File details
File name: msseces.exe
Name: Microsoft Security Essentials
Description: Microsoft Security Essentials User Interface
Version: 4.2.0223.0
Size: 1.22 MB
Original file name: msseces.exe
Digital certificate
Certificate authority:
Microsoft Corporation
Effective date: 7/13/2009
Expiration date: 10/13/2010
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0032794417%
Privileged CPU:
0.0011865369%

User CPU:
0.00209290478064%

Privileged CPU time: 9498724.02 ms
Privileged CPU time /min: 2,390 ms
CPU cycle count:
513,710,643
CPU cycle count /min: 33,435,982
Context switches /sec:
26
 | Memory utilization averages |
Committed memory:
115.9 MB
Peak committed memory: 124.34 MB
Paged memory:
7.73 MB
Peak paged memory: 9.47 MB
Paged system memory:
219.9 KB
Non-paged system memory: 20.47 KB
Working set memory:
11.29 MB
Peak working set memory: 18.27 MB
Min working set memory: 9.95 MB
Private memory:
7.73 MB
Page faults:
38,108
Page faults /min: 103
 | Process I/O averages |
Total read operations:
117
Read operations /min: 1
Total read transfer: 138.99 KB
Read transfer /min: 22 Bytes
Total write operations:
1,853
Write operations /min: 10
Total write transfer: 14.44 MB
Write transfer /min: 69.64 KB
Total other operations:
2,514
Other operations /min: 7
Total other transfer: 3.87 MB
Other Transfer /min: 22.6 KB
 | GUI Object Averages |
GDI objects:
161
Peak GDI objects: 166
USER objects:
84
Peak USER objects: 83
Resources
Handle count average: 282
Thread count average: 5
Thread resource averages
Total CPU: 0.011328211802%
Privileged CPU: 0.003585551754%
User CPU: 0.007742660049%
CPU Cycle count /sec: 578,848
Context switches /sec: 7
Module memory size: 1.23 MB
ntdll.dll

Total CPU: 0.000899670472%
Privileged CPU: 0.000276415604%
User CPU: 0.000623254868%
CPU Cycle count /sec: 34,028
Module memory size: 1.66 MB
gdiplus.dll

Total CPU: 0.000174412639%
Privileged CPU: 0.000158097890%
User CPU: 0.000016314749%
CPU Cycle count /sec: 1,353
Module memory size: 2.09 MB
ntdll.dll

Total CPU: 0.000173025969%
Privileged CPU: 0.000000000000%
User CPU: 0.000173025969%
CPU Cycle count /sec: 52,238
Module memory size: 1.67 MB
gdiplus.dll

Total CPU: 0.000173025432%
Privileged CPU: 0.000173025432%
User CPU: 0.000000000000%
CPU Cycle count /sec: 1,082
Module memory size: 2.08 MB
Total CPU: 0.000058453209%
Privileged CPU: 0.000046762567%
User CPU: 0.000011690642%
CPU Cycle count /sec: 21,840
Module memory size: 1.69 MB
ntdll.dll

Total CPU: 0.000008292231%
Privileged CPU: 0.000007014619%
User CPU: 0.000001277612%
CPU Cycle count /sec: 87
Module memory size: 1.52 MB
gdiplus.dll

Total CPU: 0.000005867618%
Privileged CPU: 0.000005359354%
User CPU: 0.000000508264%
CPU Cycle count /sec: 113
Module memory size: 2.11 MB
Process details
Runs as (owner): User
Integrety level: Undefined
Windows platform: 64-bit
System Tray: Yes
Parent Processes
Process Commands
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files\Microsoft Security Client\msseces.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" /UpdateAndQuickScan /OpenWebPageOnClose
/hide
Startup files (all users) run details
Name: MSC
Command: "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
Image hashes
MD5: 3911917b93dd9023daa8258147aa7bcf
SHA-1: be7bd2352ec09bc29c7a2ee26dd6a673475350bd
SHA-256: 490542572acee2ee3a7e5905f0564e4ded2da1116575e951ba7262ba5c495417
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File entropy: 6.24204
File packed: No
Import Table
advapi32.dll

