Coupons.dll

Slick Savings

Spigot, Inc.

This component is part of the Spigot browser add-on, a web browser addition that is designed to modify the core search provider in order to redirect search queries through partner portals. The module Coupons.dll, “Slick Savings for Internet Explorer” by Spigot has been detected as adware by 2 anti-malware scanners. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘Slick Savings’. This file is typically installed with the program Slick Savings by Spigot, Inc. which is a potentially unwanted software program.
Publisher:
Spigot, Inc.  (signed and verified)

Product:
Slick Savings

Description:
Slick Savings for Internet Explorer

Version:
1, 0, 0, 2

MD5:
6b1a43ff810aaceb2dc7cfa541e89cf3

SHA-1:
54c4467a3d5b3b069fc8c0e85e1060e2cd739246

SHA-256:
fc240917c04bbce4c9cf5eedc2cb91a5ce7b372c2cc711a9e99676cca834b5c7

Scanner detections:
2 / 68

Status:
Adware

Analysis date:
4/26/2024 2:58:38 PM UTC  (today)

Scan engine
Detection
Engine version

Boost by Reason
PUP.Spigot.H
13.11.22.16

Reason Heuristics
PUP.BHO.Spigot.H
14.8.7.21

File size:
526.3 KB (538,944 bytes)

Product version:
1, 0, 0, 2

Copyright:
2013 (c) Spigot, Inc. All rights reserved.

Original file name:
Coupons.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\slick savings\coupons.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/25/2012 4:00:00 PM

Valid to:
3/28/2015 4:59:59 PM

Subject:
CN="Spigot, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Spigot, Inc.", L=El Granada, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
494FF8E91607158CD480B23C615CFF8B

File PE Metadata
Compilation timestamp:
4/11/2013 11:37:26 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:idNjasMOqpGZBxOoXIua+UYm8TY4gS9s1sbsXIWTd4FJrbhLbS:idzFwN+xNgS9lbsXTTd4zrbB2

Entry address:
0x3B5DF

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, D7, 8E, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, C1, 83, 60, 04, 00, 83, 60, 08, 00, C7, 00, 0C, AC, 05, 10, C3, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 56, 57, 8B, F9, C7, 07, 0C, AC, 05, 10, 8B, 03, 85, C0, 74, 26, 50, E8, 9E, 8F, 00, 00, 8B, F0, 46, 56, E8, 25, E9, FF, FF, 59, 59, 89, 47, 04, 85, C0, 74, 12, FF, 33, 56, 50, E8, 0F, 8F, 00, 00, 83, C4, 0C, EB, 04, 83, 67, 04, 00, C7, 47, 08, 01, 00, 00, 00, 8B, C7...
 
[+]

Entropy:
6.3920

Code size:
328 KB (335,872 bytes)

Internet Explorer BHO
Display name:
Slick Savings

CLSID:
{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}


The file Coupons.dll has been discovered within the following program.

Slick Savings  by Spigot, Inc.
Slick Savings is an ad-supported (users may see additional banner, search, pop-up, pop-under, interstitial and in-text link advertisements) cross web browser plugin for Internet Explorer (BHO) and Firefox/Chrome (plugin) and distributed through various monetization platforms during installation.
www.spigot.com
85% remove it
 
Powered by Should I Remove It?

Remove Coupons.dll - Powered by Reason Core Security