smuninstall.exe

Goobzo LTD

The application smuninstall.exe by Goobzo has been detected as adware by 14 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is the uninstaller utility registered in the Windows Control Panel for the program Search Module Plus by Goobzo. This file is typically installed with the program Search Module Plus by Goobzo LTD which is a potentially unwanted software program.
Publisher:
Goobzo LTD  (signed and verified)

Version:
2.1.8.524

MD5:
8531505a1fc134f76c3fc705253990d0

SHA-1:
166eeb917f76e7abfb97ec0ca6d78c8f4beac348

SHA-256:
9f12ee98875e4a5e07d4ae147849e1c0d5518bfe967d8b2ba49d14d9728ed04a

Scanner detections:
14 / 68

Status:
Adware

Explanation:
Bundles various adware toolbars and browser extensions.

Analysis date:
4/26/2024 4:56:53 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win-PUP/CrossRider
2015.02.01

Avira AntiVirus
W32/Ramnit.C
7.11.30.172

avast!
Adware-CDO [PUP]
150101-1

AVG
Skodna
2016.0.3213

Dr.Web
Adware.Downware.6419
9.0.1.05190

ESET NOD32
Win32/SBWatchman.D potentially unwanted application
7.0.302.0

G Data
Win32.Application.GoobZo
15.1.25

K7 AntiVirus
Unwanted-Program
13.193.14818

Kaspersky
not-a-virus:AdWare.Win32.Shopper
15.0.0.543

NANO AntiVirus
Trojan.Nsis.Agent.dmgbnp
0.30.0.65070

Panda Antivirus
Adware/Goobzo
15.01.31.08

Reason Heuristics
PUP.Goobzo
15.1.31.7

Sophos
PUA 'AppRider' (of type Adware)
5.09

VIPRE Antivirus
Threat.4792716
36666

File size:
540.1 KB (553,056 bytes)

Product version:
2.1.8.524

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\Program Files\common files\goobzo\gbupdateplus\smuninstall.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/2/2013 1:00:00 AM

Valid to:
5/3/2015 12:59:59 AM

Subject:
CN=Goobzo LTD, O=Goobzo LTD, L=Haifa, S=Israel, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
120B25DDE57B88636AD4D97D23B99C88

File PE Metadata
Compilation timestamp:
5/11/2014 9:03:36 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:kTZmPiU5R79JXMbe0Cs97wcOWjHTHnxbk3Pin5e1jr5/:kAKU79BMbe0Cs9MKTb5eHt

Entry address:
0x3217

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 89, 5C, 24, 20, C6, 44, 24, 14, 20, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 8C, 72, 40, 00, 6A, 08, A3, 98, 37, 42, 00, E8, AD, 2D, 00, 00, A3, E4, 36, 42, 00, 53, 8D, 44, 24, 38, 68, 60, 01, 00, 00, 50, 53, 68, A0, EC, 41, 00, FF, 15, 64, 71, 40, 00, 68, E4, 91, 40, 00, 68, E0, 2E, 42, 00, E8, 57, 2A, 00, 00, FF, 15, B0, 70, 40, 00, BD, 00, 90, 42, 00, 50, 55, E8, 45, 2A...
 
[+]

Entropy:
7.9799

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

Program Uninstaller
Program name:
Search Module Plus

Display publisher:
Goobzo

Uninstall string:
C:\Program Files\Common Files\Goobzo\GBUpdatePlus\smUninstall.exe


The file smuninstall.exe has been discovered within the following program.

Search Module Plus  by Goobzo LTD
Goobzo's Search Module Plus is a web browser toolbar/extension that will insert itself into IE, Firefox or Chrome and will modify the search and home page providers of the targeted browser. Once installed Search Module Plus changes Windows host file and DNS settings.
79% remove it
 
Powered by Should I Remove It?

Remove smuninstall.exe - Powered by Reason Core Security