Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

15.0.0149.500 (win7sp1_gdr_oob_osppv2(oobla).120427-1624) 0.92%
15.0.0149.500 (win7sp1_gdr_oob_osppv2(oobla).120427-1605) 0.92%
14.0.0370.400 (longhorn(wmbla).090811-1833) 25.77%
14.0.0370.400 (longhorn(wmbla).090811-1826) 72.39%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
TraceMessage, RegCloseKey, GetTraceEnableFlags, GetTraceEnableLevel, GetTraceLoggerHandle, RegisterTraceGuidsW, UnregisterTraceGuids, SetServiceStatus, RegOpenKeyExW, RegQueryValueExW, RegisterServiceCtrlHandlerW, StartServiceCtrlDispatcherW, FreeSid, RegDeleteKeyW, RegCreateKeyExW, CheckTokenMembership, AllocateAndInitializeSid, ConvertStringSidToSidW, RegEnumKeyW, RegQueryInfoKeyW, ConvertStringSecurityDescriptorToSecurityDescriptorW, RegSetKeySecurity, RegDeleteValueW, RegSetValueExW, CryptGenRandom, CryptAcquireContextW, CryptReleaseContext, DeregisterEventSource, ReportEventW, RegisterEventSourceW, EqualSid, OpenProcessToken, ConvertSidToStringSidW, LookupAccountNameW, RegEnumKeyExW, CryptDestroyHash, CryptHashData, CryptCreateHash, CryptGetHashParam, CryptDestroyKey, CryptEncrypt, CryptDecrypt, CryptImportKey, CryptSignHashA, CryptVerifySignatureA, CryptExportKey, CryptGenKey, RegOpenKeyW, RegCreateKeyW, GetTokenInformation
kernel32.dll
DllMain, DeleteTimerQueue, Sleep, InterlockedCompareExchange, InitializeCriticalSectionAndSpinCount, WaitForSingleObject, GetCurrentThreadId, DeleteTimerQueueEx, ReleaseSemaphore, LoadLibraryW, SetThreadPriority, GetThreadPriority, DuplicateHandle, GetCurrentProcess, GetCurrentThread, OpenThread, GetTickCount, ReleaseMutex, CreateSemaphoreW, IsWow64Process, OpenMutexW, CreateMutexW, ExpandEnvironmentStringsW, GetTimeFormatW, GetDateFormatW, FileTimeToSystemTime, SetFileAttributesW, GetFileAttributesW, ChangeTimerQueueTimer, CreateDirectoryW, WriteFile, CreateFileW, GetFileSizeEx, QueueUserWorkItem, ReadFile, GetFileSize, MultiByteToWideChar, OpenProcess, GetCurrentProcessId, UnregisterWaitEx, CompareFileTime, SystemTimeToFileTime, GetSystemTimeAsFileTime, lstrlenW, GetSystemTime, DebugBreak, GetPrivateProfileStringW, lstrcmpiW, GetPrivateProfileSectionW, InitializeCriticalSection, SetLastError, VirtualProtect, VirtualFree, VirtualAlloc, GetLocalTime, MoveFileExW, CopyFileW, FlushFileBuffers, DeleteFileW, SetFilePointer, CreateFileMappingW, MapViewOfFile, UnmapViewOfFile, GetSystemDefaultUILanguage, GetUserDefaultUILanguage, GetComputerNameW, DeviceIoControl, GetLocaleInfoW, GetSystemDirectoryW, LCMapStringW, WideCharToMultiByte, GetVersionExA, GetVersion, UnhandledExceptionFilter, TerminateProcess, QueryPerformanceCounter, GetModuleHandleA, SetUnhandledExceptionFilter, InterlockedExchange, SetEvent, GetModuleHandleExW, GetProcAddress, CreateTimerQueue, CreateTimerQueueTimer, CreateEventW, RegisterWaitForSingleObject, RaiseException, InterlockedDecrement, GetVersionExW, InterlockedIncrement, GetLastError, HeapSetInformation, DeleteTimerQueueTimer, LeaveCriticalSection, EnterCriticalSection, DeleteCriticalSection, LocalFree, LocalAlloc, FreeLibrary, CloseHandle, DecodePointer, EncodePointer, HeapFree, GetProcessHeap, HeapAlloc, GetSystemInfo, GetModuleHandleW
msvcrt.dll
DllMain
ntdll.dll
RtlUnwind, RtlEqualUnicodeString, RtlInitUnicodeString, NtQueryObject, RtlFreeHeap, RtlAllocateHeap
ole32.dll
CoInitializeEx, CoUninitialize, CoInitializeSecurity
rpcrt4.dll
UuidFromStringW, I_RpcMapWin32Status, RpcServerRegisterIfEx, RpcServerUseProtseqEpW, RpcServerListen, RpcServerUnregisterIf, RpcMgmtStopServerListening, I_RpcBindingInqLocalClientPID, RpcServerInqCallAttributesW, RpcRaiseException, RpcStringFreeW, RpcRevertToSelfEx, UuidToStringW, NdrServerCall2, UuidCreate, RpcImpersonateClient
user32.dll
CharPrevW, CharNextW

osppsvc.exe

Microsoft Office by Microsoft Corporation (Signed)

Remove osppsvc.exe
Version:   15.0.0149.500 (win7sp1_gdr_oob_osppv2(oobla).120427-1624)
MD5:   31dc8d825d2c4eb0ff7ed021bb92c541
SHA1:   4c9e653d9fd83ccdc6bcd2417cda0f162a517c5a
SHA256:   5fc370d0ed18b8570f26321a16614315e858e455670fb490d41b9f327afb9d78

Overview

OSPPSVC.EXE runs as a service under the name Office Software Protection Platform (SYSTEM\CurrentControlSet\Services\osppsvc) with minimal NETWORK SERVICE privileges on the local PC and acts as the computer on the network. The file is digitally signed by Microsoft Corporation. This version is designed to run on Windows 7 and is compiled as a 64 bit program.

DetailsDetails

File name:OSPPSVC.EXE
Publisher:Microsoft Corporation
Product name:Microsoft® Office
Description:Microsoft Office Software Protection Platform Service
Typical file path:C:\Program Files\common files\microsoft shared\officesoftwareprotectionplatform\osppsvc.exe
File version:15.0.0149.500 (win7sp1_gdr_oob_osppv2(oobla).120427-1624)
Product version:15.0.0149.500
Size:4.9 MB (5,132,888 bytes)
Certificate
Issued to:Microsoft Corporation
Authority (CA):Microsoft Corporation
Effective date:Monday, July 13, 2009
Expiration date:Wednesday, October 13, 2010
Digital DNA
Entropy:7.491986
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'osppsvc' (Office Software Protection Platform)

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00014842%
0.028634%
Kernel CPU:0.00001749%
0.013761%
User CPU:0.00013093%
0.014873%
Kernel CPU time:78 ms/min
100,923,805ms/min
CPU cycles:73,908/sec
17,470,203/sec
Memory
Private memory:4.75 MB
21.59 MB
Private (maximum):12.09 MB
Private (minimum):1.51 MB
Non-paged memory:4.75 MB
21.59 MB
Virtual memory:45.06 MB
140.96 MB
Virtual memory (peak):46.07 MB
169.69 MB
Working set:2.51 MB
18.61 MB
Working set (peak):12.09 MB
37.95 MB
Page faults:4,723/min
2,039/min
I/O
I/O read transfer:221 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O other transfer:2 Bytes/sec
448.09 KB/min
I/O other operations:1/sec
1,671/min
Resource allocations
Threads:3
12
Handles:139
600

BehaviorsProcess properties

Integrety level:System
Platform:64-bit
Command line:"C:\Program Files\common files\microsoft shared\officesoftwareprotectionplatform\osppsvc.exe"
Owner:NETWORK SERVICE
Windows Service
Service name:SYSTEM\CurrentControlSet\Services\osppsvc
Display name:Office Software Protection Platform
Description:“Office Software Protection Platform Service (unlocalized description)”
Type:Win32OwnProcess
Parent process:services.exe (Services and Controller app by Microsoft)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 48.00%
Windows 7 Ultimate 13.50%
Windows 7 Professional 12.00%
Windows 8.1 5.50%
Windows 8.1 Pro 3.50%
Windows 7 Home Basic 3.50%
Windows 8.1 Single Language 2.50%
Windows 8 2.00%
Windows 8 Pro 2.00%
Windows 8 Enterprise N 1.00%
Windows Vista Home Premium 1.00%
Windows 8.1 Pro with Media Center 1.00%
Windows 8 Enterprise 1.00%
Windows 8 Pro with Media Center 1.00%
Microsoft Windows XP 1.00%
Windows 8 Single Language 0.50%
Windows 7 Starter 0.50%
Windows Se7en Titan 0.50%

Distribution by countryDistribution by country

United States installs about 42.05% of Microsoft® Office.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 25.00%
Hewlett-Packard 15.00%
ASUS 12.86%
Toshiba 12.86%
Lenovo 9.29%
Acer 8.93%
Sony 5.71%
Intel 5.71%
Samsung 1.43%
GIGABYTE 1.43%
NEC 1.43%
Alienware 0.36%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE