Smartbar.GUI.MainClient.dll

Smartbar

PINWID LTD

This is part of the Linkury/SnapDo monetization software, a web browser toolbar used to hijack a user's search in order to collect revenues. The SmartBar is a a potentially unwanted toolbar and Windows Gadget that is advertising supported (adware). The module Smartbar.GUI.MainClient.dll by PINWID has been detected as adware by 3 anti-malware scanners. Additionally, the file is typically installed by a number of programs including Muvic Smartbar Engine by Pinwid Ltd. and Snap.Do by ReSoft Ltd., both potentially unwanted software.
Publisher:
PINWID LTD  (signed and verified)

Product:
Smartbar

Version:
1.2.0.0

MD5:
cd994bfce71e196edf69f64d1ff2def0

SHA-1:
64368edb3b585c322b6a74844e3d065cc0a5b946

SHA-256:
5157ab62897b85872f7a6b4588a089172ffbc192a0236530c78c59897057940d

Scanner detections:
3 / 68

Status:
Adware

Analysis date:
4/24/2024 2:50:09 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
MalSign.Pindi
2015.0.3526

Reason Heuristics
PUP.PINWID.V
14.3.13.22

VIPRE Antivirus
Adware.Linkury
27680

File size:
1.2 MB (1,286,176 bytes)

Product version:
1.2.0.0

Original file name:
Smartbar.GUI.MainClient.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\smartbar\application\smartbar.gui.mainclient.dll

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/4/2014 7:00:00 PM

Valid to:
2/5/2015 6:59:59 PM

Subject:
CN=PINWID LTD, O=PINWID LTD, STREET=14 Shenkar Arie, L=HERZLIYA, S=NA, PostalCode=46733, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00D9AC9FC9A1B1E8FD63013E3CCE7B0578

File PE Metadata
Compilation timestamp:
2/25/2014 4:50:37 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:5mUWn9RU81Ow/C7sPgJdKdQoN0VUlBWGhSkAoOuv2IZ3YyCkunjJSztDW+gq9MC:5m7OwChJd004BWw/NuId+jJkuqiC

Entry address:
0x139BEA

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 90, 13, 00, 0C, 00, 00, 00, EC, 3B, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.7355

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
1.2 MB (1,276,928 bytes)

The file Smartbar.GUI.MainClient.dll has been discovered within the following programs.

Muvic Smartbar  by Pinwid Ltd.
This adware injects advertising in the user's Internet browser by running as an extension and/or add-on. Ads are delivered in the form of banners and text-links (roll-overs) as well as some popup ads.
www.browse-search.com/?
80% remove it
Muvic Smartbar Engine  by Pinwid Ltd.
This adware program injects advertisements with its affiliate ad providers in order to serve a number of ad types including banner, inline text links and popups.
82% remove it
Snap.Do  by ReSoft Ltd.
Snap.Do is a web browser addin/toolbar (depending on the browser it is installed within) that plugs into all the major web browsers including Internet Explorer, Chrome and Firefox. Snap.
snap.do
85% remove it
 
Powered by Should I Remove It?

Remove Smartbar.GUI.MainClient.dll - Powered by Reason Core Security