smi64.exe

SBInject Application

Goobzo LTD

The application smi64.exe by Goobzo has been detected as adware by 28 anti-malware scanners.
Publisher:
Goobzo LTD  (signed and verified)

Product:
SBInject Application

Version:
2, 1, 0, 93

MD5:
df41ea702c26643f23449bf7a61e55ef

SHA-1:
5f2c8909e8b56cd8132199e4ec6026812b0eb232

SHA-256:
e79778a8832f065725f47d813c6cdc4bd19b0c4ddbaf31bb97f6b9c9264ef59e

Scanner detections:
28 / 68

Status:
Adware

Analysis date:
4/24/2024 6:52:23 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Generic.1162760
526

AhnLab V3 Security
Win-PUP/CrossRider
2015.04.04

avast!
Win32:Adware-CDO [PUP]
2014.9-150827

AVG
ShopperPro
2016.0.3004

Baidu Antivirus
Adware.Win32.Shopper
4.0.3.15827

Bitdefender
Adware.Generic.1162760
1.0.20.1195

Bkav FE
W64.HfsAdware
1.3.0.6379

Emsisoft Anti-Malware
Adware.SearchModule
8.15.08.27.11

ESET NOD32
MSIL/SBWatchman.A potentially unwanted (variant)
9.11425

Fortinet FortiGate
Adware/Shopper
8/27/2015

F-Secure
Adware.Generic.1162760
11.2015-27-08_5

G Data
Adware.Generic.1162760
15.8.25

IKARUS anti.virus
PUA.MSIL.SBWatchman
t3scan.1.8.9.0

K7 AntiVirus
Trojan
13.202.15484

Kaspersky
not-a-virus:AdWare.Win32.Shopper
14.0.0.1515

McAfee
Artemis!DF41EA702C26
5600.6660

MicroWorld eScan
Adware.SearchModule.C
16.0.0.717

NANO AntiVirus
Riskware.Win64.Shopper.dnsjvp
0.30.8.659

Norman
Adware.SearchModule.C
11.20150827

nProtect
Trojan-Clicker/W32.Shopper.101224
15.04.03.01

Panda Antivirus
Adware/Goobzo
15.08.27.11

Reason Heuristics
PUP.Goobzo (M)
15.8.27.23

Rising Antivirus
PE:Trojan.Win32.Generic.17F5D823!401987619
23.00.65.15825

Trend Micro House Call
TROJ_GEN.R047C0EBQ15
7.2.239

Trend Micro
TROJ_GEN.R047C0EBQ15
10.465.27

Vba32 AntiVirus
AdWare.Shopper
3.12.26.3

VIPRE Antivirus
Goobzo
39052

Zillya! Antivirus
Adware.Shopper.Win32.634
2.0.0.2127

File size:
98.9 KB (101,224 bytes)

Product version:
2, 1, 0, 93

Copyright:
Copyright (C) 2014

Original file name:
SBInject.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\common files\goobzo\gbupdateplus\smi64.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/1/2013 8:00:00 PM

Valid to:
5/2/2015 7:59:59 PM

Subject:
CN=Goobzo LTD, O=Goobzo LTD, L=Haifa, S=Israel, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
120B25DDE57B88636AD4D97D23B99C88

File PE Metadata
Compilation timestamp:
2/4/2015 4:27:34 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
1536:VGG8FRXVQz9f0QO2CPBTzeXViSoLJSD0TknpLI4sO+zAUBv:VuXVQBMQOhPBTwiSoLJA0ILI4sO+Hv

Entry address:
0xA3D8

Entry point:
48, 83, EC, 28, E8, D3, 03, 00, 00, 48, 83, C4, 28, E9, FA, FC, FF, FF, CC, CC, 48, 89, 4C, 24, 08, 48, 81, EC, 88, 00, 00, 00, 48, 8D, 0D, F1, C4, 00, 00, FF, 15, 13, 3C, 00, 00, 4C, 8B, 1D, DC, C5, 00, 00, 4C, 89, 5C, 24, 58, 45, 33, C0, 48, 8D, 54, 24, 60, 48, 8B, 4C, 24, 58, E8, 5D, 04, 00, 00, 48, 89, 44, 24, 50, 48, 83, 7C, 24, 50, 00, 74, 41, 48, C7, 44, 24, 38, 00, 00, 00, 00, 48, 8D, 44, 24, 48, 48, 89, 44, 24, 30, 48, 8D, 44, 24, 40, 48, 89, 44, 24, 28, 48, 8D, 05, 9C, C4, 00, 00, 48, 89, 44, 24...
 
[+]

Entropy:
5.8563

Code size:
49.5 KB (50,688 bytes)

Remove smi64.exe - Powered by Reason Core Security