kxetray.exe

Kingsoft Internet Security

Beijing Kingsoft Security software Co.,Ltd

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘kxesc’.
Publisher:
Kingsoft Corporation  (signed by Beijing Kingsoft Security software Co.,Ltd)

Product:
Kingsoft Internet Security

Description:
金山毒霸

Version:
2017,02,14,17534

MD5:
9b155bf41d69e6fc08fe8b626aa6b4ad

SHA-1:
92191461610d38ef252514756e8f23e365e91ea5

SHA-256:
c4a12183b31f6fd163a19e7833e04291b5df39278881e32772eb6801e1159c69

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/29/2024 10:42:24 PM UTC  (today)

File size:
1.7 MB (1,816,864 bytes)

Product version:
9,3,302731,17534

Copyright:
Copyright (C) 1998-2017 Kingsoft Corporation

Original file name:
kxetray.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\kingsoft\kingsoft antivirus\kxetray.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/22/2015 8:00:00 AM

Valid to:
2/20/2017 7:59:59 AM

Subject:
CN="Beijing Kingsoft Security software Co.,Ltd", OU=OPS, O="Beijing Kingsoft Security software Co.,Ltd", L=BeiJing, S=BeiJing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6E744ECE6B39EC11594755543471D551

File PE Metadata
Compilation timestamp:
2/14/2017 3:13:15 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0x105117

Entry point:
E8, B8, 03, 00, 00, E9, 36, FD, FF, FF, CC, CC, CC, 68, 7D, 51, 50, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 28, 40, 58, 00, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, FF, 74, 24, 10, FF, 74, 24, 10, FF, 74, 24, 10, FF, 74, 24, 10, 68, A0, 51, 50, 00, 68, 28, 40, 58, 00...
 
[+]

Entropy:
6.2324

Code size:
1 MB (1,099,776 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
kxesc

Command:
"C:\Program Files\kingsoft\kingsoft antivirus\kxetray.exe" -autorun


Scan kxetray.exe - Powered by Reason Core Security