File details
File name: realplay.exe
Name: RealPlayer (32-bit)
Description: RealPlayer
Version: 15.0.6.14
Size: 487.65 KB
Original file name: REALPLAY.EXE
Digital certificate
Certificate authority:
Thawte
Expiration date: 8/16/2011
Resource utilization
 | CPU utilization averages |
Total CPU: 0.1391809948%
Privileged CPU:
0.0385361362%

User CPU:
0.10064485866623%

Privileged CPU time: 7574.33 ms
Privileged CPU time /min: 24 ms
CPU cycle count:
1,203,980,987
CPU cycle count /min: 297,265,601
Context switches /sec:
561
 | Memory utilization averages |
Committed memory:
305.52 MB
Peak committed memory: 336.81 MB
Paged memory:
76.12 MB
Peak paged memory: 94.08 MB
Paged system memory:
328.37 KB
Non-paged system memory: 58.94 KB
Working set memory:
11.67 MB
Peak working set memory: 72.52 MB
Min working set memory: 7.32 MB
Private memory:
76.12 MB
Page faults:
839,849
Page faults /min: 3,939
 | Process I/O averages |
Total read operations:
82,408
Read operations /min: 353
Total read transfer: 140.4 MB
Read transfer /min: 624.16 KB
Total write operations:
2,415
Write operations /min: 11
Total write transfer: 3.73 MB
Write transfer /min: 17.92 KB
Total other operations:
292,142
Other operations /min: 1,343
Total other transfer: 13.32 MB
Other Transfer /min: 58.24 KB
 | GUI Object Averages |
GDI objects:
300
Peak GDI objects: 320
USER objects:
322
Peak USER objects: 370
Resources
Handle count average: 920
Thread count average: 39
Thread resource averages
Total CPU: 0.240366497014%
Privileged CPU: 0.066344921487%
User CPU: 0.174021575527%
CPU Cycle count /sec: 16,746,794
Context switches /sec: 100
Module memory size: 804 KB
ntdll.dll

Total CPU: 0.102109645875%
Privileged CPU: 0.102109645875%
User CPU: 0.000000000000%
CPU Cycle count /sec: 1,340,531
Context switches /sec: 1
Module memory size: 1.23 MB
Total CPU: 0.015588884625%
Privileged CPU: 0.015588884625%
User CPU: 0.000000000000%
CPU Cycle count /sec: 678,274
Context switches /sec: 20
Module memory size: 316 KB
wow64.dll

Total CPU: 0.006422168586%
Privileged CPU: 0.000212212846%
User CPU: 0.006209955740%
CPU Cycle count /sec: 332,819
Module memory size: 252 KB
msvcr90.dll

Total CPU: 0.006210699533%
Privileged CPU: 0.002717995230%
User CPU: 0.003492704302%
CPU Cycle count /sec: 580,500
Context switches /sec: 19
Module memory size: 652 KB
Total CPU: 0.005722838944%
Privileged CPU: 0.005722838944%
User CPU: 0.000000000000%
CPU Cycle count /sec: 92,384
Module memory size: 1.41 MB
wininet.dll

Total CPU: 0.004933456808%
Privileged CPU: 0.004933456808%
User CPU: 0.000000000000%
CPU Cycle count /sec: 138,886
Module memory size: 980 KB
msvcr90.dll

Total CPU: 0.004808046602%
Privileged CPU: 0.002726615034%
User CPU: 0.002081431568%
CPU Cycle count /sec: 614,507
Context switches /sec: 21
Module memory size: 652 KB
msvcr90.dll

Total CPU: 0.004425335393%
Privileged CPU: 0.002382722911%
User CPU: 0.002042612482%
Context switches /sec: 32
Module memory size: 652 KB
Total CPU: 0.003954908216%
Privileged CPU: 0.001232812050%
User CPU: 0.002722096166%
CPU Cycle count /sec: 71,079
Module memory size: 5.71 MB
Total CPU: 0.003587701797%
Privileged CPU: 0.003075172969%
User CPU: 0.000512528828%
Context switches /sec: 189
Module memory size: 2.93 MB
ole32.dll

Total CPU: 0.001021779353%
Privileged CPU: 0.000510889677%
User CPU: 0.000510889677%
Module memory size: 1.23 MB
gdiplus.dll

Total CPU: 0.001001739939%
Privileged CPU: 0.001001739939%
User CPU: 0.000000000000%
CPU Cycle count /sec: 40,960
Context switches /sec: 8
Module memory size: 1.56 MB
ntdll.dll

