propccleaner.exe

Pro PC Cleaner

Rainmaker Software Group LLC

The application propccleaner.exe, “This installer database contains the logic and data required to install Pro PC Cleaner.” by Rainmaker Software Group has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software.
Publisher:
Rainmaker Software Group LLC.​  (signed by Rainmaker Software Group LLC)

Product:
Pro PC Cleaner

Description:
This installer database contains the logic and data required to install Pro PC Cleaner.

Version:
2.5.9

MD5:
afc76eaea593bc0c3fe2f2da15422dec

SHA-1:
e17c534a753efa93b11598b798f1a6bc7e1ffdc1

SHA-256:
850638252eab053dfe09932f437f89a49f461773091de6c97991ff15cfc684af

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
5/2/2024 2:31:10 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Rainmaker.Installer.Meta (L)
16.6.13.20

File size:
6.3 MB (6,627,200 bytes)

Product version:
2.5.9

Copyright:
Copyright (C) 2014 Rainmaker Software Group LLC.​

Original file name:
ProPCCleanerSetup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\panda security\panda security protection\lostandfound\propccleaner.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
2/2/2015 7:00:00 PM

Valid to:
11/16/2015 6:59:59 PM

Subject:
CN=Rainmaker Software Group LLC, O=Rainmaker Software Group LLC, L=Wilmington, S=Delaware, C=US, SERIALNUMBER=5411289, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Delaware, OID.1.3.6.1.4.1.311.60.2.1.3=US

Issuer:
CN=Symantec Class 3 Extended Validation Code Signing CA - G2, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
44BD3AE304607E86F138009896D74AD6

File PE Metadata
Compilation timestamp:
10/7/2014 11:05:58 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
196608:8uQK5ARKnuICKHMBeqfEV7y7jPhtKBgZ2504+q:h5nnuI129fE2htKB/5wq

Entry address:
0xC87EC

Entry point:
E8, 4A, CC, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 51, 53, 56, 8B, F0, 33, DB, 3B, F3, 75, 1E, E8, 5D, 4D, 00, 00, 6A, 16, 5E, 53, 53, 53, 53, 53, 89, 30, E8, C5, D5, FF, FF, 83, C4, 14, 8B, C6, E9, C2, 00, 00, 00, 57, 39, 5D, 0C, 77, 1E, E8, 39, 4D, 00, 00, 6A, 16, 5E, 53, 53, 53, 53, 53, 89, 30, E8, A1, D5, FF, FF, 83, C4, 14, 8B, C6, E9, 9D, 00, 00, 00, 33, C0, 39, 5D, 14, 66, 89, 06, 0F, 95, C0, 40, 39, 45, 0C, 77, 09, E8, 0A, 4D, 00, 00, 6A, 22, EB, CF, 8B, 45, 10, 83, C0, FE, 83, F8, 22, 77...
 
[+]

Entropy:
7.7862  (probably packed)

Code size:
1021.5 KB (1,046,016 bytes)

Remove propccleaner.exe - Powered by Reason Core Security