BHOToolBar.dll

Online Games Downloader

Cheng Du VTools Information Technology

The module BHOToolBar.dll, “Firefox Extension” by Cheng Du VTools Information Technology has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
VTools  (signed by Cheng Du VTools Information Technology)

Product:
Online Games Downloader

Description:
Firefox Extension

Version:
2.0.0.104

MD5:
d906d01b517baf3d59da860bd754b618

SHA-1:
4e6a8d5e67b4eca9c7b26515c1d492a018011e93

SHA-256:
ae54a901d778011984a39da1f1988e93a445a98b91915a7669a7a239081e008f

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/27/2024 2:39:02 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.1.1.8

File size:
1.2 MB (1,265,568 bytes)

Product version:
2.0.0.0

Copyright:
Copyright(C) 2005-2011

Trademarks:
VTools

Original file name:
BHOToolBar.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\online games downloader\bhotoolbar.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/25/2010 7:00:00 PM

Valid to:
1/26/2012 6:59:59 PM

Subject:
CN=Cheng Du VTools Information Technology, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Cheng Du VTools Information Technology, L=ChengDu, S=SiChuan, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
74ABEBE80CBD793FD40D60CBD6D03A38

File PE Metadata
Compilation timestamp:
11/12/2010 3:21:10 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xF4DC4

Entry point:
55, 8B, EC, 83, C4, C0, B8, 9C, 2F, 4F, 00, E8, C4, 3C, F1, FF, E8, 4F, 05, F1, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 32, 13, 8B, C0, 02, 00, 8B, C0, 00, 8D, 40, 00, 00, 8D, 40, 00, 00, 8D, 40, 00, 01, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
972.5 KB (995,840 bytes)

Remove BHOToolBar.dll - Powered by Reason Core Security