sparktrust pc cleaner plus setup.exe

SparkTrust Systems

The application sparktrust pc cleaner plus setup.exe, “SparkTrust PC Cleaner Plus Installer” by SparkTrust Systems has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. The file has been seen being downloaded from RevenueWire's affiliate distribution platform spark2.sparktrust.revenuewire.net and multiple other hosts.
Publisher:
SparkTrust  (signed by SparkTrust Systems)

Description:
SparkTrust PC Cleaner Plus Installer

Version:
3.1.9.0

MD5:
14b8d11e80157fa76bba8332fe9c6a5d

SHA-1:
cbdba43a749f0f413b5eb0f05a7d07dceced4712

SHA-256:
651fc3749507d7239fddf57faf06462e4bb4b6a59578e45caacd1af8bdf46176

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/28/2024 7:32:50 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.SparkTrust.Installer.Meta (L)
16.7.12.8

File size:
5.6 MB (5,912,360 bytes)

Copyright:
Copyright © 2013 SparkTrust

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\sparktrust pc cleaner plus setup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
4/4/2013 11:17:59 AM

Valid to:
4/4/2014 4:00:13 PM

Subject:
CN=SparkTrust Systems, O=SparkTrust Systems, C=CA

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112188E80872CB93AAD5F8D9BA185623CFA1

File PE Metadata
Compilation timestamp:
2/24/2012 2:19:59 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:rci5nw/kYBCYOflFVFjhaOJnADVTH0FvfMMXCRSNXJ6kbpxehKBq26jiNde:J5xYOfVFEO9ADifzRNXqEBke+

Entry address:
0x39E3

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 91, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, C0, 82, 40, 00, 6A, 08, A3, B8, 2E, 47, 00, E8, 37, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, D0, 2D, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 93, 40, 00, FF, 15, 84, 81, 40, 00, 68, 04, 93, 40, 00, 68, C0, AD, 46, 00, E8, 19, 27, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 30, 4C, 00, 57, E8, 07, 27, 00, 00...
 
[+]

Entropy:
7.9978  (probably packed)

Code size:
28 KB (28,672 bytes)

The file sparktrust pc cleaner plus setup.exe has been seen being distributed by the following 7 URLs.

Remove sparktrust pc cleaner plus setup.exe - Powered by Reason Core Security