uninstall.exe

Media Saver

Macte! Labs, Inc.

The application uninstall.exe by Macte! Labs has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is the uninstaller utility registered in the Windows Control Panel for the program Media Saver by Macte! Labs.
Publisher:
Macte! Labs  (signed by Macte! Labs, Inc.)

Product:
Media Saver

Version:
1.0.3.36

MD5:
6487c30045cede4e39e389ad7f73646e

SHA-1:
90f597a80abe22bc64f610c60f2f3f583f05ec38

SHA-256:
6f60400eac7fd618791041d336658dbb54722eba26926909c05dbd3440692d1f

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/26/2024 5:04:05 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.2.17.23

File size:
3.8 MB (4,023,864 bytes)

Product version:
1.0.3.36

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\Program Files\media saver\uninstall.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
7/23/2013 2:00:00 AM

Valid to:
10/4/2015 1:59:59 AM

Subject:
CN="Macte! Labs, Inc.", O="Macte! Labs, Inc.", L=Vancouver, S=British Columbia, C=CA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
2072154B981EC5FD7991B0C51744D0B3

File PE Metadata
Compilation timestamp:
2/24/2012 9:20:04 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x38AF

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 68, A2, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 90, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 90, 40, 00, 55, FF, 15, C0, 92, 40, 00, 6A, 08, A3, 98, EB, 47, 00, E8, 36, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, EA, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 64, A2, 40, 00, FF, 15, 84, 91, 40, 00, 68, 4C, A2, 40, 00, 68, A0, 6A, 47, 00, E8, 18, 27, 00, 00, FF, 15, B0, 90, 40, 00, 50, BF, A0, F0, 4C, 00, 57, E8, 06, 27, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
29 KB (29,696 bytes)

Program Uninstaller
Program name:
Media Saver

Display publisher:
Macte! Labs

Display version:
1.0.3.36

Uninstall string:
C:\Program Files (x86)\Media Saver\uninstall.exe


Remove uninstall.exe - Powered by Reason Core Security