rcpsetup_17970.exe

RegClean Pro

systweak.com

The application rcpsetup_17970.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from cloudfront.systweak.com.
Publisher:
systweak.com

Product:
RegClean Pro

Version:
RegClean Pro

MD5:
7f012e338e30a3518b37554e36fa20fd

SHA-1:
67a0b47a42ddcaccb92dd95b4c63ce50f1558948

SHA-256:
87a86d3c380dfd87c74cc651856f84644f5a65e465409778ecab217b3c851d6d

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 1:12:02 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Systweak.Optional.Installer.Meta (L)
16.5.24.15

File size:
627.5 KB (642,560 bytes)

Product version:
6.21

Copyright:
© systweak.com

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\rcpsetup_17970.exe

File PE Metadata
Compilation timestamp:
7/9/2012 8:41:29 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:W3MjhM1ZUL2IumBhuU76LbL2RyxHH888888888888W888888888888r/S5:gMjhqiLRLhls6Rywze

Entry address:
0x16478

Entry point:
85, F2, 8D, 3D, AC, EC, E5, 6C, 51, 68, 51, 83, 5C, 00, 80, E4, 5F, 0F, AF, ED, 30, FD, 2A, D4, 8B, D2, 87, DB, 69, C0, 45, 87, A2, AE, 80, D9, 57, 87, ED, 85, D2, 71, 05, 29, D6, F6, C3, 81, 12, D4, 84, DA, 8A, F2, 8D, 17, 52, 5D, 81, DA, 0F, 51, ED, 47, BA, 6A, 1C, 95, 11, 8B, F5, 89, DA, 2A, D7, 0B, D6, 89, EA, 83, E3, 00, 8B, ED, F7, C3, DA, CC, BA, F5, 03, DE, B6, 43, 84, E2, EB, 09, 89, CE, 8D, 35, EC, 9B, B2, 09, F3, 8D, 0B, 0F, B7, D1, FF, CA, 8A, F3, 8D, 01, 0F, BE, D1, 85, D6, 70, 08, 8D, 1D, 52...
 
[+]

Code size:
84 KB (86,016 bytes)

The file rcpsetup_17970.exe has been seen being distributed by the following URL.

Remove rcpsetup_17970.exe - Powered by Reason Core Security