iedll.dll

TODO:

AZTEC MEDIA INC.

The module iedll.dll, “TODO: <File description>” by AZTEC MEDIA INC has been detected as adware by 13 anti-malware scanners. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘LinkeyBHO’.
Publisher:
TODO: <Company name>  (signed by AZTEC MEDIA INC.)

Product:
TODO: <Product name>

Description:
TODO: <File description>

Version:
1.0.0.1

MD5:
9cc0d0a96f3af783c04e46649ceb1d33

SHA-1:
fb9b6d52bf01a2e5bffa7f3c4a7bddea78325661

SHA-256:
2d7e28f384c4548daf29ed58879263bb397b7502c2484254a8f35f5bc5d0b858

Scanner detections:
13 / 68

Status:
Adware

Analysis date:
4/25/2024 5:33:56 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.Toolbar
2014.08.20

Baidu Antivirus
Adware.Win32.SearchSuite
4.0.3.14922

F-Prot
W32/SearchSuite.A.gen
v6.4.7.1.166

G Data
Win32.Application.AztecSystemK
14.9.24

IKARUS anti.virus
PUA.Toolbar.SearchSuite
t3scan.1.7.5.0

K7 AntiVirus
Unwanted-Program
13.183.13098

Kaspersky
not-a-virus:WebToolbar.Win64.SearchSuite
14.0.0.3212

Malwarebytes
PUP.Optional.Linkey.A
v2014.09.22.01

McAfee
Artemis!F8FB4ADA1F12
5600.6999

Panda Antivirus
Trj/CI.A
14.09.22.01

Qihoo 360 Security
Win32/Virus.WebToolbar.d3d
1.0.0.1015

Reason Heuristics
PUP.BHO.AZTECMEDIAINC.C
14.3.3.18

Sophos
SearchSuite
4.98

File size:
179 KB (183,312 bytes)

Product version:
1.0.0.1

Copyright:
TODO: (c) <Company name>. All rights reserved.

Original file name:
comext.dll

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\linkey\ieextension\iedll.dll

Digital Signature
Authority:
Thawte, Inc.

Valid from:
5/18/2013 5:00:00 PM

Valid to:
5/19/2015 4:59:59 PM

Subject:
CN=AZTEC MEDIA INC., OU=Development, O=AZTEC MEDIA INC., L=Panama City, S=Panama, C=PA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
546A239CA30D7A98B656DADCE4AA28E0

Registration
CLSID:
{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}

ProgID:
LinkeyBHO.LinkeyBHO

COM registered:
Yes

File PE Metadata
Compilation timestamp:
12/4/2013 11:45:21 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:ms7N59kSqsrcp36tABagol+EagDpELNFMSSaN8lFI:ms7NTkSqRrBagolHaMuUaNT

Entry address:
0xE0FD

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, C6, 36, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 8D, 45, 14, 50, 6A, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 8F, 39, 00, 00, 83, C4, 14, 5D, C3, B8, EB, 25, 01, 10, A3, F8, 27, 02, 10, C7, 05, FC, 27, 02, 10, E1, 1C, 01, 10, C7, 05, 00, 28, 02, 10, 95, 1C, 01, 10, C7, 05, 04, 28, 02, 10, CE, 1C, 01, 10, C7, 05, 08, 28, 02, 10, 37, 1C, 01, 10, A3, 0C, 28, 02, 10, C7, 05, 10, 28, 02, 10, 63, 25...
 
[+]

Entropy:
6.2415

Code size:
99 KB (101,376 bytes)

Internet Explorer BHO
Display name:
LinkeyBHO

CLSID:
{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}


Remove iedll.dll - Powered by Reason Core Security