ramicro_toolbar.dll

ra e IE Toolbar

RA-MICRO Software GmbH

The module ramicro_toolbar.dll, “ra e IE Toolbar Engine” by RA-MICRO Software GmbH has been detected as a potentially unwanted program by 7 anti-malware scanners. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘RAToolbar’.
Publisher:
Jurasoft AG  (signed by RA-MICRO Software GmbH)

Product:
ra e IE Toolbar

Description:
ra e IE Toolbar Engine

Version:
4, 0, 0, 6

MD5:
e29c7b596f66b5a57e8039ee25bb796a

SHA-1:
8c38972a0ceb9791cedf8ca65cab6e56b4f8689d

SHA-256:
6f1e9274932b151cacc76b8bb16892684b843032cd8a5224a620ee7aed542d4c

Scanner detections:
7 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 7:12:26 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Adware.Mostofate
7.1.1

Comodo Security
ApplicUnwnt
17620

Dr.Web
Adware.Softomate.494
9.0.1.0220

ESET NOD32
Win32/Adware.Softomate.AF (variant)
9.9296

Fortinet FortiGate
Adware/Mostofate
8/8/2015

Vba32 AntiVirus
Trojan.BHORA.01529
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic
25464

File size:
914.3 KB (936,216 bytes)

Product version:
4.0.0.0

Copyright:
(c) Jurasoft. All rights reserved.

Original file name:
ramicro_toolbar.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\ra-micro\ratoolbar\ramicro_toolbar.dll

Digital Signature
Authority:
TC TrustCenter GmbH

Valid from:
1/19/2012 2:07:40 PM

Valid to:
1/19/2015 2:07:40 PM

Subject:
CN=RA-MICRO Software GmbH, OU=TC Publisher ID for Authenticode, OU=Produktion, O=RA-MICRO Software GmbH, L=Berlin, S=Berlin, C=DE

Issuer:
CN=TC TrustCenter Class 2 L1 CA XII, OU=TC TrustCenter Class 2 L1 CA, O=TC TrustCenter GmbH, C=DE

Serial number:
00EE63000100023FF20175E0F4CDC3

Registration
CLSID:
{EF8E1F96-FF80-4E85-AD4F-0F19166E21DB}

ProgID:
Toolbar4.RAToolbar.1

COM registered:
Yes

File PE Metadata
Compilation timestamp:
9/8/2011 8:12:31 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
12288:3rDrlBsIrbTySzQp0WpGBOkh2+jNEg2Nnn0eDUBjjvFbnruhbVR5EobWD09CV60y:bnkIHzRlBOASUBxnruFZbWQ926RnD

Entry address:
0x95AB7

Entry point:
6A, 0C, 68, 68, AC, 0B, 10, E8, 4D, 01, 00, 00, 33, C0, 40, 89, 45, E4, 8B, 75, 0C, 33, FF, 3B, F7, 75, 0C, 39, 3D, DC, 2F, 0D, 10, 0F, 84, B3, 00, 00, 00, 89, 7D, FC, 3B, F0, 74, 05, 83, FE, 02, 75, 31, A1, 9C, 48, 0D, 10, 3B, C7, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D0, 89, 45, E4, 39, 7D, E4, 0F, 84, 85, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 22, FE, FF, FF, 89, 45, E4, 3B, C7, 74, 72, 8B, 5D, 10, 53, 56, FF, 75, 08, E8, 38, 01, FD, FF, 89, 45, E4, 83, FE, 01, 75, 0E, 3B, C7, 75, 0A, 53, 57, FF...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
668 KB (684,032 bytes)

Internet Explorer BHO
Display name:
RAToolbar

CLSID:
{EF8E1F96-FF80-4E85-AD4F-0F19166E21DB}

CLSID name:
ra e Toolbar Class


Remove ramicro_toolbar.dll - Powered by Reason Core Security