uninstall.exe

Linkey

AZTEC MEDIA INC.

The application uninstall.exe, “Linkey - Uninstall” by AZTEC MEDIA INC has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is the uninstaller utility registered in the Windows Control Panel for the program Linkey by Aztec Media Inc. This file is typically installed with the program Linkey by Aztec Media Inc. which is a potentially unwanted software program.
Publisher:
Aztec Media Inc  (signed by AZTEC MEDIA INC.)

Product:
Linkey

Description:
Linkey - Uninstall

Version:
0.0.0.256

MD5:
5c981612318dc1078f512903163ae26f

SHA-1:
d4a5ca3f8e0a5905c4790be011ecbb4968fbf876

SHA-256:
2832221e52743eb266ce3464e2c4f895b54814ecce1a9cb54295b19c787ef577

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/23/2024 4:58:15 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.AZTECMEDIAINC.J
14.3.3.18

File size:
318 KB (325,632 bytes)

Product version:
0.0.0.256

Copyright:
Copyright (c) 2013

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\Documents and Settings\{user}\Local settings\temp\{random}.tmp\uninstall.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
5/18/2013 8:00:00 PM

Valid to:
5/19/2015 7:59:59 PM

Subject:
CN=AZTEC MEDIA INC., OU=Development, O=AZTEC MEDIA INC., L=Panama City, S=Panama, C=PA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
546A239CA30D7A98B656DADCE4AA28E0

File PE Metadata
Compilation timestamp:
5/30/2013 4:09:15 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:e6Tea0X47XePnfwKQeMjUzsX7oJ49EklZP9MMkgnRYj8eLEo19Hf8gb72fY6i5+M:yX47XebMj065L6gaj8ibJ7pzsVfvjmhv

Entry address:
0x38AF

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 68, A2, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 90, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 90, 40, 00, 55, FF, 15, BC, 92, 40, 00, 6A, 08, A3, 98, EB, 47, 00, E8, 25, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, EA, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 64, A2, 40, 00, FF, 15, 80, 91, 40, 00, 68, 4C, A2, 40, 00, 68, A0, 6A, 47, 00, E8, 8F, 27, 00, 00, FF, 15, B0, 90, 40, 00, 50, BF, A0, F0, 4C, 00, 57, E8, 7D, 27, 00, 00...
 
[+]

Entropy:
6.6436

Packer / compiler:
Nullsoft install system v2.x

Code size:
29.5 KB (30,208 bytes)

Program Uninstaller
Program name:
Linkey

Display publisher:
Aztec Media Inc

Display version:
0.0.0.256

Uninstall string:
"C:\Archivos de programa\Linkey\uninstall.exe"


The file uninstall.exe has been discovered within the following program.

Linkey  by Aztec Media Inc.
Linkey is a potentially unwanted web browser search extension for the top browsers and designed to modify the user's search and home pages (www.default-search.com or www.linkeyproject.com/app/) in order to direct advertising via the linkeyproject.com portal.
linkeyproject.com
81% remove it
 
Powered by Should I Remove It?

Remove uninstall.exe - Powered by Reason Core Security