platypus7.client.uninstall.exe

Platypus Billing System (Client)

Tucows Inc.

The application platypus7.client.uninstall.exe by Tucows has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is the uninstaller utility registered in the Windows Control Panel for the program Platypus Billing System (Client) 7.0 by Tucows Inc..
Publisher:
Tucows Inc.  (signed and verified)

Product:
Platypus Billing System (Client)

Version:
7.0.2219.0

MD5:
0ddfe08f5b13da1c8c8cc72563ecdfa6

SHA-1:
de54c2ffc7a2ade8e6dee200688b818c1da829f6

SHA-256:
f415ef581bf5fe4beaafead9e8e3fa7b38ae627d4479e63bbdd833dea7712691

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/3/2024 7:20:28 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Tucows.Installer (M)
16.5.18.1

File size:
865.7 KB (886,520 bytes)

Product version:
7.0.2219.0

Copyright:
Tucows, Inc. © 1996-2010, 2011

Trademarks:
Platypus Billing System, Platypus Logo, Wombat Helpdesk System, Wombat Logo

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\Program Files\platypus\platypus7.client.uninstall.exe

Digital Signature
Signed by:

Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
4/29/2009 7:00:00 PM

Valid to:
4/30/2011 6:59:59 PM

Subject:
CN=Tucows Inc., OU=Platypus Billing System, O=Tucows Inc., L=Toronto, S=Ontario, C=CA

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
264D222837911D35F90821F7D3395837

File PE Metadata
Compilation timestamp:
12/5/2009 4:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:3S4Fxn6M4ZmUy6qJWj1PMUI5f9j76OZR1D+TyWnZbkKm4:3lFx6M4Zh/jeP6OZRtUyUZQQ

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
6.0399

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Program Uninstaller
Program name:
Platypus Billing System (Client) 7.0

Display publisher:
Tucows Inc.

Display version:
7.0

Uninstall string:
C:\Program Files (x86)\Platypus\Platypus7.Client.Uninstall.exe


Remove platypus7.client.uninstall.exe - Powered by Reason Core Security