uninstall.exe

Yordan Damyanov

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application uninstall.exe by Yordan Damyanov has been detected as adware by 4 anti-malware scanners. The program is a setup application that uses the WebPick InstalleRex installer. While running, it connects to the Internet address r1.stylezip.info on port 80 using the HTTP protocol.
Publisher:
Yordan Damyanov  (signed and verified)

MD5:
d9e7aa45e46de13e43e0d2432a21b064

SHA-1:
7ebf9abdf5d00f8388506cf8caf84c388cd5ae37

SHA-256:
933455d0b192dcec61df3763c32f62bebd9f9cbb9e38211cc43e74c7657acd1e

Scanner detections:
4 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/24/2024 10:53:15 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Trojan.Click3.5376
9.0.1.0335

Kaspersky
HEUR:Trojan.Win32.StartPage
14.0.0.1037

Qihoo 360 Security
Win32/Trojan.d77
1.0.0.1015

Reason Heuristics
PUP.WebPick.YordanDamyanov.Bundler (M)
15.12.1.15

File size:
1.6 MB (1,681,856 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
WebPick InstalleRex

Common path:
C:\users\{user}\appdata\roaming\arhome\uninstall.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
10/7/2013 3:00:00 AM

Valid to:
10/8/2015 2:59:59 AM

Subject:
CN=Yordan Damyanov, O=Yordan Damyanov, STREET=19 Dobri Voinikov Str, L=Sofia, S=Sofia, PostalCode=1000, C=BG

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00FEEF0D77D0AC7E55D4E7707B384AC901

File PE Metadata
Compilation timestamp:
1/21/2014 12:47:27 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:q4klbgSbpjwP20ktxWGdsK0QgyVlkOGTTAiOkgxBtMtPkyw3Wx7zjFF2zuD/j:WPFjwKZsKlgyVlITTAiJgW2mRXFF2zG

Entry address:
0x8FB04

Entry point:
E8, 9C, CB, 00, 00, E9, 89, FE, FF, FF, CC, CC, 8B, FF, 55, 8B, EC, 83, EC, 18, 53, 8B, 5D, 0C, 56, 8B, 73, 08, 33, 35, 04, 25, 4C, 00, 57, 8B, 06, C6, 45, FF, 00, C7, 45, F4, 01, 00, 00, 00, 8D, 7B, 10, 83, F8, FE, 74, 0D, 8B, 4E, 04, 03, CF, 33, 0C, 38, E8, 83, C6, FF, FF, 8B, 4E, 0C, 8B, 46, 08, 03, CF, 33, 0C, 38, E8, 73, C6, FF, FF, 8B, 45, 08, F6, 40, 04, 66, 0F, 85, 19, 01, 00, 00, 8B, 4D, 10, 8D, 55, E8, 89, 53, FC, 8B, 5B, 0C, 89, 45, E8, 89, 4D, EC, 83, FB, FE, 74, 5F, 8D, 49, 00, 8D, 04, 5B, 8B...
 
[+]

Entropy:
7.5985

Code size:
685 KB (701,440 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to r1.stylezip.info  (54.186.255.26:80)

Remove uninstall.exe - Powered by Reason Core Security