allgeniusbho.dll

allgenius

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The module allgeniusbho.dll by allgenius has been detected as adware by 39 anti-malware scanners. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘allgenius’. This file is typically installed with the program allgenius by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
allgenius  (signed and verified)

Product:
allgenius

Version:
1.0.0.3

MD5:
fa4e9fa1de38629e87165c6d8591cc71

SHA-1:
6c7ce68904aab38985843318ae055e85e357950b

Scanner detections:
39 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
1/13/2025 5:51:30 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.SwiftBrowse.CX
372

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
Adware/Win32.BrowseFox
2015.11.24

Avira AntiVirus
ADWARE/BrowseFox.Gen2
7.11.217.198

avast!
Win32:BrowseFox-FC [PUP]
2014.9-160128

AVG
BrowseFox.F
2017.0.2850

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.16128

Bitdefender
Adware.SwiftBrowse.CX
1.0.20.140

Bkav FE
W32.HfsAdware
1.3.0.7383

Clam AntiVirus
Win.Adware.Browsefox-178
0.98/21511

Comodo Security
Application.Win32.BrowseFox.JM
23648

Dr.Web
Trojan.Yontoo.1734
9.0.1.028

Emsisoft Anti-Malware
Adware.SwiftBrowse.CX
8.16.01.28.08

ESET NOD32
Win32/BrowseFox.O potentially unwanted (variant)
10.12614

Fortinet FortiGate
Adware/BrowseFox
1/28/2016

F-Prot
W32/S-7bed2e86
v6.4.7.1.166

F-Secure
Adware.SwiftBrowse.CX
11.2016-28-01_5

G Data
Adware.SwiftBrowse.CX
16.1.25

IKARUS anti.virus
PUA.BrowseFox
t3scan.1.9.5.0

K7 AntiVirus
Trojan
13.212.17945

Kaspersky
not-a-virus:AdWare.Win32.Kranet
14.0.0.746

Malwarebytes
PUP.Optional.Allgenius.A
v2016.01.28.08

McAfee
BrowseFox
5600.6506

MicroWorld eScan
Adware.SwiftBrowse.CX
17.0.0.84

NANO AntiVirus
Riskware.Win32.Kranet.dkvuxq
0.30.26.4751

nProtect
Adware.SwiftBrowse.CX
15.11.24.01

Panda Antivirus
Trj/CI.A
16.01.28.08

Qihoo 360 Security
HEUR/QVM30.1.Malware.Gen
1.0.0.1015

Quick Heal
PUA.Allgenius.Gen
1.16.14.00

Reason Heuristics
PUP.Yontoo.allgenius (M)
16.1.28.20

Rising Antivirus
PE:Adware.BrowserFox!1.A127 [F]
23.00.65.16126

Sophos
Generic PUA HN (PUA)
4.98

Total Defense
Heur/TrojanHorse.ZCGV!suspicious
37.1.62.1

Trend Micro House Call
TROJ_GEN.F0C2C00BC15
7.2.28

Trend Micro
TROJ_GEN.R047C0EH415
10.465.28

Vba32 AntiVirus
AdWare.Kranet
3.12.26.4

VIPRE Antivirus
Yontoo
45392

ViRobot
Adware.Browsefox.250144.E[h]
2014.3.20.0

Zillya! Antivirus
Adware.Agent.Win32.29836
2.0.0.2527

File size:
244.3 KB (250,144 bytes)

Product version:
1.0.0.3

Copyright:
(c) allgenius. All rights reserved.

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\allgenius\allgeniusbho.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/21/2014 9:00:00 PM

Valid to:
4/22/2015 8:59:59 PM

Subject:
CN=allgenius, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=allgenius, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
570352A91D1B96E64EC15703FDAF2405

Registration
CLSID:
{963e8e8b-052d-46d7-abe6-6728f612ae99}

COM registered:
Yes

File PE Metadata
Compilation timestamp:
11/24/2014 4:33:43 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
3072:/xBotzn5MrRY/xRyklvnnDSuDTci+G3IaIbhutJxP:/yzn5MtY/LyijINeJxP

Entry address:
0x12854

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 41, 8D, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, 80, 30, 03, 10, E8, BD, 01, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, 24, 78, 03, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, 0C, A5, 02, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
159 KB (162,816 bytes)

Internet Explorer BHO
Display name:
allgenius

CLSID:
{963e8e8b-052d-46d7-abe6-6728f612ae99}


The file allgeniusbho.dll has been discovered within the following program.

allgenius  by Yontoo Technology, Inc.
allgenius is an adware program that runs within the user's web browser and will modify various browser settings such as changing the search provider.
allgenius.info/support
80% remove it
 
Powered by Should I Remove It?

The file allgeniusbho.dll has been seen being distributed by the following URL.

Remove allgeniusbho.dll - Powered by Reason Core Security