Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

5.4.0.148 50.00%
5.2.2.121 50.00%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
RegQueryValueExW, GetUserNameA, SetSecurityDescriptorDacl, GetSecurityDescriptorLength, MakeSelfRelativeSD, InitializeSecurityDescriptor, GetSecurityDescriptorOwner, GetSecurityDescriptorGroup, GetSecurityDescriptorDacl, GetSecurityDescriptorSacl, MakeAbsoluteSD, GetSecurityDescriptorControl, GetAclInformation, RegOpenKeyExW, RegEnumKeyExW, RegDeleteKeyW, RegSetValueExW, RegQueryInfoKeyW, RegCreateKeyExW, RegDeleteValueW, RegQueryValueExA, GetTokenInformation, OpenProcessToken, CopySid, ConvertSidToStringSidW, GetLengthSid, IsValidSid, OpenThreadToken, ImpersonateSelf, RevertToSelf, ImpersonateNamedPipeClient, GetSidLengthRequired, RegEnumValueW, InitializeSid, GetSidSubAuthority, CheckTokenMembership, DuplicateToken, RegNotifyChangeKeyValue, AddAce, InitializeAcl, RegCloseKey
gdi32.dll
SetDIBColorTable, CreateCompatibleDC, DeleteDC, StretchBlt, GetObjectW, GetDIBColorTable, CreateDIBSection, DeleteObject, SelectObject
gdiplus.dll
GdipCreateBitmapFromScan0, GdipCreateBitmapFromFile, GdipDrawImageI, GdipGetImagePalette, GdipGetImagePaletteSize, GdipGetImagePixelFormat, GdipDisposeImage, GdipGetImageHeight, GdipGetImageWidth, GdipDeleteGraphics, GdipGetImageGraphicsContext, GdipBitmapLockBits, GdipBitmapUnlockBits, GdipFree, GdipCloneImage, GdipAlloc, GdiplusStartup, GdiplusShutdown
kernel32.dll
RaiseException, FindClose, lstrcpynA, FindFirstFileW, lstrcpyW, EnterCriticalSection, LeaveCriticalSection, SetLastError, lstrlenW, WideCharToMultiByte, InterlockedExchange, lstrcmpiA, InitializeCriticalSection, SetEnvironmentVariableW, DeleteCriticalSection, GetModuleFileNameW, Sleep, MultiByteToWideChar, OpenEventW, CreateMutexW, LoadLibraryExW, GetEnvironmentVariableW, WaitForMultipleObjects, InterlockedIncrement, lstrcmpiW, InterlockedDecrement, SetEvent, GetThreadLocale, CreateProcessW, HeapFree, CreateEventA, GetDateFormatW, HeapAlloc, GetProcessHeap, LocalFree, lstrlenA, GetCurrentThread, GetModuleFileNameA, CreateEventW, FindNextFileW, GetPrivateProfileSectionNamesW, GetPrivateProfileSectionW, GetLocalTime, GetUserDefaultUILanguage, GetSystemDefaultUILanguage, EnumUILanguagesW, GetUserDefaultLCID, IsValidLocale, GetLocaleInfoW, ConvertDefaultLocale, GetFileAttributesW, GetUserDefaultLangID, OutputDebugStringA, FileTimeToDosDateTime, FileTimeToLocalFileTime, GetFileAttributesExA, DeleteFileW, MoveFileW, GetFileSizeEx, WriteFile, SetFilePointer, CreateFileW, lstrcpynW, GetComputerNameA, CreateWaitableTimerA, SetWaitableTimer, SystemTimeToFileTime, ResumeThread, TlsSetValue, ResetEvent, CreateMutexA, TlsGetValue, TlsFree, TlsAlloc, ReleaseMutex, GetSystemTimeAsFileTime, QueryPerformanceCounter, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, TerminateProcess, GetStartupInfoW, GetLocaleInfoA, GetACP, VirtualAlloc, VirtualFree, IsProcessorFeaturePresent, InterlockedCompareExchange, HeapSize, HeapReAlloc, HeapDestroy, GetVersionExA, LoadLibraryA, LocalAlloc, FlushInstructionCache, GetCurrentProcess, GetTickCount, WaitForSingleObject, CloseHandle, FindResourceW, FindResourceExW, LoadResource, LockResource, SizeofResource, CreateThread, GetFileInformationByHandle, GetVersionExW, LoadLibraryW, GetLastError, OpenProcess, GetProcAddress, GetModuleHandleW, FreeLibrary, GetCurrentThreadId, FormatMessageA, GetCurrentProcessId, GetSystemDefaultLCID
msimg32.dll
AlphaBlend, TransparentBlt
msvcp80.dll
DllMain
msvcr80.dll
DllMain
ole32.dll
CoCreateInstance, CoUninitialize, CoRevertToSelf, CoInitialize, CoInitializeEx, CoInitializeSecurity, CoRegisterClassObject, CoTaskMemAlloc, CoRevokeClassObject, StringFromGUID2, CoGetClassObject, CoTaskMemRealloc, CoTaskMemFree, CoDisconnectObject, CoImpersonateClient
shell32.dll
SHCreateDirectoryExW, Shell_NotifyIconW, ShellExecuteW
shfolder.dll
SHGetFolderPathW
shlwapi.dll
PathRenameExtensionW, PathFindFileNameW, PathFindFileNameA, PathFindExtensionA, PathRemoveFileSpecW, StrStrIW, PathIsRelativeW, PathAppendW, PathIsDirectoryW, PathFileExistsW, PathStripPathW
user32.dll
GetMonitorInfoW, UnregisterClassA, BringWindowToTop, GetSystemMetrics, DestroyIcon, SetTimer, KillTimer, LoadImageW, LoadCursorW, IsWindow, PeekMessageW, PtInRect, GetWindowLongW, InvalidateRect, LoadStringA, GetProcessWindowStation, GetUserObjectInformationA, SetMenuDefaultItem, InsertMenuW, SetProcessDefaultLayout, GetProcessDefaultLayout, SetForegroundWindow, GetMenuItemID, GetAsyncKeyState, TrackPopupMenu, wsprintfW, CharNextW, GetLastInputInfo, MessageBoxW, LoadAcceleratorsW, LoadMenuW, GetDoubleClickTime, GetCursorPos, RegisterWindowMessageW, EndPaint, BeginPaint, GetWindow, SystemParametersInfoW, GetParent, DestroyWindow, MsgWaitForMultipleObjects, DispatchMessageW, GetWindowRect, CreateWindowExW, PostQuitMessage, SetWindowLongW, SetFocus, ShowWindow, GetClientRect, UpdateWindow, SetWindowPos, CreatePopupMenu, SendMessageW, DestroyMenu, RegisterClassExW, TrackPopupMenuEx, PostMessageW, CallWindowProcW, DefWindowProcW, AppendMenuW, GetMenuItemCount, GetClassInfoExW, GetMenuItemInfoW, MessageBeep, MonitorFromPoint, MapWindowPoints, TranslateMessage, RemoveMenu, LoadStringW
userenv.dll
UnloadUserProfile

XTray.exe

McAfee Security-as-a-Service by McAfee (Signed)

Remove XTray.exe
Version:   5.2.2.121
MD5:   514fe75b9508040510cb7bde7f191b50
SHA1:   2148863e0fe21cbee37b7908cfa23c33c194ba07
SHA256:   1007cce30a0578a7ebdbc45a06af58a5f8042a1dade8832d4949295178d83700

Overview

xtray.exe executes as a process with the local user's privileges. It is set to be start when the PC boots and any user logs into Windows (added to the Run registry key for the all users under the local machine). The file is digitally signed by McAfee which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:xtray.exe
Publisher:McAfee, Inc.
Product name:McAfee® Security-as-a-Service
Description:XTray Application
Typical file path:C:\Program Files\mcafee\managed virusscan\desktopui\xtray.exe
File version:5.2.2.121
Product version:5.2.2
Size:465.31 KB (476,480 bytes)
Certificate
Issued to:McAfee
Authority (CA):VeriSign
Effective date:Wednesday, October 5, 2011
Expiration date:Tuesday, December 31, 2013
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 8.0
.NET CLR:No
More details

BehaviorsBehaviors

Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'MVS Splash' → "C:\Program Files\McAfee\Managed VirusScan\DesktopUI\XTray.exe"
  • 'McAfee Managed Services Tray' → "C:\Program Files\McAfee\Managed VirusScan\DesktopUI\XTray.Exe" /LOGON

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00359226%
0.028634%
Kernel CPU:0.00207553%
0.013761%
User CPU:0.00151673%
0.014873%
Kernel CPU time:234 ms/min
100,923,805ms/min
CPU cycles:109,096/sec
17,470,203/sec
Memory
Private memory:4.22 MB
21.59 MB
Private (maximum):10.14 MB
Private (minimum):2.95 MB
Non-paged memory:4.22 MB
21.59 MB
Virtual memory:79.24 MB
140.96 MB
Virtual memory (peak):85.57 MB
169.69 MB
Working set:3.01 MB
18.61 MB
Working set (peak):10.16 MB
37.95 MB
Page faults:4,125/min
2,039/min
I/O
I/O read transfer:118 Bytes/sec
1.02 MB/min
I/O read operations:3/sec
343/min
I/O write transfer:14 Bytes/sec
274.99 KB/min
I/O write operations:1/sec
227/min
I/O other transfer:186 Bytes/sec
448.09 KB/min
I/O other operations:19/sec
1,671/min
Resource allocations
Threads:5
12
Handles:146
600
GUI GDI count:82
103
GUI GDI peak:85
142
GUI USER count:37
49
GUI USER peak:41
71

BehaviorsProcess properties

Integrety level:High
Platform:64-bit
Command line:"C:\Program Files\mcafee\managed virusscan\desktopui\xtray.exe"
Owner:User

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Professional 50.00%
Windows 7 Home Premium 50.00%

Distribution by countryDistribution by country

TT installs about 50.00% of McAfee® Security-as-a-Service.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Lenovo 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE