ltvlib.dll

Atom Security OOO

The module ltvlib.dll, “Network Maintenance Service” by Atom Security OOO has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is installed as a Winsock Layered Service Provider (LSP) named “Network Proxy System over [MSAFD Tcpip [TCP/IP]]” as a layered chain entry.
Publisher:
RapidLights, Inc.  (signed by Atom Security OOO)

Description:
Network Maintenance Service

Version:
2.2.4.5

MD5:
0fafeac369642c7940bf010c2614ecb4

SHA-1:
4b6112dbe165c3a510e1dbc77c91193c068b7bc3

SHA-256:
640fb5feae24badacb899b428551cda6cfc9a3ef7cb89d07c7aa2bb063c66967

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/28/2024 4:30:47 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Optional.AtomSecu
17.2.3.10

File size:
333.1 KB (341,072 bytes)

Product version:
2.2.4.5

Copyright:
Copyright (C) 2015 RapidLights, Inc.

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\Windows\System32\ltvlib.dll

Digital Signature
Authority:
COMODO CA Limited

Valid from:
6/4/2015 5:30:00 AM

Valid to:
6/4/2018 5:29:59 AM

Subject:
CN=Atom Security OOO, OU=development, O=Atom Security OOO, STREET="Academician Koptyuga Prospect, 4,office 158", L=Novosibirsk, S=nso, PostalCode=630090, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
2F74D159839B911DB6F1DFF991E70893

File PE Metadata
Compilation timestamp:
12/7/2015 1:28:59 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x29BB8

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 94, 77, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, FF, 35, 30, E6, 04, 10, FF, 15, E8, C1, 03, 10, 85, C0, 74, 02, FF, D0, 6A, 19, E8, 7D, 78, 00, 00, 6A, 01, 6A, 00, E8, 2D, 78, 00, 00, 83, C4, 0C, E9, F2, 77, 00, 00, 8B, FF, 55, 8B, EC, 83, EC, 20, 53, 57, 33, DB, 6A, 07, 33, C0, 59, 8D, 7D, E4, 89, 5D, E0, F3, AB, 39, 5D, 0C, 75, 15, E8, 99, E9, FF, FF, C7, 00, 16, 00, 00, 00, E8, E1, 0F, 00, 00, 83, C8, FF, EB, 4D...
 
[+]

Entropy:
6.5770

Code size:
235 KB (240,640 bytes)

Winsock2 LSP
Name:
Network Proxy System over [MSAFD Tcpip [TCP/IP]]

Type:
Layered Chain Entry

Provider ID:
{77919C82-E590-4A97-BDF8-AB53ADF07ABA}

Service flags:
0x66


Remove ltvlib.dll - Powered by Reason Core Security