Ge-Force

Ge-Force

Known Adware

by Sailor Project

What is Ge-Force?

Ge-Force is software application developed by Sailor Project. It is most commonly found on computers running Windows 7 with nearly 62.39% of installations running this operating system. Ge-Force's installer is typically 13.00 MB in size and installs around 811 files. The most common release is 1.35.12.18 with 24.35% of all installations currently using this version.

Ge-Force is most popular in the United States with 8.5% of installations residing in this country.

Ge-Force adds 1 scheduled task to the Windows Task Scheduler launching the program at randomly scheduled times.

About Ge-Force?

Ge-Force/iWebbar is a browser extension that is supported by advertising and may also run as a background process. This program is often included as part of a bundle distributed by a third-party download manager, which may include other software that the user did not intend to install. Once installed, Ge-Force/iWebbar delivers various types of ads to the user's web browser, including banners, text hyperlinks, inline text ads, and transitional ads. It's important to note that these ads are not endorsed by the websites on which they appear. Additionally, the software communicates with a remote server to collect information about the user's browsing habits, including the URLs and domains visited. This information is used to update and target the advertisements displayed to the user. According to the software's End User License Agreement (EULA), the ads may be targeted based on the user's search queries, information processed by the software, or other data collected from the user's use of the software.

Multiple virus scanners have detected malware in Ge-Force.

