KHost.exe

Delivery Manager

Kontiki, Inc

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘kdx’. This is installed with Kontiki Media Manager.
Publisher:
Kontiki Inc.  (signed by Kontiki, Inc)

Product:
Delivery Manager

Version:
8.3.181.4

MD5:
d698ffc2684c7ea338b4b1289d3f7776

SHA-1:
3cae320b61785d135e95503a6afef5c6f05dbc07

SHA-256:
c155c076cd4406639c197afa19fb9658bf9a986cfb29fd4e3d48c53c1b4bea3d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 2:01:40 AM UTC  (today)

File size:
1.3 MB (1,379,968 bytes)

Product version:
8.3.181.4

Copyright:
Copyright 2001-2013 Kontiki, Inc.

Original file name:
KHost.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\kontiki\khost.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/7/2012 8:00:00 PM

Valid to:
6/5/2014 7:59:59 PM

Subject:
CN="Kontiki, Inc", OU=SECURE APPLICATION DEVELOPMENT, O="Kontiki, Inc", L=Mountain View, S=California, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
2DE8720EB3B7C31293EFB31FC771E080

File PE Metadata
Compilation timestamp:
11/8/2013 3:25:42 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:awP4E0RGUq0MoPE38ahq7g1FfPW9Z/4ocPKMHUoPGMmcPfhwbIkKxl2q+tUXjIlF:DP4E0RGUq0MoPE3/q7g1Ffu9Z/4ocT56

Entry address:
0xCFD28

Entry point:
E8, 31, F7, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, 3D, 48, 9C, 54, 00, 00, 56, 8B, 35, A4, 7E, 54, 00, 75, 04, 33, C0, EB, 63, 57, 85, F6, 75, 1B, 39, 35, AC, 7E, 54, 00, 74, 53, E8, 9F, F8, 00, 00, 85, C0, 75, 4A, 8B, 35, A4, 7E, 54, 00, 85, F6, 74, 40, 83, 7D, 08, 00, 74, 3A, FF, 75, 08, E8, 77, 9E, FF, FF, 59, 8B, F8, EB, 27, 50, E8, 6C, 9E, FF, FF, 59, 3B, C7, 76, 19, 8B, 06, 80, 3C, 38, 3D, 75, 11, 57, FF, 75, 08, 50, E8, 47, F8, 00, 00, 83, C4, 0C, 85, C0, 74, 0F, 83, C6, 04, 8B, 06, 85...
 
[+]

Entropy:
6.6965

Code size:
967 KB (990,208 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
kdx

Command:
C:\Program Files\kontiki\khost.exe -all


The file KHost.exe has been discovered within the following program.

Kontiki Media Manager  by Kontiki
About 6% of users remove it
 
Powered by Should I Remove It?

Scan KHost.exe - Powered by Reason Core Security