cmtray.exe

Clean Master For PC

Beijing Kingsoft Security software Co.,Ltd

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘cmsc’.
Publisher:
Kingsoft Corporation  (signed by Beijing Kingsoft Security software Co.,Ltd)

Product:
Clean Master For PC

Description:
Clean Master

Version:
2015,03,31,96

MD5:
eb54b1a9137a69ca727a84188c4d3653

SHA-1:
8e0256597df6e0608e9a5a01e98c49f256180841

SHA-256:
74b72dd319e758e07349fcd76687f615418e0e881d64f680a96cdd01fefc65e2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/25/2024 6:44:12 PM UTC  (today)

File size:
753.8 KB (771,912 bytes)

Product version:
9,1,224061,96

Copyright:
Copyright (C) 1998-2015 Kingsoft Corporation

Original file name:
cmtray.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\cmcm\clean master\cmtray.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/7/2500 2:00:00 AM

Valid to:
3/10/2501 1:59:59 AM

Subject:
CN="Beijing Kingsoft Security software Co.,Ltd", OU=IT, O="Beijing Kingsoft Security software Co.,Ltd", L=beijing, S=beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7A1FE7676A4849DAEE2BFFC4A4FF4BD3

File PE Metadata
Compilation timestamp:
3/31/2015 9:09:41 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0x428FD

Entry point:
E8, 82, 03, 00, 00, E9, 36, FD, FF, FF, CC, 68, 61, 29, 44, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 20, C0, 45, 00, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, FF, 74, 24, 10, FF, 74, 24, 10, FF, 74, 24, 10, FF, 74, 24, 10, 68, 84, 29, 44, 00, 68, 20, C0, 45, 00, E8, 98...
 
[+]

Entropy:
7.1243

Code size:
291 KB (297,984 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
cmsc

Command:
"C:\Program Files\cmcm\clean master\cmtray.exe" -autorun


Scan cmtray.exe - Powered by Reason Core Security