KiweeContentHost.dll

Kiwee Toolbar

American Greetings, Inc.

The module KiweeContentHost.dll, “Browser Dialog Host” by American Greetings has been detected as a potentially unwanted program by 27 anti-malware scanners.
Publisher:
AG Interactive  (signed by American Greetings, Inc.)

Product:
Kiwee Toolbar

Description:
Browser Dialog Host

Version:
1.3.0.118

MD5:
1e61546357ca653311c8cad1ad8f39f1

SHA-1:
8d3538e18792186e26a644847ef8dc191ac5e4c8

SHA-256:
3405dbf7dfff118e71c18e4ad96675048603212e4be20ed835c00802753f5660

Scanner detections:
27 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 3:19:24 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Kiwee.A
388

Agnitum Outpost
Trojan.DL.Zlob
7.1.1

AhnLab V3 Security
Win-Trojan/Zlob.319488.AC
2015.03.11

Avira AntiVirus
TR/Dldr.Zlob.meq.1
7.11.215.236

avast!
Win32:Trojan-gen
2014.9-160113

Baidu Antivirus
Adware.Win32.Kiwee
4.0.3.16113

Bitdefender
Adware.Kiwee.A
1.0.20.65

Comodo Security
TrojWare.Win32.TrojanDownloader.Zlob.meq
21366

Dr.Web
Trojan.Popuper.13272
9.0.1.013

Emsisoft Anti-Malware
Adware.Kiwee
8.16.01.13.08

Fortinet FortiGate
W32/Zlob.MEQ!tr
1/13/2016

F-Prot
W32/Downldr2.EJWT
v6.4.7.1.166

F-Secure
Adware.Kiwee.A
11.2016-13-01_4

G Data
Adware.Kiwee
16.1.25

Kaspersky
not-a-virus:AdWare.Win32
14.0.0.823

McAfee
Generic.dx!1E61546357CA
5600.6522

MicroWorld eScan
Adware.Kiwee.A
17.0.0.39

NANO AntiVirus
Trojan.Win32.Popuper.bwovqf
0.30.0.296

Norman
Zlob.GIGW
11.20160113

nProtect
Trojan-Clicker/W32.Kiwee.322712
15.03.10.01

Qihoo 360 Security
Win32/Trojan.e0d
1.0.0.1015

Total Defense
Win32/Zlob.EL
37.0.11488

Trend Micro House Call
GRAY_GEN.7X0418S
7.2.13

Trend Micro
GRAY_GEN.7X0418S
10.465.13

VIPRE Antivirus
Trojan-Downloader.Zlob.Media-Codec
38318

ViRobot
Adware.Zlob.Do.322712[h]
2014.3.20.0

Zillya! Antivirus
Trojan.Zlob.Win32.26
2.0.0.2093

File size:
315.1 KB (322,712 bytes)

Product version:
1.3.0.118

Copyright:
Copyright © 2007. AG Interactive, Inc. All rights reserved.

Original file name:
KiweeContentHost.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\kiwee toolbar2\1.3.118\kiweecontenthost.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/5/2006 8:00:00 PM

Valid to:
11/17/2009 6:59:59 PM

Subject:
CN="American Greetings, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="American Greetings, Inc.", L=Cleveland, S=OH, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1B19336ECEEC6FDE6D5E559B9065B037

File PE Metadata
Compilation timestamp:
2/18/2008 2:01:00 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:o5whTiSgl/0JYNE0AdQoQJUXJHpoLCDosIPUF:M0JYNpSQoQJexW2DoY

Entry address:
0x1CFFF

Entry point:
83, 7C, 24, 08, 01, 75, 05, E8, A9, 5B, 00, 00, FF, 74, 24, 04, 8B, 4C, 24, 10, 8B, 54, 24, 0C, E8, ED, FE, FF, FF, 59, C2, 0C, 00, 6A, 0C, 68, E8, D6, 03, 10, E8, B8, 1D, 00, 00, 83, 65, E4, 00, 8B, 75, 08, 3B, 35, 70, 65, 04, 10, 77, 22, 6A, 04, E8, 7C, 5D, 00, 00, 59, 83, 65, FC, 00, 56, E8, BE, 65, 00, 00, 59, 89, 45, E4, C7, 45, FC, FE, FF, FF, FF, E8, 09, 00, 00, 00, 8B, 45, E4, E8, C4, 1D, 00, 00, C3, 6A, 04, E8, 79, 5C, 00, 00, 59, C3, 55, 8B, 6C, 24, 08, 83, FD, E0, 0F, 87, 9F, 00, 00, 00, 53, 8B...
 
[+]

Entropy:
6.2173

Code size:
200 KB (204,800 bytes)

Remove KiweeContentHost.dll - Powered by Reason Core Security