adwcleaner.exe

AdwCleaner from Xplode is a free application designed to search for and remove adware such as browser toolbars and other potentially unwanted programs and specifically targets software that is bundled with free programs that you download from the web. This is a setup program which is used to install the application. The file has been seen being downloaded from download.bleepingcomputer.com and multiple other hosts.
Version:
3.2.0.2

MD5:
d67f6941f666e53eef6214da441abc3f

SHA-1:
3e32500d594994d4f3cdc83d6052f84e4d0d3a9d

SHA-256:
d63192e6a72930922c87ac5a4babb11e25139818aa9674491a60217de191a5b6

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
12/28/2024 12:49:06 AM UTC  (today)

Scan engine
Detection
Engine version

Qihoo 360 Security
Malware.QVM11.Gen
1.0.0.1015

File size:
1.3 MB (1,365,865 bytes)

Product version:
3.3.8.1

File type:
Executable application (Win32 EXE)

Language:
French (France)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\adwcleaner.exe

File PE Metadata
Compilation timestamp:
1/29/2012 4:32:28 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:zthEVaPqL7dLaqmjIxXCA7mTJoLkDWLUbkYhotzws7GkyIs6/zVhy4kk:HEVUc7d+qSxwkrD6UbkYAq36a4f

Entry address:
0xCFE90

Entry point:
60, BE, 00, E0, 48, 00, 8D, BE, 00, 30, F7, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
268 KB (274,432 bytes)

The file adwcleaner.exe has been seen being distributed by the following 31 URLs.

http://download.bleepingcomputer.com/dl/5ac4d4098115673975f8b572cbd39d43/53594f72/windows/security/security-utilities/a/.../AdwCleaner.exe

http://download.bleepingcomputer.com/dl/fe7f602d774d7c121d14c9f93e696fb7/535bba01/windows/security/security-utilities/a/.../AdwCleaner.exe

http://download.bleepingcomputer.com/dl/3aa6758f0c96929bdf25f5201ea08c02/53596061/windows/security/security-utilities/a/.../AdwCleaner.exe

q=http://general-changelog-team.fr/fr/downloads/finish/.../2-adwcleaner&redir_token=hfbz_d5qWs68uon8octarVpbNit8MTM5ODM4NzgxNkAxMzk4MzAxNDE2

Latest 30 of 31 download URLs

Scan adwcleaner.exe - Powered by Reason Core Security