encyclopediabritannicagamesbar.dll

DTX Toolbar

Visicom Media Inc.

This is part of the Visicom VMN web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The module encyclopediabritannicagamesbar.dll, “DTX kernel Module” by Visicom Media has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program GamesBar from ATT by Visicom Media inc. which is a potentially unwanted software program.
Publisher:
Visicom Media Inc  (signed by Visicom Media Inc.)

Product:
DTX Toolbar

Description:
DTX kernel Module

Version:
5, 0, 8, 238

MD5:
1a922307e9f98f0b2d8d5d75441f0dcf

SHA-1:
75185042c214e4200dcfcc1a86bde3cfcc8bf1e0

SHA-256:
5be4dc643ba99c3f8a9ba9962c4aedd800c7199d6a28de0a2e506586dece2a95

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/18/2024 10:33:16 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Visicom.VisicomMedia.Toolbar (M)
16.2.7.14

File size:
447.3 KB (458,024 bytes)

Product version:
5, 0, 8, 238

Copyright:
Copyright 2011 Visicom Media Inc.

Original file name:
dtBand.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\att_en\encyclopediabritannicagamesbar.dll

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
6/23/2010 7:00:00 PM

Valid to:
6/21/2012 6:59:59 PM

Subject:
CN=Visicom Media Inc., OU=SECURE APPLICATION DEVELOPMENT, O=Visicom Media Inc., L=Brossard, S=Quebec, C=CA

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
73C74D9445094BFD79759F7B9CAFD730

File PE Metadata
Compilation timestamp:
1/19/2012 4:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
12288:JDHuz3qBH5erjmR7Y3w28iFlBa49kf1SR3Wft4q3lWjK4bs5QW:JDHu7qWr6uPFHk9AGlFIKosV

Entry address:
0x3F840

Entry point:
6A, 0C, 68, 28, 6E, 05, 10, E8, D0, C9, FF, FF, 33, C0, 40, 89, 45, E4, 8B, 75, 0C, 33, FF, 3B, F7, 75, 0C, 39, 3D, 00, 5D, 06, 10, 0F, 84, B3, 00, 00, 00, 89, 7D, FC, 3B, F0, 74, 05, 83, FE, 02, 75, 31, A1, 8C, 75, 06, 10, 3B, C7, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D0, 89, 45, E4, 39, 7D, E4, 0F, 84, 85, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 22, FE, FF, FF, 89, 45, E4, 3B, C7, 74, 72, 8B, 5D, 10, 53, 56, FF, 75, 08, E8, B3, 5E, FC, FF, 89, 45, E4, 83, FE, 01, 75, 0E, 3B, C7, 75, 0A, 53, 57, FF...
 
[+]

Entropy:
6.4216

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
320 KB (327,680 bytes)

The file encyclopediabritannicagamesbar.dll has been discovered within the following program.

GamesBar from ATT  by Visicom Media inc.
GamesBar from ATT is a Visicom Media (VMN) toolbar that integrates with major web browsers including Google Chrome, Firefox and Internet Explorer.
www.dynamictoolbar.com
66% remove it
 
Powered by Should I Remove It?

Remove encyclopediabritannicagamesbar.dll - Powered by Reason Core Security