uninstall.exe

Goobzo LTD

The application uninstall.exe by Goobzo has been detected as adware by 11 anti-malware scanners. This is the uninstaller utility registered in the Windows Control Panel for the program iWebar by iWebar. This file is typically installed with the program iWebar by iWebBar which is a potentially unwanted software program. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
Goobzo LTD  (signed and verified)

MD5:
bf870774b38b013989c3b5362b2f17f9

SHA-1:
14d4bd9d26c71d3966f9f5be6716c2688be05263

SHA-256:
0ba0c97610cdc5527c9287a3eebe74aedc2fc05740e7f2732f242699e48dc6ec

Scanner detections:
11 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
4/25/2024 10:34:08 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Skodna
2015.0.3336

Baidu Antivirus
Adware.Win32.CrossRider
4.0.3.14930

Dr.Web
Trojan.Crossrider.27207
9.0.1.05190

G Data
Win32.Application.Shopperpro
14.9.24

K7 AntiVirus
Unwanted-Program
13.183.13521

Kaspersky
not-a-virus:WebToolbar.Win32.CrossRider
15.0.0.494

NANO AntiVirus
Riskware.Win32.AdLoad.dcushc
0.28.2.62440

Panda Antivirus
Adware/Goobzo
14.09.30.04

Reason Heuristics
PUP.Goobzo.J
14.9.30.4

Vba32 AntiVirus
AdWare.AdLoad
3.12.26.3

VIPRE Antivirus
Threat.4792716
33120

File size:
100.9 KB (103,280 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\iwebar\uninstall.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/2/2013 4:00:00 AM

Valid to:
5/3/2015 3:59:59 AM

Subject:
CN=Goobzo LTD, O=Goobzo LTD, L=Haifa, S=Israel, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
120B25DDE57B88636AD4D97D23B99C88

File PE Metadata
Compilation timestamp:
7/9/2014 2:10:16 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
1536:k5+oxR7qWiOXfeHBU+sUt4T84bz90YcuesWjcdSOkWKC:1o79f62+Ft8PBSxWT

Entry address:
0x57C2

Entry point:
E8, EB, 63, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 58, 6F, 41, 00, E8, 28, 0A, 00, 00, E8, 87, 24, 00, 00, 0F, B7, F0, 6A, 02, E8, 7E, 63, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 5F, 5D, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.3776

Code size:
67.5 KB (69,120 bytes)

Program Uninstaller
Program name:
iWebar

Display publisher:
iWebar

Display version:
1.34.7.1

Uninstall string:
C:\Program Files (x86)\iWebar\Uninstall.exe /fcp=1


The file uninstall.exe has been discovered within the following program.

iWebar  by iWebBar
iWebar is a web browser extension and toolbar that delivers contextual based advertising as well as modify the user's web browser home and search pages to provide advertising and search.
80% remove it
 
Powered by Should I Remove It?

Remove uninstall.exe - Powered by Reason Core Security