registrycleanerpro.exe

The program is a setup application that uses the Nullsoft Scriptable Install System installer. The file has been seen being downloaded from downloads.otweak.com.
MD5:
089cfd8bf635875ae5e59cf81a12a452

SHA-1:
555fe00317f40d6dcba48d710874dae339c6f2d9

SHA-256:
99fb8d9bb76d825f592ac6ca7e16b38e5b044a82406560dded71527a682de537

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 6:43:02 AM UTC  (today)

File size:
2.7 MB (2,790,856 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Scriptable Install System

Common path:
C:\users\{user}\downloads\registrycleanerpro.exe

File PE Metadata
Compilation timestamp:
12/6/2009 12:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:jLGcsH0zq7hoRy3DM6/NTZtgK6vKq65GEGnnHM3e2MqAsouGKo4Q7y4fsGYnZH:XGcg0zq91/NTXsnSGNnnHM3hMZspGV7A

Entry address:
0x30FA

Entry point:
8D, 15, 30, 65, C8, 6A, F3, BA, E0, 6E, 73, 73, 89, F1, 76, 03, 40, 84, DD, F3, B4, 61, C6, C3, 16, F6, C4, D6, 81, FF, 96, AB, 00, 00, 1A, DA, 0F, AF, FE, 0F, AF, D1, 14, 21, 0F, B6, EA, 0B, C6, 85, CE, 80, F0, F6, 81, F8, B7, D3, FD, DA, E8, 00, 00, 00, 00, 5B, 1D, 9E, BD, AA, 46, 21, FE, F6, C2, 9E, 80, E2, C2, F7, C3, 95, F2, 4E, 74, 08, F6, B2, 13, 0F, B6, EB, 46, 12, F0, 81, E9, 38, F4, 00, 00, 81, D0, 49, AA, 9B, 25, F2, 88, FC, 88, F6, 84, DE, BF, 72, 06, 50, 45, 88, F8, F3, 81, C9, F4, 2D, 76, B9...
 
[+]

Entropy:
7.9934  (probably packed)

Code size:
23.5 KB (24,064 bytes)

The file registrycleanerpro.exe has been seen being distributed by the following URL.

Scan registrycleanerpro.exe - Powered by Reason Core Security