solid savings plugin-helper.exe

Fun Apps

This is part of a distribution package that is classified as adware distributed by 50onRed. This adware is used to interact with the installed web browsers and inject ads and modify the default search and homepages. The application solid savings plugin-helper.exe by Fun Apps has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program Solid Savings Plugin by 215 Apps which is a potentially unwanted software program. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
Fun Apps  (signed and verified)

MD5:
0eeeac56a07a56b13e6571e7f7a5621b

SHA-1:
ce13b1a9f5b64bbafb0ae34c77f627ef3ef1531f

SHA-256:
a0d6b063640e4ef5d75c83501e39ee9b215c52309ed9de38d29c2488959ac884

Scanner detections:
1 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
4/26/2024 8:51:58 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Crossrider.50OnRed (M)
16.1.2.8

File size:
307.9 KB (315,256 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\solid savings plugin\solid savings plugin-helper.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
6/3/2013 8:00:00 PM

Valid to:
6/4/2014 7:59:59 PM

Subject:
CN=Fun Apps, O=Fun Apps, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
684B8CFA6A114F5EE6A8115E415BF20A

File PE Metadata
Compilation timestamp:
8/12/2013 5:45:17 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:r9YRrQzVNiNFuZz0Z4iGKSeGepoxfp2EqTB654Rzt:yRrQBNiveyCFEpoxfp2EqT45M

Entry address:
0x25E38

Entry point:
E8, 71, 9A, 00, 00, E9, 89, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 57, 56, 53, 33, FF, 8B, 44, 24, 14, 0B, C0, 7D, 14, 47, 8B, 54, 24, 10, F7, D8, F7, DA, 83, D8, 00, 89, 44, 24, 14, 89, 54, 24, 10, 8B, 44, 24, 1C, 0B, C0, 7D, 14, 47, 8B, 54, 24, 18, F7, D8, F7, DA, 83, D8, 00, 89, 44, 24, 1C, 89, 54, 24, 18, 0B, C0, 75, 18, 8B, 4C, 24, 18, 8B, 44, 24, 14, 33, D2, F7, F1, 8B, D8, 8B, 44, 24, 10, F7, F1, 8B, D3, EB, 41, 8B, D8, 8B, 4C, 24, 18, 8B, 54, 24, 14, 8B, 44, 24, 10, D1...
 
[+]

Entropy:
6.5479

Code size:
233.5 KB (239,104 bytes)

The file solid savings plugin-helper.exe has been discovered within the following program.

Solid Savings Plugin  by 215 Apps
Solid Savings Plugin is an adware web browser extension designed to take control of the user's browser in order to redirect web searches and inject advertising. In Internet Explorer the program run as a Browser Helper Object.
www.50onred.com
79% remove it
 
Powered by Should I Remove It?

Remove solid savings plugin-helper.exe - Powered by Reason Core Security