smei32.dll

W

Goobzo LTD

The module smei32.dll, “Search Module Plus Update Service” by Goobzo has been detected as adware by 19 anti-malware scanners. This file is typically installed with the program Search Module Plus by Goobzo LTD which is a potentially unwanted software program.
Publisher:
Search Module Plus Ltd.  (signed by Goobzo LTD)

Product:
W

Description:
Search Module Plus Update Service

Version:
2, 1, 8, 525

MD5:
002523e5f493fd993a83ca23e4efe2dd

SHA-1:
5a177d8d8f620329d33bcf11de76312e5a9cec5d

SHA-256:
9f5870fbe7535974dad87efdd3e949ec23078e7caedd0bcdd376e53c6b888701

Scanner detections:
19 / 68

Status:
Adware

Analysis date:
4/25/2024 9:02:04 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Graftor.171106
6496598

AhnLab V3 Security
Win-PUP/CrossRider
2015.02.01

avast!
Win32:Adware-CDO [PUP]
150101-1

AVG
Skodna
2016.0.3213

Baidu Antivirus
Adware.Win32.Shopper
4.0.3.15226

Bitdefender
Gen:Variant.Graftor.171106
1.0.20.155

Bkav FE
W32.HfsAdware
1.3.0.6379

Emsisoft Anti-Malware
Gen:Variant.Graftor.171106
9.0.0.4799

ESET NOD32
Win32/SBWatchman.A potentially unwanted application
7.0.302.0

F-Secure
Gen:Variant.Graftor.171106
5.13.68

G Data
Gen:Variant.Graftor.171106
15.1.25

IKARUS anti.virus
AdWare.Win32.SBWatchman
t3scan.1.8.6.0

K7 AntiVirus
Unwanted-Program
13.197.15026

Kaspersky
not-a-virus:AdWare.Win32.Shopper
15.0.0.543

MicroWorld eScan
Gen:Variant.Graftor.171106
16.0.0.93

Panda Antivirus
Adware/Goobzo
15.01.31.07

Reason Heuristics
PUP.Goobzo
15.1.31.7

Sophos
PUA 'Goobzo' (of type Adware)
5.09

VIPRE Antivirus
Threat.4792716
36666

File size:
708.9 KB (725,864 bytes)

Product version:
2, 1, 8, 525

Copyright:
Copyright (C) 2014

Original file name:
smu.exe

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\common files\goobzo\gbupdateplus\smei32.dll

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/2/2013 1:00:00 AM

Valid to:
5/3/2015 12:59:59 AM

Subject:
CN=Goobzo LTD, O=Goobzo LTD, L=Haifa, S=Israel, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
120B25DDE57B88636AD4D97D23B99C88

File PE Metadata
Compilation timestamp:
1/31/2015 7:10:29 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:vLXJkmMtDWFdk/HYGRMH93FKdraLO9ZlgEHNgZRjdmS:tChdh9ZZgZRRmS

Entry address:
0x6295E

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 78, 03, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, CC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, B0, D1, 09, 10, 89, 0D, AC, D1, 09, 10, 89, 15, A8, D1, 09, 10, 89, 1D, A4, D1, 09, 10, 89, 35, A0, D1, 09, 10, 89, 3D, 9C, D1, 09, 10, 66, 8C, 15, C8, D1, 09, 10, 66, 8C, 0D, BC, D1, 09, 10, 66, 8C, 1D, 98, D1, 09, 10, 66, 8C, 05, 94, D1, 09, 10, 66, 8C, 25, 90, D1, 09, 10, 66, 8C, 2D, 8C, D1, 09, 10, 9C, 8F, 05, C0, D1...
 
[+]

Entropy:
6.4315

Code size:
437 KB (447,488 bytes)

The file smei32.dll has been discovered within the following program.

Search Module Plus  by Goobzo LTD
Goobzo's Search Module Plus is a web browser toolbar/extension that will insert itself into IE, Firefox or Chrome and will modify the search and home page providers of the targeted browser. Once installed Search Module Plus changes Windows host file and DNS settings.
79% remove it
 
Powered by Should I Remove It?

Remove smei32.dll - Powered by Reason Core Security