Goodware

Publisher Information

Goodware is a software publisher located in Bellevue, Washington in the United States*. The company is a primary distributor of unwanted software. There is one additional code signing certificate issued to this publisher.
Remove Goodware Malware - Powered by Reason Core Security
Authority:
GoDaddy.com, Inc.

Valid from:
6/11/2013 11:48:47 PM

Valid to:
6/7/2014 12:17:21 PM

Subject:
CN=Goodware, O=Goodware, L=Bellevue, S=WA, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
280598dc6499bd

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Goodware.H, PUP.Goodware.X, PUP.Goodware.V, PUP.Goodware.R, PUP.Goodware.W, PUP.Goodware.L, PUP.Goodware.T, PUP.Installer.Goodware, PUP.Goodware.Installer (M)
100.00%

VIPRE Antivirus
Trojan.Win32.Generic, Adinstaller.Goodware/SmartInstaller, Threat.4835496
60.87%

Sophos
Generic PUA ME, Goodware Installer, PUA 'Goodware Installer' (of type Adware)
60.87%

McAfee
Artemis!BE1E8640E8B0, RDN/Generic Downloader.x!iq, Artemis!0F9AD143417C, Artemis!1D6D203FB9D0, Artemis!6C8F9B709A4F, Artemis!32995018C8C7, Artemis!4D71BDC1D047, Artemis!7C1963E3E113
52.17%

Malwarebytes
PUP.Optional.Campaign.A, PUP.Optional.Goodware
52.17%

Dr.Web
Adware.Downware.1235, Trojan.DownLoader9.5149, Trojan.DownLoader9.18811, Adware.Downware.7940, Trojan.DownLoader9.22154
47.83%

Norman
Suspicious_Gen4.FONJK, Downloader
47.83%

McAfee Web Gateway
Artemis!BE1E8640E8B0, RDN/Generic Downloader.x!iq, Artemis!0F9AD143417C, Artemis!1D6D203FB9D0, Artemis!6C8F9B709A4F, Artemis!32995018C8C7
47.83%

Trend Micro House Call
TROJ_GEN.R0CBC0OLR13, TROJ_GEN.F47V0130, TROJ_GEN.F47V1113, TROJ_GEN.F47V1109, TROJ_GEN.F47V1110, Suspicious_GEN.F47V0701
39.13%

ESET NOD32
NSIS/TrojanDownloader.Agent.NOD, Win32/SmartInstaller
21.74%

1 / 68      (Adware)
ultracleaner_269035.exe  (570afff167f5915d5e4481aa956cfc32)

1 / 68      (Adware)
Setup.exe  (d2e704dd8df706d4fcb7b58823322e8b)

1 / 68      (Adware)
myshoppingtools_235539.exe  (9c4b081eccef54b3548c5785c8aba985)

1 / 68      (Adware)
jobowl_222844.exe  (d3b34b911bf370f87e5a682714ce64ae)

1 / 68      (Adware)
Setup.exe  (f1c77f3694219ad502b4e64b4acc697a)

1 / 68      (Adware)
jewelquest_245162.exe  (c0d96f86d1b442331d30851fc6fbaaa4)

8 / 68      (Adware)
zooanimals_236915a.exe  (7c1963e3e1135e09839af0423d5e1cc2)

9 / 68      (Adware)
aroundtheworld_252258.exe  (4d71bdc1d047363e3518ba45914bbd64)

2 / 68      (Adware)
retrophaser_138202.exe  (661f624c6ca167d503faf43caf98974c)

10 / 68    (Adware)
optimizerpro_251011.exe  (71c10e7a7a18427586e72aaa7df7f2c1)

6 / 68      (Adware)
mahjong_262066.exe  (c781faeb59741a49bdc50ed8418e6dee)

11 / 68    (Adware)
thehiddenworld_244191.exe  (6691ae22f5bdbfbe9c57039e1fe1775c)

7 / 68      (Adware)
news_p062413_197255.exe  (5d8793c13d7c21f3f5f6f1d5ef1f556c)

8 / 68      (Adware)
heroesofhellas_252259.exe  (32995018c8c79dccc3a344cc097d18ac)

23 / 68    (Adware)
execcomponent1.exe  (b2aa689491a5f898ef711eca52e0b1fc)

2 / 68      (Adware)
screensaver_pro_276881.exe  (4bb58d7c5dd02a37e8a299ac92f05b90)

8 / 68      (Adware)
RealPlayer_253539.exe  (6c8f9b709a4fde328f5911b038d83b75)

8 / 68      (Adware)
AroundtheWorld_252258.exe  (1d6d203fb9d044712e0c6548fcea3fd4)

8 / 68      (Adware)
HiddenWorldofArt_251013.exe  (0f9ad143417c1490409dffcc0357439d)

13 / 68    (Adware)
hiddenworldofart_249341.exe  (dc888e9a06434d567eb276924275e8d3)

4 / 68      (Adware)
compete.exe  (416035ff4e5e9d076c731d3d7402d24a)

20 / 68    (Adware)
compete.exe  (7d306c9e07dcb0741731fc8b8f1f010d)

20 / 68    (Adware)
compete.exe  (0130254b945f464ad3dcc4f7d95997f5)

Downloads URLs for files signed by Goodware.

20 / 68    (Adware)

6 / 68      (Adware)
http://cloudnet2.com/.../mahjong_262066.exe  (c781faeb59741a49bdc50ed8418e6dee)

8 / 68      (Adware)
http://www.cloudnet2.com/.../RealPlayer_253539.exe  (6c8f9b709a4fde328f5911b038d83b75)

8 / 68      (Adware)
http://cloudnet2.com/.../AroundtheWorld_252258.exe  (1d6d203fb9d044712e0c6548fcea3fd4)

8 / 68      (Adware)
http://cloudnet2.com/.../HiddenWorldofArt_251013.exe  (0f9ad143417c1490409dffcc0357439d)

The following websites host and distribute files published by Goodware.

The following certificate is also signed by Goodware.

2B195A2F4FE730  (Jan 17, 2014 to Jan 15, 2015)

The following publishers (by Authenticode signature organization name) are related.

Remove Goodware Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Goodware by GoDaddy.com, Inc. on June 11, 2013 with the serial number '280598dc6499bd'.