File details
File name: Explorer.EXE
Name: Windows Explorer
Description: Microsoft® Windows® Operating System
Version: 6.0.6000.16386 (vista_rtm.061101-2205)
Product version: 6.0.6000.16386
Size: 2.79 MB
Original file name: EXPLORER.EXE
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0046557905%
Privileged CPU:
0.0013972765%

User CPU:
0.00325851399779%

Privileged CPU time: 50285456857.89 ms
Privileged CPU time /min: 19 ms
CPU cycle count:
145,231,261
CPU cycle count /min: 270,570,661
Context switches /sec:
42
 | Memory utilization averages |
Committed memory:
262.27 MB
Peak committed memory: 327.53 MB
Paged memory:
46.11 MB
Peak paged memory: 81.42 MB
Paged system memory:
409.04 KB
Non-paged system memory: 55.53 KB
Working set memory:
50.66 MB
Peak working set memory: 96.19 MB
Min working set memory: 33.33 MB
Private memory:
46.11 MB
Page faults:
13,095,302
Page faults /min: 159
 | Process I/O averages |
Total read operations:
131,324
Read operations /min: 5
Read transfer /min: 10.46 KB
Total write operations:
5,574
Write operations /min: 1
Total write transfer: 102.95 MB
Write transfer /min: 101 Bytes
Total other operations:
47,978,932
Other operations /min: 196
Total other transfer: 138.48 MB
Other Transfer /min: 18.06 KB
 | GUI Object Averages |
GDI objects:
407
USER objects:
247
Resources
Handle count average: 762
Thread count average: 28
Thread resource averages
Total CPU: 0.013315085314%
Privileged CPU: 0.006930931340%
User CPU: 0.006384153975%
CPU Cycle count /sec: 265,638
Module memory size: 2.8 MB
shlwapi.dll

Total CPU: 0.007714627545%
Privileged CPU: 0.005493707607%
User CPU: 0.002220919939%
CPU Cycle count /sec: 380,421
Context switches /sec: 1
Module memory size: 352 KB
Total CPU: 0.007236223861%
Privileged CPU: 0.004333830944%
User CPU: 0.002902392917%
CPU Cycle count /sec: 161,160
Module memory size: 1.27 MB
stobject.dll

Total CPU: 0.002707357412%
Privileged CPU: 0.001445560180%
User CPU: 0.001261797232%
CPU Cycle count /sec: 62,788
Module memory size: 584 KB
wlanapi.dll

Total CPU: 0.000489339056%
Privileged CPU: 0.000321973831%
User CPU: 0.000167365225%
CPU Cycle count /sec: 13,388
Module memory size: 72 KB
rpcrt4.dll

Total CPU: 0.000473314673%
Privileged CPU: 0.000359642794%
User CPU: 0.000113671879%
CPU Cycle count /sec: 14,042
Module memory size: 776 KB
mscorwks.dll

Total CPU: 0.000138671664%
Privileged CPU: 0.000138671664%
User CPU: 0.000000000000%
CPU Cycle count /sec: 1,375
Module memory size: 5.67 MB
gdiplus.dll

Total CPU: 0.000069887702%
Privileged CPU: 0.000068274952%
User CPU: 0.000001612750%
CPU Cycle count /sec: 830
Module memory size: 1.67 MB
wdmaud.drv

Total CPU: 0.000050074314%
Privileged CPU: 0.000045485846%
User CPU: 0.000004588468%
CPU Cycle count /sec: 439
Module memory size: 188 KB
sndvolsso.dll

Total CPU: 0.000042260806%
Privileged CPU: 0.000006462794%
User CPU: 0.000035798012%
CPU Cycle count /sec: 758
Module memory size: 192 KB
ole32.dll

Total CPU: 0.000020131133%
Privileged CPU: 0.000017931344%
User CPU: 0.000002199789%
CPU Cycle count /sec: 1,236
Module memory size: 1.27 MB
winmm.dll

Total CPU: 0.000017666112%
Privileged CPU: 0.000012306731%
User CPU: 0.000005359380%
CPU Cycle count /sec: 459
Module memory size: 200 KB
mmdevapi.dll

Total CPU: 0.000006576540%
Privileged CPU: 0.000003555953%
User CPU: 0.000003020587%
CPU Cycle count /sec: 100
Module memory size: 156 KB
msvcrt.dll

Total CPU: 0.000001797075%
Privileged CPU: 0.000001797075%
User CPU: 0.000000000000%
CPU Cycle count /sec: 28
Module memory size: 680 KB
ntdll.dll

Total CPU: 0.000001605888%
Privileged CPU: 0.000001198051%
User CPU: 0.000000407838%
CPU Cycle count /sec: 40
Module memory size: 1.16 MB
Process details
Runs as (owner): User
Integrety level: Medium
Windows platform: 32-bit
System Tray: Yes
Process Command
C:\Windows\Explorer.EXE
Shell open command details
Name: SHCmdFile
Command: explorer.exe
Autoplay handler details
Name: MSOpenFolder
Command: SOFTWARE\Microsoft\Windows\ CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSOpenFolder
Network connectivity
Windows Firewall allowed program: Yes
Image hashes
MD5: 4f554999d7d5f05daaebba7b5ba1089d
SHA-1: e509a42554cc0e5888ac8bf494d3c02223238609
SHA-256: 178d20aaecbd408dffda71ae4d70ad61c278229b4cd7dcd7b854a9a8404ca657
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File entropy: 6.74403
File packed: No
Import Table
advapi32.dll

RegSetValueW
RegEnumKeyExW
GetUserNameW
RegNotifyChangeKeyValue
RegEnumValueW
RegQueryValueExA
RegOpenKeyExA
RegEnumKeyW
RegCloseKey
RegCreateKeyW
RegQueryInfoKeyW
RegOpenKeyExW
RegQueryValueExW
RegCreateKeyExW
RegSetValueExW
RegDeleteValueW
RegQueryValueW
RegGetValueW
GetTraceEnableFlags
GetTraceEnableLevel
GetTraceLoggerHandle
RegisterTraceGuidsW
UnregisterTraceGuids
EventRegister
EventUnregister
EventWrite
EventEnabled
GetLengthSid
GetTokenInformation
OpenProcessToken
TraceMessage
RegOpenKeyW
ConvertStringSidToSidW
CloseServiceHandle
OpenServiceW
OpenSCManagerW
QueryServiceStatus
CreateWellKnownSid
StartServiceW
CryptAcquireContextW
CryptCreateHash
CryptHashData
CryptGetHashParam
CryptDestroyHash
CryptReleaseContext
StartTraceW
EnableTraceEx
StopTraceW
LsaLookupSids
IsValidSid
GetSidSubAuthorityCount
GetSidSubAuthority
LsaOpenPolicy
LsaFreeMemory
LsaClose
OpenThreadToken
ConvertSidToStringSidW
ConvertStringSecurityDescriptorToSecurityDescriptorW
CheckTokenMembership
RegDeleteKeyExW
dwmapi.dll

DwmEnableBlurBehindWindow
DwmIsCompositionEnabled
DwmSetWindowAttribute
DwmQueryThumbnailSourceSize
DwmUnregisterThumbnail
DwmUpdateThumbnailProperties
DwmGetColorizationColor
DwmRegisterThumbnail
gdi32.dll

GetStockObject
CreatePatternBrush
OffsetViewportOrgEx
GetLayout
CombineRgn
CreateDIBSection
GetTextExtentPoint32W
StretchBlt
CreateRectRgnIndirect
CreateRectRgn
GetClipRgn
IntersectClipRect
GetViewportOrgEx
SetViewportOrgEx
SelectClipRgn
PatBlt
GetBkColor
CreateCompatibleDC
CreateCompatibleBitmap
OffsetWindowOrgEx
DeleteDC
SetBkColor
BitBlt
ExtTextOutW
GetTextExtentPointW
GetClipBox
GetObjectW
SetTextColor
SetBkMode
CreateFontIndirectW
DeleteObject
GetTextMetricsW
SelectObject
GetDeviceCaps
TranslateCharsetInfo
SetStretchBltMode
SetWindowOrgEx
LPtoDP
Polyline
CreatePen
GetTextColor
ExtCreateRegion
GetRegionData
SetLayout
GetRgnBox
GdiFlush
OffsetRgn
SetDIBits
CreateBitmap
GdiAlphaBlend
GetPixel
CreateSolidBrush
gdiplus.dll

GdipFree
GdipAlloc
GdiplusStartup
GdiplusShutdown
GdipDeleteGraphics
GdipDisposeImage
GdipGetImageWidth
GdipGetImageHeight
GdipCreateBitmapFromHBITMAP
GdipCreateFromHDC
GdipSetCompositingMode
GdipSetInterpolationMode
GdipDrawImageRectI
GdipCloneImage
GdipCreateBitmapFromStreamICM
GdipCreateBitmapFromStream
GdipLoadImageFromFileICM
GdipLoadImageFromFile
kernel32.dll

GetSystemDirectoryW
CreateThread
CreateJobObjectW
ExitProcess
SetProcessShutdownParameters
ReleaseMutex
CreateMutexW
SetPriorityClass
GetCurrentProcess
GetStartupInfoW
GetCommandLineW
SetErrorMode
LeaveCriticalSection
EnterCriticalSection
ResetEvent
LoadLibraryExA
CompareFileTime
GetSystemTimeAsFileTime
SetThreadPriority
GetCurrentThreadId
GetThreadPriority
GetCurrentThread
GetUserDefaultLangID
Sleep
GetBinaryTypeW
GetModuleHandleExW
SystemTimeToFileTime
GetLocalTime
GetCurrentProcessId
GetEnvironmentVariableW
UnregisterWait
GlobalGetAtomNameW
GetFileAttributesW
MoveFileW
lstrcmpW
LoadLibraryExW
FindClose
FindNextFileW
FindFirstFileW
lstrcmpiA
SetEvent
AssignProcessToJobObject
GetDateFormatW
GetTimeFormatW
FlushInstructionCache
lstrcpynW
GetSystemWindowsDirectoryW
SetLastError
GetProcessHeap
HeapFree
HeapReAlloc
HeapSize
HeapAlloc
GetUserDefaultLCID
ReadProcessMemory
OpenProcess
InterlockedCompareExchange
LoadLibraryA
QueryPerformanceCounter
UnhandledExceptionFilter
SetUnhandledExceptionFilter
VirtualFree
VirtualAlloc
ResumeThread
TerminateProcess
TerminateThread
GetSystemDefaultLCID
GetLocaleInfoW
CreateEventW
GetLastError
OpenEventW
DelayLoadFailureHook
WaitForSingleObject
GetTickCount
ExpandEnvironmentStringsW
GetModuleFileNameW
GetPrivateProfileStringW
lstrcmpiW
CreateProcessW
FreeLibrary
GetWindowsDirectoryW
LocalAlloc
CreateFileW
DeviceIoControl
LocalFree
GetQueuedCompletionStatus
CreateIoCompletionPort
SetInformationJobObject
CloseHandle
LoadLibraryW
GetModuleHandleW
ActivateActCtx
DeactivateActCtx
GetFileAttributesExW
GetProcAddress
DeleteCriticalSection
CreateEventA
HeapDestroy
InitializeCriticalSection
MulDiv
InitializeCriticalSectionAndSpinCount
lstrlenW
InterlockedDecrement
InterlockedIncrement
GlobalAlloc
InterlockedExchange
GetModuleHandleA
GetVersionExA
GlobalFree
GetProcessTimes
lstrcpyW
GetLongPathNameW
RegisterWaitForSingleObject
GetFileSize
ReadFile
RaiseException
OpenThread
GetSystemTime
GetPriorityClass
SearchPathW
GetSystemDefaultUILanguage
UnmapViewOfFile
MapViewOfFile
GetTimeZoneInformation
GetDynamicTimeZoneInformation
QueryPerformanceFrequency
GetTickCount64
MultiByteToWideChar
QueueUserWorkItem
GetProductInfo
DeleteFileW
GetProcessId
CompareStringW
QueryFullProcessImageNameW
CreateFileMappingW
WideCharToMultiByte
GlobalLock
GlobalUnlock
DuplicateHandle
GetCurrentDirectoryW
WaitForMultipleObjects
GetComputerNameW
ReleaseActCtx
CreateActCtxW
FindResourceExW
LoadResource
LockResource
QueryInformationJobObject
GetUserDefaultUILanguage
HeapSetInformation
GetVersionExW
RegisterApplicationRestart
SetProcessDEPPolicy
SetTermsrvAppInstallMode
CompareStringOrdinal
GetPrivateProfileIntW
SetFilePointer
FormatMessageW
WriteFile
msvcrt.dll
ntdll.dll

RtlNtStatusToDosError
NtQueryInformationProcess
WinSqmSetString
NtSetInformationProcess
WinSqmIsOptedIn
WinSqmAddToStreamEx
NtOpenThreadToken
NtOpenProcessToken
NtSetSystemInformation
WinSqmAddToStream
WinSqmEventEnabled
EtwEventWrite
EtwEventEnabled
RtlGetProductInfo
NtClose
NtQueryInformationToken
WinSqmSetDWORD
ole32.dll

CoFreeUnusedLibraries
RegisterDragDrop
CreateBindCtx
RevokeDragDrop
CoInitializeEx
CoUninitialize
OleInitialize
CoRevokeClassObject
CoRegisterClassObject
CoMarshalInterThreadInterfaceInStream
CoCreateInstance
OleUninitialize
DoDragDrop
StringFromGUID2
CoRegisterMessageFilter
CoCreateFreeThreadedMarshaler
PropVariantClear
ReleaseStgMedium
CreateStreamOnHGlobal
CoTaskMemFree
CoGetInterfaceAndReleaseStream
CoInitialize
CoGetMalloc
CoTaskMemAlloc
CLSIDFromString
CoGetClassObject
CoGetObject
powrprof.dll

CallNtPowerInformation
GetPwrCapabilities
PowerDeterminePlatformRole
propsys.dll

PropVariantToStringAlloc
PropVariantToUInt32
PropVariantToUInt64
PropVariantToBoolean
VariantToStringAlloc
VariantToStringWithDefault
PropVariantToString
VariantToBooleanWithDefault
VariantToInt32WithDefault
PSCreateMemoryPropertyStore
PropVariantToInt64
PSGetPropertyKeyFromName
PSPropertyKeyFromString
PSGetPropertyDescription
PSGetNameFromPropertyKey
rpcrt4.dll

RpcBindingFree
RpcBindingSetAuthInfoExW
RpcStringFreeW
RpcBindingFromStringBindingW
RpcStringBindingComposeW
I_RpcExceptionFilter
NdrClientCall2
secur32.dll

shell32.dll

SHGetFolderPathW
ExtractIconExW
SHGetSpecialFolderLocation
ShellExecuteExW
SHGetSpecialFolderPathW
SHBindToParent
SHParseDisplayName
SHChangeNotify
SHGetDesktopFolder
SHAddToRecentDocs
DuplicateIcon
SHUpdateRecycleBinIcon
SHGetFolderLocation
SHGetPathFromIDListA
SHGetPathFromIDListW
SHGetPropertyStoreForWindow
SHGetStockIconInfo
Shell_GetCachedImageIndexW
SHGetLocalizedName
SHCreateDataObject
SHCreateShellItemArrayFromShellItem
SHGetKnownFolderPath
SHCreateShellItemArrayFromIDLists
SHBindToFolderIDListParentEx
SHGetFileInfoW
SHCreateItemWithParent
SHGetKnownFolderIDList
SHBindToObject
SHGetNameFromIDList
SHCreateShellItem
ShellExecuteW
SHEnableServiceObject
SHGetIDListFromObject
SHChangeNotifyRegisterThread
SHCreateItemFromIDList
SHFileOperationW
SHGetFolderPathEx
Shell_NotifyIconW
Shell_NotifyIconGetRect
SHEvaluateSystemCommandTemplate
SHCreateItemFromParsingName
DragQueryFileW
SHBindToFolderIDListParent
SHGetFolderPathAndSubDirW
shlwapi.dll

StrCpyNW
StrRetToBufW
StrRetToStrW
SHQueryValueExW
PathIsNetworkPathW
AssocCreate
StrCatW
StrCpyW
SHGetValueW
StrCmpNIW
PathRemoveBlanksW
PathRemoveArgsW
PathFindFileNameW
StrStrIW
PathGetArgsW
StrToIntW
SHRegGetBoolUSValueW
SHRegWriteUSValueW
SHRegCloseUSKey
SHRegCreateUSKeyW
SHRegGetUSValueW
SHSetValueW
PathAppendW
PathUnquoteSpacesW
PathQuoteSpacesW
SHSetThreadRef
SHCreateThreadRef
PathCombineW
SHStrDupW
PathIsPrefixW
PathParseIconLocationW
AssocQueryKeyW
AssocQueryStringW
StrCmpW
SHRegQueryUSValueW
SHRegOpenUSKeyW
SHRegSetUSValueW
PathIsDirectoryW
PathFileExistsW
PathGetDriveNumberW
StrChrW
PathFindExtensionW
PathRemoveFileSpecW
PathStripToRootW
SHOpenRegStream2W
StrDupW
SHDeleteValueW
StrCatBuffW
SHDeleteKeyW
StrCmpIW
wnsprintfW
StrCmpNW
SHStrDupA
PathCommonPrefixW
PathRemoveExtensionW
PathIsFileSpecW
StrChrIW
SHRegGetValueW
StrTrimW
SHQueryInfoKeyW
SHCreateStreamOnFileW
PathIsRootW
PathStripPathW
ChrCmpIW
PathMatchSpecW
StrPBrkW
slc.dll

SLGetWindowsInformationDWORD
user32.dll
uxtheme.dll

GetThemeBackgroundContentRect
GetThemeBool
GetThemePartSize
DrawThemeParentBackground
OpenThemeData
DrawThemeBackground
GetThemeTextExtent
DrawThemeText
CloseThemeData
SetWindowTheme
GetThemeBackgroundRegion
GetThemeMargins
GetThemeColor
GetThemeFont
GetThemeRect
IsAppThemed
BufferedPaintInit
IsCompositionActive
GetThemeMetric
GetWindowTheme
EndBufferedPaint
BeginBufferedPaint
DrawThemeTextEx
BufferedPaintUnInit
IsThemeActive
IsThemePartDefined
DrawThemeIcon
GetBufferedPaintBits
BufferedPaintClear
GetThemeBackgroundExtent
GetThemeInt