uninstall.exe

Brightcircle Investments Limited

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The application uninstall.exe by Brightcircle Investments Limited has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. This is the uninstaller utility registered in the Windows Control Panel for the program Feven 1.5 by Feven. This file is typically installed with the program Feven 1.5 by Crossrider Advanced Technologies Ltd. (Platform) which is a potentially unwanted software program. It is distributed as part of the Brightcircle group of browser-extensions.
Publisher:
Brightcircle Investments Limited  (signed and verified)

MD5:
6e4d7360808bfe3a09f3c90d3d50c5d4

SHA-1:
cafda3e88a7af58c1c80166f7ebb786d995110ab

SHA-256:
d569b21f594958def315593223d8368f325a62c4c7282969f98c81959f537606

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
6/2/2020 12:55:57 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Brightcircle (M)
17.2.12.3

File size:
117.4 KB (120,168 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\feven 1.5\uninstall.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
3/8/2013 2:33:54 PM

Valid to:
3/8/2016 2:33:54 PM

Subject:
CN=Brightcircle Investments Limited, O=Brightcircle Investments Limited, L=Nicosia, S=Strovolos, C=CY

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
047F36483DC84C

File PE Metadata
Compilation timestamp:
6/12/2013 4:31:58 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x7417

Entry point:
E8, 3C, 79, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 51, 53, 56, 8B, 35, A0, 70, 41, 00, 57, FF, 35, A8, F2, 41, 00, FF, D6, FF, 35, A4, F2, 41, 00, 8B, D8, 89, 5D, FC, FF, D6, 8B, F0, 3B, F3, 0F, 82, 81, 00, 00, 00, 8B, FE, 2B, FB, 8D, 47, 04, 83, F8, 04, 72, 75, 53, E8, 3F, 7A, 00, 00, 8B, D8, 8D, 47, 04, 59, 3B, D8, 73, 48, B8, 00, 08, 00, 00, 3B, D8, 73, 02, 8B, C3, 03, C3, 3B, C3, 72, 0F, 50, FF, 75, FC, E8, CE, 08, 00, 00, 59, 59, 85, C0, 75, 16, 8D, 43, 10, 3B, C3, 72, 3E, 50, FF, 75, FC, E8...
 
[+]

Code size:
85 KB (87,040 bytes)

Program Uninstaller
Program name:
Feven 1.5

Display publisher:
Feven

Display version:
1.27.153.11

Uninstall string:
C:\Program Files (x86)\Feven 1.5\Uninstall.exe /fromcontrolpanel=1


The file uninstall.exe has been discovered within the following program.

Feven 1.5  by Crossrider Advanced Technologies Ltd. (Platform)
Feven is a web browser extension that changes the browsers search and home pages as well as delivers.
crossrider.com
87% remove it
 
Powered by Should I Remove It?

Remove uninstall.exe - Powered by Reason Core Security