uninstall.exe

IronSource Ltd

The application uninstall.exe by IronSource has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. This is the uninstaller utility registered in the Windows Control Panel for the program FoxTab PDF Reader.
Publisher:
IronSource Ltd  (signed and verified)

MD5:
cd6f3eb167944813ed25e9dc7f7f6d4c

SHA-1:
d64d69aa19166b8e60a281db1b648d92d053e96d

SHA-256:
4ead6b9dc71060311b3eaca96f02ce3e909c280bfca1d3e7043f844601995c81

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 10:50:16 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ironSource.Installer (M)
16.2.15.9

File size:
568.4 KB (582,024 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\foxtabpdfreader\uninstall\uninstall.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
11/8/2011 1:00:00 AM

Valid to:
11/8/2012 12:59:59 AM

Subject:
CN=IronSource Ltd, O=IronSource Ltd, STREET=Namal 36 suit 1, L=Tel Aviv-Yafo, S=IL, PostalCode=68033, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
008E236034501AEA96AE96F0B0FD227271

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:ua/WIKRSrQklYwf7k4paeakR2ebRRUIZwp6WO7XaUe9p5cYxMMqo:LWIKRS8kl1zk9YHMo/aUe9TPMMqo

Entry address:
0x1157E0

Entry point:
60, BE, 00, 00, 49, 00, 8D, BE, 00, 10, F7, FF, C7, 87, 10, 57, 0C, 00, 90, 22, 0C, 47, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
536 KB (548,864 bytes)

Program Uninstaller
Program name:
FoxTab PDF Reader

Uninstall string:
C:\Program Files (x86)\FoxTabPDFReader\Uninstall\Uninstall.exe /Uninstall


Remove uninstall.exe - Powered by Reason Core Security