Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

5.0.5116 90.00%
5.0.4464 10.00%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
ReportEventW, RegCloseKey, RegDeleteValueW, RegOpenKeyExW, AdjustTokenPrivileges, LookupPrivilegeValueW, OpenProcessToken, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, SetServiceStatus, DeregisterEventSource, RegisterEventSourceW, CloseServiceHandle, OpenServiceW, OpenSCManagerW, RegCreateKeyExW, RegDeleteKeyW, RegQueryValueExW, RegSetValueExW, RegQueryInfoKeyW, CopySid, GetLengthSid, IsValidSid, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, GetTokenInformation, CreateServiceW, DeleteService, ControlService, RegEnumKeyExW, OpenThreadToken, RegisterServiceCtrlHandlerExW, StartServiceCtrlDispatcherW, QueryServiceStatus, ChangeServiceConfig2W, ChangeServiceConfigW, CloseEventLog, CryptDestroyHash, CryptGetHashParam, CryptHashData, CryptCreateHash, CryptReleaseContext, CryptAcquireContextW, RevertToSelf, CreateProcessAsUserW, ImpersonateLoggedOnUser, DuplicateTokenEx, AddAccessAllowedAce, InitializeAcl, MakeSelfRelativeSD, FreeSid, AllocateAndInitializeSid, RegCreateKeyW, EqualSid, CryptDecrypt, CryptEncrypt, CryptDestroyKey, CryptDeriveKey, RegEnumValueW
kernel32.dll
DllMain
ole32.dll
CoRegisterClassObject, CoTaskMemRealloc, CoInitialize, CoUninitialize, CoRevokeClassObject, CoTaskMemFree, StringFromGUID2, CoCreateInstance, CoAddRefServerProcess, CoReleaseServerProcess, CoInitializeSecurity, CoDisconnectObject, CoInitializeEx, CoCreateGuid, CoSetProxyBlanket, OleRun, CoTaskMemAlloc
psapi.dll
EmptyWorkingSet, GetModuleFileNameExW
sbap.dll
SBAPStartVolumeWatcher, SBAPStopVolumeWatcher, SBAPStart, SBAPSetExtensionList, SBAPIsStarted, SBAPStartETW, SBAPStopETW, SBAPSetPromptCallback, SBAPSetNotifyCallback, SBAPSetReportCallback, SBAPStop, SBAPSetLoggerCallback, SBAPClearCache, SBAPSetMonitorAction, SBAPSetMonitorActive, SBAPAddAllowedPid, SBAPIsETWRunning, SBAPSetUserKnownEntityCallback, SBAPUninstallDriver
sbhips.dll
SBHIPS_GetState, SBHIPS_Start, SBHIPS_Resume, SBHIPS_ClearProgramList, SBHIPS_Stop, SBHIPS_AddProgram, SBHIPS_Pause
sbte.dll
SBCSSetStringOption, SBCSGetScannerResultsW, SBCSGetScannerResultsSizeW, SBCSRunScanner, SBCSIsFileGood, SBCSClearUserKnownEntityList, SBCSAddUserKnownEntity, SBCSSetScanProgressDetailCallbackW, SBCSResetScanOptions, SBCSSetScanProgressStateCallback, SBCSSetCleanerProgressCallbackW, SBCSGetBootTimeRegistrationStatus, SBCSUnRegisterBootTimeScanner, SBCSRegisterBootTimeScanner, SBCSScanBuffer, SBCSApplyDefinitionUpdateW, SBCSSetScanDescriptionW, SBCSGetDefReleaseDateW, SBCSScanFileTrace, SBCSQueryThreatDataW, SBCSUnquarantineThreatW, SBCSQueryQuarantineIDW, SBCSGetQuarantineRecordSizeW, SBCSGetQuarantineRecordW, SBCSQuarantineBufferW, SBCSSetScanOption, SBCSEnableFileCache, SBCSClearPathsToScan, SBCSQuarantineFile2W, SBCSQuarantineFileW, SBCSDeleteThreatW, SBCSPurgeQuarantine, SBCSSetLoggerCallbackW, SBCSOpenThreatEngineW, SBCSSetQuarantineActionCallbackW, SBCSEnableAV, SBCSEncryptFileW, SBCSCloseThreatEngine, SBCSAddPathToScanW, SBCSSetLowRiskThreatDetection, SBCSEnableRootkitEngine, SBCSClearIgnoredThreats, SBCSAddIgnoredThreat, SBCSGetFileSignatureW, SBCSClearThreatCategoryActions, SBCSAddThreatCategoryActionW, SBCSRunCleanerW, SBCSGetCleanerResultsSizeW, SBCSGetCleanerResultsW, SBCSGetDefVersionW
shell32.dll
SHGetFolderPathW, SHGetSpecialFolderPathW, ShellExecuteExA, ShellExecuteExW, SHCreateDirectoryExW
shlwapi.dll
PathRemoveFileSpecW, UrlGetPartW, PathAppendW, PathFileExistsW
spursdownload.dll
SpursProxyDownload, SetSpursLoggingCallback, ThreatUpdateViaProxy, ThreatUpdate, GetNextVersionNumber, ProxyGetNextVersionNumber, SpursDownload
user32.dll
DispatchMessageW, GetMessageW, PostThreadMessageW, LoadStringW, CharNextW, CharUpperW, MessageBoxW, GetSystemMetrics, PeekMessageW, MsgWaitForMultipleObjects, wsprintfW, TranslateMessage
userenv.dll
GetDefaultUserProfileDirectoryW, CreateEnvironmentBlock, DestroyEnvironmentBlock
version.dll
GetFileVersionInfoSizeW, GetFileVersionInfoW, VerQueryValueW
winhttp.dll
WinHttpSetCredentials, WinHttpConnect, WinHttpQueryDataAvailable, WinHttpReadData, WinHttpQueryAuthSchemes, WinHttpQueryHeaders, WinHttpOpen, WinHttpCloseHandle, WinHttpReceiveResponse, WinHttpSendRequest, WinHttpOpenRequest
winmm.dll
timeGetTime
ws2_32.dll
FreeAddrInfoW, WSASocketW, WSAGetOverlappedResult, WSACreateEvent, WSASetEvent, WSAEventSelect, WSAConnect, WSAEnumNetworkEvents, WSASend, WSAResetEvent, WSARecv, WSACloseEvent, GetAddrInfoW

SBAMSvc.exe

GFI AntiMalware Common SDK Merge Module by GFI Software Development Ltd. (Signed)

Remove SBAMSvc.exe
Version:   5.0.4464
MD5:   77dbda1401ff941962bb133125ee22c7
SHA1:   5e96be9efd03c944337cf791587ca70f0afceadc
SHA256:   dcac985b57c469b67298af123f5bbe39c31edb4bb8404defe556fed55cdffc52

What is SBAMSvc.exe?

GFI Software Anti Malware Service - GFI/VIPRE Antivirus combines antispyware and antivirus together which detects and removes viruses, spyware, rootkits, bots, Trojans and all other types of malware.

About SBAMSvc.exe (from GFI Software Development Ltd.)

Get everything you need to protect your PC with Vipre Internet Security. This anti-malware solution includes a firewall and spam blocker for highly efficient online security that won't slow down your

DetailsDetails

File name:sbamsvc.exe
Publisher:GFI Software
Product name:GFI AntiMalware Common SDK Merge Module
Description:GFI Software Anti Malware Service
Typical file path:C:\Program Files\ad-aware antivirus\sbamsvc.exe
File version:5.0.4464
Size:2.67 MB (2,804,312 bytes)
Certificate
Issued to:GFI Software Development Ltd.
Authority (CA):VeriSign
Digital DNA
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
GFI Software
9% remove
GFI VIPRE® Antivirus Business is a scalable Endpoint Solution that protects your networked machines from all types of malware and viruses and includes a firewall (Premium only). Its Bad URL Blocking feature under web filtering prevents end users from accidentally opening known bad websites (Premium only). VIPRE Business can be installed at more than one physical location and still be centrally managed. Its policy-based architecture allo...

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'SBAMSvc' (VIPRE Internet Security)
  • SBAMSvc

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00010487%
0.028634%
Kernel CPU:0.00003774%
0.013761%
User CPU:0.00006713%
0.014873%
Kernel CPU time:18,732,132,077 ms/min
100,923,805ms/min
Memory
Private memory:114.15 MB
21.59 MB
Private (maximum):159.27 MB
Private (minimum):1.19 MB
Non-paged memory:114.15 MB
21.59 MB
Virtual memory:300.34 MB
140.96 MB
Virtual memory (peak):606.97 MB
169.69 MB
Working set:92.57 MB
18.61 MB
Working set (peak):308.98 MB
37.95 MB
Resource allocations
Threads:34
12
Handles:576
600

BehaviorsProcess properties

Integrety level:System
Platform:64-bit
Command line:C:\progra~2\advanc~1\managedav\sbamsvc.exe
Owner:User
Windows Service
Service name:SBAMSvc
Display name:VIPRE Internet Security
Description:“Manages your antispyware and antivirus application”
Type:Win32OwnProcess
Parent process:services.exe (Services and Controller app by Microsoft)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 40.00%
Windows 7 Professional 30.00%
Windows Vista Home Premium 20.00%
Windows 7 Ultimate 10.00%

Distribution by countryDistribution by country

United States installs about 70.00% of GFI AntiMalware Common SDK Merge Module.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE