vntsrv.dll

Virtual New Tab

APN LLC.

This installer is part of the Ask.com (APN) network which will install the Ask.com branded toolbar or browser extension which will take control of the web browser's search functions. The module vntsrv.dll, “Virtual New Tab Server” has been detected as adware by 40 anti-malware scanners. The program is a setup application that uses the APN Stub installer, however the file is not signed with an authenticode signature from a trusted source. According to the AV engines that detect this, it is a detection for a file infected by members of the Win32/Ramnit malware family and may drop and load other malware.
Publisher:
APN LLC.

Product:
Virtual New Tab

Description:
Virtual New Tab Server

Version:
10.0.0.1064

MD5:
03d32957ff25406d3123692ace0d470e

SHA-1:
3e8a16d049d9f91a43b11b928c62279f5c2ccf0a

SHA-256:
2892a71c77bf7a238fa011bba564d28b7d87719c9be0fcf473331f2b6c04522b

Scanner detections:
40 / 68

Status:
Adware

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/26/2024 8:59:53 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Ramnit.N
6516214

Agnitum Outpost
Win32.Nimnul.Gen.2
7.1.1

AhnLab V3 Security
Win32/Ramnit.G
2015.03.16

Avira AntiVirus
W32/Ramnit.C
7.11.30.172

avast!
Win32:RmnDrp
150303-0

AVG
SHeur4
2016.0.3169

Baidu Antivirus
Virus.Win32.Nimnul.$a
4.0.3.15316

Bitdefender
Win32.Ramnit.N
1.0.20.375

Bkav FE
W32.InjectAdwaredDwnA1.PE
1.3.0.6379

Clam AntiVirus
W32.Ramnit-1
0.98/20195

Comodo Security
Virus.Win32.Ramnit.K
21428

Dr.Web
Win32.Rmnet.12
9.0.1.05190

Emsisoft Anti-Malware
Win32.Ramnit.N
9.0.0.4799

ESET NOD32
Win32/Ramnit.H virus
7.0.302.0

Fortinet FortiGate
W32/Ramnit.C
3/16/2015

F-Prot
W32/Ramnit.E
4.6.5.141

F-Secure
Win32.Ramnit.N
5.13.68

G Data
Win32.Ramnit
15.3.25

IKARUS anti.virus
Virus.Win32.Ramnit
t3scan.1.8.6.0

K7 AntiVirus
Virus
13.200.15264

Kaspersky
Virus.Win32.Nimnul
15.0.0.543

Malwarebytes
Virus.Ramnit
v2015.03.16.04

McAfee
Virus.W32/Ramnit.a
16.8.708.2

Microsoft Security Essentials
Threat.Undefined
1.193.2698.0

MicroWorld eScan
Win32.Ramnit.N
16.0.0.225

NANO AntiVirus
Virus.Win32.Nimnul.bqjjnb
0.30.0.296

Norman
Win32.Ramnit.N
03.12.2014 13:20:04

nProtect
Virus/W32.SpyEye
15.03.13.01

Panda Antivirus
W32/Cosmu.E
15.03.16.04

Quick Heal
W32.Ramnit.A
3.15.14.00

Reason Heuristics
PUP.Installer.Ask
15.3.16.3

Rising Antivirus
PE:Win32.Mgr.b!1594784
23.00.65.15314

Sophos
Virus 'W32/Ramnit-A'
5.12

Total Defense
Win32/Ramnit.C
37.0.11497

Trend Micro House Call
PE_RAMNIT.DEN
7.2.75

Trend Micro
PE_RAMNIT.DEN
10.465.16

Vba32 AntiVirus
Virus.Win32.Nimnul.b
3.12.26.3

VIPRE Antivirus
Threat.4732184
37788

ViRobot
Win32.Nimnul.A[h]
2014.3.20.0

Zillya! Antivirus
Virus.Nimnul.Win32.1
2.0.0.2100

File size:
209.5 KB (214,501 bytes)

Product version:
10.0.0.1064

Copyright:
(c) APN LLC. All rights reserved.

Original file name:
vntsrv.dll

File type:
Dynamic link library (Win32 DLL)

Installer:
APN Stub

Language:
English (United States)

Common path:
C:\Program Files\askpartnernetwork\toolbar\clm-sp\source\Program Files\vnt\vntsrv.dll

File PE Metadata
Compilation timestamp:
8/19/2014 12:19:42 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:Cn1NUhYBrNJwjdZsEOGfxNXh6tKMWbefxyVqW8XmtfnheBPwnvkDRM:CIhY1NyjdSADAtobtqW8XmiinvYM

Entry address:
0x1C000

Entry point:
60, E8, 00, 00, 00, 00, 5D, 8B, C5, 81, ED, A8, A6, 01, 20, 2B, 85, 0F, AE, 01, 20, 89, 85, 0B, AE, 01, 20, B0, 00, 86, 85, 40, B0, 01, 20, 3C, 01, 0F, 85, BC, 01, 00, 00, 83, BD, 3B, AF, 01, 20, 00, 74, 33, 83, BD, 3F, AF, 01, 20, 00, 74, 2A, 8B, 85, 0B, AE, 01, 20, 2B, 85, 3B, AF, 01, 20, 8B, 00, 89, 85, 78, AF, 01, 20, 8B, 85, 0B, AE, 01, 20, 2B, 85, 3F, AF, 01, 20, 8B, 00, 89, 85, 7C, AF, 01, 20, EB, 61, 83, BD, 43, AF, 01, 20, 00, 74, 58, 8B, 85, 0B, AE, 01, 20, 2B, 85, 43, AF, 01, 20, FF, 30, 8D, 85...
 
[+]

Entropy:
7.4503

Packer / compiler:
ASPack v1.08.04

Code size:
62 KB (63,488 bytes)

Remove vntsrv.dll - Powered by Reason Core Security