File Name | PC_Cleaner_setup.exe |
File Type |
PE32 executable (GUI) Intel 80386, for MS Windows
|
Scanner Version | 1.0.213.174 |
Database Version | 2025-04-13 06:00:34 UTC |
Malware family: Avanquest
Hash Type | Value | Action |
---|---|---|
MD5 |
db4cb78d65d71424217ad2a227b30225
|
|
SHA1 |
e606ca8ce3f597d9b494a4a9fc93b202e705036c
|
|
SHA256 |
d54b331aeefe3b9aef34f90d785c81c01890eb1d176363679f277566cf67b75c
|
|
SHA512 |
55a438695ab5ead46ade50977d86e51a4bf8baac379fabe6c2f9e4bde18dd6513de9de1d3d633cf41a6322c4f3aaaad96bbec734097b3ec4715f7583f8390c8a
|
|
ImpHash |
8b7e1f5e80876a5b21126049c947d1b2
|
Icon |
Hash: baab1fcdc08bd61ba8700a590723ed7f
Fuzzy: 4efbd9f2d747d9026f95224e465e151a dHash: 50509254cccc80aa |
Image Base | 0x00400000 |
Entry Point | 0x00643d3d |
Compilation Time | 2025-02-25 14:27:38 |
Checksum | 0x0085dda1 (Actual: 0x0085dda1) |
OS Version | 6.0 |
PEiD Signatures |
PE32 executable (GUI) Intel 80386, for MS Windows
|
PDB Path | F:\TemporaryBuilds\azure-adaware-pool-build-de-1\11\s\_build\bin\x86\Release\installer.pdb |
Digital Signature | OK |
Imports | 17 libraries |
Exports | 0 functions |
Resources | 13 Resources |
Sections | 5 Sections |
CompanyName | Avanquest |
FileDescription | PC Cleaner Installer |
FileVersion | 9,9,39351,5169 |
LegalCopyright | © Avanquest |
InternalName | PC Cleaner Installer |
OriginalFilename | PC Cleaner Installer.exe |
ProductName | PC Cleaner |
ProductVersion | 9,9,39351,5169 |
Translation | 0x0809 0x04b0 |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
2,791,094 bytes | 2,791,424 bytes | 6.59 (Compressed) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
94B42241EC12B5768A09B4A8CACA1E93 |
.rdata |
0x002ab000 |
1,780,342 bytes | 1,780,736 bytes | 6.72 (Compressed) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
17E36D9821890A158133814175645445 |
.data |
0x0045e000 |
167,044 bytes | 137,216 bytes | 5.16 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
EE004B24DE66452DE2C7047FB1FC7281 |
.rsrc |
0x00487000 |
3,895,952 bytes | 3,896,320 bytes | 7.98 (Packed/Encrypted) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
82CF25516F970DD2502472271928B3D7 |
.reloc |
0x0083f000 |
140,252 bytes | 140,288 bytes | 6.59 (Compressed) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
A6B0BA3FE5B8909629B20E6ADB23CB72 |
1 section(s) with high entropy (≥7.5) detected - possible packing/encryption
3 section(s) with elevated entropy (≥6.5) - possible compression
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
UPDATE_SERVER | 1 | 4 bytes | |
RT_ICON | 6 | 72,464 bytes | |
RT_RCDATA | 3 | 3,819,987 bytes | |
RT_GROUP_ICON | 1 | 90 bytes | |
RT_VERSION | 1 | 772 bytes | |
RT_MANIFEST | 1 | 1,740 bytes |
This file is not digitally signed.
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
OK
Gridinsoft has the capability to identify and eliminate PUP.Win32.Avanquest.dd!c without requiring further user intervention.
Download Anti-MalwareFollow these steps to completely remove the threat from your system