Should I block it?

No, this file is 100% safe to run.

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
RegQueryValueExA, RegOpenKeyExA, RegCloseKey, RegSetValueExA, RegQueryInfoKeyA, RegFlushKey, RegEnumKeyExA, RegCreateKeyExA, OpenProcessToken, LookupPrivilegeValueA, GetLengthSid, AdjustTokenPrivileges, GetKernelObjectSecurity, CryptGetProvParam, CryptImportKey, CryptExportKey, CryptReleaseContext, CryptDestroyKey, CryptGetUserKey, CryptAcquireContextA
comctl32.dll
_TrackMouseEvent, ImageList_SetIconSize, ImageList_GetIconSize, ImageList_Write, ImageList_Read, ImageList_GetDragImage, ImageList_DragShowNolock, ImageList_DragMove, ImageList_DragLeave, ImageList_DragEnter, ImageList_EndDrag, ImageList_BeginDrag, ImageList_Remove, ImageList_DrawEx, ImageList_Draw, ImageList_GetBkColor, ImageList_SetBkColor, ImageList_Add, ImageList_GetImageCount, ImageList_Destroy, ImageList_Create, InitCommonControls
crypt32.dll
CertSetCertificateContextProperty, CertGetCertificateContextProperty, CertOpenStore, CertDuplicateCertificateContext, CertEnumCertificatesInStore, CertDeleteCertificateFromStore, CertFreeCertificateContext, CertAddEncodedCertificateToStore, CertCloseStore, CertFindCertificateInStore, CertOpenSystemStoreA
gdi32.dll
UnrealizeObject, StretchBlt, SetWindowOrgEx, SetWinMetaFileBits, SetViewportOrgEx, SetTextColor, SetStretchBltMode, SetROP2, SetPixel, SetEnhMetaFileBits, SetDIBColorTable, SetBrushOrgEx, SetBkMode, SetBkColor, SelectPalette, SelectObject, SaveDC, RestoreDC, Rectangle, RectVisible, RealizePalette, PlayEnhMetaFile, PatBlt, MoveToEx, MaskBlt, LineTo, IntersectClipRect, GetWindowOrgEx, GetWinMetaFileBits, GetTextMetricsA, GetTextExtentPointA, GetTextExtentPoint32A, GetSystemPaletteEntries, GetStockObject, GetRgnBox, GetPixel, GetPaletteEntries, GetObjectA, GetEnhMetaFilePaletteEntries, GetEnhMetaFileHeader, GetEnhMetaFileBits, GetDeviceCaps, GetDIBits, GetDIBColorTable, GetDCOrgEx, GetCurrentPositionEx, GetClipBox, GetBrushOrgEx, GetBitmapBits, ExtTextOutA, ExcludeClipRect, DeleteObject, DeleteEnhMetaFile, DeleteDC, CreateSolidBrush, CreatePenIndirect, CreatePalette, CreateHalftonePalette, CreateFontIndirectA, CreateDIBitmap, CreateDIBSection, CreateCompatibleDC, CreateCompatibleBitmap, CreateBrushIndirect, CreateBitmap, CopyEnhMetaFileA, BitBlt
kernel32.dll
GetACP, Sleep, VirtualFree, VirtualAlloc, GetTickCount, QueryPerformanceCounter, GetCurrentThreadId, InterlockedDecrement, InterlockedIncrement, VirtualQuery, WideCharToMultiByte, MultiByteToWideChar, lstrlenA, lstrcpynA, LoadLibraryExA, GetThreadLocale, GetStartupInfoA, GetProcAddress, GetModuleHandleA, GetModuleFileNameA, GetLocaleInfoA, GetLastError, GetCommandLineA, FreeLibrary, FindFirstFileA, FindClose, ExitProcess, CreateThread, CompareStringA, WriteFile, UnhandledExceptionFilter, SetFilePointer, SetEndOfFile, RtlUnwind, ReadFile, RaiseException, GetStdHandle, GetFileSize, GetFileType, CreateFileA, CloseHandle, TlsSetValue, TlsGetValue, TlsFree, TlsAlloc, LocalFree, LocalAlloc, lstrlenW, lstrcpyA, lstrcmpA, WaitForSingleObject, UnmapViewOfFile, TerminateThread, TerminateProcess, SizeofResource, SetThreadLocale, SetLastError, SetFileAttributesA, SetEvent, SetErrorMode, ResetEvent, ReleaseSemaphore, QueryDosDeviceA, OutputDebugStringA, OpenProcess, MulDiv, MoveFileA, MapViewOfFile, LockResource, LoadResource, LoadLibraryA, LeaveCriticalSection, IsBadWritePtr, IsBadReadPtr, InitializeCriticalSection, GlobalUnlock, GlobalLock, GlobalFree, GlobalFindAtomA, GlobalDeleteAtom, GlobalAlloc, GlobalAddAtomA, GetWindowsDirectoryA, GetVolumeInformationA, GetVersionExA, GetVersion, GetTimeZoneInformation, GetSystemInfo, GetSystemDirectoryA, GetStringTypeExA, GetModuleHandleW, GetModuleFileNameW, GetLogicalDrives, GetLocalTime, GetFullPathNameA, GetFileAttributesA, GetExitCodeThread, GetDiskFreeSpaceA, GetDateFormatA, GetCurrentThread, GetCurrentProcessId, GetCurrentProcess, GetCPInfo, FreeResource, InterlockedExchange, FormatMessageA, FindResourceA, FindNextFileA, FileTimeToLocalFileTime, FileTimeToDosDateTime, EnumCalendarInfoA, EnterCriticalSection, DuplicateHandle, DeleteFileA, DeleteCriticalSection, CreateSemaphoreA, CreateFileMappingW, CreateFileMappingA, CreateFileW, CreateEventA
ole32.dll
CoTaskMemFree, StringFromCLSID, CoTaskMemAlloc, CoCreateInstance, CoUninitialize, CoInitialize, CoCreateGuid
oleaut32.dll
SysFreeString, SysReAllocStringLen, SysAllocStringLen, SafeArrayPtrOfIndex, SafeArrayGetUBound, SafeArrayGetLBound, SafeArrayCreate, VariantChangeType, VariantCopy, VariantClear, VariantInit, GetErrorInfo
shell32.dll
ShellExecuteA, SHGetSpecialFolderLocation, SHGetPathFromIDListA
user32.dll
GetKeyboardType, DestroyWindow, LoadStringA, MessageBoxA, CharNextA, DllMain
version.dll
VerQueryValueA, GetFileVersionInfoSizeA, GetFileVersionInfoA
Export table
CheckWinsockAndClean
CompareFilenames
CompatibilityCheckEx
FixWinSock
GetFlagNumber
MyDeleteFile
PreparePathSolvePE
RandomName
RandomUniqueName
RASInstalled
SetDebugMode
ShredFile
SolveEnv
SolveEnvMulti
WinSockCorrupted

