Should I block it?

No, this file is 100% safe to run.

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegQueryValueExW, RegOpenKeyExW, RegCloseKey, SetSecurityDescriptorDacl, RegUnLoadKeyW, RegSetValueExW, RegSaveKeyW, RegRestoreKeyW, RegReplaceKeyW, RegQueryInfoKeyW, RegLoadKeyW, RegFlushKey, RegEnumValueW, RegEnumKeyExW, RegDeleteValueW, RegDeleteKeyW, RegCreateKeyExW, RegConnectRegistryW, InitializeSecurityDescriptor, AllocateAndInitializeSid, SetEntriesInAclW, DuplicateTokenEx, CreateProcessAsUserW, OpenProcessToken, StartServiceW, QueryServiceStatus, OpenServiceW, OpenSCManagerW, CloseServiceHandle
comctl32.dll
InitializeFlatSB, FlatSB_SetScrollProp, FlatSB_SetScrollPos, FlatSB_SetScrollInfo, FlatSB_GetScrollPos, FlatSB_GetScrollInfo, _TrackMouseEvent, ImageList_GetImageInfo, ImageList_SetIconSize, ImageList_GetIconSize, ImageList_Write, ImageList_Read, ImageList_GetDragImage, ImageList_DragShowNolock, ImageList_DragMove, ImageList_DragLeave, ImageList_DragEnter, ImageList_EndDrag, ImageList_BeginDrag, ImageList_Copy, ImageList_LoadImageW, ImageList_GetIcon, ImageList_Remove, ImageList_DrawEx, ImageList_Replace, ImageList_Draw, ImageList_SetOverlayImage, ImageList_GetBkColor, ImageList_SetBkColor, ImageList_ReplaceIcon, ImageList_Add, ImageList_SetImageCount, ImageList_GetImageCount, ImageList_Destroy, ImageList_Create
gdi32.dll
UnrealizeObject, StretchDIBits, StretchBlt, StartPage, StartDocW, SetWindowOrgEx, SetViewportOrgEx, SetTextColor, SetStretchBltMode, SetROP2, SetPixel, SetDIBits, SetDIBColorTable, SetBrushOrgEx, SetBkMode, SetBkColor, SetAbortProc, SelectPalette, SelectObject, SaveDC, RoundRect, RestoreDC, Rectangle, RectVisible, RealizePalette, Polyline, Polygon, PolyBezierTo, PolyBezier, Pie, PatBlt, MoveToEx, MaskBlt, LineTo, IntersectClipRect, GetWindowOrgEx, GetTextMetricsW, GetTextExtentPoint32W, GetSystemPaletteEntries, GetStockObject, GetRgnBox, GetPixel, GetPaletteEntries, GetObjectW, GetDeviceCaps, GetDIBits, GetDIBColorTable, GetDCOrgEx, GetCurrentPositionEx, GetClipBox, GetBrushOrgEx, GetBitmapBits, FrameRgn, ExtTextOutW, ExtFloodFill, ExcludeClipRect, EnumFontsW, EnumFontFamiliesExW, EndPage, EndDoc, Ellipse, DeleteObject, DeleteDC, CreateSolidBrush, CreateRectRgn, CreatePenIndirect, CreatePalette, CreateICW, CreateHalftonePalette, CreateFontIndirectW, CreateDIBitmap, CreateDIBSection, CreateDCW, CreateCompatibleDC, CreateCompatibleBitmap, CreateBrushIndirect, CreateBitmap, Chord, BitBlt, Arc, AbortDoc
kernel32.dll
lstrcmpiA, LoadLibraryA, LocalFree, LocalAlloc, GetACP, Sleep, VirtualFree, VirtualAlloc, GetSystemInfo, GetTickCount, QueryPerformanceCounter, GetVersion, GetCurrentThreadId, VirtualQuery, WideCharToMultiByte, MultiByteToWideChar, lstrlenW, lstrcpynW, LoadLibraryExW, IsValidLocale, GetSystemDefaultUILanguage, GetStartupInfoA, GetProcAddress, GetModuleHandleW, GetModuleFileNameW, GetUserDefaultUILanguage, GetLocaleInfoW, GetLastError, GetCommandLineW, FreeLibrary, FindFirstFileW, FindClose, ExitProcess, ExitThread, CreateThread, CompareStringW, WriteFile, UnhandledExceptionFilter, RtlUnwind, RaiseException, GetStdHandle, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, CloseHandle, TlsSetValue, TlsGetValue, lstrcpyW, WaitForSingleObject, WaitForMultipleObjectsEx, WaitForMultipleObjects, VirtualQueryEx, TryEnterCriticalSection, TerminateThread, SwitchToThread, SuspendThread, SizeofResource, SignalObjectAndWait, SetThreadPriority, SetThreadLocale, SetThreadAffinityMask, SetLastError, SetFilePointer, SetEvent, SetErrorMode, SetEndOfFile, ResumeThread, ResetEvent, ReadFile, QueryPerformanceFrequency, IsDebuggerPresent, MulDiv, LockResource, LoadResource, LoadLibraryW, GlobalUnlock, GlobalLock, GlobalFree, GlobalFindAtomW, GlobalDeleteAtom, GlobalAlloc, GlobalAddAtomW, GetVersionExW, GetTimeZoneInformation, GetThreadTimes, GetThreadPriority, GetThreadLocale, GetTempPathW, GetSystemDirectoryW, GetProcessAffinityMask, GetLocalTime, GetFullPathNameW, GetFileSize, GetFileAttributesW, GetExitCodeThread, GetDiskFreeSpaceW, GetDateFormatW, GetCurrentThread, GetCurrentProcessId, GetCurrentProcess, GetComputerNameW, GetCPInfo, FreeResource, InterlockedIncrement, InterlockedExchangeAdd, InterlockedExchange, InterlockedDecrement, InterlockedCompareExchange, FormatMessageW, FindResourceW, FileTimeToSystemTime, FileTimeToLocalFileTime, EnumCalendarInfoW, DeleteFileW, CreateProcessW, CreateMailslotW, CreateFileW, CreateEventW, TerminateProcess, OpenProcess
msimg32.dll
AlphaBlend
ole32.dll
OleUninitialize, OleInitialize, CoCreateInstance, CoUninitialize, CoInitialize
oleaut32.dll
SysFreeString, SysReAllocStringLen, SysAllocStringLen, CreateErrorInfo, GetErrorInfo, SetErrorInfo, SafeArrayPtrOfIndex, SafeArrayPutElement, SafeArrayGetElement, SafeArrayGetUBound, SafeArrayGetLBound, SafeArrayCreate, VariantChangeType, VariantCopy, VariantClear, VariantInit
shell32.dll
ShellExecuteW, SHGetSpecialFolderPathW
user32.dll
LoadStringW, MessageBoxA, CharNextW, DllMain
userenv.dll
CreateEnvironmentBlock
version.dll
VerQueryValueW, GetFileVersionInfoSizeW, GetFileVersionInfoW
winmm.dll
timeGetTime, timeEndPeriod, timeBeginPeriod
winspool.drv
OpenPrinterW, EnumPrintersW, DocumentPropertiesW, ClosePrinter, GetDefaultPrinterW

