ccleaner_installer.exe

Vittalia Internet S.L.

This is the Vittalia Filewon bundler, a software application that bundles programs with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application ccleaner_installer.exe by Vittalia Internet S.L has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The file has been seen being downloaded from ccleaner.descargar.es. While running, it connects to the Internet address services.upd4ter.com on port 80 using the HTTP protocol.
Publisher:
Vittalia Internet S.L.  (signed and verified)

MD5:
2a3c42c45625476bcf6ec686cc1ff8b1

SHA-1:
4191f5f81a6852ca8818938b2f6adf897340b7e5

SHA-256:
1d8baa5eddbf9e9f0931611ce811bf9a91ce987e95a0759054ad108d8796cdd0

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Analysis date:
4/26/2024 1:44:06 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.VittaliaInternetSL.S
14.8.7.21

File size:
538.2 KB (551,096 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\ccleaner_installer.exe

Digital Signature
Authority:
VeriSign

Valid from:
6/4/2012 8:00:00 PM

Valid to:
5/8/2013 7:59:59 PM

Subject:
CN=Vittalia Internet S.L., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Vittalia Internet S.L., L=Mostoles, S=Madrid, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7952CFD9EF040B59F3C140BA1DA97A60

File PE Metadata
Compilation timestamp:
11/20/2012 3:52:01 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

Entry address:
0x948D

Code size:
84 KB (86,016 bytes)

The file ccleaner_installer.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.uplstatsone.com  (93.189.33.84:80)

TCP (HTTP):
Connects to services.upd4ter.com  (93.189.33.101:80)

TCP (HTTP):
Connects to media.vitavita.com.es  (109.70.128.135:80)

Remove ccleaner_installer.exe - Powered by Reason Core Security