thehdvid-codec v10-buttonutil.dll

Pess Kess Games

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The module thehdvid-codec v10-buttonutil.dll by Pess Kess Games has been detected as adware by 7 anti-malware scanners. The ButtonUtil module (32-bit version) uses the Crossrider web extension monetization toolkit and will perform a number of helper integration activities on the user's web browser's as well as the Window's Shell in order to install the addon. It is distributed as part of the Brightcircle group of browser-extensions.
Publisher:
Pess Kess Games  (signed and verified)

MD5:
d2d11f53b999b752da9115919183b22b

SHA-1:
bc5c1b77a2513949bcd16432221cff2f8ffcea49

SHA-256:
1aa24d6d4388356909a978ee94495c1d1a3e516ab99e23a6726340f0afccdb44

Scanner detections:
7 / 68

Status:
Adware

Explanation:
Part of the Crossrider toolbar platform. Distributed through the Brightcircle investments brand.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is Pess Kess Games.

Analysis date:
4/24/2024 7:54:41 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.CrossRider
2014.10.24

AVG
Generic
2015.0.3312

Dr.Web
DLOADER.Trojan
9.0.1.0297

ESET NOD32
Win32/Toolbar.CrossRider.BD (variant)
8.10613

IKARUS anti.virus
AdWare.CrossRider
t3scan.1.7.8.0

Reason Heuristics
PUP.Crossrider.PessKessGames.DD
14.10.24.6

Rising Antivirus
PE:Malware.Obscure!1.9C59
23.00.65.141022

File size:
406.9 KB (416,664 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\thehdvid-codec v10\thehdvid-codec v10-buttonutil.dll

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
8/27/2014 7:00:00 PM

Valid to:
8/28/2015 6:59:59 PM

Subject:
CN=Pess Kess Games, O=Pess Kess Games, STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Cyprus, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00985357810266ED5784B0A15904D65082

File PE Metadata
Compilation timestamp:
10/22/2014 2:40:10 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:wdBRPGMXI9NzDP7mUsL8toRPTBU13xQHhPn+poaOVq:wd/xIH71sLhRPT4xQBvlaOVq

Entry address:
0x295E3

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 01, 9A, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, 70, 1B, 05, 10, E8, 0E, 36, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, 28, 91, 05, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, F0, AE, 04, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Entropy:
6.3553

Developed / compiled with:
Microsoft Visual C++

Code size:
274.5 KB (281,088 bytes)

Remove thehdvid-codec v10-buttonutil.dll - Powered by Reason Core Security