Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

73353 50.00%
be4e2 50.00%
(Note, the developer publishes each variation of this file with the same version, but the hashes are unique.)

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
RegCloseKey, RegOpenKeyExA, RegEnumValueA, RegSetValueExA, RegCreateKeyExA, QueryServiceStatus, CloseServiceHandle, OpenServiceA, OpenSCManagerA, AdjustTokenPrivileges, LookupPrivilegeValueA, OpenProcessToken, RegQueryValueExA
comctl32.dll
InitCommonControlsEx
gdi32.dll
DeleteObject, CreateEllipticRgnIndirect, SelectObject, CreateCompatibleBitmap, GetDeviceCaps, CreateCompatibleDC, CreatePalette, DeleteDC, StretchBlt, SetStretchBltMode, RealizePalette, SelectPalette, PatBlt, GetObjectA, BitBlt
kernel32.dll
FlushFileBuffers, SetStdHandle, SetFilePointer, LCMapStringW, LCMapStringA, ReadFile, HeapReAlloc, VirtualAlloc, HeapAlloc, GetOEMCP, GetACP, GetCPInfo, GetStringTypeW, GetStringTypeA, MultiByteToWideChar, WriteFile, RtlUnwind, HeapFree, VirtualFree, HeapCreate, HeapDestroy, GetFileType, GetStdHandle, SetHandleCount, GetEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsW, FreeEnvironmentStringsA, UnhandledExceptionFilter, TerminateProcess, ExitProcess, GetVersion, GetCommandLineA, GetStartupInfoA, GetModuleFileNameA, GetPrivateProfileIntA, FindResourceExA, LoadResource, LockResource, WideCharToMultiByte, LocalAlloc, LocalFree, GetCurrentProcess, GetLastError, lstrcatA, CreateEventA, ExitThread, WaitForSingleObject, ExpandEnvironmentStringsA, FindFirstFileA, FindClose, CreateProcessA, lstrcpyA, lstrcmpiA, lstrcmpA, lstrlenA, GetPrivateProfileStringA, UnmapViewOfFile, CreateFileMappingA, MapViewOfFile, FreeLibrary, GetProcAddress, LoadLibraryA, GetVersionExA, CreateFileA, DeviceIoControl, CloseHandle, WinExec, GetModuleHandleA, CreateThread, lstrcpynA
shell32.dll
Shell_NotifyIconA
user32.dll
ReleaseCapture, InvalidateRect, SetCapture, SetRect, ExitWindowsEx, PtInRect, ClipCursor, GetClientRect, MapWindowPoints, GetDC, DrawFocusRect, ReleaseDC, GetWindowTextA, SendDlgItemMessageA, SetDlgItemInt, CheckDlgButton, SetDlgItemTextA, IsDlgButtonChecked, GetDlgItem, EnableWindow, SystemParametersInfoA, IsIconic, IsWindowVisible, IsWindowEnabled, SetWindowPos, GetWindowRect, GetParent, GetWindow, SetTimer, DefWindowProcA, BeginPaint, DrawIcon, EndPaint, GetSystemMetrics, MoveWindow, SetWindowRgn, CreateWindowExA, LoadBitmapA, WindowFromPoint, CharUpperA, MapVirtualKeyA, keybd_event, GetForegroundWindow, GetClassNameA, GetWindowLongA, mouse_event, KillTimer, DestroyIcon, LoadMenuA, GetSubMenu, GetMenuStringA, ModifyMenuA, SetMenuDefaultItem, TrackPopupMenu, DestroyMenu, RegisterWindowMessageA, wsprintfA, IsWindow, DestroyWindow, SendMessageA, PostQuitMessage, GetCursorPos, ShowWindow, SetForegroundWindow, UnregisterClassA, FindWindowA, PostMessageA, DefDlgProcA, LoadIconA, LoadCursorA, RegisterClassA, MessageBoxA, CreateDialogParamA, GetMessageA, IsDialogMessageA, TranslateMessage, DispatchMessageA, UpdateWindow

wh_exec.exe

Remove wh_exec.exe
MD5:   7335312dddeb92aa7462a4dc20467b82
SHA1:   87230740fb8274fa7a748fa87fcd7a5a76e40377
SHA256:   f0f0ea438101a3d41c89817f22a3118ad7e8a4004d63ed16291c6a56a8503ef8

Overview

wh_exec.exe executes as a process with the local user's privileges usually within the context of Windows Explorer. It is set to be start when the PC boots and any user logs into Windows (added to the Run registry key for the all users under the local machine).

DetailsDetails

File name:wh_exec.exe
Typical file path:C:\mouse driver\wh_exec.exe
Size:144 KB (147,456 bytes)
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'WheelMouse' → C:\MSI\ADVANC~1\wh_exec.exe
  • 'uni mouse driver tilt' → "C:\Mouse driver\wh_exec.exe"

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00343922%
0.028634%
Kernel CPU:0.00276924%
0.013761%
User CPU:0.00066998%
0.014873%
Kernel CPU time:936,006 ms/min
100,923,805ms/min
Memory
Private memory:4.36 MB
21.59 MB
Private (maximum):5.25 MB
Private (minimum):4.47 MB
Non-paged memory:4.36 MB
21.59 MB
Virtual memory:158.95 MB
140.96 MB
Virtual memory (peak):158.95 MB
169.69 MB
Working set:5.16 MB
18.61 MB
Working set (peak):5.33 MB
37.95 MB
Resource allocations
Threads:105
12
Handles:401
600
GUI GDI count:20
103
GUI USER count:38
49

BehaviorsProcess properties

Tray notification:Yes
Integrety level:Medium
Platform:32-bit
Command line:"C:\mouse driver\wh_exec.exe"
Owner:User
Parent process:explorer.exe (Windows Explorer by Microsoft Corporation)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 8 Pro 50.00%
Windows Vista Home Premium 50.00%

Distribution by countryDistribution by country

United States installs about 50.00% of wh_exec.exe.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Samsung 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE