uninstaller.exe

Web United

This is the installer/setup program for a Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application uninstaller.exe by Web United has been detected as adware by 7 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is the uninstaller utility registered in the Windows Control Panel for the program Web United by Web United. This file is typically installed with the program Web United. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
Web United  (signed and verified)

Version:
2.0.5551.10055

MD5:
fbc0ef2da67ff20e1bafcab0e691b6cc

SHA-1:
93a7a23c7320971db4f6082de9e18c149352c5e2

SHA-256:
babe328aae176eb2304b96c5364858bc9b152e13c83f5da8daf4578ce54e5575

Scanner detections:
7 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/26/2024 7:16:51 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
BrowseFox
2016.0.3156

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.15328

Dr.Web
Trojan.Yontoo.1742
9.0.1.05190

ESET NOD32
Win32/BrowseFox.AH potentially unwanted application
7.0.302.0

herdProtect (fuzzy)
2015.7.3.8

Reason Heuristics
PUP.Installer.Yontoo
15.3.28.20

VIPRE Antivirus
Threat.4741131
38552

File size:
304 KB (311,296 bytes)

Product version:
2015.03.14

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\Program Files\web united\uninstaller.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
12/11/2014 5:00:00 PM

Valid to:
12/12/2015 4:59:59 PM

Subject:
CN=Web United, O=Web United, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
067F6E1F1D47FD4673122535E58BAC13

File PE Metadata
Compilation timestamp:
6/4/2014 5:58:31 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:MQ3WQUmdJbnM3DoFFjuvf/toNQ8dqLuJoU0U7Hd8CntQOHHM+HFFTjXdpNnT2UWD:YurbnM3D0Fw/tN8dkmLtpHHHrh7Vq

Entry address:
0x31E4

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, E0, 73, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, B8, 6C, 44, 00, E8, 1B, 25, 00, 00, 53, 68, 60, 01, 00, 00, A3, C0, 6B, 44, 00, 8D, 44, 24, 38, 50, 53, 68, DB, 73, 40, 00, FF, 15, 58, 71, 40, 00, 68, D0, 73, 40, 00, 68, C0, 2B, 44, 00, E8, 0D, 24, 00, 00, FF, 15, AC, 70, 40, 00, 50, BF, 00, F0, 46, 00, 57, E8, FB, 23, 00, 00...
 
[+]

Entropy:
7.9395

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

Program Uninstaller
Program name:
Web United

Display publisher:
Web United

Display version:
2.0.5551.10055

Uninstall string:
"C:\Program Files (x86)\Web United\uninstaller.exe"


The file uninstaller.exe has been discovered within the following program.

Web United  by Web United
www.mywebunitedapp.com/support
About 1% of users remove it
 
Powered by Should I Remove It?

Remove uninstaller.exe - Powered by Reason Core Security