Smartbar.Monetization.Proxy.ProxyRemover.exe

ProxyRemover

PINWID LTD

This is part of the Linkury/SnapDo monetization software, a web browser toolbar used to hijack a user's search in order to collect revenues. The SmartBar is a a potentially unwanted toolbar and Windows Gadget that is advertising supported (adware). The application Smartbar.Monetization.Proxy.ProxyRemover.exe by PINWID has been detected as adware by 4 anti-malware scanners. Additionally, the file is typically installed by a number of programs including Muvic Smartbar by Pinwid Ltd. and Muvic Smartbar Engine by Pinwid Ltd., both potentially unwanted software.
Publisher:
PINWID LTD  (signed and verified)

Product:
ProxyRemover

Version:
1.0.0.0

MD5:
9a7a772a3d11c093871e2897d54561ed

SHA-1:
2899cf44d19a2ee5305b8d87eb0141db47304221

SHA-256:
00e89ee00e32adbd7a55b6a0ca8a25a594571e4eb8a2ea48bb743dd325a9c7f0

Scanner detections:
4 / 68

Status:
Adware

Analysis date:
5/10/2024 2:52:45 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/Linkury.Gen2
7.11.169.168

AVG
MalSign.Pindi
2015.0.3369

IKARUS anti.virus
AdWare.Linkury
t3scan.1.6.1.0

Reason Heuristics
PUP.PINWID.f
14.8.28.10

File size:
24 KB (24,600 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2014

Original file name:
Smartbar.Monetization.Proxy.ProxyRemover.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\lpt\smartbar.monetization.proxy.proxyremover.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
8/13/2014 2:00:00 AM

Valid to:
8/14/2015 1:59:59 AM

Subject:
CN=PINWID LTD, OU=514841295, O=PINWID LTD, STREET=14 Shenkar Arie, L=HERZLIYA, S=TLV, PostalCode=4672514, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
009956EF23AED48987569DC3E7434BBB19

File PE Metadata
Compilation timestamp:
8/27/2014 5:39:03 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
384:5rG0v2drdC5MCNIByiINgeTGzRV9UmioXqCt250KYDhnhCxYPLg8fn0AG:U0FTzNgcsNx250KYDhMEf8

Entry address:
0x589A

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
14.5 KB (14,848 bytes)

The file Smartbar.Monetization.Proxy.ProxyRemover.exe has been discovered within the following programs.

Muvic Smartbar  by Pinwid Ltd.
This adware injects advertising in the user's Internet browser by running as an extension and/or add-on. Ads are delivered in the form of banners and text-links (roll-overs) as well as some popup ads.
www.browse-search.com/?
80% remove it
Muvic Smartbar Engine  by Pinwid Ltd.
This adware program injects advertisements with its affiliate ad providers in order to serve a number of ad types including banner, inline text links and popups.
82% remove it
 
Powered by Should I Remove It?

Remove Smartbar.Monetization.Proxy.ProxyRemover.exe - Powered by Reason Core Security