uninstall.exe

ColoColo Apps (Bright Circle Investments Ltd)

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The application uninstall.exe by ColoColo Apps (Bright Circle Investments) has been detected as adware by 11 anti-malware scanners. This is the uninstaller utility registered in the Windows Control Panel for the program HQCinema Pro 2.1V28.01 by HQ CinemaV28.01. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. It is part of the Brightcircle group of web-extensions that inject advertisements in the browser.
Publisher:

MD5:
818a5a6cfe0172cffaac0b8ed8f73135

SHA-1:
fed482d9d1c3f8d978f1ca769549ebbb5881c826

SHA-256:
1b68745a59e0c87c8f52f6709934f81789b0a09ac544bdc88f5bdf73ac18777c

Scanner detections:
11 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/25/2024 7:49:31 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Application.Heur.hqX@lSTaoYii
6473648

Avira AntiVirus
Adware/CrossRider.A.16675
7.11.205.178

avast!
Win32:Malware-gen
150101-1

Bitdefender
Gen:Application.Heur.hqX@lSTaoYii
1.0.20.140

Comodo Security
Application.Win32.InstallCore.GIFI
20877

Emsisoft Anti-Malware
Gen:Application.Heur.hqX@lSTaoYii
9.0.0.4799

ESET NOD32
Win32/Toolbar.CrossRider.BM potentially unwanted application
7.0.302.0

F-Secure
Riskware.Gen:Application.Heur.hqX@lSTaoYii
5.13.68

G Data
Gen:Application.Heur.hqX@lSTaoYii
15.1.25

Reason Heuristics
PUP.Brightcircle
15.2.10.11

VIPRE Antivirus
Threat.4789396
36666

File size:
121.5 KB (124,376 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\hqcinema pro 2.1v28.01\uninstall.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
12/16/2014 1:00:00 AM

Valid to:
12/17/2015 12:59:59 AM

Subject:
CN=ColoColo Apps (Bright Circle Investments Ltd), O=ColoColo Apps (Bright Circle Investments Ltd), STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Nicosia, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00D815C7CD687694A6F4119A3535D31D7A

File PE Metadata
Compilation timestamp:
1/28/2015 12:04:56 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
1536:eA0nTEvb8sX7CObGidrgjR3VKTfXisAJtxuX0WtxclTWMusWjcdx2HpDAcB2:rYTybVXDu/K7PmTThx2H9AcM

Entry address:
0x957D

Entry point:
E8, 01, 68, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 20, C3, 41, 00, E8, 2D, 0A, 00, 00, E8, 62, 31, 00, 00, 0F, B7, F0, 6A, 02, E8, 94, 67, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 75, 61, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.4205

Code size:
86 KB (88,064 bytes)

Program Uninstaller
Program name:
HQCinema Pro 2.1V28.01

Display publisher:
HQ CinemaV28.01

Display version:
1.36.01.22

Uninstall string:
C:\Program Files (x86)\HQCinema Pro 2.1V28.01\Uninstall.exe /fcp=1


Remove uninstall.exe - Powered by Reason Core Security