Smartbar.Monetization.Proxy.ProxyRemover.exe

ProxyRemover

PINWID LTD

This is part of the Linkury/SnapDo monetization software, a web browser toolbar used to hijack a user's search in order to collect revenues. The SmartBar is a a potentially unwanted toolbar and Windows Gadget that is advertising supported (adware). The application Smartbar.Monetization.Proxy.ProxyRemover.exe by PINWID has been detected as adware by 3 anti-malware scanners. This file is typically installed with the program Muvic Smartbar by Pinwid Ltd. which is a potentially unwanted software program.
Publisher:
PINWID LTD  (signed and verified)

Product:
ProxyRemover

Version:
1.0.0.0

MD5:
08fa8a6205ca8d615d922910c0340772

SHA-1:
9aad54bbf9781ef14f4f6933a99041b10e99d576

SHA-256:
c133fe0a03e48ae9130c272188dd19f78b2404ea28f113c854679da7237be991

Scanner detections:
3 / 68

Status:
Adware

Analysis date:
4/20/2024 12:07:59 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
MalSign.Pindi
2015.0.3425

IKARUS anti.virus
AdWare.Linkury
t3scan.1.6.1.0

Reason Heuristics
PUP.PINWID.f
14.7.3.5

File size:
24 KB (24,608 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2014

Original file name:
Smartbar.Monetization.Proxy.ProxyRemover.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\lpt\smartbar.monetization.proxy.proxyremover.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/4/2014 6:00:00 PM

Valid to:
2/5/2015 5:59:59 PM

Subject:
CN=PINWID LTD, O=PINWID LTD, STREET=14 Shenkar Arie, L=HERZLIYA, S=NA, PostalCode=46733, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00D9AC9FC9A1B1E8FD63013E3CCE7B0578

File PE Metadata
Compilation timestamp:
6/15/2014 9:24:32 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
384:qa9yJAhrLRxa8iIig9e9dlxZHmqdFtU5HUKYD1nhCxYPLg8l4:L9EOL/XzigwrnU5HUKYD1MEl

Entry address:
0x58D6

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.3525

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
14.5 KB (14,848 bytes)

The file Smartbar.Monetization.Proxy.ProxyRemover.exe has been discovered within the following program.

Muvic Smartbar  by Pinwid Ltd.
This adware injects advertising in the user's Internet browser by running as an extension and/or add-on. Ads are delivered in the form of banners and text-links (roll-overs) as well as some popup ads.
www.browse-search.com/?
80% remove it
 
Powered by Should I Remove It?

Remove Smartbar.Monetization.Proxy.ProxyRemover.exe - Powered by Reason Core Security