Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.2.1.10 1.92%
6.1.5496 1.92%
6.1.5493 1.92%
6.1.5488 5.77%
6.0.5481 9.62%
6.0.5449 75.00%
6.0.5424 1.92%
5.2.5162 1.92%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
ReportEventW, RegCloseKey, RegDeleteValueW, RegOpenKeyExW, AdjustTokenPrivileges, LookupPrivilegeValueW, OpenProcessToken, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, SetServiceStatus, DeregisterEventSource, RegisterEventSourceW, CloseServiceHandle, OpenServiceW, OpenSCManagerW, RegCreateKeyExW, RegDeleteKeyW, RegQueryValueExW, RegSetValueExW, RegQueryInfoKeyW, CopySid, GetLengthSid, IsValidSid, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, GetTokenInformation, CreateServiceW, DeleteService, ControlService, RegEnumKeyExW, OpenThreadToken, RegisterServiceCtrlHandlerExW, StartServiceCtrlDispatcherW, QueryServiceStatus, ChangeServiceConfig2W, ChangeServiceConfigW, CloseEventLog, CryptDestroyHash, CryptGetHashParam, CryptHashData, CryptCreateHash, CryptReleaseContext, CryptAcquireContextW, RevertToSelf, CreateProcessAsUserW, ImpersonateLoggedOnUser, DuplicateTokenEx, AddAccessAllowedAce, InitializeAcl, MakeSelfRelativeSD, FreeSid, AllocateAndInitializeSid, RegCreateKeyW, EqualSid, CryptDecrypt, CryptEncrypt, CryptDestroyKey, CryptDeriveKey, RegEnumValueW
iphlpapi.dll
GetExtendedTcpTable, GetExtendedUdpTable
kernel32.dll
DllMain
ole32.dll
CoRegisterClassObject, CoTaskMemRealloc, CoInitialize, CoUninitialize, CoRevokeClassObject, CoTaskMemFree, StringFromGUID2, CoCreateInstance, CoAddRefServerProcess, CoReleaseServerProcess, CoInitializeSecurity, CoDisconnectObject, CoInitializeEx, CoCreateGuid, CoSetProxyBlanket, OleRun, CoTaskMemAlloc
psapi.dll
EmptyWorkingSet, GetModuleFileNameExW
sbap.dll
SBAPStartVolumeWatcher, SBAPStopVolumeWatcher, SBAPStart, SBAPSetExtensionList, SBAPIsStarted, SBAPStartETW, SBAPStopETW, SBAPSetPromptCallback, SBAPSetNotifyCallback, SBAPSetReportCallback, SBAPStop, SBAPSetLoggerCallback, SBAPClearCache, SBAPSetMonitorAction, SBAPSetMonitorActive, SBAPAddAllowedPid, SBAPIsETWRunning, SBAPSetUserKnownEntityCallback, SBAPUninstallDriver
sbhips.dll
SBHIPS_GetState, SBHIPS_Start, SBHIPS_Resume, SBHIPS_ClearProgramList, SBHIPS_Stop, SBHIPS_AddProgram, SBHIPS_Pause
sbte.dll
SBCSSetStringOption, SBCSGetScannerResultsW, SBCSGetScannerResultsSizeW, SBCSRunScanner, SBCSIsFileGood, SBCSClearUserKnownEntityList, SBCSAddUserKnownEntity, SBCSSetScanProgressDetailCallbackW, SBCSResetScanOptions, SBCSSetScanProgressStateCallback, SBCSSetCleanerProgressCallbackW, SBCSGetBootTimeRegistrationStatus, SBCSUnRegisterBootTimeScanner, SBCSRegisterBootTimeScanner, SBCSScanBuffer, SBCSApplyDefinitionUpdateW, SBCSSetScanDescriptionW, SBCSGetDefReleaseDateW, SBCSScanFileTrace, SBCSQueryThreatDataW, SBCSUnquarantineThreatW, SBCSQueryQuarantineIDW, SBCSGetQuarantineRecordSizeW, SBCSGetQuarantineRecordW, SBCSQuarantineBufferW, SBCSSetScanOption, SBCSEnableFileCache, SBCSClearPathsToScan, SBCSQuarantineFile2W, SBCSQuarantineFileW, SBCSDeleteThreatW, SBCSPurgeQuarantine, SBCSSetLoggerCallbackW, SBCSOpenThreatEngineW, SBCSSetQuarantineActionCallbackW, SBCSEnableAV, SBCSEncryptFileW, SBCSCloseThreatEngine, SBCSAddPathToScanW, SBCSSetLowRiskThreatDetection, SBCSEnableRootkitEngine, SBCSClearIgnoredThreats, SBCSAddIgnoredThreat, SBCSGetFileSignatureW, SBCSClearThreatCategoryActions, SBCSAddThreatCategoryActionW, SBCSRunCleanerW, SBCSGetCleanerResultsSizeW, SBCSGetCleanerResultsW, SBCSGetDefVersionW, SBCSUninstall
shell32.dll
SHGetFolderPathW, SHGetSpecialFolderPathW, ShellExecuteExA, ShellExecuteExW, SHCreateDirectoryExW
shlwapi.dll
PathRemoveFileSpecW, UrlGetPartW, PathAppendW, PathFileExistsW, StrCpyW
spursdownload.dll
SpursProxyDownload, SetSpursLoggingCallback, ThreatUpdateViaProxy, ThreatUpdate, GetNextVersionNumber, ProxyGetNextVersionNumber, SpursDownload
user32.dll
DispatchMessageW, GetMessageW, PostThreadMessageW, LoadStringW, CharNextW, CharUpperW, MessageBoxW, GetSystemMetrics, PeekMessageW, MsgWaitForMultipleObjects, wsprintfW, TranslateMessage
userenv.dll
GetDefaultUserProfileDirectoryW, CreateEnvironmentBlock, DestroyEnvironmentBlock
version.dll
GetFileVersionInfoSizeW, GetFileVersionInfoW, VerQueryValueW
winhttp.dll
WinHttpSetCredentials, WinHttpConnect, WinHttpQueryDataAvailable, WinHttpReadData, WinHttpQueryAuthSchemes, WinHttpQueryHeaders, WinHttpOpen, WinHttpCloseHandle, WinHttpReceiveResponse, WinHttpSendRequest, WinHttpOpenRequest
winmm.dll
timeGetTime
ws2_32.dll
FreeAddrInfoW, WSASocketW, WSAGetOverlappedResult, WSACreateEvent, WSASetEvent, WSAEventSelect, WSAConnect, WSAEnumNetworkEvents, WSASend, WSAResetEvent, WSARecv, WSACloseEvent, GetAddrInfoW

SBAMSvc.exe

GFI AntiMalware Common SDK Merge Module by GFI Software (Florida) Inc. (Signed)

Remove SBAMSvc.exe
Version:   6.0.5449
MD5:   99fc1599f89a80216e41175b8ca44d89
SHA1:   9052b95f04fd99429d15499e4c83d953e324718a
SHA256:   20306278cf081e58002d6adcc07ca65d7651c8d059392337562612edfac5beb5

What is SBAMSvc.exe?

GFI Software Anti Malware Service - GFI/VIPRE Antivirus combines antispyware and antivirus together which detects and removes viruses, spyware, rootkits, bots, Trojans and all other types of malware.

About SBAMSvc.exe (from GFI Software (Florida) Inc.)

Get everything you need to protect your PC with Vipre Internet Security. This anti-malware solution includes a firewall and spam blocker for highly efficient online security that won't slow down your

DetailsDetails

File name:sbamsvc.exe
Publisher:GFI Software
Product name:GFI AntiMalware Common SDK Merge Module
Description:GFI Software Anti Malware Service
Typical file path:C:\Program Files\gfi software\vipre\sbamsvc.exe
File version:6.0.5449
Size:3.51 MB (3,677,000 bytes)
Certificate
Issued to:GFI Software (Florida) Inc.
Authority (CA):VeriSign
Expiration date:Sunday, January 25, 2015
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
GFI Software
10% remove
VIPRE Internet Security is the award-winning antivirus software that includes a firewall, a spam filter and bad website blocking into one powerful solution for complete protection against malware. From a two-way firewall that keeps away malicious Internet traffic to VIPRE® Easy Update™ that automatically updates out-of-date software, VIPRE Internet Security 2013 features provide complete PC security. Updates the most common cause of PC ...
GFI Software
8% remove
Vipre Antivirus is the essential antivirus software that protects against over 100,000 new web threats every day without slowing down your computer. It also eliminates conflicts during installation with Vipre Easy Install, protects against email viruses and phishing scams and scans USB sticks and other removable drives for malicious software. Vipre Antivirus keeps your personal and financial information safe from identity theft, cybercr...
MaxTuneup LLC
49% remove
AntiVirus software that uses the GFI AntiMalware engine with a custom UI.
ParetoLogic Inc.
50% remove
XoftSpy Detects & Removes Spyware, Adware, Hijackers & Other Malicious Files.
ParetoLogic, Inc.
  67% remove
ParetoLogic Internet Security provides premium protection against all kinds of cyber threats. Your email messages and contact list are protected by Anti-Phishing technology and advanced Email Security. Surf the web without worry – the Active Protection and Web Shield have you covered against drive-by downloads and suspicious files. The Firewall offers a sophisticated Intrusion Detection System, monitoring, logging, and custom port or ap...
Red Dog Media
  72% remove
Run the free scan to identify the issues affecting your system and register a full version of the software for just $29.97 semiannually to clean, fix and optimize identified issues with your computer which could boost speed and performance, improve startup times, and increase stability. Live support is also available for an additional $9.97.
SparkTrust
49% remove
SparkTrust AntiVirus protects your computer by using a variety of proven and cutting edge detection methods to catch viruses and malware. It utilizes signature-based detection and, with free, frequent database updates, keeps you protected against emerging threats. In addition, SparkTrust AntiVirus employs heuristics and behavioral detection to find even more viruses and malware.

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'SBAMSvc' (XoftSpy AntiVirus Pro)
  • SBAMSvc

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00137164%
0.028634%
Kernel CPU:0.00072748%
0.013761%
User CPU:0.00064417%
0.014873%
Kernel CPU time:50,024,786 ms/min
100,923,805ms/min
CPU cycles:1,904,581/sec
17,470,203/sec
Context switches:85/sec
284/sec
Memory
Private memory:101.79 MB
21.59 MB
Private (maximum):119.32 MB
Private (minimum):3.01 MB
Non-paged memory:101.79 MB
21.59 MB
Virtual memory:264.92 MB
140.96 MB
Virtual memory (peak):416.55 MB
169.69 MB
Working set:20.56 MB
18.61 MB
Working set (peak):201.3 MB
37.95 MB
Page faults:35,723,997/min
2,039/min
I/O
I/O read transfer:74.53 MB/sec
1.02 MB/min
I/O read operations:7,730/sec
343/min
I/O write transfer:7.23 MB/sec
274.99 KB/min
I/O write operations:865/sec
227/min
I/O other transfer:1.56 MB/sec
448.09 KB/min
I/O other operations:5,475/sec
1,671/min
Resource allocations
Threads:30
12
Handles:478
600
GUI GDI count:4
103
GUI USER count:16
49

BehaviorsProcess properties

Integrety level:System
Platform:64-bit
Command lines:
  • "C:\Program Files\ad-aware antivirus\sbamsvc.exe"
  • "C:\Program Files\gfi software\vipre\sbamsvc.exe"
Owner:SYSTEM
Windows Service
Service name:SBAMSvc
Display name:XoftSpy AntiVirus Pro
Description:“Manages your antispyware and antivirus application”
Type:Win32OwnProcess
Parent process:services.exe (Services and Controller app by Microsoft)

ResourcesThreads

Averages
 
SBAMSvc.exe (main module)
Total CPU:0.31458266%
0.272967%
Kernel CPU:0.04015074%
0.107585%
User CPU:0.27443192%
0.165382%
CPU cycles:7,052,442/sec
5,741,424/sec
Context switches:2/sec
79/sec
Memory:3.53 MB
1.16 MB
ntdll.dll
Total CPU:0.00698597%
Kernel CPU:0.00627066%
User CPU:0.00071531%
CPU cycles:51,626/sec
Memory:1.66 MB
wow64.dll
Total CPU:0.00121167%
Kernel CPU:0.00045960%
User CPU:0.00075207%
CPU cycles:38,097/sec
Memory:252 KB
advapi32.dll (Advanced Windows 32 Base API by Microsoft)
Total CPU:0.00058795%
Kernel CPU:0.00012378%
User CPU:0.00046417%
Memory:620 KB
wow64win.dll
Total CPU:0.00042401%
Kernel CPU:0.00042401%
User CPU:0.00000000%
CPU cycles:3,484/sec
Memory:360 KB
sbhips.dll (GFI Firewall SDK by GFI Software)
Total CPU:0.00010005%
Kernel CPU:0.00006595%
User CPU:0.00003410%
Memory:84 KB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 30.77%
Windows 7 Professional 17.31%
Windows 7 Ultimate 11.54%
Windows 8 Pro 11.54%
Windows 8 Pro with Media Center 11.54%
Microsoft Windows XP 9.62%
Windows Vista Business 3.85%
Windows 7 Ultimate N 1.92%
Windows Vista Ultimate 1.92%

Distribution by countryDistribution by country

United States installs about 73.08% of GFI AntiMalware Common SDK Merge Module.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 29.79%
Hewlett-Packard 27.66%
GIGABYTE 10.64%
Acer 10.64%
ASUS 8.51%
Samsung 8.51%
Sony 4.26%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE