KSafeTray.exe

Kingsoft PC Doctor

Kingsoft Security Co.,Ltd

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘KSafeTray’. This is installed with Kingsoft PC Doctor 3.7.0.47.
Publisher:
Kingsoft Corporation  (signed by Kingsoft Security Co.,Ltd)

Product:
Kingsoft PC Doctor

Description:
PC Doctor Flow Monitor

Version:
3.7.0.47

MD5:
5be101cb8bb688839e9203e827684c41

SHA-1:
458495345618efda452ff00d688f5ff689a4b1e4

SHA-256:
cc6f7d46abfcbd67549fe353ff533369acd58b7f833c236161f036cd3b7de6a9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 12:04:39 AM UTC  (today)

File size:
725.4 KB (742,816 bytes)

Product version:
3.7.0.47

Copyright:
Copyright (C) 1998-2012 Kingsoft Corporation

Original file name:
KSafeTray.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\kingsoft\pcdoctor\ksafetray.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/8/2010 7:00:00 PM

Valid to:
3/8/2013 6:59:59 PM

Subject:
CN="Kingsoft Security Co.,Ltd", OU=Kingsoft Duba, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Kingsoft Security Co.,Ltd", L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
11B3AF5DB11EC91D1CF0B3E1B80C85E4

File PE Metadata
Compilation timestamp:
4/11/2012 2:35:36 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:35ZRgZBhhwRoJngb61V4UlDM5CNrx1eJ266+7D6chheDxi9v6F7ObdZydf43AVdG:35ZMBzioJngbcV4HG1GDfheDxzFaB4du

Entry address:
0x7083C

Entry point:
E8, B3, 03, 00, 00, E9, 36, FD, FF, FF, CC, CC, 68, A1, 08, 47, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 20, 70, 4A, 00, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, FF, 74, 24, 10, FF, 74, 24, 10, FF, 74, 24, 10, FF, 74, 24, 10, 68, 80, 04, 47, 00, 68, 20, 70, 4A, 00, E8...
 
[+]

Entropy:
6.2475

Code size:
508 KB (520,192 bytes)

Scheduled Task
Task name:
KsafeDelay

Trigger:
Logon (Runs on logon)


Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
KSafeTray

Command:
"C:\Program Files\kingsoft\pcdoctor\ksafetray.exe" -autorun


The file KSafeTray.exe has been discovered within the following program.

Kingsoft PC Doctor 3.7.0.47  by Kingsoft Security
Publisher's description - “Kingsoft PC Doctor, which focuses on providing computer users excellent privacy cleaner, registry cleaner and, brilliant Windows optimization service, is your best free professional and easy-to-use Windows Diagnosis and Optimization software.”
pcdoctor.kingsoft.com
56% remove it
 
Powered by Should I Remove It?

Scan KSafeTray.exe - Powered by Reason Core Security