yet_another_cleaner_gam.exe

YAC Security Protection

Elex do Brasil Participações Ltda

The application yet_another_cleaner_gam.exe by Elex do Brasil Participaçõesa has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. The file has been seen being downloaded from adsrvmedia.adk2.net and multiple other hosts.
Publisher:
Elex do Brasil Participações Ltda  (signed and verified)

Product:
YAC Security Protection

Description:
Setup

Version:
1.0.22.14169

MD5:
88de86b76a820c6ebaa4519c2fe040d2

SHA-1:
08450e36adb4e8dd3a81c5895f74000cf3a739bc

SHA-256:
f4db08022d394ab5a12c3c873d8b5ff72d3660849282614189897ef6b885c3b6

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 1:18:40 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Optional.Installer.X
14.8.7.17

File size:
840.9 KB (861,104 bytes)

Product version:
1.0.22.14169

Copyright:
Copyright (c) 2011-2014 Elex do Brasil Participações Ltda

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\yet_another_cleaner_gam.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/22/2014 7:00:00 PM

Valid to:
6/20/2015 6:59:59 PM

Subject:
CN=Elex do Brasil Participações Ltda, O=Elex do Brasil Participações Ltda, L=São Paulo, S=São Paulo, C=BR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5C6950D0A05A1CD63164D1E1EB1FFB8A

File PE Metadata
Compilation timestamp:
8/7/2014 4:58:33 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:r8xPNYhGEgy37iLliDAOesdSy8pA3UYesjxmOWcIwSlb8ZqPIyHTLo:r8xlb5y37kkDAOefyDj7FZrSVgqPVo

Entry address:
0x10993

Entry point:
E8, EB, 67, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 83, EC, 10, FF, 75, 0C, 8D, 4D, F0, E8, 73, FA, FF, FF, 8B, 4D, F0, 83, 79, 74, 01, 7E, 15, 8D, 45, F0, 50, 6A, 04, FF, 75, 08, E8, 00, 69, 00, 00, 83, C4, 0C, 8B, C8, EB, 10, 8B, 89, 90, 00, 00, 00, 8B, 45, 08, 0F, B7, 0C, 41, 83, E1, 04, 80, 7D, FC, 00, 74, 07, 8B, 45, F8, 83, 60, 70, FD, 8B, C1, C9, C3, 55, 8B, EC, 83, 3D, D8, 61, 43, 00, 00, 75, 11, 8B, 4D, 08, A1, 40, 3F, 43, 00, 0F, B7, 04, 48, 83, E0, 04, 5D, C3, 6A, 00, FF, 75, 08, E8, 89, FF, FF...
 
[+]

Entropy:
7.3061

Code size:
140.5 KB (143,872 bytes)

The file yet_another_cleaner_gam.exe has been seen being distributed by the following 50 URLs.

https://adsrvmedia.adk2.net/event/click/0/Mu9Wc3Jr8ng0rmQ8bF0-dBPRAKd3EjvGuwJOCUQg_UrWOQ7E9QM8n1wLd_haI_ChZkZNER824UGENrd9gSdgVTZTrjeAMakulh6-FIKuYw6HLzg5xJzO1W1aPJBk2pDW7psVy2iONa3pa4zT1YvnMLhpX0EuIHkdNg19AXvJsepBk4zXZytp8IYiw5W5JslARC3zp51t4bilTgzX5Nzzf5-30AM2QHZbUWU4NcW8N8H4-OHFVxrykLZRW44QmdRk1WeYYIci6Z-lZULNF5xL4O4PJj_P8Oe19TWPR6BlHISvk7ECx1n7BhEOrez5x-kf-7_LVaS4cbVa1EBfrUg1ZjUquOZcBjxYIfLHrhaQInPnP9CaqMBdhquyVVjOZ1NRdVs4zFwSAWELaiuiteaVADs9OUunptM2Gw/.../

http://ads.adsrvmedia.com/event/click/0/gkUL2upCIe5s1a65vRB-W_qD0H_GYN73OAzYMfYzuEw79U3oha630EvUvQNd1tRrI519t2sO1TM03YbDcNAm3x-8uXmuUjQ0uYTm4ixer0IQDN5FL53WocmWoC107YAgRh98L4zYrP0K7zwzoPCEHozinvBucg4PMXxSrlmetP0tzIea9Ynom6yEdrEuyedfAnVP3OlbVKnkpRLzLyP0OUZo5Qz4nzJEOOCZpLXHc0RFjtmq33D0uMNa6UZ0keLxqwxXj_mfyg5tW0QFrxV16wM3q_0m2tn4oQsAyv-bxhEgItzH1aX29SgS120cdFjO-3qERLuy2wz6ypg0XL5vk29ja5v3YDbiOv1SiKW69NiPjO6JZCKoI1BH1UQdpmpqaWJ09KCXYQY6ErUczmVE5SdftrcabNbRz3nTNcWNLc0k-cfaTnrxeA/.../

http://adm.soft365.com/ads/adsavess?sid=yac&ptid=avai&subid=6621859374&lplink=http://www.yac.mx/download/.../down.php?pt=avai

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=brog&subid=Hx3UO2df89HSRRA980E7O4_2uudmiUsIlETxzTG7kJ-KC4SDeftiYPFyhicYr17c2sY8K9ZYyC6tUh4JZrgJQzPv7lvSI90baJV5J7yMmCZdpileerhgiRyeoNZfeJdE0S4rdlkQE5Nu7Vy-TXHdZic8Au29UGqRDu49HkcC_GIIL-Tlpv3DwuabQ92Kczub03dT5M4ynOw0WYF50Zm_vAq8U1BThyDf0bg9MUoRqX3cfgutsV2035hVE6y6TQqBrYUYFb_VTMNnFkDlxh09Gl3lU5AdQO5VE1OEiPHWEVzW_oFUEj-9TwLPyP062ZxevcUdaoPJ8XT6Fg4FYzUExvce77MLRBUmrtR_G3ikgj5w1tWhj0RSydrFEWq5y6OLn4CDDfO4MtzI0REWGl2799TCw7XvBz8mGm6pNpnRmYEfetQGEbDl7OFOjQSxR45yL2KGv8zGmDnuTvVlpDc&lplink=http://www.yac.mx/download/.../down.php?pt=brog

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=brog&subid=BSnNVurDirzAyfpS49XACPXbTZTTwKzOTfczzagjStAbtd0jkT_XoMQJ0VfMJZ3tUOslps6wfMVA_b6HWlhnTQDdowcu2IUPOpGtWFRt5f19tTQJA0w_tUdVMD779Qv4e949nOAullISfIYhAMU9kR74ESLvUfbOxc2rzPifKiasm85ysr5QlkTd2Ej-F36zUyMDDXon7Hc5e--BOmWcTkCW-tMOqPluEd77jnYy1VYSGEmTgkhY_Y6kD59F0EwTRd0lQ8JZYZLUI-5blPp1C38VZSWH9UTdcrcVlVIMQDhK8JpAjdjOTqrFlgukQm-vnBacgvXZFlXzLMDJyDDipoCEt0c-RtPcHBabl307vg3TckOiAUUPip2AHVWmQp0Oihtn9elRdJNXkE3xZXZHY0dUO7CXd_2NpQEq&lplink=http://www.yac.mx/download/.../down.php?pt=brog

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=brog&subid=y5h96agcEbaAJmggagljP0164bXR6Gfm5ESNJykH2RJ4E8Fmh3Ii-mFI5dw-mIrTukmNDXnlQ9XeIfqtqjc9sSQZUv9UzU2c0LTlJyr_googQ9GNAWOwfrpR-qI1kgxVXrIqH2Efrd8yLePSRaGuUh19PumAginGzozECa5-VL2wHNB2KFFEK8MowTKWOz0xssM_z6ZAyfDhuehRXt0eqderU_TwLhHuFBixBDRdZLPHmoz_c2mKgfTXTTfOd65qBKr-Dx_9Ntmu06wTdBBqP00d0baptkfqZS5k2CQJQtCAbPwDUj1Fb8ekF4KVjOt3Tb7jG6Wn40QixEx0FHKuUJADe6iXNssy353iagUThHns9JHUgoQe1CNShuL3AWksNtuCunxDDduuZg-iYx0j4piYGdhfxMllnvUKTNmSrRv-FPr_ayDXRuqTOb9ra_wBgS_2w6BKZXWCNA&lplink=http://www.yac.mx/download/.../down.php?pt=brog

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=brog&subid=a-XCZ3PKpWSd248j8YZU4hqg0Dq8NEaUlElO9B9TeSYL8RVVMDx_WUndQSuS5cWNny6HrRKRT_utnUlxtc7wI5Cl3F673VK6QHYNrHWSpZ27OOAjSYokeJojtiL7HdYmIQ17ChPhZ4__VJqvlc5GclM_v8v50uTr1EgWSJMsIQfs9cYs4HWihSRPF-vZVf00zwn10e-cJsklwyY88Swy0oDBs90xhbMdDL8n9GnA1SOYFQ-vFOVc7vtrzrNy-nRP7fCP0JVP9hGsn0ObgvFC-yAq1NKS6I50L4Q6l73fEsj-vE4KrRmQaa22dP7Q99n-GBCH2XRdV11yzZdRKzmt0XT7XqJ4-egtJYy3DvSEmCqMJfeVs5lFFqBcPpOkNq2USR2lBdX3xwMwyN4IFf0-hONjj2xGkDC7VIMsKxzBYJqF67gw1QJRc9QynT8oYM46ASzhF5tKdrxWvoeJIS4BEFMK&lplink=http://www.yac.mx/download/.../down.php?pt=brog

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=brog&subid=Vo4lIlr2Cos5KhBmUIPq3i2OJG67OvSdWYuX8cTWifVjkpIHt0f0iqQpav6IruovZBKcqHT1vZjxLahJXK2ttBBCVnHwIwzGhv_Sr2uzCs1BtPjE5TCApOBxRN74hDduh4RU0yQnTyz2yXby4VxI59ObxM2elLXwyP9J7BnY5oONcz25GbWhBnZ-xBAUZXu2vYRj9lBEmz3u_D0O5nSH4GQqSv1vIqM5OWEGcZNcA_Mg_iW4a5Ew5HbYVU5qLLEhHozp4MQSN8znGnqIhQsFbfCwSlWpd43gka2Vc_n-W9fY8KJN1J9Z_iaj20Nzx2xCU34eKnMBFzWKpFtMdhvLK826FRkb4W6JB3ysRPISjws8edWNDGSkiD7fsyqHa_e-QKqTyrQjLQ2BTuy8LnAPZGKzoC6HONhyggAlX2gK9SBfH1jQJERDmPqxR6jMxKZuWhvsKcbJB9f3axeWJeOc4nUmY8nZpA&lplink=http://www.yac.mx/download/.../down.php?pt=brog

http://www.yac.mx/download/.../down.php?pt=exo

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=brog&subid=Xs49Lhw-uN8qfAbjv5yLYbu8_o_TldwO62TS5RFpbn7XnLOXGsPiVeOaKj6ly_ocTaGBJkaJc4g0MxtXC6nWDL3H4dd2I6JRH6MHI02ZcPVIAyjlg5ymp7eCWfSOiW0pjpKv0-PpZzkI7_OEH52oCUDlXCgvSg3obYekGgC-0zoawRczUra0PkbzgUe8JHT9PpiDxxVujQ6fABFXOdR7v34BUKBBF7RvqykfrOqFZryy8ZfmRlfin-lXvVkw7cGXf6GXLVnb2WblHppkpuDzDZwKSI-45VDBz3dWEAiw9rvoJGHu-jZpx2EjqdfK38T9ZnkHsgU2c8S5vThYsDIMT2ZI9CYqlhiEs6kJBCBNb4ysQ3RiBcM-Q4B8FsOhNV5d75gO_nwbxDOnwDZDSwP2K5H9oRyf3nnxRRZT6dagDm_YB_Szz2YnkrXTFFmU0LcZlLrF_QTw86i-M2VmxQNsY4bomtKyja6nCXDwSIaeHQ&lplink=http://www.yac.mx/download/.../down.php?pt=brog

http://ads.adsrvmedia.com/event/click/0/IygRutnnoLL1sUpmAudP1kYgExvAKl7g3CuL9IqWp0GguEVUFMw1-h0vBcO_5u3h3S76uKcdsSDW2v8U3sUxVi-_9qOA638acJBZoYhl3lBqbF0kTuWcknGi4AAwi-HIjuuNEnFbH3_hPxviEkwcEG9Vm--PjHd6gFviIX3ehfsdrR6orlglryn5OLN_cgYH0W9F1d9XMyJmZGnq92CagZTW-5DpwIpSz-YMtN2hodrZ2lgX3WD5x7Nflo96sU-ZCcPF9CHMPtICx3KZ9LzqpZn96pClvm8FKSo3lpkTIyw_t-cOXzsTgV63XhV3IuTvFKIH0uv-mA3-QiYNIA3LJL8yFokUIb0eNzZGYyIuGL6Ni7FVL-7cBFvx2xgwtTHGgzqOgFQRt7RRrZcecHhJfurxk28Yt-sbJjyn7-zI-JiOzqVD2uY5sZRJkw/.../

https://adsrvmedia.adk2.net/event/click/0/tJesILfWttqcTARLXQTVddlN4EXYGgz_KJaO341EtnaSoYuaHGFE3lNdZw49qVpx4a7jAohK9IK4dGY6fkuEndUEjaNNqYNNqICRmJsBR81IuG4K3BN33MtuS1Pkl6VLXrrqXYk2Di728h8jFw3nSLTl0J5F1cKw3Rfi2XCtl2tLZJp23PC4XrGCoV37x0ZhTG7JO2fyW3AEJ_pzIYw7ADyEswul3kwKqCrhbHRF3XyKU4PHZ_fzt_1nGwv2fQQmyr_161HTf-VONDK6a41EUTW7TH7rlHj3Y2BH1Jz9MQOoUsL55dalPTwwOWpjJJwFQA37FeLT0yu2slTTzwhdOfboQgf5jMoGTfqfPduZ-tqQcqYcAQPOwKY6quZsceIgjK6IGSdapkhbkhK3b5LqnzO6FIF_RPI/.../

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=brog&subid=SNBVOiDZRqJoDp-0fdAt-5Iq1lHo59XrBsAEB5gmxjzl_9lBv1a-uZhtetv2RnjO0uE3Dy45BGJFSaRmTVgt-uMuvihD2a5IX8GfQLu9HttE3fdDjUMEvQViXzX-JnvOYlJR7bIT2KK6fKJ-N56IOBOQfZkroeLqLdBctZvFQZP7WIUknURq52KbcKjRzmCiKYyEzZBcrApmc0cwu8GiIoiAgNJJsy4mIU2PuLZqL8biTsFyGBtLjNjJV14bRGz2Ev1z5LdvKb00uQ2W2Jwp5X4lbs6m1V1hJ8tg4ycJS6OWH9GrgbZ0JNdYY2MUq35yovw7IJcdeRU_hvUyrOHOWpALKi1jOA9d2qi8gEUYnVYch12ButkvoLkJEB4BkkZPmt2zWZ3R1CmKDFshv9Xt6XX3dpWmQdDPjfe6Y6K0wlYOtQkj4e7vBfuCmHS29jq5PyARr-GWzu805V2aMNOBCQ&lplink=http://www.yac.mx/download/.../down.php?pt=brog

https://adsrvmedia.adk2.net/event/click/0/P8OfDWQ5BGr8IUbpIIp6p5Sgs5GOCNY-2HFw3zQMGidGBJSQfawELH4S1DkD3KL3EiLZ8w-NRChDofRqyM6najx26dct4nbDrxnHiA25huBAhnzoIOmLjSw53FRHbKjxVn9Bmxf9M-3RV9XAqOEz93fe5NTrZOFNOTrOhF-dgKYzMWrOCLmXkYTp4ufxoW5POatKu7OKibNbcacGzIDhViizECnv5TpqIEYxunz21dEFcFprdMUDIoIBSxByQ6-la6BM8FqBQtouDJ5BxDZilLtGPdTX88FR-aH4jd_LsGMXS31VkOO_UIf4dwTtuLXShRSx05WfxgvoRMj4XTCaNP_l15glE4n1z2KvaNw0TGU1AXWY16ywAYS5y5djzw2_zid3LzbZ0LfIpc3f8xa6rvfcMgwPnfiR_xeq2SY/.../

http://ads.adk2.com/event/click/0/z83Vo_qCKLU-8m9Pcts1thjQ3CYuzJaelpwivecIDl2N6bc8zi373s0DQJlADy_DQsvj-KgQlRPoWaR3UhhZxO8mKyw3C7GnxWhx9_lC2XoWianoXiFShx4G0ZeooYKm70B0z4bSRmIixJbjH5EbxSyCseWT8Y2qbi1d50rXVD8RScMUbNxTVgJZwswkIs5JPT1ZZkb8zw22JLmuSoSZuS9Txo5WfTXA7HMFDyU6onAfIgwoRCuVAdd1fSyoY4Y0yhWaH6ow0FMs7UmUSQmlyZsmKAmBdNsa6P2T5CIjhA9kcdQtAoI9HqrHGRMChUn6MqpQHNhVGOJdjE_SjTgKb4XGNdf7HTpWCEH-GCZ00BSwC5p-92bL_HDhsAIV-cNK0TVpd8tqqbVzJHF_ZqTkXCkurJQaXuWjRvLPSiFbTSG_1v0/.../

http://adm.soft365.com/ads/adsavess?sid=yac&ptid=avai&subid=6621744293&lplink=http://www.yac.mx/download/.../down.php?pt=avai

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=rkl&subid=1032&lplink=http://www.yac.mx/download/.../down.php?pt=rkl&offer_id=2149&aff_id=1032

http://ads.adsrvmedia.com/event/click/0/Ft4E_MKOF9hrTxqkcuFUgQACGaJcu_RZuY8fFRsj57kkMwRVtEjDqgtfobd_tU_iHhzf8OZZg7PdI4Rprpe18PGwv99Fvs0iRzvpmzbPw-GpxO5Tfxt47PUR1IX-292NHPZ6kXSTrC-gN8ZBWJbYog8fp1EDhJbNePy7JfxQEC8V68g00luzJZtDgP1GV_90oaayVptQnzSwJR3ekKi1qC0zuSHhjPzZG9erBO0_5UtWN5FotQjEiBMazD05ApcNp87g6P_Mt5gtZWX56SKjFZ6Sszpe6ybF-bi1kYMtqsHDFEkxl5Ii4jkI7FD__AENOn2kDndvnuapyTBfwHf60_poSbBD4eiP5YRVedmuRDR858jVkLANAmRCUU2mi1zpaMk0dc7y3yeUIBQHlNkbpk_W4SaZ4ZbiYpBV4ovLw9SJp4Z5hSpXUQ/.../

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=brog&subid=UDqM659sWxm9tkDgiLX09jANKmaSBh7SyGAGiThqmVyuHVCzK68SSkG8nPPZu2bk4GhnuRGsYrGuffr0ieSqJsbLD2eK-HgIZ7Bcla4es01AjrY7y3SzrYsvr5Cz_v85wXI5jZHwAcZ8jbloN0JFOssmzixFUgd4Cg8STT1GbOlTnlU8SPwQaXBUZstqmByuPFoVOIaZrjG8DY6jAjV543EorjJPL0jucVQzNTVb-k67Q7sYuOXnKW3ag4kRwafJzT4sXbf7hottqC_iy7V_BguKbSL-qCfJvpjGNxFo5DDxn3Y2m5v60DNcWF3QHSgihW9gcDsdzGVKRWAhfjsLWI8tKIp1NxIkrPWZJktTh_ZgwqHQzARz8XPdMwezgXu-xxe49GEASBgtnnJoD2KX5BK23m1YEIIC_gN7iB-LGIiTJ6ivQpwh3j7WFMBcHv9boLzS5VcimHhbT4UhDw&lplink=http://www.yac.mx/download/.../down.php?pt=brog

http://ads.adsrvmedia.com/event/click/0/A7ur43V4MCwosXrORtKyRPmQPMeZIBRFOOdtWFlJLbTuTW6arSlfwsM4qYRzwxmXlhjsQijdngqnJ1x3bkUPMyl44vsebvjuvi2pCJsw0fvJAjr7lnVtHXmKy8YFrhYiH-KcM2PQNfsj290-9FWmo1TRtAs3XOQs-XimKnClXCwQlNPjfoqDM4mPfmrrqHnuRBVOjuJdC3tNNRxjSRDmc1sfpQWHKq5j5ePt2fmMyNTE1EBcw786lta3hXE_DcVCScm4NmM0zc7PPYZBAQJRRH2WrZVpVnp8e0R2XmVNAAykJqdx3kWs4UewfVjc_mJ_ZJTpbCxs4WFeA_UEpkHVpTaoMjmI5iFw7tyoSCA6ZwEw3UZ0fvcpTzzHYem8EBAYzApJQP8yMxCitekF4wpHM_w6pO4GPhu4YYhGu7NuMqusSA/.../

http://www.yac.mx/download/.../down.php?pt=spt

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=brog&subid=PSlX9LObcoX_V54DLzgZqX8CuXE9UGUFIFHCscB4OGdDxFRpD5uMWTwae1MNkidTvwJRMdMVDflyQ3geB5aEe6uSbD3J6nCWGL_0kW6ctsyvB_0vSEX4bZmzbNQlBZF-Qda6trpoZm9y0dz7ms5H_y4NAuR8kdbh8388uL2kWzHIXhjbQj23vBlWOJZbfILDjeZs5OAsv2tmQxJlbmwIyEfjEbJWvgGn54CB5HLuUgJnwQKlGbDO70ovKgv-MGABn0RaOeLJVMqZrWFDp_0KcVJKDWxG7aPY_jYLpYH7m5vgu39lCSpoX777ahj1TxuXyExgbxP8KIqhSzqXUoBdrATL9dm2atRuaz-xc3bU1_UNS3uQG3vdhtQmRVOC156WQJzXT_97rNFUI3MD-PACl08Ztw0lFBRm-G5CQt7U4OaOr3ITRDS8tkWE3sHYoa-ueTA&lplink=http://www.yac.mx/download/.../down.php?pt=brog

Latest 30 of 107 download URLs

Remove yet_another_cleaner_gam.exe - Powered by Reason Core Security