Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

2, 7, 10, 0 9.38%
2, 6, 0, 0 9.38%
2, 6, 0, 0 53.13%
2.0.4.0 28.13%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegQueryValueExW, RegEnumKeyW, RegCreateKeyW, DuplicateTokenEx, OpenThreadToken, OpenProcessToken, SetSecurityInfo, RegisterServiceCtrlHandlerW, SetServiceStatus, StartServiceCtrlDispatcherW, RegOpenKeyW, RegDeleteKeyW, RegDeleteValueW, RegCloseKey, RegSetValueExW, DuplicateToken, ImpersonateLoggedOnUser, RevertToSelf, GetTokenInformation, CopySid, ConvertStringSidToSidW, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, SetEntriesInAclW, ImpersonateNamedPipeClient, SetTokenInformation, CreateProcessAsUserW, ControlService, QueryServiceStatusEx, StartServiceW, ChangeServiceConfig2W, OpenServiceW, OpenSCManagerW, DeleteService, CloseServiceHandle, CreateServiceW, RegCreateKeyExW, ReportEventW, RegisterEventSourceW
comctl32.dll
InitCommonControlsEx
gdi32.dll
GetObjectW, DeleteObject, GetBitmapBits, BitBlt, DeleteDC, CreateDIBSection, GetDIBits, GetCurrentObject, SelectObject, CreateCompatibleDC, CreateDCW, ExtEscape
kernel32.dll
CreateDirectoryW, SetFileTime, MoveFileW, FindClose, RemoveDirectoryW, FindNextFileW, DeleteFileW, ProcessIdToSessionId, GetStartupInfoW, TerminateProcess, UnhandledExceptionFilter, IsDebuggerPresent, HeapFree, GetSystemTimeAsFileTime, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, SetLastError, InterlockedDecrement, HeapSize, ExitProcess, GetStdHandle, GetModuleFileNameA, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCommandLineW, SetHandleCount, GetFileType, GetStartupInfoA, HeapCreate, VirtualFree, QueryPerformanceCounter, GetTickCount, HeapAlloc, RaiseException, GetCPInfo, GetACP, GetOEMCP, WideCharToMultiByte, LCMapStringW, VirtualAlloc, HeapReAlloc, LoadLibraryA, InitializeCriticalSectionAndSpinCount, RtlUnwind, GetLocaleInfoA, LCMapStringA, GetStringTypeA, GetStringTypeW, GetLogicalDriveStringsW, SetFilePointer, GetConsoleCP, GetConsoleMode, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, CreateFileA, FlushFileBuffers, CompareStringA, CompareStringW, SetEnvironmentVariableA, GlobalUnlock, CreateFileMappingW, UnmapViewOfFile, MapViewOfFile, DuplicateHandle, WaitForMultipleObjects, GetExitCodeProcess, CreateProcessW, SetErrorMode, FindFirstFileW, ReleaseMutex, CreateMutexW, CreateThread, ResumeThread, LocalFree, LocalAlloc, DisconnectNamedPipe, ReadFile, WriteFile, GetProcAddress, LoadLibraryW, FreeLibrary, OpenThread, GetOverlappedResult, SetHandleInformation, CreatePipe, GetFileSizeEx, CreateNamedPipeW, ConnectNamedPipe, SetNamedPipeHandleState, CreateEventW, SetEvent, GetModuleFileNameW, GetVersionExW, GetComputerNameW, WaitForSingleObject, CloseHandle, GetCurrentThreadId, CreateFileW, GetCurrentProcess, SetUnhandledExceptionFilter, GetLastError, FormatMessageW, GetModuleHandleW, GetCurrentProcessId, Sleep, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSection, GetLocalTime, MultiByteToWideChar, SystemTimeToFileTime, SetEndOfFile, GlobalLock, GlobalAlloc, IsValidCodePage, GetModuleHandleA, FreeResource, FindResourceW, LoadResource, LockResource, FileTimeToSystemTime, OpenProcess
psapi.dll
GetModuleFileNameExW
shell32.dll
SHGetSpecialFolderPathW, ShellExecuteW, ShellExecuteExW, Shell_NotifyIconW, CommandLineToArgvW
user32.dll
SetFocus, GetForegroundWindow, InvalidateRect, GetWindowTextW, ShowWindow, DestroyIcon, DialogBoxParamW, GetWindowLongW, SetWindowLongW, EndDialog, CreateDialogParamW, SendMessageW, GetThreadDesktop, MoveWindow, MapWindowPoints, KillTimer, SetWindowTextW, SetTimer, ToUnicodeEx, OpenInputDesktop, OpenDesktopW, CloseDesktop, SetThreadDesktop, GetUserObjectInformationW, LoadIconW, LoadStringW, FindWindowW, SystemParametersInfoW, DestroyWindow, GetMessageW, PostQuitMessage, TranslateMessage, IsDialogMessageW, CreateWindowExW, RegisterClassW, DefWindowProcW, DispatchMessageW, SetProcessWindowStation, CloseWindowStation, OpenWindowStationW, GetDlgItem, EnumWindows, IsWindowVisible, RegisterWindowMessageW, TrackPopupMenu, PostMessageW, GetSubMenu, SetForegroundWindow, LoadMenuW, GetCursorPos, RemoveMenu, GetWindowThreadProcessId, GetKeyboardLayout, GetKeyState, MapVirtualKeyW, VkKeyScanExW, EnumChildWindows, UnregisterClassW, SetMenuDefaultItem, ExitWindowsEx, LockWorkStation, GetClientRect, GetSystemMetrics, SendInput, GetWindowInfo, SetClipboardViewer, SetClipboardData, OpenClipboard, ChangeClipboardChain, EmptyClipboard, GetClipboardData, IsClipboardFormatAvailable, CloseClipboard, UnhookWindowsHookEx, SetWindowsHookExW, PostThreadMessageW, PeekMessageW, WaitMessage, CallNextHookEx, GetDC, GetClassNameW, GetWindowRect, GetCursorInfo, GetIconInfo, DrawIconEx, MessageBoxW, SetClassLongW, IsWindow, EnumDisplayMonitors, GetWindow, FindWindowExW, ChangeDisplaySettingsExW, EnumDisplayDevicesW
version.dll
VerQueryValueW, GetFileVersionInfoSizeW, GetFileVersionInfoW
wtsapi32.dll
WTSQuerySessionInformationW, WTSFreeMemory

GeekBuddyRSP.exe

GeekBuddyRSP by Comodo Security Solutions (Signed)

Remove GeekBuddyRSP.exe
Version:   2, 6, 0, 0
MD5:   ae63d0db96c07cae5dc4cdb2b2a719a0
SHA1:   928a3b0dcc6f3db3f352af660115954a67a3ec1c
SHA256:   1e38e4e350484e0942be2af61cdbbacc132c955fe3fa0c1485bdca0c6283ba51

What is GeekBuddyRSP.exe?

GeekBuddyRSP Server for Windows is part of GeekBuddy, a support system built into Comodo Internet Security whereby a Comodo expert makes a remote connection to the user's computer and resolves a wide variety of technical issues, included but not restricted to virus cleaning and Internet security, such as software installation and printer setup. It is available in the paid-for versions of Comodo Internet Security, and as a separate subscription service.

About GeekBuddyRSP.exe (from Comodo Security Solutions)

GeekBuddy is part of the Comodo Group, one of the world's most trusted Internet Security and Antivirus technology providers. With over 45 million PCs around the world protected by Comodo security soft

DetailsDetails

File name:geekbuddyrsp.exe
Publisher:Comodo Security Solutions, Inc.
Product name:GeekBuddyRSP
Description:GeekBuddyRSP Server for Windows
Typical file path:C:\Program Files\common files\comodo\geekbuddyrsp.exe
File version:2, 6, 0, 0
Size:1.77 MB (1,851,088 bytes)
Certificate
Issued to:Comodo Security Solutions
Authority (CA):COMODO CA Limited
Effective date:Wednesday, April 4, 2012
Expiration date:Friday, April 5, 2013
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
COMODO
41% remove
GeekBuddy is part of the Comodo Group, one of the world's most trusted Internet Security and Antivirus technology providers. With over 45 million PCs around the world protected by Comodo security software - including its award-winning free Antivirus and Anti-malware solutions - Comodo is guided by its mission to Create Trust Online. When you need computer support, click the desktop icon to connect to one of our certified support technic...

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'GeekBuddyRSP' (GeekBuddyRSP Server)
  • GeekBuddyRSP
Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'gbrspcontrol' → "C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe" -controlservice -slave

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00301334%
0.028634%
Kernel CPU:0.00176139%
0.013761%
User CPU:0.00125194%
0.014873%
Kernel CPU time:8,116,774 ms/min
100,923,805ms/min
CPU cycles:1,319,252/sec
17,470,203/sec
Context switches:58/sec
284/sec
Memory
Private memory:2.46 MB
21.59 MB
Private (maximum):5.21 MB
Private (minimum):3.99 MB
Non-paged memory:2.46 MB
21.59 MB
Virtual memory:57.62 MB
140.96 MB
Virtual memory (peak):59.52 MB
169.69 MB
Working set:4.04 MB
18.61 MB
Working set (peak):6.27 MB
37.95 MB
Page faults:40,925/min
2,039/min
I/O
I/O read transfer:5.56 KB/sec
1.02 MB/min
I/O read operations:633/sec
343/min
I/O write transfer:5.56 KB/sec
274.99 KB/min
I/O write operations:633/sec
227/min
I/O other transfer:6.32 KB/sec
448.09 KB/min
I/O other operations:402/sec
1,671/min
Resource allocations
Threads:10
12
Handles:157
600
GUI GDI count:13
103
GUI GDI peak:19
142
GUI USER count:5
49
GUI USER peak:8
71

BehaviorsProcess properties

Integrety level:Undefined
Platform:64-bit
Command lines:
  • "C:\Program Files\common files\comodo\geekbuddyrsp.exe" -service
  • "C:\Program Files\common files\comodo\geekbuddyrsp.exe" -controlservice -slave
  • "C:\Program Files\gemeinsame dateien\comodo\geekbuddyrsp.exe" -service
Owner:User
Windows Service
Service name:GeekBuddyRSP
Display name:GeekBuddyRSP Server
Type:Win32OwnProcess
Parent processes:

ResourcesThreads

Averages
 
GeekBuddyRSP.exe (main module)
Total CPU:0.00268075%
0.272967%
Kernel CPU:0.00160868%
0.107585%
User CPU:0.00107207%
0.165382%
CPU cycles:155,741/sec
5,741,424/sec
Context switches:10/sec
79/sec
Memory:1.78 MB
1.16 MB
wow64.dll
Total CPU:0.00028325%
Kernel CPU:0.00000000%
User CPU:0.00028325%
CPU cycles:9,849/sec
Memory:252 KB
advapi32.dll (Advanced Windows 32 Base API by Microsoft)
Total CPU:0.00001882%
Kernel CPU:0.00000000%
User CPU:0.00001882%
Memory:620 KB

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 28.13%
Microsoft Windows XP 21.88%
Windows 7 Professional 15.63%
Windows 8 Pro 12.50%
Windows 7 Ultimate 9.38%
Windows 8 6.25%
Windows 8.1 3.13%
Windows 7 Ultimate N 3.13%

Distribution by countryDistribution by country

United States installs about 59.38% of GeekBuddyRSP.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 72.73%
ASUS 12.12%
Acer 9.09%
Toshiba 6.06%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE