File details
File name: msimn.exe
Name: Outlook Express
Description: Microsoft® Windows® Operating System
Version: 6.00.2900.5512 (xpsp.080413-2105)
Product version: 6.00.2900.5512
Size: 59 KB
Original file name: MSIMN.EXE
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.1089604945%
Privileged CPU:
0.0272509069%

User CPU:
0.08170958755400%

Privileged CPU time: 19727.48 ms
Privileged CPU time /min: 21 ms
Context switches /sec:
24
 | Memory utilization averages |
Committed memory:
184.37 MB
Peak committed memory: 691.75 MB
Paged memory:
25.43 MB
Peak paged memory: 40.69 MB
Paged system memory:
200.39 KB
Non-paged system memory: 19.78 KB
Working set memory:
13.66 MB
Peak working set memory: 45.49 MB
Min working set memory: 8.56 MB
Private memory:
25.43 MB
Page faults:
240,149
Page faults /min: 377
 | Process I/O averages |
Total read operations:
21,961
Read operations /min: 22
Total read transfer: 36.57 MB
Read transfer /min: 71 KB
Total write operations:
1,396
Write operations /min: 2
Total write transfer: 19.33 MB
Write transfer /min: 31.39 KB
Total other operations:
112,696
Other operations /min: 152
Total other transfer: 4.6 MB
Other Transfer /min: 2.68 KB
 | GUI Object Averages |
GDI objects:
431
USER objects:
228
Resources
Handle count average: 504
Thread count average: 15
Thread resource averages
Total CPU: 1.931699130376%
Privileged CPU: 1.029118871276%
User CPU: 0.902580259099%
Context switches /sec: 12
Module memory size: 72 KB
ntdll.dll

Total CPU: 0.039344293830%
Privileged CPU: 0.016573596313%
User CPU: 0.022770697517%
Context switches /sec: 2
Module memory size: 712 KB
Total CPU: 0.031486147111%
Privileged CPU: 0.000000000000%
User CPU: 0.031486147111%
Context switches /sec: 5
Module memory size: 5.75 MB
wininet.dll

Total CPU: 0.028544243230%
Privileged CPU: 0.009514747743%
User CPU: 0.019029495487%
Context switches /sec: 9
Module memory size: 924 KB
Total CPU: 0.010172913728%
Privileged CPU: 0.004074478434%
User CPU: 0.006098435295%
Context switches /sec: 1
Module memory size: 1.29 MB
winmm.dll

Total CPU: 0.009046498565%
Privileged CPU: 0.000000000000%
User CPU: 0.009046498565%
Module memory size: 180 KB
Total CPU: 0.000624934829%
Privileged CPU: 0.000433906716%
User CPU: 0.000191028114%
Module memory size: 252 KB
wininet.dll

Total CPU: 0.000305017022%
Privileged CPU: 0.000135563121%
User CPU: 0.000169453901%
Module memory size: 920 KB
directdb.dll

Total CPU: 0.000010915885%
Privileged CPU: 0.000010915885%
User CPU: 0.000000000000%
Module memory size: 100 KB
gdiplus.dll

Total CPU: 0.000009574588%
Privileged CPU: 0.000003191529%
User CPU: 0.000006383059%
Module memory size: 1.67 MB
wininet.dll

Total CPU: 0.000006383287%
Privileged CPU: 0.000003191644%
User CPU: 0.000003191644%
Module memory size: 920 KB
wab32.dll

Total CPU: 0.000002740724%
Privileged CPU: 0.000002740724%
User CPU: 0.000000000000%
Module memory size: 516 KB
Process details
Runs as (owner): User
Integrety level: Undefined
Windows platform: 32-bit
System Tray: Yes
Parent Process
Child Process
Process Command
"C:\Program Files\Outlook Express\msimn.exe"
Shell open command details
Name: snews
Command: "C:\Program Files\Outlook Express\msimn.exe" /newsurC:"%1"
Network connectivity
TCP: server-54-240-188-38.sea50.r.cloudfront.net on port 1120
UDP: LISTENING on port 1072
UDP: LISTENING on port 1106
UDP: LISTENING on port 4068
UDP: LISTENING on port 2408
Windows Firewall allowed program: Yes
Image hashes
MD5: 1eeae496a51f017d04dd41322935d2b9
SHA-1: f7afaf8e61263e3117a762ae2f817dff9f5ccc44
SHA-256: 5c60d72118528ee01cce426a686b32f949a0153919868aaf388f32f8f6233a9c
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File entropy: 5.62607
File packed: No
Import Table
advapi32.dll

RegOpenKeyExA
RegCloseKey
RegQueryValueExA
kernel32.dll

GetVersionExA
UnhandledExceptionFilter
CloseHandle
ReleaseMutex
GetFileAttributesA
GetLastError
FreeLibrary
GetProcAddress
LoadLibraryA
lstrlenW
WaitForSingleObject
CreateMutexA
ExitProcess
GetModuleHandleA
GetStartupInfoA
SetErrorMode
GetCommandLineW
QueryPerformanceCounter
GetTickCount
GetCurrentThreadId
GetCurrentProcessId
GetSystemTimeAsFileTime
TerminateProcess
GetCurrentProcess
lstrcpynA
SetUnhandledExceptionFilter
lstrlenA
GetEnvironmentVariableA
GetModuleFileNameA
msvcrt.dll
shlwapi.dll

SHGetValueA
StrCmpIW
SHSetValueA
StrStrIA
PathRemoveFileSpecA
user32.dll

GetWindowThreadProcessId
SetForegroundWindow
SendMessageTimeoutA
LoadStringA
MessageBoxA