uninstall.exe

IronSource Ltd

The application uninstall.exe by IronSource has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. This is the uninstaller utility registered in the Windows Control Panel for the program FoxTab PDF Reader.
Publisher:
IronSource Ltd  (signed and verified)

MD5:
6e6ac18b309e3dfe2621a713267b35d1

SHA-1:
b2d0f3b815cd72ce5b12045d4fe66169a873a34c

SHA-256:
265c91ab90e0d7462dfeebe8cd5e4853eccfa3b7febf5d5ac4b77ba4e62cbf9b

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/24/2024 7:40:36 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ironSource.Installer (M)
16.2.15.0

File size:
568.4 KB (582,024 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\foxtabpdfreader\uninstall\uninstall.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
11/8/2011 1:00:00 AM

Valid to:
11/8/2012 12:59:59 AM

Subject:
CN=IronSource Ltd, O=IronSource Ltd, STREET=Namal 36 suit 1, L=Tel Aviv-Yafo, S=IL, PostalCode=68033, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
008E236034501AEA96AE96F0B0FD227271

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:ra/WIKRSrQklYwf7k4paeakR2ebRRUIZwp6WO7XaUe9p5cYxMMqo:WWIKRS8kl1zk9YHMo/aUe9TPMMqo

Entry address:
0x1157E0

Entry point:
60, BE, 00, 00, 49, 00, 8D, BE, 00, 10, F7, FF, C7, 87, 10, 57, 0C, 00, 90, 22, 0C, 47, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
536 KB (548,864 bytes)

Program Uninstaller
Program name:
FoxTab PDF Reader

Uninstall string:
C:\Program Files (x86)\FoxTabPDFReader\Uninstall\Uninstall.exe /Uninstall


Remove uninstall.exe - Powered by Reason Core Security