uninstall.exe

ROSTPAY LLC

The software installer program will bundle additional offers in its setup routine. The application uninstall.exe by ROSTPAY has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is the uninstaller utility registered in the Windows Control Panel for the program Carambis Driver Updater by MEDIA FOG LTD.
Publisher:
ROSTPAY LLC  (signed and verified)

MD5:
10b7d46c42268ca0308e29091b4f990c

SHA-1:
a16ee117e986767a63751e346775da04662103c7

SHA-256:
c1ed7c61ab89710fdb205fc584eec308225edbac6ebd99998811d47aa1e7ced6

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/25/2024 6:08:02 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.MediaFrog.ROSTPAY.Installer (M)
16.1.11.5

File size:
142.3 KB (145,752 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\Program Files\carambis\driver updater\uninstall.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
12/14/2010 10:00:00 PM

Valid to:
12/14/2012 9:59:59 PM

Subject:
CN=ROSTPAY LLC, OU=Software Development, O=ROSTPAY LLC, L=Rostov-on-Don, S=RU, C=RU

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
31F74FDD9FABF79D4C202D79A0DA4146

File PE Metadata
Compilation timestamp:
9/26/2011 10:21:33 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:mweqOYEUXPn8FjT9APQAeFzc3gv1zc3c:jEUXEFG45cQv1z

Entry address:
0x39E3

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 91, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, C0, 82, 40, 00, 6A, 08, A3, B8, 2E, 47, 00, E8, 37, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, D0, 2D, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 93, 40, 00, FF, 15, 84, 81, 40, 00, 68, 04, 93, 40, 00, 68, C0, AD, 46, 00, E8, 19, 27, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 30, 4C, 00, 57, E8, 07, 27, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
28 KB (28,672 bytes)

Program Uninstaller
Program name:
Carambis Driver Updater

Display publisher:
MEDIA FOG LTD

Display version:
2.0.0.4706

Uninstall string:
C:\Program Files (x86)\Carambis\Driver Updater\uninstall.exe


Remove uninstall.exe - Powered by Reason Core Security