Uninstall.exe

DomaUninstaller

Awimba LLC

This is the Tuguu DomaIQ download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application Uninstall.exe by Awimba has been detected as adware by 6 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer. The file has been seen being downloaded from static.ooopsvideo.com.
Publisher:
Awimba LLC  (signed and verified)

Product:
DomaUninstaller

Version:
1.0.0.0

MD5:
6254a448ae80acc3bf684f37fa6eb716

SHA-1:
1658a2a3c75d44161b2d1a185447a88d7f656e37

SHA-256:
efabb0915809ecf85ac40c803a40b717f9efe61de6fe3537d57d5421bfb90d99

Scanner detections:
6 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/20/2024 12:15:35 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
MalSign.Generic
2014.0.3643

Boost by Reason
Adware.Installer.Awimba.J
2013.8.28.22

ESET NOD32
MSIL/DomaIQ
7.9091

Fortinet FortiGate
Adware/DomaIQ
8/28/2013

Reason Heuristics
PUP.Installer.Awimba.J
14.8.7.18

VIPRE Antivirus
DomaIQ
23700

File size:
47.5 KB (48,640 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2013

Original file name:
Uninstall.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\uninstall.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
5/9/2013 5:00:00 PM

Valid to:
5/15/2014 5:00:00 AM

Subject:
CN=Awimba LLC, O=Awimba LLC, L=Wilmington, S=Delaware, C=US

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
09A928EF40E9E87418147E2639362A6E

File PE Metadata
Compilation timestamp:
5/23/2013 4:14:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
768:A3OwArikC9SXUv9+eJRn5Am6kRRJ2iZ3igoJ11JHG73uYcqElK0Ma:T2kC9L4qAELVigo71JIEkZa

Entry address:
0x5D7E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.3736

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
15.5 KB (15,872 bytes)

The file Uninstall.exe has been seen being distributed by the following URL.

Remove Uninstall.exe - Powered by Reason Core Security