KHost.exe

Delivery Manager

Kontiki, Inc

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘kdx’. This is installed with Kontiki Media Manager.
Publisher:
Kontiki Inc.  (signed by Kontiki, Inc)

Product:
Delivery Manager

Version:
8.3.169.0

MD5:
6a84aacfe26f10eb34d497810b3323a2

SHA-1:
ca338c637d50b83e94c5d0d682c5916d33603ae3

SHA-256:
69ee351f1430be314bed78cc1dfda94a90d62b4bfe1b98754353eeb5d7ddf576

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 12:01:26 PM UTC  (today)

File size:
1.3 MB (1,379,456 bytes)

Product version:
8.3.169.0

Copyright:
Copyright 2001-2013 Kontiki, Inc.

Original file name:
KHost.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\kontiki\khost.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/7/2012 8:00:00 PM

Valid to:
6/5/2014 7:59:59 PM

Subject:
CN="Kontiki, Inc", OU=SECURE APPLICATION DEVELOPMENT, O="Kontiki, Inc", L=Mountain View, S=California, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
2DE8720EB3B7C31293EFB31FC771E080

File PE Metadata
Compilation timestamp:
7/9/2013 12:34:49 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:WkGAynmEjWuc7E1kKjUGo5iu/k/ihVa6upWSKM5K/tQbHsrKbjIvVl3O:RGhnmEjWuc7E6KjUGoD/5hVa6ulKUKyv

Entry address:
0xCFC28

Entry point:
E8, 8B, F7, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, 3D, 48, 9C, 54, 00, 00, 56, 8B, 35, A4, 7E, 54, 00, 75, 04, 33, C0, EB, 63, 57, 85, F6, 75, 1B, 39, 35, AC, 7E, 54, 00, 74, 53, E8, F9, F8, 00, 00, 85, C0, 75, 4A, 8B, 35, A4, 7E, 54, 00, 85, F6, 74, 40, 83, 7D, 08, 00, 74, 3A, FF, 75, 08, E8, 77, 9E, FF, FF, 59, 8B, F8, EB, 27, 50, E8, 6C, 9E, FF, FF, 59, 3B, C7, 76, 19, 8B, 06, 80, 3C, 38, 3D, 75, 11, 57, FF, 75, 08, 50, E8, A1, F8, 00, 00, 83, C4, 0C, 85, C0, 74, 0F, 83, C6, 04, 8B, 06, 85...
 
[+]

Entropy:
6.6980

Code size:
966.5 KB (989,696 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
kdx

Command:
C:\Program Files\kontiki\khost.exe -all


The file KHost.exe has been discovered within the following program.

Kontiki Media Manager  by Kontiki
About 6% of users remove it
 
Powered by Should I Remove It?

Scan KHost.exe - Powered by Reason Core Security