Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

7, 0, 315459, 4132 10.71%
6, 3, 300670, 2970 14.29%
6, 3, 297838, 2953 3.57%
6, 2, 285401, 2860 10.71%
6, 2, 285401, 2860 10.71%
6, 2, 282872, 2847 21.43%
6, 2, 282872, 2847 3.57%
6, 1, 275152, 2801 14.29%
6, 0, 264710, 2708 10.71%

Relationships

Parent processes
Child process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegCreateKeyExW, InitiateSystemShutdownExW, CryptDestroyHash, OpenProcessToken, RegCloseKey, RegSetValueExW, RegQueryValueExW, AdjustTokenPrivileges, RegOpenKeyExW, GetUserNameW, CryptReleaseContext, CryptAcquireContextW, CryptHashData, CryptGetHashParam, CryptCreateHash, LookupPrivilegeValueW, RegEnumKeyExW
comctl32.dll
InitCommonControlsEx
crypt32.dll
CryptUnprotectData
dbghelp.dll
MiniDumpWriteDump
gdi32.dll
CreateRoundRectRgn
gdiplus.dll
GdipCreateFromHWND, GdipDeleteGraphics, GdiplusStartup, GdiplusShutdown, GdipCreateFromHDC, GdipGetImageHeight, GdipGetImageWidth, GdipCreateFont, GdipGetGenericFontFamilySansSerif, GdipDeleteFontFamily, GdipCreateFontFamilyFromName, GdipCreateSolidFill, GdipDeleteBrush, GdipFree, GdipAlloc, GdipCloneBrush, GdipCreateStringFormat, GdipDeleteStringFormat, GdipSetStringFormatAlign, GdipDrawImageRectI, GdipDrawString, GdipCreateBitmapFromStream, GdipCloneImage, GdipDisposeImage, GdipDeleteFont
kernel32.dll
GetVersionExW, GetSystemInfo, WaitForSingleObject, DeleteCriticalSection, SetEvent, SetProcessWorkingSetSize, WriteFile, FlushFileBuffers, EnterCriticalSection, LeaveCriticalSection, OutputDebugStringW, InitializeCriticalSectionAndSpinCount, CreateEventW, CreateWaitableTimerW, SetWaitableTimer, WaitForMultipleObjects, LocalFree, ProcessIdToSessionId, Sleep, CreateMutexW, FlushInstructionCache, SetLastError, DecodePointer, EncodePointer, GlobalFree, GlobalUnlock, GlobalLock, GlobalAlloc, FileTimeToSystemTime, GetModuleHandleW, GetProcAddress, lstrlenW, GetLastError, WideCharToMultiByte, FindResourceExW, FindResourceW, LoadResource, LockResource, SizeofResource, GetComputerNameW, FindNextFileW, FindFirstFileW, FindClose, lstrcpyW, GetCurrentProcessId, FileTimeToLocalFileTime, CloseHandle, GetCurrentThreadId, InterlockedExchange, RaiseException, CreateFileW, GetModuleFileNameW, GetSystemTimeAsFileTime, GetCurrentProcess, SetUnhandledExceptionFilter, FileTimeToDosDateTime, InterlockedPopEntrySList, VirtualFree, InterlockedPushEntrySList, InterlockedCompareExchange, GetProcessHeap, SetEnvironmentVariableA, CompareStringW, GetTickCount, WriteConsoleW, SetStdHandle, LoadLibraryW, GetConsoleMode, GetConsoleCP, SetFilePointer, IsProcessorFeaturePresent, RtlUnwind, QueryPerformanceCounter, GetFileType, SetHandleCount, GetEnvironmentStringsW, MultiByteToWideChar, FreeEnvironmentStringsW, LCMapStringW, HeapSize, HeapReAlloc, GetTimeZoneInformation, GetStdHandle, ExitProcess, HeapDestroy, HeapCreate, GetStringTypeW, IsValidCodePage, GetOEMCP, GetACP, GetCPInfo, TlsFree, TlsSetValue, OpenMutexW, TlsGetValue, TlsAlloc, IsDebuggerPresent, UnhandledExceptionFilter, TerminateProcess, GetStartupInfoW, HeapSetInformation, GetCommandLineW, CreateThread, ExitThread, VirtualAlloc, HeapAlloc, HeapFree, FormatMessageW, LocalAlloc, InterlockedIncrement, InterlockedDecrement
ole32.dll
CoCreateInstance, CLSIDFromProgID, CoTaskMemAlloc, CoGetClassObject, OleInitialize, CoTaskMemFree, CreateStreamOnHGlobal
psapi.dll
GetProcessMemoryInfo
rpcrt4.dll
RpcStringFreeW, UuidToStringW
shell32.dll
Shell_NotifyIconW, ShellExecuteExW, SHGetFolderPathW, ShellExecuteW
shlwapi.dll
PathAppendW, PathFindExtensionW, PathFindFileNameW, PathRemoveFileSpecW, PathIsFileSpecW, PathAddExtensionW, PathFileExistsW, PathAddBackslashW
user32.dll
GetMonitorInfoW, MonitorFromRect, RegisterClassExW, DispatchMessageW, TranslateMessage, GetMessageW, DestroyWindow, GetClientRect, GetDesktopWindow, SetWindowRgn, ReleaseCapture, SetCapture, OffsetRect, SetRect, PtInRect, GetMenu, AdjustWindowRectEx, UnregisterClassA, CreateWindowExW, SetWindowLongW, LoadCursorW, ShowWindow, GetClassInfoExW, ClientToScreen, TrackMouseEvent, SetRectEmpty, wsprintfW, GetSystemMetrics, GetThreadDesktop, GetUserObjectInformationW, RegisterWindowMessageW, SetTimer, CheckMenuItem, GetMenuState, RemoveMenu, GetSubMenu, EnableMenuItem, MessageBoxW, LoadIconW, EndPaint, KillTimer, IsWindow, SendMessageW, DestroyMenu, PostQuitMessage, SetForegroundWindow, GetCursorPos, TrackPopupMenu, GetWindowLongW, GetWindowRect, SetWindowPos, LoadMenuW, DefWindowProcW, CallWindowProcW, SetMenuItemInfoW, GetLastInputInfo, IsRectEmpty, MoveWindow, RedrawWindow, BeginPaint, PostMessageW

cistray.exe

COMODO Internet Security by Comodo Security Solutions (Signed)

Remove cistray.exe
Version:   6, 2, 282872, 2847
MD5:   434ff2266745162e67219101e46b2113
SHA1:   7a3c27daa4d680820441d1ef96e9e8a58eee34ea
SHA256:   ccff89ad5e5821612c600f93391c1dbc33743cf455aff6af38173fbf7a8df133

Overview

cistray.exe executes as a process with the local user's privileges usually within the context of Windows Explorer. It is set to be start when the PC boots and any user logs into Windows (added to the Run registry key for the all users under the local machine). It is installed with a couple of know programs including COMODO Antivirus published by COMODO, COMODO Internet Security from COMODO and COMODO Internet Security by COMODO. The assembly utilizes the .NET run-time framework (which is required to be installed on the PC). The file is digitally signed by Comodo Security Solutions which was issued by the COMODO CA Limited certificate authority (CA).

DetailsDetails

File name:cistray.exe
Publisher:COMODO
Product name:COMODO Internet Security
Typical file path:C:\Program Files\comodo\comodo internet security\cistray.exe
File version:6, 2, 282872, 2847
Size:1.43 MB (1,497,816 bytes)
Build date:6/17/2013 12:24 PM
Certificate
Issued to:Comodo Security Solutions
Authority (CA):COMODO CA Limited
Effective date:Wednesday, June 13, 2012
Expiration date:Friday, June 14, 2013
Digital DNA
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details

ResourcesPrograms

The following programs will install this file
COMODO
7% remove
Comodo Antivirus is the free way to rid your computer of viruses, malware, Trojans, worms, hackers, and other Internet threats. Scan any drive or file. Get in-depth reports on viral activity. Detect suspicious files that behave like viruses do. Even scan compressed .zip files, where viruses often hide. The latest version sees a major leap forward in security and usability with the addition of cloud based virus-scanning and behavior anal...
COMODO
27% remove
Comodo Internet Security (CIS), developed by Comodo Group, is an Internet security suite available for Microsoft Windows. It offers anti-malware (antivirus) protection, a personal firewall, a sandbox and a Host-based Intrusion Prevention System (HIPS) called Defense+. Comodo Internet Security (CIS) is available in four editions: Comodo Internet Security (the standard edition), Comodo Internet Security Plus, Comodo Internet Security Pro ...
COMODO
7% remove
Comodo's free Firewall is your first layer of defense against viruses, worms, Trojans, hackers and all Internet threats. Comodo's Firewall uses Default Deny Protection to prevent threats from occurring, rather than just detecting them when it's already too late. Whenever an unknown piece of software is introduced to your system, Comodo Firewall cross-references it with a white-list of over 15 million trusted files and applications. If t...
COMODO
22% remove
Comodo Internet Security is the free, multi-layered, security application that offers complete protection from viruses, Trojans, worms, buffer overflows, zero-day attacks, spyware and hackers. Built from the ground upwards with your security in mind, Comodo Internet Security combines powerful Antivirus protection, an enterprise class packet filtering firewall, advanced host intrusion prevention, application control and anti-spyware in o...
COMODO
9% remove
Comodo Internet Security Complete 2013 guarantees protection against viruses and malware by focusing on prevention not simply detection. Our patent pending prevention based technology creates an impenetrable shield that identifies safe, unsafe and questionable files. Comodo Internet Security Complete 2013 offers real-time protection against Viruses, Trojans, Adware, Spyware and other Malware threats. Other Antivirus products depend on s...

BehaviorsBehaviors

Scheduled tasks
  • The task '{31DDBD37-5DB7-4030-8064-10B0CAA806C3}' runs on logon in the path '\{31DDBD37-5DB7-4030-8064-10B0CAA806C3}'
  • Entry path '\{31DDBD37-5DB7-4030-8064-10B0CAA806C3}'
Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'COMODO Internet Security' → C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
Scheduled tasks startups
Set to load on user login (bypasses Windows UAC if enabled)
  • Login entry path '\{31DDBD37-5DB7-4030-8064-10B0CAA806C3}'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00354358%
0.028634%
Kernel CPU:0.00222747%
0.013761%
User CPU:0.00131611%
0.014873%
Kernel CPU time:950,242 ms/min
100,923,805ms/min
CPU cycles:2,045,950/sec
17,470,203/sec
Memory
Private memory:5.25 MB
21.59 MB
Private (maximum):6.64 MB
Private (minimum):1.15 MB
Non-paged memory:5.25 MB
21.59 MB
Virtual memory:131.01 MB
140.96 MB
Virtual memory (peak):136.6 MB
169.69 MB
Working set:1.98 MB
18.61 MB
Working set (peak):10.3 MB
37.95 MB
Page faults:442,244/min
2,039/min
I/O
I/O read transfer:49 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O other transfer:930 Bytes/sec
448.09 KB/min
I/O other operations:109/sec
1,671/min
Resource allocations
Threads:6
12
Handles:188
600
GUI GDI count:125
103
GUI GDI peak:128
142
GUI USER count:49
49
GUI USER peak:52
71

BehaviorsProcess properties

Integrety level:Medium
Platform:64-bit
Command line:"C:\Program Files\comodo\comodo internet security\cistray.exe"
Owner:User
Parent processes:

ResourcesThreads

Averages
 
cistray.exe (main module)
Total CPU:0.01297552%
0.272967%
Kernel CPU:0.00861062%
0.107585%
User CPU:0.00436490%
0.165382%
CPU cycles:788,128/sec
5,741,424/sec
Context switches:2/sec
79/sec
Memory:1.46 MB
1.16 MB
ntdll.dll
Total CPU:0.00002369%
Kernel CPU:0.00000000%
User CPU:0.00002369%
CPU cycles:1,661/sec
Memory:1.66 MB
gdiplus.dll
Total CPU:0.00000717%
Kernel CPU:0.00000717%
User CPU:0.00000000%
CPU cycles:101/sec
Memory:2.09 MB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 21.43%
Windows 8 21.43%
Windows 7 Professional 14.29%
Windows 7 Ultimate 14.29%
Windows 8.1 Pro 10.71%
Windows 8 Pro 10.71%
Windows 8.1 3.57%
Microsoft Windows XP 3.57%

Distribution by countryDistribution by country

United States installs about 50.00% of COMODO Internet Security.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 36.84%
Sony 21.05%
Acer 10.53%
Lenovo 10.53%
Hewlett-Packard 7.89%
ASUS 5.26%
GIGABYTE 5.26%
Samsung 2.63%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE