Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

2, 70, 39 25.00%
2, 70, 32 25.00%
2, 70, 16 25.00%
2, 51, 20 25.00%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
GetKernelObjectSecurity, SetKernelObjectSecurity, GetSecurityDescriptorDacl, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, IsValidSid, GetSidIdentifierAuthority, GetSidSubAuthorityCount, GetSidSubAuthority, AllocateAndInitializeSid, EqualSid, FreeSid, RegOpenKeyA, RegQueryValueExA, DuplicateToken, SetThreadToken, RegDeleteValueW, RegDeleteKeyW, RegEnumValueW, RegCreateKeyExW, ControlService, QueryServiceStatus, DeleteService, StartServiceCtrlDispatcherW, CreateServiceW, RegisterServiceCtrlHandlerW, SetServiceStatus, OpenSCManagerW, OpenServiceW, CloseServiceHandle, StartServiceW, DuplicateTokenEx, CreateProcessAsUserW, OpenThreadToken, OpenProcessToken, GetTokenInformation, LookupAccountSidW, RegOpenKeyExW, RegQueryValueExW, RegSetValueExW, RegQueryInfoKeyW, RegEnumKeyExW, RevertToSelf, RegEnumKeyW, RegCloseKey, LookupPrivilegeValueW
kernel32.dll
GetDriveTypeW, DeviceIoControl, GetLogicalDrives, MoveFileW, DeleteFileW, GetTempFileNameW, GetModuleFileNameW, Sleep, GetVersionExA, GetTimeFormatA, GetDateFormatA, GetModuleHandleW, SetFileAttributesW, CreateDirectoryW, CopyFileW, WritePrivateProfileSectionW, GetPrivateProfileSectionW, MoveFileExW, GetFileAttributesW, GetACP, GetComputerNameA, SetEndOfFile, SetLastError, QueryDosDeviceW, HeapFree, HeapAlloc, GetProcessHeap, GetCurrentProcess, GetLocaleInfoW, GetModuleHandleA, LocalFree, lstrlenA, lstrcmpA, LocalAlloc, lstrlenW, FlushFileBuffers, GetFileTime, GetTempPathW, ReadProcessMemory, UnmapViewOfFile, CreateMutexW, ReleaseMutex, VirtualAlloc, MapViewOfFile, CreateFileMappingW, OpenFileMappingW, DuplicateHandle, OpenMutexW, SetThreadPriority, MultiByteToWideChar, InterlockedExchange, VirtualFree, WritePrivateProfileStringW, GetPrivateProfileStringW, WideCharToMultiByte, GetDiskFreeSpaceW, CompareStringW, CompareStringA, LoadLibraryA, GetOEMCP, GetExitCodeProcess, CreateFileA, SetStdHandle, GetStringTypeW, GetStringTypeA, GetCPInfo, IsBadCodePtr, IsBadReadPtr, SetUnhandledExceptionFilter, GetFileType, GetStdHandle, GetWindowsDirectoryW, FileTimeToLocalFileTime, FileTimeToSystemTime, GetVersion, GetLocaleInfoA, WaitForMultipleObjects, GetShortPathNameW, CreateProcessW, GetSystemTime, SystemTimeToFileTime, GetLocalTime, CreateThread, GetCurrentThread, OpenProcess, GetVersionExW, GlobalMemoryStatus, FindFirstFileW, FindNextFileW, CompareFileTime, FindClose, GetComputerNameW, GetDateFormatW, GetTimeFormatW, ExpandEnvironmentStringsW, SetFilePointer, GetSystemTimeAsFileTime, WriteFile, CreateFileW, GetFileSize, ReadFile, InterlockedIncrement, InterlockedDecrement, WaitForSingleObject, EnterCriticalSection, TerminateThread, LeaveCriticalSection, CloseHandle, DeleteCriticalSection, InitializeCriticalSection, CreateEventW, GetTickCount, SetEvent, GetTimeZoneInformation, GetCurrentThreadId, GetCurrentProcessId, LoadLibraryW, GetLastError, GetProcAddress, FreeLibrary, RtlUnwind, ResetEvent, SetEnvironmentVariableA, SetHandleCount, GetEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsW, FreeEnvironmentStringsA, UnhandledExceptionFilter, LCMapStringW, LCMapStringA, HeapSize, TerminateProcess, IsBadWritePtr, HeapCreate, HeapDestroy, GetEnvironmentVariableA, GetModuleFileNameA, TlsGetValue, GetStartupInfoA, TlsAlloc, TlsSetValue, ExitProcess, GetCommandLineA, HeapReAlloc, OpenEventW
mpr.dll
WNetGetUserW
netapi32.dll
NetMessageBufferSend
ole32.dll
CoCreateInstance, CoUninitialize, CoInitialize
user32.dll
LoadStringW, PostMessageW, DispatchMessageW, TranslateMessage, GetMessageW, SetTimer, DefWindowProcW, KillTimer, CreateWindowExW, RegisterClassW, SendMessageW, PeekMessageW, MsgWaitForMultipleObjects, wsprintfW

nod32krn.exe

NOD32 Antivirus System by ESET (Signed)

Remove nod32krn.exe
Version:   2, 51, 20
MD5:   4a1036cc19a9226c843895612409148f
SHA1:   b4bfea833691369a520c3e9e9c0ea715a7d8dece

What is nod32krn.exe?

NOD32 Kernel Service is part of ESET NOD32 Antivirus System, an antivirus software program from ESET. ESET's use of assembly language in its products contributes to their low system requirements and disk space utilization. ESET calls its scanning engine ThreatSense, and makes extensive use of generic signatures and heuristics.

About nod32krn.exe (from ESET)

ESET NOD32 Antivirus System offers advanced detection technologies and multi-layered security features, along with Cybersecurity training. ESET NOD32 Antivirus System is built on ESET's unique heurist

DetailsDetails

File name:nod32krn.exe
Publisher:Eset
Product name:NOD32 Antivirus System
Description:NOD32 Kernel Service
Typical file path:C:\Program Files\eset\nod32krn.exe
File version:2, 51, 20
Size:496 KB (507,904 bytes)
Build date:1/11/2006 3:42 PM
Certificate
Issued to:ESET
Authority (CA):VeriSign
Effective date:Thursday, June 8, 2006
Expiration date:Saturday, June 9, 2007
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'NOD32krn' (NOD32 Kernel Service)
  • NOD32krn

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00479821%
0.028634%
Kernel CPU:0.00281736%
0.013761%
User CPU:0.00198085%
0.014873%
Kernel CPU time:4,421,875 ms/min
100,923,805ms/min
Context switches:12/sec
284/sec
Memory
Private memory:23.47 MB
21.59 MB
Private (maximum):26.48 MB
Private (minimum):25.63 MB
Non-paged memory:23.47 MB
21.59 MB
Virtual memory:101.58 MB
140.96 MB
Virtual memory (peak):107.84 MB
169.69 MB
Working set:25.75 MB
18.61 MB
Working set (peak):30.61 MB
37.95 MB
Resource allocations
Threads:17
12
Handles:262
600
GUI GDI count:22
103
GUI USER count:6
49

BehaviorsProcess properties

Integrety level:Undefined
Platform:32-bit
Command line:"C:\Program Files\eset\nod32krn.exe"
Owner:SYSTEM
Windows Service
Service name:NOD32krn
Display name:NOD32 Kernel Service
Type:Win32OwnProcess
Parent process:services.exe (Services and Controller app by Microsoft)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 75.00%
Windows 7 Ultimate 25.00%

Distribution by countryDistribution by country

Malaysia installs about 25.00% of NOD32 Antivirus System.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
GIGABYTE 33.33%
American Megatrends 33.33%
Hewlett-Packard 33.33%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE