__uninstall_.exe

JumpyApps

The file is a bundle distribution and utilizes the installCore download manager to distribute this potentially unwanted software. The application __uninstall_.exe by JumpyApps has been detected as adware by 7 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.flvplayerapp.com.
Publisher:
JumpyApps  (signed and verified)

MD5:
866e4ab9b167bdba67b7522f1c9f373c

SHA-1:
23ea12c3766dc405d159c05b14e308df1358d04a

SHA-256:
451f05da5119a43ce986f6c4f07afd9a5da6b6671717ae6633c0e0acc7525623

Scanner detections:
7 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/27/2024 4:09:15 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
7.11.144.160

Baidu Antivirus
Adware.Win32.InstallCore
4.0.3.14421

Dr.Web
Trojan.Packed.25903
9.0.1.0111

ESET NOD32
Win32/InstallCore.JN (variant)
8.9704

Norman
Kryptik.CDMO
11.20140421

Reason Heuristics
PUP.JumpyApps.M
14.8.7.18

VIPRE Antivirus
InstallCore
28466

File size:
1.2 MB (1,286,592 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Nullsoft Install System)

Common path:
C:\Program Files\flvplayer\uninstall\__uninstall_.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/18/2013 7:00:00 AM

Valid to:
2/19/2014 6:59:59 AM

Subject:
CN=JumpyApps, O=JumpyApps, STREET=63 Rothschild Blvd., L=Tel Aviv, S=NA, PostalCode=65785, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
6DB423F9C6473168CF486AAF112EDD5C

File PE Metadata
Compilation timestamp:
5/20/2013 6:53:02 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:WiSeqFluk8pt59M9P67KQq5PcfUgd9belgnG895umqKCoZ+UF:cyuQqtE9Kli95uMt

Entry address:
0x310B

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 1C, C7, 44, 24, 10, 90, 91, 40, 00, 89, 5C, 24, 18, C6, 44, 24, 14, 20, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 8C, 72, 40, 00, 6A, 08, A3, 58, EC, 42, 00, E8, 6E, 2D, 00, 00, A3, A4, EB, 42, 00, 53, 8D, 44, 24, 38, 68, 60, 01, 00, 00, 50, 53, 68, E0, 8F, 42, 00, FF, 15, 64, 71, 40, 00, 68, 80, 91, 40, 00, 68, A0, E3, 42, 00, E8, 18, 2A, 00, 00, FF, 15, 1C, 71, 40, 00, BD, 00, 40, 43, 00, 50, 55, E8, 06, 2A...
 
[+]

Entropy:
7.0026

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file __uninstall_.exe has been seen being distributed by the following URL.

Remove __uninstall_.exe - Powered by Reason Core Security