Uninstall.exe

Share This

Data Protection Solutions

This is the uninstall module for the Injekt branded web browser extension program which injects advertising in the web browser as well as modifies the browser settings. The uninstaller is registered within Control Panel > Add/Remove Programs. The application Uninstall.exe, “ShareThis Uninstall” by Data Protection Solutions has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software.
Publisher:
Data Protection Solutions  (signed and verified)

Product:
Share This

Description:
ShareThis Uninstall

Version:
1.0.0.0

MD5:
42a29f20b1ba363cad2c316bc22502c2

SHA-1:
5fcf00df2c8175a477fad3bf6166f8b63ed8bd37

SHA-256:
f6d2723880751c4961cf8404510d9d224d49287435a269efa1c912ece18bce59

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
12/25/2024 11:58:14 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Injekt (M)
17.3.12.9

File size:
639.9 KB (655,216 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Data Protection Solutions 2014

Original file name:
Uninstall.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\ProgramData\sharethis\uninstall.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/9/2014 8:00:00 PM

Valid to:
3/10/2015 7:59:59 PM

Subject:
CN=Data Protection Solutions, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Data Protection Solutions, L=St. James, S=St. James, C=BB

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6FA5269C2FC95B961427D4FD1474CDC5

File PE Metadata
Compilation timestamp:
11/5/2014 7:17:24 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

Entry address:
0x840EE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.6595

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
520.5 KB (532,992 bytes)

Remove Uninstall.exe - Powered by Reason Core Security