Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

2, 70, 39 25.00%
2, 70, 32 25.00%
2, 70, 16 25.00%
2, 51, 20 25.00%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
GetKernelObjectSecurity, SetKernelObjectSecurity, GetSecurityDescriptorDacl, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, IsValidSid, GetSidIdentifierAuthority, GetSidSubAuthorityCount, GetSidSubAuthority, AllocateAndInitializeSid, EqualSid, FreeSid, RegOpenKeyA, RegQueryValueExA, DuplicateToken, SetThreadToken, RegDeleteValueW, RegDeleteKeyW, RegEnumValueW, RegCreateKeyExW, ControlService, QueryServiceStatus, DeleteService, StartServiceCtrlDispatcherW, CreateServiceW, RegisterServiceCtrlHandlerW, SetServiceStatus, OpenSCManagerW, OpenServiceW, CloseServiceHandle, StartServiceW, DuplicateTokenEx, CreateProcessAsUserW, OpenThreadToken, OpenProcessToken, GetTokenInformation, LookupAccountSidW, RegOpenKeyExW, RegQueryValueExW, RegSetValueExW, RegQueryInfoKeyW, RegEnumKeyExW, RevertToSelf, RegEnumKeyW, RegCloseKey, LookupPrivilegeValueW
kernel32.dll
GetDriveTypeW, DeviceIoControl, GetLogicalDrives, MoveFileW, DeleteFileW, GetTempFileNameW, GetModuleFileNameW, Sleep, GetVersionExA, GetTimeFormatA, GetDateFormatA, GetModuleHandleW, SetFileAttributesW, CreateDirectoryW, CopyFileW, WritePrivateProfileSectionW, GetPrivateProfileSectionW, MoveFileExW, GetFileAttributesW, GetACP, GetComputerNameA, SetEndOfFile, SetLastError, QueryDosDeviceW, HeapFree, HeapAlloc, GetProcessHeap, GetCurrentProcess, GetLocaleInfoW, GetModuleHandleA, LocalFree, lstrlenA, lstrcmpA, LocalAlloc, lstrlenW, FlushFileBuffers, GetFileTime, GetTempPathW, ReadProcessMemory, UnmapViewOfFile, CreateMutexW, ReleaseMutex, VirtualAlloc, MapViewOfFile, CreateFileMappingW, OpenFileMappingW, DuplicateHandle, OpenMutexW, SetThreadPriority, MultiByteToWideChar, InterlockedExchange, VirtualFree, WritePrivateProfileStringW, GetPrivateProfileStringW, WideCharToMultiByte, GetDiskFreeSpaceW, CompareStringW, CompareStringA, LoadLibraryA, GetOEMCP, GetExitCodeProcess, CreateFileA, SetStdHandle, GetStringTypeW, GetStringTypeA, GetCPInfo, IsBadCodePtr, IsBadReadPtr, SetUnhandledExceptionFilter, GetFileType, GetStdHandle, GetWindowsDirectoryW, FileTimeToLocalFileTime, FileTimeToSystemTime, GetVersion, GetLocaleInfoA, WaitForMultipleObjects, GetShortPathNameW, CreateProcessW, GetSystemTime, SystemTimeToFileTime, GetLocalTime, CreateThread, GetCurrentThread, OpenProcess, GetVersionExW, GlobalMemoryStatus, FindFirstFileW, FindNextFileW, CompareFileTime, FindClose, GetComputerNameW, GetDateFormatW, GetTimeFormatW, ExpandEnvironmentStringsW, SetFilePointer, GetSystemTimeAsFileTime, WriteFile, CreateFileW, GetFileSize, ReadFile, InterlockedIncrement, InterlockedDecrement, WaitForSingleObject, EnterCriticalSection, TerminateThread, LeaveCriticalSection, CloseHandle, DeleteCriticalSection, InitializeCriticalSection, CreateEventW, GetTickCount, SetEvent, GetTimeZoneInformation, GetCurrentThreadId, GetCurrentProcessId, LoadLibraryW, GetLastError, GetProcAddress, FreeLibrary, RtlUnwind, ResetEvent, SetEnvironmentVariableA, SetHandleCount, GetEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsW, FreeEnvironmentStringsA, UnhandledExceptionFilter, LCMapStringW, LCMapStringA, HeapSize, TerminateProcess, IsBadWritePtr, HeapCreate, HeapDestroy, GetEnvironmentVariableA, GetModuleFileNameA, TlsGetValue, GetStartupInfoA, TlsAlloc, TlsSetValue, ExitProcess, GetCommandLineA, HeapReAlloc, OpenEventW
mpr.dll
WNetGetUserW
netapi32.dll
NetMessageBufferSend
ole32.dll
CoCreateInstance, CoUninitialize, CoInitialize
user32.dll
LoadStringW, PostMessageW, DispatchMessageW, TranslateMessage, GetMessageW, SetTimer, DefWindowProcW, KillTimer, CreateWindowExW, RegisterClassW, SendMessageW, PeekMessageW, MsgWaitForMultipleObjects, wsprintfW

nod32krn.exe

NOD32 Antivirus System by ESET (Signed)

Remove nod32krn.exe
Version:   2, 70, 16
MD5:   c0c81a2be22f496b26b3e1ef3f559b83
SHA1:   4daac65bde70ef69d429a9a9501263eaead8a0ac
SHA256:   b6985465ab9eb9e9588595f8f9983f50402df4060259c70d038a25c1111eb9cf

What is nod32krn.exe?

NOD32 Kernel Service is part of ESET NOD32 Antivirus System, an antivirus software program from ESET. ESET's use of assembly language in its products contributes to their low system requirements and disk space utilization. ESET calls its scanning engine ThreatSense, and makes extensive use of generic signatures and heuristics.

About nod32krn.exe (from ESET)

ESET NOD32 Antivirus System offers advanced detection technologies and multi-layered security features, along with Cybersecurity training. ESET NOD32 Antivirus System is built on ESET's unique heurist

DetailsDetails

File name:nod32krn.exe
Publisher:Eset
Product name:NOD32 Antivirus System
Description:NOD32 Kernel Service
Typical file path:C:\Program Files\eset\nod32krn.exe
File version:2, 70, 16
Size:536.38 KB (549,256 bytes)
Build date:11/16/2006 7:01 PM
Certificate
Issued to:ESET
Authority (CA):VeriSign
Effective date:Thursday, June 8, 2006
Expiration date:Saturday, June 9, 2007
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'NOD32krn' (NOD32 Kernel Service)
  • NOD32krn

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00717011%
0.028634%
Kernel CPU:0.00248376%
0.013761%
User CPU:0.00468634%
0.014873%
Kernel CPU time:7,266 ms/min
100,923,805ms/min
Context switches:10/sec
284/sec
Memory
Private memory:18.71 MB
21.59 MB
Private (maximum):38.04 MB
Private (minimum):19.3 MB
Non-paged memory:18.71 MB
21.59 MB
Virtual memory:72.45 MB
140.96 MB
Virtual memory (peak):104.46 MB
169.69 MB
Working set:21.33 MB
18.61 MB
Working set (peak):42.9 MB
37.95 MB
Resource allocations
Threads:15
12
Handles:200
600
GUI GDI count:15
103
GUI USER count:2
49

BehaviorsProcess properties

Integrety level:Undefined
Platform:32-bit
Command line:"C:\Program Files\eset\nod32krn.exe"
Owner:SYSTEM
Windows Service
Service name:NOD32krn
Display name:NOD32 Kernel Service
Type:Win32OwnProcess
Parent process:services.exe (Services and Controller app by Microsoft)

ResourcesThreads

Averages
 
ps_amon.dll (NOD32 Antivirus System by Eset)
Total CPU:0.00350097%
0.272967%
Kernel CPU:0.00153167%
0.107585%
User CPU:0.00196929%
0.165382%
Context switches:4/sec
79/sec
Memory:248 KB
1.16 MB
nod32krn.exe (main module)
Total CPU:0.00014590%
Kernel CPU:0.00014590%
User CPU:0.00000000%
Memory:544 KB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 75.00%
Windows 7 Ultimate 25.00%

Distribution by countryDistribution by country

Malaysia installs about 25.00% of NOD32 Antivirus System.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
GIGABYTE 33.33%
American Megatrends 33.33%
Hewlett-Packard 33.33%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE