uninstall.exe

The executable uninstall.exe has been detected as malware by 27 anti-virus scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. This is the uninstaller utility registered in the Windows Control Panel for the program KN StrongDC.
MD5:
eaaf3351825d7822561d8245fa52e710

SHA-1:
76506221b451301f289e7fdfea99e0c0b8ba2483

SHA-256:
e42355e60cf6b9eb94a60300b1ba5ab68d22c055fffd4980b81356e4dedfd262

Scanner detections:
27 / 68

Status:
Malware

Analysis date:
4/26/2024 9:10:11 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win-Trojan/Agent.105472.BP
2011.02.06

Avira AntiVirus
TR/Click.Agent.hhw
7.11.2.92

avast!
Win32:Trojan-gen
2014.9-140722

AVG
Clicker
2015.0.3405

Bitdefender
Trojan.Generic.2585320
1.0.20.1015

Dr.Web
Trojan.Click1.23973
9.0.1.0203

Emsisoft Anti-Malware
Trojan-Dropper.Agent!IK
8.14.07.22.04

ESET NOD32
Win32/TrojanClicker.Agent.HCNRDIO (variant)
8.5853

F-Prot
W32/Trojan2.JEAE
v6.4.6.2.117

F-Secure
Trojan.Generic.2585320
11.2014-22-07_3

G Data
Trojan.Generic.2585320
14.7.21

IKARUS anti.virus
Trojan-Dropper.Agent
t3scan.1.1.97.0

K7 AntiVirus
Trojan
13.81.3771

Kaspersky
Trojan-Clicker.Win32.Agent
14.0.0.3522

McAfee
Generic.dx!jav
5600.7061

Norman
W32/Suspicious_Gen2.ACGJN
11.20140722

nProtect
Trojan-Clicker/W32.Agent.105472.B
11.01.27.01

Panda Antivirus
Trj/CI.A
14.07.22.04

Prevx
Medium Risk Malware
3.0

Quick Heal
TrojanClicker.Agent.hhw
7.14.11.00

Rising Antivirus
Trojan.Win32.Generic.12451306
23.00.65.14720

Sophos
Mal/Generic-L
4.61

Trend Micro House Call
TROJ_GEN.USF0YJ
7.2.203

Trend Micro
TROJ_GEN.USF0YJ
10.465.22

Vba32 AntiVirus
Trojan-Clicker.Win32.Agent.hhw
3.12.14.3

VIPRE Antivirus
Trojan.Win32.Generic
8338

ViRobot
Backdoor.Win32.S.Poison.105472
2011.2.7.4297

File size:
103 KB (105,472 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\kn_strongdc\uninstall.exe

File PE Metadata
Compilation timestamp:
4/5/2006 10:55:39 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
3.0

CTPH (ssdeep):
1536:oQC9V+ahCZjv8CnepdipbSL1ww/cdFrkdJuhyy219IDV5LyIldX7zPP1fL9:QBMvzevo6jExQyGOD5b5L9

Entry address:
0x1226

Entry point:
55, 8B, EC, 81, EC, 5C, 0A, 00, 00, 53, 8D, 85, A4, F9, FF, FF, 56, 33, DB, 57, 8D, 8D, A4, F5, FF, FF, 68, 00, 02, 00, 00, 89, 5D, F0, 51, 89, 45, F8, 53, FF, 15, F8, 40, 40, 00, 39, 1D, 2C, 20, 40, 00, 74, 4F, A1, 2C, 20, 40, 00, 8D, 8D, A4, FD, FF, FF, 50, 68, 98, 31, 40, 00, 51, FF, 15, 08, 41, 40, 00, 83, C4, 0C, 8D, 8D, A4, FD, FF, FF, 51, 6A, 01, 53, FF, 15, F4, 40, 40, 00, FF, 15, F0, 40, 40, 00, 3D, B7, 00, 00, 00, 75, 17, 68, 74, 31, 40, 00, 8D, 85, A4, FD, FF, FF, 50, FF, 15, B4, 40, 40, 00, E9...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
3.5 KB (3,584 bytes)

Program Uninstaller
Program name:
KN StrongDC

Uninstall string:
C:\Program Files\KN_StrongDC\uninstall.exe


Remove uninstall.exe - Powered by Reason Core Security