408e6fa5-a716-4273-a633-6eb8b8c07ae9-11.exe (MD5: 71631d4221512db1138d441a77dad63d) has been flagged by 35 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Plush.1
AhnLab-V3 PUP/Win32.CrossRider
AVG Generic.D77
Avira Adware/CrossRider.pq
AVware Crossrider (fs)
Bitdefender Gen:Variant.Adware.Plush.1
Emsisoft Anti-Malware Gen:Variant.Adware.Plush.1 (B)
F-Prot W32/A-dc12a8d9!Eldorado
F-Secure Gen:Variant.Adware.Plush.1
G Data Gen:Variant.Adware.Plush.1
IKARUS anti.virus AdWare.Adload
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
Malwarebytes PUP.Optional.GeForce.A
MicroWorld-eScan Gen:Variant.Adware.Plush.1
Panda Antivirus Trj/Genetic.gen
VIPRE Antivirus Crossrider (fs)
Avira AntiVir Adware/CrossRider.pq
Dr.Web Trojan.Crossrider.31451
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
McAfee Artemis!987F28012907
McAfee-GW-Edition Artemis!987F28012907
Qihoo-360 Win32/Virus.Adware.970
Tencent Nsis.Adware.Adwapper.Hufv
avast! Win32:Malware-gen
Fortinet FortiGate Riskware/CrossRider
Sophos Generic PUA FA
Symantec Trojan.ADH.2
Baidu-International PUA.Win32.CrossRider.BAH
K7GW Adware ( 0049f20e1 )
Antiy-AVL GrayWare[AdWare:not-a-virus]/NSIS.Adwapper.ai
K7 AntiVirus Unwanted-Program ( 004a9d071 )
NANO AntiVirus Trojan.Win32.Crossrider.ddtlmb
Rising Antivirus PE:Malware.Obscure!1.9C59
TrendMicro-HouseCall Suspicious_GEN.F47V0808
3b4ff9b7-b774-412b-9ba4-58d6f55cc810-7.exe (MD5: 14974994041d44fa065de46195fc6522) has been flagged by 28 scanners:
Scanner Software Result
Avira AntiVir Adware/CrossRider.pq
avast! Win32:Adware-gen [Adw]
AVG Generic.D77
AVware Crossrider (fs)
Dr.Web Trojan.Crossrider.31451
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AJ
IKARUS anti.virus AdWare.Adload
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.GeForce.A
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Virus.Adware.970
Tencent Nsis.Adware.Adwapper.Dxwx
VIPRE Antivirus Crossrider (fs)
G Data Win32.Adware.Crossrider.L
Rising Antivirus PE:Malware.Obscure!1.9C59
Avira Adware/CrossRider.pq
K7 AntiVirus Unwanted-Program ( 004a9d071 )
K7GW Unwanted-Program ( 004a9d071 )
Baidu-International PUA.Win32.CrossRider.bAJ
Sophos Generic PUA OB
F-Prot W32/A-04c00d5a!Eldorado
Antiy-AVL GrayWare[AdWare:not-a-virus]/NSIS.Adwapper.ai
Fortinet FortiGate Riskware/CrossRider
TrendMicro-HouseCall Suspicious_GEN.F47V0808
Symantec Trojan.ADH.2
McAfee Artemis!28A3DF24395D
AhnLab-V3 PUP/Win32.CrossRider
3b4ff9b7-b774-412b-9ba4-58d6f55cc810-5.exe (MD5: 7b58d18c567f330e0c3f4b3a82e57a20) has been flagged by 36 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Plush.2
Avira AntiVir Adware/CrossRider.pq
AVG Generic.D77
AVware Crossrider (fs)
Bitdefender Gen:Variant.Adware.Plush.2
Dr.Web Trojan.Crossrider.31451
Emsisoft Anti-Malware Gen:Variant.Adware.Plush.2 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AH
F-Secure Gen:Variant.Adware.Plush.2
G Data Gen:Variant.Adware.Plush.2
IKARUS anti.virus AdWare.Adload
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.GeForce.A
MicroWorld-eScan Gen:Variant.Adware.Plush.2
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Virus.Adware.970
Rising Antivirus PE:Malware.Obscure!1.9C59
Tencent Nsis.Adware.Adwapper.Aise
VIPRE Antivirus Crossrider (fs)
avast! Win32:Adware-gen [Adw]
Baidu-International PUA.Win32.CrossRider.bAH
K7GW Adware ( 0049f20e1 )
McAfee Artemis!34C6149952F0
AhnLab-V3 PUP/Win32.CrossRider
Avira Adware/CrossRider.pq
F-Prot W32/A-dc12a8d9!Eldorado
NANO AntiVirus Trojan.Win32.GoogUpdate.ddshff
Antiy-AVL GrayWare[AdWare:not-a-virus]/NSIS.Adwapper.ai
K7 AntiVirus Unwanted-Program ( 004a9d071 )
Sophos Generic PUA KE
Symantec Adware.Crossid
Zillya Adware.Adwapper.Win32.250
McAfee-GW-Edition Artemis!BDED7EA6D6AD
Fortinet FortiGate Adware/Adwapper
TrendMicro-HouseCall Suspicious_GEN.F47V0808
3b4ff9b7-b774-412b-9ba4-58d6f55cc810-2.exe (MD5: a4423694e2df93c916175b7e5e312292) has been flagged by 33 scanners:
Scanner Software Result
Avira AntiVir Adware/CrossRider.pq
AVG Generic.D77
AVware Crossrider (fs)
Dr.Web Trojan.Crossrider.31451
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AJ
G Data Win32.Adware.Crossrider.L
IKARUS anti.virus AdWare.Adload
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.GeForce.A
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Virus.Adware.970
Rising Antivirus PE:Malware.Obscure!1.9C59
Tencent Nsis.Adware.Adwapper.Lkna
VIPRE Antivirus Crossrider (fs)
avast! Win32:Crossrider-N [PUP]
Baidu-International Trojan.Win32.GoogUpdate.APyR
Sophos Generic PUA BJ
Symantec Trojan.ADH
Avira Adware/CrossRider.pq
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374062
Bitdefender Gen:Variant.Adware.Kazy.374062
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374062 (B)
F-Secure Gen:Variant.Adware.Kazy.374062
MicroWorld-eScan Gen:Variant.Adware.Kazy.374062
AhnLab-V3 PUP/Win32.CrossRider
K7 AntiVirus Unwanted-Program ( 004a9d071 )
K7GW Unwanted-Program ( 004a9d071 )
F-Prot W32/A-04c00d5a!Eldorado
Antiy-AVL GrayWare[AdWare:not-a-virus]/NSIS.Adwapper.ai
Fortinet FortiGate Riskware/CrossRider
TrendMicro-HouseCall Suspicious_GEN.F47V0808
McAfee Artemis!28A3DF24395D
365413fd-6ef6-4ecd-8bdb-0b07a540fb87-7.exe (MD5: 843b06dd07fb09ec3e8b0e9384dec8eb) has been flagged by 49 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.dv1@mereOpkO
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL GrayWare[WebToolbar:not-a-virus]/Win32.CrossRider.kyc
Arcabit Application.Heur.E84BC7
avast! Win32:Adware-CUB [PUP]
AVG Generic.619
Avira ADWARE/CrossRid.bqyp
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.CD
Bitdefender Gen:Application.Heur.dv1@mereOpkO
Bkav FE W32.HfsAdware.52D8
CAT-QuickHeal PUA.BrightCircle.OD6
Cyren W32/S-dbad4651!Eldorado
Dr.Web Trojan.Crossrider1.23051
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.CD potentially unwanted
Fortinet FortiGate Riskware/CrossRider
F-Prot W32/S-dbad4651!Eldorado
F-Secure Gen:Application.Heur.dv1@mereOpkO
G Data Gen:Application.Heur.dv1@mereOpkO
K7 AntiVirus Unwanted-Program ( 0040f9e41 )
K7GW Unwanted-Program ( 0040f9e41 )
Malwarebytes PUP.Optional.GeForce.A
McAfee Artemis!843B06DD07FB
McAfee-GW-Edition Artemis
NANO AntiVirus Trojan.Win32.Crossrider1.dmjijm
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Application.b0d
Rising Antivirus PE:Trojan.GoogUpdate!6.1E39
Sophos AppRider (PUA)
SUPERAntiSpyware Adware.CrossRider/Variant
Symantec Adware.Crossid
Trend Micro TROJ_GEN.F0C2C00AI15
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.2050
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.kti
MicroWorld-eScan Gen:Application.Heur.cv1@m4Tfj@bO
Tencent Trojan.Win32.Qudamah.Gen.6
TrendMicro-HouseCall TROJ_GEN.F0C2C00A115
Jiangmin AdWare/NSIS.cpv
Vba32 AntiVirus AdWare.Adwapper
Clam AntiVirus Win.Trojan.Crossrider-201
Agnitum Outpost PUA.Toolbar.CrossRider!
Comodo Security ApplicUnwnt
IKARUS anti.virus Trojan.GoogUpdate
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
nProtect Trojan-Clicker/W32.Agent.558440
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.433849 (B)
Avira AntiVir Adware/CrossRider.pq

