Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.2.1.10 1.92%
6.1.5496 1.92%
6.1.5493 1.92%
6.1.5488 5.77%
6.0.5481 9.62%
6.0.5449 75.00%
6.0.5424 1.92%
5.2.5162 1.92%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
ReportEventW, RegCloseKey, RegDeleteValueW, RegOpenKeyExW, AdjustTokenPrivileges, LookupPrivilegeValueW, OpenProcessToken, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, SetServiceStatus, DeregisterEventSource, RegisterEventSourceW, CloseServiceHandle, OpenServiceW, OpenSCManagerW, RegCreateKeyExW, RegDeleteKeyW, RegQueryValueExW, RegSetValueExW, RegQueryInfoKeyW, CopySid, GetLengthSid, IsValidSid, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, GetTokenInformation, CreateServiceW, DeleteService, ControlService, RegEnumKeyExW, OpenThreadToken, RegisterServiceCtrlHandlerExW, StartServiceCtrlDispatcherW, QueryServiceStatus, ChangeServiceConfig2W, ChangeServiceConfigW, CloseEventLog, CryptDestroyHash, CryptGetHashParam, CryptHashData, CryptCreateHash, CryptReleaseContext, CryptAcquireContextW, RevertToSelf, CreateProcessAsUserW, ImpersonateLoggedOnUser, DuplicateTokenEx, AddAccessAllowedAce, InitializeAcl, MakeSelfRelativeSD, FreeSid, AllocateAndInitializeSid, RegCreateKeyW, EqualSid, CryptDecrypt, CryptEncrypt, CryptDestroyKey, CryptDeriveKey, RegEnumValueW
iphlpapi.dll
GetExtendedTcpTable, GetExtendedUdpTable
kernel32.dll
DllMain
ole32.dll
CoRegisterClassObject, CoTaskMemRealloc, CoInitialize, CoUninitialize, CoRevokeClassObject, CoTaskMemFree, StringFromGUID2, CoCreateInstance, CoAddRefServerProcess, CoReleaseServerProcess, CoInitializeSecurity, CoDisconnectObject, CoInitializeEx, CoCreateGuid, CoSetProxyBlanket, OleRun, CoTaskMemAlloc
psapi.dll
EmptyWorkingSet, GetModuleFileNameExW
sbap.dll
SBAPStartVolumeWatcher, SBAPStopVolumeWatcher, SBAPStart, SBAPSetExtensionList, SBAPIsStarted, SBAPStartETW, SBAPStopETW, SBAPSetPromptCallback, SBAPSetNotifyCallback, SBAPSetReportCallback, SBAPStop, SBAPSetLoggerCallback, SBAPClearCache, SBAPSetMonitorAction, SBAPSetMonitorActive, SBAPAddAllowedPid, SBAPIsETWRunning, SBAPSetUserKnownEntityCallback, SBAPUninstallDriver
sbhips.dll
SBHIPS_GetState, SBHIPS_Start, SBHIPS_Resume, SBHIPS_ClearProgramList, SBHIPS_Stop, SBHIPS_AddProgram, SBHIPS_Pause
sbte.dll
SBCSSetStringOption, SBCSGetScannerResultsW, SBCSGetScannerResultsSizeW, SBCSRunScanner, SBCSIsFileGood, SBCSClearUserKnownEntityList, SBCSAddUserKnownEntity, SBCSSetScanProgressDetailCallbackW, SBCSResetScanOptions, SBCSSetScanProgressStateCallback, SBCSSetCleanerProgressCallbackW, SBCSGetBootTimeRegistrationStatus, SBCSUnRegisterBootTimeScanner, SBCSRegisterBootTimeScanner, SBCSScanBuffer, SBCSApplyDefinitionUpdateW, SBCSSetScanDescriptionW, SBCSGetDefReleaseDateW, SBCSScanFileTrace, SBCSQueryThreatDataW, SBCSUnquarantineThreatW, SBCSQueryQuarantineIDW, SBCSGetQuarantineRecordSizeW, SBCSGetQuarantineRecordW, SBCSQuarantineBufferW, SBCSSetScanOption, SBCSEnableFileCache, SBCSClearPathsToScan, SBCSQuarantineFile2W, SBCSQuarantineFileW, SBCSDeleteThreatW, SBCSPurgeQuarantine, SBCSSetLoggerCallbackW, SBCSOpenThreatEngineW, SBCSSetQuarantineActionCallbackW, SBCSEnableAV, SBCSEncryptFileW, SBCSCloseThreatEngine, SBCSAddPathToScanW, SBCSSetLowRiskThreatDetection, SBCSEnableRootkitEngine, SBCSClearIgnoredThreats, SBCSAddIgnoredThreat, SBCSGetFileSignatureW, SBCSClearThreatCategoryActions, SBCSAddThreatCategoryActionW, SBCSRunCleanerW, SBCSGetCleanerResultsSizeW, SBCSGetCleanerResultsW, SBCSGetDefVersionW, SBCSUninstall
shell32.dll
SHGetFolderPathW, SHGetSpecialFolderPathW, ShellExecuteExA, ShellExecuteExW, SHCreateDirectoryExW
shlwapi.dll
PathRemoveFileSpecW, UrlGetPartW, PathAppendW, PathFileExistsW, StrCpyW
spursdownload.dll
SpursProxyDownload, SetSpursLoggingCallback, ThreatUpdateViaProxy, ThreatUpdate, GetNextVersionNumber, ProxyGetNextVersionNumber, SpursDownload
user32.dll
DispatchMessageW, GetMessageW, PostThreadMessageW, LoadStringW, CharNextW, CharUpperW, MessageBoxW, GetSystemMetrics, PeekMessageW, MsgWaitForMultipleObjects, wsprintfW, TranslateMessage
userenv.dll
GetDefaultUserProfileDirectoryW, CreateEnvironmentBlock, DestroyEnvironmentBlock
version.dll
GetFileVersionInfoSizeW, GetFileVersionInfoW, VerQueryValueW
winhttp.dll
WinHttpSetCredentials, WinHttpConnect, WinHttpQueryDataAvailable, WinHttpReadData, WinHttpQueryAuthSchemes, WinHttpQueryHeaders, WinHttpOpen, WinHttpCloseHandle, WinHttpReceiveResponse, WinHttpSendRequest, WinHttpOpenRequest
winmm.dll
timeGetTime
ws2_32.dll
FreeAddrInfoW, WSASocketW, WSAGetOverlappedResult, WSACreateEvent, WSASetEvent, WSAEventSelect, WSAConnect, WSAEnumNetworkEvents, WSASend, WSAResetEvent, WSARecv, WSACloseEvent, GetAddrInfoW

SBAMSvc.exe

GFI AntiMalware Common SDK Merge Module by GFI Software (Florida) Inc. (Signed)

Remove SBAMSvc.exe
Version:   6.1.5496
MD5:   709976d3f27a6fd40735e01ef34cb745
SHA1:   1d9e0bd4612ca0967c055b1455b06d308f5e942d

What is SBAMSvc.exe?

GFI Software Anti Malware Service - GFI/VIPRE Antivirus combines antispyware and antivirus together which detects and removes viruses, spyware, rootkits, bots, Trojans and all other types of malware.

About SBAMSvc.exe (from GFI Software (Florida) Inc.)

Get everything you need to protect your PC with Vipre Internet Security. This anti-malware solution includes a firewall and spam blocker for highly efficient online security that won't slow down your

DetailsDetails

File name:sbamsvc.exe
Publisher:GFI Software
Product name:GFI AntiMalware Common SDK Merge Module
Description:GFI Software Anti Malware Service
Typical file path:C:\Program Files\gfi software\vipre\sbamsvc.exe
File version:6.1.5496
Size:3.51 MB (3,677,000 bytes)
Build date:11/6/2012 4:58 PM
Certificate
Issued to:GFI Software (Florida) Inc.
Authority (CA):VeriSign
Expiration date:Sunday, January 25, 2015
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
Ascentive
  53% remove
From the site: "The free download of Ascentive’s Registry Cleaner, Anti-Malware Software, and other trial products are intended to find issues, errors, threats, junk, and clutter that can be removed by single or multiple Ascentive products after paid activation. The free scans do not require payment and are set to run automatically every 7 days for your convenience. Uninstall is easy and can be done at any time using “Add/Remove Program...
ParetoLogic Inc.
  62% remove
XoftSpy scans your computer's memory, registry, files & folders for Spyware, Adware, Spybots, Malware, Spy Pop-ups, Keyloggers, and Unwanted Toolbars.
ParetoLogic Inc.
50% remove
XoftSpy Detects & Removes Spyware, Adware, Hijackers & Other Malicious Files.
PC VITALWARE, LLC
23% remove
Scan, and remove malware from your Windows PC now with PC MRI Anti-Malware software. In minutes, you can remove malware and other errors from your computer that can slow it down. Easy to use features and tools let you take control of your system. PC MRI Anti-Malware has a advanced scanner that locate issues fast and accurately. The scanner dives deep into every aspect of the computers system searching for potential issues. Results are d...
SparkTrust
20% remove
SparkTrust AntiVirus is a versatile protector. It searches your computer deeply to find and boot out all kinds of malicious and unwanted programs: viruses, adware, spyware, malware, pop-up generators, keyloggers, computer worms, Trojan downloaders and more. This advanced antivirus/antimalware software finds rootkits and other deep-rooted threats and thoroughly removes them. SparkTrust AntiVirus protects your computer by using a variety ...
VastTech
  52% remove
This program includes extensive protection by kicking out spyware, viruses, adware, Trojan downloads and other malware. Not only is it easy to use, it will install and set up quickly. It also has active protection by the use of real time blocking technology. There is also advanced detection with up to date ways to find viruses, spyware, and malware. Root kits can be removed by be ridding malware that goes into the darkest corners of the...
VastTech
49% remove
This program includes extensive protection by kicking out spyware, viruses, adware, Trojan downloads and other malware. Not only is it easy to use, it will install and set up quickly. It also has active protection by the use of real time blocking technology. There is also advanced detection with up to date ways to find viruses, spyware, and malware. Root kits can be removed by be ridding malware that goes into the darkest corners of the...
VastTech
48% remove
Several programs out there today advertise that they can help you remove the infections slowing your computer down. OMG Tech Help’s personnel have all the training to help you eliminate all the spyware, adware, and malware on your computer. Many of the virus protection software on the market can not guarantee that it will remove all of the infections like OMG Tech Help can. IF you try to download antivirus software and are unable to ins...
VastTech
  52% remove
http://www.omgtechhelp.com

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'SBAMSvc' (XoftSpy AntiVirus Pro)
  • SBAMSvc

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00458693%
0.028634%
Kernel CPU:0.00332727%
0.013761%
User CPU:0.00125966%
0.014873%
Kernel CPU time:99,125 ms/min
100,923,805ms/min
Memory
Private memory:108.61 MB
21.59 MB
Private (maximum):117.39 MB
Private (minimum):1.18 MB
Non-paged memory:108.61 MB
21.59 MB
Virtual memory:310.76 MB
140.96 MB
Virtual memory (peak):455.09 MB
169.69 MB
Working set:41.13 MB
18.61 MB
Working set (peak):204.11 MB
37.95 MB
Resource allocations
Threads:59
12
Handles:590
600

BehaviorsProcess properties

Integrety level:System
Platform:32-bit
Command line:"C:\Program Files\paretologic\xoftspy antivirus pro\sbamsvc.exe"
Owner:SYSTEM
Windows Service
Service name:SBAMSvc
Display name:XoftSpy AntiVirus Pro
Description:“Manages your antispyware and antivirus application”
Type:Win32OwnProcess
Parent process:services.exe (Services and Controller app by Microsoft)

ResourcesThreads

Averages
 
sbap.dll (GFI AntiMalware Common SDK Merge Module by GFI Software)
Total CPU:0.15341057%
0.272967%
Kernel CPU:0.01417886%
0.107585%
User CPU:0.13923171%
0.165382%
CPU cycles:2,984,050/sec
5,741,424/sec
Memory:528 KB
1.16 MB
SBAMSvc.exe (main module)
Total CPU:0.02436500%
Kernel CPU:0.01663312%
User CPU:0.00773188%
CPU cycles:466,993/sec
Memory:3.53 MB
sechost.dll
Total CPU:0.00280995%
Kernel CPU:0.00068815%
User CPU:0.00212180%
CPU cycles:56,617/sec
Memory:100 KB
sbtis.dll (GFI Firewall SDK by GFI Software)
Total CPU:0.00032440%
Kernel CPU:0.00007209%
User CPU:0.00025231%
CPU cycles:8,426/sec
Memory:104 KB
sbfwe.dll (GFI Firewall SDK by GFI Software)
Total CPU:0.00029821%
Kernel CPU:0.00014430%
User CPU:0.00015392%
CPU cycles:18,179/sec
Memory:836 KB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 30.77%
Windows 7 Professional 17.31%
Windows 7 Ultimate 11.54%
Windows 8 Pro 11.54%
Windows 8 Pro with Media Center 11.54%
Microsoft Windows XP 9.62%
Windows Vista Business 3.85%
Windows 7 Ultimate N 1.92%
Windows Vista Ultimate 1.92%

Distribution by countryDistribution by country

United States installs about 73.08% of GFI AntiMalware Common SDK Merge Module.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 29.79%
Hewlett-Packard 27.66%
GIGABYTE 10.64%
Acer 10.64%
ASUS 8.51%
Samsung 8.51%
Sony 4.26%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE