knowhowcloud.exe

Knowhow Cloud

DSG Retail Limited

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘KnowhowCloud’.
Publisher:
DSG Retail Limited  (signed and verified)

Product:
Knowhow Cloud

Description:
Knowhow Cloud Desktop Client

Version:
2.0.0.0

MD5:
58d9974422f004c6a2214a7872cb2f51

SHA-1:
406cc3643763253643e3ae0abc256305af2b33b6

SHA-256:
500b9602760b64626b0f53c590ce53051cccbc302ce561eb6fae5296c73b9c62

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 7:37:52 PM UTC  (today)

File size:
3.6 MB (3,818,144 bytes)

Product version:
2.0.0.0

Copyright:
2013 DSG Retail Limited

Original file name:
Livedrive.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\knowhow cloud\knowhowcloud.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
9/26/2013 12:45:51 PM

Valid to:
9/26/2016 12:45:51 PM

Subject:
CN=DSG Retail Limited, O=DSG Retail Limited, L=Hemel Hempstead, S=Hertfordshire, C=GB

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121495C263926CD3E019E9B697461E92DB5

File PE Metadata
Compilation timestamp:
10/2/2013 11:52:21 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:w9WrdIZHPePtHjcOtayjrjr1o8Bwj7j7+pAIjs2q0QcAJhUAWQyZZEF5gdeeKcp7:wMpPVb5rP7cv7it8nDWFZE4EJir

Entry address:
0x39E046

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.6332

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
3.6 MB (3,785,216 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
KnowhowCloud

Command:
"C:\Program Files\knowhow cloud\knowhowcloud.exe" \setup


Scan knowhowcloud.exe - Powered by Reason Core Security