kxetray.exe

Kingsoft Internet Security

Zhuhai Kingsoft Software Co.,Ltd

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘kxesc’.
Publisher:
Kingsoft Corporation  (signed by Zhuhai Kingsoft Software Co.,Ltd)

Product:
Kingsoft Internet Security

Description:
KXEngine Security Center Tray manager

Version:
2010,12,17,246

MD5:
b29e956b4377427eb9c65542fc796553

SHA-1:
932ccac5bed978cf2cac5fc5cf7e5af876013886

SHA-256:
74ce52a3f267119e9bc342946f6999d155202ebdcad506ba2091b47223c3d099

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 7:23:35 PM UTC  (today)

File size:
529.4 KB (542,104 bytes)

Product version:
9,0,25324,246

Copyright:
Copyright (C) 1998-2010 Kingsoft Corporation

Original file name:
kxetray.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\common files\kingsoft\kiscommon\kxetray.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/22/2009 8:00:00 AM

Valid to:
6/22/2012 7:59:59 AM

Subject:
CN="Zhuhai Kingsoft Software Co.,Ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Zhuhai Kingsoft Software Co.,Ltd", L=Zhuhai, S=Guangdong, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0BA4BC439930346B95694B4C7F2B981B

File PE Metadata
Compilation timestamp:
12/17/2010 10:13:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0x59CAA

Entry point:
E8, 89, 05, 00, 00, E9, DA, FC, FF, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 18, F2, 47, 00, 89, 0D, 14, F2, 47, 00, 89, 15, 10, F2, 47, 00, 89, 1D, 0C, F2, 47, 00, 89, 35, 08, F2, 47, 00, 89, 3D, 04, F2, 47, 00, 66, 8C, 15, 30, F2, 47, 00, 66, 8C, 0D, 24, F2, 47, 00, 66, 8C, 1D, 00, F2, 47, 00, 66, 8C, 05, FC, F1, 47, 00, 66, 8C, 25, F8, F1, 47, 00, 66, 8C, 2D, F4, F1, 47, 00, 9C, 8F, 05, 28, F2, 47, 00, 8B, 45, 00, A3, 1C, F2, 47, 00, 8B, 45, 04, A3, 20, F2, 47, 00, 8D, 45, 08, A3, 2C, F2, 47, 00, 8B...
 
[+]

Entropy:
6.1838

Code size:
420 KB (430,080 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
kxesc

Command:
"C:\Program Files\common files\kingsoft\kiscommon\kxetray.exe" -autorun


Scan kxetray.exe - Powered by Reason Core Security