thehdvid-codec v10-buttonutil.dll

Pess Kess Games

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The module thehdvid-codec v10-buttonutil.dll by Pess Kess Games has been detected as adware by 23 anti-malware scanners. This file is typically installed with the program TheHDvid-Codec V10 by Joseph CM which is a potentially unwanted software program. The ButtonUtil module (32-bit version) uses the Crossrider web extension monetization toolkit and will perform a number of helper integration activities on the user's web browser's as well as the Window's Shell in order to install the addon. It is distributed as part of the Brightcircle group of browser-extensions.
Publisher:
Pess Kess Games  (signed and verified)

MD5:
84d80685926f82e87fb0fd5ffd3e67d5

SHA-1:
88dfd488fc7b93350d9854a61c36b3fb970201db

SHA-256:
ea8a7af2492459039153dac7a76f15ea383b51a59f4b0f433700f34ba10e29f4

Scanner detections:
23 / 68

Status:
Adware

Explanation:
Part of the Crossrider toolbar platform. Distributed through the Brightcircle investments brand.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is Pess Kess Games.

Analysis date:
4/27/2024 1:03:31 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Application.Heur.Ay5@kSe0WWji
6213306

AhnLab V3 Security
PUP/Win32.CrossRider
2014.12.22

Avira AntiVirus
ADWARE/CrossRider.Gen
7.11.197.30

AVG
Generic
2015.0.3253

Bitdefender
Gen:Application.Heur.Ay5@kSe0WWji
1.0.20.1780

Clam AntiVirus
Win.Trojan.Crossrider-128
0.98/21511

Dr.Web
DLOADER.Trojan
9.0.1.0356

Emsisoft Anti-Malware
Gen:Application.Heur.Ay5@kSe0WWji
9.0.0.4668

ESET NOD32
Win32/Toolbar.CrossRider.BD potentially unwanted application
7.0.302.0

F-Prot
W32/S-89e9aa96
v6.4.7.1.166

F-Secure
Riskware.Gen:Application.Heur.Ay5@kSe0WWji
5.13.68

G Data
Gen:Application.Heur.Ay5@kSe0WWji
14.12.24

K7 AntiVirus
Unwanted-Program
13.188.14410

Kaspersky
Trojan.NSIS.GoogUpdate
15.0.0.543

MicroWorld eScan
Gen:Application.Heur.Ay5@kSe0WWji
15.0.0.1068

NANO AntiVirus
Trojan.Win32.CrossRider.didend
0.28.6.64267

Norman
Gen:Application.Heur.Ay5@kSe0WWji
04.12.2014 14:30:06

Panda Antivirus
Trj/Genetic.gen
14.12.22.06

Reason Heuristics
PUP.Crossrider.PessKessGames.DD
14.12.22.6

Rising Antivirus
PE:Malware.Obscure!1.9C59
23.00.65.141220

Sophos
PUA 'AppRider' (of type Adware)
5.09

VIPRE Antivirus
Threat.4150696
35418

Zillya! Antivirus
Adware.CrossRider.Win32.413
2.0.0.2012

File size:
426.4 KB (436,632 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\thehdvid-codec v10\thehdvid-codec v10-buttonutil.dll

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
8/28/2014 3:00:00 AM

Valid to:
8/29/2015 2:59:59 AM

Subject:
CN=Pess Kess Games, O=Pess Kess Games, STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Cyprus, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00985357810266ED5784B0A15904D65082

File PE Metadata
Compilation timestamp:
10/31/2014 11:40:35 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:cZgwEtg8rZh1U84MJmGHmIK/qTBjH2hAzSaIFIN:cOwEtjd5UGm1qTNHgESaIFIN

Entry address:
0x2B0B3

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 01, 9A, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, 18, 60, 05, 10, E8, 0E, 36, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, 28, E1, 05, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, C0, F3, 04, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Entropy:
6.3653

Developed / compiled with:
Microsoft Visual C++

Code size:
291 KB (297,984 bytes)

The file thehdvid-codec v10-buttonutil.dll has been discovered within the following program.

TheHDvid-Codec V10  by Joseph CM
TheHDvid-Codec is an advertising supported (adware) extension that runs in the context of the user's web browser as well as a process in the background.
crossrider.com/install/61180-thehdvid-codec-v10
83% remove it
 
Powered by Should I Remove It?

Remove thehdvid-codec v10-buttonutil.dll - Powered by Reason Core Security