Kepard.exe

Kepard

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Kepard’. This is installed with Kepard.
Publisher:
Kepard

Description:
Kepard

Version:
1.0.8.5

MD5:
afaa46ff179824028948320d2f3b6b99

SHA-1:
165e8fa87698c6a50eed304645f766b729e4703a

SHA-256:
61cf1f0a5bb42eec8123a3dbd701b0797d770ff1e5056d133f244d2f6f8d0e53

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 12:00:26 PM UTC  (today)

File size:
729 KB (746,496 bytes)

Product version:
1.0.8.5

Copyright:
Kepard, Inc.

Original file name:
Kepard.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\kepard\kepard.exe

File PE Metadata
Compilation timestamp:
3/5/2013 5:24:54 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:FrZDNZ/PVgv7PQX5MY+Uyi6XZXTTT2RhnFWdwZKjj/lEEiJnwHZ3q++odQL2LntS:Fro00izE8j01ZWc/6GhGE7B/K

Entry address:
0x91E6E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.2539

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
576 KB (589,824 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Kepard

Command:
"C:\Program Files\kepard\kepard.exe" tray


The file Kepard.exe has been discovered within the following program.

Kepard  by Kepard
www.kepard.com
About 1% of users remove it
 
Powered by Should I Remove It?

Scan Kepard.exe - Powered by Reason Core Security