kwifi.exe

Kingsoft Internet Security

Beijing Kingsoft Security software Co.,Ltd

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘kwifi’.
Publisher:
Kingsoft Corporation  (signed by Beijing Kingsoft Security software Co.,Ltd)

Product:
Kingsoft Internet Security

Description:
Kingsoft Wireless Manager

Version:
2014,12,26,1009

MD5:
6fa074f591e29a1245eef472a810aae4

SHA-1:
6b7c42a5108b2fd4ef985ccb44002f1792dd93b5

SHA-256:
b0dc371aec6ff2bf9a56ed9f61f18fb9acf244d3ac36c071188ef31b247a984e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/25/2024 6:20:31 PM UTC  (today)

File size:
2.6 MB (2,688,136 bytes)

Product version:
5,1,7700,1009

Copyright:
Copyright (C) 1998-2014 Kingsoft Corporation

Original file name:
kswireless.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\kingsoft\kwifi\kwifi.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
12/24/2014 8:00:00 AM

Valid to:
1/23/2018 7:59:59 AM

Subject:
CN="Beijing Kingsoft Security software Co.,Ltd", OU=IT, O="Beijing Kingsoft Security software Co.,Ltd", L=beijing, S=beijing, C=CN

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
39A0156D17E10ECA0C1486FE5F0E7DA1

File PE Metadata
Compilation timestamp:
12/26/2014 6:26:05 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
49152:oYnFUWkhb7Zt4qFsDubszpUsUgro2+lJBNST16VRW8IpeGezMa:o1eqaubnsUJXBjW8fGcMa

Entry address:
0x169D1D

Entry point:
E8, 12, 04, 00, 00, E9, 36, FD, FF, FF, CC, FF, 25, 30, 77, 59, 00, FF, 25, 2C, 77, 59, 00, 68, 8D, 9D, 56, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 2C, 10, 5F, 00, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, FF, 74, 24, 10, FF, 74, 24, 10, FF, 74, 24, 10, FF, 74, 24, 10...
 
[+]

Entropy:
6.6932

Code size:
1.6 MB (1,662,976 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
kwifi

Command:
"C:\Program Files\kingsoft\kwifi\kwifi.exe" \autorun


Scan kwifi.exe - Powered by Reason Core Security