solid savings plugin-buttonutil64.dll

Fun Apps

This file is a support library for an advertising-based software package (potentially unwanted/adware) distributed by 50onRed used to hijack the Internet browser search provider. The module solid savings plugin-buttonutil64.dll by Fun Apps has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program Solid Savings Plugin by 215 Apps which is a potentially unwanted software program. The ButtonUtil module (64-bit version) uses the Crossrider web extension platform and will perform a number of helper integration on the user's web browser's as well as the Window's Shell in order to install the addon.
Publisher:
Fun Apps  (signed and verified)

MD5:
1933749fb1e40192cb0d14acec104d5d

SHA-1:
30d5f96707da19968343bca498d185c44389b730

SHA-256:
1eda2ed27c1460cc8658bf52bf53238a578d1efbc903034dc3b2717f5f55851e

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Crossrider toolbar platform.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is Fun Apps.

Analysis date:
4/26/2024 12:08:44 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Crossrider.50OnRed (M)
16.1.2.8

File size:
479.4 KB (490,872 bytes)

File type:
Dynamic link library (Win64 DLL)

Common path:
C:\Program Files\solid savings plugin\solid savings plugin-buttonutil64.dll

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
6/3/2013 8:00:00 PM

Valid to:
6/4/2014 7:59:59 PM

Subject:
CN=Fun Apps, O=Fun Apps, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
684B8CFA6A114F5EE6A8115E415BF20A

File PE Metadata
Compilation timestamp:
8/12/2013 5:46:43 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:Y70N3RKk1Sv/x4HODdgUiGnK8NVilWgXyK6gT+nChYOdmX4at6eTBXtnr504+t+W:73RKk1IJ4aMcoWguxnoeTV84+tUW9Si

Entry address:
0x39830

Entry point:
48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 57, 48, 83, EC, 20, 49, 8B, F8, 8B, DA, 48, 8B, F1, 83, FA, 01, 75, 05, E8, 7B, AB, 00, 00, 4C, 8B, C7, 8B, D3, 48, 8B, CE, 48, 8B, 5C, 24, 30, 48, 8B, 74, 24, 38, 48, 83, C4, 20, 5F, E9, A7, FE, FF, FF, CC, CC, CC, 48, 8B, C4, 48, 89, 58, 08, 48, 89, 68, 10, 48, 89, 70, 18, 48, 89, 78, 20, 41, 54, 48, 83, EC, 20, 4D, 8B, 51, 38, 48, 8B, F2, 4D, 8B, E0, 41, 8B, 02, 48, 8B, E9, 49, 8B, D1, 48, 03, C0, 48, 8B, CE, 49, 8B, F9, 49, 8D, 5C, C2, 04, 4C, 8B, C3, E8, 36, 39...
 
[+]

Entropy:
6.3249

Code size:
337.5 KB (345,600 bytes)

The file solid savings plugin-buttonutil64.dll has been discovered within the following program.

Solid Savings Plugin  by 215 Apps
Solid Savings Plugin is an adware web browser extension designed to take control of the user's browser in order to redirect web searches and inject advertising. In Internet Explorer the program run as a Browser Helper Object.
www.50onred.com
79% remove it
 
Powered by Should I Remove It?

Remove solid savings plugin-buttonutil64.dll - Powered by Reason Core Security