"EvtEng.exe" Process on Windows 8

Q

What is the "EvtEng.exe" process on Windows 8? Is the "EvtEng.exe" process a virus? Can I terminate the "EvtEng.exe" process?

✍: FYIcenter.com

A

"EvtEng.exe" process represents "Intel(R) PROSet/Wireless Event Log Service" program.

"EvtEng.exe" process is normally running under the parent process "Boot" as shown in the process tree below:

Boot
   EvtEng

On the Processes tab of "Task Manager", "EvtEng.exe" process may be listed as:

Image Name                 Memory   Description
--------------------   ----------   -----------
EvtEng.exe                6,828 K   Intel(R) PROSet/Wireless Event Log Service

Additional information about "EvtEng.exe" process:

Command line:
   "C:\Program Files\Intel\WiFi\bin\EvtEng.exe"

Programe file information:
   Name: EvtEng.exe
   Location: C:\Program Files\Intel\WiFi\bin\EvtEng.exe
   Description: Intel(R) PROSet/Wireless Event Log Service
   Version: 16, 1, 0, 0
   Size: 626416 bytes
   Last modified: 8/28/2013 5:23:40 PM
   Company Name: Intel(R) Corporation
   
Some data files used:
C:\Windows\System32
C:\Program Files\Intel\WiFi\UnifiedLogging\MurocLog.log
C:\Program Files\Intel\WiFi\AutoImport

Some registry keys used:
HKLM\SYSTEM\ControlSet001\Control\SESSION MANAGER
HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions
HKU\.DEFAULT\Control Panel\International
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer
HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids
HKCR\AppID\{E7DCA9D7-1577-45DA-BF99-8BD6184ACF99}
HKLM\SOFTWARE\MICROSOFT\WindowsRuntime\CLSID
HKCR\ActivatableClasses\CLSID
HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\AppCompatFlags

Some DLL libraries used:
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\system32\KERNEL32.DLL
C:\Windows\system32\KERNELBASE.dll
C:\Program Files\Intel\WiFi\bin\MurocApi.dll
C:\Windows\SYSTEM32\mfc100.dll
C:\Windows\SYSTEM32\MSVCR100.dll
C:\Windows\system32\USER32.dll
C:\Windows\system32\ADVAPI32.dll
C:\Windows\system32\SHELL32.dll
C:\Windows\system32\ole32.dll

"EvtEng.exe" process is not a virus. You should not terminate "EvtEng.exe" process.

 

"appupdater.exe" Process on Windows 8

"HeciServer.exe" Process on Windows 8

System Processes on Windows 8

⇑⇑ Windows 8 Processes Tutorials

2016-12-30, 383👍, 0💬