savebarieextension.dll

REDDOOR MEDIA GROUP CO., LTD.

The module savebarieextension.dll by REDDOOR MEDIA GROUP CO. has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘SaveBar省省吧’. This file is typically installed with the program RedDoor SaveBar by RedDoor.
Publisher:
REDDOOR MEDIA GROUP CO., LTD.  (signed and verified)

MD5:
d18390a2cb5af3a4eaf632f1feed80b6

SHA-1:
530c41a1dd32a5fdc5c828123f0d6d37418a9d2b

SHA-256:
2367dbd73949dcf4c150368c2fdcdc7311a375021a93c1e5566f6960c37e0f04

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/26/2024 9:21:57 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.REDDOORMEDIAGROUPCO
15.4.24.0

File size:
733.6 KB (751,192 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\reddoor\savebar\savebarieextension.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/7/2012 8:00:00 AM

Valid to:
2/7/2013 7:59:59 AM

Subject:
CN="REDDOOR MEDIA GROUP CO., LTD.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="REDDOOR MEDIA GROUP CO., LTD.", L=Taipei City, S=Taiwan, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
72E5FBF1118CBD525968171DFFEE8C2A

File PE Metadata
Compilation timestamp:
3/13/2012 2:41:15 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:dVIqI0yqZNdToC60q5a62/7ukYucme9hmkVvvLzI15HcUwmOX+21M0Fn6QYFEe:dWcZNdT8gJdwFX+2S0Fn6QY/

Entry address:
0x46E97

Entry point:
E9, 64, FE, 07, 00, E9, DF, A7, 06, 00, E9, 42, F3, 07, 00, E9, 55, 17, 08, 00, E9, 60, 0E, 04, 00, E9, 0F, F3, 07, 00, E9, A6, 0A, 08, 00, E9, 21, 29, 06, 00, E9, 1C, C0, 05, 00, E9, C7, AB, 03, 00, E9, 02, F5, 06, 00, E9, 5D, 43, 06, 00, E9, A8, F5, 05, 00, E9, 73, 98, 04, 00, E9, DC, E8, 07, 00, E9, 69, 86, 05, 00, E9, D4, 77, 05, 00, E9, DF, FB, 05, 00, E9, 4A, 54, 03, 00, E9, D5, 5E, 04, 00, E9, 70, 97, 02, 00, E9, 5B, 0E, 06, 00, E9, C6, CB, 03, 00, E9, F1, 82, 02, 00, E9, 4C, 14, 01, 00, E9, 37, F3...
 
[+]

Entropy:
5.5764

Developed / compiled with:
Microsoft Visual C++ 8.0 (Debug)

Code size:
581.5 KB (595,456 bytes)

Internet Explorer BHO
CLSID:
{3543619C-D563-43f7-95EA-4DA7E1CC396A}


The file savebarieextension.dll has been discovered within the following program.

RedDoor SaveBar  by RedDoor
www.RedDoor.com
44% remove it
 
Powered by Should I Remove It?

Remove savebarieextension.dll - Powered by Reason Core Security