yet_another_cleaner_cdls_setup_15375.exe

Setup

Elex do Brasil Participações Ltda

The application yet_another_cleaner_cdls_setup_15375.exe by Elex do Brasil Participaçõesa has been detected as a potentially unwanted program by 6 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. The file has been seen being downloaded from www.softonic.it and multiple other hosts.
Publisher:
Elex do Brasil Participações Ltda  (signed and verified)

Product:
Setup

Version:
1.0.182.28836

MD5:
946cfc915a70901bffdda7f0a1207087

SHA-1:
e5ba1578a3279f306e508e206c47bb6a81959925

SHA-256:
e9000d3d5875257068d0e9a319f52a43de1361a6b0f31e14e251820a1dedca79

Scanner detections:
6 / 68

Status:
Potentially unwanted

Analysis date:
11/5/2024 6:52:20 PM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.HfsAdware
1.3.0.6979

Dr.Web
Adware.Mutabaha.456
9.0.1.0213

G Data
Win32.Application.Elex
15.8.25

IKARUS anti.virus
PUA.Elex
t3scan.1.9.5.0

Malwarebytes
PUP.Optional.ELEX
v2015.08.01.02

Reason Heuristics
Win32.Generic.ELEX.Installer.Meta
15.8.1.14

File size:
846.3 KB (866,648 bytes)

Product version:
1.0.182.28836

Copyright:
Copyright (c) 2011-2015 Elex do Brasil Participações Ltda

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\packages\microsoft.microsoftedge_8wekyb3d8bbwe\ac\#!001\microsoftedge\cache\b96tlm0p\yet_another_cleaner_cdls_setup_15375.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/13/2015 1:00:00 AM

Valid to:
7/13/2017 12:59:59 AM

Subject:
CN=Elex do Brasil Participações Ltda, O=Elex do Brasil Participações Ltda, L=Sao Paulo, S=Consolacao, C=BR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0671EE526ACB6F9BE201F5A8E203C41C

File PE Metadata
Compilation timestamp:
7/30/2015 6:57:11 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:9/cA0Lh7jed/6WV6zj8oC1BEOi/ixaC6Rm3kWribKPYuV+GEcURW/Dvno:90/56kzi1Ni/ic/1Wrib2YuVmVW/Dw

Entry address:
0x9F58

Entry point:
E8, 41, 40, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, FF, 15, 88, 70, 41, 00, 6A, 01, A3, AC, FE, 41, 00, E8, 2C, 45, 00, 00, FF, 75, 08, E8, C1, 44, 00, 00, 83, 3D, AC, FE, 41, 00, 00, 59, 59, 75, 08, 6A, 01, E8, 12, 45, 00, 00, 59, 68, 09, 04, 00, C0, E8, 8F, 44, 00, 00, 59, 5D, C3, 55, 8B, EC, 81, EC, 24, 03, 00, 00, 6A, 17, E8, 11, 70, 00, 00, 85, C0, 74, 05, 6A, 02, 59, CD, 29, A3, 90, FC, 41, 00, 89, 0D, 8C, FC, 41, 00, 89, 15, 88, FC, 41, 00, 89, 1D, 84, FC, 41, 00, 89, 35, 80, FC, 41, 00, 89, 3D, 7C...
 
[+]

Code size:
86.5 KB (88,576 bytes)

The file yet_another_cleaner_cdls_setup_15375.exe has been seen being distributed by the following 36 URLs.

http://www.softonic.it/sads/tracker.php?ev=c&co=IT&sid=c000346d97373bda583ddde37daf8fed&upv=46ed9d01a37a6a08e3a71d2dca7c4ffd&z=list&sk=644&abp=0&params=F24F8F4D368AFA5D32C8A90D9EFD1CBADD0CB244B8D47EE8EF2B6FDF0EA0CE2344562F2C85E4FB0A83BD24934782303578EF99A651AF07B770959A1C578B90DB46BA3FBD250DDA424FD07542C5A3C02D16B378C45850BD6BCB40BA095F315EE22F6CAC49137673BF961CE14D7C30ED54BD7438AA85BE60F5670387F7DCB716DE706BD29E0130059A12B387FF4174CDF48EB5E57638A6CC3EE76A211A641EEC03&h=B55910AB1BFADDE8955AE61D8D05A7ACF66A9EC36CE46FFF81E3D6EEF8405997&directdownload=1&f=69665508&d=http://www.yac-tech.com/download/.../down.php?pt=sftc

http://dl.yac-tech.com/download/.../yet_another_cleaner_dft.exe

http://www.softonic.it/sads/tracker.php?ev=c&co=IT&sid=c2cb898d8c095a01b98db91174aaa113&upv=2d85842e3be2c662e1b0689a9d8bbe51&z=results&sk=0&abp=0&params=F24F8F4D368AFA5D32C8A90D9EFD1CBADD0CB244B8D47EE8EF2B6FDF0EA0CE237E8B55F716ADC97C70D5F4DB55B100F5E555C1D51A4C5A29DD40395EE328F7BF30D67289B661354C9AC21E85C1761A30721D5B7F92E531560F5C6C0CA08697390D93148E211BC91C15425371C55F98C3F4FDFE1F993F5276CDD82F7E49A4B9F530C771D5642F48C25DF75BC16642101A52147116B27B18F280717468DAF993F3&h=414E7401839E1C47F3C7EA4C306827D8E583E699FEC54FE6290D82F53778FB93&directdownload=1&f=69665508&d=http://www.yac-tech.com/download/.../down.php?pt=sftc

http://www.softonic.com/sads/tracker.php?ev=c&co=ES&sid=db548fd758a195fef4e248d736b2781c&upv=e824c2db2150daa4f0962b6986389c95&z=results&sk=0&abp=0&params=F24F8F4D368AFA5D32C8A90D9EFD1CBAC9B15663BFCC32A4B420C96190DC24F2C4EC6E561351677C77086EC499320CACD5021AB3672758348078DBC31F8467FDB310D52CC97BB8B87CD32564B6F1E2067ED25C59A3FD75BB261CD24E07517682C9052556488F1C8CEE139208FBF250EC4871AF7CB14518352454F09BA01F2099CFA3F0E44DF59FABF3C24754471733FF20232FC001B147D80443D3F20CA2634381ED7775C136968E5C3C7E68B9FBD686&h=5214B31CC467BD6DAB458676A01409848B751FAEA367D8EDCFA6F0DADF5232E9&directdownload=1&f=69665508&d=http://www.yac-tech.com/download/.../down.php?pt=sftc

http://fr.softonic.com/sads/tracker.php?ev=c&co=FR&sid=859e57d2232be275c323e3cd730c8a59&upv=cd284bf474a4b8b7cb80882caa024007&z=results&sk=0&abp=0&params=F24F8F4D368AFA5D32C8A90D9EFD1CBA6CC51E5F2F1CC0781D87EC9BB0C214C64EA7E5E4B39867A9F0179C9568FAA3BFE106903F32D362BBB81EEC48886EC11AACA5CA572351188A6D80B1CE8DF2ACBA5A4FA171AAE7DE784A4C8FB38FB5F5AAEAB8C238961B4E5B6919A90892F2A812FC6795F5AAD9CD82F6657AF5A77BA1C510C518A7B0F295948AF7518586CFADD7B6B93702CDC49128C7D637E8A2E7066FA5C92DA95389CFC08E342A65DB51C3CF&h=B5FB7DD5C6DC6023E08C47F97C38323FB1A724CB9D2D9194DE59A776D1E37684&directdownload=1&f=69665508&d=http://www.yac-tech.com/download/.../down.php?pt=sftc

http://www.softonic.com/sads/tracker.php?ev=c&co=ES&sid=ee4ef114801572211587732ded38dc43&upv=724f6e84948458b4df6a8d3ea198b729&z=results&sk=0&abp=1&abt=0&eid=SWH-1566&params=F24F8F4D368AFA5D32C8A90D9EFD1CBAC9B15663BFCC32A4B420C96190DC24F2C4EC6E561351677C77086EC499320CACD5021AB3672758348078DBC31F8467FD710464AA1BE844A83576161450BDC5BD228E4861AC46EF5F914B28C8FC09A4776975A16C5BCADE6DE9B05EB889E87489C5C413977302F33633E09BA4F517B3F7EC09ACA15B8FCD8586789E6A6AC8BF53EB87F22CBED4EDD2A11E4EA2AFB447447A41B66872F4102F2467D6270D8B3DC8&h=A0DF6BD52F0BABB98FEF6DBC5A6E3DE854D42313FB32D53DF0C09136D2DB146A&directdownload=1&f=69665508&d=http://www.yac-tech.com/download/.../down.php?pt=sftc

http://en.softonic.com/sads/tracker.php?ev=c&co=IT&sid=8964bb47610230491e26fca93631774f&upv=a55f5726dab6fdd860828d84f719fb01&z=results&sk=0&abp=0&params=F39B2A32BFC101987B1458170C278E0313858C8F8C1052086E0A941149460CE76A106AC15BAC4D67AC234C1B8B1D350AB3FA6B6898D3AC1988D25B2B8D1C0234C2C0D85DE6D38A68C50E96BF2BB5FA28C8CFE9178D6B13500B7E242E78F01B8D5E0E08A124A2EFA310FCECD9016DCE38C506FE0CDCAA5225F33480FA9A46E99F2643840EF51974D1B8316D1001344A707794B843588C221E6076F1B3357803CFD545BE3EC69234EEC21AD771BEAC6612&h=0397F8BBE75128063A7324B3217CC689395497DF9B99D4C0B24E6E12787A537C&directdownload=1&f=69665508&d=http://www.yac-tech.com/download/.../down.php?pt=sftc

Latest 30 of 36 download URLs

Remove yet_another_cleaner_cdls_setup_15375.exe - Powered by Reason Core Security