Goodware

Publisher Information

Goodware is a software publisher located in Bellevue, Washington in the United States*. The company is a primary distributor of unwanted software. There is one additional code signing certificate issued to this publisher.
Remove Goodware Malware - Powered by Reason Core Security
Authority:
Starfield Technologies, Inc.

Valid from:
1/17/2014 12:03:03 PM

Valid to:
1/15/2015 4:26:56 PM

Subject:
CN=Goodware, O=Goodware, L=Bellevue, S=Washington, C=US

Issuer:
CN=Starfield Secure Certificate Authority - G2, OU=http://certs.starfieldtech.com/repository/, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2b195a2f4fe730

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Goodware.L, PUP.Goodware.K, PUP.Installer.Goodware.N, PUP.Goodware.Q, PUP.Goodware.V, PUP.Goodware.W, PUP.Goodware.Installer (M)
100.00%

Sophos
Goodware Installer, PUA 'Goodware Installer' (of type Adware), Goodware Installer (PUA)
69.57%

McAfee Web Gateway
BehavesLike.Win32.Sality.fc, BehavesLike.Win32.CryptDoma.jc, BehavesLike.Win32.Downloader.jc, BehavesLike.Win32.Dropper.bc, BehavesLike.Win32.BadFile.jc, BehavesLike.Win32.BadFile.bc, BehavesLike.Win32.BadFile.cc, BehavesLike.Win32.Suspicious.bc, Artemis
50.00%

Trend Micro House Call
TROJ_GEN.F47V0325, Suspicious_GEN.F47V0820, Suspicious_GEN.F47V1115, Suspicious_GEN.F47V1216, Suspicious_GEN.F47V1230, Suspicious_GEN.F47V1210, Suspicious_GEN.F47V0111, TROJ_GEN.R02SH07BH15, Suspicious_GEN.F47V0703, TROJ_GEN.R02SH07BG15, Suspicious_GEN.F47V1122
39.13%

McAfee
Artemis!098D5CDFD46A, Artemis!FEAFFB352AA4, Artemis!891FCD4127AE, Artemis!CC4DEFFC4E92, Artemis!F1D63292EC2C, Artemis!53B31914F941, Artemis!007A6604C10A, Artemis!5886F23F5D3A, Artemis!DB2341E5E5C6
21.74%

avast!
Win32:Malware-gen
2.17%

Dr.Web
Trojan.DownLoader11.27320
2.17%

1 / 68      (Adware)
angel_ascent_276267.exe  (7d9e90d7d2dd15605cb645605fb06f50)

1 / 68      (Adware)
Setup.exe  (add6b8b9b0bdde436ba342a4016c0e86)

1 / 68      (Adware)
Setup.exe  (0fc0a097b7b2b10c7176d74eb06ea6cf)

1 / 68      (Adware)
ytdownloader_282896.exe  (0b0a4af4b6f7d73916c9f438c647343f)

1 / 68      (Adware)
pdf_converter_281059.exe  (670a629e8fa5872eea98f8a9cf239e8f)

1 / 68      (Adware)
2dto3d_270194.exe  (f4075b4456b260477efa98057f49dfb8)

1 / 68      (Adware)
1500survey_286406.exe  (3e607d112e23a25d45dc8471fa336db0)

1 / 68      (Adware)
youtubedownloader_289286.exe  (ca9f335d1d750dc43a133608a6e16003)

1 / 68      (Adware)
ytlightsout_271925.exe  (b5bf9dcce12e492da9f11a0a61e52514)

1 / 68      (Adware)
Setup.exe  (068ba38fe4993f8613c3d1fab0ef93bc)

1 / 68      (Adware)
angel_chick_276267.exe  (42215444d92a5835ebd39941fdb3a46a)

2 / 68      (Adware)
helicopter_274098.exe  (e6090af52043d92b2907fd7e86942d49)

4 / 68      (Adware)
sonicsurfer_220917.exe  (fed60d5cff7ea82804b787b9a5dcb984)

3 / 68      (Adware)
Setup.exe  (53b435755259982655d91b58debe6a64)

4 / 68      (Adware)
hiddenworldofart_249341.exe  (096310b4d70992d584ec4f68ee419a1b)

3 / 68      (Adware)
cookingdash_264420.exe  (a7eb8105486a2c229fe7e3f0b515744a)

3 / 68      (Adware)
azteca_mystery_250876.exe  (e7b00a4ffe92b9daece72e621b335d15)

3 / 68      (Adware)
viraltube_196565.exe  (c0fd7e9df92a864b8f789eb0ccb093cb)

2 / 68      (Adware)
youtube_autowide_271957.exe  (f0bba0b6a4e8d937afea047d704130b9)

3 / 68      (Adware)
smart_driver_288924.exe  (877a41276706882b5ebcb2d52cbe3f6c)

3 / 68      (Adware)
optimizerpro_245913.exe  (65c34ac44805b4fea0b46f65c3101337)

3 / 68      (Adware)
megacoupons_224453.exe  (c1f6a7dc5dd1881f313fbcb98e293cc2)

4 / 68      (Adware)
arcadefever_237484.exe  (a9a3566050c47e6fb0d0ecbfa2aa6619)

5 / 68      (Adware)
zoo_animals_236915.exe  (db2341e5e5c62e4e906cfa3670f8caf8)

5 / 68      (Adware)
tube2file_205731.exe  (5886f23f5d3a8ae83a1dea6f873b71b5)

3 / 68      (Adware)
youtubewide_271957.exe  (660141427d6a94d6b26ae9a0a9fd163d)

3 / 68      (Adware)
sin confirmar 513166.crdownload  (249bfaa9ab5df4f317e2755428f71c3c)

3 / 68      (Adware)
phantasmat_262834.exe  (9c0c891c49e9dc605c72715e8393b7fd)

5 / 68      (Adware)
optimizerpro_251011.exe  (007a6604c10acb4c95a651348f1be1ac)

3 / 68      (Adware)
screenstudio_276881.exe  (149aaa34a9c5fd4b7ebeba1240789149)

 
Latest 30 of 46 files

Downloads URLs for files signed by Goodware.

1 / 68      (Adware)
http://cloudnet4.us/.../YouTubeDownloader_289286.exe  (ca9f335d1d750dc43a133608a6e16003)

1 / 68      (Adware)
http://cloudnet4.us/.../YTLightsOut_271925.exe  (b5bf9dcce12e492da9f11a0a61e52514)

1 / 68      (Adware)
http://cloudnet2.com/.../Angel_Chick_276267.exe  (42215444d92a5835ebd39941fdb3a46a)

5 / 68      (Adware)
http://cloudnet4.us/.../YouTubeHD_272054.exe  (f1d63292ec2cb0d32871655990003c41)

5 / 68      (Adware)
http://cloudnet4.us/.../OptimizerPro_251011.exe  (007a6604c10acb4c95a651348f1be1ac)

3 / 68      (Adware)
http://cloudnet4.us/.../Jewel_Quest_245162.exe  (14909c0f8ba8787f8aa609b59b2c8aaa)

5 / 68      (Adware)
http://cloudnet4.us/.../RiseofAtlantis_252256.exe  (cc4deffc4e92eb4dc3b9a796c6a2f086)

4 / 68      (Adware)
http://cloudnet4.us/.../ChickAscent_276267.exe  (8187e2b654f60580bb43d74ef562aa70)

3 / 68      (Adware)
http://cloudnet4.us/.../Mighty_Converter_208061.exe  (78c1e813947336c84c935e806cdf1b68)

2 / 68      (Adware)
http://cloudnet4.us/.../HoverHeli_274098.exe  (d27057b549d2596191273f84e349473a)

2 / 68      (Adware)
http://cloudnet2.com/.../2d3d_270194.exe  (7be6cd53c6d3b4c0362cd38febd4727f)

The following websites host and distribute files published by Goodware.

The following certificate is also signed by Goodware.

280598DC6499BD  (Jun 12, 2013 to Jun 07, 2014)

The following publishers (by Authenticode signature organization name) are related.

Remove Goodware Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Goodware by Starfield Technologies, Inc. on January 17, 2014 with the serial number '2b195a2f4fe730'.