Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

940b4 16.67%
59756 66.67%
6b15b 16.67%
(Note, Garena Online Pte Ltd publishes each variation of this file with the same version, but the hashes are unique.)

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
InitializeSecurityDescriptor, GetUserNameW, FreeSid, CheckTokenMembership, AllocateAndInitializeSid, SetSecurityDescriptorDacl
kernel32.dll
GetProcessId, InitializeCriticalSection, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, OpenProcess, GetModuleFileNameW, GetCurrentProcessId, GetSystemDirectoryW, SetLastError, InterlockedDecrement, WaitForSingleObject, FlushViewOfFile, ReleaseMutex, CreateFileMappingW, MapViewOfFileEx, CreateMutexW, OpenMutexW, OpenFileMappingW, UnmapViewOfFile, CreateEventW, CreateThread, SetEvent, TerminateThread, ResetEvent, GetTickCount, GetLastError, GetCurrentProcess, DuplicateHandle, GetCurrentThreadId, OpenEventW, Sleep, GetCurrentDirectoryW, IsBadCodePtr, WaitForMultipleObjects, CreateToolhelp32Snapshot, Process32FirstW, Process32NextW, GetProcessTimes, GetPrivateProfileIntW, GetACP, MoveFileW, OutputDebugStringW, OutputDebugStringA, WideCharToMultiByte, MultiByteToWideChar, GetLocalTime, LocalAlloc, IsBadWritePtr, CreateProcessW, IsBadReadPtr, CloseHandle, DisableThreadLibraryCalls, SetErrorMode, GetTempPathW, CreateFileA, ReadFile, SetEndOfFile, WriteConsoleW, GetConsoleOutputCP, WriteConsoleA, FlushFileBuffers, SetStdHandle, CreateFileW, IsValidLocale, HeapDestroy, HeapAlloc, HeapFree, HeapReAlloc, HeapSize, GetProcessHeap, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetSystemTimeAsFileTime, GetFileAttributesW, GetCommandLineA, RaiseException, RtlUnwind, GetModuleHandleW, GetProcAddress, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, ExitProcess, WriteFile, GetStdHandle, GetModuleFileNameA, GetCPInfo, GetOEMCP, IsValidCodePage, SetHandleCount, GetFileType, GetStartupInfoA, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, HeapCreate, VirtualFree, QueryPerformanceCounter, VirtualAlloc, FreeLibrary, InterlockedExchange, LoadLibraryA, InitializeCriticalSectionAndSpinCount, SetFilePointer, GetConsoleCP, GetConsoleMode, GetLocaleInfoW, GetLocaleInfoA, LCMapStringA, LCMapStringW, GetStringTypeA, GetStringTypeW, GetUserDefaultLCID, EnumSystemLocalesA, GetModuleHandleA, GetWindowsDirectoryW, SetPriorityClass, SetThreadPriority, GetCurrentThread
ole32.dll
CoInitializeSecurity, CoUninitialize, CoCreateInstance, CoInitializeEx
shlwapi.dll
SHGetValueW
user32.dll
DispatchMessageW, TranslateMessage, GetMessageW, PeekMessageW
Export table
DllUnregisterServer
rundll_entryW

ggspawn.dll

By Garena Online Pte Ltd (Signed)

Remove ggspawn.dll
MD5:   597565173589a476f8c0a3cbf766c670
SHA1:   17da5b86ea4f4205b6c4d6db3170a54e335666de
SHA256:   8571e3297e4c1c3a9df2c37541aca1cc7794405ed2f9ce40eb8e618d68c64b45

Overview

ggspawn.dll executes as a process with the local user's privileges. It is an auto-starting process that used the Windows Task Scheduler service to load when the user logs into Windows (sometimes this is required to bypass the UAC protection). This is typically installed with the program Garena Plus published by Garena Online Pte Ltd.. The file is digitally signed by Garena Online Pte Ltd which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:ggspawn.dll
Typical file path:C:\game\garena plus\ggspawn.dll
Size:183.95 KB (188,360 bytes)
Certificate
Issued to:Garena Online Pte Ltd
Authority (CA):VeriSign
Effective date:Tuesday, October 18, 2011
Expiration date:Monday, November 3, 2014
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
Garena Online Pte Ltd.
2% remove
The Garena Plus application developed for various games distributed by the comapny allows gamers to develop buddy lists, chat with friends online and check on game progress and achievements. The Garena Plus game platform can be downloaded for free and it has an interface similar to instant messaging platforms. Gamers are also able to form groups or clans, and chat with multiple gamers simultaneously through public or private channels t...

BehaviorsBehaviors

Scheduled tasks
  • Entry path '\gg_uac_daemon_DonutLoveDew'
  • Entry path '\gg_uac_daemon_Mycom'
  • Entry path '\gg_uac_daemon_bikun_000'
Scheduled tasks startups
Set to load on user login (bypasses Windows UAC if enabled)
  • Login entry path '\gg_uac_daemon_DonutLoveDew'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00083362%
0.028634%
Kernel CPU:0.00035727%
0.013761%
User CPU:0.00047636%
0.014873%
Kernel CPU time:1,217 ms/min
100,923,805ms/min
Memory
Private memory:1.34 MB
21.59 MB
Private (maximum):3.66 MB
Private (minimum):116 KB
Non-paged memory:1.34 MB
21.59 MB
Virtual memory:43.33 MB
140.96 MB
Virtual memory (peak):45.49 MB
169.69 MB
Working set:200 KB
18.61 MB
Working set (peak):4.28 MB
37.95 MB
Resource allocations
Threads:3
12
Handles:79
600
GUI GDI count:15
103
GUI GDI peak:16
142
GUI USER count:5
49
GUI USER peak:6
71

BehaviorsProcess properties

Integrety level:High
Platform:32-bit
Command line:C:\Windows\System32\rundll32.exe "C:\Program Files\garena plus\ggspawn.dll",rundll_entry -p 0
Owner:User
Parent process:taskeng.exe (Task Scheduler Engine by Microsoft)

ResourcesThreads

Averages
 
ggspawn.dll (main module)
Total CPU:0.00701612%
0.272967%
Kernel CPU:0.00392077%
0.107585%
User CPU:0.00309535%
0.165382%
CPU cycles:983,907/sec
5,741,424/sec
Memory:200 KB
1.16 MB
rundll32.exe (Windows host process (Rundll32) by Microsoft)
Total CPU:0.00015476%
Kernel CPU:0.00010317%
User CPU:0.00005159%
CPU cycles:2,841/sec
Memory:56 KB

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 66.67%
Microsoft Windows XP 16.67%
Windows 8 Pro 16.67%

Distribution by countryDistribution by country

Thailand installs about 66.67% of ggspawn.dll.
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE