uninstall.exe

PHRASEFINDER

This is part of the InfoAtoms browser extension which will display variopus forms of advertising in the web browser by injecting new ads such as banner, text-links and search results. The application uninstall.exe, “Phrase Finder Setup” by PHRASEFINDER has been detected as adware by 3 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is the uninstaller utility registered in the Windows Control Panel for the program Phrase Finder 1.10.0.12 by Phrase Finder.
Publisher:
Phrase Finder  (signed by PHRASEFINDER)

Product:
Phrase Finder

Description:
Phrase Finder Setup

Version:
1.10.0.12

MD5:
e2d0fc2b89968ea6cdfb59dbacb1f663

SHA-1:
cafe390d17f2d498e0838a1fef1b860ddbacf333

Scanner detections:
3 / 68

Status:
Adware

Analysis date:
12/25/2024 12:49:59 AM UTC  (today)

Scan engine
Detection
Engine version

Malwarebytes
PUP.Optional.PhraseFinder.A
v2015.04.01.06

Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.Installer.InfoAtoms
15.4.1.7

File size:
307.3 KB (314,696 bytes)

Product version:
1.10.0.12

Copyright:
(c) 2014 Phrase Finder

Original file name:
phrasefinder-setup.exe

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\Program Files\phrasefinder_1.10.0.12\uninstall.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
9/4/2014 10:45:11 PM

Valid to:
9/4/2016 8:20:25 PM

Subject:
E=support@phrasefinderapp.com, CN=PHRASEFINDER, O=PHRASEFINDER, L=Dover, S=DE, C=US

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112137C4F7456ECE3D7C3EA998E1558D1585

File PE Metadata
Compilation timestamp:
12/5/2009 11:52:06 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:oSg3GvJETJH3XxvC/inva4TsaeeZRhHpmobBPg8S0x:lxaJHHminvaieMhHplPPTx

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 6F, 44, 00, E8, 09, 2C, 00, 00, A3, A4, 6E, 44, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, 9C, 42, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 2E, 44, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, F0, 46, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

Program Uninstaller
Program name:
Phrase Finder 1.10.0.12

Display publisher:
Phrase Finder

Display version:
1.10.0.12

Uninstall string:
H:\Archivos de programa\PhraseFinder_1.10.0.12\Uninstall.exe


Remove uninstall.exe - Powered by Reason Core Security