kxetray.exe

Kingsoft Internet Security

KINGSOFT JAPAN, INC.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘kxesc’.
Publisher:
Kingsoft Corporation  (signed by KINGSOFT JAPAN, INC.)

Product:
Kingsoft Internet Security

Version:
2016,09,27,339

MD5:
33263ee6ead3d27cc4b2e6851922ca17

SHA-1:
254595edf8f94831796aa038b44586c26633be0f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 9:34:48 AM UTC  (today)

File size:
2.2 MB (2,263,000 bytes)

Product version:
9,3,291235,339

Copyright:
Copyright (C) 1998-2016 Kingsoft Corporation

Original file name:
kxetray.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\kingsoft\kingsoft internet security 2015\kxetray.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
4/18/2016 6:57:28 PM

Valid to:
12/31/2016 3:25:00 PM

Subject:
E=codesign@kingsoft.jp, CN="KINGSOFT JAPAN, INC.", OU=Administration Division, O="KINGSOFT JAPAN, INC.", L=Minato-ku, S=Tokyo, C=JP

Issuer:
CN=GlobalSign CodeSigning CA - G3, O=GlobalSign nv-sa, C=BE

Serial number:
048800C4C0D9BFD80364C176

File PE Metadata
Compilation timestamp:
9/27/2016 5:24:57 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
49152:Rbuud5PCM89oRiRZABTgLplO57Ziq1D+S39nacPPPPPPPPPPPPPPPPPPPPPPPPPx:Rbu2aM89oRiRZM1NwSa6J

Entry address:
0xD06DA

Entry point:
E8, B5, 03, 00, 00, E9, 36, FD, FF, FF, 3B, 0D, 28, 10, 54, 00, 75, 02, F3, C3, E9, 35, 04, 00, 00, CC, 68, 4D, 07, 4D, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 28, 10, 54, 00, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, FF, 74, 24, 10, FF, 74, 24, 10, FF, 74, 24, 10, FF...
 
[+]

Entropy:
6.6502

Code size:
867.5 KB (888,320 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
kxesc

Command:
"C:\Program Files\kingsoft\kingsoft internet security 2015\kxetray.exe" -autorun


Scan kxetray.exe - Powered by Reason Core Security