flv player addon-buttonutil.dll

Morgan Enter Mode

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The module flv player addon-buttonutil.dll by Morgan Enter Mode has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The ButtonUtil module (32-bit version) uses the Crossrider web extension monetization toolkit and will perform a number of helper integration activities on the user's web browser's as well as the Window's Shell in order to install the addon. It is distributed as part of the Brightcircle group of browser-extensions.
Publisher:
Morgan Enter Mode  (signed and verified)

MD5:
97f6aaa31c26e21d3494adaca75d61ab

SHA-1:
8007b77a0e3e7af6609e5c7be0bab721f92d8fd3

SHA-256:
af1e4922d63bec4c058e5b565454c91bef4954f04fde11f38bb5208fc7727ea5

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Crossrider toolbar platform. Distributed through the Brightcircle investments brand.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is Morgan Enter Mode.

Analysis date:
7/2/2020 4:40:10 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Crossrider (M)
17.3.15.8

File size:
381.9 KB (391,072 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\flv player addon\flv player addon-buttonutil.dll

Digital Signature
Authority:
COMODO CA Limited

Valid from:
8/27/2014 5:00:00 PM

Valid to:
8/28/2015 4:59:59 PM

Subject:
CN=Morgan Enter Mode, O=Morgan Enter Mode, STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Cyprus, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00E247EA066029B70533C15792B60ED4D8

File PE Metadata
Compilation timestamp:
10/15/2014 12:35:10 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

Entry address:
0x26D93

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 01, 9A, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, D8, C5, 04, 10, E8, 0E, 36, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, 28, 41, 05, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, D0, 59, 04, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Entropy:
6.3221

Developed / compiled with:
Microsoft Visual C++

Code size:
253.5 KB (259,584 bytes)

Remove flv player addon-buttonutil.dll - Powered by Reason Core Security