File details
File name: wmpnetwk.exe
Name: Windows Media Player Network Sharing Service
Description: Microsoft® Windows® Operating System
Version: 12.0.7600.16385 (win7_rtm.090713-1255)
Product version: 12.0.7600.16385
Size: 1.07 MB
Original file name: WMPNetwk.exe.mui
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0088033087%
Privileged CPU:
0.0041566200%

User CPU:
0.00464668866117%

Privileged CPU time: 116026778.34 ms
Privileged CPU time /min: 4,340 ms
CPU cycle count:
8,472,226
CPU cycle count /min: 53,203,094
Context switches /sec:
219
 | Memory utilization averages |
Committed memory:
114.41 MB
Peak committed memory: 130.13 MB
Paged memory:
9.66 MB
Peak paged memory: 23.46 MB
Paged system memory:
190.23 KB
Non-paged system memory: 19.48 KB
Working set memory:
7.62 MB
Peak working set memory: 20.91 MB
Min working set memory: 2.53 MB
Private memory:
9.66 MB
Page faults:
79,677
Page faults /min: 75
 | Process I/O averages |
Total read operations:
32,098
Read operations /min: 22
Total read transfer: 66.8 MB
Read transfer /min: 64.56 KB
Total write operations:
469
Write operations /min: 1
Total write transfer: 1.72 MB
Write transfer /min: 1.46 KB
Total other operations:
2,277,102
Other operations /min: 1,448
Total other transfer: 20.95 MB
Other Transfer /min: 34.51 KB
Resources
Handle count average: 406
Thread count average: 15
Thread resource averages
ntdll.dll

Total CPU: 0.519422304372%
Privileged CPU: 0.275287750766%
User CPU: 0.244134553607%
CPU Cycle count /sec: 12,468,444
Context switches /sec: 37
Module memory size: 1.23 MB
ole32.dll

Total CPU: 0.083499814509%
Privileged CPU: 0.083217558167%
User CPU: 0.000282256342%
CPU Cycle count /sec: 1,678,361
Context switches /sec: 26
Module memory size: 1.36 MB
wmp.dll

Total CPU: 0.044046022754%
Privileged CPU: 0.026582421740%
User CPU: 0.017463601014%
CPU Cycle count /sec: 1,211,035
Context switches /sec: 3
Module memory size: 10.95 MB
ole32.dll

Total CPU: 0.012782707870%
Privileged CPU: 0.009120325101%
User CPU: 0.003662382768%
CPU Cycle count /sec: 359,880
Context switches /sec: 1
Module memory size: 1.36 MB
sechost.dll

Total CPU: 0.009691209948%
Privileged CPU: 0.004080821334%
User CPU: 0.005610388614%
CPU Cycle count /sec: 204,972
Module memory size: 100 KB
ntdll.dll

Total CPU: 0.007824120829%
Privileged CPU: 0.001780193658%
User CPU: 0.006043927171%
CPU Cycle count /sec: 122,660
Module memory size: 1.23 MB
npggnt.des

Total CPU: 0.005369978755%
Privileged CPU: 0.000000000000%
User CPU: 0.005369978755%
CPU Cycle count /sec: 101,341
Module memory size: 256 KB
Total CPU: 0.002209050887%
Privileged CPU: 0.001140542444%
User CPU: 0.001068508442%
CPU Cycle count /sec: 315,944
Context switches /sec: 8
Module memory size: 352 KB
ntdll.dll

Total CPU: 0.001095575797%
Privileged CPU: 0.001000669814%
User CPU: 0.000094905983%
CPU Cycle count /sec: 22,443
Module memory size: 1.23 MB
Total CPU: 0.001043682901%
Privileged CPU: 0.000845002349%
User CPU: 0.000198680552%
CPU Cycle count /sec: 18,705
Module memory size: 1.09 MB
ntdll.dll

Total CPU: 0.000742824327%
Privileged CPU: 0.000619020273%
User CPU: 0.000123804055%
CPU Cycle count /sec: 28,122
Module memory size: 1.24 MB
Total CPU: 0.000476321416%
Privileged CPU: 0.000190528655%
User CPU: 0.000285792760%
CPU Cycle count /sec: 472,724
Context switches /sec: 16
Module memory size: 316 KB
gdiplus.dll

Total CPU: 0.000204464735%
Privileged CPU: 0.000191327545%
User CPU: 0.000013137190%
CPU Cycle count /sec: 274
Module memory size: 1.56 MB
Total CPU: 0.000106259594%
Privileged CPU: 0.000057721834%
User CPU: 0.000048537761%
CPU Cycle count /sec: 397,598
Context switches /sec: 16
Module memory size: 688 KB
wmdrmdev.dll

Total CPU: 0.000092040560%
Privileged CPU: 0.000018408112%
User CPU: 0.000073632448%
CPU Cycle count /sec: 2,386
Module memory size: 504 KB
ssdpapi.dll

Total CPU: 0.000057372793%
Privileged CPU: 0.000040946843%
User CPU: 0.000016425950%
CPU Cycle count /sec: 871
Module memory size: 52 KB
gdiplus.dll

Total CPU: 0.000047406998%
Privileged CPU: 0.000041900887%
User CPU: 0.000005506111%
CPU Cycle count /sec: 96
Module memory size: 1.56 MB
Process details
Runs as (owner): Network Service
Integrety level: System
Windows platform: 32-bit
Runs as a service: Yes
Parent Process
Process Commands
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
Service details
Name: Υπηρεσία κοινής χρήσης δικτύου του Windows Media Player
Service name: WMPNetworkSvc
Service type:
Win32OwnProcess
Description: “Επιτρέπει την κοινή χρήση βιβλιοθηκών του Windows Media Player με άλλες συσκευές αναπαραγωγής και συσκευές πολυμέσων του δικτύου χρησιμοποιώντας τη δυνατότητα Τοποθέτησης και Άμεσης Λειτουργίας γενικής χρήσης”
Network connectivity
UDP: LISTENING on port 5005
TCP: localhost on port 554
TCP: localhost on port 64957
TCP: localhost on port 63710
TCP: localhost on port 55431
TCP: localhost on port 61692
TCP: localhost on port 61925
TCP: localhost on port 55655
Image hashes
MD5: 3b40d3a61aa8c21b88ae57c58ab3122e
SHA-1: 77298efb673f13c768924f67724e4201a4dbc6c0
SHA-256: 6c67dcb007c3cdf2eb0bbf5fd89c32cd7800c20f7166872f8c387be262c5cd21
PE image details
Langauge*: Microsoft Visual C++
File entropy: 6.45352
File packed: No
Import Table
advapi32.dll

EventRegister
EventUnregister
TraceMessage
GetTraceEnableFlags
GetTraceEnableLevel
GetTraceLoggerHandle
RegisterTraceGuidsW
UnregisterTraceGuids
EventWrite
RegCloseKey
RegOpenKeyExW
QueryServiceStatusEx
ControlService
SetServiceStatus
CloseServiceHandle
OpenServiceW
OpenSCManagerW
DeleteService
ChangeServiceConfig2W
CreateServiceW
RegisterServiceCtrlHandlerExW
StartServiceCtrlDispatcherW
GetSecurityDescriptorControl
MakeAbsoluteSD
GetSecurityDescriptorSacl
GetSecurityDescriptorDacl
GetSecurityDescriptorGroup
GetSecurityDescriptorOwner
InitializeSecurityDescriptor
RegDeleteValueW
RegCreateKeyExW
RegQueryValueExW
RegSetValueExW
GetLengthSid
IsValidSid
CopySid
AddAce
InitializeAcl
GetAclInformation
SetSecurityDescriptorDacl
ConvertSecurityDescriptorToStringSecurityDescriptorW
ConvertStringSidToSidW
RegSetKeySecurity
ConvertStringSecurityDescriptorToSecurityDescriptorW
EqualSid
GetNamedSecurityInfoW
RegEnumKeyExW
RegNotifyChangeKeyValue
RegGetValueW
DeregisterEventSource
ReportEventW
RegisterEventSourceW
FreeSid
SetNamedSecurityInfoW
SetEntriesInAclW
AllocateAndInitializeSid
LsaClose
LsaFreeMemory
LsaLookupNames2
LsaOpenPolicy
SetSecurityDescriptorGroup
SetSecurityDescriptorOwner
ConvertSidToStringSidW
ImpersonateLoggedOnUser
RevertToSelf
OpenProcessToken
GetTokenInformation
TraceEvent
LookupAccountSidW
ChangeServiceConfigW
StartServiceW
SetSecurityInfo
GetAce
GetSecurityInfo
SetSecurityDescriptorControl
LookupAccountNameW
RegDeleteKeyW
RegGetKeySecurity
RegQueryInfoKeyW
RegCreateKeyExA
RegQueryValueExA
RegSetValueExA
CryptGenRandom
CryptAcquireContextW
CreateWellKnownSid
SetFileSecurityW
GetFileSecurityW
OpenThreadToken
CryptReleaseContext
faultrep.dll

gdi32.dll

httpapi.dll

HttpInitialize
HttpTerminate
HttpSetServiceConfiguration
HttpDeleteServiceConfiguration
iphlpapi.dll

GetAdaptersAddresses
GetIpForwardTable
NotifyAddrChange
GetBestInterfaceEx
GetIpNetEntry2
SendARP
ResolveIpNetEntry2
CancelIPChangeNotify
GetIpAddrTable
CancelMibChangeNotify2
NotifyIpInterfaceChange
kernel32.dll
mfplat.dll

MFShutdown
MFStartup
MFInvokeCallback
MFCreateAsyncResult
CreatePropertyStore
msvcrt.dll
netapi32.dll

NetApiBufferFree
NetGetJoinInformation
NetShareGetInfo
ntdll.dll

NtQuerySystemTime
RtlFreeHeap
RtlAllocateHeap
RtlIpv4StringToAddressExW
RtlInitUnicodeString
RtlInitString
NtAllocateLocallyUniqueId
RtlFreeUnicodeString
RtlNtStatusToDosError
strchr
RtlUnwind
RtlGetVersion
ole32.dll

CoInitializeSecurity
CoInitializeEx
CoSetProxyBlanket
CoTaskMemFree
CoUninitialize
PropVariantClear
CoMarshalInterface
CreateStreamOnHGlobal
CoReleaseMarshalData
CoUnmarshalInterface
IIDFromString
CoTaskMemAlloc
PropVariantCopy
StringFromGUID2
CoCreateGuid
CoCreateInstance
CLSIDFromProgID
propsys.dll

PropVariantToString
PropVariantToStringAlloc
PSGetPropertyDescriptionByName
PSGetPropertyKeyFromName
InitPropVariantFromCLSID
shell32.dll

SHGetFolderPathW
SHCreateDirectoryExW
SHGetFolderPathAndSubDirW
SHGetKnownFolderItem
SHCreateItemWithParent
SHGetKnownFolderPath
SHCreateItemFromParsingName
shlwapi.dll

PathFileExistsW
StrCmpNW
PathFindFileNameW
StrStrIW
PathAppendW
HashData
PathRemoveExtensionW
PathFindExtensionW
PathCreateFromUrlW
SHStrDupW
SHDeleteKeyW
user32.dll

wvsprintfA
CharLowerBuffW
CharUpperBuffW
PeekMessageW
DispatchMessageW
CharNextA
TranslateMessage
MsgWaitForMultipleObjects
MsgWaitForMultipleObjectsEx
RegisterPowerSettingNotification
CharUpperW
wvsprintfW
UnregisterPowerSettingNotification
UnregisterClassA
userenv.dll

RegisterGPNotification
UnregisterGPNotification
winhttp.dll

WinHttpWriteData
WinHttpQueryHeaders
WinHttpAddRequestHeaders
WinHttpCrackUrl
WinHttpSetCredentials
WinHttpGetDefaultProxyConfiguration
WinHttpGetIEProxyConfigForCurrentUser
WinHttpGetProxyForUrl
WinHttpSetOption
WinHttpTimeFromSystemTime
WinHttpQueryDataAvailable
WinHttpCloseHandle
WinHttpReadData
WinHttpReceiveResponse
WinHttpSendRequest
WinHttpOpen
WinHttpSetTimeouts
WinHttpSetStatusCallback
WinHttpConnect
WinHttpOpenRequest
wmpmde.dll

MFCreateNetVRoot
MFCreateWMPMDEOpCenter
ws2_32.dll

GetAddrInfoW
getnameinfo
FreeAddrInfoW
wtsapi32.dll

WTSFreeMemory
WTSEnumerateSessionsW
WTSQuerySessionInformationW
xmllite.dll

CreateXmlReader
CreateXmlWriter