What is wcescomm.exe?
wcescomm.exe is a legitimate process file popularly known as ActiveSync Connection Manager. It is associated with Microsoft ActiveSync developed by Microsoft Corporation. It is located in C:\Program Files by default. Malware programmers create files with virus scripts and name them after wcescomm.exe with an intention to spread virus on the internet.
Affected Platform: Windows OS
How to check if your computer is infected with wcescomm.exe malware?
Keep an eye for the following symptoms to see if your PC is infected with wcescomm.exe malware:
- Internet connection fluctuates
- wcescomm.exe takes too much CPU space
- PC slows down significantly
- Browser automatically redirects to some irrelevant websites
- Unsolicited ads and popups starts appearing
- Screen freezes constantly
Take the following steps to diagnose your PC for possible wcescomm.exe malware attack:
Step 1: Simultaneously press CTRL+ALT+DEL keys to open Task Manager.
Step 2: If you notice the file located outside C:\Program Files, then you should run an antivirus scan to get rid of the malware.
How to remove waol.exe malware from system using Comodo Antivirus?
Step 1: Download the award-winning Antivirus.
Step 2: Installation configuration frames will be displayed. Select the configuration you would like to apply.
Step 3: After network detection is complete, press “Close” button for a scan window.
Step 4: Restart your PC.
Step 5: It will take some time for the Comodo Internet Security to update the antivirus.
Step 6: Proceed with a quick scan that automatically begins after the update.
Step 7: If threats are found during the scanning, you will be prompted with an alert screen.
Step 8: Comodo Antivirus will remove the waol.exe virus from your computer including all other malwares!
| No. | Company | File Type | SHA1 | MD5 | Malware Name |
Digitally Signed |
File Version |
Product Version |
Submitted From |
Malware Behavior |
|---|---|---|---|---|---|---|---|---|---|---|
| 1 | Microsoft Corporation | Executable | db6b6a67aa1686b8 aa0c19459e51b2ec fcd6e116 |
a13e0c37da0950ba 2bb8f2abb78fcd5d |
Virus.Win32. Sality.gen |
No | 4.5.5096.0 | 4.5.5096 | Russian Federation |
N/A |
| 2 | Microsoft Corporation | Executable | d61d5a34abaadb35 18d260422da32854 9c74f985 |
d11b8393296f2ddd 621651c211cae76d |
Virus.Win32. Sality.gen |
No | 4.5.5096.0 | 4.5.5096 | China |
N/A |
| 3 | Microsoft Corporation | Executable | 9486ee50497cd7fa 067b05ceb1017dad 61d71dca |
803b0060a34b5c76 09b5ea406460de68 |
Virus.Win32. Sality.gen |
No | 4.5.5096.0 | 4.5.5096 | Romania |
N/A |
| 4 | Microsoft Corporation | Executable | 87c30b49e4742f4f 941af882903a83a3 4d398ffd |
bfaa904fdc86f497 4f4e03028d04e6e2 |
Virus.Win32. Sality.gen |
No | 4.5.5096.0 | 4.5.5096 | 128.72.156.225/32 |
N/A |
| No. | Company | File Type | SHA1 | MD5 | Digitally Signed |
File Version |
Product Version |
Submitted From |
|---|---|---|---|---|---|---|---|---|
| 1 | Microsoft Corporation | Executable | b642bfd9a72d9c52 a56266fad66d90b3 9ad33d49 |
0d667f8b21d7975c 663f35d7af3c9bdb |
No | 4.1.4841.0 | 4.1.4841 | Internal Submission |
| 2 | Microsoft Corporation | Executable | 48017ab24dd3e8e1 19c0a0846b9e3099 96690e12 |
67a6951da793e24b c876f1f380e25ac7 |
No | 3.7.1.4034 | 3.7.4034 | Internal Submission |
| 3 | Microsoft Corporation | Executable | cea53b093061f125 7a567f26f41d1075 adf1c90d |
510fc3ed0125aa4c f3f1002cb6ea8a15 |
No | 3.5.0.1240 | 3.5.1240 | Internal Submission |
| 4 | Microsoft Corporation | Executable | b5c6a1b40fe5cc0f 4b2ac4eec8d91df3 8dd80f0f |
5dd84df95d117784 6b312f12cac4addf |
Yes | 4.2.4876.0 | 4.2.4876 | Internal Submission |

Russian Federation
China
Romania
128.72.156.225/32
Poland
Lithuania
Ukraine
Azerbaijan
Thailand
France
Turkey
Dominican Republic
India
Palestinian Territory, Occupied
Iran, Islamic Republic of
South Africa
Macedonia
Czech Republic
United States
Japan
Netherlands
Spain
Indonesia
Denmark
Venezuela
Germany
Brazil
Portugal
Sweden
Italy
Norway
United Kingdom
Greece
