surfslideuninstall.exe

surf slide

This is the installer/setup program for a Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application surfslideuninstall.exe by surf slide has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is the uninstaller utility registered in the Windows Control Panel for the program surf slide by surf slide.
Publisher:
surf slide  (signed and verified)

MD5:
f91d4e821c5cefaff058b08ab894fdfb

SHA-1:
68d105e4cd80c059440031b4880e29307c7b7fa5

SHA-256:
25f3e1f7ccaf734e626daec1c216c72b7d106ede04be85dab314e07a9c82b25b

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Belongs to the Sambreel/Yontoo progam that inserts various forms of advertising in the user's web browser, installed with minimal or no user consent.

Analysis date:
11/23/2024 6:53:54 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Yontoo (M)
17.3.12.9

File size:
253.5 KB (259,616 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\Program Files\surf slide\surfslideuninstall.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
9/2/2014 5:30:00 AM

Valid to:
9/3/2015 5:29:59 AM

Subject:
CN=surf slide, O=surf slide, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
40C4725F1712C4789A4BDCEA560D5BE2

File PE Metadata
Compilation timestamp:
12/6/2009 4:22:01 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 6F, 44, 00, E8, F1, 2B, 00, 00, A3, 84, 6E, 44, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, 9C, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 2E, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, F0, 46, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.8703

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

Program Uninstaller
Program name:
surf slide

Display publisher:
surf slide

Display version:
2014.10.29.062704

Uninstall string:
C:\Program Files (x86)\surf slide\surfslideuninstall.exe


Remove surfslideuninstall.exe - Powered by Reason Core Security