shelltray.exe

快看影视

FENGSHANG YUNQI Culture Media (Beijing) Co., Ltd

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘KKShowedFilms’.
Publisher:
kuaikan studio  (signed by FENGSHANG YUNQI Culture Media (Beijing) Co., Ltd)

Product:
快看影视

Description:
快看影视主程序

Version:
1.0.41.0329

MD5:
cba482aa1cd196e9fa239cf70e40f7e1

SHA-1:
db0d3477593ef2111cf9ebcfe2d321e6c3c208e8

SHA-256:
b60b976112ad5dbd719aa10bff139a5034076580e06bd0cfd4cfc3b5a00c3398

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 2:40:54 AM UTC  (today)

File size:
813.7 KB (833,240 bytes)

Product version:
1.0.41.0329

Copyright:
Copyright (C) 2015 kuaikan studio

Original file name:
KKfilms.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\kkshowedfilms\shelltray.exe

Digital Signature
Authority:
WoSign CA Limited

Valid from:
10/27/2015 2:51:09 PM

Valid to:
10/27/2016 2:51:09 PM

Subject:
CN="FENGSHANG YUNQI Culture Media (Beijing) Co., Ltd", O="FENGSHANG YUNQI Culture Media (Beijing) Co., Ltd", L=Beijing, S=Beijing, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA G2, O=WoSign CA Limited, C=CN

Serial number:
5BA22DD56638592FA5283CAFD23A41D9

File PE Metadata
Compilation timestamp:
3/29/2016 2:35:48 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x7F4EA

Entry point:
E8, B7, 7D, 00, 00, E9, 7F, FE, FF, FF, 3B, 0D, A0, 12, 4B, 00, 75, 02, F3, C3, E9, 66, 7F, 00, 00, 58, 59, 87, 04, 24, FF, E0, CC, CC, CC, CC, CC, CC, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 0F, 03, C1, 1B, C9, 0B, C1, 59, E9, 0A, 3E, 00, 00, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 07, 03, C1, 1B, C9, 0B, C1, 59, E9, F4, 3D, 00, 00, CC, CC, CC, CC, 55, 8B, EC, 83, EC, 18, 53, 8B, 5D, 0C, 56, 57, C6, 45, FF, 00, 8B, 7B, 08, 8D, 73, 10, 33, 3D, A0, 12, 4B, 00, C7, 45, F4, 01, 00, 00, 00, 8B, 07, 83, F8, FE, 74, 0D...
 
[+]

Entropy:
6.9316

Code size:
573 KB (586,752 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
KKShowedFilms

Command:
C:\Program Files\kkshowedfilms\shelltray.exe


Scan shelltray.exe - Powered by Reason Core Security