uninstall.exe

I Want This

215 Apps

This is the installer application for a 50onRed advertising supported software package (displays ads in the browser and may hijack the home and search pages of the web browser). The application uninstall.exe, “I Want This Installer” has been detected as adware by 17 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer, however the file is not signed with an authenticode signature from a trusted source. This file is typically installed with the program I Want This by 215 Apps which is a potentially unwanted software program. This web browser addon will display additional advertisements in the user's browser including popup, banner, contextual hyperlinks as well as affiliate links.
Publisher:
215 Apps

Product:
I Want This

Description:
I Want This Installer

Version:
1.14.149.149

MD5:
d5bdb1b5810c2d54ca15dc138e2bd741

SHA-1:
32cffe6d472fb277fa4a1e3b1cdab9600d813e3a

SHA-256:
24377bb123e61200d2517f26deb5d99879acba368202b97dedbe74ecb602bf66

Scanner detections:
17 / 68

Status:
Adware

Explanation:
This is part of the Crossrider Internet browser extension framework which may modify the user's web browser settings including changing the home and search pages.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application.

Analysis date:
12/6/2021 1:18:46 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Plush.2
886

Agnitum Outpost
PUA.Toolbar.CrossRider
7.1.1

Baidu Antivirus
Adware.Win32.CrossRider
4.0.3.1492

Bitdefender
Gen:Variant.Adware.Plush.2
1.0.20.1225

Bkav FE
W32.Clod5d5.Trojan
1.3.0.4959

Emsisoft Anti-Malware
Gen:Variant.Adware.Plush
8.14.09.02.08

ESET NOD32
Win32/Toolbar.CrossRider (variant)
8.10325

F-Secure
Gen:Variant.Adware.Plush.2
11.2014-02-09_3

G Data
Gen:Variant.Adware.Plush
14.9.24

Malwarebytes
PUP.Optional.IWantThis.A
v2014.09.02.08

McAfee
Artemis!D5BDB1B5810C
5600.7020

MicroWorld eScan
Gen:Variant.Adware.Plush.2
15.0.0.735

Panda Antivirus
Trj/CI.A
14.09.02.08

Reason Heuristics
PUP.Installer.215Apps.J
14.9.2.8

Sophos
AppRider
4.98

Trend Micro House Call
TROJ_GE.546BE4CF
7.2.245

VIPRE Antivirus
GamePlayLabs
32602

File size:
484.6 KB (496,234 bytes)

Copyright:
Copyright 215 Apps

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\Program Files\i want this\uninstall.exe

File PE Metadata
Compilation timestamp:
1/5/2010 12:09:27 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
12288:4yAt+RRyeT+soH4noPpsnlYkAU/itEcQa85+qYZ+4UTscu:4yAt+jy5soBsCRsTcQa8YqYQ4wzu

Entry address:
0x3E13

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, E8, 98, 52, 00, 00, C7, 04, 24, 01, 80, 00, 00, E8, 3C, 4F, 00, 00, 53, C7, 04, 24, 00, 00, 00, 00, E8, A7, 52, 00, 00, A3, 48, 5C, 42, 00, 51, C7, 04, 24, 08, 00, 00, 00, E8, 27, 32, 00, 00, A3, F8, 5C, 42, 00, 8D, 85, 84, FE, FF, FF, 52, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 4C, B2, 40, 00, E8, D1, 51, 00, 00, 83, EC, 14, C7, 44, 24, 04, 4D, B2, 40, 00, C7, 04, 24, 28, 5D...
 
[+]

Entropy:
7.9319  (probably packed)

Code size:
32.5 KB (33,280 bytes)

The file uninstall.exe has been discovered within the following program.

I Want This  by 215 Apps
I Want This (i want this.dll) is a web browser extension loaded with Internet Explorer via the I Want This BHO.
iw.antthis.com
88% remove it
 
Powered by Should I Remove It?

Remove uninstall.exe - Powered by Reason Core Security