File details
File name: wpffontcache_v0400.exe
Name: Microsoft® .NET Framework
Description: wpffontcache_v0400.exe
Version: 4.0.30319.18408 built by: FX451RTMGREL
Product version: 4.0.30319.18408
Size: 752.12 KB
Original file name: wpffontcache_v0400.exe.mui
Digital certificate
Certificate authority:
Microsoft Corporation
Effective date: 12/7/2009
Expiration date: 3/7/2011
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0001681608%
Privileged CPU:
0.0000677011%

User CPU:
0.00010045972116%

Privileged CPU time: 31.2 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
232,104,752
 | Memory utilization averages |
Committed memory:
50.53 MB
Peak committed memory: 52.53 MB
Paged memory:
1.88 MB
Peak paged memory: 1.92 MB
Paged system memory:
93.66 KB
Non-paged system memory: 3.87 KB
Working set memory:
5.34 MB
Peak working set memory: 5.73 MB
Min working set memory: 5.34 MB
Private memory:
1.88 MB
Page faults:
1,719
Page faults /min: 0
 | Process I/O averages |
Total read operations:
3
Total read transfer: 16.81 KB
Total write operations:
2
Total write transfer: 28 Bytes
Total other operations:
2,888
Total other transfer: 99.79 KB
Resources
Handle count average: 81
Thread count average: 5
Thread resource averages
Total CPU: 0.000340524599%
Privileged CPU: 0.000136209840%
User CPU: 0.000204314760%
CPU Cycle count /sec: 8,374
Module memory size: 752 KB
Process details
Runs as (owner): Local Service
Integrety level: System
Windows platform: 32-bit
Runs as a service: Yes
Parent Process
Process Command
C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
Service details
Name: Windows Presentation Foundation Font Cache 4.0.0.0
Service name: WPFFontCache_v0400
Service type:
Win32OwnProcess
Description: “Optimizes performance of Windows Presentation Foundation (WPF) applications by caching commonly used font data. WPF applications will start this service if it is not already running. It can be disabled, though doing so will degrade the performance of WPF applications.”
Image hashes
MD5: f8d3544acbce9110362119f7c10d848e
SHA-1: 8a1332ab8d2636eb73f926cd78a9c597ce945287
PE image details
File entropy: 6.37482
File packed: No
Import Table
advapi32.dll

TraceEvent
GetTraceEnableFlags
GetTraceEnableLevel
GetTraceLoggerHandle
RegisterTraceGuidsW
UnregisterTraceGuids
RegisterServiceCtrlHandlerExW
SetServiceStatus
StartServiceCtrlDispatcherW
RegNotifyChangeKeyValue
RegCloseKey
RegQueryInfoKeyW
RegQueryValueExW
RegOpenKeyExW
AccessCheck
MapGenericMask
GetSecurityInfo
SetSecurityDescriptorDacl
InitializeSecurityDescriptor
SetEntriesInAclW
GetSidSubAuthority
GetSidSubAuthorityCount
GetTokenInformation
OpenProcessToken
OpenThreadToken
CopySid
GetLengthSid
ConvertSidToStringSidW
EqualSid
CreateWellKnownSid
RegEnumValueW
EventWrite
EventRegister
EventUnregister
kernel32.dll

GetSystemWindowsDirectoryW
LocalAlloc
FindClose
FindFirstFileW
SetLastError
GetModuleHandleExW
GetLocaleInfoW
GetSystemInfo
OutputDebugStringA
WideCharToMultiByte
MultiByteToWideChar
CompareStringW
LCMapStringW
ReadFile
GetFileInformationByHandle
ResetEvent
SetEvent
WaitForSingleObjectEx
CreateEventW
IsProcessorFeaturePresent
VirtualQuery
VirtualAlloc
GetVersion
GetExitCodeThread
WaitForMultipleObjectsEx
CreateThread
WaitForSingleObject
FindFirstChangeNotificationW
FindCloseChangeNotification
Sleep
GlobalMemoryStatusEx
QueueUserWorkItem
GetVersionExW
GetModuleHandleW
GetProcAddress
WriteFile
GetLastError
CreateFileW
SetErrorMode
RtlCaptureStackBackTrace
InterlockedExchange
InterlockedCompareExchange
HeapSetInformation
EncodePointer
DecodePointer
SetUnhandledExceptionFilter
QueryPerformanceCounter
GetTickCount
GetCurrentThreadId
GetCurrentProcessId
GetSystemTimeAsFileTime
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
IsDebuggerPresent
RaiseException
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
CloseHandle
InterlockedIncrement
InterlockedDecrement
LocalFree
GetCurrentThread
CreateFileMappingW
MapViewOfFileEx
UnmapViewOfFile
GetTickCount64
msvcp110_clr0400.dll
msvcr100_clr0400.dll
msvcr110_clr0400.dll
rpcrt4.dll

RpcImpersonateClient
RpcServerUseProtseqEpW
RpcServerRegisterIfEx
RpcServerUnregisterIfEx
RpcStringFreeW
UuidToStringW
UuidCreate
NdrAsyncServerCall
RpcAsyncCompleteCall
RpcMgmtStopServerListening
RpcServerListen
RpcRevertToSelf
shell32.dll
