File details
File name: WUDFHost.exe
Name: Windows Driver Foundation - User-mode Driver Framework Host Process
Description: Microsoft® Windows® Operating System
Version: 6.2.9200.16384 (win8_rtm.120725-1247)
Product version: 6.2.9200.16384
Size: 224.5 KB
Original file name: WUDFHost.exe.mui
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0021282628%
Privileged CPU:
0.0013424043%

User CPU:
0.00078585843762%

Privileged CPU time: 2290518.78 ms
Privileged CPU time /min: 21 ms
CPU cycle count:
189,026,614
CPU cycle count /min: 7,165,413
Context switches /sec:
8
 | Memory utilization averages |
Committed memory:
51.64 MB
Peak committed memory: 81.74 MB
Paged memory:
2.61 MB
Peak paged memory: 3.58 MB
Paged system memory:
89.93 KB
Non-paged system memory: 11 KB
Working set memory:
4.65 MB
Peak working set memory: 6.97 MB
Min working set memory: 4.14 MB
Private memory:
2.61 MB
Page faults:
7,491
Page faults /min: 10
 | Process I/O averages |
Total read operations:
4,243
Read operations /min: 1
Total read transfer: 16.86 MB
Read transfer /min: 1.19 KB
Total write operations:
126
Write operations /min: 1
Total write transfer: 716 KB
Write transfer /min: 336 Bytes
Total other operations:
54,023
Other operations /min: 4
Total other transfer: 12.32 MB
Other Transfer /min: 935 Bytes
Resources
Handle count average: 249
Thread count average: 8
Thread resource averages
Total CPU: 0.074357138605%
Privileged CPU: 0.066981632936%
User CPU: 0.007375505668%
CPU Cycle count /sec: 1,645,698
Module memory size: 440 KB
ntdll.dll

Total CPU: 0.057030432514%
Privileged CPU: 0.024808157781%
User CPU: 0.032222274733%
CPU Cycle count /sec: 1,121,977
Context switches /sec: 3
Module memory size: 1.74 MB
ntdll.dll

Total CPU: 0.032299092108%
Privileged CPU: 0.012138858611%
User CPU: 0.020160233497%
CPU Cycle count /sec: 639,497
Context switches /sec: 3
Module memory size: 1.66 MB
combase.dll

Total CPU: 0.031898191291%
Privileged CPU: 0.014499177859%
User CPU: 0.017399013431%
CPU Cycle count /sec: 377,148
Context switches /sec: 4
Module memory size: 1.69 MB
Total CPU: 0.015897060226%
Privileged CPU: 0.009563954332%
User CPU: 0.006333105894%
CPU Cycle count /sec: 433,601
Context switches /sec: 1
Module memory size: 660 KB
msvcrt.dll

Total CPU: 0.011444958581%
Privileged CPU: 0.000787957885%
User CPU: 0.010657000696%
CPU Cycle count /sec: 1,963,669
Context switches /sec: 34
Module memory size: 636 KB
tcwbf.dll

Total CPU: 0.006257025726%
Privileged CPU: 0.000243786648%
User CPU: 0.006013239079%
CPU Cycle count /sec: 314,636
Context switches /sec: 8
Module memory size: 992 KB
Total CPU: 0.004937615891%
Privileged CPU: 0.001346622516%
User CPU: 0.003590993375%
CPU Cycle count /sec: 1,126,647
Module memory size: 100 KB
wpdfs.dll

Total CPU: 0.001782879264%
Privileged CPU: 0.001347740957%
User CPU: 0.000435138306%
CPU Cycle count /sec: 46,722
Module memory size: 304 KB
Total CPU: 0.001471044094%
Privileged CPU: 0.000966511147%
User CPU: 0.000504532947%
CPU Cycle count /sec: 38,257
Module memory size: 240 KB
msvcr80.dll

Total CPU: 0.001388675991%
Privileged CPU: 0.000491468760%
User CPU: 0.000897207230%
CPU Cycle count /sec: 372,545
Context switches /sec: 4
Module memory size: 804 KB
wpdfs.dll

Total CPU: 0.000600686369%
Privileged CPU: 0.000501203600%
User CPU: 0.000099482769%
CPU Cycle count /sec: 13,225
Module memory size: 304 KB
Total CPU: 0.000457838918%
Privileged CPU: 0.000196216679%
User CPU: 0.000261622239%
CPU Cycle count /sec: 127,416
Context switches /sec: 8
Module memory size: 88 KB
ntdll.dll

Total CPU: 0.000380186818%
Privileged CPU: 0.000118323255%
User CPU: 0.000261863563%
CPU Cycle count /sec: 13,830
Module memory size: 1.74 MB
zunemtpz.dll

Total CPU: 0.000235849617%
Privileged CPU: 0.000235849617%
User CPU: 0.000000000000%
CPU Cycle count /sec: 13,162
Module memory size: 260 KB
wpdfs.dll

Total CPU: 0.000215709583%
Privileged CPU: 0.000168109222%
User CPU: 0.000047600361%
CPU Cycle count /sec: 5,354
Module memory size: 292 KB
sensorsclassextension.dll

Total CPU: 0.000213633701%
Privileged CPU: 0.000189712911%
User CPU: 0.000023920790%
CPU Cycle count /sec: 4,835
Module memory size: 136 KB
ntdll.dll

Total CPU: 0.000199007800%
Privileged CPU: 0.000102029956%
User CPU: 0.000096977844%
CPU Cycle count /sec: 95,409
Module memory size: 1.75 MB
sensorsalsdriver.dll

Total CPU: 0.000114911867%
Privileged CPU: 0.000009502234%
User CPU: 0.000105409633%
CPU Cycle count /sec: 2,313
Module memory size: 60 KB
sensorsalsdriver.dll

Total CPU: 0.000096412321%
Privileged CPU: 0.000023562065%
User CPU: 0.000072850256%
CPU Cycle count /sec: 1,759
Module memory size: 76 KB
Process details
Runs as (owner): Local Service
Integrety level: Undefined
Windows platform: 64-bit
Parent Processes
Process Commands
"C:\Windows\System32\WUDFHost.exe" -HostGUIC:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortNamC:HostProcess-bd9c81f9-de15-4b0e-ba9c-fee86ea7d93f -SystemEventPortNamC:HostProcess-a1fe8232-60eb-4b3c-a35d-c430f9d96668 -IoCancelEventPortNamC:HostProcess-28e081a3-e4e5-4473-a569-1e959ea2d541 -NonStateChangingEventPortNamC:HostProcess-5e7f03f5-dcf4-4203-af68-fea703352533 -ServiceSIC:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeIC:552f1c78-7795-4a85-bcdc-076e667de80b -Devi
"C:\Windows\System32\WUDFHost.exe" -HostGUIC:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortNamC:HostProcess-1af3e9d4-f1fd-4d88-86c7-0fc6949b7684 -SystemEventPortNamC:HostProcess-ddded7bc-bad7-4871-9998-fa7f14a8cfcb -IoCancelEventPortNamC:HostProcess-1a499224-224b-4c82-9904-0bc241a3adc2 -NonStateChangingEventPortNamC:HostProcess-df8c8ec0-6be3-458d-b227-e39a055c9d5f -ServiceSIC:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeIC:0734fc36-f1e8-4d44-ab14-f8ce87c2a04d -Devi
"C:\Windows\System32\WUDFHost.exe" -HostGUIC:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortNamC:HostProcess-29c4e6e9-0b0e-4873-b630-ffd2b66fe327 -SystemEventPortNamC:HostProcess-450d99a1-1f03-4607-b15a-229e474d417d -IoCancelEventPortNamC:HostProcess-6a08d51c-ff5e-48a5-868e-ad3695639ed4 -NonStateChangingEventPortNamC:HostProcess-4dac4764-df9f-4daf-9697-38d86dbe49d0 -ServiceSIC:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeIC:99eb2048-cc06-4e0d-aadd-87c7ca31447d -Devi
"C:\Windows\System32\WUDFHost.exe" -HostGUIC:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortNamC:HostProcess-979d3c6e-96e3-48a5-a191-48ed049b65e1 -SystemEventPortNamC:HostProcess-30fb6778-0872-403c-acb6-92e3bb400104 -IoCancelEventPortNamC:HostProcess-ae599049-3344-4544-9a1a-5cbf43ff251b -NonStateChangingEventPortNamC:HostProcess-1d021a77-f3fe-4804-a607-d1f4dfa8eca7 -ServiceSIC:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeIC:f19ec7c6-8a89-4f5c-8344-87eb17eb6ff3 -Devi
"C:\Windows\System32\WUDFHost.exe" -HostGUIC:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortNamC:HostProcess-955c4d3d-1700-4dbb-b6c9-8c04ee93fe1e -SystemEventPortNamC:HostProcess-1ce13438-bc2d-4877-b2ce-afede8498c02 -IoCancelEventPortNamC:HostProcess-a8986160-d93f-410a-b0b6-7f0278ee61be -NonStateChangingEventPortNamC:HostProcess-4f821528-c09e-430a-8e9c-377b491777af -ServiceSIC:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeIC:9b574ca9-cd0d-46e4-b96b-3d0df4a020ef -Devi
Image hashes
MD5: 8abfe00f213f2571498f1b8fd7939a98
SHA-1: 803e2aa7eb71676c3d0981fa01be9a38ffaf050d
SHA-256: b557ec9efd33612bafe01ffd304b50efb8c3c19763470560da950b5ab4a9ac9c
PE image details
Langauge*: Microsoft Visual C++
File entropy: 5.85629
File packed: No
Import Table
advapi32.dll

