uninstall.exe

nbiz Ltd.

The application uninstall.exe by nbiz has been detected as adware by 9 anti-malware scanners.
Publisher:
nbiz Ltd.  (signed and verified)

MD5:
b186739ffd091b18bd9b6dc3279b2494

SHA-1:
744ec266d877d20b0592358323e4dacc7f73154f

Scanner detections:
9 / 68

Status:
Adware

Analysis date:
4/25/2024 1:09:47 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win-PUP/Helper.InfoTab.29864.E
2011.09.02

Avira AntiVirus
Adware/BonusCash.AB.11
7.11.14.90

AVG
Generic4
2015.0.3490

Comodo Security
UnclassifiedMalware
9966

Dr.Web
Trojan.AVKill.2
9.0.1.0118

ESET NOD32
Win32/Adware.BonusCash.AB (variant)
8.6430

McAfee
Artemis!B186739FFD09
5600.7146

Reason Heuristics
PUP.nbiz.J
14.8.8.0

VIPRE Antivirus
Trojan.Win32.Generic
10348

File size:
29.2 KB (29,864 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\infotab\uninstall.exe

Digital Signature
Signed by:

Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
11/17/2009 9:00:00 AM

Valid to:
12/18/2010 8:59:59 AM

Subject:
CN=nbiz Ltd., OU=Development Department, O=nbiz Ltd., L=Gangnam-gu, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
33C94BE607A8FCA76527503BC6F9940A

File PE Metadata
Compilation timestamp:
5/11/2010 11:46:14 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
384:/pzalmOPUaWYVa1irjeU0tP9nNxkjpYJLH:RXWciryUq9nuELH

Entry address:
0x222D

Entry point:
55, 8B, EC, 6A, FF, 68, C8, 34, 40, 00, 68, B0, 21, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 0C, 32, 40, 00, 59, 83, 0D, A4, 42, 40, 00, FF, 83, 0D, A8, 42, 40, 00, FF, FF, 15, 10, 32, 40, 00, 8B, 0D, 98, 42, 40, 00, 89, 08, FF, 15, 14, 32, 40, 00, 8B, 0D, 94, 42, 40, 00, 89, 08, A1, 18, 32, 40, 00, 8B, 00, A3, A0, 42, 40, 00, E8, 17, 01, 00, 00, 39, 1D, B0, 41, 40, 00, 75, 0C, 68, B0, 23, 40, 00, FF, 15, 1C, 32...
 
[+]

Entropy:
4.1660

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
8 KB (8,192 bytes)

Remove uninstall.exe - Powered by Reason Core Security