sourceappuninstall.exe

Source App

This is the installer/setup program for a Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application sourceappuninstall.exe by Source App has been detected as adware by 5 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is the uninstaller utility registered in the Windows Control Panel for the program SourceApp by SourceApp. This file is typically installed with the program SourceApp by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
Source App  (signed and verified)

MD5:
cc32fdcbd69f31302ba726900d9682d1

SHA-1:
28fecd78f59dee10ed600422020f997ec04d3957

SHA-256:
83e81a9354ce6816970f43ca43423cf3152360ee4bab4eeba3f3dca1aad4dcc2

Scanner detections:
5 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/19/2024 12:35:09 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
BrowseFox-D [PUP]
141214-1

AVG
Generic
2015.0.3253

ESET NOD32
Win32/BrowseFox.C potentially unwanted application
7.0.302.0

Reason Heuristics
PUP.SourceApp.S
14.12.22.5

VIPRE Antivirus
Threat.4150696
35418

File size:
252.6 KB (258,680 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\Program Files\sourceapp\sourceappuninstall.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/16/2014 12:00:00 AM

Valid to:
10/16/2015 11:59:59 PM

Subject:
CN=Source App, O=Source App, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5436973D688F7AF7E3F875CD8B463EDD

File PE Metadata
Compilation timestamp:
12/5/2009 10:52:01 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:ZZ+11NV0y/1RWBT5yCqWeOuwZm/G/HcJpw:a+s1s15dEp/G/8bw

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 6F, 44, 00, E8, F1, 2B, 00, 00, A3, 84, 6E, 44, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, 9C, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 2E, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, F0, 46, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

Program Uninstaller
Program name:
SourceApp

Display publisher:
SourceApp

Display version:
2014.12.20.122154

Uninstall string:
C:\Program Files\SourceApp\SourceAppuninstall.exe


The file sourceappuninstall.exe has been discovered within the following program.

SourceApp  by Yontoo Technology, Inc.
Source App is an ad-supported program that will display third-party advertisements in the user's web browser. It displays several types of advertising, including but not limited to: - Sponsored links - Video targeted ads (which are displayed when you view a video).
sourceapp.info/support
80% remove it
 
Powered by Should I Remove It?

Remove sourceappuninstall.exe - Powered by Reason Core Security