searchresultstb.dll

DTX Toolbar

IAC Search and Media

This is a component of the Ask.com toolbar, a browser extension that will modify the default web browser's search provider, home page and various other settings. The module searchresultstb.dll, “DTX kernel Module” by IAC Search and Media has been detected as a potentially unwanted program by 2 anti-malware scanners. Additionally, the file is typically installed by a number of programs including Search Protect by Conduit Ltd. and Movies Toolbar for Internet Explorer (Dist. by Bandoo Media, Inc.) by APN LLC, both potentially unwanted software.
Publisher:
IAC Search and Media  (signed and verified)

Product:
DTX Toolbar

Description:
DTX kernel Module

Version:
5, 0, 8, 266

MD5:
fe6b5a67543c47a3ccbc41c459e850fb

SHA-1:
1ab1729a3f5bfd236de138d12b8e0f3ffa78c2a6

SHA-256:
7dade1b360cc0177db10479b7eb1d76e3b6d2739177473f3b6f4a1c960da9703

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 4:52:44 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Toolbar.Visicom (variant)
8.9241

Reason Heuristics
PUP.Toolbar.IACSearchandMedia.P
14.8.8.0

File size:
534 KB (546,768 bytes)

Product version:
5, 0, 8, 266

Copyright:
Copyright 2013 IAC Search and Media

Original file name:
dtBand.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\movies toolbar\datamngr\srtool~2\ie\searchresultstb.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/10/2012 5:00:00 PM

Valid to:
10/20/2015 4:59:59 PM

Subject:
CN=IAC Search and Media, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=IAC Search and Media, L=Oakland, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3444D7AA32B4D542D3C80027404D5CD6

File PE Metadata
Compilation timestamp:
11/15/2013 1:16:22 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:7NARNzTpdIMQLw5Ys7s5FoaEVt68eHqYG9ASY6QKbOo:szlX2gyea4KHqYILY6QKao

Entry address:
0x455E3

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 9C, B6, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 6A, 0C, 68, 60, 49, 07, 10, E8, EA, BB, FF, FF, 6A, 0E, E8, 5C, 23, 00, 00, 59, 83, 65, FC, 00, 8B, 75, 08, 8B, 4E, 04, 85, C9, 74, 2F, A1, 68, C4, 07, 10, BA, 64, C4, 07, 10, 89, 45, E4, 85, C0, 74, 11, 39, 08, 75, 2C, 8B, 48, 04, 89, 4A, 04, 50, E8, 28, B8, FF, FF, 59, FF, 76, 04, E8, 1F, B8, FF, FF, 59, 83, 66, 04, 00, C7, 45, FC, FE, FF, FF, FF, E8, 0A, 00, 00, 00...
 
[+]

Entropy:
6.5707

Code size:
378 KB (387,072 bytes)

The file searchresultstb.dll has been discovered within the following programs.

Extended Update  by Hoolapp
Extended Update is a potentially unwanted application that is triggered to run daily by bypassing Windows User Account Control (UAC).
79% remove it
Movies Toolbar (by Bandoo Media, Inc.) is an Ask.com Partner Network Toolbar which is an is an ad-supported (users may see additional banner and in-text link advertisements) web browser plugin distributed through various monetization platforms during installation.
84% remove it
Movies Toolbar for Internet Explorer is an Ask.com Partner Network Toolbar which is an is an ad-supported (users may see additional banner and in-text link advertisements) web browser plugin distributed through various monetization platforms during installation.
69% remove it
This is a potentially unwanted web browser extension that is designed to deliver search modification as well as contextual advertising. The program does this by modifying the user's home and search page in order to monetize a user's search activities.
apn.ask.com
87% remove it
From the EULA: "The Toolbar interacts with your computer by: Displaying advertisements, including without limitation by inserting into web pages or displaying over parts of such web pages advertisements, banners or coupons that would not otherwise appear; Converting words on pages you view into hyperlinks that are linked to advertisements; Communicating with our servers to check for new offers, the placement of offers, the date and time you install and uninstall the Toolbar, and whether an updated version of the Toolbar is available; Monitoring and recording the domain name of each page you view, the advertisements that appear on these pages, and the advertisements that you click.
80% remove it
Search Protect  by Conduit Ltd.
From the Terms of Service: "Search Protect is a separate piece of software installed on your hard-drive in connection with your installation of a Toolbar. It is designed to protect your Search settings from takeover by third parties.
84% remove it
 
Powered by Should I Remove It?

Remove searchresultstb.dll - Powered by Reason Core Security