uninstall.exe

The application uninstall.exe, “Designed for Windows” has been detected as a potentially unwanted program by 13 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. This is the uninstaller utility registered in the Windows Control Panel for the program BlockAndSurf by BlockAndSurf-software. This file is typically installed with the program BlockAndSurf by Revizer Technologies which is a potentially unwanted software program.
Description:
Designed for Windows

Version:
1.192.0.5

MD5:
1b558dd9d9716f5933e76c467f74b114

SHA-1:
c9d528de596e1bcba6ab31f1768aa11034d5a731

SHA-256:
18ecd70d3745e2aeadb8a53010a109a764a171d815d7b2e766a539c051541e0c

Scanner detections:
13 / 68

Status:
Potentially unwanted

Analysis date:
4/24/2024 10:19:22 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Strictor.83953
5646091

AVG
AddLyrics_r
2016.0.3136

Baidu Antivirus
Adware.Win32.AddLyrics
4.0.3.15418

Bitdefender
Gen:Variant.Strictor.83953
1.0.20.540

Emsisoft Anti-Malware
Gen:Variant.Strictor.83953
9.0.0.4799

ESET NOD32
Win32/Adware.AddLyrics.EB application
7.0.302.0

F-Secure
Gen:Variant.Strictor.83953
5.13.68

G Data
Gen:Variant.Strictor.83953
15.4.25

IKARUS anti.virus
AdWare.AddLyrics
t3scan.1.8.9.0

MicroWorld eScan
Gen:Variant.Strictor.83953
16.0.0.324

Panda Antivirus
Trj/Genetic.gen
15.04.18.09

Reason Heuristics
Threat.Installer
15.4.18.4

Rising Antivirus
PE:Malware.Obscure/Heur!1.9E03
23.00.65.15416

File size:
432.8 KB (443,202 bytes)

Copyright:
Copyright (c) 2015

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Turkish (Turkey)

Common path:
C:\Program Files\version90blockandsurf\uninstall.exe

File PE Metadata
Compilation timestamp:
2/24/2012 9:19:59 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:7El7dkbOmw0tZ6WE+I1G8vffupztmsjbwhDu9I:70deOmw0CGQXSztmYcAa

Entry address:
0x39E3

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 91, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, C0, 82, 40, 00, 6A, 08, A3, B8, 2E, 47, 00, E8, 37, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, D0, 2D, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 93, 40, 00, FF, 15, 84, 81, 40, 00, 68, 04, 93, 40, 00, 68, C0, AD, 46, 00, E8, 19, 27, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 30, 4C, 00, 57, E8, 07, 27, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
28 KB (28,672 bytes)

Program Uninstaller
Program name:
BlockAndSurf

Display publisher:
BlockAndSurf-software

Uninstall string:
C:\Program Files\version90BlockAndSurf\Uninstall.exe


The file uninstall.exe has been discovered within the following program.

BlockAndSurf  by Revizer Technologies
BlockAndSurf is an adware browser extension that will display banner and text-context link ads aimed to promote the installation of additional questionable content including web browser toolbars, optimization utilities and other products.
www.revizer.com
82% remove it
 
Powered by Should I Remove It?

Remove uninstall.exe - Powered by Reason Core Security