Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.3.9600.16384 (winblue_rtm.130821-1623) 1.84%
6.3.9600.16384 (winblue_rtm.130821-1623) 0.10%
6.3.9600.16384 (winblue_rtm.130821-1623) 3.20%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.24%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.05%
6.2.9200.16384 (win8_rtm.120725-1247) 0.92%
6.2.9200.16384 (win8_rtm.120725-1247) 0.87%
6.2.9200.16384 (win8_rtm.120725-1247) 1.65%
6.2.9200.16384 (win8_rtm.120725-1247) 13.87%
6.2.8400.0 (winmain_win8rc.120518-1423) 0.10%
6.2.8400.0 (winmain_win8rc.120518-1423) 0.10%
6.2.8250.0 (winmain_win8beta.120217-1520) 0.05%
6.2.8102.0 (winmain_win8m3.110823-1455) 0.10%
6.1.7600.16385 (win7_rtm.090713-1255) 24.44%
6.1.7600.16385 (win7_rtm.090713-1255) 43.31%
6.1.7600.16385 (win7_rtm.090713-1255) 0.05%
6.1.7600.16385 (win7_rtm.090713-1255) 0.05%
6.1.7600.16385 (win7_rtm.090713-1255) 0.10%
6.1.7600.16385 (win7_rtm.090713-1255) 0.05%
6.0.6000.16386 (vista_rtm.061101-2205) 6.60%
6.0.6000.16386 (vista_rtm.061101-2205) 0.05%
6.0.6000.16386 (vista_rtm.061101-2205) 0.39%
6.0.6000.16386 (vista_rtm.061101-2205) 1.36%
6.0.6000.16386 (vista_rtm.061101-2205) 0.48%
6.0.6000.16386 (vista_rtm.061101-2205) 0.05%

Relationships

Parent process
Child processes
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegOpenKeyExW, RegQueryValueExW, RegCloseKey, RegisterTraceGuidsW, GetTraceLoggerHandle, GetTraceEnableLevel, UnregisterTraceGuids, TraceEvent, DeregisterEventSource, RegisterEventSourceW, ReportEventW, RegGetValueW, RegCreateKeyExW, RegSetValueExW
api-ms-win-core-debug-l1-1-1.dll
IsDebuggerPresent
api-ms-win-core-delayload-l1-1-1.dll
ResolveDelayLoadedAPI, DelayLoadFailureHook
api-ms-win-core-errorhandling-l1-1-1.dll
GetLastError, SetUnhandledExceptionFilter, SetErrorMode, SetLastError, UnhandledExceptionFilter
api-ms-win-core-handle-l1-1-0.dll
DuplicateHandle, CloseHandle
api-ms-win-core-heap-l1-2-0.dll
HeapFree, HeapAlloc, HeapReAlloc, GetProcessHeap, HeapSetInformation
api-ms-win-core-heap-obsolete-l1-1-0.dll
LocalAlloc, LocalFree
api-ms-win-core-interlocked-l1-2-0.dll
InterlockedCompareExchange, InterlockedDecrement, InterlockedExchange, InterlockedIncrement
api-ms-win-core-kernel32-legacy-l1-1-0.dll
LoadLibraryW, GetStartupInfoA
api-ms-win-core-kernel32-legacy-l1-1-1.dll
LoadLibraryW, GetStartupInfoA
api-ms-win-core-libraryloader-l1-1-1.dll
LoadStringW, GetModuleHandleA, GetProcAddress, GetModuleHandleW
api-ms-win-core-libraryloader-l1-2-0.dll
GetProcAddress, LoadStringW, GetModuleHandleW, GetModuleHandleA
api-ms-win-core-localization-obsolete-l1-1-0.dll
CompareStringA
api-ms-win-core-localization-obsolete-l1-2-0.dll
CompareStringA
api-ms-win-core-processthreads-l1-1-1.dll
TerminateProcess, GetCurrentThreadId, GetCurrentThread, GetCurrentProcess, GetCurrentProcessId, GetThreadId, TerminateThread, ResumeThread, GetExitCodeThread, ExitProcess, OpenProcess, SetThreadPriority, CreateThread
api-ms-win-core-processthreads-l1-1-2.dll
GetExitCodeThread, ResumeThread, GetCurrentProcess, GetCurrentThread, TerminateProcess, TerminateThread, SetPriorityClass, SetThreadPriority, CreateThread, OpenProcess, ExitProcess, GetCurrentProcessId, ProcessIdToSessionId, GetThreadId, GetCurrentThreadId
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-psapi-l1-1-0.dll
QueryFullProcessImageNameW
api-ms-win-core-registry-l1-1-0.dll
RegSetValueExW, RegOpenKeyExW, RegQueryValueExW, RegGetValueW, RegCloseKey
api-ms-win-core-rtlsupport-l1-2-0.dll
RtlCompareMemory, RtlCaptureStackBackTrace
api-ms-win-core-shlwapi-legacy-l1-1-0.dll
PathFindFileNameW
api-ms-win-core-string-obsolete-l1-1-0.dll
lstrcmpiW
api-ms-win-core-synch-l1-2-0.dll
DeleteCriticalSection, AcquireSRWLockShared, WaitForMultipleObjectsEx, InitializeSRWLock, Sleep, ReleaseSRWLockShared, ReleaseMutex, CreateMutexW, InitializeCriticalSection, EnterCriticalSection, LeaveCriticalSection, SetEvent, CreateEventW, WaitForSingleObject, ReleaseSRWLockExclusive, AcquireSRWLockExclusive
api-ms-win-core-sysinfo-l1-2-0.dll
GetSystemInfo, GetTickCount64, GetSystemTimeAsFileTime, GetTickCount
api-ms-win-core-sysinfo-l1-2-1.dll
GetTickCount64, GetSystemTimeAsFileTime, GetTickCount, GetSystemInfo
api-ms-win-core-threadpool-legacy-l1-1-0.dll
QueueUserWorkItem
api-ms-win-core-wow64-l1-1-0.dll
IsWow64Process
api-ms-win-eventing-provider-l1-1-0.dll
EventWrite
api-ms-win-security-base-l1-2-0.dll
CheckTokenMembership
dwmcore.dll
MilChannel_CommitChannel, MilComposition_WaitForNextMessage, MilCompositionEngine_UpdateSchedulerSettings, MilResource_SendCommand, MilChannel_GetMarshalType, MilConnection_CreateChannel, MilConnection_HandleSfmEventOnPartition, MilConnection_ClearSfmEventOnPartition, MilConnection_DestroyChannel, MilComposition_PeekNextMessage
dwmredir.dll
DwmRedirectionManagerLockMemoryAllocations, DwmRedirectionManagerEnableMMCSS, DwmRedirectionManagerPlayingVideo, DwmInitializeTransport, DwmShutdownTransport, DwmRedirectionManagerShutdown, DwmRedirectionManagerShouldRemainOnHibernate, DwmRedirectionManagerDispatchMessage, DwmRedirectionManagerFailMessage, DwmRedirectionManagerWaitForMultipleObjects, DwmVersionCheck, DwmRedirectionManagerInitialize, DwmRenderDesktopForDDA
gdi32.dll
GetDeviceCaps, D3DKMTSetProcessSchedulingPriorityClass, GetRandomRgn, GetStockObject, CreateCompatibleBitmap, DeleteObject, GetDIBits, BitBlt, DeleteDC, GetRgnBox, SelectObject, SelectClipRgn, CreateCompatibleDC, CombineRgn, OffsetRgn, GdiAlphaBlend, CreateRectRgn, CreateDIBSection
imm32.dll
ImmDisableIME
kernel32.dll
InterlockedExchange, GetStartupInfoA, GetModuleHandleA, LocalAlloc, LocalFree, ResumeThread, DuplicateHandle, InterlockedDecrement, InterlockedIncrement, lstrcmpiW, WaitForMultipleObjectsEx, IsWow64Process, RegSetValueExW, RegCreateKeyExW, QueryPerformanceCounter, SetThreadPriority, CreateThread, OpenProcess, ReleaseMutex, CreateMutexW, SetEvent, OpenEventW, SignalObjectAndWait, UnhandledExceptionFilter, GetCurrentThread, TerminateThread, TerminateProcess, DebugBreak, GetProcessHeap, HeapReAlloc, HeapAlloc, HeapFree, IsDebuggerPresent, GetModuleHandleW, LoadLibraryExA, InterlockedCompareExchange, FreeLibrary, DelayLoadFailureHook, Sleep, GetUserDefaultLangID, FormatMessageW, GetExitCodeThread, WaitForSingleObject, RegisterWaitForSingleObject, GetThreadId, GetTickCount, ProcessIdToSessionId, CreateEventW, GetCurrentProcessId, SetProcessWorkingSetSize, GetSystemTimeAsFileTime, RegGetValueW, GetSystemInfo, GetCurrentProcess, GetProcAddress, LoadLibraryW, SetErrorMode, QueryFullProcessImageNameW, ExitProcess, GetCurrentThreadId, SetProcessShutdownParameters, SetUnhandledExceptionFilter, HeapSetInformation, WerSetFlags, SetLastError, CloseHandle, GetLastError, GetTickCount64, DeleteCriticalSection, InitializeCriticalSection, QueueUserWorkItem, LeaveCriticalSection, EnterCriticalSection, RtlCaptureStackBackTrace, LoadLibraryA, LocalReAlloc, ResolveDelayLoadedAPI, IsProcessorFeaturePresent, ReleaseSRWLockExclusive, AcquireSRWLockExclusive, CompareStringA, AcquireSRWLockShared, ReleaseSRWLockShared, InitializeSRWLock
msvcrt.dll
DllMain
ntdll.dll
DbgPrompt, NtQuerySystemInformation, DbgPrintEx, RtlCaptureStackBackTrace, WinSqmAddToStreamEx, WinSqmIsOptedIn, NtAcceptConnectPort, NtCompleteConnectPort, NtReplyWaitReceivePort, NtRequestPort, NtConnectPort, NtRequestWaitReplyPort, RtlUpcaseUnicodeChar, WinSqmIncrementDWORD, RtlNtStatusToDosError, EtwEventWriteNoRegistration, NtClose, NtWaitForSingleObject, NtOpenEvent, RtlFreeSid, NtAlpcSendWaitReceivePort, NtAlpcConnectPort, RtlAllocateAndInitializeSid, NtQueryInformationProcess, NtReplyPort, NtCreateWaitablePort, RtlInitUnicodeString, RtlInsertElementGenericTable, RtlIsGenericTableEmpty, RtlLookupElementGenericTable, RtlInitializeGenericTable, EtwEventEnabled, EtwEventRegister, EtwEventUnregister, RtlEnumerateGenericTableWithoutSplaying, RtlDeleteElementGenericTable, WinSqmAddToStream, EtwEventWrite, DbgBreakPoint, WinSqmEventWrite, WinSqmEventEnabled, RtlNumberGenericTableElements, NtSetInformationProcess, ZwQueryWnfStateNameInformation, ZwUpdateWnfStateData, NtOpenProcess, PssCreateSnapshot, PssFreeSnapshot, PssNtCaptureSnapshot, PssNtFreeSnapshot
ole32.dll
CoCreateInstance, CoUninitialize, CoInitialize
slc.dll
SLGetWindowsInformationDWORD
slwga.dll
SLIsGenuineLocal
user32.dll
GetClassNameW, UpdateWindow, SetWindowTextW, DestroyIcon, GetWindowThreadProcessId, GetWindowRect, OffsetRect, SetClassLongW, MonitorFromWindow, AdjustWindowRectEx, GetMonitorInfoW, EnumDisplayDevicesW, EnumDisplaySettingsW, GetSystemMetrics, MsgWaitForMultipleObjectsEx, PostMessageW, RegisterErrorReportingDialog, RegisterGhostWindow, HungWindowFromGhostWindow, InternalGetWindowIcon, GhostWindowFromHungWindow, RegisterFrostWindow, OpenThreadDesktop, GetWindow, CloseDesktop, GetPropW, UnregisterSessionPort, RegisterSessionPort, CheckDesktopByThreadId, DwmStopRedirection, DwmStartRedirection, SetForegroundWindow, IsHungAppWindow, MessageBeep, IsWindowEnabled, EnumWindows, FlashWindowEx, SendMessageTimeoutW, IsWindow, GetCaretBlinkTime, EndTask, OpenDesktopW, IsDialogMessageW, GetAncestor, SetThreadDesktop, EndPaint, ClientToScreen, InternalGetWindowText, GetUpdateRgn, SetTimer, IsIconic, FillRect, KillTimer, IsZoomed, GetTitleBarInfo, GetWindowInfo, LogicalToPhysicalPoint, GetClientRect, BeginPaint, ChangeWindowMessageFilterEx, InvalidateRect, GetWindowLongW, GetWindowTextW, GetDCEx, SetWindowLongW, ShowWindow, GetSysColorBrush, CreateDialogParamW, PostThreadMessageW, IsWindowVisible, GetGuiResources, SetWindowPos, LoadStringW, LoadIconW, RegisterWindowMessageW, DispatchMessageW, TranslateMessage, PeekMessageW, RegisterPowerSettingNotification, ReleaseDC, GetDC, PostQuitMessage, DestroyWindow, UnregisterPowerSettingNotification, DefWindowProcW, CreateWindowExW, RegisterClassExW, GetThreadDesktop, GetUserObjectInformationW, SystemParametersInfoW, SendMessageW, SetProcessDPIAware, ChangeWindowMessageFilter, CreateWindowInBand, CheckProcessSession, GetWindowBand, MonitorFromPoint, DwmControl, UnregisterHotKey, RegisterHotKey
uxtheme.dll
CloseThemeData, OpenThemeData

Dwm.exe

Desktop Window Manager by Microsoft

Remove Dwm.exe
Version:   6.1.7600.16385 (win7_rtm.090713-1255)
MD5:   505bf4d1cadeb8d4f8bcd08d944de25d
SHA1:   a3ea58d117bcf0a7719b50249829c778f12e5b24
SHA256:   526f07768471f4457cbeab7093af0b0242044c89a80a347db47f44ebadeea68d
This is a Windows system installed file with Windows File Protection (WFP) enabled.

What is Dwm.exe?

The desktop composition feature, introduced in Windows Vista, fundamentally changed the way applications display pixels on the screen. When desktop composition is enabled, individual windows no longer draw directly to the screen or primary display device as they did in previous versions of Windows. Instead, their drawing is redirected to off-screen surfaces in video memory, which are then rendered into a desktop image and presented on the display.

About Dwm.exe (from Microsoft)

Desktop composition is performed by the Desktop Window Manager (DWM). Through desktop composition, DWM enables visual effects on the desktop as well as various features such as glass window frames, 3-

DetailsDetails

File name:Dwm.exe
Publisher:Microsoft Corporation
Product name:Desktop Window Manager
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\dwm.exe
Original name:dwm.exe.mui
File version:6.1.7600.16385 (win7_rtm.090713-1255)
Product version:6.1.7600.16385
Size:90.5 KB (92,672 bytes)
Digital DNA
Entropy:6.297931
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details
Network connections
  • [UDP] listens on port 65429

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.00888823%
    0.028634%
    Kernel CPU:0.00390313%
    0.013761%
    User CPU:0.00498509%
    0.014873%
    Kernel CPU time:766,411,570 ms/min
    100,923,805ms/min
    CPU cycles:3,586,708/sec
    17,470,203/sec
    Context switches:74/sec
    284/sec
    Memory
    Private memory:35.04 MB
    21.59 MB
    Private (maximum):39.77 MB
    Private (minimum):17.75 MB
    Non-paged memory:35.04 MB
    21.59 MB
    Virtual memory:123.53 MB
    140.96 MB
    Virtual memory (peak):151.9 MB
    169.69 MB
    Working set:28.47 MB
    18.61 MB
    Working set (peak):49.28 MB
    37.95 MB
    Page faults:2,786,543/min
    2,039/min
    I/O
    I/O read transfer:1.02 KB/sec
    1.02 MB/min
    I/O read operations:1/sec
    343/min
    I/O other transfer:30 Bytes/sec
    448.09 KB/min
    I/O other operations:5/sec
    1,671/min
    Resource allocations
    Threads:5
    12
    Handles:152
    600
    GUI GDI count:16
    103
    GUI GDI peak:32
    142
    GUI USER count:2
    49
    GUI USER peak:9
    71

    BehaviorsProcess properties

    Integrety level:Medium
    Platform:32-bit
    Command lines:
    • "C:\Windows\System32\dwm.exe"
    Owner:User
    Parent process:svchost.exe (Host Process for Windows Services by Microsoft Corporation)

    ResourcesThreads

    Averages
     
    dwmcore.dll
    Total CPU:2.44990710%
    0.272967%
    Kernel CPU:0.61098071%
    0.107585%
    User CPU:1.83892639%
    0.165382%
    CPU cycles:54,281,708/sec
    5,741,424/sec
    Context switches:33/sec
    79/sec
    Memory:1.32 MB
    1.16 MB
    Dwm.exe (main module)
    Total CPU:0.02115747%
    Kernel CPU:0.00888962%
    User CPU:0.01226785%
    CPU cycles:579,112/sec
    Context switches:5/sec
    Memory:104 KB
    uDWM.dll
    Total CPU:0.00056795%
    Kernel CPU:0.00032056%
    User CPU:0.00024740%
    CPU cycles:355,469/sec
    Context switches:4/sec
    Memory:252 KB
    ntdll.dll
    Total CPU:0.00016519%
    Kernel CPU:0.00009573%
    User CPU:0.00006946%
    CPU cycles:168,066/sec
    Context switches:3/sec
    Memory:1.23 MB

    Common loaded modules

    These are modules that are typiclaly loaded within the context of this process.

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Windows 7 Home Premium 32.50%
    Windows 8.1 21.00%
    Windows 7 Ultimate 14.50%
    Windows 8.1 Pro 8.50%
    Windows 7 Professional 7.00%
    Windows 8.1 Single Language 7.00%
    Windows 8.1 Pro with Media Center 2.50%
    Windows 7 Home Basic 2.50%
    Windows Vista Home Premium 2.00%
    Windows 8.1 N 0.50%
    Windows 8 Enterprise N 0.50%
    Windows Seven Black Edition 0.50%
    Windows 8.1 Enterprise Evaluation 0.50%
    Windows 8 Pro 0.50%

    Distribution by countryDistribution by country

    United States installs about 44.22% of Desktop Window Manager.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    Dell 20.63%
    ASUS 18.25%
    Hewlett-Packard 16.67%
    Acer 15.48%
    Toshiba 11.11%
    Lenovo 7.94%
    Sony 3.17%
    Alienware 2.78%
    Samsung 1.19%
    GIGABYTE 1.19%
    Intel 0.79%
    Medion 0.79%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE