Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.3.9600.16384 (winblue_rtm.130821-1623) 14.29%
6.3.9600.16384 (winblue_rtm.130821-1623) 14.29%
6.2.9200.16384 (win8_rtm.120725-1247) 42.86%
6.2.9200.16384 (win8_rtm.120725-1247) 28.57%

Relationships

Parent process
Child processes
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
CloseServiceHandle, OpenSCManagerW, OpenServiceW, GetTraceEnableFlags, RegQueryValueExW, GetTraceLoggerHandle, AllocateAndInitializeSid, UnregisterTraceGuids, FreeSid, RegOpenKeyExW, GetTraceEnableLevel, CheckTokenMembership, QueryServiceConfigW, RegCloseKey, RegisterTraceGuidsW, RegSetKeyValueW, TraceMessage
kernel32.dll
OpenMutexW, LocalAlloc, lstrcmpiW, GetCurrentThreadId, SetProcessShutdownParameters, CloseHandle, LocalFree, ExpandEnvironmentStringsW, GetVersionExW, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, RaiseException, GetProcessHeap, HeapSize, HeapFree, HeapReAlloc, HeapAlloc, HeapDestroy, Sleep, OpenJobObjectW, IsProcessInJob, RegEnumValueW, RegDeleteTreeW, RegNotifyChangeKeyValue, RegEnumKeyExW, FindResourceExW, LoadResource, LockResource, SizeofResource, DeleteFileW, GetFileAttributesW, CreateProcessW, GetLastError, InterlockedExchange, InterlockedCompareExchange, SetUnhandledExceptionFilter, GetModuleHandleA, QueryPerformanceCounter, GetCurrentProcessId, GetSystemTimeAsFileTime, GetTickCount, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, RegLoadMUIStringW, K32EnumProcesses, ProcessIdToSessionId, OpenProcess, K32EnumProcessModules, K32GetModuleBaseNameW, MultiByteToWideChar, RegSetValueExW, RegCreateKeyExW, DeleteProcThreadAttributeList, UpdateProcThreadAttribute, InitializeProcThreadAttributeList
msvcrt.dll
DllMain
ntdll.dll
WinSqmAddToStream, WinSqmIsOptedIn
shell32.dll
ShellExecuteW
shlwapi.dll
PathFileExistsW
user32.dll
SendInput, SendMessageTimeoutW, GetKeyState, GetUserObjectInformationW, SystemParametersInfoW, UnregisterClassA, GetThreadDesktop, GetShellWindow, GetWindowThreadProcessId

atbroker.exe

Windows Assistive Technology Manager by Microsoft

Remove atbroker.exe
Version:   6.2.9200.16384 (win8_rtm.120725-1247)
MD5:   1c36f01131aa9e8daf2094b860a3a849
SHA1:   31f0a7da66fe84e19fc88dae4c9cd0b941c51b07
SHA256:   79e074ff9dfed9b8bf72723d1c4a3cc722dfab3463f05ea1a4e3409da83e33df
This is a Windows system installed file with Windows File Protection (WFP) enabled.

Overview

atbroker.exe executes as a process under the SYSTEM account with extensive privileges (the system and the administrator accounts have the same file privileges) typically within the context of its parent winlogon.exe (Windows Logon Application by Microsoft). The assembly utilizes the .NET run-time framework (which is required to be installed on the PC). This version is installed on Windows 8 and is compiled as a 64 bit program.

DetailsDetails

File name:atbroker.exe
Publisher:Microsoft Corporation
Product name:Windows Assistive Technology Manager
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\atbroker.exe
Original name:ATBroker.exe.mui
File version:6.2.9200.16384 (win8_rtm.120725-1247)
Product version:6.2.9200.16384
Size:52.5 KB (53,760 bytes)
Digital DNA
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00730363%
0.028634%
Kernel CPU:0.00549715%
0.013761%
User CPU:0.00180647%
0.014873%
Kernel CPU time:94 ms/min
100,923,805ms/min
CPU cycles:2,101/sec
17,470,203/sec
Memory
Private memory:1.43 MB
21.59 MB
Private (maximum):6.16 MB
Private (minimum):5.7 MB
Non-paged memory:1.43 MB
21.59 MB
Virtual memory:70.77 MB
140.96 MB
Virtual memory (peak):76.55 MB
169.69 MB
Working set:5.85 MB
18.61 MB
Working set (peak):6.48 MB
37.95 MB
Page faults:1,847/min
2,039/min
I/O
I/O read transfer:23 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O other transfer:7 Bytes/sec
448.09 KB/min
I/O other operations:1/sec
1,671/min
Resource allocations
Threads:2
12
Handles:105
600
GUI GDI count:9
103
GUI GDI peak:9
142
GUI USER count:1
49
GUI USER peak:2
71

BehaviorsProcess properties

Integrety level:Medium
Platform:64-bit
Command line:atbroker.exe
Owner:SYSTEM
Parent process:winlogon.exe (Windows Logon Application by Microsoft)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 8 Pro 42.86%
Windows 8.1 28.57%
Windows 8 28.57%

Distribution by countryDistribution by country

United Kingdom installs about 28.57% of Windows Assistive Technology Manager.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Hewlett-Packard 50.00%
Lenovo 33.33%
Acer 16.67%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE