dllogic.exe

ClientConnect LTD

This application is part of the Conduit Toolbar platform (Community Toolbar) and is used to install and maintain its web browser extensions. These Toolbars are typiclaly bundled on a user's PC through various thrird party installations. The application dllogic.exe by ClientConnect has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is also typically executed from the user's temporary directory.
Publisher:
Conduit  (signed by ClientConnect LTD)

Version:
1.0.0.1

MD5:
3d06c481f5cd81171f8ba81d3fcaf6bb

SHA-1:
1a6133cb3450ba4184672b9ef8cbb96a4a3ef169

SHA-256:
267235f0ac868dff6c2584bed8bb7f9c1ae13aaed68b30881f3316ab804ab184

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Part of the Conduit/ClientConnect toolbar/extension distribution.

Analysis date:
11/5/2024 1:37:16 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Conduit (M)
16.11.29.1

File size:
1.9 MB (1,992,838 bytes)

Copyright:
Conduit Ltd.

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\dllogic.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/4/2014 1:00:00 AM

Valid to:
2/6/2016 12:59:59 AM

Subject:
CN=ClientConnect LTD, OU=Digital ID Class 3 - Microsoft Software Validation v2, OU=Prod3, O=ClientConnect LTD, L=Ness Ziona, S=Israel, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1DE981E6776F551E66C8506523102501

File PE Metadata
Compilation timestamp:
3/5/2012 9:37:55 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:3gm/4fStbTChxKCnFnQXBbrtgb/iQvu0UHOLe:wm/wSt6hxvWbrtUTrUHOq

Entry address:
0x167F

Entry point:
55, 8B, EC, 6A, FF, 68, F8, 20, 40, 00, 68, 30, 18, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, 5F, 57, FF, 15, D4, 20, 40, 00, 59, 83, 0D, 90, 30, 40, 00, FF, 83, 0D, 94, 30, 40, 00, FF, FF, 15, D0, 20, 40, 00, 8B, 0D, 8C, 30, 40, 00, 89, 08, FF, 15, CC, 20, 40, 00, 8B, 0D, 88, 30, 40, 00, 89, 08, A1, C8, 20, 40, 00, 8B, 00, A3, 98, 30, 40, 00, E8, 35, 01, 00, 00, 39, 1D, 70, 30, 40, 00, 75, 0C, 68, 22, 18, 40, 00, FF, 15...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
2.5 KB (2,560 bytes)

Remove dllogic.exe - Powered by Reason Core Security