setup_multilang.exe

Kingsoft PC Doctor

Kingsoft Security Co.,Ltd

This is a setup and installation application. This is installed with multiple programs including Kingsoft PC Doctor 3.7.0.47. The file has been seen being downloaded from www.lo4d.com and multiple other hosts.
Publisher:
Kingsoft Corporation  (signed by Kingsoft Security Co.,Ltd)

Product:
Kingsoft PC Doctor

Description:
Kingsoft PC Doctor Installer

Version:
3.7.0.47

MD5:
2bffc14ddbf56790b9eb6b7b37ba8a75

SHA-1:
f83cb6174317e937b990d0202bd2b4d33fecc637

SHA-256:
ea127c15238347b83951f0f9084405baf50373e1df4057d748db73cbcc261d90

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2024 10:17:25 AM UTC  (today)

File size:
5.3 MB (5,576,608 bytes)

Product version:
3.7.0.47

Copyright:
Copyright (C) 1998-2011 Kingsoft Corporation

Original file name:
ksinstall.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Common path:
C:\users\{user}\downloads\setup_multilang.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/9/2010 1:00:00 AM

Valid to:
3/9/2013 12:59:59 AM

Subject:
CN="Kingsoft Security Co.,Ltd", OU=Kingsoft Duba, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Kingsoft Security Co.,Ltd", L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
11B3AF5DB11EC91D1CF0B3E1B80C85E4

File PE Metadata
Compilation timestamp:
4/11/2012 1:45:00 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
98304:HkTHzjQWQ7BjAoVUORMECtpk7GVNqiu5TZy4QrIkpvi/f46PvxrWfEiAqBhk:HkTzjlQN/Vj9Co78Nq3CsCvgfX35WfHk

Entry address:
0x27984

Entry point:
E8, 2B, 8D, 00, 00, E9, 17, FE, FF, FF, CC, CC, 68, F0, 79, 42, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 44, 60, 44, 00, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, CC, CC, CC, CC, CC, CC, CC, 83, EC, 14, 53, 8B, 5C, 24, 20, 55, 56, 8B, 73, 08, 33, 35, 44, 60, 44, 00, 57...
 
[+]

Code size:
225 KB (230,400 bytes)

The file setup_multilang.exe has been discovered within the following programs.

360Amigo is registry optimizer. 360Amigo System Speedup bundles a branded version of the Conduit Toolbar, designed to deliver search based advertising and results. During installation the user is presented in some cases with the option to install the toolbar (on by default).
www.360amigo.com
53% remove it
Kingsoft PC Doctor 3.7.0.47  by Kingsoft Security
Publisher's description - “Kingsoft PC Doctor, which focuses on providing computer users excellent privacy cleaner, registry cleaner and, brilliant Windows optimization service, is your best free professional and easy-to-use Windows Diagnosis and Optimization software.”
pcdoctor.kingsoft.com
56% remove it
 
Powered by Should I Remove It?

The file setup_multilang.exe has been seen being distributed by the following 50 URLs.

http://www.lo4d.com/get-file/pc-doctor/.../

http://global-shared-files-lw.softonic.com/f83/cb6/.../setup_multilang.exe

http://global-shared-files-l3.softonic.com/f83/cb6/.../file?nvb=20140815145454&nva=20140816025554&token=05f168c3f105cf61bb497&id_file=326655&channel=WEB&instance=softonic_en&type=PROGRAM&fdh=yes&SD_used=0&filename=setup_multilang.exe

http://kingsoft-pc-doctor.software.informer.com/.../

http://gsf-cf.softonic.com/f83/cb6/.../file?SD_used=0&channel=WEB&fdh=yes&id_file=326655&instance=softonic_en&type=PROGRAM&Expires=1428507042&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=Bg57mmBPN35NMw8zaXMhoCh1njthGEr8J1pIQHL1gAcrdzZz8JTYYFk9POTIXVaTTb3AfKO6aSrcomRVA6LG6C-22QD2AEhWgt4eHMBttH70GyR5pLhIrT0DnciE7xxA5jvqCxP1TKstt5s8qd4hAtmH5VQLOINRqF-BWYoQPFY_&filename=setup_multilang.exe

http://gsf-cf.softonic.com/f83/cb6/.../file?SD_used=0&channel=WEB&fdh=yes&id_file=326655&instance=softonic_en&type=PROGRAM&Expires=1431377171&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=EC6OkkDL9ZZPVRLdEfCG48Y1ZH3oDE3DkZWSf7NYxQTtUQhn40bzgqvMwbRtVBc1NB0riO0ahdlP6NAOiFoJSjymoDsIog0w-7nO5fuNOFFZD474Qb0a3RHPlez3yhO8CKVKPf1D5CBPcjs4AAOwwqaj07l0t2l~zfeO~-0XXdM_&filename=setup_multilang.exe

http://universal-downloader.en.softonic.com/326000/326655/.../setup_multilang.exe

http://gsf-cf.softonic.com/f83/cb6/.../file?SD_used=0&channel=WEB&fdh=yes&id_file=326655&instance=softonic_en&type=PROGRAM&Expires=1438173032&Signature=ESCgBPc-aaO5dHNNQwef5UmpfI8Eb919Klit8Xu0laX1EQVU6bmSF84zpmEiZthaz77xiG5LmEF5p7XidW2BToeW9EbH7suKiQnYA1c0zjsttxpCKNh3AZQMHsokiJmmd35pS-yni4-SNUM9Pxln5fE3LuHq1PgNbP6BAuJ~16A_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=setup_multilang.exe

http://gsf-cf.softonic.com/f83/cb6/.../file?SD_used=0&channel=WEB&fdh=yes&id_file=326655&instance=softonic_en&type=PROGRAM&Expires=1428266641&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=SCMzToFWEaxb4EIAY15HIgbGL~rTxhSMVby0RfUrO4dDhMYDm4PFWLfIvad5sKkb67gxUai8yLcPQGGAmP~hOqK~LqnX~hWJYKGxfQqPi5qwpbN4MCBQWeicyadrTu6OI891~GKdH~DHJQab4d8DeFAlNVlIlvEiMo4CmYxWJfE_&filename=setup_multilang.exe

http://global-shared-files-l3.softonic.com/f83/cb6/.../file?nvb=20141130115006&nva=20141130235106&token=0feb33138d69c22caef9f&instance=softonic_en&filename=setup_multilang.exe

http://gsf-cf.softonic.com/f83/cb6/.../file?SD_used=0&channel=WEB&fdh=yes&id_file=326655&instance=softonic_en&type=PROGRAM&Expires=1436828889&Signature=fisWBW8MNqoo6kAZi-n3aPjNtkArbRliDeC6ygearC1MpSMvJNpu8c9JGsJiAA5LooqiEm6XE0cEx3dzvib6bKNMnlS8Q4wQ7Gx3WarAUhPF-2povfm3hCD6VzLX4S~xnnL1Yve55MTCSycvwBBoCOuJwJuoFF07aRAESSJINMQ_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=setup_multilang.exe

http://gsf-cf.softonic.com/f83/cb6/.../file?SD_used=0&channel=WEB&fdh=yes&id_file=326655&instance=softonic_en&type=PROGRAM&Expires=1449417582&Signature=QjiPSCXgLxfD51H686Wx6w7Y6vrtctcLALrebqrutChDL0KdPVZE7Pcey5gTUTW~A~3UkIjA1RRUTamX45pl7u3uuoZrAAW0XmkZ-sjRcthHfDaiKKGzvva7SseFT0lD8Vsfif0HDDQCxAIK4WzHUltvx5SsHWzRWTGe-ruQNEc_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=setup_multilang.exe

Latest 30 of 80 download URLs

Scan setup_multilang.exe - Powered by Reason Core Security