Smartbar.Personalization.ServicesPlugins.MessengerPlugin.dll

MessengerPlugin

ReSoft LTD.

This is part of the Linkury/SnapDo monetization software, a web browser toolbar used to hijack a user's search in order to collect revenues. The SmartBar is a a potentially unwanted toolbar and Windows Gadget that is advertising supported (adware). The module Smartbar.Personalization.ServicesPlugins.MessengerPlugin.dll by ReSoft has been detected as adware by 4 anti-malware scanners.
Publisher:
Microsoft  (signed by ReSoft LTD.)

Product:
MessengerPlugin

Version:
1.2.0.0

MD5:
f63076fcb9bcc9e56db18a0877616de8

SHA-1:
43ef20d8f4b30aa99e7d8467de5968518c93e099

SHA-256:
b9df478d33bf0b4e7f02a91a62b6d05f8c09699d96e4a3ac68a833c25a39d3f5

Scanner detections:
4 / 68

Status:
Adware

Analysis date:
4/27/2024 12:32:21 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/Linkury.Gen2
7.11.174.76

AVG
Adware AdInject.Resoft
2014.0.4040

Reason Heuristics
PUP.ReSoft.v
14.10.19.23

Trend Micro House Call
TROJ_GEN.F47V0814
7.2.292

File size:
13 KB (13,312 bytes)

Product version:
1.2.0.0

Copyright:
Copyright © Microsoft 2011

Original file name:
Smartbar.Personalization.ServicesPlugins.MessengerPlugin.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\smartbar\common\servicesplugins\smartbar.personalization.servicesplugins.messengerplugin.dll

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/29/2012 8:00:00 PM

Valid to:
7/30/2013 7:59:59 PM

Subject:
CN=ReSoft LTD., O=ReSoft LTD., STREET=4th Hanevi'im, L=Tel Aviv, S=Israel, PostalCode=64356, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
7ABDE829D4244ADA77EE42C7A70C0FA3

File PE Metadata
Compilation timestamp:
2/10/2013 1:46:34 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
192:ENaAFsSNmtVPdv/I1RLHeFW0W3MBsnJfHix8fe+PjPW38LWM18og2qg6:JAFX4xNIvgW0W3MBsnhCxYPLg8Y

Entry address:
0x2C2E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.3568

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
3.5 KB (3,584 bytes)