File details
File name: wmpnetwk.exe
Name: Windows Media Player Network Sharing Service
Description: Microsoft® Windows® Operating System
Version: 12.0.7600.16385 (win7_rtm.090713-1255)
Product version: 12.0.7600.16385
Size: 1.45 MB
Original file name: WMPNetwk.exe.mui
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0030603597%
Privileged CPU:
0.0014856414%

User CPU:
0.00157471825602%

Privileged CPU time: 30101144.87 ms
Privileged CPU time /min: 4,112 ms
CPU cycle count:
1,861,233
CPU cycle count /min: 161,372,792
Context switches /sec:
8
 | Memory utilization averages |
Committed memory:
157.97 MB
Peak committed memory: 163.23 MB
Paged memory:
20.04 MB
Peak paged memory: 23.39 MB
Paged system memory:
256.31 KB
Non-paged system memory: 45.61 KB
Working set memory:
12.03 MB
Peak working set memory: 33.9 MB
Min working set memory: 4.11 MB
Private memory:
20.04 MB
Page faults:
693,127
Page faults /min: 380
 | Process I/O averages |
Total read operations:
339,046
Read operations /min: 505
Total read transfer: 152.03 MB
Read transfer /min: 2.58 MB
Total write operations:
3,134
Write operations /min: 1
Total write transfer: 9.39 MB
Write transfer /min: 1.93 KB
Other operations /min: 18,128
Total other transfer: 31.58 MB
Other Transfer /min: 349.52 KB
Resources
Handle count average: 434
Thread count average: 15
Thread resource averages
ole32.dll

Total CPU: 0.506564009799%
Privileged CPU: 0.386892485850%
User CPU: 0.119671523949%
CPU Cycle count /sec: 10,300,875
Context switches /sec: 1
Module memory size: 2.01 MB
ntdll.dll

Total CPU: 0.257265283616%
Privileged CPU: 0.133663090950%
User CPU: 0.123602192666%
CPU Cycle count /sec: 4,860,394
Context switches /sec: 1
Module memory size: 1.66 MB
Total CPU: 0.191504154981%
Privileged CPU: 0.111902042615%
User CPU: 0.079602112366%
CPU Cycle count /sec: 4,034,519
Context switches /sec: 2
Module memory size: 100 KB
Total CPU: 0.057538975410%
Privileged CPU: 0.051319828723%
User CPU: 0.006219146687%
CPU Cycle count /sec: 1,299,662
Module memory size: 440 KB
Total CPU: 0.054549726690%
Privileged CPU: 0.026575507875%
User CPU: 0.027974218815%
CPU Cycle count /sec: 6,208,302
Module memory size: 100 KB
ntdll.dll

Total CPU: 0.031329235791%
Privileged CPU: 0.016197896171%
User CPU: 0.015131339620%
CPU Cycle count /sec: 687,386
Context switches /sec: 2
Module memory size: 1.66 MB
wmp.dll

Total CPU: 0.013236589030%
Privileged CPU: 0.005324048693%
User CPU: 0.007912540337%
CPU Cycle count /sec: 531,556
Context switches /sec: 1
Module memory size: 14.05 MB
ntdll.dll

Total CPU: 0.012775819003%
Privileged CPU: 0.007164570521%
User CPU: 0.005611248482%
CPU Cycle count /sec: 445,404
Module memory size: 1.66 MB
ntdll.dll

Total CPU: 0.011530392595%
Privileged CPU: 0.005813538994%
User CPU: 0.005716853601%
CPU Cycle count /sec: 282,814
Module memory size: 1.66 MB
sechost.dll

Total CPU: 0.004333944738%
Privileged CPU: 0.001904741508%
User CPU: 0.002429203230%
CPU Cycle count /sec: 108,032
Module memory size: 124 KB
ntdll.dll

Total CPU: 0.004054138358%
Privileged CPU: 0.003879638092%
User CPU: 0.000174500265%
CPU Cycle count /sec: 30,871
Context switches /sec: 1
Module memory size: 1.66 MB
Total CPU: 0.002679016641%
Privileged CPU: 0.001131978800%
User CPU: 0.001547037841%
CPU Cycle count /sec: 279,999
Context switches /sec: 10
Module memory size: 512 KB
Total CPU: 0.001130894064%
Privileged CPU: 0.000490608440%
User CPU: 0.000640285625%
CPU Cycle count /sec: 131,712
Context switches /sec: 6
Module memory size: 548 KB
sechost.dll

Total CPU: 0.000766957338%
Privileged CPU: 0.000183023910%
User CPU: 0.000583933428%
CPU Cycle count /sec: 23,994
Module memory size: 124 KB
Total CPU: 0.000530199704%
Privileged CPU: 0.000441083297%
User CPU: 0.000089116407%
CPU Cycle count /sec: 10,539
Module memory size: 1.48 MB
ssdpapi.dll

Total CPU: 0.000222529107%
Privileged CPU: 0.000095780090%
User CPU: 0.000126749017%
CPU Cycle count /sec: 4,657
Module memory size: 68 KB
wmdrmdev.dll

Total CPU: 0.000140226787%
Privileged CPU: 0.000002623426%
User CPU: 0.000137603361%
CPU Cycle count /sec: 5,249
Module memory size: 632 KB
gdiplus.dll

Total CPU: 0.000129121501%
Privileged CPU: 0.000116771978%
User CPU: 0.000012349524%
CPU Cycle count /sec: 273
Module memory size: 2.09 MB
ole32.dll

Total CPU: 0.000087154580%
Privileged CPU: 0.000034861832%
User CPU: 0.000052292748%
CPU Cycle count /sec: 28,134
Module memory size: 2.01 MB
Total CPU: 0.000062484170%
Privileged CPU: 0.000042299131%
User CPU: 0.000020185039%
CPU Cycle count /sec: 82,657
Context switches /sec: 4
Module memory size: 636 KB
Process details
Runs as (owner): Network Service
Integrety level: System
Windows platform: 64-bit
Runs as a service: Yes
Parent Process
Process Command
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
Service details
Name: Υπηρεσία κοινής χρήσης δικτύου του Windows Media Player
Service name: WMPNetworkSvc
Service type:
Win32OwnProcess
Description: “Επιτρέπει την κοινή χρήση βιβλιοθηκών του Windows Media Player με άλλες συσκευές αναπαραγωγής και συσκευές πολυμέσων του δικτύου χρησιμοποιώντας τη δυνατότητα Τοποθέτησης και Άμεσης Λειτουργίας γενικής χρήσης”
Network connectivity
UDP: LISTENING on port 5005
TCP: localhost on port 554
TCP: localhost on port 49798
TCP: localhost on port 50606
TCP: localhost on port 61133
TCP: localhost on port 53168
TCP: localhost on port 49194
TCP: 10.0.0.4 on port 61161
TCP: 192.168.1.1 on port 58625
TCP: 192.168.0.102 on port 51204
TCP: 192.168.1.2 on port 52869
TCP: localhost on port 56296
Image hashes
MD5: a9f3bfc9345f49614d5859ec95b9e994
SHA-1: 64638c3ff08eecd62e2b24708cf5b5f111c05e3d
SHA-256: 306467d280e99d0616e839278a4db5bed684f002ae284c3678cabb5251459cb3
PE image details
Langauge*: Microsoft Visual C++
File entropy: 6.45352
File packed: No
Import Table
advapi32.dll

EventRegister
EventUnregister
TraceMessage
GetTraceEnableFlags
GetTraceEnableLevel
GetTraceLoggerHandle
RegisterTraceGuidsW
UnregisterTraceGuids
EventWrite
RegCloseKey
RegOpenKeyExW
QueryServiceStatusEx
ControlService
SetServiceStatus
CloseServiceHandle
OpenServiceW
OpenSCManagerW
DeleteService
ChangeServiceConfig2W
CreateServiceW
RegisterServiceCtrlHandlerExW
StartServiceCtrlDispatcherW
GetSecurityDescriptorControl
MakeAbsoluteSD
GetSecurityDescriptorSacl
GetSecurityDescriptorDacl
GetSecurityDescriptorGroup
GetSecurityDescriptorOwner
InitializeSecurityDescriptor
RegDeleteValueW
RegCreateKeyExW
RegQueryValueExW
RegSetValueExW
GetLengthSid
IsValidSid
CopySid
AddAce
InitializeAcl
GetAclInformation
SetSecurityDescriptorDacl
ConvertSecurityDescriptorToStringSecurityDescriptorW
ConvertStringSidToSidW
RegSetKeySecurity
ConvertStringSecurityDescriptorToSecurityDescriptorW
EqualSid
GetNamedSecurityInfoW
RegEnumKeyExW
RegNotifyChangeKeyValue
RegGetValueW
DeregisterEventSource
ReportEventW
RegisterEventSourceW
FreeSid
SetNamedSecurityInfoW
SetEntriesInAclW
AllocateAndInitializeSid
LsaClose
LsaFreeMemory
LsaLookupNames2
LsaOpenPolicy
SetSecurityDescriptorGroup
SetSecurityDescriptorOwner
ConvertSidToStringSidW
ImpersonateLoggedOnUser
RevertToSelf
OpenProcessToken
GetTokenInformation
TraceEvent
LookupAccountSidW
ChangeServiceConfigW
StartServiceW
SetSecurityInfo
GetAce
GetSecurityInfo
SetSecurityDescriptorControl
LookupAccountNameW
RegDeleteKeyW
RegGetKeySecurity
RegQueryInfoKeyW
RegCreateKeyExA
RegQueryValueExA
RegSetValueExA
CryptGenRandom
CryptAcquireContextW
CreateWellKnownSid
SetFileSecurityW
GetFileSecurityW
OpenThreadToken
CryptReleaseContext
faultrep.dll

gdi32.dll

httpapi.dll

HttpInitialize
HttpTerminate
HttpSetServiceConfiguration
HttpDeleteServiceConfiguration
iphlpapi.dll

GetAdaptersAddresses
GetIpForwardTable
NotifyAddrChange
GetBestInterfaceEx
GetIpNetEntry2
SendARP
ResolveIpNetEntry2
CancelIPChangeNotify
GetIpAddrTable
CancelMibChangeNotify2
NotifyIpInterfaceChange
kernel32.dll
mfplat.dll

MFShutdown
MFStartup
MFInvokeCallback
MFCreateAsyncResult
CreatePropertyStore
msvcrt.dll
netapi32.dll

NetApiBufferFree
NetGetJoinInformation
NetShareGetInfo
ntdll.dll

NtQuerySystemTime
RtlFreeHeap
RtlAllocateHeap
RtlIpv4StringToAddressExW
RtlInitUnicodeString
RtlInitString
NtAllocateLocallyUniqueId
RtlFreeUnicodeString
RtlNtStatusToDosError
strchr
RtlUnwind
RtlGetVersion
ole32.dll

CoInitializeSecurity
CoInitializeEx
CoSetProxyBlanket
CoTaskMemFree
CoUninitialize
PropVariantClear
CoMarshalInterface
CreateStreamOnHGlobal
CoReleaseMarshalData
CoUnmarshalInterface
IIDFromString
CoTaskMemAlloc
PropVariantCopy
StringFromGUID2
CoCreateGuid
CoCreateInstance
CLSIDFromProgID
propsys.dll

PropVariantToString
PropVariantToStringAlloc
PSGetPropertyDescriptionByName
PSGetPropertyKeyFromName
InitPropVariantFromCLSID
shell32.dll

SHGetFolderPathW
SHCreateDirectoryExW
SHGetFolderPathAndSubDirW
SHGetKnownFolderItem
SHCreateItemWithParent
SHGetKnownFolderPath
SHCreateItemFromParsingName
shlwapi.dll

PathFileExistsW
StrCmpNW
PathFindFileNameW
StrStrIW
PathAppendW
HashData
PathRemoveExtensionW
PathFindExtensionW
PathCreateFromUrlW
SHStrDupW
SHDeleteKeyW
user32.dll

wvsprintfA
CharLowerBuffW
CharUpperBuffW
PeekMessageW
DispatchMessageW
CharNextA
TranslateMessage
MsgWaitForMultipleObjects
MsgWaitForMultipleObjectsEx
RegisterPowerSettingNotification
CharUpperW
wvsprintfW
UnregisterPowerSettingNotification
UnregisterClassA
userenv.dll

RegisterGPNotification
UnregisterGPNotification
winhttp.dll

WinHttpWriteData
WinHttpQueryHeaders
WinHttpAddRequestHeaders
WinHttpCrackUrl
WinHttpSetCredentials
WinHttpGetDefaultProxyConfiguration
WinHttpGetIEProxyConfigForCurrentUser
WinHttpGetProxyForUrl
WinHttpSetOption
WinHttpTimeFromSystemTime
WinHttpQueryDataAvailable
WinHttpCloseHandle
WinHttpReadData
WinHttpReceiveResponse
WinHttpSendRequest
WinHttpOpen
WinHttpSetTimeouts
WinHttpSetStatusCallback
WinHttpConnect
WinHttpOpenRequest
wmpmde.dll

MFCreateNetVRoot
MFCreateWMPMDEOpCenter
ws2_32.dll

GetAddrInfoW
getnameinfo
FreeAddrInfoW
wtsapi32.dll

WTSFreeMemory
WTSEnumerateSessionsW
WTSQuerySessionInformationW
xmllite.dll

CreateXmlReader
CreateXmlWriter