solid savings plugin-buttonutil64.exe

Solid Savings Plugin

Fun Apps

This is part of a distribution package that is classified as adware distributed by 50onRed. This adware is used to interact with the installed web browsers and inject ads and modify the default search and homepages. The application solid savings plugin-buttonutil64.exe, “Solid Savings Plugin exe” by Fun Apps has been detected as adware by 17 anti-malware scanners. This file is typically installed with the program Solid Savings Plugin by 215 Apps which is a potentially unwanted software program. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
Innovative Apps  (signed by Fun Apps)

Product:
Solid Savings Plugin

Description:
Solid Savings Plugin exe

Version:
1000.1000.1000.1000

MD5:
9043b41bc5c7fbb1abaad300a80922f5

SHA-1:
dedd9677d7ddfa5b0869730388f61ecf62689242

SHA-256:
dce35bf797b7215d6676ec74ce7d09aa677d926bd61830136bb2c72c4cc21996

Scanner detections:
17 / 68

Status:
Adware

Explanation:
Part of the Crossrider toolbar platform. It will download and install new code and Javascript updates for the extension.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is Fun Apps.

Analysis date:
12/25/2024 12:32:04 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Generic.585693
1032

AVG
AdInject.FunApps
2015.0.3519

Baidu Antivirus
HackTool.Win64.Crossrider
4.0.3.1448

Bitdefender
Adware.Generic.585693
1.0.20.490

Bkav FE
W32.Clod9bc.Trojan
1.3.0.4613

Dr.Web
Trojan.Crossrider.1
9.0.1.098

Emsisoft Anti-Malware
Adware.Generic.585693
8.14.04.08.09

ESET NOD32
Win64/Toolbar.Crossrider (variant)
8.9614

Fortinet FortiGate
Adware/Fam.NB
4/8/2014

F-Secure
Adware.Generic.585693
11.2014-08-04_3

G Data
Adware.Generic.585693
14.4.22

K7 AntiVirus
Trojan
13.174.10530

Malwarebytes
PUP.Optional.SolidSavings.A
v2014.03.30.03

McAfee
Artemis!09E1271B51C6
5600.7166

MicroWorld eScan
Adware.Generic.585693
15.0.0.294

Reason Heuristics
PUP.Crossrider.FunApps.b
14.8.7.17

VIPRE Antivirus
Crossrider
27864

File size:
436.9 KB (447,352 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
Solid Savings Plugin.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\solid savings plugin\solid savings plugin-buttonutil64.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
6/3/2013 6:00:00 PM

Valid to:
6/4/2014 5:59:59 PM

Subject:
CN=Fun Apps, O=Fun Apps, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
684B8CFA6A114F5EE6A8115E415BF20A

File PE Metadata
Compilation timestamp:
8/12/2013 3:46:43 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:EsDw3GMZ0yKDzfFk0C2q+TKdGmvOn+UKc439e4+mkT5l8sX62ZShLR0tKec4KCTH:bDw3GD/9gd0uBX3efYhN5CT4IkS

Entry address:
0x304B8

Entry point:
48, 83, EC, 28, E8, 7F, B3, 00, 00, 48, 83, C4, 28, E9, 52, FE, FF, FF, CC, CC, 40, 55, 41, 54, 41, 55, 41, 56, 41, 57, 48, 83, EC, 50, 48, 8D, 6C, 24, 40, 48, 89, 5D, 40, 48, 89, 75, 48, 48, 89, 7D, 50, 48, 8B, 05, FE, 72, 03, 00, 48, 33, C5, 48, 89, 45, 08, 8B, 5D, 60, 33, FF, 4D, 8B, F1, 45, 8B, F8, 89, 55, 00, 85, DB, 7E, 2A, 44, 8B, D3, 49, 8B, C1, 41, FF, CA, 40, 38, 38, 74, 0C, 48, FF, C0, 45, 85, D2, 75, F0, 41, 83, CA, FF, 8B, C3, 41, 2B, C2, FF, C8, 3B, C3, 8D, 58, 01, 7C, 02, 8B, D8, 44, 8B, 65...
 
[+]

Entropy:
6.2047

Code size:
290.5 KB (297,472 bytes)

The file solid savings plugin-buttonutil64.exe has been discovered within the following program.

Solid Savings Plugin  by 215 Apps
Solid Savings Plugin is an adware web browser extension designed to take control of the user's browser in order to redirect web searches and inject advertising. In Internet Explorer the program run as a Browser Helper Object.
www.50onred.com
79% remove it
 
Powered by Should I Remove It?

Remove solid savings plugin-buttonutil64.exe - Powered by Reason Core Security