Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.500.3165.0 34.27%
6.500.3165.0 46.01%
6.500.3146.0 0.94%
6.500.3146.0 0.47%
6.3.9600.16384 (winblue_rtm.130821-1623) 3.29%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.47%
6.2.9200.16384 (win8_rtm.120725-1247) 0.94%
6.2.9200.16384 (win8_rtm.120725-1247) 2.82%
6.2.9200.16384 (win8_rtm.120725-1247) 9.39%
6.2.9200.16384 (win8_rtm.120725-1247) 1.41%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
CryptDestroyHash, CryptDestroyKey, RegDeleteKeyW, RegDeleteValueW, RegCloseKey, RegCreateKeyExW, RegOpenKeyExW, RegQueryValueExW, RegSetValueExW, RegQueryInfoKeyW, MakeAbsoluteSD, ConvertStringSecurityDescriptorToSecurityDescriptorW, DeregisterEventSource, ReportEventW, RegisterEventSourceW, SetServiceStatus, CloseServiceHandle, OpenServiceW, OpenSCManagerW, RegEnumKeyExW, CreateServiceW, DeleteService, ControlService, RegisterServiceCtrlHandlerExW, StartServiceCtrlDispatcherW, SetThreadToken, GetTokenInformation, OpenThreadToken, CheckTokenMembership, CryptGetUserKey, LookupAccountNameW, AllocateAndInitializeSid, GetLengthSid, SetSecurityDescriptorDacl, SetSecurityDescriptorGroup, SetSecurityDescriptorOwner, CryptGetKeyParam, CryptDeriveKey, CryptVerifySignatureW, CryptSignHashW, FreeSid, CredWriteDomainCredentialsW, CreateProcessAsUserW, CredReadW, CryptImportKey, CryptExportKey, RegQueryValueExA, RegEnumValueA, OpenProcessToken, EqualSid, GetSidSubAuthorityCount, GetSidLengthRequired, GetSidIdentifierAuthority, InitializeSid, GetSidSubAuthority, CryptCreateHash, CryptDuplicateKey, CryptSetHashParam, CryptGetHashParam, CryptHashData, IsValidSid, ConvertStringSidToSidW, IsWellKnownSid, CryptAcquireContextA, CryptGenKey, RegEnumValueW, CredEnumerateW, CredWriteW, CredDeleteW, CredFree, ConvertSidToStringSidW, CryptDecrypt, CryptEncrypt, RegOpenCurrentUser, DuplicateToken, ImpersonateLoggedOnUser, SetTokenInformation, RevertToSelf, CryptGetProvParam, CryptContextAddRef, CryptGenRandom, CryptReleaseContext, CryptAcquireContextW, GetAce, GetAclInformation, AddAccessAllowedAce, AddAce, SetNamedSecurityInfoW, InitializeAcl, GetSecurityDescriptorDacl, GetFileSecurityW, InitializeSecurityDescriptor, AccessCheck, IsValidSecurityDescriptor, CryptSetProvParam
crypt32.dll
CertFreeCertificateChain, CryptSignMessage, CertGetNameStringA, CryptUnprotectData, CryptProtectData, CryptExportPublicKeyInfo, CryptEncodeObjectEx, CryptSignAndEncodeCertificate, CertSetCertificateContextProperty, CertGetIssuerCertificateFromStore, CertEnumCertificatesInStore, CertCompareCertificate, CertDuplicateCertificateContext, CertGetCertificateContextProperty, CertAddCertificateContextToStore, CertOpenStore, CertFindCertificateInStore, CertDeleteCertificateFromStore, CertCloseStore, CertGetNameStringW, CryptAcquireCertificatePrivateKey, CertCreateCertificateContext, CertVerifySubjectCertificateContext, CertFreeCertificateContext, CryptVerifyMessageSignature, CertVerifyCertificateChainPolicy, CryptImportPublicKeyInfo, CertGetCertificateChain
iphlpapi.dll
CancelIPChangeNotify, NotifyAddrChange
kernel32.dll
GetStringTypeA, GetStringTypeW, LCMapStringA, LCMapStringW, FlushFileBuffers, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, GetTimeZoneInformation, CreateFileA, CompareStringA, CompareStringW, SetEnvironmentVariableA, GetSystemInfo, lstrcmpA, CreateFileW, WaitForMultipleObjects, LoadLibraryW, DeleteFileW, GetFileSize, ReadFile, CreateMutexW, ExpandEnvironmentStringsW, ReleaseMutex, ResetEvent, GetComputerNameW, lstrlenW, CreateProcessW, lstrlenA, SetEndOfFile, GetLocalTime, FileTimeToLocalFileTime, FileTimeToSystemTime, GetUserDefaultLCID, GetDateFormatA, GetTimeFormatA, OutputDebugStringW, GlobalAlloc, GlobalFree, EnumResourceNamesW, CreateDirectoryExW, GetSystemDefaultLangID, SetThreadLocale, GetFileAttributesExW, FindFirstFileW, TryEnterCriticalSection, LockResource, LoadResource, FindResourceW, FindResourceExW, GetLastError, GetSystemTimeAsFileTime, GetConsoleMode, GetConsoleCP, SetFilePointer, IsValidCodePage, GetOEMCP, GetCPInfo, LoadLibraryA, VirtualAlloc, IsDebuggerPresent, UnhandledExceptionFilter, TerminateProcess, GetCurrentProcessId, GetTickCount, QueryPerformanceCounter, VirtualFree, HeapCreate, SetLastError, TlsFree, TlsSetValue, FindNextFileW, FindClose, InterlockedIncrement, InterlockedDecrement, TlsAlloc, RaiseException, TlsGetValue, GetStartupInfoA, GetFileType, SetHandleCount, GetCommandLineA, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, GetModuleFileNameA, GetStdHandle, WriteFile, CloseHandle, lstrcmpiW, LocalFree, SetCurrentDirectoryW, GetCurrentDirectoryW, EnterCriticalSection, LocalAlloc, WaitForSingleObject, GetModuleFileNameW, Sleep, GetModuleHandleW, GetCurrentThreadId, CreateThread, CreateEventW, SetEvent, FreeLibrary, MultiByteToWideChar, LoadLibraryExW, GetProcessHandleCount, LeaveCriticalSection, InitializeCriticalSection, DeleteCriticalSection, SizeofResource, ExitProcess, GetModuleHandleA, CopyFileW, GetProcAddress, SetUnhandledExceptionFilter, RtlUnwind, GetStartupInfoW, HeapSize, HeapReAlloc, HeapFree, HeapAlloc, HeapDestroy, GetVersionExA, GetThreadLocale, GetLocaleInfoA, GetACP, InterlockedExchange, CreateTimerQueueTimer, DeleteTimerQueueEx, GetCurrentThread, WideCharToMultiByte, GetProcessHeap, HeapSetInformation, GetCommandLineW, CreateTimerQueue, GetCurrentProcess, GetVersionExW
netapi32.dll
NetUserModalsGet, NetApiBufferFree
ntdsapi.dll
DsUnBindW, DsCrackNamesW, DsFreeNameResultW, DsBindW
ole32.dll
IIDFromString, CreateStreamOnHGlobal, CoTaskMemRealloc, CoUninitialize, CoInitializeEx, CoRevokeClassObject, CoRegisterClassObject, CoTaskMemFree, CoTaskMemAlloc, CoInitializeSecurity, CLSIDFromProgID, CoSuspendClassObjects, StringFromGUID2, CoCreateInstance, CoResumeClassObjects, PropVariantClear, CoImpersonateClient, CoRevertToSelf, CoSetProxyBlanket
psapi.dll
GetProcessMemoryInfo
rpcrt4.dll
RpcServerUnregisterIf, RpcRevertToSelf, NdrServerCall2, RpcServerUseProtseqEpW, RpcStringFreeW, RpcServerRegisterIf, RpcImpersonateClient, I_RpcBindingInqLocalClientPID, UuidCreate, UuidToStringA, RpcStringFreeA, UuidToStringW, RpcServerListen, RpcMgmtStopServerListening
secur32.dll
GetUserNameExW
sensapi.dll
IsNetworkAlive
shell32.dll
SHGetFolderPathW, SHFileOperationW, SHGetSpecialFolderPathW, SHCreateDirectoryExW
shlwapi.dll
PathIsDirectoryW, PathFileExistsW, SHStrDupW, PathCombineW
sqmapi.dll
SqmAddToStreamDWord, SqmSet, SqmEndSession, SqmStartSession, SqmStartUpload, SqmSetAppVersion, SqmSetMachineId, SqmWriteSharedMachineId, SqmCreateNewId, SqmReadSharedMachineId, SqmGetSession, SqmSetAppId, SqmAddToStreamString
user32.dll
LoadStringA, LoadStringW, TranslateMessage, UnregisterClassA, PostThreadMessageW, GetMessageW, CharUpperW, MessageBoxW, DispatchMessageW, CharNextW
userenv.dll
UnloadUserProfile, CreateEnvironmentBlock, DestroyEnvironmentBlock
version.dll
GetFileVersionInfoW, GetFileVersionInfoSizeW, VerQueryValueW
winhttp.dll
WinHttpGetIEProxyConfigForCurrentUser, WinHttpGetProxyForUrl, WinHttpCreateUrl, WinHttpConnect, WinHttpOpenRequest, WinHttpSetOption, WinHttpSendRequest, WinHttpOpen, WinHttpSetTimeouts, WinHttpQueryHeaders, WinHttpQueryAuthSchemes, WinHttpQueryDataAvailable, WinHttpReadData, WinHttpAddRequestHeaders, WinHttpCloseHandle, WinHttpCrackUrl, WinHttpReceiveResponse
wininet.dll
InternetSetCookieW
wintrust.dll
WinVerifyTrustEx, WTHelperGetProvSignerFromChain, WTHelperProvDataFromStateData
ws2_32.dll
WSACloseEvent, WSACreateEvent
wtsapi32.dll
WTSFreeMemory, WTSEnumerateSessionsW, WTSQueryUserToken

Wlidsvc.exe

Microsoft Windows Live ID by Microsoft Corporation (Signed)

Remove Wlidsvc.exe
Version:   6.3.9431.0 (winmain_bluemp.130615-1214)
MD5:   9f458c8bc4c5dc63bff2c97444afc7f9
SHA1:   428adcbf7db5b4531937e4bf2c14e11dc6baa555
SHA256:   2828133b6cad7f6a51d92429f3c50a56811877a69149fefecda39243bd4bba95

What is Wlidsvc.exe?

Microsoft account (previously Windows Live ID) is a single sign-on web service developed and provided by Microsoft that allows users to log in to many websites using one account. Microsoft account allows users to sign in to websites that support this service using a single set of credentials. Users' credentials are not checked by Microsoft account-enabled websites, but by a Microsoft account authentication server.

About Wlidsvc.exe (from Microsoft Corporation)

Windows Live ID (formerly known as Microsoft Passport) is a service that allows you to use a single e-mail address and password, referred to as credentials, to sign into most Microsoft sites and servi

DetailsDetails

File name:wlidsvc.exe
Publisher:Microsoft Corporation
Product name:Microsoft® Windows Live ID
Description:Microsoft® Windows Live ID Service
Typical file path:C:\Program Files\common files\microsoft shared\windows live\wlidsvc.exe
File version:6.3.9431.0 (winmain_bluemp.130615-1214)
Product version:6.3.9431.0
Size:1.49 MB (1,566,208 bytes)
Build date:6/15/2013 3:35 PM
Certificate
Issued to:Microsoft Corporation
Authority (CA):Microsoft Corporation
Effective date:Wednesday, October 22, 2008
Expiration date:Friday, January 22, 2010
Digital DNA
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'wlidsvc' (Windows Live ID Sign-in Assistant)
  • wlidsvc

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 25.86%
Windows 7 Home Premium 23.56%
Windows 7 Ultimate 21.26%
Windows Vista Home Premium 11.49%
Windows 7 Professional 9.20%
Windows Vista Business 2.30%
Windows 7 Enterprise 1.72%
Windows Vista Home Basic 1.15%
Windows 7 Home Basic 1.15%
Windows 7 Starter 1.15%
Windows Vista Ultimate 1.15%

Distribution by countryDistribution by country

United States installs about 51.15% of Microsoft® Windows Live ID.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Hewlett-Packard 30.33%
Dell 19.67%
Toshiba 13.11%
Acer 9.84%
ASUS 6.56%
Sony 3.28%
Lenovo 3.28%
MSI 3.28%
Gateway 3.28%
Samsung 2.46%
Sahara 1.64%
American Megatrends 1.64%
GIGABYTE 1.64%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE