GoRadioSvc.exe

GoGoGoRadio Service

gogogoradio

This is part of the Sendori web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application GoRadioSvc.exe by gogogoradio has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “GoRadioV1”. This file is typically installed with the program GoGoGoRadio.
Publisher:
gogogoradio  (signed and verified)

Product:
GoGoGoRadio Service

Version:
3.0.0

MD5:
009173b0ec9038864615f93aabb00b19

SHA-1:
5724dcf8f2da68ee6cdb3e9c581ec13464900412

SHA-256:
069e7edee18bef0f4e4218fe2428edfef54c9c9a1a6ad48677f641b426efcc46

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/23/2024 4:48:42 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Sendori (M)
16.10.12.22

File size:
262.2 KB (268,528 bytes)

Product version:
3.0.0

Copyright:
© Dynamic Network Services, Inc.

Trademarks:
Dyn (sm)

Original file name:
GoRadioSvc.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\gogogoradio\goradiosvc.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
9/14/2014 8:00:00 PM

Valid to:
9/14/2017 7:59:59 PM

Subject:
CN=gogogoradio, O=gogogoradio, L=San Leandro, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2E4E52FE2A8CBC43AE36B704CC702908

File PE Metadata
Compilation timestamp:
6/1/2015 1:59:43 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
1536:mZKg8xlSz3+Q0uykO7ER6KsDbTnBoyC3zUdy1itQu1r2VtCXk5UBELR1MrBv:mZ0xlO3+QzsKgTYUdvqS2V8o7Mtv

Entry address:
0x27A7

Entry point:
E8, 32, 3B, 00, 00, E9, 95, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, 04, D3, 40, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, 48, D1, 40, 00, C9, C2, 08, 00, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 08, 30, 41, 00, 89, 0D, 04, 30, 41, 00, 89, 15, 00, 30, 41, 00, 89, 1D, FC, 2F, 41, 00, 89, 35, F8, 2F, 41, 00, 89, 3D...
 
[+]

Entropy:
4.3132

Code size:
47.5 KB (48,640 bytes)

Service
Display name:
GoRadioV1

Description:
Sets and maintains GoGoGoRadio protection on this computer.

Type:
Win32OwnProcess

Depends on:
WINMGMT


The file GoRadioSvc.exe has been discovered within the following program.

GoGoGoRadio  by GoGoGoRadio
gogogoradio.com
About 4% of users remove it
 
Powered by Should I Remove It?

Remove GoRadioSvc.exe - Powered by Reason Core Security