Parent process
Import table
EventWrite, GetTraceEnableFlags, RegQueryValueExW, EventUnregister, GetTraceLoggerHandle, TraceEvent, UnregisterTraceGuids, RegOpenKeyExW, EventRegister, GetTraceEnableLevel, RegCloseKey, RegisterTraceGuidsW
RegGetValueW, RegOpenKeyExW, EventRegister, RegCloseKey, EventUnregister, EventWrite, RegQueryValueExW
Wow64DisableWow64FsRedirection, Wow64RevertWow64FsRedirection, TerminateProcess, CreateFileW, lstrlenW, VerifyVersionInfoW, GetLastError, GetProcAddress, LocalAlloc, IsWow64Process, HeapSetInformation, GetFileTime, DeleteCriticalSection, CloseHandle, GetWindowsDirectoryW, LocalFree, ExpandEnvironmentStringsW, LoadLibraryW, GetModuleHandleW, GetCurrentProcess, VerSetConditionMask, SetDllDirectoryW, CreateProcessW, SetErrorMode, GetCommandLineW, RaiseException, LoadLibraryA, GetSystemDefaultLCID, GetUserDefaultLCID, EnterCriticalSection, GetModuleFileNameW, LeaveCriticalSection, InitializeCriticalSectionAndSpinCount, GetVersionExA, FreeLibrary, UnhandledExceptionFilter, GetSystemTimeAsFileTime, GetCurrentProcessId, GetCurrentThreadId, GetTickCount, QueryPerformanceCounter, GetModuleHandleA, SetUnhandledExceptionFilter, GetStartupInfoW, InterlockedCompareExchange, Sleep, InterlockedExchange, GetCurrentDirectoryW, InitializeCriticalSection, GetVersionExW, SetLastError, SearchPathW, GetUserDefaultUILanguage, GetSystemDefaultUILanguage, UnmapViewOfFile, GetLocaleInfoW, CreateFileMappingW, MapViewOfFile, LoadLibraryExW, LoadResource, FindResourceExW, ReleaseMutex, LoadLibraryExA, SetProcessDEPPolicy, VirtualAlloc, GetNativeSystemInfo, CreateMutexW, WaitForSingleObject, WaitForSingleObjectEx, CreateEventW, FindResourceW
CoUninitialize, CoInitialize
SHGetValueW, SHRegGetValueW, SHSetValueW, UrlApplySchemeW, PathIsURLW, UrlCanonicalizeW, PathFindFileNameW, UrlCreateFromPathW, StrStrW, PathCombineW, PathRemoveFileSpecW, PathAppendW, PathQuoteSpacesW, SHEnumValueW
IsWindowEnabled, LoadStringW, CharNextW, GetWindowThreadProcessId, SendMessageTimeoutW, FindWindowExW, MessageBoxW, IsWindowVisible, AllowSetForegroundWindow, GetThreadDesktop, GetUserObjectInformationW


Windows Internet Explorer by Microsoft Corporation (Signed)

Version:   9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)
MD5:   45bda923be52906d1460bcb13ac2ab7a
SHA1:   56476be42cd568f950ff4cf73f25d1e2d67c9483
SHA256:   44040c37875864f5d7499269ea29b21f5c45f852c06a6adca68c8275a9cad5e0
This is a Windows system installed file with Windows File Protection (WFP) enabled.

What is iexplore.exe?

IExplore.exe is at the top level, and is the Internet Explorer executable. It is a small application that relies on the other main components of Internet Explorer to do the work of rendering, navigation, protocol implementation, and so on.

About iexplore.exe (from Microsoft Corporation)

Internet Explorer harnesses the untapped power of your PC, delivering pages full of vivid graphics, smoother video, and interactive content. Experience the web the way you want to with a cleaner look


File name:iexplore.exe
Publisher:Microsoft Corporation
Product name:Windows® Internet Explorer
Description:Internet Explorer
Typical file path:C:\Program Files\internet explorer\iexplore.exe
Original name:IEXPLORE.EXE.MUI
File version:9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)
Product version:9.00.8112.16421
Size:739.65 KB (757,400 bytes)
Build date:9/22/2013 12:11 PM
Issued to:Microsoft Corporation
Authority (CA):Microsoft Corporation
Effective date:Monday, July 19, 2010
Expiration date:Wednesday, October 19, 2011
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++
The following programs will install this file
Microsoft Corporation
5% remove
Windows IE8 (Internet Explorer 8) is a web browser from Microsoft. IE8 contains many new features, including WebSlices and Accelerators (Accelerators are a form of selection-based search which allow a user to invoke an online service from any other page using only the mouse). The address bar features domain highlighting for added security so that the top-level domain is shown in black whereas the other parts of the URL are grayed out. I...
Microsoft Corporation
1% remove
Internet Explorer 7 has been designed to make everyday tasks easier, provide dynamic security protection and improve the development platform and manageability. End user improvements include a streamlined interface, tabbed browsing, printing advances, improved search functionality, instant feeds (RSS), dynamic security protection, and more.


Shell open commands
  • InternetShortcut
  • gopher
  • xmlfile
  • https
  • http
  • ftp
  • mhtmlfile
  • htmlfile
  • giffile
Scheduled tasks
  • The task '{28A27677-1781-49A8-B133-EB46963B3733}' runs on registration in the path '\{28A27677-1781-49A8-B133-EB46963B3733}'
  • The job '{6A41DE04-F86E-4812-8E56-D7C304AFA991}' runs on registration in the path '\{6A41DE04-F86E-4812-8E56-D7C304AFA991}'
  • The task '{C48C9DC5-E815-40AF-B6EE-0E171DE3D38C}' runs on registration in the path '\{C48C9DC5-E815-40AF-B6EE-0E171DE3D38C}'
  • The task '{FE6FFAEC-6178-4BB5-B843-5F732950078D}' runs on registration in the path '\{FE6FFAEC-6178-4BB5-B843-5F732950078D}'
  • The task '{16F5D73B-1343-4432-A594-D7826D3FEF09}' runs on registration in the path '\{16F5D73B-1343-4432-A594-D7826D3FEF09}'
  • The task '{EE54F59E-E85E-43EC-AE55-959F40FD02E5}' runs on registration in the path '\{EE54F59E-E85E-43EC-AE55-959F40FD02E5}'
  • The job '{DB5B152C-A89D-4C18-83DB-9C930BE954DE}' runs on registration in the path '\{DB5B152C-A89D-4C18-83DB-9C930BE954DE}'
  • The job '{BD7348E0-7711-4DBB-BDD7-8515854EA1BD}' runs on registration in the path '\{BD7348E0-7711-4DBB-BDD7-8515854EA1BD}'
  • The task '{9C1F91B7-4B2F-44BC-A0C5-C3A3414126A2}' runs on registration in the path '\{9C1F91B7-4B2F-44BC-A0C5-C3A3414126A2}'
  • The task '{982CB9F0-92FC-44BF-B041-4263CC9171E8}' runs on registration in the path '\{982CB9F0-92FC-44BF-B041-4263CC9171E8}'
  • The job '{6601423E-9F04-4B05-A02A-22A7D5A8EA35}' runs on registration in the path '\{6601423E-9F04-4B05-A02A-22A7D5A8EA35}'
  • The task '{098EC717-A53A-49E9-9370-690CE169048A}' runs on registration in the path '\{098EC717-A53A-49E9-9370-690CE169048A}'
  • The task '{FF83A9C5-07BD-4AEB-B214-2016EB76E77E}' runs on registration in the path '\{FF83A9C5-07BD-4AEB-B214-2016EB76E77E}'
  • The job '{D29708AF-17A8-405B-9C8D-5ABE0B01EBE7}' runs on registration in the path '\{D29708AF-17A8-405B-9C8D-5ABE0B01EBE7}'
  • The job '{5F70B5BD-3E5F-48B3-9B48-989F1E28D0C6}' runs on registration in the path '\{5F70B5BD-3E5F-48B3-9B48-989F1E28D0C6}'
  • The job '{BA44AC86-B7CB-4065-B78E-4D080AD2166B}' runs on registration in the path '\{BA44AC86-B7CB-4065-B78E-4D080AD2166B}'
  • The task '{07FA7E58-4DD1-4A40-A77D-A9FE91ACA8EC}' runs on registration in the path '\{07FA7E58-4DD1-4A40-A77D-A9FE91ACA8EC}'
  • The job '{FDF80C9A-2116-4EAE-9E9C-C743606B60F0}' runs on registration in the path '\{FDF80C9A-2116-4EAE-9E9C-C743606B60F0}'
  • The task '{B9524566-4DAF-4E69-97F5-3CC1807F84E6}' runs on registration in the path '\{B9524566-4DAF-4E69-97F5-3CC1807F84E6}'
  • The task '{FDDB66ED-3880-47D1-B567-ECAB9EE621F6}' runs on registration in the path '\{FDDB66ED-3880-47D1-B567-ECAB9EE621F6}'
  • The job '{A7D7A5C7-B134-48E8-B39B-239493C43AD8}' runs on registration in the path '\{A7D7A5C7-B134-48E8-B39B-239493C43AD8}'
  • The task '{3D313F7A-B0C7-4AE8-94B6-73C969AB8F8C}' runs on registration in the path '\{3D313F7A-B0C7-4AE8-94B6-73C969AB8F8C}'
Windows firewall allowed programs
Exceptions allow programs to access to the Internet through an outbound connections
  • Firewall exception for 'C:\Program Files\Internet Explorer\IEXPLORE.EXE'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Total CPU:0.10158112%
Kernel CPU:0.06133997%
User CPU:0.04024114%
Kernel CPU time:1,688 ms/min
Private memory:55.88 MB
21.59 MB
Private (maximum):42.46 MB
Private (minimum):27.24 MB
Non-paged memory:55.88 MB
21.59 MB
Virtual memory:229.81 MB
140.96 MB
Virtual memory (peak):237.58 MB
169.69 MB
Working set:27.33 MB
18.61 MB
Working set (peak):47.57 MB
37.95 MB
Resource allocations
GUI GDI count:137
GUI GDI peak:144
GUI USER count:69
GUI USER peak:80

BehaviorsProcess properties

Integrety level:High
Command lines:
  • "C:\Program Files\internet explorer\iexplore.exe" scodeC:2916 credaC:145409
  • "C:\Program Files\internet explorer\iexplore.exe" httC://
Parent processes:


ieframe.dll (Windows Internet Explorer by Microsoft)
Total CPU:0.09807212%
Kernel CPU:0.03448443%
User CPU:0.06358769%
CPU cycles:8,043,034/sec
Context switches:54/sec
Memory:9.3 MB
1.16 MB
iexplore.exe (main module)
Total CPU:0.07452368%
Kernel CPU:0.05230666%
User CPU:0.02221703%
CPU cycles:3,388,832/sec
Context switches:7/sec
Memory:736 KB
Total CPU:0.01606769%
Kernel CPU:0.00803385%
User CPU:0.00803385%
CPU cycles:307,024/sec
Memory:1.23 MB
Total CPU:0.00265237%
Kernel CPU:0.00265237%
User CPU:0.00000000%
CPU cycles:52,096/sec
Memory:1.72 MB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 39.00%
Windows 8.1 Pro 14.50%
Windows 8.1 11.00%
Windows 8 10.00%
Windows 7 Ultimate 9.00%
Windows 8.1 Single Language 5.00%
Windows 7 Professional 4.50%
Windows 8 Single Language 2.50%
Windows 8.1 Pro with Media Center 2.00%
Windows 8.1 N 2.00%
Windows Seven Black Edition 0.50%

Distribution by countryDistribution by country

United States installs about 58.00% of Windows® Internet Explorer.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Hewlett-Packard 25.96%
ASUS 24.68%
Dell 13.62%
Acer 12.77%
Toshiba 10.21%
Samsung 5.96%
Lenovo 5.11%
Alienware 1.70%
