SpywareClearShield.exe

Spyware Clear

Crawler, LLC

The application SpywareClearShield.exe, “Spyware Clear Realtime Shield” by Crawler has been detected as a potentially unwanted program by 2 anti-malware scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘SpywareClearShield’.
Publisher:
Crawler.com  (signed by Crawler, LLC)

Product:
Spyware Clear

Description:
Spyware Clear Realtime Shield

Version:
1.3.0.5

MD5:
536de753bd3efcd0c855ae53a712a639

SHA-1:
6b9c3ba1c9ff154c82c8edda30ae375d6d421f82

SHA-256:
24e9f01481dfe20d974ff7fe590865e930712fb491428d8a2bcceb73651ab82f

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 7:56:27 AM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Adware.Win32.Crawler
4.0.3.14829

Reason Heuristics
PUP.Crawler.S
14.8.29.2

File size:
3.6 MB (3,733,384 bytes)

Product version:
1.3.0.0

Copyright:
© Crawler.com

Original file name:
SpywareClearShield.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\spyware clear\spywareclearshield.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/26/2013 7:00:00 PM

Valid to:
1/25/2017 6:59:59 PM

Subject:
CN="Crawler, LLC", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Crawler, LLC", L=Boca Raton, S=Florida, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
48E3A7F6CBA47D0C3FCD17CF81AB3F76

File PE Metadata
Compilation timestamp:
7/28/2014 7:14:00 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:sM6Fl0oJB5rCIuLhpUP7SKP0gtcK1S41O6oA/cHTJuJm0mMbKDEnHETEl7:sM0BduL4tcK1XU6HcG+DEnHETe7

Entry address:
0x286864

Entry point:
55, 8B, EC, 83, C4, F0, B8, 5C, B3, 67, 00, E8, C8, 85, D8, FF, E8, 33, 43, FF, FF, E8, 26, 30, D8, FF, 8B, C0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.6610

Developed / compiled with:
Microsoft Visual C++

Code size:
2.5 MB (2,643,968 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
SpywareClearShield

Command:
C:\Program Files\spyware clear\spywareclearshield.exe


Remove SpywareClearShield.exe - Powered by Reason Core Security