Should I block it?

No, this file is 100% safe to run.

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
SetSecurityDescriptorDacl, RegOpenKeyExW, RegDeleteValueW, RegCloseKey, RegQueryValueExW, RegSetValueExW, RegCreateKeyExW, RegDeleteKeyW, RegQueryInfoKeyW, RegEnumKeyExW, AdjustTokenPrivileges, LookupPrivilegeValueW, OpenProcessToken, InitializeSecurityDescriptor, SetServiceStatus, DeregisterEventSource, ReportEventW, RegisterEventSourceW, CloseServiceHandle, OpenServiceW, OpenSCManagerW, CopySid, GetLengthSid, IsValidSid, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, GetTokenInformation, CreateServiceW, DeleteService, ControlService, OpenThreadToken, RegisterServiceCtrlHandlerExW, StartServiceCtrlDispatcherW, QueryServiceStatus, RegCreateKeyW, ChangeServiceConfig2W, ChangeServiceConfigW, CloseEventLog, CryptDestroyHash, CryptGetHashParam, CryptHashData, CryptCreateHash, CryptReleaseContext, CryptAcquireContextW, RevertToSelf, CreateProcessAsUserW, ImpersonateLoggedOnUser, DuplicateTokenEx, AddAccessAllowedAce, InitializeAcl, MakeSelfRelativeSD, FreeSid, AllocateAndInitializeSid, EqualSid, CryptDecrypt, CryptEncrypt, CryptDestroyKey, CryptDeriveKey, RegEnumValueW
iphlpapi.dll
GetExtendedTcpTable, GetExtendedUdpTable
kernel32.dll
DllMain
ole32.dll
OleRun, CoTaskMemRealloc, CoTaskMemFree, CoCreateInstance, CoDisconnectObject, CoUninitialize, CoInitializeEx, CoInitialize, CoRevokeClassObject, CoRegisterClassObject, StringFromGUID2, CoAddRefServerProcess, CoReleaseServerProcess, CoInitializeSecurity, CoCreateGuid, CoSetProxyBlanket, CoTaskMemAlloc
psapi.dll
EmptyWorkingSet, GetModuleFileNameExW
sbap.dll
SBAPStartVolumeWatcher, SBAPStopVolumeWatcher, SBAPStart, SBAPSetExtensionList, SBAPStartETW, SBAPStopETW, SBAPIsStarted, SBAPSetPromptCallback, SBAPSetNotifyCallback, SBAPSetReportCallback, SBAPStop, SBAPSetLoggerCallback, SBAPClearCache, SBAPSetMonitorAction, SBAPSetMonitorActive, SBAPAddAllowedPid, SBAPIsETWRunning, SBAPSetUserKnownEntityCallback, SBAPUninstallDriver
sbhips.dll
SBHIPS_GetState, SBHIPS_Start, SBHIPS_AddProgram, SBHIPS_ClearProgramList, SBHIPS_Resume, SBHIPS_Stop, SBHIPS_Pause
sbte.dll
SBCSSetStringOption, SBCSGetScannerResultsW, SBCSGetScannerResultsSizeW, SBCSRunScanner, SBCSIsFileGood, SBCSClearUserKnownEntityList, SBCSAddUserKnownEntity, SBCSSetScanProgressDetailCallbackW, SBCSSetScanProgressStateCallback, SBCSResetScanOptions, SBCSSetCleanerProgressCallbackW, SBCSUninstall, SBCSGetBootTimeRegistrationStatus, SBCSUnRegisterBootTimeScanner, SBCSRegisterBootTimeScanner, SBCSScanBuffer, SBCSSetScanDescriptionW, SBCSGetDefVersionW, SBCSGetDefReleaseDateW, SBCSScanFileTrace, SBCSQueryThreatDataW, SBCSUnquarantineThreatW, SBCSQueryQuarantineIDW, SBCSGetQuarantineRecordSizeW, SBCSGetQuarantineRecordW, SBCSSetScanOption, SBCSEnableFileCache, SBCSClearPathsToScan, SBCSQuarantineBufferW, SBCSQuarantineFile2W, SBCSQuarantineFileW, SBCSDeleteThreatW, SBCSPurgeQuarantine, SBCSSetLoggerCallbackW, SBCSOpenThreatEngineW, SBCSSetQuarantineActionCallbackW, SBCSEncryptFileW, SBCSCloseThreatEngine, SBCSAddPathToScanW, SBCSSetLowRiskThreatDetection, SBCSEnableRootkitEngine, SBCSClearIgnoredThreats, SBCSAddIgnoredThreat, SBCSGetFileSignatureW, SBCSClearThreatCategoryActions, SBCSAddThreatCategoryActionW, SBCSRunCleanerW, SBCSGetCleanerResultsSizeW, SBCSGetCleanerResultsW, SBCSApplyDefinitionUpdateW
shell32.dll
SHGetFolderPathW, SHGetSpecialFolderPathW, ShellExecuteExW, SHCreateDirectoryExW
shlwapi.dll
PathRemoveFileSpecW, StrCpyW, PathAppendW, UrlGetPartW, PathFileExistsW
spursdownload.dll
SpursProxyDownload, SetSpursLoggingCallback, ThreatUpdateViaProxy, ThreatUpdate, GetNextVersionNumber, ProxyGetNextVersionNumber, SpursDownload
user32.dll
TranslateMessage, DispatchMessageW, GetMessageW, PostThreadMessageW, LoadStringW, CharUpperW, MessageBoxW, GetSystemMetrics, PeekMessageW, MsgWaitForMultipleObjects, CharNextW
userenv.dll
GetDefaultUserProfileDirectoryW, CreateEnvironmentBlock, DestroyEnvironmentBlock
version.dll
VerQueryValueW, GetFileVersionInfoSizeW, GetFileVersionInfoW
winhttp.dll
WinHttpQueryDataAvailable, WinHttpReadData, WinHttpConnect, WinHttpSetCredentials, WinHttpQueryAuthSchemes, WinHttpOpen, WinHttpSetTimeouts, WinHttpCloseHandle, WinHttpReceiveResponse, WinHttpSendRequest, WinHttpOpenRequest, WinHttpQueryHeaders
winmm.dll
timeGetTime
ws2_32.dll
FreeAddrInfoW, GetAddrInfoW, WSACreateEvent, WSAEventSelect, WSAConnect, WSAEnumNetworkEvents, WSASocketW, WSASend, WSAResetEvent, WSARecv, WSAGetOverlappedResult, WSACloseEvent, WSASetEvent

sbamsvc.exe

GFI AntiMalware Common SDK Merge Module by GFI Software (Florida) Inc. (Signed)

Remove sbamsvc.exe
Version:   6.2.4.7
MD5:   b236b3b48d167b542280ae710a233b88
SHA1:   25b69e4231d2a99c9ce88226b4ef07e30ffa96b9
SHA256:   6ecbe2f64495b047534a7ee18b9d15a2084f7293d476773f602fab07f4f780b6

Overview

sbamsvc.exe runs as a service under the name VIPRE Antivirus (SBAMSvc) with extensive SYSTEM privileges (full administrator access). It is installed with a couple of know programs including VIPRE Internet Security published by GFI Software and VIPRE Antivirus published by GFI Software. The file is digitally signed by GFI Software (Florida) Inc. which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:sbamsvc.exe
Publisher:ThreatTrack Security, Inc.
Product name:GFI AntiMalware Common SDK Merge Module
Description:GFI Software Anti Malware Service
Typical file path:C:\Program Files\gfi software\vipre\sbamsvc.exe
File version:6.2.4.7
Size:3.51 MB (3,680,512 bytes)
Build date:4/18/2013 11:42 AM
Certificate
Issued to:GFI Software (Florida) Inc.
Authority (CA):VeriSign
Effective date:Wednesday, January 25, 2012
Expiration date:Sunday, January 25, 2015
Digital DNA
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
GFI Software
10% remove
VIPRE Internet Security is the award-winning antivirus software that includes a firewall, a spam filter and bad website blocking into one powerful solution for complete protection against malware. From a two-way firewall that keeps away malicious Internet traffic to VIPRE® Easy Update™ that automatically updates out-of-date software, VIPRE Internet Security 2013 features provide complete PC security. Updates the most common cause of PC ...
GFI Software
8% remove
Vipre Antivirus is the essential antivirus software that protects against over 100,000 new web threats every day without slowing down your computer. It also eliminates conflicts during installation with Vipre Easy Install, protects against email viruses and phishing scams and scans USB sticks and other removable drives for malicious software. Vipre Antivirus keeps your personal and financial information safe from identity theft, cybercr...

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'SBAMSvc' (VIPRE Antivirus)
Network connections
  • [TCP] 4.27.18.126:80

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.00110169%
    0.028634%
    Kernel CPU:0.00043569%
    0.013761%
    User CPU:0.00066600%
    0.014873%
    Kernel CPU time:185,210 ms/min
    100,923,805ms/min
    CPU cycles:20,107,024/sec
    17,470,203/sec
    Memory
    Private memory:190.33 MB
    21.59 MB
    Private (maximum):274.84 MB
    Private (minimum):5.12 MB
    Non-paged memory:190.33 MB
    21.59 MB
    Virtual memory:373.59 MB
    140.96 MB
    Virtual memory (peak):692.95 MB
    169.69 MB
    Working set:46.88 MB
    18.61 MB
    Working set (peak):426.78 MB
    37.95 MB
    Page faults:18,090,221/min
    2,039/min
    I/O
    I/O read transfer:65.27 MB/sec
    1.02 MB/min
    I/O read operations:1,952/sec
    343/min
    I/O write transfer:8.25 MB/sec
    274.99 KB/min
    I/O write operations:512/sec
    227/min
    I/O other transfer:756.5 KB/sec
    448.09 KB/min
    I/O other operations:2,294/sec
    1,671/min
    Resource allocations
    Threads:54
    12
    Handles:605
    600

    BehaviorsProcess properties

    Integrety level:System
    Platform:64-bit
    Command line:"C:\Program Files\gfi software\vipre\sbamsvc.exe"
    Owner:SYSTEM
    Windows Service
    Service name:SBAMSvc
    Display name:VIPRE Antivirus
    Description:“Manages your antispyware and antivirus application”
    Type:Win32OwnProcess
    Parent process:services.exe (Services and Controller app by Microsoft)

    ResourcesThreads

    Averages
     
    sbap.dll (GFI AntiMalware Common SDK Merge Module by ThreatTrack Security)
    Total CPU:0.20071809%
    0.272967%
    Kernel CPU:0.01643260%
    0.107585%
    User CPU:0.18428550%
    0.165382%
    CPU cycles:4,791,809/sec
    5,741,424/sec
    Memory:528 KB
    1.16 MB
    wow64.dll (Win32 Emulation on NT64 by Microsoft)
    Total CPU:0.13905713%
    Kernel CPU:0.02986344%
    User CPU:0.10919368%
    CPU cycles:2,832,220/sec
    Memory:252 KB
    ntdll.dll
    Total CPU:0.06806176%
    Kernel CPU:0.02275869%
    User CPU:0.04530306%
    CPU cycles:1,297,802/sec
    Memory:1.68 MB
    SBAMSvc.exe (main module)
    Total CPU:0.04624025%
    Kernel CPU:0.01010589%
    User CPU:0.03613436%
    CPU cycles:1,134,200/sec
    Memory:3.53 MB
    sbtis.dll (GFI Firewall SDK by GFI Software)
    Total CPU:0.00587282%
    Kernel CPU:0.00175625%
    User CPU:0.00411657%
    CPU cycles:132,272/sec
    Memory:104 KB
    sbfwe.dll (GFI Firewall SDK by GFI Software)
    Total CPU:0.00250563%
    Kernel CPU:0.00190158%
    User CPU:0.00060404%
    CPU cycles:89,508/sec
    Memory:836 KB
    ADVAPI32.dll
    Total CPU:0.00151332%
    Kernel CPU:0.00071215%
    User CPU:0.00080117%
    CPU cycles:58,799/sec
    Memory:792 KB
    sbwebfilter.dll (GFI Firewall SDK by GFI Software)
    Total CPU:0.00008949%
    Kernel CPU:0.00008949%
    User CPU:0.00000000%
    CPU cycles:679/sec
    Memory:456 KB

    Common loaded modules

    These are modules that are typiclaly loaded within the context of this process.

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Windows 7 Home Premium 60.00%
    Windows Vista Ultimate 40.00%

    Distribution by countryDistribution by country

    United States installs about 60.00% of GFI AntiMalware Common SDK Merge Module.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    Dell 80.00%
    Toshiba 20.00%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE