kxetray.exe

Kingsoft Internet Security

Beijing Kingsoft Security software Co.,Ltd

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘kxesc’. This is installed with Kingsoft Antivirus 2012.
Publisher:
Kingsoft Corporation  (signed by Beijing Kingsoft Security software Co.,Ltd)

Product:
Kingsoft Internet Security

Description:
Kingsoft Antivirus Tray

Version:
2012,09,28,153

MD5:
4f11e95ca5577d3f5863c2ea0d0cc791

SHA-1:
e604333b4e33dc1141b2dd0bcd681eb2fd932ae8

SHA-256:
90fca2152d9b5a9cab5b4fceb9756ef6ecb52db27c80995c0d3f303f04132916

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 2:10:20 AM UTC  (today)

File size:
1.5 MB (1,595,056 bytes)

Product version:
9,0,82500,153

Copyright:
Copyright (C) 1998-2012 Kingsoft Corporation

Original file name:
kxetray.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\kingsoft\kingsoft antivirus\kxetray.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/26/2011 1:00:00 AM

Valid to:
12/26/2014 12:59:59 AM

Subject:
CN="Beijing Kingsoft Security software Co.,Ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Beijing Kingsoft Security software Co.,Ltd", L=beijing, S=beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
07BC3A51B589E5AF43291DF84EA4C571

File PE Metadata
Compilation timestamp:
9/28/2012 4:51:36 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
49152:oSmqvDXnDw2vV8bZyw/gTogfL/M+mULdYYPPPPPPPPPPPPPPPPPPPPPPPPPPPPPT:oSmsTlV+ZywcqO

Entry address:
0xB42FD

Entry point:
E8, B2, 03, 00, 00, E9, 36, FD, FF, FF, CC, 68, 61, 43, 4B, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 20, 30, 51, 00, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, FF, 74, 24, 10, FF, 74, 24, 10, FF, 74, 24, 10, FF, 74, 24, 10, 68, A9, 3D, 4B, 00, 68, 20, 30, 51, 00, E8, C8...
 
[+]

Code size:
805.5 KB (824,832 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
kxesc

Command:
"C:\Program Files\kingsoft\kingsoft antivirus\kxetray.exe" -autorun


The file kxetray.exe has been discovered within the following program.

Kingsoft Antivirus 2012  by Kingsoft Security
Publisher's description - “Kingsoft Antivirus 2012 is a completely free antivirus solution for detecting, cleaning trojan virus, and protect your computer. It can be a standalone product, and can also work along with other AV.”
www.ijinshan.com
10% remove it
 
Powered by Should I Remove It?

Scan kxetray.exe - Powered by Reason Core Security