GetTraceEnableFlags
GetTraceEnableLevel
GetTraceLoggerHandle
RegisterTraceGuidsW
TraceMessage
UnregisterTraceGuids
RegQueryValueExW
RegCloseKey
RegOpenKeyExW
TraceEvent
ConvertStringSidToSidW
RegSetValueExW
RevertToSelf
EventRegister
EventWrite
EventUnregister
EventActivityIdControl
api-ms-win-core-com-l1-1-1.dll

CLSIDFromString
CoInitializeEx
CoUninitialize
api-ms-win-core-errorhandling-l1-1-1.dll

SetLastError
GetLastError
RaiseException
SetUnhandledExceptionFilter
UnhandledExceptionFilter
api-ms-win-core-file-l1-2-1.dll

CreateFileW
WriteFile
FlushFileBuffers
ReadFile
api-ms-win-core-handle-l1-1-0.dll

api-ms-win-core-heap-l1-2-0.dll

HeapAlloc
GetProcessHeap
HeapFree
HeapSetInformation
api-ms-win-core-heap-obsolete-l1-1-0.dll

api-ms-win-core-io-l1-1-1.dll

GetOverlappedResult
DeviceIoControl
api-ms-win-core-libraryloader-l1-1-1.dll

LoadLibraryExW
GetModuleHandleA
GetProcAddress
LoadLibraryExA
FreeLibrary
api-ms-win-core-namedpipe-l1-2-0.dll

WaitNamedPipeW
SetNamedPipeHandleState
TransactNamedPipe
api-ms-win-core-processenvironment-l1-2-0.dll

SetEnvironmentVariableW
ExpandEnvironmentStringsW
api-ms-win-core-processthreads-l1-1-2.dll

GetCurrentThread
TlsFree
GetCurrentProcess
TlsSetValue
GetCurrentProcessId
TlsAlloc
TlsGetValue
GetCurrentThreadId
TerminateProcess
CreateThread
api-ms-win-core-profile-l1-1-0.dll

api-ms-win-core-registry-l1-1-0.dll

RegCloseKey
RegQueryValueExW
RegSetValueExW
RegOpenKeyExW
api-ms-win-core-rtlsupport-l1-2-0.dll

api-ms-win-core-synch-l1-2-0.dll

DeleteCriticalSection
InitializeCriticalSection
Sleep
WaitForSingleObject
CreateEventW
EnterCriticalSection
SetEvent
WaitForMultipleObjectsEx
InitializeCriticalSectionAndSpinCount
LeaveCriticalSection
api-ms-win-core-sysinfo-l1-2-1.dll

GetTickCount
GetSystemTimeAsFileTime
GetSystemDirectoryW
GetOsSafeBootMode
api-ms-win-core-threadpool-l1-2-0.dll

SetThreadpoolThreadMinimum
SetThreadpoolThreadMaximum
CloseThreadpool
CreateThreadpool
CreateThreadpoolWait
SetThreadpoolWait
WaitForThreadpoolWaitCallbacks
CloseThreadpoolWait
CloseThreadpoolCleanupGroupMembers
CloseThreadpoolCleanupGroup
CreateThreadpoolCleanupGroup
api-ms-win-eventing-classicprovider-l1-1-0.dll

TraceMessage
RegisterTraceGuidsW
GetTraceEnableFlags
GetTraceEnableLevel
UnregisterTraceGuids
GetTraceLoggerHandle
api-ms-win-eventing-provider-l1-1-0.dll

EventActivityIdControl
EventUnregister
EventWrite
EventRegister
api-ms-win-security-base-l1-2-0.dll

api-ms-win-security-sddl-l1-1-0.dll

devobj.dll

DevObjGetDeviceRegistryProperty
DevObjCreateDeviceInfoList
DevObjOpenDevRegKey
DevObjGetDeviceInstanceId
DevObjDestroyDeviceInfoList
DevObjEnumDeviceInfo
DevObjGetClassDevs
kernel32.dll

GetProcAddress
GetModuleHandleW
GetVersionExW
WaitForSingleObject
CloseHandle
TlsFree
GetLastError
TlsGetValue
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
TlsSetValue
TlsAlloc
InitializeCriticalSectionAndSpinCount
GetSystemDirectoryW
HeapSetInformation
InterlockedIncrement
InterlockedDecrement
InterlockedCompareExchange
CreateThread
LocalFree
CreateEventW
SetEvent
GetOverlappedResult
DeviceIoControl
CreateFileW
SetEnvironmentVariableW
InitializeCriticalSection
InterlockedExchange
BindIoCompletionCallback
FreeLibrary
LoadLibraryExW
GetCurrentProcessId
HeapFree
HeapAlloc
GetProcessHeap
FlushFileBuffers
Sleep
ReadFile
WriteFile
GetCurrentThread
VerifyVersionInfoW
VerSetConditionMask
LocalAlloc
LoadLibraryA
RaiseException
UnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
GetSystemTimeAsFileTime
GetCurrentThreadId
GetTickCount
QueryPerformanceCounter
GetModuleHandleA
SetUnhandledExceptionFilter
OutputDebugStringA
RtlCaptureContext
WaitNamedPipeW
SetNamedPipeHandleState
TransactNamedPipe
ExpandEnvironmentStringsW
SetThreadpoolThreadMinimum
SetThreadpoolThreadMaximum
CloseThreadpool
CreateThreadpool
CreateThreadpoolWait
SetThreadpoolWait
WaitForThreadpoolWaitCallbacks
CloseThreadpoolWait
WaitForMultipleObjects
LoadLibraryExA
msvcrt.dll
ntdll.dll

DbgPrintEx
RtlNtStatusToDosError
NtQueryInformationFile
RtlUnwind
NtSetInformationFile
RtlInitUnicodeString
RtlSetIoCompletionCallback
VerSetConditionMask
RtlVerifyVersionInfo
ole32.dll

CoInitializeEx
CLSIDFromString
CoUninitialize
rpcrt4.dll

user32.dll

wudfplatform.dll

GetAndInitializePlatformObject
ShutdownPlatformLibrary
WudfWaitForDebugger
WudfDebugBreakPoint
WudfIsUserDebuggerPresent
WdfGetLpcInterface
InitializePlatformLibrary
WudfIsKernelDebuggerPresent