AdxEngine.exe

MPC AdCleaner

DotC United Inc

The application AdxEngine.exe, “MPC AdCleaner CleanEngine” has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. While running, it connects to the Internet address host176.b5.trdns.com on port 80 using the HTTP protocol.
Publisher:
DotC United Inc

Product:
MPC AdCleaner

Description:
MPC AdCleaner CleanEngine

Version:
4, 3, 13364, 0822

MD5:
b77fd7d013df7e63c36b8e83b717bd80

SHA-1:
e657672753a47daaa5ffbff8c746af4233b61835

SHA-256:
d180ccc278d4b3c8cd51161a140c6e4d36e3c357b05ae8678c95c0f0ccfa7d3c

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/21/2025 12:36:17 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.DotC.MPC (L)
17.2.11.13

File size:
1.7 MB (1,833,440 bytes)

Product version:
4, 3, 13364, 0822

Copyright:
Copyright (c) 2015 DotC United Inc.

Original file name:
AdxEngine.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\mpc cleaner\adxengine.exe

File PE Metadata
Compilation timestamp:
8/22/2016 3:37:08 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x2771B

Entry point:
74, 06, 69, D7, 5B, 9C, 1F, 96, 49, 0F, CB, 84, C3, 8A, F5, EB, 02, 87, D7, 8A, FF, 8D, 6D, 00, 87, DA, 8D, 75, 00, FE, C5, C6, C7, 2A, 2B, C6, 76, 0C, 69, D6, 5F, 69, 64, 98, 0F, BE, EF, 80, C1, EB, FF, CE, 68, B3, 7A, 4E, 00, 52, 1C, 3C, F6, D5, 81, E6, 9F, 74, 6C, FB, 0F, CB, 68, 1C, 23, 00, 00, 86, EB, 59, 86, FA, 81, E9, B2, 09, 00, 00, 87, D6, 8D, 01, F7, C3, 24, C1, 16, 24, 2D, B7, 0A, 00, 00, F7, D9, 88, E1, 2D, 01, 00, 00, 00, 8D, 1D, A4, 16, 29, 1B, 8D, 0D, FA, 8B, C7, B4, 0F, BE, EF, 73, 03, 41...
 
[+]

Entropy:
3.4128

Code size:
272 KB (278,528 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to win15.securedc.com  (64.8.117.67:80)

TCP (HTTP):
Connects to host176.b5.trdns.com  (77.245.148.176:80)

Remove AdxEngine.exe - Powered by Reason Core Security