uninstall.exe

Morgan Enter Mode

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The application uninstall.exe by Morgan Enter Mode has been detected as adware by 33 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. This file is typically installed with the program Internet Speed Checker by Sailor Project which is a potentially unwanted software program. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. It is distributed as part of the Brightcircle group of browser-extensions.
Publisher:
Morgan Enter Mode  (signed and verified)

MD5:
31523451f5faf68b0ba9ea97fe98c531

SHA-1:
e48abf1affb6493ef27c5da5a68474b0f3485c44

SHA-256:
5e7f4bdbb67586dcd21832a615517c509db4463d41980487cba4574f25fda0f9

Scanner detections:
33 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars. Distributed through the Brightcircle investments brand.

Analysis date:
4/23/2024 3:29:41 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Application.Heur.gqX@laSAOHki
5695233

Agnitum Outpost
PUA.Adwapper
7.1.1

AhnLab V3 Security
PUP/Win32.CrossRider
2015.10.05

Avira AntiVirus
TR/Crypt.ZPACK.Gen2
7.11.168.116

Arcabit
Application.Heur.EAAAE3
1.0.0.568

avast!
Win32:Crossrider-DN [PUP]
151205-4

AVG
Generic
2015.0.3311

Baidu Antivirus
PUA.Win32.CrossRider
4.0.3.141025

Bitdefender
Gen:Application.Heur.gqX@laSAOHki
1.0.20.1710

Bkav FE
W32.HfsAdware
1.3.0.7237

Comodo Security
Application.Win32.InstallCore.GIFI
23355

Dr.Web
Trojan.Crossrider1.23142
9.0.1.05190

Emsisoft Anti-Malware
Gen:Application.Heur.gqX@laSAOHki
10.0.0.5366

ESET NOD32
Win32/Toolbar.CrossRider.AW potentially unwanted application
7.0.302.0

F-Prot
W32/S-3e774f4e
v6.4.7.1.166

G Data
Win32.Adware.Crossrider
14.10.24

IKARUS anti.virus
PUA.Plush
t3scan.1.7.5.0

K7 AntiVirus
Unwanted-Program
13.210.17418

Kaspersky
not-a-virus:HEUR:AdWare.Win32.CrossRider
15.0.0.543

Malwarebytes
v2015.12.08.06

McAfee
Trojan.Artemis!31523451F5FA
18.0.204.0

MicroWorld eScan
Gen:Application.Heur.gqX@laSAOHki
16.0.0.1026

NANO AntiVirus
Riskware.Win32.Crossrider.dgmsab
0.28.2.62483

Norman
Gen:Application.Heur.gqX@laSAOHki
07.10.2015 03:16:12

nProtect
Trojan/W32.Agent.102824.C
14.10.22.01

Panda Antivirus
Trj/Genetic.gen
14.10.25.08

Qihoo 360 Security
Win32/Virus.Adware.a87
1.0.0.1015

Quick Heal
PUA.BrightCircle.OD6
12.15.14.00

Reason Heuristics
Threat.Win.Reputation.IMP
14.10.25.7

Rising Antivirus
PE:Malware.Obscure!1.9C59
23.00.65.141023

Vba32 AntiVirus
Trojan.GoogUpdate
3.12.26.4

VIPRE Antivirus
Threat.4150696
45588

Zillya! Antivirus
Trojan.GoogUpdate.Win32.3590
2.0.0.1962

File size:
100.4 KB (102,816 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\internet speed checker\uninstall.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
8/28/2014 2:00:00 AM

Valid to:
8/29/2015 1:59:59 AM

Subject:
CN=Morgan Enter Mode, O=Morgan Enter Mode, STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Cyprus, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00E247EA066029B70533C15792B60ED4D8

File PE Metadata
Compilation timestamp:
10/8/2014 9:35:21 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
1536:ERmX2xPG5Pcdu6lNQRZibT30bi7hPyZecVglsWjcd6LfAQCBOzVhfU2K:OmGxPGF563QGptWgK6LfAQCBOzVhfUZ

Entry address:
0x5044

Entry point:
E8, E9, 63, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 98, 6E, 41, 00, E8, 26, 0A, 00, 00, E8, 85, 24, 00, 00, 0F, B7, F0, 6A, 02, E8, 7C, 63, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 5D, 5D, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
65.5 KB (67,072 bytes)

The file uninstall.exe has been discovered within the following program.

Internet Speed Checker  by Sailor Project
Internet Speed Checker is an adware web browser application that displays banner ads as well as contextual link ads that are injected in the web page.
62% remove it
 
Powered by Should I Remove It?

Remove uninstall.exe - Powered by Reason Core Security