productsremovaltool.exe

Smartbar.Resources.ProductsRemovalTool

PINWID LTD

The application productsremovaltool.exe by PINWID has been detected as adware by 3 anti-malware scanners. Additionally, the file is typically installed by a number of programs including Muvic Smartbar by Pinwid Ltd. and Muvic Smartbar Engine by Pinwid Ltd., both potentially unwanted software.
Publisher:
PINWID LTD  (signed and verified)

Product:
Smartbar.Resources.ProductsRemovalTool

Version:
1.0.0.0

MD5:
0187ab50139e77a39fd5c0eafa104f7a

SHA-1:
c40bc06b5708bcbf605e519f5e56b575070ec760

SHA-256:
96f3cd62fa7366fe07c59f096f6c2fb19d57789f4913e9b2d739bf0b2a9c9bf4

Scanner detections:
3 / 68

Status:
Adware

Analysis date:
4/6/2014 9:52:28 AM UTC  (seven months ago)

Scan engine
Detection
Engine version

AVG
MalSign.Pindi
2015.0.3513

Reason Heuristics
PUP.PINWID.T
14.4.6.1

VIPRE Antivirus
Adware.Linkury
28072

File size:
120 KB (122,912 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2012

Original file name:
Smartbar.Resources.ProductsRemovalTool.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\user\appdata\local\smartbar\application\productsremovaltool.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/4/2014 4:00:00 PM

Valid to:
2/5/2015 3:59:59 PM

Subject:
CN=PINWID LTD, O=PINWID LTD, STREET=14 Shenkar Arie, L=HERZLIYA, S=NA, PostalCode=46733, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00D9AC9FC9A1B1E8FD63013E3CCE7B0578

File PE Metadata
Compilation timestamp:
3/25/2014 7:14:25 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:fIu/RFtHcChFsnpaYBh034WGMECLJhzWscJlW8:jDFaC341FCXzW

Entry address:
0x1D7EE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, D0, 01, 00, 0C, 00, 00, 00, F0, 37, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.7613

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
110 KB (112,640 bytes)

The file productsremovaltool.exe has been discovered within the following programs.

Muvic Smartbar  by Pinwid Ltd.
This adware injects advertising in the user's Internet browser by running as an extension and/or add-on. Ads are delivered in the form of banners and text-links (roll-overs) as well as some popup ads.
www.browse-search.com/?
80% remove it
Muvic Smartbar Engine  by Pinwid Ltd.
This adware program injects advertisements with its affiliate ad providers in order to serve a number of ad types including banner, inline text links and popups.
82% remove it
 
Powered by Should I Remove It?

There are 10 known versions of productsremovaltool.exe.

6 / 68      (Adware)
productsremovaltool.exe  1.0.0.0  (9a202520b90b9e511fa9c76cad8719bf0b5c5a18)

6 / 68      (Adware)
productsremovaltool.exe  1.0.0.0  (0633e57ce810a59d07a956ca524a038dc0107b10)

6 / 68      (Adware)
productsremovaltool.exe  1.0.0.0  (3c8875ad0c06a6ff777da3b87284b61129c7e209)

6 / 68      (Adware)
productsremovaltool.exe  1.0.0.0  (ee7e0b9ffe3770c19e8fe12b6ad549d7e88416be)

6 / 68      (Adware)
productsremovaltool.exe  1.0.0.0  (90d812a1625281f946b7a895458bf2f348430cea)

5 / 68      (Adware)
productsremovaltool.exe  1.0.0.0  (525c0179b8e35b8a8d33329fd2a4d11dc10c2a98)

4 / 68      (Adware)
productsremovaltool.exe  1.0.0.0  (560c6e94bb6c0c06bf15d70fc75cf765bcfd6db9)

3 / 68      (Adware)
productsremovaltool.exe  1.0.0.0  (de61226b55f3b12ccaeb40449523e6417be1df93)

1 / 68      (Adware)
productsremovaltool.exe  1.0.0.0  (38b310d6d7ab2c1368b74992d396b324a497ea71)

3 / 68      (Adware)
productsremovaltool.exe  1.0.0.0  (c04c275e944f18f448e9d6144b433644ff85bb7b)

11 / 68    (Adware)
smartbarfirefoxremoteplugin_27.dll  (4daaf48aabce45e5033c7a5172ced0360e6eb2f2)

9 / 68      (Adware)
installer.exe  (2ecfac6c3fc4e13f894d89a3cfa89c57bb1039ce)

3 / 68      (Adware)
srpts.exe  (50c1ec642a5a5258c17db267c6ff3768449106cc)

3 / 68      (Adware)
srpt.dll  (65fcd4cb2f73a97e38c0a7e93fd45328a5e301e9)

2 / 68      (Adware)
Smartbar.Communication.NamedPipe.dll  (778f38ae4a151a337b6a846cd551dce2759cde0c)

2 / 68      (Adware)
Smartbar.Communication.dll  (0c756d33ed8662a26c11c862adfbcfb705a6928b)

3 / 68      (Adware)
srptc.dll  (8ddc81202b07814c5f01d582b8491b17149a12c3)

2 / 68      (Adware)
Smartbar.Common.dll  (53776c68d7f2bb104aa35585dab3d15cf6a0b208)

2 / 68      (Adware)
srptm.exe  (bd4dc01cc4472486b8c6ba87eb9a8eb2a991d708)

3 / 68      (Adware)
srut.dll  (559656c5c50d651482f0697368373652b1828394)

3 / 68      (Adware)
sppsm.dll  (c145eafae7afd3e087a726fdac42520952363021)

3 / 68      (Adware)
spusm.dll  (50afa9026144ed5316773e055f7a056f392b530d)

3 / 68      (Adware)
Smartbar.Resources.HistoryAndStatsWrapper.dll  (bd0f6d1e02f99c56d0a386a4eeffdf18dacb8952)

2 / 68      (Adware)
Smartbar.Personalization.Common.dll  (2254806f1e6bfe4030e5e63b342af4bbaff1a5e1)

2 / 68      (Adware)
Smartbar.Infrastructure.Utilities.dll  (da628bf41c53488a6146dc50aa94a0796a3c624f)

3 / 68      (Adware)
srbs.dll  (aeaa3beebed0f09e9c43a254665f4400dc04019b)

Detection Incidence by Country