File details
File name: iexplore.exe
Name: Windows® Internet Explorer
Description: Internet Explorer
Version: 9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)
Product version: 9.00.8112.16421
Size: 739.53 KB
Original file name: IEXPLORE.EXE.MUI
Windows file protection:
Yes
Digital certificate
Certificate authority:
Microsoft Corporation
Effective date: 7/19/2010
Expiration date: 10/19/2011
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0604338416%
Privileged CPU:
0.0309840452%

User CPU:
0.02944979639988%

Privileged CPU time: 110332233.86 ms
Privileged CPU time /min: 677 ms
CPU cycle count:
375,591,971
CPU cycle count /min: 246,152,380
Context switches /sec:
244
 | Memory utilization averages |
Committed memory:
418.15 MB
Peak committed memory: 484.39 MB
Paged memory:
132.44 MB
Peak paged memory: 162.06 MB
Paged system memory:
453.41 KB
Non-paged system memory: 85.21 KB
Working set memory:
118.83 MB
Peak working set memory: 164.13 MB
Min working set memory: 57.46 MB
Private memory:
132.44 MB
Page faults:
8,538,634
Page faults /min: 8,565
 | Process I/O averages |
Total read operations:
159,465
Read operations /min: 1,022
Total read transfer: 65.6 MB
Read transfer /min: 4.09 MB
Total write operations:
16,481
Write operations /min: 554
Total write transfer: 39.35 MB
Write transfer /min: 1.76 MB
Total other operations:
680,063
Other operations /min: 4,756
Total other transfer: 26.01 MB
Other Transfer /min: 148.38 KB
 | GUI Object Averages |
GDI objects:
230
Peak GDI objects: 327
USER objects:
126
Peak USER objects: 182
Resources
Handle count average: 1,186
Thread count average: 36
Thread resource averages
Total CPU: 1.225806880694%
Privileged CPU: 0.702588119112%
User CPU: 0.523218761582%
CPU Cycle count /sec: 33,547,322
Module memory size: 36 KB
Total CPU: 0.853967754829%
Privileged CPU: 0.148583356934%
User CPU: 0.705384397895%
CPU Cycle count /sec: 18,476,879
Context switches /sec: 7
Module memory size: 9.3 MB
Total CPU: 0.405582539174%
Privileged CPU: 0.064863467024%
User CPU: 0.340719072150%
CPU Cycle count /sec: 11,592,731
Context switches /sec: 13
Module memory size: 736 KB
ntdll.dll

Total CPU: 0.193951826042%
Privileged CPU: 0.026887628082%
User CPU: 0.167064197959%
CPU Cycle count /sec: 4,381,340
Context switches /sec: 2
Module memory size: 1.23 MB
ntdll.dll

Total CPU: 0.132482631746%
Privileged CPU: 0.031409420743%
User CPU: 0.101073211004%
CPU Cycle count /sec: 3,445,457
Context switches /sec: 7
Module memory size: 1.66 MB
ntdll.dll

Total CPU: 0.091058781755%
Privileged CPU: 0.076197128670%
User CPU: 0.014861653084%
CPU Cycle count /sec: 1,896,043
Module memory size: 1.16 MB
ntdll.dll

Total CPU: 0.080343043121%
Privileged CPU: 0.040361557224%
User CPU: 0.039981485897%
CPU Cycle count /sec: 1,091,256
Context switches /sec: 6
Module memory size: 1.23 MB
rpcrt4.dll

Total CPU: 0.078516891950%
Privileged CPU: 0.078516891950%
User CPU: 0.000000000000%
CPU Cycle count /sec: 437,283
Module memory size: 780 KB
ntdll.dll

Total CPU: 0.065461481081%
Privileged CPU: 0.044231878496%
User CPU: 0.021229602586%
CPU Cycle count /sec: 1,475,051
Context switches /sec: 1
Module memory size: 1.23 MB
ntdll.dll

Total CPU: 0.048675323497%
Privileged CPU: 0.032192523689%
User CPU: 0.016482799807%
CPU Cycle count /sec: 1,584,745
Module memory size: 1.52 MB
iertutil.dll

Total CPU: 0.021274935749%
Privileged CPU: 0.005318081004%
User CPU: 0.015956854745%
CPU Cycle count /sec: 344,644
Module memory size: 1.72 MB
Total CPU: 0.015212181428%
Privileged CPU: 0.005813548142%
User CPU: 0.009398633286%
CPU Cycle count /sec: 439,213
Context switches /sec: 2
Module memory size: 252 KB
wow64.dll

Total CPU: 0.014926587567%
Privileged CPU: 0.014480054711%
User CPU: 0.000446532857%
CPU Cycle count /sec: 324,238
Module memory size: 276 KB
iertutil.dll

Total CPU: 0.010787419296%
Privileged CPU: 0.005273761338%
User CPU: 0.005513657958%
CPU Cycle count /sec: 221,679
Context switches /sec: 1
Module memory size: 1.72 MB
Total CPU: 0.007736724907%
Privileged CPU: 0.004835453067%
User CPU: 0.002901271840%
CPU Cycle count /sec: 1,013,534
Module memory size: 1.16 MB
ole32.dll

Total CPU: 0.004412828743%
Privileged CPU: 0.002206414372%
User CPU: 0.002206414372%
CPU Cycle count /sec: 39,333
Module memory size: 1.36 MB
Total CPU: 0.003708904645%
Privileged CPU: 0.002662802220%
User CPU: 0.001046102425%
CPU Cycle count /sec: 594,026
Context switches /sec: 15
Module memory size: 352 KB
ole32.dll

Total CPU: 0.001006900325%
Privileged CPU: 0.001006900325%
User CPU: 0.000000000000%
CPU Cycle count /sec: 11,086
Module memory size: 1.27 MB
msvcr80.dll

Total CPU: 0.000542449940%
Privileged CPU: 0.000221262475%
User CPU: 0.000321187465%
CPU Cycle count /sec: 3,676,448
Context switches /sec: 270
Module memory size: 620 KB
wininet.dll

Total CPU: 0.000481223953%
Privileged CPU: 0.000041062554%
User CPU: 0.000440161399%
CPU Cycle count /sec: 27,316
Module memory size: 1.11 MB
Process details
Runs as (owner): User
Integrety level: Medium
Windows platform: 64-bit
Parent Processes
Child Processes
Process Commands
"C:\Program Files\Internet Explorer\iexplore.exe"
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEC:4680 CREDAC:596225
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEC:4680 CREDAC:465153
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEC:10176 CREDAC:203009
"C:\Program Files\Internet Explorer\iexplore.exe"
Shell open command details
Name: gopher
Command: "C:\Program Files\Internet Explorer\iexplore.exe" -nohome
Scheduled task details
CLSID: {DC7ABF42-D45A-4D97-B5A3-E1981D317C8A}
Command: \{DC7ABF42-D45A-4D97-B5A3-E1981D317C8A}
Image hashes
MD5: 698eb1e5f8c66344d97c00b5699e871d
SHA-1: fd9385213a4ee6763428cb426bd9a048c88caeed
SHA-256: 597a81e7f7366e282f3e93cfca6c48d5cec435c60695153fe537ba9d5b9e3280
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File entropy: 6.58338
File packed: No
Import Table
advapi32.dll

EventWrite
GetTraceEnableFlags
RegQueryValueExW
EventUnregister
GetTraceLoggerHandle
TraceEvent
UnregisterTraceGuids
RegOpenKeyExW
EventRegister
GetTraceEnableLevel
RegCloseKey
RegisterTraceGuidsW
api-ms-win-downlevel-advapi32-l1-1-0.dll

RegGetValueW
RegOpenKeyExW
EventRegister
RegCloseKey
EventUnregister
EventWrite
RegQueryValueExW
api-ms-win-downlevel-shlwapi-l1-1-0.dll

kernel32.dll

Wow64DisableWow64FsRedirection
Wow64RevertWow64FsRedirection
TerminateProcess
CreateFileW
lstrlenW
VerifyVersionInfoW
GetLastError
GetProcAddress
LocalAlloc
IsWow64Process
HeapSetInformation
GetFileTime
DeleteCriticalSection
CloseHandle
GetWindowsDirectoryW
LocalFree
ExpandEnvironmentStringsW
LoadLibraryW
GetModuleHandleW
GetCurrentProcess
VerSetConditionMask
SetDllDirectoryW
CreateProcessW
SetErrorMode
GetCommandLineW
RaiseException
LoadLibraryA
GetSystemDefaultLCID
GetUserDefaultLCID
EnterCriticalSection
GetModuleFileNameW
LeaveCriticalSection
InitializeCriticalSectionAndSpinCount
GetVersionExA
FreeLibrary
UnhandledExceptionFilter
GetSystemTimeAsFileTime
GetCurrentProcessId
GetCurrentThreadId
GetTickCount
QueryPerformanceCounter
GetModuleHandleA
SetUnhandledExceptionFilter
GetStartupInfoW
InterlockedCompareExchange
Sleep
InterlockedExchange
GetCurrentDirectoryW
InitializeCriticalSection
GetVersionExW
SetLastError
SearchPathW
GetUserDefaultUILanguage
GetSystemDefaultUILanguage
UnmapViewOfFile
GetLocaleInfoW
CreateFileMappingW
MapViewOfFile
LoadLibraryExW
LoadResource
FindResourceExW
ReleaseMutex
LoadLibraryExA
SetProcessDEPPolicy
VirtualAlloc
GetNativeSystemInfo
msvcrt.dll
ntdll.dll

ole32.dll

CoUninitialize
CoInitialize
shell32.dll

shlwapi.dll

SHGetValueW
SHRegGetValueW
SHSetValueW
UrlApplySchemeW
PathIsURLW
UrlCanonicalizeW
PathFindFileNameW
UrlCreateFromPathW
StrStrW
PathCombineW
PathRemoveFileSpecW
PathAppendW
PathQuoteSpacesW
SHEnumValueW
user32.dll

IsWindowEnabled
LoadStringW
CharNextW
GetWindowThreadProcessId
SendMessageTimeoutW
FindWindowExW
MessageBoxW
IsWindowVisible
AllowSetForegroundWindow