Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

dd9d8 83.33%
14154 16.67%
(Note, the developer publishes each variation of this file with the same version, but the hashes are unique.)

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
RegSetValueExW, RegEnumKeyW, RegDeleteKeyW, RegQueryValueW, RegOpenKeyW, RegCreateKeyExW, CreateProcessAsUserW, SetServiceStatus, RegisterServiceCtrlHandlerExW, StartServiceCtrlDispatcherW, RegQueryValueExW, RegOpenKeyExW, RegCloseKey, DeleteService, CreateServiceW, EnumDependentServicesW, ControlService, ChangeServiceConfigW, QueryServiceStatusEx, StartServiceW, OpenServiceW, OpenSCManagerW, CloseServiceHandle, AdjustTokenPrivileges, LookupPrivilegeValueW, OpenProcessToken
feature.dll
CreateFeature, ReleaseFeature
gdi32.dll
GetStockObject, DeleteDC, SetMapMode, RestoreDC, SaveDC, CreateBitmap, SetBkColor, SetTextColor, GetClipBox, GetDeviceCaps, ScaleWindowExtEx, SetWindowExtEx, ScaleViewportExtEx, SetViewportExtEx, OffsetViewportOrgEx, SetViewportOrgEx, SelectObject, Escape, ExtTextOutW, TextOutW, RectVisible, PtVisible, DeleteObject
kernel32.dll
WriteFile, SetFilePointer, FlushFileBuffers, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, RtlUnwind, ReadFile, HeapReAlloc, ExitProcess, HeapSize, SetHandleCount, GetStdHandle, GetFileType, GetStartupInfoA, GetCPInfo, GetOEMCP, IsValidCodePage, LCMapStringW, GetConsoleCP, GetConsoleMode, HeapCreate, VirtualFree, VirtualAlloc, LCMapStringA, GetModuleFileNameA, FreeEnvironmentStringsW, GetEnvironmentStringsW, QueryPerformanceCounter, GetSystemTimeAsFileTime, InitializeCriticalSectionAndSpinCount, GetStringTypeA, GetStringTypeW, GetLocaleInfoA, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, SetStdHandle, CreateFileA, GlobalFlags, GetModuleHandleA, WritePrivateProfileStringW, lstrlenA, TlsFree, DeleteCriticalSection, LocalReAlloc, TlsSetValue, TlsAlloc, InitializeCriticalSection, GlobalHandle, GlobalReAlloc, EnterCriticalSection, TlsGetValue, LeaveCriticalSection, LocalAlloc, GetCurrentProcessId, InterlockedDecrement, InterlockedIncrement, GlobalAddAtomW, GlobalFindAtomW, LoadLibraryA, GetVersionExA, SetErrorMode, GlobalDeleteAtom, GetCurrentThread, GetCurrentThreadId, ConvertDefaultLocale, EnumResourceLanguagesW, lstrcmpA, GetLocaleInfoW, InterlockedExchange, lstrcmpW, SetLastError, GlobalFree, GlobalAlloc, GlobalLock, GlobalUnlock, lstrlenW, Process32NextW, OpenProcess, Process32FirstW, CreateToolhelp32Snapshot, LocalFree, FormatMessageW, WaitForMultipleObjects, CreateThread, ReleaseSemaphore, CreateSemaphoreW, WaitForSingleObject, SetEvent, CreateEventW, WideCharToMultiByte, GetACP, HeapFree, GetProcessHeap, HeapAlloc, Sleep, GetTickCount, GetModuleFileNameW, GetVersionExW, GetProcAddress, FreeLibrary, LoadLibraryW, DeviceIoControl, CreateFileW, CloseHandle, GetLastError, GetCurrentProcess, GetModuleHandleW, GetCommandLineW, MultiByteToWideChar, FindResourceW, LoadResource, LockResource, SizeofResource, RaiseException
setupapi.dll
CM_Get_DevNode_Status, SetupDiGetDeviceRegistryPropertyW, SetupDiEnumDeviceInfo, SetupDiGetDeviceInstanceIdW, SetupDiGetDeviceInterfaceDetailW, SetupDiEnumDeviceInterfaces, SetupDiGetClassDevsW, SetupDiDestroyDeviceInfoList
shlwapi.dll
PathFindExtensionW, PathFindFileNameW
user32.dll
DestroyMenu, ShowWindow, SetWindowTextW, ClientToScreen, GrayStringW, DrawTextExW, DrawTextW, TabbedTextOutW, SetCursor, SetMenuItemBitmaps, GetMenuCheckMarkDimensions, LoadBitmapW, ModifyMenuW, EnableMenuItem, CheckMenuItem, GetMessageW, TranslateMessage, GetActiveWindow, GetCursorPos, ValidateRect, GetWindowThreadProcessId, IsWindowEnabled, LoadCursorW, ReleaseDC, GetSysColorBrush, RegisterWindowMessageW, LoadIconW, WinHelpW, GetCapture, SetWindowsHookExW, CallNextHookEx, GetClassLongW, SetPropW, GetPropW, RemovePropW, GetFocus, GetWindowTextLengthW, GetWindowTextW, GetForegroundWindow, GetLastActivePopup, DispatchMessageW, GetDlgItem, GetTopWindow, DestroyWindow, UnhookWindowsHookEx, GetMessageTime, GetMessagePos, UnregisterDeviceNotification, IsWindow, PeekMessageW, MapWindowPoints, GetKeyState, SetMenu, EnableWindow, SetForegroundWindow, GetClientRect, MessageBoxW, CreateWindowExW, GetClassInfoExW, GetClassInfoW, RegisterClassW, GetSysColor, AdjustWindowRectEx, GetParent, CopyRect, GetDC, PostMessageW, RegisterDeviceNotificationW, IsWindowVisible, EnumChildWindows, GetClassNameW, SendMessageW, EnumWindows, GetSubMenu, GetMenuItemCount, GetMenuItemID, GetMenuState, PostQuitMessage, GetWindow, GetSystemMetrics, GetWindowRect, PtInRect, GetDlgCtrlID, DefWindowProcW, CallWindowProcW, GetMenu, GetWindowLongW, SetWindowLongW, SetWindowPos, SystemParametersInfoA, IsIconic, GetWindowPlacement
userenv.dll
DestroyEnvironmentBlock, CreateEnvironmentBlock
winspool.drv
DocumentPropertiesW, OpenPrinterW, ClosePrinter

c+weject.exe

Remove c+weject.exe
MD5:   141547babc4714fae5e66625fd960dea
SHA1:   7b037ebd98bcf0ad7da871864e1547c32d7f4cd5
SHA256:   e109fe86d22840ac6663da2d3826ad48ddb4e639747ceae1d7a2df32cc660c48

Overview

c+weject.exe runs as a service under the name CDROM_Eject_Z (CDROM_Detect) with extensive SYSTEM privileges (full administrator access).

DetailsDetails

File name:c+weject.exe
Typical file path:C:\Program Files\smartfren connex ac782 ui\c+weject.exe
Size:263 KB (269,312 bytes)
Build date:11/21/2011 9:21 AM
Digital DNA
PE subsystem:Windows Console
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'CDROM_Detect'
  • 'CDROM_Eject_Z'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00192486%
0.028634%
Kernel CPU:0.00102632%
0.013761%
User CPU:0.00089854%
0.014873%
Kernel CPU time:2,496,016 ms/min
100,923,805ms/min
Memory
Private memory:1.85 MB
21.59 MB
Private (maximum):4.67 MB
Private (minimum):3.32 MB
Non-paged memory:1.85 MB
21.59 MB
Virtual memory:58.55 MB
140.96 MB
Virtual memory (peak):59.55 MB
169.69 MB
Working set:3.34 MB
18.61 MB
Working set (peak):4.67 MB
37.95 MB
Resource allocations
Threads:4
12
Handles:113
600

BehaviorsProcess properties

Integrety level:System
Platform:32-bit
Command line:"C:\Program Files\aha\c+weject.exe"
Owner:SYSTEM
Windows Service
Service name:CDROM_Detect
Display name:CDROM_Eject_Z
Type:Win32OwnProcess, InteractiveProcess
Parent process:services.exe (Services and Controller app by Microsoft)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 33.33%
Windows Vista Ultimate 33.33%
Windows 7 Starter 16.67%
Windows 7 Ultimate 16.67%

Distribution by countryDistribution by country

Indonesia installs about 100.00% of c+weject.exe.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
ASUS 50.00%
American Megatrends 25.00%
Toshiba 25.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE