uninstall.exe

Install Core

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application uninstall.exe by Install Core has been detected as adware by 25 anti-malware scanners. The program is a setup application that uses the installCore installer. This is the uninstaller utility registered in the Windows Control Panel for the program FoxTab AVI Converter. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Install Core  (signed and verified)

MD5:
d28acac3f15271ec3393371f1a74acd5

SHA-1:
4271c778f6879d78fc0d706582ec805229306441

SHA-256:
636bd8267aa3f183ec7a80c99563cc3f44424ccaa0c2d77c8bea033b2ae2220b

Scanner detections:
25 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/18/2024 1:38:47 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Adware/Win32.InstallCore
2013.10.21

Avira AntiVirus
7.11.108.166

avast!
Win32:InstallCore-F [PUP]
2014.9-140108

Baidu Antivirus
Trojan.Win32.Agent
4.0.3.1418

Bitdefender
Gen:Variant.Application.InstallCore.1
1.0.20.40

Comodo Security
ApplicUnwnt.Win32.AdWare.InstallCore.0
17135

Dr.Web
Adware.InstallCore.14
9.0.1.08

Emsisoft Anti-Malware
Gen:Variant.Application.InstallCore
8.14.01.08.02

ESET NOD32
Win32/InstallCore (variant)
8.8941

Fortinet FortiGate
1/8/2014

F-Prot
W32/InstallCore.A.gen
v6.4.7.1.166

G Data
Gen:Variant.Application.InstallCore
14.1.22

K7 AntiVirus
Trojan
13.173.9916

Malwarebytes
Adware.Agent
v2014.01.08.02

McAfee
RDN/Generic PUP.x!bjm
5600.7257

MicroWorld eScan
Gen:Variant.Application.InstallCore.1
15.0.0.24

Quick Heal
Trojan.Sisproc.A8
1.14.12.00

Reason Heuristics
PUP.InstallCore.J
14.8.7.23

Rising Antivirus
AdWare.Win32.InstallCore.b
23.00.65.14106

Sophos
Install Core Installer
4.93

SUPERAntiSpyware
Adware.InstallCore
10859

Trend Micro House Call
TROJ_GEN.R11CEKF
7.2.8

Trend Micro
TROJ_GEN.R11CEKF
10.465.08

Vba32 AntiVirus
BScope.Malware-Cryptor.Sinba.B
3.12.24.3

VIPRE Antivirus
InstallCore
22562

File size:
556.5 KB (569,864 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\uninstall.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
2/2/2011 8:00:00 AM

Valid to:
2/3/2012 7:59:59 AM

Subject:
CN=Install Core, O=Install Core, STREET=Nisim Aloni 21, L=Tel Aviv, S=Tel Aviv, PostalCode=62919, C=IL

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
2BCA6BFDAB7E5637BA8E7E9C6400CC75

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:AgxQcf6/1HzMaVPTHbo2iJfUhqpi4ZnVofmMMjL:AgycoMaVPn3oLZn6fmMMjL

Entry address:
0x119030

Entry point:
60, BE, 00, 60, 49, 00, 8D, BE, 00, B0, F6, FF, C7, 87, 10, 97, 0C, 00, 05, 4D, 29, 3A, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Entropy:
7.8921

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
528 KB (540,672 bytes)

Program Uninstaller
Program name:
FoxTab AVI Converter

Uninstall string:
C:\Program Files (x86)\FoxTabAVIConverter\Uninstall\Uninstall.exe /Uninstall


The file uninstall.exe has been seen being distributed by the following URL.

Remove uninstall.exe - Powered by Reason Core Security