kxetray.exe

Kingsoft Internet Security

KINGSOFT JAPAN, INC.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘kxesc’.
Publisher:
Kingsoft Corporation  (signed by KINGSOFT JAPAN, INC.)

Product:
Kingsoft Internet Security

Description:
Kingsoft Antivirus Tray

Version:
2013,12,11,104

MD5:
8661d7f1e5e9b72bdebc58ef36f3276e

SHA-1:
53c8047bae7787039cfb603b37c6c7f7df2ba8e7

SHA-256:
16dad8c9b776939964923b409b4d3bd67667cc4f5aec8788866a5f60954e0e65

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 9:41:24 AM UTC  (today)

File size:
1.2 MB (1,262,872 bytes)

Product version:
9,0,136996,104

Copyright:
Copyright (C) 1998-2013 Kingsoft Corporation

Original file name:
kxetray.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\kingsoft\kingsoft antivirus\kxetray.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
10/30/2013 3:25:00 PM

Valid to:
10/31/2014 3:25:00 PM

Subject:
E=codesign@kingsoft.jp, CN="KINGSOFT JAPAN, INC.", OU=Engineering & Development Dept., O="KINGSOFT JAPAN, INC.", L=Minato-ku, S=Tokyo, C=JP

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121C2E61628723177993D8FC4D154EAF5D7

File PE Metadata
Compilation timestamp:
12/11/2013 4:31:45 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0x9E428

Entry point:
E8, B7, 03, 00, 00, E9, 36, FD, FF, FF, CC, CC, 68, 8D, E4, 49, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 20, 50, 4E, 00, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, FF, 74, 24, 10, FF, 74, 24, 10, FF, 74, 24, 10, FF, 74, 24, 10, 68, 8E, DE, 49, 00, 68, 20, 50, 4E, 00, E8...
 
[+]

Entropy:
6.8244

Code size:
711 KB (728,064 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
kxesc

Command:
"C:\Program Files\kingsoft\kingsoft antivirus\kxetray.exe" -autorun


Scan kxetray.exe - Powered by Reason Core Security