Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.0.6002.18005 (lh_sp2rtm.090410-1830) 60.34%
6.0.6002.18005 (lh_sp2rtm.090410-1830) 10.34%
6.0.6001.18000 (longhorn_rtm.080118-1840) 8.62%
6.0.6000.16386 (vista_rtm.061101-2205) 1.72%
5.1.2600.5512 (xpsp.080413-2105) 5.17%
5.1.2600.5512 (xpsp.080413-2105) 8.62%
5.1.2600.5512 (xpsp.080413-2105) 1.72%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 1.72%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 1.72%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegQueryValueExW, RegOpenKeyExW, RegCloseKey
gdi32.dll
GetStockObject, TranslateCharsetInfo
imm32.dll
ImmCreateContext, ImmReleaseContext, ImmGetContext, ImmGetGuideLineW, ImmGetConversionStatus, ImmGetOpenStatus, ImmSetConversionStatus, ImmGetProperty, ImmAssociateContext, ImmSimulateHotKey, ImmTranslateMessage, ImmCallImeConsoleIME, ImmGetIMEFileNameW, ImmEscapeW, ImmNotifyIME, ImmGetCandidateListW, ImmGetCompositionStringW, ImmGetHotKey, ImmSetActiveContextConsoleIME, ImmDestroyContext, ImmSetOpenStatus, ImmDisableTextFrameService, ImmIsIME
kernel32.dll
lstrlenA, MultiByteToWideChar, VirtualQuery, RegisterConsoleIME, InterlockedExchange, Sleep, GetSystemInfo, VirtualAlloc, VirtualProtect, GetVersionExW, InterlockedDecrement, InterlockedIncrement, lstrlenW, WideCharToMultiByte, GetCommandLineW, RegisterApplicationRestart, HeapSetInformation, SetEvent, CreateThread, GetCurrentThreadId, OpenEventW, WaitForSingleObject, CloseHandle, GetACP, LocalAlloc, LocalReAlloc, LocalFree, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, GetSystemTimeAsFileTime, GetCurrentProcessId, GetTickCount, QueryPerformanceCounter, GetModuleHandleA, SetUnhandledExceptionFilter, GetStartupInfoA, InterlockedCompareExchange, UnregisterConsoleIME, lstrcpyW, lstrcatW, lstrcpynW, GetSystemDirectoryW, SetCurrentDirectoryW
msctf.dll
TF_IsCtfmonRunning, TF_WaitForInitialized, TF_Notify
msvcrt.dll
DllMain
ntdll.dll
RtlLeaveCriticalSection, NtOpenProcessToken, RtlUnicodeToMultiByteSize, NtQueryInformationToken, NtClose, RtlInitializeCriticalSection, NtQueryVirtualMemory, RtlUnwind, RtlCopyLuid, RtlEnterCriticalSection
ole32.dll
CoUninitialize, CoCreateInstance, CoInitializeEx
user32.dll
IsWindowEnabled, EnableWindow, UnregisterClassW, CreateWindowExW, RegisterClassW, LoadCursorW, SetForegroundWindow, RegisterWindowMessageW, DispatchMessageW, TranslateMessage, GetMessageW, GetKeyState, GetKeyboardLayoutNameW, PostQuitMessage, DefWindowProcW, GetGUIThreadInfo, IsWindow, DestroyWindow, SetTimer, LoadIconW, PostMessageW, SendMessageTimeoutW, KillTimer, AttachThreadInput, ActivateKeyboardLayout, GetKeyboardLayoutList, LoadStringW, GetSystemMetrics
uxtheme.dll
SetThemeAppProperties

CONIME.exe

Console IME by Microsoft

Remove CONIME.exe
Version:   6.0.6001.18000 (longhorn_rtm.080118-1840)
MD5:   f96ebc5a624349d81dcc7600a3c5dc43
SHA1:   97b4c1c6e8cd9707b2b67ed012e53581692b7514
SHA256:   7812184afc24f7a245d3d140eb0c1a4a23e73b34bc0a8c1556715368086f0376
This is a Windows system installed file with Windows File Protection (WFP) enabled.

Overview

conime.exe executes as a process with the local user's privileges typically within the context of its parent Apntex.exe (Alps Pointing-device Driver for Windows NT/2000/XP/Vista by Alps Electric Co., Ltd). It is set to be start when the PC boots and any user logs into Windows (added to the Run registry key for the all users under the local machine). and is compiled as a 32 bit program.

DetailsDetails

File name:conime.exe
Publisher:Microsoft Corporation
Product name:Console IME
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\conime.exe
File version:6.0.6001.18000 (longhorn_rtm.080118-1840)
Product version:6.0.6001.18000
Size:67.5 KB (69,120 bytes)
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

BehaviorsBehaviors

Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'Conime' → %windir%\system32\conime.exe

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00026109%
0.028634%
Kernel CPU:0.00021505%
0.013761%
User CPU:0.00004604%
0.014873%
Kernel CPU time:31,253 ms/min
100,923,805ms/min
Memory
Private memory:1.07 MB
21.59 MB
Private (maximum):3.21 MB
Private (minimum):968 KB
Non-paged memory:1.07 MB
21.59 MB
Virtual memory:44.1 MB
140.96 MB
Virtual memory (peak):45.66 MB
169.69 MB
Working set:1.27 MB
18.61 MB
Working set (peak):3.52 MB
37.95 MB
Resource allocations
Threads:1
12
Handles:38
600
GUI GDI count:10
103
GUI USER count:9
49

BehaviorsProcess properties

Integrety level:Medium
Platform:32-bit
Command line:C:\Windows\System32\conime.exe
Owner:User
Parent process:Apntex.exe (Alps Pointing-device Driver for Windows NT/2000/XP/Vista by Alps Electric Co., Ltd)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows Vista Home Premium 50.00%
Microsoft Windows XP 20.69%
Windows Vista Home Basic 15.52%
Windows Vista Ultimate 8.62%
Windows Vista Business 5.17%

Distribution by countryDistribution by country

Germany installs about 12.28% of Console IME.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Hewlett-Packard 20.00%
ASUS 17.14%
Sony 11.43%
Dell 11.43%
American Megatrends 8.57%
GIGABYTE 5.71%
Acer 5.71%
Gateway 5.71%
Toshiba 5.71%
Sahara 2.86%
Packard Bell 2.86%
Samsung 2.86%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE