Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.0.6000.16386 (vista_rtm.061101-2205) 74.88%
6.0.6000.16386 (vista_rtm.061101-2205) 4.50%
6.0.6000.16386 (vista_rtm.061101-2205) 16.11%
6.0.6000.16386 (vista_rtm.061101-2205) 4.27%
6.0.6000.16386 (vista_rtm.061101-2205) 0.24%
(Note, Microsoft publishes each variation of this file with the same version, but the hashes are unique.)

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
RegisterTraceGuidsW, GetTraceLoggerHandle, GetTraceEnableFlags, GetTraceEnableLevel, UnregisterTraceGuids, RegisterIdleTask, UnregisterIdleTask, RegCreateKeyW, InitializeAcl, AddAccessAllowedAceEx, SetNamedSecurityInfoW, SetSecurityInfo, LookupPrivilegeValueW, AdjustTokenPrivileges, RegQueryValueExW, RegisterServiceCtrlHandlerExW, RegEnumValueW, RegEnumKeyExW, SetServiceStatus, RegQueryInfoKeyW, RegSetValueExW, RegOpenKeyExW, RegCreateKeyExW, RegCloseKey, RegDeleteValueW, RegDeleteKeyW, FreeSid, LookupAccountSidW, AllocateAndInitializeSid, ConvertStringSecurityDescriptorToSecurityDescriptorW, EventUnregister, EventRegister, EventWrite, EventEnabled, ControlTraceW, CloseTrace, ProcessTrace, OpenTraceW, CheckTokenMembership, OpenThreadToken, GetLengthSid
kernel32.dll
FindFirstFileW, MultiByteToWideChar, SizeofResource, LoadResource, FindResourceW, SetThreadLocale, GetThreadLocale, LoadLibraryA, DeleteFileW, GetDateFormatW, SystemTimeToTzSpecificLocalTime, FileTimeToSystemTime, FormatMessageW, Sleep, InterlockedCompareExchange, GetVersionExA, InterlockedExchange, QueryPerformanceCounter, GetTickCount, GetCurrentThreadId, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, FindNextFileW, FindClose, InterlockedDecrement, InterlockedIncrement, FreeLibrary, DisableThreadLibraryCalls, CreateEventW, CloseHandle, LoadLibraryExW, ResetEvent, OutputDebugStringA, GetModuleFileNameW, SetLastError, LoadLibraryW, SetEvent, lstrcmpiW, GetLastError, DeleteCriticalSection, InitializeCriticalSection, LeaveCriticalSection, EnterCriticalSection, RaiseException, lstrlenW, GetVersion, GetFileAttributesW, GetProcAddress, GetModuleHandleW, GetModuleHandleA, GetTimeFormatW, DelayLoadFailureHook, LocalFree, DeviceIoControl, CancelWaitableTimer, SetWaitableTimer, CreateWaitableTimerW, WaitForSingleObject, WaitForMultipleObjects, CreateThread, GlobalMemoryStatusEx, CreateFileW, ReadFile, QueryDosDeviceW, GetVolumeInformationW, GetModuleHandleExW, GetWindowsDirectoryW, HeapCreate, HeapDestroy, HeapAlloc, HeapFree, QueryPerformanceFrequency, WriteFile, GetOverlappedResult, WaitForSingleObjectEx, VirtualFree, GetSystemTime, GetDiskFreeSpaceW, MoveFileExW, VirtualAlloc, GetFileSizeEx, CancelIoEx, SetFilePointer, GetTempFileNameW, GetDriveTypeW, CancelIo, WaitForMultipleObjectsEx, GetCurrentThread, GetProcessHeap, SetFileAttributesW, OpenThread, GetFileSize, SetFileInformationByHandle, SetThreadPriority, GetThreadPriority, ExpandEnvironmentStringsW, CreateDirectoryW, HeapReAlloc
msvcrt.dll
DllMain
ntdll.dll
WinSqmIsOptedIn, RtlNtStatusToDosError, NtQueryVolumeInformationFile, NtQuerySystemInformation, NtQueryObject, DbgPrint, NtOpenFile, RtlInitUnicodeString, RtlCompareMemory, WinSqmEndSession, WinSqmStartSession, WinSqmEventWrite, WinSqmEventEnabled, WinSqmAddToStream, WinSqmSetString, NtSetInformationThread, NtQueryInformationThread, NtOpenEvent, RtlDecompressBuffer, NtClose, RtlGetVersion, RtlComputeCrc32
rpcrt4.dll
NdrServerCall2, RpcServerRegisterAuthInfoW, RpcServerRegisterIfEx, RpcServerUseProtseqEpW, RpcServerInqBindings, RpcEpRegisterW, RpcBindingToStringBindingW, RpcStringBindingParseW, RpcImpersonateClient, RpcRevertToSelf, RpcEpUnregister, RpcServerUnregisterIfEx, RpcBindingVectorFree, RpcStringBindingComposeW, RpcBindingFromStringBindingW, RpcServerInqDefaultPrincNameW, RpcStringFreeW, RpcBindingSetAuthInfoExW, RpcBindingFree, NdrClientCall2
setupapi.dll
SetupDiDestroyDeviceInfoList, SetupDiGetDeviceInterfaceDetailW, SetupDiEnumDeviceInterfaces, SetupDiGetClassDevsW
slc.dll
SLGetWindowsInformationDWORD
slwga.dll
SLIsGenuineLocal
user32.dll
GetClientRect, SetWindowPos, EnumChildWindows, GetDlgItem, ShowWindow, EnableWindow, GetWindowLongW, SetWindowLongW, LoadStringW, SetTimer, GetMessageW, TranslateMessage, DispatchMessageW, KillTimer, GetParent, CharNextW, SendDlgItemMessageW, UnregisterDeviceNotification, RegisterDeviceNotificationW, UnregisterClassA, LoadImageW, SetDlgItemInt, MessageBoxW, SendMessageW, GetDlgItemInt, DestroyIcon, RegisterClipboardFormatW, SetDlgItemTextW, InvalidateRect
wdscore.dll
WdsSetupLogMessageW, CurrentIP, ConstructPartialMsgVW
Export table
CloseEmdPerf
CollectEmdPerf
DllCanUnloadNow
DllGetClassObject
DllRegisterServer
DllUnregisterServer
EMDMgmtGetCacheStats
EMDMgmtLaunchEMDUIW
EMDMgmtLaunchPropertiesW
EMDMgmtQueryIsEMDActive
EMDMgmtServiceMain
EMDMgmtSysPrep
OpenEmdPerf

emdmgmt.dll

ReadyBoost Service by Microsoft

Remove emdmgmt.dll
Version:   6.0.6000.16386 (vista_rtm.061101-2205)
MD5:   70b1a86df0c8ead17d2bc332edae2c7c
SHA1:   b711a01e1c493a50f6353384a4d566bbd6f7adc8
SHA256:   80385ac32ce8388f06341aa4a880f68e0eb5815ccca5cf8e799846f472dce360
This is a Windows system installed file with Windows File Protection (WFP) enabled.

What is emdmgmt.dll?

Provides support for improving system performance using ReadyBoost. ReadyBoost uses the Superfetch service and an USB flash drive or memory card as memory cache and performs boot optimization. If you do not use an USB flash drive in this manner, you can disable ReadyBoost, but a negitive impact on performance could result, depending upon the amount of memory installed. I recommend to leave the Superfetch service on Automatic.

About emdmgmt.dll (from Microsoft)

ReadyBoost is a disk cache component of Microsoft Windows, first introduced with Microsoft's Windows Vista in 2006 and bundled with Windows 7 in 2009. It works by using flash memory, a USB flash drive

DetailsDetails

File name:emdmgmt.dll
Publisher:Microsoft Corporation
Product name:ReadyBoost Service
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\emdmgmt.dll
Original name:emdmgmt.dll.mui
File version:6.0.6000.16386 (vista_rtm.061101-2205)
Product version:6.0.6000.16386
Size:552 KB (565,248 bytes)
Digital DNA
PE subsystem:Windows GUI
Entropy:4.691532
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

BehaviorsBehaviors

Autoplay handlers
Runs under the registry key 'SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers'
  • Handler name 'MSCreateEmdCache'
Approved shell extensions
Located in the registry at 'SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved'
  • 'EMDFileProperties' with CLSID {BB6B2374-3D79-41DB-87F4-896C91846510}
Hosted services
Runs as a shared service under the Windows svcHost
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows Vista Home Premium 78.00%
Windows Vista Home Basic 11.50%
Windows Vista Business 5.50%
Windows Vista Ultimate 5.00%

Distribution by countryDistribution by country

United States installs about 73.33% of ReadyBoost Service.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 29.47%
Hewlett-Packard 21.40%
Toshiba 12.63%
Sony 12.63%
ASUS 7.02%
Gateway 7.02%
Acer 5.26%
Lenovo 1.40%
Intel 1.40%
Packard Bell 1.05%
American Megatrends 0.70%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE