adb.exe

Simple Leads LLC

The application adb.exe by Simple Leads has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Simple Leads LLC  (signed and verified)

MD5:
36d80e06893ee55d00a7402fa0587d3c

SHA-1:
0770f7788f2736fb720956dd6d8dc909fe338fcd

SHA-256:
2bf00da4bd9afe7e25fd00949eabdc12b80e20ac98cbc1ebf180de6f05f0beb6

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/12/2024 7:32:29 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.3.4.6

File size:
1.4 MB (1,425,912 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\one click root\one click root\adb.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
4/11/2016 5:00:00 PM

Valid to:
3/8/2017 4:00:00 AM

Subject:
CN=Simple Leads LLC, O=Simple Leads LLC, L=White Plains, S=New York, C=US

Issuer:
CN=DigiCert SHA2 High Assurance Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
079005AFBD2EFBF77EF042AE1BFD1F2C

File PE Metadata
Compilation timestamp:
1/19/1998 9:23:09 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
2.24

Entry address:
0x1510

Entry point:
83, EC, 0C, C7, 05, 3C, 26, 56, 00, 00, 00, 00, 00, E8, BE, B1, 09, 00, 83, C4, 0C, E9, 56, FC, FF, FF, 90, 90, 90, 90, 90, 90, 83, EC, 1C, C7, 04, 24, 3A, 01, 00, C0, E8, F9, CA, 0A, 00, 90, 55, 89, E5, 57, 56, 89, C6, 53, 81, EC, 3C, 02, 00, 00, 8D, 9D, E0, FD, FF, FF, C7, 85, D8, FD, FF, FF, 61, 64, 62, 2E, C7, 85, DC, FD, FF, FF, 6C, 6F, 67, 00, 89, 5C, 24, 04, C7, 04, 24, 04, 01, 00, 00, FF, 15, 20, 55, 56, 00, 83, E8, 01, 83, EC, 08, 3D, 02, 01, 00, 00, 0F, 87, 82, 00, 00, 00, 8D, BD, D4, FD, FF, FF...
 
[+]

Entropy:
6.4025

Code size:
1.1 MB (1,110,528 bytes)

Remove adb.exe - Powered by Reason Core Security