radio canyon-buttonutil.dll

Morgan Enter Mode

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The module radio canyon-buttonutil.dll by Morgan Enter Mode has been detected as adware by 8 anti-malware scanners. The ButtonUtil module (32-bit version) uses the Crossrider web extension monetization toolkit and will perform a number of helper integration activities on the user's web browser's as well as the Window's Shell in order to install the addon. It is part of the Brightcircle group of web-extensions that inject advertisements in the browser.
Publisher:
Morgan Enter Mode  (signed and verified)

MD5:
1faee8bd00dfe6c4f640efab77cecf1b

SHA-1:
0e85df737b74a86855c5a85dec4cd0ceae0f6757

SHA-256:
8cc2ab5e7b883a07e9915b73c0946d637bf2ad3e905b75b88e53d630870c6236

Scanner detections:
8 / 68

Status:
Adware

Explanation:
Part of the Crossrider toolbar platform.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is Morgan Enter Mode.

Analysis date:
4/25/2024 8:17:34 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.CrossRider
2014.10.22

AVG
Morgan
2015.0.3313

Baidu Antivirus
Adware.NSIS.Adwapper
4.0.3.141022

Dr.Web
DLOADER.Trojan
9.0.1.0295

Fortinet FortiGate
Adware/Adwapper
10/22/2014

IKARUS anti.virus
AdWare.CrossRider
t3scan.1.7.8.0

Reason Heuristics
PUP.Crossrider.MorganEnterMode.X
14.10.22.15

Rising Antivirus
PE:Malware.Obscure!1.9C59
23.00.65.141020

File size:
374.9 KB (383,904 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\radio canyon\radio canyon-buttonutil.dll

Digital Signature
Authority:
COMODO CA Limited

Valid from:
8/28/2014 1:00:00 AM

Valid to:
8/29/2015 12:59:59 AM

Subject:
CN=Morgan Enter Mode, O=Morgan Enter Mode, STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Cyprus, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00E247EA066029B70533C15792B60ED4D8

File PE Metadata
Compilation timestamp:
10/16/2014 8:34:33 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:sA+pMXnrDd+3kul6mI4GZvfEIp2TBoY0hgySaIM85:shpMn/dQ98dfdp2TKYa/SaIMg

Entry address:
0x262C3

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 01, 9A, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, 68, A4, 04, 10, E8, 0E, 36, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, 28, 21, 05, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, 60, 38, 04, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Entropy:
6.3146

Developed / compiled with:
Microsoft Visual C++

Code size:
247.5 KB (253,440 bytes)

Remove radio canyon-buttonutil.dll - Powered by Reason Core Security