Newtonsoft.Json.dll

Json.NET

Robokid Technologies

By using the Crossrider framework, this web extension is loaded in the web browser and displays advertisments on web pages not affiliated by the extension or company. These unwanted advertisements are injected by the extension in the browser in the form of common ad types such as banners and text-links. Newtonsoft.Json.dll is the assembly provides support for JSON parsing for .NET applications and is recompiled by Robokid Technologies. The module Newtonsoft.Json.dll, “Json.NET .NET 2.0” by Robokid Technologies has been detected as adware by 5 anti-malware scanners. The library is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. Although a detection has been made for this resource, it is generally a commonly distributed 3rd-party library and is typically safe by itself. It is part of the Brightcircle group of web-extensions that inject advertisements in the browser.
Publisher:
Newtonsoft  (signed by Robokid Technologies)

Product:
Json.NET

Description:
Json.NET .NET 2.0

Version:
6.0.3.17227

MD5:
9e0dbdf299c9bb62400bda717f718470

SHA-1:
4f866b5e5acf1a4960ae864393f04ff83aae7b84

SHA-256:
f5e6b3dfed6d0fc2f27c8cb8e19ac7a277f75d976d0972cf578ba99e84ef5693

Scanner detections:
5 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
4/25/2024 11:04:57 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Dr.Web
Trojan.Crossrider1.32446
9.0.1.05190

Kaspersky
not-a-virus:WebToolbar.Win32.CroRi
15.0.0.562

Reason Heuristics
Common.PUP.RobokidTechnologies.O
14.7.24.1

Sophos
PUA 'AppRider' (of type Adware)
5.21

VIPRE Antivirus
Threat.4150696
45588

File size:
481.5 KB (493,080 bytes)

Product version:
6.0.3.17227

Copyright:
Copyright © James Newton-King 2008

Original file name:
Newtonsoft.Json.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\Program Files\hd-quality-v2\newtonsoft.json.dll

Digital Signature
Authority:
COMODO CA Limited

Valid from:
6/22/2014 8:00:00 PM

Valid to:
6/23/2015 7:59:59 PM

Subject:
CN=Robokid Technologies, O=Robokid Technologies, STREET=Athinodorou 3 Dasoupoli Strovolos, L=Nicosia, S=Cyprus, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00ECF35E880AD0F3BC6F82DFB1F2E84CC0

File PE Metadata
Compilation timestamp:
4/26/2014 11:12:58 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:z14RIXwj5Ga4BztxXRKSPJtvKlJ3EQo5WyscPcDv:zK4JzlvEEQo5WyscPs

Entry address:
0x7930E

Entry point:
FF, 25, 00, 20, 00, 10, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.8656

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
477 KB (488,448 bytes)

Remove Newtonsoft.Json.dll - Powered by Reason Core Security