File details
File name: realplay.exe
Name: RealPlayer (32-bit)
Description: RealPlayer
Version: 16.0.0.282
Size: 489.15 KB
Original file name: REALPLAY.EXE
Digital certificate
Certificate authority:
Thawte
Expiration date: 8/16/2011
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0132844450%
Privileged CPU:
0.0039592165%

User CPU:
0.00932522844452%

Privileged CPU time: 5634952.24 ms
Privileged CPU time /min: 100 ms
CPU cycle count:
53,339,538
CPU cycle count /min: 68,040,236
Context switches /sec:
679
 | Memory utilization averages |
Committed memory:
345.62 MB
Peak committed memory: 364.55 MB
Paged memory:
92.56 MB
Peak paged memory: 101.1 MB
Paged system memory:
405.9 KB
Non-paged system memory: 50.72 KB
Working set memory:
58.52 MB
Peak working set memory: 91.03 MB
Min working set memory: 34.64 MB
Private memory:
92.56 MB
Page faults:
487,359
Page faults /min: 2,371
 | Process I/O averages |
Total read operations:
166,755
Read operations /min: 616
Total read transfer: 41.66 MB
Read transfer /min: 784.02 KB
Total write operations:
6,995
Write operations /min: 13
Total write transfer: 16.3 MB
Write transfer /min: 9.07 KB
Total other operations:
622,703
Other operations /min: 285
Total other transfer: 8.96 MB
Other Transfer /min: 8.67 KB
 | GUI Object Averages |
GDI objects:
212
Peak GDI objects: 165
USER objects:
279
Peak USER objects: 240
Resources
Handle count average: 782
Thread count average: 41
Thread resource averages
Total CPU: 0.990739953355%
Privileged CPU: 0.236083271772%
User CPU: 0.754656681583%
CPU Cycle count /sec: 25,016,551
Context switches /sec: 254
Module memory size: 804 KB
Total CPU: 0.651569331587%
Privileged CPU: 0.049154518663%
User CPU: 0.602414812924%
CPU Cycle count /sec: 11,598,671
Module memory size: 688 KB
Total CPU: 0.484856111987%
Privileged CPU: 0.008903455372%
User CPU: 0.475952656615%
CPU Cycle count /sec: 8,696,898
Context switches /sec: 14
Module memory size: 14.77 MB
Total CPU: 0.333040009112%
Privileged CPU: 0.068938521958%
User CPU: 0.264101487154%
CPU Cycle count /sec: 6,400,803
Module memory size: 11.77 MB
ntdll.dll

Total CPU: 0.288120977599%
Privileged CPU: 0.224893030649%
User CPU: 0.063227946949%
CPU Cycle count /sec: 5,347,322
Module memory size: 1.23 MB
Total CPU: 0.215365798618%
Privileged CPU: 0.015835712153%
User CPU: 0.199530086464%
CPU Cycle count /sec: 3,602,960
Context switches /sec: 2
Module memory size: 680 KB
wininet.dll

Total CPU: 0.118261144389%
Privileged CPU: 0.076963601904%
User CPU: 0.041297542485%
CPU Cycle count /sec: 1,978,675
Module memory size: 1.11 MB
Total CPU: 0.092826987954%
Privileged CPU: 0.037668922648%
User CPU: 0.055158065306%
CPU Cycle count /sec: 8,528,100
Module memory size: 216 KB
Total CPU: 0.053382005957%
Privileged CPU: 0.011067936098%
User CPU: 0.042314069860%
CPU Cycle count /sec: 1,134,708
Context switches /sec: 6
Module memory size: 11.77 MB
ntdll.dll

Total CPU: 0.052545650394%
Privileged CPU: 0.035775761970%
User CPU: 0.016769888424%
CPU Cycle count /sec: 1,009,143
Context switches /sec: 4
Module memory size: 1.16 MB
wininet.dll

Total CPU: 0.038694083009%
Privileged CPU: 0.023439684899%
User CPU: 0.015254398109%
CPU Cycle count /sec: 669,587
Context switches /sec: 9
Module memory size: 1.11 MB
Total CPU: 0.009732190321%
Privileged CPU: 0.001819282970%
User CPU: 0.007912907351%
CPU Cycle count /sec: 1,426,780
Module memory size: 14.91 MB
msvcr100.dll

Total CPU: 0.008279680616%
Privileged CPU: 0.003805972080%
User CPU: 0.004473708536%
CPU Cycle count /sec: 825,180
Context switches /sec: 15
Module memory size: 764 KB
Total CPU: 0.007933424103%
Privileged CPU: 0.003966712051%
User CPU: 0.003966712051%
CPU Cycle count /sec: 297,246
Module memory size: 2.05 MB
wow64cpu.dll

Total CPU: 0.004167471690%
Privileged CPU: 0.000185220964%
User CPU: 0.003982250726%
CPU Cycle count /sec: 120,510
Module memory size: 32 KB
mswsock.dll

Total CPU: 0.003754744908%
Privileged CPU: 0.003754744908%
User CPU: 0.000000000000%
CPU Cycle count /sec: 20,302
Module memory size: 240 KB
wdmaud.drv

Total CPU: 0.002645667655%
Privileged CPU: 0.000000000000%
User CPU: 0.002645667655%
CPU Cycle count /sec: 22,439
Module memory size: 188 KB
Total CPU: 0.002008142341%
Privileged CPU: 0.001068121262%
User CPU: 0.000940021079%
CPU Cycle count /sec: 2,535
Module memory size: 232 KB
winmm.dll

Total CPU: 0.001877301981%
Privileged CPU: 0.001877301981%
User CPU: 0.000000000000%
CPU Cycle count /sec: 40,554
Module memory size: 200 KB
winmm.dll

Total CPU: 0.001488190380%
Privileged CPU: 0.001116142785%
User CPU: 0.000372047595%
CPU Cycle count /sec: 7,068
Module memory size: 200 KB
Process details
Runs as (owner): User
Integrety level: High
Windows platform: 32-bit
Parent Processes
Child Process
Process Commands
"C:\Program Files\real\realplayer\\RealPlay.exe" /runevent "C:\Program Files\Real\RealPlayer\update\upgr3270.dll" AutoUpdateEvent
"C:\Program Files\Real\RealPlayer\realplay.exe" /launcC:start_menu
"C:\Program Files\real\realplayer\realplay.exe" "/commanC:MyLibrary(NavigateToPath)"
"C:\Program Files\real\realplayer\\RealPlay.exe" "C:\????\.rm"
"C:\Program Files\Real\RealPlayer\realplay.exe" /launcC:start_menu
Autoplay handler details
Name: RPPlayMediaOnArrival
Command: SOFTWARE\Microsoft\Windows\ CurrentVersion\Explorer\AutoplayHandlers\Handlers\RPPlayMediaOnArrival
Scheduled task details
CLSID: {CAF98FFB-8246-4180-8543-CE4146F5E2AE}
Command: \{CAF98FFB-8246-4180-8543-CE4146F5E2AE}
Startup files (all users) run details
Name: RealTray
Command: C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
Network connectivity
TCP: v-5-327-d2928-214.webazilla.com on port 49583
TCP: channel-ecmp-13-prn1.facebook.com on port 50271
UDP: LISTENING on port 64359
UDP: LISTENING on port 49200
UDP: LISTENING on port 55226
UDP: LISTENING on port 64636
Windows Firewall allowed program: Yes
Image hashes
MD5: 01243fa89fbec041e873de8386138440
SHA-1: 118f225e23e365e7b5cc01be2dc40146cd52d473
SHA-256: 7a9f1b4d4c295eae8cd8cc1805cb0df57e71d3411351c735cf425eb3dfa3bb40
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++ 9.0
File packed: No
Import Table
advapi32.dll

RegEnumKeyExA
RegCreateKeyExA
RegQueryInfoKeyA
RegEnumKeyA
RegDeleteKeyA
RegQueryValueA
RegDeleteValueA
RegOpenKeyA
RegOpenKeyExA
RegQueryValueExA
RegCloseKey
RegCreateKeyA
RegSetValueA
RegSetValueExA
RegCreateKeyW
RegSetValueW
RegOpenKeyW
RegQueryValueW
gdi32.dll

kernel32.dll

GetEnvironmentVariableA
GetProcAddress
LoadLibraryA
GetModuleHandleA
GetTickCount
InterlockedIncrement
InterlockedDecrement
FreeLibrary
QueryPerformanceCounter
QueryPerformanceFrequency
GetVersionExA
CreateFileA
FindClose
CreateDirectoryA
MoveFileA
GetSystemInfo
GetVersion
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
GetModuleHandleExA
GetCurrentThreadId
RaiseException
Sleep
FindFirstFileW
GetModuleFileNameA
GetCurrentProcessId
SizeofResource
LockResource
LoadResource
FindResourceA
FindResourceExA
SetCurrentDirectoryA
GetCurrentDirectoryA
IsBadWritePtr
VirtualProtect
IsBadReadPtr
SetUnhandledExceptionFilter
TerminateThread
CreateThread
GetCurrentProcess
WriteFile
GetThreadContext
VirtualQuery
OpenProcess
SetFilePointer
GlobalMemoryStatus
UnmapViewOfFile
MapViewOfFile
CreateFileMappingA
GetSystemTimeAsFileTime
IsDebuggerPresent
UnhandledExceptionFilter
TerminateProcess
GetStartupInfoA
InterlockedCompareExchange
InterlockedExchange
GetProcessHeap
HeapSize
HeapReAlloc
HeapFree
HeapAlloc
HeapDestroy
SetEnvironmentVariableA
GetCommandLineW
WideCharToMultiByte
GetLastError
DeleteFileA
CreateMutexA
ReleaseMutex
CloseHandle
OpenMutexA
WaitForSingleObject
SetErrorMode
SetEvent
ResetEvent
CreateEventA
FindResourceW
FindResourceExW
lstrlenW
MultiByteToWideChar
GetStartupInfoW
HeapSetInformation
DecodePointer
EncodePointer
InitializeCriticalSectionAndSpinCount
lstrlenA
ExitProcess
GlobalAddAtomA
GlobalDeleteAtom
msvcp100.dll
msvcp71.dll
msvcp90.dll
msvcr100.dll
msvcr71.dll
msvcr90.dll
ole32.dll

OleInitialize
OleUninitialize
pncrt.dll

strrchr
strstr
_controlfp
_except_handler3
__set_app_type
__p__fmode
__p__commode
_adjust_fdiv
_putenv
_initterm
__getmainargs
__setusermatherr
printf
_assert
sprintf
getenv
_purecall
memmove
strchr
exit
_acmdln
__dllonexit
_onexit
_exit
_XcptFilter
shell32.dll

SHGetFolderPathA
SHGetFolderPathW
SHCreateDirectoryExW
SHCreateDirectoryExA
shlwapi.dll

PathAddBackslashA
PathAppendA
PathAppendW
PathAddBackslashW
user32.dll

GetDC
ReleaseDC
RegisterWindowMessageA
RegisterClassExA
GetClassInfoExA
CreateWindowExA
DefWindowProcA
PostThreadMessageA
DestroyWindow
UnregisterClassA
CharPrevA
CharNextA
GetSystemMetrics
SetMessageQueue
EnumWindows
GetPropA
SendMessageA
version.dll

VerQueryValueA
GetFileVersionInfoA