uninst.exe

DLNow Setup

Logixoft

The application uninst.exe by Logixoft has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. This is the uninstaller utility registered in the Windows Control Panel for the program DLNow 1.2 by Logixoft.
Publisher:
Logixoft  (signed and verified)

Product:
DLNow Setup

Version:
1.2.0.0

MD5:
27a6ff977c7e249b918f09258a39700d

SHA-1:
b0e5a1cf002ae6f7c52473f2172a192f3e7f5c72

SHA-256:
889348ea163ee78c010d6b5b9791ee8ea8e26380643f73e866606ac853ca1f51

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/25/2024 5:35:54 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.11.2.21

File size:
28 MB (29,396,136 bytes)

Product version:
1.2.0.0

Copyright:
Copyright (C) 2016 Logixoft

Original file name:
dlnow_setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\dlnow\uninst.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
4/26/2016 3:04:46 PM

Valid to:
4/27/2019 3:04:46 PM

Subject:
CN=Logixoft, O=Logixoft, S=Bretagne, C=FR

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112117D4A5842F3B784C81F4B86B98258AB4

File PE Metadata
Compilation timestamp:
8/17/2016 3:01:58 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
393216:yk+JBf3iC1quJk0f3CYpGgAmn/0V3sv7cIk/6vUinmz3r4Ykiwd7yn2dCclt8y:r+JF1quJP3nprnu8gfyDyDDrn2pt8y

Entry address:
0x7CCC

Entry point:
E8, 7B, 03, 00, 00, E9, 8E, FE, FF, FF, E9, 1C, 2D, 00, 00, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, 58, 00, 00, 00, C7, 06, F4, 44, 41, 00, 8B, C6, 5E, 5D, C2, 04, 00, 83, 61, 04, 00, 8B, C1, 83, 61, 08, 00, C7, 41, 04, FC, 44, 41, 00, C7, 01, F4, 44, 41, 00, C3, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, 25, 00, 00, 00, C7, 06, 10, 45, 41, 00, 8B, C6, 5E, 5D, C2, 04, 00, 83, 61, 04, 00, 8B, C1, 83, 61, 08, 00, C7, 41, 04, 18, 45, 41, 00, C7, 01, 10, 45, 41, 00, C3, 55, 8B, EC, 56, 8B, F1, 8D, 46, 04, C7, 06...
 
[+]

Entropy:
7.9850  (probably packed)

Code size:
73.5 KB (75,264 bytes)

Program Uninstaller
Program name:
DLNow 1.2

Display publisher:
Logixoft

Display version:
1.2

Uninstall string:
"C:\Program Files (x86)\DLNow\uninst.exe" /u


Remove uninst.exe - Powered by Reason Core Security