Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

12.0.9600.16384 (winblue_rtm.130821-1623) 5.00%
12.0.7600.16385 (win7_rtm.090713-1255) 45.00%
12.0.7600.16385 (win7_rtm.090713-1255) 25.00%
11.0.6001.7000 (longhorn_rtm.080118-1840) 10.00%
11.0.6001.7000 (longhorn_rtm.080118-1840) 5.00%
11.0.6000.6324 (vista_rtm.061101-2205) 10.00%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
TraceMessage, RegDeleteValueW, RegCloseKey, RegCreateKeyExW, RegOpenKeyExW, RegSetValueExW, RegQueryInfoKeyW, RegEnumValueW, GetTraceEnableFlags, GetTraceEnableLevel, GetTraceLoggerHandle, RegisterTraceGuidsW, UnregisterTraceGuids, RegEnumKeyExW, RegQueryValueExW
gdi32.dll
GetObjectW, CreateCompatibleBitmap, CreateCompatibleDC, SelectObject, BitBlt, DeleteDC, GetDeviceCaps, DeleteObject, CreateSolidBrush, GetStockObject
kernel32.dll
SetLastError, GlobalUnlock, GlobalLock, GlobalAlloc, GetVersionExW, VirtualProtect, VirtualAlloc, GetSystemInfo, VirtualQuery, MultiByteToWideChar, lstrcpyW, InitializeCriticalSection, DeleteCriticalSection, InterlockedDecrement, LoadLibraryW, FlushInstructionCache, lstrcmpiW, GetCurrentThreadId, SetEvent, CloseHandle, WaitForSingleObject, lstrcpynW, GetModuleFileNameW, FreeLibrary, CreateThread, CreateEventW, lstrcatW, lstrlenA, SizeofResource, LoadResource, FindResourceW, LoadLibraryExW, Sleep, GetCommandLineW, lstrcmpW, EnterCriticalSection, LeaveCriticalSection, lstrlenW, DeleteFileW, GetModuleHandleW, GetLastError, RaiseException, InterlockedIncrement, HeapDestroy, GetCurrentProcess, CompareStringW, UnhandledExceptionFilter, TerminateProcess, GetSystemTimeAsFileTime, GetCurrentProcessId, GetTickCount, QueryPerformanceCounter, GetProcAddress, HeapFree, GetProcessHeap, HeapAlloc, LoadLibraryA, VirtualFree, InterlockedExchange, InterlockedCompareExchange, GetStartupInfoW, SetUnhandledExceptionFilter, GetModuleHandleA, ExpandEnvironmentStringsW
msvcrt.dll
DllMain
ole32.dll
CoCreateInstance, CoTaskMemFree, StringFromCLSID, CLSIDFromProgID, CLSIDFromString, CoTaskMemAlloc, OleLockRunning, CoInitialize, CoUninitialize, CoTaskMemRealloc, CoRegisterClassObject, CoRevokeClassObject, OleUninitialize, OleInitialize, CreateStreamOnHGlobal
shell32.dll
SHParseDisplayName, SHCreateItemFromIDList
user32.dll
CreateAcceleratorTableW, SetWindowTextW, GetWindowTextW, GetWindowTextLengthW, RegisterWindowMessageW, CharNextW, PostThreadMessageW, CharPrevW, DispatchMessageW, GetMessageW, EndPaint, GetWindow, ReleaseCapture, GetClassNameW, GetDlgItem, wsprintfW, IsChild, SetCapture, RedrawWindow, InvalidateRgn, InvalidateRect, ReleaseDC, GetDC, GetClientRect, CallWindowProcW, GetSysColor, DestroyWindow, UnregisterClassW, SetWindowPos, GetWindowLongW, SetWindowLongW, SetClassLongW, GetFocus, IsWindow, BeginPaint, GetParent, FillRect, SetFocus, GetDesktopWindow, GetClassInfoExW, LoadCursorW, RegisterClassExW, SendMessageW, SetParent, ShowWindow, PostMessageW, CreateWindowExW, DefWindowProcW

wmprph.exe

Windows Media Player Rich Preview Handler by Microsoft

Remove wmprph.exe
Version:   12.0.7600.16385 (win7_rtm.090713-1255)
MD5:   a94ea68fe940e9d912f7bdfc9654d401
SHA1:   6fdb674b639f44f9a5c26e243ea020ba08e637ee
SHA256:   67ec48023a52cad2a8161bac40a0fd7ff1abcffda399e9792e39f8223de8881e
This is a Windows system installed file with Windows File Protection (WFP) enabled.

What is wmprph.exe?

Windows Media Player (abbreviated WMP) is a media player and media library application developed by Microsoft that is used for playing audio, video and viewing images on personal computers running the Microsoft Windows operating system, as well as on Pocket PC and Windows Mobile-based devices.

About wmprph.exe (from Microsoft)

By sharing your media, you can do all of these things on your private network. (Media sharing does not allow you to share files outside of your network, however. For example, you cannot use media shar

DetailsDetails

File name:wmprph.exe
Publisher:Microsoft Corporation
Product name:Windows Media Player Rich Preview Handler
Description:Microsoft® Windows® Operating System
Typical file path:C:\Program Files\windows media player\wmprph.exe
File version:12.0.7600.16385 (win7_rtm.090713-1255)
Product version:12.0.7600.16385
Size:61.5 KB (62,976 bytes)
Digital DNA
PE subsystem:Windows GUI
Entropy:6.313521
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
Amazon Services LLC
11% remove
Amazon MP3 is an online music store owned and operated by Amazon.com. Amazon MP3's catalog is accessible from the Amazon.com web site by searching for an artist or title name. To download purchased music, Amazon.com offers the Amazon MP3 Downloader which is optional for individual tracks and required for album purchases. It saves purchased music into a particular folder and can, at the user's discretion, add purchased tracks to the libr...
Amazon Services LLC
6% remove
The Amazon MP3 Downloader is software you'll use along with Amazon Cloud Player to manage your music. The Downloader is a piece of software that streamlines the process of downloading by enabling you to download entire albums or playlists and automatically import them into iTunes or Windows Media Player.
D-Link
11% remove
DWA-130 software package includes the required drivers, configuration and management utilities and quick start guides and wizard to support this wireless adapter.
Microsoft Corporation
5% remove
Windows Media Player 11 was included with Vista with no updates, final release on XP. Windows Media Player is a media player and media library application developed by Microsoft that is used for playing audio, video and viewing images .In addition to being a media player, Windows Media Player includes the ability to rip music from and copy music to compact discs, burn recordable discs in Audio CD format or as data discs with playlists ...
Microsoft Corporation
5% remove
Obtenez le Lecteur Windows Media pour votre version de Windows ou découvrez comment lire des fichiers Windows Media sur votre Mac. Obtenez de l'aide et des procédures relatives à votre version du Lecteur, notamment des informations sur les fonctionnalités, la résolution de problèmes, etc. Personnalisez votre Lecteur avec des apparences, des visualisations et des plug-ins faciles à installer et vous bénéficierez d'un nouveau look et de f...
Olsen Software
6% remove
Skype Technologies S.A.
5% remove
Skype is a proprietary Voice over IP service and software application. The service allows users to communicate with peers by voice using a microphone, video by using a webcam, and instant messaging over the Internet. Phone calls may be placed to recipients on the traditional telephone networks. Calls to other users within the Skype service are free of charge, while calls to landline telephones and mobile phones are charged via a debit-b...

BehaviorsBehaviors

Approved shell extension
Located in the registry at 'SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved'
  • CLSID: {031EE060-67BC-460d-8847-E4A7C5E45A27}

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00166032%
0.028634%
Kernel CPU:0.00079236%
0.013761%
User CPU:0.00086796%
0.014873%
Kernel CPU time:1,941 ms/min
100,923,805ms/min
CPU cycles:546,417/sec
17,470,203/sec
Memory
Private memory:12.06 MB
21.59 MB
Private (maximum):19.86 MB
Private (minimum):9.36 MB
Non-paged memory:12.06 MB
21.59 MB
Virtual memory:127.79 MB
140.96 MB
Virtual memory (peak):140.44 MB
169.69 MB
Working set:10.39 MB
18.61 MB
Working set (peak):25.45 MB
37.95 MB
Page faults:62,525/min
2,039/min
I/O
I/O read transfer:13.02 KB/sec
1.02 MB/min
I/O read operations:2/sec
343/min
I/O write transfer:873 Bytes/sec
274.99 KB/min
I/O write operations:1/sec
227/min
I/O other transfer:86 Bytes/sec
448.09 KB/min
I/O other operations:10/sec
1,671/min
Resource allocations
Threads:7
12
Handles:279
600
GUI GDI count:76
103
GUI GDI peak:122
142
GUI USER count:22
49
GUI USER peak:36
71

BehaviorsProcess properties

Integrety level:Medium
Platform:32-bit
Command line:"C:\Program Files\windows media player\wmprph.exe" -embedding
Owner:User
Parent process:svchost.exe (Host Process for Windows Services by Microsoft Corporation)

ResourcesThreads

Averages
 
wmprph.exe (main module)
Total CPU:0.01111341%
0.272967%
Kernel CPU:0.00581946%
0.107585%
User CPU:0.00529395%
0.165382%
CPU cycles:581,485/sec
5,741,424/sec
Context switches:5/sec
79/sec
Memory:72 KB
1.16 MB
ntdll.dll
Total CPU:0.00005638%
Kernel CPU:0.00003383%
User CPU:0.00002255%
CPU cycles:31,461/sec
Memory:1.23 MB
gdiplus.dll
Total CPU:0.00004488%
Kernel CPU:0.00004488%
User CPU:0.00000000%
CPU cycles:730/sec
Memory:1.56 MB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 30.00%
Windows 7 Ultimate 20.00%
Windows 7 Professional 20.00%
Windows Vista Ultimate 15.00%
Windows 8.1 5.00%
Windows Vista Home Premium 5.00%
Windows Vista™ Home Premium 5.00%

Distribution by countryDistribution by country

United States installs about 46.67% of Windows Media Player Rich Preview Handler.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Hewlett-Packard 44.44%
ASUS 22.22%
Acer 22.22%
GIGABYTE 11.11%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE