yet_another_cleaner_sk.exe

YAC Security Protection

Elex do Brasil Participações Ltda

The application yet_another_cleaner_sk.exe by Elex do Brasil Participaçõesa has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. The file has been seen being downloaded from www.yac.mx and multiple other hosts.
Publisher:
Elex do Brasil Participações Ltda  (signed and verified)

Product:
YAC Security Protection

Description:
Setup

Version:
5.6.105.19081

MD5:
cc65d4efbf70f21579a3d2270dbf19e3

SHA-1:
0f7e3153bbc1b3e998801127eb4b2ce0b46f8475

SHA-256:
4fb3f80ebb17f652dae6a704538c7ab0168618318054962d36e0cef3d5b93a95

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 9:58:06 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Optional.Installer.W
14.11.20.13

File size:
14.6 MB (15,281,584 bytes)

Product version:
5.6.105.19081

Copyright:
Copyright (c) 2011-2014 Elex do Brasil Participações Ltda

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\yet_another_cleaner_sk.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/22/2014 7:00:00 PM

Valid to:
6/20/2015 6:59:59 PM

Subject:
CN=Elex do Brasil Participações Ltda, O=Elex do Brasil Participações Ltda, L=São Paulo, S=São Paulo, C=BR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5C6950D0A05A1CD63164D1E1EB1FFB8A

File PE Metadata
Compilation timestamp:
11/20/2014 3:25:26 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
393216:xWeWWXiNiNGRkPLaras9Yum+R4j58zKt8nnGCR:AWXxJLarLYfqzKmnnGCR

Entry address:
0x3F292

Entry point:
E8, 9E, 1A, 01, 00, E9, 39, FE, FF, FF, 55, 8B, EC, 56, 8B, 75, 08, 83, 3C, F5, 70, 19, 48, 00, 00, 75, 13, 56, E8, 91, 00, 00, 00, 59, 85, C0, 75, 08, 6A, 11, E8, AD, 88, 00, 00, 59, FF, 34, F5, 70, 19, 48, 00, FF, 15, 94, D1, 46, 00, 5E, 5D, C3, E8, 3E, 29, 00, 00, 85, C0, 75, 0B, FF, 74, 24, 04, 50, FF, 15, 50, D2, 46, 00, 68, FF, 00, 00, 00, E8, 58, 87, 00, 00, 59, C3, 56, 57, BE, 70, 19, 48, 00, 8B, FE, 53, 8B, 1F, 85, DB, 74, 17, 83, 7F, 04, 01, 74, 11, 53, FF, 15, A4, D0, 46, 00, 53, E8, 8F, BE, FF...
 
[+]

Entropy:
7.8989  (probably packed)

Code size:
431.5 KB (441,856 bytes)

The file yet_another_cleaner_sk.exe has been seen being distributed by the following 20 URLs.

http://www.yac.mx/.../658623

http://global-shared-files-l3.softonic.com/0f7/e31/.../file?nvb=20150123173759&nva=20150124053859&token=00b04b97e2ab5fb6641ee&SD_used=0&channel=WEB&fdh=yes&id_file=69665508&instance=softonic_fr&type=PROGRAM&filename=yet_another_cleaner_sfto_5_6_105.exe

http://www.softonic.com/sads/tracker.php?ev=c&co=ES&sid=e93f3f2b7df3c05d4d352619772071e5&upv=a691b5dd43a361e0b5b0c6ffd2b04b7d&z=results&sk=0&abt=&eid=&params=F24F8F4D368AFA5D32C8A90D9EFD1CBAC9B15663BFCC32A4B420C96190DC24F2C4EC6E561351677C77086EC499320CACD5021AB3672758348078DBC31F8467FDB310D52CC97BB8B87CD32564B6F1E206CBCB6AE03A81379C5F5065BCF515F0C96545E2CF592E9EDC22AA6F04F7C4ACDA72755E1551C81C4E06E0E56CC12056369ACC761E25460462E2A7D5A59EABB6FDD3F78E193A8E5E4AD8BCFCDEBD563175105FEB5760601E7B1690B6029A896274&h=B6F2571B1B6EAF07D38BFEBC476F72124E972F772766A6F1A9C82B29B56C64D6&directdownload=1&f=69665508&d=http://dl.yac.mx/download/.../yet_another_cleaner_sftc.exe

http://www.softonic.com/sads/tracker.php?ev=c&co=US&sid=d3f9c34f9704be1935a009f9d4426ac9&upv=e39e03c04ecf1a927a277f0190cb81f4&z=results&sk=0&abt=&eid=&params=F24F8F4D368AFA5D32C8A90D9EFD1CBAC9B15663BFCC32A4B420C96190DC24F2C4EC6E561351677C77086EC499320CAC3CA5E7EB440B9F07FCB18AD5BF2142044686CF12E4890860CBFC85ED61FBAFECA681057E481C0AD8E532B2AD9CD3ABF87D8FDC4BE3C734E4C57A77A8E5235C879FBD13F5B83CD758FF7D03014D10564FE32BDE80D98B6C46B91DAB9E9C2EBE6FC25BCED5DB275A05CE1DC252C757A9493542CE4A6DF1DDC6FB9626DCE19B5093&h=3E13F445E92F20C0C79F8971B5CFABE826BC37BF3165AAF2832B4D9A5902B985&directdownload=1&f=69665508&d=http://dl.yac.mx/download/.../yet_another_cleaner_sftc.exe

http://global-shared-files-l3.softonic.com/0f7/e31/.../file?nvb=20141130191705&nva=20141201071805&token=05f96c0e6bc9126d707e7&instance=softonic_br&filename=yet_another_cleaner_sfto_5_6_105.exe

Remove yet_another_cleaner_sk.exe - Powered by Reason Core Security