uninstall.exe

Setup Factory Runtime

Mindspark Interactive Network

This is the installer stub for the Mindspark (Indigo Rose Corporation/Ask) browser toolbar which provides the offer to the end user to install the toolbar and set the browser's search, home page and new tab to an Ask.com search destination. The application uninstall.exe, “Setup Application” by Mindspark Interactive Network has been detected as a potentially unwanted program by 8 anti-malware scanners. The program is a setup application that uses the Setup Factory installer. This file is typically installed with the program Elite Unzip by Mindspark Interactive Network which is a potentially unwanted software program. This version of the installer will bundle a Mindspark/MyWebSearch Toolbar, a potentially unwanted web browser extension.
Publisher:
Indigo Rose Corporation  (signed by Mindspark Interactive Network)

Product:
Setup Factory Runtime

Description:
Setup Application

Version:
9.2.0.0

MD5:
b6440cf92d3de542ed6d4cffe56758d1

SHA-1:
4957d5d1047f88d0ebfbe4aae6747df7941d8e33

SHA-256:
541a9b71b37e5d9522889835cfe5c1b753164ca6742344d5e4125a3678878db6

Scanner detections:
8 / 68

Status:
Potentially unwanted

Explanation:
Bundles the Mindspark (MyWebSearch/Ask) toolbar, a web browser extension that will modify a user's search and home pages.

Analysis date:
4/26/2024 11:39:01 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

avast!
Win32:Mindspark-A [PUP]
2014.9-141124

AVG
MyWebSearch
2015.0.3280

Baidu Antivirus
Adware.Win32.MyWebSearch
4.0.3.141124

G Data
Win32.Adware.Mindspark
14.11.24

Panda Antivirus
Adware/WebSearch
14.11.24.03

Reason Heuristics
PUP.Installer.MindsparkInteractiveNetwork.J
14.11.24.15

Trend Micro House Call
Suspicious_GEN.F47V1121
7.2.328

VIPRE Antivirus
35092

File size:
1.3 MB (1,352,032 bytes)

Product version:
9.2.0.0

Copyright:
Runtime Engine Copyright © 2013 Indigo Rose Corporation (www.indigorose.com)

Trademarks:
Setup Factory is a trademark of Indigo Rose Corporation

Original file name:
suf_rt.exe

File type:
Executable application (Win32 EXE)

Installer:
Setup Factory

Language:
English (United States)

Common path:
C:\Program Files\eliteunzip\uninstall.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/9/2012 5:00:00 PM

Valid to:
5/6/2015 4:59:59 PM

Subject:
CN=Mindspark Interactive Network, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Mindspark Interactive Network, L=White Plains, S=NewYork, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
098417F7EA6406EC7B320590E17A65B7

File PE Metadata
Compilation timestamp:
8/27/2013 11:43:38 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:N3BrELwtW5a1bTFQE+m/OHe72CmAD/XWsQRs9fTSO7OwHmPWce6NsR:VR2X6pymME2HAD/W5Rsleo+PWceay

Entry address:
0x3C40A0

Entry point:
60, BE, 00, 40, 68, 00, 8D, BE, 00, D0, D7, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Entropy:
7.9210

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
1.3 MB (1,314,816 bytes)

The file uninstall.exe has been discovered within the following programs.

Elite Unzip  by Mindspark Interactive Network
Publisher's description - “The Toolbar, in the course of processing a given search query, sends a request to our servers.”
www.mindspark.com
72% remove it
 
Powered by Should I Remove It?

Remove uninstall.exe - Powered by Reason Core Security