techgileuninstall.exe

techgile

This is the installer/setup program for a Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application techgileuninstall.exe by techgile has been detected as adware by 4 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is the uninstaller utility registered in the Windows Control Panel for the program Techgile by Techgile. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
techgile  (signed and verified)

MD5:
8af94c6f6e255312e60c4f134d1d1e95

SHA-1:
de2d5d3ab8fa02fb1ca884cd6891d3a308c43ead

SHA-256:
f27603f51f203a2fe1e643dc4504b81147dcf203012a4dbc6909cd5b1c159917

Scanner detections:
4 / 68

Status:
Adware

Explanation:
This is the installer/uninstaller for the Yontoo branded (techgile) adware program. The main protgram is desigend to deliver advertisements to the user's web browser through injection.

Analysis date:
4/26/2024 5:34:02 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic
2015.0.3312

Baidu Antivirus
Adware.Win64.BrowseFox
4.0.3.141024

ESET NOD32
Win32/BrowseFox.C potentially unwanted application
7.0.302.0

VIPRE Antivirus
Threat.4741131
33706

File size:
254.6 KB (260,736 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\Program Files\techgile\techgileuninstall.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
9/4/2014 4:00:00 AM

Valid to:
9/5/2015 3:59:59 AM

Subject:
CN=techgile, O=techgile, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
73F8CC58517F3D5D8C50DFEA9B1C4816

File PE Metadata
Compilation timestamp:
12/6/2009 1:52:01 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:RZ+11wYXNy/1RWBT5y44sQeD8j5yIwZm/G/HcVZw:7Cs1s15yQ8zp/G/8o

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 6F, 44, 00, E8, F1, 2B, 00, 00, A3, 84, 6E, 44, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, 9C, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 2E, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, F0, 46, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.8684

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

Program Uninstaller
Program name:
Techgile

Display publisher:
Techgile

Display version:
2014.10.23.082637

Uninstall string:
C:\Program Files (x86)\Techgile\Techgileuninstall.exe


Remove techgileuninstall.exe - Powered by Reason Core Security