netclean.exe

Fix and patch windows update

Nanjing Baishite Gardens Co., Ltd.

The executable netclean.exe has been detected as malware by 10 anti-virus scanners.
Publisher:
MicrosoftAffilate  (signed by Nanjing Baishite Gardens Co., Ltd.)

Product:
Fix and patch windows update

Version:
3.9.2.2

MD5:
4d6d0c8484962774f74571ee7093d92f

SHA-1:
9c69e3bc3292c774d40e4b22a5fd416ab4f81b9b

SHA-256:
1dc94ba12e8df53df8ead122ace2eb58d0155fc0a160516038d689afdaf26f3d

Scanner detections:
10 / 68

Status:
Malware

Analysis date:
11/16/2024 8:36:40 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Trojan.Heur.3Q1@rS4O!Uci
6779108

Bitdefender
Gen:Trojan.Heur.3Q1@rS4O!Uci
1.0.20.315

Emsisoft Anti-Malware
Gen:Trojan.Heur.3Q1@rS4O!Uci
9.0.0.4799

F-Prot
W32/Threat-SysVenFak-based!Maxi
4.6.5.141

F-Secure
Gen:Trojan.Heur.3Q1@rS4O!Uci
5.13.68

G Data
Gen:Trojan.Heur.3Q1@rS4O!Uci
15.3.25

herdProtect (fuzzy)
2015.6.11.2

Microsoft Security Essentials
Threat.Undefined
1.193.1647.0

MicroWorld eScan
Gen:Trojan.Heur.3Q1@rS4O!Uci
16.0.0.189

Norman
Gen:Trojan.Heur.3Q1@rS4O!Uci
03.12.2014 13:20:04

File size:
2.9 MB (3,008,600 bytes)

Product version:
3.9.2.2

Copyright:
MicrosoftAffilate

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\youtube-downloader\g1\netclean.exe

Digital Signature
Authority:
WoSign CA Limited

Valid from:
3/2/2015 3:53:11 AM

Valid to:
3/2/2016 3:53:11 AM

Subject:
CN="Nanjing Baishite Gardens Co., Ltd.", O="Nanjing Baishite Gardens Co., Ltd.", L=Nanjing, S=Jiangsu, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA, O=WoSign CA Limited, C=CN

Serial number:
1B224EE507B4D09B57EB838796D6181C

File PE Metadata
Compilation timestamp:
3/4/2015 9:42:06 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:BKpJkDicdCSS7aI+IoQDxw1jfmVmxYLkWiGcoFXhi6r5D:BCiDHINcjGd7

Entry address:
0x2595DC

Entry point:
55, 8B, EC, 83, C4, F0, B8, CC, CD, 64, 00, E8, 14, 2C, DB, FF, 33, C0, 55, 68, 5B, 96, 65, 00, 64, FF, 30, 64, 89, 20, E8, D5, B6, DA, FF, 83, F8, 02, 7C, 49, A1, 7C, 2C, 66, 00, 8B, 00, E8, 40, 6B, EC, FF, A1, 7C, 2C, 66, 00, 8B, 00, C6, 40, 5F, 00, A1, 7C, 2C, 66, 00, 8B, 00, 33, D2, E8, 47, 88, EC, FF, 8B, 0D, 98, 29, 66, 00, A1, 7C, 2C, 66, 00, 8B, 00, 8B, 15, A8, BE, 64, 00, E8, 27, 6B, EC, FF, A1, 7C, 2C, 66, 00, 8B, 00, E8, 7F, 6C, EC, FF, 33, C0, 5A, 59, 59, 64, 89, 10, 68, 62, 96, 65, 00, C3, E9...
 
[+]

Entropy:
6.5732

Developed / compiled with:
Microsoft Visual C++

Code size:
2.3 MB (2,456,064 bytes)

Remove netclean.exe - Powered by Reason Core Security