pc-cleaner-417.exe

PC Cleaner

PC HelpSoft Labs Inc.

The application pc-cleaner-417.exe by PC HelpSoft Labs has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from webtools.avanquest.com and multiple other hosts.
Publisher:
PC Help Soft   (signed by PC HelpSoft Labs Inc.)

Product:
PC Cleaner

Version:
4.0

MD5:
c89e685bc65f118ad8d315b07696b167

SHA-1:
8f2bf6f515d239b8fda5dce2d361f1c7e9e9c182

SHA-256:
ad0c04a6aed3a58fd92dfb408d3e78d579d49694bb63bba267bcca54f21a84e4

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 5:46:26 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Program.Unwanted.54
9.0.1.0295

Reason Heuristics
Optional.PCHelpSoft.PCHelpSoftLabs.Installer.Meta (L)
15.12.1.1

File size:
1.9 MB (2,005,120 bytes)

Product version:
4.0

Copyright:
PC Help Soft

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\pc-cleaner-417.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/3/2014 1:00:00 AM

Valid to:
7/4/2015 12:59:59 AM

Subject:
CN=PC HelpSoft Labs Inc., O=PC HelpSoft Labs Inc., L=Victoria, S=British Columbia, C=CA

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6621BA2E90BF744DB88F6E6F6EBD0F4E

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:ka2rIrdZQXpYtvyMqARXA15PSLDz4iVuMy/UGZfwinXBgN:J2re7E36w7PSLnnVu4GNRgN

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, E8, CD, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E8, CD...
 
[+]

Entropy:
7.9941

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file pc-cleaner-417.exe has been seen being distributed by the following 26 URLs.

http://webtools.avanquest.com/download.cfm?tracking=PH_EN_PP_MRM_PCC&keyword=&campaignID=PLY&filter=51202476&mrmid=_F4pnXsQiZPbz1hGTt9nrRkkR_NMxWbq5dWFueLWl82gOF7ps-JV-mQ-jMK6VlkJou4kesPyRvuTXdatOZwapnop1WZOWXcG8njfnbK_EjWIFx1-R_shvLwuaHtPRjNCVGspLWsyieqEcaHcsxvCKB-lMz5eFT7_-Sc4jnt6UefgOseqeSaJ1ELRfFnLxUI4Vxgqx9v903yRDMjwUrrZA294Ij3UQo_Y7AN6CSXsqkZQuLAlToNWYeFG_YhNtN2U6LxhcPUFaJWsbtlgQQi2VX4hVWawBvGhrj1tP2POrez1B684qOkCbZhk-pXApP1iazab8icLnmXspsYBAQXE08GzVeMTmXJ71MEKycV8ZZtIq8GlBSAQAUxwvPw_6MtSBqYztpa1aqy_9y2175m1loBhgBPXEJAo5v1wqGxr32b9v6dh10F4fnXvCsdcKDrW9JeD&mtmid=&clickid=&go=http://cdn2.pchelpsoft.com/.../pc-cleaner-417.exe

http://webtools.avanquest.com/download.cfm?tracking=PH_EN_PP_MRM_PCC&keyword=&campaignID=PLYS&filter=intBBYL38431131&mrmid=KueyzAUhy538O2qogX5aVfWJEAAy8_bfE08ASEU7_3XXG8d0nT3iEIPYqp4itqhwGh76hY9mlRU7jsn4QXeMDy42GI6MR5KKwWau9CRwZhXnlzJ6RPtZCM3u0sDoRDRk5isi17kUJgRowTzluBZIcgJtsh7gvWmiB4-LogBBpT09tHSWzGiypK15Pv22LHCZYXMYQfCE7j2r-EFKKq_XTd37oSDY3wuCvwwZjFyt3izdjo7d93MXOT_YiMqhyxrvxN7hd_O-ia82Qm40-ASDlxPO6M25iX_3R7oQcnZt_cI1V_r64PePd1-1xCok9P29D29GhLO4F6_f_mHVUMsyDNXbSdwoow6aV_7T53XsLTjwnLF_n3VDtgmGYEQ7DnBMbt4JtC-n2UBE08axWxPpyJPBP_XN&mtmid=&clickid=&go=http://cdn2.pchelpsoft.com/.../pc-cleaner-417.exe

http://webtools.avanquest.com/download.cfm?tracking=PH_EN_PP_MRM_PCC&keyword=&campaignID=PLY&filter=53022403&mrmid=QO7xgGLrxXXHwcIjjMQAgnIV4R5tofwd2NTd3GQ_tDJDxVBUmsjK6N5PfUGyU9EluAh4bfsZAblY5nzVKRR2CedimLuqhmN_6XGTpYSXPvVCNxAUExFF2wlPlKml2R4Ez2c6JOCYzJ7fYlPXGLYb0xN_WdZ3-NOeYJ7li2fR0k5SOrrzKpWfIqO1DqpRuSKMBQjhiNR50I_SFZ_Ar7PCn--3lr2hq3DxZD0-wb6_7xlih4x4QsojwJNq7XbhRk6Wl9IPJXf604-0D47YtDAlDESle-QeJTAtzBXQhZwb4RFhIgEthpum8L_tLgHw-YidIkuhy2a_M2ZBPF2S8kTXyijDqphf4YskXTRDWgPyafz4uDImlPrBGUbEVd9KKaXGMk6TrrLUv0McB42hAnWwfkzvyp3tRIA2NYdwnys&mtmid=&clickid=&go=http://cdn2.pchelpsoft.com/.../pc-cleaner-417.exe

http://webtools.avanquest.com/download.cfm?tracking=PH_EN_PP_MRM_PCC&keyword=&campaignID=PLY&filter=35621080&mrmid=6hcmd1Y7z0bC_vmF01yReyHs5Q-jJ9JQuXk4YPCDgQ1pHHP6xqpFsJ60gCoyuMp3gRdH3WE8JxoOHXpx2mNw2cxZcTDU3Nv-zJ0OOF91fyRWBaxUpCPFQrTK_MT1dICDGqcsMXX5F2h72bc-SIE-oW7ieEZOtCmZJgIMDrkljJ_1G9pg8_H_vGV1cOokb6pvHjGcY5jTym9-ROMoDEmol_AEr9x4iej93DJcpyQf-6WgnCmCR7Rgw3l23KwwVk_u_RwbFzWB2bW5REAg6McTGmNlvdxmXr5G0yg5OjbjXz6gDc3-DU2kFXGDYhNQWx7G0FTU1xp36nbkjFli78jmuBUxRPb2Ez5dlVpImadPgVwW8dmj8QACTpDpyvVmnBL6ccXaohBHAEJEHhlrERK-4vRNKYhcbAP4t4SJ9Unc6g7kQ02EILoTN5JBZE2e1c1XdQ&mtmid=&clickid=&go=http://cdn2.pchelpsoft.com/.../pc-cleaner-417.exe

http://webtools.pchelpsoft.com/download.cfm?tracking=PH_EN_PP_MRM_PCC&keyword=&campaignID=PLY&mrmid=WyqUg_dPwx67sp93IUbLiuoLG3pZBrLlRpUHw3bRp1nvv67kFelZT_lFmLWuHWACXj26aNvygfE1OTPqw57jsQcHct3vdqKvpJOHVX_XZIT5rz5GXKIdTlp6X-weE4G_CQ1iYxwK0DqyHFQLyHXchr0X1EmNdKScaYdvux94qOgmITZBuI3AcFkIkcqcQJ3RCsoWO8HShfQif30Otkh97mxn4fMoByBjlir5oysjuhD6YD7X42oLUz06KKra1AUHVhCCd48goc38-JSHrkum_DPpALz4qNOHgYjdS1gdCgVZ6aWt1dBh-nrX7WBoFOw5y1aWxxTiso3co6-J6WyjvmenlD2WqxsEdPifw11ot3brovNeP4371b-K6-QiJd7B_J81bhhcmImhcXJ-keJfFQFauGZxJOp6Pv_G4aVpJd2Bmmj71zCSzEmePHmTDs2AhEgv_23W2-Uabf73Vs5S_w&clickid=&filter=43391365&go=http://cdn2.pchelpsoft.com/.../pc-cleaner-417.exe

Remove pc-cleaner-417.exe - Powered by Reason Core Security