Microsoft.VisualBasic.DLL

Microsoft Visual Studio 2005

VITBIAN TELECOM SL

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The module Microsoft.VisualBasic.DLL, “Visual Basic Runtime Library” by VITBIAN TELECOM SL has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Microsoft Corporation  (signed by VITBIAN TELECOM SL)

Product:
Microsoft® Visual Studio® 2005

Description:
Visual Basic Runtime Library

Version:
8.0.50727.6387 (Win8RTM.050727-6300)

MD5:
c182e4ed5f069332f85a67a6fdc1cade

SHA-1:
223533d011901f6d23c206025947ff1373af9eaa

SHA-256:
ef84d335886d93382c74a76bf121bfe219732b253206d4df9068b00ccbb65a4f

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/23/2024 1:38:25 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.VITBIANTELECOM (M)
16.1.6.7

File size:
649 KB (664,552 bytes)

Product version:
8.0.50727.6387

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
Microsoft.VisualBasic.DLL

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\curetraffic\microsoft.visualbasic.dll

Digital Signature
Authority:
COMODO CA Limited

Valid from:
2/15/2012 1:00:00 AM

Valid to:
2/15/2013 12:59:59 AM

Subject:
CN=VITBIAN TELECOM SL, O=VITBIAN TELECOM SL, STREET=DURANGO 45, L=MADRID, S=MADRID, PostalCode=28023, C=ES

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00CE10339A95EC106E2B411D80D314A159

File PE Metadata
Compilation timestamp:
6/30/2012 7:34:10 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:SdnS23pu41pTTNbE6Wlg1mI5g/9ZasPJAx74yUUUUUUUUUUUUUEuR5KEUEIpM04:SdnS0pfoLlPJAxFKIpM04

Entry address:
0x8E14E

Entry point:
FF, 25, 00, 20, 43, 5E, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
564 KB (577,536 bytes)

Remove Microsoft.VisualBasic.DLL - Powered by Reason Core Security