Should I block it?

40%
40% of PCs block this file from running.
Possible reason:
Performance resource utilization

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegQueryValueExA, RegOpenKeyExA, RegCloseKey, SetSecurityDescriptorDacl, RegOpenKeyA, RegFlushKey, OpenProcessToken, LookupPrivilegeNameA, LookupAccountSidA, InitializeSecurityDescriptor, GetTokenInformation
gdi32.dll
UnrealizeObject, SetTextColor, SetROP2, SetBkMode, SetBkColor, SelectPalette, SelectObject, MoveToEx, GetTextMetricsA, GetSystemPaletteEntries, GetStockObject, GetDeviceCaps, GetCurrentPositionEx, DeleteObject, DeleteDC, CreatePenIndirect, CreatePalette, CreateFontIndirectA, CreateBrushIndirect
kernel32.dll
GetACP, Sleep, VirtualFree, VirtualAlloc, GetCurrentThreadId, InterlockedDecrement, InterlockedIncrement, VirtualQuery, WideCharToMultiByte, MultiByteToWideChar, lstrlenA, lstrcpynA, LoadLibraryExA, GetThreadLocale, GetStartupInfoA, GetProcAddress, GetModuleHandleA, GetModuleFileNameA, GetLocaleInfoA, GetLastError, GetCommandLineA, FreeLibrary, FindFirstFileA, FindClose, ExitProcess, ExitThread, CreateThread, WriteFile, UnhandledExceptionFilter, SetFilePointer, SetEndOfFile, RtlUnwind, ReadFile, RaiseException, GetStdHandle, GetFileSize, GetFileType, CreateFileA, CloseHandle, TlsSetValue, TlsGetValue, LocalAlloc, WaitForSingleObject, WaitForMultipleObjects, TerminateThread, SystemTimeToFileTime, SuspendThread, SizeofResource, SetThreadPriority, SetFileTime, SetFileAttributesA, SetEvent, SearchPathA, ResumeThread, ResetEvent, ReadProcessMemory, QueryPerformanceFrequency, QueryDosDeviceA, OutputDebugStringA, OpenProcess, MulDiv, MoveFileExA, LockResource, LocalFree, LocalFileTimeToFileTime, LoadResource, LoadLibraryA, LeaveCriticalSection, InitializeCriticalSection, GetVersionExA, GetTickCount, GetThreadContext, GetTempPathA, GetTempFileNameA, GetShortPathNameA, GetLogicalDriveStringsA, GetLocalTime, GetFullPathNameA, GetFileInformationByHandle, GetFileAttributesA, GetExitCodeThread, GetDriveTypeA, GetDiskFreeSpaceA, GetDateFormatA, GetCurrentThread, GetCurrentProcessId, GetCurrentProcess, GetComputerNameA, GetCPInfo, FreeResource, InterlockedExchange, FormatMessageA, FlushFileBuffers, FindResourceA, FindNextFileA, FileTimeToLocalFileTime, FileTimeToDosDateTime, ExpandEnvironmentStringsA, EnumCalendarInfoA, EnterCriticalSection, DosDateTimeToFileTime, DisconnectNamedPipe, DeviceIoControl, DeleteFileA, DeleteCriticalSection, CreateNamedPipeA, CreateEventA, CreateDirectoryA, ConnectNamedPipe, CompareStringA, Beep
ole32.dll
CoTaskMemFree, CoCreateInstance, CoIsHandlerConnected, CoUninitialize, CoInitialize
oleaut32.dll
SysFreeString, SysReAllocStringLen, SysAllocStringLen, GetErrorInfo, SafeArrayPtrOfIndex, SafeArrayGetUBound, SafeArrayGetLBound, SafeArrayCreate, VariantChangeType, VariantCopy, VariantClear, VariantInit
shell32.dll
ShellExecuteA, SHGetPathFromIDListA, SHGetDesktopFolder
shfolder.dll
SHGetFolderPathA
user32.dll
GetKeyboardType, DestroyWindow, LoadStringA, MessageBoxA, CharNextA, SendMessageTimeoutA, ReleaseDC, PeekMessageA, MsgWaitForMultipleObjects, LoadIconA, IsWindow, GetSystemMetrics, GetSysColor, GetPropA, GetDesktopWindow, GetDC, CharLowerBuffA, CharUpperBuffA, CharToOemA

sp_rsser.exe

Crawler Spyware Terminator by Crawler.com

Remove sp_rsser.exe
Version:   2.6.0.524
MD5:   4a4a857713740e1564f0b7623493af06
SHA1:   6bfef427dbada017da889556eccee1e14fa1bf75
SHA256:   9fec297a72643c16340945516fdaedc25804a77d72c3fd68e9b1349813a8ad52

Overview

sp_rsser.exe runs as a service under the name Spyware Terminator Realtime Shield Service (sp_rssrv) with extensive SYSTEM privileges (full administrator access). It is installed with a couple of know programs including Spyware Terminator published by Crawler, LLC, Spyware Terminator from Crawler, LLC and Spyware Terminator by Crawler, LLC. This particular version is usually found on Windows Vista (TM) Home Premium (6.0.6002.131072).

DetailsDetails

File name:sp_rsser.exe
Publisher:Crawler.com
Product name:Crawler Spyware Terminator
Description:Spyware Terminator Realtime Shield Service
Typical file path:C:\Program Files\Spyware Terminator\sp_rsser.exe
File version:2.6.0.524
Size:477.5 KB (488,960 bytes)
Digital DNA
PE subsystem:Windows Console
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
Crawler, LLC
50% remove
The software is typically bundled with third party installers such as Open Candy. "A free spyware removal program that scans the user's computer for known threats and reports the findings to the user along with a rating of the threat's severity. Note: Spyware Terminator includes an opt-out offer for Web Security Guard, a browser add-on for Internet Explorer and Firefox that helps users avoid malicious websites." The product’s uninsta...

BehaviorsBehaviors

Service
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'sp_rssrv' (Spyware Terminator Realtime Shield Service)

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00583377%
0.028634%
Kernel CPU:0.00350026%
0.013761%
User CPU:0.00233351%
0.014873%
Kernel CPU time:94 ms/min
100,923,805ms/min
Memory
Private memory:2.61 MB
21.59 MB
Private (maximum):3.62 MB
Private (minimum):3.18 MB
Non-paged memory:2.61 MB
21.59 MB
Virtual memory:42.66 MB
140.96 MB
Virtual memory (peak):46.87 MB
169.69 MB
Working set:3.61 MB
18.61 MB
Working set (peak):3.97 MB
37.95 MB
Resource allocations
Threads:5
12
Handles:108
600

BehaviorsProcess properties

Integrety level:System
Platform:32-bit
Command line:C:\progra~1\spywar~1\sp_rsser.exe
Owner:SYSTEM
Windows Service
Service name:sp_rssrv
Display name:Spyware Terminator Realtime Shield Service
Type:Win32OwnProcess
Parent process:services.exe (Services and Controller app by Microsoft)

ResourcesThreads

Averages
 
sp_rsser.exe (main module)
Total CPU:0.00233318%
0.272967%
Kernel CPU:0.00145823%
0.107585%
User CPU:0.00087494%
0.165382%
CPU cycles:134,112/sec
5,741,424/sec
Context switches:3/sec
79/sec
Memory:528 KB
1.16 MB
ADVAPI32.dll
Total CPU:0.00116662%
Kernel CPU:0.00116662%
User CPU:0.00000000%
CPU cycles:179,154/sec
Context switches:10/sec
Memory:792 KB

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows Vista Home Premium 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE