dmwu.exe

ClientConnect LTD

The file belongs to the ClientConnect (Conduit/Perion) platform, a utility that bundles and monetizes search toolbars and browser add-ons. The application dmwu.exe by ClientConnect has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a windows Service named “IBUpdaterService”.
Publisher:
ClientConnect LTD  (signed and verified)

MD5:
97aeaea30f3a5f4a530ae912c8e852f7

SHA-1:
4a22cca224136b26b128dfa894f97ea6d6cf9a15

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Conduit/ClientConnect toolbar/extension distribution.

Analysis date:
8/13/2020 1:25:10 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Conduit (M)
17.2.13.15

File size:
2.3 MB (2,447,312 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Windows\System32\dmwu.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
7/8/2014 9:00:00 PM

Valid to:
7/9/2016 8:59:59 PM

Subject:
CN=ClientConnect LTD, OU=Guardbox, O=ClientConnect LTD, L=Ness Ziona, S=Israel, C=IL

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
3215FFC06E15A37E45F6521CECC8C3BD

File PE Metadata
Compilation timestamp:
4/17/2016 7:58:55 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x161018

Entry point:
E8, 86, 04, 00, 00, E9, 6B, FD, FF, FF, FF, 25, 38, D7, 59, 00, FF, 25, 3C, D7, 59, 00, FF, 25, 40, D7, 59, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, FF, 25, 44, D7, 59, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 0F, 03, C1, 1B, C9, 0B, C1, 59, E9, DA, 04, 00, 00, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 07, 03, C1, 1B, C9, 0B, C1, 59, E9, C4, 04, 00, 00, FF, 25, 7C, D7, 59, 00, 8B, FF, 55, 8B, EC, FF, 75, 14, FF, 75, 10, FF, 75, 0C, FF, 75, 08, 68, D2, 0A, 56, 00...
 
[+]

Code size:
1.6 MB (1,682,432 bytes)

Service
Display name:
IBUpdaterService

Type:
Win32OwnProcess, InteractiveProcess


Remove dmwu.exe - Powered by Reason Core Security