youtubeacceleratorservice.exe

YouTube Accelerator

Goobzo LTD

This is part of the Goobzo YouTube Accelerator program which is a web browser extension that includes advertising in the form of injected coupons (based on the visited web page) as well as additional advertising. - "The Software provides a suite of browser features that customize and enhance your interaction with video and other various websites by rendering download button, graphics, text, or other functional or interactive content in your browser." The application youtubeacceleratorservice.exe by Goobzo has been detected as adware by 4 anti-malware scanners. It runs as a windows Service named “YouTubeAcceleratorService”. This file is typically installed with the program YouTube Accelerator by Goobzo Ltd. which is a potentially unwanted software program.
Publisher:
GOOBZO  (signed by Goobzo LTD)

Product:
YouTube Accelerator

Version:
3.3.9.4

MD5:
7bc722e83fa1f233404a874724b7a650

SHA-1:
f1cd3f0653b2c80b323d7e8c9a071a4e74c20fa5

SHA-256:
d5a16beed3842f8f91fbc082f4bed723e9bc07731f2d16c5a3536d0d1ce735e7

Scanner detections:
4 / 68

Status:
Adware

Analysis date:
4/26/2024 6:44:29 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
MalSign.Skodna
2014.0.3618

Reason Heuristics
PUP.Service.Goobzo.Z
14.8.8.2

Trend Micro House Call
TROJ_GEN.F47V1128
7.2.355

VIPRE Antivirus
Goobzo
24480

File size:
1.4 MB (1,502,056 bytes)

Product version:
3.3.9.4

Copyright:
Copyright © 2013 GOOBZO Ltd.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\youtubeacceleratorservice.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/2/2013 2:00:00 AM

Valid to:
5/3/2015 1:59:59 AM

Subject:
CN=Goobzo LTD, O=Goobzo LTD, L=Haifa, S=Israel, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
120B25DDE57B88636AD4D97D23B99C88

File PE Metadata
Compilation timestamp:
11/25/2013 2:24:12 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
83.82

CTPH (ssdeep):
24576:IG6oQHV3GShHckW3GETkBgoIBQlhfZVJRLDte5xmsrv3goeLnZq3:IJ13GS5W3GETYjImRLDOxmKfIY

Entry address:
0xB436F

Entry point:
E8, E0, D7, 00, 00, E9, 16, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, 55, 8B, EC, 57, 56, 8B, 75, 0C, 8B, 4D, 10, 8B, 7D, 08, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, A4, 01, 00, 00, 81, F9, 00, 01, 00, 00, 72, 1F, 83, 3D, 24, 13, 52, 00, 00, 74, 16, 57, 56, 83, E7, 0F, 83, E6, 0F, 3B, FE, 5E, 5F, 75, 08, 5E, 5F, 5D, E9, A8, D8, 00, 00, F7, C7, 03, 00, 00, 00, 75, 15, C1, E9, 02, 83, E2, 03, 83, F9, 08, 72, 2A, F3, A5, FF, 24, 95, F4, 44, 4B, 00, 90, 8B, C7, BA, 03, 00, 00, 00, 83, E9, 04, 72...
 
[+]

Code size:
708 KB (724,992 bytes)

Service
Display name:
YouTubeAcceleratorService

Type:
Win32OwnProcess, InteractiveProcess


The file youtubeacceleratorservice.exe has been discovered within the following program.

YouTube Accelerator  by Goobzo Ltd.
Bundles and includes itself various adware toolbars that are designed to modify the user's web browser search settings and home page as well as inject advertising in the browser in the form of coupons/deals, banners and text links as well as 'download' buttons.
www.youtubeaccelerator.com/support
74% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-107-20-238-80.compute-1.amazonaws.com  (107.20.238.80:80)

TCP (HTTP):
Connects to ec2-50-18-63-239.us-west-1.compute.amazonaws.com  (50.18.63.239:80)

Remove youtubeacceleratorservice.exe - Powered by Reason Core Security