knowhowcloud.exe

Knowhow Cloud

DSG Retail Limited

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘KnowhowCloud’.
Publisher:
DSG Retail Limited  (signed and verified)

Product:
Knowhow Cloud

Description:
Knowhow Cloud Desktop Client

Version:
2.0.2.179

MD5:
3fcd241950833db05e390aea2f883eea

SHA-1:
b6eeb0ff3032c3af35d7a2fc51af4a162bc9c20d

SHA-256:
4404f5b71e5ad00da312b6ece045123a78d0f08f9769a4a2e81298bcb64cdf29

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/30/2024 11:06:53 AM UTC  (today)

File size:
3.6 MB (3,784,864 bytes)

Product version:
2.0.2.179

Copyright:
2013 DSG Retail Limited

Original file name:
Livedrive.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\knowhow cloud\knowhowcloud.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
9/26/2013 12:45:51 PM

Valid to:
9/26/2016 12:45:51 PM

Subject:
CN=DSG Retail Limited, O=DSG Retail Limited, L=Hemel Hempstead, S=Hertfordshire, C=GB

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121495C263926CD3E019E9B697461E92DB5

File PE Metadata
Compilation timestamp:
11/1/2013 10:05:25 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
98304:od5Li0uFuCYsm10SADcnR0evtZbL98E8nv3Kup6e:sNixFuCq0SNnR0elZbBz8nv3Kuz

Entry address:
0x382DEA

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 04, 00, 03, 00, 00, 00, 30, 00, 00, 80, 0E, 00, 00, 00, D8, 8F, 01, 80, 10, 00, 00, 00, 6E, 90, 01, 80, 18, 00, 00, 00, 3E, 94, 01, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 06, 00, 02, 00, 00, 00, 70, 00, 00, 80, 03, 00, 00, 00, BC, 08, 01, 80, 04, 00, 00, 00, 08, 4B, 01, 80, 05, 00, 00, 00, D4, 70, 01, 80, 06, 00, 00, 00, A0, 81, 01, 80, 07, 00...
 
[+]

Entropy:
7.7529

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
3.5 MB (3,673,600 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
KnowhowCloud

Command:
"C:\Program Files\knowhow cloud\knowhowcloud.exe" \setup


Scan knowhowcloud.exe - Powered by Reason Core Security