buttonwrap.dll

Browser Extensions

Spigot, Inc.

This component is part of the Spigot browser add-on, a web browser addition that is designed to modify the core search provider in order to redirect search queries through partner portals. The module buttonwrap.dll, “Browser Extensions for Internet Explorer” by Spigot has been detected as adware by 2 anti-malware scanners. This file is typically installed with the program Browser Extensions by Spigot, Inc. which is a potentially unwanted software program.
Publisher:
S p i g o t, I n c .  (signed by Spigot, Inc.)

Product:
Browser Extensions

Description:
Browser Extensions for Internet Explorer

Version:
1, 6, 0, 3

MD5:
9d4c7fef9915185900249b2406ffdf75

SHA-1:
dd5c3b6e5254a75fcb84d4f3208a6d34df7e0dec

SHA-256:
37ee39a20e0732b1e9b1e514a1df28e4c9c3d6405d130df93d6e2aaa3e8d720a

Scanner detections:
2 / 68

Status:
Adware

Analysis date:
4/25/2024 8:13:19 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Spigot.K
14.8.22.12

Sophos
Spigot Toolbar
4.98

File size:
216.9 KB (222,056 bytes)

Product version:
1, 6, 0, 3

Copyright:
2013 - 2014 (c) Spigot, Inc. All rights reserved.

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\browser extensions\buttonwrap.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/26/2012 8:00:00 AM

Valid to:
3/29/2015 7:59:59 AM

Subject:
CN="Spigot, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Spigot, Inc.", L=El Granada, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
494FF8E91607158CD480B23C615CFF8B

File PE Metadata
Compilation timestamp:
8/13/2014 1:05:43 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:UpMhlBguAONdSG0+O3+cGuqQOXqt1zCmK:UpgZiG0r9GuP1zC3

Entry address:
0x7DF3

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, D4, 2B, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 69, 33, C0, 8A, 44, 24, 08, 84, C0, 75, 16, 81, FA, 00, 01, 00, 00, 72, 0E, 83, 3D, C0, BB, 01, 10, 00, 74, 05, E9, 78, 2C, 00, 00, 57, 8B, F9, 83, FA, 04, 72, 31, F7, D9, 83, E1, 03, 74, 0C, 2B, D1, 88, 07, 83, C7, 01, 83, E9, 01, 75, F6, 8B, C8, C1, E0, 08, 03, C1, 8B, C8, C1, E0, 10...
 
[+]

Entropy:
4.9965

Code size:
74.5 KB (76,288 bytes)

The file buttonwrap.dll has been discovered within the following programs.

Browser Extensions  by Spigot, Inc.
Publisher's description - “The toolbar communicates with our servers from time to time to check for available software updates such as bug fixes, patches, enhanced functions and new versions. By installing the toolbar, you agree to automatically request and receive updates.”
www.spigot.com
66% remove it
 
Powered by Should I Remove It?

Remove buttonwrap.dll - Powered by Reason Core Security