iwebar-buttonutil.dll

Gogo Network Club

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The module iwebar-buttonutil.dll by Gogo Network Club has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The ButtonUtil module (32-bit version) uses the Crossrider web extension monetization toolkit and will perform a number of helper integration activities on the user's web browser's as well as the Window's Shell in order to install the addon. It is part of the Brightcircle group of web-extensions that inject advertisements in the browser.
Publisher:
Gogo Network Club  (signed and verified)

MD5:
61eb18f4a2ec2db5f35eb758de6dfa80

SHA-1:
3b3be0c36ed7a64e9ac04dbc4afb7db8781bf961

SHA-256:
3ba813658d57e85cff96bfe5ef638f85015482d4de5a3a3e41e48433d0c772db

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Crossrider toolbar platform.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is Gogo Network Club.

Analysis date:
6/2/2020 3:23:32 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Crossrider (M)
17.2.23.12

File size:
394.4 KB (403,872 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\iwebar\iwebar-buttonutil.dll

Digital Signature
Authority:
COMODO CA Limited

Valid from:
8/19/2014 7:00:00 AM

Valid to:
8/20/2015 6:59:59 AM

Subject:
CN=Gogo Network Club, O=Gogo Network Club, STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Nicosia, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
75BF783471861CAD78DE03A20768BF56

File PE Metadata
Compilation timestamp:
11/17/2014 3:35:23 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

Entry address:
0x28A73

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, A1, 97, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, 70, E8, 04, 10, E8, 1E, 36, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, 28, 61, 05, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, D0, 7B, 04, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Entropy:
6.3387

Developed / compiled with:
Microsoft Visual C++

Code size:
264 KB (270,336 bytes)

Remove iwebar-buttonutil.dll - Powered by Reason Core Security