crimsolite

crimsolite

Known Adware

by Yontoo Technology, Inc.

What is crimsolite?

crimsolite is software application developed by Yontoo Technology, Inc.. It is most commonly found on computers running Windows 7 with nearly 52.24% of installations running this operating system. crimsolite's installer is typically 2.00 MB in size and installs around 9 files. The most common release is 2014.02.26.051729 with 11.94% of all installations currently using this version.

crimsolite is most popular in the United States with 59.49% of installations residing in this country.

About crimsolite?

crimsolite is an adware application distributed by Yontoo, a subsidiary of Sambreel Holdings located in Carlsbad, CA. It is a rebranded version of several web browser extensions delivered by Yontoo with similar names. The program is typically bundled with other software downloads. Upon installation, crimsolite installs itself as a web browser add-in or extension, depending on the browser being used (Chrome, IE, Firefox). It then injects various forms of advertising into the browser, including inline text, multi-site searching, comparison shopping pop-ups, and numerous banners and pop-ups/pop-unders for additional offers, both standard ads and unwanted software. In addition to displaying advertisements, the adware extension modifies the web browser's settings to facilitate its ad injection offers. It automatically disables the two-second load time in Internet Explorer, without user notification, preventing the browser from warning about the effects of a slower BHO. It also modifies the browser's Instant Search feature and adjusts it so that clicking on a search engine results page link opens the page in a new browser tab. These actions are performed without proper user notification, except for mention in the website's EULA.

Multiple virus scanners have detected malware in crimsolite.

updatecrimsolite.exe (MD5: 3df44bf35075be7a1f7d94ff7c23e5cb) has been flagged by 21 scanners:
Scanner Software Result
Lavasoft Ad-Aware Adware.SwiftBrowse.AA
Agnitum Outpost Riskware.Agent!
Antiy-AVL Trojan/Win32.TSGeneric
AVG Crimso.E8C
Baidu-International Adware.Win32.BrowseFox.bH
Bitdefender Adware.SwiftBrowse.AA
CMC Antivirus P2P-Worm.Win32.SpyBot!O
Emsisoft Anti-Malware Adware.SwiftBrowse.AA (B)
ESET-NOD32 a variant of Win32/BrowseFox.H
Fortinet FortiGate Riskware/BrowseFox
F-Secure Adware.SwiftBrowse.AA
G Data Adware.SwiftBrowse.AA
IKARUS anti.virus AdWare.Agent
Malwarebytes PUP.Optional.Crimsolite.A
McAfee Artemis!3DF44BF35075
McAfee-GW-Edition Artemis!3DF44BF35075
MicroWorld-eScan Adware.SwiftBrowse.AA
nProtect Adware.SwiftBrowse.AA
Sophos Generic PUA FJ
TrendMicro-HouseCall Suspicious_GEN.F47V0621
VIPRE Antivirus Yontoo (fs)
crimsoliteBHO.dll (MD5: 3b2b48ad60b752cffe49b18c4c407bc8) has been flagged by 27 scanners:
Scanner Software Result
Antiy-AVL AdWare/Win32.Agent
Comodo Security Application.Win32.Altbrowse.AK
Dr.Web Adware.Plugin.100
ESET-NOD32 Win32/BrowseFox.D
Fortinet FortiGate Adware/Agent
Kaspersky not-a-virus:AdWare.Win32.Agent
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.Crimsolite.A
NANO AntiVirus Riskware.Win32.Agent.cqycvd
Sophos Generic PUA DA
Vba32 AntiVirus AdWare.Agent
VIPRE Antivirus Adware.Agent
Lavasoft Ad-Aware Adware.SwiftBrowse.AA
Agnitum Outpost Riskware.Agent!
AVG Crimso.E8C
Baidu-International Adware.Win32.BrowseFox.bH
Bitdefender Adware.SwiftBrowse.AA
CMC Antivirus P2P-Worm.Win32.SpyBot!O
Emsisoft Anti-Malware Adware.SwiftBrowse.AA (B)
F-Secure Adware.SwiftBrowse.AA
G Data Adware.SwiftBrowse.AA
IKARUS anti.virus AdWare.Agent
McAfee Artemis!3DF44BF35075
McAfee-GW-Edition Artemis!3DF44BF35075
MicroWorld-eScan Adware.SwiftBrowse.AA
nProtect Adware.SwiftBrowse.AA
TrendMicro-HouseCall Suspicious_GEN.F47V0621

Software Behaviors

Services:
  • updatecrimsolite.exe runs as a service named 'Update crimsolite' (Update crimsolite).

Software Details

URL:
https://crimsolite.co/support
Support:
https://mailto:
Installation path:
C:\Program Files\crimsolite
Uninstaller:
C:\Program Files\crimsolite\crimsoliteuninstall.exe
Size:
2.00 MB
Language:
English

crimsolite Executable Details

Primary executable:
crimsoliteBHO.dll
Name:
crimsolite
Path:
C:\Program Files\crimsolite\crimsoliteBHO.dll
MD5:
3b2b48ad60b752cffe49b18c4c407bc8
SHA-1:
SHA-256:
Files installed by crimsolite
File Type Filename MD5
EXE
e92604e043f51c604b6d1ac3bcd3a202
EXE
3df44bf35075be7a1f7d94ff7c23e5cb
EXE
2f4883f3f61a16977c66c71b83bce0c4
DLL
3b2b48ad60b752cffe49b18c4c407bc8
EXE
a31b6a992db381741f8049260c164d1d
EXE
68f6b7161df4f5ffa3f50c2536b096bd
CRX
75d9030ca59c98c2bf9de8d18ced8b99
DLL
05aae3bfe7c49e4a416c386f1bd524a4
EXE
080444b0b40d822cec7270329a6f0116