Should I block it?

No, this file is 100% safe to run.

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
DuplicateTokenEx, QueryServiceConfigW, ControlService, StartServiceW, OpenSCManagerW, GetSidSubAuthorityCount, GetSidIdentifierAuthority, IsValidSid, SetThreadToken, GetSidSubAuthority, InitializeSid, GetSidLengthRequired, RegEnumKeyExW, RegDeleteValueW, RegEnumValueW, RegEnumKeyW, GetSecurityDescriptorOwner, GetSecurityDescriptorGroup, GetSecurityDescriptorDacl, AccessCheck, SetSecurityDescriptorGroup, SetSecurityDescriptorOwner, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, FreeSid, EqualSid, AllocateAndInitializeSid, OpenProcessToken, RegDeleteKeyW, CopySid, GetLengthSid, GetTokenInformation, RevertToSelf, DuplicateToken, OpenThreadToken
kernel32.dll
WriteFile, SetEndOfFile, GetSystemTimeAsFileTime, VirtualAlloc, VirtualFree, VirtualProtect, GetTickCount, GetVolumeInformationW, WaitForMultipleObjects, DuplicateHandle, ResetEvent, SetThreadPriority, GetModuleFileNameW, LoadLibraryExW, LoadLibraryW, GetProcAddress, FreeLibrary, SuspendThread, SetUnhandledExceptionFilter, VirtualQuery, CreateSemaphoreW, ReleaseSemaphore, GetCurrentThreadId, QueryPerformanceCounter, UnhandledExceptionFilter, TerminateProcess, InterlockedCompareExchange, GetThreadLocale, GetLocaleInfoA, GetACP, InterlockedExchange, GetVersionExA, RaiseException, GetProcessHeap, SetFilePointer, Sleep, lstrcpynW, lstrlenW, GetFullPathNameW, GetFileAttributesW, SetLastError, MultiByteToWideChar, WideCharToMultiByte, LocalFree, LocalAlloc, QueryDosDeviceW, FindResourceExW, GetLastError, SetEvent, GetCurrentThread, GetCurrentProcess, DisableThreadLibraryCalls, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, WaitForSingleObject, TerminateThread, GetCurrentProcessId, InterlockedDecrement, InterlockedIncrement, FindResourceW, SizeofResource, LockResource, LoadResource, GetVersionExW, DeleteCriticalSection, HeapSize, HeapReAlloc, HeapFree, HeapAlloc, HeapDestroy
msvcp80.dll
DllMain
msvcr80.dll
DllMain
setupapi.dll
SetupDiGetDeviceInstanceIdW
shell32.dll
SHGetMalloc, SHGetDesktopFolder
user32.dll
UnregisterClassA, wsprintfW, LoadStringW
Export table
NODIoctl

ekrnDevmon.dll

ESET Endpoint Security by ESET (Signed)

Remove ekrnDevmon.dll
Version:   5.0.2126.0
MD5:   ecae84aa48dcdfc63be8f0328f2c8bb1
SHA1:   72a8d7f222ed759bcf193791c7740bc7150744a8
SHA256:   f662dfc9b0ba0bdbd48ae69d9d9bdb1ba72f5c5f8af054e636daf14eb26b1a56

Overview

ekrndevmon.dll is loaded as dynamic link library that runs in the context of a process. The file is digitally signed by ESET which was issued by the VeriSign certificate authority (CA). This particular version is usually found on Windows 7 Professional (6.1.7601.65536).

DetailsDetails

File name:ekrndevmon.dll
Publisher:ESET
Product name:ESET Endpoint Security
Description:ESET Devmon Service
Typical file path:C:\Program Files\eset\eset endpoint antivirus\ekrndevmon.dll
File version:5.0.2126.0
Size:268.15 KB (274,584 bytes)
Certificate
Issued to:ESET
Authority (CA):VeriSign
Effective date:Saturday, June 5, 2010
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 8.0
.NET CLR:No
More details

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Professional 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE