KWTray.exe

KidsWatch System Tray

Computer Business Solutions, Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘TCTray’.
Publisher:
© 2008 Computer Business Solutions, Inc.  (signed by Computer Business Solutions, Inc.)

Product:
KidsWatch System Tray

Description:
KidsWatch Tray

Version:
5, 0, 216, 17

MD5:
2f89769e0c40ba4cd9a3205772a01f49

SHA-1:
b79df38df9b95d8d0ee6438d16bc2a4ed19df118

SHA-256:
6fcd05837e744707149dac02cd9394831678d66e767e931868bb3e9f96e6e1e2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 6:57:02 AM UTC  (today)

File size:
161.3 KB (165,208 bytes)

Product version:
5, 0, 216, 17

Copyright:
Copyright © 2002-2008 Computer Business Solutions, Inc.

Trademarks:
Copyright © 2002-2008 Computer Business Solutions, Inc.

Original file name:
KWTray.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\kliksafe\kliktime\kwtray.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/11/2006 1:00:00 AM

Valid to:
12/11/2008 12:59:59 AM

Subject:
CN="Computer Business Solutions, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Computer Business Solutions, Inc.", L=Garden City, S=New York, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
725B05B4E6C85A56232B31DD336FF345

File PE Metadata
Compilation timestamp:
8/8/2008 8:04:28 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
3072:/1r1een0Sz9FeBmIa4sU94WORJHGq53oPNXWKwDnoV9ZHTavs3ttcv0scmjqTObD:9r11z/CwWO7Gg

Entry address:
0xCD0F

Entry point:
E8, B0, 04, 00, 00, E9, 35, FD, FF, FF, CC, CC, CC, 68, 88, C7, 40, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, DC, E5, 41, 00, 31, 45, FC, 33, C5, 89, 45, E4, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, E4, 33, CD, E8, FE, F9, FF, FF, E9, 22, 02, 00, 00, 6A, 14, 68, E0, 45, 41, 00, E8, D1, 01, 00, 00, 83, 65, FC, 00, FF, 4D, 10, 78, 3A, 8B, 4D, 08, 2B, 4D, 0C, 89...
 
[+]

Code size:
56 KB (57,344 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
TCTray

Command:
C:\Program Files\kliksafe\kliktime\kwtray.exe


Scan KWTray.exe - Powered by Reason Core Security