uninstall19122714.exe

YourFile Downloader

Via Advertising Group Limited

This is the Via Advertising bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application uninstall19122714.exe by Via Advertising Group Limited has been detected as adware by 13 anti-malware scanners. The program is a setup application that uses the YourFile Downloader installer. This is the uninstaller utility registered in the Windows Control Panel for the program Feature Update Service (YFD). It is also typically executed from the user's temporary directory.
Publisher:
http://yourfiledownloader.com  (signed by Via Advertising Group Limited)

Product:
YourFile Downloader

Version:
1, 0, 0, 293

MD5:
bc578f80d7ca21b21eb9afb978cf9a91

SHA-1:
6a4302f0f30da97e5ec97036e88ba7321aba8359

SHA-256:
b700a5e95cef73933d6b339153e8948a9b85a4db713cb710cec52f5eba762076

Scanner detections:
13 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/19/2024 7:32:49 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

Avira AntiVirus
APPL/Downloader.Gen
7.11.170.102

avast!
Win32:Downloader-UEO [PUP]
140813-1

AVG
Adware Generic_r.PF
2014.0.4015

Dr.Web
Adware.Downware.5658
9.0.1.05190

ESET NOD32
Win32/ExpressDownloader.I potentially unwanted application
7.0.302.0

G Data
Win32.Application.ExpressDownloader
14.9.24

IKARUS anti.virus
PUA.Expressdownloader
t3scan.1.7.5.0

Malwarebytes
PUP.Optional.YourFileDownloader
v2014.09.01.08

Reason Heuristics
PUP.ViaAdvertisingGroupLimited.R
14.9.1.19

Sophos
YourFile Downloader
4.98

VIPRE Antivirus
Threat.4758264
32210

Zillya! Antivirus
Trojan.Black.Win32.17778
2.0.0.1908

File size:
6.3 MB (6,601,256 bytes)

Product version:
1.0.0

Copyright:
Copyright http://yourfiledownloader.com (C) 2012

Original file name:
YourFile.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
YourFile Downloader

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\uninstall19122714.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
4/12/2013 1:00:00 AM

Valid to:
4/12/2016 12:59:59 AM

Subject:
CN=Via Advertising Group Limited, O=Via Advertising Group Limited, STREET=Boumpoulinas 11, L=Nicosia, S=Nicosia, PostalCode=1060, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00BABC309174F531C6762BBA466401FEAF

File PE Metadata
Compilation timestamp:
6/26/2014 4:43:02 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
98304:M3YFyqqT8k6mlnBdOt9EWJ4jfbYzfRa2kW6KH0q2UiLNLwUBfJk2n8l+O9:M3YFyqa8pZ9pJ4jTYzv08FiLyUZmvgO9

Entry address:
0x3FB97

Entry point:
E8, E8, F0, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, B8, 3B, 47, 00, E8, 23, 78, 00, 00, E8, 3A, 29, 00, 00, 0F, B7, F0, 6A, 02, E8, 7B, F0, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 73, B5, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
371 KB (379,904 bytes)

Program Uninstaller
Program name:
Feature Update Service (YFD)

Display version:
2.14.27

Uninstall string:
"C:\Program Files (x86)\YourFileDownloader Updater\uninstall.exe"


Remove uninstall19122714.exe - Powered by Reason Core Security