uninstall.exe

WinBooster 2012

Dr Salman Zafar

The application uninstall.exe, “WinBooster 2012 Setup” by Dr Salman Zafar has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. This is the uninstaller utility registered in the Windows Control Panel for the program WinBooster 2012 by Digital Millenium Inc.
Publisher:
Digital Millenium Inc  (signed by Dr Salman Zafar)

Product:
WinBooster 2012

Description:
WinBooster 2012 Setup

Version:
5.21.0.2012

MD5:
f055b5f7ee9fd17b401ed31aeb26bab2

SHA-1:
41d4cb498c905559b557c176b2633d67134f3db5

SHA-256:
b7de70f9ea5f2f53b899a0fe556582a53694f40179555dc727e0eeb459735de9

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/27/2024 4:03:27 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.DrSalman.Installer (M)
16.4.15.9

File size:
142.2 KB (145,648 bytes)

Product version:
5.21.0.2012

Copyright:
Copyright © 2012 Digital Millenium Inc

Original file name:
winboost.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\winbooster 2012\uninstall.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/3/2012 5:30:00 AM

Valid to:
5/4/2013 5:29:59 AM

Subject:
CN=Dr Salman Zafar, O=Dr Salman Zafar, STREET=8 Achilles Road, L=Coventry, S=West Midlands, PostalCode=CV6 7NH, C=GB

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
7BDC15504020A97470E73278B5718D59

File PE Metadata
Compilation timestamp:
1/31/2011 11:14:13 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:njlSRC9Z/ey04DEN6bs25rRCxQkbdnUim/7I:jlSRC9Zey1Da25rITdUfI

Entry address:
0x1D20

Entry point:
55, 8B, EC, 6A, FF, 68, 28, 21, 40, 00, 68, A0, 1E, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 88, 20, 40, 00, 59, 83, 0D, 54, 35, 40, 00, FF, 83, 0D, 58, 35, 40, 00, FF, FF, 15, 84, 20, 40, 00, 8B, 0D, CC, 32, 40, 00, 89, 08, FF, 15, 80, 20, 40, 00, 8B, 0D, C8, 32, 40, 00, 89, 08, A1, 7C, 20, 40, 00, 8B, 00, A3, 5C, 35, 40, 00, E8, 10, 01, 00, 00, 39, 1D, BC, 32, 40, 00, 75, 0C, 68, 9C, 1E, 40, 00, FF, 15, 78, 20...
 
[+]

Entropy:
7.5366

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
4 KB (4,096 bytes)

Program Uninstaller
Program name:
WinBooster 2012

Display publisher:
Digital Millenium Inc

Display version:
5.21.0.2012

Uninstall string:
C:\Program Files (x86)\WinBooster 2012\uninstall.exe


Remove uninstall.exe - Powered by Reason Core Security