feven 1.7-buttonutil64.dll

Brightcircle Investments Limited

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The module feven 1.7-buttonutil64.dll by Brightcircle Investments Limited has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The ButtonUtil module (64-bit version) uses the Crossrider web extension platform and will perform a number of helper integration on the user's web browser's as well as the Window's Shell in order to install the addon. It is distributed as part of the Brightcircle group of browser-extensions.
Publisher:
Brightcircle Investments Limited  (signed and verified)

MD5:
aa906b167b904b2b6400c3d8f4452517

SHA-1:
d12aadef8be8222cce732a796862473d28d374b8

SHA-256:
d5d1d7c5cd5a177db97853921614e0a9d786f0c824909e8f9df6664ca93c2aa2

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Crossrider toolbar platform. Distributed through the Brightcircle investments brand.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is Brightcircle Investments Limited.

Analysis date:
4/18/2024 1:58:47 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Crossrider.Brightcircle (M)
16.2.6.13

File size:
483.9 KB (495,464 bytes)

File type:
Dynamic link library (Win64 DLL)

Common path:
C:\Program Files\feven 1.7\feven 1.7-buttonutil64.dll

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
3/8/2013 4:33:54 AM

Valid to:
3/8/2016 4:33:54 AM

Subject:
CN=Brightcircle Investments Limited, O=Brightcircle Investments Limited, L=Nicosia, S=Strovolos, C=CY

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
047F36483DC84C

File PE Metadata
Compilation timestamp:
11/19/2013 7:21:07 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:FGoPXwkPs5kVKy6O3vsPKNApsVkuheT/AazGNJz02uTBXN3nr5t4rl0BRLZ0Xl:FYkFMyj33qPuta4uTJNn4rKV6

Entry address:
0x3A414

Entry point:
48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 57, 48, 83, EC, 20, 49, 8B, F8, 8B, DA, 48, 8B, F1, 83, FA, 01, 75, 05, E8, 2B, A2, 00, 00, 4C, 8B, C7, 8B, D3, 48, 8B, CE, 48, 8B, 5C, 24, 30, 48, 8B, 74, 24, 38, 48, 83, C4, 20, 5F, E9, 03, 00, 00, 00, CC, CC, CC, 48, 8B, C4, 48, 89, 58, 20, 4C, 89, 40, 18, 89, 50, 10, 48, 89, 48, 08, 56, 57, 41, 56, 48, 83, EC, 50, 49, 8B, F0, 8B, DA, 4C, 8B, F1, BA, 01, 00, 00, 00, 89, 50, B8, 85, DB, 75, 0F, 39, 1D, B8, A9, 03, 00, 75, 07, 33, C0, E9, D2, 00, 00, 00, 8D, 43, FF...
 
[+]

Entropy:
6.2322

Code size:
324.5 KB (332,288 bytes)

Remove feven 1.7-buttonutil64.dll - Powered by Reason Core Security