Should I block it?

No, this file is 100% safe to run.

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
RegDeleteValueA, RegQueryValueExW, RegOpenKeyExW, RegSetValueExW, RegCreateKeyExW, RegQueryValueW, RegOpenKeyW, RegEnumKeyW, RegDeleteValueW, RegEnumKeyExA, GetUserNameA, RegSetValueExA, RegEnumValueA, RegCreateKeyExA, RegCloseKey, RegDeleteKeyW, RegOpenKeyExA, RegQueryValueExA, RegEnumKeyExW, LookupPrivilegeValueW, AdjustTokenPrivileges, GetUserNameW, OpenThreadToken, LookupAccountSidW, ConvertSidToStringSidW, OpenProcessToken, GetTokenInformation, AllocateAndInitializeSid, EqualSid, FreeSid
comctl32.dll
ImageList_GetIcon, PropertySheetW, ImageList_GetIconSize, ImageList_DrawEx
comdlg32.dll
GetOpenFileNameA, GetFileTitleW
gdi32.dll
CreateEllipticRgn, Ellipse, GetBkColor, GetTextColor, CreatePatternBrush, DeleteDC, ExtSelectClipRgn, ScaleWindowExtEx, SetWindowExtEx, SetWindowOrgEx, ScaleViewportExtEx, SetViewportExtEx, OffsetViewportOrgEx, SetViewportOrgEx, GetPixel, GetStockObject, DeleteObject, CreateSolidBrush, Escape, ExtTextOutW, TextOutW, BitBlt, RectVisible, PtVisible, LPtoDP, DPtoLP, GetWindowExtEx, GetViewportExtEx, GetMapMode, CreateCompatibleDC, GetRgnBox, CreateCompatibleBitmap, MoveToEx, LineTo, SetMapMode, SetBkMode, RestoreDC, SaveDC, CreateBitmap, SetBkColor, SetTextColor, GetClipBox, CreateRectRgnIndirect, GetTextMetricsW, Rectangle, SelectObject, CreatePen, CreateFontIndirectW, GetTextExtentPoint32W, CreateRectRgn, CombineRgn, GetObjectW, CreateRoundRectRgn, GetDeviceCaps
gdiplus.dll
GdipCreateImageAttributes, GdipDisposeImageAttributes, GdipSetImageAttributesColorMatrix, GdipFillRectangle, GdipDrawImagePointRect, GdipDrawImageRectRect, GdipGetImageWidth, GdipGetImageHeight, GdipCreateLineBrushFromRect, GdipCreatePath, GdipDeletePath, GdipClosePathFigures, GdipAddPathArc, GdipDrawLine, GdipDrawLines, GdipDrawPath, GdipFillPath, GdipCreateLineBrushFromRectI, GdipGetSmoothingMode, GdipSetSmoothingMode, GdipFillRectangleI, GdipAlloc, GdipGetClip, GdipCreateRegion, GdipCreateRegionPath, GdipDeleteRegion, GdipSetTextRenderingHint, GdipMeasureString, GdipDrawImageRectI, GdipDeleteFontFamily, GdipCreateFont, GdipDeleteFont, GdipGetFamily, GdipGetFontSize, GdipGetFontUnit, GdipCreateFontFromDC, GdipCreateFontFromLogfontW, GdipDrawCachedBitmap, GdipCreateCachedBitmap, GdipDeleteCachedBitmap, GdipGetImageGraphicsContext, GdipFree, GdipGetFontStyle, GdiplusShutdown, GdipFillEllipse, GdipSetClipRectI, GdipSetClipPath, GdipClonePath, GdipAddPathLineI, GdipAddPathArcI, GdipStartPathFigure, GdipClosePathFigure, GdipSetInterpolationMode, GdipReleaseDC, GdipDrawImageI, GdipGetDC, GdipSetClipRect, GdipResetClip, GdipCreateRegionRectI, GdipCreatePen2, GdipResetPath, GdipAddPathLine, GdipGetPathWorldBounds, GdipCreateFromHWND, GdipCreateFromHWNDICM, GdipDrawImageRectRectI, GdipGetEmHeight, GdipGetCellDescent, GdipGetPathWorldBoundsI, GdipCreateFontFamilyFromName, GdipCloneFont, GdipCreateLineBrushFromRectWithAngle, GdipSetStringFormatFlags, GdipSetStringFormatHotkeyPrefix, GdipAddPathRectangle, GdipCreatePathGradientFromPath, GdipSetPathGradientCenterColor, GdipSetPathGradientSurroundColorsWithCount, GdipGetPathGradientPointCount, GdipSetPathGradientCenterPoint, GdipSetPathGradientFocusScales, GdipDrawRectangle, GdipGetGenericFontFamilySansSerif, GdipCombineRegionRect, GdipCreateBitmapFromHBITMAP, GdipAddPathRectangleI, GdipDrawEllipse, GdiplusStartup, GdipCreateBitmapFromFileICM, GdipCreateBitmapFromFile, GdipGetImageDimension, GdipDrawImageRect, GdipGraphicsClear, GdipDrawLineI, GdipDeletePen, GdipCreatePen1, GdipCloneImage, GdipDisposeImage, GdipLoadImageFromFileICM, GdipLoadImageFromFile, GdipGetFontHeight, GdipDrawString, GdipDeleteGraphics, GdipCreateFromHDC, GdipSetStringFormatTrimming, GdipSetStringFormatLineAlign, GdipSetStringFormatAlign, GdipDeleteStringFormat, GdipDrawRectangleI, GdipCreateStringFormat, GdipCloneBrush, GdipDeleteBrush, GdipCreateSolidFill, GdipSetClipRegion, GdipCreateBitmapFromScan0
kernel32.dll
DllMain
netapi32.dll
Netbios
ole32.dll
CoInitialize, CoUninitialize, CoCreateInstance, CoTaskMemFree, CoGetClassObject, CoTaskMemAlloc, CoInitializeEx, CLSIDFromString, StgOpenStorageOnILockBytes, StgCreateDocfileOnILockBytes, CreateILockBytesOnHGlobal, CLSIDFromProgID, OleUninitialize, CoFreeUnusedLibraries, OleInitialize, CoRevokeClassObject, OleIsCurrentClipboard, CoRegisterMessageFilter, OleFlushClipboard
oledlg.dll
OleUIBusyW
sensapi.dll
IsNetworkAlive
shell32.dll
SHGetFolderPathW, SHCreateDirectoryExW, ShellExecuteW, SHGetFileInfoW, ExtractIconExW, Shell_NotifyIconW, SHAppBarMessage, DragFinish, SHGetSpecialFolderPathW, DragQueryFileW
shlwapi.dll
PathFindExtensionW, PathStripToRootW, PathIsUNCW, PathRemoveFileSpecW, PathFindFileNameW, PathFileExistsW, PathIsDirectoryW
user32.dll
DllMain
version.dll
GetFileVersionInfoSizeW, VerQueryValueW, GetFileVersionInfoW
wininet.dll
InternetWriteFile, InternetSetFilePointer, InternetSetStatusCallbackW, InternetGetLastResponseInfoW, InternetQueryDataAvailable, InternetOpenW, InternetConnectW, HttpOpenRequestW, HttpSendRequestW, InternetCloseHandle, InternetReadFile, HttpQueryInfoW, HttpAddRequestHeadersW
winspool.drv
DocumentPropertiesW, ClosePrinter, OpenPrinterW

xoftspyse.exe

XoftspySE by ParetoLogic Inc. (Signed)

Remove xoftspyse.exe
Version:   6.0.0.0
MD5:   4ec893a683ca46c0bbefdd9d1e8cab9e
SHA1:   413c8645ef548b03fe36ff3128b43b9acd3fb01b
SHA256:   d18cd0e7c59e24b3b4bc027944be697cdecd92327b3051b6332673f01fabd692

Overview

xoftspyse.exe executes as a process with the local user's privileges. It is set to be start when the PC boots and any user logs into Windows (added to the Run registry key for the all users under the local machine). The file is digitally signed by ParetoLogic Inc. which was issued by the VeriSign certificate authority (CA). This particular version is usually found on Microsoft Windows XP (5.1.2600.131072).

DetailsDetails

File name:xoftspyse.exe
Publisher:ParetoLogic Inc.
Product name:XoftspySE
Typical file path:C:\Program Files\xoftspyse6\xoftspyse.exe
File version:6.0.0.0
Product version:6.0.0.39
Size:4.63 MB (4,853,016 bytes)
Build date:8/29/2009 12:15 AM
Certificate
Issued to:ParetoLogic Inc.
Authority (CA):VeriSign
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'XoftSpySE' → "C:\Program Files\xoftspyse6\xoftspyse.exe" -NM -hidesplash

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00627396%
0.028634%
Kernel CPU:0.00276765%
0.013761%
User CPU:0.00350631%
0.014873%
Kernel CPU time:1,297 ms/min
100,923,805ms/min
Context switches:1/sec
284/sec
Memory
Private memory:4.89 MB
21.59 MB
Private (maximum):13.93 MB
Private (minimum):6.14 MB
Non-paged memory:4.89 MB
21.59 MB
Virtual memory:60.37 MB
140.96 MB
Virtual memory (peak):191.93 MB
169.69 MB
Working set:13.61 MB
18.61 MB
Working set (peak):14.36 MB
37.95 MB
Resource allocations
Threads:5
12
Handles:287
600
GUI GDI count:192
103
GUI USER count:215
49

BehaviorsProcess properties

Tray notification:Yes
Integrety level:Undefined
Platform:32-bit
Command line:"C:\Program Files\xoftspyse6\xoftspyse.exe" -nm -hidesplash
Owner:User
Parent process:explorer.exe (Windows Explorer by Microsoft Corporation)

ResourcesThreads

Averages
 
xoftspyse.exe (main module)
Total CPU:0.00718895%
0.272967%
Kernel CPU:0.00559141%
0.107585%
User CPU:0.00159754%
0.165382%
Memory:4.69 MB
1.16 MB
gdiplus.dll
Total CPU:0.00029050%
Kernel CPU:0.00014525%
User CPU:0.00014525%
Memory:1.67 MB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 100.00%

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
American Megatrends 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE