Distribution URL is http://cloud.quicksnooker.com/qsLaunch3.exe
I am the author of this program - which is the legitimate launcher/installer for Quick Snooker - an on-line Snooker game, running for nearly 20 years and with 100,000+ installs.
The summary on the (VirusTotal) 'behavior' tab is accurate - the program makes no attempt to disguise what is does.
It downloads a location from quicksnooker.com, and then downloads and unzip files from http://cloud.quicksnooker.com (our content delivery network hosted in the 'google cloud'.)
The files containing the main executable QuickSnooker.exe, and a set of resources (images, textures, sound and geometry files).
The program also creates a folder (%LocalAppdata%\qs8) , a desktop shortcut, and the appropriate registry keys to uninstall Quick Snooker program when requested.
Of course it *looks* very Trojan like - but it is harmless and complies with industry standard clean guidelines.
See our terms or help sections at http://quicksnooker.com
Please remove ASAP
Hopefully your "ML" will be smart about future versions ?
thanks in advance
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The Live Community thanks you for your participation!