shelltray.exe

快看影视

FENGSHANG YUNQI Culture Media (Beijing) Co., Ltd

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘KKShowedFilms’.
Publisher:
kuaikan studio  (signed by FENGSHANG YUNQI Culture Media (Beijing) Co., Ltd)

Product:
快看影视

Description:
快看影视主程序

Version:
1.0.38.0323

MD5:
7529c89dc95b4aa0d1668ae56038919f

SHA-1:
be0e8495e9089a4d3084ce7da25c24f4dc1d5bed

SHA-256:
a4d68aece7abf536d8b57620debd49a64195f915b009b00e89d2803d12818817

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 2:51:49 AM UTC  (today)

File size:
814.2 KB (833,752 bytes)

Product version:
1.0.38.0323

Copyright:
Copyright (C) 2015 kuaikan studio

Original file name:
KKfilms.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\kkshowedfilms\shelltray.exe

Digital Signature
Authority:
WoSign CA Limited

Valid from:
10/27/2015 2:51:09 PM

Valid to:
10/27/2016 2:51:09 PM

Subject:
CN="FENGSHANG YUNQI Culture Media (Beijing) Co., Ltd", O="FENGSHANG YUNQI Culture Media (Beijing) Co., Ltd", L=Beijing, S=Beijing, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA G2, O=WoSign CA Limited, C=CN

Serial number:
5BA22DD56638592FA5283CAFD23A41D9

File PE Metadata
Compilation timestamp:
3/23/2016 1:41:21 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
24576:Waql0KuFbcAtt1GQOVBO9O336e5MvzUiGboFtYBoPUWYRTi:kE1GQpoP5M7UiqB6YRTi

Entry address:
0x7F4BA

Entry point:
E8, B7, 7D, 00, 00, E9, 7F, FE, FF, FF, 3B, 0D, A0, 12, 4B, 00, 75, 02, F3, C3, E9, 66, 7F, 00, 00, 58, 59, 87, 04, 24, FF, E0, CC, CC, CC, CC, CC, CC, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 0F, 03, C1, 1B, C9, 0B, C1, 59, E9, 0A, 3E, 00, 00, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 07, 03, C1, 1B, C9, 0B, C1, 59, E9, F4, 3D, 00, 00, CC, CC, CC, CC, 55, 8B, EC, 83, EC, 18, 53, 8B, 5D, 0C, 56, 57, C6, 45, FF, 00, 8B, 7B, 08, 8D, 73, 10, 33, 3D, A0, 12, 4B, 00, C7, 45, F4, 01, 00, 00, 00, 8B, 07, 83, F8, FE, 74, 0D...
 
[+]

Entropy:
6.9305

Code size:
573 KB (586,752 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
KKShowedFilms

Command:
C:\Program Files\kkshowedfilms\shelltray.exe


Scan shelltray.exe - Powered by Reason Core Security