KHost.exe

Delivery Manager

Kontiki, Inc

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘kdx’. This file is installed with the program Kontiki Media Manager.
Publisher:
Kontiki Inc.  (signed by Kontiki, Inc)

Product:
Delivery Manager

Version:
8.3.185.5

MD5:
5c249c9b8f3d14a2a9d08d8764febb03

SHA-1:
4217c19f59206ebfae6558ff6ea9c6a7fc7ade0e

SHA-256:
a47a68fe41eea8768c2e755cd0f6747e66657f1eefd37603a075eb03b983d933

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/26/2024 9:51:37 AM UTC  (today)

Scan engine
Detection
Engine version

Boost by Reason
Optional.Startup.Kontiki.F
188838

File size:
1.3 MB (1,379,968 bytes)

Product version:
8.3.185.5

Copyright:
Copyright 2001-2014 Kontiki, Inc.

Original file name:
KHost.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\kontiki\khost.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/7/2012 4:00:00 PM

Valid to:
6/5/2014 3:59:59 PM

Subject:
CN="Kontiki, Inc", OU=SECURE APPLICATION DEVELOPMENT, O="Kontiki, Inc", L=Mountain View, S=California, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
2DE8720EB3B7C31293EFB31FC771E080

File PE Metadata
Compilation timestamp:
1/15/2014 11:24:13 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:pwP4E0RGUq0MoPE38ahq7g1FfPW9Z/4ocPKMHUoPGMmcPfhwbIkKxl2q+tUSjIlV:GP4E0RGUq0MoPE3/q7g1Ffu9Z/4ocT5B

Entry address:
0xCFD28

Entry point:
E8, 31, F7, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, 3D, 48, 9C, 54, 00, 00, 56, 8B, 35, A4, 7E, 54, 00, 75, 04, 33, C0, EB, 63, 57, 85, F6, 75, 1B, 39, 35, AC, 7E, 54, 00, 74, 53, E8, 9F, F8, 00, 00, 85, C0, 75, 4A, 8B, 35, A4, 7E, 54, 00, 85, F6, 74, 40, 83, 7D, 08, 00, 74, 3A, FF, 75, 08, E8, 77, 9E, FF, FF, 59, 8B, F8, EB, 27, 50, E8, 6C, 9E, FF, FF, 59, 3B, C7, 76, 19, 8B, 06, 80, 3C, 38, 3D, 75, 11, 57, FF, 75, 08, 50, E8, 47, F8, 00, 00, 83, C4, 0C, 85, C0, 74, 0F, 83, C6, 04, 8B, 06, 85...
 
[+]

Entropy:
6.6965

Code size:
967 KB (990,208 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
kdx

Command:
C:\Program Files\kontiki\khost.exe -all


The file KHost.exe has been discovered within the following program.

Kontiki Media Manager  by Kontiki
About 6% of users remove it
 
Powered by Should I Remove It?

Scan KHost.exe - Powered by Reason Core Security