vntsrv.dll

Virtual New Tab

APN LLC.

This installer is part of the Ask.com (APN) network which will install the Ask.com branded toolbar or browser extension which will take control of the web browser's search functions. The module vntsrv.dll, “Virtual New Tab Server” has been detected as adware by 41 anti-malware scanners. The program is a setup application that uses the APN Stub installer, however the file is not signed with an authenticode signature from a trusted source. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
Publisher:
APN LLC.

Product:
Virtual New Tab

Description:
Virtual New Tab Server

Version:
10.0.0.1064

MD5:
4f857c2abe37eb72b146bd24334bd27a

SHA-1:
f57b084f6d3435ca99d8541e4afe24baadfa1df9

SHA-256:
8c15d1329a9090112efbe56c00adc7ff0b36c640a3d8681e74e6c3da14d8fc3b

Scanner detections:
41 / 68

Status:
Adware

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/26/2024 10:34:20 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Ramnit.N
6439068

Agnitum Outpost
Win32.Nimnul.Gen.2
7.1.1

AhnLab V3 Security
Win32/Ramnit.F
2015.01.26

Avira AntiVirus
W32/Ramnit.C
7.11.205.14

avast!
Win32:RmnDrp
150102-1

AVG
Win32/Zbot.G
2014.0.4253

Baidu Antivirus
Virus.Win32.Nimnul.$a
4.0.3.15125

Bitdefender
Win32.Ramnit.N
1.0.20.125

Bkav FE
W32.Tmgrtext.PE
1.3.0.6379

Clam AntiVirus
W32.Ramnit-1
0.98/19976

Comodo Security
Virus.Win32.Ramnit.K
20841

Dr.Web
Win32.Siggen.7
9.0.1.05190

Emsisoft Anti-Malware
Win32.Ramnit.N
9.0.0.4799

ESET NOD32
Win32/Ramnit.H virus
7.0.302.0

Fortinet FortiGate
W32/Ramnit.C
1/25/2015

F-Prot
W32/Ramnit.D
4.6.5.141

F-Secure
Win32.Ramnit.N
5.13.68

G Data
Win32.Ramnit
15.1.24

IKARUS anti.virus
Virus.Win32.Ramnit
t3scan.1.8.6.0

K7 AntiVirus
Virus
13.192.14746

Kaspersky
Virus.Win32.Nimnul
15.0.0.543

Malwarebytes
Virus.Ramnit
v2015.01.25.02

McAfee
W32/Ramnit.a
5600.6874

Microsoft Security Essentials
Threat.Undefined
1.191.3234.0

MicroWorld eScan
Win32.Ramnit.N
16.0.0.75

NANO AntiVirus
Virus.Win32.Nimnul.bmnup
0.30.0.64812

Norman
Win32.Ramnit.N
03.12.2014 13:20:04

nProtect
Win32.Ramnit.N
15.01.23.01

Panda Antivirus
W32/Cosmu.C
15.01.25.02

Qihoo 360 Security
Virus.Win32.Ramnit.A
1.0.0.1015

Quick Heal
W32.Ramnit.A
1.15.14.00

Reason Heuristics
PUP.APN
15.1.25.13

Rising Antivirus
PE:Win32.Ramnit.i!1075353400
23.00.65.15123

Sophos
Virus 'W32/Ramnit-A'
5.09

Total Defense
Win32/Ramnit.C
37.0.11403

Trend Micro House Call
PE_RAMNIT.DEN
7.2.25

Trend Micro
PE_RAMNIT.DEN
10.465.25

Vba32 AntiVirus
Virus.Win32.Nimnul.b
3.12.26.3

VIPRE Antivirus
Threat.4732184
36666

ViRobot
Win32.Nimnul.A[h]
2014.3.20.0

Zillya! Antivirus
Virus.Nimnul.Win32.2
2.0.0.2045

File size:
155.5 KB (159,228 bytes)

Product version:
10.0.0.1064

Copyright:
(c) APN LLC. All rights reserved.

Original file name:
vntsrv.dll

File type:
Dynamic link library (Win32 DLL)

Installer:
APN Stub

Language:
English (United States)

Common path:
C:\Program Files\askpartnernetwork\toolbar\ff3-sp\source\Program Files\vnt\vntsrv.dll

File PE Metadata
Compilation timestamp:
8/19/2014 5:19:42 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:pn1NUhYBrNJwjdZsEOGfxNXh6H3WjRbCbkqHaqJ8l:pIhY1NyjdSADAXulCwq6qKl

Entry address:
0x1C000

Entry point:
60, E8, 00, 00, 00, 00, 5D, 8B, C5, 81, ED, 1E, A5, 01, 20, 2B, 85, 85, AC, 01, 20, 89, 85, 81, AC, 01, 20, B0, 00, 86, 85, B6, AE, 01, 20, 3C, 01, 0F, 85, BC, 01, 00, 00, 83, BD, B1, AD, 01, 20, 00, 74, 33, 83, BD, B5, AD, 01, 20, 00, 74, 2A, 8B, 85, 81, AC, 01, 20, 2B, 85, B1, AD, 01, 20, 8B, 00, 89, 85, EE, AD, 01, 20, 8B, 85, 81, AC, 01, 20, 2B, 85, B5, AD, 01, 20, 8B, 00, 89, 85, F2, AD, 01, 20, EB, 61, 83, BD, B9, AD, 01, 20, 00, 74, 58, 8B, 85, 81, AC, 01, 20, 2B, 85, B9, AD, 01, 20, FF, 30, 8D, 85...
 
[+]

Packer / compiler:
ASPack v1.08.04

Code size:
62 KB (63,488 bytes)

Remove vntsrv.dll - Powered by Reason Core Security