Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

7, 0, 315459, 4132 7.14%
6, 3, 301686, 2974 3.57%
6, 3, 300670, 2970 3.57%
6, 3, 297838, 2953 3.57%
6, 3, 294583, 2937 3.57%
6, 2, 285401, 2860 10.71%
6, 2, 285401, 2860 10.71%
6, 2, 282872, 2847 28.57%
6, 2, 282872, 2847 3.57%
6, 1, 276535, 2808 14.29%
6, 0, 264710, 2708 10.71%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
CryptDestroyHash, LookupAccountSidW, InitializeSid, GetLengthSid, InitializeSecurityDescriptor, InitializeAcl, SetSecurityDescriptorDacl, AddAccessAllowedAceEx, SetNamedSecurityInfoW, GetUserNameW, AllocateAndInitializeSid, ConvertStringSidToSidW, RegConnectRegistryW, RegLoadKeyW, LookupAccountNameW, ConvertSidToStringSidW, RegCloseKey, RegOpenKeyExW, RegSetValueExW, RegQueryValueExW, CryptGetHashParam, CryptHashData, CryptCreateHash, CopySid, CryptAcquireContextW, CryptReleaseContext, RegFlushKey, OpenProcessToken, RegQueryInfoKeyW, RegEnumKeyExW, RegOpenKeyW, RegQueryValueW, RegEnumKeyW, RegDeleteKeyW, AdjustTokenPrivileges, LookupPrivilegeValueW, OpenThreadToken, RegDeleteValueW, RegCreateKeyExW, StartServiceW, ChangeServiceConfigW, QueryServiceConfigW, QueryServiceStatus, CloseServiceHandle, OpenServiceW, OpenSCManagerW, RegEnumValueW
cmdhtml.dll
SciterIsElementEnabled, ValueInt64DataSet, SciterCloneElement, ValueInt64Data, ValueFloatDataSet, SciterSendEvent, SciterGetElementText, SciterCallBehaviorMethod, SciterGetElementTextCB, SciterGetElementHtmlCB, SciterDetachElement, SciterCall, ValueNthElementValueSet, ValueElementsCount, ValueFromString, SciterShowPopup, SciterGetValue, SciterGetElementIntrinsicHeight, SciterGetElementIntrinsicWidths, SciterGetStyleAttribute, SciterCallScriptingMethod, SciterCallScriptingFunction, SciterInsertElement, SciterCreateElement, SciterGetElementType, SciterUpdateElement, ValueIntData, SciterSetValue, SciterSetElementText, SciterSetElementHtml, SciterSetStyleAttribute, ValueStringDataSet, SciterLoadHtml, SciterSetCallback, SciterDataReady, SciterProcND, SciterGetMinHeight, SciterGetMinWidth, SciterDetachEventHandler, SciterAttachEventHandler, SciterGetElementLocation, SciterGetRootElement, SciterWindowAttachEventHandler, ValueToString, ValueStringData, ValueIntDataSet, ValueCopy, ValueClear, ValueInit, SciterPostEvent, SciterSetElementState, SciterGetElementState, SciterSelectParent, SciterSelectElements, SciterSetAttributeByName, SciterGetAttributeByName, SciterGetElementIndex, SciterGetParentElement, SciterGetNthChild, SciterGetChildrenCount, Sciter_UnuseElement, Sciter_UseElement
comctl32.dll
InitCommonControlsEx, ImageList_ReplaceIcon, ImageList_GetIconSize, ImageList_Destroy, ImageList_DrawEx, ImageList_DrawIndirect, ImageList_GetImageInfo, ImageList_GetBkColor, FlatSB_GetScrollProp, _TrackMouseEvent, ImageList_GetImageCount
comdlg32.dll
