uninstall.exe

BitGuard

MediaTechSoft Inc.

This is part of a Performersoft product, a 'PC optimzation' application that provides minimal benifits and may have been bundled by a third party installer. The application uninstall.exe by MediaTechSoft has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is the uninstaller utility registered in the Windows Control Panel for the program BitGuard by MediaTechSoft Inc..
Publisher:
MediaTechSoft Inc.  (signed and verified)

Product:
BitGuard

Description:
Generic software

Version:
2,7,1832,68

MD5:
c022f559ce55e7092d37262cbe4658ec

SHA-1:
d781db1b0a44056c51ed101ff56bc8ed12a9979f

SHA-256:
ee3d8d7336dd953f6b716398527eb0ed3a38be6a83aebc6fce924b5125654d88

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/20/2024 7:46:13 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Performersoft (M)
17.3.1.11

File size:
3.6 MB (3,780,064 bytes)

Product version:
2,7,1832,68

Copyright:
Copyright (C) 2013

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\bitguard\2.7.1832.68\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\uninstall.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
8/4/2013 3:09:22 AM

Valid to:
3/29/2016 11:18:00 AM

Subject:
CN=MediaTechSoft Inc., O=MediaTechSoft Inc., L=Beaverton, S=Oregon, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
047346D0687AB1

File PE Metadata
Compilation timestamp:
11/18/2013 8:32:32 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x1129B7

Entry point:
E8, 45, DF, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 10, 53, 8B, 5D, 08, 56, 85, DB, 74, 11, 83, 7D, 0C, 00, 76, 11, 85, DB, 75, 23, 33, C0, E9, BC, 00, 00, 00, 83, 7D, 0C, 00, 74, EF, E8, E1, 31, 00, 00, 6A, 16, 5E, 89, 30, E8, 7B, 7F, 00, 00, 8B, C6, E9, A0, 00, 00, 00, FF, 75, 0C, 53, E8, BD, E1, FF, FF, 59, 59, 3B, 45, 0C, 72, 05, C6, 03, 00, EB, D5, 57, FF, 75, 10, 8D, 4D, F0, E8, 6E, DC, FF, FF, 80, 3B, 00, 8B, FB, 8B, F3, 74, 63, 8A, 0F, 8B, 55, F4, 0F, B6, C1, 03, C2, 8A, 50, 1D, F6...
 
[+]

Entropy:
6.5749

Code size:
2 MB (2,099,712 bytes)

Program Uninstaller
Program name:
BitGuard

Display publisher:
MediaTechSoft Inc.

Uninstall string:
"C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\uninstall.exe" /Uninstall /{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693} /um


Remove uninstall.exe - Powered by Reason Core Security