solid savings plugin-buttonutil.dll

Fun Apps

This file is a support library for an advertising-based software package (potentially unwanted/adware) distributed by 50onRed used to hijack the Internet browser search provider. The module solid savings plugin-buttonutil.dll by Fun Apps has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program Solid Savings Plugin by 215 Apps which is a potentially unwanted software program. The ButtonUtil module (32-bit version) uses the Crossrider web extension monetization toolkit and will perform a number of helper integration activities on the user's web browser's as well as the Window's Shell in order to install the addon.
Publisher:
Fun Apps  (signed and verified)

MD5:
a1aec95c71ff8ab8188dea9ec132622c

SHA-1:
ef57a06434af44e9c9c503ecae8cb391242a9f69

SHA-256:
ad9974033fe6bf6d5ebd56ea94b6851371256ec746cbd0958f0fafb149fc99c8

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Crossrider toolbar platform.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is Fun Apps.

Analysis date:
4/26/2024 7:20:02 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Crossrider.50OnRed (M)
16.1.2.8

File size:
395.4 KB (404,856 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\solid savings plugin\solid savings plugin-buttonutil.dll

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
6/3/2013 8:00:00 PM

Valid to:
6/4/2014 7:59:59 PM

Subject:
CN=Fun Apps, O=Fun Apps, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
684B8CFA6A114F5EE6A8115E415BF20A

File PE Metadata
Compilation timestamp:
8/12/2013 5:44:30 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:w5kFD6YnTrIQkK+5g8aWuvyLOFjeCTrW4u7h+/ne1/8:t6YnFsgg32jlTrW40c/e1/8

Entry address:
0x30AEB

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, AE, 9D, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, CC, CC, 55, 8B, EC, 57, 56, 8B, 75, 0C, 8B, 4D, 10, 8B, 7D, 08, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, A0, 01, 00, 00, 81, F9, 80, 00, 00, 00, 72, 1C, 83, 3D, A0, D1, 05, 10, 00, 74, 13, 57, 56, 83, E7, 0F, 83, E6, 0F, 3B, FE, 5E, 5F, 75, 05, E9, 85, 73, 00, 00, F7, C7, 03, 00, 00, 00, 75, 14, C1, E9, 02, 83, E2, 03, 83, F9, 08, 72, 29, F3, A5, FF, 24...
 
[+]

Entropy:
6.6999

Code size:
292 KB (299,008 bytes)

The file solid savings plugin-buttonutil.dll has been discovered within the following program.

Solid Savings Plugin  by 215 Apps
Solid Savings Plugin is an adware web browser extension designed to take control of the user's browser in order to redirect web searches and inject advertising. In Internet Explorer the program run as a Browser Helper Object.
www.50onred.com
79% remove it
 
Powered by Should I Remove It?

Remove solid savings plugin-buttonutil.dll - Powered by Reason Core Security