feven 1.1-buttonutil.dll

Brightcircle Investments Limited

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The module feven 1.1-buttonutil.dll by Brightcircle Investments Limited has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The ButtonUtil module (32-bit version) uses the Crossrider web extension monetization toolkit and will perform a number of helper integration activities on the user's web browser's as well as the Window's Shell in order to install the addon. It is distributed as part of the Brightcircle group of browser-extensions.
Publisher:
Brightcircle Investments Limited  (signed and verified)

MD5:
6e6bd980d31c7dd829707c605937cc37

SHA-1:
3013d0d2ecea31a9e3062da8acef4693cbfb6e65

SHA-256:
b238e9936072aded0c6ec7e3345c0b26e47520672cdf41bd4e9039faee4c27e1

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Crossrider toolbar platform. Distributed through the Brightcircle investments brand.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is Brightcircle Investments Limited.

Analysis date:
4/19/2024 11:08:07 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Crossrider.Brightcircle (M)
16.2.9.4

File size:
422.9 KB (433,000 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\feven 1.1\feven 1.1-buttonutil.dll

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
3/8/2013 10:33:54 AM

Valid to:
3/8/2016 10:33:54 AM

Subject:
CN=Brightcircle Investments Limited, O=Brightcircle Investments Limited, L=Nicosia, S=Strovolos, C=CY

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
047F36483DC84C

File PE Metadata
Compilation timestamp:
12/4/2013 9:25:14 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:/KREdskryJQ0cKI7dWBYtzPq5WBeTGi0Ab4rjXA/S6:3YQ0cKDl8ETGvAb4Y/S6

Entry address:
0x31798

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 9C, 95, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, F0, 3E, 05, 10, E8, 59, 40, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, 98, D1, 05, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, 70, C1, 04, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
283 KB (289,792 bytes)

Remove feven 1.1-buttonutil.dll - Powered by Reason Core Security