kwtbaim.exe

Kiwee Toolbar

American Greetings, Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘KiweeHook’.
Publisher:
AG Interactive  (signed by American Greetings, Inc.)

Product:
Kiwee Toolbar

Version:
2.8.0.167

MD5:
7e39ecd22fd96436a161741ecf06fb38

SHA-1:
7e181ff9b5fc9668f8685592178b90511c7e14c5

SHA-256:
c6341f8f6ab68570d8d92f624510379ad7d99684c2139c3743dfbf50af2af8d3

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 8:51:42 AM UTC  (today)

File size:
55.1 KB (56,456 bytes)

Product version:
2.8.0.167

Copyright:
Copyright © 2007. AG Interactive, Inc. All rights reserved.

Original file name:
kwtbaim.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\kiwee toolbar\3.1\kwtbaim.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/6/2006 2:00:00 AM

Valid to:
11/18/2009 12:59:59 AM

Subject:
CN="American Greetings, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="American Greetings, Inc.", L=Cleveland, S=OH, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1B19336ECEEC6FDE6D5E559B9065B037

File PE Metadata
Compilation timestamp:
10/21/2009 8:53:03 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
768:UntSLWjE7MJAOapURQj0aRX7iAk7O5rTkgJbb/:kSajEu/apMYX7iBO5rggJX/

Entry address:
0x4954

Entry point:
E8, BB, 03, 00, 00, E9, 3A, FD, FF, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, F8, 91, 40, 00, 89, 0D, F4, 91, 40, 00, 89, 15, F0, 91, 40, 00, 89, 1D, EC, 91, 40, 00, 89, 35, E8, 91, 40, 00, 89, 3D, E4, 91, 40, 00, 66, 8C, 15, 10, 92, 40, 00, 66, 8C, 0D, 04, 92, 40, 00, 66, 8C, 1D, E0, 91, 40, 00, 66, 8C, 05, DC, 91, 40, 00, 66, 8C, 25, D8, 91, 40, 00, 66, 8C, 2D, D4, 91, 40, 00, 9C, 8F, 05, 08, 92, 40, 00, 8B, 45, 00, A3, FC, 91, 40, 00, 8B, 45, 04, A3, 00, 92, 40, 00, 8D, 45, 08, A3, 0C, 92, 40, 00, 8B...
 
[+]

Code size:
20 KB (20,480 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
KiweeHook

Command:
"C:\Program Files\kiwee toolbar\3.1\kwtbaim.exe"


Scan kwtbaim.exe - Powered by Reason Core Security