ultra adware killer 1.6.0.0 x64.exe

Ultra Adware Killer

Alfredo Anibal santos silva

The application ultra adware killer 1.6.0.0 x64.exe by Alfredo Anibal santos silva has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from 113.171.224.169 and multiple other hosts.
Publisher:
Carifred  (signed by Alfredo Anibal santos silva)

Product:
Ultra Adware Killer

Version:
4.0.0.0

MD5:
7069fc64980769457a22c3da059ab399

SHA-1:
f0d0b13c41d6aca58d2b26677bb80e21565583bf

SHA-256:
f835c1f5187359cbcc6a12e23b17fcaf2a089497907a542639a26f2680f06dbb

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/16/2024 11:12:19 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.AlfredoAnibalsantossilva (M)
15.8.27.15

File size:
880 KB (901,088 bytes)

Product version:
4.0.0.0

Copyright:
Carifred © 2010 - 2015

Trademarks:
Carifred.com

Original file name:
UltraAdwareKiller.exe

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\ultra adware killer 1.6.0.0 x64.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/9/2014 3:00:00 AM

Valid to:
3/10/2019 2:59:59 AM

Subject:
CN=Alfredo Anibal santos silva, O=Alfredo Anibal santos silva, STREET=Résidence les angéliques, STREET=Rue du grand large, L=Port vendres, S=Languedoc - Roussillon, PostalCode=66660, C=FR

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00E4E0EEAC938C9428AF79577D5C6F9663

File PE Metadata
Compilation timestamp:
8/26/2015 1:11:33 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
24576:oGnkLvQHwxfN/cRPDA6+60osu0m5MZgQJs9FlxwnHcvw1o+zpFO92zieV0aJBCkH:o+EDxf4Eo8PSvQXhkWgOLSIe5d1pY

Entry address:
0x54F3C

Entry point:
48, 83, EC, 28, E8, BB, 03, 00, 00, 48, 83, C4, 28, E9, 72, FE, FF, FF, CC, CC, 40, 53, 48, 83, EC, 20, 48, 8B, D9, 48, 8B, C2, 48, 8D, 0D, 65, DF, 01, 00, 48, 89, 0B, 48, 8D, 53, 08, 33, C9, 48, 89, 0A, 48, 89, 4A, 08, 48, 8D, 48, 08, E8, BC, 3C, 00, 00, 48, 8D, 05, 5D, DF, 01, 00, 48, 89, 03, 48, 8B, C3, 48, 83, C4, 20, 5B, C3, CC, 33, C0, 48, 89, 41, 10, 48, 8D, 05, 53, DF, 01, 00, 48, 89, 41, 08, 48, 8D, 05, 38, DF, 01, 00, 48, 89, 01, 48, 8B, C1, C3, CC, 40, 53, 48, 83, EC, 20, 48, 8B, D9, 48, 8B, C2...
 
[+]

Code size:
449.5 KB (460,288 bytes)

The file ultra adware killer 1.6.0.0 x64.exe has been seen being distributed by the following 5 URLs.

http://113.171.224.169/.../UltraAdwareKiller64.exe

Remove ultra adware killer 1.6.0.0 x64.exe - Powered by Reason Core Security