uninstall.exe

Digit Network (Extreme White Limited)

The application uninstall.exe by Digit Network (Extreme White Limited) has been detected as adware by 17 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. This is the uninstaller utility registered in the Windows Control Panel for the program Cinem Plus 2.4cV25.05 by Cinema Plus ProV25.05. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Digit Network (Extreme White Limited)  (signed and verified)

MD5:
06123607e28847f808d8226f87123e06

SHA-1:
507b8c09607ee9c6f34a8da0f656b876035442b5

SHA-256:
3d673bcd0e91fc75dfa2996859f11a01a402a01bec7494e9b261aa1f566702f3

Scanner detections:
17 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
5/10/2024 11:49:56 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Application.Heur.hqX@lO@DvSdi
5575765

AhnLab V3 Security
PUP/Win32.CrossRider
2015.05.29

Avira AntiVirus
ADWARE/CrossRider.A.6348
8.3.1.6

AVG
Crossrider
2016.0.3095

Bitdefender
Gen:Application.Heur.hqX@lO@DvSdi
1.0.20.740

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.InstallCore.GIFI
22258

Emsisoft Anti-Malware
Gen:Application.Heur.hqX@lO@DvSdi
10.0.0.5366

F-Secure
Riskware.Gen:Application.Heur.hqX@lO@DvSdi
5.14.151

G Data
Gen:Application.Heur.hqX@lO@DvSdi
15.5.25

K7 AntiVirus
Unwanted-Program
13.204.16062

Malwarebytes
v2015.05.28.05

MicroWorld eScan
Gen:Application.Heur.hqX@lO@DvSdi
16.0.0.444

Qihoo 360 Security
Win32/Virus.Adware.9b6
1.0.0.1015

Reason Heuristics
PUP.ExtremeWhite.Installer
15.5.28.13

Rising Antivirus
PE:Malware.Adload!6.1D9D
23.00.65.15526

VIPRE Antivirus
Threat.4150696
40552

File size:
115.6 KB (118,352 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\cinem plus 2.4cv25.05\uninstall.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
4/15/2015 12:00:00 AM

Valid to:
4/14/2016 11:59:59 PM

Subject:
CN=Digit Network (Extreme White Limited), O=Digit Network (Extreme White Limited), STREET=Tassou Papadopulu 6 (flat/office 22), L=Nicosia, S=Agios Dometios, PostalCode=2373, C=CY

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F39F5E5096779B72822CF8381166A432

File PE Metadata
Compilation timestamp:
5/25/2015 1:04:22 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
1536:3sKHUG/A04elTsuP85p9RsRhn7rMy0xxPxFclZsWjcdCBwsE0vYS:YGoSPopovnYpMmCmsE0vYS

Entry address:
0x8B83

Entry point:
E8, 99, 66, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, C8, B2, 41, 00, E8, 27, 0A, 00, 00, E8, 41, 3C, 00, 00, 0F, B7, F0, 6A, 02, E8, 2C, 66, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 0D, 60, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
82.5 KB (84,480 bytes)

Program Uninstaller
Program name:
Cinem Plus 2.4cV25.05

Display publisher:
Cinema Plus ProV25.05

Display version:
1.36.01.22

Uninstall string:
C:\Program Files\Cinem Plus 2.4cV25.05\Uninstall.exe /fcp=1 /runexe='C:\Program Files\Cinem Plus 2.4cV25.05\UninstallBrw.exe' /url='http://notif.lockmaprack.com/notf_sys/index.html' /brwtype='uni' /on


Remove uninstall.exe - Powered by Reason Core Security