uninstall.exe

iLivid

Bandoo Media, Inc

The application uninstall.exe by Bandoo Media, Inc has been detected as a potentially unwanted program by 19 anti-malware scanners.
Publisher:
Bandoo Media Inc  (signed by Bandoo Media, Inc)

Product:
iLivid

Description:
iLivid Uninstall

Version:
5.0.0.4286

MD5:
1ca06205546f8de4d513ac1c76812392

SHA-1:
80cc5ba50b1a311d9b4824ebf1c4da3c812c98ac

Scanner detections:
19 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 6:01:58 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Toolbar.SearchSuite
7.1.1

AhnLab V3 Security
Win-PUP/SearchSuite
2015.03.31

Avira AntiVirus
PUA/iLivid.Gen
3.6.1.96

Baidu Antivirus
Adware.Win32.SearchSuite
4.0.3.16215

Bkav FE
W32.HfsAdware
1.3.0.6379

Clam AntiVirus
Win.Adware.Searchsuite-3
0.98/21147

Comodo Security
Application.Win32.SeaSuite.AKA
21595

Dr.Web
Adware.Bandoo.226, Adware.Bandoo.184
9.0.1.046

ESET NOD32
Win32/Toolbar.SearchSuite.G potentially unwanted application
10.7.0.302.0

G Data
Win32.Adware.Bandoo
16.2.25

IKARUS anti.virus
PUA.Bandoo
t3scan.1.9.5.0

K7 AntiVirus
Unwanted-Program
13.202.15432

Kaspersky
not-a-virus:Downloader.Win32.Agent
14.0.0.659

Malwarebytes
PUP.Optional.Ilivid
v2016.02.15.02

McAfee
Trojan.Artemis!713C113CB985
5600.6489

NANO AntiVirus
Trojan.Win32.Downware.crewao
0.28.0.57029

Reason Heuristics
Win32.Generic
16.2.15.2

SUPERAntiSpyware
PUP.Bandoo/Variant
9323

Trend Micro House Call
TROJ_GEN.F47V1120
7.2.46

File size:
597.5 KB (611,803 bytes)

Product version:
5.0.0.4286

Copyright:
Copyright (c) 2013

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Documents and Settings\{user}\Local settings\temp\{random}.tmp\uninstall.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
9/19/2012 7:00:00 AM

Valid to:
11/3/2014 6:59:59 AM

Subject:
CN="Bandoo Media, Inc", O="Bandoo Media, Inc", L=Panama City, S=Panama, C=PA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
7A5189D163723107DEFA157662A4BAE4

File PE Metadata
Compilation timestamp:
5/30/2013 3:09:15 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:CX47XeKmyti5ELY4jurIMdpmzsV1pDlOCkqsZ4zytbLe:CXmmwO4SrIM3vV1pDlO8a4zki

Entry address:
0x38AF

Entry point:
60, E8, 00, 00, 00, 00, 5B, 81, EB, D0, 48, 19, 01, 83, EC, 74, 8B, EC, 8B, 83, AB, 4B, 19, 01, 89, 45, 00, 8B, 83, B3, 4B, 19, 01, 03, 45, 00, 89, 45, 2C, 8B, 83, B7, 4B, 19, 01, 03, 45, 00, 89, 45, 30, C7, 45, 14, 00, 00, 00, 00, C7, 45, 18, 00, 00, 00, 00, C7, 45, 1C, 00, 00, 00, 00, 8B, 45, 14, FF, 45, 14, 66, 33, C9, 8A, 8C, 03, FF, 4B, 19, 01, 84, C9, 74, 7A, 8B, 45, 1C, 66, 01, 4D, 1C, 03, C3, 05, 13, 4C, 19, 01, 50, 8B, 45, 2C, FF, 10, 85, C0, 0F, 84, 5E, 02, 00, 00, 89, 45, 10, 8B, 45, 1C, 03, C3...
 
[+]

Entropy:
5.2371

Packer / compiler:
ASPack v1.08.04

Code size:
29.5 KB (30,208 bytes)

Remove uninstall.exe - Powered by Reason Core Security