kxetray.exe

Kingsoft Internet Security

KINGSOFT JAPAN, INC.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘kxesc’.
Publisher:
Kingsoft Corporation  (signed by KINGSOFT JAPAN, INC.)

Product:
Kingsoft Internet Security

Version:
2016,09,27,339

MD5:
1219df6e62140ba5ab88f89d800ff431

SHA-1:
7bd0fa54a0ff49fc67d20429d4aa1f07b888149e

SHA-256:
dd0db1bd9d38bec40434c02348474558d2875699b5e05bf931df74a4a01ff4e5

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 9:03:05 AM UTC  (today)

File size:
2.2 MB (2,263,000 bytes)

Product version:
9,3,291235,339

Copyright:
Copyright (C) 1998-2016 Kingsoft Corporation

Original file name:
kxetray.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\kingsoft\kingsoft internet security 2015\kxetray.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
4/18/2016 6:57:28 PM

Valid to:
12/31/2016 3:25:00 PM

Subject:
E=codesign@kingsoft.jp, CN="KINGSOFT JAPAN, INC.", OU=Administration Division, O="KINGSOFT JAPAN, INC.", L=Minato-ku, S=Tokyo, C=JP

Issuer:
CN=GlobalSign CodeSigning CA - G3, O=GlobalSign nv-sa, C=BE

Serial number:
048800C4C0D9BFD80364C176

File PE Metadata
Compilation timestamp:
9/27/2016 5:24:57 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
49152:Rbuud5PCM8doRiRZABTgLplO57Ziq1D+S39nacPPPPPPPPPPPPPPPPPPPPPPPPPx:Rbu2aM8doRiRZM1NwSa6J

Entry address:
0xD06DA

Entry point:
E8, B5, 03, 00, 00, E9, 36, FD, FF, FF, 3B, 0D, 28, 10, 54, 00, 75, 02, F3, C3, E9, 35, 04, 00, 00, CC, 68, 4D, 07, 4D, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 28, 10, 54, 00, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, FF, 74, 24, 10, FF, 74, 24, 10, FF, 74, 24, 10, FF...
 
[+]

Entropy:
6.6500

Code size:
867.5 KB (888,320 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
kxesc

Command:
"C:\Program Files\kingsoft\kingsoft internet security 2015\kxetray.exe" -autorun


Scan kxetray.exe - Powered by Reason Core Security