Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

ba772 50.00%
6baac 50.00%
(Note, Ashampoo GmbH & Co. KG publishes each variation of this file with the same version, but the hashes are unique.)

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
RegQueryValueExW, RegOpenKeyExW, RegCloseKey, SetSecurityDescriptorDacl, RegFlushKey, RegDeleteValueW, OpenProcessToken, LookupPrivilegeValueA, InitializeSecurityDescriptor, GetUserNameW, GetTokenInformation, GetLengthSid, FreeSid, AllocateAndInitializeSid, AdjustTokenPrivileges, GetKernelObjectSecurity
comctl32.dll
InitializeFlatSB, FlatSB_SetScrollProp, FlatSB_SetScrollPos, FlatSB_SetScrollInfo, FlatSB_GetScrollPos, FlatSB_GetScrollInfo, _TrackMouseEvent, ImageList_SetIconSize, ImageList_GetIconSize, ImageList_Write, ImageList_Read, ImageList_GetDragImage, ImageList_DragShowNolock, ImageList_DragMove, ImageList_DragLeave, ImageList_DragEnter, ImageList_EndDrag, ImageList_BeginDrag, ImageList_Copy, ImageList_GetIcon, ImageList_Remove, ImageList_DrawEx, ImageList_Replace, ImageList_Draw, ImageList_GetBkColor, ImageList_SetBkColor, ImageList_ReplaceIcon, ImageList_Add, ImageList_SetImageCount, ImageList_GetImageCount, ImageList_Destroy, ImageList_Create
fltlib.dll
FilterReplyMessage, FilterGetMessage, FilterSendMessage, FilterConnectCommunicationPort
gdi32.dll
UnrealizeObject, StretchDIBits, StretchBlt, SetWindowOrgEx, SetWinMetaFileBits, SetViewportOrgEx, SetTextColor, SetStretchBltMode, SetROP2, SetPixelV, SetPixel, SetPaletteEntries, SetMapMode, SetEnhMetaFileBits, SetDIBits, SetDIBColorTable, SetBrushOrgEx, SetBkMode, SetBkColor, SelectPalette, SelectObject, SaveDC, RoundRect, RestoreDC, ResizePalette, Rectangle, RectVisible, RealizePalette, Polyline, Polygon, PolyBezierTo, PolyBezier, PlayEnhMetaFile, Pie, PatBlt, MoveToEx, MaskBlt, LineTo, LPtoDP, IntersectClipRect, GetWindowOrgEx, GetWinMetaFileBits, GetTextMetricsW, GetTextExtentPointW, GetTextExtentPoint32W, GetSystemPaletteEntries, GetStockObject, GetRgnBox, GetPixel, GetPaletteEntries, GetObjectW, GetNearestPaletteIndex, GetEnhMetaFilePaletteEntries, GetEnhMetaFileHeader, GetEnhMetaFileDescriptionW, GetEnhMetaFileBits, GetDeviceCaps, GetDIBits, GetDIBColorTable, GetDCOrgEx, GetCurrentPositionEx, GetClipBox, GetBrushOrgEx, GetBitmapBits, GdiFlush, FrameRgn, ExtTextOutW, ExtFloodFill, ExcludeClipRect, EnumFontFamiliesExW, Ellipse, DeleteObject, DeleteEnhMetaFile, DeleteDC, CreateSolidBrush, CreateRectRgn, CreatePenIndirect, CreatePalette, CreateHalftonePalette, CreateFontIndirectW, CreateDIBitmap, CreateDIBSection, CreateCompatibleDC, CreateCompatibleBitmap, CreateBrushIndirect, CreateBitmap, CopyEnhMetaFileW, Chord, BitBlt, Arc
gdiplus.dll
GdiplusShutdown, GdiplusStartup
kernel32.dll
lstrcmpiA, LoadLibraryA, LocalFree, LocalAlloc, GetACP, Sleep, VirtualFree, VirtualAlloc, GetSystemInfo, GetTickCount, QueryPerformanceCounter, GetVersion, GetCurrentThreadId, VirtualQuery, WideCharToMultiByte, MultiByteToWideChar, lstrlenW, lstrcpynW, LoadLibraryExW, IsValidLocale, GetSystemDefaultUILanguage, GetStartupInfoA, GetProcAddress, GetModuleHandleW, GetModuleFileNameW, GetUserDefaultUILanguage, GetLocaleInfoW, GetLastError, GetCommandLineW, FreeLibrary, FindFirstFileW, FindClose, ExitProcess, ExitThread, CreateThread, CompareStringW, WriteFile, UnhandledExceptionFilter, RtlUnwind, RaiseException, GetStdHandle, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, CloseHandle, TlsSetValue, TlsGetValue, DllMain
msimg32.dll
AlphaBlend
ole32.dll
CreateStreamOnHGlobal, OleUninitialize, OleInitialize, CoTaskMemFree, CoTaskMemAlloc, CoCreateInstance, CoUninitialize, CoInitialize, IsEqualGUID, GetHGlobalFromStream
oleacc.dll
LresultFromObject
oleaut32.dll
SysFreeString, SysReAllocStringLen, SysAllocStringLen, GetErrorInfo, VariantInit, SafeArrayPtrOfIndex, SafeArrayPutElement, SafeArrayGetElement, SafeArrayUnaccessData, SafeArrayAccessData, SafeArrayGetUBound, SafeArrayGetLBound, SafeArrayCreate, VariantChangeType, VariantCopyInd, VariantCopy, VariantClear
psapi.dll
GetProcessImageFileNameA
shell32.dll
SHGetFileInfoA, ShellExecuteExW, ShellExecuteW, Shell_NotifyIconW, SHGetSpecialFolderLocation, SHGetPathFromIDListW
user32.dll
LoadStringW, MessageBoxA, CharNextW, DllMain
version.dll
VerQueryValueA, VerQueryValueW, GetFileVersionInfoSizeA, GetFileVersionInfoSizeW, GetFileVersionInfoA, GetFileVersionInfoW
winmm.dll
timeGetTime, timeEndPeriod, sndPlaySoundW

ui5guard.exe

By Ashampoo GmbH & Co. KG (Signed)

Remove ui5guard.exe
MD5:   ba772b5c0c40acd82dc59f5c1cda37ae
SHA1:   a3dad447a449cd97d2f3cc6ed97f677d6fed7c6e
SHA256:   ea88bff862307a5349bb771025fa89710d35fcdc56efb45e62947ba704034da4

Overview

ui5guard.exe executes as a process with the local user's privileges. It is set to be start when the PC boots and any user logs into Windows (added to the Run registry key for the all users under the local machine). It is installed with a couple of know programs including Ashampoo UnInstaller 5 v.5.0.2 published by Ashampoo GmbH & Co. KG, Ashampoo UnInstaller 5 v.5.00 from Ashampoo GmbH & Co. KG and Ashampoo UnInstaller 5 v.5.00 by Ashampoo GmbH & Co. KG. The file is digitally signed by Ashampoo GmbH & Co. KG which was issued by the VeriSign certificate authority (CA). Note, some antivirus scanners have flagged this file, however it is not necessarily considered malware (see below for details).

DetailsDetails

File name:ui5guard.exe
Typical file path:C:\Program Files\ashampoo\ashampoo uninstaller 5\ui5guard.exe
Size:2.24 MB (2,345,896 bytes)
Certificate
Issued to:Ashampoo GmbH & Co. KG
Authority (CA):VeriSign
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
Ashampoo GmbH & Co. KG
23% remove
Ashampoo UnInstaller is an uninstall utility designed to remove other software or parts of it from a computer.

BehaviorsBehaviors

Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'Ashampoo Uninstaller 5 Guard' → "C:\Program Files\Ashampoo\Ashampoo UnInstaller 5\UI5Guard.exe" -TRAY

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.04664021%
0.028634%
Kernel CPU:0.01813478%
0.013761%
User CPU:0.02850543%
0.014873%
Kernel CPU time:343 ms/min
100,923,805ms/min
Memory
Private memory:8.27 MB
21.59 MB
Private (maximum):2.13 MB
Private (minimum):848 KB
Non-paged memory:8.27 MB
21.59 MB
Virtual memory:89.9 MB
140.96 MB
Virtual memory (peak):96.17 MB
169.69 MB
Working set:2.13 MB
18.61 MB
Working set (peak):20.11 MB
37.95 MB
Resource allocations
Threads:13
12
Handles:132
600
GUI GDI count:68
103
GUI GDI peak:75
142
GUI USER count:34
49
GUI USER peak:35
71

BehaviorsProcess properties

Integrety level:High
Platform:32-bit
Command line:"C:\Program Files\ashampoo\ashampoo uninstaller 5\ui5guard.exe"
Owner:User

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 8 Pro 50.00%
Windows 7 Ultimate 50.00%

Distribution by countryDistribution by country

United States installs about 50.00% of ui5guard.exe.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Hewlett-Packard 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE