toolwizcares.exe
Toolwiz Care by XII CNC Inc. (Signed)
Overview
There are 4 versions of toolwizcares.exe in the wild, the latest version being 3.1.0.0. toolwizcares.exe is run as a standard windows process with the logged in user's account privileges. By adding a startup entry to the run registry key, the file will be executed when the user logs into Windows. In addition the the run registry key, it also creates a scheduled job to be executed by the Windows Task Scheduler up user login, this is typically done in order to bypass a User Account Control (UAC) prompt. The average file size is about 5.04 MB. The file is a digitally signed and issued to XII CNC Inc. by VeriSign. Some variations of the file have been seen to be installed with the program Toolwiz Care from ToolWiz. During the process's lifecycle, the typical CPU resource utilization is about 0.0022% including both foreground and background operations, the average private memory consumption is about 34.86 MB. Addionally, typically read and write I/O disk operations is about 452.92 KB per minute for reads and 60.05 KB per minute for writes.
Details |
File name: | toolwizcares.exe |
Publisher: | Toolwiz |
Product name: | Toolwiz Care |
Typical file path: | C:\Program Files\toolwizcarefree\toolwizcares.exe |
Original name: | Toolwiz.exe |
Certificate |
Issued to: | XII CNC Inc. |
Authority (CA): | VeriSign |
Programs installed in
(Note, the programs listed below are for all versions of Toolwiz Care.)
“ToolWiz Care is a set of free-of-charge tools designed to speed up your PC and give your system a full range of care. With multi-functional optimization suite, this software provides a collection of ...”
Behaviors
(Note, the behaviors below are for all versions of toolwizcares.exe, select a unique version for details.)
Startup files (user) run
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
- 'ToolwizCareFree' → "C:\Program Files\ToolwizCareFree\ToolwizCares.exe" -autorun
Scheduled tasks
- Entry path '\ToolwizCareFree'
Scheduled tasks startups
Set to load on user login (bypasses Windows UAC if enabled)
- Login entry path '\ToolwizCareFree'
All file variations of toolwizcares.exe
Distribution by Windows OS
OS version | distribution |
Windows 7 Home Premium |
75.00% |
|
Microsoft Windows XP |
12.50% |
|
Windows 7 Ultimate |
12.50% |
|
Distribution by country
United States installs about 62.50% of Toolwiz Care.
Distribution by PC manufacturer
PC Manufacturer | distribution |
Hewlett-Packard |
40.00% |
|
Toshiba |
20.00% |
|
ASUS |
20.00% |
|
American Megatrends |
10.00% |
|
Acer |
10.00% |
|