uninstall.exe

Winston Project

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The application uninstall.exe by Winston Project has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. This is the uninstaller utility registered in the Windows Control Panel for the program CinemaPro 1.5V25.11 by Cinema ProV25.11. It is distributed as part of the Brightcircle group of browser-extensions.
Publisher:
Winston Project  (signed and verified)

MD5:
514190b171e7a7691871ea7149f8d694

SHA-1:
af80dd70079f5f6141d07f7b83bee5e8de7599b2

SHA-256:
71ea754689e438e06554560c70f5f0212c7e3bc61672008440fff8b862a2af9d

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/27/2024 12:07:15 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Brightcircle (M)
17.3.14.8

File size:
105.9 KB (108,440 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\cinemapro 1.5v25.11\uninstall.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
10/20/2014 2:00:00 AM

Valid to:
10/21/2015 1:59:59 AM

Subject:
CN=Winston Project, O=Winston Project, STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Cyprus, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00B312FD1B7F10CF48C48080B24091FB8E

File PE Metadata
Compilation timestamp:
11/25/2014 1:04:18 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

Entry address:
0x5FC7

Entry point:
E8, CE, 66, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, A8, 7F, 41, 00, E8, 23, 0A, 00, 00, E8, 79, 32, 00, 00, 0F, B7, F0, 6A, 02, E8, 61, 66, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 42, 60, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
71 KB (72,704 bytes)

Program Uninstaller
Program name:
CinemaPro 1.5V25.11

Display publisher:
Cinema ProV25.11

Display version:
1.35.9.29

Uninstall string:
C:\Program Files (x86)\CinemaPro 1.5V25.11\Uninstall.exe /fcp=1


Remove uninstall.exe - Powered by Reason Core Security