solid savings plugin-helper.exe

Fun Apps

This is part of a distribution package that is classified as adware distributed by 50onRed. This adware is used to interact with the installed web browsers and inject ads and modify the default search and homepages. The application solid savings plugin-helper.exe by Fun Apps has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program Solid Savings Plugin by 215 Apps which is a potentially unwanted software program. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
Fun Apps  (signed and verified)

MD5:
ecb879fcd836ed87e32e2d95a0a550b4

SHA-1:
d9bd330ca56ea0e731eaff96b33ae2619f873fce

Scanner detections:
1 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
4/18/2024 12:58:02 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Crossrider.50OnRed (M)
15.12.22.14

File size:
307.9 KB (315,256 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\solid savings plugin\solid savings plugin-helper.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
6/3/2013 8:00:00 PM

Valid to:
6/4/2014 7:59:59 PM

Subject:
CN=Fun Apps, O=Fun Apps, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
684B8CFA6A114F5EE6A8115E415BF20A

File PE Metadata
Compilation timestamp:
8/12/2013 5:45:17 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:s9YRrQzVNiNFuZz0Z4iGKSeGepoxfp2EqTB654RzU:xRrQBNiveyCFEpoxfp2EqT45F

Entry address:
0x25E38

Entry point:
E8, 71, 9A, 00, 00, E9, 89, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 57, 56, 53, 33, FF, 8B, 44, 24, 14, 0B, C0, 7D, 14, 47, 8B, 54, 24, 10, F7, D8, F7, DA, 83, D8, 00, 89, 44, 24, 14, 89, 54, 24, 10, 8B, 44, 24, 1C, 0B, C0, 7D, 14, 47, 8B, 54, 24, 18, F7, D8, F7, DA, 83, D8, 00, 89, 44, 24, 1C, 89, 54, 24, 18, 0B, C0, 75, 18, 8B, 4C, 24, 18, 8B, 44, 24, 14, 33, D2, F7, F1, 8B, D8, 8B, 44, 24, 10, F7, F1, 8B, D3, EB, 41, 8B, D8, 8B, 4C, 24, 18, 8B, 54, 24, 14, 8B, 44, 24, 10, D1...
 
[+]

Entropy:
6.5479

Code size:
233.5 KB (239,104 bytes)

The file solid savings plugin-helper.exe has been discovered within the following program.

Solid Savings Plugin  by 215 Apps
Solid Savings Plugin is an adware web browser extension designed to take control of the user's browser in order to redirect web searches and inject advertising. In Internet Explorer the program run as a Browser Helper Object.
www.50onred.com
79% remove it
 
Powered by Should I Remove It?

Remove solid savings plugin-helper.exe - Powered by Reason Core Security