pclunst.exe

PC Cleaners Inc.

The application pclunst.exe by PC Cleaners has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. This is the uninstaller utility registered in the Windows Control Panel for the program PC Cleaners by PC Cleaners. The file has been seen being downloaded from RevenueWire's affiliate distribution platform pcdesk1.nwpc.revenuewire.net and multiple other hosts.
Publisher:
PC Cleaners  (signed by PC Cleaners Inc.)

Product:
PC Cleaners

Description:
PC Cleaner Pro

Version:
10.0.0.0

MD5:
e826be08cc5c9e730bdb07f3d062e5da

SHA-1:
592758d5e90fe259462b7f3b71d2d7c52769184e

SHA-256:
b0c3156d165ab0d7b71766ebdc0b88ed2f95bcca1179abec331dffa4b71e6eaf

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/23/2024 5:21:16 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.PCCleaner.Installer.Meta (M)
16.6.10.14

File size:
5.2 MB (5,404,512 bytes)

Product version:
10.0.0.0

Copyright:
(c)2015 PC Cleaners Inc. All rights reserved.

Original file name:
PCSetup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\pclunst.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
2/20/2015 1:00:00 AM

Valid to:
2/20/2017 12:59:59 AM

Subject:
CN=PC Cleaners Inc., O=PC Cleaners Inc., POBox=92677, STREET="220 Newport Center Dr. Suite #197", L=Newport Beach, S=California, PostalCode=92660, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
4A378F900AF4F6360FF3B19DFF48F58F

File PE Metadata
Compilation timestamp:
6/11/2015 6:50:43 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
98304:BSHz20ZBw517qB0P6Uw4Xs/eWs8nVhf1A5ltPbSIIHuta3HTvS:iwnf6StWs8n3f1otOnHz3H+

Entry address:
0x4FFEF20

Entry point:
60, BE, 00, 00, EE, 04, 8D, BE, 00, 10, 52, FB, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
5.1 MB (5,373,952 bytes)

Program Uninstaller
Program name:
PC Cleaners

Display publisher:
PC Cleaners

Uninstall string:
"C:\ProgramData\pclunst.exe" -removeit


The file pclunst.exe has been seen being distributed by the following 2 URLs.

Remove pclunst.exe - Powered by Reason Core Security