Should I block it?
No, this file is 100% safe to run.
 
Relationships
Parent process
Child process
     
    
        eventcreate.exe
| MD5: | 7abe906939eca722b950884006d54148 | 
| SHA1: | 9b547366506fea5ca30588a8f977bfd9c002a1ba | 
Overview
eventcreate.exe executes as a process with the local user's privileges typically within the context of its parent 
sysmon.exe. The assembly utilizes the .NET run-time framework (which is required to be installed on the PC). This particular version is usually found on Windows 7 Home Premium (6.1.7601.65536).
 Details
Details
| File name: | eventcreate.exe | 
| Typical file path: | C:\users\user\appdata\roaming\microsoft\windows\eventcreate.exe | 
| Size: | 190.31 MB (199,552,512 bytes) | 
| Build date: | 10/10/2013 9:49 PM | 
| Digital DNA | 
| File packed: | No | 
| Code language: | Microsoft Visual C# / Basic .NET | 
| .NET CLR: | Yes | 
| .NET NGENed: | No | 
More details
 Resource utilization
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
| CPU | 
| Total CPU: | 0.00021042% |  | 
| Kernel CPU: | 0.00004942% |  | 
| User CPU: | 0.00016100% |  | 
| Kernel CPU time: | 16,138,459,451 ms/min |  | 
| CPU cycles: | 30,537,486/sec |  | 
| Memory | 
| Private memory: | 19.76 MB |  | 
| Private (maximum): | 21.97 MB |  | 
| Private (minimum): | 3.71 MB |  | 
| Non-paged memory: | 19.76 MB |  | 
| Virtual memory: | 344.77 MB |  | 
| Virtual memory (peak): | 491.5 MB |  | 
| Working set: | 7.23 MB |  | 
| Working set (peak): | 23.28 MB |  | 
| Page faults: | 17,071,941/min |  | 
| I/O | 
| I/O read transfer: | 20 Bytes/sec |  | 
| I/O read operations: | 1/sec |  | 
| I/O other transfer: | 147 Bytes/sec |  | 
| I/O other operations: | 1/sec |  | 
| Resource allocations | 
| Threads: | 6 |  | 
| Handles: | 209 |  | 
| GUI GDI count: | 9 |  | 
| GUI GDI peak: | 11 |  | 
| GUI USER count: | 1 |  | 
| GUI USER peak: | 4 |  | 
 
 Process properties
Process properties
| Integrety level: | High | 
| Platform: | 64-bit | 
| Command line: | "C:\users\user\appdata\roaming\microsoft\windows\eventcreate.exe" | 
| Owner: | User | 
| Parent process: | sysmon.exe | 
 Distribution by Windows OS
Distribution by Windows OS
| OS version | distribution | 
| Windows 7 Home Premium | 100.00% |  | 
 Distribution by PC manufacturer
Distribution by PC manufacturer
| PC Manufacturer | distribution | 
| MSI | 100.00% |  |