Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

Version 9.5.0.0 50.00%
Version 9.5.0.0 50.00%
(Note, Total Defense publishes each variation of this file with the same version, but the hashes are unique.)

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegDeleteKeyW, RegSetValueExA, SetServiceStatus, RegisterServiceCtrlHandlerA, StartServiceCtrlDispatcherA, FreeSid, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, AllocateAndInitializeSid, RegCloseKey, RegQueryValueExA, RegOpenKeyExA, RegOpenKeyExW, RegCreateKeyExW, RegSetValueExW, RegQueryValueExW, RegDeleteValueW, RegEnumValueW, RegQueryInfoKeyW, RegEnumKeyExW, RegNotifyChangeKeyValue
kernel32.dll
CreateMutexA, lstrcpyA, GetVersionExA, WaitForSingleObject, GetLastError, CloseHandle, SetEvent, OpenEventA, ReleaseMutex, GetCurrentProcessId, GetProcAddress, GetModuleHandleA, FreeLibrary, LoadLibraryA, lstrcatA, lstrlenA, GetCurrentProcess, LocalFree, LocalAlloc, CreateEventA, InterlockedIncrement, InterlockedDecrement, GetVersionExW, WideCharToMultiByte, MultiByteToWideChar, lstrcpyW, CreateDirectoryW, GetDateFormatW, GetTimeFormatW, SetFileAttributesW, GetTickCount, SystemTimeToTzSpecificLocalTime, CreateFileA, ReadFile, SetFilePointer, WriteFile, GetFileSize, SetEndOfFile, CreateFileW, GetFileAttributesW, GetModuleFileNameW, GetModuleHandleW, InterlockedCompareExchange, InterlockedExchange, Sleep, InitializeCriticalSection, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, RtlUnwind, RaiseException, GetCommandLineA, HeapFree, HeapAlloc, GetProcessHeap, GetStartupInfoA, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, ExitProcess, LCMapStringA, LCMapStringW, GetCPInfo, GetStringTypeA, GetStringTypeW, GetStdHandle, GetModuleFileNameA, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, SetLastError, GetCurrentThreadId, GetACP, GetOEMCP, IsValidCodePage, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, SetHandleCount, GetFileType, HeapDestroy, HeapCreate, VirtualFree, QueryPerformanceCounter, GetSystemTimeAsFileTime, VirtualAlloc, HeapReAlloc, HeapSize, GetLocaleInfoA, GetUserDefaultLCID, EnumSystemLocalesA, IsValidLocale, GetLocaleInfoW, GetConsoleCP, GetConsoleMode, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, FlushFileBuffers, GetSystemTime, WaitForMultipleObjects
rpcrt4.dll
RpcStringFreeW, UuidToStringW, RpcStringFreeA, UuidToStringA, UuidCreate
user32.dll
MessageBoxA

ISafe.exe

Computer Associates Antivirus by Total Defense (Signed)

Remove ISafe.exe
Version:   Version 9.5.0.0
MD5:   eae7ba27bbd8cc4e0319f29777a23ec2
SHA1:   95b7cbc2f4afa55577620ee0f743cf7d181b1d09
SHA256:   77330b19eb5a70c7007653f224b20d96ffafaedf772a4320c40b27551b00952f

Overview

isafe.exe runs as a service under the name CAISafe with extensive SYSTEM privileges (full administrator access). The file is digitally signed by Total Defense which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:isafe.exe
Publisher:Computer Associates International, Inc.
Product name:Computer Associates Antivirus
Description:CA ISafe Service
Typical file path:C:\Program Files\total defense\internet security suite\anti-virus\isafe.exe
File version:Version 9.5.0.0
Size:307.08 KB (314,448 bytes)
Build date:8/17/2012 10:25 PM
Certificate
Issued to:Total Defense
Authority (CA):VeriSign
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Service
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'CAISafe'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00000465%
0.028634%
Kernel CPU:0.00000465%
0.013761%
Kernel CPU time:31 ms/min
100,923,805ms/min
Memory
Private memory:4.74 MB
21.59 MB
Private (maximum):1.85 MB
Private (minimum):400 KB
Non-paged memory:4.74 MB
21.59 MB
Virtual memory:90.17 MB
140.96 MB
Virtual memory (peak):92.17 MB
169.69 MB
Working set:1.71 MB
18.61 MB
Working set (peak):9.15 MB
37.95 MB
Page faults:3,007/min
2,039/min
Resource allocations
Threads:8
12
Handles:145
600

BehaviorsProcess properties

Integrety level:Undefined
Platform:64-bit
Command line:"C:\Program Files\total defense\internet security suite\anti-virus\isafe.exe"
Owner:SYSTEM
Windows Service
Service name:CAISafe
Type:Win32OwnProcess, InteractiveProcess
Parent process:services.exe (Services and Controller app by Microsoft)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 50.00%
Windows 7 Ultimate 50.00%

Distribution by countryDistribution by country

United States installs about 100.00% of Computer Associates Antivirus .

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Sony 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE