pw clean - 2.6.9 - [atalhos].exe

Wallinson Oliveira Schutte

This is a setup program which is used to install the application. The file has been seen being downloaded from dc364.4shared.com and multiple other hosts.
Publisher:
Wallinson Oliveira Schutte  (signed and verified)

MD5:
4c7f218d6a1cb30a3221aa7a44b5a9b1

SHA-1:
526f4352c3f5f54f5b0a9e380abfae6b4e4c2a07

SHA-256:
581326b715286a12864f0f91618b2c082f0aa68d5480958de8a61fd29aef0b2a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 4:37:39 AM UTC  (today)

File size:
1.4 MB (1,424,424 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\pw clean - 2.6.9 - [atalhos].exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
5/29/2016 5:00:00 PM

Valid to:
7/7/2017 5:00:00 AM

Subject:
CN=Wallinson Oliveira Schutte, O=Wallinson Oliveira Schutte, L=Teófilo Otoni, S=Minas Gerais, C=BR

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0A4866D10DD4A402CEEE08787EEA5BD3

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:4gsRpX2WmWCveO2MeJLftkKtwGjsvae1NcHHoT:4g62Wp8e1wa/4

Entry address:
0xD01F4

Entry point:
55, 8B, EC, 83, C4, F0, B8, CC, FE, 4C, 00, E8, CC, 68, F3, FF, A1, D4, 2D, 4D, 00, 8B, 00, E8, 48, D2, F9, FF, 8B, 0D, 48, 2F, 4D, 00, A1, D4, 2D, 4D, 00, 8B, 00, 8B, 15, 90, 9E, 4A, 00, E8, 48, D2, F9, FF, A1, D4, 2D, 4D, 00, 8B, 00, E8, BC, D2, F9, FF, E8, 8F, 45, F3, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
829 KB (848,896 bytes)

The file pw clean - 2.6.9 - [atalhos].exe has been seen being distributed by the following 3 URLs.

http://dc364.4shared.com/download/.../remove_vrus_que_cria_atalhos_n.exe

http://ufpr.dl.sourceforge.net/project/.../PW Clean - 2.6.9 - [Atalhos].exe

http://downloads.sourceforge.net/project/.../PW Clean - 2.6.9 - [Atalhos].exe

Scan pw clean - 2.6.9 - [atalhos].exe - Powered by Reason Core Security