productsremovaltool.exe

Smartbar.Resources.ProductsRemovalTool

PINWID LTD

This is part of the Linkury/SnapDo monetization software, a web browser toolbar used to hijack a user's search in order to collect revenues. The SmartBar is a a potentially unwanted toolbar and Windows Gadget that is advertising supported (adware). The application productsremovaltool.exe by PINWID has been detected as adware by 5 anti-malware scanners. Additionally, the file is typically installed by a number of programs including Muvic Smartbar by Pinwid Ltd. and Muvic Smartbar Engine by Pinwid Ltd., both potentially unwanted software.
Publisher:
PINWID LTD  (signed and verified)

Product:
Smartbar.Resources.ProductsRemovalTool

Version:
1.0.0.0

MD5:
7d7d0df5b430ba9c33f8134eb622892c

SHA-1:
525c0179b8e35b8a8d33329fd2a4d11dc10c2a98

SHA-256:
923d80a30889abb59e7b49cb0384f6c66a08c4efdfc9bcbdfef8f08a0b72b815

Scanner detections:
5 / 68

Status:
Adware

Analysis date:
4/19/2024 3:44:50 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/Linkury.Gen2
7.11.169.168

AVG
MalSign.Pindi
2015.0.3369

IKARUS anti.virus
AdWare.Linkury
t3scan.1.6.1.0

Reason Heuristics
PUP.PINWID.T
14.8.28.10

VIPRE Antivirus
Adware.Linkury
27684

File size:
122 KB (124,952 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2012

Original file name:
Smartbar.Resources.ProductsRemovalTool.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\smartbar\application\productsremovaltool.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
8/13/2014 2:00:00 AM

Valid to:
8/14/2015 1:59:59 AM

Subject:
CN=PINWID LTD, OU=514841295, O=PINWID LTD, STREET=14 Shenkar Arie, L=HERZLIYA, S=TLV, PostalCode=4672514, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
009956EF23AED48987569DC3E7434BBB19

File PE Metadata
Compilation timestamp:
8/27/2014 5:38:21 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:wpViwcqsDMcChFsnpaYBh034WGMECLJhzWsG+jWzX:eDFaC341FCXzWn

Entry address:
0x1DE8A

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
112 KB (114,688 bytes)

The file productsremovaltool.exe has been discovered within the following programs.

Muvic Smartbar  by Pinwid Ltd.
This adware injects advertising in the user's Internet browser by running as an extension and/or add-on. Ads are delivered in the form of banners and text-links (roll-overs) as well as some popup ads.
www.browse-search.com/?
80% remove it
Muvic Smartbar Engine  by Pinwid Ltd.
This adware program injects advertisements with its affiliate ad providers in order to serve a number of ad types including banner, inline text links and popups.
82% remove it
 
Powered by Should I Remove It?

Remove productsremovaltool.exe - Powered by Reason Core Security