How to remove dtuser.exe.vir

dtuser.exe.vir

The module dtuser.exe.vir has been detected as PUP.Visicom

dtuser.exe.vir
Company Name:

IAC Search and Media, Inc.

MD5: ac0eadc3dca71d43a55cc7e03dca843e
Size: 495 KB
First Published: 2017-05-21 21:04:40 (7 years ago)
Latest Published: 2019-12-02 14:17:01 (4 years ago)
Status: PUP.Visicom (on last analysis)
Analysis Date: 2019-12-02 14:17:01 (4 years ago)
Signed By: IAC Search and Media
Status: Valid
%ffprofile%\extensions\{05bf0e05-a298-4d0a-b6eb-f55b30a2e662}
%appdata%\profiles\norakgrejety.default\extensions\{c0caa5fe-7c9c-4dca-a265-63cf55379d1a}
%ffprofile%\extensions\{c0caa5fe-7c9c-4dca-a265-63cf55379d1a}
%desktop%\desktop\old firefox data\9udgu9h8.default\extensions\{c0caa5fe-7c9c-4dca-a265-63cf55379d1a}
%ffprofile%\extensions\{41ca0640-a64c-4262-8540-36c33ee58961}
%ffprofile%\extensions
%sysdrive%\adwcleaner\quarantine\c\users\ghla\appdata\roaming\mozilla\firefox\profiles\pqjnv055.default\extensions
%localappdata%\malwareprotectionlive
%desktop%\old firefox data\7f5df5u9.default\extensions
%ffprofile%\extensions
dtuser.exe
dtuser.exe.vir
dtuser-2d648987-3533-47ba-a786-f15cd0568140.exe
dtuser-fcc16bcd-a955-4874-b9bb-9ea0c520067c.exe
dtuser-9c3988e7-1c9f-4381-8d8b-84d4c59d1334.exe
dtuser-eff8727f-f09c-44de-90a7-caf51455de88.exe
dtuser-cee98e55-c1fb-4ff7-9610-707b7b415e82.exe
dtuser-b0b660d8-14da-4b39-a7f4-13b9f989a4c9.exe
dtuser-c5511627-1213-42da-af4a-b12f0c8b508c.exe
33.3%
24.2%
18.2%
6.1%
3.0%
3.0%
3.0%
3.0%
3.0%
3.0%
Windows 7 72.7%
Windows 8.1 12.1%
Windows 10 9.1%
Windows 8 6.1%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x0001d47d

PE Sections:

Name Size of data MD5
.text 313344 3c101af119da5963e3879ed74c3679c9
.orpc 512 3f5fa750ed18296a3827bcfa275d2695
.rdata 81408 bc6055d88242f76dcafeffd99ffc6248
.data 8192 3e2f0a05f655d58c59c6ec3cd0fa8a16
.rsrc 77312 96b1caa0eb23ad9322400079b403d0e3
.reloc 19456 c99b603dac0cd8d199e966119ca6537d

More information:

Download GridinSoft Anti-Malware - Removal tool for dtuser.exe.vir