uninstall.exe

Sara Kodama Project

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The application uninstall.exe by Sara Kodama Project has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. This is the uninstaller utility registered in the Windows Control Panel for the program PalMall by BND. It is distributed as part of the Brightcircle group of browser-extensions.
Publisher:
Sara Kodama Project  (signed and verified)

MD5:
8341bb5acc77a449bc8a64a308690807

SHA-1:
07b0edfa807b181ee9002c4a92af68c66514df23

SHA-256:
1e01eeddc964c8ff2e87b0a063b8b4e7a9c6d46e7a6a15a44cbdce12f10e1654

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/26/2024 11:22:25 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Brightcircle (M)
17.2.18.0

File size:
99.9 KB (102,304 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\palmall\uninstall.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
10/19/2014 7:00:00 PM

Valid to:
10/20/2015 6:59:59 PM

Subject:
CN=Sara Kodama Project, O=Sara Kodama Project, STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Cyprus, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
75E47031A737D2A200F0C7A94034399F

File PE Metadata
Compilation timestamp:
11/6/2014 3:35:27 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

Entry address:
0x4F04

Entry point:
E8, E9, 63, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, A8, 6E, 41, 00, E8, 26, 0A, 00, 00, E8, 85, 24, 00, 00, 0F, B7, F0, 6A, 02, E8, 7C, 63, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 5D, 5D, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
65 KB (66,560 bytes)

Program Uninstaller
Program name:
PalMall

Display publisher:
BND

Display version:
1.35.9.29

Uninstall string:
C:\Program Files (x86)\PalMall\Uninstall.exe /fcp=1


Remove uninstall.exe - Powered by Reason Core Security