uninstall.exe

FLV Player

Install Core

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application uninstall.exe, “FLV Player Installer” by Install Core has been detected as adware by 30 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from apps.foxtab.com.
Publisher:
FLV Player Technologies  (signed by Install Core)

Product:
FLV Player

Description:
FLV Player Installer

Version:
3.1.0.0

MD5:
af4b68f8c53a43377b35b55f6dea56c9

SHA-1:
f8760cadf57b7cb86dfce56c579135991d6f9d23

Scanner detections:
30 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/26/2024 6:16:54 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Graftor.27885
362

Agnitum Outpost
Adtool.InstallCore.Gen
7.1.1

AhnLab V3 Security
Packed/Win32.InstallCore
2013.08.25

Avira AntiVirus
7.11.98.18

avast!
Win32:InstallCore-F [PUP]
2014.9-160207

Bitdefender
Application.Generic.563271
1.0.20.190

Bkav FE
W32.HfsAdware
1.3.0.6379

Clam AntiVirus
W32.Adware.InstallCore-2
0.98/20520

Comodo Security
ApplicUnwnt.Win32.AdWare.InstallCore.0
16817

Dr.Web
Adware.InstallCore.20
9.0.1.038

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.27885
8.16.02.07.03

ESET NOD32
Win32/InstallCore.Gen
10.8724

Fortinet FortiGate
W32/InstallCore.gen
2/7/2016

F-Prot
W32/Agent.MC.gen
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Graftor
11.2016-07-02_1

G Data
Application.Generic.563271
16.2.22

K7 AntiVirus
Trojan
13.170.9377

Malwarebytes
Adware.Agent
v2016.02.07.03

MicroWorld eScan
Application.Generic.563271
17.0.0.114

NANO AntiVirus
Riskware.Win32.InstallCore.nyaof
0.28.6.63850

Norman
Adware.Generic.241742
11.20160207

nProtect
Trojan-Clicker/W32.Agent.559624
14.12.10.01

Reason Heuristics
PUP.installCore.FLVPlayerTechnologies.Installer (M)
16.2.7.15

Sophos
Install Core Installer
4.91

SUPERAntiSpyware
Trojan.Agent/Gen-InstallCore
9338

Trend Micro House Call
TROJ_GEN.R47H1BL
7.2.38

Trend Micro
HT_INSTALLCORE_BL210179.TOMC
10.465.07

Vba32 AntiVirus
BScope.Malware-Cryptor.Sinba.C
3.12.22.3

VIPRE Antivirus
InstallCore
20846

Zillya! Antivirus
Trojan.Genome.Win32.137604
2.0.0.2188

File size:
537.5 KB (550,408 bytes)

Product version:
3.1.0.0

Copyright:
Copyright © Instsaller

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore

Common path:
C:\Documents and Settings\{user}\Local settings\temp\{random}.tmp\uninstall.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
2/2/2011 1:00:00 AM

Valid to:
2/3/2012 12:59:59 AM

Subject:
CN=Install Core, O=Install Core, STREET=Nisim Aloni 21, L=Tel Aviv, S=Tel Aviv, PostalCode=62919, C=IL

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
2BCA6BFDAB7E5637BA8E7E9C6400CC75

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:PRnQJLBYXMsteShll7Qn7BEmB/4NYv+yz01ckK5JqBnMM34:PRQJ9YcirstB/8YPA1ck6sBMM34

Entry address:
0x10BA80

Entry point:
60, BE, 00, E0, 48, 00, 8D, BE, 00, 30, F7, FF, C7, 87, 10, E7, 0B, 00, 16, 1F, 3E, ED, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
504 KB (516,096 bytes)

The file uninstall.exe has been seen being distributed by the following URL.

Remove uninstall.exe - Powered by Reason Core Security