crimsolite.IEUpdate.dll

crimsolite

This is the Internet Explorer add-on for the Yontoo crimsolite branded web browser plugin (injects banner, text-link and popup ads). The component is responisble for registering the Browser Helper Object into IE and keeping it registered. The module crimsolite.IEUpdate.dll by crimsolite has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
crimsolite  (signed and verified)

Version:
1.0.5382.14734

MD5:
8069fa104af0b68556c70847b84ba4fc

SHA-1:
87af32d04b6f213a77394c6c5b92fe73e5c2a467

SHA-256:
9dcef8b691d304672bd2e8c7552a25a18577ad5cd6a322d5c80e33c7f881152b

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Yontoo distributed ad-supported web browser add-on for Internet Explorer.

Analysis date:
5/4/2024 5:36:28 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Yontoo.crimsolite (M)
16.2.3.15

File size:
533.3 KB (546,080 bytes)

Product version:
1.0.5382.14734

Original file name:
crimsolite.IEUpdate.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\Program Files\crimsolite\bin\plugins\crimsolite.ieupdate.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/26/2013 10:00:00 PM

Valid to:
11/27/2014 9:59:59 PM

Subject:
CN=crimsolite, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=crimsolite, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
02CCA1F2B8F504106134601E82CFA150

File PE Metadata
Compilation timestamp:
9/26/2014 6:11:15 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:tYzWiZ4vaDnkzkGj9tabFD6xEsLPkcPPd5MzSIPG9DV:t9i+vaozfjXabuPH3d5M+IPm

Entry address:
0x8527A

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
525 KB (537,600 bytes)

Remove crimsolite.IEUpdate.dll - Powered by Reason Core Security