kxetray.exe

Kingsoft Antivirus Corporate Edition

Beijing Kingsoft Security software Co.,Ltd

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘kxesc’.
Publisher:
Kingsoft Corporation  (signed by Beijing Kingsoft Security software Co.,Ltd)

Product:
Kingsoft Antivirus Corporate Edition

Description:
金山企业

Version:
2017,03,06,1404

MD5:
128b10eb89885cf776469b188b5a59bf

SHA-1:
d44c01e9aea2084bf7641243b785b9476ec3b9a4

SHA-256:
1d987ae1ffa74316fb66419687cafd09ef3347535f6913b725ae5614937c935e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 9:33:47 AM UTC  (today)

File size:
1.5 MB (1,595,544 bytes)

Product version:
8,0,20067,1404

Copyright:
Copyright (C) 1998-2017 Kingsoft Corporation

Original file name:
kxetray.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\kingsoft\kingsoft antivirus\kxetray.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/17/2017 8:00:00 AM

Valid to:
3/20/2019 7:59:59 AM

Subject:
CN="Beijing Kingsoft Security software Co.,Ltd", OU=IT, O="Beijing Kingsoft Security software Co.,Ltd", L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4C6D7B5EA289C274426434E65B417ABA

File PE Metadata
Compilation timestamp:
3/6/2017 8:51:25 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0xF226B

Entry point:
E8, 84, 03, 00, 00, E9, 36, FD, FF, FF, CC, FF, 25, 9C, E6, 4F, 00, 68, D5, 22, 4F, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 20, 40, 55, 00, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, FF, 74, 24, 10, FF, 74, 24, 10, FF, 74, 24, 10, FF, 74, 24, 10, 68, F8, 22, 4F, 00, 68...
 
[+]

Entropy:
6.2337

Code size:
1009 KB (1,033,216 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
kxesc

Command:
"C:\Program Files\kingsoft\kingsoft antivirus\kxetray.exe" -autorun


Scan kxetray.exe - Powered by Reason Core Security