MyCleanPC.exe

MyCleanPC.exe Stub Installer

US Tech Support LLC

The file MyCleanPC.exe by US Tech Support has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. While running, it connects to the Internet address server-52-85-133-6.iad53.r.cloudfront.net on port 80 using the HTTP protocol.
Publisher:
US Tech Support LLC  (signed and verified)

Product:
MyCleanPC.exe Stub Installer

Description:
MyCleanPC.exe

Version:
1.1.0.0

MD5:
fb30d29dcf735d63e8c4490d2fc0b363

SHA-1:
b666f277d407322f613fbb449f04e537d0a2207a

SHA-256:
0efa44a9d3e10105a45737e057f816252175ddb5a46f860d9cb0715aad3aa63d

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/29/2024 10:15:09 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Win64.Generic
17.3.16.13

File size:
1.7 MB (1,787,448 bytes)

Product version:
1.1.0.0

Copyright:
Copyright © 2012-2015 US Tech Support LLC

Original file name:
MyCleanPC.exe

Language:
English (United States)

Common path:
C:\users\{user}\downloads\555b.tmp

Digital Signature
Authority:
Symantec Corporation

Valid from:
6/15/2016 8:00:00 PM

Valid to:
9/15/2018 7:59:59 PM

Subject:
CN=US Tech Support LLC, O=US Tech Support LLC, L=Santa Monica, S=California, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
32AB4F629A39A7795CA3E9EE205286C9

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to server-52-85-133-6.iad53.r.cloudfront.net  (52.85.133.6:80)

TCP (HTTP):
Connects to ec2-54-81-201-18.compute-1.amazonaws.com  (54.81.201.18:80)

Remove MyCleanPC.exe - Powered by Reason Core Security