cleaner8_update.exe

The Cleaner

MooSoft Development LLC

The application cleaner8_update.exe, “The Cleaner Setup ” by MooSoft Development has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. This file is typically installed with the program The Cleaner 2012 by MooSoft Development LLC. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
MooSoft Development LLC   (signed by MooSoft Development LLC)

Product:
The Cleaner

Description:
The Cleaner Setup

MD5:
a53e406b6ad40be0b94409889640ed3e

SHA-1:
f228e6d4469c5fb073ea0ea16d8986285aa56277

SHA-256:
efdd6d52f279c5ed5f136d44b8fff363e2291bc93ee77f78692b9ae5d503cef6

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/24/2024 11:58:26 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.CSH (L)
16.12.13.14

File size:
8.2 MB (8,577,616 bytes)

Product version:
The Cleaner 2012

Copyright:
MooSoft Development LLC

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\Program Files\the cleaner\cleaner8_update.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
7/5/2012 9:00:00 AM

Valid to:
7/6/2013 8:59:59 AM

Subject:
CN=MooSoft Development LLC, O=MooSoft Development LLC, STREET=4401 Montgomery Blvd NE, STREET="#77", L=Albuquerque, S=NM, PostalCode=87109, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00BA8C98C2283A7BB17E05AB7963F3B0FA

File PE Metadata
Compilation timestamp:
6/20/1992 7:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file cleaner8_update.exe has been discovered within the following program.

The Cleaner 2012  by MooSoft Development LLC
www.moosoft.com
About 6% of users remove it
 
Powered by Should I Remove It?

Remove cleaner8_update.exe - Powered by Reason Core Security