Smartbar.Personalization.ServicesPlugins.WordPlugin.dll

WordPlugin

Veristaff.com Inc

This is part of the Linkury/SnapDo monetization software, a web browser toolbar used to hijack a user's search in order to collect revenues. The SmartBar is a a potentially unwanted toolbar and Windows Gadget that is advertising supported (adware). The module Smartbar.Personalization.ServicesPlugins.WordPlugin.dll by Veristaff.com Inc has been detected as adware by 3 anti-malware scanners. This file is typically installed with the program SafeFinder Smartbar by Linkury Ltd. which is a potentially unwanted software program.
Publisher:
xxx  (signed by Veristaff.com Inc)

Product:
WordPlugin

Version:
1.2.0.0

MD5:
82bb7e4912092706acebaa0e2d641e43

SHA-1:
edbf5adf69b897e064292dd606fb1c966416b9ba

SHA-256:
26c97be8bc92bfb8860b24675101e855097c6873dab86e771d6edf7d4eec0926

Scanner detections:
3 / 68

Status:
Adware

Analysis date:
4/25/2024 8:43:50 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Veristaff
2015.0.3400

IKARUS anti.virus
AdWare.Linkury
t3scan.1.6.1.0

Reason Heuristics
PUP.Veristaff.q
14.7.28.9

File size:
22.8 KB (23,336 bytes)

Product version:
1.2.0.0

Copyright:
Copyright © xxx 2010

Original file name:
Smartbar.Personalization.ServicesPlugins.WordPlugin.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\smartbar\common\servicesplugins\smartbar.personalization.servicesplugins.wordplugin.dll

Digital Signature
Authority:
DigiCert Inc

Valid from:
7/8/2014 8:00:00 PM

Valid to:
7/14/2015 8:00:00 AM

Subject:
CN=Veristaff.com Inc, O=Veristaff.com Inc, L=Wilmington, S=Delaware, C=US

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0B0EA10F13BB9EB2057BECB9A30F59D4

File PE Metadata
Compilation timestamp:
7/21/2014 7:52:58 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
384:C9O4EwXaYWDmEw3qilhxWS4xdYyZgtjIvr/cTMknYPLx8I1M043:C9OW4iEwqmnmqjIjUTMk48mM043

Entry address:
0x588E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.3607

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
14.5 KB (14,848 bytes)

The file Smartbar.Personalization.ServicesPlugins.WordPlugin.dll has been discovered within the following program.

SafeFinder Smartbar  by Linkury Ltd.
SafeFinder displays advertising in the user's Internet browser by running as an extension and/or add-on. Ads are delivered in the form of search-related ads, banner and video ads, and text-links (roll-overs) as well as some popup ads.
www.linkury.com/faq/s/faq.aspx?company=SafeFinder
67% remove it
 
Powered by Should I Remove It?