GetOpenFileNameW, CommDlgExtendedError, GetFileTitleW, GetSaveFileNameW
crypt32.dll
CryptUnprotectData, CryptVerifyMessageSignature, CertGetCertificateChain, CertVerifyCertificateChainPolicy, CertFreeCertificateContext, CertFreeCertificateChain, CertGetNameStringW, CryptProtectData
dbghelp.dll
ImageDirectoryEntryToData, MiniDumpWriteDump
gdi32.dll
CreatePalette, GetPaletteEntries, GetNearestPaletteIndex, RealizePalette, GetSystemPaletteEntries, OffsetRgn, SetDIBColorTable, GetDIBits, StretchBlt, SetPixel, RoundRect, Rectangle, EnumFontFamiliesExW, LPtoDP, GetWindowOrgEx, GetViewportOrgEx, PtInRegion, FillRgn, FrameRgn, GetBoundsRect, ExtFloodFill, SetPaletteEntries, GetCharWidthW, GetNearestColor, GetBkMode, GetPolyFillMode, GetROP2, GetStretchBltMode, GetTextAlign, SetPixelV, DPtoLP, PatBlt, GetMapMode, CombineRgn, SetRectRgn, GetRgnBox, GetTextCharsetInfo, EnumFontFamiliesW, GetTextMetricsW, CreateRectRgnIndirect, CreateCompatibleBitmap, CreateDIBitmap, Polygon, GetTextColor, GetBkColor, CreateHatchBrush, CreateSolidBrush, CreatePen, GetObjectType, SelectPalette, GetStockObject, CreateCompatibleDC, CreateRoundRectRgn, EqualRgn, GetDeviceCaps, DeleteObject, GetTextExtentPoint32W, CopyMetaFileW, CreateDCW, CreateBitmap, SetTextColor, SetBkColor, GetObjectW, SaveDC, RestoreDC, SetBkMode, SetPolyFillMode, SetROP2, SetStretchBltMode, SetMapMode, GetClipBox, ExcludeClipRect, IntersectClipRect, LineTo, MoveToEx, SetBrushOrgEx, GetBitmapBits, ExtCreateRegion, GetTextExtentPoint32A, StrokePath, FillPath, StrokeAndFillPath, EndPath, CloseFigure, BeginPath, Ellipse, Polyline, CreateEllipticRgn, CreatePolygonRgn, CreateDIBSection, GetCurrentObject, StretchDIBits, CreateFontIndirectW, CreateFontW, SetTextAlign, GetLayout, SetLayout, SelectClipRgn, GetClipRgn, CreateRectRgn, GetViewportExtEx, GetWindowExtEx, BitBlt, GetPixel, PtVisible, RectVisible, TextOutW, ExtTextOutW, Escape, SelectObject, SetViewportOrgEx, OffsetViewportOrgEx, SetViewportExtEx, ScaleViewportExtEx, SetWindowOrgEx, OffsetWindowOrgEx, SetWindowExtEx, ScaleWindowExtEx, GetCurrentPositionEx, PolyBezierTo, ExtSelectClipRgn, DeleteDC, GetTextFaceW, CreatePatternBrush
gdiplus.dll
GdipDrawImageI, GdipGetImageGraphicsContext, GdipBitmapUnlockBits, GdipBitmapLockBits, GdipCreateBitmapFromScan0, GdipCreateBitmapFromStream, GdipGetImagePalette, GdipGetImagePaletteSize, GdipGetImageHeight, GdipGetImageWidth, GdipCloneImage, GdipDrawImageRectI, GdipSetInterpolationMode, GdipCreateFromHDC, GdipCreateBitmapFromHBITMAP, GdipDisposeImage, GdipDeleteGraphics, GdipAlloc, GdipFree, GdiplusShutdown, GdiplusStartup, GdipGetImagePixelFormat
imagehlp.dll
ImageGetCertificateData, ImageGetCertificateHeader, ImageEnumerateCertificates
imm32.dll
ImmGetContext, ImmGetOpenStatus, ImmReleaseContext
iphlpapi.dll
GetAdaptersInfo, GetIfEntry, GetAdaptersAddresses, GetAdapterIndex
kernel32.dll
DllMain
mpr.dll
WNetGetUniversalNameW
msimg32.dll
TransparentBlt, AlphaBlend
ole32.dll
RevokeDragDrop, CoLockObjectExternal, RegisterDragDrop, OleGetClipboard, DoDragDrop, OleLockRunning, IsAccelerator, OleTranslateAccelerator, OleDestroyMenuDescriptor, OleCreateMenuDescriptor, OleRun, CoRegisterMessageFilter, OleFlushClipboard, OleIsCurrentClipboard, CoRevokeClassObject, CreateILockBytesOnHGlobal, StgCreateDocfileOnILockBytes, StgOpenStorageOnILockBytes, CoDisconnectObject, CoFreeUnusedLibraries, OleUninitialize, CoCreateGuid, OleDuplicateData, StringFromCLSID, CoGetClassObject, CoTaskMemAlloc, CoTaskMemFree, CoMarshalInterThreadInterfaceInStream, CoGetInterfaceAndReleaseStream, CoInitialize, CoUninitialize, ReleaseStgMedium, OleInitialize, CreateStreamOnHGlobal, PropVariantClear, CoTaskMemRealloc, CoSetProxyBlanket, StringFromGUID2, CoInitializeSecurity, CoInitializeEx, CLSIDFromString, CoCreateInstance, CLSIDFromProgID
oleacc.dll
CreateStdAccessibleObject, AccessibleObjectFromWindow, LresultFromObject
oledlg.dll
OleUIAddVerbMenuW, OleUIBusyW
psapi.dll
EnumProcessModules, GetProcessImageFileNameW, GetProcessMemoryInfo, GetDeviceDriverFileNameW, EnumDeviceDrivers, GetModuleFileNameExW, EnumProcesses
rasapi32.dll
RasGetEntryDialParamsW, RasGetConnectStatusW, RasDialW, RasHangUpW, RasSetCredentialsW, RasGetEntryPropertiesW, RasSetEntryPropertiesW, RasEnumEntriesW, RasEnumConnectionsW
rpcrt4.dll
UuidFromStringW
setupapi.dll
SetupCopyOEMInfW, SetupGetInfFileListW, SetupOpenInfFileW, SetupFindFirstLineW, InstallHinfSectionW, SetupCloseInfFile, SetupGetStringFieldW
shell32.dll
DragFinish, ExtractIconExW, SHChangeNotify, SHGetSpecialFolderLocation, SHGetDesktopFolder, SHGetFolderLocation, SHGetMalloc, SHGetPathFromIDListW, SHBrowseForFolderW, SHCreateDirectoryExW, SHFileOperationW, SHGetFileInfoW, ShellExecuteW, CommandLineToArgvW, ShellExecuteExW, DragQueryFileW, SHGetFolderPathW, SHAppBarMessage
shlwapi.dll
PathFileExistsW, PathIsFileSpecW, PathAddBackslashW, PathAppendW, PathFindFileNameW, StrFormatByteSizeW, PathStripPathW, PathIsPrefixW, PathCompactPathExW, StrRetToBufW, StrToIntW, PathFindExtensionW, PathUnquoteSpacesW, SHDeleteKeyW, PathRemoveExtensionW, PathQuoteSpacesW, PathRemoveFileSpecW, SHStrDupW, PathStripToRootW, PathIsUNCW, PathRemoveBackslashW, PathIsRelativeW, PathIsNetworkPathW
user32.dll
DllMain
version.dll
GetFileVersionInfoSizeW, VerQueryValueW, GetFileVersionInfoW
wininet.dll
HttpSendRequestW, HttpOpenRequestW, InternetReadFile, InternetOpenW, InternetQueryOptionW, InternetCloseHandle, InternetSetOptionW, InternetGetLastResponseInfoW, HttpQueryInfoW, InternetConnectW
winmm.dll
PlaySoundW
winspool.drv
OpenPrinterW, DocumentPropertiesW, ClosePrinter
wintrust.dll
WinVerifyTrust
ws2_32.dll
WSAAddressToStringW

cis.exe

COMODO Internet Security by Comodo Security Solutions (Signed)

Remove cis.exe
Version:   6, 2, 282872, 2847
MD5:   fe836322ed37f586468d11d04393e724
SHA1:   89d60ca1f22538f01f5234e53654d429b3f2107e
SHA256:   2dba1bf138313ec0375950aa62628a20c4c14b73769bf664cf0c69da39667bd7

Overview

cis.exe executes as a process with the local user's privileges typically within the context of its parent cistray.exe (COMODO Internet Security by Comodo Security Solutions). It is an auto-starting process that used the Windows Task Scheduler service to load when the user logs into Windows (sometimes this is required to bypass the UAC protection). It is installed with a couple of know programs including COMODO Antivirus published by COMODO, COMODO Internet Security from COMODO and COMODO Internet Security by COMODO.

DetailsDetails

File name:cis.exe
Publisher:COMODO
Product name:COMODO Internet Security
Typical file path:C:\Program Files\comodo\comodo internet security\cis.exe
File version:6, 2, 282872, 2847
Size:10.79 MB (11,315,416 bytes)
Build date:6/17/2013 12:31 PM
Certificate
Issued to:Comodo Security Solutions
Authority (CA):COMODO CA Limited
Effective date:Wednesday, June 13, 2012
Expiration date:Friday, June 14, 2013
Digital DNA
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details

ResourcesPrograms

The following programs will install this file
COMODO
7% remove
Comodo Antivirus is the free way to rid your computer of viruses, malware, Trojans, worms, hackers, and other Internet threats. Scan any drive or file. Get in-depth reports on viral activity. Detect suspicious files that behave like viruses do. Even scan compressed .zip files, where viruses often hide. The latest version sees a major leap forward in security and usability with the addition of cloud based virus-scanning and behavior anal...
COMODO
27% remove
Comodo Internet Security (CIS), developed by Comodo Group, is an Internet security suite available for Microsoft Windows. It offers anti-malware (antivirus) protection, a personal firewall, a sandbox and a Host-based Intrusion Prevention System (HIPS) called Defense+. Comodo Internet Security (CIS) is available in four editions: Comodo Internet Security (the standard edition), Comodo Internet Security Plus, Comodo Internet Security Pro ...
COMODO
7% remove
Comodo's free Firewall is your first layer of defense against viruses, worms, Trojans, hackers and all Internet threats. Comodo's Firewall uses Default Deny Protection to prevent threats from occurring, rather than just detecting them when it's already too late. Whenever an unknown piece of software is introduced to your system, Comodo Firewall cross-references it with a white-list of over 15 million trusted files and applications. If t...
COMODO
22% remove
Comodo Internet Security is the free, multi-layered, security application that offers complete protection from viruses, Trojans, worms, buffer overflows, zero-day attacks, spyware and hackers. Built from the ground upwards with your security in mind, Comodo Internet Security combines powerful Antivirus protection, an enterprise class packet filtering firewall, advanced host intrusion prevention, application control and anti-spyware in o...
COMODO
9% remove
Comodo Internet Security Complete 2013 guarantees protection against viruses and malware by focusing on prevention not simply detection. Our patent pending prevention based technology creates an impenetrable shield that identifies safe, unsafe and questionable files. Comodo Internet Security Complete 2013 offers real-time protection against Viruses, Trojans, Adware, Spyware and other Malware threats. Other Antivirus products depend on s...

BehaviorsBehaviors

Scheduled tasks startups
Set to load on user login (bypasses Windows UAC if enabled)
  • Login entry path '\COMODO\COMODO Welcome {CEB54B45-2B5E-4FF5-9223-6735CD80FE69}'
Scheduled tasks
  • The job 'COMODO Welcome {CEB54B45-2B5E-4FF5-9223-6735CD80FE69}' runs on logon in the path '\COMODO\COMODO Welcome {CEB54B45-2B5E-4FF5-9223-6735CD80FE69}'
Network connections
  • [UDP] listens on port 61498

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.01389747%
    0.028634%
    Kernel CPU:0.00394195%
    0.013761%
    User CPU:0.00995552%
    0.014873%
    Kernel CPU time:3,197,755 ms/min
    100,923,805ms/min
    CPU cycles:100,763/sec
    17,470,203/sec
    Memory
    Private memory:23 MB
    21.59 MB
    Private (maximum):18.52 MB
    Private (minimum):2.13 MB
    Non-paged memory:23 MB
    21.59 MB
    Virtual memory:225.9 MB
    140.96 MB
    Virtual memory (peak):249.28 MB
    169.69 MB
    Working set:5.79 MB
    18.61 MB
    Working set (peak):29.81 MB
    37.95 MB
    Page faults:296,643/min
    2,039/min
    I/O
    I/O read transfer:36 Bytes/sec
    1.02 MB/min
    I/O read operations:1/sec
    343/min
    I/O write transfer:0 Bytes/sec
    274.99 KB/min
    I/O write operations:1/sec
    227/min
    I/O other transfer:3 Bytes/sec
    448.09 KB/min
    I/O other operations:1/sec
    1,671/min
    Resource allocations
    Threads:10
    12
    Handles:306
    600
    GUI GDI count:223
    103
    GUI GDI peak:263
    142
    GUI USER count:34
    49
    GUI USER peak:62
    71

    BehaviorsProcess properties

    Integrety level:Medium
    Platform:64-bit
    Command lines:
    • "C:\Program Files\comodo\comodo internet security\cis.exe" --alertsui
    • "C:\Program Files\comodo\comodo internet security\cis.exe" --scanui {135706c6-3fec-4169-bee0-1f165ecea83f}
    • "C:\Program Files\comodo\comodo internet security\cis.exe" --mainui
    Owner:User
    Parent processes:

    ResourcesThreads

    Averages
     
    cis.exe (main module)
    Total CPU:0.06286611%
    0.272967%
    Kernel CPU:0.01571888%
    0.107585%
    User CPU:0.04714723%
    0.165382%
    CPU cycles:1,392,899/sec
    5,741,424/sec
    Context switches:9/sec
    79/sec
    Memory:10.89 MB
    1.16 MB
    combase.dll
    Total CPU:0.00305591%
    Kernel CPU:0.00305591%
    User CPU:0.00000000%
    CPU cycles:5,490/sec
    Memory:1.69 MB
    WINMM.dll
    Total CPU:0.00167109%
    Kernel CPU:0.00167109%
    User CPU:0.00000000%
    CPU cycles:67,066/sec
    Memory:128 KB
    ole32.dll
    Total CPU:0.00004735%
    Kernel CPU:0.00002367%
    User CPU:0.00002367%
    CPU cycles:1,701/sec
    Memory:2.01 MB
    gdiplus.dll
    Total CPU:0.00000717%
    Kernel CPU:0.00000717%
    User CPU:0.00000000%
    CPU cycles:148/sec
    Memory:2.09 MB

    Common loaded modules

    These are modules that are typiclaly loaded within the context of this process.

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Windows 7 Home Premium 25.00%
    Windows 8 21.43%
    Windows 8 Pro 17.86%
    Windows 7 Ultimate 14.29%
    Windows 7 Professional 10.71%
    Windows 8.1 3.57%
    Windows 8.1 Pro 3.57%
    Microsoft Windows XP 3.57%

    Distribution by countryDistribution by country

    United States installs about 50.00% of COMODO Internet Security.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    Dell 45.00%
    Lenovo 15.00%
    Sony 15.00%
    Hewlett-Packard 7.50%
    Acer 5.00%
    ASUS 5.00%
    GIGABYTE 5.00%
    Samsung 2.50%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE