iWebar

iWebar

Known Toolbar

by iWebBar

What is iWebar?

iWebar is software application developed by iWebBar. It is most commonly found on computers running Windows 7 with nearly 60.26% of installations running this operating system. iWebar's installer is typically 6.00 MB in size and installs around 524 files. The most common release is 1.34.5.12 with 15.98% of all installations currently using this version.

iWebar is most popular in the United States with 41.12% of installations residing in this country.

iWebar adds 6 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About iWebar?

iWebar is an innovative web browser extension and toolbar designed to deliver targeted advertising and enhance the user's online experience. This software modifies the user's web browser home and search pages to provide relevant advertising and search capabilities, while also offering the functionality to change the default search engine and browser home page. The browser toolbar leverages the Crossrider cross-platform toolbar monetization platform to effectively deliver contextual advertising in the form of banner and text ads. Please note that while iWebar is a legitimate software, it may be categorized as a potentially unwanted application by certain malware vendors.

Multiple virus scanners have detected malware in iWebar.

utils.exe (MD5: 36b3933e6693e36587b7cbaa6d4fcf1a) has been flagged by 43 scanners:
Scanner Software Result
Baidu-International Trojan.Win32.Packed.ScrambleWrapper.C
ESET-NOD32 Win32/Packed.ScrambleWrapper.C
Symantec WS.Reputation
TrendMicro-HouseCall TROJ_GEN.F47V0716
Lavasoft Ad-Aware Gen:Variant.Adware.Graftor.151676
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL GrayWare[AdWare:not-a-virus]/NSIS.Adwapper.ai
avast! Win32:Crossrider-AK [PUP]
AVG Generic.D77
Avira Adware/CrossRider.pq
AVware Crossrider (fs)
Bitdefender Gen:Variant.Adware.Graftor.151676
CAT-QuickHeal AdWare.NSIS.r6 (Not a Virus)
Comodo Security ApplicUnwnt
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.151676 (B)
Fortinet FortiGate Adware/Adwapper
F-Prot W32/A-ee826839!Eldorado
F-Secure Gen:Variant.Adware.Graftor.151676
G Data Gen:Variant.Adware.Graftor.151676
IKARUS anti.virus AdWare.WebToolbar.CroRi
K7 AntiVirus Unwanted-Program ( 004a9d0d1 )
K7GW Unwanted-Program ( 004a9d0d1 )
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.iWebar.A
McAfee Artemis!84771CDC2F5D
McAfee-GW-Edition BehavesLike.Win32.PUP.hh
MicroWorld-eScan Gen:Variant.Adware.Graftor.151676
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/Malware.QVM30.Gen
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos AppRider
Tencent Nsis.Adware.Adwapper.Dztn
Vba32 AntiVirus AdWare.Adwapper
VIPRE Antivirus Crossrider (fs)
Zillya Adware.Adwapper.Win32.337
Avira AntiVir Adware/CrossRider.A.16003
NANO AntiVirus Riskware.Win32.AdLoad.dcajdu
Agnitum Outpost PUA.Toolbar.CrossRider!
Dr.Web Trojan.Crossrider.27638
Clam AntiVirus Win.Adware.Agent-7640
Bkav FE W32.CrossRiderL.Adware
SUPERAntiSpyware Trojan.Agent/Gen-Crossrider
a19aed07-12ae-4167-a600-64993570c207-4.exe (MD5: 600bebbf5c5342feb95231b5260178fe) has been flagged by 38 scanners:
Scanner Software Result
Avira AntiVir Adware/CrossRider.A.12314
avast! Win32:Adware-gen [Adw]
AVG Skodna.A8D
Baidu-International Adware.Win32.CrossRider.bAG
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
Fortinet FortiGate Riskware/Toolbar_CrossRider
IKARUS anti.virus AdWare.CrossRider
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.iWebar.A
McAfee Artemis!600BEBBF5C53
McAfee-GW-Edition Artemis!600BEBBF5C53
NANO AntiVirus Riskware.Win32.AdLoad.dboaba
Qihoo-360 HEUR/Malware.QVM10.Gen
Sophos AppRider
Tencent Win32.Trojan.Falsesign.Wjsd
VIPRE Antivirus Crossrider (fs)
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374062
AVware Crossrider (fs)
Bitdefender Gen:Variant.Adware.Kazy.374062
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374062 (B)
F-Secure Gen:Variant.Adware.Kazy.374062
G Data Gen:Variant.Adware.Kazy.374062
MicroWorld-eScan Gen:Variant.Adware.Kazy.374062
Panda Antivirus Adware/Goobzo
AhnLab-V3 PUP/Win32.CrossRider
Avira Adware/CrossRider.pq
Dr.Web Trojan.Crossrider.31451
K7 AntiVirus Adware ( 004a970a1 )
K7GW Adware ( 004a970a1 )
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
Agnitum Outpost PUA.Toolbar.CrossRider!
TrendMicro-HouseCall TROJ_GEN.F47V0506
F-Prot W32/AdLoad.AL.gen!Eldorado
Rising Antivirus PE:Malware.Obscure!1.9C59
Symantec Adware.Crossid
Antiy-AVL Trojan/Win32.SGeneric
SUPERAntiSpyware Trojan.Agent/Gen-Crossrider
Bkav FE W32.CrossRider.Trojan
a19aed07-12ae-4167-a600-64993570c207-11.exe (MD5: 252961efa66c5d2291f74f991838a4ff) has been flagged by 39 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374062
Avira AntiVir Adware/CrossRider.A.12201
avast! Win32:Adware-gen [Adw]
AVG Skodna.A8D
Baidu-International Adware.Win32.CrossRider.BAD
Bitdefender Gen:Variant.Adware.Kazy.374062
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Gen:Variant.Adware.Kazy.374062
G Data Gen:Variant.Adware.Kazy.374062
IKARUS anti.virus AdWare.CrossRider
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.iWebar.A
McAfee Artemis!252961EFA66C
McAfee-GW-Edition Artemis!252961EFA66C
MicroWorld-eScan Gen:Variant.Adware.Kazy.374062
NANO AntiVirus Riskware.Win32.CrossRider.dbmnba
Tencent Win32.Trojan.Falsesign.Hoon
VIPRE Antivirus Crossrider (fs)
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374062 (B)
Qihoo-360 Win32/Virus.Adware.157
Panda Antivirus Trj/Genetic.gen
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.AdLoad
Comodo Security ApplicUnwnt
K7 AntiVirus Unwanted-Program ( 00454f261 )
K7GW Unwanted-Program ( 00454f261 )
Sophos AppRider
TrendMicro-HouseCall Suspicious_GEN.F47V0624
Bkav FE W32.CrossRider.Trojan
Rising Antivirus PE:Malware.Obscure!1.9C59
AVware Crossrider (fs)
AhnLab-V3 PUP/Win32.Toolbar
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
Avira Adware/CrossRider.pq
Dr.Web Trojan.Crossrider.31451
Agnitum Outpost PUA.Toolbar.CrossRider!
F-Prot W32/AdLoad.AL.gen!Eldorado
Symantec Adware.Crossid
SUPERAntiSpyware Trojan.Agent/Gen-Crossrider
9ea95148-5bca-4182-9dc1-6b8d5b480459-5.exe (MD5: 7a11f2a46a6089daed444192280c21d5) has been flagged by 39 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374109
AVG Skodna.A8D
Baidu-International Adware.Win32.CrossRider.bAH
Bitdefender Gen:Variant.Adware.Kazy.374109
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374109 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AH
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Gen:Variant.Adware.Kazy.374109
G Data Gen:Variant.Adware.Kazy.374109
IKARUS anti.virus AdWare.CrossRider
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.iWebar.A
McAfee Artemis!7A11F2A46A60
McAfee-GW-Edition Artemis!7A11F2A46A60
MicroWorld-eScan Gen:Variant.Adware.Kazy.374109
Panda Antivirus Trj/Genetic.gen
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos AppRider
Tencent Win32.Trojan.Falsesign.Agur
VIPRE Antivirus Crossrider (fs)
NANO AntiVirus Riskware.Win32.AdLoad.dbqwyf
Qihoo-360 HEUR/Malware.QVM10.Gen
Avira AntiVir ADWARE/CrossRider.Gen2
avast! Win32:Adware-gen [Adw]
Comodo Security ApplicUnwnt
K7 AntiVirus Trojan ( 0049c6eb1 )
K7GW Trojan ( 0049c6eb1 )
TrendMicro-HouseCall Suspicious_GEN.F47V0701
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.AdLoad
Bkav FE W32.CrossRider.Trojan
AVware Crossrider (fs)
AhnLab-V3 PUP/Win32.Toolbar
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
Avira Adware/CrossRider.pq
Dr.Web Trojan.Crossrider.31451
Agnitum Outpost PUA.Toolbar.CrossRider!
F-Prot W32/AdLoad.AL.gen!Eldorado
Symantec Adware.Crossid
SUPERAntiSpyware Trojan.Agent/Gen-Crossrider
9ea95148-5bca-4182-9dc1-6b8d5b480459-4.exe (MD5: 651e27987593b455c84434e381d67d81) has been flagged by 16 scanners:
Scanner Software Result
AVG Skodna.A8D
Baidu-International Adware.Win32.CrossRider.bAG
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AG
IKARUS anti.virus AdWare.CrossRider
Malwarebytes PUP.Optional.iWebar.A
Qihoo-360 HEUR/Malware.QVM10.Gen
Sophos AppRider
VIPRE Antivirus Crossrider (fs)
Avira AntiVir Adware/CrossRider.A.18
TrendMicro-HouseCall TROJ_GEN.F47V0408
McAfee Artemis!7FCEADEC6F73
McAfee-GW-Edition Artemis!7FCEADEC6F73
NANO AntiVirus Riskware.Win32.AdLoad.dbdvjz
Tencent Win32.Trojan.Falsesign.Hreo
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Symantec Adware.Crossid

Software Behaviors

Scheduled tasks:
  • iWebar-codedownloader.exe is scheduled as a task named 'dabd2399-244d-430c-bc75-0a3a1534fc3d-1'.
  • iWebar-nova.exe is scheduled as a task named 'temp_51a98152-68df-45fd-baf2-e0bc3abe65b2-7'.
  • 7c82d588-f306-4366-8f8b-71f85e442eb4-2.exe is scheduled as a task named 'temp_7c82d588-f306-4366-8f8b-71f85e442eb4-2'.
  • 55bb3565-b1d7-4a6f-9574-e5b0df03743f-2.exe is scheduled as a task named 'temp_55bb3565-b1d7-4a6f-9574-e5b0df03743f-2'.
  • 4bd3ec58-c42f-443e-8edb-0a5b2d035380-2.exe is scheduled as a task named 'temp_4bd3ec58-c42f-443e-8edb-0a5b2d035380-2'.
  • b758eec0-2d77-437d-8ac8-dcd399a3b7db-2.exe is scheduled as a task named 'temp_b758eec0-2d77-437d-8ac8-dcd399a3b7db-2'.

Startup Entries

Startup tasks:
  • iWebar-codedownloader.exe is automatically launched at startup through a scheduled task named 7c82d588-f306-4366-8f8b-71f85e442eb4-1.
  • b648c6f7-8e8b-4175-a5f6-dbae56ab26c4-7.exe is automatically launched at startup through a scheduled task named b648c6f7-8e8b-4175-a5f6-dbae56ab26c4-1.
  • iWebar-nova.exe is automatically launched at startup through a scheduled task named 64033f54-cb52-4027-b8f1-871837c2d26b-7.
  • 8c3d90b7-f279-4387-8f01-82deeb8a69d6-7.exe is automatically launched at startup through a scheduled task named 8c3d90b7-f279-4387-8f01-82deeb8a69d6-1.
  • 77138d0f-5d2b-4a16-99d4-f7db76ec38e1-7.exe is automatically launched at startup through a scheduled task named 1898e4ed-5a08-4640-945c-d1dd798785ac-1.
  • e9af6310-bf21-4eb7-a907-24d61f98dd82-7.exe is automatically launched at startup through a scheduled task named e9af6310-bf21-4eb7-a907-24d61f98dd82-1.

Software Details

URL:
–
Support:
–
Installation path:
C:\Program Files\iwebar
Uninstaller:
C:\Program Files\iWebar\Uninstall.exe /fromcontrolpanel=1
Size:
6.00 MB
Language:
English

iWebar Executable Details

Primary executable:
utils.exe
Name:
iWebar
Path:
C:\Program Files\iwebar\utils.exe
MD5:
36b3933e6693e36587b7cbaa6d4fcf1a
SHA-1:
–
SHA-256:
–
Files installed by iWebar
File Type Filename MD5
EXE
ab91a7350a5fddcdf0a7b0c60e8e4e71
EXE
utils.exe
Malware
36b3933e6693e36587b7cbaa6d4fcf1a
EXE
600bebbf5c5342feb95231b5260178fe
EXE
252961efa66c5d2291f74f991838a4ff
EXE
7a11f2a46a6089daed444192280c21d5
EXE
651e27987593b455c84434e381d67d81
EXE
b1dc5e919ab3903e1fbac4316b2bffe9
EXE
48c6d034251394c4f8dc87e0a717fb56
EXE
350a387fc49a7863267aa91acf74310b
EXE
96452e538f054c7138c4212183c0c5e9