Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

Version 9.5.0.0 50.00%
Version 9.5.0.0 50.00%
(Note, Total Defense publishes each variation of this file with the same version, but the hashes are unique.)

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegDeleteKeyW, RegSetValueExA, SetServiceStatus, RegisterServiceCtrlHandlerA, StartServiceCtrlDispatcherA, FreeSid, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, AllocateAndInitializeSid, RegCloseKey, RegQueryValueExA, RegOpenKeyExA, RegOpenKeyExW, RegCreateKeyExW, RegSetValueExW, RegQueryValueExW, RegDeleteValueW, RegEnumValueW, RegQueryInfoKeyW, RegEnumKeyExW, RegNotifyChangeKeyValue
kernel32.dll
CreateMutexA, lstrcpyA, GetVersionExA, WaitForSingleObject, GetLastError, CloseHandle, SetEvent, OpenEventA, ReleaseMutex, GetCurrentProcessId, GetProcAddress, GetModuleHandleA, FreeLibrary, LoadLibraryA, lstrcatA, lstrlenA, GetCurrentProcess, LocalFree, LocalAlloc, CreateEventA, InterlockedIncrement, InterlockedDecrement, GetVersionExW, WideCharToMultiByte, MultiByteToWideChar, lstrcpyW, CreateDirectoryW, GetDateFormatW, GetTimeFormatW, SetFileAttributesW, GetTickCount, SystemTimeToTzSpecificLocalTime, CreateFileA, ReadFile, SetFilePointer, WriteFile, GetFileSize, SetEndOfFile, CreateFileW, GetFileAttributesW, GetModuleFileNameW, GetModuleHandleW, InterlockedCompareExchange, InterlockedExchange, Sleep, InitializeCriticalSection, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, RtlUnwind, RaiseException, GetCommandLineA, HeapFree, HeapAlloc, GetProcessHeap, GetStartupInfoA, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, ExitProcess, LCMapStringA, LCMapStringW, GetCPInfo, GetStringTypeA, GetStringTypeW, GetStdHandle, GetModuleFileNameA, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, SetLastError, GetCurrentThreadId, GetACP, GetOEMCP, IsValidCodePage, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, SetHandleCount, GetFileType, HeapDestroy, HeapCreate, VirtualFree, QueryPerformanceCounter, GetSystemTimeAsFileTime, VirtualAlloc, HeapReAlloc, HeapSize, GetLocaleInfoA, GetUserDefaultLCID, EnumSystemLocalesA, IsValidLocale, GetLocaleInfoW, GetConsoleCP, GetConsoleMode, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, FlushFileBuffers, GetSystemTime, WaitForMultipleObjects
rpcrt4.dll
RpcStringFreeW, UuidToStringW, RpcStringFreeA, UuidToStringA, UuidCreate
user32.dll
MessageBoxA

ISafe.exe

Computer Associates Antivirus by Total Defense (Signed)

Remove ISafe.exe
Version:   Version 9.5.0.0
MD5:   1176477577cd293b4465de2acf4da12b
SHA1:   13b1695b1e34e2f99e610aa9859553231850cf1e

Overview

isafe.exe runs as a service under the name CAISafe with extensive SYSTEM privileges (full administrator access). The file is digitally signed by Total Defense which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:isafe.exe
Publisher:Computer Associates International, Inc.
Product name:Computer Associates Antivirus
Description:CA ISafe Service
Typical file path:C:\Program Files\total defense\internet security suite\anti-virus\isafe.exe
File version:Version 9.5.0.0
Size:219.08 KB (224,336 bytes)
Certificate
Issued to:Total Defense
Authority (CA):VeriSign
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Service
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'CAISafe'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00023692%
0.028634%
Kernel CPU:0.00023692%
0.013761%
Kernel CPU time:125 ms/min
100,923,805ms/min
Memory
Private memory:3.2 MB
21.59 MB
Private (maximum):6.77 MB
Private (minimum):132 KB
Non-paged memory:3.2 MB
21.59 MB
Virtual memory:64.57 MB
140.96 MB
Virtual memory (peak):67.57 MB
169.69 MB
Working set:356 KB
18.61 MB
Working set (peak):6.79 MB
37.95 MB
Resource allocations
Threads:8
12
Handles:135
600

BehaviorsProcess properties

Integrety level:System
Platform:32-bit
Command line:"C:\Program Files\total defense\internet security suite\anti-virus\isafe.exe"
Owner:SYSTEM
Windows Service
Service name:CAISafe
Type:Win32OwnProcess, InteractiveProcess
Parent process:services.exe (Services and Controller app by Microsoft)

ResourcesThreads

Averages
 
sechost.dll
Total CPU:0.00014783%
0.272967%
Kernel CPU:0.00014783%
0.107585%
User CPU:0.00000000%
0.165382%
CPU cycles:2,860/sec
5,741,424/sec
Memory:100 KB
1.16 MB
isafe.exe (main module)
Total CPU:0.00005913%
Kernel CPU:0.00005913%
User CPU:0.00000000%
CPU cycles:995/sec
Memory:220 KB
isafeif.dll (Computer Associates Antivirus by Computer Associates International)
Total CPU:0.00002957%
Kernel CPU:0.00002957%
User CPU:0.00000000%
CPU cycles:358/sec
Memory:124 KB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 50.00%
Windows 7 Ultimate 50.00%

Distribution by countryDistribution by country

United States installs about 100.00% of Computer Associates Antivirus .

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Sony 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE