uninstall.exe

Windows Winerspop

JE communication

The application uninstall.exe by JE communication has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is the uninstaller utility registered in the Windows Control Panel for the program Windows Winerspop by Windows Winerspop.
Publisher:
JE communication  (signed and verified)

Product:
Windows Winerspop

Version:
1.0.0.4

MD5:
9a403ae3a2d7f8f008a1d385569430fc

SHA-1:
d8d09cbf63a8e189dfc6fca254e57c948ee499aa

SHA-256:
3bb09d2661ffdc607bdd5502ddeb87abbb85fc60073c5ccd6373508e6ca0e6f0

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/25/2024 11:51:09 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.JEcommunication.Installer (M)
16.3.5.10

File size:
158.2 KB (161,976 bytes)

Product version:
1.0.0.4

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\Program Files\windows winerspop 1.5\uninstall.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
10/29/2012 9:00:00 AM

Valid to:
11/29/2013 8:59:59 AM

Subject:
CN=JE communication, OU=IT Team, O=JE communication, L=Gangnam-gu, S=SEOUL, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
79BFEDDF41C2E1BD5C1C61870556A607

File PE Metadata
Compilation timestamp:
12/6/2009 7:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:1gXdZt9P6D3XJNyw23XLvvmOoS/Z2OV/z7NMNUQupMhklgmD7IOvQfq2fF63CN:1e34r3S/sg/NMN8pMhqgE0OykU

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.4561

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Program Uninstaller
Program name:
Windows Winerspop

Display publisher:
Windows Winerspop

Display version:
1.0

Uninstall string:
C:\Program Files (x86)\Windows Winerspop 1.5\uninstall.exe delete


Remove uninstall.exe - Powered by Reason Core Security