claro.exe

claro-search

The application claro.exe has been detected as a potentially unwanted program by 10 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider. The file has been seen being downloaded from cdn.guttastatdk.us.
Publisher:
claro-search

Product:
claro-search

Version:
1.0

MD5:
5c7e43b2f4c7c6ba4041bc8f3f563205

SHA-1:
26210619ebfc706e5e43931f11e89b599cb87a50

SHA-256:
a73e8386b80756a9202f2c59042608d51af93518372624a3f39aed9dd516caf3

Scanner detections:
10 / 68

Status:
Potentially unwanted

Explanation:
The installer may include an offer for the Babylon Toolbar (a homepage/search hijacker), which is potentially installed with minimal user consent.

Analysis date:
12/25/2024 12:47:09 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Toolbar.Babylon
7.1.1

AVG
Toolbar.Babylon
2016.0.3235

Baidu Antivirus
Adware.Win32.Bbylon
4.0.3.1519

Bkav FE
W32.Clod541.Trojan
1.3.0.4959

Dr.Web
Adware.Toolbar.26
9.0.1.09

ESET NOD32
Win32/DownWare
9.10695

Fortinet FortiGate
Adware/Toolbar
1/9/2015

NANO AntiVirus
Riskware.Win32.Babylon.deintc
0.28.6.62995

Trend Micro House Call
TROJ_DLOADER.ABXZ
7.2.9

Trend Micro
TROJ_DLOADER.ABXZ
10.465.09

File size:
927.9 KB (950,171 bytes)

Copyright:
© claro-search

Trademarks:
claro-search.com

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\flash-player_083\software\claro.exe

File PE Metadata
Compilation timestamp:
12/5/2009 4:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:HC20zuaMhhVE9AiE8fD/gTvQEGFRe1AdXTN/6bgi7:70HMzVEnEG4EJ61Az6/7

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9592

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file claro.exe has been seen being distributed by the following URL.

Remove claro.exe - Powered by Reason Core Security