Should I block it?

No, this file is 100% safe to run.

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
CryptGetHashParam, StartServiceA, LookupPrivilegeValueA, AdjustTokenPrivileges, OpenThreadToken, RegDeleteKeyA, RegOpenKeyA, GetUserNameA, SetSecurityDescriptorGroup, SetSecurityDescriptorOwner, GetLengthSid, CopySid, StartServiceCtrlDispatcherA, ControlService, QueryServiceStatusEx, ChangeServiceConfigW, DeleteService, CreateServiceW, ChangeServiceConfig2A, RegDeleteValueA, SetServiceStatus, RegisterServiceCtrlHandlerW, RegisterEventSourceW, ReportEventA, DeregisterEventSource, OpenServiceW, GetSecurityDescriptorLength, ConvertStringSecurityDescriptorToSecurityDescriptorW, ChangeServiceConfigA, OpenSCManagerA, OpenServiceA, CloseServiceHandle, QueryServiceConfigW, OpenProcessToken, GetTokenInformation, RegEnumKeyA, ConvertStringSidToSidA, LookupAccountSidW, CryptAcquireContextA, CryptCreateHash, CryptHashData, CryptDestroyHash, CryptReleaseContext, RegQueryValueExA, RegOpenKeyExA, RegCreateKeyA, RegCloseKey, RegSetValueExA, AllocateAndInitializeSid, SetEntriesInAclA, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, FreeSid, ConvertStringSecurityDescriptorToSecurityDescriptorA, GetSecurityDescriptorSacl, SetNamedSecurityInfoA
kernel32.dll
DllMain
ole32.dll
StringFromGUID2, ProgIDFromCLSID, CoTaskMemFree, CoCreateGuid, CoUninitialize, CoInitializeSecurity, CoInitializeEx, CoRegisterClassObject, CoRevokeClassObject, CoInitialize, CoCreateFreeThreadedMarshaler, CoCreateInstance
psapi.dll
GetModuleFileNameExW, GetProcessImageFileNameW
secur32.dll
GetUserNameExW
user32.dll
GetCursorPos, GetQueueStatus, SendMessageA, FindWindowA, GetForegroundWindow, GetCapture, MsgWaitForMultipleObjectsEx, DefWindowProcA, RegisterClassA, UnregisterClassA, DestroyWindow, CreateWindowExA, PostMessageA, GetMessageA, TranslateMessage, KillTimer, SetTimer, ShowWindow, SetThreadDesktop, GetProcessWindowStation, SetProcessWindowStation, CreateDesktopA, PeekMessageA, DispatchMessageA, PostThreadMessageA, CharNextA, LoadStringA, GetClipboardOwner, MsgWaitForMultipleObjects
version.dll
GetFileVersionInfoSizeW, GetFileVersionInfoW
ws2_32.dll
WSASocketA, WSAIoctl, WSAEventSelect, WSCGetProviderPath, WSCEnumProtocols

pbproxy.exe

PBProxy.exe by PingBetter

Remove pbproxy.exe
Version:   2.1.4.9
MD5:   9f3d18f9b3c94a2fc219fb2d17454e9d
SHA1:   bf7482752f16b6d3e583a1062baed7c9d97a4400

Overview

pbproxy.exe runs as a service under the name PBProxy with extensive SYSTEM privileges (full administrator access). This is typically installed with the program PingBetter published by PingBetter. This particular version is usually found on Windows 7 Ultimate (6.1.7600.0).

DetailsDetails

File name:pbproxy.exe
Publisher:PingBetter
Product name:PBProxy.exe
Typical file path:C:\Program Files\pingbetter\pbproxy.exe
File version:2.1.4.9
Size:2.11 MB (2,211,840 bytes)
Build date:10/31/2011 7:01 PM
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
PingBetter
5% remove

BehaviorsBehaviors

Service
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'PBProxy'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.03142760%
0.028634%
Kernel CPU:0.01076181%
0.013761%
User CPU:0.02066579%
0.014873%
Kernel CPU time:1,232 ms/min
100,923,805ms/min
Memory
Private memory:4.73 MB
21.59 MB
Private (maximum):8.25 MB
Private (minimum):8.09 MB
Non-paged memory:4.73 MB
21.59 MB
Virtual memory:109.83 MB
140.96 MB
Virtual memory (peak):110.95 MB
169.69 MB
Working set:8.21 MB
18.61 MB
Working set (peak):8.36 MB
37.95 MB
Resource allocations
Threads:103
12
Handles:441
600

BehaviorsProcess properties

Integrety level:System
Platform:32-bit
Owner:SYSTEM
Windows Service
Service name:PBProxy
Description:“Provide PingBetter services”
Type:Win32OwnProcess
Parent process:services.exe (Services and Controller app by Microsoft)

ResourcesThreads

Averages
 
ntdll.dll
Total CPU:0.04802042%
0.272967%
Kernel CPU:0.00965108%
0.107585%
User CPU:0.03836934%
0.165382%
CPU cycles:509,026/sec
5,741,424/sec
Memory:1.23 MB
1.16 MB
pbproxy.exe (main module)
Total CPU:0.00899214%
Kernel CPU:0.00743745%
User CPU:0.00155470%
CPU cycles:1,986,542/sec
Memory:2.14 MB
sechost.dll
Total CPU:0.00465733%
Kernel CPU:0.00000000%
User CPU:0.00465733%
CPU cycles:3,021,373/sec
Memory:100 KB

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 100.00%

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Acer 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE