internet speed checker-buttonutil64.dll

Porter Studio Plus

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The module internet speed checker-buttonutil64.dll by Porter Studio Plus has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program Internet Speed Checker by Sailor Project which is a potentially unwanted software program. The ButtonUtil module (64-bit version) uses the Crossrider web extension platform and will perform a number of helper integration on the user's web browser's as well as the Window's Shell in order to install the addon. It is part of the Brightcircle group of web-extensions that inject advertisements in the browser.
Publisher:
Porter Studio Plus  (signed and verified)

MD5:
4502d7f84c65ec7c77550de56ba719f8

SHA-1:
22e6bbdb30ea408f4da15a671fa8bf257dc92264

SHA-256:
a7223fb6d9b0d4593ec8bc2239c76e8a6b342d6ad8ec7a07b64f6079fbf10743

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Crossrider toolbar platform.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is Porter Studio Plus.

Analysis date:
4/19/2024 1:38:09 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Crossrider.PorterStudioPlus.d
14.11.3.21

File size:
428.9 KB (439,200 bytes)

File type:
Dynamic link library (Win64 DLL)

Common path:
C:\Program Files\internet speed checker\internet speed checker-buttonutil64.dll

Digital Signature
Authority:
COMODO CA Limited

Valid from:
10/20/2014 2:00:00 AM

Valid to:
10/21/2015 1:59:59 AM

Subject:
CN=Porter Studio Plus, O=Porter Studio Plus, STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Cyprus, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00B7BA41CFBA8D50AF9A2A64362C08FA91

File PE Metadata
Compilation timestamp:
10/30/2014 9:36:16 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:Vwx1rd7/g9B1rlt+h9LpzoYSa7l6L5jKUs39fYEITGUVT23SkGTBaPY/3AZf2ie5:2B+AVG6UcpGToPYOxxK

Entry address:
0x2BADC

Entry point:
48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 57, 48, 83, EC, 20, 49, 8B, F8, 8B, DA, 48, 8B, F1, 83, FA, 01, 75, 05, E8, 7F, A7, 00, 00, 4C, 8B, C7, 8B, D3, 48, 8B, CE, 48, 8B, 5C, 24, 30, 48, 8B, 74, 24, 38, 48, 83, C4, 20, 5F, E9, 03, 00, 00, 00, CC, CC, CC, 48, 8B, C4, 48, 89, 58, 20, 4C, 89, 40, 18, 89, 50, 10, 48, 89, 48, 08, 56, 57, 41, 56, 48, 83, EC, 50, 49, 8B, F0, 8B, DA, 4C, 8B, F1, BA, 01, 00, 00, 00, 89, 50, B8, 85, DB, 75, 0F, 39, 1D, 90, 92, 03, 00, 75, 07, 33, C0, E9, D2, 00, 00, 00, 8D, 43, FF...
 
[+]

Code size:
279.5 KB (286,208 bytes)

The file internet speed checker-buttonutil64.dll has been discovered within the following program.

Internet Speed Checker  by Sailor Project
Internet Speed Checker is an adware web browser application that displays banner ads as well as contextual link ads that are injected in the web page.
62% remove it
 
Powered by Should I Remove It?

Remove internet speed checker-buttonutil64.dll - Powered by Reason Core Security