Total CPU: 0.000641581914%
Privileged CPU: 0.000499008155%
User CPU: 0.000142573759%
CPU Cycle count /sec: 23,196
Module memory size: 1.66 MB
Total CPU: 0.000511802223%
Privileged CPU: 0.000511802223%
User CPU: 0.000000000000%
Module memory size: 2.05 MB
Process details
Runs as (owner): User
Integrety level: Medium
Windows platform: 64-bit
Parent Processes
Child Processes
Process Commands
"C:\Program Files\Real\RealPlayer\realplay.exe" /launcC:start_menu
"C:\Program Files\Real\RealPlayer\realplay.exe" /launcC:desktop
"C:\Program Files\real\realplayer\realplay.exe" /launcC:start_menu
"C:\Program Files\Real\RealPlayer\realplay.exe"
"C:\Program Files\Real\RealPlayer\realplay.exe"
Autoplay handler details
Name: RPPlayMediaOnArrival
Command: SOFTWARE\Microsoft\Windows\ CurrentVersion\Explorer\AutoplayHandlers\Handlers\RPPlayMediaOnArrival
Scheduled task details
CLSID: {CAF98FFB-8246-4180-8543-CE4146F5E2AE}
Command: \{CAF98FFB-8246-4180-8543-CE4146F5E2AE}
Startup files (all users) run details
Name: RealTray
Command: C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
Network connectivity
TCP: lhr08s04-in-f1.1e100.net on port 62671
UDP: LISTENING on port 61224
UDP: LISTENING on port 53641
UDP: LISTENING on port 61312
UDP: LISTENING on port 50685
TCP: 63.116.243.24 on port 54024
UDP: LISTENING on port 52025
UDP: LISTENING on port 2968
Windows Firewall allowed program: Yes
Image hashes
MD5: b7cfa3f9df5df31e67b93c4aacbb9c97
SHA-1: f4b4adf447953eeb5f5ff779ee62720dc8e2c82a
SHA-256: bb582a70090f3660c231405aba6155d2b8cf8f59c653d16cbdc57412347fe298
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++ 9.0
File packed: No
Import Table
advapi32.dll

RegEnumKeyExA
RegCreateKeyExA
RegQueryInfoKeyA
RegEnumKeyA
RegDeleteKeyA
RegQueryValueA
RegDeleteValueA
RegOpenKeyA
RegOpenKeyExA
RegQueryValueExA
RegCloseKey
RegCreateKeyA
RegSetValueA
RegSetValueExA
RegCreateKeyW
RegSetValueW
RegOpenKeyW
RegQueryValueW
gdi32.dll

kernel32.dll

GetEnvironmentVariableA
GetProcAddress
LoadLibraryA
GetModuleHandleA
GetTickCount
InterlockedIncrement
InterlockedDecrement
FreeLibrary
QueryPerformanceCounter
QueryPerformanceFrequency
GetVersionExA
CreateFileA
FindClose
CreateDirectoryA
MoveFileA
GetSystemInfo
GetVersion
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
GetModuleHandleExA
GetCurrentThreadId
RaiseException
Sleep
FindFirstFileW
GetModuleFileNameA
GetCurrentProcessId
SizeofResource
LockResource
LoadResource
FindResourceA
FindResourceExA
SetCurrentDirectoryA
GetCurrentDirectoryA
IsBadWritePtr
VirtualProtect
IsBadReadPtr
SetUnhandledExceptionFilter
TerminateThread
CreateThread
GetCurrentProcess
WriteFile
GetThreadContext
VirtualQuery
OpenProcess
SetFilePointer
GlobalMemoryStatus
UnmapViewOfFile
MapViewOfFile
CreateFileMappingA
GetSystemTimeAsFileTime
IsDebuggerPresent
UnhandledExceptionFilter
TerminateProcess
GetStartupInfoA
InterlockedCompareExchange
InterlockedExchange
GetProcessHeap
HeapSize
HeapReAlloc
HeapFree
HeapAlloc
HeapDestroy
SetEnvironmentVariableA
GetCommandLineW
WideCharToMultiByte
GetLastError
DeleteFileA
CreateMutexA
ReleaseMutex
CloseHandle
OpenMutexA
WaitForSingleObject
SetErrorMode
SetEvent
ResetEvent
CreateEventA
FindResourceW
FindResourceExW
lstrlenW
MultiByteToWideChar
GetStartupInfoW
HeapSetInformation
DecodePointer
EncodePointer
InitializeCriticalSectionAndSpinCount
lstrlenA
ExitProcess
GlobalAddAtomA
GlobalDeleteAtom
msvcp100.dll
msvcp71.dll
msvcp90.dll
msvcr100.dll
msvcr71.dll
msvcr90.dll
ole32.dll

OleInitialize
OleUninitialize
pncrt.dll

strrchr
strstr
_controlfp
_except_handler3
__set_app_type
__p__fmode
__p__commode
_adjust_fdiv
_putenv
_initterm
__getmainargs
__setusermatherr
printf
_assert
sprintf
getenv
_purecall
memmove
strchr
exit
_acmdln
__dllonexit
_onexit
_exit
_XcptFilter
shell32.dll

SHGetFolderPathA
SHGetFolderPathW
SHCreateDirectoryExW
SHCreateDirectoryExA
shlwapi.dll

PathAddBackslashA
PathAppendA
PathAppendW
PathAddBackslashW
user32.dll

GetDC
ReleaseDC
RegisterWindowMessageA
RegisterClassExA
GetClassInfoExA
CreateWindowExA
DefWindowProcA
PostThreadMessageA
DestroyWindow
UnregisterClassA
CharPrevA
CharNextA
GetSystemMetrics
SetMessageQueue
EnumWindows
GetPropA
SendMessageA
version.dll

VerQueryValueA
GetFileVersionInfoA