ramicro_toolbar.dll

ra e IE Toolbar

RA-MICRO Software GmbH

The module ramicro_toolbar.dll, “ra e IE Toolbar Engine” by RA-MICRO Software GmbH has been detected as a potentially unwanted program by 11 anti-malware scanners. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘RAToolbar’.
Publisher:
Jurasoft AG  (signed by RA-MICRO Software GmbH)

Product:
ra e IE Toolbar

Description:
ra e IE Toolbar Engine

Version:
4, 0, 0, 6

MD5:
22ad958b20549d3295d53b4df0464b2c

SHA-1:
3dd0603e7b20a55effb1ed28824b03099ad3e727

SHA-256:
624f8dc9eee9b3a430ca0cbdee17ec4e27c3264ce7fd310d2d97a564449af39d

Scanner detections:
11 / 68

Status:
Potentially unwanted

Analysis date:
4/24/2024 12:30:41 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Adware.Mostofate
7.1.1

Clam AntiVirus
Win.Adware.Mostofate-65
0.98/21511

Comodo Security
ApplicUnwnt
21366

Dr.Web
Adware.Softomate.494
9.0.1.0169

ESET NOD32
Win32/Adware.Softomate.AF (variant)
10.11300

Fortinet FortiGate
Riskware/Softomate
6/17/2016

McAfee
Artemis!22AD958B2054
5600.6365

Sophos
Generic PUA DN
4.98

Vba32 AntiVirus
Trojan.BHORA.01529
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
38314

Zillya! Antivirus
Adware.Mostofate.Win32.236
2.0.0.2093

File size:
914.3 KB (936,216 bytes)

Product version:
4.0.0.0

Copyright:
(c) Jurasoft. All rights reserved.

Original file name:
ramicro_toolbar.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\ra-micro\ratoolbar\ramicro_toolbar.dll

Digital Signature
Authority:
TC TrustCenter GmbH

Valid from:
1/19/2012 2:07:40 PM

Valid to:
1/19/2015 2:07:40 PM

Subject:
CN=RA-MICRO Software GmbH, OU=TC Publisher ID for Authenticode, OU=Produktion, O=RA-MICRO Software GmbH, L=Berlin, S=Berlin, C=DE

Issuer:
CN=TC TrustCenter Class 2 L1 CA XII, OU=TC TrustCenter Class 2 L1 CA, O=TC TrustCenter GmbH, C=DE

Serial number:
00EE63000100023FF20175E0F4CDC3

File PE Metadata
Compilation timestamp:
9/8/2011 8:12:31 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
12288:arDrlBsIrbTySzQp0WpGBOkh2+jNEg2Nnn0eDUBjjvFbnruhbVR5EobWD09CV60c:qnkIHzRlBOASUBxnruFZbWQ926Rn1

Entry address:
0x95AB7

Entry point:
6A, 0C, 68, 68, AC, 0B, 10, E8, 4D, 01, 00, 00, 33, C0, 40, 89, 45, E4, 8B, 75, 0C, 33, FF, 3B, F7, 75, 0C, 39, 3D, DC, 2F, 0D, 10, 0F, 84, B3, 00, 00, 00, 89, 7D, FC, 3B, F0, 74, 05, 83, FE, 02, 75, 31, A1, 9C, 48, 0D, 10, 3B, C7, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D0, 89, 45, E4, 39, 7D, E4, 0F, 84, 85, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 22, FE, FF, FF, 89, 45, E4, 3B, C7, 74, 72, 8B, 5D, 10, 53, 56, FF, 75, 08, E8, 38, 01, FD, FF, 89, 45, E4, 83, FE, 01, 75, 0E, 3B, C7, 75, 0A, 53, 57, FF...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
668 KB (684,032 bytes)

Internet Explorer BHO
Display name:
RAToolbar

CLSID:
{EF8E1F96-FF80-4E85-AD4F-0F19166E21DB}

CLSID name:
ra e Toolbar Class


Remove ramicro_toolbar.dll - Powered by Reason Core Security