OpenThreadToken
StartTraceW
ControlTraceW
EnableTrace
QueryAllTracesW
RegQueryValueExW
RegOpenKeyExW
GetTokenInformation
GetLengthSid
AllocateAndInitializeSid
FreeSid
CopySid
CheckTokenMembership
OpenProcessToken
LookupPrivilegeValueW
AdjustTokenPrivileges
TraceEvent
RegCloseKey
UnregisterTraceGuids
RegisterTraceGuidsW
GetTraceLoggerHandle
GetTraceEnableLevel
GetTraceEnableFlags
GetNamedSecurityInfoW
GetSecurityDescriptorControl
GetSecurityDescriptorLength
MakeSelfRelativeSD
GetSecurityDescriptorSacl
GetSecurityDescriptorDacl
GetSecurityDescriptorGroup
GetSecurityDescriptorOwner
GetAce
GetAclInformation
AddAce
InitializeAcl
EqualSid
IsValidSid
ConvertStringSecurityDescriptorToSecurityDescriptorW
GetSidSubAuthorityCount
DuplicateTokenEx
GetSidSubAuthority
OpenSCManagerW
ConvertStringSidToSidW
OpenServiceW
ChangeServiceConfigW
ControlService
QueryServiceStatus
PrivilegeCheck
InitiateSystemShutdownExW
CloseServiceHandle
LookupPrivilegeNameW
CreateProcessAsUserW
RegDeleteValueW
RegDeleteKeyW
RegSetValueExW
RegCreateKeyExW
SetNamedSecurityInfoW
comctl32.dll

ImageList_LoadImageW
ImageList_Destroy
ImageList_Create
ImageList_ReplaceIcon
InitCommonControlsEx
ImageList_GetIconSize
comdlg32.dll

CommDlgExtendedError
PrintDlgW
crypt32.dll

CertVerifyCertificateChainPolicy
gdi32.dll

SetViewportOrgEx
SetWindowOrgEx
SetGraphicsMode
RestoreDC
CreatePatternBrush
DPtoLP
ModifyWorldTransform
SaveDC
ExtTextOutW
CreateDIBSection
GetObjectW
SetLayout
SelectObject
CreateBitmap
GetDeviceCaps
CreateCompatibleDC
SetTextColor
SetBkMode
PatBlt
GetTextExtentPoint32W
GetStockObject
GetObjectA
CreateSolidBrush
GetLayout
GetPixel
SetBkColor
GetTextMetricsW
DeleteDC
DeleteObject
CreateFontIndirectW
BitBlt
EndDoc
AbortDoc
StartDocW
EndPage
StartPage
CreateCompatibleBitmap
gdiplus.dll

GdipDrawImageRect
GdipSetStringFormatHotkeyPrefix
GdipSetStringFormatLineAlign
GdipSetStringFormatAlign
GdipStringFormatGetGenericDefault
GdipCloneStringFormat
GdipDrawLine
GdipLoadImageFromStreamICM
GdipLoadImageFromStream
GdipDeleteStringFormat
GdipCreateStringFormat
GdipDrawLineI
GdipDrawPath
GdipFillPath
GdipDeletePath
GdipCreatePath
GdipDrawImageRectI
GdipDrawString
GdipCloneBitmapAreaI
GdipCreateFontFromLogfontA
GdipCreateFontFromDC
GdipMeasureString
GdipFillRectangle
GdipReleaseDC
GdipGetDC
GdipAddPathArcI
GdipAddPathLineI
GdipClosePathFigure
GdipCreateLineBrushFromRect
GdipCreateHICONFromBitmap
GdipCreateBitmapFromStreamICM
GdipCreateBitmapFromStream
GdipGetImagePixelFormat
GdipDeleteFont
GdipCloneBrush
GdipFillRectangleI
GdipDrawRectangleI
GdipCreateLineBrushFromRectI
GdiplusShutdown
GdipFree
GdipAlloc
GdipDeleteGraphics
GdipDisposeImage
GdipGetImageWidth
GdipGetImageHeight
GdipCreateBitmapFromHICON
GdiplusStartup
GdipCreateFromHDC
GdipSetSmoothingMode
GdipDrawImageRectRectI
GdipCloneImage
GdipDeleteBrush
GdipCreatePen1
GdipDeletePen
GdipCreateSolidFill
GdipSetTextRenderingHint
GdipImageRotateFlip
kernel32.dll

HeapDestroy
HeapAlloc
HeapFree
HeapReAlloc
HeapSize
GetProcessHeap
LoadLibraryA
VirtualFree
VirtualAlloc
UnmapViewOfFile
GetSystemDefaultUILanguage
GetUserDefaultUILanguage
SearchPathW
WaitForMultipleObjects
InterlockedExchange
Sleep
InterlockedCompareExchange
OutputDebugStringA
RtlUnwind
SetUnhandledExceptionFilter
GetModuleHandleA
QueryPerformanceCounter
GetTickCount
GetCurrentThreadId
GetCurrentProcessId
GetSystemTimeAsFileTime
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
GetVersion
RaiseException
CloseHandle
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSection
DeleteCriticalSection
SizeofResource
LockResource
LoadResource
FindResourceW
FindResourceExW
GetLastError
FlushInstructionCache
LocalFree
LocalAlloc
FreeLibrary
GetProcAddress
LoadLibraryW
SetEvent
CreateEventW
ResetEvent
CreateMutexW
SetLastError
InterlockedIncrement
InterlockedDecrement
GetVersionExW
FreeConsole
GetConsoleDisplayMode
AttachConsole
lstrcmpW
GetModuleHandleW
GetDateFormatW
GetModuleFileNameW
GetTimeFormatW
FileTimeToLocalFileTime
GetLocaleInfoW
GetLocalTime
FileTimeToSystemTime
CreateFileW
ReadFile
GetDriveTypeW
GetFileAttributesW
MulDiv
GetLogicalDriveStringsW
FindClose
FindFirstFileW
FindNextFileW
ExitProcess
CompareFileTime
GetExitCodeProcess
SwitchToThread
WaitForSingleObject
FormatMessageW
DeleteFileW
MoveFileW
GetTempPathW
LoadLibraryExW
GetSystemDefaultLangID
lstrlenW
TryEnterCriticalSection
GetFileSizeEx
GetSystemDefaultLCID
CreateProcessW
MoveFileExW
WriteFile
GetTempFileNameW
InitializeCriticalSectionAndSpinCount
CreateThread
LCMapStringW
CreateFileMappingW
MapViewOfFile
ExpandEnvironmentStringsW
GetCurrentThread
SystemTimeToFileTime
WideCharToMultiByte
MultiByteToWideChar
SetErrorMode
GetVersionExA
GetCommandLineW
VerifyVersionInfoW
GetFileSize
GetLongPathNameW
GetExitCodeThread
GetPrivateProfileStringW
FreeResource
WritePrivateProfileStringW
ProcessIdToSessionId
GlobalFindAtomW
HeapSetInformation
RemoveDirectoryW
Process32NextW
Process32FirstW
CreateToolhelp32Snapshot
GetDiskFreeSpaceExW
GetWindowsDirectoryW
IsWow64Process
ReleaseMutex
CopyFileW
GlobalFree
GlobalAlloc
GetPrivateProfileIntW
InterlockedPopEntrySList
IsProcessorFeaturePresent
InterlockedPushEntrySList
OpenProcess
GetSystemDirectoryW
CreateDirectoryW
GetNativeSystemInfo
mpclient.dll

MpConfigRegisterForNotifications
MpThreatQuery
MpSampleQuery
MpSampleSubmit
MpThreatEnumerate
MpThreatOpen
MpElevateCleanHandle
MpElevationHandleAcquire
MpCleanOpen
MpCleanStart
MpUpdateStartEx
MpScanStart
MpOfflineScanStatusQuery
MpManagerStatusQueryEx
MpNotificationRegister
MpUpdateControl
MpManagerVersionQuery
MpConfigIteratorEnum
MpConfigIteratorOpen
MpTelemetryUpdateUserConsent
MpConfigUnregisterNotifications
MpConfigIteratorClose
MpConfigGetValueAlloc
MpProductGenuineCheck
MpManagerEnable
MpFreeMemory
MpCreateComInstance
MpConfigClose
MpConfigGetValue
MpConfigOpen
MpHandleClose
MpForcedReboot
MpTelemetryIncrementDWORD
MpTelemetrySetDWORD
MpClientUtilExportFunctions
MpErrorMessageFormat
MpManagerOpen
MpUtilsExportFunctions
MpAllocMemory
MpTelemetryIsOptIn
MpConfigUninitialize
MpConfigInitialize
MpTelemetryUninitialize
MpTelemetryUpload
MpTelemetryInitialize
msvcrt.dll
ole32.dll

CoInitializeEx
CoCreateGuid
StringFromGUID2
CoCreateInstance
CoUninitialize
psapi.dll

shell32.dll

ShellExecuteExW
SHGetFileInfoW
Shell_NotifyIconW
SHGetFolderPathW
SHGetSpecialFolderLocation
SHGetPathFromIDListW
CommandLineToArgvW
shlwapi.dll

PathFileExistsW
StrCmpNIW
StrStrIW
PathAppendW
PathRemoveFileSpecW
StrCmpNW
StrCmpW
PathIsDirectoryW
PathCombineW
PathIsRelativeW
PathFindFileNameW
StrCmpIW
PathMatchSpecW
PathIsRootW
user32.dll

GetMessageW
LoadAcceleratorsW
GetDesktopWindow
FindWindowExW
AllowSetForegroundWindow
MessageBoxW
EnableWindow
SetWindowTextW
LoadImageW
GetLastActivePopup
ShowCursor
SetCursor
GetWindowTextW
GetWindowTextLengthW
PostQuitMessage
SetFocus
GetFocus
GetWindowLongW
IsWindowEnabled
GetNextDlgTabItem
IsDialogMessageW
GetClassNameW
GetKeyState
CallWindowProcW
MoveWindow
SetWindowPos
GetWindowRect
GetClientRect
GetWindowPlacement
ScreenToClient
BeginPaint
EndPaint
GetDC
ReleaseDC
InvalidateRect
ShowWindow
IsWindowVisible
LockWindowUpdate
SetTimer
KillTimer
MapWindowPoints
SystemParametersInfoW
GetWindow
GetParent
IsRectEmpty
GetSysColor
PeekMessageW
FindWindowW
WindowFromPoint
GetSystemMetrics
GetWindowThreadProcessId
GetForegroundWindow
DefWindowProcW
DestroyMenu
FlashWindowEx
TrackMouseEvent
TranslateAcceleratorW
RegisterWindowMessageW
TrackPopupMenu
GetCursorPos
EnableMenuItem
AppendMenuW
CreatePopupMenu
ReplyMessage
MessageBeep
GetDoubleClickTime
GetAncestor
DrawFocusRect
FillRect
InflateRect
EndDialog
GetDlgItem
DrawTextW
GetDlgCtrlID
GetSubMenu
LoadMenuW
DeleteMenu
RedrawWindow
MessageBoxIndirectW
GetActiveWindow
GetSysColorBrush
GetSystemMenu
GetMenuState
PtInRect
EqualRect
LoadIconW
SetMenuItemInfoW
SetMenuInfo
IsMenu
OffsetRect
ShowCaret
HideCaret
GetWindowDC
SetDlgItemTextW
SetRectEmpty
SetCapture
ReleaseCapture
DrawEdge
GetMessagePos
GetCapture
UpdateWindow
GetScrollPos
ScrollWindow
ScrollWindowEx
SetScrollPos
GetScrollInfo
SetScrollInfo
GetWindowInfo
CreateDialogIndirectParamW
SetActiveWindow
TranslateMessage
DispatchMessageW
SendMessageW
PostMessageW
CreateWindowExW
RegisterClassExW
DestroyIcon
DestroyWindow
LoadCursorW
GetClassInfoExW
IsWindow
SetWindowLongW
DialogBoxIndirectParamW
UnregisterClassA
ClientToScreen
ExitWindowsEx
SetForegroundWindow
GetIconInfo
DrawIconEx
CreateIconIndirect
ModifyMenuW
GetMenuStringW
GetMenuItemID
GetMenuItemInfoW
GetMenuItemCount
CheckDlgButton
AdjustWindowRect
PostThreadMessageW
LoadStringW
CreateDialogParamW
IsDlgButtonChecked
userenv.dll

UnloadUserProfile
DestroyEnvironmentBlock
CreateEnvironmentBlock
version.dll

GetFileVersionInfoSizeW
GetFileVersionInfoW
VerQueryValueW
wininet.dll

InternetGetConnectedState
wintrust.dll

WinVerifyTrust
WTHelperProvDataFromStateData
WTHelperGetProvSignerFromChain
CryptCATAdminCalcHashFromFileHandle
CryptCATAdminAcquireContext
CryptCATAdminEnumCatalogFromHash
CryptCATCatalogInfoFromContext
CryptCATAdminReleaseCatalogContext
CryptCATAdminReleaseContext
wtsapi32.dll

WTSQuerySessionInformationW
WTSEnumerateSessionsW
WTSFreeMemory
WTSQueryUserToken