We Recommend: You Boost your PC today

Should I block it?

No, this file is 100% safe to run.

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegQueryValueExW, RegCreateKeyExW, RegCloseKey, RegOpenKeyExW, SetServiceStatus, RegisterServiceCtrlHandlerW, StartServiceCtrlDispatcherW, OpenSCManagerW, CreateServiceW, RegSetValueExW, RegQueryValueExA, RegOpenKeyExA, StartServiceW, AdjustTokenPrivileges, LookupPrivilegeValueW, OpenProcessToken, RegDeleteValueW, DeleteService, QueryServiceStatus, OpenServiceW, CloseServiceHandle
crypt32.dll
CryptDecodeObject, CertFreeCertificateContext, CertGetNameStringW, CertFindCertificateInStore, CryptQueryObject, CryptMsgClose, CertCloseStore, CryptMsgGetParam
kernel32.dll
GetCurrentProcess, CreateProcessW, HeapFree, GetProcessHeap, HeapAlloc, CreateEventA, GetSystemTimeAsFileTime, SetEvent, WaitForSingleObject, GetModuleFileNameA, lstrcmpiW, CreateEventW, SetLastError, lstrcmpA, lstrcpyW, VirtualAlloc, LocalAlloc, GetModuleHandleA, CreateFileW, CopyFileW, MoveFileExW, SetFileAttributesW, TerminateProcess, GetExitCodeProcess, OpenProcess, Process32NextW, GetModuleFileNameW, GetEnvironmentVariableW, SetEnvironmentVariableW, MultiByteToWideChar, GetModuleHandleW, LoadLibraryExA, FormatMessageA, RemoveDirectoryW, FindNextFileW, LocalFree, GetPrivateProfileStringA, ReleaseMutex, CreateMutexA, OpenMutexA, CreateWaitableTimerA, SetWaitableTimer, WaitForMultipleObjects, SystemTimeToFileTime, ResumeThread, TlsSetValue, ResetEvent, OpenEventA, GetCurrentProcessId, TlsGetValue, TlsFree, TlsAlloc, GetVolumeInformationW, FreeLibrary, CompareStringW, InterlockedDecrement, GetSystemInfo, GetVersionExW, SetPriorityClass, DeviceIoControl, CreateFileA, InterlockedExchange, InterlockedCompareExchange, HeapSetInformation, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, QueryPerformanceCounter, lstrlenA, CloseHandle, WideCharToMultiByte, DeleteCriticalSection, InitializeCriticalSection, GetProcAddress, LoadLibraryW, GetCurrentThreadId, LeaveCriticalSection, EnterCriticalSection, FindClose, MoveFileW, FindFirstFileW, DeleteFileW, GetLastError, Sleep, GetTickCount, GetFileAttributesW, GetFileAttributesExW, SetFileTime, CreateDirectoryW, AreFileApisANSI, EncodePointer, DosDateTimeToFileTime, LocalFileTimeToFileTime, CreateToolhelp32Snapshot, IsProcessorFeaturePresent, DecodePointer
msvcp100.dll
DllMain
msvcr100.dll
DllMain
ole32.dll
CoUninitialize, CoInitializeSecurity, CoInitializeEx, CoCreateInstance, CoSetProxyBlanket
rpcrt4.dll
NdrAsyncServerCall, RpcServerRegisterIf, RpcAsyncAbortCall, RpcServerListen, RpcServerRegisterAuthInfoW, RpcEpRegisterW, RpcServerInqBindings, NdrServerCall2, RpcServerUseProtseqW, RpcBindingVectorFree, RpcEpUnregister, RpcMgmtStopServerListening
shell32.dll
SHGetSpecialFolderPathW, SHGetFolderPathW
shlwapi.dll
SHGetValueA
user32.dll
ExitWindowsEx, MessageBoxA
wininet.dll
InternetReadFile, InternetOpenW, InternetGetConnectedState, InternetCloseHandle, InternetOpenUrlW

PSafesvc.exe

PSafe Core by PSafe Tecnologia S.A. (Signed)

Version:   3.6.51302.6102
MD5:   5d205e91393d65870fb1aa49d859852b
SHA1:   f1fb52ac0a2655d3fe2dc6f1d5f2979bf70374a4
SHA256:   d4a9da1d0b2f7fbfef73ace62eccccae540faa28e4be80785b3bf2d6d7fd1f51

Overview

psafesvc.exe runs as a service under the name PSafeSVC within the local user context. The file is digitally signed by PSafe Tecnologia S.A. which was issued by the DigiCert Inc certificate authority (CA). This particular version is usually found on Windows 7 Home Basic (6.1.7601.65536).

DetailsDetails

File name:psafesvc.exe
Publisher:PSafe S/A
Product name:PSafe Core
Description:PSafe Core Service
Typical file path:C:\Program Files\psafe\psafesvc.exe
File version:3.6.51302.6102
Size:1.12 MB (1,174,728 bytes)
Certificate
Issued to:PSafe Tecnologia S.A.
Authority (CA):DigiCert Inc
Digital DNA
PE subsystem:Windows Console
File packed:No
Code language:Microsoft Visual C++ 10.0
.NET CLR:No
More details

BehaviorsBehaviors

Service
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'PSafeSVC'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00210447%
0.028634%
Kernel CPU:0.00115679%
0.013761%
User CPU:0.00094768%
0.014873%
Kernel CPU time:780,005 ms/min
100,923,805ms/min
Memory
Private memory:2.87 MB
21.59 MB
Private (maximum):8.48 MB
Private (minimum):380 KB
Non-paged memory:2.87 MB
21.59 MB
Virtual memory:55.45 MB
140.96 MB
Virtual memory (peak):65.44 MB
169.69 MB
Working set:704 KB
18.61 MB
Working set (peak):8.79 MB
37.95 MB
Resource allocations
Threads:6
12
Handles:185
600

BehaviorsProcess properties

Integrety level:System
Platform:32-bit
Command line:"C:\Program Files\psafe\psafesvc.exe"
Owner:User
Windows Service
Service name:PSafeSVC
Type:Win32OwnProcess
Parent process:services.exe (Services and Controller app by Microsoft)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Basic 100.00%

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Hewlett-Packard 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE