Coupon Companion Plugin.dll

Coupon Companion Plugin

215 Apps

This web browser extension uses the Crossrider toolbar creation and distribution platform. The module Coupon Companion Plugin.dll, “Coupon Companion Plugin BHO” has been detected as adware by 26 anti-malware scanners. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘CrossriderApp0021804’. This file is typically installed with the program Coupon Companion Plugin by 215 Apps which is a potentially unwanted software program. The library is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
215 Apps

Product:
Coupon Companion Plugin

Description:
Coupon Companion Plugin BHO

Version:
1.1.151.5

MD5:
2d964d5b81da98a69319b6935113108b

SHA-1:
11c28559ea3d238dccf2c457c4972e3eb6291ea5

SHA-256:
d5aa3425bb491f8cad73e70266b5c14e32e86da73928faef442fad64134db705

Scanner detections:
26 / 68

Status:
Adware

Explanation:
May modify the web browser's settings including changing the homepage and search provider in addition to delivering ads (by injecting banner and text-links directly in the webpage).

Analysis date:
4/27/2024 4:08:56 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.VidSaver.1
922

Agnitum Outpost
Trojan.Adware
7.1.1

AhnLab V3 Security
Win-Trojan/Agent2.M.617344.H
2013.12.24

Avira AntiVirus
Adware/Vidsaver.A.12
7.11.121.112

AVG
MalSign.Skodna
2015.0.3400

Baidu Antivirus
Trojan.Win32.Agent
4.0.3.14110

Bitdefender
Gen:Variant.Adware.VidSaver.1
1.0.20.1045

Boost by Reason
Optional.BHO.215Apps.X
188163

Comodo Security
ApplicUnwnt
17581

Emsisoft Anti-Malware
Gen:Variant.Adware.VidSaver
8.14.07.28.01

ESET NOD32
Win32/Toolbar.CrossRider (variant)
8.9271

Fortinet FortiGate
Riskware/CrossRider.A
1/10/2014

F-Secure
Gen:Variant.Adware.VidSaver.1
11.2014-28-07_2

G Data
Gen:Variant.Adware.VidSaver
14.7.22

herdProtect (fuzzy)
2014.1.26.11

IKARUS anti.virus
AdWare.Win32.Vidsaver
t3scan.2.2.29

McAfee
Artemis!7E68FD9E08F3
5600.7056

Microsoft Security Essentials
Adware:Win32/Vidsaver
1.165.247.01

MicroWorld eScan
Gen:Variant.Adware.VidSaver.1
15.0.0.627

Panda Antivirus
Trj/CI.A
14.07.28.01

Reason Heuristics
PUP.BHO.215Apps.X
14.2.21.8

Rising Antivirus
PE:Trojan.Win32.Generic.14C086EF!348161775
23.00.65.14108

Sophos
AppRider
4.96

Trend Micro House Call
TROJ_GEN.R0CBH05JG13
7.2.10

Trend Micro
TROJ_GEN.RCBCDAH
10.465.28

VIPRE Antivirus
Crossrider
25260

File size:
599 KB (613,376 bytes)

Product version:
1.1.151.5

Copyright:
Copyright 2011

Original file name:
Coupon Companion Plugin.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\coupon companion plugin\coupon companion plugin.dll

Registration
CLSIDs:
{11111111-1111-1111-1111-110211181104}, {22222222-2222-2222-2222-220222182204}

ProgIDs:
CrossriderApp0021804.BHO.1, CrossriderApp0021804.Sandbox.1

COM registered:
Yes

File PE Metadata
Compilation timestamp:
11/12/2012 8:12:12 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:dUIXJ8ND/bhpduBwiOOpQAFWrsZhwYOF4rTbTkGmOkDm+N+pP:+BD/bhpduBrOOpgrKwjyrT3kBOktN+pP

Entry address:
0x3B7DE

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 96, 9A, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 8B, 45, 08, 85, C0, 74, 12, 83, E8, 08, 81, 38, DD, DD, 00, 00, 75, 07, 50, E8, 55, C2, FF, FF, 59, 5D, C3, 8B, FF, 55, 8B, EC, 83, EC, 10, A1, E0, 7D, 08, 10, 33, C5, 89, 45, FC, 8B, 55, 18, 53, 33, DB, 56, 57, 3B, D3, 7E, 1F, 8B, 45, 14, 8B, CA, 49, 38, 18, 74, 08, 40, 3B, CB, 75, F6, 83, C9, FF, 8B, C2, 2B, C1, 48, 3B, C2, 7D, 01, 40, 89, 45, 18...
 
[+]

Entropy:
6.5886

Code size:
421 KB (431,104 bytes)

Internet Explorer BHO
Display name:
CrossriderApp0021804

CLSID:
{11111111-1111-1111-1111-110211181104}

CLSID name:
Coupon Companion Plugin


The file Coupon Companion Plugin.dll has been discovered within the following program.

Coupon Companion by Red Online Marketing Group is a Browser Helper Object installed into Internet Explorer that monitors web pages for possible affiliate merchant partners.
coupon-companion.com
83% remove it
 
Powered by Should I Remove It?

Remove Coupon Companion Plugin.dll - Powered by Reason Core Security