uninstall.exe

PDF Reader

Install Core

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application uninstall.exe, “PDF Reader Installer” by Install Core has been detected as adware by 32 anti-malware scanners. The program is a setup application that uses the installCore installer. This is the uninstaller utility registered in the Windows Control Panel for the program PDF Reader. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
PDF Reader Technologies  (signed by Install Core)

Product:
PDF Reader

Description:
PDF Reader Installer

Version:
3.1.0.0

MD5:
10918c42e200c1cc22168586f1c7ef0e

SHA-1:
2b4a6e0755312e0e52395afe08803a957c28bc37

SHA-256:
67ffad73537572d33d5eea3e931ce14b4ee5cc6c32bece093a49e80b010fa309

Scanner detections:
32 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/25/2024 9:54:35 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Graftor.31818
355

Agnitum Outpost
Trojan.Genome
7.1.1

AhnLab V3 Security
Packed/Win32.InstallCore
2014.08.29

Avira AntiVirus
ADWARE/Adware.Gen
7.11.30.172

avast!
Win32:InstallCore-F [PUP]
2014.9-160215

Bitdefender
Gen:Variant.Adware.Graftor.31818
1.0.20.230

Bkav FE
W32.HfsAdware
1.3.0.6379

Clam AntiVirus
W32.Adware.InstallCore-2
0.98/19313

Comodo Security
ApplicUnwnt.Win32.AdWare.InstallCore.0
19344

Dr.Web
Adware.InstallCore.13
9.0.1.046

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.31818
8.16.02.15.02

ESET NOD32
Win32/InstallCore.E potentially unwanted application
10.7.0.302.0

Fortinet FortiGate
Riskware/InstallCore
2/15/2016

F-Prot
W32/Agent.MC.gen
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Graftor.31818
11.2016-15-02_2

G Data
Gen:Variant.Adware.Graftor.31818
16.2.24

IKARUS anti.virus
AdWare.InstallCore
t3scan.1.7.5.0

K7 AntiVirus
Trojan
13.176.11684

Malwarebytes
Adware.Agent
v2016.02.15.02

MicroWorld eScan
Gen:Variant.Graftor.31818
17.0.0.138

NANO AntiVirus
Riskware.Win32.InstallCore.nreyf
0.28.2.61861

Norman
Gen:Variant.Adware.Graftor.31818
11.20160215

nProtect
Trojan/W32.InstallCore.550408.C
14.04.07.01

Qihoo 360 Security
Malware.QVM11.Gen
1.0.0.1015

Reason Heuristics
PUP.installCore.PDFReaderTechnologies.Installer (M)
16.2.15.2

Sophos
PUA 'Install Core Installer'
5.12

SUPERAntiSpyware
Trojan.Agent/Gen-InstallCore
9323

Trend Micro House Call
HV_ZYX_BG31019C.TOMC
7.2.46

Trend Micro
HT_INSTALLCORE_BL2100B1.TOMC
10.465.15

Vba32 AntiVirus
BScope.Malware-Cryptor.Sinba.A
3.12.26.3

VIPRE Antivirus
Threat.4150696
32210

Zillya! Antivirus
Trojan.Genome.Win32.137604
2.0.0.1977

File size:
550 KB (563,208 bytes)

Product version:
3.1.0.0

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore

Common path:
C:\Program Files\pdfreader\uninstall\uninstall.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
2/2/2011 1:00:00 AM

Valid to:
2/3/2012 12:59:59 AM

Subject:
CN=Install Core, O=Install Core, STREET=Nisim Aloni 21, L=Tel Aviv, S=Tel Aviv, PostalCode=62919, C=IL

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
2BCA6BFDAB7E5637BA8E7E9C6400CC75

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:ViHKoaTM7VlF9LrJR1x73NFmWQdm1Mz1SS1N31vPhSfFMMXd:Vxx0fF9XXdHX1cSSF1vPhSdMMXd

Entry address:
0x112A90

Entry point:
60, BE, 00, 20, 49, 00, 8D, BE, 00, F0, F6, FF, C7, 87, 10, 27, 0C, 00, 3A, 5C, 06, 91, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
516 KB (528,384 bytes)

Program Uninstaller
Program name:
PDF Reader

Uninstall string:
C:\Program Files (x86)\PDFReader\Uninstall\Uninstall.exe /Uninstall


Remove uninstall.exe - Powered by Reason Core Security