× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 59306a394c07f971da68300442b862bf8a4dd4dfccac8dda76d5fa269bca2c34
File name: amdcleanuputility.exe
Detection ratio: 0 / 67
Analysis date: 2018-11-21 04:14:31 UTC ( 2 months ago ) View latest
Antivirus Result Update
Ad-Aware 20181121
AegisLab 20181121
AhnLab-V3 20181121
Alibaba 20180921
ALYac 20181121
Antiy-AVL 20181121
Arcabit 20181121
Avast 20181121
Avast-Mobile 20181120
AVG 20181121
Avira (no cloud) 20181121
Babable 20180918
Baidu 20181120
BitDefender 20181121
Bkav 20181120
CAT-QuickHeal 20181120
ClamAV 20181120
CMC 20181120
CrowdStrike Falcon (ML) 20181022
Cybereason 20180225
Cylance 20181121
Cyren 20181121
DrWeb 20181121
eGambit 20181121
Emsisoft 20181121
Endgame 20181108
ESET-NOD32 20181121
F-Prot 20181121
F-Secure 20181121
Fortinet 20181121
GData 20181121
Ikarus 20181120
Sophos ML 20181108
Jiangmin 20181121
K7AntiVirus 20181120
K7GW 20181120
Kaspersky 20181121
Kingsoft 20181121
Malwarebytes 20181121
MAX 20181121
McAfee 20181121
McAfee-GW-Edition 20181121
Microsoft 20181121
eScan 20181121
NANO-Antivirus 20181121
Palo Alto Networks (Known Signatures) 20181121
Panda 20181120
Qihoo-360 20181121
Rising 20181121
SentinelOne (Static ML) 20181011
Sophos AV 20181121
SUPERAntiSpyware 20181121
Symantec 20181120
Symantec Mobile Insight 20181108
TACHYON 20181121
Tencent 20181121
TheHacker 20181118
TotalDefense 20181118
TrendMicro 20181121
TrendMicro-HouseCall 20181121
Trustlook 20181121
VBA32 20181120
ViRobot 20181120
Webroot 20181121
Yandex 20181119
Zillya 20181119
ZoneAlarm by Check Point 20181121
Zoner 20181121
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
Authenticode signature block and FileVersionInfo properties
Copyright
Copyright (C) 2015

Product AMDCleanup Utility
Original name AMDCleanupUtil.exe
Internal name AMDCleanup
File version 1, 5, 7, 0
Description AMDCleanup Utility
Signature verification Signed file, verified signature
Signing date 11:09 AM 11/3/2016
Signers
[+] Advanced Micro Devices, Inc.
Status Valid
Issuer VeriSign Class 3 Code Signing 2010 CA
Valid from 1:00 AM 6/16/2016
Valid to 12:59 AM 7/17/2019
Valid usage Code Signing
Algorithm sha1RSA
Thumbprint 9A3DC14FFF86A5DB502718FBB23E1FED80446C71
Serial number 72 DC D3 5B 1D BB F2 8F 0F 98 48 EC 76 6A 1B DF
[+] VeriSign Class 3 Code Signing 2010 CA
Status Valid
Issuer VeriSign Class 3 Public Primary Certification Authority - G5
Valid from 1:00 AM 2/8/2010
Valid to 12:59 AM 2/8/2020
Valid usage Client Auth, Code Signing
Algorithm sha1RSA
Thumbprint 495847A93187CFB8C71F840CB7B41497AD95C64F
Serial number 52 00 E5 AA 25 56 FC 1A 86 ED 96 C9 D4 4B 33 C7
[+] VeriSign
Status Valid
Issuer VeriSign Class 3 Public Primary Certification Authority - G5
Valid from 1:00 AM 11/8/2006
Valid to 12:59 AM 7/17/2036
Valid usage Server Auth, Client Auth, Email Protection, Code Signing
Algorithm sha1RSA
Thumbprint 4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5
Serial number 18 DA D1 9E 26 7D E8 BB 4A 21 58 CD CC 6B 3B 4A
Counter signers
[+] Symantec Time Stamping Services Signer - G4
Status Valid
Issuer Symantec Time Stamping Services CA - G2
Valid from 1:00 AM 10/18/2012
Valid to 12:59 AM 12/30/2020
Valid usage Timestamp Signing
Algorithm sha1RSA
Thumbrint 65439929B67973EB192D6FF243E6767ADF0834E4
Serial number 0E CF F4 38 C8 FE BF 35 6E 04 D8 6A 98 1B 1A 50
[+] Symantec Time Stamping Services CA - G2
Status Valid
Issuer Thawte Timestamping CA
Valid from 1:00 AM 12/21/2012
Valid to 12:59 AM 12/31/2020
Valid usage Timestamp Signing
Algorithm sha1RSA
Thumbrint 6C07453FFDDA08B83707C09B82FB3D15F35336B1
Serial number 7E 93 EB FB 7C C6 4E 59 EA 4B 9A 77 D4 06 FC 3B
[+] Thawte Timestamping CA
Status Valid
Issuer Thawte Timestamping CA
Valid from 1:00 AM 1/1/1997
Valid to 12:59 AM 1/1/2021
Valid usage Timestamp Signing
Algorithm md5RSA
Thumbrint BE36A4562FB2EE05DBB3D32323ADF445084ED656
Serial number 00
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2016-11-03 10:08:06
Entry Point 0x0000304D
Number of sections 4
PE sections
Overlays
MD5 43624743e878e5083cb64d94833d654d
File type data
Offset 6885376
Size 16264
Entropy 7.40
PE imports
AdjustTokenPrivileges
LookupPrivilegeValueW
OpenProcessToken
GetStdHandle
GetConsoleOutputCP
WaitForSingleObject
HeapDestroy
FreeEnvironmentStringsA
DeleteCriticalSection
GetCurrentProcess
GetConsoleMode
GetLocaleInfoA
FreeEnvironmentStringsW
SetStdHandle
WideCharToMultiByte
GetStringTypeA
WriteFile
GetSystemTimeAsFileTime
HeapReAlloc
GetStringTypeW
InitializeCriticalSection
LoadResource
InterlockedDecrement
SetLastError
GetModuleFileNameW
IsDebuggerPresent
HeapAlloc
FlushFileBuffers
GetModuleFileNameA
UnhandledExceptionFilter
TlsGetValue
MultiByteToWideChar
SetFilePointer
SetUnhandledExceptionFilter
TerminateProcess
WriteConsoleA
SetEndOfFile
GetCurrentThreadId
InterlockedIncrement
WriteConsoleW
HeapFree
EnterCriticalSection
SetHandleCount
GetVersionExW
GetOEMCP
QueryPerformanceCounter
GetTickCount
TlsAlloc
GetVersionExA
LoadLibraryA
RtlUnwind
GetStartupInfoA
GetStartupInfoW
GetProcAddress
GetProcessHeap
CreateFileMappingW
CreateFileW
GetFileType
TlsSetValue
CreateFileA
ExitProcess
LeaveCriticalSection
GetLastError
LCMapStringW
HeapCreate
GetSystemInfo
GetConsoleCP
FindResourceW
LCMapStringA
GetEnvironmentStringsW
CreateProcessW
SizeofResource
GetCurrentDirectoryW
GetCurrentProcessId
LockResource
GetCommandLineW
GetCPInfo
HeapSize
GetCommandLineA
RaiseException
MapViewOfFile
TlsFree
GetModuleHandleA
ReadFile
CloseHandle
GetACP
GetModuleHandleW
GetEnvironmentStrings
UnmapViewOfFile
GetTempPathW
VirtualFree
Sleep
VirtualAlloc
CreateWindowExW
MessageBoxW
EndPaint
EndDialog
BeginPaint
GetMessageW
TranslateMessage
DialogBoxParamW
LoadStringW
LoadCursorW
LoadIconW
DefWindowProcW
LoadAcceleratorsW
RegisterClassExW
PostQuitMessage
TranslateAcceleratorW
DispatchMessageW
DestroyWindow
Number of PE resources by type
BINARIES 10
RT_ICON 6
RT_GROUP_ICON 2
RT_DIALOG 1
RT_MANIFEST 1
RT_STRING 1
RT_MENU 1
RT_ACCELERATOR 1
RT_VERSION 1
Number of PE resources by language
ENGLISH US 18
ENGLISH ARABIC QATAR 6
PE resources
Debug information
ExifTool file metadata
UninitializedDataSize
0

LinkerVersion
8.0

ImageVersion
0.0

FileSubtype
0

FileVersionNumber
1.5.7.0

LanguageCode
English (U.S.)

FileFlagsMask
0x0017

FileDescription
AMDCleanup Utility

ImageFileCharacteristics
No relocs, Executable, 32-bit

CharacterSet
Unicode

InitializedDataSize
6828032

EntryPoint
0x304d

OriginalFileName
AMDCleanupUtil.exe

MIMEType
application/octet-stream

LegalCopyright
Copyright (C) 2015

FileVersion
1, 5, 7, 0

TimeStamp
2016:11:03 11:08:06+01:00

FileType
Win32 EXE

PEType
PE32

InternalName
AMDCleanup

ProductVersion
1, 5, 7, 0

SubsystemVersion
4.0

OSVersion
4.0

FileOS
Win32

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

CompanyName
Advanced Micro Devices

CodeSize
53248

ProductName
AMDCleanup Utility

ProductVersionNumber
1.5.7.0

FileTypeExtension
exe

ObjectFileType
Executable application

File identification
MD5 4b12ccf3c2873702a0ea00313e12d44d
SHA1 21e4f3a24f909e5d4f921becf574d7538202e25a
SHA256 59306a394c07f971da68300442b862bf8a4dd4dfccac8dda76d5fa269bca2c34
ssdeep
98304:Ocdn5YpeVWJ8u3n5YpeVWJvkjKlmjKbxDWRB8Ad8Y:hJ5YZJr5YZJvkjKlmjKbCBFdx

authentihash 175c33a377b3743f598261346fa98ffbf268017f27c94fa5c2c91f6753843889
imphash 782e1bb175f2573b868ef39ca948a2e4
File size 6.6 MB ( 6901640 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID Win32 EXE PECompact compressed (generic) (31.8%)
Win32 Executable MS Visual C++ (generic) (23.8%)
Win64 Executable (generic) (21.1%)
Windows screen saver (10.0%)
Win32 Dynamic Link Library (generic) (5.0%)
Tags
peexe signed overlay

VirusTotal metadata
First submission 2016-12-08 16:39:44 UTC ( 2 years, 1 month ago )
Last submission 2019-01-10 12:01:41 UTC ( 1 week, 3 days ago )
File names AMD-Clean-Uninstall-Utility.exe
vsr51lqm.0et
AMDCleanup
vsg60a3q.gq8
amdcleanuputility_v1570.exe
59306a394c07f971_amddelete.exe
AMDCleanupUtility.exe
amdcleanuputility-1.5.7.0.exe
amdcleanuputility.exe
amdcleanuputility.exe
vso80ff2.049
AMDCleanupUtility.exe
vsdl03p0.r7d
amdcleanuputility (1).exe
vsjg07ja.01p
amdcleanuputility.exe
amdcleanuputility.exe
amdcleanuputility(1).exe
amdcleanuputility_1.5.7.exe
vs400vbq.019
amdcleanuputility.exe
amdcleanuputility.exe
amdcleanuputility.exe
amdcleanuputility.exe
vsdl0g06.15p
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!
Condensed report! The following is a condensed report of the behaviour of the file when executed in a controlled environment. The actions and events described were either performed by the file itself or by any other process launched by the executed file or subjected to code injection by the executed file.