yet_another_cleaner_sk_0.exe

Setup

Elex do Brasil Participações Ltda

The application yet_another_cleaner_sk_0.exe by Elex do Brasil Participaçõesa has been detected as a potentially unwanted program by 3 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The file has been seen being downloaded from fr.softonic.com and multiple other hosts.
Publisher:
Elex do Brasil Participações Ltda  (signed and verified)

Product:
Setup

Version:
1.0.178.26080

MD5:
5d4f94116e4f0da975683c3e511634a3

SHA-1:
100b1190d720b3a6d20d687bab64cb78e9673bfc

SHA-256:
9168593b921c14652bcf28711dfa5e2f644f64f1b1e7d7700173928b251cb838

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 2:12:00 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.HfsAdware
1.3.0.6379

Malwarebytes
PUP.Optional.ELEX
v2015.05.27.07

Reason Heuristics
Win32.Generic.Installer.ELEX.Meta
15.5.27.6

File size:
844.4 KB (864,648 bytes)

Product version:
1.0.178.26080

Copyright:
Copyright (c) 2011-2015 Elex do Brasil Participações Ltda

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\yet_another_cleaner_sk_0.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/13/2015 7:00:00 AM

Valid to:
7/13/2017 6:59:59 AM

Subject:
CN=Elex do Brasil Participações Ltda, O=Elex do Brasil Participações Ltda, L=Sao Paulo, S=Consolacao, C=BR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0671EE526ACB6F9BE201F5A8E203C41C

File PE Metadata
Compilation timestamp:
5/27/2015 11:37:04 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:C/cA0LPdknqybzoBx9122Ji8UMFX/tarKtJq2xC6MrBuRVK/ImsrPgM:C0/ZybUjHBIrKTCjsHmyoM

Entry address:
0x9F58

Entry point:
E8, 41, 40, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, FF, 15, 88, 70, 41, 00, 6A, 01, A3, AC, FE, 41, 00, E8, 2C, 45, 00, 00, FF, 75, 08, E8, C1, 44, 00, 00, 83, 3D, AC, FE, 41, 00, 00, 59, 59, 75, 08, 6A, 01, E8, 12, 45, 00, 00, 59, 68, 09, 04, 00, C0, E8, 8F, 44, 00, 00, 59, 5D, C3, 55, 8B, EC, 81, EC, 24, 03, 00, 00, 6A, 17, E8, 11, 70, 00, 00, 85, C0, 74, 05, 6A, 02, 59, CD, 29, A3, 90, FC, 41, 00, 89, 0D, 8C, FC, 41, 00, 89, 15, 88, FC, 41, 00, 89, 1D, 84, FC, 41, 00, 89, 35, 80, FC, 41, 00, 89, 3D, 7C...
 
[+]

Code size:
86.5 KB (88,576 bytes)

The file yet_another_cleaner_sk_0.exe has been seen being distributed by the following 50 URLs.

http://fr.softonic.com/sads/tracker.php?ev=c&co=CA&sid=6ae0e7a3dfcdb7da961207468fe227ea&upv=d8443d9a0244fe6b894f87e1f3ca8b9b&z=results&sk=0&abt=&eid=&params=F24F8F4D368AFA5D32C8A90D9EFD1CBA6CC51E5F2F1CC0781D87EC9BB0C214C64EA7E5E4B39867A9F0179C9568FAA3BFE106903F32D362BBB81EEC48886EC11A9756AD8DAAD34C48B807E88BF264384AD969FD6561E5E41310D159EA680D908D5CBA798CDFB929CE6279B4A12A01A62780FF232E6E4A2E5AB8DDAEA645E6B42F1F52109919BCF2D9697B54D0E587F37F79A2A74C1160E692338215EC626908C5378421166C09638CA1614D2CAC63289F&h=DE7A949ADA43262437ED5131C0BC2CF0BAD4F84926CD1911B7FCE106750C126F&directdownload=1&f=69665508&d=http://www.yac-tech.com/download/.../down.php?pt=sftc

http://dl.yac-tech.com/download/.../yet_another_cleaner_rmv.exe

http://www.yac.mx/.../7449892

http://www.softonic.it/sads/tracker.php?ev=c&co=IT&sid=c1d29d902dab8b0ecd1ed3a708987c4e&upv=13cb21322d4aac02c2e0a203a59f311e&z=results&sk=0&abt=&eid=&params=F24F8F4D368AFA5D32C8A90D9EFD1CBADD0CB244B8D47EE8EF2B6FDF0EA0CE23C8594D788EE802BF1345B03D32F8EBEF6DD2F2D3DE487748BEC7794C220647AB37A7863D356E29E653A2B382789C786BDCFF8EDE066D9A1347E4D10A59BF6AE7A2C09A2D29D944FDAA3552460CB34BB5730D0CA3F2444E6B270CC9294950152E912BE1831498139F96BB25EAD75AA2F30390E1DC342454813D958F9D07584086&h=456C6B5FFF1A1460A98BFB08D088BC50E99C65697914022853D2B92601C315D9&directdownload=1&f=69665508&d=http://www.yac-tech.com/download/.../down.php?pt=sftc

http://www.yac.mx/.../7792602

http://www.yac.mx/.../186949

http://www.yac.mx/.../786492

http://yknowlarge.com/.../7695302

http://www.yac.mx/.../4267349

http://www.yac.mx/.../6364504

Latest 30 of 55 download URLs

Remove yet_another_cleaner_sk_0.exe - Powered by Reason Core Security