b1toolbar32.dll

Internet Explorer Toolbar

IT Management Group LTD

This is part of a bundled installer which provides applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The module b1toolbar32.dll by IT Management Group has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘AliBar BHO’.
Publisher:
ImprovedSearch  (signed by IT Management Group LTD)

Product:
Internet Explorer Toolbar

Description:
Improved Search

Version:
1.0.2.1

MD5:
f6457051119c89dec0b7bf2ef1474557

SHA-1:
c2e319ae9cf30020b42298ba55bcc9286459e30c

SHA-256:
331cd913ec49d6d2818d6852f42277348912a691524f918918f6707553491bc6

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/19/2024 11:46:21 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.BHO.ITManagementGroup.L
14.9.11.21

File size:
271 KB (277,488 bytes)

Product version:
1.0.2.1

Copyright:
http://search.b1.org

Original file name:
ImprovedSearch.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\Program Files\b1 free archiver\toolbar\b1toolbar32.dll

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/18/2012 3:00:00 AM

Valid to:
1/18/2013 2:59:59 AM

Subject:
CN=IT Management Group LTD, O=IT Management Group LTD, STREET=135 Arch. Makarios III Avenue, STREET=Emelle Building 4th floor, L=Limassol, S=Limassol, PostalCode=3021, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
009F750087DD24E5BFA7394C0A178EEAD8

File PE Metadata
Compilation timestamp:
9/4/2012 7:01:17 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:GvP15wrAvxFKoeAqs/JjLyJig7eQzrAMeexSeLcO1LyfFe2V/j4uizr2M:Gvh6iIWmDcO1ujV/dnM

Entry address:
0x157AF

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 57, 03, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, CC, FE, FF, FF, 59, 5D, C2, 0C, 00, CC, CC, 68, 3C, 53, 01, 10, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, F8, 19, 02, 10, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, 8B, FF...
 
[+]

Entropy:
5.2383

Code size:
88 KB (90,112 bytes)

Internet Explorer BHO
Display name:
AliBar BHO

CLSID:
{E4E012DC-1925-48E9-8010-2D195574642A}

CLSID name:
Improved search toolbar


Remove b1toolbar32.dll - Powered by Reason Core Security