Should I block it?

45%
45% of PCs block this file from running.
Possible reason:
Performance resource utilization

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
SetNamedSecurityInfoW, IsValidSid, CopySid, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, SetSecurityInfo, GetSecurityDescriptorSacl, ConvertStringSecurityDescriptorToSecurityDescriptorW, OpenServiceW, ControlService, OpenSCManagerW, StartServiceW, QueryServiceStatus, RegCreateKeyW, CloseServiceHandle, RegEnumKeyExW, RegDeleteKeyW, RegDeleteValueW, RegQueryInfoKeyW, GetTokenInformation, OpenProcessToken, RegOpenKeyExW, RegCreateKeyExW, RegCloseKey, RegQueryValueExW, RegSetValueExW, LookupPrivilegeValueW, AdjustTokenPrivileges, GetAclInformation, AddAce, InitializeAcl, GetNamedSecurityInfoW, GetLengthSid, InitializeSid, GetSidSubAuthority, GetSidLengthRequired, GetAce
comctl32.dll
InitCommonControlsEx, _TrackMouseEvent
crypt32.dll
CertGetNameStringW, CertNameToStrW
gdi32.dll
GetObjectA, GetStockObject, GetObjectW, SetTextColor, OffsetRgn, SaveDC, SetRectRgn, CreateCompatibleBitmap, CreateCompatibleDC, BitBlt, DeleteDC, CombineRgn, LineTo, MoveToEx, GetTextColor, SelectObject, SetBkColor, ExtTextOutW, StretchBlt, CreateBitmap, RestoreDC, CreateDIBSection, CreateFontIndirectW, RectInRegion, SelectClipRgn, TextOutW, CreateRectRgnIndirect, GetClipRgn, RoundRect, GetTextExtentPoint32W, Rectangle, CreateRectRgn, DeleteObject, SetBkMode, CreatePen
gdiplus.dll
GdipCloneBrush, GdipSetTextRenderingHint, GdipAlloc, GdipFree, GdipCreateFontFromLogfontW, GdipCreateFontFromDC, GdipCreateFontFromLogfontA, GdipFillRectangle, GdipCreateStringFormat, GdipDeleteFont, GdipCreateSolidFill, GdipSetStringFormatAlign, GdipSetStringFormatLineAlign, GdipLoadImageFromStream, GdipDeleteBrush, GdipDrawString, GdipSetPageScale, GdipSetPageUnit, GdipCloneImage, GdipDisposeImage, GdiplusStartup, GdiplusShutdown, GdipLoadImageFromFile, GdipSetSmoothingMode, GdipRotateWorldTransform, GdipTranslateWorldTransform, GdipDrawImageRectI, GdipResetWorldTransform, GdipDrawImageRectRectI, GdipDeleteGraphics, GdipGetImageHeight, GdipGetImageWidth, GdipDrawImageI, GdipDeleteStringFormat, GdipCreateFromHDC
imagehlp.dll
ImageGetCertificateHeader
iphlpapi.dll
GetAdaptersInfo
kernel32.dll
CopyFileW, OpenEventW, QueryPerformanceCounter, UnmapViewOfFile, QueryPerformanceFrequency, OpenFileMappingW, MapViewOfFile, CreateFileMappingW, TerminateThread, GlobalUnlock, GlobalLock, GetSystemTime, ResetEvent, GlobalAlloc, GetPrivateProfileSectionNamesW, TryEnterCriticalSection, InterlockedCompareExchange, Sleep, QueryDosDeviceW, GetDiskFreeSpaceW, GetLogicalDriveStringsW, ExitProcess, lstrcmpiW, MoveFileExW, SetThreadPriority, GetSystemTimeAsFileTime, IsBadReadPtr, GetLocalTime, SetProcessWorkingSetSize, ReadProcessMemory, CompareFileTime, GetSystemDefaultLCID, WaitNamedPipeW, DeleteFileW, OpenMutexW, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, TerminateProcess, GetStartupInfoW, HeapSize, HeapReAlloc, HeapDestroy, GetVersionExA, GetLocaleInfoA, GetACP, VirtualAlloc, VirtualFree, IsProcessorFeaturePresent, LoadLibraryA, HeapAlloc, HeapFree, InterlockedExchange, FindCloseChangeNotification, FindNextChangeNotification, WaitForMultipleObjects, OutputDebugStringW, SetPriorityClass, SystemTimeToFileTime, FindFirstChangeNotificationW, CreateThread, CreateEventW, GlobalMemoryStatusEx, GetSystemInfo, GetPrivateProfileStringW, GetPrivateProfileIntW, InitializeCriticalSectionAndSpinCount, SetFilePointer, GetWindowsDirectoryW, ExpandEnvironmentStringsW, DeviceIoControl, FindNextFileW, FindClose, FindFirstFileW, SetFileAttributesW, LocalFree, GetUserDefaultLangID, LoadLibraryW, GetVersionExW, OpenProcess, GetProcessTimes, GetCurrentProcessId, Process32NextW, Process32FirstW, CreateToolhelp32Snapshot, GetFileAttributesExW, SetErrorMode, GetTempPathW, GetCurrentDirectoryW, GetSystemWindowsDirectoryW, GetSystemDirectoryW, GetEnvironmentVariableW, GetLongPathNameW, CreateProcessW, FreeLibrary, LoadLibraryExW, FileTimeToSystemTime, GetFileAttributesW, CreateDirectoryW, WriteFile, GetThreadLocale, SetEvent, ReleaseMutex, InterlockedIncrement, InterlockedDecrement, DeleteCriticalSection, CreateMutexW, WaitForSingleObject, EnterCriticalSection, SetThreadLocale, GetTickCount, CreateFileW, GetFileSize, GetVersion, ReadFile, CloseHandle, GetCurrentThreadId, RaiseException, FreeResource, FindResourceExW, lstrlenA, LoadResource, LockResource, MultiByteToWideChar, SizeofResource, lstrlenW, GetLastError, SetLastError, FlushInstructionCache, GetModuleFileNameW, InitializeCriticalSection, FindResourceW, WritePrivateProfileStringW, WideCharToMultiByte, GetCurrentProcess, GetModuleHandleW, LeaveCriticalSection, GetProcAddress, GetProcessHeap
mpr.dll
WNetGetResourceInformationW
msvcp80.dll
DllMain
msvcr80.dll
DllMain
ole32.dll
CoUninitialize, CoCreateInstance, CoCreateGuid, CreateStreamOnHGlobal, CoInitialize, CoSetProxyBlanket, CoInitializeSecurity, CoTaskMemRealloc, CoTaskMemFree, CoTaskMemAlloc, CoInitializeEx
psapi.dll
GetProcessImageFileNameW, GetProcessMemoryInfo, GetModuleFileNameExW
shell32.dll
Shell_NotifyIconW, CommandLineToArgvW, SHAppBarMessage, SHGetFolderPathW, SHGetFileInfoW, SHGetFileInfoA, SHGetSpecialFolderPathW, ShellExecuteW
shlwapi.dll
StrChrW, StrToIntA, PathFileExistsA, StrToIntW, SHGetValueW, PathFindFileNameW, PathAppendW, PathRemoveFileSpecW, PathFileExistsW, StrRChrW, StrCmpNIW, StrCpyNW, StrCmpNW, StrStrIA, PathIsDirectoryW, PathStripPathW, SHSetValueW, SHEnumValueW, PathFindExtensionW
user32.dll
GetWindowRect, EqualRect, BeginPaint, MonitorFromWindow, CreateWindowExW, SetTimer, IsWindowVisible, SetWindowRgn, ShowWindow, SetCapture, GetWindowTextLengthW, GetWindowLongW, SetWindowLongW, EndPaint, PostThreadMessageW, GetParent, SetActiveWindow, SetWindowPos, SendMessageW, OffsetRect, GetWindowTextW, GetWindowDC, SystemParametersInfoW, DrawTextW, GetClientRect, DrawIconEx, MapWindowPoints, DispatchMessageW, LoadImageW, GetKeyState, RegisterWindowMessageW, PostMessageW, PtInRect, SetRect, TranslateMessage, GetMessageW, MoveWindow, UnregisterClassA, IsWindow, GetDlgCtrlID, ReleaseDC, CallWindowProcW, IsWindowEnabled, SetCursor, LoadCursorW, RegisterClassExW, DestroyWindow, GetActiveWindow, InvalidateRect, EnableWindow, RedrawWindow, SetLayeredWindowAttributes, GetClassInfoExW, ClientToScreen, SendMessageTimeoutW, EnumWindows, SetMenuItemInfoW, TrackPopupMenu, SetForegroundWindow, SetWindowTextW, FindWindowW, CharNextW, MonitorFromRect, UpdateLayeredWindow, IsRectEmpty, IntersectRect, AppendMenuW, GetDesktopWindow, CreatePopupMenu, MonitorFromPoint, TrackPopupMenuEx, CheckMenuItem, GetMenuState, ExitWindowsEx, GetClassNameW, GetSystemMetrics, GetForegroundWindow, GetWindowThreadProcessId, GetAncestor, WindowFromPoint, MsgWaitForMultipleObjects, GetCursorPos, LoadBitmapW, KillTimer, GetDlgItem, DrawFrameControl, GetWindow, DestroyIcon, CopyRect, InflateRect, GetDC, DefWindowProcW, GetMonitorInfoW, LoadIconW, ReleaseCapture, PeekMessageW
version.dll
GetFileVersionInfoSizeW, VerQueryValueW, GetFileVersionInfoW
wininet.dll
InternetCrackUrlW

KSafeTray.exe

Kingsoft PC Doctor by Kingsoft Security Co. (Signed)

Remove KSafeTray.exe
Version:   3.7.0.47
MD5:   5be101cb8bb688839e9203e827684c41
SHA1:   458495345618efda452ff00d688f5ff689a4b1e4
SHA256:   cc6f7d46abfcbd67549fe353ff533369acd58b7f833c236161f036cd3b7de6a9

What is KSafeTray.exe?

ksafetray.exe is the PC Doctor Flow Monitor of Kingsoft PC Doctor, developed by Chinese software developer Kingsoft, a PC optimization utility.

About KSafeTray.exe (from Kingsoft Security Co.)

Kingsoft PC Doctor, which focuses on providing computer users excellent privacy cleaner, registry cleaner and, brilliant Windows optimization service, is your best free professional and easy-to-use Wi

Overview

ksafetray.exe executes as a process with the local user's privileges typically within the context of its parent ksafesvc.exe (Kingsoft PC Doctor by Kingsoft Security Co.). It is set to be start when the PC boots and any user logs into Windows (added to the Run registry key for the all users under the local machine). This is typically installed with the program Kingsoft PC Doctor 3.7.0.47 published by Kingsoft Security. The file is digitally signed by Kingsoft Security Co. which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:ksafetray.exe
Publisher:Kingsoft Corporation
Product name:Kingsoft PC Doctor
Description:PC Doctor Flow Monitor
Typical file path:C:\Program Files\kingsoft\pcdoctor\ksafetray.exe
File version:3.7.0.47
Size:725.41 KB (742,816 bytes)
Certificate
Issued to:Kingsoft Security Co.
Authority (CA):VeriSign
Effective date:Tuesday, March 9, 2010
Expiration date:Saturday, March 9, 2013
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 8.0
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
Kingsoft Security
  56% remove
Kingsoft PC Doctor, which focuses on providing computer users excellent privacy cleaner, registry cleaner and, brilliant Windows optimization service, is your best free professional and easy-to-use Windows Diagnosis and Optimization software. Meanwhile, Computer Health Diagnosis provides you a quick and deepin computer working status diagnosis and, gives you professional suggestion to optimize computer to peak performance.

BehaviorsBehaviors

Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'KSafeTray' → "C:\Program Files\Kingsoft\PCDoctor\KSafeTray.exe" -autorun
Scheduled tasks
  • The task 'KsafeDelay' runs on logon in the path 'C:\WINDOWS\Tasks\KsafeDelay.job'
  • Entry path '\KsafeDelay'
Scheduled tasks startups
Set to load on user login (bypasses Windows UAC if enabled)
  • Login entry path 'C:\WINDOWS\Tasks\KsafeDelay.job'
  • Login entry path '\KsafeDelay'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.01675499%
0.028634%
Kernel CPU:0.00070483%
0.013761%
User CPU:0.01605016%
0.014873%
Kernel CPU time:28,239,968 ms/min
100,923,805ms/min
CPU cycles:4,009,738/sec
17,470,203/sec
Context switches:29/sec
284/sec
Memory
Private memory:14.08 MB
21.59 MB
Private (maximum):19.86 MB
Private (minimum):4.19 MB
Non-paged memory:14.08 MB
21.59 MB
Virtual memory:119.08 MB
140.96 MB
Virtual memory (peak):133.45 MB
169.69 MB
Working set:6.05 MB
18.61 MB
Working set (peak):20.52 MB
37.95 MB
Page faults:186,734/min
2,039/min
I/O
I/O read transfer:6.76 KB/sec
1.02 MB/min
I/O read operations:16/sec
343/min
I/O write transfer:2.5 KB/sec
274.99 KB/min
I/O write operations:4/sec
227/min
I/O other transfer:3.63 KB/sec
448.09 KB/min
I/O other operations:256/sec
1,671/min
Resource allocations
Threads:14
12
Handles:518
600
GUI GDI count:106
103
GUI GDI peak:95
142
GUI USER count:36
49
GUI USER peak:40
71

BehaviorsProcess properties

Integrety level:High
Platform:64-bit
Command lines:
  • "C:\Program Files\kingsoft\pcdoctor\ksafetray.exe" -hig -autorun
  • "C:\Program Files\kingsoft\pcdoctor\ksafetray.exe" -autorun
  • "C:\Program Files\kingsoft\pcdoctor\ksafetray.exe"
Owner:User
Parent processes:

ResourcesThreads

Averages
 
KSafeTray.exe (main module)
Total CPU:0.02177287%
0.272967%
Kernel CPU:0.00442056%
0.107585%
User CPU:0.01735231%
0.165382%
CPU cycles:236,461/sec
5,741,424/sec
Context switches:4/sec
79/sec
Memory:732 KB
1.16 MB
MSVCR80.dll
Total CPU:0.00652605%
Kernel CPU:0.00540656%
User CPU:0.00111949%
Memory:620 KB
json.dll
Total CPU:0.00000516%
Kernel CPU:0.00000000%
User CPU:0.00000516%
Memory:68 KB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 35.00%
Microsoft Windows XP 25.00%
Windows 7 Professional 20.00%
Windows 7 Home Premium 20.00%

Distribution by countryDistribution by country

United States installs about 60.00% of Kingsoft PC Doctor.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Acer 36.36%
GIGABYTE 36.36%
Hewlett-Packard 27.27%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE