Should I block it?

40%
40% of PCs block this file from running.
Possible reason:
Performance resource utilization

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
RegOpenKeyW, RegQueryValueW, RegCloseKey, RegCreateKeyExW, RegOpenKeyExW, RegEnumValueW, RegQueryValueExW, RegEnumKeyExW, RegSetValueExW, CreateProcessAsUserW, SetTokenInformation, GetLengthSid, ConvertStringSidToSidW, DuplicateTokenEx, OpenProcessToken, SetSecurityInfo, GetSecurityDescriptorSacl, ConvertStringSecurityDescriptorToSecurityDescriptorW, RegDeleteKeyW
gdi32.dll
DeleteDC, DeleteObject, RectVisible, CreateRectRgnIndirect, SelectClipRgn, SelectObject, CreateCompatibleDC, GetStockObject, CreateFontW, CreateSolidBrush, GetObjectW, CreateDIBSection
kernel32.dll
OutputDebugStringW, GetLastError, SetLastError, GetProcAddress, GetModuleHandleW, LoadLibraryW, Sleep, DeleteFileW, ReleaseMutex, UnmapViewOfFile, VirtualQuery, MapViewOfFile, CreateFileMappingW, OpenFileMappingW, GetTempPathW, ExpandEnvironmentStringsW, MoveFileExW, GetTempFileNameW, InterlockedExchange, InterlockedCompareExchange, GetStartupInfoW, SetUnhandledExceptionFilter, QueryPerformanceCounter, GetCurrentThreadId, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, UnhandledExceptionFilter, IsDebuggerPresent, lstrlenW, LocalFree, FormatMessageW, MoveFileW, CloseHandle, CreateFileW, GetFileAttributesW, SetFileAttributesW, RemoveDirectoryW, CopyFileW, CreateDirectoryW, SetEvent, GetEnvironmentVariableW, CreateEventA, FreeLibrary, CreateMutexW, GetVersionExW, WaitForMultipleObjects, OpenProcess, GetExitCodeProcess, WaitForSingleObject, CreateProcessW, GetCurrentProcess, GetACP, GetLocaleInfoA, GetThreadLocale, GetVersionExA, GetShortPathNameW, CreateEventW, GetLocalTime, GetTickCount, GetPrivateProfileSectionNamesW, SetCurrentDirectoryW, GetCurrentDirectoryW, OpenMutexW, lstrcmpiW, GetPrivateProfileStringW, GetPrivateProfileIntW
mfc80u.dll
DllMain
msvcp80.dll
DllMain
msvcr80.dll
DllMain
ole32.dll
CoCreateInstance, StringFromCLSID, CoTaskMemFree, CoUninitialize, CoInitialize, StringFromGUID2, CoCreateGuid
psapi.dll
GetModuleFileNameExW
shell32.dll
ShellExecuteW, SHGetSpecialFolderPathW, SHGetMalloc, SHGetPathFromIDListW, SHGetSpecialFolderLocation, ShellExecuteExW
shlwapi.dll
PathFileExistsW, PathAddBackslashW, StrStrIW, SHCopyKeyW
user32.dll
EnableWindow, LoadIconW, GetClientRect, GetWindowRect, SendMessageW, LoadBitmapW, MessageBoxW, wsprintfW, KillTimer, UnionRect, DestroyWindow, CreateWindowExW, SetWindowLongW, InvalidateRect, SetWindowPos, ShowWindow, RegisterClassExW, GetWindowLongW, BeginPaint, EndPaint, DefWindowProcW, UpdateLayeredWindow, IsRectEmpty, EqualRect, SetTimer, SetWinEventHook, GetWindowThreadProcessId, GetClassNameW, FindWindowW, IsWindow
wininet.dll
InternetSetCookieW, InternetGetCookieW

HiYo.exe

HiYo by IncrediMail Ltd. (Signed)

Remove HiYo.exe
Version:   1, 7, 0, 0383
MD5:   300afb2f1be5d69ca2070d304b4028f8
SHA1:   2d15632660c2c13ce6c89e2a1483671c4b57447c
SHA256:   710ac79d3281b33f2d3950782fbddc5959f2fb08fe6f4bbe0ad57ea0df29ce63

About HiYo.exe (from IncrediMail Ltd.)

HiYo is a free add-on for Windows Live Messenger (MSN), AIM & Yahoo! Instant Messenger that takes Instant Messaging to a whole new level of FUN! HiYo has tons of the most amazing Emoticons, Winks, Sup

Overview

HiYo.exe executes as a process with the local user's privileges. This is typically installed with the program HiYo published by Perion Network Ltd. and is most likely removed by most users once installed (63% removed). The file is digitally signed by IncrediMail Ltd.. This particular version is usually found on Windows Vista™ Home Premium (6.0.6002.131072).

DetailsDetails

File name:HiYo.exe
Publisher:IncrediMail, Ltd.
Product name:HiYo
Description:HiYo
Typical file path:C:\Program Files\hiyo\bin\hiyo.exe
File version:1, 7, 0, 0383
Size:193.3 KB (197,936 bytes)
Certificate
Issued to:IncrediMail Ltd.
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 8.0
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
Perion Network Ltd.
  63% remove
HiYo bundles the IncrediMail Incredibar Toolbar during installation.
Network connections
  • [UDP] listens on port 49162

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.33805671%
    0.028634%
    Kernel CPU:0.16499186%
    0.013761%
    User CPU:0.17306485%
    0.014873%
    Kernel CPU time:328 ms/min
    100,923,805ms/min
    CPU cycles:5,220,325/sec
    17,470,203/sec
    Memory
    Private memory:6.12 MB
    21.59 MB
    Private (maximum):11.8 MB
    Private (minimum):11.8 MB
    Non-paged memory:6.12 MB
    21.59 MB
    Virtual memory:99.49 MB
    140.96 MB
    Virtual memory (peak):101.98 MB
    169.69 MB
    Working set:11.8 MB
    18.61 MB
    Working set (peak):12.93 MB
    37.95 MB
    Page faults:10,603/min
    2,039/min
    I/O
    I/O read transfer:1.17 KB/sec
    1.02 MB/min
    I/O read operations:17/sec
    343/min
    I/O write transfer:134 Bytes/sec
    274.99 KB/min
    I/O write operations:1/sec
    227/min
    I/O other transfer:222.29 KB/sec
    448.09 KB/min
    I/O other operations:613/sec
    1,671/min
    Resource allocations
    Threads:4
    12
    Handles:1556
    600
    GUI GDI count:19
    103
    GUI USER count:21
    49

    BehaviorsProcess properties

    Integrety level:Medium
    Platform:64-bit
    Command line:"C:\Program Files\hiyo\bin\hiyo.exe" /runfromstartup
    Owner:User

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Windows Vista™ Home Premium 100.00%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE