allgeniusbho.dll

allgenius

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The module allgeniusbho.dll by allgenius has been detected as adware by 37 anti-malware scanners. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘allgenius’. This file is typically installed with the program allgenius by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
allgenius  (signed and verified)

Product:
allgenius

Version:
1.0.0.3

MD5:
c9a0d0830fe0587b905d4cc9c7aeb150

SHA-1:
70d737f8b31c8bcb0e978ee425dff0b81e0b9320

SHA-256:
a1e8340870847cc6ad151c636d87cba7e2418a7d6f4819e44334431f6726859c

Scanner detections:
37 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
1/13/2025 5:50:34 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.BHO.Agent.4
874

Avira AntiVirus
APPL/BrowseFox.Gen2
7.11.171.112

avast!
Win32:BrowseFox-AW [PUP]
2014.9-140913

AVG
BrowseFox.F
2015.0.3352

Baidu Antivirus
Adware.Win32.Agent
4.0.3.14913

Bitdefender
Gen:Variant.Adware.BHO.Agent.4
1.0.20.1280

Comodo Security
Application.Win32.Altbrowse.AK
19469

Dr.Web
Trojan.BPlug.17
9.0.1.0256

Emsisoft Anti-Malware
Gen:Variant.Adware.BHO.Agent
8.14.09.13.05

ESET NOD32
Win32/BrowseFox (variant)
8.10390

Fortinet FortiGate
Adware/Agent
9/13/2014

F-Prot
W32/BadBHO.AW.gen
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.BHO.Agent.4
11.2014-13-09_7

G Data
Gen:Variant.Adware.BHO.Agent
14.9.24

herdProtect (fuzzy)
2014.11.10.3

IKARUS anti.virus
not-a-virus:AdWare.Win32.Agent
t3scan.1.7.5.0

K7 AntiVirus
Unwanted-Program
13.183.13319

Kaspersky
not-a-virus:AdWare.Win32.Agent
14.0.0.3256

Malwarebytes
PUP.Optional.Allgenius.A
v2014.09.13.05

McAfee
Artemis!C9A0D0830FE0
5600.7008

MicroWorld eScan
Gen:Variant.Adware.BHO.Agent.4
15.0.0.768

NANO AntiVirus
Riskware.Win32.Agent.crkvek
0.28.2.61942

nProtect
Trojan-Clicker/W32.Agent.249632.B
14.09.07.01

Panda Antivirus
Trj/CI.A
14.09.13.05

Qihoo 360 Security
HEUR/Malware.QVM30.Gen
1.0.0.1015

Reason Heuristics
Adware.Yontoo.BHO.M
14.9.13.17

Sophos
Generic PUA HA
4.98

SUPERAntiSpyware
Adware.BrowseFox/Variant
10362

Trend Micro House Call
TROJ_GEN.F0C2H00I314
7.2.256

Vba32 AntiVirus
AdWare.Agent
3.12.26.3

VIPRE Antivirus
Yontoo
32960

Zillya! Antivirus
Adware.Agent.Win32.9068
2.0.0.1916

File size:
243.8 KB (249,632 bytes)

Product version:
1.0.0.3

Copyright:
(c) allgenius. All rights reserved.

Original file name:
allgeniusIEClient.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\allgenius\allgeniusbho.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/21/2014 5:00:00 PM

Valid to:
4/22/2015 4:59:59 PM

Subject:
CN=allgenius, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=allgenius, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
570352A91D1B96E64EC15703FDAF2405

File PE Metadata
Compilation timestamp:
5/19/2014 11:55:34 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
3072:s3zAFVxVbC/hm4w9uRil2D/ID9HedRpjP+L1IaIus/yBeQayg:s3zeK92ukDUdHLU1InNbyg

Entry address:
0x12844

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 41, 8D, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, 30, 2D, 03, 10, E8, BD, 01, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, 24, 68, 03, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, 8C, A1, 02, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Entropy:
6.3663

Developed / compiled with:
Microsoft Visual C++

Code size:
159 KB (162,816 bytes)

Internet Explorer BHO
Display name:
allgenius

CLSID:
{b69e6465-8844-4d10-8a6f-22d056e4c2bf}


The file allgeniusbho.dll has been discovered within the following programs.

allgenius  by Yontoo Technology, Inc.
allgenius is an adware program that runs within the user's web browser and will modify various browser settings such as changing the search provider.
allgenius.info/support
80% remove it
Buzzdock  by Alactro LLC
This is a web browser extension that injects advertising. From the EULA: "Buzzdock is free to download and use. Buzzdock is supported by advertising, and users will see additional ads on websites where Buzzdock features operate.
www.buzzdock.com/faq-support
79% remove it
 
Powered by Should I Remove It?

The file allgeniusbho.dll has been seen being distributed by the following URL.

Remove allgeniusbho.dll - Powered by Reason Core Security