sma.exe

W

Goobzo LTD

The application sma.exe by Goobzo has been detected as adware by 12 anti-malware scanners. This file is typically installed with the program Search Module Plus by Goobzo LTD which is a potentially unwanted software program.
Publisher:
.  (signed by Goobzo LTD)

Product:
W

Description:
agent

Version:
2, 1, 8, 525

MD5:
752b797ddf173f20009a0d306b3b9bd1

SHA-1:
4b48755c181fa282ebfd771ffc587335d4ffb702

SHA-256:
2499faa88eaeea1034b321dc743f9b18218b43eaf2ec9430bde86a516549dcdc

Scanner detections:
12 / 68

Status:
Adware

Analysis date:
4/25/2024 6:24:32 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
Win-PUP/CrossRider
2015.02.01

avast!
Win32:Adware-CDO [PUP]
150101-1

AVG
Skodna
2016.0.3213

Dr.Web
Adware.Searcher.2656
9.0.1.05190

ESET NOD32
Win32/SBWatchman.D potentially unwanted application
7.0.302.0

F-Prot
W64/Goobzo.A
4.6.5.141

Kaspersky
not-a-virus:AdWare.Win32.Shopper
15.0.0.543

Panda Antivirus
Adware/Goobzo
15.01.31.07

Reason Heuristics
PUP.Goobzo
15.1.31.7

VIPRE Antivirus
Threat.4792716
36666

Zillya! Antivirus
Adware.Shopper.Win64.9
2.0.0.2049

File size:
123.9 KB (126,824 bytes)

Product version:
2, 1, 8, 525

Copyright:
Copyright (C) 2012

Original file name:
sma.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\common files\goobzo\gbupdateplus\sma.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/2/2013 1:00:00 AM

Valid to:
5/3/2015 12:59:59 AM

Subject:
CN=Goobzo LTD, O=Goobzo LTD, L=Haifa, S=Israel, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
120B25DDE57B88636AD4D97D23B99C88

File PE Metadata
Compilation timestamp:
1/31/2015 7:11:27 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
9.0

CTPH (ssdeep):
3072:UKWA/6zh+gyaUAsmm9jetJ9h9yMRMHlhTaBLbT6uuGOK3r:UnyVADmhepHE6yuuGOK7

Entry address:
0xD074

Entry point:
48, 83, EC, 28, E8, 27, 03, 00, 00, 48, 83, C4, 28, E9, 86, FD, FF, FF, CC, CC, 48, 89, 4C, 24, 08, 48, 81, EC, 88, 00, 00, 00, 48, 8D, 0D, 65, F6, 00, 00, FF, 15, 57, 50, 00, 00, 4C, 8B, 1D, 50, F7, 00, 00, 4C, 89, 5C, 24, 58, 45, 33, C0, 48, 8D, 54, 24, 60, 48, 8B, 4C, 24, 58, E8, B5, 05, 00, 00, 48, 89, 44, 24, 50, 48, 83, 7C, 24, 50, 00, 74, 41, 48, C7, 44, 24, 38, 00, 00, 00, 00, 48, 8D, 44, 24, 48, 48, 89, 44, 24, 30, 48, 8D, 44, 24, 40, 48, 89, 44, 24, 28, 48, 8D, 05, 10, F6, 00, 00, 48, 89, 44, 24...
 
[+]

Entropy:
5.8645

Code size:
64.5 KB (66,048 bytes)

The file sma.exe has been discovered within the following program.

Search Module Plus  by Goobzo LTD
Goobzo's Search Module Plus is a web browser toolbar/extension that will insert itself into IE, Firefox or Chrome and will modify the search and home page providers of the targeted browser. Once installed Search Module Plus changes Windows host file and DNS settings.
79% remove it
 
Powered by Should I Remove It?

Remove sma.exe - Powered by Reason Core Security