uninstall.exe

Sailor Project

This potentially unwanted Internet browser extension is built upon and distributed using the free Crossrider platform and will deliver advertisements to the web browser in various formats such as banner, text hyper-links, inline text and transitional ads. The application uninstall.exe by Sailor Project has been detected as adware by 13 anti-malware scanners. This is the uninstaller utility registered in the Windows Control Panel for the program PalMall by BND. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. It is part of the Brightcircle group of web-extensions that inject advertisements in the browser.
Publisher:
Sailor Project  (signed and verified)

MD5:
b3fa3d2925761b2c9c01cfbee127df79

SHA-1:
b31185334181e14853aefba9dadb21386650db18

SHA-256:
a718b842897e79f2fc9f28abec3f5e02f1bf1ce0d249deef2a13dd6b61d3e2e5

Scanner detections:
13 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
4/24/2024 1:14:56 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win-PUP/CrossRider
2014.10.31

Avira AntiVirus
TR/Crypt.ZPACK.Gen2
7.11.30.172

avast!
Win32:Crossrider-N [PUP]
141025-0

AVG
Generic
2015.0.3305

Baidu Antivirus
Adware.Win32.GoogUpdate
4.0.3.141030

Dr.Web
Trojan.Crossrider.27207
9.0.1.05190

ESET NOD32
Win32/Toolbar.CrossRider.AW (variant)
8.10647

Kaspersky
Trojan.NSIS.GoogUpdate
15.0.0.494

NANO AntiVirus
Trojan.Win32.Crossrider.dfpshi
0.28.6.62995

Reason Heuristics
PUP.SailorProject.J
14.10.27.15

SUPERAntiSpyware
Trojan.Agent/Gen-Anomaly
10267

Vba32 AntiVirus
Trojan.GoogUpdate
3.12.26.3

Zillya! Antivirus
Trojan.GoogUpdate.Win32.1182
2.0.0.1973

File size:
88.4 KB (90,472 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\palmall\uninstall.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/17/2014 7:00:00 PM

Valid to:
7/18/2015 6:59:59 PM

Subject:
CN=Sailor Project, O=Sailor Project, STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Cyprus, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
47C5F145C734CD3D086C0A102176F0A1

File PE Metadata
Compilation timestamp:
7/28/2014 5:04:35 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
1536:sPS39gC5lZ4GMm3TMAZz5J4clCsWjcdXFDl3hXSI4:D39/oGMm3IG/tX1BhXS1

Entry address:
0x56DE

Entry point:
E8, 6D, 5B, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 38, 3F, 41, 00, E8, 2C, 0A, 00, 00, E8, 4A, 33, 00, 00, 0F, B7, F0, 6A, 02, E8, 00, 5B, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, E1, 54, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.2542

Code size:
54.5 KB (55,808 bytes)

Program Uninstaller
Program name:
PalMall

Display publisher:
BND

Display version:
1.34.7.1

Uninstall string:
C:\Program Files (x86)\PalMall\Uninstall.exe /fcp=1


Remove uninstall.exe - Powered by Reason Core Security