common.dll

SearchDonkey

WebAppTech Coding LLC

This is part of an adware program designed to inject advertising in the web browser (banners, text-links) as well as modify the normal behavior of the browser as well as modify the computer’s system settings that control applications to run on startup. Part of the Injekt brand of unwanted programs. The module common.dll by WebAppTech Coding has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘SearchDonkey’.
Publisher:
WebAppTech Coding, LLC  (signed by WebAppTech Coding LLC)

Product:
SearchDonkey

Version:
2.6.49

MD5:
44f12c0c053d1d0c24e982062750e7d1

SHA-1:
c6c78e68988ad92df49c00aa8caf1aa88d5da69d

SHA-256:
ef286edfe8cdd2c3c80a13ebfca0c872c01fd3e9a90c882466e0d30d97e12285

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
12/25/2024 1:17:21 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Injekt (M)
17.3.2.9

File size:
400.6 KB (410,256 bytes)

Product version:
2.6.49

Copyright:
(c) WebAppTech Coding, LLC

Original file name:
common.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\ProgramData\searchdonkey\ie\common.dll

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/16/2013 12:00:00 AM

Valid to:
1/16/2014 11:59:59 PM

Subject:
CN=WebAppTech Coding LLC, O=WebAppTech Coding LLC, STREET="2885 Sanford Ave SW #18716", L=Grandville, S=MI, PostalCode=49418, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00ED976277604B937F55FA8DF427C5B534

File PE Metadata
Compilation timestamp:
11/20/2013 2:00:51 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x15A0C

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 14, 5D, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, CC, 8B, FF, 55, 8B, EC, 83, EC, 18, 53, 8B, 5D, 0C, 56, 8B, 73, 08, 33, 35, A0, 9C, 04, 10, 57, 8B, 06, C6, 45, FF, 00, C7, 45, F4, 01, 00, 00, 00, 8D, 7B, 10, 83, F8, FE, 74, 0D, 8B, 4E, 04, 03, CF, 33, 0C, 38, E8, EE, C1, FF, FF, 8B, 4E, 0C, 8B, 46, 08, 03, CF, 33, 0C, 38, E8, DE, C1, FF, FF, 8B, 45, 08, F6, 40, 04, 66, 0F, 85, 19, 01, 00, 00, 8B, 4D, 10, 8D, 55, E8...
 
[+]

Entropy:
6.4250

Code size:
232.5 KB (238,080 bytes)

Internet Explorer BHO
Display name:
SearchDonkey

CLSID:
{44ed99e2-16a6-4b89-80d6-5b21cf42e78b}


Remove common.dll - Powered by Reason Core Security