kistray.exe

Kingsoft Internet Security

Beijing Kingsoft Internet Security Software Co.,Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘kisEnterpriseSecurity’.
Publisher:
Kingsoft Corporation  (signed by Beijing Kingsoft Internet Security Software Co.,Ltd.)

Product:
Kingsoft Internet Security

Description:
Kingsoft Internet Security FEI Tray

Version:
2015, 1, 7, 1

MD5:
82a3607cda933f8b2756a69b96e6793b

SHA-1:
6390dd86403cb6b3ada2bb66cebff0693408292f

SHA-256:
c8880b15e0f968b5a3bf0c828c98f9c3cf24d9ae516ea82ba39c1ed4c99ae2a7

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
2/26/2025 5:46:30 AM UTC  (today)

File size:
513.6 KB (525,904 bytes)

Product version:
1, 2, 0, 2

Copyright:
Copyright (C) 1998-2014 Kingsoft Corporation

Original file name:
KisTray

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\kingsoft\enterprise security\kistray.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
7/13/2015 8:00:00 AM

Valid to:
7/13/2018 7:59:59 AM

Subject:
CN="Beijing Kingsoft Internet Security Software Co.,Ltd.", OU=Network Security dept., O="Beijing Kingsoft Internet Security Software Co.,Ltd.", L=Beijing, S=Beijing, C=CN

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
48357CD9BD2E097987D8464C36A7ACD4

File PE Metadata
Compilation timestamp:
9/14/2015 1:21:29 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:623xzUcvlFenxeBHGpihJJXOvED39qLfdd7iH18:62hzUcvls0BHGpYXdD3md7O8

Entry address:
0x3EDFE

Entry point:
E8, BE, 02, 00, 00, E9, 49, FE, FF, FF, FF, 25, 24, 33, 44, 00, FF, 25, 28, 33, 44, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 68, 79, EE, 43, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 00, 10, 45, 00, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, 55, 8B, EC, FF, 75...
 
[+]

Entropy:
6.3654

Code size:
262.5 KB (268,800 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
kisEnterpriseSecurity

Command:
"C:\Program Files\kingsoft\enterprise security\kistray.exe" -autorun


Scan kistray.exe - Powered by Reason Core Security