Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

27cb5 3.45%
bef7d 31.03%
50794 6.90%
6c5b7 48.28%
4f6ba 3.45%
b7cfe 3.45%
6cd48 3.45%
(Note, AnchorFree Inc publishes each variation of this file with the same version, but the hashes are unique.)

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
ChangeServiceConfig2A, CloseServiceHandle, ControlService, CreateServiceA, DeleteService, DeregisterEventSource, InitializeSecurityDescriptor, OpenSCManagerA, OpenServiceA, QueryServiceStatus, RegCloseKey, RegEnumKeyExA, RegOpenKeyExA, RegQueryValueExA, RegisterEventSourceA, RegisterServiceCtrlHandlerExA, ReportEventA, SetSecurityDescriptorDacl, SetServiceStatus, StartServiceA, StartServiceCtrlDispatcherA, RegSetValueExA, RegQueryValueExW, RegCreateKeyExA, RegOpenKeyExW, RegCreateKeyExW, RegDeleteKeyW, RegDeleteValueW, RegEnumKeyExW, RegSetValueExW
iphlpapi.dll
GetAdaptersInfo, GetIpAddrTable, GetIpForwardTable
kernel32.dll
AddAtomA, CloseHandle, CompareFileTime, CopyFileA, CreateDirectoryA, CreateEventA, CreateFileA, CreateProcessA, CreateThread, CreateToolhelp32Snapshot, DeleteCriticalSection, DeleteFileA, EnterCriticalSection, ExitProcess, FileTimeToSystemTime, FindAtomA, FindClose, FindFirstFileA, FindNextFileA, FormatMessageA, FreeLibrary, GetAtomNameA, GetCurrentProcess, GetCurrentThreadId, GetFileSize, GetFileTime, GetLastError, GetModuleFileNameA, GetModuleHandleA, GetProcAddress, GetProcessTimes, GetStartupInfoA, GetStdHandle, GetSystemInfo, GetSystemTimeAsFileTime, GetTempFileNameA, GetTempPathA, GetTickCount, GetVersionExA, GetVolumeInformationA, InitializeCriticalSection, InterlockedExchange, LeaveCriticalSection, LoadLibraryA, LocalFree, MoveFileA, OpenEventA, OutputDebugStringA, OutputDebugStringW, Process32First, Process32Next, PulseEvent, ReadFile, ResetEvent, SetConsoleCtrlHandler, SetEvent, SetFilePointer, SetFileTime, SetLastError, SetUnhandledExceptionFilter, Sleep, WaitForSingleObject, WriteFile, lstrlenA, SetFileAttributesA, TlsFree, MoveFileExA, TlsAlloc, InterlockedDecrement, InterlockedIncrement, LockResource, SizeofResource, WideCharToMultiByte, LoadResource, FindResourceW, FindResourceExW, SetEnvironmentVariableA, CompareStringW, WriteConsoleW, SetEndOfFile, SetStdHandle, GetStringTypeW, LCMapStringW, GetTimeZoneInformation, GetCurrentProcessId, QueryPerformanceCounter, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetStartupInfoW, SetHandleCount, FlushFileBuffers, GetConsoleMode, GetConsoleCP, GetCurrentDirectoryW, GetFileType, PeekNamedPipe, GetModuleHandleW, CreateFileW, MultiByteToWideChar, DeleteFileW, GetVolumeInformationW, CreateDirectoryW, LoadLibraryW, GetVersionExW, FindFirstFileW, FindNextFileW, RaiseException, InitializeCriticalSectionAndSpinCount, HeapDestroy, HeapAlloc, HeapFree, HeapReAlloc, HeapSize, GetProcessHeap, FileTimeToLocalFileTime, GetDriveTypeA, FindFirstFileExA, DecodePointer, EncodePointer, GetCommandLineA, HeapSetInformation, GetTimeFormatA, GetDateFormatA, GetDriveTypeW, RtlUnwind, TerminateProcess, UnhandledExceptionFilter, IsDebuggerPresent, HeapCreate, GetModuleFileNameW, IsProcessorFeaturePresent, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, TlsGetValue, TlsSetValue, GetFullPathNameA, GetFileInformationByHandle, CopyFileW, IsDBCSLeadByteEx, VirtualProtect, VirtualQuery
libcurl.dll
curl_easy_cleanup, curl_easy_init, curl_easy_perform, curl_easy_setopt, curl_formadd, curl_formfree, curl_global_cleanup, curl_global_init, curl_slist_append, curl_slist_free_all
libeay32.dll
MD5_Final, MD5_Init, MD5_Update, SHA1_Final, SHA1_Init, SHA1_Update
msvcrt.dll
DllMain
shell32.dll
SHGetFolderPathA, SHGetFolderPathW
shlwapi.dll
PathAddBackslashW, PathIsDirectoryW, PathFileExistsW, PathIsRootW, PathAppendA, PathIsDirectoryA, PathIsRootA, PathFileExistsA, PathAppendW, PathBuildRootA, PathAddBackslashA
user32.dll
GetSystemMetrics
winmm.dll
mixerClose, mixerGetControlDetailsA, mixerGetLineControlsA, mixerGetLineInfoA, mixerOpen, mixerSetControlDetails, mixerGetLineInfoW, mixerGetControlDetailsW, mixerGetLineControlsW
ws2_32.dll
WSAGetLastError, WSAStartup, __WSAFDIsSet, accept, bind, closesocket, gethostname, htonl, htons, ioctlsocket, listen, ntohl, ntohs, recv, select, send, socket, WSACleanup

openvpnas.exe

By AnchorFree Inc (Signed)

Remove openvpnas.exe
MD5:   507942b5bfdbb8efd0e03bde9f72bc86
SHA1:   bc772b535f7ba2791f470ed8949bf1c7f602de46
SHA256:   59fcec6dea278bcbd4ea2fb751a8a95c8b2397531de41ee217dd11697855385c

What is openvpnas.exe?

OpenVPN is an open source software application that implements virtual private network (VPN) techniques for creating secure point-to-point or site-to-site connections in routed or bridged configurations and remote access facilities. It uses a custom security protocol. OpenVPN can be extended with third-party plug-ins or scripts which can be called at defined entry points.

About openvpnas.exe (from AnchorFree Inc)

OpenVPN is a robust and highly flexible tunneling application that uses all of the encryption, authentication, and certification features of the OpenSSL library to securely tunnel IP networks over a s

Overview

openvpnas.exe runs as a service under the name ExpatShieldService (ExpatShieldService) with extensive SYSTEM privileges (full administrator access). This is typically installed with the program Expat Shield 2.24 published by AnchorFree Inc and is most likely removed by most users once installed (61% removed). The file is digitally signed by AnchorFree Inc which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:openvpnas.exe
Typical file path:C:\Program Files\hotspot shield\bin\openvpnas.exe
Size:323.84 KB (331,608 bytes)
Certificate
Issued to:AnchorFree Inc
Authority (CA):VeriSign
Effective date:Sunday, March 27, 2011
Expiration date:Sunday, April 13, 2014
Digital DNA
PE subsystem:Windows Console
Entropy:6.573917
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
AnchorFree Inc
  61% remove
Expat Shield is a VPN program that allows users to access UK TV websites such as BBC iPlayer and ITV when outside of the UK. Expat Shield routes your IP address via a UK IP address as if you were still in the UK wherever you are in the world. Normally, the BBC will block any IP address that is outside the UK from accessing its services both online and through the BBC iPlayer program.

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • ExpatShieldService
  • 'ExpatShieldService' (Expat Shield Service)
  • 'hshld' (Hotspot Shield Service)

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.01247197%
0.028634%
Kernel CPU:0.00909709%
0.013761%
User CPU:0.00337488%
0.014873%
Kernel CPU time:1,981 ms/min
100,923,805ms/min
Memory
Private memory:6.7 MB
21.59 MB
Private (maximum):3.77 MB
Private (minimum):3.55 MB
Non-paged memory:6.7 MB
21.59 MB
Virtual memory:73.57 MB
140.96 MB
Virtual memory (peak):81.5 MB
169.69 MB
Working set:3.55 MB
18.61 MB
Working set (peak):7.6 MB
37.95 MB
Resource allocations
Threads:6
12
Handles:150
600

BehaviorsProcess properties

Integrety level:System
Platform:32-bit
Command line:"C:\Program Files\expat shield\bin\openvpnas.exe"
Owner:SYSTEM
Windows Service
Service name:ExpatShieldService
Display name:ExpatShieldService
Type:Win32OwnProcess, InteractiveProcess
Parent process:services.exe (Services and Controller app by Microsoft)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 27.59%
Windows 7 Home Premium 24.14%
Microsoft Windows XP 24.14%
Windows 8 Pro 6.90%
Windows 7 Professional 6.90%
Windows Vista Home Premium 6.90%
Windows XP Professional 3.45%

Distribution by countryDistribution by country

United States installs about 17.39% of openvpnas.exe.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
MSI 23.53%
Toshiba 23.53%
Acer 17.65%
Sony 11.76%
Hewlett-Packard 11.76%
GIGABYTE 11.76%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE