klive.exe

KDrive

KINGSOFT JAPAN INC.

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘klive’. This is installed with KDrive.
Publisher:
Kingsoft Corp. Ltd.  (signed by KINGSOFT JAPAN INC.)

Product:
KDrive

Description:
KliveShell Module

Version:
1,21,0,866

MD5:
6c5b66821b298b231f1b61a90271191d

SHA-1:
f09a781a7660c8a6bf55b393509c6c128db84d2f

SHA-256:
152990925e4c6d4db1f9a84b4eb3863c01d9bf4c0cb1b083483901aca896e106

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/18/2024 3:41:27 AM UTC  (today)

File size:
2.5 MB (2,591,128 bytes)

Product version:
1,21,0,866

Copyright:
Copyright©1988-2010 Kingsoft Corporation. All rights reserved.

Original file name:
klive.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\kingsoft\klive\bin\klive.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
8/9/2010 5:54:52 PM

Valid to:
9/29/2011 10:54:12 AM

Subject:
CN=KINGSOFT JAPAN INC., O=KINGSOFT JAPAN INC., C=JP

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012A56275F04

File PE Metadata
Compilation timestamp:
6/1/2011 12:43:33 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:4ECmFf1BcYadeVHjBIJJgfSq0hsq/4UsRuWBzVAM/zZJqm0QtCfCjavnaLuei1oa:R7TcDYa4UpIAMbZJgo1TeV0mdBhKAA2

Entry address:
0xE42A0

Entry point:
E8, 4B, 5D, 01, 00, E9, 79, FE, FF, FF, CC, CC, CC, CC, CC, CC, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 69, 33, C0, 8A, 44, 24, 08, 84, C0, 75, 16, 81, FA, 00, 01, 00, 00, 72, 0E, 83, 3D, C4, 00, 58, 00, 00, 74, 05, E9, 01, 5E, 01, 00, 57, 8B, F9, 83, FA, 04, 72, 31, F7, D9, 83, E1, 03, 74, 0C, 2B, D1, 88, 07, 83, C7, 01, 83, E9, 01, 75, F6, 8B, C8, C1, E0, 08, 03, C1, 8B, C8, C1, E0, 10, 03, C1, 8B, CA, 83, E2, 03, C1, E9, 02, 74, 06, F3, AB, 85, D2, 74, 0A, 88, 07, 83, C7, 01, 83, EA, 01, 75, F6, 8B...
 
[+]

Entropy:
6.6014

Code size:
1.2 MB (1,243,136 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
klive

Command:
"C:\users\{user}\appdata\roaming\kingsoft\klive\bin\klive.exe" -autorun


The file klive.exe has been discovered within the following program.

KDrive  by Kingsoft Corp.
www.kingsoft.jp
About 3% of users remove it
 
Powered by Should I Remove It?

Scan klive.exe - Powered by Reason Core Security