uninstall.exe

Bright circle investments Ltd.

This adware utilizes the Crossrider extension platform and will inject advertisiments in the Internet browser and may modify core browser settings. Ads will be delivered as banners and contextual text-links and may promote other potentially unwanted software. The application uninstall.exe by Bright circle investments has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is the uninstaller utility registered in the Windows Control Panel for the program Plus-HD-V1.5 by Plus-HD-V1.5. It is part of the Brightcircle group of web-extensions that inject advertisements in the browser.
Publisher:
Bright circle investments Ltd.  (signed and verified)

MD5:
8728760ce009c509d9fa13fcfd3eabbf

SHA-1:
aba3428242bb9c1758d11c03bbf75cb23cd297e3

SHA-256:
c2c6b4b9f103c298de456e274ce190c4ee023086d82df6c2ac7e9f00282b32cb

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
9/30/2020 4:48:57 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Brightcircle (M)
16.4.7.8

File size:
88.5 KB (90,608 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\plus-hd-v1.5\uninstall.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
6/18/2014 8:00:00 PM

Valid to:
6/19/2015 7:59:59 PM

Subject:
CN=Bright circle investments Ltd., O=Bright circle investments Ltd., STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Nicosia, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00EF90FEF9AC8E258E5D30D0E08C84D37E

File PE Metadata
Compilation timestamp:
6/22/2014 6:10:13 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
1536:h4btUkg615aiI1NjKqOaH0RcVCsWjcdRB7Zklj:euk+Z1N+AtRZZS

Entry address:
0x5C8B

Entry point:
E8, 60, 5B, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, B8, 3F, 41, 00, E8, 1F, 0A, 00, 00, E8, CB, 32, 00, 00, 0F, B7, F0, 6A, 02, E8, F3, 5A, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, D4, 54, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.2482

Code size:
56 KB (57,344 bytes)

Program Uninstaller
Program name:
Plus-HD-V1.5

Display publisher:
Plus-HD-V1.5

Display version:
1.34.6.10

Uninstall string:
C:\Program Files (x86)\Plus-HD-V1.5\Uninstall.exe /fcp=1


Remove uninstall.exe - Powered by Reason Core Security