fulluninstallagent.exe

Konstantin Polyakov

It runs as a scheduled task under the Windows Task Scheduler named InstallerTracingAgent triggered to execute each time a user logs in.
Publisher:
Konstantin Polyakov  (signed and verified)

MD5:
bce6a28ed0e3fefcfcb2d56c72a83b86

SHA-1:
a377b82c7de6b50498e4122a72485a24225290d7

SHA-256:
aa9b94caf53e3a22d3ede2d6709c1073705150ad2da1df5a3c9fbacfc1e90fc1

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 4:21:32 PM UTC  (today)

File size:
870.3 KB (891,136 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\full uninstall\fulluninstallagent.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
6/21/2010 3:00:00 AM

Valid to:
6/21/2012 2:59:59 AM

Subject:
CN=Konstantin Polyakov, O=Konstantin Polyakov, STREET="Behtereva Str.,3-65", L=Ekaterinburg, S=N/A, PostalCode=620137, C=RU

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
18148592B16C7BAA183584A9A875C576

File PE Metadata
Compilation timestamp:
1/27/2012 4:17:11 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

CTPH (ssdeep):
12288:jwbrtcGnKVMoPb5nTmxpjIyeMTxFUxWMT5gT8dIind/ZtEaYdfr2uHbRpIUW2lQp:jIrgVzIxtITMFem8dvDYd6Q9lNhIIgM

Entry address:
0x14A4

Entry point:
EB, 10, 66, 62, 3A, 43, 2B, 2B, 48, 4F, 4F, 4B, 90, E9, 9C, 90, 4A, 00, A1, 8F, 90, 4A, 00, C1, E0, 02, A3, 93, 90, 4A, 00, 52, 6A, 00, E8, 45, 71, 0A, 00, 8B, D0, E8, 12, 88, 09, 00, 5A, E8, F0, 83, 09, 00, E8, 43, 8D, 09, 00, 6A, 00, E8, C4, 9E, 09, 00, 59, 68, 38, 90, 4A, 00, 6A, 00, E8, 1F, 71, 0A, 00, A3, 97, 90, 4A, 00, 6A, 00, E9, 17, 30, 0A, 00, E9, F6, 9E, 09, 00, 33, C0, A0, 81, 90, 4A, 00, C3, A1, 97, 90, 4A, 00, C3, 60, BB, 00, 50, B0, BC, 53, 68, AD, 0B, 00, 00, C3, B9, EC, 00, 00, 00, 0B, C9...
 
[+]

Code size:
672 KB (688,128 bytes)

Scheduled Task
Task name:
InstallerTracingAgent

Trigger:
Logon (Runs on logon)


Scan fulluninstallagent.exe - Powered by Reason Core Security