blekkotb_014x.dll

dtx Dynamic Link Library

Visicom Media Inc.

This is part of the Visicom VMN web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The module blekkotb_014x.dll, “dtx Dynamic Link Library” by Visicom Media has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘Blekko Search Bar’.
Publisher:
Visicom Media Inc.  (signed and verified)

Product:
dtx Dynamic Link Library

Description:
dtx Dynamic Link Library

Version:
1, 0, 0, 20

MD5:
bb9a7e6329906080016a7b3a840da8d1

SHA-1:
128916e3317355ac17ba4fc8c586b97fab41cb20

SHA-256:
5e7f8f4c684683305685b853384a688b519dda1d57951670c71e7c9079884e92

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/14/2024 3:00:49 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Visicom (M)
17.1.18.8

File size:
83.3 KB (85,288 bytes)

Product version:
1, 0, 0, 20

Copyright:
Copyright 2010 Visicom Media Inc.

Original file name:
dtx.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\blekkotb_014\blekkotb_014x.dll

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
6/23/2010 7:00:00 PM

Valid to:
6/21/2012 6:59:59 PM

Subject:
CN=Visicom Media Inc., OU=SECURE APPLICATION DEVELOPMENT, O=Visicom Media Inc., L=Brossard, S=Quebec, C=CA

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
73C74D9445094BFD79759F7B9CAFD730

File PE Metadata
Compilation timestamp:
7/15/2010 10:21:46 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

Entry address:
0x4C36

Entry point:
6A, 0C, 68, C0, D5, 00, 10, E8, 6A, 05, 00, 00, 33, C0, 40, 89, 45, E4, 8B, 75, 0C, 33, FF, 3B, F7, 75, 0C, 39, 3D, 98, 0F, 01, 10, 0F, 84, B3, 00, 00, 00, 89, 7D, FC, 3B, F0, 74, 05, 83, FE, 02, 75, 31, A1, CC, 27, 01, 10, 3B, C7, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D0, 89, 45, E4, 39, 7D, E4, 0F, 84, 85, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 22, FE, FF, FF, 89, 45, E4, 3B, C7, 74, 72, 8B, 5D, 10, 53, 56, FF, 75, 08, E8, F9, DB, FF, FF, 89, 45, E4, 83, FE, 01, 75, 0E, 3B, C7, 75, 0A, 53, 57, FF...
 
[+]

Entropy:
5.9303

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
48 KB (49,152 bytes)

Internet Explorer BHO
Display name:
Blekko Search Bar

CLSID:
{e7f726c6-8016-47f5-8a66-e9b4374f0224}


Remove blekkotb_014x.dll - Powered by Reason Core Security