kxetray.exe

Kingsoft Internet Security

KINGSOFT JAPAN, INC.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘kxesc’.
Publisher:
Kingsoft Corporation  (signed by KINGSOFT JAPAN, INC.)

Product:
Kingsoft Internet Security

Version:
2016,09,27,339

MD5:
33263ee6ead3d27cc4b2e6851922ca17

SHA-1:
8cc213fb6d92ed3700ffb216ab58941a433fe54a

SHA-256:
c1a5ccde0e1e687d98e36bfa6a907dd356381ee5219c07cd53bdab33acbbd63b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 9:24:32 AM UTC  (today)

File size:
2.2 MB (2,263,000 bytes)

Product version:
9,3,291235,339

Copyright:
Copyright (C) 1998-2016 Kingsoft Corporation

Original file name:
kxetray.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\kingsoft\kingsoft internet security 2015\kxetray.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
4/18/2016 6:57:28 PM

Valid to:
12/31/2016 3:25:00 PM

Subject:
E=codesign@kingsoft.jp, CN="KINGSOFT JAPAN, INC.", OU=Administration Division, O="KINGSOFT JAPAN, INC.", L=Minato-ku, S=Tokyo, C=JP

Issuer:
CN=GlobalSign CodeSigning CA - G3, O=GlobalSign nv-sa, C=BE

Serial number:
048800C4C0D9BFD80364C176

File PE Metadata
Compilation timestamp:
9/27/2016 5:24:57 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0xD06DA

Entry point:
E8, B5, 03, 00, 00, E9, 36, FD, FF, FF, 3B, 0D, 28, 10, 54, 00, 75, 02, F3, C3, E9, 35, 04, 00, 00, CC, 68, 4D, 07, 4D, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 28, 10, 54, 00, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, FF, 74, 24, 10, FF, 74, 24, 10, FF, 74, 24, 10, FF...
 
[+]

Entropy:
6.6502

Code size:
867.5 KB (888,320 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
kxesc

Command:
"C:\Program Files\kingsoft\kingsoft internet security 2015\kxetray.exe" -autorun


Scan kxetray.exe - Powered by Reason Core Security