ccleaner.exe

AVSoftware EOOD

The software installer uses the StartInstall.com download manager which bundles additional adware offers (toolbars and utilities such as the SafeSearch toolbar) during setup. The application ccleaner.exe by AVSoftware EOOD has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
AVSoftware EOOD  (signed and verified)

Version:
1.0.0.0

MD5:
fadd559b0c117cfdf981976e043b4b14

SHA-1:
e8c19ecb61b829029ecd4a41791172500c64e420

SHA-256:
f830831105b9e962e96c31a0614a04343fd2acf410bb8c07680443cd5cbb9d6e

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/27/2024 3:43:54 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.AVSoftware EOOD
16.2.8.23

File size:
1.1 MB (1,114,272 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\ccleaner.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/30/2010 1:00:00 AM

Valid to:
5/11/2013 12:59:59 AM

Subject:
CN=AVSoftware EOOD, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=AVSoftware EOOD, L=Gabrovo, S=Gabrovo, C=BG

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
612C0FFE70F6570A7F6914CEE86BC00F

File PE Metadata
Compilation timestamp:
2/27/2013 12:40:14 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:GKz0aFC/NWRmILNoUxaNji6ZVADxAtD5HqQskoxDY5p8ysX97:Go0a8/NWYbNrAAHM5YbW

Entry address:
0x37C120

Entry point:
60, BE, 00, 10, 67, 00, 8D, BE, 00, 00, D9, FF, C7, 87, 2C, CC, 2E, 00, 72, 72, 72, 72, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Entropy:
7.9213

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
1 MB (1,097,728 bytes)

Remove ccleaner.exe - Powered by Reason Core Security