uninstaller.exe

bProtector Installer

Performersoft LLC

This is the Performersoft setup installer. The application uninstaller.exe by Performersoft has been detected as a potentially unwanted program by 16 anti-malware scanners. The program is a setup application that uses the InstallBrain installer. The setup program bundles additional offers, mostly adware, using the InstallBrain installer, a pay-per-install monetization download manager. InstallBrain will also install a background updater service that will update any installed browser add-ons and plug-ins. The file has been seen being downloaded from www.bit89.com. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
bProtector  (signed by Performersoft LLC)

Product:
bProtector Installer

Description:
Install Module

Version:
2,3,507,38

MD5:
352c4d49be77547a4e16e448db3f27c3

SHA-1:
3ff142f22c18ec525c4ab408093dd13994677cfe

SHA-256:
b897d91fec600ea3a3c9f31b1b57bd02a4f854d1dad1998b2000dc0c5bd4b04c

Scanner detections:
16 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallBrain monetization platform from iBario to deliver bundled adware both search toolbars and PC optimizers from Performersoft.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/15/2024 6:14:00 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Trojan/Win32.Rotbrow
2014.02.08

Avira AntiVirus
APPL/InstallBrain.JU
7.11.130.16

AVG
MalSign.InstallBrain
2015.0.3508

Bkav FE
W32.Clod04d.Trojan
1.3.0.4924

Boost by Reason
Adware.Installer.Performersoft.L
2013.7.26.1

Clam AntiVirus
Win.Adware.BProtector
0.98/18355

Comodo Security
UnclassifiedMalware
17751

ESET NOD32
Win32/bProtector (variant)
7.9397

Fortinet FortiGate
W32/BProtector.A
4/11/2014

K7 AntiVirus
Trojan
13.175.11103

McAfee
Artemis!352C4D49BE77
5600.7270

Microsoft Security Essentials
TrojanDropper:Win32/Rotbrow.B
1.165.247.01

Panda Antivirus
PUP/Ibups
13.12.29.01

Reason Heuristics
PUP.Installer.Performersoft.L
14.8.7.22

Sophos
Mal/Generic-S
4.97

VIPRE Antivirus
Bprotector
26258

File size:
725.5 KB (742,944 bytes)

Product version:
2,3,507,38

Copyright:
Copyright 2011

File type:
Executable application (Win32 EXE)

Bundler/Installer:
InstallBrain

Language:
English (United States)

Common path:
C:\users\{user}\downloads\uninstaller.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
6/27/2012 1:28:03 PM

Valid to:
6/27/2015 1:28:03 PM

Subject:
CN=Performersoft LLC, O=Performersoft LLC, L=Beaverton, S=OR, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
07DAC5F73C6773

File PE Metadata
Compilation timestamp:
7/6/2012 6:20:32 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:XfrsUatzZeR4n6cKMpnS2y7mygjvzSmjp1XkXzioyYR8wOa0sgXBPM6TPoSWHP/U:vg/MR45KWS2ub81X0Z8w9C1KHP/eAjq

Entry address:
0x1F6410

Entry point:
60, BE, 00, 90, 55, 00, 8D, BE, 00, 80, EA, FF, C7, 87, D8, D7, 1B, 00, 42, EF, 87, 6B, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, FC, 4C, 1F, 00, 57, 83, C3, 04, 53, 68, 07, D4, 09, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 02, 00, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9...
 
[+]

Entropy:
7.8764  (probably packed)

Code size:
636 KB (651,264 bytes)

The file uninstaller.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

Remove uninstaller.exe - Powered by Reason Core Security