uninstall.exe

PHRASEFINDER

This is part of the InfoAtoms browser extension which will display variopus forms of advertising in the web browser by injecting new ads such as banner, text-links and search results. The application uninstall.exe, “Phrase Finder Setup” by PHRASEFINDER has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is the uninstaller utility registered in the Windows Control Panel for the program Phrase Finder 1.10.0.9 by Phrase Finder.
Publisher:
Phrase Finder  (signed by PHRASEFINDER)

Product:
Phrase Finder

Description:
Phrase Finder Setup

Version:
1.10.0.9

MD5:
faaea786a815ef674046ce0ed805c5b5

SHA-1:
1153a50011df553dfebe13ea4015b99191732265

SHA-256:
1ebd3f94beaa73c1362f6a7feb7ef08b385211e5c653ba2ce0e78d5e3a81f534

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/25/2024 12:38:24 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InfoAtoms.PHRASEFI.Installer (M)
16.5.31.9

File size:
307.3 KB (314,720 bytes)

Product version:
1.10.0.9

Copyright:
(c) 2014 Phrase Finder

Original file name:
phrasefinder-setup.exe

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\Program Files\phrasefinder_1.10.0.9\uninstall.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
9/5/2014 3:45:11 AM

Valid to:
9/5/2016 1:20:25 AM

Subject:
E=support@phrasefinderapp.com, CN=PHRASEFINDER, O=PHRASEFINDER, L=Dover, S=DE, C=US

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112137C4F7456ECE3D7C3EA998E1558D1585

File PE Metadata
Compilation timestamp:
12/6/2009 5:52:06 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:0Sg3G0htYYsELTQd2lEOFKv99Q+A03UE4Rj6h:xotNLLljEv9aJCp4E

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 6F, 44, 00, E8, 09, 2C, 00, 00, A3, A4, 6E, 44, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, 9C, 42, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 2E, 44, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, F0, 46, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
6.8905

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

Program Uninstaller
Program name:
Phrase Finder 1.10.0.9

Display publisher:
Phrase Finder

Display version:
1.10.0.9

Uninstall string:
C:\Program Files (x86)\PhraseFinder_1.10.0.9\Uninstall.exe


Remove uninstall.exe - Powered by Reason Core Security