1857375_stp.exe

Baidu PC Faster

Baidu Online Network Technology (Beijing)Co., Ltd

This is a setup and installation application. The file has been seen being downloaded from dl.security.baidu.co.th.
Publisher:
Baidu Inc.  (signed by Baidu Online Network Technology (Beijing)Co., Ltd)

Product:
Baidu PC Faster

Description:
Baidu PC Faster MiniSetup

Version:
3,7,2,42022

MD5:
39df91f383cac49e479da10dc3f577ca

SHA-1:
f9753e895f567235ac815a6e66649194e9dee7da

SHA-256:
80ee7ceff3c6769b4147b08b6a97784fd62cbe29d89afc7e3b85000bcf113bb2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 9:58:55 AM UTC  (today)

File size:
1.4 MB (1,449,664 bytes)

Product version:
3,7,2,42022

Copyright:
Copyright (C) 2012 Baidu, Inc. All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\1857375_stp.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/24/2012 12:00:00 AM

Valid to:
4/24/2015 11:59:59 PM

Subject:
CN="Baidu Online Network Technology (Beijing)Co., Ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Baidu Online Network Technology (Beijing)Co., Ltd", L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3BDB1994B98BBB19AB55A42337FA4F5C

File PE Metadata
Compilation timestamp:
9/4/2013 7:09:44 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:d3mYtOUxCXPd3EOoKxxBTS1zZsiCFtqiZGi8p5fo:DPGhEEXBTS1zZsvyiuzfo

Entry address:
0xA54AC

Entry point:
E8, 87, 03, 01, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 51, 83, 65, FC, 00, 56, 8D, 45, FC, 50, FF, 75, 0C, FF, 75, 08, E8, FE, 03, 01, 00, 8B, F0, 83, C4, 0C, 85, F6, 75, 18, 39, 45, FC, 74, 13, E8, 6C, 2A, 00, 00, 85, C0, 74, 0A, E8, 63, 2A, 00, 00, 8B, 4D, FC, 89, 08, 8B, C6, 5E, C9, C3, 8B, FF, 55, 8B, EC, 83, EC, 10, 53, 56, 33, F6, 33, C0, 57, 39, 75, 10, 0F, 84, CD, 00, 00, 00, 8B, 5D, 08, 3B, DE, 75, 22, E8, 35, 2A, 00, 00, 56, 56, 56, 56, 56, C7, 00, 16, 00, 00, 00, E8, 95, F0, FF, FF, 83, C4...
 
[+]

Code size:
950.5 KB (973,312 bytes)

The file 1857375_stp.exe has been discovered within the following program.

360Amigo is registry optimizer. 360Amigo System Speedup bundles a branded version of the Conduit Toolbar, designed to deliver search based advertising and results. During installation the user is presented in some cases with the option to install the toolbar (on by default).
www.360amigo.com
53% remove it
 
Powered by Should I Remove It?

The file 1857375_stp.exe has been seen being distributed by the following URL.

Scan 1857375_stp.exe - Powered by Reason Core Security