uninstall.browsersafeguard.exe

Distributed by Adknowledge's installers (Optimum/Fusion/Tiny), the trojan adware will proxy various web traffic and inject advertising in the browser. BrowserProtect was programmed by Danny Miller of Adknowledge. The application uninstall.browsersafeguard.exe has been detected as adware by 7 anti-malware scanners. Additionally, the file is typically installed by a number of programs including BrowserSafeguard by Adknowledge, Inc. and BrowserSafeguard with RocketTab by Adknowledge, Inc., both potentially unwanted software.
Version:
1.0.0.0

MD5:
24f2e14eeff05b6d96c281839ca8f4fd

SHA-1:
af196d2d7e677ab1e2133c897328d66e2df98579

SHA-256:
3c5da4da115a104ca96a38668971a606c23d57caeda120c726e42511d334c6fb

Scanner detections:
7 / 68

Status:
Adware

Explanation:
Part of an adware program delivered by Adknowledge that will modify the web browser's settings (preferred home page and default search settings) and install a local proxy to intercept and inject various forms of advertising.

Analysis date:
12/25/2024 12:40:25 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic5
2015.0.3559

Bkav FE
W32.Clod12f.Trojan
1.3.0.4613

McAfee
Adware-Bsafeg!24F2E14EEFF0
5600.7215

Panda Antivirus
Trj/OCJ.D
14.02.19.12

Reason Heuristics
PUP.BrowserSafeguard.Z
14.5.8.11

Trend Micro House Call
TROJ_GEN.R02KH06K813
7.2.50

VIPRE Antivirus
Adware.Bsafeg
25040

File size:
3.3 MB (3,447,296 bytes)

Product version:
1.0.0.0

Original file name:
Installer.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\browsersafeguard\uninstall.browsersafeguard.exe

File PE Metadata
Compilation timestamp:
11/4/2013 9:37:02 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:Hz2/b9zITJPwLJVHUGqI4vQrb+qQMvr52i2DSa4Y9qnCs+7SCvzCKT:Gb98NoLPHUGqI4IXbNvrElDSxY

Entry address:
0x33C8D6

Entry point:
FF, 25, E4, C8, 73, 00, 00, 00, 00, 00, 00, 00, 00, 00, B8, C8, 33, 00, 00, 00, 00, 00, 00, 00, 00, 00, 1E, BF, 77, 52, 00, 00, 00, 00, 02, 00, 00, 00, 79, 00, 00, 00, 08, C9, 33, 00, 08, AB, 33, 00, 52, 53, 44, 53, F5, 83, C4, B4, B0, A3, 07, 42, B7, 19, ED, DC, 39, A1, A0, 6C, 01, 00, 00, 00, 43, 3A, 5C, 55, 73, 65, 72, 73, 5C, 64, 6D, 69, 6C, 6C, 65, 72, 5C, 44, 6F, 63, 75, 6D, 65, 6E, 74, 73, 5C, 50, 72, 6F, 6A, 65, 63, 74, 73, 5C, 49, 6E, 73, 74, 61, 6C, 6C, 65, 72, 73, 5C, 42, 72, 6F, 77, 73, 65, 72...
 
[+]

Entropy:
7.0952

Code size:
3.2 MB (3,385,856 bytes)

The file uninstall.browsersafeguard.exe has been discovered within the following programs.

BrowserSafeguard  by Adknowledge, Inc.
RocketTab is licensed by Rich River Media but typically bundled with BrowserSafeguard, the software is distributed through numerous adware bundlers including optimum-installer, FUSION INSTALL and Tint Installer.
www.browsersafeguard.com
80% remove it
BrowserSafeguard with RocketTab  by Adknowledge, Inc.
BrowserSafeguard is distributed through the company's OptimumInstaller / InstallIQ, a pay-per-install download bundler.
82% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to ec2-54-243-65-88.compute-1.amazonaws.com  (54.243.65.88:80)

Remove uninstall.browsersafeguard.exe - Powered by Reason Core Security