ramicro_toolbar.dll

ra e IE Toolbar

RA-MICRO GmbH & Co. KGaA

The module ramicro_toolbar.dll, “ra e IE Toolbar Engine” by RA-MICRO GmbH & Co. KGaA has been detected as a potentially unwanted program by 3 anti-malware scanners. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘RAToolbar’.
Publisher:
Jurasoft AG  (signed by RA-MICRO GmbH & Co. KGaA)

Product:
ra e IE Toolbar

Description:
ra e IE Toolbar Engine

Version:
4, 0, 0, 6

MD5:
5889ccb8f75e7c154651a7601f61b553

SHA-1:
c082777abe35d93b9b054a3670d2693b5f8e1370

SHA-256:
eb6dba0a169bd917756a63065cb78ae49804fc24e8e783206b25a3d91df20ac6

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 10:38:09 PM UTC  (today)

Scan engine
Detection
Engine version

Clam AntiVirus
Win.Adware.Mostofate-65
0.98/21286

Dr.Web
Adware.Softomate.494
9.0.1.05190

ESET NOD32
Win32/Adware.Softomate.AF application
7.0.302.0

File size:
913.6 KB (935,512 bytes)

Product version:
4.0.0.0

Copyright:
(c) Jurasoft. All rights reserved.

Original file name:
ramicro_toolbar.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\ra-micro\ratoolbar\ramicro_toolbar.dll

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
4/5/2013 10:16:43 AM

Valid to:
4/5/2016 10:16:43 AM

Subject:
CN=RA-MICRO GmbH & Co. KGaA, O=RA-MICRO GmbH & Co. KGaA, L=Berlin, C=DE

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11210B6A8FC260B1FE48FE2A674D2E9943C6

File PE Metadata
Compilation timestamp:
9/8/2011 8:12:31 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
12288:6rDrlBsIrbTySzQp0WpGBOkh2+jNEg2Nnn0eDUBjjvFbnruhbVR5EobWD09CV609:KnkIHzRlBOASUBxnruFZbWQ926RnA

Entry address:
0x95AB7

Entry point:
6A, 0C, 68, 68, AC, 0B, 10, E8, 4D, 01, 00, 00, 33, C0, 40, 89, 45, E4, 8B, 75, 0C, 33, FF, 3B, F7, 75, 0C, 39, 3D, DC, 2F, 0D, 10, 0F, 84, B3, 00, 00, 00, 89, 7D, FC, 3B, F0, 74, 05, 83, FE, 02, 75, 31, A1, 9C, 48, 0D, 10, 3B, C7, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D0, 89, 45, E4, 39, 7D, E4, 0F, 84, 85, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 22, FE, FF, FF, 89, 45, E4, 3B, C7, 74, 72, 8B, 5D, 10, 53, 56, FF, 75, 08, E8, 38, 01, FD, FF, 89, 45, E4, 83, FE, 01, 75, 0E, 3B, C7, 75, 0A, 53, 57, FF...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
668 KB (684,032 bytes)

Internet Explorer BHO
Display name:
RAToolbar

CLSID:
{EF8E1F96-FF80-4E85-AD4F-0F19166E21DB}

CLSID name:
ra e Toolbar Class


Remove ramicro_toolbar.dll - Powered by Reason Core Security