"WmiApSrv.exe" Process on Windows 7

Q

What is the "WmiApSrv.exe" process on windows 7? Is the "WmiApSrv.exe" process a virus? Can I terminate the "WmiApSrv.exe" process?

✍: FYIcenter.com

A

"WmiApSrv.exe" process represents "WMI Performance Reverse Adapter" program.

"WmiApSrv.exe" process is normally launched by "services" as shown in the process tree below:

Boot
   wininit
      services
         WmiApSrv

On the Processes tab of "Task Manager", "WmiApSrv.exe" process may be listed as:

Image Name                 Memory   Description
--------------------   ----------   -----------
WmiApSrv.exe              5,464 K   WMI Performance Reverse Adapter

Additional information about "WmiApSrv.exe" process:

Command line:
   C:\windows\system32\wbem\WmiApSrv.exe

Programe file information:
   Name: WmiApSrv.exe
   Location: C:\windows\system32\wbem\WmiApSrv.exe
   Description: WMI Performance Reverse Adapter
   Version: 6.1.7600.16385 (win7_rtm.090713-1255)
   Size: 203264 bytes
   Last modified: 7/13/2009 9:39:55 PM
   Company Name: Microsoft Corporation
   
Some data files used:
C:\Windows\System32
C:\Windows\System32\wbem\en-US\WmiApSrv.exe.mui

Some registry keys used:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions
HKLM\SYSTEM\ControlSet001\Control\SESSION MANAGER

Some DLL libraries used:
C:\windows\SYSTEM32\ntdll.dll
C:\windows\system32\kernel32.dll
C:\windows\system32\KERNELBASE.dll
C:\windows\system32\ADVAPI32.dll
C:\windows\system32\msvcrt.dll
C:\windows\SYSTEM32\sechost.dll
C:\windows\system32\RPCRT4.dll
C:\windows\system32\USER32.dll
C:\windows\system32\GDI32.dll
C:\windows\system32\LPK.dll

"WmiApSrv.exe" process is not a virus. You should not terminate "WmiApSrv.exe" process.

 

System Service Processes on Windows 7

⇒⇒Windows 7 Processes Tutorials

2016-12-21, 370👍, 0💬