Should I block it?

No, this file is 100% safe to run.

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegQueryValueExA, OpenProcessToken, CloseServiceHandle, OpenServiceA, StartServiceCtrlDispatcherA, RegisterServiceCtrlHandlerA, SetServiceStatus, LookupPrivilegeValueA, AdjustTokenPrivileges, RegSaveKeyA, AllocateAndInitializeSid, SetTokenInformation, CreateProcessAsUserA, RegOpenKeyA, RegCreateKeyA, RegSetValueExA, CreateServiceA, ChangeServiceConfigA, RegOpenKeyExA, RegCloseKey, OpenSCManagerA, GetTokenInformation
crypt32.dll
CertGetNameStringW, CertFindCertificateInStore, CertCloseStore, CryptMsgClose
kernel32.dll
GetPrivateProfileStringA, SizeofResource, LockResource, LoadResource, GetLocalTime, FindResourceA, FindResourceExA, lstrcpynA, WaitForSingleObject, OpenProcess, lstrcmpiA, MultiByteToWideChar, FindNextFileA, FindClose, WideCharToMultiByte, WriteFile, SetFilePointer, MoveFileA, DeleteFileA, SetFileAttributesA, GetFileSize, GetCurrentThreadId, GetCurrentProcessId, GetFullPathNameA, FindFirstFileA, OutputDebugStringA, GetModuleHandleA, CreateProcessA, SetEvent, OpenEventA, GetVersion, GetFileAttributesA, CreateThread, ResetEvent, WritePrivateProfileStringA, TerminateThread, GetExitCodeThread, ResumeThread, CreateEventA, WritePrivateProfileSectionA, GetPrivateProfileIntA, CompareStringW, RemoveDirectoryA, SetEnvironmentVariableA, ReadFile, SetStdHandle, FlushFileBuffers, GetThreadLocale, GetLocaleInfoA, GetACP, InterlockedExchange, GetCommandLineA, GetModuleFileNameA, SetLastError, GlobalAlloc, FreeLibrary, GlobalFree, GetWindowsDirectoryA, GetTickCount, Sleep, GetCurrentProcess, CreateFileA, GetVersionExA, DeviceIoControl, lstrcpyA, lstrlenA, lstrcatA, LoadLibraryA, GetProcAddress, CloseHandle, GetLastError, LCMapStringW, LCMapStringA, IsBadCodePtr, IsBadReadPtr, GetFileType, SetHandleCount, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, UnhandledExceptionFilter, GetStdHandle, GetStringTypeW, GetStringTypeA, GetTimeZoneInformation, GetCPInfo, GetOEMCP, TlsGetValue, TlsSetValue, TlsFree, LocalAlloc, LocalFree, DeleteCriticalSection, InitializeCriticalSection, RaiseException, CompareStringA, TlsAlloc, IsBadWritePtr, HeapDestroy, HeapAlloc, HeapFree, HeapReAlloc, HeapSize, GetProcessHeap, EnterCriticalSection, LeaveCriticalSection, RtlUnwind, ExitProcess, GetSystemTimeAsFileTime, TerminateProcess, VirtualProtect, VirtualAlloc, GetSystemInfo, VirtualQuery, GetStartupInfoA, SetUnhandledExceptionFilter, QueryPerformanceCounter, HeapCreate, VirtualFree
ole32.dll
CoUninitialize, CoInitializeSecurity, CoCreateInstance, CoInitialize
rpcrt4.dll
UuidCreate
user32.dll
wvsprintfA, CharUpperA, SendMessageA, FindWindowA, wsprintfA, IsWindow

RsMgrSvc.exe

Rising Software Distribute System by Beijing Rising Information Technology Corporation Limited (Signed)

Remove RsMgrSvc.exe
Version:   1.0.0.38
MD5:   811a775db3dba12d8fd27c352af071dc
SHA1:   30e1b1cda69ab8d4fde80ab12555c0cedb2db123
SHA256:   e9b74cb7836a2e4312fdd6c3aaf5db3a832cbf72e0098231b5997f28ab7989c7

What is RsMgrSvc.exe?

Belongs to Rising Antivirus by Rising, a Chinese software antivirus software company. Rising AV has real-time file monitor scanning as well as dynamic behavior analysis and web browser protection.

About RsMgrSvc.exe (from Beijing Rising Information Technology Corporation Limited)

Rising Antivirus protects your computers against all types of viruses, Trojans, Worms, Rootkits and other malicious programs. Ease of use, Active Defense technology, Patented Unknown Virus Scan&Clean

DetailsDetails

File name:rsmgrsvc.exe
Publisher:Beijing Rising Information Technology Co., Ltd.
Product name:Rising Software Distribute System
Description:RsMgrSvc Application
Typical file path:C:\Program Files\rising\rsd\rsmgrsvc.exe
File version:1.0.0.38
Product version:1.00
Size:146.65 KB (150,168 bytes)
Certificate
Issued to:Beijing Rising Information Technology Corporation Limited
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
Beijing Rising Information Technology, Inc.
18% remove
This software is distributed with the Rising AntiVirus application and is used in enterprise deployments to distribute the AntiVirus software to client computers.

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'RsMgrSvc' (Rsd Service)
  • RsMgrSvc

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00147009%
0.028634%
Kernel CPU:0.00094873%
0.013761%
User CPU:0.00052137%
0.014873%
Kernel CPU time:106 ms/min
100,923,805ms/min
CPU cycles:73,736/sec
17,470,203/sec
Context switches:2/sec
284/sec
Memory
Private memory:1.18 MB
21.59 MB
Private (maximum):3.15 MB
Private (minimum):1.72 MB
Non-paged memory:1.18 MB
21.59 MB
Virtual memory:38.35 MB
140.96 MB
Virtual memory (peak):41.55 MB
169.69 MB
Working set:1.98 MB
18.61 MB
Working set (peak):4.2 MB
37.95 MB
Page faults:1,524/min
2,039/min
I/O
I/O read transfer:49 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O write transfer:2 Bytes/sec
274.99 KB/min
I/O write operations:1/sec
227/min
I/O other transfer:27 Bytes/sec
448.09 KB/min
I/O other operations:1/sec
1,671/min
Resource allocations
Threads:5
12
Handles:78
600
GUI GDI count:7
103
GUI USER count:2
49

BehaviorsProcess properties

Integrety level:System
Platform:32-bit
Command line:"C:\Program Files\rising\rsd\rsmgrsvc.exe"
Owner:SYSTEM
Windows Service
Service name:RsMgrSvc
Display name:Rsd Service
Type:Win32OwnProcess, InteractiveProcess
Parent process:services.exe (Services and Controller app by Microsoft)

ResourcesThreads

Averages
 
wow64.dll
Total CPU:0.00874140%
0.272967%
Kernel CPU:0.00218535%
0.107585%
User CPU:0.00655605%
0.165382%
CPU cycles:169,863/sec
5,741,424/sec
Memory:252 KB
1.16 MB
advapi32.dll (Advanced Windows 32 Base API by Microsoft)
Total CPU:0.00415153%
Kernel CPU:0.00207577%
User CPU:0.00207577%
Memory:620 KB
sechost.dll
Total CPU:0.00166643%
Kernel CPU:0.00160338%
User CPU:0.00006305%
CPU cycles:89,566/sec
Context switches:1/sec
Memory:100 KB
RsMgrSvc.exe (main module)
Total CPU:0.00007404%
Kernel CPU:0.00005592%
User CPU:0.00001813%
CPU cycles:635/sec
Memory:144 KB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 40.00%
Windows 7 Ultimate 26.67%
Windows 7 Ultimate N 20.00%
Windows 7 Home Premium 13.33%

Distribution by countryDistribution by country

United States installs about 20.00% of Rising Software Distribute System.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Acer 33.33%
Hewlett-Packard 33.33%
GIGABYTE 33.33%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE