ScriptHost.dll

Add-ons Framework

Lyoness Cashback AG

The module ScriptHost.dll by Lyoness Cashback AG has been detected as adware by 17 anti-malware scanners. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘Lyoness Cashback Bar’.
Publisher:
Lyoness Cashback AG  (signed and verified)

Product:
Add-ons Framework

Description:
ScriptHost

Version:
1.0.12.16

MD5:
73977b6efac7281f8c1f5aaf573335f0

SHA-1:
e8f693f75ca0cd667f2676875d7105f0c8f4fef1

SHA-256:
6e36c1fdf8dc8fb1802898d92b981ad343d6b2295968b340a897093e1c43e349

Scanner detections:
17 / 68

Status:
Adware

Explanation:
Part of the Besttoolbars Add-on framework for Internet Explorer, Chrome and Firefox.

Analysis date:
4/24/2024 4:13:14 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Toolbar.Agent
7.1.1

Baidu Antivirus
PUA.Win32.Besttoolbars
4.0.3.15824

Dr.Web
Adware.BGuard.117
9.0.1.0236

ESET NOD32
Win32/Toolbar.Besttoolbars.J potentially unwanted application
9.7.0.302.0

Fortinet FortiGate
Riskware/Agent
8/24/2015

G Data
Win32.Application.Agent.283RQ5
15.8.25

K7 AntiVirus
Trojan
13.207.16837

Kaspersky
not-a-virus:WebToolbar.Win32.Agent
14.0.0.1534

Malwarebytes
PUP.Optional.BestToolBars.A
v2015.08.24.06

McAfee
Artemis!73977B6EFAC7
5600.6664

NANO AntiVirus
Riskware.Win32.Agent.dsygtj
0.30.24.3079

Qihoo 360 Security
Win32/Virus.WebToolbar.174
1.0.0.1015

Reason Heuristics
PUP.Besttoolbars.LyonessCashbackAG (M)
15.8.24.6

Sophos
Generic PUA OI (PUA)
4.98

Trend Micro
TROJ_GEN.R021C0OFQ15
10.465.24

VIPRE Antivirus
Threat.4796038
33624

Zillya! Antivirus
Adware.Agent.Win32.52906
2.0.0.2345

File size:
431.4 KB (441,776 bytes)

Product version:
0.6.2.2

Copyright:
Besttoolbars Inc. All rights reserved.

Original file name:
ScriptHost.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\lyoness cashback bar\scripthost.dll

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
10/21/2013 6:07:04 PM

Valid to:
10/21/2016 6:07:04 PM

Subject:
E=domainadmin@lyoness.ag, CN=Lyoness Cashback AG, O=Lyoness Cashback AG, L=Graz, S=Styria, C=AT

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121966E6F40865E27DA6418F77DA28077D3

Registration
CLSIDs:
{2A87E8F3-74F4-4832-BB0D-2DDC1E25A889}, {85A0F2AE-E5D7-43A1-AB78-B18437CC31DB}

ProgIDs:
Lyoness Cashback Bar.ScriptHostObject.1, Lyoness Cashback Bar.Tool.1

COM registered:
Yes

File PE Metadata
Compilation timestamp:
12/17/2013 9:58:06 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:8C3uWaUvgQKFo/LaAsXCVxqwvj4dwun3IecUWa0:8ku7viMSWwvj4db3ICW1

Entry address:
0x3E05A

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 62, 6B, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 6A, 0C, 68, A0, FE, 05, 10, E8, A7, 1C, 00, 00, 6A, 0E, E8, 51, 6D, 00, 00, 59, 83, 65, FC, 00, 8B, 75, 08, 8B, 4E, 04, 85, C9, 74, 2F, A1, A0, 5E, 06, 10, BA, 9C, 5E, 06, 10, 89, 45, E4, 85, C0, 74, 11, 39, 08, 75, 2C, 8B, 48, 04, 89, 4A, 04, 50, E8, 5C, DE, FF, FF, 59, FF, 76, 04, E8, 53, DE, FF, FF, 59, 83, 66, 04, 00, C7, 45, FC, FE, FF, FF, FF, E8, 0A, 00, 00, 00...
 
[+]

Code size:
319 KB (326,656 bytes)

Internet Explorer BHO
CLSID:
{2A87E8F3-74F4-4832-BB0D-2DDC1E25A889}

CLSID name:
Lyoness Cashback Bar


Remove ScriptHost.dll - Powered by Reason Core Security