trolatuntbho.dll

The module trolatuntbho.dll has been detected as a potentially unwanted program by 28 anti-malware scanners. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
MD5:
66fa194ecd1adc2f57e98d63a85632d7

SHA-1:
ea500ccd11e6b782ba6bdbb912548c165266415e

SHA-256:
747995e21c57caf0f942876f16223b3032d53a70c7f6beedc338d850a1a08f83

Scanner detections:
28 / 68

Status:
Potentially unwanted

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/26/2024 2:00:23 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.BHO.Agent.4
922

Agnitum Outpost
PUA.Agent
7.1.1

Avira AntiVirus
APPL/BrowseFox.Gen2
7.11.152.20

AVG
Adware BrowseFox.F
2014.0.3986

Baidu Antivirus
Adware.Win32.Agent
4.0.3.14727

Bitdefender
Gen:Variant.Adware.BHO.Agent.4
1.0.20.1040

Comodo Security
Application.Win32.Altbrowse.AK
18371

Dr.Web
Trojan.Damaged.1
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.BHO.Agent
8.14.07.27.08

ESET NOD32
Win32/BrowseFox (variant)
8.9867

Fortinet FortiGate
Adware/Agent
7/27/2014

F-Secure
Gen:Variant.Adware.BHO.Agent.4
11.2014-27-07_1

G Data
Gen:Variant.Adware.BHO.Agent
14.7.24

IKARUS anti.virus
not-a-virus:AdWare.Win32.Agent
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.176.11663

Kaspersky
not-a-virus:AdWare.Win32.Agent
14.0.0.3496

Malwarebytes
PUP.Optional.Sizlsearch.A
v2014.07.27.08

McAfee
Artemis!CB33CD12C648
5600.7056

MicroWorld eScan
Gen:Variant.Adware.BHO.Agent.4
15.0.0.624

NANO AntiVirus
Riskware.Win32.Agent.cqycvd
0.28.0.59921

Panda Antivirus
Trj/CI.A
14.07.27.08

Reason Heuristics
Threat.Win.Reputation.IMP
14.7.27.20

Sophos
Generic PUA EN
4.98

SUPERAntiSpyware
Adware.BrowseFox/Variant
10457

Trend Micro House Call
TROJ_GEN.F47V0327
7.2.208

Vba32 AntiVirus
AdWare.Agent
3.12.26.0

VIPRE Antivirus
Yontoo
29746

Zillya! Antivirus
Adware.Agent.Win32.9011
2.0.0.1794

File size:
243.8 KB (249,632 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\trolatunt\trolatuntbho.dll

File PE Metadata
Compilation timestamp:
3/12/2014 5:26:55 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
3072:V3zAdVJVbC/hm4w9uRil2D/InlHedRpjP+T1IaIp4fpWay:V3zWK92uknMdHLU1IOBJy

Entry address:
0x12844

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 41, 8D, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, 30, 2D, 03, 10, E8, BD, 01, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, 24, 68, 03, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, 8C, A1, 02, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
159 KB (162,816 bytes)

Remove trolatuntbho.dll - Powered by Reason Core Security