adwcleaner.exe

AdwCleaner from Xplode is a free application designed to search for and remove adware such as browser toolbars and other potentially unwanted programs and specifically targets software that is bundled with free programs that you download from the web. This is a setup program which is used to install the application. This file is installed with multiple programs including SuperCleanerZ. The file has been seen being downloaded from downloader.disk.yandex.com.tr and multiple other hosts.
Version:
3.0.0.5

MD5:
17c8bf490ca207d06ef2a0ec84f47191

SHA-1:
7261a2faaa2ac215985ca453a38bbde606eecca9

SHA-256:
3b4600b0e5c444f0cc14cffe75c472c964fe941f5d333bcb8e6cbba38b9fcbf1

Scanner detections:
3 / 68

Status:
Clean  (3 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/25/2024 6:49:00 AM UTC  (today)

Scan engine
Detection
Engine version

Emsisoft Anti-Malware
Trojan.Generic.9255389
8.13.12.27.05

Rising Antivirus
AU3SCRIPT:Dropper.Insrun!1.9E21
23.00.65.131225

Trend Micro House Call
TROJ_GEN.F47V0912
7.2.361

File size:
1017.6 KB (1,042,066 bytes)

File type:
Executable application (Win32 EXE)

Language:
French (France)

Common path:
C:\users\{user}\downloads\adwcleaner.exe

File PE Metadata
Compilation timestamp:
1/29/2012 10:32:28 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:xthEVaPqLW2iiNwtO79sIt4ws7GkyIs6/zVvC:pEVUcWXiNIOqq36ZC

Entry address:
0xB5E60

Entry point:
60, BE, 00, 40, 47, 00, 8D, BE, 00, D0, F8, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Entropy:
7.9850

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
268 KB (274,432 bytes)

The file adwcleaner.exe has been discovered within the following programs.

µTorrent  by BitTorrent Inc.
µTorrent is a is a free, ad-supported, lighter-weight BitTorrent client designed to consume less resources then the full BitTorrent version.
www.utorrent.com
12% remove it
360Amigo is registry optimizer. 360Amigo System Speedup bundles a branded version of the Conduit Toolbar, designed to deliver search based advertising and results. During installation the user is presented in some cases with the option to install the toolbar (on by default).
www.360amigo.com
53% remove it
HOSTS Anti-PUPs/Adwares  by Malekal's Team
Here's a new HOSTS Anti-PUPs/Adwares tools - it will change your HOSTS file to block known addresses to distribute the PUP / LPIS (Software potentiellements side) and adware. The HOSTS file is not overwritten (if you already have addresses), the entries will be added.
www.malekal.com/2012/01/10/hosts-anti-pupsadware
50% remove it
www.ZyoTechnoogy.com
52% remove it
 
Powered by Should I Remove It?

The file adwcleaner.exe has been seen being distributed by the following 37 URLs.

https://downloader.disk.yandex.com.tr/disk/0a0e9a81e900d30def8b1a67073a7efe/54d8ab01/.../x-msdownload&fsize=1042066&hid=b984089ce7a5d9bb09ee0a99795f2fa2&media_type=executable

http://download.bleepingcomputer.com/dl/1d65246f8727ef2a0f42f9b0ff507d34/5241df53/windows/security/security-utilities/a/.../AdwCleaner.exe

http://www.programosy.pl/.../pobierz,adwcleaner,2.html

Latest 30 of 37 download URLs

Scan adwcleaner.exe - Powered by Reason Core Security