Uninstall.exe

Picexa Viewer

Taiwan Shui Mu Chih Ching Technology Limited

The application Uninstall.exe by Taiwan Shui Mu Chih Ching Technology Limited has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. This file is typically installed with the program Picexa by Taiwan Shui Mu Chih Ching Technology Limited.. It is also typically executed from the user's temporary directory.
Publisher:

Product:
Picexa Viewer

Version:
2.1.78.378

MD5:
03da757196942d4d7c25c446e5456409

SHA-1:
16c549f03490a46470b1f8111db270c462f25a77

SHA-256:
b7bed4de9ab08ece155d68b59a97ab6bc660e1ce114f02dd8c39a137b9deb54a

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/23/2024 10:04:58 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Thinknice (M)
17.2.11.8

File size:
1.4 MB (1,513,096 bytes)

Product version:
2.1.78.378

Copyright:
Copyright (c)Taiwan Shui Mu Chih Ching Technology Limited. All Rights Reserved.

Original file name:
Uninstall.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\uninstall.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
3/6/2015 7:19:12 AM

Valid to:
3/4/2016 10:26:37 AM

Subject:
CN=Taiwan Shui Mu Chih Ching Technology Limited, O=Taiwan Shui Mu Chih Ching Technology Limited, L=Taipei City, S=Taiwan, C=TW

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112127474DE010DA49D31D0EE8193EAC2D0E

File PE Metadata
Compilation timestamp:
12/18/2015 7:21:10 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

Entry address:
0xC1B25

Entry point:
E8, 8F, C6, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, FF, 75, 0C, 6A, 00, FF, 75, 08, 68, 35, 9C, 4C, 00, E8, 05, 00, 00, 00, 83, C4, 10, 5D, C3, 55, 8B, EC, 83, EC, 20, 57, 6A, 07, 33, D2, 59, 33, C0, 8D, 7D, E4, 89, 55, E0, F3, AB, 5F, 39, 45, 0C, 75, 15, E8, 36, 14, 00, 00, C7, 00, 16, 00, 00, 00, E8, 38, 7F, 00, 00, 83, C8, FF, C9, C3, FF, 75, 14, 8D, 45, E0, FF, 75, 10, C7, 45, E4, FF, FF, FF, 7F, FF, 75, 0C, C7, 45, EC, 42, 00, 00, 00, 50, 89, 55, E8, 89, 55, E0, FF, 55, 08, 83, C4, 10, C9, C3, 53, 8B...
 
[+]

Code size:
961 KB (984,064 bytes)

The file Uninstall.exe has been discovered within the following program.

Picexa  by Taiwan Shui Mu Chih Ching Technology Limited.
About 2% of users remove it
 
Powered by Should I Remove It?

Remove Uninstall.exe - Powered by Reason Core Security