uninstall.exe

Goobzo LTD

The application uninstall.exe by Goobzo has been detected as adware by 10 anti-malware scanners. This is the uninstaller utility registered in the Windows Control Panel for the program Object Browser by Object Browser. This file is typically installed with the program Object Browser which is a potentially unwanted software program. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
Goobzo LTD  (signed and verified)

MD5:
d42f0806114ca371d71c8b319e5d05d5

SHA-1:
14835467c9b70c6ad1a74bf2c12116f4cb3ee101

SHA-256:
7a2f663b4517cac395577a4a4a74266552da9cda4340fa912ff245f6764e88d3

Scanner detections:
10 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
4/18/2024 3:35:18 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Crypt.ZPACK.Gen2
7.11.167.196

AVG
Skodna
2016.0.2969

Baidu Antivirus
Adware.Win32.CrossAd
4.0.3.15102

Dr.Web
Trojan.Crossrider.28033
9.0.1.0275

G Data
Win32.Application.Shopperpro
15.10.24

IKARUS anti.virus
PUA.Plush
t3scan.1.7.5.0

Panda Antivirus
Adware/Goobzo
15.10.02.04

Reason Heuristics
PUP.Goobzo (M)
15.10.2.4

Rising Antivirus
PE:Malware.Obscure!1.9C59
23.00.65.15930

VIPRE Antivirus
Goobzo
32300

File size:
85.4 KB (87,408 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\object browser\uninstall.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/1/2013 5:00:00 PM

Valid to:
5/2/2015 4:59:59 PM

Subject:
CN=Goobzo LTD, O=Goobzo LTD, L=Haifa, S=Israel, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
120B25DDE57B88636AD4D97D23B99C88

File PE Metadata
Compilation timestamp:
8/11/2014 6:59:37 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
1536:IOWlv4pViZaoRPQKKDRclnrsWjcdHVlAw8:zWoV8aoBQQUHVlAx

Entry address:
0x4E8D

Entry point:
E8, 1E, 59, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 48, 2E, 41, 00, E8, 2D, 0A, 00, 00, E8, 8C, 24, 00, 00, 0F, B7, F0, 6A, 02, E8, B1, 58, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 92, 52, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.2279

Code size:
52 KB (53,248 bytes)

Program Uninstaller
Program name:
Object Browser

Display publisher:
Object Browser

Display version:
1.34.7.29

Uninstall string:
C:\Program Files\Object Browser\Uninstall.exe /fcp=1


The file uninstall.exe has been discovered within the following program.

Object Browser  by Object Browser
Object Browser is an adware style application that runs in the web browser as a toolbar and web extension.
66% remove it
 
Powered by Should I Remove It?

Remove uninstall.exe - Powered by Reason Core Security