dtuser.exe

IAC Search and Media

This installer is part of the Ask.com (APN) network which will install the Ask.com branded toolbar or browser extension which will take control of the web browser's search functions. The application dtuser.exe by IAC Search and Media has been detected as a potentially unwanted program by 12 anti-malware scanners. The program is a setup application that uses the APN Stub installer. Additionally, the file is typically installed by a number of programs including Search Protect by Conduit Ltd. and Movies Toolbar for Internet Explorer (Dist. by Torch Media, Inc.) by IAC Search and Media, both potentially unwanted software.
Publisher:
IAC Search and Media  (signed and verified)

Description:
DtUser

Version:
1, 0, 0, 102

MD5:
541d52441b96386fd1928fc8e831820a

SHA-1:
ddcd6f1275b9c4c760faa8c9c9b8ff117d29eb26

SHA-256:
7ea7a4a1f8d57c958cba0d6355204ff5a5a1918628c8e99db804f456c455b466

Scanner detections:
12 / 68

Status:
Potentially unwanted

Explanation:
The setup program may install a variant of the Visicom Toolbar, a web browser extension that may modify the browser's home and search pages.

Analysis date:
4/23/2024 8:39:03 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win32/Kashu.E
2014.07.24

avast!
Win32:Kukacka
2014.9-140929

ESET NOD32
Win32/Toolbar.Visicom (variant)
8.9241

K7 AntiVirus
Virus
13.181.12819

Microsoft Security Essentials
Threat.Undefined
1.179.842.0

Norman
Sality.ZHB
11.20140929

Qihoo 360 Security
Malware.QVM19.Gen
1.0.0.1015

Reason Heuristics
PUP.IACSearchandMedia.G
14.8.8.0

Rising Antivirus
PE:Win32.KUKU.kj!1522176
23.00.65.14927

Trend Micro House Call
PE_SALITY.RL
7.2.272

Trend Micro
PE_SALITY.RL
10.465.29

VIPRE Antivirus
Threat.4721115
31208

File size:
496 KB (507,856 bytes)

Product version:
1, 0, 0, 102

Copyright:
© 2010-2013 IAC Search and Media

File type:
Executable application (Win32 EXE)

Installer:
APN Stub

Language:
English (United States)

Common path:
C:\Program Files\music toolbar\datamngr\srtool~1\ie\dtuser.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/10/2012 8:00:00 PM

Valid to:
10/20/2015 8:59:59 PM

Subject:
CN=IAC Search and Media, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=IAC Search and Media, L=Oakland, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3444D7AA32B4D542D3C80027404D5CD6

File PE Metadata
Compilation timestamp:
11/15/2013 6:58:29 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:NWAsEa60NGXSF3ZK2OqTebzA7SQF/nIJTS4jTrwtZl:NWAsEL0eSFQZvVQZnIJTSYTrwnl

Entry address:
0x1D47D

Entry point:
E8, 17, 86, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 5D, E9, 8B, 07, 00, 00, 8B, FF, 55, 8B, EC, FF, 75, 08, 51, E8, FF, 86, 00, 00, 59, 59, 5D, C2, 04, 00, 8B, FF, 51, C7, 01, C8, 97, 45, 00, E8, 7B, 86, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 56, 8B, F1, E8, E3, FF, FF, FF, F6, 45, 08, 01, 74, 07, 56, E8, B8, FF, FF, FF, 59, 8B, C6, 5E, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, FF, 75, 08, 51, E8, 52, 88, 00, 00, 59, 59, 5D, C2, 04, 00, 8B, FF, 51, E8, A1, 87, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 8B, 45, 08...
 
[+]

Code size:
306.5 KB (313,856 bytes)

Windows Firewall Allowed Program
Name:
C:\Archivos de programa\Music Toolbar\Datamngr\SRTOOL~1\IE\dtuser.exe


The file dtuser.exe has been discovered within the following programs.

Extended Update  by Hoolapp
Extended Update is a potentially unwanted application that is triggered to run daily by bypassing Windows User Account Control (UAC).
79% remove it
Movies Toolbar (by Bandoo Media, Inc.) is an Ask.com Partner Network Toolbar which is an is an ad-supported (users may see additional banner and in-text link advertisements) web browser plugin distributed through various monetization platforms during installation.
84% remove it
Movies Toolbar for Internet Explorer is an Ask.com Partner Network Toolbar which is an is an ad-supported (users may see additional banner and in-text link advertisements) web browser plugin distributed through various monetization platforms during installation.
69% remove it
This is a potentially unwanted web browser extension that is designed to deliver search modification as well as contextual advertising. The program does this by modifying the user's home and search page in order to monetize a user's search activities.
apn.ask.com
87% remove it
From the EULA: "The Toolbar interacts with your computer by: Displaying advertisements, including without limitation by inserting into web pages or displaying over parts of such web pages advertisements, banners or coupons that would not otherwise appear; Converting words on pages you view into hyperlinks that are linked to advertisements; Communicating with our servers to check for new offers, the placement of offers, the date and time you install and uninstall the Toolbar, and whether an updated version of the Toolbar is available; Monitoring and recording the domain name of each page you view, the advertisements that appear on these pages, and the advertisements that you click.
80% remove it
Search Protect  by Conduit Ltd.
From the Terms of Service: "Search Protect is a separate piece of software installed on your hard-drive in connection with your installation of a Toolbar. It is designed to protect your Search settings from takeover by third parties.
84% remove it
 
Powered by Should I Remove It?

Remove dtuser.exe - Powered by Reason Core Security