uninstall.exe

Goobzo LTD

The application uninstall.exe by Goobzo has been detected as adware by 22 anti-malware scanners. This is the uninstaller utility registered in the Windows Control Panel for the program iWebar by iWebar. This file is typically installed with the program iWebar by iWebBar which is a potentially unwanted software program. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
Goobzo LTD  (signed and verified)

MD5:
d952b7abbd135129db1c9dd6da4b63ad

SHA-1:
43470ad3024a8016df9fd293d1a904c064391701

SHA-256:
e9ad57b78eaefde737388245ca341ab0426fcadcf7a4f67d7931b7d8c2a27e5d

Scanner detections:
22 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
4/19/2024 9:02:40 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Application.Heur.gqX@lC!gPcei
439

AhnLab V3 Security
PUP/Win32.CrossRider
2015.01.09

Avira AntiVirus
ADWARE/CrossRider.Gen7
7.11.200.58

avast!
Win32:Malware-gen
2014.9-151122

AVG
Skodna
2016.0.2917

Baidu Antivirus
PUA.Win32.CrossRider
4.0.3.151122

Bitdefender
Gen:Application.Heur.gqX@lC!gPcei
1.0.20.1630

Comodo Security
ApplicUnwnt
20646

Dr.Web
Trojan.Crossrider.27207
9.0.1.0326

ESET NOD32
Win32/Toolbar.CrossRider.AW (variant)
9.10985

F-Secure
Gen:Application.Heur.gqX@lC!gPcei
11.2015-22-11_1

G Data
Gen:Application.Heur.gqX@lC!gPcei
15.11.24

K7 AntiVirus
Unwanted-Program
13.190.14585

Kaspersky
not-a-virus:WebToolbar.Win32.CrossRider
14.0.0.1082

McAfee
Artemis!D952B7ABBD13
5600.6573

MicroWorld eScan
Gen:Application.Heur.gqX@lC!gPcei
16.0.0.978

NANO AntiVirus
Trojan.Win32.Crossrider.dhipqt
0.30.0.64448

Panda Antivirus
Adware/Goobzo
15.11.22.01

Qihoo 360 Security
HEUR/Malware.QVM10.Gen
1.0.0.1015

Reason Heuristics
PUP.Goobzo (M)
15.11.22.13

VIPRE Antivirus
Goobzo
36490

Zillya! Antivirus
Adware.CrossRider.Win32.275
2.0.0.2029

File size:
101.9 KB (104,304 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\iwebar\uninstall.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/1/2013 7:00:00 PM

Valid to:
5/2/2015 6:59:59 PM

Subject:
CN=Goobzo LTD, O=Goobzo LTD, L=Haifa, S=Israel, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
120B25DDE57B88636AD4D97D23B99C88

File PE Metadata
Compilation timestamp:
7/14/2014 8:27:01 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
1536:UYn7MV/4CiZQSQcK8wVSL9+0qezBKIc1F3sWjcdSPiYv:PKlcF79KDF4SPiE

Entry address:
0x5AD2

Entry point:
E8, 3B, 66, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 98, 7F, 41, 00, E8, 28, 0A, 00, 00, E8, CE, 32, 00, 00, 0F, B7, F0, 6A, 02, E8, CE, 65, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, AF, 5F, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.3907

Code size:
68.5 KB (70,144 bytes)

Program Uninstaller
Program name:
iWebar

Display publisher:
iWebar

Display version:
1.34.7.1

Uninstall string:
C:\Program Files (x86)\iWebar\Uninstall.exe /fcp=1


The file uninstall.exe has been discovered within the following program.

iWebar  by iWebBar
iWebar is a web browser extension and toolbar that delivers contextual based advertising as well as modify the user's web browser home and search pages to provide advertising and search.
80% remove it
 
Powered by Should I Remove It?

Remove uninstall.exe - Powered by Reason Core Security