Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.3.9600.17031 (winblue_gdr.140221-1952) 11.02%
6.3.9600.17031 (winblue_gdr.140221-1952) 3.15%
6.3.9600.16384 (winblue_rtm.130821-1623) 6.69%
6.3.9600.16384 (winblue_rtm.130821-1623) 5.51%
6.3.9600.16384 (winblue_rtm.130821-1623) 1.18%
6.2.9200.16384 (win8_rtm.120725-1247) 58.27%
6.2.9200.16384 (win8_rtm.120725-1247) 10.24%
6.2.9200.16384 (win8_rtm.120725-1247) 1.57%
6.2.9200.16384 (win8_rtm.120725-1247) 2.36%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
api-ms-win-appmodel-identity-l1-1-0.dll
AppXGetDevelopmentMode, AppXGetApplicationData, AppXGetOSMaxVersionTested, AppXFreeMemory
api-ms-win-appmodel-runtime-internal-l1-1-0.dll
GetPackagePropertyString, GetPackageApplicationPropertyString, GetPackageProperty, GetCurrentPackageApplicationContext, GetPackageOSMaxVersionTested, GetCurrentPackageContext
api-ms-win-appmodel-runtime-l1-1-0.dll
GetCurrentPackageInfo, PackageIdFromFullName, GetCurrentPackageFullName
api-ms-win-appmodel-state-l1-1-0.dll
CloseState, OpenStateExplicit, GetStateFolder, OpenState
api-ms-win-core-apiquery-l1-1-0.dll
ApiSetQueryApiSetPresence
api-ms-win-core-com-l1-1-0.dll
PropVariantClear, CoCreateGuid, StringFromGUID2, CoWaitForMultipleHandles, CoGetApartmentType, CoTaskMemAlloc, StringFromCLSID, CoTaskMemFree, CoCreateInstance
api-ms-win-core-debug-l1-1-1.dll
OutputDebugStringW, DebugBreak
api-ms-win-core-delayload-l1-1-1.dll
DelayLoadFailureHook, ResolveDelayLoadedAPI
api-ms-win-core-errorhandling-l1-1-1.dll
SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetLastError, RaiseException
api-ms-win-core-file-l1-2-0.dll
GetFileAttributesW, CreateFileW, GetFileSizeEx, WriteFile
api-ms-win-core-file-l1-2-1.dll
GetFileAttributesW, CreateFileW, GetFileSizeEx, WriteFile
api-ms-win-core-handle-l1-1-0.dll
DuplicateHandle, CloseHandle
api-ms-win-core-heap-l1-2-0.dll
HeapAlloc, HeapFree, GetProcessHeap
api-ms-win-core-heap-obsolete-l1-1-0.dll
LocalFree
api-ms-win-core-interlocked-l1-2-0.dll
InterlockedCompareExchange64, InterlockedIncrement, InterlockedDecrement
api-ms-win-core-libraryloader-l1-1-1.dll
GetModuleHandleW, GetModuleFileNameW, GetModuleHandleExW, GetProcAddress, LoadLibraryExW, FreeLibrary, LoadStringW
api-ms-win-core-libraryloader-l1-2-0.dll
LoadStringW, GetModuleHandleExW, GetModuleFileNameW, GetModuleHandleW, LoadLibraryExW, FreeLibrary, GetProcAddress
api-ms-win-core-localization-l1-2-0.dll
SetThreadPreferredUILanguages, FormatMessageW, LCMapStringW
api-ms-win-core-localization-l1-2-1.dll
LCMapStringW, SetThreadPreferredUILanguages, FormatMessageW
api-ms-win-core-memory-l1-1-1.dll
CreateFileMappingW, MapViewOfFile, UnmapViewOfFile
api-ms-win-core-memory-l1-1-2.dll
MapViewOfFile, UnmapViewOfFile, CreateFileMappingW
api-ms-win-core-path-l1-1-0.dll
PathCchCombineEx
api-ms-win-core-processthreads-l1-1-1.dll
ExitProcess, GetCurrentThreadId, GetCurrentProcessId, OpenProcess, GetProcessTimes, OpenProcessToken, GetCurrentProcess, TerminateProcess
api-ms-win-core-processthreads-l1-1-2.dll
OpenProcessToken, ExitProcess, GetCurrentProcess, GetCurrentProcessId, GetProcessTimes, OpenProcess, GetCurrentThreadId, TerminateProcess
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-psapi-l1-1-0.dll
K32GetProcessMemoryInfo
api-ms-win-core-quirks-l1-1-0.dll
QuirkIsEnabled
api-ms-win-core-registry-l1-1-0.dll
RegOpenKeyExW, RegQueryValueExW, RegCloseKey, RegGetValueW, RegOpenCurrentUser
api-ms-win-core-shlwapi-obsolete-l1-1-0.dll
SHLoadIndirectString
api-ms-win-core-string-l1-1-0.dll
CompareStringOrdinal, MultiByteToWideChar, CompareStringEx
api-ms-win-core-synch-l1-2-0.dll
WaitForSingleObject, ResetEvent, AcquireSRWLockExclusive, InitOnceInitialize, CreateEventW, WaitForMultipleObjectsEx, InitOnceExecuteOnce, SleepEx, SetEvent, ReleaseSRWLockExclusive, CreateSemaphoreExW, ReleaseSemaphore
api-ms-win-core-sysinfo-l1-2-0.dll
GetSystemTimeAsFileTime, GetTickCount, GetVersionExW
api-ms-win-core-sysinfo-l1-2-1.dll
GetTickCount, GetSystemTimeAsFileTime, GetTickCount64
api-ms-win-core-threadpool-l1-2-0.dll
CreateThreadpoolWait, SetThreadpoolWait, WaitForThreadpoolWaitCallbacks, CloseThreadpoolWork, CreateThreadpoolCleanupGroup, CloseThreadpoolCleanupGroupMembers, WaitForThreadpoolWorkCallbacks, SubmitThreadpoolWork, CloseThreadpoolWait, CreateThreadpoolWork
api-ms-win-core-url-l1-1-0.dll
PathCreateFromUrlW
api-ms-win-core-util-l1-1-0.dll
DecodePointer
api-ms-win-core-winrt-error-l1-1-1.dll
SetRestrictedErrorInfo, RoGetMatchingRestrictedErrorInfo, RoOriginateError
api-ms-win-core-winrt-l1-1-0.dll
RoActivateInstance, RoGetActivationFactory, RoInitialize, RoUninitialize
api-ms-win-core-winrt-string-l1-1-0.dll
WindowsDuplicateString, WindowsStringHasEmbeddedNull, WindowsCreateString, WindowsDeleteString, WindowsGetStringRawBuffer, WindowsCreateStringReference
api-ms-win-eventing-classicprovider-l1-1-0.dll
GetTraceLoggerHandle, GetTraceEnableLevel, GetTraceEnableFlags, RegisterTraceGuidsW, UnregisterTraceGuids, TraceMessage
api-ms-win-eventing-provider-l1-1-0.dll
EventUnregister, EventRegister, EventWrite
api-ms-win-ro-typeresolution-l1-1-0.dll
RoResolveNamespace, RoGetMetaDataFile
api-ms-win-security-base-l1-2-0.dll
GetTokenInformation, CheckTokenCapability, CreateWellKnownSid
api-ms-win-service-management-l1-1-0.dll
OpenSCManagerW, CloseServiceHandle
api-ms-win-shcore-scaling-l1-1-0.dll
RevokeScaleChangeNotifications, RegisterScaleChangeNotifications, GetScaleFactorForDevice
bcp47langs.dll
GetApplicationLanguages, LanguageListAsMuiForm
dui70.dll
CreateTouchTooltip
dwmapi.dll
DwmSetWindowAttribute
gdi32.dll
BitBlt, DeleteObject, SelectObject, CreateCompatibleDC, DeleteDC, CreateDIBSection
iertutil.dll
CreateUri, CreateIUriBuilder
mshtml.dll
GetWebPlatformObject
ntdll.dll
WinSqmAddToStreamEx, _ftol2, RtlAllocateHeap, RtlReAllocateHeap, RtlFreeHeap, RtlReportException, NtQuerySystemInformation, RtlInitializeCriticalSection, RtlDeleteCriticalSection, _itow_s, RtlLeaveCriticalSection, _vsnwprintf, memcpy_s, wcsncmp, memmove, WinSqmSetString, WinSqmEndSession, WinSqmSetDWORD, _wcsnicmp, strchr, _chkstk, memcmp, memset, RtlConvertSidToUnicodeString, RtlNtStatusToDosError, RtlFreeUnicodeString, wcscspn, RtlNtStatusToDosErrorNoTeb, wcstoul, _ftol2_sse, wcschr, RtlInitUnicodeString, RtlCompareUnicodeString, NtQueryInformationToken, WinSqmStartSession, WinSqmIsOptedIn, memcpy, RtlEnterCriticalSection, RtlUnwind, RtlGetVersion, wcsstr, EtwEventRegister, EtwEventWrite, EtwEventUnregister, RtlFreeSid, RtlInitializeGenericTableAvl, RtlInsertElementGenericTableAvl, RtlLookupElementGenericTableAvl, RtlEnumerateGenericTableWithoutSplayingAvl, RtlDeleteElementGenericTableAvl, RtlFindAceByType, RtlEqualSid, RtlAllocateAndInitializeSid, NtGetCachedSigningLevel, RtlCaptureContext
ole32.dll
CoAllowSetForegroundWindow, OleUninitialize, OleInitialize
rometadata.dll
MetaDataGetDispenser
urlmon.dll
CoInternetCombineIUri, RegisterWebPlatformPermanentSecurityManager, CoInternetGetSession, UrlMkSetSessionOption, CoInternetParseIUri, UnregisterWebPlatformPermanentSecurityManager
user32.dll
DefWindowProcW, LoadCursorW, MapWindowPoints, CreateWindowExW, GetWindowLongW, ShowWindow, PeekMessageW, TranslateMessage, GetWindowThreadProcessId, SetCursor, MsgWaitForMultipleObjectsEx, SetTimer, KillTimer, IsRectEmpty, GetClientRect, RegisterClassExW, GetWindowRect, DestroyWindow, PostQuitMessage, SetWindowLongW, SetLayeredWindowAttributes, SetWindowPos, SystemParametersInfoW, PostMessageW, DispatchMessageW, IsWindow, EndPaint, BeginPaint, UpdateWindow
uxtheme.dll
OpenThemeData, GetThemeAnimationTransform, CloseThemeData

wwahost.exe

Microsoft WWA Host by Microsoft

Remove wwahost.exe
Version:   6.3.9600.16384 (winblue_rtm.130821-1623)
MD5:   7b5d275fbcfebfc9960638f391cd4278
SHA1:   07e878be2e0bb0b6eaf0fee55318e680c230e9af
This is a Windows system installed file with Windows File Protection (WFP) enabled.

Overview

wwahost.exe executes as a process with the local user's privileges typically within the context of its parent svchost.exe (Host Process for Windows Services by Microsoft Corporation). The assembly utilizes the .NET run-time framework (which is required to be installed on the PC). and is compiled as a 64 bit program.

DetailsDetails

File name:wwahost.exe
Publisher:Microsoft Corporation
Product name:Microsoft WWA Host
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\wwahost.exe
Original name:WWAHost.exe.mui
File version:6.3.9600.16384 (winblue_rtm.130821-1623)
Product version:6.3.9600.16384
Size:616.5 KB (631,296 bytes)
Build date:10/16/2013 2:33 AM
Digital DNA
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details
Network connections
  • [TCP] a-0001.a-msedge.net (204.79.197.200:80)
  • [TCP] a23-51-193-48.deploy.static.akamaitechnologies.com (23.51.193.48:80)
  • [TCP] 95.100.77.199:443
  • [TCP] a23-3-193-48.deploy.static.akamaitechnologies.com (23.3.193.48:80)
  • [TCP] a23-56-225-48.deploy.static.akamaitechnologies.com (23.56.225.48:80)
  • [TCP] a23-72-209-48.deploy.static.akamaitechnologies.com (23.72.209.48:80)
  • [TCP] a23-6-97-48.deploy.static.akamaitechnologies.com (23.6.97.48:80)

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.00238728%
    0.028634%
    Kernel CPU:0.00097867%
    0.013761%
    User CPU:0.00140861%
    0.014873%
    Kernel CPU time:226,237 ms/min
    100,923,805ms/min
    CPU cycles:615,344/sec
    17,470,203/sec
    Context switches:3/sec
    284/sec
    Memory
    Private memory:68.31 MB
    21.59 MB
    Private (maximum):123.77 MB
    Private (minimum):36.15 MB
    Non-paged memory:68.31 MB
    21.59 MB
    Virtual memory:436.02 MB
    140.96 MB
    Virtual memory (peak):458.73 MB
    169.69 MB
    Working set:61.08 MB
    18.61 MB
    Working set (peak):144.31 MB
    37.95 MB
    Page faults:192,826/min
    2,039/min
    I/O
    I/O read transfer:10.26 KB/sec
    1.02 MB/min
    I/O read operations:3/sec
    343/min
    I/O write transfer:5.63 KB/sec
    274.99 KB/min
    I/O write operations:2/sec
    227/min
    I/O other transfer:2.73 KB/sec
    448.09 KB/min
    I/O other operations:14/sec
    1,671/min
    Resource allocations
    Threads:34
    12
    Handles:771
    600
    GUI GDI count:28
    103
    GUI GDI peak:30
    142
    GUI USER count:53
    49
    GUI USER peak:60
    71

    BehaviorsProcess properties

    Integrety level:Low
    Platform:64-bit
    Command lines:
    • "C:\Windows\System32\wwahost.exe" -servernamC:windows.store
    • "C:\Windows\System32\wwahost.exe" -servernamC:microsoft.windowslive.mail.wwa
    • "C:\Windows\System32\wwahost.exe" -servernamC:app.wwa
    • "C:\Windows\System32\wwahost.exe" -servernamC:microsoft.windowsreadinglist.wwa
    Owner:User
    Parent process:svchost.exe (Host Process for Windows Services by Microsoft Corporation)

    ResourcesThreads

    Averages
     
    shcore.dll
    Total CPU:0.02864902%
    0.272967%
    Kernel CPU:0.00351426%
    0.107585%
    User CPU:0.02513477%
    0.165382%
    CPU cycles:471,369/sec
    5,741,424/sec
    Memory:644 KB
    1.16 MB
    msvcrt.dll
    Total CPU:0.00232105%
    Kernel CPU:0.00024481%
    User CPU:0.00207625%
    CPU cycles:36,588/sec
    Memory:668 KB
    MSHTML.dll
    Total CPU:0.00154022%
    Kernel CPU:0.00047474%
    User CPU:0.00106548%
    CPU cycles:26,724/sec
    Memory:22.15 MB
    ntdll.dll
    Total CPU:0.00072614%
    Kernel CPU:0.00042404%
    User CPU:0.00030209%
    CPU cycles:13,299/sec
    Memory:1.66 MB
    WWAHost.exe (main module)
    Total CPU:0.00037311%
    Kernel CPU:0.00033618%
    User CPU:0.00003694%
    CPU cycles:5,852/sec
    Memory:636 KB
    combase.dll
    Total CPU:0.00018468%
    Kernel CPU:0.00000000%
    User CPU:0.00018468%
    CPU cycles:94/sec
    Memory:1.84 MB
    WinStoreUI.dll
    Total CPU:0.00014590%
    Kernel CPU:0.00011229%
    User CPU:0.00003361%
    CPU cycles:3,307/sec
    Memory:1.05 MB
    threadpoolwinrt.dll
    Total CPU:0.00003590%
    Kernel CPU:0.00000598%
    User CPU:0.00002991%
    CPU cycles:284/sec
    Memory:72 KB
    shell32.dll (Windows Shell Common Dll by Microsoft)
    Total CPU:0.00002692%
    Kernel CPU:0.00001795%
    User CPU:0.00000897%
    CPU cycles:267/sec
    Memory:20.06 MB

    Common loaded modules

    These are modules that are typiclaly loaded within the context of this process.

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Windows 8 34.50%
    Windows 8 Pro 18.50%
    Windows 8.1 18.00%
    Windows 8.1 Pro 11.00%
    Windows 8 Pro with Media Center 5.50%
    Windows 8.1 Single Language 4.00%
    Windows 8 Single Language 4.00%
    Windows 8 Enterprise 2.00%
    Windows 8.1 Pro with Media Center 1.50%
    Windows 8.1 Enterprise 0.50%
    Windows 8 Enterprise Evaluation 0.50%

    Distribution by countryDistribution by country

    United States installs about 54.55% of Microsoft WWA Host.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    Dell 22.22%
    Hewlett-Packard 19.05%
    ASUS 16.67%
    Acer 15.48%
    Toshiba 11.90%
    Lenovo 5.56%
    Sony 4.76%
    GIGABYTE 1.59%
    Samsung 1.19%
    Medion 0.79%
    Alienware 0.40%
    American Megatrends 0.40%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE