allgeniusbho.dll

allgenius

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The module allgeniusbho.dll by allgenius has been detected as adware by 26 anti-malware scanners. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘allgenius 1.0.0.6’. This file is typically installed with the program allgenius by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
allgenius  (signed and verified)

Product:
allgenius

Version:
1.0.0.6

MD5:
cfea1aa4377d8bf090a19e4aa877e5b2

SHA-1:
a33199ff73b1d7b6100070f1dd4bb830f96d7dfd

SHA-256:
c17b57eccdaded8f01dcf4d202d716b5b9523c541f50861b43e9b35b86a28b1d

Scanner detections:
26 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
6/20/2025 12:56:25 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
Win-PUP/BrowseFox.Gen
2014.12.31

Avira AntiVirus
ADWARE/BrowseFox.Gen2
7.11.198.192

avast!
Win32:BrowseFox-FC [PUP]
2014.9-150102

AVG
BrowseFox.F
2016.0.3241

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.1512

Comodo Security
Application.Win32.BrowseFox.JM
20542

Dr.Web
Trojan.BPlug.215
9.0.1.02

ESET NOD32
Win32/BrowseFox (variant)
9.10947

Fortinet FortiGate
Adware/BrowseFox
1/2/2015

F-Prot
W32/S-7bed2e86
v6.4.7.1.166

G Data
Win32.Application.Agent.3OYQAZ
15.1.24

K7 AntiVirus
Trojan
13.188.14496

Kaspersky
not-a-virus:AdWare.Win32.Kranet
14.0.0.2702

Malwarebytes
PUP.Optional.Allgenius.A
v2015.01.02.12

McAfee
BrowseFox
5600.6897

NANO AntiVirus
Riskware.Win32.Kranet.dkvuxq
0.30.0.64448

nProtect
Trojan-Clicker/W32.LinkSwift.250144
14.11.27.01

Panda Antivirus
Trj/CI.A
15.01.02.12

Qihoo 360 Security
HEUR/QVM30.1.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.BHO.allgenius.M
15.1.2.12

Sophos
Generic PUA KD
4.98

Trend Micro House Call
TROJ_GEN.F0C2C00LP14
7.2.2

Trend Micro
TROJ_GEN.F0C2C00LP14
10.465.02

Vba32 AntiVirus
AdWare.SwiftBrowse
3.12.26.3

VIPRE Antivirus
Yontoo
36238

File size:
244.3 KB (250,144 bytes)

Product version:
1.0.0.6

Copyright:
(c) allgenius. All rights reserved.

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\allgenius\allgeniusbho.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/22/2014 2:00:00 AM

Valid to:
4/23/2015 1:59:59 AM

Subject:
CN=allgenius, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=allgenius, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
570352A91D1B96E64EC15703FDAF2405

File PE Metadata
Compilation timestamp:
12/20/2014 4:31:25 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
3072:0cJBot/Cq/itJwlKXt6SSkFhTwGSujTci+nIaI9YUDHzD:01b/itDXtDSkAIKeHzD

Entry address:
0x12854

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 41, 8D, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, 80, 30, 03, 10, E8, BD, 01, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, 04, 78, 03, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, 0C, A5, 02, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
159 KB (162,816 bytes)

Internet Explorer BHO
Display name:
allgenius 1.0.0.6

CLSID:
{963e8e8b-052d-46d7-abe6-6728f612ae99}


The file allgeniusbho.dll has been discovered within the following programs.

allgenius  by Yontoo Technology, Inc.
allgenius is an adware program that runs within the user's web browser and will modify various browser settings such as changing the search provider.
allgenius.info/support
80% remove it
Buzzdock  by Alactro LLC
This is a web browser extension that injects advertising. From the EULA: "Buzzdock is free to download and use. Buzzdock is supported by advertising, and users will see additional ads on websites where Buzzdock features operate.
www.buzzdock.com/faq-support
79% remove it
 
Powered by Should I Remove It?

The file allgeniusbho.dll has been seen being distributed by the following URL.

Remove allgeniusbho.dll - Powered by Reason Core Security