youtubeacceleratorservice.exe

YouTube Accelerator

Goobzo LTD

This is part of the Goobzo YouTube Accelerator program which is a web browser extension that includes advertising in the form of injected coupons (based on the visited web page) as well as additional advertising. - "The Software provides a suite of browser features that customize and enhance your interaction with video and other various websites by rendering download button, graphics, text, or other functional or interactive content in your browser." The application youtubeacceleratorservice.exe by Goobzo has been detected as adware by 3 anti-malware scanners. It runs as a windows Service named “YouTubeAcceleratorService”. This file is typically installed with the program YouTube Accelerator by Goobzo Ltd. which is a potentially unwanted software program.
Publisher:
GOOBZO  (signed by Goobzo LTD)

Product:
YouTube Accelerator

Version:
3.3.9.3

MD5:
cc8f3ce2f901d567edf39e30b0354d9d

SHA-1:
eaf84bfffdb26d431bfb58e0276e4f3f41f1ebe2

SHA-256:
82ad1414c2c26e87aca8b2d709e33b7bac7784a10f5fad948cf80baef2317a1d

Scanner detections:
3 / 68

Status:
Adware

Analysis date:
4/20/2024 2:05:04 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
MalSign.Skodna
2014.0.3614

Reason Heuristics
PUP.Service.Goobzo.Z
14.8.8.2

VIPRE Antivirus
Goobzo
23726

File size:
1.4 MB (1,502,056 bytes)

Product version:
3.3.9.3

Copyright:
Copyright © 2013 GOOBZO Ltd.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\youtubeacceleratorservice.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/2/2013 2:00:00 AM

Valid to:
5/3/2015 1:59:59 AM

Subject:
CN=Goobzo LTD, O=Goobzo LTD, L=Haifa, S=Israel, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
120B25DDE57B88636AD4D97D23B99C88

File PE Metadata
Compilation timestamp:
11/6/2013 4:48:16 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
83.82

CTPH (ssdeep):
24576:SG6oQHV3GShHckW2GETkBvcIIOkjaHxMCQjkeOJmsrv3goeL2UhGp:SJ13GS5W2GETYUIWCQj8JmKfChGp

Entry address:
0xB436F

Entry point:
E8, E0, D7, 00, 00, E9, 16, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, 55, 8B, EC, 57, 56, 8B, 75, 0C, 8B, 4D, 10, 8B, 7D, 08, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, A4, 01, 00, 00, 81, F9, 00, 01, 00, 00, 72, 1F, 83, 3D, 24, 13, 52, 00, 00, 74, 16, 57, 56, 83, E7, 0F, 83, E6, 0F, 3B, FE, 5E, 5F, 75, 08, 5E, 5F, 5D, E9, A8, D8, 00, 00, F7, C7, 03, 00, 00, 00, 75, 15, C1, E9, 02, 83, E2, 03, 83, F9, 08, 72, 2A, F3, A5, FF, 24, 95, F4, 44, 4B, 00, 90, 8B, C7, BA, 03, 00, 00, 00, 83, E9, 04, 72...
 
[+]

Code size:
708 KB (724,992 bytes)

Service
Display name:
YouTubeAcceleratorService

Type:
Win32OwnProcess, InteractiveProcess


The file youtubeacceleratorservice.exe has been discovered within the following program.

YouTube Accelerator  by Goobzo Ltd.
Bundles and includes itself various adware toolbars that are designed to modify the user's web browser search settings and home page as well as inject advertising in the browser in the form of coupons/deals, banners and text links as well as 'download' buttons.
www.youtubeaccelerator.com/support
74% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to ec2-54-197-238-106.compute-1.amazonaws.com  (54.197.238.106:80)

Remove youtubeacceleratorservice.exe - Powered by Reason Core Security