File details
File name: MSASCui.exe
Name: Windows Defender
Description: Windows Defender User Interface
Version: 1.1.1600.0
Size: 984.55 KB
Original file name: MSASCUI.exe
Digital certificate
Certificate authority:
Microsoft Corporation
Effective date: 4/4/2006
Expiration date: 10/4/2007
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0041016317%
Privileged CPU:
0.0023021481%

User CPU:
0.00179948357715%

Total CPU time: 14 ms
Total CPU time /min: 0 ms
Privileged CPU time: 1635023.03 ms
Privileged CPU time /min: 340 ms
User CPU time: 5.21 ms
User CPU time /min: 0 ms
CPU cycle count:
1,377,003
CPU cycle count /min: 161,104,224
 | Memory utilization averages |
Committed memory:
96.56 MB
Peak committed memory: 99.19 MB
Paged memory:
7.29 MB
Peak paged memory: 7.58 MB
Paged system memory:
163.98 KB
Non-paged system memory: 12.01 KB
Working set memory:
6.53 MB
Peak working set memory: 9.99 MB
Min working set memory: 4.6 MB
Private memory:
7.29 MB
Page faults:
9,326
Page faults /min: 338
 | Process I/O averages |
Total read operations:
18
Read operations /min: 2
Total read transfer: 6.14 KB
Read transfer /min: 104 Bytes
Total write operations:
20
Write operations /min: 2
Total write transfer: 2.57 KB
Write transfer /min: 94 Bytes
Total other operations:
4,480
Other operations /min: 56
Total other transfer: 128.36 KB
Other Transfer /min: 1.52 KB
 | GUI Object Averages |
GDI objects:
130
USER objects:
126
Resources
Handle count average: 365
Thread count average: 11
Thread resource averages
Total CPU: 0.057174119740%
Privileged CPU: 0.013993574020%
User CPU: 0.043180545721%
CPU Cycle count /sec: 1,416,225
Context switches /sec: 6
Module memory size: 996 KB
ntdll.dll

Total CPU: 0.011011871277%
Privileged CPU: 0.002941494626%
User CPU: 0.008070376651%
CPU Cycle count /sec: 256,790
Module memory size: 1.16 MB
mpclient.dll

Total CPU: 0.008117630723%
Privileged CPU: 0.003466061554%
User CPU: 0.004651569169%
CPU Cycle count /sec: 180,325
Context switches /sec: 3
Module memory size: 308 KB
rpcrt4.dll

Total CPU: 0.002649916636%
Privileged CPU: 0.001639148035%
User CPU: 0.001010768601%
CPU Cycle count /sec: 66,711
Context switches /sec: 2
Module memory size: 780 KB
ntdll.dll

Total CPU: 0.001579189832%
Privileged CPU: 0.000702904678%
User CPU: 0.000876285154%
CPU Cycle count /sec: 36,271
Module memory size: 1.16 MB
rpcrt4.dll

Total CPU: 0.000278222257%
Privileged CPU: 0.000176507856%
User CPU: 0.000101714402%
CPU Cycle count /sec: 7,679
Module memory size: 776 KB
rpcrt4.dll

Total CPU: 0.000206129949%
Privileged CPU: 0.000044170703%
User CPU: 0.000161959246%
CPU Cycle count /sec: 2,955
Module memory size: 776 KB
gdiplus.dll

Total CPU: 0.000136681920%
Privileged CPU: 0.000094762302%
User CPU: 0.000041919618%
CPU Cycle count /sec: 500
Module memory size: 1.67 MB
ntdll.dll

Total CPU: 0.000084324367%
Privileged CPU: 0.000025239947%
User CPU: 0.000059084421%
CPU Cycle count /sec: 1,468
Module memory size: 1.16 MB
mprtmon.dll

Total CPU: 0.000023878863%
Privileged CPU: 0.000023251513%
User CPU: 0.000000627351%
CPU Cycle count /sec: 471
Module memory size: 668 KB
gdiplus.dll

Total CPU: 0.000012619177%
Privileged CPU: 0.000008030385%
User CPU: 0.000004588792%
CPU Cycle count /sec: 183
Module memory size: 1.67 MB
gdiplus.dll

Total CPU: 0.000011986849%
Privileged CPU: 0.000011986849%
User CPU: 0.000000000000%
CPU Cycle count /sec: 170
Module memory size: 1.67 MB
Process details
Runs as (owner): User
Integrety level: Medium
Windows platform: 32-bit
System Tray: Yes
Parent Processes
Process Commands
"C:\Program Files\Windows Defender\MSASCui.exe" -hide
"C:\Program Files\Windows Defender\MSASCui.exe" -Hide
Startup files (all users) run details
Name: Windows Defender User Interface
Command: "C:\Program Files\Windows Defender\MSASCui.exe" -hide
Image hashes
MD5: 0d392ede3b97e0b3131b2f63ef1db94e
SHA-1: e92253719e1b71920add22992d32c9f02705dfdc
SHA-256: 3eda280f91097293e00bf984d377e1111cfde1fc81b30a3fdeb38f321ef82bb6
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++ 8.0
File entropy: 6.32243
File packed: No
Import Table
advapi32.dll

TraceEvent
OpenProcessToken
LookupPrivilegeValueW
AdjustTokenPrivileges
UnregisterTraceGuids
RegisterTraceGuidsW
RegCreateKeyExW
RegSetValueExW
RegCloseKey
RegOpenKeyExW
RegQueryValueExW
OpenThreadToken
GetLengthSid
GetTokenInformation
ConvertSidToStringSidW
LookupAccountSidW
RegOpenKeyW
CryptReleaseContext
CryptDestroyHash
CryptGetHashParam
CryptHashData
CryptCreateHash
CryptGenRandom
CryptAcquireContextW
GetTraceEnableFlags
GetTraceEnableLevel
GetTraceLoggerHandle
comctl32.dll

ImageList_Create
ImageList_ReplaceIcon
ImageList_LoadImageW
ImageList_Destroy
InitCommonControlsEx
HIMAGELIST_QueryInterface
gdi32.dll

GetTextExtentPoint32W
CreateCompatibleDC
CreateBitmap
BitBlt
SetBkMode
GetTextExtentPointW
GetTextColor
GetCurrentObject
SaveDC
SetGraphicsMode
ModifyWorldTransform
SetViewportOrgEx
SetWindowOrgEx
GetDeviceCaps
DPtoLP
GetTextMetricsW
RestoreDC
GetStockObject
GetObjectA
GetLayout
SetLayout
CreateSolidBrush
SetTextColor
GetObjectW
DeleteObject
CreateFontIndirectW
SelectObject
CreatePatternBrush
PatBlt
DeleteDC
CreateCompatibleBitmap
GetPixel
LineTo
MoveToEx
CreatePen
SetBkColor
ExtTextOutW
CreateDIBSection
gdiplus.dll

GdipAddPathLineI
GdipClosePathFigure
GdipCreateLineBrushFromRect
GdipCreateHICONFromBitmap
GdipImageRotateFlip
GdipGetImagePixelFormat
GdipReleaseDC
GdipGetDC
GdipDrawRectangleI
GdipDrawPath
GdipDrawImageRectRectI
GdipFillPath
GdipGetSmoothingMode
GdipDeletePath
GdipCreatePath
GdipAddPathArcI
GdipLoadImageFromStream
GdipSetSmoothingMode
GdipCloneBrush
GdipDeletePen
GdipCreateFontFromDC
GdipDrawImageRectI
GdipMeasureString
GdipDrawString
GdipFillRectangleI
GdipDrawLineI
GdipSetTextRenderingHint
GdipCreateFromHDC
GdipCreateLineBrushFromRectI
GdipCreateSolidFill
GdipGetImageHeight
GdipGetImageWidth
GdipDeleteFont
GdipDeleteGraphics
GdipDeleteStringFormat
GdipCreateStringFormat
GdipFillRectangle
GdipCloneBitmapAreaI
GdiplusStartup
GdipCreatePen1
GdipDeleteBrush
GdiplusShutdown
GdipCloneImage
GdipCreateBitmapFromStreamICM
GdipCreateBitmapFromStream
GdipDisposeImage
GdipAlloc
GdipFree
GdipLoadImageFromStreamICM
GdipCreateFontFromLogfontA
kernel32.dll

CreateThread
GetCurrentThread
WaitForMultipleObjects
QueueUserWorkItem
ReleaseMutex
OpenMutexW
MultiByteToWideChar
GetSystemInfo
GetSystemDefaultLCID
GetFileTime
GetFileSizeEx
CreateFileW
SystemTimeToFileTime
GetSystemTime
WideCharToMultiByte
SetEndOfFile
WriteFile
SetFilePointerEx
GlobalFree
InterlockedExchange
RaiseException
EnterCriticalSection
LeaveCriticalSection
FlushInstructionCache
GetCurrentProcess
InterlockedIncrement
InterlockedDecrement
GetCurrentThreadId
SetLastError
LocalFree
LocalAlloc
InitializeCriticalSection
DeleteCriticalSection
CloseHandle
GetLastError
CreateMutexW
LockResource
LoadResource
FindResourceW
FileTimeToLocalFileTime
GetSystemTimeAsFileTime
FindClose
FindNextFileW
SizeofResource
FindResourceExW
GetDriveTypeW
GetLogicalDriveStringsW
FindFirstFileW
SetErrorMode
lstrlenW
MulDiv
lstrcmpW
InterlockedCompareExchange
GetProcAddress
GetModuleHandleW
SetProcessWorkingSetSize
GetLocalTime
GetLocaleInfoW
FileTimeToSystemTime
GetDateFormatW
GetUserDefaultUILanguage
GetTimeFormatW
FreeLibrary
LoadLibraryW
FormatMessageW
GetVersionExW
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
Sleep
GetStartupInfoW
HeapFree
GetProcessHeap
HeapAlloc
LoadLibraryA
IsProcessorFeaturePresent
VirtualFree
VirtualAlloc
GetVersionExA
HeapDestroy
HeapReAlloc
HeapSize
DeleteFileW
CreateProcessW
CreateDirectoryW
ExpandEnvironmentStringsW
GetFileSize
ReadFile
ResetEvent
LCMapStringW
GetSystemDirectoryW
GetFileAttributesW
WaitForSingleObject
SetEvent
CreateEventW
InitializeCriticalSectionAndSpinCount
TryEnterCriticalSection
CompareFileTime
RegisterApplicationRestart
OutputDebugStringA
GetModuleHandleA
mpclient.dll

MpScanOpen
MpScanResult
MpRegisterEventNotification
MpScanCancel
MpScan
MpScanThreatEnum
MpScanThreatOpen
MpScanHistoryEnum
MpScanHistoryOpen
MpConfigUnregisterNotifications
MpConfigRegisterForNotifications
MpElevationHandleClose
MpElevationHandleAttach
MpCleanThreats
MpCleanSetAction
MpCleanOpen
MpCleanPreCheck
MpConfigIteratorClose
MpConfigIteratorEnum
MpConfigIteratorOpen
MpClientUtilExportFunctions
MpConfigInitialize
MpConfigUninitialize
MpFreeMemory
MpConfigGetValue
MpConfigGetValueAlloc
MpConfigClose
MpConfigOpen
MpFormatVErrorMessage
MpClose
MpOpen
MpAllocMemory
MpConfigSetValue
MpConfigDelValue
MpUnregisterEventNotification
MpScanClose
MpScanThreatClose
MpScanHistoryClose
MpCleanClose
MpQuarantineClose
MpQuarantineQuery
MpQuarantineEnum
MpQuarantineOpen
MpGetThreatLocalizedInfo
MpGetThreatStaticInfo
MpSignaturesUpdateClose
MpSignaturesUpdateCancel
MpDownloadAndUpdateSignaturesEx
MpScanCreateReport
mprtmon.dll

MpGetRealtimeManager
MpShutdownRealtimeMonitoring
MpInitializeRealtimeMonitoring
MpConstructCDetections
MpConstructOnDemandDetection
msmpres.dll

msvcp80.dll
msvcr80.dll
msvcrt.dll
netapi32.dll

NetGetJoinInformation
NetApiBufferFree
ole32.dll

CoCreateGuid
OleRun
CoTaskMemFree
CoCreateInstance
StringFromGUID2
CoInitialize
CoUninitialize
CoInitializeEx
CoGetObject
oleacc.dll

LresultFromObject
AccessibleObjectFromWindow
rpcrt4.dll

shell32.dll

SHGetFileInfoW
Shell_NotifyIconW
ShellExecuteExW
SHGetPathFromIDListW
SHBrowseForFolderW
SHGetFolderLocation
SHGetFolderPathW
shlwapi.dll

StrCmpNW
StrDupW
StrStrIW
StrStrW
StrChrW
StrCmpNIW
StrCmpIW
urlmon.dll

user32.dll

GetDC
ReleaseDC
SetWindowPos
GetWindow
SetTimer
DrawTextW
GetWindowTextLengthW
GetWindowTextW
AllowSetForegroundWindow
FindWindowExW
LoadIconW
GetDesktopWindow
LoadAcceleratorsW
SystemParametersInfoW
TrackMouseEvent
CallWindowProcW
IsRectEmpty
PostMessageW
GetParent
IsWindowEnabled
InvalidateRect
EndPaint
BeginPaint
GetWindowRect
GetWindowLongW
GetDlgCtrlID
DestroyMenu
TrackPopupMenu
TranslateAcceleratorW
IsDialogMessageW
TranslateMessage
DispatchMessageW
DestroyIcon
IsWindow
CharUpperW
MapWindowPoints
UnregisterClassA
MessageBoxW
CopyIcon
IsMenu
GetClassNameW
GetIconInfo
DrawIconEx
CreateIconIndirect
GetAncestor
GetCapture
GetMessagePos
DrawEdge
GetWindowDC
ReleaseCapture
SetCapture
SetRectEmpty
InflateRect
SetScrollInfo
GetScrollInfo
SetScrollPos
ScrollWindowEx
ScrollWindow
GetScrollPos
GetSystemMetrics
DrawIcon
ShowCursor
GetSysColorBrush
GetDoubleClickTime
MessageBeep
RegisterWindowMessageW
CreatePopupMenu
AppendMenuW
SetForegroundWindow
ExitWindowsEx
KillTimer
GetMessageW
EnableMenuItem
GetSubMenu
LoadMenuW
DialogBoxIndirectParamW
RegisterClassExW
DefWindowProcW
GetSysColor
CheckMenuItem
LoadCursorW
GetClassInfoExW
GetDlgItem
SetDlgItemTextW
GetClientRect
MoveWindow
CharNextW
DestroyWindow
SetWindowTextW
SendMessageW
CreateWindowExW
SetWindowLongW
EndDialog
SetFocus
LockWindowUpdate
ScreenToClient
GetWindowPlacement
GetNextDlgTabItem
PostQuitMessage
RegisterClassW
UnregisterClassW
RedrawWindow
IsChild
IsWindowVisible
GetFocus
DrawFocusRect
EqualRect
SetRect
LoadStringW
IsCharAlphaNumericW
CopyRect
GetKeyState
PtInRect
OffsetRect
SetCursor
GetCursorPos
EnableWindow
ShowWindow
FillRect
GetLastActivePopup
LoadImageW
SetMenuInfo
SetMenuItemInfoW
version.dll

GetFileVersionInfoSizeW
GetFileVersionInfoW
VerQueryValueW
winhttp.dll

WinHttpOpenRequest
WinHttpGetIEProxyConfigForCurrentUser
WinHttpGetProxyForUrl
WinHttpAddRequestHeaders
WinHttpWriteData
WinHttpQueryHeaders
WinHttpReceiveResponse
WinHttpConnect
WinHttpSetTimeouts
WinHttpCrackUrl
WinHttpSetOption
WinHttpSetStatusCallback
WinHttpQueryOption
WinHttpCloseHandle
WinHttpOpen
WinHttpReadData
WinHttpQueryDataAvailable
WinHttpSendRequest