wdfmgr.exe" good or bad???

The machines we love to hate

Moderator: Wiz Feinberg

Donny Hinson
Posts: 21763
Joined: 16 Feb 1999 1:01 am
Location: Glen Burnie, Md. U.S.A.

wdfmgr.exe" good or bad???

Post by Donny Hinson »

I've been to many online sites, and some say this is a necessary program, and some say it dangerous spyware added by a worm.

Does anyone know the truth? (See below)

One site says...

<i>Name of the thread: MS_Update Check

Command or file name: wdfmgr.exe

Hazard index: 5. Dangerous threat! Virus, trojan or spyware. You must get rid of it as soon as possible.

Description

Added by the AGOBOT-TB WORM!</i>

While another says...<i>

<i> Description:
wdfmgr.exe is part of Microsoft Windows media player 10 and above. This process decreases compatibility problems whilst the product is in use. This program is non-essential process to the running of the system, but should not be terminated unless suspected to be causing problems.</i>

Image
Dave Potter
Posts: 1565
Joined: 15 Apr 2003 12:01 am
Location: Texas

Post by Dave Potter »

http://www.auditmypc.com/process/wdfmgr.asp

I guess I'd say, in response to your rhetorical question, "does it pose a risk", if your anti-malware apps don't flag it, that should be an answer you can live with.

On the "does anyone know" part of the question, we're all going to get the same "google" hits you've got, so, caveat emptor.<font size="1" color="#8e236b"><p align="center">[This message was edited by Dave Potter on 29 June 2006 at 04:43 PM.]</p></FONT>
User avatar
Wiz Feinberg
Posts: 6113
Joined: 8 Jan 1999 1:01 am
Location: Mid-Michigan, USA

Post by Wiz Feinberg »

Donny;
Search for wdfmgr.exe using Windows Search. I have three instances under XP Pro, one of which is: C:\Windows\System32\wdfmgr.exe.
Reading it's properties the exact filesize is 38,912 bytes.
The "Modified" date is "Friday, January 28, 2005, 2:44:28 PM."
The version number is 5.2.3790.1230.
The Description is: "Windows User Mode Driver Manager"
The Copyright is: "© Microsoft Corporation. All rights reserved."

Compare your version to the above details, then run a virus scan on that file, with up-to-date definitions.

It could be the real deal, or the W32/Agobot-TB

------------------
Bob "Wiz" Feinberg
Moderator of the SGF Computers Forum
<small>Visit my Wiztunes Steel Guitar website at: http://www.wiztunes.com/
or my computer troubleshooting website: Wizcrafts Computer Services,
or my Webmaster Services webpage.
Learn about current computer virus and security threats here.
Read Wiz's Blog for security news and update notices</small>

Donny Hinson
Posts: 21763
Joined: 16 Feb 1999 1:01 am
Location: Glen Burnie, Md. U.S.A.

Post by Donny Hinson »

Thanks Wiz! My files are the same size, but different dates. Just figured I'd check up on it since it just popped up in 4 different folders.

Compswerkin, so we can close this one up! Image