ScriptHost.dll

Add-ons Framework

PurpleTech Software Inc

This is the Performersoft setup installer. The module ScriptHost.dll by PurpleTech Software Inc has been detected as adware by 6 anti-malware scanners. The program is a setup application that uses the InstallBrain installer. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘Speed Analysis Plus’. This file is typically installed with the program Speed Analysis Plus by PerformerSoft LLC which is a potentially unwanted software program. The setup program bundles additional offers, mostly adware, using the InstallBrain installer, a pay-per-install monetization download manager. InstallBrain will also install a background updater service that will update any installed browser add-ons and plug-ins.
Publisher:
SpeedAnalysis.com  (signed by PurpleTech Software Inc)

Product:
Add-ons Framework

Description:
ScriptHost

Version:
0.9.5.6

MD5:
a96fd1a371fd75d3775b25d12aed5ce4

SHA-1:
fbdb0416d0af08d6490b4115139087d6f6d68b9a

SHA-256:
70650b85fffac626704016fb7d6c7385abdaa1b832b239e13c059dc2fe5d43d0

Scanner detections:
6 / 68

Status:
Adware

Explanation:
Part of the Besttoolbars Add-on framework for Internet Explorer, Chrome and Firefox.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/26/2024 9:05:10 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Drop.Softomat.AN
7.11.147.26

ESET NOD32
Win32/Toolbar.Besttoolbars (variant)
9.9190

Reason Heuristics
Plugin.Besttoolbars.BHO.Performersoft
15.1.31.7

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
10082

Trend Micro House Call
TROJ_GEN.F47V0702
7.2.31

VIPRE Antivirus
InstallBrain
21738

File size:
373.3 KB (382,272 bytes)

Product version:
1.0.0.3

Copyright:
Besttoolbars Inc. All rights reserved.

Original file name:
ScriptHost.dll

File type:
Dynamic link library (Win32 DLL)

Bundler/Installer:
InstallBrain

Language:
engleski (Sjedinjene Države)

Common path:
C:\Program Files\speed analysis plus\scripthost.dll

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
9/12/2012 4:45:58 AM

Valid to:
9/12/2015 4:45:58 AM

Subject:
CN=PurpleTech Software Inc, O=PurpleTech Software Inc, L=Beaverton, S=OR, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
00C5C4C135A4BC

Registration
CLSIDs:
{8582B176-B96B-4EA3-AD69-8F51C8EB514C}, {FED79EC7-F051-415F-B86E-0C41308A5736}

ProgIDs:
Speed Analysis Plus.ScriptHostObject.1, Speed Analysis Plus.Tool.1

COM registered:
Yes

File PE Metadata
Compilation timestamp:
5/24/2013 11:42:42 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:9woBTY/RRMnJIrk8DRYH20Di3O2u/KT3Qxl8Ao4UrQ9/UcvAENiHHJTDM+w:CETWRRWJck+OHJDAO2u/KT3Qxl8AzAQx

Entry address:
0x34054

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 8E, 6B, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 6A, 08, 68, 10, 27, 05, 10, E8, 8D, 00, 00, 00, E8, 1B, 15, 00, 00, 8B, 40, 78, 85, C0, 74, 16, 83, 65, FC, 00, FF, D0, EB, 07, 33, C0, 40, C3, 8B, 65, E8, C7, 45, FC, FE, FF, FF, FF, E8, 51, 5E, 00, 00, E8, A6, 00, 00, 00, C3, E8, EE, 14, 00, 00, 8B, 40, 7C, 85, C0, 74, 02, FF, D0, E9, B4, FF, FF, FF, 6A, 08, 68, 30, 27, 05, 10, E8, 41, 00, 00, 00, FF, 35, 94, 77, 05...
 
[+]

Code size:
275.5 KB (282,112 bytes)

Internet Explorer BHO
CLSID:
{8582B176-B96B-4EA3-AD69-8F51C8EB514C}

CLSID name:
Speed Analysis Plus


The file ScriptHost.dll has been discovered within the following program.

Speed Analysis Plus  by PerformerSoft LLC
Speed Test Analysis is a 'free' web browser add-in, a BHO for Internet Explorer, that is designed to help analyze your Internet Connection speed.
www.speedanalysis.com
83% remove it
 
Powered by Should I Remove It?

Remove ScriptHost.dll - Powered by Reason Core Security