__uninstall_.exe

JumpyApps

The file is a bundle distribution and utilizes the installCore download manager to distribute this potentially unwanted software. The application __uninstall_.exe by JumpyApps has been detected as adware by 7 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. It is also typically executed from the user's temporary directory.
Publisher:
JumpyApps  (signed and verified)

MD5:
a7266001bff18a53279ab4a52ad63bb4

SHA-1:
eadebeccdcdd7b0bf5e03171228b1a0221beccbc

SHA-256:
c7664eeacf96c26dea1f90b18b6f99bab7e3db47fdf5fb0bfb151b543b738eb0

Scanner detections:
7 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/25/2024 12:52:52 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/InstallCore.IX (variant)
8.9356

Qihoo 360 Security
HEUR/Malware.QVM20.Gen
1.0.0.1015

Reason Heuristics
PUP.JumpyApps.M
14.8.7.18

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.14408

Vba32 AntiVirus
3.12.24.3

VIPRE Antivirus
InstallCore
25956

File size:
651 KB (666,600 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\__uninstall_.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/18/2013 4:00:00 AM

Valid to:
2/19/2014 3:59:59 AM

Subject:
CN=JumpyApps, O=JumpyApps, STREET=63 Rothschild Blvd., L=Tel Aviv, S=NA, PostalCode=65785, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
6DB423F9C6473168CF486AAF112EDD5C

File PE Metadata
Compilation timestamp:
6/20/1992 2:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:CYDdyyZWGnqFVQCoPMY2qH/GbeIggZQXwbguUWYCyt9QukKwet8iUt4BSMk:CS5qPQCoPD2qHeqGmCgaY/QukKwGI

Entry address:
0x75F8

Entry point:
55, 8B, EC, 83, C4, F4, B8, C8, 75, 40, 00, E8, 98, CF, FF, FF, B8, 64, 00, 00, 00, E8, 02, B0, FF, FF, 3D, E8, 03, 00, 00, 75, 05, E8, 06, FF, FF, FF, E8, E5, B8, FF, FF, 90, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
26 KB (26,624 bytes)

Remove __uninstall_.exe - Powered by Reason Core Security