kxetray.exe

Kingsoft Internet Security

Beijing Kingsoft Internet Security Software Co.,Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘kxesc’.
Publisher:
Kingsoft Corporation  (signed by Beijing Kingsoft Internet Security Software Co.,Ltd.)

Product:
Kingsoft Internet Security

Description:
猎鹰

Version:
2015,01,13,819

MD5:
06c3c456674c2d7526f21347c4537529

SHA-1:
e6cfa40b00554abd7917c44e46379c306aa87f33

SHA-256:
8d2181e827c10102abd8e1f1450ca3706d1d107fdf8e0d0c8362404f0f6c75d5

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
2/26/2025 5:05:55 AM UTC  (today)

File size:
1.9 MB (2,036,808 bytes)

Product version:
9,0,215018,819

Copyright:
Copyright (C) 1998-2015 Kingsoft Corporation

Original file name:
kxetray.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\kpcsafe\kpcsafe new client\kxetray.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
7/13/2015 8:00:00 AM

Valid to:
7/13/2018 7:59:59 AM

Subject:
CN="Beijing Kingsoft Internet Security Software Co.,Ltd.", OU=Network Security dept., O="Beijing Kingsoft Internet Security Software Co.,Ltd.", L=Beijing, S=Beijing, C=CN

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
48357CD9BD2E097987D8464C36A7ACD4

File PE Metadata
Compilation timestamp:
1/28/2016 10:47:19 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:iHa2DNHSCrXgIPabV1ZPKHNv0rwl/jJYWH9twoHY3xTDL9BhEeT+Pwrchc2ccccs:oadCQbdQXYHTDL9BhEeMAF

Entry address:
0x135493

Entry point:
E8, BC, 03, 00, 00, E9, 36, FD, FF, FF, CC, FF, 25, 18, F8, 53, 00, 68, FD, 54, 53, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 28, 60, 5A, 00, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, FF, 74, 24, 10, FF, 74, 24, 10, FF, 74, 24, 10, FF, 74, 24, 10, 68, 20, 55, 53, 00, 68...
 
[+]

Entropy:
6.2909

Code size:
1.2 MB (1,299,456 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
kxesc

Command:
"C:\Program Files\kpcsafe\kpcsafe new client\kxetray.exe" -autorun


Scan kxetray.exe - Powered by Reason Core Security