Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

2, 0, 0, 60 50.00%
2, 0, 0, 60 50.00%
(Note, CA publishes each variation of this file with the same version, but the hashes are unique.)

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
RegQueryValueExW, GetUserNameW, RegQueryInfoKeyW, RegEnumKeyExW, RegDeleteKeyW, RegEnumValueW, RegOpenKeyExW, RegSetValueExW, RegDeleteValueW, RegCloseKey, RegCreateKeyExW
comdlg32.dll
GetFileTitleW
kernel32.dll
LoadLibraryExW, GetProcAddress, CreateFileW, InterlockedIncrement, TlsAlloc, TlsSetValue, TlsGetValue, GetTickCount, lstrcmpA, SetFilePointer, FreeLibrary, GetFileSize, LocalAlloc, lstrlenW, GetVersionExW, GetCurrentProcess, GetCurrentThreadId, DeleteCriticalSection, InitializeCriticalSection, ReleaseMutex, CreateMutexW, InterlockedCompareExchange, EnterCriticalSection, LeaveCriticalSection, InterlockedDecrement, CloseHandle, WaitForSingleObject, GetLastError, LocalFree, ReadFile, FormatMessageW, SetEnvironmentVariableA, WriteConsoleW, GetConsoleOutputCP, WriteConsoleA, GetProcessHeap, DeleteFileW, SetCurrentDirectoryW, GetFullPathNameW, GetShortPathNameW, FindFirstFileW, GetCurrentDirectoryW, GetModuleFileNameW, GetSystemDirectoryW, GetWindowsDirectoryW, GetTempPathW, GetTimeFormatW, GetDateFormatW, GetLocaleInfoW, OutputDebugStringA, OutputDebugStringW, MoveFileW, WriteFile, FlushFileBuffers, GetThreadTimes, GetCurrentThread, GetFileAttributesW, GetFileAttributesExW, FileTimeToSystemTime, FileTimeToLocalFileTime, SystemTimeToFileTime, GetSystemTimeAsFileTime, GetLocalTime, GetSystemTime, LocalFileTimeToFileTime, InterlockedExchange, MultiByteToWideChar, WideCharToMultiByte, GetLocaleInfoA, Sleep, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, HeapFree, GetCommandLineA, RtlUnwind, SetCurrentDirectoryA, GetFileInformationByHandle, PeekNamedPipe, GetFileType, RaiseException, GetTimeFormatA, GetDateFormatA, GetCPInfo, LCMapStringA, LCMapStringW, GetStringTypeW, CompareStringA, CompareStringW, HeapAlloc, GetStdHandle, GetModuleFileNameA, GetModuleHandleW, TlsFree, SetLastError, HeapCreate, HeapDestroy, VirtualFree, VirtualAlloc, HeapReAlloc, HeapSize, ExitProcess, GetACP, GetOEMCP, IsValidCodePage, SetHandleCount, GetStartupInfoA, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, QueryPerformanceCounter, GetCurrentProcessId, SetStdHandle, CreateFileA, GetTimeZoneInformation, GetModuleHandleA, GetUserDefaultLCID, EnumSystemLocalesA, IsValidLocale, GetStringTypeA, LoadLibraryA, InitializeCriticalSectionAndSpinCount, GetConsoleCP, GetConsoleMode, SetEndOfFile
shfolder.dll
SHGetFolderPathW
version.dll
GetFileVersionInfoSizeW, VerQueryValueW, GetFileVersionInfoW
Export table
Create_KnownAppDbPaths
Create_KnownAppList

knownapps.dll

Threat Management Engine by CA (Signed)

Remove knownapps.dll
Version:   2, 0, 0, 60
MD5:   f5cc2b37668026e815d30d1bbec74bb1
SHA1:   667eea43071e05796b0993106c6a766a2e7ee60e

Overview

knownapps.dll is loaded as dynamic link library that runs in the context of a process. The file is digitally signed by CA which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:knownapps.dll
Product name:Threat Management Engine
Description:KnownApps
Typical file path:C:\Program Files\ca\sharedcomponents\tmengine\knownapps.dll
Original name:Copyright CA (C) 2009
File version:2, 0, 0, 60
Product version:2, 0, 0, 1
Size:1017.08 KB (1,041,488 bytes)
Build date:1/28/2011 9:11 AM
Certificate
Issued to:CA
Authority (CA):VeriSign
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 50.00%
Windows 7 Ultimate 50.00%

Distribution by countryDistribution by country

United States installs about 100.00% of Threat Management Engine.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Sony 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE