Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.3.9600.17031 (winblue_gdr.140221-1952) 11.02%
6.3.9600.17031 (winblue_gdr.140221-1952) 3.15%
6.3.9600.16384 (winblue_rtm.130821-1623) 6.69%
6.3.9600.16384 (winblue_rtm.130821-1623) 5.51%
6.3.9600.16384 (winblue_rtm.130821-1623) 1.18%
6.2.9200.16384 (win8_rtm.120725-1247) 58.27%
6.2.9200.16384 (win8_rtm.120725-1247) 10.24%
6.2.9200.16384 (win8_rtm.120725-1247) 1.57%
6.2.9200.16384 (win8_rtm.120725-1247) 2.36%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
api-ms-win-appmodel-identity-l1-1-0.dll
AppXGetDevelopmentMode, AppXGetApplicationData, AppXGetOSMaxVersionTested, AppXFreeMemory
api-ms-win-appmodel-runtime-internal-l1-1-0.dll
GetPackagePropertyString, GetPackageApplicationPropertyString, GetPackageProperty, GetCurrentPackageApplicationContext, GetPackageOSMaxVersionTested, GetCurrentPackageContext
api-ms-win-appmodel-runtime-l1-1-0.dll
GetCurrentPackageInfo, PackageIdFromFullName, GetCurrentPackageFullName
api-ms-win-appmodel-state-l1-1-0.dll
CloseState, OpenStateExplicit, GetStateFolder, OpenState
api-ms-win-core-apiquery-l1-1-0.dll
ApiSetQueryApiSetPresence
api-ms-win-core-com-l1-1-0.dll
PropVariantClear, CoCreateGuid, StringFromGUID2, CoWaitForMultipleHandles, CoGetApartmentType, CoTaskMemAlloc, StringFromCLSID, CoTaskMemFree, CoCreateInstance
api-ms-win-core-debug-l1-1-1.dll
OutputDebugStringW, DebugBreak
api-ms-win-core-delayload-l1-1-1.dll
DelayLoadFailureHook, ResolveDelayLoadedAPI
api-ms-win-core-errorhandling-l1-1-1.dll
SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetLastError, RaiseException
api-ms-win-core-file-l1-2-0.dll
GetFileAttributesW, CreateFileW, GetFileSizeEx, WriteFile
api-ms-win-core-file-l1-2-1.dll
GetFileAttributesW, CreateFileW, GetFileSizeEx, WriteFile
api-ms-win-core-handle-l1-1-0.dll
DuplicateHandle, CloseHandle
api-ms-win-core-heap-l1-2-0.dll
HeapAlloc, HeapFree, GetProcessHeap
api-ms-win-core-heap-obsolete-l1-1-0.dll
LocalFree
api-ms-win-core-interlocked-l1-2-0.dll
InterlockedCompareExchange64, InterlockedIncrement, InterlockedDecrement
api-ms-win-core-libraryloader-l1-1-1.dll
GetModuleHandleW, GetModuleFileNameW, GetModuleHandleExW, GetProcAddress, LoadLibraryExW, FreeLibrary, LoadStringW
api-ms-win-core-libraryloader-l1-2-0.dll
LoadStringW, GetModuleHandleExW, GetModuleFileNameW, GetModuleHandleW, LoadLibraryExW, FreeLibrary, GetProcAddress
api-ms-win-core-localization-l1-2-0.dll
SetThreadPreferredUILanguages, FormatMessageW, LCMapStringW
api-ms-win-core-localization-l1-2-1.dll
LCMapStringW, SetThreadPreferredUILanguages, FormatMessageW
api-ms-win-core-memory-l1-1-1.dll
CreateFileMappingW, MapViewOfFile, UnmapViewOfFile
api-ms-win-core-memory-l1-1-2.dll
MapViewOfFile, UnmapViewOfFile, CreateFileMappingW
api-ms-win-core-path-l1-1-0.dll
PathCchCombineEx
api-ms-win-core-processthreads-l1-1-1.dll
ExitProcess, GetCurrentThreadId, GetCurrentProcessId, OpenProcess, GetProcessTimes, OpenProcessToken, GetCurrentProcess, TerminateProcess
api-ms-win-core-processthreads-l1-1-2.dll
OpenProcessToken, ExitProcess, GetCurrentProcess, GetCurrentProcessId, GetProcessTimes, OpenProcess, GetCurrentThreadId, TerminateProcess
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-psapi-l1-1-0.dll
K32GetProcessMemoryInfo
api-ms-win-core-quirks-l1-1-0.dll
QuirkIsEnabled
api-ms-win-core-registry-l1-1-0.dll
RegOpenKeyExW, RegQueryValueExW, RegCloseKey, RegGetValueW, RegOpenCurrentUser
api-ms-win-core-shlwapi-obsolete-l1-1-0.dll
SHLoadIndirectString
api-ms-win-core-string-l1-1-0.dll
CompareStringOrdinal, MultiByteToWideChar, CompareStringEx
api-ms-win-core-synch-l1-2-0.dll
WaitForSingleObject, ResetEvent, AcquireSRWLockExclusive, InitOnceInitialize, CreateEventW, WaitForMultipleObjectsEx, InitOnceExecuteOnce, SleepEx, SetEvent, ReleaseSRWLockExclusive, CreateSemaphoreExW, ReleaseSemaphore
api-ms-win-core-sysinfo-l1-2-0.dll
GetSystemTimeAsFileTime, GetTickCount, GetVersionExW
api-ms-win-core-sysinfo-l1-2-1.dll
GetTickCount, GetSystemTimeAsFileTime, GetTickCount64
api-ms-win-core-threadpool-l1-2-0.dll
CreateThreadpoolWait, SetThreadpoolWait, WaitForThreadpoolWaitCallbacks, CloseThreadpoolWork, CreateThreadpoolCleanupGroup, CloseThreadpoolCleanupGroupMembers, WaitForThreadpoolWorkCallbacks, SubmitThreadpoolWork, CloseThreadpoolWait, CreateThreadpoolWork
api-ms-win-core-url-l1-1-0.dll
PathCreateFromUrlW
api-ms-win-core-util-l1-1-0.dll
DecodePointer
api-ms-win-core-winrt-error-l1-1-1.dll
SetRestrictedErrorInfo, RoGetMatchingRestrictedErrorInfo, RoOriginateError
api-ms-win-core-winrt-l1-1-0.dll
RoActivateInstance, RoGetActivationFactory, RoInitialize, RoUninitialize
api-ms-win-core-winrt-string-l1-1-0.dll
WindowsDuplicateString, WindowsStringHasEmbeddedNull, WindowsCreateString, WindowsDeleteString, WindowsGetStringRawBuffer, WindowsCreateStringReference
api-ms-win-eventing-classicprovider-l1-1-0.dll
GetTraceLoggerHandle, GetTraceEnableLevel, GetTraceEnableFlags, RegisterTraceGuidsW, UnregisterTraceGuids, TraceMessage
api-ms-win-eventing-provider-l1-1-0.dll
EventUnregister, EventRegister, EventWrite
api-ms-win-ro-typeresolution-l1-1-0.dll
RoResolveNamespace, RoGetMetaDataFile
api-ms-win-security-base-l1-2-0.dll
GetTokenInformation, CheckTokenCapability, CreateWellKnownSid
api-ms-win-service-management-l1-1-0.dll
OpenSCManagerW, CloseServiceHandle
api-ms-win-shcore-scaling-l1-1-0.dll
RevokeScaleChangeNotifications, RegisterScaleChangeNotifications, GetScaleFactorForDevice
bcp47langs.dll
GetApplicationLanguages, LanguageListAsMuiForm
dui70.dll
CreateTouchTooltip
dwmapi.dll
DwmSetWindowAttribute
gdi32.dll
BitBlt, DeleteObject, SelectObject, CreateCompatibleDC, DeleteDC, CreateDIBSection
iertutil.dll
CreateUri, CreateIUriBuilder
mshtml.dll
GetWebPlatformObject
ntdll.dll
WinSqmAddToStreamEx, _ftol2, RtlAllocateHeap, RtlReAllocateHeap, RtlFreeHeap, RtlReportException, NtQuerySystemInformation, RtlInitializeCriticalSection, RtlDeleteCriticalSection, _itow_s, RtlLeaveCriticalSection, _vsnwprintf, memcpy_s, wcsncmp, memmove, WinSqmSetString, WinSqmEndSession, WinSqmSetDWORD, _wcsnicmp, strchr, _chkstk, memcmp, memset, RtlConvertSidToUnicodeString, RtlNtStatusToDosError, RtlFreeUnicodeString, wcscspn, RtlNtStatusToDosErrorNoTeb, wcstoul, _ftol2_sse, wcschr, RtlInitUnicodeString, RtlCompareUnicodeString, NtQueryInformationToken, WinSqmStartSession, WinSqmIsOptedIn, memcpy, RtlEnterCriticalSection, RtlUnwind, RtlGetVersion, wcsstr, EtwEventRegister, EtwEventWrite, EtwEventUnregister, RtlFreeSid, RtlInitializeGenericTableAvl, RtlInsertElementGenericTableAvl, RtlLookupElementGenericTableAvl, RtlEnumerateGenericTableWithoutSplayingAvl, RtlDeleteElementGenericTableAvl, RtlFindAceByType, RtlEqualSid, RtlAllocateAndInitializeSid, NtGetCachedSigningLevel, RtlCaptureContext
ole32.dll
CoAllowSetForegroundWindow, OleUninitialize, OleInitialize
rometadata.dll
MetaDataGetDispenser
urlmon.dll
CoInternetCombineIUri, RegisterWebPlatformPermanentSecurityManager, CoInternetGetSession, UrlMkSetSessionOption, CoInternetParseIUri, UnregisterWebPlatformPermanentSecurityManager
user32.dll
DefWindowProcW, LoadCursorW, MapWindowPoints, CreateWindowExW, GetWindowLongW, ShowWindow, PeekMessageW, TranslateMessage, GetWindowThreadProcessId, SetCursor, MsgWaitForMultipleObjectsEx, SetTimer, KillTimer, IsRectEmpty, GetClientRect, RegisterClassExW, GetWindowRect, DestroyWindow, PostQuitMessage, SetWindowLongW, SetLayeredWindowAttributes, SetWindowPos, SystemParametersInfoW, PostMessageW, DispatchMessageW, IsWindow, EndPaint, BeginPaint, UpdateWindow
uxtheme.dll
OpenThemeData, GetThemeAnimationTransform, CloseThemeData

wwahost.exe

Microsoft WWA Host by Microsoft

Remove wwahost.exe
Version:   6.3.9600.17031 (winblue_gdr.140221-1952)
MD5:   8df7f2a9b72b7ca4294bb9e59feaefcd
SHA1:   0af34255db6c4bfd6a79c18c05e52b814c13a0cd
This is a Windows system installed file with Windows File Protection (WFP) enabled.

Overview

wwahost.exe executes as a process with the local user's privileges typically within the context of its parent svchost.exe (Host Process for Windows Services by Microsoft Corporation). The assembly utilizes the .NET run-time framework (which is required to be installed on the PC). and is compiled as a 64 bit program.

DetailsDetails

File name:wwahost.exe
Publisher:Microsoft Corporation
Product name:Microsoft WWA Host
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\wwahost.exe
Original name:WWAHost.exe.mui
File version:6.3.9600.17031 (winblue_gdr.140221-1952)
Product version:6.3.9600.17031
Size:502.5 KB (514,560 bytes)
Build date:2/22/2014 8:00 AM
Digital DNA
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details
Network connections
  • [TCP] 157.56.53.44:12350
  • [TCP] 157.55.56.143:443
  • [TCP] 157.56.53.40:12350
  • [UDP] listens on port 13682
  • [UDP] listens on port 2652
  • [UDP] listens on port 30966

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.05942528%
    0.028634%
    Kernel CPU:0.03505826%
    0.013761%
    User CPU:0.02436702%
    0.014873%
    Kernel CPU time:8,306,348 ms/min
    100,923,805ms/min
    CPU cycles:2,977,519/sec
    17,470,203/sec
    Context switches:18/sec
    284/sec
    Memory
    Private memory:114.03 MB
    21.59 MB
    Private (maximum):87.59 MB
    Private (minimum):40.26 MB
    Non-paged memory:114.03 MB
    21.59 MB
    Virtual memory:508.27 MB
    140.96 MB
    Virtual memory (peak):554.73 MB
    169.69 MB
    Working set:119.38 MB
    18.61 MB
    Working set (peak):174.58 MB
    37.95 MB
    Page faults:852,066/min
    2,039/min
    I/O
    I/O read transfer:137 KB/sec
    1.02 MB/min
    I/O read operations:11/sec
    343/min
    I/O write transfer:17.97 KB/sec
    274.99 KB/min
    I/O write operations:8/sec
    227/min
    I/O other transfer:12.84 KB/sec
    448.09 KB/min
    I/O other operations:335/sec
    1,671/min
    Resource allocations
    Threads:74
    12
    Handles:2369
    600
    GUI GDI count:56
    103
    GUI GDI peak:98
    142
    GUI USER count:202
    49
    GUI USER peak:242
    71

    BehaviorsProcess properties

    Platform:64-bit
    Command lines:
    • "C:\windows\syswow64\wwahost.exe" -servernamC:app.wwa
    Owner:User
    Parent process:svchost.exe (Host Process for Windows Services by Microsoft Corporation)

    ResourcesThreads

    Averages
     
    wow64.dll
    Total CPU:0.01262697%
    0.272967%
    Kernel CPU:0.00600806%
    0.107585%
    User CPU:0.00661891%
    0.165382%
    CPU cycles:497,018/sec
    5,741,424/sec
    Context switches:1/sec
    79/sec
    Memory:292 KB
    1.16 MB
    wwahost.exe (main module)
    Total CPU:0.01111571%
    Kernel CPU:0.00241454%
    User CPU:0.00870117%
    CPU cycles:314,664/sec
    Memory:512 KB
    wow64win.dll
    Total CPU:0.00291387%
    Kernel CPU:0.00127402%
    User CPU:0.00163985%
    CPU cycles:68,270/sec
    Memory:416 KB
    wow64cpu.dll
    Total CPU:0.00085868%
    Kernel CPU:0.00031386%
    User CPU:0.00054481%
    CPU cycles:13,897/sec
    Memory:36 KB

    Common loaded modules

    These are modules that are typiclaly loaded within the context of this process.

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Windows 8 34.50%
    Windows 8 Pro 18.50%
    Windows 8.1 18.00%
    Windows 8.1 Pro 11.00%
    Windows 8 Pro with Media Center 5.50%
    Windows 8.1 Single Language 4.00%
    Windows 8 Single Language 4.00%
    Windows 8 Enterprise 2.00%
    Windows 8.1 Pro with Media Center 1.50%
    Windows 8.1 Enterprise 0.50%
    Windows 8 Enterprise Evaluation 0.50%

    Distribution by countryDistribution by country

    United States installs about 54.55% of Microsoft WWA Host.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    Dell 22.22%
    Hewlett-Packard 19.05%
    ASUS 16.67%
    Acer 15.48%
    Toshiba 11.90%
    Lenovo 5.56%
    Sony 4.76%
    GIGABYTE 1.59%
    Samsung 1.19%
    Medion 0.79%
    Alienware 0.40%
    American Megatrends 0.40%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE