Should I block it?

No, this file is 100% safe to run.

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
CloseServiceHandle, OpenSCManagerA, RegCloseKey, RegSetValueExA, CreateProcessAsUserA, StartServiceCtrlDispatcherA, RegisterServiceCtrlHandlerA, SetServiceStatus, OpenProcessToken, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, OpenServiceA, DeleteService, RegCreateKeyExA, CreateServiceA
hid.dll
HidD_GetAttributes, HidD_GetPreparsedData, HidD_GetHidGuid, HidP_GetCaps
kernel32.dll
GetModuleFileNameA, GetModuleHandleA, Sleep, CreateEventA, GetWindowsDirectoryA, SetEvent, OpenProcess, Process32Next, lstrcmpiA, Process32First, CreateToolhelp32Snapshot, InterlockedDecrement, OutputDebugStringA, lstrlenA, CreateThread, InterlockedIncrement, GetTickCount, MultiByteToWideChar, WideCharToMultiByte, HeapFree, GetProcessHeap, GetLocaleInfoA, SetFilePointer, FlushFileBuffers, GetConsoleMode, GetConsoleCP, SetStdHandle, ReadFile, WaitForMultipleObjects, GetLastError, CreateFileA, CloseHandle, GetStringTypeA, GetStringTypeW, LCMapStringA, LCMapStringW, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, ResumeThread, IsValidCodePage, GetOEMCP, GetACP, GetCPInfo, LoadLibraryA, InitializeCriticalSectionAndSpinCount, GetSystemTimeAsFileTime, GetCurrentProcessId, QueryPerformanceCounter, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, GetFileType, SetHandleCount, IsDebuggerPresent, SetUnhandledExceptionFilter, HeapAlloc, RtlUnwind, EnterCriticalSection, LeaveCriticalSection, GetCommandLineA, GetStartupInfoA, RaiseException, HeapCreate, VirtualFree, DeleteCriticalSection, VirtualAlloc, HeapReAlloc, GetModuleHandleW, GetProcAddress, ExitProcess, WriteFile, GetStdHandle, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, SetLastError, GetCurrentThreadId, HeapSize, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter
msi_io.dll
MSI_LoadIOSYS, MSI_FIND_F000_STR, MSI_UnloadIOSYS
ole32.dll
CoSetProxyBlanket, CoUninitialize, CoCreateInstance, CoInitializeSecurity, CoInitializeEx
setupapi.dll
SetupDiSetClassInstallParamsA, SetupDiDestroyDeviceInfoList, SetupDiGetDeviceInterfaceDetailA, SetupDiEnumDeviceInterfaces, SetupDiEnumDeviceInfo, SetupDiGetClassDevsA, SetupDiGetDeviceInstallParamsA, SetupDiChangeState, SetupDiGetDeviceInstanceIdA, CM_Get_DevNode_Status, SetupDiSetDeviceInstallParamsA
user32.dll
CreateWindowExA, GetMessageA, UnregisterDeviceNotification, DispatchMessageA, RegisterClassA, PostQuitMessage, RegisterDeviceNotificationA, DefWindowProcA, TranslateMessage

wmi_hook_service.exe

WMI_Hook_Service by Micro-Star Int'l Co. Ltd. (Signed)

Remove wmi_hook_service.exe
Version:   0, 0, 6, 8
MD5:   39f73934fd99df699044451e829c7211
SHA1:   3dc1b5f435c2dcb29222973eef7db07e2c256149
SHA256:   7df9512c30b114d28deaa3c64a9b945941e85dc5c9f791d87413bced8f27164e

Overview

wmi_hook_service.exe runs as a service under the name WMI_Hook_Service with extensive SYSTEM privileges (full administrator access). This is typically installed with the program OSD hot keys published by MSI Co., LTD. The file is digitally signed by Micro-Star Int'l Co. Ltd. which was issued by the GlobalSign nv-sa certificate authority (CA). This particular version is usually found on Windows 7 Home Premium (6.1.7601.65536).

DetailsDetails

File name:wmi_hook_service.exe
Publisher:MICRO-STAR INT'L,.LTD.
Product name:WMI_Hook_Service
Description:MSI Keyboard Fn Solution Service
Typical file path:C:\Program Files\msi\osd hot keys\wmi_hook_service.exe
Original name:WMI_Hook_Service
File version:0, 0, 6, 8
Size:98.8 KB (101,176 bytes)
Build date:9/4/2009 5:54 AM
Certificate
Issued to:Micro-Star Int'l Co. Ltd.
Authority (CA):GlobalSign nv-sa
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
MSI Co., LTD
4% remove

BehaviorsBehaviors

Service
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'WMI_Hook_Service'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00214289%
0.028634%
Kernel CPU:0.00144412%
0.013761%
User CPU:0.00069877%
0.014873%
Kernel CPU time:312,002 ms/min
100,923,805ms/min
Memory
Private memory:1.44 MB
21.59 MB
Private (maximum):5.03 MB
Private (minimum):4.98 MB
Non-paged memory:1.44 MB
21.59 MB
Virtual memory:48.69 MB
140.96 MB
Virtual memory (peak):50.69 MB
169.69 MB
Working set:4.97 MB
18.61 MB
Working set (peak):5.06 MB
37.95 MB
Resource allocations
Threads:7
12
Handles:116
600

BehaviorsProcess properties

Integrety level:System
Platform:32-bit
Command line:"C:\Program Files\msi\osd hot keys\wmi_hook_service.exe"
Owner:SYSTEM
Windows Service
Service name:WMI_Hook_Service
Description:“Hotkey function for Volume/Brightness adjusts.”
Type:Win32OwnProcess, InteractiveProcess
Parent process:services.exe (Services and Controller app by Microsoft)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 100.00%

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Medion 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE