uninstall.exe

Softacular

The application uninstall.exe by Softacular has been detected as a potentially unwanted program by 12 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. This is the uninstaller utility registered in the Windows Control Panel for the program RocketTab by RocketTab.
Publisher:
Softacular  (signed and verified)

Version:
1.0.5404.14490

MD5:
2772f4954efd4d0edca4f8001bfece4b

SHA-1:
319ec6c7039bf19ef2d0a9b7eecf2f866d72d386

SHA-256:
f2df819aa7ecc3b14e3c4f6a93393cd43fb51f6344cba934b807cbc4f81be0d4

Scanner detections:
12 / 68

Status:
Potentially unwanted

Analysis date:
5/19/2024 10:32:57 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.RocketTab
2015.02.19

Avira AntiVirus
Adware/MSIL.RocketTab.mh
7.11.211.72

avast!
Win32:IBryte-GU [PUP]
2014.9-150218

AVG
Adware Generic5.CJJJ
2014.0.4253

ESET NOD32
MSIL/Adware.iBryte.G application
7.0.302.0

F-Prot
W32/S-3ab11bd4
v6.4.7.1.166

G Data
Win32.Adware.Rockettab
15.2.25

Kaspersky
not-a-virus:AdWare.MSIL.RocketTab
15.0.0.543

McAfee
Program.Adware-RocketTab
16.8.708.2

VIPRE Antivirus
Threat.4798837
36694

Zillya! Antivirus
Adware.RocketTab.Win32.264
2.0.0.2073

File size:
3.7 MB (3,886,816 bytes)

Product version:
1.0.5404.14490

Original file name:
Installer.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\search extensions\uninstall.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
3/23/2014 7:00:00 PM

Valid to:
3/24/2015 6:59:59 PM

Subject:
CN=Softacular, O=Softacular, STREET="4600 Madison Ave, 10th FL", L=Kansas City, S=Missouri, PostalCode=64112, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
753A79B32D5A96BF1872FDE1AC60DEEA

File PE Metadata
Compilation timestamp:
10/18/2014 4:03:23 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
98304:98NoLPH1FPL/EcnIbKCfdolVNlVBav1LYDU:6ohFPbZncLKNpadX

Entry address:
0x3AAC0A

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.3694

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
3.7 MB (3,837,440 bytes)

Program Uninstaller
Program name:
RocketTab

Display publisher:
RocketTab

Uninstall string:
"C:\Program Files (x86)\Search Extensions\uninstall.exe" /u=true /UserID=776be93b-f7c7-47a7-954e-82628eb2c193 /SourceID=leadimpact|leadimpact-2 /ImplementationID=browsersafeguard-rockettab /UC=2014062


Remove uninstall.exe - Powered by Reason Core Security