TooltabExtension.dll

APN, LLC Tooltab Platform for Internet Explorer

IAC Search and Media

This is a component of the Ask.com toolbar, a browser extension that will modify the default web browser's search provider, home page and various other settings. The module TooltabExtension.dll, “APN, LLC Tooltab Platform” by IAC Search and Media has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
APN, LLC  (signed by IAC Search and Media)

Product:
APN, LLC Tooltab Platform for Internet Explorer

Description:
APN, LLC Tooltab Platform

Version:
2.1.3.16237

MD5:
5476470b2dc1b0d6e4a6ac0b23f2b995

SHA-1:
2f2d9a791c7bd947b61010b4723c4d9141990887

SHA-256:
72271242e3b0e1f86b84f76b51adebaad06c4e6971d8b43bc7a49d10115c8622

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/24/2024 11:57:32 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Ask (M)
16.9.11.12

File size:
243.3 KB (249,160 bytes)

Product version:
2.104.34.16237

Copyright:
© 2016 APN, LLC. An IAC Company. All rights reserved.

Original file name:
TooltabExtension.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\tv stream nowtooltab\tooltabextension.dll

Digital Signature
Authority:
Symantec Corporation

Valid from:
9/21/2015 5:00:00 PM

Valid to:
11/16/2018 3:59:59 PM

Subject:
CN=IAC Search and Media, O=IAC Search and Media, L=Oakland, S=California, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
555361B990788EAF1F345E34ECA97A08

File PE Metadata
Compilation timestamp:
8/24/2016 8:41:52 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:f/Yg1TopQI/tDp44dJQcXT7J7ONdl5X68:fAQMte4dJQ2T7J7gq8

Entry address:
0x1604D

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, F0, 5A, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, 6C, 67, 02, 10, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, 20, 61, 02, 10, C9, C2, 08, 00, CC, CC, CC, CC, 55, 8B, EC, 57, 56, 8B, 75, 0C, 8B, 4D, 10, 8B, 7D...
 
[+]

Entropy:
6.5063

Code size:
148 KB (151,552 bytes)

Remove TooltabExtension.dll - Powered by Reason Core Security