uninstall.exe

iLivid

Bandoo Media, Inc

The application uninstall.exe by Bandoo Media, Inc has been detected as a potentially unwanted program by 16 anti-malware scanners.
Publisher:
Bandoo Media Inc  (signed by Bandoo Media, Inc)

Product:
iLivid

Description:
iLivid Uninstall

Version:
5.0.0.4618

MD5:
c87d90e23c48266368a136ccb87166a3

SHA-1:
f24a67722b85a0895169225c8396b835d2c804f0

Scanner detections:
16 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 10:39:27 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Toolbar.SearchSuite
7.1.1

Avira AntiVirus
APPL/Downloader.Gen
7.11.181.152

AVG
Generic
2017.0.2833

Baidu Antivirus
Adware.Win32.SearchSuite
4.0.3.16215

Clam AntiVirus
Win.Adware.Searchsuite-3
0.98/20656

Dr.Web
Adware.Bandoo.222, Adware.Bandoo.184
9.0.1.046

ESET NOD32
Win32/Toolbar.SearchSuite.G potentially unwanted application
10.7.0.302.0

Fortinet FortiGate
Riskware/Toolbar_SearchSuite
2/15/2016

G Data
Win32.Adware.Bandoo
16.2.24

IKARUS anti.virus
PUA.Bandoo
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.185.13805

Kaspersky
not-a-virus:WebToolbar.Win64.SearchSuite
14.0.0.659

McAfee
Trojan.Artemis!F90084180158
5600.6489

Panda Antivirus
Trj/Chgt.C
16.02.15.03

Reason Heuristics
Win32.Generic
16.2.15.3

VIPRE Antivirus
Threat.4150696
40786

File size:
597.9 KB (612,275 bytes)

Product version:
5.0.0.4618

Copyright:
Copyright (c) 2014

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Documents and Settings\{user}\Local settings\temp\{random}.tmp\uninstall.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
2/9/2014 7:00:00 AM

Valid to:
11/3/2014 6:59:59 AM

Subject:
CN="Bandoo Media, Inc", O="Bandoo Media, Inc", L=Panama City, S=Panama, C=PA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
74B45E4BF603EDCA78C252159948CF7A

File PE Metadata
Compilation timestamp:
5/30/2013 3:09:15 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:GX47XeJmyti5ELY4jurbMFgzsV1pDlOCkqXZ4zytbL2:GXtmwO4SrbMNV1pDlO8J4zki

Entry address:
0x38AF

Entry point:
60, E8, 00, 00, 00, 00, 5B, 81, EB, D0, 48, 00, 10, 83, EC, 74, 8B, EC, 8B, 83, AB, 4B, 00, 10, 89, 45, 00, 8B, 83, B3, 4B, 00, 10, 03, 45, 00, 89, 45, 2C, 8B, 83, B7, 4B, 00, 10, 03, 45, 00, 89, 45, 30, C7, 45, 14, 00, 00, 00, 00, C7, 45, 18, 00, 00, 00, 00, C7, 45, 1C, 00, 00, 00, 00, 8B, 45, 14, FF, 45, 14, 66, 33, C9, 8A, 8C, 03, FF, 4B, 00, 10, 84, C9, 74, 7A, 8B, 45, 1C, 66, 01, 4D, 1C, 03, C3, 05, 13, 4C, 00, 10, 50, 8B, 45, 2C, FF, 10, 85, C0, 0F, 84, 5E, 02, 00, 00, 89, 45, 10, 8B, 45, 1C, 03, C3...
 
[+]

Entropy:
5.2398

Packer / compiler:
ASPack v1.08.04

Code size:
29.5 KB (30,208 bytes)

Remove uninstall.exe - Powered by Reason Core Security