sourceappuninstall.exe

Source App

This is the installer/setup program for a Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application sourceappuninstall.exe by Source App has been detected as adware by 17 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is the uninstaller utility registered in the Windows Control Panel for the program SourceApp by SourceApp. Additionally, the file is typically installed by a number of programs including SourceApp by Yontoo Technology, Inc. and Buzzdock by Alactro LLC, both potentially unwanted software. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
Source App  (signed and verified)

MD5:
72933ae49fd919c03b4e1d7df98d37db

SHA-1:
24ed3443846bd10f4a240e287ca84f2a6c584968

SHA-256:
cac8c91dfddc8af894ec77207dac094ecc5ce16019376980472d06ab9245eb65

Scanner detections:
17 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/25/2024 12:40:43 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Dropped:Adware.BrowseFox.BP
6765824

Avira AntiVirus
ADWARE/BrowseFox.Gen4
7.11.214.34

avast!
BrowseFox-GY [PUP]
150303-0

AVG
Generic
2016.0.3179

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.1535

Bitdefender
Dropped:Adware.BrowseFox.BP
1.0.20.320

Dr.Web
Trojan.Yontoo.474
9.0.1.05190

Emsisoft Anti-Malware
Dropped:Adware.BrowseFox.BP
9.0.0.4799

ESET NOD32
Win32/BrowseFox.C potentially unwanted application
7.0.302.0

F-Secure
Dropped:Adware.BrowseFox.BP
5.13.68

G Data
Dropped:Adware.BrowseFox.BP
15.3.25

K7 AntiVirus
Unwanted-Program
13.200.15176

MicroWorld eScan
Dropped:Adware.BrowseFox.BP
16.0.0.192

NANO AntiVirus
Trojan.Nsis.BrowseFox.dnxihk
0.30.0.296

nProtect
Dropped:Adware.BrowseFox.BP
15.03.05.01

Qihoo 360 Security
Win32/Virus.Adware.650
1.0.0.1015

Reason Heuristics
PUP.Installer.Yontoo
15.3.5.21

File size:
253.3 KB (259,384 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\Program Files\sourceapp\sourceappuninstall.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/16/2014 1:00:00 AM

Valid to:
10/17/2015 12:59:59 AM

Subject:
CN=Source App, O=Source App, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5436973D688F7AF7E3F875CD8B463EDD

File PE Metadata
Compilation timestamp:
12/5/2009 11:52:01 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:xZ+11UWLCORy/1RWBT5+ukticdyzJsURwZm/G/HcJge:bWLCORs1s15vkInqIp/G/8Se

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 6F, 44, 00, E8, F1, 2B, 00, 00, A3, 84, 6E, 44, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, 9C, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 2E, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, F0, 46, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.8659

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

Program Uninstaller
Program name:
SourceApp

Display publisher:
SourceApp

Display version:
2015.03.05.220324

Uninstall string:
C:\Program Files\SourceApp\SourceAppuninstall.exe


The file sourceappuninstall.exe has been discovered within the following programs.

Buzzdock  by Alactro LLC
This is a web browser extension that injects advertising. From the EULA: "Buzzdock is free to download and use. Buzzdock is supported by advertising, and users will see additional ads on websites where Buzzdock features operate.
www.buzzdock.com/faq-support
79% remove it
SourceApp  by Yontoo Technology, Inc.
Source App is an ad-supported program that will display third-party advertisements in the user's web browser. It displays several types of advertising, including but not limited to: - Sponsored links - Video targeted ads (which are displayed when you view a video).
sourceapp.info/support
80% remove it
 
Powered by Should I Remove It?

Remove sourceappuninstall.exe - Powered by Reason Core Security