kentbcli.exe

AVM KEN!

AVM Computersysteme Vertriebs GmbH

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘KEN Taskbar Client’.
Publisher:
AVM Berlin, DATEV eG Nürnberg  (signed by AVM Computersysteme Vertriebs GmbH)

Product:
AVM KEN!

Description:
kentbcli

Version:
4.01.26.2011

MD5:
4e24dabe77c0baa42f52cbbc1df511a2

SHA-1:
c2ec53a225f32bcf17e2db16ffd04e55fb31ca67

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 11:11:26 AM UTC  (today)

File size:
273.4 KB (279,928 bytes)

Product version:
4.01.26.2011

Copyright:
© AVM Berlin 1999-2010, Copyright © DATEV eG, 2011

Original file name:
kentbcli.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/11/2010 1:00:00 AM

Valid to:
2/10/2013 12:59:59 AM

Subject:
CN=AVM Computersysteme Vertriebs GmbH, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=AVM Computersysteme Vertriebs GmbH, L=Berlin, S=Berlin, C=DE

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
262C83F316538BC43E17AFEF5FF41792

File PE Metadata
Compilation timestamp:
10/25/2011 3:50:08 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
6144:OYi2udg8NSDHTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTT+TTTTTTTTTTTc:CNzO

Entry address:
0x9D22

Entry point:
6A, 74, 68, 00, D5, 40, 00, E8, 32, 02, 00, 00, 33, DB, 89, 5D, E0, 53, 8B, 3D, F4, B0, 40, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03, C8, 81, 39, 50, 45, 00, 00, 75, 12, 0F, B7, 41, 18, 3D, 0B, 01, 00, 00, 74, 1F, 3D, 0B, 02, 00, 00, 74, 05, 89, 5D, E4, EB, 27, 83, B9, 84, 00, 00, 00, 0E, 76, F2, 33, C0, 39, 99, F8, 00, 00, 00, EB, 0E, 83, 79, 74, 0E, 76, E2, 33, C0, 39, 99, E8, 00, 00, 00, 0F, 95, C0, 89, 45, E4, 89, 5D, FC, 6A, 02, FF, 15, 3C, B5, 40, 00, 59, 83, 0D, 34, 0B, 41, 00, FF, 83...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
40 KB (40,960 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
KEN Taskbar Client

Command:
"C:\ken\kentbcli.exe"