propccleaner.exe

Pro PC Cleaner

Rainmaker Software Group LLC

The application propccleaner.exe, “This installer database contains the logic and data required to install Pro PC Cleaner.” by Rainmaker Software Group has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software.
Publisher:
Rainmaker Software Group LLC.​  (signed by Rainmaker Software Group LLC)

Product:
Pro PC Cleaner

Description:
This installer database contains the logic and data required to install Pro PC Cleaner.

Version:
2.5.6

MD5:
d5f07e55e6cdd69a65cac7c186e4631a

SHA-1:
51d063bb2b3728f6bf2f5f0e83b1131966253fe6

SHA-256:
579d4eaeee8d21c8ca7a49b42784b3890f71f14d7dd2c6aea772592d2cd77f4f

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/23/2024 11:55:21 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Rainmaker.Installer.Meta (L)
16.6.13.20

File size:
6.3 MB (6,604,080 bytes)

Product version:
2.5.6

Copyright:
Copyright (C) 2014 Rainmaker Software Group LLC.​

Original file name:
ProPCCleanerSetup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\propccleaner.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
11/11/2014 7:00:00 PM

Valid to:
11/12/2015 6:59:59 PM

Subject:
CN=Rainmaker Software Group LLC, O=Rainmaker Software Group LLC, L=Wilmington, S=Delaware, C=US, SERIALNUMBER=5411289, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Delaware, OID.1.3.6.1.4.1.311.60.2.1.3=US

Issuer:
CN=Symantec Class 3 Extended Validation Code Signing CA - G2, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
71B3EF9E363C3440B74AB0B78DC2553E

File PE Metadata
Compilation timestamp:
10/7/2014 11:05:58 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
98304:iG7cl1155MF19LK5He/amQ/J47IuYPVRwF81Q3gKSfViDB06I/A1R778EC:vuQ65HeA4E9Rw+Q3gKesIA1RH8EC

Entry address:
0xC87EC

Entry point:
E8, 4A, CC, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 51, 53, 56, 8B, F0, 33, DB, 3B, F3, 75, 1E, E8, 5D, 4D, 00, 00, 6A, 16, 5E, 53, 53, 53, 53, 53, 89, 30, E8, C5, D5, FF, FF, 83, C4, 14, 8B, C6, E9, C2, 00, 00, 00, 57, 39, 5D, 0C, 77, 1E, E8, 39, 4D, 00, 00, 6A, 16, 5E, 53, 53, 53, 53, 53, 89, 30, E8, A1, D5, FF, FF, 83, C4, 14, 8B, C6, E9, 9D, 00, 00, 00, 33, C0, 39, 5D, 14, 66, 89, 06, 0F, 95, C0, 40, 39, 45, 0C, 77, 09, E8, 0A, 4D, 00, 00, 6A, 22, EB, CF, 8B, 45, 10, 83, C0, FE, 83, F8, 22, 77...
 
[+]

Entropy:
7.7851  (probably packed)

Code size:
1021.5 KB (1,046,016 bytes)

Remove propccleaner.exe - Powered by Reason Core Security