WTP.dll

Positive Networks PositivePRO VPN

Positive Networks

The library WTP.dll, “PositivePRO WebTop Protocol Client” has been detected as malware by 6 anti-virus scanners.
Publisher:
Positive Networks  (signed and verified)

Product:
Positive Networks PositivePRO VPN

Description:
PositivePRO WebTop Protocol Client

Version:
2, 1, 28, 11

MD5:
e9bb6b1f1c5f7c24be7390e88afd73eb

SHA-1:
9c3feaff0051a2049ecec8dd7ae4937c789a9675

SHA-256:
529b486dc490a935f9157ab59ff0294225780a19b111b6521e97378957265490

Scanner detections:
6 / 68

Status:
Malware

Analysis date:
7/12/2025 7:18:13 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Agent.20292
8.2.4.46

avast!
Win32:Rootkit-gen
2014.9-151116

G Data
Win32:Rootkit-gen
15.11.21

IKARUS anti.virus
Trojan-Dropper.Agent
t3scan.1.1.88.0

McAfee
Generic.dx!tiv
5600.6579

Prevx
Medium Risk Malware
3.0

File size:
2 MB (2,095,904 bytes)

Product version:
2, 1, 28, 11

Copyright:
Copyright © 2007 Positive Networks, Inc. All rights reserved.

Original file name:
WTP.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\windows\downloaded Program Files\wtp.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/13/2007 7:00:00 PM

Valid to:
9/20/2008 6:59:59 PM

Subject:
CN=Positive Networks, OU=Software Development, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Positive Networks, L=Overland Park, S=Kansas, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
52397DFB795037D36DC501C822C90E9D

File PE Metadata
Compilation timestamp:
5/19/2008 11:16:48 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
49152:xaJ2Oyzj8rhV94/jhFlpv99dTzZuKgno5j+:xaJ2Ou+fu/VF3dTzZxgo5j+

Entry address:
0xB74C0

Entry point:
83, 7C, 24, 08, 01, 75, 05, E8, 2A, D5, 00, 00, FF, 74, 24, 04, 8B, 4C, 24, 10, 8B, 54, 24, 0C, E8, ED, FE, FF, FF, 59, C2, 0C, 00, 55, 8B, EC, 83, EC, 18, 53, FF, 75, 0C, 8D, 4D, E8, E8, 9C, D7, FF, FF, 8B, 5D, 08, 81, FB, 00, 01, 00, 00, 73, 54, 8B, 4D, E8, 83, B9, AC, 00, 00, 00, 01, 7E, 14, 8D, 45, E8, 50, 6A, 02, 53, E8, 68, 9F, 00, 00, 8B, 4D, E8, 83, C4, 0C, EB, 0D, 8B, 81, C8, 00, 00, 00, 0F, B6, 04, 58, 83, E0, 02, 85, C0, 74, 0F, 8B, 81, D0, 00, 00, 00, 0F, B6, 04, 18, E9, AB, 00, 00, 00, 80, 7D...
 
[+]

Entropy:
6.7167

Code size:
908 KB (929,792 bytes)

ActiveX Install
Name:
{03CC02A3-6098-4D0E-89D9-71041E7F5F86}


Remove WTP.dll - Powered by Reason Core Security