adwcleaner_setup_download.exe

DownloadGuide

The executable adwcleaner_setup_download.exe has been detected as malware by 5 anti-virus scanners. The file has been seen being downloaded from adwcleaner.pro.de.
Product:
DownloadGuide

Version:
1.4.0.2

MD5:
5e58e3bc644962ad8edf95525399ae94

SHA-1:
c24d9fbc13d6cec0802607b699dfe97e7cf6ad6a

SHA-256:
86aefb8edee08640fb6e004c3b31ada1c145e7a65b261016cb56f8fac7637fdf

Scanner detections:
5 / 68

Status:
Malware

Analysis date:
12/25/2024 5:56:15 PM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
Troj.Dropper.Gen
2.1.4+

Bkav FE
HW32.CDB
1.3.0.4959

Dr.Web
Trojan.DownLoader9.20206
9.0.1.094

ESET NOD32
MSIL/DownloadGuide (variant)
8.9637

G Data
Win32.Application.DownloadGuide
14.4.24

File size:
668.7 KB (684,776 bytes)

Product version:
1.4.0.2

Copyright:
Copyright © 2014

Original file name:
in.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\adwcleaner_setup_download.exe

File PE Metadata
Compilation timestamp:
1/31/2014 5:02:56 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:+jmmcqVmWEcQwHa8CFNMQoQJu6jCs1mkqVKyAXjd9ELMu71:OABcQwHauQ3/jCsatAb+Muh

Entry address:
0x7EDCE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 48, B8, 00, 00, 00, 00, 00, 00, 00, 00, 49, 39, 40, 08, 74, 0C, 48, B8, 00, 00, 00, 00, 00, 00, 00, 00, FF, E0, 48, B8, 00, 00, 00, 00, 00, 00, 00, 00, FF, E0, 55, 8B, EC, 8B, 45, 10, 81, 78, 04, 7D, 1D, EA, 0C, 74, 07, B8, B6, B1, 4A, 06, EB, 05, B8, B6, 92, 40, 0C, 5D, FF, E0, 7B, 05, 4A, 0C, F4, 9C, DD, 9A...
 
[+]

Entropy:
7.1346

Code size:
499.5 KB (511,488 bytes)

The file adwcleaner_setup_download.exe has been seen being distributed by the following URL.

Remove adwcleaner_setup_download.exe - Powered by Reason Core Security