uninstaller.exe

Savepath Deals

The application uninstaller.exe by Savepath Deals has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. This is the uninstaller utility registered in the Windows Control Panel for the program PCBackup wizard by PCBackup wizard. This file is typically installed with the program PCBackup wizard.
Publisher:
Savepath Deals  (signed and verified)

MD5:
a99dff6ebb0ec8cb48c3e534b9971b77

SHA-1:
d9b3de046d11e66cbcdb95a7e06a3fa4a353263b

SHA-256:
0ef0cf8f74ccc9553534e24ed961cf8d3aaf1cfe0e629c7e7842206257b6fb27

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/27/2024 4:42:44 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Savepath.Installer (M)
16.4.15.19

File size:
295.4 KB (302,448 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\pcbackup wizard\uninstaller.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
6/10/2014 2:00:00 AM

Valid to:
6/10/2016 1:59:59 AM

Subject:
CN=Savepath Deals, O=Savepath Deals, STREET=8923 W Sunset blvd, L=West Hollywood, S=CA, PostalCode=90069, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
56EA9CE76728F55E8F87B7F0683773B7

File PE Metadata
Compilation timestamp:
4/15/2016 4:20:48 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
3072:IXWtF662dHt309icaZtigFWD5NmWH0gKuo6WIiZ3EGhTLvpfnXb1CDRSgX:IGtGdN309iPbM5NmW8uGlFLhfLgRSgX

Entry address:
0xD6ED

Entry point:
E8, E8, 05, 00, 00, E9, 80, FE, FF, FF, FF, 25, D8, 31, 42, 00, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, BC, 01, 43, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, F2, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 0F, 03, C1, 1B, C9, 0B, C1, 59, E9, EA, 06, 00, 00, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 07, 03, C1, 1B, C9, 0B, C1, 59, E9, D4, 06, 00, 00, CC...
 
[+]

Code size:
133 KB (136,192 bytes)

Program Uninstaller
Program name:
PCBackup wizard

Display publisher:
PCBackup wizard

Uninstall string:
"C:\Program Files (x86)\PCBackup Wizard\uninstaller.exe" /uninstall


The file uninstaller.exe has been discovered within the following program.

PCBackup wizard  by PCBackup wizard
support.pcbackupwizard.net
About 3% of users remove it
 
Powered by Should I Remove It?

Remove uninstaller.exe - Powered by Reason Core Security