DispatchMessageA
LoadStringA
DefWindowProcA
RegisterClassA
CreateMenu
CreateWindowExA
ShowWindow
GetForegroundWindow
wsprintfA