Should I block it?

98%
Yes, 98% block recommendation.
Possible reasons:
Multiple malware detections
Performance resource utilization

VersionsAdditional versions

896e6 33.33%
8df44 33.33%
73494 33.33%
(Note, Blabbers Communications Ltd publishes each variation of this file with the same version, but the hashes are unique.)

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
RegSetValueExW, RegCreateKeyExW, RegSetValueExA, RegCreateKeyExA, RegCloseKey, RegDeleteValueW, RegOpenKeyExW, RegQueryValueExW
kernel32.dll
GetStringTypeW, IsValidLocale, EnumSystemLocalesA, GetLocaleInfoA, GetUserDefaultLCID, GetTimeZoneInformation, GetConsoleMode, GetConsoleCP, GetFileType, SetHandleCount, IsProcessorFeaturePresent, IsValidCodePage, FindFirstFileW, FindNextFileW, FindClose, CloseHandle, GetLastError, CreateFileW, GetProcAddress, GetModuleHandleW, GetFileSize, ReadFile, SetEndOfFile, SetFilePointer, WriteFile, MultiByteToWideChar, SizeofResource, LockResource, LoadResource, FindResourceW, FindResourceExW, GetTickCount, GetTempPathA, GetFileAttributesA, SetFileAttributesA, DeleteFileA, DeleteFileW, WideCharToMultiByte, GlobalAlloc, GlobalLock, GlobalUnlock, FreeResource, GlobalFree, GetPrivateProfileStringW, GetFileAttributesW, CreateDirectoryW, GetTempPathW, InterlockedDecrement, CopyFileW, GetVersion, CreateMutexW, ReleaseMutex, GetCommandLineW, FreeEnvironmentStringsW, CreateProcessW, WaitForSingleObject, GetFullPathNameW, GetFullPathNameA, HeapReAlloc, CreateFileA, MapViewOfFile, UnmapViewOfFile, FreeLibrary, HeapAlloc, SystemTimeToFileTime, QueryPerformanceCounter, HeapFree, InterlockedCompareExchange, UnlockFile, LockFile, UnlockFileEx, GetSystemTimeAsFileTime, FormatMessageA, InitializeCriticalSection, LoadLibraryW, Sleep, FormatMessageW, HeapDestroy, LeaveCriticalSection, HeapCreate, HeapValidate, FlushFileBuffers, HeapSize, LockFileEx, EnterCriticalSection, GetDiskFreeSpaceW, LoadLibraryA, CreateFileMappingW, GetDiskFreeSpaceA, GetSystemInfo, RtlUnwind, DeleteCriticalSection, GetVersionExA, GetCurrentProcessId, GetSystemTime, AreFileApisANSI, GetOEMCP, GetACP, GetModuleFileNameW, GetStdHandle, GetCurrentThreadId, SetLastError, TlsFree, TlsSetValue, GetEnvironmentStringsW, WriteConsoleW, SetStdHandle, CompareStringW, SetEnvironmentVariableA, LCMapStringW, GetCPInfo, LocalFree, GetFileAttributesExW, TlsGetValue, TlsAlloc, GetLocaleInfoW, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetCurrentProcess, GetStartupInfoW, HeapSetInformation, GetDateFormatW, GetTimeFormatW, ExitProcess, lstrlenA, InitializeCriticalSectionAndSpinCount, RaiseException, GetProcessHeap, DecodePointer, InterlockedIncrement, InterlockedExchange, EncodePointer, TerminateProcess
ole32.dll
CoUninitialize, CoCreateInstance, OleRun, CoInitializeEx
shell32.dll
CommandLineToArgvW, SHFileOperationW, SHGetFolderPathW
user32.dll
TranslateMessage, PeekMessageW, SetTimer, FindWindowExW, KillTimer, PostMessageW, GetMessageW, DispatchMessageW
version.dll
GetFileVersionInfoW, VerQueryValueW, GetFileVersionInfoSizeW
winhttp.dll
WinHttpOpenRequest, WinHttpOpen, WinHttpConnect, WinHttpSendRequest, WinHttpReceiveResponse, WinHttpQueryDataAvailable, WinHttpReadData, WinHttpCloseHandle
wininet.dll
InternetOpenUrlW, InternetSetOptionW, InternetOpenW, DeleteUrlCacheEntryW, InternetCloseHandle, HttpQueryInfoW, InternetReadFile

tbhcn.exe

By Blabbers Communications Ltd (Signed)

Remove tbhcn.exe
MD5:   8df4449b75c3c6743666844771cc3bea
SHA1:   cf5b3456d35386b4b843dc6c46fc8445e148c00b
SHA256:   ee1f3a5673de6d9d98bb5dd4fb43558b3af4d55a890cffef71048dc51b82a715
Warning 3 antivirus scanners has detected malware.

What is tbhcn.exe?

The Ginyas Browser Companion from Ginyas (Blabbers Communications Ltd Toolbar) installs a web browser extension such as an Internet Explorer Browser Helper Object (BHO) and a toolbar in some cases to view web pages loaded and look for affiliated merchants in order to possibly provide better pricing or alternative deals on a given product or merhcant. Ginyas Browser Companion might also show related coupons in yoru web browser for simular products or merchants when you browse the Internet.

About tbhcn.exe (from Blabbers Communications Ltd)

Ginyas is a free & friendly browser app that helps you save time & money on your online shopping. We'll help you find attractive offers while you browse your favorite stores. Ginyas is a leader in onl

DetailsDetails

File name:tbhcn.exe
Typical file path:C:\users\user\appdata\roaming\ginyasbrowsercompanion\tbhcn.exe
Size:681.69 KB (698,048 bytes)
Certificate
Issued to:Blabbers Communications Ltd
Authority (CA):COMODO CA Limited
Effective date:Monday, February 20, 2012
Expiration date:Thursday, February 20, 2014
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

User start menu folder
Shortcut pointer placed in '%appdata%\Microsoft\Windows\Start Menu'
  • Shortcut to 'tbhcn.exe'

MalwareMalware detections

Based on 40+ industry antivirus scanners, 3 of them detected the following malware.
Antivirus engineEngine versionDetection
Dr.Web 8.13.4.12 Adware.Downware.368
eSafe 7.0.17.0 Win32.Trojan
ESET NOD32 7.8169 a variant of Win32/BrowserCompanion.H

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00142062%
0.028634%
Kernel CPU:0.00142062%
0.013761%
Kernel CPU time:30 ms/min
100,923,805ms/min
Memory
Private memory:1.42 MB
21.59 MB
Private (maximum):264 KB
Private (minimum):200 KB
Non-paged memory:1.42 MB
21.59 MB
Virtual memory:57.82 MB
140.96 MB
Virtual memory (peak):60.82 MB
169.69 MB
Working set:216 KB
18.61 MB
Working set (peak):3.88 MB
37.95 MB
Resource allocations
Threads:2
12
Handles:78
600
GUI GDI count:4
103
GUI GDI peak:4
142
GUI USER count:6
49
GUI USER peak:6
71

BehaviorsProcess properties

Integrety level:High
Platform:32-bit
Command line:"C:\users\user\appdata\roaming\browsercompanion\tbhcn.exe" -interval=10 -iehome=0 -iesearch=0 -ffhome=0 -ffsearch=0 -chhome=0 -chsearch=0 -pubid=ginyas_91 -affid=g91_jul12
Owner:User

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate N 66.67%
Windows 7 Home Premium 33.33%

Distribution by countryDistribution by country

United States installs about 66.67% of tbhcn.exe.
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE