Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

5, 6, 0, 1020 75.00%
5, 6, 0, 1020 25.00%
(Note, SUPERAntiSpyware.com publishes each variation of this file with the same version, but the hashes are unique.)

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
comctl32.dll
ImageList_Create, ImageList_ReplaceIcon, PropertySheetA, CreatePropertySheetPageA, InitCommonControlsEx
gdi32.dll
SelectClipRgn, GetClipRgn, CreateRectRgn, PaintRgn, CombineRgn, PathToRegion, WidenPath, DeleteObject, StrokeAndFillPath, CreatePen, SelectObject, CreateSolidBrush, GetObjectA, CreateFontW, GetDeviceCaps, FillPath, GetTextExtentPoint32W, CreateRectRgnIndirect, SetBkColor, SetTextColor, GetTextColor, GetTextExtentPoint32A, SetBkMode, StrokePath, BitBlt, GetStockObject, CreateCompatibleBitmap, CreateCompatibleDC, GetDIBits, CreateDIBSection, CreateFontIndirectW, GetObjectW, SetBrushOrgEx, CreatePatternBrush, StretchBlt, ExtCreateRegion, CreateICA, ExcludeClipRect, CreateFontIndirectA, SetWindowOrgEx, SetViewportOrgEx, ModifyWorldTransform, SetBitmapBits, GetBitmapBits, ExtTextOutA, CreateFontA, SetGraphicsMode, BeginPath, Rectangle, EndPath, MoveToEx, DeleteDC, LineTo, AngleArc
iphlpapi.dll
GetAdaptersInfo
kernel32.dll
DllMain
msimg32.dll
AlphaBlend, TransparentBlt, GradientFill
netapi32.dll
NetUseEnum, NetApiBufferFree
ole32.dll
StgCreateDocfile, StgCreateStorageEx, OleUninitialize, CoInitializeEx, CoInitializeSecurity, CoSetProxyBlanket, CoTaskMemFree, StgOpenStorage, StgOpenStorageEx, OleInitialize, CoCreateGuid, StringFromGUID2, CoInitialize, CoCreateInstance, CoUninitialize, StgIsStorageFile
psapi.dll
GetProcessMemoryInfo
rpcrt4.dll
UuidFromStringA, UuidCreate, UuidToStringA, RpcStringFreeA
secur32.dll
GetUserNameExW
shell32.dll
SHGetPathFromIDListA, SHGetMalloc, SHGetSpecialFolderLocation, ShellExecuteExA, Shell_NotifyIconA, ShellExecuteA, SHGetSpecialFolderPathA, SHGetSpecialFolderPathW, SHGetFileInfoW, ShellExecuteW, SHBrowseForFolderA, SHChangeNotify
shlwapi.dll
PathCompactPathW, PathRemoveBackslashA, PathGetDriveNumberA, PathFindNextComponentA, PathRemoveFileSpecW, PathFindNextComponentW, PathFindFileNameW, PathAppendW, PathQuoteSpacesW, PathAddBackslashW, PathRemoveBlanksA, StrChrA, PathGetArgsA, PathRemoveArgsA, PathUnquoteSpacesA, StrStrIA, StrCmpNIA, StrCpyW, PathAppendA, SHCopyKeyW, SHCopyKeyA, SHDeleteValueW, SHDeleteValueA, SHDeleteKeyW, SHDeleteKeyA, SHSetValueW, SHSetValueA, SHGetValueW, SHGetValueA, PathIsDirectoryW, PathIsDirectoryA, PathFileExistsW, PathFileExistsA, PathRemoveFileSpecA, PathAddBackslashA, PathStripToRootA, PathIsNetworkPathA, PathFindExtensionA, StrStrA, UrlUnescapeA, StrCmpNA, PathIsFileSpecA, PathAddExtensionA, PathRemoveExtensionA, PathSetDlgItemPathA, PathQuoteSpacesA, PathFindFileNameA
user32.dll
DllMain
version.dll
VerQueryValueA, GetFileVersionInfoW, GetFileVersionInfoA, GetFileVersionInfoSizeW, GetFileVersionInfoSizeA
wininet.dll
InternetOpenA, InternetGetCookieA, InternetOpenUrlA, InternetConnectA, HttpOpenRequestA, HttpSendRequestA, HttpQueryInfoA, InternetReadFile, FindFirstUrlCacheEntryA, FindNextUrlCacheEntryA, FindCloseUrlCache, DeleteUrlCacheEntry, InternetCrackUrlA, InternetCloseHandle
winmm.dll
PlaySoundA, timeGetTime
ws2_32.dll
WSCInstallProvider

SUPERAntiSpyware.exe

SUPERAntiSpyware by SUPERAntiSpyware.com (Signed)

Remove SUPERAntiSpyware.exe
Version:   5, 6, 0, 1020
MD5:   ccbcce4217948af35d2da650dbc5b761
SHA1:   a87884bcd9f218bb728cdb32f00af51141b689e8
SHA256:   b14893ebd3749592879e539381885a749b36c4866d96f49f92773521946de6b2

Overview

superantispyware.exe executes as a process with the local user's privileges usually within the context of Windows Explorer. It is set to be run when the PC boots and the user logs into Windows (added to the Run registry key for the current user). It is installed with a couple of know programs including SUPERAntiSpyware published by SUPERAntiSpyware.com, SUPERAntiSpyware from SUPERAntiSpyware.com and SUPERAntiSpyware by SUPERAntiSpyware.com. The file is digitally signed by SUPERAntiSpyware.com which was issued by the GoDaddy.com certificate authority (CA).

DetailsDetails

File name:superantispyware.exe
Publisher:SUPERAntiSpyware.com
Product name:SUPERAntiSpyware
Description:SUPERAntiSpyware Application
Typical file path:C:\Program Files\superantispyware\superantispyware.exe
File version:5, 6, 0, 1020
Size:4.54 MB (4,760,816 bytes)
Build date:5/15/2013 2:08 AM
Certificate
Issued to:SUPERAntiSpyware.com
Authority (CA):GoDaddy.com
Effective date:Friday, July 5, 2013
Expiration date:Sunday, July 5, 2015
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
SUPERAntiSpyware.com
25% remove
SUPERAntiSpyware is a software application distributed as shareware which can detect and remove spyware, adware, trojan horses, rogue security software, computer worms, rootkits, parasites and other potentially harmful software applications. Although it can detect malware, SUPERAntiSpyware is not designed to replace antivirus software. The product is available as freeware for personal use with limited functions, such as no automatic upd...
SUPERAntiSpyware.com
24% remove
SUPERAntiSpyware is a software application distributed as shareware which can detect and remove spyware, adware, trojan horses, rogue security software, computer worms, rootkits, parasites and other potentially harmful software applications. Although it can detect malware, SUPERAntiSpyware is not designed to replace antivirus software. The product is available as freeware for personal use with limited functions, such as no automatic upd...
SUPERAntiSpyware.com
19% remove
SUPERAntiSpyware is a software application distributed as shareware which can detect and remove spyware, adware, trojan horses, rogue security software, computer worms, rootkits, parasites and other potentially harmful software applications. Although it can detect malware, SUPERAntiSpyware is not designed to replace antivirus software. The product is available as freeware for personal use with limited functions, such as no automatic upd...

BehaviorsBehaviors

Startup files (user) run
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'SUPERAntiSpyware' → C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Network connections
  • [UDP] listens on port 1581

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.01121487%
    0.028634%
    Kernel CPU:0.00782437%
    0.013761%
    User CPU:0.00339049%
    0.014873%
    Kernel CPU time:2,156 ms/min
    100,923,805ms/min
    CPU cycles:837,860/sec
    17,470,203/sec
    Context switches:31/sec
    284/sec
    Memory
    Private memory:129.84 MB
    21.59 MB
    Private (maximum):24.38 MB
    Private (minimum):476 KB
    Non-paged memory:129.84 MB
    21.59 MB
    Virtual memory:264.96 MB
    140.96 MB
    Virtual memory (peak):360.87 MB
    169.69 MB
    Working set:927.2 KB
    18.61 MB
    Working set (peak):66.81 MB
    37.95 MB
    Page faults:2,940,707/min
    2,039/min
    I/O
    I/O read transfer:42.34 KB/sec
    1.02 MB/min
    I/O read operations:2/sec
    343/min
    I/O write transfer:92 Bytes/sec
    274.99 KB/min
    I/O write operations:1/sec
    227/min
    I/O other transfer:194 Bytes/sec
    448.09 KB/min
    I/O other operations:6/sec
    1,671/min
    Resource allocations
    Threads:4
    12
    Handles:291
    600
    GUI GDI count:57
    103
    GUI USER count:32
    49

    BehaviorsProcess properties

    Tray notification:Yes
    Integrety level:Undefined
    Platform:32-bit
    Command line:"C:\Program Files\superantispyware\superantispyware.exe"
    Owner:User
    Parent process:Explorer.EXE (Windows Explorer by Microsoft)

    ResourcesThreads

    Averages
     
    SUPERAntiSpyware.exe (main module)
    Total CPU:0.06753450%
    0.272967%
    Kernel CPU:0.02614110%
    0.107585%
    User CPU:0.04139340%
    0.165382%
    CPU cycles:92,923/sec
    5,741,424/sec
    Context switches:13/sec
    79/sec
    Memory:68.86 MB
    1.16 MB
    RPCRT4.dll
    Total CPU:0.00001103%
    Kernel CPU:0.00001103%
    User CPU:0.00000000%
    CPU cycles:198/sec
    Memory:780 KB

    Common loaded modules

    These are modules that are typiclaly loaded within the context of this process.

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Microsoft Windows XP 58.33%
    Windows 7 Home Premium 25.00%
    Windows Vista Home Premium 16.67%

    Distribution by countryDistribution by country

    Canada installs about 33.33% of SUPERAntiSpyware.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    American Megatrends 35.29%
    Dell 23.53%
    ASUS 23.53%
    Intel 11.76%
    Hewlett-Packard 5.88%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE