buttonutil64.dll

Evidon, Inc.

This file is installed with the program Ghostery IE.
Publisher:
Evidon, Inc.  (signed and verified)

MD5:
69cba0d063fcb2861f8a723fb160d1cf

SHA-1:
11fa5b7287a5a42db9278a628463dc6b76544c9e

SHA-256:
b148d581227d6c137f178e0ac352ec8afdb9347476828f98986ad9d66b894b92

Scanner detections:
6 / 68

Status:
Clean  (6 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

False Positives:
A number of engines detected this file but were erroneous detections (false positives).

Analysis date:
11/27/2024 9:33:50 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Installer-M [Adw]
2014.9-140930

ESET NOD32
Win64/Toolbar.Crossrider.A potentially unwanted application
8.7.0.302.0

IKARUS anti.virus
PUA.Toolbar.CrossRider
t3scan.1.7.5.0

Reason Heuristics
Threat.Win.Reputation.IMP
14.9.30.16

Sophos
AppRider
4.98

VIPRE Antivirus
Threat.4736651
32210

File size:
449.6 KB (460,392 bytes)

File type:
Dynamic link library (Win64 DLL)

Common path:
C:\Program Files\ghostery ie\buttonutil64.dll

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
3/14/2011 12:00:00 AM

Valid to:
3/13/2014 11:59:59 PM

Subject:
CN="Evidon, Inc.", O="Evidon, Inc.", STREET=28 W. 44th St., STREET=Ste. 800, L=New York, S=NY, PostalCode=10036, C=US

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00A360D17B416CE4A553A541F18C27640A

File PE Metadata
Compilation timestamp:
3/21/2013 8:56:52 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:qYtNTpIbazIcaaeRw7mqKY2LIksopFcvqTJHc5PgLVzRKRD9TBIHJnr5C49C53Jk:XNd92a5cfLigPVcRD9T6HG49CrFi

Entry address:
0x350B8

Entry point:
48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 57, 48, 83, EC, 20, 49, 8B, F8, 8B, DA, 48, 8B, F1, 83, FA, 01, 75, 05, E8, CF, 9F, 00, 00, 4C, 8B, C7, 8B, D3, 48, 8B, CE, 48, 8B, 5C, 24, 30, 48, 8B, 74, 24, 38, 48, 83, C4, 20, 5F, E9, A7, FE, FF, FF, CC, CC, CC, 48, 8B, C4, 48, 89, 58, 08, 48, 89, 68, 10, 48, 89, 70, 18, 48, 89, 78, 20, 41, 54, 48, 83, EC, 20, 4D, 8B, 51, 38, 48, 8B, F2, 4D, 8B, E0, 41, 8B, 02, 48, 8B, E9, 49, 8B, D1, 48, 03, C0, 48, 8B, CE, 49, 8B, F9, 49, 8D, 5C, C2, 04, 4C, 8B, C3, E8, AE, 38...
 
[+]

Entropy:
6.2938

Code size:
311.5 KB (318,976 bytes)

The file buttonutil64.dll has been discovered within the following program.

Ghostery IE  by Evidon Inc.
Publisher's description - “Ghostery™ sees the invisible web - tags, web bugs, pixels and beacons. Ghostery tracks the trackers and gives you a roll-call of the ad networks, behavioral data providers, web publishers, and other companies interested in your activity.”
www.ghostery.com
11% remove it
 
Powered by Should I Remove It?