adwcleaner.exe

Ultra Setup Manager

Husren SA

This is a self-extracting archive and installer. The file has been seen being downloaded from develop2repo.com and multiple other hosts.
Publisher:
MS  (signed by Husren SA)

Product:
Ultra Setup Manager

Version:
1.0.4.33

MD5:
b374b229c8780e965927133b825be2dc

SHA-1:
4c9d21a38894fa473b69738f3e3ebd93b9030da5

SHA-256:
c0d66a59778b848c49bcc2673f5b1ba19f4024239cc02f0d84deac2228b6fd5f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/25/2024 6:13:47 AM UTC  (today)

File size:
30.1 KB (30,824 bytes)

Product version:
1.0.4.33

Copyright:
Copyright © 2015

Trademarks:
MS

Original file name:
iEx.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\adwcleaner.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
6/11/2015 9:00:00 PM

Valid to:
6/11/2016 8:59:59 PM

Subject:
CN=Husren SA, OU=602, O=Husren SA, STREET=Colonia 810 esc502, L=Montevideo, S=Montevideo, PostalCode=11000, C=UY

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
13D29ADB2F499B625116D9BBF3D8B83F

File PE Metadata
Compilation timestamp:
8/31/2015 11:21:14 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
192:PLC5JoT0onY9u2y+psa0EhZiyMrj1g6g2PmbbhXH87uGauospvxwu7nrAAnh+:G56T0oY9ul+psa0EhzMaTriw6rq

Entry address:
0x2EEE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
4 KB (4,096 bytes)

The file adwcleaner.exe has been seen being distributed by the following 40 URLs.

http://develop2repo.com/getAd.php?f=iEx.exe&fc=adobe-acrobat-reader.exe

http://repodepo2.com/getAd.php?f=iEx.exe&fc=cacaoweb-free.exe

http://develop2repo.com/getAd.php?f=iEx.exe&fc=vlc.exe

http://repodepo2.com/getAd.php?f=iEx.exe&fc=mp3rocket.exe

http://repodepo1.com/getAd.php?f=iEx.exe&fc=happy-wheels-1-1-0.exe

http://ropedope3.com/getAd.php?f=iEx.exe&fc=angry-birds.exe

http://repodepo3.com/getAd.php?f=iEx.exe&fc=firefox-2-3.exe

Latest 30 of 40 download URLs

Scan adwcleaner.exe - Powered by Reason Core Security