Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.0.6000.16386 (vista_rtm.061101-2205) 74.88%
6.0.6000.16386 (vista_rtm.061101-2205) 4.50%
6.0.6000.16386 (vista_rtm.061101-2205) 16.11%
6.0.6000.16386 (vista_rtm.061101-2205) 4.27%
6.0.6000.16386 (vista_rtm.061101-2205) 0.24%
(Note, Microsoft publishes each variation of this file with the same version, but the hashes are unique.)

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
RegisterTraceGuidsW, GetTraceLoggerHandle, GetTraceEnableFlags, GetTraceEnableLevel, UnregisterTraceGuids, RegisterIdleTask, UnregisterIdleTask, RegCreateKeyW, InitializeAcl, AddAccessAllowedAceEx, SetNamedSecurityInfoW, SetSecurityInfo, LookupPrivilegeValueW, AdjustTokenPrivileges, RegQueryValueExW, RegisterServiceCtrlHandlerExW, RegEnumValueW, RegEnumKeyExW, SetServiceStatus, RegQueryInfoKeyW, RegSetValueExW, RegOpenKeyExW, RegCreateKeyExW, RegCloseKey, RegDeleteValueW, RegDeleteKeyW, FreeSid, LookupAccountSidW, AllocateAndInitializeSid, ConvertStringSecurityDescriptorToSecurityDescriptorW, EventUnregister, EventRegister, EventWrite, EventEnabled, ControlTraceW, CloseTrace, ProcessTrace, OpenTraceW, CheckTokenMembership, OpenThreadToken, GetLengthSid
kernel32.dll
FindFirstFileW, MultiByteToWideChar, SizeofResource, LoadResource, FindResourceW, SetThreadLocale, GetThreadLocale, LoadLibraryA, DeleteFileW, GetDateFormatW, SystemTimeToTzSpecificLocalTime, FileTimeToSystemTime, FormatMessageW, Sleep, InterlockedCompareExchange, GetVersionExA, InterlockedExchange, QueryPerformanceCounter, GetTickCount, GetCurrentThreadId, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, FindNextFileW, FindClose, InterlockedDecrement, InterlockedIncrement, FreeLibrary, DisableThreadLibraryCalls, CreateEventW, CloseHandle, LoadLibraryExW, ResetEvent, OutputDebugStringA, GetModuleFileNameW, SetLastError, LoadLibraryW, SetEvent, lstrcmpiW, GetLastError, DeleteCriticalSection, InitializeCriticalSection, LeaveCriticalSection, EnterCriticalSection, RaiseException, lstrlenW, GetVersion, GetFileAttributesW, GetProcAddress, GetModuleHandleW, GetModuleHandleA, GetTimeFormatW, DelayLoadFailureHook, LocalFree, DeviceIoControl, CancelWaitableTimer, SetWaitableTimer, CreateWaitableTimerW, WaitForSingleObject, WaitForMultipleObjects, CreateThread, GlobalMemoryStatusEx, CreateFileW, ReadFile, QueryDosDeviceW, GetVolumeInformationW, GetModuleHandleExW, GetWindowsDirectoryW, HeapCreate, HeapDestroy, HeapAlloc, HeapFree, QueryPerformanceFrequency, WriteFile, GetOverlappedResult, WaitForSingleObjectEx, VirtualFree, GetSystemTime, GetDiskFreeSpaceW, MoveFileExW, VirtualAlloc, GetFileSizeEx, CancelIoEx, SetFilePointer, GetTempFileNameW, GetDriveTypeW, CancelIo, WaitForMultipleObjectsEx, GetCurrentThread, GetProcessHeap, SetFileAttributesW, OpenThread, GetFileSize, SetFileInformationByHandle, SetThreadPriority, GetThreadPriority, ExpandEnvironmentStringsW, CreateDirectoryW, HeapReAlloc
msvcrt.dll
DllMain
ntdll.dll
WinSqmIsOptedIn, RtlNtStatusToDosError, NtQueryVolumeInformationFile, NtQuerySystemInformation, NtQueryObject, DbgPrint, NtOpenFile, RtlInitUnicodeString, RtlCompareMemory, WinSqmEndSession, WinSqmStartSession, WinSqmEventWrite, WinSqmEventEnabled, WinSqmAddToStream, WinSqmSetString, NtSetInformationThread, NtQueryInformationThread, NtOpenEvent, RtlDecompressBuffer, NtClose, RtlGetVersion, RtlComputeCrc32
rpcrt4.dll
NdrServerCall2, RpcServerRegisterAuthInfoW, RpcServerRegisterIfEx, RpcServerUseProtseqEpW, RpcServerInqBindings, RpcEpRegisterW, RpcBindingToStringBindingW, RpcStringBindingParseW, RpcImpersonateClient, RpcRevertToSelf, RpcEpUnregister, RpcServerUnregisterIfEx, RpcBindingVectorFree, RpcStringBindingComposeW, RpcBindingFromStringBindingW, RpcServerInqDefaultPrincNameW, RpcStringFreeW, RpcBindingSetAuthInfoExW, RpcBindingFree, NdrClientCall2
setupapi.dll
SetupDiDestroyDeviceInfoList, SetupDiGetDeviceInterfaceDetailW, SetupDiEnumDeviceInterfaces, SetupDiGetClassDevsW
slc.dll
SLGetWindowsInformationDWORD
slwga.dll
SLIsGenuineLocal
user32.dll
GetClientRect, SetWindowPos, EnumChildWindows, GetDlgItem, ShowWindow, EnableWindow, GetWindowLongW, SetWindowLongW, LoadStringW, SetTimer, GetMessageW, TranslateMessage, DispatchMessageW, KillTimer, GetParent, CharNextW, SendDlgItemMessageW, UnregisterDeviceNotification, RegisterDeviceNotificationW, UnregisterClassA, LoadImageW, SetDlgItemInt, MessageBoxW, SendMessageW, GetDlgItemInt, DestroyIcon, RegisterClipboardFormatW, SetDlgItemTextW, InvalidateRect
wdscore.dll
WdsSetupLogMessageW, CurrentIP, ConstructPartialMsgVW
Export table
CloseEmdPerf
CollectEmdPerf
DllCanUnloadNow
DllGetClassObject
DllRegisterServer
DllUnregisterServer
EMDMgmtGetCacheStats
EMDMgmtLaunchEMDUIW
EMDMgmtLaunchPropertiesW
EMDMgmtQueryIsEMDActive
EMDMgmtServiceMain
EMDMgmtSysPrep
OpenEmdPerf

emdmgmt.dll

ReadyBoost Service by Microsoft

Remove emdmgmt.dll
Version:   6.0.6000.16386 (vista_rtm.061101-2205)
MD5:   a9b18b63a4fd6baab83326706d857fab
SHA1:   955ef8818cf7c021a6a33aa8d6a82bf474fb4955
SHA256:   7721cc67c0f8ce3060d0eb35a10e4adc1e3cb470c0797b17d606060c270f96d7
This is a Windows system installed file with Windows File Protection (WFP) enabled.

What is emdmgmt.dll?

Provides support for improving system performance using ReadyBoost. ReadyBoost uses the Superfetch service and an USB flash drive or memory card as memory cache and performs boot optimization. If you do not use an USB flash drive in this manner, you can disable ReadyBoost, but a negitive impact on performance could result, depending upon the amount of memory installed. I recommend to leave the Superfetch service on Automatic.

About emdmgmt.dll (from Microsoft)

ReadyBoost is a disk cache component of Microsoft Windows, first introduced with Microsoft's Windows Vista in 2006 and bundled with Windows 7 in 2009. It works by using flash memory, a USB flash drive

DetailsDetails

File name:emdmgmt.dll
Publisher:Microsoft Corporation
Product name:ReadyBoost Service
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\emdmgmt.dll
Original name:emdmgmt.dll.mui
File version:6.0.6000.16386 (vista_rtm.061101-2205)
Product version:6.0.6000.16386
Size:390 KB (399,360 bytes)
Digital DNA
PE subsystem:Windows GUI
Entropy:4.691532
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

BehaviorsBehaviors

Autoplay handlers
Runs under the registry key 'SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers'
  • Handler name 'MSCreateEmdCache'
Approved shell extensions
Located in the registry at 'SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved'
  • 'EMDFileProperties' with CLSID {BB6B2374-3D79-41DB-87F4-896C91846510}
Hosted services
Runs as a shared service under the Windows svcHost
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'
  • Shared name is 'EMDMgmt'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows Vista Home Premium 78.00%
Windows Vista Home Basic 11.50%
Windows Vista Business 5.50%
Windows Vista Ultimate 5.00%

Distribution by countryDistribution by country

United States installs about 73.33% of ReadyBoost Service.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 29.47%
Hewlett-Packard 21.40%
Toshiba 12.63%
Sony 12.63%
ASUS 7.02%
Gateway 7.02%
Acer 5.26%
Lenovo 1.40%
Intel 1.40%
Packard Bell 1.05%
American Megatrends 0.70%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE