vntsrv.dll

Virtual New Tab

APN LLC.

This installer is part of the Ask.com (APN) network which will install the Ask.com branded toolbar or browser extension which will take control of the web browser's search functions. The module vntsrv.dll, “Virtual New Tab Server” has been detected as adware by 41 anti-malware scanners. The program is a setup application that uses the APN Stub installer, however the file is not signed with an authenticode signature from a trusted source. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
Publisher:
APN LLC.

Product:
Virtual New Tab

Description:
Virtual New Tab Server

Version:
1.2.0.3294

MD5:
3f42eba9f6cf61f0b75218b6900508a7

SHA-1:
b69b09d0636fdc25bbeca097c2173568132677ad

SHA-256:
14d8d41244aa029c0cf4550b602970af190d9807d018a40d44520a81ddd3a2e1

Scanner detections:
41 / 68

Status:
Adware

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/26/2024 10:32:48 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Ramnit.N
1004

Agnitum Outpost
Win32.Nimnul.Gen.2
7.1.1

AhnLab V3 Security
Win32/Ramnit.G
14.05.06

Avira AntiVirus
W32/Ramnit.C
7.11.148.6

avast!
Win32:RmnDrp
2014.9-140506

AVG
Win32/Zbot.F
2015.0.3482

Baidu Antivirus
Virus.Win32.Nimnul.$a
4.0.3.1456

Bitdefender
Win32.Ramnit.N
1.0.20.630

Bkav FE
W32.InjectAdwaredDwnA1.PE
1.3.0.4959

Clam AntiVirus
W32.Ramnit-1
0.98/211

Comodo Security
Virus.Win32.Ramnit.K
18230

Dr.Web
Win32.Rmnet.12
9.0.1.0126

Emsisoft Anti-Malware
Win32.Ramnit.N
8.14.05.06.08

ESET NOD32
Win32/Ramnit
8.9766

Fortinet FortiGate
W32/Ramnit.C
5/6/2014

F-Prot
W32/Ramnit.E
v6.4.7.1.166

F-Secure
Win32.Ramnit.N
11.2014-06-05_3

G Data
Win32.Ramnit
14.5.24

IKARUS anti.virus
Virus.Win32.Ramnit
t3scan.1.6.1.0

K7 AntiVirus
Virus
13.177.11997

Kaspersky
Virus.Win32.Nimnul
14.0.0.3906

Malwarebytes
Virus.Ramnit
v2014.05.06.08

McAfee
W32/Ramnit.a
5600.7138

Microsoft Security Essentials
Virus:Win32/Ramnit.J
1.10502

MicroWorld eScan
Win32.Ramnit.N
15.0.0.378

NANO AntiVirus
Virus.Win32.Nimnul.bqjjnb
0.28.0.59608

Norman
Ramnit.AS
11.20140506

nProtect
Virus/W32.SpyEye
14.05.06.01

Panda Antivirus
W32/Cosmu.E
14.05.06.08

Qihoo 360 Security
Virus.Win32.Ramnit.A
1.0.0.1015

Quick Heal
W32.Ramnit.A
5.14.14.00

Reason Heuristics
PUP.APN.G
14.5.6.18

Rising Antivirus
PE:Win32.Mgr.b!1594784
23.00.65.14504

Sophos
W32/Ramnit-A
4.98

Total Defense
Win32/Ramnit.C
37.0.10921

Trend Micro House Call
PE_RAMNIT.DEN
7.2.126

Trend Micro
PE_RAMNIT.DEN
10.465.06

Vba32 AntiVirus
Virus.Win32.Nimnul.b
3.12.26.0

VIPRE Antivirus
Virus.Win32.Ramnit.b
28936

ViRobot
Win32.Nimnul.A
2011.4.7.4223

Zillya! Antivirus
Virus.Nimnul.Win32.2
2.0.0.1779

File size:
313.5 KB (321,023 bytes)

Product version:
1.2.0.3294

Copyright:
(c) APN LLC. All rights reserved.

Original file name:
vntsrv.dll

File type:
Dynamic link library (Win32 DLL)

Installer:
APN Stub

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\vnt\vntsrv.dll

File PE Metadata
Compilation timestamp:
12/21/2013 3:16:03 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:VkxkFhgRP67uNYzrCu4z95M7bnHg8l+UHWaRMMddAds:KigRP67uNxu4unH/l2aRVdf

Entry address:
0x1C000

Entry point:
60, E8, 00, 00, 00, 00, 5D, 8B, C5, 81, ED, A8, A6, 01, 20, 2B, 85, 0F, AE, 01, 20, 89, 85, 0B, AE, 01, 20, B0, 00, 86, 85, 40, B0, 01, 20, 3C, 01, 0F, 85, BC, 01, 00, 00, 83, BD, 3B, AF, 01, 20, 00, 74, 33, 83, BD, 3F, AF, 01, 20, 00, 74, 2A, 8B, 85, 0B, AE, 01, 20, 2B, 85, 3B, AF, 01, 20, 8B, 00, 89, 85, 78, AF, 01, 20, 8B, 85, 0B, AE, 01, 20, 2B, 85, 3F, AF, 01, 20, 8B, 00, 89, 85, 7C, AF, 01, 20, EB, 61, 83, BD, 43, AF, 01, 20, 00, 74, 58, 8B, 85, 0B, AE, 01, 20, 2B, 85, 43, AF, 01, 20, FF, 30, 8D, 85...
 
[+]

Entropy:
7.0651

Packer / compiler:
ASPack v1.08.04

Code size:
61 KB (62,464 bytes)

Remove vntsrv.dll - Powered by Reason Core Security