Smartbar.Infrastructure.Core.dll

SmartbarProxy

VERISTAFF.COM LTD

This is part of the Linkury/SnapDo monetization software, a web browser toolbar used to hijack a user's search in order to collect revenues. The SmartBar is a a potentially unwanted toolbar and Windows Gadget that is advertising supported (adware). The module Smartbar.Infrastructure.Core.dll by VERISTAFF.COM has been detected as adware by 7 anti-malware scanners. This file is typically installed with the program SafeFinder Smartbar by Linkury Ltd. which is a potentially unwanted software program.
Publisher:
VERISTAFF.COM LTD  (signed and verified)

Product:
SmartbarProxy

Version:
1.2.0.0

MD5:
e9910cb048163e1bdd5c130f75ceaf14

SHA-1:
af584a88eeef436feff7d226b276990bb04629bd

SHA-256:
80e3197ae4a848354dd772151543e018b880872be0a5b2975c7c77f680d6d7ba

Scanner detections:
7 / 68

Status:
Adware

Analysis date:
4/25/2024 10:48:55 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/Linkury.Gen2
7.11.189.70

AVG
Generic
2015.0.3277

Baidu Antivirus
PUA.MSIL.Linkury
4.0.3.141128

ESET NOD32
MSIL/Toolbar.Linkury.I potentially unwanted application
7.0.302.0

G Data
Win32.Application.Linkury
14.11.24

Reason Heuristics
PUP.Smartbar.VERISTAFFCOM.AA
14.12.4.0

VIPRE Antivirus
Threat.4783962
35088

File size:
52 KB (53,264 bytes)

Product version:
1.2.0.0

Original file name:
Smartbar.Infrastructure.Core.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\smartbar\application\smartbar.infrastructure.core.dll

Digital Signature
Authority:
COMODO CA Limited

Valid from:
9/15/2014 8:00:00 AM

Valid to:
9/16/2015 7:59:59 AM

Subject:
CN=VERISTAFF.COM LTD, OU=514841295, O=VERISTAFF.COM LTD, STREET=Shenkar 14, L=Hertzlya, S=TLV, PostalCode=4672514, C=IL

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
2AF13BF1274B91869E8E8BA9B16282CA

File PE Metadata
Compilation timestamp:
11/19/2014 10:18:00 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:zQz4UmuioRRGXj3EOSsfrCa+YFB/nC6JKwBflJXLnajObbYM49driS:zXUmuioRRGXj3EOSsfrCafFlC6JfBnrO

Entry address:
0xC812

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.4571

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
42.5 KB (43,520 bytes)

The file Smartbar.Infrastructure.Core.dll has been discovered within the following programs.

SafeFinder Smartbar  by Linkury Ltd.
SafeFinder displays advertising in the user's Internet browser by running as an extension and/or add-on. Ads are delivered in the form of search-related ads, banner and video ads, and text-links (roll-overs) as well as some popup ads.
www.linkury.com/faq/s/faq.aspx?company=SafeFinder
67% remove it
 
Powered by Should I Remove It?

Remove Smartbar.Infrastructure.Core.dll - Powered by Reason Core Security