common.dll

Search Deals

Injekt LLC

This is part of an adware program designed to inject advertising in the web browser (banners, text-links) as well as modify the normal behavior of the browser as well as modify the computer’s system settings that control applications to run on startup. Part of the Injekt brand of unwanted programs. The module common.dll by Injekt has been detected as adware by 4 anti-malware scanners. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘Search Deals’.
Publisher:
CloudCanvas, Inc. DBA Injekt  (signed by Injekt LLC)

Product:
Search Deals

Version:
2.6.78

MD5:
f8a61d684c5bee6cda60c3fdc18548e4

SHA-1:
f3bb5f31451d55f85c3a8b0138f1c083d28c31f9

SHA-256:
e77a19f60bee700f190f91edc0c03e1346090e85d17f2ec368d8e61c143e600a

Scanner detections:
4 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
4/25/2024 9:48:49 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:BHO-AMO [PUP]
2014.9-140424

Dr.Web
Adware.Plugin.128
9.0.1.0114

ESET NOD32
Win32/ExFriendAlert (variant)
8.9704

Reason Heuristics
PUP.BHO.Injekt.G
14.8.8.3

File size:
399.3 KB (408,928 bytes)

Product version:
2.6.78

Copyright:
(c) CloudCanvas, Inc. DBA Injekt

Original file name:
common.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\ProgramData\searchdeals2\ie\common.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/22/2014 8:00:00 PM

Valid to:
6/22/2015 7:59:59 PM

Subject:
CN=Injekt LLC, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Injekt LLC, L=Carlsbad, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
22388FB3C3238D36E8B8ABBBE3903F04

Registration
CLSID:
{44ed99e2-16a6-4b89-80d6-5b21cf42e78b}

ProgID:
DynConIE.DynConIEObject.1

COM registered:
Yes

File PE Metadata
Compilation timestamp:
4/17/2014 8:27:56 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:9vkn4PC6Wc+lV8PsFbSnqDrrpeW0ULkMPX+fDEVU1WoqBUWVoM35it:eBlysF2n8r8WbPX+fDEV9pit

Entry address:
0x15A0C

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 14, 5D, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, CC, 8B, FF, 55, 8B, EC, 83, EC, 18, 53, 8B, 5D, 0C, 56, 8B, 73, 08, 33, 35, A0, 9C, 04, 10, 57, 8B, 06, C6, 45, FF, 00, C7, 45, F4, 01, 00, 00, 00, 8D, 7B, 10, 83, F8, FE, 74, 0D, 8B, 4E, 04, 03, CF, 33, 0C, 38, E8, EE, C1, FF, FF, 8B, 4E, 0C, 8B, 46, 08, 03, CF, 33, 0C, 38, E8, DE, C1, FF, FF, 8B, 45, 08, F6, 40, 04, 66, 0F, 85, 19, 01, 00, 00, 8B, 4D, 10, 8D, 55, E8...
 
[+]

Entropy:
6.4251

Code size:
232.5 KB (238,080 bytes)

Internet Explorer BHO
Display name:
Search Deals

CLSID:
{44ed99e2-16a6-4b89-80d6-5b21cf42e78b}


Remove common.dll - Powered by Reason Core Security