Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

9.0.2 build-1031769 4.00%
9.0.1 build-894247 36.00%
9.0.0 build-812388 24.00%
8.0.0 build-471780 4.00%
8.0.0 build-471780 4.00%
7.1.4 build-385536 4.00%
7.0.1 build-227600 4.00%
7.0.0 build-203739 12.00%
4.5.2 build-8848 4.00%
10.0.0 build-1295980 4.00%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
OpenServiceW, ReportEventW, RegSetValueExW, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, RegOpenKeyExW, RegQueryValueExW, StartServiceCtrlDispatcherA, RegCloseKey, RegisterServiceCtrlHandlerA, RegisterEventSourceA, DeregisterEventSource, SetServiceStatus, CloseServiceHandle, OpenSCManagerW
dnsapi.dll
DnsFree, DnsQuery_A
iphlpapi.dll
CancelIPChangeNotify, NotifyAddrChange, GetAdaptersAddresses, GetAdaptersInfo
kernel32.dll
LoadLibraryA, InitializeCriticalSectionAndSpinCount, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, HeapAlloc, VirtualAlloc, HeapReAlloc, RtlUnwind, HeapSize, GetLocaleInfoA, WideCharToMultiByte, GetStringTypeA, MultiByteToWideChar, GetStringTypeW, LCMapStringA, LCMapStringW, GetTimeZoneInformation, CompareStringA, CompareStringW, TerminateThread, WaitForSingleObject, CreateThread, ReadFile, CloseHandle, DeviceIoControl, CreateEventA, ResetEvent, WaitForMultipleObjects, SetEvent, InitializeCriticalSection, CreatePipe, RaiseException, PeekNamedPipe, GetFileInformationByHandle, GetProcessHeap, LeaveCriticalSection, GetSystemTimeAsFileTime, GetCurrentProcessId, GetTickCount, QueryPerformanceCounter, HeapFree, VirtualFree, HeapCreate, InterlockedDecrement, GetLastError, GetCurrentThreadId, SetEndOfFile, FileTimeToLocalFileTime, FileTimeToSystemTime, SetLastError, InterlockedIncrement, TlsFree, TlsSetValue, TlsAlloc, TlsGetValue, DeleteCriticalSection, GetStartupInfoA, GetFileType, SetHandleCount, GetCommandLineW, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetModuleFileNameW, GetModuleFileNameA, GetStdHandle, WriteFile, ExitProcess, GetProcAddress, Sleep, GetModuleHandleW, IsDebuggerPresent, GetCurrentProcess, UnhandledExceptionFilter, TerminateProcess, GetCurrentDirectoryA, EnterCriticalSection, SetUnhandledExceptionFilter, SetEnvironmentVariableA, GetModuleHandleA, SetFilePointer, GetConsoleCP, GetConsoleMode, FlushFileBuffers, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, CreateFileA, GetFullPathNameW, FindFirstFileW, GetDriveTypeW, CreateFileW, DeleteFileW, CreateDirectoryW, GetFileAttributesW, LocalFree, FormatMessageW, OutputDebugStringW, UnmapViewOfFile, MapViewOfFile, CreateFileMappingA, GetFileAttributesA, GetVersionExA, FindClose, VirtualQuery, GetDriveTypeA, InterlockedCompareExchange, GetStartupInfoW
shfolder.dll
SHGetFolderPathW
user32.dll
CreateWindowExW, DispatchMessageA, GetMessageA, PostMessageA, MsgWaitForMultipleObjects, PeekMessageA, DestroyWindow, PostThreadMessageA
ws2_32.dll
WSAIoctl, WSACreateEvent

vmnat.exe

VMware Workstation by VMware (Signed)

Remove vmnat.exe
Version:   9.0.1 build-894247
MD5:   709b9008bcc9e0375d0a45b08f4c48ed
SHA1:   7adc54c6fa7db4eb403b81ac25f2df63fcd469b2
SHA256:   e1dcf66f52bdee2b5bb84a6e01f6442b8cf7da3f31f33619a065a957f787b864

What is vmnat.exe?

VMware NAT Service is part of VMware Workstation, a hypervisor that enables users to set up multiple virtual machines (VMs) and use them simultaneously along with the actual machine. Each virtual machine can execute its own operating system, such as Windows. VMware Workstation allows one physical machine to run multiple operating systems simultaneously.

About vmnat.exe (from VMware)

VMware Workstation provides a seamless way to access all of the virtual machines you need, regardless of where they are running. Remotely connect to virtual machines running on VMware vSphere, ESXi or

DetailsDetails

File name:vmnat.exe
Publisher:VMware, Inc.
Product name:VMware Workstation
Description:VMware NAT Service
Typical file path:C:\windows\syswow64\vmnat.exe
File version:9.0.1 build-894247
Size:425.65 KB (435,864 bytes)
Certificate
Issued to:VMware
Authority (CA):VeriSign
Digital DNA
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Service
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'VMware NAT Service'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00015585%
0.028634%
Kernel CPU:0.00004435%
0.013761%
User CPU:0.00011150%
0.014873%
Kernel CPU time:234,540 ms/min
100,923,805ms/min
CPU cycles:60,236/sec
17,470,203/sec
Context switches:1/sec
284/sec
Memory
Private memory:2.27 MB
21.59 MB
Private (maximum):4.57 MB
Private (minimum):3.26 MB
Non-paged memory:2.27 MB
21.59 MB
Virtual memory:48.92 MB
140.96 MB
Virtual memory (peak):51.61 MB
169.69 MB
Working set:3.69 MB
18.61 MB
Working set (peak):5.36 MB
37.95 MB
Page faults:4,616/min
2,039/min
I/O
I/O read transfer:1.51 KB/sec
1.02 MB/min
I/O read operations:7/sec
343/min
I/O write transfer:1.94 KB/sec
274.99 KB/min
I/O write operations:2/sec
227/min
I/O other transfer:152 Bytes/sec
448.09 KB/min
I/O other operations:6/sec
1,671/min
Resource allocations
Threads:6
12
Handles:106
600

BehaviorsProcess properties

Integrety level:System
Platform:64-bit
Command line:C:\windows\syswow64\vmnat.exe
Owner:SYSTEM
Windows Service
Service name:VMware NAT Service
Description:“Network address translation for virtual networks.”
Type:Win32OwnProcess
Parent process:services.exe (by Microsoft)

ResourcesThreads

Averages
 
vmnat.exe (main module)
Total CPU:0.00086601%
0.272967%
Kernel CPU:0.00042713%
0.107585%
User CPU:0.00043887%
0.165382%
CPU cycles:57,006/sec
5,741,424/sec
Memory:444 KB
1.16 MB
wow64win.dll
Total CPU:0.00034164%
Kernel CPU:0.00005694%
User CPU:0.00028470%
CPU cycles:5,957/sec
Memory:360 KB

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 29.17%
Windows 7 Ultimate 16.67%
Windows 8 Pro 12.50%
Windows 7 Professional 12.50%
Windows 7 Home Basic 8.33%
Microsoft Windows XP 8.33%
Windows Vista Home Premium 4.17%
Windows 8 Pro with Media Center 4.17%
Windows 8 Enterprise 4.17%

Distribution by countryDistribution by country

United States installs about 25.00% of VMware Workstation.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 62.50%
Toshiba 12.50%
Acer 12.50%
Hewlett-Packard 6.25%
GIGABYTE 6.25%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE