uninstall.exe

Goobzo LTD

The application uninstall.exe by Goobzo has been detected as adware by 21 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. This is the uninstaller utility registered in the Windows Control Panel for the program iWebar by iWebar. This file is typically installed with the program iWebar by iWebBar which is a potentially unwanted software program. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
Goobzo LTD  (signed and verified)

MD5:
c73a139300e99a39aba1a36038d5ddd2

SHA-1:
82b61b10504132fa5c5c6936d319ef48c8d2df40

SHA-256:
bcaff24447a7143702340fc9a563c0670cde3c13811de709a6d73ca572fd73b2

Scanner detections:
21 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
4/26/2024 8:33:09 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win-PUP/CrossRider
2015.05.19

Avira AntiVirus
ADWARE/CrossRider.Gen7
7.11.186.88

avast!
Win32:Adware-gen [Adw]
2014.9-150423

AVG
Skodna
2016.0.3131

Baidu Antivirus
Adware.Win32.CrossAd
4.0.3.15423

Dr.Web
Trojan.Crossrider.27207
9.0.1.0113

ESET NOD32
Win32/Toolbar.CrossRider.AW potentially unwanted (variant)
9.11650

Fortinet FortiGate
Riskware/CrossRider
7/24/2015

G Data
Gen:Application.Heur.gqX@lmg7S9pi
15.4.25

IKARUS anti.virus
Trojan.GoogUpdate
t3scan.1.8.9.0

K7 AntiVirus
Unwanted-Program
13.185.14021

Kaspersky
not-a-virus:WebToolbar.Win32.CrossRider
14.0.0.2148

McAfee
Artemis!C73A139300E9
5600.6787

NANO AntiVirus
Riskware.Win32.AdLoad.dfqwab
0.28.6.63362

Panda Antivirus
PUP/CrossRider
15.04.23.09

Qihoo 360 Security
Win32/Virus.WebToolbar.ffe
1.0.0.1015

Reason Heuristics
Threat.Goobzo.Installer
15.4.23.5

Rising Antivirus
PE:Malware.Adload!6.1D9D
23.00.65.15722

Vba32 AntiVirus
AdWare.AdLoad
3.12.26.4

VIPRE Antivirus
Goobzo
34832

Zillya! Antivirus
Adware.CroRi.Win32.823
2.0.0.1983

File size:
100.4 KB (102,768 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\iwebar\uninstall.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/2/2013 2:00:00 AM

Valid to:
5/3/2015 1:59:59 AM

Subject:
CN=Goobzo LTD, O=Goobzo LTD, L=Haifa, S=Israel, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
120B25DDE57B88636AD4D97D23B99C88

File PE Metadata
Compilation timestamp:
6/19/2014 12:03:19 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
1536:iswP0BK1NZ5k7Wfix/jTZ2qTjT3ubC7ua6NcuesWjcdScAWL:MSyrRfil3wqTvaRBSHWL

Entry address:
0x5614

Entry point:
E8, E9, 63, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 58, 6F, 41, 00, E8, 26, 0A, 00, 00, E8, 85, 24, 00, 00, 0F, B7, F0, 6A, 02, E8, 7C, 63, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 5D, 5D, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
67 KB (68,608 bytes)

Program Uninstaller
Program name:
iWebar

Display publisher:
iWebar

Display version:
1.34.6.10

Uninstall string:
C:\Program Files (x86)\iWebar\Uninstall.exe /fcp=1


The file uninstall.exe has been discovered within the following program.

iWebar  by iWebBar
iWebar is a web browser extension and toolbar that delivers contextual based advertising as well as modify the user's web browser home and search pages to provide advertising and search.
80% remove it
 
Powered by Should I Remove It?

Remove uninstall.exe - Powered by Reason Core Security