VersionsVersions

5.8.9600.16384 3.85%
5.8.9600.16384 0.05%
5.8.9431.0 0.20%
5.8.9431.0 0.01%
5.8.9200.16384 2.21%
5.8.9200.16384 12.21%
5.8.8400.0 0.05%
5.8.8400.0 0.05%
5.8.8250.0 0.01%
5.8.8102.0 0.05%
5.8.7600.16385 21.69%
5.8.7600.16385 32.81%
5.8.7600.16385 0.01%
5.8.7600.16385 0.01%
5.8.7600.16385 4.56%
5.8.7600.16385 0.14%
5.8.7264.0 0.01%
5.7.0.18066 11.46%
5.7.0.18066 0.10%
5.7.0.18066 0.05%
5.7.0.18066 0.01%
5.7.0.18066 0.14%
5.7.0.18066 0.01%
5.7.0.18066 0.01%
5.7.0.18066 0.01%
5.7.0.18066 0.05%
5.7.0.18066 0.01%
5.7.0.18066 0.01%
5.7.0.18066 0.05%
5.7.0.18066 0.01%
5.7.0.18066 0.01%
5.7.0.18066 0.01%
5.7.0.18066 0.01%
5.7.0.18066 0.01%
5.7.0.18066 0.01%
5.7.0.16599 0.87%
5.7.0.16599 0.01%
5.7.0.16599 0.01%
5.7.0.16599 0.01%
5.7.0.16599 0.01%
5.7.0.16535 0.01%
5.7.0.6000 5.19%
5.7.0.6000 0.01%
5.7.0.6000 0.27%
5.7.0.6000 1.02%
5.7.0.6000 0.36%
5.7.0.6000 0.10%
5.7.0.6000 0.01%
5.6.0.8833 0.01%
5.6.0.8832 0.01%
View more

Relationships

wscript.exe

Microsoft Windows Script Host by Microsoft

Remove wscript.exe
This is a Windows system installed file with Windows File Protection (WFP) enabled.

Overview

There are 65 versions of wscript.exe in the wild, the latest version being 5.8.9600.16384. wscript.exe is run as a standard windows process with the logged in user's account privileges. By adding a startup entry to the run registry key, the file will be executed when the user logs into Windows. In addition the the run registry key, it also creates a scheduled job to be executed by the Windows Task Scheduler up user login, this is typically done in order to bypass a User Account Control (UAC) prompt. The average file size is about 187.86 KB. Numerous variations of wscript.exe have been installed with both Location Saisonniere and EVViewer. During the process's lifecycle, the typical CPU resource utilization is about 0.0016% including both foreground and background operations, the average private memory consumption is about 6.66 MB with the maximum memory reaching around 11.85 MB. Addionally, typically read and write I/O disk operations is about 12.83 KB per minute for reads and 20.18 KB per minute for writes.

What is wscript.exe?

The Microsoft Windows Script Host (WSH) is an automation technology for Microsoft Windows that provides scripting abilities comparable to batch files, but with a wider range of supported features. It was originally called Windows Scripting Host, but was renamed for the second release.

About wscript.exe (from Microsoft)

Microsoft® Windows® Script Host (WSH) is a language-independent scripting host for Windows Script compatible scripting engines. It brings simple, powerful, and flexible scripting to the Windows 32-bit

DetailsDetails

File name:wscript.exe
Publisher:Microsoft Corporation
Product name:Microsoft ® Windows Script Host
Description:Microsoft ® Windows Based Script Host
Typical file path:C:\Windows\System32\wscript.exe
Original name:wscript.exe.mui

ResourcesPrograms installed in

(Note, the programs listed below are for all versions of Microsoft ® Windows Script Host.)
Enhanced Vision
7% remove
Rocher Digital
9% remove

BehaviorsBehaviors

(Note, the behaviors below are for all versions of wscript.exe, select a unique version for details.)
Shell open commands
  • vbefile
  • VBSFile
  • jsefile
  • JSFile
Scheduled tasks
  • The job '4804' runs on registration in the path '\4804'
  • The task 'SBW_UpdateTask_Time_3932323637373635372d7837235a576c4a3241345041' runs daily in the path '\SBW_UpdateTask_Time_3932323637373635372d7837235a576c4a3241345041'
  • The job 'SBW_UpdateTask_Time_313035393136322d5a236c2a4a45574150574132' runs daily in the path '\SBW_UpdateTask_Time_313035393136322d5a236c2a4a45574150574132'
  • The task '80e45e89-e004-444c-a9bb-a8361c5d9ecc' runs on registration in the path '\Event Viewer Tasks\80e45e89-e004-444c-a9bb-a8361c5d9ecc'
  • The job '4834' runs on registration in the path '\4834'
  • The job 'SBW_UpdateTask_Time_323532333439303136352d6c235a2a5b4532412d573432' runs daily in the path '\SBW_UpdateTask_Time_323532333439303136352d6c235a2a5b4532412d573432'
  • The task 'SBW_UpdateTask_Logon_323532333439303136352d6c235a2a5b4532412d573432' runs on logon in the path '\SBW_UpdateTask_Logon_323532333439303136352d6c235a2a5b4532412d573432'
  • The task 'SBW_UpdateTask_Time_333736373630353831392d784a234157344a2a416c505a' runs daily in the path '\SBW_UpdateTask_Time_333736373630353831392d784a234157344a2a416c505a'
  • The job 'SBW_UpdateTask_Logon_333736373630353831392d784a234157344a2a416c505a' runs on logon in the path '\SBW_UpdateTask_Logon_333736373630353831392d784a234157344a2a416c505a'
  • The job '4895' runs on registration in the path '\4895'
  • The task '4469' runs on registration in the path '\4469'
  • The task '4806' runs on registration in the path '\4806'
  • The job '4729' runs on registration in the path '\4729'
  • The task '4792' runs on registration in the path '\4792'
  • The task '4696' runs on registration in the path '\4696'
  • The task '4797' runs on registration in the path '\4797'
  • The task 'SBW_UpdateTask_Time_3737383533343234332d455b2a34504141454a5a576c' runs daily in the path '\SBW_UpdateTask_Time_3737383533343234332d455b2a34504141454a5a576c'
  • The job 'SBW_UpdateTask_Logon_3737383533343234332d455b2a34504141454a5a576c' runs on logon in the path '\SBW_UpdateTask_Logon_3737383533343234332d455b2a34504141454a5a576c'
  • The job '4394' runs on registration in the path '\4394'
  • The task '4510' runs on registration in the path '\4510'
  • The task '4638' runs on registration in the path '\4638'
  • The job '4628' runs on registration in the path '\4628'
Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'IntelTBRunOnce' → wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
Startup files (user) run
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'TempSnippingTool' → wscript.exe //B "C:\users\user\appdata\Local\Temp\TempSnippingTool.vbs"
  • 'SpeedUpSystem' → wscript "C:\users\user\appdata\Roaming\Adobe\Flash Player\SpeedCache\afile.vbs" "C:\users\user\appdata\Roaming\Adobe\Flash Player\SpeedCache\aso.bat"
  • 'ActiveXService' → wscript "C:\users\user\appdata\Roaming\ActiveX\invis.vbs" "C:\users\user\appdata\Roaming\ActiveX\svchost.exe"
  • 'Protector' → wscript.exe "C:\users\user\appdata\Roaming\SDIV 2.0\Prot\prot.vbs" check
Scheduled tasks startups
Set to load on user login (bypasses Windows UAC if enabled)
  • Login entry path '\SBW_UpdateTask_Logon_323532333439303136352d6c235a2a5b4532412d573432'
  • Login entry path '\SBW_UpdateTask_Logon_333736373630353831392d784a234157344a2a416c505a'
  • Login entry path '\SBW_UpdateTask_Logon_3737383533343234332d455b2a34504141454a5a576c'
  • Login entry path '\USER_ESRV_SVC'
Startup files (all users) run once
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce'
  • 'Start Savin-repairJob' → wscript.exe "C:\users\user\appdata\Local\Start Savin\repair.js" "Start Savin-repairJob"

VersionsAll file variations of wscript.exe

MD5SHA-1File size
c15b3fe9b7ab65a984b7bfd1382de43e 7dde0549d3078ee472d150d07c9aca120a65b61c 157.5 KB
54b3866e6741b34f3fb1ba6b18f607eb 992583ad6f1dbe1fbdb029ffb417e22260d9103e 130 KB
e248b964f05cafac57df37dfaa06e745 780f08934beea380e38380922b346d759b3f2ee7 157 KB
b9635db0d481c9a92114a3051dc07dbf 5b8fe8e7d52eb010033ec4c216a27872a78f7658 130 KB
d1ade450ea96092cf5006e3beea3e810 535cfcece359aa7be1a0612f816db7d783aaf598 128.5 KB
524c9700e3385814c278cf547ce75fec eb71a0d4b32641c7c4cbf596514c25ca2b7b2e7d 156.5 KB
3c42098933ce8a63fbbe97421e7a840c 9734af14474a39ecb791a075a513a2848ec2074d 155.5 KB
dafdcf2411c981bfaa6494a53a7d4b86 95aca514e81739000c7c44bdd142ff77b435e04a 127.5 KB
76564eda5d97101672db791e7b9bba80 59a0f4c6a592f05327ea92efd3a8a231d9fa89c4 127 KB
1226b1e8b9b0477bbdace0b3229a3bdf 3a59ba62083eff39b8207dcde4471ffc30d779be 127 KB
d1ab72db2bedd2f255d35da3da0d4b16 860265276b29b42b8c4b077e5c651def9c81b6e9 138.5 KB
8886e0697b0a93c521f99099ef643450 851bd390bf559e702b8323062dbeb251d9f2f6f7 165 KB
751a993392202d149945cf07d866f328 8738a4ab5d6e2ed4bdbc948bdf4d68ee62ed389a 158 KB
5d21b9789103cff0cc745694116f0d9a f81113a76e7b3f327a0c7852e33ff11650742d85 165 KB
045451fa238a75305cc26ac982472367 2131cff0959d213cd9a5e8a8ac362d265d5b1316 165 KB
979d74799ea6c8b8167869a68df5204a 7fde3d18c7370dff0d5a339c93b8b7e91930f65d 138.5 KB
1122ce3a5700520bc6c3cde8fe477a53 a1088f0f68b1773896b066040fa47daf740895b4 138.5 KB
cea8f7e45b7b098f5fb085bb6a6a4432 36632da9b915460f45ffdf040c459bc4ab9cb05a 152 KB
540ea540030f56bd9e2106aac0b7198a 0948aa6099fe50df16766eb8d1c7726c69bc4011 204 KB
b592570631fcebac5c5392d80b874e03 c8b7c5d49c1ed951799558fa712db5f96b868352 204 KB
45dbda38c644fa916c191b56b36b3f11 aad03d006e962f3cc5b3ccd0111d2b3b98ec82de 380 KB
44bdf95be17e3ba3cd76dc664bbfe06d 27bd8d4f153bbcbe44dd89aa60e20f0cd9958bb2 200 KB
72616290c81c531e698e0c3f7b3d0149 ad2ad9a39502cc3d0cf78158f1ac53229e6e2805 208 KB
9ef3f4f0788e572cad72dd746cb36420 5a0f11d71c3309e2758880d7ceb1430631eacb8e 572 KB
781e7330a9e881be09ed17cf37793fd4 080817eaef250b48f5b26527936519a4164e308f 212 KB
e5ee884b4bbd2c2342584b4131dcb012 da58f9fb784d1f2b20492a059e4f854664f5602a 236 KB
d0fd3ad8ac4a0090a44a4d08aaa05f5f 0f1db6f1f944bf5dbd704c0e3f9a08f4f9f5055a 196 KB
af5991e47a19e56893feb5b60c624266 09e3625d97d85e031fff90eb9b3df985b489ef87 572 KB
deed05d38a70de6adc7e39dceedfbc79 fb1358a81a3813ed0c72db9f7f37161c629013a5 236 KB
0d8d00341dc75f5c30f7461f37cf53af b0c17e4795f41cebbb410cf68faa830f8aa7222c 188 KB
1acdab806b69b13e961ddbc27a2b21c8 07fa4e59b2b5c98cda84f9f59cc32549a55b44fa 572 KB
58098a190786ed33fef06ce08744d812 1191808a32f8cccd67dc8f60e2f58ef5b580d73e 164 KB
a0e5b22aae7ab99d5ed8a385edb4fd2c b9fc083412119263206dc65c06e0c8ea23e94546 196 KB
d709f8b6bfa389bf0b4f8b66d50d6955 b83cf74da996c5b78abcd529a74a095df40b2873 208 KB
1d140ca0af7de674ae14a4b5cd083084 0e3dcebe4c768756b1c6fddd55b939ed635f98bb 572 KB
3e235d5e9093b8bac47d9c8b124ea16c e4ea0dddbc460415309d9ca8351ba405100a2e06 152 KB
880726cacac2696236e87b122fa3cd09 00c6661a3fc4fc981ae323e440c5b43d4208cd2a 152 KB
0cdb713bada380f4a340b9c4a5540a8f 5f903205eaed492a3333235c3bba5e2986cf3591 152 KB
5de68559f43a89c64e363d75ec9f20e8 44cd476ea87c56015592d61a55f3c5b08699b8dd 152 KB
e85fe525792924614b70b24fd4a869a3 7d3be73b970ff33878585a530099a9916aab8ddf 152 KB
cbe09923dd9cb1c4148c198feb9ed4f5 ce49f46012f22e690126af917fda23a457db5bb0 132 KB
1259e03dcd5f265b23db738fb075df8c 655d245277626a7893c55de282077d42f4ac4e0f 152 KB
8008128d00deead87f755d1d0bdc83ff bd0a06c9a726af55440632381d82d89ec66eaa89 163 KB
a05436d8b64417e0ca7f5f757c802386 792ce318c8bd9ae1ec9f20ae571649ef028dc265 132 KB
895083a7a0c4a75c6f8825895050abb7 67fa1f608e7b27f2f57e4f2076eae494496dc067 163 KB
549fa98184d34da75d84f9914be2defb 49d78e165a8c681baa4a1445c893533dffa4c91d 152 KB
1d0a82b11235d68cf55a54b2adecb9f1 1ee8b7bca25141bc05a77dbf9a7dd3697cdc0d1e 152 KB
d74f10ad834fa4a8c597954a84e5988c 34b3a3ce475b4ce9fe3632074ca6ea2f528bac67 163 KB
3ace38b4d0ef4161e825fa05b5a40acf da328b1fda797745f44c0fe18d5501a2ad3c2c25 112 KB
26380e1e200e899d46695700f257b822 0fc8eff4ae4e309843ab81b9ad9f7d91441b51fe 112 KB
f9ea7bf7d35ddffd29fda5c42eaf0efa 888e50862c64ef385e1739a4ff2b850611e77b3e 149 KB

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 36.50%
Windows 8.1 14.25%
Windows 7 Ultimate 11.50%
Windows 8.1 Pro 10.75%
Windows 7 Professional 8.25%
Windows 8.1 Single Language 4.00%
Windows 8 3.75%
Windows 8 Single Language 3.25%
Windows 8.1 Pro with Media Center 2.00%
Windows 8 Enterprise N 1.00%
Windows Seven Black Edition 1.00%
Windows 7 Home Basic 1.00%
Windows 8.1 Enterprise Evaluation 1.00%
Windows 8 Pro 1.00%
Windows 8.1 N 0.75%

Distribution by countryDistribution by country

United States installs about 54.00% of Microsoft ® Windows Script Host.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 25.72%
Hewlett-Packard 15.93%
ASUS 15.36%
Acer 11.52%
Toshiba 10.75%
Lenovo 8.83%
Sony 4.99%
Alienware 2.30%
Samsung 2.30%
Intel 1.54%
GIGABYTE 0.77%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE