winuninstaller_setup.exe

Special Uninstaller

Ideakee Inc

The application winuninstaller_setup.exe, “Special Uninstaller Setup ” by Ideakee Inc has been detected as adware by 3 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from www.windowsuninstaller.org and multiple other hosts.
Publisher:
http://www.specialuninstaller.com/   (signed by Ideakee Inc)

Product:
Special Uninstaller

Description:
Special Uninstaller Setup

MD5:
6471171657cc04ec282ed9dfb2d44896

SHA-1:
87bfe4fe12a58b7514d8536cfe877d19f8cfe9e0

SHA-256:
1b4c70007de226b524b5472c765d48c38fbe0c229a381874e9506754ae08f78e

Scanner detections:
3 / 68

Status:
Adware

Analysis date:
4/25/2024 11:07:37 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Dr.Web
Program.Unwanted.157
9.0.1.049

Qihoo 360 Security
Malware.QVM06.Gen
1.0.0.1015

Reason Heuristics
PUP.Installer.Ideakee
15.2.18.12

File size:
4.5 MB (4,700,968 bytes)

Product version:
3.0

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\winuninstaller_setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
10/10/2013 6:00:00 PM

Valid to:
10/10/2016 5:59:59 PM

Subject:
CN=Ideakee Inc, O=Ideakee Inc, STREET="1104# Asphodel Pavilion,Hengxiang Garden 18 LIjiangRoad", L=Guilin, S=Guangxi, PostalCode=541004, C=CN

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00BFB37ABE3F235073942F877A67382940

File PE Metadata
Compilation timestamp:
7/9/2014 1:58:13 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:1Z1rdFp/xuZOzxHFPzxtLZOsIj2NosJCtAzOeP3z/9EidNLgLM:1ZR3p3zP9blIKlCtAXr95P

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 2C, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 16, D8, FF, FF, E8, 65, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 2B, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 50, 86...
 
[+]

Entropy:
7.9907

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file winuninstaller_setup.exe has been seen being distributed by the following 2 URLs.

Remove winuninstaller_setup.exe - Powered by Reason Core Security