uninstall.exe

Sailor Project

This potentially unwanted Internet browser extension is built upon and distributed using the free Crossrider platform and will deliver advertisements to the web browser in various formats such as banner, text hyper-links, inline text and transitional ads. The application uninstall.exe by Sailor Project has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. This is the uninstaller utility registered in the Windows Control Panel for the program PlusVid by Phoenix Media. It is part of the Brightcircle group of web-extensions that inject advertisements in the browser.
Publisher:
Sailor Project  (signed and verified)

MD5:
5d4e694fdc01b22d50efcf8a59c622f4

SHA-1:
5aa47fbad334c045f2f9baee61cdb32562fe074e

SHA-256:
9b3c9a1d61ef728fe770c05b9f0ea6f3d33195be3141a5018c1831023a395db9

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/25/2020 7:13:18 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Brightcircle (M)
17.3.11.16

File size:
103.9 KB (106,344 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\plusvid\uninstall.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/17/2014 9:00:00 PM

Valid to:
7/18/2015 8:59:59 PM

Subject:
CN=Sailor Project, O=Sailor Project, STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Cyprus, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
47C5F145C734CD3D086C0A102176F0A1

File PE Metadata
Compilation timestamp:
7/21/2014 7:07:40 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

Entry address:
0x5D12

Entry point:
E8, 3B, 66, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, F8, 7F, 41, 00, E8, 28, 0A, 00, 00, E8, 46, 33, 00, 00, 0F, B7, F0, 6A, 02, E8, CE, 65, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, AF, 5F, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
69.5 KB (71,168 bytes)

Program Uninstaller
Program name:
PlusVid

Display publisher:
Phoenix Media

Display version:
1.34.7.1

Uninstall string:
C:\Program Files\PlusVid\Uninstall.exe /fcp=1


Remove uninstall.exe - Powered by Reason Core Security