specialuninstaller_setup-2015-02-11-www.specialuninstaller.com.exe

Special Uninstaller

Ideakee Inc

The application specialuninstaller_setup-2015-02-11-www.specialuninstaller.com.exe, “Special Uninstaller Setup ” by Ideakee Inc has been detected as adware by 2 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.specialuninstaller.com.
Publisher:
http://www.specialuninstaller.com/   (signed by Ideakee Inc)

Product:
Special Uninstaller

Description:
Special Uninstaller Setup

MD5:
c3bcf503fccab3418573473ec139417f

SHA-1:
9c5cfec214798c9ca3226659f6231794d8463399

SHA-256:
eec4875ebaf51e838b61b467b5dc7be373d05cfbba0d752eee4eea94581403b5

Scanner detections:
2 / 68

Status:
Adware

Analysis date:
4/26/2024 11:28:41 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Program.Unwanted.157
9.0.1.043

Reason Heuristics
PUP.Installer.Ideakee
15.2.12.3

File size:
4.5 MB (4,704,680 bytes)

Product version:
3.0

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\vmwarednd\da403a95\2015-02-11\specialuninstaller_setup-2015-02-11-www.specialuninstaller.com.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
10/11/2013 8:00:00 AM

Valid to:
10/11/2016 7:59:59 AM

Subject:
CN=Ideakee Inc, O=Ideakee Inc, STREET="1104# Asphodel Pavilion,Hengxiang Garden 18 LIjiangRoad", L=Guilin, S=Guangxi, PostalCode=541004, C=CN

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00BFB37ABE3F235073942F877A67382940

File PE Metadata
Compilation timestamp:
7/9/2014 3:58:13 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:jZ1rdFp/xuZOzxHFQrTQmfsoAjx08yHh6O+DX7aoV:jZR3p3z1zXjHyHS775

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 2C, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 16, D8, FF, FF, E8, 65, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 2B, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 50, 86...
 
[+]

Entropy:
7.9909

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file specialuninstaller_setup-2015-02-11-www.specialuninstaller.com.exe has been seen being distributed by the following URL.