tftray.exe
ThreatFire by PC Tools (Signed)
Version: | 4.10.1.14 |
MD5: | 6a52a7525aa33c7df2867bf3a7876e1c |
SHA1: | c70f87364d9a6bb6a068fc5e7347fe830035a740 |
SHA256: | 580fe246df8b1cfc5ef8dc20f021748457e45c485707d671ac5825104cf5ac95 |
Overview
tftray.exe executes as a process with the local user's privileges. It is set to be start when the PC boots and any user logs into Windows (added to the Run registry key for the all users under the local machine). This is typically installed with the program ThreatFire published by PC Tools Software. The file is digitally signed by PC Tools which was issued by the VeriSign certificate authority (CA).
Details
File name: | tftray.exe |
Publisher: | PC Tools |
Product name: | ThreatFire |
Description: | PC Tools ThreatFire Tray App |
Typical file path: | C:\Program Files\threatfire\tftray.exe |
Original name: | TrayApp.exe |
File version: | 4.10.1.14 |
Product version: | 4.7.0.17 |
Size: | 369.27 KB (378,128 bytes) |
Build date: | 1/14/2010 11:00 PM |
Certificate |
Issued to: | PC Tools |
Authority (CA): | VeriSign |
Expiration date: | Friday, July 8, 2011 |
Digital DNA |
PE subsystem: | Windows GUI |
File packed: | No |
Code language: | Microsoft Visual C++ 8.0 |
.NET CLR: | No |
More details
Programs
The following program will install this file
“Traditional antivirus solutions cannot protect you until after they have discovered a new threat and produced a signature to counter it. ThreatFire does not rely on signatures, but instead provides behavior-based protection. It is designed to be used alongside your existing antivirus software and it fills the gap in protection between your antivirus signature updates. ThreatFire protects you against major security threats including viru...”
Behaviors
Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
- 'ThreatFire' → C:\Program Files\ThreatFire\TFTray.exe
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
CPU |
Total CPU: | 0.00023253% | |
Kernel CPU: | 0.00021729% | |
User CPU: | 0.00001524% | |
Kernel CPU time: | 18,656 ms/min | |
Memory |
Private memory: | 6.96 MB | |
Private (maximum): | 3.66 MB | |
Private (minimum): | 3.33 MB | |
Non-paged memory: | 6.96 MB | |
Virtual memory: | 64.42 MB | |
Virtual memory (peak): | 68.59 MB | |
Working set: | 3.34 MB | |
Working set (peak): | 10.7 MB | |
Page faults: | 29,749/min | |
I/O |
I/O read transfer: | 18 Bytes/sec | |
I/O read operations: | 1/sec | |
I/O write transfer: | 0 Bytes/sec | |
I/O write operations: | 1/sec | |
I/O other transfer: | 0 Bytes/sec | |
I/O other operations: | 1/sec | |
Resource allocations |
Threads: | 3 | |
Handles: | 182 | |
GUI GDI count: | 42 | |
GUI USER count: | 15 | |
Process properties
Distribution by Windows OS
OS version | distribution |
Windows 7 Home Premium |
50.00% |
|
Microsoft Windows XP |
50.00% |
|
Distribution by country
Canada installs about 50.00% of ThreatFire.
Distribution by PC manufacturer
PC Manufacturer | distribution |
Intel |
50.00% |
|
Dell |
50.00% |
|