srbu.dll

srbu

MY POP SHOP LTD

The module srbu.dll by MY POP SHOP has been detected as adware by 22 anti-malware scanners. This file is typically installed with the program LPT System Updater Service by Linkury Ltd. which is a potentially unwanted software program.
Publisher:
MY POP SHOP LTD  (signed and verified)

Product:
srbu

Version:
1.0.0.0

MD5:
64d91522949b385f647c7031db41db60

SHA-1:
ab53953b5ec7d7ad59356bd07cdd670f3a210300

SHA-256:
291c80bc637cca680300f14c3f535d9b0e4e6b862dc9f60af4d68a2aa43f63d5

Scanner detections:
22 / 68

Status:
Adware

Analysis date:
4/27/2024 3:40:45 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Smartbar.O
832

Avira AntiVirus
TR/Trash.Gen
7.11.30.172

AVG
Mypopshop
2015.0.3310

Baidu Antivirus
PUA.MSIL.Linkury
4.0.3.141025

Bitdefender
Adware.Smartbar.O
1.0.20.1490

Dr.Web
Trojan.Damaged.1
9.0.1.0298

Emsisoft Anti-Malware
Adware.Smartbar.O
8.14.10.25.06

ESET NOD32
MSIL/Toolbar.Linkury (variant)
8.10577

F-Secure
Adware.Smartbar.O
11.2014-25-10_7

G Data
Adware.Smartbar
14.10.24

IKARUS anti.virus
PUA.Linkury
t3scan.1.6.1.0

Malwarebytes
PUP.Optional.Linkury
v2014.10.25.06

McAfee
Artemis!64D91522949B
5600.6966

MicroWorld eScan
Adware.Smartbar.O
15.0.0.894

nProtect
Adware.Smartbar.O
14.10.16.01

Panda Antivirus
PUP/LinkUry
14.10.25.06

Qihoo 360 Security
HEUR/QVM23.0.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.MYPOPSHOP.E
14.10.25.18

Sophos
Generic PUA KL
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
10277

Trend Micro House Call
Suspicious_GEN.F47V0619
7.2.298

VIPRE Antivirus
Adware.Linkury
33994

File size:
46.5 KB (47,624 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2013

Original file name:
srbu.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\lpt\srbu.dll

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/6/2014 8:00:00 PM

Valid to:
7/7/2015 7:59:59 PM

Subject:
CN=MY POP SHOP LTD, O=MY POP SHOP LTD, STREET=14 Shenkar Arie, L=HERZLIYA, S=NA, PostalCode=46725, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
4A7D93FD75281A37A4ADCDCD636D3ADB

File PE Metadata
Compilation timestamp:
10/6/2014 7:59:48 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
768:iv+3J+T5JmB/zLzVVlNVHcPk06JlhxiZKWMY/JAkI+dVxNNaME3:iG5+ur9VlNV8YlhI8WMwJAkJ7Q3

Entry address:
0xB43E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.5044

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
37.5 KB (38,400 bytes)

The file srbu.dll has been discovered within the following program.

LPT System Updater Service  by Linkury Ltd.
This is a potentially unwanted web browser extension this is distributed and installed by PINWID LTD, ReSoft LTD., MY POP SHOP LTD and Linkury. It will display advertisements including banners and popups in the user's web browser.
81% remove it
 
Powered by Should I Remove It?

Remove srbu.dll - Powered by Reason Core Security