ietoolbar64.dll

Findwide Toolbar

Findwide

This is the Tightrope WebInstall which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The module ietoolbar64.dll by Findwide has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Tightrope WebInstall installer. Additionally, the file is typically installed by a number of programs including TNT2-10521 Toolbar by Search.us.com and FindWide.com by FindWide, both potentially unwanted software.
Publisher:
Findwide  (signed and verified)

Product:
Findwide Toolbar

Version:
2.0.0.1529

MD5:
006b9a0e17674831fc2660bf71eac76e

SHA-1:
f3a5fad5a00abe747772760ea84d9edaeb3e433b

SHA-256:
d39c217fef50c6ad7485c5171390374b253f2554d85a8a83da6334c7ec01d4ee

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/23/2024 10:29:17 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Tightrope.Bundler
15.4.2.1

File size:
159.3 KB (163,072 bytes)

Product version:
2.0.0.1529

Copyright:
© Findwide All Rights Reserved

Original file name:
IEToolbar.dll

File type:
Dynamic link library (Win64 DLL)

Bundler/Installer:
Tightrope WebInstall

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\tnt2\2.0.0.1534\ietoolbar64.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/2/2012 3:00:00 AM

Valid to:
4/4/2013 2:59:59 AM

Subject:
CN=Findwide, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Findwide, L=San Francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4DA4730894ED337B96666A0979D619C2

File PE Metadata
Compilation timestamp:
3/25/2013 8:15:45 PM

OS version:
6.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
3072:TY5zypFQ1BGh3ZKY9UWjSOR7uTQxt+wI8+t1g9edKrm20Xa+fVu:3peGh3ZfUWvUTqt+5dt6m2N3

Entry address:
0xA824

Entry point:
48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 57, 48, 83, EC, 20, 49, 8B, F8, 8B, DA, 48, 8B, F1, 83, FA, 01, 75, 05, E8, 53, 65, 00, 00, 4C, 8B, C7, 8B, D3, 48, 8B, CE, 48, 8B, 5C, 24, 30, 48, 8B, 74, 24, 38, 48, 83, C4, 20, 5F, E9, 03, 00, 00, 00, CC, CC, CC, 48, 8B, C4, 48, 89, 58, 20, 4C, 89, 40, 18, 89, 50, 10, 48, 89, 48, 08, 56, 57, 41, 56, 48, 83, EC, 50, 49, 8B, F0, 8B, DA, 4C, 8B, F1, BA, 01, 00, 00, 00, 89, 50, B8, 85, DB, 75, 0F, 39, 1D, 18, B7, 01, 00, 75, 07, 33, C0, E9, D2, 00, 00, 00, 8D, 43, FF...
 
[+]

Code size:
81 KB (82,944 bytes)

The file ietoolbar64.dll has been discovered within the following programs.

FindWide.com  by FindWide
FindWide is a potentially unwanted application that runs in the web browser as a toolbar and web extension.
search.findwide.com
67% remove it
Search.us.com  by Search.us.com
Search.us.com Toolbar a web browser extension and Browser helper Object (for Internet Explorer) that delivers contextual based advertising to the web browser.
www.Search.us.com
82% remove it
TNT2-10521 Toolbar  by Search.us.com
TNT2 Toolbar (AKA Search.Us.com Toolbar) from TightRope Interactive is a potentially unwanted application that runs in the web browser as a toolbar and web extension.
87% remove it
 
Powered by Should I Remove It?

Remove ietoolbar64.dll - Powered by Reason Core Security