tools.dll

Spybot - Search & Destroy by Safer Networking Ltd. (Signed)

Remove tools.dll
Version:   2, 1, 6, 8
MD5:   6d7841700ad6c0737f4558a91f1bdb8a
SHA1:   b5d5cb603f346c2e8e7cd6bbbf2a8e4acb8cd555
SHA256:   44cc1cd4980243778f9bb001782c66b8a165c2dbc80d811b15e5331c80176868

Overview

tools.dll is loaded as dynamic link library that runs in the context of a process. It is installed with a couple of know programs including Spybot - Search & Destroy published by Safer-Networking Ltd., Spybot - Search & Destroy 1.4 from Safer-Networking Ltd. and Spybot - Search & Destroy 1.4 by Safer-Networking Ltd.. The file is digitally signed by Safer Networking Ltd. which was issued by the VeriSign certificate authority (CA). This particular version is usually found on Microsoft Windows XP (5.1.2600.131072).

DetailsDetails

File name:tools.dll
Publisher:Safer Networking Limited
Product name:Spybot - Search & Destroy
Description:Bibliothek für Spybot-S&D
Typical file path:C:\Program Files\spybot - search & destroy\tools.dll
File version:2, 1, 6, 8
Product version:1, 6, 0, 0
Size:940.33 KB (962,896 bytes)
Certificate
Issued to:Safer Networking Ltd.
Authority (CA):VeriSign
Effective date:Thursday, March 23, 2006
Expiration date:Wednesday, April 8, 2009
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
Safer-Networking Ltd.
6% remove
Spybot Search & Destroy (S&D) is a spyware and adware removal computer program compatible with Microsoft Windows. It scans the computer hard disk and/or RAM for malicious software. In addition to spyware and adware detection and disinfection, Spybot-S&D can repair the registry, winsock LSPs, ActiveX objects, browser hijackers and BHOs, PUPS, computer cookies, trackerware, heavy duty, homepage hijackers, keyloggers, LSP, tracks, trojans,...

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE