Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

15.0.0149.500 (win7sp1_gdr_oob_osppv2(oobla).120427-1624) 0.92%
15.0.0149.500 (win7sp1_gdr_oob_osppv2(oobla).120427-1605) 0.92%
14.0.0370.400 (longhorn(wmbla).090811-1833) 25.77%
14.0.0370.400 (longhorn(wmbla).090811-1826) 72.39%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
TraceMessage, RegCloseKey, GetTraceEnableFlags, GetTraceEnableLevel, GetTraceLoggerHandle, RegisterTraceGuidsW, UnregisterTraceGuids, SetServiceStatus, RegOpenKeyExW, RegQueryValueExW, RegisterServiceCtrlHandlerW, StartServiceCtrlDispatcherW, FreeSid, RegDeleteKeyW, RegCreateKeyExW, CheckTokenMembership, AllocateAndInitializeSid, ConvertStringSidToSidW, RegEnumKeyW, RegQueryInfoKeyW, ConvertStringSecurityDescriptorToSecurityDescriptorW, RegSetKeySecurity, RegDeleteValueW, RegSetValueExW, CryptGenRandom, CryptAcquireContextW, CryptReleaseContext, DeregisterEventSource, ReportEventW, RegisterEventSourceW, EqualSid, OpenProcessToken, ConvertSidToStringSidW, LookupAccountNameW, RegEnumKeyExW, CryptDestroyHash, CryptHashData, CryptCreateHash, CryptGetHashParam, CryptDestroyKey, CryptEncrypt, CryptDecrypt, CryptImportKey, CryptSignHashA, CryptVerifySignatureA, CryptExportKey, CryptGenKey, RegOpenKeyW, RegCreateKeyW, GetTokenInformation
kernel32.dll
DllMain, DeleteTimerQueue, Sleep, InterlockedCompareExchange, InitializeCriticalSectionAndSpinCount, WaitForSingleObject, GetCurrentThreadId, DeleteTimerQueueEx, ReleaseSemaphore, LoadLibraryW, SetThreadPriority, GetThreadPriority, DuplicateHandle, GetCurrentProcess, GetCurrentThread, OpenThread, GetTickCount, ReleaseMutex, CreateSemaphoreW, IsWow64Process, OpenMutexW, CreateMutexW, ExpandEnvironmentStringsW, GetTimeFormatW, GetDateFormatW, FileTimeToSystemTime, SetFileAttributesW, GetFileAttributesW, ChangeTimerQueueTimer, CreateDirectoryW, WriteFile, CreateFileW, GetFileSizeEx, QueueUserWorkItem, ReadFile, GetFileSize, MultiByteToWideChar, OpenProcess, GetCurrentProcessId, UnregisterWaitEx, CompareFileTime, SystemTimeToFileTime, GetSystemTimeAsFileTime, lstrlenW, GetSystemTime, DebugBreak, GetPrivateProfileStringW, lstrcmpiW, GetPrivateProfileSectionW, InitializeCriticalSection, SetLastError, VirtualProtect, VirtualFree, VirtualAlloc, GetLocalTime, MoveFileExW, CopyFileW, FlushFileBuffers, DeleteFileW, SetFilePointer, CreateFileMappingW, MapViewOfFile, UnmapViewOfFile, GetSystemDefaultUILanguage, GetUserDefaultUILanguage, GetComputerNameW, DeviceIoControl, GetLocaleInfoW, GetSystemDirectoryW, LCMapStringW, WideCharToMultiByte, GetVersionExA, GetVersion, UnhandledExceptionFilter, TerminateProcess, QueryPerformanceCounter, GetModuleHandleA, SetUnhandledExceptionFilter, InterlockedExchange, SetEvent, GetModuleHandleExW, GetProcAddress, CreateTimerQueue, CreateTimerQueueTimer, CreateEventW, RegisterWaitForSingleObject, RaiseException, InterlockedDecrement, GetVersionExW, InterlockedIncrement, GetLastError, HeapSetInformation, DeleteTimerQueueTimer, LeaveCriticalSection, EnterCriticalSection, DeleteCriticalSection, LocalFree, LocalAlloc, FreeLibrary, CloseHandle, DecodePointer, EncodePointer, HeapFree, GetProcessHeap, HeapAlloc, GetSystemInfo, GetModuleHandleW
msvcrt.dll
DllMain
ntdll.dll
RtlUnwind, RtlEqualUnicodeString, RtlInitUnicodeString, NtQueryObject, RtlFreeHeap, RtlAllocateHeap
ole32.dll
CoInitializeEx, CoUninitialize, CoInitializeSecurity
rpcrt4.dll
UuidFromStringW, I_RpcMapWin32Status, RpcServerRegisterIfEx, RpcServerUseProtseqEpW, RpcServerListen, RpcServerUnregisterIf, RpcMgmtStopServerListening, I_RpcBindingInqLocalClientPID, RpcServerInqCallAttributesW, RpcRaiseException, RpcStringFreeW, RpcRevertToSelfEx, UuidToStringW, NdrServerCall2, UuidCreate, RpcImpersonateClient
user32.dll
CharPrevW, CharNextW

osppsvc.exe

Microsoft Office by Microsoft Corporation (Signed)

Remove osppsvc.exe
Version:   15.0.0149.500 (win7sp1_gdr_oob_osppv2(oobla).120427-1605)
MD5:   eb7467c63290f868991fbe15a7c97e5d
SHA1:   504512b9edba08a2106b8f2b7f85100b549c9dc6

Overview

OSPPSVC.EXE runs as a service under the name Office Software Protection Platform (SYSTEM\CurrentControlSet\Services\osppsvc) with minimal NETWORK SERVICE privileges on the local PC and acts as the computer on the network. The file is digitally signed by Microsoft Corporation. This version is designed to run on Windows 7 and is compiled as a 32 bit program.

DetailsDetails

File name:OSPPSVC.EXE
Publisher:Microsoft Corporation
Product name:Microsoft® Office
Description:Microsoft Office Software Protection Platform Service
Typical file path:C:\Program Files\common files\microsoft shared\officesoftwareprotectionplatform\osppsvc.exe
File version:15.0.0149.500 (win7sp1_gdr_oob_osppv2(oobla).120427-1605)
Product version:15.0.0149.500
Size:4.62 MB (4,846,168 bytes)
Certificate
Issued to:Microsoft Corporation
Authority (CA):Microsoft Corporation
Effective date:Monday, July 13, 2009
Expiration date:Wednesday, October 13, 2010
Digital DNA
Entropy:7.491986
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'osppsvc' (Office Software Protection Platform)

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.10737468%
0.028634%
Kernel CPU:0.00909458%
0.013761%
User CPU:0.09828010%
0.014873%
Kernel CPU time:62 ms/min
100,923,805ms/min
Memory
Private memory:2.2 MB
21.59 MB
Private (maximum):8.86 MB
Private (minimum):7.97 MB
Non-paged memory:2.2 MB
21.59 MB
Virtual memory:27.79 MB
140.96 MB
Virtual memory (peak):28.04 MB
169.69 MB
Working set:8.86 MB
18.61 MB
Working set (peak):8.87 MB
37.95 MB
Resource allocations
Threads:5
12
Handles:122
600

BehaviorsProcess properties

Integrety level:System
Platform:32-bit
Command line:"C:\Program Files\common files\microsoft shared\officesoftwareprotectionplatform\osppsvc.exe"
Owner:NETWORK SERVICE
Windows Service
Service name:SYSTEM\CurrentControlSet\Services\osppsvc
Display name:Office Software Protection Platform
Description:“Office Software Protection Platform Service (unlocalized description)”
Type:Win32OwnProcess
Parent process:services.exe (Services and Controller app by Microsoft)

ResourcesThreads

Averages
 
ntdll.dll
Total CPU:0.07076235%
0.272967%
Kernel CPU:0.00000000%
0.107585%
User CPU:0.07076235%
0.165382%
CPU cycles:2,083,358/sec
5,741,424/sec
Memory:1.23 MB
1.16 MB
OSPPSVC.EXE (main module)
Total CPU:0.01324541%
Kernel CPU:0.00883027%
User CPU:0.00441514%
CPU cycles:201,519/sec
Memory:4.63 MB

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 48.00%
Windows 7 Ultimate 13.50%
Windows 7 Professional 12.00%
Windows 8.1 5.50%
Windows 8.1 Pro 3.50%
Windows 7 Home Basic 3.50%
Windows 8.1 Single Language 2.50%
Windows 8 2.00%
Windows 8 Pro 2.00%
Windows 8 Enterprise N 1.00%
Windows Vista Home Premium 1.00%
Windows 8.1 Pro with Media Center 1.00%
Windows 8 Enterprise 1.00%
Windows 8 Pro with Media Center 1.00%
Microsoft Windows XP 1.00%
Windows 8 Single Language 0.50%
Windows 7 Starter 0.50%
Windows Se7en Titan 0.50%

Distribution by countryDistribution by country

United States installs about 42.05% of Microsoft® Office.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 25.00%
Hewlett-Packard 15.00%
ASUS 12.86%
Toshiba 12.86%
Lenovo 9.29%
Acer 8.93%
Sony 5.71%
Intel 5.71%
Samsung 1.43%
GIGABYTE 1.43%
NEC 1.43%
Alienware 0.36%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE