adwcleaner.exe

Install Manager

QUALITY SCORE SL

The application adwcleaner.exe by QUALITY SCORE SL has been detected as adware by 10 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from logiciel-bureau.com.
Publisher:
QUALITY SCORE SL  (signed and verified)

Product:
Install Manager

Version:
1.1.0.1

MD5:
a4b9dcbae424a670142d0d262a24c33f

SHA-1:
6ac95cd06b4aa19616ee9b547ee6ec6a4ede79d9

SHA-256:
7677ebca48a068785825ac302ab4111a271e81452d369057161f9b99fc9b563d

Scanner detections:
10 / 68

Status:
Adware

Analysis date:
4/27/2024 3:21:58 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Downloader
2016.0.3184

Comodo Security
ApplicUnwnt
19085

ESET NOD32
MSIL/Adware.Colooader (variant)
9.10203

Fortinet FortiGate
Adware/Colooader
3/1/2015

IKARUS anti.virus
PUA.Downloader
t3scan.1.6.1.0

Malwarebytes
PUP.Optional.QualityScore
v2015.03.01.05

McAfee
Artemis!A4B9DCBAE424
5600.6840

Reason Heuristics
PUP.QUALITYSCORE
15.3.1.5

Trend Micro House Call
TROJ_GEN.F47V0414
7.2.60

VIPRE Antivirus
MSIL.Adware.Colooader
31924

File size:
253.3 KB (259,384 bytes)

Product version:
1.1.0.1

Copyright:
Copyright © 2014

Original file name:
Loader.exe

File type:
Executable application (Win64 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\adwcleaner.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/2/2014 1:00:00 AM

Valid to:
1/3/2015 12:59:59 AM

Subject:
CN=QUALITY SCORE SL, O=QUALITY SCORE SL, STREET=CALLE SERRANO 213, L=MADRID, S=MADRID, PostalCode=28016, C=ES

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
4AB0F061E1C305B4B31A8ACE3AEA2E01

File PE Metadata
Compilation timestamp:
4/14/2014 9:33:46 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:ZxUhrumaXJmDfK69dTF38/iHTMU0DTJnJIsf6OYL9cc8:7/7GfK69H8/KTGTxbf1Ym5

Entry address:
0x3684A

Entry point:
4D, 5A, 90, 00, 03, 00, 00, 00, 04, 00, 00, 00, FF, FF, 00, 00, B8, 00, 00, 00, 00, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 80, 00, 00, 00, 0E, 1F, BA, 0E, 00, B4, 09, CD, 21, B8, 01, 4C, CD, 21, 54, 68, 69, 73, 20, 70, 72, 6F, 67, 72, 61, 6D, 20, 63, 61, 6E, 6E, 6F, 74, 20, 62, 65, 20, 72, 75, 6E, 20, 69, 6E, 20, 44, 4F, 53, 20, 6D, 6F, 64, 65, 2E, 0D, 0D, 0A, 24, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Code size:
210.5 KB (215,552 bytes)

The file adwcleaner.exe has been seen being distributed by the following URL.

Remove adwcleaner.exe - Powered by Reason Core Security