uninstall.exe

Big Water Applications, LLC

This is the uninstall module for the Injekt branded web browser extension program which injects advertising in the web browser as well as modifies the browser settings. The uninstaller is registered within Control Panel > Add/Remove Programs. The application uninstall.exe by Big Water Applications has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is the uninstaller utility registered in the Windows Control Panel for the program Spy Guard by Big Water Applications, LLC. This file is typically installed with the program Spy Guard by Big Water Applications, LLC which is a potentially unwanted software program.
Publisher:
Big Water Applications, LLC  (signed and verified)

MD5:
19e72d4daa924d4ff66766e7f156a48f

SHA-1:
81899452f95fccb8c006c07e7fd621620e8bad2d

SHA-256:
41beaa8a8e4b1e4babe678a2e0891679208640289bb8e05ddf1955bb33602569

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
4/25/2024 11:04:46 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Injekt.BigWaterApplications (M)
15.12.16.4

File size:
509.6 KB (521,832 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\ProgramData\spyguard\uninstall.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
4/21/2013 5:00:00 PM

Valid to:
4/22/2014 4:59:59 PM

Subject:
CN="Big Water Applications, LLC", O="Big Water Applications, LLC", STREET=640 Grand Ave, STREET=Suite E, L=Carlsbad, S=CA, PostalCode=92008, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0088DD6A4DF46D819C84B9E99D7A0530C5

File PE Metadata
Compilation timestamp:
1/22/2014 2:14:57 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:vmNddPK0G2DfYmxLW4j5n/XfaojxFSdysocghSep5:OHdPHV3jBCojxJnSeH

Entry address:
0x40763

Entry point:
E8, 7C, D3, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, EC, 44, 47, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, 60, 20, 47, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, EC, 44, 47, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7, 03, 00, 00, 00, 0F, 85, B8, 01, 00, 00, F7, C6, 03...
 
[+]

Entropy:
6.3273

Code size:
377.5 KB (386,560 bytes)

Program Uninstaller
Program name:
Spy Guard

Display publisher:
Big Water Applications, LLC

Display version:
2.6.58

Uninstall string:
C:\ProgramData\SpyGuard\uninstall.exe /kb=y /ic=1


The file uninstall.exe has been discovered within the following program.

Spy Guard  by Big Water Applications, LLC
This is an adware web browser extension. From the publisher's site: "In some cases, we may display product offers during your installation process. Of course, you will have the ability to accept or pass on these offers.
www.spyguardapp.com
82% remove it
 
Powered by Should I Remove It?

Remove uninstall.exe - Powered by Reason Core Security