Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

4.5.5096.0 86.67%
4.1.4841.0 6.67%
4.0.4343.0 6.67%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
AllocateAndInitializeSid, SetSecurityDescriptorDacl, RegEnumKeyA, GetUserNameA, RegQueryValueExA, RegCreateKeyExA, RegOpenKeyExA, RegSetValueExA, RegCloseKey, RegEnumValueA, RegDeleteValueA, InitializeSecurityDescriptor, FreeSid, GetLengthSid, InitializeAcl, AddAccessAllowedAce, MakeSelfRelativeSD
ceutil.dll
CeSvcGetBinary, CeSvcSetBinary, CeSvcClose, CeSvcSetDword, CeSvcOpen, CeSvcGetDword, CeSvcGetString, CeSvcSetString
comctl32.dll
PropertySheetA
crypt32.dll
CryptUnprotectData, CryptProtectData
gdi32.dll
CreateFontIndirectA, GetDeviceCaps, GetTextExtentPoint32A, SelectObject, GetObjectA, DeleteObject
kernel32.dll
GetProcessHeap, OutputDebugStringW, InterlockedCompareExchange, GetStartupInfoA, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, QueryPerformanceCounter, GetModuleHandleA, GetModuleHandleW, GetProcAddress, GetSystemTimeAsFileTime, GetVersion, LoadLibraryW, GetLastError, SetLastError, GetModuleFileNameW, OutputDebugStringA, GetCurrentThreadId, lstrlenA, ProcessIdToSessionId, GetCurrentProcessId, LocalFree, CompareStringA, LocalAlloc, GetModuleFileNameA, GetCurrentProcess, SetProcessWorkingSetSize, Sleep, CreateSemaphoreA, OpenSemaphoreA, CreateMutexA, CloseHandle, SetEvent, GetTickCount, WaitForSingleObject, ReleaseSemaphore, CreateThread, CreateEventA, LocalReAlloc, FormatMessageA, lstrcmpiA, RaiseException, FreeLibrary, CreateFileA, MultiByteToWideChar, LoadLibraryA, ReleaseMutex, UnmapViewOfFile, FlushViewOfFile, OpenMutexA, MapViewOfFile, CreateFileMappingA, lstrcmpA, InterlockedExchange, WideCharToMultiByte, lstrcpynA, IsDBCSLeadByte, lstrlenW, GetFileAttributesW, InitializeCriticalSection, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, InterlockedDecrement, SetEndOfFile, WriteFile, ReadFile, SetFilePointer, GetFileSize, GetLocalTime, GetTempPathA, GetVersionExA, HeapAlloc, HeapFree, VirtualAlloc, GetSystemInfo, VirtualFree, ExitThread, InterlockedIncrement, SetThreadPriority, GetCurrentThread, ResumeThread, DebugBreak, ResetEvent, SetCommState, GetCommState, EscapeCommFunction, GetOverlappedResult, PurgeComm, GetCommModemStatus, ClearCommError, WaitCommEvent, SetCommMask, SetCommTimeouts, GetCommTimeouts, HeapCreate, HeapDestroy, IsBadWritePtr, DeviceIoControl, ExitProcess
msvcr71.dll
DllMain
msvcr80.dll
DllMain
ole32.dll
CLSIDFromString, CoUninitialize, CoCreateInstance, CoTaskMemFree, CoInitializeEx
rapi.dll
CeRapiInitEx, CeRapiUninit, CeRegCreateKeyEx, CeRegSetValueEx, CeRegCloseKey
setupapi.dll
SetupDiGetDeviceRegistryPropertyA, SetupDiEnumDeviceInfo, SetupDiDestroyDeviceInfoList, SetupDiGetClassDevsA
shell32.dll
Shell_NotifyIconA, SHGetFolderPathA, ShellExecuteA
shlwapi.dll
StrCpyNW, PathFindFileNameA
tcp2udp.dll
TCP2UDPStartup, TCP2UDPShutdown
user32.dll
SetWindowLongA, SetDlgItemTextA, GetSystemMenu, CheckDlgButton, GetDlgItemTextA, LoadIconA, SendDlgItemMessageA, ShowWindow, SetFocus, IsDlgButtonChecked, EndDialog, SetWindowTextA, GetWindowRect, ScreenToClient, SetWindowPos, GetDlgItem, GetSystemMetrics, PostMessageA, SendMessageTimeoutA, IsWindow, DispatchMessageA, TranslateMessage, MsgWaitForMultipleObjects, SetCursor, PeekMessageA, LoadCursorA, DestroyMenu, TrackPopupMenu, SetForegroundWindow, GetLastActivePopup, GetCursorPos, EnableMenuItem, SetMenuDefaultItem, GetSubMenu, LoadMenuA, SetTimer, GetDoubleClickTime, KillTimer, DestroyWindow, RegisterClassA, CreateWindowExA, CreateDialogParamA, ReleaseDC, SystemParametersInfoA, GetDC, MessageBoxA, LoadStringA, LoadImageA, PostQuitMessage, GetClientRect, SendMessageA, IsWindowEnabled, MessageBeep, DefWindowProcA, RegisterWindowMessageA, DestroyIcon, FindWindowA, GetMessageA, DialogBoxParamA, EnableWindow, SetParent, IsWindowVisible, GetWindowLongA, GetParent
version.dll
GetFileVersionInfoA, GetFileVersionInfoSizeA, VerQueryValueA
winmm.dll
PlaySoundA
ws2_32.dll
WSAEnumProtocolsA, WSAEventSelect, WSAAccept, WSAEnumNetworkEvents, WSASocketA, WSAWaitForMultipleEvents, WSAAddressToStringA, WSACloseEvent, WSASetEvent, WSACreateEvent

WCESCOMM.exe

Microsoft ActiveSync by Microsoft Corporation (Signed)

Remove WCESCOMM.exe
Version:   4.0.4343.0
MD5:   8de3880ac3458c904cae6aedc931be03
SHA1:   d62a398f792b478375f7b9bf5097046e49afaf4d
SHA256:   2ab3a4474e46c43b6f4b92ef8284681c31b64787b0e147b9cf7d4fbb435fec2f

What is WCESCOMM.exe?

ActiveSync Connection Manager allows a mobile device to be synchronized with either a desktop PC or a server running a compatible software product including Microsoft Exchange Server. On desktops, ActiveSync synchronizes emails, calendar, contacts and tasks with Microsoft Outlook, along with Internet bookmarks and files. ActiveSync does not support all features of Outlook. For instance, contacts grouped into subfolders are not transferred.

Overview

wcescomm.exe executes as a process with the local user's privileges. It is set to be run when the PC boots and the user logs into Windows (added to the Run registry key for the current user). It has been configured with a firewall exception which allows both inbound and outbound network communication without being blocked. The file is digitally signed by Microsoft Corporation.

DetailsDetails

File name:wcescomm.exe
Publisher:Microsoft Corporation
Product name:Microsoft ActiveSync
Description:ActiveSync Connection Manager
Typical file path:C:\Program Files\microsoft activesync\wcescomm.exe
File version:4.0.4343.0
Product version:4.0.4343
Size:1.14 MB (1,196,032 bytes)
Build date:4/23/2005 3:18 AM
Certificate
Issued to:Microsoft Corporation
Authority (CA):Microsoft Corporation
Effective date:Tuesday, April 4, 2006
Expiration date:Tuesday, April 10, 2007
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 8.0
.NET CLR:No
More details

BehaviorsBehaviors

Startup files (user) run
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'H/PC Connection Agent' → "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
Windows firewall allowed programs
Exceptions allow programs to access to the Internet through an outbound connections
  • Firewall exception for 'C:\Program Files\Microsoft ActiveSync\wcescomm.exe'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00040318%
0.028634%
Kernel CPU:0.00030512%
0.013761%
User CPU:0.00009806%
0.014873%
Kernel CPU time:2,922 ms/min
100,923,805ms/min
Memory
Private memory:7.96 MB
21.59 MB
Private (maximum):10.78 MB
Private (minimum):10.57 MB
Non-paged memory:7.96 MB
21.59 MB
Virtual memory:49.92 MB
140.96 MB
Virtual memory (peak):58.99 MB
169.69 MB
Working set:10.76 MB
18.61 MB
Working set (peak):10.89 MB
37.95 MB
Page faults:15,009/min
2,039/min
I/O
I/O read transfer:0 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O write transfer:0 Bytes/sec
274.99 KB/min
I/O write operations:1/sec
227/min
I/O other transfer:3 Bytes/sec
448.09 KB/min
I/O other operations:1/sec
1,671/min
Resource allocations
Threads:4
12
Handles:245
600
GUI GDI count:8
103
GUI USER count:8
49

BehaviorsProcess properties

Tray notification:Yes
Integrety level:Undefined
Platform:32-bit
Command line:"C:\Program Files\microsoft activesync\wcescomm.exe"
Owner:User
Parent process:Explorer.EXE (Windows Explorer by Microsoft)

ResourcesThreads

Averages
 
wcescomm.exe (main module)
Total CPU:0.00157355%
0.272967%
Kernel CPU:0.00140791%
0.107585%
User CPU:0.00016564%
0.165382%
Memory:1.14 MB
1.16 MB
TCP2UDP.dll
Total CPU:0.00014506%
Kernel CPU:0.00012434%
User CPU:0.00002072%
Memory:28 KB

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 100.00%

Distribution by countryDistribution by country

United States installs about 40.00% of Microsoft ActiveSync.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
MSI 80.00%
Dell 20.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE