SpywareBot.exe

SpywareBot

C-NetMedia

The application SpywareBot.exe, “C-NetMedia Spyware Cleaner” by C-NetMedia has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a scheduled task under the Windows Task Scheduler triggered daily at a specified time.
Publisher:
C-NetMedia  (signed and verified)

Product:
SpywareBot

Description:
C-NetMedia Spyware Cleaner

Version:
1.5.2728.890

MD5:
8b011f4bdc66b5306072d921f9e1d523

SHA-1:
a6904ecc4e5c1fea32eb7740442305ee13e5abc4

SHA-256:
046bb56d5e5685af4e3403bb5407da0f551795cf08744d84c9d3f7ad13c8e7aa

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/25/2024 2:22:07 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.1.30.15

File size:
8.3 MB (8,676,848 bytes)

Product version:
1.5.0.1

Copyright:
SpywareBot (c). All rights reserved.

Original file name:
SpywareBot.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\spywarebot\spywarebot.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/14/2006 5:30:00 AM

Valid to:
11/16/2007 5:29:59 AM

Subject:
CN=C-NetMedia, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=C-NetMedia, L=Mobile, S=Alabama, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
38F51432ABAD3AA35011F824E0C565EC

File PE Metadata
Compilation timestamp:
6/15/2007 1:20:39 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0x83A2F

Entry point:
E8, 52, CC, 00, 00, E9, 16, FE, FF, FF, E8, 7B, B0, 00, 00, FF, 74, 24, 04, E8, D2, AE, 00, 00, FF, 35, 88, BC, 4C, 00, E8, 68, 63, 00, 00, 68, FF, 00, 00, 00, FF, D0, 83, C4, 0C, C3, 68, 7C, 2D, 4B, 00, FF, 15, 08, 63, 4A, 00, 85, C0, 74, 16, 68, 6C, 2D, 4B, 00, 50, FF, 15, 68, 63, 4A, 00, 85, C0, 74, 06, FF, 74, 24, 04, FF, D0, C3, FF, 74, 24, 04, E8, D1, FF, FF, FF, 59, FF, 74, 24, 04, FF, 15, AC, 61, 4A, 00, CC, 6A, 08, E8, FE, B3, 00, 00, 59, C3, 6A, 08, E8, 1D, B3, 00, 00, 59, C3, 56, 8B, F0, EB, 0B...
 
[+]

Entropy:
4.5556

Code size:
660 KB (675,840 bytes)

Scheduled Task
Task name:
SpywareBot Scheduled Scan

Trigger:
Daily (Runs daily at 03:00:00)

Description:
Runs SpywareBot to scan your computer for malicious and potenially unwanted programs.


Remove SpywareBot.exe - Powered by Reason Core Security