SuperSocket.ClientEngine.Common.dll

SuperSocket ClientEngine

Naruto Source

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The module SuperSocket.ClientEngine.Common.dll, “SuperSocket.ClientEngine.Common for .Net 2.0” by Naruto Source has been detected as adware by 13 anti-malware scanners. This file is typically installed with the program Internet Speed Checker by Sailor Project which is a potentially unwanted software program. The library is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. It is part of the Brightcircle group of web-extensions that inject advertisements in the browser.
Publisher:
SuperSocket  (signed by Naruto Source)

Product:
SuperSocket ClientEngine

Description:
SuperSocket.ClientEngine.Common for .Net 2.0

Version:
0.3.0.0

MD5:
d62dbeb440a33671a5c26b099d973b8d

SHA-1:
24db6a3e2e67b9c477d86c31ad67b996c7ec5073

SHA-256:
7ffa46ee8030e8e4d0a6b0f90333e13d3b16a9a53876e3311ae74f53244987c1

Scanner detections:
13 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
4/18/2024 4:12:13 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
Adware/CrossRider.pq
7.11.169.108

AVG
Generic
2015.0.3364

Dr.Web
Trojan.Crossrider.28247
9.0.1.05190

IKARUS anti.virus
PUA.Plush
t3scan.1.7.5.0

Kaspersky
not-a-virus:AdWare.NSIS.Adwapper
15.0.0.463

McAfee
Artemis!D6B154D9AF5E
5600.7020

NANO AntiVirus
Trojan.Win32.GoogUpdate.deefsh
0.28.2.61861

nProtect
Trojan-Clicker/W32.Agent.23400
14.08.26.01

Panda Antivirus
Trj/Chgt.D
14.09.01.10

Qihoo 360 Security
Win32/Virus.Adware.970
1.0.0.1015

Reason Heuristics
PUP.NarutoSource.DD
14.9.1.22

Sophos
Generic PUA FO
4.98

Vba32 AntiVirus
Trojan.GoogUpdate
3.12.26.3

File size:
22.9 KB (23,400 bytes)

Product version:
0.3.0.0

Copyright:
Copyright © clientengine.codeplex.com 2012

Original file name:
SuperSocket.ClientEngine.Common.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\Program Files\internet speed checker\supersocket.clientengine.common.dll

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/27/2014 8:00:00 PM

Valid to:
7/28/2015 7:59:59 PM

Subject:
CN=Naruto Source, O=Naruto Source, STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Cyprus, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
1CE82906A7F364268F66771839675655

File PE Metadata
Compilation timestamp:
4/11/2014 10:22:22 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
384:D64b8rYkcUTMdzJzga3Vmt1xf3Qa/qOle+1aRu7/2hjwO05Ll8Nw:N8iUTMdzJkEMnlQa/q+YR5jwODNw

Entry address:
0x5FBE

Entry point:
FF, 25, 00, 20, 00, 10, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 10, 00, 00, 00, 18, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 01, 00, 00, 00, 30, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.8720

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
16 KB (16,384 bytes)

The file SuperSocket.ClientEngine.Common.dll has been discovered within the following program.

Internet Speed Checker  by Sailor Project
Internet Speed Checker is an adware web browser application that displays banner ads as well as contextual link ads that are injected in the web page.
62% remove it
 
Powered by Should I Remove It?

Remove SuperSocket.ClientEngine.Common.dll - Powered by Reason Core Security