uninstall.exe

Install Core

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application uninstall.exe by Install Core has been detected as adware by 32 anti-malware scanners. The program is a setup application that uses the installCore installer. This is the uninstaller utility registered in the Windows Control Panel for the program FoxTab FLV Player. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Install Core  (signed and verified)

MD5:
41dc09fcbb20692634be5a77ccbd2ffc

SHA-1:
38cff6fc85fceffd669aa7aae895afb6ae114a1a

SHA-256:
4895da870c27879f8b6849cbb4619e69ab75bc69e33c8abe0c7386189eb39b66

Scanner detections:
32 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/19/2024 6:38:50 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.8055905
6213306

Agnitum Outpost
Adware.InstallCore
7.1.1

AhnLab V3 Security
Adware/Win32.InstallCore
2014.12.22

Avira AntiVirus
7.11.197.38

avast!
Win32:InstallCore-F [PUP]
141214-1

Bitdefender
Trojan.Generic.8055905
1.0.20.1780

Clam AntiVirus
W32.Adware.InstallCore-2
0.98/19819

Comodo Security
ApplicUnwnt.Win32.AdWare.InstallCore.0
20438

Dr.Web
Adware.InstallCore.20
9.0.1.05190

Emsisoft Anti-Malware
Trojan.Generic.8055905
9.0.0.4668

ESET NOD32
Win32/InstallCore.F potentially unwanted application
7.0.302.0

Fortinet FortiGate
W32/InstallCore.gen
12/22/2014

F-Prot
W32/InstallCore.A.gen
4.6.5.141

F-Secure
Trojan.Generic.8055905
5.13.68

G Data
Trojan.Generic.8055905
14.12.24

IKARUS anti.virus
Virus.Win32.Heur
t3scan.1.8.5.0

K7 AntiVirus
Trojan
13.188.14410

Malwarebytes
Adware.Agent
v2014.12.22.07

MicroWorld eScan
Trojan.Generic.8055905
15.0.0.1068

NANO AntiVirus
Riskware.Win32.InstallCore.nmzdv
0.28.6.64267

Norman
Trojan.Generic.8055905
04.12.2014 14:30:06

nProtect
Trojan.Generic.8055905
14.12.22.01

Qihoo 360 Security
Malware.QVM11.Gen
1.0.0.1015

Reason Heuristics
Adware.InstallCore.J
14.12.22.7

Rising Antivirus
PE:AdWare.Win32.InstallCore.b!1075350581
23.00.65.141220

Sophos
PUA 'Install Core Installer'
5.09

SUPERAntiSpyware
Adware.InstallCore
10162

Trend Micro House Call
TSPY_INSTALLCORE_BK08035E.TOMC
7.2.356

Trend Micro
TSPY_INSTALLCORE_BK08035E.TOMC
10.465.22

Vba32 AntiVirus
BScope.Malware-Cryptor.Sinba.A
3.12.26.3

VIPRE Antivirus
Threat.4150696
35418

Zillya! Antivirus
Trojan.Genome.Win32.155192
2.0.0.2012

File size:
546.5 KB (559,624 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore

Common path:
C:\Program Files\foxtabflvplayer\uninstall\uninstall.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
2/2/2011 1:00:00 AM

Valid to:
2/3/2012 12:59:59 AM

Subject:
CN=Install Core, O=Install Core, STREET=Nisim Aloni 21, L=Tel Aviv, S=Tel Aviv, PostalCode=62919, C=IL

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
2BCA6BFDAB7E5637BA8E7E9C6400CC75

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:ISiKVtSG2dKqs1+CneWrN557DfLque1VA0g7QTMMl7:IvAiT+55nfuue1mdQTMMl7

Entry address:
0x1118B0

Entry point:
60, BE, 00, 10, 49, 00, 8D, BE, 00, 00, F7, FF, C7, 87, 10, 27, 0C, 00, 1F, 27, 37, 0D, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
516 KB (528,384 bytes)

Program Uninstaller
Program name:
FoxTab FLV Player

Uninstall string:
C:\Program Files (x86)\FoxTabFLVPlayer\Uninstall\Uninstall.exe /Uninstall


Remove uninstall.exe - Powered by Reason Core Security