ccleaner.exe

Installation Wizard

Advertiso GmbH

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application ccleaner.exe by Advertiso GmbH has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. With this installer, users are expecting to download the free Piriform CCleaner but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
SecuredDownload  (signed by Advertiso GmbH)

Product:
Installation Wizard

Version:
1.0.13.24053

MD5:
9eafadc7131c911df9eb7b961adec609

SHA-1:
a64a5cba7a83b7c657263fefc0da8f2601d70670

SHA-256:
1083007b32d0d6d9e61f096590b4280ab91f65ec8e91be630c6a4e9d1e3a1404

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/24/2024 11:54:38 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore (M)
17.3.15.9

File size:
1.2 MB (1,213,104 bytes)

Product version:
1.0.13.24053

Copyright:
SecuredDownload

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\ccleaner.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
1/20/2016 3:52:17 PM

Valid to:
5/17/2017 3:53:46 PM

Subject:
CN=Advertiso GmbH, O=Advertiso GmbH, L=Hamburg, S=Hamburg, C=DE

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11218D42D633AAFCED2E0A8CAF0245EEE3D1

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

Remove ccleaner.exe - Powered by Reason Core Security