shelltray.exe

快看影视

FENGSHANG YUNQI Culture Media (Beijing) Co., Ltd

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘KKShowedFilms’.
Publisher:
kuaikan studio  (signed by FENGSHANG YUNQI Culture Media (Beijing) Co., Ltd)

Product:
快看影视

Description:
快看影视主程序

Version:
1.0.37.0318

MD5:
3aad15fd7db1d7068e2636589ef3d05f

SHA-1:
88b6ceef71d2e3522553e56ba51f654bf6b434e9

SHA-256:
0de5615212b226dcb19af5988de59bb82ecbfcb85c46dad5ee8d092d299f813f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/25/2024 7:17:35 PM UTC  (today)

File size:
814.2 KB (833,752 bytes)

Product version:
1.0.37.0318

Copyright:
Copyright (C) 2015 kuaikan studio

Original file name:
KKfilms.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\kkshowedfilms\shelltray.exe

Digital Signature
Authority:
WoSign CA Limited

Valid from:
10/27/2015 6:51:09 AM

Valid to:
10/27/2016 7:51:09 AM

Subject:
CN="FENGSHANG YUNQI Culture Media (Beijing) Co., Ltd", O="FENGSHANG YUNQI Culture Media (Beijing) Co., Ltd", L=Beijing, S=Beijing, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA G2, O=WoSign CA Limited, C=CN

Serial number:
5BA22DD56638592FA5283CAFD23A41D9

File PE Metadata
Compilation timestamp:
3/18/2016 3:37:07 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
24576:D7CTziQ6ySOCEaAbhHGyDq5M1S9dLSE41zcYopPUhDl:AlCEBU95Mg9dm5cxeDl

Entry address:
0x7F49A

Entry point:
E8, C7, 7D, 00, 00, E9, 7F, FE, FF, FF, 3B, 0D, A0, 12, 4B, 00, 75, 02, F3, C3, E9, 76, 7F, 00, 00, 58, 59, 87, 04, 24, FF, E0, CC, CC, CC, CC, CC, CC, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 0F, 03, C1, 1B, C9, 0B, C1, 59, E9, AA, 31, 00, 00, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 07, 03, C1, 1B, C9, 0B, C1, 59, E9, 94, 31, 00, 00, CC, CC, CC, CC, 55, 8B, EC, 83, EC, 18, 53, 8B, 5D, 0C, 56, 57, C6, 45, FF, 00, 8B, 7B, 08, 8D, 73, 10, 33, 3D, A0, 12, 4B, 00, C7, 45, F4, 01, 00, 00, 00, 8B, 07, 83, F8, FE, 74, 0D...
 
[+]

Entropy:
6.9283

Code size:
573 KB (586,752 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
KKShowedFilms

Command:
C:\Program Files\kkshowedfilms\shelltray.exe


Scan shelltray.exe - Powered by Reason Core Security