uninstall.exe

Ticno iO

Media Labs Ltd.

The application uninstall.exe, “Ticno iO Installer” by Media Labs has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is the uninstaller utility registered in the Windows Control Panel for the program Ticno iO by Ticno.com. This file is typically installed with the program Ticno iO by Ticno.com.
Publisher:
Media Labs Ltd.  (signed and verified)

Product:
Ticno iO

Description:
Ticno iO Installer

Version:
0.3.3.1

MD5:
bd1eb2867470066a94b42629e5966f9f

SHA-1:
177a8c4231f6ee6301d5e8b2a20d65ec790bbb76

SHA-256:
76eb312c3b07b2cbd3aa038b62e47cc0ddb6058dcea11bc9e4e63e3608ff4b17

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/26/2024 4:59:02 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Media Labs.MediaLabs.Installer (M)
16.2.13.6

File size:
69.8 KB (71,504 bytes)

Copyright:
Copyright © 2013 - Media Labs

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\Program Files\ticno\ticno io\uninstall.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
6/13/2012 8:00:00 AM

Valid to:
6/14/2013 7:59:59 AM

Subject:
CN=Media Labs Ltd., O=Media Labs Ltd., STREET="Electrolitnii proezd, 1-3", L=Moscow, S=Moscow, PostalCode=115230, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
79A168B461275EFDFE54CFD7B17B0BAF

File PE Metadata
Compilation timestamp:
12/6/2009 6:50:46 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:ZQpQ5EP0ijnRTXJc7FM6NvCHoCSnM6ksFUbSLfcFBO+VdJrWwquCk:ZQIURTXJc7G6NaI/M3sFUbq+O6dJrWwX

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

Program Uninstaller
Program name:
Ticno iO

Display publisher:
Ticno.com

Display version:
0.3.3.1

Uninstall string:
C:\Program Files (x86)\Ticno\Ticno iO\uninstall.exe


The file uninstall.exe has been discovered within the following program.

Ticno iO  by Ticno.com
ticno.com
37% remove it
 
Powered by Should I Remove It?

Remove uninstall.exe - Powered by Reason Core Security