buttonutil.dll

Innovative Apps

This file is a support library for an advertising-based software package (potentially unwanted/adware) distributed by 50onRed used to hijack the Internet browser search provider. The module buttonutil.dll by Innovative Apps has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program Deal Spy by 215 Apps which is a potentially unwanted software program.
Publisher:
Innovative Apps  (signed and verified)

MD5:
c0685ba5091b54b36c22229cfbce9a0c

SHA-1:
675088d5a5ea8f2df3be07c12543fefa4fc29b5d

SHA-256:
3949b8691026bfa7c8f88b33460667872a820bb3a5116b7a82efb6bd7bf3dd26

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/16/2024 6:45:09 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.50OnRed.InnovativeApps (M)
16.2.12.11

File size:
239.9 KB (245,640 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\deal spy\buttonutil.dll

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
1/8/2013 6:00:00 PM

Valid to:
1/9/2014 5:59:59 PM

Subject:
CN=Innovative Apps, O=Innovative Apps, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
5419E32FDAD7A6E5666A35066C5EAAC5

File PE Metadata
Compilation timestamp:
2/11/2013 8:08:18 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:eJVrno90DDvPuUFp7VfeNl3QQFA/6p4veOmkW3fte:IZno9uDvP1doQQFA/6p4vrxWfte

Entry address:
0x1B5A2

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, AC, 64, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 83, EC, 18, 53, 8B, 5D, 0C, 56, 8B, 73, 08, 33, 35, 70, 64, 03, 10, 57, 8B, 06, C6, 45, FF, 00, C7, 45, F4, 01, 00, 00, 00, 8D, 7B, 10, 83, F8, FE, 74, 0D, 8B, 4E, 04, 03, CF, 33, 0C, 38, E8, BE, E0, FF, FF, 8B, 4E, 0C, 8B, 46, 08, 03, CF, 33, 0C, 38, E8, AE, E0, FF, FF, 8B, 45, 08, F6, 40, 04, 66, 0F, 85...
 
[+]

Entropy:
6.5850

Code size:
172.5 KB (176,640 bytes)

The file buttonutil.dll has been discovered within the following program.

Deal Spy  by 215 Apps
Deal Spy from 215 Apps (Amazing Apps, Friendly Apps, and a bunch of other names 50onRed goes by) installs an extension within all the major browsers to view web pages loaded and looks for affiliated merchants in order to possibly provide better pricing or alternative deals on a given product or merchant.
87% remove it
 
Powered by Should I Remove It?

Remove buttonutil.dll - Powered by Reason Core Security