Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.3.9600.16384 (winblue_rtm.130821-1623) 9.09%
6.1.7600.16385 (win7_rtm.090713-1255) 86.36%
6.1.7600.16385 (win7_rtm.090713-1255) 4.55%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
GetLengthSid, EqualDomainSid, GetSidIdentifierAuthority, GetSidSubAuthorityCount, GetSidSubAuthority, CreateWellKnownSid, AllocateAndInitializeSid, InitializeSecurityDescriptor, InitializeAcl, AddAccessAllowedAce, SetSecurityDescriptorDacl, SetSecurityDescriptorGroup, SetSecurityDescriptorOwner, IsValidSecurityDescriptor, FreeSid, CredProtectW, EventUnregister, EventWrite, RegCloseKey, RegDeleteValueW, RegSetValueExW, RegCreateKeyExW, RegOpenKeyExW, RegGetValueW, RegEnumKeyExW, RegQueryValueExW, AccessCheck, CopySid, EventRegister, GetTokenInformation, ConvertStringSecurityDescriptorToSecurityDescriptorW, EqualSid, IsValidSid, LogonUserW, CredIsProtectedW, ImpersonateLoggedOnUser
api-ms-win-core-debug-l1-1-0.dll
OutputDebugStringA
api-ms-win-core-errorhandling-l1-1-0.dll
SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetLastError, SetLastError, RaiseException
api-ms-win-core-file-l1-1-0.dll
CompareFileTime, WriteFile, ReadFile, CreateFileW, FindClose, FindNextFileW, FindFirstFileW
api-ms-win-core-handle-l1-1-0.dll
DuplicateHandle, CloseHandle
api-ms-win-core-heap-l1-1-0.dll
GetProcessHeap, HeapAlloc, HeapFree
api-ms-win-core-interlocked-l1-1-0.dll
InterlockedCompareExchange, InterlockedIncrement, InterlockedDecrement, InterlockedExchangeAdd, InterlockedExchange
api-ms-win-core-io-l1-1-0.dll
CreateIoCompletionPort, GetOverlappedResult, DeviceIoControl, GetQueuedCompletionStatus, PostQueuedCompletionStatus
api-ms-win-core-libraryloader-l1-1-0.dll
GetProcAddress, FreeLibraryAndExitThread, GetModuleHandleExW, FreeLibrary, GetModuleHandleW
api-ms-win-core-misc-l1-1-0.dll
LocalFree, LocalAlloc, Sleep
api-ms-win-core-namedpipe-l1-1-0.dll
CreatePipe
api-ms-win-core-processthreads-l1-1-0.dll
TerminateProcess, GetCurrentProcess, GetCurrentProcessId, OpenProcessToken, CreateThread, ResumeThread, ProcessIdToSessionId, GetCurrentThread, GetCurrentThreadId, OpenThreadToken
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-synch-l1-1-0.dll
CreateEventW, LeaveCriticalSection, WaitForSingleObject, DeleteCriticalSection, EnterCriticalSection, InitializeCriticalSectionAndSpinCount, SetEvent, ResetEvent, OpenProcess, ReleaseSemaphore
api-ms-win-core-sysinfo-l1-1-0.dll
GetSystemTime, GetTickCount, SystemTimeToFileTime, GetSystemTimeAsFileTime, GetSystemDirectoryW
api-ms-win-security-lsalookup-l1-1-0.dll
LookupAccountSidLocalW
api-ms-win-service-core-l1-1-0.dll
RegisterServiceCtrlHandlerExW, SetServiceStatus
api-ms-win-service-management-l1-1-0.dll
OpenServiceW, OpenSCManagerW, CloseServiceHandle
api-ms-win-service-management-l2-1-0.dll
ChangeServiceConfigW, QueryServiceConfigW
api-ms-win-service-winsvc-l1-1-0.dll
QueryServiceStatus
credui.dll
CredPackAuthenticationBufferW
crypt32.dll
CryptUnprotectData, CryptUnprotectMemory, CryptProtectData
kernel32.dll
UnregisterWaitEx, LoadLibraryW, WaitForMultipleObjects, RaiseFailFastException, WTSGetActiveConsoleSessionId, CancelSynchronousIo, UnregisterWait, RegisterWaitForSingleObject, CreateSemaphoreW
msvcrt.dll
DllMain
netapi32.dll
NetApiBufferFree, NetUserModalsGet, NetGetJoinInformation
ntdll.dll
RtlEqualSid, RtlImageNtHeader, RtlGetNtProductType
ole32.dll
CoTaskMemAlloc, CoTaskMemFree
rpcrt4.dll
UuidCreate, RpcServerUseProtseqEpW, RpcServerListen, RpcServerInqBindings, RpcImpersonateClient, RpcAsyncCompleteCall, RpcRevertToSelfEx, RpcServerInqCallAttributesW, RpcServerSubscribeForNotification, RpcServerRegisterIfEx, RpcEpRegisterW, RpcEpUnregister, RpcServerUnregisterIf, RpcBindingVectorFree, NdrAsyncServerCall, RpcServerTestCancel, RpcServerUnsubscribeForNotification, RpcMgmtStopServerListening, RpcRevertToSelf, NdrServerCall2
secur32.dll
LsaDeregisterLogonProcess, LsaConnectUntrusted, LsaLookupAuthenticationPackage, LsaFreeReturnBuffer, LsaLogonUser
setupapi.dll
SetupDiGetDeviceInterfaceDetailW, SetupDiGetDeviceRegistryPropertyW, SetupDiEnumDeviceInfo, SetupDiEnumDeviceInterfaces, SetupDiDestroyDeviceInfoList, SetupDiGetClassDevsW, SetupDiGetDeviceInstanceIdW, SetupDiOpenDevRegKey, SetupDiGetClassDevsExW
user32.dll
UnregisterDeviceNotification, RegisterDeviceNotificationW
vaultcli.dll
VaultFree, VaultCreateItemType, VaultGetItemType, VaultOpenVault, VaultAddItem, VaultEnumerateItems, VaultRemoveItem, VaultGetItem, VaultCloseVault
version.dll
GetFileVersionInfoSizeW
wtsapi32.dll
WTSDisconnectSession, WTSQuerySessionInformationW, WTSFreeMemory

wbiosrvc.dll

Windows Biometric Service by Microsoft

Remove wbiosrvc.dll
Version:   6.1.7600.16385 (win7_rtm.090713-1255)
MD5:   9614b5d29dc76ac3c29f6d2d3aa70e67
SHA1:   d48e22aec80e01d8eaef95a48758dfc6e2e1c353
SHA256:   a2ffb92f0030b4cd771e862da575eccf2f3a5b4b85858c1241a0c59262c0ec88
This is a Windows system installed file with Windows File Protection (WFP) enabled.

Overview

wbiosrvc.dll is loaded as dynamic link library that runs in the context of a process. The assembly utilizes the .NET run-time framework (which is required to be installed on the PC). This version is designed to run on Windows 7.

DetailsDetails

File name:wbiosrvc.dll
Publisher:Microsoft Corporation
Product name:Windows Biometric Service
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\wbiosrvc.dll
Original name:wbiosrvc.dll.mui
File version:6.1.7600.16385 (win7_rtm.090713-1255)
Product version:6.1.7600.16385
Size:148 KB (151,552 bytes)
Digital DNA
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details

BehaviorsBehaviors

Hosted services
Runs as a shared service under the Windows svcHost
  • Shared name is 'WbioSrvc'
  • Shared name is 'WbioSrvc'
  • Shared name is 'WbioSrvc'
  • Shared name is 'WbioSrvc'
  • Shared name is 'WbioSrvc'
  • Shared name is 'WbioSrvc'
  • Shared name is 'WbioSrvc'
  • Shared name is 'WbioSrvc'
  • Shared name is 'WbioSrvc'
  • Shared name is 'WbioSrvc'
  • Shared name is 'WbioSrvc'
  • Shared name is 'WbioSrvc'
  • Shared name is 'WbioSrvc'
  • Shared name is 'WbioSrvc'
  • Shared name is 'WbioSrvc'
  • Shared name is 'WbioSrvc'
  • Shared name is 'WbioSrvc'
  • Shared name is 'WbioSrvc'
  • Shared name is 'WbioSrvc'
  • Shared name is 'WbioSrvc'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 68.18%
Windows 7 Ultimate 13.64%
Windows 8.1 9.09%
Windows 7 Professional 9.09%

Distribution by countryDistribution by country

United States installs about 50.00% of Windows Biometric Service.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Hewlett-Packard 86.67%
Sony 13.33%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE