VersionsAdditional versions

9c051 31.58%
4ed75 5.26%
7f460 42.11%
3b520 5.26%
a8247 5.26%
d933c 5.26%
b51c3 5.26%
(Note, the developer publishes each variation of this file with the same version, but the hashes are unique.)

PE structurePE file structure

Show functions
Import table
RegCreateKeyExW, CheckTokenMembership, RegQueryValueW, RegEnumKeyW, RegDeleteKeyW, RegSetValueExW, AllocateAndInitializeSid, RegOpenKeyExW, RegOpenKeyW, RegQueryValueExW, RegCloseKey, FreeSid, OpenSCManagerW, OpenServiceW, GetUserNameW, CloseServiceHandle
InitCommonControlsEx, ImageList_ReplaceIcon, ImageList_SetBkColor
CertEnumCertificatesInStore, CertGetNameStringW, CertOpenSystemStoreW, CertGetCertificateContextProperty
SetWindowExtEx, ScaleWindowExtEx, ExtSelectClipRgn, CreateBitmap, LineTo, CreateRectRgnIndirect, GetMapMode, DPtoLP, GetBkColor, GetTextColor, GetRgnBox, SetWindowOrgEx, GetClipBox, ScaleViewportExtEx, SetViewportExtEx, OffsetViewportOrgEx, GetWindowExtEx, GetViewportExtEx, SetTextAlign, CreateCompatibleDC, SetMapMode, SetTextColor, SetBkMode, SetBkColor, RestoreDC, SaveDC, Escape, ExtTextOutW, TextOutW, RectVisible, PtVisible, PatBlt, CreateDIBSection, Ellipse, GetBkMode, CreatePen, Rectangle, SetViewportOrgEx, GetViewportOrgEx, CreateSolidBrush, DeleteObject, DeleteDC, SelectObject, CreateFontW, CreateRoundRectRgn, GetTextExtentPoint32W, CreateFontIndirectW, GetDeviceCaps, GetStockObject, GetObjectW, BitBlt, CreateCompatibleBitmap, MoveToEx, GetTextMetricsW
GdipDisposeImage, GdipAlloc, GdipFree, GdipGetImageWidth, GdipDrawImageRectI, GdipSetInterpolationMode, GdipDeleteGraphics, GdipCreateFromHDC, GdipLoadImageFromStream, GdipGetImageHeight, GdiplusStartup, GdiplusShutdown, GdipCloneImage, GdipDrawLine, GdipDeletePen, GdipCreatePen1
HeapFree, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, ExitThread, RaiseException, RtlUnwind, HeapReAlloc, HeapSize, VirtualProtect, VirtualAlloc, VirtualQuery, GetStdHandle, GetModuleFileNameA, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCommandLineW, SetHandleCount, GetFileType, GetStartupInfoA, HeapCreate, VirtualFree, QueryPerformanceCounter, HeapAlloc, GetACP, GetOEMCP, IsValidCodePage, InitializeCriticalSectionAndSpinCount, LCMapStringW, GetTimeZoneInformation, GetConsoleCP, GetConsoleMode, LCMapStringA, GetStringTypeA, GetStringTypeW, GetLocaleInfoA, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, CreateFileA, SetEnvironmentVariableA, ExitProcess, GetStartupInfoW, GetTickCount, GetFileTime, GetFileSizeEx, FileTimeToLocalFileTime, SetErrorMode, FileTimeToSystemTime, TlsFree, DeleteCriticalSection, LocalReAlloc, TlsSetValue, TlsAlloc, InitializeCriticalSection, GlobalHandle, GlobalReAlloc, EnterCriticalSection, TlsGetValue, LeaveCriticalSection, LocalAlloc, InterlockedIncrement, GlobalFlags, GetCurrentThread, ConvertDefaultLocale, EnumResourceLanguagesW, lstrcmpA, GetLocaleInfoW, CompareStringA, InterlockedExchange, CreateFileW, GetFullPathNameW, GetVolumeInformationW, GetCurrentProcess, DuplicateHandle, GetFileSize, SetEndOfFile, UnlockFile, LockFile, FlushFileBuffers, SetFilePointer, WriteFile, ReadFile, GetThreadLocale, InterlockedDecrement, GetCurrentThreadId, GlobalAddAtomW, GlobalFindAtomW, GlobalDeleteAtom, CompareStringW, LoadLibraryA, lstrcmpW, GetVersionExA, FormatMessageW, LocalFree, lstrlenW, GetCurrentProcessId, GetModuleHandleA, WritePrivateProfileStringW, GetSystemInfo, GetModuleHandleW, SetLastError, GetCPInfo, lstrlenA, GetVersionExW, GetVersion, GetPrivateProfileSectionNamesW, GetPrivateProfileStringW, GetPrivateProfileIntW, ResetEvent, FreeResource, ResumeThread, MulDiv, WideCharToMultiByte, lstrcpyW, GetCurrentDirectoryW, GetProcAddress, LoadLibraryW, GetFileAttributesW, WaitForSingleObjectEx, GetLastError, FreeLibrary, GlobalFree, GlobalUnlock, GlobalLock, GlobalAlloc, WaitForSingleObject, Sleep, MultiByteToWideChar, ReleaseMutex, CreateMutexW, GetModuleFileNameW, CloseHandle, CreateEventW, FindClose, CreateDirectoryW, FindFirstFileW, SetEvent, CreateThread, FindResourceW, LoadResource, LockResource, GetSystemTimeAsFileTime, SizeofResource, FindNextFileW, GetLocalTime, OpenEventW, GetSystemDirectoryW, CreateProcessW, GetDateFormatW, GetTimeFormatW
CLSIDFromProgID, CoTaskMemAlloc, CLSIDFromString, CoTaskMemFree, CreateStreamOnHGlobal, CoGetClassObject, StgOpenStorageOnILockBytes, StgCreateDocfileOnILockBytes, CreateILockBytesOnHGlobal, OleUninitialize, CoFreeUnusedLibraries, OleInitialize, CoRevokeClassObject, OleIsCurrentClipboard, OleFlushClipboard, CoRegisterMessageFilter, CoUninitialize, CoInitialize, CoCreateInstance, CoInitializeEx, CoSetProxyBlanket, CoInitializeSecurity
ShellExecuteExW, ShellExecuteW, Shell_NotifyIconW, SHGetSpecialFolderPathW
PathIsUNCW, PathFindExtensionW, PathFindFileNameW, PathStripToRootW
DllMain, GetSubMenu, GetMenu, CheckMenuItem, InsertMenuW, CreatePopupMenu, GetMenuItemCount, CopyRect, GetSysColor, UpdateWindow, RedrawWindow, GetMenuItemID, CloseWindow, SetRectEmpty, GetWindowRect, TrackPopupMenu, GetCursorPos, SetMenuDefaultItem, LoadIconW, SendMessageW, EnableWindow, WinHelpW, GetMenuStringW, LoadBitmapW, ModifyMenuW, SetTimer, KillTimer, GetClientRect, PostMessageW, GetWindowTextW, EnumWindows, RegisterWindowMessageW, MessageBoxW, SetForegroundWindow, IsWindow, GetParent, LoadImageW, RemoveMenu, DeleteMenu, GetWindow, IsWindowVisible, SetActiveWindow, GetSystemMenu, AppendMenuW, EnableMenuItem, LoadMenuW, SetMenu, DestroyIcon
DocumentPropertiesW, ClosePrinter, OpenPrinterW


Remove twcu.exe
MD5:   d933cfad8eba37227178ae6e4b31302d
SHA1:   c65ec384ba272d78f212e09779b65909d7acf55b
SHA256:   a3d204050fdb9cc5a4aa14c117eddf16c27c55a43143a2e41fefaa8120f5242f


twcu.exe executes as a process with the local user's privileges. It is set to be start when the PC boots and any user logs into Windows (added to the Run registry key for the all users under the local machine). It is installed with a couple of know programs including TP-LINK TL-WN725N_WN723N Controlador published by TP-LINK, TP-LINK Wireless Configuration Utility from TP-LINK and TP-LINK Wireless Configuration Utility by TP-LINK.


File name:twcu.exe
Typical file path:C:\Program Files\tp-link\tp-link wireless configuration utility\twcu.exe
Size:827 KB (846,848 bytes)
Build date:8/24/2012 10:43 AM
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++
More details


User start menu folder
Shortcut pointer placed in '%appdata%\Microsoft\Windows\Start Menu'
  • Shortcut to 'twcu.exe'
Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'TWCU' → "C:\Program Files\TP-LINK\TP-LINK Wireless Client Utility\TWCU.exe" -nogui

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 68.42%
Windows 7 Ultimate 26.32%
Windows 8 Pro 5.26%

Distribution by countryDistribution by country

Hungary installs about 15.79% of twcu.exe.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Compaq 25.00%
Dell 25.00%
MSI 25.00%
American Megatrends 18.75%
