Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

8.2.0.21 5.22%
8.1.0.7 3.48%
7.4.0.18 20.87%
7.4.0.18 7.83%
7.3.0.42 2.61%
7.3.0.42 8.70%
7.3.0.41 4.35%
7.3.0.41 13.04%
7.2.0.11 26.09%
7.2.0.11 7.83%

Relationships


PE structurePE file structure

Show functions
Import table
comctl32.dll
CreatePropertySheetPageW, ImageList_ReplaceIcon, ImageList_Create, InitCommonControlsEx
gdi32.dll
DeleteObject
gdiplus.dll
GdiplusShutdown, GdipAlloc, GdipDeleteGraphics, GdipDisposeImage, GdipCreateBitmapFromScan0, GdipCreateBitmapFromHICON, GdipCreateHBITMAPFromBitmap, GdipGetImageGraphicsContext, GdipDrawImageRectI, GdipCloneImage, GdipFree, GdiplusStartup
kernel32.dll
TerminateProcess, DecodePointer, EncodePointer, InterlockedPopEntrySList, VirtualAlloc, VirtualFree, InterlockedExchange, RaiseException, EnterCriticalSection, LeaveCriticalSection, GetLastError, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, SizeofResource, LockResource, LoadResource, FindResourceW, FindResourceExW, GetProcAddress, GetModuleHandleW, lstrlenW, GetModuleFileNameW, FreeLibrary, CloseHandle, ReadFile, GetFileSize, CreateFileW, InterlockedIncrement, InterlockedDecrement, SetThreadLocale, GetThreadLocale, LoadLibraryExW, GetFileTime, GetFileAttributesW, GetDriveTypeW, CompareFileTime, lstrcmpiW, MultiByteToWideChar, GlobalUnlock, GlobalLock, OutputDebugStringW, GetCurrentProcessId, UnhandledExceptionFilter, WideCharToMultiByte, GetCurrentProcess, LocalFree, FormatMessageW, SetLastError, OpenProcess, QueryDosDeviceW, LocalAlloc, GetLocaleInfoW, GetUserDefaultLCID, GetNumberFormatW, GetTimeFormatW, GetDateFormatW, FileTimeToSystemTime, SystemTimeToTzSpecificLocalTime, GetFileSizeEx, FindNextFileW, DeviceIoControl, FindClose, FindFirstFileW, GetShortPathNameW, SetFileAttributesW, SetFileTime, DeleteFileW, GetPrivateProfileStringW, GetDiskFreeSpaceExW, WriteFile, GetVolumeInformationW, Sleep, LocalFileTimeToFileTime, SystemTimeToFileTime, FlushInstructionCache, SetUnhandledExceptionFilter, IsDebuggerPresent, QueryPerformanceCounter, GetTickCount, GetSystemTimeAsFileTime, LoadLibraryA, HeapDestroy, HeapAlloc, HeapFree, HeapReAlloc, HeapSize, GetProcessHeap, InterlockedCompareExchange, InterlockedPushEntrySList, IsProcessorFeaturePresent, GetCurrentThreadId
msvcp100.dll
DllMain
msvcr100.dll
DllMain
ole32.dll
StringFromGUID2, CoCreateInstance, CoTaskMemAlloc, CoTaskMemRealloc, CoTaskMemFree, ReleaseStgMedium, IIDFromString, StringFromIID, CLSIDFromString
psapi.dll
EnumProcessModules, GetModuleBaseNameW, EnumProcesses
user32.dll
SetDlgItemTextW, SetWindowLongW, GetSystemMetrics, LoadIconW, SendMessageW, wsprintfW, GetActiveWindow, AllowSetForegroundWindow, SetMenuDefaultItem, AppendMenuW, GetDlgItem, InsertMenuW, InsertMenuItemW, GetForegroundWindow, DestroyIcon, LoadImageW, GetMenuItemCount, GetMenuStringW, GetSubMenu, DrawIconEx, MessageBoxW, CharNextW, GetParent, CreatePopupMenu, UnregisterClassA
Export table
DllCanUnloadNow
DllGetClassObject
DllRegisterServer
DllUnregisterServer

BUShell.dll

Backup by Symantec Corporation (Signed)

Remove BUShell.dll
Version:   7.3.0.42
MD5:   d526b6964eb436530f14982b86151f17
SHA1:   83de033195af36736d95e762a2c4ac9c7927cb7b
SHA256:   bcea6b785a15441e266eea5fa539515fbba26899ff87add264d9a897bf9852d0

What is BUShell.dll?

Backup Shell is part of Norton Internet Security, a PC program that provides malware prevention and removal during subscription period and uses signatures and heuristics to identify viruses, trojans and other malware. Norton Internet Security features include a email spam filtering, personal firewall, and phishing protection.

Overview

bushell.dll is loaded as dynamic link library that runs in the context of a process. The assembly utilizes the .NET run-time framework (which is required to be installed on the PC). The file is digitally signed by Symantec Corporation which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:bushell.dll
Publisher:Symantec Corporation
Product name:Backup
Description:Backup Shell
Typical file path:C:\Program Files\norton 360\engine64\20.2.0.19\bushell.dll
File version:7.3.0.42
Product version:7.3
Size:2.53 MB (2,656,592 bytes)
Certificate
Issued to:Symantec Corporation
Authority (CA):VeriSign
Effective date:Tuesday, September 7, 2010
Expiration date:Saturday, November 23, 2013
Digital DNA
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details

BehaviorsBehaviors

Context menu handler
Located in '*\shellex\ContextMenuHandlers'
  • Name: 'BUContextMenu'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 43.48%
Windows Vista Home Premium 9.57%
Windows 8 Pro 8.70%
Windows 8 6.96%
Microsoft Windows XP 6.09%
Windows 7 Ultimate 5.22%
Windows 8 Pro with Media Center 5.22%
Windows 7 Professional 4.35%
Windows 8.1 3.48%
Windows 8 Enterprise 2.61%
Windows 8.1 Pro 1.74%
Windows Vista Business 0.87%
Windows 7 Home Basic 0.87%
Windows 7 Starter 0.87%

Distribution by countryDistribution by country

United States installs about 78.07% of Backup.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Hewlett-Packard 28.23%
Dell 19.35%
Toshiba 16.13%
Acer 14.52%
ASUS 6.45%
Sony 4.84%
GIGABYTE 4.03%
MSI 1.61%
Intel 1.61%
Lenovo 1.61%
Samsung 0.81%
American Megatrends 0.81%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE