Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

7.250.4311.0 15.99%
7.250.4311.0 6.00%
7.250.4232.0 33.63%
7.250.4232.0 16.68%
7.250.4226.0 0.07%
7.250.4225.0 7.24%
7.250.4225.0 20.33%
7.250.4204.0 0.07%

Relationships

Parent process
Child process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
CryptDestroyHash, CryptDestroyKey, MakeAbsoluteSD, ConvertStringSecurityDescriptorToSecurityDescriptorW, RegDeleteKeyW, RegDeleteValueW, RegCloseKey, RegCreateKeyExW, RegOpenKeyExW, RegQueryValueExW, RegSetValueExW, RegQueryInfoKeyW, DeregisterEventSource, ReportEventW, RegisterEventSourceW, SetServiceStatus, CloseServiceHandle, OpenServiceW, OpenSCManagerW, RegEnumKeyExW, CreateServiceW, DeleteService, ControlService, RegisterServiceCtrlHandlerExW, StartServiceCtrlDispatcherW, SetThreadToken, GetTokenInformation, OpenThreadToken, CheckTokenMembership, CryptSetProvParam, CryptGetUserKey, AllocateAndInitializeSid, GetLengthSid, SetSecurityDescriptorDacl, SetSecurityDescriptorGroup, SetSecurityDescriptorOwner, IsValidSecurityDescriptor, AccessCheck, FreeSid, OpenProcessToken, InitializeSecurityDescriptor, InitializeAcl, AddAccessAllowedAce, RegNotifyChangeKeyValue, CryptGetProvParam, CryptGetKeyParam, CryptDeriveKey, CryptVerifySignatureW, CryptSignHashW, CredWriteDomainCredentialsW, CredReadW, CreateProcessAsUserW, CryptImportKey, CryptExportKey, EqualSid, GetSidSubAuthorityCount, GetSidLengthRequired, GetSidIdentifierAuthority, InitializeSid, GetSidSubAuthority, IsValidSid, RegQueryValueExA, RegEnumValueA, CryptCreateHash, CryptSetHashParam, CryptGetHashParam, CryptHashData, CryptAcquireContextA, CryptGenKey, CryptContextAddRef, RegEnumValueW, ImpersonateSelf, CredWriteW, CredDeleteW, CredEnumerateW, CredFree, CryptDecrypt, CryptDuplicateKey, CryptEncrypt, RegOpenCurrentUser, ConvertSidToStringSidW, DuplicateToken, ImpersonateLoggedOnUser, SetTokenInformation, RevertToSelf, CryptGenRandom, CryptReleaseContext, CryptAcquireContextW
crypt32.dll
CryptAcquireCertificatePrivateKey, CertEnumCertificatesInStore, CertCompareCertificate, CryptUnprotectData, CryptExportPublicKeyInfo, CryptEncodeObjectEx, CryptSignAndEncodeCertificate, CertGetCertificateChain, CertFreeCertificateChain, CryptSignMessage, CertGetNameStringA, CryptVerifyMessageSignature, CertVerifyCertificateChainPolicy, CryptImportPublicKeyInfo, CertSetCertificateContextProperty, CryptProtectData, CertGetIssuerCertificateFromStore, CertFreeCertificateContext, CertGetNameStringW, CertVerifySubjectCertificateContext, CertCreateCertificateContext, CertCloseStore, CertDeleteCertificateFromStore, CertFindCertificateInStore, CertOpenStore, CertAddCertificateContextToStore, CertGetCertificateContextProperty, CertDuplicateCertificateContext
iphlpapi.dll
NotifyAddrChange, CancelIPChangeNotify
kernel32.dll
DllMain, GetSystemDirectoryW, GetLastError, GetSystemTimeAsFileTime, SetEvent, GetModuleHandleW, GetProcAddress, LocalAlloc, LocalFree, DeviceIoControl, CloseHandle, OutputDebugStringW, GetFileSize, RegisterWaitForSingleObject, UnregisterWaitEx, GlobalAlloc, GlobalFree, WaitForMultipleObjects, LoadLibraryW, lstrcmpA, DeleteFileW, CopyFileW, CreateMutexW, GetVersionExW, GetUserDefaultUILanguage, GetSystemInfo, ReleaseMutex, CreateFileW, ResetEvent, GetSystemTime, GetComputerNameW, CreateProcessW, lstrlenA, SetEnvironmentVariableA, CompareStringW, CompareStringA, CreateFileA, GetTimeZoneInformation, WriteConsoleW, GetConsoleOutputCP, WriteConsoleA, SetStdHandle, FlushFileBuffers, LCMapStringW, LCMapStringA, GetStringTypeW, GetStringTypeA, InterlockedDecrement, GetLocalTime, TerminateProcess, GetDriveTypeA, GetCurrentDirectoryA, GetFullPathNameW, FindFirstFileW, GetDriveTypeW, FileTimeToLocalFileTime, FileTimeToSystemTime, FindClose, lstrlenW, RaiseException, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSection, DeleteCriticalSection, SizeofResource, LockResource, LoadResource, FindResourceW, FindResourceExW, GetUserDefaultLCID, GetDateFormatA, GetTimeFormatA, GetLocaleInfoA, GetConsoleMode, GetConsoleCP, SetFilePointer, CreateTimerQueueTimer, CreateTimerQueue, DeleteTimerQueueEx, DeleteTimerQueueTimer, GetCurrentThread, WideCharToMultiByte, GetCurrentProcess, GetProcessHandleCount, GetProcessHeap, HeapSetInformation, GetCommandLineW, LoadLibraryExW, MultiByteToWideChar, FreeLibrary, CreateEventW, CreateThread, GetCurrentThreadId, Sleep, GetModuleFileNameW, WaitForSingleObject, lstrcmpiW, HeapDestroy, HeapAlloc, HeapFree, HeapReAlloc, HeapSize, GetStartupInfoW, RtlUnwind, SetUnhandledExceptionFilter, ExitProcess, WriteFile, GetStdHandle, GetModuleFileNameA, FreeEnvironmentStringsW, GetEnvironmentStringsW, SetHandleCount, GetFileType, GetStartupInfoA, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, SetLastError, HeapCreate, VirtualFree, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, IsValidCodePage, UnhandledExceptionFilter, IsDebuggerPresent, VirtualAlloc, GetModuleHandleA, InterlockedExchange, LoadLibraryA, InitializeCriticalSectionAndSpinCount, GetCPInfo, GetACP, GetOEMCP, InterlockedIncrement
netapi32.dll
NetUserModalsGet, NetApiBufferFree
ole32.dll
CLSIDFromProgID, CreateStreamOnHGlobal, CoTaskMemAlloc, CoTaskMemRealloc, CoUninitialize, CoInitializeEx, CoRevokeClassObject, CoRegisterClassObject, CoInitializeSecurity, CoTaskMemFree, CoSuspendClassObjects, StringFromGUID2, CoCreateInstance, CoResumeClassObjects, CoSetProxyBlanket, CoRevertToSelf, CoImpersonateClient, PropVariantClear
psapi.dll
GetProcessMemoryInfo
rpcrt4.dll
RpcServerRegisterIf, RpcServerListen, UuidToStringA, RpcStringFreeA, UuidToStringW, RpcStringFreeW, RpcServerUseProtseqEpW, RpcImpersonateClient, RpcRevertToSelf, I_RpcBindingInqLocalClientPID, RpcMgmtStopServerListening, NdrServerCall2, RpcServerUnregisterIf, UuidCreate
sensapi.dll
IsNetworkAlive
shell32.dll
SHCreateDirectoryExW, SHGetFolderPathW, SHGetSpecialFolderPathW
shlwapi.dll
PathFileExistsW, SHCopyKeyW, SHStrDupW, PathIsDirectoryW, PathCombineW, SHDeleteKeyW
sqmapi.dll
SqmSetAppId, SqmAddToStreamString, SqmIncrement, SqmSet, SqmGetSession, SqmReadSharedMachineId, SqmCreateNewId, SqmWriteSharedMachineId, SqmSetMachineId, SqmEndSession, SqmSetAppVersion, SqmStartUpload, SqmStartSession, SqmAddToStreamDWord
user32.dll
MessageBoxW, GetMessageW, DispatchMessageW, TranslateMessage, CharUpperW, PostThreadMessageW, CharNextW, LoadStringW
userenv.dll
CreateEnvironmentBlock, DestroyEnvironmentBlock, UnloadUserProfile
version.dll
GetFileVersionInfoSizeW, GetFileVersionInfoW, VerQueryValueW
wer.dll
WerReportSubmit, WerReportCreate, WerReportCloseHandle, WerReportSetParameter, WerReportAddFile
winhttp.dll
WinHttpAddRequestHeaders, WinHttpQueryAuthSchemes, WinHttpSetStatusCallback, WinHttpCrackUrl, WinHttpCloseHandle, WinHttpSetOption, WinHttpOpen, WinHttpReadData, WinHttpQueryDataAvailable, WinHttpCreateUrl, WinHttpConnect, WinHttpQueryHeaders, WinHttpReceiveResponse, WinHttpOpenRequest, WinHttpSendRequest, WinHttpGetIEProxyConfigForCurrentUser, WinHttpGetProxyForUrl, WinHttpSetTimeouts
winscard.dll
SCardFreeMemory, SCardListReadersW, SCardEstablishContext, SCardReleaseContext
wintrust.dll
WTHelperGetProvSignerFromChain, WTHelperProvDataFromStateData, WinVerifyTrustEx
ws2_32.dll
WSACreateEvent, WSACloseEvent
wtsapi32.dll
WTSFreeMemory, WTSEnumerateSessionsW, WTSQueryUserToken

Wlidsvc.exe

Microsoft CoReXT by Microsoft Corporation (Signed)

Remove Wlidsvc.exe
Version:   7.250.4232.0
MD5:   2bacd71123f42cea603f4e205e1ae337
SHA1:   0673a5ed24878d1af86e4c2b7267e1c67d9466ca
SHA256:   1fef20554110371d738f462ecffa999158efeed02062414c58c1b61c422bf0b9

What is Wlidsvc.exe?

Microsoft account (previously Windows Live ID) is a single sign-on web service developed and provided by Microsoft that allows users to log in to many websites using one account. Microsoft account allows users to sign in to websites that support this service using a single set of credentials. Users' credentials are not checked by Microsoft account-enabled websites, but by a Microsoft account authentication server.

About Wlidsvc.exe (from Microsoft Corporation)

Windows Live ID (formerly known as Microsoft Passport) is a service that allows you to use a single e-mail address and password, referred to as credentials, to sign into most Microsoft sites and servi

DetailsDetails

File name:WLIDSVC.EXE
Publisher:Microsoft Corp.
Product name:Microsoft® CoReXT
Description:Microsoft® Windows Live ID Service
Typical file path:C:\Program Files\common files\microsoft shared\windows live\wlidsvc.exe
File version:7.250.4232.0
Size:2.19 MB (2,292,096 bytes)
Certificate
Issued to:Microsoft Corporation
Authority (CA):Microsoft Corporation
Effective date:Monday, December 7, 2009
Expiration date:Monday, March 7, 2011
Digital DNA
Entropy:6.009591
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
Lenovo
12% remove
This program provides the utilities (sub packages) related for the special keys and buttons on your computer. The special keys and buttons are designed on the accessibility and usability. The utilities enable the full functionality for the special keys and buttons. This program provides a function to change various settings of the ThinkPad's internal display. This program is applicable only to several featurized ThinkPad products. The s...
Microsoft Corporation
10% remove
Windows Live Essentials is a suite of freeware applications by Microsoft that aims to offer integrated and bundled e-mail, instant messaging, photo-sharing, blog publishing, and security services. Essentials programs are designed to integrate well with each other, with Microsoft Windows, and with other Microsoft web-based services such as SkyDrive and Outlook.com, so that they operate as a seamless whole.

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • wlidsvc
  • 'wlidsvc' (Windows Live ID Sign-in Assistant)

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00119834%
0.028634%
Kernel CPU:0.00058885%
0.013761%
User CPU:0.00060949%
0.014873%
Kernel CPU time:1,885,271 ms/min
100,923,805ms/min
CPU cycles:165,963/sec
17,470,203/sec
Context switches:3/sec
284/sec
Memory
Private memory:7.24 MB
21.59 MB
Private (maximum):13.98 MB
Private (minimum):8.92 MB
Non-paged memory:7.24 MB
21.59 MB
Virtual memory:79.74 MB
140.96 MB
Virtual memory (peak):82.23 MB
169.69 MB
Working set:10.01 MB
18.61 MB
Working set (peak):15.39 MB
37.95 MB
Page faults:16,270/min
2,039/min
I/O
I/O read transfer:504 Bytes/sec
1.02 MB/min
I/O read operations:2/sec
343/min
I/O write transfer:831 Bytes/sec
274.99 KB/min
I/O write operations:8/sec
227/min
I/O other transfer:204 Bytes/sec
448.09 KB/min
I/O other operations:8/sec
1,671/min
Resource allocations
Threads:10
12
Handles:327
600

BehaviorsProcess properties

Integrety level:System
Platform:64-bit
Command lines:
  • "C:\Program Files\common files\microsoft shared\windows live\wlidsvc.exe"
Owner:SYSTEM
Windows Service
Service name:SYSTEM\CurrentControlSet\Services\wlidsvc
Display name:wlidsvc
Description:“Enables Windows Live ID authentication.”
Type:Win32OwnProcess
Parent process:services.exe (Services and Controller app by Microsoft)

ResourcesThreads

Averages
 
ntdll.dll
Total CPU:0.00245064%
0.272967%
Kernel CPU:0.00164636%
0.107585%
User CPU:0.00080429%
0.165382%
CPU cycles:103,236/sec
5,741,424/sec
Context switches:1/sec
79/sec
Memory:1.66 MB
1.16 MB
RPCRT4.dll
Total CPU:0.00048654%
Kernel CPU:0.00024398%
User CPU:0.00024256%
CPU cycles:8,889/sec
Memory:1.26 MB
WLIDSVC.EXE (main module)
Total CPU:0.00029876%
Kernel CPU:0.00019597%
User CPU:0.00010279%
CPU cycles:6,051/sec
Memory:2.21 MB
sechost.dll (Host for SCM/SDDL/LSA Lookup APIs by Microsoft)
Total CPU:0.00029555%
Kernel CPU:0.00009359%
User CPU:0.00020196%
CPU cycles:1,970/sec
Memory:124 KB
ADVAPI32.dll
Total CPU:0.00000192%
Kernel CPU:0.00000000%
User CPU:0.00000192%
CPU cycles:7/sec
Memory:1.03 MB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 62.50%
Windows Vista Home Premium 13.50%
Windows 7 Professional 8.50%
Windows 7 Ultimate 6.00%
Windows 7 Home Basic 4.50%
Windows Vista Home Basic 2.00%
Windows 7 Starter 2.00%
Windows Vista Ultimate 1.00%

Distribution by countryDistribution by country

United States installs about 64.00% of Microsoft® CoReXT.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 25.87%
Hewlett-Packard 24.13%
Toshiba 11.89%
Sony 11.89%
Acer 11.89%
Lenovo 6.29%
ASUS 5.59%
GIGABYTE 1.75%
Samsung 0.70%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE