Should I block it?

No, this file is 100% safe to run.

Relationships

Child processes
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
CreateProcessAsUserW, GetLengthSid, DuplicateTokenEx, EqualSid, RegSetValueExW, SetTokenInformation, RegQueryInfoKeyW, RegQueryValueExW, GetUserNameW, OpenProcessToken, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, ControlService, ReportEventW, UnlockServiceDatabase, QueryServiceStatusEx, SetServiceStatus, ChangeServiceConfigW, QueryServiceStatus, StartServiceW, ChangeServiceConfig2W, LockServiceDatabase, DeregisterEventSource, RegisterServiceCtrlHandlerExW, OpenServiceW, StartServiceCtrlDispatcherW, OpenSCManagerW, DeleteService, CloseServiceHandle, RegisterEventSourceW, CreateServiceW, RegCreateKeyExW, RegCloseKey, RegOpenKeyExW, RevertToSelf, ImpersonateLoggedOnUser
dbghelp.dll
MiniDumpWriteDump
icommu.dll
ICOM_0002, ICOM_1002, ICOM_0001, ICOM_1004, ICOM_0003, ICOM_0005
kernel32.dll
GetPrivateProfileSectionNamesW, GetPrivateProfileStringW, GetPrivateProfileIntW, GlobalMemoryStatusEx, GetDiskFreeSpaceExW, SetUnhandledExceptionFilter, CreateFileW, GetLocalTime, GetCurrentThreadId, GetCurrentProcessId, GetFileSize, SetFilePointer, SetEndOfFile, CreateDirectoryW, WriteFile, ReadFile, SetFileAttributesW, GlobalAlloc, DeviceIoControl, GetVolumeInformationW, GetEnvironmentVariableW, FindFirstFileW, GetCurrentThread, GetFileAttributesW, FlushFileBuffers, FindClose, FindNextFileW, GetQueuedCompletionStatus, RaiseException, InterlockedExchange, ResetEvent, PostQueuedCompletionStatus, CreateIoCompletionPort, MapViewOfFile, UnmapViewOfFile, SystemTimeToFileTime, FileTimeToSystemTime, CreateFileMappingW, CreateProcessW, lstrcmpiW, GetLogicalDriveStringsW, HeapFree, GetProcessHeap, LoadLibraryA, QueryDosDeviceW, InterlockedIncrement, InterlockedDecrement, TlsAlloc, TlsFree, QueryPerformanceCounter, IsProcessorFeaturePresent, IsDebuggerPresent, DecodePointer, EncodePointer, HeapSize, HeapReAlloc, HeapDestroy, FormatMessageA, GetSystemTimeAsFileTime, GetCurrentProcess, GetSystemWindowsDirectoryW, WaitForSingleObject, GetTickCount, InitializeCriticalSection, GetSystemDirectoryW, LoadLibraryW, InitializeCriticalSectionAndSpinCount, LeaveCriticalSection, GetModuleFileNameW, GetSystemInfo, GetVersionExW, WideCharToMultiByte, GetSystemDefaultLangID, LocalAlloc, ProcessIdToSessionId, TerminateProcess, OpenProcess, GetProcessTimes, GetModuleHandleW, FreeLibrary, LocalFree, SetConsoleCtrlHandler, GetCommandLineW, DeleteFileW, GetExitCodeProcess, GlobalFree, GetLastError, MultiByteToWideChar, ResumeThread, GetExitCodeThread, CreateThread, CreateEventW, TerminateThread, SetPriorityClass, Sleep, SetEvent, CloseHandle, DeleteCriticalSection, GetFileAttributesExW, WaitForMultipleObjects, EnterCriticalSection, GetProcAddress, HeapAlloc
msvcp110.dll
DllMain
msvcr110.dll
DllMain
psapi.dll
GetModuleFileNameExW, EnumProcessModules, EnumProcesses
sensapi.dll
IsNetworkAlive
shell32.dll
SHGetFolderPathW, CommandLineToArgvW
shlwapi.dll
SHDeleteKeyW, PathFindFileNameW, PathFindFileNameA, PathFileExistsW, PathAppendW
user32.dll
GetDesktopWindow, CloseDesktop, CloseWindowStation, GetSystemMetrics, wsprintfW, EnumDisplaySettingsW
winhttp.dll
WinHttpOpen, WinHttpOpenRequest, WinHttpGetProxyForUrl, WinHttpQueryDataAvailable, WinHttpReadData, WinHttpAddRequestHeaders, WinHttpQueryHeaders, WinHttpCloseHandle, WinHttpCrackUrl, WinHttpConnect, WinHttpReceiveResponse, WinHttpSetTimeouts, WinHttpGetIEProxyConfigForCurrentUser, WinHttpSendRequest, WinHttpWriteData, WinHttpSetOption
wininet.dll
InternetCheckConnectionW

iSafeSvc.exe

iSafe Security Protection by WOODTALE TECHNOLOGY INC (Signed)

Remove iSafeSvc.exe
Version:   2.7.25.3163
MD5:   074244d67b15d732d957d431388dbca8
SHA1:   04ccf42ee0e5d43763b8fdc95f1495814f29d0be
SHA256:   d77cee8ef758d73ff6a9e8424d0633a6971f809176dc82f407b2dc0097c2bb8a

Overview

isafesvc.exe runs as a service under the name iSafeService with extensive SYSTEM privileges (full administrator access). This is typically installed with the program iSafe published by Woodtale Technology Inc and is most likely removed by most users once installed (58% removed). The file is digitally signed by WOODTALE TECHNOLOGY INC which was issued by the WoSign eCommerce Services Limited certificate authority (CA). This particular version is usually found on Microsoft Windows XP (5.1.2600.196608).

DetailsDetails

File name:isafesvc.exe
Publisher:Woodtale Technology Inc
Product name: iSafe Security Protection
Description:iSafeSvc
Typical file path:C:\Program Files\isafe\isafesvc.exe
File version:2.7.25.3163
Size:343.32 KB (351,560 bytes)
Build date:8/15/2013 7:39 AM
Certificate
Issued to:WOODTALE TECHNOLOGY INC
Authority (CA):WoSign eCommerce Services Limited
Effective date:Wednesday, July 11, 2012
Expiration date:Thursday, July 16, 2015
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
Woodtale Technology Inc
  58% remove
iSafe is a re-branded version of the YAC (Yet Another PC Cleaner) software from Elex do Brasil Participações Ltda.

BehaviorsBehaviors

Service
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'iSafeService'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00376260%
0.028634%
Kernel CPU:0.00237738%
0.013761%
User CPU:0.00138522%
0.014873%
Kernel CPU time:750 ms/min
100,923,805ms/min
Memory
Private memory:7.11 MB
21.59 MB
Private (maximum):2 MB
Private (minimum):612 KB
Non-paged memory:7.11 MB
21.59 MB
Virtual memory:53.93 MB
140.96 MB
Virtual memory (peak):57.93 MB
169.69 MB
Working set:1.2 MB
18.61 MB
Working set (peak):6.96 MB
37.95 MB
Page faults:86,035/min
2,039/min
I/O
I/O read transfer:836 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O write transfer:153 Bytes/sec
274.99 KB/min
I/O write operations:1/sec
227/min
I/O other transfer:792 Bytes/sec
448.09 KB/min
I/O other operations:12/sec
1,671/min
Resource allocations
Threads:17
12
Handles:239
600
GUI GDI count:4
103
GUI USER count:5
49

BehaviorsProcess properties

Integrety level:Undefined
Platform:32-bit
Command line:"C:\Program Files\isafe\isafesvc.exe"
Owner:SYSTEM
Windows Service
Service name:iSafeService
Description:“iSafe Service”
Type:Win32OwnProcess
Parent process:services.exe (Services and Controller app by Microsoft)

ResourcesThreads

Averages
 
MSVCR110.dll
Total CPU:0.00051154%
0.272967%
Kernel CPU:0.00028052%
0.107585%
User CPU:0.00023102%
0.165382%
Memory:856 KB
1.16 MB
iSafeSvc.exe (main module)
Total CPU:0.00039603%
Kernel CPU:0.00032178%
User CPU:0.00007426%
Memory:360 KB
icommu.dll (iSafe Security Protection by Woodtale Technology Inc)
Total CPU:0.00004950%
Kernel CPU:0.00004950%
User CPU:0.00000000%
Memory:60 KB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE