Ge-Force

Ge-Force

Known Adware

by Sailor Project

What is Ge-Force?

Ge-Force is software application developed by Sailor Project. It is most commonly found on computers running Windows 7 with nearly 62.39% of installations running this operating system. Ge-Force's installer is typically 13.00 MB in size and installs around 811 files. The most common release is 1.35.12.18 with 24.35% of all installations currently using this version.

Ge-Force is most popular in the United States with 8.5% of installations residing in this country.

Ge-Force adds 1 scheduled task to the Windows Task Scheduler launching the program at randomly scheduled times.

About Ge-Force?

Ge-Force/iWebbar is a browser extension that is supported by advertising and may also run as a background process. This program is often included as part of a bundle distributed by a third-party download manager, which may include other software that the user did not intend to install. Once installed, Ge-Force/iWebbar delivers various types of ads to the user's web browser, including banners, text hyperlinks, inline text ads, and transitional ads. It's important to note that these ads are not endorsed by the websites on which they appear. Additionally, the software communicates with a remote server to collect information about the user's browsing habits, including the URLs and domains visited. This information is used to update and target the advertisements displayed to the user. According to the software's End User License Agreement (EULA), the ads may be targeted based on the user's search queries, information processed by the software, or other data collected from the user's use of the software.

Multiple virus scanners have detected malware in Ge-Force.

