msvcp100.dll

Microsoft Visual Studio 2010

Crossrider Advanced Technologies

Part of the Crossrider framework, a web browser extension that will deliver advertisements such as coupons, price-comparisons, display media, affiliate links, banners, popups/popunders and other links. msvcp100.dll is the runtime components of Visual C++ Libraries required to run applications developed with Visual C++ and is recompiled by Crossrider Advanced Technologies. While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The module msvcp100.dll, “Microsoft® C Runtime Library” by Crossrider Advanced Technologies has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The library is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. Although a detection has been made for this resource, it is generally a commonly distributed 3rd-party library and is typically safe by itself.
Publisher:
Microsoft Corporation  (signed by Crossrider Advanced Technologies)

Product:
Microsoft® Visual Studio® 2010

Description:
Microsoft® C Runtime Library

Version:
10.00.40219.1

MD5:
f7efbb3221ecf1a012138b98137b7db0

SHA-1:
4e125e99233aca26d62e64305f15f96440b72ceb

SHA-256:
433c2d79a52125e16cc8e5d7a67b087d4cd659a3a7a43fc97080de9f76eaef16

Scanner detections:
1 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
12/25/2024 2:13:40 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Crossrider (M)
17.3.14.1

File size:
411 KB (420,816 bytes)

Product version:
10.00.40219.1

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
msvcp100.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\fcb fan alert\msvcp100.dll

Digital Signature
Authority:
COMODO CA Limited

Valid from:
9/24/2012 2:00:00 AM

Valid to:
9/25/2015 1:59:59 AM

Subject:
CN=Crossrider Advanced Technologies, O=Crossrider Advanced Technologies, STREET=40 Lilienblum St, L=Tel-Aviv, S=Israel, PostalCode=65133, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00B9966EA31AF5750F30968D041D15669B

File PE Metadata
Compilation timestamp:
2/19/2011 1:18:09 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x33CF4

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 26, 04, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, C7, FE, FF, FF, 59, 5D, C2, 0C, 00, CC, CC, CC, CC, CC, FF, 25, B0, 11, 05, 78, CC, CC, CC, CC, CC, CC, FF, 25, C0, 11, 05, 78, CC, CC, CC, CC, CC, 6A, 0A, FF, 15, 24, 10, 05, 78, A3, 14, 1A, 0B, 78, 33, C0, C3, CC, CC, CC, CC, CC, FF, 25, C4, 11, 05, 78, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 68, BE, 3D, 08, 78, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10...
 
[+]

Code size:
371.5 KB (380,416 bytes)

Remove msvcp100.dll - Powered by Reason Core Security