Smartbar.Personalization.ServicesPlugins.WeatherPlugin.dll

WeatherPlugin

Veristaff.com Inc

This is part of the Linkury/SnapDo monetization software, a web browser toolbar used to hijack a user's search in order to collect revenues. The SmartBar is a a potentially unwanted toolbar and Windows Gadget that is advertising supported (adware). The module Smartbar.Personalization.ServicesPlugins.WeatherPlugin.dll by Veristaff.com Inc has been detected as adware by 3 anti-malware scanners. This file is typically installed with the program SafeFinder Smartbar by Linkury Ltd. which is a potentially unwanted software program.
Publisher:
Veristaff.com Inc  (signed and verified)

Product:
WeatherPlugin

Version:
1.0.0.0

MD5:
6eb202a83a8d41aa69e16d2e192ee295

SHA-1:
cb400881b8ea90e040b51d5b0537fef631ff2bb9

SHA-256:
baef18b6585ec142b5eb93787beeea77fec0c6d65ed669c3d8bd704a8aa8c90c

Scanner detections:
3 / 68

Status:
Adware

Analysis date:
4/20/2024 1:38:53 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Veristaff
2015.0.3400

IKARUS anti.virus
AdWare.Linkury
t3scan.1.6.1.0

Reason Heuristics
PUP.Veristaff.t
14.7.28.9

File size:
29.3 KB (29,992 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2012

Original file name:
Smartbar.Personalization.ServicesPlugins.WeatherPlugin.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\smartbar\common\servicesplugins\smartbar.personalization.servicesplugins.weatherplugin.dll

Digital Signature
Authority:
DigiCert Inc

Valid from:
7/8/2014 8:00:00 PM

Valid to:
7/14/2015 8:00:00 AM

Subject:
CN=Veristaff.com Inc, O=Veristaff.com Inc, L=Wilmington, S=Delaware, C=US

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0B0EA10F13BB9EB2057BECB9A30F59D4

File PE Metadata
Compilation timestamp:
7/21/2014 7:53:24 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
384:OiJHbrhFpqjTjV2hKiWgZ7lnfqpYovVN8NtPV3rxFlSW/Xso+06tUL/pI7ekPhne:Jrh57Z9lod2HXcUbpIikpnSTMR48mM0l

Entry address:
0x7362

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.4099

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
21 KB (21,504 bytes)

The file Smartbar.Personalization.ServicesPlugins.WeatherPlugin.dll has been discovered within the following program.

SafeFinder Smartbar  by Linkury Ltd.
SafeFinder displays advertising in the user's Internet browser by running as an extension and/or add-on. Ads are delivered in the form of search-related ads, banner and video ads, and text-links (roll-overs) as well as some popup ads.
www.linkury.com/faq/s/faq.aspx?company=SafeFinder
67% remove it
 
Powered by Should I Remove It?