MBTIVuninstall.EXE

MBTIVuninstall 응용 프로그램

Rainnd Inc

The application MBTIVuninstall.EXE, “MBTIVuninstall MFC 응용 프로그램” by Rainnd Inc has been detected as a potentially unwanted program by 21 anti-malware scanners. This is the uninstaller utility registered in the Windows Control Panel for the program Windows Desktop MBT Icons Ver 6.1.1.4.
Publisher:
Rainnd Inc  (signed and verified)

Product:
MBTIVuninstall 응용 프로그램

Description:
MBTIVuninstall MFC 응용 프로그램

Version:
1, 0, 0, 1

MD5:
d41fd4b0b9b99ed735466d1739222568

SHA-1:
6571639d2dae9ccc4154e0dbefdff2131db42892

SHA-256:
8adff607ad3dd6d13f23aaccb9bcada41b085dc19f8385a8bf2b44b62314a83b

Scanner detections:
21 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 2:26:23 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Agent.ACU
69

AegisLab AV Signature
Backdoor.W32.Runagry.lEMt
2.1.4+

Avira AntiVirus
TR/Agent.bta
8.3.3.4

Arcabit
Application.Agent.ACU
1.0.0.788

avast!
Win32:Adware-gen [Adw]
2014.9-161126

AVG
Luhe.Fiha.A
2017.0.2547

Baidu Antivirus
Win32.Trojan.WisdomEyes.16070401.9500
4.0.3.161126

Bitdefender
Application.Agent.ACU
1.0.20.1655

Dr.Web
BackDoor.Siggen2.824
9.0.1.0331

ESET NOD32
Win32/Adware.CloverPlus.AB (variant)
10.14503

F-Secure
Application.Agent.ACU
11.2016-26-11_7

G Data
Application.Agent.ACU
16.11.25

IKARUS anti.virus
not-a-virus:AdWare.CloverPlus
t3scan.2.1.16.0

K7 AntiVirus
Adware
13.245.21626

McAfee
PUP-XAK-XZ
5600.6203

MicroWorld eScan
Application.Agent.ACU
17.0.0.993

NANO AntiVirus
Trojan.Win32.Siggen2.egjrsj
1.0.70.13328

Qihoo 360 Security
HEUR/QVM07.1.0000.Malware.Gen
1.0.0.1120

Rising Antivirus
Malware.Generic!Ef1HGghc4AG@5 (thunder)
23.00.65.161124

SUPERAntiSpyware
Adware.CloverPlus/Variant
8751

Zillya! Antivirus
Adware.CloverPlus.Win32.397
2.0.0.3134

File size:
103.1 KB (105,568 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright (C) 2009

Original file name:
MBTIVuninstall.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\windows mbt icons\mbtivuninstall.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
10/20/2016 5:12:38 PM

Valid to:
9/27/2017 11:50:38 PM

Subject:
CN=Rainnd Inc, O=Rainnd Inc, L=New York, S=New York, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
277FB6AB1157A64B

File PE Metadata
Compilation timestamp:
11/24/2016 5:02:21 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:RFb8X5AsQop9On6SwHszMJ6NWDt9DmgQvy+e:bb8AEOPwHYCeOt9DmgQvy+e

Entry address:
0xF4D4

Entry point:
55, 8B, EC, 6A, FF, 68, B0, 17, 41, 00, 68, 60, F6, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 18, 13, 41, 00, 59, 83, 0D, 50, 5A, 41, 00, FF, 83, 0D, 54, 5A, 41, 00, FF, FF, 15, 1C, 13, 41, 00, 8B, 0D, 44, 5A, 41, 00, 89, 08, FF, 15, 20, 13, 41, 00, 8B, 0D, 40, 5A, 41, 00, 89, 08, A1, 24, 13, 41, 00, 8B, 00, A3, 4C, 5A, 41, 00, E8, 1C, 01, 00, 00, 39, 1D, A8, 58, 41, 00, 75, 0C, 68, 5C, F6, 40, 00, FF, 15, 28, 13...
 
[+]

Entropy:
6.1353

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
64 KB (65,536 bytes)

Program Uninstaller
Program name:
Windows Desktop MBT Icons Ver 6.1.1.4

Uninstall string:
C:\users\{user}\appdata\local\windows mbt icons\mbtivuninstall.exe


Remove MBTIVuninstall.EXE - Powered by Reason Core Security