File details
File name: realsched.exe
Name: RealPlayer (32-bit)
Description: RealNetworks Scheduler
Version: 15.0.6.14
Size: 289.16 KB
Original file name: realsched.exe
Digital certificate
Certificate authority:
Thawte
Effective date: 8/15/2010
Expiration date: 8/16/2011
Resource utilization
 | CPU utilization averages |
Total CPU: 0.1719139587%
Privileged CPU:
0.0163559297%

User CPU:
0.15555802902681%

Privileged CPU time: 4136088.35 ms
Privileged CPU time /min: 8 ms
CPU cycle count:
426,486,965
CPU cycle count /min: 120,769,861
Context switches /sec:
80
 | Memory utilization averages |
Committed memory:
68.2 MB
Peak committed memory: 76.1 MB
Paged memory:
2.41 MB
Peak paged memory: 2.8 MB
Paged system memory:
114.93 KB
Non-paged system memory: 9.42 KB
Working set memory:
588.7 KB
Peak working set memory: 5.41 MB
Min working set memory: 201.22 KB
Private memory:
2.41 MB
Page faults:
314,169
Page faults /min: 1,772
 | Process I/O averages |
Total read operations:
411
Read operations /min: 3
Total read transfer: 643.42 KB
Read transfer /min: 4.31 KB
Total write operations:
5
Write operations /min: 1
Total write transfer: 9.76 KB
Write transfer /min: 38 Bytes
Total other operations:
75,204
Other operations /min: 442
Total other transfer: 1.73 MB
Other Transfer /min: 13.23 KB
 | GUI Object Averages |
GDI objects:
9
Peak GDI objects: 10
USER objects:
11
Peak USER objects: 14
Resources
Handle count average: 331
Thread count average: 6
Thread resource averages
Total CPU: 0.042106566462%
Privileged CPU: 0.029250597056%
User CPU: 0.012855969406%
CPU Cycle count /sec: 1,021,722
Context switches /sec: 1
Module memory size: 312 KB
ntdll.dll

Total CPU: 0.000050896463%
Privileged CPU: 0.000050896463%
User CPU: 0.000000000000%
CPU Cycle count /sec: 512
Module memory size: 1.23 MB
Process details
Runs as (owner): User
Integrety level: High
Windows platform: 64-bit
Parent Processes
Process Commands
"C:\Program Files\Real\RealPlayer\Update\realsched.exe" -osboot
"C:\Program Files\real\realplayer\update\realsched.exe" -startedByApp
"C:\Program Files\real\realplayer\update\realsched.exe"
"C:\Program Files\Real\RealPlayer\update\realsched.exe" -restart
"C:\Program Files\Real\RealPlayer\update\realsched.exe" -restart
Startup files (all users) run details
Name: TkBellExe
Command: "C:\Program Files\Real\RealPlayer\update\realsched.exe" -osboot
Autoplay handler details
Name: RPPlayMediaOnArrival
Command: SOFTWARE\Microsoft\Windows\ CurrentVersion\Explorer\AutoplayHandlers\Handlers\RPPlayMediaOnArrival
Scheduled task details
Name: Real Player オンライン更新プログラム
Command: \Real Player オンライン更新プログラム
Image hashes
MD5: a73731a0b0a165907799e9afb461f856
SHA-1: 3c5af46aa972ecfdcd3b2433cd1665a194c8b63e
SHA-256: e6238656ad6eae8b398ca3ed5ae81285826bb62f3af6846924e0ee5f7810f0d6
PE image details
File entropy: 6.57887
File packed: No
Import Table
advapi32.dll

RegDeleteValueA
FreeSid
RegEnumKeyA
RegCreateKeyA
RegSetValueA
RegQueryValueA
RegDeleteKeyA
RegCreateKeyExA
RegSetValueExA
RegEnumKeyExA
RegNotifyChangeKeyValue
RegOpenKeyExA
RegQueryValueExA
RegOpenKeyA
RegCloseKey
RegCreateKeyW
RegSetValueW
RegOpenKeyW
RegQueryValueW
gdi32.dll

kernel32.dll
ole32.dll

CreateClassMoniker
CoRevokeClassObject
CoRegisterClassObject
CoInitializeEx
GetRunningObjectTable
CoUninitialize
setupapi.dll

SetupDiGetClassDevsW
SetupDiEnumDeviceInfo
SetupDiDeleteDeviceInfo
SetupDiDestroyDeviceInfoList
CM_Get_Parent
CM_Get_Device_ID_Size
CM_Get_Device_IDW
SetupDiGetDeviceInstanceIdW
shell32.dll

SHGetFolderPathW
SHGetFolderPathA
SHCreateDirectoryExA
SHCreateDirectoryExW
shlwapi.dll

PathGetDriveNumberW
PathAppendA
PathAddBackslashA
PathAppendW
PathAddBackslashW
user32.dll

CharPrevA
CharNextA
RegisterWindowMessageA
ReleaseDC
GetClassInfoExA
UnregisterClassA
SetWindowsHookExA
GetMessageA
TranslateMessage
DispatchMessageA
GetClassInfoA
RegisterClassA
GetSystemMetrics
CreateWindowExA
DefWindowProcA
PostQuitMessage
SetTimer
KillTimer
DestroyWindow
PostThreadMessageA
FindWindowA
PostMessageA
IsWindow
SendMessageA
GetDC
RegisterClassExA
UnhookWindowsHookEx
version.dll

GetFileVersionInfoA
VerQueryValueA