Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
- Fraudulent Security Program
- Worm
- Malicious Software
File Behavior
UNINST.EXE has been seen to perform the following behavior:
- This process creates other processes on disk
- This Process Deletes Other Processes From Disk
- Executes Processes stored in Temporary Folders
- Can communicate with other computer systems using HTTP protocols
- Executes a Process
- Writes to another Process's Virtual Memory (Process Hijacking)
- Terminates Processes
- Adds a Registry Key (RUN) to auto start Programs on system start up
- Creates new file extentions so that Internet Explorer will automatically open and potentially execute additional file types
- Creates a Toolbar Extension for Internet Explorer
- Creation and Registration of a Browser Helper Object in Internet Explorer
- Registers a Dynamic Link Library File
- The Process is packed and/or encrypted using a software packing process
- The Process is polymorphic and can change its structure
- Uses rootkit techniques to conceal its presence, interrogation or removal
UNINST.EXE has been the subject of the following behavior:
- Created as a process on disk
- Executed as a Process
- Executed from Temporary Folders
- Deleted as a process from disk
- Has code inserted into its Virtual Memory space by other programs
- Copied to multiple locations on the system
- Terminated as a Process
Country Of Origin
The filename UNINST.EXE was first seen on May 8 2007 in the following geographical regions of the Prevx community:
- The UNITED STATES on May 8 2007
- GERMANY on May 8 2007
- URUGUAY on May 31 2007
- ROMANIA on May 31 2007
- SPAIN on Jun 5 2007
- SINGAPORE on Jun 5 2007
- SLOVENIA on Oct 23 2007
- The UNITED KINGDOM on Oct 23 2007
- FRANCE on Oct 4 2008
- The EUROPEAN UNION on Sep 23 2009
- NETHERLANDS on Sep 23 2009
- ISRAEL on Nov 21 2009
File Name Aliases
UNINST.EXE can also use the following file names:
- SPINSTALL.EXE
- M2|UNINST.EXE
- $RKN1MGK.EXE
- AU_.EXE
- ADVERT
- BU_.EXE
- CU_.EXE
- DU_.EXE
- EU_.EXE
- FU_.EXE
- GU_.EXE
- HU_.EXE
- IU_.EXE
- JU_.EXE
- KU_.EXE
- LU_.EXE
- MU_.EXE
- NU_.EXE
- OU_.EXE
- PU_.EXE
- QU_.EXE
- RU_.EXE
- SU_.EXE
- TU_.EXE
- UU_.EXE
- VU_.EXE
- WU_.EXE
- XU_.EXE
- YU_.EXE
- ZU_.EXE
- 53463908.SVD
Filesizes
The following file size has been seen:
- 80,864 bytes
- 90,340 bytes
- 51,751 bytes
- 57,792 bytes
- 41,221 bytes
- 432,640 bytes
- 39,018 bytes
- 15,360 bytes
- 118,807 bytes
File Type
The filename UNINST.EXE refers to many versions of an executable program.
File Activity
One or more files with the name UNINST.EXE creates, deletes, copies or moves the following files and folders:
- Deletes c:\docume~1\user\locals~1\temp\nsj7.tmp
- Creates c:\docume~1\user\locals~1\temp\nsz9.tmp
- Deletes c:\docume~1\user\locals~1\temp\~nsu.tmp\Au_.exe
- Deletes c:\docume~1\user\locals~1\temp\~nsu.tmp\Bu_.exe
- Deletes c:\docume~1\user\locals~1\temp\~nsu.tmp\Cu_.exe
- Deletes c:\docume~1\user\locals~1\temp\~nsu.tmp\Du_.exe
- Deletes c:\docume~1\user\locals~1\temp\~nsu.tmp\Eu_.exe
- Deletes c:\docume~1\user\locals~1\temp\~nsu.tmp\Fu_.exe
- Deletes c:\docume~1\user\locals~1\temp\~nsu.tmp\Gu_.exe
- Deletes c:\docume~1\user\locals~1\temp\~nsu.tmp\Hu_.exe
- Deletes c:\docume~1\user\locals~1\temp\~nsu.tmp\Iu_.exe
- Deletes c:\docume~1\user\locals~1\temp\~nsu.tmp\Ju_.exe
- Deletes c:\docume~1\user\locals~1\temp\~nsu.tmp\Ku_.exe
- Deletes c:\docume~1\user\locals~1\temp\~nsu.tmp\Lu_.exe
- Deletes c:\docume~1\user\locals~1\temp\~nsu.tmp\Mu_.exe
- Deletes c:\docume~1\user\locals~1\temp\~nsu.tmp\Nu_.exe
- Deletes c:\docume~1\user\locals~1\temp\~nsu.tmp\Ou_.exe
- Deletes c:\docume~1\user\locals~1\temp\~nsu.tmp\Pu_.exe
- Deletes c:\docume~1\user\locals~1\temp\~nsu.tmp\Qu_.exe
- Deletes c:\docume~1\user\locals~1\temp\~nsu.tmp\Ru_.exe
- Deletes c:\docume~1\user\locals~1\temp\~nsu.tmp\Su_.exe
- Deletes c:\docume~1\user\locals~1\temp\~nsu.tmp\Tu_.exe
- Deletes c:\docume~1\user\locals~1\temp\~nsu.tmp\Uu_.exe
- Deletes c:\docume~1\user\locals~1\temp\~nsu.tmp\Vu_.exe
- Deletes c:\docume~1\user\locals~1\temp\~nsu.tmp\Wu_.exe
- Deletes c:\docume~1\user\locals~1\temp\~nsu.tmp\Xu_.exe
- Deletes c:\docume~1\user\locals~1\temp\~nsu.tmp\Yu_.exe
- Deletes c:\docume~1\user\locals~1\temp\~nsu.tmp\Zu_.exe
- Deletes c:\docume~1\user\locals~1\temp\nsaE.tmp
- Creates c:\docume~1\user\locals~1\temp\nsq10.tmp
- Deletes c:\docume~1\user\locals~1\temp\nsl12.tmp
- Creates c:\docume~1\user\locals~1\temp\nsl12.tmp\System.dll
- Creates c:\docume~1\user\locals~1\temp\nsl12.tmp\nsProcess.dll
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.