kmpprocess.exe

By PandoraTV (Signed)

Remove kmpprocess.exe
Version:   1.0.1.2
MD5:   544d66ce8c715ee5f18e2e4e7caae27e
SHA1:   5e9d40633cc47477bc17bd44862eb425386592d3
SHA256:   b07ea658f473fc1a2bd043bec2d954ff337f6d3360ad4381ded6f882b0cab414

Overview

kmpprocess.exe executes as a process under the SYSTEM account with extensive privileges (the system and the administrator accounts have the same file privileges) typically within the context of its parent kmpservice.exe (by PandoraTV). It has been configured with a firewall exception which allows both inbound and outbound network communication without being blocked. It is installed with a couple of know programs including Pandora Service published by Pandora.TV, KMP Service from KMP Media co., Ltd and KMP Service by KMP Media co., Ltd.

DetailsDetails

File name:kmpprocess.exe
Publisher:PandoraTV
Typical file path:C:\Program Files\pandora.tv\panservice\kmpprocess.exe
Original name:PanProcess
File version:1.0.1.2
Size:1.72 MB (1,798,696 bytes)
Build date:7/4/2013 8:48 AM
Certificate
Issued to:PandoraTV
Authority (CA):Thawte
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
KMP Media co., Ltd
40% remove
The player handles a wide range of audio, video and subtitles formats and allows one to capture audio, video, and screenshots. It provides both internal and external filters with a fully controlled environment in terms of connections to other splitters, decoders, audio/video transform filters and renderers without grappling with the DirectShow merit system.
Pandora.TV
  55% remove
Pandora TV is a video sharing website that hosts user-generated content. Pandora TV is a video sharing website designed to attach advertisement to user-submitted video clips and to provide unlimited storage space for users to upload.
Pandora.TV
  53% remove
Pandora TV is a video sharing website that hosts user-generated content. Pandora TV is a video sharing website designed to attach advertisement to user-submitted video clips and to provide unlimited storage space for users to upload.

BehaviorsBehaviors

Windows firewall allowed program
Exceptions allow programs to access to the Internet through an outbound connections
  • Firewall exception for 'C:\Program Files\PANDORA.TV\PanService\KMPProcess.exe'
Network connections
Access through an approved Windows firewall exception
  • [UDP] listens on port 62298
  • [UDP] listens on port 60509
  • [UDP] listens on port 60301
  • [UDP] listens on port 52186
  • [UDP] listens on port 49161
  • [UDP] listens on port 57687
  • [UDP] listens on port 54696
  • [UDP] listens on port 50632
  • [UDP] listens on port 1089
  • [UDP] listens on port 54084
  • [UDP] listens on port 55843

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.00462163%
    0.028634%
    Kernel CPU:0.00251256%
    0.013761%
    User CPU:0.00210907%
    0.014873%
    Kernel CPU time:204,820,188 ms/min
    100,923,805ms/min
    CPU cycles:4,534,767/sec
    17,470,203/sec
    Context switches:714/sec
    284/sec
    Memory
    Private memory:13.35 MB
    21.59 MB
    Private (maximum):11.62 MB
    Private (minimum):8.59 MB
    Non-paged memory:13.35 MB
    21.59 MB
    Virtual memory:104.13 MB
    140.96 MB
    Virtual memory (peak):107.28 MB
    169.69 MB
    Working set:9.23 MB
    18.61 MB
    Working set (peak):12.96 MB
    37.95 MB
    Page faults:2,501,604/min
    2,039/min
    I/O
    I/O read transfer:861 Bytes/sec
    1.02 MB/min
    I/O read operations:1/sec
    343/min
    I/O write transfer:0 Bytes/sec
    274.99 KB/min
    I/O write operations:1/sec
    227/min
    I/O other transfer:3.98 KB/sec
    448.09 KB/min
    I/O other operations:257/sec
    1,671/min
    Resource allocations
    Threads:25
    12
    Handles:373
    600
    GUI GDI count:55
    103
    GUI USER count:36
    49

    BehaviorsProcess properties

    Integrety level:System
    Platform:64-bit
    Command line:"C:\Program Files\pandora.tv\panservice\kmpprocess.exe" kmpprocess
    Owner:SYSTEM
    Parent process:kmpservice.exe (by PandoraTV)

    ResourcesThreads

    Averages
     
    KMPProcess.exe (main module)
    Total CPU:0.00785110%
    0.272967%
    Kernel CPU:0.00526771%
    0.107585%
    User CPU:0.00258339%
    0.165382%
    CPU cycles:1,717,676/sec
    5,741,424/sec
    Context switches:114/sec
    79/sec
    Memory:1.75 MB
    1.16 MB
    proxy.dll (by PANDORA.TV)
    Total CPU:0.00438094%
    Kernel CPU:0.00368865%
    User CPU:0.00069229%
    CPU cycles:291,627/sec
    Context switches:4/sec
    Memory:828 KB
    msvcrt.dll
    Total CPU:0.00276275%
    Kernel CPU:0.00000000%
    User CPU:0.00276275%
    Memory:352 KB
    wow64.dll
    Total CPU:0.00114402%
    Kernel CPU:0.00041353%
    User CPU:0.00073048%
    CPU cycles:49,502/sec
    Context switches:1/sec
    Memory:252 KB
    ntdll.dll
    Total CPU:0.00001825%
    Kernel CPU:0.00001825%
    User CPU:0.00000000%
    CPU cycles:1,071/sec
    Memory:1.23 MB

    Common loaded modules

    These are modules that are typiclaly loaded within the context of this process.

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Windows 7 Ultimate 41.67%
    Microsoft Windows XP 16.67%
    Windows 8.1 8.33%
    Windows 8 Enterprise N 8.33%
    Windows 7 Home Premium 8.33%
    Windows 8 Pro 8.33%
    Windows 8 8.33%

    Distribution by countryDistribution by country

    Taiwan installs about 25.00% of kmpprocess.exe.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    Dell 38.10%
    ASUS 28.57%
    Intel 9.52%
    Sony 9.52%
    Hewlett-Packard 4.76%
    Acer 4.76%
    GIGABYTE 4.76%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE