uninstaller.exe

Roll Around

This is the installer/setup program for a Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application uninstaller.exe by Roll Around has been detected as adware by 20 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is the uninstaller utility registered in the Windows Control Panel for the program Roll Around by Roll Around. Additionally, the file is typically installed by a number of programs including Roll Around by Yontoo Technology, Inc. and Buzzdock by Alactro LLC, both potentially unwanted software. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
Roll Around  (signed and verified)

Version:
2.0.5554.26260

MD5:
dcaacb388892b7629519fd244d0e828a

SHA-1:
30b754d5aae33e0153d3a3fbd0fe8f6e9c8d11d5

SHA-256:
0b537338acedf85362f7925a078960c604e2e7722286d79144e8901ebd63c2d0

Scanner detections:
20 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/19/2024 4:19:00 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/BrowseFox.311304.6
8.3.2.4

Arcabit
PUP.Adware.RollAround
1.0.0.624

avast!
Win32:BrowseFox-JL [PUP]
2014.9-151126

AVG
BrowseFox
2016.0.2913

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.151126

Bkav FE
W32.HfsAdware
1.3.0.7383

Clam AntiVirus
Win.Adware.Browsefox-725
0.98/21511

Dr.Web
Trojan.Yontoo.1738
9.0.1.0330

ESET NOD32
Win32/BrowseFox.AI potentially unwanted (variant)
9.12625

K7 AntiVirus
Adware
13.212.17972

Malwarebytes
PUP.Optional.RollAround
v2015.11.26.07

McAfee
Artemis!DCAACB388892
5600.6569

NANO AntiVirus
Trojan.Win32.Yontoo.dvtotm
0.30.26.4751

Panda Antivirus
PUP/SoftwareUpdater
15.11.26.07

Quick Heal
PUA.Rollaround.Gen
11.15.14.00

Reason Heuristics
PUP.Yontoo.RollAround.Installer (M)
15.11.26.19

Rising Antivirus
PE:Adware.BrowseFox!1.A1B7 [F]
23.00.65.151124

Sophos
Browse Fox (PUA)
4.98

SUPERAntiSpyware
PUP.BrowseFox/Variant
9483

VIPRE Antivirus
Yontoo
45432

File size:
304 KB (311,304 bytes)

Product version:
2015.03.17

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\Program Files\roll around\uninstaller.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
12/21/2014 7:00:00 PM

Valid to:
12/22/2015 6:59:59 PM

Subject:
CN=Roll Around, O=Roll Around, L=Los Angeles, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
02A1223E320B2EC6C2C8789B5CB4BB4B

File PE Metadata
Compilation timestamp:
6/4/2014 7:58:31 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:rQ3jJGUnM3DoFFjuvf/toNQ8dqLuJoU0U7Hd8CntQOHHM+HFFTjXdpNnT2y:+JJnM3D0Fw/tN8dkmLtpHHHrh7H

Entry address:
0x31E4

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, E0, 73, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, B8, 6C, 44, 00, E8, 1B, 25, 00, 00, 53, 68, 60, 01, 00, 00, A3, C0, 6B, 44, 00, 8D, 44, 24, 38, 50, 53, 68, DB, 73, 40, 00, FF, 15, 58, 71, 40, 00, 68, D0, 73, 40, 00, 68, C0, 2B, 44, 00, E8, 0D, 24, 00, 00, FF, 15, AC, 70, 40, 00, 50, BF, 00, F0, 46, 00, 57, E8, FB, 23, 00, 00...
 
[+]

Entropy:
7.9380

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

Program Uninstaller
Program name:
Roll Around

Display publisher:
Roll Around

Display version:
2.0.5554.26260

Uninstall string:
"C:\Program Files (x86)\Roll Around\uninstaller.exe" /ut RM


The file uninstaller.exe has been discovered within the following programs.

Buzzdock  by Alactro LLC
This is a web browser extension that injects advertising. From the EULA: "Buzzdock is free to download and use. Buzzdock is supported by advertising, and users will see additional ads on websites where Buzzdock features operate.
www.buzzdock.com/faq-support
79% remove it
Roll Around  by Yontoo Technology, Inc.
Roll Around is an adware program that installs as a web browser plugin to inject and display advertisements.
www.rollaround.net/support
79% remove it
 
Powered by Should I Remove It?

Remove uninstaller.exe - Powered by Reason Core Security