File details
File name: realplay.exe
Name: RealPlayer (32-bit)
Description: RealPlayer
Version: 16.0.1.18
Size: 489.58 KB
Original file name: REALPLAY.EXE
Digital certificate
Certificate authority:
Thawte
Expiration date: 8/16/2011
Resource utilization
 | CPU utilization averages |
Total CPU: 1.2632104238%
Privileged CPU:
0.5097096895%

User CPU:
0.75350073431700%

Privileged CPU time: 2347.82 ms
Privileged CPU time /min: 10 ms
CPU cycle count:
1,194,060,014
CPU cycle count /min: 210,847,464
 | Memory utilization averages |
Committed memory:
294.18 MB
Peak committed memory: 324.27 MB
Paged memory:
40.07 MB
Peak paged memory: 49.92 MB
Paged system memory:
486.51 KB
Non-paged system memory: 63.64 KB
Working set memory:
8.9 MB
Peak working set memory: 53.29 MB
Min working set memory: 5.68 MB
Private memory:
40.07 MB
Page faults:
50,902
Page faults /min: 213
 | Process I/O averages |
Total read operations:
9,898
Read operations /min: 41
Total read transfer: 90.17 MB
Read transfer /min: 386.71 KB
Total write operations:
206
Write operations /min: 1
Total write transfer: 666.76 KB
Write transfer /min: 2.79 KB
Total other operations:
15,777
Other operations /min: 66
Total other transfer: 238.33 KB
Other Transfer /min: 1022 Bytes
 | GUI Object Averages |
GDI objects:
96
Peak GDI objects: 103
USER objects:
154
Peak USER objects: 204
Resources
Handle count average: 658
Thread count average: 27
Thread resource averages
Total CPU: 0.004313135819%
Privileged CPU: 0.002113258477%
User CPU: 0.002199877342%
CPU Cycle count /sec: 226,161
Context switches /sec: 4
Module memory size: 804 KB
wow64win.dll

Total CPU: 0.000129745323%
Privileged CPU: 0.000086492630%
User CPU: 0.000043252693%
CPU Cycle count /sec: 4,326
Module memory size: 360 KB
Process details
Runs as (owner): User
Integrety level: Medium
Windows platform: 64-bit
Parent Processes
Child Process
Process Commands
"C:\Program Files\real\realplayer\RealPlay.exe" /launcC:desktop
"C:\Program Files\real\realplayer\\RealPlay.exe" /runevent "C:\Program Files\Real\RealPlayer\rpwa3260.dll" WatchFolders_Timer
Autoplay handler details
Name: RPPlayMediaOnArrival
Command: SOFTWARE\Microsoft\Windows\ CurrentVersion\Explorer\AutoplayHandlers\Handlers\RPPlayMediaOnArrival
Scheduled task details
CLSID: {CAF98FFB-8246-4180-8543-CE4146F5E2AE}
Command: \{CAF98FFB-8246-4180-8543-CE4146F5E2AE}
Startup files (all users) run details
Name: RealTray
Command: C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
Network connectivity
UDP: LISTENING on port 52828
Windows Firewall allowed program: Yes
Image hashes
MD5: 56d1d4ba99d1a18cdfe35d65f1752b52
SHA-1: e04b3784473fc2c11718bf8c435c9d7bd37be717
SHA-256: 457538bcf00beb9191ebb0766f8e6f9408c64aac39b86c6f02724ab7138a8ccf
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++ 9.0
File packed: No
Import Table
advapi32.dll

RegEnumKeyExA
RegCreateKeyExA
RegQueryInfoKeyA
RegEnumKeyA
RegDeleteKeyA
RegQueryValueA
RegDeleteValueA
RegOpenKeyA
RegOpenKeyExA
RegQueryValueExA
RegCloseKey
RegCreateKeyA
RegSetValueA
RegSetValueExA
RegCreateKeyW
RegSetValueW
RegOpenKeyW
RegQueryValueW
gdi32.dll

kernel32.dll

GetEnvironmentVariableA
GetProcAddress
LoadLibraryA
GetModuleHandleA
GetTickCount
InterlockedIncrement
InterlockedDecrement
FreeLibrary
QueryPerformanceCounter
QueryPerformanceFrequency
GetVersionExA
CreateFileA
FindClose
CreateDirectoryA
MoveFileA
GetSystemInfo
GetVersion
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
GetModuleHandleExA
GetCurrentThreadId
RaiseException
Sleep
FindFirstFileW
GetModuleFileNameA
GetCurrentProcessId
SizeofResource
LockResource
LoadResource
FindResourceA
FindResourceExA
SetCurrentDirectoryA
GetCurrentDirectoryA
IsBadWritePtr
VirtualProtect
IsBadReadPtr
SetUnhandledExceptionFilter
TerminateThread
CreateThread
GetCurrentProcess
WriteFile
GetThreadContext
VirtualQuery
OpenProcess
SetFilePointer
GlobalMemoryStatus
UnmapViewOfFile
MapViewOfFile
CreateFileMappingA
GetSystemTimeAsFileTime
IsDebuggerPresent
UnhandledExceptionFilter
TerminateProcess
GetStartupInfoA
InterlockedCompareExchange
InterlockedExchange
GetProcessHeap
HeapSize
HeapReAlloc
HeapFree
HeapAlloc
HeapDestroy
SetEnvironmentVariableA
GetCommandLineW
WideCharToMultiByte
GetLastError
DeleteFileA
CreateMutexA
ReleaseMutex
CloseHandle
OpenMutexA
WaitForSingleObject
SetErrorMode
SetEvent
ResetEvent
CreateEventA
FindResourceW
FindResourceExW
lstrlenW
MultiByteToWideChar
GetStartupInfoW
HeapSetInformation
DecodePointer
EncodePointer
InitializeCriticalSectionAndSpinCount
lstrlenA
ExitProcess
GlobalAddAtomA
GlobalDeleteAtom
msvcp100.dll
msvcp71.dll
msvcp90.dll
msvcr100.dll
msvcr71.dll
msvcr90.dll
ole32.dll

OleInitialize
OleUninitialize
pncrt.dll

strrchr
strstr
_controlfp
_except_handler3
__set_app_type
__p__fmode
__p__commode
_adjust_fdiv
_putenv
_initterm
__getmainargs
__setusermatherr
printf
_assert
sprintf
getenv
_purecall
memmove
strchr
exit
_acmdln
__dllonexit
_onexit
_exit
_XcptFilter
shell32.dll

SHGetFolderPathA
SHGetFolderPathW
SHCreateDirectoryExW
SHCreateDirectoryExA
shlwapi.dll

PathAddBackslashA
PathAppendA
PathAppendW
PathAddBackslashW
user32.dll

GetDC
ReleaseDC
RegisterWindowMessageA
RegisterClassExA
GetClassInfoExA
CreateWindowExA
DefWindowProcA
PostThreadMessageA
DestroyWindow
UnregisterClassA
CharPrevA
CharNextA
GetSystemMetrics
SetMessageQueue
EnumWindows
GetPropA
SendMessageA
version.dll

VerQueryValueA
GetFileVersionInfoA