kjrili.exe

SimpleCalendar

北京百聚互动广告有限公司

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘KpAcdSee’.
Publisher:
北京百聚互动广告有限公司  (signed and verified)

Product:
SimpleCalendar

Version:
2.0.2.5

MD5:
04382c5d9ed669ed393c7914258170b5

SHA-1:
c3c93ffb29d877fffc78e585c5ba9c6e1798b218

SHA-256:
d40c05da2d5b43e1b51aec0821ac369cbed7287340be31743013a9c6232ef0da

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/1/2024 7:34:51 AM UTC  (today)

File size:
782.1 KB (800,840 bytes)

Product version:
2.0.2.5

Copyright:
重庆趣玩科技有限公司版权所有Copyright (C) 2016

Original file name:
SimpleCalendar.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\kjrili\kjrili.exe

Digital Signature
Authority:
WoSign CA Limited

Valid from:
8/17/2015 8:28:17 AM

Valid to:
8/17/2016 8:28:17 AM

Subject:
CN=北京百聚互动广告有限公司, O=北京百聚互动广告有限公司, L=北京市, S=北京市, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA, O=WoSign CA Limited, C=CN

Serial number:
35AC89B865FC1B741C81BF1A54CECEC4

File PE Metadata
Compilation timestamp:
3/17/2016 11:39:37 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:IdjLBetgFKH0b/NylVoEGJEcD+qD/TC8SF0g1TPEUBBgO0TsZjiB/rkME1KE1n:U3ctg8u/NylCEGaKfA0g1TGTcaE1KE1n

Entry address:
0x47310

Entry point:
E8, CD, 99, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 83, FB, E0, 77, 6F, 56, 57, 83, 3D, 3C, CA, 4A, 00, 00, 75, 18, E8, E0, 7A, 00, 00, 6A, 1E, E8, 2A, 79, 00, 00, 68, FF, 00, 00, 00, E8, 9C, 74, 00, 00, 59, 59, 85, DB, 74, 04, 8B, C3, EB, 03, 33, C0, 40, 50, 6A, 00, FF, 35, 3C, CA, 4A, 00, FF, 15, 7C, 92, 48, 00, 8B, F8, 85, FF, 75, 26, 6A, 0C, 5E, 39, 05, 74, CA, 4A, 00, 74, 0D, 53, E8, EB, 3B, 00, 00, 59, 85, C0, 75, A9, EB, 07, E8, E3, 3D, 00, 00, 89, 30, E8, DC, 3D, 00, 00, 89...
 
[+]

Entropy:
6.6736

Code size:
543 KB (556,032 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
KpAcdSee

Command:
C:\Program Files\kjrili\kjrili.exe -start


Scan kjrili.exe - Powered by Reason Core Security