Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.3.9600.17031 (winblue_gdr.140221-1952) 11.02%
6.3.9600.17031 (winblue_gdr.140221-1952) 3.15%
6.3.9600.16384 (winblue_rtm.130821-1623) 6.69%
6.3.9600.16384 (winblue_rtm.130821-1623) 5.51%
6.3.9600.16384 (winblue_rtm.130821-1623) 1.18%
6.2.9200.16384 (win8_rtm.120725-1247) 58.27%
6.2.9200.16384 (win8_rtm.120725-1247) 10.24%
6.2.9200.16384 (win8_rtm.120725-1247) 1.57%
6.2.9200.16384 (win8_rtm.120725-1247) 2.36%

Relationships


PE structurePE file structure

Show functions
Import table
api-ms-win-appmodel-identity-l1-1-0.dll
AppXGetDevelopmentMode, AppXGetApplicationData, AppXGetOSMaxVersionTested, AppXFreeMemory
api-ms-win-appmodel-runtime-internal-l1-1-0.dll
GetPackagePropertyString, GetPackageApplicationPropertyString, GetPackageProperty, GetCurrentPackageApplicationContext, GetPackageOSMaxVersionTested, GetCurrentPackageContext
api-ms-win-appmodel-runtime-l1-1-0.dll
GetCurrentPackageInfo, PackageIdFromFullName, GetCurrentPackageFullName
api-ms-win-appmodel-state-l1-1-0.dll
CloseState, OpenStateExplicit, GetStateFolder, OpenState
api-ms-win-core-apiquery-l1-1-0.dll
ApiSetQueryApiSetPresence
api-ms-win-core-com-l1-1-0.dll
PropVariantClear, CoCreateGuid, StringFromGUID2, CoWaitForMultipleHandles, CoGetApartmentType, CoTaskMemAlloc, StringFromCLSID, CoTaskMemFree, CoCreateInstance
api-ms-win-core-debug-l1-1-1.dll
OutputDebugStringW, DebugBreak
api-ms-win-core-delayload-l1-1-1.dll
DelayLoadFailureHook, ResolveDelayLoadedAPI
api-ms-win-core-errorhandling-l1-1-1.dll
SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetLastError, RaiseException
api-ms-win-core-file-l1-2-0.dll
GetFileAttributesW, CreateFileW, GetFileSizeEx, WriteFile
api-ms-win-core-file-l1-2-1.dll
GetFileAttributesW, CreateFileW, GetFileSizeEx, WriteFile
api-ms-win-core-handle-l1-1-0.dll
DuplicateHandle, CloseHandle
api-ms-win-core-heap-l1-2-0.dll
HeapAlloc, HeapFree, GetProcessHeap
api-ms-win-core-heap-obsolete-l1-1-0.dll
LocalFree
api-ms-win-core-interlocked-l1-2-0.dll
InterlockedCompareExchange64, InterlockedIncrement, InterlockedDecrement
api-ms-win-core-libraryloader-l1-1-1.dll
GetModuleHandleW, GetModuleFileNameW, GetModuleHandleExW, GetProcAddress, LoadLibraryExW, FreeLibrary, LoadStringW
api-ms-win-core-libraryloader-l1-2-0.dll
LoadStringW, GetModuleHandleExW, GetModuleFileNameW, GetModuleHandleW, LoadLibraryExW, FreeLibrary, GetProcAddress
api-ms-win-core-localization-l1-2-0.dll
SetThreadPreferredUILanguages, FormatMessageW, LCMapStringW
api-ms-win-core-localization-l1-2-1.dll
LCMapStringW, SetThreadPreferredUILanguages, FormatMessageW
api-ms-win-core-memory-l1-1-1.dll
CreateFileMappingW, MapViewOfFile, UnmapViewOfFile
api-ms-win-core-memory-l1-1-2.dll
MapViewOfFile, UnmapViewOfFile, CreateFileMappingW
api-ms-win-core-path-l1-1-0.dll
PathCchCombineEx
api-ms-win-core-processthreads-l1-1-1.dll
ExitProcess, GetCurrentThreadId, GetCurrentProcessId, OpenProcess, GetProcessTimes, OpenProcessToken, GetCurrentProcess, TerminateProcess
api-ms-win-core-processthreads-l1-1-2.dll
OpenProcessToken, ExitProcess, GetCurrentProcess, GetCurrentProcessId, GetProcessTimes, OpenProcess, GetCurrentThreadId, TerminateProcess
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-psapi-l1-1-0.dll
K32GetProcessMemoryInfo
api-ms-win-core-quirks-l1-1-0.dll
QuirkIsEnabled
api-ms-win-core-registry-l1-1-0.dll
RegOpenKeyExW, RegQueryValueExW, RegCloseKey, RegGetValueW, RegOpenCurrentUser
api-ms-win-core-shlwapi-obsolete-l1-1-0.dll
SHLoadIndirectString
api-ms-win-core-string-l1-1-0.dll
CompareStringOrdinal, MultiByteToWideChar, CompareStringEx
api-ms-win-core-synch-l1-2-0.dll
WaitForSingleObject, ResetEvent, AcquireSRWLockExclusive, InitOnceInitialize, CreateEventW, WaitForMultipleObjectsEx, InitOnceExecuteOnce, SleepEx, SetEvent, ReleaseSRWLockExclusive, CreateSemaphoreExW, ReleaseSemaphore
api-ms-win-core-sysinfo-l1-2-0.dll
GetSystemTimeAsFileTime, GetTickCount, GetVersionExW
api-ms-win-core-sysinfo-l1-2-1.dll
GetTickCount, GetSystemTimeAsFileTime, GetTickCount64
api-ms-win-core-threadpool-l1-2-0.dll
CreateThreadpoolWait, SetThreadpoolWait, WaitForThreadpoolWaitCallbacks, CloseThreadpoolWork, CreateThreadpoolCleanupGroup, CloseThreadpoolCleanupGroupMembers, WaitForThreadpoolWorkCallbacks, SubmitThreadpoolWork, CloseThreadpoolWait, CreateThreadpoolWork
api-ms-win-core-url-l1-1-0.dll
PathCreateFromUrlW
api-ms-win-core-util-l1-1-0.dll
DecodePointer
api-ms-win-core-winrt-error-l1-1-1.dll
SetRestrictedErrorInfo, RoGetMatchingRestrictedErrorInfo, RoOriginateError
api-ms-win-core-winrt-l1-1-0.dll
RoActivateInstance, RoGetActivationFactory, RoInitialize, RoUninitialize
api-ms-win-core-winrt-string-l1-1-0.dll
WindowsDuplicateString, WindowsStringHasEmbeddedNull, WindowsCreateString, WindowsDeleteString, WindowsGetStringRawBuffer, WindowsCreateStringReference
api-ms-win-eventing-classicprovider-l1-1-0.dll
GetTraceLoggerHandle, GetTraceEnableLevel, GetTraceEnableFlags, RegisterTraceGuidsW, UnregisterTraceGuids, TraceMessage
api-ms-win-eventing-provider-l1-1-0.dll
EventUnregister, EventRegister, EventWrite
api-ms-win-ro-typeresolution-l1-1-0.dll
RoResolveNamespace, RoGetMetaDataFile
api-ms-win-security-base-l1-2-0.dll
GetTokenInformation, CheckTokenCapability, CreateWellKnownSid
api-ms-win-service-management-l1-1-0.dll
OpenSCManagerW, CloseServiceHandle
api-ms-win-shcore-scaling-l1-1-0.dll
RevokeScaleChangeNotifications, RegisterScaleChangeNotifications, GetScaleFactorForDevice
bcp47langs.dll
GetApplicationLanguages, LanguageListAsMuiForm
dui70.dll
CreateTouchTooltip
dwmapi.dll
DwmSetWindowAttribute
gdi32.dll
BitBlt, DeleteObject, SelectObject, CreateCompatibleDC, DeleteDC, CreateDIBSection
iertutil.dll
CreateUri, CreateIUriBuilder
mshtml.dll
GetWebPlatformObject
ntdll.dll
WinSqmAddToStreamEx, _ftol2, RtlAllocateHeap, RtlReAllocateHeap, RtlFreeHeap, RtlReportException, NtQuerySystemInformation, RtlInitializeCriticalSection, RtlDeleteCriticalSection, _itow_s, RtlLeaveCriticalSection, _vsnwprintf, memcpy_s, wcsncmp, memmove, WinSqmSetString, WinSqmEndSession, WinSqmSetDWORD, _wcsnicmp, strchr, _chkstk, memcmp, memset, RtlConvertSidToUnicodeString, RtlNtStatusToDosError, RtlFreeUnicodeString, wcscspn, RtlNtStatusToDosErrorNoTeb, wcstoul, _ftol2_sse, wcschr, RtlInitUnicodeString, RtlCompareUnicodeString, NtQueryInformationToken, WinSqmStartSession, WinSqmIsOptedIn, memcpy, RtlEnterCriticalSection, RtlUnwind, RtlGetVersion, wcsstr, EtwEventRegister, EtwEventWrite, EtwEventUnregister, RtlFreeSid, RtlInitializeGenericTableAvl, RtlInsertElementGenericTableAvl, RtlLookupElementGenericTableAvl, RtlEnumerateGenericTableWithoutSplayingAvl, RtlDeleteElementGenericTableAvl, RtlFindAceByType, RtlEqualSid, RtlAllocateAndInitializeSid, NtGetCachedSigningLevel, RtlCaptureContext
ole32.dll
CoAllowSetForegroundWindow, OleUninitialize, OleInitialize
rometadata.dll
MetaDataGetDispenser
urlmon.dll
CoInternetCombineIUri, RegisterWebPlatformPermanentSecurityManager, CoInternetGetSession, UrlMkSetSessionOption, CoInternetParseIUri, UnregisterWebPlatformPermanentSecurityManager
user32.dll
DefWindowProcW, LoadCursorW, MapWindowPoints, CreateWindowExW, GetWindowLongW, ShowWindow, PeekMessageW, TranslateMessage, GetWindowThreadProcessId, SetCursor, MsgWaitForMultipleObjectsEx, SetTimer, KillTimer, IsRectEmpty, GetClientRect, RegisterClassExW, GetWindowRect, DestroyWindow, PostQuitMessage, SetWindowLongW, SetLayeredWindowAttributes, SetWindowPos, SystemParametersInfoW, PostMessageW, DispatchMessageW, IsWindow, EndPaint, BeginPaint, UpdateWindow
uxtheme.dll
OpenThemeData, GetThemeAnimationTransform, CloseThemeData

wwahost.exe

Microsoft WWA Host by Microsoft

Remove wwahost.exe
Version:   6.2.9200.16384 (win8_rtm.120725-1247)
MD5:   7a8c0e5882eef1495ce74654d7cdcb4d
SHA1:   18356d2a962ce0b39b8872dde64cf3a9dcd58645
SHA256:   74d6bdfa7ff6f4b4e7ed9bf798224a726b39315f5944256c4fab83e80c641fc2
This is a Windows system installed file with Windows File Protection (WFP) enabled.

Overview

wwahost.exe executes as a process with the local user's privileges. The assembly utilizes the .NET run-time framework (which is required to be installed on the PC). This version is installed on Windows 8 and is compiled as a 64 bit program.

DetailsDetails

File name:wwahost.exe
Publisher:Microsoft Corporation
Product name:Microsoft WWA Host
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\wwahost.exe
Original name:WWAHost.exe.mui
File version:6.2.9200.16384 (win8_rtm.120725-1247)
Product version:6.2.9200.16384
Size:410.5 KB (420,352 bytes)
Digital DNA
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details
Network connections
  • [TCP] cdp1.public-trust.com.30.18.64.in-addr.arpa (64.18.30.7:80)
  • [TCP] 167.206.87.41:80
  • [TCP] 67.131.38.24:80
  • [TCP] 2.20.182.230:80
  • [TCP] 65.55.42.34:443
  • [TCP] a23-4-20-230.deploy.static.akamaitechnologies.com (23.4.20.230:443)
  • [TCP] a23-62-165-117.deploy.static.akamaitechnologies.com (23.62.165.117:443)
  • [TCP] a23-49-36-230.deploy.akamaitechnologies.com (23.49.36.230:443)
  • [TCP] a72-247-238-42.deploy.akamaitechnologies.com (72.247.238.42:80)
  • [TCP] 173.194.44.239:80
  • [TCP] 2.16.225.190:443
  • [TCP] 107.14.47.9:80
  • [TCP] a184-26-136-59.deploy.akamaitechnologies.com (184.26.136.59:80)
  • [TCP] cds43.mia9.msecn.net (65.54.93.46:443)
  • [TCP] a184-86-52-230.deploy.akamaitechnologies.com (184.86.52.230:443)
  • [TCP] 8.26.209.126:80
  • [TCP] a23-67-61-83.deploy.akamaitechnologies.com (23.67.61.83:80)
  • [TCP] 64.4.11.36:80
  • [TCP] a60-254-131-77.deploy.akamaitechnologies.com (60.254.131.77:80)
  • [TCP] a184-31-241-190.deploy.akamaitechnologies.com (184.31.241.190:443)
  • [TCP] https-117-121-251-192.sin.llnw.net (117.121.251.192:80)

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.01808664%
    0.028634%
    Kernel CPU:0.01028562%
    0.013761%
    User CPU:0.00780102%
    0.014873%
    Kernel CPU time:1,216,933 ms/min
    100,923,805ms/min
    CPU cycles:2,933,999/sec
    17,470,203/sec
    Context switches:17/sec
    284/sec
    Memory
    Private memory:92.38 MB
    21.59 MB
    Private (maximum):135.61 MB
    Private (minimum):84.29 MB
    Non-paged memory:92.38 MB
    21.59 MB
    Virtual memory:612.42 MB
    140.96 MB
    Virtual memory (peak):618.88 MB
    169.69 MB
    Working set:104.84 MB
    18.61 MB
    Working set (peak):156.59 MB
    37.95 MB
    Page faults:376,370/min
    2,039/min
    I/O
    I/O read transfer:1.2 MB/sec
    1.02 MB/min
    I/O read operations:398/sec
    343/min
    I/O write transfer:293.15 KB/sec
    274.99 KB/min
    I/O write operations:72/sec
    227/min
    I/O other transfer:5.13 KB/sec
    448.09 KB/min
    I/O other operations:324/sec
    1,671/min
    Resource allocations
    Threads:36
    12
    Handles:807
    600
    GUI GDI count:25
    103
    GUI GDI peak:28
    142
    GUI USER count:49
    49
    GUI USER peak:57
    71

    BehaviorsProcess properties

    Integrety level:Low
    Platform:64-bit
    Command lines:
    • "C:\Windows\System32\wwahost.exe" -servernamC:app.wwa
    • "C:\Windows\System32\wwahost.exe" -servernamC:windows.store
    • "C:\Windows\System32\wwahost.exe" -servernamC:microsoft.windowslive.mail.wwa
    • "C:\Windows\System32\wwahost.exe" -servernamC:microsoft.windowslive.modernphotos.wwa
    • "C:\Windows\System32\wwahost.exe" -servernamC:microsoft.zunevideo.wwa
    • "C:\Windows\System32\wwahost.exe" -servernamC:microsoft.xboxlivegames.wwa
    • "C:\Windows\System32\wwahost.exe" -servernamC:microsoft.windowslive.chat.wwa
    • (21 more)
    Owner:User
    Parent process:svchost.exe (by Microsoft)

