uninst.exe

PerformerSoft LLC

This is part of a Performersoft product, a 'PC optimzation' application that provides minimal benifits and may have been bundled by a third party installer. The application uninst.exe by PerformerSoft has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
PerformerSoft LLC  (signed and verified)

MD5:
519d1a8cd137e8df66a7bd5084366d8d

SHA-1:
1c41224521b4d6d26ea10569a3e02b677317a6f6

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/23/2024 3:24:28 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Performersoft
15.2.12.9

File size:
92.6 KB (94,816 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\pc performer\uninst.exe

Digital Signature
Authority:
Starfield Technologies, Inc.

Valid from:
4/18/2011 7:13:23 AM

Valid to:
6/25/2011 2:20:46 PM

Subject:
CN=PerformerSoft LLC, O=PerformerSoft LLC, L=Beaverton, S=OR, C=US

Issuer:
SERIALNUMBER=10688435, CN=Starfield Secure Certification Authority, OU=http://certificates.starfieldtech.com/repository, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
0820595B0D0DA7

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
1536:YjqjoQnFFW375v45dEKJ3tvOUp0WQ9Esv3jtHqfRmqG7k5OTAY63Nb934HniASSV:/oqFI7K5dE2tWUeWQWsv3BHqfRmqG7k+

Entry address:
0x123CC

Entry point:
55, 8B, EC, 83, C4, F0, 53, B8, 3C, 23, 41, 00, E8, 3B, 31, FF, FF, B2, 01, A1, 60, 1F, 41, 00, E8, 1B, FC, FF, FF, 8B, D8, BA, 01, 00, 00, 80, 8B, C3, E8, AD, FC, FF, FF, 33, C9, BA, 18, 25, 41, 00, 8B, C3, E8, 03, FD, FF, FF, 84, C0, 74, 5B, BA, 50, 25, 41, 00, 8B, C3, E8, 87, FE, FF, FF, 84, C0, 74, 0C, BA, 50, 25, 41, 00, 8B, C3, E8, 07, FE, FF, FF, BA, 68, 25, 41, 00, 8B, C3, E8, 6B, FE, FF, FF, 84, C0, 74, 0C, BA, 68, 25, 41, 00, 8B, C3, E8, EB, FD, FF, FF, BA, 88, 25, 41, 00, 8B, C3, E8, 4F, FE, FF...
 
[+]

Entropy:
6.5097

Developed / compiled with:
Microsoft Visual C++

Code size:
70 KB (71,680 bytes)

Remove uninst.exe - Powered by Reason Core Security