Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

7, 0, 315459, 4132 10.71%
6, 3, 300670, 2970 14.29%
6, 3, 297838, 2953 3.57%
6, 2, 285401, 2860 10.71%
6, 2, 285401, 2860 10.71%
6, 2, 282872, 2847 21.43%
6, 2, 282872, 2847 3.57%
6, 1, 275152, 2801 14.29%
6, 0, 264710, 2708 10.71%

Relationships

Child process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegCreateKeyExW, InitiateSystemShutdownExW, CryptDestroyHash, OpenProcessToken, RegCloseKey, RegSetValueExW, RegQueryValueExW, AdjustTokenPrivileges, RegOpenKeyExW, GetUserNameW, CryptReleaseContext, CryptAcquireContextW, CryptHashData, CryptGetHashParam, CryptCreateHash, LookupPrivilegeValueW, RegEnumKeyExW
comctl32.dll
InitCommonControlsEx
crypt32.dll
CryptUnprotectData
dbghelp.dll
MiniDumpWriteDump
gdi32.dll
CreateRoundRectRgn
gdiplus.dll
GdipCreateFromHWND, GdipDeleteGraphics, GdiplusStartup, GdiplusShutdown, GdipCreateFromHDC, GdipGetImageHeight, GdipGetImageWidth, GdipCreateFont, GdipGetGenericFontFamilySansSerif, GdipDeleteFontFamily, GdipCreateFontFamilyFromName, GdipCreateSolidFill, GdipDeleteBrush, GdipFree, GdipAlloc, GdipCloneBrush, GdipCreateStringFormat, GdipDeleteStringFormat, GdipSetStringFormatAlign, GdipDrawImageRectI, GdipDrawString, GdipCreateBitmapFromStream, GdipCloneImage, GdipDisposeImage, GdipDeleteFont
kernel32.dll
GetVersionExW, GetSystemInfo, WaitForSingleObject, DeleteCriticalSection, SetEvent, SetProcessWorkingSetSize, WriteFile, FlushFileBuffers, EnterCriticalSection, LeaveCriticalSection, OutputDebugStringW, InitializeCriticalSectionAndSpinCount, CreateEventW, CreateWaitableTimerW, SetWaitableTimer, WaitForMultipleObjects, LocalFree, ProcessIdToSessionId, Sleep, CreateMutexW, FlushInstructionCache, SetLastError, DecodePointer, EncodePointer, GlobalFree, GlobalUnlock, GlobalLock, GlobalAlloc, FileTimeToSystemTime, GetModuleHandleW, GetProcAddress, lstrlenW, GetLastError, WideCharToMultiByte, FindResourceExW, FindResourceW, LoadResource, LockResource, SizeofResource, GetComputerNameW, FindNextFileW, FindFirstFileW, FindClose, lstrcpyW, GetCurrentProcessId, FileTimeToLocalFileTime, CloseHandle, GetCurrentThreadId, InterlockedExchange, RaiseException, CreateFileW, GetModuleFileNameW, GetSystemTimeAsFileTime, GetCurrentProcess, SetUnhandledExceptionFilter, FileTimeToDosDateTime, InterlockedPopEntrySList, VirtualFree, InterlockedPushEntrySList, InterlockedCompareExchange, GetProcessHeap, SetEnvironmentVariableA, CompareStringW, GetTickCount, WriteConsoleW, SetStdHandle, LoadLibraryW, GetConsoleMode, GetConsoleCP, SetFilePointer, IsProcessorFeaturePresent, RtlUnwind, QueryPerformanceCounter, GetFileType, SetHandleCount, GetEnvironmentStringsW, MultiByteToWideChar, FreeEnvironmentStringsW, LCMapStringW, HeapSize, HeapReAlloc, GetTimeZoneInformation, GetStdHandle, ExitProcess, HeapDestroy, HeapCreate, GetStringTypeW, IsValidCodePage, GetOEMCP, GetACP, GetCPInfo, TlsFree, TlsSetValue, OpenMutexW, TlsGetValue, TlsAlloc, IsDebuggerPresent, UnhandledExceptionFilter, TerminateProcess, GetStartupInfoW, HeapSetInformation, GetCommandLineW, CreateThread, ExitThread, VirtualAlloc, HeapAlloc, HeapFree, FormatMessageW, LocalAlloc, InterlockedIncrement, InterlockedDecrement
ole32.dll
CoCreateInstance, CLSIDFromProgID, CoTaskMemAlloc, CoGetClassObject, OleInitialize, CoTaskMemFree, CreateStreamOnHGlobal
psapi.dll
GetProcessMemoryInfo
rpcrt4.dll
RpcStringFreeW, UuidToStringW
shell32.dll
Shell_NotifyIconW, ShellExecuteExW, SHGetFolderPathW, ShellExecuteW
shlwapi.dll
PathAppendW, PathFindExtensionW, PathFindFileNameW, PathRemoveFileSpecW, PathIsFileSpecW, PathAddExtensionW, PathFileExistsW, PathAddBackslashW
user32.dll
GetMonitorInfoW, MonitorFromRect, RegisterClassExW, DispatchMessageW, TranslateMessage, GetMessageW, DestroyWindow, GetClientRect, GetDesktopWindow, SetWindowRgn, ReleaseCapture, SetCapture, OffsetRect, SetRect, PtInRect, GetMenu, AdjustWindowRectEx, UnregisterClassA, CreateWindowExW, SetWindowLongW, LoadCursorW, ShowWindow, GetClassInfoExW, ClientToScreen, TrackMouseEvent, SetRectEmpty, wsprintfW, GetSystemMetrics, GetThreadDesktop, GetUserObjectInformationW, RegisterWindowMessageW, SetTimer, CheckMenuItem, GetMenuState, RemoveMenu, GetSubMenu, EnableMenuItem, MessageBoxW, LoadIconW, EndPaint, KillTimer, IsWindow, SendMessageW, DestroyMenu, PostQuitMessage, SetForegroundWindow, GetCursorPos, TrackPopupMenu, GetWindowLongW, GetWindowRect, SetWindowPos, LoadMenuW, DefWindowProcW, CallWindowProcW, SetMenuItemInfoW, GetLastInputInfo, IsRectEmpty, MoveWindow, RedrawWindow, BeginPaint, PostMessageW

cistray.exe

COMODO Internet Security by Comodo Security Solutions (Signed)

Remove cistray.exe
Version:   6, 2, 282872, 2847
MD5:   7f54b11b7cb1f4adb3f06d6282e1df64
SHA1:   486b3562279178cfb7d39846ba2b831453235b21
SHA256:   6505cc4be91256a0a1f7a367ee240316a779bb51ec47703f1ea3ba983a77ad7d

Overview

cistray.exe executes as a process with the local user's privileges. It is set to be start when the PC boots and any user logs into Windows (added to the Run registry key for the all users under the local machine). It is installed with a couple of know programs including COMODO Internet Security published by COMODO, COMODO Firewall from COMODO and COMODO Firewall by COMODO. The assembly utilizes the .NET run-time framework (which is required to be installed on the PC). The file is digitally signed by Comodo Security Solutions which was issued by the COMODO CA Limited certificate authority (CA).

DetailsDetails

File name:cistray.exe
Publisher:COMODO
Product name:COMODO Internet Security
Typical file path:C:\Program Files\comodo\comodo internet security\cistray.exe
File version:6, 2, 282872, 2847
Size:1.39 MB (1,460,952 bytes)
Build date:6/17/2013 12:09 PM
Certificate
Issued to:Comodo Security Solutions
Authority (CA):COMODO CA Limited
Effective date:Wednesday, June 13, 2012
Expiration date:Friday, June 14, 2013
Digital DNA
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details

ResourcesPrograms

The following programs will install this file
COMODO
27% remove
Comodo Internet Security (CIS), developed by Comodo Group, is an Internet security suite available for Microsoft Windows. It offers anti-malware (antivirus) protection, a personal firewall, a sandbox and a Host-based Intrusion Prevention System (HIPS) called Defense+. Comodo Internet Security (CIS) is available in four editions: Comodo Internet Security (the standard edition), Comodo Internet Security Plus, Comodo Internet Security Pro ...
COMODO
7% remove
Comodo's free Firewall is your first layer of defense against viruses, worms, Trojans, hackers and all Internet threats. Comodo's Firewall uses Default Deny Protection to prevent threats from occurring, rather than just detecting them when it's already too late. Whenever an unknown piece of software is introduced to your system, Comodo Firewall cross-references it with a white-list of over 15 million trusted files and applications. If t...
COMODO
22% remove
Comodo Internet Security is the free, multi-layered, security application that offers complete protection from viruses, Trojans, worms, buffer overflows, zero-day attacks, spyware and hackers. Built from the ground upwards with your security in mind, Comodo Internet Security combines powerful Antivirus protection, an enterprise class packet filtering firewall, advanced host intrusion prevention, application control and anti-spyware in o...
COMODO
7% remove
Comodo Antivirus is the free way to rid your computer of viruses, malware, Trojans, worms, hackers, and other Internet threats. Scan any drive or file. Get in-depth reports on viral activity. Detect suspicious files that behave like viruses do. Even scan compressed .zip files, where viruses often hide. The latest version sees a major leap forward in security and usability with the addition of cloud based virus-scanning and behavior anal...

BehaviorsBehaviors

Scheduled tasks
  • The task '{31DDBD37-5DB7-4030-8064-10B0CAA806C3}' runs on logon in the path '\{31DDBD37-5DB7-4030-8064-10B0CAA806C3}'
  • Entry path '\{31DDBD37-5DB7-4030-8064-10B0CAA806C3}'
Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'COMODO Internet Security' → C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
Scheduled tasks startups
Set to load on user login (bypasses Windows UAC if enabled)
  • Login entry path '\{31DDBD37-5DB7-4030-8064-10B0CAA806C3}'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00305492%
0.028634%
Kernel CPU:0.00167923%
0.013761%
User CPU:0.00137569%
0.014873%
Kernel CPU time:34,375 ms/min
100,923,805ms/min
Context switches:13/sec
284/sec
Memory
Private memory:6.44 MB
21.59 MB
Private (maximum):3.95 MB
Private (minimum):556 KB
Non-paged memory:6.44 MB
21.59 MB
Virtual memory:189.71 MB
140.96 MB
Virtual memory (peak):199.33 MB
169.69 MB
Working set:1.28 MB
18.61 MB
Working set (peak):9.2 MB
37.95 MB
Resource allocations
Threads:6
12
Handles:199
600
GUI GDI count:136
103
GUI USER count:54
49

BehaviorsProcess properties

Tray notification:Yes
Integrety level:Undefined
Platform:32-bit
Command line:"C:\Program Files\comodo\comodo internet security\cistray.exe"
Owner:User
Parent process:explorer.exe (by Microsoft)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 21.43%
Windows 8 21.43%
Windows 7 Professional 14.29%
Windows 7 Ultimate 14.29%
Windows 8.1 Pro 10.71%
Windows 8 Pro 10.71%
Windows 8.1 3.57%
Microsoft Windows XP 3.57%

Distribution by countryDistribution by country

United States installs about 50.00% of COMODO Internet Security.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 36.84%
Sony 21.05%
Acer 10.53%
Lenovo 10.53%
Hewlett-Packard 7.89%
ASUS 5.26%
GIGABYTE 5.26%
Samsung 2.63%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE