klcp_update_1062_20140707.exe

KLCP Update

This is a setup and installation application. The file has been seen being downloaded from files2.digital-digest.com and multiple other hosts.
Product:
KLCP Update

Description:
KLCP Update Setup

Version:
10.6.2.0

MD5:
cdcc4f538ccc587057cd069cb8fa895b

SHA-1:
d6158102d6443901fae425f313426d9bbb3dfb6b

SHA-256:
93362da0360ba1855a75e334a7e3e731022683a4a037417d1e7a296a6a0b2a8a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 5:00:34 AM UTC  (today)

File size:
5.2 MB (5,478,927 bytes)

Product version:
1.0

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\klcp_update_1062_20140707.exe

File PE Metadata
Compilation timestamp:
10/13/2013 10:19:32 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:IqaLKHDlg3rEgGplDrM6YG6aT03637cJHnMVKM7R6gg2mfFPuYCPNfvYYzxDL:SLKHeEgGpFrM6YWQ3Rtn9M7Rlg2m9uJ7

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 2C, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 16, D8, FF, FF, E8, 65, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 2B, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 50, 86...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file klcp_update_1062_20140707.exe has been discovered within the following program.

360Amigo is registry optimizer. 360Amigo System Speedup bundles a branded version of the Conduit Toolbar, designed to deliver search based advertising and results. During installation the user is presented in some cases with the option to install the toolbar (on by default).
www.360amigo.com
53% remove it
 
Powered by Should I Remove It?

The file klcp_update_1062_20140707.exe has been seen being distributed by the following 2 URLs.

Scan klcp_update_1062_20140707.exe - Powered by Reason Core Security