_common.dll

Secure Web

Big Water Applications, LLC

This is part of an adware program designed to inject advertising in the web browser (banners, text-links) as well as modify the normal behavior of the browser as well as modify the computer’s system settings that control applications to run on startup. Part of the Injekt brand of unwanted programs. The module _common.dll by Big Water Applications has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program Secure Web by Big Water Applications, LLC which is a potentially unwanted software program.
Publisher:
Big Water Applications, LLC  (signed and verified)

Product:
Secure Web

Version:
2.6.49

MD5:
5d386f290760f66e65c1aa1e6f83c104

SHA-1:
676afe9bb382c88961bb27c4f25316f49111e46c

SHA-256:
d2b0217690c14ba542e9d3e1049eca739cdb9eb7855392ba594dd8321d10e4fa

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
4/26/2024 8:26:15 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Injekt.BigWaterApplications (M)
15.12.14.9

File size:
400.1 KB (409,704 bytes)

Product version:
2.6.49

Copyright:
(c) Big Water Applications, LLC

Original file name:
common.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\ProgramData\secureweb\ie\_common.dll

Digital Signature
Authority:
COMODO CA Limited

Valid from:
4/21/2013 7:00:00 PM

Valid to:
4/22/2014 6:59:59 PM

Subject:
CN="Big Water Applications, LLC", O="Big Water Applications, LLC", STREET=640 Grand Ave, STREET=Suite E, L=Carlsbad, S=CA, PostalCode=92008, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0088DD6A4DF46D819C84B9E99D7A0530C5

File PE Metadata
Compilation timestamp:
11/20/2013 3:23:58 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:yvEH4vCKW8OV1MPslbSnWkLJMTFwULkvPXKfDEVU8I2qBUWVoM3aitpq:d1VCsl2nPL0FoPXKfDEVOqitQ

Entry address:
0x15A0C

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 14, 5D, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, CC, 8B, FF, 55, 8B, EC, 83, EC, 18, 53, 8B, 5D, 0C, 56, 8B, 73, 08, 33, 35, A0, 9C, 04, 10, 57, 8B, 06, C6, 45, FF, 00, C7, 45, F4, 01, 00, 00, 00, 8D, 7B, 10, 83, F8, FE, 74, 0D, 8B, 4E, 04, 03, CF, 33, 0C, 38, E8, EE, C1, FF, FF, 8B, 4E, 0C, 8B, 46, 08, 03, CF, 33, 0C, 38, E8, DE, C1, FF, FF, 8B, 45, 08, F6, 40, 04, 66, 0F, 85, 19, 01, 00, 00, 8B, 4D, 10, 8D, 55, E8...
 
[+]

Entropy:
6.4284

Code size:
232.5 KB (238,080 bytes)

The file _common.dll has been discovered within the following program.

Secure Web  by Big Water Applications, LLC
SecureWeb is an adware web browser extension that will inject advertisements into the user's browser. It is typically bundled by the Conduit installer.
www.getsecureweb.com
83% remove it
 
Powered by Should I Remove It?

Remove _common.dll - Powered by Reason Core Security