Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

2.1.4.11 4.76%
2.1.0.6 28.57%
2.0.3.0 33.33%
1.2.5.30 14.29%
1.2.4.26 19.05%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
RegQueryValueExW, RegOpenKeyExW, RegCloseKey, RegSetValueExW, RegQueryInfoKeyW, RegFlushKey, RegEnumValueW, RegEnumKeyExW, RegDeleteKeyW, RegCreateKeyExW
cbscreatevc.dll
IsAdmin, createVC
cbsproducstinfo.dll
CompareVersion
comctl32.dll
InitializeFlatSB, FlatSB_SetScrollProp, FlatSB_SetScrollPos, FlatSB_SetScrollInfo, FlatSB_GetScrollPos, FlatSB_GetScrollInfo, _TrackMouseEvent, ImageList_SetIconSize, ImageList_GetIconSize, ImageList_Write, ImageList_Read, ImageList_GetDragImage, ImageList_DragShowNolock, ImageList_DragMove, ImageList_DragLeave, ImageList_DragEnter, ImageList_EndDrag, ImageList_BeginDrag, ImageList_GetIcon, ImageList_Remove, ImageList_DrawEx, ImageList_Draw, ImageList_GetBkColor, ImageList_SetBkColor, ImageList_ReplaceIcon, ImageList_Add, ImageList_SetImageCount, ImageList_GetImageCount, ImageList_Destroy, ImageList_Create
comdlg32.dll
GetOpenFileNameW
gdi32.dll
UnrealizeObject, StretchBlt, SetWindowOrgEx, SetWinMetaFileBits, SetViewportOrgEx, SetTextColor, SetStretchBltMode, SetROP2, SetPixel, SetMapMode, SetEnhMetaFileBits, SetDIBColorTable, SetBrushOrgEx, SetBkMode, SetBkColor, SelectPalette, SelectObject, SaveDC, RoundRect, RestoreDC, Rectangle, RectVisible, RealizePalette, Polyline, PlayEnhMetaFile, PatBlt, OffsetWindowOrgEx, OffsetRgn, OffsetClipRgn, MoveToEx, MaskBlt, LineTo, LPtoDP, IntersectClipRect, GetWindowOrgEx, GetWinMetaFileBits, GetTextMetricsW, GetTextExtentPointW, GetTextExtentPoint32W, GetSystemPaletteEntries, GetStretchBltMode, GetStockObject, GetRgnBox, GetRegionData, GetPixel, GetPaletteEntries, GetObjectW, GetEnhMetaFilePaletteEntries, GetEnhMetaFileHeader, GetEnhMetaFileDescriptionW, GetEnhMetaFileBits, GetDeviceCaps, GetDIBits, GetDIBColorTable, GetDCOrgEx, GetCurrentPositionEx, GetCurrentObject, GetClipBox, GetBrushOrgEx, GetBitmapBits, GdiFlush, FrameRgn, ExtTextOutW, ExtSelectClipRgn, ExtCreateRegion, ExcludeClipRect, Ellipse, DeleteObject, DeleteEnhMetaFile, DeleteDC, CreateSolidBrush, CreateRoundRectRgn, CreateRectRgn, CreatePenIndirect, CreatePalette, CreateHalftonePalette, CreateFontIndirectW, CreateEnhMetaFileW, CreateEllipticRgn, CreateDIBitmap, CreateDIBSection, CreateCompatibleDC, CreateCompatibleBitmap, CreateBrushIndirect, CreateBitmap, CopyEnhMetaFileW, CombineRgn, CloseEnhMetaFile, BitBlt
gdiplus.dll
GdipGetImageEncoders, GdipGetImageEncodersSize, GdipRestoreGraphics, GdipSaveGraphics, GdipDrawImageRectRectI, GdipDrawImageRectI, GdipDrawImageRect, GdipGraphicsClear, GdipSetPageUnit, GdipSetInterpolationMode, GdipSetPixelOffsetMode, GdipSetSmoothingMode, GdipReleaseDC, GdipDeleteGraphics, GdipCreateFromHDC, GdipSetImageAttributesColorKeys, GdipSetImageAttributesColorMatrix, GdipDisposeImageAttributes, GdipCreateImageAttributes, GdipBitmapUnlockBits, GdipBitmapLockBits, GdipCreateBitmapFromHBITMAP, GdipCreateBitmapFromScan0, GdipCreateBitmapFromFileICM, GdipCreateBitmapFromStreamICM, GdipCreateBitmapFromFile, GdipCreateBitmapFromStream, GdipGetPropertyItem, GdipGetPropertyItemSize, GdipGetImagePaletteSize, GdipSetImagePalette, GdipGetImagePalette, GdipImageSelectActiveFrame, GdipImageGetFrameCount, GdipImageGetFrameDimensionsList, GdipImageGetFrameDimensionsCount, GdipGetImagePixelFormat, GdipGetImageRawFormat, GdipGetImageFlags, GdipGetImageVerticalResolution, GdipGetImageHorizontalResolution, GdipGetImageHeight, GdipGetImageWidth, GdipGetImageType, GdipGetImageBounds, GdipGetImageGraphicsContext, GdipSaveImageToStream, GdipSaveImageToFile, GdipDisposeImage, GdipLoadImageFromFileICM, GdipLoadImageFromStreamICM, GdipLoadImageFromFile, GdipLoadImageFromStream, GdiplusShutdown, GdiplusStartup, GdipFree, GdipAlloc
kernel32.dll
GetACP, Sleep, VirtualFree, VirtualAlloc, GetSystemInfo, GetTickCount, QueryPerformanceCounter, GetVersion, GetCurrentThreadId, VirtualQuery, WideCharToMultiByte, SetCurrentDirectoryW, MultiByteToWideChar, lstrlenW, lstrcpynW, LoadLibraryExW, GetThreadLocale, GetStartupInfoA, GetProcAddress, GetModuleHandleW, GetModuleFileNameW, GetLocaleInfoW, GetLastError, GetCurrentDirectoryW, GetCommandLineW, FreeLibrary, FindFirstFileW, FindClose, ExitProcess, ExitThread, CreateThread, CompareStringW, WriteFile, UnhandledExceptionFilter, SetFilePointer, SetEndOfFile, RtlUnwind, ReadFile, RaiseException, GetStdHandle, GetFileSize, GetFileType, CreateFileW, CloseHandle, TlsSetValue, TlsGetValue, LocalAlloc, lstrcpyW, WriteProcessMemory, WritePrivateProfileStringA, WritePrivateProfileStringW, WaitForSingleObject, WaitForMultipleObjectsEx, VirtualQueryEx, VirtualProtect, TerminateProcess, SystemTimeToFileTime, SwitchToThread, SuspendThread, SizeofResource, SignalObjectAndWait, SetVolumeLabelW, SetThreadPriority, SetThreadLocale, SetLastError, SetFileTime, SetFileAttributesW, SetEvent, SetErrorMode, ResumeThread, ResetEvent, RemoveDirectoryA, RemoveDirectoryW, ReleaseMutex, OutputDebugStringW, OpenProcess, OpenMutexW, MulDiv, MoveFileW, LockResource, LocalFileTimeToFileTime, LoadResource, LoadLibraryW, LeaveCriticalSection, IsValidLocale, IsBadReadPtr, InitializeCriticalSection, GlobalUnlock, GlobalSize, GlobalMemoryStatus, GlobalLock, GlobalFree, GlobalFindAtomW, GlobalDeleteAtom, GlobalAlloc, GlobalAddAtomW, GetVolumeInformationW, GetVersionExW, GetUserDefaultLangID, GetUserDefaultLCID, GetTimeZoneInformation, GetTempPathW, GetTempFileNameW, GetSystemDirectoryW, GetSystemDefaultLCID, GetShortPathNameW, GetPrivateProfileStringA, GetPrivateProfileStringW, GetModuleHandleA, GetModuleFileNameA, GetLogicalDrives, GetLocalTime, GetFullPathNameA, GetFullPathNameW, GetFileTime, GetFileAttributesExW, GetFileAttributesA, GetFileAttributesW, GetExitCodeThread, GetExitCodeProcess, GetDriveTypeW, GetDiskFreeSpaceW, GetDateFormatW, GetCurrentThread, GetCurrentProcessId, GetCurrentProcess, GetComputerNameW, GetCPInfo, FreeResource, InterlockedIncrement, InterlockedExchangeAdd, InterlockedExchange, InterlockedDecrement, InterlockedCompareExchange, FormatMessageW, FlushFileBuffers, FindResourceW, FindNextFileA, FindNextFileW, FindFirstFileA, FileTimeToSystemTime, FileTimeToLocalFileTime, FileTimeToDosDateTime, EnumSystemLocalesW, EnumResourceNamesW, EnumCalendarInfoW, EnterCriticalSection, DeviceIoControl, DeleteFileA, DeleteFileW, DeleteCriticalSection, CreateProcessW, CreateMutexW, CreateFileA, CreateEventW, CreateDirectoryW, CopyFileW, QueryPerformanceFrequency
mpr.dll
WNetGetConnectionW
msimg32.dll
AlphaBlend
ole32.dll
CreateStreamOnHGlobal, IsAccelerator, OleDraw, OleSetMenuDescriptor, RevokeDragDrop, RegisterDragDrop, OleUninitialize, OleInitialize, CoTaskMemFree, CoTaskMemAlloc, CoCreateGuid, ProgIDFromCLSID, StringFromCLSID, CoCreateInstance, CoLockObjectExternal, CoDisconnectObject, CoRevokeClassObject, CoRegisterClassObject, CoGetClassObject, CoUninitialize, CoInitialize, IsEqualGUID, CLSIDFromString
oleaut32.dll
SysFreeString, SysReAllocStringLen, SysAllocStringLen, CreateErrorInfo, GetErrorInfo, SetErrorInfo, GetActiveObject, DispGetIDsOfNames, RegisterTypeLib, LoadTypeLibEx, SafeArrayPtrOfIndex, SafeArrayGetUBound, SafeArrayGetLBound, SafeArrayCreate, VariantChangeType, VariantCopy, VariantClear, VariantInit
shell32.dll
Shell_NotifyIconW, ShellExecuteExW, ShellExecuteA, ShellExecuteW, SHAppBarMessage, SHGetSpecialFolderPathW, SHGetFolderPathW
urlmon.dll
CoInternetCreateZoneManager, CoInternetCreateSecurityManager
user32.dll
GetKeyboardType, LoadStringW, MessageBoxA, CharNextW, DllMain
version.dll
VerQueryValueW, GetFileVersionInfoSizeW, GetFileVersionInfoW
wininet.dll
InternetSetOptionW, InternetOpenW, InternetConnectW, InternetCloseHandle, InternetGetConnectedState
wsock32.dll
__WSAFDIsSet, WSACleanup, WSAStartup, WSAGetLastError, getservbyname, gethostbyname, socket, shutdown, setsockopt, send, select, recv, ntohs, ioctlsocket, inet_addr, htons, connect, closesocket

WSHelper.exe

Wondershare Studio by Wondershare Software Co. (Signed)

Remove WSHelper.exe
Version:   1.2.4.26
MD5:   b1868f9e2b5224e57ce55570af4fbc99
SHA1:   013603e94e88674e4daead356b0ff8f0356d0e10
SHA256:   a4279be54ca66029ba208049162dc0c9e9ea3bb7830b7e310ca8868614564f34

Overview

WSHelper.exe executes as a process with the local user's privileges. It is set to be run when the PC boots and the user logs into Windows (added to the Run registry key for the current user). The file is digitally signed by Wondershare Software Co. which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:WSHelper.exe
Publisher:Wondershare
Product name:Wondershare Studio
Typical file path:C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
Original name:Wondershare Studio
File version:1.2.4.26
Size:1.61 MB (1,686,528 bytes)
Certificate
Issued to:Wondershare Software Co.
Authority (CA):VeriSign
Expiration date:Friday, September 20, 2013
Digital DNA
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'WSHelperSetup.exe' → C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
  • 'Wondershare Helper Compact' → "C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe"
  • 'Wondershare Helper Compact.exe' → C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
Startup files (user) run
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'Wondershare Helper Compact' → "C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe"

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 47.62%
Windows 7 Ultimate 23.81%
Windows 8.1 14.29%
Windows Vista Home Premium 4.76%
Windows 7 Professional 4.76%
Windows 8 Pro 4.76%

Distribution by countryDistribution by country

United States installs about 47.62% of Wondershare Studio.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 50.00%
ASUS 16.67%
Hewlett-Packard 16.67%
Toshiba 8.33%
Acer 8.33%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE