zatray.exe
ZoneAlarm by Check Point Software Technologies Ltd. (Signed)
| Version: | 11.0.000.057 | 
| MD5: | 4f1f35044428cd8981bea81432e9e51d | 
| SHA1: | f6acf3cb5d11a96a3a033b452579f4f5584f998e | 
| SHA256: | 73df0166ce3cc411dd7610b8de0f7cb7abd8e7863ffb52a3f655f5acdfe58a47 | 
What is zatray.exe?
zatray.exe is the program that runs in the notification area system tray for the ZoneAlarm application.
About zatray.exe (from Check Point Software Technologies Ltd.)
“ZoneAlarm Security Toolbar is keeping you protected and connected.”
Overview
zatray.exe executes as a process with the local user's privileges. It is set to be start when the PC boots and any user logs into Windows (added to the Run registry key for the all users under the local machine). It is installed with a couple of know programs including ZoneAlarm Free Firewall published by Check Point, Inc and ZoneAlarm Antivirus published by Check Point, Inc. The file is digitally signed by Check Point Software Technologies Ltd. which was issued by the VeriSign certificate authority (CA).
 Details
Details
| File name: | zatray.exe | 
| Publisher: | Check Point Software Technologies LTD | 
| Product name: | ZoneAlarm | 
| Typical file path: | C:\Program Files\checkpoint\zonealarm\zatray.exe | 
| File version: | 11.0.000.057 | 
| Size: | 72.1 KB (73,832 bytes) | 
| Certificate | 
| Issued to: | Check Point Software Technologies Ltd. | 
| Authority (CA): | VeriSign | 
| Expiration date: | Monday, May 5, 2014 | 
| Digital DNA | 
| PE subsystem: | Windows GUI | 
| File packed: | No | 
| Code language: | Microsoft Visual C++ 9.0 | 
| .NET CLR: | No | 
More details
 Programs
Programs
The following programs will install this file
The software is typically bundled with third party installers such as Open Candy. "Offer your users a free software firewall to help them protect their PC -- created by one of the world's leading security companies. Note: Includes ZoneAlarm Security Toolbar with ZoneAlarm homepage, search default and new tab page search."
 
“Detects and removes viruses, spyware, Trojan horses, worms, bots and more. Independently tested to provide superior protection. Restricts programs from malicious activities – blocking attacks that bypass other defenses. Antivirus by itself is on average only 68% effective against new threats and even two-way firewalls can’t keep all hackers out. Application Control stops malware from phoning home or turning your PC into a bot. Stops Int...”
 
 Behaviors
Behaviors
Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
- 'ZoneAlarm' → "C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe"
 Resource utilization
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
| CPU | 
| Total CPU: | 0.00123478% |  | 
| Kernel CPU: | 0.00111916% |  | 
| User CPU: | 0.00011562% |  | 
| Kernel CPU time: | 11,186 ms/min |  | 
| CPU cycles: | 4,223,937/sec |  | 
| Context switches: | 11/sec |  | 
| Memory | 
| Private memory: | 52.44 MB |  | 
| Private (maximum): | 19.24 MB |  | 
| Private (minimum): | 1.38 MB |  | 
| Non-paged memory: | 52.44 MB |  | 
| Virtual memory: | 141.19 MB |  | 
| Virtual memory (peak): | 151.59 MB |  | 
| Working set: | 4.67 MB |  | 
| Working set (peak): | 50.46 MB |  | 
| Page faults: | 355,116/min |  | 
| I/O | 
| I/O read transfer: | 2.31 KB/sec |  | 
| I/O read operations: | 1/sec |  | 
| I/O write transfer: | 8.36 KB/sec |  | 
| I/O write operations: | 471/sec |  | 
| I/O other transfer: | 18.82 KB/sec |  | 
| I/O other operations: | 288/sec |  | 
| Resource allocations | 
| Threads: | 13 |  | 
| Handles: | 312 |  | 
| GUI GDI count: | 134 |  | 
| GUI GDI peak: | 136 |  | 
| GUI USER count: | 10 |  | 
| GUI USER peak: | 14 |  | 
 
 Process properties
Process properties
| Integrety level: | Undefined | 
| Platform: | 32-bit | 
| Command lines: | 
"C:\Program Files\zone labs\zonealarm\zatray.exe""C:\Program Files\checkpoint\zonealarm\zatray.exe" | 
| Owner: | User | 
| Parent process: | Explorer.EXE (Windows Explorer by Microsoft) | 
 Threads
Threads
Averages
 
| MSVCR90.dll | 
| Total CPU: | 0.01865504% |  | 
| Kernel CPU: | 0.00358971% |  | 
| User CPU: | 0.01506533% |  | 
| Context switches: | 2/sec |  | 
| Memory: | 652 KB |  | 
| zatray.exe (main module) | 
| Total CPU: | 0.01078119% |  | 
| Kernel CPU: | 0.00088194% |  | 
| User CPU: | 0.00989924% |  | 
| CPU cycles: | 299,910/sec |  | 
| Memory: | 80 KB |  | 
 
Common loaded modules
These are modules that are typiclaly loaded within the context of this process.
 Distribution by Windows OS
Distribution by Windows OS
| OS version | distribution | 
| Windows 7 Home Premium | 60.00% |  | 
| Windows 7 Ultimate | 11.43% |  | 
| Microsoft Windows XP | 8.57% |  | 
| Windows 7 Professional | 5.71% |  | 
| Windows Vista Home Premium | 2.86% |  | 
| Windows Vista Home Basic | 2.86% |  | 
| Windows 8 Pro | 2.86% |  | 
| Windows 7 Ultimate N | 2.86% |  | 
| Windows Vista Ultimate | 2.86% |  | 
 Distribution by country
Distribution by country
United States installs about 60.00% of ZoneAlarm.
 Distribution by PC manufacturer
Distribution by PC manufacturer
| PC Manufacturer | distribution | 
| Acer | 40.00% |  | 
| Sony | 20.00% |  | 
| Hewlett-Packard | 20.00% |  | 
| Sahara | 10.00% |  | 
| Toshiba | 10.00% |  |