BackgroundHost.exe

Add-ons Framework

We Code Good Inc.

This is part of a Performersoft product, a 'PC optimzation' application that provides minimal benifits and may have been bundled by a third party installer. The application BackgroundHost.exe by We Code Good has been detected as adware by 12 anti-malware scanners. This file is typically installed with the program Smiley Bar for Facebook by Status Winks which is a potentially unwanted software program.
Publisher:
We Code Good Inc.  (signed and verified)

Product:
Add-ons Framework

Description:
BackgroundHost

Version:
0.9.3.25

MD5:
5764c6092ca45a8f5677da9a11d31df5

SHA-1:
bc3cfda08ba49d5945d62bf1b8256a281019d19b

SHA-256:
5f89a3a13d46e2becc0815b34c1ff287dae45caabef9603f7632296e9cf6c49a

Scanner detections:
12 / 68

Status:
Adware

Explanation:
Part of the Besttoolbars Add-on framework for Internet Explorer, Chrome and Firefox.

Analysis date:
2/7/2026 7:31:47 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Toolbar.Besttoolbars
7.1.1

Bkav FE
HW32.Laneul
1.3.0.4923

Dr.Web
Adware.BGuard.32
9.0.1.048

ESET NOD32
Win32/Toolbar.Besttoolbars
10.9284

Malwarebytes
PUP.Optional.BestToolbar
v2016.02.17.06

McAfee
Artemis!DD63717721EB
5600.6486

NANO AntiVirus
Trojan.Win32.Brantall.czxhnn
0.28.2.62483

Panda Antivirus
Trj/Brantall.A
16.02.17.06

Reason Heuristics
PUP.Besttoolbars.Performersoft (M)
16.2.17.18

Trend Micro House Call
TROJ_GEN.F47V1209
7.2.48

VIPRE Antivirus
Besttoolbars
33754

XVirus List
Win.Detected
2.3.31

File size:
657.3 KB (673,080 bytes)

Product version:
0.9.3.25

Copyright:
Besttoolbars Inc. All rights reserved.

Original file name:
BackgroundHost.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\smiley bar for facebook\backgroundhost.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
11/1/2012 2:20:37 PM

Valid to:
11/1/2015 2:20:37 PM

Subject:
CN=We Code Good Inc., O=We Code Good Inc., L=Beaverton, S=OR, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
4EEF3A85620395

File PE Metadata
Compilation timestamp:
4/19/2013 2:47:07 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:+NotPeb8PzBF/7EKSrqu7lBmB9DzOas7Yn8AZuZ6NX8+4nDM:IAE8PzU4Fzr3ndusN8vnw

Entry address:
0x5B05C

Entry point:
E8, 16, B1, 00, 00, E9, 79, FE, FF, FF, CC, CC, 68, 20, 5D, 45, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 98, C4, 49, 00, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, 8B, FF, 55, 8B, EC, 56, 8D, 45, 08, 50, 8B, F1, E8, 2D, EF, FF, FF, C7, 06, 98, A4, 48, 00, 8B, C6, 5E, 5D...
 
[+]

Entropy:
6.3414

Code size:
513.5 KB (525,824 bytes)

The file BackgroundHost.exe has been discovered within the following program.

Smiley Bar for Facebook  by Status Winks
Smiley Bar for Facebook installs the "Monetization Platform", which is designed to show context based advertisements in your web browsers.
www.statuswinks.com
79% remove it
 
Powered by Should I Remove It?

Remove BackgroundHost.exe - Powered by Reason Core Security