kxetray.exe

Kingsoft Internet Security

KINGSOFT JAPAN, INC.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘kxesc’.
Publisher:
Kingsoft Corporation  (signed by KINGSOFT JAPAN, INC.)

Product:
Kingsoft Internet Security

Description:
Kingsoft Antivirus Tray

Version:
2014,02,18,141

MD5:
07980ab6580082f679ba44a0813ffbb4

SHA-1:
4bc6e615919b33fa8ffce1bea43ec5ff77c01def

SHA-256:
3a37811f61895c46a0c50665e43c3e3fe77c625ee05a98ec5c73328fb650fe1e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 9:27:54 AM UTC  (today)

File size:
1.2 MB (1,265,944 bytes)

Product version:
9,0,148768,141

Copyright:
Copyright (C) 1998-2014 Kingsoft Corporation

Original file name:
kxetray.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\kingsoft\kingsoft internet security 2015\kxetray.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
10/30/2013 3:25:00 PM

Valid to:
10/31/2014 3:25:00 PM

Subject:
E=codesign@kingsoft.jp, CN="KINGSOFT JAPAN, INC.", OU=Engineering & Development Dept., O="KINGSOFT JAPAN, INC.", L=Minato-ku, S=Tokyo, C=JP

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121C2E61628723177993D8FC4D154EAF5D7

File PE Metadata
Compilation timestamp:
2/18/2014 2:12:08 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0x9ED6A

Entry point:
E8, B5, 03, 00, 00, E9, 36, FD, FF, FF, 68, CD, ED, 49, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 20, 60, 4E, 00, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, FF, 74, 24, 10, FF, 74, 24, 10, FF, 74, 24, 10, FF, 74, 24, 10, 68, D0, E7, 49, 00, 68, 20, 60, 4E, 00, E8, CC, 03...
 
[+]

Entropy:
6.8216

Code size:
713.5 KB (730,624 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
kxesc

Command:
"C:\Program Files\kingsoft\kingsoft internet security 2015\kxetray.exe" -autorun


Scan kxetray.exe - Powered by Reason Core Security