youtubeacceleratorservice.exe

YouTube Accelerator

Goobzo LTD

This is part of the Goobzo YouTube Accelerator program which is a web browser extension that includes advertising in the form of injected coupons (based on the visited web page) as well as additional advertising. - "The Software provides a suite of browser features that customize and enhance your interaction with video and other various websites by rendering download button, graphics, text, or other functional or interactive content in your browser." The application youtubeacceleratorservice.exe by Goobzo has been detected as adware by 4 anti-malware scanners. It runs as a windows Service named “YouTubeAcceleratorService”. This file is typically installed with the program YouTube Accelerator by Goobzo Ltd. which is a potentially unwanted software program.
Publisher:
GOOBZO  (signed by Goobzo LTD)

Product:
YouTube Accelerator

Version:
3.3.9.5

MD5:
6acae9ebdadc351d114e38601ca2d88a

SHA-1:
1a5098fbf2e3caaef8ebe374489c7cf90d36dfbb

SHA-256:
a23df8849b2c317581442fd0840a2cb9a2dbcbe4a99286d29ed35cdaba2979ef

Scanner detections:
4 / 68

Status:
Adware

Analysis date:
4/20/2024 4:33:23 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
MalSign.Skodna
2015.0.3603

Reason Heuristics
PUP.Service.Goobzo.Z
14.8.8.2

Trend Micro House Call
TROJ_GEN.F47V1222
7.2.7

VIPRE Antivirus
Goobzo
25190

File size:
1.4 MB (1,502,056 bytes)

Product version:
3.3.9.5

Copyright:
Copyright © 2013 GOOBZO Ltd.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\youtubeacceleratorservice.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/2/2013 2:00:00 AM

Valid to:
5/3/2015 1:59:59 AM

Subject:
CN=Goobzo LTD, O=Goobzo LTD, L=Haifa, S=Israel, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
120B25DDE57B88636AD4D97D23B99C88

File PE Metadata
Compilation timestamp:
12/19/2013 11:48:58 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
83.82

CTPH (ssdeep):
24576:QG6oQHV3GShHckWSGETkBroI0Axjn/zB4eijIBlmsrv3goeLpEui0:QJ13GS5WSGETYsIR4ei+lmKfF0

Entry address:
0xB436F

Entry point:
E8, E0, D7, 00, 00, E9, 16, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, 55, 8B, EC, 57, 56, 8B, 75, 0C, 8B, 4D, 10, 8B, 7D, 08, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, A4, 01, 00, 00, 81, F9, 00, 01, 00, 00, 72, 1F, 83, 3D, 24, 13, 52, 00, 00, 74, 16, 57, 56, 83, E7, 0F, 83, E6, 0F, 3B, FE, 5E, 5F, 75, 08, 5E, 5F, 5D, E9, A8, D8, 00, 00, F7, C7, 03, 00, 00, 00, 75, 15, C1, E9, 02, 83, E2, 03, 83, F9, 08, 72, 2A, F3, A5, FF, 24, 95, F4, 44, 4B, 00, 90, 8B, C7, BA, 03, 00, 00, 00, 83, E9, 04, 72...
 
[+]

Entropy:
7.1809

Code size:
708 KB (724,992 bytes)

Service
Display name:
YouTubeAcceleratorService

Type:
Win32OwnProcess, InteractiveProcess


The file youtubeacceleratorservice.exe has been discovered within the following program.

YouTube Accelerator  by Goobzo Ltd.
Bundles and includes itself various adware toolbars that are designed to modify the user's web browser search settings and home page as well as inject advertising in the browser in the form of coupons/deals, banners and text links as well as 'download' buttons.
www.youtubeaccelerator.com/support
74% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-54-197-238-106.compute-1.amazonaws.com  (54.197.238.106:80)

TCP (HTTP):
Connects to ec2-107-20-238-80.compute-1.amazonaws.com  (107.20.238.80:80)

Remove youtubeacceleratorservice.exe - Powered by Reason Core Security