b1toolbar32.dll

Internet Explorer Toolbar

IT Management Group LTD

This is a bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The module b1toolbar32.dll by IT Management Group has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the New IT Desktop Setup installer. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘AliBar BHO’.
Publisher:
ImprovedSearch  (signed by IT Management Group LTD)

Product:
Internet Explorer Toolbar

Description:
Improved Search

Version:
1.0.2.1

MD5:
e4021fbe34d70a458a1cfb1007662c26

SHA-1:
dc52cdea7f526b5d2bc5fa68795b8dadbbc7bf89

SHA-256:
cadbd9319f5254c3255353875a3ce2f173c5410a2b4f4d6b259f186b166aabd8

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
6/17/2024 1:25:29 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.New IT Limited.ITManagementGroup.Bundler (M)
16.2.11.8

File size:
265 KB (271,344 bytes)

Product version:
1.0.2.1

Copyright:
http://search.b1.org

Original file name:
ImprovedSearch.dll

File type:
Dynamic link library (Win32 DLL)

Bundler/Installer:
New IT Desktop Setup

Language:
Language Neutral

Common path:
C:\Program Files\b1 free archiver\toolbar\b1toolbar32.dll

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/17/2012 10:00:00 PM

Valid to:
1/17/2013 9:59:59 PM

Subject:
CN=IT Management Group LTD, O=IT Management Group LTD, STREET=135 Arch. Makarios III Avenue, STREET=Emelle Building 4th floor, L=Limassol, S=Limassol, PostalCode=3021, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
009F750087DD24E5BFA7394C0A178EEAD8

File PE Metadata
Compilation timestamp:
7/24/2012 5:07:19 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:I3Il1ki85sE79aFaqAsSclfq8UAgcY1D0l3O1/nn+eVV/j4ui1FZv:I3IXNSS3O1mwV/duZv

Entry address:
0x14B7F

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 57, 03, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, CC, FE, FF, FF, 59, 5D, C2, 0C, 00, CC, CC, 68, 0C, 47, 01, 10, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, F8, 19, 02, 10, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, 8B, FF...
 
[+]

Code size:
85 KB (87,040 bytes)

Internet Explorer BHO
Display name:
AliBar BHO

CLSID:
{E4E012DC-1925-48E9-8010-2D195574642A}

CLSID name:
Improved search toolbar


Remove b1toolbar32.dll - Powered by Reason Core Security