jcptsdlt.dll

GenTechnologies Apps, LLC

This is part of an adware program designed to inject advertising in the web browser (banners, text-links) as well as modify the normal behavior of the browser as well as modify the computer’s system settings that control applications to run on startup. Part of the Injekt brand of unwanted programs. The module jcptsdlt.dll by GenTechnologies Apps has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
GenTechnologies Apps, LLC  (signed and verified)

MD5:
5dda1cdd36c1641d5418eef57fabb7f5

SHA-1:
3a1aaff0a8bcf2345b5160a41f8cb03bb3acdda4

SHA-256:
9a8b0c0f121cbf4d46f6a37a190931ffebcf665e155231c87b908e86f989a22a

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
12/25/2024 1:20:51 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Injekt (M)
16.9.5.18

File size:
1.3 MB (1,386,864 bytes)

File type:
Dynamic link library (Win64 DLL)

Common path:
C:\ProgramData\hdauhlguqol\dat\jcptsdlt.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/2/2014 9:30:00 AM

Valid to:
5/3/2015 9:29:59 AM

Subject:
CN="GenTechnologies Apps, LLC", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="GenTechnologies Apps, LLC", L=Grandville, S=Michigan, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
169927F400601EBFFB8BCB8CA159DB85

File PE Metadata
Compilation timestamp:
7/30/2014 9:10:08 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:JjdHxLsV4HgXS36oN2vFffiE+Wq50O/sxx8ThCQ:JjdHxLsARnN2vk5NsoThf

Entry address:
0xC6480

Entry point:
48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 57, 48, 83, EC, 20, 49, 8B, F8, 8B, DA, 48, 8B, F1, 83, FA, 01, 75, 05, E8, 73, C5, 00, 00, 4C, 8B, C7, 8B, D3, 48, 8B, CE, 48, 8B, 5C, 24, 30, 48, 8B, 74, 24, 38, 48, 83, C4, 20, 5F, E9, A7, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00, 00, 00, 00, 00, 48, 8B, C1, 49, 83, F8, 08, 72, 53, 0F, B6, D2, 49, B9, 01, 01, 01, 01, 01, 01, 01, 01, 49, 0F, AF, D1, 49, 83, F8, 40, 72, 1E, 48, F7, D9, 83, E1, 07, 74, 06, 4C, 2B, C1, 48, 89, 10, 48, 03...
 
[+]

Code size:
899.5 KB (921,088 bytes)

Remove jcptsdlt.dll - Powered by Reason Core Security