408e6fa5-a716-4273-a633-6eb8b8c07ae9-11.exe (MD5: 71631d4221512db1138d441a77dad63d) has been flagged by 35 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Plush.1
AhnLab-V3 PUP/Win32.CrossRider
AVG Generic.D77
Avira Adware/CrossRider.pq
AVware Crossrider (fs)
Bitdefender Gen:Variant.Adware.Plush.1
Emsisoft Anti-Malware Gen:Variant.Adware.Plush.1 (B)
F-Prot W32/A-dc12a8d9!Eldorado
F-Secure Gen:Variant.Adware.Plush.1
G Data Gen:Variant.Adware.Plush.1
IKARUS anti.virus AdWare.Adload
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
Malwarebytes PUP.Optional.GeForce.A
MicroWorld-eScan Gen:Variant.Adware.Plush.1
Panda Antivirus Trj/Genetic.gen
VIPRE Antivirus Crossrider (fs)
Avira AntiVir Adware/CrossRider.pq
Dr.Web Trojan.Crossrider.31451
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
McAfee Artemis!987F28012907
McAfee-GW-Edition Artemis!987F28012907
Qihoo-360 Win32/Virus.Adware.970
Tencent Nsis.Adware.Adwapper.Hufv
avast! Win32:Malware-gen
Fortinet FortiGate Riskware/CrossRider
Sophos Generic PUA FA
Symantec Trojan.ADH.2
Baidu-International PUA.Win32.CrossRider.BAH
K7GW Adware ( 0049f20e1 )
Antiy-AVL GrayWare[AdWare:not-a-virus]/NSIS.Adwapper.ai
K7 AntiVirus Unwanted-Program ( 004a9d071 )
NANO AntiVirus Trojan.Win32.Crossrider.ddtlmb
Rising Antivirus PE:Malware.Obscure!1.9C59
TrendMicro-HouseCall Suspicious_GEN.F47V0808
3b4ff9b7-b774-412b-9ba4-58d6f55cc810-7.exe (MD5: 14974994041d44fa065de46195fc6522) has been flagged by 28 scanners:
Scanner Software Result
Avira AntiVir Adware/CrossRider.pq
avast! Win32:Adware-gen [Adw]
AVG Generic.D77
AVware Crossrider (fs)
Dr.Web Trojan.Crossrider.31451
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AJ
IKARUS anti.virus AdWare.Adload
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.GeForce.A
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Virus.Adware.970
Tencent Nsis.Adware.Adwapper.Dxwx
VIPRE Antivirus Crossrider (fs)
G Data Win32.Adware.Crossrider.L
Rising Antivirus PE:Malware.Obscure!1.9C59
Avira Adware/CrossRider.pq
K7 AntiVirus Unwanted-Program ( 004a9d071 )
K7GW Unwanted-Program ( 004a9d071 )
Baidu-International PUA.Win32.CrossRider.bAJ
Sophos Generic PUA OB
F-Prot W32/A-04c00d5a!Eldorado
Antiy-AVL GrayWare[AdWare:not-a-virus]/NSIS.Adwapper.ai
Fortinet FortiGate Riskware/CrossRider
TrendMicro-HouseCall Suspicious_GEN.F47V0808
Symantec Trojan.ADH.2
McAfee Artemis!28A3DF24395D
AhnLab-V3 PUP/Win32.CrossRider
3b4ff9b7-b774-412b-9ba4-58d6f55cc810-5.exe (MD5: 7b58d18c567f330e0c3f4b3a82e57a20) has been flagged by 36 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Plush.2
Avira AntiVir Adware/CrossRider.pq
AVG Generic.D77
AVware Crossrider (fs)
Bitdefender Gen:Variant.Adware.Plush.2
Dr.Web Trojan.Crossrider.31451
Emsisoft Anti-Malware Gen:Variant.Adware.Plush.2 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AH
F-Secure Gen:Variant.Adware.Plush.2
G Data Gen:Variant.Adware.Plush.2
IKARUS anti.virus AdWare.Adload
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.GeForce.A
MicroWorld-eScan Gen:Variant.Adware.Plush.2
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Virus.Adware.970
Rising Antivirus PE:Malware.Obscure!1.9C59
Tencent Nsis.Adware.Adwapper.Aise
VIPRE Antivirus Crossrider (fs)
avast! Win32:Adware-gen [Adw]
Baidu-International PUA.Win32.CrossRider.bAH
K7GW Adware ( 0049f20e1 )
McAfee Artemis!34C6149952F0
AhnLab-V3 PUP/Win32.CrossRider
Avira Adware/CrossRider.pq
F-Prot W32/A-dc12a8d9!Eldorado
NANO AntiVirus Trojan.Win32.GoogUpdate.ddshff
Antiy-AVL GrayWare[AdWare:not-a-virus]/NSIS.Adwapper.ai
K7 AntiVirus Unwanted-Program ( 004a9d071 )
Sophos Generic PUA KE
Symantec Adware.Crossid
Zillya Adware.Adwapper.Win32.250
McAfee-GW-Edition Artemis!BDED7EA6D6AD
Fortinet FortiGate Adware/Adwapper
TrendMicro-HouseCall Suspicious_GEN.F47V0808
3b4ff9b7-b774-412b-9ba4-58d6f55cc810-2.exe (MD5: a4423694e2df93c916175b7e5e312292) has been flagged by 33 scanners:
Scanner Software Result
Avira AntiVir Adware/CrossRider.pq
AVG Generic.D77
AVware Crossrider (fs)
Dr.Web Trojan.Crossrider.31451
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AJ
G Data Win32.Adware.Crossrider.L
IKARUS anti.virus AdWare.Adload
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.GeForce.A
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Virus.Adware.970
Rising Antivirus PE:Malware.Obscure!1.9C59
Tencent Nsis.Adware.Adwapper.Lkna
VIPRE Antivirus Crossrider (fs)
avast! Win32:Crossrider-N [PUP]
Baidu-International Trojan.Win32.GoogUpdate.APyR
Sophos Generic PUA BJ
Symantec Trojan.ADH
Avira Adware/CrossRider.pq
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374062
Bitdefender Gen:Variant.Adware.Kazy.374062
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374062 (B)
F-Secure Gen:Variant.Adware.Kazy.374062
MicroWorld-eScan Gen:Variant.Adware.Kazy.374062
AhnLab-V3 PUP/Win32.CrossRider
K7 AntiVirus Unwanted-Program ( 004a9d071 )
K7GW Unwanted-Program ( 004a9d071 )
F-Prot W32/A-04c00d5a!Eldorado
Antiy-AVL GrayWare[AdWare:not-a-virus]/NSIS.Adwapper.ai
Fortinet FortiGate Riskware/CrossRider
TrendMicro-HouseCall Suspicious_GEN.F47V0808
McAfee Artemis!28A3DF24395D
365413fd-6ef6-4ecd-8bdb-0b07a540fb87-7.exe (MD5: 843b06dd07fb09ec3e8b0e9384dec8eb) has been flagged by 49 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.dv1@mereOpkO
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL GrayWare[WebToolbar:not-a-virus]/Win32.CrossRider.kyc
Arcabit Application.Heur.E84BC7
avast! Win32:Adware-CUB [PUP]
AVG Generic.619
Avira ADWARE/CrossRid.bqyp
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.CD
Bitdefender Gen:Application.Heur.dv1@mereOpkO
Bkav FE W32.HfsAdware.52D8
CAT-QuickHeal PUA.BrightCircle.OD6
Cyren W32/S-dbad4651!Eldorado
Dr.Web Trojan.Crossrider1.23051
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.CD potentially unwanted
Fortinet FortiGate Riskware/CrossRider
F-Prot W32/S-dbad4651!Eldorado
F-Secure Gen:Application.Heur.dv1@mereOpkO
G Data Gen:Application.Heur.dv1@mereOpkO
K7 AntiVirus Unwanted-Program ( 0040f9e41 )
K7GW Unwanted-Program ( 0040f9e41 )
Malwarebytes PUP.Optional.GeForce.A
McAfee Artemis!843B06DD07FB
McAfee-GW-Edition Artemis
NANO AntiVirus Trojan.Win32.Crossrider1.dmjijm
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Application.b0d
Rising Antivirus PE:Trojan.GoogUpdate!6.1E39
Sophos AppRider (PUA)
SUPERAntiSpyware Adware.CrossRider/Variant
Symantec Adware.Crossid
Trend Micro TROJ_GEN.F0C2C00AI15
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.2050
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.kti
MicroWorld-eScan Gen:Application.Heur.cv1@m4Tfj@bO
Tencent Trojan.Win32.Qudamah.Gen.6
TrendMicro-HouseCall TROJ_GEN.F0C2C00A115
Jiangmin AdWare/NSIS.cpv
Vba32 AntiVirus AdWare.Adwapper
Clam AntiVirus Win.Trojan.Crossrider-201
Agnitum Outpost PUA.Toolbar.CrossRider!
Comodo Security ApplicUnwnt
IKARUS anti.virus Trojan.GoogUpdate
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
nProtect Trojan-Clicker/W32.Agent.558440
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.433849 (B)
Avira AntiVir Adware/CrossRider.pq

Software Behaviors

Scheduled tasks:
  • f35f3986-71ea-4c44-b09d-40719e41731a-2.exe is scheduled as a task named 'temp_f35f3986-71ea-4c44-b09d-40719e41731a-2'.

Startup Entries

Startup tasks:
  • ba02e9b3-5672-4d83-849e-e1fe9868890e-7.exe is automatically launched at startup through a scheduled task named ba02e9b3-5672-4d83-849e-e1fe9868890e-1.
  • 86deb0d5-f916-4243-b6a8-28ec198fea77-7.exe is automatically launched at startup through a scheduled task named 86deb0d5-f916-4243-b6a8-28ec198fea77-1.
  • Ge-Force-codedownloader.exe is automatically launched at startup through a scheduled task named 7633d77e-5a81-4a2b-9a50-349a56f43628-7.
  • 8f34616f-c621-42dd-baa5-6d1a9ae24424-5.exe is automatically launched at startup through a scheduled task named 8f34616f-c621-42dd-baa5-6d1a9ae24424-5_user.
  • 61709476-a280-47b5-a735-d492ef19db8d-7.exe is automatically launched at startup through a scheduled task named a738dcdf-e6a3-4b57-9ff1-54da0bf96c87-1.
  • 365413fd-6ef6-4ecd-8bdb-0b07a540fb87-6.exe is automatically launched at startup through a scheduled task named 365413fd-6ef6-4ecd-8bdb-0b07a540fb87-6.

Software Details

URL:
https://crossrider.com/install/61911-ge-forces
Support:
–
Installation path:
C:\Program Files\ge-force
Uninstaller:
C:\Program Files\Ge-Force\Uninstall.exe /fcp=1
Size:
13.00 MB
Language:
English

Ge-Force Executable Details

Primary executable:
utils.exe
Name:
Ge-Force
Path:
C:\Program Files\ge-force\utils.exe
MD5:
–
SHA-1:
–
SHA-256:
–
Files installed by Ge-Force
File Type Filename MD5
EXE
c1db3a0416cc9b216b3fef904e1fbe02
EXE
679858c08f871dc0e4af83ee49197a1b
EXE
4a2bb62ab05350c5617209cac263cbe8
EXE
f67dbb36542f7d1f006ee8560b4f1bd4
EXE
ed1252b9df9061e2bc5d9f861390f4a9
EXE
2ea24cbde20d316d9bad44dac2cd0bf0
EXE
54428eb65cebb954ac5b45fb4f0ac382
EXE
6e5d620baa5f16ffa1cb6e4220e7303d
EXE
fbe12fcd74bad1478843c95e63b68379
EXE
27e04280cad23675be237ae851874474