Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.00.3790.3959 (srv03_sp2_rtm.070216-1710) 0.09%
6.00.3790.3959 (srv03_sp2_rtm.070216-1710) 0.45%
6.00.2900.5512 (xpsp.080413-2105) 67.21%
6.00.2900.5512 (xpsp.080413-2105) 0.63%
6.00.2900.5512 (xpsp.080413-2105) 0.36%
6.00.2900.5512 (xpsp.080413-2105) 0.82%
6.00.2900.5512 (xpsp.080413-2105) 0.09%
6.00.2900.5512 (xpsp.080413-2105) 0.09%
6.00.2900.5512 (xpsp.080413-2105) 0.63%
6.00.2900.5512 (xpsp.080413-2105) 0.09%
6.00.2900.5512 (xpsp.080413-2105) 0.09%
6.00.2900.5512 (xpsp.080413-2105) 0.09%
6.00.2900.5512 (xpsp.080413-2105) 0.09%
6.00.2900.5512 (xpsp.080413-2105) 0.09%
6.00.2900.5512 (xpsp.080413-2105) 0.09%
6.00.2900.5512 (xpsp.080413-2105) 2.08%
6.00.2900.5512 (xpsp.080413-2105) 0.45%
6.00.2900.5512 (xpsp.080413-2105) 2.63%
6.00.2900.5512 (xpsp.080413-2105) 0.09%
6.00.2900.5512 (xpsp.080413-2105) 0.09%
6.00.2900.5512 (xpsp.080413-2105) 0.36%
6.00.2900.5512 (xpsp.080413-2105) 2.26%
6.00.2900.5512 (xpsp.080413-2105) 1.27%
6.00.2900.5512 (xpsp.080413-2105) 0.09%
6.00.2900.5512 (xpsp.080413-2105) 0.09%
View more

Relationships

Child process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegOpenKeyExA, RegCloseKey, RegQueryValueExA
kernel32.dll
GetVersionExA, UnhandledExceptionFilter, CloseHandle, ReleaseMutex, GetFileAttributesA, GetLastError, FreeLibrary, GetProcAddress, LoadLibraryA, lstrlenW, WaitForSingleObject, CreateMutexA, ExitProcess, GetModuleHandleA, GetStartupInfoA, SetErrorMode, GetCommandLineW, QueryPerformanceCounter, GetTickCount, GetCurrentThreadId, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, GetCurrentProcess, lstrcpynA, SetUnhandledExceptionFilter, lstrlenA, GetEnvironmentVariableA, GetModuleFileNameA
msvcrt.dll
DllMain
shlwapi.dll
SHGetValueA, StrCmpIW, SHSetValueA, StrStrIA, PathRemoveFileSpecA
user32.dll
GetWindowThreadProcessId, SetForegroundWindow, SendMessageTimeoutA, LoadStringA, MessageBoxA

MSIMN.exe

Outlook Express by Microsoft

Remove MSIMN.exe
Version:   6.00.2900.5512 (xpsp.080413-2105)
MD5:   1eeae496a51f017d04dd41322935d2b9
SHA1:   f7afaf8e61263e3117a762ae2f817dff9f5ccc44
SHA256:   5c60d72118528ee01cce426a686b32f949a0153919868aaf388f32f8f6233a9c
This is a Windows system installed file with Windows File Protection (WFP) enabled.

Overview

msimn.exe executes as a process with the local user's privileges. It has been configured with a firewall exception which allows both inbound and outbound network communication without being blocked. This is typically installed with the program WSE_Astromenda published by installCore and is most likely removed by most users once installed (86% removed). This version is installed on Windows XP and is compiled as a 32 bit program.

DetailsDetails

File name:msimn.exe
Publisher:Microsoft Corporation
Product name:Outlook Express
Description:Microsoft® Windows® Operating System
Typical file path:C:\Program Files\outlook express\msimn.exe
File version:6.00.2900.5512 (xpsp.080413-2105)
Product version:6.00.2900.5512
Size:59 KB (60,416 bytes)
Digital DNA
PE subsystem:Windows GUI
Entropy:5.626074
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
installCore
  86% remove
Astromenda/Astromendario may change your default search engine to add Astromenda's (or any of Astromenda's affiliates) search engine; Astromenda's search engine is provided free of charge, and provides you with great search results. is an adware (advertising support) web browser application that is designed to display banner ads as well as contextual link ads (such as hyperlinks the user will see underlined). The ads are injected by the...

BehaviorsBehaviors

Shell open commands
  • snews
  • nntp
  • news
  • mailto
Windows firewall allowed programs
Exceptions allow programs to access to the Internet through an outbound connections
  • Firewall exception for 'C:\Program Files\Outlook Express\msimn.exe'
Network connections
Access through an approved Windows firewall exception
  • [TCP] server-54-240-188-38.sea50.r.cloudfront.net (54.240.188.38:80)
  • [UDP] listens on port 1072
  • [UDP] listens on port 1106
  • [UDP] listens on port 4068
  • [UDP] listens on port 2408

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.10896049%
    0.028634%
    Kernel CPU:0.02725091%
    0.013761%
    User CPU:0.08170959%
    0.014873%
    Kernel CPU time:19,727 ms/min
    100,923,805ms/min
    Context switches:24/sec
    284/sec
    Memory
    Private memory:25.43 MB
    21.59 MB
    Private (maximum):27.76 MB
    Private (minimum):8.56 MB
    Non-paged memory:25.43 MB
    21.59 MB
    Virtual memory:184.37 MB
    140.96 MB
    Virtual memory (peak):691.75 MB
    169.69 MB
    Working set:13.66 MB
    18.61 MB
    Working set (peak):45.49 MB
    37.95 MB
    Page faults:240,149/min
    2,039/min
    I/O
    I/O read transfer:71 KB/sec
    1.02 MB/min
    I/O read operations:22/sec
    343/min
    I/O write transfer:31.39 KB/sec
    274.99 KB/min
    I/O write operations:2/sec
    227/min
    I/O other transfer:2.68 KB/sec
    448.09 KB/min
    I/O other operations:152/sec
    1,671/min
    Resource allocations
    Threads:15
    12
    Handles:504
    600
    GUI GDI count:431
    103
    GUI USER count:228
    49

    BehaviorsProcess properties

    Integrety level:Undefined
    Platform:32-bit
    Command line:"C:\Program Files\outlook express\msimn.exe"
    Owner:User
    Parent process:Explorer.EXE (Windows Explorer by Microsoft)

    ResourcesThreads

    Averages
     
    msimn.exe (main module)
    Total CPU:1.93169913%
    0.272967%
    Kernel CPU:1.02911887%
    0.107585%
    User CPU:0.90258026%
    0.165382%
    Context switches:12/sec
    79/sec
    Memory:72 KB
    1.16 MB
    ntdll.dll
    Total CPU:0.03934429%
    Kernel CPU:0.01657360%
    User CPU:0.02277070%
    Context switches:2/sec
    Memory:712 KB
    mshtml.dll (Windows Internet Explorer by Microsoft)
    Total CPU:0.03148615%
    Kernel CPU:0.00000000%
    User CPU:0.03148615%
    Context switches:5/sec
    Memory:5.75 MB
    WININET.dll
    Total CPU:0.02854424%
    Kernel CPU:0.00951475%
    User CPU:0.01902950%
    Context switches:9/sec
    Memory:924 KB
    msoe.dll (Outlook Express by Microsoft)
    Total CPU:0.01017291%
    Kernel CPU:0.00407448%
    User CPU:0.00609844%
    Context switches:1/sec
    Memory:1.29 MB
    WINMM.dll
    Total CPU:0.00904650%
    Kernel CPU:0.00000000%
    User CPU:0.00904650%
    Memory:180 KB
    mswsock.dll (Microsoft Windows Sockets 2.0 Service Provider by Microsoft)
    Total CPU:0.00062493%
    Kernel CPU:0.00043391%
    User CPU:0.00019103%
    Memory:252 KB
    directdb.dll
    Total CPU:0.00001092%
    Kernel CPU:0.00001092%
    User CPU:0.00000000%
    Memory:100 KB
    gdiplus.dll
    Total CPU:0.00000957%
    Kernel CPU:0.00000319%
    User CPU:0.00000638%
    Memory:1.67 MB
    wab32.dll
    Total CPU:0.00000274%
    Kernel CPU:0.00000274%
    User CPU:0.00000000%
    Memory:516 KB

    Common loaded modules

    These are modules that are typiclaly loaded within the context of this process.

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Microsoft Windows XP 100.00%

    Distribution by countryDistribution by country

    United States installs about 37.77% of Outlook Express.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    Dell 38.43%
    Intel 12.55%
    Compaq 10.98%
    Hewlett-Packard 7.45%
    American Megatrends 6.27%
    GIGABYTE 5.49%
    Toshiba 5.49%
    Gateway 3.92%
    Lenovo 3.14%
    Sahara 2.75%
    Acer 2.75%
    ASUS 0.78%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE