uninstall.exe

Big Water Applications, LLC

This is the uninstall module for the Injekt branded web browser extension program which injects advertising in the web browser as well as modifies the browser settings. The uninstaller is registered within Control Panel > Add/Remove Programs. The application uninstall.exe by Big Water Applications has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is the uninstaller utility registered in the Windows Control Panel for the program Spy Guard by Big Water Applications, LLC.
Publisher:
Big Water Applications, LLC  (signed and verified)

MD5:
c9ba3bf2ea3315ccb613b56d4894d927

SHA-1:
3fbfe9e45b2cf0a90f071a4acd8756cf429930bf

SHA-256:
94c6afddfde9864ca790540305d9df5cde6471c5376d12c59399eb2116e57757

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
9/8/2024 3:17:15 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Injekt (M)
16.11.8.13

File size:
509.6 KB (521,832 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\ProgramData\spyguard\uninstall.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
4/21/2013 8:00:00 PM

Valid to:
4/22/2014 7:59:59 PM

Subject:
CN="Big Water Applications, LLC", O="Big Water Applications, LLC", STREET=640 Grand Ave, STREET=Suite E, L=Carlsbad, S=CA, PostalCode=92008, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0088DD6A4DF46D819C84B9E99D7A0530C5

File PE Metadata
Compilation timestamp:
1/22/2014 5:14:57 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:4mNddPK0G2DfYmxLW4j5n/XfaojxFSdysocghSep/:dHdPHV3jBCojxJnSeZ

Entry address:
0x40763

Entry point:
E8, 7C, D3, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, EC, 44, 47, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, 60, 20, 47, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, EC, 44, 47, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7, 03, 00, 00, 00, 0F, 85, B8, 01, 00, 00, F7, C6, 03...
 
[+]

Entropy:
6.3272

Code size:
377.5 KB (386,560 bytes)

Program Uninstaller
Program name:
Spy Guard

Display publisher:
Big Water Applications, LLC

Display version:
2.6.58

Uninstall string:
C:\ProgramData\SpyGuard\uninstall.exe /kb=y /ic=9


Remove uninstall.exe - Powered by Reason Core Security