adwcleaner.exe

AdwCleaner from Xplode is a free application designed to search for and remove adware such as browser toolbars and other potentially unwanted programs and specifically targets software that is bundled with free programs that you download from the web. This is a setup program which is used to install the application. The file has been seen being downloaded from download.bleepingcomputer.com and multiple other hosts.
Version:
3.0.1.5

MD5:
693e44d7b4f5fd5532dd2b47731c5f90

SHA-1:
8ac26ad4ae09e2b7a635413a8e96d49cd6c20a1e

SHA-256:
189f51c27bfffc1996c28b624bbaff4c540810de24351896141456af40169377

Scanner detections:
3 / 68

Status:
Clean  (3 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/25/2024 1:22:43 PM UTC  (today)

Scan engine
Detection
Engine version

F-Prot
W32/Undefined.Threat
v6.4.7.1.166

Rising Antivirus
AU3SCRIPT:Dropper.Insrun!1.9E21
23.00.65.131216

Trend Micro House Call
TROJ_GEN.F47V1215
7.2.352

File size:
1.2 MB (1,226,802 bytes)

File type:
Executable application (Win32 EXE)

Language:
French (France)

Common path:
C:\users\{user}\downloads\adwcleaner.exe

File PE Metadata
Compilation timestamp:
1/29/2012 4:32:28 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:OthEVaPqLLdfhAU3+V/e63yiw8t+zsMYtmws7GkyIsv/zVgZnC:WEVUcLdJ/3+VFyNyYrq3vahC

Entry address:
0xCFE90

Entry point:
60, BE, 00, E0, 48, 00, 8D, BE, 00, 30, F7, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Entropy:
7.8911

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
268 KB (274,432 bytes)

The file adwcleaner.exe has been seen being distributed by the following 24 URLs.

http://download.bleepingcomputer.com/dl/259d89999c86df190442d73c48c11eb1/52ac7f56/windows/security/security-utilities/a/.../AdwCleaner.exe

Scan adwcleaner.exe - Powered by Reason Core Security