Software Behaviors

Scheduled tasks:
  • f35f3986-71ea-4c44-b09d-40719e41731a-2.exe is scheduled as a task named 'temp_f35f3986-71ea-4c44-b09d-40719e41731a-2'.

Startup Entries

Startup tasks:
  • ba02e9b3-5672-4d83-849e-e1fe9868890e-7.exe is automatically launched at startup through a scheduled task named ba02e9b3-5672-4d83-849e-e1fe9868890e-1.
  • 86deb0d5-f916-4243-b6a8-28ec198fea77-7.exe is automatically launched at startup through a scheduled task named 86deb0d5-f916-4243-b6a8-28ec198fea77-1.
  • Ge-Force-codedownloader.exe is automatically launched at startup through a scheduled task named 7633d77e-5a81-4a2b-9a50-349a56f43628-7.
  • 8f34616f-c621-42dd-baa5-6d1a9ae24424-5.exe is automatically launched at startup through a scheduled task named 8f34616f-c621-42dd-baa5-6d1a9ae24424-5_user.
  • 61709476-a280-47b5-a735-d492ef19db8d-7.exe is automatically launched at startup through a scheduled task named a738dcdf-e6a3-4b57-9ff1-54da0bf96c87-1.
  • 365413fd-6ef6-4ecd-8bdb-0b07a540fb87-6.exe is automatically launched at startup through a scheduled task named 365413fd-6ef6-4ecd-8bdb-0b07a540fb87-6.

Software Details

URL:
https://crossrider.com/install/61911-ge-forces
Support:
–
Installation path:
C:\Program Files\ge-force
Uninstaller:
C:\Program Files\Ge-Force\Uninstall.exe /fcp=1
Size:
13.00 MB
Language:
English

Ge-Force Executable Details

Primary executable:
utils.exe
Name:
Ge-Force
Path:
C:\Program Files\ge-force\utils.exe
MD5:
–
SHA-1:
–
SHA-256:
–
Files installed by Ge-Force
File Type Filename MD5
EXE
ab91a7350a5fddcdf0a7b0c60e8e4e71
EXE
a0bdc8051a740904d9e5f24d697f6875
EXE
71631d4221512db1138d441a77dad63d
EXE
14974994041d44fa065de46195fc6522
EXE
7b58d18c567f330e0c3f4b3a82e57a20
EXE
40ec200eb9dac76fe7f85041adbc91ce
EXE
a4423694e2df93c916175b7e5e312292
EXE
41188b05fc65c3acd47a26d57ed925b1
EXE
843b06dd07fb09ec3e8b0e9384dec8eb
EXE
bf0f99df07d6345b75b1e38652d7c262