BackgroundHost.exe

Add-ons Framework

Lyoness Cashback AG

The application BackgroundHost.exe by Lyoness Cashback AG has been detected as adware by 7 anti-malware scanners. This file is typically installed with the program Lyoness Cashback Bar by Lyoness Cashback AG.
Publisher:
Lyoness Cashback AG  (signed and verified)

Product:
Add-ons Framework

Description:
BackgroundHost

Version:
1.0.12.16

MD5:
552117b7738dd63b130183894877b660

SHA-1:
ccab195f71c7b010720f432881e617c50f826fe5

SHA-256:
63eba945fb63bf10976cf233db32eaf2b0d83cbec7801a7305f18524e2508636

Scanner detections:
7 / 68

Status:
Adware

Explanation:
Part of the Besttoolbars Add-on framework for Internet Explorer, Chrome and Firefox.

Analysis date:
4/25/2024 11:20:59 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Toolbar.Besttoolbars
7.1.1

Dr.Web
Adware.Plugin.349
9.0.1.0236

ESET NOD32
Win32/Toolbar.Besttoolbars.G potentially unwanted (variant)
9.11335

Fortinet FortiGate
Riskware/Besttoolbars
8/24/2015

McAfee
Artemis!552117B7738D
5600.6664

Reason Heuristics
PUP.Besttoolbars.LyonessCashbackAG (M)
15.8.24.6

VIPRE Antivirus
Besttoolbars
38514

File size:
639.4 KB (654,768 bytes)

Product version:
1.0.12.16

Copyright:
Besttoolbars Inc. All rights reserved.

Original file name:
BackgroundHost.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\lyoness cashback bar\backgroundhost.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
10/21/2013 6:07:04 PM

Valid to:
10/21/2016 6:07:04 PM

Subject:
E=domainadmin@lyoness.ag, CN=Lyoness Cashback AG, O=Lyoness Cashback AG, L=Graz, S=Styria, C=AT

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121966E6F40865E27DA6418F77DA28077D3

File PE Metadata
Compilation timestamp:
12/17/2013 9:57:54 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:XNUVeV3rV0KMiYE3V4g9xEidGBvjgvspLNdb+39ptM30mLR6AL5SU:XNKe6EFHvd4gkpLNd0G3PRzB

Entry address:
0x5A791

Entry point:
E8, 72, A2, 00, 00, E9, 89, FE, FF, FF, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 04, 89, 49, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 04, 89, 49, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B...
 
[+]

Code size:
492.5 KB (504,320 bytes)

The file BackgroundHost.exe has been discovered within the following program.

Lyoness Cashback Bar  by Lyoness Cashback AG
www.lyoness.net
About 7% of users remove it
 
Powered by Should I Remove It?

Remove BackgroundHost.exe - Powered by Reason Core Security