uninstall.exe

Piffle LLC

This is a self-extracting archive and installer. This is installed with Enigma64. The file has been seen being downloaded from madebysource.com.
Publisher:
Piffle LLC  (signed and verified)

MD5:
8a82493396e73fd93208e13ae64edb9a

SHA-1:
33bd1c7c2f871f270f9301978baac68a1a030ed4

SHA-256:
74cd9e00a87550030e3de5c4b83a4c54592512e136d57e78a85e0a4c4ae2db9f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/29/2024 5:52:31 PM UTC  (today)

File size:
23.8 MB (24,903,896 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\ProgramData\application data\getenigma64.com\uninstall.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
3/21/2013 8:21:24 AM

Valid to:
3/20/2015 12:49:45 PM

Subject:
CN=Piffle LLC, O=Piffle LLC, L=New York, S=NY, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
079A342FF699ED

File PE Metadata
Compilation timestamp:
4/25/2014 11:42:49 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
393216:ZC7ybYIYZWgIP0FjGc3ij2ZrMKykQgRdFwbjnXumoCirIGMgOJsv6tWKFdu9Cvx:ZuFVjFkSlVwbz3cax

Entry address:
0x12A0

Entry point:
55, 89, E5, 83, EC, 08, C7, 04, 24, 02, 00, 00, 00, FF, 15, D4, 8C, BB, 01, E8, 98, FE, FF, FF, 90, 8D, B4, 26, 00, 00, 00, 00, 55, 8B, 0D, 64, 8D, BB, 01, 89, E5, 5D, FF, E1, 8D, 74, 26, 00, 55, 8B, 0D, 18, 8D, BB, 01, 89, E5, 5D, FF, E1, 90, 90, 90, 90, 55, 89, E5, 83, EC, 18, C7, 04, 24, 00, E0, 97, 00, E8, 12, 7F, 4D, 00, 52, 85, C0, 74, 65, C7, 44, 24, 04, 13, E0, 97, 00, 89, 04, 24, E8, 05, 7F, 4D, 00, 83, EC, 08, 85, C0, 74, 11, C7, 44, 24, 04, 08, 20, BB, 01, C7, 04, 24, E0, E5, BA, 01, FF, D0, 8B...
 
[+]

Entropy:
7.5878

Packer / compiler:
MingWin32

Code size:
5.5 MB (5,719,552 bytes)

The file uninstall.exe has been discovered within the following program.

Enigma64  by Piffle
About 1% of users remove it
 
Powered by Should I Remove It?

The file uninstall.exe has been seen being distributed by the following URL.

Scan uninstall.exe - Powered by Reason Core Security