"WUDFHost.exe" Process on Windows 7

Q

What is the "WUDFHost.exe" process on windows 7? Is the "WUDFHost.exe" process a virus? Can I terminate the "WUDFHost.exe" process?

✍: FYIcenter.com

A

"WUDFHost.exe" process represents "Windows Driver Foundation - User-mode Driver Framework Host Process" program. "WUDFHost.exe" process is created by the "Windows Update" service and is related to Windows Update Driver Foundation for running USB drivers in user mode.

"WUDFHost.exe" process is normally running under the parent process "svchost" as shown in the process tree below:

Boot
   wininit
      services
         svchost
            WUDFHost

On the Processes tab of "Task Manager", "WUDFHost.exe" process may be listed as:

Image Name                 Memory   Description
--------------------   ----------   -----------
WUDFHost.exe             12,996 K   Windows Driver Foundation - User-mode 
                                    Driver Framework Host Process

Additional information about "WUDFHost.exe" process:

Command line:
   "C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} 
   -IoEventPortName:HostProcess-30d1a209-036d-449c-b329-fc20da5b65bc 
   -SystemEventPortName:HostProcess-bedd8f5c-3063-4297-aba4-29340ef0cdbf 
   -IoCancelEventPortName:HostProcess-996c565f-74a8-4e43-b9cf-935d5452c315 
   -NonStateChangingEventPortName:HostProcess-c543c895-4186-4c8f-8dd4-1a184635adc3 
   -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 
   -LifetimeId:4733b451-355e-4e14-b6f5-fb65678b6b08 -DeviceGroupId:

Programe file information:
   Name: WUDFHost.exe
   Location: C:\Windows\System32\WUDFHost.exe
   Description: Windows Driver Foundation - User-mode Driver Framework Host Process
   Version: 6.2.9200.16384 (win8_rtm.120725-1247)
   Size: 229888 bytes
   Last modified: 9/3/2016 4:53:47 PM
   Company Name: Microsoft Corporation
   
Some data files used:
C:\Windows\System32
C:\Windows\System32\en-US\WUDFHost.exe.mui
C:\Windows\System32\en-US\setupapi.dll.mui

Some registry keys used:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions
HKLM\SYSTEM\ControlSet001\Control\SESSION MANAGER
HKCU\Control Panel\International
HKLM\SYSTEM\ControlSet001\Enum
HKLM\SYSTEM\ControlSet001\services
HKLM\SYSTEM\ControlSet001\Control\CLASS
HKLM\SYSTEM\ControlSet001\Control\DeviceClasses
HKLM\SYSTEM\ControlSet001\Control\CoDeviceInstallers

Some DLL libraries used:
C:\windows\SYSTEM32\ntdll.dll
C:\windows\system32\kernel32.dll
C:\windows\system32\KERNELBASE.dll
C:\windows\system32\ADVAPI32.dll
C:\windows\system32\msvcrt.dll
C:\windows\SYSTEM32\sechost.dll
C:\windows\system32\RPCRT4.dll
C:\windows\system32\USER32.dll
C:\windows\system32\GDI32.dll
C:\windows\system32\LPK.dll

"WUDFHost.exe" process is not a virus. You should not terminate "WUDFHost.exe" process.

 

System Service Processes on Windows 7

⇒⇒Windows 7 Processes Tutorials

2016-12-21, 479👍, 0💬