Goobzo LTD

Publisher Information

Goobzo LTD is a software publisher located in Haifa, Israel*. The company is a primary distributor of adware type software.
Authority:
Thawte, Inc.

Valid from:
5/2/2013 3:30:00 AM

Valid to:
5/3/2015 3:29:59 AM

Subject:
CN=Goobzo LTD, O=Goobzo LTD, L=Haifa, S=Israel, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
120b25dde57b88636ad4d97d23b99c88

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Crossrider.Goobzo.h, PUP.Goobzo.e, PUP.Crossrider.Goobzo.R, PUP.Crossrider.Goobzo.Z, PUP.Crossrider.Goobzo.BB, Adware.Goobzo.J, PUP.Goobzo.G, PUP.Task.Goobzo.L, Adware.Goobzo.ShopperPro.I, PUP.Goobzo.I, Adware.Task.Goobzo.K, Adware.Revizor.Task.H, PUP.BHO.Goobzo.K, PUP.Goobzo.M
100.00%

VIPRE Antivirus
Crossrider, Threat.4792716, Goobzo
98.00%

AVG
Skodna, MalSign.Skodna
98.00%

Panda Antivirus
Adware/Goobzo, W32/Cosmu.E, Trj/Chgt.H, Generic Malware, Generic Suspicious
94.00%

Kaspersky
not-a-virus:WebToolbar.Win32.CrossRider, not-a-virus:AdWare.NSIS.Adwapper, not-a-virus:AdWare.Win32.Shopper, not-a-virus:Downloader.NSIS.Agent
94.00%

Baidu Antivirus
PUA.Win64.Crossrider, PUA.Win32.CrossRider, Adware.Win32.CrossRider, Adware.Win32.CrossAd, Adware.Win32.Shopper, Trojan.Win32.ShopperPro
88.00%

AhnLab V3 Security
Win-PUP/CrossRider, PUP/Win32.MulDrop, Win32/Kashu.E, PUP/Win32.CrossRider
80.00%

K7 Gateway Antivirus
Unwanted-Program , Virus , Trojan , Riskware
74.00%

G Data
Win32.Adware.Crossrider, Gen:Variant.Adware.Kazy.374109, Gen:Application.Heur.zy5@ka2B5Yfi, Win32.Application.Shopperpro
72.00%

ESET NOD32
Win64/Toolbar.Crossrider (variant), Win32/SBWatchman (variant), Win64/ShopperPro (variant), Win32/ShopperPro (variant), MSIL/SBWatchman (variant)
68.00%

21 / 68    (Adware)
dcytaiesmt_smtyc_setup.exe  (73f523132c75e394577287b8c999452a)

8 / 68      (Adware)
sysmenu64.dll (by Goobzo)  (1d355de14bbaef2993aaf2ca619fba9a)

26 / 68    (Adware)
SBMNTR.sys (YTDownloader Driver by YTDownloader)  (6504b2a5290f8263f99a4d871f62be84)

12 / 68    (Adware)
tu17p84.exe  (aa9b0cd209ac9fc7bb2d0554f6583daa)

12 / 68    (Adware)
tu17p84.exe  (52f2759f9d28057278fd18370ea57850)

11 / 68    (Adware)
tu17p84.exe  (44952e2b8000e26a97ffc0d9af679c80)

25 / 68    (Adware)
setup.exe (Shopper-Pro)  (4110dfd0ec427aeb4fde843933627313)

11 / 68    (Adware)
downloadapi.dll (DownloadAPI by YTDownloader)  (cc8a176c0010347d7fed2fca349c223c)

15 / 68    (Adware)
spremove.exe  (b79507432e49ec7b9f3f88333802a98f)

14 / 68    (Adware)
ytduninstall.exe  (60726b8162f26233d5617ae887f04286)

15 / 68    (Adware)
downloadhelper.exe (YTDownloader)  (9e92bfd35606d28288c6e44ed10ad34d)

12 / 68    (Adware)

21 / 68    (Adware)
shopperpro64.dll (ShopperPro Extension by Goobzo)  (72fb66001420003e20d32bd636628059)

27 / 68    (Adware)
ShopperPro.dll (ShopperPro Extension by Goobzo)  (e98027a81abae7dd77d8ad652ff2dae4)

32 / 68    (Adware)
Updater.exe (Update Helper by Goobzo)  (f11c55ff845ed376a7a6e768344c1f23)

32 / 68    (Adware)
Updater.exe (Update Helper by Goobzo)  (afe2a9948a53c472194c7f654eaf5b69)

15 / 68    (Adware)
shopperpro.exe (by Goobzo)  (a33c9074cb9f582ceaea830cc0015994)

27 / 68    (Adware)
SBMNTR.sys (YTDownloader Driver by YTDownloader)  (b8754f330d26b589a36c0198a62bb26b)

22 / 68    (Adware)
jsdrv.sys (JsDriver)  (a3f766d168932cb639733b942c03eb46)

16 / 68    (Adware)
YTDownloader.exe (YTDownloader)  (c6b608a82a4923be451aa45eb85937ae)

23 / 68    (Adware)
jsdrv.sys (JsDriver)  (3273becbb7625c49671d9c72f553fa34)

9 / 68      (Adware)
SysMenu.dll (by Goobzo)  (8a56d8a32430e99da19e2d265dc042f3)

11 / 68    (Adware)
spbiw.sys  (feda52f93ab17b2c8887187bded3646b)

23 / 68    (Adware)
spbiu.exe (SBWatchman by ShopperPro)  (faf6ab23695222f55c6eb08cb094e151)

32 / 68    (Adware)
Updater.exe (Update Helper by Goobzo)  (ba12b3d886f46702856412f71748ca9b)

16 / 68    (Adware)
YTDownloader.exe (YTDownloader)  (90739c9b646ba4d58dc15c8f18282e78)

26 / 68    (Adware)
SBMNTR.sys (YTDownloader Driver by YTDownloader)  (6c349b3e49978f4aab1f91698eb423b1)

12 / 68    (Adware)
dc1ab11rn50.exe  (dcb59ef46d837a8d281173cdca231c2b)

13 / 68    (Adware)
spremove.exe  (c4e73f0019a5ab322c244a41047db966)

8 / 68      (Adware)
sysmenu64.dll (by Goobzo)  (c0bf65790682b0c5081126584cd15dc8)

 
Latest 30 of 6,988 files

The following publishers (by Authenticode signature organization name) are related.

Detection Incidence by Country
* Note, the details and description above are based on the code signing digital signature issued to Goobzo LTD by Thawte, Inc. on May 02, 2013 with the serial number '120b25dde57b88636ad4d97d23b99c88'.