shelltray.exe

快看影视

FENGSHANG YUNQI Culture Media (Beijing) Co., Ltd

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘KKShowedFilms’.
Publisher:
kuaikan studio  (signed by FENGSHANG YUNQI Culture Media (Beijing) Co., Ltd)

Product:
快看影视

Description:
快看影视主程序

Version:
1.0.34.0228

MD5:
f1d40a6a95be05dbe5237dfaae95f2e4

SHA-1:
92ea41ab7087dd4023a2299c93c7dd17b9591e63

SHA-256:
bb7ade176ed9b72d1c1e702d96825fe04038f6b5bec678456362a87dc0b9a2fd

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 2:30:27 AM UTC  (today)

File size:
814.2 KB (833,752 bytes)

Product version:
1.0.34.0228

Copyright:
Copyright (C) 2015 kuaikan studio

Original file name:
KKfilms.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\kkshowedfilms\shelltray.exe

Digital Signature
Authority:
WoSign CA Limited

Valid from:
10/27/2015 3:51:09 PM

Valid to:
10/27/2016 3:51:09 PM

Subject:
CN="FENGSHANG YUNQI Culture Media (Beijing) Co., Ltd", O="FENGSHANG YUNQI Culture Media (Beijing) Co., Ltd", L=Beijing, S=Beijing, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA G2, O=WoSign CA Limited, C=CN

Serial number:
5BA22DD56638592FA5283CAFD23A41D9

File PE Metadata
Compilation timestamp:
2/29/2016 12:36:35 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
24576:WUkCffjk7DwzkSnG5Lpj26OL5MDjga3cTNPUPx5L:4uiSna075MvgB65L

Entry address:
0x7F3BA

Entry point:
E8, 16, 75, 00, 00, E9, 7F, FE, FF, FF, 3B, 0D, A0, 12, 4B, 00, 75, 02, F3, C3, E9, C5, 76, 00, 00, 58, 59, 87, 04, 24, FF, E0, CC, CC, CC, CC, CC, CC, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 0F, 03, C1, 1B, C9, 0B, C1, 59, E9, EA, 46, 00, 00, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 07, 03, C1, 1B, C9, 0B, C1, 59, E9, D4, 46, 00, 00, CC, CC, CC, CC, 55, 8B, EC, 83, EC, 18, 53, 8B, 5D, 0C, 56, 57, C6, 45, FF, 00, 8B, 7B, 08, 8D, 73, 10, 33, 3D, A0, 12, 4B, 00, C7, 45, F4, 01, 00, 00, 00, 8B, 07, 83, F8, FE, 74, 0D...
 
[+]

Entropy:
6.9311

Code size:
573 KB (586,752 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
KKShowedFilms

Command:
C:\Program Files\kkshowedfilms\shelltray.exe


Scan shelltray.exe - Powered by Reason Core Security