Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

7.0.302.0 10.29%
6.0.316.0 11.27%
6.0.314.0 0.49%
6.0.308.0 11.27%
6.0.306.0 7.35%
6.0.115.0 RC 2.45%
5.2.7.0 16.67%
5.2.15.0 4.41%
5.0.94.0 4.41%
5.0.93.7 1.47%
5.0.93.0 2.45%
4.2.71.2 4.41%
4.2.67.10 0.49%
4.2.64.12 4.41%
4.2.58.3 0.49%
4.2.42.7 0.49%
4.2.42.0 0.49%
4.0.474.10 0.49%
4.0.474.0 1.47%
4.0.468.0 0.49%
4.0.467.0 0.49%
4.0.437.0 0.49%
4.0.417 6.86%
4.0.314 1.47%
3.0.710 0.49%
View more

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
DuplicateToken, RegEnumKeyW, DuplicateTokenEx, GetTokenInformation, OpenThreadToken, StartServiceW, RegQueryInfoKeyW, RegEnumKeyExW, OpenSCManagerW, RevertToSelf, RegOpenKeyW, ControlService, OpenProcessToken, CreateProcessAsUserW, SetServiceStatus, RegisterServiceCtrlHandlerW, CreateServiceW, StartServiceCtrlDispatcherW, QueryServiceStatus, DeleteService, RegDeleteKeyW, AllocateAndInitializeSid, EqualSid, FreeSid, RegEnumValueW, RegDeleteValueW, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, GetSecurityDescriptorDacl, GetKernelObjectSecurity, SetKernelObjectSecurity, RegOpenKeyA, RegUnLoadKeyW, RegLoadKeyW, LookupPrivilegeValueW, AdjustTokenPrivileges, LookupAccountNameW, GetSidSubAuthority, IsValidSid, GetSidIdentifierAuthority, GetSidSubAuthorityCount, SetThreadToken, RegOpenKeyExW, CloseServiceHandle, OpenServiceW, RegCloseKey, LookupAccountSidW, RegQueryValueExW, RegCreateKeyExW, RegSetValueExW, RegQueryValueExA, RegDeleteKeyA, GetNamedSecurityInfoW, SetNamedSecurityInfoW, LogonUserW, LsaNtStatusToWinError, LsaAddAccountRights, LsaRemoveAccountRights, GetAclInformation, GetLengthSid, InitializeAcl, AddAccessAllowedAceEx, AddAccessDeniedAceEx, GetAce, AddAce, DeleteAce, LsaStorePrivateData, LsaRetrievePrivateData, ReportEventW, RegisterEventSourceW, DeregisterEventSource
gdi32.dll
SelectObject, CreateCompatibleDC, GetObjectW, DeleteDC, DeleteObject, GetDIBits
kernel32.dll
MoveFileExW, MoveFileW, GetVersion, LocalFree, SetFileAttributesW, FileTimeToLocalFileTime, GetComputerNameA, GetLocalTime, GetACP, VirtualAlloc, ReleaseMutex, OpenFileMappingW, DuplicateHandle, UnmapViewOfFile, CreateMutexW, MapViewOfFile, OpenMutexW, GetDriveTypeW, QueryDosDeviceW, GetEnvironmentVariableW, GetLogicalDriveStringsW, FindResourceW, FindResourceExW, LoadResource, LockResource, FreeResource, SizeofResource, LocalAlloc, GlobalMemoryStatus, ReadProcessMemory, GetModuleHandleA, lstrcmpA, InterlockedExchangeAdd, GetLocaleInfoW, LoadLibraryExW, GetLogicalDrives, GetModuleFileNameA, VirtualProtect, GetFileTime, SetFileTime, SetFilePointer, SetEndOfFile, GetTempFileNameW, FlushFileBuffers, GetFileInformationByHandle, GetDiskFreeSpaceW, LockFileEx, UnlockFileEx, GetSystemInfo, VirtualFree, TryEnterCriticalSection, CreateSemaphoreW, ReleaseSemaphore, GetExitCodeThread, SetUnhandledExceptionFilter, TlsFree, TlsGetValue, TlsSetValue, GetExitCodeProcess, InterlockedExchange, QueryPerformanceCounter, UnhandledExceptionFilter, TerminateProcess, GetStartupInfoA, InterlockedCompareExchange, GetVersionExA, RaiseException, GetProcessHeap, HeapSize, HeapReAlloc, HeapFree, HeapAlloc, HeapDestroy, lstrcpynW, lstrlenW, GetFullPathNameW, GetFileAttributesW, GetModuleFileNameW, WaitForMultipleObjects, WriteFile, FileTimeToSystemTime, CreateProcessW, GetShortPathNameW, SetThreadPriority, CopyFileW, CreateDirectoryW, GetTempPathW, GetCurrentThread, FindClose, FindNextFileW, InterlockedDecrement, InterlockedIncrement, FindFirstFileW, GetModuleHandleW, GetTimeZoneInformation, GetCurrentThreadId, GetVersionExW, DeleteCriticalSection, InitializeCriticalSection, LeaveCriticalSection, GetLastError, SystemTimeToFileTime, CompareFileTime, EnterCriticalSection, GetSystemTime, WaitForSingleObject, ReadFile, GetFileSize, FreeLibrary, SetEvent, LoadLibraryW, Sleep, GetProcAddress, ExpandEnvironmentStringsW, ResetEvent, WideCharToMultiByte, lstrlenA, MultiByteToWideChar, TlsAlloc, GetTickCount, GetCurrentProcess, GetCurrentProcessId, GetTimeFormatW, SetErrorMode, TerminateThread, GetDateFormatW, GetSystemTimeAsFileTime, GetComputerNameW, LocalFileTimeToFileTime, OpenProcess, DeleteFileW, SetLastError, GetSystemPowerStatus, GetFileAttributesA, GetFullPathNameA, AreFileApisANSI, lstrcpynA, CreateFileA, CreateFileMappingW, CreateFileMappingA, DeviceIoControl, CreateEventW, CreateFileW, CreateThread, CloseHandle, ResumeThread, IsBadReadPtr, GetOverlappedResult, GetVolumeNameForVolumeMountPointW, GetVolumePathNameW, lstrcpyW, lstrcatW, CreatePipe, GetWindowsDirectoryW, SetHandleInformation, RemoveDirectoryW, GetEnvironmentStringsW, FreeEnvironmentStringsW, GlobalFree, IsProcessorFeaturePresent
msvcp110.dll
DllMain
msvcp80.dll
DllMain
msvcr110.dll
DllMain
msvcr80.dll
DllMain
ole32.dll
CoTaskMemFree, CoUninitialize, CoCreateInstance, CoInitialize, CoCreateGuid
secur32.dll
FreeCredentialsHandle, AcquireCredentialsHandleW, LsaFreeReturnBuffer, LsaEnumerateLogonSessions, LsaGetLogonSessionData
shell32.dll
SHGetMalloc, SHGetDesktopFolder, SHGetPathFromIDListW, SHGetPathFromIDListA, SHGetSpecialFolderPathW
user32.dll
UnregisterClassA, PostMessageW, GetDC, PeekMessageW, TranslateMessage, DispatchMessageW, MsgWaitForMultipleObjects, wsprintfW, SendMessageW, KillTimer, DefWindowProcW, LoadStringW, RegisterClassW, CreateWindowExW, SetTimer, GetIconInfo, DestroyIcon, GetMessageW
ws2_32.dll
WSAIoctl
wtsapi32.dll
WTSLogoffSession, WTSOpenServerW, WTSCloseServer

ekrn.exe

ESET Smart Security by ESET (Signed)

Remove ekrn.exe
Version:   5.2.15.0
MD5:   6576cdef9945dfa6bae25fa0119468e9
SHA1:   9cbf161a653bc4c673f06d6f5c8db28f43c4e910
SHA256:   32b3bd8420f73e325d14545d7c352ee47f297f03e9758cb15608727cbfa99742

What is ekrn.exe?

ESET NOD32 Antivirus, commonly known as NOD32, is an antivirus software package from ESET. ESET's use of assembly language in its products contributes to their low system requirements and disk space utilization. ESET calls its scanning engine ThreatSense, and makes extensive use of generic signatures and heuristics.

About ekrn.exe (from ESET)

Protect your family with ESET’s complete Internet security suite, built on the award-winning ThreatSense antivirus and antispyware engine. Our proactive heuristic technology intercepts and eliminates

DetailsDetails

File name:ekrn.exe
Publisher:ESET
Product name:ESET Smart Security
Description:ESET Service
Typical file path:C:\Program Files\eset\eset nod32 antivirus\ekrn.exe
File version:5.2.15.0
Size:891.78 KB (913,184 bytes)
Certificate
Issued to:ESET
Authority (CA):VeriSign
Expiration date:Wednesday, June 12, 2013
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 8.0
.NET CLR:No
More details

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'ekrn' (ESET Service)
  • ekrn

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00069157%
0.028634%
Kernel CPU:0.00030697%
0.013761%
User CPU:0.00038460%
0.014873%
Kernel CPU time:59,154 ms/min
100,923,805ms/min
CPU cycles:9,414,458/sec
17,470,203/sec
Context switches:11/sec
284/sec
Memory
Private memory:99.44 MB
21.59 MB
Private (maximum):89.97 MB
Private (minimum):45.49 MB
Non-paged memory:99.44 MB
21.59 MB
Virtual memory:223.19 MB
140.96 MB
Virtual memory (peak):305.58 MB
169.69 MB
Working set:69.58 MB
18.61 MB
Working set (peak):138.41 MB
37.95 MB
Page faults:1,116,162/min
2,039/min
I/O
I/O read transfer:4.18 MB/sec
1.02 MB/min
I/O read operations:212/sec
343/min
I/O write transfer:463.49 KB/sec
274.99 KB/min
I/O write operations:25/sec
227/min
I/O other transfer:8.43 KB/sec
448.09 KB/min
I/O other operations:601/sec
1,671/min
Resource allocations
Threads:25
12
Handles:427
600

BehaviorsProcess properties

Integrety level:System
Platform:32-bit
Command lines:
  • "C:\Program Files\eset\eset smart security\ekrn.exe"
  • "C:\Program Files\eset\eset smart security\x86\ekrn.exe"
  • "C:\Program Files\eset\eset nod32 antivirus\ekrn.exe"
  • "C:\Program Files\eset\eset nod32 antivirus\x86\ekrn.exe"
Owner:SYSTEM
Windows Service
Service name:ekrn
Display name:ESET Service
Description:“ESET Service”
Type:Win32OwnProcess, InteractiveProcess
Parent process:services.exe (by Microsoft)

ResourcesThreads

Averages
 
wow64.dll
Total CPU:0.51104957%
0.272967%
Kernel CPU:0.31569850%
0.107585%
User CPU:0.19535106%
0.165382%
CPU cycles:14,279,275/sec
5,741,424/sec
Memory:252 KB
1.16 MB
ekrnamon.dll (ESET Smart Security by ESET)
Total CPU:0.08210605%
Kernel CPU:0.01216184%
User CPU:0.06994421%
CPU cycles:2,572,739/sec
Memory:284 KB
sechost.dll
Total CPU:0.02501289%
Kernel CPU:0.00293361%
User CPU:0.02207928%
CPU cycles:1,184,155/sec
Memory:100 KB
ekrn.exe (main module)
Total CPU:0.01243114%
Kernel CPU:0.00374565%
User CPU:0.00868549%
CPU cycles:396,018/sec
Context switches:1/sec
Memory:880 KB
ekrnepfw.dll (ESET Smart Security by ESET)
Total CPU:0.01208149%
Kernel CPU:0.00725545%
User CPU:0.00482604%
CPU cycles:425,238/sec
Context switches:1/sec
Memory:520 KB
ekrnhips.dll (ESET Smart Security by ESET)
Total CPU:0.00644111%
Kernel CPU:0.00401330%
User CPU:0.00242781%
CPU cycles:222,423/sec
Memory:132 KB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 40.50%
Microsoft Windows XP 23.50%
Windows 7 Home Premium 11.50%
Windows 8 Pro 7.00%
Windows 7 Professional 6.50%
Windows 7 Ultimate N 2.50%
Windows 7 Home Basic 1.50%
Windows 8.1 N 1.00%
Windows 8.1 Single Language 1.00%
Windows 8.1 1.00%
Windows 8 Enterprise 1.00%
Windows 8 1.00%
Windows Vista Home Premium 1.00%
Windows 8 Consumer Preview 0.50%
Windows 8 Pro with Media Center 0.50%

Distribution by countryDistribution by country

Ireland installs about 14.50% of ESET Smart Security.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
ASUS 18.54%
Hewlett-Packard 13.17%
Dell 12.68%
Intel 11.71%
Acer 9.27%
Lenovo 8.78%
Sony 8.78%
GIGABYTE 7.32%
Toshiba 6.83%
Sahara 0.98%
Samsung 0.98%
American Megatrends 0.98%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE