KUsrInit.exe

KACE Agent

Dell Inc.

Publisher:
Dell Inc.  (signed and verified)

Product:
KACE Agent

Description:
KUsrInit Application

Version:
5.4.5315

MD5:
c47e5d3ba5e161ecc36cca0dd99689ad

SHA-1:
a9f8ddb5ab9b9de0b0a5f490911a3d3d5459a47c

SHA-256:
a9ea0fa4a41bef3318490bb544d1055032959e6de5fd2b7a08e1fd929ee0ced1

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
5/7/2024 6:31:23 PM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
HW32.Keylogger
1.3.0.4959

File size:
376.6 KB (385,640 bytes)

Product version:
5.4.5315

Copyright:
© 2009-2012 Dell Inc.

Original file name:
KUsrInit.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Windows\System32\kusrinit.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
1/5/2011 11:48:17 AM

Valid to:
1/5/2014 11:48:13 AM

Subject:
CN=Dell Inc., OU=KACE, O=Dell Inc., L=Round Rock, S=Texas, C=US

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012D577BA226

File PE Metadata
Compilation timestamp:
11/6/2012 5:20:26 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:TCBg26VlfhoBGvOYoM0MguJdMbpQYuW7QBTOQzOWjxjOjsT40fsD:qgNkBGvOYsDuJ6GTOQzOWjxjOjsT40fM

Entry address:
0x3289

Entry point:
E8, 97, 3A, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 51, C7, 01, 40, 08, 41, 00, E8, 1F, 3B, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 56, 8B, F1, E8, E3, FF, FF, FF, F6, 45, 08, 01, 74, 07, 56, E8, 8E, 00, 00, 00, 59, 8B, C6, 5E, 5D, C2, 04, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 69, 33, C0, 8A, 44, 24, 08, 84, C0, 75, 16, 81, FA, 80, 00, 00, 00, 72, 0E, 83, 3D, 04, 6E, 41, 00, 00, 74, 05, E9, BC, 3B, 00, 00, 57, 8B, F9, 83, FA, 04, 72, 31, F7, D9, 83, E1, 03...
 
[+]

Entropy:
5.0216

Code size:
58 KB (59,392 bytes)

Scan KUsrInit.exe - Powered by Reason Core Security