    ResourcesThreads

    Averages
     
    shcore.dll
    Total CPU:0.32253813%
    0.272967%
    Kernel CPU:0.04456591%
    0.107585%
    User CPU:0.27797223%
    0.165382%
    CPU cycles:8,814,225/sec
    5,741,424/sec
    Context switches:6/sec
    79/sec
    Memory:600 KB
    1.16 MB
    msmpeg2vdec.dll
    Total CPU:0.07405875%
    Kernel CPU:0.04507826%
    User CPU:0.02898049%
    CPU cycles:1,889,958/sec
    Context switches:2/sec
    Memory:2.78 MB
    MSHTML.dll
    Total CPU:0.04599504%
    Kernel CPU:0.02440877%
    User CPU:0.02158627%
    CPU cycles:477,127/sec
    Memory:18.57 MB
    LocationApi.dll
    Total CPU:0.03724999%
    Kernel CPU:0.03724999%
    User CPU:0.00000000%
    CPU cycles:328,008/sec
    Memory:336 KB
    msvcrt.dll
    Total CPU:0.01582021%
    Kernel CPU:0.00039726%
    User CPU:0.01542295%
    CPU cycles:376,379/sec
    Memory:660 KB
    MSVCR110.dll
    Total CPU:0.01432748%
    Kernel CPU:0.00168207%
    User CPU:0.01264542%
    CPU cycles:427,589/sec
    Memory:848 KB
    ntdll.dll
    Total CPU:0.00541866%
    Kernel CPU:0.00112207%
    User CPU:0.00429658%
    CPU cycles:239,776/sec
    Memory:1.75 MB
    WININET.dll
    Total CPU:0.00456000%
    Kernel CPU:0.00284811%
    User CPU:0.00171188%
    CPU cycles:116,738/sec
    Memory:2.18 MB
    shell32.dll (by Microsoft)
    Total CPU:0.00344631%
    Kernel CPU:0.00129237%
    User CPU:0.00215395%
    CPU cycles:64,789/sec
    Memory:18.91 MB
    UxTheme.dll
    Total CPU:0.00282332%
    Kernel CPU:0.00282332%
    User CPU:0.00000000%
    CPU cycles:5,155/sec
    Memory:908 KB
    wwahost.exe (main module)
    Total CPU:0.00152256%
    Kernel CPU:0.00121126%
    User CPU:0.00031130%
    CPU cycles:29,915/sec
    Memory:424 KB
    WinStoreUI.dll
    Total CPU:0.00136179%
    Kernel CPU:0.00005876%
    User CPU:0.00130303%
    CPU cycles:15,108/sec
    Memory:844 KB

    Common loaded modules

    These are modules that are typiclaly loaded within the context of this process.

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Windows 8 34.50%
    Windows 8 Pro 18.50%
    Windows 8.1 18.00%
    Windows 8.1 Pro 11.00%
    Windows 8 Pro with Media Center 5.50%
    Windows 8.1 Single Language 4.00%
    Windows 8 Single Language 4.00%
    Windows 8 Enterprise 2.00%
    Windows 8.1 Pro with Media Center 1.50%
    Windows 8.1 Enterprise 0.50%
    Windows 8 Enterprise Evaluation 0.50%

    Distribution by countryDistribution by country

    United States installs about 54.55% of Microsoft WWA Host.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    Dell 22.22%
    Hewlett-Packard 19.05%
    ASUS 16.67%
    Acer 15.48%
    Toshiba 11.90%
    Lenovo 5.56%
    Sony 4.76%
    GIGABYTE 1.59%
    Samsung 1.19%
    Medion 0.79%
    Alienware 0.40%
    American Megatrends 0.40%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE