Should I block it?

No, this file is 100% safe to run.

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegEnumKeyA, RegOpenKeyA, RegSetValueExA, RegCreateKeyA, RegDeleteKeyA, RegQueryValueExA, RegEnumKeyExA, RegOpenKeyExA, RegCloseKey
cfgmgr32.dll
CM_Get_Parent, CM_Get_Sibling, CM_Get_Child, CM_Get_DevNode_Registry_PropertyA, CM_Locate_DevNodeA, CM_Remove_SubTree, CM_Query_Remove_SubTree
comctl32.dll
ImageList_ReplaceIcon, ImageList_Destroy, ImageList_Create
kernel32.dll
GetOEMCP, GetACP, GetCPInfo, GetStringTypeW, GetStringTypeA, SetFilePointer, GetLastError, HeapReAlloc, VirtualAlloc, WriteFile, RtlUnwind, VirtualFree, HeapCreate, HeapDestroy, GetFileType, GetStdHandle, SetHandleCount, GetProcAddress, GetEnvironmentStrings, FreeEnvironmentStringsW, FreeEnvironmentStringsA, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, LCMapStringW, LCMapStringA, MultiByteToWideChar, WideCharToMultiByte, HeapAlloc, HeapFree, ExitProcess, GetVersion, GetCommandLineA, GetStartupInfoA, GetModuleHandleA, SetStdHandle, lstrcatA, GlobalAddAtomA, GlobalDeleteAtom, FreeLibrary, GetVersionExA, GetDiskFreeSpaceExA, LoadLibraryA, GetPrivateProfileStringA, CloseHandle, GetVolumeInformationA, lstrcmpiA, GetModuleFileNameA, lstrcpyA, lstrlenA, GetEnvironmentStringsW, FlushFileBuffers
shell32.dll
Shell_NotifyIconA
user32.dll
GetParent, GetDlgItem, EnableWindow, InvalidateRect, GetCursorPos, TrackPopupMenu, CreatePopupMenu, AppendMenuA, LoadBitmapA, InsertMenuItemA, DestroyMenu, DefWindowProcA, DialogBoxParamA, MessageBoxA, KillTimer, PostQuitMessage, RegisterWindowMessageA, CreateWindowExA, ShowWindow, UpdateWindow, SetWindowTextA, SetForegroundWindow, EndDialog, LoadIconA, LoadCursorA, RegisterClassExA, FindWindowA, LoadAcceleratorsA, GetMessageA, IsDialogMessageA, TranslateAcceleratorA, TranslateMessage, DispatchMessageA, wsprintfA, SendMessageA, BeginPaint

res.exe

ali usb1 by ali

Remove res.exe
Version:   1, 0, 0, 1
MD5:   f708a2ca13f52ad594333765de034526
SHA1:   920d8e719dbe9bb69f1d736a86fa555b57b24845
SHA256:   ed2e257f6a0c7eba2ec0677660a54befc843c1f8b8ad58531c5600fee02b3473

Overview

res.exe executes as a process with the local user's privileges usually within the context of Windows Explorer. It is set to be start when the PC boots and any user logs into Windows (added to the Run registry key for the all users under the local machine). This is typically installed with the program Hama Webcam Suite published by ArcSoft. This particular version is usually found on Windows Vista (TM) Home Basic (6.0.6002.131072).

DetailsDetails

File name:res.exe
Publisher:ali
Product name:ali usb1
Description:usb1
Typical file path:C:\windows\umstor\res.exe
Original name:usb1.exe
File version:1, 0, 0, 1
Size:64 KB (65,536 bytes)
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
ArcSoft
24% remove
Full version of the Hama Webcam Suite, consisting of: Arcsoft Webcam Companion 2, Media Impression and Magic i Visual Effects to manage and edit photos at the PC.

BehaviorsBehaviors

Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'USB Storage Toolbox' → C:\Windows\UMStor\Res.EXE

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00005846%
0.028634%
Kernel CPU:0.00005846%
0.013761%
Kernel CPU time:16 ms/min
100,923,805ms/min
CPU cycles:1,639/sec
17,470,203/sec
Memory
Private memory:1.11 MB
21.59 MB
Private (maximum):3.42 MB
Private (minimum):2.74 MB
Non-paged memory:1.11 MB
21.59 MB
Virtual memory:56.15 MB
140.96 MB
Virtual memory (peak):57.15 MB
169.69 MB
Working set:2.77 MB
18.61 MB
Working set (peak):3.47 MB
37.95 MB
Page faults:951/min
2,039/min
Resource allocations
Threads:1
12
Handles:41
600
GUI GDI count:27
103
GUI USER count:8
49

BehaviorsProcess properties

Integrety level:High
Platform:32-bit
Command line:"C:\windows\umstor\res.exe"
Owner:User
Parent process:explorer.exe (Windows Explorer by Microsoft Corporation)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows Vista Home Basic 100.00%

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE