File details
File name: realplay.exe
Name: RealPlayer (32-bit)
Description: RealPlayer
Version: 17.0.1.181
Size: 259.58 KB
Original file name: REALPLAY.EXE
Digital certificate
Certificate authority:
Thawte
Expiration date: 8/16/2011
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0000433952%
Privileged CPU:
0.0000067805%

User CPU:
0.00003661468670%

Privileged CPU time: 248369.19 ms
Privileged CPU time /min: 184 ms
CPU cycle count:
331,526,313
CPU cycle count /min: 1,301,796,933
 | Memory utilization averages |
Committed memory:
920.52 MB
Peak committed memory: 993.26 MB
Paged memory:
264.64 MB
Peak paged memory: 339.52 MB
Paged system memory:
922.97 KB
Non-paged system memory: 207.86 KB
Working set memory:
20.42 MB
Peak working set memory: 88.49 MB
Min working set memory: 3.63 MB
Private memory:
264.64 MB
 | Process I/O averages |
Total read operations:
504,789
Read operations /min: 374
Total read transfer: 1.01 GB
Read transfer /min: 781.31 KB
Total write operations:
13,980
Write operations /min: 10
Total write transfer: 46.96 MB
Write transfer /min: 35.59 KB
Total other operations:
2,389,477
Other operations /min: 1,768
Total other transfer: 124.43 MB
Other Transfer /min: 94.29 KB
 | GUI Object Averages |
GDI objects:
419
Peak GDI objects: 443
USER objects:
1,013
Peak USER objects: 1,075
Resources
Handle count average: 3,160
Thread count average: 233
Thread resource averages
Total CPU: 0.068555742588%
Privileged CPU: 0.013030237369%
User CPU: 0.055525505219%
CPU Cycle count /sec: 2,582,646
Module memory size: 576 KB
wow64.dll

Total CPU: 0.000755586275%
Privileged CPU: 0.000146605801%
User CPU: 0.000608980475%
CPU Cycle count /sec: 17,122
Module memory size: 252 KB
ntdll.dll

Total CPU: 0.000301094544%
Privileged CPU: 0.000152237620%
User CPU: 0.000148856924%
CPU Cycle count /sec: 7,997
Module memory size: 1.66 MB
Process details
Runs as (owner): User
Integrety level: Medium
Windows platform: 64-bit
Parent Process
Process Command
"C:\Program Files\real\realplayer\realplay.exe" /launcC:start_menu
Autoplay handler details
Name: RPPlayMediaOnArrival
Command: SOFTWARE\Microsoft\Windows\ CurrentVersion\Explorer\AutoplayHandlers\Handlers\RPPlayMediaOnArrival
Scheduled task details
CLSID: {CAF98FFB-8246-4180-8543-CE4146F5E2AE}
Command: \{CAF98FFB-8246-4180-8543-CE4146F5E2AE}
Startup files (all users) run details
Name: RealTray
Command: C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
Network connectivity
UDP: LISTENING on port 60632
Windows Firewall allowed program: Yes
Image hashes
MD5: 831bdaae30a1a9c9c4c6083c3193105e
SHA-1: 23dec734b7ea0a23986c18d58b3bac718e10ebcb
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++ 9.0
File packed: No
Import Table
advapi32.dll

RegEnumKeyExA
RegCreateKeyExA
RegQueryInfoKeyA
RegEnumKeyA
RegDeleteKeyA
RegQueryValueA
RegDeleteValueA
RegOpenKeyA
RegOpenKeyExA
RegQueryValueExA
RegCloseKey
RegCreateKeyA
RegSetValueA
RegSetValueExA
RegCreateKeyW
RegSetValueW
RegOpenKeyW
RegQueryValueW
gdi32.dll

kernel32.dll

GetEnvironmentVariableA
GetProcAddress
LoadLibraryA
GetModuleHandleA
GetTickCount
InterlockedIncrement
InterlockedDecrement
FreeLibrary
QueryPerformanceCounter
QueryPerformanceFrequency
GetVersionExA
CreateFileA
FindClose
CreateDirectoryA
MoveFileA
GetSystemInfo
GetVersion
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
GetModuleHandleExA
GetCurrentThreadId
RaiseException
Sleep
FindFirstFileW
GetModuleFileNameA
GetCurrentProcessId
SizeofResource
LockResource
LoadResource
FindResourceA
FindResourceExA
SetCurrentDirectoryA
GetCurrentDirectoryA
IsBadWritePtr
VirtualProtect
IsBadReadPtr
SetUnhandledExceptionFilter
TerminateThread
CreateThread
GetCurrentProcess
WriteFile
GetThreadContext
VirtualQuery
OpenProcess
SetFilePointer
GlobalMemoryStatus
UnmapViewOfFile
MapViewOfFile
CreateFileMappingA
GetSystemTimeAsFileTime
IsDebuggerPresent
UnhandledExceptionFilter
TerminateProcess
GetStartupInfoA
InterlockedCompareExchange
InterlockedExchange
GetProcessHeap
HeapSize
HeapReAlloc
HeapFree
HeapAlloc
HeapDestroy
SetEnvironmentVariableA
GetCommandLineW
WideCharToMultiByte
GetLastError
DeleteFileA
CreateMutexA
ReleaseMutex
CloseHandle
OpenMutexA
WaitForSingleObject
SetErrorMode
SetEvent
ResetEvent
CreateEventA
FindResourceW
FindResourceExW
lstrlenW
MultiByteToWideChar
GetStartupInfoW
HeapSetInformation
DecodePointer
EncodePointer
InitializeCriticalSectionAndSpinCount
lstrlenA
ExitProcess
GlobalAddAtomA
GlobalDeleteAtom
msvcp100.dll
msvcp71.dll
msvcp90.dll
msvcr100.dll
msvcr71.dll
msvcr90.dll
ole32.dll

OleInitialize
OleUninitialize
pncrt.dll

strrchr
strstr
_controlfp
_except_handler3
__set_app_type
__p__fmode
__p__commode
_adjust_fdiv
_putenv
_initterm
__getmainargs
__setusermatherr
printf
_assert
sprintf
getenv
_purecall
memmove
strchr
exit
_acmdln
__dllonexit
_onexit
_exit
_XcptFilter
shell32.dll

SHGetFolderPathA
SHGetFolderPathW
SHCreateDirectoryExW
SHCreateDirectoryExA
shlwapi.dll

PathAddBackslashA
PathAppendA
PathAppendW
PathAddBackslashW
user32.dll

GetDC
ReleaseDC
RegisterWindowMessageA
RegisterClassExA
GetClassInfoExA
CreateWindowExA
DefWindowProcA
PostThreadMessageA
DestroyWindow
UnregisterClassA
CharPrevA
CharNextA
GetSystemMetrics
SetMessageQueue
EnumWindows
GetPropA
SendMessageA
version.dll

VerQueryValueA
GetFileVersionInfoA