kuezhoaj7iilof.dll

and

The module kuezhoaj7iilof.dll, “tools data the is” has been detected as a potentially unwanted program by 6 anti-malware scanners. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘GoSave’. This file is typically installed with the program ApptoU by InstalleRex-WebPick which is a potentially unwanted software program.
Publisher:
and

Product:
and

Description:
tools data the is

Version:
one Physically significant

MD5:
e632e9bdbcd9337b0b85d5a437d2e2c3

SHA-1:
46d02d5bad7cc1819737d16d4ad0cb931f57347b

SHA-256:
87aa09c3eabbc691b1e422972057dccb71aae9c5dd0608a53e1e43c73818560a

Scanner detections:
6 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 11:54:42 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

AegisLab AV Signature
AdWare.W32.MegaSearch
2.1.4+

Avira AntiVirus
ADWARE/MultiPlug.Gen
7.11.180.144

Baidu Antivirus
Adware.Win32.MultiPlug
4.0.3.141022

ESET NOD32
Win32/AdWare.MultiPlug.BN (variant)
8.10603

Malwarebytes
PUP.Optional.MultiPlug
v2014.10.22.02

McAfee
MultiPlug
5600.6969

File size:
631 KB (646,144 bytes)

Product version:
and

Copyright:
Copyright (C) 2014

Original file name:
tools data the is

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\gosave\kuezhoaj7iilof.dll

File PE Metadata
Compilation timestamp:
10/22/2014 4:04:23 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:ANOBC36tUb62HejEss0ZUzt9dhmAeLIWmhQw:AN8aqjFdUztQrg

Entry address:
0x5F441

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 6D, 5B, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, B8, 94, 07, 10, E8, 50, 0B, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, D8, 3E, 08, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, B8, 06, 07, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
427 KB (437,248 bytes)

Internet Explorer BHO
Display name:
GoSave

CLSID:
{91864fe1-2341-45b8-9a9d-9997c9eeafc6}


The file kuezhoaj7iilof.dll has been discovered within the following program.

ApptoU  by InstalleRex-WebPick
AppToU is an adware program that will display extra advertisements when users are using search engines such as Bing and Google. In Chrome, it installs itself as an extension and in Internet Explorer it runs as a process as well as a Browser Helper Object.
83% remove it
 
Powered by Should I Remove It?

Remove kuezhoaj7iilof.dll - Powered by Reason Core Security