uninstall.exe

Goobzo LTD

The application uninstall.exe by Goobzo has been detected as adware by 14 anti-malware scanners. This is the uninstaller utility registered in the Windows Control Panel for the program iWebar by iWebar. This file is typically installed with the program iWebar by iWebBar which is a potentially unwanted software program. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
Goobzo LTD  (signed and verified)

MD5:
cd706553f518e7383dd561f7fcb71dca

SHA-1:
b9032d8a970297fb5df7cb8198a7d32384fc5163

SHA-256:
81175a1effe92424d38e1a1a3f467c9554307799f98a9e93a8dd254b6b7fa387

Scanner detections:
14 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
5/10/2024 1:07:06 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Crypt.ZPACK.Gen2
7.11.30.172

AVG
Skodna
2015.0.3368

Baidu Antivirus
Adware.Win32.CrossAd
4.0.3.14829

Dr.Web
Trojan.Crossrider.28033
9.0.1.05190

G Data
Win32.Application.Shopperpro
14.8.24

IKARUS anti.virus
PUA.Plush
t3scan.1.7.5.0

NANO AntiVirus
Trojan.Win32.GoogUpdate.decypm
0.28.2.61861

Panda Antivirus
Adware/Goobzo
14.08.29.06

Qihoo 360 Security
HEUR/Malware.QVM10.Gen
1.0.0.1015

Reason Heuristics
PUP.Goobzo.J
14.8.29.3

Rising Antivirus
PE:Malware.Obscure!1.9C59
23.00.65.14827

Vba32 AntiVirus
Trojan.GoogUpdate
3.12.26.3

VIPRE Antivirus
Threat.4792716
32210

Zillya! Antivirus
Trojan.GoogUpdate.Win32.916
2.0.0.1905

File size:
85.4 KB (87,408 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\iwebar\uninstall.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/1/2013 5:00:00 PM

Valid to:
5/2/2015 4:59:59 PM

Subject:
CN=Goobzo LTD, O=Goobzo LTD, L=Haifa, S=Israel, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
120B25DDE57B88636AD4D97D23B99C88

File PE Metadata
Compilation timestamp:
8/11/2014 6:59:37 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
1536:FOWlv4pViZaoRPQKKoRclnrsWjcdHVlAc:EWoV8aoBQJUHVlAc

Entry address:
0x4E8D

Entry point:
E8, 1E, 59, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 48, 2E, 41, 00, E8, 2D, 0A, 00, 00, E8, 8C, 24, 00, 00, 0F, B7, F0, 6A, 02, E8, B1, 58, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 92, 52, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.2275

Code size:
52 KB (53,248 bytes)

Program Uninstaller
Program name:
iWebar

Display publisher:
iWebar

Display version:
1.34.7.29

Uninstall string:
C:\Program Files\iWebar\Uninstall.exe /fcp=1


The file uninstall.exe has been discovered within the following program.

iWebar  by iWebBar
iWebar is a web browser extension and toolbar that delivers contextual based advertising as well as modify the user's web browser home and search pages to provide advertising and search.
80% remove it
 
Powered by Should I Remove It?

Remove uninstall.exe - Powered by Reason Core Security