Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.3.9600.16384 (winblue_rtm.130821-1623) 5.88%
6.3.9431.0 (winmain_bluemp.130615-1214) 1.47%
6.2.9200.16384 (win8_rtm.120725-1247) 23.53%
6.1.7600.16385 (win7_rtm.090713-1255) 4.41%
6.1.7600.16385 (win7_rtm.090713-1255) 33.82%
6.1.7600.16385 (win7_rtm.090713-1255) 26.47%
6.1.7600.16385 (win7_rtm.090713-1255) 2.94%
6.0.6001.18000 (longhorn_rtm.080118-1840) 1.47%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
CreateWellKnownSid, TraceMessage, ReportEventW, DeregisterEventSource, RegisterEventSourceW, IsValidSid, GetSidIdentifierAuthority, GetSidSubAuthorityCount, GetSidSubAuthority, CopySid, IsValidAcl, AddAccessAllowedAceEx, FreeSid, AllocateAndInitializeSid, GetLengthSid, InitializeAcl, AddAccessAllowedAce, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, ImpersonateLoggedOnUser, RevertToSelf, OpenThreadToken, EqualSid, GetTokenInformation, CheckTokenMembership, EventRegister, EventUnregister, EventWrite, RegConnectRegistryW
api-ms-win-core-localregistry-l1-1-0.dll
RegDeleteKeyExW, RegSetValueExW, RegOpenUserClassesRoot, RegDeleteValueW, RegCreateKeyExW, RegNotifyChangeKeyValue, RegOpenKeyExW, RegQueryValueExW, RegCloseKey, RegOpenCurrentUser
kernel32.dll
SleepEx, OpenThread, SwitchToThread, TlsGetValue, TlsSetValue, GetModuleHandleExW, GetSystemInfo, TlsFree, TlsAlloc, FreeLibraryAndExitThread, GetModuleHandleW, DeleteTimerQueueTimer, CreateTimerQueueTimer, lstrcmpiW, CancelIo, WaitForSingleObjectEx, QueueUserAPC, ReadFileEx, ProcessIdToSessionId, CancelIoEx, GetThreadId, ResumeThread, ReleaseSemaphore, CreateSemaphoreW, WaitForMultipleObjects, SetUnhandledExceptionFilter, UnhandledExceptionFilter, TerminateProcess, GetSystemTimeAsFileTime, QueryPerformanceCounter, InterlockedExchange, LoadLibraryExA, InterlockedCompareExchange, DelayLoadFailureHook, WaitForMultipleObjectsEx, lstrlenW, CreateWaitableTimerW, LoadLibraryW, GetProcAddress, GetTickCount, Sleep, CancelWaitableTimer, GetFileSize, ReadFile, FormatMessageW, GetTempPathW, WriteFile, DeleteFileW, QueryDosDeviceW, GetSystemWindowsDirectoryW, LocalAlloc, MultiByteToWideChar, FreeLibrary, GetCurrentThreadId, SetWaitableTimer, GetLastError, InitializeCriticalSection, DeleteCriticalSection, CloseHandle, GetCurrentThread, LocalFree, GetCurrentProcessId, DuplicateHandle, GetCurrentProcess, OpenProcess, InterlockedIncrement, GetVersionExW, InterlockedDecrement, LeaveCriticalSection, EnterCriticalSection, SetEvent, WaitForSingleObject, UnregisterWait, CreateEventW, SetLastError, HeapAlloc, DeviceIoControl, HeapFree, HeapReAlloc, ResetEvent, GetOverlappedResult, CreateFileW, VerifyVersionInfoW, CreateThread
msvcrt.dll
DllMain
ntdll.dll
RtlEnumerateGenericTableWithoutSplaying, EtwEventWrite, RtlMultiByteToUnicodeN, NtCreateFile, NtQueryInformationProcess, RtlInitUnicodeString, NtCreateSymbolicLinkObject, NtOpenSymbolicLinkObject, NtQuerySymbolicLinkObject, NtClose, NtMakeTemporaryObject, NtMakePermanentObject, RtlNtStatusToDosError, RtlOpenCurrentUser, VerSetConditionMask, DbgPrint, RtlEnumerateGenericTable, RtlDeleteResource, RtlDeleteElementGenericTable, RtlLookupElementGenericTable, RtlInsertElementGenericTable, RtlInitializeGenericTable, RtlInitializeResource, RtlAcquireResourceExclusive, RtlAcquireResourceShared, EtwEventRegister, RtlReleaseResource, EtwEventUnregister, EtwUnregisterTraceGuids, EtwRegisterTraceGuidsW, EtwGetTraceLoggerHandle, EtwGetTraceEnableLevel, EtwGetTraceEnableFlags, EtwTraceMessage
slc.dll
SLGetWindowsInformationDWORD
user32.dll
RegisterDeviceNotificationW, UnregisterDeviceNotification, LoadStringW, DispatchMessageW, PeekMessageW, MsgWaitForMultipleObjectsEx, PostThreadMessageW, PostMessageW, DestroyWindow, DefWindowProcW, RegisterClassExW, GetClassInfoExW, CreateWindowExW, UnregisterClassW
winspool.drv
DeletePrinter, SetPrinterW, OpenPrinterW, FindClosePrinterChangeNotification, EnumPrintersW, SetPrinterDataW, GetPrinterW, EnumPrinterDriversW, FindNextPrinterChangeNotification, FindFirstPrinterChangeNotification, FreePrinterNotifyInfo, GetPrinterDataW, ClosePrinter
Export table
ServiceMain
SvchostPushServiceGlobals

umrdp.dll

Remote Desktop Services Device Redirector Service by Microsoft

Remove umrdp.dll
Version:   6.1.7600.16385 (win7_rtm.090713-1255)
MD5:   af0ac98ee5077eb844413eb54287fde3
SHA1:   81997ae9b5592ac19d4b4c100df7aa2bf4bae851
SHA256:   1586326510de94e2735efad94a68d06db5b7347b68055a9ea8b95e19d91a2e69
This is a Windows system installed file with Windows File Protection (WFP) enabled.

Overview

umrdp.dll is loaded as dynamic link library that runs in the context of a process. The assembly utilizes the .NET run-time framework (which is required to be installed on the PC). This version is designed to run on Windows 7.

DetailsDetails

File name:umrdp.dll
Publisher:Microsoft Corporation
Product name:Remote Desktop Services Device Redirector Service
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\umrdp.dll
Original name:umrdp.dll.mui
File version:6.1.7600.16385 (win7_rtm.090713-1255)
Product version:6.1.7600.16385
Size:190.5 KB (195,072 bytes)
Digital DNA
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details

BehaviorsBehaviors

Hosted services
Runs as a shared service under the Windows svcHost
  • Shared name is 'UmRdpService'
  • Shared name is 'UmRdpService'
  • Shared name is 'UmRdpService'
  • Shared name is 'UmRdpService'
  • Shared name is 'UmRdpService'
  • Shared name is 'UmRdpService'
  • Shared name is 'UmRdpService'
  • Shared name is 'UmRdpService'
  • Shared name is 'UmRdpService'
  • Shared name is 'UmRdpService'
  • Shared name is 'UmRdpService'
  • Shared name is 'UmRdpService'
  • Shared name is 'UmRdpService'
  • Shared name is 'UmRdpService'
  • Shared name is 'UmRdpService'
  • Shared name is 'UmRdpService'
  • Shared name is 'UmRdpService'
  • Shared name is 'UmRdpService'
  • Shared name is 'UmRdpService'
  • Shared name is 'UmRdpService'
  • Shared name is 'UmRdpService'
  • Shared name is 'UmRdpService'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 34.33%
Windows 7 Professional 29.85%
Windows 8 Pro 10.45%
Windows 8 Pro with Media Center 10.45%
Windows 8.1 Pro 2.99%
Windows 7 Enterprise 2.99%
Windows 8.1 N 1.49%
Windows 8.1 Pro with Media Center 1.49%
Windows 8.1 Pro Preview 1.49%
Windows 8 Enterprise 1.49%
Windows 7 Starter 1.49%
Windows Server 2012 Standard Evaluation 1.49%

Distribution by countryDistribution by country

United States installs about 35.82% of Remote Desktop Services Device Redirector Service.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Hewlett-Packard 25.45%
Dell 18.18%
Acer 12.73%
ASUS 10.91%
Intel 7.27%
GIGABYTE 5.45%
Samsung 5.45%
Lenovo 3.64%
NEC 3.64%
Sony 3.64%
American Megatrends 1.82%
Sahara 1.82%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE