adwcleaner.exe

Setup Manager

QUALITY SCORE SL

The application adwcleaner.exe by QUALITY SCORE SL has been detected as adware by 2 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. The file has been seen being downloaded from offersrepo.com and multiple other hosts. While running, it connects to the Internet address 198-154-229-28.unifiedlayer.com on port 80 using the HTTP protocol.
Publisher:
QUALITY SCORE SL  (signed and verified)

Product:
Setup Manager

Version:
2.7.4.106

MD5:
79392c0a7084bfc1c8846560ef5a8a20

SHA-1:
c44d92c7f1f2ed8ed1e84391aab4e50cf175efeb

SHA-256:
873327ed2724b5834b70a7af12e86885c8d3ea604efc25263cd921e5ad24f824

Scanner detections:
2 / 68

Status:
Adware

Analysis date:
12/25/2024 1:51:10 PM UTC  (today)

Scan engine
Detection
Engine version

IKARUS anti.virus
AdWare.MSIL.Colooader
t3scan.1.7.8.0

Reason Heuristics
PUP.Installer.QUALITYSCORESL.K
14.9.13.15

File size:
194.8 KB (199,480 bytes)

Product version:
2.7.4.106

Copyright:
Copyright © 2014

Original file name:
DynmicInstaller.exe

File type:
Executable application (Win64 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\adwcleaner.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/2/2014 1:00:00 AM

Valid to:
1/3/2015 12:59:59 AM

Subject:
CN=QUALITY SCORE SL, O=QUALITY SCORE SL, STREET=CALLE SERRANO 213, L=MADRID, S=MADRID, PostalCode=28016, C=ES

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
4AB0F061E1C305B4B31A8ACE3AEA2E01

File PE Metadata
Compilation timestamp:
9/8/2014 9:13:51 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:G03QTy2KerSh0a7biVNsrNfVA694N87fe+eI:ZCy2K1swJ6I2G/N

Entry address:
0x2BB4A

Entry point:
4D, 5A, 90, 00, 03, 00, 00, 00, 04, 00, 00, 00, FF, FF, 00, 00, B8, 00, 00, 00, 00, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 80, 00, 00, 00, 0E, 1F, BA, 0E, 00, B4, 09, CD, 21, B8, 01, 4C, CD, 21, 54, 68, 69, 73, 20, 70, 72, 6F, 67, 72, 61, 6D, 20, 63, 61, 6E, 6E, 6F, 74, 20, 62, 65, 20, 72, 75, 6E, 20, 69, 6E, 20, 44, 4F, 53, 20, 6D, 6F, 64, 65, 2E, 0D, 0D, 0A, 24, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Code size:
167 KB (171,008 bytes)

The file adwcleaner.exe has been seen being distributed by the following 47 URLs.

http://offersrepo.com/download.php?__tc=1410662950234&signature=qualityscore&downloadName=windows-8-1-system.exe

http://teamviewer.logiciel-bureau.com/.../teamviewer.exe

http://picasa-3.logiciel-bureau.com/.../picasa-3.exe

http://offersrepo.com/download.php?__tc=1411294922952&signature=qualityscore&downloadName=google-chrome-29.exe

http://ms-office-2013.free-safe.com/.../ms-office-2013.exe

http://zune-software.go-download.net/.../zune-software.exe

http://libre-office.logiciel-bureau.com/.../libre-office.exe

http://athan-azan-basic-4-4.logiciel-bureau.com/.../athan-azan-basic-4-4.exe

http://glary-utilities.descargas205.com/.../glary-utilities.exe

http://adblock-plus.descargas205.com/.../adblock-plus.exe

http://outlook-express.descargas205.com/.../outlook-express.exe

Latest 30 of 47 download URLs

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to 198-154-229-28.unifiedlayer.com  (198.154.229.28:80)

TCP (HTTP):
Connects to 162-144-91-108.unifiedlayer.com  (162.144.91.108:80)

Remove adwcleaner.exe - Powered by Reason Core Security