mystartblekkotemplatex.dll

dtx Dynamic Link Library

Visicom Media Inc.

This is part of the Visicom VMN web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The module mystartblekkotemplatex.dll, “dtx Dynamic Link Library” by Visicom Media has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘Vafoon Toolbar’. This file is typically installed with the program Vafoon Toolbar by Visicom Media inc. which is a potentially unwanted software program.
Publisher:
Visicom Media Inc.  (signed and verified)

Product:
dtx Dynamic Link Library

Description:
dtx Dynamic Link Library

Version:
1, 0, 0, 20

MD5:
757c4db5b2d665b468f8c47751bf323d

SHA-1:
3acc3cba0d9fa136858e30beaee0ba70791274a6

SHA-256:
b991d643b02f9bf4909683c56887b86f1dab0d8d57ee73735ffadb08c099de80

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/24/2024 4:37:08 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Visicom.VisicomMedia (M)
16.2.5.23

File size:
83.3 KB (85,288 bytes)

Product version:
1, 0, 0, 20

Copyright:
Copyright 2010 Visicom Media Inc.

Original file name:
dtx.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\vafoontoolbar\mystartblekkotemplatex.dll

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
6/23/2010 5:00:00 PM

Valid to:
6/21/2012 4:59:59 PM

Subject:
CN=Visicom Media Inc., OU=SECURE APPLICATION DEVELOPMENT, O=Visicom Media Inc., L=Brossard, S=Quebec, C=CA

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
73C74D9445094BFD79759F7B9CAFD730

File PE Metadata
Compilation timestamp:
7/15/2010 8:21:46 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
1536:gNznD/GJR0M0DV0X9Umxe2OG8pixJkGCl6klluPNw53DnU2:gdnDVM0I962Ol6klluPNGDnb

Entry address:
0x4C36

Entry point:
6A, 0C, 68, C0, D5, 00, 10, E8, 6A, 05, 00, 00, 33, C0, 40, 89, 45, E4, 8B, 75, 0C, 33, FF, 3B, F7, 75, 0C, 39, 3D, 98, 0F, 01, 10, 0F, 84, B3, 00, 00, 00, 89, 7D, FC, 3B, F0, 74, 05, 83, FE, 02, 75, 31, A1, CC, 27, 01, 10, 3B, C7, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D0, 89, 45, E4, 39, 7D, E4, 0F, 84, 85, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 22, FE, FF, FF, 89, 45, E4, 3B, C7, 74, 72, 8B, 5D, 10, 53, 56, FF, 75, 08, E8, F9, DB, FF, FF, 89, 45, E4, 83, FE, 01, 75, 0E, 3B, C7, 75, 0A, 53, 57, FF...
 
[+]

Entropy:
5.9303

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
48 KB (49,152 bytes)

Internet Explorer BHO
Display name:
Vafoon Toolbar

CLSID:
{c65d6942-fe75-4ef5-8fe0-20e8a29ecd20}


The file mystartblekkotemplatex.dll has been discovered within the following program.

Vafoon Toolbar  by Visicom Media inc.
Vafoon Toolbar is a Visicom Media (VMN) toolbar that integrates with major web browsers including Google Chrome, Firefox and Internet Explorer.
software.visicommedia.com
68% remove it
 
Powered by Should I Remove It?

Remove mystartblekkotemplatex.dll - Powered by Reason Core Security