BFTB.dll

BeFrugal.com Toolbar

Capital Intellect Inc

The module BFTB.dll by Capital Intellect Inc has been detected as a potentially unwanted program by 3 anti-malware scanners. It is installed as a toolbar in Internet Explore as ‘BFToolbar’.
Publisher:
Capital Intellect, Inc.  (signed by Capital Intellect Inc)

Product:
BeFrugal.com Toolbar

Version:
2013.3.6.1

MD5:
e997f6e728190e88b1aaaea3b4c43b10

SHA-1:
ce8eb644168672d93f29b3c53d855b0a0c880606

SHA-256:
b45ae797b9f94b2cbeff72d5cb9f40fcb0d2dbf1c50ded687052770c3d430386

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
4/18/2024 10:29:18 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.HfsAdware
1.3.0.7133

Reason Heuristics
Win32.Generic.CapitalIntellect.Toolbar.Meta
15.12.18.1

Sophos
Capital Intellect Installer
4.97

File size:
1.1 MB (1,114,960 bytes)

Product version:
2013.3.6.1

Copyright:
Copyright © 2011-2013 Capital Intellect, Inc. All Rights Reserved.

Trademarks:
All Rights Reserved. Patents Pending. Capital Intellect, Inc.

Original file name:
BFTB.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\common files\befrugal.com\toolbar\bftb.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/19/2011 8:00:00 PM

Valid to:
7/20/2014 7:59:59 PM

Subject:
CN=Capital Intellect Inc, OU=Winferno Software, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Capital Intellect Inc, L=Boston, S=Massachusetts, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
197FCA08FE62EEB9A434DA3987E23171

File PE Metadata
Compilation timestamp:
11/11/2013 3:38:33 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:rskOtO4IqjGCcG5UPN6B58VfL+fN925ybwBgUkMhwCrN6w03gzK6zQxMlN+E2dd2:Ik5DCcGgVfq192ob2k0wCYwC8Ewh7x1t

Entry address:
0x48E2B

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, E3, AA, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 33, C0, 39, 45, 0C, 76, 0F, 8B, 4D, 08, 80, 39, 00, 74, 07, 40, 41, 3B, 45, 0C, 72, F4, 5D, C3, 8B, FF, 55, 8B, EC, 53, 56, 8B, F1, 33, DB, 3B, F3, 75, 16, E8, 11, 04, 00, 00, 6A, 16, 5E, 89, 30, E8, 20, 44, 00, 00, 8B, C6, E9, 8F, 00, 00, 00, 57, 39, 5D, 08, 77, 13, E8, F5, 03, 00, 00, 6A, 16, 5E, 89, 30, E8, 04, 44, 00, 00, 8B, C6, EB, 75, 33, C9...
 
[+]

Entropy:
6.8192

Code size:
375 KB (384,000 bytes)

Internet Explorer Toolbar
Display name:
BFToolbar

CLSID:
{5BA2C4EE-42EF-4E2D-88BE-7271AE4E35B7}

CLSID name:
BeFrugal.com Toolbar


Remove BFTB.dll - Powered by Reason Core Security