uninstall.exe

Sailor Project

This potentially unwanted Internet browser extension is built upon and distributed using the free Crossrider platform and will deliver advertisements to the web browser in various formats such as banner, text hyper-links, inline text and transitional ads. The application uninstall.exe by Sailor Project has been detected as adware by 32 anti-malware scanners. This is the uninstaller utility registered in the Windows Control Panel for the program Sense by Object Browser. This file is typically installed with the program Sense by Object Browser which is a potentially unwanted software program. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. It is distributed as part of the Brightcircle group of browser-extensions.
Publisher:
Sailor Project  (signed and verified)

MD5:
c0be0e1e9cef2e278030254498df7c35

SHA-1:
145772107f83014a949bcddf7496d49f5041ad0f

SHA-256:
9fc887a460a385d249a3dedf7dba4cdb8e6063bffbbc77962c26bc9d6ed13072

Scanner detections:
32 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars. Distributed through the Brightcircle investments brand.

Analysis date:
4/25/2024 3:04:13 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Application.Heur.fqX@lmw!lVdi
431

Agnitum Outpost
PUA.Toolbar.CrossRider
7.1.1

AhnLab V3 Security
PUP/Win32.CrossRider
2015.12.01

Avira AntiVirus
TR/Crypt.ZPACK.Gen2
7.11.30.172

Arcabit
Application.Heur.E1D92A
1.0.0.627

avast!
Win32:Crossrider-N [PUP]
151024-0

AVG
Toolbar.Crossrider.V
2016.0.2909

Baidu Antivirus
Adware.Win32.CrossAd
4.0.3.15121

Bitdefender
Gen:Application.Heur.fqX@lmw!lVdi
1.0.20.1675

Bkav FE
W32.HfsAdware
1.3.0.7383

Comodo Security
Application.Win32.InstallCore.GIFI
23688

Dr.Web
Trojan.Crossrider1.27036
9.0.1.05190

Emsisoft Anti-Malware
Gen:Application.Heur.fqX@lmw!lVdi
10.0.0.5366

ESET NOD32
Win32/Toolbar.CrossRider.AW potentially unwanted application
7.0.302.0

F-Prot
W32/S-ac71d174
v6.4.7.1.166

F-Secure
Riskware.Gen:Application.Heur.fqX@lmw!lVdi
5.15.21

G Data
Gen:Application.Heur.fqX@lmw!lVdi
15.12.25

K7 AntiVirus
Unwanted-Program
13.212.18014

Kaspersky
Trojan.NSIS.GoogUpdate
15.0.0.562

Malwarebytes
v2015.12.01.06

MicroWorld eScan
Gen:Application.Heur.fqX@lmw!lVdi
16.0.0.1005

NANO AntiVirus
Trojan.Win32.GoogUpdate.dedzce
0.30.26.4751

Norman
Gen:Application.Heur.fqX@lmw!lVdi
07.10.2015 03:16:12

nProtect
Trojan/W32.Agent.90984.B
15.11.30.01

Panda Antivirus
Trj/CI.A
15.12.01.06

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
1.0.0.1077

Quick Heal
PUA.Sailorproj.Gen
12.15.14.00

Reason Heuristics
PUP.SailorProject.J
14.8.13.23

Rising Antivirus
PE:Malware.Obscure!1.9C59 [F]
23.00.65.151129

SUPERAntiSpyware
PUP.CrossRider/Variant
9474

Vba32 AntiVirus
Trojan.GoogUpdate
3.12.26.4

Zillya! Antivirus
Trojan.GoogUpdate.Win32.1575
2.0.0.2539

File size:
88.9 KB (90,984 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\sense\uninstall.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/18/2014 1:00:00 AM

Valid to:
7/19/2015 12:59:59 AM

Subject:
CN=Sailor Project, O=Sailor Project, STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Cyprus, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
47C5F145C734CD3D086C0A102176F0A1

File PE Metadata
Compilation timestamp:
7/31/2014 11:03:56 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
1536:LFXZ1CqT3YhIOs+bRAF3ETn5cV20fsWjcde+pnVIB:RZ1CNaO3YWI20ge+pnVE

Entry address:
0x585E

Entry point:
E8, 6D, 5B, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 78, 3F, 41, 00, E8, 2C, 0A, 00, 00, E8, D8, 32, 00, 00, 0F, B7, F0, 6A, 02, E8, 00, 5B, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, E1, 54, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.2768

Code size:
55 KB (56,320 bytes)

Program Uninstaller
Program name:
Sense

Display publisher:
Object Browser

Display version:
1.34.7.29

Uninstall string:
C:\Program Files (x86)\Sense\Uninstall.exe /fcp=1


The file uninstall.exe has been discovered within the following program.

Sense  by Object Browser
Sense is a potentially unwanted web browser extension that will attempt to modify the user's home and search page settings as well as display advertisements in the browser. The software will attach to IE, Chrome and Firefox.
85% remove it
 
Powered by Should I Remove It?

Remove uninstall.exe - Powered by Reason Core Security