ui5guard.exe
By Ashampoo GmbH & Co. KG (Signed)
Warning 4 antivirus scanners has detected malware in various versions of ui5guard.exe.
Overview
There are 2 versions of ui5guard.exe in the wild, the latest version being . ui5guard.exe is run as a standard windows process with the logged in user's account privileges. During installation, a run registry key for all users is added that will cause the program to run each time any user logs on to Windows. The average file size is about 2.24 MB. The file is a digitally signed and issued to Ashampoo GmbH & Co. KG by VeriSign. The programs Ashampoo UnInstaller 5 v.5.0.1, Ashampoo UnInstaller 5 v.5.0.2 and Ashampoo UnInstaller 2010 have been observed as installing specific variations of ui5guard.exe. During the process's lifecycle, the typical CPU resource utilization is less than 0.01%, the average private memory consumption is about 8.65 MB and typical read I/O operations are around 15.49 KB per minute.
Details |
File name: | ui5guard.exe |
Typical file path: | C:\Program Files\ashampoo\ashampoo uninstaller 5\ui5guard.exe |
Certificate |
Issued to: | Ashampoo GmbH & Co. KG |
Authority (CA): | VeriSign |
Programs installed in
(Note, the programs listed below are for all versions of ui5guard.exe.)
Ashampoo UnInstaller is an uninstall utility designed to remove other software or parts of it from a computer.
“A combination of traditional Windows uninstallation and intelligent system monitoring, Ashampoo UnInstaller 2010 extends time-tested procedures with advanced algorithms for unmatched cleaning results....”
Behaviors
(Note, the behaviors below are for all versions of ui5guard.exe, select a unique version for details.)
Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
- 'Ashampoo Uninstaller 5 Guard' → "C:\Program Files\Ashampoo\Ashampoo UnInstaller 5\UI5Guard.exe" -TRAY
Malware detections
Based on 40+ industry antivirus scanners, 4 of them detected the following malware.
All file variations of ui5guard.exe