newword.exe

Kingsoft PowerWord

Zhuhai Kingsoft Software Co.,Ltd

Publisher:
Kingsoft Corporation  (signed by Zhuhai Kingsoft Software Co.,Ltd)

Product:
Kingsoft PowerWord

Version:
2013, 10, 28, 31

MD5:
396028c85211ca7076e68ef600778055

SHA-1:
8ce1665a694f5e973087b405f0685f67476ed81d

SHA-256:
6cd6e7f04ea1be6228917582a1ffa0728732d45e6b182bdd652f3ef4a4c5724d

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/20/2024 4:22:20 AM UTC  (today)

Scan engine
Detection
Engine version

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.693

Norman
Malware
11.20160208

File size:
1.1 MB (1,108,336 bytes)

Product version:
2013, 10, 28, 31

Copyright:
Copyright (c) Kingsoft Corporation Limited. All rights reserved.

Original file name:
NewWord2008.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Common path:
C:\Program Files\kingsoft\powerworddict\newword.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/29/2012 8:00:00 PM

Valid to:
7/8/2015 7:59:59 PM

Subject:
CN="Zhuhai Kingsoft Software Co.,Ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Zhuhai Kingsoft Software Co.,Ltd", L=Zhuhai, S=Guangdong, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7BFD453A9507D02E0183A6C815679E5F

File PE Metadata
Compilation timestamp:
12/3/2013 8:26:35 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:yxO60z4oVYVU4SP3wxQuvBb79hYTU1hAbfgwD+R6:mO60z4lUv3wuuF79hYTUfAUwD+6

Entry address:
0x7395C

Entry point:
E8, 5D, A8, 00, 00, E9, 17, FE, FF, FF, 55, 8B, EC, 83, EC, 20, 53, 33, DB, 39, 5D, 0C, 75, 1D, E8, CE, 55, 00, 00, 53, 53, 53, 53, 53, C7, 00, 16, 00, 00, 00, E8, CE, 0B, 00, 00, 83, C4, 14, 83, C8, FF, EB, 69, 8B, 45, 08, 3B, C3, 74, DC, 56, FF, 75, 14, 89, 45, E8, FF, 75, 10, 89, 45, E0, FF, 75, 0C, 8D, 45, E0, 50, C7, 45, EC, 42, 00, 00, 00, C7, 45, E4, FF, FF, FF, 7F, E8, 8C, AA, 00, 00, 83, C4, 10, FF, 4D, E4, 8B, F0, 78, 0A, 8B, 45, E0, 88, 18, FF, 45, E0, EB, 0C, 8D, 45, E0, 50, 53, E8, 75, A8, 00...
 
[+]

Entropy:
6.2106

Code size:
704 KB (720,896 bytes)

Scan newword.exe - Powered by Reason Core Security